Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

197 results about "Network address translation" patented technology

Network address translation (NAT) is a method of remapping one IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device. The technique was originally used as a shortcut to avoid the need to readdress every host when a network was moved. It has become a popular and essential tool in conserving global address space in the face of IPv4 address exhaustion. One Internet-routable IP address of a NAT gateway can be used for an entire private network.

Attack chain restoration method and system based on large language model and traditional AI model

The invention provides an attack link restoration method and system based on a large language model and a traditional AI model, and effectively solves the problem that attack link restoration is incomplete and inaccurate when a current attack link restoration scheme faces complex factors such as network address translation. The method comprises the following steps: acquiring an attack semantic knowledge base containing an attack context knowledge matrix, wherein the knowledge base is generated by processing an attack framework, a security log and a traceability report by a generative large model; obtaining an asset access relation graph generated by analyzing the metadata of the target network infrastructure by the large model and reasoning in combination with an attack semantic knowledge base; regularly acquiring security alarm logs in a first time window and scoring, and acquiring context logs if the security alarm logs exceed a threshold value; based on a time sequence diagram attention network model, determining the confidence degree that edges in an asset access relation graph corresponding to logs containing access pairs in the alarm logs and the context logs belong to attack links; and performing sub-graph extraction in the atlas to obtain candidate sub-graphs, and then determining a target attack link.
Owner:ULTRAPOWER SOFTWARE +1

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Controller-based traffic filtering and address modification

In communication with components of a cloud platform, namely a software-defined network constructed to overlay at least one public cloud network, a controller features a virtual processor and a data store. The data store includes network address translation (NAT) processing logic configured to determine whether a control plane message from tenant resources is associated with a network address overlapping condition, which represents a first network address included in the control plane message overlaps a network address range relied upon by either (a) at least one of the components of the cloud platform or (b) a component associated with other tenant resources. The NAT processing logic is further configured to alter routing data stores that maintain routing information for each of the components of the cloud platform to substitute the first network address with a first virtual network address for subsequent data message routing.
Owner:AVIATRIX SYSTEMS INC

Intelligent DNS load balancing using combination of dynamic DNAT pool and application probing in connector based solution for private application access

PendingUS20260032115A1Securing communicationDomain nameFully qualified domain name
The present application discloses a method, system, and computer system for providing intelligent DNS load balancing using a combination of a dynamic DNAT pool and application providing in a connector-based solution for private application access. The method includes: (a) performing a DNS re-resolution for resolving an application Fully Qualified Domain Name (FQDN) to obtain a plurality of IP addresses for a plurality of application servers, (b) performing periodic application server probing, and (c) dynamically updating a destination network address translation (DNAT) to provide DNS load balancing for application traffic. The DNAT is updated based at least in part on one or more of the DNS re-resolution and the application server probing.
Owner:PALO ALTO NETWORKS INC

Method for Configuring Network Address Translation Gateway and Cloud Management Platform

A method for configuring a network address translation NAT gateway based on a public cloud service including: a cloud management platform obtains NAT gateway creation information that is input by a tenant; The cloud management platform creates the NAT gateway in the first VPC based on the NAT gateway creation information; The cloud management platform obtains configuration information that is input by the tenant and applied to the NAT gateway; The cloud management platform sets, based on the identifier of the second VPC, the NAT gateway to be connected to the second VPC, and sends the first NAT rule to the NAT gateway, where the first NAT rule is used to indicate the NAT gateway to: bind a first network segment in the first VPC to a first elastic IP address EIP; and bind the first network segment in the first VPC to a first transit private IP address.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Address translation method, device and system

The invention provides an address conversion method, device and system, and belongs to the technical field of networks. According to the scheme provided by the invention, based on the fact that the first message of the first user is the message of the target application, the source address of the first message is converted from the first private network address to the target address and then is sent to the first forwarding device. Moreover, the source tracing information of the first user not only comprises a target address corresponding to the first private network address, but also comprises a first public network address and a first port range corresponding to the first private network address. In the tracing information of the first user, the first private network address corresponds to two different addresses, so that the source address of the message can be converted into different network addresses from the first private network address based on the type of the application to which the message belongs when network address conversion is performed on the message of the first user; therefore, the flexibility of address translation is effectively improved.
Owner:HUAWEI TECH CO LTD

Application-agnostic puncturing of network address translation (NAT) services

Two electronic devices attempt to communicate and exchange Internet Protocol (IP) packets over a cellular communication network, and at least one of the two devices is behind a symmetric Network Address Translation (NAT) service. At least one of the two devices executes a Session Traversal Utilities for NAT (STUN) protocol, which provides to that device a pair of external IP address and port of that device; which that device then informs to a Message Broker Unit that is accessible to both devices via the public Internet. The Message Broker Unit provides the external IP address and port of that device, to the other device; which then connects to a Virtual Private Network (VPN) server and sends to the first device one or more User Datagram Protocol (UDP) packets that penetrate or puncture the NAT service in an application-agnostic manner.
Owner:LIVEU

Flow entropy management using network address translation scheme

PendingUS20250365234A1TransmissionPathPingEngineering
Devices, systems, methods, and processes for flow entropy management using network address translation (NAT) scheme are described herein. Typically, due to fewer flows and high bandwidth demands in backend data center networks, hash distribution algorithms may exhibit bias, leading to congestion on certain network paths while others remain underutilized, a phenomenon known as low flow entropy. To address the low flow entropy problem, a network interface controller (NIC) decomposes a traffic flow into multiple flowlets and applies a NAT operation on each flowlet. In the NAT operation, an actual source port value of a flowlet is replaced with a unique unused source port value to make the flowlet look like a different traffic flow to a switch. Thus, the switch processes each flowlet as a different traffic flow and uses load balancing schemes to distribute the flowlets across various network paths. Thus, improving the flow entropy of the network.
Owner:CISCO TECHNOLOGY INC

Remote intelligent control system for multimedia equipment and implementation method of remote intelligent control system

The invention discloses a remote intelligent control system for multimedia equipment and an implementation method thereof, and belongs to the technical field of network communication, and the implementation method comprises the following steps: acquiring network environment information of the multimedia equipment, judging an NAT (Network Address Translation) type, and generating a mixed penetration protocol selection rule to determine an initial penetration protocol; the method comprises the following steps: acquiring port allocation characteristics of NAT equipment based on an initial penetration protocol, generating port prediction parameters through linear increment prediction and LSTM neural network training, and formulating a port prediction and keep-alive strategy; executing UDP (User Datagram Protocol) penetration according to a keep-alive strategy, starting a TCP (Transmission Control Protocol) standby mechanism when the UDP penetration fails, and generating a penetration scheme by combining HTTP tunnel encapsulation and firewall inbound rule configuration; equipment identification information collection, signaling interaction, penetration attempt and connection establishment are completed based on a penetration scheme, successful feedback is generated after verification is passed, and remote control is realized; according to the invention, the stability and efficiency of remote connection of the multimedia equipment in a complex network environment are improved.
Owner:HUASHENG XINGHUI (BEIJING) TECH CO LTD

Data processing method and device, electronic equipment and medium

The embodiment of the invention discloses a data processing method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining a network address translation type, a power consumption level and network topology information of network equipment when a registration request of the network equipment is received, and carrying out the registration of the network equipment according to the network address translation type, the power consumption level and the network topology information, generating equipment associated information; when a connection request of a client is received, analyzing a target device identifier in the connection request, and determining a target network device corresponding to the target device identifier and pre-stored device association information; and determining an adaptive point-to-point transmission strategy according to the equipment association information, and establishing point-to-point direct connection between the target network equipment and the client based on the determined point-to-point transmission strategy and an interactive enhanced session description protocol between the target network equipment and the client, and the scheme can provide a hole digging success rate.
Owner:SHENZHEN STARCAM TECH

Port mapping method and device for sharing elastic public network IP by multiple private clouds

The embodiment of the invention relates to the technical field of virtual network resource scheduling, and provides a port mapping method and device for multiple private clouds to share an elastic public network IP, and the method comprises the steps: creating multiple private clouds in a Cloud platform, and configuring and sharing one elastic public network IP for the multiple private clouds; an ARP pickup flow table of the elastic public network IP is configured on a gateway node of the elastic public network IP through a breip network bridge of the Cloud pods platform, the ARP pickup flow table is used for guiding a data center network to guide the flow accessing the elastic public network IP to the gateway node of the elastic public network IP, the gateway node is a node deployed in a centralized manner on the Cloud pods platform, and the flow of the elastic public network IP is guided by the data center network to the gateway node of the elastic public network IP. The public network flow processing module is used for uniformly processing public network flow of all private clouds sharing an elastic public network IP; and configuring a network address translation rule on the breip network bridge, and mapping a specified port of the elastic public network IP to an intranet IP of the target virtual machine in the corresponding private cloud and a port of the corresponding service. An elastic public network IP is shared in a virtual machine service scene of multiple tenants and multiple private clouds.
Owner:ZHONGKE ZIDONG TAICHU (BEIJING) TECH CO LTD

Methods, systems, and computer readable media for providing stream control transmission protocol (SCTP) multihoming between a kubernetes environment and a non-kubernetes environment

A method for providing stream control transmission protocol (SCTP) multihoming between a Kubernetes environment and a non-Kubernetes environment includes receiving, at an SCTP multihoming router (SMR) deployed as a pod within the Kubernetes environment and from a client in the non-Kubernetes environment, an SCTP INIT message for establishing a multi-homed SCTP association between first and second Internet protocol (IP) addresses of the client and first and second local IP addresses of the SMR. The first and second local IP addresses of the SMR are added to an SCTP header of the SCTP INIT message. Source and destination network address translations (NATs) are performed to change a source IP address and a destination IP address in an IP header of an IP datagram carrying the SCTP INIT message to a third local IP address of the SMR and a service IP address of a service in the Kubernetes environment, respectively.
Owner:ORACLE INT CORP

SFC deployment method of symmetric flow firewall based on cloud platform

The invention discloses an SFC deployment method of a symmetric flow firewall based on a cloud platform, and relates to the technical field of the cloud platform, and the method comprises the steps that a VPC1 and a VPC2 are created on the cloud platform, the VPC1 is used for bearing a virtual machine VM1 created by a user, and the VPC2 is a network environment needed for constructing SFC deployment of the symmetric flow firewall; a virtual machine is deployed on the cloud platform to serve as a network flow transfer virtual machine; four virtual network cards are created in the transfer virtual machine; the method comprises the following steps: deploying a plurality of virtual flow symmetric firewall virtual machines on a cloud platform, and creating two virtual network cards in each firewall virtual machine; closing security group protection mechanisms of all virtual network cards; oVS software is installed in the transfer virtual machine in advance, and a network bridge connected with the virtual network card is established through the OVS software; and the transfer virtual machine provides a source network address translation function through an OVS flow table, so that flow received by all firewall virtual machines is symmetrical, and translation between a floating IP address FIP1 and a local IP address is realized. According to the invention, north-south network traffic security guarantee service is provided for the virtual machine.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Virtual private cloud network switching

In one embodiment, a system includes a plurality of first host machines implementing a public-cloud computing environment, wherein at least one of the first host machines comprises at least one public-cloud virtual machine (VM) that performs network address translation; and a plurality of second host machines implementing a private-cloud computing environment, wherein at least one of the second host machines comprises one or more private-cloud virtual machines, wherein the public-cloud VM is configured to receive, via a network tunnel from the private-cloud VM, one or more first packets to be sent to a public Internet Protocol (IP) address of a public network host, translate, using a NAT mapping, a source address of each first packet from a private IP address of the private-cloud VM to an IP address of the public-cloud VM, and send the first packet to the IP address of the public-cloud VM.
Owner:GOOGLE LLC

System and method for autonomously fingerprinting and enumerating internet of thing (IoT) devices based on nated IPFIX and DNS traffic

This document describes a system and method for detecting the presence of Internet of Things (IoTs) from network traffic that has undergone a Network Address Translation (NAT) process, i.e., NATed network traffic, regardless of whether the network traffic comprises IP Flow Information Export (IPFIX) type of traffic or Domain Name System (DNS) type of traffic. Such a capability is crucial as the adoption rate of IoTs have increased exponentially over the past few years. In order to protect IoTs from cyber-attacks, one would first have to understand what type of IoTs are being used, and how many / how widely used these IoTs are. Once the IoT landscape has been defined, cyber defenders may then dedicate resources to identify and subsequently address vulnerabilities that may be in these IoTs.
Owner:ENSIGN INFOSECURITY PTE LTD

Mechanism to expose reverse NAT information

PCT designated stageWO2025172951A1TransmissionInternet privacyEngineering
Systems and methods are disclosed herein that enable a Network Function (NF) consumer or Application Function (AF) to obtain a public Internet Protocol (IP) address and port for a User Equipment (UE) after Network Address Translation (NAT), when the NF consumer or AF has only the Subscription Permanent Identifier (SUPI) (or GPSI) of the UE.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Network address translation in active-active edge cluster

Some embodiments provide a method for forwarding data messages at multiple edge gateways of a logical network that process data messages between the logical network and an external network. At a first edge gateway, the method receives a data message, having an external address as a destination address, from the logical network. Based on the destination address, the method applies a default route to the data message that routes the data message to a second edge gateway and specifies a first output interface of the first edge gateway for the data message. After routing the data message, the method applies a stored NAT entry that (i) modifies a source address of the data message to be a public NAT address associated with the first edge gateway and (ii) redirects the modified data message to a second output interface of the first edge gateway instead of the first output interface.
Owner:VMWARE INC

Resource sharing between cloud-hosted virtual networks

Techniques for resource sharing between cloud-hosted virtual networks are described. A first network address of a first virtual network is associated with a resource connected to a second virtual network, the first and second virtual networks within a cloud provider network. A service of the cloud provider network receives a message destined for the first network address. The service translates the first network address to a second network address of the resource in the second virtual private network. The service sends the message to the resource at the second network address in the second virtual network.
Owner:AMAZON TECH INC

External network access method and apparatus, and computer device, readable storage medium and product

PCT designated stageWO2026108800A1TransmissionAccess methodNetwork addressing
The present application relates to an external network access method and apparatus, and a computer device, a readable storage medium and a product. The method comprises: upon receiving an external network access request sent by at least one internal network device, acquiring the priority with which each external network access request is transmitted to each of at least two gateway servers, wherein the priority is determined on the basis of connection attributes between the gateway servers and the internal network device (S202); sending the external network access request to a first gateway server having the highest priority, and performing network address translation (S204); when an anomaly occurs in the first gateway server during the process of network address translation, sending the external network access request to a second gateway server having the highest priority among the gateway servers other than the first gateway server (S206); performing network address translation (S208); and when the second gateway server converts an internal network address of the internal network device into a public network address of an external network indicated by the external network access request, obtaining an external network access result (S210).
Owner:CHINA TELECOM CLOUD TECH CO LTD

A method of processing and a routing device for controlling a session

The specification provides a processing method and a routing device for controlling a session, the method comprising: an NPU receiving a first control packet, converting a first source address in the first control packet into a second source address according to a network address translation (NAT) rule, the NPU uploading the first control packet and the second source address to a CPU kernel state, the NPU receiving a second control packet sent by the CPU kernel state, converting a first destination address in the second control packet into a second destination address according to the NAT rule, the NPU uploading the second control packet and the second destination address to the CPU kernel state, and the NPU receiving a takeover notification sent by the CPU kernel state and a control packet converted by a user state to process a session. By the method, the technical problem that the processing logic is limited by the NPU hardware and that the IP can be converted only once in each flow processing and the twice NAT conversion in the NAT hairpin scene cannot be implemented is avoided.
Owner:NEW H3C TECH CO LTD

Client IP persistence for traffic egressing from a distributed service access service edge (SASE) infrastructure for language localization

Techniques for providing language localization for traffic egressing from a distributed Service Access Service Edge (SASE) infrastructure are disclosed. In some embodiments, a system, a process, and / or a computer program product for providing client IP persistence for traffic egressing from a distributed SASE infrastructure includes receiving traffic associated with a user application (app) session at a Secure Access Service Edge (SASE) cloud network via a proxy node; processing the traffic associated with the user app session using a security processing node (SPN), and wherein a source network address translation (SNAT) rule is configured for the SPN; and egressing the traffic associated with the user app session from the SASE cloud network to its original destination using a fixed public IP address based on the SNAT rule to facilitate language localization for all network connections associated with the user app session.
Owner:PALO ALTO NETWORKS INC

Security scanning method and system based on cloud proxy

According to the security scanning method and system based on the cloud proxy, the resource-intensive scanning task is transferred to the cloud server to be executed, the client only needs to run the lightweight proxy plug-in, the requirement for client hardware resources is lowered, resource-limited equipment can bear comprehensive scanning, and the problems that gateway resources are limited, and the scanning efficiency is low are solved. And a scanner which consumes resources cannot be built in. The isolation limitation of network address translation equipment and a firewall is broken through by utilizing a reverse connection and cloud proxy mechanism, and the penetration scanning of an intranet target without a public network IP is realized; meanwhile, tasks can be uniformly configured according to the cloud, multiple client nodes are scheduled, scanning results are integrated, and large-scale concurrent scanning is achieved by combining the high-performance computing power of the cloud; client deployment is further simplified, and distributed deployment and maintenance of a complex scanning tool can be avoided only by installing a single proxy plug-in; moreover, the scanning flow of a cloud source can enhance the operation concealment, and improves the tracking and tracing difficulty.
Owner:SUZHOU MAXNET NETWORK SECURITY TECH CO LTD

Method and device for realizing seven-layer NAT (Network Address Translation) based on openstack platform

The invention relates to the technical field of communication, and particularly provides a method and a device for realizing seven-layer NAT (Network Address Translation) based on an openstack platform, which comprises the following steps of: firstly, creating a virtual machine in a VPC intranet, enabling FTP (File Transfer Protocol) service by the virtual machine, supporting a conntackhelper module by a neutron through a plug-in, starting nfconntackhelper kernel forwarding in an exclusive router of an existing virtual private network, and starting an nfconntackhelper kernel forwarding in a router exclusive to the existing virtual private network; the method comprises the following steps: firstly, a router is established, an FTP dual-channel port is established, an iptables rule for opening and closing an FTP dual-channel port is issued in the router through an interface, then, under the implementation of a helper module, internal and external conversion, namely conversion between floatingIp and an intranet Ip, is carried out on an IP address in seven layers, and conversion between floatingIp and a public network Ip in seven layers of data is also carried out on a firewall. Compared with the prior art, the connection consistency of the control channel and the data channel can be ensured, the problem of connection interruption caused by obtaining the private network address in the cloud is avoided, and mutual access of the external network and the internal network under a special protocol is completed.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Satellite switching method, communication method, system, device, equipment and medium

The present application relates to a satellite switching method, communication method, system, device, equipment and medium. The method includes: receiving a private network address sent by a terminal; the private network address is the network address of the terminal in the intranet of a high-altitude platform device; the terminal is located in the area served by the high-altitude platform device; converting the private network address corresponding to the terminal into a public network address in the extranet of the high-altitude platform device; sending the public network address to a first satellite device to establish a communication link between the high-altitude platform device and the first satellite device; when it is detected that a preset satellite switching condition is met, obtaining the network address of the second satellite device, sending a satellite switching signaling to the first satellite device to disconnect the communication link between the high-altitude platform device and the first satellite device, and sending a satellite switching signaling to the second satellite device according to the network address of the second satellite device to establish a communication link between the high-altitude platform device and the second satellite device. The use of this method can improve communication quality.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Anti-attack method and network equipment

The invention provides an anti-attack method and network equipment, and the method comprises the steps: a carrier level network address translation CGN creates an anti-attack table for an access user, and when the user meets an attack condition, the message flow of the user is processed according to an anti-attack strategy in the anti-attack table of the user. Through the method, the CGN aims at the attack prevention of the user level.
Owner:NEW H3C TECH CO LTD

Controller-based distributed remote access with static public IP avoidance

A method of implementing controller-based distributed remote access may include connecting a plurality of edge devices to a controller via a network. The plurality of edge devices may perform hole punching to traverse a network address translation (NAT) gateway to create a NAT hole. The method may also include connecting a client device to the controller. The client device may be directly connected to one of the plurality of edge devices via the NAT hole in the network. The method may further include directly connecting the client device to one of the plurality of edge devices by receiving a query from the client device and returning public IP / ports of a most relevant edge device to the client device, the most relevant edge device being based on attributes of the client device, attributes of the plurality of edge devices, or combinations thereof.
Owner:CISCO TECHNOLOGY INC

Network attack surface identification optimization method based on network topology and security simulation calculation

The invention discloses a network attack surface identification optimization method based on network topology and security simulation calculation, and relates to the field of network security, and the method comprises the following steps: collecting configuration information of multi-manufacturer network equipment through a remote protocol, executing security simulation calculation on a network topology model, querying an access path from a source address to a destination address, and executing the security simulation calculation on the network topology model; analyzing a strategy matching state, a network address translation rule and route accessibility in the path, and outputting a path on-off state; based on the path on-off state, calculating a whole network data flow relationship, identifying an internal network address and a port which can be directly accessed from an external network, and generating a network attack surface report; and optimizing the strategy rule of the multi-manufacturer network equipment according to the network attack surface report, and outputting an optimized security configuration scheme. According to the network attack surface identification optimization method based on the network topology and the security simulation calculation, the problems that omission risks exist in network security and the network security protection is weak are solved.
Owner:JILIN ELECTRIC POWER RES INST LTD

Configuring application availability using anycast addressing

Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port / protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
Owner:PALO ALTO NETWORKS INC

Controller-based distributed remote access with static public IP avoidance

A method of implementing controller-based distributed remote access may include connecting a plurality of edge devices to a controller via a network. The plurality of edge devices may perform hole punching to traverse a network address translation (NAT) gateway to create a NAT hole. The method may also include connecting a client device to the controller. The client device may be directly connected to one of the plurality of edge devices via the NAT hole in the network. The method may further include directly connecting the client device to one of the plurality of edge devices by receiving a query from the client device and returning public IP / ports of a most relevant edge device to the client device, the most relevant edge device being based on attributes of the client device, attributes of the plurality of edge devices, or combinations thereof.
Owner:CISCO TECHNOLOGY INC

Kafka cluster access method and device, electronic equipment and storage medium

The embodiment of the invention discloses a Kafka cluster access method and device, electronic equipment and a storage medium. The method comprises the following steps: deploying a proxy server in a Kafka cluster; proxy ports on the proxy server are respectively mapped to ports of nodes in the Kafka cluster; configuring a destination network address translation rule at the client; converting a port address of a node in the Kafka cluster into a proxy port address of a proxy server according to a destination network address conversion rule, so that a client initiates connection through an original port address of the node in the Kafka cluster; according to a connection request initiated by a client, forwarding the connection request to a target node of the corresponding Kafka cluster; and establishing an access connection between the client and the Kafka cluster according to the connection request, so that the client accesses a target node of the Kafka cluster. Through a destination network address translation rule of the proxy server and the client, no matter what address the Kafka cluster returns, the client rewrites the address as the address of the proxy server, and successful access to the Kafka cluster is realized.
Owner:CHINA TELECOM CLOUD TECH CO LTD