Seamless multi-cloud SDWAN disaster recovery using an orchestration plane
By monitoring and identifying new destination cloud networks using virtual connection devices of network orchestration components, the dependence problem of third-party witness components in existing SD-WAN migration is solved, and efficient and reliable multi-cloud structural migration management is achieved.
Patent Information
- Application Number
- CN202080050008.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-02
- Filing Date
- 2020-06-30
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2040-06-30
AI Technical Summary
Existing SD-WAN solutions rely on third-party witness components when migrating in multi-cloud structures, resulting in complex management, invisible health conditions, single point failures, and other problems, affecting high availability and high reliability.
The virtual connection device of network orchestration components is used to monitor the virtual management component clusters of multiple cloud networks, detect failure transfer events, and identify new destination cloud networks to realize the migration of SD-WAN services and eliminate dependence on third-party witness components.
Improves the reliability and availability of SD-WAN migration, simplifies management processes, avoids the shortcomings of third-party witness components, and ensures an efficient migration process.
Smart Images

Figure CN114080597B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims the benefit of and priority to U.S. non-provisional patent application No. 16 / 806,750, filed on March 2, 2020, and entitled “SEAMLESS MULTI-CLOUD SDWANDISASTER RECOVERY USING ORCHESTRATION PLANE,” which claims the benefit of U.S. provisional patent application No. 62 / 872,125, filed on July 9, 2019, and entitled “SEAMLESS MULTI CLOUD SDWANDISASTER RECOVERY USING ORCHESTRATION PLANE,” the contents of which are incorporated herein by reference in their entirety. Technical Field
[0003] The subject matter of the present disclosure relates generally to the field of computer networking and, more particularly, to systems and methods for managing the migration of software-defined network components from a source cloud to a destination cloud in a multi-cloud setting. Background Art
[0004] Software-defined networking (SD-WAN) provides connectivity for computing devices (e.g., servers, workstations, desktop computers, laptops, tablets, mobile phones, etc.) and things (e.g., desk phones, security cameras, lighting, heating, ventilation, and air conditioning (HVAC), windows, doors, locks, medical equipment, industrial and manufacturing equipment, etc.) in environments such as offices, hospitals, universities, and factories. SD-WAN can be implemented in a multi-cloud architecture.
[0005] When a multi-cloud fabric experiences a failure, a specific SD-WAN solution implemented using this fabric may need to be moved and migrated from one cloud fabric to another. Current solutions for achieving this type of migration rely on a third-party witness component that needs to be integrated into the SD-WAN infrastructure. Furthermore, managing the lifecycle of this third-party witness component places an additional burden on the network, with little or no visibility into its health. The third-party witness component also represents a single point of failure, requiring high availability and high dependency. Summary of the Invention
[0006] According to an embodiment of the present disclosure, a method is provided, comprising: using a virtual link device of a network orchestration component to monitor a cluster of virtual management components of multiple cloud networks, wherein the corresponding virtual management component of one cloud network among the multiple cloud networks implements one or more services of a software-defined wide area network (SD-WAN) solution; using the virtual link device to detect a failover event at the one cloud network among the multiple cloud networks; and identifying a new destination cloud network by the virtual link device to migrate the one or more services of the SD-WAN solution from the source cloud network where the failover event was detected to the new destination cloud network.
[0007] According to an embodiment of the present disclosure, a network controller is provided, comprising: a memory having computer-readable instructions stored therein; and one or more processors configured to execute the computer-readable instructions as a virtual link device of a software-defined wide area network (SD-WAN) solution to perform the following operations: monitoring a cluster of virtual management components of multiple cloud networks, wherein a corresponding virtual management component of one of the multiple cloud networks implements one or more services of the software-defined network (SD-WAN) solution; detecting a failover event at the one of the multiple cloud networks; and identifying a new destination cloud network to migrate the one or more services of the SD-WAN solution from the source cloud network where the failover event is detected to the new destination cloud network.
[0008] According to an embodiment of the present disclosure, one or more non-transitory computer-readable media are provided, including computer-readable instructions, which, when executed by one or more processors, cause the one or more processors to function as a virtual link device of a software-defined wide area network (SD-WAN) solution to perform the following operations: monitoring a cluster of virtual management components of multiple cloud networks, wherein a corresponding virtual management component of one of the multiple cloud networks implements one or more services of the software-defined wide area network (SD-WAN) solution; detecting a failover event at the one of the multiple cloud networks; and identifying a new destination cloud network to migrate one or more services of the SD-WAN solution from a source cloud network where the failover event is detected to the new destination cloud network.
[0009] According to an embodiment of the present disclosure, a device is provided, comprising: a device for monitoring a cluster of virtual management components of multiple cloud networks using a virtual link device of a network orchestration component, wherein the corresponding virtual management component of one cloud network among the multiple cloud networks implements one or more services of a software-defined wide area network (SD-WAN) solution; a device for detecting a failover event at the one cloud network among the multiple cloud networks using the virtual link device; and a device for identifying a new destination cloud network by the virtual link device to migrate the one or more services of the SD-WAN solution from the source cloud network where the failover event is detected to the new destination cloud network. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] To provide a more complete understanding of the present disclosure and its features and advantages, reference is made to the following description taken in conjunction with the accompanying drawings, in which:
[0011] Figure 1 shows a network architecture according to one aspect of the present disclosure;
[0012] Figure 2 An example of a multi-cloud architecture with a third-party witness component for managing SD-WAN migrations according to one aspect of the present disclosure is shown;
[0013] Figure 3 An example of a multi-cloud architecture for managing SD-WAN migration without relying on a third-party witness component according to one aspect of the present disclosure is shown;
[0014] Figure 4 An example method for managing SD-WAN migration of a multi-cloud fabric according to one aspect of the present disclosure is described; and
[0015] Figure 5A-5B An example of a system according to one aspect of the present disclosure is shown. DETAILED DESCRIPTION
[0016] Various example embodiments of the present disclosure are discussed in detail below. Although specific implementations are discussed, it should be understood that this is for illustrative purposes only. Those skilled in the relevant art will recognize that other components and configurations can be used without departing from the spirit and scope of the present disclosure. Therefore, the following description and drawings are illustrative and should not be interpreted as limiting. Many specific details are described to provide a thorough understanding of the present disclosure. However, in some cases, in order to avoid confusing the description, well-known or conventional details are not described. References to an embodiment or embodiments in the present disclosure may refer to the same embodiment or any embodiment; and such references mean at least one embodiment.
[0017] Reference to "one embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. The phrase "in one embodiment" appearing in various places throughout the specification is not necessarily referring to the same embodiment, nor is separate or alternative embodiments mutually exclusive of other embodiments. Furthermore, various features are described that may be exhibited by some embodiments but not by others.
[0018] Without limiting the scope of this disclosure, examples of instruments, devices, methods, and related results according to embodiments of the present disclosure are provided below. It should be noted that titles or subtitles may be used in the examples for the convenience of the reader, and this should in no way limit the scope of this disclosure. Unless otherwise defined, technical and scientific terms used herein have the meanings commonly understood by those of ordinary skill in the art to which this disclosure belongs. In the event of a conflict, this document (including definitions) will control.
[0019] Additional features and advantages of the present disclosure will be set forth in the description that follows, and in part will be apparent from the description, or may be learned by practice of the principles disclosed herein. The features and advantages of the present disclosure may be realized and obtained by the means and combinations particularly pointed out in the appended claims. These and other features of the present disclosure will become more apparent from the following description and the appended claims, or may be learned by practice of the principles set forth herein.
[0020] The following detailed description is intended to serve as a description of the various configurations of the embodiments, rather than being intended to represent a unique configuration in which the subject matter of the present application can be implemented. The accompanying drawings are incorporated herein and form a part of the detailed description. The content of the detailed description includes specific details intended to provide a more thorough understanding of the subject matter of the present disclosure. However, it is apparent that the subject matter of the present disclosure is not limited to the specific details described herein, and can be implemented without these details. In some cases, structures and components are shown in block diagram form to avoid confusing the concept of the subject matter of the present disclosure.
[0021] Overview
[0022] Various aspects of the invention are set out in the independent claims and preferred features are set out in the dependent claims. Features of one aspect may apply to each aspect alone or in combination with other aspects.
[0023] As mentioned above, currently, software-defined network (SD-WAN) infrastructure owners are required to create a third-party witness component and integrate the third-party witness component into the SD-WAN infrastructure in order to manage the migration of the SD-WAN from a source cloud to a destination cloud in a multi-cloud architecture. The present disclosure proposes a solution and mechanism for migrating SD-WAN components from a source cloud to a destination cloud in a multi-cloud architecture without using the third-party witness component, thereby eliminating the disadvantages caused by the reliance on the third-party witness component.
[0024] In one aspect, a method includes: using a virtual connect device of a network orchestration component to monitor a cluster of virtual management components of multiple cloud networks, wherein the corresponding virtual management component of one of the multiple cloud networks implements one or more services of a software-defined wide area network (SD-WAN) solution; detecting a failover event at the one of the multiple cloud networks using the virtual connect device; and identifying, by the virtual connect device, a new destination cloud network to migrate the one or more services of the SD-WAN solution from a source cloud network where the failover event was detected to the new destination cloud network.
[0025] In another aspect, each virtual link device has a constructed secure channel to each virtual management component in each cluster.
[0026] In another aspect, monitoring the cluster includes determining a number of inactive virtual management components in each of a plurality of cloud networks.
[0027] In another aspect, detecting a failover event includes: each of the virtual link devices determining whether the corresponding cluster is in an active state or an inactive state based on the number of inactive virtual management components in the one of the multiple cloud networks; and determining a failover event for the one of the multiple cloud networks when a first threshold number of the virtual link devices determine that the number of inactive virtual management components in the corresponding cluster is equal to a second threshold number.
[0028] In another aspect, identifying a new destination cloud network includes determining a combined weight of virtual management components in a target destination cloud; and identifying the target destination cloud as the new destination cloud if the combined weight of the virtual management components in the target destination cloud is equal to or greater than a third threshold.
[0029] In another aspect, determining the combined weight is based on, for each of the virtual management components in the target destination cloud: a respective assigned weight, a respective configuration parameter, and a respective location.
[0030] In another aspect, the method further includes transmitting identification information of the new destination cloud to a virtual intelligence component in a network control and data plane, wherein the virtual intelligence component triggers a network edge device to migrate to a cluster of virtual network components of the new destination cloud.
[0031] In one aspect, a network controller includes: a memory having computer-readable instructions stored therein; and one or more processors configured to execute the computer-readable instructions as a virtual connect device of a software-defined wide area network (SD-WAN) solution to perform the following operations: monitoring a cluster of virtual management components of multiple cloud networks, wherein a corresponding virtual management component of one of the multiple cloud networks implements one or more services of the software-defined network (SD-WAN) solution; detecting a failover event at the one of the multiple cloud networks; and identifying a new destination cloud network to migrate the one or more services of the SD-WAN solution from a source cloud network where the failover event was detected to the new destination cloud network.
[0032] In one aspect, one or more non-transitory computer-readable media include computer-readable instructions that, when executed by one or more processors, cause the one or more processors to function as a virtual connecter for a software-defined wide area network (SD-WAN) solution to: monitor a cluster of virtual management components of a plurality of cloud networks, wherein a corresponding virtual management component of one of the plurality of cloud networks implements one or more services of the software-defined wide area network (SD-WAN) solution; detect a failover event at the one of the plurality of cloud networks; and identify a new destination cloud network to migrate one or more services of the SD-WAN solution from a source cloud network where the failover event was detected to the new destination cloud network.
[0033] Example Embodiments
[0034] Using this third-party witness component has several disadvantages. First, it needs to be integrated into the SD-WAN infrastructure. Second, the third-party witness component cannot select the correct destination cloud for migration based on policies enforced at the edge of the network overlay. Third, the third-party witness component requires secure communication with the vManage cluster of the multi-cloud architecture. Fourth, because vBond is part of the overlay's orchestration plane, the third-party witness component requires a permanent secure connection with vBond to configure the destination cloud's vManage cluster to be valid, ensuring control and data plane migration to the destination vManage cluster. Fifth, the SD-WAN fabric owner is responsible for managing the third-party witness component's lifecycle. Sixth, the health of the third-party witness component is not visible. Finally, the third-party witness component is a single point of failure and therefore requires high reliability and availability.
[0035] The solution proposed in the present disclosure for managing the migration of SD-WAN on a multi-cloud fabric when a failure occurs in the fabric eliminates the use of a third-party witness component and solves the above-mentioned disadvantages of using a third-party witness component. The proposed solution will be fully described below.
[0036] This disclosure begins with an overview of SD-WAN and the corresponding architecture.
[0037] Figure 1 The diagram illustrates a network architecture according to one aspect of the present disclosure. One example implementation of network architecture 100 is a Cisco® Software-Defined Wide Area Network (SD-WAN) architecture. However, those skilled in the art will appreciate that network architecture 100, as well as any other systems discussed in this disclosure, may have additional or fewer components in similar or alternative configurations. The diagrams and examples provided in this disclosure are for simplicity and clarity. Other embodiments may include different numbers and / or types of elements, but those skilled in the art will recognize that such variations do not depart from the scope of this disclosure.
[0038] In this example, network architecture 100 may include an orchestration plane 102, a management plane 120, a control plane 130, and a data plane 140. Orchestration plane 102 facilitates the automated onboarding of edge network devices 142 (e.g., switches, routers, etc.) into an overlay network. Orchestration plane 102 may include one or more physical or virtual network orchestrator appliances 104. Network orchestrator appliances 104 may perform initial authentication of edge network devices 142 and orchestrate connectivity between devices in control plane 130 and data plane 140. In some example embodiments, network orchestrator appliances 104 may also facilitate communication between devices located behind network address translation (NAT). In some example embodiments, a physical or virtual Cisco® SD-WAN vBond appliance may function as network orchestrator appliance 104.
[0039] The management plane 120 may be responsible for central configuration and monitoring of the network. The management plane 120 may include one or more physical or virtual network management appliances 122. The network management appliances 122 may provide centralized management of the network through a graphical user interface, enabling users to monitor, configure, and maintain edge network devices 142 and links in underlay and overlay networks (e.g., Internet transport network 160, Multiprotocol Label Switching (MPLS) network 162, 4G / LTE network 164). The network management appliances 122 may support multi-tenancy and enable centralized management of multiple logically isolated networks associated with different entities (e.g., an enterprise, a department within an enterprise, a group within a department, etc.). Alternatively or additionally, the network management appliance 122 may be a dedicated network management system for a single entity. In some example embodiments, a physical or virtual Cisco® SD-WAN vManage appliance may function as the network management appliance 122.
[0040] The management plane 120 may also include an analytics engine 124 to provide visibility into application and network performance over time, such as the best and worst performing applications, the highest bandwidth consuming applications, anomalous application clusters (e.g., applications whose bandwidth consumption varies over time), network availability and circuit availability, carrier health, and the best and worst performing tunnels. The analytics engine 124 can generate a graphical representation of the overlay network and enable users to drill down to display the characteristics of individual carriers, tunnels, or applications at a specific time. These characteristics can be presented to network administrators via a user interface of the network management appliance 122 (e.g., vManage). The user interface can serve as an interactive overview of the network and an entry point to more detailed information. In some example embodiments, the user interface can display information from the past 24 hours and enable users to drill down to select different time periods for different data sets. The user interface can also display data related to network availability, WAN performance by carrier and application, and other network analytics.
[0041] In some example embodiments, the analysis engine 124 may provide application performance using a virtual quality of experience (vQoE) value, which may be customized for individual applications. This value may range from zero to ten, with zero being the worst performance and ten being the best. The analysis engine may calculate vQoE based on latency, loss, and jitter, and customize the calculation for each application.
[0042] The control plane 130 can build and maintain the network topology and make decisions about where traffic should flow. The control plane 130 can include one or more physical or virtual network controller devices 132. The network controller devices 132 can establish secure connections to each edge network device 142 and distribute routing and policy information via control plane protocols (e.g., Overlay Management Protocol (OMP), Open Shortest Path First (OSPF), Intermediate System to Intermediate System (IS-IS), Border Gateway Protocol (BGP), Protocol Independent Multicast (PIM), Internet Group Management Protocol (IGMP), Internet Control Message Protocol (ICMP), Address Resolution Protocol (ARP), Bidirectional Forwarding Detection (BFD), Link Aggregation Control Protocol (LACP), etc.). In some example embodiments, the network controller devices 132 can operate as route reflectors. The network controller devices 132 can also orchestrate secure connectivity between multiple edge network devices 142 in the data plane 140. For example, in some example embodiments, the network controller devices 132 can distribute encryption key information between multiple edge network devices 142. This can allow the network to support secure network protocols or applications (e.g., Internet Protocol Security (IPSec), Transport Layer Security (TLS), Secure Shell (SSH), etc.) without Internet Key Exchange (IKE) and achieve network scalability. In some example embodiments, a physical or virtual Cisco® SD-WAN vSmart controller can operate as the network controller device 132.
[0043] The data plane 140 may be responsible for forwarding packets based on decisions from the control plane 130. The data plane 140 may include a plurality of edge network devices 142, which may be physical network devices or virtual network devices. The edge network devices 142 may operate at the edge of various network sites associated with an organization, such as in one or more data centers or hosting centers 150, campus networks 152, branch office networks 154, home office networks 156, etc., or in the cloud (e.g., Infrastructure as a Service (IaaS), Platform as a Service (PaaS), SaaS, and other cloud service provider networks). The edge network device 142 can provide secure data plane connectivity between sites over one or more WAN transports, such as via one or more Internet transport networks 160 (e.g., digital subscriber line (DSL), cable, etc.), MPLS networks 162 (or other private packet switching networks (e.g., metropolitan Ethernet, frame relay, asynchronous transfer mode (ATM)), etc.), mobile networks 164 (e.g., 3G, 4G / LTE, 5G, etc.), or other WAN technologies (e.g., synchronous optical network (SONET), synchronous digital hierarchy (SDH), dense wavelength division multiplexing (DWDM), or other fiber technologies; leased lines (e.g., T1 / E1, T3 / E3, etc.); public switched telephone network (PSTN), integrated services digital network (ISDN), or other private circuit switching networks; small aperture terminal (VSAT) or other satellite networks, etc.). The edge network device 142 can be responsible for traffic forwarding, security, encryption, quality of service (QoS), and routing (e.g., BGP, OSPF, etc.), among other tasks. In some embodiments, the physical or virtual Cisco® The SD-WAN vEdge router may operate as an edge network device 142 .
[0044] Figure 2 Illustrated is an example of a multi-cloud architecture with a third-party witness component for managing SD-WAN migrations according to an aspect of the present disclosure.
[0045] Architecture 200 is a multi-cloud structure with multiple cloud structures. The number of multiple cloud structures can be two or more. Figure 2 In the example of FIG, multiple cloud structures 202-1, 202-2, ..., 202-N are shown, where N is an integer equal to or greater than 3. Each of the multiple cloud structures 202-1, 202-2, ..., 202-N can have a cluster of vManage (e.g., as described above with reference to FIG). Figure 1For example, cloud fabric 202-1 has cluster 204-1, which includes interconnected vManage 205-1 (in this example, cluster 204-1 includes three vManage 205-1, but the number of vManage 205-1 can be different, such as 1, 2, 3, etc.). Similarly, cloud fabric 202-2 has cluster 204-2, which includes interconnected vManage 205-2; cloud fabric 202-N has cluster 204-N, which includes interconnected vManage 205-N, and so on. Figure 2 In the example of FIG, it is assumed that the SD-WAN solution is currently deployed and running on the cloud structure 202-1. Therefore, the cloud structure 202-1 can be referred to as the source cloud.
[0046] vManage components such as vManage 205-1 are graphical user interface based controllers used to provide and manage Figure 2 vManage provides the ability to manage all aspects of the WAN, from configuring, monitoring, and upgrading routers to application visibility and troubleshooting WAN issues.
[0047] The architecture 200 also includes control and data plane components 206 for the SD-WAN solution currently running on the cloud fabric 202-1. The control and data plane components 202 include a number of vEdge 206-1 components and vSmart 206-2 components, as well as other components known to those skilled in the art. The number of vEdges 206-1 and vSmarts 206-2 is not limited to Figure 2 The number shown is not the same as the one shown, but can be more or less. vSmart is the centralized brain / controller of the SD-WAN solution, implementing policy and connectivity between multiple SD-WAN branches. The centralized policy engine in the Cisco vSmart controller provides the policy structure for manipulating routing information, access control, segmentation, extranets, and service chaining. As mentioned above, vEdge is an SD-WAN router that can operate as an edge network device.
[0048] The network architecture 200 also includes a third-party witness component 208, which can be communicatively coupled to each cloud fabric 202-1, 202-2, ..., 202-N, and the third-party witness component 208 is currently used to manage the following operations: when a failure occurs in a particular cloud fabric and a supporting cluster of vManage, the migration of the SD-WAN solution from a source cloud (e.g., cloud fabric 202-1) to a destination cloud (e.g., one of cloud fabrics 202-2, ..., 202-N) (this migration process may also be referred to as disaster recovery).
[0049] As mentioned above, using a third-party witness component for disaster recovery and SD-WAN solution migration has several disadvantages. First, the third-party witness component 208 needs to be spliced into the Figure 2 in the infrastructure shown. Second, the third-party witness component 209 cannot select the correct destination based on the enforced policy on the edge of the overlay. Third, the third-party witness component 208 needs to establish a secure connection with the vManage cluster of the source cloud fabric and the vManage cluster of the destination cloud fabric (e.g., cluster 204-1 and one of clusters 204-2, ..., 204-N). Fourth, since vBond is the orchestrator of the overlay, the third-party witness component 208 needs to have a permanent secure connection with vBond to configure the destination vManage cluster as valid (e.g., one of vManage clusters 204-2, ..., 204-N). This will ensure that the control and data planes of the SD-WAN solution are migrated to the destination vManage cluster. Fifth, the responsibility for managing the lifecycle of the third-party witness component 208 lies with the infrastructure owner. Sixth, the third-party witness component 208 relies on a polling model that only checks the reachability of the currently running vManage cluster and therefore does not provide visibility into the service health of the third-party witness component. Seventh, since the third-party witness component 208 is a single point of failure, the high availability and high reliability of the third-party witness component 208 should be guaranteed.
[0050] In view of the above-mentioned shortcomings of relying on a third-party witness component 208 to manage SD-WAN migration and disaster recovery, the following describes Figure 3 and Figure 4 structures and processes to address these shortcomings.
[0051] Figure 3 An example of a multi-cloud architecture for managing SD-WAN migration without relying on a third-party witness component according to an aspect of the present disclosure is illustrated. Figure 3 In the architecture 300, Figure 3 of and Figure 2Components that are identical to corresponding parts are given the same numbers and thus will not be described further for the sake of brevity.
[0052] Unlike architecture 200, architecture 300 has an orchestration plane 302 that can be used with Figure 1 The orchestration plane 302 is identical to the orchestration plane 102 of FIG. The orchestration plane 302 has one or more vBonds 304, which are orchestrators that facilitate the initial startup of the SD-WAN solution by performing authentication and authorization of all elements entering the SD-WAN. The vBond orchestrator 304 also provides information about how each component of the SD-WAN solution is connected to the other components.
[0053] from Figure 3 As can be seen in the structural diagram of FIG, orchestration plane 302 is connected to each of cloud fabrics 202-1, ..., 202-N and control and data plane 206, and therefore vBond 304 is also connected to each of cloud fabrics 202-1, ..., 202-N and control and data plane 206. In addition, each vManage in each of clusters 204-1, ..., 204-N has a weight assigned to the vManage, which is used to manage cross-cloud migration of the SD-WAN solution as will be described in more detail below.
[0054] During disaster recovery, the architecture 300 leverages the existing orchestration plane 302 to monitor the vManage clusters 204-1, ..., 204-N and trigger the migration of the control and data planes of the SD-WAN solution from the source cloud to the destination cloud. By relying on the existing orchestration plane 302, the third-party witness component 208 is no longer required, and the shortcomings of the third-party witness component 208 as described above can be addressed as follows: Figure 4 process is resolved.
[0055] Figure 4 An example method of managing SD-WAN migration in a multi-cloud fabric is described according to an aspect of the present disclosure. Figure 4 The description is from the perspective of the orchestration plane 302, and more specifically from the perspective of the vBond 304. Figure 4 For the purposes of this disclosure, vBond 304 may be referred to as a controller (network controller). It should be noted that such vBond 304 may be implemented by one or more processors that execute computer-readable instructions to implement the following description. Figure 4 Steps in .
[0056] At S400 , vBond 304 monitors a cluster of virtual management components (e.g., vManage clusters 204-1, 204-2, ..., 204-N). Leveraging the SD-WAN design, vBond 304 maintains a permanent, secure connection to each vManage cluster in clusters 204-1, 204-2, ..., 204-N. At S400 , vBond 304 monitors not only the reachability of multiple clusters 204-1, 204-2, ..., 204-N, but also their health, including but not limited to the availability of various services (database, message bus, etc.) running in a given vManage cluster. vBond 304 connects not only to each of clusters 204-1, 204-2, ..., 204-N, but also to each vManage cluster within each of these clusters.
[0057] At S402, vBonds 304 may receive information regarding preferences, weights, and locations for each vManage cluster. In one example, such preferences, weights, and location information may be configured by a network administrator through the vManage itself. Preferences may be numerical values based on a best effort approach to connecting to another component in the network using a preferred circuit. Weights may also be numerical values used for load balancing across multiple vManages in a given cluster. Locations may represent the geographic location of each vManage in a given cluster, which may be used to reduce latency and redundancy within the network.
[0058] In one example, a similar process can be used in vSmart 206 - 2 for load balancing, which is described in U.S. Application No. 15 / 286,116, filed on October 5, 2016, the entire contents of which are incorporated herein by reference.
[0059] At S404, vBond 304 maintains a record of active / inactive vManage clusters based on the received preferences, weights, and positions. For example, if the number of operational vManages in the cluster exceeds a configurable threshold (the threshold is determined based on experiments and / or empirical studies), the vManage cluster may be determined to be active.
[0060] At S406 , a determination is made as to whether a threshold number of vBonds 304 indicate that a certain number of vManages in a given vManage cluster (e.g., a threshold number of vManages in cluster 204 - 1 ) are active (and / or alternatively, inactive). This threshold number of vBonds 304 may be referred to as a quorum of vBonds 304 . The threshold value for the quorum of vBonds 304 is a configurable parameter that may be determined based on experimentation and / or empirical research. For example, assuming that the SD-WAN solution is currently executing on cluster 202 - 1 , at S406 , a determination is made as to whether a threshold number of vBonds 304 indicate that a threshold number of vManages in vManage cluster 204 - 1 are active (and / or inactive).
[0061] If the threshold number of vBonds 304 is not reached at S406, the process returns to S400 and repeats S400-S406. However, if the threshold number of vBonds 304 is reached at S406, a failover event is detected at S408. The failover event triggers the migration of the SD-WAN solution from the current cloud fabric (e.g., cloud 202-1) to the destination cloud (e.g., one of cloud fabrics 202-2, ..., 202-N).
[0062] After a failover event is detected at S408 , a target destination cloud (eg, one of cloud fabrics 202 - 2 , . . . , 202 -N) is selected at S410 .
[0063] At S412 , vBonds 304 determines the combined weights of the target destination clouds. In one example, the target destination clouds are assigned configurable preferences and locations, and each vManage in a corresponding cluster (e.g., one of vManage clusters 204 - 2 , ..., 204 -N) has a configurable weight. The combined weights of the target destination clouds are determined based on the configurable weights of each vManage and the configurable preferences and locations.
[0064] For example, the structure 300 may have three clouds 202-1, 202-2, and 202-3 (e.g., Amazon Web Services®, Google®, and Microsoft®, respectively), where cloud structure 202-1 is the source (primary) cloud structure. Therefore, cloud structures 202-2 and 202-3 may both be target destination clouds. Further, assume that the combined weight of vManage 205-2 of cloud structure 202-2 is a combined value of 10, while vManage 205-3 of cloud structure 202-3 ( Figure 3The combined weight of the infrastructure provided by cloud fabric 202-2 (not explicitly shown) is a combined value of 5. Furthermore, assume that the preferred value for cloud fabric 202-2 is 2, while the preferred value for cloud fabric 202-3 is 4. Finally, assume that the location providing the infrastructure for cloud fabric 202-2 (example value 1) is relatively preferred over the location providing the infrastructure for cloud fabric 202-3 (example value 0) for the execution of the SD-WAN solution. Therefore, the combined weight for cloud fabric 202-2 is 13, while the combined weight for cloud fabric 202-3 is 9.
[0065] At S414 , it is determined whether the combined weight of the target destination cloud is below a configurable threshold (a target threshold, a non-limiting numerical example of which is 10). If it is determined that the combined weight is less than the target threshold (e.g., the combined weight for cloud structure 2020-3 in the non-limiting example above is 9), then at S416 , the next target destination cloud is selected, and S412 and S414 are repeated for the next target destination cloud.
[0066] Once it is determined at S414 that the combined weight of the target destination cloud is equal to or greater than the target threshold (or alternatively, greater than the target threshold), then at S418, the target destination cloud is marked as valid and selected as the destination cloud (e.g., cloud fabric 202-2) to migrate the SD-WAN solution from the source cloud (e.g., from cloud fabric 202-1) to the destination cloud. In the above non-limiting example, the combined weight of cloud fabric 202-2 is 13, which is greater than the example threshold of 10, and therefore cloud fabric 202-2 is selected as the destination cloud.
[0067] At S420, vBonds 304 marks the source cloud (e.g., cloud fabric 202-1) as invalid, and transmits the invalid status of the source cloud and information about the selected destination cloud (e.g., cloud fabric 202-2) to all vSmarts in the control and data plane component 206. In one example, upon receiving the new destination cloud information (e.g., information about cloud fabric 202-2), the vSmarts will perform a make-before-break operation to connect to the new target cloud, and will then inform all edge devices (vEdges) in the control and data plane component 206 of the change in the management plane, thereby triggering all edge devices to migrate to a new vManage cluster (e.g., vManage cluster 204-2) in the destination cloud (e.g., in the destination cloud fabric 202-2).
[0068] With the above-described example of the peer node discovery process, the present disclosure now turns to a description of device components and architecture that may be implemented as any of the network management device 122 , the network controller device 132 , the edge network device 142 , and the like.
[0069] Following the example of migration management of SD-WAN instances in a multi-cloud fabric (described above), the present disclosure now turns to a description of example components that may be used as controllers and components of the multi-cloud fabric 200 to implement migration management.
[0070] Figure 5A-5B An example of a system according to an aspect of the present disclosure is illustrated.
[0071] Figure 5A An example of a bus computing system 500 is shown, in which the system's components electrically communicate with each other using a bus 505. Computing system 500 may include a processing unit (CPU or processor) 510 and a system bus 505 that couples various system components (e.g., read-only memory (ROM) 520 and random-access memory (RAM) 525) to processor 510, including system memory 515. Computing system 500 may include a cache 512, a high-speed memory directly connected to, in close proximity to, or integrated as part of processor 510. Computing system 500 may copy data from memory 515, ROM 520, RAM 525, and / or storage devices 530 to cache 512 for faster access by processor 510. In this way, cache 512 can provide a performance boost, avoiding processor delays while waiting for data. These and other modules may control processor 510 to perform various actions. Additional system memory 515 may also be available. Memory 515 may include a variety of different types of memory with varying performance characteristics. Processor 510 may include any general-purpose processor and hardware or software modules (e.g., module 1 532, module 2 534, and module 3 536 stored in storage device 530) configured to control processor 510, and may include a dedicated processor in which software instructions are incorporated into the actual processor design. Processor 510 may be essentially a fully self-contained computing system that includes multiple cores or processors, a bus, a memory controller, a cache, etc. Multi-core processors may be symmetric or asymmetric.
[0072] In order to enable the user to interact with the computing system 500, the input device 545 can represent any number of input mechanisms, such as a microphone for voice, a touch screen for gesture or graphic input, a keyboard, a mouse, motion input, voice, etc. The output device 535 can also be one or more of the many output mechanisms known to those skilled in the art. In some cases, a multimodal system can enable a user to provide multiple types of input to communicate with the computing system 500. The communication interface 540 can control and manage user input and system output. There is no limitation on the operation on any specific hardware arrangement, so as improved hardware or firmware arrangements are developed, the basic features here can be easily replaced with these improved hardware or firmware arrangements.
[0073] The storage device 530 may be a non-volatile memory and may be a hard disk or other type of computer-readable medium that can store data that can be accessed by a computer, such as a magnetic tape cartridge, a flash memory card, a solid-state memory device, a digital versatile disk, a cassette tape, a random access memory, a read-only memory, and combinations thereof.
[0074] As described above, the storage device 530 may include software modules 532, 534, 536 for controlling the processor 510. Other hardware or software modules are contemplated. The storage device 530 may be connected to the system bus 505. In some embodiments, a hardware module that performs a particular function may include a software component stored in a computer-readable medium that is associated with the necessary hardware components (e.g., the processor 510, the bus 505, the output device 535, etc.) to perform that function.
[0075] Figure 5BAn example architecture of a chipset computing system 550 that can be used according to one embodiment is shown. Computing system 550 may include a processor 555, which represents any number of physically and / or logically distinct resources capable of executing software, firmware, and hardware configured to perform the identified computations. Processor 555 may communicate with chipset 560, which may control input to and output from processor 555. In this example, chipset 560 may output information to an output device 565, such as a display, and may read and write information to storage device 570, which may include magnetic media, solid-state media, and other suitable storage media. Chipset 560 may also read data from and write data to RAM 575. A bridge 580 may be provided for interfacing with various user interface components 585 for interfacing with chipset 560. User interface components 585 may include a keyboard, a microphone, touch detection and processing circuitry, a pointing device such as a mouse, and the like. Input to computing system 550 may come from any of a variety of sources, machine-generated and / or human-generated.
[0076] Chipset 560 may also interface with one or more communication interfaces 590, which may have different physical interfaces. Communication interfaces 590 may include interfaces for wired and wireless LANs, for broadband wireless networks, and for personal area networks. Some applications of the methods for generating, displaying, and using the technology disclosed herein may include receiving an ordered data set through a physical interface, or these applications may be generated by the machine itself by analyzing data stored in storage device 570 or RAM 575 by processor 555. In addition, computing system 550 may receive input from a user via user interface component 585 and perform appropriate functions, such as browsing functions, by interpreting these inputs using processor 555.
[0077] It should be understood that computing systems 500 and 550 may have more than one processor 510 and 555, respectively, or that computing systems 500 and 550 may be part of a group or cluster of computing devices networked together to provide greater processing power.
[0078] In summary, the present disclosure relates to managing the migration of an SD-WAN solution in a multi-cloud fabric after detecting a failover event. In one aspect, a method includes: using a virtual connect appliance of a network orchestration component to monitor a cluster of virtual management components of a plurality of cloud networks, wherein a corresponding virtual management component of one of the plurality of cloud networks implements one or more services of a software-defined wide area network (SD-WAN) solution; detecting a failover event at the one of the plurality of cloud networks using the virtual connect appliance; and identifying, by the virtual connect appliance, a new destination cloud network to migrate the one or more services of the SD-WAN solution from the source cloud network where the failover event was detected to the new destination cloud network.
[0079] For clarity of explanation, in some cases, various embodiments may be represented as including functional blocks, including functional blocks comprising devices, device components, steps or routines in methods implemented in software, or a combination of hardware and software.
[0080] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and signals themselves.
[0081] The method according to the above example can be implemented using computer-executable instructions stored in a computer-readable medium or otherwise available from a computer-readable medium. Such instructions can include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a dedicated processing device to perform a specific function or group of functions. The portion of the computer resources used can be accessible via a network. The computer-executable instructions can be, for example, binary, intermediate format instructions, such as assembly language, firmware, or source code. Examples of computer-readable media that can be used to store instructions, information used during the method according to the example, and / or information created include magnetic or optical disks, flash memory, USB devices equipped with non-volatile memory, networked storage devices, and the like.
[0082] Devices implementing the methods according to these disclosures may include hardware, firmware, and / or software and may be implemented in any of a variety of form factors. Some examples of such form factors include general-purpose computing devices, such as servers, rack-mounted devices, desktops, laptops, and the like, or general-purpose mobile computing devices, such as tablets, smartphones, personal digital assistants, wearable devices, and the like. The functionality described herein may also be embodied in peripheral devices or add-in cards. As a further example, such functionality may also be implemented on different chips or circuit boards between different processes executed in a single device.
[0083] Instructions, media for communicating such instructions, computing resources for executing such instructions, and other structure for supporting such computing resources are the means for providing the functionality described in these disclosures.
[0084] Although various examples and other information are used to explain various aspects within the scope of the appended claims, no limitation to the claims should be implied based on the specific features or arrangements in such examples, as one of ordinary skill in the art will be able to use these examples to derive a variety of implementations. In addition, although some subject matter may have been described in language specific to examples of structural features and / or method steps, it should be understood that the subject matter defined in the appended claims is not necessarily limited to these described features or actions. For example, such functionality may be distributed in different ways or performed in components other than those identified herein. Instead, the described features and steps are disclosed as examples of components and methods of systems within the scope of the appended claims.
Claims
1. A method for managing software-defined wide area network (SD-WAN) migration for a multi-cloud architecture, comprising: monitoring a cluster of virtual management components of a plurality of cloud networks using a virtual connect appliance within an orchestration plane of the SD-WAN, wherein a corresponding virtual management component of one of the plurality of cloud networks implements one or more services of the SD-WAN solution; detecting a failover event at the one of the plurality of cloud networks using the virtual link device; and identifying, by the virtual connect device, a new destination cloud network to migrate the one or more services of the SD-WAN solution from the source cloud network where the failover event was detected to the new destination cloud network, wherein each of the virtual link devices has a constructed secure channel to each virtual management component in each of the clusters, wherein monitoring the cluster comprises determining a number of inactive virtual management components for each of the plurality of cloud networks, The detecting of the failover event includes: determining, by each of the virtual link devices, whether the corresponding cluster is in an active state or an inactive state based on a number of inactive virtual management components in the one of the plurality of cloud networks; and When a first threshold number of the virtual link devices determines that the number of inactive virtual management components in the corresponding cluster is equal to a second threshold number, a failover event is determined for the one of the plurality of cloud networks.
2. The method according to claim 1, wherein Identifying the new destination cloud network includes: determining a combined weight of virtual management components in a target destination cloud; If the combined weights of the virtual management components in the target destination cloud are equal to or greater than a third threshold, the target destination cloud is identified as the new destination cloud.
3. The method according to claim 2, wherein: Determining the combined weight is based on, for each of the virtual management components in the target destination cloud, a respective assigned weight, a respective configuration parameter, and a respective location.
4. The method according to any one of claims 1 to 3, further comprising: The identification information of the new destination cloud is communicated to a virtual intelligence component in a network control and data plane, wherein the virtual intelligence component triggers a network edge device to migrate to a cluster of virtual network components of the new destination cloud.
5. A network controller comprising: a memory having computer-readable instructions stored therein; as well as One or more processors configured to execute the computer-readable instructions as a virtual link device within an orchestration plane of a software-defined wide area network (SD-WAN) to: monitoring a cluster of virtual management components of a plurality of cloud networks, wherein a corresponding virtual management component of a cloud network in the plurality of cloud networks implements one or more services of the SD-WAN solution; detecting a failover event at the one of the plurality of cloud networks; and identifying a new destination cloud network to migrate the one or more services of the SD-WAN solution from the source cloud network where the failover event was detected to the new destination cloud network, wherein each of the virtual link devices has a constructed secure channel to each virtual management component of each of the clusters, wherein the virtual connect device is configured to execute the computer-readable instructions to monitor the cluster by determining a number of inactive virtual management components for each of the plurality of cloud networks, The virtual link device is configured to execute the computer-readable instructions to detect the failover event by performing the following operations: determining, by each of the virtual link devices, whether the corresponding cluster is in an active state or an inactive state based on a number of inactive virtual management components of the one of the plurality of cloud networks; and The failover event for the one of the plurality of cloud networks is determined when a first threshold number of the virtual link devices determines that the number of inactive virtual management components in the corresponding cluster is equal to a second threshold number. The network controller according to claim 5 , wherein: The virtual link device is configured to execute the computer-readable instructions to identify the new destination cloud network by: determining a combined weight of virtual management components in a target destination cloud; If the combined weights of the virtual management components in the target destination cloud are equal to or greater than a third threshold, the target destination cloud is identified as the new destination cloud.
7. The network controller according to claim 6, wherein: Determining the combined weight is based on, for each of the virtual management components in the target destination cloud, a respective assigned weight, a respective configuration parameter, and a respective location.
8. The network controller according to any one of claims 5 to 7, wherein: The virtual connect device is configured to execute the computer-readable instructions to transmit identification information of the new destination cloud to a virtual intelligence component in a network control and data plane, wherein the virtual intelligence component triggers a network edge device to migrate to a cluster of virtual network components of the new destination cloud.
9. One or more non-transitory computer-readable media comprising computer-readable instructions that, when executed by one or more processors, cause the one or more processors to function as a virtual link within an orchestration plane of a software-defined wide area network (SD-WAN) to: A cluster of virtual management components that monitor multiple cloud networks, where A corresponding virtual management component of one of the plurality of cloud networks implements one or more services of the SD-WAN solution; detecting a failover event at the one of the plurality of cloud networks; as well as identifying a new destination cloud network to migrate one or more services of the SD-WAN solution from the source cloud network where the failover event was detected to the new destination cloud network, wherein each of the virtual link devices has a constructed secure channel to each virtual management component of each of the clusters, wherein execution of the computer-readable instructions by the one or more processors causes the virtual connect device to monitor the cluster by determining a number of inactive virtual management components for each of the plurality of cloud networks; Execution of the computer-readable instructions by the one or more processors causes the virtual link device to detect the failover event by: determining, by each of the virtual link devices, whether the corresponding cluster is in an active state or an inactive state based on a number of inactive virtual management components in the one of the plurality of cloud networks; and When a first threshold number of the virtual link devices determines that the number of inactive virtual management components in the corresponding cluster is equal to a second threshold, the failover event is determined for the one of the plurality of cloud networks.
10. The one or more non-transitory computer-readable media of claim 9, wherein: Execution of the computer-readable instructions by the one or more processors causes the virtual link device to identify the new destination cloud network by: determining a combined weight of virtual management components in a target destination cloud; If the combined weights of the virtual management components in the target destination cloud are equal to or greater than a third threshold, the target destination cloud is identified as the new destination cloud.
11. The one or more non-transitory computer-readable media of claim 10, wherein: Determining the combined weight is based on, for each of the virtual management components in the target destination cloud, a respective assigned weight, a respective configuration parameter, and a respective location.
12. An apparatus for managing software-defined wide area network (SD-WAN) migration of a multi-cloud structure, comprising: means for monitoring a cluster of virtual management components of a plurality of cloud networks using a virtual connect appliance within an orchestration plane of an SD-WAN, wherein a corresponding virtual management component of one of the plurality of cloud networks implements one or more services of the SD-WAN solution; means for detecting a failover event at the one of the plurality of cloud networks using the virtual link device; and means for identifying, by the virtual connect device, a new destination cloud network to migrate the one or more services of the SD-WAN solution from the source cloud network in which the failover event was detected to the new destination cloud network, wherein each of the virtual link devices has a constructed secure channel to each virtual management component in each of the clusters, wherein the means for monitoring the cluster comprises means for determining a number of inactive virtual management components of each of the plurality of cloud networks, The device for detecting the failover event includes: means for determining, by each of the virtual link devices, whether the corresponding cluster is in an active state or an inactive state based on a number of inactive virtual management components in the one of the plurality of cloud networks; and Means for determining a failover event for the one of the plurality of cloud networks when a first threshold number of the virtual link devices determines that a number of inactive virtual management components in the corresponding cluster equals a second threshold number.
13. The apparatus according to claim 12, wherein The means for identifying a new destination cloud network comprises: means for determining a combined weight of virtual management components in a target destination cloud; Means for identifying the target destination cloud as the new destination cloud when a combined weight of virtual management components in the target destination cloud is equal to or greater than a third threshold.
14. The apparatus according to claim 13, wherein Determining the combined weight is based on, for each of the virtual management components in the target destination cloud, a respective assigned weight, a respective configuration parameter, and a respective location.
15. The apparatus according to any one of claims 12 to 14, further comprising: Means for communicating identification information of the new destination cloud to a virtual intelligence component in a network control and data plane, wherein the virtual intelligence component triggers a network edge device to migrate to a cluster of virtual network components of the new destination cloud.
16. A computer-readable medium comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method according to any one of claims 1 to 4.
17. A computer program product comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Method and system for managing control connections with a distributed control plane
US20180367384A1
Replication of virtualized infrastructure within distributed computing environments
US20160048408A1