A method and device for tenant gateway migration, an electronic device, and a storage medium

By identifying the target ingress and egress ports during the tenant gateway migration process and obtaining and updating the virtual switch configuration information, the problem of VPN service interruption during tenant gateway migration was resolved, and stable VPN service transmission was achieved.

CN119766647BActive Publication Date: 2025-11-04CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411727850.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-11-04
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

During tenant gateway migration, existing technologies suffer from VPN service interruptions due to configuration delays causing data packets to fail to find their destination port for forwarding.

Method used

During the migration process, the target ingress and egress ports of the host machine are determined based on the type of the target tenant gateway. The configuration data of the virtual private network gateway is obtained, and the port configuration information is added to the virtual switch to update the configuration of the traffic redirection gateway, so as to ensure that public network data has a clear transmission path in the virtual switch.

Benefits of technology

This avoids the loss of public network data, ensuring the stability of VPN services and improving their overall stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119766647B_ABST
    Figure CN119766647B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a tenant gateway migration method and device, electronic equipment and storage medium, comprising: in the process of migrating an initial tenant gateway to a target tenant gateway, determining a target ingress port and a target egress port of a host machine according to a type of the target tenant gateway, wherein the target ingress port is used to receive public network data or receive public network data forwarded by a flow guide gateway, the target egress port is used to send the public network data or the public network data forwarded by the flow guide gateway to a virtual private network gateway, obtaining configuration data associated with the virtual private network gateway, and adding port configuration information corresponding to the target ingress port and the target egress port in a virtual switch according to the configuration data. Through the embodiments of the present application, the public network data is avoided from being discarded, the VPN service is prevented from being interrupted, and the stability of the VPN service is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of cloud computing, and particularly to a tenant gateway migration method and device, electronic equipment and storage medium. BACKGROUND

[0002] The tenant gateway is a key component in the cloud computing environment, and is mainly responsible for forwarding the data packets sent and received by the tenant to the correct destination address. For the tenant gateway with VPN (Virtual Private Network) service, in order to adapt to different service requirements, it is usually necessary to migrate the tenant gateway. Migrating the tenant gateway means migrating a tenant gateway of one mode to a tenant gateway of another mode. The network topology structure, network configuration, data packet flow direction, etc. of the tenant gateways of different modes are different.

[0003] The active-standby mode refers to a tenant gateway realized by two network elements, one of which is the master node responsible for sending and receiving data packets, and the other is the standby node which communicates with the external network through the VPN gateway. The cluster mode refers to a tenant gateway realized by at least two network elements, each of which can send and receive data packets. Since the number of network elements is large, the data packets of the external network need to pass through the flow guide gateway and the speed limit gateway first, and then be transmitted to the tenant gateway through the VPN gateway.

[0004] In the related art, when migrating the tenant gateway between the active-standby mode and the cluster mode, the configuration for forwarding the data packets of the external network needs to be updated on the flow guide gateway according to the mode of the migrated tenant gateway, and the port configuration needs to be updated on the host of the VPN gateway to adapt to the new data packet flow direction. However, there may be a delay in the effectiveness of the configuration, and when the data packet has reached the host of the VPN gateway, the data packet cannot find the destination port to forward out in the host due to the new port configuration not taking effect, resulting in the data packet being discarded and the VPN service being interrupted. SUMMARY

[0005] In view of the above problems, a tenant gateway migration method and device, electronic equipment and storage medium are provided to overcome the above problems or at least partially solve the above problems, comprising:

[0006] A tenant gateway migration method, the method comprising:

[0007] In response to a migration request of a tenant gateway, migrating an initial tenant gateway to a target tenant gateway; wherein the initial tenant gateway and the target tenant gateway both perform data transmission with a public network through a virtual private network gateway, and a host of the virtual private network gateway is further provided with a virtual switch;

[0008] In the process of migrating the initial tenant gateway to the target tenant gateway, according to the type of the target tenant gateway, a target ingress port and a target egress port of the host are determined; wherein the target ingress port is used to receive public network data or receive public network data forwarded by a flow guide gateway, and the target egress port is used to send public network data or the public network data forwarded by the flow guide gateway to the virtual private network gateway;

[0009] Configuration data associated with the virtual private network gateway is obtained;

[0010] According to the configuration data, port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch;

[0011] According to the type of the target tenant gateway and the configuration data, the configuration of the flow guide gateway forwarding public network data is updated, and in the virtual switch, the port configuration information corresponding to the initial tenant gateway is updated to the port configuration information corresponding to the target tenant gateway.

[0012] Optionally, the flow guide gateway is further communicatively connected with a flow limiting gateway, the flow limiting gateway is communicatively connected with the virtual private network gateway, and the flow limiting gateway is provided with a first port for receiving data sent by the virtual private network gateway. After the port configuration information corresponding to the initial tenant gateway is updated to the port configuration information corresponding to the target tenant gateway, the method further comprises:

[0013] Obtaining a public network gateway physical address corresponding to the virtual private network gateway, or obtaining a physical address of the first port;

[0014] According to the public network gateway physical address or the physical address of the first port, address resolution protocol information is sent to the virtual private network gateway.

[0015] Optionally, the determining the target ingress port and the target egress port of the host according to the type of the target tenant gateway comprises:

[0016] If the target tenant gateway receives public network data forwarded by the flow guide gateway through the virtual private network gateway, a target ingress port for receiving the public network data forwarded by the flow guide gateway and a target egress port for sending the public network data forwarded by the flow guide gateway to the virtual private network gateway are determined;

[0017] If the target tenant gateway receives public network data through the virtual private network gateway, a target ingress port for receiving the public network data and a target egress port for sending the public network data to the virtual private network gateway are determined.

[0018] Optionally, the configuration data comprises a public network IP address corresponding to the virtual private network gateway, a port name of the target ingress port, and a port name of the target egress port, and the adding of the port configuration information corresponding to the target ingress port and the target egress port in the virtual switch according to the configuration data comprises:

[0019] According to the public network IP address, the port name of the target ingress port, and the port name of the target egress port, the port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch.

[0020] Optionally, the updating of the configuration of the flow guide gateway forwarding public network data according to the type of the target tenant gateway comprises:

[0021] If the initial tenant gateway receives public network data through the virtual private network gateway, and the target tenant gateway receives the public network data forwarded by the flow guide gateway through the virtual private network gateway, a public network IP address corresponding to the virtual private network gateway is acquired.

[0022] According to the public network IP address, the configuration of the flow guide gateway forwarding public network data is updated.

[0023] Optionally, the updating of the configuration of the flow guide gateway forwarding public network data according to the type of the target tenant gateway further comprises:

[0024] If the target tenant gateway receives public network data through the virtual private network gateway, and the initial tenant gateway receives the public network data forwarded by the flow guide gateway through the virtual private network gateway, target forwarding configuration information of the public network IP address corresponding to the virtual private network gateway is determined in the flow guide gateway, and the target forwarding configuration information is deleted.

[0025] Optionally, the flow guide gateway and the rate limiting gateway are a cluster composed of multiple nodes.

[0026] A device for tenant gateway migration, the device comprising:

[0027] A migration module configured to, in response to a migration request of a tenant gateway, migrate an initial tenant gateway to a target tenant gateway, wherein the initial tenant gateway and the target tenant gateway both perform data transmission with a public network through a virtual private network gateway, and a host computer of the virtual private network gateway is further provided with a virtual switch.

[0028] a target port determination module, configured to determine a target ingress port and a target egress port of the host computer according to a type of the target tenant gateway in a process of migrating the initial tenant gateway to the target tenant gateway, wherein the target ingress port is configured to receive public network data or public network data forwarded by a flow guide gateway, and the target egress port is configured to send the public network data or the public network data forwarded by the flow guide gateway to the virtual private network gateway;

[0029] a configuration data acquisition module, configured to acquire configuration data associated with the virtual private network gateway;

[0030] a port configuration information addition module, configured to add port configuration information corresponding to the target ingress port and the target egress port in the virtual switch according to the configuration data;

[0031] a configuration update module, configured to update a configuration of the flow guide gateway forwarding public network data according to the type of the target tenant gateway and the configuration data, and update port configuration information corresponding to the initial tenant gateway to port configuration information corresponding to the target tenant gateway in the virtual switch.

[0032] An electronic device, comprising a processor, a memory, and a computer program stored on the memory and capable of running on the processor, wherein the computer program is executed by the processor to implement the method for tenant gateway migration.

[0033] A computer readable storage medium, wherein a computer program is stored on the computer readable storage medium, and the computer program is executed by a processor to implement the method for tenant gateway migration.

[0034] The embodiment of the present application has the following advantages: in the process of migrating the initial tenant gateway to the target tenant gateway, the target ingress port and the target egress port of the host computer are determined according to the type of the target tenant gateway, wherein the target ingress port is configured to receive public network data or public network data forwarded by a flow guide gateway, and the target egress port is configured to send the public network data or the public network data forwarded by the flow guide gateway to the virtual private network gateway, the configuration data associated with the virtual private network gateway is acquired, and the port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch according to the configuration data, so that the public network data transmitted under the target tenant gateway can find a corresponding transmission path in the virtual switch, thereby avoiding the public network data being discarded and causing the VPN service to be interrupted, and the stability of the VPN service is effectively improved. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the present application, the drawings needed to be used in the description of the present application will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and all other drawings obtained by those skilled in the art without creative labor on the basis of these drawings also belong to the protection scope of the present application.

[0036] Figure 1 Fig. 1 is a network topology diagram of a tenant gateway in a master-backup mode;

[0037] Figure 2 Fig. 2 is a network topology diagram of a tenant gateway in a cluster mode;

[0038] Figure 3 Fig. 3 is a schematic diagram of service flow interruption when migrating the tenant gateway in the master-backup mode to the cluster mode in the related art;

[0039] Figure 4 Fig. 4 is a schematic diagram of service flow interruption when migrating the tenant gateway in the cluster mode to the master-backup mode in the related art;

[0040] Figure 5 Fig. 5 is a step flow chart of a method for migrating a tenant gateway according to an embodiment of the present application;

[0041] Figure 6 Fig. 6 is a structural block diagram of an apparatus for migrating a tenant gateway according to an embodiment of the present application. DETAILED DESCRIPTION

[0042] In order to make the above-mentioned purposes, features and advantages of the present application more apparent and easy to understand, the present application will be further described in detail below with reference to the drawings and specific embodiments. Obviously, the described embodiments are some embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor also belong to the protection scope of the present application.

[0043] The following are explanations of some terms used in the embodiments of the present application:

[0044] Tenant: an entity such as a personal user or an enterprise that meets the needs of computing, storage, network, etc. by renting the resources of a cloud service provider.

[0045] VPC (Virtual Private Cloud): a virtual private cloud network, which is a network mode for isolating cloud hosts of different tenants on a public cloud from each other.

[0046] VPN(Virtual Private Network): A virtual private network that uses specific encryption methods to establish a stable tunnel between two networks for secure communication between the two networks.

[0047] Tenant Gateway: One of the basic network elements in a cloud computing network, which is the default gateway for tenants and is used to forward traffic to and from the tenant VPC, enabling interconnection between the tenant VPC and other networks.

[0048] VPN Gateway: One of the basic network elements in a cloud computing network, which is a gateway that implements VPN functions.

[0049] Rate Limiting Gateway: One of the basic network elements in a cloud computing network, which is connected to the tenant gateway and is used to implement bandwidth management and traffic rate limiting for tenants.

[0050] b-leaf(Border Leaf): A network design pattern used to build high-performance and highly available data center networks. b-leaf nodes are located at the edge of the data center and are responsible for connecting the internal network of the data center to external networks (such as public networks).

[0051] BGP(Border Gateway Protocol): A protocol used to exchange routing information in the Internet, responsible for transmitting routing information between different systems to ensure that data packets can reach the destination address from the source address.

[0052] Drain Gateway: One of the basic network elements in a cloud computing network, which is connected to the b-leaf node and is used to synchronize BGP routes with the b-leaf node to implement public network traffic drainage.

[0053] OVS(OpenvSwitch): A high-quality virtual switch that supports multi-layer data forwarding, mainly deployed on computer nodes to manage virtual machines on that computer node.

[0054] ARP(Address Resolution Protocol): A protocol used in computer networks to map network layer addresses (such as IP addresses) to data link layer addresses (such as MAC addresses).

[0055] VTEP IP(Virtual Tunnel Endpoint IP): The IP address of the virtual tunnel endpoint, used to establish a virtual network tunnel between different physical networks.

[0056] The technical problems existing in the related art will be described in detail below.

[0057] I. Master-slave mode

[0058] The tenant gateway is in a master-slave mode, and the tenant gateway is implemented by two network elements, one of which is a master node and the other is a standby node, to realize high availability in the form of master-slave, and the network topology is as shown in Figure 1 .

[0059] The data flow direction of the tenant gateway VPN service in the master-slave mode will be described below. Figure 1

[0060] As shown in Figure 1 , for the data packet of the VPN service out direction, that is, after the data packet is sent to the tenant gateway from the virtual machine (VM1, VM2, etc. in the VPC) in the virtual machine, since the tenant gateway is in a master-slave mode, only the master node can provide the data packet forwarding service. The master node of the tenant gateway queries the corresponding forwarding route according to the destination IP of the data packet, and forwards the data packet to the intranet port (eth1) on the VPN gateway. Figure 1

[0061] The VPN gateway is usually implemented in the form of a virtual gateway, that is, the VPN gateway is essentially a virtual machine, which exists on a physical machine (i.e. a host machine), and communicates with the outside world through the OVS of the physical machine.

[0062] The VPN gateway has at least two network ports, one of which is an intranet port (eth1) that communicates with the tenant gateway and is used to forward the intranet traffic in the cloud environment, and the other is an extranet port (eth2) that communicates with the b-leaf switch, and the VPN tunnel is established between the eth2 and the customer-side VPN gateway of the extranet, which is used to forward the extranet traffic connected with the cloud environment. Since the eth2 of the VPN gateway needs to communicate with the extranet (such as the public network), the eth2 has a floating IP that can be accessed by the extranet, which is referred to as the VPN extranet EIP. The OVS on the host machine where the VPN gateway is located has at least two ports related to the extranet, one of which is the port corresponding to the eth2 (the port named vhuxxxxxxxx-01 in Figure 1 ), and the other is the port connected with the B-leaf switch (the port named bond2.xxx in Figure 1 ).

[0063] ​​The inner network port of the VPN receives the data packet sent by the tenant gateway, encrypts the data packet using a specified VPN security protocol, and sends the data packet out from eth2. The encrypted data packet then reaches the vhuxxxxxxxx-01 port of the OVS, is forwarded according to the flow table forwarding rule in the OVS (a rule defining that data traffic enters from which port and exits from which port), reaches the bond2.xxx port of the OVS, and is sent to the b-leaf switch by the bond2.xxx port, and finally reaches the public network and reaches the VPN gateway on the customer side through the VPN tunnel.

[0064] Thus, the out-bound traffic path of the VPN service is completed. The in-bound traffic path of the VPN service is completely opposite to the out-bound traffic path, and will not be described herein again.

[0065] II. Cluster mode

[0066] When the tenant gateway is in the cluster mode, the tenant gateway is implemented by at least two network elements, and each network element is in an equal position, so that the number of nodes of the tenant gateway can be more conveniently horizontally expanded to meet higher service requirements, and the network topology structure is as shown in Figure 2 .

[0067] The data flow of the tenant gateway VPN service in the cluster mode will be described below. Figure 2

[0068] As shown in Figure 2 , for the data packet of the out-bound VPN service, the data packet is sent to the tenant gateway from the virtual machine (such as the virtual machines VM1, VM2, and the like) of the VPC. Since the tenant gateway is in the cluster mode, each tenant gateway node is in an equal position, so the data packet can be sent to any tenant gateway node. For example, when the data packet is forwarded to the tenant gateway node 1, the tenant gateway node 1 queries the corresponding forwarding route according to the destination IP of the data packet, and forwards the data packet to the inner network port (eth1) of the VPN gateway.

[0069] In the cluster mode, the VPN gateway also has an inner network port (eth1) and an outer network port (eth2). The eth1 receives the data packet sent by the tenant gateway, encrypts the data packet using a specified VPN security protocol, and sends the data packet out from the eth2. The encrypted data packet then reaches the vhuxxxxxxxx-01 port of the OVS, is forwarded according to the flow table forwarding rule in the OVS, reaches the vxlan1 port of the OVS, and is sent to the rate limiting gateway through the vxlan tunnel between the vxlan1 and the rate limiting gateway. The rate limiting gateway node receives the data packet sent by the VPN gateway, forwards the data packet to the b-leaf switch, and finally sends the data packet to the public network and reaches the VPN gateway on the customer side through the VPN tunnel.​

[0070] Thus, the out direction traffic path of the VPN service is completed.

[0071] For the data packet of the VPN service in the in direction, after reaching the b-leaf switch from the public network through the VPN tunnel, the b-leaf switch will forward the data packet to the flow guide gateway. The flow guide gateway and the b-leaf synchronize the routing data of all floating IPs in the environment through the bgp routing protocol, so that the flow guide gateway can provide the flow guide function of the floating IP. Among them, all floating IPs include VPN external network EIP.

[0072] After the flow guide gateway receives the data packet of the VPN service in the in direction, it sends the data packet to the rate limiting gateway for rate limiting processing, and the rate limiting gateway forwards the data packet to the vxlan1 port of the host machine where the VPN gateway is located through the vxlan tunnel.

[0073] After the vxlan1 port of the host machine where the VPN gateway is located receives the data packet, it sends the data packet to the vhuxxxxxxxx-01 port after OVS flow table rule processing, and the eth2 of the VPN gateway can receive the data packet.

[0074] The VPN gateway decrypts the data packet, and then sends the decrypted data packet to a tenant gateway node in the tenant gateway cluster through the eth1 port. Finally, the tenant gateway node sends the data packet to the corresponding virtual machine (e.g. VM1).

[0075] Thus, the in direction traffic path of the VPN service is completed.

[0076] III. Tenant migration

[0077] Because the external network traffic path of the VPN gateway is different in different tenant gateway modes, at least the following steps are included when migrating the tenant gateway: 1. updating the VPN external network EIP on the flow guide gateway; 2. replacing the external network OVS flow table of the VPN gateway.

[0078] Specifically, when migrating the tenant gateway from the master-backup mode to the cluster mode, the following steps are included:

[0079] 1. Update the VPN external network EIP on the flow guide gateway: publish the routing data of the VPN external network EIP to the flow guide gateway, and then the b-leaf will automatically learn the routing data of the VPN external network EIP through the bgp routing protocol, so that the b-leaf forwards the data packet with the VPN external network EIP as the destination address (i.e. in direction traffic) to the flow guide gateway.

[0080] 2. Replacement operation of the external network OVS flow table of the VPN gateway: update the OVS flow table rule on the physical machine where the VPN gateway is located, specifically:

[0081] update the out direction traffic path of the VPN external network EIP from "vhuxxxxxxxx-01 in, bond2.xxx out" to "vhuxxxxxxxx-01 in, vxlan1 out";

[0082] update the in direction traffic path of the VPN external network EIP from "bond2.xxx in, vhuxxxxxxxx-01 out" to "vxlan1 in, vhuxxxxxxxx-01 out";

[0083] adapt the network topology of the tenant gateway in the migrated cluster mode.

[0084] When migrating the tenant gateway from the cluster mode to the master-slave mode, the following steps are included:

[0085] 1. Update the VPN external network EIP on the flow guide gateway: cancel the publication and delete the route data of the VPN external network EIP on the flow guide gateway, and then the b-leaf will automatically delete the route data of the VPN external network EIP through the bgp routing protocol, so that the b-leaf will no longer forward the data packet (i.e. in direction traffic) whose destination address is the VPN external network EIP to the flow guide gateway, but directly to the host where the VPN gateway is located.

[0086] 2. Replacement operation of the external network OVS flow table of the VPN gateway: update the OVS flow table rule on the physical machine where the VPN gateway is located, specifically:

[0087] update the out direction traffic path of the VPN external network EIP from "vhuxxxxxxxx-01 in, vxlan1 out" to "vhuxxxxxxxx-01 in, bond2.xxx out";

[0088] update the in direction traffic path of the VPN external network EIP from "vxlan1 in, vhuxxxxxxxx-01 out" to "bond2.xxx in, vhuxxxxxxxx-01 out";

[0089] adapt the network topology of the tenant gateway in the migrated master-slave mode.

[0090] Four, technical problems existing in the related art

[0091] 1、In the process of migrating the tenant gateway from active-standby mode to cluster mode, there is a time difference between the two steps of "updating the VPN external network EIP on the lead gateway" and "replacing the external network OVS flow table of the VPN gateway". If the time difference is relatively long, the incoming direction traffic of the VPN service will enter the lead gateway, and when it reaches the host of the VPN gateway, the OVS flow table has not been replaced, causing the incoming direction traffic packets to be discarded, resulting in VPN service packet loss and flow interruption. Therefore, the customer VPN service will be interrupted during the gateway migration process, and the VPN service traffic will not be restored until the "replacement operation of the external network OVS flow table of the VPN gateway" is completed.

[0092] Specifically, referring to Figure 3 , which is a network topology diagram of VPN service traffic in the process of migrating the tenant gateway from active-standby mode to cluster mode.

[0093] As shown in Figure 3 , in the migration process, the step of "updating the VPN external network EIP on the lead gateway" has been completed, that is, the bgp route of the VPN external network EIP has been published on the lead gateway, so the b-leaf switch will automatically synchronize and learn the route of the EIP. Therefore, the data packets with the EIP as the destination IP (VPN service incoming direction traffic) from the b-leaf will be forwarded to the lead gateway, and then the lead gateway will forward the data packets to the rate limiting gateway, and then the rate limiting gateway will forward the data packets to the host of the VPN gateway.

[0094] The vxlan1 port on the OVS of the host of the VPN gateway will receive the data packets, but at this time the flow table related to the VPN external network EIP on the OVS has not been updated, so the data packets cannot be forwarded to vhuxxxxxxxx-01, resulting in packet loss and VPN service flow interruption, affecting the availability of customer service.

[0095] 2、In the process of migrating the tenant gateway from "cluster mode gateway" to "active-standby mode gateway", there is a time difference between the two steps of "updating the VPN external network EIP on the lead gateway" and "replacing the external network OVS flow table of the VPN gateway". If the time difference is relatively long, the incoming direction traffic of the VPN service will enter the b-leaf, and when it reaches the host of the VPN gateway, the OVS flow table has not been replaced, causing the incoming direction traffic packets to be discarded, resulting in VPN service packet loss and flow interruption. Therefore, the customer VPN service will be interrupted during the gateway migration process, and the VPN service traffic will not be restored until the "replacement operation of the external network OVS flow table of the VPN gateway" is completed.

[0096] Specifically, referring to Figure 4This is a network topology diagram of VPN service traffic during the migration of a tenant gateway from a "cluster mode gateway" to a "primary / backup mode gateway".

[0097] like Figure 4 As shown, the step of "updating the VPN external network EIP on the referral gateway" has been completed during the migration process. This means that the BGP route for the VPN external network EIP has been canceled and deleted on the referral gateway. As a result, the route for this EIP will also be automatically deleted on the b-leaf switch. Therefore, data packets (VPN service inbound traffic) with the destination IP of this EIP coming from the b-leaf switch will no longer be forwarded to the referral gateway, but will be forwarded directly to the host machine where the VPN gateway is located.

[0098] At this time, bond2.xxx on the OVS of the host machine where the VPN gateway is located will receive the data packet. However, the flow table related to the VPN external network EIP on the OVS has not been updated yet, which makes it impossible for the data packet to be forwarded to vhuxxxxxxxx-01, resulting in packet loss, VPN service interruption, and affecting the availability of customer services.

[0099] 3. Regardless of whether the tenant gateway is migrated from primary / standby mode to cluster mode, or vice versa, the external next hop of the VPN gateway's external EIP will change:

[0100] In a network topology of "tenant gateway in primary / backup mode", the next hop of the VPN external network EIP is the MAC address (physical address) of the external network gateway on the b-leaf.

[0101] In the network topology of "tenant gateway in cluster mode", the next hop of the VPN external network EIP is the MAC address of the network port on the rate limiting gateway used to receive traffic sent from the VPN gateway.

[0102] Therefore, when migrating a tenant gateway, the default gateway MAC address of the external interface in the VPN gateway needs to be changed, which means the corresponding ARP configuration needs to be changed. However, the ARP configuration in the operating system has a cache expiration time. If the corresponding ARP configuration in the VPN gateway is not updated in time after the migration, the outbound traffic path will be blocked, resulting in packet loss, VPN service interruption, and affecting the availability of customer services. Service can only be restored after the ARP cache in the VPN gateway expires and the ARP is relearned.

[0103] The embodiments of the present invention will be described in detail below.

[0104] Reference Figure 5 The diagram illustrates a flowchart of a tenant gateway migration method according to an embodiment of the present invention, which may specifically include the following steps:

[0105] Step 501, in response to the migration request of the tenant gateway, migrating the initial tenant gateway to the target tenant gateway; wherein the initial tenant gateway and the target tenant gateway both transmit data with the public network through a virtual private network gateway, and a host of the virtual private network gateway is further provided with a virtual switch;

[0106] In step 501, the initial tenant gateway is the tenant gateway to be migrated, and the target tenant gateway is the tenant gateway after migration.

[0107] The initial tenant gateway and the target tenant gateway both have VPN services, transmit data with the public network through a virtual private network gateway (VPN gateway), and the host of the VPN gateway is further provided with a virtual switch. The virtual switch is used to forward the data packets received by the host to the VPN gateway, for example, an OSV virtual switch.

[0108] In some examples, the initial tenant gateway can be a tenant gateway in a master-backup mode, and the target tenant gateway can be a tenant gateway in a cluster mode; or the initial tenant gateway can be a tenant gateway in a cluster mode, and the target tenant gateway can be a tenant gateway in a master-backup mode.

[0109] Step 502, in the process of migrating the initial tenant gateway to the target tenant gateway, determining a target ingress port and a target egress port of the host according to the type of the target tenant gateway; wherein the target ingress port is used to receive public network data or receive public network data forwarded by a flow guide gateway, and the target egress port is used to send public network data or public network data forwarded by the flow guide gateway to the virtual private network gateway;

[0110] In step 502, after migrating the initial tenant gateway to the target tenant gateway, the network topology structure of different types of target tenant gateways will also change, resulting in a change in the transmission path of public network data. Therefore, according to the type of the target tenant gateway, the target ingress port and the target egress port in the host are determined, so that the public network data arriving at the host under different types of target tenant gateways can find the path corresponding to the target tenant gateway after migration in the host, and then the data is normally forwarded to the VPN gateway.

[0111] In some embodiments of the present application, the determination of the target ingress port and the target egress port of the host according to the type of the target tenant gateway comprises:

[0112] If the target tenant gateway receives public network data forwarded by the flow guide gateway through the virtual private network gateway, the target ingress port for receiving public network data forwarded by the flow guide gateway and the target egress port for sending public network data forwarded by the flow guide gateway to the virtual private network gateway are determined.

[0113] If the target tenant gateway receives public network data through the virtual private network gateway, a target ingress port for receiving the public network data is determined, and a target egress port for sending the public network data to the virtual private network gateway is determined.

[0114] In some examples, the target tenant gateway can be a cluster mode tenant gateway. In the inflow direction of the VPN service data, the public network data first passes through the forwarding of the flow guide gateway, then reaches the host of the VPN gateway, and then passes through the scheduling of the OSV flow table rule in the virtual switch in the host and is forwarded to the VPN gateway. Therefore, a target ingress port of the host for receiving the public network data forwarded by the flow guide gateway and a target egress port for sending the public network data forwarded by the flow guide gateway to the virtual private network gateway need to be determined, so that the public network data has a clear forwarding path in the virtual switch.

[0115] The target tenant gateway can also be a master-backup mode tenant gateway. In the inflow direction of the VPN service data, the host where the VPN gateway is located directly receives the public network data, and then passes through the scheduling of the OSV flow table rule in the virtual switch in the host and forwards the public network data to the VPN gateway. Therefore, a target ingress port of the host for receiving the public network data and a target egress port for sending the public network data to the virtual private network gateway need to be determined, so that the public network data has a clear forwarding path in the virtual switch.

[0116] In step 503, configuration data associated with the virtual private network gateway is obtained.

[0117] In step 503, the configuration data is associated with the virtual private network gateway, that is, the network configuration data related to the VPN service, such as IP address, physical address, port name, and other types of network configuration data.

[0118] In some examples, the configuration data associated with the virtual private network gateway can include the following:

[0119] The public IP address of the VPN gateway is denoted as VPN_EXT_EIP, that is, the IP address of the external network port (such as eth2)

[0120] The physical address of the external network port of the VPN gateway is denoted as VPN_EXT_MAC.

[0121] The external network port of the VPN gateway corresponds to a port name on the OVS of the host computer where the VPN gateway is located, and is denoted as VPN_EXT_PORT. Since the VPN gateway is essentially a virtual machine, it is managed by a virtual switch on the host computer, and all network ports of the virtual machine managed by the virtual switch have a corresponding port. For example, the eth1 port and the eth2 port described above both have a corresponding port on the OVS, and the port name of the corresponding port of the eth2 port on the OVS is vhuxxxxxxxx-01.

[0122] In step 504, port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch according to the configuration data.

[0123] In step 504, the specific information of the target ingress port and the target egress port can be determined from the configuration data, such as the port number, the port name, the public IP address of the VPN, and the like, and then the port configuration information is added through the specific information.

[0124] When the port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch, the public network data has a clear forwarding path when it reaches the virtual switch under the network topology structure of the target tenant gateway.

[0125] In some embodiments of the present application, the configuration data includes the public IP address corresponding to the virtual private network gateway, the port name of the target ingress port, and the port name of the target egress port, and step 504 includes:

[0126] According to the public IP address, the port name of the target ingress port, and the port name of the target egress port, port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch.

[0127] In some examples, the port configuration information corresponding to the target ingress port and the target egress port can be added by issuing an OSV flow table under the host computer of the VPN gateway.

[0128] Specifically, the initial tenant gateway can be a tenant gateway in a master-slave mode, and the target tenant gateway can be a tenant gateway in a cluster mode; or the initial tenant gateway can be a tenant gateway in a cluster mode, and the target tenant gateway can be a tenant gateway in a master-slave mode.

[0129] The network topology structure of the tenant gateway in the master-slave mode is as shown in Figure 1 The network topology structure of the target tenant gateway is as shown in Figure 2

[0130] ​In the two modes of tenant gateway, there are at least two network ports on the VPN gateway, one of which is used for communication with the tenant gateway in the cloud environment, that is, the intranet port (eth1), and the other is used for communication with the public network, that is, the extranet port (eth2). The IP address on eth2 is the public IP address, for example, 100.126.16.16 (24-bit subnet mask), which is accessible by the public network.

[0131] When the target tenant gateway is a master-slave mode tenant gateway and the initial tenant gateway is a cluster mode tenant gateway, as shown in Figure 1 The bond2.xxx port on the OSV of the target tenant gateway is the target entry port for receiving public network data, and the vhuxxxxxxxx-01 is the target exit port for forwarding public network data to the VPN gateway. Then the port configuration information is added, that is, the new OSV flow table TB1 is issued as follows: 1.

[0133] table=20,priority=200,ip,in_port=bond2.xxx,nw_dst=100.126.16.16actions=NORMAL 2.

[0135] table=20,priority=200,arp,in_port=bond2.xxx,arp_tpa=100.126.16.16actions=NORMAL

[0136] In this OSV flow table, the item before actions is the matching condition of the data packet. ip indicates that the protocol of the data packet is ip protocol; arp indicates that the data packet is an arp protocol; in_port=bond2.xxx indicates that the data packet enters the host from the bond2.xxx port, for example, bond2.xxx can be bond2.100, bond2.200, etc. The specific port name. The bond2.xxx of the host is connected with the b-leaf switch. nw_dst=100.126.16.16 indicates that the destination IP of the data packet is 100.126.16.16 (i.e. the public IP address of the VPN gateway). arp_tpa=100.126.16.16 indicates that the target IP of the ARP request is 100.126.16.16. actions=NORMAL indicates that the data packet is forwarded according to the default mode of the switch.

[0137] For the original tenant gateway (i.e. the tenant gateway in cluster mode), the data packet from the limited rate gateway to the VPN gateway in the original network topology is first sent to the vxlan1 port of the OVS of the host machine, instead of the bond2.xxx port, so the data packet from the limited rate gateway still matches the original OVS flow table and does not match the flow table TB1, and the original VPN service traffic is not affected

[0138] In this way, by issuing the above OVS flow table, if a data packet comes from the bond2.xxx and matches the above rule, the OVS will forward the data packet in the default manner of the switch, and the external network port of the VPN gateway can receive the data packet.

[0139] When the target tenant gateway is a tenant gateway in cluster mode and the initial tenant gateway is a tenant gateway in active-standby mode, as shown in FIG. 6, the vxlan1 port on the OVS of the target tenant gateway is the target ingress port, the public network data is forwarded through the flow guide gateway and then through the limited rate gateway, and then enters the vxlan1; the vhuxxxxxxxx-01 port on the OVS is the target egress port, and the public network data is forwarded through the vhuxxxxxxxx-01 to the VPN gateway, so the added port configuration information, i.e. the new OVS flow table TB2, is as follows: Figure 2 1.

[0141] table=20,priority=200,ip,in_port=vxlan1,nw_dst=100.126.16.16actions=set_field:fa:00:00:00:00:01->eth_dst,output:"vhuxxxxxxxx-01" 2.

[0143] table=20,priority=200,arp,in_port=vxlan1,nw_dst=100.126.16.16actions=set_field:fa:00:00:00:00:01->eth_dst,output:"vhuxxxxxxxx-01"

[0144] ​In the OSV flow table, the item before actions is the matching condition of the data packet. ip indicates that the protocol of the data packet is an ip protocol; arp indicates that the data packet is an arp protocol; in_port=vxlan1 indicates that the data packet is from the vxlan1 port of the host computer (the host computer communicates with other network elements outside the world through a VXLAN tunnel, and the vxlan1 port is the port of the host computer for receiving the data packet coming in through the VXLAN tunnel).

[0145] nw_dst=100.126.16.16 indicates that the destination IP of the data packet is 100.126.16.16. actions=set_field:fa:00:00:00:00:01->eth_dst,output:"vhuxxxxxxxx-01" indicates that if the data packet matching the above three conditions is found, the destination MAC address of the data packet is changed to fa:00:00:00:00:01 (that is, to VPN_EXT_MAC), and the data packet is sent to the vhuxxxxxxxx-01 port. The vhuxxxxxxxx-01 port corresponds to the eth2 port of the VPN gateway, so the external network port of the VPN gateway can receive the data packet.

[0146] For the network topology structure of the initial tenant gateway (that is, the tenant gateway in the primary-backup mode), the data packet entering the VPN gateway from the external network is from the b-leaf switch, and the data packet from the b-leaf switch enters the host computer OVS through the bond2.xxx port, not the vxlan1 port. Therefore, the data packet from the b-leaf switch still matches the original OVS flow table and does not match the above flow table TB2, and does not affect the original VPN service traffic.

[0147] In some examples, when the flow table TB2 is issued to the OVS of the host computer where the VPN gateway is located, a flow table TB3 as follows can also be issued:

[0148] table=20, priority=200, arp, in_port=vhuxxxxxxxx-01, arp_op=2 actions=NORMAL

[0149] In the flow table TB3, in_port=vhuxxxxxxxx-01 indicates that the matching data packet is from the eth2 port of the VPN gateway, and arp_op=2 indicates that the matching data packet is an ARP response message. Using this flow table indicates that if the ARP response message from the eth2 port of the VPN gateway is matched, the OVS will forward it in the default switch mode.

[0150] The usage scenario of the flow table is as follows: in some business scenarios, the eth2 port of the VPN gateway needs to communicate with other network element nodes in the same network segment, and then the eth2 port of the VPN gateway needs to reply to the ARP response message. The flow table is used to pass such messages, so that the eth2 port of the VPN gateway can normally communicate with other network element nodes in the same network segment.

[0151] In step 505, according to the type of the target tenant gateway and the configuration data, the configuration of the flow gateway forwarding public network data is updated, and the port configuration information corresponding to the initial tenant gateway in the virtual switch is updated to the port configuration information corresponding to the target tenant gateway.

[0152] In step 505, the configuration of the flow gateway forwarding public network data needs to be updated to adapt to the network topology structure of the target tenant gateway, for example, the flow gateway forwarding public network data is set or canceled, at this time, the public network data is transmitted according to the transmission path of the network topology structure of the target tenant gateway.

[0153] At this time, since the port configuration information corresponding to the target ingress port and the target egress port has been added in the virtual switch in step 504, whether the public network data is received directly through the host or received after being forwarded by the flow gateway, a corresponding path can be found in the virtual switch, that is, entering from the target ingress port and exiting from the target egress port to the virtual private network gateway, without causing data loss.

[0154] Then, in the virtual switch, the port configuration information corresponding to the initial tenant gateway is updated to the port configuration information corresponding to the target tenant gateway, so that the data flow direction adapts to the network topology structure of the target tenant gateway. For example, the data flow direction in the VPN service egress direction is updated from the data flow direction corresponding to the network topology structure of the initial tenant gateway to the data flow direction corresponding to the network topology structure of the target tenant gateway.

[0155] In some embodiments of the present application, the updating of the configuration of the flow gateway forwarding public network data according to the type of the target tenant gateway comprises:

[0156] If the initial tenant gateway receives public network data through the virtual private network gateway, and the target tenant gateway receives the public network data forwarded by the flow gateway through the virtual private network gateway, the public network IP address corresponding to the virtual private network gateway is obtained.

[0157] According to the public network IP address, the configuration of the flow gateway forwarding public network data is updated.

[0158] In some examples, for the case that the initial tenant gateway is in active-standby mode and the target tenant gateway is in cluster mode, since the cluster mode requires the flow guide gateway to forward public network data, the configuration of the flow guide gateway forwarding public network data needs to be updated according to the public IP address corresponding to the virtual private network gateway, so that the flow guide gateway forwards the data packet with the public IP address as the destination address.

[0159] Specifically, the route of the public IP address can be published on the flow guide gateway. Since the BGP synchronization is started between the flow guide gateway and the b-leaf switch, after the route of the public IP address is published on the flow guide gateway, the b-leaf switch will also synchronize the route through BGP. After the b-leaf switch has the route of the public IP address, when the b-leaf receives a data packet and the destination IP of the data packet is the public IP address, the b-leaf switch will forward the data packet to the flow guide gateway through the route. Subsequently, the flow guide gateway forwards the data packet to the rate limiting gateway, and then the rate limiting gateway forwards the data packet to the vxlan1 port of the VPN gateway through the VXLAN tunnel, that is, the new network topology is used for the ingress direction traffic path of the VPN service.

[0160] When the new route is published on the flow guide gateway, the egress direction traffic of the VPN gateway is from the VPN gateway to the b-leaf node, and the ingress direction traffic is from the rate limiting gateway to the VPN gateway.

[0161] At this time, since the new flow table has been issued on the OVS in the previous step, for example, the above-mentioned flow table TB2, the path of the public network data in the virtual switch is from the target ingress port to the target egress port, for example, the data with the public IP address as the target address in the above-mentioned flow table TB2 is from the vxlan1 port to the vhuxxxxxxxx-01 port, therefore, after the host receives the data packet of the ingress direction traffic of the above-mentioned VPN service on the target ingress port, the data packet can be matched to the above-mentioned new flow table, so the data packet will not be discarded, but will be sent to the VPN gateway through the target egress port by using the new flow table rule, and then sent to the external network port (for example, the eth2 port) of the VPN gateway, thereby ensuring the continuous flow of the VPN service.

[0162] In actual application, after the new route is published on the flow guide gateway, the OVS flow table related to the VPN external network port can be added to adapt to the network topology structure of the target tenant gateway, and the OVS flow table related to the VPN external network port of the initial tenant gateway can be deleted, so as to update the port configuration information corresponding to the initial tenant gateway in the virtual switch to the port configuration information corresponding to the target tenant gateway.

[0163] Specifically, after publishing the new route on the drain gateway, all the inbound traffic of the VPN service will go through the new network topology path, that is, from the b-leaf to the drain gateway, the rate limiting gateway, and then to the VPN gateway, instead of being directly forwarded from the b-leaf to the VPN gateway. Also, the outbound traffic of the VPN service should go through the new network topology path. Therefore, at this time, the new flow table for the public IP address of the VPN gateway can be issued on the host where the VPN gateway is located to adapt to the new network topology, and the original flow table for the public IP address can be deleted on the host where the VPN gateway is located. Generally, the matching items of the new and old flow tables are different and do not conflict with each other, so the new flow table can be added first and then the old flow table is deleted, so as to ensure that the VPN service traffic will not be interrupted. In specific practice, the flow table adapting to the new network topology can be designed according to the specific service model of the cloud environment.

[0164] In some embodiments of the application, the updating of the configuration of the drain gateway for forwarding public network data according to the type of the target tenant gateway further comprises:

[0165] If the target tenant gateway receives public network data through the virtual private network gateway, and the initial tenant gateway receives the public network data forwarded by the drain gateway through the virtual private network gateway, the target forwarding configuration information of the public network IP address corresponding to the virtual private network gateway is determined in the drain gateway, and the target forwarding configuration information is deleted.

[0166] In some examples, for the case that the initial tenant gateway is in a cluster mode and the target tenant gateway is in a master-slave mode, since the master-slave mode does not need the drain gateway to forward public network data, but directly receives public network data, the configuration of the drain gateway for forwarding public network data needs to be updated according to the public network IP address corresponding to the virtual private network gateway, so that the drain gateway cancels the forwarding of the data packet with the destination address being the public network IP address.

[0167] Specifically, the route for the public network IP address can be deleted on the drain gateway. Since the BGP synchronization is started between the drain gateway and the b-leaf switch, after the route for the public network IP address is deleted on the drain gateway, the route will also be deleted on the b-leaf switch through the BGP synchronization. After that, when the b-leaf receives a data packet and the destination IP of the data packet is the public network IP address of the VPN gateway, since there is no corresponding route, the b-leaf will use the new network topology to directly forward the data packet to the target ingress port of the host where the VPN gateway is located.

[0168] After the route for the public network IP address is deleted on the drain gateway, the data of the VPN gateway goes in the outbound direction from the VPN gateway to the rate limiting gateway, and in the inbound direction from the b-leaf node to the VPN gateway.

[0169] At this time, since the new OSV flow table (for example, the flow table TB1 described above) has been issued in the above step, that is, the path of public network data in the virtual switch is from the target ingress port to the target egress port (for example, the data with the public network IP address as the target address in the flow table TB1 described above is from the bond2.xxx port to the vhuxxxxxxxx-01 port), therefore, after the host receives the data packet of the ingress direction flow of the VPN service, the data packet can be matched to the newly added flow table, and the data packet will not be discarded, but will be sent to the external network port (for example, eth2) of the VPN gateway through the target egress port by using the newly added flow table rule, thereby ensuring the continuous flow of the VPN service.

[0170] In actual application, after the route for the public network IP address is deleted on the flow guide gateway, the OVS flow table related to the VPN external network port can be added to adapt to the network topology structure of the target tenant gateway, and the OVS flow table related to the VPN external network port of the initial tenant gateway can be deleted to update the port configuration information corresponding to the initial tenant gateway in the virtual switch to the port configuration information corresponding to the target tenant gateway.

[0171] Specifically, after the route for the public network IP address is deleted on the flow guide gateway, the ingress direction flow of all VPN services will go through the new network topology path, that is, directly forwarded from the b-leaf to the VPN gateway, and will not go through the b-leaf to the flow guide gateway, the rate limiting gateway, and then to the VPN gateway. The egress direction flow of the VPN service should also go through the new network topology path. Therefore, at this time, the new flow table for the public network IP address of the VPN gateway can be issued on the host where the VPN gateway is located to adapt to the new network topology, and the original flow table for the public network IP address can be deleted on the host where the VPN gateway is located. Generally, the matching items of the new and old flow tables are different and do not conflict with each other, so the new flow table can be added first and then the old flow table can be deleted, thereby ensuring that the VPN service flow will not be interrupted. Here, the flow table adapting to the new network topology can be designed according to the service model of the specific cloud environment.

[0172] In some embodiments of the present application, the flow guide gateway is further in communication connection with a flow limiting gateway, the flow limiting gateway is in communication connection with the virtual private network gateway, and the flow limiting gateway is provided with a first port for receiving the data sent by the virtual private network gateway. After the port configuration information corresponding to the initial tenant gateway is updated to the port configuration information corresponding to the target tenant gateway, the method further comprises:

[0173] Obtaining the public network gateway physical address corresponding to the virtual private network gateway, or obtaining the physical address of the first port;

[0174] According to the public network gateway physical address or the physical address of the first port, address resolution protocol information is sent to the virtual private network gateway.

[0175] The first port of the traffic limiting gateway is recorded as SGW_MAC, and is used to receive data sent by the virtual private network gateway. As an example, as shown in the following table, the bond-LAN is the first port, and the physical address of the first port is the MAC address of the bond-LAN. For example, fe:00:00:00:00:02. Figure 2

[0176] The public network gateway physical address corresponding to the virtual private network gateway is the physical address corresponding to the public network gateway IP address, and is recorded as VPN_EXT_EIP_GW_MAC. For example, aa:aa:aa:aa:aa:aa.

[0177] The public network gateway IP address is recorded as VPN_EXT_EIP_GW. Since the public IP address of the VPN gateway is accessible to the public network, it needs to communicate with the public network, and therefore has its own public network gateway IP address, that is, it needs to communicate with the public network through the public network gateway IP address. Generally, the public network gateway IP address is an IP address in the same network segment as the public IP address. For example, if the public IP address is 100.126.16.16, the public network gateway IP address is 100.126.16.254 (24-bit subnet mask).

[0178] Specifically, the physical address of the first port and the public network gateway physical address corresponding to the virtual private network gateway can be obtained from configuration data associated with the virtual private network gateway.

[0179] In this embodiment, since the default gateway of the external network port in the VPN gateway needs to be changed during tenant migration, the physical address of the default gateway also needs to be changed, that is, the corresponding ARP configuration needs to be changed. The ARP configuration in the operating system has a cache time limit. If the corresponding ARP in the VPN gateway is not updated in time after migration, the outbound traffic path will not be available, resulting in packet loss, VPN service interruption, and affecting the availability of customer services. Therefore, according to the public network gateway physical address or the physical address of the first port, address resolution protocol information is sent to the virtual private network gateway to update the physical address of the default gateway of the external network port.

[0180] In some examples, for a tenant gateway whose initial tenant gateway is in a primary-backup mode and whose target tenant gateway is in a cluster mode, the default gateway of the VPN external network port is usually the public network gateway IP address (VPN_EXT_EIP_GW). Before migration, there is an ARP entry in the VPN gateway for the public network gateway IP address, for example: ​

[0181] 100.126.16.254 aa:aa:aa:aa:aa:aa

[0182] The above ARP entry has a certain timeliness in the system, and under normal circumstances, the ARP needs to be relearned and updated after the ARP cache in the system expires.

[0183] After migration, the VPN service needs to go through the new network topology. For the VPN external network port, the next hop of the outbound traffic needs to change from b-leaf to the rate-limiting gateway, and therefore the physical address of the next hop of the outbound traffic needs to be updated from the public network gateway physical address (VPN_EXT_EIP_GW_MAC) to the physical address of the first port (SGW_MAC).

[0184] Therefore, at this time, an address resolution protocol information (ARP message) can be sent to the VPN gateway, in which the IP address of the default gateway is the public network gateway IP address (VPN_EXT_EIP_GW), and the physical address is the physical address of the first port (SGW_MAC), so that the above ARP entry in the VPN gateway is changed to:

[0185] 100.126.16.254 fe:00:00:00:00:02

[0186] By sending the above gratuitous ARP message to the VPN gateway, the old ARP entry in the VPN gateway can be avoided from being updated for a long time, and the corresponding ARP entry can be refreshed in time, so as to ensure the normal delivery of the outbound traffic of the VPN service and the stability of the customer VPN service.

[0187] In actual application, the ARP message can be free information, that is, the information fee of the tenant is exempted.

[0188] In some examples, for the case that the initial tenant gateway is a cluster mode tenant gateway and the target tenant gateway is a motherboard mode tenant gateway, the default gateway of the external network port of the VPN gateway is the public network gateway IP address (VPN_EXT_EIP_GW), and before migration, there is an ARP entry in the VPN gateway for the public network gateway IP address, for example:

[0189] 100.126.16.254 aa:aa:aa:aa:aa:aa

[0190] The above ARP entry has a certain timeliness in the system, and under normal circumstances, the ARP needs to be relearned and updated after the ARP cache in the system expires.

[0191] After migration, the VPN service needs to go through a new network topology. For the VPN external interface, the next hop of the out direction traffic needs to change from the rate limiting gateway to the b-leaf switch, and thus the MAC address of the next hop of the out direction needs to be updated from the physical address of the first port (SGW_MAC) to the physical address of the public gateway (VPN_EXT_EIP_GW).

[0192] Therefore, an address resolution protocol message (ARP message) can be sent to the VPN gateway at this time, in which the IP address of the default gateway is the public gateway IP address (VPN_EXT_EIP_GW), and the physical address is the public gateway physical address (VPN_EXT_EIP_GW_MAC), so that the above ARP table entry in the VPN gateway is changed to:

[0193] 100.126.16.254 aa:aa:aa:aa:aa:aa

[0194] By sending the above free ARP message to the VPN gateway, the old ARP table entry in the VPN gateway can be avoided to be updated for a long time, and the corresponding ARP table entry can be refreshed in time, so as to ensure the normal delivery of the out direction traffic of the VPN service and the stability of the customer VPN service.

[0195] In actual application, after sending the address resolution protocol message to the virtual private network gateway, other steps of migrating the tenant gateway can also be performed, for example, updating the configuration data of other services of the tenant on the related network element, such as updating the Vtep IP address on the cloud private line switch, updating the service flow table corresponding to the virtual machine in the VPC, and the like, until the migration from the initial tenant gateway to the target tenant gateway is completed.

[0196] In some embodiments of the present application, the flow guide gateway and the rate limiting gateway are clusters composed of multiple nodes.

[0197] In the present example, the rate limiting gateway and the flow guide gateway are both implemented in the form of a cluster. For example, the rate limiting gateway and the flow guide gateway each use at least two servers to form a cluster, so as to improve the redundancy of the rate limiting gateway and the flow guide gateway, and thus improve the availability and reliability of the rate limiting gateway and the flow guide gateway.

[0198] The embodiment of the present application has the following advantages: in the process of migrating the initial tenant gateway to the target tenant gateway, the target ingress port and the target egress port of the host are determined according to the type of the target tenant gateway, wherein the target ingress port is used to receive public network data or receive public network data forwarded by a flow guide gateway, the target egress port is used to send public network data or public network data forwarded by the flow guide gateway to a virtual private network gateway, configuration data associated with the virtual private network gateway is obtained, and port configuration information corresponding to the target ingress port and the target egress port is added in the virtual switch according to the configuration data, so that public network data transmitted under the target tenant gateway can find a corresponding transmission path in the virtual switch, thereby avoiding discarding of the public network data and causing VPN service flow interruption, and effectively improving the stability of the VPN service.

[0199] It should be noted that, for the method embodiments, in order to simply describe, they are all described as a series of action combinations, but those skilled in the art should know that the embodiment of the present application is not limited to the order of the actions described, because according to the embodiment of the present application, some steps can be performed in other order or at the same time. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily required by the embodiment of the present application.

[0200] Referring to Figure 6 , a structure schematic diagram of a device for tenant gateway migration provided by an embodiment of the present application is shown, and specifically can include the following modules:

[0201] The migration module 601 is configured to migrate the initial tenant gateway to the target tenant gateway in response to a migration request of the tenant gateway, wherein the initial tenant gateway and the target tenant gateway both perform data transmission with a public network through a virtual private network gateway, and a host of the virtual private network gateway is further provided with a virtual switch;

[0202] The target port determination module 602 is configured to determine a target ingress port and a target egress port of the host according to the type of the target tenant gateway in the process of migrating the initial tenant gateway to the target tenant gateway, wherein the target ingress port is used to receive public network data or receive public network data forwarded by a flow guide gateway, and the target egress port is used to send public network data or public network data forwarded by the flow guide gateway to the virtual private network gateway;

[0203] The configuration data acquisition module 603 is configured to acquire configuration data associated with the virtual private network gateway;

[0204] The port configuration information addition module 604 is configured to add port configuration information corresponding to the target ingress port and the target egress port in the virtual switch according to the configuration data.​

[0205] The configuration updating module 605 is configured to update the configuration of the lead-through gateway forwarding public network data according to the type of the target tenant gateway and the configuration data, and update the port configuration information corresponding to the initial tenant gateway to the port configuration information corresponding to the target tenant gateway in the virtual switch.

[0206] In some embodiments of the present application, the lead-through gateway is further connected with a flow-limiting gateway, the flow-limiting gateway is connected with the virtual private network gateway, and the flow-limiting gateway is provided with a first port for receiving data sent by the virtual private network gateway. After the port configuration information corresponding to the initial tenant gateway is updated to the port configuration information corresponding to the target tenant gateway, the device further comprises:

[0207] The physical address obtaining module is configured to obtain the physical address of the public network gateway corresponding to the virtual private network gateway, or obtain the physical address of the first port.

[0208] The address resolution protocol information sending module is configured to send address resolution protocol information to the virtual private network gateway according to the physical address of the public network gateway or the physical address of the first port.

[0209] In some embodiments of the present application, the target port determining module 602 comprises:

[0210] The first target port determining submodule is configured to determine a target ingress port for receiving public network data forwarded by the lead-through gateway and a target egress port for sending public network data forwarded by the lead-through gateway to the virtual private network gateway if the target tenant gateway receives the public network data forwarded by the lead-through gateway through the virtual private network gateway.

[0211] The second target port determining submodule is configured to determine a target ingress port for receiving public network data and a target egress port for sending public network data to the virtual private network gateway if the target tenant gateway receives the public network data through the virtual private network gateway.

[0212] In some embodiments of the present application, the configuration data comprises a public network IP address corresponding to the virtual private network gateway, a port name of the target ingress port, and a port name of the target egress port, and the port configuration information adding module 604 comprises:

[0213] The port configuration information adding submodule is configured to add port configuration information corresponding to the target ingress port and the target egress port in the virtual switch according to the public network IP address, the port name of the target ingress port, and the port name of the target egress port.

[0214] In some embodiments of the present application, the configuration updating module 605 comprises:

[0215] a first configuration updating submodule, configured to, if the initial tenant gateway receives public network data through the virtual private network gateway and the target tenant gateway receives the public network data forwarded by the flow guide gateway through the virtual private network gateway, acquire a public IP address corresponding to the virtual private network gateway;

[0216] update, according to the public IP address, the configuration of the flow guide gateway forwarding public network data

[0217] In some embodiments of the present application, the configuration updating module 605 further comprises:

[0218] a second configuration updating submodule, configured to, if the target tenant gateway receives public network data through the virtual private network gateway and the initial tenant gateway receives the public network data forwarded by the flow guide gateway through the virtual private network gateway, determine, in the flow guide gateway, target forwarding configuration information of the public IP address corresponding to the virtual private network gateway, and delete the target forwarding configuration information.

[0219] In some embodiments of the present application, the flow guide gateway and the rate limiting gateway are clusters composed of multiple nodes.

[0220] Some embodiments of the present application further provide an electronic device, which can comprise a processor, a memory, and a computer program stored on the memory and capable of running on the processor, and the computer program is executed by the processor to implement the method for tenant gateway migration as described above.

[0221] Some embodiments of the present application further provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the method for tenant gateway migration as described above.

[0222] Some embodiments of the present application further provide a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the method for tenant gateway migration as described above.

[0223] For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the related parts refer to the parts of the method embodiments.

[0224] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of countries and regions, and provide corresponding operation portal for user to choose authorization or refusal.

[0225] Each of the embodiments in the present specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments, and the same and similar parts between the embodiments can be referred to each other.

[0226] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, device or computer program product. Therefore, the embodiments of the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0227] The embodiments of the present application are described with reference to flowcharts and / or block diagrams according to the method, terminal device (system) and computer program product of the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of the flows and / or blocks in the flowchart and / or block diagram can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device realize the functions specified in the flowchart and / or block diagram. Figure 1 The functions specified in one flow or multiple flows and / or blocks Figure 1 The functions specified in one flow or multiple flows and / or blocks

[0228] These computer program instructions can also be stored in a computer readable storage medium that can guide the computer or other programmable data processing terminal device to work in a specific way, so that the instructions stored in the computer readable storage medium produce a product including instruction devices, which realize the functions specified in the flowchart and / or block diagram. Figure 1 The functions specified in one flow or multiple flows and / or blocks Figure 1 The functions specified in one flow or multiple flows and / or blocks

[0229] These computer program instructions can also be loaded into a computer or other programmable data processing terminal device, so that a series of operational steps are performed on the computer or other programmable terminal device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable terminal device provide a process for implementing the functions specified in the flowchart Figure 1 one flow or a plurality of flows and / or the functions specified in the block Figure 1 one block or a plurality of blocks.

[0230] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic inventive concept. Therefore, the appended claims are intended to cover all changes and modifications falling within the scope of the embodiments of the present application.

[0231] Finally, it should be noted that the relational terms herein, such as first and second, are used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, so that a process, method, article, or terminal device including a series of elements includes not only those elements but also other elements not expressly listed or inherent to such process, method, article, or terminal device. Without more limitations, an element defined by the statement "comprising a" does not exclude the existence of additional identical elements in the process, method, article, or terminal device including the above element.

[0232] The above provides a detailed description of the method and device for tenant gateway migration, electronic equipment, and storage medium provided, and the principles and implementation modes of the present application are described by applying specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, there will be changes in the specific implementation mode and application range; in conclusion, the content of the specification should not be understood as a limitation of the present application.

Claims

1. A method for tenant gateway migration, characterized in that, The method includes: In response to a tenant gateway migration request, the initial tenant gateway is migrated to the target tenant gateway; wherein both the initial tenant gateway and the target tenant gateway transmit data with the public network through a virtual private network gateway, and the host of the virtual private network gateway is also equipped with a virtual switch; During the migration of the initial tenant gateway to the target tenant gateway, the target ingress port and target egress port of the host are determined according to the type of the target tenant gateway; wherein, the target ingress port is used to receive public network data or receive public network data forwarded by the referral gateway, and the target egress port is used to send public network data or public network data forwarded by the referral gateway to the virtual private network gateway. Obtain the configuration data associated with the virtual private network gateway; Based on the configuration data, add port configuration information corresponding to the target ingress port and the target egress port to the virtual switch; Based on the type of the target tenant gateway and the configuration data, update the configuration of the referral gateway for forwarding public network data, and in the virtual switch, update the port configuration information corresponding to the initial tenant gateway to the port configuration information corresponding to the target tenant gateway.

2. The method according to claim 1, characterized in that, The traffic redirection gateway is also communicatively connected to the rate limiting gateway, which in turn is communicatively connected to the virtual private network gateway. The rate limiting gateway is configured with a first port for receiving data sent by the virtual private network gateway. After updating the port configuration information corresponding to the initial tenant gateway to the port configuration information corresponding to the target tenant gateway, the method further includes: Obtain the physical address of the public gateway corresponding to the virtual private network gateway, or obtain the physical address of the first port; Based on the physical address of the public network gateway or the physical address of the first port, send Address Resolution Protocol (ARP) information to the Virtual Private Network (VPN) gateway.

3. The method according to claim 1 or 2, characterized in that, The step of determining the target ingress port and target egress port of the host machine based on the type of the target tenant gateway includes: If the target tenant gateway receives public network data forwarded by the referral gateway through the virtual private network gateway, it determines the target ingress port for receiving the public network data forwarded by the referral gateway, and the target egress port for sending the public network data forwarded by the referral gateway to the virtual private network gateway. If the target tenant gateway receives public network data through the virtual private network gateway, it determines the target ingress port for receiving the public network data and the target egress port for sending the public network data to the virtual private network gateway.

4. The method according to claim 1, characterized in that, The configuration data includes the public IP address corresponding to the virtual private network gateway, the port name of the target ingress port, and the port name of the target egress port. The step of adding port configuration information corresponding to the target ingress port and the target egress port to the virtual switch based on the configuration data includes: Based on the public IP address, the port name of the target ingress port, and the port name of the target egress port, add port configuration information corresponding to the target ingress port and the target egress port in the virtual switch.

5. The method according to claim 1, characterized in that, The step of updating the configuration of the referral gateway for forwarding public network data according to the type of the target tenant gateway includes: If the initial tenant gateway receives public network data through the virtual private network gateway, and the target tenant gateway receives public network data forwarded by the traffic redirection gateway through the virtual private network gateway, the public IP address corresponding to the virtual private network gateway is obtained. Update the configuration of the traffic redirection gateway for forwarding public network data based on the public IP address.

6. The method according to claim 1, characterized in that, The step of updating the configuration of the referral gateway for forwarding public network data according to the type of the target tenant gateway further includes: If the target tenant gateway receives public network data through the virtual private network gateway, and the initial tenant gateway receives public network data forwarded by the referral gateway through the virtual private network gateway, the target forwarding configuration information corresponding to the public network IP address of the virtual private network gateway is determined in the referral gateway, and the target forwarding configuration information is deleted.

7. The method according to claim 2, characterized in that, The traffic redirection gateway and the traffic limiting gateway are a cluster composed of multiple nodes.

8. An apparatus for tenant gateway migration, characterized in that, The device includes: The migration module is used to migrate the initial tenant gateway to the target tenant gateway in response to the migration request of the tenant gateway; wherein both the initial tenant gateway and the target tenant gateway transmit data with the public network through a virtual private network gateway, and the host of the virtual private network gateway is also equipped with a virtual switch; The target port determination module is used to determine the target ingress port and target egress port of the host machine according to the type of the target tenant gateway during the process of migrating the initial tenant gateway to the target tenant gateway; wherein, the target ingress port is used to receive public network data or receive public network data forwarded by the referral gateway, and the target egress port is used to send public network data or public network data forwarded by the referral gateway to the virtual private network gateway. A configuration data acquisition module is used to acquire configuration data associated with the virtual private network gateway; The port configuration information adding module is used to add port configuration information corresponding to the target ingress port and the target egress port in the virtual switch according to the configuration data. The configuration update module is used to update the configuration of the traffic redirection gateway for forwarding public network data according to the type of the target tenant gateway and the configuration data, and to update the port configuration information corresponding to the initial tenant gateway to the port configuration information corresponding to the target tenant gateway in the virtual switch.

9. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the tenant gateway migration method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the tenant gateway migration method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Route configuration method and gateway after thermal migration of virtual machine in large two-layer network

    CN103346900A

  • Gateway control method, device and system based on virtual machine migration

    WO2016034014A1