Traffic forwarding methods, devices, equipment, media and products
By registering business traffic identifiers on the management platform and establishing a data tunnel between the access layer device and the new business server, the high cost and high maintenance issues of deploying new services in enterprise networks are solved, enabling the rapid launch and stable operation of new services.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN SUNDRAY NETWORK SCI TECH
- Filing Date
- 2026-02-28
- Publication Date
- 2026-05-26
AI Technical Summary
When deploying new services in an enterprise network, existing technologies suffer from high implementation costs and high operational complexity. Especially in complex network environments, mismatches and omissions are prone to occur, making it difficult to troubleshoot service access failures.
By registering business traffic identifiers on the management platform and establishing a data tunnel between the access layer device and the new business server, customized traffic forwarding can be achieved, avoiding the need to allow new services to be launched across the entire network.
This reduces the implementation cost and operational complexity of new service deployment, ensures the rapid launch and stable operation of new services, and reduces the risk of mismatch or omissions caused by network-wide deployment.
Smart Images

Figure CN122093340A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to traffic forwarding methods, apparatus, devices, media and products. Background Technology
[0002] Currently, when enterprises deploy new services, the access locations of these services are not fixed. This typically requires operations and maintenance personnel to enable the new services across the entire network. This means enabling the corresponding services on network switches, routers, firewalls, and other devices. Since enabling services requires access to the entire network forwarding devices, and there are many network devices, misconfigurations and omissions are prone to occur. Furthermore, due to the complexity of some enterprise networks, it is difficult to troubleshoot service inaccessibility caused by misconfigurations and omissions, resulting in high implementation costs and difficulties in maintenance and operation. In addition, if the network is rebuilt, existing services may be overlooked during the expansion phase, further increasing implementation difficulties.
[0003] Therefore, how to reduce implementation costs and operational complexity when deploying new services is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a traffic forwarding method, apparatus, device, medium, and product that can reduce implementation costs and operational complexity when deploying new services. The specific solution is as follows: In a first aspect, embodiments of this application provide a traffic forwarding method, applied to an access layer device, comprising: Obtain the business traffic identifier issued by the management platform, wherein the business traffic identifier is the traffic identifier of the new business server registered to the management platform; The access traffic is matched based on the service traffic identifier; When the access traffic matches the service traffic identifier, a data tunnel between the access layer device and the new service server is determined. The access traffic is forwarded to the new service server through the data tunnel.
[0005] Optionally, determining the data tunnel between the access layer device and the new service server includes: In the absence of an existing data tunnel between the access layer device and the new service server, a direct communication tunnel between the access layer device and the new service server is established based on the IP address of the new service server, thereby obtaining the data tunnel. If a direct communication tunnel cannot be established between the access layer device and the new service server, a first communication tunnel is established between the access layer device and the management platform. The first communication tunnel and the second communication tunnel are used as the data tunnel, wherein the second communication tunnel is the communication tunnel between the management platform and the new service server.
[0006] Optionally, establishing a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server includes: Extract the IP address of the new service server from the service traffic identifier; A direct communication tunnel is established between the access layer device and the new service server based on the IP address of the new service server.
[0007] Optionally, matching access traffic based on the service traffic identifier includes: Extract the service port and message format from the service traffic identifier; The access traffic is matched based on the service port and the message format.
[0008] Optional, also includes: If the duration of access traffic that does not match the service traffic identifier exceeds a preset duration threshold, the data tunnel will be shut down.
[0009] Secondly, this application provides a traffic forwarding method applied to a management platform, including: Obtain the business traffic identifier reported by the new business server; The service traffic identifier is distributed to all access layer devices within the network. The service traffic identifier is used to match the access traffic of the access layer devices. When the access traffic matches the service traffic identifier, it is forwarded to the new service server by the data tunnel between the access layer device and the new service server.
[0010] Thirdly, this application provides a traffic forwarding device, comprising: The traffic identifier determination module is used to obtain the business traffic identifier issued by the management platform, wherein the business traffic identifier is the traffic identifier of the new business server registered to the management platform; An access traffic matching module is used to match access traffic based on the service traffic identifier; A data tunnel determination module is used to determine the data tunnel between the access layer device and the new service server when the access traffic matches the service traffic identifier. The access traffic forwarding module is used to forward the access traffic to the new service server through the data tunnel.
[0011] Fourthly, this application provides an electronic device, including a memory and a processor, wherein: The memory is used to store computer programs; The processor is used to execute the computer program to implement the aforementioned traffic forwarding method.
[0012] Fifthly, this application provides a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the aforementioned traffic forwarding method.
[0013] Sixthly, this application provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the aforementioned traffic forwarding method.
[0014] As can be seen from the above scheme, this application provides a traffic forwarding method applied to an access layer device, including: obtaining a service traffic identifier issued by a management platform, wherein the service traffic identifier is a traffic identifier registered by a new service server to the management platform; matching access traffic based on the service traffic identifier; when the access traffic matches the service traffic identifier, determining a data tunnel between the access layer device and the new service server; and forwarding the access traffic to the new service server through the data tunnel.
[0015] As can be seen, the beneficial effects of this application are as follows: When deploying a new service, the new service server registers its own service traffic identifier with the management platform. The access layer devices obtain the service traffic identifier issued by the management platform. When they obtain access traffic, they match the access traffic based on the service traffic identifier. If the access traffic matches the service traffic identifier, a data tunnel is determined between the access layer devices and the new service server. The access traffic is then forwarded to the new service server through this data tunnel. In this way, when deploying a new service, it is not necessary to enable the newly deployed service on the entire network forwarding devices. By registering the service traffic identifier on the management platform and issuing it to each access layer device, and transmitting traffic through the data tunnel between the access layer devices and the new service server, the implementation cost and operation and maintenance complexity can be reduced when deploying a new service.
[0016] Correspondingly, the traffic forwarding device, equipment, readable storage medium, and product provided in this application also have the above-mentioned technical effects. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0018] Figure 1 A flowchart of a traffic forwarding method provided in an embodiment of this application; Figure 2 A flowchart of another traffic forwarding method provided in this application embodiment; Figure 3 This is a schematic diagram of a traffic forwarding device provided in an embodiment of this application; Figure 4 This is a structural diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0020] Current Enterprise Network Status: Large-scale enterprises have complex internal networks; enterprise network access is mainly divided into external network access and internal business access. Currently, due to the increasing digitalization of enterprises, internal network business access traffic is gradually becoming dominant (accounting for approximately 60%-80% of total traffic); when enterprises deploy new services, the access locations of these services are not fixed, usually requiring maintenance personnel to enable the new services across the entire network (typically requiring enabling the corresponding services on network switches, routers, firewalls, etc.), which presents several potential drawbacks: High implementation costs and maintenance difficulties for service deployment: Service deployment requires deployment across the entire network's forwarding equipment. With numerous network devices, mismatches and omissions are prone to occur. Furthermore, the complexity of large-scale enterprise networks makes troubleshooting service inaccessibility caused by mismatches and omissions difficult. Implementation costs are high, and maintenance and operation are challenging. Service deployment requires reimplementation after network reconstruction: Network expansion or reconstruction can easily lead to the omission of existing service deployments, necessitating network reconstruction or new construction. Therefore, this application provides a traffic forwarding solution that eliminates the need for network-wide traffic deployment for new service launches, thus resolving the aforementioned problems of high implementation costs and maintenance difficulties for network-wide service deployment.
[0021] See Figure 1 As shown in the figure, this application discloses a traffic forwarding method applied to an access layer device, including: Step S11: Obtain the business traffic identifier issued by the management platform, wherein the business traffic identifier is the traffic identifier of the new business server registered to the management platform.
[0022] The management platform is the overall network device management platform for the enterprise network. Managed devices include edge access points (APs), access layer switches, aggregation switches, core switches, firewalls, routers, and new service servers. The management platform communicates with managed devices through a control tunnel. APs are wireless devices or modules used in wireless local area networks (WLANs) to provide 802.11 wireless access to terminal devices, typically connected to switches via wired Ethernet ports. New service servers are servers that deploy new service applications, providing services for these new applications. New service servers register their service traffic identifiers with the management platform. In other words, when a customer deploys a new service on the intranet, the server hosting the new service is called the new service server. The service traffic identifier represents the service traffic of the new service and can specifically include: service traffic port and message type (unicast, multicast, etc.). The service traffic identifier can be flexibly defined according to the service type and may include, but is not limited to, the new service server IP (Internet Protocol), service port, and message type.
[0023] In this embodiment, the access layer device is a device that provides network access ports and executes access control, traffic forwarding, and security policies, and may include wireless access points, access layer switches, etc. After receiving a service traffic identifier sent by a new service server, the server management platform can save the service traffic identifier sent by the new service server and distribute the service traffic identifier of the new service server to all access layer devices in the enterprise network. This identifier is also distributed to subsequently newly connected access layer devices.
[0024] Step S12: Match the access traffic based on the service traffic identifier.
[0025] Among them, access traffic refers to the traffic received by the access layer device. In this embodiment of the application, target key information can be extracted from the access traffic and matched with the target field of the service traffic identifier.
[0026] In an optional implementation, matching access traffic based on the service traffic identifier includes: extracting the service port and packet format from the service traffic identifier; and matching access traffic based on the service port and the packet format.
[0027] That is, in this embodiment, the service traffic identifier may include the service port and the message format. The destination port of the access traffic is extracted and the message format of the access traffic is obtained. If it is consistent with the service port and message format in the service traffic identifier, then the service traffic identifier matches the access traffic.
[0028] Step S13: When the access traffic matches the service traffic identifier, the data tunnel between the access layer device and the new service server is determined.
[0029] The data tunnel can be a direct communication tunnel between the access layer device and the new service server, or it can be a data tunnel proxied by the management platform. That is, the data tunnel consists of the communication tunnel between the access layer device and the management platform and the communication tunnel between the management platform and the new service server.
[0030] In an optional implementation, determining the data tunnel between the access layer device and the new service server may include: if no existing data tunnel exists between the access layer device and the new service server, establishing a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server to obtain the data tunnel; if a direct communication tunnel cannot be established between the access layer device and the new service server, establishing a first communication tunnel between the access layer device and the management platform, and using the first communication tunnel and the second communication tunnel as the data tunnel, wherein the second communication tunnel is the communication tunnel between the management platform and the new service server.
[0031] In other words, the embodiments of this application can first determine whether there is an existing data tunnel between the access layer device and the new service server. If there is, the data tunnel is determined to forward traffic; otherwise, a data tunnel between the access layer device and the new service server is established.
[0032] The step of establishing a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server includes: extracting the IP address of the new service server from the service traffic identifier; and establishing a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server.
[0033] That is, in this embodiment, the service traffic identifier may include the IP address of the new service server, and a direct communication tunnel between the access layer device and the new service server may be established based on the IP address of the new service server.
[0034] Step S14: Forward the access traffic to the new service server through the data tunnel.
[0035] In other words, in this embodiment, once the data tunnel between the access layer device and the new service server is successfully created, traffic accessing the new service is forwarded to the new service server through the data tunnel.
[0036] Furthermore, this embodiment may also include: if the duration of access traffic that does not match the service traffic identifier exceeds a preset duration threshold, then the data tunnel is shut down.
[0037] This embodiment can periodically trigger the step of shutting down the data tunnel if the duration of access traffic that has not matched the service traffic identifier exceeds a preset duration threshold. In other words, the access layer device periodically checks for new service traffic; if no new traffic is found, the data tunnel is shut down to avoid resource consumption.
[0038] As can be seen, in this embodiment, when deploying a new service, the new service server registers its own service traffic identifier with the management platform. The access layer device obtains the service traffic identifier issued by the management platform. When it obtains access traffic, it matches the access traffic with the service traffic identifier. If the access traffic matches the service traffic identifier, it determines the data tunnel between the access layer device and the new service server, and forwards the access traffic to the new service server through this data tunnel. In this way, when deploying a new service, it is not necessary to enable the newly deployed service on the entire network forwarding device. By registering the service traffic identifier on the management platform and issuing it to each access layer device, and transmitting traffic through the data tunnel between the access layer device and the new service server, the implementation cost and operation and maintenance complexity can be reduced when deploying a new service.
[0039] In other words, this application provides a critical business traffic virtualization technology. When large-scale enterprises deploy new services, they do not need to concern themselves with network topology or traffic flow, nor do they need to enable the newly deployed services on the entire network forwarding devices. Only the access layer devices and the management platform need to be connected. By establishing a proxy data tunnel between the business server, the management platform, and the access layer devices, the problem of accessing new services across the entire network is solved, thereby avoiding the high implementation costs and maintenance difficulties associated with enabling new services across the entire network. This embodiment implements a scheme for establishing a data tunnel between self-registered access layer devices and new business servers. The main process includes: New business server management: All network devices are managed uniformly on the management platform. After the new business server is deployed, it needs to be activated on the management platform. After the new business server goes online, it will report the business traffic identification to the management platform and register. It can be flexibly defined according to the business type, including but not limited to: new business server IP, business port, message type, etc.
[0040] Service traffic identifier distribution to access layer devices: After receiving the service traffic identifier from a new service server, the management platform saves the identifier and simultaneously distributes it to all access layer devices (wireless access points, access layer switches, etc.) in the enterprise network. Subsequent newly connected access layer devices are also included in the distribution. Upon receiving the service traffic identifier, the access layer devices monitor whether the current access traffic matches the service traffic. For example, if the service traffic identifier is defined as {New service server IP: 192.168.100.254; Service port: 9981; Packet type: UDP (User Datagram Protocol) unicast}, then the access layer device considers traffic containing UDP unicast packets with a destination port of 9981 as a match for the new service.
[0041] Virtual data tunnel establishment: After the access layer device matches the new service in the access traffic, it first establishes a data tunnel directly with the new service server (by directly establishing a data tunnel with the new service server IP in the service traffic identifier). If the direct establishment of the data tunnel is successful, this tunnel serves as the data tunnel between the access layer device and the new service server. If the direct establishment of the data tunnel with the new service server fails, the access layer device first establishes a data tunnel with the management platform, and then the management platform establishes a data tunnel with the new service server. In this case, the data tunnel between the access layer device and the new service server is proxied through the management platform.
[0042] New service data traffic forwarding: Once a data tunnel is successfully established between the access layer device and the new service server, traffic accessing the new service is forwarded to the new service server through the data tunnel. Additionally, the access layer device periodically checks for new service traffic; if no traffic is found, the data tunnel is closed to avoid resource consumption.
[0043] With the aforementioned solution, when a new service is launched, there is no need to allow service traffic to flow across the entire network. Access layer devices access the new service server directly through the data tunnel, which is transparent to the network devices as a whole and eliminates the need to consider the impact of network policies. This enables rapid launch of new services without requiring network-wide service access, ensuring rapid deployment and stable operation of services in the future.
[0044] This approach enables rapid deployment of self-registered new services, resolving mismatch and omission issues caused by unblocking network traffic during the original new service deployment process, as well as difficulties in subsequent operation and maintenance. In this embodiment, new services can automatically register their characteristics upon deployment, eliminating the need for platform configuration. The entire network self-negotiates data tunnels, effectively reducing administrator learning costs. Furthermore, it automatically applies to new access layer devices during subsequent network expansion, resulting in a rapid deployment with zero impact. Through private data tunnel technology, new service traffic forwarding does not require attention to network-wide forwarding permissions, minimizing human error and significantly reducing implementation and maintenance costs during new service deployment. Service traffic forwarding is transparent to the entire network: Custom forwarding channels are built through direct creation and management platform proxies. Service traffic forwarding is not restricted by network policies of the entire network devices. Transparent forwarding via custom channels allows new service deployment to proceed without considering network policy limitations. Customizable service traffic identifiers: When deploying a new service server, service traffic identifiers can be customized based on the service's attributes, with automatic network-wide adaptation.
[0045] See Figure 2 As shown in the figure, this application discloses a traffic forwarding method applied to a management platform, including: Step S21: Obtain the business traffic identifier reported by the new business server.
[0046] Step S22: Distribute the service traffic identifier to all access layer devices in the network. The service traffic identifier is used to match the access traffic of the access layer devices. When the access traffic matches the service traffic identifier, it is forwarded to the new service server by the data tunnel between the access layer device and the new service server.
[0047] As can be seen, in this embodiment, when deploying a new service, the new service server registers its own service traffic identifier with the management platform. The management platform then distributes the service traffic identifier to the access layer devices. When the access layer devices receive access traffic, they match the access traffic with the service traffic identifier. If the access traffic matches the service traffic identifier, a data tunnel is established between the access layer devices and the new service server. The access traffic is then forwarded to the new service server through this data tunnel. In this way, when deploying a new service, it is unnecessary to enable the new service on all network forwarding devices. By registering the service traffic identifier on the management platform and distributing it to each access layer device, and transmitting traffic through the data tunnel between the access layer devices and the new service server, the implementation cost and operational complexity can be reduced when deploying a new service.
[0048] See Figure 3 As shown in the figure, this application provides a traffic forwarding device, including: Traffic identification module 11 is used to obtain the business traffic identification issued by the management platform, wherein the business traffic identification is the traffic identification of a new business server registered to the management platform; Access traffic matching module 12 is used to match access traffic based on the service traffic identifier; The data tunnel determination module 13 is used to determine the data tunnel between the access layer device and the new service server when the access traffic matches the service traffic identifier; The access traffic forwarding module 14 is used to forward the access traffic to the new service server through the data tunnel.
[0049] Specifically, the data tunnel determination module 13 can be used to establish a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server when no existing data tunnel exists between the access layer device and the new service server, thereby obtaining the data tunnel; if a direct communication tunnel between the access layer device and the new service server cannot be established, a first communication tunnel between the access layer device and the management platform is established, and the first communication tunnel and the second communication tunnel are used as the data tunnel, wherein the second communication tunnel is the communication tunnel between the management platform and the new service server.
[0050] Furthermore, the data tunnel determination module 13 can be specifically used to extract the IP address of the new service server from the service traffic identifier; and establish a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server.
[0051] The access traffic matching module 12 can be specifically used to: extract the service port and message format from the service traffic identifier; and match the access traffic based on the service port and message format.
[0052] Furthermore, the device may also include: If the duration of access traffic that does not match the service traffic identifier exceeds a preset duration threshold, the data tunnel will be shut down.
[0053] As can be seen, in this embodiment, when deploying a new service, the new service server registers its own service traffic identifier with the management platform. The access layer device obtains the service traffic identifier issued by the management platform. When it obtains access traffic, it matches the access traffic with the service traffic identifier. If the access traffic matches the service traffic identifier, it determines the data tunnel between the access layer device and the new service server, and forwards the access traffic to the new service server through this data tunnel. In this way, when deploying a new service, it is not necessary to enable the newly deployed service on the entire network forwarding device. By registering the service traffic identifier on the management platform and issuing it to each access layer device, and transmitting traffic through the data tunnel between the access layer device and the new service server, the implementation cost and operation and maintenance complexity can be reduced when deploying a new service.
[0054] Furthermore, embodiments of this application provide a traffic forwarding device applied to a management platform, comprising: The identifier acquisition module is used to acquire the business traffic identifier reported by the new business server; The identifier distribution module is used to distribute the service traffic identifier to all access layer devices in the network. The service traffic identifier is used to match the access traffic of the access layer devices. When the access traffic matches the service traffic identifier, it is forwarded to the new service server by the data tunnel between the access layer device and the new service server.
[0055] As can be seen, in this embodiment, when deploying a new service, the new service server registers its own service traffic identifier with the management platform. The management platform then distributes the service traffic identifier to the access layer devices. When the access layer devices receive access traffic, they match the access traffic with the service traffic identifier. If the access traffic matches the service traffic identifier, a data tunnel is established between the access layer devices and the new service server. The access traffic is then forwarded to the new service server through this data tunnel. In this way, when deploying a new service, it is unnecessary to enable the new service on all network forwarding devices. By registering the service traffic identifier on the management platform and distributing it to each access layer device, and transmitting traffic through the data tunnel between the access layer devices and the new service server, the implementation cost and operational complexity can be reduced when deploying a new service.
[0056] See Figure 4 As shown in the figure, this application discloses an electronic device 20, including a processor 21 and a memory 22; wherein, the memory 22 is used to store a computer program; the processor 21 is used to execute the computer program, the traffic forwarding method disclosed in the foregoing embodiments.
[0057] For details regarding the specific process of the traffic forwarding method described above, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.
[0058] Furthermore, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk, or optical disk, and the storage method can be temporary storage or permanent storage.
[0059] In addition, the electronic device 20 also includes a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26; wherein, the power supply 23 is used to provide operating voltage for the various hardware devices on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0060] Furthermore, embodiments of this application also disclose a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the traffic forwarding method disclosed in the foregoing embodiments.
[0061] For details regarding the specific process of the traffic forwarding method described above, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.
[0062] Furthermore, embodiments of this application provide a computer program product, including a computer program / instructions, which, when executed by a processor, implement the traffic forwarding method disclosed in the foregoing embodiments.
[0063] For details regarding the specific process of the traffic forwarding method described above, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.
[0064] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0065] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0066] The traffic forwarding method, apparatus, device, medium, and product provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A traffic forwarding method, characterized in that, Applied to access layer devices, including: Obtain the business traffic identifier issued by the management platform, wherein the business traffic identifier is the traffic identifier of the new business server registered to the management platform; The access traffic is matched based on the service traffic identifier; When the access traffic matches the service traffic identifier, a data tunnel between the access layer device and the new service server is determined. The access traffic is forwarded to the new service server through the data tunnel.
2. The traffic forwarding method according to claim 1, characterized in that, Determining the data tunnel between the access layer device and the new service server includes: In the absence of an existing data tunnel between the access layer device and the new service server, a direct communication tunnel between the access layer device and the new service server is established based on the IP address of the new service server, thereby obtaining the data tunnel. If a direct communication tunnel cannot be established between the access layer device and the new service server, a first communication tunnel is established between the access layer device and the management platform. The first communication tunnel and the second communication tunnel are used as the data tunnel, wherein the second communication tunnel is the communication tunnel between the management platform and the new service server.
3. The traffic forwarding method according to claim 2, characterized in that, The establishment of a direct communication tunnel between the access layer device and the new service server based on the IP address of the new service server includes: Extract the IP address of the new service server from the service traffic identifier; A direct communication tunnel is established between the access layer device and the new service server based on the IP address of the new service server.
4. The traffic forwarding method according to claim 1, characterized in that, The matching of access traffic based on the service traffic identifier includes: Extract the service port and message format from the service traffic identifier; The access traffic is matched based on the service port and the message format.
5. The traffic forwarding method according to claim 1, characterized in that, Also includes: If the duration of access traffic that does not match the service traffic identifier exceeds a preset duration threshold, the data tunnel will be shut down.
6. A traffic forwarding method, characterized in that, Applications in management platforms include: Obtain the business traffic identifier reported by the new business server; The service traffic identifier is distributed to all access layer devices within the network. The service traffic identifier is used to match the access traffic of the access layer devices. When the access traffic matches the service traffic identifier, it is forwarded to the new service server by the data tunnel between the access layer device and the new service server.
7. A traffic forwarding device, characterized in that, include: The traffic identifier determination module is used to obtain the business traffic identifier issued by the management platform, wherein the business traffic identifier is the traffic identifier of the new business server registered to the management platform; An access traffic matching module is used to match access traffic based on the service traffic identifier; A data tunnel determination module is used to determine the data tunnel between the access layer device and the new service server when the access traffic matches the service traffic identifier. The access traffic forwarding module is used to forward the access traffic to the new service server through the data tunnel.
8. An electronic device, characterized in that, Includes memory and processor, wherein: The memory is used to store computer programs; The processor is configured to execute the computer program to implement the traffic forwarding method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, Used to store a computer program, wherein the computer program, when executed by a processor, implements the traffic forwarding method as described in any one of claims 1 to 6.
10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the traffic forwarding method as described in any one of claims 1 to 6.