Connection tracking table synchronization method and device, related equipment and storage medium
By creating a virtual network card and building specific packets in the OVS internal bridge of the new node, the problem that OVS cannot copy the connection tracking table is solved, and the reconstruction and resource saving of the connection tracking table are realized.
Patent Information
- Application Number
- CN202510072836.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-02
AI Technical Summary
In scenarios such as hot upgrades, virtual machine hot migration and OVS twin network simulation, existing OVS cannot copy the connection tracking table from one OVS to another OVS, resulting in user connection disconnection and affecting user experience.
Through the SDN controller, the OVS communication with the node is added, the flow table entry is added to identify the matching message, and the connection tracking table is obtained by communicating with another OVS, and the message is built to rebuild the connection tracking table.
Rebuilding of the connection tracking table is implemented, reducing the number of virtual ports that need to be added, saving resources, and improving user experience.
Smart Images

Figure CN119922150A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and in particular to a method, an apparatus, related equipment and a storage medium for synchronizing a connection tracking table. Background Art
[0002] Connection Track (CT) is an important advanced function in the network field. When a message passes through the Open vSwitch (OVS), the virtual switch can record some connection information of the data packet in this connection session, forming a CT table containing one or more CT entries, so as to provide it for subsequent related session connection query and use.
[0003] However, OVS currently does not provide the ability to import CT tables. In scenarios such as OVS hot upgrade (new and old OVS dual-process replacement upgrade method), virtual machine hot migration (that is, virtual machines migrate from one computing node to another computing node in real time), and OVS twin network simulation, the CT table cannot be copied from one OVS to another. This will cause the new OVS process to lack the CT table previously established by the user in the old OVS, resulting in disconnection of users in communication and the need to reconnect, which will affect the user experience to a certain extent. Summary of the invention
[0004] In order to solve the existing technical problems, the embodiments of the present invention provide a method, an apparatus, related equipment and a storage medium for synchronizing a connection tracking table.
[0005] To achieve the above object, the technical solution of the embodiment of the present invention is implemented as follows:
[0006] In a first aspect, an embodiment of the present invention provides a method for synchronizing a connection tracking table, the method being applied to a software defined network (SDN) controller; the method comprising:
[0007] The SDN controller communicates with a first open virtual switch (OVS) of the first node to add one or more flow table entries in a first flow table of an internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message;
[0008] Obtain a connection tracking table by communicating with a second OVS of a second node, and construct a first message according to the connection tracking table, wherein an action field of the first message is used to indicate a first virtual network card in a pair of virtual network cards created by the first OVS on an internal network bridge;
[0009] The first message is sent so that an internal bridge of the first OVS of the first node identifies and matches the first message according to the one or more flow table entries in the first flow table and generates the connection tracking table.
[0010] In a second aspect, an embodiment of the present invention further provides a method for synchronizing a connection tracking table, the method being applied to a first node; the method comprising:
[0011] The first node adds one or more flow table entries in a first flow table of an internal bridge of a first OVS of the first node by communicating with the SDN controller;
[0012] The first OVS of the first node receives the first message sent by the SDN controller, identifies and matches the first message according to the one or more flow table entries, and generates a connection tracking table;
[0013] The first message is constructed by the SDN controller according to the connection tracking table obtained from the second OVS of the second node; the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge.
[0014] In a third aspect, an embodiment of the present invention further provides a synchronization device for a connection tracking table, the device is applied to an SDN controller, and the device includes: a first processing unit and a first communication unit; wherein,
[0015] The first processing unit is used to communicate with the first OVS of the first node through the first communication unit to add one or more flow table entries in the first flow table of the internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message;
[0016] The first communication unit is further configured to obtain a connection tracking table by communicating with a second OVS of the second node;
[0017] The first processing unit is further used to construct a first message according to the connection tracking table, wherein the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge;
[0018] The first communication unit is further used to send the first message so that the internal bridge of the first OVS of the first node can identify and match the first message according to the one or more flow table entries in the first flow table and generate the connection tracking table.
[0019] In a fourth aspect, an embodiment of the present invention further provides a synchronization device for a connection tracking table, the device is applied to a first node, and the device includes: a second processing unit and a second communication unit; wherein,
[0020] The second processing unit is used to communicate with the SDN controller through the second communication unit, and add one or more flow table entries in the first flow table of the internal bridge of the first OVS; and is also used to receive the first message sent by the SDN controller in the first OVS through the second communication unit, identify and match the first message according to the one or more flow table entries, and generate a connection tracking table;
[0021] The first message is constructed by the SDN controller according to the connection tracking table obtained from the second OVS of the second node; the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge.
[0022] In a fifth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method for synchronizing a connection tracking table described in the first aspect or the second aspect of the embodiment of the present invention.
[0023] In a sixth aspect, an embodiment of the present invention further provides a communication device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method for synchronizing the connection tracking table described in the first aspect or the second aspect of the embodiment of the present invention are implemented.
[0024] In a seventh aspect, an embodiment of the present invention further provides a computer program product, comprising computer program instructions, which enable a computer to execute the steps of the method for synchronizing a connection tracking table as described in the first aspect or the second aspect of the embodiment of the present invention.
[0025] The synchronization method, device, related equipment and storage medium of the connection tracking table provided by the embodiment of the present invention, the software defined network (SDN) controller communicates with the first open virtual switch OVS of the first node to add one or more flow table entries in the first flow table of the internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message; by communicating with the second OVS of the second node, the connection tracking table is obtained, and the first message is constructed according to the connection tracking table, and the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge; the first message is sent, so that the internal bridge of the first OVS of the first node identifies and matches the first message according to the one or more flow table entries in the first flow table and generates the connection tracking table. The technical solution of the embodiment of the present invention is adopted, through the pair of virtual network cards created by the internal bridge of the OVS of the new node (i.e., the first node), combined with the action of the first message, the sending and receiving messages of the virtual machine port can be simulated, thereby realizing the reconstruction of the connection tracking table, and greatly reducing the number of virtual ports that need to be added, saving resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 A schematic diagram of a system architecture for applying a method for synchronizing a connection tracking table according to an embodiment of the present invention;
[0027] Figure 2 Schematic diagram of the process of the connection tracking table synchronization method according to an embodiment of the present invention Figure 1 ;
[0028] Figure 3 Schematic diagram of the process of the connection tracking table synchronization method according to an embodiment of the present invention Figure 2 ;
[0029] Figure 4a and Figure 4b A schematic diagram of an interactive process of a method for synchronizing a connection tracking table according to an embodiment of the present invention;
[0030] Figure 5 Schematic diagram of the structure of the synchronization device of the connection tracking table according to the embodiment of the present invention Figure 1 ;
[0031] Figure 6 Schematic diagram of the structure of the synchronization device of the connection tracking table according to the embodiment of the present invention Figure 2 ;
[0032] Figure 7 The figure is a schematic diagram of the hardware structure of the communication device according to the embodiment of the present invention. DETAILED DESCRIPTION
[0033] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0034] The term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0035] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and need not be used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable in appropriate circumstances, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein, for example. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, the process, method, system, product or equipment comprising a series of steps or units need not be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0036] The connection tracking table synchronization method of the embodiment of the present invention is applied to Figure 1 The system architecture shown.
[0037] Cloud computing is an Internet-based computing method that converts computing resources into virtual machine resources, which are then scheduled and managed through virtual machine management technology on the cloud computing platform. Computing resources are efficiently utilized and managed, and software-defined networking (SDN) technology is used to achieve mutual communication, thereby improving resource utilization and computing efficiency.
[0038] SDN is a new type of innovative network architecture. Its core technology, OpenFlow, separates the control plane from the data plane of network devices, thereby achieving flexible control of network traffic and directly implementing programmatic control of the network through a unified and open southbound interface.
[0039] OpenFlow is a protocol in SDN, which is used to separate the message forwarding and forwarding strategies on the switch. Usually, a dedicated controller is used to manage the network forwarding strategy, so that the message forwarding function (hardware chip implementation) and message forwarding strategy (various software protocols) originally on the same switch device are separated to different hardware devices, where the message forwarding function is still completed on the switch, while the message forwarding strategy is transferred to the controller for implementation. One controller can control multiple switches, thereby realizing unified forwarding plane management and more effective network control.
[0040] OVS is a virtual switch that supports OpenFlow and is widely used in cloud computing environments. It is mainly used to connect virtual machines and other network devices to realize virtual networks.
[0041] Reference Figure 1 As shown, the system architecture may include: an SDN controller (or controller), a first node and a second node; wherein the first node and the second node both have an OVS and multiple virtual switches (or virtual machines), and each virtual machine in each node (such as the first node or the second node) is connected to the OVS in each node (such as the first node or the second node). In other optional embodiments, the OVS may also be connected to other network devices. Figure 1 Not shown in the figure.
[0042] The main components of OVS may include bridges and flow tables, which work together to manage and forward network traffic. Among them, a bridge is an instance of OVS, which simulates the function of a physical switch. OVS can have multiple bridges, each of which can have multiple ports, which can be connected to virtual machines, containers, or other network devices to at least forward data packets. Flow tables are used to define how data packets are processed and forwarded, that is, to define the forwarding rules for data packets. Each bridge can have multiple flow tables, but at least one default flow table, denoted as Table 0.
[0043] The OVS in the computing node can record the connection information in the connection session and form a CT table. The main application scenarios of CT may include: stateful security groups, stateful firewalls, network address translation (NAT) and other network functions. A typical example is the stateful security group function in cloud computing: due to security reasons, when the cloud host provides WEB services to the outside world, the general security group will only allow port 80 in the inbound direction, but will not allow the Internet Protocol (IP, Internet Protocol) and port rules in the outbound direction. At this time, with the help of the OVS connection status (CT) capability, the 5-tuple (source IP, destination IP, protocol number, source port, destination port) connection information of the user's first access to the cloud host can be recorded, and the precise 5-tuple CT table entries in the outbound direction (reverse direction) can be dynamically and automatically released; when the user's connection is not accessed or times out, the outbound CT table entries are dynamically deleted. This can greatly improve security without the need to release all outbound rules.
[0044] Currently, when the CT table of the OVS in a computing node (such as computing node 1) needs to be migrated to the OVS in another computing node (such as computing node 2), OVS does not have this capability, which will cause the OVS process in the new computing node (such as computing node 2) to lack the CT table in the OVS in the old computing node (such as computing node 1), resulting in user disconnection.
[0045] Based on this, an embodiment of the present invention further provides a method for synchronizing a connection tracking table. Figure 2 Schematic diagram of the process of the connection tracking table synchronization method according to an embodiment of the present invention Figure 1 ;like Figure 2 As shown, the method includes:
[0046] Step 101: The SDN controller communicates with the first OVS of the first node to add one or more flow table entries in the first flow table of the internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message;
[0047] Step 102: Obtain a connection tracking table by communicating with a second OVS of a second node, and construct a first message according to the connection tracking table, wherein the action field of the first message is used to indicate a first virtual network card in a pair of virtual network cards created by the first OVS on an internal bridge.
[0048] Step 103: Send the first message so that the internal bridge of the first OVS of the first node can identify and match the first message according to the one or more flow table entries in the first flow table and generate the connection tracking table.
[0049] In this embodiment, the first node may be equivalent to Figure 1 The computing node 2 in the example may be referred to as a new node; the second node may be equivalent to Figure 1 The computing node 1 in the second node may be called the old node. The OVS of the second node (referred to as the second OVS) has a CT table to be transmitted or imported to the OVS of the first node (referred to as the first OVS).
[0050] In this embodiment, the SDN controller adds one or more specific flow table entries in the first flow table of the internal bridge of the first node, so as to identify and match the first message and restore the connection tracking table. The internal bridge can be described as a br-int bridge. The internal bridge (i.e., br-int bridge) can be used to manage internal network communications between virtual machines and implement data packet forwarding between virtual machines.
[0051] In this embodiment, the first flow table can also be described as a default flow table or Table 0. The SDN controller adds one or more specific flow table entries in the first flow table (i.e., Table 0) of the internal bridge (i.e., br-int bridge) of the first node for subsequent identification and matching of the first message and recovery of the connection tracking table.
[0052] In some optional embodiments, the SDN controller communicates with the first OVS of the first node to add one or more flow table entries in the first flow table of the internal bridge of the first OVS, including: the SDN controller generates one or more flow table entries, and sends flow table information containing the one or more flow table entries to the first OVS of the first node, so that the internal bridge of the first OVS adds the one or more flow table entries in the first flow table according to the flow table information; wherein the flow table entry includes at least a matching domain field and an action field; wherein the matching domain field includes at least: first information, the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards; the action field includes at least: second information, the second information is used to indicate a message that configures the source address of the Ethernet frame as tag information and the destination address of the Ethernet frame as matching information, and submits it to the CT module of the OVS.
[0053] In this embodiment, the SDN controller generates the one or more flow table entries according to preset rules. The preset rules are set according to the identification and matching requirements in this embodiment. The flow table entry includes at least a matching domain field and an action field; the matching domain field includes at least: first information, the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards; the action field includes at least: second information, the second information is used to indicate that the source address of the Ethernet frame is configured as the tag information, and the destination address of the Ethernet frame is configured as the matching information, and the message is submitted to the CT module of OVS.
[0054] Exemplarily, the identification and matching rules represented by a flow table entry may include:
[0055] Match domain: (priority = highest priority, protocol = ip, inbound port = veth_ct_in), action: (configure ct_mask = eth_dst, configure ct_label = eth_src, submit to OVS CT module); or
[0056] Match domain: (priority = highest priority, protocol = icmp, inbound port = veth_ct_in), action: (configure ct_mask = eth_dst, configure ct_label = eth_src, submit to OVS CT module).
[0057] In other optional embodiments, the identification matching rule represented by the flow table entry may also include: matching domain: (priority=lowest priority), action: (discard).
[0058] The identification and matching rules represented by the above flow table entries are only examples. Other identification and matching rules may be included according to different protocol types, which will not be described here.
[0059] Before executing this embodiment, or before executing step 101, the first node creates a pair of virtual network cards (e.g., veth_pair) including a first virtual network card and a second virtual network card, for example, named (veth_ct_in, veth_ct_out); the pair of virtual network cards (i.e., veth_ct_in and veth_ct_out) are added to the first OVS on an internal bridge (e.g., br-int). Veth_ct_in represents the second virtual network card; correspondingly, veth_ct_out represents the first virtual network card. It can be understood that the pair of virtual network cards can represent a virtual network path with an inbound direction and an outbound direction, or can be understood as a virtual network cable.
[0060] In some optional embodiments, the connection tracking table includes at least one table entry, each of which includes: protocol type, connection information, connection status information, tag information and matching information; wherein,
[0061] The protocol types include: Transmission Control Protocol (TCP), User Datagram Protocol (UDP) or Internet Control Message Protocol (ICMP);
[0062] The connection information includes: source IP address, destination IP address, source port number and destination port number;
[0063] The connection status includes: a synchronization sequence number sent status, a connected status, and a waiting status before termination.
[0064] In this embodiment, the connection tracking table (CT table) generated by the second OVS of the second node includes at least one table entry, each of which includes: a protocol type field, a connection information field, a connection status information field, a tag information field, and a matching information field. The tag information field can be described as CT_MARK, which is used to fill in the tag information; the matching information field can be described as CT_LABEL, which is used to fill in the matching information.
[0065] In this embodiment, the connection tracking table (CT table) has a tag field and a match field. The tag field is used to fill in the customized tag information, and the match field is used to fill in the customized match information. Both can be customized according to the needs. Among them, as an implementation method, the tag information can be used to identify the message, and the match information can be used to match the message. As another implementation method, according to the length of the tag field and the match field, part of the tag field can be used to fill in the tag information, and the remaining part of the match field and the tag field can be used to fill in the match information. The specific setting can be based on the actual situation.
[0066] In this embodiment, the connection status information field is used to fill in the connection status information. As an implementation method, when the protocol type is TCP, there is a connection status, mainly including the synchronization sequence number sent status, the connected status, the waiting status before the end, and other connection status; in the case of other protocol types, there is no connection status. Then in the connection tracking table (CT table), the table items corresponding to the TCP protocol type, the connection status information field therein is filled with the corresponding connection status information; the table items corresponding to other protocol types except the TCP protocol type, the connection status information field therein may not be filled with information.
[0067] In this embodiment, the SDN controller can obtain the connection tracking table (CT table) in the second OVS by communicating with the second OVS of the second node. As an implementation method, the SDN controller can first send a request to the second OVS of the second node to request to obtain the connection tracking table (CT table); after receiving the request, the second OVS of the second node sends the connection tracking table (CT table) to the SDN controller. As another implementation method, when there is a need for hot migration, the second node can also actively send the connection tracking table (CT table) to the SDN controller, or can first send a notification to the SDN controller to inform it to send the connection tracking table (CT table) to the SDN controller, and after confirming that the SDN has received the notification, send the connection tracking table (CT table) to the SDN controller.
[0068] In this embodiment, the connection tracking table obtained by the SDN controller may be a connection tracking table containing all table entries in the second OVS of the second node, or may be a connection tracking table containing some table entries; wherein some table entries may be table entries for a specified user or a specified session, which may be set or configured according to actual needs, and this embodiment does not specifically limit this.
[0069] In this embodiment, after obtaining the connection tracking table of the second OVS, the SDN controller carries the content of the connection tracking table through the generated first message according to the specified message generation rule, and sends the first message to the first OVS of the first node; the first OVS identifies and matches the received first message through the one or more flow table entries in the first flow table obtained in step 101, thereby restoring the generation of the connection tracking table. As an example, the first message is a packet-out message.
[0070] In some optional embodiments, constructing the first message according to the connection tracking table includes: the SDN controller analyzing each entry in the connection tracking table, and constructing the first message according to each entry according to the following rules:
[0071] The action field of the first message is configured as: sending to the first virtual network card;
[0072] For the layer 2 header of the first message, the destination MAC address field is filled with the tag information, and the source MAC address field is filled with the matching information;
[0073] For the layer 3 header of the first message, the source IP field is filled with the source IP address, the destination IP field is filled with the destination IP address, and the IP protocol type field is filled with the protocol type;
[0074] For the layer 4 header of the first message, the source port number field is filled with the source port number, and the destination port number field is filled with the destination port number.
[0075] Exemplarily, taking the first message as a packet-out message as an example, the SDN controller generates a packet-out message according to the following rules by analyzing each entry of the connection tracking table one by one:
[0076] 1. Fill in the action field of the packet-out message: send to port: veth_ct_out
[0077] 2. The data part of the packet-out message is constructed as follows:
[0078] For the layer 2 header: the destination MAC address field is filled with the mark information of the CT_MARK field in the CT table entry, and the source MAC address field is filled with the matching information of the CT_LABEL field in the CT table entry;
[0079] For the Layer 3 header: fill in the source IP address in the source IP field, fill in the destination IP address in the destination IP field, and fill in the protocol type in the CT table entry in the IP protocol type field, such as TCP, UDP, or ICMP.
[0080] For the Layer 4 header: the source port number field is filled with the source port number in the CT table entry, and the destination port number field is filled with the destination port number in the CT table entry.
[0081] In some optional embodiments, when the protocol type is TCP, the flag field of the first message is filled with marking information indicating the connection state; wherein, when the connection state is a waiting state before termination, the marking information filled in the flag field of two consecutive first messages is used to indicate the waiting state before termination.
[0082] In this embodiment, for a TCP connection, there is a connection state, and this embodiment mainly targets the state where the synchronization sequence number has been sent (or recorded as the SYN state), the connected state (or recorded as the ESTABLISHED state), and the waiting state before the end (or recorded as the FIN_WAIT state). Among them, for the state where the synchronization sequence number has been sent (or recorded as the SYN state) and the connected state (or recorded as the ESTABLISHED state), the flag bit corresponding to each state can be filled in the flag field (such as the TCP FLAG field) of the first message. For example, for the state where the synchronization sequence number has been sent (or recorded as the SYN state), the SYN flag bit is filled in the TCP FLAG field of the first message; for the connected state (or recorded as the ESTABLISHED state), the ACK flag bit is filled in the TCP FLAG field of the first message.
[0083] In this embodiment, for the waiting state before the end (or recorded as FIN_WAIT state), two consecutive first messages are required, and the flag information corresponding to the waiting state before the end (or recorded as FIN_WAIT state) is filled in the flag field of the two consecutive first messages to indicate the waiting state before the end. For example, the ACK flag bit is filled in the TCPFLAG field of the first message; the FIN+ACK flag bit is filled in the TCP FLAG field of the second message.
[0084] Based on the above embodiments, an embodiment of the present invention further provides a method for synchronizing a connection tracking table. Figure 3 Schematic diagram of the process of the connection tracking table synchronization method according to an embodiment of the present invention Figure 2 ;like Figure 3 As shown, the method includes:
[0085] Step 201: A first node adds one or more flow table entries in a first flow table of an internal bridge of a first OVS of the first node by communicating with an SDN controller;
[0086] Step 202: The first OVS of the first node receives the first message sent by the SDN controller, identifies and matches the first message according to the one or more flow table entries, and generates a connection tracking table;
[0087] The first message is constructed by the SDN controller according to the connection tracking table obtained from the second OVS of the second node; the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge.
[0088] In this embodiment, the first node may be equivalent to Figure 1 The computing node 2 in the example may be referred to as a new node; the second node may be equivalent to Figure 1 The computing node 1 in the second node may be called the old node. The OVS of the second node (referred to as the second OVS) has a CT table to be transmitted or imported to the OVS of the first node (referred to as the first OVS).
[0089] In this embodiment, the SDN controller adds one or more specific flow table entries in the first flow table of the internal bridge of the first node, so as to identify and match the first message and restore the connection tracking table. The internal bridge can be described as a br-int bridge. The internal bridge (i.e., br-int bridge) can be used to manage internal network communications between virtual machines and implement data packet forwarding between virtual machines.
[0090] In this embodiment, the first flow table can also be described as a default flow table or Table 0. The SDN controller adds one or more specific flow table entries in the first flow table (i.e., Table 0) of the internal bridge (i.e., br-int bridge) of the first node for subsequent identification and matching of the first message and recovery of the connection tracking table.
[0091] In some optional embodiments, the first node communicates with the SDN controller, and adds one or more flow table entries in the first flow table of the internal bridge of the first OVS of the first node, including: the first OVS of the first node receives the flow table information containing the one or more flow table entries sent by the SDN, and adds the one or more flow table entries to the first flow table; wherein the flow table entry includes at least a matching domain field and an action field; wherein the matching domain field includes at least: first information, the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards; the action field includes at least: second information, the second information is used to indicate the message that the source address of the Ethernet frame is configured as the tag information and the destination address of the Ethernet frame is configured as the matching information, and is submitted to the CT module of the OVS.
[0092] In this embodiment, the SDN controller generates the one or more flow table entries according to preset rules. The preset rules are set according to the identification and matching requirements in this embodiment. The flow table entry includes at least a matching domain field and an action field; the matching domain field includes at least: first information, the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards; the action field includes at least: second information, the second information is used to indicate that the source address of the Ethernet frame is configured as the tag information, and the destination address of the Ethernet frame is configured as the matching information, and the message is submitted to the CT module of OVS.
[0093] Exemplarily, the identification and matching rules represented by a flow table entry may include:
[0094] Match domain: (priority = highest priority, protocol = ip, inbound port = veth_ct_in), action: (configure ct_mask = eth_dst, configure ct_label = eth_src, submit to OVS CT module); or
[0095] Match domain: (priority = highest priority, protocol = icmp, inbound port = veth_ct_in), action: (configure ct_mask = eth_dst, configure ct_label = eth_src, submit to OVS CT module).
[0096] In other optional embodiments, the identification matching rule represented by the flow table entry may also include: matching domain: (priority=lowest priority), action: (discard).
[0097] The identification and matching rules represented by the above flow table entries are only examples. Other identification and matching rules may be included according to different protocol types, which will not be described here.
[0098] In some optional embodiments, before the first node communicates with the SDN controller, the method further includes: the first node creates a pair of virtual network cards including a first virtual network card and a second virtual network card, and adds the pair of virtual network cards to the first OVS on an internal bridge.
[0099] Before executing this embodiment, or before executing step 201, the first node creates a pair of virtual network cards (e.g., veth_pair) including a first virtual network card and a second virtual network card, for example, named (veth_ct_in, veth_ct_out); the pair of virtual network cards (i.e., veth_ct_in and veth_ct_out) are added to the first OVS on the internal bridge (e.g., br-int). Among them, veth_ct_in represents the second virtual network card; correspondingly, veth_ct_out represents the first virtual network card. It can be understood that the pair of virtual network cards can represent a virtual network path with an inbound direction and an outbound direction, or can be understood as a virtual network cable.
[0100] In this embodiment, the first message capable of generating a connection tracking table (CT table) is constructed according to the following rules:
[0101] The action field of the first message is configured as: sending to the first virtual network card;
[0102] For the layer 2 header of the first message, the destination MAC address field is filled with the tag information, and the source MAC address field is filled with the matching information;
[0103] For the layer 3 header of the first message, the source IP field is filled with the source IP address, the destination IP field is filled with the destination IP address, and the IP protocol type field is filled with the protocol type;
[0104] For the layer 4 header of the first message, the source port number field is filled with the source port number, and the destination port number field is filled with the destination port number.
[0105] Exemplarily, taking the first message as a packet-out message as an example, the SDN controller generates a packet-out message according to the following rules by analyzing each entry of the connection tracking table one by one:
[0106] 1. Fill in the action field of the packet-out message: send to port: veth_ct_out
[0107] 2. The data part of the packet-out message is constructed as follows:
[0108] For the layer 2 header: the destination MAC address field is filled with the mark information of the CT_MARK field in the CT table entry, and the source MAC address field is filled with the matching information of the CT_LABEL field in the CT table entry;
[0109] For the Layer 3 header: fill in the source IP address in the source IP field, fill in the destination IP address in the destination IP field, and fill in the protocol type in the CT table entry in the IP protocol type field, such as TCP, UDP, or ICMP.
[0110] For the Layer 4 header: the source port number field is filled with the source port number in the CT table entry, and the destination port number field is filled with the destination port number in the CT table entry.
[0111] In some optional embodiments, when the protocol type is TCP, the flag field of the first message is filled with marking information indicating the connection state; wherein, when the connection state is a waiting state before termination, the marking information filled in the flag field of two consecutive first messages is used to indicate the waiting state before termination.
[0112] In this embodiment, for a TCP connection, there is a connection state, and this embodiment mainly targets the state where the synchronization sequence number has been sent (or recorded as the SYN state), the connected state (or recorded as the ESTABLISHED state), and the waiting state before the end (or recorded as the FIN_WAIT state). Among them, for the state where the synchronization sequence number has been sent (or recorded as the SYN state) and the connected state (or recorded as the ESTABLISHED state), the flag bit corresponding to each state can be filled in the flag field (such as the TCP FLAG field) of the first message. For example, for the state where the synchronization sequence number has been sent (or recorded as the SYN state), the SYN flag bit is filled in the TCP FLAG field of the first message; for the connected state (or recorded as the ESTABLISHED state), the ACK flag bit is filled in the TCP FLAG field of the first message.
[0113] In this embodiment, for the waiting state before the end (or recorded as FIN_WAIT state), two consecutive first messages are required, and the flag information corresponding to the waiting state before the end (or recorded as FIN_WAIT state) is filled in the flag field of the two consecutive first messages to indicate the waiting state before the end. For example, the ACK flag bit is filled in the TCPFLAG field of the first message; the FIN+ACK flag bit is filled in the TCP FLAG field of the second message.
[0114] In some optional embodiments, the connection tracking table includes at least one table entry, each of which includes: protocol type, connection information, connection status information, tag information and matching information; wherein,
[0115] The protocol type includes: TCP, UDP or ICMP;
[0116] The connection information includes: source IP address, destination IP address, source port number and destination port number;
[0117] The connection status includes: a synchronization sequence number sent status, a connected status, and a waiting status before termination.
[0118] In this embodiment, after the internal bridge (br-int) of the first OVS of the first node receives the first message, it identifies and matches the message according to the specific one or more flow table entries added in the first flow table (i.e., Table 0) of the internal bridge (br-int), and automatically generates a connection tracking table (CT table) that is consistent with the connection tracking table (CT table) in the second node.
[0119] The generated connection tracking table (CT table) includes at least one table entry, each of which includes: a protocol type field, a connection information field, a connection status information field, a tag information field, and a matching information field. The tag information field can be described as CT_MARK, which is used to fill in the tag information; the matching information field can be described as CT_LABEL, which is used to fill in the matching information.
[0120] In this embodiment, the connection tracking table (CT table) has a tag field and a match field. The tag field is used to fill in the customized tag information, and the match field is used to fill in the customized match information. Both can be customized according to the needs. Among them, as an implementation method, the tag information can be used to identify the message, and the match information can be used to match the message. As another implementation method, according to the length of the tag field and the match field, part of the tag field can be used to fill in the tag information, and the remaining part of the match field and the tag field can be used to fill in the match information. The specific setting can be based on the actual situation.
[0121] In this embodiment, the connection status information field is used to fill in the connection status information. As an implementation method, when the protocol type is TCP, there is a connection status, mainly including the synchronization sequence number sent status, the connected status, the waiting status before the end, and other connection status; in the case of other protocol types, there is no connection status. Then in the connection tracking table (CT table), the table items corresponding to the TCP protocol type, the connection status information field therein is filled with the corresponding connection status information; the table items corresponding to other protocol types except the TCP protocol type, the connection status information field therein may not be filled with information.
[0122] In some optional embodiments of the present invention, after generating the connection tracking table, the method further includes: deleting the pair of virtual network cards.
[0123] The embodiment of the present invention is described below with reference to a specific example.
[0124] Figure 4a and Figure 4b FIG. 1 is a schematic diagram of an interactive process of a method for synchronizing a connection tracking table according to an embodiment of the present invention; in this example, computing node 1 is equivalent to the second node in the above embodiment, and computing node 2 is equivalent to the first node in the above embodiment. Figure 4a and Figure 4b As shown, the method includes:
[0125] Step 301: The OVS of computing node 1 generates a connection tracking table (CT table). The connection tracking table (CT table) includes at least one table entry, and each table entry includes: a protocol type field, a connection information field, a connection status information field, a tag information field, and a matching information field. The tag information field can be described as CT_MARK, which is used to fill in the tag information; the matching information field can be described as CT_LABEL, which is used to fill in the matching information.
[0126] Wherein, the protocol type includes: TCP, UDP or ICMP;
[0127] The connection information includes: source IP address, destination IP address, source port number and destination port number;
[0128] The connection status includes: a synchronization sequence number sent status (SYN status), a connected status (ESTABLISHED status), and a waiting status before termination (FIN_WAIT status).
[0129] Step 302: Computing node 2 creates a pair of virtual network cards including a first virtual network card and a second virtual network card, and adds the pair of virtual network cards to the internal bridge (br-int) of OVS.
[0130] Here, the pair of virtual network cards is recorded as veth_pair, for example, named (veth_ct_in, veth_ct_out); the pair of virtual network cards (i.e., veth_ct_in and veth_ct_out) is added to the internal bridge (such as br-int) of the OVS. Among them, veth_ct_in can represent the second virtual network card or virtual network card 2, and veth_ct_out can represent the first virtual network card or virtual network card 1.
[0131] It should be noted that the execution order of step 301 and step 302 is not limited to that shown above. In other optional embodiments, step 302 may be executed first and then step 301, or step 301 and step 302 may be executed simultaneously, which will not be elaborated in this embodiment.
[0132] Step 303: The SDN controller generates one or more flow table entries, and adds the one or more flow table entries to Table 0 of the internal bridge (br-int) of the OVS of computing node 2.
[0133] Here, the SDN controller generates one or more flow table entries, and sends flow table information containing the one or more flow table entries to the OVS of computing node 2, so that the internal bridge (br-int) of the OVS can add the one or more flow table entries in Table 0 according to the flow table information.
[0134] Exemplarily, the identification and matching rules represented by a flow table entry may include:
[0135] Match domain: (priority = highest priority, protocol = ip, inbound port = veth_ct_in), action: (configure ct_mask = eth_dst, configure ct_label = eth_src, submit to OVS CT module);
[0136] Match domain: (priority = highest priority, protocol = icmp, inbound port = veth_ct_in), action: (configure ct_mask = eth_dst, configure ct_label = eth_src, submit to OVS CT module).
[0137] Match domain: (priority = lowest priority), action: (discard).
[0138] Step 304: The SDN controller imports the CT table generated by the OVS of computing node 1.
[0139] Here, the SDN controller may obtain a connection tracking table (CT table) in the OVS of the computing node 1 by communicating with the OVS of the computing node 1 .
[0140] Step 305: The SDN controller constructs a first message according to the CT table.
[0141] Here, the first message may be a packet-out message of the Openflow protocol.
[0142] The SDN controller analyzes each entry in the connection tracking table one by one and generates a packet-out message according to the following rules:
[0143] 1. Fill in the action field of the packet-out message: send to port: veth_ct_out
[0144] 2. The data part of the packet-out message is constructed as follows:
[0145] For the layer 2 header: the destination MAC address field is filled with the mark information of the CT_MARK field in the CT table entry, and the source MAC address field is filled with the matching information of the CT_LABEL field in the CT table entry;
[0146] For the Layer 3 header: fill in the source IP address in the source IP field, fill in the destination IP address in the destination IP field, and fill in the protocol type in the CT table entry in the IP protocol type field, such as TCP, UDP, or ICMP.
[0147] For the Layer 4 header: the source port number field is filled with the source port number in the CT table entry, and the destination port number field is filled with the destination port number in the CT table entry.
[0148] For TCP connection, there is a connection state. This embodiment mainly targets the state where the synchronization sequence number has been sent (or recorded as SYN state), the connected state (or recorded as ESTABLISHED state), and the waiting state before the end (or recorded as FIN_WAIT state). Among them, for the state where the synchronization sequence number has been sent (or recorded as SYN state) and the connected state (or recorded as ESTABLISHED state), the flag bit corresponding to each state can be filled in the flag field (such as TCP FLAG field) of the packet-out message. For example, for the state where the synchronization sequence number has been sent (or recorded as SYN state), the SYN flag bit is filled in the TCP FLAG field of the packet-out message; for the connected state (or recorded as ESTABLISHED state), the ACK flag bit is filled in the TCP FLAG field of the packet-out message.
[0149] In this embodiment, for the waiting state before the end (or recorded as FIN_WAIT state), two consecutive packet-out messages are required, and the flag information corresponding to the waiting state before the end (or recorded as FIN_WAIT state) is filled in the flag field of the two consecutive packet-out messages to indicate the waiting state before the end. For example, the ACK flag bit is filled in the TCP FLAG field of the first packet-out message; the FIN+ACK flag bit is filled in the TCP FLAG field of the second packet-out message.
[0150] Step 306: The SDN controller uses the OpenFlow protocol to send the first message (ie, packet-out message) to the internal bridge (br-int) of the OVS of computing node 2 in sequence.
[0151] Step 307: After the first message (ie, packet-out message) reaches the internal bridge (br-int) of the OVS of computing node 2, the CT table is automatically generated using the flow table entry in Table 0.
[0152] In other optional embodiments, after step 307, the method further includes: the OVS of computing node 2 deletes the created pair of virtual network cards (veth_ct_in, veth_ct_out).
[0153] By adopting the technical solution of the embodiment of the present invention, on the first aspect, by creating a pair of virtual network cards in the internal bridge of the OVS of the new node (i.e., the first node), combined with the action of the first message, the sending and receiving messages of the virtual machine port can be simulated, thereby realizing the reconstruction of the connection tracking table; compared with sending messages on each virtual machine port, or adding a corresponding simulated port to each virtual machine port, the number of virtual ports that need to be added is greatly reduced, saving resources.
[0154] Secondly, in the layer 2 header of the data message of the first message, the original source MAC address field and the destination MAC address field are reused to fill in the mark information (CT_MARK) and the matching information (CT_LABEL). This field reuse method can realize the synchronization of the two important custom fields of the mark information and the matching information in the CT table; since the original source MAC address field and the destination MAC address field have no practical effect in the CT table, the newly added flow table in the embodiment of the present invention will not process these two fields, so reusing these two fields will not affect the integrity and accuracy of the message, and the message can be correctly transmitted; compared with carrying these two field information through an additional message encapsulation method, the message length and the message header parsing burden will be increased, affecting the forwarding efficiency, so the embodiment of the present invention also improves the overall performance of the system on the other hand.
[0155] Thirdly, the first message corresponding to the connection tracking table is constructed through Openflow rules, and the action field in the first message (such as sending to the first virtual network card) is used. The corresponding flow table entry is configured in table0, including the ingress port as the second virtual network card. This can effectively distinguish the flow table channel of the normal message and the flow table channel synchronized with the CT table to prevent mutual influence.
[0156] Fourthly, by sending a first message with a flag field (such as a packet-out message) and filling in the ACK flag bit, a CT table entry in the connected (ESTABLISHED) state can be quickly established, thereby improving the performance of CT table synchronization; fifthly, by sending two consecutive first messages with a flag field (such as a packet-out message) in sequence, the flag field of the first first message (such as a packet-out message) is filled with the ACK flag bit, and the flag field of the second first message (such as a packet-out message) is filled with the FIN+ACK flag bit, thereby quickly establishing a CT table entry in the waiting (FIN_WAIT) state before the end, thereby improving the performance of CT table synchronization.
[0157] Based on the above embodiments, an embodiment of the present invention further provides a synchronization device for a connection tracking table, and the device is applied to an SDN controller. Figure 5 Schematic diagram of the structure of the synchronization device of the connection tracking table according to the embodiment of the present invention Figure 1 ;like Figure 5 As shown, the device includes: a first processing unit 11 and a first communication unit 12; wherein,
[0158] The first processing unit 11 is used to communicate with the first OVS of the first node through the first communication unit 12 to add one or more flow table entries in the first flow table of the internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message;
[0159] The first communication unit 12 is further configured to obtain a connection tracking table by communicating with a second OVS of the second node;
[0160] The first processing unit 11 is further used to construct a first message according to the connection tracking table, wherein the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge;
[0161] The first communication unit 12 is further configured to send the first message so that an internal bridge of the first OVS of the first node can identify and match the first message according to the one or more flow table entries in the first flow table and generate the connection tracking table.
[0162] In some optional embodiments of the present invention, the first processing unit 11 is used to generate one or more flow table entries, and send flow table information containing the one or more flow table entries to the first OVS of the first node through the first communication unit 12, so that the internal bridge of the first OVS adds the one or more flow table entries in the first flow table according to the flow table information; wherein the flow table entry includes at least a matching domain field and an action field; wherein,
[0163] The matching domain field at least includes: first information, wherein the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards;
[0164] The action field includes at least: second information, where the second information is used to indicate that a message that configures the source address of the Ethernet frame as tag information and the destination address of the Ethernet frame as matching information is submitted to the CT module of the OVS.
[0165] In some optional embodiments of the present invention, the connection tracking table includes at least one table entry, each table entry includes: protocol type, connection information, connection status information, tag information and matching information; wherein the protocol type includes: TCP, UDP or ICMP;
[0166] The connection information includes: source IP address, destination IP address, source port number and destination port number;
[0167] The connection status includes: a synchronization sequence number sent status, a connected status, and a waiting status before termination.
[0168] In some optional embodiments of the present invention, the first processing unit 11 is used to analyze each entry in the connection tracking table, and construct a first message according to each entry according to the following rules:
[0169] The action field of the first message is configured as: sending to the first virtual network card;
[0170] For the layer 2 header of the first message, the destination MAC address field is filled with the tag information, and the source MAC address field is filled with the matching information;
[0171] For the layer 3 header of the first message, the source IP field is filled with the source IP address, the destination IP field is filled with the destination IP address, and the IP protocol type field is filled with the protocol type;
[0172] For the layer 4 header of the first message, the source port number field is filled with the source port number, and the destination port number field is filled with the destination port number.
[0173] In some optional embodiments of the present invention, when the protocol type is TCP, the flag field of the first message is filled with marking information indicating the connection state;
[0174] Wherein, when the connection state is a waiting state before termination, the mark information filled in the flag field of two consecutive first messages is used to indicate the waiting state before termination.
[0175] In an embodiment of the present invention, the first processing unit 11 in the device can be implemented by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU) or a programmable gate array (FPGA) in actual applications; the first communication unit 12 in the device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in actual applications.
[0176] An embodiment of the present invention further provides a device for synchronizing a connection tracking table, and the device is applied to a first node. Figure 6 Schematic diagram of the structure of the synchronization device of the connection tracking table according to the embodiment of the present invention Figure 2 ;like Figure 6 As shown, the device includes: a second processing unit 21 and a second communication unit 22; wherein,
[0177] The second processing unit 21 is used to communicate with the SDN controller through the second communication unit 22, and add one or more flow table entries in the first flow table of the internal bridge of the first OVS; it is also used to receive the first message sent by the SDN controller in the first OVS through the second communication unit 22, identify and match the first message according to the one or more flow table entries, and generate a connection tracking table;
[0178] The first message is constructed by the SDN controller according to the connection tracking table obtained from the second OVS of the second node; the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge.
[0179] In some optional embodiments of the present invention, the second processing unit 21 is further configured to create a pair of virtual network cards including a first virtual network card and a second virtual network card, and add the pair of virtual network cards to the first OVS on an internal bridge.
[0180] In some optional embodiments of the present invention, the second processing unit 21 is used to receive the flow table information including the one or more flow table entries sent by the SDN on the first OVS through the second communication unit 22, and add the one or more flow table entries to the first flow table; wherein the flow table entry includes at least a matching domain field and an action field; wherein,
[0181] The matching domain field at least includes: first information, wherein the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards;
[0182] The action field includes at least: second information, where the second information is used to indicate that a message that configures the source address of the Ethernet frame as tag information and the destination address of the Ethernet frame as matching information is submitted to the CT module of the OVS.
[0183] In some optional embodiments of the present invention, the connection tracking table includes at least one table entry, each table entry includes: protocol type, connection information, connection status information, tag information and matching information; wherein the protocol type includes: TCP, UDP or ICMP;
[0184] The connection information includes: source IP address, destination IP address, source port number and destination port number;
[0185] The connection status includes: a synchronization sequence number sent status, a connected status, and a waiting status before termination.
[0186] In some optional embodiments of the present invention, the second processing unit 21 is further configured to delete the pair of virtual network cards after generating the connection tracking table.
[0187] In an embodiment of the present invention, the second processing unit 21 in the device can be implemented by a CPU, a DSP, an MCU or an FPGA in actual applications; the second communication unit 22 in the device can be implemented by a communication module (including: a basic communication kit, an operating system, a communication module, a standardized interface and protocol, etc.) and a transceiver antenna in actual applications.
[0188] It should be noted that: the synchronization device for the connection tracking table provided in the above embodiment only uses the division of the above program modules as an example when synchronizing the connection tracking table. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the synchronization device for the connection tracking table provided in the above embodiment and the synchronization method embodiment of the connection tracking table belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0189] An embodiment of the present invention further provides a communication device, where the communication device is an SDN controller or a first node. Figure 7 FIG. 1 is a schematic diagram of the hardware structure of a communication device according to an embodiment of the present invention. Figure 7 As shown, the communication device includes a memory 32, a processor 31, and a computer program stored in the memory 32 and executable on the processor 31. When the processor 31 executes the program, the steps of the method for synchronizing the connection tracking table of the SDN controller or the first node according to the embodiment of the present invention are implemented.
[0190] Optionally, the communication device may further include at least one communication interface 33. The various components in the communication device are coupled together via a bus system 34. It is understood that the bus system 34 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 34 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 7 Various buses are labeled as bus system 34 .
[0191] It can be understood that the memory 32 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory 32 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.
[0192] The method disclosed in the above embodiment of the present invention can be applied to the processor 31, or implemented by the processor 31. The processor 31 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit in the processor 31 or the instruction in the form of software. The above processor 31 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 31 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiment of the present invention. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present invention, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the memory 32. The processor 31 reads the information in the memory 32 and completes the steps of the above method in combination with its hardware.
[0193] In an exemplary embodiment, the communication device may be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), FPGA, general purpose processor, controller, MCU, microprocessor, or other electronic components to execute the aforementioned method.
[0194] In an exemplary embodiment, the present invention also provides a computer-readable storage medium, such as a memory 32 including a computer program, which can be executed by a processor 31 of a communication device to complete the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM; or it can be various devices including one or any combination of the above memories.
[0195] The computer-readable storage medium provided by the embodiment of the present invention stores a computer program, which, when executed by a processor, implements the steps of the method for synchronizing a connection tracking table of an SDN controller or a first node applied by the embodiment of the present invention.
[0196] An embodiment of the present application also provides a computer program product, including a computer program, which can be executed by a communication device (such as a processor 31 of the communication device) to complete the steps of any of the aforementioned methods for synchronizing a connection tracking table applied to an SDN controller or a first node.
[0197] The methods disclosed in several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0198] The features disclosed in several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0199] The features disclosed in several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0200] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0201] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0202] In addition, all functional units in the embodiments of the present invention may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0203] A person of ordinary skill in the art can understand that: all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium, which, when executed, executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, disks or optical disks.
[0204] Alternatively, if the above-mentioned integrated unit of the present invention is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention can be essentially or partly reflected in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.
[0205] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.
Claims
1. A method for synchronizing a connection tracking table, characterized in that: The method is applied to a software defined network (SDN) controller; the method comprises: The SDN controller communicates with a first open virtual switch OVS of the first node to add one or more flow table entries in a first flow table of an internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message; Obtain a connection tracking table by communicating with a second OVS of a second node, and construct a first message according to the connection tracking table, wherein an action field of the first message is used to indicate a first virtual network card in a pair of virtual network cards created by the first OVS on an internal network bridge; The first message is sent so that an internal bridge of the first OVS of the first node identifies and matches the first message according to the one or more flow table entries in the first flow table and generates the connection tracking table.
2. The method according to claim 1, characterized in that The SDN controller communicates with a first open virtual switch OVS of the first node to add one or more flow table entries in a first flow table of an internal bridge of the first OVS, including: The SDN generates one or more flow table entries, and sends flow table information containing the one or more flow table entries to the first OVS of the first node, so that the internal bridge of the first OVS adds the one or more flow table entries to the first flow table according to the flow table information; wherein the flow table entry includes at least a matching domain field and an action field; wherein, The matching domain field at least includes: first information, wherein the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards; The action field includes at least: second information, where the second information is used to indicate that a message that configures the source address of the Ethernet frame as tag information and the destination address of the Ethernet frame as matching information is submitted to the CT module of the OVS.
3. The method according to claim 1, characterized in that The connection tracking table includes at least one table entry, each of which includes: protocol type, connection information, connection status information, tag information and matching information; wherein, The protocol types include: Transmission Control Protocol TCP, User Datagram Protocol UDP or Internet Control Message Protocol ICMP; The connection information includes: a source Internet Protocol IP address, a destination Internet Protocol IP address, a source port number, and a destination port number; The connection status includes: a synchronization sequence number sent status, a connected status, and a waiting status before termination.
4. The method according to claim 3, characterized in that The step of constructing a first message according to the connection tracking table includes: The SDN controller analyzes each entry in the connection tracking table and constructs a first message according to each entry in accordance with the following rules: The action field of the first message is configured as: sending to the first virtual network card; For the layer 2 header of the first message, the destination MAC address field is filled with the tag information, and the source MAC address field is filled with the matching information; For the layer 3 header of the first message, the source IP field is filled with the source IP address, the destination IP field is filled with the destination IP address, and the IP protocol type field is filled with the protocol type; For the layer 4 header of the first message, the source port number field is filled with the source port number, and the destination port number field is filled with the destination port number.
5. The method according to claim 4, characterized in that When the protocol type is TCP, the flag field of the first message is filled with marking information indicating the connection state; Wherein, when the connection state is a waiting state before termination, the mark information filled in the flag field of two consecutive first messages is used to indicate the waiting state before termination.
6. A method for synchronizing a connection tracking table, characterized in that: The method is applied to a first node; the method comprises: The first node adds one or more flow table entries in a first flow table of an internal bridge of a first OVS of the first node by communicating with the SDN controller; The first OVS of the first node receives the first message sent by the SDN controller, identifies and matches the first message according to the one or more flow table entries, and generates a connection tracking table; The first message is constructed by the SDN controller according to the connection tracking table obtained from the second OVS of the second node; the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge.
7. The method according to claim 6, characterized in that Before the first node communicates with the SDN controller, the method further includes: The first node creates a pair of virtual network cards including a first virtual network card and a second virtual network card, and adds the pair of virtual network cards to the first OVS on an internal bridge.
8. The method according to claim 6, characterized in that The first node communicates with the SDN controller, and one or more flow table entries are added to a first flow table of an internal bridge of a first OVS of the first node, including: The first OVS of the first node receives the flow table information including the one or more flow table entries sent by the SDN, and adds the one or more flow table entries to the first flow table; wherein the flow table entry includes at least a matching domain field and an action field; wherein, The matching domain field at least includes: first information, wherein the first information indicates that the priority information is the highest priority, the protocol information, and the ingress port is the second virtual network card in the pair of virtual network cards; The action field includes at least: second information, where the second information is used to indicate that a message that configures the source address of the Ethernet frame as tag information and the destination address of the Ethernet frame as matching information is submitted to the CT module of the OVS.
9. The method according to claim 6, characterized in that The connection tracking table includes at least one table entry, each of which includes: protocol type, connection information, connection status information, tag information and matching information; wherein, The protocol type includes: TCP, UDP or ICMP; The connection information includes: source IP address, destination IP address, source port number and destination port number; The connection status includes: a synchronization sequence number sent status, a connected status, and a waiting status before termination.
10. The method according to claim 6, characterized in that After generating the connection tracking table, the method further includes: deleting the pair of virtual network cards.
11. A synchronization device for a connection tracking table, characterized in that: The device is applied to an SDN controller, and comprises: a first processing unit and a first communication unit; wherein, The first processing unit is used to communicate with the first OVS of the first node through the first communication unit to add one or more flow table entries in the first flow table of the internal bridge of the first OVS; wherein the one or more flow table entries are used for the internal bridge of the first OVS to identify and match the first message; The first communication unit is further configured to obtain a connection tracking table by communicating with a second OVS of the second node; The first processing unit is further used to construct a first message according to the connection tracking table, wherein the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge; The first communication unit is further used to send the first message so that the internal bridge of the first OVS of the first node can identify and match the first message according to the one or more flow table entries in the first flow table and generate the connection tracking table.
12. A synchronization device for a connection tracking table, characterized in that: The device is applied to a first node, and comprises: a second processing unit and a second communication unit; wherein, The second processing unit is used to communicate with the SDN controller through the second communication unit, and add one or more flow table entries in the first flow table of the internal bridge of the first OVS; and is also used to receive the first message sent by the SDN controller in the first OVS through the second communication unit, identify and match the first message according to the one or more flow table entries, and generate a connection tracking table; The first message is constructed by the SDN controller according to the connection tracking table obtained from the second OVS of the second node; the action field of the first message is used to indicate the first virtual network card in a pair of virtual network cards created by the first OVS on the internal bridge.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method described in any one of claims 1 to 5 are implemented; or, when the program is executed by a processor, the steps of the method described in any one of claims 6 to 10 are implemented.
14. A communication device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method described in any one of claims 1 to 5 are implemented; or, when the processor executes the program, the steps of the method described in any one of claims 6 to 10 are implemented.
15. A computer program product, characterized in that The method comprises computer program instructions, which enable a computer to execute the steps of the method according to any one of claims 1 to 5; or, the computer program instructions enable a computer to execute the steps of the method according to any one of claims 6 to 10.