CN102821036A - Method and device for achieving packet forwarding - Google Patents

Method and device for achieving packet forwarding Download PDF

Info

Publication number
CN102821036A
CN102821036A CN2012101183301A CN201210118330A CN102821036A CN 102821036 A CN102821036 A CN 102821036A CN 2012101183301 A CN2012101183301 A CN 2012101183301A CN 201210118330 A CN201210118330 A CN 201210118330A CN 102821036 A CN102821036 A CN 102821036A
Authority
CN
China
Prior art keywords
business board
interface
board
message
address
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2012101183301A
Other languages
Chinese (zh)
Inventor
王其勇
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hangzhou H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CN2012101183301A priority Critical patent/CN102821036A/en
Publication of CN102821036A publication Critical patent/CN102821036A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Small-Scale Networks (AREA)

Abstract

The invention provides a method and a device for achieving packet forwarding. The method is applied to a distributed firewall device which is at least composed of a plurality of interface boards, a plurality of business boards and a main control board. The method at least includes that each interface board receives a forward message in a private network and sends the forward message to a corresponding business board, each business board receives the forward message, a source internet protocol (IP) address of the forward message is modified to a preset public network IP address of the local business board, a source port of the forward message is modified to any network address translation port of a network address translation port section distributed by the main control board, a network address translation session is established, the converted forward message is sent to a corresponding interface board, and the interface boards send the converted forward message in a public network. According to the method and the device, the main control board of a distributed firewall distributes ports used for network address translation (NAT) based on a request of each business board, and thereby the NAT is performed for the forward message, a corresponding NAT is established, and the new establishing and concurrence of the NAT session can increase with the increasing of the business boards.

Description

A kind of method and apparatus of realizing that message is transmitted
Technical field
The present invention relates to network communications technology, particularly a kind of method and apparatus of realizing that message is transmitted.
Background technology
Distributed fire wall is professional through the parallel processing of distributed multi-service plate, can satisfy the demand of concurrent, the high newly-built and high-throughput of user's height.
Distributed fire wall equipment is generally by interface board, and business board and master control borad are formed.In this equipment, interface board is used for receiving and sending message, and message is sent to business board to manage business; Business board is used to set up session, Qos processing, forwarding and the network address and revises most of business such as (NAT, Network Address Translation); Master control borad is used for processing configuration and route etc., and does not participate in transmitting.
Because there are a plurality of business boards in distributed fire wall equipment; The message that interface board will belong to same Business Stream is sent to same business board and handles; Simultaneously because application layer webmaster (ALG; Application Layer Gateway) needs, interface board also is sent to same business board processing with the message of associated data stream.
At present; Distributed fire wall equipment utilization interface board is sent to each business board mode with message and mainly contains two kinds: mode one, interface board send to each business board through load-balancing algorithm with message; But interface board need keep all session informations, and the complete machine performance of distributed fire wall equipment possibly can't effectively promote; Mode two, interface board utilize the mode of equal-cost route that message is sent to each business board; But each business board need dispose different nat address pools; To handling, caused distributed fire wall equipment can supply configuration of IP v4 address to reduce from carrying out NAT in the forward message of interface board and the reverse message.
Summary of the invention
The object of the present invention is to provide a kind of method and apparatus of realizing that message is transmitted, in order to.
For realizing above-mentioned purpose; The invention provides a kind of method that realizes that message is transmitted; This method is applied to distributed fire wall equipment; This distributed fire wall equipment is made up of a plurality of interface boards, a plurality of business board and master control borad at least, and this method comprises: each interface board receives the forward message and sends to the corresponding service plate in private network; Each business board receives the forward message; The source IP address of forward message is revised the preset public network IP address of cost business board and the source port of forward message is modified as the arbitrary network address conversion port in the network address conversion port section that master control borad distributes and sets up the network address translation session, the forward message after the conversion is sent to the corresponding interface plate; Interface board sends the forward message after the conversion in public network.
For realizing above-mentioned purpose; The present invention also provides a kind of distributed fire wall equipment; This distributed fire wall equipment comprises a plurality of interface boards, a plurality of business board and the master control borad through the switching network interconnection at least, wherein, and interface board; Be used in private network receiving the forward message and sending to corresponding business board the forward message after receiving the forward message after the conversion that corresponding business board sends and in public network, sending conversion; Business board; Be used to receive forward message from interface board; The source IP address of forward message is revised the preset public network IP address of cost business board and the source port of forward message is modified as the arbitrary network address conversion port in the network address conversion port section that master control borad distributes and sets up the network address translation session, the forward message after the conversion is sent to the corresponding interface plate.
Beneficial effect of the present invention is; The master control borad of distributed fire wall is used in the port of NAT conversion for the business board branch based on each business board request; Thereby the forward message is carried out the NAT conversion and sets up corresponding NAT, thereby can guarantee newly-built and concurrent can the rising at double of NAT session with the rising of business board quantity.
Description of drawings
The message forwarding process sketch map that provides for the embodiment of the invention shown in Figure 1;
The structural representation of the distributed fire wall equipment that provides for another embodiment of the present invention shown in Figure 2;
Shown in Figure 3ly distributed fire wall equipment is provided for the embodiment of the invention.
Embodiment
Implement one
Present embodiment provides a kind of method that realizes that message is transmitted, and this method is applied to distributed fire wall equipment, and this distributed fire wall equipment is made up of a plurality of interface boards, a plurality of business board and master control borad at least, and this method as shown in Figure 1 comprises at least:
Step 101, each interface board receive the forward message and send to the corresponding service plate in private network;
Step 102; Each business board receives the forward message; The source IP address of forward message is revised the preset public network IP address of cost business board and the source port of forward message is modified as the arbitrary network address conversion port in the network address conversion port section that master control borad distributes and sets up the network address translation session, the forward message after the conversion is sent to the corresponding interface plate;
Step 103, interface board are sent the forward message after the conversion in public network.
The beneficial effect of present embodiment is; The master control borad of distributed fire wall is used in the port of NAT conversion for the business board branch based on each business board request; Thereby the forward message is carried out the NAT conversion and sets up corresponding NAT, thereby can guarantee newly-built and concurrent can the rising at double of NAT session with the rising of business board quantity.
Embodiment two
A kind of distributed fire wall equipment of present embodiment further provides other schemes to realize the message forwarding compared to embodiment one.
The structure of this distributed fire wall equipment that provides for present embodiment shown in Figure 2, this equipment is made up of a plurality of interface boards, a plurality of business board and the master control borad through the switching network interconnection.
Interface board passes through switching network; All forward messages of same stream (mailing to outer net by Intranet) and all reverse messages (having outer net to mail to the message of Intranet) are all sent to same business board to be handled; Need based on the application layer webmaster, interface board sends to same business board processing with the message of associated data stream.For example, interface board can send to identical business board with data flow with the control flows of FTP (FTP, File Transfer Protocol).
Be example with interface board shown in Fig. 21 and business board 1 in the present embodiment, wherein, this interface board 1 is provided with interior network interface that is in Intranet and the outer network interface that is in outer net.
As shown in Figure 3; When interface board 1 is received the forward message through interior network interface, need carry out NAT to this message and handle, then interface board 1 is according to preset load-balancing algorithm; As carrying out hash calculation according to source IP address, purpose IP address, source MAC and target MAC (Media Access Control) address in the forward message; According to the hash calculation result,, the forward message is sent to the business board 1 corresponding to the hash calculation result through switching network.
After business board 1 is received the forward message from interface board 1, be used in the nat port section of NAT conversion through switching network request master control borad branch.
Specifically do not limit the mode that business board 1 request master control borad distributes the nat port section in the present embodiment, business board 1 can be under the condition of receiving the forward message first or the nat port section of distributing all being used up, and the request master control borad distributes the nat port section.The mode of other business board request nat port sections of equipment shown in Figure 2 is identical.
Master control borad can be used for selecting a part of port to distribute to business board 1 as the nat port section in the NAT PAT of each address (Port address Translation, port the is multiplexed) port (being generally 65535 ports).For example, master control borad evenly is divided into multistage according to business board number in the equipment with available port, selects one section nat port section to distribute to business board 1.Master control borad can be selected the nat port section at random or select the nat port section in regular turn according to port numbers.
Master control borad is access control lists (ACL, Access Control List) in the configuration of total interface plate, and this ACL comprises the preset public network IP address and the nat port section of distributing to business board 1 of business board 1.Fig. 3 shows the process of master control borad at interface board 1 configuration ACL, on the total interface plate, disposes the process of ACL in order to the explanation master control borad.
Likewise, other business boards of the equipment of distributed fire wall shown in Fig. 2, like business board N, receive forward message from interface board 1 or other interface boards after, the request master control borad distributes the nat port section, master control borad selects one section nat port to distribute to this business board.The preset public network IP address of master control borad configuration service plate N on the total interface plate and the nat port section of distributing to business board N.
Business board 1 is selected a nat port in the nat port section that master control borad distributes; Source port of forward message (port that is used for application layer identification) and source IP address are modified as the preset public network IP address of selected nat port and business board 1 respectively, and will changing afterwards, the forward message sends to interface board 1 through switching network.
Suppose that the preset public network IP address of business board 1 is 202.116.100.5 in this enforcement.Interface board 1 is that 192.168.0.2 (private network IP address) and source port are that 4444 forward message sends to business board 1 with source IP address.Business board 1 is to master control borad application nat port section.Master control borad is according to the application of business board 1, and 50000-50500 distributes to business board 1 with the nat port section.Master control borad disposes ACL on the total interface plate, this ACL comprises the incidence relation of preset public network IP address 202.116.100.5 and segment port 50000-50500 and business board 1.
Business board 1 is revised as 202.116.100.5 with the source IP address of forward message by 192.168.0.2; Source port in the forward message is revised as from the selected port 50003 of segment port that distributes by 4444; And set up the NAT session, this NAT session comprises: the source IP after original source IP, purpose IP, protocol type, source port destination interface and the conversion, purpose IP, protocol type, source port destination interface etc.
Forward message after business board 1 will be changed is sent to interface board 1, in public network, transmits the forward message after changing by it through the public network interface.
It is that 202.116.100.5 and destination interface are 50003 that interface board 1 is received purpose IP address through the public network interface, and the ACL that interface board 1 is provided with according to this interface board confirms that the business board of coupling is a business board 1, then reverse message is sent to business board 1.
After business board 1 is received reverse message; Source IP, purpose IP, protocol type, source port and destination interface according to message; The inquiry related session information is revised as 192.168.0.2 with the source IP address in the reverse message by 202.116.100.5 according to the NAT session information; With the source port in the reverse message 50003 by being revised as 4444.
Reverse message after business board 1 will be changed is sent to interface board 1, in private network, transmits the reverse message after changing by it through the private network interface.
Need to prove, in this instance,, then need ask master control borad to distribute the nat port section once more if business board 1 is all used up the nat port section that master control borad distributes.Master control borad distributes the nat port section and on the total interface plate, disposes an ACL again for business board 1 once more, comprises the preset public network IP address of business board 1 and distributes to the nat port section of business board 1 once more.But the ACL about business board 1 that is disposed at the total interface plate before the master control borad can not delete or cover.
Beneficial effect of the present invention; The master control borad of distributed fire wall is used in the port of NAT conversion for the business board branch based on each business board request; Thereby the forward message is carried out the NAT conversion and sets up corresponding NAT; Thereby newly-built and concurrent can be with the rising of business board quantity the rising at double that can guarantee the NAT session, and the interface board of distributed fire wall guarantees that based on the destination interface (port that is used for application layer identification) of reverse message the forward message of same stream and reverse message all handled by the identical services plate of equipment.

Claims (8)

1. method that realizes that message is transmitted, this method is applied to distributed fire wall equipment, and this distributed fire wall equipment is made up of a plurality of interface boards, a plurality of business board and master control borad at least, it is characterized in that, and said method comprises:
Each interface board receives the forward message and sends to the corresponding service plate in private network;
Each business board receives the forward message; The source IP address of forward message revised the preset public network IP address of cost business board and the source port of forward message is modified as master control borad distribute to network address conversion port of network address conversion port section of this business board and set up the network address translation session, the forward message after the conversion is sent to the corresponding interface plate;
Interface board sends the forward message after the conversion in public network.
2. method according to claim 1 is characterized in that, business board is revised the source IP address of forward message before the preset public network IP address of cost business board, and said method is further comprising the steps of:
Business board request master control borad distribution network address transition segment port;
Master control borad is according to business board request distribution network address transition segment port.
3. method according to claim 1 is characterized in that, said method also comprises:
Master control borad is configuration service plate identifying information on the total interface plate, and this business board identifying information comprises the preset public network IP address and the network address conversion port section of distributing to this business board of business board.
4. method according to claim 1 is characterized in that said method also comprises;
Each interface board receives reverse message in public network, according to the destination interface and the purpose IP address of reverse message and the business board identifying information that is disposed at this interface board, coupling corresponding service plate is sent to the corresponding service plate with the reverse message of receiving;
Each business board receives the reverse message from each interface board, according to reverse message information inquiry NAT session; According to the NAT session that inquires the preset public network IP address of the purpose IP address in the reverse message by business board is modified as private network IP address and the destination interface in the reverse message is modified as corresponding destination interface, the reverse message after the conversion is sent to the corresponding interface plate;
Interface board sends the reverse message after the conversion in private network.
5. distributed fire wall equipment, this distributed fire wall equipment comprise at least through a plurality of interface boards, a plurality of business board and the master control borad of switching network interconnection, it is characterized in that;
Interface board is used in private network receiving the forward message and sending to corresponding business board, the forward message after receiving the forward message after the conversion that corresponding business board sends and in public network, sending conversion;
Business board; Be used to receive forward message from interface board; The source IP address of forward message revised the preset public network IP address of cost business board and the source port of forward message is modified as master control borad distribute to a network address conversion port in the network address conversion port section of this business board and set up the network address translation session, the forward message after the conversion is sent to the corresponding interface plate.
6. equipment according to claim 5 is characterized in that;
Business board also is used to ask master control borad distribution network address transition segment port;
Master control borad is used for according to business board request distribution network address transition segment port.
7. equipment according to claim 5 is characterized in that;
Master control borad also is used for configuration service plate identifying information on the total interface plate, and this business board identifying information comprises the preset public network IP address and the network address conversion port section of distributing to this business board of business board.
8. equipment according to claim 5 is characterized in that;
Each interface board; Also be used in public network, receiving reverse message; According to destination interface in the reverse message and purpose IP address and the business board identifying information that is disposed at this interface board; Coupling corresponding service plate is sent to corresponding business board with the reverse message of receiving, receives the reverse message reverse message after the conversion that business board sends also sends conversion in private network after;
Business board also is used to receive the reverse message from each interface board; According to reverse message information inquiry NAT session; According to the NAT session that inquires the preset public network IP address of the purpose IP address in the reverse message by business board is modified as private network IP address and the destination interface in the reverse message is modified as corresponding destination interface, the reverse message after the conversion is sent to the corresponding interface plate.
CN2012101183301A 2012-04-20 2012-04-20 Method and device for achieving packet forwarding Pending CN102821036A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2012101183301A CN102821036A (en) 2012-04-20 2012-04-20 Method and device for achieving packet forwarding

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2012101183301A CN102821036A (en) 2012-04-20 2012-04-20 Method and device for achieving packet forwarding

Publications (1)

Publication Number Publication Date
CN102821036A true CN102821036A (en) 2012-12-12

Family

ID=47304899

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2012101183301A Pending CN102821036A (en) 2012-04-20 2012-04-20 Method and device for achieving packet forwarding

Country Status (1)

Country Link
CN (1) CN102821036A (en)

Cited By (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103797774A (en) * 2013-11-05 2014-05-14 华为技术有限公司 Device and method for network address conversion
CN104065759A (en) * 2013-03-22 2014-09-24 杭州迪普科技有限公司 Method for improving utilization efficiency of NAT address pool resource and device thereof
CN104506513A (en) * 2014-12-16 2015-04-08 北京星网锐捷网络技术有限公司 Firewall flow graph backup method, firewall and firewall system
CN104601738A (en) * 2014-12-09 2015-05-06 国家计算机网络与信息安全管理中心 Distributed network address translation system
CN104869013A (en) * 2015-04-24 2015-08-26 杭州华三通信技术有限公司 SDN-based gateway configuration method and SDN controller
CN104954239A (en) * 2014-03-26 2015-09-30 中国电信股份有限公司 CGN broadband access gateway and implementation method thereof
CN105162702A (en) * 2015-06-30 2015-12-16 杭州华三通信技术有限公司 AC current guide method and device
CN103825976B (en) * 2014-03-04 2017-05-10 新华三技术有限公司 NAT (network address translation) processing method and device in distributed system architecture
CN106878179A (en) * 2016-12-14 2017-06-20 新华三技术有限公司 A kind of message forwarding method and device
CN107222408A (en) * 2017-06-01 2017-09-29 杭州迪普科技股份有限公司 A kind of shunt method and device
CN107547659A (en) * 2017-09-29 2018-01-05 新华三技术有限公司 The safe retransmission method of message and device
CN107547666A (en) * 2016-06-24 2018-01-05 迈普通信技术股份有限公司 The implementation method and device of network address translation
CN107743098A (en) * 2017-11-23 2018-02-27 新华三技术有限公司 The method, apparatus and realization device of load balancing between CGN plates
CN107896196A (en) * 2017-12-28 2018-04-10 杭州迪普科技股份有限公司 A kind of method and apparatus of assignment message
CN108390954A (en) * 2018-03-26 2018-08-10 新华三信息安全技术有限公司 A kind of message transmitting method and equipment
CN109120732A (en) * 2018-07-18 2019-01-01 北京天融信网络安全技术有限公司 The hot insert method of business board, system and storage medium in distributed NAT system
CN109218205A (en) * 2018-09-26 2019-01-15 新华三信息安全技术有限公司 A kind of message forwarding method and device
CN110784535A (en) * 2019-10-25 2020-02-11 新华三信息安全技术有限公司 Message forwarding method, device and network equipment
CN112367261A (en) * 2020-11-30 2021-02-12 迈普通信技术股份有限公司 Message forwarding method and device and distributed equipment
CN113507431A (en) * 2021-05-17 2021-10-15 新华三信息安全技术有限公司 Message management method, device, equipment and machine readable storage medium
CN115086183A (en) * 2022-07-05 2022-09-20 武汉思普崚技术有限公司 Message association method and device for application layer gateway
CN115412526A (en) * 2022-08-17 2022-11-29 北京天融信网络安全技术有限公司 NAT processing method, device, electronic equipment and medium in distributed system

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1754374A (en) * 2003-03-28 2006-03-29 思科技术公司 Network address translation with gateway load distribution
CN101202756A (en) * 2007-12-20 2008-06-18 杭州华三通信技术有限公司 Method and apparatus of message processing
CN101247421A (en) * 2008-03-28 2008-08-20 杭州华三通信技术有限公司 Self-adapting distribution method and system of NAT address pool under distributed structure
CN101296189A (en) * 2008-06-25 2008-10-29 杭州华三通信技术有限公司 Distributed stream processing network appliance and packet transmission method thereof
CN101425929A (en) * 2008-12-01 2009-05-06 成都市华为赛门铁克科技有限公司 Board number table allocation method, device and system
CN101599899A (en) * 2009-07-06 2009-12-09 杭州华三通信技术有限公司 The access method of employing network address translation (NAT) device for supporting multi-networking and equipment

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1754374A (en) * 2003-03-28 2006-03-29 思科技术公司 Network address translation with gateway load distribution
CN101202756A (en) * 2007-12-20 2008-06-18 杭州华三通信技术有限公司 Method and apparatus of message processing
CN101247421A (en) * 2008-03-28 2008-08-20 杭州华三通信技术有限公司 Self-adapting distribution method and system of NAT address pool under distributed structure
CN101296189A (en) * 2008-06-25 2008-10-29 杭州华三通信技术有限公司 Distributed stream processing network appliance and packet transmission method thereof
CN101425929A (en) * 2008-12-01 2009-05-06 成都市华为赛门铁克科技有限公司 Board number table allocation method, device and system
CN101599899A (en) * 2009-07-06 2009-12-09 杭州华三通信技术有限公司 The access method of employing network address translation (NAT) device for supporting multi-networking and equipment

Cited By (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104065759A (en) * 2013-03-22 2014-09-24 杭州迪普科技有限公司 Method for improving utilization efficiency of NAT address pool resource and device thereof
CN103797774B (en) * 2013-11-05 2017-07-21 华为技术有限公司 A kind of network address translation apparatus and method
CN103797774A (en) * 2013-11-05 2014-05-14 华为技术有限公司 Device and method for network address conversion
CN103825976B (en) * 2014-03-04 2017-05-10 新华三技术有限公司 NAT (network address translation) processing method and device in distributed system architecture
CN104954239A (en) * 2014-03-26 2015-09-30 中国电信股份有限公司 CGN broadband access gateway and implementation method thereof
CN104954239B (en) * 2014-03-26 2019-04-05 中国电信股份有限公司 A kind of broad access network gate and its implementation of built-in CGN
CN104601738B (en) * 2014-12-09 2018-04-10 国家计算机网络与信息安全管理中心 A kind of distributed network address conversion system
CN104601738A (en) * 2014-12-09 2015-05-06 国家计算机网络与信息安全管理中心 Distributed network address translation system
CN104506513A (en) * 2014-12-16 2015-04-08 北京星网锐捷网络技术有限公司 Firewall flow graph backup method, firewall and firewall system
CN104506513B (en) * 2014-12-16 2018-05-22 北京星网锐捷网络技术有限公司 Fire wall flow table backup method, fire wall and firewall system
CN104869013A (en) * 2015-04-24 2015-08-26 杭州华三通信技术有限公司 SDN-based gateway configuration method and SDN controller
CN104869013B (en) * 2015-04-24 2019-02-19 新华三技术有限公司 A kind of gateway configuration method and SDN controller based on SDN
CN105162702B (en) * 2015-06-30 2018-11-27 新华三技术有限公司 A kind of AC drainage method and device
CN105162702A (en) * 2015-06-30 2015-12-16 杭州华三通信技术有限公司 AC current guide method and device
CN107547666A (en) * 2016-06-24 2018-01-05 迈普通信技术股份有限公司 The implementation method and device of network address translation
CN106878179A (en) * 2016-12-14 2017-06-20 新华三技术有限公司 A kind of message forwarding method and device
CN107222408B (en) * 2017-06-01 2020-08-04 杭州迪普科技股份有限公司 Shunting method and device
CN107222408A (en) * 2017-06-01 2017-09-29 杭州迪普科技股份有限公司 A kind of shunt method and device
CN107547659A (en) * 2017-09-29 2018-01-05 新华三技术有限公司 The safe retransmission method of message and device
CN107547659B (en) * 2017-09-29 2020-08-11 新华三技术有限公司 Message secure forwarding method and device
CN107743098A (en) * 2017-11-23 2018-02-27 新华三技术有限公司 The method, apparatus and realization device of load balancing between CGN plates
CN107896196A (en) * 2017-12-28 2018-04-10 杭州迪普科技股份有限公司 A kind of method and apparatus of assignment message
CN108390954A (en) * 2018-03-26 2018-08-10 新华三信息安全技术有限公司 A kind of message transmitting method and equipment
CN109120732B (en) * 2018-07-18 2022-03-11 北京天融信网络安全技术有限公司 Service board hot-plug method, system and storage medium in distributed NAT system
CN109120732A (en) * 2018-07-18 2019-01-01 北京天融信网络安全技术有限公司 The hot insert method of business board, system and storage medium in distributed NAT system
CN109218205A (en) * 2018-09-26 2019-01-15 新华三信息安全技术有限公司 A kind of message forwarding method and device
CN110784535A (en) * 2019-10-25 2020-02-11 新华三信息安全技术有限公司 Message forwarding method, device and network equipment
CN110784535B (en) * 2019-10-25 2022-06-28 新华三信息安全技术有限公司 Message forwarding method, device and network equipment
CN112367261A (en) * 2020-11-30 2021-02-12 迈普通信技术股份有限公司 Message forwarding method and device and distributed equipment
CN112367261B (en) * 2020-11-30 2022-10-18 迈普通信技术股份有限公司 Message forwarding method and device and distributed equipment
CN113507431A (en) * 2021-05-17 2021-10-15 新华三信息安全技术有限公司 Message management method, device, equipment and machine readable storage medium
CN113507431B (en) * 2021-05-17 2024-02-09 新华三信息安全技术有限公司 Message management method, device, equipment and machine-readable storage medium
CN115086183A (en) * 2022-07-05 2022-09-20 武汉思普崚技术有限公司 Message association method and device for application layer gateway
CN115086183B (en) * 2022-07-05 2024-02-06 武汉思普崚技术有限公司 Message association method and device of application layer gateway
CN115412526A (en) * 2022-08-17 2022-11-29 北京天融信网络安全技术有限公司 NAT processing method, device, electronic equipment and medium in distributed system
CN115412526B (en) * 2022-08-17 2024-02-02 北京天融信网络安全技术有限公司 NAT processing method, device, electronic equipment and medium in distributed system

Similar Documents

Publication Publication Date Title
CN102821036A (en) Method and device for achieving packet forwarding
CN100466629C (en) Network equipment and message transferring method based on multiple-core processor
Jain Internet 3.0: Ten problems with current internet architecture and solutions for the next generation
CN101155196B (en) Service-oriented IPv6 address specification and distribution method, terminal and system for implementing the same
CN101399742B (en) Data service network system and access method of data service
CN101262506B (en) Allocation method and system for network address conversion port resource under distributed architecture
CN101350759B (en) Method for processing packet, service plate, interface plate and network communication equipment
CN109218201A (en) A kind of method, controller and network equipment generating forwarding-table item
CN105850102A (en) Control of a chain of services
JP2006524974A5 (en)
CN101001264B (en) Method, device, network edge equipment and addressing server for L1VPN address distribution
EP3151477B1 (en) Fast path content delivery over metro access networks
WO2012065531A1 (en) Method, device, and system for implementing relay selection
JP5548696B2 (en) Multicast quality of service module and method
CN101699817B (en) Method and device for controlling messages transmitted to CPU
CN102571375B (en) Multicast forwarding method and device as well as network device
EP3151478B1 (en) Content caching in metro access networks
de Oliveira Silva et al. On the analysis of multicast traffic over the entity title architecture
CN109076019A (en) Addressing for customer rs premise LAN extension
CN107659930A (en) A kind of AP connection control methods and device
CN103179044A (en) Method, device and system for achieving flow management
US20110149972A1 (en) Communication network system, network switch and bandwidth control, for site-to-site communications
JP6011762B2 (en) Label switching network
CN102325074A (en) Three-network convergence system
KR20180007898A (en) Method for separating groups within tenent in virtual private cloud network

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication
RJ01 Rejection of invention patent application after publication

Application publication date: 20121212