A traffic orchestration method, apparatus, and medium thereof

By using traffic orchestration methods in network security devices, using the acl rule table, interface flow table and policy table for traffic matching, the traffic delay and fault interruption caused by series deployment are solved, and flexible traffic path orchestration and high-reliability traffic transmission are achieved.

CN115643174BActive Publication Date: 2025-05-27HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211293084.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-21
Publication Date
2025-05-27
Estimated Expiration
2042-10-21

AI Technical Summary

Technical Problem

Existing network security devices deployed in series lead to large delays in traffic transmission and easy service interruption in case of equipment failure, which leads to high recovery costs.

Method used

Through the traffic orchestration method, the traffic matching is used to determine the next hop interface of the service traffic, and flexible traffic path orchestration is realized and faulty equipment is skipped.

Benefits of technology

Reduces network delay, avoids traffic jams and service interruptions caused by device failures, and improves the flexibility and reliability of traffic orchestration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643174B_ABST
    Figure CN115643174B_ABST
Patent Text Reader

Abstract

The present application discloses a traffic orchestration method, apparatus and medium, which relate to the field of network security technology and are used for the orchestration of traffic cleaning. Aiming at the problems of delay and difficult restoration of interruption existing in the current series deployment scheme, a traffic orchestration method is provided. The next-hop interface of the service traffic is determined by matching the entries stored in the acl rule table, the interface flow table and the policy table, and the process is repeated until returning to the drainage network segment interface of the virtual router, thus completing one traffic cleaning orchestration. According to different settings of the entries, the service traffic can have different orchestration paths, and thus it is not limited to the form of series-deploying security devices. Users can adjust the entries in the above three tables as needed, so as to achieve the effect of freely defining the security devices passed by the service traffic and the order of traffic flow, and reduce network delay. Moreover, when any security device fails, corresponding entries can be set to skip the security device to solve the problem of request congestion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and particularly to a traffic orchestration method, apparatus, and medium thereof. Background Art

[0002] With the continuous development of information technology, network security issues have now received increasing attention. Currently, there is a protection method for traffic cleaning through multiple network security devices deployed in series in a network to ensure data security.

[0003] However, this deployment solution has the following problems: 1. Before the traffic reaches the server business system, it needs to flow through all security devices, and each device has to process the traffic, and it is impossible to selectively skip security devices, resulting in a large network delay; 2. In a serial architecture, if a device in the cascaded link fails, user requests will be blocked, causing service interruption, and the fault recovery processing time and cost are very high.

[0004] Therefore, those skilled in the art now urgently need a traffic orchestration method to solve the problems existing in the current serial deployment solution. Summary of the Invention

[0005] The purpose of this application is to provide a traffic orchestration method, apparatus, and medium thereof to solve the problems existing in the current serial deployment solution.

[0006] To solve the above technical problems, this application provides a traffic orchestration method, including:

[0007] Receiving service traffic and forwarding it to the drainage network segment interface of the virtual router; wherein, the service traffic includes: source IP and destination IP;

[0008] Matching the acl entry in the acl rule table according to the source IP of the service traffic, and recording the acl number of the matched acl entry; wherein, the acl entry includes acl number, source IP, and destination IP;

[0009] Determining the corresponding interface flow table according to the current interface where the service traffic is located, and recording the policy numbers of each interface entry therein; wherein, the interface entry includes a policy number and an interface;

[0010] Matching the policy entry in the policy table according to the recorded policy number, and determining whether the acl number in the successfully matched policy entry is consistent with the recorded acl number. If they are consistent, the interface of the policy entry is the next-hop interface of the service traffic, and return to the step of determining the corresponding interface flow table according to the current interface of the service traffic until the next-hop interface is the drainage network segment interface; wherein, the policy entry includes: policy number, acl number, and interface.

[0011] Preferably, the interface entry further includes a priority, and the priorities of the interface entries in the same interface flow table are unique;

[0012] Correspondingly, recording the policy numbers of the interface entries therein includes:

[0013] Recording the policy number of the interface entry with the highest priority among the interface entries.

[0014] Preferably, the priority is determined by the creation time of the interface entry, and the earlier the creation time of the interface entry, the higher its priority.

[0015] Preferably, the acl entries are grouped in pairs, and two acl entries in the same group are respectively used to match tenant traffic and response traffic; wherein, the tenant traffic is the service traffic sent from the tenant side, and the response traffic is the service traffic sent from the tenant asset side.

[0016] Preferably, the destination ip of the acl entry used to match the response traffic in the same group is the same as the source ip of the acl entry used to match the tenant traffic.

[0017] Preferably, it further includes:

[0018] If the acl number in the successfully matched policy entry is inconsistent with the recorded acl number, the service traffic will be returned along the original path.

[0019] Preferably, it further includes:

[0020] If the acl number in the successfully matched policy entry is inconsistent with the recorded acl number, a traffic orchestration failure prompt message will be returned to the cloud management platform.

[0021] To solve the above technical problems, the present application also provides a traffic orchestration device, including:

[0022] A traffic receiving module, configured to receive service traffic and forward it to the drainage network segment interface of the virtual router; wherein, the service traffic includes: source ip, destination ip;

[0023] A first matching module, configured to match the acl entry in the acl rule table according to the source ip of the service traffic and record the acl number of the matched acl entry; wherein, the acl entry includes an acl number, a source ip, and a destination ip;

[0024] A second matching module, configured to determine the corresponding interface flow table according to the current interface where the service traffic is located, and record the policy numbers of the interface entries therein; wherein, the interface entry includes a policy number and an interface;

[0025] The interface arrangement module is used to match the policy table items in the policy table according to the recorded policy number, and determine whether the acl number in the successfully matched policy table item is consistent with the recorded acl number. If they are consistent, the interface of the policy table item is the next-hop interface of the business traffic, and returns to the step of determining the corresponding interface flow table according to the current interface of the business traffic until the next-hop interface is the drainage network segment interface; wherein the policy table item includes: policy number, acl number, interface.

[0026] Preferably, it also includes:

[0027] The traffic return module is used to return the business traffic along the original path when the ACL number in the successfully matched policy table item is inconsistent with the recorded ACL number.

[0028] The failure prompt module is used to return traffic orchestration failure prompt information to the cloud management platform when the ACL number in the successfully matched policy table item is inconsistent with the recorded ACL number.

[0029] In order to solve the above technical problems, the present application also provides a traffic scheduling device, including:

[0030] Memory for storing computer programs;

[0031] A processor is used to implement the steps of the above-mentioned traffic scheduling method when executing a computer program.

[0032] In order to solve the above technical problems, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the traffic orchestration method as described above are implemented.

[0033] A traffic orchestration method provided by this application matches the corresponding ACL entry from the ACL rule table through the destination IP of the service traffic, and records the corresponding ACL number; then records the corresponding policy number according to the interface flow table of the interface where the service traffic is currently located; afterwards, according to the policy entry in the policy table that matches the recorded policy number, determines whether the ACL number in the policy entry is consistent with the previously recorded ACL number. If they are consistent, the interface in the corresponding policy entry is used as the next-hop interface of the service traffic; repeat the above steps until the next-hop interface is the drainage network segment interface of the virtual router, indicating that the service traffic has been cleaned by several network security devices. It is easy to know that the order of the above traffic orchestration method passing through the network security devices is determined by the entries stored in the ACL rule table, the interface flow table, and the policy table. According to different settings of the entries, the service traffic can have different interface paths, and thus is not limited to the form of cascading security devices in series, nor does it need to pass through all security devices. Users can adjust the entries in the above three tables as needed, so as to achieve the effect of freely defining the security devices passed by the service traffic and the order of traffic flow. Also because of this, when any security device fails, only need to set the corresponding entry to skip this security device, and there will be no problem of request congestion caused by the currently used method.

[0034] The traffic orchestration device and computer-readable storage medium provided by this application correspond to the above method and have the same effect. Brief Description of the Drawings

[0035] To more clearly illustrate the embodiments of this application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0036] Figure 1 It is a flowchart of a traffic orchestration method provided by the present invention;

[0037] Figure 2 It is an application principle diagram of a traffic orchestration method provided by the present invention;

[0038] Figure 3 It is a structure diagram of a traffic orchestration device provided by the present invention;

[0039] Figure 4 It is a structure diagram of another traffic orchestration device provided by the present invention. Detailed Embodiments

[0040] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0041] The core of the present application is to provide a traffic orchestration method, device, and medium thereof.

[0042] In order to enable those skilled in the art to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0043] In today's business systems, in order to ensure network security, network security devices are usually set up. When business traffic is transmitted, it needs to pass through the network security devices for cleaning first and then be transmitted to the corresponding side to ensure data security.

[0044] Currently, the common deployment method of network security devices is to deploy them in series in the network. When business traffic is transmitted from one side to the other side, it must pass through each series-connected security device for traffic cleaning. This method makes the traffic transmission path unique and must pass through all security devices, and it is impossible to selectively skip some security devices, which will lead to a relatively large network delay. Moreover, when any security device in the above series-connected link fails, the business traffic will be blocked at the faulty device, resulting in service interruption, and the recovery of the service also requires troubleshooting the security device, and the required processing time and cost are very large, which is not conducive to the recovery of the service and affects the user experience.

[0045] Based on the above problems, the present application provides a traffic orchestration method, as Figure 1 shown, including:

[0046] S11: Receive business traffic and forward it to the drainage network segment interface of the virtual router.

[0047] Among them, the business traffic at least includes: source IP and destination IP.

[0048] S12: Match the ACL entry in the ACL rule table according to the source IP of the business traffic and record the ACL number of the matched ACL entry.

[0049] Among them, the ACL entry at least includes an ACL number, communication protocol (IPv4 / IPv6), source IP, destination IP, source port, and destination port. Exemplarily, in actual applications, an ACL entry is as follows:

[0050] acl-index 0count 1tag{acl_in_1}

[0051] 0: ipv4 permit src 0.0.0.0 / 0 dst 99.2.3.4 / 32 proto 6 sport 0-65535 dport 0-65535

[0052] S13: Determine the corresponding interface flow table according to the current interface where the service traffic is located, and record the policy numbers of each interface entry therein.

[0053] Among them, the interface entry includes at least a policy number, a communication protocol (ipv4), and an interface.

[0054] Exemplarily, an interface entry is as follows:

[0055] abf-interface-attach:policy:1 priority:1

[0056] arp-ipv4:via 1.1.2.9 GigabitEthernet0 / 5 / 0

[0057] It should be noted that there are generally multiple interface flow tables, and each interface corresponds to its own interface flow table. When the service traffic starts to perform network orchestration, it starts from the drainage network segment interface of the virtual router, that is, the interface flow table searched at this time is the interface flow table of the drainage network segment interface. When the service traffic is transmitted to the next-hop interface, the queried interface flow table is the interface flow table of the next-hop interface.

[0058] S14: Match the policy entries in the policy table according to the recorded policy numbers, and determine whether the acl number in the successfully matched policy entry is consistent with the recorded acl number. If they are consistent, the interface of the policy entry is the next-hop interface of the service traffic.

[0059] S15: Determine whether the next-hop interface is the drainage network segment interface. If it is, end this method; if not, return to step S13.

[0060] Among them, the policy entry includes at least: a policy number, an acl number, a communication protocol (ipv4), and an interface.

[0061] Exemplarily, a policy entry is as follows:

[0062] policy:5 acl:3

[0063] arp-ipv4:via 1.1.2.9 GigabitEthernet0 / 5 / 0

[0064] To further illustrate the principle of traffic orchestration implemented by a traffic orchestration method provided in this application, the following is an illustration in combination with examples:

[0065] A business system, such as Figure 2 as shown, includes: tenant side 21, tenant asset side 22 (also known as the response side), layer 2 switch 23, virtual router 24, and three different network security devices 25 (VFW, FNGFW, IPS).

[0066] Among them, the security devices 25 VFW, FNGFW, and IPS are created in the security resource pool, the virtual router 24 is pre-created by the administrator. When the tenant side 21 or the tenant asset side 22 sends service traffic to the other side, it is first forwarded by the layer 2 switch 23 to the drainage network segment interface of the virtual router 24, waiting for subsequent traffic orchestration.

[0067] When performing traffic orchestration, the cloud management platform orchestrates and issues the corresponding service chain. For example: VFW - FNGFW - tenant asset side 22. That is, this service chain means that after the service traffic is forwarded from the tenant side 21 to the virtual router 24, it first passes through the security device 25 VFW, then through the security device 25 FNGFW, and finally returns to the virtual router 24 and is sent to the tenant asset side 22 via the layer 2 switch 23, completing a one-way traffic transmission. It is easy to know that the traffic orchestration from the tenant asset side 22 to the tenant side 21 is the same reason.

[0068] For the orchestration of the above service chain, it can be implemented by converting it into the corresponding entries in the acl rule table, interface flow table, and policy table. After the above three tables are set up, the traffic can be sequentially orchestrated through the above traffic orchestration method, without flowing through all the security devices 25, nor a fixed flow-through order, and the entire traffic transmission process will not be blocked when any link fails.

[0069] It should also be noted that for the above acl rule table, interface flow table, and policy table, the acl rule table and interface flow table are existing, and the policy table can be pre-configured and issued.

[0070] A traffic orchestration method provided by this application realizes the matching between entries through an ACL rule table, an interface flow table, and a policy table. Then, according to the policy table entry obtained by matching, the next-hop interface of the current service traffic is determined until the service chain of the entire service traffic is orchestrated, completing an orchestration process for traffic cleaning. This traffic orchestration method based on entry matching is more flexible compared to the currently used series form. It is not limited to flowing through all or some of the security devices, nor is it limited to the order of flowing through the security devices. It can effectively reduce the network latency of request response while solving the problems of traffic congestion and service interruption caused by the failure of any network device. In addition, it should be noted that the above method is based on the existing ACL rule table and interface flow table, and completes the matching of the next-hop interface through the policy table. It has little interference with the business system configuration, is simple to implement, and the method of storing and matching by separate tables can also decouple between tables. When any entry in any table has a problem, it will not interfere with the matching of other entries, improving the reliability of traffic orchestration. Moreover, this structure of separate tables is also beneficial to controlling the size of each table, so that when the business faced by the business system is relatively complex, the situation of an overly large table will not occur, which better meets the actual application needs.

[0071] As can be seen from the above embodiments, a traffic orchestration method provided by this application performs traffic orchestration through the matching between entries in the ACL rule table, the interface flow table, and the policy table. When the number of service chains arranged by the cloud management platform is large and the business is relatively complex, it is inevitable that multiple service chains that meet the requirements will be matched simultaneously. At this time, it will bring uncertainty to traffic orchestration. Therefore, this embodiment provides a preferred implementation:

[0072] The interface entry also includes a priority, and the priorities of the interface entries in the same interface flow table are unique.

[0073] That is to say, the interface entry at least includes: a policy number, a priority, a communication protocol (IPv4), and an interface.

[0074] Correspondingly, the step of recording the policy numbers of the interface entries therein includes:

[0075] Record the policy number of the interface entry with the highest priority among the interface entries.

[0076] That is to say, in step S13, when determining the policy number corresponding to the policy table participating in the subsequent matching, it is determined according to the interface entry with the highest priority in the current interface flow table, achieving the effect of uniquely determining the policy number. Further, that is to say, a unique service chain is determined for cleaning and transmitting the service traffic.

[0077] In addition to the above effect of uniquely determining the traffic cleaning and transmission path of the service chain orchestration, the priority can also meet the specific needs of the management personnel. For example, in some specific application scenarios, if the management personnel tend to use certain service chains as the transmission path of the service traffic, the priorities of these service chains can be set higher. Considering that there are various different application scenarios in actual applications and the needs of the management personnel are also different, this embodiment will not elaborate here.

[0078] In addition, without special requirements for preferentially selecting certain specific service chains, this embodiment provides a method for determining the priority: the priority is determined by the creation time of the interface entry, and the earlier the creation time of the interface entry, the higher its priority. That is to say, the priority is determined according to the creation time sequence of the corresponding service chain, and the earlier the time, the higher the priority, and it is more preferentially used in traffic orchestration.

[0079] The above implementation method of determining the priority according to the creation time sequence is simple and easy to implement, and can quickly and conveniently determine the priorities of each entry, so as to achieve the effect of uniquely determining the service chain according to the priority for traffic orchestration.

[0080] In this embodiment, by adding the priority to the interface entry, it can be uniquely determined when determining the policy table for subsequent traffic orchestration, avoiding the problem of uncertain traffic orchestration paths caused by multiple policy tables being matched simultaneously, and improving the stability of traffic orchestration. At the same time, the setting of the priority can also meet the needs of the management personnel in specific application scenarios, enabling traffic orchestration to preferentially use certain specific service chains for traffic cleaning and transmission. In addition, when there are no special requirements, the priority can be quickly and conveniently determined according to the creation time sequence of the service chain, so as to meet the above needs of uniquely determining the policy table.

[0081] As can be seen from the above embodiments, a traffic orchestration method provided by this application can realize the traffic cleaning path orchestration from the tenant side to the tenant asset side. Similarly, the traffic orchestration from the tenant asset side to the tenant side is the same. Specifically, as shown in the following embodiments:

[0082] The acl entries are grouped in pairs, and the two acl entries in the same group are respectively used to match the tenant traffic and the response traffic; among them, the tenant traffic is the service traffic sent from the tenant side, and the response traffic is the service traffic sent from the tenant asset side.

[0083] Since the matching of the acl entries is performed by the destination ip of the service traffic, naturally, in the communication between the tenant side and the tenant asset side, for the service traffic sent from different sides (which can be divided into tenant traffic and response traffic according to the sending side, and the tenant asset side is also called the response side), their source ip and destination ip are different. Exemplarily, a group of acl entries is as follows:

[0084] acl-index 0 count 1 tag{acl_in_1}

[0085] 0: ipv4 permit src 0.0.0.0 / 0 dst 99.2.3.4 / 32 proto 6 sport 0-65535 dport 0-65535

[0086] acl-index 1 count 1 tag{acl_out_2}

[0087] 0: ipv4 permit src 28.1.2.3 / 32 dst 0.0.0.0 / 0 proto 6 sport 80 dport 0-65535

[0088] That is, for service traffic from different sides, the corresponding acl number can be recorded through the corresponding acl entry. In subsequent matching, the corresponding traffic orchestration can be achieved through the above traffic orchestration method, not limited to the service traffic from a certain side.

[0089] It should be noted that a business system does not only correspond to one tenant and its assets. Therefore, the above descriptions for the tenant side, the tenant asset side, and the two grouped acl entries are all for a group of tenants and their assets. The same applies to other tenants and assets, so no further elaboration will be made.

[0090] For the traffic orchestration of the communication between the tenant side and its tenant asset side, the above traffic orchestration method can be adopted. Further, this embodiment also provides a preferred implementation scheme:

[0091] The destination IP of the acl entry used to match the response traffic in the same group is the same as the source IP of the acl entry used to match the tenant traffic.

[0092] That is, the traffic path (i.e., the service chain) from the tenant side to the tenant asset side is opposite to the traffic path from the tenant asset side to the tenant side.

[0093] During the traffic transmission process, the transmission path used for successfully transmitting from the tenant side to the tenant asset side is more reliable than other unknown paths. The reverse transmission method is considered for the ease of implementation of the method. By making the destination IP of the acl entry used to match the response traffic the same as the source IP of the acl entry used to match the tenant traffic among the grouped acl entries, no additional complex configuration is required and the implementation is simple.

[0094] A possible implementation provided in this embodiment specifically illustrates how the above traffic orchestration method is implemented in the application scenario of reversely sending service traffic from the tenant asset side to the tenant side. At the same time, a preferred reverse implementation scheme is also provided. By simply setting the ACL entries, the response traffic can be transmitted in the same path as the tenant traffic but in the reverse direction, further improving the reliability and ease of implementation of traffic orchestration.

[0095] In addition, as can be seen from the above embodiment, when the recorded ACL number is consistent with the ACL number stored in the policy table entry that matches successfully according to the policy number in the policy table, the interface in this policy table entry is used as the next-hop interface. Therefore, correspondingly, this embodiment provides an implementation scheme when the ACL numbers are inconsistent. Step S14 further includes:

[0096] If the ACL number in the successfully matched policy table entry is inconsistent with the recorded ACL number, the service traffic is returned along the original path.

[0097] Generally speaking, according to the ACL rule table, interface flow table, and table entries of the policy table obtained by converting the service chain issued by the cloud management platform, the next-hop interface can be matched under normal working conditions. If the phenomenon of inconsistent ACL numbers occurs, it means that there are problems (problems with table entries or data transmission, etc.). At this time, the correctness of traffic orchestration cannot be guaranteed. To ensure network security, the service traffic is returned along the original path.

[0098] Furthermore, in the above application scenario, this embodiment also provides a preferred implementation scheme. The above method further includes:

[0099] If the ACL number in the successfully matched policy table entry is inconsistent with the recorded ACL number, a traffic orchestration failure prompt message is returned to the cloud management platform.

[0100] Specifically, the effect of feedback prompt information can be achieved through message push or acoustic, optical signal warning, etc. This embodiment does not limit this, so as to prompt the management personnel to quickly check and solve the problem and restore the normal operation of the business system.

[0101] A preferred scheme provided in this embodiment is that when the service traffic fails to be orchestrated according to the above traffic orchestration method, it indicates that there are probably problems or failures in the business system. At this time, the service traffic is returned along the original path to ensure network security, and a traffic orchestration failure prompt message is fed back to the cloud management platform, so that the management personnel can learn this situation in time, check the problems and failures of the business system, and restore the traffic orchestration function and the normal operation of the business system as soon as possible, further improving the reliability.

[0102] In the above embodiments, a traffic orchestration method is described in detail. The present application also provides corresponding embodiments of a traffic orchestration device. It should be noted that the present application describes the embodiments of the device part from two perspectives, one is from the perspective of functional modules, and the other is from the perspective of hardware.

[0103] From the perspective of functional modules, as Figure 3 shown, this embodiment provides a traffic orchestration device, including:

[0104] A traffic receiving module 31, configured to receive service traffic and forward it to the drainage network segment interface of the virtual router; wherein, the service traffic includes: source ip, destination ip;

[0105] A first matching module 32, configured to match the acl entry in the acl rule table according to the source ip of the service traffic, and record the acl number of the matched acl entry; wherein, the acl entry includes acl number, source ip, destination ip;

[0106] A second matching module 33, configured to determine the corresponding interface flow table according to the current interface where the service traffic is located, and record the policy numbers of each interface entry therein; wherein, the interface entry includes a policy number and an interface;

[0107] An interface orchestration module 34, configured to match the policy entry in the policy table according to the recorded policy number, and determine whether the acl number in the successfully matched policy entry is consistent with the recorded acl number. If they are consistent, the interface of the policy entry is the next-hop interface of the service traffic, and return to the step of determining the corresponding interface flow table according to the current interface of the service traffic until the next-hop interface is the drainage network segment interface; wherein, the policy entry includes: policy number, acl number, interface.

[0108] Preferably, it further includes:

[0109] A traffic return module, configured to return the service traffic along the original route when the acl number in the successfully matched policy entry is inconsistent with the recorded acl number.

[0110] A failure prompt module, configured to return a traffic orchestration failure prompt message to the cloud management platform when the acl number in the successfully matched policy entry is inconsistent with the recorded acl number.

[0111] Since the embodiments of the device part correspond to the embodiments of the method part, please refer to the description of the embodiments of the method part for the embodiments of the device part, and details are not described here for the time being.

[0112] A traffic orchestration device provided in this embodiment, when the traffic receiving module receives service traffic, records the destination IP of the service traffic and the current interface it is on, and records the corresponding ACL number and policy number through the first matching module and the second matching module, so as to find the next-hop interface according to the policy table until the service chain of the entire service traffic is orchestrated, completing an orchestration procedure for traffic cleaning. Compared with the currently used series form, it has stronger flexibility, is not limited to having to flow through all or some security devices, nor is it limited to the order of flowing through security devices. It can effectively reduce the network latency of request response while solving the problems of traffic congestion and service interruption caused by the failure of any network device. In addition, this method of completing traffic orchestration by sub-table matching can achieve decoupling. When any entry in any table has a problem, it will not interfere with the matching of other entries, improving the reliability of traffic orchestration. Moreover, this sub-table structure is also conducive to controlling the size of each table, so that the table will not become too large when the business faced by the business system is relatively complex, which better meets the actual application needs.

[0113] Figure 4 The structure diagram of a traffic orchestration device provided in another embodiment of this application is shown as Figure 4 shown. A traffic orchestration device includes: a memory 40 for storing computer programs;

[0114] a processor 41 for implementing the steps of a traffic orchestration method as described in the above embodiment when executing the computer program.

[0115] A traffic orchestration device provided in this embodiment may include but is not limited to a smart phone, a tablet computer, a notebook computer, or a desktop computer, etc.

[0116] Among them, the processor 41 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 41 may be implemented in at least one hardware form of a Digital Signal Processor (DSP), a Field-Programmable Gate Array (FPGA), or a Programmable Logic Array (PLA). The processor 41 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the Central Processing Unit (CPU); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 41 may be integrated with a Graphics Processing Unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 41 may also include an Artificial Intelligence (AI) processor, which is used to process computational operations related to machine learning.

[0117] The memory 40 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 40 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 40 is at least used to store the following computer program 401. After the computer program is loaded and executed by the processor 41, it can implement the relevant steps of a traffic orchestration method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 40 may also include an operating system 402 and data 403, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 402 may include Windows, Unix, Linux, etc. The data 403 may include, but is not limited to, a traffic orchestration method, etc.

[0118] In some embodiments, a traffic orchestration device may further include a display screen 42, an input / output interface 43, a communication interface 44, a power supply 45, and a communication bus 46.

[0119] Those skilled in the art can understand that Figure 4 the structure shown in

[0120] A traffic orchestration device provided by an embodiment of the present application includes a memory and a processor. When the processor executes the program stored in the memory, the following method can be implemented: A traffic orchestration method.

[0121] A traffic orchestration device provided by this embodiment realizes the matching between the entries of the acl rule table, the interface flow table, and the policy table through the processor executing the computer program stored in the memory, determines the next-hop interface of the current service traffic, and until the service chain of the entire service traffic is orchestrated, completing the orchestration of traffic cleaning. Compared with the current method of connecting security devices in series, the above device is more flexible, not limited to flowing through specific security devices and the flowing order, can effectively reduce the network latency of request response, and solve the problems of traffic congestion and service interruption caused when any network device fails. In addition, the method of sub-table matching can also achieve decoupling between tables. When any problem occurs in any entry in any table, it will not interfere with the matching of other entries, improving the reliability of traffic orchestration. And this sub-table structure is also beneficial to controlling the size of each table, and when the services faced by the business system are relatively complex, the situation of the table being too large will not occur, which is more in line with the actual application needs.

[0122] Finally, the present application also provides an embodiment corresponding to a computer-readable storage medium. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, the steps recorded in the above method embodiment are implemented.

[0123] It can be understood that if the method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in various embodiments of the present application. And the foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0124] A computer-readable storage medium provided in this embodiment, when the computer program stored therein is executed, can realize the matching between the entries of the acl rule table, the interface flow table, and the policy table, determine the next-hop interface of the current service traffic, and thus arrange the service chain of the entire service traffic. This method is not limited to flowing through specific security devices and the flowing order. Compared with the current method of connecting security devices in series, it has higher flexibility, can effectively reduce the network latency of request response, and the traffic congestion and service interruption problems caused when any network device fails. In addition, the method of table-by-table matching can also achieve decoupling between tables. When any problem occurs in any entry of any table, it will not interfere with the matching of other entries, improving the reliability of traffic arrangement. Moreover, this table-by-table structure is also beneficial to controlling the size of each table, and when the services faced by the service system are relatively complex, the situation of the table being too large will not occur, which is more in line with the actual application needs.

[0125] The above has introduced in detail a traffic arrangement method, device, and its medium provided by this application. The various embodiments in the specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same and similar parts between the various embodiments, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the description of the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.

[0126] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article, or device including the said element.

Claims

1. A traffic orchestration method, It is characterized in that include: Receive business traffic and forward it to the drainage network segment interface of the virtual router; wherein the business traffic includes: source IP and destination IP; Matching the ACL entry in the ACL rule table according to the source IP of the service flow, and recording the ACL number of the matched ACL entry; wherein the ACL entry includes the ACL number, source IP, and destination IP; Determine the corresponding interface flow table according to the current interface of the service flow, and record the policy number of each interface table entry therein; wherein the interface table entry includes the policy number and the interface; Match the policy items in the policy table according to the recorded policy number, and determine whether the acl number in the successfully matched policy item is consistent with the recorded acl number. If they are consistent, the interface of the policy item is the next-hop interface of the business traffic, and return to the step of determining the corresponding interface flow table according to the current interface of the business traffic until the next-hop interface is the drainage network segment interface; wherein, the policy item includes: policy number, acl number, interface.

2. The traffic scheduling method according to claim 1, It is characterized in that The interface table entry also includes a priority, and the priority of each interface table entry in the same interface flow table is unique; Correspondingly, the policy number of each interface entry in the record includes: The policy number of the interface table entry with the highest priority among the interface table entries is recorded.

3. The traffic scheduling method according to claim 2, It is characterized in that The priority is determined by the creation time of the interface table entry, and the earlier the creation time of the interface table entry is, the higher the priority is.

4. The traffic scheduling method according to claim 1, It is characterized in that The acl table entries are grouped in pairs, and the two acl table entries in the same group are respectively used to match tenant traffic and response traffic; wherein, the tenant traffic is the business traffic sent by the tenant side, and the response traffic is the business traffic sent by the tenant asset side.

5. The traffic scheduling method according to claim 4, It is characterized in that The destination IP of the ACL table entry used to match the response traffic in the same group is the same as the source IP of the ACL table entry used to match the tenant traffic.

6. The traffic scheduling method according to any one of claims 1 to 5, It is characterized in that Also includes: If the acl number in the successfully matched policy entry is inconsistent with the recorded acl number, the service traffic is returned along the original path.

7. The traffic scheduling method according to claim 6, It is characterized in that Also includes: If the ACL number in the successfully matched policy entry is inconsistent with the recorded ACL number, a traffic orchestration failure prompt message is returned to the cloud management platform.

8. A traffic arrangement device, It is characterized in that include: A traffic receiving module is used to receive business traffic and forward it to the drainage network segment interface of the virtual router; wherein the business traffic includes: source IP and destination IP; The first matching module is configured to match the ACL entries in the ACL rule table according to the source IP of the service traffic, and record the ACL numbers of the matched ACL entries; wherein, the ACL entries include ACL numbers, source IPs, and destination IPs. The second matching module is configured to determine the corresponding interface flow table according to the current interface where the service traffic is located, and record the policy numbers of each interface entry therein; wherein, the interface entries include policy numbers and interfaces. The interface orchestration module is configured to match the policy entries in the policy table according to the recorded policy numbers, and determine whether the ACL number in the successfully matched policy entry is consistent with the recorded ACL number. If they are consistent, the interface in the policy entry is the next-hop interface of the service traffic, and return to the step of determining the corresponding interface flow table according to the current interface of the service traffic until the next-hop interface is the drainage network segment interface; wherein, the policy entries include: policy numbers, ACL numbers, and interfaces.

9. A traffic orchestration device Characterized in that It includes: A memory for storing computer programs; A processor for implementing the steps of the traffic orchestration method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium Characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of the traffic orchestration method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and device for searching network logic path and storage medium

    CN110855721A

  • Slice-based routing

    US20200366607A1