Data packet transmission method and related equipment for cloud computing platform accessing third-party network elements
By encapsulating information indicating access to third-party network elements in the access gateway of the cloud computing platform and adaptively adjusting the PMTU, the problem of possible sharding of data packets during transmission is solved, and transmission efficiency and user experience are improved.
Patent Information
- Application Number
- CN202510181046.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-02-18
AI Technical Summary
On the cloud computing platform, the original data packets sent by the user's application client need to be processed through third-party network elements, resulting in tunnel encapsulation resulting in the packet size exceeding the PMTU on the path, thus requiring sharding, increasing network latency and affecting the network connectivity and user experience of the application service.
The original data packet is received through the access gateway and encapsulated on the data packet that instructs the access gateway to access third-party network elements, determine the PMTU required for this transmission, and write it into the data packet to ensure that the data packet does not need to be sharded during the transmission process.
This greatly reduces the probability of data packets being sharded, improves the transmission efficiency of data packets, ensures the network connectivity and user experience of application services, and avoids the emergence of non-standard MTUs on cloud computing platforms.
Smart Images

Figure CN119675992B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud computing technology, and in particular to a data packet transmission method and related equipment for a cloud computing platform accessed to a third-party network element. Background Art
[0002] With the development of cloud computing technology, more and more third-party service providers have connected the third-party network elements they provide to the cloud computing platform. For example, third-party network elements include but are not limited to: firewalls, intrusion detection systems or traffic mirroring services, etc. For users who use application services on the cloud computing platform, the user can choose a third-party network element to enhance the function or security of the application service they use. In this way, when the user's application client requests to access the application server, the original data packet sent by the user's application client needs to be processed by the third-party network element first, and then sent to the application server for response.
[0003] In actual applications, due to the natural isolation between the user network and the third-party network element, the original data packets sent by the user's application client are usually sent to the third-party network element for processing through the access gateway. The access gateway usually tunnel encapsulates the original data packet through tunnel encapsulation, and then sends the tunnel encapsulated data packet to the third-party network element for processing. However, tunnel encapsulation is likely to cause the data packet size to exceed the PMTU (Path Maximum Transmission Unit) on the path between the access gateway and the third-party network element, so the data packet needs to be fragmented. Fragmenting the data packet not only increases network latency, but may also cause the entire data packet to be retransmitted due to the loss or damage of any fragment, thereby affecting the network connectivity and user experience of the application service. Summary of the invention
[0004] Multiple aspects of the present application provide a data packet transmission method and related equipment for a cloud computing platform accessed to a third-party network element, so as to greatly reduce the probability of data packets being fragmented and ensure network connectivity and user experience of application services.
[0005] The embodiment of the present application provides a data packet transmission method for a cloud computing platform accessing a third-party network element, which is applied to a first computing node among multiple computing nodes included in the cloud computing platform, the first computing node including a first virtual switch and a first virtual machine that communicate with each other, and the first virtual machine has deployed an access gateway; the method comprises: receiving an original data packet forwarded by the first virtual switch through the access gateway, and encapsulating first encapsulation information indicating that the access gateway accesses the third-party network element on the original data packet to obtain a first data packet; wherein the original data packet is sent by an application client in a second virtual machine running on a second computing node, and the third-party network element is deployed on a third computing node running a third virtual machine; determining the PMTU required for this transmission based on the data packet size information of the first data packet through the access gateway, and writing the PMTU required for this transmission into the first packet; Encapsulate information to obtain a second data packet, and send the second data packet to the first virtual switch; obtain the PMTU required for this transmission from the second data packet through the first virtual switch, and determine the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, and update the current PMTU recorded in the first flow table item to the PMTU required for this transmission, and send the second data packet to the third virtual machine according to the updated first flow table item, and send the third data packet returned by the third virtual machine to the access gateway; decapsulate the third data packet through the access gateway to obtain a target data packet, which is obtained by the third-party network element processing the original data packet in the second data packet; and forward the target data packet to the application server in the fourth virtual machine running on the fourth computing node through the first virtual switch for response processing.
[0006] The embodiment of the present application also provides a data packet transmission method for a cloud computing platform that accesses a third-party network element, which is applied to a third computing node among multiple computing nodes included in the cloud computing platform, the third computing node includes a third virtual switch and a third virtual machine that communicate with each other, and the third virtual machine has deployed a third-party network element; the method includes: receiving a second data packet sent by the first virtual switch through the third virtual switch, obtaining the PMTU required for this transmission from the second data packet, and determining a second flow table item associated with the third-party network element accessing the access gateway in the flow table corresponding to the third virtual switch, and updating the current PMTU recorded in the second flow table item to the PMTU required for this transmission; wherein the first virtual switch and the access gateway are deployed on the first computing node, and the second data packet is sent by the access gateway to the first virtual switch; forwarding the second data packet to the third virtual machine through the third virtual switch, so that the third-party network element in the third virtual machine processes the second data packet to obtain a third data packet; sending the third data packet to the first virtual switch according to the updated second flow table item through the third virtual switch, so that the first virtual switch forwards the third data packet to the access gateway.
[0007] The embodiment of the present application also provides a cloud computing platform, including: a first computing node, a second computing node, a third computing node and a fourth computing node; the first computing node includes a first virtual switch and a first virtual machine that communicate with each other, and the first virtual machine has deployed an access gateway; the second computing node includes a second virtual machine that has deployed an application client; the third computing node includes a third virtual switch and a third virtual machine that communicate with each other, and the third virtual machine has deployed access to a third-party network element; the fourth computing node includes a fourth virtual machine that has deployed an application server; the second computing node is used to forward the original data packet sent by the application client in the second virtual machine to the first computing node; the first computing node is used to execute the steps in the data packet transmission method of the cloud computing platform that accesses the third-party network element; the third computing node is used to execute the steps in the data packet transmission method of the cloud computing platform that accesses the third-party network element; the fourth computing node is used to respond to and process the target data packet sent by the first computing node through the application server in the fourth virtual machine, and the target data packet is the original data packet processed by the third-party network element.
[0008] An embodiment of the present application also provides a data packet transmission method, including: receiving an original data packet forwarded by a first virtual switch through an access gateway; and encapsulating first encapsulation information indicating that the access gateway accesses a target network element on the original data packet to obtain a first data packet; determining the PMTU required for this transmission based on the data packet size information of the first data packet through the access gateway, and writing the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain a second data packet, and sending the second data packet to the first virtual switch; obtaining the PMTU required for this transmission from the second data packet through the first virtual switch, and determining a first flow table entry associated with the access gateway accessing the target network element in the flow table corresponding to the first virtual switch, and updating the current PMTU recorded in the first flow table entry to the PMTU required for this transmission, and sending the second data packet to the target network element according to the updated first flow table entry.
[0009] An embodiment of the present application also provides an electronic device, including: a memory and a processor; the memory is used to store a computer program; the processor is coupled to the memory, and is used to execute the computer program to execute the steps in the data packet transmission method of the cloud computing platform accessing a third-party network element.
[0010] An embodiment of the present application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor is enabled to implement the steps in the data packet transmission method of a cloud computing platform connected to a third-party network element.
[0011] An embodiment of the present application also provides a computer program product, including a computer program or instructions. When the computer program or instructions are executed by a processor, the processor is enabled to implement the steps in the data packet transmission method of a cloud computing platform connected to a third-party network element.
[0012] In an embodiment of the present application, after receiving the original data packet sent by the application client forwarded by the virtual switch, the access gateway encapsulates the original data packet with encapsulation information indicating that the access gateway accesses the third-party network element to obtain a first data packet, and adaptively determines the PMTU required for the current transmission of the path between the access gateway and the third-party network element according to the data packet size of the first data packet, and writes the PMTU required for this transmission into the first data packet to obtain a second data packet. The access gateway forwards the second data packet to the virtual switch, and the virtual switch updates the current PMTU in the flow table item associated with the access gateway accessing the third-party network element to the PMTU required for this transmission, and sends the second data packet that does not need to be fragmented to the third-party network element according to the updated flow table item. The third-party network element processes the original data packet in the second data packet to obtain the target data packet, and the target data packet is returned by the access gateway through the virtual switch to the application server for response processing. Therefore, in the case where the application service uses the third-party network element, the access gateway can adaptively adjust the PMTU required for this transmission according to the data packet size information of the first data packet, greatly reducing the probability of the data packet sent by the access gateway to the third-party network element being fragmented, improving the transmission efficiency of the data packet, and ensuring the network connectivity of the application service. In addition, adaptive PMTU is only provided for data packet transmission between the access gateway and the third-party network element. This will not cause non-standard MTU on the cloud computing platform, and will open PMTU restrictions on network traffic of application clients accessing third-party network elements through the access gateway, thereby improving the user experience of the cloud computing platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0014] Figure 1 A schematic diagram of the structure of a cloud computing platform provided for the present application example;
[0015] Figure 2 A flowchart of a method for transmitting data packets of a cloud computing platform connected to a third-party network element provided in an embodiment of the present application;
[0016] Figure 3 A flowchart of another method for transmitting data packets of a cloud computing platform accessing a third-party network element provided in an embodiment of the present application;
[0017] Figure 4 A flowchart of a data packet transmission method provided in an embodiment of the present application;
[0018] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.
[0020] In the embodiments of the present application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the access relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B may be singular or plural. In the text description of the present application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. In addition, in the embodiments of the present application, "first", "second", "third", etc. are only used to distinguish the contents of different objects and have no other special meanings.
[0021] It should be noted that, in the case of user information involved in the embodiments of this application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation portals for users to choose to authorize or refuse. In addition, the various models involved in this application (including but not limited to language models or large language models) are in compliance with relevant laws and standards.
[0022] The following are some words related to the embodiments of the present application:
[0023] Maximum Transmission Unit (MTU): refers to the maximum size of a data packet that a network can transmit, in bytes. The size of the MTU determines the maximum number of bytes that the sender can send in a data packet at one time. If a data packet exceeds the MTU of any network segment in the path, it will be fragmented, that is, divided into smaller data packets for transmission.
[0024] PMTU (Path Maximum Transmission Unit): refers to the maximum size of a data packet that can be transmitted from a source IP address to a destination IP address through a network. For a transmission path, PMTU is determined by the minimum value of the MTU of each network element on the path, such as a virtual machine. Each network element has its own MTU, which defines the size of the data packet that the network element can handle. By indirectly changing the PMTU value through MTU, it is possible to effectively avoid data packet fragmentation and reassembly, thereby improving the utilization of network bandwidth.
[0025] Virtual Machine (VM): A software environment created through virtualization technology that simulates a real physical computer. It provides an independent and isolated execution environment for applications. It allows multiple operating system instances to run on the same physical server (also called a physical machine) while ensuring resource isolation and security between each virtual machine.
[0026] Virtual Switch (vSwitch): It is a software component running on the host machine, responsible for managing and forwarding network traffic between virtual machines. It is a bridge between virtual machines and the physical network, ensuring that virtual machines can access external networks like physical machines and can communicate with other virtual machines. The main functions of virtual switches include traffic forwarding, virtual network card management, network isolation and security, performance optimization, and monitoring and management.
[0027] Access Gateway is a gateway service designed specifically for managing service traffic in a cloud-native environment. It can provide various functions such as load balancing, routing management, authentication, security protection, monitoring and logging.
[0028] Cloud computing platform refers to the infrastructure, platform services or software application platform that provides cloud computing services. It allows users to access and use computing resources (such as servers, storage, databases, networks, etc.), platform services (such as operating systems, development tools, database management, etc.) and software applications through the Internet without owning or maintaining physical hardware.
[0029] Flow table: A collection of policy entries for a specific flow, responsible for searching and forwarding data packets. A flow table contains a series of flow entries. Flow entries in a flow table usually include: match fields, counters, actions, etc. The match fields cover most of the identifiers of the link layer, network layer, and transport layer; the counters are used to count traffic-related information, and can be maintained for each flow table, each data flow, each device port, and each forwarding queue in the switch; the action information is used to indicate the next step that should be performed for the data packet that matches the flow entry.
[0030] The following specific embodiments are used to describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following is a detailed description of the technical solutions provided by each embodiment of the present application in conjunction with the accompanying drawings.
[0031] In actual applications, a cloud computing platform may include multiple computing nodes, including but not limited to physical machines (also known as physical servers), serverless computing, edge nodes, etc., but not limited to these. A computing node may run one or more virtual machines, which communicate over the network through a virtual switch. In actual applications, a cloud computing platform may provide a variety of application services for users to use, including but not limited to elastic computing services, object storage services, database services, etc. In addition, users may also migrate their own application services to the cloud computing platform. Therefore, users may use application services provided by the cloud computing platform or application services migrated to the cloud computing platform. For users who use the application services of the cloud computing platform, users access the application server through an application client. An application client refers to a client that interacts with an application service, and an application server refers to a server that executes the technical logic of an application service. A user initiates a request through an application client, and the request is transmitted to the application server through the network. The application server responds to the request, executes the corresponding technical logic, and returns the execution result to the application server. In actual applications, a cloud computing platform may also access third-party network elements provided by various third-party service providers, and a third-party service provider refers to a service provider independent of the service provider of the cloud computing platform. A third-party network element (also referred to as a third-party service) can be understood as an application service provided by a third-party service provider. For example, third-party network elements include but are not limited to: a firewall, an intrusion detection system, or a traffic mirroring service.
[0032] For users who use application services on the cloud computing platform, the user can select a third-party network element to enhance the function or security of the application service they use. In this way, when the user's application client requests to access the application server, the original data packet sent by the user's application client needs to be processed by the third-party network element first, and then sent to the application server for response. In actual applications, due to the natural isolation between the user network and the third-party network element, the original data packet sent by the user's application client is usually sent to the third-party network element for processing through the access gateway. The access gateway usually tunnel encapsulates the original data packet by tunnel encapsulation, and then sends the tunnel encapsulated data packet to the third-party network element for processing. However, tunnel encapsulation is likely to cause the data packet size to exceed the PMTU on the path between the access gateway and the third-party network element, so the data packet needs to be fragmented. The fragmentation of the data packet not only increases the network delay, but also may cause the retransmission of the entire data packet due to the loss or damage of any fragment, thereby affecting the network connectivity and user experience of the application service.
[0033] Specifically, the PMTU on the path between the access gateway and the third-party network element is usually determined by the MTU corresponding to the access gateway and the MTU corresponding to the third-party network element. Generally speaking, the smaller MTU between the MTU corresponding to the access gateway and the MTU corresponding to the third-party network element is used as the PMTU on the path between the access gateway and the third-party network element. Generally speaking, in order to facilitate management, the cloud computing platform allows the MTU corresponding to each network element to be uniformly set to a fixed value. For example, the MTU corresponding to each network element is set to 1500 bytes. Each network element can be a third-party network element or a network element provided by the cloud computing platform. The network elements provided by the cloud computing platform include, but are not limited to: application clients, application servers, access gateways, etc. In other words, the cloud computing platform usually does not allow users to adjust the MTU corresponding to the network element to avoid too many non-standard MTUs, which causes confusion in MTU management. Among them, the non-standard MTU can be understood as the MTU other than the fixed value of the MTU uniformly set by the cloud computing platform.
[0034] For ease of understanding and distinction, the data packet sent by the application client is called the original data packet. After the access gateway receives the original data packet sent by the application client, the access gateway usually needs to perform VXLAN (Virtual eXtensible Local Area Network) tunnel encapsulation on the original data packet. The VXLAN information in the encapsulated data packet usually includes the IP address of the access gateway and the IP address of the third-party network element. In this way, the encapsulated data packet can be transmitted from the access gateway to the third-party network element based on the VXLAN information in the encapsulated data packet. For example, the data packet size of the original data packet is 1500 bytes, and the VXLAN information occupies 200 bytes. In this way, the data packet size of the encapsulated data packet is 1700 bytes. If the MTU corresponding to the access gateway and the third-party network element are both set to 1500 bytes, the PMTU on the path between the access gateway and the third-party network element is 1500 bytes. Since the data packet size of the encapsulated data packet (1700 bytes) is larger than the PMTU (1500 bytes), the encapsulated data packet sent by the access gateway needs to be fragmented to obtain smaller data packets, and the smaller data packets are transmitted to the third-party network element. The third-party network element needs to reassemble the received fragmented data packets to obtain the data packets of the encapsulated data packets, and process the data packets of the encapsulated data packets to obtain the processed data packets. In the case where the size of the processed data packets is greater than 1500 bytes, the processed data packets sent by the third-party network element also need to be fragmented to obtain smaller data packets for transmission to the access gateway. The access gateway also needs to reassemble the data packets to obtain the data packets processed by the third-party network element, and send the data packets processed by the third-party network element to the application server for response. At this point, the entire process of the original data packets sent by the application client being processed by the third-party network element and then sent to the application server for response is completed.
[0035] Figure 1 This is a schematic diagram of the structure of a cloud computing platform provided in this application example. For ease of understanding, Figure 1 Only four computing nodes are shown in the figure, and each computing node includes a virtual machine and a virtual switch that communicate with each other. However, in actual applications, there is no limit on the number of computing nodes, data of virtual machines, and the number of virtual switches. Figure 1The cloud computing platform may include: a first computing node, a second computing node, a third computing node, and a fourth computing node. The first computing node includes a first virtual switch and a first virtual machine that communicate with each other, and the first virtual machine has deployed an access gateway; the second computing node includes a second virtual machine that has deployed an application client; the third computing node includes a third virtual switch and a third virtual machine that communicate with each other, and the third virtual machine has deployed an access to a third-party network element; the fourth computing node includes a fourth virtual machine that has deployed an application server.
[0036] In this embodiment, the second computing node is used to forward the original data packet sent by the application client in the second virtual machine to the first computing node. In actual applications, the application client in the second virtual machine can be forwarded to the first computing node through the second virtual switch. Figure 1 As shown in ①, after the second virtual switch receives the original data packet sent by the application client, the second virtual switch can perform tunnel encapsulation on the original data packet, and the encapsulated original data packet carries VXLAN information. The VXLAN information may include the IP address of the second computing node (as source address information) and the IP address of the first computing node (as destination address information). The second virtual switch sends the encapsulated original data packet to the first computing node according to the VXLAN information.
[0037] In this embodiment, the first computing node is used to receive the original data packet forwarded by the first virtual switch through the access gateway, and encapsulate the first encapsulation information instructing the access gateway to access the third-party network element on the original data packet to obtain the first data packet; wherein the original data packet is sent by the application client in the second virtual machine running on the second computing node, and the third-party network element is deployed on the third computing node running the third virtual machine; the access gateway determines the PMTU required for this transmission based on the data packet size information of the first data packet, and writes the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain the second data packet, and sends the second data packet to the first virtual switch; the first virtual switch receives the data packet from the second virtual machine through the first virtual switch. The PMTU required for this transmission is obtained from the data packet, and the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch is determined, and the current PMTU recorded in the first flow table item is updated to the PMTU required for this transmission, and the second data packet is sent to the third virtual machine according to the updated first flow table item, and the third data packet returned by the third virtual machine is sent to the access gateway; the third data packet is decapsulated by the access gateway to obtain the target data packet, which is obtained by the third-party network element processing the original data packet in the second data packet; and the target data packet is forwarded to the application server in the fourth virtual machine running on the fourth computing node through the first virtual switch for response processing.
[0038] In actual applications, the access gateway can determine the next hop address of the data packet through the internal routing table or routing policy. According to the destination IP address of the data packet, the access gateway will query its routing table or routing policy to determine which third-party network element the data packet should be forwarded to. Of course, when it comes to using tunneling technology, the access gateway will encapsulate a new header outside the original data packet. This process is usually transparent, and the selection of the tunnel endpoint is also based on a preset policy or configuration. The information contained in this new header enables the data packet to be correctly transmitted from one network endpoint to another. The IP addresses at both ends of the tunnel are usually pre-configured before establishing the tunnel connection, and this information is stored in the configuration of the access gateway. This means that once a tunnel is established, all data packets that meet specific conditions will be transmitted according to this tunnel.
[0039] Specifically, the first virtual switch may receive the original data packet encapsulated with the VXLAN information forwarded by the second virtual switch. The first virtual switch decapsulates the original data packet encapsulated with the VXLAN information to obtain the original data packet sent by the application client. Figure 1 As shown in ②, the first virtual switch sends the original data packet to the first virtual machine running the access gateway. After receiving the original data packet forwarded by the first virtual switch, the access gateway encapsulates the first encapsulation information indicating that the access gateway accesses the third-party network element on the original data packet to obtain the first data packet. The first encapsulation information includes, for example, but is not limited to: VXLAN protocol information, GRE (Generic Routing Encapsulation) protocol information, GPE (Generic Protocol Extension) protocol information, or NSH (Network Service Header) protocol information. In actual applications, the source address information in the first encapsulation information is the address information of the access gateway (for example, the IP address information of the access gateway), and the destination address information in the first encapsulation information is the address information of the third-party network element (for example, the IP address information of the third-party network element). In this way, the first encapsulation information can instruct the access gateway to access the third-party network element.
[0040] In this embodiment, the access gateway also needs to determine the PMTU required for this transmission based on the data packet size information of the first data packet, and write the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain the second data packet.
[0041] In practical applications, the data packet size information of the first data packet can be directly used as the PMTU required for this transmission, or a correction value can be added to the data packet size information of the first data packet to obtain the PMTU required for this transmission. The correction value can be flexibly set as needed, and the correction value can be, for example, 10 bytes.
[0042] It is understandable that the access gateway can adaptively adjust the PMTU required for this transmission based on the data packet size information of the first data packet, which greatly reduces the probability of data packets being fragmented when sent by the access gateway to the third-party network element, improves the transmission efficiency of data packets, and ensures the network connectivity of application services. In addition, adaptive PMTU is only provided for data packet transmission between the access gateway and the third-party network element. In this way, non-standard MTU will not appear on the cloud computing platform, and PMTU restrictions are opened to the network traffic of the application client accessing the third-party network element through the access gateway, thereby improving the user experience of the cloud computing platform.
[0043] Further optionally, before determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway, the access gateway determines whether the packet size information of the first data packet is greater than a specified PMTU, and the specified PMTU is a PMTU determined based on the MTU of each of the first virtual machine and the third virtual machine; when the packet size information of the first data packet is greater than the specified PMTU, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is executed; when the packet size information of the first data packet is less than or equal to the specified PMTU, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is prohibited.
[0044] In actual applications, the cloud computing platform can set the MTU corresponding to the first virtual machine where the access gateway has been deployed, and set the MTU corresponding to the third virtual machine where the third-party network element has been deployed, and use the smaller MTU of the MTU corresponding to the first virtual machine and the MTU corresponding to the third virtual machine as the designated PMTU on the path between the access gateway and the third-party network element. Usually, the cloud computing platform allows the MTU of the first virtual machine where the access gateway has been deployed and the MTU of each of the three virtual machines where the third-party network element has been deployed to be a fixed value that is uniformly managed, such as 1500 bytes. In this case, the designated PMTU can be 1500 bytes.
[0045] In actual applications, the access gateway determines whether the data packet size information of the first data packet is greater than the specified PMTU. If it is greater, it means that the specified PMTU cannot meet the requirement of non-fragmentation of the first data packet. At this time, it is necessary to set the PMTU required for this transmission that is adaptive to the data packet size information of the first data packet. If it is greater or less than, it means that the specified PMTU can meet the requirement of fragmentation of the first data packet. At this time, the step of setting the PMTU required for this transmission that is adaptive to the data packet size information of the first data packet can be omitted to save computing resources and improve data packet transmission efficiency.
[0046] Further optionally, when the packet size information of the first data packet is greater than the specified PMTU, the access gateway determines whether the packet size information of the first data packet is greater than the PMTU required for the most recent transmission; if the packet size information of the first data packet is greater than the PMTU required for the most recent transmission, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is executed; if the packet size information of the first data packet is less than or equal to the PMTU determined most recently, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is prohibited.
[0047] As time goes by, the access gateway transmits data packets to the third-party network element multiple times, and the PMTU required for multiple transmissions may be determined multiple times based on the data packet size information of the data packet. In the case where the data packet size information of the first data packet is greater than the specified PMTU, the data packet size information of the first data packet can also be compared with the PMTU required for the most recent transmission, and the PMTU required for the most recent transmission is also the PMTU required for the transmission determined before this transmission. If the data packet size information of the first data packet is greater than the PMTU required for the most recent transmission, it means that the PMTU required for the most recent transmission cannot meet the requirement of non-fragmentation of the first data packet. At this time, it is necessary to set the PMTU required for this transmission that is adaptive to the data packet size information of the first data packet. If the data packet size information of the first data packet is less than or equal to the PMTU determined most recently, it means that the PMTU required for the most recent transmission can meet the requirement of non-fragmentation of the first data packet. At this time, the step of setting the PMTU required for this transmission that is adaptive to the data packet size information of the first data packet can be omitted, so as to save computing resources and improve data packet transmission efficiency.
[0048] In this embodiment, the access gateway determines the PMTU required for this transmission based on the data packet size information of the first data packet, and writes the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain the second data packet, see Figure 1As shown in ③, the access gateway sends the second data packet to the first virtual switch. Of course, if there is no need to perform the step of determining the PMTU required for this transmission based on the data packet size information of the first data packet, the access gateway can directly send the first data packet to the first virtual switch.
[0049] In this embodiment, after the first virtual switch receives the second data packet sent by the access gateway, the first virtual switch can obtain the PMTU required for this transmission from the second data packet, and determine the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, and update the current PMTU recorded in the first flow table item to the PMTU required for this transmission, and send the second data packet to the third virtual machine according to the updated first flow table item.
[0050] Specifically, the first virtual switch can obtain the PMTU required for this transmission from the first encapsulation information in the second data packet; then, determine the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, and the first flow table item is the flow table item associated with the access gateway accessing the third-party network element among the multiple flow table items included in the flow table. Optionally, in order to accurately find the flow table item associated with the access gateway accessing the third-party network element, the source address information in the first encapsulation information is the address information of the access gateway, and the destination address information in the first encapsulation information is the address information of the third-party network element; accordingly, the implementation method for determining the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch is: search the flow table corresponding to the first virtual switch according to the first encapsulation information in the second data packet, and use the flow table item that matches the source address information and the destination address information in the first encapsulation information as the first flow table item associated with the access gateway accessing the third-party network element.
[0051] Typically, the matching domain of a flow table entry is a 5-tuple of information, and the 5-tuple information includes, for example, but is not limited to: source IP address (Source IP Address), destination IP address (Destination IPAddress), source port (SourcePort), destination port (Destination Port), protocol (Protocol), etc. Therefore, the flow table entry whose matching domain matches the first encapsulation information can be used as the first flow table entry. Specifically, the source address information in the first encapsulation information is the address information of the access gateway (for example, the IP address information of the access gateway), and the destination address information in the first encapsulation information is the address information of the third-party network element (for example, the IP address information of the third-party network element). Then, the source IP address in the matching domain of the first flow table entry is the address information of the access gateway, and the destination IP address in the matching domain of the first flow table entry is the address information of the third-party network element.
[0052] In this embodiment, if the first virtual switch updates the current PMTU recorded in the first flow table entry to the PMTU required for this transmission, the data packet transmission control can be performed according to the latest PMTU in the first flow table entry. For example, the current PMTU recorded in the action information of the first flow table entry can be updated to the PMTU required for this transmission. The first virtual switch determines that the data packet size information of the second data packet matches the latest PMTU in the first flow table entry, determines that there is no need to fragment the second data packet, and directly sends the second data packet to the third virtual machine where the third-party network element has been deployed.
[0053] Optionally, if the second data packet is the first data packet (ie, the first packet) transmitted by the access gateway to the third-party network element, the current PMTU recorded in the first flow table entry may be a specified PMTU.
[0054] For example, the source IP address in the five-tuple information in the first flow table entry is 1.1.1.1:1, and the destination IP address in the five-tuple information in the first flow table entry is 4.4.4.4:3. The action table information of the first flow table entry is "VXLAN encapsulation: 9.9.9.9:9->31.31.31.31:31, ACL passed, speed limit 10Mbps, PMTU:1700", which means that the traffic from IP address 1.1.1.1:1 to IP address 4.4.4.4:3 will be encapsulated into the VXLAN tunnel from 9.9.9.9:9 to 31.31.31.31:31, and pass the ACL (Access Control List) check, with a speed limit of 10Mbps and a PMTU of 1700 bytes. The first flow table entry indicates that "traffic from IP address 1.1.1.1:1 to IP address 4.4.4.4:3 will be encapsulated into the VXLAN tunnel from IP address 9.9.9.9:9 to IP address 31.31.31.31:31, and pass the ACL check, with a rate limit of 10Mbps and a PMTU of 1700 bytes."
[0055] In actual applications, the second encapsulation information of accessing the third-party network element can be encapsulated in the second data packet through the first virtual switch, see Figure 1 As shown in ④, the first virtual switch sends the second data packet encapsulated with the second encapsulation information to the third computing node where the third virtual machine is deployed, and the second encapsulation information may be VXLAN information. The second encapsulation information may include: the IP address information of the first computing node (as the source address information) and the IP address information of the third computing node (as the source address information), and the second encapsulation information indicates access to a third-party network element.
[0056] Optionally, the implementation method of sending the second data packet to the third virtual machine according to the updated first flow table entry through the first virtual switch is: encapsulating the second encapsulation information for accessing the third-party network element on the second data packet through the first virtual switch, and the second encapsulation information includes the PMTU required for this transmission; sending the second data packet encapsulated with the second encapsulation information to the third virtual machine through the first virtual switch according to the updated first flow table entry. In practical applications, there is no restriction on the protocol of the second encapsulation information. Optionally, the second encapsulation information is the encapsulation information of the VXLAN protocol. Optionally, the field information of the reserved field (reserve field) in the encapsulation information of the VXLAN protocol is the PMTU required for this transmission. By writing the PMTU required for this transmission in the reserved field in the encapsulation information of the VXLAN protocol, it is convenient to quickly and accurately determine the PMTU required for this transmission. Of course, it is not limited to writing the PMTU required for this transmission in the reserved field.
[0057] It is worth noting that writing the PMTU required for this transmission into the second encapsulation information of the encapsulated second data packet can facilitate the subsequent third computing node to quickly and accurately determine the PMTU required for this transmission of the second data packet.
[0058] It is worth noting that if the access gateway sends the first data packet without writing the PMTU required for this transmission to the first virtual switch, the first virtual switch also needs to determine the first flow table entry associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, and send the second data packet to the third virtual machine according to the first flow table entry.
[0059] If the access gateway directly sends the first data packet to the first virtual switch, the first virtual switch also needs to determine the first flow table entry associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, and send the first data packet to the third virtual machine according to the first flow table entry.
[0060] In this embodiment, the third computing node is used to receive the second data packet sent by the first virtual switch of the first computing node, and process the second data packet through the third-party network element on the third virtual machine to obtain a third data packet, and return it to the first computing node.
[0061] See also Figure 1 As shown in ④, the first virtual switch of the first computing node can send the second data packet encapsulated with the second encapsulation information to the third virtual switch of the third computing node. Figure 1As shown in ⑤, the third virtual switch decapsulates the second data packet encapsulated with the second encapsulation information to obtain the second data packet, and sends the second data packet to the third virtual machine. The third virtual machine can obtain the original data packet from the second data packet, process the original data packet to obtain the target data packet, and obtain the third data packet based on the target data packet. Optionally, the third-party network element in the third virtual machine processes the second data packet to obtain the third data packet in the following manner: obtain the address information of the access gateway and the address information of the third-party network element from the first encapsulation information included in the second data packet by the third-party network element; process the original data packet in the second data packet by the third-party network element to obtain the target data packet; encapsulate the third encapsulation information on the target data packet by the third-party network element to obtain the third data packet, wherein the source address information of the third encapsulation information is the address information of the third-party network element, and the destination address information of the third encapsulation information is the address information of the access gateway. See. Figure 1 As shown in ⑥, the third virtual machine returns the third data packet including the third encapsulation information and the target data packet to the third virtual switch.
[0062] In this embodiment, the third virtual switch can encapsulate VXLAN information on the third data packet, and the VXLAN information includes the IP address information (source address information) of the third computing node and the IP address information (destination address information) of the second computing node. Figure 1 As shown in ⑦, the third virtual switch sends the encapsulated third data packet to the first virtual switch according to the VXLAN information in the encapsulated third data packet. Figure 1 As shown in ⑧, the first virtual switch decapsulates the encapsulated third data packet to obtain the third data packet, and sends the third data packet to the access gateway. Figure 1 As shown in 9, the access gateway decapsulates the third data packet to obtain the target data packet, and sends the target data packet to the first virtual switch. Figure 1 As shown in ⑩, the first virtual switch can encapsulate VXLAN information for the target data packet, and the VXLAN information includes the IP address information (source address information) of the first computing node and the IP address information (destination address information) of the fourth computing node. The first virtual switch sends the encapsulated target data packet to the fourth virtual switch according to the VXLAN information in the encapsulated target data packet. Figure 1 In As shown, the fourth virtual switch decapsulates the encapsulated target data packet to obtain the target data packet, and sends the target data packet to the application server for response processing. At this point, the original data packet sent from the application client is processed by the third-party network element to obtain the target data packet, and then the entire process of sending the target data packet to the application server for response is completed.
[0063] In this embodiment, the fourth computing node is used to respond to the target data packet sent by the first computing node through the application server in the fourth virtual machine, and the target data packet is the original data packet processed by the third-party network element.
[0064] In some optional embodiments, in addition to the second virtual switch in the second computing node being able to dynamically update the flow table entry, the second virtual switch in the third computing node can also dynamically update the flow table entry, thereby ensuring that the target data packet can be transmitted from the third service network element to the access gateway without undergoing a sharding operation. Based on this, the third computing node is used to receive the second data packet sent by the first virtual switch through the third virtual switch, obtain the PMTU required for this transmission from the second data packet, and determine the second flow table entry associated with the third-party network element accessing the access gateway in the flow table corresponding to the third virtual switch, and update the current PMTU recorded in the second flow table entry to the PMTU required for this transmission; wherein the first virtual switch and the access gateway are deployed on the first computing node, and the second data packet is sent by the access gateway to the first virtual switch; the second data packet is forwarded to the third virtual machine through the third virtual switch, so that the third-party network element in the third virtual machine processes the second data packet to obtain a third data packet; the third virtual switch sends the third data packet to the first virtual switch according to the updated second flow table entry, so that the first virtual switch forwards the third data packet to the access gateway.
[0065] Optionally, the implementation method of obtaining the PMTU required for this transmission from the second data packet through the third virtual switch is: obtaining the second encapsulation information for accessing the third-party network element from the second data packet through the third virtual switch; and obtaining the PMTU required for this transmission from the second encapsulation information.
[0066] In actual applications, the third virtual switch can obtain the address information of the access gateway and the address information of the third-party network element from the first encapsulation information in the second data packet, and obtain the flow table entry whose source address information in the matching domain is the address information of the third-party network element and whose destination address information is the address information of the access gateway in the flow table corresponding to the third virtual switch as the second flow table entry associated with the third-party network element accessing the access gateway. The current PMTU recorded in the second flow table entry is updated to the PMTU required for this transmission, so that the third data packet obtained after the third-party network element processes the second data packet can be returned to the access gateway without fragmentation.
[0067] It is worth noting that if the second data packet received by the third virtual switch does not contain the PMTU required for this transmission, the third virtual switch can forward the second data packet to the third virtual machine. Alternatively, if the third virtual switch receives the first data packet sent by the first virtual switch, the third virtual switch can forward the first data packet to the third virtual machine.
[0068] In the cloud computing platform provided by the embodiment of the present application, after the access gateway receives the original data packet sent by the application client forwarded by the virtual switch, the access gateway encapsulates the original data packet with encapsulation information indicating that the access gateway accesses the third-party network element to obtain a first data packet, and adaptively determines the PMTU required for the current transmission of the path between the access gateway and the third-party network element according to the data packet size of the first data packet, and writes the PMTU required for this transmission into the first data packet to obtain a second data packet. The access gateway forwards the second data packet to the virtual switch, and the virtual switch updates the current PMTU in the flow table item associated with the access gateway accessing the third-party network element to the PMTU required for this transmission, and sends the second data packet that does not need to be fragmented to the third-party network element according to the updated flow table item. The third-party network element processes the original data packet in the second data packet to obtain the target data packet, and the target data packet is returned by the access gateway through the virtual switch to the application server for response processing. Therefore, in the case where the application service uses the third-party network element, the access gateway can adaptively adjust the PMTU required for this transmission according to the data packet size information of the first data packet, greatly reducing the probability of the data packet sent by the access gateway to the third-party network element being fragmented, improving the transmission efficiency of the data packet, and ensuring the network connectivity of the application service. In addition, adaptive PMTU is only provided for data packet transmission between the access gateway and the third-party network element. This will not cause non-standard MTU on the cloud computing platform, and will open PMTU restrictions on network traffic of application clients accessing third-party network elements through the access gateway, thereby improving the user experience of the cloud computing platform.
[0069] In order to better understand the technical solution of this application, Figure 1 A specific process of an application client accessing an application server is introduced. Specifically, the process of an application client accessing an application server may include the following steps:
[0070] S1. The second virtual switch receives an original data packet sent by an application client in a second virtual machine.
[0071] S2. The second virtual switch encapsulates the first VXLAN information into the original data packet, where the first VXLAN information includes: the IP address information of the second computing node (as source address information) and the IP address information of the first computing node (as destination address information).
[0072] S3. The second virtual switch sends an original data packet encapsulated with the first VXLAN information to the first virtual switch, such as Figure 1As shown in ①. The original data packet encapsulating the first VXLAN information can be recorded as "IP address information of the second computing node->IP address information of the first computing node|original data packet". Among them, -> indicates the data packet transmission direction. "IP address information of the second computing node->IP address information of the first computing node" represents the first VXLAN information.
[0073] S4, the first virtual switch decapsulates the original data packet encapsulated with the first VXLAN information to obtain the original data packet; the first virtual switch sends the original data packet to the access gateway in the first virtual machine, such as Figure 1 As shown in ②;
[0074] S5. The access gateway in the first virtual machine encapsulates the first encapsulation information into the original data packet to obtain a first data packet; determines the PMTU required for this transmission according to the data packet size information of the first data packet, and writes the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain a second data packet.
[0075] The source address information in the first encapsulation information is the IP address information of the access gateway, the destination address information in the first encapsulation information is the IP address information of the third-party network element, and the first encapsulation information also records the PMTU required for this transmission. The second data packet can be recorded as "IP address information of the access gateway->IP address information of the third-party network element (a field is added to the protocol header, and the field records the PMTU required for this transmission)|original data packet", and "IP address information of the access gateway->IP address information of the third-party network element" represents the first encapsulation information.
[0076] S6. The access gateway in the first virtual machine sends a second data packet to the first virtual switch. Figure 1 As shown in ③;
[0077] S7. The first virtual switch encapsulates the second VXLAN information in the second data packet, where the second VXLAN information includes: the IP address information of the first computing node (as the source address information) and the IP address information of the third computing node (as the destination address information), and sends the second data packet encapsulating the second VXLAN information to the third virtual switch. Figure 1 As shown in ④.
[0078] The second data packet encapsulating the second VXLAN information can be recorded as “IP address information of the first computing node->IP address information of the third computing node|IP address information of the access gateway->IP address information of the third-party network element (a field is added in the protocol header, and the field records the PMTU required for this transmission)|original data packet”. “IP address information of the first computing node->IP address information of the third computing node” represents the second VXLAN information.
[0079] S8, the third virtual switch decapsulates the second data packet encapsulating the second VXLAN information to obtain a second data packet; and the third virtual switch sends the second data packet to a third-party network element in the third virtual machine, such as Figure 1 As shown in ⑤.
[0080] S9. The third-party network element in the third virtual machine decapsulates the second data packet to obtain the original data packet, and processes the original data packet to obtain the target data packet. The third-party network element generates third encapsulation information that does not record the PTMU information based on the first encapsulation information that records the PTMU information in the second data packet, and encapsulates the third encapsulation information on the target data packet. The encapsulated target data packet (which may be referred to as the third data packet) is recorded as "IP address information of the third-party network element->IP address information of the access gateway (the protocol header does not record the PMTU required for this transmission)|target data packet". The third virtual machine sends the third data packet to the third virtual switch, as shown in FIG. Figure 1 As shown in ⑥.
[0081] S10, the third virtual switch encapsulates the third VXLAN information in the third data packet, and sends the third data packet encapsulating the third VXLAN information to the first virtual switch, such as Figure 1 As shown in ⑦.
[0082] The third data packet encapsulating the third VXLAN information can be recorded as "IP address information of the third computing node->IP address information of the first computing node|IP address information of the third-party network element->IP address information of the access gateway (the protocol header does not record the PMTU required for this transmission)|target data packet". The third VXLAN information is expressed as "IP address information of the third computing node->IP address information of the first computing node".
[0083] S11, the first virtual switch decapsulates the third data packet encapsulating the third VXLAN information to obtain a third data packet, and sends the third data packet to the access gateway in the first virtual machine, such as Figure 1 As shown in ⑧.
[0084] S12: The access gateway in the second virtual machine decapsulates the third data packet, obtains the target data packet and sends it to the first virtual switch, such as Figure 1 As shown in Figure 9.
[0085] S13, the first virtual switch encapsulates the fourth VXLAN information in the target data packet, and sends the target data packet encapsulating the fourth VXLAN information to the fourth virtual switch, such as Figure 1 As shown in (10).
[0086] Among them, the target data packet encapsulating the fourth VXLAN information is recorded as "IP address information of the first computing node->IP address information of the fourth computing node|target data packet", and "IP address information of the first computing node->IP address information of the fourth computing node" can be expressed as the fourth VXLAN information.
[0087] S14, the fourth virtual switch decapsulates the target data packet encapsulating the fourth VXLAN information to obtain the target data packet, and sends the target data packet to the application server in the fourth virtual machine for response processing, such as Figure 1 middle shown.
[0088] Figure 2 A flowchart of a data packet transmission method for a cloud computing platform accessing a third-party network element provided in an embodiment of the present application. Applied to a first computing node among a plurality of computing nodes included in the cloud computing platform, the first computing node includes a first virtual switch and a first virtual machine that communicate with each other, and the first virtual machine has deployed an access gateway; see Figure 2 , the method may include:
[0089] 201. Receive an original data packet forwarded by a first virtual switch through an access gateway, and encapsulate first encapsulation information instructing the access gateway to access a third-party network element on the original data packet to obtain a first data packet; wherein the original data packet is sent by an application client in a second virtual machine running on a second computing node, and the third-party network element is deployed on a third computing node running a third virtual machine.
[0090] 202. Determine the PMTU required for this transmission based on the data packet size information of the first data packet through the access gateway, write the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain a second data packet, and send the second data packet to the first virtual switch.
[0091] 203. Obtain the PMTU required for this transmission from the second data packet through the first virtual switch, determine the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, and update the current PMTU recorded in the first flow table item to the PMTU required for this transmission, and send the second data packet to the third virtual machine according to the updated first flow table item, and send the third data packet returned by the third virtual machine to the access gateway.
[0092] 204. Decapsulate the third data packet through the access gateway to obtain a target data packet, where the target data packet is obtained by a third-party network element processing the original data packet in the second data packet; and forward the target data packet through the first virtual switch to the application server in the fourth virtual machine running on the fourth computing node for response processing.
[0093] Optionally, before determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway, the above method also includes: determining through the access gateway whether the packet size information of the first data packet is greater than a specified PMTU, and the specified PMTU is a PMTU determined based on the MTU of each of the first virtual machine and the third virtual machine; when the packet size information of the first data packet is greater than the specified PMTU, executing the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway; when the packet size information of the first data packet is less than or equal to the specified PMTU, prohibiting the execution of the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway.
[0094] Optionally, when the packet size information of the first data packet is greater than the specified PMTU, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is executed, including: when the packet size information of the first data packet is greater than the specified PMTU, determining through the access gateway whether the packet size information of the first data packet is greater than the PMTU required for the most recent transmission; if the packet size information of the first data packet is greater than the PMTU required for the most recent transmission, executing the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway; if the packet size information of the first data packet is less than or equal to the most recently determined PMTU, prohibiting executing the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway.
[0095] Optionally, sending a second data packet to the third virtual machine according to the updated first flow table entry through the first virtual switch, including: encapsulating second encapsulation information for accessing a third-party network element on the second data packet through the first virtual switch, the second encapsulation information including the PMTU required for this transmission; sending a second data packet encapsulated with the second encapsulation information to the third virtual machine according to the updated first flow table entry through the first virtual switch.
[0096] Optionally, the second encapsulation information is encapsulation information of the VXLAN protocol, and the field information of the reserved field in the encapsulation information of the VXLAN protocol is the PMTU required for this transmission.
[0097] Optionally, the source address information in the first encapsulation information is the address information of the access gateway, and the destination address information in the first encapsulation information is the address information of the third-party network element; accordingly, determining the first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch includes: searching the flow table corresponding to the first virtual switch according to the first encapsulation information in the second data packet, and using the flow table item found that matches the source address information and the destination address information in the first encapsulation information as the first flow table item associated with the access gateway accessing the third-party network element.
[0098] Figure 3 A flowchart of another method for transmitting data packets of a cloud computing platform connected to a third-party network element provided in an embodiment of the present application. Applied to a third computing node among multiple computing nodes included in the cloud computing platform, the third computing node includes a third virtual switch and a third virtual machine that communicate with each other, and the third virtual machine has deployed a third-party network element; see Figure 3 , the method may include:
[0099] 301. Receive a second data packet sent by the first virtual switch through the third virtual switch, obtain the PMTU required for this transmission from the second data packet, determine a second flow table item associated with the third-party network element accessing the access gateway in the flow table corresponding to the third virtual switch, and update the current PMTU recorded in the second flow table item to the PMTU required for this transmission; wherein the first virtual switch and the access gateway are deployed on the first computing node, and the second data packet is sent by the access gateway to the first virtual switch.
[0100] 302. Forward the second data packet to the third virtual machine through the third virtual switch, so that the third-party network element in the third virtual machine processes the second data packet to obtain a third data packet.
[0101] 303. Send a third data packet to the first virtual switch according to the updated second flow table entry through the third virtual switch, so that the first virtual switch forwards the third data packet to the access gateway.
[0102] Optionally, obtaining the PMTU required for this transmission from the second data packet through the third virtual switch includes: obtaining second encapsulation information for accessing a third-party network element from the second data packet through the third virtual switch; and obtaining the PMTU required for this transmission from the second encapsulation information.
[0103] Optionally, the third-party network element in the third virtual machine processes the second data packet to obtain the third data packet, including: obtaining, by the third-party network element, address information of the access gateway and address information of the third-party network element from the first encapsulation information included in the second data packet; and processing, by the third-party network element, an original data packet in the second data packet to obtain a target data packet;
[0104] The third encapsulation information is encapsulated on the target data packet by the third-party network element to obtain a third data packet, wherein the source address information of the third encapsulation information is the address information of the third-party network element, and the destination address information of the third encapsulation information is the address information of the access gateway.
[0105] Optionally, the third-party network element includes any of the following: a firewall, an intrusion detection system, or a traffic mirroring service.
[0106] about Figure 2 or Figure 3 The detailed implementation and beneficial effects of each step in the method have been described in detail in the aforementioned embodiments and will not be elaborated here.
[0107] In actual applications, after the access gateway receives the original data packet forwarded by the virtual switch, the access gateway usually tunnel encapsulates the original data packet through tunnel encapsulation, and then sends the tunnel encapsulated data packet to other network elements for processing. Other network elements can be third-party network elements or network elements provided by the cloud computing platform itself. However, tunnel encapsulation is likely to cause the size of the data packet to exceed the PMTU (Path Maximum Transmission Unit) on the path between the access gateway and other network elements, so the data packet needs to be fragmented. Fragmenting the data packet not only increases network latency, but may also cause the entire data packet to be retransmitted due to the loss or damage of any fragment, resulting in low reliability and efficiency of data packet transmission.
[0108] Figure 4 A flowchart of a data packet transmission method provided in an embodiment of the present application. Figure 4 , the method may include the following steps:
[0109] 401. Receive, through an access gateway, an original data packet forwarded by a first virtual switch; and encapsulate, on the original data packet, first encapsulation information indicating that the access gateway accesses a target network element, to obtain a first data packet.
[0110] The target network elements and other network elements may be third-party network elements or various application services provided by the cloud computing platform itself, and there is no restriction on this.
[0111] The first virtual switch and the access gateway are deployed on the same computing node. The original data packet forwarded by the first virtual switch is a data packet sent by an application service on other computing nodes, and the other computing nodes are different from the computing node where the first virtual switch is located.
[0112] After receiving the original data packet forwarded by the first virtual switch, the access gateway encapsulates the first encapsulation information indicating that the access gateway accesses the target network element on the original data packet to obtain the first data packet. The first encapsulation information includes, for example, but is not limited to: VXLAN protocol information, GRE (Generic Routing Encapsulation) protocol information, GPE (Generic Protocol Extension) protocol information, or NSH (Network Service Header) protocol information. In actual applications, the source address information in the first encapsulation information is the address information of the access gateway (for example, the IP address information of the access gateway), and the destination address information in the first encapsulation information is the address information of the target network element (for example, the IP address information of the target network element). In this way, the first encapsulation information can instruct the access gateway to access the target network element.
[0113] 402. Determine the PMTU required for this transmission based on the data packet size information of the first data packet through the access gateway, write the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain a second data packet, and send the second data packet to the first virtual switch.
[0114] In practical applications, the data packet size information of the first data packet can be directly used as the PMTU required for this transmission, or a correction value can be added to the data packet size information of the first data packet to obtain the PMTU required for this transmission. The correction value can be flexibly set as needed, and the correction value can be, for example, 10 bytes.
[0115] It is understandable that the access gateway can adaptively adjust the PMTU required for this transmission according to the data packet size information of the first data packet, which greatly reduces the probability of data packets being fragmented when sent by the access gateway to the target network element and improves the transmission efficiency of data packets.
[0116] Further optionally, before determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway, the access gateway determines whether the packet size information of the first data packet is greater than a specified PMTU, and the specified PMTU is a PMTU determined based on the respective MTUs of the access gateway and the target network element; if the packet size information of the first data packet is greater than the specified PMTU, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is executed; if the packet size information of the first data packet is less than or equal to the specified PMTU, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is prohibited.
[0117] Optionally, when the packet size information of the first data packet is greater than the specified PMTU, the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway is executed, including: when the packet size information of the first data packet is greater than the specified PMTU, determining through the access gateway whether the packet size information of the first data packet is greater than the PMTU required for the most recent transmission; if the packet size information of the first data packet is greater than the PMTU required for the most recent transmission, executing the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway; if the packet size information of the first data packet is less than or equal to the most recently determined PMTU, prohibiting executing the step of determining the PMTU required for this transmission based on the packet size information of the first data packet through the access gateway.
[0118] 403. Obtain the PMTU required for this transmission from the second data packet through the first virtual switch, determine the first flow table item associated with the access gateway accessing the target network element in the flow table corresponding to the first virtual switch, update the current PMTU recorded in the first flow table item to the PMTU required for this transmission, and send the second data packet to the target network element according to the updated first flow table item.
[0119] Optionally, sending the second data packet to the target network element through the first virtual switch according to the updated first flow table entry includes: encapsulating the second encapsulation information for accessing the target network element on the second data packet through the first virtual switch, the second encapsulation information including the PMTU required for this transmission; sending the second data packet encapsulated with the second encapsulation information to the target network element through the first virtual switch according to the updated first flow table entry. Optionally, the second encapsulation information is the encapsulation information of the VXLAN protocol, and the field information of the reserved field in the encapsulation information of the VXLAN protocol is the PMTU required for this transmission. Optionally, the source address information in the first encapsulation information is the address information of the access gateway, and the destination address information in the first encapsulation information is the address information of the target network element; accordingly, determining the first flow table entry associated with the access gateway accessing the target network element in the flow table corresponding to the first virtual switch includes: searching the flow table corresponding to the first virtual switch according to the first encapsulation information in the second data packet, and using the flow table entry that matches the source address information and the destination address information in the first encapsulation information as the first flow table entry associated with the access gateway accessing the target network element.
[0120] The technical solution provided by the embodiment of the present application enables the access gateway to adaptively adjust the PMTU required for this transmission based on the data packet size information, greatly reducing the probability of data packets sent by the access gateway to other network elements being fragmented, and improving the transmission efficiency and reliability of data packets.
[0121] about Figure 4 The implementation of each step in the illustrated method embodiment is similar to the implementation of the relevant steps in the aforementioned embodiments, and will not be repeated here.
[0122] It should be noted that the execution subject of each step of the method provided in the above embodiment can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 301 to 303 can be device A; for another example, the execution subject of steps 301 and 302 can be device A, and the execution subject of step 303 can be device B; and so on. In addition, in some processes described in the above embodiments and the accompanying drawings, multiple operations appearing in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or executed in parallel. The sequence numbers of the operations, such as 301, 302, etc., are only used to distinguish different operations, and the sequence numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations can be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., and do not represent the order of precedence, nor do they limit "first" and "second" to be different types.
[0123] Figure 5This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 5 As shown, in practice, the electronic device includes: a memory 51 and a processor 52.
[0124] The memory 51 is used to store computer programs and can be configured to store various other data to support operations on the electronic device. Examples of such data include instructions for any application or method operating on the electronic device, data structures, contact data, phone book data, messages, pictures, videos, etc.
[0125] The processor 52 is coupled to the memory 51 and is used to execute the computer program in the memory 51 to: execute the steps in the data packet transmission method of the cloud computing platform accessing the third-party network element, or execute the steps in the data packet transmission method.
[0126] Optional, such as Figure 5 As shown, the electronic device also includes: a communication component 53, a display 54, a power component 55, an audio component 56 and other components. Figure 5 Only some components are shown schematically, which does not mean that the electronic device only includes Figure 5 In addition, Figure 5 The components in the dashed box are optional components, not mandatory components, and the specific components depend on the product form of the working node. The working node of this embodiment can be implemented as a terminal device such as a desktop computer, a laptop computer, a smart phone, or an IOT device, or a server-side device such as a conventional server, a cloud server, or a server array. If the working node of this embodiment is implemented as a terminal device such as a desktop computer, a laptop computer, a smart phone, etc., it can include Figure 5 If the working node of this embodiment is implemented as a server device such as a conventional server, a cloud server or a server array, it may not include Figure 5 Components within the dashed box.
[0127] The above-mentioned memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read only memory (EEPROM), erasable programmable read only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, disk or optical disk. The above-mentioned communication component is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as 2G, 3G, 4G / LTE, 5G and other mobile communication networks, or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. The above-mentioned display includes a screen, and the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, slides, and gestures on the touch panel. The touch sensor can not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. The above-mentioned power supply component provides power to various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device where the power supply component is located. The above-mentioned audio component may be configured to output and / or input audio signals. For example, the audio component includes a microphone (Microphone, MIC), and when the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive an external audio signal. The received audio signal may be further stored in a memory or sent via a communication component. In some embodiments, the audio component also includes a speaker for outputting an audio signal.
[0128] Accordingly, the embodiment of the present application also provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the processor is enabled to implement each step in the above method embodiment. Among them, the computer-readable storage medium includes volatile or non-volatile or a combination thereof, and can be removable or non-removable. Examples of computer-readable storage media include, but are not limited to, phase-change random access memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, tape disk storage or other magnetic storage device or any other non-transmission medium
[0129] Accordingly, the present application embodiment also provides a computer program product, the computer program product includes a computer program or instructions, when the computer program or instructions are executed by the processor, the processor is enabled to implement the steps in the above method embodiment. It should be understood that each process or a combination of multiple processes in the above method flow can be implemented by a computer program or instruction. In addition, these computer programs or instructions can be applied to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device, so that the processor of the general-purpose computer, the special-purpose computer, the embedded processor or other programmable data processing device can be implemented as a device for implementing the corresponding functions in the above method embodiment.
[0130] It should also be noted that the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, commodity or equipment including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or equipment. In the absence of further restrictions, the elements defined by the sentence "including one..." do not exclude the presence of other identical elements in the process, method, commodity or equipment including the elements. The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of the claims of the present application.
Claims
1. A method for transmitting data packets of a cloud computing platform connected to a third-party network element, characterized in that: Applied to a first computing node among a plurality of computing nodes included in the cloud computing platform, the first computing node includes a first virtual switch and a first virtual machine that communicate with each other, and the first virtual machine has deployed an access gateway; the method includes: Receiving, by the access gateway, an original data packet forwarded by the first virtual switch, and encapsulating, on the original data packet, first encapsulation information indicating that the access gateway accesses a third-party network element, to obtain a first data packet; wherein the original data packet is sent by an application client in a second virtual machine running on a second computing node, and the third-party network element is deployed on a third computing node running a third virtual machine; Determining, by the access gateway, a PMTU required for this transmission based on the data packet size information of the first data packet, and writing the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain a second data packet, and sending the second data packet to the first virtual switch; Obtaining the PMTU required for the current transmission from the second data packet through the first virtual switch, determining a first flow table item associated with the access gateway accessing the third-party network element in the flow table corresponding to the first virtual switch, updating the current PMTU recorded in the first flow table item to the PMTU required for the current transmission, sending the second data packet to the third virtual machine according to the updated first flow table item, and sending the third data packet returned by the third virtual machine to the access gateway; The third data packet is decapsulated by the access gateway to obtain a target data packet, where the target data packet is obtained by the third-party network element processing the original data packet in the second data packet; and the target data packet is forwarded by the first virtual switch to the application server in the fourth virtual machine running on the fourth computing node for response processing.
2. The method according to claim 1, characterized in that Before determining, by the access gateway, the PMTU required for the current transmission based on the data packet size information of the first data packet, the method further includes: Determining, by the access gateway, whether the data packet size information of the first data packet is greater than a specified PMTU, where the specified PMTU is a PMTU determined according to the respective MTUs of the first virtual machine and the third virtual machine; In the case where the data packet size information of the first data packet is greater than the specified PMTU, a step of determining the PMTU required for this transmission based on the data packet size information of the first data packet by the access gateway is performed; In the case where the data packet size information of the first data packet is less than or equal to the specified PMTU, the step of determining the PMTU required for this transmission based on the data packet size information of the first data packet by the access gateway is prohibited.
3. The method according to claim 2, characterized in that In a case where the data packet size information of the first data packet is greater than the specified PMTU, the step of determining the PMTU required for this transmission based on the data packet size information of the first data packet by the access gateway is performed, including: In the case where the data packet size information of the first data packet is greater than the specified PMTU, determining, by the access gateway, whether the data packet size information of the first data packet is greater than the PMTU required for the most recent transmission; If the data packet size information of the first data packet is larger than the PMTU required for the most recent transmission, performing the step of determining the PMTU required for this transmission based on the data packet size information of the first data packet by the access gateway; If the data packet size information of the first data packet is less than or equal to the most recently determined PMTU, the step of determining the PMTU required for this transmission based on the data packet size information of the first data packet by the access gateway is prohibited.
4. The method according to claim 1, characterized in that: Sending the second data packet to the third virtual machine according to the updated first flow table entry through the first virtual switch includes: Encapsulating second encapsulation information for accessing the third-party network element on the second data packet through the first virtual switch, wherein the second encapsulation information includes the PMTU required for the current transmission; A second data packet encapsulated with the second encapsulation information is sent to the third virtual machine through the first virtual switch according to the updated first flow table entry.
5. The method according to claim 4, characterized in that The second encapsulation information is the encapsulation information of the VXLAN protocol, and the field information of the reserved field in the encapsulation information of the VXLAN protocol is the PMTU required for the current transmission.
6. The method according to any one of claims 1 to 5, characterized in that: The source address information in the first encapsulation information is the address information of the access gateway, and the destination address information in the first encapsulation information is the address information of the third-party network element; Correspondingly, determining a first flow table entry in the flow table corresponding to the first virtual switch that is associated with the access gateway accessing the third-party network element includes: The flow table corresponding to the first virtual switch is searched according to the first encapsulation information in the second data packet, and the flow table entry found that matches the source address information and the destination address information in the first encapsulation information is used as the first flow table entry associated with the access gateway accessing the third-party network element.
7. A method for transmitting data packets of a cloud computing platform connected to a third-party network element, characterized in that: The method is applied to a third computing node among the plurality of computing nodes included in the cloud computing platform, wherein the third computing node includes a third virtual switch and a third virtual machine that communicate with each other, and the third virtual machine has deployed a third-party network element; the method includes: Receiving a second data packet sent by the first virtual switch through the third virtual switch, obtaining the PMTU required for this transmission from the second data packet, and determining a second flow table item associated with the third-party network element access access gateway in the flow table corresponding to the third virtual switch, and updating the current PMTU recorded in the second flow table item to the PMTU required for this transmission; wherein the first virtual switch and the access gateway are deployed on the first computing node, and the second data packet is sent by the access gateway to the first virtual switch; forwarding the second data packet to the third virtual machine through the third virtual switch, so that the third-party network element in the third virtual machine processes the second data packet to obtain a third data packet; The third data packet is sent to the first virtual switch according to the updated second flow table entry through the third virtual switch, so that the first virtual switch forwards the third data packet to the access gateway.
8. The method according to claim 7, characterized in that Obtaining the PMTU required for the current transmission from the second data packet through the third virtual switch includes: The second encapsulation information for accessing the third-party network element is obtained from the second data packet through the third virtual switch; and the PMTU required for the current transmission is obtained from the second encapsulation information.
9. The method according to claim 7, characterized in that: The third-party network element in the third virtual machine processes the second data packet to obtain a third data packet, including: Acquire, by the third-party network element, the address information of the access gateway and the address information of the third-party network element from the first encapsulation information included in the second data packet; Processing the original data packet in the second data packet by the third-party network element to obtain a target data packet; The third data packet is obtained by encapsulating the third encapsulation information on the target data packet through the third-party network element, wherein the source address information of the third encapsulation information is the address information of the third-party network element, and the destination address information of the third encapsulation information is the address information of the access gateway.
10. The method according to any one of claims 7 to 9, characterized in that: The third-party network element includes any one of the following: a firewall, an intrusion detection system or a traffic mirroring service.
11. A cloud computing platform, characterized in that: include: a first computing node, a second computing node, a third computing node, and a fourth computing node; The first computing node includes a first virtual switch and a first virtual machine that communicate with each other, and the first virtual machine has deployed an access gateway; the second computing node includes a second virtual machine that has deployed an application client; the third computing node includes a third virtual switch and a third virtual machine that communicate with each other, and the third virtual machine has deployed an access to a third-party network element; The fourth computing node includes a fourth virtual machine on which the application server has been deployed; The second computing node is used to forward the original data packet sent by the application client in the second virtual machine to the first computing node; The first computing node is used to execute the steps in the method according to any one of claims 1 to 6; The third computing node is used to execute the steps in the method according to any one of claims 7 to 10; The fourth computing node is used to respond to and process the target data packet sent by the first computing node through the application server in the fourth virtual machine, and the target data packet is obtained by processing the original data packet by the third-party network element.
12. A data packet transmission method, characterized in that: include: receiving, through the access gateway, an original data packet forwarded by the first virtual switch; and encapsulating first encapsulation information instructing the access gateway to access the target network element on the original data packet to obtain a first data packet; Determining, by the access gateway, a PMTU required for this transmission based on the data packet size information of the first data packet, and writing the PMTU required for this transmission into the first encapsulation information in the first data packet to obtain a second data packet, and sending the second data packet to the first virtual switch; The PMTU required for the current transmission is obtained from the second data packet through the first virtual switch, and the first flow table item associated with the access gateway accessing the target network element in the flow table corresponding to the first virtual switch is determined, and the current PMTU recorded in the first flow table item is updated to the PMTU required for the current transmission, and the second data packet is sent to the target network element according to the updated first flow table item.
13. An electronic device, characterized in that: include: Memory and processor; The memory is used to store a computer program; the processor is coupled to the memory and is used to execute the computer program to perform the steps in the method according to any one of claims 1 to 10 or claim 12.
14. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the processor is enabled to implement the steps of the method according to any one of claims 1 to 10 or claim 12.
15. A computer program product, characterized in that The method comprises a computer program or an instruction. When the computer program or the instruction is executed by a processor, the processor is enabled to implement the steps of the method according to any one of claims 1 to 10 or claim 12.
Citation Information
Patent Citations
Message transformation method and device of virtual extensible local area network (VXLAN)
CN105991387A
Method for dynamically discovering IPsec tunnel PMTU
CN1545253A