Network function optimization method based on ODL controller
By implementing ARP answering service for virtual machine ports, whitelist network access control and hyper-large-scale network node simulation on the ODL controller, the problems of single network functions, slow response speed, complex ACL policies and no support for hyper-large-scale network node simulation in the existing technology are solved, and more efficient virtual machine response, simplified network access control and large-scale network simulation are achieved.
Patent Information
- Application Number
- CN202510138544.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-09
AI Technical Summary
In the prior art, the network function is single, the virtual machine response speed is slow, the ACL policy configuration is complex, and it does not support hyper-large-scale network node simulation.
The network function optimization method based on ODL controller is adopted, and ARP answering service is performed for a single virtual machine port, network access control is performed for whitelists, and super-large-scale network nodes are simulated using the flow table.
It improves the response speed of virtual machines, reduces latency, provides whitelist-oriented network access control, simplifies ACL policy settings, and supports hyper-large-scale network node simulation, providing a hyper-large-scale network virtualization derivation environment.
Smart Images

Figure CN119966725A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of controller network function technology in the field of software defined networks, and in particular to a network function optimization method based on an ODL controller. Background Art
[0002] ODL is a modular, scalable, upgradeable, and multi-protocol controller framework developed based on SDN. It is widely used in SDN data centers and cloud network environments. ODL provides basic network functions and network services at the control plane layer, and provides basic network abstraction modules. In terms of cloud-network integration combined with OpenStack, ODL provides the network component NetVirt, which basically replaces the Neutron network virtualization function of OpenStack, including Layer 2 forwarding, Layer 3 routing, ARP proxy, DHCP service, floating IP and other functions, and uses OpenFlow flow tables to implement lightweight network services.
[0003] Based on the above functions, the present invention optimizes the ODL virtualized network service in combination with actual application scenarios, and proposes ARP proxy service for virtual machine port level, ACL policy configuration for whitelist and ultra-large-scale network node simulation function. It can improve the response speed of virtual machines, reduce latency, provide whitelist-oriented network access control, simplify ACL policy settings, support ultra-large-scale network node simulation, and provide an ultra-large-scale network virtualization deduction environment in a large-scale virtualization simulation environment. Summary of the invention
[0004] In view of the above-mentioned technical deficiencies, the purpose of the present invention is to provide a network function optimization method based on an ODL controller to solve the problems in the prior art of single network function, slow virtual machine response speed, complex ACL policy configuration and lack of support for ultra-large-scale network node simulation.
[0005] In order to solve the above technical problems, the present invention adopts the following technical solutions: In a first aspect, the present invention provides a network function optimization method based on an ODL controller, the method comprising: Perform ARP proxy reply for a single virtual machine port and forward the matching ARP request based on the matching rules between the virtual machine IP address and MAC address; Network access control for whitelist; Use flow tables to simulate large-scale network nodes and simulate the network's ARP and ICMP replies.
[0006] Preferably, in a possible implementation of the first aspect, the ARP proxy service for a single virtual machine port is performed by modifying the ODL flow table, adding matching rules for the virtual machine IP and MAC in Table 81, and forwarding the matching ARP request to Table 220 for ARP proxy, thereby minimizing the ARP broadcast domain.
[0007] Preferably, in a possible implementation of the first aspect, the flow table design for ARP proxy for a single virtual machine port includes: setting a high priority rule in Table 81, matching the virtual machine IP and ARP request operation code, executing the ARP proxy action, including modifying the source / destination MAC address and ARP operation code, and forwarding to Table 220; at the same time, setting a low priority rule to forward unmatched ARP requests to Table 48.
[0008] Preferably, in a possible implementation of the first aspect, the network access control for the whitelist is performed by adding Table 171 to process the virtual machine access control in the whitelist, and according to the data and source MAC address matching rules, the virtual machine traffic in the whitelist is allowed to continue to be forwarded, and other traffic is discarded.
[0009] Preferably, in a possible implementation of the first aspect, the flow table design for network access control for the whitelist includes: setting rules in Table 43 to redirect traffic to the newly added Table 171; setting high priority rules in Table 171 to match whitelist virtual machines, and low priority rules to process unmatched traffic.
[0010] Preferably, in a possible implementation of the first aspect, the use of flow tables to simulate ultra-large-scale network nodes supports the simultaneous generation of 100,000 virtual nodes at the flow table layer, and realizes the network ping function, and increases the ARP proxy and ICMP proxy functions of the simulated network by modifying the ODL flow table, including setting rules in Table 81 to match the ARP request of the simulated network and forwarding it to the newly added Table 181 for ARP proxy, and setting rules in Table 19 to match the ICMP request of the simulated network and forwarding it to the newly added Table 182 for processing.
[0011] Preferably, in a possible implementation of the first aspect, the flow table design for simulating a large-scale network node using a flow table includes: setting a low priority rule in Table 81 to match the ARP request of the simulated network and forward it to the newly added Table 181 for ARP proxy reply; setting rules in Table 181 to execute ARP proxy reply actions, including modifying the MAC address and ARP operation code.
[0012] Preferably, in a possible implementation of the first aspect, the flow table design for simulating a large-scale network node using a flow table also includes: setting rules in Table 19 to match ICMP requests of the simulated network, and forwarding them to the newly added Table 182 for processing; setting rules in Table 182 to distinguish between real virtual machine and simulated network traffic according to the destination IP address, and performing corresponding forwarding or discarding actions.
[0013] Preferably, in a possible implementation of the first aspect, the process of modifying the ODL flow table includes: based on the existing ODL flow table, according to network function requirements, adding, deleting or modifying flow table entries, realizing ARP proxy for virtual machine ports, whitelist-oriented network access control and ultra-large-scale network node simulation.
[0014] The beneficial effects of the present invention are: through the ARP proxy service at the virtual machine port level, the ACL policy configuration for the whitelist and the ultra-large-scale network node simulation function, the response speed of the virtual machine is improved, the delay is reduced, and the network access control for the whitelist is provided, the ACL policy setting is simplified, and the ultra-large-scale network node simulation is supported, providing an ultra-large-scale network virtualization deduction environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0016] Figure 1 A flow chart of a network function optimization method based on an ODL controller is provided for this application.
[0017] Figure 2 An architectural diagram of functional components of a network function optimization method based on an ODL controller is provided for this application.
[0018] Figure 3 A flow table modification design diagram for the ARP proxy service of a single virtual machine port is provided for this application.
[0019] Figure 4 A flow table modification design diagram for whitelist-oriented network access control is provided for this application.
[0020] Figure 5 A flow table modification design diagram that supports the function of ultra-large-scale network node simulation is provided for this application. DETAILED DESCRIPTION
[0021] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0022] Embodiment 1: Figure 1 As shown, the present invention provides a network function optimization method based on an ODL controller, and the specific implementation process includes: Step S100: Build an integrated environment of ODL and OpenStack. The OVS of all computing nodes points to the ODL controller. When creating a basic network in Neutron, the ODL NetVirt component sends a basic flow table.
[0023] Specifically, Figure 2 The integrated environment of ODL and OpenStack includes the network service application layer, Neutron, and ODL. When building the integrated environment of ODL and OpenStack, the ODL controller is combined with the OpenStack platform. The OVS on all computing nodes is configured to point to the ODL controller. OVS will serve as a data plane device, responsible for forwarding data packets and processing data packets according to the flow table rules issued by the ODL controller.
[0024] In the Neutron component of OpenStack, when the basic network is created, the NetVirt component of ODL will automatically intervene and send basic flow tables to all relevant computing nodes. These basic flow tables contain the necessary rules for network initialization, such as the forwarding path of data packets, security policies, etc. As part of the ODL controller, the NetVirt component is responsible for handling the flow table delivery and management tasks related to the virtualized network. Through integration with Neutron, it realizes the control of the virtualized network environment.
[0025] Step S200: Build a network service application layer, build network application services for actual business scenarios based on OpenStack, and provide network whitelist functions and large-scale node simulation functions.
[0026] Specifically, after the construction of the ODL and OpenStack integrated environment is completed and the OVS of all computing nodes correctly points to the ODL controller, the network service application layer is built. In the network service application layer, based on the OpenStack platform, the network whitelist function and large-scale node simulation function are implemented. The network whitelist function is a security policy that allows administrators to specify IP addresses or subnets that can access specific network resources, thereby effectively preventing unauthorized access. Relying on the close integration of the NetVirt component and Neutron, by sending ACL flow tables to all relevant computing nodes, it ensures that only traffic that meets the whitelist rules is allowed to pass.
[0027] At the same time, in order to support the simulation and testing of large-scale network nodes, a large-scale node simulation function is designed in the network service application layer. A large number of virtual machine nodes are simulated on the OpenStack platform, and ARP proxy and ICMP proxy flow tables are sent to these nodes through the NetVirt component, thereby simulating a large network environment.
[0028] Step S300: Optimize the NetVirt component function. When creating a virtual machine port, trigger NetVirt's flow table sending operation to send the ARP proxy flow table of the virtual machine port to all computing nodes.
[0029] Specifically, Figure 3 The design diagram of the flow table modification for the ARP proxy service of a single virtual machine port is as follows: by modifying the ODL flow table for the ARP proxy service of a single virtual machine port, matching rules for the virtual machine IP and MAC are added in Table 81, and the matched ARP request is forwarded to Table 220 for ARP proxy, minimizing the ARP broadcast domain. The flow table design for the ARP proxy service of a single virtual machine port includes: setting a high priority rule in Table 81, matching the virtual machine IP and ARP request operation code, executing the ARP proxy action, including modifying the source / destination MAC address and ARP operation code, and forwarding it to Table 220; at the same time, setting a low priority rule to forward unmatched ARP requests to Table 48.
[0030] In this embodiment, originally in Table 43, the system will match the ARP protocol and the ARP request, then forward the data packet to Group 5000 (the group contains 3 buckets), report it to the controller, and forward the data packet to Table 48 and Table 81. In the subsequent process, Table 48 will further guide the data packet to Table 49 for self-learning, while Table 81 is responsible for matching the ARP proxy address, and then forwarding the data packet to Table 220.
[0031] The modified ARP proxy part flow table has added the ARP proxy function for the virtual machine port. Now, Group only sends data packets to Table81. In Table81, the system first matches the IP and MAC addresses of the virtual machine. Once the match is successful, the data packet will be forwarded to Table220. In the process before optimization, Table81 will perform a Drop operation on some data packets, but in the new process, these data packets are redirected to Table48.
[0032] Implement the ARP proxy function for virtual machine ports based on the existing ODL network flow table. Modify the flow table accordingly in each host node. Ensure that the ARP request for a single virtual machine does not exceed the host range, thereby minimizing the coverage of ARP broadcast.
[0033] Step S400: After setting the whitelist, trigger NetVirt's flow table distribution operation to distribute the ACL flow table to all computing nodes.
[0034] Specifically, Figure 4 The design diagram of the flow table modification for network access control facing whitelist is provided. The network access control facing whitelist is provided by adding Table 171 to process the access control of virtual machines in the whitelist. According to the data and source MAC address matching rules, the virtual machine traffic in the whitelist is allowed to continue to be forwarded, and other traffic is discarded. The flow table design for network access control facing whitelist includes: setting rules in Table 43 to redirect traffic to the newly added Table 171; setting high priority rules in Table 171 to match whitelist virtual machines, and low priority rules to handle unmatched traffic.
[0035] In this embodiment, in the original ODL flow table, after the ARP communication is processed in Table 43, the virtual machine traffic will be forwarded to Table 48, and then forwarded according to the destination MAC and source MAC addresses. The modified flow table adds Table 171, which is specifically used to process the virtual machine traffic in the network whitelist. Specifically, only when the MAC address of the virtual machine is in the whitelist, its traffic will be allowed to pass; and for the virtual machine traffic outside the whitelist, it will be discarded.
[0036] Step S500: After the ultra-large-scale network node simulation communication function is enabled, NetVirt is triggered to send the flow table operation, and the ARP proxy reply and ICMP proxy reply flow tables are sent to the computing node where the physical virtual machine is located.
[0037] Specifically, Figure 5In order to support the function of ultra-large-scale network node simulation, the flow table modification design diagram is provided to support the function of ultra-large-scale network node simulation, support the simultaneous generation of 100,000 virtual nodes in the flow table layer, and realize the network ping function. By modifying the ODL flow table, the ARP proxy and ICMP proxy functions of the simulated network are added, including setting rules in Table 81 to match the ARP request of the simulated network and forwarding it to the newly added Table 181 for ARP proxy, and setting rules in Table19 to match the ICMP request of the simulated network and forwarding it to the newly added Table 182 for processing.
[0038] The flow table design that supports the function of emulating ultra-large-scale network nodes includes: setting low-priority rules in Table 81 to match the ARP request of the simulated network and forward it to the newly added Table 181 for ARP proxy reply; setting rules in Table 181 to execute ARP proxy reply actions, including modifying MAC addresses and ARP opcodes. Setting rules in Table 19 to match ICMP requests of the simulated network and forward them to the newly added Table 182 for processing; setting rules in Table 182 to distinguish between real virtual machine and simulated network traffic based on the destination IP address, and performing corresponding forwarding or discarding actions.
[0039] In this embodiment, for the ARP proxy flow table, a flow table rule with a slightly lower priority is added on the basis of the ARP proxy flow table of the original ODL real network, which is used to simulate the ARP proxy of the network. This rule first matches Table81, whose priority is 90, and the condition is that the ARP request and the metadata field contain the VNI of the simulated network. When the match is successful, the rule will resubmit the data packet to Table 181 for processing. In Table 181, a rule with a priority of 100 is set to process the ARP request of the simulated network. The rule will construct an ARP reply message based on the target IP address and other relevant information in the request, and set the corresponding Ethernet source address, ARP operation code and other fields. Finally, the processed data packet is resubmitted to Table 220 for subsequent processing.
[0040] For the ICMP proxy flow table, a new Table 182 is added to process the ICMP requests of the simulated network. A rule with a priority of 20 is set in Table 19. When the metadata field of the data packet contains the VNI of the simulated network and the destination MAC address matches, the data packet is resubmitted to Table 182 for processing. In Table 182, two rules are set. The priority of the first rule is 100, and the condition is ICMP request and the destination IP address is the IP address of the real virtual machine. This rule will jump the data packet to Table 48 for subsequent processing. The priority of the second rule is 90, and the condition is ICMP request and the metadata field contains the VNI of the simulated network. This rule pushes, pops, and other operations on the Ethernet source address, destination address, and IP source address and destination address of the data packet.
[0041] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A network function optimization method based on an ODL controller, characterized in that: The method comprises: Perform ARP proxy reply for a single virtual machine port and forward the matching ARP request based on the matching rules between the virtual machine IP address and MAC address; Network access control for whitelist; Use flow tables to simulate large-scale network nodes and simulate the network's ARP and ICMP replies.
2. The network function optimization method according to claim 1, characterized in that: The ARP proxy service for a single virtual machine port modifies the ODL flow table, adds matching rules for the virtual machine IP and MAC in Table 81, forwards the matching ARP request to Table 220 for ARP proxy, and minimizes the ARP broadcast domain.
3. The network function optimization method according to claim 2, characterized in that: The flow table design for ARP proxy for a single virtual machine port includes: setting a high priority rule in Table 81, matching the virtual machine IP and ARP request operation code, executing the ARP proxy action, including modifying the source / destination MAC address and ARP operation code, and forwarding it to Table 220; at the same time, setting a low priority rule to forward unmatched ARP requests to Table 48.
4. The network function optimization method according to claim 1, characterized in that: The network access control for the whitelist is performed by adding Table 171 to process the access control of the virtual machines in the whitelist. According to the data and source MAC address matching rules, the virtual machine traffic in the whitelist is allowed to continue to be forwarded, and other traffic is discarded.
5. The network function optimization method according to claim 4, characterized in that: The flow table design for network access control for whitelists includes: setting rules in Table 43 to redirect traffic to the newly added Table 171; setting high-priority rules in Table 171 to match whitelisted virtual machines, and low-priority rules to handle unmatched traffic.
6. The network function optimization method according to claim 1, characterized in that: The use of flow tables to simulate ultra-large-scale network nodes supports the simultaneous generation of 100,000 virtual nodes at the flow table layer, and realizes the network ping function. By modifying the ODL flow table, the ARP proxy and ICMP proxy functions of the simulated network are added, including setting rules in Table 81 to match the ARP request of the simulated network and forwarding it to the newly added Table 181 for ARP proxy, and setting rules in Table 19 to match the ICMP request of the simulated network and forwarding it to the newly added Table 182 for processing.
7. The network function optimization method according to claim 6, characterized in that: The flow table design for simulating ultra-large-scale network nodes using flow tables includes: setting low-priority rules in Table 81 to match the ARP requests of the simulated network and forward them to the newly added Table 181 for ARP proxy reply; setting rules in Table 181 to execute ARP proxy reply actions, including modifying the MAC address and ARP operation code.
8. The network function optimization method according to claim 6, characterized in that: The flow table design for simulating ultra-large-scale network nodes using flow tables also includes: setting rules in Table 19 to match ICMP requests of the simulated network and forwarding them to the newly added Table 182 for processing; setting rules in Table 182 to distinguish between real virtual machine and simulated network traffic based on the destination IP address, and performing corresponding forwarding or discarding actions.
9. The network function optimization method as claimed in claims 1 to 8, characterized in that: The process of modifying the ODL flow table includes: based on the existing ODL flow table, according to network function requirements, adding, deleting or modifying flow table entries, realizing ARP proxy reply for virtual machine ports, network access control for whitelists, and ultra-large-scale network node simulation.