Domain name isolation method and device of private network, storage medium and program product
By using domain name servers and configuration view collections in private networks, the problem of low resource utilization of domain name isolation system in the prior art is solved, and the isolation and customized response of DNS domain names in multi-tenant networks are realized, and resource utilization is improved.
Patent Information
- Application Number
- CN202510545884.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the domain name isolation system has the problem of low resource utilization rate and no effective solution has been proposed.
By introducing a domain name server into a private network, the target configuration view corresponding to the virtual cloud is determined using the configuration view set, and then the domain name is parsed and the subnet address is returned to the domain name isolation.
This method does not require a separate configuration of a domain name server for each private virtual cloud, which improves resource utilization and realizes the isolation and customized response of DNS domain names in a multi-tenant network.
Smart Images

Figure CN120074964A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of domain name conversion, and particularly relates to a method and apparatus for isolating domain names in a private network, a storage medium, and a program product. Background Art
[0002] In a cloud computing platform, a tenant can manage one or more virtual private clouds (VPCs) to support the deployment of different business applications. Due to business requirements, resource interaction may be required between different VPC networks. To simplify the mutual access between different VPCs, the Domain Name System (DNS) can be used for access.
[0003] During the process of accessing using the domain name system, it may occur that the same domain name is used to access different VPC networks. Therefore, a function that has the same domain name but different address resolutions for different VPCs is required to ensure the accuracy of mutual access. In the related art, usually a separate DNS server is deployed for each VPC. Obviously, in the face of multiple VPCs, this method requires a large amount of computing resources, resulting in waste of resources.
[0004] In view of the technical problem in the related art that the current domain name isolation system has low resource utilization rate, no effective solution has been proposed yet. Summary of the Invention
[0005] This application provides a method and apparatus for isolating domain names in a private network, a storage medium, and a program product, so as to at least solve the problem of low resource utilization rate in the domain name isolation system in the related art.
[0006] This application provides a method for isolating domain names in a private network, including: a first virtual cloud sending domain name request information to a domain name server, where the domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud;
[0007] The domain name server determines at least one target configuration view corresponding to the first virtual cloud in the configuration view set according to the first global address, where the configuration view is used to indicate the relationship between the domain name and the address;
[0008] According to the target configuration view, determine the first subnet address corresponding to the domain name to be resolved, and return the first subnet address to the first virtual cloud, where the first subnet address is used to indicate the address corresponding to the subnet in the first virtual cloud of the domain name to be resolved.
[0009] The present application also provides a domain name isolation device for a private network, including: a request sending module, configured to send domain name request information from a first virtual cloud to a domain name server, where the domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud;
[0010] a configuration view determination module, configured to determine, by the domain name server according to the first global address, at least one target configuration view corresponding to the first virtual cloud from a set of configuration views, where the configuration view is used to indicate the relationship between a domain name and an address;
[0011] a domain name resolution module, configured to determine, according to the target configuration view, a first subnet address corresponding to the domain name to be resolved, and return the first subnet address to the first virtual cloud, where the first subnet address is used to indicate the address corresponding to the subnet in the first virtual cloud where the domain name to be resolved is located.
[0012] The present application also provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any of the above domain name isolation methods for a private network when executing the computer program.
[0013] The present application also provides a computer-readable storage medium, in which a computer program is stored, where the computer program implements the steps of any of the above domain name isolation methods for a private network when executed by a processor.
[0014] The present application also provides a computer program product, including a computer program, where the computer program implements the steps of any of the above domain name isolation methods for a private network when executed by a processor.
[0015] Through this application, a first virtual cloud sends domain name request information to a domain name server. The domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud. The domain name server determines at least one target configuration view corresponding to the first virtual cloud in a set of configuration views according to the first global address. The configuration view is used to indicate the relationship between the domain name and the address. According to the target configuration view, the first subnet address corresponding to the domain name to be resolved is determined and returned to the first virtual cloud. The first subnet address is used to indicate the address corresponding to the subnet of the domain name to be resolved in the first virtual cloud. Through the above method, domain name resolution for different private virtual clouds can be achieved through a set of domain name servers, and domain name isolation can be achieved. When performing domain name resolution for each private virtual cloud, the domain name server will obtain the global address of the private virtual cloud and determine the corresponding configuration view in the set of configuration views according to the global address, so as to achieve the effect of domain name isolation through the globally unique global address. There is no need to configure a domain name server separately for each private virtual cloud. Therefore, the problem of low resource utilization rate in the domain name isolation system in the related technology can be solved, and the technical effect of improving resource utilization rate can be achieved. Brief Description of the Drawings
[0016] In order to more clearly illustrate the embodiments of the present application, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other accompanying drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 It is a schematic diagram of the hardware environment of an optional method for domain name isolation of a private network according to an embodiment of the present application;
[0018] Figure 2 It is a flowchart of an optional method for domain name isolation of a private network according to an embodiment of the present application;
[0019] Figure 3 It is a structural block diagram of an optional device for domain name isolation of a private network according to an embodiment of the present application. Detailed Embodiments
[0020] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present application.
[0021] It should be noted that in the description of this application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0022] In order to enable those skilled in the art of this technology to better understand the solution of this application, the following further detailed description of this application will be given in conjunction with the accompanying drawings and specific embodiments.
[0023] According to one aspect of the embodiments of this application, a method for domain name isolation of a private network is provided. As an alternative embodiment, the method for domain name isolation of the above private network can be but is not limited to being applied to a domain name isolation system of a private network in a hardware environment as shown in Figure 1 The domain name isolation system of the private network may include but is not limited to a first virtual cloud 102, a second virtual cloud 106, and a domain name server 116. Among them, the first virtual cloud 102 may include a VPC gateway and a domain name router 104, the second virtual cloud 106 may include a VPC gateway and a domain name router 108, and the domain name server 116 may include multiple configuration views (such as Figure 1 Configuration view 110, configuration view 112, and configuration view 114 in
[0024] Among them, both the first virtual cloud 102 and the second virtual cloud 106 are virtual private clouds (VPCs), which are a virtualized network environment in cloud computing and are used to implement the private network space of users on the cloud platform. Each VPC has an independent network configuration, including subnets, IP address pools, routing tables, etc., and can provide network isolation and security protection for different applications or tenants on the cloud.
[0025] Both the domain name router 104 and the domain name router 108 are DNS routers, which are virtual routers created in the VPC and are specifically used to process DNS requests. It forwards DNS queries within the VPC to an external DNS server by configuring static routing or dynamic routing policies. At the same time, it is also the entry for DNS responses to return to the VPC, ensuring the correct and efficient transfer of DNS traffic between the VPC and the external DNS server.
[0026] The VPC gateway is the boundary gateway for the interaction between the internal and external networks of the VPC, and is used for NAT address translation, firewall policy implementation, etc. The VPC gateway is the only way for communication between the VPC and the external network, and all traffic entering and leaving the VPC will pass through the VPC gateway for processing, such as NAT conversion, security filtering, etc.
[0027] The domain name server 116 (DNS server) is a server that provides domain name resolution services and can convert human-readable domain names into machine-readable IP addresses. The DNS server plays a key role in a multi-tenant network. It returns the corresponding IP address according to the domain name and source IP address in the DNS request, enabling resources in the cloud environment to be accessed through the domain name.
[0028] The configuration view (View) is a mechanism in the DNS server that provides different DNS resolution results according to the IP address range of the client. The configuration view allows the DNS server to select the correct DNS data set to return to the client according to the IP address of the request source when receiving a DNS request, and is the core technology for implementing DNS domain name isolation in a multi-tenant network.
[0029] In one example, the global network can be 100.64.0.0 / 16, the second global address of the domain name server 116 can be 100.64.0.253, the first global address of the domain name router 104 in the first virtual cloud 102 facing the outside can be 100.64.1.10, and the global address of the domain name router 108 in the second virtual cloud 106 facing the outside can be 100.64.1.11. The configuration view 110 in the domain name server 116 can be a configuration view with Match-clients set to 100.64.1.10, which only matches the first virtual cloud 102; the configuration view 112 can be a configuration view with Match-clients set to 100.64.1.11, which only matches the second virtual cloud 106; the configuration view 114 can be a configuration view with Match-clients set to 100.64.1.10 and 100.64.1.11, which matches the first virtual cloud 102 and the second virtual cloud 106.
[0030] The embodiments of the present application provide a method for domain name isolation in a private network. Figure 2 is a flowchart of an optional method for domain name isolation in a private network according to an embodiment of the present application; as Figure 2 shown, the method for domain name isolation in the private network includes:
[0031] Step S202, the first virtual cloud sends domain name request information to the domain name server, where the domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud.
[0032] It should be noted that the first virtual cloud refers to a virtual private cloud (VPC) used by a specific tenant in a multi-tenant network environment. The "first" here does not mean the first in sequence, but is only used to distinguish different VPCs in the description. Each VPC may serve an independent business or tenant and has its own network resources and configurations. The first global address is the global (public) IP address obtained through network address translation (NAT) when internal resources of the first virtual cloud access an external network (such as the Internet). The first global address is used to identify the first virtual cloud on the DNS server to ensure that the DNS server can provide the correct resolution result based on this address.
[0033] A domain name server is a server in the DNS (Domain Name System) that is responsible for resolving the mapping relationship between domain names and IP addresses. In the scenario of multi-tenant network isolation, the domain name server needs to return different resolution results according to the request source of the client (here, the resources of the VPC). When a client needs to resolve a domain name, it sends a domain name request to the DNS server, and this request information includes the domain name to be resolved and the source address of the request (in the case of a multi-tenant network, it is the global address assigned by the NAT gateway of the VPC).
[0034] In an optional implementation, the domain name request sent by the resource includes two parts of information: one is the domain name to be resolved, and the other is the global address used by the resource to access the DNS server, which is assigned by the NAT gateway of the first virtual cloud.
[0035] In a multi-tenant network environment, especially in the method of implementing DNS domain name isolation, each virtual cloud (VPC) may need to resolve the same domain name but expects to obtain different resolution results to adapt to its respective network environment. Therefore, when a resource (such as a server or an application) in the first virtual cloud needs to resolve a domain name, it does not directly send the request to the DNS server. Instead, it first sends the request to the NAT gateway of the VPC through the network configuration inside the VPC. After receiving this request, the NAT gateway converts its source address into a predefined global address (i.e., the first global address), which is the key identifier for the DNS server to identify the first virtual cloud.
[0036] Step S204, the domain name server determines at least one target configuration view corresponding to the first virtual cloud in the set of configuration views, where the configuration view is used to indicate the relationship between the domain name and the address.
[0037] It should be noted that the configuration view set is a collection of multiple views (view) defined in a DNS server (such as Bind9). Each view defines different DNS resolution rules for handling DNS query requests from different sources. The target configuration view is the configuration view in the configuration view set that is related to a specific VPC (identified by the first global address), and it will determine the IP address record returned when a domain name resolution is requested within that VPC.
[0038] In an alternative embodiment, the configuration view set contains multiple views, and each view defines a different mapping relationship between a domain name and an IP address, that is, a DNS record. When a DNS request arrives from a certain VPC, its source IP address has been converted to an address in the global network corresponding to that VPC. The DNS server will check this address and then look for a configuration view in the configuration view set that matches this global address. Once a matching view is found, the DNS server will use the relationship between the domain name and the IP address defined in that view to respond to the query request, thus achieving the isolation and customized response of the same domain name between different VPCs.
[0039] In an alternative embodiment, the DNS server determines the source of the request through a predefined configuration view set and the match-clients rules configured in each view, and selects the correct view to handle the DNS query. In this way, even if different VPCs use the same domain name, the DNS server can return the correct IP address related to that VPC, achieving the isolation of the domain name resolution results.
[0040] Step S206, according to the target configuration view, determine the first subnet address corresponding to the domain name to be resolved, and return the first subnet address to the first virtual cloud, where the first subnet address is used to indicate the address corresponding to the subnet in the first virtual cloud where the domain name to be resolved is located.
[0041] It should be noted that the domain name to be resolved is the domain name that the user requests to resolve within the VPC, such as "web.testserver.com". The first subnet address is the address of the subnet within the VPC associated with the domain name to be resolved, such as "10.0.1.0 / 24". This is the IP address in the DNS response that points to a specific resource within the VPC.
[0042] In an alternative embodiment, the DNS server looks up the first subnet address associated with the domain name to be resolved, that is, the resource IP address within the VPC, according to the view (configuration view) matched by the client query request (corresponding to a specific VPC). The DNS server returns the resolved IP address (the first subnet address) as a response to the DNS client within the VPC, allowing the client to access the corresponding resource within the VPC.
[0043] In an alternative embodiment, when a DNS client (such as a server within a VPC) initiates a DNS resolution request, the DNS server determines which view should handle the request based on the client's IP address. Specific domain name record sets are configured in the view, and these record sets contain subnet addresses associated with the VPC. Therefore, even though the domain names are the same, the IP addresses returned by the DNS server vary according to the different VPCs, thus achieving resource access isolation between different tenants.
[0044] In an alternative embodiment, assume there are two VPCs, VPC_A and VPC_B, both of which request to resolve the domain name "web.testserver.com". The DNS client IP address of VPC_A is 100.64.1.10, while that of VPC_B is 100.64.1.11. In the DNS server (such as using Bind9), views have been configured for these two VPCs respectively.
[0045] When the client of VPC_A sends a query for "web.testserver.com", the DNS server will look up the zone file related to "view_vpcA" and the resolved IP address is "10.0.1.10". On the contrary, when the client of VPC_B queries the same domain name, the DNS server will resolve "10.0.2.10" from the zone file of "view_vpcB" as the response. In this way, even though the two VPCs use the same domain name, the DNS server can return the correct subnet address according to the client IP address and view configuration, ensuring the independence and security of each VPC's access to internal resources.
[0046] Through this application, a first virtual cloud sends domain name request information to a domain name server. The domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud. The domain name server determines at least one target configuration view corresponding to the first virtual cloud from a set of configuration views according to the first global address. The configuration view is used to indicate the relationship between the domain name and the address. According to the target configuration view, the first subnet address corresponding to the domain name to be resolved is determined and returned to the first virtual cloud. The first subnet address is used to indicate the address corresponding to the subnet of the domain name to be resolved in the first virtual cloud. Through the above method, domain name resolution for different private virtual clouds can be implemented through a set of domain name servers, and domain name isolation can be achieved. When performing domain name resolution for each private virtual cloud, the domain name server will obtain the global address of the private virtual cloud and determine the corresponding configuration view from the set of configuration views according to the global address, so as to achieve the effect of domain name isolation through the globally unique global address. There is no need to configure a domain name server separately for each private virtual cloud. Therefore, the problem of low resource utilization rate in the domain name isolation system in the related art can be solved, and the technical effect of improving resource utilization rate can be achieved.
[0047] In an alternative embodiment, the first virtual cloud sending domain name request information to the domain name server includes: a domain name router in the first virtual cloud generates the first global address of the first virtual cloud, where the domain name router corresponds to the virtual cloud one by one; the first global address of the first virtual cloud and the domain name to be resolved are sent to the domain name server as domain name request information.
[0048] It should be noted that the domain name router is a router inside the virtual cloud used to route DNS requests. It will generate a global address, enabling resources within the VPC to access the DNS server through this global address. The first global address is the address in the global network generated by the domain name router for the first virtual cloud, and is used to identify the DNS request of the first virtual cloud, ensuring that the DNS server can identify the source VPC of the request according to this address for domain name resolution isolation.
[0049] In an alternative embodiment, within the first virtual cloud, there is a dedicated domain name router responsible for handling DNS requests. When a resource within the VPC needs to query a domain name, the domain name router generates a global address (the first global address) to replace the private IP address of the resource, ensuring that the DNS server can identify the source VPC of the request. The domain name request information is constructed, including the domain name to be resolved and the first global address. This means that when the DNS server receives the request, it can not only know which domain name to resolve but also determine which VPC the request comes from through the first global address. The domain name request information is then sent to the DNS server, which resolves the domain name and determines the resolution result to be returned to which VPC based on the first global address.
[0050] In an alternative embodiment, in this multi-tenant network scenario, each VPC has a dedicated domain name router for handling DNS queries. When a resource within the VPC attempts to access other resources, it first sends the request to the domain name router. After receiving the request, the domain name router converts the private IP address of the resource into a global address (the first global address), and then constructs the domain name request information, including the converted global address and the domain name to be resolved. The domain name request information is then sent to the DNS server, which will determine the source VPC of the request based on the global address and use the view associated with that VPC to resolve the domain name, thus returning the correct IP address to the resource within the VPC.
[0051] In an alternative embodiment, assume there are two VPCs, VPC_A and VPC_B, both of which need to resolve the same domain name web.testserver.com, but the resolution results should point to different servers within their respective VPCs. To achieve this, two domain name routers are configured:
[0052] The domain name router of VPC_A has the global address 100.64.1.10.
[0053] The domain name router of VPC_B has the global address 100.64.1.11.
[0054] The DNS server is configured with two views:
[0055] VPC_A_View, which is used to handle all DNS queries from 100.64.1.10, and the A record of web.testserver.com is configured as 10.0.0.10.
[0056] VPC_B_View, which is used to handle all DNS queries from 100.64.1.11, and the A record of web.testserver.com is configured as 10.0.1.10.
[0057] When resources within VPC_A attempt to access web.testserver.com, they first send the request to the domain name router of VPC_A. The router converts the source address of the request to 100.64.1.10 and then constructs a domain name request message that includes web.testserver.com and 100.64.1.10. This request message is then sent to the DNS server. The DNS server identifies 100.64.1.10 and uses VPC_A_View to resolve the domain name, finally returning 10.0.0.10 to the resources within VPC_A.
[0058] Similarly, when resources within VPC_B attempt to access web.testserver.com, their request is first sent to the domain name router of VPC_B. The router converts the source address of the request to 100.64.1.11 and constructs a domain name request message that includes web.testserver.com and 100.64.1.11. After receiving this request, the DNS server identifies 100.64.1.11, uses VPC_B_View to resolve the domain name, and returns 10.0.1.10 to the resources within VPC_B.
[0059] Through the above implementation manners of the present application, even if multiple VPCs use the same domain name, the DNS server can accurately return the resource address related to the requesting VPC, achieving the isolation of DNS domain names and customized responses in a multi-tenant network.
[0060] In an alternative implementation manner, sending the first global address of the first virtual cloud and the domain name to be resolved as a domain name request message to the domain name server includes: the internal gateway in the first virtual cloud sends the domain name to be resolved and the second global address of the domain name server to the domain name router; the domain name router uses the second global address as the destination network segment and sends the domain name request message to the domain name server.
[0061] It should be noted that the internal gateway is a device used to manage internal network traffic in each VPC, responsible for sending the network requests within the VPC to the external network or specific network services after NAT conversion. The second global address is the public IP address of the domain name server in the global network, used to receive DNS requests from different VPCs.
[0062] In an alternative embodiment, when resources (such as servers or applications) within a VPC need to resolve a domain name, they send request information containing the domain name to be resolved and the second global address of the DNS server to the internal gateway of the VPC. After receiving this request, the internal gateway then forwards the converted request information to the domain name router, which converts the source IP address to the first global address corresponding to the VPC. The domain name router identifies the second global address of the DNS server as the destination network segment and sends the entire DNS request information to the DNS server to wait for the resolution result.
[0063] In an alternative embodiment, by using the internal gateway for NAT conversion, the private IP addresses within the VPC can be hidden, enhancing network security. As an intermediate communication node, the domain name router can not only guide the DNS request to reach the DNS server correctly but also avoid exposing the internal network structure of the VPC during the DNS resolution process, further safeguarding the resource security and network isolation in a multi-tenant network. At the same time, the second global address of the DNS server serves as a unified access point, simplifying the routing configuration of DNS requests and improving network efficiency.
[0064] In an alternative embodiment, assume the following network configuration:
[0065] VPC_A: Internal network 10.0.0.0 / 16, global address (first global address) 100.64.1.10 assigned by the NAT gateway.
[0066] DNS server: IP address (second global address) 200.1.1.1 in the global network.
[0067] When a resource in VPC_A (for example, a server with the IP address 10.0.0.5) needs to resolve the domain testserver.com, it first sends the request to the internal gateway of VPC_A. After receiving the request, the NAT gateway forwards the request information containing the domain name to be resolved testserver.com and the second global address 200.1.1.1 of the DNS server to the domain name router. The domain name router converts the source IP address 10.0.0.5 to the global address 100.64.1.10.
[0068] The domain name router is configured with a static route with 200.1.1.1 as the destination network segment. After receiving the DNS request, it identifies that the IP address 200.1.1.1 is the second global address of the DNS server and then sends the DNS request information to the DNS server with 200.1.1.1 as the destination address.
[0069] After the DNS server receives this DNS request, it identifies that the request comes from VPC_A based on the source address 100.64.1.10, processes the request using the VPC_A_View configuration view (which contains specific resolution records for testserver.com), and returns the resolution result (such as 192.168.1.10) to the domain name router via the second global address 200.1.1.1. The domain name router then forwards the result to the NAT gateway of VPC_A and finally returns the resolved IP address to the resource that initially initiated the DNS request.
[0070] Through the above implementation manners of this application, even if different VPC resources use the same domain name, the DNS server can, based on different source addresses, return resolution results related to their respective VPCs, achieving DNS domain name isolation in a multi-tenant network.
[0071] In an optional implementation manner, before the internal gateway in the first virtual cloud sends the domain name to be resolved and the second global address of the domain name server to the domain name router, it includes: configuring the destination network segment for the internal gateway in the first virtual cloud as the global network segment, where the first global address and the second global address are included in the global network segment; configuring the next address to reach for the internal gateway in the first virtual cloud as the first communication address corresponding to the domain name router, where the first communication address is used to indicate the communication address of the domain name router.
[0072] It should be noted that the global network segment is a public network address range that covers all VPCs and includes the global addresses used by the NAT gateways of all VPCs and the global address of the DNS server. The first communication address is the communication address of the domain name router in the VPC and is used for the internal gateway to identify and forward DNS-related traffic.
[0073] In an optional implementation manner, the internal gateway needs to be configured to identify the global network segment, which includes the global addresses used by the NAT gateways of the VPC and the public IP address of the DNS server. Then, the internal gateway is set to forward the DNS request to the domain name router, and the communication address (the first communication address) of the domain name router becomes the next-hop address for the internal gateway's DNS traffic. In this way, DNS requests within the VPC can indirectly reach the DNS server through the domain name router, achieving secure communication between the VPC and the DNS server and maintaining network isolation.
[0074] Through the above implementation manners of this application, by configuring the next-hop address of the internal gateway as the communication address of the domain name router, all DNS requests and responses will be forwarded through the domain name router, which not only simplifies network management but also increases network security because the private IP addresses within the VPC are not directly exposed to the DNS server.
[0075] In an alternative embodiment, the first global address of the first virtual cloud and the domain name to be resolved are sent as domain name request information to a domain name server. Thereafter, the following steps are included: the domain name router receives the first subnet address and sends the first subnet address to the internal gateway in the first virtual cloud.
[0076] In an alternative embodiment, the first global address of the first virtual cloud (which is used to identify the VPC where the request originates) and the domain name to be resolved. After receiving this request, the DNS server uses the target configuration view (i.e., the view corresponding to the VPC) to resolve the domain name and returns a first subnet address, which is resolved based on the DNS record set configured for the requested VPC. Next, the first subnet address in the DNS response is received by the domain name router, and the task of the domain name router is to forward this resolution result to the internal gateway within the VPC. The internal gateway is responsible for further providing this subnet address information to the resource that initially sent the DNS request, enabling the resource to access the target service or host within its VPC using the resolved private network address.
[0077] In an alternative embodiment, when a resource within the VPC requests DNS resolution, the DNS request information includes the global address of the VPC where the resource is located and the domain name to be resolved. The DNS server determines the correct resolution result, i.e., the first subnet address, based on the global address and the set of configuration views, and then returns this resolution result to the domain name router that sent the request. After receiving the first subnet address, the domain name router forwards it to the internal gateway within the VPC, and the internal gateway then provides the resolution result to the resource, allowing the resource to access services or hosts within the VPC according to the resolution result without caring about the DNS server address in the global network. This process ensures that the domain name resolution requests and responses of resources in different VPCs are isolated from each other, while maintaining the privacy and security of resource access to internal services.
[0078] In an alternative embodiment, assume there is a VPC_A, and the global address of its domain name router is 100.64.1.10. A VPC_A_View view corresponding to VPC_A has been configured on the DNS server. When a resource (e.g., a server or a client) within VPC_A attempts to access an internal web service via the domain name web.testserver.com, the resource first sends a DNS query request to the domain name router. The request information includes the domain name web.testserver.com to be resolved and the global address 100.64.1.10 of VPC_A. The domain name router forwards this request to the DNS server. After receiving the request, the DNS server identifies 100.64.1.10 and uses the VPC_A_View view to resolve the domain name web.testserver.com. According to the DNS records of VPC_A, the DNS server resolves web.testserver.com to 10.0.0.10 (assuming this is a private subnet address belonging to VPC_A). Subsequently, the DNS server returns the resolution result 10.0.0.10 to the domain name router. The domain name router receives this first subnet address and then forwards it to the internal gateway within VPC_A. The internal gateway is responsible for passing this resolved address information to the resource that initially sent the DNS query. For example, it notifies the resource that web.testserver.com can be accessed using the private network address 10.0.0.10 to access the web service within VPC_A.
[0079] Through the above embodiments of the present application, even if other VPCs also request to resolve the same domain name, the DNS server can return a unique first subnet address related to the requesting VPC, ensuring the isolation and security of resource access within each tenant network, and at the same time supporting the requirement for resources to access internal services using private network addresses.
[0080] In an alternative embodiment, before sending the first subnet address to the internal gateway in the first virtual cloud, it includes: configuring the destination network segment for the domain name router as the subnet network segment in the first virtual cloud; configuring the next address to reach for the domain name router as the second communication address corresponding to the internal gateway in the first virtual cloud.
[0081] It should be noted that the destination network segment is the network address range of the internal subnet within the VPC to which the first subnet address returned by the DNS server belongs, such as 10.0.0.0 / 16. The second communication address is the communication address of the internal gateway in the global network, that is, the address that the DNS server can identify and return, used to send the response back to the inside of the VPC.
[0082] In an alternative embodiment, before the DNS server returns the resolution result to the domain name router, the following configurations need to be made on the domain name router: The domain name router needs to clearly know which part of the network (i.e., the subnet in the first virtual cloud) the received response should be forwarded to. Therefore, it is necessary to configure the destination network segment as the private subnet address range of the VPC. The domain name router must know through which global communication address (i.e., the second communication address) of the internal gateway the received response should be sent back to the VPC. This means that the DNS server should send the response to a pre-configured address that can be recognized by the internal gateway within the VPC, so that the response can be correctly forwarded to the requested resource.
[0083] In an alternative embodiment, the destination network segment can be configured on the VPC gateway: the network segment where the DNS service is located (such as 100.64.0.0 / 16); the next hop: the IP address on the DNS router connected to the vpc gateway (such as 172.16.0.2 in VPC_A).
[0084] DNS router configuration: destination network segment: VPC network segment (such as 10.0.0.0 / 16 of VPC_A), next hop: the IP address of the VPC gateway connected to the DNS router (such as 172.16.0.1 in VPC_A).
[0085] Through the above embodiments of the present application, through the collaborative work of the internal gateway and the domain name router, it is ensured that the resolution result returned by the DNS server can be correctly returned to the target VPC, realizing the isolation and efficiency of network communication. By configuring the second communication address of the internal gateway and the destination network segment of the domain name router, it can be ensured that the DNS response information can be accurately received and used by the resources within the VPC.
[0086] In an alternative embodiment, before the first virtual cloud sends the domain name request information to the domain name server, it includes: determining the global network segment and allocating a second global address to the domain name server; incorporating the first virtual cloud into the global network segment and allocating a first global address to the first virtual cloud.
[0087] It should be noted that to ensure that the resources within the VPC can correctly resolve domain names through the DNS server, network configuration steps need to be carried out in advance. For example, a global network address range is planned for the external network connections of all VPCs. At the same time, the DNS server needs to have a fixed address (the second global address) in this global network segment so that the resources within the VPC can find and access the DNS server. And the network architecture of the first virtual cloud (VPC) can be connected to the global network segment to allow the resources within the VPC to access the DNS server through the NAT technology. Before the DNS request within the VPC is sent to the DNS server, it will be converted into the first global address corresponding to the VPC to identify the source of the request.
[0088] In an alternative embodiment, before implementing DNS domain name isolation in a multi-tenant network, a key network planning and configuration task needs to be carried out. This includes determining a global network segment that is independent of the private network addresses of each VPC and is used for external network communication across the entire cloud platform, particularly for accessing DNS services. The DNS server needs to have a fixed address (the second global address) within this global network segment to receive DNS requests from all VPCs. Subsequently, each VPC (such as the first virtual cloud) needs to be incorporated into this global network segment, which means that the network egress of the VPC needs to be configured with the address range of the global network segment. When resources within the VPC access the DNS server, the source IP address of their requests will be translated into a specific global address (the first global address) to distinguish requests from different VPCs and ensure that the DNS server can correctly resolve domain names based on the request source and return IP addresses related to the VPC.
[0089] In an alternative embodiment, assume the following network planning: Global network segment: 100.64.0.0 / 16, which will be used for external communication of all VPCs. Second global address of the DNS server: 100.64.0.5, which is the fixed address of the DNS server within the global network segment. Private network address segment of VPC_A: 10.0.0.0 / 16, First global address of VPC_A: 100.64.1.10.
[0090] Before deploying DNS domain name isolation, first determine the global network segment as 100.64.0.0 / 16 and assign 100.64.0.5 as the fixed access address for the DNS server within this network segment. Next, incorporate VPC_A into the global network segment, which means that the network egress of VPC_A will use the address range of the global network segment. Specifically, the NAT gateway of VPC_A is configured with the address 100.64.1.10 in the global network. In the subsequent DNS server configuration, create a view (such as VPC_A_View) that matches the first global address 100.64.1.10 of VPC_A, and configure the A record of testserver.com to the service IP address within VPC_A, such as 10.0.1.10.
[0091] When a server within VPC_A attempts to access testserver.com, its DNS request is first sent to the NAT gateway of VPC_A. After receiving the DNS request, the NAT gateway converts the source IP address of the request to the first global address 100.64.1.10 of VPC_A, and then forwards the request to the DNS server. The DNS server recognizes that 100.64.1.10 corresponds to VPC_A_View, resolves testserver.com to 10.0.1.10 according to the configuration, and returns this resolution result to the server within VPC_A.
[0092] Through the above embodiments of the present application, even if other VPCs also attempt to access testserver.com, the DNS server can return the IP addresses of services within different VPCs based on the first global addresses assigned to different VPCs, thereby achieving the isolation of DNS domain names in a multi-tenant network.
[0093] In an alternative embodiment, incorporating the first virtual cloud into the global network segment includes one of the following:
[0094] 1) Plan a layer 2 network for the first virtual cloud and the domain name server, and assign a first global address to the first virtual cloud;
[0095] 2) Create a domain name router and connect the first virtual cloud and the domain name server through the domain name router.
[0096] It should be noted that the layer 2 network refers to the network connection in the data link layer of the OSI model, which allows direct communication between different network devices through MAC addresses without the need for IP address conversion through a router. In a cloud platform environment, the layer 2 network is usually implemented through virtual network technologies such as VLAN or Overlay network, enabling different VPCs to directly access the DNS server.
[0097] In an alternative embodiment, by establishing a layer 2 network connection between the DNS server and the VPC, the network traffic of the VPC can be directly transmitted to the DNS server without passing through a layer 3 network device (such as a router). At the same time, an IP address within the global network segment (i.e., the first global address) is assigned to the VPC for NAT conversion to ensure that the DNS server can identify the VPC based on this address.
[0098] In an alternative embodiment, another method is to create a virtual domain name router as a bridge between the VPC and the DNS server. The domain name router is responsible for forwarding DNS requests and responses between the VPC and the DNS server. By configuring static routing or dynamic routing protocols, the domain name router can ensure that DNS traffic is correctly transmitted between the VPC and the DNS server.
[0099] In an alternative embodiment, in a multi-tenant cloud platform, in order to achieve DNS domain name isolation and flexibility in resource access, the platform needs to plan a mechanism that enables each VPC to communicate with the DNS server independently without interfering with the DNS requests of other VPCs. By planning a layer 2 network or creating a domain name router, it can be ensured that DNS traffic is correctly transmitted from the VPC to the DNS server. At the same time, through NAT technology, a global address is assigned to the VPC, and the DNS server can determine the source VPC of the request based on this address, thereby achieving DNS resolution isolation based on the VPC.
[0100] In an alternative embodiment, assume the following network configuration: VPC_A: internal network 10.0.0.0 / 16, where the NAT gateway is located. DNS server: located in the global network with an IP address of 100.64.0.2.
[0101] Example 1: Plan a layer 2 network to achieve a direct connection between VPC_A and the DNS server.
[0102] To achieve a layer 2 network connection between VPC_A and the DNS server, a layer 2 network bridge can be created in the cloud platform to directly connect the NAT gateway of VPC_A to the network segment where the DNS server is located. Assign an IP address 100.64.1.10 in the global network to VPC_A as its global address. In this way, when DNS requests for internal resources in VPC_A reach the NAT gateway, they will be converted to this global address and then directly sent to the DNS server 100.64.0.2 through the layer 2 network bridge.
[0103] Example 2: Use a domain name router to connect VPC_A and the DNS server.
[0104] Create a virtual domain name router in the global network and assign it an IP address 100.64.1.10. Configure static routes for the domain name router so that it can forward DNS traffic to the DNS server 100.64.0.2. On the NAT gateway of VPC_A, configure static routes so that all DNS requests are forwarded through the domain name router 100.64.1.10. When resources within VPC_A attempt to resolve domain names, the DNS requests first reach the NAT gateway, the source IP address is converted to 100.64.1.10, and then forwarded to the DNS server through the domain name router. The DNS server identifies that the request comes from VPC_A based on 100.64.1.10, performs domain name resolution, and returns the resolution result to the domain name router, which then forwards it back to VPC_A.
[0105] Through the above embodiments of the present application, whether directly planning a Layer 2 network or using a domain name router, an effective connection between the VPC and the DNS server can be achieved, ensuring that resources within each VPC can access internal services through the DNS server. At the same time, isolation of DNS requests is achieved based on different global addresses, meeting the requirements of DNS domain name isolation in a multi-tenant network.
[0106] In an alternative embodiment, determining the global network segment includes: creating a network of an external network type and creating a global network on the network of the external network type; setting the gateway address and address range of the global network to determine the global network segment.
[0107] It should be noted that the network of the external network type refers to a network type created in a cloud platform, aiming to provide a connection to an external network (such as the Internet). It usually has a public IP address pool and can provide global addresses for the NAT gateway of the VPC.
[0108] In an alternative embodiment, it is necessary to create a network of an external network type, which is the basis for creating a global network. Subsequently, configure the global network on this external network, determine its gateway address and address range, thereby defining the global network segment. The determination of the global network segment is crucial. It will be used as the address for VPC resources to access the DNS server after NAT conversion, ensuring that the DNS server can identify different VPC requests and return the correct resolution results.
[0109] In an alternative embodiment, on the OpenStack cloud platform, first create a network of an external network type, named External_Network, and configure its physical network and VLAN information, such as physnet1 and vlan type. Then, create a global network on External_Network, named Global_Network, and allocate a public IP address pool, such as 100.64.0.0 / 16, as the global address range. Set the gateway address for Global_Network, for example, 100.64.0.1, to ensure that after NAT conversion of DNS requests sent by all VPC resources, the addresses within the global network segment can be used as the source addresses and 100.64.0.1 as the destination gateway, ensuring that the DNS server can identify and process these requests. The specific steps are as follows:
[0110] S1, create a network of an external network type, External_Network, configure its network type as vlan, physical network as physnet1, and set it as the external network type.
[0111] S2. Create a global network Global_Network on the external network type network, configure the IP address pool as 100.64.0.0 / 16, and set the gateway address as 100.64.0.1.
[0112] Through such an embodiment, a global network segment 100.64.0.0 / 16 can be defined, where the gateway address is 100.64.0.1. This will be used as the address range after NAT conversion for all VPC resources to access the DNS server. When the resources in VPC_A and VPC_B need to access the DNS server, their DNS requests will be converted into global addresses (such as 100.64.1.10 and 100.64.1.11) in the Global_Network through the NAT gateways of their respective VPCs, and then these requests will be sent to the DNS server through the gateway 100.64.0.1. The DNS server can identify VPC_A and VPC_B based on the global addresses of these requests, and then return the correct domain name resolution results, realizing DNS domain name isolation in a multi-tenant environment.
[0113] Through the above implementation manner of the present application, by creating a network of the external network type and configuring a global network on it, a unified network access interface can be provided for all VPCs for communication with the DNS server. The gateway address and address range of the global network determine the characteristics of the global network segment, and this network segment will be used for NAT conversion of VPC resources, enabling DNS requests and responses to be correctly located and processed by the DNS server while maintaining VPC isolation.
[0114] In an alternative embodiment, incorporating the first virtual cloud into the global network segment and allocating a first global address to the first virtual cloud includes: creating a domain name router in the first virtual cloud and allocating a first global address to the domain name router; enabling the address conversion function of the domain name router, where the address conversion function instructs the resources within the first virtual cloud to use the first global address to access the domain name server.
[0115] It should be noted that the address conversion function is the NAT (Network Address Translation) function, which can convert the private IP addresses inside the VPC into the first global address in the global network segment to achieve access to external services.
[0116] In an alternative embodiment, the network management module automatically configures a DNS router for the VPC to connect to the DNS server. Specifically, it automatically creates a DNS router that connects to the DNS service, associates the globally planned network with the DNS router, obtains the DNS gateway address DNS_Client_IP_A (such as the DNS gateway 100.64.1.10 of VPC_A), and enables the SNAT switch of the vRouter. Specifically, in the first virtual cloud, a domain name router can be automatically created through the network management module of the cloud platform. This router will be responsible for forwarding DNS requests. Assign a global address (the first global address) in the global network segment to the domain name router, so that resources within the VPC can access the DNS service through this address. Configure the NAT function of the domain name router to ensure that when internal resources in the VPC access the DNS server, their private IP addresses will be converted to the first global address, thus realizing a unified identifier for external network access and maintaining the isolation of the internal network of the VPC.
[0117] In an alternative embodiment, a domain name router must be created in each VPC, and a unique address (the first global address) in the global network is assigned to this router. Then, enable the address translation function of the domain name router to ensure that when resources within the VPC attempt to access the DNS server, their private IP addresses will be converted to this global address. In this way, regardless of which VPC the resources are located in, the DNS server can identify and process requests by receiving requests with the global address, while the network configuration and resource access of each VPC remain independent and isolated.
[0118] In an alternative embodiment, assume the following network plan: Global network segment: 100.64.0.0 / 16. The private network address of VPC_A is 10.0.0.0 / 16. The public IP of the DNS service located in the global network segment is 100.64.0.5.
[0119] During the process of integrating VPC_A into the global network segment, a virtual router (domain name router) is created for VPC_A to handle the forwarding of DNS requests. This router will be connected to the private network of VPC_A and the global network segment. Assign the address 100.64.1.10 in the global network segment to the domain name router as its global address. Configure the NAT function of the domain name router to ensure that all DNS requests initiated from within VPC_A will have their source IP addresses converted to 100.64.1.10, so that the DNS server will know it comes from VPC_A when identifying the request and return the resolution result according to the DNS records of VPC_A.
[0120] When resources within VPC_A (e.g., a server with IP address 10.0.0.5) need to resolve the domain name web.testserver.com, the server first sends the request to the domain name router. After receiving the request, the domain name router converts the source IP address of the request (10.0.0.5) to the first global address (100.64.1.10), and then forwards this converted DNS request to the DNS server. The DNS server recognizes that 100.64.1.10 corresponds to VPC_A and uses the corresponding DNS record set to resolve web.testserver.com, for example, resolving the domain name to the service IP 10.0.1.10 within VPC_A. Subsequently, the DNS server returns the resolution result to the domain name router with 100.64.1.10 as the source address. The domain name router performs address conversion again and forwards the resolution result of 10.0.1.10 to the VPC_A server that initially sent the request, namely the server with IP address 10.0.0.5.
[0121] Through the above implementation manners of the present application, even if different VPCs use the same domain name, the DNS server can identify the request source according to the global address (the first global address) of the request and provide the correct resolution result, thereby realizing the isolation and customized response of DNS domain names in a multi-tenant network. At the same time, the use of the NAT function ensures the security and isolation of the internal network of the VPC, meeting the network requirements in the multi-tenant environment of the cloud platform.
[0122] In an optional implementation manner, the domain name server determines at least one target configuration view corresponding to the first virtual cloud in the configuration view set according to the first global address, including: determining the global address information corresponding to each in the configuration view set; and determining the configuration view containing the first global address as the target configuration view, where the global address information corresponding to the configuration view includes at least one global address.
[0123] It should be noted that the DNS server selects an appropriate configuration view for domain name resolution according to the source address of the DNS request (i.e., the first global address). First, the DNS server checks the configuration view set to determine the global address information of each view, that is, the global address list associated with each view. Then, the DNS server searches for the configuration view containing the first global address (i.e., the source address of the DNS request), and this view is regarded as the target configuration view and will be used to process and resolve the domain name in the DNS request. The global address information in the target configuration view may include one or more global addresses, indicating that the configuration view of the DNS server can serve multiple VPCs simultaneously as long as the global addresses of their NAT gateways appear in the global address information of the configuration view.
[0124] In an alternative embodiment, in a multi-tenant network environment, the DNS server needs to process DNS requests from different VPCs and return DNS records related to the requesting VPC. To achieve this goal, the DNS server implements intelligent processing of DNS requests through a set of configured views. First, by examining the global address information of each configured view, the DNS server can understand which views are applicable to which VPCs. When the DNS server receives a DNS request, it determines the correct configured view based on the source address of the request (i.e., the first global address). This view will be used to resolve the domain name in the request and return the DNS record corresponding to the requesting VPC.
[0125] In an alternative embodiment, assume the following network configuration: two views, View1 and View2, are configured on the DNS server to handle DNS requests from VPC_A and VPC_B, respectively.
[0126] The global address information associated with View1 includes 100.64.1.10.
[0127] The global address information associated with View2 includes 100.64.1.11.
[0128] The global address of the NAT gateway for VPC_A is 100.64.1.10, and the global address of the NAT gateway for VPC_B is 100.64.1.11.
[0129] When a resource within VPC_A attempts to access an internal web service via the domain name web.testserver.com, the DNS request is first sent to the DNS server, and the source address is translated to 100.64.1.10 (the first global address). After receiving the request, the DNS server examines the set of configured views and determines that the global address information of View1 contains 100.64.1.10, so View1 is determined as the target configured view.
[0130] The DNS server uses View1 to resolve web.testserver.com and returns the IP address 10.0.0.10 associated with VPC_A. Similarly, if a resource within VPC_B attempts to access the same domain name, the DNS server will match the DNS request with source address 100.64.1.11 to View2. View2 is determined as the target configured view and returns the IP address 10.0.1.10 associated with VPC_B.
[0131] Through the above embodiments of the present application, the DNS server has successfully achieved the isolation processing of DNS requests for different VPCs through the configuration view set. Even if they request to resolve the same domain name, it can return the correct IP addresses of the internal services of their respective VPCs, thus ensuring DNS domain name isolation and data security in a multi-tenant network environment.
[0132] In an alternative embodiment, determining a first subnet address corresponding to a domain name to be resolved according to a target configuration view includes: determining a target configuration view including the domain name to be resolved in at least one target configuration view; and determining the first subnet address according to the target configuration view.
[0133] It should be noted that after receiving a DNS request, the DNS server selects the correct view (target configuration view) to resolve the domain name according to the global address (first global address) of the request and the configured view rules, and returns a private network address (first subnet address) related to the VPC. Specifically: when receiving a request, the DNS server will identify one or more Views (target configuration views) applicable to the request from the multiple Views it has configured according to the global address of the request source (i.e., the first global address). This is because the global addresses of the NAT gateways of each VPC are configured in the match-clients of different Views. Once the target configuration view is determined, the DNS server will use the DNS records configured in this View to resolve the domain name to be resolved in the request, and return a first subnet address located in the private network of the VPC where the requested resource is located. This address is meaningful to the resources within the VPC and can be used to access specific services or hosts within the VPC.
[0134] In an alternative embodiment, in a multi-tenant network environment, the DNS server needs to process DNS requests from multiple VPCs while ensuring that each VPC's request gets a correct response, that is, resolved into an IP address related to that VPC. To achieve this goal, the DNS server pre-configures multiple Views, each View corresponding to the global address of one or more VPCs' NAT gateways, so that it can select the correct View for domain name resolution based on the source address of the DNS request. When the DNS server receives a request, it first determines one or more target configuration views from the multiple Views, and these Views contain DNS records related to the domain name to be resolved in the request. Then, the DNS server uses the DNS records in the selected View to resolve the domain name and returns a first subnet address located in the VPC where the requested resource is located, ensuring that the resource can access the correct internal service.
[0135] Through the above implementation manners of the present application, the DNS server realizes domain name resolution isolation between different VPCs through the target configuration view, ensuring that resources within each VPC can access the internal services associated with their own VPC, thereby providing flexible and secure domain name resolution services in a multi-tenant network environment.
[0136] In an alternative implementation manner, before the domain name server determines at least one target configuration view corresponding to the first virtual cloud in the configuration view set according to the first global address, it includes: editing the configuration file of the domain name server to create a configuration view to be configured; determining the global address corresponding to the configuration view to be configured; and determining the domain name file corresponding to the configuration view to be configured to obtain the configuration view.
[0137] It should be noted that the configuration file of the domain name server refers to the configuration file of the DNS server, such as named.conf when using Bind9, which contains various configuration information of the DNS server, such as zone data, view settings, etc. The configuration view to be configured is a new configuration view that needs to be created on the domain name server and is used to be associated with a specific VPC (the first virtual cloud) to achieve domain name resolution isolation. The domain name file refers to the zone file stored in the configuration view and contains DNS records of specific domain names, such as A records, CNAME records, etc.
[0138] In an alternative implementation manner, it is necessary to edit the configuration file of the domain name server to create a configuration view to be configured for isolating and differentiating DNS requests of different VPCs. Subsequently, determine which global address (i.e., the first global address of a specific VPC) this configuration view will be associated with, so that the DNS server can know which configuration view should be used to process the request based on the source IP address of the DNS request (i.e., the first global address). Finally, determine the domain name file corresponding to the configuration view, which contains DNS records of a specific VPC, such as IP address information of web servers, database servers, etc. The entire process ensures that the DNS server can identify the VPC of the request based on the configuration view set according to the first global address and use the correct DNS records to respond to the DNS request.
[0139] In an alternative implementation manner, assuming that there is a DNS server using Bind9 DNS software, it is necessary to create a configuration view VPC_A_View for VPC_A to achieve domain name isolation. The platform calls the DNS service management module to create a view, issue domain name configuration and view configuration, and set match-clients to include the above DNS_Client_IP_A. The mapping relationship between the VPC and the DNS view is N:N, that is, many-to-many.
[0140] The specific steps are as follows:
[0141] S1, Edit the named.conf configuration file of the domain name server to create the configuration view VPC_A_View to be configured.
[0142] S2, Determine the global address corresponding to the configuration view VPC_A_View to be configured, which is 100.64.1.10 here. This address will be used to identify the DNS requests of VPC_A.
[0143] S3, Determine the domain name file testserver.com.db corresponding to the configuration view VPC_A_View, which contains the DNS records of the specific testserver.com domain name within VPC_A.
[0144] In the above manner, the configuration view VPC_A_View is pre-created on the DNS server, and by editing the named.conf file, its match-clients is configured as 100.64.1.10 (the first global address), which ensures that the DNS server can identify and use this view to process the DNS requests of VPC_A. At the same time, the zone data of testserver.com is configured and stored in the testserver.com.db file, which contains the IP address information of ns.testserver.com and www.testserver.com within VPC_A. In this way, when the DNS server processes the requests of VPC_A, it can return the correct resource IP addresses within VPC_A.
[0145] Subsequently, when the resources within VPC_A attempt to resolve www.testserver.com, their DNS requests will be sent using the global address 100.64.1.10. After receiving the requests, the DNS server will identify 100.64.1.10 and determine to use VPC_A_View in the configuration view set to process this request. Finally, the resolved result 10.0.1.11 (i.e., the IP address of www.testserver.com within VPC_A) is returned to the resources within VPC_A, thus realizing DNS domain name isolation and resource access control based on VPC.
[0146] Through the above implementation manners of the present application, in order to achieve the isolation of DNS domain names in a multi-tenant network, detailed configurations need to be performed on the DNS server, including creating configuration views, determining the global addresses corresponding to these views, and the domain name files included in the configuration views. The configuration view set provides a mechanism. According to the source IP address (the first global address) of the DNS request, the DNS server can determine which VPC the request comes from and use the configuration view corresponding to that VPC to provide domain name resolution services. This not only ensures that domain name requests between different VPCs do not interfere with each other, but also improves the security and flexibility of the cloud platform network environment.
[0147] In an alternative implementation manner, creating a configuration view to be configured includes: naming the configuration view to be configured by using a unique identifier, where the unique identifier is a globally unique string.
[0148] It should be noted that the unique identifier indicates the name of the configuration view, which is usually a globally unique string used to uniquely identify each configuration view on the DNS server, ensuring that DNS requests from different VPCs can be correctly routed to the corresponding views for processing.
[0149] To achieve DNS domain name isolation, configuration views need to be created on the DNS server and these views are named using unique identifiers. When creating a configuration view, the configuration file in the DNS server software (such as Bind9) uses a globally unique string as the name of the view, and this name is the unique identifier of the configuration view, ensuring that the DNS server can accurately identify and process DNS requests from different VPCs.
[0150] In an alternative implementation manner, in a multi-tenant network environment, the DNS server needs to process DNS requests from each VPC, and each VPC may require different domain name resolution results. To achieve DNS domain name isolation, the DNS server must be able to perform corresponding configurations and responses according to the source of the request. The creation and naming of configuration views are key steps to achieve this goal. The DNS server software (such as Bind9) allows administrators to create multiple configuration views, and each view can contain different domain name resolution rules. By naming the configuration views using unique identifiers, the DNS server can accurately associate the views with specific VPCs. Thus, when receiving a DNS request, according to the IP address of the request source, the request is forwarded to the correct configuration view for domain name resolution, and finally the domain name resolution result related to the requesting VPC is returned, achieving DNS domain name isolation between different VPCs.
[0151] In an alternative embodiment, assuming that Bind9 is being used as the DNS server, a configuration view needs to be created to handle DNS requests in VPC_A. Before creating the configuration view, a globally unique string needs to be planned as the name of the configuration view. This unique identifier can be a UUID (Universally Unique Identifier), such as VPC_A_View_UUID.
[0152] Next, in the Bind9 configuration file, a configuration view named VPC_A_View_UUID is created. Through the match-clients directive, it is configured to handle only DNS requests with a source address of 100.64.1.10, which is exactly the global address after NAT gateway translation in VPC_A. The configuration view also includes a domain name testserver.com, and its resolution file is / var / named / testserver.com.zone.
[0153] When a resource in VPC_A attempts to resolve the domain name web.testserver.com, the DNS request is first sent to the NAT gateway in VPC_A, and its source IP address is translated to 100.64.1.10. Then this request is forwarded to the DNS server. After receiving the request, the DNS server identifies that this request matches the VPC_A_View_UUID configuration view based on the source address 100.64.1.10, and thus uses the resolution rules of testserver.com to handle the request, and finally returns the correct IP address of web.testserver.com within VPC_A.
[0154] Through the above embodiments of the present application, not only a configuration view is created, but also a unique identifier (UUID) is used to name this view, ensuring that the DNS server can accurately route DNS requests of different VPCs to the corresponding configuration views, realizing DNS domain name isolation in a multi-tenant network environment.
[0155] In an alternative embodiment, after obtaining the configuration view, it includes one of the following:
[0156] 1) In the case of replacing the virtual cloud corresponding to the configuration view, modify the global address corresponding to the configuration view;
[0157] 2) In the case of deleting the virtual cloud corresponding to the configuration view, delete the global address corresponding to the configuration view.
[0158] It should be noted that the replacement of a Virtual Private Cloud (VPC) refers to the situation where, within a multi-tenant cloud environment, a VPC may need to change the DNS configuration view it is bound to, usually because of service changes within the VPC that require updating DNS resolution records.
[0159] When a VPC replaces its DNS configuration view, the global address bound to the original VPC on the DNS server may need to be modified to ensure that DNS query requests can be correctly processed by the new configuration view.
[0160] In a multi-tenant cloud platform, a user may need to delete a VPC that is no longer in use, which means that all resources bound to that VPC, including the DNS configuration view and the global address, should be cleared. After the VPC is deleted, the global address bound to that VPC on the DNS server should be removed from the corresponding configuration view to maintain the accuracy of the DNS server configuration and the effective utilization of resources.
[0161] In an alternative implementation, in a multi-tenant cloud platform, the configuration of the DNS server needs to be consistent with the VPC services and network status to ensure the correct implementation of DNS domain name isolation. When there are changes in the services or network configuration within the VPC, such as server migration, IP address change, etc., the configuration view on the DNS server should also be adjusted accordingly to ensure the accuracy of DNS resolution results. At the same time, if a VPC is deleted by a user, all configurations related to it on the DNS server, including the configuration view and its bound global address, should be promptly cleared to maintain the cleanliness and effectiveness of the overall DNS server configuration, avoiding resource waste and configuration errors.
[0162] In an alternative implementation, assume the following network configuration: VPC_A: Initially bound to configuration view View_id_uuid1 and using 100.64.1.10 as the global address. DNS server: Configured with two configuration views, View_id_uuid1 and View_id_uuid2, which contain different domain name resolution records respectively.
[0163] Case 1: VPC_A replaces its configuration view.
[0164] There is a service change in VPC_A that requires updating DNS resolution records, so it is decided to change from View_id_uuid1 to View_id_uuid2. On the DNS server, first remove the match for 100.64.1.10 from the configuration of View_id_uuid1, and then update the configuration of View_id_uuid2 by adding 100.64.1.10 to the match-clients configuration. In this way, the DNS server will respond to DNS query requests from VPC_A according to the new configuration view View_id_uuid2.
[0165] Scenario 2: VPC_A is deleted.
[0166] The user decides to delete VPC_A, which means that all DNS configurations and resources related to VPC_A should be cleared. On the DNS server, the match for 100.64.1.10 needs to be deleted from View_id_uuid1. If 100.64.1.10 is not used by any other VPC, then this global address can be released and no longer occupy the DNS server's configuration resources. If 100.64.1.10 has been associated with View_id_uuid2 after the VPC's configuration view is changed, then before deleting VPC_A, 100.64.1.10 needs to be removed from the match-clients configuration of View_id_uuid2 to ensure that the DNS server does not continue to provide services for the non-existent VPC_A.
[0167] Through the above embodiments of the present application, in the case of VPC replacement or deletion, the update and cleaning of the configuration view and global address on the DNS server are very critical steps to ensure the accuracy of DNS services and the effective management of resources. This not only helps to maintain the DNS domain name isolation policy in a multi-tenant network but also avoids redundant information and potential parsing errors in the DNS server configuration.
[0168] In an alternative embodiment, after returning the first subnet address to the first virtual cloud, it further includes: determining the first subnet address in the first virtual cloud and performing resource interaction with the first subnet address.
[0169] It should be noted that after the DNS server resolves and returns the private IP address (the first subnet address) related to the requested VPC, resources within the VPC (such as servers or clients) will use this address to access through the internal network, thereby establishing a communication connection with the target resource for data exchange or service invocation.
[0170] In an alternative embodiment, in a multi-tenant network, after the DNS server resolves a domain name, it returns a corresponding first subnet address according to the VPC where the request comes from. Next, this address will be used by resources in the first virtual cloud for internal communication positioning, and the resources will use this private IP address to access the target service or data. This process not only realizes resource access through domain names but also maintains network isolation and security in the multi-tenant environment of the cloud platform. The resource interaction within the VPC is based on the first subnet address, ensuring the accuracy and efficiency of access. Communication between resources does not require additional NAT conversion or global address recognition, reducing network latency and improving access speed.
[0171] In an alternative embodiment, assume that ServerA within VPC_A wants to access an internal web service named web.testserver.com. After the DNS server resolves this domain name, it returns a first subnet address 10.0.0.10 associated with VPC_A. After receiving the resolution result 10.0.0.10, ServerA starts interacting with 10.0.0.10 for resources. ServerA identifies the network location of the target web service based on the first subnet address 10.0.0.10 returned by the DNS server. The communication between ServerA and 10.0.0.10 is carried out through the internal network of VPC_A, without the need to use NAT conversion or other global network services again, and resource access is directly completed within the private network subnet. ServerA may send an HTTP request to 10.0.0.10 to obtain data provided by the web service or perform specific operations.
[0172] Through the above-described embodiment of the present application, the first subnet address 10.0.0.10 returned by the DNS server is used by ServerA to directly access the web.testserver.com service within VPC_A, achieving fast and direct communication between resources, while maintaining isolation and security in a multi-tenant network environment. This resource interaction mechanism based on the first subnet address improves the access efficiency of internal services in the cloud platform and is a key component of the DNS domain name isolation method.
[0173] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner.
[0174] The embodiments of the present application also provide a domain name isolation device for a private network. Figure 3 It is a structural block diagram of an alternative domain name isolation device for a private network according to an embodiment of the present application, as Figure 3 shown. The device includes:
[0175] A request sending module 302, configured to send domain name request information from a first virtual cloud to a domain name server, where the domain name request information is used to indicate a domain name to be resolved and a first global address of the first virtual cloud;
[0176] A configuration view determination module 304, configured to determine, by the domain name server according to the first global address, at least one target configuration view corresponding to the first virtual cloud from a set of configuration views, where the configuration view is used to indicate the relationship between a domain name and an address;
[0177] The domain name resolution module 306 is used to determine the first subnet address corresponding to the domain name to be resolved according to the target configuration view, and return the first subnet address to the first virtual cloud, where the first subnet address is used to indicate the address corresponding to the subnet of the domain name to be resolved in the first virtual cloud.
[0178] Optionally, the request sending module 302 is further used for: the domain name router in the first virtual cloud generates the first global address of the first virtual cloud, where the domain name router corresponds to the virtual cloud one by one; and sends the first global address of the first virtual cloud and the domain name to be resolved as domain name request information to the domain name server.
[0179] Optionally, the request sending module 302 is further used for: the internal gateway in the first virtual cloud sends the domain name to be resolved and the second global address of the domain name server to the domain name router; and the domain name router sends the domain name request information to the domain name server with the second global address as the destination network segment.
[0180] Optionally, before the internal gateway in the first virtual cloud sends the domain name to be resolved and the second global address of the domain name server to the domain name router, it includes: configuring the destination network segment of the internal gateway in the first virtual cloud as the global network segment, where the first global address and the second global address are included in the global network segment; and configuring the next address to reach of the internal gateway in the first virtual cloud as the first communication address corresponding to the domain name router, where the first communication address is used to indicate the communication address of the domain name router.
[0181] Optionally, the request sending module 302 is further used for: the domain name router receives the first subnet address and sends the first subnet address to the internal gateway in the first virtual cloud.
[0182] Optionally, before sending the first subnet address to the internal gateway in the first virtual cloud, it includes: configuring the destination network segment of the domain name router as the subnet network segment in the first virtual cloud; and configuring the next address to reach of the domain name router as the second communication address corresponding to the internal gateway in the first virtual cloud.
[0183] Optionally, the domain name isolation device of the private network further includes: a global network segment creation module, which is used to determine the global network segment and allocate the second global address to the domain name server; incorporate the first virtual cloud into the global network segment and allocate the first global address to the first virtual cloud.
[0184] Optionally, the global network segment creation module is further used for: planning a layer 2 network for the first virtual cloud and the domain name server, and allocating the first global address to the first virtual cloud; creating a domain name router to connect the first virtual cloud and the domain name server through the domain name router.
[0185] Optionally, determining a global network segment includes: creating a network of an external network type and creating a global network on the network of the external network type; setting a gateway address and an address range of the global network to determine the global network segment.
[0186] Optionally, the global network segment creation module is further configured to: create a domain name router in the first virtual cloud and assign a first global address to the domain name router; enable the network address translation function of the domain name router, where the network address translation function instructs resources within the first virtual cloud to access the domain name server using the first global address.
[0187] Optionally, the configuration view determination module 304 is further configured to: determine the respective corresponding global address information in the configuration view set; determine the configuration view including the first global address as the target configuration view, where the global address information corresponding to the configuration view includes at least one global address.
[0188] Optionally, determining a first subnet address corresponding to a domain name to be resolved according to the target configuration view includes: determining a target configuration view including the domain name to be resolved in at least one target configuration view; determining the first subnet address according to the target configuration view.
[0189] Optionally, before the domain name server determines at least one target configuration view corresponding to the first virtual cloud in the configuration view set according to the first global address, it includes: editing a configuration file of the domain name server to create a configuration view to be configured; determining a global address corresponding to the configuration view to be configured; determining a domain name file corresponding to the configuration view to be configured to obtain the configuration view.
[0190] Optionally, creating a configuration view to be configured includes: naming the configuration view to be configured using a unique identifier, where the unique identifier is a globally unique string.
[0191] Optionally, after obtaining the configuration view, it includes one of the following: modifying the global address corresponding to the configuration view in the case where the virtual cloud corresponding to the configuration view is replaced; deleting the global address corresponding to the configuration view in the case where the virtual cloud corresponding to the configuration view is deleted.
[0192] Optionally, the domain name resolution module 306 is further configured to: determine a first subnet address in the first virtual cloud and perform resource interaction with the first subnet address.
[0193] For the descriptions of the features in the embodiments corresponding to the domain name isolation device of the private network, reference can be made to the relevant descriptions of the embodiments corresponding to the domain name isolation method of the private network, which will not be elaborated here one by one.
[0194] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above-described embodiments of the domain name isolation method for a private network.
[0195] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any of the above-described embodiments of the domain name isolation method for a private network when running.
[0196] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media that can store computer programs such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs.
[0197] An embodiment of the present application further provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the domain name isolation method for a private network.
[0198] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the domain name isolation method for a private network.
[0199] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.
[0200] The above has introduced in detail a domain name isolation method and device, a storage medium, and a program product for a private network provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A domain name isolation method for a private network, characterized in that: include: The first virtual cloud sends domain name request information to a domain name server, wherein the domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud; The domain name server determines, according to the first global address, at least one target configuration view corresponding to the first virtual cloud in a configuration view set, wherein the configuration view is used to indicate a relationship between a domain name and an address; According to the target configuration view, a first subnet address corresponding to the domain name to be resolved is determined, and the first subnet address is returned to the first virtual cloud, wherein the first subnet address is used to indicate an address corresponding to the subnet of the domain name to be resolved in the first virtual cloud.
2. The method according to claim 1, characterized in that The first virtual cloud sends domain name request information to a domain name server, including: The domain name router in the first virtual cloud generates a first global address of the first virtual cloud, wherein the domain name router corresponds to the virtual cloud one by one; The first global address of the first virtual cloud and the domain name to be resolved are sent to the domain name server as the domain name request information.
3. The method according to claim 2, characterized in that The sending the first global address of the first virtual cloud and the domain name to be resolved as the domain name request information to the domain name server includes: The internal gateway in the first virtual cloud sends the domain name to be resolved and the second global address of the domain name server to the domain name router; The domain name router uses the second global address as the destination network segment and sends the domain name request information to the domain name server.
4. The method according to claim 3, characterized in that The internal gateway in the first virtual cloud sends the domain name to be resolved and the second global address of the domain name server to the domain name router, before that, comprising: configuring a destination network segment for the internal gateway in the first virtual cloud as a global network segment, wherein the first global address and the second global address are included in the global network segment; The next address to be reached is configured for the internal gateway in the first virtual cloud as the first communication address corresponding to the domain name router, wherein the first communication address is used to indicate the communication address of the domain name router.
5. The method according to claim 2, characterized in that: The first global address of the first virtual cloud and the domain name to be resolved are sent to the domain name server as the domain name request information, and then include: The domain name router receives the first subnet address, and sends the first subnet address to an internal gateway in the first virtual cloud.
6. The method according to claim 5, characterized in that Before sending the first subnet address to the internal gateway in the first virtual cloud, the method includes: Configuring a destination network segment for the domain name router to be a subnet segment in the first virtual cloud; The domain name router is configured with a second communication address corresponding to the internal gateway in the first virtual cloud as the next address to be reached.
7. The method according to any one of claims 1 to 6, characterized in that: Before the first virtual cloud sends the domain name request information to the domain name server, the process includes: Determine a global network segment and assign a second global address to the domain name server; The first virtual cloud is merged into the global network segment, and the first global address is allocated to the first virtual cloud.
8. The method according to claim 7, characterized in that The step of merging the first virtual cloud into the global network segment includes one of the following: Planning a layer 2 network for the first virtual cloud and the domain name server, and allocating the first global address to the first virtual cloud; A domain name router is created, and the first virtual cloud and the domain name server are connected through the domain name router.
9. The method according to claim 7, characterized in that: Determining the global network segment includes: Creating a network of an external network type, and creating a global network on the network of the external network type; The gateway address and address range of the global network are set to determine the global network segment.
10. The method according to claim 7, characterized in that Incorporating the first virtual cloud into the global network segment and allocating the first global address to the first virtual cloud includes: Creating a domain name router in the first virtual cloud, and assigning the first global address to the domain name router; The address translation function of the domain name router is enabled, wherein the address translation function instructs resources in the first virtual cloud to access the domain name server using the first global address.
11. The method according to claim 1, characterized in that: The domain name server determines, according to the first global address, at least one target configuration view corresponding to the first virtual cloud in a configuration view set, including: Determine the global address information corresponding to each of the configuration view sets; A configuration view including the first global address is determined as the target configuration view, wherein the global address information corresponding to the configuration view includes at least one global address.
12. The method according to claim 11, characterized in that The determining, according to the target configuration view, a first subnet address corresponding to the domain name to be resolved includes: Determining the target configuration view including the domain name to be resolved in the at least one target configuration view; The first subnet address is determined according to the target configuration view.
13. The method according to claim 12, characterized in that Before the domain name server determines, according to the first global address, at least one target configuration view corresponding to the first virtual cloud in a configuration view set, the method includes: Editing the configuration file of the domain name server to create a configuration view to be configured; Determine the global address corresponding to the configuration view to be configured; Determine the domain name file corresponding to the configuration view to be configured, and obtain the configuration view.
14. The method according to claim 13, characterized in that The step of creating a configuration view to be configured includes: The configuration view to be configured is named using a unique identifier, wherein the unique identifier is a globally unique string.
15. The method according to claim 13, characterized in that After obtaining the configuration view, one of the following is included: When the virtual cloud corresponding to the configuration view is replaced, modifying the global address corresponding to the configuration view; When the virtual cloud corresponding to the configuration view is deleted, the global address corresponding to the configuration view is deleted.
16. The method according to claim 1, characterized in that After returning the first subnet address to the first virtual cloud, the method further includes: The first subnet address is determined in the first virtual cloud, and resources are interacted with the first subnet address.
17. A domain name isolation device for a private network, characterized in that: include: A request sending module, used for the first virtual cloud to send domain name request information to a domain name server, wherein the domain name request information is used to indicate the domain name to be resolved and the first global address of the first virtual cloud; a configuration view determination module, configured for the domain name server to determine, according to the first global address, at least one target configuration view corresponding to the first virtual cloud in a configuration view set, wherein the configuration view is used to indicate a relationship between a domain name and an address; A domain name resolution module is used to determine the first subnet address corresponding to the domain name to be resolved according to the target configuration view, and return the first subnet address to the first virtual cloud, wherein the first subnet address is used to indicate the address corresponding to the subnet of the domain name to be resolved in the first virtual cloud.
18. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the method according to any one of claims 1 to 16 when executing the computer program.
19. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program implements the steps of the method according to any one of claims 1 to 16 when executed by a processor.
20. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 16 are implemented.
Citation Information
Patent Citations
External network domain name resolution method and system, and server
CN108063835A
Domain name resolution method based on cloud computing network and related system and device
CN113726918A
Domain name resolution detection method, system and device
CN116132402A