Automated and scalable multi-level redundancy of cloud infrastructure
By configuring SDWAN tunnels, virtual Layer 2 connections, and BGP sessions, the automation and expansion issues of multi-level redundant connections in cloud infrastructure management are resolved, enabling dynamic and reliable redundant connection management to support the continuous growth of business needs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-07
- Publication Date
- 2026-03-13
AI Technical Summary
Existing cloud infrastructure management lacks automated and seamless network solutions, making it difficult to achieve dynamic, scalable, multi-level redundant connectivity.
By configuring software-defined wide area network (SDWAN) tunnels, virtual Layer 2 connections, and border gateway protocol (BGP) sessions, combined with automated management of virtual cloud resources (VCRs) and cloud service providers (CSPs), the redundancy of paths, networks, data centers, and cloud can be automated and scaled.
It enables dynamic, automated, and scalable multi-level redundant connectivity for cloud infrastructure, supporting the continuous growth of business needs, and dynamically managing and monitoring connection status through an orchestrator to ensure high reliability and flexibility.
Smart Images

Figure CN116746118B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims the benefit and priority of U.S. non-provisional patent application No. 17 / 389,122, filed July 29, 2021, which claims the benefit and priority of U.S. non-provisional patent application No. 63 / 172,463, filed April 8, 2021, entitled “Scalable Multi-Level Redundancy To Access Cloud Resources,” each of which is incorporated herein by reference in its entirety. Technical Field
[0003] This technology generally relates to the field of computer networking, and more specifically, to methods, systems, and nontransitory computer-readable storage media for automating and extending multi-level redundancy of cloud infrastructure. Background Technology
[0004] As cloud resource infrastructure becomes increasingly complex and enterprise functions become more essential, the demand for network solutions that provide easy management of cloud infrastructure connectivity is growing. However, there is currently no known on-premises controller that provides automated or seamless management of cloud infrastructure. Attached Figure Description
[0005] To describe the various advantages and features that can be obtained from this disclosure, a more specific description of the principles briefly described above will be presented by reference to specific embodiments thereof illustrated in the accompanying drawings. It should be understood that these drawings depict only exemplary embodiments of this disclosure and should not be considered as limiting its scope. The principles herein are described and explained with additional specificity and detail using the drawings, in which:
[0006] Figure 1 Examples of advanced network architectures based on some examples of this disclosure are shown;
[0007] Figure 2 Examples of network topologies based on some examples of this disclosure are shown;
[0008] Figure 3 Examples of diagrams illustrating the operation of protocols for managing overlay networks, according to some examples of this disclosure;
[0009] Figure 4 Examples illustrating the operation of a virtual private network for segmenting a network are shown, according to some examples of this disclosure;
[0010] Figures 5A to 5DAn example system for automating and scaling multi-level redundancy of cloud infrastructure is shown, according to some examples of this disclosure;
[0011] Figures 6A to 6C An example graphical user interface for automating and scaling multi-level redundancy of cloud infrastructure is shown, according to some examples of this disclosure;
[0012] Figure 7 This is a flowchart illustrating a method for automating and scaling multi-level redundancy in cloud infrastructure, based on examples of this disclosure; and
[0013] Figure 8 An example of a system used to implement some aspects of this technology is shown. Detailed Implementation
[0014] Various embodiments of this disclosure are discussed in detail below. Although specific implementations are discussed, it should be understood that this is done for illustrative purposes only. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of this disclosure. Therefore, the following description and drawings are illustrative and should not be construed as limiting. Numerous specific details are described to provide a thorough understanding of this disclosure. However, in some cases, well-known or conventional details have not been described to avoid obscuring the description. References to one embodiment or an embodiment in this disclosure may be references to the same embodiment or any embodiment; and such references indicate at least one embodiment.
[0015] The reference to "an embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment of this disclosure. The appearance of the phrase "in one embodiment" in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. Furthermore, various features that may be manifested by some embodiments but not others are described.
[0016] In the context of this disclosure and in the specific context in which each term is used, the terms used herein generally have their common meaning in the art. Alternative languages and synonyms may be used for any one or more of the terms discussed herein and should not be given special meaning in relation to whether a term is stated or discussed herein. In some cases, synonyms for certain terms are provided. The statement of one or more synonyms does not preclude the use of other synonyms. The use of examples anywhere in this specification, including examples of any terms discussed herein, is merely illustrative and is not intended to further limit the scope and meaning of this disclosure or any example terms. Likewise, this disclosure is not limited to the various embodiments given in this specification.
[0017] Without intending to limit the scope of this disclosure, examples of instruments, apparatus, methods, and related results according to embodiments of this disclosure are given below. Note that headings or subheadings may be used in the examples for the reader's convenience, which should in no way limit the scope of this disclosure. Unless otherwise defined, the technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. In case of conflict, this document (including the definitions) shall prevail. Additional features and advantages of this disclosure will be set forth in the description which follows, and in part will be apparent from the description, or may be learned by practicing the principles disclosed herein. The features and advantages of this disclosure may be realized and obtained by means and combinations thereof specifically pointed out in the appended claims. These and other features of this disclosure will become more fully apparent from the following description and the appended claims, or may be learned by practicing the principles set forth herein.
[0018] Overview
[0019] The invention is set forth in the independent claims, and preferred features are set forth in the dependent claims. A feature of one aspect may be applied individually to each aspect or in combination with other aspects to each aspect.
[0020] Systems, methods, and computer-readable media are provided for establishing redundant path connections. Example methods may include configuring a software-defined wide area network (SDWAN) tunnel between a local router and multiple SDWAN routers. The method may also include configuring a virtual Layer 2 connection between multiple SDWAN routers and a handover location of at least one Virtual Cloud Resource (VCR) associated with at least one VCR label, wherein a software-defined cloud infrastructure (SDCI) lower layer associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the handover location. The method may also include configuring a VCR connection between at least one VCR associated with at least one VCR label and the handover location of that at least one VCR. The method may further include configuring a Border Gateway Protocol (BGP) session between multiple SDWAN routers and the handover location. The method may also include verifying the SDWAN tunnel, the virtual Layer 2 connection, the VCR connection, and the BGP session.
[0021] In some examples of this method, configuring an SDWAN tunnel between a local router and multiple SDWAN routers may include instantiating multiple SDWAN routers at multiple physical locations, where the multiple physical locations may be provided by at least one SDCI provider.
[0022] In some examples of this method, configuring a virtual Layer 2 connection between multiple SDWAN routers and a switching location may include providing a switching location with at least one VCR label to multiple SDWAN routers and at least one SDCI provider.
[0023] In some examples, the method also includes generating a virtual interface in the CSP account associated with the user and associating the virtual interface with the switching location.
[0024] In some examples, the method further includes receiving an extension request that includes at least one of the following: an SDCI account, an SDWAN router among multiple SDWAN routers, a primary and secondary handover locations, workload labels, and a Virtual Private Network (VPN) segment. The method may also include: verifying the extension request. The method may further include: providing Layer 2 Virtual Cross-Connect (VXC) from the SDWAN router to the primary and secondary handover locations, route propagation of workloads associated with workload labels, BGP peering, and site prioritization. The method may also include: configuring the SDWAN router, and verifying at least one of network redundancy, data center redundancy, and cloud redundancy.
[0025] In some examples, the method further includes: selecting an SDCI account, an SDWAN router among multiple SDWAN routers, and a set of connections for expansion. The method may also include: retrieving information about the set of connections used for expansion. The method may also include: providing Layer 2 Virtual Cross-Connect (VXC) routing from the SDWAN router to the switch location, workload route propagation, BGP peering, and site prioritization. The method may also include: configuring the SDWAN router. The method may also include: verifying redundancy.
[0026] In some examples, the method also includes detecting a connectivity failure in one of the following: an SDWAN tunnel, a virtual Layer 2 connection, a VCR connection, or a BGP session. The method may also include attempting to reconcile the connectivity failure. The method may further include notifying the user equipment of the connectivity failure. The method may also include reconfiguring the connection associated with the connectivity failure in response to a request from the user equipment.
[0027] The example system may include one or more processors and at least one computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the one or more processors to configure software-defined wide area network (SDWAN) tunnels between a local router and multiple SDWAN routers. These instructions may also cause the one or more processors to configure virtual Layer 2 connectivity between multiple SDWAN routers and a switchover location of at least one Virtual Cloud Resource (VCR) associated with at least one VCR label, wherein a software-defined cloud infrastructure (SDCI) lower layer associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the switchover location. These instructions may also cause the one or more processors to configure VCR connectivity between at least one VCR associated with at least one VCR label and the switchover location of at least one VCR. These instructions may also cause the one or more processors to configure Border Gateway Protocol (BGP) sessions between multiple SDWAN routers and switchover locations. These instructions may also cause the one or more processors to authenticate SDWAN tunnels, virtual Layer 2 connectivity, VCR connectivity, and BGP sessions.
[0028] An example non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to configure software-defined wide area network (SDWAN) tunnels between a local router and multiple SDWAN routers. These instructions can also cause one or more processors to configure virtual Layer 2 connectivity between multiple SDWAN routers and a handover location of at least one Virtual Cloud Resource (VCR) associated with at least one VCR label, wherein a software-defined cloud infrastructure (SDCI) lower layer associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the handover location. These instructions can also cause one or more processors to configure VCR connectivity between at least one VCR associated with at least one VCR label and the handover location of at least one VCR. These instructions can also cause one or more processors to configure Border Gateway Protocol (BGP) sessions between multiple SDWAN routers and handover locations. These instructions can also cause one or more processors to authenticate SDWAN tunnels, virtual Layer 2 connectivity, VCR connectivity, and BGP sessions.
[0029] Description of Example Implementations
[0030] This disclosure will first discuss examples of network architectures and topologies for software-defined wide area networks (SD-WAN), and various overlays for such networks. Then, this disclosure will discuss example embodiments for automating and scaling cloud infrastructure with multi-level redundancy. Finally, this disclosure will discuss example computing systems that can be used to implement various aspects of this technology.
[0031] Figure 1An example of a network architecture 100 for implementing various aspects of this technology is shown. An example of how the network architecture 100 is implemented is... SD-WAN architecture. However, those skilled in the art will understand that for network architecture 100 and any other system discussed in this disclosure, there may be more or fewer components in similar or alternative configurations. For brevity and clarity, illustrations and examples are provided in this disclosure. Other embodiments may include different numbers and / or types of elements, but those skilled in the art will recognize that these variations do not depart from the scope of this disclosure.
[0032] In this example, network architecture 100 may include an orchestration plane 102, a management plane 120, a control plane 130, and a data plane 140. Orchestration plane 102 may assist in the automatic on-boarding of edge network devices 142 (e.g., switches, routers, etc.) within the network. Orchestration plane 102 may include one or more physical or virtual network orchestrator devices 104. The network orchestrator devices 104 may perform initial authentication of the edge network devices 142 and orchestrate connections between devices in the control plane 130 and data plane 140. In some embodiments, the network orchestrator devices 104 may also enable communication for devices located behind Network Address Translation (NAT). In some embodiments, physical or virtual... The SD-WAN vBond device can operate as one or more network orchestrator devices 104.
[0033] Management plane 120 can be responsible for the central configuration and monitoring of the network. Management plane 120 may include one or more physical or virtual network management devices 122. In some embodiments, the network management devices 122 may provide centralized management of the network via a graphical user interface, enabling users to monitor, configure, and maintain edge network devices 142 and links (e.g., Internet transport network 160, MPLS network 162, 4G / LTE network 164) in the underlying and overlay networks. The network management devices 122 may support multi-tenancy and enable centralized management of logically isolated networks (networks associated with different entities, such as enterprises, departments within enterprises, groups within departments, etc.). Alternatively or additionally, the network management devices 122 may be dedicated network management systems for a single entity. In some embodiments, physical or virtual The SD-WAN vManage device can operate as one or more network management devices 122. The management plane 120 may include an analytics engine 124 that provides analytics for the network.
[0034] Control plane 130 can build and maintain network topology and determine where traffic flows. Control plane 130 may include one or more physical or virtual network controller devices 132. The network controller devices 132 can establish secure connections to each network device 142 and distribute routing and policy information via control plane protocols such as Overlay Management Protocol (OMP) (discussed in further detail below), Open Shortest Path First (OSPF), Intermediate System to Intermediate System (IS-IS), Border Gateway Protocol (BGP), Protocol Independent Multicast (PIM), Internet Group Management Protocol (IGMP), Internet Control Message Protocol (ICMP), Address Resolution Protocol (ARP), Bidirectional Forwarding Detection (BFD), Link Aggregation Control Protocol (LACP), etc. In some embodiments, the network controller devices 132 may operate as route reflectors. The network controller devices 132 may also orchestrate secure connections in the data plane 140 between two or more edge network devices 142. For example, in some embodiments, the network controller devices 132 may distribute encryption key information between the network devices 142. This allows the network to support secure network protocols or applications (e.g., Internet Security Protocol (IPSec), Transport Layer Security (TLS), Secure Shell Protocol (SSH), etc.) without Internet Key Exchange (IKE) and enables network scalability. In some embodiments, physical or virtual The SD-WAN vSmart controller can operate as one or more network controller devices 132.
[0035] Data plane 140 can be responsible for forwarding packets based on decisions from control plane 130. Data plane 140 may include edge network device 142, which can be a physical or virtual network device. Edge network device 142 can operate at the edge of an organization's various network environments, such as in one or more data centers or hosting centers 150, campus network 152, branch office network 154, home office network 154, etc., or in the cloud (e.g., Infrastructure as a Service (IaaS), Platform as a Service (PaaS), SaaS, and other cloud service provider networks). Edge network device 142 can provide secure data plane connectivity between sites via one or more WAN transports, such as via one or more Internet transport networks 160 (e.g., Digital Subscriber Line (DSL), cable, etc.), MPLS network 162 (or other dedicated packet-switched networks (e.g., Metro Ethernet, Frame Relay, Asynchronous Transfer Mode (ATM), etc.), mobile network 164 (e.g., 3G, 4G / LTE, 5G, etc.) or other WAN technologies (e.g., Synchronous Optical Network (SONET), Synchronous Digital Hierarchy (SDH), Dense Wavelength Division Multiplexing (DWDM) or other fiber optic technologies; leased lines (e.g., T1 / E1, T3 / E3, etc.); Public Switched Telephone Network (PSTN), Integrated Services Digital Network (ISDN), or other dedicated circuit-switched networks; Small Aperture Terminal (VSAT) or other satellite networks; etc.). Edge network device 142 can be responsible for tasks such as traffic forwarding, security, encryption, Quality of Service (QoS), and routing (e.g., BGP, OSPF, etc.). In some embodiments, physical or virtual The SD-WAN vEdge router can operate as an edge network device 142.
[0036] Figure 2An example of a network topology 200 is shown to illustrate various aspects of network architecture 100. Network topology 200 may include: a management network 202, a pair of network sites 204A and 204B (collectively referred to as “network sites 204”) (e.g., one or more data centers 150, one or more campus networks 152, one or more branch office networks 154, one or more home office networks 156, one or more cloud service provider networks, etc.), and a pair of internet transport networks 160A and 160B (collectively referred to as “internet transport network 160”). Management network 202 may include one or more network orchestrator devices 104, one or more network management devices 122, and one or more network controller devices 132. Although management network 202 is shown as a single network in this example, those skilled in the art will understand that each element of management network 202 can be distributed across any number of networks and / or coexist with site 204. In this example, each element of management network 202 can be reached via transport network 160A or 160B.
[0037] Each site may include one or more endpoints 206 connected to one or more site network devices 208. Endpoints 206 may include general-purpose computing devices (e.g., servers, workstations, desktop computers, etc.), mobile computing devices (e.g., laptops, tablets, mobile phones, etc.), wearable devices (e.g., watches, glasses or other head-mounted displays (HMDs), headsets, etc.), etc. Endpoint 206 may also include Internet of Things (IoT) devices or apparatuses, such as agricultural apparatus (e.g., livestock tracking and management systems, irrigation equipment, unmanned aerial vehicles (UAVs), etc.); connected cars and other vehicles; smart home sensors and apparatus (e.g., alarm systems, security cameras, lighting, appliances, media players, HVAC units, utility meters, windows, automatic doors, doorbells, locks, etc.); office apparatus (e.g., desktop telephones, copiers, fax machines, etc.); medical devices (e.g., pacemakers, biosensors, medical devices, etc.); industrial apparatus (e.g., robots, factory machinery, construction equipment, industrial sensors, etc.); retail apparatus (e.g., vending machines, point-of-sale (POS) equipment, radio frequency identification (RFID) tags, etc.); smart city apparatus (e.g., streetlights, parking meters, waste management sensors, etc.); transportation and logistics apparatus (e.g., revolving doors, rental car trackers, navigation devices, inventory monitors, etc.), etc.
[0038] Site network device 208 may include physical or virtual switches, routers, and other network devices. Although in this example, site 204A is shown as including a pair of site network devices and site 204B is shown as including a single site network device, site network device 208 may include any number of network devices in any network topology, including multi-layer (e.g., core, distribution, and access layers), spine-leaf, mesh, tree, bus, hub, and spoke, etc. For example, in some embodiments, one or more data center networks may be implemented. Application Center Infrastructure (ACI) architecture and / or one or more campus networks can achieve Software-defined access (SD access or SDA) architecture. Site network device 208 can connect endpoint 206 to one or more edge network devices 142, and edge network devices 142 can be used to directly connect to transport network 160.
[0039] In some embodiments, "color" can be used to identify individual WAN transport networks, and different WAN transport networks can be assigned different colors (e.g., MPLS, Private1, Commercial Internet, Metro Ethernet, LTE, etc.). In this example, network topology 200 can use the color referred to as "Commercial Internet" for Internet transport network 160A, and use the color referred to as "Public Internet" for Internet transport network 160B.
[0040] In some embodiments, each edge network device 208 may form a Datagram Transport Layer Security (DTLS) or TLS Control connection to one or more network controller devices 132 and connect to any network controller device 132 via each transport network 160. In some embodiments, edge network device 142 may also securely connect to edge network devices in other sites via IPSec tunnels. In some embodiments, the BFD protocol may be used in each of these tunnels to detect loss, latency, jitter, and path failures.
[0041] On edge network device 142, colors can be used to help identify or differentiate individual WAN transport tunnels (e.g., the same color cannot be used twice on a single edge network device). The colors themselves are also important. For example, the colors for metro-ethernet, MPLS, and private1, private2, private3, private4, private5, and private6 can be considered dedicated colors. These dedicated colors can be used in private networks or where there is no NAT addressing at the transport IP endpoints (e.g., because there may be no NAT between two endpoints of the same color). When edge network device 142 uses dedicated colors, it can attempt to build IPSec tunnels to other edge network devices using local, dedicated, lower-layer IP addresses. Public colors can include 3g, business (biz), internet, blue, bronze, custom 1, custom 2, custom 3, default, gold, green, LTE, public internet, red, and silver. Public colors can be used by edge network device 142 to build tunnels to IP addresses behind NAT (if NAT is involved). If edge network device 142 uses a private color and requires NAT to communicate with other private colors, the ISP settings in the configuration can indicate whether edge network device 142 uses a private IP address or a public IP address. When one or both private colors use NAT, the two private colors can establish a session using this setting.
[0042] Figure 3 An example illustration of OMP operation is shown in diagram 300. OMP can be used in some embodiments to manage the overlay layer of a network (e.g., network architecture 100). In this example, OMP messages 302A and 302B (collectively referred to as 302) can be transmitted back and forth between network controller device 132 and edge network devices 142A and 142B, respectively, where control plane information (e.g., routing prefixes, next-hop routes, encryption keys, policy information, etc.) can be exchanged via corresponding secure DTLS or TLS connections 304A and 304B. Network controller device 132 can operate similarly to a route reflector. For example, network controller device 132 can receive routes from edge network devices 142, process them and apply any policies, and advertise routes to other edge network devices 142 in the overlay layer. If no policies are defined, edge network devices 142 can operate in a manner similar to a full mesh topology, in which each edge network device 142 can directly connect to another edge network device 142 at another site and receive complete routing information from each site.
[0043] OMP can advertise various types of routes. For example, OMP can advertise OMP routes, which can correspond to prefixes learned from the local site or service side of edge network device 142. Prefixes can be initiated as static routes or connection routes, or they can be initiated from protocols such as OSPF or BGP and reassigned to OMP so that they can be transmitted across the overlay layer. OMP routes can advertise attributes such as Transport Location (TLOC) information (which can be similar to a BGP next-hop IP address) and other attributes such as origin, initiator, preference, site identifier, label, and Virtual Private Network (VPN). If the TLOC pointed to by the OMP route is active, the OMP route can be installed in the forwarding table.
[0044] In another example, the OMP can advertise a TLOC route that corresponds to a logical tunnel endpoint connected to an edge network device 142 in the transport network 160. In some embodiments, a TLOC route can be uniquely identified and represented by a triplet including IP address, link color, and encapsulation (e.g., Generic Routing Encapsulation (GRE), IPSec, etc.). In addition to the system IP address, color, and encapsulation, the TLOC route can also convey attributes such as TLOC private and public IP addresses, carrier, preferences, site identifier, label, and weight. In some embodiments, a TLOC can be active on a specific edge network device 142 when an active BFD session is associated with it.
[0045] In another example, the OMP can advertise service routes, which may represent services (e.g., firewalls, distributed denial-of-service (DDoS) mitigators, load balancers, intrusion prevention systems (IPS), intrusion detection systems (IDS), WAN optimizers, etc.) that can connect to the local site of edge network device 142 and be accessible to other sites for service insertion. Furthermore, these routes may also include VPNs; VPN labels may be sent in update type to inform network controller device 132 which VPNs are being served at remote sites.
[0046] exist Figure 3In the example, OMP is shown running on a DTLS / TLS tunnel 304 established between edge network device 142 and network controller device 132. Furthermore, Figure 300 illustrates an IPSec tunnel 306A established between TLOC 308A and TLOC 308C via WAN transport network 160A, and an IPSec tunnel 306B established between TLOC 308B and TLOC 308D via WAN transport network 160B. Once IPSec tunnels 306A and 306B are established, BFD can be enabled on each of them.
[0047] Figure 4 An example illustration of a VPN 400 illustrating VPN operation is shown. These VPNs may be used in some embodiments to provide segmentation for a network (e.g., network architecture 100). VPNs may be isolated from each other and may have their own forwarding tables. Interfaces or sub-interfaces may be explicitly configured under a single VPN and may not be part of more than one VPN. Tags may be used in OMP routing attributes and packet encapsulation to identify the VPN to which a packet belongs. VPN numbers may be four-byte integers with values from 0 to 65530. In some embodiments, one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, and / or one or more edge network devices 142 may each include a transport VPN 402 (e.g., VPN 0) and an administrative VPN 404 (e.g., VPN 512). Transport VPN 402 may include one or more physical or virtual network interfaces (e.g., network interface 410A and network interface 410B) respectively connected to a WAN transport network (e.g., MPLS network 162 and Internet transport network 160). Secure DTLS / TLS connections to or between network controller device 132 or between network controller device 132 and network orchestrator device 104 can be initiated from transport VPN 402. Furthermore, static or default routes or dynamic routing protocols can be configured within transport VPN 402 to obtain appropriate next-hop information, enabling control plane 130 to be established and IPSec tunnel 306 (not shown) to connect to remote sites.
[0048] Management VPN 404 can execute out-of-band management traffic to or from one or more network coordinator devices 104, one or more network management devices 122, one or more network controller devices 132, and / or one or more edge network devices 142 via network interface 410C. In some embodiments, management VPN 404 may not be transmitted across overlay networks.
[0049] In addition to the transport VPN 402 and the management VPN 404, one or more network orchestrator devices 104, one or more network management devices 122, one or more network controller devices 132, or one or more edge network devices 142 may also include one or more service-side VPNs 406. The service-side VPN 406 may include one or more physical or virtual network interfaces (e.g., network interface 410D and network interface 410E) connected to one or more local site networks 412 and transmitting user data traffic. The one or more service-side VPNs 406 may be enabled for functions such as OSPF or BGP, Virtual Router Redundancy Protocol (VRRP), QoS, traffic shaping, control, etc. In some embodiments, user traffic can be routed to other sites via IPSec tunnels by reallocating OMP routes received at site 412 from one or more network controller devices 132 into the service-side VPN routing protocol. Furthermore, by advertising the service VPN route to the OMP routing protocol, routes from local site 412 can be advertised to other sites. This OMP routing protocol can be sent to (one or more) network controller devices 132 and redistributed to other edge network devices 142 in the network. Although network interfaces 410A to 410E (collectively referred to as "network interface 410") are shown as physical interfaces in this example, those skilled in the art will recognize that interface 410 in the transport VPN and service VPN can also be a sub-interface.
[0050] This disclosure now turns to discuss examples of multi-level redundancy for automating and scaling cloud infrastructure.
[0051] There is a need in the field for a cloud infrastructure architecture that enables network administrators to dynamically enable or dismantle fully automated and scalable redundant connections from sites (e.g., on-premises branches) to cloud service providers (CSPs). As explained in this paper, in some examples, an orchestrator providing the underlying layer can provide this service, connecting sites (e.g., on-premises branches) to one or more Software-Defined Cloud Interconnect (SDCI) platforms and CSPs. As business demands increase, continuous and scalable connectivity and continuity are increasingly beneficial for modern operations.
[0052] Figures 5A to 5D An example system with multi-level redundancy for automating and scaling cloud infrastructure is shown. Various example redundancies are illustrated in each figure.
[0053] Sites 500-1, 500-2, 500-3, 500-4, and 500-5 (hereinafter collectively referred to as "Site 500") can be various local branch sites of an entity (e.g., a business) and can be similar to Figure 1 The examples shown are campus 152, branch office 154, or home office 156. Site 500 can connect to SDWAN architecture 510, which can contain router 520. SDWAN architecture 510 can be similar to... Figure 2 Networks 204A and 204B are shown.
[0054] Router 520 can connect site 500 to dedicated site 530 and / or SDCI network 540-1 and / or SDCI network 540-2 (collectively referred to as "SDCI network 540") via interconnect gateways 550-1, 550-2, 550-3, and 550-4 (collectively referred to as "interconnect gateway 550"). Interconnect gateway 550 and connection gateways 570-1, 570-2, 570-3, and 570-4 (collectively referred to as "connection gateway 570") can be routers or network edge devices. Interconnect gateway 550 can connect SDWAN structure 510 to SDCI network 540. Gateway 570 can connect SDCI network 540 to cloud service provider 560-1 and cloud service provider 560-2 (collectively referred to as "cloud service provider 560").
[0055] In some examples, SDCI Network 540 can be a software-defined cloud infrastructure network. In some cases, SDCI Network 540 can be similar to... Figure 2 Networks 204A and 204B are shown. SDCI network 540 can be used as an intermediate network between SDWAN architecture 510 and cloud service provider 560.
[0056] Cloud service providers 560 may include similar Figure 2 The networks shown are 204A and 204B. Cloud service provider 560 may include gateways 580-1 and 580-2 (collectively referred to as "gateway 580") and virtual cloud resources 590-1 and 590-2 (collectively referred to as "virtual cloud resources 590"). Cloud service provider 560 may also be accessed by routers 595-1 and 595-2 (collectively referred to as "router 595").
[0057] In some examples, virtual cloud resource 590 may include a private network hosted by one or more cloud networks and / or infrastructure associated with cloud service provider 560. For example, in some cases, cloud service provider 560 may be Amazon Web Services (AWS), virtual cloud resource 590 may be a virtual private cloud, and connection gateway 570 may be a direct connection gateway. In another example, cloud service provider 560 may be Google Cloud, virtual cloud resource 590 may be a virtual private cloud, and connection gateway 570 may be a Google Cloud router.
[0058] like Figure 5A As shown, path redundancy can be achieved by configuring connections between router 520 and multiple interconnecting gateways 550. In some examples, a dedicated site 530 can be used to establish path redundancy. Path redundancy allows redundant paths to access workloads and / or resources based on: site priority, path attributes (e.g., AS-PATH attribute), Border Gateway Protocol (BGP) Multiple Exit Discriminator (MED) configuration, prefix, control plane data, service level protocol, service constraints, network conditions, and / or other factors.
[0059] like Figure 5B As shown, network redundancy can be achieved by configuring a connection between the first interconnect gateway 550 and the first connection gateway 570 in the first SDCI network 540, and then configuring a connection between the second interconnect gateway 550 and the second connection gateway 570 in the second SDCI network 540. Network redundancy allows redundant SDCI networks 540 to access workloads through interconnect gateways 550 in different SDCI networks 540.
[0060] like Figure 5C As shown, data center redundancy can be achieved by configuring connections between connection gateway 570 and multiple interconnect gateways 550. Data center redundancy allows redundant sites 500 to access workloads through multiple interconnect gateways 550.
[0061] like Figure 5D As shown, cloud redundancy can be achieved by configuring connections from interconnect gateway 550 to multiple connection gateways 570 or routers 595. Cloud redundancy allows redundant virtual cloud resources 590 to access workloads through multiple connection gateways 570.
[0062] From the perspective of site 500 using an orchestrator (e.g., Cisco vManage), all these connections can be dynamically configured and managed. Resources in the traffic path, including router 520, interconnect gateway 550, and connection gateway 570, can all be provided and managed by the orchestrator. Network administrators can manage and scale the number of redundant paths for workloads based on requirements or other factors. (See reference...) Figures 6A to 6C Let's discuss further details.
[0063] In summary, this allows the orchestrator to manage path redundancy, network redundancy, data center redundancy, and cloud redundancy. Traffic paths can be determined based on prefix advertisements or BGP MEDs configured during the connection creation process. These connections can be end-to-end, configurable, scalable, and / or automated.
[0064] For example, an orchestrator can be used to enable redundant connectivity in an automated manner. To illustrate, the orchestrator can instantiate multiple interconnect gateways 550 at different physical locations within and / or on multiple SDCI networks 540, thereby achieving data center redundancy. The orchestrator can establish SDWAN tunnels between a router 520 and the instantiated interconnect gateways 550 running in one or more SDCI networks 540. Priority can be assigned to any of the sites 500 for each interconnect gateway 550. The orchestrator can provide the locations of the interconnect gateways 550 and one or more SDCI networks 540, where the SDCI lower layer switches to a cloud service provider 560 at these locations to obtain any Virtual Cloud Resource (VCR) label corresponding to a Virtual Cloud Resource 590 to be connected to the site 500.
[0065] The orchestrator can internally automate the configuration of the lower layers by creating virtual Layer 2 (L2) connections from the selected interconnect gateway 550 to the SDCI switch location. Virtual interfaces can be created in the account associated with the cloud service provider 560 as part of this operation. The orchestrator can create connection gateways 570 and other gateways 580 in the cloud service provider 560's account to access the virtual cloud resource 590. The orchestrator can automate routing by creating and managing the routing table for the virtual cloud resource 590. To achieve intra-cloud redundancy, the orchestrator can automate the creation of multiple connections between the connection gateways 570 and the virtual cloud resource 590. The orchestrator can internally associate the virtual interfaces created in the account associated with the cloud service provider 560 with the created connection gateway 570. The orchestrator can configure BGP sessions between the interconnect gateway 550 and the connection gateway 570. BGP MED can be configured to dynamically select the preferred path. The orchestrator can verify that redundant connections have been successfully created.
[0066] At the end of the process, a network administrator or other agent operating at site 500 can access virtual cloud resource 590 from site 500.
[0067] The orchestrator can also automatically extend connectivity to the virtual cloud resource 590 within the SDCI network 540. For illustration, the orchestrator can instantiate new interconnect gateways 550 at different physical locations within the SDCI network 540. Given a set of existing connections to be replicated, the orchestrator can automate the replication of connections from the new interconnect gateway 550 to the virtual cloud resource 590. This replication process is similar to the detailed process described above.
[0068] The orchestrator can monitor automatically. Figures 5A to 5D The system displays the health and status of all connections. If a link failure is detected, the orchestrator can attempt to reconcile the connection. It can also reconfigure failed connections in response to requests.
[0069] Figures 6A to 6C An example graphical user interface for the arranger discussed with reference to Figure 5 is shown.
[0070] Figure 6A An example graphical user interface (GUI) 600 is shown. In this example, GUI 600 can display something similar to... Figures 5A to 5D The number of interconnect gateways 550 shown and / or the number of connections in the cloud infrastructure. GUI 600 may display a search bar for searching through interconnect gateways. GUI 600 may display information about each interconnect gateway and / or associated with each interconnect gateway, such as, but not limited to, information about the associated provider, region, connection, resource status, account ID, gateway ID, and / or any other relevant information.
[0071] Figure 6B A graphical user interface (GUI) 610 is shown. In this example, GUI 610 can display available interconnect gateways (e.g., a drop-down menu when clicked in this example). For the selected interconnect gateway, for example... Figure 6B The ICFW-V2 GUI 610 can display status and location information. Clicking "Add Connection" allows you to create a new connection.
[0072] Figure 6C A graphical user interface (GUI) 620 is shown. When "Auto-Expand" is selected, GUI 620 enables an interface to select the interconnect gateways and existing connections for auto-expansion. The selected connections can be automatically cloned to the selected interconnect gateway.
[0073] Figure 7An example method 700 for establishing redundant path connections is illustrated. Although example method 700 depicts a specific sequence of operations, this sequence can be changed without departing from the scope of this disclosure. For example, some of the depicted operations can be performed in parallel or in a different order that does not substantially affect the functionality of method 700. In other examples, different components of the example device or system implementing method 700 can perform their functions substantially simultaneously or in a specific order.
[0074] At box 710, method 700 includes configuring a software-defined wide area network tunnel between a local router and multiple SDWAN routers. For example, Figure 1 The network orchestrator device 104 shown can configure software-defined wide area network tunnels between a local router and multiple SDWAN routers.
[0075] In another example of configuring a software-defined WAN tunnel at box 710, method 700 may include: instantiating multiple SDWAN routers at multiple physical locations, each provided by at least one SDCI provider. For example, Figure 1 The network orchestrator device 104 shown can instantiate multiple SDWAN routers at multiple physical locations, provided by at least one SDCI provider.
[0076] At box 720, method 700 includes configuring a virtual Layer 2 connection between multiple SDWAN routers and a switchover location of at least one Virtual Cloud Resource (VCR) associated with at least one VCR label. In some examples, the software-defined cloud infrastructure (SDC) lower layer associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the switchover location. For example, Figure 1 The network orchestrator device 104 shown can configure virtual Layer 2 connectivity between multiple SDWAN routers and the switching location of at least one VCR associated with at least one VCR label. VCR labels can logically group workloads and / or routing domains (e.g., virtual networks, prefixes, tenant spaces, etc.) that have one or more common characteristics, such as common security groups, common networks, common routing domains, common applicable policies, common entities, common functions, common tenants, common types of traffic, common types of workloads, common applications / services, etc. In some examples, VCR labels can logically group IaaS workloads using names defined by network administrator protocols or other protocols.
[0077] In another example of configuring the virtual layer at box 720, method 700 may include: providing a switching location for at least one VCR label to multiple SDWAN routers and at least one SDCI provider. For example, Figure 1 The network orchestrator device 104 shown can provide at least one VCR label switching location to multiple SDWAN routers and at least one SDCI provider.
[0078] At box 730, method 700 includes configuring a VCR connection between at least one VCR associated with at least one VCR label and a switching position of the at least one VCR. For example, Figure 1 The network orchestrator device 104 shown can configure VCR connections between at least one VCR associated with at least one VCR tag and the switching position of the at least one VCR tag.
[0079] At box 740, method 700 includes configuring a Border Gateway Protocol (BGP) session between multiple SDWAN routers and at least one handover location. For example, Figure 1 The network orchestrator device 104 shown can configure BGP sessions between multiple SDWAN routers and at least one switching location.
[0080] At frame 750, method 700 includes verifying the SDWAN tunnel, virtual Layer 2 connection, VCR connection, and BGP session. For example, Figure 1 The network orchestrator device 104 shown can verify SDWAN tunnels, virtual Layer 2 connections, VCR connections, and BGP sessions.
[0081] Figure 8 An example of a computing system 800 is shown, which may be, for example, any computing device or any component thereof constituting a network orchestrator device, wherein the components of the system communicate with each other using connection 805. Connection 805 may be a physical connection via a bus or a direct connection to processor 810, such as in a chipset architecture. Connection 805 may also be a virtual connection, a networking connection, or a logical connection.
[0082] In some embodiments, the computing system 800 is a distributed system, wherein the functions described herein may be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more of the described system components represent a plurality of such components, each performing some or all of the functions of the described components. In some embodiments, the components may be physical or virtual devices.
[0083] Example system 800 includes at least one processing unit (CPU or processor) 810 and system connection 805, which couples various system components, including system memory 815 (e.g., read-only memory (ROM) 820 and random access memory (RAM) 825), to processor 810. Computing system 800 may include a cache of high-speed memory 812, which is directly connected to, adjacent to, or integrated into processor 810.
[0084] Processor 810 may include any general-purpose processor and hardware or software services (e.g., services 832, 834, and 836 stored in storage device 830) configured to control processor 810 and dedicated processors, wherein software instructions are incorporated into the actual processor design. Processor 810 may essentially be a fully self-contained computing system containing multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.
[0085] To enable users to interact with the computing system 800, the computing system 800 includes an input device 845, which can represent any number of input mechanisms, such as a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice input, etc. The computing system 800 may also include an output device 835, which can be one or more of many output mechanisms known to those skilled in the art. In some cases, a multi-mode system allows users to provide multiple types of input / output to communicate with the computing system 800. The computing system 800 may include a communication interface 840, which typically controls and manages user input and system output. There are no limitations on operation for any particular hardware arrangement, and therefore the basic features described herein can be readily replaced by improved hardware or firmware arrangements as they are developed.
[0086] Storage device 830 may be a non-volatile memory and may be a hard disk or other type of computer-readable medium that can store data accessible by a computer, such as a magnetic tape cassette, flash memory card, solid-state memory device, digital multifunction disk, magnetic tape cassette, random access memory (RAM), read-only memory (ROM), and / or some combination of these devices.
[0087] Storage device 830 may include software services, servers, etc., which enable the system to perform functions when the code defining such software is executed by processor 810. In some embodiments, hardware services that perform a particular function may include software components stored in a computer-readable medium in association with necessary hardware components (such as processor 810, connection 805, output device 835, etc.) to perform that function.
[0088] In summary, this technology discloses methods, systems, and nontransitory computer-readable storage media for establishing redundant path connections. Example methods may include: configuring a software-defined wide area network (SDWAN) tunnel between a local router and multiple SDWAN routers; configuring a virtual Layer 2 connection between the multiple SDWAN routers and a handover location of a Virtual Cloud Resource (VCR) associated with at least one VCR label, wherein a software-defined cloud infrastructure (SDCI) lower layer associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the handover location; configuring a VCR connection between at least one VCR associated with a VCR label and the handover location of the at least one VCR; configuring a Border Gateway Protocol (BGP) session between the multiple SDWAN routers and the handover location; and verifying the SDWAN tunnel, the virtual Layer 2 connection, the VCR connection, and the BGP session.
[0089] For clarity, in some cases, this technology may be represented as comprising individual functional blocks, including functional blocks having the following: devices, device components, steps or routines in methods embodied in software, or combinations of hardware and software.
[0090] Any steps, operations, functions, or processes described herein may be performed or implemented, individually or in combination with other devices, through hardware and software services or combinations of services. In some embodiments, a service may be software residing in the memory of a client device and / or one or more servers of a content management system, and may perform one or more functions when a processor executes the software associated with the service. In some embodiments, a service is a program or collection of programs that performs a specific function. In some embodiments, a service may be considered a server. The memory may be a non-transitory computer-readable medium.
[0091] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transitory computer-readable storage media explicitly excludes media such as energy, carrier signals, electromagnetic waves, and the signals themselves.
[0092] The methods according to the examples above can be implemented using computer-executable instructions, which are stored in or otherwise made available from a computer-readable medium. Such instructions may include, for example, instructions and data that cause a general-purpose computer, special-purpose computer, or special-purpose processing device to perform a function or group of functions. Some of the computer resources used may be accessible via a network. The computer-executable instructions may be, for example, binary code, intermediate format instructions such as assembly language, firmware, or source code. Examples of computer-readable media that may be used to store instructions, information used, and / or information created during the methods according to the examples include hard disks or optical disks, flash memory, USB devices equipped with non-volatile memory, networked storage devices, etc.
[0093] Devices implementing the methods according to these disclosures may include hardware, firmware, and / or software, and may take any of a variety of form factors. Typical examples of such form factors include servers, laptops, smartphones, minicomputers, personal digital assistants, etc. The functionality described herein may also be implemented in peripheral devices or interposer cards. As a further example, such functionality may also be implemented on a circuit board between different chips or between different processes executing in a single device.
[0094] These instructions, the medium for conveying these instructions, the computing resources for executing such instructions, and other structures for supporting such computing resources are modules for providing the functionality described in these disclosures.
[0095] Aspect 1: A method for configuring redundant path connectivity, the method comprising: configuring a software-defined wide area network (SDWAN) tunnel between a local router and a plurality of SDWAN routers; configuring a virtual Layer 2 connection between the plurality of SDWAN routers and a connection gateway with at least one Virtual Cloud Resource (VCR) label, wherein a software-defined cloud infrastructure (SDCI) lower layer associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the connection gateway; configuring a VCR connection between at least one VCR associated with at least one VCR label and a connection gateway with at least one VCR label; configuring a Border Gateway Protocol (BGP) session between the plurality of SDWAN routers and at least one connection gateway; and verifying the SDWAN tunnel, the virtual Layer 2 connection, the VCR connection, and the BGP session.
[0096] Aspect 2: According to the method of Aspect 1, configuring an SDWAN tunnel between a local router and multiple SDWAN routers includes: instantiating multiple SDWAN routers at multiple physical locations, the multiple physical locations being provided by at least one SDCI provider.
[0097] Aspect 3: The method according to any one of Aspects 1 to 2, wherein configuring a virtual Layer 2 connection among multiple SDWAN routers and a connectivity gateway includes: providing a connectivity gateway with at least one VCR label to the multiple SDWAN routers and at least one SDCI provider.
[0098] Aspect 4: The method according to any one of Aspects 1 to 3 further includes: generating a virtual interface in a CSP account associated with the user; and associating the virtual interface with at least one connection gateway.
[0099] Aspect 5: The method according to any one of Aspects 1 to 4 further includes: extending at least one of network redundancy, data center redundancy, and cloud redundancy, comprising: receiving an extension request, the extension request including at least one of the following: an SDCI account, an SDWAN router among multiple SDWAN routers, a primary and secondary connectivity gateway, a workload label, and a virtual private network (VPN) segment; verifying the extension request; providing a Layer 2 virtual cross-connect (VXC) from the SDWAN router to the primary and secondary connectivity gateways, routing propagation of workloads associated with workload labels, BGP peering, and site prioritization; configuring the SDWAN router; and verifying at least one of network redundancy, data center redundancy, and cloud redundancy.
[0100] Aspect 6: The method according to any one of Aspects 1 to 5 further includes: extending redundancy within at least one SDCI provider, including: selecting SDCI accounts for extension, SDWAN routers among multiple SDWAN routers, and a set of connections; retrieving information about the set of connections for extension; providing Layer 2 Virtual Cross-Connect (VXC) from the SDWAN router to the connectivity gateway, routing propagation of workloads, BGP peering, and site prioritization; configuring the SDWAN router; and verifying redundancy.
[0101] Aspect 7: The method according to any one of Aspects 1 to 6 further includes: detecting a connection failure in one of the SDWAN tunnel, virtual Layer 2 connection, VCR connection, or BGP session; attempting to reconcile the connection failure; notifying the user equipment of the connection failure; and reconfiguring the connection associated with the connection failure in response to a request from the user equipment.
Claims
1. A method for establishing a redundant path connection, the method comprising: configuring a software-defined wide area network (SDWAN) tunnel between a local router and a plurality of SDWAN routers; configuring a virtual Layer 2 connection between the plurality of SDWAN routers and a switching location of at least one virtual cloud resource (VCR) associated with at least one VCR tag, wherein an SDCI underlay associated with at least one software-defined cloud infrastructure (SDCI) provider is connected to a cloud service provider (CSP) at the switching location; configuring a VCR connection between at least one VCR associated with the at least one VCR tag and the switching location of the at least one VCR; configuring a border gateway protocol (BGP) session between the plurality of SDWAN routers and the switching location to dynamically select a preferred packet path within the redundant path connection; validating the redundant path connection by validating the SDWAN tunnel, the virtual Layer 2 connection, the VCR connection, and the BGP session; and dynamically tearing down a connection to the local router and switching to a connection to a cloud service provider (CSP) based on validating the redundant path connection.
2. The method of claim 1, wherein, configuring the SDWAN tunnel between the local router and the plurality of SDWAN routers comprises: instantiating the plurality of SDWAN routers at a plurality of physical locations, the plurality of physical locations being provided by the at least one SDCI provider.
3. The method of claim 1 or 2, wherein, configuring the virtual Layer 2 connection between the plurality of SDWAN routers and the switching location comprises: providing the switching location of the at least one VCR tag to the plurality of SDWAN routers and the at least one SDCI provider.
4. The method of claim 1 or 2, further comprising: generating a virtual interface in a CSP account associated with a user; and associating the virtual interface with the switching location.
5. The method of claim 1 or 2, further comprising: receiving an expansion request, the expansion request comprising at least one of an SDCI account, an SDWAN router of the plurality of SDWAN routers, a primary switching location and a secondary switching location, a workload tag, and a virtual private network (VPN) segment; validating the expansion request; providing the Layer 2 virtual cross-connect (VXC) from the SDWAN router to the primary and secondary switching locations, route propagation of a workload associated with the workload tag, BGP peering, and site priority; configuring the SDWAN router; and validating at least one of network redundancy, data center redundancy, and cloud redundancy.
6. The method of claim 1 or 2, further comprising: selecting an SDCI account, an SDWAN router of the plurality of SDWAN routers, and a set of connections for expansion; retrieving information about the set of connections for expansion; providing the Layer 2 virtual cross-connect (VXC) from the SDWAN router to a switching location, route propagation of a workload, BGP peering, and site priority; configuring the SDWAN router; and verifying the redundancy.
7. The method of claim 1 or 2, further comprising: detecting a connection failure in one of: the SDWAN tunnel, the virtual Layer 2 connection, the VCR connection, or the BGP session; attempting to reconcile the connection failure; notifying a user device of the connection failure; and reconfiguring a connection associated with the connection failure in response to a request from the user device.
8. A system for establishing a redundant path connection, the system comprising: one or more processors; and at least one computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the one or more processors to perform the following operations: configuring a software-defined wide area network (SDWAN) tunnel between a local router and a plurality of SDWAN routers; configuring a virtual Layer 2 connection between the plurality of SDWAN routers and a switching location of at least one virtual cloud resource (VCR) associated with at least one VCR tag, wherein an SDCI underlay associated with at least one software-defined cloud infrastructure (SDCI) provider is connected to a cloud service provider (CSP) at the switching location; configuring a VCR connection between at least one VCR associated with the at least one VCR tag and the switching location of the at least one VCR; configuring a border gateway protocol (BGP) session between the plurality of SDWAN routers and the switching location to dynamically select a preferred packet path within the redundant path connection; verifying the redundant path connection by verifying the SDWAN tunnel, the virtual Layer 2 connection, the VCR connection, and the BGP session; and dynamically tearing down a connection to the local router and switching to a connection to a cloud service provider (CSP) based on verifying the redundant path connection. the instructions for configuring the SDWAN tunnel between the local router and the plurality of SDWAN routers cause the one or more processors to perform the following operations: instantiating the plurality of SDWAN routers at a plurality of physical locations, the plurality of physical locations being provided by the at least one SDCI provider.
9. The system of claim 8, wherein, the instructions for configuring the virtual Layer 2 connection between the plurality of SDWAN routers and the switching location cause the one or more processors to perform the following operations: providing the switching location of the at least one VCR tag to the plurality of SDWAN routers and the at least one SDCI provider.
10. The system of claim 8 or 9, wherein, the instructions are further effective to cause the one or more processors to perform the following operations: generating a virtual interface in a CSP account associated with a user; and 11. The system of claim 8 or 9, wherein, associating the virtual interface with the switching location. the instructions are further effective to cause the one or more processors to perform the following operations: 12. The system of claim 8 or 9, wherein, receiving an expansion request, the expansion request including at least one of: an SDCI account, an SDWAN router of the plurality of SDWAN routers, primary and secondary handoff locations, a workload tag, and a virtual private network (VPN) segment; validating the expansion request; providing layer 2 virtual cross connects (VXCs) from the SDWAN router to the primary and secondary handoff locations, route propagation of workloads associated with the workload tag, BGP peering, and site priority; configuring the SDWAN router; and validating at least one of network redundancy, data center redundancy, and cloud redundancy.
13. The system of claim 8 or 9, wherein, the instructions are further effective to cause the one or more processors to perform operations of: selecting an SDCI account, an SDWAN router of the plurality of SDWAN routers, and a set of connections for expansion; retrieving information about the set of connections for expansion; providing layer 2 virtual cross connects (VXCs) from the SDWAN router to handoff locations, route propagation of workloads, BGP peering, and site priority; configuring the SDWAN router; and validating the redundancy.
14. The system of claim 8 or 9, wherein, the instructions are further effective to cause the one or more processors to perform operations of: detecting a connection failure in one of: the SDWAN tunnel, the virtual layer 2 connection, the VCR connection, or the BGP session; attempting to reconcile the connection failure; notifying a user device of the connection failure; and reconfiguring a connection associated with the connection failure in response to a request from the user device.
15. A non-transitory computer-readable storage medium for establishing a redundant path connection having instructions stored thereon that, when executed by a processor, cause the processor to perform operations of: configuring a software-defined wide area network (SDWAN) tunnel between a local router and a plurality of SDWAN routers; configuring a virtual layer 2 connection between the plurality of SDWAN routers and a handoff location of at least one VCR associated with at least one virtual cloud resource, VCR, tag, wherein, an SDCI underlay associated with at least one software-defined cloud infrastructure (SDCI) provider connects to a cloud service provider (CSP) at a handoff location; configuring a virtual circuit routing (VCR) connection between at least one VCR associated with the at least one VCR tag and a handoff location of the at least one VCR; configuring a border gateway protocol (BGP) session between the plurality of SDWAN routers and the handoff location to dynamically select a preferred packet path within the redundant path connection; validating the redundant path connection by validating the SDWAN tunnel, the virtual layer 2 connection, the VCR connection, and the BGP session; and dynamically tearing down a connection to the local router and handoff to a connection to a cloud service provider (CSP) based on validating the redundant path connection.
16. The non-transitory computer-readable storage medium of claim 15, wherein, the instructions for configuring the SDWAN tunnel between the local router and the plurality of SDWAN routers cause the processor to perform operations of: instantiating the plurality of SDWAN routers at a plurality of physical locations, the plurality of physical locations provided by the at least one SDCI provider.
17. The non-transitory computer-readable storage medium of claim 15 or 16, wherein, instructions to configure the virtual layer 2 connection between the plurality of SDWAN routers and the switching location cause the processor to perform operations comprising: providing the plurality of SDWAN routers and the at least one SDCI provider with a switching location for the at least one VCR tag.
18. The non-transitory computer-readable storage medium of claim 15 or 16, wherein, the instructions are further effective to cause the processor to perform operations comprising: generating a virtual interface in a CSP account associated with a user; and associating the virtual interface with the switching location.
19. The non-transitory computer-readable storage medium of claim 15 or 16, wherein, the instructions are further effective to cause the processor to perform operations comprising: receiving an expansion request, the expansion request comprising at least one of: an SDCI account, an SDWAN router of the plurality of SDWAN routers, a primary and secondary switching location, a workload tag, and a virtual private network (VPN) segment; validating the expansion request; providing layer 2 virtual cross connects (VXCs) from the SDWAN router to the primary and secondary switching locations, route propagation of a workload associated with the workload tag, BGP peering, and site priority; configuring the SDWAN router; and validating at least one of network redundancy, data center redundancy, and cloud redundancy.
20. The non-transitory computer-readable storage medium of claim 15 or 16, wherein, the instructions are further effective to cause the processor to perform operations comprising: selecting an SDCI account, an SDWAN router of the plurality of SDWAN routers, and a set of connections for expansion; retrieving information about the set of connections for expansion; providing layer 2 virtual cross connects (VXCs) from the SDWAN router to a switching location, route propagation of a workload, BGP peering, and site priority; configuring the SDWAN router; and validating the redundancy.
21. An apparatus for establishing a redundant path connection, the apparatus comprising: means for configuring a software-defined wide area network (SDWAN) tunnel between a local router and a plurality of SDWAN routers; means for configuring a virtual layer 2 connection between the plurality of SDWAN routers and a switching location for at least one virtual cloud resource (VCR) tag associated with the at least one VCR, wherein a software-defined cloud infrastructure (SDCI) underlay associated with at least one SDCI provider is connected to a cloud service provider (CSP) at the switching location; means for configuring a VCR connection between at least one VCR associated with the at least one VCR tag and the switching location for the at least one VCR; means for configuring a border gateway protocol (BGP) session between the plurality of SDWAN routers and the switching location to dynamically select a preferred packet path within the redundant path connection; means for validating the redundant path connection by validating the SDWAN tunnel, the virtual layer 2 connection, the VCR connection, and the BGP session; and means for dynamically tearing down a connection to the local router and switching to a connection to a cloud service provider (CSP) based on validating the redundant path connection.
22. The apparatus of claim 21, further comprising: A module for implementing the method according to any one of claims 2 to 7.
23. A computer program product or a computer readable medium comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Layer two over multiple sites
CN102971992A
Virtual network construction method, system, and relaying apparatus
US20020067725A1
Redundancy between physical and virtual entities in hyper-converged infrastructures
US20210089402A1
Inter service network communication optimization
US9800474B1