Cloud gateway access method and device, equipment, storage medium and program product
By adjusting the NAT-MSS value in the cloud gateway and determining the ideal MSS value based on the fragment size of the fragmented packet record, the problem of fragment loss of VxLANv4 packets in the public network is solved, and efficient and reliable transmission from the internal network to the public network is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA MOBILE GRP GUANGDONG CO LTD
- Filing Date
- 2025-12-18
- Publication Date
- 2026-04-17
AI Technical Summary
In existing technologies, optical network units have low network performance, and VxLANv4 packets, which are based on UDP, lack the ability to fragment, reassemble, and retransmit lost packets, resulting in fragment loss in intermediate devices and making inner-layer reliable transmission unreliable.
By obtaining the fragment size record of fragmented packets, the ideal MSS value is determined, and the NAT-MSS value is adjusted in the cloud gateway to ensure that packets are not fragmented, thereby achieving efficient forwarding from the intranet to the public network.
It improves the reliability and efficiency of network transmission, balances transmission efficiency with network compatibility, and avoids packet fragmentation on the public network.
Smart Images

Figure CN121887771A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network technology, and in particular to a method, apparatus, device, storage medium, and program product for cloud gateway access. Background Technology
[0002] In current technology, the WAN port of the Optical Network Unit (ONU) first obtains an internet IP address from the Broadband Remote Access Server (BRAS) via Point-to-Point Protocol over Ethernet (PPPoE). Based on the ONU's IPv4 internet address and the cloud gateway's public IP address, a scalable virtual local area network (VxLANV4) based on the IPv4 network is established. Finally, the home terminal's packets are encapsulated in a Layer 2 tunnel, transparently transmitted through the access network, directly connected to the cloud gateway, and an IP address is allocated from the cloud gateway. Finally, the home terminal performs Network Address Translation (NAT) through the cloud gateway's public port to offload traffic to the public Internet.
[0003] However, the existing technology has low network performance. VxLANv4 packets are implemented based on the User Datagram Protocol (UDP), which does not have the ability to reassemble and retransmit fragmented packets. It can only reassemble fragmented packets based on unreliable IP. In particular, the loss of fragments in intermediate devices makes some of the original reliable transmissions unreliable. Summary of the Invention
[0004] To address the aforementioned technical issues, this disclosure provides a method, apparatus, device, storage medium, and program product for cloud gateway access, achieving efficient forwarding from the intranet to the public network.
[0005] A first aspect of this disclosure provides a method for cloud gateway access, applied to a cloud gateway, the method comprising: Obtain a list of fragments based on the fragment size record of the fragmented packet; The ideal MSS value is determined based on the minimum value in the fragment list; If the ideal MSS value is less than the currently set NAT-MSS value, then the NAT-MSS value is reset so that the ideal MSS value is not less than the NAT-MSS value.
[0006] A second aspect of this disclosure provides a cloud gateway access device, applied to a cloud gateway, the device comprising: The list module is configured to obtain a list of fragments based on the fragment size records of the fragmented packets; The calculation module is configured to determine the ideal MSS value based on the minimum value in the sharding list; The reset module is configured to reset the NAT-MSS value when the ideal MSS value is less than the currently set NAT-MSS value, so that the ideal MSS value is not less than the NAT-MSS value.
[0007] A third aspect of this disclosure provides an electronic device, including: At least one processor; Memory for storing the at least one processor-executable instruction; The at least one processor is used to execute the instructions to implement the above-described method.
[0008] A fourth aspect of this disclosure provides a computer-readable storage medium that, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform the methods described above.
[0009] A fifth aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the cloud gateway access method described above.
[0010] The at least one technical solution adopted in this disclosure can achieve the following beneficial effects: This disclosure calculates the ideal MSS value of the intranet transmission path by analyzing the actual fragment size, and then compares it with the current NAT-MSS, adjusting the NAT-MSS value as needed to ensure that packets are not fragmented in the public network. Ultimately, it achieves efficient forwarding from the intranet to the public network, balancing transmission efficiency and network compatibility. Attached Figure Description
[0011] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.
[0012] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1This is a schematic flowchart of a cloud gateway access method provided in an embodiment of the present disclosure; Figure 2 This is a schematic diagram of the network framework for a cloud gateway access method provided in an embodiment of the present disclosure; Figure 3 A flowchart illustrating another method for cloud gateway access provided in this disclosure embodiment; Figure 4 A schematic diagram of the structure of a device for cloud gateway access applied to a cloud gateway, provided in an embodiment of this disclosure; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure; Figure 6 This is a schematic diagram of the structure of an exemplary computer system provided in an embodiment of the present disclosure. Detailed Implementation
[0014] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0015] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.
[0016] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0017] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0018] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0019] Before explaining this disclosure, the terms used in this disclosure will be explained for ease of understanding.
[0020] PPPoE: PPPoE is short for Point-to-Point Protocol Over Ethernet. It is a network tunneling protocol that encapsulates the Point-to-Point Protocol (PPP) within the Ethernet framework.
[0021] IP: IP is short for Internet Protocol, which is one of the core protocols of the TCP / IP protocol suite and is used to enable communication and data transmission between hosts on the Internet.
[0022] IPv4 addresses: IPv4 addresses are 32 bits long and are divided into five classes: A, B, C, D, and E. Class A, B, and C addresses are used to identify networks of different sizes, Class D addresses are mainly used for multicast communication, and Class E addresses are reserved.
[0023] IPv6 Address: IPv6 is a new generation Internet protocol developed to solve the IPv4 address shortage problem. The address length is 128 bits and it uses colon hexadecimal notation. Its address space is greatly increased compared to IPv4.
[0024] PPPoEv6: PPPoEv6 refers to a technology that combines PPPoE with IPv6 over Ethernet. It allows users to dial into a network via PPPoE and assigns IPv6 addresses to terminals.
[0025] DHCPv6: DHCPv6 (Dynamic Host Configuration Protocol for IPv6) is a dynamic host configuration protocol designed specifically for IPv6 networks. It is used to automatically assign IPv6 addresses, prefixes, and other network configuration parameters (such as DNS server addresses). It is an extended version of the DHCP protocol in IPv4, addressing the needs of address allocation and management in IPv6 networks.
[0026] TCP (Transmission Control Protocol) is a connection-oriented, reliable, byte-stream-based transport layer communication protocol defined by IETF RFC 793. TCP is designed to adapt to layered protocol hierarchies that support multiple network applications. In interconnected computer networks, pairs of application processes can rely on TCP to provide reliable communication services for transmitting byte streams. TCP supports bidirectional data streaming, but applications can also send data unidirectionally. Between hosts, TCP uses port numbers to identify application services and can multiplex data streams.
[0027] NAT: Network Address Translation (NAT) is a technology that translates an IP address in the header of an IP datagram into another IP address.
[0028] SNAT: Source Network Address Translation (SNAT) is a typical application of NAT technology. It is mainly used to translate the source IP address of a data packet into another IP address, enabling multiple devices to access the Internet through the same public IP address.
[0029] The following is combined Figures 1-6 This disclosure describes the cloud gateway access method, apparatus, device, storage medium, and program product provided in the embodiments of this disclosure.
[0030] Figure 1 This is a schematic flowchart of a cloud gateway access method provided in an embodiment of this disclosure, as shown below. Figure 1 As shown, a method for cloud gateway access, applied to a cloud gateway, includes: S101. Obtain a list of fragments based on the fragment size records of the fragmented packets; This embodiment establishes a tunnel based on VxLANv6. Based on the characteristic of IPv6 that only the sending and receiving ends can fragment and reassemble, and combined with the fragmentation extension header of the cloud gateway based on IPv6 packets, the fragmentation size of each fragmented packet is recorded as a fragmentation list.
[0031] S102. Determine the ideal MSS value based on the minimum value in the fragment list; MSS (Maximum Segment Size) is a key parameter in TCP that defines the maximum length of the data portion (excluding the TCP and IP headers) in a TCP segment. Its core function is to prevent TCP segments from being fragmented during transmission, thereby improving network transmission efficiency and reliability.
[0032] The cloud gateway obtains the minimum value of the shard list, which represents the actual available MTU in the path and is converted into the ideal MSS value.
[0033] Understandably, the current MSS value is derived from the fragment size of the already transmitted fragmented packets. This MSS value is considered ideal because it can prevent TCP packets from being fragmented during intranet transmission.
[0034] MTU (Maximum Transmission Unit) refers to the maximum size of a data packet that the data link layer allows to be transmitted, measured in bytes. Data packets exceeding the MTU will be fragmented or dropped, affecting network transmission efficiency.
[0035] S103. When the ideal MSS value is less than the currently set NAT-MSS value, the NAT-MSS value is reset so that the ideal MSS value is not less than the NAT-MSS value.
[0036] NAT-MSS is the "maximum TCP segment size" that a NAT device pre-configures or dynamically calculates based on the MTU difference between the networks on either side (e.g., internal network MTU = 1500 bytes, public network MTU = 1492 bytes). When a TCP packet passes through the NAT device, the NAT checks and modifies the negotiated MSS value in the packet to ensure it does not exceed NAT-MSS, thus preventing fragmentation during subsequent transmission over the public network.
[0037] If the calculated ideal MSS value is less than the currently configured NAT-MSS value, it means that the previously configured NAT-MSS value cannot ensure that the packet does not exceed the public network MTU, and the packet is at risk of being fragmented in the public network. Therefore, it is necessary to modify the currently configured NAT-MSS value, that is, to reduce the NAT-MSS value so that the ideal MSS value is not less than the NAT-MSS value.
[0038] This embodiment calculates the ideal MSS value for the intranet transmission path by analyzing the actual fragment size, and then compares it with the currently configured NAT-MSS. The NAT-MSS value is adjusted as needed to ensure that packets are not fragmented on the public network. This ultimately achieves efficient forwarding from the intranet to the public network, balancing transmission efficiency and network compatibility.
[0039] Figure 2 This is a schematic diagram of the network framework for a cloud gateway access method provided in an embodiment of this disclosure. For ease of explanation, only the parts related to the embodiments of this disclosure are shown. Figure 2 As shown, since most current home gateway ONUs already support obtaining IPv6 addresses, this embodiment of the disclosure implements a high-performance cloud gateway access method based on VxLANv6 and combining the characteristics of cloud gateways with IPv6.
[0040] Figure 3 This is a flowchart illustrating another cloud gateway access method provided in an embodiment of the present disclosure. In one embodiment, as shown... Figure 3 As shown, the methods for accessing the cloud gateway include: S301, OUN obtains the WAN port IPv6 public address.
[0041] The ONU obtains a globally unique public IPv6 address for its WAN port via PPPoev6 or DHCPv6.
[0042] An IPv6 public address is the "identity identifier" for the ONU to access the Internet, and it is also the basis for establishing a tunnel with the cloud gateway.
[0043] The S302 and ONU establish a VxLANv6 tunnel based on the WAN port and cloud gateway.
[0044] Based on the public IPv6 address obtained in step S301, the ONU initiates a VxLANv6 tunnel establishment request to the cloud gateway.
[0045] S303, the cloud gateway obtains the WAN port address of the ONU and establishes a VxLANv6 tunnel with the ONU.
[0046] The cloud gateway obtains the public IP address of the ONU's WAN port, responds with its own IPv6 public service IP, and establishes a unique and fixed VxLANv6 tunnel with the ONU.
[0047] VxLANv6 tunnels isolate the public network from the home network, ensuring the security of data transmission over the public network (by encapsulating and hiding inner information) while enabling direct communication between home terminals and cloud gateways.
[0048] S304. The cloud gateway receives a DHCP request from the user terminal.
[0049] When user terminals (such as routers, mobile phones, laptops, etc.) connected to a home gateway need to obtain IP addresses (usually IPv4 private addresses), they request DHCP addresses from the cloud gateway. The user terminal's inner DHCP control message is encapsulated as a VxLANv6 message at the ONU and transmitted transparently to the cloud gateway over the public network.
[0050] S305: The cloud gateway removes the VxLANv6 header, restores the inner DHCP control message, and replies.
[0051] The cloud gateway decapsulates the VxLANv6 message (since DHCP control messages are small messages and do not involve fragmentation, the fragmentation recording process is not performed here to simplify the process), restores the inner original DHCP control message, and prepares to process the IP allocation request of the user terminal.
[0052] S306. Repeat the above steps to complete the DHCP interaction, and the user terminal obtains an IPv4 address.
[0053] The cloud gateway and the user terminal complete the full DHCP interaction through the above tunnel (e.g., the user terminal sends Discover → the cloud gateway responds with Offer → the user terminal requests Request → the cloud gateway confirms Ack), and finally the user terminal connected to the ONU obtains the IPv4 private address (e.g., 192.168.1.100) assigned by the cloud gateway's DHCP service.
[0054] S307, the cloud gateway receives a service message.
[0055] When a user terminal starts accessing the Internet, it accesses reliable TCP services (such as browsing web pages, video calls, etc.). The service packets are transmitted to the cloud gateway through the VxLANv6 tunnel.
[0056] The cloud gateway receives a service packet. First, it determines whether the TCP service packet has been fragmented (because service packets may be large and will be fragmented if they exceed the path MTU).
[0057] S308, the cloud gateway determines whether service packets are fragmented.
[0058] After receiving a service packet, the cloud gateway first determines whether the TCP service packet has been fragmented (because the service packet may be large and will be fragmented if it exceeds the path MTU).
[0059] The cloud gateway determines whether the received service message is a fragmented message. If the service message is not fragmented, it directly executes step S314.
[0060] If the service message is fragmented, proceed to step S309.
[0061] S309. Obtain the fragment sequence number and fragment size through the IPv6 fragmentation extension field.
[0062] In IPv6 networks, the Fragment Extension Header is a key component for packet fragmentation. Its fields accurately reveal the fragment sequence number and fragment size. The S310 and cloud gateway record the fragment size excluding the last sequence number.
[0063] The cloud gateway records the fragment size excluding the last sequence number. That is, the cloud gateway records the fragment size of each fragment packet except the last sequence number in the fragment list. For example, when processing a group of fragment packets, the fragment sizes of the group of fragment packets are: 1280, 1280, 200, and the fragment size of the last sequence number is 200. Only the fragment sizes before the last fragment are recorded, so the recorded fragment list is [1280, 1280].
[0064] MTU (Maximum Transmission Unit) refers to the maximum size of a data packet allowed to be transmitted at the data link layer, measured in bytes. Packets exceeding the MTU are fragmented or dropped, impacting network transmission efficiency. Understandably, except for the last fragment, the size of other fragments is usually fixed (equal to the minimum MTU in the path minus header overhead), while the last fragment may be smaller due to insufficient original data, thus not reflecting the true MTU limit. Recording the sizes of preceding fragments provides a more accurate estimate of the effective MTU of the path.
[0065] S311. The cloud gateway obtains the minimum value of the shard list and converts it into the ideal MSS value.
[0066] Based on the shard list recorded in step S310 as [1280, 1280], the cloud gateway obtains the minimum value of the shard list min(1280, 1280), which is 1280. This value represents the actual usable MTU in the path (the shard size is usually equal to the MTU minus the effective data size after the header).
[0067] TCP-MSS is the negotiated MSS of the inner TCP segment. The minimum value of the fragment list is used as the MTU value, and the TCP-MSS is calculated based on this MTU to obtain the current ideal MSS value.
[0068] TCP-MSS (ideal MSS value) = MTU - IP header length (20 bytes) - TCP header length (20 bytes) = 1280 - 20 - 20 = 1240 bytes.
[0069] By inferring the path MTU from the fragment size, the ideal MSS value for adapting the path is calculated, which will serve as the basis for adjusting NAT-MSS in the next step.
[0070] S312. Determine whether the ideal MSS value is less than the currently configured NAT-MSS value.
[0071] The ideal MSS value is compared with the currently configured NAT-MSS value to determine whether the currently calculated ideal MSS value is less than the currently set NAT-MSS value.
[0072] If the currently calculated ideal MSS value is greater than the currently set NAT-MSS value, then proceed directly to step S314.
[0073] For example, if the calculated ideal MSS value is 1240 bytes and the current NAT-MSS is 1200 bytes (1240>1200), then the current NAT-MSS is already smaller than the ideal MSS, indicating that the existing configuration can ensure that the packets do not exceed the public network MTU (NAT-MSS is smaller and more conservative), and no modification is needed.
[0074] If the currently calculated ideal MSS value is less than the currently set NAT-MSS value, then proceed to step S313.
[0075] For example, the calculated ideal MSS value is 1240 bytes, while the current NAT-MSS is 1300 bytes (1240 < 1300). This indicates that the existing configuration cannot ensure that packets do not exceed the public network MTU, and therefore needs to be modified.
[0076] S313. Modify the NAT-MSS of the cloud gateway when it goes out to the public network.
[0077] If, in step S312, it is determined that the currently calculated ideal MSS value is less than the currently set NAT-MSS value, then the NAT-MSS is reset, that is, the negotiated MSS value of the inner TCP packet is modified to ensure that the terminal can be set to a non-segmented MSS value.
[0078] For example, the NAT-MSS value can be adjusted to the calculated 1240 bytes (i.e., modify the negotiated MSS value of the inner TCP packet so that the terminal uses 1240 bytes as the MSS). This ensures that the MSS value negotiated by the terminal is compatible with the path MTU, avoiding packet fragmentation due to the NAT-MSS being too large and exceeding the public network MTU.
[0079] S314, the cloud gateway performs SNAT on packets, and traffic is offloaded to the public network.
[0080] The cloud gateway performs SNAT on packets, NATing the packet source's private IP address to a public IP address before sending the data packet to the Internet. Through the cloud gateway's SNAT capability, internal traffic is directly redirected to the public network, achieving efficient traffic forwarding and resource offloading.
[0081] To address the issues of unreliable packet transmission due to IP packet fragmentation and reassembly after VxLAN encapsulation in existing technologies, and fragmentation caused by inconsistencies in MTU between terminals and network devices, this disclosure proposes a VxLANv6-based tunnel. Leveraging the characteristic that IPv6 only allows fragmentation and reassembly at the sending and receiving ends, and combining this with the cloud gateway's IPv6 packet fragmentation extension header, the maximum fragment size is recorded and calculated. By incorporating NAT at the cloud gateway's egress and setting a NAT-MSS, it ensures that the terminal device can negotiate a TCP-MSS that will not lead to fragmentation. This ensures high availability even after the inner TCP packet is encapsulated with VxLAN, thereby improving network performance. It is understood that this disclosure requires no modification to the user-side terminal equipment, retaining the universality of IPv4; it simply transforms the tunnel from the ONU to the cloud gateway into a VxLAN-based IPv6 tunnel, while simultaneously recording fragmentation and modifying the TCP-MSS on the cloud gateway.
[0082] To address the issue that existing technologies can only use VNI as a user identifier, and that VNIs may be duplicated across different provinces, this disclosure proposes an embodiment that identifies users based on IPv6 addresses. The cloud gateway records the relationship between VNI (region) and IPv6 addresses, and the management platform, business platform, order platform, and other unified user broadband-allocated IPv6 addresses are used to enable value-added services on the cloud gateway side.
[0083] To address the issue of frequent VxLAN refreshes on the cloud gateway side following the BRAS in existing technologies, this disclosure implements VxLAN based on IPv6, eliminating the need for NAT and allowing for pre-configuration of VxLAN without frequent refreshes.
[0084] The above description is only a preferred embodiment of the present invention. It should be noted that, for those skilled in the art, several improvements, optimizations and modifications can be made without departing from the principle of the present invention, and these should also be considered within the scope of protection of the present invention.
[0085] Figure 4 This is a schematic diagram of a device for cloud gateway access applied to a cloud gateway, as provided in an embodiment of this disclosure. Figure 4 As shown, the device 400 includes: List module 401 is configured to obtain a list of fragments based on the fragment size records of fragmented packets; Calculation module 402 is configured to determine the ideal MSS value based on the minimum value in the sharding list; The reset module 403 is configured to reset the NAT-MSS value when the ideal MSS value is less than the currently set NAT-MSS value, so that the ideal MSS value is not less than the NAT-MSS value.
[0086] In some embodiments, the list module 401 includes: The acquisition module is configured to obtain the fragment sequence number and fragment size of the fragmented packet based on the IPv6 fragmentation extension header; The recording module is configured to record the sizes of all fragments prior to the last fragment number as a fragment list.
[0087] In some embodiments, the device 400 further includes: The judgment module 404 is configured to receive service messages and determine whether the service message is a fragmented message.
[0088] In some embodiments, the calculation module 402 is further configured to determine the ideal MSS value based on the difference between the minimum value in the fragmentation list and the IP header length and the TCP header length.
[0089] In some embodiments, the device 400 further includes: Module 405 is configured to establish a VxLANv6 tunnel with the ONU.
[0090] In some embodiments, the device 400 further includes: The receiving module 406 is configured to receive DHCP control messages sent by the ONU, wherein the DHCP control messages are encapsulated in VxLANv6 format at the ONU. The allocation module 407 is configured to parse the DHCP control message and allocate an IPv4 address.
[0091] In some embodiments, the device 400 further includes: The unloading module 408 is configured to perform source network address translation on the received service messages and unload them to the public network.
[0092] The specific implementation process of the functions and roles of each module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0093] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure, such as... Figure 5 As shown, this disclosure also provides an electronic device 500, which includes at least one processor 501 and a memory 502 coupled to the processor 501. The memory 502 is used to store at least one processor 501 executable instructions, wherein the at least one processor 501 is used to execute the instructions to implement the steps of the method described above in this disclosure.
[0094] The processor 501 described above can also be called a Central Processing Unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the method described in this embodiment can be implemented by the integrated logic circuitry in the processor 501 or by software instructions. The processor 501 can be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method in this embodiment can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in the memory 502, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The processor 501 reads information from the memory 502 and, in conjunction with its hardware, completes the steps of the method described above.
[0095] Figure 6 This is a schematic diagram of an exemplary computer system provided by an embodiment of the present disclosure. Various operations / processes according to embodiments of the present disclosure, implemented via software and / or firmware, can be transmitted from a storage medium or network to a computer system with a dedicated hardware architecture, for example... Figure 6 The computer system 600 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including those described above.
[0096] Computer system 600 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0097] like Figure 6As shown, the computer system 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. The RAM 603 may also store various programs and data required for the operation of the computer system 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0098] Multiple components in the computer system 600 are connected to the I / O interface 605, including: an input unit 606, an output unit 607, a storage unit 608, and a communication unit 609. The input unit 606 can be any type of device capable of inputting information into the computer system 600. The input unit 606 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 607 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. The storage unit 608 may include, but is not limited to, a hard disk and an optical disk. The communication unit 609 allows the computer system 600 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, modems, network interface cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth™ devices, Wi-Fi devices, WiMax devices, cellular communication devices, and / or the like.
[0099] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above. For example, in some embodiments, the methods described above in the embodiments of this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed on an electronic device via ROM 602 and / or communication unit 609. In some embodiments, the computing unit 601 can be configured to perform the methods described above in the embodiments of this disclosure by any other suitable means (e.g., by means of firmware).
[0100] This disclosure provides a computer-readable storage medium storing one or more programs that can be executed by one or more processors to implement the methods described in this disclosure.
[0101] Computer-readable storage media can be volatile memory, such as random-access memory (RAM); or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); or devices that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0102] It should be noted that the computer-readable storage medium described in this disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), or any suitable combination thereof.
[0103] Embodiments of this disclosure provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the cloud gateway access method described above.
[0104] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof. These programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on a computer, partially on a computer, as a standalone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0105] The modules, components, or units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules, components, or units do not necessarily constitute a limitation on the module, component, or unit itself.
[0106] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary hardware logic components that can be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), etc.
[0107] It should be noted that, in this document, terms such as "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0108] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for cloud gateway access, applied to a cloud gateway, and having the characteristics that, The method includes: Obtain a list of fragments based on the fragment size record of the fragmented packet; The ideal MSS value is determined based on the minimum value in the fragment list; If the ideal MSS value is less than the currently set NAT-MSS value, then the NAT-MSS value is reset so that the ideal MSS value is not less than the NAT-MSS value.
2. The method of claim 1, wherein, The fragment list obtained based on the fragment size record of the fragmented packet includes: Based on the IPv6 fragmentation extension header, obtain the fragmentation sequence number and fragmentation size of the fragmented packet; Record the sizes of all fragments before the last fragment number as a fragment list.
3. The method of claim 2, wherein, Before obtaining the list of fragments based on the fragment size records of the fragmented packets, the method further includes: Receive service messages and determine whether the service message is a fragmented message.
4. The method of claim 1, wherein, The process of determining the ideal MSS value based on the minimum value in the fragment list includes: The ideal MSS value is determined based on the difference between the minimum value in the fragmentation list and the IP header length and TCP header length.
5. The method according to any one of claims 1-4, characterized in that, The method further includes: Establish a VxLANv6 tunnel with ONU.
6. The method according to claim 5, characterized in that, The method further includes: Receive DHCP control messages sent by the ONU, wherein the DHCP control messages are encapsulated in VxLANv6 format at the ONU; The DHCP control message is parsed and an IPv4 address is assigned.
7. The method of claim 6, wherein, The method further includes: The received service messages will undergo source network address translation and be offloaded to the public network.
8. An apparatus for cloud gateway access, applied to a cloud gateway, and having the characteristics of, The device includes: The list module is configured to obtain a list of fragments based on the fragment size records of the fragmented packets; The calculation module is configured to determine the ideal MSS value based on the minimum value in the sharding list; The reset module is configured to reset the NAT-MSS value when the ideal MSS value is less than the currently set NAT-MSS value, so that the ideal MSS value is not less than the NAT-MSS value.
9. An electronic device, comprising: include: At least one processor; Memory for storing the at least one processor-executable instruction; The at least one processor is configured to execute the instructions to implement the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is able to perform the method as described in any one of claims 1-7.
11. A computer program product comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the cloud gateway access method as described in any one of claims 1-7.