Configuration method, device, equipment and program product of multi-vendor hybrid virtual private network
By collaboratively orchestrating multi-vendor SDN controllers through the SD-WAN application platform, the problem of interconnection between gateways from different vendors in the SD-WAN backbone transmission network is solved, and cross-vendor interconnection and end-to-end automated activation are achieved.
Patent Information
- Application Number
- CN202411962424.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2044-12-27
AI Technical Summary
Gateways from different vendors cannot achieve cross-vendor interconnection in the SD-WAN backbone transmission network, resulting in differences in service access and VPN establishment processes, and inability to achieve end-to-end automated activation.
Use the SD-WAN application platform to achieve collaborative orchestration of multi-vendor SDN controllers, establish neighbor relationships with vendor gateways and SDN controllers from different vendors through the SD-WAN application platform, unify the configuration process, and achieve cross-vendor interconnection.
It achieves interconnection and interoperability within or across multiple vendor domains, eliminates the differences in gateway configuration processes among different vendors, completes end-to-end automated activation of virtual private network services, and supports standardized service access and VPN establishment.
Smart Images

Figure CN119814561B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a configuration method, apparatus, equipment, and program product for a multi-vendor hybrid virtual private network. Background Art
[0002] Software-defined wide area network (SD-WAN) is a service that applies software-defined network (SDN) technology to wide area network scenarios. It can manage wide area network connections in a software-defined manner and support multiple connection methods such as the Internet and 4G / 5G. Compared with multi-protocol label switching virtual private network (MPLS VPN), it has the advantages of rapid deployment and cost savings. It has become an important means for enterprises to innovate network architecture and build industry digitalization in pursuit of cost reduction and efficiency improvement.
[0003] In the current multi-tenant point of presence (POP) SD-WAN solution, POP points are mainly composed of vendor gateways. If an SD-WAN backbone transmission network is built based on the Internet, encrypted tunnels need to be established for data transmission between gateways. However, there are differences in the vendor gateways of different vendors, making cross-vendor interoperability impossible. Summary of the Invention
[0004] This application provides a configuration method, device, equipment and program product for a multi-vendor hybrid virtual private network, which can use the SD-WAN application platform to realize the collaborative orchestration of multi-vendor SDN controllers and achieve interconnection within or across multi-vendor domains.
[0005] In the first aspect, the present application provides a configuration method for a multi-vendor hybrid virtual private network, which is applied to a software-defined wide area network (SD-WAN) application platform; the SD-WAN application platform is connected to vendor software-defined network (SDN) controllers and backbone network (SDN) systems of different vendors; the vendor SDN controller of each vendor is connected to the vendor gateway of the vendor; the method includes: in response to service request information of the service to be allocated, determining the target point of entry (POP) corresponding to the service to be allocated, and calling the backbone network (SDN) system to create a new virtual private network (VPN) for the service to be allocated; the target POP includes a forwarding control device and vendor gateways of multiple vendors connected to the forwarding control device; the forwarding control device is used to forward service data of the service to be allocated to devices outside the network topology area covered by the target POP through the VPN, or to forward service data of the service to be allocated to devices within the network topology area covered by the target POP through the vendor gateway in the target POP; sending connection information of the target vendor gateway to the forwarding control device in the target POP; the target vendor gateway is the vendor gateway called by the service to be allocated; calling the vendor SDN controller of the vendor corresponding to the target vendor gateway to send connection information of the forwarding control device to the target vendor gateway, so that the forwarding control device establishes a neighbor relationship with the target vendor gateway.
[0006] In the configuration method of a multi-vendor hybrid virtual private network provided in the present application, the SD-WAN application platform can respond to the service request information of the service to be allocated, determine the target POP corresponding to the service to be allocated, send the connection information of the target vendor gateway called by the service to be allocated to the forwarding control device in the target POP, and call the vendor SDN controller of the vendor corresponding to the target vendor gateway to send the connection information of the forwarding control device to the target gateway, thereby establishing a neighbor relationship between the forwarding control device and the target vendor gateway. In this way, the automatic setting of the forwarding control device and the target vendor gateway in the target POP is completed, and the target vendor gateway and forwarding control device in the target POP point can forward the service data of the service to be allocated, that is, the target POP point can forward the service data of the service to be allocated, thereby completing the end-to-end automatic activation of the virtual private network service. Compared with the related art in which different vendors independently set up service access and VPN establishment methods, the present application can provide a unified orchestration configuration process for the vendor gateways of different vendors by the SD-WAN application platform, so that the service access and VPN establishment process are standardized, eliminating the differences in the configuration process of the vendor gateways of different vendors, thereby realizing cross-vendor interoperability.
[0007] In addition, the forwarding control device in this application can forward the business data of the service to be allocated to the devices outside the network topology area covered by the target POP through VPN, or forward the business data of the service to be allocated to the devices within the network topology area covered by the target POP through the manufacturer gateway in the target POP, thereby realizing intra-domain or cross-domain interconnection and interoperability of multiple manufacturers.
[0008] Optionally, the forwarding control device includes a provider edge PE device in the target POP; the PE device is physically pre-connected to vendor gateways of multiple vendors; and the vendor gateways of the multiple vendors include a target vendor gateway.
[0009] Optionally, the backbone network SDN system is connected to PE devices in multiple POPs; the multiple POPs include a target POP; sending connection information of the target manufacturer's gateway to the forwarding control device in the target POP includes: calling the backbone network SDN system to send connection information of the target manufacturer's gateway to the PE device in the target POP.
[0010] Optionally, the forwarding control device includes a convergence gateway in the target POP; the convergence gateway is physically pre-connected to vendor gateways of multiple vendors, and the convergence gateway is physically pre-connected to a PE device in the target POP.
[0011] Optionally, the SD-WAN application platform is also connected to the aggregation gateway SDN controller; the aggregation gateway SDN controller is connected to multiple aggregation gateways; the multiple aggregation gateways include the aggregation gateway in the target POP; the connection information of the target manufacturer's gateway is sent to the forwarding control device in the target POP, including: calling the aggregation gateway SDN controller to send the connection information of the target manufacturer's gateway to the aggregation gateway in the target POP.
[0012] It should be understood that as the number of vendor brands increases, the demand for PE device ports becomes excessive, leading to tight resource usage on PE devices. In the multi-vendor hybrid VPN configuration method provided in the embodiments of the present application, the POP can also adopt a three-tier architecture, adding a convergence gateway between the vendor gateway and the PE device. The convergence gateway is physically pre-connected to the vendor gateways of multiple vendors, and the PE device only needs to be physically pre-connected to the convergence gateway, thus saving port resources on the PE device.
[0013] Furthermore, this application proposes two-tier and three-tier POP deployment architectures, both of which enable cross-vendor virtual private network interoperability and support on-demand deployment based on budget and network requirements, maximizing investment returns. Furthermore, the two POP deployment architectures are compatible and interoperable, enabling flexible expansion based on subsequent business needs.
[0014] Optionally, the backbone network SDN system is connected to PE devices in multiple POPs; the multiple POPs include a target POP; the method also includes: calling the backbone network SDN system to send connection information of the aggregation gateway in the target POP to the PE device in the target POP; calling the aggregation gateway SDN controller to send connection information of the PE device in the target POP to the aggregation gateway in the target POP, so that the aggregation gateway in the target POP and the PE device in the target POP establish a neighbor relationship.
[0015] Optionally, the method also includes: calling the aggregation gateway SDN controller to send service configuration information of the service to be allocated to the aggregation gateway in the target POP; the service configuration information includes: the port for transmitting the service data of the service to be allocated, the bandwidth allocated for the service to be allocated, the identity of the VPN of the service to be allocated, the identity of the autonomous system to which the aggregation gateway in the target POP belongs, and the identity of the virtual local area network allocated for the service to be allocated.
[0016] Optionally, the manufacturer SDN controller of each manufacturer is connected to the manufacturer terminal device of the manufacturer; the method also includes: calling the manufacturer SDN controller of the manufacturer corresponding to the target manufacturer gateway to send the connection information of the target manufacturer gateway and the service configuration information of the service to be allocated to the target manufacturer terminal device, so that the target manufacturer terminal device and the target manufacturer gateway establish an encrypted transmission tunnel.
[0017] Optionally, the backbone network SDN system is called to create a new virtual private network VPN for the service to be allocated, including: based on the service request information indication, requesting to establish a VPN that is mutually communicating with the existing multi-protocol label switching MPLS VPN, and obtaining the networking parameters of the existing MPLS VPN; sending the networking request parameters including the networking parameters of the existing MPLS VPN to the backbone network SDN system, so that the backbone network SDN system creates a new VPN that is mutually communicating with the existing MPLS VPN for the service to be allocated.
[0018] In the configuration method of a multi-vendor hybrid virtual private network provided in an embodiment of the present application, the SD-WAN application platform can also send networking request parameters including existing MPLS VPN networking parameters to the backbone network SDN system. The backbone network SDN system can create a new VPN for the service to be allocated that is connected to the existing MPLS VPN for communication, thereby achieving interconnection between the newly created VPN service and the existing MPLSVPN service, meeting the needs of multi-type hybrid networking.
[0019] In a second aspect, the present application provides a configuration device for a multi-vendor hybrid virtual private network, which includes various functional modules used in the method described in the first aspect above.
[0020] In a third aspect, the present application provides a computer program product, comprising: computer instructions; when the computer instructions are executed on an electronic device, the electronic device implements the method described in the first aspect above.
[0021] In a fourth aspect, the present application provides an electronic device comprising: a processor and a memory; the memory stores instructions executable by the processor; when the processor is configured to execute the instructions, the electronic device implements the method described in the first aspect above.
[0022] In a fifth aspect, the present application provides a readable storage medium, which includes: software instructions; when the software instructions are executed in an electronic device, the electronic device implements the method described in the first aspect above.
[0023] The beneficial effects of the second to fifth aspects mentioned above can be referred to the first aspect and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0025] Figure 1 A schematic diagram of the configuration system for a multi-vendor hybrid virtual private network provided in an embodiment of the present application;
[0026] Figure 2 A schematic diagram of the primary and backup redundant deployment of the first POP 400 provided in an embodiment of the present application;
[0027] Figure 3 A schematic diagram of the primary-backup redundant deployment of the second POP 500 provided in an embodiment of the present application;
[0028] Figure 4 A flowchart of a method for configuring a multi-vendor hybrid virtual private network provided in an embodiment of the present application;
[0029] Figure 5 A schematic diagram of the configuration apparatus for a multi-vendor hybrid virtual private network provided in an embodiment of the present application;
[0030] Figure 6 A schematic diagram of the composition of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0031] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0032] It should be noted that in the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described in the embodiments of this application as "exemplarily" or "for example" should not be interpreted as being more preferred or advantageous than other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.
[0033] In order to facilitate a clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art can understand that words such as "first" and "second" do not limit the quantity and execution order.
[0034] As a service that applies SDN technology to wide area network scenarios, SD-WAN can manage wide area network connections in a software-defined manner and support multiple connection methods such as the Internet, 4G / 5G, etc. Compared with MPLS VPN, it has the advantages of rapid deployment and cost savings. It has become an important means for enterprises to innovate network architecture and build industry digitalization in pursuit of cost reduction and efficiency improvement.
[0035] In the current SD-WAN solution for multi-tenant POP (providing services to multiple tenants at the same time at one POP), it is necessary to build a manufacturer gateway to build the SD-WAN transmission backbone network. The POP point is mainly composed of the manufacturer gateway. The manufacturer terminal equipment on the enterprise side establishes an Internet encrypted tunnel with the manufacturer gateway. The manufacturer gateway decapsulates the data and forwards the data to the gateway connected to the destination site. The gateway then forwards the data to the manufacturer terminal equipment on the enterprise side of the destination site, thereby realizing end-to-end network access.
[0036] If an SD-WAN backbone transmission network is built based on Internet lines, an encrypted tunnel needs to be established to transmit data between gateways. However, there are differences in gateways from different manufacturers, making it impossible to achieve cross-manufacturer interoperability.
[0037] Based on this, the embodiments of the present application provide a configuration method, device, equipment and program product for a multi-vendor hybrid virtual private network, which can use the SD-WAN application platform to realize the collaborative orchestration of multi-vendor SDN controllers and achieve interconnection within or across multi-vendor domains.
[0038] The following is an introduction with reference to the accompanying drawings.
[0039] Figure 1 This is a schematic diagram of the configuration system of a multi-vendor hybrid virtual private network provided in the embodiment of the present application. Figure 1 As shown, the system includes: an SD-WAN application platform 100, a manufacturer SDN controller 200, a backbone network SDN system 300, a first POP 400, a second POP 500, and a manufacturer terminal device 600.
[0040] The SD-WAN application platform 100 can be deployed on electronic devices with computing and processing capabilities, such as servers or computers.
[0041] Among them, the server can be a single server, or it can be a server cluster composed of multiple servers. In some implementations, the server cluster can also be a distributed cluster. Optionally, the server can also be implemented on a cloud platform. For example, the cloud platform can include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an inter-cloud, and a multi-cloud, etc., or any combination thereof. This is not limited to the embodiments of the present application.
[0042] The SD-WAN application platform 100 can be used to collaboratively orchestrate the manufacturer's SDN controller 200 and the backbone network SDN system 300, and support end-to-end automated activation of virtual private network services between the first POP 400, the second POP 500, and the manufacturer's terminal equipment 600. The specific process can be referred to the configuration method of the multi-vendor hybrid virtual private network provided in the following embodiment, and will not be repeated here.
[0043] The vendor SDN controller 200 may include vendor SDN controllers of multiple different vendors ( Figure 1 In the example, four vendor SDN controllers, namely, vendor A SDN controller, vendor B SDN controller, vendor C SDN controller, and vendor D SDN controller, are used. Each vendor SDN controller is connected to the vendor gateway of the vendor ( Figure 1 In the figure, the SDN controller of manufacturer A is connected to the gateway of manufacturer A in the first POP 400, the SDN controller of manufacturer B is connected to the gateway of manufacturer B in the first POP 400, the SDN controller of manufacturer C is connected to the gateway of manufacturer C in the second POP 500, and the SDN controller of manufacturer D is connected to the gateway of manufacturer D in the second POP 500 as an example).
[0044] In some embodiments, the vendor SDN controller 200 can also be connected to vendor terminal devices of multiple vendors in the vendor terminal device 600 ( Figure 1 In the figure, the connection between the SDN controller of manufacturer A and the terminal device of manufacturer A in the manufacturer terminal device 600, the connection between the SDN controller of manufacturer B and the terminal device of manufacturer B in the manufacturer terminal device 600, the connection between the SDN controller of manufacturer C and the terminal device of manufacturer C in the manufacturer terminal device 600, and the connection between the SDN controller of manufacturer D and the terminal device of manufacturer D in the manufacturer terminal device 600 are used as examples).
[0045] The vendor SDN controller 200 can be used to send connection information or service configuration information to the corresponding connected vendor gateway and vendor terminal device. For details, please refer to the configuration method of the multi-vendor hybrid virtual private network provided in the following embodiment, which will not be repeated here.
[0046] The backbone network SDN system 300 can be used to create a VPN. The specific process can be referred to in the related art and will not be repeated here.
[0047] In some embodiments, the backbone network SDN system 300 may also be connected to a PE device in a POP to send connection information or service configuration information to the PE device, etc. This embodiment of the present application does not limit this.
[0048] The first POP 400 may be a three-tiered POP. The first tier may include vendor gateways of different vendors ( Figure 1 The following example uses two vendor gateways, one from vendor A and one from vendor B, as examples. The second layer may include a convergence gateway. The third layer may include provider edge (PE) devices. Enterprise-side vendor terminal devices can establish encrypted transmission tunnels with the vendor gateways on the first layer. The vendor terminal devices can transmit encapsulated service data to the vendor gateways via the encrypted transmission tunnels, and the vendor gateways can transmit decapsulated service data to the convergence gateways.
[0049] In the case of cross-vendor mutual access within the domain (or within the network topology covered by the first POP 400), the aggregation gateway can forward the business data transmitted by the gateway of manufacturer A to the gateway of manufacturer B, and the gateway of manufacturer B can forward the business data to the terminal device of manufacturer B, thereby realizing cross-vendor mutual access within the domain.
[0050] In the case of cross-domain access (or outside the network topology covered by the first POP 400), the aggregation gateway can aggregate the business data of multiple vendor gateways and transmit it to the PE device, which then transmits customer routes and business data through the MPLS VPN backbone network.
[0051] For example, the terminal device of manufacturer A can transmit business data to the gateway of manufacturer A, and then transmit it to the aggregation gateway. The aggregation gateway transmits the business data to the PE device. The PE device can transmit it to the PE device in the second POP 500 through the MPLS VPN backbone network, and transmit the business data to the terminal device of manufacturer D through the gateway of manufacturer D.
[0052] In some embodiments, in order to improve the reliability of the POP, the first-layer vendor gateway, the second-layer aggregation gateway, and the third-layer PE device in the first POP 400 can all be deployed in active / standby redundancy. Figure 2 The following is a schematic diagram of the primary and backup redundant deployment of the first POP 400 provided in the embodiment of the present application. Figure 2 As shown, the first layer of the first POP 400 may specifically include multiple vendor gateways ( Figure 2 In the example, the gateways A and B of manufacturer A and B of manufacturer B are used as examples. The second layer of the first POP 400 may include multiple aggregation gateways ( Figure 2 In the figure, two convergence gateways, convergence gateway 1 and convergence gateway 2, are used as examples. Each convergence gateway can be connected to all the vendor gateways in the first POP 400. The third layer of the first POP 400 can specifically include multiple PE devices ( Figure 2 In the figure, PE device 1 and PE device 2 are used as an example. Each PE device is connected to a convergence gateway ( Figure 2 In the figure, PE device 1 is connected to aggregation gateway 1, and PE device 2 is connected to aggregation gateway 2 as an example.
[0053] In some possible embodiments, Figure 1 As shown, the multi-vendor hybrid VPN configuration system may further include a convergence gateway SDN controller 700. The convergence gateway SDN controller 700 may be connected to a convergence gateway in a POP (e.g., the first POP 400 described above). The convergence gateway SDN controller 700 may be configured to send connection information or service configuration information to the connected convergence gateway. For details, please refer to the multi-vendor hybrid VPN configuration method provided in the following embodiment and will not be repeated here.
[0054] The second POP 500 may be a POP with a two-layer architecture. The first layer may include vendor gateways of different vendors ( Figure 1(The following example uses vendor gateways from two vendors, C and D, as examples.) The second layer can include PE devices. Enterprise-side vendor terminal devices can establish encrypted transmission tunnels with the vendor gateways in the first layer. The vendor terminal devices can transmit encapsulated service data to the vendor gateways via the encrypted transmission tunnels, and the vendor gateways can transmit decapsulated service data to the PE devices.
[0055] In the case of cross-vendor intercommunication within the domain (or within the network topology covered by the second POP 500), the PE device can forward the business data transmitted by the C manufacturer gateway to the D manufacturer gateway, and the D manufacturer gateway can forward the business data to the D manufacturer terminal device, thereby realizing cross-vendor intercommunication within the domain.
[0056] In the case of cross-domain access (or outside the network topology covered by the second POP 500), after the service data is transmitted to the PE device, the backbone side can transmit the customer route and service data through the MPLS VPN backbone network.
[0057] For example, the terminal device of manufacturer D can transmit business data to the gateway of manufacturer D, and then to the PE device. The PE device can transmit the business data to the PE device in the first POP 400 through the MPLS VPN backbone network, and then transmit the business data to the terminal device of manufacturer A through the aggregation gateway and the gateway of manufacturer A in turn.
[0058] In some embodiments, in order to improve the reliability of the POP, the first-tier vendor gateway in the second POP 500 can be deployed in a primary-backup redundant manner. Figure 3 The following is a schematic diagram of the primary and backup redundant deployment of the second POP 500 provided in the embodiment of the present application. Figure 3 As shown, the first layer of the second POP 500 may specifically include multiple vendor gateways ( Figure 3 In the figure, Vendor A Gateway 1 and Vendor A Gateway 2 of Vendor A, and Vendor B Gateway 1 and Vendor B Gateway 2 of Vendor B are used as examples. The PE devices of the second layer of the second POP 500 can be connected to all the vendor gateways in the first layer of the second POP 500 respectively.
[0059] It should be noted that, considering the increase in the number of manufacturers' brands, the demand for PE device ports is too large, which will lead to tight resource usage of PE devices. Therefore, in the two-tier architecture POP active-standby redundant deployment solution, different manufacturers' gateways of the same manufacturer can be connected to one port of a PE device ( Figure 3 In the example, Manufacturer A's Gateway 1 and Manufacturer A's Gateway 2 are connected to one port of the PE device, and Manufacturer B's Gateway 1 and Manufacturer B's Gateway 2 are connected to another interface of the PE device.
[0060] It should be noted that the above Figure 1 The configuration system for a multi-vendor hybrid VPN provided by the embodiment of the present application is described by taking a first POP 400 and a second POP 500 of two POPs with different architectures as examples. The system may include more or fewer POPs, which may adopt the three-tier architecture shown in the first POP 400 or the two-tier architecture shown in the second POP 500. The embodiment of the present application does not limit this.
[0061] Optionally, the POP in the multi-vendor hybrid virtual private network configuration system can be deployed in the MPLS VPN backbone network room.
[0062] The execution subject of the configuration method of the multi-vendor hybrid virtual private network provided in the embodiment of the present application is an SD-WAN application platform (for example, the above-mentioned SD-WAN application platform 100). Optionally, the execution subject of the configuration method of the multi-vendor hybrid virtual private network may also be an electronic device deployed with the aforementioned SD-WAN application platform; or, it may also be a processor (for example, a central processing unit (CPU)) in the aforementioned electronic device; or, it may also be a functional module in the aforementioned electronic device for executing the configuration method of the multi-vendor hybrid virtual private network, etc. The embodiment of the present application does not impose any restrictions on this.
[0063] For the sake of simplicity, the following will use the SD-WAN application platform as an example to introduce the configuration method of a multi-vendor hybrid virtual private network provided in the embodiment of the present application.
[0064] Figure 4 This is a flow chart of the configuration method of a multi-vendor hybrid virtual private network provided in the embodiment of the present application. Figure 4 As shown, the method includes the following steps:
[0065] S101 : In response to service request information of a service to be allocated, determine a target point of presence (POP) corresponding to the service to be allocated, and call a backbone network SDN system to create a new virtual private network (VPN) for the service to be allocated.
[0066] The target POP includes a forwarding control device and multiple vendor gateways connected to the forwarding control device. The forwarding control device can be understood as the convergence gateway in the first POP 400 of the three-tier architecture or the PE device in the second POP 500 of the two-tier architecture.
[0067] The forwarding control device can be used to forward the business data of the service to be allocated to the devices outside the network topology area covered by the target POP through VPN (that is, the business data forwarding in the case of cross-domain access mentioned above), or to forward the business data of the service to be allocated to the devices within the network topology area covered by the target POP through the manufacturer gateway in the target POP (that is, the business data forwarding in the case of intra-domain mutual access mentioned above).
[0068] For example, the forwarding control device can check the destination Internet Protocol (IP) address of the service data and determine whether to forward it to the outside of the domain through the VPN or directly forward it within the domain based on the IP address range of the network topology area covered by the preset target POP.
[0069] In one possible implementation, the service request information can directly specify the POP to be used for the service to be allocated, and the SD-WAN application platform can directly use the POP indicated in the service request information as the target POP.
[0070] In another possible implementation, the service request information may include demand information of the service to be allocated (for example, the demand information may specifically include a geographical location range), and the SD-WAN application platform may determine the target POP based on the demand information and the capability information of multiple preset POPs (for example, selecting a POP whose geographical location is within the geographical location range required by the demand information).
[0071] In some possible embodiments, before the above S101, the SD-WAN application platform may also obtain service request information of the service to be allocated.
[0072] For example, the SD-WAN application platform can also be connected to the service orchestration system. The service orchestration system can obtain and aggregate service request information of different services from user devices, and send the service request information of the services to be allocated to the SD-WAN application platform.
[0073] For another example, the SD-WAN application platform can also be connected to the user equipment, and the SD-WAN application platform can receive service request information of the service to be allocated sent by the user equipment.
[0074] In some embodiments, after determining the target POP point, the SD-WAN application platform can also allocate the required virtual private network resources for the business to be allocated.
[0075] S102: Send the connection information of the target manufacturer's gateway to the forwarding control device in the target POP.
[0076] The target vendor gateway is the vendor gateway called by the service to be allocated. The connection information of the target vendor gateway may include the port information of the target vendor gateway and the type of communication protocol for communicating with the target vendor gateway.
[0077] For example, the SD-WAN application platform can first determine the target manufacturer's gateway based on the service request information.
[0078] Optionally, the vendor gateway may be directly specified in the service request information, and the SD-WAN application platform may use the vendor gateway specified in the service request information as the target vendor gateway.
[0079] Optionally, the service request information may include the demand information for the manufacturer gateway of the service to be allocated (for example, the demand information for the manufacturer gateway may specifically include the geographical location range of the manufacturer and the manufacturer gateway, etc.). The SD-WAN application platform may specifically determine the target manufacturer gateway based on the demand information for the manufacturer gateway and the attribute information of multiple preset manufacturer gateways (for example, select the manufacturer gateway that meets the geographical location range from all the manufacturer gateways of the manufacturer indicated by the demand information).
[0080] As an example, when the forwarding control device is a convergence gateway, the communication protocol used by the forwarding control device to communicate with the target vendor gateway may specifically be the Internal Border Gateway Protocol (IBGP).
[0081] As another example, when the forwarding control device is a PE device, the communication protocol used by the forwarding control device to communicate with the target vendor gateway may specifically be the External Border Gateway Protocol (EBGP).
[0082] S103: Invoke the vendor SDN controller of the vendor corresponding to the target vendor gateway to send connection information of the forwarding control device to the target vendor gateway, so that the forwarding control device establishes a neighbor relationship with the target vendor gateway.
[0083] The connection information of the forwarding control device may include port information of the forwarding control device and the type of communication protocol for communicating with the forwarding control device.
[0084] As an example, as described above, when the forwarding control device is a convergence gateway, the communication protocol used by the forwarding control device and the target vendor gateway to communicate may be IBGP. In this case, the forwarding control device and the target vendor gateway may establish an IBGP neighbor relationship.
[0085] As another example, as described above, when the forwarding control device is a PE device, the communication protocol used by the forwarding control device and the target vendor gateway to communicate may be EBGP. In this case, the forwarding control device and the target vendor gateway may establish an EBGP neighbor relationship.
[0086] Optionally, the SD-WAN application platform may also call the vendor SDN controller of the target vendor gateway corresponding to the vendor to send service configuration information of the service to be allocated to the target vendor gateway.
[0087] Among them, the service configuration information may include: the port for transmitting the service data of the service to be allocated, the bandwidth allocated for the service to be allocated, the identity of the VPN of the service to be allocated, the identity of the autonomous system (AS) to which the aggregation gateway in the target POP belongs, and the identity of the virtual local area network allocated for the service to be allocated.
[0088] In the configuration method of a multi-vendor hybrid virtual private network provided in an embodiment of the present application, the SD-WAN application platform can respond to the service request information of the service to be allocated, determine the target POP corresponding to the service to be allocated, send the connection information of the target vendor gateway called by the service to be allocated to the forwarding control device in the target POP, and call the vendor SDN controller of the vendor corresponding to the target vendor gateway to send the connection information of the forwarding control device to the target gateway, thereby establishing a neighbor relationship between the forwarding control device and the target vendor gateway. In this way, the automatic setting of the forwarding control device and the target vendor gateway in the target POP is completed, and the target vendor gateway and forwarding control device in the target POP point can forward the service data of the service to be allocated, that is, the target POP point can forward the service data of the service to be allocated, thereby completing the end-to-end automatic activation of the virtual private network service. Compared with the related art in which different vendors independently set up service access and VPN establishment methods, the present application can provide a unified orchestration configuration process for the vendor gateways of different vendors by the SD-WAN application platform, so that the service access and VPN establishment process are standardized, eliminating the differences in the configuration process of the vendor gateways of different vendors, thereby achieving cross-vendor interoperability.
[0089] In addition, the forwarding control device in this application can forward the business data of the service to be allocated to the devices outside the network topology area covered by the target POP through VPN, or forward the business data of the service to be allocated to the devices within the network topology area covered by the target POP through the manufacturer gateway in the target POP, thereby realizing intra-domain or cross-domain interconnection and interoperability of multiple manufacturers.
[0090] The following describes the process of establishing the VPN for the service to be allocated in S101.
[0091] In some possible embodiments, the above S101 may specifically include the following steps:
[0092] Step 1a: Based on the service request information, a request is made to establish a VPN that communicates with an existing Multi-Protocol Label Switching (MPLS) VPN, and networking parameters of the existing MPLS VPN are obtained.
[0093] Optionally, the networking parameters of the existing MPLS VPN may specifically include network address parameters (e.g., the public IP address of the interface connecting the PE device to the public network), VPN instance parameters (e.g., the VPN instance name), routing protocol parameters (e.g., IGP protocol parameters or BGP protocol parameters), etc. The embodiments of the present application do not limit the specific content of the networking parameters.
[0094] As an example, the SD-WAN application platform can obtain the networking parameters of the existing MPLS VPN through the network management system (NMS), or can query the networking parameters of the existing MPLS VPN through the connected network devices related to the MPLS VPN (such as PE devices), or can obtain the networking parameters of the MPLS VPN through manual input. The embodiments of the present application are not limited to this.
[0095] Step 2a: Sending networking request parameters including existing MPLS VPN networking parameters to the backbone network SDN system, so that the backbone network SDN system creates a new VPN for the service to be allocated that is in communication connection with the existing MPLS VPN.
[0096] In the configuration method of a multi-vendor hybrid virtual private network provided in an embodiment of the present application, the SD-WAN application platform can also send networking request parameters including existing MPLS VPN networking parameters to the backbone network SDN system. The backbone network SDN system can create a new VPN for the service to be allocated that is connected to the existing MPLS VPN for communication, thereby achieving interconnection between the newly created VPN service and the existing MPLSVPN service, meeting the needs of multi-type hybrid networking.
[0097] The specific process of the above S102 is introduced below.
[0098] In some possible embodiments, as shown in the first POP 400 above, the target POP may specifically be a three-tier architecture as shown in the first POP 400 above. The forwarding control device may specifically include a convergence gateway in the target POP, the convergence gateway being physically pre-connected to multiple vendor gateways, and the convergence gateway being physically pre-connected to PE devices in the target POP. In this case, the above S102 may specifically include the following steps:
[0099] Step 1b: Call the aggregation gateway SDN controller to send the connection information of the target manufacturer gateway to the aggregation gateway in the target POP.
[0100] In other possible embodiments, as shown in the second POP 500 above, the target POP may specifically be a two-tier architecture as shown in the second POP 500 above. The forwarding control device may specifically include a PE device in the target POP, the PE device being physically pre-connected to multiple vendor gateways, the multiple vendor gateways including the target vendor gateway. In this case, S102 above may specifically include the following steps:
[0101] Step 1c: Call the backbone network SDN system to send the connection information of the target manufacturer's gateway to the PE device in the target POP.
[0102] It should be understood that as the number of vendor brands increases, the demand for PE device ports becomes excessive, leading to tight resource usage on PE devices. In the multi-vendor hybrid VPN configuration method provided in the embodiments of the present application, the POP can also adopt a three-tier architecture, adding a convergence gateway between the vendor gateway and the PE device. The convergence gateway is physically pre-connected to the vendor gateways of multiple vendors, and the PE device only needs to be physically pre-connected to the convergence gateway, thus saving port resources on the PE device.
[0103] Furthermore, the present application proposes two-tier and three-tier POP deployment architectures, both of which enable cross-vendor virtual private network interoperability and support on-demand deployment based on budget and network requirements, maximizing investment returns. Furthermore, the two POP deployment architectures are compatible and interoperable, enabling flexible expansion based on subsequent business needs.
[0104] In some embodiments, the SD-WAN application platform may also establish a neighbor relationship between the aggregation gateway and the PE device. In this case, the method may also include the following steps:
[0105] Step 1d: Call the backbone network SDN system to send the connection information of the aggregation gateway in the target POP to the PE device in the target POP.
[0106] The connection information may be specifically described in S102 or S103 above, which will not be repeated here.
[0107] Step 2d: Call the aggregation gateway SDN controller to send the connection information of the PE device in the target POP to the aggregation gateway in the target POP, so that the aggregation gateway in the target POP and the PE device in the target POP establish a neighbor relationship.
[0108] In some embodiments, in order to meet the isolation requirements of different services, the SD-WAN application platform can also configure the service configuration information of the service to be allocated for the aggregation gateway. In this case, the method can also include the following steps:
[0109] Step 1e: Call the aggregation gateway SDN controller to send the service configuration information of the service to be allocated to the aggregation gateway in the target POP.
[0110] Among them, the service configuration information may include: the port for transmitting service data of the service to be allocated, the bandwidth allocated for the service to be allocated, the identity of the VPN of the service to be allocated, the identity of the autonomous system to which the aggregation gateway in the target POP belongs, and the identity of the virtual LAN allocated for the service to be allocated.
[0111] In some possible embodiments, the services to be allocated may be performed specifically through the manufacturer's terminal equipment, and the SD-WAN application platform may also configure the manufacturer's terminal equipment. In this case, the method may further include the following steps:
[0112] Step 1f: Call the vendor SDN controller of the target vendor gateway to send the target vendor gateway connection information and service configuration information of the service to be allocated to the target vendor terminal device, so that the target vendor terminal device and the target vendor gateway establish an encrypted transmission tunnel.
[0113] Optionally, the SD-WAN application platform can also send WAN port configuration information and LAN port configuration information to the manufacturer's terminal equipment.
[0114] Optionally, the target manufacturer gateway may include multiple manufacturer gateways of one manufacturer. In this case, the target manufacturer terminal device may respectively establish encrypted primary and backup transmission tunnels for the multiple manufacturer gateways of the manufacturer.
[0115] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. In order to realize the above functions, the SD-WAN platform or the electronic device deploying the SD-WAN platform includes the corresponding hardware structure and / or software modules for performing each function. It should be easy to realize that the technical goals in this field are combined with the units and algorithm steps of each example described in the embodiments disclosed in this document, and the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technical goals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0116] In an exemplary embodiment, the embodiment of the present application also provides a configuration device for a multi-vendor hybrid virtual private network, which can be applied to the above-mentioned SD-WAN application platform. Figure 5 This is a schematic diagram of the configuration device for a multi-vendor hybrid virtual private network provided in an embodiment of the present application. Figure 5 As shown, the device includes: a processing module 501.
[0117] Processing module 501 is used to respond to the service request information of the service to be allocated, determine the target point of entry POP corresponding to the service to be allocated, and call the backbone network SDN system to create a new virtual private network VPN for the service to be allocated; the target POP includes a forwarding control device and multiple vendor gateways connected to the forwarding control device; the forwarding control device is used to forward the service data of the service to be allocated to the device outside the network topology area covered by the target POP through the VPN, or forward the service data of the service to be allocated to the device within the network topology area covered by the target POP through the vendor gateway in the target POP; send the connection information of the target vendor gateway to the forwarding control device in the target POP; the target vendor gateway is the vendor gateway called by the service to be allocated; the connection information of the target vendor gateway is used to indicate the address information of the target vendor gateway and the type of communication protocol for communicating with the target vendor gateway; call the vendor SDN controller of the vendor corresponding to the target vendor gateway to send the connection information of the forwarding control device to the target vendor gateway, so that the forwarding control device and the target vendor gateway establish a neighbor relationship; the connection information of the forwarding control device is used to indicate the address information of the forwarding control device and the type of communication protocol for communicating with the forwarding control device.
[0118] In some possible embodiments, the forwarding control device includes a provider edge (PE) device in a target POP; the PE device is physically pre-connected to vendor gateways of multiple vendors; and the vendor gateways of the multiple vendors include a target vendor gateway.
[0119] In some other possible embodiments, the backbone network SDN system is connected to PE devices in multiple POPs; the multiple POPs include a target POP; the processing module 501 is specifically used to call the backbone network SDN system to send connection information of the target manufacturer gateway to the PE device in the target POP.
[0120] In some other possible embodiments, the forwarding control device includes a convergence gateway in the target POP; the convergence gateway is physically pre-connected to vendor gateways of multiple vendors, and the convergence gateway is physically pre-connected to a PE device in the target POP.
[0121] In some other possible embodiments, the SD-WAN application platform is also connected to the aggregation gateway SDN controller; the aggregation gateway SDN controller is connected to multiple aggregation gateways; the multiple aggregation gateways include the aggregation gateway in the target POP; the processing module 501 is specifically used to call the aggregation gateway SDN controller to send the connection information of the target manufacturer gateway to the aggregation gateway in the target POP.
[0122] In some other possible embodiments, the backbone network SDN system is connected to PE devices in multiple POPs; the multiple POPs include a target POP; the processing module 501 is also used to call the backbone network SDN system to send connection information of the aggregation gateway in the target POP to the PE device in the target POP; and call the aggregation gateway SDN controller to send connection information of the PE device in the target POP to the aggregation gateway in the target POP, so that the aggregation gateway in the target POP and the PE device in the target POP establish a neighbor relationship.
[0123] In some other possible embodiments, the processing module 501 is also used to call the aggregation gateway SDN controller to send service configuration information of the service to be allocated to the aggregation gateway in the target POP; the service configuration information includes: the port for transmitting the service data of the service to be allocated, the bandwidth allocated for the service to be allocated, the identity of the VPN of the service to be allocated, the identity of the autonomous system to which the aggregation gateway in the target POP belongs, and the identity of the virtual LAN allocated for the service to be allocated.
[0124] In some other possible embodiments, the manufacturer SDN controller of each manufacturer is connected to the manufacturer terminal device of the manufacturer; the processing module 501 is also used to call the manufacturer SDN controller of the manufacturer corresponding to the target manufacturer gateway to send the connection information of the target manufacturer gateway and the service configuration information of the service to be allocated to the target manufacturer terminal device, so that the target manufacturer terminal device and the target manufacturer gateway establish an encrypted transmission tunnel.
[0125] In some other possible embodiments, the processing module 501 is specifically used to request to establish a VPN that is connected to the existing Multi-Protocol Label Switching MPLS VPN based on the service request information indication, and obtain the networking parameters of the existing MPLS VPN; send the networking request parameters including the networking parameters of the existing MPLS VPN to the backbone network SDN system, so that the backbone network SDN system creates a new VPN that is connected to the existing MPLS VPN for the service to be allocated.
[0126] It should be noted that Figure 5The module division described is illustrative and represents only one logical functional division. Actual implementations may employ different divisions. For example, two or more functions may be integrated into a single processing module. These integrated modules may be implemented as either hardware or software functional modules.
[0127] In an exemplary embodiment, as described above, the SD-WAN application platform can be deployed on an electronic device with computing and processing capabilities, such as a computer or server. In this case, the embodiment of the present application also provides an electronic device, Figure 6 This is a schematic diagram of the composition of the electronic device provided in the embodiment of the present application. Figure 6 As shown, the electronic device includes: a processor 10 , a memory 20 , a communication line 30 , a communication interface 40 , and an input / output interface 50 .
[0128] The processor 10 , the memory 20 , the communication interface 40 , and the input / output interface 50 may be connected via a communication line 30 .
[0129] The processor 10 is used to execute the instructions stored in the memory 20 to implement the configuration method of the multi-vendor hybrid virtual private network provided in the above embodiment of the present application. The processor 10 can be a CPU, a general-purpose processor network processor (network processor, NP), a digital signal processor (digital signal processing, DSP), a microprocessor, a microcontroller (micro control unit, MCU) / single-chip microcomputer / single-chip microcomputer, a programmable logic device (programmable logic device, PLD) or any combination thereof. The processor 10 can also be any other device with processing functions, such as a circuit, device or software module, and the embodiment of the present application does not limit this. In one example, the processor 10 may include one or more CPUs, such as Figure 6 As an optional implementation, the electronic device may include multiple processors, for example, in addition to the processor 10, it may also include a processor 60 ( Figure 6 The dashed line is used as an example.
[0130] The memory 20 is used to store instructions. For example, the instruction may be a computer program. Optionally, the memory 20 may be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, etc., and the embodiments of the present application are not limited thereto.
[0131] It should be noted that the memory 20 may exist independently of the processor 10 or may be integrated with the processor 10. The memory 20 may be located inside the electronic device or outside the electronic device, which is not limited in the embodiment of the present application.
[0132] The communication line 30 is used to transmit information between the components included in the electronic device.
[0133] Communication interface 40 is used to communicate with other devices or other communication networks. Such other communication networks may be Ethernet, radio access networks (RAN), wireless local area networks (WLAN), etc. Communication interface 40 may be a module, circuit, transceiver, or any other device capable of communication.
[0134] The input / output interface 50 is used to implement human-computer interaction between a user and the electronic device, for example, to implement action interaction or information interaction between the user and the electronic device.
[0135] For example, the input / output interface 50 may be a mouse, keyboard, display screen, or touch screen screen, etc. Action interaction or information interaction between a user and the electronic device may be achieved through the mouse, keyboard, display screen, or touch screen screen, etc.
[0136] It should be noted that Figure 6 The structure shown in the figure does not constitute a limitation on the electronic device, except Figure 6 In addition to the components shown, the electronic device may include more or fewer components than shown, or a combination of certain components, or a different arrangement of components.
[0137] In an exemplary embodiment, the present application also provides a computer program product, which includes computer instructions. When the computer instructions are executed in an electronic device, the electronic device implements the method in the aforementioned method embodiment.
[0138] In an exemplary embodiment, the present application also provides a computer-readable storage medium including software instructions. When the software instructions are executed in an electronic device, the electronic device implements the method in the aforementioned method embodiment. The computer-readable storage medium can be a non-transitory computer-readable storage medium, for example, a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0139] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer-executable instructions. When the computer-executable instructions are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer-executable instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer-executable instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0140] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "one" or "an" does not exclude multiple components. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.
[0141] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.
[0142] The above is only a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for configuring a multi-vendor hybrid virtual private network, characterized in that: The method is applied to a software-defined wide area network (SD-WAN) application platform; the SD-WAN application platform is connected to vendor software-defined network (SDN) controllers and backbone network (SDN) systems of different vendors; each vendor SDN controller is connected to the vendor gateway of that vendor; The method comprises: In response to service request information of a service to be allocated, a target point of presence (POP) corresponding to the service to be allocated is determined, and the backbone network SDN system is called to create a new virtual private network (VPN) for the service to be allocated; the target POP includes a forwarding control device and multiple vendor gateways connected to the forwarding control device; the forwarding control device is used to forward service data of the service to be allocated to devices outside the network topology area covered by the target POP through the VPN, or to forward service data of the service to be allocated to devices within the network topology area covered by the target POP through the vendor gateway in the target POP; Sending connection information of a target vendor gateway to the forwarding control device in the target POP; the target vendor gateway is the vendor gateway called by the service to be allocated; The vendor SDN controller of the vendor corresponding to the target vendor gateway is called to send the connection information of the forwarding control device to the target vendor gateway, so that the forwarding control device establishes a neighbor relationship with the target vendor gateway.
2. The method according to claim 1, characterized in that The forwarding control device includes a provider edge (PE) device in the target POP; the PE device is physically pre-connected to vendor gateways of multiple vendors; and the vendor gateways of the multiple vendors include the target vendor gateway.
3. The method according to claim 2, characterized in that The backbone network SDN system is connected to PE devices in multiple POPs; the multiple POPs include the target POP; and the sending of connection information of the target vendor gateway to the forwarding control device in the target POP includes: The backbone network SDN system is called to send the connection information of the target manufacturer gateway to the PE device in the target POP.
4. The method according to claim 1, wherein The forwarding control device includes a convergence gateway in the target POP; the convergence gateway is physically pre-connected to vendor gateways of multiple vendors, and the convergence gateway is physically pre-connected to a PE device in the target POP.
5. The method according to claim 4, characterized in that The SD-WAN application platform is also connected to a convergence gateway SDN controller; the convergence gateway SDN controller is connected to multiple convergence gateways; the multiple convergence gateways include the convergence gateway in the target POP; the sending of the connection information of the target manufacturer gateway to the forwarding control device in the target POP includes: The convergence gateway SDN controller is called to send the connection information of the target manufacturer gateway to the convergence gateway in the target POP.
6. The method according to claim 5, characterized in that The backbone network SDN system is connected to PE devices in multiple POPs; the multiple POPs include the target POP; and the method further includes: Calling the backbone network SDN system to send the connection information of the aggregation gateway in the target POP to the PE device in the target POP; The convergence gateway SDN controller is called to send the connection information of the PE device in the target POP to the convergence gateway in the target POP, so that the convergence gateway in the target POP and the PE device in the target POP establish a neighbor relationship.
7. The method according to claim 6, characterized in that The method further comprises: Call the aggregation gateway SDN controller to send the service configuration information of the service to be allocated to the aggregation gateway in the target POP; the service configuration information includes: the port for transmitting the service data of the service to be allocated, the bandwidth allocated for the service to be allocated, the identity of the VPN of the service to be allocated, the identity of the autonomous system to which the aggregation gateway in the target POP belongs, and the identity of the virtual local area network allocated for the service to be allocated.
8. The method according to any one of claims 1 to 7, characterized in that The vendor SDN controller of each vendor is connected to the vendor terminal device of the vendor; the method further includes: The vendor SDN controller of the vendor corresponding to the target vendor gateway is called to send the connection information of the target vendor gateway and the service configuration information of the service to be allocated to the target vendor terminal device, so that the target vendor terminal device and the target vendor gateway establish an encrypted transmission tunnel.
9. The method according to any one of claims 1 to 7, characterized in that The calling of the backbone network SDN system to create a new virtual private network VPN for the service to be allocated includes: Based on the service request information indicating a request to establish a VPN that is in communication with an existing Multi-Protocol Label Switching (MPLS) VPN, obtaining networking parameters of the existing MPLS VPN; Sending a networking request parameter including the existing MPLS VPN networking parameter to the backbone network SDN system so that the backbone network SDN system creates a VPN for the service to be allocated that is in communication connection with the existing MPLS VPN.
10. A device for configuring a multi-vendor hybrid virtual private network, characterized in that: The device is applied to a software-defined wide area network (SD-WAN) application platform; the SD-WAN application platform is connected to vendor software-defined network (SDN) controllers and backbone network (SDN) systems of different vendors; each vendor SDN controller is connected to the vendor gateway of the vendor; the device includes: a processing module; The processing module is used to respond to the service request information of the service to be allocated, determine the target point of presence POP corresponding to the service to be allocated, and call the backbone network SDN system to create a new virtual private network VPN for the service to be allocated; the target POP includes a forwarding control device and a plurality of manufacturer gateways connected to the forwarding control device; the forwarding control device is used to forward the service data of the service to be allocated to the device outside the network topology area covered by the target POP through the VPN, or forward the service data of the service to be allocated to the device within the network topology area covered by the target POP through the manufacturer gateway in the target POP; The forwarding control device in the target POP sends the connection information of the target manufacturer gateway; the target manufacturer gateway is the manufacturer gateway called by the service to be allocated; the connection information of the target manufacturer gateway is used to indicate the address information of the target manufacturer gateway and the type of communication protocol for communicating with the target manufacturer gateway; the manufacturer SDN controller of the manufacturer corresponding to the target manufacturer gateway is called to send the connection information of the forwarding control device to the target manufacturer gateway, so that the forwarding control device establishes a neighbor relationship with the target manufacturer gateway; the connection information of the forwarding control device is used to indicate the address information of the forwarding control device and the type of communication protocol for communicating with the forwarding control device.
11. An electronic device, characterized in that: include: processor and memory; The memory stores instructions executable by the processor; When the processor is configured to execute the instructions, the electronic device implements the method according to any one of claims 1 to 9.
12. A computer program product, characterized in that include: Computer instructions; When the computer instructions are executed in an electronic device, the electronic device is enabled to implement the method according to any one of claims 1 to 9.