Network message packet capturing method, system and equipment of network equipment and medium

By setting up NAT matching identifiers and auxiliary message identification areas in network devices, the problem that existing tools are difficult to capture messages before and after NAT conversion is solved, and complete message capture is achieved in the NAT environment, improving the troubleshooting efficiency of network devices.

CN120378144APending Publication Date: 2025-07-25CHENGDU DBAPP SECURITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510452118.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the case of NAT conversion, it is difficult for existing network packet capture tools to capture both pre-conversion and converted network packets at the same time. Especially when DNAT policies are configured, it is difficult for conventional tools to capture converted packets.

Method used

By setting a NAT matching identifier in the network device, adding a secondary message identification area, and directly crawling or filtering network messages based on the NAT matching identifier of the message, packet capture in the sending and reply stages can be achieved.

Benefits of technology

It realizes that without additional configuration, it can capture messages processed by NAT network conversion at one time, improving the efficiency and accuracy of network problems of network equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378144A_ABST
    Figure CN120378144A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, in particular to a network message packet capturing method, system and equipment of network equipment and a medium. The method comprises the following steps: firstly, setting an NAT matching identifier according to packet capture filtering parameters; secondly, filling a buffer area with the network message, and adding an auxiliary message identification area; then checking whether an NAT matching identifier exists in an auxiliary message identifier area of the network message, if so, directly capturing the network message, and if not, filtering according to a packet capturing filtering parameter; and finally, judging whether the to-be-replied network message has the NAT matching identifier or not, if so, directly capturing the to-be-replied network message, otherwise, filtering according to the packet capturing filtering parameter, and completing packet capturing in the sending stage and the replying stage. Extra configuration is not needed, and the message subjected to NAT network conversion processing is captured on the network equipment; messages containing NAT tracking are captured at a time, and the troubleshooting efficiency of network problems of the network equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method, system, device, and medium for capturing network packets of a network device. Background Art

[0002] For network devices, the control plane and the forwarding plane are often separated. An administrator issues configurations and rules in the control plane. After combination and arrangement, the control plane issues the administrator's configurations to the forwarding plane through a private protocol. After receiving the control signal, the forwarding plane converts it into actual actions for data forwarding, processing, and filtering. The same is true for network packet capture.

[0003] Network packet capture is the most commonly used means for network administrators to handle network devices in daily work. If a network connection failure occurs during the implementation of network devices or daily operation and maintenance, and the cause cannot be intuitively inferred from the interface of the network device, a packet capture command is often needed to assist in judgment. For layer-2 devices, the actions of network devices are often limited, and traditional packet capture tools can filter the expected network packets relatively smoothly; however, for layer-3 devices or network devices above layer-3, especially gateway-type devices, due to the existence of technologies such as NAT, it is very difficult for traditional packet capture filtering methods to filter both the network packets before and after conversion at the same time.

[0004] Packet capture is the most commonly used means in the routine troubleshooting and fault troubleshooting of network devices. The principle of conventional network packet capture tools is to filter out the network packets to be captured by matching the issued network packet matching conditions at the packet receiving and sending nodes.

[0005] However, there are three problems that are difficult to solve with conventional packet capture tools: 1. If packet capture conditions are configured, it is often impossible to filter the packets sent and replied by the network device at one time; 2. If the network device is configured with network conversion strategies such as NAT, conventional packet capture methods cannot capture both the network packets before and after conversion at the same time; 3. Especially when a DNAT strategy is configured, it is sometimes very difficult for conventional packet capture tools to capture the packets after conversion. Summary of the Invention

[0006] In view of the problem that the existing packet capture method cannot hit the packet capture rule due to NAT, the present invention provides a network packet capture method, system, device and medium for network devices; first, set the NAT matching identifier according to the packet capture filtering parameters; secondly, fill the network packet into the buffer and add an auxiliary packet identifier area; then check whether the NAT matching identifier exists in the auxiliary packet identifier area of the network packet, if it exists, directly capture the network packet, otherwise filter according to the packet capture filtering parameters; finally, judge whether the NAT matching identifier exists in the network packet to be replied, if it exists, directly capture the network packet to be replied, otherwise filter according to the packet capture filtering parameters, and complete the packet capture in the sending stage and the reply stage; no additional configuration is required, and the packet after NAT network conversion processing can be captured on the network device.

[0007] The specific implementation content of the present invention is as follows: A network packet capture method for a network device, first set the NAT matching identifier according to the packet capture filtering parameters set in the network device; secondly, fill the network packet obtained from the network card into the buffer and add an auxiliary packet identifier area; then check whether the NAT matching identifier exists in the auxiliary packet identifier area of the network packet, if it exists, directly capture the network packet, otherwise filter according to the packet capture filtering parameters, and complete the packet capture in the sending stage; finally, judge whether the NAT matching identifier exists in the network packet to be replied obtained from the network device, if it exists, directly capture the network packet to be replied, otherwise filter according to the packet capture filtering parameters, and complete the packet capture in the reply stage.

[0008] To better implement the present invention, further, the network packet capture method of the network device specifically includes the following steps: Step S1: Set the packet capture filtering parameters in the network device and calibrate the NAT matching identifier; Step S2: In the network packet receiving stage, fill the network packet received from the network card into the buffer, and add a preposed auxiliary packet identifier area to the buffer structure of the network packet; Step S3: Check whether the NAT matching identifier exists in the auxiliary packet identifier area of the processed network packet. If it exists, directly capture the network packet and send it to the sending queue. Otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the sending stage; Step S4: According to the layer 2 header information and layer 3 header information of the network packet to be replied obtained from the network device, judge whether the NAT matching identifier exists. If it exists, directly capture the network packet to be replied. Otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the reply stage.

[0009] To better implement the present invention, further, the step S3 specifically includes the following steps: Step S31: Filter the network packet according to the packet capture filtering parameters; Step S32: Add a flag bit in the auxiliary message identification area according to the NAT matching identification, and capture it into the message storage queue; Step S33: In the sending stage, check whether the NAT matching identification exists in the auxiliary message identification area of the network message. If it exists, directly capture the network message and send it to the sending queue; otherwise, filter the network message according to the packet capture filtering parameters.

[0010] To better implement the present invention, further, step S3 further includes: Step S34: Calculate the five-tuple information according to the three-layer header information and the three-layer header information of the captured network message, and write it into the five-tuple table.

[0011] To better implement the present invention, further, the size of the flag bit added in the auxiliary message identification area in step S32 is 1 bit.

[0012] To better implement the present invention, further, step S4 specifically includes the following steps: Step S41: Extract the two-layer header information and the three-layer header information of the captured network message, check whether the five-tuple is in the NAT five-tuple table. If it is in the NAT five-tuple table, directly capture it and mark the NAT matching identification; otherwise, fill the network message to be replied into the buffer, add a preposed auxiliary message identification area in the buffer structure of the network message to be replied, and store it in the message storage queue; Step S42: Save the network messages in the message storage queue in chronological order, and save them to the hard disk medium after the packet capture action is completed.

[0013] To better implement the present invention, further, the processed network messages in step S3 include the network messages after session establishment, the network messages after NAT conversion, the network messages after route lookup, and the network messages after security check.

[0014] Based on the above-mentioned network message packet capture method of the network device, to better implement the present invention, further, a network message packet capture system of the network device is proposed, which is used to execute the above-mentioned network message packet capture method of the network device; it includes an initial setting unit, an identification unit, a sending and capturing unit, and a reply and capturing unit; The initial setting unit is used to set the NAT matching identification according to the packet capture filtering parameters set in the network device; The identification unit is used to fill the network message obtained from the network card into the buffer and add an auxiliary message identification area; The sending and capturing unit is used to check whether the NAT matching identification exists in the auxiliary message identification area of the network message. If it exists, directly capture the network message, otherwise filter it according to the packet capture filtering parameters to complete the packet capture in the sending stage; The reply packet capture unit is used to determine whether a NAT matching identifier exists in the network packet to be replied obtained from the network device. If it exists, the network packet to be replied is directly captured; otherwise, it is filtered according to the packet capture filtering parameters to complete the packet capture in the reply stage.

[0015] Based on the above-mentioned network packet capture method for network devices, in order to better implement the present invention, further, an electronic device is proposed, including a memory and a processor; a computer program is stored on the memory; when the computer program is executed on the processor, the above-mentioned network packet capture method for network devices is implemented.

[0016] Based on the above-mentioned network packet capture method for network devices, in order to better implement the present invention, further, a computer-readable storage medium is proposed, and a computer instruction is stored on the computer-readable storage medium; when the computer instruction is executed on the above-mentioned electronic device, the above-mentioned network packet capture method for network devices is implemented.

[0017] The present invention has the following beneficial effects: (1) By adding an identifier in the packet auxiliary identifier area, the present invention captures the packets containing NAT tracking at one time, improving the troubleshooting efficiency of network problems in network devices.

[0018] (2) The present invention does not require additional configuration to capture the packets that have undergone NAT network conversion processing on the network device; regardless of any conversion of the packets on the network device, the packets sent and replied by the network device can be captured simultaneously; the packets that have undergone network conversion can be easily captured to obtain a more complex and reliable packet analysis result at one time. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 It is a schematic diagram of the packet capture process provided by the present invention.

[0020] Figure 2 It is a schematic diagram of the data structure provided by the present invention.

[0021] Figure 3 It is a schematic diagram of the RX packet capture process provided by the present invention.

[0022] Figure 4 It is a schematic diagram of the TX packet capture process provided by the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0023] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will describe the technical solutions in the embodiments of the present invention clearly and completely in conjunction with the accompanying drawings in the embodiments of the present invention. It should be understood that the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments, and should not be regarded as a limitation of the protection scope. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work belong to the scope of protection of the present invention.

[0024] In the description of the present invention, it should be noted that unless otherwise clearly defined and limited, the terms "set", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can also be directly connected, or indirectly connected through an intermediate medium, and can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0025] The professional terms and English explanations involved in this embodiment are as follows: 1. NAT (Network Address Translation); NAT is a network address translation technology used to convert private IP addresses into public IP addresses in network devices (such as routers), thereby allowing multiple devices to access the external network through a single public IP address. NAT improves network security, reduces the need for public network IP addresses, and at the same time allows devices in the internal network to hide their real IP addresses.

[0026] 2. RX (Receive); RX refers to the process of a network device or interface receiving data, usually used to describe the received data packets or signals. The RX rate is usually used to measure the data rate received by the device from the network and is one of the important indicators of network performance.

[0027] 3. TX (Transmit); TX refers to the process of a network device or interface sending data, usually used to describe the sent data packets or signals. The TX rate represents the rate at which the device transmits data to the network and is usually used together with RX to monitor and analyze network traffic.

[0028] 4. Network Packet; A network packet is the basic data unit in network communication, containing the data information that needs to be transmitted over the network. Each network packet consists of a header and a payload. The header contains control information such as the destination address and source address, and the payload is the actual data being transmitted. Network packets are transmitted through network protocols (such as TCP / IP).

[0029] Embodiment 1: This embodiment proposes a method for capturing network packets of a network device. First, set the NAT matching identifier according to the packet capture filtering parameters set in the network device. Secondly, fill the network packets obtained from the network card into the buffer and add an auxiliary packet identifier area. Then, check whether the NAT matching identifier exists in the auxiliary packet identifier area of the network packet. If it exists, directly capture the network packet; otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the sending stage. Finally, judge whether the NAT matching identifier exists in the network packet to be replied obtained from the network device. If it exists, directly capture the network packet to be replied; otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the reply stage.

[0030] Working principle: In this embodiment, by adding the NAT matching identifier to the packet auxiliary identifier area, the packets containing NAT tracking are captured at one time, which extends the packet capture tool to a certain extent and improves the troubleshooting efficiency of network problems of the network device.

[0031] Embodiment 2: This embodiment is described in the form of steps based on the above Embodiment 1.

[0032] The method for capturing network packets of the network device specifically includes the following steps: Step S1: Set the packet capture filtering parameters in the network device and calibrate the NAT matching identifier.

[0033] Step S2: In the network packet receiving stage, fill the network packets received from the network card into the buffer and add a preposed auxiliary packet identifier area to the buffer structure of the network packet.

[0034] Step S3: Check whether the NAT matching identifier exists in the auxiliary packet identifier area of the processed network packet. If it exists, directly capture the network packet and send it to the sending queue; otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the sending stage.

[0035] The processed network packets in Step S3 include the network packets after session establishment, the network packets after NAT conversion, the network packets after route lookup, and the network packets after security check.

[0036] The specific steps of Step S3 include the following steps: Step S31: Filter the network packets according to the packet capture filtering parameters. Step S32: Add a flag bit in the auxiliary message identification area according to the NAT matching identification, and capture it into the message storage queue; The size of the flag bit added in the auxiliary message identification area in Step S32 is 1 bit.

[0037] Step S33: In the sending stage, check whether the NAT matching identification exists in the auxiliary message identification area of the network message. If it exists, directly capture the network message and send it to the sending queue; otherwise, filter the network message according to the packet capture filtering parameters.

[0038] Step S34: Calculate the five-tuple information according to the three-layer header information and the three-layer header information of the captured network message, and write it into the five-tuple table.

[0039] Step S4: According to the two-layer header information and the three-layer header information of the network message to be replied obtained from the network device, determine whether the NAT matching identification exists. If it exists, directly capture the network message to be replied; otherwise, filter it according to the packet capture filtering parameters to complete the packet capture in the reply stage.

[0040] The specific steps of Step S4 are as follows: Step S41: Extract the two-layer header information and the three-layer header information of the captured network message, check whether the five-tuple is in the NAT five-tuple table. If it is in the NAT five-tuple table, directly capture it and mark the NAT matching identification; otherwise, fill the network message to be replied into the buffer, add a preposed auxiliary message identification area in the buffer structure of the network message to be replied, and store it in the message storage queue; Step S42: Save the network messages in the message storage queue in chronological order, and save them to the hard disk medium after completing the packet capture operation.

[0041] Working principle: In this embodiment, innovatively, in the message sending and receiving stage, by adding an auxiliary identification of the message, it is marked that the message has been matched. At the same time, a NAT five-tuple table is established to record the message information of the forwarded messages, so that it can be captured again when the message is replied. Through the message auxiliary identification and the NAT five-tuple table, the above problems encountered by conventional network packet capture tools are effectively solved.

[0042] Other parts of this embodiment are the same as those of the above Embodiment 1, so they will not be described in detail here.

[0043] Embodiment 3: This embodiment is based on any one of the above Embodiments 1-2, as Figure 1 、 Figure 2 、 Figure 3 、 Figure 4 shown, taking the network message related to NAT as an example for illustration, and specifically includes the following steps.

[0044] Step S1: Send and receive packet capture filtering parameters, and mark that "NAT tracking" needs to be performed. At the data structure level, in this embodiment, some auxiliary fields "NAT matching identifier" are innovatively added to the buffer structure of the packet. This field is located in the front part of the packet, and the meaning of this field is that packet capture needs to perform "NAT tracking". When this identifier exists, the packet capture of the network device will use a separate processing logic to achieve an effect that cannot be achieved by traditional packet capture tools and capture packets that cannot be directly captured by traditional packet capture tools.

[0045] Step S2: After the network packet is received by the network card, it will be filled into the buffer in the RX stage, and the auxiliary packet identifier area will be automatically added in front of the packet in the buffer. When the packet officially enters the first stage of the packet processing of the network device, it will first pass through the packet capture module for processing; the packet capture module will first filter according to the sent packet capture filtering parameters. Since it is marked that "NAT tracking" needs to be performed, after the packet is filtered, a bit identifier will be added to the auxiliary packet identifier area to indicate that the packet "is tracked by NAT"; at the same time, the packet will be captured by the packet capture module into the packet storage queue. Subsequently, the packet will officially enter various packet processing stages of the network device, including but not limited to session construction, NAT conversion, route lookup, security check, etc.

[0046] Step S3: After the packet processing is completed and ready to be sent to TX, the network packet needs to be filtered and captured at this stage; since the administrator has marked that "NAT tracking" needs to be performed, so here first check whether the auxiliary packet identifier area of the sent packet marks that the packet "is tracked by NAT". If there is this identifier, directly capture the packet, otherwise, filter according to the filtering rules sent by the administrator.

[0047] If the packet is captured, since it is marked that "NAT tracking" needs to be performed, it is necessary to calculate the five-tuple information of the possible replied packet according to the layer 2 and layer 3 header information of the packet and write it into the NAT five-tuple table for subsequent use. Subsequently, the packet will be sent into the TX queue and sent away by the network card; since there is generally a replied packet for the network packet, when the replied packet returns to this network device, after receiving the packet in RX, it is necessary to extract the layer 2 and layer 3 header information of the packet and check whether the five-tuple is in the NAT five-tuple table. If it is in the table, directly capture it and mark it as "tracked by NAT", otherwise, process it according to the first stage of the packet processing.

[0048] Step S4: Similar to Step S2 - Step S3, the packet may be captured again in the TX stage. After the packet capture is completed, the packets in the packet storage queue are saved to the memory in chronological order, and are saved on the hard disk medium after the packet capture action is completed.

[0049] Working principle: Through the above four steps, if the packet capture filtering conditions can be hit and NAT tracking is turned on, the relevant messages will be captured in four copies, namely RX and TX in the sending phase, and RX and TX in the reply phase; in this way, since not only the packet capture rules are filtered in the TX phase, but also the relevant identifiers are checked, the problem of not being able to hit the packet capture rules due to NAT is solved very well; at the same time, the reply message after NAT is also identified and captured in the RX phase, which provides a more complete processing process on this network device during the entire message cycle.

[0050] This embodiment improves the traditional network packet capture tool. When conducting network troubleshooting, due to the existence of other network conversion strategies such as NAT strategy, it is often impossible to capture the network packets before and after the conversion at one time. After using the method of this embodiment, these packets that have undergone network conversion can be easily captured, so as to obtain more complex and reliable packet analysis results in one go.

[0051] This embodiment can capture messages that have been processed by network conversions such as NAT on the network device without any additional configuration. Regardless of any conversion of the messages on the network device, the messages sent and replied by the network device can be captured at the same time.

[0052] The other parts of this embodiment are the same as any one of the above-mentioned embodiments 1-2, so they will not be repeated here.

[0053] Embodiment 4: Based on any one of the above-mentioned embodiments 1 to 3, this embodiment proposes a network packet capture system for a network device, which is used to execute the above-mentioned network packet capture method for a network device; it includes an initial setting unit, an identification unit, a sending packet capture unit, and a reply packet capture unit; The initial setting unit is used to set the NAT matching flag according to the packet capture filtering parameters set in the network device; The identification unit is used to fill the network message obtained from the network card into the buffer and add an auxiliary message identification area; The sending packet capture unit is used to check whether there is a NAT matching mark in the auxiliary message identification area of the network message, and if so, directly capture the network message, otherwise filter according to the packet capture filtering parameter to complete the packet capture in the sending stage; The reply packet capture unit is used to determine whether the network message to be replied obtained from the network device has a NAT matching identifier. If so, the network message to be replied is directly captured. Otherwise, it is filtered according to the packet capture filtering parameters to complete the packet capture in the reply stage.

[0054] This embodiment also provides an electronic device, including a memory and a processor; a computer program is stored on the memory; when the computer program is executed on the processor, the network packet capturing method of the above-mentioned network device is implemented.

[0055] This embodiment also provides a computer-readable storage medium, on which a computer instruction is stored; when the computer instruction is executed on the above-mentioned electronic device, the network packet capturing method of the above-mentioned network device is implemented.

[0056] Other parts of this embodiment are the same as any one of the above-mentioned Embodiment 1 - Embodiment 3, so details are not described herein again.

[0057] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Any simple modification or equivalent change made to the above embodiments based on the technical essence of the present invention shall fall within the protection scope of the present invention.

Claims

1. A method for capturing network packets of a network device, characterized in that, First, set the NAT matching identifier according to the packet capture filtering parameters set in the network device; second, fill the network packets obtained from the network card into the buffer and add an auxiliary packet identifier area; then check whether the NAT matching identifier exists in the auxiliary packet identifier area of the network packet. If it exists, directly capture the network packet. Otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the sending stage; finally, judge whether the NAT matching identifier exists in the network packet to be replied obtained from the network device. If it exists, directly capture the network packet to be replied. Otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the reply stage.

2. The network packet capturing method of a network device according to claim 1, wherein The method for capturing network packets of the network device specifically includes the following steps: Step S1: Set the packet capture filtering parameters in the network device and calibrate the NAT matching identifier; Step S2: In the network packet receiving stage, fill the network packets received from the network card into the buffer, and add a preposed auxiliary packet identifier area to the buffer structure of the network packet; Step S3: Check whether the NAT matching identifier exists in the auxiliary packet identifier area of the processed network packet. If it exists, directly capture the network packet and send it to the sending queue. Otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the sending stage; Step S4: According to the layer 2 header information and layer 3 header information of the network packet to be replied obtained from the network device, judge whether the NAT matching identifier exists. If it exists, directly capture the network packet to be replied. Otherwise, filter according to the packet capture filtering parameters to complete the packet capture in the reply stage.

3. The network packet capture method of a network device according to claim 2, characterized in that, The specific steps of step S3 include the following steps: Step S31: Filter the network packet according to the packet capture filtering parameters; Step S32: According to the NAT matching identifier, add a flag bit to the auxiliary packet identifier area and capture it into the packet storage queue; Step S33: In the sending stage, check whether the NAT matching identifier exists in the auxiliary packet identifier area of the network packet. If it exists, directly capture the network packet and send it to the sending queue; otherwise, filter the network packet according to the packet capture filtering parameters.

4. The network packet capturing method for a network device according to claim 3, characterized in that Step S3 also includes: Step S34: Calculate the five-tuple information according to the layer 3 header information and layer 3 header information of the captured network packet and write it into the five-tuple table.

5. The network packet capture method of a network device according to claim 3, characterized in that, The size of the flag bit added to the auxiliary packet identifier area in step S32 is 1 bit.

6. A method for capturing network packets of a network device according to claim 4, characterized in that, The specific steps of step S4 include the following steps: Step S41: Extract the layer 2 header information and layer 3 header information of the captured network packet, check whether the five-tuple is in the NAT five-tuple table. If it is in the NAT five-tuple table, directly capture it and calibrate the NAT matching identifier; otherwise, fill the network packet to be replied into the buffer, add a preposed auxiliary packet identifier area to the buffer structure of the network packet to be replied, and store it in the packet storage queue; Step S42: Save the network packets in the packet storage queue in chronological order and save them to the hard disk medium after completing the packet capture action.

7. A method for capturing network packets of a network device according to claim 2, characterized in that, The processed network packets in step S3 include network packets after session establishment, network packets after NAT conversion, network packets after route lookup, and network packets after security check.

8. A network packet capture system for a network device, which is used to execute the network packet capture method for the network device as described in claim 1; characterized in that, It includes an initial setting unit, an identification unit, a sending packet capture unit, and a reply packet capture unit; The initial setting unit is configured to set a NAT matching identifier according to the packet capture filtering parameters set in the network device; The identification unit is configured to fill the network packets obtained from the network card into a buffer and add an auxiliary packet identification area; The sending packet capture unit is configured to check whether a NAT matching identifier exists in the auxiliary packet identification area of the network packet. If it exists, the network packet is directly captured; otherwise, it is filtered according to the packet capture filtering parameters to complete the packet capture in the sending stage; The reply packet capture unit is configured to determine whether a NAT matching identifier exists in the network packet to be replied obtained from the network device. If it exists, the network packet to be replied is directly captured; otherwise, it is filtered according to the packet capture filtering parameters to complete the packet capture in the reply stage.

9. An electronic device, characterized in that, It includes a memory and a processor; a computer program is stored on the memory; when the computer program is executed on the processor, the network packet capture method of the network device according to any one of claims 1-7 is implemented.

10. A computer-readable storage medium, characterized in that, A computer instruction is stored on the computer-readable storage medium; when the computer instruction is executed on the electronic device according to claim 9, the network packet capture method of the network device according to any one of claims 1-7 is implemented.