A method and device for cross-SD-WAN converged deployment of data centers

Through the plug-in modules in the orchestration system, configuration information is automatically generated and distributed, solving the automation problem of cross-data center and SD-WAN network convergence deployment, and achieving efficient business interconnection and secure SLA guarantees.

CN116319296BActive Publication Date: 2025-10-03NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310295145.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-22
Publication Date
2025-10-03
Estimated Expiration
2043-03-22

AI Technical Summary

Technical Problem

In existing technologies, the integrated deployment of cross-data center and SD-WAN networks cannot be automated, resulting in long service deployment time, complex administrator operations, and security risks.

Method used

Through the plug-in modules in the orchestration system, it connects to the data center DC controller and SD-WAN controller respectively to generate and distribute configuration information, realize the automated deployment of edge devices and site devices, ensure the consistency of interface addresses, VLAN and VPN configurations, and match routing protocols, and support the automated deployment and SLA guarantee of cross-scenario services.

Benefits of technology

It achieves automated connectivity between data centers and SD-WAN sites, simplifies administrator operations, improves security, and ensures efficient interconnection and SLA guarantees for cross-scenario services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319296B_ABST
    Figure CN116319296B_ABST
Patent Text Reader

Abstract

The present application relates to the field of network communication technology, and in particular to a method and apparatus for cross-SD-WAN converged deployment of a data center. The method comprises: determining, based on a selection instruction triggered by a user, an edge device of a target data center to be deployed and a site device in an SD-WAN directly connected to the edge device; generating a first configuration of the edge device and a second configuration of the site device, wherein the first configuration includes an identifier and related configurations of the edge device, and the second configuration includes an identifier and related configurations of the site device; sending the first configuration to the DC controller via the first plug-in, so that the DC controller deploys the edge device based on the first configuration; and sending the second configuration to the SD-WAN controller via the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network communication technology, and in particular to a method and apparatus for cross-SD-WAN converged deployment of a data center. Background Art

[0002] SD-WAN (Software-Defined Wide Area Network) is mainly used to connect enterprise networks, data centers and cloud services with wide geographical distribution and many branches, helping enterprises reduce WAN costs and improve network connection flexibility.

[0003] Currently, a corporate headquarters, branches, data centers, and cloud environments together form an enterprise private network. Centrally managed by an SD-WAN controller, it enables automated interconnection between organizations, automated service deployment, and flexible resource scheduling. Internet links or MPLS dedicated lines can be requested based on business needs, providing differentiated SLAs for access to different services. Enterprises typically deploy their mission-critical applications in their own data centers. For reliability and security, they typically build active-active or disaster recovery data centers, synchronizing and backing up services across multiple data centers. Branch and headquarters users also access data center services. In this scenario, the SD-WAN network, acting as the bearer network for data center services, provides interoperability and isolation for data center tenant services. Intelligent routing optimizes the inter-data center access experience.

[0004] More and more enterprises are looking to automatically connect data center egresses with the LAN side of SD-WAN sites when deploying cross-data center tenant services. This reduces deployment time and simplifies administrator operations. Therefore, how to automatically connect data centers across SD-WAN converged deployments has become a pressing issue. Summary of the Invention

[0005] The present application provides a method and apparatus for cross-SD-WAN converged deployment of data centers.

[0006] In a first aspect, the present application provides a method for cross-SD-WAN converged deployment of a data center, which is applied to an orchestration system, wherein the orchestration system includes a first plug-in for interfacing with a data center DC controller and a second plug-in for interfacing with an SD-WAN controller; the method includes:

[0007] Determine, based on a user-triggered selection instruction, an edge device of a target data center to be deployed and a site device in the SD-WAN directly connected to the edge device;

[0008] Generate a first configuration of the edge device and generate a second configuration of the site device, wherein the first configuration includes an identifier and related configurations of the edge device, and the second configuration includes an identifier and related configurations of the site device;

[0009] Sending the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration;

[0010] The second configuration is sent to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

[0011] Optionally, the relevant configuration of the edge device includes an interconnection address of a first interface on the edge device interconnected with the site device, VLAN and VPN configurations on the first interface for different tenant networks, and routing protocol selection for the first interface;

[0012] The relevant configurations of the site device include the interconnection address of the second interface on the site device that is interconnected with the edge device, VLAN and VPN configurations on the second interface for different tenant networks, and routing protocol selection for the second interface.

[0013] Optionally, the interconnection addresses of the first interface and the second interface belong to the same network segment, the VLAN and VPN configurations on the first interface and the second interface for different tenant networks are the same, and the routing protocol selections of the first interface and the second interface are the same.

[0014] Optionally, the method further includes:

[0015] Generate application groups corresponding to each tenant network and application control policies corresponding to each application group based on user-triggered configuration operations;

[0016] Sending the association relationship between each tenant network and its corresponding application group to the DC controller through the first plug-in, so that the DC controller forwards the association relationship between each tenant network and its corresponding application group to the edge device;

[0017] The association relationship between each application group and its corresponding application policy is sent to the SD-WAN controller through the second plug-in, so that the SD-WAN controller forwards the association relationship between each application group and its corresponding application policy to the edge device.

[0018] In a second aspect, the present application provides a device for cross-SD-WAN converged deployment of a data center, which is applied to an orchestration system, wherein the orchestration system includes a first plug-in for interfacing with a data center DC controller and a second plug-in for interfacing with an SD-WAN controller; the device includes:

[0019] A determination unit, configured to determine, based on a selection instruction triggered by a user, an edge device of a target data center to be deployed and a site device in the SD-WAN directly connected to the edge device;

[0020] a generating unit, configured to generate a first configuration of the edge device and a second configuration of the site device, wherein the first configuration includes an identifier and related configurations of the edge device, and the second configuration includes an identifier and related configurations of the site device;

[0021] a sending unit, configured to send the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration;

[0022] The sending unit is further configured to send the second configuration to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

[0023] Optionally, the relevant configuration of the edge device includes an interconnection address of a first interface on the edge device interconnected with the site device, VLAN and VPN configurations on the first interface for different tenant networks, and routing protocol selection for the first interface;

[0024] The relevant configurations of the site device include the interconnection address of the second interface on the site device that is interconnected with the edge device, VLAN and VPN configurations on the second interface for different tenant networks, and routing protocol selection for the second interface.

[0025] Optionally, the interconnection addresses of the first interface and the second interface belong to the same network segment, the VLAN and VPN configurations on the first interface and the second interface for different tenant networks are the same, and the routing protocol selections of the first interface and the second interface are the same.

[0026] Optionally, the generating unit is further configured to generate an application group corresponding to each tenant network and an application control policy corresponding to each application group based on a configuration operation triggered by a user;

[0027] The sending unit is further configured to send the association relationship between each tenant network and its corresponding application group to the DC controller through the first plug-in, so that the DC controller forwards the association relationship between each tenant network and its corresponding application group to the edge device;

[0028] The sending unit is also used to send the association relationship between each application group and its corresponding application policy to the SD-WAN controller through the second plug-in, so that the SD-WAN controller forwards the association relationship between each application group and its corresponding application policy to the edge device.

[0029] In a third aspect, an embodiment of the present application provides a cross-SD-WAN converged deployment data center device, the cross-SD-WAN converged deployment data center device comprising:

[0030] a memory for storing program instructions;

[0031] The processor is configured to call the program instructions stored in the memory and execute the steps of the method as described in any one of the first aspects above according to the obtained program instructions.

[0032] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the above-mentioned first aspects.

[0033] In summary, the method for cross-SD-WAN converged deployment of a data center provided in an embodiment of the present application is applied to an orchestration system, the orchestration system including a first plug-in for docking with a data center DC controller and a second plug-in for docking with an SD-WAN controller; the method including: based on a user-triggered selection instruction, determining the edge device of the target data center to be deployed and the site device in the SD-WAN directly connected to the edge device; generating a first configuration of the edge device and a second configuration of the site device, the first configuration including an identifier and related configuration of the edge device, the second configuration including an identifier and related configuration of the site device; sending the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration; sending the second configuration to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

[0034] The method for cross-SD-WAN converged data center deployment provided in the embodiments of this application enables automatic deployment of cross-SD-WAN services in the data center through the upper-layer orchestration module. This eliminates the need to couple the SD-WAN controller deployed on the public network with the DC controller deployed on the enterprise private network, preventing interaction between the two and improving the security of the enterprise private network. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments of the present application or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings of the embodiments of the present application.

[0036] Figure 1 A schematic diagram of a cross-scenario networking architecture provided in an embodiment of the present application;

[0037] Figure 2 A detailed flowchart of a method for cross-SD-WAN converged deployment of data centers provided in an embodiment of the present application;

[0038] Figure 3 A schematic diagram of a cross-scenario SLA guarantee business model provided in an embodiment of the present application;

[0039] Figure 4 A schematic diagram of the structure of an apparatus for cross-SD-WAN converged deployment of a data center provided in an embodiment of the present application;

[0040] Figure 5 A schematic diagram of the hardware architecture of an apparatus for integrating and deploying data centers across SD-WANs, as provided in an embodiment of the present application. DETAILED DESCRIPTION

[0041] The terms used in the embodiments of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. The singular forms "a," "the," and "the" used in this application and claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more associated listed items.

[0042] It should be understood that although the terms first, second, third, etc. may be used to describe various information in the embodiments of the present application, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" used may also be interpreted as "at the time of" or "when" or "in response to determining".

[0043] Currently, when enterprises deploy data center services, they perform automated operations through controllers for their respective scenarios. For example, they deploy tenant VPCs, subnets, terminal access, and external network access services on the DC controller, and deploy sites, WAN-side interconnection, LAN-side interconnection, application groups, and other services on the SD-WAN controller.

[0044] However, when it comes to cross-scenario business integration, for example, the interconnection configuration between the data center egress border device and the SD-WAN site device requires administrators to plan and configure them separately, and cannot be automated.

[0045] More and more enterprises hope to automatically connect the LAN side between the data center egress and the SD-WAN site when deploying data center tenant services across SD-WAN, saving service deployment time and simplifying administrator operations. At the same time, enterprises also hope to ensure SLA guarantees within the SD-WAN network when tenant services between data centers communicate with each other. In related technologies, in order to facilitate the integrated deployment of data center services across SD-WAN, a DC controller is used as the main controller, integrated with the SD-WAN controller, and the SD-WAN controller interface is called through the DC controller. This controller cooperates with the SD-WAN controller to achieve automated service deployment and SLA guarantees across scenarios.

[0046] In practice, DC controllers are typically deployed within the data center's internal management network (private network), while SD-WAN controllers are typically deployed on the public network. Direct interaction between the two poses a security risk to the data center and may not meet enterprise security requirements in some scenarios. The DC controller needs to connect to the SD-WAN controller to obtain SD-WAN-related services. These two domain controllers in different scenarios are highly coupled, and in some scenarios, coupling between the two controllers is not permitted.

[0047] For example, see Figure 1As shown, this is a schematic diagram of a cross-scenario networking architecture provided by an embodiment of the present application. Data Center 1 (data center 1) needs to communicate with Data Center 2 (data center 2) through SD-WAN Fabric networking. Data Center 1 and Data Center 2 are deployed in the enterprise intranet. Data Center 1 and Data Center 2 communicate across the SD-WAN network. Data Center 1 and Data Center 2 are deployed with their own DC controllers (DC controllers in the enterprise intranet). The SD-WAN Controller (SD-WAN controller in the public network) is deployed in the SD-WAN Fabric networking. In an embodiment of the present application, the DC controller and the SD-WAN controller are connected through the orchestration layer (upper-layer orchestration module, orchestration system). Specifically, the controllers can be connected by adding information such as controller address, port, account and password. Multiple data centers need to be connected to multiple DC controllers.

[0048] After connecting to each scene controller, you can use the upper-layer orchestration module to perform cross-scene business orchestration and realize the automatic deployment of interconnected parts. For example, see Figure 2 FIG2 is a detailed flow chart of a method for cross-SD-WAN converged deployment of a data center provided by an embodiment of the present application. The method is applied to an orchestration system, wherein the orchestration system includes a first plug-in for interfacing with a data center DC controller and a second plug-in for interfacing with an SD-WAN controller. The method includes the following steps:

[0049] Step 200: Based on the selection instruction triggered by the user, determine the edge device of the target data center to be deployed and the site device in the SD-WAN directly connected to the edge device.

[0050] In actual applications, users (administrators) can configure border devices (edge ​​devices) in the data center to be connected to site devices (site devices) in the SD-WAN network, as well as site devices in the SD-WAN network to connect to border devices in the data center.

[0051] For example, combined with Figure 1As shown, Site 1 of SD-WAN Fabric is used to connect to the Border device of Data Center 1, and Site 2 of SD-WAN Fabric is used to connect to the Border device of Data Center 2. Then, the user can select the Border device of the data center to be configured this time, and the Site of the SD-WAN network directly connected to the Border device (for example, Border and Site 1 of Data Center 1, or Border and Site 2 of Data Center 2).

[0052] Step 210: Generate a first configuration of the edge device and a second configuration of the site device, wherein the first configuration includes the identifier and related configuration of the edge device, and the second configuration includes the identifier and related configuration of the site device.

[0053] In an embodiment of the present application, the relevant configuration of the boundary device includes the interconnection address of the first interface on the boundary device that is interconnected with the site device, the VLAN and VPN configuration on the first interface for different tenant networks, and the routing protocol selection of the first interface; the relevant configuration of the site device includes the interconnection address of the second interface on the site device that is interconnected with the boundary device, the VLAN and VPN configuration on the second interface for different tenant networks, and the routing protocol selection of the second interface.

[0054] Furthermore, the interconnection addresses of the first interface and the second interface belong to the same network segment, the VLAN and VPN configurations on the first interface and the second interface for different tenant networks are the same, and the routing protocol selections of the first interface and the second interface are the same.

[0055] That is to say, the upper-layer orchestration system plans the data center egress network configuration (network configuration of border devices), including egress gateway selection (border selection, such as border1), egress interconnection address (port address (Layer 3 port) connected to site1 on border1) and VLAN allocation (virtualization, tenant network 1, interface + VLAN 1 + VPN 1, tenant network 2, interface + VLAN 1 + VPN 2), egress routing protocol selection (optional protocol 1, protocol 2), etc., and jointly plans the LAN side configuration of the corresponding SD-WAN site device (the configuration of site1 connected to border1), keeping it consistent with the data center egress gateway side, for example: the VPN is consistent with the egress gateway extranet VPN, the routing protocol configuration corresponds, the interconnection address belongs to the same network segment, the VLAN is consistent, etc.

[0056] For example, let's configure the Border device (egress gateway) of Data Center 1 and Site 1 of the SD-WAN Fabric. Assume that Interface A of the Border device of Data Center 1 is directly connected (physically connected) to Interface B of Site 1 of the SD-WAN Fabric. For Interface A, the corresponding configuration is:

[0057] Configure the IP address for interface A, such as IP 1; assign VLANs, such as VLAN 1. (If there are multiple tenant networks, you can virtualize interfaces and configure VPNs for different tenant networks. For example, Tenant Network 1: Interface A + VLAN 1 + VPN 1; Tenant Network 2: Interface A + VLAN 1 + VPN 2; Tenant Network 3: Interface A + VLAN 1 + VPN 3; ...); Select the routing protocol for interface A, such as OSPF.

[0058] For interface B, the corresponding configuration is generated as follows:

[0059] Configure the IP address for interface B, such as IP 2 (belonging to the same network segment as IP 1); assign VLANs, such as VLAN 1 (if there are multiple tenant networks, you can virtualize interfaces and configure VPNs for different tenant networks. For example, tenant network 1: interface B + VLAN 1 + VPN 1; tenant network 2: interface B + VLAN 1 + VPN 2; tenant network 3: interface B + VLAN 1 + VPN 3, etc.); select the routing protocol for interface B, such as OSPF (the same routing protocol as interface A).

[0060] Step 220: Send the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration.

[0061] Specifically, the orchestration system may include a pre-developed DC Controller plug-in (first plug-in) for connecting to the DC controller, that is, the orchestration system can communicate with the docked DC controller through the first plug-in and issue configuration instructions; it may also include a pre-developed SD-WAN Controller plug-in (second plug-in) for connecting to the SD-WAN controller, that is, the orchestration system can communicate with the docked SD-WAN controller through the second plug-in and issue configuration instructions.

[0062] In an embodiment of the present application, the orchestration system sends the first configuration generated for configuring and deploying the Border device of DataCenter 1 to the DC controller of Data Center 1 to which the Border device belongs based on the Border device identifier. After receiving the first configuration, the DC controller determines the Border device to be configured, and then sends the first configuration to the Border device to complete the configuration deployment.

[0063] Step 230: Send the second configuration to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

[0064] In an embodiment of the present application, the orchestration system sends the generated second configuration for configuring and deploying the Site device in the SD-WAN Fabric to the SD-WAN controller of the SD-WAN Fabric. After receiving the first configuration, the SD-WAN controller determines the Site device to be configured based on the Site device identifier, and then sends the first configuration to the Site device to complete the configuration deployment.

[0065] At this point, the path between Data Center 1 and the SD-WAN Fabric is established. Similarly, based on the above method, the path between Data Center 2 and the SD-WAN Fabric can be established, thus enabling cross-SD-WAN communication between Data Center 1 and Data Center 2.

[0066] Furthermore, in the embodiment of the present application, the above method may further include the following steps:

[0067] Based on the configuration operation triggered by the user, an application group corresponding to each tenant network and an application control policy corresponding to each application group are generated; the association relationship between each tenant network and its corresponding application group is sent to the DC controller through the first plug-in, so that the DC controller forwards the association relationship between each tenant network and its corresponding application group to the edge device; the association relationship between each application group and its corresponding application policy is sent to the SD-WAN controller through the second plug-in, so that the SD-WAN controller forwards the association relationship between each application group and its corresponding application policy to the edge device.

[0068] In other words, the upper-layer orchestration module can also provide cross-scenario SLA guarantees for various businesses.

[0069] The following describes in detail the cross-scenario SLA guarantee business model provided by the embodiment of the present application in conjunction with specific application scenarios. Figure 3 The figure shows a schematic diagram of a cross-scenario SLA guarantee business model provided in an embodiment of the present application.

[0070] Specifically, the upper-layer orchestration module configures the SD-WAN application group and application policy (e.g., Tenant 1, DSCP1; Policy 1; Tenant 2, DSCP2, Policy 2), specifies the network scope and application SLA policy for the application group, and specifies the corresponding DSCP (Differentiated Services Code Point) value in the policy. The application group is then delivered to the SD-WAN Controller, which configures the application group on the corresponding site devices. This means the site devices maintain the relationship between the DSCP value and the forwarding policy. The upper-layer orchestration module selects the data center tenant VPC, binds the VPC to the SD-WAN application group, and identifies the tenant VPC that uses the application policy. The upper-layer orchestration module binds the VPC to the corresponding DSCP value and delivers it to the corresponding DC Controller. The DC Controller delivers the configuration to the VPC egress device, Border, setting the corresponding DSCP value for the VPC traffic. This means the Border maintains the relationship between the tenant and DSCP values. The SD-WAN Controller intelligently selects routes for traffic matching the DSCP value on the corresponding site devices to ensure the SLA for the VPC traffic in the SD-WAN network.

[0071] For cross-SD-WAN access between different tenant VPCs, different external networks can be created, corresponding to the site LAN side VPN, to achieve cross-SD-WAN service isolation between tenant VPCs.

[0072] For example, see Figure 4 FIG2 is a schematic diagram of a structure of a device for cross-SD-WAN converged deployment of a data center provided by an embodiment of the present application. The device is applied to an orchestration system. The orchestration system includes a first plug-in for interfacing with a data center DC controller and a second plug-in for interfacing with an SD-WAN controller. The device includes:

[0073] A determining unit 40 is configured to determine, based on a selection instruction triggered by a user, an edge device of a target data center to be deployed and a site device in the SD-WAN directly connected to the edge device;

[0074] a generating unit 41, configured to generate a first configuration of the edge device and a second configuration of the site device, wherein the first configuration includes an identifier and related configurations of the edge device, and the second configuration includes an identifier and related configurations of the site device;

[0075] a sending unit 42, configured to send the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration;

[0076] The sending unit 42 is further configured to send the second configuration to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

[0077] Optionally, the relevant configuration of the edge device includes an interconnection address of a first interface on the edge device interconnected with the site device, VLAN and VPN configurations on the first interface for different tenant networks, and routing protocol selection for the first interface;

[0078] The relevant configurations of the site device include the interconnection address of the second interface on the site device that is interconnected with the edge device, VLAN and VPN configurations on the second interface for different tenant networks, and routing protocol selection for the second interface.

[0079] Optionally, the interconnection addresses of the first interface and the second interface belong to the same network segment, the VLAN and VPN configurations on the first interface and the second interface for different tenant networks are the same, and the routing protocol selections of the first interface and the second interface are the same.

[0080] Optionally, the generating unit 41 is further configured to generate an application group corresponding to each tenant network and an application control policy corresponding to each application group based on a configuration operation triggered by a user;

[0081] The sending unit 42 is further configured to send the association relationship between each tenant network and its corresponding application group to the DC controller through the first plug-in, so that the DC controller forwards the association relationship between each tenant network and its corresponding application group to the edge device;

[0082] The sending unit 42 is also used to send the association relationship between each application group and its corresponding application policy to the SD-WAN controller through the second plug-in, so that the SD-WAN controller forwards the association relationship between each application group and its corresponding application policy to the edge device.

[0083] The above units may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASICs), one or more digital singnal processors (DSPs), or one or more field programmable gate arrays (FPGAs). For another example, when a unit is implemented by scheduling program code through a processing element, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0084] Furthermore, the embodiment of the present application provides a device for cross-SD-WAN integrated deployment of a data center. From a hardware perspective, the hardware architecture diagram of the device for cross-SD-WAN integrated deployment of a data center can be found in Figure 5 As shown, the device for cross-SD-WAN converged deployment of data centers may include: a memory 50 and a processor 51,

[0085] The memory 50 is used to store program instructions. The processor 51 calls the program instructions stored in the memory 50 and executes the above method embodiment according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.

[0086] Optionally, the present application also provides a device for deploying a data center across SD-WAN convergence, comprising at least one processing element (or chip) for executing the above method embodiments.

[0087] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above method embodiments.

[0088] Here, the machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as CD, DVD, etc.), or similar storage media, or a combination thereof.

[0089] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or any combination of these devices.

[0090] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0091] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0092] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0093] Furthermore, these computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0094] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0095] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A method for cross-SD-WAN converged deployment of data centers, characterized in that: Applied to an orchestration system, the orchestration system includes a first plug-in for interfacing with a data center (DC) controller and a second plug-in for interfacing with an SD-WAN controller; the method includes: Determine, based on a user-triggered selection instruction, an edge device of a target data center to be deployed and a site device in the SD-WAN directly connected to the edge device; Generate a first configuration of the edge device and generate a second configuration of the site device, wherein the first configuration includes an identifier and related configurations of the edge device, and the second configuration includes an identifier and related configurations of the site device; Sending the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration; The second configuration is sent to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

2. The method according to claim 1, wherein The relevant configuration of the edge device includes the interconnection address of the first interface on the edge device that is interconnected with the site device, VLAN and VPN configuration on the first interface for different tenant networks, and routing protocol selection for the first interface; The relevant configurations of the site device include the interconnection address of the second interface on the site device that is interconnected with the edge device, VLAN and VPN configurations on the second interface for different tenant networks, and routing protocol selection for the second interface.

3. The method according to claim 2, wherein The interconnection addresses of the first interface and the second interface belong to the same network segment, the VLAN and VPN configurations on the first interface and the second interface for different tenant networks are the same, and the same routing protocol is selected for the first interface and the second interface.

4. The method according to any one of claims 1 to 3, wherein The method further comprises: Generate application groups corresponding to each tenant network and application control policies corresponding to each application group based on user-triggered configuration operations; Sending the association relationship between each tenant network and its corresponding application group to the DC controller through the first plug-in, so that the DC controller forwards the association relationship between each tenant network and its corresponding application group to the edge device; The association relationship between each application group and its corresponding application policy is sent to the SD-WAN controller through the second plug-in, so that the SD-WAN controller forwards the association relationship between each application group and its corresponding application policy to the edge device.

5. A device for cross-SD-WAN converged deployment of data centers, characterized in that: Applied to an orchestration system, the orchestration system includes a first plug-in for interfacing with a data center DC controller and a second plug-in for interfacing with an SD-WAN controller; the device includes: A determination unit, configured to determine, based on a selection instruction triggered by a user, an edge device of a target data center to be deployed and a site device in the SD-WAN directly connected to the edge device; a generating unit, configured to generate a first configuration of the edge device and a second configuration of the site device, wherein the first configuration includes an identifier and related configurations of the edge device, and the second configuration includes an identifier and related configurations of the site device; a sending unit, configured to send the first configuration to the DC controller through the first plug-in, so that the DC controller deploys the edge device based on the first configuration; The sending unit is further configured to send the second configuration to the SD-WAN controller through the second plug-in, so that the SD-WAN controller deploys the site device based on the second configuration.

6. The device according to claim 5, characterized in that The relevant configuration of the edge device includes the interconnection address of the first interface on the edge device that is interconnected with the site device, VLAN and VPN configuration on the first interface for different tenant networks, and routing protocol selection for the first interface; The relevant configurations of the site device include the interconnection address of the second interface on the site device that is interconnected with the edge device, VLAN and VPN configurations on the second interface for different tenant networks, and routing protocol selection for the second interface.

7. The device according to claim 6, characterized in that The interconnection addresses of the first interface and the second interface belong to the same network segment, the VLAN and VPN configurations on the first interface and the second interface for different tenant networks are the same, and the same routing protocol is selected for the first interface and the second interface.

8. The device according to any one of claims 5 to 7, characterized in that The generating unit is further configured to generate, based on the configuration operation triggered by the user, an application group corresponding to each tenant network and an application control policy corresponding to each application group; The sending unit is further configured to send the association relationship between each tenant network and its corresponding application group to the DC controller through the first plug-in, so that the DC controller forwards the association relationship between each tenant network and its corresponding application group to the edge device; The sending unit is also used to send the association relationship between each application group and its corresponding application policy to the SD-WAN controller through the second plug-in, so that the SD-WAN controller forwards the association relationship between each application group and its corresponding application policy to the edge device.

9. A cross-SD-WAN converged deployment data center device, characterized in that: The cross-SD-WAN converged deployment data center device includes: a memory for storing program instructions; A processor is configured to call the program instructions stored in the memory and execute the steps of the method according to any one of claims 1 to 4 according to the obtained program instructions.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of any one of the methods in claims 1 to 4.

Citation Information

Patent Citations

  • SD-WAN service orchestration method, system and device and storage medium

    CN112994915A

  • Routing meshes for facilitating routing through an SD-WAN

    US11381499B1