A traffic control method and system based on a P4 switch
By binding the P4 Internet gateway to the P4 switch, the speed limit of a single traffic is solved, the performance improvement problem of a single traffic is optimized, and the network performance is reduced.
Patent Information
- Application Number
- CN202410537547.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-30
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-04-30
AI Technical Summary
In the prior art, the packet processing rate or data transmission rate of a single traffic exceeds the processing capacity of the network element, resulting in the performance of a single traffic being unable to be further improved, and the existing methods lead to network delay and resource waste.
By binding the P4 Internet gateway on the P4 switch, establishing a correspondence relationship, and limiting the speed of a single stream according to the needs of the public network bandwidth, improving the processing performance of a single stream.
Optimizes the processing efficiency of Eip traffic, avoids network element overload, improves network performance and reduces latency.
Smart Images

Figure CN118282957B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication networks, and particularly relates to a traffic control method and system based on a P4 switch. Background Art
[0002] Currently, a user can access its application services located on the cloud through a public network IP address (EIP), and at the same time use an internal network fixed IP address to communicate within the cloud. The user sends a network application layer request to the public cloud service with an Eip through the Internet. The request traffic corresponding to the network application request first routes through the Internet to the ingress switch of the public cloud. The public cloud service is built based on the public cloud. Inside the public cloud, DPDK and X86 servers are used to process high-performance network functions. Through the BGP protocol, high-performance network elements in the public cloud announce the Eip address route to the ingress switch. Thus, based on the Eip address route, the traffic of the Eip is sent to the cloud internal network element. After receiving the traffic, the cloud internal network element performs rate limiting processing, and forwards the traffic after rate limiting to the port corresponding to the Ecs instance. The Ecs instance generates response traffic according to the traffic after rate limiting and forwards it to the Internet gateway, so that the user can access the service through the Internet through the response traffic. However, in the above communication method, the DPDK technology uses a server to implement high-performance network elements, which only supports horizontal expansion. For a single flow from the same source to the same destination, it will continuously be routed to the same network element, and this single flow is only supported by one network element, and other network elements cannot support it. This will cause the packet processing rate or data transmission rate requirement of this flow to exceed the processing capacity of this network element. Then, even if other network elements have idle resources, the performance of this flow cannot be further improved. Summary of the Invention
[0003] In view of the above deficiencies of the prior art, the purpose of the invention is to provide a traffic control method and system based on a P4 switch, which improves the processing efficiency of a single flow. This method binds a virtual private cloud with a P4 Internet gateway, establishes a corresponding relationship between the P4 Internet gateway and the P4 switch, and performs rate limiting processing on a single flow on the P4 switch according to the public network bandwidth requirement, thereby improving the performance of single flow processing.
[0004] In the first aspect of the present invention, a traffic control method based on a P4 switch is proposed, including:
[0005] The edge switch receives a network application layer request sent by the Internet route; wherein, the network application layer request indicates a request for the Internet route to communicate with the client;
[0006] The virtual private cloud receives the network application layer request sent by the edge switch;
[0007] The virtual private cloud is bound to the P4 Internet gateway according to the network application request. If the P4 Internet gateway is in an open state and the elastic public network is communicatively connected to the P4 Internet gateway, a processing instruction is generated. Among them, the P4 Internet gateway table corresponding to the P4 Internet gateway stores the association relationship between the virtual private cloud and the P4 Internet gateway, and the P4 Internet gateway establishes a corresponding relationship with the P4 switch.
[0008] The P4 switch publishes the address of the elastic public network route to the border switch according to the processing instruction.
[0009] The border switch obtains the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and sends the request traffic of the elastic public network to the P4 switch.
[0010] The P4 switch performs speed limit processing on the request traffic of the elastic public network to obtain the request traffic of the elastic public network after speed limit processing, and forwards the request traffic of the elastic public network after speed limit processing to the corresponding elastic public network host instance.
[0011] The elastic public network host instance responds to the request traffic of the elastic public network after speed limit processing to obtain response traffic, and sends the response traffic to the P4 switch.
[0012] The P4 switch performs speed limit processing on the response traffic to obtain the response traffic after speed limit, and sends the response traffic after speed limit to the border switch.
[0013] The border switch sends the response traffic after speed limit to the client through the Internet route, so that the client communicates with the Internet route.
[0014] Further, the publishing the address of the elastic public network route to the border switch according to the processing instruction includes:
[0015] Publishing the address of the elastic public network route of the elastic public network bound to the elastic public network host instance under the original virtual private cloud to the border switch through the Border Gateway Protocol (BGP); among them, the routing priority of the elastic public network route is less than the routing priority of the Internet network element server.
[0016] Further, the traffic control method based on the P4 switch further includes:
[0017] When the P4 Internet gateway is in the open state and the elastic public network is defaultly diverted to the P4 Internet gateway, the P4 switch publishes the elastic public network route under the virtual private cloud bound to the P4 Internet gateway to the border switch; wherein, the routing priority of the elastic public network route is less than that of the Internet network element server.
[0018] Further, the traffic control method based on the P4 switch further includes:
[0019] When the P4 Internet gateway is in the closed state, the P4 switch generates a traffic forwarding configuration.
[0020] Further, there are multiple P4 switches, wherein, obtaining the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request and sending the request traffic of the elastic public network to the P4 switch includes:
[0021] Obtaining the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request and sending the request traffic of the elastic public network to multiple P4 switches; wherein, the routing priorities of the multiple P4 switches are less than a preset priority threshold;
[0022] When the multiple P4 switches are abnormal, sending the request traffic of the elastic public network to the Internet gateway; wherein, the Internet gateway performs a downgrade process on the elastic public network route to obtain a downgraded elastic public network route.
[0023] Further, forwarding the request traffic of the elastic public network after rate limiting processing to the corresponding elastic public network host instance includes:
[0024] Performing network address translation on the request traffic of the elastic public network after rate limiting processing;
[0025] Changing the destination IP corresponding to the translated request traffic to the fixed IP corresponding to the internal network of the elastic public network host instance;
[0026] Encapsulating the changed request traffic;
[0027] Sending the encapsulated request traffic to the corresponding elastic public network host instance through a computing node; wherein, the computing node is communicatively connected to the elastic public network host instance and the P4 switch respectively.
[0028] Further, encapsulating the changed request traffic includes:
[0029] Changing the destination IP to the computing internal network IP of the computing node where the elastic public network host instance is located;
[0030] Set the network identifier to the virtual network identifier in the virtual private cloud;
[0031] Set the MAC address of the destination device in the data packet to the Mac address of the elastic public network host instance.
[0032] Further, the sending the response traffic to the P4 switch includes:
[0033] Send the response traffic to the P4 switch through the computing node; wherein, the computing node encapsulates the response traffic.
[0034] Further, the rate limiting process for the response traffic includes:
[0035] Receive the encapsulated response traffic sent by the computing node;
[0036] Perform network address translation on the encapsulated response traffic;
[0037] Perform rate limiting processing on the translated response traffic.
[0038] A second aspect of the present invention, a traffic control system based on a P4 switch, includes:
[0039] A boundary switch for receiving a network application layer request sent by an Internet route, wherein the network application layer request indicates a request for the Internet route to communicate with a client. The boundary switch obtains the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and sends the request traffic of the elastic public network to the P4 switch, and sends the rate-limited response traffic to the client through the Internet route, so that the client communicates with the Internet route;
[0040] A virtual private cloud, which is communicatively connected to the boundary switch. The virtual private cloud receives the network application layer request sent by the boundary switch, binds to the P4 Internet gateway according to the network application request. If the P4 Internet gateway is in an open state and the elastic public network is communicatively connected to the P4 Internet gateway, a processing instruction is generated. Wherein, the P4 Internet gateway table corresponding to the P4 Internet gateway stores the association relationship between the virtual private cloud and the P4 Internet gateway, and the P4 Internet gateway establishes a corresponding relationship with the P4 switch;
[0041] The P4 switch is communicatively connected to the border switch. The P4 switch issues the address of the elastic public network route to the border switch according to the processing instruction, performs rate limiting on the request traffic of the elastic public network to obtain the request traffic of the elastic public network after rate limiting, and forwards the request traffic of the elastic public network after rate limiting to the corresponding elastic public network host instance, performs rate limiting on the response traffic to obtain the response traffic after rate limiting, and sends the response traffic after rate limiting to the border switch.
[0042] The elastic public network host instance is communicatively connected to the P4 switch. The elastic public network host instance is used to respond to the request traffic of the elastic public network after rate limiting to obtain response traffic, and send the response traffic to the P4 switch.
[0043] The beneficial effects of the present invention are as follows:
[0044] The traffic control method and system based on the P4 switch of the present invention can optimize the Eip traffic by constructing a P4 Internet gateway to support the binding of the P4 switch and the virtual private cloud, and enabling the P4 switch to perform rate limiting on the Eip traffic (traffic of the elastic public network). And by adding an activated P4 Internet gateway field to the elastic public network, it supports rate limiting either on the request traffic corresponding to the elastic public network under the original virtual private cloud or on the request traffic corresponding to the elastic public network of the virtual private cloud bound to the P4 Internet gateway. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The drawings are only for the purpose of illustrating specific embodiments and are not considered to be a limitation of the present invention. Throughout the drawings, the same reference signs denote the same components. Obviously, the drawings in the following description are only some embodiments described in the embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings.
[0046] Figure 1 It is a flowchart of a traffic control method for a P4 switch according to an embodiment of the present invention;
[0047] Figure 2 It is a flowchart of a traffic control method for a P4 switch according to another embodiment of the present invention;
[0048] Figure 3 It is a flowchart of a traffic control method for a P4 switch according to another embodiment of the present invention;
[0049] Figure 4 It is a schematic diagram of a traffic control system for a P4 switch according to an embodiment of the present invention;
[0050] Figure 5 It is a schematic structural diagram of the electronic device according to an embodiment of the present invention. Detailed implementation manners
[0051] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0052] In addition, in the following description, the descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts disclosed in the present invention.
[0053] In the description of the present invention, it should be noted that unless otherwise clearly defined and limited, the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be understood as a limitation to the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. The terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0054] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all the implementation manners consistent with the present invention. On the contrary, they are merely examples of the methods and systems consistent with some aspects of the present invention as detailed in the appended claims.
[0055] The present invention provides a traffic control method and system based on a P4 switch, aiming to solve the problems that the packet processing rate or data transmission rate requirement of a single flow in the existing method exceeds the processing capacity of the corresponding network element, even if other network elements have idle resources, resulting in the inability to further improve the performance of a single flow, and that the public cloud needs to centrally collect Eip traffic statistics and then send new speed limit configurations to each network element, resulting in delays during the statistical data calculation and speed limit configuration distribution processes.
[0056] Method Embodiment
[0057] A traffic control method based on a P4 switch provided by the present invention optimizes the traffic of the elastic public network through the P4 switch, thereby improving network performance.
[0058] Specifically, the method includes steps S1 to S9, as Figure 1 shown.
[0059] Step S1. The border switch receives a network application layer request sent by the Internet route, where the network application layer request indicates a request for the Internet route to communicate with the client.
[0060] In an embodiment of the present invention, the user sends a network application layer request to a public cloud service with an elastic public network through the Internet route. Among them, the request traffic of the elastic public network corresponding to the network application layer request passes through the border switch of the public cloud service. The traffic corresponding to the response is obtained from the elastic public network instance through the network application layer request, so that the Internet route and the client can communicate. Among them, the internal network of the Internet route is communicatively connected to the internal network plane of the border switch, the external network of the Internet route is communicatively connected to the public network plane of the border switch, the public network plane of the border switch is also communicatively connected to the Internet gateway, and the Internet gateway is communicatively connected to the Internet.
[0061] Step S2. The virtual private cloud receives the network application layer request sent by the border switch.
[0062] In an embodiment of the present invention, the border switch can send the network application layer request to the virtual private cloud. Among them, the virtual private cloud is built on the computing internal network switch. The computing internal network switch is communicatively connected to the internal network plane of the border switch. The internal network of the virtual private cloud is communicatively connected to the computing internal network switch. The computing internal network switch is used to construct the computing internal network. The computing internal network switch prevents the virtual private cloud from directly communicating with the public network, reducing the possibility of being attacked. The computing internal network switch is used to forward the network application layer request received by the border switch to the virtual private cloud.
[0063] Step S3. The virtual private cloud is bound to the P4 Internet gateway according to the network application request. If the P4 Internet gateway is turned on and the elastic public network is connected to the P4 Internet gateway for communication, a processing instruction is generated; wherein the P4 Internet gateway table corresponding to the P4 Internet gateway stores the association relationship between the virtual private cloud and the P4 Internet gateway, and a corresponding relationship is established between the P4 Internet gateway and the P4 switch.
[0064] In an embodiment of the present invention, when the virtual private cloud receives a network application request, the virtual private cloud is bound to the P4 Internet gateway, thereby forwarding the request traffic of the elastic public network to the P4 switch, and then the P4 switch performs rate limiting processing on the request traffic.
[0065] Among them, the P4 Internet gateway table corresponding to the P4 Internet gateway is shown in Table 1.
[0066] Table 1
[0067]
[0068]
[0069] According to Table 1, a correspondence is established between the gateway instance ID of the P4 Internet gateway and the VPC ID in the cloud of the virtual private cloud, so that the request traffic is transferred to the P4 Internet gateway with the corresponding gateway instance ID according to the VPC ID in the cloud for processing. Among them, whether the P4 Internet gateway is put into use can be determined by the management status. If admin_status is false, the P4 Internet gateway is in the open state and can be put into use. If admin_status is true, the P4 Internet gateway is in the closed state and cannot be put into use.
[0070] If deafault_enable is false, the elastic public network is marked not to be diverted to the P4 Internet gateway by default. If deafault_enable is true, the elastic public network is marked to be diverted to the P4 Internet gateway by default.
[0071] Then, if the P4 Internet gateway is turned on, the elastic public network is marked not to be directed to the P4 Internet gateway by default, and the elastic public network is connected to the P4 Internet gateway, the virtual private cloud generates a processing instruction to send to the P4 switch, so that the P4 switch processes the request traffic of the elastic public network. The P4 cluster ID in Table 1 represents the ID of the P4 switch, where if there is one P4 switch, Group_id represents the P4 switch ID, and if there are multiple P4 switches, Group_id represents the P4 switch cluster ID.
[0072] Step S4. The P4 switch publishes the address of the elastic public network route to the border switch according to the processing instruction.
[0073] In the embodiment of the present invention, since the P4 switch establishes a corresponding relationship with the P4 Internet gateway, the processing instruction can be sent to the P4 switch through the P4 Internet gateway. The P4 switch publishes the elastic public network route address to the border switch according to the processing instruction. Among them, AsPath is smaller than the Internet network element server, and the ASPath controls the routing priority of publishing the Eip through BGP. Eip is the elastic public network. Among them, the internal network of the P4 switch can be communicatively connected to the internal network plane of the border switch, and the external network of the P4 switch can be communicatively connected to the external network plane of the border switch.
[0074] Step S5. The border switch obtains the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and sends the request traffic of the elastic public network to the P4 switch.
[0075] In the embodiment of the present invention, the border switch searches the local routing table based on the elastic public network route address and the size of the request traffic of the network application layer request, and sends the request traffic of the elastic public network to the P4 switch, so that the P4 switch can perform rate limiting processing on the request traffic. Since in the prior art, the traffic from the same source to the same destination will continue to be routed to the same network element. If the packet processing rate (PPS) or data transmission rate (BPS) requirement of this flow exceeds the processing capacity of this network element, then even if other network elements have idle resources, the performance of this flow cannot be further improved. Therefore, the P4 switch performs rate limiting processing on the request traffic, so as to set the packet processing rate (PPS) or data transmission rate (BPS) of the single flow exceeding this network element to be processed by the P4 switch, thereby improving the performance of this single flow.
[0076] Step S6. The P4 switch performs rate limiting processing on the request traffic of the elastic public network to obtain the request traffic of the elastic public network after rate limiting processing, and forwards the request traffic of the elastic public network after rate limiting processing to the corresponding elastic public network host instance.
[0077] Step S7. The elastic public network host instance responds to the request traffic of the elastic public network after rate limiting processing to obtain the response traffic, and sends the response traffic to the P4 switch.
[0078] In the embodiment of the present invention, since the P4 switch performs rate limiting processing on the request traffic of the elastic public network, the transmission speed of this request traffic becomes slower. The elastic public network host instance responds according to the request traffic of the elastic public network after rate limiting processing to obtain the response traffic, and the transmission speed of this response traffic is equal to the transmission speed of the request traffic after rate limiting processing.
[0079] Among them, the P4 switch performs rate limiting on the request traffic, which can control the traffic rate flowing into the elastic public network and avoid causing too much load on the elastic public network.
[0080] Step S8. The P4 switch performs rate limiting on the response traffic to obtain the rate-limited response traffic, and sends the rate-limited response traffic to the border switch.
[0081] In the embodiment of the present invention, the P4 switch performs rate limiting on the response traffic to prevent the elastic public network host instance from generating too much response traffic, which may cause overload of the border switch or Internet routing, thereby improving the network performance.
[0082] Step S9. The border switch sends the rate-limited response traffic to the client through the Internet routing, so that the client can communicate with the Internet routing.
[0083] The P4 switch mentioned above is a programmable data plane device that can customize the processing logic of data packets according to specific network traffic requirements. The border switch refers to a switch that connects different network areas in the network and is usually used to connect different physical networks or logical networks. Among them, the rate-limited response traffic of the P4 switch is forwarded to the Internet routing through the internal network plane of the border switch, so that the Internet routing can communicate with the client.
[0084] Figure 2 This is a flowchart of a traffic control method based on a P4 switch according to another embodiment of the present invention. As Figure 2 shown, step S4 may include:
[0085] Step S41. Publish the address of the elastic public network route of the elastic public network bound to the elastic public network host instance under the original virtual private cloud to the border switch through the Border Gateway Protocol, where the routing priority of the elastic public network route is lower than that of the Internet network element server.
[0086] In an embodiment of the present invention, the P4 switch publishes the address of the elastic public network route of the elastic public network host instance bound under the virtual private cloud to the border switch through BGP, ensuring that the request traffic authorized by the border switch reaches the elastic public network host instance, so as to achieve the correct forwarding and processing of the traffic and enhance the network security. Among them, BGP is the abbreviation of Border Gateway Protocol, which is one of the most commonly used routing protocols in the Internet. BGP is a path vector protocol, mainly used to exchange routing information between different autonomous systems (ASes), and help different networks in the Internet find the best path for data transmission. If there are multiple elastic public networks, the border switch forwards the corresponding request traffic to the P4 switch in turn according to multiple elastic public network route addresses (the multiple elastic public network route addresses are not bound to the P4 Internet gateway with the original virtual private cloud), and this process is called Eip granularity drainage, where Eip is the elastic public network.
[0087] In addition, when both the elastic public network and the Internet gateway server are communicatively connected to the border switch, in order to ensure the normal operation of the service, the routing priority of the Internet gateway server is set to be higher and higher than that of the elastic public network route. Since the Internet gateway server includes network security functions such as firewalls and intrusion detection systems, it is necessary to deeply inspect and filter the request traffic. In order to ensure network security, it is necessary for the Internet gateway server to process the request traffic first. Then process the traffic of the elastic public network.
[0088] In an embodiment, the traffic control method based on the P4 switch can be specifically implemented as follows: when the P4 Internet gateway is in the open state and the elastic public network is default-drained to the P4 Internet gateway, the P4 switch publishes the elastic public network route under the virtual private cloud bound to the P4 Internet gateway to the border switch, where the routing priority of the elastic public network route is less than that of the Internet network element server.
[0089] In an embodiment of the present invention, when the P4 Internet gateway is in the open state and the elastic public network is default-drained to the P4 Internet gateway, that is, when admin_status is up and deafault_enable is true, the P4 switch publishes the elastic public network route under the virtual private cloud bound to the P4 Internet gateway to the border switch, that is, publishes all the elastic public network routes under the bound virtual private cloud to the border switch, that is, this process is the VPC drainage granularity. In an embodiment, the traffic control method based on the P4 switch can be specifically implemented as follows: when the P4 Internet gateway is in the closed state, the P4 switch generates a traffic forwarding configuration.
[0090] In an embodiment of the present invention, when the P4 Internet gateway is in the closed state, it means that admin_status is down. Then, the P4 switch only generates traffic forwarding configurations and does not publish the routing address of the elastic public network to the border switch.
[0091] In one embodiment, when a virtual private cloud needs to be unbound from the P4 Internet gateway, it only needs to delete the P4 Internet gateway and delete the corresponding relationship established with the P4 Internet gateway on the P4 switch.
[0092] Figure 3 It is a flowchart of a traffic control method based on a P4 switch according to another embodiment of the present invention. As Figure 3 shown, there are multiple P4 switches, and step S5 may include:
[0093] Step S51. Obtain the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and send the request traffic of the elastic public network to multiple P4 switches; wherein, the routing priorities of the multiple P4 switches are less than a preset priority threshold; when the multiple P4 switches are abnormal, send the request traffic of the elastic public network to the Internet gateway, wherein the Internet gateway performs a downgrading process on the elastic public network route to obtain the downgraded elastic public network route.
[0094] In an embodiment of the present invention, multiple P4 switches that can set speed limits for the request traffic can be formed into a P4 cluster. When the P4 cluster is abnormal or fails, the P4 cluster can send the request traffic of the elastic public network to the Internet gateway. Since the Internet gateway is also bound to the virtual private cloud, the Internet gateway can also process the request traffic of the P4 cluster and downgrade the priority of the elastic public network route corresponding to the request traffic of the P4 cluster, thereby improving the network performance. The Internet gateway requests response traffic from the Internet server through the elastic public network route and sends the response traffic to the border switch so that the Internet route can communicate with the client through the response traffic.
[0095] In one embodiment, step S6 can be specifically implemented as: performing network address conversion on the request traffic of the elastic public network after speed limit processing; changing the destination IP corresponding to the converted request traffic to the fixed IP corresponding to the internal network of the elastic public network host instance; encapsulating the changed request traffic; and sending the encapsulated request traffic to the corresponding elastic public network host instance through the computing node, wherein the computing node is respectively communicatively connected to the elastic public network host instance and the P4 switch.
[0096] In an embodiment of the present invention, the P4 switch performs rate limiting on the request traffic of the elastic public network, and performs network address translation on the request traffic of the elastic public network after rate limiting. Specifically, it performs 1:1 Nat on the request traffic of the elastic public network after rate limiting. Then, it changes the destination IP corresponding to the converted request traffic to the fixed IP corresponding to the internal network of the elastic public network host instance. Specifically, it changes the destination IP corresponding to the converted request traffic to the Ecs internal network FixIp. Then, it encapsulates the changed request traffic into Vxlan. And it sends the encapsulated request traffic to the corresponding elastic public network host instance through the compute node vSwithch. The compute node is communicatively connected to the elastic public network host instance and the P4 switch through the compute internal network switch. The response traffic generated by the ECS instance returns to the port connecting the compute node through the virtual private cloud. After receiving the response traffic of the ECS instance, the compute node forwards the response traffic to the port connecting the P4 switch through the compute internal network switch.
[0097] In one embodiment, step S6 can be specifically implemented as: changing the destination IP to the compute internal network IP of the compute node where the elastic public network host instance is located; setting the network identifier to the virtual network identifier in the virtual private cloud; setting the MAC address of the destination device in the data packet to the Mac address of the elastic public network host instance.
[0098] In an embodiment of the present invention, the encapsulation process includes: changing the destination IP to the compute internal network IP of the compute node where the elastic public network host instance is located, setting the network identifier to the virtual network identifier in the virtual private cloud, setting the MAC address of the destination device in the data packet to the Mac address of the elastic public network host instance. Among them, changing the destination IP to the compute internal network IP of the compute node where the elastic public network host instance is located is expressed as the destination Ip being the compute internal network IP of the compute node where the Ecs is located, setting the network identifier to the virtual network identifier in the virtual private cloud is expressed as the VNI being the Vpc Vni. Setting the MAC address of the destination device in the data packet to the Mac address of the elastic public network host instance is expressed as the overlay destination Mac being the Mac of the Ecs Port.
[0099] In one embodiment, step S7 can be specifically implemented as: sending the response traffic to the P4 switch through the compute node; among them, the compute node encapsulates the response traffic.
[0100] In an embodiment of the present invention, the elastic public network host instance responds to the request data and sends the response traffic to the compute node vSwitch, and the compute node vSwitch encapsulates the response traffic into Vxlan. Its encapsulation steps include: the destination Ip is the compute internal network IP of the compute node where the P4 switch is located, the VNI is the Vpc Vni, and the overlay destination Mac is the Mac address of the P4 switch.
[0101] In one embodiment, step S8 can be specifically implemented as follows: receiving the encapsulated response traffic sent by the computing node; performing network address translation on the encapsulated response traffic; and performing rate limiting on the translated response traffic.
[0102] In the embodiment of the present invention, the encapsulated response traffic sent by the computing node is received, and then the network address translation is performed on the encapsulated response traffic, that is, 1:1 nat processing is performed. Then, rate limiting is performed on the translated response traffic to prevent excessive response traffic from being generated on the elastic public network, which may cause overload of the border switch or the Internet router, thereby improving the network performance.
[0103] Device embodiment
[0104] Another specific embodiment of the present invention discloses a traffic control system based on a P4 switch, including: a border switch 10, a virtual private cloud 20, a P4 switch 30, and an elastic public network host instance 40. The border switch 10 is used to receive a network application layer request sent by an Internet router, where the network application layer request indicates a request for the Internet router to communicate with a client. The border switch 10 obtains the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and sends the request traffic of the elastic public network to the P4 switch 30. The rate-limited response traffic is sent to the client through the Internet router to enable the client to communicate with the Internet router. The virtual private cloud 20 is communicatively connected to the border switch 10. The virtual private cloud 20 receives the network application layer request sent by the border switch 10, and binds to the P4 Internet gateway according to the network application request. If the P4 Internet gateway is in an open state and the elastic public network is communicatively connected to the P4 Internet gateway, a processing instruction is generated. Among them, the P4 Internet gateway table corresponding to the P4 Internet gateway stores the association relationship between the virtual private cloud and the P4 Internet gateway. The P4 Internet gateway establishes a corresponding relationship with the P4 switch. The P4 switch 30 is communicatively connected to the border switch 10. The P4 switch 30 publishes the address of the elastic public network route to the border switch 10 according to the processing instruction, performs rate limiting on the request traffic of the elastic public network to obtain the rate-limited request traffic of the elastic public network, and forwards the rate-limited request traffic of the elastic public network to the corresponding elastic public network host instance, performs rate limiting on the response traffic to obtain the rate-limited response traffic, sends the rate-limited response traffic to the border switch 10. The elastic public network host instance 40 is communicatively connected to the P4 switch 30. The elastic public network host instance 40 is used to respond to the rate-limited elastic public network request traffic to obtain a response traffic, and send the response traffic to the P4 switch 30.
[0105] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: publish the address of the elastic public network route of the elastic public network bound to the elastic public network host instance under the original virtual private cloud to the border switch through BGP; wherein, the routing priority of the elastic public network route is less than the routing priority of the Internet network element server.
[0106] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: when the P4 Internet gateway is in the open state and the elastic public network is defaultly diverted to the P4 Internet gateway, the P4 switch publishes the elastic public network route under the virtual private cloud bound to the P4 Internet gateway to the border switch; wherein, the routing priority of the elastic public network route is less than that of the Internet network element server.
[0107] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: when the P4 Internet gateway is in the closed state, the P4 switch generates a traffic forwarding configuration.
[0108] In one embodiment, there are multiple P4 switches, and the traffic control system based on the P4 switch can be specifically configured to: obtain the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and send the request traffic of the elastic public network to multiple P4 switches; wherein, the routing priorities of the multiple P4 switches are less than the preset priority threshold; when the multiple P4 switches are abnormal, send the request traffic of the elastic public network to the Internet gateway; wherein, the Internet gateway performs a downgrading process on the elastic public network route to obtain the downgraded elastic public network route.
[0109] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: perform network address translation on the request traffic of the elastic public network after rate limiting processing; change the destination IP corresponding to the translated request traffic to the fixed IP corresponding to the internal network of the elastic public network host instance; encapsulate the changed request traffic; send the encapsulated request traffic to the corresponding elastic public network host instance through the computing node; wherein, the computing node is communicatively connected to the elastic public network host instance and the P4 switch respectively.
[0110] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: change the destination IP to the computing internal network IP of the computing node where the elastic public network host instance is located; set the network identifier to the virtual network identifier in the virtual private cloud; set the MAC address of the destination device in the data packet to the Mac address of the elastic public network host instance.
[0111] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: send the response traffic to the P4 switch through the computing node; wherein, the computing node encapsulates the response traffic.
[0112] In one embodiment, the traffic control system based on the P4 switch can be specifically configured to: receive the encapsulated response traffic sent by the computing node; perform network address translation on the encapsulated response traffic; and perform rate limiting processing on the translated response traffic.
[0113] In a third aspect, the present invention provides an electronic device, as Figure 5 shown, comprising: a memory and one or more processors.
[0114] One or more application programs are stored in the memory, and the one or more application programs are adapted to be executed by the one or more processors to implement the traffic control method of the P4 switch described in the first aspect.
[0115] As Figure 5 shown, the electronic device 100 includes: a processor 101 and a memory 103. Among them, the processor 101 and the memory 103 are connected, such as through a bus 102.
[0116] The structure of the electronic device 100 does not constitute a limitation on the embodiments of the present invention.
[0117] The processor 101 may be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in connection with the disclosure of the present invention. The processor 101 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0118] The bus 102 may include a path for transmitting information between the above components. The bus 102 may be a PCI bus or an EISA bus, etc. The bus 102 may be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 5 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0119] The memory 103 may be a ROM or other type of static storage device that can store static information and instructions, a RAM or other type of dynamic storage device that can store information and instructions, or an EEPROM, a CD-ROM or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0120] Fourthly, the present invention provides a computer-readable storage medium, on which a computer program is stored. The computer program can be loaded and executed by a processor to implement the method for constructing scientific and technological big data elements described in the first aspect.
[0121] The applicant of the present invention has described the embodiments of the present invention in detail with reference to the accompanying drawings. However, those skilled in the art should understand that the above embodiments are only the preferred implementation schemes of the present invention, and the detailed description is only to help readers better understand the spirit of the present invention, rather than a limitation on the protection scope of the present invention. On the contrary, any improvement or modification based on the spirit of the present invention should fall within the protection scope of the present invention.
[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. Any changes or replacements that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention.
Claims
1. A traffic control method based on a P4 switch, characterized in that including: The border switch receives a network application layer request sent by the Internet route; wherein, the network application layer request indicates a request for the Internet route to communicate with the client; The virtual private cloud receives the network application layer request sent by the border switch; The virtual private cloud binds to the P4 Internet gateway according to the network application request. If the P4 Internet gateway is in an enabled state and the elastic public network is communicatively connected to the P4 Internet gateway, a processing instruction is generated; wherein, the P4 Internet gateway table corresponding to the P4 Internet gateway stores the association relationship between the virtual private cloud and the P4 Internet gateway, and the P4 Internet gateway establishes a corresponding relationship with the P4 switch; The P4 switch publishes the address of the elastic public network route to the border switch according to the processing instruction; The border switch obtains the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and sends the request traffic of the elastic public network to the P4 switch; The P4 switch performs rate limiting processing on the request traffic of the elastic public network to obtain the request traffic of the elastic public network after rate limiting processing, and forwards the request traffic of the elastic public network after rate limiting processing to the corresponding elastic public network host instance; The elastic public network host instance responds to the request traffic of the elastic public network after rate limiting processing to obtain response traffic, and sends the response traffic to the P4 switch; The P4 switch performs rate limiting processing on the response traffic to obtain the response traffic after rate limiting, and sends the response traffic after rate limiting to the border switch; The border switch sends the response traffic after rate limiting to the client through the Internet route, so that the client communicates with the Internet route; wherein, P4 represents a programming language.
2. The traffic control method based on a P4 switch according to claim 1, wherein The publishing the address of the elastic public network route to the border switch according to the processing instruction includes: Publishing the address of the elastic public network route of the elastic public network bound to the elastic public network host instance under the original virtual private cloud to the border switch through the Border Gateway Protocol (BGP); wherein, the routing priority of the elastic public network route is lower than the routing priority of the Internet network element server.
3. The flow control method based on a P4 switch according to claim 1, wherein further including: When the P4 Internet gateway is in an enabled state and the elastic public network is defaultly diverted to the P4 Internet gateway, the P4 switch publishes the elastic public network route under the virtual private cloud bound to the P4 Internet gateway to the border switch; wherein, the routing priority of the elastic public network route is lower than that of the Internet network element server.
4. The flow control method based on a P4 switch according to claim 1, wherein further including: When the P4 Internet gateway is in a disabled state, the P4 switch generates a traffic forwarding configuration.
5. The traffic control method based on a P4 switch according to claim 1, characterized in that, There are multiple P4 switches, and the obtaining the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request and sending the request traffic of the elastic public network to the P4 switch includes: Obtain the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and send the request traffic of the elastic public network to multiple P4 switches; wherein, the routing priority of the multiple P4 switches is less than a preset priority threshold; When the multiple P4 switches are abnormal, send the request traffic of the elastic public network to the Internet gateway; wherein, the Internet gateway performs a downgrade process on the elastic public network route to obtain a downgraded elastic public network route.
6. The flow control method based on a P4 switch according to claim 1, characterized in that The forwarding the rate-limited request traffic of the elastic public network to the corresponding elastic public network host instance includes: Perform network address translation on the rate-limited request traffic of the elastic public network; Change the destination IP corresponding to the converted request traffic to the fixed IP corresponding to the internal network of the elastic public network host instance; Encapsulate the changed request traffic; Send the encapsulated request traffic to the corresponding elastic public network host instance through the computing node; wherein, the computing node is communicatively connected to the elastic public network host instance and the P4 switch respectively.
7. The flow control method based on a P4 switch according to claim 6, characterized in that, The encapsulating the changed request traffic includes: Change the destination IP to the computing internal network IP of the computing node where the elastic public network host instance is located; Set the network identifier to the virtual network identifier in the virtual private cloud; Set the MAC address of the destination device in the data packet to the Mac address of the elastic public network host instance.
8. The flow control method based on a P4 switch according to claim 6, wherein The sending the response traffic to the P4 switch includes: Send the response traffic to the P4 switch through the computing node; wherein, the computing node encapsulates the response traffic.
9. The flow control method based on a P4 switch according to claim 8, wherein The rate-limiting process on the response traffic includes: Receive the encapsulated response traffic sent by the computing node; Perform network address translation on the encapsulated response traffic; Perform a rate-limiting process on the converted response traffic.
10. A traffic control system based on a P4 switch, characterized in that, Includes: A boundary switch for receiving a network application layer request sent by an Internet route, wherein the network application layer request indicates a request for the Internet route to communicate with a client, and the boundary switch obtains the request traffic of the elastic public network according to the address of the elastic public network route and the network application layer request, and sends the request traffic of the elastic public network to the P4 switch, and sends the rate-limited response traffic to the client through the Internet route, so that the client communicates with the Internet route; A virtual private cloud communicatively connected to the boundary switch, the virtual private cloud receives the network application layer request sent by the boundary switch, binds to the P4 Internet gateway according to the network application request, and generates a processing instruction if the P4 Internet gateway is in an open state and the elastic public network is communicatively connected to the P4 Internet gateway, wherein the P4 Internet gateway table corresponding to the P4 Internet gateway stores the association relationship between the virtual private cloud and the P4 Internet gateway, and the P4 Internet gateway establishes a corresponding relationship with the P4 switch; The P4 switch, which is communicatively connected to the border switch, issues the address of the elastic public network route to the border switch according to the processing instruction, performs rate limiting processing on the request traffic of the elastic public network to obtain the request traffic of the elastic public network after rate limiting processing, and forwards the request traffic of the elastic public network after rate limiting processing to the corresponding elastic public network host instance, performs rate limiting processing on the response traffic to obtain the response traffic after rate limiting, and sends the response traffic after rate limiting to the border switch; The elastic public network host instance, which is communicatively connected to the P4 switch, is used to respond to the request traffic of the elastic public network after rate limiting processing to obtain response traffic, and send the response traffic to the P4 switch.
Citation Information
Patent Citations
Cloud tenant EIP migration method and device, computer equipment and storage medium
CN117880097A
Overlay network routing using a programmable switch
US20200213154A1