VPN cluster system, message processing method and device, equipment and storage medium

By configuring VPN devices with the same virtual IP and unicast addresses in the VPN cluster system, the routing device selects the first VPN device that forwards messages, solving the problem of excessive network overhead caused by the existing IPSec VPN cluster deployment method, and achieving efficient traffic processing and network overhead reduction.

CN120017620APending Publication Date: 2025-05-16QI AN XIN TECHNOLOGY GROUP INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510163927.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The deployment method of existing IPSec VPN clusters has led to excessive network overhead, especially in a large number of branches and high bandwidth scenarios, where a single device is difficult to meet the needs of large-scale access.

Method used

By configuring the VPN device with the same virtual IP and unicast address in the VPN cluster system, the routing device selects the first VPN device that forwards the message after receiving the message sent by the client, and forwards the message to the device according to its unicast address, reducing unnecessary traffic replication and forwarding.

Benefits of technology

It effectively reduces network overhead, reduces the average traffic processed by each VPN device, optimizes the existing network architecture, and reduces optimization costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017620A_ABST
    Figure CN120017620A_ABST
Patent Text Reader

Abstract

The invention provides a VPN cluster system, a message processing method and device, equipment and a storage medium. The VPN cluster system comprises a routing device, a VPN cluster and a plurality of clients, each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, an execution main body of the message processing method is the routing device, and the message processing method comprises the following steps: receiving a message with a target address being the virtual IP sent by the client; selecting a first VPN device for forwarding the message in the VPN cluster; and forwarding the message to a second VPN device according to the unicast address of the first VPN device, the first VPN device being used for determining the second VPN device for processing the message in the VPN cluster, and the second VPN device being used for processing the message. According to the invention, the network overhead in the VPN cluster system can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of virtual network processing, and in particular to a VPN cluster system and a message processing method, device, equipment and storage medium. Background Art

[0002] With the rise of modern enterprises and cross-border business, enterprises have more and more branches and their locations are becoming more and more extensive. The demand for cross-WAN communication between branches of enterprises has also gradually increased. Many enterprises rely on the technology of establishing a dedicated data communication network in the public network to realize virtual private network. In a virtual private network, the connection between any two nodes does not have an end-to-end physical link in a traditional private network. Instead, a virtual private network is established using tunnel technology such as IPSecVPN, so that the business traffic of each branch can access each other, and the business traffic can be encrypted to prevent internal data leakage of the enterprise. With the increasing number of enterprise branches, for example, when there are tens of thousands of branches, the bandwidth of the tunnel used with the corporate headquarters will also increase. The performance requirements for the equipment deployed in the central node are also getting higher and higher. It is difficult for a single device to meet the access of such a large number of branches and bandwidth, so the solution for IPSec VPN cluster deployment has emerged.

[0003] The current deployment method of IPSec VPN cluster is generally implemented by virtual IP + multicast MAC. The client initiates an IPSec VPN connection request, and the target is the virtual IP address. All traffic entering the virtual IP will be copied by the router and forwarded to all VPN devices configured with the virtual IP based on the multicast MAC. After each VPN device receives the same traffic, it uses the load balancing algorithm to determine which device actually handles the connection, determines the VPN device that handles the connection to establish an IPSec tunnel, and handles the encryption and decryption traffic of the session. This will lead to a huge expansion of traffic. For example, if the export bandwidth is 10G (M), the number of cluster devices is 10 (N), each device needs to process 10G, and the router connecting these 10 devices needs to copy M*N=100G of traffic, which consumes a lot of network overhead.

[0004] Therefore, how to reduce the network overhead in the deployment of IPSec VPN clusters has become a technical problem that urgently needs to be solved in this field. Summary of the invention

[0005] The purpose of the present invention is to provide a VPN cluster system and a message processing method, device, equipment and storage medium, which are used to solve the above technical problems in the prior art.

[0006] On the one hand, to achieve the above object, the present invention provides a message processing method for a VPN cluster system.

[0007] The VPN cluster system includes a routing device, a VPN cluster and multiple clients. Each VPN device in the VPN cluster is configured with the same virtual IP and unicast address. The execution subject of the message processing method is the routing device. The message processing method of the VPN cluster system includes: receiving a message sent by a client with a target address being a virtual IP; selecting a first VPN device in the VPN cluster for forwarding the message; and forwarding the message to a second VPN device according to the unicast address of the first VPN device, wherein the first VPN device is used to determine a second VPN device in the VPN cluster for processing the message, and the second VPN device is used to process the message.

[0008] Furthermore, the message processing method also includes: establishing a session with a VPN cluster; receiving a virtual IP sent by the VPN cluster and a unicast address of each VPN device based on the session; establishing a routing table according to the unicast address of each VPN device; the step of selecting a first VPN device for forwarding messages in the VPN cluster includes: selecting a first VPN device for forwarding messages in the VPN cluster according to the routing table.

[0009] Furthermore, each path in the routing table is an equal-cost path. According to the routing table, the step of selecting a first VPN device for forwarding messages in the VPN cluster includes: selecting an equal-cost path in the routing table based on source information of the client; and using the VPN device of the selected equal-cost path as the first VPN device.

[0010] Furthermore, the message processing method further includes: detecting a first state change of a VPN device in the VPN cluster based on the session; and updating a routing table when the first state change satisfies a first preset condition.

[0011] Furthermore, the VPN cluster system also includes a management platform, which is used to send a device configuration table to each VPN device in the VPN cluster, and the device configuration table includes the VPN device configured for the client; the first VPN device is used to determine the second VPN device according to the device configuration table, and when the second VPN device is the same as the first VPN device, directly process the message, and when the second VPN device is different from the first VPN device, forward the message to the second VPN device for processing.

[0012] On the other hand, to achieve the above object, the present invention provides a VPN cluster system.

[0013] The VPN cluster system includes a routing device, a VPN cluster and multiple clients, and each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, wherein: the client is used to send a message to the virtual IP; the routing device is used to receive the message and select a first VPN device in the VPN cluster to forward the message, and forward the message to the first VPN device according to the unicast address of the first VPN device; the first VPN device is used to determine a second VPN device in the VPN cluster to process the message; and the second VPN device is used to process the message.

[0014] Furthermore, the routing device is also used to establish a session with the VPN cluster to receive the virtual IP sent by the VPN cluster and the unicast address of each VPN device based on the session, and establish a routing table according to the unicast address of each VPN device, and select the first VPN device in the VPN cluster to forward the message according to the routing table.

[0015] Furthermore, each path in the routing table is an equal-cost path, and the routing device is further configured to select an equal-cost path in the routing table based on the source information of the client, and use the VPN device of the selected equal-cost path as the first VPN device.

[0016] Furthermore, the routing device is further configured to detect a first state change of a VPN device in the VPN cluster based on the session, and update the routing table when the first state change satisfies a first preset condition.

[0017] Furthermore, the VPN cluster system also includes a management platform, which is used to send a device configuration table to each VPN device in the VPN cluster, and the device configuration table includes the VPN device configured for the client; the first VPN device is used to determine the second VPN device according to the device configuration table, and when the second VPN device is the same as the first VPN device, directly process the message, and when the second VPN device is different from the first VPN device, forward the message to the second VPN device for processing.

[0018] Furthermore, the management platform is also used to send tunnel configuration information adapted to the client only to the VPN device configured for the client.

[0019] Furthermore, the management platform is also used to send a tunnel configuration information set to each VPN device in the VPN cluster, and the tunnel configuration information set includes tunnel configuration information adapted to each client; the management platform is also used to monitor the second state change of the VPN device in the VPN cluster, and when the second state change meets the second preset condition, update the device configuration table.

[0020] On the other hand, to achieve the above object, the present invention provides a message processing device for a VPN cluster system.

[0021] The VPN cluster system includes a routing device, a VPN cluster and multiple clients. Each VPN device in the VPN cluster is configured with the same virtual IP and unicast address. The message processing device is arranged in the routing device. The message processing device of the VPN cluster system includes: a receiving module, which is used to receive a message sent by a client and whose target address is a virtual IP; a determining module, which is used to select a first VPN device in the VPN cluster to forward the message; and a forwarding module, which is used to forward the message to the first VPN device according to the unicast address of the first VPN device, wherein the first VPN device is used to determine a second VPN device in the VPN cluster to process the message, and the second VPN device is used to process the message.

[0022] On the other hand, to achieve the above objectives, the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.

[0023] On the other hand, to achieve the above object, the present invention also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0024] The VPN cluster system and message processing method, device, equipment and storage medium provided by the present invention are that each VPN device in the VPN cluster is configured with the same virtual IP and unicast address. After a client in the system sends a message with the destination address being the virtual IP, a routing device in the system receives the message and selects a VPN device in the VPN cluster. Based on its unicast address, the message is only sent to the VPN device, and the VPN device then determines the VPN device to process the message. It can be seen that after receiving the message from the client, the routing device in the VPN cluster system does not need to forward all of it, and can directly forward the message to a device in the cluster; the VPN device in the cluster system also does not need to process all of the export traffic in the cluster. Through the present invention, compared with the prior art, the network overhead is greatly reduced, and at the same time, only improvements need to be made on the existing network architecture, and the optimization cost is low. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings: Figure 1 A flowchart of a method for processing a message in a VPN cluster system provided in Embodiment 1 of the present invention; Figure 2Block diagram of the VPN cluster system provided in the second embodiment of the present invention; Figure 3 Block diagram of the message processing device of the VPN cluster system provided in the third embodiment of the present invention; Figure 4 Hardware structure diagram of the computer device provided in the fourth embodiment of the present invention. Detailed implementation manners

[0026] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present invention.

[0027] To solve the problem of large network overhead caused by the deployment method of IPSec VPN clusters in the prior art, the present invention provides a VPN cluster system, a message processing method, device, equipment and storage medium. The VPN cluster system includes a routing device, a VPN cluster and multiple clients. VPN channels are established between the clients through the VPN cluster. Each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, and the virtual IP is published to the routing device. The destination addresses of the clients are all the virtual IPs of the VPN cluster. Therefore, after the client sends a message to the virtual IP, the VPN traffic reaches the routing device. After receiving the message, the routing device does not forward the message to all devices in the cluster, but selects the first VPN device to forward the message in the VPN cluster, and then forwards the message to the first VPN device according to the unicast address of the first VPN device. After receiving the message, the first VPN device determines the second VPN device for processing the message in the VPN cluster, so that the second VPN device processes the message, and finally realizes the decapsulation and forwarding of the VPN traffic. Through the present invention, after the traffic reaches the routing device, for the routing device, there is no need to copy the message, but directly forward the message to one device in the VPN cluster, and then this device performs traffic scheduling to the device corresponding to process the tunnel for corresponding processing. For the scenario where the egress bandwidth is 10G (M) and the number of cluster devices is 10 (N), the average traffic that each device in the VPN cluster needs to process is M / N = 10G / 10 = 1G. If all the traffic coming from the routing device is not the tunnel traffic that this device needs to process, the traffic that needs to be processed is 1*2 = 2G, which is much less than the situation in the prior art where each device needs to process 10G, and the routing device connecting these 10 devices needs to copy out M*N = 100G traffic. Therefore, under the hardware conditions of the prior art, the present invention can achieve the technical effect of reducing network overhead.

[0028] Specific embodiments for the present invention to achieve the above technical effects will be described in detail hereinafter.

[0029] Embodiment 1 The embodiment of the present invention provides a method for processing packets in a VPN cluster system. The VPN cluster system includes a routing device, a VPN cluster, and multiple clients. Each VPN device in the VPN cluster is configured with the same virtual IP and unicast address. The VPN device can be a firewall or an SDWAN CPE. The execution subject of this packet processing method is the routing device. Through this method, the network overhead in the VPN cluster system can be reduced. Specifically, Figure 1 FIG. is a flowchart of the method for processing packets in the VPN cluster system provided in Embodiment 1 of the present invention. As Figure 1 shown, the method for processing packets in the VPN cluster system provided in this embodiment includes the following steps S101 to S103.

[0030] Step S101: Receive a packet with a destination address of the virtual IP sent by the client.

[0031] Specifically, in a scenario, each branch of an enterprise communicates with each other across a wide area network. A virtual private network is established between any two branch structures using the tunnel technology of IPSec VPN. The service traffic of each branch can be mutually accessible based on the VPN cluster. The client belongs to a node of a certain branch structure. After sending a packet with a destination address of the virtual IP. Each VPN device in the VPN cluster is configured with the same virtual IP and published to the routing device, and the routing device can receive the packet.

[0032] Step S102: Select a first VPN device in the VPN cluster to forward the packet.

[0033] After the routing device receives the packet from the client, the biggest difference from the prior art is that it no longer forwards the packet to all VPN devices, but selects a device in the VPN cluster to forward the packet. Here, the selected device is defined as the first VPN device. Optionally, any traffic distribution rule in the prior art can be pre-configured in the routing device, so that when selecting a VPN device, a device can be selected to forward the packet based on this traffic distribution rule. Specifically, for example, rules such as traffic load balancing, etc. This application does not limit this. By configuring the routing device, as long as it can execute this step S102 to select a first VPN device in the VPN cluster to forward the packet.

[0034] Step S103: Forward the packet to the first VPN device according to the unicast address of the first VPN device.

[0035] The first VPN device is used to determine a second VPN device for processing the message in the VPN cluster, and the second VPN device is used to process the message.

[0036] Each VPN device in the VPN cluster has a different unicast address, for example, each device has a unique MAC address. After determining the first VPN device, the routing device accurately forwards the message to the first VPN device based on its unicast address.

[0037] Optionally, each VPN device in the VPN cluster is configured with a message forwarding processing rule. When the forwarding processing rule specifies that the first VPN device and the second VPN device are different devices, based on the forwarding processing rule, after receiving the message, the first VPN device determines the second VPN device that processes the message in the VPN cluster, and then forwards the message to the VPN device that processes the message for processing. Here, the device to which the message is forwarded for processing is defined as the second VPN device. When the forwarding processing rule does not specify whether the first VPN device and the second VPN device are different devices, based on the forwarding processing rule, after receiving the message, the first VPN device determines the second VPN device that processes the message in the VPN cluster. If the second VPN device is itself, that is, the second VPN device and the first VPN device are the same device, the first VPN device can directly process the message. If the second VPN device is another device, that is, the second VPN device and the first VPN device are different devices, the first VPN device forwards the message to the second VPN device for processing.

[0038] In the message processing method of the VPN cluster system provided in this embodiment, each VPN device in the VPN cluster is configured with the same virtual IP and unicast address. After the client in the system sends a message with the destination address being the virtual IP, the routing device in the system receives the message and selects a VPN device in the VPN cluster. Based on its unicast address, the message is sent only to the VPN device, and the VPN device then determines the VPN device to process the message. It can be seen that after receiving the message from the client, the routing device in the VPN cluster system does not need to forward all of it, but can directly forward the message to a device in the cluster; the VPN device in the cluster system also does not need to process all of the export traffic in the cluster. Compared with the prior art, the network overhead is greatly reduced, and only improvements need to be made to the existing network architecture, with low optimization costs.

[0039] Optionally, in one embodiment, the message processing method also includes: establishing a session with a VPN cluster; receiving a virtual IP sent by the VPN cluster and a unicast address of each VPN device based on the session; establishing a routing table according to the unicast address of each VPN device; the step of selecting a first VPN device for forwarding messages in the VPN cluster includes: selecting a first VPN device for forwarding messages in the VPN cluster according to the routing table.

[0040] Specifically, the routing device establishes a session with the VPN cluster. Based on the session, the VPN cluster sends its virtual IP and the unicast address of each VPN device to the routing device, so that the routing device can receive the message with the destination address as the virtual IP. At the same time, a routing table is established according to the unicast address of each VPN device, so that after receiving the message, the first VPN device to forward the message can be selected in the VPN cluster according to the routing table. For example, after a data packet with a destination address of a virtual IP (such as 10.0.0.10) enters the routing device, the routing device finds in the routing table that the VPN device that forwards the message is device A, and the unicast address of device A, that is, MAC is 00:1A:2B:3C:4D:5E. Then the routing device sets the destination MAC address field of the data packet to 00:1A:2B:3C:4D:5E, and sends the data packet to device A through the corresponding network interface.

[0041] Further optionally, the process of establishing a session between the routing device and the VPN cluster is as follows: first, a reliable connection between the VPN cluster and the routing device is established based on the TCP protocol. After the TCP connection is established, the routing device and the VPN cluster send open messages to each other to negotiate session parameters, such as the session version number, session retention time, etc. After the session is established, the routing device can periodically send retention messages to maintain the session to ensure that the devices in the VPN cluster are online and available. When the devices in the VPN cluster change, the routing device detects the change and modifies the routing table, so that the VPN cluster can dynamically publish the virtual IP and the unicast address of each VPN device to the routing device, so that the routing device will know how to correctly route the message sent to the virtual IP to the device in the VPN cluster.

[0042] By adopting the message processing method of the VPN cluster system provided in this embodiment, the routing device establishes a session with the VPN cluster, obtains the virtual IP sent by the VPN cluster and the unicast address of each VPN device, so that the routing device can receive the message sent to the virtual IP, and at the same time establishes a routing table based on the unicast address of each VPN device, and accurately forwards the received message to a certain VPN device according to the routing table.

[0043] Optionally, in one embodiment, each path in the routing table is an equal-cost path, and according to the routing table, the step of selecting a first VPN device for forwarding messages in the VPN cluster includes: selecting an equal-cost path in the routing table based on source information of the client; and using the VPN device of the selected equal-cost path as the first VPN device.

[0044] Specifically, the routing device sets each path in the routing table as an equal-cost path based on an equal-cost routing protocol. Optionally, after receiving the unicast address of each VPN device sent by the VPN cluster, the routing device first uses a routing protocol such as OSPF, IS-IS or BGP to calculate all available paths and marks these paths as equal-cost paths. The routing device adds these equal-cost paths to the routing table. These paths exist in the routing table in an equal-cost manner, indicating that the message can be forwarded through any path.

[0045] After receiving the message, the routing device can use a predetermined algorithm to distribute the traffic to different equal-cost paths based on the source information of the client, such as using a hash algorithm to calculate a hash value based on the source IP address to distribute the traffic to different paths, or it can distribute the traffic to each equal-cost path in sequence based on the source information of the client. For example, the routing table includes three equal-cost paths: path A corresponding to device A, path B corresponding to device B, and path C corresponding to device C. After the message arrives at the routing device, the routing device calculates the hash value based on the source IP address and decides to forward the message to device B through path B, the next message is forwarded to device C through path C, and the next message is forwarded to device A through path A, so that the routing device achieves load balancing of the traffic, the load of each path is relatively balanced, and network resources are effectively utilized.

[0046] By adopting the message processing method of the VPN cluster system provided by this embodiment, when the routing device forwards the message to the corresponding processing device in the VPN cluster, the forwarding device is selected based on the equivalent routing method, so that the traffic can be distributed among multiple paths with the same cost and evenly distributed among multiple VPN devices, making full use of the network bandwidth, avoiding overload of a single path, and improving the performance and response speed of the overall network.

[0047] Optionally, in an embodiment, the message processing method further includes: detecting a first state change of a VPN device in the VPN cluster based on the session; and updating a routing table when the first state change satisfies a first preset condition.

[0048] Specifically, during the operation of the VPN cluster system, the routing device detects the state change of each VPN device in the VPN cluster based on the session with the VPN cluster, which is defined as the first state change in the present invention, and updates the routing table based on the first state change. Further optionally, the first state change can be a change in the working state of the VPN device, and the first state change and the first preset condition are used to determine whether the VPN device fails. When the first state change meets the first preset condition, that is, a VPN device is in an abnormal working state, it indicates that the VPN device fails, and the path corresponding to the VPN device is deleted from the routing table, so that the VPN device no longer forwards messages, and is replaced by other equivalent paths, thereby ensuring the continuity and reliability of message forwarding. Alternatively, optionally, the first state change may also be a change in the number of VPN devices in the VPN cluster. The first state change and the first preset condition are used to determine whether the VPN devices in the VPN cluster have increased or decreased. When the first state change satisfies the first preset condition, that is, a new VPN device is added to the VPN cluster or an existing VPN device is removed, the path corresponding to the new VPN device is added to the routing table, or the path corresponding to the removed VPN device is deleted from the routing table. Dynamic routing adjustment is supported, making it more flexible to add or reduce VPN devices on the basis of the existing network, and improving network scalability without the need for complex manual configuration.

[0049] By adopting the message processing method of the VPN cluster system provided by this embodiment, the routing device detects the status change of the VPN device in the VPN cluster based on the session, and updates the routing table according to the change, which can ensure the continuity and reliability of message forwarding when the VPN device fails, and dynamically adjust the routing when VPN devices are added or deleted in the VPN cluster, thereby improving the flexibility of VPN cluster formation.

[0050] Optionally, in one embodiment, the VPN cluster system also includes a management platform, which is used to send a device configuration table to each VPN device in the VPN cluster, and the device configuration table includes a VPN device configured for the client; the first VPN device is used to determine the second VPN device according to the device configuration table, and when the second VPN device is the same as the first VPN device, directly processes the message, and when the second VPN device is different from the first VPN device, forwards the message to the second VPN device for processing.

[0051] Specifically, which VPN device in the VPN cluster processes the message sent by which client in the VPN cluster can be comprehensively evaluated in advance based on the client's egress bandwidth to select the effective device of the client in the VPN cluster, which is responsible for establishing a VPN tunnel with the client and processing VPN traffic. The corresponding relationship between each client in the VPN cluster system and its effective device in the VPN cluster, that is, the VPN device configured for each client, is used to build a device configuration table. The VPN cluster system also includes a management platform, through which the device configuration table is sent to all VPN devices in the VPN cluster, so that when the routing device forwards the message to any VPN device therein, the first VPN device, the VPN device can use the source information of the client to determine the VPN device configured for the client in the device configuration table, that is, the VPN device that processes the message sent by the client, the second VPN device. Further, if the second VPN device is the same as the first VPN device, there is no need to forward it, and the message can be directly processed locally. When the second VPN device is different from the first VPN device, the message is forwarded to the second VPN device and processed by the second VPN device.

[0052] Further optionally, the management platform is also used to monitor the second state change of the VPN device in the VPN cluster, which is defined as the second state change in the present invention, and update the device configuration table based on the second state change. The second state change can be a change in the working state of the VPN device. The second state change and the second preset condition are used to determine whether the VPN device fails. When the second state change meets the second preset condition, that is, when a VPN device is in an abnormal working state, it indicates that the VPN device fails. Then, the VPN device is deleted from the device configuration table, and the client corresponding to the VPN device is assigned to other VPN devices, such as a backup VPN device, etc., and other VPN devices are assigned to the client corresponding to the VPN device, so that when the first VPN device forwards a message according to the device configuration table, the message from the client corresponding to the VPN device is forwarded to the reallocated other VPN devices, thereby ensuring the continuity and reliability of message processing. Alternatively, optionally, the second state change may also be a change in the number of VPN devices in the VPN cluster. The second state change and the second preset condition are used to determine whether there has been an increase or decrease in the number of VPN devices in the VPN cluster. When the second state change satisfies the second preset condition, that is, a new VPN device is added to the VPN cluster or an existing VPN device is removed, the new VPN device is assigned a client, or the client corresponding to the removed VPN device is assigned to other VPN devices, thereby updating the device configuration table and supporting dynamic tunnel change adjustment, making it more flexible to add or reduce VPN devices on the basis of the existing network, and improving network scalability without the need for complex manual configuration.

[0053] The VPN cluster system message processing method provided by this embodiment is adopted, and the VPN cluster system is provided with a management platform, through which a device configuration table is sent to each VPN device in the VPN cluster, so that the VPN device can forward the message to the VPN device corresponding to the message processing according to the device configuration table. Furthermore, when the state of the VPN device in the VPN cluster changes and / or the cluster changes, the management platform updates the device configuration table, which can ensure the continuity and reliability of message processing when a VPN device fails, and dynamically adjust the processing device when VPN devices are added or deleted in the VPN cluster, thereby improving the flexibility of VPN cluster formation.

[0054] A message sent by a client and forwarded to the VPN cluster via a routing device eventually reaches the VPN device configured for the client, and the VPN device establishes and maintains the VPN tunnel according to the tunnel configuration information. Optionally, in one embodiment, the management platform is also used to send only the tunnel configuration information adapted to the client to the VPN device configured for the client. For example, the management platform only sends the tunnel configuration information adapted to client A to VPN device A configured for client A, and only sends the tunnel configuration information adapted to client B to VPN device B configured for client B, so that each VPN device in the VPN cluster does not need to be configured with a full amount of tunnel configuration, but only needs to configure the VPN tunnel configuration of the corresponding client that is effective in this VPN cluster, thereby avoiding redundant configuration. Optionally, in another embodiment, the management platform is also used to send a set of tunnel configuration information to each VPN device in the VPN cluster, and the set of tunnel configuration information includes the tunnel configuration information adapted to each client. That is, the management platform forms a set of tunnel configuration information adapted to all clients and sends it to each VPN device. At the same time, as described above, the management platform is also used to monitor the second state change of the VPN device in the VPN cluster, and when the second state change meets the second preset condition, the device configuration table is updated. The message processing method of the VPN cluster system provided by this embodiment is used to perform full tunnel configuration on each VPN device in the VPN cluster, so that when the device configuration table is updated and the VPN device assigned to the client changes, the new VPN device can also establish a new VPN tunnel based on the full tunnel configuration.

[0055] Embodiment 2 The embodiment of the present invention provides a VPN cluster system, which includes a routing device, a VPN cluster and multiple clients. Each VPN device in the VPN cluster is configured with the same virtual IP and unicast address. Through the VPN cluster system, the network overhead in the VPN cluster system can be reduced. Specifically, Figure 2 A block diagram of a VPN cluster system provided in Embodiment 2 of the present invention is shown in FIG. Figure 2As shown, the VPN cluster system includes a routing device 201, a VPN cluster 202 and multiple clients 203. In one scenario, the client is a branch of an enterprise. Each VPN device 202-N (N=1, 2, 3, 4) in the VPN cluster 202 is configured with the same virtual IP and unicast address, wherein the client 203 is used to send a message to the virtual IP, the routing device 201 is used to receive the message, and select a first VPN device in the VPN cluster 202 to forward the message, forward the message to the first VPN device according to the unicast address of the first VPN device, the first VPN device is used to determine a second VPN device in the VPN cluster to process the message, and the second VPN device is used to process the message.

[0056] Optionally, in one embodiment, routing device 201 is also used to establish a session with VPN cluster 202 to receive the virtual IP and unicast addresses of each VPN device sent by VPN cluster 202 based on the session, and establish a routing table according to the unicast addresses of each VPN device, and select the first VPN device in VPN cluster 202 to forward the message according to the routing table.

[0057] Optionally, in an embodiment, each path in the routing table is an equal-cost path, and the routing device 201 is further configured to select an equal-cost path in the routing table based on the source information of the client 203, and use the VPN device of the selected equal-cost path as the first VPN device.

[0058] Optionally, in an embodiment, the routing device 201 is further configured to detect a first state change of a VPN device in the VPN cluster 202 based on a session, and update the routing table when the first state change satisfies a first preset condition.

[0059] Optionally, in one embodiment, the VPN cluster system also includes a management platform 204, which is used to send a device configuration table to each VPN device in the VPN cluster 202, and the device configuration table includes a VPN device configured for the client 203; the first VPN device is used to determine the second VPN device according to the device configuration table, and when the second VPN device is the same as the first VPN device, directly processes the message, and when the second VPN device is different from the first VPN device, forwards the message to the second VPN device for processing.

[0060] Optionally, in one embodiment, the management platform 204 is further configured to send tunnel configuration information adapted to the client 203 only to the VPN device configured for the client 203 .

[0061] Optionally, in one embodiment, the management platform 204 is also used to send a tunnel configuration information set to each VPN device in the VPN cluster 202, and the tunnel configuration information set includes tunnel configuration information adapted for each client 203; the management platform 204 is also used to monitor the second state change of the VPN device in the VPN cluster 202, and when the second state change meets the second preset condition, update the device configuration table.

[0062] Optionally, in one embodiment, the management platform 204 serves as a unified management platform in the VPN cluster system, and can centrally issue VPN tunnel configuration information, conduct a comprehensive evaluation of the export bandwidth of each client, and select an effective device for each client in the cluster (responsible for establishing a VPN tunnel with the client and forwarding IPSec VPN traffic). The VPN cluster 202 is an IPSec VPN cluster, and the VPN device can be a firewall or SDWAN CPE.

[0063] The internal group communication addresses between VPN devices in the VPN cluster adopt the three-layer forwarding method of routing isolation, such as VPN device 202-1: 172.24.0.1, VPN device 202-2: 172.24.1.1, that is, when a VPN device forwards a message to another VPN device, it is forwarded in the three-layer forwarding method of routing isolation. Each VPN device in the VPN cluster is set with the same virtual IP and unicast MAC, which are published to routing device 201 through BGP as the IP address for tunnel establishment, and all clients are connected to this IP address for IPSec VPN tunnel.

[0064] The VPN cluster is managed by the management platform 204, which receives the VPN tunnel configuration information and the client's device configuration table issued by the management platform 204. The table is composed of the client's WAN IP address (or the IP address of the branch office) and the internal communication IP address of the VPN device in the corresponding VPN cluster. For example, the message sent by the client with IP address 202.0.0.1 is processed by VPN device 202-1, and the message sent by the client with IP address 203.0.0.1 is processed by VPN device 202-2. The corresponding client device configuration table is as follows: 202.0.0.1nexthop 172.24.0.1 203.0.0.1nexthop 172.24.1.1 When forwarding messages, the IPSec VPN message of the client 203 arrives at the routing device 201. Since the destination addresses are all the virtual IPs of the IPSec VPN cluster 202, the routing device 201 will send these message payloads to the VPN devices in the IPSec VPN cluster through equal-cost routing. After receiving the message, a device in the IPSec VPN (for example, VPN device 202-1) searches the device configuration table and finds the corresponding nexthop. By judging that the nexthop is the local device, the corresponding processing will be performed on the local device. If the nexthop is another device in the cluster (for example, VPN device 202-2), the message will be forwarded to the other device (for example, VPN device 202-2) through routing. After receiving the message, VPN device 202-2 repeats the step of searching the device configuration table, and finally realizes the decapsulation and forwarding of the IPSEC VPN message.

[0065] The VPN cluster system provided by this embodiment adopts virtual IP+unicast MAC, and establishes BGP with the routing device. Through equal-cost routing, the routing device does not need to copy the message, and directly forwards the message to a VPN device in the VPN cluster. Each VPN device will perform traffic scheduling according to the device configuration table and forward it to the device that processes the message for corresponding processing, which can not only ensure the normal processing of the tunnel, but also greatly reduce the traffic processing in the network. Each VPN device in the VPN cluster does not need to configure the full tunnel configuration, but only needs to configure the VPN tunnel configuration of the corresponding client that is effective in this cluster.

[0066] Embodiment 3 Corresponding to the above-mentioned embodiment 1, embodiment 2 of the present invention provides a message processing device for a VPN cluster system, wherein the VPN cluster system includes a routing device, a VPN cluster and multiple clients, each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, and the message processing device is arranged in the routing device. The corresponding technical feature details and corresponding technical effects can be referred to the above-mentioned embodiment 1, and will not be repeated in this embodiment. Figure 3 A block diagram of a message processing device of a VPN cluster system provided in Embodiment 3 of the present invention, such as Figure 3 As shown, the device includes: a receiving module 301, a determining module 302 and a forwarding module 303.

[0067] Among them, the receiving module 301 is used to receive a message sent by the client with the destination address being the virtual IP; the determining module 302 is used to select a first VPN device in the VPN cluster for forwarding the message; and the forwarding module 303 is used to forward the message to the first VPN device according to the unicast address of the first VPN device, wherein the first VPN device is used to determine a second VPN device in the VPN cluster for processing the message, and the second VPN device is used to process the message.

[0068] Optionally, in one embodiment, the message processing device also includes: a communication module, used to establish a session with the VPN cluster, and receive the virtual IP and the unicast address of each of the VPN devices sent by the VPN cluster based on the session; a construction module, used to establish a routing table according to the unicast address of each of the VPN devices, wherein the determination module is also used to select the first VPN device in the VPN cluster that forwards the message based on the routing table.

[0069] Optionally, in an embodiment, each path in the routing table is an equal-cost path, and the determination module is further configured to select an equal-cost path in the routing table based on the source information of the client, and use the VPN device of the selected equal-cost path as the first VPN device.

[0070] Optionally, in an embodiment, the message processing device further includes: a detection module, used to detect a first state change of a VPN device in the VPN cluster based on the session, and an update module, used to update the routing table when the first state change satisfies a first preset condition.

[0071] Optionally, in one embodiment, the VPN cluster system further includes a management platform, which is used to send a device configuration table to each VPN device in the VPN cluster, wherein the device configuration table includes a VPN device configured for the client; the first VPN device is used to determine the second VPN device according to the device configuration table, and when the second VPN device is the same as the first VPN device, directly processes the message, and when the second VPN device is different from the first VPN device, forwards the message to the second VPN device for processing.

[0072] Embodiment 4 This embodiment also provides a computer device, such as a smart phone, tablet computer, laptop computer, desktop computer, rack server, blade server, tower server or cabinet server (including an independent server or a server cluster composed of multiple servers) that can execute programs. Figure 4As shown, the computer device 01 of this embodiment includes at least but is not limited to: a memory 012 and a processor 011 which can be interconnected through a system bus. Figure 4 It should be pointed out that Figure 4 Only a computer device 01 having components memory 012 and processor 011 is shown, but it should be understood that it is not required to implement all of the components shown, and more or fewer components may be implemented instead.

[0073] In this embodiment, the memory 012 (i.e., readable storage medium) includes flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 012 may be an internal storage unit of the computer device 01, such as a hard disk or memory of the computer device 01. In other embodiments, the memory 012 may also be an external storage device of the computer device 01, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card, etc. equipped on the computer device 01. Of course, the memory 012 may also include both the internal storage unit of the computer device 01 and its external storage device. In this embodiment, the memory 012 is generally used to store the operating system and various reference software installed on the computer device 01, such as the program code of the message processing device of the VPN cluster system in the third embodiment. In addition, the memory 012 can also be used to temporarily store various types of data that have been output or are to be output.

[0074] In some embodiments, the processor 011 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 011 is generally used to control the overall operation of the computer device 01. In this embodiment, the processor 011 is used to run the program code stored in the memory 012 or process data, such as a message processing method of a VPN cluster system.

[0075] Embodiment 5 This embodiment also provides a computer-readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a disk, an optical disk, a server, an App reference mall, etc., on which a computer program is stored, and the program implements corresponding functions when executed by a processor. The computer-readable storage medium of this embodiment is used to store a message processing device of a VPN cluster system, and when executed by a processor, implements the message processing method of the VPN cluster system of embodiment 1.

[0076] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0077] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0078] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.

[0079] The above are only preferred embodiments of the present invention, and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A method for processing messages in a VPN cluster system, characterized in that: The VPN cluster system includes a routing device, a VPN cluster and multiple clients, each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, the execution subject of the message processing method is the routing device, and the message processing method includes: Receive a message sent by the client whose destination address is the virtual IP; Selecting a first VPN device in the VPN cluster to forward the message; and The message is forwarded to the second VPN device according to the unicast address of the first VPN device, wherein the first VPN device is used to determine a second VPN device in the VPN cluster that processes the message, and the second VPN device is used to process the message.

2. The message processing method of the VPN cluster system according to claim 1, characterized in that: The message processing method further includes: Establishing a session with the VPN cluster; Receiving the virtual IP and the unicast address of each VPN device sent by the VPN cluster based on the session; Establishing a routing table according to the unicast address of each VPN device; The step of selecting a first VPN device in the VPN cluster for forwarding the message includes: selecting a first VPN device in the VPN cluster for forwarding the message according to the routing table.

3. The message processing method of the VPN cluster system according to claim 2, characterized in that: Each path in the routing table is an equal-cost path. According to the routing table, the step of selecting a first VPN device for forwarding the message in the VPN cluster includes: Selecting an equal-cost path in the routing table based on the source information of the client; The selected VPN device of the equal-cost path is used as the first VPN device.

4. The message processing method of the VPN cluster system according to claim 2, characterized in that: The message processing method further includes: detecting a first state change of a VPN device in the VPN cluster based on the session; When the first state change satisfies a first preset condition, the routing table is updated.

5. The message processing method of the VPN cluster system according to claim 1, characterized in that: The VPN cluster system further includes a management platform, the management platform being used to send a device configuration table to each VPN device in the VPN cluster, the device configuration table including the VPN device configured for the client; The first VPN device is used to determine the second VPN device according to the device configuration table, and directly process the message when the second VPN device is the same as the first VPN device, and forward the message to the second VPN device for processing when the second VPN device is different from the first VPN device.

6. A VPN cluster system, characterized in that: It includes a routing device, a VPN cluster and multiple clients, each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, wherein: The client is used to send a message to the virtual IP; The routing device is used to receive the message, select a first VPN device in the VPN cluster that forwards the message, and forward the message to the first VPN device according to a unicast address of the first VPN device; The first VPN device is used to determine a second VPN device in the VPN cluster to process the message; and The second VPN device is used to process the message.

7. The VPN cluster system according to claim 6, characterized in that: The routing device is also used to establish a session with the VPN cluster to receive the virtual IP and the unicast addresses of each VPN device sent by the VPN cluster based on the session, and to establish a routing table according to the unicast addresses of each VPN device, and to select a first VPN device in the VPN cluster to forward the message according to the routing table.

8. The VPN cluster system according to claim 7, characterized in that: Each path in the routing table is an equal-cost path. The routing device is further configured to select an equal-cost path in the routing table based on the source information of the client, and use the VPN device of the selected equal-cost path as the first VPN device.

9. The VPN cluster system according to claim 7, characterized in that: The routing device is further configured to detect a first state change of a VPN device in the VPN cluster based on the session, and update the routing table when the first state change satisfies a first preset condition.

10. The VPN cluster system according to claim 6, characterized in that: Also included is a management platform, the management platform is used to send a device configuration table to each VPN device in the VPN cluster, the device configuration table includes the VPN device configured for the client; The first VPN device is used to determine the second VPN device according to the device configuration table, and directly process the message when the second VPN device is the same as the first VPN device, and forward the message to the second VPN device for processing when the second VPN device is different from the first VPN device.

11. The VPN cluster system according to claim 10, characterized in that: The management platform is also used to send tunnel configuration information adapted to the client only to the VPN device configured for the client.

12. The VPN cluster system according to claim 10, characterized in that: The management platform is also used to send a set of tunnel configuration information to each VPN device in the VPN cluster, wherein the set of tunnel configuration information includes tunnel configuration information adapted to each of the clients; The management platform is further used to monitor a second state change of the VPN devices in the VPN cluster, and update the device configuration table when the second state change satisfies a second preset condition.

13. A message processing device for a VPN cluster system, characterized in that: The VPN cluster system includes a routing device, a VPN cluster and multiple clients, each VPN device in the VPN cluster is configured with the same virtual IP and unicast address, the message processing device is arranged in the routing device, and the message processing device includes: A receiving module, used for receiving a message sent by the client whose destination address is the virtual IP; a determination module, configured to select a first VPN device in the VPN cluster for forwarding the message; and The forwarding module is configured to forward the message to the first VPN device according to the unicast address of the first VPN device, wherein the first VPN device is configured to determine a second VPN device in the VPN cluster to process the message, and the second VPN device is configured to process the message.

14. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.