An OVS flow table creation method, device, equipment and medium
Patent Information
- Application Number
- CN202311148637.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-07
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2043-09-07
AI Technical Summary
此种流表管理方式在进行多个匹配条件组合配置时,若此匹配条件组合同时适用于多个网桥,需要在每个网桥配置一遍,容易遗漏匹配条件或出错,同样多个动作组合配置适用于多个网桥的情景也不能复用
[0105]本发明提供的OVS流表创建方法、装置、终端及存储介质,将OVS流表的匹配条件及执行动作分别组合形成模板,利于流表的配置和复用,方便管理,将流表划分等级,逐级处理,实现兼顾流量的统一处理和精确分类后处理。
Smart Images

Figure CN117118887B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network traffic management technology, specifically relating to an OVS flow table creation method, apparatus, device, and medium. Background Technology
[0002] OVS, short for Open Virtual Switch, is an open-source virtual machine switch. In today's internet network environment, network traffic management is necessary to ensure network performance and security. OVS, because it can use flow tables to match network traffic and distribute actions, has become an important component in virtualization and software-defined networking. Through OVS flow tables, traffic control and optimization can be achieved.
[0003] Traditional OVS flow tables typically match traffic based on keywords such as source IP address, destination IP address, source port, and destination port, and then execute corresponding actions upon successful matching. However, with the increasing scale and diversification of network traffic characteristics, the traditional OVS flow table matching method is no longer sufficient to meet the needs of modern network environments. First, the number of keywords used as matching conditions in traditional flow tables is limited, making it impossible to identify and manage various types of network traffic. Second, the action options in traditional flow tables are relatively limited, failing to provide flexible and efficient traffic control strategies.
[0004] Furthermore, current flow table management involves adding, modifying, and deleting individual flow tables in OVS. A single flow table can be configured with multiple matching conditions and actions. Typically, flow tables are bound to corresponding bridges or ports, and traffic is processed through the configured flow tables. However, this flow table management method suffers from several drawbacks. When configuring multiple matching condition combinations that apply to multiple bridges, each bridge needs to be configured, which can easily lead to missed matching conditions or errors. Similarly, multiple action combinations applicable to multiple bridges cannot be reused. Moreover, the flow table currently bound to a bridge and the flow table for the specified port when binding the bridge coexist, making management difficult and configuration complex.
[0005] Therefore, it is essential to provide an OVS flow table creation method, apparatus, device, and medium to address the aforementioned shortcomings. Summary of the Invention
[0006] To address the limitations of traditional flow tables in terms of the limited number of matching conditions and actions, restrictive identification of network traffic types and traffic control policies, and the inability to reuse configurations of multiple matching condition combinations and action combinations in current flow table management methods, which require repeated settings on each bridge or port, and the simultaneous existence of flow tables bound to bridges and specified ports, resulting in chaotic management and complex configuration, this invention provides an OVS flow table creation method, apparatus, device, and medium to solve the aforementioned technical problems.
[0007] In a first aspect, the present invention provides an OVS flow table creation method, comprising the following steps:
[0008] Create matching condition templates and action templates for OVS flow tables;
[0009] Create hierarchical flow tables in the OVS system using matching condition templates and execution action templates;
[0010] The OVS system uses hierarchical flow tables to forward and filter traffic received at each level.
[0011] Furthermore, the specific steps for creating matching condition templates and execution action templates for OVS flow tables are as follows:
[0012] Perform statistical analysis on the original OVS flow table to establish a set of matching conditions and a set of execution actions;
[0013] Select matching conditions to be aggregated from the set of matching conditions according to the requirements, or count the matching conditions in the set of matching conditions that are used more than a threshold at the same time as the matching conditions to be aggregated.
[0014] Based on the requirements, select the execution actions to be aggregated from the set of execution actions, or count the execution actions in the set of execution actions that are used more than a threshold at the same time as the execution actions to be aggregated.
[0015] Combine the matching conditions to be aggregated to generate a matching condition template and name it. Save the matching condition template, the name, and each matching condition of the matching condition template to the OVS database.
[0016] The actions to be aggregated are combined to generate an action template and named. The action template, the name, and each action of the action template are saved to the OVS database.
[0017] This documentation introduces interfaces for adding, deleting, and modifying matching condition templates and action templates in the OVS database. Building upon the original flow table where matching conditions and actions are directly configured, the documentation extracts these elements. Matching conditions are combined to form matching condition templates, and action templates are combined to form action templates.
[0018] Furthermore, the specific steps for creating a hierarchical flow table in the OVS system using matching condition templates and execution action templates are as follows:
[0019] Determine whether it is necessary to create an OVS system-level flow table;
[0020] When it is necessary to create an OVS system-level flow table, obtain the system traffic management requirements of the OVS system, find the matching condition template and execution action template in the OVS database according to the system traffic management requirements, and use the found matching condition template and execution action template to create the OVS system-level flow table in the OVS system.
[0021] If it is not necessary to create an OVS system-level flow table, or after the OVS system-level flow table has been created, determine in turn whether each bridge needs to create a bridge-level flow table.
[0022] When it is necessary to create a bridge-level flow table, obtain the bridge traffic management requirements of the bridge, search for matching condition templates and execution action templates in the OVS database according to the bridge traffic management requirements, and create the bridge-level flow table on the bridge using the found matching condition templates and execution action templates.
[0023] If it is not necessary to create a bridge-level flow table, or after the bridge-level flow table has been created, determine in turn whether each port under the bridge needs to create a port-level flow table;
[0024] When it is necessary to create a port-level flow table, obtain the port traffic management requirements of the port, search for matching condition templates and execution action templates in the OVS database according to the port traffic management requirements, and create a port-level flow table on the port using the found matching condition templates and execution action templates.
[0025] The traffic management step can proceed without creating port-level flow tables or after port-level flow tables have been created. The original configuration matching conditions and actions for the flow tables are replaced with configuration matching condition templates and action templates. After obtaining the matching condition template name, the specific matching condition is retrieved from the OVS database based on the template name. Similarly, after obtaining the action template name, the specific action is retrieved based on the template name. By configuring OVS system-level flow tables step by step, followed by bridge-level flow tables, and finally port-level flow tables, the flow tables are categorized into levels to facilitate subsequent hierarchical processing of traffic.
[0026] Furthermore, the specific steps for obtaining the system traffic management requirements of the OVS system, finding matching condition templates and execution action templates in the OVS database based on the system traffic management requirements, and creating OVS system-level flow tables using the found matching condition templates and execution action templates are as follows:
[0027] The specific steps for obtaining the system traffic management requirements of the OVS system, finding matching condition templates and execution action templates in the OVS database based on the system traffic management requirements, and creating OVS system-level flow tables using the found matching condition templates and execution action templates are as follows:
[0028] Obtain the system traffic management requirements of the OVS system, search the OVS database, and determine whether each matching condition template in the OVS database meets the system traffic management requirements.
[0029] When the matching condition template in the OVS database meets the system-level traffic management requirements, select and use the matching condition template that meets the requirements to set the OVS system flow table, and enter the system traffic management requirement judgment step of the execution action template;
[0030] When the matching condition template in the OVS database does not meet the system-level traffic management requirements, the matching conditions are set one by one in the OVS system according to the system traffic management requirements.
[0031] Based on the system traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the system traffic management requirements;
[0032] When the execution action template in the OVS database meets the system traffic management requirements, select and use the qualified execution action template to set the OVS system flow table, and enter the bridge-level flow table creation judgment step;
[0033] When the matching condition template in the OVS database does not meet the system-level traffic management requirements, the execution action is set in the OVS system one by one according to the system traffic management requirements.
[0034] The specific steps for obtaining the bridge traffic management requirements, finding matching condition templates and action templates in the OVS database based on these requirements, and then creating a bridge-level flow table on the bridge using the found matching condition templates and action templates are as follows:
[0035] Obtain the bridge traffic management requirements of the bridge, search the OVS database, and determine whether each matching condition template in the OVS database meets the bridge traffic management requirements;
[0036] When the matching condition template in the OVS database meets the requirements of bridge-level traffic management, select and use the matching condition template that meets the requirements, set the bridge flow table, and enter the bridge-level traffic management requirement judgment step of the execution action template.
[0037] When the matching condition template in the OVS database does not meet the requirements of bridge-level traffic management, the matching conditions are set one by one on the bridge according to the requirements of bridge traffic management.
[0038] Based on the bridge traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the bridge traffic management requirements.
[0039] When the execution action template in the OVS database meets the requirements of bridge-level traffic management, select and use the qualified execution action template to set the bridge flow table, and proceed to the port-level flow table creation judgment step;
[0040] When the action templates in the OVS database do not meet the requirements of bridge-level traffic management, the action to be executed is set for each bridge according to the bridge traffic management requirements.
[0041] The specific steps for obtaining port traffic management requirements, searching the OVS database for matching condition templates and action templates based on these requirements, and then creating a port-level flow table using the found matching condition templates and action templates are as follows:
[0042] Obtain the port traffic management requirements for the port, search the OVS database, and determine whether each matching condition template in the OVS database meets the port traffic management requirements;
[0043] When the matching condition template in the OVS database meets the port traffic management requirements, select and use the matching condition template that meets the conditions to set the port flow table, and enter the port-level flow table creation judgment step;
[0044] When the matching condition template in the OVS database does not meet the port-level traffic management requirements, the matching conditions are set one by one on the port according to the port traffic management requirements.
[0045] Based on port traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the port traffic management requirements;
[0046] When the execution action template in the OVS database meets the port traffic management requirements, select and use the qualified execution action template to set the port flow table and enter the traffic management step;
[0047] When the action templates in the OVS database do not meet the port traffic management requirements, actions are set for each port individually according to the port traffic management requirements. When configuring flow tables, if there are no suitable matching condition templates and action templates in the OVS database, the original method of configuring matching conditions and action separately can still be used.
[0048] Furthermore, the specific steps for using hierarchical flow tables to forward and filter traffic received by the OVS system level by level are as follows:
[0049] After receiving traffic from external devices, the OVS system obtains the matching condition template and execution action template from the OVS system-level flow table;
[0050] Find the matching condition templates for the OVS system-level flow tables in the OVS database, and the execution action templates for the corresponding execution actions.
[0051] The OVS system uses the found matching conditions to filter the traffic from external devices, then uses the found execution actions to process the filtered traffic, and determines the destination bridge for traffic forwarding.
[0052] Upon receiving traffic forwarded by the OVS system, the destination bridge obtains the matching condition template and the action template from the bridge-level flow table.
[0053] Search the OVS database for the matching condition templates of the bridge-level flow table, corresponding to each matching condition, and the execution action templates, corresponding to each execution action.
[0054] The destination bridge uses the found matching conditions to filter the traffic forwarded by the OVS system, and then uses various execution actions to process the filtered traffic to determine the destination port for traffic forwarding.
[0055] Upon receiving traffic forwarded by the destination bridge at the destination port, retrieve the matching condition template and the action template from the port-level flow table;
[0056] Retrieve the matching condition templates for port-level flow tables from the OVS database, along with the corresponding matching conditions and actions.
[0057] The destination port uses the found matching conditions to filter the traffic forwarded by the destination bridge, and then uses various execution actions to process the filtered traffic to complete the traffic forwarding. Traffic is processed according to the flow table level. Among them, the system-level flow table can intercept or forward all traffic as a whole, realizing unified traffic processing, while the flow tables of each bridge and port realize precise traffic processing.
[0058] Furthermore, the OVS database also stores default OVS system-level flow tables, default bridge-level flow tables, and default port-level flow tables;
[0059] In the OVS system-level flow table creation judgment step, if it is not necessary to create an OVS system-level flow table, the default OVS system-level flow table is used in the OVS system, and the process proceeds to the bridge-level flow table creation judgment step.
[0060] In the bridge-level flow table creation judgment step, when it is not necessary to create a bridge-level flow table, the default bridge-level flow table is used in the bridge.
[0061] In the port-level flow table creation judgment step, if it is not necessary to create a port-level flow table, the default port-level flow table is used on the port, and the flow management step is entered.
[0062] In the steps of obtaining the matching condition template and execution action template of the OVS system-level flow table, after the OVS system receives the traffic from the external device, it determines whether the OVS default system-level flow table exists.
[0063] If so, the OVS system does not manage the traffic of external devices, and treats each bridge in the OVS system as the destination bridge, and enters the steps of obtaining the matching condition template and execution action template of the bridge-level flow table;
[0064] If not, obtain the matching condition template and execution action template of the OVS system-level flow table, and proceed to the step of finding the matching condition template corresponding to each matching condition and the execution action template corresponding to each execution action from the OVS database;
[0065] In the steps of obtaining the matching condition template and execution action template in the bridge-level flow table, the destination bridge that receives the traffic forwarded by the OVS system determines whether a default bridge-level flow table exists.
[0066] If so, the destination bridge does not manage the OVS system traffic, and treats each port under the destination bridge as the destination port, and enters the steps of obtaining the matching condition template and executing the action template in the port-level flow table;
[0067] If not, obtain the matching condition template and execution action template of the bridge-level flow table, and proceed to the step of finding the matching condition template corresponding to each matching condition and the execution action template corresponding to each execution action from the OVS database;
[0068] In the steps of obtaining the matching condition template and executing the action template in the port-level flow table, the destination port of the traffic forwarded by the destination bridge is received, and it is determined whether a default port-level flow table exists.
[0069] If so, the destination port does not manage the destination bridge traffic and directly forwards the traffic. The default flow table makes it easy to choose whether to configure flow tables at each level. For flow tables that are not configured, the default flow table can be used to not process the traffic, avoiding the situation where the traffic forwarding is affected by the lack of configured flow tables.
[0070] Furthermore, in the bridge-level flow table creation judgment step, it is determined whether there are bridges of the same type for which a bridge-level flow table needs to be created. When there are bridges of the same type, after the first bridge-level flow table is created in the bridge-level flow table creation step, the bridge-level flow table is directly copied to the same type of bridge to complete the creation of bridge-level flow tables for the same type of bridge.
[0071] In the port flow table creation judgment step, it is determined whether there are ports of the same type for which port-level flow tables need to be created. If ports of the same type exist, after the first port-level flow table is created, this port-level flow table is directly assigned to the ports of the same type, thus completing the port-level flow table creation for ports of the same type. For bridges or ports of the same type, the flow tables that need to be configured are the same. The use of matching condition templates and action templates allows the flow table configuration to be easily copied after it has been completed.
[0072] In a second aspect, the present invention provides an OVS flow table creation apparatus, comprising:
[0073] The template generation module is used to create matching condition templates and execution action templates for OVS flow tables.
[0074] The hierarchical flow table creation module is used to create hierarchical flow tables in the OVS system using matching condition templates and execution action templates.
[0075] The traffic management module is used to forward and filter traffic received by the OVS system using hierarchical flow tables.
[0076] Furthermore, the template generation module includes:
[0077] The set creation unit is used to perform statistics on the original OVS flow table and create a set of matching conditions and a set of execution actions;
[0078] The unit for obtaining matching conditions to be aggregated is used to select matching conditions to be aggregated from the set of matching conditions according to requirements, or to count the matching conditions in the set of matching conditions that are used more than a threshold at the same time as matching conditions to be aggregated.
[0079] The unit for obtaining execution actions to be aggregated is used to select execution actions to be aggregated from the set of execution actions according to requirements, or to count the execution actions in the set of execution actions that are used more than a threshold at the same time as execution actions to be aggregated.
[0080] The matching condition template saving unit is used to combine the matching conditions to be aggregated to generate a matching condition template and name it, and save the matching condition template, name and each matching condition of the matching condition template to the OVS database;
[0081] The execution action template saving unit is used to combine the execution actions to be aggregated to generate an execution action template and name it, and save the execution action template, name and each execution action of the execution action template to the OVS database;
[0082] The template editing interface creation unit is used to create interfaces for adding, deleting, and modifying matching condition templates and action templates in the OVS database.
[0083] Furthermore, the flow table hierarchical creation module includes:
[0084] The system flow table creation decision unit is used to determine whether an OVS system-level flow table needs to be created.
[0085] The system flow table creation unit is used to obtain the system traffic management requirements of the OVS system when it is necessary to create an OVS system-level flow table. Based on the system traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and uses the found matching condition templates and execution action templates to create the OVS system-level flow table in the OVS system.
[0086] The bridge flow table creation judgment unit is used to determine whether each bridge needs to create a bridge-level flow table after the OVS system-level flow table is created or not required to create an OVS system-level flow table.
[0087] The bridge flow table creation unit is used to obtain the bridge traffic management requirements of the bridge when it is necessary to create a bridge-level flow table. Based on the bridge traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and uses the found matching condition templates and execution action templates to create a bridge-level flow table on the bridge.
[0088] The port-level flow table creation judgment unit is used to determine whether port-level flow tables need to be created for each port under the bridge when there is no need to create bridge-level flow tables or when the bridge-level flow table has been created.
[0089] The port-level flow table creation unit is used to obtain the port traffic management requirements of a port when it is necessary to create a port-level flow table. Based on the port traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and then uses the found matching condition templates and execution action templates to create a port-level flow table on the port.
[0090] Furthermore, the traffic management module includes:
[0091] The system template acquisition unit is used to acquire the matching condition template and execution action template in the OVS system-level flow table after the OVS system receives traffic from external devices;
[0092] The system flow table matching condition and execution action lookup unit is used to look up the matching condition templates corresponding to the matching conditions and the execution action templates corresponding to the execution actions of the OVS system-level flow tables from the OVS database.
[0093] The system traffic management unit is used to filter external device traffic in the OVS system using the matching conditions found, process the filtered traffic using the execution actions found, and determine the destination bridge for traffic forwarding.
[0094] The bridge template acquisition unit is used to acquire the matching condition template and the action template in the bridge-level flow table when the destination bridge receives traffic forwarded by the OVS system.
[0095] The bridge flow table matching condition and execution action lookup unit is used to look up the matching condition template corresponding to each matching condition and the execution action template corresponding to each execution action from the OVS database.
[0096] The bridge traffic management unit is used to filter the traffic forwarded by the OVS system at the destination bridge using the found matching conditions, and then use various execution actions to process the filtered traffic to determine the destination port for traffic forwarding.
[0097] The port template acquisition unit is used to acquire the matching condition template and the action template in the port-level flow table when receiving traffic forwarded by the destination bridge.
[0098] The port flow table matching condition and execution action lookup unit is used to look up the matching condition templates of port-level flow tables from the OVS database, along with the corresponding matching conditions and execution actions.
[0099] The port traffic management unit is used to filter the traffic forwarded by the destination bridge at the destination port using the found matching conditions, and then use various execution actions to process the filtered traffic to complete the traffic forwarding.
[0100] Thirdly, the present invention provides a computer device, including a processor and a memory;
[0101] The memory is used to store computer programs, and the processor is used to retrieve and run the computer programs from the memory, causing the computer device to perform the method described in the first aspect above.
[0102] Fourthly, the present invention provides a storage medium,
[0103] The storage medium stores instructions that, when run on a computer, cause the computer to perform the method described in the first aspect above.
[0104] The beneficial effects of this invention are as follows:
[0105] The OVS flow table creation method, device, terminal, and storage medium provided by this invention combine the matching conditions and execution actions of the OVS flow table into templates, which facilitates the configuration and reuse of flow tables, makes management convenient, divides flow tables into levels, and processes them step by step, achieving both unified processing of traffic and precise post-classification processing.
[0106] Furthermore, the design principle of this invention is reliable, the structure is simple, and it has a very wide range of application prospects.
[0107] Therefore, it is evident that the present invention has outstanding substantive features and significant progress compared with the prior art, and the beneficial effects of its implementation are also obvious. Attached Figure Description
[0108] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0109] Figure 1 This is a schematic flowchart of Embodiment 1 of the OVS flow table creation method of the present invention.
[0110] Figure 2 This is a schematic flowchart of Embodiment 2 of the OVS flow table creation method of the present invention.
[0111] Figure 3 This is a schematic diagram of the process for creating OVS system-level flow tables according to the present invention.
[0112] Figure 4 This is a schematic diagram of the process for creating a bridge-level flow table according to the present invention.
[0113] Figure 5 This is a schematic diagram of the process for creating a port-level flow table according to the present invention.
[0114] Figure 6 This is a schematic diagram of the OVS flow table creation device of the present invention. Detailed Implementation
[0115] To enable those skilled in the art to better understand the technical solutions of this invention, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this invention.
[0116] Example 1:
[0117] like Figure 1 As shown, this invention provides an OVS flow table creation and management method, including the following steps:
[0118] S1. Create matching condition templates and execution action templates for the OVS flow table;
[0119] S2. Create a hierarchical flow table in the OVS system using matching condition templates and execution action templates;
[0120] S 3. Use hierarchical flow tables to forward and filter traffic received by the OVS system step by step.
[0121] Example 2:
[0122] like Figure 2 As shown, this invention provides an OVS flow table creation method, including the following steps:
[0123] S1. Create matching condition templates and execution action templates for the OVS flow table; the specific steps of step S1 are as follows:
[0124] S11. Perform statistics on the original OVS flow table to establish a set of matching conditions and a set of execution actions;
[0125] S12. Select matching conditions to be aggregated from the matching condition set according to the requirements, or count the matching conditions in the matching condition set that are used more than the threshold at the same time as the matching conditions to be aggregated.
[0126] S13. Select the execution actions to be aggregated from the execution action set according to the requirements, or count the execution actions in the execution action set that are used more than the threshold at the same time as the execution actions to be aggregated;
[0127] S14. Combine the matching conditions to be aggregated to generate a matching condition template and name it. Save the matching condition template, the name, and each matching condition of the matching condition template to the OVS database.
[0128] S15. Combine the actions to be aggregated to generate an action template and name it. Save the action template, name, and each action of the action template to the OVS database.
[0129] S16. Create interfaces for adding, deleting, and modifying matching condition templates and execution action templates in the OVS database;
[0130] S2. Create a hierarchical flow table in the OVS system using matching condition templates and execution action templates; Step S2 is detailed as follows:
[0131] S21. Determine whether it is necessary to create an OVS system-level flow table;
[0132] If so, proceed to step S22;
[0133] If not, proceed to step S23;
[0134] S22. Obtain the system traffic management requirements of the OVS system, find the matching condition templates and execution action templates in the OVS database according to the system traffic management requirements, and create the OVS system-level flow table in the OVS system using the found matching condition templates and execution action templates;
[0135] S23. Determine in turn whether each bridge needs to create a bridge-level flow table;
[0136] If so, proceed to step S24;
[0137] If not, proceed to step S25;
[0138] S24. Obtain the bridge traffic management requirements of the bridge, find the matching condition template and execution action template in the OVS database according to the bridge traffic management requirements, and create a bridge-level flow table on the bridge using the found matching condition template and execution action template;
[0139] S25. Determine in turn whether port-level flow tables need to be created for each port under the bridge;
[0140] If so, proceed to step S26;
[0141] If not, proceed to step S3;
[0142] S26. Obtain the port traffic management requirements of the port, search for matching condition templates and execution action templates in the OVS database according to the port traffic management requirements, and create a port-level flow table on the port using the found matching condition templates and execution action templates;
[0143] S3. Use hierarchical flow tables to forward and filter traffic received by the OVS system level by level; the specific steps of step S3 are as follows:
[0144] S 31. After receiving traffic from an external device, the OVS system obtains the matching condition template and the action template to be executed from the OVS system-level flow table;
[0145] S 32. Retrieve from the OVS database the matching condition templates corresponding to each matching condition and the execution action templates corresponding to each execution action in the OVS system-level flow table;
[0146] The S 33.OVS system uses the found matching conditions to filter the traffic from external devices, then uses the found execution actions to process the filtered traffic, and determines the destination bridge for traffic forwarding.
[0147] S 34. Receive the destination bridge of the traffic forwarded by the OVS system, obtain the matching condition template and the action template in the bridge-level flow table;
[0148] S 35. Retrieve from the OVS database the matching condition templates for the bridge-level flow table, corresponding to each matching condition, and the execution action templates for each execution action;
[0149] S 36. The destination bridge uses the found matching conditions to filter the traffic forwarded by the OVS system, and then uses the execution actions to process the filtered traffic to determine the destination port for traffic forwarding;
[0150] S 37. Receive the destination port of the traffic forwarded by the destination bridge, obtain the matching condition template and the action template in the port-level flow table;
[0151] S 38. Retrieve the matching condition templates for port-level flow tables from the OVS database, along with the corresponding matching conditions and actions;
[0152] S 39. The destination port uses the found matching conditions to filter the traffic forwarded by the destination bridge, and then uses the execution actions to process the filtered traffic to complete the traffic forwarding.
[0153] Example 3:
[0154] like Figure 2 As shown, this invention provides an OVS flow table creation method, including the following steps:
[0155] S1. Create matching condition templates and execution action templates for the OVS flow table; the specific steps of step S1 are as follows:
[0156] S11. Perform statistics on the original OVS flow table to establish a set of matching conditions and a set of execution actions;
[0157] S12. Select matching conditions to be aggregated from the matching condition set according to the requirements, or count the matching conditions in the matching condition set that are used more than the threshold at the same time as the matching conditions to be aggregated.
[0158] S13. Select the execution actions to be aggregated from the execution action set according to the requirements, or count the execution actions in the execution action set that are used more than the threshold at the same time as the execution actions to be aggregated;
[0159] S14. Combine the matching conditions to be aggregated to generate a matching condition template and name it. Save the matching condition template, the name, and each matching condition of the matching condition template to the OVS database.
[0160] S15. Combine the actions to be aggregated to generate an action template and name it. Save the action template, name, and each action of the action template to the OVS database.
[0161] S16. Create interfaces for adding, deleting, and modifying matching condition templates and execution action templates in the OVS database; based on the direct configuration of matching conditions and execution actions in the original flow table, extract the matching conditions and execution actions, combine the matching conditions to form a matching condition template, and combine the execution actions to form an execution action template;
[0162] A matching condition template combines multiple matching conditions into one. In the OVS database, a matching condition template is added using the command "ovs-ofctlmod-tmpl matching condition template name first matching condition, second matching condition...", deleted using the command "ovs-ofctlmod-tmpl matching condition template name first matching condition, second matching condition...", and modified using the command "ovs-ofctlmod-tmpl matching condition template name first matching condition, second matching condition...".
[0163] An execution action template combines multiple execution actions into a single matching condition template. In the OVS database, a new matching condition template is added using the command "ovs-ofctlmod-tmpl execution action template name first execution action, second execution action...", a template is deleted using the command "ovs-ofctlmod-tmpl execution action template name first execution action, second execution action...", and a template is modified using the command "ovs-ofctlmod-tmpl execution action template name first execution action, second execution action...".
[0164] The matching condition template format recorded in the OVS database is (matching condition ID, matching condition name, first matching condition, second matching condition, etc.); the execution action format recorded in the OVS database is (execution action ID, execution action name, first execution action, second execution action, etc.).
[0165] The matching criteria determine which data in the traffic will be processed. For example, matching criterion 1 is for data in the traffic whose source address is the first IP address, matching criterion 2 is for data in the traffic whose destination address is the second IP address, and matching criterion 3 is for data in the traffic whose protocol number is A.
[0166] The actions performed determine how the matched data in the traffic should be processed. For example, action 1 intercepts the data in the traffic, action 2 forwards the data in the traffic, and action 3 forwards the data in the traffic from the local port.
[0167] Flow tables process traffic by combining matching conditions with execution actions. For example, matching condition 1 combined with execution action 2 can be used to forward data in the traffic whose source address is the first IP address, while matching condition 2 combined with execution action can be used to intercept data in the traffic whose destination address is the second IP address.
[0168] After the matching conditions and execution actions in the flow table are templated, multiple matching conditions and multiple execution actions can be configured at once;
[0169] The OVS database also stores the default OVS system-level flow table, the default bridge-level flow table, and the default port-level flow table.
[0170] S2. Create a hierarchical flow table in the OVS system using matching condition templates and execution action templates; Step S2 is detailed as follows:
[0171] S21. Determine whether it is necessary to create an OVS system-level flow table;
[0172] If so, proceed to step S22;
[0173] If not, use the default OVS system-level flow table in the OVS system and proceed to step S23;
[0174] S22. Obtain the system traffic management requirements of the OVS system, search for matching condition templates and execution action templates in the OVS database based on the system traffic management requirements, and create an OVS system-level flow table using the found matching condition templates and execution action templates; for example... Figure 3 As shown, the specific steps of step S22 are as follows:
[0175] S221. Obtain the system traffic management requirements of the OVS system, search the OVS database, and determine whether each matching condition template in the OVS database meets the system traffic management requirements;
[0176] If so, proceed to step S222;
[0177] If not, proceed to step S223;
[0178] S222. Select and use the matching condition template that meets the conditions to set the OVS system flow table, and proceed to step S224;
[0179] S223. Set matching conditions in the OVS system one by one according to the system traffic management requirements;
[0180] S224. Based on the system traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the system traffic management requirements;
[0181] If so, proceed to step S225;
[0182] If not, proceed to step S226;
[0183] S225. Select and use the execution action template that meets the conditions to set the OVS system flow table, and proceed to step S23;
[0184] S226. Configure execution actions for each item in the OVS system according to system traffic management requirements;
[0185] S23. Determine in turn whether each bridge needs to create a bridge-level flow table;
[0186] If so, proceed to step S24;
[0187] If not, use the default bridge-level flow table on the bridge and proceed to step S25;
[0188] S24. Obtain the bridge traffic management requirements of the bridge, search for matching condition templates and execution action templates in the OVS database based on the bridge traffic management requirements, and create a bridge-level flow table on the bridge using the found matching condition templates and execution action templates; such as Figure 4 As shown, the specific steps of step S24 are as follows:
[0189] S241. Obtain the bridge traffic management requirements of the bridge, search the OVS database, and determine whether each matching condition template in the OVS database meets the bridge traffic management requirements;
[0190] If so, proceed to step S242;
[0191] If not, proceed to step S243;
[0192] S242. Select and use the matching condition template that meets the conditions to set the bridge flow table, and proceed to step S244;
[0193] S243. Set matching conditions for each bridge according to the bridge traffic management requirements;
[0194] S244. Based on the bridge traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the bridge traffic management requirements;
[0195] If so, proceed to step S245;
[0196] If not, proceed to step S246;
[0197] S245. Select and use the execution action template that meets the conditions to set the bridge flow table, and proceed to step S25;
[0198] S246. Configure execution actions for each bridge according to the bridge traffic management requirements;
[0199] S25. Determine in turn whether port-level flow tables need to be created for each port under the bridge;
[0200] If so, proceed to step S26;
[0201] If not, use the default port-level flow table for the port and proceed to step S3;
[0202] S26. Obtain the port traffic management requirements for the port, search the OVS database for matching condition templates and execution action templates based on the port traffic management requirements, and create a port-level flow table on the port using the found matching condition templates and execution action templates; for example... Figure 5 As shown, the specific steps of step S26 are as follows:
[0203] S261. Obtain the port traffic management requirements of the port, search the OVS database, and determine whether each matching condition template in the OVS database meets the port traffic management requirements;
[0204] If so, proceed to step S262;
[0205] If not, proceed to step S263;
[0206] S262. Select and use the matching condition template that meets the conditions to set the port flow table, and proceed to step S264;
[0207] S263. Set matching conditions for each port according to port traffic management requirements;
[0208] S264. Based on the port traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the port traffic management requirements;
[0209] If so, proceed to step S265;
[0210] If not, proceed to step S266;
[0211] S265. Select and use the execution action template that meets the conditions to set the port flow table, and proceed to step S3;
[0212] S266. Configure and execute actions for each port according to port traffic management requirements;
[0213] The original configuration matching conditions and execution actions of the flow table are replaced with configuration matching condition templates and execution action templates. After obtaining the name of the matching condition template, the specific matching condition is retrieved from the OVS database based on the matching condition template name. Similarly, after obtaining the name of the execution action template, the specific execution action is retrieved based on the execution action template name. The OVS system-level flow table is configured first, then the bridge-level flow table, and finally the port-level flow table. The flow table is divided into levels to facilitate subsequent hierarchical processing of traffic. When configuring the flow table, if there is no suitable matching condition template and execution action template in the OVS database, the original method of configuring matching conditions and execution actions separately can still be used.
[0214] S3. Use hierarchical flow tables to forward and filter traffic received by the OVS system level by level; the specific steps of step S3 are as follows:
[0215] S 31. After receiving traffic from an external device, the OVS system determines whether the OVS default system-level flow table exists;
[0216] If so, the OVS system does not manage the traffic of external devices, and all bridges in the OVS system are used as destination bridges, proceeding to step S34;
[0217] If not, retrieve the matching condition template and execution action template from the OVS system-level flow table;
[0218] S 32. Retrieve from the OVS database the matching condition templates corresponding to each matching condition and the execution action templates corresponding to each execution action in the OVS system-level flow table;
[0219] The S 33.OVS system uses the found matching conditions to filter the traffic from external devices, then uses the found execution actions to process the filtered traffic, and determines the destination bridge for traffic forwarding.
[0220] S 34. Upon receiving traffic forwarded by the OVS system, determine if a default bridge-level flow table exists;
[0221] If so, the destination bridge does not manage the OVS system traffic, and all ports under the destination bridge are treated as destination ports, proceeding to step S37;
[0222] If not, retrieve the matching condition template and execution action template from the bridge-level flow table;
[0223] S 35. Retrieve from the OVS database the matching condition templates for the bridge-level flow table, corresponding to each matching condition, and the execution action templates for each execution action;
[0224] S 36. The destination bridge uses the found matching conditions to filter the traffic forwarded by the OVS system, and then uses the execution actions to process the filtered traffic to determine the destination port for traffic forwarding;
[0225] S 37. Upon receiving traffic forwarded by the destination bridge, determine if a default port-level flow table exists at the destination port port.
[0226] If so, the destination port does not manage the traffic of the destination bridge, but directly forwards the traffic and ends the process;
[0227] If not, retrieve the matching condition template and execution action template from the port-level flow table;
[0228] S 38. Retrieve the matching condition templates for port-level flow tables from the OVS database, along with the corresponding matching conditions and actions;
[0229] S 39. The destination port uses the found matching conditions to filter the traffic forwarded by the destination bridge, and then uses various execution actions to process the filtered traffic to complete the traffic forwarding; the traffic is processed according to the flow table level. Among them, the system-level flow table can intercept or forward all traffic as a whole, realizing unified traffic processing, while the flow tables of each bridge and port realize precise traffic processing.
[0230] The OVS system-level flow table configuration plays a crucial role in OVS, with its scope covering the entire OVS system. All traffic entering the OVS system first undergoes processing through the OVS system-level flow table, enabling global control over all traffic. Depending on requirements, the OVS system-level flow table can be configured to block all eligible traffic from entering the OVS system, or only allow eligible traffic to enter. Alternatively, one can choose not to configure the OVS system-level flow table and use the default open flow table, in which case all traffic will be matched against the bridge-level flow table.
[0231] Unlike OVS system-level flow tables, bridge-level flow tables have a scope of specific bridges and only apply to all ports on that bridge. When traffic passes through the OVS system-level flow table and enters the designated bridge, it will be further filtered by the bridge-level flow table. By configuring the bridge-level flow table, fine-grained control and management of traffic on a specific bridge can be achieved.
[0232] Port-level flow tables have the smallest scope, operating only on specific ports and performing corresponding actions on traffic that meets the requirements of that port. By configuring port-level flow tables, personalized processing of traffic on each port can be achieved, such as limiting bandwidth or implementing security policies.
[0233] In some embodiments, in step S23, it is determined whether there are bridges of the same type for which bridge-level flow tables need to be created. When there are bridges of the same type, in step S24, after the creation of the first bridge-level flow table is completed, the bridge-level flow table is directly copied to the same type of bridge to complete the creation of bridge-level flow tables for the same type of bridge.
[0234] In step S25, it is determined whether there are ports of the same type for which port-level flow tables need to be created. If there are ports of the same type, in step S26, after the creation of the first port-level flow table is completed, the port-level flow table is directly assigned to the port of the same type, and the port-level flow table creation for the port of the same type is completed.
[0235] For bridges or ports of the same type, the flow tables that need to be configured are the same. The use of matching condition templates and action templates makes it easy to copy the flow table configuration after it has been completed.
[0236] Example 4:
[0237] like Figure 6 As shown, the present invention provides an OVS flow table creation apparatus, comprising:
[0238] The template generation module is used to create matching condition templates and execution action templates for OVS flow tables; the template generation module includes:
[0239] The set creation unit is used to perform statistics on the original OVS flow table and create a set of matching conditions and a set of execution actions;
[0240] The unit for obtaining matching conditions to be aggregated is used to select matching conditions to be aggregated from the set of matching conditions according to requirements, or to count the matching conditions in the set of matching conditions that are used more than a threshold at the same time as matching conditions to be aggregated.
[0241] The unit for obtaining execution actions to be aggregated is used to select execution actions to be aggregated from the set of execution actions according to requirements, or to count the execution actions in the set of execution actions that are used more than a threshold at the same time as execution actions to be aggregated.
[0242] The matching condition template saving unit is used to combine the matching conditions to be aggregated to generate a matching condition template and name it, and save the matching condition template, name and each matching condition of the matching condition template to the OVS database;
[0243] The execution action template saving unit is used to combine the execution actions to be aggregated to generate an execution action template and name it, and save the execution action template, name and each execution action of the execution action template to the OVS database;
[0244] The template editing interface creation unit is used to create interfaces for adding, deleting, and modifying matching condition templates and action templates in the OVS database;
[0245] The hierarchical flow table creation module is used to create hierarchical flow tables in the OVS system using matching condition templates and execution action templates. The hierarchical flow table creation module includes:
[0246] The system flow table creation decision unit is used to determine whether an OVS system-level flow table needs to be created.
[0247] The system flow table creation unit is used to obtain the system traffic management requirements of the OVS system when it is necessary to create an OVS system-level flow table. Based on the system traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and uses the found matching condition templates and execution action templates to create the OVS system-level flow table in the OVS system.
[0248] The bridge flow table creation judgment unit is used to determine whether each bridge needs to create a bridge-level flow table after the OVS system-level flow table is created or not required to create an OVS system-level flow table.
[0249] The bridge flow table creation unit is used to obtain the bridge traffic management requirements of the bridge when it is necessary to create a bridge-level flow table. Based on the bridge traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and uses the found matching condition templates and execution action templates to create a bridge-level flow table on the bridge.
[0250] The port-level flow table creation judgment unit is used to determine whether port-level flow tables need to be created for each port under the bridge when there is no need to create bridge-level flow tables or when the bridge-level flow table has been created.
[0251] The port-level flow table creation unit is used to obtain the port traffic management requirements of a port when it is necessary to create a port-level flow table. Based on the port traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and then uses the found matching condition templates and execution action templates to create a port-level flow table on the port.
[0252] The traffic management module is used to forward and filter traffic received by the OVS system using hierarchical flow tables. The traffic management module includes:
[0253] The system template acquisition unit is used to acquire the matching condition template and execution action template in the OVS system-level flow table after the OVS system receives traffic from external devices;
[0254] The system flow table matching condition and execution action lookup unit is used to look up the matching condition templates corresponding to the matching conditions and the execution action templates corresponding to the execution actions of the OVS system-level flow tables from the OVS database.
[0255] The system traffic management unit is used to filter external device traffic in the OVS system using the matching conditions found, process the filtered traffic using the execution actions found, and determine the destination bridge for traffic forwarding.
[0256] The bridge template acquisition unit is used to acquire the matching condition template and the action template in the bridge-level flow table when the destination bridge receives traffic forwarded by the OVS system.
[0257] The bridge flow table matching condition and execution action lookup unit is used to look up the matching condition template corresponding to each matching condition and the execution action template corresponding to each execution action from the OVS database.
[0258] The bridge traffic management unit is used to filter the traffic forwarded by the OVS system at the destination bridge using the found matching conditions, and then use various execution actions to process the filtered traffic to determine the destination port for traffic forwarding.
[0259] The port template acquisition unit is used to acquire the matching condition template and the action template in the port-level flow table when receiving traffic forwarded by the destination bridge.
[0260] The port flow table matching condition and execution action lookup unit is used to look up the matching condition templates of port-level flow tables from the OVS database, along with the corresponding matching conditions and execution actions.
[0261] The port traffic management unit is used to filter the traffic forwarded by the destination bridge at the destination port using the found matching conditions, and then use various execution actions to process the filtered traffic to complete the traffic forwarding.
[0262] Example 5:
[0263] This invention provides a computer device, including a processor and a memory;
[0264] The memory is used to store computer programs, and the processor is used to call and run the computer programs from the memory, so that the computer device performs the methods described in Embodiment 1, Embodiment 2 or Embodiment 3 above.
[0265] Example 6:
[0266] This invention provides a storage medium,
[0267] The storage medium stores instructions that, when run on a computer, cause the computer to execute the methods described in Embodiment 1, Embodiment 2, or Embodiment 3.
[0268] Although the present invention has been described in detail with reference to the accompanying drawings and preferred embodiments, the invention is not limited thereto. Various equivalent modifications or substitutions can be made to the embodiments of the invention by those skilled in the art without departing from the spirit and essence of the invention, and such modifications or substitutions should all be within the scope of the invention. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the invention should also be covered within the protection scope of the invention. Therefore, the protection scope of the invention should be determined by the scope of the claims.
Claims
1. An OVS flow table creation method, characterized in that, Includes the following steps: Create matching condition templates and action templates for OVS flow tables; Create hierarchical flow tables in the OVS system using matching condition templates and execution action templates; Use hierarchical flow tables to forward and filter traffic received by the OVS system step by step; The specific steps for creating a hierarchical flow table in the OVS system using matching condition templates and execution action templates are as follows: Determine whether it is necessary to create an OVS system-level flow table; When it is necessary to create an OVS system-level flow table, obtain the system traffic management requirements of the OVS system, find the matching condition template and execution action template in the OVS database according to the system traffic management requirements, and use the found matching condition template and execution action template to create the OVS system-level flow table in the OVS system. If it is not necessary to create an OVS system-level flow table, or after the OVS system-level flow table has been created, determine in turn whether each bridge needs to create a bridge-level flow table. When it is necessary to create a bridge-level flow table, obtain the bridge traffic management requirements of the bridge, search for matching condition templates and execution action templates in the OVS database according to the bridge traffic management requirements, and create the bridge-level flow table on the bridge using the found matching condition templates and execution action templates. If it is not necessary to create a bridge-level flow table, or after the bridge-level flow table has been created, determine in turn whether each port under the bridge needs to create a port-level flow table; When it is necessary to create a port-level flow table, obtain the port traffic management requirements of the port, search for matching condition templates and execution action templates in the OVS database according to the port traffic management requirements, and create a port-level flow table on the port using the found matching condition templates and execution action templates. You can proceed to the traffic management step without creating port-level flow tables or after creating port-level flow tables.
2. The OVS flow table creation method as described in claim 1, characterized in that, The specific steps for creating matching condition templates and action templates for OVS flow tables are as follows: Perform statistical analysis on the original OVS flow table to establish a set of matching conditions and a set of execution actions; Select matching conditions to be aggregated from the set of matching conditions according to the requirements, or count the matching conditions in the set of matching conditions that are used more than a threshold at the same time as the matching conditions to be aggregated. Based on the requirements, select the execution actions to be aggregated from the set of execution actions, or count the execution actions in the set of execution actions that are used more than a threshold at the same time as the execution actions to be aggregated. Combine the matching conditions to be aggregated to generate a matching condition template and name it. Save the matching condition template, the name, and each matching condition of the matching condition template to the OVS database. The actions to be aggregated are combined to generate an action template and named. The action template, the name, and each action of the action template are saved to the OVS database. Create interfaces for adding, deleting, and modifying matching condition templates and action templates in the OVS database.
3. The OVS flow table creation method as described in claim 1, characterized in that, The specific steps for obtaining the system traffic management requirements of the OVS system, finding matching condition templates and execution action templates in the OVS database based on the system traffic management requirements, and creating OVS system-level flow tables using the found matching condition templates and execution action templates are as follows: Obtain the system traffic management requirements of the OVS system, search the OVS database, and determine whether each matching condition template in the OVS database meets the system traffic management requirements. When the matching condition template in the OVS database meets the system traffic management requirements, the matching condition template that meets the requirements is selected and used to set the OVS system-level flow table, and the system traffic management requirement judgment step of the execution action template is entered. When the matching condition template in the OVS database does not meet the system traffic management requirements, the matching conditions are set one by one in the OVS system according to the system traffic management requirements. Based on the system traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the system traffic management requirements; When the execution action template in the OVS database meets the system traffic management requirements, select and use the qualified execution action template to set the OVS system-level flow table, and proceed to the bridge-level flow table creation judgment step; When the action templates in the OVS database do not meet the system traffic management requirements, the action to be executed is set one by one in the OVS system according to the system traffic management requirements. The specific steps for obtaining the bridge traffic management requirements of the bridge, finding the matching condition template and execution action template in the OVS database based on the bridge traffic management requirements, and then creating the bridge-level flow table using the found matching condition template and execution action template on the bridge are as follows: Obtain the bridge traffic management requirements of the bridge, search the OVS database, and determine whether each matching condition template in the OVS database meets the bridge traffic management requirements; When the matching condition template in the OVS database meets the bridge traffic management requirements, select and use the matching condition template that meets the requirements, set the bridge-level flow table, and enter the bridge traffic management requirement judgment step of the execution action template. When the matching condition template in the OVS database does not meet the bridge traffic management requirements, the matching conditions are set one by one on the bridge according to the bridge traffic management requirements. Based on the bridge traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the bridge traffic management requirements. When the execution action template in the OVS database meets the requirements of bridge traffic management, select and use the qualified execution action template to set the bridge-level flow table, and then proceed to the port-level flow table creation judgment step. When the action templates in the OVS database do not meet the bridge traffic management requirements, the action to be executed is set one by one on the bridge according to the bridge traffic management requirements. The specific steps for obtaining port traffic management requirements, finding matching condition templates and action templates in the OVS database based on these requirements, and then creating a port-level flow table on the port using the found matching condition templates and action templates are as follows: Obtain the port traffic management requirements for the port, search the OVS database, and determine whether each matching condition template in the OVS database meets the port traffic management requirements; When the matching condition template in the OVS database meets the port traffic management requirements, the matching condition template that meets the requirements is selected and used to set the port-level flow table, and the port traffic management requirement judgment step of the execution action template is entered. When the matching condition template in the OVS database does not meet the port traffic management requirements, the matching conditions are set one by one on the port according to the port traffic management requirements. Based on port traffic management requirements, search the OVS database and determine whether each execution action template in the OVS database meets the port traffic management requirements; When the execution action template in the OVS database meets the port traffic management requirements, select and use the qualified execution action template to set the port-level flow table and enter the traffic management step; When the action templates in the OVS database do not meet the port traffic management requirements, the action to be executed is set for each port according to the port traffic management requirements.
4. The OVS flow table creation method as described in claim 1, characterized in that, The specific steps for forwarding and filtering traffic received by the OVS system using hierarchical flow tables are as follows: After receiving traffic from external devices, the OVS system obtains the matching condition template and execution action template from the OVS system-level flow table; Retrieve from the OVS database the matching conditions corresponding to the matching condition templates of the OVS system-level flow tables and the execution actions corresponding to the execution action templates; The OVS system uses the found matching conditions to filter the traffic from external devices, then uses the found execution actions to process the filtered traffic, determine the destination bridge, and forward the traffic. Upon receiving traffic forwarded by the OVS system, the destination bridge obtains the matching condition template and the action template from the bridge-level flow table. Retrieve from the OVS database the matching conditions corresponding to the matching condition templates of the bridge-level flow table and the execution actions corresponding to the execution action templates; The destination bridge uses the found matching conditions to filter the traffic forwarded by the OVS system, then uses various execution actions to process the filtered traffic, determine the destination port, and forward the traffic. Upon receiving traffic forwarded by the destination bridge at the destination port, retrieve the matching condition template and the action template from the port-level flow table; Find the matching conditions corresponding to the matching condition templates of the port-level flow table and the execution actions corresponding to the execution action templates in the OVS database; The destination port uses the found matching conditions to filter the traffic forwarded by the destination bridge, and then uses various execution actions to process the filtered traffic to complete the traffic forwarding.
5. The OVS flow table creation method as described in claim 4, characterized in that, The OVS database also stores the default OVS system-level flow table, the default bridge-level flow table, and the default port-level flow table. In the OVS system-level flow table creation judgment step, if it is not necessary to create an OVS system-level flow table, the default OVS system-level flow table is used in the OVS system, and the process proceeds to the bridge-level flow table creation judgment step. In the bridge-level flow table creation judgment step, if it is not necessary to create a bridge-level flow table, the default bridge-level flow table is used in the bridge, and the port-level flow table creation judgment step is entered. In the port-level flow table creation judgment step, if it is not necessary to create a port-level flow table, the default port-level flow table is used for the port, and the flow management step is entered. In the steps of obtaining the matching condition template and execution action template of the OVS system-level flow table, after the OVS system receives the traffic from the external device, it determines whether a default OVS system-level flow table exists. If so, the OVS system does not manage the traffic of external devices, and treats each bridge in the OVS system as the destination bridge, and enters the steps of obtaining the matching condition template and execution action template of the bridge-level flow table; If not, obtain the matching condition template and execution action template of the OVS system-level flow table, and proceed to the step of finding the matching condition template corresponding to each matching condition and the execution action template corresponding to each execution action from the OVS database; In the steps of obtaining the matching condition template and execution action template in the bridge-level flow table, the destination bridge that receives the traffic forwarded by the OVS system determines whether a default bridge-level flow table exists. If so, the destination bridge does not manage the OVS system traffic, and treats each port under the destination bridge as the destination port, and enters the steps of obtaining the matching condition template and executing the action template in the port-level flow table; If not, obtain the matching condition template and execution action template of the bridge-level flow table, and proceed to the step of finding the matching condition template corresponding to each matching condition and the execution action template corresponding to each execution action from the OVS database; In the steps of obtaining the matching condition template and executing the action template in the port-level flow table, the destination port of the traffic forwarded by the destination bridge is received, and it is determined whether a default port-level flow table exists. If so, the destination port does not manage the traffic of the destination bridge and directly forwards the traffic.
6. The OVS flow table creation method as described in claim 1, characterized in that, In the bridge-level flow table creation judgment step, it is determined whether there are bridges of the same type for which a bridge-level flow table needs to be created. When there are bridges of the same type, after the first bridge-level flow table is created in the bridge-level flow table creation step, the bridge-level flow table is directly copied to the same type of bridge to complete the creation of the bridge-level flow table for the same type of bridge. In the port-level flow table creation judgment step, it is determined whether there are ports of the same type for which port-level flow tables need to be created. When there are ports of the same type, in the port-level flow table creation step, after the creation of the first port-level flow table is completed, the port-level flow table is directly copied to the port of the same type to complete the creation of port-level flow tables for the same type of ports.
7. An OVS flow table creation device, characterized in that, include: The template generation module is used to create matching condition templates and execution action templates for OVS flow tables. The hierarchical flow table creation module is used to create hierarchical flow tables in the OVS system using matching condition templates and execution action templates. The traffic management module is used to forward and filter traffic received by the OVS system step by step using hierarchical flow tables; The flow table hierarchical creation module includes: The system-level flow table creation decision unit is used to determine whether an OVS system-level flow table needs to be created. The system-level flow table creation unit is used to obtain the system traffic management requirements of the OVS system when it is necessary to create an OVS system-level flow table. Based on the system traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and uses the found matching condition templates and execution action templates to create the OVS system-level flow table in the OVS system. The bridge-level flow table creation judgment unit is used to determine whether each bridge needs to create a bridge-level flow table after the OVS system-level flow table is created or not required to be created. The bridge-level flow table creation unit is used to obtain the bridge traffic management requirements of the bridge when it is necessary to create a bridge-level flow table. Based on the bridge traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and uses the found matching condition templates and execution action templates to create a bridge-level flow table on the bridge. The port-level flow table creation judgment unit is used to determine whether port-level flow tables need to be created for each port under the bridge when there is no need to create bridge-level flow tables or when the bridge-level flow table has been created. The port-level flow table creation unit is used to obtain the port traffic management requirements of a port when it is necessary to create a port-level flow table. Based on the port traffic management requirements, it searches for matching condition templates and execution action templates in the OVS database, and then uses the found matching condition templates and execution action templates to create a port-level flow table on the port. The system also performs the following steps: if port-level flow table creation is not required or port-level flow table creation is complete, proceed to the flow management module's flow management steps.
8. A computer device, characterized in that, Including processor and memory; The memory is used to store a computer program, and the processor is used to retrieve and run the computer program from the memory, causing the computer device to perform the method described in any one of claims 1-6.
9. A storage medium, characterized in that, The storage medium stores instructions that, when run on a computer, cause the computer to perform the method described in any one of claims 1-6.
Citation Information
Patent Citations
Flow table processing method and device
CN114448886A
Verifying firewall filter entries using rules associated with an access control list (ACL) template
US9912639B1