Data sending method, apparatus, device, and storage medium

CN122554261APending Publication Date: 2026-08-11BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

IPv4最大的问题在于网络地址资源不足,严重制约了互联网的应用和发展

Benefits of technology

[0069]Compared with the prior art, the technical solution provided in this application has the following advantages: In this application embodiment, a Virtual Extensible Local Area Network (VXLAN) data packet sent by a Virtual Private Cloud (VPC) gateway is received; the received VXLAN data packet is parsed to obtain an initial data packet and a VXLAN network identifier; the target gateway of the target network is determined based on the VXLAN network identifier; and the initial data packet is sent to the target network through the target gateway. The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is the data packet to be sent to the target network, and the IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located. Therefore, this application embodiment can realize data communication between a VPC in an IPv6 domain and a network in another IPv6 domain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122554261A_ABST
    Figure CN122554261A_ABST
Patent Text Reader

Abstract

This application relates to a data transmission method, apparatus, device, and storage medium. The method is applied to a VPN network device supporting the IPv6 protocol and includes: receiving a Virtual Extensible Local Area Network (VXLAN) data packet sent by a Virtual Private Cloud (VPC) gateway; parsing the VXLAN data packet to obtain an initial data packet and a VXLAN network identifier; determining a target gateway for a target network based on the VXLAN network identifier; and sending the initial data packet to the target network through the target gateway. The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain of the VPC gateway and the IPv6 domain of the target network are different. This method enables data communication between a VPC in an IPv6 domain and networks in other IPv6 domains.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a data transmission method, apparatus, device, and storage medium. Background Technology

[0002] IPv6 (Internet Protocol Version 6) is the next-generation IP protocol designed to replace IPv4 (Internet Protocol Version 4). The biggest problem with IPv4 is the insufficient number of network address resources, which severely restricts the application and development of the Internet. The use of IPv6 not only solves the problem of the limited number of network address resources but also removes obstacles for various access devices to connect to the Internet.

[0003] Current VPN devices only support message communication between different IPv4 domains. With the increasing prevalence of Virtual Private Clouds (VPCs), the shortage of IPv4 domain address resources is becoming increasingly serious. Setting up VPCs in IPv6 domains has become a trend and a necessity. Therefore, there is an urgent need for a method to enable data communication between VPCs and networks set up in other IPv6 domains. Summary of the Invention

[0004] This application provides a data transmission method, apparatus, device, and storage medium that enables data communication between a VPC in an IPv6 domain and networks in other IPv6 domains.

[0005] In a first aspect, this application provides a data transmission method, the method being applied to a VPN network device supporting the IPv6 protocol, comprising:

[0006] Receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway;

[0007] The VXLAN data packet is parsed to obtain the initial data packet and the VXLAN network identifier;

[0008] Based on the VXLAN network identifier, determine the target gateway of the target network;

[0009] The initial data packet is sent to the target network through the target gateway;

[0010] The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

[0011] Optionally, the VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier, specifically:

[0012] Obtain the predefined association between networks and network identifiers;

[0013] Based on the target network and the association relationship, determine the VXLAN network identifier corresponding to the target network;

[0014] Based on the VXLAN network identifier, a VXLAN header is generated, and the VXLAN header and the initial data packet are combined to obtain a VXLAN data packet.

[0015] Optionally, the VPN network device includes a VPN gateway cluster, and the step of parsing the VXLAN data packets to obtain the initial data packets and the VXLAN network identifier includes:

[0016] Obtain the first virtual VIP from the attribute data in the VPN gateway cluster;

[0017] Based on the VXLAN data packet, the second VIP corresponding to the VXLAN data packet is obtained;

[0018] The first VIP and the second VIP are compared to obtain the comparison results;

[0019] When the comparison results are the same, the VXLAN data packet is sent to each VPN gateway in the VPN gateway cluster so that the VPN gateway can obtain the initial data packet and VXLAN network identifier from the VXLAN data packet.

[0020] Optionally, sending the VXLAN data packet to each VPN gateway in the VPN gateway cluster includes:

[0021] Retrieve pre-stored traffic distribution strategies;

[0022] According to the traffic distribution strategy, the VXLAN data packets are distributed to each VPN gateway.

[0023] Optionally, the VPN network device includes an IPv6 switch, and the step of sending the initial data packet to the target network through the target gateway includes:

[0024] Obtain routing information related to traffic from each VPN gateway;

[0025] Based on the routing information, monitor whether the routing on the IPv6 switch is effective, and adjust the routing information accordingly;

[0026] Based on the adjusted routing information, determine the effective path to the target gateway;

[0027] The initial data packet is sent to the target network through the effective path.

[0028] Optionally, the routing information includes a VXLAN network identifier, and obtaining traffic-related routing information from each VPN gateway includes:

[0029] Obtain the VPN control plane management attribute corresponding to the target data packet;

[0030] Based on the VPN control plane management attributes, select the VXLAN interface exclusively used by the VPN gateway, and obtain the VXLAN network identifier in the VPN gateway through the VXLAN interface.

[0031] Optionally, receive VXLAN packets sent by the VPC gateway, including:

[0032] Receive VXLAN data packets sent by the VPC gateway through a VXLAN tunnel, wherein the VXLAN tunnel corresponds to the VXLAN network identifier.

[0033] Secondly, this application provides a data transmission apparatus, which is a VPN network device supporting the IPv6 protocol, comprising:

[0034] The receiving unit is used to receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway.

[0035] The parsing unit is used to parse the VXLAN data packet to obtain the initial data packet and the VXLAN network identifier;

[0036] The determining unit is configured to determine the target gateway of the target network based on the VXLAN network identifier;

[0037] A sending unit is configured to send the initial data packet to the target network via the target gateway;

[0038] The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

[0039] Optionally, the apparatus further includes a generation unit, the generation unit being used for:

[0040] Obtain the predefined association between networks and network identifiers;

[0041] Based on the target network and the association relationship, determine the VXLAN network identifier corresponding to the target network;

[0042] Based on the VXLAN network identifier, a VXLAN header is generated, and the VXLAN header and the initial data packet are combined to obtain a VXLAN data packet.

[0043] Optionally, the VPN network device includes a VPN gateway cluster, and the resolution unit is used for:

[0044] Obtain the first virtual VIP from the attribute data in the VPN gateway cluster;

[0045] Based on the VXLAN data packet, the second VIP corresponding to the VXLAN data packet is obtained;

[0046] The first VIP and the second VIP are compared to obtain the comparison results;

[0047] When the comparison results are the same, the VXLAN data packet is sent to each VPN gateway in the VPN gateway cluster so that the VPN gateway can obtain the initial data packet and VXLAN network identifier from the VXLAN data packet.

[0048] Optionally, the parsing unit is used for:

[0049] Retrieve pre-stored traffic distribution strategies;

[0050] According to the traffic distribution strategy, the VXLAN data packets are distributed to each VPN gateway.

[0051] Optionally, the VPN network device includes an IPv6 switch, and the sending unit is used for:

[0052] Obtain routing information related to traffic from each VPN gateway;

[0053] Based on the routing information, monitor whether the routing on the IPv6 switch is effective, and adjust the routing information accordingly;

[0054] Based on the adjusted routing information, determine the effective path to the target gateway;

[0055] The initial data packet is sent to the target network through the effective path.

[0056] Optionally, the routing information includes a VXLAN network identifier, and the sending unit is used for:

[0057] Obtain the VPN control plane management attribute corresponding to the target data packet;

[0058] Based on the VPN control plane management attributes, select the VXLAN interface exclusively used by the VPN gateway, and obtain the VXLAN network identifier in the VPN gateway through the VXLAN interface.

[0059] Optional, receiving unit, used for:

[0060] Receive VXLAN data packets sent by the VPC gateway through a VXLAN tunnel, wherein the VXLAN tunnel corresponds to the VXLAN network identifier.

[0061] Thirdly, this application provides a data transmission device, comprising: at least one communication interface; at least one bus connected to the at least one communication interface; at least one processor connected to the at least one bus; and at least one memory connected to the at least one bus, wherein the processor is configured to:

[0062] The method is applied to VPN network devices that support the IPv6 protocol, including:

[0063] Receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway;

[0064] The VXLAN data packet is parsed to obtain the initial data packet and the VXLAN network identifier;

[0065] Based on the VXLAN network identifier, determine the target gateway of the target network;

[0066] The initial data packet is sent to the target network through the target gateway;

[0067] The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

[0068] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described data transmission method.

[0069] Compared with the prior art, the technical solution provided in this application has the following advantages: In this application embodiment, a Virtual Extensible Local Area Network (VXLAN) data packet sent by a Virtual Private Cloud (VPC) gateway is received; the received VXLAN data packet is parsed to obtain an initial data packet and a VXLAN network identifier; the target gateway of the target network is determined based on the VXLAN network identifier; and the initial data packet is sent to the target network through the target gateway. The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is the data packet to be sent to the target network, and the IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located. Therefore, this application embodiment can realize data communication between a VPC in an IPv6 domain and a network in another IPv6 domain. Attached Figure Description

[0070] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0071] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0072] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.

[0073] Figure 1 This is a schematic diagram of the structure of a data transmission method provided in an embodiment of this application;

[0074] Figure 2 A flowchart illustrating a data transmission method provided in an embodiment of this application;

[0075] Figure 3 A flowchart illustrating a VXLAN packet determination method provided in an embodiment of this application;

[0076] Figure 4 This is a schematic diagram of the structure of a VPN network device method provided in an embodiment of this application;

[0077] Figure 5 A flowchart illustrating another data packet detection method provided in this application embodiment;

[0078] Figure 6A flowchart illustrating a data distribution method provided in an embodiment of this application;

[0079] Figure 7 A flowchart illustrating a network identifier sending method provided in an embodiment of this application;

[0080] Figure 8 A flowchart illustrating a method for determining an effective path provided in an embodiment of this application;

[0081] Figure 9 This is a schematic flowchart of a data transmission device provided in an embodiment of this application;

[0082] Figure 10 This is a schematic diagram of a data transmission device provided in an embodiment of this application. Detailed Implementation

[0083] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0084] The following disclosure provides numerous different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of the invention. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.

[0085] IPv6 is the next-generation IP protocol designed to replace IPv4. The biggest problem with IPv4 is the insufficient number of network address resources, which severely restricts the application and development of the Internet. The use of IPv6 not only solves the problem of insufficient network address resources but also removes obstacles for various access devices to connect to the Internet. Currently, VPN devices only support message communication between different IPv4 domains. With the widespread development of Virtual Private Clouds (VPCs), the problem of insufficient IPv4 domain address resources is becoming increasingly serious, making VPCs set up in IPv6 domains a trend and a necessity. Therefore, there is an urgent need for a method for VPCs to communicate with networks set up in other IPv6 domains.

[0086] To address the aforementioned problems, this application provides a data transmission method, which is applied to... Figure 1 In the structure described. Figure 1The sending end in the example is the VPC gateway in the IPv6 domain. The VPC gateway is a device in the VPC network that exchanges data with external networks. When the device receives the initial data packet to be sent out, it indicates that the initial data packet needs to be sent to other networks. At this time, the VPC gateway processes the initial data packet to obtain a VXLAN data packet, and then sends the VXLAN data packet to the VPN network device so that the VPN network device can forward the VXLAN data packet to other networks. Figure 1 The receiving end can be a VPC gateway in another IPv6 domain, or an IDC (Internet Data Center) gateway in another IPv6 domain; there are no limitations here. In this way, the initial data packet can be sent from the VPC to other IPv6 domains using the above method.

[0087] based on Figure 1 The illustrated diagram illustrates a data transmission method provided in this application embodiment. This method enables communication between a VPC in an IPv6 domain and networks in other IPv6 domains, such as... Figure 1 As shown, the specific steps include:

[0088] Step 201: Receive VXLAN data packets sent by the VPC gateway.

[0089] Among them, the VPC gateway is the gateway in the Virtual Private Cloud (VPC). The VPC gateway is a key component connecting the Virtual Private Cloud with the external network. In other words, all data packets sent to the outside world will pass through the VPC gateway.

[0090] VXLAN packets are derived from an initial packet and a VXLAN network identifier. The initial packet is the data packet to be sent to the target network. That is, after the VPC gateway receives the initial packet, it needs to process it to obtain the VXLAN packet. The VXLAN network identifier is the VNI (VXLAN Network Identifier), which is essentially a network identifier in VXLAN (Virtual Xtensible Local Area Network) used to determine the VXLAN tunnel to be used and the target network.

[0091] The IPv6 domain where the virtual private cloud resides is different from the IPv6 domain where the target network resides. An IPv6 domain refers to a logical area in a network environment that uses the IPv6 protocol for communication. Within this logical area, devices communicate with each other and transmit data using IPv6 addresses and the IPv6 protocol stack.

[0092] In this step, when the VPC gateway detects the initial data packet, it can parse the packet to obtain its destination address. Then, based on the destination address and the mapping between addresses and network identifiers, the VXLAN network identifier is obtained. Afterward, the VPC gateway can generate a VXLAN data packet based on the initial data packet and the VXLAN network identifier, and send this VXLAN data packet to the VPN network device so that the VPN network device can receive the target data packet.

[0093] Furthermore, since the VXLAN network identifier is a VNI identifier, which is used to determine the VXLAN tunnel to be used, the tunnel to be used can also be determined based on the target network identifier. This allows the VPC gateway to send target data packets to the VPN network device through that tunnel. The VPN network device then receives the VXLAN data packets sent by the VPC gateway through the VXLAN tunnel.

[0094] Among them, VPN network devices are network devices that support the IPv6 protocol, including VPN gateways, route reflectors, and switches, all of which support the IPv6 protocol.

[0095] Step 202: Parse the VXLAN data packet to obtain the initial data packet and the VXLAN network identifier.

[0096] In this step, the VPN network device parses the VXLAN packet to obtain the initial packet and the VXLAN network identifier.

[0097] Step 203: Determine the target gateway of the target network based on the VXLAN network identifier.

[0098] The target gateway is the gateway through which the target network exchanges data with external networks. When the target network is a VPC, the target gateway is the VPC gateway; when the target network is an IDC, the target gateway is the IDC gateway.

[0099] In this step, the VPN network device stores the mapping between VXLAN network identifiers and gateways, so that the VPN network device can determine the target gateway of the target network based on the VXLAN network identifier and the mapping.

[0100] Step 204: Send the initial data packet to the target network through the target gateway.

[0101] In this step, the VPN network device can plan a path to the target gateway based on the target gateway, and then send the initial data packet to the target gateway through this path, so that the target gateway can send the initial data packet to the gateway of the target network, thereby sending the initial data packet to the target network.

[0102] In this embodiment, a Virtual Extensible Local Area Network (VXLAN) data packet sent by a Virtual Private Cloud (VPC) gateway is received; the received VXLAN data packet is parsed to obtain an initial data packet and a VXLAN network identifier; based on the VXLAN network identifier, the target gateway of the target network is determined; and the initial data packet is sent to the target network through the target gateway. The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is the data packet to be sent to the target network, and the IPv6 domain of the VPC gateway and the IPv6 domain of the target network are different. Therefore, this embodiment can realize data communication between a VPC in an IPv6 domain and a network in another IPv6 domain.

[0103] In this embodiment, since the VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier, the VPC gateway can analyze the initial data packet after obtaining it to obtain the VXLAN network identifier to be used, and then obtain the VXLAN data packet based on the initial data packet and the VXLAN network identifier. This application provides a VXLAN data packet determination method, as follows: Figure 3 As shown, the specific steps include:

[0104] Step 301: Obtain the preset association between networks and network identifiers.

[0105] The VPC gateway stores routing information, which includes the association between networks and network identifiers. When this step is required, the VPC gateway can access the network-network identifier associations within the routing information.

[0106] It should be noted that this application can distinguish different virtual networks using VXLAN network identifiers. In practical use, networks are usually divided based on factors such as business needs and tenant isolation. To achieve this division, this application establishes a relationship between networks and VXLAN network identifiers, and then accurately finds the corresponding VXLAN network identifier based on the target network.

[0107] For example, in a data center network, there are multiple enterprise tenants, and each tenant's servers may be distributed across different subnets. To isolate the network traffic of tenant A from that of tenant B, different VNIs are associated with tenant A's subnet and tenant B's subnet. When data needs to be sent to a specific subnet of tenant A, the corresponding VXLAN network identifier can be found through this association.

[0108] Step 302: Determine the VXLAN network identifier corresponding to the target network based on the target network and its association.

[0109] In this step, the VPC gateway can determine the VXLAN network identifier to be used based on the target network and its associations, so as to determine the VXLAN tunnel to be used based on the VXLAN network identifier, and then use the VXLAN tunnel to transmit data.

[0110] Specifically, the destination address in the initial data packet can be obtained, and the corresponding target network can be represented by the destination address. Then, the association between the address and the network identifier can be obtained from the stored routing information. Finally, based on the destination address and the association, the VXLAN network identifier to be used, that is, the VXLAN network identifier corresponding to the target network, can be determined.

[0111] Step 303: Generate a VXLAN header based on the VXLAN network identifier, and combine the VXLAN header with the initial data packet to obtain a VXLAN data packet.

[0112] In this step, the VPC gateway can fill the VXLAN network identifier into the preset fields in the VXLAN header to obtain the VXLAN header. Then, the VXLAN header is combined with the initial data packet in sequence to obtain the VXLAN data packet.

[0113] It's important to note that combining the VXLAN header and the initial data packet to form a VXLAN data packet is a complete encapsulation process. This encapsulates the initial data packet within a VXLAN packet with a VXLAN identifier, allowing it to be transmitted over VXLAN-enabled networks. When network devices forward this packet, they only need to route it based on the outer IP address and other information, without needing to know the specific content of the encapsulated initial data packet, until the packet reaches its destination and is decapsulated.

[0114] In the embodiments of this application, such as Figure 4 As shown, the VPN network device includes a VPN gateway cluster, which combines multiple VPN gateways to form a unified and more powerful logical gateway system through clustering technology. These VPN gateways work together to present a single VPN access point (VIP) to the outside world, thereby enhancing the performance, reliability, and scalability of the VPN service. The VPN network device can receive VXLAN packets sent by the VPC gateway and then process the VXLAN packets accordingly. For example, the VPN gateway cluster can first detect whether the received VXLAN packet is a packet it needs to process. If the packet is a packet it needs to process, it processes the packet accordingly. Therefore, this application embodiment provides a packet detection method, which is as follows: Figure 5 As shown, the specific steps include:

[0115] Step 501: Obtain the first VIP from the attribute data in the VPN gateway cluster.

[0116] The VIP (Virtual IP) serves as the unified entry point for external users to access the VPN gateway cluster. External clients only need to connect to this VIP and do not need to know the IP address of the specific gateway device inside the cluster to achieve the purpose of accessing the VPN gateway cluster.

[0117] In this step, the VPN gateway cluster stores its own attribute data, which includes the cluster's VIP. The VPN gateway cluster will then retrieve its own VIP from its stored attribute data and identify it as the first VIP.

[0118] Step 502: Obtain the second VIP corresponding to the VXLAN data packet based on the VXLAN data packet.

[0119] In this step, the VPN gateway cluster can parse the VXLAN data packets to obtain the VXLAN network identifiers included in them. Based on the VXLAN network identifiers and the preset association between identifiers and VIPs, the VIP corresponding to the VXLAN network identifiers is determined, and the VIP is designated as the second VIP.

[0120] Step 503: Compare the first VIP and the second VIP to obtain the comparison result.

[0121] In this step, the first VIP and the second VIP are compared to obtain the comparison result. When the comparison result is the same, it means that the VPN gateway cluster needs to further process the VXLAN packet and continue the operation. When the comparison result is different, it means that the VPN gateway cluster does not need to further process the VXLAN packet and the VXLAN packet can be discarded.

[0122] Step 504: When the comparison results are the same, the VXLAN packet is sent to each VPN gateway in the VPN gateway cluster so that the VPN gateway can obtain the initial packet and VXLAN network identifier in the VXLAN packet.

[0123] In this step, when the comparison results are the same, the VXLAN packets can be evenly distributed to each VPN gateway in the VPN gateway cluster, or they can be distributed to each VPN gateway according to a certain distribution strategy; the specific distribution strategy is not limited. Each VPN gateway then retrieves the initial packet and VXLAN network identifier from the VXLAN packet.

[0124] In this embodiment, the VPN gateway cluster pre-stores a data distribution strategy, which allows VXLAN data packets to be sent to each VPN gateway in the cluster according to the strategy. Therefore, this embodiment provides a data distribution method, such as... Figure 6 As shown, the specific steps include:

[0125] Step 601: Obtain the pre-stored data distribution strategy.

[0126] In this step, the VPN gateway cluster stores a data distribution policy. When this step needs to be executed, the VPN gateway cluster can obtain the pre-stored data distribution policy and distribute VXLAN packets according to the data distribution policy.

[0127] For example, the data distribution strategy can be a source-based data distribution strategy, a load-balanced data distribution strategy, or other data distribution strategies; there are no limitations here.

[0128] For example, each time a VPN gateway cluster receives a data packet, it determines the network from which the packet originated. Based on this network and the association between the network and the VPN gateways, it determines the VPN gateway to process the packet. For instance, the VPN gateways corresponding to network 1 are gateway 1, gateway 2, and network 3, while the VPN gateways corresponding to network 2 are gateway 4 and gateway 5. When a VXLAN packet is detected to originate from network 2, it is forwarded to gateway 4 and gateway 5.

[0129] Since the above method assigns data packets from a specific network to a specific VPN gateway for processing, data packets from an IPv6 domain can also be assigned to a specific VPN gateway. In this way, only these specific VPN gateways need to support the IPv6 protocol, and it is not necessary for all VPN gateways in the VPN gateway cluster to support the IPv6 protocol. This makes full use of devices that do not support the IPv6 protocol and reduces resource waste.

[0130] Step 602: Distribute VXLAN packets to each VPN gateway according to the data distribution policy.

[0131] In this step, the VPN gateway cluster can distribute VXLAN packets to each VPN gateway according to the data distribution policy.

[0132] like Figure 4As shown, VPN network equipment includes an IPv6 route reflector and an IPv6 switch. The IPv6 route reflector is a device or functional component used to optimize and control the propagation of routing information in an IPv6 network environment. It allows routing information learned from its client routers to be reflected back to other routers, instead of exchanging routing information according to the traditional fully connected interior gateway protocol peer relationship. The IPv6 switch is a switch that supports the IPv6 protocol. This switch is used to forward data frames in an IPv6-based network environment. It can identify and process data frames containing IPv6 packets and forward data frames from one port to another based on the destination address and other configuration information in the data frame. Based on the above, multiple IPv6 routes form a route reflection cluster, and multiple IPv6 switches form a switch cluster, such as... Figure 4 As shown, the route reflection cluster connects to the VPN gateway cluster to the north and to the switch cluster to the south. Simultaneously, the route reflection cluster establishes a VPN gateway-level EVPN (Ethernet Virtual Private Network) environment with the southbound switch cluster, learning the effective isolated route configurations from the switches to determine valid paths.

[0133] In this embodiment, after the VPN gateway sends the VXLAN network identifier to the IPv6 route reflector, a valid path to the target gateway is determined in the EVPN environment, and then the initial data packet is sent to the target network through this valid path. Therefore, this embodiment provides a method for determining a valid path, as follows: Figure 7 As shown, the specific steps include:

[0134] Step 701: Receive traffic-related routing information from each VPN gateway.

[0135] The routing information includes the network prefix, next-hop address, and other data related to traffic forwarding, as well as the VXLAN network identifier obtained by each VPN gateway.

[0136] In this step, by running routing protocols such as EVPN in the EVPN environment, a connection is established between the IPv6 route reflector and each VPN gateway, enabling each VPN gateway to send its own routing information to the IPv6 route reflector. In this way, by collecting comprehensive routing information, the IPv6 route reflector can understand the entire network topology and reachability.

[0137] Step 702: Monitor the IPv6 switch to see if the routing information is effective, and adjust the routing information accordingly.

[0138] In this step, a preset monitoring mechanism is used to monitor the routing status on the IPv6 switch. When a route is found to be ineffective, the routing information in the system can be adjusted by re-announcing the route information or adjusting the routing policy. For example, if an important branch network route is found to be ineffective on the IPv6 switch, the route reflector can increase the priority of the route and re-announce it to the IPv6 switch, prompting it to learn and apply the route.

[0139] Step 703: Determine the valid path to the target gateway based on the adjusted routing information.

[0140] In this step, since the VXLAN interface can determine the target gateway, the effective path to the target gateway can be determined based on the adjusted routing information. Specifically, the path corresponding to each route can be calculated using a path calculation algorithm, and these paths can be identified as effective paths. Alternatively, based on strategies such as shortest path priority, the optimal path can be determined among these paths, and then that optimal path can be selected as the final effective path. Other methods can also be used to determine the effective path; this is not limited to these methods.

[0141] Step 704: Send the initial data packet to the target network through a valid path.

[0142] In this step, the IPv6 route reflector can send the valid path to the VPN gateway, which then sends the initial data packet to the target network according to the valid path.

[0143] Based on the above, the VPN gateway also needs to send the obtained VXLAN network identifier to the IPv6 route reflector so that, in the EVPN environment, it can learn the effective isolated route configuration and obtain a valid transmission path. Therefore, this application embodiment provides a network identifier transmission method, which is as follows: Figure 8 As shown, the specific steps include:

[0144] Step 801: Obtain the VPN control plane management attributes corresponding to the initial data packet.

[0145] Among these, VPN control plane management attributes mainly involve VPN management and control information, including data on network topology, device connectivity, routing policies, and other aspects. Based on this data, the role and responsibilities of VPN gateways in the network, as well as the network scope they manage, can be clearly defined.

[0146] Step 802: Based on the VPN control plane management attributes, select the VXLAN interface exclusively used by the VPN gateway, and obtain the VXLAN network identifier in the VPN gateway through the VXLAN interface.

[0147] In this step, VPN control plane management attributes are a set of rules and parameters used to manage and control VPN networks. It includes key information such as network access policies, routing policies, and device connectivity relationships. This key information is used to determine the functions and responsibilities of these VPN gateways, including the interfaces within these VPN gateways specifically used to send VXLAN network identifiers. These interfaces are designated as VXLAN interfaces, and based on these VXLAN interfaces, the VXLAN network identifiers are sent to the corresponding IPv6 route reflectors.

[0148] In practice, different interfaces may perform different functions. Some interfaces may be shared for access by multiple services or user groups, while others may be dedicated interfaces set up specifically for a particular VPN gateway. Therefore, this step requires selecting a dedicated VXLAN interface for the VPN gateway based on the VPN control plane management attributes, and then sending the VXLAN network identifier to the corresponding IPv6 route reflector based on that VXLAN interface.

[0149] like Figure 9 As shown, this application embodiment provides a data transmission device, which corresponds to the method embodiment, and specifically includes:

[0150] Receiving unit 901 is used to receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway;

[0151] The parsing unit 902 is used to parse the VXLAN data packet to obtain the initial data packet and the VXLAN network identifier;

[0152] The determining unit 903 is used to determine the target gateway of the target network based on the VXLAN network identifier;

[0153] The sending unit 904 is used to send the initial data packet to the target network through the target gateway;

[0154] The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

[0155] Optionally, the apparatus further includes a generation unit 905, the generation unit 905 being used for:

[0156] Obtain the predefined association between networks and network identifiers;

[0157] Based on the target network and the association relationship, determine the VXLAN network identifier corresponding to the target network;

[0158] Based on the VXLAN network identifier, a VXLAN header is generated, and the VXLAN header and the initial data packet are combined to obtain a VXLAN data packet.

[0159] Optionally, the VPN network device includes a VPN gateway cluster, and the parsing unit 902 is used for:

[0160] Obtain the first virtual VIP from the attribute data in the VPN gateway cluster;

[0161] Based on the VXLAN data packet, the second VIP corresponding to the VXLAN data packet is obtained;

[0162] The first VIP and the second VIP are compared to obtain the comparison results;

[0163] When the comparison results are the same, the VXLAN data packet is sent to each VPN gateway in the VPN gateway cluster so that the VPN gateway can obtain the initial data packet and VXLAN network identifier from the VXLAN data packet.

[0164] Optionally, the parsing unit 902 is used for:

[0165] Retrieve pre-stored traffic distribution strategies;

[0166] According to the traffic distribution strategy, the VXLAN data packets are distributed to each VPN gateway.

[0167] Optionally, the VPN network device includes an IPv6 switch, and the sending unit 904 is used for:

[0168] Obtain routing information related to traffic from each VPN gateway;

[0169] Based on the routing information, monitor whether the routing on the IPv6 switch is effective, and adjust the routing information accordingly;

[0170] Based on the adjusted routing information, determine the effective path to the target gateway;

[0171] The initial data packet is sent to the target network through the effective path.

[0172] Optionally, the routing information includes a VXLAN network identifier, and the sending unit 904 is used for:

[0173] Obtain the VPN control plane management attribute corresponding to the target data packet;

[0174] Based on the VPN control plane management attributes, select the VXLAN interface exclusively used by the VPN gateway, and obtain the VXLAN network identifier in the VPN gateway through the VXLAN interface.

[0175] Optionally, the receiving unit 901 is used for:

[0176] Receive VXLAN data packets sent by the VPC gateway through a VXLAN tunnel, wherein the VXLAN tunnel corresponds to the VXLAN network identifier.

[0177] like Figure 10 As shown in the figure, this application embodiment provides a data transmission device, including a processor 1001, a communication interface 1002, a memory 1003, and a communication bus 1004, wherein the processor 1001, the communication interface 1002, and the memory 1003 communicate with each other through the communication bus 1004.

[0178] Memory 1003 is used to store computer programs;

[0179] In one embodiment of this application, when the processor 1001 executes a program stored in the memory 1003, it implements the data transmission method provided in any of the foregoing method embodiments, including:

[0180] Receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway;

[0181] The VXLAN data packet is parsed to obtain the initial data packet and the VXLAN network identifier;

[0182] Based on the VXLAN network identifier, determine the target gateway of the target network;

[0183] The initial data packet is sent to the target network through the target gateway;

[0184] The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

[0185] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps performed by the data transmission method provided in any of the foregoing method embodiments.

[0186] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0187] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented using software plus a general-purpose hardware platform, or of course, using hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0188] It should be understood that the terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also include the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in a particular order described or illustrated unless the order of performance is explicitly indicated. It should also be understood that additional or alternative steps may be used.

[0189] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A data transmission method, characterized in that, The method includes: Receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway; The VXLAN data packet is parsed to obtain the initial data packet and the VXLAN network identifier; Based on the VXLAN network identifier, determine the target gateway of the target network; The initial data packet is sent to the target network through the target gateway; The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

2. The method according to claim 1, characterized in that, The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier, specifically: Obtain the predefined association between networks and network identifiers; Based on the target network and the association relationship, determine the VXLAN network identifier corresponding to the target network; Based on the VXLAN network identifier, a VXLAN header is generated, and the VXLAN header and the initial data packet are combined to obtain a VXLAN data packet.

3. The method according to claim 1, characterized in that, The VPN network device includes a VPN gateway cluster. The step of parsing the VXLAN data packets to obtain the initial data packet and the VXLAN network identifier includes: Obtain the first virtual VIP from the attribute data in the VPN gateway cluster; Based on the VXLAN data packet, the second VIP corresponding to the VXLAN data packet is obtained; The first VIP and the second VIP are compared to obtain the comparison results; When the comparison results are the same, the VXLAN data packet is sent to each VPN gateway in the VPN gateway cluster so that the VPN gateway can obtain the initial data packet and VXLAN network identifier from the VXLAN data packet.

4. The method according to claim 3, characterized in that, Sending the VXLAN data packet to each VPN gateway in the VPN gateway cluster includes: Retrieve pre-stored traffic distribution strategies; According to the traffic distribution strategy, the VXLAN data packets are distributed to each VPN gateway.

5. The method according to claim 1, characterized in that, The VPN network device includes an IPv6 switch, and the step of sending the initial data packet to the target network through the target gateway includes: Obtain routing information related to traffic from each VPN gateway; Based on the routing information, monitor whether the routing on the IPv6 switch is effective, and adjust the routing information accordingly; Based on the adjusted routing information, determine the effective path to the target gateway; The initial data packet is sent to the target network through the effective path.

6. The method according to claim 5, characterized in that, The routing information includes the VXLAN network identifier, and obtaining traffic-related routing information from each VPN gateway includes: Obtain the VPN control plane management attribute corresponding to the target data packet; Based on the VPN control plane management attributes, select the VXLAN interface exclusively used by the VPN gateway, and obtain the VXLAN network identifier in the VPN gateway through the VXLAN interface.

7. The method according to claim 1, characterized in that, Receive VXLAN packets sent by the VPC gateway, including: Receive VXLAN data packets sent by the VPC gateway through a VXLAN tunnel, wherein the VXLAN tunnel corresponds to the VXLAN network identifier.

8. A data transmission device, characterized in that, The device is a VPN network device that supports the IPv6 protocol, including: The receiving unit is used to receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway. The parsing unit is used to parse the VXLAN data packet to obtain the initial data packet and the VXLAN network identifier; The determining unit is configured to determine the target gateway of the target network based on the VXLAN network identifier; A sending unit is configured to send the initial data packet to the target network via the target gateway; The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

9. A data transmission device, characterized in that, include: At least one communication interface; At least one bus connected to the at least one communication interface; at least one processor connected to the at least one bus; At least one memory connected to the at least one bus, wherein the processor is configured to: Receive Virtual Extensible Local Area Network (VXLAN) data packets sent by the Virtual Private Cloud (VPC) gateway; The VXLAN data packet is parsed to obtain the initial data packet and the VXLAN network identifier; Based on the VXLAN network identifier, determine the target gateway of the target network; The initial data packet is sent to the target network through the target gateway; The VXLAN data packet is obtained based on the initial data packet and the VXLAN network identifier. The initial data packet is a data packet to be sent to the target network. The IPv6 domain where the VPC gateway is located is different from the IPv6 domain where the target network is located.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the data transmission method according to any one of claims 1 to 7.