A network communication method and forwarding network

By introducing a forwarding network and configuring communication tunnels between virtual private clouds, the problem of direct communication between different virtual private clouds is solved, achieving effective data relay and improved communication capabilities.

CN115834686BActive Publication Date: 2026-04-10ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ALIBABA (CHINA) CO LTD
Filing Date
2022-11-16
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Different virtual private clouds cannot communicate directly, creating a communication need but lacking an effective solution.

Method used

By introducing a forwarding network between virtual private clouds, data relay is achieved using controllers and forwarding nodes, and communication between virtual private clouds is realized by configuring communication tunnels to connect different forwarding nodes.

Benefits of technology

It enables communication between different virtual private clouds, improves the communication capabilities and flexibility of the forwarding network, and meets the data interaction needs between multiple virtual private clouds.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834686B_ABST
    Figure CN115834686B_ABST
Patent Text Reader

Abstract

The embodiment of the present specification discloses a network communication method and a forwarding network. A network communication method applied to a forwarding network, the method comprises: a first forwarding node in the forwarding network receiving to-be-forwarded data sent by a first virtual private cloud to which the forwarding network is connected; in a case where a sending target of the to-be-forwarded data cannot be determined, the first forwarding node sends preset information of the to-be-forwarded data to a controller; the controller determines, based on the preset information, that the sending target of the to-be-forwarded data is a second virtual private cloud to which the forwarding network is connected, and in a case where it is determined that the first forwarding node cannot communicate with the second virtual private cloud, determines a second forwarding node capable of communicating with the second virtual private cloud from the forwarding network, and configures a communication tunnel for the first forwarding node and the second forwarding node; the first forwarding node sends the to-be-forwarded data to the second forwarding node through the configured communication tunnel; and the second forwarding node sends the to-be-forwarded data to the second virtual private cloud.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present specification relate to the field of communication, and in particular to a network communication method and a forwarding network. BACKGROUND

[0002] Currently, in the related technology of network virtualization, a virtual private cloud is an isolated and private virtual network environment constructed based on cloud services. Different virtual private clouds are logically isolated and cannot directly communicate.

[0003] However, there is a communication demand between different virtual private clouds. Therefore, there is an urgent need for a method for communication between different virtual private clouds. SUMMARY

[0004] To solve the above problems, embodiments of the present specification provide a network communication method and a forwarding network. The technical solutions are as follows.

[0005] A network communication method applied to a forwarding network, the forwarding network comprising a controller and a plurality of forwarding nodes; the forwarding network is connected to at least two virtual private clouds; for any connected virtual private cloud, at least one forwarding node in the forwarding network can communicate with the virtual private cloud; the method comprises:

[0006] A first forwarding node in the forwarding network receives data to be forwarded sent by a first virtual private cloud connected to the forwarding network;

[0007] In a case where the sending target of the data to be forwarded cannot be determined, the first forwarding node sends preset information of the data to be forwarded to the controller;

[0008] The controller determines, based on the preset information, that the sending target of the data to be forwarded is a second virtual private cloud connected to the forwarding network, and in a case where the first forwarding node cannot communicate with the second virtual private cloud, determines a second forwarding node capable of communicating with the second virtual private cloud from the forwarding network, and configures a communication tunnel for the first forwarding node and the second forwarding node;

[0009] The first forwarding node sends the data to be forwarded to the second forwarding node through the configured communication tunnel;

[0010] The second forwarding node sends the data to be forwarded to the second virtual private cloud.

[0011] A forwarding network comprising a controller and a plurality of forwarding nodes; the forwarding network is connected to at least two virtual private clouds; for any connected virtual private cloud, at least one forwarding node in the forwarding network can communicate with the virtual private cloud;

[0012] The first forwarding node in the forwarding network is capable of communicating with a first virtual private cloud interfaced by the forwarding network;

[0013] The first forwarding node is configured to receive data to be forwarded sent by the first virtual private cloud, and send preset information of the data to be forwarded to the controller in a case where a sending target of the data to be forwarded cannot be determined;

[0014] The controller is configured to determine, based on the preset information, that the sending target of the data to be forwarded is a second virtual private cloud interfaced by the forwarding network, and in a case where the first forwarding node is determined to be incapable of communicating with the second virtual private cloud, determine a second forwarding node capable of communicating with the second virtual private cloud from the forwarding network, and configure a communication tunnel for the first forwarding node and the second forwarding node;

[0015] The first forwarding node is configured to send the data to be forwarded to the second forwarding node through the configured communication tunnel;

[0016] The second forwarding node is configured to send the data to be forwarded to the second virtual private cloud.

[0017] The above technical solution realizes communication between different virtual private clouds by taking the forwarding network as a transit between different virtual private clouds. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments described in the present specification, and other drawings can also be obtained by those skilled in the art based on these drawings.

[0019] Figure 1 is a flow diagram of a network communication method provided by an embodiment of the present specification;

[0020] Figure 2 is a principle diagram of a network communication method provided by an embodiment of the present specification;

[0021] Figure 3 is a format diagram of a GENEVE encapsulated packet provided by an embodiment of the present specification;

[0022] Figure 4 is a structure diagram of a forwarding network provided by an embodiment of the present specification;

[0023] Figure 5is a structural schematic diagram of a network communication system provided by an embodiment of the present specification.

[0024] Figure 6 is a structural schematic diagram of a device for configuring the method of an embodiment of the present specification. DETAILED DESCRIPTION

[0025] In order for those skilled in the art to better understand the technical solutions in the embodiments of the present specification, the technical solutions in the embodiments of the present specification will be described in detail below with reference to the drawings in the embodiments of the present specification. Obviously, the described embodiments are only a part of the embodiments of the present specification, not all the embodiments. Based on the embodiments in the present specification, all other embodiments obtained by those skilled in the art should belong to the disclosed scope.

[0026] At present, in the related technology of network virtualization, a virtual private cloud (VPC) is an isolated and private virtual network environment constructed based on cloud services. Different virtual private clouds are completely isolated in logic and cannot directly communicate.

[0027] However, there is a communication demand between different virtual private clouds, and therefore, there is an urgent need for a method for communicating between different virtual private clouds.

[0028] For example, the same user rents multiple virtual private clouds, and multiple virtual private clouds need to interact with data; a service provider rents a virtual private cloud to realize a cloud service function, and other virtual private clouds need to use the cloud service function.

[0029] In order to solve the above problems, an embodiment of the present specification provides a network communication method.

[0030] In the method, a forwarding network can be added as a relay between multiple virtual private clouds. The forwarding network can be connected to a plurality of virtual private clouds, and the plurality of virtual private clouds connected can communicate with the forwarding network, so that communication between different virtual private clouds can be realized through the relay of the forwarding network.

[0031] In order to facilitate management, the forwarding network can include a controller and a plurality of forwarding nodes, wherein the forwarding nodes can be virtual machines, and the controller can issue configuration information to the forwarding nodes, so that the forwarding nodes perform data forwarding according to the configuration information.

[0032] For any virtual private cloud connected to the forwarding network, at least one forwarding node in the forwarding network can communicate with the virtual private cloud. The specific communication form is not limited, and optionally, communication can be performed through a virtual network card of the virtual private cloud.

[0033] Optionally, a virtual private cloud can communicate with one or more forwarding nodes in a forwarding network; a forwarding node in a forwarding network can communicate with one or more virtual private clouds that are connected to the forwarding network.

[0034] Therefore, a single forwarding node capable of communicating with multiple virtual private clouds can achieve communication between different virtual private clouds based on the information configured by the controller.

[0035] Due to limitations in the computing and communication resources of forwarding nodes, the number of virtual private clouds that a single forwarding node can communicate with is typically limited. Therefore, two virtual private clouds that need to communicate may communicate with different forwarding nodes.

[0036] To enhance the communication capabilities of the forwarding network, different forwarding nodes can communicate with each other. Specifically, the controller can configure communication tunnels for different forwarding nodes that need to communicate, thereby enabling communication. Different virtual private clouds can communicate through the communication tunnels between forwarding nodes.

[0037] The above method can enable communication between different virtual private clouds by using the forwarding network as a relay between them, and can also improve the communication capability of the forwarding network by using communication tunnels to connect different forwarding nodes.

[0038] like Figure 1 The diagram shown is a flowchart illustrating a network communication method provided in an embodiment of this specification. This method can be applied to a forwarding network, which may include a controller and several forwarding nodes. The controller can issue configuration information to the forwarding nodes to implement data forwarding.

[0039] Optionally, the forwarding network can interface with at least two virtual private clouds; for any one of the interfaced virtual private clouds, there can be at least one forwarding node in the forwarding network that can communicate with that virtual private cloud.

[0040] Optionally, for several forwarding nodes in the forwarding network, any two forwarding nodes can communicate with each other, and have communication capabilities. Specifically, every two forwarding nodes can communicate with each other, which facilitates the subsequent construction of communication tunnel connections between forwarding nodes.

[0041] Optionally, several forwarding nodes can be used as a distributed forwarding cluster to enable communication between different virtual private clouds.

[0042] The method may include the following steps.

[0043] S101: The first forwarding node in the forwarding network receives the data to be forwarded sent by the first virtual private cloud connected to the forwarding network.

[0044] Optionally, the first forwarding node is capable of communicating with a first virtual private cloud interfaced with the forwarding network.

[0045] S102: In a case where the sending target of the data to be forwarded cannot be determined, the first forwarding node sends preset information of the data to be forwarded to a controller.

[0046] S103: The controller determines, based on the preset information, that the sending target of the data to be forwarded is a second virtual private cloud interfaced with the forwarding network, and in a case where the first forwarding node cannot communicate with the second virtual private cloud, determines a second forwarding node capable of communicating with the second virtual private cloud from the forwarding network, and configures a communication tunnel for the first forwarding node and the second forwarding node.

[0047] S104: The first forwarding node sends the data to be forwarded to the second forwarding node through the configured communication tunnel.

[0048] S105: The second forwarding node sends the data to be forwarded to the second virtual private cloud.

[0049] The first forwarding node can be any forwarding node in the forwarding network. For ease of description, any forwarding node receiving data sent by a virtual private cloud is referred to as the first forwarding node, and the virtual private cloud sending the data is referred to as the first virtual private cloud.

[0050] In the above method flow, the forwarding network can be used as a relay between different virtual private clouds to realize communication between the different virtual private clouds, and the communication tunnel can be used to connect different forwarding nodes to improve the communication capability of the forwarding network.

[0051] Optionally, the forwarding network can interface with a plurality of virtual private clouds, and any virtual private cloud interfaced can communicate with one or more forwarding nodes in the forwarding network. Specifically, the any virtual private cloud can maintain a communication connection with the one or more forwarding nodes in the forwarding network.

[0052] Optionally, the controller in the forwarding network can manage a topology relationship for any virtual private cloud interfaced, and specifically, can manage a forwarding node capable of communicating with the virtual private cloud.

[0053] For example, the controller can manage and maintain one or more forwarding nodes connected to any virtual private cloud through a virtual network card, to facilitate determination of a forwarding node capable of communicating with the virtual private cloud.

[0054] The first virtual private cloud can be any virtual private cloud interfaced with the forwarding network, and the second virtual private cloud can be any virtual private cloud interfaced with the forwarding network. The first virtual private cloud can have a communication requirement with other virtual private clouds.

[0055] As for the forwarding network, the embodiments of the present specification do not specifically limit the form, as long as the forwarding network can interface with multiple virtual private clouds and can communicate with the multiple virtual private clouds.

[0056] Optionally, the forwarding network can be a network that can be communicated by other virtual private clouds, specifically, a Fabric network, that is, an internally interconnected network, which is invisible to the outside, and can improve availability and performance through Equal Cost Multi-path (ECMP); the forwarding network can also be a system virtual private cloud constructed by a service provider providing virtual private cloud services, so that other virtual private clouds can communicate with the system virtual private cloud. Optionally, the forwarding node in the forwarding network can be a virtual machine.

[0057] The following will explain each step in detail.

[0058] S101: A first forwarding node in a forwarding network receives data to be forwarded sent by a first virtual private cloud interfaced by the forwarding network.

[0059] Optionally, the first forwarding node can be a forwarding node in the forwarding network that can communicate with the first virtual private cloud, so as to receive the data to be forwarded sent by the first virtual private cloud.

[0060] As for the data to be forwarded, the method flow does not limit the specific form, which can be a message format.

[0061] As for the communication mode, the method flow does not limit. In an optional embodiment, it can be communicated through a virtual network card in the virtual private cloud.

[0062] Optionally, there can be a communication connection between the first forwarding node and the virtual network card in the first virtual private cloud. The first forwarding node receiving the data to be forwarded by the first virtual private cloud can include: the first forwarding node receiving the data to be forwarded by the first virtual private cloud through the virtual network card in the first virtual private cloud interfaced by the forwarding network. Specifically, it can be the data to be forwarded sent by the first virtual private cloud.

[0063] Optionally, the virtual network card can be an Elastic Network Interface (ENI), or a Bonding ENI.

[0064] In an optional embodiment, the virtual private cloud can communicate with one or more forwarding nodes in the forwarding network, and a single forwarding node in the forwarding network can communicate with one or more virtual private clouds.

[0065] Therefore, optionally, the first virtual private cloud can select the first forwarding node from the communicable forwarding nodes.

[0066] Optionally, the first forwarding node can be selected by the first virtual private cloud from the communicable forwarding nodes based on a first preset selection strategy.

[0067] The embodiment is not limited to a specific first preset selection strategy. Optionally, it can be randomly selected, or it can be selected according to information of the data to be forwarded. Specifically, the first virtual private cloud can take the number of communicable forwarding nodes as a hash value range, hash the information of the data to be forwarded, and determine a corresponding forwarding node.

[0068] For example, the data to be forwarded can be a packet. The five-tuple information or source address information of the packet to be forwarded can be hashed.

[0069] S102: In a case where a sending target of the data to be forwarded cannot be determined, the first forwarding node sends preset information of the data to be forwarded to the controller.

[0070] The method flow is not limited to a specific case where a sending target of the data to be forwarded cannot be determined.

[0071] Optionally, the first forwarding node can not parse a sending target of the data to be forwarded. Specifically, the first forwarding node can not parse which device or virtual private cloud needs to send the data to be forwarded to.

[0072] Optionally, the first forwarding node can also not have routing information matching the data to be forwarded in the routing information of the first forwarding node, so that the sending target of the data to be forwarded cannot be determined.

[0073] In an optional embodiment, the first forwarding node can perform data forwarding according to configuration information issued by the controller.

[0074] However, for the data to be forwarded, the sending target can not be determined according to the configuration information. Specifically, which device or virtual private cloud needs to send the data to be forwarded to can not be determined.

[0075] Optionally, the configuration information can be flow table information issued by the controller. The first forwarding node can determine whether the data to be forwarded successfully matches any piece of flow table information, so as to execute an operation in the piece of flow table information. The operation can be sending the data to be forwarded to a certain device or a certain virtual private cloud.

[0076] For example, in a case where the data to be forwarded is a packet to be forwarded, whether the five-tuple information of the packet to be forwarded successfully matches the five-tuple information in any piece of flow table information can be determined.

[0077] In an optional embodiment, if the first forwarding node can determine the sending target of the data to be forwarded, it can then determine whether the first forwarding node can communicate with the sending target.

[0078] Optionally, if the first forwarding node can communicate with the second virtual private cloud when the first forwarding node determines that the sending target of the data to be forwarded is the second virtual private cloud, the first forwarding node can directly send the data to be forwarded to the second virtual private cloud.

[0079] If the first forwarding node cannot communicate with the second virtual private cloud, the controller can determine a second forwarding node that can communicate with the second virtual private cloud from the forwarding network when it is determined that the first forwarding node cannot communicate with the second virtual private cloud, and configure a communication tunnel for the first forwarding node and the second forwarding node. For specific explanations, please refer to the following.

[0080] In another optional embodiment, when the sending target of the data to be forwarded cannot be determined, the controller can help determine the sending target, and new configuration information can also be issued to the first forwarding node.

[0081] Optionally, the first forwarding node can send preset information of the data to be forwarded to the controller, so that the controller determines the sending target of the data to be forwarded.

[0082] Regarding the preset information, the method flow is not specifically limited, as long as the controller can determine the sending target of the data to be forwarded according to the preset information, that is, the virtual private cloud to which the data needs to be sent.

[0083] Optionally, the preset information can include at least one of the following: quintuple information of the data to be forwarded, the data to be forwarded itself, transaction requirements of the data to be forwarded, cloud service information to which the data to be forwarded needs to be sent, and the like. For specific explanations of determining the sending target, please refer to the following.

[0084] S103: The controller determines that the sending target of the data to be forwarded is a second virtual private cloud connected by the forwarding network, and determines a second forwarding node that can communicate with the second virtual private cloud from the forwarding network when it is determined that the first forwarding node cannot communicate with the second virtual private cloud, and configures a communication tunnel for the first forwarding node and the second forwarding node.

[0085] The method flow does not limit the specific way in which the controller determines the sending target of the data to be forwarded.

[0086] Optionally, the controller can store a correspondence between preset information and virtual private clouds. Thus, the corresponding virtual private cloud can be determined as the sending target according to the received preset information.

[0087] Optionally, the controller can be deployed with several transaction logics for determining the sending target according to preset information of the data to be forwarded.

[0088] For example, the preset information can include cloud service information to which the data to be forwarded needs to be sent. The controller can store a correspondence between the cloud service information and the interfaced virtual private cloud. When the controller determines that the data to be forwarded needs to be sent to any cloud service, the controller can determine the virtual private cloud in which the cloud service is located as the sending target.

[0089] Optionally, the preset information can include quintuple information of the data to be forwarded. The controller can store a correspondence between the destination IP and the interfaced virtual private cloud. Therefore, the controller can determine the sending target of the data to be forwarded as the virtual private cloud corresponding to the destination IP in the quintuple information. Of course, the controller can also store a correspondence between the destination IP and the destination port and the interfaced virtual private cloud. The controller can determine the sending target of the data to be forwarded as the virtual private cloud corresponding to the destination IP and the destination port in the quintuple information.

[0090] Optionally, the preset information can include transaction demand in the data to be forwarded. The controller can store transactions implemented by the interfaced virtual private cloud, so as to determine the virtual private cloud for implementing the corresponding transaction according to the transaction demand in the preset information. Therefore, the controller can determine the sending target of the data to be forwarded as the virtual private cloud for implementing the transaction demand according to the transaction demand in the preset information. The transaction demand can specifically include cloud service information.

[0091] Optionally, the preset information can include a virtual private cloud identifier to which the data to be forwarded needs to be sent. The controller can store the virtual private cloud identifiers of the interfaced virtual private cloud. Therefore, the controller can determine the sending target of the data to be forwarded as the virtual private cloud corresponding to the virtual private cloud identifier in the preset information.

[0092] Optionally, the preset information can include the data to be forwarded. The controller can parse the data to be forwarded to obtain at least one of the following: cloud service information, transaction demand, quintuple information, and virtual private cloud identifier, and so on, so as to determine the sending target by using the above embodiments.

[0093] It should be noted that in an optional embodiment, in order to facilitate the controller to determine the sending target of the forwarded data, the controller can store relevant information of the interfaced virtual private cloud, so as to determine the sending target of the forwarded data by using the stored virtual private cloud relevant information.

[0094] Of course, optionally, the transaction logic deployed by the controller can perform permission judgment on the communication between the virtual private clouds.

[0095] Specifically, it can be determined whether the first virtual private cloud has the permission to communicate with the second virtual private cloud.

[0096] For example, the cloud service provided by the second virtual private cloud can be implemented for any virtual private cloud, and thus it can be directly determined that the first virtual private cloud has the permission to communicate with the second virtual private cloud. The second virtual private cloud and the first virtual private cloud are rented by the same user, and thus it can be determined that the first virtual private cloud has the permission to communicate with the second virtual private cloud.

[0097] Therefore, by the controller, the sending target of the data to be forwarded, that is, the second virtual private cloud to which the data to be forwarded needs to be sent, can be determined, and thus it can be determined that the second virtual private cloud needs to communicate.

[0098] In an optional embodiment, the controller can maintain a set of forwarding nodes capable of communication for each virtual private cloud connected thereto. Specifically, the forwarding nodes in the set can be regarded as members of equal routes, and thus any of the forwarding nodes can be used to communicate with the corresponding virtual private cloud.

[0099] Therefore, after determining that the data to be forwarded needs to be sent to the second virtual private cloud, the controller can determine the set of forwarding nodes capable of communication of the second virtual private cloud.

[0100] In an optional embodiment, since a single forwarding node can communicate with multiple virtual private clouds, the first forwarding node can communicate with the first virtual private cloud and the second virtual private cloud respectively. In this case, the corresponding configuration information can be directly issued by the controller, so that the first forwarding node can send the data to be forwarded to the second virtual private cloud, thereby realizing fast forwarding without configuring a communication tunnel.

[0101] Optionally, in the case where the first forwarding node is capable of communicating with the second virtual private cloud, the first forwarding node can send the data to be forwarded to the second virtual private cloud. Specifically, it can be determined by the controller or the first forwarding node itself whether it is capable of communicating with the second virtual private cloud.

[0102] In another optional embodiment, since the number of virtual private clouds capable of communication of a single forwarding node is limited, the first forwarding node generally cannot communicate with all the virtual private clouds connected to the forwarding network. Specifically, the number of virtual network cards capable of connection of the first forwarding node is limited.

[0103] Therefore, the first forwarding node can not be able to directly communicate with the second virtual private cloud determined by the controller. In this case, the controller can select other forwarding nodes capable of communicating with the second virtual private cloud, and configure a communication tunnel to realize communication between the forwarding nodes through the communication tunnel, so as to send the data to be forwarded to the second virtual private cloud.

[0104] The embodiment is not limited to the specific way of selecting the second forwarding node.

[0105] Optionally, the selecting the second forwarding node can include: selecting a forwarding node as the second forwarding node from the forwarding nodes capable of communicating with the second virtual private cloud based on a second preset selection policy. The second forwarding node can be selected by the controller from the forwarding nodes capable of communicating with the second virtual private cloud based on the second preset selection policy.

[0106] The embodiment is not limited to the specific second preset selection policy. Optionally, the selection can be random, or can be based on information of the data to be forwarded, and specifically, the number of forwarding nodes capable of communicating with the second virtual private cloud can be taken as a hash value range, and the information of the data to be forwarded can be hashed to determine a corresponding forwarding node.

[0107] For example, the data to be forwarded can be a packet, and the five-tuple information, or the source address information, or the destination address information, or the like of the packet to be forwarded can be hashed.

[0108] It should be noted that for the first forwarding node, the controller can regard each of the forwarding nodes capable of communicating with the second virtual private cloud as a next hop of an equal-cost route, and select based on an equal-cost route policy. Since these forwarding nodes can all communicate with the second virtual private cloud, whichever forwarding node is selected will not affect subsequent communication.

[0109] Therefore, by using the forwarding nodes capable of communicating with the second virtual private cloud in the distributed forwarding cluster, the availability and performance can be improved based on equal-cost routing, in the case of failure or inability to communicate of a certain forwarding node, other available forwarding nodes can be selected based on equal-cost routing for communication, and a load balancing policy can also be configured to improve availability and performance.

[0110] As for the communication tunnel, the method flow is not limited to a specific tunnel form and configuration manner.

[0111] Optionally, the communication tunnel can be a Virtual eXtensible Local Area Network (VXLAN) tunnel, a Segment Routing IPv6 (SRv6) tunnel based on an IPv6 forwarding plane, or a Generic Network Virtualization Encapsulation (GENEVE) tunnel.

[0112] Optionally, the configuration manner can be static configuration or dynamic configuration, specifically, tunnel configuration information can be respectively issued to the first forwarding node and the second forwarding node, and the first forwarding node and the second forwarding node can complete tunnel configuration by connecting and interacting information.

[0113] In the embodiment, communication is performed through the communication tunnel, and the complexity of the topology relationship between the forwarding nodes can be reduced.

[0114] In the embodiment, communication is performed through the communication tunnel, and the complexity of the topology relationship between the forwarding nodes can be reduced.

[0115] In the embodiment, communication is performed through the communication tunnel, and the complexity of the topology relationship between the forwarding nodes can be reduced.

[0116] Optionally, when the controller configures the communication tunnel, tunnel encapsulation information of the communication tunnel can be issued to the first forwarding node, so as to facilitate the first forwarding node to encapsulate the to-be-forwarded data.

[0117] Optionally, when the controller configures the communication tunnel, the analysis logic of the tunnel encapsulation information can be issued to the second forwarding node, so as to facilitate the second forwarding node to analyze the encapsulation result received from the communication tunnel.

[0118] Optionally, the second forwarding node cannot determine the sending target according to the configuration information for the encapsulation result received from the communication tunnel for the first time, and the encapsulation result can be sent to the controller for analysis.

[0119] The controller can issue the analysis operation to the second forwarding node as the configuration information, so that the second forwarding node can perform corresponding analysis operation on the data received from the communication tunnel.

[0120] Optionally, the analysis operation can include analyzing the sending target, that is, the information of the second virtual private cloud, from the encapsulation result. The information of the second virtual private cloud can be specifically an identifier of a virtual network card of the second virtual private cloud.

[0121] Optionally, the analysis operation can include decapsulating the encapsulation result, so as to obtain the to-be-forwarded data.

[0122] The configuration information can be specifically flow table information, which can be used to determine corresponding operation information for the data received from the communication tunnel, analyze the information of the second virtual private cloud from the data, and then the second forwarding node can forward the data to the second virtual private cloud, to realize the forwarding of the fast channel.

[0123] To facilitate the second forwarding node to parse, the encapsulation result can include various information of the data to be forwarded, for example, a source of the data to be forwarded, the first virtual private cloud; a sending target of the data to be forwarded, the second virtual private cloud; a sending direction of the data to be forwarded, and the like.

[0124] In an optional embodiment, the communication tunnel can be a generic network virtualization encapsulation (GENEVE) tunnel; in a tunnel encapsulation format of GENEVE, an extension option field of indefinite length is included, and the extension option field has good extensibility, facilitating encapsulation of information of the data to be forwarded in the extension option field and facilitating implementation of flexible extension.

[0125] Optionally, the encapsulation result can be a GENEVE packet, wherein the option field of the packet includes at least one of the following: the first virtual private cloud identifier, the second virtual private cloud identifier, transaction information, and a data sending direction.

[0126] In the embodiment, the form of the virtual private cloud identifier is not specifically limited, and the virtual private cloud identifier can be a virtual network card identifier of the virtual private cloud, for example.

[0127] In the embodiment, the content of the transaction information is not specifically limited, and the transaction information can include cookie information of a transaction, or can include a mapping relationship between the first virtual private cloud and the second virtual private cloud.

[0128] S105: The second forwarding node sends the data to be forwarded to the second virtual private cloud.

[0129] In an optional embodiment, the second forwarding node can have a communication connection with a virtual network card in the second virtual private cloud. The second forwarding node sending the data to be forwarded to the second virtual private cloud can include: the second forwarding node sending the data to be forwarded to the second virtual private cloud through the virtual network card in the second virtual private cloud.

[0130] In an optional embodiment, the second forwarding node can communicate with multiple virtual private clouds, and therefore, the second forwarding node needs to determine the second virtual private cloud to which the data to be forwarded is to be sent.

[0131] In the embodiment, the specific determination manner is not limited, and the second forwarding node can send data for which a sending target cannot be determined to a controller for parsing to determine the sending target. The controller can issue configuration information to the second forwarding node, and for data received by the communication tunnel, the second virtual private cloud information in the data can be parsed to determine that the data needs to be forwarded to the second virtual private cloud.

[0132] Optionally, the second forwarding node can determine, according to the second virtual private cloud identifier in the encapsulation result, that the data to be forwarded needs to be sent to the second virtual private cloud.

[0133] The second forwarding node sends the data to be forwarded to the second virtual private cloud, thereby realizing communication between the first virtual private cloud and the second virtual private cloud.

[0134] In an optional embodiment, the controller configures the communication tunnel for the first forwarding node and the second forwarding node, and the communication tunnel can be used to realize communication between the first virtual private cloud and the second virtual private cloud.

[0135] In an optional embodiment, the controller can issue configuration information to the first forwarding node, so that the first forwarding node can send other data having the same preset information as the data to be forwarded to the second forwarding node through the communication tunnel.

[0136] Specifically, the other data having the same five-tuple information as the data to be forwarded can be sent to the second forwarding node through the communication tunnel.

[0137] Optionally, the controller can issue configuration information to the second forwarding node, so that the second forwarding node can parse the encapsulated data received from the communication tunnel and send the parsing result to the second virtual private cloud.

[0138] In this embodiment, other data having the same preset information as the data to be forwarded, which is sent by the first virtual private cloud to the first forwarding node, can be sent to the second virtual private cloud through the communication tunnel, thereby realizing multiple utilization of the communication tunnel and multiple communication between the first virtual private cloud and the second virtual private cloud.

[0139] In an optional embodiment, the communication tunnel can be bidirectional, and the second virtual private cloud can send data to the first virtual private cloud by using the communication tunnel.

[0140] Correspondingly, optionally, the controller can issue tunnel encapsulation information to the second forwarding node and issue parsing logic of the tunnel encapsulation information to the first forwarding node, so that the second forwarding node can encapsulate data and the first forwarding node can parse the data encapsulated by the second forwarding node.

[0141] Optionally, the controller can issue configuration information to the second forwarding node, so that the second forwarding node can send data to be sent to the first virtual private cloud to the first forwarding node through the communication tunnel.

[0142] The controller can issue configuration information to the first forwarding node, so that the first forwarding node can parse the encapsulation result received from the communication tunnel and send the parsing result to the first virtual private cloud.

[0143] For specific explanations, refer to the above embodiments.

[0144] For ease of understanding, the embodiments of the present specification also provide a specific embodiment.

[0145] As Figure 2 shown, a principle schematic diagram of a network communication method provided by the embodiments of the present specification.

[0146] Among them, the forwarding network can be a Fabric network, which can include Fabric controllers and forwarding nodes 1-4. Among the forwarding nodes 1-4, each two forwarding nodes can communicate and have communication capabilities. Specifically, they can have the ability to establish connections with each other, which facilitates the establishment of GENEVE tunnel connections between different forwarding nodes.

[0147] The forwarding network can correspond to a user-side virtual private cloud and a cloud service virtual private cloud.

[0148] The user-side virtual private cloud can include a user-side interface (User Network Interface, UNI), which can be a virtual network card. The user-side interface can connect the forwarding node 1 and the forwarding node 2.

[0149] The cloud service virtual private cloud can include a network-side interface (Network to Network Interface, NNI), which can be a virtual network card. The network-side interface can connect the forwarding node 3 and the forwarding node 4.

[0150] Among them, the forwarding node 1 and the forwarding node 2 can be equal route members of the user-side virtual private cloud, and the forwarding node 3 and the forwarding node 4 can be equal route members of the cloud service virtual private cloud.

[0151] The Fabric controller can maintain the equal route members of each virtual private cloud.

[0152] The complete processing flow can include the following steps.

[0153] The traffic of the virtual machine instance in the user-side virtual private cloud can be sent to the forwarding node 1 through the UNI.

[0154] The forwarding node 1 cannot determine the sending target for the traffic and sends the traffic to the Fabric controller.

[0155] The Fabric controller can determine that the traffic needs to be sent to the cloud service virtual private cloud, so it can collect the topology information of the NNI, select the forwarding node 3 after equal routing for forwarding traffic, and configure the GENEVE tunnel for the forwarding node 1 and the forwarding node 3.

[0156] Specifically, the GENEVE encapsulation information can be informed to the forwarding node 1, and the GENEVE encapsulation information can include the identifier of the ingress UNI, the identifier of the egress NNI, the traffic direction, the transaction Cookie and the like.

[0157] The forwarding node 1 can obtain the GENEVE message based on the GENEVE encapsulation information and send the message to the forwarding node 3.

[0158] After receiving the GENEVE message, the forwarding node 3 can send the GENEVE message to the Fabric controller. The Fabric controller can parse the GENEVE message, determine that the traffic needs to be sent to the cloud service virtual private cloud, and can be encapsulated. Therefore, the Fabric controller can send the corresponding configuration information to the forwarding node 3.

[0159] Based on the configuration information, the forwarding node 3 can parse the GENEVE header, determine that the message needs to be sent to the cloud service virtual private cloud, and send the message to the NNI interface, so that it can be sent to the cloud service virtual private cloud.

[0160] As shown in Figure 3 , it is a format diagram of a GENEVE encapsulation message provided by an embodiment of the present specification.

[0161] As shown in Figure 3 , the specific format of the GENEVE message is shown in the figure, and the GENEVE Option Class=0x138 can be the GENEVE Option Class exclusive field applied for, and the Option can include the identification information of the UNI, the identification information of the NNI, the transaction Cookie information, the traffic direction Direction, the virtual private cloud mapping relationship XNI Mapping and the like, and can be flexibly extended.

[0162] The embodiment provides a forwarding topology management and information transmission technology based on the GENEVE encapsulation technology, and provides flexible and expandable technical support for the forwarding traffic between different VPC Bonding ENIs of the cloud network and different transactions.

[0163] The system mainly includes a Fabric topology controller running on a network function virtualization platform and a forwarding node for completing bottom-layer GENEVE encapsulation and decapsulation.

[0164] The Fabric controller can be responsible for topology management of virtual network cards, internal network interconnection, selection of equal-cost routing members in virtual network cards and GENEVE information assembly.

[0165] The forwarding node is responsible for GENEVE encapsulation and decapsulation and forwarding of traffic between different VPCs.

[0166] The system can improve ENI utilization, reduce transaction network element interface topology management complexity, and guarantee flexible expansion of various interface information in the complex large-scale multi-network element network function virtualization platform scenario, and meet network element transaction requirements.

[0167] The information carried in the encapsulation of GENEVE can meet the forwarding requirements between forwarding nodes and has flexible expansion properties. Compared with VXLAN and SRv6, the Option capability of multiple TLV (Type+Length+Value) encoding formats of GENEVE has strong expansion and can meet the requirements of transaction flexibility.

[0168] Corresponding to the method embodiments, the specification embodiments also provide a product embodiment.

[0169] As shown in Figure 4 , a structure diagram of a forwarding network provided by the specification embodiments. The forwarding network can include a controller and a plurality of forwarding nodes. Figure 4 The forwarding network includes four forwarding nodes, which are only used for illustrative purposes.

[0170] In an optional embodiment, a forwarding network includes a controller and a plurality of forwarding nodes; the forwarding network is connected to at least two virtual private clouds; for any virtual private cloud connected, at least one forwarding node in the forwarding network can communicate with the virtual private cloud.

[0171] Optionally, the first forwarding node in the forwarding network can communicate with the first virtual private cloud connected by the forwarding network.

[0172] The first forwarding node is configured to: receive the to-be-forwarded data sent by the first virtual private cloud; and send preset information of the to-be-forwarded data to the controller in a case where the sending target of the to-be-forwarded data cannot be determined.

[0173] The controller is configured to: determine, based on the received preset information, that the sending target of the to-be-forwarded data is a second virtual private cloud connected by the forwarding network, and in a case where the first forwarding node cannot communicate with the second virtual private cloud, determine a second forwarding node in the forwarding network that can communicate with the second virtual private cloud, and configure a communication tunnel for the first forwarding node and the second forwarding node.

[0174] The first forwarding node is configured to: send the to-be-forwarded data to the second forwarding node through the configured communication tunnel.

[0175] The second forwarding node is configured to: send the received to-be-forwarded data to the second virtual private cloud.

[0176] Optionally, the first forwarding node has a communication connection with the virtual network interface card (NIC) in the first virtual private cloud. The first forwarding node is used to: receive data to be forwarded from the first virtual private cloud via the virtual NIC connected to the forwarding network.

[0177] Optionally, the first forwarding node is selected by the first virtual private cloud from among the forwarding nodes that can communicate, based on a first preset selection strategy; the second forwarding node is selected by the controller from among the forwarding nodes that can communicate with the second virtual private cloud, based on a second preset selection strategy.

[0178] The first forwarding node is used to encapsulate the data to be forwarded using tunnel encapsulation information, and send the encapsulation result to the second forwarding node so that the second forwarding node can parse the encapsulation result and obtain the data to be forwarded.

[0179] Optionally, the communication tunnel is a general network virtualization encapsulated GENEVE tunnel; the encapsulation result is a GENEVE message, wherein the option field of the message includes at least one of the following: a first virtual private cloud identifier, a second virtual private cloud identifier, transaction information, and data transmission direction.

[0180] Optionally, the second forwarding node has a communication connection with the virtual network interface card in the second virtual private cloud; the second forwarding node is used to send the data to be forwarded to the second virtual private cloud through the virtual network interface card in the second virtual private cloud.

[0181] Optionally, the first forwarding node is further configured to: send the data to be forwarded to the second virtual private cloud if it is determined that the first forwarding node is capable of communicating with the second virtual private cloud.

[0182] For a detailed explanation, please refer to the above method implementation examples.

[0183] Corresponding to the above method embodiments, this specification also provides a system embodiment.

[0184] like Figure 5 The diagram shown is a structural schematic of a network communication system provided in an embodiment of this specification. The system may include the following devices.

[0185] The first forwarding node 401 is used to receive data to be forwarded from the first virtual private cloud; if the destination of the data to be forwarded cannot be determined, the preset information of the data to be forwarded is sent to the controller 402.

[0186] The controller 402 is configured to determine a second virtual private cloud to which the data to be forwarded is to be forwarded based on preset information, and configure a communication tunnel for the first forwarding node 401 and a second forwarding node 403 in a case where it is determined that the first forwarding node 401 cannot communicate with the second virtual private cloud; the second forwarding node 403 can communicate with the second virtual private cloud.

[0187] The first forwarding node 401 is configured to send the data to be forwarded to the second forwarding node 403 through the configured communication tunnel.

[0188] The second forwarding node 403 is configured to send the data to be forwarded to the second virtual private cloud.

[0189] Optionally, the first forwarding node 401 and a virtual network card in the first virtual private cloud can be in communication connection.

[0190] The first forwarding node 401 can be configured to receive the data to be forwarded of the first virtual private cloud through the virtual network card in the first virtual private cloud.

[0191] Optionally, the first forwarding node 401 is selected by the controller from the forwarding nodes capable of communication based on a first preset selection policy. The second forwarding node 403 can be selected by the controller from the forwarding nodes capable of communication with the second virtual private cloud based on a second preset selection policy.

[0192] The controller 402 can be configured to select one of the forwarding nodes capable of communication with the second virtual private cloud as the second forwarding node 403 based on the second preset selection policy.

[0193] Optionally, the first forwarding node 401 can be configured to encapsulate the data to be forwarded by using tunnel encapsulation information, and send the encapsulation result to the second forwarding node 403, so that the second forwarding node 403 parses the encapsulation result to obtain the data to be forwarded.

[0194] Optionally, the communication tunnel is a generic network virtualization encapsulation (GENEVE) tunnel; and the encapsulation result is a GENEVE message, wherein the message includes at least one of the following in an option field: a first virtual private cloud identifier, a second virtual private cloud identifier, transaction information, and a data sending direction.

[0195] Optionally, the second forwarding node 403 and a virtual network card in the second virtual private cloud are in communication connection; and the second forwarding node 403 can be configured to send the data to be forwarded to the second virtual private cloud through the virtual network card in the second virtual private cloud.

[0196] Optionally, the first forwarding node 401 is further configured to send the data to be forwarded to the second virtual private cloud if the controller 402 determines that the first forwarding node 401 is capable of communicating with the second virtual private cloud.

[0197] The above-mentioned method embodiments can be specifically explained as follows.

[0198] The embodiments of the present specification also provide a computer device, which at least includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps performed by the controller or the forwarding node in any of the above-mentioned method embodiments when executing the program.

[0199] Figure 6 A more specific hardware structure schematic diagram of a computer device provided by the embodiments of the present specification is shown, which can include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 for communication connection within the device.

[0200] The processor 1010 can be implemented in the form of a general-purpose CPU, a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute related programs to implement the technical solutions provided by the embodiments of the present specification.

[0201] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs, and when the technical solutions provided by the embodiments of the present specification are implemented by software or firmware, the related program codes are stored in the memory 1020 and executed by the processor 1010.

[0202] The input / output interface 1030 is used to connect input / output modules to realize information input and output. The input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. The input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0203] The communication interface 1040 is configured to connect a communication module (not shown in the figure) to realize the communication interaction between the device and other devices. The communication module can realize the communication through a wired manner (for example, a USB, a network cable, etc.) or a wireless manner (for example, a mobile network, WIFI, Bluetooth, etc.).

[0204] The bus 1050 includes a path for transmitting information between various components (for example, the processor 1010, the memory 1020, the input / output interface 1030 and the communication interface 1040) of the device.

[0205] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device can also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device can also only contain the components necessary for the implementation of the embodiments of the present specification, and does not have to contain all the components shown in the figure.

[0206] The embodiments of the present specification also provide a computer readable storage medium, which stores a computer program, and the program is executed by a processor to realize the steps performed by the controller or the forwarding node in any of the above method embodiments.

[0207] The computer readable medium includes permanent and non-permanent, removable and non-removable media, which can be realized by any method or technology to store information. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition in this paper, the computer readable medium does not include transitory computer readable media, such as modulated data signals and carriers.

[0208] Those skilled in the art can clearly understand the implementation of the embodiments of the present specification by the description of the above embodiments. Based on such understanding, the technical solutions of the embodiments of the present specification can be embodied in the form of a software product, which can be stored in a storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in various embodiments or some parts of the embodiments of the present specification.

[0209] The systems, devices, modules or units illustrated by the above embodiments can be specifically implemented by a computer chip or entity, or by a product with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an e-mail device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0210] Each of the embodiments of the present specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the device embodiments, since they are basically similar to the method embodiments, they are described more simply, and the relevant parts can be referred to the part of the description of the method embodiments. The device embodiments described above are only illustrative, and the modules described as separate components can or can not be physically separated, and the functions of each module can be implemented in one or more software and / or hardware when implementing the embodiments of the present specification. Part or all of the modules can be selected to achieve the purpose of the embodiments of the present specification according to the actual needs. Those skilled in the art can understand and implement without creative labor.

[0211] The above is only a specific implementation of the embodiments of the present specification, and it should be noted that those skilled in the art can make several improvements and refinements without departing from the principles of the embodiments of the present specification, and these improvements and refinements should be considered as the protection of the embodiments of the present specification.

Claims

1. A network communication method applied to a forwarding network, the forwarding network comprising a controller and a plurality of forwarding nodes; the forwarding network being connected to at least two virtual private clouds; for any connected virtual private cloud, there is at least one forwarding node in the forwarding network capable of communicating with the virtual private cloud; wherein, The forwarding network comprises a Fabric network, and the controller comprises a Fabric controller which parses the GENEVE packet and determines that the traffic needs to be sent to a cloud service virtual private cloud, and the method comprises: A first forwarding node in the forwarding network receives to-be-forwarded data sent by a first virtual private cloud to which the forwarding network is connected; In a case where a sending target of the to-be-forwarded data cannot be determined, the first forwarding node sends preset information of the to-be-forwarded data to the controller; The controller determines, based on the preset information, that the sending target of the to-be-forwarded data is a second virtual private cloud to which the forwarding network is connected, and in a case where the first forwarding node cannot communicate with the second virtual private cloud, determines a second forwarding node capable of communicating with the second virtual private cloud from the forwarding network, and configures a communication tunnel for the first forwarding node and the second forwarding node; The first forwarding node sends the to-be-forwarded data to the second forwarding node through the configured communication tunnel; wherein the first forwarding node encapsulates the to-be-forwarded data by using tunnel encapsulation information, and sends an encapsulation result to the second forwarding node, so that the second forwarding node parses the encapsulation result to obtain the to-be-forwarded data; the communication tunnel is a general network virtualization encapsulation (GENEVE) tunnel; and the encapsulation result is a GENEVE packet, and the option field of the packet contains at least one of the following: a first virtual private cloud identifier, a second virtual private cloud identifier, transaction information and a data sending direction; The second forwarding node sends the to-be-forwarded data to the second virtual private cloud.

2. The method of claim 1, wherein the first forwarding node and a virtual network card in the first virtual private cloud are communicatively connected; The first forwarding node receives to-be-forwarded data sent by a first virtual private cloud to which the forwarding network is connected, comprising: The first forwarding node receives, through a virtual network card in the first virtual private cloud to which the forwarding network is connected, to-be-forwarded data sent by the first virtual private cloud.

3. The method of claim 1, wherein the first forwarding node is selected by the first virtual private cloud from forwarding nodes capable of communication based on a first preset selection policy; and the second forwarding node is selected by the controller from forwarding nodes capable of communicating with the second virtual private cloud based on a second preset selection policy.

4. The method of claim 1, wherein the second forwarding node and a virtual network card in the second virtual private cloud are communicatively connected; The second forwarding node sends the to-be-forwarded data to the second virtual private cloud, comprising: The second forwarding node sends, through the virtual network card in the second virtual private cloud, the to-be-forwarded data to the second virtual private cloud.

5. The method of claim 1, further comprising: In a case where the first forwarding node is determined to be capable of communicating with the second virtual private cloud, the first forwarding node sends the to-be-forwarded data to the second virtual private cloud. ​ 6. A forwarding network comprising a controller and a number of forwarding nodes; the forwarding network being interfaced to at least two virtual private clouds; for any virtual private cloud that is interfaced, there is at least one forwarding node in the forwarding network that is able to communicate with that virtual private cloud; wherein, The forwarding network comprises a Fabric network, and the controller comprises a Fabric controller which parses the GENEVE packet and determines that the traffic needs to be sent to a cloud service virtual private cloud; The first forwarding node in the forwarding network is capable of communicating with a first virtual private cloud interfaced with the forwarding network; The first forwarding node is configured to receive to-be-forwarded data sent by the first virtual private cloud, and send preset information of the to-be-forwarded data to the controller in a case where a sending target of the to-be-forwarded data cannot be determined; The controller is configured to determine, based on the preset information, that the sending target of the to-be-forwarded data is a second virtual private cloud interfaced with the forwarding network, and determine, in a case where the first forwarding node is incapable of communicating with the second virtual private cloud, a second forwarding node capable of communicating with the second virtual private cloud from the forwarding network, and configure a communication tunnel for the first forwarding node and the second forwarding node; The first forwarding node is configured to send the to-be-forwarded data to the second forwarding node through the configured communication tunnel; wherein the first forwarding node is configured to encapsulate the to-be-forwarded data by using tunnel encapsulation information, and send an encapsulation result to the second forwarding node, so that the second forwarding node parses the encapsulation result to obtain the to-be-forwarded data; wherein the communication tunnel is a generic network virtualization encapsulation (GENEVE) tunnel, and the encapsulation result is a GENEVE packet, wherein the packet contains at least one of the following in an option field: a first virtual private cloud identifier, a second virtual private cloud identifier, transaction information, and a data sending direction; The second forwarding node is configured to send the to-be-forwarded data to the second virtual private cloud.

7. The forwarding network of claim 6, wherein the first forwarding node and a virtual network card in the first virtual private cloud are in communication connection; The first forwarding node is configured to receive to-be-forwarded data sent by the first virtual private cloud through a virtual network card in the first virtual private cloud interfaced with the forwarding network.

8. The forwarding network of claim 6, wherein the first forwarding node is selected by the first virtual private cloud from forwarding nodes capable of communication based on a first preset selection policy; The second forwarding node is selected by the controller from forwarding nodes capable of communicating with the second virtual private cloud based on a second preset selection policy.

9. The forwarding network of claim 6, wherein the second forwarding node and a virtual network card in the second virtual private cloud are in communication connection; The second forwarding node is configured to send the to-be-forwarded data to the second virtual private cloud through the virtual network card in the second virtual private cloud.

10. The forwarding network of claim 6, wherein the first forwarding node is further configured to send the to-be-forwarded data to the second virtual private cloud in a case where the first forwarding node is capable of communicating with the second virtual private cloud.

Citation Information

Patent Citations

  • Data processing method, system and node

    CN107306215A

  • Multi-cloud connectivity using srv6 and bgp

    CN112470436A