Communication method, device, equipment and medium of virtual machine

By modifying the address information of the virtual machine to send and receive data packets and forwarding it through the physical network card, the problem that the virtual machine cannot communicate directly with the public network server is solved, and the function of the virtual machine to access the public network server is realized without increasing costs.

CN118075228BActive Publication Date: 2025-05-02GUANGZHOU DULING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410332912.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-21
Publication Date
2025-05-02
Estimated Expiration
2044-03-21

AI Technical Summary

Technical Problem

Since virtual machines are intranet devices, they cannot communicate directly with public network servers. The existing solution is to set independent and public virtual IP addresses for virtual machines, resulting in increased costs.

Method used

By obtaining the original sending packet to be sent by the target virtual machine to the target public network server, modifying its source address information as the network card address information of the physical network card, sending it to the public network server through the physical network card, and after receiving the feedback data packet, modifying its destination address information as the virtual machine address information and sending it to the target virtual machine.

Benefits of technology

The function of virtual machines accessing public network servers is realized, without setting independent and public virtual IP addresses for virtual machines, saving overhead costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118075228B_ABST
    Figure CN118075228B_ABST
Patent Text Reader

Abstract

The present disclosure provides a communication method, device, equipment and medium for a virtual machine, and relates to technical fields such as ARM cloud, virtual machine, virtual network, physical network, communication transmission and cloud computing. The specific implementation scheme is: obtain the original sending data packet to be sent by the target virtual machine to the target public network server; modify the source address information of the original sending data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, and obtain a modified sending data packet; send the modified sending data packet to the target public network server through the physical network card, and receive the original receiving data packet fed back by the target public network server through the physical network card; modify the destination address information of the original receiving data packet from the network card address information to the virtual machine address information, obtain a modified receiving data packet, and send the modified receiving data packet to the target virtual machine. The present disclosure uses the network card address information of the physical network card itself to realize the virtual machine access to the public network server, so there is no need to set an independent and public virtual IP address for the virtual machine, saving the overhead cost required for the virtual machine to access the public network server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, specifically to technical fields such as ARM cloud, virtual machine, virtual network, physical network, communication transmission and cloud computing, and more particularly to a communication method, device, equipment and medium for a virtual machine. Background Art

[0002] A virtual machine is a complete computer system that is simulated by software and has complete hardware system functions and runs in a completely isolated environment. Any work that can be done in a physical computer can also be done in a virtual machine.

[0003] In the actual operation of virtual machines, business scenarios often require access to public network servers. However, since virtual machines are intranet devices, they cannot communicate directly with public network servers. Currently, a common practice is to set an independent and public virtual IP address for the virtual machine to enable the virtual machine to access the public network server. Summary of the invention

[0004] The present disclosure provides a communication method, apparatus, device and medium for a virtual machine for reducing the cost required for the virtual machine to access a public network server.

[0005] According to one aspect of the present disclosure, a communication method of a virtual machine is provided, comprising:

[0006] Obtaining the original data packet to be sent by the target virtual machine to the target public network server;

[0007] Modify the source address information of the original sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card to obtain a modified sent data packet;

[0008] Sending the modified send data packet to the target public network server through the physical network card, and receiving the original receive data packet fed back by the target public network server through the physical network card;

[0009] The destination address information of the original received data packet is modified from the network card address information to the virtual machine address information to obtain a modified received data packet, and the modified received data packet is sent to the target virtual machine.

[0010] According to another aspect of the present disclosure, a communication device of a virtual machine is provided, comprising:

[0011] The data packet acquisition module is used to acquire the original data packet to be sent by the target virtual machine to the target public network server;

[0012] A source address information modification module, used to modify the source address information of the original sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, so as to obtain a modified sent data packet;

[0013] A data packet transceiver module, used to send the modified send data packet to the target public network server through the physical network card, and receive the original receive data packet fed back by the target public network server through the physical network card;

[0014] The destination address information modification module is used to modify the destination address information of the original received data packet from the network card address information to the virtual machine address information, obtain a modified received data packet, and send the modified received data packet to the target virtual machine.

[0015] According to another aspect of the present disclosure, there is provided an electronic device, comprising:

[0016] at least one processor; and

[0017] a memory communicatively connected to at least one processor; wherein,

[0018] The memory stores instructions that can be executed by at least one processor. The instructions are executed by at least one processor to enable the at least one processor to perform any method in the present disclosure.

[0019] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to execute any one of the methods in the present disclosure.

[0020] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, and the computer program executes any one of the methods of the present disclosure when a processor is used.

[0021] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The accompanying drawings are used to better understand the present solution and do not constitute a limitation of the present disclosure.

[0023] Figure 1 is a flow chart of a communication method of some virtual machines disclosed in an embodiment of the present disclosure;

[0024] Figure 2 is a flow chart of another communication method of virtual machines disclosed in an embodiment of the present disclosure;

[0025] Figure 3A is a flow chart of another communication method of virtual machines disclosed in an embodiment of the present disclosure;

[0026] Figure 3B It is a schematic diagram of the structure of some computing node servers disclosed in the embodiments of the present disclosure;

[0027] Figure 4 It is a schematic diagram of the structure of the communication device of some virtual machines disclosed in the embodiments of the present disclosure;

[0028] Figure 5 The present invention is a block diagram of an electronic device used to implement the communication method of the virtual machine disclosed in the embodiment of the present disclosure. DETAILED DESCRIPTION

[0029] The following is a description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those of ordinary skill in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0030] Since the virtual machine is an intranet device, the virtual machine address information is all intranet addresses. If the virtual machine directly sends data packets to the public network server, the public network server will not be able to use the virtual machine address information to feedback the data packet, resulting in the virtual machine being unable to access the public network server.

[0031] At present, the common practice for virtual machines to access public network servers is to set up independent and public virtual IP addresses for virtual machines, so that public network servers can use virtual IP addresses to feedback data packets, thereby enabling virtual machines to access public network servers. However, using independent and public virtual IP addresses requires costs. As the number of virtual machines increases, the number of independent and public virtual IP addresses required also increases accordingly, which will undoubtedly generate large overhead costs.

[0032] Figure 1 This is a flowchart of some virtual machine communication methods disclosed in the embodiments of the present disclosure. This embodiment can be applied to the case where a virtual machine accesses a public network server using a physical network card. The method of this embodiment can be executed by a virtual machine communication device disclosed in the embodiments of the present disclosure. The device can be implemented in software and / or hardware and can be integrated in any electronic device with computing capabilities, such as a computing node server configured with a virtual machine.

[0033] like Figure 1 As shown, the communication method of the virtual machine disclosed in this embodiment may include:

[0034] S101. Obtain an original data packet to be sent by a target virtual machine to a target public network server.

[0035] A virtual machine is a complete computer system that is simulated by software and has complete hardware system functions and runs in a completely isolated environment. A target virtual machine is a virtual machine that has the business needs of accessing public network servers.

[0036] The target public network server refers to a server (also known as server) deployed in a physical network (also known as an underlay network), while the target virtual machine is a virtual machine deployed in a virtual network (also known as an overlay network). If the target virtual machine wants to access the target public network server, it needs to generate a link layer data packet as a sending data packet, and transmit the sending data packet to the target public network server, and based on the receiving data packet fed back by the target public network server, realize the "communication handshake" between the target virtual machine and the target public network server. Taking TCP (Transmission Control Protocol) as an example to establish a connection, three data packet interactions are required between the target virtual machine and the target public network server to realize three "communication handshakes" before a TCP connection can be established between the target virtual machine and the target public network server. In other words, the original sending data packet in this embodiment refers to the link layer data packet required in the process of establishing a communication connection between the target virtual machine and the target public network server.

[0037] In one embodiment, a target virtual machine deployed in a computing node server (also known as a compute node, hereinafter referred to as a computing node) generates a required original sending data packet, and sends the original sending data packet to an OVS (Open vSwitch) in the computing node through a network interface (such as an eth0 interface) corresponding to the target virtual machine, and the br-int (bridge-integration) in the OVS receives the original sending data packet sent by the target virtual machine through a virtual network interface (such as a veth interface) carried thereon.

[0038] br-int sends the original data packet to br-tun (bridge-tunnel) in OVS through the first data port, and br-tun obtains the original data packet through the second data port. The first data port and the second data port are a data port pair, such as the first data port can be a patch-tun port, and the second data port can be a patch-int port.

[0039] By obtaining the original data packet to be sent from the target virtual machine to the target public network server, a data foundation is laid for the subsequent source address modification of the original data packet.

[0040] S102: modify the source address information of the original sending data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, so as to obtain a modified sending data packet.

[0041] The source address information is recorded in the original data packet, and is used to reflect the address information of the sender of the original data packet. It is understandable that since the original data packet is generated and sent by the target virtual machine, the source address information is the address information of the target virtual machine at the very beginning, that is, the virtual machine address information. The virtual machine address information represents the address information corresponding to the target virtual machine in the virtual network. It is understandable that the virtual machine address information is a kind of intranet address information. For example, the virtual machine IP address in the virtual machine address information can be "172.16.80.1" and the like.

[0042] The physical network card represents the physical network card deployed in the computing node, and the network card address information represents the address information corresponding to the physical network card in the physical network. Since the network card address information is an independent and public address information, the network card address information can be used to perform SNAT (Source Network Address Translation), so as to forward data packets to the target public network server through the physical network card.

[0043] In one implementation, br-tun modifies the source address information in the original data packet from the virtual machine address information of the target virtual machine to the pre-configured virtual address information, and then uses the physical network card to modify the source address information in the original data packet from the virtual address information to the physical network card information, thereby generating a modified data packet. The virtual address information is an internal virtual address pre-configured for the target virtual machine, that is, the target virtual machine has unique virtual address information, for example, the virtual IP address of the target virtual machine can be "100.72.1.1". The virtual address information is used for br-tun to forward layer 2 packets, so that br-tun can route the original data packet to the physical network card.

[0044] By modifying the source address information of the original sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, a modified sent data packet is obtained, thereby achieving the effect of disguising the virtual machine address information by using the network card address information. Since the network card address information is independent and public address information, it can ensure that the target public network server can smoothly feedback the data packet, indirectly ensuring the target virtual machine's smooth access to the target public network server.

[0045] S103: Send the modified send data packet to the target public network server through the physical network card, and receive the original receive data packet fed back by the target public network server through the physical network card.

[0046] The original received data packet is a link layer data packet generated by the target public network server according to the received modified sent data packet and used for "communication handshake" with the target virtual machine.

[0047] In one embodiment, br-tun sends the modified send data packet to the physical network card through the third data port, and the physical network card obtains the modified send data packet through the fourth data port, and then sends the modified send data packet to the target public network server through the physical network card according to the destination address information of the target public network server recorded in the modified send data packet.

[0048] The target public network server generates an original received data packet according to the modified sent data packet, and feeds the original received data packet back to the physical network card. The physical network card sends the original received data packet to br-tun through the fourth data port, and br-tun obtains the original received data packet through the third data port.

[0049] The third data port and the fourth data port are a data port pair. For example, the third data port may be a veth-br-tun port, and the fourth data port may be a veth-br0 port.

[0050] The modified sending data packet is sent to the target public network server through the physical network card, and the original receiving data packet fed back by the target public network server is received through the physical network card, thereby achieving the effect of sending and receiving data packets using the physical network card, thereby eliminating the need to separately configure an independent and public virtual IP address, and saving overhead costs while ensuring that the target virtual machine can successfully access the target public network server.

[0051] S104: modify the destination address information of the original received data packet from the network card address information to the virtual machine address information to obtain a modified received data packet, and send the modified received data packet to the target virtual machine.

[0052] Among them, the destination address information is recorded in the original received data packet, which is used to reflect the address information of the recipient of the original received data packet. It can be understood that since the source address information in the modified sent data packet is ultimately modified to the network card address information, the target public network server will believe that the modified sent data packet is generated and sent by the physical network card. Therefore, the target public network server will identify the physical network card as the recipient of the original received data packet, and the destination address information filled in the original received data packet generated by the target public network server is the network card address information of the physical network card.

[0053] However, the modified sending data packet is actually generated by the target virtual machine. Therefore, after receiving the original receiving data packet, the destination address information of the original receiving data packet needs to be modified from the network card address information to the virtual machine address information to ensure that the original data packet can be correctly sent to the target virtual machine for establishing communication between the target virtual machine and the target public network server.

[0054] In one implementation, br-tun first uses a physical network card to modify the destination address information of an original received data packet from the network card address information to the virtual address information, and then br-tun determines the virtual machine address information of the corresponding target virtual machine based on the virtual address information, and then modifies the destination address information of the original received data packet from the virtual address information to the virtual machine address information to obtain a modified received data packet.

[0055] br-tun sends the modified received data packet to br-int through the second data port, and br-int receives the modified received data packet through the first data port. br-int sends the modified received data packet to the target virtual machine through the virtual network interface, and the target virtual machine receives the modified received data packet through the corresponding network interface. The target virtual machine establishes communication with the target public network server based on the received modified received data packet.

[0056] The present invention obtains an original sending data packet to be sent by a target virtual machine to a target public network server; modifies the source address information of the original sending data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card to obtain a modified sending data packet; sends the modified sending data packet to the target public network server through the physical network card, and receives the original receiving data packet fed back by the target public network server through the physical network card; modifies the destination address information of the original receiving data packet from the network card address information to the virtual machine address information to obtain a modified receiving data packet, and sends the modified receiving data packet to the target virtual machine. Since the network card address information is independent and public address information, the network card address information of the physical network card itself is used to send a data packet to the target public network server, which can ensure that the target public network server can smoothly feed back the data packet through the network card address information, thereby achieving the effect of the target virtual machine accessing the target public network server, and there is no need to set an independent and public virtual IP address for the virtual machine, thereby saving the overhead cost required for the virtual machine to access the public network server.

[0057] Figure 2 It is a flowchart of other communication methods of virtual machines disclosed in the embodiments of the present disclosure, which can be used to further optimize and expand the above technical solution and can be combined with the above optional implementation methods.

[0058] like Figure 2As shown, the communication method of the virtual machine disclosed in this embodiment may include:

[0059] S201. Obtain an original data packet to be sent by a target virtual machine to a target public network server.

[0060] S202. Obtain the destination address information of the original data packet as the first address information, and obtain the source path information of the original data packet as the first source path information, and determine the sending method used to send the original data packet to the target public network server based on the first address information and the first source path information.

[0061] Among them, the destination address information of the original data packet is used to reflect the address information of the recipient of the original data packet. It can be understood that since the target virtual machine wants to send the original data packet to the target public network server, the destination address information of the original data packet is the address information of the target public network server, including but not limited to the server IP address, server port address, etc.

[0062] The source path information of the original data packet reflects the port through which the original data packet is sent to br-tun. For example, the original data packet is sent to br-tun through the "patch-int port", so the "patch-int port" is used as the source path information.

[0063] The sending methods used to send the original data packet to the target public network server include "conventional sending method" and "source address translation sending method". Among them, "conventional sending method" is usually used in business access scenarios, with the characteristics of speed limit, traffic limit and high charges; while "source address translation sending method" is usually used in operation and maintenance access scenarios, such as operation and maintenance and management of virtual machine access scenarios, with the characteristics of unlimited speed, unlimited traffic and low charges.

[0064] In one implementation, br-tun parses the original transmitted data packet to obtain the destination address information and source path information of the original transmitted data packet, and uses the destination address information as the first address information, and the source path information as the first source path information.

[0065] br-tun obtains the standard destination address information and standard source path information corresponding to the pre-configured source address translation sending mode, and matches the first address information with the standard destination address information, and the first source path information with the standard source path information respectively. If both are matched successfully, the sending mode is determined to be the source address translation sending mode, otherwise the sending mode is determined to be the conventional sending mode.

[0066] By obtaining the destination address information of the original sent data packet as the first address information, and obtaining the source path information of the original sent data packet as the first source path information; according to the first address information and the first source path information, determining the sending method used to send the original sent data packet to the target public network server, so that the computing node can send the original sent data packet to the target public network server through the conventional sending method or the source address conversion sending method, thereby eliminating the need to separate the operation and maintenance access traffic and business access traffic of the computing node, effectively reducing the network load of the computing node.

[0067] Optionally, the first address information includes a first IP address and a first port address.

[0068] The first address information indicates the address information of the target public network server, and the address information of the target public network server includes a server IP address and a server port address. The server IP address is used as the first IP address, and the server port address is used as the first port address.

[0069] For example, assuming that the server IP address is "192.168.168.104" and the server port address (ServerPort) is "23", then "192.168.168.104" is used as the first IP address and "23" is used as the first port address.

[0070] Optionally, determining, according to the first address information and the first source path information, a sending method adopted to send the original sending data packet to the target public network server includes:

[0071] A. Obtain a standard destination IP address, a standard destination port address, and a first standard source path corresponding to the source address translation sending mode.

[0072] Among them, the standard destination IP address, standard destination port address, and the first standard source path indicate: when the original sending data packet is sent to the target public network server using the source address translation sending method, the destination IP address, destination port address, and source path that should be recorded in the original sending data packet.

[0073] In one implementation, a flow entry is added to br-tun in advance, and a matching field is set for the flow entry, that is, the matching field of the flow entry is set to the standard destination IP address, the standard destination port address, and the first standard source path. br-tun uses the matching field of the flow entry to perform a matching operation on the first IP address, the first port address, and the first source path information.

[0074] B. When the first IP address matches the standard destination IP address, the first port address matches the standard destination port address, and the first source path information matches the first standard source path, the sending mode is determined to be the source address translation sending mode.

[0075] In one implementation, br-tun utilizes the matching field of the flow table entry to respectively match the first IP address with the standard destination IP address, the first port address with the standard destination port address, and the first source path information with the first standard source path; when the first IP address with the standard destination IP address, the first port address with the standard destination port address, and the first source path information with the first standard source path all match successfully, the sending mode is determined to be the source address conversion sending mode; when the first IP address with the standard destination IP address, the first port address with the standard destination port address, or the first source path information with the first standard source path fails to match, the sending mode is determined to be the conventional sending mode.

[0076] By obtaining the standard destination IP address, standard destination port address, and the first standard source path corresponding to the source address translation sending mode; when the first IP address and the standard destination IP address, the first port address and the standard destination port address, and the first source path information and the first standard source path all match successfully, determining the sending mode as the source address translation sending mode, thereby achieving the effect of determining the appropriate sending mode for sending data packets to the target public network server, avoiding the problem that the data packet cannot be successfully sent to the target public network server due to the use of an inappropriate sending mode, resulting in the target virtual machine being unable to successfully access the target public network server.

[0077] S203. When the sending mode is a conventional sending mode, execute S204; when the sending mode is a source address conversion sending mode, execute S205.

[0078] In one implementation, it is determined whether the sending mode is a conventional sending mode or a source address conversion sending mode. If the sending mode is determined to be a conventional sending mode, the execution is jumped to S204; if the sending mode is determined to be a source address conversion sending mode, the execution is jumped to S205.

[0079] S204: Send the original data packet to the target network node, so as to forward the original data packet to the target public network server through the target network node.

[0080] The target network node, also known as a network node, is a node device that has the ability to access a physical network.

[0081] In one embodiment, when the sending mode is a conventional sending mode, br-tun uses a vxlan tunnel to send the original sending data packet to a target network node, thereby using the target network node to transfer the original sending data packet to a physical network, and then sending it to a target public network server.

[0082] By sending the original data packet to the target network node in the case of a conventional sending mode, and forwarding the original data packet to the target public network server through the target network node, the computing node can send the data packet to the public network server using the conventional sending mode to meet the needs of business access scenarios and ensure the diversity of computing node access to the public network server scenarios.

[0083] S205 , modify the source IP address from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and modify the source MAC address from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, to obtain a forwarded data packet.

[0084] The source address information of the original sent data packet includes the source IP address and the source MAC address, the virtual machine address information includes the virtual machine IP address and the virtual machine MAC address, and the network card address information includes the network card IP address and the network card MAC address.

[0085] In one implementation, when the sending mode is source address conversion sending mode, br-tun modifies the source IP address from the virtual machine IP address to the virtual IP address and the source MAC address from the virtual machine MAC address to the virtual MAC address through the Conntrack+NAT mechanism of OVS, and obtains the relayed sending data packet. Among them, the virtual IP address and the virtual MAC address are virtual addresses in the computing node pre-allocated to the target virtual machine, and are used when the second-layer packet is forwarded from br-tun to the physical network card in the computing node.

[0086] S206, sending the transit sending data packet to the physical network card, so that the physical network card can modify the source IP address from the virtual IP address to the network card IP address, and modify the source MAC address from the virtual MAC address to the network card MAC address, to obtain a modified sending data packet.

[0087] In one implementation, br-tun modifies the destination MAC address in the forwarding data packet to the MAC address of the physical network card, and then sends the forwarding data packet to the physical network card through the third data port. This is because the MAC address is a link layer address, which is only valid in the same IP network segment, and data packets in different IP network segments need to be forwarded. Therefore, the destination MAC address in the forwarding data packet is modified to the MAC address of the network card to ensure that br-tun can route the forwarding data packet to the physical network card.

[0088] The physical network card receives the forwarded data packet through the fourth data port, and modifies the source IP address from the virtual IP address to the network card IP address through the SNAT rule of iptables, and modifies the source MAC address from the virtual MAC address to the network card MAC address, thereby obtaining the modified data packet.

[0089] By, when judging that the sending mode is the source address conversion sending mode, modifying the source IP address from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and modifying the source MAC address from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, obtaining a transit sending data packet; sending the transit sending data packet to the physical network card, so that the physical network card modifies the source IP address from the virtual IP address to the network card IP address, and modifies the source MAC address from the virtual MAC address to the network card MAC address. On the one hand, by modifying the source address information to the virtual address information inside the computing node, it is possible to ensure the smooth execution of the second-layer packet forwarding from br-tun to the physical network card inside the computing node; on the other hand, by modifying the source address information to the network card address information, there is no need to set an independent and public virtual address for the virtual machine, thereby saving the overhead cost required for the virtual machine to access the public network server.

[0090] S207: Send the modified send data packet to the target public network server through the physical network card, and receive the original receive data packet fed back by the target public network server through the physical network card.

[0091] S208: Modify the destination address information of the original received data packet from the network card address information to the virtual machine address information to obtain a modified received data packet, and send the modified received data packet to the target virtual machine.

[0092] Figure 3A It is a flowchart of other communication methods of virtual machines disclosed in the embodiments of the present disclosure, which can be used to further optimize and expand the above technical solution and can be combined with the above optional implementation methods.

[0093] like Figure 3A As shown, the communication method of the virtual machine disclosed in this embodiment may include:

[0094] S301. Obtain an original data packet to be sent by a target virtual machine to a target public network server.

[0095] S302: modify the source address information of the original sending data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, and obtain a modified sending data packet.

[0096] S303: Send the modified send data packet to the target public network server through the physical network card, and receive the original receive data packet fed back by the target public network server through the physical network card.

[0097] S304, modifying the destination IP address from the network card IP address to the virtual IP address through the physical network card, and modifying the destination MAC address from the network card MAC address to the virtual MAC address, to obtain a transit received data packet.

[0098] In one embodiment, the destination IP address is modified from the network card IP address to the virtual IP address through the physical network card through the SNAT reverse rule of iptables, and the destination MAC address is modified from the network card MAC address to the virtual MAC address to obtain the transit received data packet. In addition, the destination port address is set to the source port address used by the target virtual machine when sending the original sending data packet.

[0099] The physical network card sends the transit received data packet to br-tun through the fourth data port.

[0100] S305, obtaining a transit received data packet, obtaining source address information of the transit received data packet as second address information, and obtaining source path information of the transit received data packet as second source path information, and verifying the validity of the transit received data packet based on the second address information and the second source path information.

[0101] Among them, the transit received data packet and the original received data packet have the same source address information, and the source address information of the transit received data packet is used to reflect the address information of the sender of the original received data packet. It can be understood that since the original received data packet is generated by the target public network server and sent to the physical network card, the source address information of the transit received data packet is the address information of the target public network server, including but not limited to the server IP address, server port address, etc.

[0102] The source path information of the transit receive data packet reflects the port through which the transit receive data packet is sent to br-tun. For example, the transit receive data packet is sent to br-tun through the "veth_br-tun port", so the "veth_br-tun port" is used as the source path information of the transit receive data packet.

[0103] In one embodiment, br-tun obtains a transit received data packet through a third data port, and parses the transit received data packet to obtain source address information and source path information of the transit received data packet, and uses the source address information as the second address information, and the source path information as the second source path information.

[0104] br-tun obtains the standard source address information and standard source path information corresponding to the pre-configured valid data packet, and matches the second address information with the standard source address information, and the second source path information with the standard source path information respectively. If both are matched successfully, the validity verification result of the transit received data packet is determined to be a valid data packet; otherwise, the validity verification result of the transit received data packet is determined to be an invalid data packet.

[0105] By obtaining the source address information of the transit received data packet as the second address information, and obtaining the source path information of the transit received data packet as the second source path information; based on the second address information and the second source path information, the validity of the transit received data packet is verified, thereby achieving the effect of verifying the validity of the transit received data packet, which is conducive to identifying useless junk data packets.

[0106] Optionally, the second address information includes a second IP address and a second port address.

[0107] The second address information indicates the address information of the target public network server, and the address information of the target public network server includes a server IP address and a server port address. The server IP address is used as the second IP address, and the server port address is used as the second port address.

[0108] For example, assuming that the server IP address is "192.168.168.104" and the server port address (ServerPort) is "23", then "192.168.168.104" is used as the second IP address and "23" is used as the second port address.

[0109] Optionally, validating the transit received data packet according to the second address information and the second source path information includes:

[0110] Obtain the standard source IP address, standard source port address, and second standard source path corresponding to the valid data packet; when the second IP address and the standard source IP address, the second port address and the standard source port address, and the second source path information and the second standard source path all match successfully, determine that the validity verification result of the transit received data packet is a valid data packet.

[0111] The standard source IP address, the standard source port address, and the second standard source path represent: the source IP address, the source port address, and the source path that should be recorded in a valid data packet.

[0112] In one implementation, a flow entry is added to br-tun in advance, and a matching field is set for the flow entry, that is, the matching field of the flow entry is set to the standard source IP address, the standard source port address, and the second standard source path. br-tun uses the matching field of the flow entry to perform a matching operation on the second IP address, the second port address, and the second source path information.

[0113] br-tun uses the matching field of the flow table entry to match the second IP address with the standard source IP address, the second port address with the standard source port address, and the second source path information with the second standard source path, respectively. When the second IP address with the standard source IP address, the second port address with the standard source port address, and the second source path information with the second standard source path all match successfully, the validity verification result of the transit received data packet is determined to be a valid data packet; when the second IP address with the standard source IP address, the second port address with the standard source port address, or the second source path information with the second standard source path fails to match, the validity verification result of the transit received data packet is determined to be an invalid data packet.

[0114] By obtaining the standard source IP address, standard source port address, and second standard source path corresponding to the valid data packet; when the second IP address and the standard source IP address, the second port address and the standard source port address, and the second source path information and the second standard source path all match successfully, the validity verification result of the transit received data packet is determined to be a valid data packet, thereby achieving the effect of verifying whether the transit received data packet is a valid data packet. Since the validity verification effect can be achieved only based on the matching field, it is convenient and fast.

[0115] S306. If the validity verification result is an invalid data packet, execute S307; if the validity verification result is a valid data packet, execute S308.

[0116] Among them, invalid data packets refer to junk data packets with no actual business function, while valid data packets refer to useful data packets with actual business function.

[0117] In one embodiment, the validity verification result of the transit received data packet is determined to be an invalid data packet or a valid data packet. If the validity verification result is determined to be an invalid data packet, the execution is jumped to S307; if the validity verification result is determined to be a valid data packet, the execution is jumped to S308.

[0118] S307: discard the transit received data packet.

[0119] In one implementation, if br-tun determines that the validity verification result of the transit received data packet is an invalid data packet, the transit received data packet is deleted, that is, the transit received data packet is discarded.

[0120] By discarding the transit received data packet when the validity verification result of the transit received data packet is an invalid data packet, on the one hand, the security of the computing node is improved, and on the other hand, the data storage capacity of the computing node is saved and the data processing pressure of the computing node is alleviated.

[0121] S308, modifying the destination IP address from the virtual IP address to the virtual machine IP address, and modifying the destination MAC address from the virtual MAC address to the virtual machine MAC address, obtaining a modified received data packet, and sending the modified received data packet to the target virtual machine.

[0122] The destination address information of the original received data packet includes a destination IP address and a destination MAC address.

[0123] In one embodiment, when the validity verification result is judged to be a valid data packet, br-tun modifies the destination IP address from the virtual IP address to the virtual machine IP address and the destination MAC address from the virtual MAC address to the virtual machine MAC address through the reverse rule mechanism of Conntrack+NAT of OVS, obtains a modified received data packet, and sends the modified received data packet to the target virtual machine.

[0124] The destination IP address is modified from the network card IP address to the virtual IP address through the physical network card, and the destination MAC address is modified from the network card MAC address to the virtual MAC address to obtain a transit receive data packet; the transit receive data packet is obtained, and the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address. On the one hand, by modifying the destination address information to the virtual address information inside the computing node, the smooth execution of the second-layer packet forwarding from the physical network card to br-tun inside the computing node can be guaranteed; on the other hand, by modifying the destination address information to the virtual machine address information, it is guaranteed that the target virtual machine can successfully receive the data packet fed back by the target public network server, and indirectly ensure that the target virtual machine can smoothly communicate with the target public network server.

[0125] Figure 3B is a schematic diagram of the structure of some computing node servers disclosed in the embodiments of the present disclosure, such as Figure 3BAs shown, the computing node server 300 includes a target virtual machine 301, an open virtual switch 302, a physical network card 303 and a data port eth0 313. Among them, the target virtual machine 301 is equipped with a network interface eth0 304. The open virtual switch 302 is provided with a comprehensive bridge br-int 305 and a tunnel bridge br-tun 306. br-int 305 is equipped with a virtual network interface veth0 307 and a data port patch-tun 308. br-tun 306 is equipped with a data port patch-int 309, a data port veth-br-tun 310 and a tunnel vxlan 311. The physical network card 303 is equipped with a data port veth-br0 312. It can be understood that the computing node server 300 can include one or more virtual machines. This embodiment is only explained by taking the computing node server 300 including one target virtual machine 301 as an example, and does not limit the specific number of virtual machines.

[0126] Specifically, the target virtual machine 301 generates an original transmission data packet, and sends the original transmission data packet to the integrated bridge br-int 305 through the network interface eth0 304, and the integrated bridge br-int 305 receives the original transmission data packet through the virtual network interface veth0 307. The integrated bridge br-int 305 sends the original transmission data packet to the tunnel bridge br-tun 306 through the data port patch-tun 308, and the tunnel bridge br-tun 306 receives the original transmission data packet through the data port patch-int 309.

[0127] The tunnel bridge br-tun 306 determines the sending method used to send the original sending data packet to the target public network server. When the sending method is the conventional sending method, the original sending data packet is sent to the target network node through the tunnel vxlan311, which is used to forward the original sending data packet to the target public network server through the target network node. When the sending method is the source address conversion sending method, the source IP address is modified from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and the source MAC address is modified from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, and a transit sending data packet is obtained, and the transit sending data packet is sent to the physical network card 303 through the data port veth-br-tun 310.

[0128] The physical network card 303 receives the forwarded data packet through the data port veth-br0 312, and modifies the source IP address from the virtual IP address to the network card IP address, and modifies the source MAC address from the virtual MAC address to the network card MAC address, obtains the modified data packet, and sends the modified data packet to the target public network server through the data port eth0 313.

[0129] The physical network card 303 receives the original received data packet through the data port eth0 313, and modifies the destination IP address from the network card IP address to the virtual IP address, and modifies the destination MAC address from the network card MAC address to the virtual MAC address, obtains the transit received data packet, and sends the transit received data packet to the tunnel bridge br-tun 306 through the data port veth-br0312.

[0130] The tunnel bridge br-tun 306 receives the transit receive data packet through veth-br-tun 310, and verifies the validity of the transit receive data packet. If the validity verification result of the transit receive data packet is an invalid data packet, the transit receive data packet is discarded. If the validity verification result of the transit receive data packet is a valid data packet, the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address, to obtain a modified receive data packet. The modified receive data packet is sent to the integrated bridge br-int 305 through the data port patch-int 309.

[0131] The integrated bridge br-int 305 receives the modified received data packet through the data port patch-tun 308, and sends the modified received data packet to the target virtual machine 301 through the virtual network interface veth0 307. The target virtual machine 301 receives the modified received data packet through the network interface eth0 304, and establishes a communication connection with the target public network server according to the modified received data packet.

[0132] This embodiment only Figure 3B Taking the provided structural diagram as an example, the method flow of the virtual machine communication method disclosed in this embodiment is explained. The specific implementation method of the above method flow process is detailed in the description of the method part of this embodiment, which will not be repeated here.

[0133] Figure 4 This is a schematic diagram of the structure of some virtual machine communication devices disclosed in the embodiments of the present disclosure, which can be applied to the case where a virtual machine accesses a public network server using a physical network card. The device of this embodiment can be implemented using software and / or hardware, and can be integrated on any electronic device with computing capabilities.

[0134] like Figure 4 As shown, the communication device 40 of the virtual machine disclosed in this embodiment may include a data packet acquisition module 41, a source address information modification module 42, a data packet transceiver module 43 and a destination address information modification module 44, wherein:

[0135] The data packet acquisition module 41 is used to acquire the original data packet to be sent by the target virtual machine to the target public network server;

[0136] The source address information modification module 42 is used to modify the source address information of the original sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, so as to obtain a modified sent data packet;

[0137] The data packet transceiver module 43 is used to send the modified send data packet to the target public network server through the physical network card, and receive the original receive data packet fed back by the target public network server through the physical network card;

[0138] The destination address information modification module 44 is used to modify the destination address information of the original received data packet from the network card address information to the virtual machine address information, obtain a modified received data packet, and send the modified received data packet to the target virtual machine.

[0139] Optionally, the device further includes a sending mode determination module, which is specifically configured to:

[0140] Acquire the destination address information of the original sent data packet as the first address information, and acquire the source path information of the original sent data packet as the first source path information;

[0141] Determine, according to the first address information and the first source path information, a sending method adopted to send the original sending data packet to the target public network server;

[0142] The source address information modification module 42 is specifically used for:

[0143] In the case where the sending mode is the source address conversion sending mode, the source address information of the original sent data packet is modified from the virtual machine address information of the target virtual machine to the network card address information of the physical network card.

[0144] Optionally, the device further includes a conventional sending module, specifically configured to:

[0145] In the case where the sending mode is a conventional sending mode, the original sending data packet is sent to a target network node, so as to forward the original sending data packet to the target public network server through the target network node.

[0146] Optionally, the first address information includes a first IP address and a first port address;

[0147] The sending mode determination module is further specifically used for:

[0148] Obtaining a standard destination IP address, a standard destination port address, and a first standard source path corresponding to the source address translation sending mode;

[0149] When the first IP address and the standard destination IP address, the first port address and the standard destination port address, and the first source path information and the first standard source path all successfully match, the sending mode is determined to be the source address conversion sending mode.

[0150] Optionally, the source address information of the originally sent data packet includes a source IP address and a source MAC address, the virtual machine address information includes a virtual machine IP address and a virtual machine MAC address, and the network card address information includes a network card IP address and a network card MAC address;

[0151] The source address information modification module 42 is further specifically used for:

[0152] The source IP address is modified from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and the source MAC address is modified from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, to obtain a forwarding and sending data packet;

[0153] The forwarded data packet is sent to the physical network card, so that the physical network card can modify the source IP address from the virtual IP address to the network card IP address, and modify the source MAC address from the virtual MAC address to the network card MAC address.

[0154] Optionally, the destination address information of the originally received data packet includes a destination IP address and a destination MAC address;

[0155] The destination address information modification module 44 is specifically used to:

[0156] The destination IP address is modified from the network card IP address to the virtual IP address through the physical network card, and the destination MAC address is modified from the network card MAC address to the virtual MAC address, to obtain a transit received data packet;

[0157] The transit received data packet is obtained, and the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address.

[0158] Optionally, the device further includes a validity verification module, specifically configured to:

[0159] Acquire the source address information of the forwarded received data packet as the second address information, and acquire the source path information of the forwarded received data packet as the second source path information;

[0160] Verifying the validity of the transit received data packet according to the second address information and the second source path information;

[0161] The destination address information modification module 44 is further specifically used for:

[0162] When the validity verification result of the transit received data packet is a valid data packet, the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address.

[0163] Optionally, the device further includes a data packet discarding module, specifically configured to:

[0164] In the case where the validity verification result of the transit received data packet is an invalid data packet, the transit received data packet is discarded.

[0165] Optionally, the second address information includes a second IP address and a second port address;

[0166] The validity verification module is further specifically used for:

[0167] Obtaining the standard source IP address, standard source port address, and second standard source path corresponding to the valid data packet;

[0168] When the second IP address and the standard source IP address, the second port address and the standard source port address, and the second source path information and the second standard source path all successfully match, the validity verification result of the transit received data packet is determined to be a valid data packet.

[0169] The communication device 40 of the virtual machine disclosed in the embodiment of the present disclosure can execute the communication method of the virtual machine disclosed in the embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects of the execution method. The contents not described in detail in this embodiment can refer to the description in the embodiment of the method of the present disclosure.

[0170] In the technical solution disclosed herein, the acquisition, storage and application of user personal information involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0171] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium and a computer program product.

[0172] Figure 5 A schematic block diagram of an example electronic device 500 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0173] like Figure 5 As shown, the device 500 includes a computing unit 501, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the device 500 can also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0174] A number of components in the device 500 are connected to the I / O interface 505, including: an input unit 506, such as a keyboard, a mouse, etc.; an output unit 507, such as various types of displays, speakers, etc.; a storage unit 508, such as a disk, an optical disk, etc.; and a communication unit 509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the device 500 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0175] The computing unit 501 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 501 performs the various methods and processes described above, such as the communication method of the virtual machine. For example, in some embodiments, the communication method of the virtual machine may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as a storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed on the device 500 via ROM 502 and / or the communication unit 509. When the computer program is loaded into RAM 503 and executed by the computing unit 501, one or more steps of the communication method of the virtual machine described above may be performed. Alternatively, in other embodiments, the computing unit 501 may be configured to perform the communication method of the virtual machine by any other appropriate means (e.g., by means of firmware).

[0176] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0177] The program code for implementing the method of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, enables the functions / operations specified in the flow chart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0178] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0179] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0180] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0181] A computer system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, a server of a distributed system, or a server combined with a blockchain.

[0182] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps recorded in this disclosure can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this document does not limit this.

[0183] The above specific implementations do not constitute a limitation on the protection scope of the present disclosure. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A communication method for a virtual machine, comprising: Obtaining the original data packet to be sent by the target virtual machine to the target public network server; The source address information of the original sending data packet is modified from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, so as to obtain a modified sending data packet; wherein the source address information of the original sending data packet includes a source IP address and a source MAC address, the virtual machine address information includes a virtual machine IP address and a virtual machine MAC address, and the network card address information includes a network card IP address and a network card MAC address; the modified sending data packet is sent to the target public network server through the physical network card, and the original receiving data packet fed back by the target public network server is received through the physical network card; Modify the destination address information of the original received data packet from the network card address information to the virtual machine address information to obtain a modified received data packet, and send the modified received data packet to the target virtual machine; The step of modifying the source address information of the originally sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card includes: The source IP address is modified from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and the source MAC address is modified from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, to obtain a forwarded data packet; wherein the virtual IP address and the virtual MAC address are virtual addresses inside the computing node pre-allocated to the target virtual machine, and are used when the tunnel bridge performs layer 2 packet forwarding to the physical network card in the computing node; The forwarded data packet is sent to the physical network card, so that the physical network card can modify the source IP address from the virtual IP address to the network card IP address, and modify the source MAC address from the virtual MAC address to the network card MAC address.

2. The method according to claim 1, after obtaining the original data packet to be sent by the target virtual machine to the target public network server, further comprises: Acquire the destination address information of the original sent data packet as the first address information, and acquire the source path information of the original sent data packet as the first source path information; Determine, according to the first address information and the first source path information, a sending method adopted to send the original sending data packet to the target public network server; The step of modifying the source address information of the originally sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card includes: In the case where the sending mode is the source address conversion sending mode, the source address information of the original sent data packet is modified from the virtual machine address information of the target virtual machine to the network card address information of the physical network card.

3. The method according to claim 2, after determining the sending mode used to send the original data packet to the target public network server, further comprising: In the case where the sending mode is a conventional sending mode, the original sending data packet is sent to a target network node, so as to forward the original sending data packet to the target public network server through the target network node.

4. The method according to claim 2, wherein: The first address information includes a first IP address and a first port address; The determining, according to the first address information and the first source path information, a sending method adopted to send the original sending data packet to the target public network server includes: Obtaining a standard destination IP address, a standard destination port address, and a first standard source path corresponding to the source address translation sending mode; When the first IP address and the standard destination IP address, the first port address and the standard destination port address, and the first source path information and the first standard source path all successfully match, the sending mode is determined to be the source address conversion sending mode.

5. The method according to claim 4, wherein: The destination address information of the originally received data packet includes a destination IP address and a destination MAC address; The modifying the destination address information of the original received data packet from the network card address information to the virtual machine address information includes: The destination IP address is modified from the network card IP address to the virtual IP address through the physical network card, and the destination MAC address is modified from the network card MAC address to the virtual MAC address, to obtain a transit received data packet; The transit received data packet is obtained, and the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address.

6. The method according to claim 5, after obtaining the transit received data packet, further comprising: Acquire the source address information of the forwarded received data packet as the second address information, and acquire the source path information of the forwarded received data packet as the second source path information; Verifying the validity of the transit received data packet according to the second address information and the second source path information; The modifying of the destination IP address from the virtual IP address to the virtual machine IP address, and the modifying of the destination MAC address from the virtual MAC address to the virtual machine MAC address, comprises: When the validity verification result of the transit received data packet is a valid data packet, the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address.

7. The method according to claim 6, after verifying the validity of the transit received data packet, further comprising: In the case where the validity verification result of the transit received data packet is an invalid data packet, the transit received data packet is discarded.

8. The method according to claim 6, wherein: The second address information includes a second IP address and a second port address; The performing validity verification on the transit received data packet according to the second address information and the second source path information includes: Obtaining the standard source IP address, standard source port address, and second standard source path corresponding to the valid data packet; When the second IP address and the standard source IP address, the second port address and the standard source port address, and the second source path information and the second standard source path all successfully match, the validity verification result of the transit received data packet is determined to be a valid data packet.

9. A communication device for a virtual machine, comprising: A data packet acquisition module, used to acquire an original data packet to be sent by a target virtual machine to a target public network server; wherein the source address information of the original data packet includes a source IP address and a source MAC address, the virtual machine address information includes a virtual machine IP address and a virtual machine MAC address, and the network card address information includes a network card IP address and a network card MAC address; A source address information modification module, used to modify the source address information of the original sent data packet from the virtual machine address information of the target virtual machine to the network card address information of the physical network card, so as to obtain a modified sent data packet; The source address information modification module is further specifically used to modify the source IP address from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and to modify the source MAC address from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, so as to obtain a forwarded data packet; wherein the virtual IP address and the virtual MAC address are virtual addresses inside the computing node pre-assigned to the target virtual machine, and are used when performing layer 2 packet forwarding from the tunnel bridge to the physical network card in the computing node; Sending the forwarded data packet to the physical network card, so that the physical network card can modify the source IP address from the virtual IP address to the network card IP address, and modify the source MAC address from the virtual MAC address to the network card MAC address; A data packet transceiver module, used to send the modified send data packet to the target public network server through the physical network card, and receive the original receive data packet fed back by the target public network server through the physical network card; The destination address information modification module is used to modify the destination address information of the original received data packet from the network card address information to the virtual machine address information, obtain a modified received data packet, and send the modified received data packet to the target virtual machine.

10. The device according to claim 9, further comprising a sending mode determination module, specifically configured to: Acquire the destination address information of the original sent data packet as the first address information, and acquire the source path information of the original sent data packet as the first source path information; Determine, according to the first address information and the first source path information, a sending method adopted to send the original sending data packet to the target public network server; The source address information modification module is specifically used to: In the case where the sending mode is the source address conversion sending mode, the source address information of the original sent data packet is modified from the virtual machine address information of the target virtual machine to the network card address information of the physical network card.

11. The device according to claim 10, further comprising a conventional sending module, specifically configured to: In the case where the sending mode is a conventional sending mode, the original sending data packet is sent to a target network node, so as to forward the original sending data packet to the target public network server through the target network node.

12. The device according to claim 10, wherein: The first address information includes a first IP address and a first port address; The sending mode determination module is further specifically used for: Obtaining a standard destination IP address, a standard destination port address, and a first standard source path corresponding to the source address translation sending mode; When the first IP address and the standard destination IP address, the first port address and the standard destination port address, and the first source path information and the first standard source path all successfully match, the sending mode is determined to be the source address conversion sending mode.

13. The device according to claim 9, wherein: The source address information of the originally sent data packet includes a source IP address and a source MAC address, the virtual machine address information includes a virtual machine IP address and a virtual machine MAC address, and the network card address information includes a network card IP address and a network card MAC address; The source address information modification module is further specifically used for: The source IP address is modified from the virtual machine IP address to the virtual IP address corresponding to the target virtual machine, and the source MAC address is modified from the virtual machine MAC address to the virtual MAC address corresponding to the target virtual machine, to obtain a forwarding and sending data packet; The forwarded data packet is sent to the physical network card, so that the physical network card can modify the source IP address from the virtual IP address to the network card IP address, and modify the source MAC address from the virtual MAC address to the network card MAC address.

14. The device according to claim 13, wherein: The destination address information of the originally received data packet includes a destination IP address and a destination MAC address; The destination address information modification module is specifically used to: The destination IP address is modified from the network card IP address to the virtual IP address through the physical network card, and the destination MAC address is modified from the network card MAC address to the virtual MAC address, to obtain a transit received data packet; The transit received data packet is obtained, and the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address.

15. The device according to claim 14, further comprising a validity verification module, specifically configured to: Acquire the source address information of the forwarded received data packet as the second address information, and acquire the source path information of the forwarded received data packet as the second source path information; Verifying the validity of the transit received data packet according to the second address information and the second source path information; The destination address information modification module is further specifically used for: When the validity verification result of the transit received data packet is a valid data packet, the destination IP address is modified from the virtual IP address to the virtual machine IP address, and the destination MAC address is modified from the virtual MAC address to the virtual machine MAC address.

16. The device according to claim 15, further comprising a data packet discarding module, specifically configured to: In the case where the validity verification result of the transit received data packet is an invalid data packet, the transit received data packet is discarded.

17. The device according to claim 15, wherein: The second address information includes a second IP address and a second port address; The validity verification module is further specifically used for: Obtaining the standard source IP address, standard source port address, and second standard source path corresponding to the valid data packet; When the second IP address and the standard source IP address, the second port address and the standard source port address, and the second source path information and the second standard source path all successfully match, the validity verification result of the transit received data packet is determined to be a valid data packet.

18. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 8.

19. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-8.

20. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Network communication method and device

    CN107395781A

  • Data packet forwarding method and device

    CN111800340A