Cross-border internet access method
Through the SDWAN architecture and NAT gateway technology, CPE device resolution and whitelist routing filtering, combined with the shared public network address pool, the problems of unstable network connections and high deployment complexity in traditional VPN methods are solved, and high-quality cross-border Internet access is achieved.
Patent Information
- Application Number
- CN202510559201.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-11
AI Technical Summary
Traditional VPN methods are difficult to provide stable, high-speed, and low-latency network connections, and cannot meet the needs of efficient operations and business expansion of enterprises. At the same time, the existing cross-border Internet networking solutions increase the deployment complexity and cost.
The SDWAN architecture and NAT gateway technology are adopted to resolve access requests through CPE devices, and the target whitelist and route are used to filter legal addresses. Combined with domestic and foreign XGW devices and overseas NAT device modules, the stability and security of cross-border data transmission are achieved, and a shared public network address pool is used to reduce address resource usage.
It provides higher quality cross-border acceleration, meets the high requirements of enterprise-level users for bandwidth and network quality, reduces deployment complexity and cost, and ensures the stability and security of network connections.
Smart Images

Figure CN120301673A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a cross-border Internet access method. Background Art
[0002] At present, the conventional means for enterprises or users to access the overseas Internet is mainly the VPN technology. This technology realizes network interconnection by establishing a dedicated network tunnel on the public network. Although it can meet the basic cross-border access needs of some users, it has significant limitations. The VPN technology is usually applicable to user scenarios with small scale and low requirements for network quality, and it performs poorly in aspects such as bandwidth stability and network delay control. For enterprise-level users, especially in scenarios with strict requirements for network bandwidth and quality, such as cross-border business operations, remote data interaction, and real-time video conferencing, the traditional VPN method is difficult to provide a stable, high-speed, and low-latency network connection, and cannot meet the needs of enterprise efficient operation and business expansion.
[0003] In addition, in some existing cross-border Internet networking solutions, it is necessary to separately deploy user-side devices for each user overseas and allocate independent public network addresses as the access outlet to the Internet. This deployment method not only greatly increases the procurement, installation, and maintenance costs of hardware devices, but also significantly improves the complexity and management difficulty of network deployment. Each user needs to independently configure and manage the dedicated device and public network address, which multiplies the network operation and maintenance workload. At the same time, it also causes waste of public network address resources, increases the operation cost of enterprises, and restricts the large-scale promotion and application of cross-border network services. Summary of the Invention
[0004] In view of this, the present invention provides a cross-border Internet access method to solve the problems that the traditional VPN method is difficult to provide a stable, high-speed, and low-latency network connection, cannot meet the needs of enterprise efficient operation and business expansion, and the existing cross-border Internet networking solutions increase the deployment complexity and additional costs.
[0005] In a first aspect, the present invention provides a cross-border Internet access method for a cross-border Internet system. The cross-border Internet system is respectively connected to an SDWAN controller and a front-end interface module. The cross-border Internet system includes a CPE device, a domestic POP device, a domestic XGW device, an overseas XGW device, and an overseas NAT device module, and the overseas NAT device module is deployed in a dual-machine mode. The method includes:
[0006] When the CPE device receives a cross-border access request sent by the front-end interface module, it parses the cross-border access request to obtain an access packet and an overseas Internet access address; when the overseas Internet access address exists in the target whitelist of the CPE device, the access packet is sent to the domestic POP device based on the first route; the domestic POP device, based on the second route, sequentially sends the access packet through the domestic XGW device and the overseas XGW device to the overseas NAT device module; the overseas NAT device module converts the source address of the access packet into a public network address based on the shared public network address pool and sends the access packet to the overseas Internet through the public network address, and the shared public network address pool is issued by the SDWAN controller; when the CPE device receives the access result returned by the overseas Internet, it sends the access result to the front-end interface module.
[0007] The cross-border Internet access method provided by the present invention can determine the access packet and the overseas Internet access address by receiving and parsing the cross-border access request through the CPE device, which helps to avoid the transmission of invalid or incorrect data and improve the data processing efficiency. Further, the CPE device filters legal access addresses through the target whitelist, preventing illegal or unauthorized overseas network access and ensuring network security. Further, the domestic POP device transmits the access packet based on the second route, ensuring that the access packet can cross the domestic XGW device and the overseas XGW device and accurately reach the overseas NAT device module. At the same time, combined with the stable connection between devices, it reduces data transmission latency and packet loss, improving the quality and stability of cross-border data transmission. Further, the overseas NAT device module adopts dual-machine deployment, achieving primary and standby high availability and dual-machine load balancing, avoiding network interruption caused by single-point failures. Further, the source address conversion is performed based on the shared public network address pool, eliminating the need to allocate a public network address for each user separately, reducing the address resource occupancy and deployment cost. Therefore, by implementing the present invention, compared with the traditional VPN method, based on the SDWAN architecture and NAT gateway technology, it provides higher-quality cross-border acceleration, meeting the high requirements of enterprise-level users for bandwidth and network quality, and solving the problem that the traditional method is only applicable to small and medium-sized users with low network quality requirements. At the same time, it avoids deploying overseas devices and public network addresses for each user separately, reducing the deployment complexity and additional costs.
[0008] In an alternative embodiment, the method further includes:
[0009] When the CPE device receives a configuration request sent by the SDWAN controller, it parses the configuration request to obtain multiple overseas Internet whitelist addresses; the CPE device generates a target whitelist based on the multiple overseas Internet whitelist addresses; and generates a first route based on the target whitelist.
[0010] The cross-border Internet access method provided by the present invention issues a whitelist address through the SDWAN controller, enabling the CPE device to precisely control the overseas Internet addresses that can be accessed, enhancing the security of network access, preventing illegal access, further optimizing the management of cross-border Internet access, and avoiding security risks and resource waste caused by users' random access to overseas networks. Further, a first route is generated based on the target whitelist, enabling the CPE device to legally transmit data to the domestic POP device according to the first route, ensuring the continuity and reliability of overseas access, and thus providing users with stable cross-border network services.
[0011] In an alternative embodiment, the method further includes:
[0012] The overseas NAT device module publishes a second route and sends the second route to the domestic POP device through the overseas XGW device and the domestic XGW device in sequence; when the domestic POP device receives the second route, it isolates the second route.
[0013] For the cross-border Internet access method provided by the present invention, the overseas NAT device publishes a second route and transmits it to the CPE device through the overseas XGW device and the domestic XGW device, ensuring the consistency of routing information between backbone network devices. Further, the CPE device isolates the second route, preventing routing from interfering with the tenant's local network default route (usually used to access the domestic Internet) and avoiding network failures caused by routing conflicts, thus ensuring the accuracy and stability of network routing.
[0014] In a second aspect, the present invention provides a cross-border Internet access method for an SDWAN controller. The SDWAN controller is respectively connected to a cross-border Internet system and a front-end interface module; the method includes:
[0015] Receiving an operation request from the front-end interface module; controlling the establishment of a traffic channel between the CPE device and the domestic POP device according to the operation request, and controlling the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device, so that the CPE device can access the overseas Internet through the domestic POP device, the domestic XGW device, and the overseas XGW device module in sequence according to the cross-border access request sent by the front-end interface module.
[0016] For the cross-border Internet access method provided by the present invention, controlling the establishment of traffic channels between different devices in the cross-border Internet system according to the front-end operation request realizes the centralized management and control of the cross-border Internet system. Compared with the traditional networking method, it greatly simplifies the network deployment and management process, improves the efficiency and accuracy of network configuration, ensures the stability and reliability of network connections, and meets the cross-border network access needs of users.
[0017] In an alternative embodiment, the method further includes: when receiving a plurality of shared addresses sent by the front-end interface module, generating a shared public network address pool according to the plurality of shared addresses, and sending the shared public network address pool to the overseas NAT device module.
[0018] The cross-border Internet access method provided by the present invention realizes the sharing of public network address resources by sending the shared address pool to the overseas NAT device module, eliminates the need to allocate a public network address for each user separately, effectively reduces the occupancy cost of public network address resources, reduces the investment in hardware devices, and reduces the network deployment cost of enterprise-level users, thus solving the problem of high cost caused by the need to configure a public network address for each user in the traditional method.
[0019] In an alternative embodiment, the method further includes: receiving a plurality of overseas Internet whitelist addresses sent by the front-end interface module; sending a configuration request to the CPE device according to the plurality of overseas Internet whitelist addresses, so that the CPE device generates a target whitelist and a first route based on the configuration request.
[0020] The cross-border Internet access method provided by the present invention, through the interaction between the SDWAN controller and the CPE device in whitelist configuration, can not only meet the security requirements of enterprise-level users for network access, but also reasonably control the use of network resources and improve network usage efficiency.
[0021] In an alternative embodiment, the SDWAN controller includes a data receiving module, a scheduling module, and a protocol module, and the operation request is an activation request; controlling the establishment of a traffic channel between the CPE device and the domestic POP device according to the operation request includes:
[0022] When the data receiving module receives the activation request sent by the front-end interface module, activating the CPE device with the activation request and parsing the activation request to obtain service data; when the service data passes the verification, sending a first device configuration scheduling task request to the scheduling module according to the service data; the scheduling module constructs a CPE device configuration information set and a first POP device configuration information set according to the first device configuration scheduling task request, the CPE device configuration information set includes first ipsec configuration information, first bgp configuration information, first bfd configuration information, and first qos configuration information, and the first POP device configuration information set includes vrf configuration information, second ipsec configuration information, second bgp configuration information, and second bfd configuration information; based on the CPE device configuration information set and the first POP device configuration information set, controlling the establishment of a traffic channel between the CPE device and the domestic POP device through the scheduling module and the protocol module.
[0023] The cross-border Internet access method provided by the present invention ensures the accuracy and integrity of device configurations by constructing detailed configuration information sets for different devices. Furthermore, each device can operate according to preset parameters and protocols, guaranteeing the stability and security of network connections and providing support for high-quality cross-border acceleration.
[0024] In an alternative embodiment, based on the CPE device configuration information set and the first POP device configuration information set, a traffic channel is established between the CPE device and the domestic POP device through a scheduling module and a protocol module, including:
[0025] When the protocol module receives the CPE device configuration information set and the first POP device configuration information set sent by the scheduling module, it obtains the southbound protocol, the first device identifier, and the second device identifier. According to the first device identifier, the protocol module uses the southbound protocol to sequentially send the device configuration information in the CPE device configuration information set to the CPE device, enabling the CPE device to execute the CPE device configuration information set. According to the second device identifier, the protocol module uses the southbound protocol to sequentially send the device configuration information in the first POP device configuration information set to the domestic POP device, enabling the domestic POP device to execute the first POP device configuration information set. When the scheduling module receives the first execution result sent by the CPE device and the second execution result sent by the domestic POP device, it controls the establishment of a traffic channel between the CPE device and the domestic POP device based on the first execution result and the second execution result.
[0026] The cross-border Internet access method provided by the present invention can send different device configuration information to the corresponding devices by obtaining the southbound protocol and device identifiers, ensuring the accurate transmission of configuration information. Further, the configuration information is sent to the corresponding devices using the southbound protocol, enabling the devices to obtain and execute the corresponding configuration information, thereby realizing the automatic configuration and update of device functions. Finally, the scheduling module controls the establishment of the traffic channel based on the device execution results, and the channel is established only when the device configuration is successful, ensuring the effectiveness and stability of the network connection and avoiding network failures caused by configuration failures.
[0027] In an alternative embodiment, the operation request is a cross-border Internet access request; controlling the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device according to the operation request, including:
[0028] When the data receiving module receives the cross-border Internet access request sent by the front-end interface module, it parses the cross-border Internet access request to obtain access data; when the accessed data passes the verification, based on the access data, it sends a second device configuration scheduling task request to the scheduling module; the scheduling module constructs a second POP device configuration information set, an XGW device configuration information set, and a NAT device configuration information set according to the second device configuration scheduling task request. The second POP device configuration information set includes the first bridge-domain configuration information, the first loop configuration information, the third bgp configuration information, and the first vxlan configuration information. The XGW device configuration information set includes vrf configuration information, the second bridge-domain configuration information, the second loop configuration information, the fourth bgp configuration information, the second vxlan configuration information, and the second qos configuration information. The NAT device configuration information set includes vrf configuration information, the third bridge-domain configuration information, the third loop configuration information, the fifth bgp configuration information, the third vxlan configuration information, and static-route configuration information; based on the second POP device configuration information set, the XGW device configuration information set, and the NAT device configuration information set, through the scheduling module and the protocol module, it controls the domestic POP device to establish a traffic channel with the foreign NAT device module through the domestic XGW device and the foreign XGW device.
[0029] The cross-border Internet access method provided by the present invention ensures the accuracy and integrity of device configuration by constructing the configuration information sets of different devices in detail, so that each device can work according to the preset parameters and protocols, ensuring the stability and security of the network connection, realizing the precise configuration of the cross-border network path, and ensuring the stability and reliability of cross-border access.
[0030] In an alternative embodiment, the method further includes:
[0031] Receiving the cross-border access route and speed limit value of the cross-border Internet system sent by the front-end interface module; controlling the access speed of the access operation based on the cross-border access route in the cross-border Internet system according to the speed limit value.
[0032] The cross-border Internet access method provided by the present invention can reasonably allocate network resources through the speed limit mechanism, avoid individual users occupying too much bandwidth and affecting the usage experience of other users, and at the same time ensure the network bandwidth requirements of key services, improving the overall usage efficiency and service quality of the network. Brief Description of the Drawings
[0033] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0034] Figure 1 It is a schematic diagram of the networking method for accessing the overseas Internet according to an embodiment of the present invention;
[0035] Figure 2 It is a schematic flowchart of the cross-border Internet access method according to an embodiment of the present invention;
[0036] Figure 3 It is a schematic flowchart of another cross-border Internet access method according to an embodiment of the present invention;
[0037] Figure 4 It is a schematic flowchart of the implementation process of the cross-border acceleration system according to an embodiment of the present invention;
[0038] Figure 5 It is a schematic diagram of the hardware structure of the computer device according to an embodiment of the present invention. Specific Embodiments
[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0040] The embodiments of the present invention provide a cross-border Internet access method, which achieves higher-quality cross-border acceleration through the SDWAN architecture and NAT gateway technology, meets the high requirements of enterprise-level users for bandwidth and network quality, and reduces deployment complexity and additional costs.
[0041] According to an embodiment of the present invention, an embodiment of a cross-border Internet access method is provided. It should be noted that the steps shown in the flowchart of the drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0042] In this embodiment, a cross-border Internet access method is provided, which can be used in a cross-border Internet system. The cross-border Internet system is respectively connected to an SDWAN controller and a front-end interface module, and the cross-border Internet system includes CPE (Customer Premises Equipment) devices, domestic POP (Point of Presence) devices, domestic XGW (eXchange Gateway) devices, overseas XGW devices, and overseas NAT (Network Address Translation) device modules.
[0043] Among them, the overseas NAT device module is deployed in a dual-machine manner. Different users can use one of them as the primary device and the other as the backup device, which can not only achieve high availability of the primary and backup, but also achieve the purpose of dual-machine load balancing. In the following embodiments of the present invention, all operations of the overseas NAT device module are executed by the primary device.
[0044] Furthermore, as Figure 1 shown, each tenant corresponds to a CPE device. The tenant's local network is connected to the LAN (Local Area Network) side of the CPE device, and the WAN (Wide Area Network) side of the CPE device is connected to the domestic POP device; the domestic POP device is connected to the domestic XGW device; the domestic XGW device is connected to the overseas XGW device, and the traffic crosses the border from here. At the same time, the XGW device, as a simple cross-border device, can control the cross-border traffic; the overseas XGW device is connected to the overseas NAT device, and the traffic can access the Internet via the overseas NAT gateway.
[0045] Among them, the traffic between tenants is isolated by vrf (Virtual Routing and Forwarding).
[0046] Further, at the overlay (a virtual network built on top of the underlying network) level, the CPE device communicates with the domestic POP device through an IPsec (Internet Protocol Security, a tunneling technology) tunnel, and IPsec is added to the tenant's VRF on the domestic POP device; the domestic POP device communicates with the domestic XGW device through a VXLAN (Virtual Extensible Local Area Network) tunnel, and the VXLAN tunnel is bound to the tenant's VRF; the domestic XGW device communicates with the overseas XGW through a device VXLAN tunnel, and the VXLAN tunnel is bound to the tenant's VRF; the overseas XGW device communicates with the overseas NAT gateway module through a VXLAN tunnel, and the VXLAN tunnel is bound to the tenant's VRF.
[0047] Among them, the channel connections between devices at the overlay level can be configured and implemented through the SDWAN controller.
[0048] Further, at the underlay level, the domestic XGW and the overseas XGW are connected by a dedicated line, reducing network latency and improving network quality.
[0049] Further, the above Figure 1 The CPE device on the tenant side and the devices in the backbone network are both controlled by the SDWAN controller. Among them, the CPE device on the tenant side and the devices in the backbone network jointly constitute a cross-border Internet system.
[0050] Figure 2 is a flowchart of the cross-border Internet access method according to an embodiment of the present invention. As Figure 2 shown, the process includes the following steps:
[0051] Step S201, when the CPE device receives a cross-border access request sent by the front-end interface module, it parses the cross-border access request to obtain an access packet and an overseas Internet access address.
[0052] Among them, the access packet may include a data part of specific access content and instructions.
[0053] Specifically, a tenant or an operation and maintenance personnel can initiate a request to access the cross-border Internet, that is, a cross-border access request, on the front-end interface module and send the cross-border access request to the CPE device.
[0054] Further, after receiving the cross-border access request, the CPE device can extract the corresponding access packet and overseas Internet access address by parsing the cross-border access request, thereby clarifying the user's access intention, which helps to avoid the transmission of invalid or incorrect data and improve data processing efficiency.
[0055] Step S202: When there is an overseas Internet access address in the target whitelist of the CPE device, send the access packet to the domestic POP device based on the first route.
[0056] Among them, the target whitelist may include multiple overseas Internet whitelist addresses; the first route is generated according to the target whitelist.
[0057] Specifically, after extracting the overseas Internet access address, the CPE device can compare the overseas Internet access address with the target whitelist stored locally.
[0058] If the overseas Internet access address is in the target whitelist, it means that the corresponding cross-border access request is legal and permitted. At this time, the CPE device can send the access packet to the domestic POP device according to the pre-generated first route.
[0059] Furthermore, if the overseas Internet access address is not in the target whitelist, then there is no first route in the CPE device at this time. Therefore, the CPE device will send the access packet using its corresponding default route. However, the default route of the CPE device is usually used to access the domestic Internet. Therefore, through this default route, the CPE device cannot send the access packet to the domestic POP device.
[0060] Through the above process, the CPE device can screen legal access addresses according to the target whitelist, prevent illegal or unauthorized overseas network access, and ensure network security.
[0061] Step S203: The domestic POP device, based on the second route, sends the access packet to the overseas NAT device module through the domestic XGW device and the overseas XGW device in sequence.
[0062] Among them, the second route is the default route published by the overseas NAT device module and transmitted to the domestic POP device.
[0063] Specifically, after receiving the access packet sent by the CPE device, the domestic POP device can send the access packet to the domestic XGW device according to the second route stored in itself. Then, the domestic XGW device forwards the access packet to the overseas XGW device, and finally the overseas XGW device sends the access packet to the overseas NAT device module.
[0064] By transmitting the access packet through the second route, it ensures that the access packet can cross the domestic and overseas networks and accurately reach the overseas NAT device module. At the same time, by combining the stable connections between devices, it reduces data transmission latency and packet loss, and improves the quality and stability of cross-border data transmission.
[0065] Step S204: The overseas NAT device module converts the source address of the access packet into a public network address based on the shared public network address pool, and sends the access packet to the overseas Internet through the public network address.
[0066] Among them, the shared public network address pool is issued by the SDWAN controller and can include multiple shared public network addresses.
[0067] Specifically, after receiving the access packet transmitted by the domestic POP device, the overseas NAT device module can convert the shared public network address pool into the corresponding public network address through the locally stored shared public network address pool.
[0068] Furthermore, after completing the source address conversion, the primary and standby NAT devices in the overseas NAT device module can send the received access packet to the overseas Internet based on this public network address through the pre-configured static default route, thus realizing the access to the overseas Internet.
[0069] By performing source address conversion through the shared public network address pool, there is no need to allocate a public network address for each user separately, reducing the occupation of address resources and deployment costs.
[0070] Step S205: When the CPE device receives the access result returned by the overseas Internet, it sends the access result to the front-end interface module.
[0071] Specifically, the overseas Internet can process the received access packet and generate the corresponding access result.
[0072] Furthermore, the overseas Internet sends the generated access result to the overseas NAT device module.
[0073] Furthermore, the destination address of the access result data in the overseas NAT device module is converted back from the public network address to the private address of the tenant's local network, and then the access result is returned to the CPE device through the overseas XGW device, the domestic XGW device, and the domestic POP device in sequence.
[0074] Furthermore, the CPE device can send the received access result to the front-end interface module for the tenant to view, download, etc.
[0075] The cross-border Internet access method provided in this embodiment, based on the SDWAN architecture and NAT gateway technology, provides higher-quality cross-border acceleration, meets the high requirements of enterprise-level users for bandwidth and network quality, and solves the problem that the traditional method is only applicable to small and medium-sized users with low network quality requirements. At the same time, it avoids deploying overseas devices and public network addresses for each user separately, reducing the deployment complexity and additional costs.
[0076] In some alternative embodiments, the above method further includes the following steps:
[0077] Step a1: When the CPE device receives a configuration request sent by the SDWAN controller, it parses the configuration request to obtain multiple overseas Internet whitelist addresses.
[0078] Step a2: The CPE device generates a target whitelist based on the multiple overseas Internet whitelist addresses.
[0079] Step a3: Generate a first route based on the target whitelist.
[0080] Among them, the configuration request contains multiple overseas Internet whitelist addresses.
[0081] Specifically, after the CPE device receives the configuration request sent by the SDWAN controller, it can parse the configuration request and extract the corresponding multiple overseas Internet whitelist addresses.
[0082] Furthermore, integrate the multiple overseas Internet whitelist addresses obtained by extraction and generate the corresponding target whitelist. At the same time, the target whitelist can be stored in the local database.
[0083] Furthermore, the CPE device can generate a first route to the domestic POP device via ipsec based on the generated target whitelist, combined with its own routing configuration algorithm and network topology information.
[0084] Exemplarily, the CPE device can plan a transmission path from the local CPE device to the domestic POP device for each overseas Internet address or address segment in the target whitelist. Among them, path planning can comprehensively consider factors such as network link quality (such as bandwidth, latency, packet loss rate), device load conditions, etc., calculate the optimal path through routing protocols such as bgp() and OSPF, and configure relevant routing information (such as next-hop address, routing priority, etc.) to form the first route.
[0085] The whitelist addresses issued by the SDWAN controller enable the CPE device to precisely control the accessible overseas Internet addresses, enhance the security of network access, prevent illegal access, further optimize the management of cross-border Internet access, and avoid security risks and resource waste caused by users' random access to overseas networks. Further, generating a first route based on the target whitelist enables the CPE device to legally transmit data to the domestic POP device according to the first route, ensuring the continuity and reliability of overseas access, and thus providing users with stable cross-border network services.
[0086] In some alternative embodiments, the above method further includes the following steps:
[0087] Step b1, the overseas NAT device module publishes the second route and sequentially passes the second route through the overseas XGW device and the domestic XGW device.
[0088] Step b2, when the domestic POP device receives the second route, isolate the second route.
[0089] Specifically, the overseas NAT device module can publish the default route of 0.0.0.0 / 0, that is, the second route, in units of vrf through bgp (Border Gateway Protocol).
[0090] Furthermore, the overseas NAT device module can publish the distributed second route to the domestic POP device through the overseas XGW device and the domestic XGW device in sequence.
[0091] Furthermore, according to the description in the above step S202, the default route of the CPE device is usually used to access the domestic Internet. Therefore, when the domestic POP device receives the second route, it is necessary to isolate the second route to prevent the second route from being published to the CPE device.
[0092] Through the above process, the overseas NAT device publishes the second route and transmits it to the CPE device through the overseas XGW device and the domestic XGW device, ensuring the consistency of routing information between backbone network devices. Furthermore, the CPE device isolates the second route, preventing routing from interfering with the tenant's local network default route (usually used to access the domestic Internet), avoiding network failures caused by routing conflicts, and ensuring the accuracy and stability of network routing.
[0093] In this embodiment, a cross-border Internet access method is provided, which can be used for an SDWAN controller. The SDWAN controller is respectively connected to a cross-border Internet system and a front-end interface module. Figure 3 It is a flowchart of the cross-border Internet access method according to an embodiment of the present invention. As Figure 3 shown, the process includes the following steps:
[0094] Step S301, receive an operation request from the front-end interface module.
[0095] Among them, the operation request can be an activation request, a cross-border Internet access request, etc.
[0096] Specifically, a tenant or an operation and maintenance personnel can initiate a corresponding operation request to the SDWAN controller in the front-end interface module.
[0097] Step S302: Control the establishment of a traffic channel between the CPE device and the domestic POP device according to the operation request, and control the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device, so that the CPE device can access the overseas Internet through the domestic POP device, the domestic XGW device, and the overseas XGW device module in sequence according to the cross-border access request sent by the front-end interface module.
[0098] Specifically, the SDWAN controller can respectively control the establishment of a traffic channel between the CPE device and the domestic POP device and control the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device according to different operation requests received.
[0099] Furthermore, when a traffic channel is established between the CPE device and the domestic POP device, and traffic channels are respectively established between the domestic POP device, the domestic XGW device, and the overseas NAT device, it means that the tenant can access the overseas Internet through the cross-border Internet system.
[0100] Among them, according to the established traffic channel, the CPE device can access the overseas Internet through the domestic POP device, the domestic XGW device, and the overseas XGW device module in sequence according to the cross-border access request sent by the received front-end interface module. The specific process can refer to the specific process description of the above cross-border Internet access method for the cross-border Internet system, which will not be elaborated here.
[0101] The cross-border Internet access method provided in this embodiment controls the establishment of traffic channels between different devices in the cross-border Internet system according to the front-end operation request, realizing centralized management and control of the cross-border Internet system. Compared with the traditional networking method, it greatly simplifies the network deployment and management process, improves the efficiency and accuracy of network configuration, ensures the stability and reliability of network connections, and meets the cross-border network access needs of users.
[0102] In some alternative embodiments, the above method further includes the following steps:
[0103] Step c1: When receiving multiple shared addresses sent by the front-end interface module, generate a shared public network address pool according to the multiple shared addresses, and send the shared public network address pool to the overseas NAT device module.
[0104] Specifically, the operation and maintenance personnel can configure different shared EIPs (Elastic IP, public network addresses) on the front-end interface module, and integrate the configured multiple shared EIPs to form a shared public network address pool. Then, send the generated shared public network address pool to the SDWAN controller.
[0105] Furthermore, the SDWAN controller can distribute the generated shared public network address pool to the overseas NAT device module through the protocol stack.
[0106] By distributing the shared address pool to the overseas NAT device module, the sharing of public network address resources is realized. There is no need to allocate public network addresses separately for each user, effectively reducing the occupancy cost of public network address resources, reducing the investment in hardware devices, lowering the network deployment cost for enterprise-level users, and solving the problem of high costs caused by the need to separately configure public network addresses for each user in the traditional method.
[0107] In some alternative embodiments, the above method further includes the following steps:
[0108] Step d1, receiving multiple overseas Internet whitelist addresses sent by the front-end interface module.
[0109] Step d2, sending a configuration request to the CPE device according to the multiple overseas Internet whitelist addresses, so that the CPE device generates a target whitelist and a first route based on the configuration request.
[0110] Specifically, a tenant or an operation and maintenance personnel can send different overseas Internet whitelist addresses (URL, Uniform Resource Locator) to the SDWAN controller through the front-end interface module.
[0111] Furthermore, the SDWAN controller can integrate and process the received multiple overseas Internet whitelist addresses and then send a corresponding configuration request to the CPE device.
[0112] Furthermore, the CPE device can generate a corresponding target whitelist and a first route according to the received configuration request. The specific process can refer to the description of the above steps a1 to a3 and will not be elaborated here.
[0113] Through the above interaction process between the SDWAN controller and the CPE device in whitelist configuration, it can not only meet the security requirements of enterprise-level users for network access, but also reasonably control the use of network resources and improve network usage efficiency.
[0114] In some alternative embodiments, the SDWAN controller includes a data receiving module, a scheduling module, and a protocol module. Furthermore, when the operation request is an activation request, in the above step S302, controlling the establishment of a traffic channel between the CPE device and the domestic POP device according to the operation request includes:
[0115] Step e1, when the data receiving module receives the activation request sent by the front-end interface module, activating the CPE device with the activation request and parsing the activation request to obtain service data.
[0116] Specifically, a tenant or an operation and maintenance personnel can send an activation request to the SDWAN controller through the front-end interface module.
[0117] Furthermore, after the data receiving module in the SDWAN controller receives the activation request sent by the front-end interface module, it can activate the corresponding CPE device according to the activation request.
[0118] Furthermore, the data receiving module can also parse the received activation request and extract the service data contained in the activation request.
[0119] Furthermore, a tenant or an operation and maintenance personnel can also set a speed limit value through the front-end interface module and send it to the SDWAN controller through the activation request. Then, the SDWAN controller can also extract the speed limit value by parsing the activation request, and further, after activating the corresponding CPE device, use the speed limit value to limit the speed in the in and out directions on the CPE device on the user side.
[0120] Step e2: When the service data passes the verification, send a first device configuration scheduling task request to the scheduling module according to the service data.
[0121] Specifically, the data receiving module can verify the parsed service data, and when the verification passes, generate a corresponding first device configuration scheduling task request according to the service data, and then send the first device configuration scheduling task request to the scheduling module.
[0122] Step e3: The scheduling module constructs a CPE device configuration information set and a first POP device configuration information set according to the first device configuration scheduling task request.
[0123] Among them, the CPE device configuration information set includes first IPsec configuration information, first BGP configuration information, first BFD (Bidirectional Forwarding Detection) configuration information, and first QoS (Quality of Service) configuration information; the first POP device configuration information set includes VRF configuration information, second IPsec configuration information, second BGP configuration information, and second BFD configuration information.
[0124] Furthermore, the functions of the first IPsec configuration information and the second IPsec configuration information, the first BGP configuration information and the second BGP configuration information, and the first BFD configuration information and the second BFD configuration information are the same, only the parameter settings are different.
[0125] Specifically, the first device configures the device configuration scheduling task request corresponding device configuration scheduling task (parent task) as a background asynchronous execution task. Therefore, the scheduling module can, based on the received first device configuration scheduling task request, start the concurrently executed configuration subtasks for the CPE device and the POP device respectively in units of devices.
[0126] Furthermore, a southbound model object for configuration will be constructed in the subtask, and the southbound model object can include the configured CPE device configuration information set and the first POP device configuration information set.
[0127] Step e4, based on the CPE device configuration information set and the first POP device configuration information set, through the scheduling module and the protocol module, control the establishment of a traffic channel between the CPE device and the domestic POP device.
[0128] Specifically, based on the configured CPE device configuration information set and the first POP device configuration information set, the establishment of a traffic channel between the CPE device and the domestic POP device can be achieved through the scheduling module and the protocol module.
[0129] In some alternative embodiments, the above step e4 includes:
[0130] Step e41, when the protocol module receives the CPE device configuration information set and the first POP device configuration information set sent by the scheduling module, obtain the southbound protocol, the first device identifier, and the second device identifier.
[0131] Step e42, according to the first device identifier, the protocol module uses the southbound protocol to sequentially send the device configuration information in the CPE device configuration information set to the CPE device, so that the CPE device executes the CPE device configuration information set.
[0132] Step e43, according to the second device identifier, the protocol module uses the southbound protocol to sequentially send the device configuration information in the first POP device configuration information set to the domestic POP device, so that the domestic POP device executes the first POP device configuration information set.
[0133] Step e44, when the scheduling module receives the first execution result sent by the CPE device and the second execution result sent by the domestic POP device, control the establishment of a traffic channel between the CPE device and the domestic POP device according to the first execution result and the second execution result.
[0134] Among them, the first device identifier is used to represent the identifier of the CPE device; the second device identifier is used to represent the identifier of the domestic POP device.
[0135] Specifically, when the protocol module receives the CPE device configuration information set and the first POP device configuration information set sent by the scheduling module, it can select an appropriate southbound protocol and obtain the first device identifier of the CPE device and the second device identifier of the domestic POP device.
[0136] Furthermore, according to the first device identifier of the CPE device, the device configuration information in the CPE device configuration information set can be sequentially sent to the corresponding CPE device by using the southbound protocol. At the same time, according to the second device identifier of the domestic POP device, the device configuration information in the first POP device configuration information set can be sequentially sent to the corresponding domestic POP device by using the southbound protocol.
[0137] Furthermore, the CPE device can execute the received CPE device configuration information set to complete the corresponding configuration. At the same time, the domestic POP device can execute the received first POP device configuration information set to complete the corresponding configuration.
[0138] Furthermore, when all the CPE devices and domestic POP devices are successfully configured, the traffic channel between the CPE device and the domestic POP device can be established through the configuration result, that is, the traffic from the CPE device to the domestic POP device is established through the ipsec tunnel.
[0139] Furthermore, if a device fails to be configured successfully, the scheduling module needs to retry the failed configuration at regular intervals until the configuration is successful.
[0140] By obtaining the southbound protocol and device identifiers, different device configuration information can be sent to the corresponding devices, ensuring the accurate transmission of the configuration information. Furthermore, using the southbound protocol to send the configuration information to the corresponding devices enables the devices to obtain and execute the corresponding configuration information, realizing the automatic configuration and update of the device functions. Finally, the scheduling module controls the establishment of the traffic channel according to the device execution results, and the channel is established only when the device configuration is successful, ensuring the effectiveness and stability of the network connection and avoiding network failures caused by configuration failures.
[0141] In some alternative embodiments, when the operation request is a cross-border Internet access request, in step S302 above, controlling the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device according to the operation request includes:
[0142] Step f1, when the data receiving module receives the cross-border Internet access request sent by the front-end interface module, it parses the cross-border Internet access request to obtain the access data.
[0143] Specifically, a tenant or an operation and maintenance personnel can send a cross-border Internet access request to the SDWAN controller through the front-end interface module.
[0144] Furthermore, after the data receiving module in the SDWAN controller receives the cross-border Internet access request sent by the front-end interface module, it can parse the received cross-border Internet access request and extract the access data contained in the cross-border Internet access request.
[0145] Step f2: When the accessed data passes the verification, based on the access data, send a second device configuration scheduling task request to the scheduling module.
[0146] Specifically, the data receiving module can verify the parsed access data, and after the verification passes, generate a corresponding second device configuration scheduling task request according to the access data, and then send the second device configuration scheduling task request to the scheduling module.
[0147] Step f3: The scheduling module constructs a second POP device configuration information set, an XGW device configuration information set, and a NAT device configuration information set according to the second device configuration scheduling task request.
[0148] Among them, the second POP device configuration information set includes the first bridge-domain configuration information, the first loop configuration information, the third bgp configuration information, and the first vxlan configuration information; the XGW device configuration information set includes vrf configuration information, the second bridge-domain configuration information, the second loop configuration information, the fourth bgp configuration information, the second vxlan configuration information, and the second qos configuration information; the NAT device configuration information set includes vrf configuration information, the third bridge-domain configuration information, the third loop configuration information, the fifth bgp configuration information, the third vxlan configuration information, and static-route configuration information.
[0149] Furthermore, as described in the above step e3, the functions of the same configuration information are the same, only the parameter settings are different.
[0150] Specifically, the device configuration scheduling task corresponding to the second device configuration scheduling task request is an asynchronous device scheduling task. Therefore, the scheduling module can, based on the received second device configuration scheduling task request, start configuration subtasks for the POP device, the XGW device, and the NAT gateway device respectively in units of devices.
[0151] Furthermore, a southbound model object for configuration will be constructed in the subtask, and the southbound model object can include the configured second POP device configuration information set, XGW device configuration information set, and NAT device configuration information set.
[0152] Step f4: Based on the second POP device configuration information set, the XGW device configuration information set, and the NAT device configuration information set, control the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device via the scheduling module and the protocol module.
[0153] Specifically, based on the configured CPE device configuration information set and the first POP device configuration information set, the establishment of a traffic channel between the CPE device and the domestic POP device can be achieved through the scheduling module and the protocol module.
[0154] Among them, the specific process can refer to the relevant descriptions in steps e41 to e44 above and will not be elaborated here.
[0155] By constructing the configuration information sets of different devices, the accuracy and integrity of device configuration are ensured. Furthermore, each device can operate according to the preset parameters and protocols, guaranteeing the stability and security of network connections, achieving the precise configuration of cross-border network paths, and ensuring the stability and reliability of cross-border access.
[0156] In some alternative embodiments, the above method further includes the following steps:
[0157] Step g1: Receive the cross-border access route and speed limit value of the cross-border Internet system sent by the front-end interface module.
[0158] Step g2: Control the access speed of the access operation based on the cross-border access route in the cross-border Internet system according to the speed limit value.
[0159] Specifically, a tenant or an operation and maintenance personnel can select the route to access the overseas Internet through the front-end interface module, and this route includes domestic POP, domestic XGW, overseas XGW, and overseas NAT gateway.
[0160] Meanwhile, a tenant or an operation and maintenance personnel can set the corresponding speed limit value through the front-end interface module.
[0161] Furthermore, when the SDWAN controller receives the cross-border access route and speed limit value sent by the front-end interface module, it can limit the access speed of the access operation based on the cross-border access route according to this speed limit value.
[0162] Among them, XGW is a pure cross-border gateway device that only transmits traffic related to cross-border services. Therefore, according to this speed limit value, direction-based speed limits are imposed on the vxlan of the domestic XGW device (in the direction from the domestic XGW device to the overseas XGW device); and direction-based speed limits are imposed on the vxlan of the overseas XGW device (in the direction from the overseas XGW device to the domestic XGW device).
[0163] Further, according to the description in step e1, rate limiting is also performed on the user side for both outgoing and incoming directions on the CPE device. Therefore, the entire section from the CPE device to the overseas XGW device achieves the purpose of rate limiting.
[0164] Further, the overseas XGW device and the overseas NAT device module are usually deployed in a resource pool, and the internal network is used between them, so rate limiting can be not performed.
[0165] Through the rate limiting mechanism, network resources can be reasonably allocated, preventing individual users from occupying too much bandwidth and affecting the usage experience of other users. At the same time, it can also ensure the network bandwidth requirements of critical services, improving the overall network usage efficiency and service quality.
[0166] In some alternative embodiments, step d2 can be implemented in the following manner:
[0167] Specifically, the data receiving module in the SDWAN controller performs parameter verification on multiple overseas Internet whitelist addresses received and initiates a configuration task.
[0168] Further, a whitelist southbound configuration model object for the CPE will be generated in the configuration task and sent to the protocol module.
[0169] Further, the protocol module selects a southbound protocol, retrieves the configuration from the queue, and distributes it to the CPE device according to the device identifier.
[0170] Further, the CPE device can generate a corresponding target whitelist and a first route based on the received configuration information.
[0171] Further, the SDWAN controller can also obtain the configuration status of the CPE device, record the successful devices in the database, and respond to the front-end interface module.
[0172] In some alternative embodiments, the CPE device and the domestic POP device can both reuse the devices of the domestic SDWAN network (domestic POP device, domestic XGW device, overseas XGW device, and overseas NAT device module). Further, the domestic SDWAN networking between the CPE device and the domestic POP device uses a detailed route, which is separated from the cross-border Internet access route of the above solution.
[0173] In one example, a high-quality overseas Internet access method based on the sdwan network is provided, including:
[0174] (1) Networking method.
[0175] Such as Figure 1As shown, each tenant needs an intelligent gateway device (hereinafter referred to as CPE device), the tenant's local network is connected to the CPE device LAN side, and the CPE device WAN side is connected to the domestic backbone network device (hereinafter referred to as POP device); the domestic POP device is connected to the domestic cross-border gateway device (hereinafter referred to as XGW device); the domestic XGW device is connected to the overseas XGW device, and the traffic crosses the border. At the same time, the XGW device, as a simple cross-border device, can control the cross-border traffic; the overseas XGW device is connected to the overseas NAT gateway device, and the traffic can access the Internet through the overseas NAT gateway. The above tenant-side CPE devices and the devices in the backbone network are all controlled by the sdwan controller.
[0176] (2) Methods for unblocking traffic.
[0177] Traffic between tenants is isolated by vrf. At the overlay (virtual network built on the underlying network) level, the CPE is connected to the domestic POP device through an ipsec tunnel, and ipsec is added to the tenant's vrf on the POP device; the POP device is connected to the domestic XGW through a vxlan tunnel, and the vxlan tunnel is bound to the tenant's vrf; the domestic XGW and the overseas XGW are connected through a vxlan tunnel, and the vxlan tunnel is bound to the tenant's vrf; the overseas XGW and the overseas NAT gateway are connected through a vxlan tunnel, and the vxlan tunnel is bound to the tenant's vrf. At the underlay level, the domestic XGW and the overseas XGW are connected through a dedicated line to reduce network latency and improve network quality.
[0178] On the overseas NAT gateway device, the default route of 0.0.0.0 / 0 needs to be published through bgp in units of vrf. This route will be published to the domestic POP device via the overseas XGW and domestic XGW. Since the default route on the tenant-side CPE device is usually used to access the domestic Internet, this route needs to be isolated on the domestic POP device and cannot be published to the tenant CPE device.
[0179] A shared eip (public network address) address pool needs to be configured on the overseas NAT gateway device. Users convert the source address of the message sent from the country to the public network address. All users who access the overseas Internet on the NAT gateway access the overseas Internet through eip, thus saving public network addresses. If the user has high requirements for eip, a dedicated eip can be configured on the NAT gateway and bound to the user vrf, so that the user can use the dedicated eip to access the overseas Internet. A static default route needs to be configured on the overseas NAT gateway device to specify the message outbound interface.
[0180] The overseas NAT gateway is deployed in a dual-machine configuration. Different users can use one of them as the primary device and the other as the standby device, achieving both primary-standby high availability and dual-machine load balancing.
[0181] On the tenant CPE device, a whitelist for accessing the overseas network needs to be configured. After adding the whitelist, the CPE device will generate a route to the domestic POP via IPsec. If accessing an overseas Internet URL that is not on the whitelist, since there is no route on the CPE device, the default route of the CPE will be used, resulting in an inaccessible connection.
[0182] (3) Overall process of accessing the overseas Internet.
[0183] After the tenant initiates a request to access the overseas Internet on the local terminal, the packet will first reach the CPE device. Since the URL of the overseas Internet to be accessed has been added to the whitelist on the CPE device, the request packet can find the route. The packet reaches the domestic POP device via the IPsec tunnel through the CPE device. Since the destination address of the packet is an overseas Internet address and there is no detailed route configured or learned on the POP, the default route on the POP is used, which is the default route advertised from the overseas NAT gateway device mentioned above. The packet can be sent sequentially from the domestic POP to the domestic XGW, overseas XGW, and overseas NAT gateway device via the VXLAN tunnel. On the overseas NAT gateway device, the source address of the packet is converted from the private network address to the public network address in the address pool. The packet for accessing the overseas Internet takes the default route on the overseas NAT gateway and is sent out through the specified interface. Thus, the tenant can access the overseas Internet locally through the SD-WAN network.
[0184] (4) Access speed limit.
[0185] The XGW is a pure cross-border gateway device that only carries traffic related to cross-border services. Directional speed limits are set on the VXLAN of the domestic XGW (in the direction from the domestic XGW to the overseas XGW) and on the VXLAN of the overseas XGW (in the direction from the overseas XGW to the domestic XGW). The user side sets speed limits for the outgoing and incoming directions on the CPE device. In this way, speed limits are achieved for the entire segment from the CPE to the overseas XGW. The overseas XGW and the overseas NAT gateway are usually deployed in the same resource pool and communicate via the private network, so speed limits can be omitted between them.
[0186] In addition, both the CPE device and the domestic POP device can reuse the devices of the domestic SD-WAN network. The domestic SD-WAN networking between the CPE device and the POP device uses detailed routes, which are separated from the routes for cross-border Internet access in this solution.
[0187] This example provides a high-quality overseas Internet access method based on the sdwan network. Based on the cross-border acceleration of sdwan, it can provide high-quality cross-border acceleration through the NAT gateway to meet the user's overseas Internet access needs in various scenarios.
[0188] Furthermore, based on the above method, a cross-border acceleration system is provided, including a front-end interface module, a data receiving module, a scheduling module, a protocol module, and a network element device. Among them, the data receiving module, the scheduling module, and the protocol module are all set in the SDWAN controller; the network element device includes a CPE device and a backbone network device, and further, the backbone network device includes a domestic POP device, a domestic XGW device, an overseas XGW device, and an overseas NAT device. Figure 4 As shown, the implementation process of the system is as follows:
[0189] First, activate the tenant-side CPE device. The purpose of this operation is to open up the traffic from CPE to POP through the tunnel. The process is as follows:
[0190] (1) The tenant or operation and maintenance personnel selects the CPE device to be activated on the front-end interface, sets the speed limit value, and clicks the Activate button.
[0191] (2) The SDWAN controller data receiving module receives the request, performs parameter verification, and stores the service data in the database. The current service status is "Active". The device configuration scheduling task is started, and the front-end interface responds to the request successfully.
[0192] (3) The device configuration scheduling task (parent task) is a background asynchronous execution task. The parent task will start concurrent configuration subtasks for CPE devices and POP devices respectively. The subtask will build the configured southbound model object. The CPE device configuration includes ipsec, bgp, bfd, and qos (Quality of Service), and the POP device configuration includes vrf, ipsec, bgp, and bfd. After the above configuration is built, it will be sent to the protocol module in sequence.
[0193] (4) The protocol module selects a southbound protocol, takes the configuration out of the queue, and sends it to the specified CPE device and POP device according to the device ID.
[0194] (5) If a device fails to execute, the scheduling module needs to retry the failed configuration regularly. After all configurations are executed successfully, the database business status is changed to "activation successful".
[0195] (6) At this point, traffic from CPE to POP is unblocked, and the speed is limited through QoS configuration on the CPE device.
[0196] Secondly, create a cross-border acceleration service. The purpose of this operation is to tunnel the traffic from the domestic POP device to the overseas NAT gateway; publish the 0.0.0.0 / 0 default route on the overseas NAT gateway so that it can direct the packets to overseas on the domestic POP; configure an isolated default route on the domestic POP to prevent the default route from being published to the tenant CPE device; configure an address pool on the overseas NAT gateway to perform SNAT (Source Network Address Translation) on the packets accessing the overseas Internet. The service process is as follows:
[0197] (1) The operation and maintenance personnel configure a shared eip on the NAT gateway of the front-end interface (users with requirements can configure a dedicated eip). The controller, through the synchronization method, distributes the nat-pool (NAT address pool) configuration to the NAT gateway device through the protocol stack.
[0198] (2) The tenant or operation and maintenance personnel select the line to access the overseas Internet on the front-end interface. This line includes the domestic POP, domestic XGW, overseas XGW, and overseas NAT gateway, set the speed limit value, and click the create cross-border acceleration button.
[0199] (3) The data receiving module of the SDWAN controller receives the request, performs parameter verification, and stores the service data in the database. The current service status is "operating". Start the device configuration scheduling task and respond to the front-end interface that the request is successful.
[0200] (4) The asynchronous device scheduling task will start configuration subtasks for the POP device, XGW device, and NAT gateway device respectively in units of devices. In the subtasks, a southbound model object of the configuration will be constructed, and the primary and standby roles of the NAT gateway device will be automatically selected for the user according to the existing load conditions. The POP device configuration includes bridge-domain, loop, bgp, vxlan. The XGW device configuration includes vrf, bridge-domain, loop, bgp, vxlan, qos. The NAT gateway device configuration includes vrf, bridge-domain, loop, bgp, vxlan, static-route. After the above configurations are built, they will be sent to the protocol module in sequence.
[0201] (5) The protocol module selects a southbound protocol, retrieves the configuration from the queue, and distributes it to the specified POP device, XGW device, and NAT gateway device respectively according to the device identifier.
[0202] (6) If a device fails to execute, the scheduling module needs to retry the failed configuration at regular intervals. After all configurations are successfully executed, modify the service status in the database to "operation successful".
[0203] (7) At this point, the traffic from the domestic POP to the overseas NAT gateway has also been connected, and traffic shaping has been performed through qos configuration on the XGW device.
[0204] Finally, configure the whitelist on the CPE device. The purpose is to generate a route on the CPE device, direct the packets accessing the overseas Internet to the ipsec tunnel on the CPE device, and then send them to the POP. The process is as follows:
[0205] (1) The tenant or operation and maintenance personnel select the above-activated CPE device on the front-end interface, enter the overseas Internet whitelist url, and click the configure whitelist button.
[0206] (2) The data reception module of the SDWAN controller receives the request, performs parameter verification, and starts the configuration task.
[0207] (3) In the configuration task, a southbound configuration model object for the CPE whitelist will be generated and sent to the protocol module.
[0208] (4) The protocol module selects a southbound protocol, retrieves the configuration from the queue, and distributes it to the CPE device according to the device identifier.
[0209] (5) The SDWAN controller obtains the configuration status, records the successful devices in the database, and responds to the front-end page.
[0210] Through the above three parts, domestic tenants can access the overseas Internet. When a tenant's local terminal needs to access the overseas Internet, the traffic will first be sent to the CPE device on the user side. If the CPE device queries that the url to be accessed is in the whitelist, it will query the route from the whitelist routing table, send the packet to the ipsec tunnel, and then reach the domestic POP device. On the POP device, since there is no detailed route for the destination address of the packet, the default route published by the overseas NAT gateway will be used to send the packet to the overseas NAT gateway. On the overseas NAT gateway, the source address of the packet will be converted to the public network address in the nat address pool. A static default route is configured on the overseas NAT gateway, and the packet is sent out through the specified interface. The purpose of accessing the overseas Internet is achieved.
[0211] Furthermore, through the above example, an enterprise-level method for accessing the overseas Internet is provided, which can provide high-quality and high-bandwidth connections. Overseas, there is no need for each user to deploy separate devices and public network addresses for accessing the overseas Internet, reducing the deployment complexity and additional business costs.
[0212] The embodiment of the present invention also provides a computer device that executes the cross-border Internet access method provided in the above embodiment.
[0213] Please refer toFigure 5 , Figure 5 is a schematic structural diagram of a computer device provided by an optional embodiment of the present invention. As Figure 5 shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Each component communicates with each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a set of blade servers, or a multi-processor system). Figure 5 In
[0214] FIG. 6, one processor 10 is taken as an example.
[0215] The processor 10 may be a central processing unit, a network processor, or a combination thereof. Among them, the processor 10 may further include a hardware chip. The above-mentioned hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The above-mentioned programmable logic device may be a complex programmable logic device, a field-programmable gate array, a general array logic, or any combination thereof.
[0216] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiments.
[0217] The memory 20 may include a storage program area and a storage data area. Among them, the storage program area may store an operating system and application programs required for at least one function; the storage data area may store data created according to the use of the computer device. In addition, the memory 20 may include a high-speed random access memory, and may further include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some optional embodiments, the memory 20 may optionally include a memory remotely set relative to the processor 10, and these remote memories may be connected to the computer device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0218] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or communication networks.
[0219] Embodiments of the present invention also provide a computer-readable storage medium. The methods according to the embodiments of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code that is originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the methods described herein can be stored as such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the methods shown in the above embodiments are implemented.
[0220] A part of the present invention can be applied as a computer program product, such as computer program instructions, which when executed by a computer, can call or provide the methods and / or technical solutions according to the present invention through the operation of the computer. Those skilled in the art should be able to understand that the forms of existence of computer program instructions in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Herein, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible by the computer.
[0221] Although the embodiments of the present invention are described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A cross-border Internet access method, characterized in that, For a cross-border Internet system, the cross-border Internet system is respectively connected to an SDWAN controller and a front-end interface module. The cross-border Internet system includes a CPE device, a domestic POP device, a domestic XGW device, an overseas XGW device, and an overseas NAT device module. The overseas NAT device module is deployed in a dual-machine configuration; The method includes: When the CPE device receives a cross-border access request sent by the front-end interface module, parse the cross-border access request to obtain an access packet and an overseas Internet access address; When the overseas Internet access address exists in the target whitelist of the CPE device, send the access packet to the domestic POP device based on the first route; The domestic POP device, based on the second route, sends the access packet to the overseas NAT device module through the domestic XGW device and the overseas XGW device in sequence; The overseas NAT device module converts the source address of the access packet into a public network address based on the shared public network address pool, and sends the access packet to the overseas Internet through the public network address. The shared public network address pool is sent by the SDWAN controller; When the CPE device receives the access result returned by the overseas Internet, send the access result to the front-end interface module.
2. The method according to claim 1, characterized in that, The method further includes: When the CPE device receives a configuration request sent by the SDWAN controller, parse the configuration request to obtain multiple overseas Internet whitelist addresses; The CPE device generates the target whitelist according to the multiple overseas Internet whitelist addresses; Generate the first route based on the target whitelist.
3. The method according to claim 1, wherein The method further includes: The overseas NAT device module publishes the second route, and sends the second route to the domestic POP device through the overseas XGW device and the domestic XGW device in sequence; When the domestic POP device receives the second route, isolate the second route.
4. A cross-border Internet access method, characterized in that, For an SDWAN controller, the SDWAN controller is respectively connected to a cross-border Internet system and a front-end interface module; The method includes: Receive an operation request from the front-end interface module; According to the operation request, control the establishment of a traffic channel between the CPE device and the domestic POP device, and control the domestic POP device to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device, so that the CPE device can access the overseas Internet through the domestic POP device, the domestic XGW device, and the overseas XGW device module in sequence according to the cross-border access request sent by the front-end interface module.
5. The method according to claim 4, characterized in that The method further includes: When receiving multiple shared addresses sent by the front-end interface module, generate a shared public network address pool according to the multiple shared addresses, and send the shared public network address pool to the overseas NAT device module.
6. The method according to claim 4, wherein The method further includes: Receive multiple overseas Internet whitelist addresses sent by the front-end interface module; Send a configuration request to the CPE device according to the multiple overseas Internet whitelist addresses, so that the CPE device generates a target whitelist and a first route based on the configuration request.
7. The method according to claim 4, wherein The SDWAN controller includes a data receiving module, a scheduling module, and a protocol module. The operation request is an activation request. Controlling the establishment of a traffic channel between the CPE device and the domestic POP device according to the operation request includes: When the data receiving module receives the activation request sent by the front-end interface module, activate the CPE device using the activation request, and parse the activation request to obtain service data; When the service data passes the verification, send a first device configuration scheduling task request to the scheduling module according to the service data; The scheduling module constructs a CPE device configuration information set and a first POP device configuration information set according to the first device configuration scheduling task request. The CPE device configuration information set includes first ipsec configuration information, first bgp configuration information, first bfd configuration information, and first qos configuration information. The first POP device configuration information set includes vrf configuration information, second ipsec configuration information, second bgp configuration information, and second bfd configuration information; Based on the CPE device configuration information set and the first POP device configuration information set, control the establishment of a traffic channel between the CPE device and the domestic POP device through the scheduling module and the protocol module.
8. The method according to claim 7, wherein Based on the CPE device configuration information set and the first POP device configuration information set, control the establishment of a traffic channel between the CPE device and the domestic POP device through the scheduling module and the protocol module, including: When the protocol module receives the CPE device configuration information set and the first POP device configuration information set sent by the scheduling module, obtain the southbound protocol, the first device identifier, and the second device identifier; According to the first device identifier, the protocol module uses the southbound protocol to sequentially send the device configuration information in the CPE device configuration information set to the CPE device, so that the CPE device executes the CPE device configuration information set; According to the second device identifier, the protocol module uses the southbound protocol to sequentially send the device configuration information in the first POP device configuration information set to the domestic POP device, so that the domestic POP device executes the first POP device configuration information set; When the scheduling module receives the first execution result sent by the CPE device and the second execution result sent by the domestic POP device, control the establishment of a traffic channel between the CPE device and the domestic POP device according to the first execution result and the second execution result.
9. The method according to claim 7, wherein The operation request is a cross-border Internet access request. Controlling the establishment of a traffic channel between the domestic POP device and the overseas NAT device module through the domestic XGW device and the overseas XGW device according to the operation request includes: When the data receiving module receives the cross-border Internet access request sent by the front-end interface module, it parses the cross-border Internet access request to obtain access data; When the access data passes the verification, based on the access data, a second device configuration scheduling task request is sent to the scheduling module; The scheduling module constructs a second POP device configuration information set, an XGW device configuration information set, and a NAT device configuration information set according to the second device configuration scheduling task request. The second POP device configuration information set includes first bridge-domain configuration information, first loop configuration information, third bgp configuration information, and first vxlan configuration information. The XGW device configuration information set includes vrf configuration information, second bridge-domain configuration information, second loop configuration information, fourth bgp configuration information, second vxlan configuration information, and second qos configuration information. The NAT device configuration information set includes the vrf configuration information, third bridge-domain configuration information, third loop configuration information, fifth bgp configuration information, third vxlan configuration information, and static-route configuration information; Based on the second POP device configuration information set, the XGW device configuration information set, and the NAT device configuration information set, through the scheduling module and the protocol module, the domestic POP device is controlled to establish a traffic channel with the overseas NAT device module through the domestic XGW device and the overseas XGW device.
10. The method according to claim 4, wherein The method further includes: Receiving the cross-border access route and speed limit value of the cross-border Internet system sent by the front-end interface module; According to the speed limit value, controlling the access speed of the access operation based on the cross-border access route in the cross-border Internet system.