Data communication method, device, system and electronic device in SDWAN
By exchanging TTE information and using Keepalive probe messages in SDWAN networking, CPE and RR can obtain public IP addresses and port numbers in a dynamic NAT environment, solving the problem of not being able to establish tunnels under dynamic NAT and realizing data communication.
Patent Information
- Application Number
- CN202411217242.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-30
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-08-30
AI Technical Summary
In SDWAN networking, when NAT devices use dynamic NAT translation, CPE and RR cannot obtain public IP addresses and port numbers, resulting in the inability to establish SDWAN tunnels and achieve data communication.
The CPE and RR exchange TTE information through the established connection, use Keepalive probe messages for keep-alive detection, dynamically obtain public IP addresses and port numbers, and establish an SDWAN tunnel for data communication.
In a dynamic NAT environment, CPE and RR can obtain and verify public IP addresses and port numbers, establish SDWAN tunnels, and enable data communication.
Smart Images

Figure CN119182751B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a data communication method, device, system and electronic equipment in SDWAN. BACKGROUND
[0002] At present, in a software defined wide area network (SDWAN), a network address translation (NAT) device converts a private network IP address and a private network port number of a customer provided edge (CPE) or a route reflector (RR) in a static NAT manner when receiving the private network IP address and the private network port number of the CPE or the RR. The public network IP address and the public network port number obtained after the conversion in the static NAT manner are fixed. Therefore, the CPE and the RR can obtain the public network IP address and the public network port number of the private network IP address and the private network port number of the CPE and the RR after the conversion by the NAT device, and the public network IP address and the public network port number of the private network IP address and the private network port number of a peer after the conversion by the NAT device, so as to establish an SDWAN tunnel between the CPE and the RR and realize data communication between the CPE and the RR.
[0003] However, in actual networking, when the NAT device converts the private network IP address and the private network port number of the CPE in a more flexible dynamic NAT conversion manner, the public network IP address and the public network port number obtained after the conversion in the dynamic NAT manner are not fixed. At this time, the CPE and the RR cannot obtain the public network IP address and the public network port number of the private network IP address and the private network port number of the CPE obtained after the conversion in the dynamic NAT manner, so as to fail to establish the SDWAN tunnel between the CPE and the RR and fail to realize the data communication between the CPE and the RR. SUMMARY
[0004] Therefore, the present application provides a data communication method, device, system and electronic equipment in SDWAN, so as to realize the data communication between the CPE and the RR.
[0005] The technical scheme provided by the present application is as follows:
[0006] According to the embodiment of the first aspect of the present application, a data communication method in a software defined wide area network (SDWAN) is provided, the method is applied to a customer provided edge (CPE), and the method comprises the following steps:
[0007] sending first transmission tunnel endpoint (TTE) information to the RR through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation (NAT) indication information; the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner;
[0008] receiving second TTE information sent by the RR through the first connection; obtaining a public network IP address and a public network port number of the RR carried in the second TTE information; the public network IP address and the public network port number of the RR are obtained respectively after a private network IP address and a private network port number of the RR are processed by NAT;
[0009] sending a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR, so that the RR obtains a public network IP address and a public network port number of the CPE from the Keepalive probe packet and sends a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE; the Keepalive probe packet is a packet used for keep-alive detection of a TTE connection between the CPE and the RR;
[0010] receiving a Keepalive probe packet sent by the RR; establishing an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet and the obtained public network IP address and public network port number of the RR, so as to perform data communication with the RR through the SDWAN tunnel.
[0011] Optionally, the first connection is a secure sockets layer (SSL) connection.
[0012] Optionally, the Keepalive probe packet carries a data field.
[0013] The data field of the Keepalive probe packet sent by the RR carries the public network IP address and the public network port number of the CPE.
[0014] According to an embodiment of the second aspect of the present application, a data communication method in a software defined wide area network (SDWAN) is provided, which is applied to a route reflector (RR), and the method comprises:
[0015] receiving first transmission tunnel endpoint (TTE) information sent by a user edge device (CPE) through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation (NAT) indication information; the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner;
[0016] The second TTE information is sent to the CPE through the first connection, so that the CPE obtains the public network IP address and the public network port number of the RR carried by the second TTE information, and sends a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR; the public network IP address and the public network port number of the RR are obtained respectively by the private network IP address and the private network port number of the RR via NAT; the Keepalive probe packet is a packet used for keep-alive detection of the TTE connection between the CPE and the RR.
[0017] The Keepalive probe packet sent by the CPE is received; a Keepalive probe packet is sent to the CPE based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet, so that the CPE establishes an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet and the public network IP address and the public network port number of the RR obtained, and communicates data with the RR through the SDWAN tunnel.
[0018] Optionally, the first connection is a secure socket layer (SSL) connection.
[0019] Optionally, the Keepalive probe packet carries a data field.
[0020] The data field of the Keepalive probe packet sent by the RR carries the public network IP address and the public network port number of the CPE.
[0021] According to an embodiment of the third aspect of the present application, a data communication system in a software defined wide area network (SDWAN) is provided, and the system comprises:
[0022] A customer premises equipment (CPE) configured to perform the method of the first aspect.
[0023] A route reflector (RR) configured to perform the method of the second aspect.
[0024] According to an embodiment of the fourth aspect of the present application, a data communication device in a software defined wide area network (SDWAN) is provided, and the device is applied to a customer premises equipment (CPE), and the device comprises:
[0025] a sending unit, configured to send first transmission tunnel endpoint (TTE) information to a route reflector (RR) through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation (NAT) indication information; the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner;
[0026] a receiving unit, configured to receive second TTE information sent by the RR through the first connection; obtain a public network IP address and a public network port number of the RR carried in the second TTE information; the public network IP address and the public network port number of the RR are obtained respectively by performing NAT on a private network IP address and a private network port number of the RR;
[0027] a detecting unit, configured to send a Keepalive detection packet to the RR based on the public network IP address and the public network port number of the RR, so that the RR obtains a public network IP address and a public network port number of the CPE from the Keepalive detection packet and sends a Keepalive detection packet to the CPE based on the public network IP address and the public network port number of the CPE; the Keepalive detection packet is a packet used for keep-alive detection of a TTE connection between the CPE and the RR;
[0028] a communicating unit, configured to receive a Keepalive detection packet sent by the RR; establish an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive detection packet, the public network IP address and the public network port number of the RR obtained, and perform data communication with the RR through the SDWAN tunnel.
[0029] According to an embodiment of the fifth aspect of the present application, a data communication device in a software defined wide area network (SDWAN) is provided, which is applied to a route reflector (RR), and the device comprises:
[0030] a receiving unit, configured to receive first transmission tunnel endpoint (TTE) information sent by a user edge device (CPE) through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation (NAT) indication information; the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner;
[0031] The sending unit is configured to send second TTE information to the CPE through the first connection, so that the CPE obtains the public network IP address and the public network port number of the RR carried by the second TTE information and sends a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR; the public network IP address and the public network port number of the RR are obtained from the private network IP address and the private network port number of the RR via NAT respectively; the Keepalive probe packet is a packet used for keep-alive detection of the TTE connection between the CPE and the RR.
[0032] The communication unit is configured to receive the Keepalive probe packet sent by the CPE; send a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet, so that the CPE establishes an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet and the public network IP address and the public network port number of the RR obtained, and performs data communication with the RR through the SDWAN tunnel.
[0033] According to the sixth aspect of the present application, an electronic device is provided, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method of the first aspect or the second aspect when executing the program.
[0034] As can be seen from the above technical solutions, in the case that the private network IP address and the private network port number of the CPE in the SDWAN network are processed in a dynamic NAT manner, the CPE obtains the public network IP address and the public network port number of the RR through the TTE information sent by the RR, and sends a Keepalive probe packet to the RR, so that the RR obtains the public network IP address and the public network port number of the CPE from the received Keepalive probe packet and sends a Keepalive probe packet to the CPE, and the CPE obtains the public network IP address and the public network port number of the CPE from the received Keepalive probe packet, so that the CPE and the RR both obtain the public network IP address and the public network port number of the peer, and establish an SDWAN tunnel between the CPE and the RR according to the public network IP address and the public network port number of the peer, thereby realizing data communication between the CPE and the RR. BRIEF DESCRIPTION OF DRAWINGS
[0035] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0036] Figure 1 A SDWAN networking schematic diagram provided for an embodiment of the present application;
[0037] Figure 2 A flow chart of a data communication method in a software defined wide area network (SDWAN) provided for an embodiment of the present application;
[0038] Figure 3 Another SDWAN networking schematic diagram provided for an embodiment of the present application;
[0039] Figure 4 An interaction diagram of CPE and RR establishing an SDWAN tunnel provided for an embodiment of the present application;
[0040] Figure 5 A Keepalive probe message structure schematic diagram provided for an embodiment of the present application;
[0041] Figure 6 Another flow chart of a data communication method in a software defined wide area network (SDWAN) provided for an embodiment of the present application;
[0042] Figure 7 A software defined wide area network (SDWAN) data communication system structure schematic diagram provided for an embodiment of the present application;
[0043] Figure 8 A structure schematic diagram of an electronic device provided for an embodiment of the present application;
[0044] Figure 9 A structure diagram of a data communication apparatus in a software defined wide area network (SDWAN) provided for an embodiment of the present application;
[0045] Figure 10 Another structure diagram of a data communication apparatus in a software defined wide area network (SDWAN) provided for an embodiment of the present application. DETAILED DESCRIPTION
[0046] In order to make the technical solution provided by the embodiments of the present application better understood by those skilled in the art, and make the above-mentioned purposes, features and advantages of the embodiments of the present application more apparent and easy to understand, the technical solutions in the embodiments of the present application are further described in detail below with reference to the drawings.
[0047] In a software defined wide area network (SDWAN), in order to save IP address resources, a network edge (CPE: Customer Provided Edge) provided by a user, referred to as a user edge device, and a route reflector (RR: Route Reflector) usually use private network IP addresses and private network port numbers, and when data communication is needed, the private network IP addresses and private network port numbers of the CPE and the RR are converted into public network IP addresses and public network port numbers by a network address translation (NAT: Network Address Translation) device. Since the IP addresses and port numbers of the messages sent by the CPE and the RR change after passing through the NAT device, in the process of establishing an SDWAN tunnel between the CPE and the RR for data communication, the CPE and the RR need to obtain the public network IP addresses and public network port numbers after the private network IP addresses and private network port numbers of the CPE and the RR are converted by the NAT device, and the public network IP addresses and public network port numbers after the private network IP addresses and private network port numbers of the opposite end are converted by the NAT device.
[0048] Currently, in an SDWAN network, when the NAT device receives the private network IP addresses and private network port numbers of the CPE or the RR, the NAT device can convert the private network IP addresses and private network port numbers of the CPE or the RR in a static NAT manner. The public network IP addresses and public network port numbers obtained after the conversion in the static NAT manner are fixed, so the CPE and the RR can obtain the public network IP addresses and public network port numbers after the private network IP addresses and private network port numbers of the CPE and the RR are converted by the NAT device, and the public network IP addresses and public network port numbers after the private network IP addresses and private network port numbers of the opposite end are converted by the NAT device, to establish an SDWAN tunnel between the CPE and the RR and realize data communication between the CPE and the RR.
[0049] Please refer to Figure 1 , Figure 1 A SDWAN networking schematic diagram provided for embodiments of the present application.
[0050] As Figure 1 shown, if an SDWAN tunnel is established between CPE1 and RR, CPE1 and RR need to obtain the public network IP addresses and public network port numbers after the private network IP addresses and private network port numbers of CPE1 are converted by NAT device 1, and the public network IP addresses and public network port numbers after the private network IP addresses and private network port numbers of RR are converted by NAT device 2.
[0051] Obviously, if the NAT device 1 and the NAT device 2 both adopt the static NAT conversion mode, the IP address and the port number converted by the static NAT mode are fixed and known, and at this time, the source IP address and the port number and the public network IP address and the public network port number after NAT conversion can be manually configured on the CPE 1 and the RR.
[0052] However, in the case where the NAT device adopts a more flexible dynamic NAT conversion mode to convert the private network IP address and the private network port number of the CPE, the public network IP address and the public network port number obtained by the dynamic NAT conversion mode are not fixed. Still taking the SDWAN network shown in Figure 1 If the SDWAN tunnel is established between the CPE 1 and the RR, the NAT device 1 adopts the dynamic NAT conversion mode, and the NAT device 2 adopts the static NAT conversion mode, at this time, the CPE 1 and the RR can still obtain the public network IP address and the public network port number converted by the private network IP address and the private network port number of the RR through the NAT device 2, but since the public network IP address and the public network port number obtained by the dynamic NAT conversion mode are not fixed, at this time, the CPE 1 and the RR cannot directly obtain the public network IP address and the public network port number converted by the private network IP address and the private network port number of the CPE 1 through the NAT device 1, so as to establish the SDWAN tunnel between the CPE and the RR to realize the data communication between the CPE and the RR.
[0053] Based on this, the present application provides a data communication method in a software defined wide area network (SDWAN) to establish an SDWAN tunnel between a CPE and a RR and realize communication between the CPE and the RR in the case where a NAT device adopts a dynamic NAT conversion mode to convert a private network IP address and a private network port number of the CPE.
[0054] Please refer to Figure 2 , Figure 2 A flow chart of a data communication method in a software defined wide area network (SDWAN) provided by an embodiment of the present application.
[0055] In the embodiment, the method can be applied to a user edge device (CPE) in an SDWAN network. The user edge device (CPE) can be a physical device specially designed for the SDWAN, which is used to provide traffic optimization, path selection, encryption and the like, and the present application does not limit this.
[0056] As shown in Figure 2 The method can include the following steps:
[0057] In step 201, first transport tunnel endpoint (TTE) information is sent to the RR through a first connection established between the CPE and the RR.
[0058] In this embodiment, the CPE and the RR that need to establish the SDWAN tunnel can be configured in advance based on a control plane protocol, so that the CPE and the RR know the opposite device that establishes the SDWAN tunnel.
[0059] As an example, the control plane protocol can be a border gateway protocol (BGP), an open shortest path first (OSPF) protocol, etc., and the present application does not limit this.
[0060] In the case where the CPE and the RR know the opposite device that needs to establish the SDWAN tunnel between the CPE and the RR, the TTE information can be exchanged based on the first connection established between the CPE and the RR.
[0061] As an example, the first connection can be a secure sockets layer (SSL) connection, and the present application does not limit this.
[0062] In this embodiment, the TTE information can carry information such as a NAT conversion type, a private network IP address of the device, and a public network IP address and a public network port number obtained by performing NAT conversion on the private network port number of the device.
[0063] In this embodiment, the NAT conversion type carried in the first TTE information sent by the CPE to the RR is a dynamic NAT type, that is, the first TTE information carries dynamic network address translation (NAT) indication information, which is used to indicate that the private network IP address and the private network port number of the CPE are processed in a dynamic NAT manner.
[0064] It should be noted that since the public network IP address and the public network port number obtained by processing the private network IP address and the private network port number of the CPE in a dynamic NAT manner are not fixed, the CPE does not know the public network IP address and the public network port number obtained by processing the private network IP address and the private network port number of the CPE in a dynamic NAT manner when sending the first TTE information, and the first TTE information does not carry the public network IP address and the public network port number obtained by processing the private network IP address and the private network port number of the CPE in a dynamic NAT manner.
[0065] As to the information carried in the second TTE information sent by the RR to the CPE, it will be described in detail in step 202 below, and thus will not be described here again.
[0066] In step 202, the second TTE information sent by the RR is received through the first connection; and the public network IP address and the public network port number of the RR carried in the second TTE information are obtained.
[0067] In the embodiment, the NAT conversion type carried in the second TTE information sent by the RR is static NAT type. Since the public network IP address and the public network port number obtained after the private network IP address and the private network port number of the RR are converted in the static NAT mode are fixed, the second TTE information sent by the RR to the CPE carries the public network IP address and the public network port number obtained after the private network IP address and the private network port number of the RR are converted in the static NAT mode.
[0068] After receiving the second TTE information sent by the RR, the CPE can obtain the public network IP address and the public network port number of the RR from the second TTE information.
[0069] It should be noted that, Figure 2 The flowchart in the above step 201 and step 202 does not have a fixed time sequence, i.e., there is no fixed sequence between the two steps of sending the first TTE information by the CPE to the RR and sending the second TTE information by the RR to the CPE (the CPE receiving the second TTE information sent by the RR). In order to facilitate the description, the step of sending the first TTE information by the CPE is recorded as step 201, and the step of receiving the second TTE information sent by the RR by the CPE is recorded as step 202.
[0070] The step 203 will be described below.
[0071] In step 203, a Keepalive probe packet is sent to the RR based on the public network IP address and the public network port number of the RR, so that the RR obtains the public network IP address and the public network port number of the CPE from the Keepalive probe packet and sends a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE.
[0072] In the embodiment, after obtaining the public network IP address and the public network port number of the RR, the CPE can send a Keepalive probe packet to the RR. The Keepalive probe packet carries the source IP address and the source port number (i.e., the private network IP address and the private network port number of the CPE) of the packet, and the destination IP address and the destination port number (i.e., the public network IP address and the public network port number of the RR) of the packet.
[0073] In the embodiment, the Keepalive probe message is a message used for keep-alive detection of the TTE connection between the CPE and the RR. The Keepalive message is used to help the CPE and the RR confirm whether the connection is valid. Even if the CPE does not have complete TTE information (does not have the public network IP address and the public network port number of the CPE) at this time, as long as the CPE can communicate, the Keepalive message can be used to maintain the connection state. That is, the sending of the Keepalive message only needs the correct network target (the public network IP address and the public network port number of the RR).
[0074] In the process of forwarding the Keepalive probe message sent by the CPE to the RR, the source IP address and the source port number are converted by the NAT device into the public network IP address and the public network port number of the CPE by dynamic NAT, and the destination IP address and the destination port number are converted by the NAT device into the private network IP address and the private network port number of the RR by static NAT.
[0075] After receiving the Keepalive probe message sent by the CPE, the RR can obtain the public network IP address and the public network port number of the CPE from the source IP address and the source port number of the Keepalive probe message.
[0076] As an embodiment, since the public network IP address and the public network port number of the CPE are not included in the first TTE information sent by the CPE to the RR in step 201, after the RR first obtains the public network IP address and the public network port number of the CPE from the Keepalive probe message, the first TTE information can be updated so as to contain the public network IP address and the public network port number of the CPE. If the RR does not first obtain the public network IP address and the public network port number of the CPE from the Keepalive probe message, the public network IP address and the public network port number of the CPE currently obtained can be compared with the public network IP address and the public network port number of the CPE contained in the first TTE information. If they are different, it indicates that the public network IP address and the public network port number of the CPE may have changed, and the first TTE information can be updated at this time.
[0077] Since the RR also obtains the public network IP address and the public network port number of the CPE at this time, the RR can also send a Keepalive probe message to the CPE. The Keepalive probe message carries the source IP address and the source port number (i.e., the private network IP address and the private network port number of the RR) of the message, and the destination IP address and the destination port number (i.e., the public network IP address and the public network port number of the CPE) of the message.
[0078] In the forwarding process of the Keepalive probe message sent by the RR to the CPE, the source IP address and the source port number are converted by the NAT device into the public network IP address and the public network port number of the RR through static NAT, and the destination IP address and the destination port number are converted by the NAT device into the private network IP address and the private network port number of the CPE through dynamic NAT.
[0079] The specific forwarding process of the Keepalive probe message and the conversion process of the source IP address, the source port number, the destination IP address and the destination port number carried by the Keepalive probe message will be described in detail in the specific embodiments below, and will not be described here again.
[0080] Thus far, the description of step 203 is ended, and step 204 is executed.
[0081] In step 204, the Keepalive probe message sent by the RR is received, and based on the public network IP address and the public network port number of the CPE carried by the Keepalive probe message and the public network IP address and the public network port number of the RR obtained, an SDWAN tunnel is established with the RR to communicate data with the RR through the SDWAN tunnel.
[0082] As an embodiment, the Keepalive probe message carries a data field, and the data field of the Keepalive probe message sent by the RR carries the public network IP address and the public network port number of the CPE.
[0083] The specific structure of the Keepalive probe message will be described in detail in the specific embodiments below, and will not be described here again.
[0084] In this embodiment, after the CPE receives the Keepalive probe message sent by the RR in step 103, since the public network IP address and the public network port number of the CPE carried in the destination IP address and the destination port number of the Keepalive probe message have been converted by the NAT device into the private network IP address and the private network port number of the CPE through dynamic NAT, the public network IP address and the public network port number of the CPE cannot be obtained from the destination IP address and the destination port number of the Keepalive probe message, so the Keepalive probe message sent by the RR also carries the public network IP address and the public network port number of the CPE in its data field, and the CPE can obtain the public network IP address and the public network port number of the CPE from the data field of the received Keepalive probe message.
[0085] After the CPE obtains its public IP address and public port number, the TTE information of the CPE and the RR are complete, that is, the CPE and the RR obtain their own and the public IP address and the public port number of the opposite end, at this time, the RR and the CPE can verify the TTE information through the SSL connection.
[0086] As an embodiment, the verification of the TTE information can determine whether the CPE and the RR are in the same routing domain according to the TTE information stored at the two ends of the CPE and the RR, and if they are in the same routing domain, it is determined that the verification of the TTE information is successful.
[0087] Among them, the specific steps of determining whether the CPE and the RR are in the same routing domain according to the TTE information stored at the two ends of the CPE and the RR are common methods in related technologies, which will not be described here.
[0088] After the TTE information verification is successful, the TTE connection is established, and the SDWAN tunnel between the CPE and the RR is naturally established, and the CPE and the RR can communicate data through the SDWAN tunnel.
[0089] It should be noted that the Keepalive probe packet is periodically sent, and the public IP address and the public port number of the CPE are carried in the data field of each Keepalive probe packet sent by the RR. Since the TTE information has an aging time, the public IP address and the public port number of the CPE carried in the Keepalive probe packet can refresh the aging time, avoiding the disconnection of the TTE connection after the information is aged.
[0090] Thus, the description of the data communication method in the software defined wide area network SDWAN in Figure 2 is ended.
[0091] In the case that the private IP address and the private port number of the CPE in the SDWAN network are processed in the dynamic NAT mode, the CPE obtains the public IP address and the public port number of the RR through the TTE information sent by the RR, and sends the Keepalive probe packet to the RR, so that the RR obtains the public IP address and the public port number of the CPE from the received Keepalive probe packet and sends the Keepalive probe packet to the CPE, and the CPE obtains the public IP address and the public port number of the CPE from the received Keepalive probe packet, so that the CPE and the RR obtain their own and the public IP address and the public port number of the opposite end, and establish the SDWAN tunnel between the CPE and the RR according to their own and the public IP address and the public port number of the opposite end, realizing the data communication between the CPE and the RR.
[0092] The following will be described in combination withFigures 3 to 5 The data communication method in a software-defined wide area network (SDWAN) is introduced through an embodiment.
[0093] Embodiment 1
[0094] Please refer to Figure 3 , Figure 3 Another SDWAN networking diagram provided by the embodiment of the present application.
[0095] As Figure 3 shown, in the SDWAN network, the NAT device 1 adopts a dynamic NAT conversion mode, the NAT device 2 and the NAT device 3 adopt a static NAT conversion mode, and the device P is an intermediate device such as an SDWAN gateway, which is used to optimize the incoming and outgoing traffic and to load balance among multiple links to improve network efficiency and stability, etc.
[0096] Suppose that the CPE1 and the RR need to establish an SDWAN tunnel for data communication, and in the case that an SSL connection has been established between the CPE1 and the RR, the information interaction process between the CPE1 and the RR is as shown in Figure 4 .
[0097] Please refer to Figure 4 , Figure 4 The interaction diagram for the CPE and the RR to establish an SDWAN tunnel provided by the embodiment of the present application.
[0098] As Figure 4 shown, the CPE1 sends first TTE information to the RR through the established SSL connection, and the first TTE information carries dynamic network address translation (NAT) indication information, which is used to indicate that the private IP address and the private port number of the CPE are processed in a dynamic NAT mode. Since the IP address and the port number processed in the dynamic NAT mode are not fixed, the public IP address and the public port number of the CPE are not carried in the first TTE information.
[0099] The RR also sends second TTE information to the CPE1 through the established SSL connection, and the NAT conversion type carried by the second TTE information is a static NAT type. Since the IP address and the port number obtained after conversion in the static NAT mode are fixed, the second TTE information sent by the RR to the CPE1 carries the public IP address and the public port number of the RR.
[0100] It should be noted that there is no fixed sequence between the two steps of the CPE1 sending the first TTE information to the RR through the established SSL connection and the RR sending the second TTE information to the CPE1 through the established SSL connection, Figure 4The order shown in FIG. 1 is only an exemplary execution order for ease of description.
[0101] After the CPE 1 receives the second TTE information sent by the RR, the CPE 1 obtains the public network IP address and the public network port number of the RR from the second TTE information, and sends a Keepalive probe packet to the RR according to the public network IP address and the public network port number of the RR.
[0102] The following will be described in combination with Figure 5 The Keepalive probe packet is briefly described.
[0103] Please refer to Figure 5 , Figure 5 The Keepalive probe packet structure diagram provided by the embodiment of the present application is shown.
[0104] As shown in FIG. 4, the Keepalive probe packet includes an outer IP header, an outer UDP header, an SDWAN header, and a data field. Figure 5 The outer IP header is used to carry the IP address of the Keepalive probe packet, and specifically can carry the source IP address and the destination IP address.
[0105] The outer UDP header is used to carry the port number of the Keepalive probe packet, and specifically can carry the source port number and the destination port number.
[0106] The SDWAN header is used to provide network state monitoring and connection management functions; the SDWAN header includes a Local TTE ID field and a Remote TTE ID field, the Local TTE ID field is used to identify the source device sending the Keepalive probe packet, and the Remote TTE ID field is used to identify the destination device of the Keepalive probe packet.
[0107] The data field is used to carry the state information of the Keepalive probe packet, such as the timestamp, the sequence number, etc. In the embodiment, the data field of the Keepalive probe packet sent by the RR to the CPE 1 also carries the public network IP address and the public network port number of the CPE.
[0108] In addition, the Keepalive probe packet can also include an IPsec header and an IPsec tail, which are used to provide encryption and authentication services for the data packet, to ensure the security and integrity of the Keepalive packet.
[0109] Thus far, the description of the Keepalive probe packet structure diagram in
[0110] is ended. Figure 5 Thus far, the description of the Keepalive probe packet structure diagram in
[0110] is ended.
[0111] In the embodiment, the source IP address carried in the outer IP header of the Keepalive probe message sent by the CPE1 to the RR is the private network IP address of the CPE1, and the destination IP address is the public network IP address of the RR; the source port number carried in the outer UDP header is the private network port number of the CPE1, and the destination port number is the public network port number of the RR; the Local TTE ID field in the SDWAN header carries the identifier of the CPE1, and the Remote TTE ID field carries the identifier of the RR;
[0112] The forwarding process of the Keepalive probe message sent by the CPE1 to the RR is as follows:
[0113] The CPE1 sends the Keepalive probe message to the NAT device 1.
[0114] After receiving the Keepalive probe message sent by the CPE1, the NAT device 1 converts the source IP address carried in the outer IP header of the Keepalive probe message, i.e. the private network IP address of the CPE1, into the public network IP address of the CPE1 by dynamic NAT conversion, and converts the source port number carried in the outer UDP header of the Keepalive probe message, i.e. the private network port number of the CPE1, into the public network port number of the CPE1 by dynamic NAT conversion; after the conversion is completed, the Keepalive probe message is forwarded to the intermediate device P.
[0115] After receiving the Keepalive probe message forwarded by the NAT device 1, the intermediate device P forwards the Keepalive probe message to the NAT device 2.
[0116] After receiving the Keepalive probe message forwarded by the intermediate device P, the NAT device 2 converts the destination IP address carried in the outer IP header of the Keepalive probe message, i.e. the public network IP address of the RR, into the private network IP address of the RR by static NAT conversion, and converts the destination port number carried in the outer UDP header of the Keepalive probe message, i.e. the public network port number of the RR, into the private network port number of the RR by static NAT conversion; after the conversion is completed, the Keepalive probe message is forwarded to the RR.
[0117] Thus, the forwarding process of the Keepalive probe message sent by the CPE1 to the RR is ended.
[0118] RR receives the Keepalive probe packet sent by CPE1, and obtains the public IP address and public port number of CPE1 from the source IP address and source port number in the Keepalive probe packet in the case that the Remote TTE ID field in the SDWAN header is matched successfully, and updates the public IP address and public port number of CPE1 to the first TTE information;
[0119] RR sends a Keepalive probe packet to CPE1 according to the public IP address and public port number of CPE1. The source IP address carried in the outer IP header of the Keepalive probe packet is the private IP address of RR, and the destination IP address is the public IP address of CPE1. The source port number carried in the outer UDP header is the private port number of RR, and the destination port number is the public port number of CPE1. The Local TTE ID field in the SDWAN header carries the identifier of RR, and the Remote TTE ID field carries the identifier of CPE1. Different from the Keepalive probe packet sent by CPE1 to RR, the Keepalive probe packet sent by RR to CPE1 also carries the public IP address and public port number of CPE1 in the data field.
[0120] The forwarding process of the Keepalive probe packet sent by RR to CPE1 is as follows:
[0121] RR sends the Keepalive probe packet to NAT device 2;
[0122] After receiving the Keepalive probe packet sent by RR, NAT device 2 converts the source IP address carried in the outer IP header of the Keepalive probe packet, i.e. the private IP address of RR, into the public IP address of RR by static NAT conversion, and converts the source port number carried in the outer UDP header of the Keepalive probe packet, i.e. the private port number of RR, into the public port number of RR by static NAT conversion, and then forwards the Keepalive probe packet to intermediate device P;
[0123] After receiving the Keepalive probe packet forwarded by NAT device 2, intermediate device P forwards the Keepalive probe packet to NAT device 1;
[0124] The NAT device 1 converts the public network IP address of the CPE 1 carried in the outer IP header of the Keepalive probe packet into the private network IP address of the CPE 1 by dynamic NAT conversion after receiving the Keepalive probe packet forwarded by the intermediate device P, and converts the destination port number carried in the outer UDP header of the Keepalive probe packet, i.e., the public network port number of the CPE 1, into the private network port number of the CPE 1 by dynamic NAT conversion, and forwards the Keepalive probe packet to the CPE 1 after the conversion is completed.
[0125] Thus, the forwarding process of the Keepalive probe packet sent by the RR to the CPE 1 is ended.
[0126] The CPE 1 obtains the public network IP address and the public network port number of the CPE 1 from the data field of the Keepalive probe packet in the case that the Remote TTE ID field in the SDWAN header is successfully compared after receiving the Keepalive probe packet sent by the RR.
[0127] At this time, the CPE 1 and the RR both obtain the public network IP address and the public network port number of the CPE 1 and the RR, i.e., obtain the complete TTE information, further verify the TTE information of the two ends, and the verification is successful in the case that the CPE and the RR are determined to be in the same routing domain, at this time, the TTE connection is established, and the SDWAN tunnel between the CPE 1 and the RR is also established.
[0128] Thus, the description of the embodiment 1 is ended.
[0129] Please refer to Figure 6 , Figure 6 Another flowchart of a data communication method in a software defined wide area network (SDWAN) provided by the embodiment is provided, and the method is applied to a route reflector (RR).
[0130] As shown in Figure 6 , the method comprises the following steps:
[0131] In step 601, the first transmission tunnel endpoint (TTE) information sent by the user edge device (CPE) is received through the first connection established between the CPE and the RR.
[0132] In the embodiment, the first connection can be an SSL connection, and the NAT conversion type carried in the first TTE information is dynamic NAT type, i.e., the dynamic network address translation (NAT) indication information is carried in the first TTE information, which is used to indicate that the private network IP address and the private network port number of the CPE are processed in the dynamic NAT manner.
[0133] Step 602, sending second TTE information to the CPE through the first connection, so that the CPE obtains the public network IP address and public network port number of the RR carried by the second TTE information and sends a Keepalive probe packet to the RR based on the public network IP address and public network port number of the RR.
[0134] Wherein, the public network IP address and public network port number of the RR are respectively obtained by the private network IP address and private network port number of the RR via NAT; the Keepalive probe packet is a packet used for keep-alive detection of the TTE connection between the CPE and the RR.
[0135] In this embodiment, similarly, there is no fixed time sequence order between the steps of the CPE sending the first TTE information to the RR (the RR receiving the first TTE information sent by the CPE) and the RR sending the second TTE information to the CPE, which will not be described here.
[0136] Step 603, receiving the Keepalive probe packet sent by the CPE; sending a Keepalive probe packet to the CPE based on the public network IP address and public network port number of the CPE carried in the Keepalive probe packet, so that the CPE establishes an SDWAN tunnel with the RR based on the public network IP address and public network port number of the CPE carried in the Keepalive probe packet and the public network IP address and public network port number of the RR obtained, and communicates data with the RR through the SDWAN tunnel.
[0137] It is easy to understand that, Figure 2 The flowchart shown is described with the user edge device CPE as the execution subject, Figure 6 The flowchart shown is described with the route reflector RR as the execution subject, and the specific interaction process and packet forwarding process between the CPE and the RR have been described in detail above, which will not be described here.
[0138] Thus far, the description of Figure 6 is ended.
[0139] Please refer to Figure 7 , Figure 7 A software defined wide area network (SDWAN) data communication system structure schematic diagram provided by the embodiment.
[0140] As shown in Figure 7 , the system comprises:
[0141] A user edge device CPE, configured to execute the method shown in Figure 2 the flowchart;
[0142] a route reflector RR configured to perform the method as shown in the flowchart. Figure 6 a route reflector RR configured to perform the method as shown in the flowchart.
[0143] The specific interaction process between the CPE and the RR and the message forwarding process have been described in detail above, and will not be described here.
[0144] Thus, the description of the Figure 7 is ended.
[0145] Please refer to Figure 8 , Figure 8 is a schematic structural diagram of an electronic device according to an embodiment of the present application. At the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course can also include other hardware required by the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs, and forms a terminal interactive device at the logical level. Of course, in addition to the software implementation, the present application does not exclude other implementation manners, such as logic devices or a combination of software and hardware, and so on, that is, the execution subject of the following processing flow is not limited to each logical unit, but can also be hardware or a logic device.
[0146] Please refer to Figure 9 , Figure 9 is a data communication device structure diagram in a software-defined wide area network (SDWAN) according to an embodiment of the present application, and Figure 2 provides a data communication method flowchart in a software-defined wide area network (SDWAN) applied to a customer edge device (CPE), and the device is applied to the customer edge device (CPE). As shown in Figure 9 , the data communication device in the software-defined wide area network (SDWAN) can include a sending unit 901, a receiving unit 902, a detection unit 903, and a communication unit 904. Specifically, the device includes:
[0147] The sending unit 901 is configured to send first transport tunnel endpoint (TTE) information to the route reflector (RR) through a first connection established between the CPE and the RR. The first TTE information carries dynamic network address translation (NAT) indication information. The dynamic NAT indication information is used to indicate that the private IP address and the private port number of the CPE are processed in a dynamic NAT manner.
[0148] The receiving unit 902 is configured to receive second TTE information sent by the RR through the first connection. The second TTE information carries the public IP address and the public port number of the RR. The public IP address and the public port number of the RR are obtained by performing NAT on the private IP address and the private port number of the RR, respectively.
[0149] The detection unit 903 is configured to send a Keepalive detection packet to the RR based on the public IP address and the public port number of the RR, so that the RR obtains the public IP address and the public port number of the CPE from the Keepalive detection packet and sends a Keepalive detection packet to the CPE based on the public IP address and the public port number of the CPE; the Keepalive detection packet is a packet used for keep-alive detection of the TTE connection between the CPE and the RR.
[0150] The communication unit 904 is configured to receive the Keepalive detection packet sent by the RR; and establish an SDWAN tunnel with the RR based on the public IP address and the public port number of the CPE carried in the Keepalive detection packet, the public IP address and the public port number of the RR obtained, and the first connection, so as to perform data communication with the RR through the SDWAN tunnel.
[0151] Optionally, the first connection is a secure sockets layer (SSL) connection.
[0152] Optionally, the Keepalive detection packet carries a data field.
[0153] The data field of the Keepalive detection packet sent by the RR carries the public IP address and the public port number of the CPE.
[0154] So far, the description of the data communication device in the software defined wide area network (SDWAN) is completed. Figure 9
[0155] Please refer to Figure 10 , Figure 10 is a software defined wide area network (SDWAN) data communication device structure diagram provided by the embodiment of the present application, and corresponds to the software defined wide area network (SDWAN) data communication method flowchart provided by the embodiment of the present application. Figure 6 The device is applied to a route reflector (RR). As shown in Figure 10 , the software defined wide area network (SDWAN) data communication device can include a receiving unit 1001, a sending unit 1002, and a communication unit 1003. Specifically, the device includes:
[0156] The receiving unit 1001 is configured to receive first transport tunnel endpoint (TTE) information sent by a customer edge (CPE) through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation (NAT) indication information; and the dynamic NAT indication information is used to indicate that the private IP address and the private port number of the CPE are processed in a dynamic NAT manner.
[0157] The sending unit 1002 is configured to send second TTE information to the CPE through the first connection, so that the CPE obtains the public network IP address and the public network port number of the RR carried by the second TTE information and sends a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR; the public network IP address and the public network port number of the RR are obtained respectively from the private network IP address and the private network port number of the RR via NAT; the Keepalive probe packet is a packet used for keep-alive detection of the TTE connection between the CPE and the RR.
[0158] The communication unit 1003 is configured to receive the Keepalive probe packet sent by the CPE; send a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet, so that the CPE establishes an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet and the public network IP address and the public network port number of the RR obtained, and performs data communication with the RR through the SDWAN tunnel.
[0159] Optionally, the first connection is a secure sockets layer (SSL) connection.
[0160] Optionally, the Keepalive probe packet carries a data field.
[0161] The data field of the Keepalive probe packet sent by the RR carries the public network IP address and the public network port number of the CPE.
[0162] So far, the description of the data communication device in the software defined wide area network (SDWAN) is completed. Figure 10
[0163] Correspondingly, in the embodiment, the application also provides a computer readable storage medium, and the computer readable storage medium stores a plurality of computer instructions, and the computer instructions are executed to implement the method disclosed in the above examples.
[0164] Exemplarily, the computer readable storage medium described above can be any electronic, magnetic, optical, or other physical storage apparatus, and can contain or store information such as executable instructions, data, and the like. For example, the computer readable storage medium can be a RAM (Random Access Memory), a volatile memory, a non-volatile memory, a flash memory, a storage drive (such as a hard drive), a solid state drive, any type of storage disk (such as an optical disk, a DVD, and the like), or similar storage medium, or a combination thereof.
[0165] The preferred embodiments of the present application have been described above with the aid of a number of drawings. These embodiments are illustrative only, and there can be other embodiments which do not depart from the spirit and essence of the application. It should be understood that various modifications and changes can be aimed at generalizing the concepts of the application and can be executed by those skilled in the art. Any modification, equivalent replacement, improvement, and the like within the spirit and principle of the present application shall be included in the scope of the present application.
Claims
1. A data communication method in a Software-Defined Wide Area Network (SDWAN), characterized in that, The method is applied to a customer edge device CPE, and the method comprises: sending first transmission tunnel endpoint TTE information to a route reflector RR through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation NAT indication information; the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner; receiving second TTE information sent by the RR through the first connection; obtaining a public network IP address and a public network port number of the RR carried by the second TTE information; the public network IP address and the public network port number of the RR are obtained respectively after a private network IP address and a private network port number of the RR are processed by NAT; sending a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR, so that the RR obtains a public network IP address and a public network port number of the CPE from the Keepalive probe packet and sends a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE; the Keepalive probe packet is a packet used for keep-alive detection of a TTE connection between the CPE and the RR; receiving a Keepalive probe packet sent by the RR; establishing an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried by the Keepalive probe packet and the obtained public network IP address and public network port number of the RR, so as to perform data communication with the RR through the SDWAN tunnel.
2. The method of claim 1, wherein, The first connection is a secure sockets layer SSL connection.
3. The method of claim 1, wherein, The Keepalive probe packet carries a data field; The data field of the Keepalive probe packet sent by the RR carries the public network IP address and the public network port number of the CPE. 4.A method of data communication in a software-defined wide area network (SDWAN), comprising: The method is applied to a route reflector RR, and the method comprises: receiving first transmission tunnel endpoint TTE information sent by a customer edge device CPE through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation NAT indication information; the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner; sending second TTE information to the CPE through the first connection, so that the CPE obtains a public network IP address and a public network port number of the RR carried by the second TTE information and sends a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR; the public network IP address and the public network port number of the RR are obtained respectively after a private network IP address and a private network port number of the RR are processed by NAT; the Keepalive probe packet is a packet used for keep-alive detection of a TTE connection between the CPE and the RR; receive the Keepalive probe packet sent by the CPE; send a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet, so that the CPE establishes an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet and the public network IP address and the public network port number of the RR obtained, and communicates data with the RR through the SDWAN tunnel.
5. The method of claim 4, wherein, The first connection is a secure socket layer (SSL) connection.
6. The method of claim 4, wherein, The Keepalive probe packet carries a data field. The data field of the Keepalive probe packet sent by the RR carries the public network IP address and the public network port number of the CPE.
7. A data communication system in a software-defined wide area network (SD-WAN), characterized by The system comprises: a customer edge device (CPE) configured to perform the method according to any one of claims 1 to 3; and a route reflector (RR) configured to perform the method according to any one of claims 4 to 6.
8. A data communication apparatus in a software-defined wide area network (SDWAN), comprising: The device is applied to a customer edge device (CPE), and the device comprises: a sending unit configured to send first transport tunnel endpoint (TTE) information to a route reflector (RR) through a first connection established between the CPE and the RR, wherein the first TTE information carries dynamic network address translation (NAT) indication information, and the dynamic NAT indication information is used to indicate that a private network IP address and a private network port number of the CPE are processed in a dynamic NAT manner; a receiving unit configured to receive second TTE information sent by the RR through the first connection, and obtain a public network IP address and a public network port number of the RR carried in the second TTE information, wherein the public network IP address and the public network port number of the RR are obtained by performing NAT on a private network IP address and a private network port number of the RR, respectively; a probing unit configured to send a Keepalive probe packet to the RR based on the public network IP address and the public network port number of the RR, so that the RR obtains a public network IP address and a public network port number of the CPE from the Keepalive probe packet and sends a Keepalive probe packet to the CPE based on the public network IP address and the public network port number of the CPE, wherein the Keepalive probe packet is a packet used for keep-alive detection of a TTE connection between the CPE and the RR; a communication unit configured to receive the Keepalive probe packet sent by the RR, and establish an SDWAN tunnel with the RR based on the public network IP address and the public network port number of the CPE carried in the Keepalive probe packet and the public network IP address and the public network port number of the RR obtained, so as to communicate data with the RR through the SDWAN tunnel. 9.A data communication apparatus in a software defined wide area network (SDWAN), characterized in that, The device is applied to a route reflector (RR), and the device comprises: The receiving unit is configured to receive first transmission tunnel endpoint (TTE) information sent by the CPE through a first connection established between the CPE and the RR; the first TTE information carries dynamic network address translation (NAT) indication information; the dynamic NAT indication information is used to indicate that the private IP address and the private port number of the CPE are processed in a dynamic NAT manner. The sending unit is configured to send second TTE information to the CPE through the first connection, so that the CPE obtains the public IP address and the public port number of the RR carried in the second TTE information and sends a Keepalive probe packet to the RR based on the public IP address and the public port number of the RR; the public IP address and the public port number of the RR are obtained respectively by performing NAT on the private IP address and the private port number of the RR; the Keepalive probe packet is a packet used for keep-alive detection of a TTE connection between the CPE and the RR. The communication unit is configured to receive the Keepalive probe packet sent by the CPE; send a Keepalive probe packet to the CPE based on the public IP address and the public port number of the CPE carried in the Keepalive probe packet, so that the CPE establishes an SDWAN tunnel with the RR based on the public IP address and the public port number of the CPE carried in the Keepalive probe packet and the public IP address and the public port number of the RR that have been obtained, and performs data communication with the RR through the SDWAN tunnel.
10. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the method according to any one of claims 1 to 3 or 4 to 6 when executing the computer program.
Citation Information
Patent Citations
A system and a method for realizing high-speed interconnection and intercommunication based on SDN and NFV technologies
CN109743244A
Communication management method, electronic equipment, storage medium and system
CN115277625A