Automatic multi-time NAT (Network Address Translation) implementation method and system based on network data packet circulation

By introducing the path prediction technology and policy aggregation function of the DFS algorithm, the flow of network data packets and NAT policy configuration are automatically processed, which solves the problems of complex NAT configurations and insufficient automation support in the existing technology, improves network management efficiency and lowers the technical threshold.

CN120017634AActive Publication Date: 2025-05-16SHENZHEN TIANYUAN CLOUD TECH CO LTD

Patent Information

Application Number
CN202510197122.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-16
Estimated Expiration
2045-02-21

AI Technical Summary

Technical Problem

When managing complex network environments, the NAT configurations are cumbersome and prone to errors, and insufficient automation support, resulting in low network management efficiency and high technical threshold.

Method used

The path prediction technology based on the Deep First Search (DFS) algorithm is used to automatically analyze and calculate all network devices passing through the network data packets from the source node to the destination node, simulate the data packet flow, automatically identify the NAT policy configuration requirements, and automatically collect and display the policy configuration of each firewall device through the policy aggregation function.

Benefits of technology

It significantly improves the efficiency of managing complex network environments, reduces manual configuration errors, reduces maintenance costs, and reduces the technical threshold of network management, so that ordinary users can easily complete NAT management tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017634A_ABST
    Figure CN120017634A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer network communication technology, and discloses an automatic multi-time NAT (Network Address Translation) implementation method and system based on network data packet circulation. The automatic multi-time NAT implementation method is applied to a network address translation device, and specifically comprises the following steps: S101, obtaining a request destination and a route of a source node, and finally reaching a destination address according to the request destination and the route through one or more times of forwarding in a cloud topology so as to generate an access line path topology; s102, searching all paths from a source node to a destination node by using depth-first, and simulating whether a route from each path to the destination node is reachable or not for a data packet from the source node; according to the method, a path prediction technology based on a depth-first search (DFS) algorithm is introduced, all network equipment through which a network data packet passes from a source node to a destination node is automatically analyzed and calculated, the circulation conditions of the data packet on different paths are accurately simulated, and NAT strategy configuration requirements are automatically identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network communication technology, and in particular to an automated multiple NAT implementation method and system based on network data packet flow. Background Art

[0002] Network Address Translation (NAT) is an Internet Engineering Task Force (IETF) standard that allows an entire organization to use the same public IP address to appear on the Internet. It is a technology that translates internal private network addresses (IP addresses) into legal public network IP addresses. Network Address Port Translation (NAPT) further develops the concept of "basic NAT" translation. While translating addresses, it also translates transport layer identifiers (such as TCP / UDP port numbers, ICMP query IDs), thereby multiplexing the transport layer identifiers of multiple internal hosts into a unique external address. NAPT allows a group of hosts to share a unique external address. In this application, NAT and NATP are collectively referred to as NAT.

[0003] In the network management of the financial field, especially in financial institutions such as banks and securities, Network Address Translation (NAT) technology is often used to manage IP resources and ensure secure communication between regions. In the current network environment management, operation and maintenance personnel need to manually calculate and configure multiple NATs to ensure that data packets can flow accurately in complex network paths. The main shortcomings are as follows:

[0004] High complexity: In the case of multiple NATs, the operation and maintenance personnel need to manually calculate the NAT configuration of each hop. This process is cumbersome and error-prone, especially on multiple network devices and multiple routing links. Manual configuration is extremely inefficient and difficult to maintain.

[0005] Insufficient automation: The technology does not provide sufficient support for multiple NAT automation, especially in large cloud environments. As the complexity of network topology increases, it is unable to effectively cope with path prediction and dynamic calculation, resulting in reduced network management efficiency. In addition, the NAT management system requires high professional skills from network administrators. It is difficult for ordinary users to master these systems, and the learning curve is steep. Summary of the invention

[0006] The purpose of the present invention is to provide an automated multiple NAT implementation method and system based on network data packet flow, which significantly improves the efficiency of managing complex network environments, reduces manual configuration errors, reduces maintenance costs, and greatly reduces the technical threshold of network management through automated functions such as path prediction, data packet flow simulation, and policy convergence, aiming to solve the problems in the prior art.

[0007] The present invention is implemented in this way: an automated multiple NAT implementation method based on network data packet flow is applied to a network address translation device, specifically comprising the following steps:

[0008] S101: Obtain the request destination and route of the source node, and finally reach the destination address after one or more forwardings in the cloud topology according to the request destination and route, so as to generate an access line path topology;

[0009] S102: starting from the source node, use depth-first search to search all paths to the destination node. For the data packet, start from the source node, simulate whether the route from each path to the destination node is reachable, and exclude those unreachable paths.

[0010] S103: According to the required source, destination address, service and source node, simulate the data flow state in the real network, and accurately understand the data packet processing flow of each firewall on the line before performing the simulation operation;

[0011] S104: Determine whether there is a matching Static NAT by processing NAT and Policy. If not, determine whether there is a matching destination NAT. Then calculate the route, policy, and source NAT in sequence, predefine the NAT IP address pool and the data packet entering the device, and calculate the change of the five-tuple of the data packet in the device.

[0012] S105: Calculate the policies and NAT policies to be enabled for all devices on the entire predicted path, understand the packet processing flows of all different types of devices on the link in advance, define the agreed NAT IP address pool range on the devices, calculate the policies to be enabled for each device on the link so that different networks can be accessed normally, and synchronize data aggregation.

[0013] Further, in S101, according to the request destination and the route, the request is forwarded once or multiple times in the cloud topology to finally reach the destination address, so as to generate an access line path topology, including:

[0014] Draw a topology based on the line structure on the cloud, in which multiple firewalls and network nodes are connected;

[0015] Find the corresponding source and destination nodes according to the source and destination IP and topology information of the data packet;

[0016] Use depth-first search to find all paths from the source node to the destination node.

[0017] Furthermore, all paths from the source node to the destination node are searched using a depth-first search, including:

[0018] Introduce path prediction based on depth-first search algorithm to automatically analyze and calculate all network devices that network data packets pass through from source node to destination node;

[0019] Accurately simulate the flow of data packets on different paths, automatically identify NAT policy configuration requirements, DFS current node search conditions: current node! = destination node A network node current node has not been visited;

[0020] The DFS pathfinding algorithm stops searching when the node has been visited, that is, the current node = the destination node or the current node has been visited.

[0021] Further, in S102, all paths from the source node to the destination node are searched using a depth-first search, and for the data packet, starting from the source node, a simulation is performed to determine whether the route from each path to the destination node is reachable, including:

[0022] The source node passes through multiple firewalls at once to determine the policies that need to be configured for each firewall device in the entire link. The first firewall matches the corresponding route according to the source and destination addresses to determine whether the route of the source and destination addresses is consistent with the ingress and egress interfaces of the device in the path.

[0023] If no, filter this path. If yes, enter the next firewall. The next firewall matches the corresponding route according to the source and destination addresses to determine whether the route of the source and destination addresses is consistent with the ingress and egress interfaces of the device in the path.

[0024] If not, filter the path. If yes, determine it as the destination node, and determine that the route from the simulated path to the destination node is a reachable path.

[0025] Furthermore, in S103, before simulating the data flow in the real network, it is necessary to accurately understand the data packet processing flow of each firewall on the line, including:

[0026] Traffic policing: Perform traffic policing on the data packets arriving at the firewall, check whether the data packets match the existing session, and determine whether they belong to the same session based on the source address, destination address, source port, destination port, protocol, and unique session token;

[0027] If an existing session is matched, the routing and policy lookup process is skipped and forwarding is performed directly based on the previous session information;

[0028] Check whether it matches the static NAT. If so, perform static NAT and then enter the route search process to check whether it matches the destination NAT. If there is a match, perform destination NAT matching and determine the port and zone for the data packet in and out.

[0029] Further, in S104, a NAT IP address pool and a data packet entering the device are predefined, and a change of a five-tuple of the data packet in the device is calculated, including:

[0030] According to the data packet processing flow, the predefined NAT IP address pool of the device, and the data packets entering the device, the changes of the five-tuple of the data packet in the device can be calculated;

[0031] Calculate what kind of Policy and NAT strategy need to be opened when the specified source, destination, and service pass through the device, so that the data packets of the specified source, destination, and service can pass through the device instead of being blocked by the device.

[0032] Furthermore, in S105, the packet processing flow of all different types of devices on the link is known in advance and the agreed NAT IP address pool range is defined on the device, including:

[0033] By understanding the packet processing flow of all different types of devices on the link in advance and defining the agreed NATIP address pool range on the devices, it is possible to predict the policies and NAT strategies that need to be enabled on all devices on the entire predicted path.

[0034] Based on the predicted policies and NAT policies to be enabled for all devices, the policies to be enabled for each device on the link are calculated, and the policies to be enabled for each device on the link are executed to achieve normal access between different networks.

[0035] Furthermore, the strategy for each device on the link to be activated is calculated to enable normal access between different networks and synchronize data aggregation, including:

[0036] By predicting the link and using data packets to simulate the flow of the link, it is possible to determine the policy that needs to be configured for each firewall device in the entire link to ensure that the entire link is unobstructed for specific data packets;

[0037] After the analysis is completed, these data are uniformly collected, aggregated and displayed to present a clear effect to the user. The user can easily compare and review the rationality of the configuration content, and can also quickly find unreasonable aspects and make timely modifications.

[0038] Furthermore, users can easily compare and review the rationality of configuration content, and quickly find unreasonable points and make timely modifications, including:

[0039] After the analysis is completed, the data is uniformly collected, aggregated and displayed. This process provides users with intuitive configuration visualization, making it easier for users to understand and manage network security policies.

[0040] The process of comparing and reviewing configurations becomes more efficient, and users can quickly determine whether the configuration logic is reasonable. By directly sending the configuration to the corresponding firewall device, the difficulty of users performing configuration on personal computing devices is greatly reduced.

[0041] Compared with the prior art, the method and system for realizing automatic multiple NAT based on network data packet flow provided by the present invention have the following beneficial effects:

[0042] 1. Path prediction algorithm: The system introduces path prediction technology based on the depth-first search (DFS) algorithm, which automatically analyzes and calculates all network devices that network data packets pass through from the source node to the destination node, accurately simulates the flow of data packets on different paths, and automatically identifies NAT policy configuration requirements; by simulating the changes of the five-tuple (source IP, destination IP, source port, destination port, protocol), the system can automatically identify the changes of data packets for each network device and calculate the required NAT configuration policy, reducing errors and complexity in manual configuration. In addition, it also provides a policy aggregation function, which automatically collects and displays the policy configuration of each firewall device in multiple NATs, and provides an intuitive visual interface. Users can easily verify and issue configurations to improve network management efficiency.

[0043] 2. Through automated functions such as path prediction, packet flow simulation, and policy convergence, the efficiency of managing complex network environments has been significantly improved, manual configuration errors have been reduced, maintenance costs have been reduced, and the technical threshold for network management has been greatly reduced. Even users who are not familiar with network knowledge can easily complete NAT management tasks through the visual interface and automated configuration functions provided by the system. Professional network administrators can also use this system to reduce their workload, while also improving system flexibility and scalability: by introducing depth-first search algorithms and dynamic routing simulation technology, the system can easily cope with complex network topologies, making communications between different regions more flexible, more adaptable, and more scalable, and suitable for multiple NAT management needs in large cloud environments.

[0044] The automated multiple NAT implementation system based on network data packet flow is executed in the above-mentioned automated multiple NAT implementation method, and the automated multiple NAT implementation system includes:

[0045] Prediction module, used to obtain the request purpose and route of the source node;

[0046] A topology generation module is used to generate an access line path topology according to the request purpose and the route, and finally reach the destination address through one or more forwardings in the cloud topology;

[0047] The DFS pathfinding module is used to use depth-first search from the source node to all paths between the destination node and the source node. It simulates whether the route from each path to the destination node is reachable for the data packet starting from the source node.

[0048] The flow module is used to process NAT and Policy to determine whether there is a matching Static NAT. If not, it determines whether there is a matching destination NAT. Then, the routing, policy, and source NAT are calculated in sequence, and the NAT IP address pool and the data packets entering the device are predefined.

[0049] The aggregation module is used to calculate the activation strategy for each device on the link so that different networks can access each other normally and realize data aggregation synchronously. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 A schematic diagram of the topological structure of the method for realizing automatic multiple NAT based on network data packet transfer proposed by the present invention;

[0051] Figure 2 This is a core concept diagram of the DFS pathfinding algorithm in the automated multiple NAT implementation method based on network data packet flow proposed by the present invention;

[0052] Figure 3 A schematic diagram of routing in the automated multiple NAT implementation method based on network data packet transfer proposed by the present invention;

[0053] Figure 4 A schematic diagram of the packet processing flow of the JuniperSRX firewall in the automated multiple NAT implementation method based on network data packet transfer proposed by the present invention;

[0054] Figure 5 A flowchart of link processing in the automated multiple NAT implementation method based on network data packet transfer proposed by the present invention;

[0055] Figure 6 This is a diagram showing the effect of implementing the automated multiple NAT implementation method based on network data packet transfer proposed by the present invention;

[0056] Figure 7 This is a schematic diagram of the structure of the automated multiple NAT implementation and system based on network data packet transfer proposed by the present invention. DETAILED DESCRIPTION

[0057] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0058] The implementation of the present invention is described in detail below in conjunction with specific embodiments.

[0059] The same or similar numbers in the drawings of this embodiment correspond to the same or similar parts; in the description of the present invention, it should be understood that if the terms "upper", "lower", "left", "right" and the like indicate directions or positional relationships based on the directions or positional relationships shown in the drawings, it is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction. Therefore, the terms describing the positional relationship in the drawings are only used for illustrative purposes and cannot be understood as limitations on the present invention. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to specific circumstances.

[0060] Reference Figure 1-6 As shown, the automated multiple NAT implementation method based on network data packet flow is applied to a network address translation device, and specifically includes the following steps:

[0061] S101: Obtain the request destination and route of the source node, and finally reach the destination address after one or more forwardings in the cloud topology according to the request destination and route, so as to generate an access line path topology;

[0062] Among them, according to the request purpose and the route, the request is forwarded once or multiple times in the cloud topology to finally reach the destination address, so as to generate the access line path topology, including:

[0063] Draw a topology based on the line structure on the cloud, in which multiple firewalls and network nodes are connected;

[0064] Find the corresponding source and destination nodes according to the source and destination IP and topology information of the data packet;

[0065] Use depth-first search to find all paths from the source node to the destination node.

[0066] Furthermore, all paths from the source node to the destination node are searched using a depth-first search, including:

[0067] Introduce path prediction based on depth-first search algorithm to automatically analyze and calculate all network devices that network data packets pass through from source node to destination node;

[0068] Accurately simulate the flow of data packets on different paths, automatically identify NAT policy configuration requirements, DFS current node search conditions: current node! = destination node A network node current node has not been visited;

[0069] The DFS pathfinding algorithm stops searching when the node has been visited, that is, the current node = the destination node or the current node has been visited;

[0070] Access line path prediction: In actual requests, data packets will be forwarded once or multiple times in the cloud topology according to the purpose of the request and the route and finally reach the target machine; therefore, if you want to calculate the NAT situation on the line, you need to predict the path result first, and then analyze the changes that each device will make to the data packet through the network devices passed through in the path result, and finally get the configuration results of each device. To this end, you need to draw a topology based on the line structure on the cloud. The structure of the topology can be simplified as follows (FW represents firewall, ND represents network node), from Figure 1 It can be found that even a simple topology can evolve into many paths from one source to the destination. It can be seen that the paths of the actual large-scale production network topology are even more numerous and messy. Simply predicting the line efficiency manually is limited, so an intelligent algorithm is needed to calculate all the node devices between the source and destination nodes in sequence through the topology map based on the depth-first search algorithm and the routing table;

[0071] S102: starting from the source node, use depth-first search to search all paths to the destination node. For the data packet, start from the source node, simulate whether the route from each path to the destination node is reachable, and exclude those unreachable paths.

[0072] Among them, starting from the source node, a depth-first search is used to search all paths from the destination node. For the data packet, starting from the source node, the simulation is performed to determine whether the route from each path to the destination node is reachable, including:

[0073] The source node passes through multiple firewalls at once to determine the policies that need to be configured for each firewall device in the entire link. The first firewall matches the corresponding route according to the source and destination addresses to determine whether the route of the source and destination addresses is consistent with the ingress and egress interfaces of the device in the path.

[0074] If no, filter this path. If yes, enter the next firewall. The next firewall matches the corresponding route according to the source and destination addresses to determine whether the route of the source and destination addresses is consistent with the ingress and egress interfaces of the device in the path.

[0075] If not, filter this path. If yes, determine it as the destination node, and determine that the route from the simulated path to the destination node is a reachable path;

[0076] S103: According to the required source, destination address, service and source node, simulate the data flow state in the real network, and accurately understand the data packet processing flow of each firewall on the line before performing the simulation operation;

[0077] Before simulating the data flow in a real network, it is necessary to accurately understand the packet processing flow of each firewall on the line, including:

[0078] Traffic policing: Perform traffic policing on the data packets arriving at the firewall, check whether the data packets match the existing session, and determine whether they belong to the same session based on the source address, destination address, source port, destination port, protocol, and unique session token;

[0079] If an existing session is matched, the routing and policy lookup process is skipped and forwarding is performed directly based on the previous session information;

[0080] Check whether it matches static NAT. If so, perform static NAT and then enter the route search process to check whether it matches the destination NAT. If there is a match, perform destination NAT matching and determine the port and zone for the data packet in and out.

[0081] S104: Determine whether there is a matching Static NAT for NAT and Policy processing. If not, determine whether there is a matching destination NAT. Then calculate the routing, policy, and source NAT in sequence. Predefine the NAT IP address pool and the data packets entering the device. Calculate the changes of the five-tuple of the data packet in the device. Take the Juniper SRX firewall as an example. Before performing the simulation operation, you need to accurately understand the data packet processing flow of each firewall on the line. For this purpose, you need to do a lot of research work in advance. The internal processing flow of firewall data packets refers to Figure 4 After obtaining the predicted path, the data is simulated to complete the flow in the real network world according to the required source, destination address, service and source node;

[0082] S105: Calculate the policies and NAT policies to be enabled for all devices on the entire predicted path, understand the packet processing flow of all different types of devices on the link in advance, define the agreed NAT IP address pool range on the devices, calculate the policies to be enabled for each device on the link so that different networks can be accessed normally, and synchronize data aggregation;

[0083] Among them, you need to know the packet processing flow of all different types of devices on the link in advance and define the agreed NAT IP address pool range on the device, including:

[0084] By understanding the packet processing flow of all different types of devices on the link in advance and defining the agreed NATIP address pool range on the devices, it is possible to predict the policies and NAT strategies that need to be enabled on all devices on the entire predicted path.

[0085] Based on the predicted policies to be enabled for all devices and the NAT policy, the policy to be enabled for each device on the link is calculated, and the policy to be enabled for each device on the link is executed to achieve normal access between different networks. This technical solution introduces a path prediction technology based on the depth-first search (DFS) algorithm, which automatically analyzes and calculates all network devices that network data packets pass through from the source node to the destination node, accurately simulates the flow of data packets on different paths, and automatically identifies NAT policy configuration requirements; by simulating the changes in the five-tuple (source IP, destination IP, source port, destination port, protocol), the system can automatically identify changes in data packets for each network device and calculate the required NAT configuration policy, reducing errors and complexity in manual configuration. In addition, it also provides a policy aggregation function, which automatically collects and displays the policy configuration of each firewall device in multiple NATs, and provides an intuitive visual interface. Users can easily verify and issue configurations, thereby improving network management efficiency.

[0086] In S104 of this implementation, a NAT IP address pool and a data packet entering the device are predefined, and a change of a five-tuple of the data packet in the device is calculated, including:

[0087] According to the data packet processing flow, the predefined NAT IP address pool of the device, and the data packets entering the device, the changes of the five-tuple of the data packet in the device can be calculated;

[0088] Calculate what kind of Policy and NAT strategy need to be opened when the specified source, destination, and service pass through the device, so that the data packets of the specified source, destination, and service can pass through the device instead of being blocked by the device.

[0089] In this implementation, the strategy for each device on the link to be enabled is calculated to enable normal access between different networks and synchronize data aggregation, including:

[0090] By predicting the link and using data packets to simulate the flow of the link, it is possible to determine the policy that needs to be configured for each firewall device in the entire link to ensure that the entire link is unobstructed for specific data packets;

[0091] After the analysis is completed, these data are uniformly collected, aggregated and displayed to present a clear effect to the user. The user can easily compare and review the rationality of the configuration content, and can also quickly find unreasonable aspects and make timely modifications.

[0092] In this implementation, refer to Figure 6 , users can easily compare and review the rationality of configuration content, and can quickly find unreasonable aspects and make timely modifications, including: unified collection, aggregation and display of these data after analysis. This process provides users with intuitive configuration visualization, making it easier for users to understand and manage network security strategies; the process of comparing and reviewing configurations becomes more efficient, and users can quickly determine whether the configuration logic is reasonable. By directly sending the configuration to the corresponding firewall device, the difficulty of user configuration on personal computing devices is greatly reduced.

[0093] The present invention significantly improves the efficiency of managing complex network environments through automated functions such as path prediction, data packet flow simulation, and policy convergence, reduces manual configuration errors, reduces maintenance costs, and greatly reduces the technical threshold of network management. Even users who are not familiar with network knowledge can easily complete NAT management tasks through the visual interface and automated configuration functions provided by the system. Professional network administrators can also reduce their workload through this system, while also improving system flexibility and scalability: by introducing a depth-first search algorithm and dynamic routing simulation technology, the system can easily cope with complex network topologies, making communications between different regions more flexible, more adaptable, and more scalable, and suitable for multiple NAT management needs in large cloud environments.

[0094] Reference Figure 7, an automated multiple NAT implementation system based on network data packet flow, executed in the above-mentioned automated multiple NAT implementation method, the automated multiple NAT implementation system includes: a prediction module, used to obtain the request purpose and route of the source node; a topology generation module, used to forward once or multiple times in the cloud topology according to the request purpose and route to finally reach the destination address, so as to generate an access line path topology; a DFS path finding module, used to use depth-first search from the source node to all paths between the destination node, and simulate whether the route from each path to the destination node is reachable for the data packet starting from the source node; a flow module, used to determine whether there is a matching StaticNAT for NAT and Policy processing, and if not, determine whether there is a matching destination NAT, and then calculate the route, policy, and source NAT in sequence, predefine the NATIP address pool and the data packet entering the device; aggregation module The module is used to calculate the policy to be opened for each device on the link so that different networks can be accessed normally and data convergence can be achieved synchronously. The path prediction algorithm of the present invention introduces a path prediction technology based on the depth-first search (DFS) algorithm, automatically analyzes and calculates all network devices that network data packets pass through from the source node to the destination node, accurately simulates the flow of data packets on different paths, and automatically identifies NAT policy configuration requirements; by simulating the changes of the five-tuple (source IP, destination IP, source port, destination port, protocol), the system can automatically identify the changes of data packets for each network device and calculate the required NAT configuration policy, reducing errors and complexity in manual configuration. In addition, a policy convergence function is provided to automatically collect and display the policy configuration of each firewall device in multiple NATs, and provide an intuitive visual interface. Users can easily verify and issue configurations, thereby improving network management efficiency.

[0095] In this embodiment, the entire operation process can be controlled by a computer to achieve automatic operation control, and in each operation link, sensors can be set to provide signal feedback to achieve sequential execution of steps. These are all common knowledge of current automatic control and will not be described in detail in this embodiment.

[0096] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. An automated multiple NAT implementation method based on network data packet flow, characterized in that: Applied to network address translation equipment, specifically including the following steps: S101: Obtain the request destination and route of the source node, and finally reach the destination address after one or more forwardings in the cloud topology according to the request destination and route, so as to generate an access line path topology; S102: starting from the source node, use depth-first search to search all paths to the destination node. For the data packet, start from the source node, simulate whether the route from each path to the destination node is reachable, and exclude those unreachable paths. S103: According to the required source, destination address, service and source node, simulate the data flow state in the real network, and accurately understand the data packet processing flow of each firewall on the line before performing the simulation operation; S104: Determine whether there is a matching Static NAT by processing NAT and Policy. If not, determine whether there is a matching destination NAT. Then calculate the route, policy, and source NAT in sequence, predefine the NAT IP address pool and the data packet entering the device, and calculate the change of the five-tuple of the data packet in the device. S105: Calculate the policies and NAT policies to be enabled for all devices on the entire predicted path, understand the packet processing flows of all different types of devices on the link in advance, define the agreed NAT IP address pool range on the devices, calculate the policies to be enabled for each device on the link so that different networks can be accessed normally, and synchronize data aggregation.

2. The method for realizing automatic multiple NAT based on network data packet flow according to claim 1, characterized in that: In S101, according to the request destination and the route, the request is forwarded once or multiple times in the cloud topology to finally reach the destination address, so as to generate an access line path topology, including: Draw a topology based on the line structure on the cloud, in which multiple firewalls and network nodes are connected; Find the corresponding source and destination nodes according to the source and destination IP and topology information of the data packet; Use depth-first search to find all paths from the source node to the destination node.

3. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 2, characterized in that: Use depth-first search to find all paths from the source node to the destination node, including: Introduce path prediction based on depth-first search algorithm to automatically analyze and calculate all network devices that network data packets pass through from source node to destination node; Accurately simulate the flow of data packets on different paths, automatically identify NAT policy configuration requirements, DFS current node search conditions: current node! = destination node A network node current node has not been visited; The DFS pathfinding algorithm stops searching when the node has been visited, that is, the current node = the destination node or the current node has been visited.

4. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 3, characterized in that: In S102, all paths from the source node to the destination node are searched using a depth-first search. For a data packet, starting from the source node, a simulation is performed to determine whether the route from each path to the destination node is reachable, including: The source node passes through multiple firewalls at once to determine the policies that need to be configured for each firewall device in the entire link. The first firewall matches the corresponding route according to the source and destination addresses to determine whether the route of the source and destination addresses is consistent with the ingress and egress interfaces of the device in the path. If no, filter this path. If yes, enter the next firewall. The next firewall matches the corresponding route according to the source and destination addresses to determine whether the route of the source and destination addresses is consistent with the ingress and egress interfaces of the device in the path. If not, filter the path. If yes, determine it as the destination node, and determine that the route from the simulated path to the destination node is a reachable path.

5. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 4, characterized in that: In S103, before simulating the data flow in the real network, it is necessary to accurately understand the data packet processing flow of each firewall on the line, including: Traffic policing: Perform traffic policing on the data packets arriving at the firewall, check whether the data packets match the existing session, and determine whether they belong to the same session based on the source address, destination address, source port, destination port, protocol, and unique session token; If an existing session is matched, the routing and policy lookup process is skipped and forwarding is performed directly based on the previous session information; Check whether it matches the static NAT. If so, perform static NAT and then enter the route search process to check whether it matches the destination NAT. If there is a match, perform destination NAT matching and determine the port and zone for the data packet in and out.

6. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 5, characterized in that: In S104, a NAT IP address pool and a data packet entering the device are predefined, and a change of a five-tuple of the data packet in the device is calculated, including: According to the data packet processing flow, the predefined NAT IP address pool of the device, and the data packets entering the device, the changes of the five-tuple of the data packet in the device can be calculated; Calculate what kind of Policy and NAT strategy need to be opened when the specified source, destination, and service pass through the device, so that the data packets of the specified source, destination, and service can pass through the device instead of being blocked by the device.

7. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 6, characterized in that: In S105, the packet processing flow of all different types of devices on the link is known in advance and the agreed NATIP address pool range is defined on the device, including: By understanding the packet processing flow of all different types of devices on the link in advance and defining the agreed NAT IP address pool range on the devices, it is possible to predict the policies and NAT strategies that need to be enabled for all devices on the entire predicted path. Based on the predicted policies and NAT policies to be enabled for all devices, the policies to be enabled for each device on the link are calculated, and the policies to be enabled for each device on the link are executed to achieve normal access between different networks.

8. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 7, characterized in that: Calculate the activation strategy for each device on the link to enable normal access between different networks and synchronize data aggregation, including: By predicting the link and using data packets to simulate the flow of the link, it is possible to determine the policy that needs to be configured for each firewall device in the entire link to ensure that the entire link is unobstructed for specific data packets; After the analysis is completed, these data are uniformly collected, aggregated and displayed to present a clear effect to the user. The user can easily compare and review the rationality of the configuration content, and can also quickly find unreasonable aspects and make timely modifications.

9. The method for realizing automatic multiple NAT based on network data packet transfer according to claim 8, characterized in that: Users can easily compare and review the rationality of configuration content, and quickly find unreasonable points and make timely modifications, including: After the analysis is completed, the data is uniformly collected, aggregated and displayed. This process provides users with intuitive configuration visualization, making it easier for users to understand and manage network security policies. The process of comparing and reviewing configurations becomes more efficient, and users can quickly determine whether the configuration logic is reasonable. By directly sending the configuration to the corresponding firewall device, the difficulty of users performing configuration on personal computing devices is greatly reduced.

10. An automated multiple NAT implementation system based on network data packet flow, characterized in that: The method for implementing the automated multiple NAT according to any one of claims 1 to 9, wherein the automated multiple NAT implementation system comprises: Prediction module, used to obtain the request purpose and route of the source node; A topology generation module is used to generate an access line path topology according to the request purpose and the route, and finally reach the destination address through one or more forwardings in the cloud topology; The DFS pathfinding module is used to use depth-first search from the source node to all paths between the destination node and the source node. It simulates whether the route from each path to the destination node is reachable for the data packet starting from the source node. The flow module is used to process NAT and Policy to determine whether there is a matching Static NAT. If not, it determines whether there is a matching destination NAT. Then, the routing, policy, and source NAT are calculated in sequence, and the NAT IP address pool and the data packets entering the device are predefined. The aggregation module is used to calculate the activation strategy for each device on the link so that different networks can access each other normally and realize data aggregation synchronously.

Citation Information

Patent Citations

  • Data forwarding method based on different priorities in software-defined network

    CN103825823A

  • Method and device for determining strategy path

    CN110430130A

  • Access path query method and device, computer equipment and storage medium

    CN112910721A

Cited By

  • Method and device for constructing traffic forwarding path topological graph

    CN121619277A