Network configuration method, network controller and network configuration system
Through automated network configuration methods and network controllers, the high labor costs and configuration errors caused by manual configuration of ACL policies in bare metal servers are solved, and more efficient and reliable network configuration is achieved.
Patent Information
- Application Number
- CN202510061113.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-15
AI Technical Summary
In the management and storage network of bare metal servers, manually configuring the ACL strategy leads to high labor costs, high resource consumption, and prone to configuration errors, especially when the number of bare metal servers increases sharply.
Provides a network configuration method and a network controller, which automatically determines configuration policy information and target servers by receiving policy configuration requests, locates target gateway devices, and sends configuration policies to target gateway devices to realize network configuration.
It reduces the labor cost of manual configuration, reduces the situation of manual configuration errors, and optimizes the resource usage of gateway devices.
Smart Images

Figure CN119945899A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to but is not limited to the field of communication technology, and in particular to a network configuration method, a network controller and a network configuration system. Background Art
[0002] A bare metal server is a physical server on the cloud that fully guarantees high performance, physical isolation, and security features in a cloud environment, and implements comprehensive management and efficient operation and maintenance of physical machine resource pools. The management network and storage network of bare metal are usually physical networks, and the management network and storage network are isolated and opened by configuring the corresponding access control list (ACL) policy on the gateway. In related technologies, ACL policies are manually configured on the gateways of the management network and storage network of bare metal servers to ensure that the network of bare metal servers can be safely isolated and opened. In addition, as the number of bare metal servers increases dramatically, the number of configured ACL policies also increases dramatically. These configurations consume gateway device resources as well as a large amount of labor costs. At the same time, there are cases where manual configuration errors occur. Summary of the invention
[0003] In view of this, the embodiments of the present application at least provide a network configuration method, a network controller and a network configuration system.
[0004] The technical solution of the embodiment of the present application is implemented as follows:
[0005] The present application provides a network configuration method, including:
[0006] In response to receiving the policy configuration request, determining configuration policy information based on the policy configuration request;
[0007] Based on the configuration policy information, determine the configuration policy and the target server corresponding to the configuration policy;
[0008] Determine the target gateway device corresponding to the physical network where the target server is located;
[0009] The configuration policy is sent to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy.
[0010] The embodiment of the present application provides a network controller, including an interface module, a management module, and a driver module, wherein:
[0011] The interface module is used to determine the configuration policy information based on the policy configuration request in response to receiving the policy configuration request;
[0012] A management module is used to determine the configuration policy and the target server corresponding to the configuration policy based on the configuration policy information; determine the target gateway device corresponding to the physical network where the target server is located;
[0013] The driver module is used to send a configuration policy to a target gateway device so that the target gateway device performs network configuration on a physical network where a target server is located based on the configuration policy.
[0014] An embodiment of the present application provides a network configuration system, which includes the above-mentioned network controller, target server and target gateway device, wherein the target gateway device is used to perform network configuration on the physical network where the target server is located based on the configuration policy.
[0015] In the embodiment of the present application, according to the received policy configuration request, the configuration policy information is determined, and according to the configuration policy information, the configuration policy and the target server corresponding to the configuration policy are determined; the target gateway device corresponding to the physical network where the target server is located is determined, and the configuration policy is sent to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy. In this way, after receiving the policy configuration request, the network controller automatically sends the corresponding configuration policy to the target gateway device according to the policy configuration request, so that the target gateway device performs the corresponding network configuration, reducing the labor cost of manual configuration and reducing the possibility of manual configuration errors.
[0016] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings herein are incorporated into the specification and constitute a part of the specification. These drawings illustrate embodiments consistent with the present application and are used together with the specification to illustrate the technical solution of the present application.
[0018] Figure 1 A schematic diagram of an implementation flow of a network configuration method provided in an embodiment of the present application;
[0019] Figure 2 A schematic diagram of the structure of a network controller provided in an embodiment of the present application;
[0020] Figure 3 A schematic diagram of the structure of a network configuration system provided in an embodiment of the present application;
[0021] Figure 4 A schematic diagram of the network architecture of the bare metal server Underlay security controller provided in an embodiment of the present application;
[0022] Figure 5A schematic diagram of the Underlay security controller architecture provided in an embodiment of the present application;
[0023] Figure 6 A schematic diagram of the interface module architecture provided in an embodiment of the present application;
[0024] Figure 7 A schematic diagram of the management module architecture provided in an embodiment of the present application;
[0025] Figure 8 A schematic diagram of a network logical topology provided for an embodiment of the present application;
[0026] Fig. 9 A schematic diagram of the drive module architecture provided in an embodiment of the present application;
[0027] Fig.10 This is a schematic diagram of the interaction timing of each module of the ACL policy issued by the underlay network security controller of the bare metal server in the cloud environment provided by the embodiment of the present application. DETAILED DESCRIPTION
[0028] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions of the present application are further elaborated in detail below in conjunction with the drawings and embodiments. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present application.
[0029] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0030] The terms "first / second / third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It is understandable that "first / second / third" can be interchanged with a specific order or sequence where permitted so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0031] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing this application and are not intended to limit this application.
[0032] The present application embodiment provides a network configuration method. Figure 1 A schematic diagram of the implementation flow of a network configuration method provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, the method includes the following steps S101 to S104:
[0033] Step S101: in response to receiving a policy configuration request, determining configuration policy information based on the policy configuration request;
[0034] Here, the policy configuration request is used to request the network controller to send a configuration policy (ie, ACL policy) to the target gateway device to achieve network security isolation and release between servers.
[0035] The configuration policy information may include the IP address of the source server, such as 192.168.10.0 / 24; the IP address of the target server, such as 192.168.11.2, 192.168.11.3, 192.168.11.4; the source port range (Source PortRange), such as [80, 8080, 8081]; the destination port range (Destination Port Range), such as 80-8081; the communication protocol (protocol), such as TCP; the network type (network type), such as storage.
[0036] In some implementations, the policy configuration request is configured by a user through a public cloud or private cloud management platform accessed by the user, and is sent to the network controller through a management node bare metal server management cluster.
[0037] In some implementations, operation and maintenance personnel may also send a policy configuration request to the network controller through a specific operation portal.
[0038] In some implementations, the interface module in the network controller receives the policy configuration request and performs a validity check on the parameters in the policy configuration request, including but not limited to checking the structure integrity, encoding format, character length, data type, whether it is non-empty, etc. According to the checked policy configuration request, the configuration policy information is determined.
[0039] In some implementations, the interface module sends the configuration policy information to a management module in the network controller.
[0040] In some implementations, upon receiving a policy configuration request, the network controller automatically sends a configuration policy to the target gateway device.
[0041] Step S102: Determine a configuration policy and a target server corresponding to the configuration policy based on the configuration policy information;
[0042] Here, the configuration policy is a network configuration policy between the physical network where the source server is located and the physical network where the target server is located, including but not limited to isolation and release.
[0043] The target server is the bare metal server to be interacted with.
[0044] In some implementations, the target server is determined based on the IP address of the target server in the configuration policy information.
[0045] In some implementations, the management module of the network controller receives the configuration policy information sent by the interface module, determines the configuration policy, and performs duplication, conflict, and error checks on the configuration policy to reduce network anomalies after the configuration policy is issued.
[0046] Step S103: Determine the target gateway device corresponding to the physical network where the target server is located;
[0047] Here, the target gateway device is a gateway device corresponding to the network where the switch that manages the target server is located.
[0048] The target gateway device may be at least one of a bare metal access switch, a core switch, an aggregation switch, and the like.
[0049] In some implementations, the target gateway device corresponding to the physical network where the target server is located is determined based on the gateway device information of each physical network, the switch information under each physical network, and the server information corresponding to the servers managed by each switch stored in the database.
[0050] In some implementations, first, according to the network type in the configuration policy information, based on the network type, the target network where the target server is located is searched in the candidate networks corresponding to the network type in the database, and the target gateway device is determined.
[0051] The network type may include but is not limited to at least one of a management network (manage), a storage network (storage), a remote direct memory access (RDMA), and the like.
[0052] In some implementations, the networks where the same bare metal server is located are different, and the corresponding IP addresses are also different. Therefore, first, the physical network where the switch that manages the target server is located is determined based on the IP address of the target bare metal server in the configuration policy information, so that the physical network where the target server is located can be determined.
[0053] In some embodiments, the management module in the network controller determines the configured policy corresponding to the target gateway device from the database, and when the current configuration policy and the configured policy can be merged, the current configuration policy and the configured policy are merged and optimized to obtain a merged configuration policy to reduce the configuration policy resource occupancy of the target gateway device.
[0054] In some implementations, when the configuration policies of the target gateway device are merged and optimized, the optimized configuration policies are first sent to the target gateway device, and then the original configuration policies of the target gateway device are deleted.
[0055] Step S104: Send the configuration policy to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy.
[0056] In some implementations, the target gateway device is an intermediate link for intercommunication with other networks, and a corresponding configuration policy is configured on the target gateway device to achieve isolation or communication between different networks.
[0057] In some implementations, after the target gateway device completes the network configuration, it sends a configuration success response to the network controller. After receiving the configuration success response, the network controller writes the configuration policy into the database.
[0058] In the embodiment of the present application, according to the received policy configuration request, the configuration policy information is determined, and according to the configuration policy information, the configuration policy and the target server corresponding to the configuration policy are determined; the target gateway device corresponding to the physical network where the target server is located is determined, and the configuration policy is sent to the target gateway device, so that the target gateway device performs network configuration on the network where the target server is located based on the configuration policy. In this way, after receiving the policy configuration request, the network controller automatically sends the corresponding configuration policy to the target gateway device according to the policy configuration request, so that the target gateway device performs the corresponding network configuration, reducing the labor cost of manual configuration and reducing the situation of manual configuration errors.
[0059] In some embodiments, the above method further includes the following step S111:
[0060] Step S111: In response to receiving a policy configuration request, before determining the configuration policy information based on the policy configuration request, the gateway device information of the gateway devices of each of the physical networks, the switch device information of each switch in the physical network, and the server information corresponding to the servers managed by each of the switches are stored in a database.
[0061] In some implementations, the network controller enters the information of each switch device and the server information corresponding to the servers managed by the switch device into the database in advance, and marks the network type of each switch, such as management network, storage network, RDMA, etc. for classification management, and associates IPs of different network types with bare metal servers as units.
[0062] The network controller provides an operation interface for adding, deleting, modifying and checking the entered information of each switch device and the server information corresponding to the servers managed by the switch device, so as to update the entered information.
[0063] In an embodiment of the present application, by storing the gateway device information of the gateway devices of each network, the switch device information of the switches in each network, and the server information corresponding to the servers managed by each switch in a database in advance, a mapping of the upper and lower association relationships of the switches at each level in the network is obtained to form a logical topology diagram of the physical network, so that the network where the server is located and the corresponding gateway device can be accurately located according to the logical topology diagram.
[0064] In some embodiments, the above method further includes the following step S121:
[0065] Step S121: When the gateway device information, the switch device information and / or the server information corresponding to the servers managed by the switches change, the gateway device information, the switch device information and / or the server information corresponding to the servers managed by the switches stored in the database are updated.
[0066] In some embodiments, when the network controller receives changes in the switch device information stored in the database, the gateway device information of the physical network where the switch is located, and / or the server information corresponding to the servers managed by each switch, the information stored in the database is updated to the latest information.
[0067] In the embodiment of the present application, when each gateway device information, each switch device information and / or the server information corresponding to the server managed by each switch changes, each gateway device information, each switch device information and / or the server information corresponding to the server managed by each switch stored in the database is updated. In this way, the database always stores the latest each gateway device information, each switch device information and the server information corresponding to the server managed by each switch, so that when the network controller issues the configuration policy, it can accurately locate the physical network where the target server is located, and the target gateway device according to the latest gateway device information, switch device information and the server information corresponding to the server managed by the switch.
[0068] In some embodiments, the step S103 of determining the target gateway device corresponding to the physical network where the target server is located includes the following steps S131 and S132:
[0069] Step S131: determining a logical topology diagram between the network controller, each gateway device, each switch and each server based on the information of each gateway device, each switch device and the server information corresponding to the server managed by each switch stored in the database;
[0070] In some embodiments, each network includes multiple switches, each switch can manage multiple servers, and each server can be managed by switches in different networks, but the networks where the switches managing the servers are located are different, and the IP addresses of the servers are also different. Servers in different networks interact through gateways in different networks, and the network controller only controls the gateways in different networks.
[0071] A logical topology diagram is formed based on the relationship between the network controller, different networks and the corresponding gateways, switches, and servers managed by the switches.
[0072] Step S132: Based on the logical topology diagram, determine the target gateway device corresponding to the physical network where the target server is located.
[0073] In some implementations, based on the IP address of the target server, the corresponding server is found from the logical topology map, and the target switch that manages the target server is determined, and the target network where the target switch is located is further determined. Finally, the target gateway device corresponding to the target network is determined.
[0074] In the embodiment of the present application, based on the information of each gateway device, the information of the switch device, and the server information corresponding to the server managed by each switch stored in the database, the logical topology diagram between the network controller, each gateway device, each switch, and each server is determined, and the target gateway device corresponding to the network where the target server is located is determined according to the logical topology diagram. In this way, the position of the target server in the logical topology diagram can be quickly located according to the logical topology diagram, and the target gateway device corresponding to the network where the target server is located can be quickly determined according to the association relationship between the switches at each level in the logical topology diagram.
[0075] In some embodiments, the step S132 described above, based on the logical topology diagram, determining the target gateway device corresponding to the physical network where the target server is located, includes the following steps S141 and S142:
[0076] Step S141: determining a target switch corresponding to the target server based on the logical topology diagram; the target switch is used to manage the target server;
[0077] Step S142: Based on the target network where the target switch is located, determine the target gateway device corresponding to the physical network where the target server is located.
[0078] In some implementations, the target server may also be searched for from a network of a corresponding network type in the logical topology diagram according to the network type corresponding to the target server, thereby narrowing the search scope and quickly finding the target network where the target server is located.
[0079] In some embodiments, the above method further includes the following steps S151 and S152:
[0080] Step S151: Obtaining the configured policy corresponding to the target gateway device from a database;
[0081] Here, the configured policy is the configuration policy that is in effect on the target gateway device.
[0082] Step S152: When the configuration policy and the configured policy satisfy a merging condition, merge the configuration policy with the configured policy to obtain a merged configuration policy.
[0083] In some implementations, the current configuration policy is compared with the configured policy. If the current configuration policy can be merged with the configured policy, the configuration policy is merged with the configured policy to obtain a merged configuration policy.
[0084] The sending of the configuration policy to the target gateway device in the above step S104 may include the following step S153:
[0085] Step S153: Send the merged configuration policy to the target gateway device.
[0086] In some implementations, after the merged configuration policy is sent to the target gateway device, the original configuration policy of the target gateway device is deleted.
[0087] In the embodiment of the present application, the configured policy corresponding to the target gateway device is obtained from the database, and when the configuration policy and the configured policy meet the merging condition, the configuration policy and the configured policy are merged to obtain the merged configuration policy, and the merged configuration policy is sent to the target gateway device. In this way, the configuration policies that can be merged are merged, and the number of entries of the policies configured on the target gateway device can be reduced, thereby reducing the resource consumption on the target gateway device.
[0088] In some embodiments, the above method may further include the following step S161:
[0089] Step S161: In response to receiving a configuration policy write success signal from the target gateway device, writing the configuration policy into a database.
[0090] In some implementations, after the target gateway device successfully writes the configuration policy, it sends a response of successful configuration policy writing to the network controller; after receiving the response of successful configuration policy writing, the network controller writes the configuration policy into the database.
[0091] After receiving the response indicating that the configuration policy is written successfully, the network controller sends a configuration success interface response to the user.
[0092] In the embodiment of the present application, in response to receiving the configuration policy write success sent by the target gateway device, the configuration policy is written into the database. In this way, the data stored in the database can be consistent with the currently effective policy, so that accurate policy information can be found from the database later.
[0093] The present application embodiment provides a network controller, Figure 2 A schematic diagram of the structure of a network controller provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the network controller 200 includes an interface module 201, a management module 202, and a driver module 203, wherein:
[0094] The interface module 201 is used to determine configuration policy information based on the policy configuration request in response to receiving the policy configuration request;
[0095] In some embodiments, the interface module 201 is used to receive requests for bare metal server management clusters and requests for switch management, and check the legitimacy of the request parameters. If the check passes, it is forwarded to the corresponding method of the management module for processing, otherwise the interface returns an exception message.
[0096] The interface module 201 supports operations such as management, viewing, deletion, and modification of gateways of the storage network and management network in the Underlay network (corresponding to the physical network in the aforementioned embodiment), and provides an interface for managing the gateways.
[0097] The interface module 201 includes an interface filtering module, an interface switching module, and an interface ACL policy module, wherein the interface filtering module is used to check the structural integrity, encoding format, character length, data type, whether it is non-empty, etc. of the interface call parameters; the interface switching module is mainly used to forward the switch information to the management module; the interface ACL policy module is mainly used to forward ACL policy-related requests (i.e., configuration policies) to the management module 202.
[0098] The management module 202 is used to determine the configuration policy and the target server corresponding to the configuration policy based on the configuration policy information; determine the target gateway device corresponding to the physical network where the target server is located;
[0099] In some implementations, the management module 202 mainly includes three parts: a management switching module, a management ACL policy module, and an optimization module, wherein:
[0100] The management switch module is mainly used to implement the logical processing of Underlay network gateway and switch related operations. When managing gateway devices and switches, the prepared network device information is entered into the security controller for management, and the upper and lower connection relationship mapping of each layer of switches is realized, thereby providing a logical topology diagram of the network.
[0101] The management switch module also supports maintenance operations such as viewing logical topology diagrams, adding, deleting, modifying, and checking network devices.
[0102] The management ACL policy module is mainly used to implement the logical processing of the configuration policy and write the processed configuration policy into the database. When the management ACL policy module receives the request of the interface module, it will determine which gateway device the corresponding configuration policy should be sent to through the management ACL policy module based on the device parameters in the request of the interface module, and perform duplication, conflict, and error checks on the configuration policy to avoid network anomalies after the configuration policy is sent.
[0103] The optimization module is mainly used to merge and optimize the configuration policies on the gateway device, record the optimized configuration policies into the database, and optimize the configuration policies that have been issued on the device to reduce the resource usage of the device's configuration policies.
[0104] The driver module 203 is used to send the configuration policy to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy.
[0105] In some implementations, the driver module 203 (Driver) may include a variety of different types of Drivers, which are mainly used to connect to a gateway device and send commands to the gateway device to implement the issuance of security rules such as ACL.
[0106] In the embodiment of the present application, the interface module determines the configuration policy information according to the received policy configuration request; the management module determines the configuration policy and the target server corresponding to the configuration policy according to the configuration policy information; determines the target gateway device corresponding to the physical network where the target server is located; the driver module sends the configuration policy to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy. In this way, after receiving the policy configuration request, the network controller automatically sends the corresponding configuration policy to the target gateway device according to the policy configuration request, so that the target gateway device performs the corresponding network configuration, reducing the labor cost of manual configuration and reducing the possibility of manual configuration errors.
[0107] In some embodiments, the network controller further comprises a database, wherein:
[0108] The management module is also used to store the device information corresponding to each gateway device and the server information corresponding to the server managed by each gateway device in the database before determining the configuration policy information based on the policy configuration request in response to receiving the policy configuration request.
[0109] In some implementations, the database is mainly used to receive data read, write, modify and other operations from the management module, as well as data read and other operation requests transmitted from the interface module, to implement data addition, deletion, modification and query operations.
[0110] In some embodiments, the management module is also used to update the gateway device information, the switch device information and / or the server information corresponding to the servers managed by each switch stored in the database when the gateway device information, the switch device information and / or the server information corresponding to the servers managed by each switch changes.
[0111] In some embodiments, the management module is also used to determine the logical topology diagram between the network controller, each gateway device, each switch and each server based on the gateway device information, each switch device information and the server information corresponding to the servers managed by each switch stored in the database; based on the logical topology diagram, determine the target gateway device corresponding to the physical network where the target server is located.
[0112] In some embodiments, the management module is also used to determine the target switch corresponding to the target server based on the logical topology diagram; the target switch is used to manage the target server; based on the target physical network where the target switch is located, determine the target gateway device corresponding to the physical network where the target server is located.
[0113] In some embodiments, the management module is further used to obtain the configured policy corresponding to the target gateway device from the database; if the configuration policy and the configured policy meet the merging condition, merge the configuration policy with the configured policy to obtain the merged configuration policy;
[0114] The driver module is also used to send the merged configuration policy to the target gateway device.
[0115] In some embodiments, the management module is further configured to write the configuration policy into a database in response to receiving a configuration policy write success signal sent by the target gateway device.
[0116] The present application embodiment provides a network configuration system. Figure 3 A schematic diagram of the composition structure of a network configuration system provided in an embodiment of the present application is shown in FIG. Figure 3 As shown, the network configuration system 300 includes the above-mentioned network controller 200, a target server 301 and a target gateway device 302, wherein the target gateway device 302 is used to perform network configuration on the physical network where the target server is located based on the configuration policy.
[0117] In some embodiments, the target gateway device is used to determine the source server address and the target server address based on the configuration policy; based on the source server address and the target server address, determine the first network where the source server is located and the second network where the target server is located, and perform network configuration on the second network so that the first network and the second network are isolated or interconnected.
[0118] In some implementations, the isolation or access between the first network and the second network is achieved by configuring a corresponding configuration policy on the target gateway device.
[0119] The following describes the application of the embodiments of the present disclosure in actual scenarios.
[0120] Bare metal servers are cloud-based physical servers that fully guarantee high performance, physical isolation, and security in a cloud environment, and enable comprehensive management and efficient operation and maintenance of physical machine resource pools. They have the same computing performance as physical machines, and are capable of handling some virtualization applications, high IO applications, high-performance computing, and other businesses, meeting the requirements of core application scenarios for high performance and stability. Bare metal servers support the full lifecycle management of bare metal hardware from shelf to shelf, and support the automated integrated deployment of application clusters after bare metal is issued, getting rid of virtualization characteristics and focusing on hardware feature function expansion.
[0121] In the cloud resource pool of the cloud computing management platform (OpenStack), the network of the bare metal server is divided into multiple network planes such as PXE, management, business, storage, and BMC. Among them, the business network is controlled by the Software Defined Network (SDN) like the cloud host, and SDN provides functions such as Dynamic Host Configuration Protocol (DHCP) address allocation, Virtual Private Cloud (VPC) network isolation, security groups and ACLs. The Preboot Execution Environment (PXE) network can reuse the business network. The Baseboard Management Controller (BMC) is the out-of-band management network of the bare metal server. The relevant network information needs to be configured in advance. It is mainly used in the bare metal server provisioning process and is also one of the important means of server operation and maintenance in the later stage. The management and storage network of the bare metal is usually a physical network (underlay network). The corresponding ACL needs to be configured on the gateway to isolate the management network and the storage network to prevent different customers from accessing each other through the underlay network after the bare metal server is provisioned, thereby reducing network security risks. In supercomputing scenarios, there may be other high-performance underlay networks such as Remote Direct Memory Access (RDMA), which also require security management.
[0122] In the related technologies, during the hardware integration and software integration phases of resource pool construction, bare metal servers will manually configure ACLs on the bare metal management network and storage network gateways to isolate and open the network, ensuring the network security isolation and opening of bare metal servers while ensuring the normal operation of bare metal server functions on the cloud. As the scale of cloud resource pools gradually expands, the number of bare metal servers managed is also increasing dramatically, and the number of ACLs that need to be configured is also increasing dramatically. These configurations consume gateway device resources, as well as a large amount of labor costs, and there may be manual configuration errors.
[0123] Based on the above description, the embodiment of the present application proposes a bare metal server underlay network security management method in a cloud environment, which can automatically configure the security policy of the bare metal server underlay network, reduce the labor cost and gateway hardware resources consumed by security management configuration, and reduce the error rate of manual configuration. It can also be connected to a public cloud management platform or a private cloud management platform for customers to use, providing customers with a customized security configuration entry for the underlay network of the ordered bare metal server, and providing a rich underlay network configuration method.
[0124] Figure 4 A schematic diagram of the network architecture of the bare metal server Underlay security controller provided in the embodiment of the present application is shown in FIG. Figure 4 As shown, the network architecture mainly includes an underlay security controller 403 (corresponding to the network controller in the aforementioned embodiment), a bare metal server management cluster 402, a public (private) cloud management platform 401, a management network 410, a storage network 420, a first bare metal server 404, a second bare metal server 405, a third bare metal server 406, a fourth bare metal server 407, a first cloud hard disk 424, a first cloud hard disk 425, an object storage 426 and a file storage 427; wherein, the management network 410 includes: a management access switch, a management aggregation switch, a management network core switch 411, a bare metal management TOR switch 412, etc., assuming that the management network core switch 411 is the gateway of the management network 410; the storage network 420 includes: a storage core switch 421, a bare metal storage TOR switch 422, a storage access switch 423, a storage aggregation switch, etc., assuming that the storage core switch 421 is the gateway of the storage network 420.
[0125] The underlay security controller records the information of each switch in advance and manages it. It uses a whitelist to deny all by default, that is, it denies all inbound or outbound network traffic without explicit permission. At the same time, it identifies the bare metal servers managed by different switches, marks different types of underlay networks, such as storage network (storage), management network (manage), remote direct memory access (Remote Direct Memory Access, RDMA), etc. for classified management, identifies the bare metal server IP addresses under different networks, and associates IPs of different network types with bare metal servers as units.
[0126] After the underlay security controller manages the bare metal server, when the underlay network of the bare metal (BM) needs to be isolated, the bare metal server management cluster interacts with the underlay security controller through the management network. The interaction information includes: source IP prefix (Source IP Prefix), such as 192.168.10.0 / 24; destination IP prefix (Destination IP Prefix), such as 192.168.11.2, 192.168.11.3, 192.168.11.4; source port range (Source Port Range), such as [80, 8080, 8081]; destination port range (Destination Port Range), such as 80-8081; communication protocol (protocol), such as TCP; network type (network type), such as storage.
[0127] After receiving the request, the underlay security controller will issue ACL configuration to the gateway devices of each underlay network. Figure 5 A schematic diagram of the Underlay security controller architecture provided in the embodiment of the present application is shown in FIG. Figure 5 As shown, the bare metal server Underlay security controller in the cloud environment mainly includes an interface module 201 (i.e., API module), a management module 202 (i.e., Manage module), a driver module (i.e., Driver module), and a database 204 (i.e., DB module), among which:
[0128] The API module is used to receive requests for bare metal server cluster management and switch management, and check the legitimacy of request parameters. If the check passes, it is forwarded to the corresponding method of the Manage module for processing. Otherwise, the interface returns an exception message.
[0129] Figure 6 The interface module architecture diagram provided in the embodiment of the present application is as follows: Figure 6As shown, the interface module 201 receives the request sent by the bare metal server management cluster, and provides an operation entry for adding, deleting, modifying, and checking the bare metal servers managed by each switch; the interface filtering module 213 (i.e., the API-Filter module) is used to check the structural integrity, encoding format, character length, data type, and whether the interface call parameters are non-empty. The interface switching module 211 (i.e., the interface Switch submodule) is mainly used to forward switch-related requests to the management switching module 221 in the management module 202. The interface ACL policy module 212 (i.e., the interface ACL submodule) is mainly used to forward ACL policy-related requests to the management ACL policy module 222 in the management module 202.
[0130] The interface parameters of the interface module 201 include the following information: source IP prefix (Source IP Prefix), for example, 192.168.10.0 / 24; destination IP prefix (Destination IP Prefix), for example, 192.168.11.2, 192.168.11.3, 192.168.11.4; source port range (Source Port Range), for example, [80, 8080, 8081]; destination port range (Destination Port Range), for example, 80-8081; communication protocol (protocol), for example, TCP; network type (network type), for example, storage.
[0131] The interface module 201 supports operations such as managing, viewing, deleting, and modifying the gateways of the storage network and the management network in the Underlay network, and provides an interface for managing the gateways. The interface parameters and response examples for querying the storage gateway information in the managed switch are as follows:
[0132] Request parameters:
[0133]
[0134] The Manage module is mainly used to receive requests from the API module, and write the processed data into the database for storage after processing by the corresponding business logic.
[0135] Figure 7 A schematic diagram of the management module architecture provided in the embodiment of the present application is shown in FIG. Figure 7 As shown, the management module 202 mainly includes three parts: a management switch module 221 (management switch submodule), a management ACL policy module (management ACL submodule), and an optimization module 223 (Optimization module), wherein:
[0136] The management switching module 221 is mainly used to implement the logical processing of Underlay network gateway related operations. When managing gateway devices, the network device information prepared in advance is entered into the security controller for management, and the upper and lower connection relationship mapping of each layer of switches is realized, thereby providing a logical topology diagram of the network. Figure 8 A schematic diagram of the network logical topology provided in the embodiment of the present application is shown in FIG. Figure 8 As shown, the Underlay security controller 403 interacts with the management network core switch 411 in the management network 410, and the management network core switch 411 interacts with the first bare metal server 404, the second bare metal server 405, the third bare metal server 406, and the fourth bare metal server 407 through the bare metal management TOR switch 412; the Underlay security controller 403 interacts with the storage core switch 421 in the storage network 420, and the storage core switch 421 interacts with the first bare metal server 404, the second bare metal server 405, the third bare metal server 406, and the fourth bare metal server 407 through the bare metal storage TOR switch 422; the Underlay security controller 403 interacts with the RDMA network 430, and the RDMA network 430 interacts with the first bare metal server 404, the second bare metal server 405, the third bare metal server 406, and the fourth bare metal server 407 through the bare metal RDMA network TOR switch 431.
[0137] The management switch module 221 also supports maintenance operations such as viewing the network logical topology, adding, deleting, modifying, and checking network devices.
[0138] The management ACL policy module 222 is mainly used to implement the logical processing of ACL and write the processed ACL into the database. When the management ACL policy module 222 receives the request of the interface module 201, it will determine which gateway device the corresponding ACL policy should be sent to through the management ACL policy module 222 according to the TOR device parameters in the request of the interface module 201, and perform duplication, conflict and error checks on the ACL policy to avoid network anomalies after the ACL policy is sent.
[0139] The optimization module 223 (Optimization) is mainly used to merge and optimize the ACL policies on the gateway device, record the optimized ACL into the database, and optimize the ACL that has been issued on the device to reduce the ACL resource usage of the device. The acl policies before and after optimization are as follows:
[0140] Before optimization:
[0141] rule 1permit source 192.168.10.2 0.0.0.0
[0142] rule 2permit source 192.168.10.3 0.0.0.0
[0143] After optimization:
[0144] rule n permit source 192.168.10.254 0.0.0.0
[0145] The driver module 203 (Driver module) may include a variety of different types of Drivers, which are mainly used to connect to the gateway device and send commands to the gateway device to implement the issuance of security rules such as ACL. Fig. 9 A schematic diagram of the drive module architecture provided in the embodiment of the present application is shown in FIG. Fig. 9 As shown, the driver module 203 includes multiple driver modules such as driver 1, driver 2, driver N, etc., wherein driver 1 includes sub-modules such as connection module 1 (connect sub-module), command line module 1 (cmd sub-module) and netconf module 1 (netconf sub-module); driver 2 includes sub-modules such as connection module 2, command line module 2 and netconf module 2; driver N includes sub-modules such as connection module N, command line module N and netconf module N.
[0146] The connect submodule is mainly used to realize the interconnection with the gateway device. The interconnection with the gateway device is realized through the gateway information in the configuration file, and the switch can be logged in or configured by remote login or netconf command.
[0147] The cmd submodule is mainly used to combine and execute commands issued by security rules such as ACL when interconnecting with gateway devices.
[0148] The netconf submodule combines ACL rules through the netconf protocol and sends them to the switch to implement ACL configuration.
[0149] The database 204 is mainly used to receive data reading, writing, modifying and other operations from the management module 202, and also includes data reading and other operation requests transmitted from the interface module 201, to implement data adding, deleting, modifying and querying operations.
[0150] Fig.10 The schematic diagram of the interaction timing of each module of the bare metal server underlay network security controller issuing ACL policy in the cloud environment provided by the embodiment of the present application is as follows Fig.10 As shown, the underlay network security controller may include the following steps S1001 to S1009:
[0151] Step S1001: issuing ACL;
[0152] The user initiates an ACL configuration request and sends it to the interface module.
[0153] Step S1002: check parameters and forward the request;
[0154] The interface module receives the request sent by the user and performs parameter check through the interface filtering module. After the check, the relevant request is forwarded to the management module.
[0155] Step S1003: receiving the request, and analyzing and determining the switch to be sent;
[0156] The management module analyzes the received request and determines which switch device to forward it to.
[0157] Step S1004: the management module obtains all ACL information of the current switch from the database;
[0158] Step S1005: ACL duplication, conflict, and error checking;
[0159] The management module checks the ACL for duplication, conflict, and errors.
[0160] Step S1006: ACL optimization;
[0161] The management module determines whether the merger can be performed. If the ACL merger can be performed, the optimization module merges and optimizes the ACL.
[0162] Step S1007: Send the ACL to be issued to the driver module;
[0163] The management module forwards the optimized ACL to the driver module.
[0164] Step S1008: Determine the switch type, authenticate and link permissions, and convert the configuration to be issued into NetConf;
[0165] The driver module determines the switch type and performs operations such as device authority authentication, device linking, and Netconf conversion, and finally sends the information to the switch.
[0166] Step S1009: the request is sent to the switch device;
[0167] The driver module sends the policy configuration request to the switch device.
[0168] Step S1010: configuration writing;
[0169] The switch device writes configuration and responds to the management module after successful configuration.
[0170] Step S1011: writing into database;
[0171] The management module receives the configuration success response and writes the successfully issued configuration into the database DB.
[0172] Step S1012: Configuration success interface response.
[0173] The management module returns a write success response to the interface module, and the interface module sends a configuration success response to the user.
[0174] In the embodiment of the present application, the underlay network of the bare metal server is automatically issued and optimized through the underlay security controller, which reduces the manual configuration cost of the physical network and saves the physical resources of the switch; the underlay security controller can be connected to the public cloud or private cloud management platform for customers to use, providing customers with a customized security configuration entry for the underlay network of the bare metal server they have ordered, and providing a richer underlay network configuration method. The management module can manage the switches in the underlay network and realize the mapping of the upper and lower association relationships of switches at all levels to form a logical topology diagram of the physical network; the management module can also save and optimize the ACL, and compare the ACLs on different gateway devices for optimization and merging, reducing the ACL resource consumption of the switch.
[0175] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the serial number of each step / process mentioned above does not mean the order of execution, and the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The serial numbers of the embodiments of the present application mentioned above are for description only and do not represent the advantages and disadvantages of the embodiments.
[0176] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0177] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0178] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0179] In addition, all functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may be a separate unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0180] A person skilled in the art can understand that all or part of the steps of implementing the above method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM), magnetic disks or optical disks, etc., various media that can store program codes.
[0181] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can essentially or in other words, the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROMs, magnetic disks, or optical disks.
[0182] The above is only an implementation method of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.
Claims
1. A network configuration method, characterized in that: Applied to a network controller, the method comprises: In response to receiving the policy configuration request, determining configuration policy information based on the policy configuration request; Based on the configuration policy information, determine the configuration policy and the target server corresponding to the configuration policy; Determine a target gateway device corresponding to the physical network where the target server is located; The configuration policy is sent to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy.
2. The method according to claim 1, characterized in that The method further comprises: In response to receiving a policy configuration request, before determining the configuration policy information based on the policy configuration request, the gateway device information of each gateway device of the physical network, the switch device information of each switch in the physical network, and the server information corresponding to the server managed by each switch are stored in the database.
3. The method according to claim 2, characterized in that The method further comprises: When the gateway device information, the switch device information and / or the server information corresponding to the servers managed by the switches change, the gateway device information, the switch device information and / or the server information corresponding to the servers managed by the switches stored in the database are updated.
4. The method according to claim 2, characterized in that The step of determining a target gateway device corresponding to the physical network where the target server is located includes: Determine a logical topology diagram between the network controller, each gateway device, each switch and each server based on the information of each gateway device, each switch device and the server information corresponding to the server managed by each switch stored in the database; Based on the logical topology diagram, a target gateway device corresponding to the physical network where the target server is located is determined.
5. The method according to claim 4, characterized in that The determining, based on the logical topology diagram, a target gateway device corresponding to the physical network where the target server is located, includes: Based on the logical topology diagram, determining a target switch corresponding to the target server; the target switch is used to manage the target server; Based on the target physical network where the target switch is located, a target gateway device corresponding to the physical network where the target server is located is determined.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Obtaining a configured policy corresponding to the target gateway device from a database; In the case where the configuration policy and the configured policy meet a merging condition, merging the configuration policy with the configured policy to obtain a merged configuration policy; The sending the configuration policy to the target gateway device includes: The merged configuration policy is sent to the target gateway device.
7. The method according to any one of claims 1 to 5, characterized in that The method further comprises: In response to receiving the configuration policy write success sent by the target gateway device, the configuration policy is written into the database.
8. A network controller, characterized in that: It includes interface module, management module and driver module, among which: The interface module is used to determine configuration policy information based on the policy configuration request in response to receiving the policy configuration request; The management module is used to determine the configuration policy and the target server corresponding to the configuration policy based on the configuration policy information; determine the target gateway device corresponding to the physical network where the target server is located; The driver module is used to send the configuration policy to the target gateway device, so that the target gateway device performs network configuration on the physical network where the target server is located based on the configuration policy.
9. The network controller according to claim 8, characterized in that: The network controller also includes a database, wherein: The management module is also used to store the device information corresponding to each gateway device and the server information corresponding to the server managed by each gateway device in the database before determining the configuration policy information based on the policy configuration request in response to receiving the policy configuration request.
10. A network configuration system, characterized in that: The network configuration system includes a network controller, a target server and a target gateway device as described in claim 8 or 9, wherein the target gateway device is used to perform network configuration on the physical network where the target server is located based on the configuration policy.
11. The network configuration system according to claim 10, characterized in that: The target gateway device is used to determine the source server address and the target server address based on the configuration policy; determine the first network where the source server is located and the second network where the target server is located based on the source server address and the target server address, and perform network configuration on the second network so that the first network and the second network are isolated or interconnected.
Citation Information
Patent Citations
Cross-data-center virtual machine migration method, service control gateway and cross-data-center virtual machine migration
CN102884763A
Network policy configuration method, management device and network management centre device
CN103026660A
Docker-oriented mandatory access control security policy automatic generation method and system
CN114003344A
Method, system and equipment for deploying gateway of battery swap station and medium
CN116418662A
Network policy configuration method, management device, and network management center device
US20140133358A1