Network access management method, system, device, storage medium and electronic device

By creating virtual routers and virtual interfaces for virtual machines in OpenStack environment and creating gateway interfaces on compute nodes of internal networks, the problem of low efficiency of virtual machine access management network is solved, and the effect of simplifying configuration, improving security and optimizing resource utilization is achieved.

CN119788437BActive Publication Date: 2025-06-06JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510282506.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-06
Estimated Expiration
2045-03-11

AI Technical Summary

Technical Problem

In OpenStack environment, the virtual machine access management network is inefficient, the traditional method configuration is complex and there are security risks.

Method used

By creating virtual routers and virtual interfaces for virtual machines and creating gateway interfaces on compute nodes on internal networks, obtaining and converting source IP information for virtual machine traffic, enabling them to access the management network.

Benefits of technology

It simplifies network configuration, reduces dependence on physical networks, improves security, and optimizes network forwarding efficiency and IP resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788437B_ABST
    Figure CN119788437B_ABST
Patent Text Reader

Abstract

The embodiment of the present application provides a network access management method, system, device, storage medium and electronic device, which relates to the field of computers, wherein the network access management method includes: creating a first virtual router for a virtual machine; adding a first virtual interface to the first virtual router; creating a first gateway interface at a first computing node in an internal network, wherein the IPs of virtual machines in a single computing node of the internal network are different; obtaining the traffic flowing out of the virtual machine on the first virtual router, and sending the traffic to the first gateway interface through the first virtual interface; replacing the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network. The above solution solves the problem of low efficiency of virtual machines accessing the management network in the related art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the computer field, and more specifically, to a network access management method, system, device, storage medium, and electronic device. Background Art

[0002] In the OpenStack (open source cloud computing platform management platform project) environment, when a virtual machine needs to access the management network (management network), traditional methods such as adding additional network cards, using floating IPs, or configuring NAT are not only complex to configure and require tedious settings on the physical network and within the virtual machine, but may also bring security risks, such as the virtual machine being directly exposed to the external network or the access rights of the entire network becoming too loose.

[0003] Therefore, there is a technical problem in the related art that the efficiency of virtual machines accessing the management network is low. Summary of the invention

[0004] The embodiments of the present application provide a network access management method, system, device, storage medium and electronic device to at least solve the technical problem of low efficiency of virtual machine access to a management network in the related art.

[0005] According to one embodiment of the present application, a network access management method is provided, which is applied to a virtual machine requesting to use an internal network to access a management network, including: creating a first virtual router for the virtual machine; adding a first virtual interface to the first virtual router; creating a first gateway interface at a first computing node in the internal network, wherein the virtual machine is located at the first computing node and the IP addresses of the virtual machines existing on the first computing node are different; obtaining traffic flowing out of the virtual machine on the first virtual router, and sending the traffic to the first gateway interface through the first virtual interface; replacing the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0006] According to one embodiment of the present application, another network access management method is also provided, which is applied to a virtual machine requesting to use an external network to access a management network, including: creating a second virtual router for the virtual machine; adding a second virtual interface to the second virtual router; creating a third gateway interface on a second computing node in an internal network, wherein the virtual machine is located on the second computing node and the virtual machine IPs existing on the second computing node are different; adding a fourth gateway interface of an external network to the second virtual router; obtaining traffic flowing out of the virtual machine on the second virtual router and sending the traffic to the second virtual interface; on the second virtual interface, converting the source IP information of the traffic from the virtual machine IP to the management network IP, and sending the replaced traffic to the fourth gateway interface, wherein the replaced traffic is allowed to access the management network through the fourth gateway interface.

[0007] According to another embodiment of the present application, a network access management device is provided, including: a first creation unit, used to create a first virtual router for a virtual machine; a first adding unit, used to add a first virtual interface to the first virtual router; a second creation unit, used to create a first gateway interface on a first computing node in an internal network, wherein the virtual machine is located at the first computing node, and the IP addresses of the virtual machines on the first computing node are different; a first acquisition unit, used to acquire traffic flowing out of the virtual machine on the first virtual router, and send the traffic to the first gateway interface through the first virtual interface; a first replacement unit, used to replace the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0008] According to another embodiment of the present application, another network access management device is also provided, including: a third creation unit, used to create a second virtual router for the virtual machine; a second adding unit, used to add a second virtual interface for the second virtual router; a fourth creation unit, used to create a third gateway interface on the second computing node of the internal network, wherein the virtual machine is located at the second computing node, and the virtual machine IPs existing on the second computing node are different; the third adding unit, used to add a fourth gateway interface of the external network to the second virtual router; a second acquisition unit, used to acquire traffic flowing out of the virtual machine on the second virtual router, and send the traffic to the second virtual interface; a second replacement unit, used to convert the source IP information of the traffic from the virtual machine IP to the management network IP on the second virtual interface, and send the replaced traffic to the fourth gateway interface, wherein the replaced traffic is allowed to access the management network through the fourth gateway interface.

[0009] According to another embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.

[0010] According to another embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0011] According to another embodiment of the present application, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps of the method in each embodiment of the present application are implemented.

[0012] Through the embodiment provided by the present application, a first virtual router is created for a virtual machine, and a first virtual interface is added to the first virtual router, and a first gateway interface is created for the first computing node where the virtual machine is located in the internal network. In this way, when the traffic flowing out from the virtual machine is obtained, the traffic is sent to the first gateway interface through the first virtual interface, and the source IP information of the traffic received from the first gateway interface is replaced from the virtual machine IP to the management network IP, so that the replaced traffic can access the management network. In this process, the traffic of the virtual machine accessing the management network is directed to the preset interface, and then the IP is replaced by converting the address, thereby realizing the virtual machine's access to the management network. This method not only simplifies the configuration and reduces the dependence on the physical network, but also improves security, because the virtual machine does not need to be directly exposed to the external network, while ensuring the efficiency of network forwarding and the efficient use of IP resources, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network and solving the technical problem of low efficiency of virtual machines accessing the management network.

[0013] Through the embodiment provided by the present application, a second virtual router is created for the virtual machine, and a second virtual interface is added to the second virtual router, and a third gateway interface of the external network is added to the second virtual router. In this way, when the traffic flowing out from the virtual machine is obtained, the traffic is sent to the third gateway interface through the second virtual interface, and the source IP information of the traffic received from the third gateway interface is replaced from the virtual machine IP to the management network IP, so that the replaced traffic can access the management network. In this process, the traffic of the virtual machine accessing the management network is directed to the preset interface, and then the IP is replaced by converting the address, thereby realizing the virtual machine's access to the management network. This method not only simplifies the configuration and reduces the dependence on the physical network, but also improves security, while ensuring the efficiency of network forwarding and the efficient use of IP resources, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network and solving the technical problem of low efficiency of virtual machines accessing the management network. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Figure 1 is a hardware structure block diagram of a network access management method according to an embodiment of the present application;

[0015] Figure 2 is a flow chart of a network access management method according to the present application;

[0016] Figure 3 is a schematic diagram of another network access management method according to the present application;

[0017] Figure 4 is a schematic diagram of a logical network design of an access management network according to the present application;

[0018] Figure 5is a structural block diagram of a network access management device according to an embodiment of the present application;

[0019] Figure 6 It is a structural block diagram of a network access management device according to an embodiment of the present application. DETAILED DESCRIPTION

[0020] The embodiments of the present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0021] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0022] The method embodiments provided in the embodiments of the present application can be executed in a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 1 is a hardware structure block diagram of a computer terminal of a network access management method according to an embodiment of the present application. Figure 1 As shown, the computer terminal may include one or more ( Figure 1 Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a microprocessor MCU (Microcontroller Unit) or a programmable logic device FPGA (Field-Programmable Gate Array) and other processing devices) and a memory 104 for storing data, wherein the above-mentioned computer terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above-mentioned computer terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0023] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for determining the mapping relationship in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the computer terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0024] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of a computer terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0025] As an alternative, Figure 2 As shown, a network access management method, the specific steps include:

[0026] S202, creating a first virtual router for the virtual machine;

[0027] S204, adding a first virtual interface to the first virtual router;

[0028] S206, creating a first gateway interface at a first computing node in the internal network, wherein the IP addresses of virtual machines in a single computing node in the internal network are different;

[0029] S208, obtaining traffic flowing out of the virtual machine on the first virtual router, and sending the traffic to the first gateway interface through the first virtual interface;

[0030] S210: Replace the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0031] Optionally, in this embodiment, the network access management method may be, but is not limited to, applied to a scenario where a virtual machine using an internal network requests access to a management network.

[0032] It should be noted that the internal network used by the virtual machine belongs to the business network, and by default, it is isolated from the management network. However, in some actual needs, the virtual machine needs to pull data from the management network, the virtual machine needs to resolve the domain name from the management network, and some virtual machines need to interact with the control plane (load balancing), etc.

[0033] If you need to allow a virtual machine to access the management network, you can add a network card that uses an external network. This method requires configuring a physical network, and you may also need to configure corresponding routing configurations in the virtual machine, which also opens up access to the external network. This method requires physical environment configuration, and the virtual machine is also exposed to the external network, which has certain risks. Another method is to use a floating IP, which requires users to configure routers, external networks, etc., and there is a certain threshold for use. After configuration, it will affect the entire network where the virtual machine is located.

[0034] For the above problems, the network access management method provided in this embodiment is used to direct the traffic of the virtual machine accessing the management network to the preset interface, and then replace the IP by converting the address, thereby realizing the virtual machine's access to the management network. This method not only simplifies the configuration and reduces the dependence on the physical network, but also improves security, because the virtual machine does not need to be directly exposed to the external network, while ensuring the efficiency of network forwarding and the efficient use of IP resources, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network and solving the above problems.

[0035] Optionally, in this embodiment, in order to meet the specific needs of a specific virtual machine to access a management network or other network resources, a logical virtual router is dynamically created through a software-defined network mechanism, such as using an OVN (Open Virtual Network) controller.

[0036] Optionally, in this embodiment, the traffic of a specific virtual machine can be finely controlled through a virtual router, such as isolating the traffic accessing the management network from other external network traffic, thereby ensuring the security and stability of the network.

[0037] Optionally, in this embodiment, the virtual router can be configured with SNAT (Source Network Address Translation) and DNAT (Destination Network Address Translation) rules to achieve the conversion between the virtual machine IP address and the management network IP address, ensuring that the virtual machine can access the management network, and the traffic returned by the management network can accurately find the corresponding virtual machine. Using the virtual router, policy routing can be implemented to direct the traffic of the virtual machine accessing the management network to the preset network interface, and then access the management network through the computing node or network node, so as to achieve fine-grained control of access.

[0038] Optionally, in this embodiment, a first virtual interface is created in the first virtual router to connect to the internal network and receive and send traffic of the virtual machine. The first virtual interface can be, but is not limited to, used to direct traffic from the virtual machine to a gateway interface on the computing node.

[0039] Optionally, in this embodiment, the specific computing node where the virtual machine is located is determined. In an optional OpenStack architecture of this embodiment, the virtual machine can run on any computing node. Therefore, in order to enable a specific virtual machine to access the management network, it is first necessary to identify the computing node where the virtual machine is located. In this embodiment, the same virtual machine IP will not exist on the computing node at the same time.

[0040] Optionally, in this embodiment, a first gateway interface is created on the first computing node, the first gateway interface is connected to the internal network, receives traffic sent from the virtual machine, and directs the traffic to the next step of SNAT conversion or sends it to the management network.

[0041] It should be noted that after the first gateway interface is created, the SNAT (source network address translation) rule is configured on the first computing node to convert the source IP information of the traffic from the source IP address of the virtual machine to the IP address of the management network, so that the virtual machine can access resources in the network as the management network IP address, while ensuring that the traffic returned by the management network can be correctly identified and returned to the original virtual machine.

[0042] Optionally, in this embodiment, the traffic is acquired on the first virtual router, flows out from the virtual machine, and is sent to the first gateway interface through the first virtual interface.

[0043] It should also be noted that in addition to the SNAT rules, static routing needs to be configured on the first computing node to ensure that the traffic returned from the management network can reach the correct virtual machine through the first gateway interface. The configuration of static routing ensures the correct direction of traffic, which is crucial for achieving two-way communication between the virtual machine and the management network.

[0044] It can be understood that in this embodiment, the process of virtual machine traffic accessing the management network is: traffic leaves the virtual machine -> reaches the virtual router -> is sent to the gateway interface through the virtual interface according to policy routing -> the IP is replaced through the computing node (SNAT rule) -> the replaced traffic accesses the management network through the management network card of the computing node.

[0045] In addition, the process of returning virtual machine traffic from the management network is as follows: traffic arrives at the management network card of the computing node –> the target address is converted to the virtual machine address through the computing node (SNAT rule) –> forwarded to the internal network virtual interface through the gateway interface according to the computer node routing –> the virtual machine router forwards to the virtual machine.

[0046] Through the embodiment provided by the present application, a first virtual router is created for the virtual machine, and a first virtual interface is added to the first virtual router, and a first gateway interface is created for the first computing node where the virtual machine is located in the internal network. In this way, when the traffic flowing out from the virtual machine is obtained, the traffic is sent to the first gateway interface through the first virtual interface, and the source IP information of the traffic received from the first gateway interface is replaced from the virtual machine IP to the management network IP, so that the replaced traffic can access the management network. In this process, the traffic of the virtual machine accessing the management network is directed to the preset interface, and then the IP is replaced by converting the address, thereby realizing the access of the virtual machine to the management network. This method not only simplifies the configuration and reduces the dependence on the physical network, but also improves security, because the virtual machine does not need to be directly exposed to the external network, while ensuring the efficiency of network forwarding and the efficient use of IP resources, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network.

[0047] As an optional solution, before obtaining the traffic flowing out of the virtual machine on the first virtual router and sending the traffic to the first gateway interface through the first virtual interface, the method further includes:

[0048] A first routing policy is added to the first virtual router, wherein the first routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the first routing policy indicates that the next hop of the traffic in the internal network is the first gateway interface.

[0049] Optionally, in this embodiment, the first routing policy may be, but is not limited to, used to identify specific traffic sent by the virtual machine and destined for the management network. When the virtual machine attempts to access the management network, the source IP and destination IP in its data packet will be checked by the virtual router and matched with the rules in the routing policy.

[0050] It should be noted that once the traffic is matched, the routing policy will instruct the virtual router to direct the traffic to a specific gateway interface (such as the first gateway interface) of the internal network. This means that the traffic no longer flows directly through the external network interface of the virtual machine, but is redirected to a preset internal network path, which can be, but is not limited to, through the gateway interface of the computing node.

[0051] It is understandable that after the traffic reaches the gateway interface of the computing node, SNAT (Source Network Address Translation) will be performed. The source IP address of the virtual machine will be translated into an IP address of the management network, so that the traffic can be used as the management network for subsequent network access without revealing the real IP of the virtual machine.

[0052] It should also be noted that for the traffic returned from the management network to the virtual machine, the virtual router will also convert the target IP address back to the original IP of the virtual machine according to the corresponding routing policy, and then send the traffic back to the corresponding virtual machine through the gateway interface and static routing of the internal network.

[0053] Through the embodiments provided by the present application, the first routing strategy can be used to accurately match the traffic of the virtual machine, so that fine-grained control of the virtual machine's access to the management network can be achieved, ensuring that only authorized virtual machines can access the management network. Accurate control and efficient conversion of traffic are achieved, achieving the technical effects of simplifying configuration, improving security and optimizing resource usage.

[0054] As an optional solution, the method further includes:

[0055] A first static route is configured on the first computing node, wherein the first static route indicates that the matching target address is the virtual machine IP, the next hop of the traffic is the first virtual interface, and the passing interface is the first gateway interface.

[0056] Optionally, in this embodiment, in order to ensure that the traffic returned from the management network can correctly reach the virtual machine, static routing needs to be configured on the computing node. The static routing is set based on the target IP address, that is, the IP address of the virtual machine.

[0057] Optionally, in this embodiment, the destination address matching rule in the static route is used to identify traffic that needs to be redirected to a specific virtual machine. When the computing node receives traffic, it checks the destination IP address of the data packet to determine whether the traffic should be sent to a specific virtual machine.

[0058] Optionally, in this embodiment, once the target IP of the traffic is identified as the IP of a virtual machine, the static route will indicate that the next hop of the traffic is the first virtual interface in the internal network. After the traffic reaches the first gateway interface, it will be further routed and address translated through the internal network connected to the interface. The role of the first gateway interface is to serve as the entrance for the traffic to return from the management network to the virtual machine, ensuring that the traffic can be accurately directed to the correct virtual machine.

[0059] Through the embodiments provided by the present application, it is ensured that any traffic returned from the management network to the virtual machine can be correctly identified, and even after SNAT conversion, it can be directed to the correct virtual machine through the gateway interface of the internal network, avoiding the situation where the traffic is lost. The setting of static routing allows fine-grained control of traffic, that is, it can accurately control which traffic should be sent to which virtual machine, which can improve the security of the access process.

[0060] As an optional solution, before replacing the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, the method further includes:

[0061] A first SNAT rule is added on the first computing node, wherein the first SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the management network IP.

[0062] Optionally, in this embodiment, a first SNAT rule is configured on the computing node where the virtual machine is located. The creation of the rule may be based on, but is not limited to, configuration of a software defined network (SDN) controller, such as OVN, and Neutron, a network management component of OpenStack.

[0063] Optionally, in this embodiment, the first SNAT rule checks the source IP address of the outbound traffic. If the source IP address matches the IP address of the virtual machine, this indicates that the traffic is sent by the virtual machine and needs to be converted to access the management network. When the first SNAT rule identifies the traffic of the virtual machine, the source IP address of the traffic is converted to an IP address in the management network.

[0064] It is understandable that after the SNAT conversion is completed, the traffic will continue to be transmitted in the network as the management network IP until it reaches its final destination. This process is transparent to the virtual machine, that is, the virtual machine does not need to know that its IP address has been converted, nor does it need to perform any internal configuration to support this conversion.

[0065] Through the embodiments provided by the present application, it is possible to ensure that the traffic of the virtual machine is directly converted and sent to the management network without having to perform complex routing configuration inside the virtual machine. This simplifies the process of network access and improves the efficiency of traffic transmission, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network.

[0066] As an optional solution, after adding the first virtual interface of the internal network to the first virtual router, the method further includes:

[0067] When the IP addresses of the virtual machines in a single computing node of the internal network are the same, creating a second gateway interface for the single computing node, wherein the single computing node includes the first computing node;

[0068] Add a second routing policy in the first virtual router, wherein the second routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the second routing policy indicates that the next hop of the traffic in the internal network is the second gateway interface;

[0069] Replace the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the first interface IP of the first virtual interface;

[0070] The source IP information of the traffic received on each computing node is replaced from the first interface IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0071] Optionally, in this embodiment, before replacing the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the first interface IP of the first virtual interface, the method further includes: adding a second SNAT rule on the virtual machine router, wherein the second SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the first interface IP. Before replacing the source IP information of the traffic received on each computing node from the first interface IP to the management network IP, the method further includes: adding a third SNAT rule on each computing node, wherein the third SNAT rule indicates that the matching source is the first interface IP and the target NAT is the management network IP.

[0072] Optionally, in this embodiment, when there are two or more virtual machines using the same IP address on the same computing node, and at least one of the virtual machines needs to be able to access the management network, this IP address conflict may cause confusion in network access, such as traffic may be mistakenly directed to another virtual machine with the same IP address. To avoid this situation, this embodiment creates a gateway interface for the internal network on all gateway nodes to ensure that the management network access of each virtual machine is independent and secure.

[0073] Optionally, in this embodiment, in order to resolve the IP conflict problem and allow specific virtual machines to access the management network, gateway interfaces are created on all gateway nodes. These gateway interfaces serve as the conversion point for traffic from the internal network to the management network, and are also the entry point for traffic returning from the management network. The creation of these interfaces ensures that no matter which computing node the virtual machine is located on, it can access the management network through a unified and secure path.

[0074] Optionally, in this embodiment, SNAT rules are configured on all network nodes to convert the source IP of the traffic (the IP of the virtual machine with IP conflict) to the IP address of the internal network, and then convert it to the management network IP through the interface on the gateway node before reaching the management network. The conversion process ensures that even if the virtual machines use the same IP address, their traffic accessing the management network can be correctly distinguished and directed.

[0075] Optionally, in this embodiment, static routing is configured on all network nodes to match the target address as the IP address of the internal network (the converted IP), and to indicate that the next hop of the traffic is the gateway interface. Through these static routing rules, it is ensured that the traffic returned from the management network can accurately reach the correct virtual machine.

[0076] Through the embodiments provided by the present application, by using an internal network and creating an independent gateway interface, the network access conflict problem caused by multiple virtual machines using the same IP address can be effectively solved. Even in the case of an IP conflict, the traffic of a specific virtual machine accessing the management network can be isolated, reducing potential security risks. It allows for more refined control of the virtual machine's access to the management network, ensuring that only authorized virtual machines can access the management network through a specific path. By sharing the gateway interface of the internal network, the demand for additional IP address resources is reduced, and the use of network resources is optimized.

[0077] As an alternative, Figure 3 As shown, another network access management method includes the following specific steps:

[0078] S302, creating a second virtual router for the virtual machine;

[0079] S304, adding a second virtual interface to the second virtual router;

[0080] S306, adding a third gateway interface of the external network to the second virtual router;

[0081] S308, obtaining the traffic flowing out from the virtual machine on the second virtual router, and sending the traffic to the second virtual interface;

[0082] S310, on the second virtual interface, convert the source IP information of the traffic from the virtual machine IP to the management network IP, and send the replaced traffic to the third gateway interface, wherein the replaced traffic is allowed to access the management network through the third gateway interface.

[0083] Optionally, in this embodiment, the network access management method may be, but is not limited to, applied to a scenario where a virtual machine using an external network requests access to a management network.

[0084] It should be noted that the external network used by the virtual machine belongs to the business network, which is isolated from the management network by default. However, in some actual needs, the virtual machine needs to pull data from the management network, the virtual machine needs to resolve the domain name from the management network, and some virtual machines need to interact with the control plane (load balancing), etc.

[0085] Currently, if a virtual machine needs to access the management network, a floating IP address can be used. Users are required to configure routers, external networks, etc., which has a certain threshold. After configuration, the entire network where the virtual machine is located will be affected.

[0086] For the above problems, the network access management method provided in this embodiment is used to direct the traffic of the virtual machine accessing the management network to the preset interface, and then replace the IP by converting the address, thereby realizing the virtual machine's access to the management network. This method not only simplifies the configuration, reduces the dependence on the physical network, but also improves security, while ensuring the efficiency of network forwarding and the efficient use of IP resources, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network and solving the above problems.

[0087] Optionally, in this embodiment, in order to meet the specific needs of a specific virtual machine to access a management network or other network resources, a logical virtual router is dynamically created through a software-defined network mechanism, such as using an OVN (Open Virtual Network) controller.

[0088] Optionally, in this embodiment, the virtual router can be configured with SNAT and DNAT rules to achieve conversion between the virtual machine IP address and the management network IP address, ensuring that the virtual machine can access the management network, and the traffic returned by the management network can accurately find the corresponding virtual machine. Using the virtual router, policy routing can be implemented to direct the traffic of the virtual machine accessing the management network to the preset network interface, and then access the management network through the computing node or network node, so as to achieve fine-grained control of access.

[0089] Optionally, in this embodiment, a second virtual interface is created in the second virtual router to connect to the internal network and receive and send traffic of the virtual machine. The second virtual interface can be, but is not limited to, used to direct traffic from the virtual machine to a gateway interface on the computing node.

[0090] Optionally, in this embodiment, the specific computing node where the virtual machine is located is determined. A virtual machine can run on any computing node. Therefore, in order to enable a specific virtual machine to access the management network, it is first necessary to identify the computing node where the virtual machine is located. In this embodiment, the same virtual machine IP will not exist on the computing node at the same time.

[0091] Optionally, in this embodiment, a second gateway interface is created on the second computing node, the second gateway interface is connected to the internal network, receives traffic sent from the virtual machine, and directs the traffic to the next step of SNAT conversion or sends it to the management network.

[0092] It should be noted that after creating the second gateway interface, SNAT (source network address translation) rules are configured on the second computing node to convert the source IP information of the traffic from the source IP address of the virtual machine to the IP address of the management network, so that the virtual machine can access resources in the network as the management network IP address, while ensuring that the traffic returned by the management network can be correctly identified and returned to the original virtual machine.

[0093] Optionally, in this embodiment, in order to enable the virtual machine to access the management network, a new virtual network interface (the third gateway interface of the external network) needs to be created in the virtual router. The third gateway interface will connect the external network and the internal network where the virtual machine is located, and is used to guide and convert traffic so that it can access the management network through the correct path.

[0094] Optionally, in this embodiment, after the third gateway interface is created, it needs to be configured as the entrance for the virtual machine to access the management network. The third gateway interface will receive traffic from the virtual machine and guide the traffic to the access path of the management network according to the preset routing policy and SNAT rules.

[0095] Optionally, in this embodiment, the third gateway interface will work in conjunction with the interface of the internal network to achieve correct guidance and conversion of virtual machine traffic through policy routing and SNAT rules.

[0096] It is understandable that the virtual machine first connects to the external network, but also needs to access the management network. By adding a third gateway interface in the virtual router, the traffic sent by the virtual machine to the management network can be directed to the internal network path, and then converted to the IP address of the management network through the SNAT rule, and finally access the management network through the management network card of the computing node.

[0097] It should also be noted that in addition to the SNAT rules, static routing needs to be configured on the second computing node to ensure that the traffic returned from the management network can reach the correct virtual machine through the second gateway interface. The configuration of static routing ensures the correct direction of traffic, which is crucial for achieving two-way communication between the virtual machine and the management network.

[0098] It can be understood that in this embodiment, the process of virtual machine traffic accessing the management network is: traffic leaves the virtual machine -> reaches the virtual router -> is sent to the gateway interface through the virtual interface according to policy routing -> the IP is replaced through the computing node (SNAT rule) -> the replaced traffic accesses the management network through the management network card of the computing node.

[0099] In addition, the process of returning virtual machine traffic from the management network is as follows: traffic arrives at the management network card of the computing node –> the target address is converted to the virtual machine address through the computing node (SNAT rule) –> forwarded to the internal network virtual interface through the gateway interface according to the computer node routing –> the virtual machine router forwards to the virtual machine.

[0100] Through the embodiment provided by the present application, a second virtual router is created for the virtual machine, and a second virtual interface is added to the second virtual router. In this way, when the traffic flowing out from the virtual machine is obtained, the source IP information of the received traffic is replaced from the virtual machine IP to the management network IP, so that the replaced traffic can access the management network. In this process, by configuring specific (routing) policies and (SNAT) rules in the virtual router, the traffic of the virtual machine accessing the management network is directed to the preset interface, and then the IP is replaced by converting the address, thereby realizing the virtual machine's access to the management network. This method not only simplifies the configuration and reduces the dependence on the physical network, but also improves security, while ensuring the efficiency of network forwarding and the efficient use of IP resources, thereby achieving the technical effect of improving the efficiency of virtual machine access to the management network. In addition, through the creation of the third gateway interface, the separation of the virtual machine's access to the external network and the management network path is realized. Even if the virtual machine is already connected to the external network, it can still independently configure and access the management network, which improves the flexibility and security of network access.

[0101] As an optional solution, after adding a fourth gateway interface of the external network to the second virtual router, the method further includes:

[0102] A preset rule is added in the second virtual router, wherein the preset rule indicates that the next hop of the traffic in the internal network is a real gateway of the external network.

[0103] Optionally, in this embodiment, the real gateway of the external network is the real gateway address of the external network to which the virtual machine is currently connected, and is the main routing point for the virtual machine to communicate with the outside world.

[0104] Optionally, in this embodiment, a default routing rule is added to the virtual router, which directs all traffic of the virtual machine that is not matched by a specific policy route to the real gateway of the external network. It can be understood that this means that except for the traffic that is explicitly marked as accessing the management network, all other traffic will follow this default rule and be routed through the real gateway of the external network.

[0105] Optionally, in this embodiment, the next hop is set to the real gateway of the external network. This configuration ensures that the traffic of the virtual machine can leave the cloud environment through the correct exit point and reach the external network.

[0106] Through the embodiments provided in the present application, it is ensured that when a virtual machine accesses a management network, its regular traffic for accessing an external network will not be affected, thereby ensuring that the network service of the virtual machine will not be interrupted.

[0107] As an optional solution, before obtaining the traffic flowing out of the virtual machine on the second virtual router and sending the traffic to the third gateway interface through the second virtual interface, the method further includes:

[0108] A third routing policy is added to the second virtual router, wherein the third routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the third routing policy indicates that the next hop of the traffic in the internal network is the third gateway interface.

[0109] Optionally, in this embodiment, the third routing policy can be, but is not limited to, used to identify specific traffic sent by the virtual machine and destined for the management network. When the virtual machine attempts to access the management network, the source IP and destination IP in its data packet will be checked by the virtual router and matched with the rules in the routing policy.

[0110] It is understandable that after the traffic reaches the gateway interface of the computing node, SNAT (Source Network Address Translation) will be performed. The source IP address of the virtual machine will be translated into an IP address of the management network, so that the traffic can be used as the management network for subsequent network access without revealing the real IP of the virtual machine.

[0111] It should also be noted that for the traffic returned from the management network to the virtual machine, the virtual router will also convert the target IP address back to the original IP of the virtual machine according to the corresponding routing policy, and then send the traffic back to the corresponding virtual machine through the gateway interface and static routing of the internal network.

[0112] Through the embodiments provided by the present application, the third routing strategy is used to accurately match the traffic of the virtual machine, so that fine-grained control of the virtual machine's access to the management network can be achieved, ensuring that only authorized virtual machines can access the management network. Accurate control and efficient conversion of traffic are achieved, achieving the technical effects of simplifying configuration, improving security and optimizing resource use.

[0113] As an optional solution, the method further includes:

[0114] A second static route is configured on the second computing node, wherein the second static route indicates that the matching target address is the virtual machine IP, the next hop of the traffic is the second virtual interface, and the passing interface is the third gateway interface.

[0115] Optionally, in this embodiment, in order to ensure that the traffic returned from the management network can correctly reach the virtual machine, static routing needs to be configured on the computing node. The static routing is set based on the target IP address, that is, the IP address of the virtual machine.

[0116] Optionally, in this embodiment, the destination address matching rule in the static route is used to identify traffic that needs to be redirected to a specific virtual machine. When the computing node receives traffic, it checks the destination IP address of the data packet to determine whether the traffic should be sent to a specific virtual machine.

[0117] Through the embodiments provided in this application, it is ensured that any traffic returned from the management network to the virtual machine can be correctly identified, and even after SNAT conversion, it can be directed to the correct virtual machine through the gateway interface, avoiding the situation where the traffic is lost. The setting of static routing allows fine-grained control of traffic, that is, it can accurately control which traffic should be sent to which virtual machine, which can improve the security of the access process.

[0118] As an optional solution, before converting the source IP information of the traffic from the virtual machine IP to the management network IP, the method further includes:

[0119] A third SNAT rule is added on the second computing node, wherein the third SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the management network IP.

[0120] Optionally, in this embodiment, a third SNAT rule is configured on the computing node where the virtual machine is located. The creation of the rule may be based on, but is not limited to, configuration of a software defined network (SDN) controller, such as OVN, and Neutron, a network management component of OpenStack.

[0121] Optionally, in this embodiment, the third SNAT rule checks the source IP address of the outbound traffic. If the source IP address matches the IP address of the virtual machine, this indicates that the traffic is sent by the virtual machine and needs to be converted to access the management network. When the third SNAT rule identifies the traffic of the virtual machine, the source IP address of the traffic is converted to an IP address in the management network.

[0122] It is understandable that after the SNAT conversion is completed, the traffic will continue to be transmitted in the network as the management network IP until it reaches its final destination. This process is transparent to the virtual machine, that is, the virtual machine does not need to know that its IP address has been converted, nor does it need to perform any internal configuration to support this conversion.

[0123] Through the embodiments provided by the present application, it is possible to ensure that the traffic of the virtual machine is directly converted and sent to the management network without having to perform complex routing configuration inside the virtual machine. This simplifies the process of network access and improves the efficiency of traffic transmission, thereby achieving the technical effect of improving the efficiency of virtual machines accessing the management network.

[0124] As an optional solution, before adding a third gateway interface of the external network to the second virtual router, the method further includes:

[0125] Creating a fourth gateway interface on a second computing node in the internal network, wherein the IP addresses of the virtual machines in the single computing node in the internal network are different;

[0126] After adding a second virtual interface of the internal network to the second virtual router, the method further includes:

[0127] When the IP addresses of the virtual machines in a single computing node are the same, creating a fifth gateway interface for each second computing node;

[0128] Add a fourth routing policy in the second virtual router, wherein the fourth routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the fourth routing policy indicates that the next hop of the traffic in the internal network is the fifth gateway interface;

[0129] Replace the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the second interface IP of the second virtual interface;

[0130] The source IP information of the traffic received on each second computing node is replaced from the second interface IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0131] Optionally, in this embodiment, before replacing the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the second interface IP of the second virtual interface, the method further includes: adding a fourth SNAT rule on the virtual machine router, wherein the fourth SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the second virtual interface. Before replacing the source IP information of the traffic received on each second computing node from the second interface IP to the management network IP, the method further includes: adding a fifth SNAT rule on each second computing node, wherein the fifth SNAT rule indicates that the matching source is the second interface IP and the target NAT is the management network IP.

[0132] Optionally, in this embodiment, when there are two or more virtual machines using the same IP address on the same computing node, and at least one of the virtual machines needs to be able to access the management network, this IP address conflict may cause confusion in network access, such as traffic may be mistakenly directed to another virtual machine with the same IP address. To avoid this situation, this embodiment creates a gateway interface on all gateway nodes to ensure that the management network access of each virtual machine is independent and secure.

[0133] Optionally, in this embodiment, in order to resolve the IP conflict problem and allow specific virtual machines to access the management network, gateway interfaces are created on all gateway nodes. These gateway interfaces serve as the conversion point for traffic from the external network to the management network, and are also the entry point for traffic returning from the management network. The creation of these interfaces ensures that no matter which computing node the virtual machine is located on, it can access the management network through a unified and secure path.

[0134] Optionally, in this embodiment, SNAT rules are configured on all network nodes to convert the source IP of the traffic (the IP of the virtual machine with IP conflict) to the IP address of the internal network, and then convert it to the management network IP through the interface on the gateway node before reaching the management network. The conversion process ensures that even if the virtual machines use the same IP address, their traffic accessing the management network can be correctly distinguished and directed.

[0135] Optionally, in this embodiment, static routing is configured on all network nodes to match the target address as the IP address of the internal network (the converted IP), and to indicate that the next hop of the traffic is the gateway interface. Through these static routing rules, it is ensured that the traffic returned from the management network can accurately reach the correct virtual machine.

[0136] Through the embodiments provided by the present application, by using an internal network and creating an independent gateway interface, the network access conflict problem caused by multiple virtual machines using the same IP address can be effectively solved. Even in the case of an IP conflict, the traffic of a specific virtual machine accessing the management network can be isolated, reducing potential security risks. It allows for more refined control of the virtual machine's access to the management network, ensuring that only authorized virtual machines can access the management network through a specific path. By sharing the gateway interface of the internal network, the demand for additional IP address resources is reduced, and the use of network resources is optimized.

[0137] As an optional solution, a network access management system includes a control plug-in, an agent module, and a virtual machine, wherein the agent module is deployed in each computing node of the virtual network, and is characterized in that:

[0138] The control plug-in includes a first control interface and a second control interface, wherein the first control interface is used to control whether the virtual machine is allowed to access the management network, and the second control interface is used to control the type of the virtual network that the virtual machine needs to pass through to access the management network;

[0139] The proxy module is used to create a gateway interface in each computing node, wherein the gateway interface is used to forward the traffic of the virtual machine accessing the management network, and the source IP information of the traffic is replaced from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0140] Optionally, when the first control interface is configured with first interface parameters, the virtual machine is prohibited from accessing the management network; when the first control interface is configured with second interface parameters and the second control interface is configured with third interface parameters, the virtual machine is allowed to access the management network through an external network; when the first control interface is configured with the second interface parameters and the second control interface is configured with fourth interface parameters, the virtual machine is allowed to access the management network through an internal network, and the virtual network includes the external network and the internal network.

[0141] Optionally, the proxy module includes a first proxy sub-module and a second proxy sub-module, wherein the first proxy sub-module is used to configure SNAT rules and static routes for each of the computing nodes when a first proxy parameter is detected, and the second proxy sub-module is used to remove the SNAT rules and the static routes for each of the computing nodes when a second proxy parameter is detected.

[0142] It is understandable that when the first control interface is configured as the first interface parameter, the system will prohibit the virtual machine from accessing the management network, ensuring that the virtual machine cannot directly communicate with the management network without authorization.

[0143] When the first control interface is configured as the second interface parameter, and the second control interface is configured as the third interface parameter, the virtual machine will be allowed to access the management network through the external network. At this time, the system creates a virtual router and corresponding policy routing to direct the virtual machine's traffic to the external network, and then converts it to the IP of the management network through SNAT rules to complete secure access.

[0144] When the first control interface is configured as the second interface parameter, and the second control interface is configured as the fourth interface parameter, the virtual machine will be allowed to access the management network through the internal network. In this case, the system directs traffic through the internal network interface preset on the computing node, and uses SNAT rules to convert the source IP of the traffic within the computing node, ensuring that the traffic is transmitted between the computing node and the management network in an efficient and secure manner.

[0145] The proxy module is further subdivided into a first proxy submodule and a second proxy submodule. When the first proxy submodule detects the first proxy parameter, it configures SNAT rules and static routes for each computing node to ensure that the virtual machine can correctly access the management network. When the second proxy submodule detects the second proxy parameter, it removes SNAT rules and static routes for each computing node so that when access to the management network is not needed, resources can be released in time to reduce unnecessary network load and security risks.

[0146] Taking the OpenStack environment as an example, the system of this embodiment can achieve the following functions: One-click configuration of virtual machine access management network, without the need for internal configuration of the virtual machine. Dynamically create and delete internal network interfaces, policy routing, SNAT rules and static routes based on the access requirements of the virtual machine. Traffic forwarding through computing nodes or gateway nodes to solve IP conflict problems and improve security.

[0147] The embodiments provided in this application can overcome the limitations of traditional virtual machine access management network methods, provide a more efficient, secure and easy-to-use solution, reduce the complexity of network configuration in a cloud computing environment, reduce management costs, improve operation and maintenance efficiency, and ensure the security of the cloud environment.

[0148] As an optional solution, the above network access management method is applied to a scenario where an openstack virtual machine quickly configures access to a management network. In this scenario, the network used by the openstack virtual machine belongs to the business network. By default, it is isolated from the management network. However, in some actual requirements, the virtual machine needs to pull data from the management network, the virtual machine needs to resolve the domain name from the management network, and some virtual machines need to interact with the control plane (load balancing), etc.

[0149] If you need to access the management network for a virtual machine, you can add a network card that uses an external network. This method requires configuring a physical network. At the same time, you may also need to configure corresponding routing configurations in the virtual machine, which also opens up access to the external network. This method requires physical environment configuration, and the virtual machine is also exposed to the external network, which has certain risks. Another method is to use a floating IP or configure NAT, which requires users to configure routers, external networks, etc., and there is a certain threshold for use. After configuration, it will affect the entire network where the virtual machine is located.

[0150] In order to solve the above defects, this embodiment is based on ovn policy routing and SNAT technology. Through the policy routing of the OVN logical router, the traffic configured with access to the management network is directed to the internal network. The node where the internal network gateway is located accesses the management network through SNAT, thereby realizing fine-grained access to the management network by the virtual machine without configuring anything in the virtual machine. This embodiment also designs a neutron plug-in to realize one-click configuration of the logical routers, routing policies, etc. required for the internal network. Design an agent to automatically create an internal network gateway interface and maintain SNAT rules, static routes, etc.

[0151] Specifically, the following Figure 4 , various scenarios are explained for the logical network design of the access management network.

[0152] First of all, Figure 4Explanation: The dotted icon part is the virtual machine access management network and newly added resources, which is not visible to the user. Internal network L and internal network G refer to two different networks created internally. Network L and network G are just to distinguish two different internal networks. The type of Logical_Switch_Port corresponding to the internal network L gateway and the internal network G gateway is localport. This design can configure the same IP for all computing nodes or network nodes, reduce IP consumption, and realize unified configuration distribution.

[0153] Further, the following combination Figure 4 , and explain different access management network logical network design schemes in different situations.

[0154] (I) When a virtual machine on the internal network accesses the management network and no virtual machine with the same IP address on the same computing node accesses the management network:

[0155] In this case, add interface LI-1 of internal network L to the virtual machine router. Create gateway interface L-GW of internal network L in the computing node where the virtual machine is located. Add a routing policy in the router that matches the source IP as the virtual machine IP and the target network segment as the management network segment. If there are multiple management network segments, configure multiple routing policies. The next hop of the routing policy is L-GW. Configure SNAT rules on the computing node where the virtual machine is located, with the source address being the virtual machine IP and NAT being the management network IP. Configure static routing on the computing node where the virtual machine is located, matching the target address as the virtual machine IP, with the next hop being the IP of routing interface LI-1 of the internal network, and the gateway interface L-GW of the internal network through the interface.

[0156] It can be understood that the process of the virtual machine gateway management network is: traffic leaves the virtual machine -> reaches the router -> is sent to the gateway interface L-GW through the routing interface LI-1 according to the policy routing -> the original IP is replaced by the SNAT rule of the computer node -> accesses the management network through the management network card of the computing node.

[0157] Management network return traffic flow: Traffic arrives at the management network card of the computing node –> The target address is converted to the virtual machine address through the computing node SNAT rule –> According to the computer node routing, it is forwarded to the internal network routing interface LI-1 through the gateway interface L-GW –> The router forwards it to the virtual machine.

[0158] (II) A virtual machine on the internal network accesses the management network and a virtual machine with the same IP address already exists on the same computing node to access the management network:

[0159] In this case, add a virtual interface GI-1 of the internal network G to the virtual machine router. And configure gateways. Create a gateway interface G-GW for the internal network G on all gateway nodes. Add a routing policy in the router that matches the source IP as the virtual machine IP and the target network segment as the management network segment. If there are multiple management network segments, configure multiple routing policies. The next hop of the routing policy is G-GW. Add an SNAT rule in the router to SNAT the virtual machine IP to GI-1. Configure SNAT rules on all network nodes, with the source address being GI-1 and SNAT being the management network IP. Configure static routes on all network nodes, matching the target address as GI-1 and the next hop being the gateway interface G-GW IP.

[0160] It can be understood that the process of the virtual machine gateway management network is: traffic leaves the virtual machine -> reaches the router -> passes through the routing interface GI-1 according to the policy routing, converts the source address to GI-1 -> reaches the gateway interface G-GW -> replaces the source IP through the network node SNAT rule -> accesses the management network through the management network card of the network node.

[0161] Management network return traffic flow: Traffic arrives at the management network card of the network node –> passes through the network node, converts the target address to the GI-1 address –> sends it to the virtual machine router through the interface G-GW –> converts the target address to the virtual machine address through the virtual router flow table –> the router forwards it to the virtual machine.

[0162] (III) When a virtual machine on an external network accesses the management network and no virtual machines with the same IP address on the same computing node access the management network:

[0163] In this case, create a virtual router. Add interface LI-2 of the internal network L to the virtual machine router. Create the gateway interface L-GW of the internal network L in the compute node where the virtual machine is located. Add interface GW-V of the external network of the virtual machine to the virtual router. Add a default rule in the virtual router. The next hop is the real gateway of the original external network of the virtual machine. Add a routing policy in the router that matches the source IP as the virtual machine IP and the target network segment as the management network segment. If there are multiple management network segments, configure multiple routing policies. The next hop of the routing policy is L-GW. Configure the SNAT rule on the compute node where the virtual machine is located, with the source address as the virtual machine IP and NAT as the management network IP. Configure a static route on the compute node where the virtual machine is located, matching the target address as the virtual machine IP, and the next hop as the IP of the routing interface LI-2 of the internal network, through the interface as the gateway interface L-GW of the internal network.

[0164] It can be understood that the process of the virtual machine gateway management network is: traffic leaves the virtual machine -> reaches the router -> is sent to the gateway interface L-GW through the routing interface LI-2 according to the policy routing -> the original IP is replaced by the SNAT rule of the computer node -> accesses the management network through the management network card of the computing node.

[0165] Management network return traffic flow: Traffic arrives at the management network card of the computing node –> The target address is converted to the virtual machine address through the computing node SNAT rule –> Traffic is sent to the internal network routing gateway interface L-GW according to the computer node routing –> Forwarded to the internal network routing interface LI-2, reaches the router –> The router forwards it to the virtual machine.

[0166] (IV) A virtual machine on an external network accesses the management network and a virtual machine with the same IP address already exists on the same computing node to access the management network:

[0167] In this case, create a virtual router. Add interface GI-2 of internal network G to the virtual machine router. And configure gateways. Create gateway interface G-GW of internal network G on all gateway nodes. Add interface GW-V of the virtual machine external network to the virtual router. Add a default rule to the virtual router. The next hop is the real gateway of the original virtual machine external network. Add a routing policy in the router that matches the source IP as the virtual machine IP and the target network segment as the management network segment. If there are multiple management network segments, configure multiple routing policies. The next hop of the routing policy is G-GW. Add SNAT rules to the router, and SNAT the virtual machine IP to GI-2. Configure SNAT rules on all network nodes, with the source address as GI-2 and SNAT as the management network IP. Configure static routes on all network nodes, matching the target address as GI-2, and the next hop as the gateway interface G-GW IP.

[0168] It can be understood that the process of the virtual machine gateway management network is: traffic leaves the virtual machine -> reaches the router -> passes through the routing interface GI-2 according to the policy routing, converts the source address to GI-2 -> reaches the gateway interface G-GW -> replaces the source IP through the network node SNAT rule -> accesses the management network through the management network card of the network node.

[0169] Management network return traffic flow: Traffic arrives at the management network card of the network node –> passes through the network node, converts the target address to the GI-2 address –> sends it to the virtual machine router through the interface G-GW –> converts the target address to the virtual machine address through the virtual router flow table –> the router forwards it to the virtual machine.

[0170] Optionally, in this embodiment, the above network access management method can be, but is not limited to, implemented based on a designed neutron plug-in, wherein the extended interface of the neutron plug-in can add a property setting access_management to indicate whether the access management network function is enabled.

[0171] Optionally, the extended subnet interface of the neutron plug-in can add the property setting gateway_location, which allows the setting of two values: incloud and external. Setting incloud means that the gateway is on the virtual router, and external means that the gateway is on the real physical device. For the subnet marked as external, the user is not allowed to add the subnet to the virtual router. The virtual machines using the incloud subnet correspond to the above-mentioned "virtual machines in the internal network", and the virtual machines using the external subnet correspond to the above-mentioned "virtual machines in the external network". Optionally, the property setting gateway_virtual_IP can also be added. If the subnet is set to gateway_location=external, this property value must be set to a virtual gateway for adding to the virtual router. The atomic network property gateway_IP is still a real physical gateway.

[0172] Optionally, when designing the function of the neutron plug-in, when creating a subnet, you can but are not limited to verify that if gateway_location=external is set, a valid gateway_virtual_IP must be set. When updating a subnet, you can but are not limited to verify that if gateway_location=external is set, a valid gateway_virtual_IP must be set, and the subnet is not added to any virtual machine router. And if a port under the subnet has access_management turned on, changing the gateway_location is not allowed.

[0173] When adding a router interface, you can, but are not limited to, verify that the subnet you add cannot be gateway_location=external.

[0174] When creating or updating a port, you can, but are not limited to, verify that the subnet where the port is located, if gateway_location=incloud, must have been added to a virtual router.

[0175] Optionally, if access_management is enabled on the port, and the subnet where the port is located has gateway_location=incloud: If the port is the first one in the subnet to enable access_management. According to the logical network design, add interfaces for the internal network L and internal network G to the virtual router where the subnet is located. According to the computer node where the port is located, determine whether the computer node has the same IP address. Based on the result of the determination and the logical network design, create corresponding policy routing in the virtual router. Add access_management related tags to the logical_swtich_port of the port corresponding to ovn. According to the above determination result, identify whether the port is forwarded by a network node or a computing node.

[0176] Optionally, if access_management is disabled for the port, and the subnet where the port is located has gateway_location=incloud: Delete the policy routing associated with the port in the virtual router. Remove the logical_swtich_port access_management related tags for the port corresponding to ovn. If no other ports in the subnet where the port is located have access_management enabled. Delete the routing interfaces associated with the internal network L and the internal network G.

[0177] Optionally, if access_management is turned on for the port, and the subnet where the port is located has gateway_location=external: If the port is the first subnet to turn on access_management, create a virtual router in ovn according to the logical network design, and add the subnet to the virtual router. Create an additional DHCP_Options in ovn, and point the gateway to the subnet's interface in the virtual router. Add interfaces for internal network L and internal network G in the virtual router. Add a default route to the virtual machine router and forward it to the real physical gateway. According to the computer node where the port is located, determine whether the computer node has the same IP. Based on the judgment result and the logical network design, create the corresponding policy routing in the virtual router. Add access_management-related tags to the logical_swtich_port of the port corresponding to ovn, and identify whether the port is forwarded by the network node or the computing node according to the judgment result of ②. Bind the additionally created DHCP_Options to the port.

[0178] Optionally, if access_management is disabled on the port, delete the policy routing related to the port in the virtual router if the subnet where the port is located is gateway_location=external. Modify the DHCP_Options bound to the port to the default DHCP_Options of the subnet. Remove the access_management related tags of the logical_swtich_port corresponding to the ovn of the port. If no other ports in the subnet where the port is located have access_management enabled. Delete the virtual router and delete the additionally created DHCP_Options.

[0179] Optionally, in this embodiment, proxy deployment may be performed on all computing nodes and gateway nodes, but is not limited to the above.

[0180] Optionally, in this embodiment, the agent monitors the Logical_Switch_Port. When it is found that the Logical_Switch_Port port has an access_management tag added, it is determined that it belongs to the management of the node, if it is not managed, it is ignored, and it is continued to determine whether the network L or network G to which the port is to be forwarded has been created in this node, and if it has not been created, it is created. According to the logical network design, the SNAT rules and static routes are configured. When it is found that the Logical_Switch_Port port has an access_management tag removed, it is determined that it belongs to the management of the node, if it is not managed, it is ignored, and it is continued to delete the relevant SNAT rules and static routes.

[0181] It can be understood that this embodiment provides a solution for quickly configuring the access management network of the Openstack virtual machine based on the network access management method, so that the one-click setting of the virtual machine granularity takes effect immediately, eliminating the cumbersome cloud environment configuration and physical environment configuration, as well as security control configuration, lowering the usage threshold, ensuring security, and improving operation and maintenance efficiency.

[0182] Through the embodiments provided in the present application, traffic path solutions for accessing the management network in different situations, such as internal networks, external networks, and when the host has the same IP or not, are designed. The interface control and processing actions for introducing access to the management network, various resource subnets, ports, and routing interfaces are designed in detail. By designing a strategy to route the traffic of specific virtual machines accessing the management network to the preset interface, the management network is then implemented through the SNAT rules. A preset interface is designed on the computing node to achieve efficient forwarding of management network traffic. The design can be forwarded to the network node to solve possible IP conflicts with the same host machine. The design adds a virtual gateway to the virtual router for the external network to achieve the traffic diversion effect. A new DHCP_Option is designed to divert traffic to the virtual router for a specific virtual machine without affecting other virtual machines.

[0183] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, disk, CD), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of each embodiment of the present application.

[0184] In this embodiment, a network access management device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0185] Figure 5 is a structural block diagram of a network access management device according to an embodiment of the present application, such as Figure 5 As shown, the device comprises:

[0186] A first creating unit 502, configured to create a first virtual router for the virtual machine;

[0187] A first adding unit 504, configured to add a first virtual interface to the first virtual router;

[0188] A second creation unit 506 is used to create a first gateway interface in a first computing node in the internal network, wherein the IP addresses of the virtual machines in a single computing node in the internal network are different;

[0189] A first acquisition unit 508, configured to acquire traffic flowing out of the virtual machine on the first virtual router, and send the traffic to the first gateway interface through the first virtual interface;

[0190] The first replacement unit 510 is used to replace the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

[0191] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0192] As an optional solution, the device also includes:

[0193] The first adding module is used to obtain the traffic flowing out from the virtual machine on the first virtual router, and before sending the traffic to the first gateway interface through the first virtual interface, add a first routing policy in the first virtual router, wherein the first routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the first routing policy indicates that the next hop of the traffic in the internal network is the first gateway interface.

[0194] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0195] As an optional solution, the device also includes:

[0196] The first configuration module is used to configure a first static route on the first computing node, wherein the first static route indicates that the matching target address is the virtual machine IP, the next hop of the traffic is the first virtual interface, and the passing interface is the first gateway interface.

[0197] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0198] As an optional solution, the device also includes:

[0199] The second adding module is used to add a first SNAT rule on the first computing node before replacing the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, wherein the first SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the management network IP.

[0200] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0201] As an optional solution, the device also includes:

[0202] A first creation module, configured to create a second gateway interface for a single computing node in an internal network when the IP addresses of the virtual machines in the single computing node are the same, wherein the single computing node includes the first computing node;

[0203] A third adding module is used to add a second routing policy in the first virtual router after adding a first virtual interface of the internal network to the first virtual router, wherein the second routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the second routing policy indicates that the next hop of the traffic in the internal network is the second gateway interface;

[0204] A first replacement module is used to replace the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the first interface IP of the first virtual interface after adding the first virtual interface of the internal network to the first virtual router;

[0205] The second replacement module is used to replace the source IP information of the traffic received on each computing node from the first interface IP to the management network IP after adding the first virtual interface of the internal network to the first virtual router, and the replaced traffic is allowed to access the management network.

[0206] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0207] As an optional solution, the device also includes:

[0208] The fourth adding module is used to add a second SNAT rule on the virtual machine router before replacing the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the first interface IP of the first virtual interface, wherein the second SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the first interface IP.

[0209] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0210] As an optional solution, the device also includes:

[0211] The fifth adding module is used to add a third SNAT rule to each computing node before replacing the source IP information of the traffic received on each computing node from the first interface IP to the management network IP, wherein the third SNAT rule indicates that the matching source is the first interface IP and the target NAT is the management network IP.

[0212] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0213] Figure 6 is a structural block diagram of a network access management device according to an embodiment of the present application, such as Figure 6 As shown, the device comprises:

[0214] The third creating unit 602 is used to create a second virtual router for the virtual machine;

[0215] A second adding unit 604, configured to add a second virtual interface to the second virtual router;

[0216] A third adding unit 606, configured to add a third gateway interface of an external network to the second virtual router;

[0217] A second acquisition unit 608, configured to acquire traffic flowing out of the virtual machine on the second virtual router, and send the traffic to the second virtual interface;

[0218] The second replacement unit 610 is used to convert the source IP information of the traffic from the virtual machine IP to the management network IP on the second virtual interface, and send the replaced traffic to the third gateway interface, wherein the replaced traffic is allowed to access the management network through the third gateway interface.

[0219] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0220] As an optional solution, the device also includes:

[0221] The sixth adding module is used to add a preset rule in the second virtual router after adding the fourth gateway interface of the external network to the second virtual router, wherein the preset rule indicates that the next hop of the traffic in the internal network is the real gateway of the external network.

[0222] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0223] As an optional solution, the device also includes:

[0224] The seventh adding module is used to obtain the traffic flowing out from the virtual machine on the second virtual router, and before sending the traffic to the third gateway interface through the second virtual interface, add a third routing policy in the second virtual router, wherein the third routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the third routing policy indicates that the next hop of the traffic in the internal network is the third gateway interface.

[0225] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0226] As an optional solution, the device also includes:

[0227] The second configuration module is used to configure a second static route on the second computing node, wherein the second static route indicates that the matching target address is the virtual machine IP, the next hop of the traffic is the second virtual interface, and the passing interface is the third gateway interface.

[0228] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0229] As an optional solution, the device also includes:

[0230] The eighth adding module is used to add a third SNAT rule on the second computing node before converting the source IP information of the traffic from the virtual machine IP to the management network IP, wherein the third SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the management network IP.

[0231] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0232] As an optional solution, the device is also used to: before adding a third gateway interface of the external network to the second virtual router, create a fourth gateway interface in the second computing node of the internal network, wherein the IP addresses of the virtual machines in a single computing node of the internal network are different.

[0233] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0234] As an optional solution, the device also includes:

[0235] A second creation module is used to create a fifth gateway interface for the second computing node after adding a second virtual interface of the internal network to the second virtual router, if the IP addresses of the virtual machines in the single computing node are the same;

[0236] A ninth adding module, configured to add a fourth routing policy in the second virtual router after adding a second virtual interface of the internal network to the second virtual router, wherein the fourth routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the fourth routing policy indicates that the next hop of the traffic in the internal network is the fifth gateway interface;

[0237] A third replacement module is used to replace the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the second interface IP of the second virtual interface after adding the second virtual interface of the internal network to the second virtual router;

[0238] The fourth replacement module is used to replace the source IP information of the traffic received on each second computing node from the second interface IP to the management network IP after adding the second virtual interface of the internal network to the second virtual router, and the replaced traffic is allowed to access the management network.

[0239] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0240] As an optional solution, the device also includes:

[0241] A tenth adding module is used to add a fourth SNAT rule on the virtual machine router before replacing the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the second interface IP of the second virtual interface, wherein the fourth SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the second virtual interface.

[0242] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0243] As an optional solution, the device also includes:

[0244] The third creation module is used to add a fifth SNAT rule to each second computing node before replacing the source IP information of the traffic received on each second computing node from the second interface IP to the management network IP, wherein the fifth SNAT rule indicates that the matching source is the second interface IP and the target NAT is the management network IP.

[0245] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0246] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0247] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, disk, CD), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of each embodiment of the present application.

[0248] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0249] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above method embodiments when running.

[0250] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0251] An embodiment of the present application further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0252] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0253] An embodiment of the present application further provides a computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores the computer program product, and when the computer program is executed by a processor, the steps of the method in each embodiment of the present application are implemented.

[0254] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail herein.

[0255] Obviously, those skilled in the art should understand that the above modules or steps of the present application can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order from that herein, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.

[0256] The above are only preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principles of the present application shall be included in the protection scope of the present application.

Claims

1. A network access management method, applied to a virtual machine requesting to use an internal network to access a management network, characterized in that: include: Creating a first virtual router for the virtual machine; Adding a first virtual interface to the first virtual router; Creating a first gateway interface at a first computing node in the internal network, wherein the IP addresses of the virtual machines in a single computing node in the internal network are different; Acquire, on the first virtual router, traffic flowing out of the virtual machine, and send the traffic to the first gateway interface through the first virtual interface; The source IP information of the traffic received from the first gateway interface is replaced from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

2. The method according to claim 1, characterized in that Before acquiring, on the first virtual router, traffic flowing out of the virtual machine and sending the traffic to the first gateway interface through the first virtual interface, the method further includes: A first routing policy is added to the first virtual router, wherein the first routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the first routing policy indicates that the next hop of the traffic in the internal network is the first gateway interface.

3. The method according to claim 1, characterized in that The method further comprises: A first static route is configured on the first computing node, wherein the first static route indicates that the matching target address is the virtual machine IP, the next hop of the traffic is the first virtual interface, and the passing interface is the first gateway interface.

4. The method according to claim 1, characterized in that: Before replacing the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, the method further includes: A first SNAT rule is added on the first computing node, wherein the first SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the management network IP.

5. The method according to claim 1, characterized in that: After adding the first virtual interface of the internal network to the first virtual router, the method further includes: When the IP addresses of the virtual machines in a single computing node of the internal network are the same, creating a second gateway interface for the single computing node, wherein the single computing node includes the first computing node; Add a second routing policy in the first virtual router, wherein the second routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the second routing policy indicates that the next hop of the traffic in the internal network is the second gateway interface; Replace the source IP information of the traffic flowing out of the virtual router from the virtual machine IP to the first interface IP of the first virtual interface; The source IP information of the traffic received on each computing node is replaced from the first interface IP to the management network IP, and the replaced traffic is allowed to access the management network.

6. The method according to claim 5, characterized in that Before replacing the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the first interface IP of the first virtual interface, the method further includes: A second SNAT rule is added to the virtual machine router, wherein the second SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the first interface IP.

7. The method according to claim 5, characterized in that Before replacing the source IP information of the traffic received on each computing node from the first interface IP to the management network IP, the method further includes: A third SNAT rule is added to each computing node, wherein the third SNAT rule indicates that a matching source is the first interface IP and a target NAT is the management network IP.

8. A network access management method, applied to a virtual machine requesting to use an external network to access a management network, characterized in that: include: Creating a second virtual router for the virtual machine; Adding a second virtual interface to the second virtual router; Adding a third gateway interface of an external network to the second virtual router; Acquire, on the second virtual router, traffic flowing out of the virtual machine, and send the traffic to the second virtual interface; On the second virtual interface, the source IP information of the traffic is replaced from the virtual machine IP to the management network IP, and the replaced traffic is sent to the third gateway interface, wherein the replaced traffic is allowed to access the management network through the third gateway interface.

9. The method according to claim 8, characterized in that The method further comprises: A preset rule is added in the second virtual router, wherein the preset rule indicates that the next hop of the traffic is a real gateway of the external network.

10. The method according to claim 8, characterized in that Before acquiring, on the second virtual router, traffic flowing out from the virtual machine and sending the traffic to the third gateway interface through the second virtual interface, the method further includes: A third routing policy is added to the second virtual router, wherein the third routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the third routing policy indicates that the next hop of the traffic is the third gateway interface.

11. The method according to claim 8, characterized in that The method further comprises: A second static route is configured on the second computing node where the virtual machine is located, wherein the second static route indicates that the matching target address is the virtual machine IP, the next hop of the traffic is the second virtual interface, and the passing interface is the third gateway interface.

12. The method according to claim 8, characterized in that Before converting the source IP information of the traffic from the virtual machine IP to the management network IP, the method further includes: A third SNAT rule is added on the second computing node where the virtual machine is located, wherein the third SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the management network IP.

13. The method according to claim 8, characterized in that Before adding a third gateway interface of an external network to the second virtual router, the method further includes: A fourth gateway interface of the internal network is created on the second computing node where the virtual machine is located, wherein the IP addresses of the virtual machines in a single computing node of the internal network are different.

14. The method according to claim 13, characterized in that After adding the second virtual interface of the internal network to the second virtual router, the method further includes: When the IP addresses of the virtual machines in the single computing node are the same, creating a fifth gateway interface of the internal network for the second computing node; Adding a fourth routing policy in the second virtual router, wherein the fourth routing policy indicates that the matching source is the virtual machine IP, the target network segment is the network segment of the management network, and the fourth routing policy indicates that the next hop of the traffic in the internal network is the fifth gateway interface; Replace the source IP information of the traffic flowing out of the virtual router from the virtual machine IP to the second interface IP of the second virtual interface; The source IP information of the traffic received on each second computing node is replaced from the second interface IP to the management network IP, and the replaced traffic is allowed to access the management network.

15. The method according to claim 14, characterized in that Before replacing the source IP information of the traffic flowing out of the virtual machine router from the virtual machine IP to the second interface IP of the second virtual interface, the method further includes: A fourth SNAT rule is added to the virtual machine router, wherein the fourth SNAT rule indicates that the matching source is the virtual machine IP and the target NAT is the second virtual interface.

16. The method according to claim 14, characterized in that Before replacing the source IP information of the traffic received on each second computing node from the second interface IP to the management network IP, the method further includes: A fifth SNAT rule is added to each of the second computing nodes, wherein the fifth SNAT rule indicates that a matching source is the second interface IP and a target NAT is the management network IP.

17. A network access management system, comprising a control plug-in, an agent module, and a virtual machine, wherein the agent module is deployed in each computing node of a virtual network, characterized in that: The control plug-in includes a first control interface and a second control interface, wherein the first control interface is used to control whether the virtual machine is allowed to access the management network, and the second control interface is used to control the type of the virtual network that the virtual machine needs to pass through to access the management network; The proxy module is used to create a gateway interface in each computing node, wherein the gateway interface is used to forward the traffic of the virtual machine accessing the management network, and the source IP information of the traffic is replaced from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

18. The system according to claim 17, characterized in that When the first control interface is configured with a first interface parameter, the virtual machine is prohibited from accessing the management network; when the first control interface is configured with a second interface parameter and the second control interface is configured with a third interface parameter, the virtual machine is allowed to access the management network through an external network; In a case where the first control interface is configured with the second interface parameter and the second control interface is configured with the fourth interface parameter, the virtual machine is allowed to access the management network through the internal network, and the virtual network includes the external network and the internal network.

19. The system according to claim 17, characterized in that The proxy module includes a first proxy submodule and a second proxy submodule, wherein the first proxy submodule is used to configure SNAT rules and static routes for each computing node when a first proxy parameter is detected, and the second proxy submodule is used to remove the SNAT rules and the static routes for each computing node when a second proxy parameter is detected.

20. A network access management device, characterized in that: include: A first creation unit, configured to create a first virtual router for the virtual machine; A first adding unit, configured to add a first virtual interface to the first virtual router; A second creation unit is used to create a first gateway interface in a first computing node of an internal network, wherein the IP addresses of the virtual machines in a single computing node of the internal network are different; A first acquisition unit, configured to acquire traffic flowing out of the virtual machine on the first virtual router, and send the traffic to the first gateway interface through the first virtual interface; The first replacement unit is used to replace the source IP information of the traffic received from the first gateway interface from the virtual machine IP to the management network IP, and the replaced traffic is allowed to access the management network.

21. A network access management device, characterized in that: include: A third creation unit, configured to create a second virtual router for the virtual machine; A second adding unit, configured to add a second virtual interface to the second virtual router; A third adding unit, configured to add a third gateway interface of an external network to the second virtual router; A second acquisition unit, configured to acquire, on a second virtual router, traffic flowing out of the virtual machine, and send the traffic to a second virtual interface; The second replacement unit is used to replace the source IP information of the traffic from the virtual machine IP to the management network IP on the second virtual interface, and send the replaced traffic to the fourth gateway interface, wherein the replaced traffic is allowed to access the management network through the third gateway interface.

22. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program implements the steps of the method according to any one of claims 1 to 7 or 8 to 16 when executed by a processor.

23. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 or 8 to 16 are implemented.

24. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 or 8 to 16 are implemented.

Citation Information

Patent Citations

  • Method for realizing southbound and northbound communication of virtual machines on computing nodes

    CN106059803A

  • Data transmission method, virtual network management device and data transmission system

    CN106487695A