Cloud network system and method of interaction of a cloud network system

By deploying virtual Layer 2 gateway devices and multiple tunnels in the cloud, combined with packet detection and device monitoring by the SDN controller, the problem of Layer 2 communication between virtual machines in the cloud and IDC data centers was solved, achieving efficient traffic communication and fault detection.

CN116996343BActive Publication Date: 2026-05-29CHINA TELECOM CORP LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD
Filing Date
2023-07-05
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, virtual machines in the cloud and data centers cannot be interconnected under the same subnet, resulting in the inability to perform Layer 2 traffic communication.

Method used

By deploying virtual Layer 2 gateway devices in the cloud, and using multi-segment tunneling to communicate with physical Layer 2 gateway devices in Internet data centers, and by using an SDN controller for packet probing and device monitoring, Layer 2 traffic communication between the cloud network and the IDC data center is achieved, and broadcast traffic is suppressed when loops or broadcast storms occur in the IDC data center.

Benefits of technology

It enables Layer 2 traffic communication between virtual machines in the cloud and physical servers in the IDC data center, avoiding the impact of IDC broadcast traffic on virtual machines in the cloud, and timely detecting and handling network faults.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116996343B_ABST
    Figure CN116996343B_ABST
Patent Text Reader

Abstract

The cloud network system and the interaction method of the cloud network system provided by the application belong to the technical field of communication network. The cloud network system comprises a cloud virtual machine, an Internet data center and a controller. The cloud virtual machine comprises a layer 2 gateway, a virtual gateway and a point-of-presence switch. The Internet data center comprises a tunnel switch, a router and a virtual network switch. The controller is used for mapping the virtual network of the Internet data center to a virtual network tunnel, so as to allocate tunnel configurations for each virtual network tunnel in the cloud network system. A layer 2 virtual network tunnel is constructed between the tunnel switch and the layer 2 gateway based on the tunnel configurations. The layer 2 virtual network tunnel comprises an inner layer virtual network tunnel between the tunnel switch and the layer 2 gateway, an outer layer virtual network tunnel between the layer 2 gateway and the virtual gateway, an outer layer virtual network tunnel between the point-of-presence switch and the virtual gateway, and a dedicated line virtual network tunnel between the router and the point-of-presence switch.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communication network technology, and specifically relates to a cloud network system and a method for interacting with the cloud network system. Background Technology

[0002] With the development of cloud network technology, cloud platforms can now support multi-resource deployments, ultra-large-scale clusters, and hardware-software collaboration. The core capabilities of resource pools meet the demands of providing ultra-large-scale, high-performance, secure, and reliable cloud services.

[0003] However, currently, virtual machines in the cloud can only communicate with traditional IDC (Internet Data Center) data centers through dedicated lines. But these dedicated lines are all Layer 3 dedicated lines, meaning that the IP address of the virtual machine in the cloud cannot be in the same subnet as the IP address of the IDC data center. This makes it impossible for virtual machines in the cloud to interconnect with the IDC data center under the same subnet. Summary of the Invention

[0004] This application provides a cloud network system and a method for interacting with the cloud network system.

[0005] Some embodiments of this application provide a cloud network system, which includes: a cloud virtual machine, an Internet data center, and a controller;

[0006] The cloud virtual machine includes: a Layer 2 gateway, a virtual gateway, and an inbound switch; the Internet data center includes: a tunnel switch, a router, and a virtual network switch.

[0007] The controller is used to map the virtual network of the Internet data center to the virtual network tunnel, so as to allocate tunnel configuration for each virtual network tunnel in the cloud network system.

[0008] A two-layer virtual network tunnel is constructed between the tunnel switch and the layer 2 gateway based on the tunnel configuration;

[0009] The Layer 2 virtual network tunnel includes: an inner virtual network tunnel between the tunnel switch and the Layer 2 gateway, an outer virtual network tunnel between the Layer 2 gateway and the virtual gateway, an outer virtual network tunnel between the inbound switch and the virtual gateway, and a leased line virtual network tunnel between the router and the inbound switch.

[0010] Optionally, the controller is further configured to:

[0011] The address resolution protocol information of the same subnet within the cloud is used as the MAC address of the Layer 2 gateway, and the virtual machine address of the same subnet within the cloud is used as the IP address of the Layer 2 gateway.

[0012] The address resolution protocol information is flooded through the inner virtual network tunnel between the Layer 2 gateway and the tunnel switch.

[0013] Optionally, the cloud network system further includes a monitoring module, wherein each network element node, computing node, and switch node in the cloud network system is equipped with a monitoring unit.

[0014] The monitored unit is used to collect statistics on the indicator parameters of each network element node, computing node, and switch node, and report the collected system information to the monitoring module.

[0015] Optionally, the controller is further configured to:

[0016] The tunnel switch periodically sends query messages to the devices on each virtual network tunnel.

[0017] The monitoring module is used to monitor the reception of the query message by each of the devices.

[0018] Optionally, the monitoring module is further configured to:

[0019] When the receiving status indicates that the device has not received the query message, an alarm message indicating a link failure is output.

[0020] Optionally, the monitoring module is further configured to:

[0021] When the receiving status reflects that the tunnel switch receives the query message, it outputs an alarm message indicating that there is a loop fault in the Internet data center.

[0022] Optionally, the controller is further configured to:

[0023] When the reception status indicates that the tunnel switch has received the query message, the port between the tunnel switch and the router is closed.

[0024] This application provides an interaction method for a cloud network system, which is applied to the aforementioned cloud network system. The method includes:

[0025] When the virtual machine on the second cloud actively accesses the virtual machine on the first cloud, it sends a message to the tunnel switch to obtain the address resolution protocol information of the virtual machine on the first cloud.

[0026] The tunnel switch sends the acquisition message to the router;

[0027] The route sends the acquired message to the Layer 2 gateway through the dedicated virtual network tunnel;

[0028] The Layer 2 gateway sends the acquired message to the first cloud virtual machine;

[0029] The first cloud virtual machine sends its own address resolution information to the Layer 2 gateway;

[0030] The Layer 2 gateway sends the address resolution information to the tunnel switch through the dedicated virtual network tunnel;

[0031] The tunnel switch sends the address resolution information to the second cloud virtual machine.

[0032] Some embodiments of this application provide a computing processing device, including:

[0033] Memory containing computer-readable code;

[0034] One or more processors, when the computer-readable code is executed by the one or more processors, the computing processing device performs the interaction method of the cloud network system as described above.

[0035] Some embodiments of this application provide a non-transient computer-readable medium that stores computer-readable code, which, when run on a computing processing device, causes the computing processing device to execute the aforementioned cloud network system interaction method.

[0036] This application provides a method for interaction between cloud network systems. By deploying virtual Layer 2 gateway devices within the cloud and interconnecting with physical Layer 2 gateway devices in internet data centers via multi-segment tunnels, it enables Layer 2 traffic communication between virtual machines in the cloud network and physical servers in the internet data center. Furthermore, it utilizes an SDN controller to perform packet probing and device monitoring of Layer 2 VXLAN devices. In the event of Layer 2 loops or broadcast storms in the IDC (Internet Data Center), the SDN controller proactively suppresses BUM (Broadcast Media Array) packets to prevent broadcast traffic from the IDC from reaching the cloud virtual machines and infrastructure.

[0037] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] Figure 1 The schematic diagram illustrates the architecture of a cloud network system provided in some embodiments of this application;

[0040] Figure 2 The diagram illustrates a network schematic of a cloud network system provided in some embodiments of this application.

[0041] Figure 3 The diagram illustrates, schematically, a data transmission diagram of a monitoring module provided in some embodiments of this application;

[0042] Figure 4 The schematic diagram illustrates a flowchart of an interaction method for a cloud network system provided in some embodiments of this application;

[0043] Figure 5 This illustration shows one of the data transmission diagrams of an interaction method for a cloud network system provided in some embodiments of this application;

[0044] Figure 6 The second schematic diagram illustrates a data transmission method of an interaction method for a cloud network system provided in some embodiments of this application.

[0045] Figure 7 A block diagram schematically illustrates a computing processing apparatus for performing methods according to some embodiments of this application;

[0046] Figure 8 A storage unit for holding or carrying program code implementing methods according to some embodiments of this application is illustrated schematically. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0048] Figure 1The schematic diagram illustrates the architecture of a cloud network system provided in this application, which includes: a cloud virtual machine 10, an Internet data center 20, and a controller 30.

[0049] The cloud virtual machine 10 includes: a Layer 2 gateway 101, a virtual gateway 102, and an inbound switch 103. The Internet data center 20 includes: a tunnel switch 201, a router 202, and a virtual network switch 203.

[0050] The controller 30 is used to map the virtual network of the Internet data center 20 to the virtual network tunnel, so as to allocate tunnel configuration for each virtual network tunnel in the cloud network system.

[0051] Reference Figure 2 The virtual network controlled by the SDN controller (Software Defined Network) is divided into three layers. The first layer is the TC zone, responsible for accessing external networks, including external network traffic, NAS (Network Attached Storage) traffic, leased line POPs (Point of Presence), high-speed cloud devices, and VPN (Virtual Private Network) devices. These devices all support multi-active access. Network elements deployed in this area include AGW (Access Gateway) and SGW (Service Gateway). The AGW is responsible for publishing public network CIDR (Classless Inter-Domain Routing), and the SGW is responsible for rate limiting. The second layer is the network element service zone, where deployed services provide layer 3 to layer 7 network services for virtual machines, including leased lines, IGW, NAT, VPN access, and load balancers. The third layer is the resource access layer, responsible for providing virtual network access services to virtual machines, containers, and bare metal. Network element types include DVRs and SmartNICs.

[0052] A two-layer virtual network tunnel is constructed between the tunnel switch 201 and the layer 2 gateway 101 based on the tunnel configuration.

[0053] The Layer 2 virtual network tunnel includes: an inner virtual network tunnel between the tunnel switch 201 and the Layer 2 gateway 101, an outer virtual network tunnel between the Layer 2 gateway 101 and the virtual gateway 102, an outer virtual network tunnel between the inbound switch 103 and the virtual gateway 102, and a dedicated line virtual network tunnel between the router 202 and the inbound switch.

[0054] In this embodiment, a new network element called a Layer 2 gateway (GW) is added within the cloud and deployed on a virtual machine. A tunnel switch supporting VXLAN (Virtual eXtensible LAN) is deployed in the customer-side IDC data center. The tunnel switch is configured via the SDN controller's netconf connection to establish an inner VXLAN tunnel with the Layer 2 gateway. Each VPC subnet's VXLAN tunnel has a unique ID, uniformly assigned by the controller to identify which subnet the Layer 2 traffic belongs to. The destination address of the cloud-encapsulated packets via the Layer 2 gateway's VXLAN tunnel is the address on the tunnel switch, here defined as 10.1.1.100, and the source address is the IP address on the Layer 2 gateway, defined as 192.1.2.20. Outside this tunnel, we encapsulate another VXLAN tunnel, from the Layer 2 gateway to the VGW (virtual gateway). The ID of this VXLAN packet is assigned by the controller to identify which VPC (Virtual Private Cloud) this tunnel belongs to. Then, the VGW connects to the POP (Point of Presence) switch, where another VXLAN tunnel is encapsulated. The ID of this VXLAN packet is also assigned by the controller to identify which VPC this tunnel belongs to. Finally, the POP switch connects to the customer's IDC router. Here, a leased line VXLAN tunnel is used. Each VPC's leased line has its own VXLAN tunnel ID, also uniformly assigned by the controller. All network element configurations along the entire path are uniformly distributed by the SDN controller. This is equivalent to building a Layer 2 VXLAN tunnel for the subnets within the VPC on the Layer 3 leased line of the cloud VPC, from the Layer 2 gateway to the tunnel switch. The tunnel switch uses the SDN controller to map Layer 2 VLANs to VXLANs, thus associating the VLANs in the IDC data center with the VPC subnets in the cloud.

[0055] This application embodiment deploys a virtual Layer 2 gateway device within the cloud and interconnects with the physical Layer 2 gateway device of the Internet data center through multiple tunnels, thereby enabling Layer 2 traffic communication between virtual machines in the cloud network and physical servers in the Internet data center.

[0056] Optionally, the controller 30 is further configured to:

[0057] The address resolution protocol information of the same subnet within the cloud is used as the MAC address of the Layer 2 gateway 101, and the virtual machine address of the same subnet within the cloud is used as the IP address of the Layer 2 gateway 101.

[0058] The address resolution protocol information is flooded through the inner virtual network tunnel between the Layer 2 gateway 101 and the tunnel switch 201.

[0059] In this embodiment, since the network communication structure provided in this application is Layer 2 interconnection, the IDC data center needs to know the ARP (Address Resolution Protocol) information of the virtual machines in the cloud. The controller injects gratuitous ARP information of all virtual machines in the same subnet within the cloud into the Layer 2 gateway. The MAC address of these gratuitous ARPs is uniformly the MAC address of the Layer 2 gateway, and the IP address is the address of the virtual machine in the same subnet within the cloud. These gratuitous ARPs are flooded by the Layer 2 GW within the Layer 2 VXLAN tunnel. After reaching the tunnel switch, they enter the VLAN of the IDC data center. In this way, the hosts in the IDC data center will forward all traffic destined for the virtual machines in the cloud to the Layer 2 gateway.

[0060] Optionally, the cloud network system further includes a monitoring module 40, wherein each network element node 41, computing node 42, and switch node 43 in the cloud network system is equipped with a monitoring unit 401.

[0061] The monitored unit is used to collect statistics on the indicator parameters of each network element node, computing node, and switch node, and report the collected system information to the monitoring module.

[0062] In the embodiments of this application, reference is made to Figure 3 The monitoring module is responsible for collecting and reporting statistics from all compute nodes and network element nodes to the operations and maintenance or product monitoring system. It deploys sys-agent (monitoring unit) on compute nodes, network element nodes, and switch nodes to obtain relevant statistics from OVS (Open vSwitch, virtual switch), DPOS, and switches, including BBS, PPS, latency and packet loss statistics, and dropped packet content of packets at the level of network card, vpc, CPU, subnet, and connection count. At the same time, the statistics of netprobe and DTC are also written to ES. vnet-controller is responsible for reading all statistical data from ES and then delivering the data to the operations and maintenance system for display via Kafka.

[0063] Optionally, the controller 30 is further configured to:

[0064] The tunnel switch 201 periodically sends query messages to the devices on each virtual network tunnel;

[0065] The monitoring module 40 is used to monitor the reception of the query message by each of the devices.

[0066] Optionally, the monitoring module 40 is further configured to:

[0067] When the receiving status indicates that the device has not received the query message, an alarm message indicating a link failure is output.

[0068] Optionally, the monitoring module 40 is further configured to:

[0069] When the receiving status reflects that the tunnel switch 201 receives the query message, it outputs an alarm message indicating that the Internet data center 20 has a loop fault.

[0070] Optionally, the controller 30 is further configured to:

[0071] When the reception status reflects that the tunnel switch 201 receives the query message, the port between the tunnel switch 201 and the router 202 is closed.

[0072] In this embodiment, a ping query message is constructed by the controller, with a destination address of 192.1.2.20, and sent to the tunnel switch. A query message is sent every 5 seconds, and the monitoring system monitors the devices on the tunnel link to ensure they receive this message. If the Layer 2 gateway receives the message, it indicates that the tunnel is open. If any device in the tunnel does not receive the message, it indicates a fault in that link, and an alarm is immediately triggered to notify the customer to repair the service. If the tunnel switch itself sends the message and then receives it, it indicates a loop in the offline IDC. In this case, an alarm is sent to the customer along with port packet information, and the controller simultaneously shuts down the port from the tunnel switch to the IDC router to protect cloud services from disruption.

[0073] In this embodiment, by deploying a Layer 2 access device and using a VXLAN tunnel to interconnect with the gateway in the cloud, the function of Layer 2 traffic interconnection between virtual machines in the cloud network and IDC data center services is achieved. At the same time, the SDN controller performs packet probing and device monitoring on the Layer 2 access device, so that the occurrence of a Layer 2 loop in the IDC data center will not affect the traffic in the cloud.

[0074] In this embodiment, the SDN controller performs packet probing and device monitoring on Layer 2 VXLAN devices. In the event of Layer 2 loops and broadcast storms in the IDC data center, the SDN controller will actively suppress BUM packets to prevent broadcast traffic from the IDC from being introduced into virtual machines and infrastructure in the cloud.

[0075] Figure 4 The schematic diagram illustrates a flowchart of an interaction method for a cloud network system provided in this application. The method is applied to the aforementioned cloud network system and includes:

[0076] Step 301: When the second cloud virtual machine actively accesses the first cloud virtual machine, it sends an acquisition message for the address resolution protocol information of the first cloud virtual machine to the tunnel switch.

[0077] Step 302: The tunnel switch sends the acquisition message to the router;

[0078] Step 303: The route sends the acquired message to the Layer 2 gateway through the leased virtual network tunnel;

[0079] Step 304: The Layer 2 gateway sends the acquired message to the first cloud virtual machine;

[0080] Step 305: The first cloud virtual machine sends its own address resolution information to the Layer 2 gateway;

[0081] Step 306: The Layer 2 gateway sends the address resolution information to the tunnel switch through the leased virtual network tunnel;

[0082] Step 307: The tunnel switch sends the address resolution information to the second cloud virtual machine.

[0083] In the embodiments of this application, reference is made to Figure 5 and Figure 6The on-premises VM2 (Virtual Machine) actively accesses VM1 on the same network segment in the cloud. It searches for an ARP entry for VM1 on its local machine, finds it doesn't exist, and sends an ARP request to VM1. The packet is sent to the on-premises tunnel switch. The switch searches its local ARP table (if ARP proxy functionality is configured), finds it doesn't exist, encapsulates the packet with an inner VXLAN layer (destination IP is 192.1.2.20), sends it back to its local routing device, and then to the virtual machine gateway via a dedicated line. Upon receiving the packet, the virtual machine gateway, based on the destination IP 192.1.2.20, forwards it to the Layer 2 gateway. The Layer 2 gateway, upon receiving the packet, removes the outer VXLAN encapsulation, finds the inner encapsulation is the address of its local loop 2 port, and forwards it to the IP layer. At the IP layer, it forwards it to UDP. At the UDP layer, based on the port number 4789, it recognizes it as VXLAN, and since the destination IP + VNI of the packet is the same as that of the VXLAN1 port within the local VRF, it removes the inner VXLAN packet. Since VXLAN1 is a split-horizon (SHS) port, it will respond to ARP packets received on this port. The Layer 2 gateway, finding that the MAC address corresponding to the IP address requested in the original ARP packet exists on this device, will respond. The Layer 2 gateway will then send the ARP response packet out through VXLAN1. VXLAN1 performs inner VXLAN encapsulation, then looks up the routing table based on the destination IP (10.1.1.100) and sends it to loop2 (the loop port where the tunnel subnet is located). A forwarding table lookup is performed in loop2, and the packet is sent to VXLAN0 (because the next hop 192.1.2.1 is on the corresponding V gateway of VXLAN0). It then performs outer VXLAN encapsulation (VNI is the VNI of the tunnel subnet, and the destination IP is the virtual machine gateway) and sends it to the virtual machine gateway. The virtual machine gateway forwards the packet based on the inner VXLAN destination IP 10.1.1.100, sending it via a leased line to the on-premises routing device, and then forwards it to the on-premises tunnel switch based on the inner destination IP. The on-premises tunnel switch forwards the packet locally based on the VNI information of the inner VXLAN, sending an ARP request to VM2. VM2 learns the ARP entry for VM1 and sends a Ping packet. Similarly, the Ping packet reaches the on-premises tunnel switch, which then encapsulates the packet with an inner VXLAN layer (destination IP is 192.1.2.20) and sends it back to the local routing device. It then sends the packet via a leased line to the virtual machine gateway, which forwards it to the Layer 2 gateway based on the destination IP. Upon receiving the packet, the Layer 2 gateway removes the outer VXLAN encapsulation, finds that the inner layer is the address of its local loop 2 port, and forwards it to the IP layer. At the IP layer, it forwards it to UDP. At the UDP layer, based on the port number 4789, it recognizes the VXLAN layer, and since the destination IP + VNI of the packet is the same as that of the VXLAN1 port within the local VRF, it removes the inner VXLAN packet. Finally, it uses L2 forwarding to deliver the original packet to the OVS1 where VM1 resides.When OVS1 receives the packet, it matches the destination MAC address (VM1's MAC address) and forwards the packet to VM1. VM1 needs to respond to VM2, so it checks VM2's ARP table, finds no match, and sends an ARP request to VM2. After the packet arrives at OVS, since no ARP reply entry or VIPARP flow table entry for any known IP is found, it defaults to VXLAN encapsulation and sends the packet to the Layer 2 gateway. When the OVS service network interface card where the Layer 2 gateway is located receives the packet, it finds that the destination IP is not itself, performs normal forwarding, and sends it to the Layer 2 gateway. The Layer 2 gateway's VXLAN2 port (Horizontal Split Group 1) receives the packet, floods it within BD1, and sends it to VXLAN port 1 for inner VXLAN encapsulation. After encapsulation, it matches the routing table within BD1 and sends it to loop2 (the loop interface where the tunnel subnet is located). Within BD2, the forwarding table is looked up and sent to VXLAN0 (because the next hop of the route, 192.1.2.1, is on the corresponding V gateway of VXLAN0). An outer VXLAN encapsulation is then performed (VNI is the VNI of the tunnel subnet, and the destination IP is the virtual machine gateway), and the packet is sent to the virtual machine gateway. The virtual machine gateway forwards the packet based on the destination IP 10.1.1.100 of the inner VXLAN, sending it via a leased line to the on-premises routing device. Then, based on the inner destination IP, it forwards the packet to the on-premises tunnel switch. The on-premises tunnel switch forwards the packet locally to VM2 based on the VNI information of the inner VXLAN. After VM2 receives the packet, a ping interaction ends.

[0084] The above methods enable the deployment of Layer 2 access devices, which can communicate with cloud gateways via VXLAN tunnels. This allows for Layer 2 traffic communication between virtual machines in the cloud network and traditional IDC data center services. Simultaneously, the SDN controller can perform packet probing and device monitoring on the Layer 2 access devices, ensuring that the presence of a Layer 2 loop in the traditional IDC data center will not affect cloud traffic.

[0085] This application embodiment deploys a virtual Layer 2 gateway device within the cloud, which interconnects with the physical Layer 2 gateway device in the Internet data center via multiple tunnels. This enables Layer 2 traffic communication between virtual machines in the cloud network and physical servers in the Internet data center. Furthermore, an SDN controller performs packet probing and device monitoring on the Layer 2 VXLAN device. In the event of Layer 2 loops or broadcast storms in the IDC data center, the SDN controller proactively suppresses BUM packets to prevent broadcast traffic from the IDC from being introduced into the cloud virtual machines and infrastructure.

[0086] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0087] The various component embodiments of this application can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing device according to the embodiments of this application. This application can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing part or all of the methods described herein. Such an implementation of this application can be stored on a non-transient computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.

[0088] For example, Figure 7 A computing processing apparatus is shown that can implement the method according to this application. The computing processing apparatus includes a processor 410 and a computer program product or non-transitory computer-readable medium in the form of a memory 420. The memory 420 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory 420 has a storage space 430 for program code 431 for performing any of the method steps described above. For example, the storage space 430 for program code may include various program codes 431 respectively for implementing the various steps in the above method. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, CDs, memory cards, or floppy disks. Such computer program products are typically as shown in the reference. Figure 8 The portable or fixed storage unit is described above. This storage unit may have the same characteristics as... Figure 7The memory 420 in the computing processing device is similarly arranged as storage segments, storage spaces, etc. Program code can be compressed, for example, in an appropriate form. Typically, the storage unit includes computer-readable code 431', that is, code that can be read by a processor such as 410, which, when run by the computing processing device, causes the computing processing device to perform the various steps in the methods described above.

[0089] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0090] The terms "an embodiment," "embodiment," or "one or more embodiments" as used herein mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of this application. Furthermore, please note that the examples of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.

[0091] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this application may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0092] In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. This application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names.

[0093] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A cloud network system, characterized in that, The cloud network system includes: cloud virtual machines, internet data centers, and controllers; The cloud virtual machine includes: a Layer 2 gateway, a virtual gateway, and an inbound switch; the Internet data center includes: a tunnel switch, a router, and a virtual network switch. The controller is used to map the virtual network of the Internet data center to the virtual network tunnel, so as to allocate tunnel configuration for each virtual network tunnel in the cloud network system. A two-layer virtual network tunnel is constructed between the tunnel switch and the layer 2 gateway based on the tunnel configuration; The Layer 2 virtual network tunnel includes: an inner virtual network tunnel between the tunnel switch and the Layer 2 gateway, an outer virtual network tunnel between the Layer 2 gateway and the virtual gateway, an outer virtual network tunnel between the ingress switch and the virtual gateway, and a leased line virtual network tunnel between the router and the ingress switch.

2. The system according to claim 1, characterized in that, The controller is also used for: The address resolution protocol information of the same subnet within the cloud is used as the MAC address of the Layer 2 gateway, and the virtual machine address of the same subnet within the cloud is used as the IP address of the Layer 2 gateway. The address resolution protocol information is flooded through the inner virtual network tunnel between the Layer 2 gateway and the tunnel switch.

3. The system according to claim 1, characterized in that, The cloud network system also includes a monitoring module, wherein each network element node, computing node, and switch node in the cloud network system is equipped with a monitoring unit. The monitoring unit is used to collect statistics on the indicator parameters of each network element node, computing node, and switch node, and report the collected system information to the monitoring module.

4. The system according to claim 3, characterized in that, The controller is also used for: The tunnel switch periodically sends query messages to the devices on each virtual network tunnel. The monitoring module is used to monitor the reception of the query message by each of the devices.

5. The system according to claim 4, characterized in that, The monitoring module is also used for: When the receiving status indicates that the device has not received the query message, an alarm message indicating a link failure is output.

6. The system according to claim 4, characterized in that, The monitoring module is also used for: When the receiving status reflects that the tunnel switch receives the query message, it outputs an alarm message indicating that there is a loop fault in the Internet data center.

7. The system according to claim 6, characterized in that, The controller is also used for: When the reception status indicates that the tunnel switch has received the query message, the port between the tunnel switch and the router is closed.

8. An interaction method for a cloud network system, characterized in that, The method is applied to any one of the cloud network systems described in claims 1-7, and the method includes: When the virtual machine on the second cloud actively accesses the virtual machine on the first cloud, it sends a message to the tunnel switch to obtain the address resolution protocol information of the virtual machine on the first cloud. The tunnel switch sends the acquisition message to the router; The route sends the acquired message to the Layer 2 gateway through the dedicated virtual network tunnel; The Layer 2 gateway sends the acquired message to the first cloud virtual machine; The first cloud virtual machine sends its own address resolution information to the Layer 2 gateway; The Layer 2 gateway sends the address resolution information to the tunnel switch through the dedicated virtual network tunnel; The tunnel switch sends the address resolution information to the second cloud virtual machine.

9. A computing processing device, characterized in that, include: Memory containing computer-readable code; One or more processors, when the computer-readable code is executed by the one or more processors, the computing processing device performs the interaction method of the cloud network system as described in claim 8.

10. A non-transient computer-readable medium, characterized in that, The system stores computer-readable code that, when executed on a computing processing device, causes the computing processing device to perform the interaction method of the cloud network system as described in claim 8.