Message forwarding method, system, device and equipment
By configuring firewall devices and subnet network forwarding devices in a private network, using routing policies and security policies to target private virtual machines and subnet virtual machines, the problem of inability to comprehensive protection in the existing technology is solved and the security of the network is improved.
Patent Information
- Application Number
- CN202510703337.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-18
AI Technical Summary
Existing protection technologies cannot effectively protect both private virtual machines and subnet virtual machines, resulting in a decline in network security in advanced network architectures when facing complex network attacks.
By configuring firewall devices and subnet network forwarding devices in a private network, using routing policies and security policies, targeted protection of private virtual machines and subnet virtual machines, including receiving connection and routing configuration instructions from the cloud security management platform, filtering idle state firewall devices for network connection.
It realizes comprehensive protection of private virtual machines and subnet virtual machines, improves the overall security of the network, and ensures effective protection of different virtual machines under different networks.
Smart Images

Figure CN120342764A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and particularly to a method, system, device, and equipment for packet forwarding. Background Art
[0002] The basic network architecture is a network architecture composed of a private switch and multiple private virtual machines, and the basic network architecture has been widely applied in some scenarios with low requirements for network complexity. However, with the continuous growth of business requirements and the expansion of the network scale, the basic network architecture is difficult to meet the complex and changing network requirements. Therefore, the advanced network architecture emerges as the times require. The advanced network architecture is obtained by dividing the basic network structure into subnets, where each subnet is equipped with a subnet router and multiple subnet virtual machines.
[0003] However, the existing protection technologies can only protect private virtual machines or subnet virtual machines, and cannot effectively protect both private virtual machines and subnet virtual machines. Facing the advanced network architecture, this single protection mode is prone to protection loopholes when facing complex network attacks, resulting in a decline in the overall network security. Summary of the Invention
[0004] In view of this, this application proposes a method, system, device, and equipment for packet forwarding to solve the problem in the related technologies that both private virtual machines and subnet virtual machines cannot be effectively protected, resulting in a decline in network security.
[0005] A first aspect embodiment of this application proposes a method for packet forwarding. The method is applied to a first network forwarding device in a private network. The private network includes a firewall device and at least one subnet, and each subnet includes a second network forwarding device. The method includes:
[0006] In response to receiving a packet to be forwarded, determining the next-hop device according to the destination address of the packet to be forwarded and a first routing policy. The first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and the second network forwarding device. The first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet.
[0007] When the next-hop device is the firewall device, forwarding the packet to be forwarded to the firewall device, so that the firewall device processes the packet to be forwarded according to a first security policy corresponding to the first destination address of the packet to be forwarded.
[0008] When the next-hop device is any second network forwarding device, forward the to-be-forwarded packet to the second network forwarding device, so that the second network forwarding device sends the to-be-forwarded packet to the firewall device according to a second routing policy and a second destination address of the to-be-forwarded packet; the firewall device processes the to-be-forwarded packet according to a second security policy corresponding to the second destination address; the second routing policy includes a third association relationship between the second destination address and the firewall device.
[0009] In the embodiment of the present application, by setting up a firewall device, configuring a first routing policy on a first network forwarding device in a private network, and configuring a second routing policy on a second network forwarding device in any subnet, the purpose of protecting different virtual machines under different networks with one firewall device can be achieved, thereby improving network security.
[0010] In the embodiment of the present application, the private network includes at least one first virtual machine; each subnet includes at least one second virtual machine; determining a next-hop device according to a destination address of the to-be-forwarded packet and the first routing policy includes:
[0011] If the destination address of the to-be-forwarded packet is a network address of any first virtual machine, determine the next-hop device as the firewall device;
[0012] If the destination address of the to-be-forwarded packet is a network address of any second virtual machine in any subnet, determine the next-hop device as the second network forwarding device of the any subnet.
[0013] In the embodiment of the present application, according to different destination addresses of the to-be-forwarded packet, the to-be-forwarded packet can be sent to different next-hop devices, which provides a technical basis for effectively protecting both private virtual machines and subnet virtual machines.
[0014] In the embodiment of the present application, the firewall device includes a plurality of sub-firewalls; before forwarding the to-be-forwarded packet to the firewall device, it further includes:
[0015] Receiving a connection instruction from a cloud security management platform, where the connection instruction includes an identifier of a first sub-firewall; the first sub-firewall is a sub-firewall in an idle state screened by the cloud security management platform from the plurality of sub-firewalls in response to a situation where any first virtual machine is a protection object;
[0016] Establish a network connection with the first sub-firewall, so that when the first sub-firewall receives the packet to be forwarded from the first network forwarding device, the packet to be forwarded is processed according to the first security policy to obtain a first packet; the first security policy corresponding to any first virtual machine is pre-configured in the first sub-firewall.
[0017] In the embodiment of the present application, by establishing a network connection between the first network forwarding device and the first sub-firewall according to the connection instruction, it can be ensured that the first sub-firewall receives all packets sent to any first virtual machine through this network connection, so as to achieve the purpose of using the first sub-firewall to only perform protection processing on the packets sent to any first virtual machine.
[0018] In the embodiment of the present application, before responding to receiving the packet to be forwarded, the method further includes:
[0019] Receiving a first routing configuration instruction and a second routing configuration instruction from the cloud security management platform; the first routing configuration instruction is generated by the cloud security management platform when determining that the protection object is any first virtual machine; the first routing configuration instruction includes the network address of any first virtual machine and the sub-firewall corresponding to any first virtual machine; the second routing configuration instruction is generated by the cloud security management platform when determining that the protection object is any second virtual machine; the second routing configuration instruction includes the network address of any second virtual machine and the network address of the second network forwarding device corresponding to any second virtual machine;
[0020] Generate the first routing policy of the packet to be forwarded according to the first routing configuration instruction and the second routing configuration instruction.
[0021] In the embodiment of the present application, the first routing policy of the packet to be forwarded is generated according to the first routing configuration instruction and the second routing configuration instruction, which can ensure that the packets sent to any first virtual machine are forwarded to the firewall device, and the packets sent to any second virtual machine are forwarded to the second network forwarding device in the subnet where any second virtual machine is located, and further can provide a technical basis for effectively protecting both private virtual machines and subnet virtual machines.
[0022] In the embodiment of the present application, the second routing policy is generated by the second network forwarding device according to the third routing configuration instruction sent by the cloud security management platform, and the third routing configuration instruction is generated by the cloud security management platform when determining that the protection object is any second virtual machine; the third routing configuration instruction includes the network address of any second virtual machine in any subnet and the network address of the firewall device.
[0023] An embodiment of the second aspect of this application provides a message forwarding method, which is applied to a firewall device in a private network. The private network also includes a first network forwarding device and at least one subnet, and each subnet includes a second network forwarding device. The method includes:
[0024] After receiving a message to be forwarded from the first network forwarding device, process the message to be forwarded according to the first security policy. The message to be forwarded is sent by the first network forwarding device when it determines, according to the destination address of the message to be forwarded and the first routing policy, that the next-hop device is the firewall device. The first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device. The first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet.
[0025] After receiving a message to be forwarded from any second network forwarding device, process the message to be forwarded according to the second security policy. The message to be forwarded is sent by any second network forwarding device to the firewall device according to the second routing policy and the second destination address of the message to be forwarded. The second routing policy includes a third association relationship between the second destination address and the firewall device.
[0026] In the embodiment of this application, the firewall device includes multiple sub-firewalls, and the method further includes:
[0027] Receive a connection instruction from a cloud security management platform. The connection instruction includes the identifier of any second network forwarding device. The any first network forwarding device is determined by the cloud security management platform in response to a situation where any second virtual machine is a protection object.
[0028] Select a second sub-firewall in an idle state from the multiple sub-firewalls.
[0029] Establish a network connection between the second sub-firewall and the any second network forwarding device, so that when the second sub-firewall receives the message to be forwarded from the any second network forwarding device, process the message to be forwarded according to the second security policy to obtain a second message. The second security policy corresponding to the any second virtual machine is pre-configured in the second sub-firewall.
[0030] An embodiment of the third aspect of this application provides a message forwarding system, which includes a first network forwarding device, a firewall device, and at least one subnet deployed in a private network. The system also includes a second network forwarding device deployed in each subnet.
[0031] The first network forwarding device is configured to, in response to receiving a packet to be forwarded, determine a next-hop device according to the destination address of the packet to be forwarded and a first routing policy; when the next-hop device is the firewall device, forward the packet to be forwarded to the firewall device; when the next-hop device is any second network forwarding device, forward the packet to be forwarded to the second network forwarding device; the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet;
[0032] Any of the second network forwarding devices is configured to send the packet to be forwarded to the firewall device according to a second routing policy and the second destination address of the packet to be forwarded; the second routing policy includes a third association relationship between the second destination address and the firewall device;
[0033] The firewall device is configured to receive the packet to be forwarded from the first network forwarding device, and process the packet to be forwarded according to a first security policy corresponding to the first destination address of the packet to be forwarded; receive the packet to be forwarded from any of the second network forwarding devices, and process the packet to be forwarded according to a second security policy corresponding to the second destination address of the packet to be forwarded.
[0034] An embodiment of the fourth aspect of the present application provides a packet forwarding device, which is applied to a first network forwarding device in a private network. The private network includes a firewall device and at least one subnet, and each subnet includes a second network forwarding device; the device includes:
[0035] A next-hop device determination module, configured to, in response to receiving a packet to be forwarded, determine a next-hop device according to the destination address of the packet to be forwarded and a first routing policy; the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet;
[0036] A first packet forwarding module, configured to, when the next-hop device is the firewall device, forward the packet to be forwarded to the firewall device, so that the firewall device processes the packet to be forwarded according to a first security policy corresponding to the first destination address of the packet to be forwarded;
[0037] The second message forwarding module is configured to forward the message to be forwarded to the second network forwarding device when the next-hop device is any second network forwarding device, so that the second network forwarding device sends the message to be forwarded to the firewall device according to the second routing policy and the second destination address of the message to be forwarded; the firewall device processes the message to be forwarded according to the second security policy corresponding to the second destination address; the second routing policy includes a third association relationship between the second destination address and the firewall device.
[0038] An embodiment of the fifth aspect of the present application provides a message forwarding device, which is applied to a firewall device in a private network. The private network further includes a first network forwarding device and at least one subnet, and each subnet includes a second network forwarding device. The device includes:
[0039] The first message processing module is configured to process the message to be forwarded according to the first security policy after receiving the message to be forwarded from the first network forwarding device; the message to be forwarded is sent by the first network forwarding device when it determines that the next-hop device is the firewall device according to the destination address of the message to be forwarded and the first routing policy; the first routing policy includes a first association relationship between the first destination address and the firewall device, and a second association relationship between the second destination address and the second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet.
[0040] The second message processing module is configured to process the message to be forwarded according to the second security policy after receiving the message to be forwarded from any second network forwarding device; the message to be forwarded is sent to the firewall device by any second network forwarding device according to the second routing policy and the second destination address of the message to be forwarded; the second routing policy includes a third association relationship between the second destination address and the firewall device.
[0041] An embodiment of the sixth aspect of the present application provides a network forwarding device, which includes a memory and a processor. The memory and the processor are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to execute the message forwarding methods described in the first aspect and the second aspect above.
[0042] An embodiment of the seventh aspect of the present application provides a computer-readable storage medium, on which computer instructions are stored. The computer instructions are used to cause a computer to execute the message forwarding methods described in the first aspect and the second aspect above.
[0043] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the following detailed description of the preferred embodiments. The drawings are only for the purpose of illustrating the preferred embodiments and are not to be construed as limiting the present application. Also, throughout the drawings, the same reference numerals are used to denote the same components.
[0045] In the drawings:
[0046] Figure 1 A schematic structural diagram of a message forwarding system provided by an embodiment of the present application is shown;
[0047] Figure 2 A schematic flowchart of a message forwarding method provided by an embodiment of the present application is shown;
[0048] Figure 3 A schematic flowchart of another message forwarding method provided by an embodiment of the present application is shown;
[0049] Figure 4 A schematic flowchart of another message forwarding method provided by an embodiment of the present application is shown;
[0050] Figure 5 A schematic configuration diagram of a firewall device provided by an embodiment of the present application is shown;
[0051] Figure 6 A schematic flowchart of another message forwarding method provided by an embodiment of the present application is shown;
[0052] Figure 7 A schematic flowchart of another message forwarding method provided by an embodiment of the present application is shown;
[0053] Figure 8 A schematic flowchart of another message forwarding method provided by an embodiment of the present application is shown;
[0054] Figure 9 A schematic structural diagram of a message forwarding device provided by an embodiment of the present application is shown;
[0055] Figure 10 A schematic structural diagram of a network forwarding device provided by an embodiment of the present application is shown;
[0056] Figure 11 A schematic diagram of a storage medium provided by an embodiment of the present application is shown. Detailed implementation manners
[0057] The exemplary implementation manners of the present application will be described in more detail with reference to the accompanying drawings. Although the exemplary implementation manners of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the implementation manners set forth herein. On the contrary, these implementation manners are provided so that the present application can be more thoroughly understood and the scope of the present application can be fully communicated to those skilled in the art.
[0058] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in the present application should have the ordinary meanings understood by those skilled in the art to which the present application belongs.
[0059] According to an embodiment of the present application, an embodiment of a message forwarding method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0060] Embodiment 1:
[0061] In this embodiment, a message forwarding method is provided. The method is applied to a first network forwarding device in a private network; as Figure 1 shown: The private network includes a firewall device, at least one subnet, and at least one first virtual machine. Each subnet includes a second network forwarding device and at least one second virtual machine.
[0062] Figure 2 is a flowchart of the message forwarding method according to an embodiment of the present application. As Figure 2 shown, the process includes the following steps:
[0063] Step S101, in response to receiving a message to be forwarded, determine the next-hop device according to the destination address of the message to be forwarded and a first routing policy.
[0064] Specifically, the first network forwarding device is configured with a first routing policy. Through this first routing policy and the destination address of the message to be forwarded, the next-hop device of the message to be forwarded can be determined. Among them, the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet.
[0065] In some specific embodiments, the above step S101 includes steps S1011 - S1012:
[0066] Step S1011, if the destination address of the packet to be forwarded is the network address of any first virtual machine, then determine the next-hop device as the firewall device.
[0067] Step S1012, if the destination address of the packet to be forwarded is the network address of any second virtual machine in any subnet, then determine the next-hop device as the second network forwarding device of the any subnet.
[0068] In the embodiment of the present application, it can be determined through the first association relationship of the above first routing policy that when the destination address of the packet to be forwarded is the network address of any first virtual machine in the private network, the next-hop device of the packet to be forwarded is the firewall device. Similarly, it can be determined through the second association relationship of the above first routing policy that when the destination address of the packet to be forwarded is the network address of any second virtual machine in any subnet, the next-hop device of the packet to be forwarded is the second network forwarding device in the any subnet.
[0069] Step S102, when the next-hop device is the firewall device, forward the packet to be forwarded to the firewall device, so that the firewall device processes the packet to be forwarded according to the first security policy corresponding to the first destination address of the packet to be forwarded.
[0070] In the embodiment of the present application, the firewall device is configured with security policies corresponding to different protected objects. For example, when the protected object is any first virtual machine in the private network, the firewall device sets a first security policy corresponding to the any first virtual machine. Among them, the first security policy can be set according to different protected objects. For example, when the protected objects include first virtual machines a1, a2, and a3 in the private network, the firewall device is configured with a first security policy b1 corresponding to the first virtual machine a1, a first security policy b2 corresponding to the first virtual machine a2, and a first security policy b3 corresponding to the first virtual machine a3.
[0071] In the embodiment of the present application, the firewall device is also configured with default routes corresponding to different protected objects, and the firewall device can send the processed packet to the corresponding protected object through the default route.
[0072] Such as Figure 3As shown: When the protected object is any first virtual machine 10.0.0.3 in a private network, the firewall device is set with a first default route corresponding to the any first virtual machine (i.e., the network address 10.0.0.1 of the first network forwarding device). After the firewall device processes the packet to be forwarded through the first security policy, it will forward the processed packet to the first network forwarding device 10.0.0.1 according to the first default route. The first network forwarding device will send the processed packet to the protected object, i.e., the first virtual machine 10.0.0.3, according to the routing table and the destination address of the processed packet. Its process is: firewall device 10.0.0.2 → first network forwarding device 10.0.0.1 → first virtual machine 10.0.0.3.
[0073] Step S103, when the next-hop device is any second network forwarding device, forward the packet to be forwarded to the second network forwarding device, so that the second network forwarding device sends the packet to be forwarded to the firewall device according to the second routing policy and the second destination address of the packet to be forwarded.
[0074] Specifically, the firewall device processes the packet to be forwarded according to the second security policy corresponding to the second destination address.
[0075] In the embodiment of the present application, the firewall device is configured with security policies corresponding to different protected objects. For example: when the protected object is any second virtual machine in any subnet, the firewall device is set with a second security policy corresponding to the any second virtual machine. Among them, the second security policy can be set according to different protected objects. For example: when the protected objects include second virtual machines c1, c2, and c3, the firewall device is configured with a second security policy d1 corresponding to the second virtual machine c1, a second security policy d2 corresponding to the second virtual machine c2, and a second security policy d3 corresponding to the second virtual machine c3.
[0076] In some specific embodiments, the second network forwarding device is configured with a second routing policy, and the second routing policy includes a second association relationship between the second destination address and the firewall device. The second destination address refers to the network address of any second virtual machine in any subnet. When the second network forwarding device receives a packet, it will determine whether the destination address of the packet is the same as the second destination address in the second routing policy. If the same, it will directly forward the packet to the firewall device, so that the firewall device processes the packet according to the second security policy corresponding to the second destination address.
[0077] In some specific embodiments, the firewall device is also configured with default routes corresponding to different protected objects, and the firewall device can send the processed packet to the corresponding protected object through the default route.
[0078] As shown Figure 4 below: When the protected object is any second virtual machine 192.168.0.3 in any subnet, the firewall device is provided with a second default route corresponding to the any second virtual machine (i.e., the network address 192.168.0.1 of the second network forwarding device). After the firewall device processes the to-be-forwarded packet through the second security policy, it will forward the processed packet to the second network forwarding device 192.168.0.1 according to the second default route. The second network forwarding device will send the processed packet to the protected object, i.e., any second virtual machine 10.0.0.3, according to the routing table and the destination address of the processed packet. The process is: firewall device 192.168.0.2 → second network forwarding device 192.168.0.1 → second virtual machine 192.168.0.3.
[0079] In some specific embodiments, before forwarding the to-be-forwarded packet to the firewall device, it further includes steps S201 - S202:
[0080] Step S201, receiving a connection instruction from the cloud security management platform.
[0081] Specifically, the firewall device includes multiple sub-firewalls, such as Figure 5 vrf-net1, vrf-net2,... in
[0082] More specifically, the connection instruction includes the identifier of the first sub-firewall; the first sub-firewall refers to the sub-firewall in an idle state screened by the cloud security management platform from the multiple sub-firewalls in response to the situation that any first virtual machine is the protected object.
[0083] Step S202, establishing a network connection with the first sub-firewall, so that when the first sub-firewall receives the to-be-forwarded packet from the first network forwarding device, it processes the to-be-forwarded packet according to the first security policy to obtain a first packet.
[0084] Specifically, the first security policy corresponding to the any first virtual machine is pre-configured in the first sub-firewall.
[0085] In steps S201 - S202, when the user adds a new protected object on the cloud security management platform, and the new protected object is any first virtual machine in the private network, the cloud security management platform will screen out the sub-firewall in an idle state from the multiple sub-firewalls as the first sub-firewall, and send the connection instruction with the identifier of the first sub-firewall to the first network forwarding device (such as Figure 6("k1" in the above) to enable the first network forwarding device to establish a network connection with the first sub-firewall according to the connection instruction, so that the first network forwarding device can forward the packet to be forwarded to the first sub-firewall.
[0086] In some specific embodiments, before responding to receiving the packet to be forwarded, the method further includes steps S301 - S302:
[0087] Step S301, receiving a first routing configuration instruction and a second routing configuration instruction from the cloud security management platform.
[0088] Specifically, the first routing configuration instruction is generated when the cloud security management platform determines that the protection object is any one of the first virtual machines; the first routing configuration instruction includes the network address of any one of the first virtual machines and the sub-firewall corresponding to any one of the first virtual machines; the second routing configuration instruction is generated when the cloud security management platform determines that the protection object is any one of the second virtual machines; the second routing configuration instruction includes the network address of any one of the second virtual machines and the network address of the second network forwarding device corresponding to any one of the second virtual machines.
[0089] Step S302, generating the first routing policy for the packet to be forwarded according to the first routing configuration instruction and the second routing configuration instruction.
[0090] In the above steps S301 - S302, according to the first routing configuration instruction, that is, the network address of any one of the first virtual machines and the sub-firewall corresponding to any one of the first virtual machines, the first association relationship in the first routing policy is established. For example, the first virtual machine w1 is associated with the sub-firewall y1, the first virtual machine w2 is associated with the sub-firewall y2, and the first virtual machine wn is associated with the sub-firewall yn. The first network forwarding device can determine the next-hop device (that is, the sub-firewall associated with any one of the first virtual machines) according to the first association relationship and the destination address of the packet to be forwarded (that is, the network address of any one of the first virtual machines), and forward the packet to be forwarded to the next-hop device.
[0091] In the above steps S301 - S302, according to the first routing configuration instruction, that is, the network address of any second virtual machine and the network address of the second network forwarding device corresponding to the any second virtual machine, the second association relationship in the first routing policy is established. For example, the second virtual machine q1 in subnet 1 is associated with the second network forwarding device of subnet 1, and the second virtual machines q2 and q3 in subnet 2 are associated with the second network forwarding device of subnet 2. The first network forwarding device can determine the next-hop device (i.e., the second network forwarding device associated with any second virtual machine) according to the second association relationship and the destination address of the packet to be forwarded (i.e., the network address of any second virtual machine), and forward the packet to be forwarded to the next-hop device.
[0092] In some specific embodiments, the second routing policy is generated by the second network forwarding device according to the third routing configuration instruction sent by the cloud security management platform. The third routing configuration instruction is generated by the cloud security management platform when determining that the protected object is the any second virtual machine; the third routing configuration instruction includes the network address of any second virtual machine in any subnet and the network address of the firewall device.
[0093] In the embodiments of the present application, when the user adds any second virtual machine as a protected object, a third routing configuration instruction including the network address of the any second virtual machine and the network address of the firewall device will be sent to the second network forwarding device of the subnet where the any second virtual machine is located (for example Figure 6 "k2" in), and the second network forwarding device will generate a second routing policy according to the third routing configuration instruction, so that the second network forwarding device can forward the packet to be forwarded with the destination address being the network address of the above any second virtual machine to the firewall device according to the second routing policy.
[0094] In some specific embodiments, the first network forwarding device may also be a physical switch outside the private network.
[0095] As Figure 7 shown: When the physical switch determines that the next-hop device of the packet to be forwarded is the firewall device in the private network, it can send the packet to be forwarded to the firewall device through the virtual switch in the private network, that is: physical switch outside the private network → virtual switch in the private network → firewall device.
[0096] As Figure 8 shown: When the physical switch determines that the next-hop device of the packet to be forwarded is the second network forwarding device of any subnet in the private network, it can send the packet to be forwarded to the second network forwarding device through the virtual switch in the private network, that is: physical switch outside the private network → virtual switch in the private network → second network forwarding device.
[0097] Corresponding to the implementation manner of the above message forwarding method, an embodiment of the present application further provides a message forwarding method, which is applied to a firewall device in a private network. The private network further includes a first network forwarding device and at least one subnet, and each subnet includes a second network forwarding device; the method includes:
[0098] Step S401: After receiving a message to be forwarded from the first network forwarding device, process the message to be forwarded according to a first security policy.
[0099] Wherein, the message to be forwarded is sent by the first network forwarding device when it receives the message to be forwarded and determines that the next-hop device is the firewall device according to the destination address of the message to be forwarded and a first routing policy; the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet.
[0100] Step S402: After receiving a message to be forwarded from any second network forwarding device, process the message to be forwarded according to a second security policy.
[0101] Wherein, the message to be forwarded is sent by any second network forwarding device to the firewall device according to a second routing policy and the second destination address of the message to be forwarded; the second routing policy includes a third association relationship between the second destination address and the firewall device.
[0102] In some specific embodiments, the firewall device includes multiple sub-firewalls, and the method further includes:
[0103] Step S501: Receive a connection instruction from a cloud security management platform.
[0104] Specifically, the connection instruction includes the identifier of any second network forwarding device; any first network forwarding device is determined by the cloud security management platform in response to a situation where any second virtual machine is a protection object.
[0105] Step S502: Screen out a second sub-firewall in an idle state from the multiple sub-firewalls;
[0106] Step S503: Establish a network connection between the second sub-firewall and any second network forwarding device, so that when the second sub-firewall receives the to-be-forwarded packet from any second network forwarding device, it processes the to-be-forwarded packet according to the second security policy to obtain a second packet; the second security policy corresponding to any second virtual machine is pre-configured in the second sub-firewall.
[0107] In the embodiment of the present application, when a user adds any second virtual machine as a protected object in the cloud security management platform, the cloud security management platform will send a connection instruction including the identifier of any second virtual machine (such as Figure 6 "k3" in ) to the firewall device, so that the firewall device, in response to the connection instruction, screens out the second sub-firewall in the idle state from multiple sub-firewalls and establishes a network connection between the second sub-firewall and any second network forwarding device, thereby achieving the purpose of "the second network forwarding device forwards the to-be-forwarded packet with the destination address being the network address of any second virtual machine to the second sub-firewall in the firewall device".
[0108] Corresponding to the implementation manner of the above packet forwarding method, the embodiment of the present application further provides a packet forwarding system, which includes a first network forwarding device, a firewall device and at least one subnet deployed in a private network, and the system further includes a second network forwarding device deployed in each subnet.
[0109] The first network forwarding device is configured to, in response to receiving a to-be-forwarded packet, determine the next-hop device according to the destination address of the to-be-forwarded packet and the first routing policy; when the next-hop device is the firewall device, forward the to-be-forwarded packet to the firewall device; when the next-hop device is any second network forwarding device, forward the to-be-forwarded packet to the second network forwarding device; the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet;
[0110] Any second network forwarding device is configured to send the to-be-forwarded packet to the firewall device according to the second routing policy and the second destination address of the to-be-forwarded packet; the second routing policy includes a third association relationship between the second destination address and the firewall device;
[0111] The firewall device is configured to receive the packet to be forwarded from the first network forwarding device and process the packet to be forwarded according to the first security policy corresponding to the first destination address of the packet to be forwarded; receive the packet to be forwarded from any of the second network forwarding devices and process the packet to be forwarded according to the second security policy corresponding to the second destination address of the packet to be forwarded.
[0112] For the implementation manner of the above packet forwarding method, an embodiment of the present application further provides a packet forwarding system, where the system includes a first network forwarding device, a firewall device, and at least one subnet deployed in a private network, and the system further includes a second network forwarding device deployed in each subnet;
[0113] The first network forwarding device is configured to, in response to receiving a packet to be forwarded, determine the next-hop device according to the destination address of the packet to be forwarded and the first routing policy; when the next-hop device is the firewall device, forward the packet to be forwarded to the firewall device; when the next-hop device is any of the second network forwarding devices, forward the packet to be forwarded to the second network forwarding device; the first routing policy includes a first association relationship between the first destination address and the firewall device, and a second association relationship between the second destination address and the second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet;
[0114] Any of the second network forwarding devices is configured to send the packet to be forwarded to the firewall device according to the second routing policy and the second destination address of the packet to be forwarded; the second routing policy includes a third association relationship between the second destination address and the firewall device;
[0115] The firewall device is configured to receive the packet to be forwarded from the first network forwarding device and process the packet to be forwarded according to the first security policy corresponding to the first destination address of the packet to be forwarded; receive the packet to be forwarded from any of the second network forwarding devices and process the packet to be forwarded according to the second security policy corresponding to the second destination address of the packet to be forwarded.
[0116] For the implementation manner of the above packet forwarding method, an embodiment of the present application further provides a packet forwarding device for executing the packet forwarding method described in any of the above Figures 1 to 8 illustrated embodiments.
[0117] Such as Figure 9As shown, the packet forwarding device is applied to the first network forwarding device in a private network. The private network includes a firewall device and at least one subnet, and each subnet includes a second network forwarding device. The device includes:
[0118] A next-hop device determination module, configured to, in response to receiving a packet to be forwarded, determine the next-hop device according to the destination address of the packet to be forwarded and a first routing policy. The first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device. The first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet.
[0119] A first packet forwarding module, configured to, when the next-hop device is the firewall device, forward the packet to be forwarded to the firewall device, so that the firewall device processes the packet to be forwarded according to a first security policy corresponding to the first destination address of the packet to be forwarded.
[0120] A second packet forwarding module, configured to, when the next-hop device is any second network forwarding device, forward the packet to be forwarded to the second network forwarding device, so that the second network forwarding device sends the packet to be forwarded to the firewall device according to a second routing policy and the second destination address of the packet to be forwarded. The firewall device processes the packet to be forwarded according to a second security policy corresponding to the second destination address. The second routing policy includes a third association relationship between the second destination address and the firewall device.
[0121] Optionally, the private network includes at least one first virtual machine; each subnet includes at least one second virtual machine. The next-hop device determination module is further configured to: if the destination address of the packet to be forwarded is the network address of any first virtual machine, determine the next-hop device as the firewall device; if the destination address of the packet to be forwarded is the network address of any second virtual machine in any subnet, determine the next-hop device as the second network forwarding device of the any subnet.
[0122] Optionally, the firewall device includes a plurality of sub-firewalls; the apparatus further includes: a network connection module, configured to receive a connection instruction from a cloud security management platform before forwarding the packet to be forwarded to the firewall device, where the connection instruction includes an identifier of a first sub-firewall; the first sub-firewall is a sub-firewall in an idle state selected from the plurality of sub-firewalls by the cloud security management platform in response to a case where any first virtual machine is a protection object; establish a network connection with the first sub-firewall, so that when the first sub-firewall receives the packet to be forwarded from the first network forwarding device, process the packet to be forwarded according to the first security policy to obtain a first packet; the first security policy corresponding to the any first virtual machine is pre-configured in the first sub-firewall.
[0123] Optionally, the apparatus further includes: a first routing policy generation module, configured to receive a first routing configuration instruction and a second routing configuration instruction from a cloud security management platform before responding to receiving a packet to be forwarded; the first routing configuration instruction is generated by the cloud security management platform when determining that the protection object is the any first virtual machine; the first routing configuration instruction includes a network address of the any first virtual machine and a sub-firewall corresponding to the any first virtual machine; the second routing configuration instruction is generated by the cloud security management platform when determining that the protection object is the any second virtual machine; the second routing configuration instruction includes a network address of the any second virtual machine and a network address of a second network forwarding device corresponding to the any second virtual machine; generate the first routing policy of the packet to be forwarded according to the first routing configuration instruction and the second routing configuration instruction.
[0124] Optionally, the second routing policy is generated by the second network forwarding device according to a third routing configuration instruction sent by the cloud security management platform, where the third routing configuration instruction is generated by the cloud security management platform when determining that the protection object is the any second virtual machine; the third routing configuration instruction includes a network address of any second virtual machine in any subnet and a network address of the firewall device.
[0125] The packet forwarding apparatus provided in the foregoing embodiments of the present application and the packet forwarding method provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by the application programs stored therein.
[0126] The embodiments of the present application further provide a network forwarding device to execute the foregoing packet forwarding method. Please refer to Figure 10 , which shows a schematic diagram of a network forwarding device provided in some embodiments of the present application. As Figure 10As shown in the figure, the network forwarding device 10 includes: a processor 1000, a memory 1001, a bus 1002, and a communication interface 1003. The processor 1000, the communication interface 1003, and the memory 1001 are connected through the bus 1002. A computer program that can run on the processor 1000 is stored in the memory 1001. When the processor 1000 runs the computer program, it executes the packet forwarding method provided by any of the foregoing Figures 1 to 8 embodiments illustrated in the schematic diagram.
[0127] Among them, the memory 1001 may include a high-speed random access memory (Random Access Memory, RAM), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 1003 (which can be wired or wireless), a communication connection is established between this system network element and at least one other network element, and the Internet, wide area network, local area network, metropolitan area network, etc. can be used.
[0128] The bus 1002 can be an ISA bus, a PCI bus, an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Among them, the memory 1001 is used to store a program. After receiving an execution instruction, the processor 1000 executes the program. The packet forwarding method disclosed in any of the foregoing Figures 1 to 8 embodiments illustrated in the schematic diagram can be applied to the processor 1000 or implemented by the processor 1000.
[0129] The processor 1000 may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 1000 or the instructions in the form of software. The above-mentioned processor 1000 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 1001, and the processor 1000 reads the information in the memory 1001 and combines its hardware to complete the steps of the above method.
[0130] The network forwarding device provided by the embodiments of the present application and the packet forwarding method provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the method adopted, run or implemented by it.
[0131] The embodiments of the present application also provide a computer-readable storage medium corresponding to the packet forwarding method provided by the foregoing embodiments. Please refer to Figure 11 , which shows that the computer-readable storage medium is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it will execute the packet forwarding method provided by any of the foregoing embodiments.
[0132] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here one by one.
[0133] The computer-readable storage medium provided by the above embodiments of the present application and the message forwarding method provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by the application programs stored therein.
[0134] It should be noted that:
[0135] In the specification provided herein, a large number of specific details are set forth. However, it is understood that the embodiments of the present application may be practiced without these specific details. In some instances, well-known structures and technologies are not shown in detail so as not to obscure the understanding of this specification.
[0136] Similarly, it should be understood that, in order to streamline the present application and assist in understanding one or more of the various inventive aspects, in the above description of the exemplary embodiments of the present application, the various features of the present application are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting the following schematic: that the claimed present application requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into the detailed description, with each claim standing on its own as a separate embodiment of the present application.
[0137] In addition, those skilled in the art will appreciate that, although some of the embodiments described herein include certain features included in other embodiments but not others, the combination of features of different embodiments is within the scope of the present application and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.
[0138] The above is only a preferred specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed by the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A message forwarding method, characterized in that The method is applied to a first network forwarding device in a private network, the private network includes a firewall device and at least one subnet, and each subnet includes a second network forwarding device; the method includes: In response to receiving a packet to be forwarded, determining a next-hop device according to the destination address of the packet to be forwarded and a first routing policy; the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet; When the next-hop device is the firewall device, forwarding the packet to be forwarded to the firewall device, so that the firewall device processes the packet to be forwarded according to a first security policy corresponding to the first destination address of the packet to be forwarded; When the next-hop device is any second network forwarding device, forwarding the packet to be forwarded to the second network forwarding device, so that the second network forwarding device sends the packet to be forwarded to the firewall device according to a second routing policy and the second destination address of the packet to be forwarded; the firewall device processes the packet to be forwarded according to a second security policy corresponding to the second destination address; the second routing policy includes a third association relationship between the second destination address and the firewall device.
2. The method according to claim 1, wherein The private network includes at least one first virtual machine; each subnet includes at least one second virtual machine; Determining a next-hop device according to the destination address of the packet to be forwarded and the first routing policy includes: If the destination address of the packet to be forwarded is the network address of any first virtual machine, determining the next-hop device as the firewall device; If the destination address of the packet to be forwarded is the network address of any second virtual machine in any subnet, determining the next-hop device as the second network forwarding device of the any subnet.
3. The method according to claim 2, wherein The firewall device includes multiple sub-firewalls; before forwarding the packet to be forwarded to the firewall device, it further includes: Receiving a connection instruction from a cloud security management platform, where the connection instruction includes an identifier of a first sub-firewall; the first sub-firewall is a sub-firewall in an idle state screened by the cloud security management platform from the multiple sub-firewalls in response to a situation where any first virtual machine is a protection object; Establishing a network connection with the first sub-firewall, so that when the first sub-firewall receives the packet to be forwarded from the first network forwarding device, processing the packet to be forwarded according to the first security policy to obtain a first packet; the first security policy corresponding to the any first virtual machine is pre-configured in the first sub-firewall.
4. The method according to claim 3, wherein Before responding to receiving a packet to be forwarded, the method further includes: Receive a first routing configuration instruction and a second routing configuration instruction from the cloud security management platform; the first routing configuration instruction is generated by the cloud security management platform when determining that the protected object is any one of the first virtual machines; the first routing configuration instruction includes the network address of any one of the first virtual machines and the sub-firewall corresponding to any one of the first virtual machines; the second routing configuration instruction is generated by the cloud security management platform when determining that the protected object is any one of the second virtual machines; the second routing configuration instruction includes the network address of any one of the second virtual machines and the network address of the second network forwarding device corresponding to any one of the second virtual machines; Generate the first routing policy for the to-be-forwarded packet according to the first routing configuration instruction and the second routing configuration instruction.
5. The method according to claim 3 or 4, characterized in that, The second routing policy is generated by the second network forwarding device according to the third routing configuration instruction sent by the cloud security management platform. The third routing configuration instruction is generated by the cloud security management platform when determining that the protected object is any one of the second virtual machines; the third routing configuration instruction includes the network address of any one of the second virtual machines in any subnet and the network address of the firewall device.
6. A message forwarding method, characterized in that, The method is applied to a firewall device in a private network. The private network further includes a first network forwarding device and at least one subnet, and each subnet includes a second network forwarding device; the method includes: After receiving the to-be-forwarded packet from the first network forwarding device, process the to-be-forwarded packet according to the first security policy; the to-be-forwarded packet is sent by the first network forwarding device when, after receiving the to-be-forwarded packet, it determines that the next-hop device is the firewall device according to the destination address of the to-be-forwarded packet and the first routing policy; the first routing policy includes the first association relationship between the first destination address and the firewall device, and the second association relationship between the second destination address and the second network forwarding device; the first destination address refers to the network address of any one of the first virtual machines in the private network, and the second destination address refers to the network address of any one of the second virtual machines in any subnet; After receiving the to-be-forwarded packet from any one of the second network forwarding devices, process the to-be-forwarded packet according to the second security policy; the to-be-forwarded packet is sent by any one of the second network forwarding devices to the firewall device according to the second routing policy and the second destination address of the to-be-forwarded packet; the second routing policy includes the third association relationship between the second destination address and the firewall device.
7. The method according to claim 6, wherein The firewall device includes multiple sub-firewalls, and the method further includes: Receive a connection instruction from the cloud security management platform. The connection instruction includes the identifier of any one of the second network forwarding devices; any one of the first network forwarding devices is determined by the cloud security management platform in response to the situation where any one of the second virtual machines is the protected object; Screen out the second sub-firewall in the idle state from the multiple sub-firewalls; Establish a network connection between the second sub-firewall and any of the second network forwarding devices, so that when the second sub-firewall receives the to-be-forwarded packet from any of the second network forwarding devices, the second sub-firewall processes the to-be-forwarded packet according to the second security policy to obtain a second packet; the second security policy corresponding to any of the second virtual machines is pre-configured in the second sub-firewall.
8. A message forwarding system, characterized in that, The system includes a first network forwarding device, a firewall device deployed in a private network, and at least one subnet, and the system further includes second network forwarding devices deployed in each subnet; The first network forwarding device is configured to, in response to receiving a to-be-forwarded packet, determine a next-hop device according to the destination address of the to-be-forwarded packet and a first routing policy; When the next-hop device is the firewall device, forward the to-be-forwarded packet to the firewall device; When the next-hop device is any of the second network forwarding devices, forward the to-be-forwarded packet to the second network forwarding device; The first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet; Any of the second network forwarding devices is configured to send the to-be-forwarded packet to the firewall device according to a second routing policy and the second destination address of the to-be-forwarded packet; The second routing policy includes a third association relationship between a second destination address and the firewall device; The firewall device is configured to receive the to-be-forwarded packet from the first network forwarding device, and process the to-be-forwarded packet according to a first security policy corresponding to the first destination address of the to-be-forwarded packet; receive the to-be-forwarded packet from any of the second network forwarding devices, and process the to-be-forwarded packet according to a second security policy corresponding to the second destination address of the to-be-forwarded packet.
9. A message forwarding device, characterized in that Applied to a first network forwarding device in a private network, the private network includes a firewall device and at least one subnet, and each subnet includes a second network forwarding device; the apparatus includes: A next-hop device determination module, configured to, in response to receiving a to-be-forwarded packet, determine a next-hop device according to the destination address of the to-be-forwarded packet and a first routing policy; the first routing policy includes a first association relationship between a first destination address and the firewall device, and a second association relationship between a second destination address and a second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet; A first packet forwarding module, configured to, when the next-hop device is the firewall device, forward the to-be-forwarded packet to the firewall device, so that the firewall device processes the to-be-forwarded packet according to a first security policy corresponding to the first destination address of the to-be-forwarded packet; The second message forwarding module is configured to forward the message to be forwarded to the second network forwarding device when the next-hop device is any second network forwarding device, so that the second network forwarding device sends the message to be forwarded to the firewall device according to the second routing policy and the second destination address of the message to be forwarded; the firewall device processes the message to be forwarded according to the second security policy corresponding to the second destination address; the second routing policy includes a third association relationship between the second destination address and the firewall device.
10. A message forwarding device, characterized in that, A firewall device applied to a private network, the private network further including a first network forwarding device and at least one subnet, each subnet including a second network forwarding device; the apparatus includes: The first message processing module is configured to process the message to be forwarded according to the first security policy after receiving the message to be forwarded from the first network forwarding device; the message to be forwarded is sent by the first network forwarding device when it determines that the next-hop device is the firewall device according to the destination address of the message to be forwarded and the first routing policy; the first routing policy includes a first association relationship between the first destination address and the firewall device, and a second association relationship between the second destination address and the second network forwarding device; the first destination address refers to the network address of any first virtual machine in the private network, and the second destination address refers to the network address of any second virtual machine in any subnet; The second message processing module is configured to process the message to be forwarded according to the second security policy after receiving the message to be forwarded from any second network forwarding device; the message to be forwarded is sent to the firewall device by any second network forwarding device according to the second routing policy and the second destination address of the message to be forwarded; the second routing policy includes a third association relationship between the second destination address and the firewall device.
11. A network forwarding device, characterized in that, Comprising: A memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the message forwarding method according to any one of claims 1 to 7.