Virtual network operator management methods, devices, electronic equipment and readable media
By using a network controller and load balancer in a virtual network to detect the communication connection status, and combining the domain name system and internet gateway to form a target mapping session, the problem of only being able to bind to a specific EIP address in the cloud platform is solved, and the reliability management and automatic fault switching of multi-carrier links are realized.
Patent Information
- Application Number
- CN202411770660.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-04
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-04
AI Technical Summary
In the private cloud environment of the cloud platform, users can only bind EIP addresses with specific network attributes and cannot directly access the networks of other operators. Furthermore, there is a lack of mechanisms for automatically handling operator link failures and efficient traffic path selection.
By using the network controller of the virtual network, the priority relationship between users and network operators is obtained, the communication connection status is detected by the load balancer, and the target mapping session is formed by combining the domain name system and the Internet gateway to realize health detection and traffic selection of multi-operator links.
It provides multi-carrier link exits, allowing customers to customize exit weights, ensuring link reliability, and automatically switching to a healthy path in the event of a link failure, thus achieving efficient management of multi-carrier networks.
Smart Images

Figure CN119814613B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network technology, and in particular to a method for managing virtual network operators, a device for managing virtual network operators, an electronic device, and a computer-readable medium. Background Technology
[0002] In related technologies, within a private cloud environment of a cloud platform, when a user needs to bind an externally accessible EIP (Elastic IP) to a virtual machine, they can only bind an EIP address with specific network attributes, such as an EIP address with network plane attributes like China Telecom's 163 network. This means that if a user needs to access the networks of other operators, such as China Mobile or China Unicom, they may not be able to directly use these operator's network plane attribute EIP addresses. Summary of the Invention
[0003] This invention provides a method, apparatus, electronic device, and computer-readable storage medium for operator management of virtual networks, to solve the problem that in a private cloud environment of a cloud platform, when a user needs to bind an externally accessible EIP (Elastic IP) to a virtual machine, they can only bind an EIP address with specific network attributes. If the user needs to access the network of other operators, they may not be able to directly use the network plane attribute EIP addresses of these operators.
[0004] This invention discloses a method for operator management of a virtual network, applied to a network controller of the virtual network, wherein the virtual network includes a Domain Name System (DNS), an Internet gateway, and a load balancer; the virtual network is communicatively connected to at least one network operator, and the method includes:
[0005] Obtain the user's priority relationship with the at least one network operator, and obtain the communication connection status between the virtual network and the network operator through the load balancer;
[0006] When the virtual network obtains first traffic sent by any of the network operators, a target network operator is determined from the at least one network operator based on the first traffic, the communication connection status, and the priority relationship.
[0007] The address of the target network operator is obtained through the domain name system, and a target mapping session is formed on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
[0008] Optionally, determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes:
[0009] Based on the first traffic, obtain the network operator to be processed that sent the first traffic;
[0010] Based on the communication connection status, determine whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed;
[0011] If such a network operator exists, the target network operator is determined from the at least one network operator based on the priority relationship.
[0012] Optionally, determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes:
[0013] If there is no abnormality in the communication connection between the virtual network and the network operator to be processed, then the network operator to be processed will be used as the target network operator.
[0014] Optionally, obtaining the communication connection status between the virtual network and the network operator through the load balancer includes:
[0015] Configure a virtual Internet Protocol address for the load balancer;
[0016] For any of the aforementioned network operators, the load balancer is controlled to send a connection request to the network operator using the virtual Internet Protocol address as the source address;
[0017] The connection request is used to determine whether there is any abnormality in the communication connection between the virtual network and the network operator.
[0018] Optionally, determining whether there is an anomaly in the communication connection between the virtual network and the network operator based on the connection request includes:
[0019] If the load balancer receives a response to the connection request sent by the network operator, it confirms that the communication connection between the virtual network and the network operator is normal.
[0020] If the load balancer does not receive a response to the connection request sent by the network operator, it confirms that there is an anomaly in the communication connection between the virtual network and the network operator.
[0021] Optionally, a preset private network address exists in the virtual network; the step of forming a target mapping session on the Internet gateway based on the address of the target network operator includes:
[0022] By converting the private network address to the address of the target network operator, the target mapping session is formed on the Internet gateway.
[0023] Optionally, the virtual network is a private cloud network.
[0024] This invention also discloses a virtual network operator management device, applied to a network controller of a virtual network, wherein the virtual network includes a Domain Name System, an Internet gateway, and a load balancer; the virtual network is communicatively connected to at least one network operator, and the device includes:
[0025] The priority relationship acquisition module is used to acquire the user's priority relationship with the at least one network operator, and to acquire the communication connection status between the virtual network and the network operator through the load balancer.
[0026] The target network operator determination module is used to determine a target network operator from the at least one network operator based on the first traffic, the communication connection status and the priority relationship when the virtual network obtains first traffic sent by any of the network operators.
[0027] The address acquisition module is used to acquire the address of the target network operator through the domain name system, and form a target mapping session on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
[0028] Optionally, the target network operator determination module includes:
[0029] The pending network operator acquisition submodule is used to acquire the pending network operator that sent the first traffic based on the first traffic.
[0030] The anomaly detection submodule is used to determine whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed, based on the communication connection status.
[0031] A target network operator determination submodule is used to determine a target network operator from the at least one network operator based on the priority relationship, if such a target network operator exists.
[0032] Optionally, the target network operator determination module includes:
[0033] The target network operator module is used to designate the network operator to be processed as the target network operator if there is no abnormality in the communication connection between the virtual network and the network operator to be processed.
[0034] Optionally, the priority relationship acquisition module includes:
[0035] A configuration submodule is used to configure a virtual Internet Protocol address for the load balancer.
[0036] The request sending submodule is used to control the load balancer to send a connection request to any of the network operators, using the virtual Internet Protocol address as the source address.
[0037] The anomaly detection submodule is used to determine whether there is an anomaly in the communication connection between the virtual network and the network operator based on the connection request.
[0038] Optionally, the anomaly detection submodule includes:
[0039] The normal confirmation unit is used to confirm that the communication connection between the virtual network and the network operator is normal if the load balancer receives a response to the connection request sent by the network operator.
[0040] An anomaly confirmation unit is used to confirm that there is an anomaly in the communication connection between the virtual network and the network operator if the load balancer does not receive a response to the connection request sent by the network operator.
[0041] Optionally, the virtual network contains a preset private network address; the address acquisition module includes:
[0042] The target mapping session formation submodule is used to form the target mapping session on the Internet gateway by converting the private network address to the address of the target network operator.
[0043] Optionally, the virtual network is a private cloud network.
[0044] This invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0045] The memory is used to store computer programs;
[0046] When the processor executes a program stored in the memory, it implements the method described in the embodiments of the present invention.
[0047] This invention also discloses one or more computer-readable media storing instructions that, when executed by one or more processors, cause the processors to perform the methods described in this invention.
[0048] The embodiments of the present invention have the following advantages:
[0049] In this embodiment of the invention, the virtual network includes a Domain Name System (DNS), an Internet gateway, and a load balancer; the virtual network communicates with at least one network operator. The system obtains the user's priority relationship with at least one network operator and acquires the communication connection status between the virtual network and the network operator through the load balancer. When the virtual network receives first traffic sent by any network operator, a target network operator is determined among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship. The address of the target network operator is obtained through the DNS, and a target mapping session is formed on the Internet gateway based on the target network operator's address. The target mapping session is used to determine the target address of the second traffic when the virtual network sends second traffic related to the first traffic; the target address is the address of the target network operator. This invention proposes a solution in a virtual network scenario that provides customers with multi-operator link exits and performs link health checks, allowing customers to choose the weight of operator exits, thereby providing customers with reliable multi-operator exit links. Attached Figure Description
[0050] Figure 1 This is a flowchart illustrating the steps of a virtual network operator management method provided in an embodiment of the present invention;
[0051] Figure 2 This is a schematic diagram of a virtual network provided in an embodiment of the present invention;
[0052] Figure 3 This is a schematic diagram of the multi-exit deployment of operators provided in an embodiment of the present invention;
[0053] Figure 4 This is a schematic diagram of a network element node provided in an embodiment of the present invention;
[0054] Figure 5 This is a structural block diagram of a virtual network operator management device provided in an embodiment of the present invention;
[0055] Figure 6 This is a block diagram of an electronic device provided in an embodiment of the present invention;
[0056] Figure 7 This is a schematic diagram of a computer-readable medium provided in an embodiment of the present invention. Detailed Implementation
[0057] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0058] To facilitate understanding of the technical solutions and effects of the embodiments of the present invention, the prior art of the present invention will be briefly described below.
[0059] Among related technologies, the cloud platform possesses the resource deployment capability of multiple Availability Zones (AZs), supports ultra-large-scale clusters (a single AZ can accommodate more than 10,000 servers), and achieves deep collaboration between hardware and software resources. The core functions of this resource pool can meet the needs of ultra-large-scale, high-performance, secure, and reliable cloud services. It further enhances the resource pool management and scheduling capabilities of the IaaS (Infrastructure as a Service) platform to address the network construction and multi-AZ architecture requirements of ultra-large-scale data centers. The resource pool now has the capability to manage networks with up to 5,000 nodes, with each AZ supporting the operation of 5,000 servers. Furthermore, the overall scale of Regions has increased more than tenfold, fully meeting users' business needs in areas such as two-site, three-center multi-active deployment and disaster recovery.
[0060] The cloud platform has been fully productized and commercialized, and is ready for deployment in real-world network environments. As an independently controllable cloud infrastructure under the "one cloud, multiple modes; one cloud, multiple chips" strategy, it provides a high-performance, highly available, and highly reliable basic cloud network foundation.
[0061] However, at least the following problems exist in cloud platforms:
[0062] First, in a private cloud environment on a cloud platform, when a user needs to bind an externally accessible EIP (Elastic IP) to a virtual machine, they can only bind an EIP address with specific network attributes, such as an EIP address with network plane attributes like China Telecom's 163 network. This means that if a user needs to access the networks of other operators, such as China Mobile or China Unicom, they may not be able to directly use these operator's network plane attribute EIP addresses.
[0063] Second, when the cloud platform is connected to multiple carrier networks, it lacks a mechanism to automatically handle problems that occur on a particular carrier's link.
[0064] Third, cloud platforms require optimal traffic path selection, which typically involves choosing the best carrier network from among multiple carrier networks connected to the cloud platform. In public cloud services, this is usually achieved by learning routes through establishing BGP (Border Gateway Protocol) neighbor relationships with multiple carriers. However, for private cloud users, purchasing links capable of establishing BGP neighbor relationships is costly.
[0065] Reference Figure 1 This diagram illustrates a flowchart of a method for managing a virtual network according to an embodiment of the present invention. The method is applied to a network controller of a virtual network, which includes a Domain Name System (DNS), an Internet gateway, and a load balancer. The virtual network is communicatively connected to at least one network operator, and the method may specifically include the following steps:
[0066] Step 101: Obtain the user's priority relationship with the at least one network operator, and obtain the communication connection status between the virtual network and the network operator through the load balancer;
[0067] In this embodiment of the invention, the network controller is an SDN (Software-Defined Networking) controller. The virtual network controlled by the SDN controller is divided into three layers.
[0068] Reference Figure 2 This diagram illustrates a virtual network provided in an embodiment of the present invention. The virtual network is divided into three layers. The first layer is the TC (Traffic Control) zone, which is responsible for accessing external networks, including external network traffic, NAS (Network Attached Storage) traffic, leased line POPs (Point of Presence), high-speed cloud devices, VPN (Virtual Private Network) devices, etc. These devices are all multi-active access. The network elements deployed in this zone are AGW (Access Gateway) and SGW (Service Gateway). The AGW is responsible for publishing public network CIDR (Classless Inter-Domain Routing), and the SGW is responsible for rate limiting. Figure 2The first layer includes DCGW (Data Center Gateway), CGW (Customer Gateway), VPNGW (Virtual Private Network Gateway), and BLeaf (Border Leaf Node). The second layer is the network element service area, where deployed services provide layer 3 to layer 7 network services to tenants, including leased lines, IGW (Internet Gateway), NAT (Network Address Translation), VPN (Virtual Private Network) access, and LB (Load Balancer). The third layer is the resource access layer, responsible for providing virtual network access services to VMs, containers, and bare metal. Network element types include DVR and SmartNIC. VMs are compute nodes, bare metal is bare metal, and DVR is OVS (Open Source Virtual Switch).
[0069] In this embodiment of the invention, the virtual network is communicatively connected to at least one network operator. (See also...) Figure 3 This diagram illustrates a multi-exit deployment for operators provided in an embodiment of the present invention. Multiple operator egress physical lines are connected to the core switch. Each operator provides an interface IP address, used for health checks on various links and as the entry IP address for incoming traffic; for example, China Telecom 10.1.1.1, China Unicom 10.1.1.2, and China Mobile 10.1.1.3. Network element nodes are nodes in the network service layer.
[0070] In this embodiment of the invention, the virtual network includes a Domain Name System, an Internet gateway, and a load balancer. (See also...) Figure 4 This diagram illustrates a network element node provided in an embodiment of the present invention. The virtual network mainly includes network element nodes such as IGW (Internet Gateway), LB (Load Balancer), and DNS (Domain Name System).
[0071] In this embodiment of the invention, the network controller can obtain the user's priority relationship with at least one network operator, and obtain the communication connection status between the virtual network and the network operator through the load balancer.
[0072] In some embodiments of the present invention, obtaining the communication connection status between the virtual network and the network operator through the load balancer includes:
[0073] Configure a virtual Internet Protocol address for the load balancer;
[0074] For any of the aforementioned network operators, the load balancer is controlled to send a connection request to the network operator using the virtual Internet Protocol address as the source address;
[0075] The connection request is used to determine whether there is any abnormality in the communication connection between the virtual network and the network operator.
[0076] In this embodiment of the invention, a virtual IP address, such as 20.1.1.1, is started on the load balancer. Then, the TCP health check of the load balancer is started using the virtual IP address (20.1.1.1) and the interface address provided by the ISP. Specifically, the load balancer uses the configured virtual IP address (20.1.1.1) as the source address to send a TCP connection request to the interface address provided by the ISP in order to detect the health status of the link and determine whether there are any abnormalities in the communication connection.
[0077] In some embodiments of the present invention, determining whether there is an anomaly in the communication connection between the virtual network and the network operator through the connection request includes:
[0078] If the load balancer receives a response to the connection request sent by the network operator, it confirms that the communication connection between the virtual network and the network operator is normal.
[0079] If the load balancer does not receive a response to the connection request sent by the network operator, it confirms that there is an anomaly in the communication connection between the virtual network and the network operator.
[0080] In this embodiment of the invention, if the load balancer receives a response to a TCP connection request sent by the network operator, it confirms that the communication connection between the virtual network and the network operator is normal; if the load balancer does not receive a response to a TCP connection request sent by the network operator, it confirms that the communication connection between the virtual network and the network operator is abnormal.
[0081] Step 102: When the virtual network obtains the first traffic sent by any of the network operators, a target network operator is determined from the at least one network operator based on the first traffic, the communication connection status, and the priority relationship.
[0082] In this embodiment of the invention, when the virtual network obtains the first traffic sent by any network operator, the network controller can determine the target network operator from at least one network operator based on the first traffic, the communication connection status, and the priority relationship.
[0083] In some embodiments of the present invention, determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes:
[0084] Based on the first traffic, obtain the network operator to be processed that sent the first traffic;
[0085] Based on the communication connection status, determine whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed;
[0086] If such a network operator exists, the target network operator is determined from the at least one network operator based on the priority relationship.
[0087] In this embodiment of the invention, the network controller can acquire the network operator to be processed that sent the first traffic. Based on the communication connection status, it determines whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed. If so, the target network operator is determined from at least one network operator based on priority relationships.
[0088] In some embodiments of the present invention, determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes:
[0089] If there is no abnormality in the communication connection between the virtual network and the network operator to be processed, then the network operator to be processed will be used as the target network operator.
[0090] In this embodiment of the invention, if there is no abnormality in the communication connection between the virtual network and the network operator to be processed, the network controller can use the network operator to be processed as the target network operator.
[0091] In this embodiment of the invention, for the second traffic, NAT address translation needs to be performed on the IGW network element for each operator's exit, for example, the IP address range of the network operator at the exit is deployed according to the following table.
[0092] Operators Export address range telecommunications 100.0.0.0 / 24 China Unicom 100.0.1.0 / 24 move 100.0.2.0 / 24
[0093] When the second traffic is sent out, the SDN controller sends corresponding NAT rules to the IGW to translate the private network address within the cloud into the corresponding carrier's exit address. This allows traffic to use multiple carrier exits, with the priority selection based on the exit from which the user traffic entered. This creates a NAT mapping session on the IGW. When traffic goes out, it selects the corresponding carrier exit based on this session. When traffic actively goes out, routing policy weights for the three exits can be configured on the SDN controller. This routing policy is then sent to the IGW network elements through the SDN controller. The IGW network elements can send NAT address mapping priorities, allowing internal network traffic to choose which carrier exit to prioritize based on different policies, and also providing backup for other exits.
[0094] Step 103: Obtain the address of the target network operator through the Domain Name System, and form a target mapping session on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
[0095] In this embodiment of the invention, when the first traffic enters the resource pool, it is first directed to the DNS network element. Customers can configure DNS domain name resolution on the SDN controller to specify which domain names should be resolved to provide services within the cloud. The DNS network element performs domain name resolution based on the traffic. The SDN controller can monitor which ISP's link the traffic originated from. The DNS server then resolves the domain name to the corresponding IP address in the target ISP's egress address range. When the IGW forms a NAT session, it directly creates a session between the target ISP's egress IP address and the internal network address of the first incoming traffic, guiding the second traffic to find the corresponding target ISP's egress link when forwarding to the cloud.
[0096] When a carrier's egress link fails, the load balancer's health check will immediately detect the TCP health check session interruption and report this message to the SDN controller. At this point, for incoming traffic, the SDN controller will immediately notify the DNS server to switch the link address for domain name resolution. Based on the customer's configuration, it will prioritize the carrier's egress link, selecting the highest priority link with a normal health check for DNS domain name resolution. Simultaneously, the SDN controller will instruct the IGW to update the existing NAT session information, creating new NAT session entries for the egress link. This ensures that outgoing traffic is also redirected to the non-failed egress link.
[0097] In some embodiments of the present invention, a preset private network address exists in the virtual network; the step of forming a target mapping session on the Internet gateway based on the address of the target network operator includes:
[0098] By converting the private network address to the address of the target network operator, the target mapping session is formed on the Internet gateway.
[0099] In this embodiment of the invention, a preset private network address exists in the virtual network. By converting the private network address into the address of the target network operator, a target mapping session can be formed on the Internet gateway.
[0100] In some embodiments of the present invention, the virtual network is a private cloud network.
[0101] In this embodiment of the invention, the virtual network includes a Domain Name System (DNS), an Internet gateway, and a load balancer; the virtual network communicates with at least one network operator. The system obtains the user's priority relationship with at least one network operator and acquires the communication connection status between the virtual network and the network operator through the load balancer. When the virtual network receives first traffic sent by any network operator, a target network operator is determined among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship. The address of the target network operator is obtained through the DNS, and a target mapping session is formed on the Internet gateway based on the target network operator's address. The target mapping session is used to determine the target address of the second traffic when the virtual network sends second traffic related to the first traffic; the target address is the address of the target network operator. This invention proposes a solution in a virtual network scenario that provides customers with multi-operator link exits and performs link health checks, allowing customers to choose the weight of operator exits, thereby providing customers with reliable multi-operator exit links.
[0102] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.
[0103] Reference Figure 5 This diagram illustrates a structural block diagram of a virtual network operator management device provided in an embodiment of the present invention. The device is applied to a network controller of a virtual network, which includes a Domain Name System (DNS), an Internet gateway, and a load balancer. The virtual network is communicatively connected to at least one network operator and may specifically include the following modules:
[0104] The priority relationship acquisition module 501 is used to acquire the user's priority relationship with the at least one network operator, and to acquire the communication connection status between the virtual network and the network operator through the load balancer.
[0105] The target network operator determination module 502 is used to determine a target network operator among the at least one network operator based on the first traffic, the communication connection status and the priority relationship when the virtual network obtains the first traffic sent by any of the network operators.
[0106] Address acquisition module 503 is used to acquire the address of the target network operator through the domain name system, and form a target mapping session on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
[0107] In an optional embodiment of the present invention, the target network operator determination module includes:
[0108] The pending network operator acquisition submodule is used to acquire the pending network operator that sent the first traffic based on the first traffic.
[0109] The anomaly detection submodule is used to determine whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed, based on the communication connection status.
[0110] A target network operator determination submodule is used to determine a target network operator from the at least one network operator based on the priority relationship, if such a target network operator exists.
[0111] In an optional embodiment of the present invention, the target network operator determination module includes:
[0112] The target network operator module is used to designate the network operator to be processed as the target network operator if there is no abnormality in the communication connection between the virtual network and the network operator to be processed.
[0113] In an optional embodiment of the present invention, the priority relationship acquisition module includes:
[0114] A configuration submodule is used to configure a virtual Internet Protocol address for the load balancer.
[0115] The request sending submodule is used to control the load balancer to send a connection request to any of the network operators, using the virtual Internet Protocol address as the source address.
[0116] The anomaly detection submodule is used to determine whether there is an anomaly in the communication connection between the virtual network and the network operator based on the connection request.
[0117] In an optional embodiment of the present invention, the anomaly detection submodule includes:
[0118] The normal confirmation unit is used to confirm that the communication connection between the virtual network and the network operator is normal if the load balancer receives a response to the connection request sent by the network operator.
[0119] An anomaly confirmation unit is used to confirm that there is an anomaly in the communication connection between the virtual network and the network operator if the load balancer does not receive a response to the connection request sent by the network operator.
[0120] In an optional embodiment of the present invention, a preset private network address exists in the virtual network; the address acquisition module includes:
[0121] The target mapping session formation submodule is used to form the target mapping session on the Internet gateway by converting the private network address to the address of the target network operator.
[0122] In one optional embodiment of the present invention, the virtual network is a private cloud network.
[0123] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0124] In addition, embodiments of the present invention also provide an electronic device, such as... Figure 6 As shown, it includes a processor 601, a communication interface 602, a memory 603, and a communication bus 604, wherein the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604.
[0125] Memory 603 is used to store computer programs;
[0126] When processor 601 executes a program stored in memory 603, it performs the following steps:
[0127] Obtain the user's priority relationship with the at least one network operator, and obtain the communication connection status between the virtual network and the network operator through the load balancer;
[0128] When the virtual network obtains first traffic sent by any of the network operators, a target network operator is determined from the at least one network operator based on the first traffic, the communication connection status, and the priority relationship.
[0129] The address of the target network operator is obtained through the Domain Name System, and a target mapping session is formed on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
[0130] In an optional embodiment of the present invention, determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes:
[0131] Based on the first traffic, obtain the network operator to be processed that sent the first traffic;
[0132] Based on the communication connection status, determine whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed;
[0133] If such a network operator exists, the target network operator is determined from the at least one network operator based on the priority relationship.
[0134] In an optional embodiment of the present invention, determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes:
[0135] If there is no abnormality in the communication connection between the virtual network and the network operator to be processed, then the network operator to be processed will be used as the target network operator.
[0136] In an optional embodiment of the present invention, obtaining the communication connection status between the virtual network and the network operator through the load balancer includes:
[0137] Configure a virtual Internet Protocol address for the load balancer;
[0138] For any of the aforementioned network operators, the load balancer is controlled to send a connection request to the network operator using the virtual Internet Protocol address as the source address;
[0139] The connection request is used to determine whether there is any abnormality in the communication connection between the virtual network and the network operator.
[0140] In an optional embodiment of the present invention, determining whether there is an anomaly in the communication connection between the virtual network and the network operator based on the connection request includes:
[0141] If the load balancer receives a response to the connection request sent by the network operator, it confirms that the communication connection between the virtual network and the network operator is normal.
[0142] If the load balancer does not receive a response to the connection request sent by the network operator, it confirms that there is an anomaly in the communication connection between the virtual network and the network operator.
[0143] In an optional embodiment of the present invention, a preset private network address exists in the virtual network; the step of forming a target mapping session on the Internet gateway based on the address of the target network operator includes:
[0144] By converting the private network address to the address of the target network operator, the target mapping session is formed on the Internet gateway.
[0145] In one optional embodiment of the present invention, the virtual network is a private cloud network.
[0146] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0147] The communication interface is used for communication between the aforementioned terminal and other devices.
[0148] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0149] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0150] like Figure 7 As shown, in another embodiment of the present invention, a computer-readable storage medium 701 is also provided, which stores instructions that, when executed on a computer, cause the computer to perform a virtual network operator management method as described in the above embodiments.
[0151] In another embodiment of the present invention, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute a virtual network operator management method as described in the above embodiments.
[0152] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).
[0153] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0154] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0155] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of protection of the present invention.
Claims
1. A method for operator management of a virtual network, characterized in that, A network controller for a virtual network, the virtual network including a Domain Name System (DNS), an Internet gateway, and a load balancer; the virtual network is communicatively connected to at least one network operator, the method comprising: Obtain the user's priority relationship with the at least one network operator, and obtain the communication connection status between the virtual network and the network operator through the load balancer; When the virtual network obtains first traffic sent by any of the network operators, a target network operator is determined from the at least one network operator based on the first traffic, the communication connection status, and the priority relationship. The address of the target network operator is obtained through the Domain Name System, and a target mapping session is formed on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
2. The method according to claim 1, characterized in that, The step of determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes: Based on the first traffic, obtain the network operator to be processed that sent the first traffic; Based on the communication connection status, determine whether there is an anomaly in the communication connection between the virtual network and the network operator to be processed; If such a network operator exists, the target network operator is determined from the at least one network operator based on the priority relationship.
3. The method according to claim 2, characterized in that, The step of determining the target network operator among the at least one network operator based on the first traffic, the communication connection status, and the priority relationship includes: If there is no abnormality in the communication connection between the virtual network and the network operator to be processed, then the network operator to be processed will be used as the target network operator.
4. The method according to claim 1, characterized in that, The step of obtaining the communication connection status between the virtual network and the network operator through the load balancer includes: Configure a virtual Internet Protocol address for the load balancer; For any of the aforementioned network operators, the load balancer is controlled to send a connection request to the network operator using the virtual Internet Protocol address as the source address; The connection request is used to determine whether there is any abnormality in the communication connection between the virtual network and the network operator.
5. The method according to claim 4, characterized in that, The step of determining whether there is an anomaly in the communication connection between the virtual network and the network operator through the connection request includes: If the load balancer receives a response to the connection request sent by the network operator, it confirms that the communication connection between the virtual network and the network operator is normal. If the load balancer does not receive a response to the connection request sent by the network operator, it confirms that there is an anomaly in the communication connection between the virtual network and the network operator.
6. The method according to claim 1, characterized in that, The virtual network contains a preset private network address; the process of forming a target mapping session on the Internet gateway based on the target network operator's address includes: By converting the private network address to the address of the target network operator, the target mapping session is formed on the Internet gateway.
7. The method according to claim 1, characterized in that, The virtual network is a private cloud network.
8. A virtual network operator management device, characterized in that, A network controller for a virtual network, the virtual network including a Domain Name System (DNS), an Internet gateway, and a load balancer; the virtual network is communicatively connected to at least one network operator, the device comprising: The priority relationship acquisition module is used to acquire the user's priority relationship with the at least one network operator, and to acquire the communication connection status between the virtual network and the network operator through the load balancer. The target network operator determination module is used to determine a target network operator from the at least one network operator based on the first traffic, the communication connection status and the priority relationship when the virtual network obtains first traffic sent by any of the network operators. The address acquisition module is used to acquire the address of the target network operator through the domain name system, and form a target mapping session on the Internet gateway based on the address of the target network operator; the target mapping session is used to determine the target address of the second traffic when the virtual network sends the second traffic for the first traffic; the target address is the address of the target network operator.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes a program stored in the memory, it implements the method as described in any one of claims 1-7.
10. One or more computer-readable media having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the method as described in any one of claims 1-7.
Citation Information
Patent Citations
Internet link load control system
CN110048956A
Network switching method and device based on user identification card, and storage medium
CN116744281A