NAT (Network Address Translation) method and system for multiple independent IPs (Internet Protocol)

By establishing a public network IP address pool and a private network IP address pool, and performing IP conversion and port conversion, the problem that existing NAT technology cannot effectively manage multiple intranet devices is solved, and NAT conversion of multiple independent IPs is realized, improving the user experience.

CN119946013APending Publication Date: 2025-05-06深圳市宇泰科技有限公司 +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510116974.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing NAT technology cannot effectively manage multiple intranet devices, resulting in the intranet hosts with multiple public IP addresses in the same gateway, which is not good for users.

Method used

By establishing a public IP address pool and a private IP address pool, IP conversion and port conversion are performed, NAT conversion of multiple independent IPs is realized, allowing external network hosts to access multiple intranet hosts through multiple public IP addresses.

Benefits of technology

It realizes that external network hosts access multiple intranet hosts one-to-one through multiple different public IP addresses, reducing the number of hardware devices, reducing costs, and improving user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119946013A_ABST
    Figure CN119946013A_ABST
Patent Text Reader

Abstract

The invention provides an NAT (Network Address Translation) method and system for a plurality of independent IPs (Internet Protocol). The method comprises the following steps: establishing a public network IP address pool and a private network IP address pool; wherein a plurality of public network IP addresses exist in the public network IP address pool, and a plurality of private network IP addresses exist in the private network IP address pool; performing address conversion on the public network IP address and the private network IP address; an external network host on the Internet accesses the corresponding private network IP address through the public network IP address; the intranet host on the private network IP address communicates with the extranet host through the public network IP address; further, one or more WAN ports of the gateway are bound with a public network IP address pool, and a plurality of LAN ports of the gateway are bound with a private network IP address pool; a plurality of LAN ports of the gateway are respectively provided with a gateway address and start a DHCP service, and the gateway addresses of the plurality of LAN ports of the gateway are different; one gateway address corresponds to one public network IP address; therefore, the extranet host can access a plurality of intranet hosts in a one-to-one manner through a plurality of different public network IP addresses, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of communication networks, and in particular relates to a NAT conversion method and system for multiple independent IP addresses. Background Art

[0002] NAT technology is used to convert the intranet address and port number into a legal external network address and port number, and establish a session to communicate with the external network host. However, the host outside the NAT cannot actively communicate with the host inside the NAT, and must actively communicate with an external IP. The NAT gateway is responsible for establishing a mapping relationship to achieve data forwarding. In an industrial environment, the external network host needs to manage multiple intranet devices through different external network IPs. The existing NAT address conversion method cannot meet the needs, so it continues to be improved. Summary of the invention

[0003] In view of the above-mentioned deficiencies in the prior art, the purpose of the present invention is to provide a NAT conversion method and system for multiple independent IPs, aiming to solve the problem that the prior art cannot provide an effective NAT conversion method for multiple independent IPs, resulting in the inability to communicate with intranet hosts with multiple private IP addresses in the same gateway through multiple public IP addresses, resulting in poor user experience.

[0004] On the one hand, the present invention provides a NAT conversion method for multiple independent IPs, the method comprising the following steps:

[0005] Establish a public IP address pool and a private IP address pool; wherein the public IP address pool has multiple public IP addresses, and the private IP address pool has multiple private IP addresses;

[0006] Performing address conversion on the public IP address and the private IP address;

[0007] The external host on the Internet accesses the corresponding private IP address through the public IP address;

[0008] The intranet host on the private IP address communicates with the external host via the public IP address.

[0009] The method of the present invention further comprises:

[0010] Bind one or more WAN ports of the gateway to the public IP address pool, and bind multiple LAN ports of the gateway to the private IP address pool;

[0011] The address conversion includes: IP conversion and port conversion.

[0012] The method of the present invention further comprises: setting a gateway address for each of the multiple LAN ports of the gateway and starting a DHCP service, wherein the gateway addresses of the multiple LAN ports of the gateway are different;

[0013] The gateway address corresponds to the public IP address.

[0014] The method of the present invention further comprises: setting the same gateway address for multiple LAN ports of the gateway and starting the DHCP service;

[0015] The public IP address and the private IP address are dynamically allocated to perform one-to-one address conversion, or multiple public IP addresses and the private IP addresses are dynamically allocated to perform many-to-one address conversion.

[0016] The method of the present invention further includes: the dynamically allocating multiple public IP addresses and the private IP addresses to perform many-to-one address conversion includes:

[0017] One or more ports of the private IP address are allocated to multiple public IP addresses for address conversion.

[0018] The method of the present invention further includes: dynamically allocating multiple public IP addresses and the private IP address to perform many-to-one address conversion when the bandwidth of a port of the private IP address exceeds the rated bandwidth.

[0019] The method of the present invention, wherein the method further comprises: the method further comprises:

[0020] An address translation mapping table is set to record a plurality of mapping relationships, wherein the mapping relationship includes: an IP translation relationship and a port translation relationship between the public network IP address and the private network IP address;

[0021] According to the address conversion mapping table, the public IP address and the private IP address are dynamically allocated to perform one-to-one address conversion, or multiple public IP addresses and the private IP addresses are dynamically allocated to perform many-to-one address conversion.

[0022] The method of the present invention, wherein the method further comprises: the method further comprises:

[0023] Scan and verify whether the mapping relationship continues to exist according to the address conversion mapping table, and if not, reclaim the public network IP address and port in the mapping relationship.

[0024] The method of the present invention, wherein the method further comprises: the method further comprises:

[0025] After the existence time of the mapping relationship exceeds the rated time, the public IP address in the mapping relationship is preferentially continued to be allocated to the private IP address in the mapping relationship.

[0026] On the other hand, the present invention also provides a NAT conversion system for multiple independent IPs, the system comprising at least one processor; and

[0027] a memory communicatively connected to the at least one processor; wherein,

[0028] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the above-mentioned NAT conversion method for multiple independent IPs.

[0029] The beneficial effects of the present invention are as follows: a public IP address pool and a private IP address pool are established; wherein, there are multiple public IP addresses in the public IP address pool, and there are multiple private IP addresses in the private IP address pool; address conversion is performed on the public IP address and the private IP address; an external host on the Internet accesses the corresponding private IP address through the public IP address; an intranet host on the private IP address communicates with the external host through the public IP address; further, one or more WAN ports of the gateway are bound to the public IP address pool, and multiple LAN ports of the gateway are bound to the private IP address pool; multiple LAN ports of the gateway are all set with a gateway address and DHCP service is turned on, and the gateway addresses of the multiple LAN ports of the gateway are all different; one gateway address corresponds to one public IP address; thereby realizing one-to-one access of the external host to multiple intranet hosts through multiple different public IP addresses, reducing the number of hardware devices, reducing costs, and thus improving user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 This is a flowchart of the implementation of the NAT conversion method for multiple independent IPs provided in the first embodiment of the present invention;

[0031] Figure 2 It is a structural diagram of a NAT conversion system for multiple independent IPs provided in Embodiment 2 of the present invention. DETAILED DESCRIPTION

[0032] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0033] The specific implementation of the present invention is described in detail below in conjunction with specific embodiments:

[0034] Embodiment 1:

[0035] In step S101, a public IP address pool and a private IP address pool are established; wherein the public IP address pool contains multiple public IP addresses, and the private IP address pool contains multiple private IP addresses;

[0036] In an embodiment of the present invention, the method further comprises: binding one or more WAN ports of the gateway to a public IP address pool, and binding multiple LAN ports of the gateway to a private IP address pool;

[0037] Preferably, a gateway address is set for each of the multiple LAN ports of the gateway and the DHCP service is turned on. The gateway addresses of the multiple LAN ports of the gateway are different. One gateway address corresponds to one public IP address, which is suitable for use when one LAN port is plugged into an intranet host and one intranet host corresponds to one public IP address. The gateway can be a soft router.

[0038] In step S102, address conversion is performed on the public IP address and the private IP address;

[0039] In the embodiment of the present invention, address translation includes: IP translation and port translation.

[0040] In step S103, the external host on the Internet accesses the corresponding private IP address through the public IP address;

[0041] In an embodiment of the present invention, a forward proxy is implemented.

[0042] In step S104, the intranet host at the private IP address communicates with the external host via the public IP address.

[0043] In an embodiment of the present invention, access to the Internet is achieved through a public IP address.

[0044] In an embodiment of the present invention, further, multiple LAN ports of the gateway are all set with the same gateway address and the DHCP service is enabled;

[0045] Dynamically allocate public IP addresses and private IP addresses for one-to-one address translation, or dynamically allocate multiple public IP addresses and private IP addresses for many-to-one address translation.

[0046] Among them, dynamically allocating multiple public IP addresses and private IP addresses for many-to-one address conversion includes: allocating one or more ports of the private IP address to multiple public IP addresses for address conversion; performing diversion control and load balancing to meet different usage requirements.

[0047] Furthermore, when the bandwidth of one port of a private IP address exceeds the rated bandwidth, multiple public IP addresses and private IP addresses are dynamically allocated to perform many-to-one address conversion; it is suitable for traffic diversion when the gateway has multiple WAN ports and each WAN port is bound to at least one public IP address / broadband.

[0048] Preferably, the method further comprises: setting an address translation mapping table to record a plurality of mapping relationships, the mapping relationships comprising: an IP translation relationship and a port translation relationship between a public network IP address and a private network IP address;

[0049] Dynamically allocate public IP addresses and private IP addresses according to the address translation mapping table for one-to-one address translation, or dynamically allocate multiple public IP addresses and private IP addresses for many-to-one address translation; avoid repeated allocation of public IP addresses and ports.

[0050] Furthermore, the method also includes: scanning and verifying whether the mapping relationship continues to exist according to the address conversion mapping table, and if not, reclaiming the public network IP address and port in the mapping relationship; and performing dynamic updates to avoid long-term occupation of the public network IP address and port.

[0051] Preferably, the method also includes: after the existence time of the mapping relationship exceeds the rated time, the public IP address in the mapping relationship is continued to be allocated to the private IP address in the mapping relationship first, so as to avoid frequent switching of public IP addresses causing network freezes.

[0052] In an embodiment of the present invention, a public IP address pool and a private IP address pool are established; wherein, there are multiple public IP addresses in the public IP address pool, and there are multiple private IP addresses in the private IP address pool; address conversion is performed on the public IP address and the private IP address; an external host on the Internet accesses the corresponding private IP address through the public IP address; an intranet host on the private IP address communicates with the external host through the public IP address; further, one or more WAN ports of the gateway are bound to the public IP address pool, and multiple LAN ports of the gateway are bound to the private IP address pool; multiple LAN ports of the gateway are all set with a gateway address and the DHCP service is turned on, and the gateway addresses of the multiple LAN ports of the gateway are all different; one gateway address corresponds to one public IP address; thereby achieving one-to-one access of the external host to multiple intranet hosts through multiple different public IP addresses, reducing the number of hardware devices, reducing costs, and thereby improving user experience.

[0053] Embodiment 2:

[0054] Figure 2 A NAT conversion system for multiple independent IPs provided by the second embodiment of the present invention is shown. Figure 2 As shown, the device 10 includes:

[0055] One or more processors 110 and memory 120, Figure 2 A processor 110 is used as an example for description. The processor 110 and the memory 120 may be connected via a bus or other means. Figure 2 The example of connecting through bus is taken in the following.

[0056] The processor 110 is used to complete various control logics of the device 10, and it can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a single-chip microcomputer, an ARM (Acorn RISCMachine) or other programmable logic device, a discrete gate or transistor logic, a discrete hardware component, or any combination of these components. In addition, the processor 110 can also be any traditional processor, microprocessor or state machine. The processor 110 can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.

[0057] The memory 120, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs and modules, such as program instructions corresponding to the NAT conversion method for multiple independent IPs in the embodiment of the present invention. The processor 110 executes various functional applications and data processing of the device 10 by running the non-volatile software programs, instructions and units stored in the memory 120, that is, the NAT conversion method for multiple independent IPs in the above method embodiment is implemented.

[0058] The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store applications required for operating the device and at least one function; the data storage area may store data created according to the use of the device 10, etc. In addition, the memory 120 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 120 may optionally include a memory remotely arranged relative to the processor 110, and these remote memories may be connected to the device 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0059] One or more units are stored in the memory 120, and when executed by one or more processors 110, the NAT conversion method for multiple independent IPs in any of the above method embodiments is executed, for example, the above described method is executed. Figure 1 The method comprises steps S101 to S104.

[0060] Embodiment three:

[0061] Embodiment 3 of the present invention provides a non-volatile computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are executed by one or more processors, for example, to execute the above-described Figure 1 The method comprises steps S101 to S104.

[0062] As an example, the non-volatile storage medium can include a read-only memory (ROM), a programmable ROM (PROM), an electrically programmable ROM (EPROM), an electrically erasable ROM (EEPROM), or a flash memory. Volatile memory can include a random access memory (RAM) as an external cache memory. By way of illustration and not limitation, RAM can be obtained in many forms such as synchronous RAM (SRAM), dynamic RAM, (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), and direct Rambus RAM (DRRAM). The disclosed memory components or memories of the operating environment described herein are intended to include one or more of these and / or any other suitable types of memory.

[0063] Embodiment 4:

[0064] Embodiment 4 of the present invention provides a computer program product, which includes a computer program stored on a non-volatile computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a processor, the processor executes the NAT conversion method for multiple independent IP addresses of the above method embodiment. For example, the above described Figure 1 The method comprises steps S101 to S104.

[0065] The embodiments described above are merely illustrative, in which the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0066] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product can exist in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer electronic device (which can be a personal computer, a server, or a network electronic device, etc.) to execute the methods of each embodiment or some parts of the embodiment.

[0067] Conditional language such as "can," "can," "might," or "may," among other things, unless specifically stated otherwise or otherwise understood within the context as used, is generally intended to convey that particular embodiments can include (while other embodiments do not) particular features, elements, and / or operations. Thus, such conditional language is generally not intended to imply that features, elements, and / or operations are in any way required for one or more embodiments or that one or more embodiments must include logic for determining whether such features, elements, and / or operations are included or will be performed in any particular embodiment, with or without student input or prompting.

[0068] What has been described herein in this specification and the accompanying drawings includes examples of NAT conversion methods and systems that can provide multiple independent IPs. Of course, it is not possible to describe every conceivable combination of elements and / or methods for the purpose of describing the various features of the present disclosure, but it can be recognized that many other combinations and permutations of the disclosed features are possible. Therefore, it is obvious that various modifications can be made to the present disclosure without departing from the scope or spirit of the present disclosure. In addition, or in an alternative, other embodiments of the present disclosure may be obvious from consideration of this specification and the accompanying drawings and from the practice of the present disclosure as presented herein. It is intended that the examples proposed in this specification and the accompanying drawings are considered to be illustrative and not restrictive in all respects. Although specific terms are used in this article, they are used in a general and descriptive sense and are not used for limiting purposes.

Claims

1. A NAT conversion method for multiple independent IPs, characterized in that: The method comprises the following steps: Establish a public IP address pool and a private IP address pool; wherein the public IP address pool has multiple public IP addresses, and the private IP address pool has multiple private IP addresses; Performing address conversion on the public IP address and the private IP address; The external host on the Internet accesses the corresponding private IP address through the public IP address; The intranet host on the private IP address communicates with the external host via the public IP address.

2. The method according to claim 1, characterized in that The method further comprises: Bind one or more WAN ports of the gateway to the public IP address pool, and bind multiple LAN ports of the gateway to the private IP address pool; The address conversion includes: IP conversion and port conversion.

3. The method according to claim 2, characterized in that A gateway address is set for each of the multiple LAN ports of the gateway and a DHCP service is enabled, and the gateway addresses of the multiple LAN ports of the gateway are different; The gateway address corresponds to the public IP address.

4. The method according to claim 2, characterized in that The multiple LAN ports of the gateway are all set with the same gateway address and the DHCP service is enabled; The public IP address and the private IP address are dynamically allocated to perform one-to-one address conversion, or multiple public IP addresses and the private IP addresses are dynamically allocated to perform many-to-one address conversion.

5. The method according to claim 4, characterized in that The dynamically allocating multiple public IP addresses and the private IP address to perform many-to-one address conversion includes: One or more ports of the private IP address are allocated to multiple public IP addresses for address conversion.

6. The method according to claim 5, characterized in that When the bandwidth of a port of the private IP address exceeds the rated bandwidth, a plurality of the public IP addresses are dynamically allocated to perform many-to-one address conversion with the private IP address.

7. The method according to claim 2, characterized in that The method further comprises: An address translation mapping table is set to record a plurality of mapping relationships, wherein the mapping relationship includes: an IP translation relationship and a port translation relationship between the public network IP address and the private network IP address; According to the address conversion mapping table, the public IP address and the private IP address are dynamically allocated to perform one-to-one address conversion, or multiple public IP addresses and the private IP addresses are dynamically allocated to perform many-to-one address conversion.

8. The method according to claim 7, characterized in that The method further comprises: Scan and verify whether the mapping relationship continues to exist according to the address conversion mapping table, and if not, reclaim the public network IP address and port in the mapping relationship.

9. The method according to claim 8, characterized in that The method further comprises: After the existence time of the mapping relationship exceeds the rated time, the public IP address in the mapping relationship is preferentially continued to be allocated to the private IP address in the mapping relationship.

10. A NAT conversion system for multiple independent IPs, characterized in that: The system includes at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the NAT conversion method for multiple independent IPs as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Method for private network customer to access public network using public network address

    CN101360030A

  • Method and device of accessing main engine of isolation region in local area network

    CN103095705A

  • Method and system for configuring NAT aging duration and NAT device

    CN109962988A

  • NAT conversion method and device, computer equipment and storage medium

    CN112040029A

  • Method for determining public network address of MPTCP server and communication device

    CN114095474A