Security protection method, cloud access method, network architecture, apparatus, device, storage medium, and computer program product
By working together among controllers, the port blocking of the public network gateway was lifted, which solved the problem of public network access policy failure in heterogeneous availability zones, ensuring normal access to user services and flexible management of port blocking.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD
- Filing Date
- 2025-11-06
- Publication Date
- 2026-05-21
AI Technical Summary
In heterogeneous availability zones, the failure of public network access policies leads to user service access failures, and it is difficult to unblock the ports of expanded SDN vendors.
The first controller sends a port unblocking request to the second controller, controls the public network gateway to unblock the port, and implements the mapping between public IP addresses and virtual machines through the NAT gateway to ensure the effectiveness of the public network access policy.
It solves the problem of public network access policy failure in heterogeneous availability zones, and realizes the normal access of user services and flexible management of port blocking.
Smart Images

Figure CN2025133122_21052026_PF_FP_ABST
Abstract
Description
Security protection methods and cloud access methods, network architecture, devices, equipment, storage media, and computer program products.
[0001] Cross-references to related applications
[0002] This application is based on and claims priority to Chinese Patent Application No. 202411604993.3, filed on November 12, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This invention relates to the field of cloud computing technology, and in particular to a security protection method, cloud access method, network architecture, device, equipment, storage medium, and computer program product. Background Technology
[0004] Given the national requirement for interconnectivity of computing power, and considering the current situation of continuously growing domestic computing power with low utilization rates, achieving unified orchestration and intelligent scheduling of computing power is a major challenge for computing power development in various countries. Leading domestic operators have proposed a computing power network integration solution, which integrates and orchestrates computing and network resources through a computing network brain, enabling intelligent scheduling and real-time response of computing resources, thereby maximizing the computing power supply capacity, data processing capacity, network connectivity capacity, and service supply capacity of the computing network.
[0005] As shown in Figure 1, computing power grid connection involves cloud platforms from multiple vendors. Different vendors use different Software Defined Network (SDN) solutions, and east-west traffic within the cloud is naturally isolated between different SDN vendors.
[0006] From the perspectives of cost and convenience, there are scenarios where different SDN vendors share the same public network exit point. Access from outside the cloud via the Internet Protocol (IP) is primarily achieved through a two-level mapping mechanism between the Virtual Private Cloud (VPC) address and the public network address: first, the internal network address is mapped to an intermediate address, and then from the intermediate address to the public network address. To ensure the security of user service ports, SDN vendors typically block ports on their respective gateways. Users can unblock ports as needed to provide services based on specific ports.
[0007] However, in heterogeneous SDN vendor availability zones sharing a single exit, the different port blocking schemes adopted by different SDN vendors make it difficult to unblock the ports of the expanded SDN vendor (such as vendor 2 shown in Figure 2) according to user needs, resulting in user service access failures. Summary of the Invention
[0008] The purpose of this invention is to provide a security protection method, cloud access method, network architecture, device, equipment, storage medium, and computer program product, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0009] To achieve the above objectives, embodiments of the present invention provide a security protection method applied to a first controller, comprising:
[0010] If the first condition is met, a port unblocking request is sent to the second controller. The port unblocking request is used to request the unblocking of the port of the target virtual public Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone.
[0011] The first condition includes at least one of the following:
[0012] The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone;
[0013] The target public IP address of the user instance has been successfully registered, and in the Destination Network Address Translation (DNAT) rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone;
[0014] The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to enable communication with the international Internet.
[0015] The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0016] To achieve the above objectives, embodiments of the present invention provide a security protection method applied to a second controller, comprising:
[0017] Receive port unblocking request sent by the first controller;
[0018] Based on the port unblocking request, the public network gateway in the first availability zone is controlled to perform a port unblocking operation. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance.
[0019] The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0020] To achieve the above objectives, embodiments of the present invention provide a security protection method applied to a public network gateway, comprising:
[0021] Upon receiving a port unblocking instruction from the second controller, the port blocking of the target virtual public IP address or the port blocking of the target port is lifted. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to lift the port blocking of the target virtual public IP address or to lift the port blocking of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address.
[0022] The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0023] To achieve the above objectives, embodiments of the present invention provide a security protection method applied to a third controller, comprising:
[0024] Upon receiving the first configuration information sent by the first controller, the third configuration information is sent to the NAT gateway. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance, and the third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address.
[0025] The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
[0026] To achieve the above objectives, embodiments of the present invention provide a cloud access method applied to a NAT gateway, comprising:
[0027] Upon receiving a first access request, the destination address of the first access request is replaced by the target public IP address with the target virtual public IP address corresponding to the target public IP address to obtain the first target information, and the first target information is transmitted to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address.
[0028] The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet;
[0029] The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0030] To achieve the above objectives, embodiments of the present invention provide a cloud access method, applied to a public network gateway, comprising:
[0031] Upon receiving the first target information, the destination address of the first target information is replaced with the target virtual public IP address and the target intermediate address to obtain the second target information;
[0032] The second target information is forwarded to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the compute node corresponding to the target intermediate address. The virtual router on the compute node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
[0033] To achieve the above objectives, embodiments of the present invention provide a network architecture, including:
[0034] The first availability zone includes the second SDN gateway and the public network gateway;
[0035] The second availability zone adopts a different SDN structure from the first availability zone, and the second availability zone includes the first SDN gateway;
[0036] The system comprises a first switch, a NAT gateway, and an egress router. The first switch is connected to a first SDN gateway, a second SDN gateway, the public network gateway, the NAT gateway, and the egress router, respectively. The egress router is connected to the Internet. Both the second availability zone and the first availability zone communicate with the Internet via the egress router.
[0037] The system comprises a first controller, a second controller, and a third controller. The first controller controls the second controller and the third controller. The second controller controls the public network gateway and the second SDN gateway. The third controller controls the NAT gateway and the first SDN gateway.
[0038] To achieve the above objectives, embodiments of the present invention provide a safety protection device applied to a first controller, comprising:
[0039] The first blocking module is configured to send a port unblocking request to the second controller when a first condition is met. The port unblocking request is used to request the unblocking of the port of the target virtual public network Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone.
[0040] The first condition includes at least one of the following:
[0041] The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone;
[0042] The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone;
[0043] The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet.
[0044] The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0045] To achieve the above objectives, embodiments of the present invention provide a safety protection device applied to a second controller, comprising:
[0046] The third receiving module is configured to receive port unblocking requests sent by the first controller;
[0047] The first control module is configured to control the public network gateway in the first availability zone to perform a port blocking unblocking operation based on the port unblocking request. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance.
[0048] The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0049] To achieve the above objectives, embodiments of the present invention provide a security protection device applied to a public network gateway, comprising:
[0050] The unblocking module is configured to, upon receiving a port unblocking instruction sent by the second controller, unblock the port of the target virtual public IP address or unblock the port of the target port. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to unblock the port of the target virtual public IP address or unblock the port of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address.
[0051] The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0052] To achieve the above objectives, embodiments of the present invention provide a safety protection device applied to a third controller, comprising:
[0053] The first sending module is configured to send third configuration information to the NAT gateway upon receiving first configuration information sent by the first controller. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance. The third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address.
[0054] The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
[0055] To achieve the above objectives, embodiments of the present invention provide a cloud access device applied to a NAT gateway, comprising:
[0056] The first processing module is configured to, upon receiving a first access request, replace the destination address of the first access request with the target public IP address and the target virtual public IP address corresponding to the target public IP address, obtain first target information, and transmit the first target information to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address.
[0057] The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet;
[0058] The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0059] To achieve the above objectives, embodiments of the present invention provide a cloud access device applied to a public network gateway, comprising:
[0060] The second processing module is configured to, upon receiving the first target information, replace the destination address of the first target information with the target virtual public IP address and the target intermediate address to obtain the second target information;
[0061] The third processing module is configured to forward the second target information to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the computing node corresponding to the target intermediate address. The virtual router on the computing node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
[0062] To achieve the above objectives, embodiments of the present invention provide a device, which is a first controller, including a processor and a transceiver, wherein the transceiver is configured as follows:
[0063] If the first condition is met, a port unblocking request is sent to the second controller. The port unblocking request is used to request the unblocking of the port of the target virtual public Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone.
[0064] The first condition includes at least one of the following:
[0065] The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone;
[0066] The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone;
[0067] The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet.
[0068] The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0069] To achieve the above objectives, embodiments of the present invention provide a device, which is a second controller, including a processor and a transceiver, wherein the transceiver is configured to receive a port unblocking request sent by a first controller;
[0070] The processor is configured to control the public network gateway in the first availability zone to perform a port blocking unblocking operation based on the port unblocking request. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance.
[0071] The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0072] To achieve the above objectives, embodiments of the present invention provide a device, which is a public network gateway and a second controller, including a processor and a transceiver, wherein the processor is configured as follows:
[0073] Upon receiving a port unblocking instruction from the second controller, the port blocking of the target virtual public IP address or the port blocking of the target port is lifted. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to lift the port blocking of the target virtual public IP address or to lift the port blocking of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address.
[0074] The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0075] To achieve the above objectives, embodiments of the present invention provide a device, which is a third controller, including a processor and a transceiver. The transceiver is configured to send third configuration information to a NAT gateway upon receiving first configuration information sent by a first controller. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of a user instance, and the third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address.
[0076] The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
[0077] To achieve the above objectives, this invention provides a device, which is a NAT gateway, including a processor and a transceiver. The processor is configured to, upon receiving a first access request, replace the destination address of the first access request with a target public IP address and then with a target virtual public IP address corresponding to the target public IP address, thereby obtaining first target information. The processor then transmits the first target information to a public gateway in a first availability zone. The first access request is used to request access to a target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address.
[0078] The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet;
[0079] The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0080] To achieve the above objectives, embodiments of the present invention provide a device, which is a public network gateway, including a processor and a transceiver, wherein the processor is configured as follows:
[0081] Upon receiving the first target information, the destination address of the first target information is replaced with the target virtual public IP address and the target intermediate address to obtain the second target information;
[0082] The second target information is forwarded to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the compute node corresponding to the target intermediate address. The virtual router on the compute node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
[0083] To achieve the above objectives, embodiments of the present invention provide a device, including a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; when the processor executes the program or instructions, it implements the security protection method applied to a first controller, or the security protection method applied to a second controller, or the security protection method applied to a public network gateway, or the security protection method applied to a third controller, or the cloud access method applied to a NAT gateway, or the cloud access method applied to a public network gateway.
[0084] To achieve the above objectives, a computer program product is provided, including computer instructions that, when executed by a processor, implement the steps of the security protection method applied to a first controller, or the steps of the security protection method applied to a second controller, or the steps of the security protection method applied to a public network gateway, or the steps of the security protection method applied to a third controller, or the steps of the cloud access method applied to a NAT gateway, or the steps of the cloud access method applied to a public network gateway.
[0085] To achieve the above objectives, embodiments of the present invention provide a readable storage medium storing a program or instructions thereon. When the program or instructions are executed by a processor, they implement the steps described above in the security protection method applied to the first controller, or the steps described above in the security protection method applied to the second controller, or the steps described above in the security protection method applied to the public network gateway, or the steps described above in the security protection method applied to the third controller, or the steps described above in the cloud access method applied to the NAT gateway, or the steps described above in the cloud access method applied to the public network gateway.
[0086] The beneficial effects of the above technical solutions in the embodiments of the present invention are as follows:
[0087] In this embodiment of the invention, a heterogeneous first availability zone and a second availability zone share an egress router and a NAT gateway to achieve communication with the international Internet. For this scenario, a port blocking policy is set on the public network gateway in the first availability zone for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone. Thus, a port unblocking request can be sent from the first controller to the second controller, allowing the second controller to control the public network gateway in the first availability zone to perform a port unblocking operation. This removes the port blocking of the target virtual IP address corresponding to the user instance by the public network gateway in the first availability zone, thereby solving the problem of public network access policy failure in heterogeneous availability zones. Attached Figure Description
[0088] Figure 1 shows the heterogeneous architecture of SDN from multiple cloud vendors in related technologies;
[0089] Figure 2 is a schematic diagram of a model in related technologies where two different Availability Zones (AZs) are heterogeneous SDNs and share a single outbound traffic.
[0090] Figure 3 is a flowchart of one of the security protection methods according to an embodiment of the present invention;
[0091] Figure 4 is a schematic diagram of a model in which heterogeneous SDNs with the same AZ share a single outbound traffic in an embodiment of the present invention;
[0092] Figure 5 is a diagram of the public IP address blocking and orchestration architecture according to an embodiment of the present invention;
[0093] Figure 6 is one of the timing diagrams for public IP blocking orchestration of heterogeneous controllers according to an embodiment of the present invention;
[0094] Figure 7 is the second timing diagram of the public IP blocking orchestration of the heterogeneous controller according to an embodiment of the present invention;
[0095] Figure 8 is a flowchart of public IP blocking under the DNAT rule application scenario of this invention.
[0096] Figure 9 is a second flowchart of the security protection method according to an embodiment of the present invention;
[0097] Figure 10 is a flowchart of the third embodiment of the security protection method of the present invention;
[0098] Figure 11 is a flowchart of the fourth embodiment of the security protection method of the present invention;
[0099] Figure 12 is a flowchart of the cloud access method according to an embodiment of the present invention;
[0100] Figure 13 is a flowchart of another embodiment of the cloud access method of the present invention;
[0101] Figure 14 is a structural diagram of one of the safety protection devices according to an embodiment of the present invention;
[0102] Figure 15 is a second structural diagram of the safety protection device according to an embodiment of the present invention;
[0103] Figure 16 is a structural diagram of the safety protection device according to an embodiment of the present invention (third one).
[0104] Figure 17 is a structural diagram of the safety protection device according to an embodiment of the present invention (fourth one).
[0105] Figure 18 is a structural diagram of the cloud access device according to an embodiment of the present invention;
[0106] Figure 19 is a structural diagram of a cloud access device according to another embodiment of the present invention;
[0107] Figure 20 is a structural diagram of the device according to an embodiment of the present invention;
[0108] Figure 21 is a structural diagram of a device according to another embodiment of the present invention. Detailed Implementation
[0109] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0110] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0111] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0112] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0113] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0114] As shown in Figure 3, a security protection method according to an embodiment of the present invention is applied to a first controller, including:
[0115] Step 301: Under the condition of satisfying the first condition, a port unblocking request is sent to the second controller. The port unblocking request is used to request the unblocking of the port of the target virtual public Internet Protocol (IP) address corresponding to the user instance by the public network gateway in the first availability zone. The first condition includes at least one of the following: (1) the target public IP address of the user instance is successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone; (2) the target public IP address of the user instance is successfully registered and the internal IP address points to the target virtual machine in the first availability zone in the target destination address translation (DNAT) rule corresponding to the target public IP address. The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures and share an egress router and a network address translation (NAT) gateway with the second availability zone to realize communication with the Internet. The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0116] Here, a specific embodiment of the present invention will be described with reference to Figures 4 and 5:
[0117] As shown in Figure 4, there is a first availability zone (the availability zone corresponding to vendor 2) and a second availability zone (the availability zone corresponding to vendor 1, where vendor 1 and vendor 2 use different SDN schemes). Both share an egress router and a NAT gateway. In this embodiment of the invention, a public network gateway is added to the first availability zone. This public network gateway is configured with a port blocking policy for the virtual public IP addresses corresponding to the public IP addresses bound to the virtual machines in the first availability zone.
[0118] As shown in Figure 5, the first controller mentioned above can specifically be a heterogeneous controller. The first controller can control the second and third controllers. The second controller can control the public network gateway (i.e., vendor 2 public network gateway) and vendor 2 SDN gateway (i.e., the second SDN gateway) in the first availability zone. The third controller can control the NAT gateway and vendor 1 SDN gateway (i.e., the first SDN gateway). It should be noted that since the two heterogeneous availability zones share a single NAT gateway, in order to reduce the load on the NAT gateway and ensure its forwarding performance, cloud security protection needs to be distributed across their respective SDN gateways.
[0119] It should also be noted that a public network gateway (not shown in the attached diagram) can also be set in the second availability zone. The public network gateway in the second availability zone can be managed by the third controller. The public network gateway in the second availability zone is configured with port blocking policies corresponding to the public IPs bound to the virtual machines in the second availability zone.
[0120] It should be noted that users can subscribe to public IP services through the console. The heterogeneous controller can allocate public IP addresses to users and persist the public IP information. Afterwards, users can subscribe to instances (i.e., user instances, such as cloud server instances) through the console. Once the subscription is successful, the public IP address is bound to the cloud server, allowing the cloud server to provide services externally through its bound public IP address. Alternatively, the DNAT rule corresponding to the public IP address can be configured to provide services externally. This embodiment of the invention mainly describes the security protection method (including blocking and deblocking methods) for the first availability zone, specifically when the target public IP address corresponds to the target virtual machine in the first availability zone, or when the internal IP address in the target destination address translation DNAT rule corresponding to the target public IP address points to the target virtual machine in the first availability zone. In these cases, if the target public IP address of the user instance is successfully registered, the first controller sends a port deblocking request to the second controller, enabling the second controller to control the public gateway in the first availability zone to unblock the port of the target virtual public IP address corresponding to the user instance.
[0121] In this embodiment, the heterogeneous first and second availability zones share an egress router and a NAT gateway to achieve communication with the international Internet. For this scenario, a port blocking policy is set on the public network gateway in the first availability zone for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone. Thus, the first controller can send a port unblocking request to the second controller, enabling the second controller to control the public network gateway in the first availability zone to perform a port unblocking operation. This removes the port blocking of the target virtual IP address corresponding to the user instance by the public network gateway in the first availability zone, thereby solving the problem of public network access policy failure in heterogeneous availability zones.
[0122] In some embodiments, the method further includes: upon obtaining a first creation request and a target virtual public IP address corresponding to the target public IP address, sending a second creation request to a second controller; wherein the first creation request is used to request the creation of a DNAT rule corresponding to the target public IP address; and the second creation request is used to request the second controller to create a DNAT rule corresponding to the target virtual public IP address.
[0123] It should be noted that if this is not the first time a DNAT rule has been created for a public IP address, a corresponding virtual public IP address should have been allocated for that public IP address when the DNAT rule corresponding to that public IP address was created previously. Therefore, upon obtaining the first creation request and the target virtual public IP address corresponding to the target public IP address, the first controller can send a second creation request to the second controller to enable the second controller to create the DNAT rule corresponding to the target public IP address.
[0124] In some embodiments, the method further includes: sending a third creation request to the second controller when a second condition is met, the third creation request being used to request the second controller to create a virtual public IP address corresponding to the target public IP address; receiving the target virtual public IP address corresponding to the target public IP address from the second controller; and storing the mapping relationship between the target public IP address and the target virtual public IP address; wherein the second condition includes at least one of the following:
[0125] (1) The first creation request is received but the target virtual public IP address corresponding to the target public IP address is not obtained.
[0126] Here, the first creation request is used to request the creation of a DNAT rule corresponding to the target public IP address. This request can be sent by the user to the first controller via the console. In other words, when a user requests to create a DNAT rule, if the target virtual public IP address corresponding to the target public IP address is not obtained, it indicates that this is the first time a DNAT rule has been created for that target public IP address. In this case, the first controller needs to first request the second controller to create the virtual public IP address corresponding to the target public IP address.
[0127] (2) Receive binding instruction information, the binding instruction information is used to indicate that the target public IP address has been bound to the target virtual machine in the first availability zone.
[0128] It should be noted that after a user successfully orders an instance through the console, the public IP address is bound to the target virtual machine (e.g., a cloud host) in the first availability zone. The first controller can receive the binding instruction information. After that, the first controller needs to request the second controller to create a virtual public IP address corresponding to the target public IP address.
[0129] (3) Receive first migration instruction information, which is used to instruct the user instance to migrate from the second availability zone to the first availability zone.
[0130] It should be noted that when a user instance migrates from the second availability zone to the first availability zone, a virtual public IP address corresponding to the target public IP address needs to be assigned to establish a mapping relationship between the target public IP address and the virtual public IP address, thereby achieving security protection for the target public IP address.
[0131] It should be noted that two private network address ranges can be reserved (pre-configured) for the first availability zone: a virtual public IP address range (let's say address range B) and a preset intermediate address range (let's say address range C). Understandably, address range B and address range C must not conflict with the private network address range reserved for the second availability zone (let's say address range A).
[0132] In this embodiment, the first controller can send a third creation request to the second controller, so that the second controller can create a virtual public IP address corresponding to the target public IP address.
[0133] In one embodiment, before storing the mapping relationship between the target public IP address and the target virtual public IP address, the method further includes: sending first configuration information to a third controller, the first configuration information being used to indicate the mapping relationship between the target public IP address and the target virtual public IP address.
[0134] In one embodiment, the method further includes: after the user instance migrates from the second availability zone to the first availability zone, sending second migration indication information to a third controller, the second migration indication information being used to indicate that the user instance has migrated out of the second availability zone.
[0135] In other words, after the migration of user instances (such as cloud host instances) is completed, the first controller can notify the third controller through the second migration instruction information that the user instance has been migrated out of the second availability zone, thereby enabling the third controller to control the vendor 1-SDN gateway (i.e. the first SDN gateway) to restore the port blocking configuration (i.e. restore port blocking of the target public IP address).
[0136] In one embodiment, the target virtual public IP address corresponds one-to-one with the target intermediate address, which is created by the second controller.
[0137] The application of the embodiments of the present invention will be described below with reference to specific scenarios.
[0138] Application Scenario 1:
[0139] Users can order instances (i.e., user instances, such as cloud server instances) through the console. The first controller assigns a target public IP address to the user instance. After successful ordering, the target public IP address is bound to the cloud server, allowing the cloud server to provide services externally through its bound public IP address. In the following embodiments, the first controller is a heterogeneous controller and the user instance is a cloud server instance as an example.
[0140] For example, after the target public IP address is bound to the cloud server, the heterogeneous controller can perform corresponding orchestration based on the availability zone where the cloud server instance is located (that is, the availability zone where the subnet corresponding to the cloud server is located). This application scenario mainly consists of the following two cases:
[0141] Scenario 1:
[0142] If the cloud host instance (bound to the target public IP address) is located in the second availability zone, that is, when the target public IP address corresponds to the target virtual machine in the second availability zone, the heterogeneous controller sends a request to the third controller. After receiving the request from the first controller, the third controller performs the following configuration: allocates an intermediate address within the address range A to the cloud host instance; notifies the NAT gateway of the mapping relationship between the intermediate address and the target public IP address; and sets the port blocking configuration (i.e., port blocking policy) for the intermediate address on the vendor 1-SDN gateway.
[0143] Users will register the target public IP address as needed, such as registering as an Internet Content Provider (ICP). Once the registration (e.g., ICP registration) is successful, the console invokes the first controller, which then sends a port unblocking request to the third controller. Upon receiving this request, the third controller unblocks the intermediate address corresponding to the target public IP address on the vendor's 1-SDN gateway. Afterward, the cloud server instance can provide services based on the unblocked port.
[0144] Scenario 2:
[0145] If the cloud host instance (bound to the target public IP address) is located in the first availability zone, that is, when the target public IP address corresponds to the target virtual machine in the first availability zone, as shown in Figure 6, the heterogeneous controller performs the following processing:
[0146] The heterogeneous controller sends a third creation request (requesting the creation of a virtual public IP address corresponding to the target public IP address) to the second controller, causing the second controller to create a virtual public IP address within address segment B. After receiving the target virtual public IP address corresponding to the target public IP address from the second controller, the heterogeneous controller records the mapping relationship between the target public IP address (i.e., the real public IP address) and the target virtual public IP address. Subsequently, the heterogeneous controller can control the third controller to maintain the mapping relationship between the target public IP address and the target virtual public IP address.
[0147] After receiving the third creation request, the second controller performs the following configuration: It creates a new target virtual public IP address within address range B and sends this target virtual public IP address back to the first controller. If the target public IP address is already bound to a target virtual machine in the first availability zone, the first controller sends a binding request to the second controller. Upon receiving the binding request, the second controller allocates a target intermediate address within address range C to the instance. This target intermediate address and the target virtual public IP address have a one-to-one correspondence. Then, the second controller sends second configuration information to the public network gateway to record the mapping relationship between the target intermediate address and the target virtual public IP address on the public network gateway. Finally, the public network gateway sets up port blocking configuration for the target virtual public IP address based on the target virtual public IP address (by default, the port corresponding to the target virtual public IP address is set to blocked).
[0148] As shown in Figure 7, after a user successfully registers the target public IP address, the console calls the heterogeneous controller. The heterogeneous controller queries the virtual public IP address corresponding to the target public IP address and sends a port unblocking request to the second controller. The second controller then unblocks the port corresponding to the target intermediate address of the registered virtual public IP address on the public network gateway of the first availability zone. At this point, the user instance can provide services to the outside world based on the unblocked port.
[0149] In the above application scenario one, regardless of whether the user instance is in the first availability zone or the second availability zone, port blocking and deblocking can be performed based on their respective intermediate addresses, thereby achieving a unified security protection solution in heterogeneous scenarios.
[0150] Application Scenario 2:
[0151] Public IP addresses can be bound to cloud servers and used in NAT rules of NAT gateways, meaning they can be configured with DNAT rules to provide services externally. It's important to note that in heterogeneous availability zone scenarios, multiple DNAT rules can be configured for the same public IP address, but the backend only supports one availability zone at a time.
[0152] For example, as shown in Figure 8, if the user has already filed a record for the target public IP address, then when setting up DNAT rules, the port unblocking process for the corresponding port in the first availability zone is as follows:
[0153] S801: Determine if the FIP (i.e., public IP address) is the first time a DNAT rule has been created; if yes, execute S802; otherwise, execute S804.
[0154] It should be noted that if this is not the first time a DNAT rule has been created for a public IP address, a corresponding virtual public IP address should have been assigned to that public IP address when the DNAT rule for that public IP address was created previously. Therefore, you can determine whether this is the first time a DNAT rule has been created for a target public IP address by checking whether a target virtual public IP address exists.
[0155] S802: In other words, if it is determined that the target public IP address is creating a DNAT rule for the first time, the first controller (heterogeneous controller) sends a third creation request to the second controller to control the second controller to create a virtual public IP address corresponding to the target public IP address.
[0156] S803: The heterogeneous controller receives the target virtual public IP address corresponding to the target public IP address fed back by the second controller, and saves the mapping information between the actual public IP address (i.e., the target public IP address) and the target virtual public IP address.
[0157] Additionally, the heterogeneous controller also distributes configuration information to the third controller for configuring the NAT gateway. For example, the heterogeneous controller sends first configuration information to the third controller, indicating the mapping relationship between the target public IP address and the target virtual public IP address. After receiving the first configuration information, the third controller can then send third configuration information to the NAT gateway, instructing the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address.
[0158] S804: This means that if it's determined that the target public IP address is not the first time a DNAT rule has been created, or if it's the first time a DNAT rule has been created and the second controller has already received feedback on the target virtual public IP address corresponding to the target public IP address, then the first controller (heterogeneous controller) sends a second creation request to the second controller to control the second controller to create the DNAT rule corresponding to the target virtual public IP address. Thus, after receiving the second creation request from the first controller, the second controller can use the target public IP address to create the target DNAT rule.
[0159] For example, after the first controller obtains the first creation request, it modifies the value corresponding to the public IP attribute in the first creation request to the target virtual public IP address, obtains the second creation request, and sends the second creation request to the second controller, which then completes the creation of the DNAT rule.
[0160] When a user has already registered the target public IP address, the first controller encapsulates the port unblocking request data differently based on the Availability Zone (AZ) where the resource (taking a cloud server as an example) is located. For example, if the resource is in the first Availability Zone, the first controller uses the target virtual public IP address, carrying the external port (i.e., the target port) in the DNAT rule, to send a port unblocking request to the second controller, causing the second controller to notify the corresponding public gateway to complete the unblocking configuration.
[0161] Application Scenario 3:
[0162] In scenarios involving cross-AZ or cross-POD migration of cloud servers, when a user binds a public IP address to a cloud server and provides specific port services externally, if the user instance needs to be migrated from the second availability zone to the first availability zone, the corresponding unblocking information also needs to be migrated synchronously to the first availability zone. The heterogeneous controller encapsulates the target virtual public IP address and the registered port information (i.e., the target port information) and sends it to the second controller. The public network gateway completes the pre-configuration of unblocking and saves the unblocking information of the first availability zone (including the target virtual public IP address and target port information). In addition, the third controller can also control the first SDN gateway in the second availability zone to restore port blocking of the target public IP address.
[0163] In this embodiment of the security protection method, the heterogeneous first and second availability zones share an egress router and a NAT gateway to achieve communication with the international Internet. In this scenario, the public network gateway in the first availability zone is configured with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone. Thus, the first controller can send a port unblocking request to the second controller, enabling the second controller to control the public network gateway in the first availability zone to perform a port unblocking operation, thereby unblocking the port of the target virtual IP address corresponding to the user instance from the public network gateway in the first availability zone, and thus solving the problem of public network access policy failure in heterogeneous availability zones.
[0164] As shown in Figure 9, a security protection method according to an embodiment of the present invention is applied to a second controller, including:
[0165] Step 901: Receive the port unblocking request sent by the first controller.
[0166] Step 902: Based on the port unblocking request, control the public network gateway in the first availability zone to perform a port unblocking operation. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance. The first controller is used to control the second controller, and the second controller is used to control the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0167] Here, a specific embodiment of the present invention will be described with reference to Figures 4 and 5:
[0168] As shown in Figure 4, the first availability zone (the availability zone corresponding to vendor 2) and the second availability zone (the availability zone corresponding to vendor 1, and vendor 1 and vendor 2 use different SDN schemes) share the same egress router and NAT gateway.
[0169] As shown in Figure 5, the first controller mentioned above can be a heterogeneous controller. The first controller can control the second controller and the third controller. The second controller can control the public network gateway (i.e., vendor 2-public network gateway) and vendor 2-SDN gateway (i.e., the second SDN gateway) in the first availability zone. The third controller can control the NAT gateway and vendor 1-SDN gateway (i.e., the first SDN gateway).
[0170] In this embodiment, after receiving the port unblocking request sent by the first controller, the second controller can control the public network gateway in the first availability zone to perform a port unblocking operation, so as to unblock the port of the target virtual public IP address corresponding to the user instance. In this way, the user instance in the first availability zone can provide services to the outside world through its bound public IP address, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0171] In some embodiments, controlling the public network gateway in the first availability zone to perform port blocking unblocking operation according to the port unblocking request includes: sending a port unblocking instruction to the public network gateway, the port unblocking instruction being used to instruct the public network gateway to unblock the port of the target virtual public IP address, or to unblock the port of the target port, the target port being a port that has been successfully registered.
[0172] It should be noted that, when the target public IP address corresponds to the target virtual machine in the first availability zone, the public network gateway will unblock the port of the target virtual public IP address according to the port unblocking instruction; when the internal IP address in the target DNAT rule corresponding to the target public IP address points to the target virtual machine in the first availability zone, the public network gateway will unblock the port of the target port according to the port unblocking instruction.
[0173] In some embodiments, the method further includes: receiving a third creation request sent by the first controller, the third creation request being used to request the second controller to create a virtual public IP address corresponding to the target public IP address; creating a new target virtual public IP address located within a virtual public IP address range according to the third creation request, the virtual public IP address range being pre-configured for the first availability zone; and sending the target virtual public IP address to the first controller.
[0174] It should be noted that two private network address segments can be pre-configured for the first availability zone: a virtual public IP address segment (let's say address segment B) and a preset intermediate address segment (let's say address segment C). Understandably, neither address segment B nor address segment C can conflict with the private network address segment reserved for the second availability zone (let's say address segment A).
[0175] In this embodiment, after receiving the third creation request sent by the first controller, the second controller can allocate a target virtual public IP address within address segment B, so that the first controller can configure the mapping relationship between the target public IP address and the target virtual public IP address on the public network gateway of the first availability zone.
[0176] In some embodiments, when the target public IP address is already bound to the target virtual machine in the first availability zone, after creating a new target virtual public IP address within the virtual public IP address range according to the third creation request, the method further includes: creating a new target intermediate address within a preset intermediate address range, wherein the target intermediate address corresponds one-to-one with the target virtual public IP address, and the preset intermediate address range is pre-configured for the first availability zone.
[0177] In this embodiment, after allocating the target virtual public IP address, the second controller can also allocate the target intermediate address within address segment C, so that the first controller can configure the mapping relationship between the target virtual public IP address and the target intermediate address on the public network gateway of the first availability zone.
[0178] In some embodiments, after creating a new target intermediate address located within a preset intermediate address range, the method further includes:
[0179] Send second configuration information to the public network gateway, the second configuration information including the target intermediate address corresponding to the target virtual public IP address.
[0180] In this embodiment, the second controller can configure the mapping relationship between the target virtual public IP address and the target intermediate address on the public network gateway of the first availability zone through the second configuration information. After the user registers the target public IP address, the first controller sends a port unblocking request to the second controller, requesting the public network gateway to unblock the port of the target virtual public IP address. After receiving the port unblocking request, the second controller controls the public network gateway to perform the port unblocking operation, thereby unblocking the target virtual public IP address on the public network gateway. In this way, based on the intermediate address mapped from the public IP address, port blocking and unblocking are implemented on different SDN gateways on the basis of heterogeneous interconnection, achieving unified access protection in heterogeneous scenarios.
[0181] In some embodiments, the method further includes: receiving a second creation request sent by the first controller; and creating a target DNAT rule using the target public IP address according to the second creation request, wherein the second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
[0182] It should be noted that when creating the DNAT rule corresponding to the target virtual public IP address, the DNAT rule includes parameters such as internal IP and public IP. The internal IP points to the target virtual machine in the first availability zone, and the public IP is the target public IP address.
[0183] In this security protection method, the second controller, controlled by the first controller, can create a virtual public IP address and a target intermediate address corresponding to the target public IP address to achieve a three-level mapping of public IP addresses. This enables blocking of the target virtual public IP address on the public network gateway. The second controller can also create a target DNAT rule corresponding to the target virtual public IP address. Thus, after receiving a port unblocking request from the first controller, the second controller can control the public network gateway in the first availability zone to perform a port unblocking operation, thereby unblocking the port of the target virtual public IP address corresponding to the user instance. In this way, the user instance in the first availability zone can provide services to the outside world through its bound public IP address, solving the problem of public network access policy failure in heterogeneous availability zones.
[0184] As shown in Figure 10, a security protection method applied to a public network gateway includes:
[0185] Step 1001: Upon receiving a port unblocking instruction from the second controller, unblock the port on the target virtual public IP address or unblock the port on the target port. The port unblocking instruction instructs the public network gateway in the first availability zone to unblock the port on the target virtual public IP address or unblock the port on the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address. The second controller controls the public network gateway, which is configured with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0186] Here, a specific embodiment of the present invention will be described with reference to Figures 4 and 5:
[0187] As shown in Figure 4, the first availability zone (the availability zone corresponding to vendor 2) and the second availability zone (the availability zone corresponding to vendor 1, and vendor 1 and vendor 2 use different SDN schemes) share the same egress router and NAT gateway.
[0188] As shown in Figure 5, the first controller mentioned above can be a heterogeneous controller. The first controller can control the second controller and the third controller. The second controller can control the public network gateway (i.e., vendor 2-public network gateway) and vendor 2-SDN gateway (i.e., the second SDN gateway) in the first availability zone. The third controller can control the NAT gateway and vendor 1-SDN gateway (i.e., the first SDN gateway).
[0189] In this embodiment, after receiving the port unblocking instruction sent by the second controller, the public network gateway can unblock the port according to the port unblocking instruction. In this way, user instances in the first availability zone can provide services to the outside world through their bound public IP addresses, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0190] In one embodiment, the method further includes: receiving second configuration information sent by the first controller, the second configuration information including a target intermediate address corresponding to the target virtual public IP address; and storing a mapping relationship between the target virtual public IP address and the target intermediate address.
[0191] In this embodiment, after receiving the second configuration information sent by the first controller, the public network gateway can store the mapping relationship between the target virtual public IP address and the target intermediate address. Then, through three-level mapping of public IP addresses, it can achieve blocking and deblocking of the target virtual public IP address on the public network gateway. Thus, based on heterogeneous interconnection and the intermediate address mapped from the public IP address, port blocking and deblocking are implemented on different SDN gateways, achieving unified access protection in heterogeneous scenarios.
[0192] The security protection method in this embodiment configures a mapping relationship between the target virtual public IP address and the target intermediate address on the public network gateway, enabling the blocking and unblocking of the target virtual public IP address. Thus, user instances in the first availability zone can provide services externally through their bound public IP addresses, resolving the problem of public network access policies failing in heterogeneous availability zones.
[0193] As shown in Figure 11, a security protection method according to an embodiment of the present invention is applied to a third controller, including:
[0194] Step 1101: Upon receiving the first configuration information sent by the first controller, send third configuration information to the NAT gateway. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance. The third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address. The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
[0195] Here, a specific embodiment of the present invention will be described with reference to Figures 4 and 5:
[0196] As shown in Figure 4, the first availability zone (the availability zone corresponding to vendor 2) and the second availability zone (the availability zone corresponding to vendor 1, where vendor 1 and vendor 2 use different SDN schemes) share an egress router and a NAT gateway. As shown in Figure 5, the aforementioned first controller can specifically be a heterogeneous controller. The first controller can control the second controller and the third controller. The second controller can control the public network gateway (i.e., vendor 2's public network gateway) and the vendor 2's SDN gateway (i.e., the second SDN gateway) in the first availability zone. The third controller can control the NAT gateway and the vendor 1's SDN gateway (i.e., the first SDN gateway).
[0197] In this embodiment, after receiving the first configuration information sent by the first controller, the third controller can configure the mapping relationship between the target public IP address and the target virtual public IP address in the NAT gateway. In this way, the NAT gateway can perform the first-level mapping after the external access traffic (i.e. the first access request) enters, mapping the public IP address to the virtual public IP address. That is, the destination address of the first access request is replaced by the target public IP address and the target virtual public IP address corresponding to the target public IP address, thereby obtaining the first target information. Then, the NAT gateway transmits the first target information to the public gateway in the first availability zone.
[0198] In some embodiments, the method further includes: receiving second migration indication information sent by the first controller, the second migration indication information being used to indicate that the user instance has migrated out of the second availability zone; and controlling the first SDN gateway in the second availability zone to resume port blocking of the target public IP address.
[0199] It should be noted that after the user instance (e.g., cloud host instance) migration is completed, the third controller will receive the second migration instruction information sent by the first controller, thereby knowing that the user instance has been migrated out of the second availability zone. At this time, the third controller can control the vendor 1-SDN gateway (i.e. the first SDN gateway) to restore the port blocking configuration (i.e. restore the port blocking of the target public IP address).
[0200] In the security protection method of this embodiment, the third controller can configure the mapping relationship between the target public IP address and the target virtual public IP address in the NAT gateway, so that the NAT gateway can map the public IP address to the virtual public IP address after the external access traffic (i.e. the first access request) enters, obtain the first target information, and then the NAT gateway transmits the first target information to the public gateway in the first availability zone to solve the problem of the failure of public access policy in heterogeneous availability zones.
[0201] As shown in Figure 12, an embodiment of the cloud access method of the present invention, applied to a NAT gateway, includes:
[0202] Step 1201: Upon receiving a first access request, the destination address of the first access request is replaced by the target public IP address with the target virtual public IP address corresponding to the target public IP address, thereby obtaining first target information. This first target information is then transmitted to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address. The first availability zone and the second availability zone employ different SDN structures and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international internet. A first controller controls a second controller and a third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0203] It should be noted that, as shown in Figure 4, after the external access traffic (i.e., the first access request) enters from the egress router, it will be forwarded to the NAT gateway. If the first access request requests access to the target virtual machine in the first availability zone, the NAT gateway performs the first-level mapping, mapping the public IP address to a virtual public IP address. In other words, the destination address of the first access request is replaced from the target public IP address to the target virtual public IP address corresponding to the target public IP address. The information obtained after the replacement is the first target information. Next, through the underlying routing, the traffic (referring to the first target information) is diverted to the public network gateway in the first availability zone (i.e., vendor 2 public network gateway); vendor 2 public network gateway performs a second mapping, mapping the virtual public IP address to an intermediate address, that is, replacing the destination address of the first target information from the target virtual public IP address to the target intermediate address. The information obtained after the replacement is the second target information, which is then diverted to the second SDN gateway (i.e., vendor 2 SDN gateway); vendor 2 SDN gateway forwards the second target information to the relevant compute nodes (i.e., the compute nodes corresponding to the target intermediate address), and completes the mapping from the intermediate address to the cloud address on the compute nodes.
[0204] Additionally, here's a brief explanation of how traffic from outside the cloud requests access to a target virtual machine in the second availability zone: Traffic from outside the cloud passes through a NAT gateway, where the first level of mapping is completed, transforming the public IP address into an intermediate address (i.e., a pre-assigned private IP address). From the NAT gateway, it's forwarded to the first SDN gateway (i.e., the vendor's 1-SDN gateway; by default, the vendor's 1-SDN gateway blocks all ports based on the intermediate address). After the user successfully registers their public IP address, the vendor's 1-SDN gateway unblocks the specific port, allowing access to the user's specific service from outside the cloud. Then, the vendor's 1-SDN gateway redirects the traffic to the compute nodes, where the distributed virtual routers on the compute nodes perform the translation from the intermediate address to the VPC within the cloud. In this way, access to the cloud is achieved in the second availability zone through two levels of public IP address mapping.
[0205] In this embodiment of the cloud access method, the NAT gateway performs a first-level mapping after external access traffic (i.e., the first access request) enters, mapping the public IP address to a virtual public IP address. This means replacing the destination address of the first access request from the target public IP address to the target virtual public IP address corresponding to the target public IP address, thus obtaining the first target information. The NAT gateway then transmits this first target information to the public gateway in the first availability zone. The public gateway then performs a second mapping, mapping the virtual public IP address to an intermediate address. This means replacing the destination address of the first target information from the target virtual public IP address to the target intermediate address, resulting in the second target information. This second target information is then redirected to the second SDN gateway (i.e., the vendor 2-SDN gateway). The vendor 2-SDN gateway forwards the second target information to the relevant compute nodes (i.e., the compute nodes corresponding to the target intermediate address), where the intermediate address is mapped to the cloud address, ultimately achieving cloud access.
[0206] As shown in Figure 13, an embodiment of the cloud access method of the present invention is applied to a public network gateway, including:
[0207] Step 1301: Upon receiving the first target information, replace the destination address of the first target information with the target virtual public IP address and the target intermediate address to obtain the second target information;
[0208] Step 1302: Forward the second target information to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the computing node corresponding to the target intermediate address. The virtual router on the computing node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
[0209] In this embodiment of the cloud access method, when the public network gateway (i.e., vendor 2-public network gateway) in the first availability zone receives the first target information, it maps the virtual public IP address to an intermediate address. That is, it replaces the destination address of the first target information with the target virtual public IP address and the target intermediate address. The information obtained after the replacement is the second target information. Then, the second target information is forwarded to the second SDN gateway (i.e., vendor 2-SDN gateway). After the vendor 2-SDN gateway forwards the second target information to the relevant computing node (i.e. the computing node corresponding to the target intermediate address), the mapping from the intermediate address to the cloud address is completed on the computing node.
[0210] As shown in Figure 4, a network architecture according to an embodiment of the present invention includes:
[0211] The first availability zone (the availability zone corresponding to vendor 2) includes the second SDN gateway and the public network gateway;
[0212] The second availability zone (the availability zone corresponding to vendor 1, and vendor 1 and vendor 2 use different SDN solutions) adopts a different SDN structure from the first availability zone. The second availability zone includes the first SDN gateway.
[0213] The system comprises a first switch, a NAT gateway, and an egress router. The first switch is connected to a first SDN gateway, a second SDN gateway, the public network gateway, the NAT gateway, and the egress router, respectively. The egress router is connected to the Internet. Both the second availability zone and the first availability zone communicate with the Internet via the egress router.
[0214] The system comprises a first controller, a second controller, and a third controller. The first controller controls the second controller and the third controller. The second controller controls the public network gateway and the second SDN gateway. The third controller controls the NAT gateway and the first SDN gateway.
[0215] It should be noted that the public network gateway in the first availability zone has a port blocking policy configured for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0216] As shown in Figure 4, the first switch mentioned above can specifically be a north-south aggregation switch. As shown in Figure 5, the first controller can specifically be a heterogeneous controller. The first controller can control the second controller and the third controller. The second controller can control the public network gateway (i.e., vendor 2-public network gateway) and vendor 2-SDN gateway (i.e., the second SDN gateway) in the first availability zone. The third controller can control the NAT gateway and vendor 1-SDN gateway (i.e., the first SDN gateway).
[0217] In some embodiments, the first availability zone is configured with a virtual public IP address range and a preset intermediate address range.
[0218] It should be noted that two private network address segments can be pre-configured for the first availability zone: a virtual public IP address segment (let's say address segment B) and a preset intermediate address segment (let's say address segment C). Understandably, neither address segment B nor address segment C can conflict with the private network address segment reserved for the second availability zone (let's say address segment A).
[0219] In this embodiment's network architecture, the heterogeneous first and second availability zones share a single egress router and a NAT gateway to enable communication with the international internet. In this scenario, a port blocking policy can be configured on the public gateway in the first availability zone to target the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone. This solves the problem of public network access policy failure in heterogeneous availability zones while maintaining heterogeneous interconnection.
[0220] As shown in Figure 14, a safety protection device according to an embodiment of the present invention is applied to a first controller and includes:
[0221] The first blocking module 1410 is configured to send a port unblocking request to the second controller when a first condition is met. The port unblocking request is used to request the unblocking of the port of the target virtual public network Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone.
[0222] The first condition includes at least one of the following:
[0223] The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone;
[0224] The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone;
[0225] The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet.
[0226] The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0227] In this embodiment, the heterogeneous first and second availability zones share an egress router and a NAT gateway to achieve communication with the international Internet. For this scenario, a port blocking policy is set on the public network gateway in the first availability zone for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone. Thus, the first controller can send a port unblocking request to the second controller, enabling the second controller to control the public network gateway in the first availability zone to perform a port unblocking operation. This removes the port blocking of the target virtual IP address corresponding to the user instance by the public network gateway in the first availability zone, thereby solving the problem of public network access policy failure in heterogeneous availability zones.
[0228] In one embodiment, the device further includes:
[0229] The first acquisition module is configured to send a second creation request to the second controller when it acquires the first creation request and the target virtual public IP address corresponding to the target public IP address;
[0230] The first creation request is used to request the creation of a DNAT rule corresponding to the target public IP address;
[0231] The second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
[0232] In one embodiment, the device further includes:
[0233] The second sending module is configured to send a third creation request to the second controller when the second condition is met. The third creation request is used to request the second controller to create a virtual public IP address corresponding to the target public IP address.
[0234] The first receiving module is configured to receive the target virtual public IP address corresponding to the target public IP address fed back by the second controller;
[0235] The first storage module is configured to store the mapping relationship between the target public IP address and the target virtual public IP address;
[0236] The second condition includes at least one of the following:
[0237] The first creation request was received, but the target virtual public IP address corresponding to the target public IP address was not obtained;
[0238] Upon receiving a binding instruction message, the binding instruction message indicates that the target public IP address has been bound to the target virtual machine in the first availability zone;
[0239] Upon receiving a first migration instruction, the first migration instruction is used to instruct the user instance to migrate from the second availability zone to the first availability zone.
[0240] In one embodiment, the device further includes:
[0241] The third sending module is configured to send first configuration information to the third controller, wherein the first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address.
[0242] In one embodiment, the device further includes:
[0243] The fourth sending module is configured to send a second migration indication message to the third controller after the user instance has migrated from the second availability zone to the first availability zone. The second migration indication message is used to indicate that the user instance has migrated out of the second availability zone.
[0244] In one embodiment, the target virtual public IP address corresponds one-to-one with the target intermediate address, which is created by the second controller.
[0245] It should be noted that the security protection device provided in this embodiment of the invention can implement all the method steps implemented in the security protection method embodiment applied to the first controller, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0246] As shown in Figure 15, a safety protection device according to an embodiment of the present invention is applied to a second controller and includes:
[0247] The third receiving module 1510 is configured to receive port unblocking requests sent by the first controller;
[0248] The first control module 1520 is configured to control the public network gateway in the first availability zone to perform a port blocking unblocking operation according to the port unblocking request. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance.
[0249] The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0250] In this embodiment, after receiving the port unblocking request sent by the first controller, the second controller can control the public network gateway in the first availability zone to perform a port unblocking operation, so as to unblock the port of the target virtual public IP address corresponding to the user instance. In this way, the user instance in the first availability zone can provide services to the outside world through its bound public IP address, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0251] In one embodiment, the first control module 1520 includes:
[0252] The first sending submodule is configured to send a port unblocking instruction to the public network gateway. The port unblocking instruction is used to instruct the public network gateway to unblock the port of the target virtual public IP address, or to unblock the port of the target port, where the target port is the port that has been successfully registered.
[0253] In one embodiment, the device further includes:
[0254] The fourth receiving module is configured to receive a third creation request sent by the first controller, wherein the third creation request is used to request the second controller to create a virtual public IP address corresponding to the target public IP address;
[0255] The first creation module is configured to create a new target virtual public IP address located within a virtual public IP address range based on the third creation request, wherein the virtual public IP address range is pre-configured for the first availability zone;
[0256] The fifth sending module is configured to send the target virtual public IP address to the first controller.
[0257] In one embodiment, the device further includes:
[0258] The first allocation module is configured to create a new target intermediate address located within a preset intermediate address range. The target intermediate address corresponds one-to-one with the target virtual public IP address. The preset intermediate address range is pre-configured for the first availability zone.
[0259] In one embodiment, after creating a new target intermediate address located within a preset intermediate address range, the device further includes:
[0260] The seventh sending module is configured to send second configuration information to the public network gateway, the second configuration information including the target intermediate address corresponding to the target virtual public network IP address.
[0261] In one embodiment, the device further includes:
[0262] The fifth receiving module is configured to receive the second creation request sent by the first controller;
[0263] The second creation module is configured to create a target DNAT rule using the target public IP address based on the second creation request. The second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
[0264] It should be noted that the security protection device provided in this embodiment of the invention can implement all the method steps implemented in the security protection method embodiment applied to the second controller, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0265] As shown in Figure 16, a security protection device according to an embodiment of the present invention is applied to a public network gateway, comprising:
[0266] The unblocking module 1610 is configured to, upon receiving a port unblocking instruction sent by the second controller, unblock the port of the target virtual public IP address or unblock the port of the target port. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to unblock the port of the target virtual public IP address or unblock the port of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address.
[0267] The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0268] In this embodiment, after receiving the port unblocking instruction sent by the second controller, the public network gateway can unblock the port according to the port unblocking instruction. In this way, user instances in the first availability zone can provide services to the outside world through their bound public IP addresses, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0269] In one embodiment, the device further includes:
[0270] The sixth receiving module is configured to receive second configuration information sent by the first controller, wherein the second configuration information includes the target intermediate address corresponding to the target virtual public IP address;
[0271] The second storage module is configured to store the mapping relationship between the target virtual public IP address and the target intermediate address.
[0272] It should be noted that the security protection device provided in this embodiment of the invention can implement all the method steps implemented in the above-mentioned security protection method embodiment applied to public network gateway, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0273] As shown in Figure 17, a safety protection device according to an embodiment of the present invention is applied to a third controller and includes:
[0274] The first sending module 1710 is configured to send third configuration information to the NAT gateway upon receiving first configuration information sent by the first controller. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance. The third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address.
[0275] The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
[0276] In this embodiment, after receiving the first configuration information sent by the first controller, the third controller can configure the mapping relationship between the target public IP address and the target virtual public IP address in the NAT gateway. In this way, the NAT gateway can perform the first-level mapping after the external access traffic (i.e. the first access request) enters, mapping the public IP address to the virtual public IP address. That is, the destination address of the first access request is replaced by the target public IP address and the target virtual public IP address corresponding to the target public IP address, thereby obtaining the first target information. Then, the NAT gateway transmits the first target information to the public gateway in the first availability zone.
[0277] In one embodiment, the device further includes:
[0278] The seventh receiving module is configured to receive second migration indication information sent by the first controller, wherein the second migration indication information is used to indicate that the user instance has migrated out of the second availability zone;
[0279] The second control module is configured to control the first SDN gateway in the second availability zone to resume port blocking of the target public IP address.
[0280] It should be noted that the security protection device provided in this embodiment of the invention can implement all the method steps implemented in the above-mentioned security protection method embodiment applied to the third controller, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0281] As shown in Figure 18, an inbound cloud access device according to an embodiment of the present invention, applied to a NAT gateway, includes:
[0282] The first processing module 1810 is configured to, upon receiving a first access request, replace the destination address of the first access request with the target public IP address and the target virtual public IP address corresponding to the target public IP address, obtain first target information, and transmit the first target information to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address.
[0283] The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet;
[0284] The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0285] It should be noted that the cloud access device provided in this embodiment of the invention can implement all the method steps implemented in the above embodiment of the cloud access method applied to NAT gateway, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0286] As shown in Figure 19, an embodiment of the cloud access device of the present invention, applied to a public network gateway, includes:
[0287] The second processing module 1910 is configured to, upon receiving the first target information, replace the destination address of the first target information with the target virtual public IP address and the target intermediate address to obtain the second target information;
[0288] The third processing module 1920 is configured to forward the second target information to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the computing node corresponding to the target intermediate address. The virtual router on the computing node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
[0289] It should be noted that the cloud access device provided in this embodiment of the invention can implement all the method steps implemented in the above embodiment of the cloud access method applied to public network gateways, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0290] As shown in Figure 20, an embodiment of the present invention provides a device 2000, which is a first controller, including a processor 2010 and a transceiver 2020, wherein the transceiver 2020 is configured as follows:
[0291] If the first condition is met, a port unblocking request is sent to the second controller. The port unblocking request is used to request the unblocking of the port of the target virtual public Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone.
[0292] The first condition includes at least one of the following:
[0293] The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone;
[0294] The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone;
[0295] The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet.
[0296] The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0297] In this embodiment, the heterogeneous first and second availability zones share an egress router and a NAT gateway to achieve communication with the international Internet. For this scenario, a port blocking policy is set on the public network gateway in the first availability zone for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone. Thus, the first controller can send a port unblocking request to the second controller, enabling the second controller to control the public network gateway in the first availability zone to perform a port unblocking operation. This removes the port blocking of the target virtual IP address corresponding to the user instance by the public network gateway in the first availability zone, thereby solving the problem of public network access policy failure in heterogeneous availability zones.
[0298] In one embodiment, the transceiver 2020 is further configured to:
[0299] Upon obtaining the first creation request and the target virtual public IP address corresponding to the target public IP address, a second creation request is sent to the second controller;
[0300] The first creation request is used to request the creation of a DNAT rule corresponding to the target public IP address;
[0301] The second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
[0302] In one embodiment, the transceiver 2020 is further configured to: send a third creation request to the second controller when a second condition is met, the third creation request being used to request the second controller to create a virtual public IP address corresponding to the target public IP address; and receive the target virtual public IP address corresponding to the target public IP address from the second controller.
[0303] The processor 2010 is also configured to store the mapping relationship between the target public IP address and the target virtual public IP address;
[0304] The second condition includes at least one of the following:
[0305] The first creation request was received, but the target virtual public IP address corresponding to the target public IP address was not obtained;
[0306] Upon receiving a binding instruction message, the binding instruction message indicates that the target public IP address has been bound to the target virtual machine in the first availability zone;
[0307] Upon receiving a first migration instruction, the first migration instruction is used to instruct the user instance to migrate from the second availability zone to the first availability zone.
[0308] In one embodiment, before storing the mapping relationship between the target public IP address and the target virtual public IP address, the transceiver 2020 is further configured to:
[0309] Send first configuration information to the third controller, the first configuration information being used to indicate the mapping relationship between the target public IP address and the target virtual public IP address.
[0310] In one embodiment, the transceiver 2020 is further configured to:
[0311] After the user instance migrates from the second availability zone to the first availability zone, a second migration indication message is sent to the third controller. The second migration indication message is used to indicate that the user instance has migrated out of the second availability zone.
[0312] In one embodiment, the target virtual public IP address corresponds one-to-one with the target intermediate address, which is created by the second controller.
[0313] It should be noted that the device provided in this embodiment of the invention can implement all the method steps implemented in the above-mentioned security protection method embodiment applied to the first controller, and can achieve the same technical effect. Here, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail.
[0314] An embodiment of the present invention provides a device, wherein the device is a second controller, and its structure can be the same as that of the first controller as shown in FIG20, including a processor and a transceiver, wherein the transceiver is configured to receive a port unblocking request sent by the first controller;
[0315] The processor is configured to control the public network gateway in the first availability zone to perform a port blocking unblocking operation based on the port unblocking request. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance.
[0316] The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0317] In this embodiment, after receiving the port unblocking request sent by the first controller, the second controller can control the public network gateway in the first availability zone to perform a port unblocking operation, so as to unblock the port of the target virtual public IP address corresponding to the user instance. In this way, the user instance in the first availability zone can provide services to the outside world through its bound public IP address, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0318] In one embodiment, when the processor controls the public network gateway in the first availability zone to perform a port blocking unblocking operation according to the port unblocking request, it is further configured to:
[0319] Send a port unblocking instruction to the public network gateway. The port unblocking instruction is used to instruct the public network gateway to unblock the port of the target virtual public IP address, or to unblock the port of the target port, where the target port is the port that has been successfully registered.
[0320] In one embodiment, the transceiver is further configured to receive a third creation request sent by the first controller, the third creation request being used to request the second controller to create a virtual public IP address corresponding to the target public IP address;
[0321] The processor is further configured to create a new target virtual public IP address within a virtual public IP address range based on the third creation request, wherein the virtual public IP address range is pre-configured for the first availability zone;
[0322] The transceiver is also configured to send the target virtual public IP address to the first controller.
[0323] In one embodiment, when the target public IP address is already bound to the target virtual machine in the first availability zone, after creating a new target virtual public IP address within a virtual public IP address range according to the third creation request, the processor is further configured to create a new target intermediate address within a preset intermediate address range. The target intermediate address corresponds one-to-one with the target virtual public IP address, and the preset intermediate address range is pre-configured for the first availability zone.
[0324] In one embodiment, after creating a new target intermediate address located within a preset intermediate address range, the processor is further configured to:
[0325] Send second configuration information to the public network gateway, the second configuration information including the target intermediate address corresponding to the target virtual public IP address.
[0326] In one embodiment, the transceiver is further configured to receive a second creation request sent by the first controller;
[0327] The processor is further configured to create a target DNAT rule using the target public IP address according to the second creation request, wherein the second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
[0328] It should be noted that the device provided in this embodiment of the invention can implement all the method steps implemented in the above-described security protection method embodiment applied to the second controller, and can achieve the same technical effect. Here, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail.
[0329] An embodiment of the present invention provides a device, which is a public network gateway. Its structure can be the same as that of the first controller, as shown in Figure 20, including a processor and a transceiver. The processor is configured as follows:
[0330] Upon receiving a port unblocking instruction from the second controller, the port blocking of the target virtual public IP address or the port blocking of the target port is lifted. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to lift the port blocking of the target virtual public IP address or to lift the port blocking of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address.
[0331] The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
[0332] In this embodiment, after receiving the port unblocking instruction sent by the second controller, the public network gateway can unblock the port according to the port unblocking instruction. In this way, user instances in the first availability zone can provide services to the outside world through their bound public IP addresses, which solves the problem of public network access policy failure in heterogeneous availability zones.
[0333] In one embodiment, the transceiver is configured to receive second configuration information sent by the first controller, the second configuration information including a target intermediate address corresponding to the target virtual public IP address;
[0334] The processor is also configured to store the mapping relationship between the target virtual public IP address and the target intermediate address.
[0335] It should be noted that the device provided in this embodiment of the invention can implement all the method steps implemented in the above-described security protection method embodiment applied to public network gateways, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0336] An embodiment of the present invention provides a device, which is a third controller. Its structure can be the same as that of the first controller, as shown in FIG20, including a processor and a transceiver. The transceiver is configured to send third configuration information to a NAT gateway upon receiving first configuration information sent by the first controller. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of a user instance. The third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address.
[0337] The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
[0338] In this embodiment, after receiving the first configuration information sent by the first controller, the third controller can configure the mapping relationship between the target public IP address and the target virtual public IP address in the NAT gateway. In this way, the NAT gateway can perform the first-level mapping after the external access traffic (i.e. the first access request) enters, mapping the public IP address to the virtual public IP address. That is, the destination address of the first access request is replaced by the target public IP address and the target virtual public IP address corresponding to the target public IP address, thereby obtaining the first target information. Then, the NAT gateway transmits the first target information to the public gateway in the first availability zone.
[0339] In one embodiment, the transceiver is further configured to receive second migration indication information sent by the first controller, the second migration indication information being used to indicate that the user instance has migrated out of the second availability zone;
[0340] The processor is configured to control the first SDN gateway in the second availability zone to resume port blocking of the target public IP address.
[0341] It should be noted that the device provided in this embodiment of the invention can implement all the method steps implemented in the above-mentioned security protection method embodiment applied to the third controller, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0342] An embodiment of the present invention provides a device, which is a NAT gateway. Its structure can be the same as that of the first controller, as shown in Figure 20, including a processor and a transceiver. The processor is configured to, upon receiving a first access request, replace the destination address of the first access request with a target public IP address and then with a target virtual public IP address corresponding to the target public IP address, thereby obtaining first target information. The processor then transmits the first target information to a public network gateway in a first availability zone. The first access request is used to request access to a target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address.
[0343] The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet;
[0344] The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
[0345] It should be noted that the device provided in this embodiment of the invention can implement all the method steps implemented in the above embodiment of the cloud access method applied to NAT gateway, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0346] An embodiment of the present invention provides a device, which is a public network gateway. Its structure can be the same as that of the first controller, as shown in Figure 20, including a processor and a transceiver. The processor is configured as follows:
[0347] Upon receiving the first target information, the destination address of the first target information is replaced with the target virtual public IP address and the target intermediate address to obtain the second target information;
[0348] The second target information is forwarded to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the compute node corresponding to the target intermediate address. The virtual router on the compute node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
[0349] It should be noted that the device provided in this embodiment of the invention can implement all the method steps implemented in the above embodiment of the cloud access method applied to public network gateway, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0350] Another embodiment of the device of the present invention, as shown in FIG21, includes a transceiver 2110, a processor 2100, a memory 2120, and a program or instructions stored in the memory 2120 and executable on the processor 2100; when the processor 2100 executes the program or instructions, it implements the security protection method applied to the first controller, or the security protection method applied to the second controller, or the security protection method applied to the public network gateway, or the security protection method applied to the third controller, or the cloud access method applied to the NAT gateway, or the cloud access method applied to the public network gateway.
[0351] The transceiver 2110 is configured to receive and send data under the control of the processor 2100.
[0352] In Figure 21, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 2100 and memory represented by memory 2120. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 2110 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over a transmission medium. Processor 2100 is responsible for managing the bus architecture and general processing, and memory 2120 may store data used by processor 2100 during operation.
[0353] This application also provides a computer program product, including computer instructions. When executed by a processor, the computer instructions implement the various processes of any of the method embodiments shown in FIG3 or FIG9-FIG13 above, and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0354] This invention provides a readable storage medium storing a program or instructions. When executed by a processor, the program or instructions implement the steps of the XX method described above and achieve the same technical effect. To avoid repetition, further details are omitted here. The computer-readable storage medium may include read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0355] It should be further noted that the terminals described in this specification include, but are not limited to, smartphones, tablets, etc., and many of the functional components described are referred to as modules in order to emphasize the independence of their implementation.
[0356] In this embodiment of the invention, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0357] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable type of data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0358] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0359] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of the invention. Therefore, the invention should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make the invention complete and convey the scope of the invention to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0360] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A safety protection method, applied to a first controller, comprising: If the first condition is met, a port unblocking request is sent to the second controller. The port unblocking request is used to request the unblocking of the port of the target virtual public Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone. The first condition includes at least one of the following: The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone; The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone; The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet. The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
2. The method according to claim 1, wherein, The method further includes: Upon obtaining the first creation request and the target virtual public IP address corresponding to the target public IP address, a second creation request is sent to the second controller; The first creation request is used to request the creation of a DNAT rule corresponding to the target public IP address; The second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
3. The method according to claim 1 or 2, wherein, The method further includes: If the second condition is met, a third creation request is sent to the second controller, the third creation request being used to request the second controller to create a virtual public IP address corresponding to the target public IP address; Receive the target virtual public IP address corresponding to the target public IP address fed back by the second controller; Store the mapping relationship between the target public IP address and the target virtual public IP address; The second condition includes at least one of the following: The first creation request was received, but the target virtual public IP address corresponding to the target public IP address was not obtained; Upon receiving a binding instruction message, the binding instruction message indicates that the target public IP address has been bound to the target virtual machine in the first availability zone; Upon receiving a first migration instruction, the first migration instruction is used to instruct the user instance to migrate from the second availability zone to the first availability zone.
4. The method according to claim 3, wherein, Before storing the mapping relationship between the target public IP address and the target virtual public IP address, the method further includes: Send first configuration information to the third controller, the first configuration information being used to indicate the mapping relationship between the target public IP address and the target virtual public IP address.
5. The method according to claim 1, wherein, The method further includes: After the user instance migrates from the second availability zone to the first availability zone, a second migration indication message is sent to the third controller. The second migration indication message is used to indicate that the user instance has migrated out of the second availability zone.
6. The method according to claim 1, wherein, The target virtual public IP address corresponds one-to-one with the target intermediate address, which is created by the second controller.
7. A safety protection method applied to a second controller, comprising: Receive port unblocking request sent by the first controller; Based on the port unblocking request, the public network gateway in the first availability zone is controlled to perform a port unblocking operation. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance. The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
8. The method according to claim 7, wherein, The step of controlling the public network gateway in the first availability zone to perform port blocking unblocking operation based on the port unblocking request includes: Send a port unblocking instruction to the public network gateway. The port unblocking instruction is used to instruct the public network gateway to unblock the port of the target virtual public IP address, or to unblock the port of the target port, which is the port that has been successfully registered.
9. The method according to claim 7 or 8, wherein, The method further includes: The system receives a third creation request sent by the first controller, the third creation request being used to request the second controller to create a virtual public IP address corresponding to the target public IP address; Based on the third creation request, a new target virtual public IP address is created within the virtual public IP address range, which is pre-configured for the first availability zone; Send the target virtual public IP address to the first controller.
10. The method according to claim 9, wherein, When the target public IP address is already bound to the target virtual machine in the first availability zone, after creating a new target virtual public IP address within the virtual public IP address range according to the third creation request, the method further includes: Create a new target intermediate address located within a preset intermediate address range. The target intermediate address corresponds one-to-one with the target virtual public IP address. The preset intermediate address range is pre-configured for the first availability zone.
11. The method according to claim 10, wherein, After creating a new target intermediate address located within a preset intermediate address range, the method further includes: Send second configuration information to the public network gateway, the second configuration information including the target intermediate address corresponding to the target virtual public IP address.
12. The method according to claim 7, wherein, The method further includes: Receive the second creation request sent by the first controller; According to the second creation request, a target DNAT rule is created using the target public IP address. The second creation request is used to request the second controller to create the DNAT rule corresponding to the target virtual public IP address.
13. A security protection method applied to a public network gateway, comprising: Upon receiving a port unblocking instruction from the second controller, the port blocking of the target virtual public IP address or the port blocking of the target port is lifted. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to lift the port blocking of the target virtual public IP address or to lift the port blocking of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address. The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
14. The method according to claim 13, wherein, The method further includes: Receive second configuration information sent by the first controller, the second configuration information including the target intermediate address corresponding to the target virtual public IP address; Store the mapping relationship between the target virtual public IP address and the target intermediate address.
15. A security protection method applied to a third controller, comprising: Upon receiving the first configuration information sent by the first controller, the third configuration information is sent to the NAT gateway. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance, and the third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address. The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
16. The method according to claim 15, wherein, The method further includes: The system receives a second migration indication message sent by the first controller, the second migration indication message being used to indicate that the user instance has migrated out of the second availability zone; Control the first SDN gateway in the second availability zone to restore port blocking of the target public IP address.
17. A cloud access method, applied to a NAT gateway, comprising: Upon receiving a first access request, the destination address of the first access request is replaced by the target public IP address with the target virtual public IP address corresponding to the target public IP address to obtain the first target information, and the first target information is transmitted to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address. The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet; The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
18. A cloud access method, applied to a public network gateway, comprising: Upon receiving the first target information, the destination address of the first target information is replaced with the target virtual public IP address and the target intermediate address to obtain the second target information; The second target information is forwarded to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the compute node corresponding to the target intermediate address. The virtual router on the compute node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
19. A network architecture, comprising: The first availability zone includes the second SDN gateway and the public network gateway; The second availability zone adopts a different SDN structure from the first availability zone, and the second availability zone includes the first SDN gateway; The system comprises a first switch, a NAT gateway, and an egress router. The first switch is connected to a first SDN gateway, a second SDN gateway, the public network gateway, the NAT gateway, and the egress router, respectively. The egress router is connected to the Internet. Both the second availability zone and the first availability zone communicate with the Internet via the egress router. The system comprises a first controller, a second controller, and a third controller. The first controller controls the second controller and the third controller. The second controller controls the public network gateway and the second SDN gateway. The third controller controls the NAT gateway and the first SDN gateway.
20. The network architecture according to claim 19, wherein, The first availability zone is configured with a virtual public IP address range and a preset intermediate address range.
21. A safety protection device applied to a first controller, comprising: The first blocking module is configured to send a port unblocking request to the second controller when a first condition is met. The port unblocking request is used to request the unblocking of the port of the target virtual public network Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone. The first condition includes at least one of the following: The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone; The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone; The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet. The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
22. A safety protection device applied to a second controller, comprising: The third receiving module is configured to receive port unblocking requests sent by the first controller; The first control module is configured to control the public network gateway in the first availability zone to perform a port blocking unblocking operation based on the port unblocking request. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance. The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
23. A security protection device applied to a public network gateway, comprising: The unblocking module is configured to, upon receiving a port unblocking instruction sent by the second controller, unblock the port of the target virtual public IP address or unblock the port of the target port. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to unblock the port of the target virtual public IP address or unblock the port of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address. The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
24. A safety protection device applied to a third controller, comprising: The first sending module is configured to send third configuration information to the NAT gateway upon receiving first configuration information sent by the first controller. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance. The third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address. The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
25. A cloud access device, applied to a NAT gateway, comprising: The first processing module is configured to, upon receiving a first access request, replace the destination address of the first access request with the target public IP address and the target virtual public IP address corresponding to the target public IP address, obtain first target information, and transmit the first target information to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address. The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet; The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
26. A cloud access device, applied to a public network gateway, comprising: The second processing module is configured to, upon receiving the first target information, replace the destination address of the first target information with the target virtual public IP address and the target intermediate address to obtain the second target information; The third processing module is configured to forward the second target information to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the computing node corresponding to the target intermediate address. The virtual router on the computing node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
27. An apparatus, said apparatus being a first controller, comprising: Transceiver and processor; the transceiver is configured as follows: If the first condition is met, a port unblocking request is sent to the second controller. The port unblocking request is used to request the unblocking of the port of the target virtual public Internet Protocol IP address corresponding to the user instance by the public network gateway in the first availability zone. The first condition includes at least one of the following: The target public IP address of the user instance has been successfully registered and the target public IP address corresponds to the target virtual machine in the first availability zone; The target public IP address of the user instance has been successfully registered, and in the target destination address translation DNAT rule corresponding to the target public IP address, the internal IP address points to the target virtual machine in the first availability zone; The first availability zone and the second availability zone adopt different software-defined networking (SDN) structures, and share an egress router and a network address translation (NAT) gateway with the second availability zone to achieve communication with the international Internet. The first controller is used to control the second controller and the third controller. The second controller is used to control the public network gateway, and the third controller is used to control the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
28. An apparatus, said apparatus being a second controller, comprising: Transceiver and processor; The transceiver is configured to receive port unblocking requests sent by the first controller; The processor is configured to control the public network gateway in the first availability zone to perform a port blocking unblocking operation based on the port unblocking request. The port unblocking request is used to request the public network gateway to unblock the port of the target virtual public IP address corresponding to the user instance. The first controller controls the second controller, which in turn controls the public network gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
29. A device, said device being a public network gateway, comprising: Transceiver and processor; the processor is configured as follows: Upon receiving a port unblocking instruction from the second controller, the port blocking of the target virtual public IP address or the port blocking of the target port is lifted. The port unblocking instruction is used to instruct the public network gateway in the first availability zone to lift the port blocking of the target virtual public IP address or to lift the port blocking of the target port. The target port is a port that has been successfully registered. The public network gateway stores a mapping relationship between the target virtual public IP address and the target intermediate address. The second controller is used to control the public network gateway, which is equipped with a port blocking policy for the virtual public IP address corresponding to the public IP address bound to the virtual machine in the first availability zone.
30. An apparatus, said apparatus being a third controller, comprising: Transceiver and processor; The transceiver is configured to send third configuration information to the NAT gateway upon receiving first configuration information from the first controller. The first configuration information is used to indicate the mapping relationship between the target public IP address and the target virtual public IP address of the user instance. The third configuration information is used to instruct the NAT gateway to configure the mapping relationship between the target public IP address and the target virtual public IP address. The first controller is used to control the third controller, and the third controller is used to control the NAT gateway.
31. A device, said device being a NAT gateway, comprising: Transceiver and processor; The processor is configured to, upon receiving a first access request, replace the destination address of the first access request with the target public IP address and the target virtual public IP address corresponding to the target public IP address, obtain first target information, and transmit the first target information to the public network gateway in the first availability zone. The first access request is used to request access to the target virtual machine in the first availability zone. The NAT gateway is configured with a mapping relationship between the target public IP address and the target virtual public IP address. The first availability zone and the second availability zone adopt different SDN structures, and share an egress router and the NAT gateway with the second availability zone to achieve communication with the international Internet; The first controller controls the second controller and the third controller. The second controller controls the public network gateway, and the third controller controls the NAT gateway. The public network gateway is configured with a port blocking policy for the virtual public network IP address corresponding to the public network IP address bound to the virtual machine in the first availability zone.
32. A device, said device being a public network gateway, comprising: Transceiver and processor; The processor is configured as follows: Upon receiving the first target information, the destination address of the first target information is replaced with the target virtual public IP address and the target intermediate address to obtain the second target information; The second target information is forwarded to the second SDN gateway in the first availability zone, so that the second SDN gateway forwards the second target information to the compute node corresponding to the target intermediate address. The virtual router on the compute node replaces the destination address of the second target information from the target intermediate address to the private address corresponding to the target virtual machine. The public network gateway is configured with a mapping relationship between the target virtual public IP address and the target intermediate address.
33. An apparatus comprising: A transceiver, a processor, a memory, and programs or instructions stored in the memory and executable on the processor; When the processor executes the program or instructions, it implements the security protection method as described in any one of claims 1-6, or the security protection method as described in any one of claims 7-12, or the security protection method as described in any one of claims 13-14, or the security protection method as described in any one of claims 15-16, or the cloud access method as described in claim 17, or the cloud access method as described in claim 18.
34. A computer program product comprising computer instructions, which, when executed by a processor, implement the steps of the security protection method as described in any one of claims 1-6, or the steps of the security protection method as described in any one of claims 7-12, or the steps of the security protection method as described in any one of claims 13-14, or the steps of the security protection method as described in any one of claims 15-16, or the steps of the cloud access method as described in claim 17, or the steps of the cloud access method as described in claim 18.
35. A readable storage medium having a program or instructions stored thereon, which, when executed by a processor, implement the steps of the security protection method as claimed in any one of claims 1-6, or the steps of the security protection method as claimed in any one of claims 7-12, or the steps of the security protection method as claimed in any one of claims 13-14, or the steps of the security protection method as claimed in any one of claims 15-16, or the steps of the cloud access method as claimed in claim 17, or the steps of the cloud access method as claimed in claim 18.