Message forwarding method and device of server, storage medium and electronic equipment
By using open flow tables in a virtual switch to implement dual ARP transmission, the problem of cumbersome server packet forwarding methods in existing technologies is solved, the operation process is simplified and the convenience of packet forwarding is improved, making it suitable for the high availability requirements of cloud platforms.
Patent Information
- Application Number
- CN202410869729.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-30
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2044-06-30
AI Technical Summary
Existing packet forwarding methods for servers are cumbersome to implement, especially in destabilization techniques which require modifying the operating system kernel to enable dual ARP transmission, leading to deployment difficulties.
By using open flow tables in the server's virtual switch to implement dual ARP transmission, the virtual switch receives packets to be forwarded and queries flow table entries. Based on matching conditions and actions, it forwards packets through multiple physical network cards, avoiding modifications to the operating system kernel.
It simplifies the implementation process of ARP dual transmission, improves the convenience and flexibility of packet forwarding, and is suitable for the high availability requirements of cloud platforms.
Smart Images

Figure CN118677872B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the computer field, in particular, to a packet forwarding method and device of a server, a storage medium and an electronic device. BACKGROUND
[0002] In order to improve network availability, a de-stacking technology can be used to remove the stacking cable in physical form, two switches work independently, and the server uses a double uplink bond mode. The de-stacking technology commonly used in the related art is a method of converting a host route based on ARP (Address Resolution Protocol). The method of converting a host route based on ARP does not need to modify the network configuration on the server side, but needs to support ARP double sending through some way.
[0003] In the related art, the method of modifying the system kernel to enable the server to support ARP double sending is a scheme of implementing ARP double sending in the kernel mode, which depends on the ARP processing mechanism of the operating system, has a large influence range, acts on the entire system, is inconvenient to operate, and is complicated and troublesome to deploy. As can be seen, the packet forwarding method of the server in the related art has the problem of a complicated implementation process of the forwarding function. SUMMARY
[0004] Embodiments of the present application provide a packet forwarding method and device of a server, a storage medium and an electronic device to at least solve the problem of a complicated implementation process of the forwarding function of the packet forwarding method of the server in the related art.
[0005] According to an embodiment of the present application, a packet forwarding method of a server is provided, including: receiving a to-be-forwarded packet by a virtual switch of the server, wherein the to-be-forwarded packet is an ARP (Address Resolution Protocol) packet sent by a target virtual machine; in response to the received to-be-forwarded packet, querying a flow table item in an open flow table of the virtual switch that matches the to-be-forwarded packet by the virtual switch, wherein the flow table item of the open flow table includes a matching field for recording a matching condition of a packet and an action field for recording a corresponding execution action; in the case that a target flow table item that matches the to-be-forwarded packet is queried and an action target of a specified execution action recorded in the action field of the target flow table item is a plurality of member ports under an uplink aggregation port of the virtual switch, forwarding the to-be-forwarded packet to the plurality of member ports by the virtual switch, wherein the plurality of member ports are a plurality of physical network cards, and the plurality of physical network cards are connected to a plurality of switches.
[0006] According to another embodiment of the present application, a packet forwarding apparatus of a server is provided, comprising: a first receiving unit configured to receive a to-be-forwarded packet through a virtual switch of the server, wherein the to-be-forwarded packet is an address resolution protocol (ARP) packet sent by a target virtual machine; a first querying unit configured to query, in response to the received to-be-forwarded packet, a flow table item in an open flow table of the virtual switch that matches the to-be-forwarded packet, wherein the flow table item of the open flow table comprises a match field used for recording a matching condition of a packet and an action field used for recording a corresponding execution action; and a forwarding unit configured to forward, in a case where a target flow table item that matches the to-be-forwarded packet is queried and an action target of a specified execution action recorded in the action field of the target flow table item is a plurality of member ports under an uplink aggregation port of the virtual switch, the to-be-forwarded packet to the plurality of member ports through the virtual switch, wherein the plurality of member ports are a plurality of physical network cards connected to a plurality of switches.
[0007] According to still another embodiment of the present application, a computer program product is further provided, comprising computer instructions, which, when executed by a processor, implement the steps in any of the above server packet forwarding method embodiments.
[0008] According to still another embodiment of the present application, a computer readable storage medium is further provided, which stores a computer program, wherein the computer program is configured to execute the steps in any of the above server packet forwarding method embodiments when running.
[0009] According to still another embodiment of the present application, an electronic device is further provided, comprising a memory and a processor, the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any of the above server packet forwarding method embodiments.
[0010] By the present application, the ARP double sending is realized by the virtual switch flow table, the server receives the to-be-forwarded packet through the virtual switch, wherein the to-be-forwarded packet is the ARP packet sent by the target virtual machine; in response to the received to-be-forwarded packet, the virtual switch queries the flow table item matched with the to-be-forwarded packet in the open flow table of the virtual switch, wherein the flow table item of the open flow table includes the matching field for recording the matching condition of the packet and the action field for recording the corresponding execution action; in the case that the target flow table item matched with the to-be-forwarded packet is queried and the action target of the specified execution action recorded in the action field of the target flow table item is the multiple member ports under the uplink aggregation port of the virtual switch, the virtual switch forwards the to-be-forwarded packet to the multiple member ports, wherein the multiple member ports are multiple physical network cards, and the multiple physical network cards are connected on multiple switches. Since the virtual switch is a software switch running in the user state, the network switching function is realized by using the flow table based mode, and the ARP double sending is realized by using the virtual switch flow table, without modifying the operating system kernel, the implementation process of the forwarding function of the related art can be simplified, the technical effect of improving the convenience of packet forwarding is achieved, and the problem that the implementation process of the forwarding function of the related art is complicated is solved. BRIEF DESCRIPTION OF DRAWINGS
[0011] Figure 1 is a hardware structure block diagram of an optional server device according to the present embodiment;
[0012] Figure 2 is a network topology schematic diagram of an optional stacking and de-stacking according to the present embodiment;
[0013] Figure 3 is a schematic diagram of an optional ARP double sending according to the present embodiment;
[0014] Figure 4 is a flow schematic diagram of an optional packet forwarding method of a server according to the present embodiment;
[0015] Figure 5 is a schematic diagram of an optional packet forwarding method of a server according to the present embodiment;
[0016] Figure 6 is a flow schematic diagram of another optional packet forwarding method of a server according to the present embodiment;
[0017] Figure 7 is a structure block diagram of an optional packet forwarding device of a server according to the present embodiment;
[0018] Figure 8 is a structure block diagram of a computer system of an electronic device according to the present embodiment. DETAILED DESCRIPTION
[0019] Hereinafter, the embodiments of the present application will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.
[0020] It should be noted that the terms "first", "second" and the like in the description and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence.
[0021] The method embodiments provided in the embodiments of the present application can be executed in a server device or similar computing device. Taking the case of running on a server device, Figure 1 is a hardware structure block diagram of an optional server device according to the present embodiment. As shown in Figure 1 , the server device can include one or more (only one is shown in Figure 1 ) processors 102 (the processor 102 can include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the above-mentioned server device can further include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 The structure shown is only schematic, which does not limit the structure of the above-mentioned server device. For example, the server device can further include more or less components than those shown in Figure 1 , or have a different configuration from that shown in Figure 1 .
[0022] The memory 104 can be used to store computer programs, for example, software programs of application software and modules, such as the computer program corresponding to the packet forwarding method of the server in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the above-mentioned method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the server device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0023] The transmission device 106 is configured to receive or send data via a network. Examples of the network can include a wireless network provided by a communication provider of a server device. Examples of the transmission device 106 can include a NIC (Network Interface Controller) that can be connected to other network devices through a base station so as to communicate with the Internet. In an example, the transmission device 106 can be an RF (Radio Frequency) module configured to communicate with the Internet in a wireless manner.
[0024] With the increasing maturity of cloud computing technology, more and more users begin to deploy their partial applications or even all applications on the cloud platform. The cloud platform provides services through cloud computing technology, allowing users to access shared computing resources and data storage through the network without maintaining local computers or servers. This trend also promotes the development of high-availability technology of the cloud platform, especially network high availability. Network high availability is the foundation of the entire cloud platform, and network high availability ensures the uninterrupted and stable operation of customers' businesses.
[0025] A common solution for network high availability is stacking technology. Stacking is a horizontal virtualization technology that refers to physically connecting multiple switches supporting stacking features through stacking cables and then logically virtualizing them into one switch device, which participates in data forwarding as a whole to improve network reliability. However, with the increasing size of the Internet and the exponential increase in the number of switches, traditional stacking technology faces many challenges, including member switch failure risks, switch system bugs, software version upgrade problems, and the like, which can affect network availability.
[0026] To this end, network technology has developed a de-stacking solution that removes the stacking cable in physical form, and two switches work independently, while the server still uses a dual uplink bond mode to improve network reliability. The de-stacking technology commonly used in related technologies is based on ARP (Address Resolution Protocol) host routing. The ARP host routing is a method of mapping IP (Internet Protocol) addresses to MAC (Media Access Control) addresses to facilitate communication between devices in a local area network. For example, when A device needs to communicate with B device, A device will send an ARP request broadcast message requesting the MAC address of B device, and B device will send an ARP response message containing its own MAC address after receiving the request.
[0027] Here, the comparison of the stacking and de-stacking network topologies is as followsFigure 2 As shown, the de-stacking needs to configure ARP double to use. For the server, the stacking is disguised as a physical device by the way of the connection; while the de-stacking is two physical switches running independently, but needs to start LACP(Link Aggregation Control Protocol, link aggregation control protocol) configuration, and start ARP proxy, converts the learned ARP from two physical network cards into host route, generates equivalent route, to achieve the physical switch upper layer device considers that there are two equivalent routes to the server, to realize the load balancing and link stability and high availability of traffic.
[0028] The way of ARP conversion host route does not need to modify the network configuration of the server side, but needs to make the server support ARP double through some methods. Here, the double refers to sending to all member interfaces of the aggregation, such as Figure 3 As shown, and the aggregation refers to using link aggregation technology to bind multiple physical network cards to the same IP address to provide services, which can realize high availability or load balancing. In related technologies, the way of modifying Linux kernel is usually used to realize ARP double in Linux kernel state (based on a part of Linux network protocol stack), which depends on the ARP processing mechanism of the operating system, has a large influence range, and acts on the whole system. Once started, all ARP flow tables in the system protocol stack are applicable, and the switch needs to replace the kernel code to realize, which is inconvenient to operate, and the process is complicated and troublesome to deploy.
[0029] In order to at least partially solve the above technical problems, in the embodiment, ARP double is realized through OpenVswitch(OVS, virtual switch) flow table. OVS is a software switch (virtual switching software) running in user mode, and uses a flow table based way to realize network switching function, which provides network connection between virtual machine and physical server, and is a specific implementation of OpenFlow protocol (OpenFlow protocol, a network communication protocol). In OVS, ARP double is configured through flow table entry, and these flow tables can specify how to process ARP packets arriving at OVS. The flow table configuration of OVS is flexible, simple to realize, limited to the OVS switch, and can control the ARP double of the switch by adding or deleting flow table, without modifying the Linux kernel. Here, the ARP double is realized through the OVS flow table, which is not only simple to realize, but also beneficial to later operation and maintenance, and greatly improves the competitiveness of the cloud platform.
[0030] Figure 4 is a flow diagram of a message forwarding method of a server according to an embodiment of the application, as shown in Figure 4 The flow includes the following steps S402 to S406.
[0031] In step S402, a to-be-forwarded packet is received by the virtual switch of the server, wherein the to-be-forwarded packet is an address resolution protocol (ARP) packet sent by a target virtual machine.
[0032] The packet forwarding method of the server in this embodiment can be executed by the server, and the virtual switch can be run on the server. The virtual switch can be an open vSwitch (OVS), and in some examples of this embodiment, the OVS is taken as an example for description. There are many virtual machines under the virtual switch, and services are deployed on the virtual machines, which need to communicate with the outside. The virtual switch is connected to the virtual machines through virtual machine interfaces.
[0033] The target switch can send a to-be-forwarded packet to the virtual switch. The to-be-forwarded packet can be an ARP packet, such as an ARP data packet or an ARP request packet. The virtual switch can receive the to-be-forwarded packet, which can be received through a target virtual machine port.
[0034] In step S404, in response to the received to-be-forwarded packet, the virtual switch queries a flow table item in an open flow table of the virtual switch that matches the to-be-forwarded packet.
[0035] The open flow table can be configured on the virtual switch, and a flow table item of the open flow table includes a match field for recording a matching condition of a packet and an action field for recording a corresponding execution action. The open flow table can be a flow table specially set for an ARP double sending function, or can be a flow table functionally set together with other packet forwarding modes. The number of matching conditions recorded by the match fields of different flow table items can be the same or different, and the number of action information recorded by the action fields of different flow table items can be the same or different.
[0036] In response to the received to-be-forwarded packet, the virtual switch can query the open flow table to determine whether there is a flow table item that matches the to-be-forwarded packet. The above-mentioned query operation can be performed by using one or more types of information corresponding to the to-be-forwarded packet, such as a virtual machine port receiving the to-be-forwarded packet, a packet type of the to-be-forwarded packet, and the like. This embodiment does not make any limitation in this regard.
[0037] In step S406, in a case where a target flow table item that matches the to-be-forwarded packet is queried, and an action target of a specified execution action recorded by an action field of the target flow table item is a plurality of member ports under an uplink aggregation port of the virtual switch, the virtual switch forwards the to-be-forwarded packet to the plurality of member ports.
[0038] If no flow table item matching the to-be-forwarded packet is queried, the to-be-forwarded packet can be ignored or discarded, and the virtual machine can send packet forwarding exception indication information, packet retransmission indication information, etc., to indicate that the to-be-forwarded packet is forwarded abnormally, the to-be-forwarded packet is retransmitted, etc.
[0039] If the target flow table item matching the to-be-forwarded packet is queried, the to-be-forwarded packet can be forwarded according to the execution action recorded in the action field of the target flow table item. If the action target of the specified execution action recorded in the action field of the target flow table item is a plurality of member ports under the uplink aggregation port of the virtual switch, the to-be-forwarded packet can be forwarded to the plurality of member ports, where the plurality of member ports are a plurality of physical network cards, and the plurality of physical network cards are connected to a plurality of switches.
[0040] It should be noted that the plurality of switches can be a plurality of physical switches, the ARP request packet is sent by the source virtual machine, and is forwarded to the physical switch through the virtual switch. Then, the physical switch (the physical switch is a transit station) forwards the broadcast ARP request packet. After the requested destination device finds that the ARP request packet is sent to itself, the corresponding response packet is sent.
[0041] The member port is a member under the aggregation (i.e., link aggregation technology) port, refers to a physical network card, and the number of member ports contained in the plurality of member ports is at least two. If ARP double sending is implemented, the plurality of member ports are two member ports, corresponding to two physical network cards, and the two physical network cards are connected to different two physical switches. This connection mode is a cloud platform deployment mode, which can ensure high availability of the link.
[0042] The member port is for link aggregation. The uplink of the virtual switch is a physical network card, and through the link aggregation technology, a plurality of physical network cards become an aggregation port and become a logical port. The physical network card is the member port of the aggregation port.
[0043] The to-be-forwarded packet is received by a virtual switch of the server through the above steps, wherein the to-be-forwarded packet is an ARP packet sent by a target virtual machine; in response to the received to-be-forwarded packet, a flow table item matching the to-be-forwarded packet in an open flow table of the virtual switch is queried by the virtual switch, wherein the flow table item of the open flow table comprises a matching field used for recording a matching condition of the packet and an action field used for recording a corresponding execution action; in the case that the target flow table item matching the to-be-forwarded packet is queried and the action target of the specified execution action recorded in the action field of the target flow table item is a plurality of member ports under an uplink aggregation port of the virtual switch, the to-be-forwarded packet is forwarded by the virtual switch to the plurality of member ports, wherein the plurality of member ports are a plurality of physical network cards, and the plurality of physical network cards are connected to a plurality of switches, so as to solve the problem that the implementation process of the forwarding function of the packet forwarding method of the server in the related art is complicated, and improve the convenience of packet forwarding.
[0044] In some example embodiments, in response to the received to-be-forwarded packet, the virtual switch queries the flow table item matching the to-be-forwarded packet in the open flow table of the virtual switch, comprising:
[0045] S11, in response to the received to-be-forwarded packet, the virtual switch queries the flow table item matching the to-be-forwarded packet in the open flow table using the packet reference information corresponding to the to-be-forwarded packet.
[0046] In the present embodiment, in order to improve the efficiency and accuracy of packet matching, the matching condition recorded in the matching field can include at least part of the following parameters: matched packet protocol, matched virtual machine port, and matched packet type. For the to-be-forwarded packet, the virtual switch can obtain the packet reference information corresponding to the to-be-forwarded packet, the packet reference information being used to indicate the packet protocol used by the to-be-forwarded packet, the virtual machine port receiving the to-be-forwarded packet, and the packet type of the to-be-forwarded packet, and query the flow table item matching the to-be-forwarded packet in the open flow table using the obtained packet reference information.
[0047] For example, the OVS flow table is composed of matching conditions and execution actions, and the flow table matching has three conditions, which are: matching ARP protocol; matching arp_op=1, i.e. ARP request packet; matching virtual machine port, i.e. ARP packet sent from the virtual machine port; when the packet is matched, the corresponding action is executed.
[0048] An example flow table rule (corresponding to a flow table item) is as follows:
[0049] arp, in_port=vnport1; arp_op=1 actions=normal output=eth0, output=eth1
[0050] Wherein, the part before "Actions" is the matching condition, arp is the matched message protocol, in_port is the virtual network card name (i.e. the virtual machine port) of the virtual machine, vnport1 is the specific port name of the virtual machine, and arp_op = 1 means the ARP request message. The meaning of the matching condition is: matching the ARP request message sent from the vnport1 virtual machine port; the actions after the actions are the execution actions, NORMAL is to ensure the original message layer 2 forwarding under the virtual switch, and output means the action target (the object target of sending), and the action target here is the physical network card with the uplink physical network card names of ethO and eth1.
[0051] For the above flow table rule, when the matching condition is met, the ARP request message is first executed with the NORMAL action to ensure normal layer 2 communication, and then the ARP request message is executed to be synchronized to the two member ports (or member ports) of the uplink. The number of member ports is at least two, and can also be multiple.
[0052] Through the embodiment, by matching the ARP protocol, the message type, and the virtual machine port through which the virtual switch sends the message, the efficiency and accuracy of message matching can be improved.
[0053] In some example embodiments, the physical switch can be divided into VLANs (Virtual Local Area Networks), which are planned in advance during deployment, so the virtual switch also needs to mark the corresponding vlan tag on the outgoing packet, and then send the message to the port of the physical switch through the uplink of the virtual switch, i.e. the physical network card, so as to ensure normal communication. If the vlan tag is not marked, the switch side receives it and compares it with its own vlan, and finds that it is not within the allowed range, so it is discarded, resulting in abnormal communication. Therefore, the action field of the flow table entry of the open flow table can also be used to record the virtual local area network tag, so as to accurately add the virtual local area network tag when processing the message.
[0054] In the case where the target flow table entry matching the to-be-forwarded message is queried, and the action target of the specified execution action recorded in the action field of the target flow table entry is a plurality of member ports under the uplink aggregation port of the virtual switch, the operation performed on the to-be-forwarded message can also be performed according to whether the virtual local area network tag is recorded in the action field of the target flow table entry.
[0055] Correspondingly, forwarding the to-be-forwarded message to the plurality of member ports through the virtual switch comprises:
[0056] S21, when the action field of the target flow table entry does not record a virtual local area network tag, directly forwarding the to-be-forwarded packet to the plurality of member ports through the virtual switch;
[0057] S22, when the action field of the target flow table entry records a specified virtual local area network tag, adding the specified virtual local area network tag in the to-be-forwarded packet through the virtual switch to obtain an updated to-be-forwarded packet, and forwarding the updated to-be-forwarded packet to the plurality of member ports.
[0058] When the action field of the target flow table entry does not record a virtual local area network tag, at this time, the forwarding of the to-be-forwarded packet can be directly performed, and the virtual switch directly forwards the to-be-forwarded packet to the plurality of member ports. The direct forwarding manner can be: copying the to-be-forwarded packet so that the number of to-be-forwarded packets is consistent with the number of member ports, and forwarding the copied to-be-forwarded packets to each member port respectively.
[0059] When the action field of the target flow table entry records a specified virtual local area network tag, at this time, if the forwarding of the to-be-forwarded packet is directly performed, a situation of mis-discarding the packet by the physical switch may occur, thereby causing communication abnormity. In this case, the virtual switch can first add the specified virtual local area network tag in the to-be-forwarded packet to update the to-be-forwarded packet, and forward the updated to-be-forwarded packet to the plurality of member ports. The adding position of the specified virtual local area network tag can be specified as needed. The manner of forwarding the updated to-be-forwarded packet to the plurality of member ports is similar to the manner of directly forwarding the to-be-forwarded packet to the plurality of member ports, and will not be described herein.
[0060] For example, taking an OVS flow table (open flow table) as an example, the OVS flow table is composed of a matching condition and an action. When the virtual machine port does not have a vlan tag, an example of the flow table rule is as follows:
[0061] arp, in_port = vnport1; arp_op = 1 actions = NORMAL, output = ethO, output = eth 1 The meanings of the above flow table rule parts are similar to the foregoing.
[0062] When the virtual machine port has a vlan tag 100, an example of the flow table rule is as follows:
[0063] arp, in_port = vnport1; arp_op = 1
[0064] actions = NORMAL, mod_v / an_vid: 100, output = ethO, output = eth 1
[0065] For the flow table rule, for the matched ARP request message, the NORMAL action is executed first to ensure normal two-layer communication; then, for the port with VLAN, the corresponding VLAN tag is added, and for the port without VLAN, no processing is performed; finally, the ARP request message is copied and sent to the two member ports of the uplink synchronously.
[0066] Through the embodiment, by recording the virtual local area network tag in the action field of the flow table entry, the virtual local area network tag can be accurately added when processing the message, so that the accuracy and convenience of message processing can be improved.
[0067] In some example embodiments, before querying the flow table entry matched with the to-be-forwarded message in the open flow table of the virtual switch through the virtual switch, the method further includes:
[0068] S31, in the case that the virtual switch is in a source-based load balancing mode, performing LACP negotiation through the virtual switch and a plurality of switches with LACP enabled configuration to aggregate a plurality of physical network cards into an aggregated port.
[0069] In the embodiment, the OVS has a plurality of bond modes, for example, a master-backup mode, a master-master mode, etc. Aggregating a plurality of physical network cards into an aggregated port can be performed in a balance-slb (source-based load balancing) mode, which requires an external physical switch to configure LACP, and the LACP is automatically negotiated, and the successful negotiation is a prerequisite for constructing the flow table to be issued. Correspondingly, in the case that the virtual switch is in a source-based load balancing mode, the virtual switch can perform LACP negotiation with a plurality of switches with LACP enabled configuration to aggregate a plurality of physical network cards into an aggregated port. The OpenFlow flow table is issued to the virtual switch after successful negotiation with the plurality of switches.
[0070] Here, the uplink of the virtual switch is the physical network card, which is configured in the form of Bond, and needs to be configured with LACP when de-stacking. By setting the server-side Bond mode to LACP and enabling the LACP cooperation of the de-stacking external switch device (i.e., the physical switch), when the LACP negotiation is successful, the server side considers the two switches of the de-stacking as the same device, so as to ensure the load balancing of the traffic and the high availability of the network.
[0071] Binding mode is a concept in link aggregation technology, and different binding mode network cards have different working principles. In the embodiment, one of the binding modes is used, which requires an external physical switch to enable LACP configuration. After the binding mode and the external switch are configured, the LACP protocol automatically negotiates, and after the negotiation is successful, for the physical switch, the two physical network cards become an aggregation port and a logical port.
[0072] It should be noted that, in the de-stacking network architecture, in order to improve reliability, it is generally necessary to establish ECMP (Equal-Cost Multi-Path) equal-cost routing between the core and the access TOR (Top of Rack) switch. The establishment of the ECMP equal-cost routing relies on the simultaneous forwarding of ARP messages to two access switches by the uplink of the virtual switch. ARP double sending cooperates with the LACP binding mode of the OVS, copies the ARP message based on the Open Flow flow table, and sends it to each member of the uplink aggregation port, realizes ARP double sending, can flexibly adapt to the de-stacking networking mode, and improves the network reliability.
[0073] Through the embodiment, the virtual switch performs LACP negotiation with a plurality of switches with enabled LACP configuration in a source-based load balancing mode, to aggregate a plurality of physical network cards into an aggregation port, so as to improve the reliability of the physical network card aggregation.
[0074] In some example embodiments, the to-be-forwarded message is sent by a target virtual machine to the virtual switch through a target virtual machine port, and the connection relationship of the virtual machine, the virtual switch and the physical switch can be as shown in Figure 5 .
[0075] In order to perform the flow table item delivery, before the to-be-forwarded message is forwarded to the plurality of physical network cards through the virtual switch, the above method further includes:
[0076] S41, monitoring the port state of the target virtual machine port and the virtual local area network tag of the target virtual machine port through the Open Flow controller;
[0077] S42, in the case that the port state of the target virtual machine port indicates that the target virtual machine is in a startup state, and the LACP negotiation between the virtual switch and the plurality of switches is successful, querying the member ports under the uplink aggregation port of the virtual switch from the virtual switch through the Open Flow controller to obtain the port names of the plurality of member ports;
[0078] S43, based on the target virtual machine port, the virtual local area network tag of the target virtual machine port and the port names of the plurality of member ports, constructing a flow table item through the Open Flow controller to obtain a target flow table item;
[0079] S44, the target flow table item is sent to the virtual switch by the Open Flow controller, so that the target flow table item is recorded in the Open Flow table by the virtual switch.
[0080] In the embodiment, the flow table item in the Open Flow table (i.e., Open Flow table) can be constructed by the Open Flow controller and sent to the virtual switch. The Open Flow controller can construct the flow table item based on the target virtual machine port, the virtual local area network tag (vlantag, which can be null) of the target virtual machine port, and the port names of the plurality of member ports, to obtain the target flow table item. Here, the target virtual machine port is the port connected to the target virtual machine on the virtual switch, and the constructed target flow table item is similar to the foregoing embodiment.
[0081] The Open Flow table is a data structure used to store flow table items in a network device, which is used to specify how to process the data flow through the device. The flow table is a data structure used to store and manage packet forwarding rules in a network switching device, which records the processing flow of the packet on the network device.
[0082] In order to construct the flow table item, all virtual machine ports that need ARP double sending can be monitored in the cloud platform (which can be performed by the Open Flow controller), and the monitoring information can include the port state of the virtual machine port and the vlantag information of the virtual machine port. For the target virtual machine port, the Open Flow controller can monitor the port state of the target virtual machine port and the virtual local area network tag of the target virtual machine port. The port state of the target virtual machine port can be used to indicate whether the corresponding target virtual machine is in the boot state.
[0083] Here, the port state of the virtual machine port is monitored to determine whether a flow table (here, flow table item) needs to be sent for the corresponding virtual machine, and the flow table is only sent for the virtual machine in the boot state. The vlantag of the virtual machine is a part of the flow table, which is a condition to ensure that the forwarded ARP packet can reach the corresponding VLAN isolated network. Collecting these information is the basis for constructing the OVS flow table and determining whether to send.
[0084] The Open Flow controller can also query the member ports under the uplink aggregation port of the virtual switch from the virtual switch to obtain the port names of the plurality of member ports. The above query operation can be performed when the port state of the target virtual machine port indicates that the target virtual machine is in the boot state, and the LACP negotiation between the virtual switch and the plurality of switches is successful.
[0085] For example, the Open Flow controller can query the uplink bond member port of the OVS virtual switch to record the names of each member port and the binding mode and negotiation state. The query operation can be achieved by querying the members of the aggregation (bond) port and the negotiation state by command. This step is to obtain the object of ARP double sending, i.e., the action target after matching the ARP request message, to forward the ARP request message to different physical network cards to reach the external physical switch.
[0086] Based on the target virtual machine port, the virtual local area network tag of the target virtual machine port, and the port names of the plurality of member ports, the Open Flow controller can construct a flow table item to obtain a target flow table item. The flow table item (flow table rule) can be constructed using a flow table model, which has two parts: match and action, wherein the match is a matching condition, used to filter the ARP message that needs to be double sent, and the action defines that the message will be forwarded to two physical network cards after matching.
[0087] For example, when constructing the OpenFlow flow table rule, the virtual port and vlan tag information, uplink bond member name and other parameters can be transmitted into the flow table model to complete the construction of a specific flow table rule. At this point, the construction of the ARP double sending flow table has been completed.
[0088] After obtaining the target flow table item, the Open Flow controller can issue the target flow table item to the virtual switch to record the target flow table item to the Open Flow table by the virtual switch. The target flow table item can be issued according to the binding mode of the server and the LACP negotiation success described above. The target flow table item is effective when the target virtual machine is in the power-on state, and is deleted from the Open Flow table when the target virtual machine is in the power-off state.
[0089] For example, according to the uplink aggregation port binding mode, the flow table is controlled to be issued by judging the negotiation state. If the negotiation is successful, it indicates that the configuration of the server external access switch is completed, and the flow table rule can be issued, i.e., the controller distributes the flow table to each virtual machine switch for data forwarding; otherwise, it needs to wait for the negotiation to be completed or the server external switch to complete the corresponding configuration before issuing.
[0090] In addition, virtual machine port monitoring can be performed. The port of the virtual machine is monitored by an SDN (Software-Defined Networking) controller. Taking a classic SDN controller RYU as an example, the port of the virtual machine is monitored by using the powerful programmable capability of the controller. When the port of the virtual machine is Down / Up, a port event is generated and reported to the controller, and the controller processes the event. Taking the Up port of the virtual machine as an example, after the event is reported, the name of the port, the vlan tag information and the like are collected, the parameters are obtained, the next step is triggered, and a flow table rule for finally processing the traffic of the port of the virtual machine is generated. When the port of the virtual machine is Down, the controller monitors the event, and sends an instruction information for deleting the flow table rule to delete the flow table.
[0091] According to the embodiment, the open flow controller is used to obtain the virtual machine port, the virtual local area network tag of the virtual machine port and the port names of the plurality of member ports to construct the flow table, so that the convenience of flow table construction is improved, the generated flow table item is valid only when the corresponding virtual machine is in a start state, the accuracy of message forwarding is improved, and communication abnormity caused by message misforwarding is avoided.
[0092] In some example embodiments, after the virtual switch forwards the to-be-forwarded message to the plurality of member ports, the method further includes:
[0093] S51, monitoring, by the open flow controller, the port states of the plurality of member ports;
[0094] S52, generating, by the open flow controller, a flow table item to obtain a to-be-updated flow table item in a case where it is monitored that there is a member port with a changed port state in the plurality of member ports;
[0095] S53, sending, by the open flow controller, the to-be-updated flow table item to the virtual switch, so that the virtual switch updates the flow table item in the open flow table by using the to-be-updated flow table item.
[0096] The aforementioned member port refers to a physical network card. The change of the physical network card indicates that the destination of data changes, and therefore, the related flow table item needs to be updated to ensure the accuracy of data forwarding. One virtual switch has one aggregation port, and the aggregation port has a plurality of virtual machines. Once the member of the aggregation port changes, the flow table corresponding to the plurality of virtual machines needs to be updated. Therefore, in the embodiment, the open flow controller monitors the port states of the plurality of member ports, that is, whether the physical network card changes.
[0097] If it is monitored that there is a member port with a changed port state in the plurality of member ports, the openflow controller can control the flow table entries in the openflow table corresponding to the plurality of member ports (for example, the flow table entries whose action targets recorded in the action field include the member port with the changed port state). Alternatively, if it is monitored that there is a member port with a changed port state in the plurality of member ports, the openflow controller can generate the flow table entries, obtain the to-be-updated flow table entries, and send the to-be-updated flow table entries to the virtual switch, so that the virtual switch updates the flow table entries in the openflow table by using the to-be-updated flow table entries.
[0098] Alternatively, the number of to-be-updated flow table entries can be the same as the number of virtual machines in the powered-on state under the virtual switch, that is, in the case where it is monitored that there is a member port with a changed port state in the plurality of member ports, the openflow controller can generate a corresponding flow table entry for each virtual machine under the virtual switch, obtain a to-be-updated flow table entry corresponding to each virtual machine, and send the to-be-updated flow table entry corresponding to each virtual machine to the virtual switch, so that the virtual switch updates the flow table entries in the openflow table by using the to-be-updated flow table entry corresponding to each virtual machine.
[0099] Alternatively, the openflow table can be used only to record the flow table entries corresponding to the virtual machines requiring ARP double sending, that is, a separate flow table is set for ARP double sending, so as to reduce the modification of the existing flow table due to the need to be compatible with other ARP double sending messages, and meanwhile, the separate flow table can facilitate maintenance and update, for example, in the case where it is monitored that there is a member port with a changed port state in the plurality of member ports, the openflow controller can generate a corresponding flow table entry for each virtual machine under the virtual switch, obtain a new openflow table, and send the new openflow table to the virtual switch, so that the virtual switch replaces the original openflow table on the virtual switch with the new openflow table.
[0100] Through the embodiment, the openflow controller monitors the port states of the plurality of member ports, and updates the related flow table entries when it is monitored that there is a member port with a changed port state in the plurality of member ports, so that the timeliness of flow table entry updating can be improved, and the accuracy of data forwarding can be ensured.
[0101] In some example embodiments, the above method further includes:
[0102] S61, receiving, by the openflow controller, a target ARP message sent by the virtual switch, wherein the target ARP message is the first ARP message matched by the virtual switch using the target flow table entry;
[0103] S62, extracting, by the openflow controller, a source MAC address, a source IP address and a target IP address of the target ARP message;
[0104] S63, generating a periodic ARP packet according to the extracted source MAC address, source IP address and target IP address, and periodically sending the periodic ARP packet to the plurality of switches.
[0105] After the physical switch receives the ARP packet, a MAC table item is generated, which is used to record the correspondence between the port receiving the ARP packet and the source MAC address. This table item has an aging time, so it needs to be reconstructed within the aging time. In order to improve the timeliness of MAC table item update, the open flow controller can periodically send an ARP packet to the physical switch to update the above MAC table item.
[0106] For the target flow table item, the virtual switch can report the target ARP packet to the open flow controller after matching the first ARP packet (the Nth ARP packet) using the target flow table item. The open flow controller can receive the target ARP packet sent by the virtual switch. Here, in addition to the first ARP packet, the target ARP packet can also be other secondary matching successful ARP packets (i.e., matching the Nth ARP packet using the target flow table item, N is a positive integer greater than 1), and uploading after matching the first ARP packet can improve the timeliness of information synchronization.
[0107] The open flow controller can extract the source MAC address, source IP address and target IP address of the target ARP packet, and generate a periodic ARP packet according to the extracted source MAC address, source IP address and target IP address, i.e., an ARP packet sent periodically to the plurality of switches, and periodically send the periodic ARP packet to the plurality of switches. The periodic ARP packet can trigger the plurality of switches to update the specified mac table item, i.e., the mac table item on the plurality of switches used to record the correspondence between the port receiving the target ARP packet and the source MAC address, to ensure the existence of the mac table item.
[0108] For example, when the Open Flow flow table matches for the first time and implements ARP packet double sending, the source MAC, source IP and destination IP information in the ARP packet are recorded. When the server uplink network card state change is detected, the recorded packet information is used to construct a gratuitous ARP packet, synchronize the ARP and MAC table items of the external de-stacking device (external switch, i.e., external physical switch), and ensure the balance of traffic load. The purpose of synchronization is to ensure that after starting ARP proxy, an equivalent route can be generated, i.e., two equivalent reliable communication links are generated. In addition, according to the ARP aging period of the external de-stacking device, gratuitous ARP packets can be actively sent periodically to update the MAC table item of the de-stacking device in time.
[0109] Through the embodiment, after the virtual switch matches the first ARP packet using the flow table entry, the virtual switch reports the first ARP packet to the open flow server, the open flow controller generates the periodic ARP packet, and the periodic ARP packet is periodically sent to the physical switch to update the MAC table entry on the physical switch, so that the timeliness of updating the MAC table entry can be improved.
[0110] The packet forwarding method of the server in the embodiment of the application is explained and described below in combination with an optional example. The optional example provides an ARP dual sending implementation scheme based on an OpenFlow flow table, and implements the ARP dual sending function based on a cloud platform, which can be applied to a cloud computing management platform that uses an OVS (also referred to as an OVS switch or an OVS bridge) as an implementation and application. The ARP dual sending function is implemented as follows: obtaining the uplink bond configuration of a virtual switch, monitoring the virtual machine port state in real time and obtaining the port related VLAN information, constructing an Open Flow flow table for implementing the ARP dual sending function, and finally issuing the Open Flow flow table, so that the virtual switch matches the ARP packet meeting the condition based on the flow table rule, and then forwards the ARP packet to each member port under the uplink aggregation port, to realize that the server side network device sends the ARP packet to multiple aggregation member ports at the same time, that is, to realize the ARP dual sending function.
[0111] Here, specific flow table rules are set in the Open Flow controller, and the flow table rules are issued to the OVS bridge of each server in the cluster. The ARP packet under the OVS bridge is matched through the specific flow table rules, and the matched packet is copied and sent to each member port under the uplink aggregation port at the same time, so as to realize the ARP dual sending function, which is an important link in the de-stacking process on the server side.
[0112] The Open Flow controller takes the RYU controller as an example, as shown in Figure 6 The flow of the packet forwarding method of the server in the optional example includes the following steps S602 to S614.
[0113] In step S602, the RYU controller monitors the port under the OVS.
[0114] The RYU controller can monitor the state of the virtual machine and the Bond port.
[0115] In step S604, the RYU controller monitors the bond member port and the state.
[0116] The RYU controller can collect the virtual machine port parameters and the Bond member port parameters, that is, monitor the state and negotiation state of the Bond member (physical network card Bond member port) on the uplink of the server side.
[0117] Step S606, the RYU controller transmits parameters to a flow table model (a model for generating flow table rules, i.e., a flow table entry generation model) to construct an OpenFlow flow table.
[0118] The RYU controller can construct a complete ARP double-flow table rule (i.e., construct an ARP double-flow table based on OpenFlow) with the Bond member port and the monitored port name and vlan_tag.
[0119] Step S608, it is judged whether the LACP negotiation state of the Bond port is in a state of negotiation completion, if yes, step S610 is executed, otherwise, step S612 is executed.
[0120] The RYU controller judges whether the external negotiation is successful by monitoring the negotiation state of the link Bond port, and then decides whether to issue the flow table.
[0121] Step S610, the RYU controller issues the flow table to the virtual switch for matching and forwarding.
[0122] Step S612, waiting for negotiation.
[0123] Step S614, the RYU controller parses the ARP packet and periodically issues a free ARP packet.
[0124] After the OVS switch receives the flow table rule issued by the OpenFlow controller, the ARP double-flow is realized by matching the flow table rule. The specific action is: matching the ARP request packet sent by the virtual switch under the virtual port, and forwarding the packet to each member port of the uplink bond after copying. If the vlan_tag is empty, the action is to directly forward the packet to each member port when matching the flow table; if the vlan_tag is not empty, the action is to add the vlan_tag first when matching the packet, and then copy and forward to each member port.
[0125] After the flow table rule is successfully issued, the first ARP packet is matched and sent to the RYU controller on the virtual switch. The ARP packet is parsed by using the RYU package library to take out the source MAC, source IP and destination IP, and a new free ARP packet is reconstructed, which is actively sent according to the bond port state or period.
[0126] When the state change of the Bond member port is monitored, the RYU controller can re-actively send gratuitous ARP packets to update the MAC and ARP table entries of the external switch in a timely manner, for example, using the scapy library in python to construct gratuitous ARP packets and re-send them. By matching the new flow table, the MAC and ARP table entries of the external de-stacking switch are actively synchronized to ensure the effectiveness of external routing. Since the ARP table entries in the switch have an aging time, periodic synchronization of gratuitous ARP packets can also be achieved by calling scapy.
[0127] Here, by parsing the matched ARP packet, a gratuitous ARP packet is reconstructed, and by detecting the aggregation member port state or periodically sending it actively, the ARP and MAC table entries of the de-stacking switch are updated in a timely manner to ensure the stability and reliability of the external network.
[0128] Through the optional example, the ARP double sending function is realized through the OVS flow table, which can solve the problem of ARP double sending on the server side, improve the stability of the network, and has the advantages of high flexibility, strong scalability and easy implementation and deployment, and is suitable for the construction of de-stacking network.
[0129] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device) to execute the method described in the embodiments of the present application.
[0130] According to another aspect of the embodiments of the present application, a packet forwarding device of a server is also provided, which is used to implement the packet forwarding method of the server provided in the above embodiments, which has been described and will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function, and different modules can be located on the same physical device or on different physical devices. Although the devices described in the following embodiments are preferably implemented in software, hardware or a combination of software and hardware is also possible and is contemplated.
[0131] Figure 7 is a structure block diagram of an optional packet forwarding device of a server according to an embodiment of the present application, which is applied to a server or a server cluster (servers and / or controllers in the server cluster), such as Figure 7As shown, the apparatus comprises:
[0132] The first receiving unit 702 is configured to receive, by a virtual switch of a server, a to-be-forwarded packet, wherein the to-be-forwarded packet is an ARP packet sent by a target virtual machine.
[0133] The first querying unit 704 is configured to, in response to the received to-be-forwarded packet, query, by the virtual switch, a flow table item matching the to-be-forwarded packet in an open flow table of the virtual switch, wherein the flow table item of the open flow table comprises a match field for recording a match condition of a packet and an action field for recording a corresponding execution action.
[0134] The forwarding unit 706 is configured to, in a case where the target flow table item matching the to-be-forwarded packet is queried and an action target of the specified execution action recorded in the action field of the target flow table item is a plurality of member ports under an uplink aggregation port of the virtual switch, forward, by the virtual switch, the to-be-forwarded packet to the plurality of member ports, wherein the plurality of member ports are a plurality of physical network cards, and the plurality of physical network cards are connected to a plurality of switches.
[0135] It should be noted that the first receiving unit 702 in this embodiment can be configured to perform the above step S402, the first querying unit 704 in this embodiment can be configured to perform the above step S404, and the forwarding unit 706 in this embodiment can be configured to perform the above step S406.
[0136] According to the present embodiment, the to-be-forwarded packet is received by the virtual switch of the server, wherein the to-be-forwarded packet is an ARP packet sent by a target virtual machine; in response to the received to-be-forwarded packet, a flow table item matching the to-be-forwarded packet is queried in an open flow table of the virtual switch by the virtual switch, wherein the flow table item of the open flow table comprises a match field for recording a match condition of a packet and an action field for recording a corresponding execution action; in a case where the target flow table item matching the to-be-forwarded packet is queried and an action target of the specified execution action recorded in the action field of the target flow table item is a plurality of member ports under an uplink aggregation port of the virtual switch, the to-be-forwarded packet is forwarded to the plurality of member ports by the virtual switch, wherein the plurality of member ports are a plurality of physical network cards, and the plurality of physical network cards are connected to a plurality of switches, thereby solving the problem that the implementation process of the forwarding function of the packet forwarding method of the server in the related art is complicated, and improving the convenience of packet forwarding.
[0137] In some example embodiments, the forwarding unit comprises:
[0138] The first forwarding module is configured to, in a case where the action field of the target flow entry records a specified virtual local area network (VLAN) tag, add the specified VLAN tag in the to-be-forwarded packet through the virtual switch to obtain an updated to-be-forwarded packet, and forward the updated to-be-forwarded packet to the plurality of member ports.
[0139] The second forwarding module is configured to, in a case where the action field of the target flow entry records a specified VLAN tag, add the specified VLAN tag in the to-be-forwarded packet through the virtual switch to obtain an updated to-be-forwarded packet, and forward the updated to-be-forwarded packet to the plurality of member ports.
[0140] In some example embodiments, the apparatus further includes:
[0141] The negotiation unit is configured to, in a case where the virtual switch is in a source-based load balancing mode, perform LACP negotiation with the plurality of switches configured to start LACP through the virtual switch to aggregate the plurality of physical network cards into one aggregate port before querying, through the virtual switch, a flow entry in an open flow table of the virtual switch that matches the to-be-forwarded packet, wherein the open flow table is delivered to the virtual switch after successful negotiation with the plurality of switches.
[0142] In some example embodiments, the to-be-forwarded packet is sent by a target virtual machine to the virtual switch through a target virtual machine port.
[0143] Correspondingly, the apparatus further includes:
[0144] The first monitoring unit is configured to monitor, through the open flow controller, a port state of the target virtual machine port and a VLAN tag of the target virtual machine port before forwarding, through the virtual switch, the to-be-forwarded packet to the plurality of physical network cards, wherein the port state of the target virtual machine port is used to indicate whether the target virtual machine is in a startup state.
[0145] The second querying unit is configured to, in a case where the port state of the target virtual machine port indicates that the target virtual machine is in the startup state and the LACP negotiation between the virtual switch and the plurality of switches is successful, query, through the open flow controller, member ports under an uplink aggregate port of the virtual switch from the virtual switch to obtain port names of the plurality of member ports.
[0146] The construction unit is configured to construct, through the open flow controller, a flow entry based on the target virtual machine port, the VLAN tag of the target virtual machine port, and the port names of the plurality of member ports to obtain the target flow entry.
[0147] The issuing unit is configured to issue the target flow table item to the virtual switch by the open flow controller, so that the virtual switch records the target flow table item into the open flow table.
[0148] The target flow table item is valid when the target virtual machine is in the start-up state, and is deleted from the open flow table when the target virtual machine is in the shut-down state.
[0149] In some example embodiments, the apparatus further includes:
[0150] The second monitoring unit is configured to monitor port states of the plurality of member ports by the open flow controller after the virtual switch forwards the to-be-forwarded packet to the plurality of member ports.
[0151] The generating unit is configured to generate a flow table item by the open flow controller to obtain a to-be-updated flow table item when it is monitored that there is a member port with a changed port state in the plurality of member ports.
[0152] The sending unit is configured to send the to-be-updated flow table item to the virtual switch by the open flow controller, so that the virtual switch updates the flow table item in the open flow table by using the to-be-updated flow table item, wherein the updated flow table item in the open flow table includes the target flow table item.
[0153] In some example embodiments, the apparatus further includes:
[0154] The second receiving unit is configured to receive the target ARP packet sent by the virtual switch by the open flow controller, wherein the target ARP packet is the first ARP packet matched by the virtual switch by using the target flow table item.
[0155] The extracting unit is configured to extract a source MAC address, a source IP address and a target IP address of the target ARP packet by the open flow controller.
[0156] The executing unit is configured to generate a periodic ARP packet according to the extracted source MAC address, source IP address and target IP address, and periodically send the periodic ARP packet to the plurality of switches, wherein the periodic ARP packet is used to trigger the plurality of switches to update a specified mac table item, and the specified mac table item is a mac table item used to record a correspondence between a port receiving the target ARP packet and the source MAC address on the plurality of switches.
[0157] In some example embodiments, the first querying unit includes:
[0158] The query module is configured to, in response to the received to-be-forwarded packet, query, by the virtual switch, a flow table item matching the to-be-forwarded packet in an open flow table by using packet reference information corresponding to the to-be-forwarded packet, wherein the packet reference information is used to indicate a packet protocol used by the to-be-forwarded packet, a virtual machine port receiving the to-be-forwarded packet, and a packet type of the to-be-forwarded packet.
[0159] It should be noted that the above modules can be implemented by software or hardware, and the hardware can be implemented in the following manner, but is not limited thereto: the modules are located in the same processor; or the modules are located in different processors in any combination.
[0160] According to another aspect of the embodiments of the present application, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is configured to execute the steps in any of the method embodiments when running.
[0161] In some example embodiments, the computer readable storage medium can include, but is not limited to, a U disk, a ROM (Read-Only Memory), a RAM (Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0162] According to another aspect of the embodiments of the present application, an electronic device is provided, which includes a memory storing a computer program and a processor configured to execute the computer program to perform the steps in any of the method embodiments.
[0163] In some example embodiments, the electronic device can further include a transmission device connected to the processor and an input / output device connected to the processor.
[0164] The specific examples in the present embodiment can refer to the examples described in the above embodiments and example embodiments, and the present embodiment will not be described herein again.
[0165] According to another aspect of the embodiments of the present application, a computer program product is provided, which includes a computer program / instruction containing program codes for executing the method shown in the flow chart. The computer program product in the present embodiment can be applied to, for example, Figure 8The illustrated electronic device is a computing system. In such an embodiment, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by central processing unit 801, it performs various functions provided in the embodiments of this application. The above-mentioned embodiment numbers are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0166] like Figure 8 As shown, the computer system 800 includes a central processing unit 801, which can perform various appropriate actions and processes based on programs stored in read-only memory 802 or programs loaded from storage section 808 into random access memory 803. The random access memory 803 also stores various programs and data required for system operation. The central processing unit 801, read-only memory 802, and random access memory 803 are interconnected via bus 804. Input / output interface 805 is also connected to bus 804.
[0167] The following components are connected to the input / output interface 805: an input section 806 including a keyboard, mouse, etc.; an output section 807 including a CRT (Cathode Ray Tube), LCD (Liquid Crystal Display), etc., and speakers, etc.; a storage section 808 including a hard disk, etc.; and a communication section 809 including a network interface card such as a LAN card, modem, etc. The communication section 809 performs communication processing via a network such as the Internet. A drive 810 is also connected to the input / output interface 805 as needed. A removable medium 811, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 810 as needed so that computer programs read from it can be installed into the storage section 808 as needed.
[0168] Specifically, according to embodiments of this application, the processes described in the various method flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 809, and / or installed from removable medium 811. When the computer program is executed by central processing unit 801, it performs various functions defined in the system of this application.
[0169] It should be noted that, Figure 8 The computer system 800 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0170] It should be apparent to those skilled in the art that the modules or steps of the application described above can be implemented with general computing devices, which can be centralized on a single computing device or distributed on a network of multiple computing devices, which can be implemented with program codes executable by the computing devices, so that they can be stored in storage devices and executed by the computing devices, and in some cases, the steps shown or described can be executed in different orders than shown, or made into individual integrated circuit modules, or made into a single integrated circuit module. Thus, the present application is not limited to any particular combination of hardware and software.
[0171] The preferred embodiments of the present application described above are only used to explain the principles of the present application and not limit the present application. Any modification, equivalent replacement, improvement, etc. within the principles of the present application should be included in the protection scope of the present application.
Claims
1. A message forwarding method for a server, characterized in that, include: The server receives packets to be forwarded via its virtual switch, wherein the packets to be forwarded are Address Resolution Protocol (ARP) packets sent by the target virtual machine. In response to the received packet to be forwarded, the virtual switch queries the open flow table of the virtual switch for a flow table entry that matches the packet to be forwarded. The flow table entry of the open flow table includes a matching field for recording the matching conditions of the packet and an action field for recording the corresponding execution action. If a target flow table entry matching the packet to be forwarded is found, and the action field of the target flow table entry records that the target of the specified action is multiple member ports under the uplink aggregation port of the virtual switch, the packet to be forwarded is forwarded to the multiple member ports through the virtual switch. The multiple member ports are multiple physical network cards, and the multiple physical network cards are connected to multiple switches. Specifically, the step of forwarding the packet to be forwarded to the multiple member ports via the virtual switch when a target flow table entry matching the packet to be forwarded is found, and the action field of the target flow table entry records that the target of the specified action is multiple member ports under the uplink aggregation port of the virtual switch, includes: when a target flow table entry matching the packet to be forwarded is found, and the action field of the target flow table entry records that the target of the specified action is multiple member ports under the uplink aggregation port of the virtual switch, if the action field of the target flow table entry does not record a virtual LAN tag, the packet to be forwarded is directly forwarded to the multiple member ports via the virtual switch; if the action field of the target flow table entry records a specified virtual LAN tag, the specified virtual LAN tag is added to the packet to be forwarded via the virtual switch to obtain an updated packet to be forwarded, and the updated packet to be forwarded is forwarded to the multiple member ports.
2. The method according to claim 1, characterized in that, Before querying the open flow table of the virtual switch to find a flow table entry that matches the packet to be forwarded, the method further includes: When the virtual switch is in source-based load balancing mode, it negotiates with the multiple switches configured with Link Aggregation Control Protocol (LACP) to aggregate the multiple physical network cards into a single aggregation port. The open flow table is sent to the virtual switch after successful negotiation with the multiple switches.
3. The method according to claim 2, characterized in that, The message to be forwarded is sent by the target virtual machine to the virtual switch through the target virtual machine port; Before forwarding the packet to be forwarded to the plurality of physical network interface cards via the virtual switch, the method further includes: The port status and virtual LAN tag of the target virtual machine port are monitored by the open flow controller, wherein the port status of the target virtual machine port is used to indicate whether the target virtual machine is powered on. If the port status of the target virtual machine port indicates that the target virtual machine is powered on, and the virtual switch successfully negotiates LACP with the multiple switches, the Open Flow Controller queries the member ports under the uplink aggregation port of the virtual switch to obtain the port names of the multiple member ports. Based on the target virtual machine port, the virtual LAN tag of the target virtual machine port, and the port names of the multiple member ports, a flow table entry is constructed through the open flow controller to obtain the target flow table entry; The target flow table entry is sent to the virtual switch through the Open Flow Controller, so that the virtual switch can record the target flow table entry into the Open Flow Table; The target flow table entry is valid when the target virtual machine is powered on, and is deleted from the open flow table when the target virtual machine is powered off.
4. The method according to claim 1, characterized in that, After forwarding the packet to be forwarded to the plurality of member ports through the virtual switch, the method further includes: The port status of the multiple member ports is monitored through the open flow controller; If a member port whose port status has changed is detected among the multiple member ports, a flow table entry is generated through the open flow controller to obtain the flow table entry to be updated; The Open Flow Controller sends the flow table entry to be updated to the virtual switch, so that the virtual switch can use the flow table entry to update the flow table entry in the Open Flow Controller, wherein the flow table entry to be updated in the Open Flow Controller includes the target flow table entry.
5. The method according to claim 1, characterized in that, The method further includes: The virtual switch receives the target ARP packet sent by the open flow controller, wherein the target ARP packet is the first ARP packet matched by the virtual switch using the target flow table entry; The source Media Access Control (MAC) address, source Internet Protocol (IP) address, and destination IP address of the target ARP packet are extracted using the Open Flow Controller. Periodic ARP packets are generated based on the extracted source MAC address, source IP address, and target IP address, and are periodically sent to the multiple switches. The periodic ARP packets are used to trigger the multiple switches to update a specified MAC entry, which is a MAC entry on the multiple switches used to record the correspondence between the port receiving the target ARP packet and the source MAC address.
6. The method according to any one of claims 1 to 5, characterized in that, In response to the received packet to be forwarded, the virtual switch queries the open flow table of the virtual switch for a flow table entry that matches the packet to be forwarded, including: In response to the received packet to be forwarded, the virtual switch uses the packet reference information corresponding to the forwarded packet to query the flow table entry in the open flow table that matches the packet to be forwarded. The packet reference information is used to indicate the packet protocol used by the packet to be forwarded, the virtual machine port receiving the packet to be forwarded, and the packet type of the packet to be forwarded.
7. A message forwarding device for a server, characterized in that, include: The first receiving unit is configured to receive a message to be forwarded through the virtual switch of the server, wherein the message to be forwarded is an Address Resolution Protocol (ARP) message sent by the target virtual machine; The first query unit is used to respond to the received packet to be forwarded by querying the open flow table of the virtual switch for a flow table entry that matches the packet to be forwarded. The flow table entry of the open flow table includes a matching field for recording the matching conditions of the packet and an action field for recording the corresponding execution action. The forwarding unit is used to forward the packet to be forwarded to multiple member ports through the virtual switch when a target flow table entry matching the packet to be forwarded is found, and the action field of the target flow table entry records that the action target of the specified action is multiple member ports under the uplink aggregation port of the virtual switch. The multiple member ports are multiple physical network cards, and the multiple physical network cards are connected to multiple switches. The forwarding unit includes: a first forwarding module, configured to, when a target flow table entry matching the packet to be forwarded is found, and the action target of the specified action recorded in the action field of the target flow table entry is multiple member ports under the uplink aggregation port of the virtual switch, and when the action field of the target flow table entry does not record a virtual LAN tag, directly forward the packet to be forwarded to the multiple member ports through the virtual switch; and a second forwarding module, configured to, when the action field of the target flow table entry records a specified virtual LAN tag, add the specified virtual LAN tag to the packet to be forwarded through the virtual switch to obtain an updated packet to be forwarded, and forward the updated packet to the multiple member ports.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method according to any one of claims 1 to 6.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Service message transmission method and equipment
CN104780088A
Flow table processing method and related equipment
CN114531405A