Network communication system and network communication method

By deploying multi-mode links and dynamic routing mechanisms in the public cloud network, the problem of poor performance of IPsec VPN tunnel networks has been solved, achieving high availability and stable network interconnection.

CN116248439BActive Publication Date: 2025-12-23NETEASE (HANGZHOU) NETWORK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310251154.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-08
Publication Date
2025-12-23
Estimated Expiration
2043-03-08

AI Technical Summary

Technical Problem

Existing public cloud deployment solutions suffer from poor IPsec VPN tunnel network performance, affecting the reliability of network interconnection, and lack effective high availability measures and dynamic route learning mechanisms.

Method used

By deploying multiple virtual private network gateways on the first network side, and using AGA-VPN links that combine Anycast technology and IPsec VPN with EIP-VPN links, multi-form links are built. Route-based mode is used to dynamically exchange routing information with BGP sessions. Combined with AS Path routing strategy, high availability and interoperability are achieved using AWS TGW.

Benefits of technology

It improves the high availability of network services, reduces latency and packet loss rate, optimizes network performance, and enables dynamic route learning and efficient traffic transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248439B_ABST
    Figure CN116248439B_ABST
Patent Text Reader

Abstract

The application provides a network communication system and a network communication method, comprising: a first network side and a second network side, the first network side and the second network side being connected through a multi-form link; wherein the first network side is provided with a plurality of virtual private network gateways; the virtual private network gateway is used for transmitting the traffic of the first network side to the second network side through a target link currently used in the multi-form link; the second network side is provided with a virtual private network connection, a relay gateway and a virtual network device, the virtual private network connection is bound with the relay gateway, and the relay gateway is mounted with at least one virtual network device; the virtual private network connection is used for transmitting the traffic to the relay gateway, and the relay gateway is used for distributing the traffic to the virtual network device. The application can effectively improve the problem of poor network performance of the IPsec VPN tunnel in the existing public cloud deployment scheme.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and in particular to a network communication system and a network communication method. BACKGROUND

[0002] At present, more and more users choose to use public clouds to deploy businesses due to the flexibility and convenience of public clouds. The existing public cloud deployment scheme is mainly to build IPsec VPN tunnels based on the existing functions of the public cloud platform (such as the AWS (Amazon Web Services) platform). However, the existing public cloud deployment scheme has the problem of poor network performance of IPsec VPN tunnels, which affects the reliability of network interconnection. SUMMARY

[0003] Therefore, the present application aims to provide a network communication system and a network communication method, which can effectively improve the problem of poor network performance of IPsec VPN tunnels in the existing public cloud deployment scheme.

[0004] In a first aspect, the embodiments of the present application provide a network communication system, comprising: a first network side and a second network side, the first network side and the second network side being connected through multi-form links; wherein the first network side is deployed with a plurality of virtual private network gateways; the virtual private network gateway is used to transmit traffic of the first network side to the second network side through a target link currently used in the multi-form links; the second network side is deployed with a virtual private network connection, a transit gateway and a virtual network device, the virtual private network connection is bound with the transit gateway, and the transit gateway is mounted with at least one virtual network device; the virtual private network connection is used to transmit the traffic to the transit gateway, and the transit gateway is used to distribute the traffic to the virtual network device.

[0005] In a second aspect, the embodiments of the present application further provide a network communication method, which is applied to the network communication system of any one of claims 1-9, and the method comprises: transmitting, by a virtual private network gateway deployed inside a first network side, traffic of the first network side to a second network side through a target link currently used in multi-form links; transmitting, by a virtual private network connection deployed inside the second network side, the traffic to a transit gateway deployed inside the second network side; and distributing, by the transit gateway, the traffic to a virtual network device deployed inside the second network side.

[0006] The network communication system and the network communication method provided by the embodiment of the present application comprise: a first network side and a second network side, and the first network side and the second network side are connected through a multi-form link. The first network side is provided with a plurality of virtual private network gateways, and the virtual private network gateway is used to transmit the traffic of the first network side to the second network side through a target link currently used in the multi-form link. The second network side is provided with a virtual private network connection, a relay gateway and a virtual network device, the virtual private network connection is bound with the relay gateway, and the relay gateway is mounted with at least one virtual network device; the virtual private network connection is used to transmit the traffic to the relay gateway, and the relay gateway is used to distribute the traffic to the virtual network device. The network communication system can guarantee the high availability of the network service level in the traffic transmission process through the multi-virtual private network gateway multi-form link, thereby effectively improving the problem of poor network performance of the IPsec VPN tunnel in the existing public cloud deployment scheme.

[0007] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application will be realized and achieved by the structure particularly pointed out in the description, claims and drawings.

[0008] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the following preferred embodiments are specifically described, and the accompanying drawings are described in detail as follows. BRIEF DESCRIPTION OF DRAWINGS

[0009] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the following will briefly introduce the drawings needed to be used in the specific embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0010] Figure 1 A traditional network communication architecture diagram is provided for the embodiment of the present application.

[0011] Figure 2 A structural schematic diagram of a network communication system is provided for the embodiment of the present application.

[0012] Figure 3 Another structural schematic diagram of a network communication system is provided for the embodiment of the present application.

[0013] Figure 4 A principle schematic diagram of an Anycast technology is provided for the embodiment of the present application.

[0014] Figure 5A structural diagram of a virtual private network gateway provided by the embodiment of the present application is provided;

[0015] Figure 6 A flowchart of a process of building an IPsec VPN tunnel provided by the embodiment of the present application is provided;

[0016] Figure 7 An architecture diagram of an IPsec VPN tunnel provided by the embodiment of the present application is provided;

[0017] Figure 8 A BGP routing diagram provided by the embodiment of the present application is provided;

[0018] Figure 9 A diagram of a master / standby mode in Keepalived provided by the embodiment of the present application is provided;

[0019] Figure 10 A structural diagram of a second network side provided by the embodiment of the present application is provided;

[0020] Figure 11 Another structural diagram of a second network side provided by the embodiment of the present application is provided;

[0021] Figure 12 A flowchart of a network communication method provided by the embodiment of the present application is provided. DETAILED DESCRIPTION

[0022] In order to make the purpose, technical scheme and advantages of the embodiments of the present application more clear, the technical scheme of the present application will be described clearly and completely in combination with embodiments. Obviously, the described embodiments are a part of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.

[0023] Currently, more and more users choose to use public clouds to deploy businesses due to the flexibility and convenience of public clouds, and AWS, as the leader in the public cloud industry, is favored by most users. Businesses can purchase and deploy on demand based on their actual needs. Among them, AWS is used to provide on-demand cloud computing platforms and APIs (Application Program Interface) for individuals, enterprises and governments, and is charged according to usage. In addition, for areas not covered by AWS, businesses will choose to use other cloud vendors to deploy resources to provide better client network access quality, forming a multi-cloud vendor mixed deployment scenario. Based on this background, the following two problems are raised: (1) In order to facilitate resource management and data communication, many users need to connect the local physical machine room intranet network to the VPC (Virtual Private Cloud) intranet network on AWS under the condition of ensuring data transmission security. VPC is a virtual network defined by a public cloud, which is very similar to the traditional network running in the data center. In VPC, you can allocate a network segment and create virtual machines in it. (2) The VPC network forms of different public cloud vendors are not the same, and how to realize the interconnection and data encrypted transmission between these networks and AWS is another problem to be solved.

[0024] AWS provides multiple ways to connect external networks and AWS VPC networks: (1) Physical private line: By building a physical private line between AWS and the local physical machine room, network interconnection is realized. The physical private line network has higher performance, but has many limitations. For example, special physical location fiber access is required for building a private line, and the construction cost is high, the construction period is long, and the flexibility and timeliness are insufficient, which cannot meet the small flow agile business scenario. (2) Site-to-Site VPN (IPsec VPN): Establish an encrypted tunnel based on Internet network to connect two different geographical location networks by building a VPN (Virtual Private Network). The advantage of this way is that the construction period is short and the deployment is more flexible. But the disadvantage is that it is built based on Internet network, and if not specially optimized, the network performance stability of Site-to-Site VPN is relatively poor. (3) Client VPN: Client devices connect to the internal network on demand, but this method is only for user / device level, not network level, so it has no reference value for the above needs.

[0025] Reference Figure 1A traditional network communication architecture diagram is shown, the main architecture and process are as follows: (1) the main deployment process on the AWS side is as follows: (1.1) create VPC, bear the business needs of virtual machine, VPN gateway and other resources; (1.2) create VGW (Virtual Private Gateway) gateway, bind it to VPC, wherein, VGW is the VPN concentrator provided by AWS for connecting Site-to-Site VPN connection on the Amazon side; (1.3) create VPN connection, used to bear the VPN gateway on the AWS side, and the opposite VPN gateway (also known as Figure 1 Customer Gateway) to establish a VPN tunnel. (2) On the VPN gateway side, use Openswan, Libreswan or StrongSwan software to realize the operation of Policy-based IPsec VPN service, and establish an encrypted tunnel with the VPN connection device on the AWS side. In addition, the VPC network segment on the AWS side needs to be filled in the configuration, which is used to hit the target network segment through the policy to forward to the IPsec tunnel.

[0026] Based on the above architecture, although the basic network connectivity can be realized, there are many problems in actual business use:

[0027] (1) Because it uses Internet public network as the underlying network, the network robustness is insufficient, and it is greatly affected by public network fluctuations, and the anti-interference and network performance are poor, there are problems such as delay, high packet loss rate, unstable transmission, etc.

[0028] (2) Since it is realized by Policy-based mode IPsec, it cannot use dynamic routing protocol to dynamically learn the opposite routing, but only relies on manual configuration, and the maintenance cost is high.

[0029] (3) Lack of effective high availability measures, the existing scheme is basically a single machine used as a VPN gateway, connected to a single VPN connection on the AWS side, such architecture is easy to cause network unavailable when single point failure, and there is no standby link to switch. Moreover, even if a dual gateway is used for master and backup, it is basically based on machine-level fault switching, and most of the faults are link / service level, that is, the VPN gateway is in a running state, but the VPN service itself appears abnormal, causing link failure. The existing scheme cannot cover this kind of fault scenario.

[0030] (4) The implementation of the existing scheme lacks support for multiple vendors and different hardware environments, and cannot meet the deployment needs of multiple hardware environments such as public cloud virtual machines, physical machines and private clouds.

[0031] Based on this, the present application provides a network communication system and a network communication method, which can effectively improve the poor network performance of the IPsec VPN tunnel in the existing public cloud deployment scheme.

[0032] To facilitate the understanding of the present embodiment, first, a network communication system disclosed by the present embodiment is introduced in detail.

[0033] Figure 2 The structure of a network communication system is shown, which includes a first network side 1 and a second network side 2. The first network side 1 can be a third-party public cloud or a physical machine room side, and the second network side 2 can be an AWS side. The first network side 1 and the second network side 2 are connected by a multi-form link. The multi-form link can be a link built by using different network addressing and routing strategies, and the number of each link can be multiple. Optionally, the multi-form link includes an AGA (AWS Global Accelerator)-VPN link and an EIP (Elastic IP addresses)-VPN link. The AGA-VPN link is a link obtained by combining Anycast technology and IPsec VPN, which can be used to optimize the network quality of the link, thereby improving the poor network performance of the IPsec VPN tunnel in the existing technology.

[0034] In an embodiment, the first network side 1 has multiple virtual private network gateways 3, referred to as VPN CGW (VPN CGW). The virtual private network gateway 3 is used to transmit the traffic of the first network side to the second network side through the target link currently used in the multi-form link. Optionally, the priority of the AGA-VPN link is higher than that of the EIP-VPN link, so the AGA-VPN link can be used as the target link by default to perform network interconnection through the AGA-VPN link and transmit the traffic of the first network side to the second network side.

[0035] In an embodiment, the second network side deploys a virtual private network connection 4, a transit gateway 5 and a virtual network device 6. The virtual private network connection 4 is bound to the transit gateway 5, and the transit gateway 5 is mounted with at least one virtual network device 6; the virtual private network connection 4 is used to transmit traffic to the transit gateway 5, and the transit gateway 5 is used to distribute traffic to the virtual network device 6. Among them, the virtual private network connection 4, that is, VPN Connection, is an access device used to implement IPsec VPN on the second network side, mainly responsible for establishing an IPsec VPN tunnel with the VPN gateway on the first network side; the transit gateway 5, that is, TGW (Transit Gateway), is a network transit center, and the embodiment of the application connects the VPN Connection to the TGW to realize the interconnection between the virtual private network connection 4 and the virtual network device 6, and simplifies the link form; the virtual network device 6, that is, VPC.

[0036] The network communication system provided by the embodiment of the application can guarantee the high availability of network service level in the traffic transmission process through the multi-form link of the multi-virtual private network gateway, thereby effectively improving the poor network performance of the IPsec VPN tunnel in the existing public cloud deployment scheme.

[0037] In order to facilitate the understanding of the above-mentioned embodiments, the embodiment of the application provides a specific structure of a network communication system, referring to Figure 3 the structure diagram of another network communication system, as shown in the figure, a plurality of VPN gateways (that is, VPN CGW) are deployed on the first network side, and a plurality of VPN Connections are deployed on the second network side, and a multi-form link is built between the VPN gateway and the VPN Connection, the multi-form link includes an AGA-VPN link and an EIP-VPN link, and the number of the AGA-VPN link and the EIP-VPN link is multiple. Among them, the AGA-VPN link is also Figure 3 VPN Connection-AGA-VPN gateway link, and the EIP-VPN link is also Figure 3 VPN Connection-VPN gateway link. In actual application, the advantage of the AGA-VPN link is that the Anycast IP and the traffic enter the cloud backbone network from the cloud edge node, which theoretically shortens the public network distance of the virtual tunnel and maximally utilizes the reliable backbone network; the EIP-VPN link is a link built by using the international public network, and the reason why the embodiment of the application adds the EIP-VPN link as a backup line on the basis of the AGA-VPN link is that the AGA-VPN link is not the best or may fail in some extreme cases. In order to avoid single link failure, therefore, the embodiment of the application uses the AGA+EIP architecture scheme.

[0038] For the AGA-VPN link described above, the AGA-VPN link is a link built by combining the Anycast technology and the IPsec VPN. The Anycast technology is a network addressing and routing strategy, which enables network data packets to be sent to the "closest" or "best" destination according to the routing topology. In the Anycast technology, there is a one-to-many relationship between network addresses and network nodes, such as Figure 4 Fig. 1 shows a schematic diagram of the principle of an Anycast technology, in which the white dots are receiving nodes, and the black dots correspond to addresses, each address corresponds to a group of receiving nodes, but at any given time, only one of them can receive information from the sending end. In the embodiment of the present application, the AGA (full name AWS Global Accelerator) service is selected on the AWS to implement the Anycast technology, so as to reduce the delay and packet loss rate between two public IP (Internet Protocol) and improve the stability.

[0039] In an optional embodiment, the priority of the AGA-VPN link is higher than that of the EIP-VPN link. In actual application, the traffic from the first network side is introduced to the two Keepalived VPN gateways through a Virtual-IP address. By default, the Virtual-IP is directed to the VPN gateway where the AGA-VPN link is located, and when the AGA-VPN link is abnormal, the Virtual-IP is directed to the VPN gateway where the EIP-VPN link is located. Each VPN gateway and TGW establishes two IPsec VPN tunnels for traffic load, and a total of four tunnels are used for double gateways, which are encrypted using the IKEv2 algorithm.

[0040] The embodiment of the present application combines the Anycast technology and the IPsec VPN, and on the basis of optimizing the network quality of the link, uses AGA+EIP to build a double-gateway multi-form link to ensure the high availability of the network service level.

[0041] Please continue to see Figure 3The first network side internally deployed VPN gateway provided by the embodiment of the application is configured with Keepalived, the Keepalived is configured with a link monitoring script (namely, a VRRP_Script script), the link monitoring script is used to monitor whether the target link is abnormal, and when it is monitored that the target link is abnormal, a standby link to be switched is selected from the other links except the target link in the multi-form link, and the virtual private network gateway is controlled to switch from the target link to the standby link. In actual application, the embodiment of the application adopts the architecture of AGA+EIP primary and standby VPN gateway accessing the TGW of the AWS side as a whole, and the traffic is set to preferentially pass through the AGA accelerated VPN link (namely, the AGA-VPN link mentioned above), and the AGA is used to optimize the best path and reduce the link delay and packet loss rate. The VRRP_Script script of the Keepalived on the VPN gateway automatically detects the link state, and when the AGA-VPN link is abnormal, the Keepalived automatically performs switching to the EIP-VPN link.

[0042] In an optional embodiment, the AGA-VPN link and the EIP-VPN link are both based on IPsec VPN tunnels and Border Gateway Protocol sessions (referred to as BGP (Border Gateway Protocol) sessions) to dynamically exchange routing information. Please continue to refer to Figure 3 The embodiment of the application takes four IPsec VPN tunnels as an example, establishes a BGP session between the VPN gateway and the TGW of the AWS side, so that both sides can dynamically learn the routes of each other, and ensure the exchange at the routing layer.

[0043] Among them, the IPsec VPN tunnel is a VPN technology that uses the IPsec protocol to realize remote access. IPsec is an Internet Protocol Security defined by the Internet Engineering Task Force (IETF) as a security standard framework, which provides a secure communication channel between two private networks on the public network, and ensures the security of the connection through the encrypted channel. BGP is a core decentralized autonomous routing protocol on the Internet.

[0044] Among them, the main function of the BGP system is to exchange network reachable information with other BGP systems, and the network reachable information includes the information of the listed autonomous system (AS). These information effectively constructs the topology of AS interconnection and eliminates the routing loop, and at the same time, the policy decision can be implemented at the AS level.

[0045] In an embodiment, the VPN gateways corresponding to the AGA-VPN link and the EIP-VPN link both need to dynamically exchange routing information with the TGW through an IPsec VPN tunnel and a BGP session, and a combination of Strongswan+Quagga+Keepalived is adopted on the VPN gateway to achieve this purpose. Among them, Strongswan is a tunnel building tool, Quagga is a session establishment tool.

[0046] For ease of understanding, referring to Figure 5 a structural diagram of a virtual private network gateway, the virtual private network gateway is further configured with a tunnel building tool (Strongswan), a session establishment tool (Quagga), and Keepalived. Figure 5 On the basis, the embodiment of the present application provides a whole working process of the VPN gateway: (1) first, the Strongswan on the two VPN gateways is responsible for establishing the IPsec VPN tunnel with the VPN Connection on the AWS side, and the underlying data transmission link is opened; (2) the Quagga on the VPN gateway establishes the BGP neighbor relationship with the TGW on the AWS side based on the IPsec VPN tunnel, and when the BGP state is Established, the neighbor relationship is established, at this time, the two sides will exchange and learn the routes published by each other; (3) when a certain network segment is added or deleted on the AWS side, the TGW will notify the VPN gateway through the BGP UPDATE message, and the Quagga adjusts the learned BGP route and the system route table on the VPN gateway based on the message; (4) Keepalived is responsible for high availability between the two VPN gateways, adopts a master-backup mode based on Virtual-IP, the Virtual IP is bound to the AGA-VPN gateway by default, and then the business machine route or VPC route is directed to this Virtual-IP, so as to ensure that all the traffic accessing the AWS side is preferentially AGA-VPN link. When Keepalived detects that the AGA-VPN link is abnormal, it will automatically switch to the standby EIP-VPN link.

[0047] For ease of understanding, referring to

[0048] The tunnel building tool is used to sequentially perform a tunnel control channel establishment operation, a data stream encryption channel establishment operation, and a Strongswan Updown script triggering operation to build an IPsec VPN tunnel. The Strongswan Updown script is used to at least create a virtual interface. In actual application, Strongswan is used to build an IPsec VPN tunnel and a Route-based VPN tunnel. Referring to FIG. 1, which is a flowchart of building an IPsec VPN tunnel according to an embodiment of the present application, the Strongswan on the primary and standby VPN gateways is set to perform the tunnel control channel establishment operation, the data stream encryption channel establishment operation, and the Strongswan Updown script triggering operation according to the flowchart shown in FIG. 2. Figure 6 The Strongswan on the primary and standby VPN gateways is set to perform the tunnel control channel establishment operation, the data stream encryption channel establishment operation, and the Strongswan Updown script triggering operation according to the flowchart shown in FIG. 2. Figure 6 The Strongswan on the primary and standby VPN gateways is set to perform the tunnel control channel establishment operation, the data stream encryption channel establishment operation, and the Strongswan Updown script triggering operation according to the flowchart shown in FIG. 2. Figure 7 FIG. 3 is an architecture diagram of an IPsec VPN tunnel according to an embodiment of the present application. Specifically, refer to the following steps a to c.

[0049] Step a, phase one establishes an IKE SA (i.e., a control channel), which is responsible for the establishment and maintenance of an IPsec SA and plays a control role.

[0050] Step b, phase two establishes an IPsec SA (i.e., a data stream encryption channel), which is responsible for specific data stream encryption.

[0051] Step c, the Strongswan Updown script is set to automatically create a VTI (Virtual Tunnel Interface) virtual interface and automatically configure Sysctl kernel parameters. The VTI virtual interface is the basis for implementing a Route-Based VPN, and Quagga uses the VTI virtual interface to establish a BGP session with AWS; the Sysctl kernel parameters can include rp_filter, disable_policy, ip_forward, and disable_xfrm.

[0052] (ii) The session establishment tool is used to take the address of the virtual interface as the source address, and to establish a border gateway protocol session between the first network side and the second network side based on the source address; wherein the border gateway protocol session is configured with an AS Path routing strategy. In actual application, Quagga is used for the creation and maintenance of the BGP session, and the TGW and the Quagga exchange routing information with each other. After the IPsec VPN tunnel is completed by Strongswan, the Quagga establishes a BGP neighbor relationship with the TGW on the AWS side by using the VTI virtual interface as the source address. In order to realize ECMP (Equal-Cost Multi-path Routing), the maximum-paths parameter is set for the BGP to support double-tunnel traffic load. Wherein, the ECMP is a primary routing weight calculation routing strategy generated when multiple optimal paths are parallel. Generally, the ECMP is used when multi-link load needs to be done. After the neighbor relationship is established, the BGP on both sides can dynamically learn the route of the other side, and the Quagga automatically registers the learned BGP route to the system routing table for subsequent data forwarding. When a certain network segment is added or deleted on the AWS side, the TGW notifies the VPN gateway through the BGP UPDATE message, and the Quagga adjusts the learned BGP route and the system routing table on the VPN gateway based on the message.

[0053] Referring to Figure 8 A BGP route diagram is shown. Under normal circumstances, if nothing is set, the priority of the BGP learned and published route on the four tunnels is the same, because the routing attributes of the BGP route are the same, which will cause the traffic initiated from the AWS side to access the third-party public cloud to simultaneously pass through the AGA-VPN link and the EIP-VPN link, resulting in unstable network performance such as delay and packet loss. In order to realize that the AGA-VPN link is preferred when the AWS side accesses the third-party cloud / physical room side, the AS Path attribute of the BGP route is adjusted in the embodiment of the application, and the route-map is used to match the BGP route published and accepted on the VPN gateway to which the EIP-VPN link belongs, and an additional AS number is set (set as-path prepend) to increase the AS Path length of the EIP VPN link. According to the routing principle of BGP, the longer AS Path route has lower priority, thereby realizing that the AGA VPN link is preferentially passed through.

[0054] In the embodiment of the application, the Route-based mode is adopted in the IPsec VPN tunnel implementation, the dynamic learning and transmission of the route are realized by using the BGP session, and the AS Path routing strategy is combined to ensure the consistency of the route level back-and-forth path.

[0055] (Three) Keepalived adopts a master-slave mode based on Virtual-IP, such as Figure 9 Fig. 1 shows a schematic diagram of a master-slave mode in Keepalived, giving a higher priority to the VPN gateway (referred to as master VPN gateway) to which the AGA-VPN link belongs, that is, the priority of the VPN gateway to which the AGA-VPN link belongs is higher than the priority of the VPN gateway (referred to as standby VPN gateway) to which the EIP VPN link belongs, so that the Virtual IP is bound to the gateway to which the AGA-VPN link belongs by default. At the same time, the business machine route or VPC route is directed to this Virtual-IP, ensuring that all traffic accessing AWS is preferentially routed through the AGA-VPN link.

[0056] In addition, in order to ensure link high availability, the VRRP_Script function is used to detect the IPsec VPN tunnel and BGP session state of the master and standby VPN gateways. When one of the IPsec VPN tunnel and BGP session states is detected to be abnormal, the system automatically switches to the standby gateway within seconds. When the master link state returns to normal, it will automatically switch back to the master VPN gateway, without the need for manual intervention to ensure continuous availability of the link in the event of a failure.

[0057] Please continue to refer to Figure 3 , Figure 3 It is shown that the number of transit gateways is multiple, each transit gateway belongs to a different region, and the transit gateways in different regions are connected through peer-to-peer connection (TGW Peering) to realize cross-region interconnection. For example, as shown in Figure 10 Fig. 2 shows a structure diagram of a second network side, each TGW can connect multiple VPCs. Further, each business VPC on the AWS side is bound to a TGW. Figure 10 VPN gateway, that is, the VPN gateway described above, the 10.99.99.0 / 24 of the VPN gateway corresponds to the network segment accessed by the third-party cloud through the VPN gateway. The embodiment of the application realizes the interconnection of the third-party cloud network and the VPC network on the AWS side through the TGW. Please continue to refer to Figure 3 , Figure 3 It is also shown that the VPN connection is connected only with one TGW (a), and then the TGW (a) is connected with the next TGW (b), wherein the TGW (a) and the TGW (b) belong to different regions. In actual application, by setting the VPNConnection and TGW binding, the traffic from the third-party public cloud / physical machine room reaches the TGW through the VPN Connection, and then the TGW distributes the traffic to the VPC in the same region or across regions.

[0058] For cross-region access requirements, it is necessary to create a TGW Peering connection, pass through the TGWs between different regions, and point the route to the corresponding TGW Peering, so that the traffic from the VPN gateway can be accessed across regions through the TGW Peering to the corresponding VPC. For ease of understanding, refer to another second network side structure diagram shown in Figure 11 In an embodiment, based on geographical location and network quality, the most reasonable AWS region for accessing the third-party cloud / physical machine room can be selected; a TGW gateway is created in the selected region, and in order to realize multi-VPN tunnel traffic load, both ends of the VPN tunnel need to support ECMP, and the maximum-paths of BGP is set on the VPN gateway side of the third-party cloud to support this feature, and the ECMP function needs to be enabled for the TGW on the AWS side to realize it.

[0059] In an embodiment, at least two VPNs are created, and each transit gateway is mounted with at least a first virtual network device (first VPN for short) and a second virtual network device (second VPN for short), the first VPN and the second VPN correspond to the AGA-VPN link and the EIP-VPN link respectively, that is, the first VPN enables the AGA acceleration function (to support the Anycast technology) to support the AGA-VPN link, and the second VPN supports the EIP-VPN link.

[0060] The embodiment of the present application needs to solve the problems of poor performance of IPsec VPN network, lack of effective service level high availability switching measures, and inability to realize dynamic learning at the routing level under the prior art. Based on this, the embodiment of the present application proposes a new implementation scheme of interworking between a third-party public cloud or a local network through IPsec VPN and AWS VPC network. The embodiment of the present application combines Anycast technology and IPsec VPN, optimizes the network quality of the link, and at the same time uses AGA+EIP to build a double-gateway multi-form link to ensure the high availability of network services. In the implementation of IPsec VPN, the Route-based mode is adopted, the dynamic learning and transmission of routes are realized by using BGP, and the AS Path routing strategy is combined to ensure the consistency of the routes at the routing level. Finally, the interworking between VPN and AWS VPC is realized by using AWS TGW. In addition, the embodiment of the present application adds an Anycast link on the IPsec VPN network architecture, the traffic from the third-party cloud vendor enters the backbone network of AWS through the edge node of AWS, which theoretically shortens the public network distance of the virtual tunnel, maximally utilizes the reliable backbone network, reduces the delay and packet loss rate, and improves the transmission stability.

[0061] In summary, the embodiment of the present application has at least the following characteristics:

[0062] (1) Link high availability: using AGA+EIP to access the AWS TGW architecture of the primary and standby VPN, four tunnels of double gateway are redundant, and when a link failure is detected, the standby node can be switched to within seconds.

[0063] (2) High-quality link: using the Anycast edge network access point of AWS, the tunnel is composed of the AWS backbone network and the short-distance public network, which is less affected by public network fluctuations, reduces the delay and packet loss rate, and the theoretical bandwidth upper limit can reach 1.25*2Gbps.

[0064] (3) Dynamic routing: using Route-based VPN, exchanging route information dynamically through BGP on the IPsec tunnel, avoiding manual configuration, and using BGP AS Path routing strategy to optimize the path and ensure the consistency of the routes at the routing level.

[0065] (4) Clear and easy-to-maintain link: using AWS TGW as the core convergence layer, the link is clear.

[0066] For the network communication system provided by the foregoing embodiment, the embodiment of the present application provides a network communication method, which is applied to the network communication system provided by the foregoing embodiment, and refers to a flow diagram of a network communication method shown in Figure 12 The method mainly includes the following steps S1202 to S1206.

[0067] In step S1202, the traffic of the first network side is transmitted to the second network side through the target link currently used in the multi-form link by using the virtual private network gateway deployed inside the first network side.

[0068] In step S1204, the traffic is transmitted to the transit gateway deployed inside the second network side by using the virtual private network connection deployed inside the second network side.

[0069] In step S1206, the transit gateway is used to distribute the traffic to the virtual network device deployed inside the second network side.

[0070] The network communication method provided by the embodiment of the present application is applied to the network communication system provided by the foregoing embodiment, and by building the multi-form link of the multi-virtual private network gateway, the high availability of the network service level can be ensured in the traffic transmission process, thereby effectively improving the problem of poor network performance of the IPsec VPN tunnel in the existing public cloud deployment scheme.

[0071] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the network communication method described above can refer to the corresponding process in the foregoing embodiment, which will not be described here.

[0072] In the description of the embodiments of the present application, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connecting" should be understood in a broad sense, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium; it can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0073] In the description of the present application, it should be noted that the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, therefore it cannot be understood as a limitation on the present application. In addition, the terms "first", "second", "third" are only for the purpose of description, and cannot be understood as indicating or implying relative importance.

[0074] Finally, it should be noted that the above-described embodiments are merely specific embodiments of the present application, which are used to illustrate the technical solutions of the present application, but not to limit the same. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that any person skilled in the art can still modify or easily think of changes to the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some of the technical features, within the technical scope disclosed by the present application. The modifications, changes or replacements do not cause the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A network communication system, characterized in that, include: A first network side and a second network side, connected via a multi-mode link; wherein... The first network side is equipped with multiple virtual private network gateways; the virtual private network gateways are used to transmit traffic from the first network side to the second network side through the target link currently in use among the multi-mode links; The second network side is equipped with a virtual private network connection, a relay gateway, and virtual network devices. The virtual private network connection is bound to the relay gateway, and the relay gateway is connected to at least one of the virtual network devices. The virtual private network connection is used to transmit the traffic to the relay gateway, and the relay gateway is used to distribute the traffic to the virtual network devices. The multi-form links include AGA-VPN links and EIP-VPN links, and there are multiple AGA-VPN links and multiple EIP-VPN links; Both the AGA-VPN link and the EIP-VPN link are based on IPsec VPN tunnels and border gateway protocol sessions to dynamically exchange routing information. The virtual private network gateway is configured with a link monitoring script; The link monitoring script is used to monitor whether the target link is abnormal, and when the target link is detected to be abnormal, it selects a backup link to be switched from the other links in the multi-form links other than the target link, and controls the virtual private network gateway to switch from the target link to the backup link; wherein, the target link is the AGA-VPN link, and the backup link is the EIP-VPN link.

2. The network communication system according to claim 1, characterized in that, The AGA-VPN link has a higher priority than the EIP-VPN link.

3. The network communication system according to claim 2, characterized in that, The virtual private network gateway is also equipped with tunnel building tools; The tunnel building tool is used to sequentially execute the tunnel control channel establishment operation, the data stream encryption channel establishment operation, and the Strongswan Updown script trigger operation to build an IPsec VPN tunnel; wherein, the Strongswan Updown script is used to create at least a virtual interface.

4. The network communication system according to claim 3, characterized in that, The virtual private network gateway is also configured with session establishment tools; The session establishment tool is used to take the address of the virtual interface as the source address and establish a border gateway protocol session between the first network side and the second network side based on the source address; wherein, the border gateway protocol session is configured with an AS Path routing policy.

5. The network communication system according to claim 1, characterized in that, There are multiple relay gateways, each belonging to a different region, and the relay gateways in different regions achieve cross-regional interconnection through peer-to-peer connections.

6. The network communication system according to claim 5, characterized in that, Each of the relay gateways is equipped with at least a first virtual network device and a second virtual network device; wherein the first virtual network device is used to support AGA-VPN links, and the second virtual network device supports EIP-VPN links.

7. A network communication method, characterized in that, The method is applied to the network communication system according to any one of claims 1-6, and the method includes: Using the virtual private network gateway deployed within the first network side, traffic from the first network side is transmitted to the second network side through the target link currently in use among the multi-mode links; The traffic is transmitted to a relay gateway deployed within the second network side using a virtual private network connection deployed within the second network side. The relay gateway is used to distribute the traffic to virtual network devices deployed within the second network side; The virtual private network gateway is configured with a link monitoring script; Using the link monitoring script configured in the virtual private network gateway, the target link is monitored for abnormality. When the target link is detected to be abnormal, a backup link to be switched is selected from the other links in the multi-form links besides the target link, and the virtual private network gateway is controlled to switch from the target link to the backup link. The target link is an AGA-VPN link, and the backup link is an EIP-VPN link.

Citation Information

Patent Citations

  • VPN construction method and apparatus, and computer-readable storage medium

    CN109274570A

  • Cloud-to-cloud communication method and device, and storage medium

    CN114726780A