Route selection method, system and device
The method addresses the challenge of selecting the appropriate network outlet for domain name-based communication by using pre-defined rules and DNS servers to create data packet forwarding rules, ensuring efficient and accurate routing between terminal devices and servers.
Patent Information
- Application Number
- CN202510124698.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-13
AI Technical Summary
Existing technologies fail to effectively select the most appropriate network outlet for communication interactions between terminal devices and target servers when multiple network outlets are available, especially when domain names are used in access requests.
A method and system for route selection that involves matching domain names with pre-defined rules to determine the appropriate network outlet, utilizing DNS servers and creating data packet forwarding rules to ensure efficient communication.
Ensures efficient and accurate routing of data packets between terminal devices and target servers by selecting the optimal network outlet based on domain name rules, reducing the need for frequent domain name resolution and enhancing communication efficiency.
Smart Images

Figure CN119996302A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network technology, and in particular to a routing selection method, system and device. Background Art
[0002] With the development of Internet technology, people can conduct information search and remote office operations through the Internet, which has brought great convenience to daily work and life. This is inseparable from the communication interaction between devices, such as the communication interaction between terminal devices and the server corresponding to the search engine, the communication interaction between terminal devices and remote devices, and so on.
[0003] In the related art, when there are multiple network exits, for the access request of the terminal device to the device to be accessed, the corresponding network exit will be selected according to the destination IP (Internet Protocol) for forwarding processing. However, the access request may not necessarily carry the destination IP of the device to be accessed. If the access request carries the domain name of the device to be accessed, the access request cannot be diverted, and the network exit assigned by default or randomly assigned may not be suitable for the communication interaction between the terminal device and the device to be accessed. Summary of the invention
[0004] The purpose of the embodiments of the present application is to provide a routing selection method, system and device to solve the problem that when there are multiple network exits, the most appropriate network exit cannot be selected according to the domain name to be accessed.
[0005] To solve the above technical problems, the embodiments of the present application are implemented as follows: On the one hand, an embodiment of the present application provides a routing selection method, which is applied to a first network device, wherein the first network device is connected to a second network device having multiple network exits; the method includes: receiving a domain name resolution request from a terminal device forwarded by the second network device; the domain name resolution request includes a domain name to be accessed; In a case where the domain name to be accessed matches a pre-created domain name rule, determining a target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device; Forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server; When the domain name resolution response matches the domain name rule, a corresponding data packet forwarding rule is created, and the response result to the domain name resolution request is returned to the terminal device through the second network device; the data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed.
[0006] On the other hand, an embodiment of the present application provides a routing selection method, which is applied to a second network device having multiple network exits, and the second network device is connected to the first network device; the method includes: Receiving a domain name resolution request from a terminal device; the domain name resolution request includes a domain name to be accessed; forwarding the domain name resolution request to the first network device; the first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule, and obtain a domain name resolution response through the target DNS server corresponding to the target network exit; Receiving a response result to the domain name resolution request sent by the first network device based on the domain name resolution response; the response result carries a first connection element; the first connection element includes a MAC address corresponding to the target network exit and a source IP address of the terminal device; Determine, according to the first connection element, a target network connection to which the response result belongs; create and store a second corresponding relationship between the target network connection and a target exit identifier corresponding to the target network exit; The response result is returned to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
[0007] On the other hand, an embodiment of the present application provides a routing selection system, comprising a first network device and a second network device having a plurality of network exits, wherein the first network device is connected to the second network device; wherein: The second network device is used to receive a domain name resolution request from a terminal device, and forward the domain name resolution request to the first network device; the domain name resolution request includes a domain name to be accessed; The first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule; forward the domain name resolution request to the target DNS server corresponding to the target network exit, and receive the domain name resolution response returned by the target DNS server; create a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and forward the response result for the domain name resolution request to the second network device; the data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed; The second network device is also used to determine the target network connection to which the response result belongs based on the first connection element carried by the response result; the first connection element includes the MAC address corresponding to the target network exit and the source IP address of the terminal device; create and store a second correspondence between the target network connection and the target exit identifier corresponding to the target network exit; return the response result to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be visited according to the response result.
[0008] In another aspect, an embodiment of the present application provides a routing selection device, which is applied to a first network device, wherein the first network device is connected to a second network device having multiple network exits; the device comprises: A first receiving module, configured to receive a domain name resolution request from a terminal device forwarded by the second network device; the domain name resolution request includes a domain name to be accessed; A first determination module is used to determine the target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule; A forwarding and receiving module, used to forward the domain name resolution request to a target DNS server corresponding to the target network exit, and receive a domain name resolution response returned by the target DNS server; A creation and return module is used to create a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and return the response result for the domain name resolution request to the terminal device through the second network device; the data packet forwarding rule is used to control the routing of the data packet between the terminal device and the website server corresponding to the domain name to be accessed.
[0009] On the other hand, an embodiment of the present application provides a routing selection device, which is applied to a second network device having multiple network exits, and the second network device is connected to the first network device; the device includes: A second receiving module is used to receive a domain name resolution request from a terminal device; the domain name resolution request includes a domain name to be accessed; A first forwarding module, configured to forward the domain name resolution request to the first network device; the first network device is configured to determine a target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches a pre-created domain name rule, and obtain a domain name resolution response through a target DNS server corresponding to the target network exit; A third receiving module is used to receive a response result to the domain name resolution request sent by the first network device based on the domain name resolution response; the response result carries a first connection element; the first connection element includes a MAC address corresponding to the target network exit and a source IP address of the terminal device; A determination and creation module, configured to determine, based on the first connection element, a target network connection to which the response result belongs; and to create and store a second correspondence between the target network connection and a target exit identifier corresponding to the target network exit; The response result returning module is used to return the response result to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
[0010] On the other hand, an embodiment of the present application provides a network device, including a processor and a memory electrically connected to the processor, the memory storing a computer program, the processor being used to call and execute the computer program from the memory to implement the above-mentioned routing selection method applied to the first network device, or the processor being used to call and execute the computer program from the memory to implement the above-mentioned routing selection method applied to a second network device having multiple network exits.
[0011] On the other hand, an embodiment of the present application provides a storage medium for storing a computer program, wherein the computer program can be executed by a processor to implement the above-mentioned routing selection method applied to a first network device, or the computer program can be executed by a processor to implement the above-mentioned routing selection method applied to a second network device having multiple network exits.
[0012] According to the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device forwarded by a second network device is received by a first network device, and the domain name to be accessed in the domain name resolution request is matched with a pre-created domain name rule. When the two match, it can be determined that the domain name resolution request needs to determine the network exit in a targeted manner, thereby determining the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device, forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server, and creating a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and then returning the response result of the domain name resolution request to the terminal device through the second network device. It can be seen that the technical solution realizes the effect of diverting the domain name resolution request from the terminal device according to the domain name, so that the terminal device can communicate and interact with the website server corresponding to the domain name to be accessed through the most appropriate network exit, providing a channel basis for the terminal device to successfully access the website server. Furthermore, by creating data packet forwarding rules, data packets between the terminal device and the website server corresponding to the domain name to be accessed can be routed based on this data packet forwarding rule without the need for frequent domain name resolution, thereby ensuring efficient communication between the terminal device and the website server corresponding to the domain name to be accessed.
[0013] By adopting the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device is received by a second network device, and the domain name resolution request is forwarded to the first network device. Thus, a response result to the domain name resolution request sent by the first network device based on the domain name resolution response is received, and the target network connection to which the response result belongs is determined according to the first connection element carried by the response result, and a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit is created and stored. Then, the response result is returned to the terminal device, so that the terminal device can send an access data packet to the website server corresponding to the domain name to be accessed according to the response result. In this way, for the data packet between the terminal device and the website server, the corresponding exit identifier can be determined according to the network connection to which the data packet belongs, thereby determining the corresponding network exit, which is conducive to realizing fast and accurate routing of the data packet between the terminal device and the website server. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0015] Figure 1 is a schematic block diagram of a routing selection system according to an embodiment of the present application; Figure 2 is a schematic flow chart of a routing selection method according to an embodiment of the present application; Figure 3 is a schematic flow chart of a process of processing a domain name resolution response according to an embodiment of the present application; Figure 4 is a schematic flow chart of a routing selection method according to another embodiment of the present application; Figure 5 is a schematic flow chart of a routing selection method according to another embodiment of the present application; Figure 6 is a structural diagram of a routing selection device according to an embodiment of the present application; Figure 7 is a structural schematic diagram of a routing selection device according to another embodiment of the present application; Figure 8 It is a schematic diagram of the hardware structure of a network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0016] The embodiments of the present application provide a routing selection method, system and device to solve the problem in the related art that when there are multiple network exits, the most appropriate network exit cannot be selected according to the domain name to be accessed.
[0017] In order to enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.
[0018] Figure 1 FIG. 1 is a schematic block diagram of a routing selection system according to an embodiment of the present application. Figure 1 As shown, the routing system includes a first network device 110 and a second network device 120 having multiple network exits. The first network device 110 is connected to the second network device 120. The multiple network exits of the second network device 120 include network exit 1, network exit 2, ..., network exit N. The number of network exits of the second network device can be determined according to the specific application scenario, and the embodiment of the present application does not limit this.
[0019] Optionally, the first network device and the second network device having multiple network exits may be connected by accessing the same bridge device.
[0020] In this embodiment, the second network device 120 is used to receive a domain name resolution request from a terminal device, and forward the domain name resolution request to the first network device 110. The domain name resolution request includes a domain name to be accessed.
[0021] In this embodiment, the first network device 110 is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device 120 when the domain name to be accessed matches the pre-created domain name rule. The domain name resolution request is forwarded to the target DNS (Domain Name System) server corresponding to the target network exit, and the domain name resolution response returned by the target DNS server is received. When the domain name resolution response matches the domain name rule, a corresponding data packet forwarding rule is created, and the response result for the domain name resolution request is forwarded to the second network device 120. The data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed.
[0022] In this embodiment, the second network device 120 is also used to determine the target network connection to which the response result belongs based on the first connection element carried by the response result. The first connection element includes a MAC (Media Access Control) address corresponding to the target network exit and a source IP address of the terminal device. A second correspondence between the target network connection and the target exit identifier corresponding to the target network exit is created and stored. The response result is returned to the terminal device so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed based on the response result.
[0023] The first network device and the second network device may be physical servers or may be implemented using virtualization technology. If they are physical servers, the first network device is a physical server and the second network device is a physical server. If they are implemented using virtualization technology, the namespace of Linux (multi-user network operating system) may be used to integrate the first network device and the second network device on a single device.
[0024] The following describes the specific operations performed by the first network device 110 and the second network device 120 in the routing system during the interaction between the terminal device and the website server corresponding to the domain name to be accessed.
[0025] like Figure 2 FIG. 1 is a schematic flow chart of a routing selection method according to an embodiment of the present application, which is applied to Figure 1 The first network device is connected to a second network device having a plurality of network exits. Figure 2 The methods include: S202, receiving a domain name resolution request from a terminal device forwarded by a second network device, where the domain name resolution request includes a domain name to be accessed.
[0026] The domain name to be accessed may be a domain name of a website, a domain name of a client system, etc., which is not limited in the present embodiment. The terminal device is a user-side device, and the user can send a domain name resolution request through the terminal device.
[0027] Optionally, the domain name resolution request may also include the type of domain name record returned by the request. The type of domain name record returned by the request may be an A record or an AAAA record. An A record is used to specify the correspondence between a domain name and an IPv4 (Internet Protocol version 4) address. An AAAA record is used to specify the correspondence between a domain name and an IPv6 (Internet Protocol version 6) address.
[0028] S204: When the domain name to be accessed matches the pre-created domain name rule, determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device.
[0029] For example, Company A itself has network exit A, but the relevant pages of Company B and Company C only authorize network exit B or network exit C. In view of this situation, the routing selection method provided in the embodiment of the present application can be used to pre-set the domain name rule "**.example-b.com" of Company B, set the domain name rule "**.example-c.com" of Company C, and create a first correspondence between "**.example-b.com" and network exit B, and create a first correspondence between "**.example-c.com" and network exit C. In this way, when the domain name to be accessed matches "**.example-b.com", according to the pre-created first correspondence, it can be determined that the target network exit corresponding to the domain name resolution request is network exit B. When the domain name to be accessed matches "**.example-c.com", according to the pre-created first correspondence, it can be determined that the target network exit corresponding to the domain name resolution request is network exit C.
[0030] Optionally, a first correspondence between each domain name in the domain name rule and one or more network exits of the second network device can be created in advance. Continuing with the above example, Company A has network exits A, B, C, and D, network exit A is the default network exit, network exit B and D are both network exits for accessing Company B, network exit B has a higher priority than network exit D, and network exit C is the network exit for accessing Company C. Then, a first correspondence between "**.example-b.com" and network exit B can be created in advance, a first correspondence between "**.example-c.com" and network exit C can be created, and a first correspondence between "**.example-b.com" and network exit D can be created. In this way, when the domain name to be accessed matches "**.example-b.com", according to the first correspondence created in advance, the network exit B with a higher priority can be selected as the target network exit corresponding to the domain name resolution request according to the priority. In the case where network exit B is unavailable, network exit D can be selected as the target network exit corresponding to the domain name resolution request.
[0031] In this embodiment, when the domain name to be accessed does not match the pre-created domain name rule, it is determined that the network exit corresponding to the domain name resolution request is the default network exit of the second network device.
[0032] S206, forwarding the domain name resolution request to a target DNS server corresponding to the target network exit, and receiving a domain name resolution response returned by the target DNS server.
[0033] The target DNS server is used to respond to the domain name resolution request and return a domain name resolution response that is consistent with the domain name record type requested by the terminal device. The domain name resolution response may include the IP address corresponding to the domain name to be accessed.
[0034] When the network exit corresponding to the domain name resolution request is the default network exit, the domain name resolution request can be forwarded to the DNS server corresponding to the default network exit through the default network exit, so as to perform domain name resolution through the DNS server.
[0035] Optionally, the target DNS server may be a DNS server with a different configuration from the DNS server corresponding to the default network exit. The user may configure the target DNS server so that the target DNS server returns a domain name resolution response consistent with the domain name record type requested by the terminal device.
[0036] For example, an A record may be added to the target DNS server so that the target DNS server can resolve the corresponding IPv4 address based on the received domain name; an AAAA record may be added to the target DNS server so that the target DNS server can resolve the corresponding IPv6 address based on the received domain name; a CNAME (Canonical Name) record may be added to the target DNS server so that the target DNS server can resolve the alias domain name pointed to by the received domain name, and further resolve the IP address corresponding to the alias domain name finally pointed to.
[0037] By adding A records and / or AAAA records, you can bind a domain name to a server address. For example, you can resolve the domain name abc.com to the IP address 192.0.2.2, so that when you visit abc.com, you will visit the website on the 192.0.2.2 server. By adding a CNAME record, you can map a domain name or subdomain to another complete domain name. For example, map a domain name www.example.com to another domain name mail.example.com, so that when a user visits www.example.com, he will actually visit the server or service pointed to by mail.example.com.
[0038] Compared with A records, AAAA records are mainly used to support IPv6 network environments. In actual applications, A records and AAAA records can coexist, and websites can support both IPv4 and IPv6 access as needed. For example, a website can set A records to support IPv4 user access and set AAAA records to support IPv6 user access to ensure compatibility and wide access.
[0039] S208: When the domain name resolution response matches the domain name rule, a corresponding data packet forwarding rule is created, and a response result to the domain name resolution request is returned to the terminal device through the second network device.
[0040] Among them, the data packet forwarding rules are used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed. The data packet forwarding rules may include the source IP address of the terminal device, the destination IP address corresponding to the domain name to be accessed, and the access timeout between the terminal device and the website server corresponding to the domain name to be accessed. By creating data packet forwarding rules, the access data packet of the terminal device to the website server corresponding to the domain name to be accessed, which flows to the first network device, can be sent through the target network exit within the access timeout. If the access timeout is exceeded, no forwarding is performed. At this time, measures such as error reporting and prompting can be taken to prompt the terminal device to send a domain name resolution request for the website server corresponding to the domain name to be accessed again.
[0041] Optionally, the domain name to be accessed corresponding to the domain name resolution response may be matched with the domain name rule. If they match, it means that the domain name resolution response is a response corresponding to the domain name resolution request that requires targeted determination of the network exit.
[0042] Optionally, when the type of domain name record requested to be returned in the domain name resolution request is an A record, if the domain name resolution response is an A record, the resolved IPv4 address can be returned to the terminal device as a response result; if the domain name resolution response is an alias record, the domain name pointed to by the alias record needs to be resolved again until the A record is resolved, and the resolved IPv4 address is returned to the terminal device as a response result.
[0043] Optionally, when the type of domain name record requested to be returned in the domain name resolution request is an AAAA record, if the domain name resolution response is an AAAA record, the resolved IPv6 address can be returned to the terminal device as a response result; if the domain name resolution response is an alias record, the domain name pointed to by the alias record needs to be resolved again until the AAAA record is resolved, and the resolved IPv6 address is returned to the terminal device as a response result.
[0044] According to the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device forwarded by a second network device is received by a first network device, and the domain name to be accessed in the domain name resolution request is matched with a pre-created domain name rule. When the two match, it can be determined that the domain name resolution request needs to determine the network exit in a targeted manner, thereby determining the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device, forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server, and creating a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and then returning the response result of the domain name resolution request to the terminal device through the second network device. It can be seen that the technical solution realizes the effect of diverting the domain name resolution request from the terminal device according to the domain name, so that the terminal device can communicate and interact with the website server corresponding to the domain name to be accessed through the most appropriate network exit, providing a channel basis for the terminal device to successfully access the website server. Furthermore, by creating data packet forwarding rules, data packets between the terminal device and the website server corresponding to the domain name to be accessed can be routed based on this data packet forwarding rule without the need for frequent domain name resolution, thereby ensuring efficient communication between the terminal device and the website server corresponding to the domain name to be accessed.
[0045] In one embodiment, the domain name resolution response may include a first A record or a first AAAA record, and the domain name resolution request may include a source IP address of the terminal device.
[0046] In this embodiment, when the domain name resolution response matches the domain name rule, a corresponding data packet forwarding rule is created (ie, S208), and the following steps A1 to A4 may be performed: Step A1, determining the destination IP address corresponding to the domain name to be accessed according to the first A record or the first AAAA record.
[0047] Wherein, when the domain name resolution response is the first A record, it can be determined that the destination IP address corresponding to the domain name to be accessed is an IPv4 address. When the domain name resolution response is the first AAAA record, it can be determined that the destination IP address corresponding to the domain name to be accessed is an IPv6 address.
[0048] Step A2: When the IP protocol versions of the source IP address and the destination IP address are consistent, determine the first lifetime of the domain name resolution response.
[0049] Among them, when the IP protocol versions of the source IP address and the destination IP address are both IPv4, or when the IP protocol versions of the source IP address and the destination IP address are both IPv6, it can be determined that the IP protocol versions of the source IP address and the destination IP address are consistent.
[0050] The expiration time is the cache time of the correspondence between the domain name to be accessed and the destination IP address on the target DNS server. Within the expiration time, the target DNS server can quickly return the domain name resolution response corresponding to the domain name to be accessed. If it exceeds (i.e. is greater than) the expiration time, a recursive query of the global DNS is required to determine the domain name resolution response corresponding to the domain name to be accessed.
[0051] Step A3: determining a first access timeout period between the terminal device and the website server according to the first survival period of the domain name resolution response.
[0052] Optionally, the first lifetime of the domain name resolution response can be directly determined as the first access timeout between the terminal device and the website server. In actual applications, the lifetime of the domain name resolution response may not meet the interaction time requirement between the terminal device and the website server. For example, the lifetime of the domain name resolution response is 200 seconds, while the interaction time requirement between the terminal device and the website server is greater than 200 seconds. At this time, in order to ensure the high efficiency of the communication interaction between the terminal device and the website server, the access timeout between the terminal device and the website server can be determined based on the lifetime of the domain name resolution response and the preset buffer time. Among them, the preset buffer time can be determined based on the historical interaction time requirement between the terminal device and the website server to be accessed, or the preset buffer time can be set in a user-defined manner.
[0053] Step A4: Create a first data packet forwarding rule between the terminal device and the website server according to the source IP address, the destination IP address and the first access timeout period. The first data packet forwarding rule includes the source IP address, the destination IP address and the first access timeout period.
[0054] In this embodiment, returning the response result to the domain name resolution request to the terminal device through the second network device can be performed as follows: taking the domain name resolution response as the response result, and returning it to the terminal device through the second network device.
[0055] In this embodiment, when the IP protocol versions of the source IP address and the destination IP address are consistent, data packet forwarding rules are created between the terminal device and the website server based on the source IP address, the destination IP address and the access timeout period between the terminal device and the website server, thereby providing a basis for judging the timeliness and legality of the communication interaction between the terminal device and the website server.
[0056] In one embodiment, after determining the destination IP address corresponding to the domain name to be accessed according to the first A record or the first AAAA record (ie, step A1), the following steps B1 to B4 may be performed: Step B1, when the IP protocol versions of the source IP address and the destination IP address are inconsistent, determine the first IP address corresponding to the terminal device and consistent with the IP protocol version of the destination IP address based on the first mapping relationship between IP addresses of different IP protocol versions obtained in advance. Alternatively, determine the first IP address corresponding to the MAC address of the terminal device and consistent with the IP protocol version of the destination IP address based on the second mapping relationship between the MAC address and IP addresses of different IP protocol versions created in advance.
[0057] Among them, when the IP protocol version of the source IP address is IPv4 and the IP protocol version of the destination IP address is IPv6, or the IP protocol version of the source IP address is IPv6 and the IP protocol version of the destination IP address is IPv4, it can be determined that the IP protocol versions of the source IP address and the destination IP address are inconsistent.
[0058] In this embodiment, when it is necessary to support IPv4 and IPv6 dual stack access, a mapping table between an IPv4 address and an IPv6 address can be obtained from an external device (such as an enterprise gateway) or a program, and the mapping table stores the above-mentioned first mapping relationship. Optionally, the first mapping relationship may include a one-to-many mapping relationship between an IPv4 address and an IPv6 address. For example, the first mapping relationship may include a mapping relationship between an IPv4 address and one or more IPv6 addresses, and may also include a mapping relationship between an IPv6 address and one or more IPv4 addresses.
[0059] Optionally, when the IP protocol versions of the source IP address and the destination IP address are inconsistent, one or more first IP addresses corresponding to the terminal device and consistent with the IP protocol version of the destination IP address can be determined according to the first mapping relationship.
[0060] For example, when the source IP address is an IPv4 address and the destination IP address is an IPv6 address, a pre-acquired mapping table may be searched to determine whether there is an IPv6 address corresponding to the IPv4 address, and if so, one or more IPv6 addresses found are determined as the first IP address. For another example, when the source IP address is an IPv6 address and the destination IP address is an IPv4 address, a pre-acquired mapping table may be searched to determine whether there is an IPv4 address corresponding to the IPv6 address, and if so, one or more IPv4 addresses found are determined as the first IP address.
[0061] In this embodiment, when the source IP address is an IPv4 address and the destination IP address is an IPv6 address, it is possible to determine whether there is a MAC address corresponding to the IPv4 address based on a pre-created second mapping relationship. When the corresponding MAC address is found, it is possible to continue to search whether there is an IPv6 address corresponding to the MAC address. If so, the found IPv6 address is determined as the first IP address.
[0062] Step B2: Determine a second lifetime of the domain name resolution response.
[0063] Step B3: determining a second access timeout period between the terminal device and the website server according to the second survival period. In this embodiment, the specific process of determining the access timeout period between the terminal device and the website server according to the survival time of the domain name resolution response is similar to the above step A3 and will not be repeated here.
[0064] Step B4: Create a second data packet forwarding rule between the terminal device and the website server according to the first IP address, the destination IP address and the second access timeout period. The second data packet forwarding rule includes the first IP address, the destination IP address and the second access timeout period.
[0065] In this embodiment, returning the response result to the domain name resolution request to the terminal device through the second network device can be performed as follows: taking the domain name resolution response as the response result, and returning it to the terminal device through the second network device.
[0066] In this embodiment, when the IP protocol versions of the source IP address and the destination IP address are inconsistent, the source IP address is converted into a first IP address that is consistent with the IP protocol version of the destination IP address, thereby creating a data packet forwarding rule between the terminal device and the website server based on the first IP address, the destination IP address and the access timeout period between the terminal device and the website server, thereby providing a basis for judging the timeliness and legality of the communication interaction between the terminal device and the website server.
[0067] In one embodiment, the domain name resolution response may include an alias record.
[0068] In this embodiment, before returning the response result to the domain name resolution request to the terminal device through the second network device (ie, S208), the following steps C1 to C4 may be performed to construct a domain name resolution result including only the domain name and IP address to be accessed.
[0069] Step C1, determining the alias domain name corresponding to the domain name to be accessed according to the alias record in the domain name resolution response.
[0070] Optionally, the number of alias domain names can be one or more. In the case where the number of alias domain names is multiple, the third mapping relationship between the domain name to be accessed and the multiple alias domain names can be: direct mapping or indirect mapping. For example, one case of indirect mapping is: for N alias domain names, the domain name to be accessed points to the first alias domain name, the first alias domain name points to the second alias domain name, the second alias domain name points to the third alias domain name, and so on, and finally the N-1th alias domain name points to the Nth alias domain name, N is a positive integer. One case of direct mapping is: for N alias domain names, the domain name to be accessed points to the first alias domain name, the second alias domain name, the third alias domain name, ... the Nth alias domain name.
[0071] Step C2: Determine the IP address corresponding to the alias domain name according to the second A record or the second AAAA record corresponding to the alias domain name.
[0072] Among them, when the number of alias domain names is one, the IP address corresponding to the alias domain name can be determined according to the second A record or the second AAAA record corresponding to the alias domain name. When the number of alias domain names is N, if the third mapping relationship is the indirect mapping listed in step C1, it is necessary to determine the IP address corresponding to the alias domain name according to the second A record or the second AAAA record corresponding to the Nth alias domain name; if the third mapping relationship is the direct mapping listed in step C1, it is necessary to determine the IP address corresponding to each alias domain name according to the second A record or the second AAAA record corresponding to each alias domain name.
[0073] To determine which of the second A record and the second AAAA record is used to determine the IP address corresponding to the alias domain name, you need to look at the type of domain name record requested to be returned in the domain name resolution request. If the request returns an A record, you need to determine the IP address corresponding to the alias domain name based on the second A record corresponding to the alias domain name. If the request returns an AAAA record, you need to determine the IP address corresponding to the alias domain name based on the second AAAA record corresponding to the alias domain name.
[0074] Step C3, constructing a domain name resolution result corresponding to the domain name resolution request according to the IP addresses corresponding to the domain name to be accessed and the alias domain name.
[0075] The domain name resolution result only includes the original domain name (ie, the domain name to be accessed) and the corresponding second A record or second AAAA record, and does not include any alias domain name.
[0076] In one embodiment, after executing step C2, if the source IP address of the terminal device is consistent with the IP protocol version of the IP address corresponding to the alias domain name, the above steps A2-A4 can be referred to to determine the third lifetime of the alias record, and then determine the third access timeout between the terminal device and the website server based on the third lifetime of the alias record, and then determine the third data packet forwarding rule between the terminal device and the website server based on the source IP address, the IP address corresponding to the alias domain name and the third access timeout.
[0077] If the source IP address of the terminal device is inconsistent with the IP protocol version of the IP address corresponding to the alias domain name, then the first IP address corresponding to the terminal device and consistent with the IP protocol version of the IP address corresponding to the alias domain name can be determined by referring to the above step B1, based on the first mapping relationship between IP addresses of different IP protocol versions obtained in advance; or, based on the second mapping relationship between the pre-created MAC address and IP addresses of different IP protocol versions, the first IP address corresponding to the MAC address of the terminal device and consistent with the IP protocol version of the IP address corresponding to the alias domain name can be determined. Then, refer to the above steps B2-B4 to determine the third life span of the alias record, thereby determining the third access timeout between the terminal device and the website server based on the third life span of the alias record, and then determining the third data packet forwarding rule between the terminal device and the website server based on the first IP address, the IP address corresponding to the alias domain name and the third access timeout.
[0078] Step C4: returning the domain name resolution result as a response result to the terminal device through the second network device.
[0079] In this embodiment, by constructing the domain name return result, the CNAME of the A record (or AAAA record) can be returned, the intermediate CNAME is removed, and only the final A record (or AAAA record) is returned, that is, only the final IP address is returned. Although this will destroy security mechanisms such as DNSSEC (Domain Name System Security Extensions), the performance is better.
[0080] In one embodiment, the number of alias domain names is multiple. After determining the alias domain name corresponding to the domain name to be accessed according to the alias record in the domain name resolution response (i.e., step C1), a temporary domain name rule can be created according to the third mapping relationship between the domain name to be accessed and each alias domain name, the temporary domain name rule can be added to the pre-created domain name rule, and the validity period of the temporary domain name rule can be determined according to the third lifetime of the alias record.
[0081] The temporary domain name rule includes a fourth corresponding relationship between each alias domain name and the domain name to be accessed.
[0082] In this embodiment, for each layer of CNAME in the CNAME return of the A record (or AAAA record), a temporary domain name rule can be recorded. For example, the domain name resolution response of the domain name resolution request "www.example-b.com" returned from the DNS server corresponding to the network exit B is CNAME to "example-b.somecdn.net", and then the domain name resolution response of "example-b.somecdn.net" is an A record. At this time, the third lifetime of each alias record can be determined, and then the access timeout of each layer of CNAME can be adjusted according to the third lifetime of each alias record. Afterwards, the temporary domain name rule is recorded according to the source IP address, the destination IP address and the access timeout of each layer of CNAME. In this way, not only can "example-b.somecdn.net" be matched to the network exit B within the access timeout, but also the DNSSEC integrity can be ensured. Among them, the effective time of the temporary domain name rule is the access timeout of each layer of CNAME.
[0083] In one embodiment, the first network device may receive an access data packet from the terminal device forwarded by the second network device, and send the access data packet through a target network exit if the access data packet complies with the data packet forwarding rule.
[0084] The circumstances under which the second network device forwards the access data packet from the terminal device to the first network device will be described in detail in the following embodiments and will not be expanded here.
[0085] In this embodiment, if the access data packet does not comply with the data packet forwarding rule, the access data packet is sent out through the default network exit of the second network device. It can be seen that by creating a data packet forwarding rule, the data packet can be routed quickly and accurately, ensuring efficient communication between the terminal device and the website server corresponding to the domain name to be accessed.
[0086] In one embodiment, Figure 3 As shown, when the domain name resolution response matches the domain name rule, the first network device creates a corresponding data packet forwarding rule, and returns the response result to the domain name resolution request to the terminal device through the second network device, which can be executed as follows S301-S310: S301, determine whether the domain name resolution response matches the domain name rule; if so, execute S302; if not, execute S310.
[0087] The domain name resolution request includes the source IP address of the terminal device, the domain name to be accessed, and the type of domain name record returned by the request, and the domain name resolution response includes an A record or an AAAA record.
[0088] S302, determine whether the domain name resolution response is an A record or an AAAA record; if so, execute S303; if not, execute S310.
[0089] If the domain name resolution response is not an A record or an AAAA record, it means that the domain name resolution response is returned by the default DNS server. In this case, the domain name resolution response can be directly sent to the terminal device without determining its data packet forwarding rules. This is because based on the pre-configuration on the target DNS server, the domain name resolution response returned by the target DNS server will be an A record or an AAAA record.
[0090] S303, determine whether the source IP address of the terminal device is consistent with the IP protocol version of the destination IP address corresponding to the domain name to be accessed; if not, execute S304; if so, execute S305.
[0091] S304, determine a first IP address corresponding to the terminal device and consistent with the IP protocol version of the destination IP address, and record the first IP address as the source IP address of the terminal device. Then, execute S305.
[0092] Among them, the first IP address corresponding to the terminal device and consistent with the IP protocol version of the destination IP address can be determined based on the first mapping relationship between IP addresses of different IP protocol versions obtained in advance; or, the first IP address corresponding to the MAC address of the terminal device and consistent with the IP protocol version of the destination IP address can be determined based on the second mapping relationship between the pre-created MAC address and IP addresses of different IP protocol versions.
[0093] S305, determine whether the domain name resolution response contains an alias record; if so, execute S306; if not, execute S307.
[0094] S306: construct a domain name resolution result corresponding to the domain name resolution request according to the domain name to be accessed and the IP address corresponding to the alias domain name in the alias record, and determine the constructed domain name resolution result as a domain name resolution response. Then, execute S307.
[0095] The specific construction method of the domain name resolution result can be found in the above steps C1 to C3, which will not be repeated here.
[0096] S307, determine the lifetime of the domain name resolution response.
[0097] S308, determining an access timeout period between the terminal device and the website server according to the lifetime of the domain name resolution response.
[0098] S309, determining a data packet forwarding rule between the terminal device and the website server according to the source IP address, the destination IP address and the access timeout period.
[0099] S310: Return the domain name resolution response as a response result to the terminal device through the second network device.
[0100] The specific process of S301 - S310 has been described in detail in the above embodiment and will not be repeated here.
[0101] In this embodiment, after receiving the domain name resolution response returned by the target DNS server, a data packet forwarding rule between the terminal device and the website server is created according to the domain name resolution response, thereby providing a basis for judging the timeliness and legality of the communication interaction between the terminal device and the website server.
[0102] like Figure 4 FIG. 1 is a schematic flow chart of a routing selection method according to another embodiment of the present application, which is applied to Figure 1 The second network device with multiple network exits shown in FIG. 1 is connected to the first network device. Figure 4 The methods include: S402, receiving a domain name resolution request from a terminal device, where the domain name resolution request includes a domain name to be accessed.
[0103] S404: Forward the domain name resolution request to the first network device.
[0104] Among them, the first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule, and obtain the domain name resolution response through the target DNS server corresponding to the target network exit.
[0105] S406: Receive a response result to the domain name resolution request sent by the first network device based on the domain name resolution response, where the response result carries the first connection element.
[0106] Among them, the first connection element may include the MAC address corresponding to the target network exit and the source IP address of the terminal device. A connection is a five-tuple consisting of a protocol, a source IP address, a destination IP address, a source port, and a destination port. Data packets with the same five-tuple information, or only with the source and destination swapped, can be matched to the same connection. In this embodiment, the source IP address is the MAC address corresponding to the target network exit, and the destination IP address is the source IP address of the terminal device.
[0107] S408, determining the target network connection to which the response result belongs according to the first connection element; and creating and storing a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit.
[0108] S410, returning the response result to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
[0109] By adopting the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device is received by a second network device, and the domain name resolution request is forwarded to the first network device. Thus, a response result to the domain name resolution request sent by the first network device based on the domain name resolution response is received, and the target network connection to which the response result belongs is determined according to the first connection element carried by the response result, and a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit is created and stored. Then, the response result is returned to the terminal device, so that the terminal device can send an access data packet to the website server corresponding to the domain name to be accessed according to the response result. In this way, for the data packet between the terminal device and the website server, the corresponding exit identifier can be determined according to the network connection to which the data packet belongs, thereby determining the corresponding network exit, which is conducive to realizing fast and accurate routing of the data packet between the terminal device and the website server.
[0110] In one embodiment, creating and storing a second correspondence between the target network connection and the target egress identifier corresponding to the target network egress (ie, S408) may be performed as follows: Steps D1 to D3: Step D1: determining a target network exit identifier corresponding to a target network exit according to a pre-created third correspondence between each network exit and each exit identifier of the second network device.
[0111] The third correspondence between the network exit and the exit identifier may include: the MAC address of the network exit corresponds to the network exit one-to-one, and the network exit corresponds to the exit identifier one-to-one. When the second network device is put into use, the unique exit identifier corresponding to each network exit can be determined, and the third correspondence can be saved.
[0112] Step D2: creating a second correspondence between the target network connection and the target exit identifier.
[0113] Step D3: Store the newly created second correspondence in a second correspondence table, wherein the second correspondence table stores correspondences between each network connection and each exit identifier.
[0114] In this embodiment, by creating a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit, subsequent data packets of the target network connection are facilitated to quickly match the corresponding exit identifier, thereby achieving fast and accurate routing of the data packets.
[0115] In one embodiment, after the response result is returned to the terminal device (ie, S410), the following steps E1 to E6 may be performed: Step E1, receiving an access data packet sent by a terminal device.
[0116] The destination MAC address of the access data packet is the MAC address of the second network device. Optionally, the access data packet carries the source IP address of the terminal device, the destination IP address of the website server and the current access time.
[0117] Step E2: determining the first network connection to which the access data packet belongs according to the second connection element carried in the access data packet.
[0118] Step E3: Determine whether there is a first exit identifier corresponding to the first network connection according to the second correspondence table.
[0119] Step E4, when it is determined that there is a first exit identifier corresponding to the first network connection, determine the first network exit corresponding to the first exit identifier based on a third correspondence between each network exit of the second network device and each exit identifier created in advance; and replace the destination MAC address of the access data packet with the MAC address corresponding to the first network exit.
[0120] Step E5, when it is determined that there is no first exit identifier corresponding to the first network connection, the access data packet is forwarded to the first network device; the first network device is used to replace the destination MAC address of the access data packet with the MAC address corresponding to the target network exit when the access data packet complies with the data packet forwarding rule.
[0121] Among them, when the source IP address of the terminal device carried by the access data packet is consistent with the source IP address in the data packet forwarding rule (or an IP address with a different IP protocol version that has a mapping relationship with the first IP address in the data packet forwarding rule), the destination IP address carried by the access data packet is consistent with the destination IP address in the data packet forwarding rule, and the current access time of the access data packet is less than or equal to the access timeout time in the data packet forwarding rule, it can be determined that the access data packet complies with the data packet forwarding rule.
[0122] Step E6, sending the access data packet through the corresponding network exit.
[0123] In this embodiment, in a corresponding network exit, the source MAC address of the access data packet may be replaced with a MAC address corresponding to the network exit so that the data packet is sent out from the network exit.
[0124] In an optional embodiment, the first network device is used to replace the destination MAC address of the access data packet with the MAC address corresponding to the default network exit when the access data packet does not comply with the data packet forwarding rule, so that the access data packet is sent out through the default network exit.
[0125] In this embodiment, when an access data packet is received, the network connection to which the access data packet belongs is determined, and when the exit identifier corresponding to the network connection is found, the access data packet is routed through the network exit corresponding to the exit identifier, and when the exit identifier corresponding to the network connection cannot be found, the access data packet is routed through the first network device. It can be seen that this technical solution provides a more comprehensive routing strategy, which is conducive to achieving accurate routing of access data packets.
[0126] In one embodiment, after the access data packet is sent out through the corresponding network exit (ie, step E6), the following steps F1 to F5 may be performed: Step F1, receiving a response data packet from a website server.
[0127] Step F2: determining the second network connection to which the response data packet belongs according to the third connection element carried in the response data packet.
[0128] Step F3: Determine whether there is a second egress identifier corresponding to the second network connection according to the second correspondence table.
[0129] Step F4: when it is determined that there is a second egress identifier corresponding to the second network connection, forward the response data packet to the terminal device.
[0130] Step F5, when it is determined that there is no second exit identifier corresponding to the second network connection, determine the third exit identifier corresponding to the network exit for receiving the response data packet according to the pre-created third correspondence between each network exit and each exit identifier of the second network device; create a correspondence between the second network connection and the third exit identifier, and store the correspondence in a second correspondence table; and forward the response data packet to the terminal device.
[0131] In this embodiment, when a response data packet is received, the network connection to which the response data packet belongs is determined, and when the exit identifier corresponding to the network connection is found, the response data packet is forwarded to the terminal device. When the exit identifier corresponding to the network connection cannot be found, the corresponding relationship between the network connection and the exit identifier is first created and stored, and then the response data packet is forwarded. It can be seen that the technical solution can timely create a corresponding relationship between a network connection without a corresponding exit identifier and an exit identifier, which is conducive to the rapid and accurate routing of subsequent data packets belonging to the network connection.
[0132] In an optional embodiment, the routing selection method provided in the embodiment of the present application can be applied to Figure 1 The routing selection system shown. Among them, the second network device is used to connect to the terminal device, and each network exit is pre-installed with a DNS server. The second network device is used to receive various data packets, and forward the received domain name resolution request and domain name resolution response to the first network device for processing. As for other received data packets (such as access data packets sent by the terminal device, response data packets sent by the website server, etc.), they are processed by themselves. The first network device is used to process domain name resolution requests and domain name resolution responses. The following details the specific execution process of the routing selection method provided in the embodiment of the present application when applied to the routing selection system.
[0133] Figure 5 is a schematic flow chart of a routing selection method according to another embodiment of the present application, such as Figure 5 As shown, the method includes: S501: The second network device receives a data packet.
[0134] S502: Determine the network connection to which the data packet belongs according to the connection element carried by the data packet.
[0135] S503, determine whether there is an exit identifier corresponding to the network connection; if so, execute S504; if not, execute S508.
[0136] Wherein, it can be determined whether there is an exit identifier corresponding to the network connection according to the second correspondence table. The second correspondence table stores the correspondence between each network connection and each exit identifier.
[0137] S504, determine whether the data packet is a response data packet sent to the terminal device; if so, execute S505; if not, execute S506.
[0138] S505: forward the data packet to the terminal device, and then terminate the current process.
[0139] S506: Determine the network exit corresponding to the exit identifier according to a pre-created third correspondence between each network exit of the second network device and each exit identifier.
[0140] S507: Send the data packet through the network exit, and then end the current process.
[0141] S508, determine whether the data packet is a response data packet sent to the terminal device; if so, execute S509; if not, execute S511.
[0142] S509, determining the exit identifier corresponding to the network exit for receiving the data packet according to the pre-created third correspondence between each network exit and each exit identifier of the second network device; and creating a correspondence between the network connection and the exit identifier.
[0143] The corresponding relationship may be stored in a second corresponding relationship table.
[0144] S510: forward the data packet to the terminal device, and then terminate the current process.
[0145] S511, determine whether the data packet comes from the first network device; if so, execute S512; if not, execute S513.
[0146] S512: Forward the data packet to a default network exit of the second network device.
[0147] Among them, the data packet is sent by the first network device and the corresponding exit identifier cannot be found, which means that the data packet does not need to be specially routed and can be routed according to the default route. Based on this, the data packet can be forwarded to the default network exit of the second network device.
[0148] S513: Forward the data packet to the first network device.
[0149] Among them, if the network connection to which the data packet belongs does not have a corresponding exit identifier, and the data packet is not a response data packet sent to the terminal device, and the data packet does not come from the first network device, it means that the data packet is a data packet from the terminal device. At this time, the data packet can be forwarded to the first network device.
[0150] S514, the first network device determines whether the received data packet is a data packet of a domain name resolution request; if so, execute S515; if not, execute S520.
[0151] S515, when the domain name to be accessed in the domain name resolution request matches the pre-created domain name rule, determine the network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device.
[0152] S516: forward the domain name resolution request to the target DNS server corresponding to the network exit.
[0153] S517, the target DNS server responds to the domain name resolution request and returns a domain name resolution response.
[0154] S518, when the domain name resolution response matches the domain name rule, the first network device creates a corresponding data packet forwarding rule, and returns the response result to the domain name resolution request to the terminal device through the second network device.
[0155] The data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed.
[0156] S519: The terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result, and then ends the current process.
[0157] S520, the first network device determines whether the received data packet complies with the pre-created data packet forwarding rule; if so, execute S521; if not, execute S522.
[0158] S521, replace the destination MAC address of the received data packet with the MAC address corresponding to the corresponding network exit, so that the data packet is sent out through the network exit.
[0159] S522, replacing the destination MAC address of the received data packet with the MAC address corresponding to the default network exit, so that the data packet is sent out through the default network exit.
[0160] The specific process of S501-S522 has been described in detail in the above embodiment and will not be repeated here.
[0161] By adopting the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device is received through a second network device, and the domain name resolution request is forwarded to a first network device. The first network device can match the domain name to be accessed in the domain name resolution request with the pre-created domain name rule. When the two match, it can be determined that the domain name resolution request needs to determine the network exit in a targeted manner, thereby determining the target network exit corresponding to the domain name resolution request according to the first correspondence between each domain name in the domain name rule and each network exit of the second network device, forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server, and creating a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and then sending the response result for the domain name resolution request to the second network device. It can be seen that the technical solution realizes the effect of diverting the domain name resolution request from the terminal device according to the domain name, so that the terminal device can communicate and interact with the website server corresponding to the domain name to be accessed through the most appropriate network exit, providing a channel basis for the terminal device to successfully access the website server. Furthermore, by creating a data packet forwarding rule, the data packet between the terminal device and the website server corresponding to the domain name to be accessed can be routed based on this data packet forwarding rule without frequent domain name resolution, thereby ensuring efficient communication between the terminal device and the website server corresponding to the domain name to be accessed. Furthermore, the second network device can determine the target network connection to which the response result belongs based on the first connection element carried by the response result, create and store a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit, and return the response result to the terminal device, so that the terminal device can send an access data packet to the website server corresponding to the domain name to be accessed based on the response result. In this way, for the data packet between the terminal device and the website server, the corresponding exit identifier can be determined based on the network connection to which the data packet belongs, thereby determining the corresponding network exit, which is conducive to realizing fast and accurate routing of the data packet between the terminal device and the website server.
[0162] In summary, specific embodiments of the present subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recorded in the claims can be performed in a different order and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing can be advantageous.
[0163] The above is a routing selection method provided in an embodiment of the present application. Based on the same idea, an embodiment of the present application also provides a routing selection device.
[0164] Figure 6is a schematic diagram of the structure of a routing selection device according to an embodiment of the present application, which is applied to a first network device, and the first network device is connected to a second network device having multiple network exits, such as Figure 6 As shown, the routing device may include: The first receiving module 610 is used to receive a domain name resolution request from a terminal device forwarded by a second network device; the domain name resolution request includes a domain name to be accessed; A first determination module 620 is used to determine a target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule; The forwarding and receiving module 630 is used to forward the domain name resolution request to the target DNS server corresponding to the target network exit, and receive the domain name resolution response returned by the target DNS server; The creation and return module 640 is used to create corresponding data packet forwarding rules when the domain name resolution response matches the domain name rule, and return the response result of the domain name resolution request to the terminal device through the second network device; the data packet forwarding rules are used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed.
[0165] In one embodiment, the domain name resolution response includes a first A record or a first AAAA record; the domain name resolution request also includes a source IP address of the terminal device; The creation and return module 640 includes: An IP address determination unit, configured to determine a destination IP address corresponding to the domain name to be accessed according to the first A record or the first AAAA record; A first survival time determination unit, configured to determine a first survival time of a domain name resolution response when the IP protocol versions of the source IP address and the destination IP address are consistent; A first access timeout determination unit, configured to determine a first access timeout between the terminal device and the website server according to the first lifetime; The first creation unit is used to create a first data packet forwarding rule between the terminal device and the website server according to the source IP address, the destination IP address and the first access timeout period; the first data packet forwarding rule includes the source IP address, the destination IP address and the first access timeout period.
[0166] In one embodiment, the creation and return module 640 further includes: A first determination unit is used to determine, after determining the destination IP address corresponding to the domain name to be accessed according to the first A record or the first AAAA record, a first IP address corresponding to the terminal device and consistent with the IP protocol version of the destination IP address according to a first mapping relationship between IP addresses of different IP protocol versions obtained in advance, if the IP protocol versions of the source IP address and the destination IP address are inconsistent; or, according to a second mapping relationship between a pre-created MAC address and IP addresses of different IP protocol versions, determine the first IP address corresponding to the MAC address of the terminal device and consistent with the IP protocol version of the destination IP address; A second lifetime determination unit, used to determine a second lifetime of the domain name resolution response; A second access timeout determination unit, configured to determine a second access timeout between the terminal device and the website server according to the second survival time; The second creation unit is used to create a second data packet forwarding rule between the terminal device and the website server according to the first IP address, the destination IP address and the second access timeout period; the second data packet forwarding rule includes the first IP address, the destination IP address and the second access timeout period.
[0167] In one embodiment, the domain name resolution response includes an alias record; The creation and return module 640 also includes: An alias domain name determination unit, used to determine the alias domain name corresponding to the domain name to be accessed according to the alias record in the domain name resolution response; A second determining unit, configured to determine an IP address corresponding to the alias domain name according to a second A record or a second AAAA record corresponding to the alias domain name; A construction unit, used to construct a domain name resolution result corresponding to the domain name resolution request according to the IP address corresponding to the domain name to be accessed and the alias domain name; The returning unit is used to return the domain name resolution result as a response result to the terminal device through the second network device.
[0168] In one embodiment, the number of alias domain names is multiple; The creation and return module 640 also includes: A third creation unit is used to create a temporary domain name rule according to a third mapping relationship between the domain name to be accessed and each alias domain name after determining the alias domain name corresponding to the domain name to be accessed according to the alias record in the domain name resolution response; the temporary domain name rule includes a fourth corresponding relationship between each alias domain name and the domain name to be accessed; An adding unit, used to add a temporary domain name rule to a pre-created domain name rule; The third determining unit is used to determine the validity period of the temporary domain name rule according to the third lifetime of the alias record.
[0169] In one embodiment, the routing device further comprises: An access data packet receiving module, used to receive an access data packet from a terminal device forwarded by a second network device; The first sending module is used to send the access data packet through the target network exit when the access data packet meets the data packet forwarding rule.
[0170] According to the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device forwarded by a second network device is received by a first network device, and the domain name to be accessed in the domain name resolution request is matched with a pre-created domain name rule. When the two match, it can be determined that the domain name resolution request needs to determine the network exit in a targeted manner, thereby determining the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device, forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server, and creating a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and then returning the response result of the domain name resolution request to the terminal device through the second network device. It can be seen that the technical solution realizes the effect of diverting the domain name resolution request from the terminal device according to the domain name, so that the terminal device can communicate and interact with the website server corresponding to the domain name to be accessed through the most appropriate network exit, providing a channel basis for the terminal device to successfully access the website server. Furthermore, by creating data packet forwarding rules, data packets between the terminal device and the website server corresponding to the domain name to be accessed can be routed based on this data packet forwarding rule without the need for frequent domain name resolution, thereby ensuring efficient communication between the terminal device and the website server corresponding to the domain name to be accessed.
[0171] Figure 7 is a schematic diagram of the structure of a routing selection device according to another embodiment of the present application, which is applied to a second network device having multiple network exits, and the second network device is connected to the first network device, such as Figure 7 As shown, the routing device may include: The second receiving module 710 is used to receive a domain name resolution request from a terminal device; the domain name resolution request includes a domain name to be accessed; The first forwarding module 720 is used to forward the domain name resolution request to the first network device; the first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule, and obtain the domain name resolution response through the target DNS server corresponding to the target network exit; The third receiving module 730 is used to receive a response result to the domain name resolution request sent by the first network device based on the domain name resolution response; the response result carries a first connection element; the first connection element includes a MAC address corresponding to the target network exit and a source IP address of the terminal device; The determination and creation module 740 is used to determine the target network connection to which the response result belongs according to the first connection element; create and store a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit; The response result returning module 750 is used to return the response result to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
[0172] In one embodiment, the determination and creation module 740 includes: A fourth determining unit, configured to determine a target exit identifier corresponding to a target network exit according to a pre-created third correspondence between each network exit and each exit identifier of the second network device; A fourth creating unit, configured to create a second corresponding relationship between a target network connection and a target egress identifier; The storage unit is used to store the newly created second correspondence in a second correspondence table; the second correspondence table stores the correspondence between each network connection and each exit identifier.
[0173] In one embodiment, the routing device further comprises: A fourth receiving module, configured to receive an access data packet sent by the terminal device after returning the response result to the terminal device; A second determining module, configured to determine the first network connection to which the access data packet belongs according to a second connection element carried by the access data packet; A third determination module, configured to determine whether there is a first exit identifier corresponding to the first network connection according to the second correspondence table; A determination and replacement module, configured to, when it is determined that there is a first exit identifier corresponding to the first network connection, determine the first network exit corresponding to the first exit identifier according to a pre-created third correspondence between each network exit of the second network device and each exit identifier; and replace the destination MAC address of the access data packet with the MAC address corresponding to the first network exit; A second forwarding module is used to forward the access data packet to the first network device when it is determined that there is no first exit identifier corresponding to the first network connection; the first network device is used to replace the destination MAC address of the access data packet with the MAC address corresponding to the target network exit when the access data packet meets the data packet forwarding rule; The second sending module is used to send the access data packet through the corresponding network exit.
[0174] In one embodiment, the routing device further comprises: A fifth receiving module, used for receiving a response data packet from the website server after sending the access data packet through a corresponding network exit; a fourth determining module, configured to determine the second network connection to which the response data packet belongs according to the third connection element carried by the response data packet; a fifth determining module, configured to determine, according to the second correspondence table, whether there is a second egress identifier corresponding to the second network connection; A third forwarding module, configured to forward the response data packet to the terminal device when it is determined that there is a second egress identifier corresponding to the second network connection; A determination and forwarding module is used to determine, when it is determined that there is no second exit identifier corresponding to the second network connection, a third exit identifier corresponding to the network exit for receiving a response data packet based on a pre-created third correspondence between each network exit of the second network device and each exit identifier; create a correspondence between the second network connection and the third exit identifier, and store the correspondence in a second correspondence table; and forward the response data packet to the terminal device.
[0175] By adopting the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device is received by a second network device, and the domain name resolution request is forwarded to the first network device. Thus, a response result to the domain name resolution request sent by the first network device based on the domain name resolution response is received, and the target network connection to which the response result belongs is determined according to the first connection element carried by the response result, and a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit is created and stored. Then, the response result is returned to the terminal device, so that the terminal device can send an access data packet to the website server corresponding to the domain name to be accessed according to the response result. In this way, for the data packet between the terminal device and the website server, the corresponding exit identifier can be determined according to the network connection to which the data packet belongs, thereby determining the corresponding network exit, which is conducive to realizing fast and accurate routing of the data packet between the terminal device and the website server.
[0176] Those skilled in the art should understand that the above-mentioned routing selection device can be used to implement the routing selection method described above, and the detailed description thereof should be similar to the description of the method part above, and will not be further described here to avoid redundancy.
[0177] Based on the same idea, the embodiment of the present application also provides a network device, such as Figure 8 As shown. The network device may have relatively large differences due to different configurations or performances, and may include one or more processors 801 and memory 802, and the memory 802 may store one or more storage applications or data. Among them, the memory 802 can be a short-term storage or a persistent storage. The application stored in the memory 802 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the network device. Furthermore, the processor 801 can be configured to communicate with the memory 802 to execute a series of computer executable instructions in the memory 802 on the network device. The network device may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input and output interfaces 805, and one or more keyboards 806.
[0178] In one embodiment, the network device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions in the network device, and the one or more programs are configured to be executed by one or more processors, including computer executable instructions for performing the following: Receiving a domain name resolution request from a terminal device forwarded by a second network device; the domain name resolution request includes a domain name to be accessed; When the domain name to be accessed matches the pre-created domain name rule, determining the target network exit corresponding to the domain name resolution request according to the first correspondence between each domain name in the domain name rule and each network exit of the second network device; Forward the domain name resolution request to the target DNS server corresponding to the target network exit, and receive the domain name resolution response returned by the target DNS server; When the domain name resolution response matches the domain name rule, a corresponding data packet forwarding rule is created, and the response result to the domain name resolution request is returned to the terminal device through the second network device; the data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed.
[0179] According to the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device forwarded by a second network device is received by a first network device, and the domain name to be accessed in the domain name resolution request is matched with a pre-created domain name rule. When the two match, it can be determined that the domain name resolution request needs to determine the network exit in a targeted manner, thereby determining the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device, forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server, and creating a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and then returning the response result of the domain name resolution request to the terminal device through the second network device. It can be seen that the technical solution realizes the effect of diverting the domain name resolution request from the terminal device according to the domain name, so that the terminal device can communicate and interact with the website server corresponding to the domain name to be accessed through the most appropriate network exit, providing a channel basis for the terminal device to successfully access the website server. Furthermore, by creating data packet forwarding rules, data packets between the terminal device and the website server corresponding to the domain name to be accessed can be routed based on this data packet forwarding rule without the need for frequent domain name resolution, thereby ensuring efficient communication between the terminal device and the website server corresponding to the domain name to be accessed.
[0180] In one embodiment, the network device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions in the network device, and the one or more programs are configured to be executed by one or more processors, including computer executable instructions for performing the following: Receiving a domain name resolution request from a terminal device; the domain name resolution request includes a domain name to be accessed; forwarding the domain name resolution request to the first network device; the first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule, and obtain the domain name resolution response through the target DNS server corresponding to the target network exit; Receiving a response result to the domain name resolution request sent by the first network device based on the domain name resolution response; the response result carries a first connection element; the first connection element includes a MAC address corresponding to a target network exit and a source IP address of a terminal device; Determine the target network connection to which the response result belongs according to the first connection element; create and store a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit; The response result is returned to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
[0181] By adopting the technical solution of the embodiment of the present application, a domain name resolution request from a terminal device is received by a second network device, and the domain name resolution request is forwarded to the first network device. Thus, a response result to the domain name resolution request sent by the first network device based on the domain name resolution response is received, and the target network connection to which the response result belongs is determined according to the first connection element carried by the response result, and a second corresponding relationship between the target network connection and the target exit identifier corresponding to the target network exit is created and stored. Then, the response result is returned to the terminal device, so that the terminal device can send an access data packet to the website server corresponding to the domain name to be accessed according to the response result. In this way, for the data packet between the terminal device and the website server, the corresponding exit identifier can be determined according to the network connection to which the data packet belongs, thereby determining the corresponding network exit, which is conducive to realizing fast and accurate routing of the data packet between the terminal device and the website server.
[0182] An embodiment of the present application further proposes a storage medium, which stores one or more computer programs, and the one or more computer programs include instructions. When the instructions are executed by an electronic device including multiple application programs, the electronic device can execute the various processes of the above-mentioned routing selection method embodiment applied to the first network device, or the electronic device can execute the various processes of the above-mentioned routing selection method embodiment applied to the second network device having multiple network exits, and the same technical effect can be achieved. To avoid repetition, they are not repeated here.
[0183] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0184] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0185] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0186] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0187] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0188] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0189] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0190] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0191] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0192] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0193] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0194] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0195] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A routing selection method, characterized in that: Applied to a first network device, the first network device is connected to a second network device having multiple network exits; the method comprises: receiving a domain name resolution request from a terminal device forwarded by the second network device; the domain name resolution request includes a domain name to be accessed; In a case where the domain name to be accessed matches a pre-created domain name rule, determining a target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device; Forwarding the domain name resolution request to the target DNS server corresponding to the target network exit, and receiving the domain name resolution response returned by the target DNS server; When the domain name resolution response matches the domain name rule, a corresponding data packet forwarding rule is created, and the response result to the domain name resolution request is returned to the terminal device through the second network device; the data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed.
2. The method according to claim 1, characterized in that The domain name resolution response includes a first A record or a first AAAA record; the domain name resolution request also includes a source IP address of the terminal device; When the domain name resolution response matches the domain name rule, creating a corresponding data packet forwarding rule includes: Determine, according to the first A record or the first AAAA record, a destination IP address corresponding to the domain name to be accessed; In the case where the IP protocol version of the source IP address is consistent with that of the destination IP address, determining a first lifetime of the domain name resolution response; Determining a first access timeout period between the terminal device and the website server according to the first survival time; A first data packet forwarding rule is created between the terminal device and the website server based on the source IP address, the destination IP address and the first access timeout period; the first data packet forwarding rule includes the source IP address, the destination IP address and the first access timeout period.
3. The method according to claim 2, characterized in that After determining the destination IP address corresponding to the domain name to be accessed according to the first A record or the first AAAA record, the method further includes: In the case where the IP protocol versions of the source IP address and the destination IP address are inconsistent, determining the first IP address corresponding to the terminal device and consistent with the IP protocol version of the destination IP address according to a first mapping relationship between IP addresses of different IP protocol versions obtained in advance; or determining the first IP address corresponding to the MAC address of the terminal device and consistent with the IP protocol version of the destination IP address according to a second mapping relationship between a pre-created MAC address and IP addresses of different IP protocol versions; Determining a second lifetime of the domain name resolution response; Determining a second access timeout period between the terminal device and the website server according to the second survival time; A second data packet forwarding rule is created between the terminal device and the website server based on the first IP address, the destination IP address and the second access timeout period; the second data packet forwarding rule includes the first IP address, the destination IP address and the second access timeout period.
4. The method according to claim 1, characterized in that: The domain name resolution response includes an alias record; The step of returning the response result to the domain name resolution request to the terminal device through the second network device includes: Determine, according to the alias record in the domain name resolution response, the alias domain name corresponding to the domain name to be accessed; Determine the IP address corresponding to the alias domain name according to the second A record or the second AAAA record corresponding to the alias domain name; Constructing a domain name resolution result corresponding to the domain name resolution request according to the domain name to be accessed and the IP address corresponding to the alias domain name; The domain name resolution result is returned as a response result to the terminal device through the second network device.
5. The method according to claim 4, characterized in that The number of the alias domain names is multiple; after determining the alias domain name corresponding to the domain name to be accessed according to the alias record in the domain name resolution response, the method further includes: Creating a temporary domain name rule according to the third mapping relationship between the domain name to be accessed and each alias domain name; the temporary domain name rule includes a fourth corresponding relationship between each alias domain name and the domain name to be accessed; Adding the temporary domain name rule to the pre-created domain name rule; The validity period of the temporary domain name rule is determined according to the third lifetime of the alias record.
6. The method according to claim 1, characterized in that The method further comprises: receiving an access data packet from the terminal device forwarded by the second network device; When the access data packet complies with the data packet forwarding rule, the access data packet is sent out through the target network exit.
7. A routing selection method, characterized in that: Applied to a second network device having multiple network exits, the second network device is connected to the first network device; the method comprises: Receiving a domain name resolution request from a terminal device; the domain name resolution request includes a domain name to be accessed; forwarding the domain name resolution request to the first network device; the first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule, and obtain a domain name resolution response through the target DNS server corresponding to the target network exit; Receiving a response result to the domain name resolution request sent by the first network device based on the domain name resolution response; the response result carries a first connection element; the first connection element includes a MAC address corresponding to the target network exit and a source IP address of the terminal device; Determine, according to the first connection element, a target network connection to which the response result belongs; create and store a second corresponding relationship between the target network connection and a target exit identifier corresponding to the target network exit; The response result is returned to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
8. The method according to claim 7, characterized in that The creating and storing a second corresponding relationship between the target network connection and the target egress identifier corresponding to the target network egress includes: Determine the target exit identifier corresponding to the target network exit according to a pre-created third correspondence between each network exit and each exit identifier of the second network device; Creating the second corresponding relationship between the target network connection and the target exit identifier; The newly created second correspondence relationship is stored in a second correspondence relationship table; the second correspondence relationship table stores the correspondence relationship between each network connection and each exit identifier.
9. The method according to claim 8, characterized in that After returning the response result to the terminal device, the method further includes: Receiving an access data packet sent by the terminal device; Determining, according to the second connection element carried by the access data packet, the first network connection to which the access data packet belongs; Determining, according to the second correspondence table, whether there is a first exit identifier corresponding to the first network connection; In the case where it is determined that there is a first exit identifier corresponding to the first network connection, determining the first network exit corresponding to the first exit identifier according to the pre-created third correspondence between each network exit and each exit identifier of the second network device; replacing the destination MAC address of the access data packet with the MAC address corresponding to the first network exit; When it is determined that there is no first exit identifier corresponding to the first network connection, the access data packet is forwarded to the first network device; the first network device is used to replace the destination MAC address of the access data packet with the MAC address corresponding to the target network exit when the access data packet meets the data packet forwarding rule; The access data packet is sent out through a corresponding network exit.
10. The method according to claim 9, characterized in that After sending the access data packet through the corresponding network exit, the method further includes: Receiving a response data packet from the website server; Determine, according to the third connection element carried by the response data packet, the second network connection to which the response data packet belongs; Determining, according to the second correspondence table, whether there is a second egress identifier corresponding to the second network connection; If it is determined that there is a second egress identifier corresponding to the second network connection, forwarding the response data packet to the terminal device; When it is determined that there is no second exit identifier corresponding to the second network connection, determine the third exit identifier corresponding to the network exit for receiving the response data packet according to the pre-created third correspondence between each network exit and each exit identifier of the second network device; create a correspondence between the second network connection and the third exit identifier, and store the correspondence in the second correspondence table; and forward the response data packet to the terminal device.
11. A routing system, characterized in that: It includes a first network device and a second network device having a plurality of network exits, wherein the first network device is connected to the second network device; wherein, The second network device is used to receive a domain name resolution request from a terminal device, and forward the domain name resolution request to the first network device; the domain name resolution request includes a domain name to be accessed; The first network device is used to determine the target network exit corresponding to the domain name resolution request according to the first corresponding relationship between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule; forward the domain name resolution request to the target DNS server corresponding to the target network exit, and receive the domain name resolution response returned by the target DNS server; create a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and forward the response result for the domain name resolution request to the second network device; the data packet forwarding rule is used to control the routing of data packets between the terminal device and the website server corresponding to the domain name to be accessed; The second network device is also used to determine the target network connection to which the response result belongs based on the first connection element carried by the response result; the first connection element includes the MAC address corresponding to the target network exit and the source IP address of the terminal device; create and store a second correspondence between the target network connection and the target exit identifier corresponding to the target network exit; return the response result to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be visited according to the response result.
12. A routing selection device, characterized in that: Applied to a first network device, the first network device is connected to a second network device having multiple network exits; the device comprises: A first receiving module, configured to receive a domain name resolution request from a terminal device forwarded by the second network device; the domain name resolution request includes a domain name to be accessed; A first determination module is used to determine the target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches the pre-created domain name rule; A forwarding and receiving module, used to forward the domain name resolution request to a target DNS server corresponding to the target network exit, and receive a domain name resolution response returned by the target DNS server; A creation and return module is used to create a corresponding data packet forwarding rule when the domain name resolution response matches the domain name rule, and return the response result for the domain name resolution request to the terminal device through the second network device; the data packet forwarding rule is used to control the routing of the data packet between the terminal device and the website server corresponding to the domain name to be accessed.
13. A routing selection device, characterized in that: Applied to a second network device having multiple network exits, the second network device is connected to the first network device; the device comprises: A second receiving module is used to receive a domain name resolution request from a terminal device; the domain name resolution request includes a domain name to be accessed; A first forwarding module, configured to forward the domain name resolution request to the first network device; the first network device is configured to determine a target network exit corresponding to the domain name resolution request according to a first correspondence between each domain name in the domain name rule and each network exit of the second network device when the domain name to be accessed matches a pre-created domain name rule, and obtain a domain name resolution response through a target DNS server corresponding to the target network exit; A third receiving module is used to receive a response result to the domain name resolution request sent by the first network device based on the domain name resolution response; the response result carries a first connection element; the first connection element includes a MAC address corresponding to the target network exit and a source IP address of the terminal device; A determination and creation module, configured to determine, based on the first connection element, a target network connection to which the response result belongs; and to create and store a second correspondence between the target network connection and a target exit identifier corresponding to the target network exit; The response result returning module is used to return the response result to the terminal device, so that the terminal device sends an access data packet to the website server corresponding to the domain name to be accessed according to the response result.
Citation Information
Cited By
Method and system for determining service forwarding source
CN120602234A