Network configuration management method, device, program product and medium

By obtaining the physical link interconnection information of network devices through the data center operation and maintenance management platform, server grouping and logical network isolation are carried out, which solves the automation problem of data center network configuration management and improves the efficiency and reliability of network configuration.

CN119402345BActive Publication Date: 2025-09-16ZHENGZHOU YUNHAI INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411642231.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-09-16
Estimated Expiration
2044-11-15

AI Technical Summary

Technical Problem

现有的数据中心运维管理平台在网络配置管理上缺乏网络变更与恢复能力,导致用户操作不便,尤其在大数据量冲击场景下效率低下且易出错。

Method used

Through the data center operation and maintenance management platform, the preset hardware management protocol is used to obtain the physical link interconnection information between network devices, group servers and issue configurations to switch ports, build logical network isolation domains, and perform corresponding operations after the business is issued to achieve automated network isolation and recovery.

Benefits of technology

It can avoid the impact of network traffic shock before business is delivered. The entire process is automated, avoiding the tedious and error-prone problems caused by manual operations, and improving the efficiency and reliability of network configuration management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402345B_ABST
    Figure CN119402345B_ABST
Patent Text Reader

Abstract

The present application discloses a network configuration management method, device, program product and medium, which relate to the field of computer technology. Applied to a data center operation and maintenance management platform, the method includes: when it is monitored that the data center needs to be configured for network configuration in the current business scenario, the physical link interconnection information between the network devices in the data center is obtained through a preset hardware management protocol; before the business is issued, the servers in the network device are grouped, and based on the physical link interconnection information, the configuration is issued to the target port of the switch in the access network device to obtain the configured port; according to the group to which the server belongs and based on the configured port, the server is divided into different virtual local area networks to construct a logical network isolation domain, and after the business is issued, corresponding business operations are performed on each group based on the logical network isolation domain. Through the technical solution of the present application, network configuration changes can be realized to avoid impacts on the network traffic of the data center.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a network configuration management method, device, program product and medium. Background Art

[0002] In data center operations and maintenance, the general-purpose operations platform and the network management software (Network Management System) are typically separate systems. Because network devices, as the hub of the data center, are complex to manage, they are typically managed using dedicated network management software. This software is typically provided by mainstream network equipment vendors, integrated with their own equipment, and incorporates advanced SDN (Software Defined Network) features. Data center operations and management platforms designed for general-purpose operations have relatively limited network configuration management capabilities and are not typically used by data center operations personnel. However, some management functions within conventional data center operations and management platforms often require changes to the data center's network configuration to achieve optimal results. This often requires modifications to the entire data center network configuration. However, current data center management platform software lacks the capabilities for network modification (isolation) and recovery, causing inconvenience for users.

[0003] Therefore, how to provide a solution to the above technical problems is a problem that those skilled in the art need to solve at present. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a network configuration management method, device, program product, and medium that can realize automated network isolation configuration and recovery when there is a demand for network configuration management functions in the data center. The specific solution is as follows:

[0005] In a first aspect, the present application discloses a network configuration management method, which is applied to a data center operation and maintenance management platform, comprising:

[0006] When it is detected that network configuration of the data center is required in the current business scenario, the physical link interconnection information between the network devices in the data center is obtained through the preset hardware management protocol;

[0007] Before the service is issued, the servers in the network device are grouped, and configuration is issued to the target port of the switch connected to the network device based on the physical link interconnection information to obtain a configured port;

[0008] According to the group to which the server belongs and based on the configured ports, the server is divided into different virtual local area networks to build a logical network isolation domain, and after the service is issued, corresponding service operations are performed on each group based on the logical network isolation domain.

[0009] Optionally, obtaining physical link interconnection information between network devices in the data center through a preset hardware management protocol includes:

[0010] The servers in the data center are managed through an intelligent platform management interface protocol, and the switches in the data center are managed through a network configuration protocol to obtain physical link interconnection information between the servers and the switches.

[0011] Optionally, managing the servers in the data center through an intelligent platform management interface protocol and managing the switches in the data center through a network configuration protocol to obtain physical link interconnection information between the servers and the switches includes:

[0012] Managing the servers in the data center through an intelligent platform management interface protocol, so as to obtain, through corresponding intelligent platform management interface instructions, first physical addresses corresponding to the network cards of the plurality of servers in the data center;

[0013] Managing the switch in the data center through a network configuration protocol to obtain a second physical address corresponding to each port of the switch in the data center;

[0014] Physical link interconnection information between the server and the switch is determined based on the first physical address and the second physical address.

[0015] Optionally, determining the physical link interconnection information between the server and the switch based on the first physical address and the second physical address includes:

[0016] After the server is powered on and generates a service request corresponding to the current service scenario, the switch obtains physical link interconnection information between the server and the switch based on an association between the first physical address and the second physical address.

[0017] Optionally, the process of delivering a configuration to a target port of a switch connected to the network device based on the physical link interconnection information further includes:

[0018] Based on the physical link interconnection information, locking the switch in the network device through the network configuration protocol;

[0019] The step of sending the configuration to the target port of the switch connected to the network device is triggered, and the configuration of the switch is rolled back when the sending of the configuration fails.

[0020] Optionally, grouping the servers in the network device includes:

[0021] Acquire a grouping strategy pre-set for the server, and group the servers in the network device according to the grouping strategy; wherein the grouping strategy includes an average grouping strategy and a specified grouping strategy.

[0022] Optionally, grouping the servers in the network device according to the grouping strategy includes:

[0023] When the grouping strategy is the average grouping strategy, determining the number of groups of the servers according to the total number of servers in the data center, and evenly grouping the servers according to the number of groups;

[0024] When the grouping strategy is the specified grouping strategy, the servers connected to the switches in the data center are determined according to the physical link interconnection information, so as to classify the servers connected to the same switch into the same group.

[0025] Optionally, after performing corresponding service operations on each of the groups based on the logical network isolation domain after the service is issued, the method further includes:

[0026] After the service operation is completed, the configuration of the configured port is deleted to perform a configuration recovery operation on the switch.

[0027] Optionally, if the current business scenario is to pre-boot the server and install the execution environment, the process of grouping the servers in the network device and issuing the configuration to the target port of the switch connected to the network device based on the physical link interconnection information further includes:

[0028] Determine the current target virtual local area network and provide a corresponding pre-boot execution environment service for the target virtual local area network;

[0029] The pre-boot execution environment service is horizontally expanded based on a virtualization deployment mode or a containerized deployment mode to provide a corresponding pre-boot execution environment service for each virtual local area network.

[0030] Optionally, delivering a configuration to a target port of a switch connected to the network device based on the physical link interconnection information includes:

[0031] Based on the physical link interconnection information, a first target port connecting the server to the switch is set to an access mode, and a second target port connecting the pre-boot execution environment service to the switch is set to an aggregation mode.

[0032] Optionally, after setting the second target port connecting the pre-boot execution environment service to the switch to an aggregation mode, the method further includes:

[0033] The virtual local area network identification tag corresponding to each group is determined according to the group to which the server belongs, and the pre-boot execution environment service is associated with the virtual local area network identification tag by using a virtual switch.

[0034] Optionally, after the service is delivered, corresponding service operations are performed on each of the groups based on the logical network isolation domain, including:

[0035] After the service is issued, based on the logical network isolation domain, a dynamic host configuration protocol request broadcast operation, a file issuance operation and a system deployment operation are sequentially performed on each of the groups.

[0036] In a second aspect, the present application discloses an electronic device, comprising:

[0037] memory for storing computer programs;

[0038] A processor is used to load and execute the computer program to implement the aforementioned network configuration management method.

[0039] In a third aspect, the present application discloses a computer program product, comprising a computer program / instruction, which implements the steps of the aforementioned network configuration management method when executed by a processor.

[0040] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein the computer program implements the aforementioned network configuration management method when executed by a processor.

[0041] The present application provides a network configuration management method, which is applied to a data center operation and maintenance management platform, comprising: when it is monitored that network configuration of the data center is required in the current business scenario, obtaining physical link interconnection information between network devices in the data center through a preset hardware management protocol; before the business is issued, grouping the servers in the network devices, and issuing configurations to target ports of switches connected to the network devices based on the physical link interconnection information to obtain configured ports; dividing the servers into different virtual local area networks according to the groups to which the servers belong and based on the configured ports to construct logical network isolation domains, and performing corresponding business operations on each of the groups based on the logical network isolation domains after the business is issued.

[0042] The beneficial technical effect of the present application is: if there is a need to configure the network of the data center to avoid the impact of the impact on the network traffic of the data center, considering that the data center operation and maintenance management platform also has the ability to configure the network settings, therefore, through the data center operation and maintenance management platform, the preset hardware management protocol is used to manage the various network devices in the data center to obtain the hardware interconnection information of the network devices. Furthermore, before the service is issued, an additional logical network configuration is created based on the physical link interconnection information to build a logical network isolation domain, and the servers are divided into different virtual LANs in a grouping manner to achieve network isolation. After the service is issued, the corresponding business operations are performed on each group based on the constructed logical network isolation domain. In this way, the impact of the business operations in the current business scenario on the network traffic of the data center can be avoided or reduced. The entire process is fully automated, and the network configuration changes before the service is issued are realized. It is simple and convenient, avoiding the tedious and error-prone problems caused by manual operations.

[0043] In addition, the present application provides a network configuration management device, program product, and medium, which correspond to the above-mentioned network configuration management method and have the same effects as above. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0045] Figure 1 A flow chart of a network configuration management method disclosed in this application;

[0046] Figure 2 This is a diagram of the network isolation and recovery architecture of a data center management platform disclosed in this application;

[0047] Figure 3 This is a schematic diagram of issuing batch configuration codes based on the NETCONF protocol disclosed in this application;

[0048] Figure 4 This is a schematic diagram of the structure of a network configuration management device disclosed in this application;

[0049] Figure 5 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0051] Data center operations and maintenance management typically utilizes data center operations and maintenance management platform software designed for general operations scenarios. This software monitors the data center's various servers, storage, and network devices, while also providing operational functions such as system deployment and firmware configuration. Currently, network configuration management capabilities within data center operations and maintenance platforms are not typically used by data center operations and maintenance personnel to manage their networks. Therefore, network configuration management is necessary for scenarios where large amounts of data are impacting the data center network.

[0052] To this end, the present application provides a network configuration management solution that can achieve automated network isolation configuration and recovery when there is a functional demand for network configuration management in the data center.

[0053] The embodiment of the present invention discloses a network configuration management method, which is applied to a data center operation and maintenance management platform. The data center operation and maintenance management platform is a software system that centrally manages and monitors data center equipment, resources, and operating status. It integrates various hardware facilities in the data center and provides various functions and processes to achieve comprehensive monitoring and detailed management of data center operations. Figure 1 As shown, the method includes:

[0054] Step S11: When it is detected that network configuration of the data center is required in the current business scenario, the physical link interconnection information between the network devices in the data center is obtained through a preset hardware management protocol.

[0055] In an embodiment of the present application, if the business operations existing in the current business scenario will have an impact on the network in the data center, it is considered that the network configuration of the data center is required in the current business scenario. Taking the deployment of the operating system on the server as an example, PXE (Preboot Execution Environment) technology is usually used, but it is not ruled out that the actual business scenario can be extended to a variety of similar scenarios. PXE is a network boot technology that allows a computer to connect to a remote server through a network, obtain the image file of the operating system from the server, and load the image file at startup to install or start the operating system. In the face of large-scale installation scenarios, since the PXE process involves operations such as DHCP (Dynamic Host Configuration Protocol) and file distribution, it will inevitably have a large amount of data impact on the network in the data center.

[0056] Current solutions for this scenario typically involve manual cabling or network isolation using VLANs (Virtual Local Area Networks). This requires interoperability between the data center operations and management platform and the network management system, resulting in low efficiency and increased risk of travel. VLAN assignment often requires manual configuration or specialized network management software, a capability often lacked by data center management platforms offering PXE installation services. Consequently, current network management often relies on complex network management software or manual operations, resulting in a lack of automation and prone to errors. This also overlooks the ability of the management platform to configure network settings.

[0057] Therefore, in the embodiments of the present application, considering that the data center operation and maintenance management platform also has the ability to configure network settings, network configuration changes before service delivery and network configuration restoration after delivery are implemented through the common protocols used by various management platforms to manage devices. First, the various network devices in the data center are managed through a preset hardware management protocol, and the physical link interconnection information between each network device is obtained. The network devices include the servers and switches in the data center.

[0058] Specifically, the servers in the data center are managed through the Intelligent Platform Management Interface (IPMI) protocol, and the switches in the data center are managed through the Network Configuration Protocol (NETCONF) protocol to obtain the physical link interconnection information between the server and the switch.

[0059] As you can understand, NETCONF is widely used for the configuration and management of various network devices, such as routers and switches. It is designed to replace the traditional Simple Network Management Protocol (SNMP) and Command Line Interface (CLI). NETCONF supports SSH (Secure Shell) as a transport protocol to ensure communication security and integrity. This embodiment does not limit the type of hardware management protocol used to manage network devices. For example, switches can also be managed using SNMP. The following examples illustrate server management using the IPMI protocol and switch management using the NETCONF protocol, and will not be further elaborated.

[0060] Step S12: before the service is issued, the servers in the network device are grouped, and configuration is issued to the target port of the switch connected to the network device based on the physical link interconnection information to obtain a configured port.

[0061] Assume that the data center operation and maintenance management platform needs to perform PXE installation operations on a large number of servers (1,000 servers). The management platform will use a grouping method to divide the servers into different VLANs. For example, the servers will be divided into 10 different VLANs for network isolation.

[0062] Specifically, when grouping servers in a network device, a grouping strategy is pre-set for the servers, including an average grouping strategy and a specified grouping strategy. The servers are grouped according to the grouping strategy. Furthermore, when the grouping strategy is the average grouping strategy, the number of groups for the servers is determined based on the total number of servers in the data center, and the servers are evenly grouped according to the number of groups; when the grouping strategy is the specified grouping strategy, the servers connected to each switch in the data center are determined based on the physical link interconnection information, so that servers connected to the same switch are divided into the same group.

[0063] It is understood that the average grouping strategy is to group servers in an even manner. The specified grouping strategy is to group servers connected to the same switch into a group according to the actual scenario.

[0064] After grouping the servers, an additional logical network configuration is created based on the physical link interconnection information between network devices. This physical link interconnection information is analyzed to set additional VLAN configurations for the switches in the network devices. Specifically, the configuration is distributed to the target ports on the access switches, and the configured ports are then automatically distributed. This dynamic configuration distribution based on acquired physical link interconnection information and switch configuration information requires no human intervention. This independent configuration is applied to the switches, transparently and without impacting all other services on the network.

[0065] Step S13: Divide the server into different virtual local area networks according to the group to which the server belongs and based on the configured ports to construct a logical network isolation domain, and perform corresponding service operations on each group based on the logical network isolation domain after the service is issued.

[0066] In an embodiment of the present application, after the servers are grouped, VLANs are assigned to each group, and the switch is configured according to the configured ports to divide the servers into different virtual LANs for network isolation, thereby realizing the construction of a logical network isolation domain.

[0067] It should be noted that when assigning VLANs to each group, the VLAN values ​​can be configured in the management platform. In one specific implementation, the default VLAN uses 4094 followed by 10, i.e., 4085-4094 and the private IP segment, assuming the 192.168.1 / 24 network segment. A more precise variable-length mask can also be set based on the number of devices in the segment for network isolation.

[0068] In addition, taking PXE installation as an example, data center management platform software usually needs to provide a PXE service, that is, provide a PXE source for each VLAN so that devices in the VLAN can be started over the network and installed or updated.

[0069] Specifically, if the current business scenario is to install a pre-boot execution environment for the server, the grouping of the servers in the network device and the sending of the configuration to the target port of the switch connected to the network device based on the physical link interconnection information also include: determining the current target virtual LAN and providing a corresponding pre-boot execution environment service for the target virtual LAN; horizontally expanding the pre-boot execution environment service based on a virtualization deployment method or a containerized deployment method to provide a corresponding pre-boot execution environment service for each virtual LAN.

[0070] It should be noted that the management platform is deployed in a virtualized or containerized manner to achieve horizontal expansion of PXE source services and more refined network isolation requirements, and is suitable for grouping server isolation domains in large-scale PXE scenarios. Among them, the choice of virtualization or containerization technology mainly depends on the specific application scenario, resource requirements and management capabilities. Since a virtual machine or containerized deployment method is adopted, the PXE service of the target virtual LAN can be horizontally expanded from 1 to 10 through virtual machine cloning, template deployment or containerized batch deployment according to the grouping obtained in the previous steps. At the same time, corresponding VLANs are set on the virtual switch VSWITCH for the ports connected to these 10 PXE services. In this way, the horizontal expansion difficulties caused by physical deployment can be avoided, such as the need for additional switch port wiring and configuration.

[0071] At this point, different server groups and their corresponding PXE sources are assigned to different VLANs. Therefore, after services are delivered, corresponding service operations are performed on each group based on the logical network isolation domain. Specifically, this includes performing DHCP request broadcasts, file delivery, and system deployment operations for the current group within the isolated VLANs.

[0072] Furthermore, the exemplary PXE installation scenario described in the previous steps is for a scenario requiring network configuration within the same data center, but it can also be expanded to more complex network scenarios. For example, if the PXE service and server are located in different data centers, VXLAN (Virtual Extensible Local Area Network) technology can be used to create an isolation domain. This involves configuring the PXE service and switch ports with VXLAN. The core of this approach is to build a logical isolation domain based on physical link interconnection, requiring only the configuration of a centralized gateway or distributed network management (VETP) to establish the VXLAN tunnel. This allows for both configuration rollback and configuration rollback.

[0073] The present application provides a network configuration management method, which is applied to a data center operation and maintenance management platform, comprising: when it is monitored that network configuration of the data center is required in the current business scenario, obtaining physical link interconnection information between network devices in the data center through a preset hardware management protocol; before the business is issued, grouping the servers in the network devices, and issuing configurations to target ports of switches connected to the network devices based on the physical link interconnection information to obtain configured ports; dividing the servers into different virtual local area networks according to the groups to which the servers belong and based on the configured ports to construct logical network isolation domains, and performing corresponding business operations on each of the groups based on the logical network isolation domains after the business is issued.

[0074] The beneficial technical effect of the present application is: if there is a need to configure the network of the data center to avoid the impact of the impact on the network traffic of the data center, considering that the data center operation and maintenance management platform also has the ability to configure the network settings, therefore, through the data center operation and maintenance management platform, the preset hardware management protocol is used to manage the various network devices in the data center to obtain the hardware interconnection information of the network devices. Furthermore, before the service is issued, an additional logical network configuration is created based on the physical link interconnection information to build a logical network isolation domain, and the servers are divided into different virtual LANs in a grouping manner to achieve network isolation. After the service is issued, the corresponding business operations are performed on each group based on the constructed logical network isolation domain. In this way, the impact of the business operations in the current business scenario on the network traffic of the data center can be avoided or reduced. The entire process is fully automated, and the network configuration changes before the service is issued are realized. It is simple and convenient, avoiding the tedious and error-prone problems caused by manual operations.

[0075] Based on the above embodiment, this embodiment will specifically explain S11 in the above embodiment. In particular, the process of managing the servers in the data center through the intelligent platform management interface protocol and managing the switches in the data center through the network configuration protocol to obtain the physical link interconnection information between the servers and the switches may include the following steps:

[0076] Managing the servers in the data center through an intelligent platform management interface protocol, so as to obtain, through corresponding intelligent platform management interface instructions, first physical addresses corresponding to the network cards of the plurality of servers in the data center;

[0077] Managing the switch in the data center through a network configuration protocol to obtain a second physical address corresponding to each port of the switch in the data center;

[0078] Physical link interconnection information between the server and the switch is determined based on the first physical address and the second physical address.

[0079] In an embodiment of the present application, the data center operation and maintenance management platform manages the servers and switches of the data center through a variety of conventional hardware management protocols. In a preferred embodiment, the server is managed through the IPMI protocol. Specifically, the MAC address (physical address) information of each network card of the server is obtained using the corresponding IPMI instructions based on the IPMI protocol. It is understandable that in the embodiment of the present application, a simple management protocol is used to manage network devices. However, the MAC address information of each network card of the server can also be obtained through other means, for example, it can also be obtained through a RESTFUL interface. The use of the IPMI protocol is more suitable for the fully automatic scenario of network configuration management in this application and is feasible.

[0080] In another preferred embodiment, the data center operation and maintenance management platform can also manage the switch through protocols such as NETCONF. Specifically, the MAC address of the switch port is obtained through the NETCONF protocol. It is understood that after obtaining the MAC address of the switch port, the MAC address of the other end of the switch port can also be obtained based on the MAC address table in the switch.

[0081] Furthermore, since the data center operations and management platform already manages the switches and servers in the data center, it can obtain the MAC addresses of each server port through protocols such as IPMI, and the MAC information of each switch port through protocols such as NETCONF. This allows the platform to analyze and determine the link interconnection relationship of the entire network. When the server boots up and initiates a PXE request, the switch obtains the MAC address of the server port. At this time, the platform can obtain the interconnection diagram topology between the server and the switch through the switch, thereby determining the physical link interconnection information.

[0082] Specifically, after the server is powered on and generates a service request corresponding to the current service scenario, the switch obtains physical link interconnection information between the server and the switch based on an association between the first physical address and the second physical address.

[0083] This application is applicable to data center management software, which can implement local changes (isolation) and restoration of data center networks based on a variety of simple management protocols. Conventional data center management software can independently implement data center network configuration modification and restoration based on the service lifecycle through limited management protocols, while being completely transparent to other service networks, with no impact and simple operation.

[0084] Based on the above embodiment, in a feasible implementation, the NETCONF protocol is used to obtain the relevant information required to build a logical network isolation domain and to issue the configuration. Since the NETCONF protocol can support batch configuration issuance, transactions, and rollback, it is more suitable for overall configuration issuance based on the business. At the same time, NETCONF supports locking operations, which can lock the switch device before the configuration is issued to avoid confusion caused by concurrent modifications to the configuration during the operation. Therefore, the process of issuing the configuration to the target port of the switch connected to the network device based on the physical link interconnection information can also include the following steps:

[0085] Based on the physical link interconnection information, locking the switch in the network device through the network configuration protocol;

[0086] The step of sending the configuration to the target port of the switch connected to the network device is triggered, and the configuration of the switch is rolled back when the sending of the configuration fails.

[0087] In this embodiment of the present application, when configuring a switch using the NETCONF protocol, the switch is first locked using the NETCONF protocol. This ensures that the switch configuration is not accidentally modified or deleted during the configuration process, allowing complex configurations to be delivered in one go. Secondly, after the lock operation is completed, the switch port mode (such as access, trunk, etc.) can be configured and applied to the corresponding switch port. If an operation fails during this process, a rollback operation is supported, which rolls back the configuration of all switches. This reduces the complexity of configuration delivery and recovery operations.

[0088] It is understandable that the embodiments of this application utilize a simple management protocol to manage network devices. However, other methods can also be used to achieve final configuration delivery and recovery. For example, batch execution of CLI scripts via SSH can achieve similar results, depending on the rollback strategy when CLI batch commands fail. However, the use of the NETCONF protocol is more suitable for the fully automated network configuration management scenario in this application and is feasible.

[0089] Based on the above embodiment, this embodiment will specifically explain S12 in the above embodiment. In the embodiment of this application, it is assumed that the network architecture of the data center is a two-level switch architecture, that is, the first-level access switch (leaf switch) is responsible for the access of servers and other devices, and the second-level core switch (backbone switch, spine switch) has the network three-layer forwarding capability. Figure 2The overall solution information of the present invention is shown in FIG. The process of sending a configuration to a target port of a switch connected to the network device based on the physical link interconnection information may include the following steps:

[0090] Based on the physical link interconnection information, a first target port connecting the server to the switch is set to an access mode, and a second target port connecting the pre-boot execution environment service to the switch is set to an aggregation mode.

[0091] In the embodiments of this application, PXE installation is also used as an example. Data center management platform software typically needs to provide a PXE service. After the device is booted, it will request the PXE service through DHCP. This process involves ARP (Address Resolution Protocol) broadcasts in the Layer 2 network and OSPF (Open Shortest Path First) routing exchanges in the Layer 3 network, as well as large-scale data transmission. In large-scale PXE installation scenarios, a series of problems, including broadcast storms, will arise, impacting the network traffic of the data center.

[0092] In this embodiment of the present application, before delivering services, the management platform groups servers and then obtains associated switch port information based on the MAC addresses of the servers' service network ports. Based on the physical link interconnection information between network devices, an additional logical network configuration is created to circumvent or mitigate such impacts through network isolation. This physical link interconnection information is analyzed to set additional VLAN configurations for switches in network devices. Simultaneously, a VLAN configuration is applied to the PXE source service, placing the PXE source service and the server on separate, isolated networks. In other words, by delivering configurations to the target ports on the access switches, the configured ports are obtained, achieving fully automated configuration delivery.

[0093] For PXE source services, VLAN and VXLAN can be configured using a virtual switch; for switches, VLAN and VXLAN configuration can be implemented using the NETCONF protocol. Specifically, begin configuring the access switch port to which the server network card is connected. Since the management platform can already determine the connected switch port information based on the MAC address information of the server network card, the corresponding switch port needs to be set to access type (access mode). Since the management platform knows the interconnection topology of all switches, the ports connecting the PXE service to the switch need to be configured as trunk (aggregation mode). At this point, all ports on the link path between the server and the PXE service are configured as trunk, and then the VLAN ID tag to which the PXE service association group belongs is added.

[0094] Specifically, the virtual local area network identification tag corresponding to each group is determined according to the group to which the server belongs, and the pre-boot execution environment service is associated with the virtual local area network identification tag using a virtual switch.

[0095] exist Figure 2 The PXE service in the management platform supports horizontal expansion, uses the virtual switch VSWITCH for VLAN isolation configuration, and the platform uses IPMI and NETCONF protocols to manage servers and switches. The overall configuration delivery and recovery also includes group management, VLAN and VXLAN and port configuration, VLANIF (Virtual Local Area NetworkInterface) and ACL (Access Control List) configuration. Figure 3 The example shown in the figure illustrates how to use NETCONF to deliver batch configurations to switch ports, including creating two VLANs and VLANIF configurations on the switch. VLAN and ACL configuration on ports is similar and is not further illustrated here.

[0096] It can be seen that the configuration is dynamically delivered based on the acquired physical link interconnection information and switch configuration information. The entire process does not require human intervention. In addition, it uses additional independent configuration for the switch, which is transparent to all other services in the network and has no impact.

[0097] It should be noted that after the network configuration is changed before the service is delivered, different server groups and corresponding PXE services are divided into different VLANs. After the service is delivered, the DHCP request broadcast operation, file delivery operation, and system deployment operation of the current group are completed in the isolated VLANs. After the service operation is completed, the management platform again restores the switch VLAN configuration involved in the above steps. At this time, the network device configuration is restored, and the network configuration before and after the service is the same. The entire process is completely transparent to other external services. Specifically, after the service operation is completed, the configuration of the configured port is deleted to perform a configuration recovery operation on the switch.

[0098] Additionally, for complex network scenarios, such as when data center IP range constraints prevent the PXE service from being assigned to the same IP segment as the server, the two can be assigned to different VLANs. Layer 2 network connectivity can be achieved by configuring VXLAN on the switch. If additional ACL access policies exist on the switch, limiting network connectivity, NETCONF can be used to modify and restore the corresponding switch configuration, effectively creating an independent VLAN domain. The principle is that after the platform obtains the physical interconnection topology of the entire network, it only needs to logically create VLAN isolation. Whether Layer 3 IP addresses are interconnected and whether ports have ACL access policies can be directly obtained through standard protocols such as NETCONF. NETCONF also allows batch validation of these configuration changes, supports transactions, and supports locking operations, so only some additional configuration is required.

[0099] Accordingly, the present application also discloses a network configuration management device, see Figure 4 As shown, the device includes:

[0100] The interconnection information acquisition module 11 is used to obtain the physical link interconnection information between the network devices in the data center through a preset hardware management protocol when it is detected that the network configuration of the data center is required in the current business scenario;

[0101] The configuration issuing module 12 is used to group the servers in the network device before issuing the service, and issue the configuration to the target port of the switch connected to the network device based on the physical link interconnection information to obtain the configured port;

[0102] The isolation domain construction module 13 is used to divide the server into different virtual local area networks according to the group to which the server belongs and based on the configured port to build a logical network isolation domain, and perform corresponding business operations on each group based on the logical network isolation domain after the business is issued.

[0103] Among them, for more specific working processes of the above modules, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.

[0104] It can be seen that the above-mentioned scheme of this embodiment is applied to the data center operation and maintenance management platform, including: when it is monitored that the network configuration of the data center is required in the current business scenario, the physical link interconnection information between the network devices in the data center is obtained through the preset hardware management protocol; before the business is issued, the servers in the network device are grouped, and based on the physical link interconnection information, the configuration is issued to the target port of the switch connected to the network device to obtain the configured port; according to the group to which the server belongs and based on the configured port, the server is divided into different virtual LANs to construct a logical network isolation domain, and after the business is issued, corresponding business operations are performed on each group based on the logical network isolation domain.

[0105] The beneficial technical effect of the present application is: if there is a need to configure the network of the data center to avoid the impact of the impact on the network traffic of the data center, considering that the data center operation and maintenance management platform also has the ability to configure the network settings, therefore, through the data center operation and maintenance management platform, the preset hardware management protocol is used to manage the various network devices in the data center to obtain the hardware interconnection information of the network devices. Furthermore, before the service is issued, an additional logical network configuration is created based on the physical link interconnection information to build a logical network isolation domain, and the servers are divided into different virtual LANs in a grouping manner to achieve network isolation. After the service is issued, the corresponding business operations are performed on each group based on the constructed logical network isolation domain. In this way, the impact of the business operations in the current business scenario on the network traffic of the data center can be avoided or reduced. The entire process is fully automated, and the network configuration changes before the service is issued are realized. It is simple and convenient, avoiding the tedious and error-prone problems caused by manual operations.

[0106] In a specific implementation, the interconnection information acquisition module 11 is specifically configured to:

[0107] The servers in the data center are managed through an intelligent platform management interface protocol, and the switches in the data center are managed through a network configuration protocol to obtain physical link interconnection information between the servers and the switches.

[0108] In a specific embodiment, the interconnection information acquisition module 11 includes:

[0109] a first physical address acquisition unit, configured to manage the servers in the data center through an intelligent platform management interface protocol, and acquire, through corresponding intelligent platform management interface instructions, first physical addresses corresponding to the network cards of the plurality of servers in the data center;

[0110] A second physical address acquiring unit, configured to manage the switch in the data center through a network configuration protocol to acquire a second physical address corresponding to each port of the switch in the data center;

[0111] An interconnection information acquiring unit is configured to determine physical link interconnection information between the server and the switch based on the first physical address and the second physical address.

[0112] In a specific implementation, the interconnection information acquisition unit is specifically configured to:

[0113] After the server is powered on and generates a service request corresponding to the current service scenario, the switch obtains physical link interconnection information between the server and the switch based on an association between the first physical address and the second physical address.

[0114] In a specific embodiment, the configuration issuing module 12 further includes:

[0115] A device locking module, configured to lock a switch in the network device through the network configuration protocol based on the physical link interconnection information;

[0116] The configuration rollback module is used to trigger the step of sending the configuration to the target port of the switch connected to the network device, and to roll back the configuration of the switch when the configuration sending fails.

[0117] In a specific implementation, the configuration issuing module 12 includes:

[0118] The policy grouping module is used to obtain the grouping policy pre-set for the server and group the servers in the network device according to the grouping policy; wherein the grouping policy includes an average grouping policy and a specified grouping policy.

[0119] In a specific embodiment, the policy grouping module is specifically used to:

[0120] When the grouping strategy is the average grouping strategy, determining the number of groups of the servers according to the total number of servers in the data center, and evenly grouping the servers according to the number of groups;

[0121] When the grouping strategy is the specified grouping strategy, the servers connected to the switches in the data center are determined according to the physical link interconnection information, so as to classify the servers connected to the same switch into the same group.

[0122] In a specific embodiment, the network configuration management device further includes:

[0123] The configuration recovery module is used to delete the configuration of the configured port after the service operation is completed, so as to perform a configuration recovery operation on the switch.

[0124] In a specific implementation, if the current business scenario is to pre-start the execution environment installation for the server, the configuration issuing module 12 further includes:

[0125] A PXE service providing module is used to determine the current target virtual local area network and provide a corresponding pre-boot execution environment service for the target virtual local area network;

[0126] The horizontal expansion module is used to horizontally expand the pre-boot execution environment service based on a virtualization deployment mode or a containerized deployment mode to provide a corresponding pre-boot execution environment service for each virtual local area network.

[0127] In a specific embodiment, the configuration sending module 12 is specifically configured to:

[0128] Based on the physical link interconnection information, a first target port connecting the server to the switch is set to an access mode, and a second target port connecting the pre-boot execution environment service to the switch is set to an aggregation mode.

[0129] The tag association module is used to determine the virtual local area network identification tag corresponding to each group according to the group to which the server belongs, and associate the pre-boot execution environment service with the virtual local area network identification tag using a virtual switch.

[0130] In a specific embodiment, the isolation domain construction module 13 includes:

[0131] The service operation module is used to perform dynamic host configuration protocol request broadcast operation, file issuance operation and system deployment operation on each group in sequence based on the logical network isolation domain after the service is issued.

[0132] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 5 This is a structural diagram of an electronic device 20 according to an exemplary embodiment, and the content in the diagram cannot be considered as any limitation to the scope of use of the present application.

[0133] Figure 5This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the network configuration management method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be a server.

[0134] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0135] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, a magnetic disk, or an optical disk. The resources stored thereon may include an operating system 221, a computer program 222, and data 223. The data 223 may include various data. The storage method can be temporary storage or permanent storage.

[0136] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to implement the network configuration management method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to perform other specific tasks.

[0137] Furthermore, the embodiments of the present application also disclose a computer-readable storage medium, where the computer-readable storage medium includes a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a magnetic disk or an optical disk, or any other form of storage medium known in the technical field. When the computer program is executed by the processor, the aforementioned network configuration management method is implemented. For the specific steps of the method, reference can be made to the corresponding content disclosed in the aforementioned embodiments, and no further description will be given here.

[0138] Furthermore, an embodiment of the present application also provides a computer program product, including a computer program / instruction, which implements any one of the above-mentioned network configuration management methods when executed by a processor.

[0139] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.

[0140] The steps of the network configuration management method or algorithm described in conjunction with the embodiments disclosed herein can be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module can be stored in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0141] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0142] The above is a detailed introduction to the network configuration management method, device, program product and medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.

Claims

1. A network configuration management method, characterized in that: Applied to data center operation and maintenance management platforms, including: When it is detected that network configuration of the data center is required in the current business scenario, the physical link interconnection information between the network devices in the data center is obtained through the preset hardware management protocol; Before the service is issued, the servers in the network device are grouped, and configuration is issued to the target port of the switch connected to the network device based on the physical link interconnection information to obtain a configured port; Dividing the servers into different virtual local area networks according to the groups to which the servers belong and based on the configured ports to construct a logical network isolation domain, and performing corresponding service operations on each of the groups based on the logical network isolation domain after the service is issued; The obtaining of physical link interconnection information between network devices in the data center through a preset hardware management protocol includes: The servers in the data center are managed through an intelligent platform management interface protocol, and the switches in the data center are managed through a network configuration protocol to obtain physical link interconnection information between the servers and the switches.

2. The network configuration management method according to claim 1, wherein: Managing the servers in the data center through the intelligent platform management interface protocol and managing the switches in the data center through the network configuration protocol to obtain physical link interconnection information between the servers and the switches includes: Managing the servers in the data center through an intelligent platform management interface protocol, so as to obtain, through corresponding intelligent platform management interface instructions, first physical addresses corresponding to the network cards of the plurality of servers in the data center; Managing the switch in the data center through a network configuration protocol to obtain a second physical address corresponding to each port of the switch in the data center; Physical link interconnection information between the server and the switch is determined based on the first physical address and the second physical address.

3. The network configuration management method according to claim 2, wherein: The determining the physical link interconnection information between the server and the switch based on the first physical address and the second physical address includes: After the server is powered on and generates a service request corresponding to the current service scenario, the switch obtains physical link interconnection information between the server and the switch based on an association between the first physical address and the second physical address.

4. The network configuration management method according to claim 1, wherein: The process of issuing a configuration to a target port of a switch connected to the network device based on the physical link interconnection information further includes: Based on the physical link interconnection information, locking the switch in the network device through the network configuration protocol; The step of sending the configuration to the target port of the switch connected to the network device is triggered, and the configuration of the switch is rolled back when the sending of the configuration fails.

5. The network configuration management method according to claim 1, wherein: The grouping of the servers in the network device includes: Acquire a grouping strategy pre-set for the server, and group the servers in the network device according to the grouping strategy; wherein the grouping strategy includes an average grouping strategy and a specified grouping strategy.

6. The network configuration management method according to claim 5, characterized in that: The grouping of the servers in the network device according to the grouping strategy includes: When the grouping strategy is the average grouping strategy, determining the number of groups of the servers according to the total number of servers in the data center, and evenly grouping the servers according to the number of groups; When the grouping strategy is the specified grouping strategy, the servers connected to the switches in the data center are determined according to the physical link interconnection information, so as to classify the servers connected to the same switch into the same group.

7. The network configuration management method according to claim 1, wherein: After the service is issued, the method further includes: performing corresponding service operations on each of the groups based on the logical network isolation domain; After the service operation is completed, the configuration of the configured port is deleted to perform a configuration recovery operation on the switch.

8. The network configuration management method according to any one of claims 1 to 7, characterized in that: If the current business scenario is to install a pre-boot execution environment for the server, the process of grouping the servers in the network device and issuing a configuration to a target port of a switch connected to the network device based on the physical link interconnection information further includes: Determine the current target virtual local area network and provide a corresponding pre-boot execution environment service for the target virtual local area network; The pre-boot execution environment service is horizontally expanded based on a virtualization deployment mode or a containerized deployment mode to provide a corresponding pre-boot execution environment service for each virtual local area network.

9. The network configuration management method according to claim 8, characterized in that: Sending a configuration to a target port of a switch connected to the network device based on the physical link interconnection information includes: Based on the physical link interconnection information, a first target port connecting the server to the switch is set to an access mode, and a second target port connecting the pre-boot execution environment service to the switch is set to an aggregation mode.

10. The network configuration management method according to claim 9, characterized in that: After setting the second target port connecting the pre-boot execution environment service to the switch to an aggregation mode, the method further includes: The virtual local area network identification tag corresponding to each group is determined according to the group to which the server belongs, and the pre-boot execution environment service is associated with the virtual local area network identification tag by using a virtual switch.

11. The network configuration management method according to claim 8, characterized in that: After the service is issued, corresponding service operations are performed on each of the groups based on the logical network isolation domain, including: After the service is issued, based on the logical network isolation domain, a dynamic host configuration protocol request broadcast operation, a file issuance operation and a system deployment operation are sequentially performed on each of the groups.

12. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to load and execute the computer program to implement the network configuration management method according to any one of claims 1 to 11.

13. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the network configuration management method according to any one of claims 1 to 11 are implemented.

14. A computer-readable storage medium, characterized in that Used to store a computer program; wherein when the computer program is executed by a processor, the network configuration management method according to any one of claims 1 to 11 is implemented.

Citation Information

Patent Citations

  • Network deployment method and device

    CN110708178A

  • Methods and apparatus to deploy virtual networking in a data center

    US20190229987A1