Network communication architecture, communication method, electronic device, and storage medium
By constructing a network communication architecture that includes SDN controllers and switches, the problem of limited business flexibility during cloud migration was solved, enabling Layer 2 traffic interconnection between the cloud network and traditional IDC data centers, and improving the versatility of the network communication architecture and the flexibility of business migration.
Patent Information
- Application Number
- CN202411773104.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-12-04
AI Technical Summary
In existing technologies, enterprises cannot gradually migrate some services within the same subnet to the cloud during the migration process, which limits business flexibility and affects business continuity and disaster recovery capabilities.
Construct a network communication architecture, including public cloud data centers and private cloud data centers. Through the combination of SDN controllers, leased line switches, Spine switches, Leaf switches and other devices, and by utilizing BGP EVPN session connections and configuration information, traffic forwarding and routing information exchange are achieved, BGP EVPN neighbors are established, and Layer 2 traffic interconnection between the cloud network and traditional IDC data centers is realized.
It enables interoperability between cloud and on-premises networks, improves the versatility of network communication architecture, and ensures flexible migration and continuity of services.
Smart Images

Figure CN119814501B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of public cloud network, in particular to a network communication architecture, a network communication method, an electronic device and a computer readable storage medium. BACKGROUND
[0002] With the acceleration of digital transformation, more and more enterprises begin to migrate their core businesses and applications to the cloud to improve efficiency, reduce costs and enhance the flexibility and scalability of their businesses. However, one of the main challenges many enterprises face during the migration process is how to gradually migrate their businesses to the cloud while preserving traditional data centers, implementing a hybrid cloud architecture.
[0003] During the process of digital transformation, enterprises have increasingly high requirements for business continuity and disaster recovery capabilities. Especially in key industries such as finance, healthcare and manufacturing, business downtime can result in significant economic losses and reputational damage. Therefore, enterprises need a corresponding platform to ensure business continuity in any situation. In related technologies, virtual machines on the cloud need to communicate with the data center's machine room through a dedicated line, but due to the limitations of this communication method, it is not possible to implement gradual migration of part of the business in the same subnet to the cloud, limiting the flexible migration of the business and potentially affecting the business of the enterprise. SUMMARY
[0004] The embodiments of the present application provide a network communication architecture, method, electronic device and computer readable storage medium to solve or partially solve the problem of network architecture limiting the flexible migration of the business.
[0005] The embodiments of the present application disclose a network communication architecture, which comprises at least a public cloud machine room and a private cloud machine room in communication with the public cloud machine room; wherein,
[0006] The public cloud machine room comprises an SDN controller, a first dedicated line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first dedicated line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; the private cloud machine room comprises at least a second dedicated line switch, an access switch in communication connection with the second dedicated line switch, and a second device in communication connection with the access switch;
[0007] The SDN controller and the access switch establish a BGP EVPN session connection, the SDN controller is used for sending the first routing information corresponding to the public cloud room to the private cloud room through the BGP EVPN session connection, and the access switch is used for sending the second routing information corresponding to the private cloud room to the public cloud room through the BGP EVPN session connection.
[0008] The first routing information is used for guiding the device in the private cloud room to perform traffic forwarding to transmit traffic to the first device, and the second routing information is used for guiding the device in the public cloud room to perform traffic forwarding to transmit traffic to the second device.
[0009] In some possible implementation manners, the SDN controller and the first private line switch establish a first control connection, and the SDN controller and the second private line switch establish a second control connection.
[0010] The SDN controller sends the first configuration information corresponding to the first private line switch to the first private line switch through the first control connection, and sends the second configuration information corresponding to the second private line switch to the second private line switch through the second control connection.
[0011] In some possible implementation manners, the first configuration information and the second configuration information respectively at least include one of basic configuration, interface configuration, valn configuration, routing configuration, security configuration, Qos configuration, high availability configuration and log and monitoring configuration.
[0012] In some possible implementation manners, the first private line switch and the second private line switch establish a 3-layer vxlan tunnel.
[0013] In some possible implementation manners, the SDN controller and the access switch establish a third control connection.
[0014] The SDN controller sends the third configuration information corresponding to the access switch to the access switch through the third control connection.
[0015] In some possible implementation manners, the third configuration information at least includes configuration information related to an Ethernet virtual private network and configuration information related to a virtual extensible local area network tunnel.
[0016] The configuration information related to the Ethernet virtual private network includes at least one of a neighbor IP address, a remote AS number, an update source interface, a multi-hop configuration, an active address family, a virtual network instance, a route identifier, a route target, and a virtual tunnel endpoint address; and the configuration information related to the virtual extensible local area network tunnel includes at least a VXLAN interface name, a VXLAN type, a remote IP address, a virtual network instance identifier, a flow table rule, a priority, an input port, an output port, and a VLAN tag processing.
[0017] The embodiment of the present application further discloses a network communication method applied to the network communication architecture as described in the embodiment of the present application; wherein the first device includes at least a first virtual switch, the first virtual switch includes at least a first virtual machine, the second device includes at least a second virtual switch, the second virtual switch includes at least a second virtual machine, and the method includes:
[0018] An EVPN neighbor is established between the SDN controller and the access switch.
[0019] The SDN controller acquires a virtual tunnel endpoint address corresponding to the first virtual switch located in the public cloud room, and encapsulates the virtual tunnel endpoint address as a class 2 route.
[0020] The SDN controller establishes a vxlan tunnel with the access switch based on the class 2 route.
[0021] The second virtual switch receives the first packet transmitted by the second virtual machine, adds a VLAN header to the first packet, and transmits the first packet to the access switch.
[0022] The access switch maps the VLAN header in the first packet into a VXLAN header, and transmits the mapped first packet to a second private line switch.
[0023] The second private line switch adds a VXLAN header of a three-layer private line to the mapped first packet, and transmits the processed first packet to a first private line switch through a 3-layer VXLAN tunnel.
[0024] The first private line switch removes the VXLAN header of the three-layer private line, transmits the removed first packet to the first virtual switch.
[0025] The first virtual switch removes the VXLAN header, obtains the first packet, and transmits the first packet to the first virtual machine.
[0026] In some possible implementation manners, the private cloud room further includes an entity server, the access switch is configured with a two-layer port, and the method further includes:
[0027] The access switch receives the second packet transmitted by the physical server through the Layer 2 port, adds a VLAN header to the second packet, and transmits the second packet to the access switch.
[0028] The access switch maps the VLAN header in the second packet to a VXLAN header, and then transmits the mapped second packet to the second leased line switch;
[0029] The second leased line switch adds a Layer 3 leased line VXLAN header to the mapped second packet and transmits the processed second packet to the first leased line switch through a Layer 3 VXLAN tunnel.
[0030] The first leased line switch removes the VXLAN header of the Layer 3 leased line and transmits the removed second message to the first virtual switch.
[0031] The first virtual switch removes the VXLAN header, obtains the second packet, and transmits the second packet to the first virtual machine.
[0032] This invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0033] The memory is used to store computer programs;
[0034] When the processor executes a program stored in the memory, it implements the method described in the embodiments of the present invention.
[0035] This invention also discloses a computer-readable storage medium storing instructions that, when executed by one or more processors, cause the processors to perform the methods described in this invention.
[0036] The embodiments of the present invention have the following advantages:
[0037] In the embodiment of the present application, by constructing a corresponding network communication architecture, the network communication architecture can include a public cloud room and a private cloud room in communication with the public cloud room, wherein the public cloud room includes an SDN controller, a first private line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first private line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; the private cloud room at least includes a second private line switch, an access switch in communication connection with the second private line switch, and a second device in communication connection with the access switch; wherein a BGP EVPN session connection is established between the SDN controller and the access switch, the SDN controller is configured to send first routing information corresponding to the public cloud room to the private cloud room through the BGP EVPN session connection, and the access switch is configured to send second routing information corresponding to the private cloud room to the public cloud room through the BGP EVPN session connection; wherein the first routing information is used to guide the devices in the private cloud room to perform traffic forwarding to transmit the traffic to the first device; the second routing information is used to guide the devices in the public cloud room to perform traffic forwarding to transmit the traffic to the second device, so as to convert the routing of the cloud network by deploying physical access devices, controllers and physical access devices to establish BGP EVPN neighbors, achieve the function of two-layer traffic interconnection between virtual machines and traditional IDC room services in the cloud network, and enable the interconnection between the cloud and the network below the cloud, thereby improving the generality of the network communication architecture and ensuring the flexible migration of services. BRIEF DESCRIPTION OF DRAWINGS
[0038] Figure 1 is a structural schematic diagram of a network communication architecture provided in the embodiment of the present application;
[0039] Figure 2 is a schematic diagram of a network communication architecture provided in the embodiment of the present application;
[0040] Figure 3 is a flowchart of a network communication method provided in the embodiment of the present application;
[0041] Figure 4 is a schematic diagram of traffic forwarding provided in the embodiment of the present application. DETAILED DESCRIPTION
[0042] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application will be further described in detail below with reference to the drawings and specific embodiments.
[0043] As an example, in the related art, the virtual machine on the cloud and the traditional IDC machine room interwork through a dedicated line, but the dedicated line is a three-layer dedicated line, that is, the IP address of the virtual machine on the cloud cannot belong to the same subnet as the IP address of the traditional IDC machine room of the enterprise. For the business of the enterprise on the cloud, it is impossible to gradually migrate part of the business on the cloud in the same subnet of the enterprise, which has a great impact on the business of the enterprise on the cloud.
[0044] To this end, in the present application, by constructing a corresponding network communication architecture, the network communication architecture can include a public cloud machine room and a private cloud machine room in communication with the public cloud machine room, wherein the public cloud machine room includes an SDN controller, a first dedicated line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first dedicated line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; the private cloud machine room at least includes a second dedicated line switch, an access switch in communication connection with the second dedicated line switch, and a second device in communication connection with the access switch; wherein the SDN controller and the access switch establish a BGP EVPN session connection, the SDN controller is used to send first routing information corresponding to the public cloud machine room to the private cloud machine room through the BGP EVPN session connection, and the access switch is used to send second routing information corresponding to the private cloud machine room to the public cloud machine room through the BGP EVPN session connection; wherein the first routing information is used to guide the device in the private cloud machine room to perform traffic forwarding to transmit the traffic to the first device; the second routing information is used to guide the device in the public cloud machine room to perform traffic forwarding to transmit the traffic to the second device, so as to convert the routing of the network in the cloud by deploying physical access devices, controllers and physical access devices to establish BGP EVPN neighbors, to achieve the function of two-layer traffic interworking between the virtual machine in the cloud and the traditional IDC machine room service, so that the network between the cloud and the cloud can be interconnected, the generality of the network communication architecture is improved, and the flexible migration of the service is ensured.
[0045] In order for those skilled in the art to better understand the technical solutions in the embodiments of the present application, some technical features involved in the embodiments of the present application are explained and described as follows:
[0046] SDN (Software Defined Network, software-defined network): it can be a network architecture that separates the network control plane from the data plane, making network management more centralized and intelligent. For SDN, it can include controllers, southbound interfaces, northbound interfaces, and network devices, etc. The SDN controller can be responsible for managing and controlling the entire network, communicating with network applications through the northbound interface, and communicating with network devices through the southbound interface. The southbound interface can be the interface between the controller and the network device, and the commonly used protocols include OpenFlow, NETCONF, etc. The northbound interface can be the interface between the controller and the network application, providing API for network applications to call to implement network policies and configurations. Network devices can perform packet forwarding and processing tasks and be centrally managed by the controller.
[0047] OVS (Open Vswitch, virtual switch): it can be an open-source virtual switch widely used in virtualization environments such as cloud computing data centers. For OVS, it has multi-layer switching functions and supports multiple protocols and standards such as OpenFlow, NETCONF, BGP, etc.
[0048] VXLAN (Virtual eXtensible LAN, extensible virtual local area network): it can be a network virtualization technology designed to solve the scalability limitations of traditional VLANs. VXLAN can be based on UDP protocol, using a 24-bit identifier (VNI), supporting the construction of large-scale virtual networks.
[0049] EIP (Elastic Public IP function, 1:1 NAT implementation): it can be a network function that allows dynamic allocation and management of public IP addresses, implementing 1:1 network address translation (NAT).
[0050] Security Group (Security Group function, used to limit traffic in and out of the port, stateful): it can be a virtual firewall function used to control traffic in and out of the port, providing stateful traffic filtering, rule-based traffic control, and dynamic adjustment of security policies to ensure network security and compliance.
[0051] Subnet (Subnet function, can create subnets within VPC): a subnet is a logical isolated network segment within a virtual private cloud (VPC) used to allocate IP addresses and control network traffic, enabling internal network division and management, and supporting flexible network architecture design and resource allocation.
[0052] The VNI range can be managed by a VNI segment manager, and the VNI segment manager is used for defining and managing an identifier (VNI) segment of a VXLAN network, and by providing allocation and control functions of the VNI, the construction and management of a large-scale virtual network are ensured.
[0053] With reference to Figure 1 , a structural schematic diagram of a network communication architecture provided in an embodiment of the present application is shown, and the network communication architecture at least includes a public cloud room and a private cloud room in communication with the public cloud room; wherein,
[0054] The public cloud room includes an SDN controller, a first private line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first private line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; and the private cloud room at least includes a second private line switch, an access switch in communication connection with the second private line switch, and a second device in communication connection with the access switch.
[0055] The SDN controller and the access switch are connected by a BGP EVPN session, the SDN controller is used to send first routing information corresponding to the public cloud room to the private cloud room through the BGP EVPN session, and the access switch is used to send second routing information corresponding to the private cloud room to the public cloud room through the BGP EVPN session.
[0056] The first routing information is used to guide the devices in the private cloud room to perform traffic forwarding to transmit the traffic to the first device, and the second routing information is used to guide the devices in the public cloud room to perform traffic forwarding to transmit the traffic to the second device.
[0057] In the embodiment of the present application, the network communication architecture is mainly composed of the public cloud room and the private cloud room, and the public cloud room and the private cloud room can communicate through the private line switch. The public cloud room and the private cloud room each contain a series of network devices, and the exchange of routing information and traffic forwarding are realized through the SDN controller and the BGP EVPN session.
[0058] For the public cloud room, the SDN controller can serve as the brain of the network, responsible for managing and controlling the traffic and routing of the entire network; the first private line switch can communicate with the SDN controller, responsible for the private line connection between the public cloud room and the private cloud room; the Spine switch can communicate with the first private line switch, responsible for high-speed data exchange within the public cloud room; the Leaf switch can communicate with the Spine switch, responsible for connecting the SDN controller and the first device; the first device can communicate with the SDN controller and the Leaf switch, which may be servers, storage devices, etc.
[0059] For the private cloud room, the second private line switch can communicate with the first private line switch, responsible for the private line connection between the private cloud room and the public cloud room; the access switch can communicate with the second private line switch, responsible for the device access within the private cloud room; the second device can communicate with the access switch, which may be servers, storage devices, etc.
[0060] For the network communication architecture, the communication process between the public cloud room and the private cloud room can include:
[0061] First, the BGP EVPN session connection can be established: the SDN controller and the access switch establish a BGP EVPN session connection for exchanging routing information. The SDN controller sends the first routing information of the public cloud room to the private cloud room through the BGP EVPN session. The access switch sends the second routing information of the private cloud room to the public cloud room through the BGP EVPN session.
[0062] Next, the routing information exchange can be performed: the first routing information is generated by the SDN controller, which contains the routing information of the public cloud room, used to guide the devices in the private cloud room how to forward traffic to the first device. The second routing information is generated by the access switch, which contains the routing information of the private cloud room, used to guide the devices in the public cloud room how to forward traffic to the second device.
[0063] Finally, the traffic forwarding can be performed: the devices in the private cloud room forward the traffic to the first device of the public cloud room according to the first routing information. The devices in the public cloud room forward the traffic to the second device of the private cloud room according to the second routing information.
[0064] In some possible implementation manners, the SDN controller and the first private line switch establish a first control connection, and the SDN controller and the second private line switch establish a second control connection;
[0065] The SDN controller issues first configuration information corresponding to the first private line switch to the first private line switch through a first control connection, and issues second configuration information corresponding to the second private line switch to the second private line switch through a second control connection.
[0066] In some possible implementation manners, the first configuration information and the second configuration information respectively at least include one of basic configuration, interface configuration, valn configuration, routing configuration, security configuration, Qos configuration, high availability configuration, and log and monitoring configuration.
[0067] In some possible implementation manners, a layer 3 VXLAN tunnel is established between the first private line switch and the second private line switch.
[0068] In some possible implementation manners, a third control connection is established between the SDN controller and the access switch; and the SDN controller is configured to issue third configuration information corresponding to the access switch to the access switch through the third control connection.
[0069] In some possible implementation manners, the third configuration information at least includes configuration information related to an Ethernet virtual private network and configuration information related to a virtual extensible local area network tunnel.
[0070] The configuration information related to the Ethernet virtual private network at least includes one of a neighbor IP address, a remote AS number, an update source interface, a multi-hop configuration, an active address family, a virtual network instance, a routing identifier, a routing target, and a virtual tunnel endpoint address; and the configuration information related to the virtual extensible local area network tunnel at least includes a VXLAN interface name, a VXLAN type, a remote IP address, a virtual network instance identifier, a flow table rule, a priority, an input port, an output port, and a VLAN tag processing.
[0071] In an example, referring to Figure 2 , a schematic diagram of a network communication architecture provided in an embodiment of the present application is shown. For a public cloud host, the network communication architecture can include an SDN controller, a first private line switch, a Spine switch, a Leaf switch, and a first virtual switch, and the first virtual switch can include a plurality of virtual machines (computing nodes) and the like. For a private cloud host, the network communication architecture can include a second private line switch, an IDC access switch, a bare metal server, and a second virtual switch, and the second virtual switch can include a plurality of virtual machines (such as a common virtualization server and the like).
[0072] It should be noted that the IDC access switch and the private line switch are deployed in the private cloud room, the private line switch is mainly used to establish a 3-layer vxlan private line tunnel with the private line switch in the cloud network, and the IDC access switch is mainly used to access the business in the private cloud room. The private line switch in the private cloud room establishes a netconf connection with the SDN controller, which is used for the SDN controller to issue relevant configurations to the private line switch, and the private line switch in the private cloud room establishes a 3-layer vxlan tunnel with the private line switch in the cloud. At the same time, the IDC access switch in the private cloud room establishes a netconf connection with the SDN controller in the cloud and establishes a BGPEVPN neighbor. The netconf connection is used for the SDN controller to issue relevant configurations on the IDC access switch, mainly including relevant configurations of the EVPN and relevant configurations of the vxlan tunnel established with the OVS; the BGPEVPN neighbor is used to send the EVPN route learned in the traditional IDC room to the SDN controller in the public cloud room for traffic forwarding, and also learns the EVPN route sent by the SDN controller in the public cloud room to guide the traffic forwarding of the device in the traditional IDC room.
[0073] It should be noted that the embodiments of the present application include but are not limited to the above examples, and it can be understood that those skilled in the art can also set according to the actual needs under the guidance of the idea of the embodiments of the present application, and the present application does not limit this.
[0074] In the embodiment of the present application, by constructing a corresponding network communication architecture, the network communication architecture can include a public cloud room and a private cloud room in communication with the public cloud room, wherein the public cloud room includes an SDN controller, a first private line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first private line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; the private cloud room at least includes a second private line switch, an access switch in communication connection with the second private line switch, and a second device in communication connection with the access switch; wherein a BGP EVPN session connection is established between the SDN controller and the access switch, the SDN controller is configured to send first routing information corresponding to the public cloud room to the private cloud room through the BGP EVPN session connection, and the access switch is configured to send second routing information corresponding to the private cloud room to the public cloud room through the BGP EVPN session connection; wherein the first routing information is used to guide the devices in the private cloud room to perform traffic forwarding to transmit the traffic to the first device; the second routing information is used to guide the devices in the public cloud room to perform traffic forwarding to transmit the traffic to the second device, so as to convert the routing of the cloud network by deploying physical access devices, controllers and physical access devices to establish BGP EVPN neighbors, achieve the function of two-layer traffic interconnection between virtual machines and traditional IDC room services in the cloud network, and enable the intercommunication between the network on the cloud and the network under the cloud, thereby improving the universality of the network communication architecture and ensuring the flexible migration of services.
[0075] Referring to Figure 3 , a flow chart of a network communication method provided in the embodiment of the present application is shown, which is applied to the network communication architecture described in the above embodiment; wherein the first device at least includes a first virtual switch, the first virtual switch at least includes a first virtual machine, the second device at least includes a second virtual switch, and the second virtual switch at least includes a second virtual machine, which can specifically include the following steps:
[0076] Step 301, establishing an EVPN neighbor between the SDN controller and the access switch;
[0077] Step 302, the SDN controller acquires a virtual tunnel endpoint address corresponding to the first virtual switch in the public cloud room, and encapsulates the virtual tunnel endpoint address as a class 2 route;
[0078] Step 303, the SDN controller establishes a vxlan tunnel based on the class 2 route and the access switch;
[0079] Step 304, the second virtual switch receives the first packet transmitted by the second virtual machine, adds a VLAN header to the first packet, and transmits the first packet to the access switch;
[0080] Step 305, the access switch maps the VLAN header in the first packet to a VXLAN header, and transmits the mapped first packet to the second private line switch;
[0081] Step 306, the second private line switch adds a VXLAN header of a three-layer private line to the mapped first packet, and transmits the processed first packet to the first private line switch through a three-layer VXLAN tunnel;
[0082] Step 307, the first private line switch removes the VXLAN header of the three-layer private line, and transmits the removed first packet to the first virtual switch;
[0083] Step 308, the first virtual switch removes the VXLAN header, obtains the first packet, and transmits the first packet to the first virtual machine.
[0084] In some possible implementation manners, the private cloud room further includes a physical server, and the access switch is configured with a two-layer port, and the method further includes:
[0085] The access switch receives a second packet transmitted by the physical server through the two-layer port, adds a VLAN header to the second packet, and transmits the second packet to the access switch;
[0086] The access switch maps the VLAN header in the second packet to a VXLAN header, and transmits the mapped second packet to the second private line switch;
[0087] The second private line switch adds a VXLAN header of a three-layer private line to the mapped second packet, and transmits the processed second packet to the first private line switch through a three-layer VXLAN tunnel;
[0088] The first private line switch removes the VXLAN header of the three-layer private line, and transmits the removed second packet to the first virtual switch;
[0089] The first virtual switch removes the VXLAN header, obtains the second packet, and transmits the second packet to the first virtual machine.
[0090] In an example, refer to Figure 4Fig. 1 shows a schematic diagram of the traffic forwarding provided in the embodiment of the present application, wherein the part of the arrowed line is the path of the traffic forwarding, for example, 10.0.0.2 is a virtual machine in the cloud, 10.0.0.3 is a bare metal server in the traditional IDC room, and 10.0.0.4 is a virtual machine in the traditional IDC room. The SDN controller in the cloud and the IDC access switch in the private cloud establish an EVPN neighbor, the relevant VTEP address of the OVS is encapsulated into a class 2 route on the SDN controller for establishing a vxlan tunnel with the IDC access switch, the conversion of the flow table and the EVPN route is performed on the SDN controller, the EVPN class 5 route of 10.0.0.3 and 10.0.0.4 is converted into a flow table and is issued to the corresponding OVS, and 10.0.0.2 is converted into an EVPN class 5 route and is published to the IDC access switch.
[0091] If 10.0.0.4 needs to communicate with 10.0.0.2, the packet of 10.0.0.4 first enters the ordinary virtualized OVS, the OVS adds a vlan header vlan10 to the packet, and then the packet enters the interface of the IDC access switch, the IDC access switch performs a vlan to vxlan mapping, vlan10 is mapped to vxlan10, the packet is stripped of the vlan header and is added with a vxlan header, the vxlan ID is 10, the traffic enters the private line switch, a layer 3 private line vxlan header is added outside the packet, the packet reaches the private line access switch in the public cloud room, the layer 3 private line vxlan header is removed, and then the packet is sent to the corresponding OVS according to the destination address, the packet header with the vxlan ID of 10 is removed on the OVS in the public cloud, and the packet is directly sent to the virtual machine of 10.0.0.2, thereby completing the arrival of the traffic.
[0092] If 10.0.0.3 needs to communicate with 10.0.0.2, the packet of 10.0.0.3 first enters the interface of the IDC access switch, the interface of the IDC access switch is configured as a truck layer 2 port and the pvid is 10, the IDC access switch performs a vlan to vxlan mapping, vlan10 is mapped to vxlan10, the packet is added with a vxlan header, the vxlan ID is 10, the traffic enters the private line switch, a layer 3 private line vxlan header is added outside the packet, the packet reaches the private line access switch in the public cloud room, the layer 3 private line vxlan header is removed, and then the packet is sent to the corresponding OVS according to the destination address, the packet header with the vxlan ID of 10 is removed on the OVS in the public cloud, and the packet is directly sent to the virtual machine of 10.0.0.2, thereby completing the arrival of the traffic.
[0093] Through the above steps, the physical access device can be deployed, the controller and the physical access device establish the BGP EVPN neighbor to convert the route of the network in the cloud, and the function of the two-layer traffic intercommunication between the virtual machine and the traditional IDC room service in the cloud network is achieved.
[0094] It should be noted that the embodiments of the present application include but are not limited to the above examples, and it can be understood that those skilled in the art can also set according to actual needs under the guidance of the idea of the embodiments of the present application, and the present application does not limit this.
[0095] In the embodiments of the present application, by constructing a corresponding network communication architecture, the network communication architecture can include a public cloud room and a private cloud room in communication with the public cloud room, wherein the public cloud room includes an SDN controller, a first private line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first private line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; the private cloud room at least includes a second private line switch, an access switch in communication connection with the second private line switch, and a second device in communication connection with the access switch; wherein the SDN controller and the access switch establish a BGP EVPN session connection, the SDN controller is used to send the first routing information corresponding to the public cloud room to the private cloud room through the BGP EVPN session connection, and the access switch is used to send the second routing information corresponding to the private cloud room to the public cloud room through the BGP EVPN session connection; wherein the first routing information is used to guide the device in the private cloud room to perform traffic forwarding to transmit the traffic to the first device; the second routing information is used to guide the device in the public cloud room to perform traffic forwarding to transmit the traffic to the second device, so that the BGP EVPN neighbor is established by deploying the physical access device, the controller and the physical access device to convert the route of the network in the cloud, the function of the two-layer traffic intercommunication between the virtual machine and the traditional IDC room service in the cloud network is achieved, the intercommunication between the network on the cloud and the network under the cloud can be achieved, the generality of the network communication architecture is improved, and then the flexible migration of the service is ensured.
[0096] It should be noted that for the method embodiments, in order to simply describe, they are all expressed as a series of action combinations, but those skilled in the art should know that the embodiments of the present application are not limited by the order of the described actions, because according to the embodiments of the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.
[0097] For the method embodiment, since it is basically similar to the network architecture embodiment, the description is relatively simple, and the relevant part can refer to the part of the network architecture embodiment.
[0098] In addition, the embodiment of the present application further provides an electronic device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements each process of the communication method embodiment of the network and achieves the same technical effects. To avoid repetition, no further description is given here.
[0099] The embodiment of the present application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program, when executed by a processor, implements each process of the communication method embodiment of the network and achieves the same technical effects. To avoid repetition, no further description is given here. The computer readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0100] Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same or similar parts of each embodiment can be referred to each other.
[0101] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, device, or computer program product. Therefore, the embodiments of the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, EEPROM, Flash, and eMMC, etc.) containing computer usable program code.
[0102] The embodiments of the present application are described with reference to flowcharts and / or block diagrams according to the method, terminal device (system), and computer program product of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to produce a machine, so that the instructions executed by the computer or other programmable data processing terminal device produce a machine that implements the flowcharts and / or block diagrams. Figure 1 one flow or multiple flows and / or blocks Figure 1means for performing the function specified by that block or blocks.
[0103] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the flow Figure 1 one or more flow diagrams and / or blocks Figure 1 means for performing the function specified by that block or blocks.
[0104] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow Figure 1 one or more flow diagrams and / or blocks Figure 1 means for performing the function specified by that block or blocks.
[0105] While preferred embodiments of the application have been described, modifications and variations can be apparent to those skilled in the art once aware of the general underlying concepts. Accordingly, the appended claims are intended to embrace all such modifications and variations as fall within the scope of the application.
[0106] Finally, it should be noted that the terms "first", "second", and the like, herein do not denote any order, quantity, combination, or importance, but rather are used to nomenclature different components to distinguish one component from another component and do not necessarily imply or require any such actual relationship or order. Also, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the presence of additional identical elements in the process, method, article, or apparatus that comprises the element. The terms "exemplary" and "example" are used herein to mean "serving as an example, instance, or illustration," and should not necessarily be construed as preferred or advantageous over other examples.
[0107] The network communication architecture and the network communication method provided by the present application are described in detail above, and the principles and implementation manners of the present application are described by using specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea; meanwhile, for those skilled in the art, the specific implementation manners and application ranges can be changed according to the idea of the present application, and the above description should not be understood as a limitation on the present application.
Claims
1. A network communication architecture, characterized by, The network communication architecture at least comprises a public cloud room and a private cloud room in communication with the public cloud room; wherein, The public cloud room comprises an SDN controller, a first private line switch in communication connection with the SDN controller, a Spine switch in communication connection with the first private line switch, a Leaf switch in communication connection with the Spine switch, and a first device in communication connection with the SDN controller and the Leaf switch respectively; the private cloud room at least comprises a second private line switch, an access switch in communication connection with the second private line switch, and a second device in communication connection with the access switch; Wherein, a BGP EVPN session connection is established between the SDN controller and the access switch, the SDN controller is used to send first routing information corresponding to the public cloud room to the private cloud room through the BGP EVPN session connection, and the access switch is used to send second routing information corresponding to the private cloud room to the public cloud room through the BGP EVPN session connection; Wherein, the first routing information is used to guide the devices in the private cloud room to perform traffic forwarding to transmit traffic to the first device; and the second routing information is used to guide the devices in the public cloud room to perform traffic forwarding to transmit traffic to the second device.
2. The network communication architecture according to claim 1, wherein, A first control connection is established between the SDN controller and the first private line switch, and a second control connection is established between the SDN controller and the second private line switch; Wherein, the SDN controller issues first configuration information corresponding to the first private line switch to the first private line switch through the first control connection, and issues second configuration information corresponding to the second private line switch to the second private line switch through the second control connection.
3. The network communication architecture of claim 2, wherein, The first configuration information and the second configuration information respectively at least comprise one of basic configuration, interface configuration, valn configuration, routing configuration, security configuration, Qos configuration, high availability configuration, and log and monitoring configuration.
4. The network communication architecture according to claim 1 or 2 or 3, wherein, A 3-layer vxlan tunnel is established between the first private line switch and the second private line switch.
5. The network communication architecture according to claim 1, wherein, A third control connection is established between the SDN controller and the access switch; Wherein, the SDN controller is used to issue third configuration information corresponding to the access switch to the access switch through the third control connection.
6. The network communication architecture of claim 5, wherein, The third configuration information at least comprises configuration information related to an Ethernet virtual private network and configuration information related to a virtual extensible local area network tunnel. The configuration information related to the Ethernet virtual private network includes at least one of a neighbor IP address, a remote AS number, an update source interface, a multi-hop configuration, an active address family, a virtual network instance, a route identifier, a route target, and a virtual tunnel endpoint address; and the configuration information related to the virtual extensible local area network tunnel includes at least a VXLAN interface name, a VXLAN type, a remote IP address, a virtual network instance identifier, a flow table rule, a priority, an input port, an output port, and a VLAN tag processing.
7. A network communication method, comprising: The network communication architecture of any one of claims 1 to 6; wherein the first device comprises at least a first virtual switch, and the first virtual switch comprises at least a first virtual machine; the second device comprises at least a second virtual switch, and the second virtual switch comprises at least a second virtual machine; and the method comprises: establishing an EVPN neighbor between the SDN controller and the access switch; the SDN controller obtains a virtual tunnel endpoint address corresponding to the first virtual switch located in the public cloud room, and encapsulates the virtual tunnel endpoint address as a class 2 route; the SDN controller establishes a vxlan tunnel with the access switch based on the class 2 route; the second virtual switch receives the first packet transmitted by the second virtual machine, adds a VLAN header to the first packet, and transmits the first packet to the access switch; the access switch maps the VLAN header in the first packet to a VXLAN header, and transmits the mapped first packet to the second private line switch; the second private line switch adds a three-layer private line VXLAN header to the mapped first packet, and transmits the processed first packet to the first private line switch through a three-layer VXLAN tunnel; the first private line switch removes the three-layer private line VXLAN header, transmits the removed first packet to the first virtual switch; the first virtual switch removes the VXLAN header, obtains the first packet, and transmits the first packet to the first virtual machine.
8. The method of claim 7, wherein, The private cloud room also includes an entity server, and the access switch is configured with a layer 2 port; the method further comprises: the access switch receives a second packet transmitted by the entity server through the layer 2 port, adds a VLAN header to the second packet, maps the VLAN header in the second packet to a VXLAN header, and transmits the mapped second packet to the second private line switch; the second private line switch adds a three-layer private line VXLAN header to the mapped second packet, and transmits the processed second packet to the first private line switch through a three-layer VXLAN tunnel; the first private line switch removes the three-layer private line VXLAN header, transmits the removed second packet to the first virtual switch; the first virtual switch removes the VXLAN header, obtains the second packet, and transmits the second packet to the first virtual machine.
9. An electronic device, comprising: comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory accomplish mutual communication through the communication bus; the memory, configured to store a computer program; the processor, configured to execute the program stored on the memory, so as to realize the method in claim 7 or 8. 10.A computer readable storage medium having stored thereon instructions which, when executed by one or more processors, cause the processors to perform the method in claim 7 or 8.
Citation Information
Patent Citations
Hybrid cloud networking method based on SDN and hybrid cloud network
CN109150737A
Method and device for realizing multiple exits of tenant network in cloud network environment, and medium
CN113645081A