VPN networking system and method, electronic device and computer program product
By adopting a mesh-distributed VPN tunnel architecture in the VPN gateway cluster, automatic and rapid switching and load balancing of VPN traffic are achieved, solving the problems of idle backup device nodes and the complexity of hot backup, and improving resource utilization and high availability of VPN traffic.
Patent Information
- Application Number
- CN202511110341.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-10-17
AI Technical Summary
The links of the backup device nodes in the existing VPN gateway cluster are idle, resulting in resource waste. In addition, session hot backup is complex and difficult to implement, and it is difficult to perfectly replicate VPN sessions between the active device nodes and the backup device nodes.
A mesh-distributed VPN gateway cluster architecture is adopted. Each device node establishes an independent VPN tunnel with the VPN site. The device nodes are connected through VPN links. Based on the internal mesh intercommunication links and routing information, automatic and fast switching is achieved in the event of a failure, avoiding hot backup, achieving load balancing and improving resource utilization.
When a VPN tunnel or device node fails, VPN traffic is automatically and smoothly switched, improving resource utilization and achieving load balancing. This avoids the complexity and resource waste of hot backup and ensures high availability of VPN traffic.
Smart Images

Figure CN120811971A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, in particular to a VPN networking system and method, electronic device and computer program product. BACKGROUND
[0002] In a high availability (HA) cluster, two or more device nodes generally bear the business together to reduce the impact of device failure on service interruption and guarantee high reliability of the business. As a high availability cluster in the role of a virtual private network (VPN) gateway, the core business is to build VPN links with associated VPN sites and carry VPN traffic to achieve fast switching and recovery of VPN link failure and guarantee high availability of the high availability cluster VPN link.
[0003] Currently, two or more devices in the VPN gateway cluster build VPN links in a primary-backup mode with associated VPN sites; the link of the primary device node is used to carry VPN traffic, and the link of the standby device node is in an idle state; after the primary device node fails, the associated VPN site switches VPN traffic to the link of the standby device node through route update and switching. Alternatively, the two or more device nodes in the VPN gateway cluster perform hot backup of VPN link session data; when the primary device node fails, the standby node takes over the interaction with the associated VPN site.
[0004] However, the link of the standby device node is in an idle state, causing waste of device resources and broadband resources; due to the security features of VPN links such as data integrity, encryption, and anti-replay in actual application, it is difficult to perfectly replicate the VPN session between the primary device node and the standby device node based on the session hot backup mode, making the implementation of session hot backup more complex and difficult. SUMMARY
[0005] According to various embodiments of the present application, a VPN networking system, method, electronic device and computer program product are provided; the implementation of VPN session hot backup can be independent, and resource utilization and load balancing can be improved.
[0006] In a first aspect, the application provides a VPN networking system, which comprises a VPN site and a VPN gateway cluster, the VPN gateway cluster comprising M device nodes based on a mesh distribution; each device node respectively establishes an independent VPN tunnel with the VPN site; a VPN subnet on a local area network side is divided into M subnet segments, and each device node carries one of the subnet segments; each two device nodes in the VPN gateway cluster are connected based on a VPN link communication, each device node contains routing information of the M device nodes, the routing information is used to indicate a forwarding path of subnet segment traffic when a system fault occurs, and the routing information comprises next hop information of the subnet segment carried by each device node; wherein M is an integer greater than or equal to 2.
[0007] In the above manner, the VPN site establishes VPN tunnels with each device node in the VPN gateway cluster based on a mesh distribution, each two device nodes in the VPN gateway cluster are connected based on a VPN link communication, based on the system architecture, when a VPN tunnel or a device node fails, the VPN site can switch the subnet segment traffic carried by the failed link to the VPN tunnel between other normal device nodes for transmission, since the device nodes based on the mesh distribution contain routing information of each device node, the subnet segment traffic carried by the failed link can be forwarded through the VPN link between each device node; each device node in the VPN gateway cluster does not rely on VPN session link hot backup, and based on the internal mesh interconnection link and routing information, the subnet segment traffic carried by other device nodes is forwarded, automatic, rapid and smooth switching is realized when any VPN tunnel or device node fails, and high availability of access VPN gateway local area network side subnet traffic is ensured; by establishing VPN tunnels between the VPN site and the M device nodes respectively, load balancing is achieved, and resource utilization is improved; the VPN networking system has strong usability and practicality.
[0008] In a possible implementation manner of the first aspect, in a case where a first VPN tunnel between the VPN site and a first device node fails, the VPN site switches first subnet segment traffic from the first VPN tunnel to a second VPN tunnel for transmission; the second VPN tunnel is a VPN tunnel between the VPN site and a second device node; wherein the M device nodes comprise the first device node and the second device node, and the first subnet segment traffic is traffic originally corresponding to transmission of the first VPN tunnel.
[0009] In a possible implementation manner of the first aspect, in a case where a first device node in the VPN gateway cluster fails, the VPN site switches first subnetwork segment traffic from a first VPN tunnel to a third VPN tunnel for transmission, a first subnetwork segment carried by the first device node is updated to be carried by a second device node or a third device node; wherein the M device nodes include the second device node and the third device node; the first VPN tunnel is a VPN tunnel between the VPN site and the first device node; the third VPN tunnel is a VPN tunnel between the VPN site and the third device node; the first subnetwork segment traffic is traffic originally transmitted by the first VPN tunnel; and the M subnetwork segments include the first subnetwork segment.
[0010] In a possible implementation manner of the first aspect, after the first device node fails and the second device node or the third device node updates a carried subnetwork segment, other device nodes in the VPN gateway cluster update their own routing information and routing information of neighbor device nodes.
[0011] In a possible implementation manner of the first aspect, in a case where the first device node fails, the VPN site reestablishes a VPN tunnel for transmitting the first subnetwork segment traffic with the second device node, to obtain a failure reconstruction VPN tunnel; and the first subnetwork segment traffic is recovered from the third VPN tunnel to the failure reconstruction VPN tunnel for transmission.
[0012] In a possible implementation manner of the first aspect, the VPN site is provided with M first VPN configurations, the VPN gateway cluster is provided with M second VPN configurations, and the M device nodes share the M second VPN configurations; and the first VPN configurations and the second VPN configurations are used to establish M VPN tunnels between the VPN site and the M device nodes.
[0013] In a possible implementation manner of the first aspect, the VPN gateway cluster is provided with M*(M-1) third VPN configurations, and the M*(M-1) third VPN configurations are used to establish the VPN links between each two device nodes.
[0014] In a possible implementation manner of the first aspect, the VPN gateway cluster includes a management device master node, the management device master node is configured with M second VPN configurations and M*(M-1) third VPN configurations, and the management device master node synchronizes the M second VPN configurations and the M*(M-1) third VPN configurations to other device nodes in the VPN gateway cluster.
[0015] In a second aspect, the application provides a VPN networking method, applied to a VPN site, wherein the VPN site establishes VPN tunnels with M device nodes in a VPN gateway cluster based on a mesh distribution; each two device nodes in the VPN gateway cluster are connected by a VPN link; each device node contains routing information of the M device nodes; a VPN subnet on a local area network side is divided into M subnet segments, and each device node carries one of the subnet segments; the method comprises the following steps:
[0016] When a first VPN tunnel between the site and a first device node is faulty, the VPN site switches first subnet segment traffic to a second VPN tunnel, transmits the first subnet segment traffic to a second device node through the second VPN tunnel, and forwards the first subnet segment traffic to the first device node through the second device node, wherein the first device node carries the first subnet segment; or,
[0017] When the first device node is faulty, the VPN site switches the first subnet segment traffic to a third VPN tunnel, transmits the first subnet segment traffic to a third device node through the third VPN tunnel, and sends the first subnet segment traffic through the third device node, or forwards the first subnet segment traffic to other device nodes in the VPN gateway cluster that carry the first subnet segment except the first device node through the third device node;
[0018] wherein the M device nodes include the first device node, the second device node and the third device node; the second VPN tunnel is a VPN tunnel between the VPN site and the second device node, and the third VPN tunnel is a VPN tunnel between the site and the third device node; the M subnet segments include the first subnet segment; M is an integer greater than or equal to 2.
[0019] In a third aspect, the application provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method in any one of the second aspect.
[0020] In a fourth aspect, the application provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method in any one of the second aspect.
[0021] In a fifth aspect, the application provides a computer program product, which, when executed on a device, causes the device to execute the method in any one of the second aspect.
[0022] It can be understood that the beneficial effects of the above-mentioned second aspect to the fifth aspect can be referred to the related description in the above-mentioned first aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.
[0024] Figure 1 The architecture schematic diagram of the VPN networking system provided by the embodiments of the present application is shown in the figure.
[0025] Figure 2 The architecture schematic diagram of the device node learning routing information provided by the embodiments of the present application is shown in the figure.
[0026] Figure 3 The structure schematic diagram of the system traffic forwarding provided by the embodiments of the present application is shown in the figure.
[0027] Figure 4 The structure schematic diagram of the traffic forwarding when the VPN tunnel fails provided by the embodiments of the present application is shown in the figure.
[0028] Figure 5 The structure schematic diagram of the traffic forwarding when the device node fails provided by the embodiments of the present application is shown in the figure.
[0029] Figure 6 The traffic forwarding schematic diagram when the tunnel switching and node mismatching provided by the embodiments of the present application is shown in the figure.
[0030] Figure 7 The traffic forwarding schematic diagram after the tunnel reconstruction provided by the embodiments of the present application is shown in the figure.
[0031] Figure 8 The structure schematic diagram of the electronic device provided by the embodiments of the present application is shown in the figure. DETAILED DESCRIPTION
[0032] The embodiments of the technical solutions of the present application will be described in detail below with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present application, and therefore only serve as examples, and cannot limit the protection scope of the present application.
[0033] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned figure descriptions are intended to cover non-exclusive inclusions.
[0034] In the description of the embodiments of this application, the technical terms "first" and "second" are used only to distinguish different objects and should not be understood to indicate or imply relative importance or implicitly specify the quantity, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "plurality" is more than two, unless otherwise clearly and specifically defined.
[0035] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0036] In the description of the embodiments of this application, the term "and / or" is simply a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent the following three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.
[0037] A high-availability cluster that acts as a VPN gateway establishes a VPN link with the associated VPN site and carries VPN traffic. When a VPN link fails, the high-availability cluster switches the link to restore the business process. In the current traditional method, the devices in the VPN gateway cluster and the VPN site establish multiple VPN links in a master-slave backup mode. Under normal circumstances, only the link of the master device node carries VPN traffic, and the link of the backup device node is idle. After the master device node fails, the VPN site switches the VPN traffic to the link of the backup device node through routing updates and switching. This method cannot effectively utilize the device resources and bandwidth resources of the idle backup node. The device load in this master-slave backup working mode is uneven, and it causes resource waste.
[0038] Alternatively, VPN link session data can be hot-backed up between the device nodes in a VPN gateway cluster. When the active device node fails, the standby device node's VPN backup session takes over interaction with the VPN site. Given that VPN link data involves real-time session interaction with the VPN site, and that sessions are often protected by authentication and encryption protocols, with security features such as data integrity and encryption to prevent replay, hot-backing up VPN links by replicating VPN link sessions between different device nodes is complex and difficult in practice. This can lead to periods of traffic interruption and even partial reestablishment of VPN session links, and failures and switchovers can still be felt during actual operation.
[0039] In response to the above technical problems, the present application proposes a VPN networking system, in which the VPN links of each device node in a VPN gateway high-availability cluster (hereinafter referred to as the VPN gateway cluster) operate in a load-sharing working mode. Under normal operating conditions, all device nodes carry VPN traffic evenly to maximize the utilization of device and bandwidth resources; and after any device node fails, the VPN traffic it carries can be quickly and smoothly switched to other device nodes in the VPN gateway cluster, solving the problem of session hot backup and load balancing difficulties; and after the abnormal device recovers and re-establishes the VPN link, the originally switched VPN traffic is switched back to the original device node, achieving device load balancing in the gateway cluster and improving resource utilization.
[0040] The specific implementation of the VPN networking system is further described below through embodiments.
[0041] See Figure 1 , Figure 1 Schematic diagram of the architecture of the VPN networking system provided in the embodiment of the present application; Figure 1 As shown, the VPN networking system includes an associated VPN site (hereinafter referred to as a VPN site) and a VPN gateway high-availability cluster (hereinafter referred to as a VPN gateway cluster). The VPN gateway cluster includes M device nodes distributed in a mesh, with each two devices connected via VPN links. Each device node establishes an independent VPN tunnel with the VPN site. M is an integer greater than or equal to 2.
[0042] Among them, in order to distinguish the communication link between each two devices in the VPN gateway cluster and the communication link between the VPN site and each device node, the communication link between each two devices in the VPN gateway cluster is named VPN link, and the communication link between the VPN site and each device node is named VPN tunnel. The communication principles of the two are the same, both are communication links implemented based on VPN tunnel technology, and are logically isolated dedicated channels built on the public network through encryption and encapsulation protocols.
[0043] As shown in Figure 1 VPN subnets on the local area network side are divided into M mutually exclusive subnet segments, such as VPN subnet 1, VPN subnet 2, and VPN subnet M, each of which is allocated an address information, such as an IP address. Each device node in the VPN gateway cluster carries one of the subnet segments, such as node 1 carrying VPN subnet 1, node 2 carrying VPN subnet 2, and node M carrying VPN subnet M. The VPN site establishes multiple VPN tunnels with each device node, and each device node carries a subnet segment, simultaneously transmits data through multiple VPN tunnels, disperses traffic pressure, achieves load balancing, and improves the resource utilization of devices and bandwidth.
[0044] Correspondingly, in the mesh network of the VPN gateway cluster, each device node is directly connected to all other device nodes, forming multiple paths; each device node can send its own routing information to other device nodes in the cluster and obtain the routing information maintained by other device nodes; the VPN links between device nodes support dynamic routing protocols (such as Open Shortest Path First (OSPF) protocol and Border Gateway Protocol (BGP)), and in the process of traffic transmission, when a fault occurs, the VPN site can automatically select available VPN tunnels, and the VPN gateway cluster selects the forwarding path of subnet segment traffic based on the latest routing information, bypasses the faulty node, and achieves the reliability of traffic transmission.
[0045] Among them, the routing information of all device nodes in the cluster contained by each device node can include the next hop information of the subnet segment carried by each device node.
[0046] In some embodiments, the VPN site is configured with M VPN configurations (i.e., the first VPN configuration) for simultaneously establishing M VPN tunnels with M device nodes in the VPN gateway cluster to jointly undertake the traffic transmission of the VPN site and the VPN gateway cluster; as shown in Figure 1 The VPN tunnel between the VPN site and node 1 forwards VPN subnet 1 traffic, the VPN tunnel between the VPN site and node 2 forwards VPN subnet 2 traffic, and the VPN tunnel between the VPN site and node M forwards VPN subnet M traffic.
[0047] In some embodiments, each device node in the VPN gateway cluster works in a load sharing mode, and collectively undertakes VPN gateway services. In the VPN gateway cluster, a management master device node can be provided, which is configured with M VPN configurations (i.e., second VPN configurations) for simultaneously establishing M VPN tunnels between M device nodes in the cluster and a VPN site; and the management master device node is further configured with M*(M-1) VPN configurations (i.e., third VPN configurations) for establishing Mesh-shaped intercommunication VPN links between the device nodes and neighbor device nodes in the cluster.
[0048] Accordingly, based on the data synchronization mechanism of the VPN gateway cluster, the management master device node synchronizes the M second VPN configurations and the M*(M-1) third VPN configurations to other device nodes in the VPN gateway cluster through high-availability cluster configuration. In the VPN gateway cluster, each device node can include M ports; in the load sharing mode, each device node binds the second VPN configuration and the third VPN configuration to one of the ports, i.e., matches the second VPN configuration and the third VPN configuration to one actual working bandwidth outlet of each device node, and activates one second VPN configuration (established with the VPN site) and M-1 third VPN configurations (established with other device nodes in the cluster); and other ports can be reserved for taking over the outlet bandwidth from other nodes after abnormal switching.
[0049] In the VPN gateway cluster, based on the high-availability protocol, the mapping relationship between the node identifier and the port number can also be synchronized between the device nodes, for example, the mapping relationship can be exchanged between the device nodes through a heartbeat packet, and the consistency of the data can be maintained through a consistency algorithm; thereby ensuring the cluster reliability, fast fault switching and traffic balancing. The unique identifier (such as node number) of each device node corresponds to the effective port number (the port currently carrying traffic); for example, the mapping relationship between the marked device node and the port number is that the effective port of node 1 is Port A, and the effective port of node 2 is Port B.
[0050] Accordingly, after a fault occurs in a device node, the VPN gateway cluster updates the mapping table based on the high-availability protocol, and the second VPN configuration and the third VPN configuration complete VPN link updating under the driving of the updated effective port; for example, node 2 fails, and its effective port Port B is taken over by node M, and at the same time, the port Port M of node M itself continues to be simultaneously effective, i.e., the takeover node has its own port and the port originally owned by the failed node (arranged according to the initial mapping relationship), and establishes a new VPN link on the newly effective port.
[0051] For example, the M first VPN configurations configured in the VPN site are used to establish an independent VPN tunnel with each device node in the VPN gateway cluster; the first VPN configuration can include the local identifier (such as the subnet IP of the VPN site) and the opposite identifier (such as the subnet IP accessible by the device node) of the corresponding VPN tunnel; in the VPN tunnel establishment stage, the local identifier in the first VPN configuration can be the device exit IP of the VPN site, and the opposite identifier can also include the public IP of the device node. Each first VPN configuration corresponds to a subnet segment carried by a device node, which is used to route the traffic of multiple internal networks.
[0052] In addition, the first VPN configuration can also include data encryption algorithm, authentication method, and fault switching strategy, etc. For example, the fault switching strategy can include switching the traffic to the VPN tunnel 2 with node 2 or the VPN tunnel 3 with node 3 if the VPN tunnel 1 with node 1 fails or node 1 fails.
[0053] Correspondingly, the M second VPN configurations configured in the device node correspond to the first VPN configuration of the VPN site, and in the data transmission stage, the configuration can include the local identifier (such as the subnet IP accessible by the device node) and the opposite identifier (such as the subnet IP of the VPN site); in the VPN tunnel establishment stage, the local identifier of the second VPN configuration can also include the public IP of the device node, and the opposite identifier can also include the device exit IP of the VPN site.
[0054] In addition, the second VPN configuration can also include routing rules, tunnel monitoring, load sharing, and encryption algorithm agreed with the VPN site, etc. The routing rules can be direct routing for sending the traffic of the VPN site to the corresponding VPN subnet terminal after being unpacked, and encapsulating the response data of the VPN gateway cluster and returning to the VPN site through the corresponding VPN tunnel.
[0055] For example, the third VPN configuration configured in the device node is used to establish an interworking VPN link between the device nodes in the VPN gateway cluster, build a Mesh network, and support dynamic routing, which supports forwarding the traffic of the VPN site to other device nodes inside the VPN gateway cluster after being unpacked. The M-1 third VPN configurations effective in one port of each device node can include bidirectional communication configuration, routing protocol, security policy, fault detection and recovery, etc.
[0056] Through the above method, the VPN gateway cluster and the VPN site can simultaneously establish M VPN tunnels, and a mesh-shaped interconnected VPN link is established between the device nodes within the VPN gateway cluster; all device nodes in the VPN gateway cluster jointly carry VPN traffic, and the mesh-shaped device nodes can realize traffic forwarding in the abnormal state of the system; the dynamic forwarding route of the VPN link and the direct connection route of the VPN subnet ensure that the route of the VPN subnet on the LAN side is reachable.
[0057] Based on the above VPN networking system, the following further describes the implementation process of the VPN networking system when the system is normal and when a failure occurs through embodiments.
[0058] In some embodiments, the VPN gateway cluster works in a load sharing mode, dividing the VPN subnet on the LAN side into M mutually exclusive subnet segments, and the load is balanced by M device nodes; Figure 2 As shown in the figure, the VPN subnet is divided into VPN subnet 1 (172.10.10.0 / 24), VPN subnet 2 (172.20.20.0 / 24), and VPN subnet M (172.30.30.0 / 24). For another example, if the LAN-side subnet resource IP address of the VPN gateway cluster is 192.168.1.0 / 24 and the number of device nodes M is 4, the VPN subnet resources are divided and the IP addresses of each subnet segment are configured as 192.168.1.0 / 26, 192.168.1.64 / 26, 192.168.1.128 / 26, and 192.168.1.192 / 26. In actual applications, the division and configuration of VPN subnet resources can be set based on actual needs.
[0059] In some embodiments, the VPN site generates M corresponding VPN routes for the target subnet based on M copies of the first VPN configuration, where each VPN route can select one of the M VPN tunnels as the primary link. For example, it is recommended to select a VPN route whose target subnet matches the subnet carried by the device node under normal conditions. For example, the VPN tunnel with node 1 is used as the primary link for VPN subnet 1 traffic, and the VPN tunnels with other device nodes are used as backup links. That is, under normal conditions, traffic from the M subnet segments is evenly distributed across the M VPN tunnels, with the remaining VPN tunnels acting as backup links. By selecting the primary link, the forwarding path for the device node is minimized, avoiding transit between device nodes within the high-availability cluster and minimizing the performance loss of the device node caused by forwarding.
[0060] like Figure 2As shown, each device node in the VPN gateway cluster advertises and learns the routes of the subnets carried by the neighbor nodes and the routes of the VPN site subnets on the internal Mesh intercommunication VPN links through a dynamic routing protocol (such as OSPF), and then generates the forwarding routes of the internal intercommunication VPN links. For example, node 1 advertises the carried subnet route 172.10.10.0 / 24 to other nodes, and learns the neighbor node subnet routes and forwarding paths 172.20.20.0 / 24 via link 1 and 172.30.30.0 / 24 via link 2; node 2 advertises the carried subnet route 172.20.20.0 / 24 to other nodes, and learns the neighbor node subnet routes and forwarding paths 172.10.10.0 / 24 via link 1 and 172.30.30.0 / 24 via link 3; and node M advertises the carried subnet route 172.30.30.0 / 24 to other nodes, and learns the neighbor node subnet routes and forwarding paths 172.10.10.0 / 24 via link 2 and 172.20.20.0 / 24 via link 3.
[0061] In a normal state, since the VPN target subnet matches the device node carried subnet, no forwarding is required on the internal VPN links of the cluster; for example, Figure 3 As shown, the VPN subnet 1 traffic is directly forwarded by node 1.
[0062] For example, the VPN site and the VPN gateway cluster perform point-to-point detection on the local tunnel interface of the VPN site to the opposite tunnel port of the device node through the set connectivity detection device, and monitor whether the established VPN tunnel is abnormal.
[0063] In the process of establishing the VPN tunnel, the VPN site and the VPN gateway cluster create a virtual VPN interface (such as a three-layer routing interface inside the device node, which is a target sending interface for traffic distribution routing); the local tunnel interface is the virtual VPN interface created for the VPN tunnel, and the opposite tunnel interface is the corresponding virtual VPN interface created for the device node of the VPN gateway cluster.
[0064] In the process of link detection, the local tunnel interface is used as the source IP, and the opposite tunnel interface is used as the destination IP, and the messages sent by the two to each other are used as the detection target (for example, messages sent based on ICMP / UDP / TCP protocols); after the VPN site sends the message through the VPN tunnel, it detects whether the correct response message can be received; in the detection process within the continuous period (which can be set as a parameter), if the response message cannot be received for several times (which can be set as a parameter), it indicates that the VPN tunnel cannot be transmitted to the opposite end, or the opposite end (the device node) cannot respond normally, that is, the VPN tunnel or the device node fails.
[0065] Wherein, the detection is performed on all primary and standby links simultaneously, and when the connectivity of the link changes, an update event is triggered, and the route maintenance device of the VPN site and the device node responds to the update event, performs route update, and completes VPN tunnel switching.
[0066] For example, if the response packet can be received for several times (the parameter can be set) after the failure, it indicates that the VPN tunnel transmission can reach the opposite end, and the opposite end responds normally and returns through the VPN tunnel, which indicates that the VPN tunnel and the device node recover from the failure. Correspondingly, after the VPN tunnel creates a virtual VPN interface and generates a corresponding detection case, the detection packet is continuously sent regardless of whether the detection result is normal, so that the point-to-point detection can be continuously performed after the failure, and the traffic switching back to the original VPN tunnel is performed after the recovery is detected.
[0067] In some embodiments, based on the above connectivity detection device, in the case where the first VPN tunnel between the VPN site and the first device node is detected to fail, the VPN site switches the first subnetwork segment traffic from the first VPN tunnel to the second VPN tunnel for transmission; wherein the first device node and the second device node are device nodes in the VPN gateway cluster, the first subnetwork segment traffic is the traffic of the first subnetwork segment originally corresponding to the transmission of the first VPN tunnel, and the second VPN tunnel is the VPN tunnel between the VPN site and the second device node.
[0068] As shown in Figure 4 When the VPN tunnel between the VPN site and node 1 fails, the VPN site switches the VPN subnetwork 1 traffic to the VPN tunnel with node M, transmits the VPN subnetwork 1 traffic to node M, and node M forwards the VPN subnetwork 1 traffic based on the link 2 between node M and node 1, and sends the VPN subnetwork 1 traffic to the terminal of the VPN subnetwork 1 by node 1.
[0069] For example, when the VPN tunnel between the VPN site and node 1 fails, the VPN site can also switch the VPN subnetwork 1 traffic to the VPN tunnel with node 2, transmit the VPN subnetwork 1 traffic to node 2, and node 2 forwards the VPN subnetwork 1 traffic based on the link 1 between node 2 and node 1, and sends the VPN subnetwork 1 traffic to the terminal of the VPN subnetwork 1 by node 1.
[0070] In some embodiments, a management master device node can be provided in the VPN gateway cluster, and the management master device node sends detection packets to other device nodes to detect the reachability and service state of the other device nodes, and determine whether the device nodes have failures; or through cluster system management, the multiple device nodes monitor each other through a distributed protocol, and the health status of one of the device nodes is transmitted through multiple device nodes, and whether the device nodes have failures is determined.
[0071] In some embodiments, in the case of failure of the first device node in the VPN gateway cluster, the VPN site switches the first subnet segment traffic from the first VPN tunnel to the third VPN tunnel for transmission, and the first subnet segment carried by the first device node is updated to be carried by the second device node or the third device node.
[0072] Wherein, the M device nodes include the second device node and the third device node; the first VPN tunnel is a VPN tunnel between the VPN site and the first device node; the third VPN tunnel is a VPN tunnel between the VPN site and the third device node; and the first subnet segment traffic is traffic originally transmitted by the first VPN tunnel.
[0073] For example, when a device node fails, the VPN site can randomly switch the VPN tunnel, for example, from the first VPN tunnel to the third VPN tunnel with another node; as Figure 6 As shown in the figure, when node 1 fails, the VPN site switches the VPN tunnel with node 1 to the VPN tunnel with node M. In the case of failure of the first device node, the driving of the internal state machine of the VPN gateway cluster automatically migrates the first subnet segment to a new second device node or a third device node; as Figure 6 As shown in the figure, in the case of failure of node 1, VPN subnet 1 is automatically migrated and updated to node 2, at this time, the VPN site is automatically switched to the VPN tunnel with node M.
[0074] In one case, when the VPN site switches to the VPN tunnel with the second device node and the first subnet segment is transferred to the second device node, it means that the route switching of the VPN site matches the switching of the device node to the VPN subnet, at this time, the traffic of the VPN site accessing the first subnet segment can directly reach the second device node through the switched VPN tunnel, and the second device node does not need to be forwarded to other nodes, but can be directly sent to the terminal of the first subnet segment on the local area network side.
[0075] As shown in the first case of Figure 6 If the VPN site switches to the VPN tunnel of node 2 and VPN subnet 1 is transferred to node 2, VPN subnet 1 traffic is directly sent to the terminal of VPN subnet 1 by node 2.
[0076] In another case, when the VPN site switches to the VPN tunnel between the VPN site and the third device node, the first subnet segment is transferred to the second device node, which means that the routing switch of the VPN site does not match the routing switch of the device node. At this time, the traffic of the VPN site accessing the first subnet segment can be sent to the third device node through the switched VPN tunnel, forwarded by the third device node to the second device node, and sent by the second device node to the terminal of the first subnet segment on the LAN side.
[0077] like Figure 6 In the second case shown, if the VPN site switches to the VPN tunnel of node M and VPN subnet 1 is transferred to node 2, the VPN site transmits the VPN subnet 1 traffic to node M through the VPN tunnel with node M, and node M forwards the VPN subnet 1 traffic to node 2, and node 2 sends the VPN subnet 1 traffic to the terminal of VPN subnet 1.
[0078] Through the above method, regardless of whether the automatic routing switching of the VPN site matches the subnet switching of the device node, based on the routing of the Mesh network within the VPN gateway cluster, the subnet segment traffic transmitted by the VPN site from any VPN tunnel can be correctly forwarded to the device node that matches the subnet, and finally sent to the terminal of the LAN VPN subnet. There is no need for hot backup of the device nodes in the VPN gateway cluster, thereby realizing automatic routing switching on the VPN site side without prediction and preconditions.
[0079] Accordingly, when the first device node fails and the second device node or the third device node updates the subnet segment it carries, the other device nodes in the VPN gateway cluster except the first device node update the routing information of the subnet segment it carries and the routing information of the subnet segment carried by the neighboring device nodes.
[0080] For example, after a VPN tunnel failure or device node failure, the VPN site performs a link switch and updates the route. After a device node failure, the device node performs a VPN link switch, triggering a subnet update. The device nodes in the VPN gateway cluster relearn the subnet routes carried by each device node based on protocols such as dynamic routing. Therefore, when any VPN tunnel anomaly or any device node fails, its subnet segment traffic is switched to a backup link (which does not match the subnet carried by the device node). The learned converged route can be forwarded to the correct device node via the internal mesh link and ultimately forwarded to the target VPN subnet terminal.
[0081] like Figure 2 As shown in Figure 2, under normal conditions, each device node announces the subnet routes it carries and learns the subnet routes carried by neighboring nodes. Figure 5As shown, after the failure, node 2 takes over the VPN subnet 1 of the original node 1, advertises the routes of the VPN subnet 1 and the VPN subnet 2 (such as the advertised subnet routes of the carried subnets: 172.10.10.0 / 24 and 172.20.20.0 / 24), and learns the route of the VPN subnet M via link 3 to node M (such as 172.30.30.0 / 24 via link 3), and node M advertises the route of the carried subnet M (such as 172.30.30.0 / 24), and learns the routes of the VPN subnet 1 and the subnet 2 via link 3 to node 2 (such as 172.10.10.0 / 24 via link 3 and 172.20.20.0 / 24 via 3).
[0082] In some embodiments, in the case of failure of the first device node, the VPN site reestablishes a VPN tunnel for transmitting the first subnet segment traffic with the second device node, to obtain a failure reconstruction VPN tunnel; and the first subnet segment traffic is recovered from the third VPN tunnel to the failure reconstruction VPN tunnel for transmission.
[0083] For example, when the original first device node fails, the VPN site reestablishes a VPN tunnel for transmitting the first subnet segment traffic based on the configuration in the second device node, and the connectivity of the newly established VPN tunnel is normal, at this time, the VPN site determines that the original link is recovered, and then switches the first subnet segment traffic from the third VPN tunnel used at the time of failure back to the failure reconstruction VPN tunnel.
[0084] The failure reconstruction VPN tunnel can also be a VPN tunnel on another device node, for example, a VPN tunnel reestablished with the first device node after the original failed first device node is recovered. When the failure reconstruction VPN tunnel is a VPN tunnel established with a device node other than the first device node, it can be a VPN tunnel established based on a second port of the other device node, which is a port other than the already effective port.
[0085] Correspondingly, when the second device node corresponding to the failure reconstruction VPN tunnel matches the device node for subnet switching (i.e., the device node for subnet switching is also the second device node), the VPN site restores the route to the failure reconstruction VPN tunnel, and transmits the first subnet segment traffic to the second device node through the failure reconstruction VPN tunnel, and sends the first subnet segment traffic to the terminal of the first subnet segment through the second device node, without internal forwarding between the device nodes. When the second device node corresponding to the failure reconstruction VPN tunnel does not match the device node for subnet switching, the first subnet segment traffic is sent to the terminal of the first subnet segment through the forwarding between the device nodes via the Mesh network of the VPN gateway cluster.
[0086] For example, after the link connectivity is recovered, the VPN site can also establish a fault recovery VPN tunnel directly with the target device node based on the target device node of the subnet switching, so as to avoid the performance loss of the device node caused by the traffic transiting between the device nodes after the link connectivity is recovered. As shown in Figure 7 As shown in FIG. 2, the original node 1 fails, the VPN tunnel between the VPN site and the node 1 is recovered at the node 2, and the link connectivity is recovered. At this time, the VPN site judges that the original link is recovered, and the VPN subnet 1 traffic is switched back to the original link. Since the recovered VPN tunnel directly reaches the node 2, the subnet is also switched to the node 2, and the entire VPN gateway cluster is recovered to a stable state.
[0087] Correspondingly, after the link is recovered and the link connectivity is recovered, the VPN site and the VPN gateway cluster update the route, and the device nodes in the VPN gateway cluster re-announce the carried subnet route and learn the subnet route carried by the neighbor node.
[0088] The embodiment of the present application also provides a VPN networking method based on the same implementation principle as the above embodiment, which will not be described herein again. The method is applied to a VPN site, and the VPN site establishes VPN tunnels with M device nodes in a VPN gateway cluster based on a mesh distribution. Each two device nodes in the VPN gateway cluster are connected based on a VPN link, and each device node contains route information of the M device nodes. The method comprises the following steps.
[0089] When the first VPN tunnel between the site and the first device node is faulty, the VPN site switches the first subnet segment traffic to the second VPN tunnel, transmits the first subnet segment traffic to the second device node through the second VPN tunnel, forwards the first subnet segment traffic to the first device node through the second device node, and the first device node carries the first subnet segment. Alternatively, when the first device node is faulty, the VPN site switches the first subnet segment traffic to the third VPN tunnel, transmits the first subnet segment traffic to the third device node through the third VPN tunnel, transmits the first subnet segment traffic through the third device node, or forwards the first subnet segment traffic to other device nodes in the VPN gateway cluster except the first device node which carries the first subnet segment through the third device node.
[0090] The M device nodes comprise the first device node, the second device node and the third device node; the second VPN tunnel is a VPN tunnel between the VPN site and the second device node, and the third VPN tunnel is a VPN tunnel between the site and the third device node; the M subnet segments comprise the first subnet segment; and M is an integer greater than or equal to 2.
[0091] In some embodiments, the method further comprises the following steps.
[0092] When the first device node has a fault, the VPN site reestablishes a VPN tunnel for transmitting the first subnet segment traffic with the second device node to obtain a fault reconstruction VPN tunnel; the VPN site recovers the VPN tunnel for transmitting the first subnet segment traffic from the third VPN tunnel to the fault reconstruction VPN tunnel, transmits the first subnet segment traffic to the second device node through the fault reconstruction VPN tunnel, and sends the first subnet segment traffic through the second device node or forwards the first subnet segment traffic to a device node other than the first device node in the VPN gateway cluster and bearing the first subnet segment.
[0093] The embodiments of the present application can realize high availability of the VPN gateway cluster. When any device node or any VPN tunnel in the cluster has a fault, the VPN site can detect VPN tunnel connectivity abnormality of the fault node in a very short time, automatically and quickly switches the subnet segment traffic to a normal link of another device node, and sends the subnet segment traffic to a terminal of a target VPN subnet through the other device node. After the device node in the cluster has a fault, the subnet segment borne by the abnormal device node is automatically drifted to another device node, and triggers relearning and convergence of dynamic routing of the device node to regenerate a target forwarding route of the VPN subnet. When the route switched by the VPN site is inconsistent with the device node switched by the VPN subnet, the regenerated route learned by the dynamic routing of the device node based on the Mesh-shaped distribution in the cluster can forward the subnet segment traffic to the device node bearing the target subnet segment, and send the subnet segment traffic to the terminal of the target VPN subnet through the device node, thereby realizing and guaranteeing high availability of the VPN link of the VPN gateway cluster. After the device node has a fault, the bandwidth export of the abnormal device node is automatically drifted to another device node, and the original fault VPN tunnel is automatically reconstructed at the drifted bandwidth export, thereby avoiding waste of export bandwidth resources.
[0094] In addition, since the VPN gateway cluster works in a load sharing mode, the subnet segment borne by any device node is automatically drifted and updated based on internal driving of the cluster after the device node has a fault, and is unpredictable; the VPN site cannot predictively select a VPN tunnel matched after the drift and update to switch routing, and the present application effectively solves the mismatching problem of the foregoing two through dynamic routing learning convergence and traffic forwarding based on the Mesh-shaped intercommunication VPN link, so that the routing of the VPN site does not need to be predicted and can be automatically switched without a precondition, thereby reducing routing implementation complexity of the VPN site and reducing device deployment cost.
[0095] In this embodiment, each device node operates in load-sharing mode. Under normal conditions, all device nodes evenly carry subnet traffic, ensuring load balancing across all device nodes while maximizing the utilization of all device resources. Under normal conditions, the VPN gateway cluster aggregates the hardware resources and bandwidth export resources of all internal device nodes. If any device node fails, its bandwidth export resources are automatically taken over by other device nodes, and connectivity is automatically reestablished within the original VPN tunnel. This maximizes the utilization of bandwidth export resources and improves the utilization rate of high-value resources.
[0096] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0097] Figure 8 A schematic diagram of the hardware structure of the electronic device 8 is shown.
[0098] like Figure 8 As shown, the electronic device 8 of this embodiment includes: at least one processor 81 ( Figure 8 ), a memory 82 (only one of which is shown), wherein the memory 82 stores a computer program 83 executable on the processor 81. When the processor 81 executes the computer program 83, the steps of the above-described method embodiment are implemented. Alternatively, when the processor 81 executes the computer program 83, the functions of the modules / units in the above-described apparatus embodiments are implemented.
[0099] It should be understood that the structures illustrated in the embodiments of the present application do not constitute a specific limitation on the electronic device 8. In other embodiments of the present application, the electronic device 8 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0100] The electronic device 8 may include, but is not limited to, a processor 81 and a memory 82. Those skilled in the art will appreciate that Figure 8 It is only an example of the electronic device 8 and does not constitute a limitation of the electronic device 8. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the server may also include an input sending device, a network access device, a bus, etc.
[0101] The processor 81 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0102] The processor 81 can also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 81 is a cache memory. The memory can store instructions or data that have just been used or are frequently used by the processor 81. If the processor 81 needs to use the instructions or data again, it can directly call them from the memory. This avoids repeated access and reduces the waiting time of the processor 81, thereby improving the efficiency of the system.
[0103] The memory 82 can be an internal storage unit of the electronic device 8, such as a hard disk or a memory of the electronic device 8, in some embodiments. The memory 82 can also be an external storage device of the electronic device 8, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. provided on the electronic device 8. Further, the memory 82 can include both the internal storage unit and the external storage device of the electronic device 8. The memory 82 is used to store an operating system, application programs, a boot loader, data, and other programs, such as program codes of computer programs, etc. The memory 82 can also be used to temporarily store data that has been transmitted or is to be transmitted.
[0104] In addition, each functional unit in each of the embodiments of the present application can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0105] It should be noted that the structure of the electronic device is only illustrative, and other physical structures can be included based on different application scenarios, and the physical structure of the electronic device is not limited herein.
[0106] In the above embodiments, the description of each embodiment focuses on different aspects, and the parts not described or recorded in a certain embodiment can be referred to the relevant description of other embodiments.
[0107] The computer program is stored in the computer readable storage medium, and when the computer program is executed by the processor, the steps in the above-mentioned various method embodiments can be implemented.
[0108] The computer program is stored in the computer readable storage medium, and when the computer program is executed by the processor, the steps in the above-mentioned various method embodiments can be implemented.
[0109] The integrated modules / units, if realized in the form of software function units and sold or used as independent products, can be stored in a computer readable storage medium. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by computer programs instructing related hardware, and the computer programs can be stored in a computer readable storage medium. The computer programs can implement the steps in the above-mentioned various method embodiments when executed by the processor. The computer programs include computer program codes, which can be in the form of source code, object code, executable files or some intermediate forms. The computer readable medium can include any entity or device capable of carrying computer program codes, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier wave signal, telecommunication signal and software distribution medium, etc.
[0110] The VPN networking system, electronic device, computer storage medium and computer program product provided by the above embodiments of the present application are all used to execute the above-mentioned methods, so the beneficial effects they can achieve can refer to the beneficial effects of the above-mentioned methods, which will not be repeated here.
[0111] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present disclosure.
[0112] It should be understood that the above description is only to help the person skilled in the art better understand the embodiments of the present application, and is not intended to limit the scope of the embodiments of the present application. Various equivalent modifications or changes can be made to the embodiments of the above-described detection method according to the above-described examples given by those skilled in the art, for example, some steps in each of the above-described embodiments of the detection method can be unnecessary, or some steps can be newly added, etc. Or a combination of any two or more embodiments. Such modifications, changes or combinations also fall within the scope of the embodiments of the present application.
[0113] It should also be understood that the ways, cases, categories and divisions of embodiments in the present application are only for the convenience of description and should not be construed as special limitations. The features in various ways, categories, cases and embodiments can be combined without contradiction.
[0114] It should also be understood that in various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be mutually referred to if not specifically stated and not logically contradictory. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0115] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0116] In the embodiments provided in the present application, it should be understood that the disclosed apparatus / network device and method can be implemented in other ways. For example, the apparatus / network device embodiments described above are only schematic. The division of the modules or units is only a logical function division, and there can be another division in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or in other forms.
[0117] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e. they can be located in one place, or distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0118] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements for some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
[0119] Finally, it should be noted that the above-described is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed by the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A VPN networking system, characterized in that: The VPN networking system includes a VPN site and a VPN gateway cluster, wherein the VPN gateway cluster includes M device nodes based on mesh distribution; Each of the device nodes establishes an independent VPN tunnel with the VPN site respectively; the VPN subnet on the LAN side is divided into M subnet segments, and each of the device nodes carries one of the subnet segments; Each two device nodes in the VPN gateway cluster are connected to each other based on a VPN link communication connection. Each device node contains routing information of M device nodes. The routing information is used to indicate the forwarding path of subnet segment traffic in the event of a system failure. The routing information includes next hop information of the subnet segment carried by each device node. Wherein, M is an integer greater than or equal to 2.
2. The VPN networking system according to claim 1, wherein: In the event that a first VPN tunnel between the VPN site and the first device node fails, the VPN site switches the first subnet segment traffic from the first VPN tunnel to the second VPN tunnel for transmission; The second VPN tunnel is a VPN tunnel between the VPN site and the second device node; The M device nodes include the first device node and the second device node, and the first subnet segment traffic is the traffic originally transmitted by the first VPN tunnel.
3. The VPN networking system according to claim 1, wherein: In the event that the first device node in the VPN gateway cluster fails, the VPN site switches the first subnet segment traffic from the first VPN tunnel to the third VPN tunnel for transmission, and updates the first subnet segment carried by the first device node to be carried by the second device node or the third device node; Among them, the M device nodes include the second device node and the third device node; the first VPN tunnel is the VPN tunnel between the VPN site and the first device node; the third VPN tunnel is the VPN tunnel between the VPN site and the third device node; the first subnet segment traffic is the traffic originally transmitted by the first VPN tunnel; the M subnet segments include the first subnet segment.
4. The VPN networking system according to claim 3, wherein: When the first device node fails and the second device node or the third device node updates the carried subnet segment, the other device nodes in the VPN gateway cluster except the first device node update their own routing information and the routing information of neighboring device nodes.
5. The VPN networking system according to claim 3, wherein: In the event of a failure of the first device node, the VPN site and the second device node re-establish a VPN tunnel for transmitting the first subnet segment traffic, obtaining a fault-reconstructed VPN tunnel; and the first subnet segment traffic is restored from the third VPN tunnel to the fault-reconstructed VPN tunnel for transmission.
6. The VPN networking system according to claim 1, wherein: The VPN site is provided with M copies of the first VPN configuration, the VPN gateway cluster is provided with M copies of the second VPN configuration, and the M device nodes share the M copies of the second VPN configuration; the first VPN configuration and the second VPN configuration are used for the VPN site to establish the M VPN tunnels with the M device nodes.
7. The VPN networking system according to claim 1, wherein: The VPN gateway cluster is provided with M*(M-1) copies of the third VPN configuration, and the M*(M-1) copies of the third VPN configuration are used to establish the VPN link between every two device nodes.
8. The VPN networking system according to any one of claims 1 to 7, characterized in that: The VPN gateway cluster includes a management device master node, which is configured with M copies of the second VPN configuration and M*(M-1) copies of the third VPN configuration. The management device master node synchronizes the M copies of the second VPN configuration and the M*(M-1) copies of the third VPN configuration to other device nodes in the VPN gateway cluster.
9. A VPN networking method, characterized in that: Applied to a VPN site, the VPN site establishes a VPN tunnel with M device nodes in a VPN gateway cluster based on a mesh distribution; each two device nodes in the VPN gateway cluster are connected to each other based on a VPN link communication, and each device node contains routing information of the M device nodes; The VPN subnet on the LAN side is divided into M subnet segments, and each of the device nodes carries one of the subnet segments; the method includes: When a first VPN tunnel between the site and the first device node fails, the VPN site switches the first subnet segment traffic to the second VPN tunnel, transmits the first subnet segment traffic to the second device node through the second VPN tunnel, forwards the first subnet segment traffic to the first device node through the second device node, and the first device node carries the first subnet segment; or When the first device node fails, the VPN site switches the first subnet segment traffic to the third VPN tunnel, transmits the first subnet segment traffic to the third device node through the third VPN tunnel, sends the first subnet segment traffic through the third device node, or forwards the first subnet segment traffic to other device nodes in the VPN gateway cluster that carry the first subnet segment except the first device node through the third device node; Among them, the M device nodes include the first device node, the second device node and the third device node; the second VPN tunnel is a VPN tunnel between the VPN site and the second device node, and the third VPN tunnel is a VPN tunnel between the site and the third device node; the M subnet segments include the first subnet segment; M is an integer greater than or equal to 2.
10. The VPN networking method according to claim 9, wherein: The method further comprises: When the first device node fails, the VPN site and the second device node re-establish a VPN tunnel for transmitting the first subnet segment traffic, thereby obtaining a failure-reconstructed VPN tunnel; The VPN site will restore the VPN tunnel that transmits the first subnet segment traffic to the fault-reconstructed VPN tunnel through the third VPN tunnel, transmit the first subnet segment traffic to the second device node through the fault-reconstructed VPN tunnel, send the first subnet segment traffic through the second device node, or forward the first subnet segment traffic to other device nodes in the VPN gateway cluster that carry the first subnet segment except the first device node through the second device node.
11. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method according to any one of claims 9 to 10 is implemented.
12. A computer program product, characterized in that When the computer program product is run on a device, the device is caused to execute the method according to any one of claims 9 to 10.
Citation Information
Cited By
Tunnel comprehensive management and control platform construction method and system
CN121309368A