A message forwarding method, electronic equipment and storage medium
By deploying routing devices and firewall devices in the cloud platform VPC instance and leveraging the host routing characteristics, fast and easy firewall service access is achieved, solving the high cost and long delivery cycle of traditional cloud platform firewalls and improving the flexibility and efficiency of firewall services.
Patent Information
- Application Number
- CN202411723847.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-11-27
AI Technical Summary
Traditional cloud platform firewall solutions require customized development, resulting in high delivery costs, long cycles, and an inability to quickly adapt to changes in the cloud platform.
Deploy routing devices and firewall devices in the VPC instance of the cloud platform, implement security protection for business hosts through preset binding relationships and address translation operations, and quickly access firewall services by leveraging the host routing characteristics.
It simplifies the delivery process of firewalls on the cloud platform, reduces the delivery difficulty and cycle, improves flexibility, and enables rapid response to customer needs.
Smart Images

Figure CN119603369B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a message forwarding method, electronic device, and storage medium. Background Art
[0002] Cloud computing has become mainstream, with a proliferation of cloud platforms. Protecting the security of service hosts within these platforms is a key issue in this field. Traditional security solutions require establishing firewall traffic channels within the cloud and developing customized firewall services tailored to the cloud platform's needs. This approach has drawbacks: Each time a new customer delivers services, or when a new vendor or version of a cloud platform is introduced, the firewall must be re-customized, resulting in high delivery costs and long lead times. Summary of the Invention
[0003] In order to overcome the problems existing in the related art, the present application provides a message forwarding method, an electronic device and a storage medium.
[0004] According to a first aspect of an embodiment of the present application, a message forwarding method is provided. The method is applied to a routing device deployed in a target VPC instance, and the method includes:
[0005] Receive a request message initiated by a client to a target host deployed in the target VPC instance;
[0006] forwarding the request message to a firewall device deployed in the target VPC instance based on a preset binding relationship and a destination address in the request message, so that the firewall device performs a destination address translation operation on the request message after confirming that the request message complies with an access control policy, and forwards the first message obtained by the translation to the target host, wherein the preset binding relationship is a binding relationship between an address of the target host providing external services and the address of the firewall device, and the destination address translation operation is to translate the destination address of the request message from the address of the firewall device to the address of the target host;
[0007] receiving a response message sent by the firewall device, wherein the response message is obtained by the firewall device performing a source address translation operation on the second message after confirming that the second message complies with the access control policy, the second message is generated by the target host based on the first message and forwarded by the target host to the firewall device according to a host route, the host route including a next hop address to any network segment being the address of the firewall device, and the source address translation operation is to translate the source address of the second message from the address of the target host to the address of the firewall device;
[0008] forward the response message to the client according to the preset binding relationship and the destination address in the response message.
[0009] According to a second aspect of the embodiments of the present application, a message forwarding device is provided, which is applied to a routing device deployed in a target VPC instance, and comprises:
[0010] a first routing receiving module, configured to receive a request message initiated by a client to a target host deployed in the target VPC instance;
[0011] a first routing forwarding module, configured to forward the request message to a firewall device deployed in the target VPC instance according to a preset binding relationship and a destination address in the request message, so that the firewall device performs a destination address conversion operation on the request message after confirming that the request message conforms to an access control policy, and forwards a first message obtained by conversion to the target host, wherein the preset binding relationship is a binding relationship between an address provided by the target host for external service and an address of the firewall device, and the destination address conversion operation is to convert the destination address of the request message from the address of the firewall device to the address of the target host;
[0012] a second routing receiving module, configured to receive a response message sent by the firewall device, wherein the response message is obtained by the firewall device performing a source address conversion operation on a second message after confirming that the second message conforms to the access control policy, the second message is generated by the target host according to the first message and is forwarded to the firewall device by the target host according to a host routing, the host routing comprises an address of the firewall device as a next hop address to any network segment, and the source address conversion operation is to convert the source address of the second message from the address of the target host to the address of the firewall device;
[0013] a second routing forwarding module, configured to forward the response message to the client according to the preset binding relationship and the destination address in the response message.
[0014] According to a third aspect of the embodiments of the present application, a message forwarding method is provided, which is applied to a firewall device deployed in a target VPC instance, and comprises:
[0015] receiving a request message sent by a routing device deployed in the target VPC instance, wherein the request message is initiated by a client to a target host deployed in the target VPC instance, is received by the routing device from the client, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message, where the preset binding relationship is a binding relationship between an address of the target host providing external services and an address of the firewall device;
[0016] Determine whether the request message complies with the access control policy, and if so, perform a destination address translation operation on the request message, and send the converted first message to the target host, wherein the destination address translation operation is: translating the destination address of the request message from the address of the firewall device to the address of the target host;
[0017] receiving a second message sent by the target host, wherein the second message is generated by the target host based on the first message and forwarded by the target host to the firewall device according to a host route, wherein the host route includes a next hop address to any network segment that is an address of the firewall device;
[0018] Determine whether the second message complies with the access control policy. If the judgment result is yes, perform a source address translation operation on the second message, and send the converted response message to the routing device, so that the routing device sends the response message to the client, wherein the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0019] According to a fourth aspect of an embodiment of the present application, a message forwarding device is provided. The device is applied to a firewall device deployed in a target VPC instance, and the device includes:
[0020] a first firewall receiving module, configured to receive a request message sent by a routing device deployed in the target VPC instance, wherein the request message is initiated by a client to a target host deployed in the target VPC instance, is received by the routing device from the client, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message, wherein the preset binding relationship is a binding relationship between an address of the target host providing external services and an address of the firewall device;
[0021] a first firewall forwarding module, configured to determine whether the request message complies with the access control policy; if so, perform a destination address translation operation on the request message, and send the converted first message to the target host, wherein the destination address translation operation is to translate the destination address of the request message from the address of the firewall device to the address of the target host;
[0022] a second firewall receiving module, configured to receive a second message sent by the target host, wherein the second message is generated by the target host based on the first message and forwarded by the target host to the firewall device according to a host route, wherein the host route includes a next hop address to any network segment that is an address of the firewall device;
[0023] The second firewall forwarding module is used to determine whether the second message complies with the access control policy. If the judgment result is yes, a source address translation operation is performed on the second message, and a response message obtained by the conversion is sent to the routing device, so that the routing device sends the response message to the client, wherein the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0024] According to a fifth aspect of an embodiment of the present application, a message forwarding method is provided. The method is applied to a target host deployed in a target VPC instance, and the method includes:
[0025] Receive a first message sent by a firewall device deployed on the target VPC instance, wherein the first message is obtained by the firewall device performing a destination address translation operation on the request message after confirming that the request message complies with the access control policy, the request message is initiated by a client to a target host deployed on the target VPC instance, is received from the client by a routing device, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message, the preset binding relationship being a binding relationship between an address of a service provided externally by the target host and the address of the firewall device, and the destination address translation operation is to convert the destination address of the request message from the address of the firewall device to the address of the target host;
[0026] A second message is generated based on the first message, and the second message is sent to the firewall device based on the host route, so that the firewall device performs a source address translation operation on the second message after confirming that the second message complies with the access control policy, and sends a response message obtained by the conversion to the routing device, wherein the host route includes a next hop address to any network segment as the address of the firewall device, and the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0027] According to a sixth aspect of an embodiment of the present application, a message forwarding device is provided. The device is applied to a target host deployed in a target VPC instance, and the device includes:
[0028] a host receiving module, configured to receive a first message sent by a firewall device deployed on the target VPC instance, wherein the first message is obtained by the firewall device performing a destination address translation operation on the request message after confirming that the request message complies with the access control policy; the request message is initiated by a client to a target host deployed on the target VPC instance, received by a routing device from the client, and forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message; the preset binding relationship is a binding relationship between an address of a service provided externally by the target host and an address of the firewall device; the destination address translation operation is to convert the destination address of the request message from the address of the firewall device to the address of the target host;
[0029] A host sending module is used to generate a second message based on the first message, and send the second message to the firewall device according to the host route, so that the firewall device performs a source address translation operation on the second message after confirming that the second message complies with the access control policy, and sends the converted response message to the routing device, wherein the host route includes a next hop address to any network segment as the address of the firewall device, and the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0030] According to the seventh aspect of an embodiment of the present application, an electronic device is provided, comprising a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the steps of the message forwarding method described above.
[0031] According to an eighth aspect of an embodiment of the present application, a computer-readable storage medium is provided, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the message forwarding method described above are implemented.
[0032] The technical solutions provided by the embodiments of the present application may have the following beneficial effects:
[0033] In the embodiment of the present application, the firewall service is deployed in the VPC instance by utilizing the feature that the business host in the cloud platform supports host routing to realize the protection of each business host in the VPC instance. This implementation method facilitates the quick and easy connection of the firewall capability to the cloud platform that supports the cloud routing table and forms the protection capability, effectively reducing the difficulty of firewall delivery in the cloud scenario and shortening the firewall delivery cycle.
[0034] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0036] Figure 1 A schematic diagram of the cloud platform structure provided for this application;
[0037] Figure 2 A schematic diagram of a process of the message forwarding method provided in this application;
[0038] Figure 3 A flowchart of the message forwarding method provided in Example 1 of the present application;
[0039] Figure 4 Another process diagram of the message forwarding method provided by this application;
[0040] Figure 5 A flowchart of the message forwarding method provided in Example 2 of the present application;
[0041] Figure 6 A flowchart of the message forwarding method provided in Example 3 of the present application;
[0042] Figure 7 Schematic diagram of the message forwarding process for a specific application scenario provided by this application;
[0043] Figure 8 Schematic diagram of the message forwarding process for specific application scenarios provided by this application;
[0044] Figure 9 This is a schematic diagram of the structure of the electronic device provided in this application. DETAILED DESCRIPTION
[0045] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0046] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. As used in this application and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0047] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words "if" or "if" as used herein may be interpreted as "when" or "when".
[0048] In this application, the cloud platform includes one or more VPC (Virtual Private Cloud) instances. The network traffic of the service hosts within each VPC instance can be controlled based on the host routing on the service host. A VPC instance can be deployed with any number of service hosts, and clients can access the service hosts within the VPC instances on the cloud platform through the public network. For ease of description, this application refers to the VPC instance that the client requests to access as the target VPC instance, and the service host that the client requests to access as the target host.
[0049] like Figure 1 As shown, the target VPC instance is deployed with a routing device. Network traffic from the client reaches the target VPC instance through the routing device. The target VPC instance is deployed with the target host requested by the client and a firewall device.
[0050] Next, the message forwarding method provided in the embodiment of the present application is introduced and explained.
[0051] Example 1
[0052] Figure 2 A schematic diagram of the message forwarding method provided in this application. Figure 3This is a flow chart of a message forwarding method provided in Example 1 of the present application, which is applied to a routing device deployed in a target VPC instance, such as Figure 3 As shown, the method includes the following steps:
[0053] Step 310: Receive a request message initiated by the client to the target host deployed in the target VPC instance;
[0054] Step 320: Forward the request message to a firewall device deployed in the target VPC instance based on the preset binding relationship and the destination address in the request message. After confirming that the request message complies with the access control policy, the firewall device performs a destination address translation operation on the request message and forwards the converted first message to the target host.
[0055] The preset binding relationship is the binding relationship between the address of the target host providing external services and the address of the firewall device, and the destination address conversion operation is: converting the destination address of the request message from the address of the firewall device to the address of the target host.
[0056] Step 330: Receive a response message sent by the firewall device;
[0057] Among them, the response message is obtained by the firewall device performing a source address translation operation on the second message after confirming that the second message complies with the access control policy. The second message is generated by the target host based on the first message and forwarded to the firewall device by the target host according to the host route. The host route includes the next hop address to any network segment as the address of the firewall device. The source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0058] Step 340: forward the response message to the client according to the preset binding relationship and the destination address in the response message.
[0059] This application does not restrict the deployment location of the target host and firewall device. Specifically, the target host and firewall device can be deployed in the same subnet of the target VPC instance, or in different subnets of the target VPC instance. In actual applications, you can even set up a subnet specifically for deploying the firewall device.
[0060] In the case where the target host and firewall device are deployed in different subnets of the target VPC instance, assuming Figure 4 As shown, the target host is deployed in the first subnet of the target VPC instance, and the firewall device is deployed in the second subnet of the target VPC instance. In this case, the host route not only includes the next hop address to any network segment being the address of the firewall device, but also includes the next hop address to the network segment where the firewall device is located being the gateway address of the target host.
[0061] In actual applications, to ensure high availability, one or more firewall devices are often set up as backup devices. Therefore, as a preferred implementation, the target VPC instance of this embodiment deploys both a primary firewall device and a backup firewall device. In this case, it is necessary to create a target VIP (Virtual IP) instance in the subnet where the primary and backup firewall devices reside, and bind the target VIP instance to the address of the primary and backup firewall devices.
[0062] When the target VPC instance is deployed with both a primary firewall device and a backup firewall device, the above preset binding relationship is adjusted to: a binding relationship between the address of the target host providing external services and the address of the target VIP instance.
[0063] When both a primary firewall device and a backup firewall device are deployed in the target VPC instance, this embodiment forwards the request message in the following manner:
[0064] According to the preset binding relationship and the destination address in the request message, the request message is forwarded to the primary firewall device or the backup firewall device deployed on the target VPC instance, so that the firewall device that receives the request message performs a destination address conversion operation on the request message after confirming that the request message complies with the access control policy, and forwards the converted first message to the target host. The destination address conversion operation is: converting the destination address of the request message from the address of the target VIP instance to the address of the target host.
[0065] Accordingly, when the target VPC instance is deployed with both a primary firewall device and a backup firewall device, this embodiment specifically receives the response message in the following manner:
[0066] Receive a response message sent by the active firewall device or the backup firewall device, wherein the response message is obtained by the active firewall device or the backup firewall device after confirming that the second message complies with the access control policy and performing a source address translation operation on the second message. The second message is generated by the target host based on the first message and forwarded by the target host to the active firewall device or the backup firewall device according to the host route. The host route includes the next hop address to any network segment as the address of the target VIP instance. The source address translation operation is: converting the source address of the second message from the address of the target host to the address of the target VIP instance.
[0067] It is worth mentioning that in this embodiment, the firewall device deployed in the target VPC instance can perform access control for a specific business host in the target VPC instance, or it can perform access control for any business host in the target VPC instance. Therefore, the target host can be any host deployed in the target VPC instance.
[0068] As a specific implementation method, the address of the target host providing external services may be an elastic public IP (Elastic IP, EIP) address.
[0069] Example 2
[0070] Figure 5 This is a flow chart of the message forwarding method provided in the second embodiment of the present application, which is applied to a firewall device deployed in a target VPC instance, such as Figure 5 As shown, the method includes the following steps:
[0071] Step 510: Receive a request message sent by a routing device deployed in the target VPC instance;
[0072] The request message is initiated by the client to the target host deployed in the target VPC instance, received by the routing device from the client, and forwarded to the firewall device by the routing device based on the preset binding relationship and the destination address in the request message. The preset binding relationship is the binding relationship between the address of the target host providing external services and the address of the firewall device.
[0073] Step 520: Determine whether the request message complies with the access control policy. If yes, perform a destination address translation operation on the request message and send the converted first message to the target host.
[0074] The destination address translation operation is to translate the destination address of the request message from the address of the firewall device to the address of the target host.
[0075] Step 530: Receive a second message sent by the target host;
[0076] The second message is generated by the target host according to the first message, and is forwarded by the target host to the firewall device according to the host route. The host route includes a next hop address to any network segment, which is the address of the firewall device.
[0077] Step 540: Determine whether the second message complies with the access control policy. If yes, perform a source address translation operation on the second message and send the converted response message to the routing device, so that the routing device sends the response message to the client.
[0078] The source address translation operation is: translating the source address of the second message from the address of the target host to the address of the firewall device.
[0079] Example 3
[0080] Figure 6This is a flow chart of the message forwarding method provided in Example 3 of this application, which is applied to the target host deployed in the target VPC instance, such as Figure 6 As shown, the method includes the following steps:
[0081] Step 610: Receive a first message sent by a firewall device deployed in the target VPC instance;
[0082] Among them, the first message is obtained by the firewall device performing a destination address translation operation on the request message after confirming that the request message complies with the access control policy. The request message is initiated by the client to the target host deployed in the target VPC instance, received by the routing device from the client, and forwarded to the firewall device by the routing device according to the preset binding relationship and the destination address in the request message. The preset binding relationship is the binding relationship between the address of the target host providing external services and the address of the firewall device. The destination address translation operation is: converting the destination address of the request message from the address of the firewall device to the address of the target host.
[0083] Step 620: Generate a second message based on the first message, and send the second message to the firewall device according to the host route, so that the firewall device performs a source address translation operation on the second message after confirming that the second message complies with the access control policy, and sends the converted response message to the routing device.
[0084] The host route includes a next hop address to any network segment that is the address of the firewall device, and the source address translation operation is: translating the source address of the second message from the address of the target host to the address of the firewall device.
[0085] The following is a further explanation of the message forwarding method of the present application by taking a specific application scenario as an example in combination with the above-mentioned embodiment 1, embodiment 2 and embodiment 3.
[0086] In actual application, the network configuration is as follows Figure 7 As shown:
[0087] Create a target VPC instance on the cloud platform, create two subnets in the target VPC instance, record them as the first subnet and the second subnet, and create a switching device in each subnet.
[0088] Create a virtual machine in the first subnet, deploy the target service in the virtual machine, obtain the target host, and assign an IP address to the target host, such as Figure 7 192.168.1.2 is shown. Create an elastic public IP address as the public address for the target host to provide external services. Name it an EIP address and bind the EIP address to the IP address of the target host.
[0089] Create two virtual machines in the second subnet and deploy the firewall service in each virtual machine, resulting in two firewall devices. Assign an IP address from the second subnet to each firewall device and configure the gateway. In the second subnet, create a highly available VIP instance named "Target VIP Instance". The Target VIP instance contains an IP address 192.168.3.101 allocated from the second subnet. The Target VIP instance is bound to the IP addresses of the two firewall devices. Issue the master / slave configuration to the two firewall devices, set the virtual address in the master / slave configuration to the IP address of the Target VIP instance, set one firewall device as the master firewall device, and the other firewall device as the backup firewall device, and start configuration synchronization.
[0090] Unbind the EIP address from the target host's IP address and bind the EIP address to the target VIP instance's IP address.
[0091] Delete the default gateway of the target host. Create a host route on the target host, which includes the first custom route and the second custom route. The first custom route specifies that the target network segment is the second subnet, and the next hop address is the gateway of the first subnet (if the target host and the firewall device are in the same subnet, the first custom route is not necessary). The second custom route specifies that the target network segment is 0.0.0.0 / 0, which is any network segment, and the next hop address is the IP address of the target VIP instance.
[0092] Configure the source address translation policy and destination address translation policy on the active firewall. The source address translation policy performs source address translation, translating the source address of the second message from the target host's IP address to the target VIP instance's IP address. The destination address translation policy performs destination address translation, translating the destination address of the request message from the target VIP instance's IP address to the target host's IP address. Synchronize the source and destination address translation policies of the active firewall to the standby firewall.
[0093] In actual application, after the above network configuration, the message forwarding process is as follows Figure 8 As shown:
[0094] The client sends a request message. The source address of the request message is the client's IP address, and the destination address is the EIP address.
[0095] After the request message reaches the routing device of the target VPC instance, the routing device modifies the destination address of the request message to the IP address of the target VIP instance based on the preset binding relationship, that is, the binding relationship between the EIP address and the IP address of the target VIP instance, and forwards the modified request message to the firewall device based on the IP address of the target VIP instance.
[0096] After the request message arrives at the firewall device, the firewall device first determines whether the request message complies with the access control policy. If it is confirmed that the request message complies with the access control policy, the firewall device performs a destination address translation operation, converts the destination address of the request message from the IP address of the target VIP instance to the IP address of the target host, obtains the first message, and forwards the first message to the target host.
[0097] The first message arrives at the target host, and the target host generates a second message based on the first message, and then forwards the second message to the firewall device according to the host route. It can be understood that the second message generated by the target host is sent to the client, so the destination address of the second message is the client's IP address. Therefore, when the second message matches the route, it will prioritize matching the aforementioned second custom route, that is, the next hop address is the IP address of the target VIP instance. However, since the target host and the target VIP instance are not in the same subnet, the second message will match the route again and match the aforementioned first custom route, that is, the next hop address is the gateway of the first subnet. Therefore, the second message can be forwarded to the firewall device via the routing device.
[0098] After the second message arrives at the firewall device, the firewall device first determines whether the second message complies with the access control policy. If it is confirmed that the second message complies with the access control policy, the firewall device performs a source address translation operation, converts the source address from the IP address of the target host to the IP address of the target VIP instance, obtains a response message, and sends the response message to the routing device.
[0099] The response message arrives at the routing device. Based on the preset binding relationship, that is, the binding relationship between the target public network EIP address and the IP address of the target VIP instance, the routing device modifies the source address of the response message to the EIP address, and finally sends the modified response message to the client.
[0100] It can be seen from the above technical solutions that this application provides a message forwarding method that can utilize the basic resources of the cloud platform to realize firewall functions. There is no need to open a dedicated firewall business traffic channel within the cloud platform, nor is there any need for customized development based on the cloud platform to connect to the firewall.
[0101] Specifically, this application utilizes the feature that the business hosts in the cloud platform support host routing to deploy firewall services in the VPC instance to protect the various business hosts in the VPC instance. On the one hand, this implementation method facilitates the quick and easy connection of firewall capabilities to the cloud platform that supports cloud routing tables and forms protection capabilities, effectively reducing the difficulty of firewall delivery in cloud scenarios and shortening the firewall delivery cycle; on the other hand, since this implementation method deploys firewall services for each VPC instance of the cloud platform separately, rather than deploying one firewall service for the entire cloud platform, it is more flexible and can respond quickly and implement firewall capabilities in a timely manner at each customer delivery.
[0102] Based on the same inventive concept, the present application also provides a corresponding message forwarding device, which is introduced below.
[0103] Corresponding to the first embodiment described above, the present application provides a message forwarding device, which is applied to a routing device deployed in a target VPC instance, and includes:
[0104] A first routing receiving module is configured to receive a request message initiated by a client to a target host deployed in a target VPC instance;
[0105] a first routing and forwarding module, configured to forward the request message to a firewall device deployed in a target VPC instance based on a preset binding relationship and a destination address in the request message, so that the firewall device performs a destination address translation operation on the request message after confirming that the request message complies with an access control policy, and forwards the converted first message to a target host, wherein the preset binding relationship is a binding relationship between an address of a service provided externally by the target host and an address of the firewall device, and the destination address translation operation is to translate the destination address of the request message from the address of the firewall device to the address of the target host;
[0106] a second routing receiving module, configured to receive a response message sent by the firewall device, wherein the response message is obtained by the firewall device performing a source address translation operation on the second message after confirming that the second message complies with the access control policy, the second message is generated by the target host based on the first message, and is forwarded by the target host to the firewall device according to a host route, the host route including a next hop address to any network segment being the address of the firewall device, and the source address translation operation being: translating the source address of the second message from the address of the target host to the address of the firewall device;
[0107] The second routing forwarding module is used to forward the response message to the client according to the preset binding relationship and the destination address in the response message.
[0108] Corresponding to the second embodiment described above, the present application provides a message forwarding device, which is applied to a firewall device deployed in a target VPC instance, and includes:
[0109] a first firewall receiving module, configured to receive a request message sent by a routing device deployed in a target VPC instance, wherein the request message is initiated by a client to a target host deployed in the target VPC instance, is received by the routing device from the client, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message, wherein the preset binding relationship is a binding relationship between an address provided by the target host to provide external services and an address of the firewall device;
[0110] a first firewall forwarding module, configured to determine whether the request message complies with the access control policy; if so, to perform a destination address translation operation on the request message, and to send the converted first message to the target host; wherein the destination address translation operation is to translate the destination address of the request message from the address of the firewall device to the address of the target host;
[0111] a second firewall receiving module, configured to receive a second message sent by a target host, wherein the second message is generated by the target host based on the first message and forwarded by the target host to the firewall device according to a host route, wherein the host route includes a next hop address to any network segment that is an address of the firewall device;
[0112] The second firewall forwarding module is used to determine whether the second message complies with the access control policy. If the judgment result is yes, a source address translation operation is performed on the second message, and a response message obtained by the conversion is sent to the routing device, so that the routing device sends the response message to the client, wherein the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0113] Corresponding to the third embodiment described above, the present application provides a message forwarding device, which is applied to a target host deployed in a target VPC instance, and includes:
[0114] a host receiving module, configured to receive a first message sent by a firewall device deployed in a target VPC instance, wherein the first message is obtained by the firewall device performing a destination address translation operation on the request message after confirming that the request message complies with an access control policy; the request message is initiated by a client to a target host deployed in the target VPC instance, is received from the client by a routing device, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message; the preset binding relationship is a binding relationship between an address provided by the target host to an external service and an address of the firewall device; the destination address translation operation is to convert the destination address of the request message from the address of the firewall device to the address of the target host;
[0115] A host sending module is used to generate a second message based on the first message, and send the second message to the firewall device according to the host route, so that the firewall device performs a source address translation operation on the second message after confirming that the second message complies with the access control policy, and sends the converted response message to the routing device, wherein the host route includes a next hop address to any network segment as the address of the firewall device, and the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
[0116] The present application also provides an electronic device, such as Figure 9 As shown, it includes a processor 910 and a machine-readable storage medium 920, and the machine-readable storage medium 920 stores machine-executable instructions that can be executed by the processor 910. The processor 910 is prompted by the machine-executable instructions to implement the steps of any of the above-mentioned message forwarding methods.
[0117] The machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the machine-readable storage medium may be at least one storage device located remote from the processor.
[0118] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0119] In another embodiment provided by the present application, a computer-readable storage medium is further provided, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the steps of any of the above-mentioned message forwarding methods are implemented.
[0120] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A message forwarding method, characterized in that: The method is applied to a routing device deployed in a target VPC instance, and includes: Receive a request message initiated by a client to a target host deployed in the target VPC instance; forwarding the request message to a firewall device deployed in the target VPC instance based on a preset binding relationship and a destination address in the request message, so that the firewall device performs a destination address translation operation on the request message after confirming that the request message complies with an access control policy, and forwards the first message obtained by the translation to the target host, wherein the preset binding relationship is a binding relationship between an address of the target host providing external services and the address of the firewall device, and the destination address translation operation is to translate the destination address of the request message from the address of the firewall device to the address of the target host; receiving a response message sent by the firewall device, wherein the response message is obtained by the firewall device performing a source address translation operation on the second message after confirming that the second message complies with the access control policy, the second message is generated by the target host based on the first message and forwarded by the target host to the firewall device according to a host route, the host route including a next hop address to any network segment being the address of the firewall device, and the source address translation operation is to translate the source address of the second message from the address of the target host to the address of the firewall device; The response message is forwarded to the client according to the preset binding relationship and the destination address in the response message.
2. The method according to claim 1, characterized in that The target host is deployed in the first subnet of the target VPC instance, and the firewall device is deployed in the second subnet of the target VPC instance; The host route includes a next hop address to any network segment which is the address of the firewall device, and also includes a next hop address to the network segment where the firewall device is located which is the gateway address of the target host.
3. The method according to claim 1, characterized in that The method specifically forwards the request message in the following manner: According to the preset binding relationship and the destination address in the request message, the request message is forwarded to the primary firewall device or the backup firewall device deployed on the target VPC instance, so that the firewall device that receives the request message performs a destination address conversion operation on the request message after confirming that the request message complies with the access control policy, and forwards the converted first message to the target host, wherein the preset binding relationship is a binding relationship between the address of the target host providing services to the outside world and the address of the target VIP instance, the target VIP instance and the primary firewall device and the backup firewall device are in the same subnet, and there is a binding relationship between the target VIP instance and the address of the primary firewall device and the address of the backup firewall device, and the destination address conversion operation is: converting the destination address of the request message from the address of the target VIP instance to the address of the target host; The method specifically receives the response message in the following manner: Receive a response message sent by the active firewall device or the backup firewall device, wherein the response message is obtained by the active firewall device or the backup firewall device performing a source address conversion operation on the second message after confirming that the second message complies with the access control policy, the second message is generated by the target host based on the first message, and forwarded by the target host to the active firewall device or the backup firewall device according to the host route, the host route includes a next hop address to any network segment as the address of the target VIP instance, and the source address conversion operation is: converting the source address of the second message from the address of the target host to the address of the target VIP instance.
4. The method according to claim 1, wherein The target host is any host deployed in the target VPC instance.
5. A message forwarding method, characterized in that: The method is applied to a firewall device deployed in a target VPC instance, and includes: receiving a request message sent by a routing device deployed in the target VPC instance, wherein the request message is initiated by a client to a target host deployed in the target VPC instance, is received by the routing device from the client, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message, where the preset binding relationship is a binding relationship between an address of the target host providing external services and an address of the firewall device; Determine whether the request message complies with the access control policy, and if so, perform a destination address translation operation on the request message, and send the converted first message to the target host, wherein the destination address translation operation is: translating the destination address of the request message from the address of the firewall device to the address of the target host; receiving a second message sent by the target host, wherein the second message is generated by the target host based on the first message and forwarded by the target host to the firewall device according to a host route, wherein the host route includes a next hop address to any network segment that is an address of the firewall device; Determine whether the second message complies with the access control policy. If the judgment result is yes, perform a source address translation operation on the second message, and send the converted response message to the routing device, so that the routing device sends the response message to the client, wherein the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
6. A message forwarding method, characterized in that: The method is applied to a target host deployed in a target VPC instance, and the method includes: Receive a first message sent by a firewall device deployed on the target VPC instance, wherein the first message is obtained by the firewall device performing a destination address translation operation on the request message after confirming that the request message complies with the access control policy, the request message is initiated by a client to a target host deployed on the target VPC instance, is received from the client by a routing device, and is forwarded by the routing device to the firewall device based on a preset binding relationship and a destination address in the request message, the preset binding relationship being a binding relationship between an address of a service provided externally by the target host and the address of the firewall device, and the destination address translation operation is to convert the destination address of the request message from the address of the firewall device to the address of the target host; A second message is generated based on the first message, and the second message is sent to the firewall device based on the host route, so that the firewall device performs a source address translation operation on the second message after confirming that the second message complies with the access control policy, and sends a response message obtained by the conversion to the routing device, wherein the host route includes a next hop address to any network segment as the address of the firewall device, and the source address translation operation is: converting the source address of the second message from the address of the target host to the address of the firewall device.
7. The method according to claim 6, characterized in that The target host is deployed in the first subnet of the target VPC instance, and the firewall device is deployed in the second subnet of the target VPC instance. The method specifically sends the second message to the firewall device in the following manner: The second message is sent to the firewall device via the gateway device of the first subnet according to the host route, wherein the host route includes the next hop address to any network segment as the address of the firewall device, and also includes the next hop address to the network segment where the firewall device is located as the gateway address of the target host.
8. The method according to claim 6, characterized in that The method specifically receives the first message in the following manner: Receive a first message sent by a primary firewall device or a backup firewall device deployed on the target VPC instance, wherein the first message is obtained by the primary firewall device or the backup firewall device performing a destination address conversion operation on the request message after confirming that the request message complies with the access control policy. The request message is initiated by a client to a target host deployed on the target VPC instance, received by a routing device from the client, and forwarded by the routing device to the primary firewall device or the backup firewall device according to a preset binding relationship and the destination address in the request message. The preset binding relationship is a binding relationship between an address provided by the target host to the outside world and an address of a target VIP instance. The target VIP instance is in the same subnet as the primary firewall device and the backup firewall device, and there is a binding relationship between the target VIP instance and the address of the primary firewall device and the address of the backup firewall device. The destination address conversion operation is: converting the destination address of the request message from the address of the target VIP instance to the address of the target host; The method specifically sends the second message in the following manner: A second message is generated based on the first message, and the second message is sent to the active firewall device or the backup firewall device based on the host route, so that the active firewall device or the backup firewall device performs a source address conversion operation on the second message after confirming that the second message complies with the access control policy, and sends the converted response message to the routing device, wherein the host route includes the next hop address to any network segment as the address of the target VIP instance, and the source address conversion operation is: converting the source address of the second message from the address of the target host to the address of the target VIP instance.
9. An electronic device, characterized in that: The method comprises a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor is prompted by the machine-executable instructions to implement the method steps according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Transmission method and device for SDN network message
CN107733800A
Message forwarding method and device, firewall equipment and storage medium
CN113328946A