Communication and configuration method of virtual private cloud and related device
The method bridges communication between VPCs with overlapping addresses using a third VPC with unique addresses, enabling seamless data exchange by address translation and routing.
Patent Information
- Application Number
- JP2022507499
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-31
- Filing Date
- 2020-09-04
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2040-09-04
AI Technical Summary
Virtual Private Clouds (VPCs) with overlapping private network addresses cannot communicate with each other due to logical separation in cloud environments.
A method and system that utilizes a third VPC with a unique private network address segment to bridge communication between two VPCs with overlapping addresses by configuring gateways and routers to translate and route packets between them.
Enables communication between VPCs with overlapping private network addresses by associating and translating addresses, allowing seamless data exchange across VPCs.
Smart Images

Figure 0007701343000002 
Figure 0007701343000003 
Figure 0007701343000004
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud technology, and in particular, to a communication and configuration method for virtual private clouds and related devices.
Background Art
[0002] With the development of cloud technology, communication between two or more Virtual Private Clouds (VPCs) is required. However, due to reasons such as the planning of private network addresses, if the private network addresses of VPCs that need to communicate with each other overlap, the VPCs cannot communicate with each other.
Summary of the Invention
Means for Solving the Problems
[0003] In order to solve the problems of the prior art, embodiments of the present invention provide a communication and configuration method for virtual private clouds and related devices for effectively solving the technical problem that VPCs on the cloud cannot communicate with each other due to overlapping private network addresses.
[0004] According to a first aspect, the present application provides a method for configuring communication of a virtual private cloud (VPC). In the method, a first VPC and a second VPC having the same private network address segment communicate with each other by using a third VPC. The private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. The method includes the following steps: associating a private network address in the first VPC with a first address, where the first address belongs to the private network address segment of the third VPC; associating a private network address in the second VPC with a second address, where the second address belongs to the private network address segment of the third VPC and the first address is different from the second address; configuring the source address of a packet sent from the first VPC to the second VPC as the first address; and configuring the destination address of a packet sent from the first VPC to the second VPC as the second address.
[0005] Through the bridging of the third VPC, the first VPC accesses the second VPC by accessing the second address associated with the second VPC, and the second VPC accesses the first VPC by accessing the first address associated with the first VPC. In this way, when the private network address segment of the first VPC overlaps with the private network address segment of the second VPC, communication between the first VPC and the second VPC can be implemented.
[0006] According to a possible implementation of the first aspect, the configuration method further includes a step of configuring a routing rule for a third VPC. The routing rule for the third VPC includes forwarding a packet whose destination address is the first address to the first VPC, and forwarding a packet whose destination address is the second address to the second VPC.
[0007] The routing rule is configured such that the third VPC can forward packets between the first VPC and the second VPC. In this way, bridging is implemented.
[0008] According to a possible implementation of the first aspect, the configuration method may further include the following steps, namely, configuring a first gateway on the first VPC and configuring a second gateway on the second VPC, where the private network address of the first gateway is configured as the first address and the private network address of the second gateway is configured as the second address; configuring a first packet processing rule for the first gateway, where the first packet processing rule includes converting the source address of an outgoing packet from an address within the first VPC to the first address, and converting the destination address of an incoming packet from the first address to an address within the first VPC; and configuring a second packet processing rule for the second gateway, where the second packet processing rule includes converting the source address of an outgoing packet from an address within the second VPC to the second address, and converting the destination address of an incoming packet from the second address to an address within the second VPC.
[0009] The packet processing rules are configured such that the first gateway associates the address within the first VPC with the first address, and the second gateway associates the address within the second VPC with the second address. In this way, the first VPC accesses the second VPC by accessing the second address, and the second VPC accesses the first VPC by accessing the first address.
[0010] According to a possible implementation of the first aspect, the configuration method further includes the step of configuring a routing rule. In particular, the routing rule is configured for the router of the first VPC, and the routing rule for the router of the first VPC includes forwarding a packet whose destination address is the second address to the first gateway, and forwarding a packet whose destination address is an address within the first VPC to the subnet of the first VPC. The routing rule is configured for the router of the second VPC, and the routing rule for the router of the second VPC includes forwarding a packet whose destination address is the first address to the second gateway, and forwarding a packet whose destination address is an address within the second VPC to the subnet of the first VPC.
[0011] The routing rule is configured such that the router of the first VPC can forward packets between the first gateway and the subnet of the first VPC, and the router of the second VPC can forward packets between the second gateway and the subnet of the second VPC.
[0012] According to another possible implementation of the first aspect, the address within the first VPC includes an address for remotely accessing the subnet of the on-premise data center corresponding to the first VPC.
[0013] According to another possible implementation of the first aspect, the address within the first VPC includes an address within the subnet of the first VPC.
[0014] According to a second aspect, the present application provides a method for configuring communication of a virtual private cloud (VPC). The method is used for a first VPC and a second VPC having the same private network address segment to communicate with each other by using a third VPC, and the private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC.The method includes the following steps: configuring a first gateway on a first VPC and a second gateway on a second VPC, where a first address is configured for the first gateway and a second address is configured for the second gateway, the first address and the second address belong to the private network address segment of a third VPC, and the first address is different from the second address; configuring a first packet processing rule for the first gateway and a second packet processing rule for the second gateway, where the first packet processing rule includes converting the source address of outgoing packets from an address within the first VPC to the first address and converting the destination address of incoming packets from the first address to an address within the first VPC, and the second packet processing rule includes converting the source address of outgoing packets from an address within the second VPC to the second address and converting the destination address of incoming packets from the second address to an address within the second VPC; and configuring a first routing rule for the router of the first VPC, a second routing rule for the router of the second VPC, and a third routing rule for the router of the third VPC, where the first routing rule includes routing packets with a destination address of the second address to the first gateway, the second routing rule includes routing packets with a destination address of the first address to the second gateway, and the third routing rule includes routing packets with a destination address of the first address to the first gateway within the first VPC and routing packets with a destination address of the second address to the second gateway within the second VPC.
[0015] Through the bridging of the third VPC, the first VPC accesses the second VPC by accessing the second address associated with the second VPC, and the second VPC accesses the first VPC by accessing the first address associated with the first VPC. In this way, when the private network address segment of the first VPC overlaps with the private network address segment of the second VPC, communication between the first VPC and the second VPC can be carried out.
[0016] According to a possible implementation of the second aspect, the method further includes the following steps, that is, the steps of configuring the connection relationship between the first VPC and the third VPC and configuring the connection relationship between the second VPC and the third VPC.
[0017] In particular, the first gateway in the first VPC may be configured to connect to the router of the third VPC, and the second gateway in the second VPC may be configured to connect to the router of the third VPC, so that as a result, the first VPC and the second VPC are separately connected to the third VPC. Further, the third VPC executes a transfer to the first VPC by using the first address associated with the first VPC, and executes a transfer to the second VPC by using the second address associated with the second VPC.
[0018] According to a third aspect, the present application provides a communication method for a virtual private cloud (VPC). The method is used for a first VPC and a second VPC having the same private network address segment to communicate with each other by using a third VPC. The private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. The method includes the following steps. The first VPC sends a packet, the source address of the packet is a first address, the destination address of the packet is a second address, both the first address and the second address belong to the private network address segment of the third VPC, the private network address in the first VPC is associated with the first address, and the private network address in the second VPC is associated with the second address. The third VPC receives the packet and forwards the packet to the second VPC according to a preset routing rule, and the routing rule of the third VPC includes forwarding a packet whose destination address is the second address to the second VPC.
[0019] Through the bridging of the third VPC, the first VPC accesses the second VPC by accessing the second address associated with the second VPC, and the second VPC accesses the first VPC by accessing the first address associated with the first VPC. In this way, when the private network address segment of the first VPC overlaps with the private network address segment of the second VPC, communication between the first VPC and the second VPC can be implemented.
[0020] According to a possible implementation of the third aspect, the routing rule further includes forwarding a packet whose destination address is the first address to the first VPC. In this case, the method further includes the following steps. The second VPC sends a response packet, the source address of the response packet is the second address, and the destination address of the response packet is the first address. The third VPC receives the response packet and forwards the response packet to the first VPC according to the routing rule.
[0021] The routing rule is configured such that, for performing a reply, a feedback reply packet from the second VPC can be forwarded to the first VPC by using the third VPC.
[0022] According to a fourth aspect, the present application provides a communication method for a virtual private cloud (VPC). A first VPC communicates with a second VPC by using a third VPC, the first VPC and the second VPC have the same private network address segment, and the private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. A first gateway is configured on the first VPC, a second gateway is configured on the second VPC, a first address is configured for the first gateway, and a second address is configured for the second gateway. Both the first address and the second address belong to the private network address segment of the third VPC, and the first address is different from the second address. The method includes the following steps. A router of the first VPC receives a packet sent by a first device, the source address of the packet is the private network address of the first device, and the destination address of the packet is the second address. The router of the first VPC transfers the packet to the first gateway according to a first routing rule. The first gateway modifies the source address of the packet to the first address and transfers the modified packet to a router of the third VPC. A third routing rule is configured for the router of the third VPC. The first routing rule is that a packet whose destination address belongs to the private network address segment of the third VPC needs to be transferred to the first gateway. The third routing rule is that a packet whose destination address is the second address needs to be transferred to the second gateway within the second VPC.
[0023] Through the bridging of the third VPC, the first VPC accesses the second VPC by accessing the second address associated with the second VPC, and the second VPC accesses the first VPC by accessing the first address associated with the first VPC. In this way, when the private network address segment of the first VPC overlaps with the private network address segment of the second VPC, communication between the first VPC and the second VPC can be carried out.
[0024] In a possible implementation of the fourth aspect, the first device may be a first virtual machine within a first subnet of the first VPC, or a physical or virtual machine within a second subnet of a first on-premises data center connected to the first VPC by using a remote communication tunnel. The second device may be a second virtual machine within a third subnet of the second VPC, or a physical or virtual machine within a fourth subnet of a second on-premises data center connected to the second VPC by using a remote communication tunnel.
[0025] In a possible implementation of the fourth aspect, the method further includes the following steps. A second gateway receives a packet forwarded by a router of the third VPC, modifies the destination address of the received packet to the address of the second device, and sends the modified packet to a router of the second VPC. The router of the second VPC forwards the received packet to the subnet where the second device is located according to a second routing rule. The second routing rule is that a packet whose destination address belongs to the second address needs to be forwarded to the subnet where the second device is located.
[0026] After the packet is modified by the second gateway, forwarded, and then forwarded by the router of the second VPC, the packet may arrive at the subnet where the second device is located. In this way, the second device can receive the packet.
[0027] According to a fifth aspect, an embodiment of the present invention provides a communication configuration device for a virtual private cloud (VPC). A first VPC and a second VPC having the same private network address segment communicate with each other by using a third VPC. The private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. The device includes the following modules: an address association module configured to associate a private network address in the first VPC with a first address belonging to the private network address segment of the third VPC, and to associate a private network address in the second VPC with a second address belonging to the private network address segment of the third VPC, the first address being different from the second address; and an address configuration module configured to configure the source address of a packet transmitted from the first VPC to the second VPC as the first address, to configure the destination address of a packet transmitted from the first VPC to the second VPC as the second address, to configure the source address of a packet transmitted from the second VPC to the first VPC as the second address, and to configure the destination address of a packet transmitted from the second VPC to the first VPC as the first address.
[0028] The fifth aspect or any implementation of the fifth aspect is an implementation of a device corresponding to the first aspect or any implementation of the first aspect. The description of the first aspect or any implementation of the first aspect may apply to the fifth aspect or any implementation of the fifth aspect. Details are not described again herein.
[0029] According to a sixth aspect, the present application provides a communication configuration device for a virtual private cloud VPC. A first virtual private cloud VPC and a second VPC having the same private network address segment communicate with each other by using a third VPC, and the private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. The device includes a gateway configuration module configured to configure a first gateway on the first VPC and a second gateway on the second VPC; an address configuration module configured to configure a first address for the first gateway and a second address for the second gateway, wherein the first address and the second address belong to the private network address segment of the third VPC and the first address is different from the second address; an address association module configured to configure a first packet processing rule for the first gateway and a second packet processing rule for the second gateway, wherein the first packet processing rule includes converting the source address of an outgoing packet from an address within the first VPC to the first address, sending the modified outgoing packet to a router of the third VPC, converting the destination address of an incoming packet from the first address to an address within the first VPC, and sending the modified incoming packet to a router of the first VPC, and the second packet processing rule includes converting the source address of an outgoing packet from an address within the second VPC to the second address, sending the modified outgoing packet to a router of the third VPC, converting the destination address of an incoming packet from the second address to an address within the second VPC, and sending the modified incoming packet to a router of the second VPC; and a routing rule configuration module configured to configure a first routing rule for a router of the first VPC and a second routing rule for a router of the second VPC,A routing rule configuration module configured to configure a third routing rule for a router of a third VPC, wherein a first routing rule includes routing a packet whose destination address is a second address to a first gateway, a second routing rule includes routing a packet whose destination address is a first address to a second gateway, and a third routing rule includes routing a packet whose destination address is a first address to a first gateway within a first VPC and routing a packet whose destination address is a second address to a second gateway within a second VPC, and includes a routing rule configuration module.
[0030] A sixth aspect or any implementation of the sixth aspect is an implementation of an apparatus corresponding to the second aspect or any implementation of the second aspect. The description of the second aspect or any implementation of the second aspect may apply to the sixth aspect or any implementation of the sixth aspect. Details are not described again herein.
[0031] According to a seventh aspect, the present application provides a communication system for a virtual private cloud (VPC) including a first VPC, a second VPC, and a third VPC. The first VPC and the second VPC have the same private network address segment, and the first VPC and the second VPC communicate with each other by using the third VPC. The private network address segment of the third VPC is different from the private network address segments of the first VPC and the second VPC. The first VPC is configured to send a packet. The source address of the packet is a first address, the destination address of the packet is a second address, both the first address and the second address belong to the private network address segment of the third VPC, the private network address within the first VPC is associated with the first address, and the private network address within the second VPC is associated with the second address. The third VPC is configured to receive the packet and transfer the packet to the second VPC according to a preset routing rule. The routing rule of the third VPC includes transferring a packet whose destination address is the second address to the second VPC.
[0032] The seventh aspect or any implementation of the seventh aspect is an implementation of a system corresponding to the third aspect or any implementation of the third aspect. The description of the third aspect or any implementation of the third aspect may apply to the seventh aspect or any implementation of the seventh aspect. Details are not described again herein.
[0033] According to an eighth aspect, the present application provides a communication system for a virtual private cloud (VPC) including a first VPC, a second VPC, and a third VPC. The first VPC communicates with the second VPC by using the third VPC, and the first VPC and the second VPC have the same private network address segment. The private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. A first gateway is configured on the first VPC, a second gateway is configured on the second VPC, a first address is configured for the first gateway, and a second address is configured for the second gateway. Both the first address and the second address belong to the private network address segment of the third VPC, and the first address is different from the second address. The router of the first VPC is configured to receive a packet sent by a first device. The source address of the packet is the private network address of the first device, and the destination address of the packet is the second address. The router of the first VPC is further configured to forward the packet to the first gateway according to a first routing rule. The first gateway is configured to modify the source address of the packet to the first address and forward the modified packet to the router of the third VPC. A third routing rule is configured for the router of the third VPC. The first routing rule is that a packet whose destination address belongs to the private network address segment of the third VPC needs to be forwarded to the first gateway. The third routing rule is that a packet whose destination address is the second address needs to be forwarded to the second gateway within the second VPC.
[0034] The eighth aspect or any implementation of the eighth aspect is an implementation of a system corresponding to the fourth aspect or any implementation of the fourth aspect. The description of the fourth aspect or any implementation of the fourth aspect may apply to the eighth aspect or any implementation of the eighth aspect. Details are not described again herein.
[0035] According to a ninth aspect, the present application provides a communication system for a virtual private cloud VPC including a first virtual private cloud VPC, a second VPC, and a third VPC. The first VPC communicates with the second VPC by using the third VPC, and the first VPC and the second VPC have the same private network address segment. The private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. A first gateway connected to the third VPC is configured on the first VPC, and a second gateway connected to the third VPC is configured on the second VPC. A first address is configured for the first gateway, and a second address is configured for the second gateway. Both the first address and the second address belong to the private network address segment of the third VPC, and the first address is different from the second address. A first virtual machine in a first subnet of the first VPC is configured to send a packet to a switch of the first subnet. The source address of the packet is the private network address of the first virtual machine in the first subnet, and the destination address of the packet is the second address. The switch of the first subnet is configured to send the packet to a router of the first VPC. The router of the first VPC is configured to receive the packet and forward the packet to the first gateway. The first gateway is configured to receive the packet, modify the destination address of the packet to the first address, and send the modified packet to a router of the third VPC. The router of the third VPC is configured to receive the packet and forward the packet to the second gateway. The second gateway is configured to receive the packet, modify the destination address of the received packet to the private network address of a second virtual machine in a second subnet of the second VPC in the second subnet, and send the modified packet to a router of the second VPC.The router of the second VPC is configured to receive a packet and transfer the packet to the switch of the second subnet. The switch of the second subnet is configured to receive a packet and transfer the packet to the second virtual machine.
[0036] According to the tenth aspect, the present application provides a communication system for a virtual private cloud VPC including a first virtual private cloud VPC, a second VPC, and a third VPC. The first VPC communicates with the second VPC by using the third VPC. The first VPC and the second VPC have the same private network address segment. The private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. A first remote connection gateway remotely connected to the first on-premises data center and a first gateway connected to the third VPC are configured on the first VPC. A second remote connection gateway remotely connected to the second on-premises data center and a second gateway connected to the third VPC are configured on the second VPC. A first address is configured for the first gateway, and a second address is configured for the second gateway. Both the first address and the second address belong to the private network address segment of the third VPC, and the first address is different from the second address. The first remote connection gateway is configured to receive a packet transmitted by a first device in a first subnet of the first on-premises data center and transmit the packet to a router of the first VPC. The source address of the packet is the private network address of the first device in the first subnet, and the destination address of the packet is the second address. The router of the first VPC is configured to receive the packet and transfer the packet to the first gateway. The first gateway is configured to receive the packet, modify the destination address of the packet to the first address, and transfer the modified packet to a router of the third VPC. The router of the third VPC is configured to receive the packet and transfer the packet to the second gateway.The second gateway is configured to receive a packet, modify the destination address of the received packet to the private network address in the second subnet of a second device in the second on-premises data center, and send the modified packet to the router of the second VPC. The router of the second VPC is configured to receive the packet and forward the packet to the second remote connection gateway. The second remote connection gateway is configured to receive the packet and send the packet to a second device in the second subnet of the second on-premises data center.
[0037] According to the 11th aspect, the present application provides a communication system for virtual private clouds (VPCs) including a first VPC, a second VPC, and a third VPC. The first VPC communicates with the second VPC by using the third VPC. The first VPC and the second VPC have the same private network address segment, and the private network address segment of the third VPC is different from the private network address segments of the first VPC and the second VPC. A first gateway is configured on the first VPC, a second gateway is configured on the second VPC, a first address is configured for the first gateway, and a second address is configured for the second gateway. Both the first address and the second address belong to the private network address segment of the third VPC. The router of the first VPC and the router of the second VPC are separately connected to the router of the third VPC, and the first address is different from the second address. A first virtual machine in the first subnet of the first VPC is configured to send a packet to the switch of the first subnet. The source address of the packet is the private network address of the first virtual machine in the first subnet, and the destination address of the packet is the second address. The switch of the first subnet is configured to send the packet to the first gateway. The first gateway is configured to modify the source address of the packet to the first address and send the modified packet to the router of the first VPC. The router of the first VPC is configured to receive the packet and forward the packet to the router of the third VPC. The router of the third VPC is configured to receive the packet and forward the packet to the router of the second VPC. The router of the second VPC is configured to receive the packet and forward the packet to the second gateway.The second gateway is configured to receive a packet, modify the destination address of the received packet to the private network address in the second subnet of the second virtual machine in the second VPC, and send the modified packet to the switch of the second subnet. The switch of the second subnet is configured to receive the packet and forward the packet to the second virtual machine.
[0038] According to a twelfth aspect, the present application provides a computing device including at least one memory and at least one processor. The at least one memory is configured to store program instructions, and the at least one processor is configured to execute the program instructions to perform a method for implementing the first aspect and any possible implementation of the first aspect.
[0039] According to a thirteenth aspect, the present application provides a computing device including at least one memory and at least one processor. The at least one memory is configured to store program instructions, and the at least one processor is configured to execute the program instructions to perform a method for implementing the second aspect and any possible implementation of the second aspect.
[0040] According to a fourteenth aspect, the present application provides a non-transitory readable storage medium. When the non-transitory readable storage medium is executed by a computing device, the computing device performs a method provided in any one of the first aspect or possible implementations of the first aspect. The storage medium stores a program. The storage medium includes, but is not limited to, volatile memory such as random access memory, or non-volatile memory such as flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0041] According to a 15th aspect, the present application provides a non-transitory readable storage medium. When the non-transitory readable storage medium is executed by a computing device, the computing device executes a method provided in any one of the 2nd aspect or possible implementations of the 2nd aspect. The storage medium stores a program. The storage medium includes, but is not limited to, volatile memory, such as random access memory, or non-volatile memory, such as flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0042] According to a 16th aspect, the present application provides a program product of a computing device. The program product of the computing device includes computer instructions. When the computer instructions are executed by a computing device, the computing device executes a method provided in any one of the 1st aspect or possible implementations of the 1st aspect. The computer program product may be a software installation package. When it is necessary to use the method provided in any one of the 1st aspect or possible implementations of the 1st aspect, the computer program product may be downloaded to the computing device and executed on the computing device.
[0043] According to the 17th aspect, the present application provides a program product for another computing device. The program product of the computing device includes computer instructions. When the computer instructions are executed by the computing device, the computing device executes the method provided in any one of the 2nd aspect or the possible implementations of the 2nd aspect. The computer program product may be a software installation package. When it is necessary to use the method provided in any one of the 2nd aspect or the possible implementations of the 2nd aspect, the computer program product may be downloaded to the computing device and executed on the computing device.
[0044] According to an 18th aspect, the present application further provides a method for configuring communication of a virtual private cloud (VPC). A first VPC and a second VPC having the same private network address segment communicate with each other by using a third VPC, and the private network address segment of the third VPC is different from the private network address segment of the first VPC and the private network address segment of the second VPC. The method includes: providing a first configuration page to a user in the first VPC, the first configuration page prompting the user in the first VPC to create a first gateway on the first VPC, prompting the user in the first VPC to input information about the third VPC to which the first gateway needs to be connected, and the first address of the first gateway in the third VPC; providing a second configuration page to a user in the second VPC, the second configuration page prompting the user in the second VPC to create a second gateway on the second VPC, prompting the user in the second VPC to input information about the third VPC to which the second gateway needs to be connected, and the second address of the second gateway in the third VPC, the first address and the second address belonging to the private network address segment of the third VPC and the first address being different from the second address; creating the first gateway based on the information about the first configuration page; and creating the second gateway based on the information about the second configuration page.
[0045] According to a possible implementation of the 18th aspect, the communication configuration method of the VPC includes the following steps, that is, the step of configuring a first packet processing rule for the first gateway and a second packet processing rule for the second gateway, wherein the first packet processing rule includes converting the source address of the packet going out from an address within the first VPC to the first address, and converting the destination address of the packet coming in from the first address to an address within the first VPC, and the second packet processing rule includes converting the source address of the packet going out from an address within the second VPC to the second address, and converting the destination address of the packet coming in from the second address to an address within the second VPC; the step of configuring a first routing rule for the router of the first VPC, a second routing rule for the router of the second VPC, and a third routing rule for the router of the third VPC, wherein the first routing rule includes routing a packet whose destination address is the second address to the first gateway, the second routing rule includes routing a packet whose destination address is the first address to the second gateway, and the third routing rule includes routing a packet whose destination address is the first address to the first gateway within the first VPC and routing a packet whose destination address is the second address to the second gateway within the second VPC.
Brief Description of the Drawings
[0046]
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 4
Figure 5a
Figure 5b
Figure 5c
Figure 5d
Figure 5e
Figure 5f
Figure 5g
Figure 6A
Figure 6B
Figure 6C
Figure 7A
Figure 7B
Figure 8A
Figure 8B
Figure 8C
Figure 9A
Figure 9B
Figure 10
Figure 11
Embodiments for Carrying Out the Invention
[0047] First, the terms used in the embodiments of the present invention will be described.
[0048] A cloud data center is a data center that provides public cloud services.
[0049] An on-premises data center is a data center that provides non-public cloud services. When the on-premises data center provides on-premises services, the on-premises data center includes a plurality of physical machines. When the on-premises data center provides private cloud services, the on-premises data center includes a plurality of virtual machines.
[0050] A public cloud service is Infrastructure as a Service (IaaS). A public cloud service means that the infrastructure provided by a public cloud service provider is offered externally as a service over the Internet. In this service model, users do not need to build a data center. Instead, users borrow infrastructure such as servers, storage, and networks that they use. A public cloud service is implemented by providing a virtual environment (such as a virtual machine). The core characteristic of a public cloud is that multiple users share the cloud infrastructure and users are isolated from each other.
[0051] A non-public cloud service provides infrastructure dedicated to a single user, such as a private cloud service and an on-premises service.
[0052] A Private Cloud service means that a single user can own and fully control infrastructure such as servers, storage, and networks. A private cloud service is implemented by providing a virtual environment (such as a virtual machine). The core characteristic of a private cloud service is that a single user uses the infrastructure exclusively.
[0053] An on-premises service means that a single user locally builds infrastructure such as servers, storage, and networks. The user uses the infrastructure exclusively. An on-premises service is implemented by using physical machines.
[0054] A private network address is an IP address that cannot be transferred on the Internet and can only be transferred on a local area network. A private network address is prohibited from being used on the Internet.
[0055] A private network address is a reserved IP address. The following table describes the classification of private network addresses, network segments, and the amount of private network addresses.
Table 1
[0056] A Virtual Private Cloud (VPC) is configured on a public cloud. A VPC is a virtual network for users of public cloud services within a cloud data center. Each VPC can form a network separately and is logically separated from other VPCs. Therefore, the private network address segments of subnets in different VPCs may be the same.
[0057] In particular, each VPC has an independent tunnel number. Packets between virtual machines within a VPC have the same tunnel identifier and are sent to the physical network for transmission. The tunnel identifiers of virtual machines in different VPCs are different, and the virtual machines are on two different routing planes. Therefore, virtual machines in different VPCs cannot communicate with each other and necessarily implement logical separation.
[0058] The tunnel identifier may be, for example, a Virtual Local Area Network Identification (VLAN ID) or a Virtual Network ID (VNI).
[0059] First, referring to FIG. 1, FIG. 1 is a schematic diagram of the system structure of the VPC communication system. As shown in FIG. 1, the VPC communication system includes a cloud data center 10 and a client 7, and the client 7 accesses the cloud data center 10 on the Internet 8.
[0060] FIG. 1 is a logical schematic diagram of the cloud data center 10. The cloud data center 10 provides VPC1 and VPC2 to users of the public cloud. VPC1 includes a router 1 and a subnet 1. The private network address segment of VPC1 is 192.168.0.0 / 16, and the private network address segment of subnet 1 is 192.168.0.0 / 24. Virtual machines (VM) 1 and VM2 are configured within subnet 1. The private network address of VM1 is 192.168.0.2, and the private network address of VM2 is 192.168.0.3. VM1 and VM2 are connected to switch 1, and router 1 is connected to switch 1.
[0061] Note that the private network address segment of subnet 1 is a subset of the private network address segment of VPC1. In addition to subnet 1, VPC1 may further include other subnets such as a subnet with a private network address segment of 192.168.1.0 / 24 or a subnet with a private network address segment of 192.168.2.0 / 24. Router 1 is configured to forward packets for communication between different subnets.
[0062] Furthermore, VPC2 includes Router 2 and Subnet 2. The private network address segment of VPC2 is 192.168.0.0 / 16, and the private network address segment of Subnet 2 is 192.168.0.0 / 24. VM3 and VM4 are configured within Subnet 2. The private network address of VM3 is 192.168.0.2, and the private network address of VM4 is 192.168.0.3. VM3 and VM4 are connected to Switch 2, and Router 2 is connected to Switch 2.
[0063] Subnet 1 and Subnet 2 have the same private network address segment. In other words, the private network address segment of Subnet 1 overlaps with the private network address segment of Subnet 2.
[0064] Similarly, the private network address segment of Subnet 2 is a subset of the private network address segment of VPC2. In addition to Subnet 2, VPC2 may further include other subnets such as a subnet with a private network address segment of 192.168.1.0 / 24 or a subnet with a private network address segment of 192.168.2.0 / 24. Router 2 is configured to forward packets for communication between different subnets.
[0065] Client 7 accesses the control platform 6 over the Internet 8, and the control platform 6 provides a VPC configuration page. Client 7 accesses the VPC configuration interface over the Internet 8 and enters the configuration information of the VPC on the VPC configuration interface. The control platform 6 configures the VPC in the cloud data center 10 based on the configuration information. In particular, each functional module within the VPC may be configured. For example, the VPC may be created or deleted, virtual machines may be created or deleted within the VPC, and the routing rules of the VPC router may be configured. The control platform 6 may perform full life cycle management on the VPC based on the configuration information. From the perspective of client 7, the cloud data center 10 provides logically separated VPC1 and VPC2. Client 7 can log in to VM1 or VM2 of VPC1 by using a remote desktop. Client 7 can also log in to VM3 and VM4 within VPC2. VPC1 and VPC2 are logically separated and do not interfere with each other.
[0066] Client 7 is a terminal device, such as a mobile phone with network access function, a personal computer, a personal digital assistant, or a thin client. The user uses the virtual machines in the cloud data center 10 by using client 7.
[0067] As shown in FIG. 1, VM1 and VM2 are configured within Subnet 1 of VPC1, with the private network address 192.168.0.2 set for VM1 within Subnet 1 of VPC1 and the private network address 192.168.0.3 set for VM2 within Subnet 1 of VPC1. VM1 communicates with VM2 by using Switch 1. VM3 and VM4 are configured within Subnet 2 of VPC2, with the private network address 192.168.0.2 set for VM3 within Subnet 2 of VPC2 and the private network address 192.168.0.3 set for VM4 within Subnet 2 of VPC2. VM3 communicates with VM4 by using Switch 2.
[0068] For example, a user logs in to VM1 using Client 7 and enters the command "ping 192.168.1.3" of the Internet Control Message Protocol (ICMP) on VM1. The command is used to control VM1 to send IP packets to VM2 to test whether VM1 and VM2 are interconnected. In this embodiment, since VM1 and VM2 are configured within the same VPC1, VM1 obtains a reply from VM2.
[0069] However, as shown in FIG. 1, since VPC1 and VPC2 are logically separated, virtual machines within VPC1 cannot communicate with virtual machines within VPC2. In particular, Client 7 may log in to VM1 and enter the ICMP command "ping 192.168.0.3" on VM1. This command is used to test whether VM1 and VM4 are interconnected. In this embodiment, since VM1 and VM4 are configured within different VPCs, VM1 does not obtain a reply from VM4.
[0070] In the scenario of an enterprise's cloud applications, due to the need for service separation between departments, VPCs can be used to separate services. For example, VPC1 belongs to the R & D department, and VPC2 belongs to the finance department. In the logical architecture shown in Figure 1, the VMs in the R & D department can communicate with each other, and the VMs in the finance department can also communicate with each other. However, the VMs in the R & D department cannot communicate with the VMs in the finance department. VMs in different departments are configured in different VPCs to effectively implement data separation.
[0071] However, in actual applications, the VMs in the R & D department and the VMs in the finance department may need to communicate with each other in some cases. For example, the VMs in the R & D department need to obtain the financial data of the R & D department from the VMs in the finance department. When the VMs in the R & D department and the VMs in the finance department are separated from each other, the financial data cannot be obtained from the VMs in the finance department.
[0072] Therefore, in some implementations, Routers 1 and 2 are connected so that VPC1 and VPC2 can communicate with each other. However, in the scenario shown in Figure 1, the private network address segment of Subnet 1 overlaps with the private network address segment of Subnet 2. In this case, even if Routers 1 and 2 are connected, Subnet 1 and Subnet 2 cannot communicate with each other. For example, VM1 communicates with VM3, and VM1 constructs an IP packet with both the source IP address and the destination IP address being 192.168.0.2. When the IP packet reaches Switch 1, Switch 1 intercepts the IP packet and sends the IP packet to VM1 based on the destination IP address of the IP packet, and the operating system of VM1 immediately intercepts the IP packet. In this case, the IP packet cannot reach Subnet 2.
[0073] To solve the above technical problems, embodiments of the present invention provide a communication system for VPC. Referring to FIG. 2, FIG. 2 is a schematic diagram of the system structure of the VPC communication system according to an embodiment of the present invention. As shown in FIG. 2, VPC1 and VPC2 having the same private network address segment communicate with each other by using VPC3, and the private network address segment of VPC3 is different from the private network address segment of VPC1 and the private network address segment of VPC2. The private network address in VPC1 is associated with 10.0.0.9, and 10.0.0.9 is an address belonging to the private network address segment of VPC3. The private network address in VPC2 is associated with 10.0.0.10, and 10.0.0.10 is an address belonging to the private network address segment of VPC3. The source address of the packet transmitted from VPC1 to VPC2 is configured as 10.0.0.9, and the destination address of the packet transmitted from VPC1 to VPC2 is configured as 10.0.0.10. The packet is transmitted from VPC1 to VPC3 and transferred from VPC3 to VPC2.
[0074] Through the bridging of VPC3, VPC1 can access VPC2 by accessing 10.0.0.10 associated with VPC2. In this way, when the private network address segment of VPC1 overlaps with the private network address segment of VPC2, communication between VPC1 and VPC2 may be implemented.
[0075] For further clarity, reference is made below to FIGS. 3A and 3B. FIGS. 3A and 3B are another schematic diagram of the system structure of the VPC communication system according to an embodiment of the present invention. FIGS. 3A and 3B are a specific implementation of FIG. 2. In this embodiment, VPC3 is configured between VPC1 and VPC2 by using the control platform 6, and a private network address segment that does not overlap with the private network address of VPC1 and the private network address of VPC2 is set for VPC3. Further, the gateway 1 connected to VPC3 is arranged within VPC1. The first private network address of VPC3 is set for the gateway 1. The gateway 2 connected to VPC3 is arranged within VPC2. The second private network address of VPC3 is set for the gateway 2. By setting the routing rules of the routers of VPC1, VPC2, and VPC3 and the packet processing rules of the gateway 1 and the gateway 2, VM1 within VPC1 is associated with the gateway 1, and VM3 within VPC2 is associated with the gateway 2. In this way, VM1 communicates with VM3 by accessing the second private network address of VPC3, and VM3 communicates with VM1 by accessing the first private network address of VPC3.
[0076] The control platform 6 may execute the creation of the above-described gateway and the configuration of the rules in the cloud data center 10 based on the configuration information, and the configuration information is input by the client 7 into the VPC configuration interface provided by the control platform 6.
[0077] In another embodiment, the control platform 6 may automatically generate the above-described configuration information and execute the above-described configuration.
[0078] The details are as follows.
[0079] The control platform 6 may allocate the private network address 10.0.0.9 of the private network address segment (e.g., 10.0.0.0 / 24) of VPC3 to gateway 1 and another private network address 10.0.0.10 of the private network address segment (e.g., 10.0.0.0 / 24) of VPC3 to gateway 2 based on the configuration information. Further, gateway 1 is configured to connect to router 3 of VPC3, and gateway 2 is configured to connect to router 3 of VPC3. The control platform 6 configures the router and the gateway separately.
[0080] Router 1 Routing rule 1: When the destination IP address of the packet received by router 1 is within the private network address segment 10.0.0.0 / 24 of VPC3, router 1 forwards the IP packet to gateway 1, and Routing rule 2: When the destination IP address of the packet received by router 1 is within the private network address segment 192.168.0.0 / 24 of subnet 1, router 1 forwards the packet to subnet 1 is provided.
[0081] Gateway 1 Packet processing rule 1: When the source IP address of the outgoing packet received by gateway 1 is the private network address 192.168.0.2 of VM1 within subnet 1, gateway 1 converts 192.168.0.2 to the private network address 10.0.0.9 of gateway 1 within VPC3 and sends the modified outgoing packet to router 3 of VPC3, and Packet Processing Rule 2: When the destination IP address of the packet received by Gateway 1 is the private network address 10.0.0.9 of Gateway 1 within VPC3, Gateway 1 converts 10.0.0.9 to the private network address 192.168.0.2 of VM1 within Subnet 1 and sends the modified incoming packet to Router 1 of VPC1. is given.
[0082] The outgoing packets are the packets received by Gateway 1 from Router 1, and the incoming packets are the packets received by Gateway 1 from Router 3.
[0083] Router 3 Routing Rule 5: When the destination IP address of the packet received by Router 3 is the private network address 10.0.0.10 of Gateway 2 within VPC3, Router 3 forwards the IP packet to Gateway 2, and Routing Rule 6: When the destination IP address of the packet received by Router 3 is the private network address 10.0.0.9 of Gateway 1 within VPC3, Router 3 forwards the packet to Gateway 1 is given.
[0084] Gateway 2 Packet Processing Rule 3: When the destination IP address of the incoming packet received by Gateway 2 is the private network address 10.0.0.10 of Gateway 2 within VPC3, Gateway 2 converts 10.0.0.10 to the private network address 192.168.0.2 of VM3 within Subnet 2 and sends the modified incoming packet to Router 2, and Packet Processing Rule 4: When the source IP address of an outgoing packet received by Gateway 2 is the private network address 192.168.0.2 of VM3 within Subnet 2, Gateway 2 converts 192.168.0.2 to the private network address 10.0.0.10 of Gateway 2 in VPC3. is given.
[0085] Outgoing packets are packets received by Gateway 2 from Router 2, and incoming packets are packets received by Gateway 2 from Router 3.
[0086] Router 2 Routing Rule 3: When the destination IP address of a packet received by Router 2 is within the private network address segment 10.0.0.0 / 24 of VPC3, Router 2 forwards the packet to Gateway 2, and Routing Rule 4: When the destination IP address of a packet received by Router 2 is within the private network address segment 192.168.0.0 / 24 of Subnet 2, Router 2 forwards the packet to Subnet 2 is given.
[0087] Note that Gateway 1 may have two private network addresses. One private network address belongs to VPC1 and is used for internal configuration and management of the gateway located within VPC1. The other address belongs to VPC3 (e.g., 10.0.0.9) and is used for communication with the outside. This patent application relates to communication with the outside. Therefore, unless otherwise specified, the private network address of Gateway 1 in this patent application is the private network address of Gateway 1 belonging to VPC3. Similarly, Gateway 2 may also have two private network addresses, the details of which are not described here.
[0088] Hereinafter, with reference to FIG. 4, a method for setting the above-described corresponding rules of the gateway and the router will be clearly described. FIG. 4 is a flowchart of a method for configuring the communication of the VPC according to an embodiment of the present invention. The method is executed by the control platform 6, and the method includes the following steps.
[0089] Step S101: Create gateway 1 within VPC1.
[0090] Specifically, please refer to FIG. 5a. FIG. 5a shows the setting interface 1 of VPC1. In the interface, the user needs to input the gateway name (gateway 1), the VPC where the gateway is located (VPC1), the VPC to which the gateway should be connected (VPC3), and the private network address 10.0.0.9 of the VPC to which the gateway should be connected.
[0091] Step S102: Configure the packet processing rule of gateway 1.
[0092] Referring to FIG. 5b, FIG. 5b shows the setting interface 2 of VPC1. In the interface, the user inputs the packet processing rule of the created gateway 1. The packet processing rules shown in FIG. 5b are the packet processing rule 1 and the packet processing rule 2 of gateway 1 shown in FIG. 3.
[0093] The packet processing rule 1 includes a source network address translation (SNAT) rule, and the packet processing rule 2 includes a destination network address translation (DNAT) rule.
[0094] Step S103: Configure the routing rule of VPC1.
[0095] Referring to FIG. 5c, FIG. 5c shows the setting interface 3 of VPC1. In the interface, the user inputs the routing rules of Router 1, specifically, the packet processing rules 1 and 2 shown in FIG. 2.
[0096] Step S104: Create Gateway 2 in VPC2.
[0097] In particular, refer to FIG. 5d. FIG. 5d shows the setting interface 1 of VPC2. In the interface, the user needs to input the gateway name (Gateway 2), the VPC where the gateway is located (VPC2), the VPC to which the gateway should be connected (VPC3), and the private network address 10.0.0.10 of the VPC to which the gateway should be connected.
[0098] Step S105: Configure the packet processing rules of Gateway 2.
[0099] Referring to FIG. 5e, FIG. 5e shows the setting interface 2 of VPC2. In the interface, the user inputs the packet processing rules of the created Gateway 2. The packet processing rules shown in FIG. 5e are the packet processing rules 3 and 4 of Gateway 2 shown in FIG. 2.
[0100] Step S106: Configure the routing rules of VPC2.
[0101] Referring to FIG. 5f, FIG. 5f shows the setting interface 3 of VPC2. In the interface, the user inputs the routing rules of Router 2, specifically, the packet processing rules 3 and 4 shown in FIG. 2.
[0102] Step S107: Configure the routing rules of VPC3.
[0103] Referring to FIG. 5g, FIG. 5g shows the configuration interface of VPC3. In the interface, the user inputs the routing rules of Router 3, specifically, the packet processing rules 5 and 6 shown in FIG. 2.
[0104] The order of steps S101 to S107 may be adjusted as necessary. For example, the step of creating Gateway 2 may be executed first, and then the step of creating Gateway 1 may be executed. This is not limited to this embodiment of the present invention.
[0105] It should be noted that the above-mentioned configuration information is input by the user into the VPC configuration interface provided by the control platform 6 by using the client 7, and the configuration information is transmitted to the control platform 6 by the control platform 6. The control platform 6 configures VPC1 and VPC2 based on the configuration information.
[0106] After the control platform 6 executes the above-mentioned configuration method, the VPC communication system shown in FIG. 3 may be implemented in the cloud data center 10.
[0107] Furthermore, referring to FIGS. 6A to 6C, FIGS. 6A to 6C are diagrams of data interaction of the VPC communication method according to an embodiment of the present invention. The method is based on the VPC communication system shown in FIGS. 3A and 3B, and particularly shows the direction in which packets flow when VM1 accesses VM3 across the VPC.
[0108] As shown in FIGS. 6A to 6C, the VPC communication method according to this embodiment of the present invention includes the following steps.
[0109] Step 1: VM1 constructs IP packet 1 and sends IP packet 1 to switch 1.
[0110] The source IP address of the IP header of IP packet 1 is the private network address 192.168.0.2 of VM1 within subnet 1, and the destination IP address of the IP header of IP packet 1 is the private network address 10.0.0.10 of gateway 2 within subnet 3. The data part of IP packet 1 carries the request information.
[0111] It should be noted that VM1 may query in advance the correspondence between 10.0.0.10 and VM3 based on service requirements. For example, VM1 may query the correspondence between 10.0.0.10 and VM3 from VPC2, and may also query the correspondence between 10.0.0.10 and VM3 from control platform 6.
[0112] Step 2: Switch 1 forwards IP packet 1 to router 1.
[0113] After receiving IP packet 1, switch 1 determines that the destination IP address of IP packet 1 does not belong to subnet 1, and sends IP packet 1 to router 1 to execute packet transmission across network segments.
[0114] Step 3: Router 1 forwards IP packet 1 according to routing rule 1.
[0115] After receiving IP packet 1, router 1 checks routing rule 1 based on the destination IP address (10.0.0.10) of IP packet 1, and sends IP packet 1 to gateway 1 according to routing rule 1.
[0116] Step 4: Gateway 1 modifies the source IP address of IP packet 1 according to packet processing rule 1, and sends the modified IP packet 1 to router 3.
[0117] After Gateway 1 receives IP Packet 1 from Router 1, since IP Packet 1 is from Router 1, Gateway 1 determines that IP Packet 1 is a packet going out, checks Packet Processing Rule 1 based on the source IP address of IP Packet 1, modifies the source IP address of IP Packet 1 from 192.168.0.2 to 10.0.0.9, and sends the modified IP Packet 1 to Router 3.
[0118] Step 5: Router 3 transfers IP Packet 1 to Gateway 2 according to Routing Rule 5.
[0119] After receiving IP Packet 1, Router 3 checks Routing Rule 5 based on the destination IP address (10.0.0.10) of IP Packet 1 and transfers IP Packet 1 to Gateway 2.
[0120] Step 6: Gateway 2 modifies the destination IP address of IP Packet 1 according to Packet Processing Rule 3 and sends the modified IP Packet 1 to Router 2.
[0121] After Gateway 2 receives IP Packet 1 from Router 3, since IP Packet 1 is from Router 3, Gateway 2 determines that IP Packet 1 is a packet coming in, checks Packet Processing Rule 3 based on the destination address of IP Packet 1, modifies the destination IP address of IP Packet 1 from 10.0.0.10 to 192.168.0.2, and sends the modified IP Packet 1 to Router 2.
[0122] Step 7: Router 2 transfers the modified IP Packet 1 to Switch 2 according to Routing Rule 4.
[0123] Router 2 matches routing rule 4 based on the destination IP address 192.168.0.2 of IP packet 1 and sends IP packet 1 to subnet 2. Switch 2 is located in subnet 2. To be specific, switch 2 is the switch that sends IP packet 1 to switch 2 within subnet 2.
[0124] Step 8: Switch 2 sends IP packet 1 to VM3.
[0125] Switch 2 sends IP packet 1 to VM3 based on the destination IP address 192.168.0.2 of IP packet 1.
[0126] Step 9: VM3 constructs IP packet 2 and sends IP packet 2 to switch 2.
[0127] IP packet 2 is the reply packet of IP packet 1.
[0128] After receiving IP packet 1, VM3 obtains the request information from the data part of IP packet 1, generates reply information based on the request information, and constructs IP packet 2. Specifically, VM3 sets the source IP address 10.0.0.9 of IP packet 1 as the destination IP address of IP packet 2, sets the destination IP address 192.168.0.2 of IP packet 1 as the source IP address of IP packet 2, sets the reply information in the data part of IP packet 2, and sends IP packet 2 to switch 2.
[0129] Step 10: Switch 2 forwards IP packet 2 to router 2.
[0130] After receiving IP packet 2, switch 2 determines that the destination IP address 10.0.0.9 of IP packet 2 does not belong to subnet 1 (192.168.0.0 / 24), and sends IP packet 2 to router 2 to perform packet transmission across network segments.
[0131] Step 11: Router 2 forwards IP packet 2 according to routing rule 3.
[0132] After receiving IP packet 2, router 2 checks routing rule 3 based on the destination IP address (10.0.0.9) of IP packet 2, and sends IP packet 2 to gateway 2 according to routing rule 3.
[0133] Step 12: Gateway 2 modifies the source IP address of IP packet 2 according to packet processing rule 4, and sends the modified IP packet 2 to router 3.
[0134] After gateway 2 receives IP packet 2 from router 2, since IP packet 2 is from router 2, gateway 2 determines that IP packet 2 is a packet going out, checks packet processing rule 4 based on the source IP address of IP packet 2, modifies the source IP address of IP packet 2 from 192.168.0.2 to 10.0.0.10, and sends the modified IP packet 2 to router 3.
[0135] Step 13: Router 3 forwards IP packet 2 to gateway 1 according to routing rule 6.
[0136] After receiving IP packet 2, router 3 checks routing rule 6 based on the destination IP address (10.0.0.9) of IP packet 2, and forwards IP packet 2 to gateway 1.
[0137] Step 14: Gateway 1 modifies the destination IP address of IP packet 2 according to packet processing rule 2, and sends the modified IP packet 2 to router 1.
[0138] After gateway 1 receives IP packet 2 from router 3, since IP packet 2 is from router 3, gateway 1 determines that IP packet 2 is a packet coming in, checks packet processing rule 2 based on the destination address of IP packet 2, modifies the destination IP address of IP packet 2 from 10.0.0.9 to 192.168.0.2, and sends the modified IP packet 2 to router 1.
[0139] Step 15: Router 1 transfers the IP packet 2 modified according to routing rule 2 to switch 1.
[0140] Router 1 checks routing rule 2 based on the destination IP address 192.168.0.2 of IP packet 2 and sends IP packet 2 to subnet 1. Switch 1 is located in subnet 1. To be precise, switch 1 is the switch that sends IP packet 2 to switch 1 within subnet 1.
[0141] Step 16: Switch 1 sends IP packet 2 to VM1.
[0142] Switch 1 sends IP packet 2 to VM1 based on the destination IP address 192.168.0.2 of IP packet 2.
[0143] After receiving IP packet 2, VM1 determines that IP packet 2 is a reply packet of IP packet 1 based on the source IP address 10.0.0.10 and destination IP address 192.168.0.2 of IP packet 2 (since the source IP address and destination IP address of IP packet 2 are inverted compared with those of IP packet 1). VM1 obtains reply information from the data part of IP packet 2 to complete the communication process between VM1 and VM2.
[0144] In summary, Gateway 1, Gateway 2, and VPC 3 are configured within Cloud Data Center 10, and the routers of VPC 1, VPC 2, and VPC 3, as well as Gateway 1 and Gateway 2, are configured such that VM 1 and VM 3 can communicate with each other when VM 1 and VM 3 have the same private network address.
[0145] For example, this embodiment of the present invention is applicable to the following scenario. VPC 3 is used as a large-scale internal network of an enterprise, and VPC 1 and VPC 2 are used as small-scale internal networks of the enterprise. For example, VPC 1 is a virtual network of the finance department of the enterprise, VPC 2 is a virtual network of the research and development department of the enterprise, and VPC 3 is a virtual network of the IT management department of the enterprise. When the private network addresses of VPC 1 and VPC 2 overlap with each other, a private network address of VPC 3 may be applied for from the control platform 6. For example, VPC 1 applies for private network address 1 of VPC 3, and VPC 2 applies for private network address 2 of VPC 3. Virtual machines within VPC 1 are associated with private network address 1 by using a gateway, and virtual machines within VPC 2 are associated with private network address 2 by using a gateway. Virtual machines within VPC 1 can access virtual machines within VPC 2 by accessing private network address 2, and virtual machines within VPC 2 can access virtual machines within VPC 1 by accessing private network address 1. In this way, the technical problem that different VPCs of an enterprise cannot communicate with each other due to overlapping private network addresses is solved.
[0146] VPC1, VPC2, and VPC3 may belong to different users. It should be noted that different users can log in to their own VPCs by using their own accounts. When VPC1 needs to connect to VPC3, the user of VPC1 may enter the account of the user of VPC3 on the control platform. The control platform sends a request to the configuration interface of VPC3 based on the account of the user of VPC3, and the user of VPC3 can check whether to accept the request on the configuration interface of VPC3. If the request is accepted, the control platform establishes a connection between VPC1 and VPC3. VPC2 and VPC3 are connected in a similar way.
[0147] In another embodiment, when VPC1, VPC2, and VPC3 belong to the same user, the user may log in to VPC1, VPC2, and VPC3 by using one account. In this case, the control platform does not need to send a request.
[0148] The user can register an account on the control platform and use the account to purchase a VPC on the payment page provided by the control platform.
[0149] Referring to FIGS. 7A and 7B, FIGS. 7A and 7B show another schematic diagram of the system structure of the VPC communication system according to an embodiment of the present invention. In contrast to the embodiment shown in FIG. 2, in this embodiment, gateway 1 may be connected to VMs in another subnet of VPC1, and gateway 2 may be connected to VMs in another subnet of VPC2. As shown in FIGS. 7A and 7B, subnet 3 (192.168.1.0 / 24) is further configured within VPC1, and VM5 is configured within subnet 3. The private network address of VM5 is 192.168.1.2. Subnet 4 (192.168.1.0 / 24) is further configured within VPC2, and VM6 is configured within subnet 4. The private network address of VM6 is 192.168.1.2.
[0150] In this case, when VM5 needs to communicate with VM6, a routing rule 7 that packets with a destination IP address belonging to 192.168.1.0 / 24 are forwarded to subnet 3 may be configured for router 1, and a routing rule 8 that packets with a destination IP address belonging to 192.168.1.0 / 24 are forwarded to subnet 4 is added to router 2. The private network address of VPC3 (for example, 10.0.0.11) is assigned to gateway 1. When the source IP address of an outgoing packet is 192.168.1.2, a packet processing rule 5 that the source IP address is modified to 10.0.0.11 is set for gateway 1. When the destination IP address of an incoming packet is 10.0.0.11, a packet processing rule 6 that the destination IP address is modified to 192.168.1.2 is set for gateway 1.
[0151] When the private network address of VPC3 (for example, 10.0.0.12) is assigned to Gateway 2 and the source IP address of the outgoing packet is 192.168.1.2, the source IP address of the outgoing packet is modified to 10.0.0.12, and the modified outgoing packet is sent to Router 3. Packet processing rule 7 is set for Gateway 2. When the destination IP address of the incoming packet is 10.0.0.12, packet processing rule 8, which modifies the destination IP address of the incoming packet to 192.168.1.2, is set for Gateway 2.
[0152] When the destination IP address of the packet is 10.0.0.12, routing rule 9, which sends the packet to Gateway 2, is set for Router 3. When the destination IP address of the packet is 10.0.0.11, routing rule 10, which sends the packet to Gateway 1, is set for Router 3.
[0153] Based on the above configuration, VM5 may construct an IP packet with a source IP address of 192.168.1.2 and a destination IP address of 10.0.0.12, and send the IP packet to VM6 in a communication method similar to the communication method of the above embodiment by using Router 1, Gateway 1, Router 3, Gateway 2, and Router 2. Further, the IP packet used for reply and returned by VM6 may be sent to VM1 by using Router 2, Gateway 2, Router 3, Gateway 1, and Router 1.
[0154] Therefore, in this embodiment of the present invention, different rules are set for the gateway and the router so that different subnets within VPC1 and VPC2 and having the same private network address segment can communicate with each other.
[0155] Furthermore, embodiments of the present invention may perform communication between on-premises data centers when private network addresses overlap with each other. Referring to FIGS. 8A to 8C, FIGS. 8A to 8C show another schematic diagram of the system structure of the VPC communication system according to embodiments of the present invention. In FIGS. 8A to 8C, based on the embodiments shown in FIGS. 3A and 3B, an on-premises data center 21 and an on-premises data center 22 are added. The on-premises data center 21 includes a subnet 5, and physical machines (PM) 1 and PM2 are arranged within the subnet 5. The on-premises data center 22 includes a subnet 6, and physical machines (PM) 3 and PM4 are arranged within the subnet 6. The subnet 5 accesses the remote connection gateway 1 within VPC1 by using the remote connection gateway 3, and the subnet 6 accesses the remote connection gateway 2 within VPC2 by using the remote connection gateway 4. A remote communication tunnel is formed between the remote connection gateway 3 and the remote connection gateway 1, and a remote communication tunnel is formed between the remote connection gateway 4 and the remote connection gateway 2. IP packets may be transmitted within the remote communication tunnel, and the IP packets remain unchanged during the transmission process.
[0156] The remote connection gateway 1 within VPC1 and the remote connection gateway 2 within VPC2 may be configured by the control platform 6 based on configuration information, and the configuration information is input into the control platform 6 by the user by using the client 7.
[0157] For example, the remote communication gateway may be a virtual private network (VPN) gateway or a manual gateway.
[0158] As shown in FIG. 8, the private network address of subnet 5 overlaps with the private network address of subnet 6, PM1 needs to communicate with PM3, and a routing rule 11 that packets with a destination IP address belonging to 192.168.2.0 / 24 are forwarded to remote connection gateway 1 may be added to router 1, and a routing rule 12 that packets with a destination IP address belonging to 192.168.2.0 / 24 are forwarded to remote connection gateway 2 is added to router 2. A packet processing rule 9 that when the source IP address of an outgoing packet is 192.168.2.2, the source IP address is modified to 10.0.0.13 is set for gateway 1, and a packet processing rule 10 that when the destination IP address of an incoming packet is 10.0.0.13, the destination IP address is modified to 192.168.2.2 is set for gateway 1.
[0159] The private network address of VPC3 (for example, 10.0.0.14) is assigned to gateway 2. A packet processing rule 11 that when the source IP address of an outgoing packet is 192.168.2.2, the source IP address is modified to 10.0.0.14 and the modified outgoing packet is sent to router 3 is set for gateway 2. A packet processing rule 12 that when the destination IP address of an incoming packet is 10.0.0.14, the destination IP address is modified to 192.168.2.2 and the modified incoming packet is sent to router 2 is set for gateway 2.
[0160] When the destination IP address of the packet is 10.0.0.14, a routing rule 13 stating that the packet is sent to gateway 2 is set for router 3. When the destination IP address of the packet is 10.0.0.13, a routing rule 14 stating that the packet is sent to gateway 1 is set for router 3.
[0161] Based on the above configuration, PM1 may construct an IP packet with a source IP address of 192.168.2.2 and a destination IP address of 10.0.0.14. The packet is transferred by switch 5 to remote connection gateway 3, sent to remote connection gateway 1 by using a remote communication tunnel, and sent to router 1 by remote connection gateway 1. Then, the IP packet is sent to remote connection gateway 2 by using router 1, gateway 1, router 3, gateway 2, and router 2 in the same communication method as the communication method of the above embodiment, and sent to remote connection gateway 4 by using a remote communication tunnel to arrive at PM3 within subnet 6. Similarly, an IP packet returned by PM3 and used for reply may be sent to PM1.
[0162] Note that the PMs within the on-premises data center may alternatively be replaced by VMs. This is not limited to this embodiment of the present invention.
[0163] Therefore, in another embodiment of the present invention, different rules are set for gateways and routers so that different subnets within the on-premises data center having the same private network address segment can communicate with each other by using the on-premises data center.
[0164] Referring to FIGS. 9A and 9B, FIGS. 9A and 9B are another schematic diagram of the system structure of the VPC communication system according to an embodiment of the present invention. Compared with the embodiment shown in FIGS. 3A and 3B, in this embodiment, gateway 1 is arranged in subnet 1, and gateway 2 is arranged in subnet 2. In this case, gateway 1 and gateway 2 may only support communication with subnet 1 and subnet 2.
[0165] In particular, based on the configuration information, the control platform 6 allocates the private network address 10.0.0.9 of the private network address segment (for example, 10.0.0.0 / 24) of VPC3 to gateway 1, and may allocate another private network address 10.0.0.10 of the private network address segment (for example, 10.0.0.0 / 24) of VPC3 to gateway 2. Further, router 1 is configured to connect to router 3, and router 2 is configured to connect to router 3.
[0166] Router 1 is Routing rule 1': When the destination IP address of the packet received by router 1 is 10.0.0.10, router 1 forwards the packet to VPC3, and Routing rule 2': When the destination IP address of the packet received by router 1 is 10.0.0.9, router 1 forwards the packet to gateway 1 are given.
[0167] Gateway 1 is Packet processing rule 1': When the source IP address of the outgoing packet received by gateway 1 is the private network address 192.168.0.2 of VM1 in subnet 1, gateway 1 converts 192.168.0.2 to the private network address 10.0.0.9 of gateway 1 in VPC3, and sends the modified outgoing packet to router 1, and Packet Processing Rule 2': When the destination IP address of a packet received by Gateway 1 falls within the range of packets received by Gateway 1 and is the private network address 10.0.0.9 of Gateway 1 in VPC3, Gateway 1 converts 10.0.0.9 to the private network address 192.168.0.2 of VM1 within Subnet 1 and sends the modified incoming packet to Gateway 1. is given.
[0168] Packets going out are the packets received by Gateway 1 from Switch 1, and incoming packets are the packets received by Gateway 1 from Router 1.
[0169] Router 2 Routing Rule 5': When the destination IP address of a packet received by Router 2 is 10.0.0.9, Router 2 forwards the packet to VPC3, and Routing Rule 6': When the destination IP address of a packet received by Router 2 is 10.0.0.10, Router 2 forwards the packet to Gateway 2 is given.
[0170] Gateway 2 Packet Processing Rule 3': When the destination IP address of an incoming packet received by Gateway 2 is 10.0.0.10, Gateway 2 converts 10.0.0.10 to 192.168.0.2 and sends the modified incoming packet to Router 2, and Packet Processing Rule 4': When the source IP address of an outgoing packet received by Gateway 2 is 192.168.0.2, Gateway 2 converts 192.168.0.2 to 10.0.0.10 and sends the modified outgoing packet to Router 1 is given.
[0171] Packets going out are the packets received by Gateway 2 from Switch 2, and packets coming in are the packets received by Gateway 1 from Router 2.
[0172] Router 3 Routing rule 3': When the destination IP address of a packet received by Router 3 is 10.0.0.10, Router 2 transfers the packet to Router 2, and Routing rule 4': When the destination IP address of a packet received by Router 2 is 10.0.0.9, Router 2 transfers the packet to Router 1 is given.
[0173] When VM1 needs to access VM3 across the VPC, VM1 constructs IP packet 1'. The source IP address of IP packet 1' is the private network address 192.168.0.2 of VM1 in Subnet 1, and the destination IP address of IP packet 1' is the private network address 10.0.0.10 of Gateway 2 in Subnet 3. The data part of IP packet 1' carries the request information.
[0174] VM1 sends IP packet 1' to Switch 1. Switch 1 determines that the destination IP address of IP packet 1' does not belong to Subnet 1 and sends IP packet 1' to Gateway 1. Gateway 1 checks packet processing rule 1' for IP packet 1', converts the source IP address of IP packet 1 from 192.168.0.2 to 10.0.0.9, and sends the modified IP packet 1' to Router 1. Router 1 checks routing rule 2' for IP packet 1' and transfers IP packet 1' to Router 3 in VPC3.
[0175] Router 3 receives IP packet 1', checks routing rule 3 for IP packet 1', and transfers IP packet 1' to Router 2 in VPC2.
[0176] Router 2 receives IP packet 1', matches routing rule 6 for IP packet 1', and forwards IP packet 1' to gateway 2.
[0177] Gateway 2 receives IP packet 1', matches packet processing rule 3' for IP packet 1', converts the destination IP address of IP packet 1' from 10.0.0.10 to 192.168.0.2, and sends IP packet 1' to switch 2. Switch 2 sends IP packet 1' to VM3.
[0178] VM3 generates reply information based on the request information carried within the data portion of IP packet 1' and constructs IP packet 2'. IP packet 2' is the reply packet of IP packet 1'. The source IP address of IP packet 2' is the destination IP address 192.168.0.2 of IP packet 1', and the destination IP address of IP packet 2' is the source IP address 10.0.0.9 of IP packet 1'. The data portion of IP packet 2' carries the reply information.
[0179] VM3 sends IP packet 2' to switch 2. Switch 2 determines that the destination IP address of IP packet 2' does not belong to subnet 2 and sends IP packet 2' to gateway 2.
[0180] Gateway 2 matches packet processing rule 4' for IP packet 2', converts the source IP address of IP packet 2' from 192.168.0.2 to 10.0.0.10, and sends IP packet 2' to router 2.
[0181] Router 2 matches routing rule 5' for IP packet 2' and forwards IP packet 2' to router 3 of VPC3.
[0182] Router 3 receives IP packet 2', matches routing rule 4' for IP packet 2', and forwards IP packet 2' to router 1 of VPC1.
[0183] Router 1 receives IP packet 2', matches routing rule 2' for IP packet 2', and forwards IP packet 2' to gateway 1.
[0184] Gateway 1 receives IP packet 2', matches packet processing rule 2' for IP packet 2', converts the destination IP address of IP packet 2' from 10.0.0.9 to 192.168.0.2, and sends IP packet 2' to switch 1. Switch 1 sends IP packet 2 to VM1.
[0185] VM1 obtains the reply information carried in IP packet 2'. For VM1, IP packet 6 is from 10.0.0.10, and IP packet 6 is the reply packet of IP packet 1'.
[0186] Ultimately, in this embodiment, although VM1 and VM2 have the same private network address, through the bridging of VPC3, VM1 and VM2 can access each other.
[0187] Furthermore, referring to FIG. 10, FIG. 10 is a schematic structural diagram of a configuration device according to an embodiment of the present invention. As shown in FIG. 10, the configuration device 60 includes a first configuration module 601 and a second configuration module 602. The first configuration module 601 is configured to execute an action of creating a gateway in the above-described embodiment, and the second configuration module 602 is configured to execute an action of setting rules for the gateway and the router in the above-described embodiment.
[0188] The configuration device 60 may be arranged on the control platform 6.
[0189] Referring to FIG. 11, FIG. 11 is a schematic structural diagram of a computing device according to an embodiment of the present invention. As shown in FIG. 11, the computing device may include a processing unit 421 and a communication interface 422. The processing unit 421 is configured to perform functions defined by, for example, an operating system and various software programs executed on a physical server in order to implement the functions of the control platform 6. The communication interface 422 is configured to communicate and interact with another computing node. The other device may be another physical server. In particular, the communication interface 422 may be a network adapter. Optionally, the physical server may further include an input / output interface 423. The input / output interface 423 is connected to an input / output device to receive input information and output operation results. The input / output interface 423 may be a mouse, a keyboard, a display, a CD-ROM drive, etc. Optionally, the physical server may further include a secondary storage device 424. The secondary storage device 424 is generally referred to as an external storage device. The storage medium of the secondary storage device 424 may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., an optical disk), a semiconductor medium (e.g., a solid state drive), etc. The processing unit 421 may have a plurality of specific implementation forms. For example, the processing unit 421 may include a processor 4212 and a memory 4211. The processor 4212 executes related operations of the control platform 6 in the above-described embodiment based on program instructions stored in the memory 4211. The processor 4212 may be a central processing unit (CPU) or a graphics processing unit (GPU). The processor 4212 may be a single-core processor or a multi-core processor.The processing unit 421 may alternatively be independently implemented by using a logic device having embedded processing logic, such as a Field Programmable Gate Array (FPGA) or a digital signal processor (DSP).
[0190] For the sake of a concise description that is just right, regarding the detailed working processes of the above-described systems, devices, and units, reference shall be made to the corresponding processes of the embodiments of the above-described methods. It will be clearly understood by those skilled in the art that the details will not be described again herein.
[0191] Furthermore, in another embodiment of the present invention, alternatively, a container may be used to replace a virtual machine. This is not limited to this embodiment of the present invention.
[0192] Embodiments of the present invention further provide a computer program product for implementing the functions of the above-described control platform. The computer program product includes a computer-readable storage medium storing program code, and the instructions included in the program code are used to execute the method steps of the method described in any one of the embodiments of the above-described method. Those skilled in the art will understand that the above-described storage medium may include any non-transitory machine-readable medium capable of storing program code, such as a USB flash drive, a removable hard disk, a magnetic disk, an optical disk, a Random-Access Memory (RAM), a Solid State Disk (SSD), or a non-volatile memory.
[0193] It should be noted that all the above-described embodiments of the devices are merely examples. The units described as separate parts may or may not be physically separated, and the parts shown as units may or may not be physical units, that is, they may be placed in one location or may be distributed over a plurality of network units. Some or all of the processes may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments. Further, in the accompanying drawings of the embodiments of the devices provided by the present invention, the connection relationships between the processes indicate that there are communication connections between the processes, and these communication connections may be implemented, in particular, as one or more communication buses or signal cables. Those skilled in the art will be able to understand and implement the embodiments of the present invention without creative efforts.
[0194] Based on the above description of the implementation, those skilled in the art will clearly understand that the present invention may be implemented by software in addition to the necessary general-purpose hardware, or may be implemented by dedicated hardware including dedicated integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally speaking, all functions that can be implemented by a computer program can be easily implemented by the corresponding hardware. Furthermore, the specific hardware structures used to implement the same function may be in various forms, such as analog circuits, digital circuits, dedicated circuits, etc. However, in the case of the present invention, in most cases, the implementation of a software program is a more excellent implementation. Based on such an understanding, the technical solution of the present invention may basically be implemented in the form of a software product, or the part that contributes to ordinary technology may be implemented in the form of a software product. The software product is stored in a readable storage medium such as a floppy disk, a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk of a computer, and includes several instructions for instructing a computer device (which may be a personal computer, a host, a network device, etc.) to execute the method described in the embodiments of the present invention.
[0195] Regarding the detailed working processes of the above-mentioned system, device, and unit, reference is made to the corresponding processes of the embodiments of the above-mentioned method, and it will be clearly understood by those skilled in the art that the details will not be described again in this specification.
[0196] The above description is only a specific implementation of the present invention and is not intended to limit the protection scope of the present invention. All changes or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention fall within the protection scope of the present invention. Therefore, the protection scope of the present invention follows the protection scope of the claims.
Description of Symbols
[0197] 6 Control Platform 7 Client 8 Internet 10 Cloud Data Center 21 On-premises Data Center 22 On-premises Data Center 60 Configuration Device 421 Processing Unit 422 Communication Interface 423 Input / Output Interface 424 Secondary Storage Device 4211 Memory 4212 Processor 601 First Configuration Module 602 Second Configuration Module
Claims
1. A method for configuring communication between a first virtual private cloud (VPC) and a second VPC that communicate with each other by using a router of a public cloud, wherein the first VPC and the second VPC are configured in the public cloud, and a first subnet of the first VPC and a second subnet of the second VPC have the same private network address segment, comprising: configuring a first gateway connected to the router of the public cloud in the first VPC and a second gateway connected to the router of the public cloud in the second VPC, wherein the first gateway is composed of a first private network address, the second gateway is composed of a second private network address different from the first private network address, and the first private network address and the second private network address are addresses belonging to the private network address segment of the public cloud; configuring a routing rule in the router of the public cloud, wherein the routing rule includes that when the destination IP address of a packet is the second private network address, the router of the public cloud forwards the packet to the second VPC, and when the destination IP address of a packet is the first private network address, the router of the public cloud forwards the packet to the first VPC; including: The first gateway is used to receive a first packet from a first virtual machine in the first subnet of the first VPC. The source IP address of the first packet is the private network address of the first virtual machine in the first subnet of the first VPC, and the destination IP address of the first packet is the second private network address of the second gateway. The first gateway converts the source IP address of the first packet from the private network address of the first virtual machine in the first subnet of the first VPC to the first private network address, and is further used to send the first packet being converted to the router of the public cloud. The router of the public cloud receives the first packet and is used to send the first packet to the second VPC according to the routing rule. The second gateway in the second VPC receives the first packet, converts the destination IP address of the first packet from the second private network address to the private network address of a second virtual machine in the second subnet of the second VPC, and is used to send the first packet being converted to the second virtual machine in the second subnet of the second VPC. The second gateway is used to receive a second packet from the second virtual machine in the second subnet of the second VPC. The second packet is a reply packet of the first packet. The source IP address of the second packet is the private network address of the second virtual machine in the second subnet of the second VPC. The destination IP address of the second packet is the first private network address of the first gateway. The second gateway is further used to convert the source IP address of the second packet from the private network address of the second virtual machine in the second subnet of the second VPC to the second private network address of the second gateway, and to send the second packet being converted to the router of the public cloud. The router of the public cloud receives the second packet and is used to send the second packet to the first VPC according to the routing rule. The first gateway in the first VPC receives the second packet, converts the destination IP address of the second packet from the first private network address to the private network address of the first virtual machine in the first subnet of the first VPC, and is used to send the second packet being converted to the first virtual machine in the first subnet of the first VPC. The method is A step of configuring a first packet processing rule in the first gateway, wherein the first packet processing rule is that when the source IP address of an outgoing packet received by the first gateway is the private network address of the first virtual machine in the first subnet of the first VPC, the first gateway converts the source IP address of the outgoing packet from the private network address of the first virtual machine in the first subnet to the first private network address of the first gateway, and transmits the outgoing packet being converted to the router of the public cloud, and the outgoing packet is a packet received by the first gateway from the first VPC, the step; A step of configuring a second packet processing rule in the first gateway, wherein the second packet processing rule is that when the destination IP address of an incoming packet received by the first gateway is the first private network address of the first gateway, the first gateway converts the destination IP address of the incoming packet from the first private network address of the first gateway to the private network address of the first virtual machine in the first subnet of the first VPC, and transmits the incoming packet being converted to the first VPC, and the incoming packet is a packet received by the first gateway from the router of the public cloud, the step; A step of configuring a third packet processing rule in the second gateway, wherein the third packet processing rule is such that when the destination IP address of a packet incoming to the second gateway is the second private network address of the second gateway, the second gateway converts the destination IP address of the incoming packet from the second private network address of the second gateway to the private network address of the second virtual machine in the second subnet of the second VPC, and transmits the incoming packet being converted to the second VPC, and the incoming packet is a packet received by the second gateway from the router of the public cloud, the step A step of configuring a fourth packet processing rule in the second gateway, wherein the fourth packet processing rule is such that when the source IP address of a packet going out from the second gateway is the private network address of the second virtual machine in the second subnet of the second VPC, the second gateway converts the source IP address of the outgoing packet from the private network address of the second virtual machine in the second subnet to the second private network address of the second gateway, and transmits the outgoing packet being converted to the router of the public cloud, and the outgoing packet is a packet received by the second gateway from the second VPC, the step further comprising a method. **Claim 2** The private network address segment to which the first private network address belongs is different from the private network address segment of the first subnet in the first VPC, and the private network address segment to which the second private network address belongs is different from the private network address segment of the second subnet in the second VPC. The method according to claim 1. **Claim 3** A step of configuring a first routing rule in a router within the first VPC, the first routing rule including that when the destination IP address of a packet received by the router within the first VPC is the second private network address, the router within the first VPC transfers the packet to the first gateway. A step of configuring a second routing rule in a router within the second VPC, the second routing rule including that when the destination IP address of a packet received by the router within the second VPC is the first private network address, the router within the second VPC transfers the packet to the second gateway. The method according to any one of claims 1 or 2, further including this.
4. The method according to any one of claims 1 to 3, wherein the router of the public cloud is configured in a third VPC of the public cloud.
5. A communication system for a virtual private cloud (VPC), a router of a public cloud, a first VPC, a second VPC, wherein the first VPC and the second VPC communicate with each other by using the router of the public cloud, the first VPC and the second VPC are configured in the public cloud, and a first subnet of the first VPC and a second subnet of the second VPC have the same private network address segment. A control platform used to configure a first gateway connected to the router of the public cloud in the first VPC and a second gateway connected to the router of the public cloud in the second VPC, wherein the first gateway is composed of a first private network address, the second gateway is composed of a second private network address different from the first private network address, and the first private network address and the second private network address are addresses belonging to the private network address segment of the public cloud, the control platform, comprising, The control platform is further used to configure a routing rule in the router of the public cloud. The routing rule includes that when the destination IP address of a packet is the second private network address, the router of the public cloud forwards the packet to the second VPC, and when the destination IP address of a packet is the first private network address, the router of the public cloud forwards the packet to the first VPC. The first gateway is used to receive a first packet from a first virtual machine in the first subnet of the first VPC. The source IP address of the first packet is the private network address of the first virtual machine in the first subnet of the first VPC, and the destination IP address of the first packet is the second private network address of the second gateway. The first gateway converts the source IP address of the first packet from the private network address of the first virtual machine in the first subnet of the first VPC to the first private network address, and is further used to send the first packet being converted to the router of the public cloud. The router of the public cloud receives the first packet and is used to send the first packet to the second VPC according to the routing rule. The second gateway in the second VPC receives the first packet, converts the destination IP address of the first packet from the second private network address to the private network address of a second virtual machine in the second subnet of the second VPC, and is used to send the first packet being converted to the second virtual machine in the second subnet of the second VPC. The second gateway is used to receive a second packet from the second virtual machine in the second subnet of the second VPC. The second packet is a reply packet of the first packet. The source IP address of the second packet is the private network address of the second virtual machine in the second subnet of the second VPC. The destination IP address of the second packet is the first private network address of the first gateway. The second gateway further uses the source IP address of the second packet to convert it from the private network address of the second virtual machine in the second subnet of the second VPC to the second private network address of the second gateway, and then sends the second packet being converted to the router of the public cloud. The router of the public cloud receives the second packet and uses it to send the second packet to the first VPC according to the routing rule. The first gateway in the first VPC receives the second packet, converts the destination IP address of the second packet from the first private network address to the private network address of the first virtual machine in the first subnet of the first VPC, and uses it to send the second packet being converted to the first virtual machine in the first subnet of the first VPC. The control platform Configuring a first packet processing rule in the first gateway, the first packet processing rule being that when the source IP address of an outgoing packet received by the first gateway is the private network address of the first virtual machine within the first subnet of the first VPC, the first gateway converts the source IP address of the outgoing packet from the private network address of the first virtual machine within the first subnet to the first private network address of the first gateway, and transmits the outgoing packet being converted to the router of the public cloud, wherein the outgoing packet is a packet received by the first gateway from the first VPC, and Configuring a second packet processing rule in the first gateway, the second packet processing rule being that when the destination IP address of an incoming packet received by the first gateway is the first private network address of the first gateway, the first gateway converts the destination IP address of the incoming packet from the first private network address of the first gateway to the private network address of the first virtual machine within the first subnet of the first VPC, and transmits the incoming packet being converted to the first VPC, wherein the incoming packet is a packet received by the first gateway from the router of the public cloud, and Configuring a third packet processing rule in the second gateway, the third packet processing rule being that when the destination IP address of a packet received by the second gateway falls within a certain range, the second gateway converts the destination IP address of the incoming packet from the second private network address of the second gateway to the private network address of the second virtual machine within the second subnet of the second VPC, and sends the incoming packet being converted to the second VPC, where the incoming packet is a packet received by the second gateway from the router of the public cloud, and Configuring a fourth packet processing rule in the second gateway, the fourth packet processing rule being that when the source IP address of an outgoing packet received by the second gateway is the private network address of the second virtual machine within the second subnet of the second VPC, the second gateway converts the source IP address of the outgoing packet from the private network address of the second virtual machine within the second subnet to the second private network address of the second gateway, and sends the outgoing packet being converted to the router of the public cloud, where the outgoing packet is a packet received by the second gateway from the second VPC, and further used to perform a system
6. The system according to claim 5, wherein the private network address segment to which the first private network address belongs is different from the private network address segment of the first subnet in the first VPC, and the private network address segment to which the second private network address belongs is different from the private network address segment of the second subnet in the second VPC.
7. The control platform is configuring a first routing rule in the router within the first VPC, the first routing rule including that when the destination IP address of a packet received by the router within the first VPC is the second private network address, the router within the first VPC forwards the packet to the first gateway, configuring a second routing rule in the router within the second VPC, the second routing rule including that when the destination IP address of a packet received by the router within the second VPC is the first private network address, the router within the second VPC forwards the packet to the second gateway, The system according to any one of claims 5 or 6, further used for performing.
8. The router of the public cloud is configured in a third VPC of the public cloud. The system according to any one of claims 5 to 7.
9. A computer program configured to cause a computer to execute the method according to any one of claims 1 to 4.
10. A computer-readable storage medium storing the computer program according to claim 9.
Citation Information
Patent Citations
Cross-VPC service access method, device and equipment, and readable storage medium
CN109361764A
Converged address translation
US20180287996A1