Automatic connection to cloud resources

By configuring VXC and BGP parameters in SDWAN, the connection between the local site and the virtual network in the cloud environment is automatically connected, solving the connection management challenges caused by the complexity of enterprise networks and improving connection stability and uptime.

CN116325668BActive Publication Date: 2026-05-15CISCO TECHNOLOGY INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CISCO TECHNOLOGY INC
Filing Date
2022-04-05
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

The increasing diversity and complexity of enterprise networks present network administrators with connectivity management challenges, resulting in low stability and low uptime, making it difficult to achieve efficient and accurate connectivity assurance.

Method used

By configuring Virtual Cross-Connect (VXC) and Border Gateway Protocol (BGP) parameters in Software Defined Wide Area Network (SDWAN), on-premises sites are automatically associated with virtual networks in the cloud environment, enabling dynamic connectivity by tagging and mapping virtual networks.

Benefits of technology

It reduces the workload of network administrators, improves connection stability and uptime, maintains service level agreements, and achieves efficient cloud resource connectivity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116325668B_ABST
    Figure CN116325668B_ABST
Patent Text Reader

Abstract

The present technology relates to receiving a tag that associates at least one routing domain in an on-premise site with at least one virtual network in a cloud environment, the cloud environment being associated with a cloud service provider. The present technology also relates to automating the populating of routing tables and the propagation of tables with the cloud service provider.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims the benefit and priority of U.S. non-provisional patent application No. 17 / 390,239, filed April 8, 2021, which claims the benefit and priority of U.S. provisional patent application No. 63 / 172,450, filed April 8, 2021, entitled “Automated Workload Mapping of Cloud IaaS and Cloud Partner Interconnect,” each of which is incorporated herein by reference in its entirety. Technical Field

[0003] This technology generally relates to the field of computer networking, and more specifically, to methods, systems, and non-transitory computer-readable storage media for automatically connecting to cloud resources. Background Technology

[0004] Enterprise networks often employ diverse and complex network topologies to meet enterprise needs. This increasing diversity and complexity places significant pressure on network administrators and opens the door to more problems, such as lower-than-expected uptime. For network administrators, establishing and managing network connectivity can be extremely challenging and time-consuming, often resulting in lower guarantees of stable / accurate connections, lower uptime, and / or a lack of certain expected characteristics. Attached Figure Description

[0005] In order to describe the various advantages and features that can be obtained from this disclosure, a more specific description of the principles briefly described above will be presented by reference to specific embodiments thereof illustrated in the accompanying drawings. It should be understood that these drawings depict only exemplary embodiments of this disclosure and are therefore not to be considered as limiting the scope of this disclosure. The principles herein are described and explained with additional specificity and detail using the drawings, in which:

[0006] Figure 1 Examples of advanced network architectures based on some examples of this disclosure are shown;

[0007] Figure 2 Examples of network topologies based on some examples of this disclosure are shown;

[0008] Figure 3 Examples illustrating the operation of protocols for managing overlay networks are shown, according to some examples of this disclosure;

[0009] Figure 4Examples illustrating the operation of a virtual private network for segmented networks are shown, according to some examples of this disclosure;

[0010] Figure 5 Examples of networks capable of automatically connecting to cloud resources, according to some examples of this disclosure, are shown;

[0011] Figures 6A to 6C An example of a graphical user interface (GUI) for a network controller is shown;

[0012] Figure 7 This is a flowchart illustrating a method for automatically connecting to cloud resources, based on some examples of this disclosure; and

[0013] Figure 8 An example of a system used to implement some aspects of this technology is shown. Detailed Implementation

[0014] Various embodiments of this disclosure are discussed in detail below. While specific implementations are discussed, it should be understood that this is done for illustrative purposes only. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of this disclosure. Therefore, the following description and drawings are illustrative and should not be construed as limiting. Numerous specific details have been described to provide a thorough understanding of this disclosure. However, in some instances, well-known or conventional details have not been described to avoid obscuring this description. References to one embodiment or embodiments in this disclosure may be references to the same embodiment or any of the embodiments; and such references imply at least one embodiment.

[0015] The reference to "an embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described with respect to that embodiment is included in at least one embodiment of this disclosure. The phrase "in an embodiment" appearing in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. Furthermore, various features that may be presented in some embodiments but not in others are described.

[0016] The terms used in this specification generally have their ordinary meaning in the art, in the context of this disclosure, and in the specific context in which each term is used. Alternative languages ​​and synonyms may be used for any one or more of the terms discussed herein and should not be given special meaning regardless of whether the terms are elaborated or discussed herein. In some cases, synonyms for certain terms are provided. The description of one or more synonyms does not preclude the use of other synonyms. The use of examples anywhere in this specification, including examples of any terms discussed herein, is merely illustrative and is not intended to further limit the scope and meaning of this disclosure or any of the example terms. Similarly, this disclosure is not limited to the various embodiments given in this specification.

[0017] Not intended to limit the scope of this disclosure, examples of instruments, apparatus, methods, and related results according to embodiments of this disclosure are given below. It should be noted that headings or subheadings may be used in the examples for the reader's convenience, but this should in no way limit the scope of this disclosure. Unless otherwise defined, the technical and scientific terms used herein have the meanings commonly understood by one of ordinary skill in the art to which this disclosure pertains. In case of conflict, this document (including the definitions) shall prevail. Additional features and advantages of this disclosure will be set forth in the following description and will be apparent in part from the description, or may be learned by practicing the principles disclosed herein. The features and advantages of this disclosure can be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. These and other features of this disclosure will become more apparent from the following description and the appended claims or may be learned by practicing the principles set forth herein.

[0018] Overview

[0019] The invention is set forth in the independent claims, and preferred features are set forth in the dependent claims. A feature of one aspect may be applied to each aspect alone or in combination with other aspects.

[0020] This technology provides methods, systems, and non-transitory computer-readable storage media for automatically connecting to cloud resources.

[0021] An example method may include receiving labels that associate at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP). The method may also include configuring a Virtual Cross-Connect (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure (SDCI) provider, the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP. The method may also include assigning Border Gateway Protocol (BGP) parameters to the VXC. The method may also include configuring BGP peering on a connectivity gateway in the cloud environment associated with the CSP. The method may also include connecting the connectivity gateway to at least one virtual network in the cloud environment. The method may also include labeling at least one virtual network. The method may further include configuring a connection between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, the connection being at least partially label-based.

[0022] In some embodiments of this method, connecting the connectivity gateway to at least one virtual network may include calling an API to use an interface associated with an SDCI provider. The method may also include using that interface to connect to the connectivity gateway. The method may further include mapping tags to at least one virtual network.

[0023] In some embodiments of the method, mapping a label to at least one virtual network for each of at least one virtual network includes attaching a cloud gateway to at least one virtual network in the cloud environment. The method may also include maintaining existing routing tables for at least one virtual network. The method may also include creating new routing tables for at least one virtual network. The method may also include adding a default route to the cloud gateway to the new routing table. The method may also include enabling route propagation based on the new routing table. The method may further include associating the cloud gateway with a connectivity gateway, wherein the advertised prefix list is set as address prefixes for at least one virtual network.

[0024] In some embodiments of this method, configuring connectivity between at least one routing domain and at least one virtual network in a locally deployed site may include providing BGP configuration to the SDWAN router. The method may also include providing segment configuration to the SDWAN router. The method may further include providing subinterface configuration to the SDWAN router based on a Virtual Local Area Network (VLAN).

[0025] In some embodiments, the method further includes updating the label. The method may also include automatically discovering the tagged connections. The method may also include automatically discovering one or more tagged virtual networks in a cloud environment. The method may further include attaching a new cloud gateway to one or more tagged virtual networks.

[0026] In some embodiments, the method further includes updating existing routing tables for one or more virtual networks affected by the label. The method may also include enabling route propagation based on existing routing tables. The method may further include attaching a new cloud gateway to the affected connection gateway, which belongs to the labeled connection and the one or more virtual networks affected by the label.

[0027] In some embodiments of the method, updating the label includes adding one or more new virtual networks to the label that correspond to one or more virtual networks.

[0028] An example system may include one or more processors and at least one computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the one or more processors to receive labels that associate at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP). The instructions may also cause the one or more processors to configure a Virtual Cross-Connect (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure (SDCI) provider, the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP. The instructions may also cause the one or more processors to assign Border Gateway Protocol (BGP) parameters to the VXC. The instructions may also cause the one or more processors to configure BGP peering on a connectivity gateway in the cloud environment associated with the CSP. The instructions may also cause the one or more processors to connect the connectivity gateway to at least one virtual network in the cloud environment. The instructions may also cause the one or more processors to label at least one virtual network. The instructions may also cause the one or more processors to configure connectivity between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, the connectivity being at least partially label-based.

[0029] An example non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to receive labels associating at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP). The instructions may also cause the processor to configure a Virtual Cross-Connect (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure (SDCI) provider, the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP. The instructions may also cause the processor to assign Border Gateway Protocol (BGP) parameters to the VXC. The instructions may also cause the processor to configure BGP peering on a connectivity gateway in the cloud environment associated with the CSP. The instructions may also cause the processor to connect the connectivity gateway to at least one virtual network in the cloud environment. The instructions may also cause the processor to label at least one virtual network. The instructions may further cause the processor to configure a connection between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, the connection being at least partially label-based.

[0030] Example Implementation

[0031] This disclosure will first discuss examples of network architectures and topologies for Software-Defined Wide Area Networks (SD-WAN), and various coverages of such networks. Then, this disclosure will discuss example embodiments for automatic connection to cloud resources. Finally, this disclosure will discuss example computing systems that can be used to implement this technology.

[0032] Figure 1 An example of a network architecture 100 for implementing various aspects of this technology is shown. An example of implementing network architecture 100 is... SD-WAN architecture. However, those skilled in the art will understand that for network architecture 100 and any system discussed in this disclosure, there may be additional or fewer components in similar or alternative configurations. For brevity and clarity, illustrations and examples are provided in this disclosure. Other embodiments may include different numbers and / or types of elements, but those skilled in the art will recognize that such changes do not depart from the scope of this disclosure.

[0033] In this example, network architecture 100 may include an orchestration plane 102, a management plane 120, a control plane 130, and a data plane 140. Orchestration plane 102 may assist edge network devices 142 (e.g., switches, routers, etc.) in automatically loading into the overlay network. Orchestration plane 102 may include one or more physical or virtual network orchestrator devices 104. One or more network orchestrator devices 104 may perform initial authentication of the edge network devices 142 and orchestrate connections between devices in the control plane 130 and devices in the data plane 140. In some embodiments, one or more network orchestrator devices 104 may also enable communication between devices located behind Network Address Translation (NAT). In some embodiments, physical or virtual... The SD-WAN vBond device can operate as one or more network orchestrator devices 104.

[0034] Management plane 120 can be responsible for the central configuration and monitoring of the network. Management plane 120 may include one or more physical or virtual network management devices 122. In some embodiments, the network management devices 122 may provide centralized management of the network via a graphical user interface, enabling users to monitor, configure, and maintain edge network devices 142 and links (e.g., Internet transport network 160, MPLS network 162, 4G / LTE network 164) in the underlay and overlay networks. The network management devices 122 may support multi-tenancy and enable centralized management of logically isolated networks associated with different entities (e.g., enterprises, departments within enterprises, groups within departments, etc.). Alternatively or additionally, the network management devices 122 may be dedicated network management systems for a single entity. In some embodiments, physical or virtual The SD-WAN vManage device can operate as one or more network management devices 122. The management plane 120 may include an analytics engine 124 to provide network analytics.

[0035] Control plane 130 can establish and maintain network topology and make decisions about traffic flow. Control plane 130 may include one or more physical or virtual network controller devices 132. The network controller devices 132 can establish secure connections to each network device 142 and allocate routing and policy information via control plane protocols such as Overlay Management Protocol (OMP) (discussed in further detail below), Open Shortest Path First (OSPF), Intermediate System to Intermediate System (IS-IS), Border Gateway Protocol (BGP), Protocol Independent Multicast (PIM), Internet Group Management Protocol (IGMP), Internet Control Message Protocol (ICMP), Address Resolution Protocol (ARP), Bidirectional Forwarding Detection (BFD), Link Aggregation Control Protocol (LACP), etc. In some embodiments, the network controller devices 132 may operate as route reflectors. The network controller devices 132 may also orchestrate secure connections between edge network devices 142 in data plane 140. For example, in some embodiments, the network controller devices 132 may distribute key information among the network devices 142. This allows the network to support secure network protocols or applications (e.g., Internet Protocol Security (IPSec), Transport Layer Security (TLS), Secure Shell (SSH), etc.) without Internet Key Exchange (IKE) and enables network scalability. In some embodiments, physical or virtual The SD-WAN vSmart controller can operate as one or more network controller devices 132.

[0036] Data plane 140 can be responsible for forwarding packets based on decisions from control plane 130. Data plane 140 may include edge network device 142, which can be a physical or virtual network device. Edge network device 142 can operate at the edge of an organization's various network environments, such as in one or more data centers or co-location centers 150, campus network 152, branch office network 154, local office network 154, or in the cloud (e.g., Infrastructure as a Service (IaaS), Platform as a Service (PaaS), SaaS, and other cloud service provider networks). Edge network device 142 can provide secure data plane connectivity between sites via one or more WAN transmissions (e.g., via one or more Internet transmission networks 160 (e.g., Digital Subscriber Line (DSL), cable, etc.), MPLS network 162 (or other dedicated packet-switched networks (e.g., Metro Ethernet, Frame Relay, Asynchronous Transfer Mode (ATM), etc.), mobile network 164 (e.g., 4G, 4G / LTE, 5G, etc.), or other WAN technologies (e.g., Synchronous Optical Network (SONET), Synchronous Digital Hierarchy (SDH), Dense Wavelength Division Multiplexing (DWDM)), or other fiber optic technologies; leased lines (e.g., T1 / E1, T3 / E3, etc.); Public Switched Telephone Network (PSTN), Integrated Services Digital Network (ISDN), or other dedicated circuit-switched networks; Small Aperture Terminal (VSAT) or other satellite networks, etc.). Edge network device 142 can be responsible for tasks such as traffic forwarding, security, encryption, Quality of Service (QoS), and routing (e.g., BGP, OSPF, etc.). In some embodiments, physical or virtual The SD-WAN vEdge router can operate as an edge network device 142.

[0037] Figure 2An example of a network topology 200 is shown to illustrate various aspects of network architecture 100. Network topology 200 may include a management network 202, a pair of network sites 204A and 204B (collectively referred to as 204) (e.g., one or more data centers 150, one or more campus networks 152, one or more branch office networks 154, one or more local office networks 156, one or more cloud service provider networks, etc.), and a pair of Internet transport networks 160A and 160B (collectively referred to as 160). Management network 202 may include one or more network orchestrator devices 104, one or more network management devices 122, and one or more network controller devices 132. Although management network 202 is shown as a single network in this example, those skilled in the art will understand that the various elements of management network 202 can be distributed across any number of networks and / or coexist with site 204. In this example, each element of management network 202 can be reached via transport networks 160A or 160B.

[0038] Each site may include one or more endpoints 206 connected to one or more site network devices 208. Endpoints 206 may include general-purpose computing devices (e.g., servers, workstations, desktop computers, etc.), mobile computing devices (e.g., laptops, tablets, mobile phones, etc.), wearable devices (e.g., watches, glasses or other head-mounted displays (HMDs), ear-mounted devices, etc.). Endpoint 206 may also include Internet of Things (IoT) devices or equipment, such as agricultural equipment (e.g., livestock tracking and management systems, irrigation equipment, unmanned aerial vehicles (UAVs), etc.); connected cars and other vehicles; smart home sensors and devices (e.g., alarm systems, security cameras, lighting, appliances, media players, HVAC equipment, utility meters, windows, automatic doors, doorbells, locks, etc.); office equipment (e.g., desktop phones, copiers, fax machines, etc.); medical devices (e.g., pacemakers, biosensors, medical equipment, etc.); industrial equipment (e.g., robots, factory machinery, construction equipment, industrial sensors, etc.); retail equipment (e.g., vending machines, point-of-sale (POS) equipment, radio frequency identification (RFID) tags, etc.); smart city equipment (e.g., streetlights, parking meters, waste management sensors, etc.); transportation and logistics equipment (e.g., rotary vehicles, rental car trackers, navigation devices, inventory monitors, etc.), etc.

[0039] Site network device 208 may include physical or virtual switches, routers, and other network devices. While site 204A is shown in this example as including a pair of site network devices and site 204B is shown as including a single site network device, site network device 208 may include any number of network devices in any network topology, including multi-layer (e.g., core, distribution, and access layers), spine, mesh, tree, bus, center-radial, etc. For example, in some embodiments, one or more data center networks may be implemented. Application Center Infrastructure (ACI) architecture and / or one or more campus networks can achieve Software-defined access (SD access or SDA) architecture. Site network device 208 can connect endpoint 206 to one or more edge network devices 142, and edge network devices 142 can be used to directly connect to transport network 160.

[0040] In some embodiments, a "color" can be used to identify individual WAN transport networks, and different WAN transport networks can be assigned different colors (e.g., MPLS, Private 1, Biz-Internet, Metro-Ethernet, LTE, etc.). In this example, network topology 200 can use the color referred to as "Biz-Internet" for Internet transport network 160A and the color referred to as "Public-Internet" for Internet transport network 160B.

[0041] In some embodiments, each edge network device 208 may form a Datagram Transport Layer Security (DTLS) or TLS Control connection to one or more network controller devices 132 and connect to any network controller device 132 via each transport network 160. In some embodiments, edge network device 142 may also securely connect to edge network devices in other sites via IPSec tunnels. In some embodiments, the BFD protocol may be used within each of these tunnels to detect loss, latency, jitter, and path failures.

[0042] On edge network device 142, colors can be used to help identify or differentiate individual WAN transport tunnels (e.g., the same color cannot be used twice on a single edge network device). The colors themselves are also important. For example, colors like Metro Ethernet, MPLS, and Private 1, Private 2, Private 3, Private 4, Private 5, and Private 6 can be considered private colors. These private colors can be used in private networks or where there is no NAT addressing for transport IP endpoints (e.g., because there may be no NAT between two endpoints of the same color). When edge network device 142 uses private colors, it can attempt to establish IPSec tunnels to other edge network devices using local, private, low-level IP addresses. Public colors can include 3g, Biz, Internet, Blue, Bronze, Custom 1, Custom 2, Custom 3, Default, Gold, Green, LTE, Public Internet, Red, and Silver. Public colors can be used by edge network device 142 to establish tunnels to IP addresses behind NAT (if NAT is involved). If edge network device 142 uses a private color and requires NAT to communicate with other private colors, the ISP setting in the configuration can instruct edge network device 142 whether to use a private IP address or a public IP address. Using this setting, two private colors can establish a session when one or both are using NAT.

[0043] Figure 3 An example illustration of OMP operation is shown in Figure 300. OMP can be used in some embodiments to manage network coverage (e.g., network architecture 100). In this example, OMP messages 302A and 302B (collectively referred to as 302) can be transmitted back and forth between network controller device 132 and edge network devices 142A and 142B, respectively. Control plane information (e.g., routing prefixes, next-hop routes, cryptographic keys, policy information, etc.) can be exchanged via corresponding secure DTLS or TLS connections 304A and TLS connection 304B. Network controller device 132 can operate similarly to a route reflector. For example, network controller device 132 can receive routes from edge network device 142, process any policies and apply any policies to the routes, and advertise the routes to other edge network devices 142 within the coverage area. Without a defined strategy, edge network device 142 can operate in a manner similar to a full mesh topology, in which each edge network device 142 can directly connect to another edge network device 142 at another site and receive full routing information from each site.

[0044] OMP can advertise various types of routes. For example, OMP can advertise OMP routes, which can correspond to prefixes learned from local sites or servers on edge network device 142. Prefixes can originate from static or connection-based routes, or from protocols such as OSPF or BGP, and are reassigned to OMP so they can be transmitted between overlays. OMP routes can advertise attributes such as Transport Location (TLOC) information (which can be similar to a BGP next-hop IP address) and other attributes such as origin, route initiator, priority, site identifier, label, and Virtual Private Network (VPN). If the TLOC to which the OMP route points is active, the OMP route can be added to the forwarding table.

[0045] As another example, the OMP can advertise a TLOC route that corresponds to a logical tunnel endpoint on an edge network device 142 connected to the transport network 160. In some embodiments, a TLOC route can be uniquely identified and represented by a triplet that includes an IP address, link color, and encapsulation (e.g., Generic Routing Encapsulation (GRE), IPSec, etc.). In addition to the system IP address, color, and encapsulation, the TLOC route can also carry attributes such as TLOC private and public IP addresses, carrier, priority, site identifier, label, and weight. In some embodiments, a TLOC can be active when an active BFD session is associated with it on a specific edge network device 142.

[0046] As another example, the OMP can advertise service routes that represent services (e.g., firewalls, distributed denial-of-service (DDoS) mitigators, load balancers, intrusion prevention systems (IPS), intrusion detection systems (IDS), WAN optimizers, etc.) that can be connected to local sites on the edge network device 142 and are accessible and available to other sites via service plug-ins. Furthermore, these routes can also include VPNs; VPN labels can be sent in update type to inform the network controller device 132 which VPNs are being served at remote sites.

[0047] exist Figure 3In the example, OMP is shown running on a DTLS / TLS tunnel 304 established between edge network device 142 and network controller device 132. Furthermore, Figure 300 shows an IPSec tunnel 306A established between TLOC 308A and TLOC 308C via WAN transport network 160A, and an IPSec tunnel 306B established between TLOC 308B and TLOC 308D via WAN transport network 160B. Once IPSec tunnels 306A and 306B are established, BFD can be enabled on each of them.

[0048] Figure 4 An example illustration of VPN operation is shown in Figure 400. VPNs can be used in some embodiments to provide segmentation for a network (e.g., network architecture 100). VPNs can be isolated from each other and can have their own forwarding tables. Interfaces or sub-interfaces can be explicitly configured under a single VPN and cannot be part of more than one VPN. Tags can be used in OMP routing attributes and packet encapsulation to identify the VPN to which a packet belongs. VPN numbers can be four-byte integers with values ​​from 0 to 65530. In some embodiments, one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, and / or one or more edge network devices 142 can each include a transport VPN 402 (e.g., VPN 0) and an administrative VPN 404 (e.g., VPN 512). Transport VPN 402 can include one or more physical or virtual network interfaces (e.g., network interface 410A and network interface 410B) respectively connected to a WAN transport network (e.g., MPLS network 162 and Internet transport network 160). Secure DTLS / TLS connections to (one or more) network controller devices 132 or between (one or more) network controller devices 132 and (one or more) network orchestrator devices 104 can be initiated from transport VPN 402. Furthermore, static routes, default routes, or dynamic routing protocols can be configured within transport VPN 402 to obtain appropriate next-hop information, enabling control plane 130 to be established and IPSec tunnel 306 (not shown) to connect to remote sites.

[0049] The management VPN 404 can carry out-of-band management traffic to and from one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, and / or one or more edge network devices 142 via network interface 410C. In some embodiments, the management VPN 404 cannot be carried on the overlay network.

[0050] In addition to transport VPN 402 and management VPN 404, one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, or one or more edge network devices 142 may also include one or more server VPNs 406. Server VPN 406 may include one or more physical or virtual network interfaces (e.g., network interface 410D and network interface 410E) connected to one or more local site networks 412 and carrying user data traffic. One or more server VPNs 406 may be enabled for features such as OSPF or BGP, Virtual Router Redundancy Protocol (VRRP), QoS, traffic shaping, and policy enforcement. In some embodiments, user traffic can be routed to other sites via IPSec tunnels by reallocating OMP routes received from one or more network controller devices 132 at site 412 to the server VPN routing protocol. Furthermore, by advertising the service VPN routes to the OMP routing protocol, routes from local site 412 can be advertised to other sites. The OMP routing protocol can be sent to network controller device(s) 132 and redistributed to other edge network devices 142 in the network. Although network interfaces 410A-E (collectively referred to as 410) are shown as physical interfaces in this example, those skilled in the art will understand that interface 410 in the transport VPN and service VPN can alternatively be a sub-interface.

[0051] This disclosure now turns to discuss examples of automatic connection to cloud resources. This technique can be utilized in… Figures 1 to 4 The tools available in the SDWAN network described herein are used to automate intent-driven connections from on-premises network segments to cloud resources. By automatically and dynamically mapping on-premises network segments to cloud resources, the workload of network administrators can be reduced, high uptime can be maintained, and Service Level Protocol (SLP) protocols can be maintained throughout the connection chain. This meets the needs of the art by dynamically mapping cloud resources to network site segments (e.g., on-premises networks).

[0052] Figure 5 An example of a network capable of automatically connecting to cloud resources is shown. Network controller 500 can send requests to connection gateway 530 and interconnect gateway 550, which connect any one of segment 570-1, segment 570-2, or segment 570-3 to any virtual network of virtual network 520-1, virtual network 520-2, or virtual network 520-3.

[0053] Network controller 500 can be with Figure 1The illustrated network controller(s) 132 are similar to network controllers. For example, network controller 500 may be a controller utilizing Cisco vManage. Network controller 500 may send requests and configurations to connection gateway 530 and interconnect gateway 550. For example, the configuration sent to interconnect gateway 550 may include configurations for establishing Border Gateway Protocol (BGP), configurations for network segments, or configurations for VLAN-based sub-interfaces.

[0054] The SDWAN architecture 560 can be with Figure 1 The network shown is similar to data center 150, campus 152, branch office 154, or local office 156, or is related to... Figure 2 The networks shown are similar to networks 204A and 204B. The SDWAN architecture 560 can be an on-premises network comprising segments 570-1, 570-2, and 570-3 (collectively referred to as segment 570). For example, segment 570 can be a virtual routing function.

[0055] The SDCI network 540 can be a Software-Defined Cloud Infrastructure (SDCI) network. The SDCI network 540 can be connected to... Figure 1 The data center 150, campus 152, branch office 154, or local office 156 shown are similar to, or related to, these. Figure 2 The networks shown, 204A and 204B, are similar. The SDCI network 540 can act as an intermediate network between the SDWAN architecture 560 and the cloud environment 510.

[0056] Cloud Environment 510 can be with Figure 2 The network shown is similar to network 204A and network 204B. Cloud environment 510 may contain virtual network 520-1, virtual network 520-2 and virtual network 520-3 (hereinafter collectively referred to as "virtual network 520").

[0057] Interconnect gateway 550 and connectivity gateway 530 can be routers or network edges. Interconnect gateway 550 can connect SDWAN infrastructure 560 to SDCI network 540. Connectivity gateway 530 can connect SDCI network 540 to cloud environment 510.

[0058] For example, cloud environment 510 could be Amazon Web Services, virtual network 520 could be a virtual private cloud, and connection gateway 530 could be a direct connection gateway. In another example, cloud environment 510 could be Google Cloud, virtual network 520 could be a virtual private cloud, and connection gateway 530 could be a Google Cloud router.

[0059] Network controller 500 can establish a connection between segment 570 and virtual network 520. This connection can be enabled by tags received by network controller 500, indicating that a connection between segment 570 and virtual network 520 should be established. For example, these tags can map or associate segments (e.g., virtual networks, routing domains, prefixes, subnets, etc.) of SDWAN infrastructure 560 to virtual networks (e.g., virtual private networks or routing domains, etc.) in cloud environment 510. These tags can be used to establish a connection between segments in SDWAN infrastructure 560 and virtual networks in cloud environment 510. In some examples, tags can associate segments(s) with virtual networks based on one or more factors (e.g., but not limited to, public attributes (e.g., public services or functions, associated public sets of users / groups / devices, public security groups or policies, demand public sets, etc.), relationships, and priorities, etc.). These tags can be received from network administrators, automated processes, or via other methods.

[0060] To establish a connection between segment 570 and virtual network 520, the network controller can send requests and configurations to interconnect gateway 550 and connection gateway 530. Network controller 500 can establish connections between interconnect gateway 550 and connection gateway 530, and between connection gateway 530 and virtual network 520. In summary, network controller 500 can establish a connection between segment 570 and virtual network 520 because segment 570 is already connected to interconnect gateway 550.

[0061] Network controller 500 can establish a connection between interconnect gateway 550 and connection gateway 530. In some examples, this connection can be a virtual cross-connect (VXC). A VXC is a Layer 2 connection or data link layer connection that originates at interconnect gateway 550 and extends to connection gateway 530.

[0062] Network controller 500 can establish a VXC and send it to interconnect gateway 550 on SDCI network 540. Below is an example of code used to establish a VXC on interconnect gateway 550, which network controller 500 can then send to interconnect gateway 550:

[0063] a_end={}

[0064] a_end['vlan'] = 0

[0065] a_end['innerVlan'] = 0

[0066] b_end={}

[0067] b_end['productUid']=destinationProductId#Partner port Location Id

[0068] b_end['vlan']=0

[0069] b_end['innerVlan']=0

[0070] cloud_vxc_req['productUid']=sourceProductId#MVE Product Id

[0071] associated_vxcs={}

[0072] associated_vxcs['productName']=connectivityName#Name of theconnection

[0073] associated_vxcs['rateLimit']=connectivitySpeed#Speed of theconnection

[0074] associated_vxcs['aEnd']=a_end

[0075] associated_vxcs['bEnd']=b_end

[0076] associated_vxcs_array=[]

[0077] associated_vxcs_array.append(associated_vxcs)

[0078] cloud_vxc_req['associatedVxcs']=associated_vxcs_array

[0079] create_vxc_array=[]

[0080] create_vxc_array.append(cloud_vxc_req)

[0081] Once the interconnect gateway 550 receives the VXC, the SDCI network 540 can verify the VXC creation request. The network administrator operating the network controller 500 can verify the request, or the request can be verified automatically or via other methods.

[0082] Network controller 500 can establish a connection between interconnect gateway 550 and one or more virtual networks 520 via connection gateway 530. Virtual network 520 can be designated by a tag received by network controller 500.

[0083] Network controller 500 can call an API to request connection gateway 530 to accept the virtual interface of SDCI network 540. For example, when cloud environment 510 is Amazon Web Services, the virtual interface can be a dedicated interface or a forwarding virtual interface. In another example, when cloud environment 510 is Google Cloud, the virtual interface can be Partner Interconnect. Below is an example of code used to request connection gateway 530 to accept the virtual interface of SDCI network 540, which network controller 500 can send to connection gateway 530:

[0084] response=self.get_dc_client().confirm_private_virtual_interface(virtualInte rfaceId=vif_id,

[0085] directConnectGatewayId=dcg_id)

[0086] Using this virtual interface, network controller 500 can map the virtual network specified in the label to a set of virtual networks 520. For example, to implement this in a cloud environment 510 where Amazon Web Services is used, for each virtual network 520, network controller 500 can:

[0087] 1) Create a virtual private gateway and attach it to virtual network 520:

[0088] response=self.get_ec2_client().create_vpn_gateway(Type=vpg_type,

[0089] AmazonSideAsn = asn,

[0090] DryRun = False)

[0091] response=self.get_ec2_client().attach_vpn_gateway(VpcId=vpc_id,

[0092] VpnGatewayId = vpg_id)

[0093] 2) Save the existing routing table for virtual network 520 and create a new routing table for virtual network 520:

[0094] #Build the tag specifications.

[0095] tag_list=[{'Key':route_table_fields['name'],'Value':name}]

[0096] tag_specifications = [

[0097] {

[0098] 'ResourceType':'route-table',

[0099] 'Tags':tag_list,

[0100] } ]

[0102] response=self.get_ec2_client().create_route_table(VpcId=vpc_id,

[0103] TagSpecifications=tag_specifications)

[0104] 3) Add a default route pointing to the virtual private gateway to the new routing table:

[0105] ret_code=self.get_ec2_client().create_route(DestinationCidrBlock=cidr_block,

[0106] GatewayId = gw_id,

[0107] RouteTableId=route_table_id)

[0108] response=

[0109] self.get_ec2_client().replace_route_table_association(AssociationId=old_association_id,

[0110] RouteTableId=new_route_table_id)

[0111] 4) Associate the Virtual Private Gateway with Connection Gateway 530, and set the advertised prefix list to the address prefixes for Virtual Network 520:

[0112] response=

[0113] self.get_dc_client().create_direct_connect_gateway_association(directConnectGatewayId=dcg_id,

[0114] gatewayId = gw_id,

[0115] addAllowedPrefixesToDirectConnectGateway=advertised_prefix_list)

[0116] In some cases, to establish a connection from segment 570 to virtual network 520, network controller 500 can push configuration to interconnect gateway 550. Network controller 500 can configure Border Gateway Protocol (BGP) peering between interconnect gateway 550 and virtual network 520. Network connection 500 can push various configurations to interconnect gateway 550 to establish BGP peering, including:

[0117] 1) BGP peer configuration:

[0118] VRF definition 10

[0119] rd 1:1

[0120] address-family IPv4

[0121] route-target export 65000:1

[0122] route-target import 65000:1

[0123] exit-address-family

[0124] !

[0125] address-family ipv6

[0126] exit-address-family

[0127] !

[0128] !

[0129] 2) Segment configuration:

[0130] interface GigabitEthernet1.2936

[0131] no shutdown

[0132] encapsulation dot1Q 2936

[0133] vrf forwarding 10

[0134] ip address 192.168.0.29 255.255.255.252

[0135] ip mtu 1496

[0136] exit 3) Virtual network sub-interface configuration

[0137] router bgp 65000

[0138] bgp log-neighbor-changes

[0139] address-family ipv4 unicast vrf 10

[0140] distance bgp 20 200 20

[0141] neighbor 192.168.0.30 remote-as 64515

[0142] neighbor 192.168.0.30 activate

[0143] neighbor 192.168.0.30 activate

[0144] neighbor 192.168.0.30 description test-tgw-asn

[0145] neighbor 192.168.0.30ebgp-multihop

[0146] neighbor 192.168.0.30password 0ECLZMN8MSXGDV65IZGM5neighbor192.168.0.30send-community both

[0147] redistribute omp

[0148] exit-address-family

[0149] !

[0150] timers bgp 60 180

[0151] !

[0152] In some examples, the labels managing the connection between the SDWAN infrastructure 560 and the cloud environment 510 can be updated. The network controller 500 can automatically discover the affected connections and endpoints in segment 570 and virtual network 520, and apply the label changes accordingly. For example, when the cloud environment 510 is Amazon Web Services, the network controller 500 can attach a new virtual cloud gateway to the affected virtual network 520 and connection gateway 530, and update the routing table for virtual network 520.

[0153] Figures 6A to 6C It shows Figure 5 An example of the graphical user interface (GUI) of the network controller 500 is shown. Through this GUI, network administrators can discover virtual networks 520, add tags to virtual networks 520, or edit the tags of virtual networks 520.

[0154] Figure 6A A GUI 610 for discovering virtual networks 520 is shown. After a cloud environment 510 is associated with a network controller 500, the network controller 500 can synchronize and display all virtual networks 520 from the corresponding account. The GUI 610 can display information such as the name of the cloud environment 510, and for each virtual network 520, it can display the cloud region, account name, host virtual network name, host virtual network label, whether the virtual network supports interconnection, account ID, and host virtual network ID. Network administrators can use the GUI 610 to select multiple virtual networks 520 on multiple cloud environments 510 and group them into a single logical group called a label. This label acts as a single control point for all virtual networks 520 associated with the label.

[0155] Figure 6B A GUI 620 for creating tags is shown. The network administrator can specify a tag name and select a virtual network 520 in a given area. The network administrator can choose whether to enable interconnection for the new tag. Once the tag is created, it can be associated with the connection created as part of the interconnection to establish a connection from segment 570 to virtual network 520.

[0156] Figure 6C A GUI 630 for editing tags is shown. Network administrators can later modify the composition of already deployed tags to update the virtual network 520 associated with those tags. If such modifications are made, the network controller 500 can detect and adjust the connectivity accordingly.

[0157] Figure 7 An example method 700 for automatically connecting to cloud resources is illustrated. While example method 700 depicts a specific sequence of operations, the sequence can be changed without departing from the scope of this disclosure. For example, some of the depicted operations may be performed in parallel or in a different order without substantially affecting the functionality of method 700. In other examples, different components of the example device or system implementing method 700 may perform their functions substantially simultaneously or in a specified order.

[0158] At box 710, method 700 includes receiving a label that associates at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP). For example, Figure 5 The network controller 500 shown can receive tags that associate at least one routing domain in a local deployment site with at least one virtual network in a cloud environment (associated with a CSP).

[0159] At box 720, method 700 includes configuring a virtual cross-connection (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure provider (SDCI), the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP. For example, Figure 5 The network controller 500 shown can establish a VXC on an SDWAN router associated with an SDCI provider, which connects on-premises sites to a cloud environment associated with the CSP.

[0160] At box 730, method 700 includes assigning Border Gateway Protocol (BGP) parameters to the VXC. For example, Figure 5 The network controller 500 shown can assign BGP parameters to the VXC.

[0161] At box 740, method 700 includes configuring BGP peering on the connectivity gateway in the cloud environment associated with the CSP. For example, Figure 5 The network controller 500 shown can configure BGP peering on the connectivity gateway in a cloud environment associated with a CSP.

[0162] At box 750, method 700 includes connecting a connectivity gateway to at least one virtual network in a cloud environment. For example, Figure 5 The network controller 500 shown can connect a connectivity gateway to at least one virtual network in a cloud environment.

[0163] At box 750, in another example of connecting a connectivity gateway to at least one virtual network in a cloud environment, method 700 may include calling an API to use an interface associated with an SDCI provider. Additionally, method 700 may include using the interface to connect to the connectivity gateway. Furthermore, method 700 may include mapping tags to at least one virtual network.

[0164] In another example of a mapping label, method 700 may include attaching a cloud gateway to at least one virtual network in a cloud environment. Furthermore, method 700 may include maintaining an existing routing table for at least one virtual network. Furthermore, method 700 may include creating a new routing table for at least one virtual network. Furthermore, method 700 may include adding a default route to the cloud gateway to the new routing table. Furthermore, method 700 may include enabling route propagation based on the new routing table. Furthermore, method 700 may include associating the cloud gateway with a connection gateway. In some examples, the advertised prefix list is set as address prefixes for at least one virtual network.

[0165] At box 760, method 700 includes labeling at least one virtual network. For example, Figure 5 The network controller 500 shown can be labeled with at least one virtual network.

[0166] At box 770, method 700 includes establishing a connection between at least one routing domain in an on-premises deployment site and at least one virtual network in a cloud environment. For example, Figure 5 The illustrated network controller 500 can establish a connection between at least one routing domain in a locally deployed site and at least one virtual network in a cloud environment. In some examples, this connection is at least partially based on tags.

[0167] At box 770, in another example of establishing a connection, method 700 may include providing BGP configuration to the SDWAN router. Furthermore, method 700 may include providing segment configuration to the SDWAN router. Additionally, method 700 may include providing subinterface configuration to the SDWAN router based on a virtual LAN.

[0168] In some embodiments, method 700 may further include updating the tag. For example, Figure 5 The illustrated network controller 500 can update tags. Furthermore, method 700 may include automatically discovering connections affected by the tag. Additionally, method 700 may include automatically discovering one or more virtual networks affected by the tag in a cloud environment. Furthermore, method 700 may include attaching a new cloud gateway to one or more virtual networks affected by the tag. In some examples, updating the tag includes adding one or more new virtual networks corresponding to one or more virtual networks to the tag.

[0169] In some embodiments, the method 700 may further include updating existing routing tables for one or more virtual networks affected by the label. For example, Figure 5 The illustrated network controller 500 can update existing routing tables for one or more virtual networks affected by the label. Method 700 may also include enabling route propagation based on the existing routing table. Method 700 may also include attaching a new cloud gateway to the affected connection gateway, which belongs to both the labeled connection and the one or more virtual networks affected by the label.

[0170] Figure 8 An example of a computing system 800 is shown. The computing system 800 can be any computing device, such as constituting a network controller 500 or any component of a network controller 500, wherein the components of the system communicate with each other using a connection 805. The connection 805 can be a physical connection via a bus, or (e.g., in a chipset architecture) a direct connection to a processor 810. The connection 805 can also be a virtual connection, a networking connection, or a logical connection.

[0171] In some embodiments, the computing system 800 is a distributed system, wherein the functions described herein can be distributed across data centers, multiple data centers, and peer-to-peer networks, etc. In some embodiments, one or more of the described system components represent a plurality of such components, each performing some or all of the functions described for that component. In some embodiments, a component can be a physical or virtual device.

[0172] Example system 800 includes at least one processing unit (CPU or processor) 810 and a connection 805 coupling various system components, including system memory 815 (e.g., read-only memory (ROM) 820 and random access memory (RAM) 825)), to processor 810. Computing system 800 may include a cache 812 of high-speed memory directly connected to adjacent processor 810, or a cache 812 of high-speed memory integrated into processor 810.

[0173] Processor 810 may include any general-purpose processor and hardware or software services (e.g., services 832, 834, and 836 stored in storage device 830), configured to control processor 810 and dedicated processors, in which software instructions are incorporated into the actual processor design. Processor 810 may essentially be a fully self-contained computing system containing multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.

[0174] To enable user interaction, the computing system 800 includes an input device 845, which can represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. The computing system 800 may also include an output device 835, which can be one or more of a plurality of output mechanisms known to those skilled in the art. In some instances, a multi-mode system allows the user to provide multiple types of input / output to communicate with the computing system 800. The computing system 800 may include a communication interface 840, which generally controls and manages user input and system output. There are no limitations regarding operation on any particular hardware arrangement, and therefore the basic features described herein can be readily replaced with improved hardware or firmware arrangements as they are developed.

[0175] Storage device 830 may be a non-volatile memory device and may be a hard disk or other types of computer-readable media that can store data accessible by a computer, such as magnetic tape cassettes, flash memory cards, solid-state memory devices, digital multifunction disks, magnetic tape cassettes, random access memory (RAM), read-only memory (ROM), and / or some combination of these devices.

[0176] Storage device 830 may include software services, servers, services, etc., which cause the system to perform functions when the code defining such software is executed by processor 810. In some embodiments, hardware services that perform a particular function may include software components stored in a computer-readable medium connected to necessary hardware components (e.g., processor 810, connection 805, output device 835, etc.) to perform that function.

[0177] In summary, this technology relates to receiving labels that associate at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider. This technology also relates to automating the population of routing and propagation tables using cloud service providers.

[0178] For clarity, in some cases, this technology may be represented as including various functional blocks, which include functional blocks containing: devices, device components, steps or routines in methods embodied in software, or combinations of hardware and software.

[0179] Any steps, operations, functions, or processes described herein may be performed or implemented by hardware and software services or combinations of services, or services alone or in combination with other devices. In some embodiments, a service may be software residing in the memory of a client device and / or one or more servers of a content management system, and may perform one or more functions when a processor executes the software associated with the service. In some embodiments, a service is a program or collection of programs that performs a specific function. In some embodiments, a service may be considered a server. Memory may be a non-transitory computer-readable medium.

[0180] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and the signals themselves.

[0181] The methods according to the examples above can be implemented using computer-executable instructions stored on or accessible from a computer-readable medium. Such instructions may include, for example, instructions and data to cause or configure a general-purpose computer, a special-purpose computer, or a special-purpose processing device to perform a function or a set of functions. Some of the computer resources used may be accessible via a network. The computer-executable instructions may be, for example, binary, intermediate format instructions (e.g., assembly language, firmware, or source code). Examples of computer-readable media that may be used to store instructions, information used and / or created during the methods according to the examples include disks or optical discs, solid-state storage devices, flash memory, USB devices providing non-volatile memory, network storage devices, etc.

[0182] Devices implementing various methods according to these disclosures may include hardware, firmware, and / or software, and may employ any of a variety of form factors. Typical examples of such form factors include servers, laptops, smartphones, small form factor personal computers, personal digital assistants, etc. The functionality described herein may also be embodied in peripheral devices or add-in cards. As a further example, such functionality may also be implemented on a circuit board between different chips or between different processes executing in a single device.

[0183] Instructions, the medium for conveying such instructions, the computing resources for executing such instructions, and other structures for supporting such computing resources are modules for providing the functionality described in these disclosures.

Claims

1. A method for providing connectivity to cloud resources, comprising: Receive a tag that associates at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP); Configure a virtual cross-connect (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure (SDCI) provider, the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP; Assign Border Gateway Protocol (BGP) parameters to the VXC; Configure BGP peering on the connection gateway in the cloud environment associated with the CSP; Connect the connectivity gateway to the at least one virtual network in the cloud environment; The at least one virtual network is labeled with the tag; as well as Configure a connection between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, wherein the connection is at least partially based on the tag.

2. The method according to claim 1, wherein, Connecting the connectivity gateway to the at least one virtual network includes: Call the API to use the interface associated with the SDCI provider; Use the interface to connect to the connection gateway; and Map the label to the at least one virtual network.

3. The method according to claim 2, wherein, Mapping the label to each of the at least one virtual network includes: Attach a cloud gateway to the at least one virtual network in the cloud environment; For the at least one virtual network, maintain an existing routing table; Create a new routing table for the at least one virtual network; Add a default route pointing to the cloud gateway to the new routing table; Enable route propagation based on the new routing table; and The cloud gateway is associated with the connection gateway, wherein the announced prefix list is set as address prefixes for the at least one virtual network.

4. The method according to any one of claims 1 to 3, wherein, Configuring the connection between the at least one routing domain and the at least one virtual network in the locally deployed site includes: Provide BGP configuration to the SDWAN router; Provide segment configuration to the SDWAN router; and Based on Virtual Local Area Network (VLAN), sub-interface configuration is provided to the SDWAN router.

5. The method according to any one of claims 1 to 3, further comprising: Update the aforementioned tags; Automatically discover connections affected by the aforementioned tag; Automatically discover one or more virtual networks in the cloud environment that are affected by the tag; as well as Attach a new cloud gateway to the one or more virtual networks affected by the label.

6. The method according to claim 5, further comprising: Update the existing routing tables for the one or more virtual networks affected by the label; Enable route propagation based on the existing routing table; as well as The new cloud gateway is attached to the affected connection gateway, which belongs to the connection affected by the tag and the one or more virtual networks affected by the tag.

7. The method according to claim 5, wherein, Updating the label includes adding one or more new virtual networks to the label that correspond to the one or more virtual networks.

8. A system for providing connectivity to cloud resources, comprising: One or more processors; as well as At least one computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the one or more processors to: Receive a tag that associates at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP); Configure a virtual cross-connect (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure (SDCI) provider, the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP; Assign Border Gateway Protocol (BGP) parameters to the VXC; Configure BGP peering on the connection gateway in the cloud environment associated with the CSP; Connect the connectivity gateway to the at least one virtual network in the cloud environment; The at least one virtual network is labeled with the tag; as well as Configure a connection between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, wherein the connection is at least partially based on the tag.

9. The system according to claim 8, wherein, The instructions for connecting the connectivity gateway to the at least one virtual network also enable the one or more processors to: Call the API to use the interface associated with the SDCI provider; Use the interface to connect to the connection gateway; and Map the label to the at least one virtual network.

10. The system according to claim 9, wherein, For each of the at least one virtual network, the instructions for mapping the tag to the at least one virtual network also enable the one or more processors to: Attach a cloud gateway to the at least one virtual network in the cloud environment; For the at least one virtual network, maintain an existing routing table; Create a new routing table for the at least one virtual network; Add a default route pointing to the cloud gateway to the new routing table; Enable route propagation based on the new routing table; and The cloud gateway is associated with the connection gateway, wherein the announced prefix list is set as address prefixes for the at least one virtual network.

11. The system according to any one of claims 8 to 10, wherein, The instructions for configuring the connection between the at least one routing domain and the at least one virtual network in the locally deployed site also enable the one or more processors to: Provide BGP configuration to the SDWAN router; Provide segment configuration to the SDWAN router; and Based on Virtual Local Area Network (VLAN), sub-interface configuration is provided to the SDWAN router.

12. The system according to any one of claims 8 to 10, wherein, The instructions can also enable the one or more processors to: Update the aforementioned tags; Automatically discover connections affected by the aforementioned tag; Automatically discover one or more virtual networks in the cloud environment that are affected by the tag; as well as Attach a new cloud gateway to the one or more virtual networks affected by the label.

13. The system according to claim 12, wherein, The instructions can also enable the one or more processors to: Update the existing routing tables for the one or more virtual networks affected by the label; Enable route propagation based on the existing routing table; and The new cloud gateway is attached to the affected connection gateway, which belongs to the connection affected by the tag and the one or more virtual networks affected by the tag.

14. The system of claim 12, wherein the instructions for updating the tag are further capable of enabling the one or more processors to add one or more new virtual networks corresponding to the one or more virtual networks to the tag.

15. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to perform the following actions to provide connectivity to cloud resources: Receive a tag that associates at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP); Configure a virtual cross-connect (VXC) on a software-defined wide area network (SDWAN) router associated with a software-defined cloud infrastructure (SDCI) provider, the VXC connecting the on-premises deployment site to the cloud environment associated with the CSP; Assign Border Gateway Protocol (BGP) parameters to the VXC; Configure BGP peering on the connection gateway in the cloud environment associated with the CSP; Connect the connectivity gateway to the at least one virtual network in the cloud environment; The at least one virtual network is labeled with the tag; as well as Configure a connection between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, wherein the connection is at least partially based on the tag.

16. The non-transitory computer-readable storage medium according to claim 15, wherein, The instructions for connecting the connectivity gateway to the at least one virtual network also enable the processor to: Call the API to use the interface associated with the SDCI provider; Use the interface to connect to the connection gateway; as well as Map the label to the at least one virtual network.

17. The non-transitory computer-readable storage medium according to claim 16, wherein, For each of the at least one virtual network, the instructions for mapping the tag to the at least one virtual network further enable the processor to: Attach a cloud gateway to the at least one virtual network in the cloud environment; For the at least one virtual network, maintain an existing routing table; Create a new routing table for the at least one virtual network; Add a default route pointing to the cloud gateway to the new routing table; Enable route propagation based on the new routing table; and The cloud gateway is associated with the connection gateway, wherein the announced prefix list is set as address prefixes for the at least one virtual network.

18. The non-transitory computer-readable storage medium according to any one of claims 15 to 17, wherein, The instructions for configuring the connection between the at least one routing domain and the at least one virtual network in the locally deployed site also enable the processor to: Provide BGP configuration to the SDWAN router; Provide segment configuration to the SDWAN router; and Based on Virtual Local Area Network (VLAN), sub-interface configuration is provided to the SDWAN router.

19. The non-transitory computer-readable storage medium according to any one of claims 15 to 17, wherein, The instructions also enable the processor to: Update the aforementioned tags; Automatically discover connections affected by the aforementioned tag; Automatically discover one or more virtual networks in the cloud environment that are affected by the tag; as well as Attach a new cloud gateway to the one or more virtual networks affected by the label.

20. The non-transitory computer-readable storage medium according to claim 19, wherein, The instructions also enable the processor to: Update the existing routing tables for the one or more virtual networks affected by the label; Enable route propagation based on the existing routing table; and The new cloud gateway is attached to the affected connection gateway, which belongs to the connection affected by the tag and the one or more virtual networks affected by the tag.

21. An apparatus for providing connectivity to cloud resources, comprising: A component for receiving a tag that associates at least one routing domain in an on-premises deployment site with at least one virtual network in a cloud environment associated with a cloud service provider (CSP); Components for configuring virtual cross-connections (VXCs) on software-defined wide area network (SDWAN) routers associated with a software-defined cloud infrastructure (SDCI) provider, the VXCs connecting the on-premises deployment site to the cloud environment associated with the CSP; Components used to assign Border Gateway Protocol (BGP) parameters to the VXC; Components for configuring BGP peering on the connectivity gateway in the cloud environment associated with the CSP; Components for connecting the connectivity gateway to the at least one virtual network in the cloud environment; Components used to label the at least one virtual network with the label; as well as Components for configuring connections between at least one routing domain in the on-premises deployment site and at least one virtual network in the cloud environment, wherein the connections are at least partially based on the tags.

22. The apparatus of claim 21, further comprising components for implementing the method of any one of claims 2 to 7.

23. A computer program product or computer-readable medium comprising instructions that, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 7.