Packet transmission method and device
By configuring virtual interfaces and building virtual links for virtual devices, the problem of insufficient physical interface resources in virtual device communication is solved, and efficient cross-virtual device message transmission is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEW H3C NETWORK INFORMATION SECURITY SOFTWARE CO LTD
- Filing Date
- 2024-09-06
- Publication Date
- 2026-04-10
AI Technical Summary
In existing technologies, communication between virtual devices requires the use of multiple physical interfaces, resulting in limited physical interface resources and becoming a communication bottleneck.
Configure a virtual interface for each virtual device and build a virtual link based on the target routing table. Transmit service packets through the virtual link to reduce dependence on the physical interface.
By creating virtual links between virtual devices, the consumption of physical interface resources is reduced, thus overcoming the bottleneck of virtual device communication.
Smart Images

Figure CN119316345B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure belongs to the technical field of communication, and particularly relates to a message transmission method and device. BACKGROUND
[0002] Virtualization technology supports abstraction of a plurality of virtual devices (Contexts) based on hardware resources of one physical device, and any virtual device can be logically equivalent to an independent device running a specific service or application program, and the virtual devices are isolated from each other.
[0003] If the above virtual devices need to transmit service messages, a commonly used solution is to transmit the service messages of the two virtual devices through physical connection. In this way, if the requirement of transmitting service messages between multiple virtual devices is to be met, multiple physical interfaces need to be occupied, and the physical interface resources are relatively limited, which can easily become a bottleneck of communication of the multiple virtual devices. SUMMARY
[0004] The present disclosure provides a message transmission method and device, which configures a virtual interface for each virtual device, and then implements cross-virtual-device message transmission based on virtual links between the virtual interfaces, which is not only beneficial to reduce consumption of physical interface resources, but also beneficial to break through the bottleneck of communication of multiple virtual devices.
[0005] The first aspect of the present disclosure provides a message transmission method, applied to a network security device, the network security device comprising a plurality of virtual devices, and the method comprising:
[0006] receiving a service message;
[0007] in a case where a next-hop device of the service message is a first virtual device in the plurality of virtual devices, constructing a virtual link based on a target routing table; the target routing table comprising a route, the route indicating a forwarding path composed of virtual interfaces, and the virtual link being a virtual link between a target ingress interface of the service message and a virtual interface of the first virtual device;
[0008] sending the service message to the first virtual device through the virtual link.
[0009] The second aspect of the present disclosure provides a message transmission device, applied to a network security device, the network security device comprising a plurality of virtual devices, and the device comprising:
[0010] a receiving module, configured to receive a service message;
[0011] The construction module is configured to construct a virtual link based on a target routing table when the next-hop device of the service packet is the first virtual device among the plurality of virtual devices; the target routing table includes routes, the routes indicate forwarding paths composed of virtual interfaces, and the virtual link is a virtual link between the target ingress interface of the service packet and the virtual interface of the first virtual device;
[0012] The sending module is used to send the service message to the first virtual device through the virtual link.
[0013] An embodiment of the third aspect of this disclosure provides a network security device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor runs the computer program to deploy multiple virtual devices, and implements the method described in the first aspect above.
[0014] An embodiment of the fifth aspect of this disclosure provides a computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the method described in the first aspect above.
[0015] The technical solutions provided in this disclosure have at least the following technical effects or advantages:
[0016] Virtual interfaces and routing tables are pre-configured for multiple virtual devices included in the network security device. Each routing table includes a route indicating a forwarding path composed of virtual interfaces. In a scenario where a second virtual device within the network security device receives and forwards a service packet to a first virtual device within the network security device, a virtual link is constructed based on the target routing table corresponding to the second virtual device. The service packet is then sent to the first virtual device via this virtual link. This virtual link is constructed based on the target ingress interface of the service packet and the virtual interface of the first virtual device. Therefore, this embodiment of the disclosure, by creating virtual links between virtual devices for cross-virtual device packet transmission, not only reduces the consumption of physical interface resources but also helps overcome the bottleneck of communication between multiple virtual devices.
[0017] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description or may be learned by practice of this disclosure. Attached Figure Description
[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of alternative embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this disclosure. Furthermore, the same reference numerals denote the same parts throughout the drawings.
[0019] In the attached diagram:
[0020] Figure 1 A schematic diagram of the structure of a network system provided in an embodiment of this disclosure is shown;
[0021] Figure 2 This illustration shows a flowchart of a message transmission method provided in an embodiment of the present disclosure;
[0022] Figure 3 A schematic diagram of the structure of a message transmission system provided in an embodiment of this disclosure is shown;
[0023] Figure 4 A schematic diagram of a message transmission scenario provided in an embodiment of this disclosure is shown;
[0024] Figure 5 A schematic diagram of the structure of a message transmission apparatus provided in an embodiment of this disclosure is shown;
[0025] Figure 6 A schematic diagram of the structure of a virtual device provided in an embodiment of this disclosure is shown;
[0026] Figure 7 A schematic diagram of a storage medium provided according to an embodiment of the present disclosure is shown. Detailed Implementation
[0027] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0028] It should be noted that, unless otherwise stated, the technical or scientific terms used in this disclosure shall have the ordinary meaning as understood by one of ordinary skill in the art to which this disclosure pertains.
[0029] The following describes the implementation scenarios and related technologies involved in the embodiments of this disclosure.
[0030] This disclosure relates to virtualization technology scenarios, and references... Figure 1 The network system shown, based on virtualization technology, supports the creation of several virtual devices (Contexts) on the basis of the hardware resources of a physical network security device, such as... Figure 1Context1, Context2 and Context3 shown in (1) in FIG. 1. Among them, Context1 can access a local area network (LAN) 1, Context2 can access a LAN 2, and Context3 can access a LAN 3. In an actual implementation scenario, the network security device can be implemented as a firewall device, and in the process of virtually outputting Context1, Context2 and Context3 based on the network security device, virtual firewall 1, virtual firewall 2 and virtual firewall 3 can be obtained by configuring the network security device, virtual firewall 1 can be a firewall of Context1, virtual firewall 2 can be a firewall of Context2, and virtual firewall 3 can be a firewall of Context3, and each firewall can isolate the current context from other contexts, so that each context runs independently of each other, for example, Figure 1 as shown in (2) in FIG. 1.
[0031] It should be noted that in a virtualized technical environment, the network security device itself can also be logically equivalent to a virtual device, wherein the virtual device logically equivalent to the network security device itself can be referred to as a "default context", and Context1, Context2 and Context3 can all be referred to as "non-default contexts", and the default context and the non-default context will be collectively referred to as a virtual device hereinafter.
[0032] In a conventional implementation, communication between any two virtual devices is implemented by physically connecting on the network security device, which not only requires physical resources, but also the network security device has only one device and a limited number of physical interfaces, which can not meet the communication needs of multiple virtual devices, thereby causing a bottleneck in communication between multiple virtual devices.
[0033] The technical solution proposed in the embodiments of the present disclosure pre-provisions virtual interfaces for multiple virtual devices respectively, takes the multiple virtual interfaces as routing nodes for cross-virtual-device transmission of service packets, configures a routing table for cross-virtual-device forwarding of service packets, supports creation of a virtual link based on virtual interfaces of two virtual devices in the scenario of cross-virtual-device packet transmission, and then transmits service packets across virtual devices through the virtual link. In this way, it is not only conducive to reducing the consumption of physical interface resources, but also conducive to breaking through the bottleneck of communication between multiple virtual devices.
[0034] A packet transmission method and device according to the embodiments of the present disclosure will be described below in combination with the above implementation scenario and the accompanying drawings.
[0035] As shown in Figure 2 The embodiments of the present disclosure provide a packet transmission method. The method can be applied to a network security device. The network security device can include a plurality of virtual devices, as shown in Figure 1 The method includes the following steps.
[0036] In step S11, a service packet is received.
[0037] The service packet is, for example, a packet that needs to be transmitted across the virtual devices in the network security device. In some embodiments, the network security device receives the service packet through a default Context, as shown in Figure 1 In some embodiments, the network security device receives the service packet through any non-default Context, as shown in Figure 1 In some embodiments, the network security device receives the service packet through any non-default Context, as shown in For ease of description, the virtual device that receives the service packet in the plurality of virtual devices is referred to as a second virtual device in the present specification.
[0038] In some embodiments, the network security device can receive the service packet based on a network to which the second virtual device is connected. In this scenario, the second virtual device is the first forwarding device of the service packet in the network security device. In other embodiments, the network security device can receive the service packet based on other virtual devices in the network security device. In this scenario, the second virtual device is an intermediate forwarding device of the service packet in the network security device.
[0039] It should be noted that, before step S11, in the stage of configuring the second virtual device, an interface creation instruction can also be received. A virtual network interface card (vNIC) is created according to the interface creation instruction. Then, the table item information of the virtual network interface card can be configured to obtain the virtual interface of the second virtual device. The interface creation instruction can be an interface configuration item in the configuration interface of the second virtual device, which is received in response to a user trigger.
[0040] The table item information of the virtual network interface card can record the state and configuration information of other virtual interfaces connected to the second virtual device, and the table item information of the virtual network interface card can include at least one of the following: a network address of the virtual network interface card, a state of the virtual network interface card, and the like. For example, the table item information can include an Internet Protocol Address (IP address), a Media Access Control address (MAC address), a Maximum Transmission Unit (MTU) size, an interface state, and the like. In some embodiments, the network identification part of the IP address of the virtual interface can indicate the LAN accessed by the second virtual device, the host identification part of the IP address of the virtual interface can indicate the second virtual device, and the state of the virtual interface is configured as an up state.
[0041] It should be understood that the above is only an example of the second virtual device for configuring a virtual interface. In some embodiments, in the stage of configuring any virtual device, the virtual interface corresponding to the virtual device can be configured. Details are not described here.
[0042] After the plurality of virtual devices in the network security device are configured with virtual interfaces, the network security device can maintain the correspondence between the virtual interfaces and the devices, which includes the correspondence between any virtual device and the corresponding virtual interface.
[0043] In step S12, in the case that the next hop device of the service packet is a first virtual device in the plurality of virtual devices, a virtual link is constructed based on a target routing table.
[0044] The first virtual device can be a virtual device other than the second virtual device in the plurality of virtual devices, and in the case that the next hop device of the service packet is determined to be the first virtual device, the network security device can determine that the service packet needs to be forwarded across virtual devices in the network security device.
[0045] In some embodiments, the first virtual device can be an intermediate forwarding device of the service packet. In other embodiments, the first virtual device can be a destination device of the service packet.
[0046] The routing table corresponding to the second virtual device is the target routing table. The target routing table includes a route indicating a forwarding path composed of virtual interfaces, and the virtual link is a virtual link between a target ingress interface of the service packet and a virtual interface of the first virtual device. For example, the forwarding path included in the target routing table is composed of IP addresses of virtual interfaces.
[0047] In combination with the foregoing description, after configuring the virtual interface for each virtual device, a routing table can also be set for each virtual device. The routing table of any virtual device can indicate the IP address of the virtual interface of the virtual device and the forwarding path composed of the IP addresses of other virtual interfaces connected with the IP address of the virtual interface. The network security device can maintain the correspondence between each virtual device and each routing table, and then determine the next-hop virtual device of the service message according to the routing tables, so as to ensure that the service message can be correctly forwarded to the destination virtual device.
[0048] It can be seen that, by adopting the implementation manner of the technical solution, the virtual interface is supported to be deployed for the virtual device, and the routing table across the virtual devices is generated based on the virtual interface of each virtual device, thereby providing an implementation basis for transmitting the message across the virtual devices through the virtual link.
[0049] It should be noted that the network security device can configure the initial state of each routing table as a static mode. Correspondingly, before the virtual link is constructed based on the target routing table, the network device can read the destination address of the service message, the destination address being the IP address of the virtual interface corresponding to the destination device of the service message. Then, the next-hop device of the service message can be determined as the first virtual device according to the destination address; the routing table corresponding to the second virtual device is determined as the target routing table from the preset correspondence between the routing table and the device, and the state of the target routing table is switched from the static mode to the dynamic mode.
[0050] It should be understood that the network security device can determine all forwarding devices from the second virtual device to the destination device according to the destination address. Then, in some implementation manners, the network security device can determine the routing table corresponding to each forwarding device from the preset correspondence between the routing table and the device, and switch the state of the determined routing table from the static mode to the dynamic mode, so that the service message is forwarded to the corresponding forwarding device, and the service message is continued to be forwarded according to the routing table of the corresponding forwarding device.
[0051] The static mode refers to the mode in which the routing table is in an inactive state. In the static mode, the routing table does not participate in actual traffic forwarding and does not consume other resources. The dynamic mode refers to the mode in which the routing table is in an active state. In the dynamic mode, the routing table can be called to participate in actual traffic forwarding. It can be seen that, by adopting the implementation manner, the initial state of each routing table is the static mode, and until the traffic matching the forwarding service message, the matching routing table is activated to the dynamic state, which not only can reduce the consumption of resources, but also can ensure that the service message is forwarded in time.
[0052] Further, the network security device can determine the target ingress interface and the virtual interface of the first virtual device based on the target routing table, and build a virtual encrypted tunnel between the target ingress interface and the virtual interface of the first virtual device.
[0053] In some embodiments, if the second virtual device is the first forwarding device of the service packet in the network security device, the second virtual device receives the service packet, for example, through a LAN interface of the second virtual device. Further, by querying the target routing table, the first egress interface and the second egress interface of the service packet can be determined, the second egress interface being the egress interface of the first egress interface. According to the correspondence between the virtual interface and the device, the first egress interface can be determined as the virtual interface of the second virtual device, and the second egress interface can be determined as the virtual interface of the first virtual device, and then the target ingress interface can be determined as the first egress interface.
[0054] In other embodiments, if the second virtual device is an intermediate forwarding device of the service packet in the network security device, the second virtual device receives the service packet through a virtual interface of the second virtual device. By querying the target routing table to determine the egress interface of the service packet, the egress interface can be determined as corresponding to the first virtual device according to the correspondence between the virtual interface and the device, and then the virtual interface received by the second virtual device can be determined as the target ingress interface.
[0055] Further, the virtual link built between the target ingress interface and the virtual interface of the first virtual device can be an unencrypted virtual tunnel or a virtual encrypted tunnel. The unencrypted virtual tunnel can be, for example, a virtual link created between the virtual interface of the second virtual device and the virtual interface of the first virtual device based on Software-Defined Networking (SDN) technology, Generic Routing Encapsulation (GRE) tunnel protocol, or IP tunnel technology. The virtual encrypted tunnel can be an encrypted tunnel created based on a Virtual Private Network (VPN).
[0056] In step S13, the service packet is sent to the first virtual device through the virtual link.
[0057] In the case that the virtual link is an unencrypted virtual tunnel, the second virtual device can configure a virtual interface IP address of the second virtual device as a source IP address of the tunnel, configure a virtual interface IP address of the first virtual device as a destination IP address of the tunnel, and then encapsulate the service message in a new data packet, the source IP address of the new data packet can be the source IP address of the tunnel, and the destination IP address of the new data packet is the destination IP address of the tunnel. Further, the service message can be transmitted to the virtual interface of the first virtual device according to the configuration rule of the corresponding virtual link in the network.
[0058] In the case that the virtual link is an encrypted tunnel, the second virtual device can encrypt the service message by using the encryption algorithm and the key agreed in the configuration stage of the encrypted tunnel, and transmit the encrypted message to the virtual interface of the first virtual device through the encrypted tunnel. Then, the first virtual device decrypts the encrypted message by using the decryption algorithm and the key agreed in the configuration stage of the encrypted tunnel, to obtain the service message. In this way, in the cross-virtual-device transmission scenario, the security of the message is guaranteed.
[0059] Further, after transmitting the service message to the first virtual device, the network security device can forward the service message based on the routing table corresponding to the first virtual device. The specific implementation manner can refer to the description of the above embodiments, which will not be described here.
[0060] In some embodiments, after transmitting the service message to the first virtual device through the virtual link, the network security device can further switch the state of the target routing table from the dynamic mode to the static mode.
[0061] As can be seen, by using the implementation manner, the virtual interfaces and the routing tables are respectively set for the plurality of virtual devices included in the network security device in advance, and any routing table includes a route, and the route indicates a forwarding path composed of virtual interfaces. In this way, in the scenario that the second virtual device included in the network security device receives and forwards the service message to the first virtual device included in the network security device, the virtual link is constructed based on the target routing table corresponding to the second virtual device, and then the service message is transmitted to the first virtual device through the virtual link. The virtual link is constructed based on the target ingress interface of the service message and the virtual interface of the first virtual device. As can be seen, by creating the virtual link between the virtual devices and performing cross-virtual-device message transmission, the disclosed embodiments are not only beneficial to reducing the consumption of physical interface resources, but also beneficial to breaking through the bottleneck of communication of the plurality of virtual devices.
[0062] The technical solutions of the disclosed embodiments are described below in conjunction with examples.
[0063] Reference Figure 3 , Figure 3A structure diagram of a packet transmission system is shown, which includes Context 30, Context 31, Context 32 and Context 33. Context 30 is a virtual device logically equivalent to a network security device (i.e. a physical firewall) in a virtualization environment, and Context 30 is a default Context. Context 31, Context 32 and Context 33 are virtual devices created by a user based on a physical firewall through a virtualization management platform (such as VMware vSphere, Microsoft Hyper-V, KVM, etc.), and Context 31, Context 32 and Context 33 are all non-default Contexts. Context 31 can access LAN 31, Context 32 can access LAN 32, and Context 33 can access LAN 33. Context 31, Context 32 and Context 33 respectively correspond to a virtual firewall, and are isolated from other Contexts through their respective firewalls.
[0064] Further, the user can create a virtual interface for each Context based on the virtualization management platform. For any Context, the user can create a vNIC on the configuration interface of the Context based on the physical interface of the physical firewall, and then configure the entries of the vNIC to obtain the virtual interface of the Context. For example, the IP address of the vNIC can be configured as m.m.m.x / 24, where m.m.m.x is the network identifier of the LAN accessed by the Context. The physical layer and the link layer of the vNIC are configured as up.
[0065] Again referring to the blocks in each Context shown in Figure 3 , Figure 3 The blocks in each Context shown in Table 1 can be respectively sent to each Context by the user through the virtualization management platform.
[0066] Table 1
[0067] Context Virtual interface Context 30 Virtual interface 30 Context 31 Virtual interface 31 Context 32 Virtual interface 32 Context 33 Virtual interface 33
[0068] It should be noted that the virtual interface of any Context can be connected to the virtual firewall of the Context.
[0069] Further, for any Context, a routing table corresponding to the Context can be constructed based on the virtual interface of the Context and the virtual interfaces of other Contexts. The routing table of the Context includes a route indicating a forwarding path composed of an IP address of the virtual interface of the Context and an IP address of a virtual interface of another Context. For example, taking Context 32 as an example, the route included in the routing table corresponding to Context 32 indicates, for example, a forwarding path of virtual interface 32 and virtual interface 30. Wherein, the initial state of the routing table of each of the above Contexts is static mode.
[0070] Taking the case that LAN 31 receives a service packet and transmits the service packet to Context 30, the virtual firewall of Context 31 (i.e., the second virtual device described above) receives the service packet from LAN 31, and the destination address included in the service packet is, for example, the IP address of virtual interface 30. The network security device can determine, for example, that the next hop device of the service packet is Context 32 (i.e., the first virtual device described above) according to the IP address of the destination address virtual interface 30, and then determine the routing tables corresponding to Context 31, Context 32 and Context 30 respectively from the preset correspondence between the routing table and the device, and switch the state of the determined routing table from static mode to dynamic mode.
[0071] After switching the state of the routing table of Context 31 (i.e., the target routing table described above) from static mode to dynamic mode, the next hop forwarding node of the service packet can be determined according to the routing table, which is virtual interface 31 (i.e., the first out interface described above), and the next hop forwarding node of virtual interface 31 is virtual interface 32 (i.e., the second out interface described above). Then, the service packet can be forwarded to virtual interface 31, and then a virtual link between virtual interface 31 and virtual interface 32 is constructed, and the service packet is sent to virtual interface 32 through the virtual link. Further, the next hop forwarding node (i.e., the out interface) of the service packet can be determined by querying the routing table of Context 32, which is virtual interface 30, and then a virtual link between virtual interface 32 and virtual interface 30 is constructed, and the service packet is sent to virtual interface 30 through the virtual link.
[0072] Wherein, the virtual link between the two virtual devices can be as follows Figure 4As shown in the figure, taking virtual device 31 and virtual device 30 as an example, the virtual firewall of Context 31 can build a virtual link between virtual interface 31 and virtual interface 30, connect Context 31 with Context 30 through the virtual link, and then send the service message from virtual interface 31 to virtual interface 30 through the virtual link, so as to realize the transmission of the service message from Context 31 to Context 30.
[0073] It should be understood that Figure 3 The message transmission system and the related forwarding path shown in the figure are illustrative implementations of the present disclosure, and do not constitute a limitation on the implementation of the embodiments of the present disclosure. In some other implementations, the message transmission system can further include more or fewer Contexts, and the implementation of the routing table can also be flexibly configured according to the implementation scenario.
[0074] In summary, the message transmission method related to the embodiments of the present disclosure pre-provides virtual interfaces and routing tables for a plurality of virtual devices included in a network security device, any routing table includes a route, and the route indicates a forwarding path composed of virtual interfaces. In the scenario where a second virtual device included in the network security device receives and forwards a service message to a first virtual device included in the network security device, a virtual link is built based on a target routing table corresponding to the second virtual device, and then the service message is sent to the first virtual device through the virtual link. The virtual link is built based on a target ingress interface of the service message and a virtual interface of the first virtual device. It can be seen that, by creating a virtual link between virtual devices, the message transmission method of the embodiments of the present disclosure can not only reduce the consumption of physical interface resources, but also break through the bottleneck of communication between a plurality of virtual devices.
[0075] The embodiments of the present disclosure also provide a message transmission device, which can be deployed in a network security device (i.e., the aforementioned physical firewall) and used to perform the operations of the message transmission method described in any of the above embodiments, such as Figure 5 As shown in the figure, the device includes:
[0076] The receiving module 501 is configured to receive a service message.
[0077] The building module 502 is configured to build a virtual link based on a target routing table in the case where the next hop device of the service message is a first virtual device in the plurality of virtual devices; the target routing table includes a route, and the route indicates a forwarding path composed of virtual interfaces; and the virtual link is a virtual link between a target ingress interface of the service message and a virtual interface of the first virtual device.
[0078] The sending module 503 is configured to send the service message to the first virtual device through the virtual link.
[0079] In the embodiments of the present disclosure, the forwarding path included in the target routing table is composed of IP addresses of virtual interfaces, and the apparatus further includes a reading module, a determining module and a state switching module, wherein the reading module is configured to read a destination address of the service packet, the destination address being an IP address of a virtual interface corresponding to a destination device of the service packet; the determining module is configured to determine, according to the destination address, that a next-hop device of the service packet is the first virtual device; and the state switching module is configured to determine, from a preset correspondence between routing tables and devices, a routing table corresponding to a second virtual device as the target routing table, and switch a state of the target routing table from a static mode to a dynamic mode, the second virtual device being a device of the plurality of virtual devices that receives the service packet.
[0080] In the embodiments of the present disclosure, the determining module is further configured to determine the target ingress interface and the virtual interface of the first virtual device based on the target routing table; and the constructing module 502 is further configured to construct a virtual encryption tunnel between the target ingress interface and the virtual interface of the first virtual device.
[0081] In the embodiments of the present disclosure, if the second virtual device is a first forwarding device of the service packet in the network security device, the apparatus further includes a querying module, wherein the querying module is configured to query the target routing table to determine a first egress interface and a second egress interface of the service packet, the second egress interface being an egress interface of the first egress interface; the determining module is further configured to determine, according to the correspondence between virtual interfaces and devices, that the first egress interface is a virtual interface of the second virtual device and that the second egress interface is a virtual interface of the first virtual device; and determine the first egress interface as the target ingress interface.
[0082] In the embodiments of the present disclosure, if the second virtual device is a first forwarding device of the service packet in the network security device, the apparatus further includes a querying module, wherein the querying module is configured to query the target routing table to determine a first egress interface and a second egress interface of the service packet, the second egress interface being an egress interface of the first egress interface; the determining module is further configured to determine, according to the correspondence between virtual interfaces and devices, that the first egress interface is a virtual interface of the second virtual device and that the second egress interface is a virtual interface of the first virtual device; and determine the first egress interface as the target ingress interface.
[0083] In the embodiments of the present disclosure, the state switching module is further configured to switch the state of the target routing table from the dynamic mode to the static mode after the service packet is sent to the first virtual device through the virtual link.
[0084] The packet transmission device provided by the above embodiments of the present disclosure has the same beneficial effects as the method adopted, run or implemented by the application program stored therein.
[0085] The present disclosure also provides a network security device for executing the packet transmission method. Please refer to Figure 6 which shows a schematic diagram of a network security device provided by some embodiments of the present disclosure. As shown in Figure 6 The network security device 6 comprises a processor 600, a memory 601, a bus 602 and a communication interface 603, wherein the processor 600, the communication interface 603 and the memory 601 are connected through the bus 602; the memory 601 stores a computer program which can be run on the processor 600, and the processor 600 runs the computer program to execute the packet transmission method provided by any one of the preceding embodiments of the present disclosure.
[0086] The memory 601 can include a high-speed random access memory (RAM) and can also include a non-volatile memory such as at least one disk memory. The communication connection between the system virtual devices can be achieved through at least one communication interface 603 (which can be wired or wireless), and the Internet, a wide area network, a local network, a metropolitan area network, etc. can be used.
[0087] The bus 602 can be an ISA bus, a PCI bus or an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 601 is used to store programs, and the processor 600 executes the programs after receiving execution instructions. The packet transmission method disclosed in the preceding embodiments of the present disclosure can be applied to the processor 600 or implemented by the processor 600.
[0088] The processor 600 can be an integrated circuit chip with a processing capability of signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware in the processor 600 or the instruction in the form of software. The processor 600 described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a ready programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. Each method, step and logic block diagram disclosed in the embodiments of the present disclosure can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the embodiments of the present disclosure can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in a random access memory, a flash memory, a read only memory, a programmable read only memory or an electrically erasable programmable memory, a register, etc. The storage medium in the art. The storage medium is located in the memory 601, and the processor 600 reads the information in the memory 601, and combines the hardware to complete the steps of the above method.
[0089] The electronic device provided by the embodiments of the present disclosure and the message transmission method provided by the embodiments of the present disclosure have the same beneficial effects as the method they adopt, run or implement.
[0090] The present disclosure also provides a computer readable storage medium corresponding to the message transmission method provided by the preceding embodiments. Please refer to Figure 7 The computer readable storage medium shown is an optical disc 70, and a computer program (i.e. program product) is stored on the optical disc 70. When the computer program is run by a processor, the message transmission method provided by any of the preceding embodiments is executed.
[0091] It should be noted that examples of the computer readable storage medium can also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other optical, magnetic storage medium, which will not be described one by one here.
[0092] The computer readable storage medium provided by the above embodiments of the present disclosure and the message transmission method provided by the embodiments of the present disclosure have the same beneficial effects as the method they store and adopt, run or implement.
[0093] While the application has been described in terms of several preferred embodiments, it will be apparent to those with ordinary skill in the art that many modifications, substitutions, improvements, and
[0094] The above detailed description has shown, described, and pointed out the various features of the application. It will be understood that various omissions, substitutions, changes, and modifications can be made to the specific embodiments disclosed in this application without departing from the spirit and scope of the application, as defined by the following claims.
Claims
1. A message transmission method, characterized in that, Applied to a network security device, the network security device comprising multiple virtual devices, the method includes: Receive service messages; When the next-hop device of the service packet is the first virtual device among the plurality of virtual devices, a virtual link is constructed based on the target routing table; the target routing table includes routes, the routes indicate forwarding paths composed of virtual interfaces, and the virtual link is a virtual link between the target ingress interface of the service packet and the virtual interface of the first virtual device; The service message is sent to the first virtual device through the virtual link; The forwarding paths included in the target routing table consist of Internet Protocol (IP) addresses of virtual interfaces. Before constructing the virtual link based on the target routing table, the following is also included: Read the destination address of the service message, where the destination address refers to the IP address of the virtual interface corresponding to the destination device of the service message; The next-hop device for the service message is determined to be the first virtual device based on the destination address; From the preset mapping between routing tables and devices, the routing table corresponding to the second virtual device is determined as the target routing table, and the state of the target routing table is switched from static mode to dynamic mode. The second virtual device is the device among the plurality of virtual devices that receives the service packet.
2. The method according to claim 1, characterized in that, The construction of virtual links based on the target routing table includes: The target ingress interface and the virtual interface of the first virtual device are determined based on the target routing table. A virtual encrypted tunnel is constructed between the target ingress interface and the virtual interface of the first virtual device.
3. The method according to claim 2, characterized in that, If the second virtual device is the first forwarding device when the service packet is transmitted in the network security device, the step of determining the target ingress interface and the virtual interface of the first virtual device based on the target routing table includes: The target routing table is queried to determine the first and second outgoing interfaces of the service packet, wherein the second outgoing interface is the outgoing interface of the first outgoing interface; Based on the correspondence between virtual interfaces and devices, it is determined that the first output interface is the virtual interface of the second virtual device, and the second output interface is the virtual interface of the first virtual device; The first outgoing interface is determined as the target incoming interface.
4. The method according to claim 2, characterized in that, If the second virtual device is an intermediate forwarding device when the service packet is transmitted in the network security device, the step of determining the target ingress interface and the virtual interface of the first virtual device based on the target routing table includes: Query the target routing table to determine the outgoing interface of the service packet; Based on the correspondence between virtual interfaces and devices, the output interface is determined to correspond to the first virtual device, and the virtual interface received by the second virtual device is determined to be the target input interface.
5. The method according to claim 1, characterized in that, After sending the service message to the first virtual device via the virtual link, the method further includes: Switch the state of the target routing table from the dynamic mode to the static mode.
6. A message transmission device, characterized in that, Applied to network security devices, the network security devices including multiple virtual devices, the device includes: The receiving module is used to receive service messages; The construction module is configured to construct a virtual link based on a target routing table when the next-hop device of the service packet is the first virtual device among the plurality of virtual devices; the target routing table includes routes, the routes indicate forwarding paths composed of virtual interfaces, and the virtual link is a virtual link between the target ingress interface of the service packet and the virtual interface of the first virtual device; The sending module is used to send the service message to the first virtual device through the virtual link; The target routing table includes forwarding paths composed of Internet Protocol (IP) addresses of virtual interfaces. The device further includes a reading module, a determining module, and a state switching module. The reading module is used to read the destination address of the service message, where the destination address refers to the IP address of the virtual interface corresponding to the destination device of the service message; The determining module is used to determine the next-hop device of the service packet as the first virtual device based on the destination address; The state switching module is used to determine the routing table corresponding to the second virtual device as the target routing table from the preset correspondence between the routing table and the device, and switch the state of the target routing table from static mode to dynamic mode. The second virtual device is the device among the plurality of virtual devices that receives the service packet.
7. The apparatus according to claim 6, characterized in that, The determining module is further configured to determine the target ingress interface and the virtual interface of the first virtual device based on the target routing table; The construction module is also used to construct a virtual encrypted tunnel between the target ingress interface and the virtual interface of the first virtual device.
8. The apparatus according to claim 7, characterized in that, If the second virtual device is the first forwarding device when the service message is transmitted in the network security device, the apparatus further includes a query module, wherein... The query module is used to query the target routing table to determine the first and second outgoing interfaces of the service packet, wherein the second outgoing interface is the outgoing interface of the first outgoing interface. The determining module is further configured to determine, based on the correspondence between the virtual interface and the device, that the first output interface is the virtual interface of the second virtual device, and the second output interface is the virtual interface of the first virtual device; and to determine the first output interface as the target input interface.
9. The apparatus according to claim 8, characterized in that, The query module is further configured to query the target routing table to determine the outgoing interface of the service packet if the second virtual device is an intermediate forwarding device when the service packet is transmitted in the network security device. The determining module is further configured to determine that the output interface corresponds to the first virtual device according to the correspondence between the virtual interface and the device, and to determine the virtual interface received by the second virtual device as the target input interface.
10. The apparatus according to claim 6, characterized in that, The state switching module is further configured to switch the state of the target routing table from the dynamic mode to the static mode after sending the service message to the first virtual device through the virtual link.
Citation Information
Patent Citations
Method and device for realizing traffic interflow between virtual devices
CN103795623A
Method and device for transmitting service message
CN108768861A