A data packet transmission method, device, apparatus and storage medium

By building a dedicated gateway for virtual software modules in the cloud environment, VXLAN encapsulation and IP address translation are achieved, solving the problem of IP conflicts in dedicated cloud networks, reducing network complexity and cost, and enabling flexible routing configuration.

CN122179429APending Publication Date: 2026-06-09BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD
Filing Date
2024-12-09
Publication Date
2026-06-09

Smart Images

  • Figure CN122179429A_ABST
    Figure CN122179429A_ABST
Patent Text Reader

Abstract

This invention relates to a data packet transmission method, apparatus, device, and storage medium. The data packet transmission method includes: acquiring a first data packet to be transmitted to a first network device; wherein the first network device is located in an internal network environment; performing VXLAN encapsulation and first IP address translation on the first data packet through a leased line gateway module; wherein the leased line gateway module is a virtual software module located in a cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device; and transmitting the first data packet to the first network device through a leased line gateway device; wherein the leased line gateway device is a physical device located at the edge of the internal network environment. The method provided in this application achieves flexible routing configuration through a virtual software module, avoids IP conflicts, and reduces dependence on physical devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data packet transmission technology, and in particular to a data packet transmission method, apparatus, device, and storage medium. Background Technology

[0002] A cloud-dedicated network (CDN) is a service that provides users with dedicated, isolated network connectivity in a cloud environment. This service is typically used to meet enterprises' high requirements for data security, network performance, and compliance. Through a complex resource-interacting network topology comprised of a Cloud Enterprise Network (CEN) and a Virtual Private Cloud (VPC), multi-region interconnection can be achieved.

[0003] However, as network topologies grow larger, multiple tenants may use the same IP address, easily leading to IP conflict issues. To avoid conflicts, IP address allocation needs to be planned, currently often done by deploying dedicated physical devices such as routers, switches, and firewalls. However, the procurement, deployment, and maintenance of these physical devices require additional costs and management effort. Summary of the Invention

[0004] To address the aforementioned technical problems, this disclosure provides a data packet transmission method, apparatus, device, and storage medium.

[0005] In a first aspect, embodiments of this disclosure provide a data packet transmission method, the method comprising:

[0006] Obtain the first data packet to be transmitted to the first network device; wherein the first network device is located in an internal network environment;

[0007] The first data packet is encapsulated using VXLAN and its first IP address is translated using a leased line gateway module. The leased line gateway module is a virtual software module located in a cloud environment. The first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device.

[0008] The first data packet is transmitted to the first network device through a leased line gateway device; wherein, the leased line gateway device is an edge device located in the internal network environment.

[0009] The leased line gateway module includes a leased line routing module and a leased line NAT module, with the leased line NAT module configured decoupled from the leased line routing module.

[0010] Optionally, the first data packet is encapsulated using VXLAN and its first IP address is translated via the leased line gateway module, including:

[0011] If the destination IP address of the first data packet is determined by the dedicated line routing module to be the first matching IP address that matches a certain route entry in the routing table, the dedicated line NAT module performs VXLAN encapsulation and first IP address translation on the first data packet to obtain the processed first data packet.

[0012] The first data packet, after being processed, is forwarded to the leased line gateway device via the leased line routing module, so that the leased line gateway device can decapsulate the first data packet and transmit it to the first network device.

[0013] Optionally, before performing VXLAN encapsulation and first IP address translation on the first data packet via the leased line NAT module, the method further includes:

[0014] The first set ACL rule in the downlink direction is matched to determine whether the first data packet conforms to the first security policy of the internal network environment; where downlink direction refers to the transmission of data packets from the cloud environment to the internal network environment.

[0015] Optionally, the first data packet can be encapsulated using a leased line NAT module and the first IP address translated, including:

[0016] If the first data packet is determined to conform to the first security policy, the first data packet is encapsulated in VXLAN and the first IP address is translated through the leased line NAT module.

[0017] Optionally, the first ACL rule setting refers to packet filtering rules set according to packet type and / or packet priority;

[0018] The dedicated line NAT module is configured with one-to-one IP translation rules.

[0019] Secondly, embodiments of this disclosure provide a data packet transmission method, the method comprising:

[0020] Obtain the second data packet generated by the second network device and to be transmitted to the third network device; wherein the second network device is in an internal network environment and the third network device is in a cloud environment;

[0021] The second data packet is transmitted to the leased line gateway module through the leased line gateway device; wherein, the leased line gateway device is an edge device in the internal network environment, and the leased line gateway module is a virtual software module in the cloud environment;

[0022] The second data packet is encapsulated using VXLAN and its second IP address is translated using a dedicated line gateway module to route the second data packet to a third network device. The second IP address translation refers to converting the source IP address of the second data packet from the private IP address of the second network device to a public IP address.

[0023] The leased line gateway module includes a leased line routing module and a leased line NAT module, with the leased line NAT module configured decoupled from the leased line routing module.

[0024] Optionally, the second data packet is encapsulated using VXLAN and its second IP address is translated via a leased line gateway module to route the second data packet to a third network device, including:

[0025] If the source IP address of the second data packet is determined by the leased line routing module to be the second hit IP address that matches a certain route entry in the routing table, the leased line NAT module performs VXLAN encapsulation and second IP address translation on the second data packet to obtain the processed second data packet.

[0026] The processed second data packet is routed to the third network device via a dedicated line routing module.

[0027] Optionally, before performing VXLAN encapsulation and second IP address translation on the second data packet via the leased line NAT module, the method further includes:

[0028] The second set ACL rules in the uplink direction are matched to determine whether the second data packet conforms to the second security policy of the cloud environment; where uplink direction refers to the transmission of data packets from the internal network environment to the cloud environment.

[0029] Optionally, the second data packet can be encapsulated using a leased line NAT module and then translated to a second IP address, including:

[0030] If the second data packet is determined to conform to the second security policy, the second data packet is encapsulated using VXLAN and the second IP address is translated using the leased line NAT module.

[0031] Thirdly, embodiments of this disclosure provide a data packet transmission apparatus, the apparatus comprising:

[0032] The first acquisition unit is used to acquire a first data packet to be transmitted to the first network device; wherein the first network device is located in an internal network environment;

[0033] The first processing unit is used to perform VXLAN encapsulation and first IP address translation on the first data packet through the leased line gateway module; wherein, the leased line gateway module is a virtual software module in the cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device;

[0034] The first transmission unit is used to transmit the first data packet to the first network device through a leased line gateway device; wherein the leased line gateway device is an edge device located in the internal network environment.

[0035] Fourthly, embodiments of this disclosure provide a data packet transmission apparatus, the apparatus comprising:

[0036] The second acquisition unit is used to acquire the second data packet generated by the second network device and to be transmitted to the third network device; wherein the second network device is located in an internal network environment and the third network device is located in a cloud environment;

[0037] The second transmission unit is used to transmit the second data packet to the leased line gateway module through the leased line gateway device; wherein, the leased line gateway device is an edge device in the internal network environment, and the leased line gateway module is a virtual software module in the cloud environment;

[0038] The second processing unit is used to perform VXLAN encapsulation and second IP address translation on the second data packet through the leased line gateway module, so as to route the second data packet to the third network device; wherein, the second IP address translation refers to converting the source IP address of the second data packet from the private IP address of the second network device to the public IP address.

[0039] Fifthly, embodiments of this disclosure provide an electronic device, including:

[0040] Memory;

[0041] Processor; and

[0042] Computer programs;

[0043] The computer program is stored in memory and configured to be executed by the processor to implement the data packet transmission method described above.

[0044] Fourthly, embodiments of this disclosure provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the data packet transmission method described above.

[0045] The data packet transmission method disclosed herein includes: acquiring a first data packet to be transmitted to a first network device; wherein the first network device is located in an internal network environment; performing VXLAN encapsulation and first IP address translation on the first data packet through a leased line gateway module; wherein the leased line gateway module is a virtual software module located in a cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device; and transmitting the first data packet to the first network device through a leased line gateway device; wherein the leased line gateway device is a physical device located at the edge of the internal network environment. The method provided in this application achieves flexible routing configuration through a virtual software module, avoids IP conflicts, and reduces dependence on physical devices. Attached Figure Description

[0046] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0047] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0048] Figure 1 A schematic diagram of a cloud-based private network provided in this embodiment of the disclosure;

[0049] Figure 2 This is a schematic diagram of a network structure that implements NAT translation using a dedicated physical device, as provided in an embodiment of this disclosure.

[0050] Figure 3 A flowchart illustrating a data packet transmission method provided in an embodiment of this disclosure;

[0051] Figure 4 A cloud-dedicated line network topology diagram provided in this embodiment of the disclosure;

[0052] Figure 5 A flowchart illustrating another data packet transmission method provided in this embodiment of the present disclosure;

[0053] Figure 6 This is a schematic diagram of the structure of a data packet transmission device provided in an embodiment of the present disclosure;

[0054] Figure 7 This is a schematic diagram of another data packet transmission device provided in an embodiment of the present disclosure;

[0055] Figure 8 This is a schematic diagram of the structure of a computer device provided in an embodiment of this disclosure. Detailed Implementation

[0056] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0057] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0058] Before providing a detailed explanation of this application, the technical terms involved will be explained first, including:

[0059] A Virtual Private Cloud (VPC) is a network of logical network devices that can be understood as a private network in the cloud. Different VPCs are logically isolated at Layer 2. It can connect to traditional data centers through direct lines, virtual private networks (VPNs), or other connection methods, and can also connect to other VPCs, private network services, and internal network services through peering connections and private links.

[0060] Direct Connect establishes a secure, stable, and high-speed private network communication between a VPC or Cloud Enterprise Network (CEN) and on-premises data centers / Internet Data Centers (IDCs) and other cloud services. Direct Connect ensures reliable and controllable transmission, guaranteeing data security and network stability. It can provide intranet-level network services with lower latency, lower packet loss rate, and higher bandwidth.

[0061] An Internet data center is a data service platform with complete infrastructure (secure and reliable data center environment, high-speed Internet access bandwidth, high-performance local area network, high-speed read and write speed), professional management, and comprehensive application services. It can provide Domain Name System (DNS) services, load balancing services, database system services, etc.

[0062] Network Address Translation (NAT) is an IP and port mapping technology that solves the problem of insufficient IP addresses and effectively avoids IP port conflicts, thus ensuring network security. The NAT process involves automatically modifying the source and destination IP addresses of IP packets; IP address verification is performed automatically during NAT. Some applications embed the source IP address into the data portion of the IP packet, so the data portion also needs to be modified simultaneously to match the modified source IP address in the IP header.

[0063] Specifically, CEN and VPC currently enable interconnection between multiple regions and multiple VPCs / IDCs, facilitating instance network communication and more conveniently integrating and expanding cloud resources across multiple regions. This provides efficient interactive communication between VPCs / IDCs in different and the same regions, forming an independent and complex resource interaction topology. However, while expanding the convenience of cloud-based private networks, IP conflict issues inevitably arise as the network topology grows larger.

[0064] For example, see Figure 1 , Figure 1 This is a schematic diagram of a network structure of a cloud-based private network provided in an embodiment of the present disclosure. The clusters of tenant A, tenant B, and tenant C that are connected to the cloud network, as well as the network segment of the cloud public service resources, are all 10.0.0.0 / 8. For example, when tenant A accesses cloud resources through a dedicated line, and tenant B accesses other resources through a dedicated line and cloud resources, it is inevitable that the services will share the same IP address, resulting in communication conflicts.

[0065] To address the aforementioned IP conflict issue, the current common solution is to implement IP NAT translation using dedicated physical devices (firewalls, NAT gateways). However, introducing new physical devices increases network complexity and the length of the routing links. Furthermore, these new devices incur additional procurement, usage, and maintenance costs, posing significant challenges to both service providers and users. Moreover, firewalls, switches, and other physical devices are limited by different manufacturers and models, requiring their own configuration processes and consideration of heterogeneous high availability – a highly complex solution that demands substantial manpower from procurement and machine networking to software development and maintenance.

[0066] For example, see Figure 2 , Figure 2 This is a schematic diagram of a network structure that implements NAT translation through a dedicated physical device, as provided in the embodiments of this disclosure. Figure 1 Based on the example, dedicated physical devices, such as firewall devices and switch devices, are configured for each cluster. IP NAT translation is performed through dedicated physical devices to avoid IP conflicts. However, the network complexity and usage costs increase accordingly in this case. Not only does purchasing and maintaining dedicated physical network devices require high initial investment and ongoing operation and maintenance costs, but subsequent configuration and management of physical devices also require professional network knowledge and technical support, increasing the management difficulty.

[0067] To address the aforementioned technical problems, this disclosure provides a data packet transmission method that implements IP NAT translation in leased lines through a constructed virtual software module. This eliminates the need for additional dedicated physical configurations such as firewalls and switches, resolving the inaccessibility issue caused by IP conflicts within the network, and further reducing network complexity and usage costs. Detailed descriptions are provided below through one or more embodiments.

[0068] The data packet transmission method provided in this disclosure is applicable to cloud-dedicated line resource transmission scenarios. This method can be executed by a data packet transmission device, which can be implemented in software and / or hardware and can be integrated into an electronic device. The electronic device can include, but is not limited to, mobile terminals such as smartphones, laptops, digital radio receivers, personal digital assistants (PDAs), tablet PCs, portable multimedia players (PMPs), in-vehicle terminals (e.g., in-vehicle navigation terminals), wearable devices, etc., as well as fixed terminals such as digital televisions, desktop computers, smart home devices, etc.

[0069] Figure 3 This is a flowchart illustrating a data packet transmission method provided in this disclosure, applied to a downlink data packet transmission scenario between cloud and dedicated line, specifically including as follows: Figure 3 Steps S301 to S303 are shown below:

[0070] S301. Obtain the first data packet to be transmitted to the first network device.

[0071] The first network device is located in an internal network environment.

[0072] Understandably, a cloud service or virtual machine in a cloud environment generates the first data packet. This first data packet refers to the data packet to be transmitted from the cloud environment to the first network device. Transmitting data packets from the cloud environment to the internal network environment can be understood as downlink data packet transmission, and transmitting data packets from the internal network environment to the cloud environment can be understood as uplink data packet transmission. The internal network environment can be a private network such as an enterprise's internal network, and the first network device is a physical device within the internal network environment, such as a server, workstation, or an application that needs to access cloud services.

[0073] S302. The first data packet is encapsulated using VXLAN and the first IP address is translated using the dedicated line gateway module.

[0074] Among them, the leased line gateway module is a virtual software module in the cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device.

[0075] Understandably, based on the above S301, the first data packet is encapsulated in VXLAN and the first IP address is translated through the leased line gateway module. The leased line gateway module is a virtual software module in the cloud environment. VXLAN (Virtual Extensible Local Area Network) is a network virtualization technology. VXLAN is used to create a logical Layer 2 network that spans physical networks. It mainly creates a tunnel by encapsulating Layer 2 data frames on top of the network layer, thereby allowing virtual machines or containers to communicate across multiple physical networks. In other words, it creates a communication tunnel between the cloud environment and the internal network environment to realize the transmission of data packets. The first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device. Each data packet has a source IP address and a destination IP address. The source IP address is the IP address of the sender that initiated the communication. When a data packet is created and sent, the source IP address is automatically added to the packet header, or it may be specified by the user. The source IP address identifies the origin of the data packet, enabling the destination node (the first network device) to send the response back to the correct address. The destination IP address is the target address of the receiving data packet. The destination IP address indicates the destination node to which the data packet should be delivered, ensuring that the data packet is correctly transmitted. In network communication, the data packet passes through a series of intermediate routers based on the destination IP address until it reaches the destination node. Additionally, each first network device has a corresponding private IP address within its internal network environment. Public IP addresses are unique addresses assigned to enterprises to uniquely identify their network devices on the Internet. In NAT scenarios, when devices in an enterprise's internal network need to communicate with an external network (cloud), private IP addresses are translated into one or a set of pre-assigned public IP addresses, increasing network security.

[0076] The leased line gateway module includes a leased line routing module and a leased line NAT module, with the leased line NAT module configured decoupled from the leased line routing module.

[0077] For example, see Figure 4 , Figure 4This disclosure provides a cloud-leased network topology diagram, which is divided into a control plane and a data plane. The control plane is where the cloud environment resides. VPCs, CENs, cloud routers, and leased line gateway modules can be deployed in the cloud environment. Cloud routers are used for other network connection methods, while leased line gateway modules are used for dedicated network connection methods and can perform VXLAN encapsulation and IP address mapping for data packets. Specifically, the leased line gateway module includes a leased line routing module and a leased line NAT module. The leased line NAT module is decoupled from the leased line routing module in configuration. The leased line routing module is used for packet routing, while the leased line NAT module is used for encapsulating VXLAN headers and IP translation. VXLAN works by encapsulating an additional header on the original Ethernet frame. The VXLAN header contains the VXLAN network identifier. The data plane is the plane where the internal network environment is located. VPCs, CENs, switches, and leased line gateway devices can be deployed in the internal network environment. The leased line gateway device is a boundary / edge device in the internal network environment. It is a physical device that uses a dedicated network connection (cloud leased line) to communicate and transmit data packets with the cloud environment. Compared with a connection through the public Internet, it provides higher bandwidth, lower latency, and higher security.

[0078] Optionally, the above-mentioned VXLAN encapsulation and IP address translation of the first data packet via the leased line gateway module can be achieved through the following steps:

[0079] If the destination IP address of the first data packet is determined by the dedicated line routing module to be the first matching IP address that matches a certain route entry in the routing table, the dedicated line NAT module performs VXLAN encapsulation and first IP address translation on the first data packet to obtain the processed first data packet. The dedicated line routing module then forwards the processed first data packet to the dedicated line gateway device, so that the dedicated line gateway device can decapsulate the processed first data packet and transmit it to the first network device.

[0080] Understandably, after receiving the first data packet, the leased line routing module determines whether the destination IP address of the first data packet is a matching IP, or whether the virtual interface carried by the first data packet is a matching IP. A matching IP refers to the first matching IP address whose destination IP address matches a routing entry in the leased line routing module's routing table. The routing table is a table stored on a router or network device that contains a series of routing entries. If the destination IP address is a matching IP, the leased line NAT module performs VXLAN encapsulation and first IP address translation on the first data packet, resulting in a processed first data packet. Subsequently, the leased line routing module routes the processed first data packet to the leased line gateway device. That is, the first data packet enters the enterprise network's border device (such as a router or gateway device) through a cloud leased line or other dedicated connection. The leased line gateway device decapsulates the processed first data packet and forwards it to the first network device through a switch in the internal network environment.

[0081] Optionally, before performing VXLAN encapsulation and first IP address translation on the first data packet via the leased line NAT module, the method further includes:

[0082] The first set ACL rule in the downlink direction is matched to determine whether the first data packet conforms to the first security policy of the internal network environment; where downlink direction refers to the transmission of data packets from the cloud environment to the internal network environment.

[0083] Understandably, before or after VXLAN encapsulation and IP address translation, the first set ACL rule in the downlink direction is matched to determine whether the first data packet conforms to the first security policy of the internal network environment, that is, to determine whether the first data packet can be transmitted to the first network device. An ACL (Access Control List) is a security policy used to define the network resources that specific devices can access. It allows or denies specific traffic by configuring rules; for example, data packets can be filtered based on conditions such as source IP address, destination IP address, port number, and protocol type.

[0084] Optionally, the first data packet can be encapsulated using a dedicated line NAT module and the first IP address can be translated. This can be achieved through the following steps:

[0085] If the first data packet is determined to conform to the first security policy, the first data packet is encapsulated in VXLAN and the first IP address is translated through the leased line NAT module.

[0086] Understandably, if it is determined that the first data packet is allowed to be transmitted to the internal gateway device, the first data packet is encapsulated in VXLAN and IP address translated through the leased line NAT module.

[0087] The first ACL rule setting refers to the packet filtering rule set according to packet type and / or packet priority; the leased line NAT module is configured with a one-to-one IP translation rule.

[0088] Understandably, to ensure that each tenant can only access the services they are authorized to and to prevent unauthorized access, ACLs can be used to define detailed access control rules. Therefore, the leased line gateway module supports ACL functionality. ACLs are configured with priorities, which can specifically be the priority of the virtual machine that generated the first data packet. ACL rules can also be set according to the data packet type. ACL rules can be understood as data packet filtering rules used to filter incoming and outgoing data packets for NAT translation. In addition, the leased line gateway module also supports local IP translation and remote IP translation.

[0089] Understandably, the number of leased line gateway modules is not limited and can be configured according to user needs, such as one leased line gateway module for each tenant. The number of leased line routing modules and leased line NAT modules included in each leased line gateway module is also not limited. Furthermore, each leased line NAT module can build multiple one-to-one NAT rules, which only apply to the leased line. This means that both uplink and downlink data packets passing through the leased line can undergo NAT translation. Downlink supports CEN and VPC, while uplink supports external IDC and other cloud resources. In addition, the leased line NAT module is decoupled from the leased line routing module and is configured independently. This means that data packet forwarding is handled by the leased line routing module, while the leased line NAT module only performs NAT translation, thus decoupling from routing. In other words, after traffic reaches the leased line gateway module, it first matches the NAT policy in the leased line NAT module, performs VXLAN header translation, and then forwards the traffic through the leased line routing module. The collaborative work of NAT, ACL, and VXLAN enables a more flexible and secure network environment.

[0090] S303. The first data packet is transmitted to the first network device through the dedicated line gateway device.

[0091] Among them, the leased line gateway device is an edge device located in the internal network environment.

[0092] Understandably, based on the S302 above, after receiving the first data packet, the leased line gateway device transmits it to the first network device. In other words, the first data packet returns to the enterprise's network boundary through the cloud leased line gateway module. The leased line gateway device also supports routing and NAT translation functions to ensure that the data packet reaches the correct first network device. That is, after the first data packet enters the enterprise network, it can be routed to the first network device via an internal router or switch.

[0093] This disclosure provides a data packet transmission method that constructs a dedicated line gateway module in a cloud environment. This module can be deployed on any server and implements dedicated line NAT functionality in software, effectively resolving IP conflicts. It offers flexible networking options, allowing for the combination of different physical hardware and software without requiring additional dedicated physical equipment, thus achieving dedicated line NAT functionality with relatively low physical gateway costs. Furthermore, the dedicated line routing and dedicated line NAT configurations within the dedicated line gateway module are decoupled, ensuring no impact on dedicated line routing configuration distribution. Additionally, dedicated line NAT only translates the source and destination IP addresses of the dedicated line and does not affect routing policies for other resources such as VPCs, cloud enterprise networks, and destination clusters.

[0094] Based on the above embodiments, Figure 5 This is a flowchart illustrating another data packet transmission method provided in this disclosure, applied to a scenario where data packets are transmitted from an internal network environment to a cloud environment. Specifically, it includes, for example... Figure 5 Steps S501 to S503 are shown below:

[0095] S501. Obtain the second data packet generated by the second network device and to be transmitted to the third network device.

[0096] The second network device is located in an internal network environment, while the third network device is located in a cloud environment.

[0097] Understandably, a second network device within an internal network environment generates a second data packet to be transmitted to a third network device, which is a service or virtual machine located in a cloud environment. The first and second data packets differ; the first data packet can be understood as a downlink data packet, and the second data packet as an uplink data packet. The second and first network devices may be the same or different; both are physical devices or applications within the internal network environment.

[0098] S502, The second data packet is transmitted to the dedicated line gateway module through the dedicated line gateway device.

[0099] Among them, the leased line gateway device is an edge device located in the internal network environment, while the leased line gateway module is a virtual software module located in the cloud environment.

[0100] Understandably, based on the above S501, the second network device can directly transmit the second data packet to the leased line gateway device, or it can forward the second data packet to the leased line gateway device through a switch in the internal network environment. Subsequently, the leased line gateway device sends the second data packet to the leased line routing module in the leased line gateway module. Here, the leased line gateway device is a physical device located at the edge of the internal network environment, and the leased line gateway module is a virtual software module located in the cloud environment. For detailed descriptions of the leased line gateway device and the leased line gateway module, please refer to the above embodiment.

[0101] S503. The second data packet is encapsulated using VXLAN and its second IP address is translated through the leased line gateway module in order to route the second data packet to the third network device.

[0102] The second IP address translation refers to converting the source IP address of the second data packet from the private IP address of the second network device to a public IP address.

[0103] Understandably, based on the S502 described above, after receiving the second data packet, the leased line gateway module performs VXLAN encapsulation and second IP address translation on the second data packet to route it to the third network device. In other words, the leased line gateway module possesses functions such as leased line routing, VXLAN encapsulation, and leased line NAT. Specifically, the second IP address translation refers to converting the source IP address carried by the second data packet from a private IP address to a public IP address within the internal network environment to ensure network security.

[0104] Optionally, the second data packet can be encapsulated using VXLAN and its second IP address translated via a leased line gateway module to route it to a third network device. This can be achieved through the following steps:

[0105] If the source IP address of the second data packet is determined by the dedicated line routing module to be the second hit IP address that matches a certain routing entry in the routing table, the dedicated line NAT module performs VXLAN encapsulation and second IP address translation on the second data packet to obtain the processed second data packet; the dedicated line routing module then routes the processed second data packet to the third network device.

[0106] Understandably, after the leased line routing module receives the second data packet, it determines whether the source IP address is a match. If the source IP address is a match, the leased line NAT module converts the source IP address of the second data packet from a private address to a public address and encapsulates VXLAN information. The second data packet is then further processed by the leased line routing module according to its routing table and other configurations (such as ACL rules) and routed to the third gateway device.

[0107] Optionally, before performing VXLAN encapsulation and second IP address translation on the second data packet via the leased line NAT module, the method further includes:

[0108] The second set ACL rules in the uplink direction are matched to determine whether the second data packet conforms to the second security policy of the cloud environment; where uplink direction refers to the transmission of data packets from the internal network environment to the cloud environment.

[0109] Understandably, the second set ACL rules in the uplink direction are matched to determine whether the second data packet conforms to the second security policy of the cloud environment, that is, to determine whether the second data packet can be transmitted to the third network device in the cloud environment. For a detailed explanation of the ACL, please refer to the above embodiment, which will not be repeated here.

[0110] Optionally, the above-mentioned VXLAN encapsulation and second IP address translation of the second data packet via the leased line NAT module can be achieved through the following steps:

[0111] If the second data packet is determined to conform to the second security policy, the second data packet is encapsulated using VXLAN and the second IP address is translated using the leased line NAT module.

[0112] Understandably, VXLAN is used to create multiple logically isolated networks, with each tenant having its own dedicated VXLAN tunnel. NAT performs address translation for all packets on the leased line from the internal network to the external network. ACLs ensure that only packets that comply with security policies can pass through the VXLAN tunnel. ACLs are also defined on the edge device (VTEP) to control inbound and outbound packets.

[0113] One possible application scenario is that tenant A's virtual machine uses its private IP address to send data packet A. Data packet A arrives at VTEP through a VXLAN tunnel. The ACL on VTEP checks whether data packet A conforms to the preset access control rules. If data packet A conforms to the rules, it is sent to cloud service A after the private IP address is translated to a public IP address through NAT.

[0114] The data packet transmission method provided in this disclosure implements one-to-one NAT translation of IPs in a leased line through software, without requiring additional physical configurations such as firewalls and switches, and can solve the problem of inaccessibility caused by IP conflicts within the network.

[0115] Figure 6 This is a schematic diagram of the structure of a data packet transmission device provided in an embodiment of the present disclosure; Figure 6 This is a schematic diagram of a data packet transmission apparatus provided in an embodiment of the present disclosure. The data packet transmission apparatus provided in this embodiment can execute the processing flow provided in the data packet method embodiment, such as... Figure 6As shown, the device 600 includes a first acquisition unit 601, a first processing unit 602, and a first transmission unit 603, wherein:

[0116] The first acquisition unit 601 is used to acquire a first data packet to be transmitted to the first network device; wherein the first network device is located in an internal network environment;

[0117] The first processing unit 602 is used to perform VXLAN encapsulation and first IP address translation on the first data packet through the leased line gateway module; wherein, the leased line gateway module is a virtual software module in the cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to a private IP address of the first network device;

[0118] The first transmission unit 603 is used to transmit the first data packet to the first network device through a leased line gateway device; wherein the leased line gateway device is an edge device located in the internal network environment.

[0119] Optionally, the leased line gateway module in device 600 includes a leased line routing module and a leased line NAT module, with the leased line NAT module configured to be decoupled from the leased line routing module.

[0120] Optionally, the first processing unit 602 is used for:

[0121] If the destination IP address of the first data packet is determined by the dedicated line routing module to be the first matching IP address that matches a certain route entry in the routing table, the dedicated line NAT module performs VXLAN encapsulation and first IP address translation on the first data packet to obtain the processed first data packet.

[0122] The first data packet, after being processed, is forwarded to the leased line gateway device via the leased line routing module, so that the leased line gateway device can decapsulate the first data packet and transmit it to the first network device.

[0123] Optionally, device 600 is also used for:

[0124] The first set ACL rule in the downlink direction is matched to determine whether the first data packet conforms to the first security policy of the internal network environment; where downlink direction refers to the transmission of data packets from the cloud environment to the internal network environment.

[0125] Optionally, the first processing unit 602 is used for:

[0126] If the first data packet is determined to conform to the first security policy, the first data packet is encapsulated in VXLAN and the first IP address is translated through the leased line NAT module.

[0127] Optionally, the first set ACL rule in device 600 refers to a packet filtering rule set according to packet type and / or packet priority;

[0128] The dedicated line NAT module is configured with one-to-one IP translation rules.

[0129] Figure 6 The data packet transmission device shown in the embodiment can be used to execute the technical solution of the above method embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.

[0130] Figure 7 This is a schematic diagram of another data packet transmission device provided in an embodiment of the present disclosure. The data packet transmission device provided in this embodiment can execute the processing flow provided in the data packet transmission method embodiment, such as... Figure 7 As shown, the device 700 includes a second acquisition unit 701, a second transmission unit 702, and a second processing unit 703, wherein:

[0131] The second acquisition unit 701 is used to acquire the second data packet generated by the second network device and to be transmitted to the third network device; wherein the second network device is located in an internal network environment and the third network device is located in a cloud environment;

[0132] The second transmission unit 702 is used to transmit the second data packet to the leased line gateway module through the leased line gateway device; wherein, the leased line gateway device is an edge device in the internal network environment, and the leased line gateway module is a virtual software module in the cloud environment;

[0133] The second processing unit 703 is used to perform VXLAN encapsulation and second IP address translation on the second data packet through the leased line gateway module, so as to route the second data packet to the third network device; wherein, the second IP address translation refers to converting the source IP address of the second data packet from the private IP address of the second network device to the public IP address.

[0134] The dedicated line gateway module in device 700 includes a dedicated line routing module and a dedicated line NAT module, with the dedicated line NAT module configured decoupled from the dedicated line routing module.

[0135] Optionally, the second transmission unit 702 is used for:

[0136] If the source IP address of the second data packet is determined by the leased line routing module to be the second hit IP address that matches a certain route entry in the routing table, the leased line NAT module performs VXLAN encapsulation and second IP address translation on the second data packet to obtain the processed second data packet.

[0137] The processed second data packet is routed to the third network device via a dedicated line routing module.

[0138] Optionally, device 700 is used for:

[0139] The second set ACL rules in the uplink direction are matched to determine whether the second data packet conforms to the second security policy of the cloud environment; where uplink direction refers to the transmission of data packets from the internal network environment to the cloud environment.

[0140] The second data packet is encapsulated using VXLAN and its second IP address is translated via a dedicated line NAT module, including:

[0141] If the second data packet is determined to conform to the second security policy, the second data packet is encapsulated using VXLAN and the second IP address is translated using the leased line NAT module.

[0142] Figure 7 The data packet transmission device shown in the embodiment can be used to execute the technical solution of the above method embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.

[0143] Figure 8 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 8 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information of a GUI on external input / output devices (such as display devices coupled to the interfaces). In some alternative implementations, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 8 Take a processor 10 as an example.

[0144] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GDA), or any combination thereof.

[0145] The memory 20 stores instructions executable by at least one processor 10 to cause the at least one processor 10 to perform the method shown in the above embodiments.

[0146] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some alternative embodiments, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0147] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0148] The computer device also includes a communication interface 30 for communicating with other devices or communication networks.

[0149] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.

[0150] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or gateway that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or gateway. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or gateway that includes said element.

[0151] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data packet transmission method, characterized in that, The method includes: Obtain a first data packet to be transmitted to a first network device; wherein the first network device is located in an internal network environment; The first data packet is encapsulated using VXLAN and its first IP address is translated using a dedicated line gateway module. The dedicated line gateway module is a virtual software module located in a cloud environment. The first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to the private IP address of the first network device. The first data packet is transmitted to the first network device via a dedicated line gateway device; wherein, the dedicated line gateway device is an edge device located in the internal network environment.

2. The method according to claim 1, characterized in that, The leased line gateway module includes a leased line routing module and a leased line NAT module. The leased line NAT module is configured to be decoupled from the leased line routing module. The step of performing VXLAN encapsulation and first IP address translation on the first data packet through the leased line gateway module includes: If the destination IP address of the first data packet is determined by the dedicated line routing module to be the first hit IP address that matches a certain route entry in the routing table, the dedicated line NAT module performs VXLAN encapsulation and first IP address translation on the first data packet to obtain the processed first data packet. The processed first data packet is forwarded to the leased line gateway device via the leased line routing module, so that the leased line gateway device can deseal the processed first data packet and transmit it to the first network device.

3. The method according to claim 2, characterized in that, Before performing VXLAN encapsulation and first IP address translation on the first data packet through the leased line NAT module, the method further includes: The first set ACL rule in the downlink direction is matched to determine whether the first data packet conforms to the first security policy of the internal network environment; wherein, the downlink direction refers to the transmission of data packets from the cloud environment to the internal network environment; The step of performing VXLAN encapsulation and first IP address translation on the first data packet through the leased line NAT module includes: If it is determined that the first data packet conforms to the first security policy, the first data packet is encapsulated in VXLAN and the first IP address is translated by the leased line NAT module.

4. The method according to claim 3, characterized in that, The first set ACL rule refers to the packet filtering rule set according to packet type and / or packet priority; The dedicated line NAT module is configured with a one-to-one IP translation rule.

5. A data packet transmission method, characterized in that, The method includes: Acquire a second data packet generated by a second network device and to be transmitted to a third network device; wherein the second network device is located in an internal network environment and the third network device is located in a cloud environment; The second data packet is transmitted to the dedicated line gateway module via a dedicated line gateway device; wherein, the dedicated line gateway device is an edge device located in the internal network environment, and the dedicated line gateway module is a virtual software module located in the cloud environment; The leased line gateway module performs VXLAN encapsulation and second IP address translation on the second data packet to route the second data packet to the third network device; wherein, the second IP address translation refers to converting the source IP address of the second data packet from the private IP address of the second network device to a public IP address.

6. The method according to claim 5, characterized in that, The leased line gateway module includes a leased line routing module and a leased line NAT module. The leased line NAT module is configured to be decoupled from the leased line routing module. The step of performing VXLAN encapsulation and second IP address translation on the second data packet through the leased line gateway module to route the second data packet to the third network device includes: If the source IP address of the second data packet is determined by the dedicated line routing module to be a second hit IP address that matches a certain route entry in the routing table, the dedicated line NAT module performs VXLAN encapsulation and second IP address translation on the second data packet to obtain the processed second data packet. The processed second data packet is routed to the third network device via the dedicated line routing module.

7. The method according to claim 6, characterized in that, Before performing VXLAN encapsulation and second IP address translation on the second data packet through the leased line NAT module, the method further includes: The second set ACL rule in the uplink direction is matched to determine whether the second data packet conforms to the second security policy of the cloud environment; wherein, the uplink direction refers to the transmission of data packets from the internal network environment to the cloud environment; The step of performing VXLAN encapsulation and second IP address translation on the second data packet through the leased line NAT module includes: If it is determined that the second data packet conforms to the second security policy, the second data packet is encapsulated using VXLAN and then translated to a second IP address using the leased line NAT module.

8. A data packet transmission device, characterized in that, The device includes: The first acquisition unit is used to acquire a first data packet to be transmitted to the first network device; wherein the first network device is located in an internal network environment; The first processing unit is used to perform VXLAN encapsulation and first IP address translation on the first data packet through a leased line gateway module; wherein, the leased line gateway module is a virtual software module in a cloud environment, and the first IP address translation refers to converting the destination IP address of the first data packet from a public IP address to a private IP address of the first network device. The first transmission unit is used to transmit the first data packet to the first network device through a leased line gateway device; wherein the leased line gateway device is an edge device located in the internal network environment.

9. A data packet transmission device, characterized in that, The device includes: The second acquisition unit is used to acquire a second data packet generated by the second network device and to be transmitted to the third network device; wherein the second network device is located in an internal network environment and the third network device is located in a cloud environment; The second transmission unit is used to transmit the second data packet to the dedicated line gateway module through the dedicated line gateway device; wherein, the dedicated line gateway device is an edge device located in the internal network environment, and the dedicated line gateway module is a virtual software module located in the cloud environment; The second processing unit is used to perform VXLAN encapsulation and second IP address translation on the second data packet through the leased line gateway module, so as to route the second data packet to the third network device; wherein, the second IP address translation refers to converting the source IP address of the second data packet from the private IP address of the second network device to the public IP address.

10. An electronic device, characterized in that, include: Memory; processor; as well as Computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the data packet transmission method as described in any one of claims 1 to 7.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the data packet transmission method as described in any one of claims 1 to 7.