Flow migration method and device
By setting up two sets of switches in the data center network to migrate different types of traffic in stages, the problem of traffic migration in the existing technology requires downtime, and traffic migration without downtime is achieved, reducing the impact on data interaction.
Patent Information
- Application Number
- CN202311487934.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-08
- Publication Date
- 2025-05-09
AI Technical Summary
In the prior art, traffic migration requires shutdown, resulting in a large impact on data interaction and a long recovery time.
By setting up two switch sets in the data center network, namely the first switch set and the second switch set, different types of traffic are migrated to the second switch set in stages to achieve traffic migration without downtime.
It reduces the impact of traffic migration on data interaction, shortens the time for data interaction recovery, and improves the stability of traffic transmission.
Smart Images

Figure CN119966926A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network communication technology, and in particular to a traffic migration method and device. Background Art
[0002] In current networks, data needs to be forwarded through switches to achieve data interaction and realize corresponding services. Switches can be used as transit devices for traffic data.
[0003] However, as the business changes, you may need to replace the switch for traffic forwarding. For example, the switch equipment is old and the forwarding capability is poor. Therefore, you need to migrate the traffic on the old switch to the new switch.
[0004] The current traffic migration method requires downtime for migration, which has a significant impact on data interaction and takes a long time to restore data interaction. Summary of the invention
[0005] The present disclosure provides a traffic migration method and device to address the deficiencies in the related art.
[0006] According to a first aspect of an embodiment of the present disclosure, there is provided a traffic migration method, which is applied to a data center network, wherein the data center network includes a first switch set and a plurality of sub-networks;
[0007] The method comprises:
[0008] Migrating the first traffic within any sub-network transmitted by the first switch set to a second switch set; the second switch set is pre-set in the data center network;
[0009] Migrating second traffic between different sub-networks transmitted by the first switch set to the second switch set;
[0010] Migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.
[0011] According to a second aspect of an embodiment of the present disclosure, there is provided a traffic migration device, which is applied to a data center network, wherein the data center network includes: a first switch set and a plurality of sub-networks;
[0012] The device comprises:
[0013] A first traffic migration unit, configured to migrate first traffic within any sub-network transmitted by the first switch set to a second switch set; the second switch set is pre-set in the data center network;
[0014] A second traffic migration unit, configured to migrate second traffic between different sub-networks transmitted by the first switch set to the second switch set;
[0015] The third traffic migration unit is used to migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.
[0016] According to the above embodiments, it can be seen that the stability of traffic transmission can be improved by migrating different traffic flows separately, thereby reducing the impact of traffic migration on data interaction and shortening the time for data interaction recovery.
[0017] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0019] Figure 1 It is a flow chart of a traffic migration method according to an embodiment of the present disclosure;
[0020] Figure 2 is a structural diagram of a data center network according to an embodiment of the present disclosure;
[0021] Figure 3 is a structural diagram of another data center network according to an embodiment of the present disclosure;
[0022] Figure 4 It is a schematic diagram showing the principle of traffic migration within a sub-network according to an embodiment of the present disclosure;
[0023] Figure 5 It is a schematic diagram showing the principle of traffic migration between sub-networks according to an embodiment of the present disclosure;
[0024] Figure 6 It is a schematic diagram showing the principle of traffic migration between a sub-network and an external device of a data center according to an embodiment of the present disclosure;
[0025] Figure 7 is a structural diagram of another data center network according to an embodiment of the present disclosure;
[0026] Figure 8 is a schematic diagram showing another principle of traffic migration within a sub-network according to an embodiment of the present disclosure;
[0027] Fig. 9is a schematic diagram showing another principle of traffic migration between sub-networks according to an embodiment of the present disclosure;
[0028] Fig.10 is a schematic diagram showing the principle of traffic migration between another sub-network and external devices of a data center according to an embodiment of the present disclosure;
[0029] Fig.11 is a structural schematic diagram of a flow migration device according to an embodiment of the present disclosure;
[0030] Fig.12 It is a schematic diagram of the hardware structure of a computer device for configuring the method of the embodiment of the present disclosure according to the embodiment of the present disclosure. DETAILED DESCRIPTION
[0031] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0032] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of the present disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0033] In current networks, data needs to be forwarded through switches to achieve data interaction and realize corresponding services. Switches can be used as transit devices for traffic data.
[0034] However, as the business changes, you may need to replace the switch for traffic forwarding. For example, the switch equipment is old and the forwarding capability is poor. Therefore, you need to migrate the traffic on the old switch to the new switch.
[0035] The current traffic migration method requires the new switch to learn the route, then the old switch is shut down and replaced with the new switch to complete the traffic migration. This method has a great impact on data interaction, and the time for data interaction recovery is long.
[0036] In order to address the deficiencies in the related art, an embodiment of the present disclosure discloses a traffic migration method.
[0037] In this method, two different switch sets may be set, which are respectively referred to as a first switch set and a second switch set for the convenience of description. Traffic migration may be performed for these two switch sets.
[0038] In order to reduce the impact of traffic migration on data interaction, in this method, the traffic transmitted by the first switch set is divided into different types and migrated to the second switch set in stages.
[0039] Specifically, the traffic transmitted by the first switch set may be divided into different types according to a sender and a receiver of the traffic transmission.
[0040] The first switch set may perform traffic transfer transmission for multiple networks, specifically, transfer traffic within each network, transfer traffic between networks, or transfer traffic between each network and external devices.
[0041] During the specific migration, the traffic within each network, the traffic between each network, and the traffic between each network and external devices can also be migrated in stages.
[0042] By migrating traffic in stages, the first switch set and the second switch set can jointly transmit traffic during the migration process.
[0043] For the data sender, data can be sent through the first switch set or the second switch set. When data cannot be sent through one of the switch sets, data can be sent through the other switch set, thereby reducing the impact of traffic migration on data interaction.
[0044] In addition, migrating traffic in stages can help locate problems that occur during traffic migration. For example, if there is no problem with the migration of the first type of traffic, but a fault is found during the migration of the second type of traffic, it can be located that the problem is with the second type of traffic.
[0045] Migrating traffic in stages can also facilitate rollback. For example, after the first type of traffic is migrated, you can migrate the first type of traffic back for rollback as needed, while other traffic does not need to be migrated.
[0046] Therefore, in this method, different traffic flows can be migrated in stages, so that the first switch set and the second switch set can be used to transmit traffic during the traffic migration process, and the traffic migration does not require downtime, thereby improving the stability of traffic transmission and data interaction, reducing the impact of traffic migration on data interaction, and shortening the time for data interaction recovery.
[0047] The following is a detailed explanation of a traffic migration method provided in an embodiment of the present disclosure.
[0048] like Figure 1 As shown, Figure 1 It is a flow chart of a traffic migration method according to an embodiment of the present disclosure.
[0049] The embodiments of the present disclosure do not limit the execution subject of the method flow. Optionally, the execution subject can be any computing device, such as a terminal, a server, a development side device, etc.
[0050] Optionally, the method process may be applied to a data center network, which may include a first switch set and multiple sub-networks.
[0051] For ease of understanding, Figure 2 As shown, Figure 2 The structure diagram of a data center network according to an embodiment of the present disclosure is shown. It includes a first switch set, a second switch set and three sub-networks. The first switch set may include two switches, and the second switch set may include two switches.
[0052] Each switch in the first switch set is connected to three sub-networks, and performs traffic transfer transmission for the three sub-networks. After traffic migration, the traffic of the three sub-networks can be migrated to the second switch set.
[0053] in, Figure 2 The numbers of the various devices are only for illustrative purposes.
[0054] The method may include the following steps.
[0055] S101: Migrate first traffic in any sub-network transmitted by a first switch set to a second switch set.
[0056] The second switch set may be pre-set in the data center network.
[0057] S102: Migrate the second traffic between different sub-networks transmitted by the first switch set to the second switch set.
[0058] S103: Migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.
[0059] The above method process can migrate different traffic in stages, so that the first switch set and the second switch set can be used to transmit traffic during the traffic migration process, and the traffic migration does not require downtime, thereby improving the stability of traffic transmission and data interaction, reducing the impact of traffic migration on data interaction, and shortening the time for data interaction recovery.
[0060] Specifically, traffic data interaction in a data center network often involves business execution. Reducing the impact of traffic migration on data interaction can also reduce the impact of traffic migration on business.
[0061] The following is a detailed explanation of each aspect.
[0062] 1. About data center network.
[0063] The method process does not limit the specific forms of the data center network and sub-network.
[0064] Optionally, the data center network can be a network deployed for an organization, and the organization can be divided into multiple sub-organizations. In order to facilitate the use of the network and improve the security of the network, sub-networks can be deployed for each sub-organization. The sub-networks can communicate with each other, and the sub-networks can also communicate with each other. The data center network can contain the deployed sub-networks and is used to manage the contained sub-networks.
[0065] Optionally, the sub-network may include a switch set and other network devices, and the switch set may be used as a traffic transfer between the sub-network and the first switch set.
[0066] For the sake of distinction, the set of switches included in a subnetwork may be referred to as a subnetwork switch set.
[0067] Optionally, the data center network may further include a firewall, so that traffic in the data center network passes through the firewall for traffic cleaning to meet regulatory requirements and business security. The firewall may be set as a bypass for the first switch set.
[0068] This embodiment does not limit the specific form of the firewall.
[0069] Optionally, the firewall can be an east-west firewall for cleaning traffic between devices inside the data center network; the firewall can also be a north-south firewall for cleaning traffic between devices inside the data center network and outside the data center.
[0070] For ease of understanding, in a specific example, the switches in the sub-network switch set may be specifically spine switches, the switches in the first switch set may be specifically super-spine switches, and the switches in the second switch set may be specifically super-spine switches.
[0071] 2. Regarding the first switch set and the second switch set.
[0072] The method flow does not limit the specific forms of the first switch set and the second switch set. The first switch set and the second switch set can be different switch sets.
[0073] Optionally, the first switch set and the second switch set may be pre-deployed in the data center network. Optionally, the second switch set may be newly added in the data center network.
[0074] Optionally, the first switch set may be an old switch set, and the second switch set may be a new switch set, so that traffic can be migrated from the old switch set to the new switch set.
[0075] Optionally, the first switch set may be a new switch set, and the second switch set may be an old switch set, so that traffic may be migrated from the new switch set to the old switch set.
[0076] Optionally, the first switch set may include at least two stacked first switches; and the second switch set may include at least one independent second switch.
[0077] The first switch set may include multiple first switches combined in a stacking manner.
[0078] Stacking refers to connecting multiple switches that support stacking features through stacking cables, logically virtualizing them into a switching device, and participating in data forwarding as a whole. Stacking is a widely used horizontal virtualization technology that has the functions of improving reliability, expanding the number of ports, increasing bandwidth, and simplifying networking.
[0079] The second switch set may include a plurality of independent second switches, and each second switch performs traffic transfer transmission respectively.
[0080] This embodiment can achieve the effect of destacking by migrating traffic from the stacked first switch set to the independent second switch set. Specifically, it can be determined that destacking is required based on business needs, so that traffic can be migrated from the stacked switch set to the independent switch set.
[0081] Optionally, the first switch set may include at least one independent first switch; and the second switch set may include at least two stacked second switches.
[0082] This embodiment can achieve the effect of increasing the stack by migrating traffic from an independent first switch set to a stacked second switch set.
[0083] 3. About routing.
[0084] This method does not limit the specific method of traffic migration.
[0085] Optionally, the transmission and transit of traffic requires the deployment of routes in advance.
[0086] In an optional embodiment, for the second set of switches, routes for interacting with other devices in the data center network may be learned in advance.
[0087] For example, the routes for the second switch set to interact with each sub-network, the routes for the second switch set to interact with network devices within each sub-network, the routes for the second switch set to interact with devices outside the data center, the routes for the second switch set to interact with the firewall, and so on.
[0088] Optionally, the second switch set may be pre-deployed in the data center network to learn routing without forwarding data.
[0089] Optionally, routes in the first switch set may also be obtained, and the routes may be learned by replacing the network identifiers of switches in the first switch set with the network identifiers of switches in the second switch set.
[0090] Optionally, it is possible to check whether the routes in the first switch set are consistent with the routes in the second switch set, thereby determining whether to start traffic migration. Specifically, traffic migration may be started when it is determined that the routes in the first switch set are consistent with the routes in the second switch set.
[0091] Furthermore, optionally, in order to implement interaction with the second switch set, the devices in the data center network also need to deploy routing for interacting with the second switch set.
[0092] For example, the switches in the sub-network also need to deploy routes for interacting with the second set of switches, so that traffic can be transmitted based on the second set of switches.
[0093] Optionally, the routes learned by the second switch set may be published to other devices in the data center network through a route learning strategy, and specifically, the routes may be published through a dynamic routing protocol.
[0094] Optionally, the data center network may further include a first route and a second route.
[0095] Optionally, the first route may be used to transmit the first target traffic through the first switch set, and the second route may be used to transmit the first target traffic through the second switch set. The first target traffic may be any of the first traffic, the second traffic, and the third traffic.
[0096] This embodiment does not limit the devices on which the first route and the second route are deployed. Optionally, any device in the data center network can be deployed with the first route and the second route.
[0097] This embodiment does not limit the source of the second route. Optionally, the second route may be determined based on the route learned by the second switch set.
[0098] This method does not limit the specific method of traffic migration.
[0099] Optionally, traffic migration can be achieved by controlling the deletion of the first route or the second route so that the device selects the reserved route for traffic transmission.
[0100] Optionally, by controlling the priorities of the first route and the second route, a device deployed with the first route and the second route can select a route with a higher priority for traffic transmission, thereby achieving traffic migration.
[0101] Optionally, the above method flow may further include: during the migration of the first target traffic, controlling the priority of the first route to be lower than the priority of the second route.
[0102] In this embodiment, traffic migration is achieved by controlling the route priority, which can facilitate subsequent rollback and retain multiple routes, thereby improving the stability of traffic transmission.
[0103] For example, if a route with a higher priority fails, the device can select a route with a lower priority to continue traffic transmission, thereby reducing the impact on traffic transmission.
[0104] This embodiment does not limit the execution subject of controlling the routing priority. Optionally, it can be the data center network that controls the routing priority, or it can be the device in the data center network that controls the routing priority.
[0105] Optionally, for a device in a data center network that has a first route and a second route deployed therein, the priority of the first route can be controlled to be lower than the priority of the second route, thereby facilitating the device to select the second route with a higher priority for traffic transmission, thereby enabling traffic to be migrated from the first switch set to the second switch set.
[0106] In an optional embodiment, during the process of migrating traffic in stages, the routing priorities can be controlled separately to achieve traffic migration.
[0107] Optionally, the first traffic within any subnetwork transmitted by the first switch set is migrated to the second switch set. Specifically, during the first traffic migration process, a first routing priority for transmitting the first traffic is controlled to be smaller than a second routing priority for transmitting the first traffic.
[0108] Optionally, the second traffic between different sub-networks transmitted by the first switch set is migrated to the second switch set. Specifically, during the second traffic migration process, the first routing priority for transmitting the second traffic is controlled to be smaller than the second routing priority for transmitting the second traffic.
[0109] Optionally, the third traffic between any sub-network and a device outside the data center network transmitted by the first switch set is migrated to the second switch set. Specifically, during the migration of the third traffic, the first routing priority used to transmit the third traffic is controlled to be lower than the second routing priority used to transmit the third traffic.
[0110] This embodiment can realize traffic migration by controlling the routing priority, thereby improving the stability and efficiency of traffic migration.
[0111] 4. About the firewall.
[0112] The method process does not limit the specific form of the firewall in the data center network.
[0113] Optionally, the firewall may specifically include an east-west firewall and / or a north-south firewall.
[0114] Optionally, the firewall can be an east-west firewall for cleaning traffic between devices inside the data center network; the firewall can also be a north-south firewall for cleaning traffic between devices inside the data center network and outside the data center.
[0115] 1. East-west firewall.
[0116] In an optional embodiment, the firewall may include an east-west firewall.
[0117] Optionally, an east-west firewall may be set up in parallel with the first switch set to clean the traffic transmitted by the first switch set, specifically, the traffic transmitted by the first switch set may be cleaned according to the policy in the east-west firewall.
[0118] Optionally, in the process of migrating the traffic of the first switch set to the second switch set, an east-west firewall may be set for the second switch set to clean the traffic transmitted by the second switch set.
[0119] Optionally, the same east-west firewall may be deployed for the second set of switches.
[0120] Optionally, the same east-west firewall may be connected to the second switch set to clean the traffic transmitted by the second switch set.
[0121] Optionally, another east-west firewall may be deployed for the second switch set, and the traffic migrated by the second switch set may be transmitted to the deployed east-west firewall for traffic cleaning.
[0122] Optionally, the data center network may further include a first east-west firewall and a second east-west firewall.
[0123] Optionally, the above method flow may further include: in the process of transmitting the second traffic by the first switch set, the second traffic, that is, the second traffic interacting between different sub-networks, may be transmitted through the first east-west firewall.
[0124] Optionally, the second traffic is transmitted through the first east-west firewall. Specifically, during the process of transmitting the second traffic through the first switch set, the second traffic is cleaned through the first east-west firewall, and the cleaned second traffic is then transmitted to the first switch set, and the first switch set transmits the cleaned second traffic to the recipient.
[0125] Optionally, the second traffic is transmitted through the first east-west firewall. Specifically, during the process of the first switch set transmitting the second traffic, the second traffic is cleaned through the first east-west firewall, and the cleaned second traffic is transmitted to the receiver by the first east-west firewall.
[0126] Optionally, in the process of transmitting the second traffic by the second switch set, the second traffic may be transmitted through the second east-west firewall. Specific explanations may refer to the above embodiments.
[0127] Optionally, during the traffic migration process, the second traffic may be migrated to the second switch set and the second east-west firewall.
[0128] Optionally, the second traffic between different subnetworks transmitted by the first switch set is migrated to the second switch set, specifically, the second traffic between different subnetworks transmitted by the first switch set and the first east-west firewall is migrated to the second switch set and the second east-west firewall.
[0129] It is understandable that the first traffic within the subnet can also be cleaned through the east-west firewall.
[0130] Correspondingly, optionally, the above method flow may further include: in the process of transmitting the first traffic through the first switch set, the first traffic may be transmitted through the first east-west firewall.
[0131] Optionally, the first traffic within any subnetwork transmitted by the first switch set is migrated to the second switch set. Specifically, the first traffic transmitted by the first switch set and the first east-west firewall is migrated to the second switch set and the second east-west firewall.
[0132] The method process does not limit the routing source of the traffic transmitted through the second east-west firewall. Optionally, the routing of the second east-west firewall can be learned and deployed in advance, or can be learned and deployed through the second switch set.
[0133] The method flow does not limit the traffic cleaning strategy of the second east-west firewall. Optionally, the traffic cleaning strategy of the first east-west firewall can be copied, or a pre-configured traffic cleaning strategy can be obtained.
[0134] This embodiment can improve the migration efficiency by synchronously implementing the traffic migration of the switch set and the east-west firewall.
[0135] 2. North-south firewall.
[0136] In an optional embodiment, the firewall may include a north-south firewall for cleaning traffic between devices inside the data center network and outside the data center.
[0137] Optionally, a north-south firewall may be set up in bypass for the first switch set to clean the third traffic transmitted by the first switch set. Specifically, the third traffic transmitted by the first switch set may be cleaned according to the policy in the north-south firewall.
[0138] Optionally, in the process of migrating the traffic of the first switch set to the second switch set, a north-south firewall may be set for the second switch set to clean the third traffic transmitted by the second switch set.
[0139] Optionally, the same north-south firewall may be deployed for the second switch set.
[0140] Optionally, specifically, the same north-south firewall may be connected to the second switch set to clean the third traffic transmitted by the second switch set.
[0141] Optionally, another north-south firewall may be deployed for the second switch set, and the traffic migrated by the second switch set may be transmitted to the deployed north-south firewall for traffic cleaning.
[0142] Optionally, the data center network may further include a first north-south firewall and a second north-south firewall.
[0143] Optionally, the above method process may also include: in the process of transmitting the third traffic by the first switch set, the third traffic, that is, the third traffic interacting between the subnet and the device outside the data center network, may be transmitted through the first north-south firewall.
[0144] Optionally, the third traffic is transmitted through the first north-south firewall. Specifically, during the process of transmitting the third traffic through the first switch set, the third traffic is cleaned through the first north-south firewall, and then the cleaned third traffic is transmitted to the receiver.
[0145] Optionally, in the process of transmitting the third traffic by the second switch set, the third traffic may be transmitted through the second north-south firewall. Specific explanations may refer to the above embodiments.
[0146] Optionally, during the traffic migration process, the third traffic may be migrated to the second switch set and the second north-south firewall.
[0147] Optionally, the third traffic transmitted by the first switch set is migrated to the second switch set, which may be specifically: the third traffic transmitted by the first switch set and the first north-south firewall is migrated to the second switch set and the second north-south firewall.
[0148] The method process does not limit the routing source of the traffic transmitted through the second north-south firewall. Optionally, the routing of the second north-south firewall can be learned and deployed in advance, or can be learned and deployed through the second switch set.
[0149] Optionally, the route of the second north-south firewall can be a static route. For data sent from external devices of the data center, it can be determined that the next hop is the second switch set or the first switch set; for data sent from the second switch set or the first switch set, it can be determined that the next hop is the device that sends data to the outside through the data center network, thereby realizing data outbound transmission.
[0150] The method process does not limit the traffic cleaning strategy of the second north-south firewall. Optionally, the traffic cleaning strategy of the first north-south firewall can be copied, or a pre-configured traffic cleaning strategy can be obtained.
[0151] This embodiment can improve the migration efficiency by synchronously implementing the traffic migration of the switch set and the north-south firewall.
[0152] 5. Regarding the timing of migration.
[0153] The process of this method is to perform traffic migration in stages.
[0154] The method flow does not limit the way of dividing the stages and the specific stages divided.
[0155] Optionally, the stages may be divided by time length, specifically, the second flow may be started to be migrated after a first preset time length after the first flow is started to be migrated; and the third flow may be started to be migrated after a second preset time length after the second flow is started to be migrated.
[0156] Optionally, after the previous phase of traffic migration is completed, the next phase of traffic migration may be started. Specifically, when the first traffic migration is completed, the second traffic migration may be started; when the second traffic migration is completed, the third traffic migration may be started.
[0157] Optionally, in order to further improve the stability of traffic migration, after a phase of traffic migration is completed, you can wait until the migrated traffic can be stably transmitted before migrating to the next phase of traffic. This is because failures or other problems may occur during traffic migration. By determining whether the migrated traffic can be stably transmitted, you can determine whether there are failures or other problems in the current phase of traffic migration, which is convenient for troubleshooting and problem location.
[0158] This embodiment does not limit the specific form of stable transmission.
[0159] Optionally, stable transmission can be fault-free transmission that continues for a specified period of time, or can be fault-free transmission achieved during the transmission of a specified amount of traffic, and so on.
[0160] Therefore, optionally, the second traffic between different sub-networks transmitted by the first switch set is migrated to the second switch set. Specifically, it can be: when the first traffic migration is completed and the duration of the first traffic based on the second switch set without failure is greater than the first preset duration, the second traffic between different sub-networks transmitted by the first switch set is migrated to the second switch set.
[0161] Optionally, the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set is migrated to the second switch set. Specifically, it can be: when the second traffic migration is completed and the duration of the second traffic based on the fault-free transmission of the second switch set is greater than a second preset duration, the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set is migrated to the second switch set.
[0162] This embodiment can set the migration timing and start the migration of the next stage when it is determined that the traffic in the previous stage has completed the migration and can be transmitted stably. This can facilitate the resolution of faults and problem location during the traffic migration process, facilitate rollback, and improve the stability of traffic migration.
[0163] 6. About the migration process.
[0164] The method flow does not limit the specific process of traffic migration.
[0165] Optionally, during the process of traffic migration, the second route can be learned by the equipment in the data center network, and the traffic migration can be achieved by controlling the route priority, wherein the second route is used to transmit the first target traffic through the second switch set. The specific explanation can be found above.
[0166] Optionally, during the traffic migration process, there may be devices that have not yet learned the second route or have not yet controlled the route priority. For these devices, the original first route can be used to transmit traffic, which can reduce the impact of traffic migration on data interaction.
[0167] Optionally, since the traffic in the method process needs to be migrated in stages, during the first traffic migration process, the second traffic and the third traffic can also be transmitted using the original first route, thereby reducing the impact of traffic migration on data interaction.
[0168] Optionally, during the second traffic migration process, the third traffic may also be transmitted using the original first route, thereby reducing the impact of traffic migration on data interaction.
[0169] Therefore, optionally, for traffic that has not yet been migrated to the second switch set, the first route may be used for transmission, that is, the traffic may be transmitted based on the first switch set.
[0170] Optionally, the above method flow may also include: during the migration of the second target traffic, the traffic in the second target traffic that has not been migrated to the second switch set may be transmitted through the first switch set; the second target traffic is any one of the first traffic, the second traffic and the third traffic.
[0171] Optionally, during the traffic migration process, the traffic of the data center network that has not been migrated to the second switch set may be transmitted through the first switch set.
[0172] This embodiment can improve the stability of traffic transmission and reduce the impact of traffic migration on data interaction by allowing the first switch set and the second switch set to coexist during traffic migration to transmit traffic.
[0173] In addition, in an optional embodiment, traffic migration may also require rollback.
[0174] For example, if a serious fault is found in the second switch set, the migrated traffic can be rolled back and the first switch set can be used to continue traffic transmission. Alternatively, if the traffic after migration to the second switch set is found to not meet expectations, a rollback can be performed.
[0175] Optionally, since the flow of the present method migrates traffic in stages, the traffic that has been migrated can be re-migrated to the first switch set.
[0176] Optionally, the above method process may also include: in the case of rolling back the third target traffic that has been migrated to the second switch set, migrating the third target traffic from the second switch set to the first switch set; the third target traffic may be any one of the first traffic, the second traffic and the third traffic.
[0177] This embodiment can facilitate rollback based on phased traffic migration. And the impact on data interaction can also be reduced during the rollback process. For the specific explanation of migration back to the first switch set, please refer to the above embodiment.
[0178] In an optional embodiment, failures or other problems may also occur during the traffic migration process.
[0179] For example, after traffic migration, equipment failure may occur, resulting in failure of traffic transmission after migration; or, during the process of traffic migration, the device cannot control the routing priority, resulting in failure of successful traffic migration, etc.
[0180] Optionally, since the flow is migrated in stages in the process of this method, the time when the fault occurs can be determined to determine the flow where the fault occurs, thereby facilitating the location of the fault.
[0181] Optionally, the above method process may also include: in the event that the transmission of the fourth target traffic fails, inspecting the equipment and / or routes related to the fourth target traffic; the fourth target traffic may be any one of the first traffic, the second traffic and the third traffic.
[0182] This embodiment can facilitate fault location and fault detection based on phased traffic migration, thereby improving fault detection efficiency.
[0183] For ease of understanding, the present disclosure also provides an application example.
[0184] Due to their special industry attributes, financial institutions often need to clean traffic through firewalls when deploying data center networks (core switches will be connected to firewalls by-passing firewalls) to meet regulatory requirements and business security. This requires that the particularity of the network architecture must be fully considered when designing it.
[0185] Traditional financial institutions usually use stacking architecture in physical networking to meet the backup needs between primary and backup core switches. Internet companies mostly use data center architecture and use a single line to access the Internet to achieve company Internet connectivity and business development.
[0186] However, with the changes and rapid development of business needs, the disadvantages of virtualization stacking have gradually emerged after years of application, mainly manifested in:
[0187] 1. Since the control plane of the stacking system is integrated and normalized, once a problem occurs in the control plane, the entire stacking system will be affected.
[0188] 2. It is difficult to achieve smooth upgrades. The business side has increasingly higher requirements for network reliability. At the same time, new features and new requirements of equipment are constantly iterating. It is difficult to strictly guarantee uninterrupted business when releasing software versions of equipment. In addition, the online upgrade of the stacking system has strict steps and the operation is relatively cumbersome. Upgrading a set of stacks often takes a long time.
[0189] 3. It is not possible to have heterogeneous equipment from multiple manufacturers. Even equipment from the same manufacturer must have the same model or series.
[0190] 4. Although virtualization is very simple to deploy, its principles and internal implementation are actually complex, involving multiple processes such as physical connection, topology collection, role election, stack merging, stack splitting, member joining / exiting, conflict detection, etc. At each stage, many meticulous rules are defined to ensure the normal operation of the entire stacking system. The development and testing workload is very large, and a long period of R&D and maintenance experience accumulation is required.
[0191] 5. Device stacking links and MAD conflict detection links require additional switch port resources, and the limited number of high-speed ports cannot be fully used for uplinks.
[0192] Therefore, this embodiment can implement switch stacking.
[0193] In traditional stacking change solutions, there is generally no hardware firewall hanging in the network architecture, so the network architecture stacking is relatively simple. However, in the financial data center network, due to the particularity of the industry, there are often hardware firewalls hanging in the network architecture, which brings great difficulties to stacking, especially when ensuring the stable operation of the business, it will be more difficult to smoothly transform the network architecture.
[0194]
Solution Value
[0195] 1. From the perspective of network architecture, reduce systemic risks caused by manufacturer anomalies.
[0196] 2. Restructure network routing planning and deployment to make operation and maintenance logic clear, standardized, and less error-prone.
[0197] 3. Explore a feasible change plan for subsequent equipment room deployment and even for the same industry. (The only research on de-stacking solution with firewall in China, no mature experience and cases for reference)
[0198] This embodiment is mainly aimed at achieving smooth changes to the stack architecture when the core stack switches of the financial data center network have hardware firewalls hanging in bypass mode while reducing the impact on the business.
[0199]
Detailed explanation of the plan
[0200] like Figure 3 As shown, Figure 3 It is a structural diagram of another data center network according to an embodiment of the present disclosure.
[0201] Among them, the switches that contain sub-networks in the data center network are DATA-spine, XSKY-spine, DB-spine and APP-spine.
[0202] DATA-spine, XSKY-spine and DB-spine belong to the same sub-network, namely the data sub-network, namely VRF: data. VRF is specifically Virtual Routing and Rorwarding (VRF).
[0203] APP-spine belongs to another subnet, namely the public subnet, namely VRF: public.
[0204] The data center network also includes a first set of switches and a second set of switches.
[0205] The first switch set includes two stacked Super-spine switches, which are old Super-spine switches.
[0206] The second switch set includes two independent Super-spine switches, which are new Super-spine switches.
[0207] The data center network also includes the old east-west firewall hanging next to the old Super-spine switch in the stack, and the new east-west firewall hanging next to the new Super-spine switch.
[0208] The data center network also includes a north-south firewall that is attached to the first switch set and the second switch set.
[0209] The north-south firewall can be connected to the functional core switch for communication with the outside of the data center network.
[0210] The process of this embodiment is explained below with reference to a plurality of drawings.
[0211] like Figure 4 As shown, Figure 4 It is a schematic diagram showing the principle of traffic migration within a sub-network according to an embodiment of the present disclosure.
[0212] To switch traffic within the same VRF (subnet) to the new environment, that is, the new Super-spine switch, you can perform the following steps.
[0213] 1. Configuration deployment.
[0214] Deploy BGP Peer on the new Super-spine switch according to the Border Gateway Protocol (BGP). The spine switches in the subnetwork are not deployed to the BGP Peer of the new Super-spine switch for the time being. Deploy the routing policy on the new Super-spine switch: only receive routes, do not send routes.
[0215] The new Super-spine is marked with the not-export community attribute in the inbound direction of the DB-spine peer. The new Super-spine is not allowed to advertise any routes in the outbound direction of the DB-spine peer.
[0216] The spine switches in the sub-network are deployed to the BGP peer of the new super-spine without any routing policy.
[0217] 2. Check and confirm.
[0218] Check the BGP peer status on the new Super-spine; check the routes on the service Spine; check the consistency of the routes between the new and old Super-spines.
[0219] 3. Switch the traffic within the VRF to the new Super-spine: On the new Super-spine, configure AS substitution for the peers with AS numbers 64001 and 64002 (that is, the data subnet and the public subnet): peer xxxxsubstitute-as. On the new Super-spine, delete the inbound and outbound routing policies for the DB spine.
[0220] 4. After traffic migration, as expected, traffic within the same VRF passes through the new Super-spine switch; traffic for east-west access across VRFs passes through the old Super-spine switch and the old east-west firewall; traffic for north-south access passes through the old Super-spine switch and the north-south firewall.
[0221] For ease of understanding, Figure 4 In the figure, taking DATA-spine as an example, the traffic between DB-spine in the same VRF is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines; the east-west traffic between APP-spine across VRFs is transmitted through the old Super-spine in the first switch set and the old east-west firewall, and the traffic transmission process is specifically represented by bold dotted lines; the north-south access traffic is transmitted through the old Super-spine in the first switch set, and the traffic transmission process is specifically represented by bold dotted lines.
[0222] like Figure 5 As shown, Figure 5 It is a schematic diagram showing the principle of traffic migration between sub-networks according to an embodiment of the present disclosure.
[0223] To switch traffic across VRFs (subnets) to the new environment, that is, the new Super-spine switch, you can perform the following steps.
[0224] 1. Configuration deployment.
[0225] On the new Super-spine, deploy two Open Shortest Path First (OSPF) processes on each Super-spine: deploy OSPF process 11 to bind the public subnet, and deploy OSPF process 12 to bind the data subnet; declare the network segments of the corresponding interfaces in the two processes respectively.
[0226] An OSPF process is deployed on the east-west firewall. Two interfaces establish neighbor relationships with the OSPF process 11 of the two new super-spines. The other two interfaces establish neighbor relationships with the OSPF process 12 of the two new super-spines.
[0227] 2. Check and confirm.
[0228] Check the OSPF peer status on the new Super-spine; check the OSPF peer status on the new east-west wall; check the cross-VRF routing on the subnet Spine.
[0229] 3. Configuration and deployment.
[0230] On the new Super-spine, summarize the network segments of the public subnet in OSPF process 11; summarize the network segments of the data subnet in OSPF1 process 12.
[0231] Deploy anti-loop routing policies on the new Super-spine: When OSPF routes are redistributed to BGP, they are imported only according to the prefix list and marked with the community attribute. When BGP routes are redistributed to OSPF, they are filtered out according to the community attribute.
[0232] Deploy a summary static black hole route on the new super-spine with the next hop null 0 to prevent loops.
[0233] 4. Check and confirm.
[0234] Check the cross-VRF routes on the new Super-spine; check the routes on the new east-west wall; check the cross-VRF routes on the business spine.
[0235] 5. Switch traffic between VRFs to the new Super-spine.
[0236] 6. After traffic migration, as expected, traffic within the same VRF passes through the new Super-spine switch; traffic for east-west access across VRFs passes through the new Super-spine switch and the east-west firewall; traffic for north-south access passes through the old Super-spine switch and the north-south firewall.
[0237] For ease of understanding, Figure 5 In the figure, taking DATA-spine as an example, the traffic between the DB-spine in the same VRF is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines; the east-west traffic between the APP-spine across VRFs is transmitted through the new Super-spine in the second switch set and the new east-west firewall, and the traffic transmission process is specifically represented by bold lines; the north-south access traffic is transmitted through the old Super-spine in the first switch set, and the traffic transmission process is specifically represented by bold dotted lines.
[0238] In addition, you can also set up cross-VRF traffic bypass.
[0239] 1. Configuration deployment.
[0240] Connect an external loopback line to each new Super-spine, deploy static routes to the public subnet and data subnet, with the next hop being the external loopback port and the priority being 200.
[0241] Redistribute static routes in BGP so that their costs are greater than the summary routes advertised by the east-west firewall OSPF to BGP.
[0242] 2. Check and confirm.
[0243] Check the routes across VRFs on the new Super-spine, including routes in the inactive state.
[0244] like Figure 6 As shown, Figure 6 It is a schematic diagram showing the principle of traffic migration between a sub-network and external devices of a data center according to an embodiment of the present disclosure.
[0245] To switch the traffic between the VRF (subnet) and the external devices of the data center (hereinafter referred to as north-south traffic) to the new environment, that is, the new Super-spine switch, you can perform the following steps.
[0246] 1. Configuration deployment.
[0247] Switch the north-south traffic on the old Super-spine to the bypass line, and transform the old north-south firewall to support OSPF dynamic routing mode.
[0248] On the new Super-spine, deploy two OSPF processes on each Super-spine. Deploy OSPF process 11 and bind the public subnet. Deploy OSPF process 12 and bind the data subnet. Declare the network segments of the corresponding interfaces in the two processes.
[0249] Deploy two OSPF processes on the north-south firewalls. The two interfaces of OSPF1 establish neighbor relationships with the OSPF11 processes of the two new Super-spines. The two interfaces of OSPF2 establish neighbor relationships with the OSPF12 processes of the two new Super-spines.
[0250] Deploy a default route on the north-south firewall to the functional core. Deploy a static summary route on the functional core to the north-south wall, which has a lower priority than the current bypass route.
[0251] The two OSPF processes on the north-south firewalls advertise the default route.
[0252] Redistribute the north-south default routes under the BGP of the new Super-spine, add the community attribute and increase the cost so that the cost is greater than the default routes published by the old Super-spine.
[0253] Redistribute BGP routes in OSPF process 11 and OSPF process 12 of the new super-spine, filter the community attribute, and summarize.
[0254] 2. Check and confirm.
[0255] Check the OSPF peer status on the new Super-spine; check the default route on the new Super-spine; check the OSPF peer status on the new north-south wall; check the default route on the subnet Spine.
[0256] 3. Configuration and deployment.
[0257] The bypass link between the functional core and the old Super-spine is disconnected, the default route advertised by the old Super-spine on the subnetwork spine is revoked, and the north-south traffic is switched to the new Super-spine.
[0258] 4. Check and confirm.
[0259] Check the session status of the north-south firewall and the default route status on the subnet Spine.
[0260] For ease of understanding, Figure 6 In the figure, taking DATA-spine as an example, the traffic between DB-spine in the same VRF is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines; the east-west traffic between APP-spine across VRFs is transmitted through the new Super-spine in the second switch set and the new east-west firewall, and the traffic transmission process is specifically represented by bold lines; the north-south access traffic is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines.
[0261] In addition, you can also set up a north-south traffic bypass.
[0262] 1. Configuration deployment.
[0263] The two new Super-spines are connected to the functional core respectively; a Layer 2 aggregation group is configured, and two interface VLANs are configured, which are associated with the public subnet and the data subnet respectively; static default routes are deployed to point to the functional core respectively, and the priority is lower than the default route published by OSPF.
[0264] The functional core deploys static summary routing, the next hop bypass, and the priority is lower than the next hop, which is the priority of the north-south wall.
[0265] Redistribute the static default route under the BGP process of the new super-spine, and increase the cost value, which is greater than the cost when redistributing the OSPF default route.
[0266] 2. Check and confirm.
[0267] Disconnect the north-south wall; check the default route of the new Super-spine; check the default route on the sub-network Spine.
[0268] This embodiment can achieve at least the following effects.
[0269] 1. The routing convergence time can be effectively controlled by pre-configuration and step-by-step changes, so that the interruption time can be controlled at the millisecond level.
[0270] 2. Through the three steps of "migrating the traffic across the spine within the VRF to the new Super-spine", "migrating the cross-region (cross-VRF) traffic to the new Super-spine and the new east-west firewall", and "migrating the traffic between the data center and external devices to the new Super-spine and the north-south firewall", the amount of routing convergence can be effectively controlled, the scope of business damage can be clarified, and targeted positioning can be carried out. If a problem occurs, only a small part of the rollback is required.
[0271] For easier understanding, this embodiment also provides a more specific description.
[0272] like Figure 7 As shown, Figure 7 It is a structural diagram of another data center network according to an embodiment of the present disclosure.
[0273] Among them, the data center network contains spine switches of sub-networks, namely the big data core spine, database core spine, XSKY core spine, and application core spine.
[0274] Among them, the big data core spine, database core spine and XSKY core spine belong to the same subnetwork, namely the data subnetwork, namely VRF: data.
[0275] The application core spine belongs to another subnet, that is, the public subnet, namely VRF: public.
[0276] The data center network also includes a first set of switches.
[0277] The first switch set includes two stacked Super-spine switches, which are also called old Super-spine switches.
[0278] The data center network also includes old east-west firewalls hanging next to the stacked old Super-spine switches.
[0279] The data center network also includes a north-south firewall that is attached to the first switch set.
[0280] The north-south firewall can be connected to the functional core switch for communication with the outside of the data center network.
[0281] like Figure 8 As shown, Figure 8 This is a schematic diagram showing the principle of traffic migration within another sub-network according to an embodiment of the present disclosure.
[0282] The first step of traffic migration is to migrate the traffic across spines within the VRF to the new Super-spine.
[0283] 1. Clarify the concept of cross-Spine traffic within a subnetwork.
[0284] In the server area, there are multiple groups of spines in the same VRF. Since each group of spines is connected to different server cabinets, these machines under the spine can communicate with each other and realize data exchange through the spine.
[0285] However, cross-spine communication needs to go through the Super-spine. For example, the traffic between big data spine1-2 and big data spine3-4 in the same data subnet. Note that the traffic does not cross VRF.
[0286] 2. New Super-spine access and routing learning.
[0287] The new Super-spine is put into operation and connected to the network. BGP is configured and the AS number is the same as the old Super-spine: 64000.
[0288] Specifically, new equipment can be added to the data center network as a new Super-spine.
[0289] Then the new Super-spine establishes a BGP neighbor relationship with each spine of the data subnet and the public subnet. Since the AS numbers of all spines are the same except for the database core spine, routes will not be transmitted to each other, and traffic within the VRF and between spines will not go to the new Super-spine.
[0290] At this point, the new Super-spine can learn the routes of the entire data center network and compare the number of route entries and detailed content with those on the old Super-spine to ensure that the routing information is consistent.
[0291] 3. Database core BGP AS number problem.
[0292] Currently, BGP has been enabled on the database core, and a neighbor relationship has been established with the data center switch. The AS number is 64006, which is different from the AS number of the spine in other data areas. The database needs special treatment.
[0293] When the database is changed to dynamically connect to the old Super-spine, it only receives the default route of all 0s from the old Super-spine, and does not receive any other detailed routes. And it does not send any routes from the local database to the old Super-spine.
[0294] When the database dynamically connects to a new Super-spine, it sends a local summary route (local static Null0 summary) and receives any route sent from the new Super-spine.
[0295] On the new Super-spine, the large-segment summary route of the database sent from the database spine is marked with the not-export label and is not sent to any neighbor. No routes are sent to the database spine. In this way, after the new Super-spine is connected to the network, it will only learn the routes of the entire network and will not forward any traffic, which will not affect the business.
[0296] 4. Switch VRF internal cross-spine traffic to the new Super-spine.
[0297] On the new Super-spine, apply a policy to all spines. Clear the originating AS number from the as-path attribute list in the received routes. Then send the processed routes to all neighbors. Specifically: in the data subnet, clear 64001 from the as-path of the routes received from the big data spine, XSKY spine. Then send it to all neighbors. Apply the routing policy to the export direction of all neighbors.
[0298] Then reverse the neighbors of the database spine and cancel the original policy of adding the not-export label to the routes in the inbound direction and cancel the policy of filtering all routes in the outbound direction. This allows the routes received from the database spine to be sent to the spines of other data areas, and the routes of the spines of other data areas to be sent to the database spine.
[0299] The above two steps are performed at the same time. After the data zone internal cross-spine intercommunication is completed, the new Super-spine is used. It does not matter if a few routes are not switched synchronously during the switching time, and the old Super-spine can still be used.
[0300] The operation in the public subnet is similar. When sending the routes received from the application spine to other application spines, apply the policy in the outbound direction and remove the origin AS number: 64002 in the as-path attribute.
[0301] For ease of understanding, Figure 8 In the figure, taking the big data core spine as an example, the traffic between the big data core spine and the database core spine in the same VRF is transmitted through the new Super-spine in the second switch set. The bold lines represent the traffic transmission process.
[0302] like Fig. 9 As shown, Fig. 9 The diagram is another schematic diagram of the principle of traffic migration between sub-networks according to an embodiment of the present disclosure.
[0303] Among them, the second step of traffic migration is to migrate cross-region (cross-VRF) traffic to the new Super-spine and new east-west firewalls.
[0304] 1. Clarify the concept of cross-VRF traffic.
[0305] The traffic between the application zone and the data zone in the server zone is in one VRF, and the traffic between the application zone and the data zone is in one VRF. This kind of cross-zone traffic needs to cross VRFs and go to the east-west firewall.
[0306] 2. Prepare policies on the new east-west firewall and the old east-west firewall.
[0307] First, add a new east-west firewall in the data center network that is hung next to the new Super-spine.
[0308] For the new east-west firewall, you must first complete the configuration of the zone and policy, translate and configure the current east-west firewall policy, and add the configuration of any any permit in the bidirectional policy group. Put this any any configuration at the end of the detailed policy, so that traffic that does not match the policy can pass. For the old east-west firewall, also add this any any permit policy at the end of the detailed policy.
[0309] Both the new East-West firewall and the old East-West firewall have asymmetric forwarding enabled. Connection integrity is not checked. Non-first-packet traffic is allowed as long as there is a policy.
[0310] 3. Prepare routing on the new firewall.
[0311] The new east-west firewall completes the OSPF configuration and establishes an OSPF neighbor relationship with the new Super-spine.
[0312] 4. The two new supersine VRFs inject routes into the east and west firewalls.
[0313] The new Super-spine injects the routes in this area (that is, in this VRF) into OSPF and summarizes them during the injection process. In this way, the summarized routes of all areas can be seen on the east-west firewalls, and the summarized OSPF routes of this end can also be seen in the VRF of the opposite Super-spine. Note that this step introduces BGP operations into OSPF, which requires summarization and filtering of the community of BGP routes. Exclude the situation where the routes are injected into BGP from the OSPF domain.
[0314] After this step is completed, there will only be cross-VRF routing on the new Super-spine, but it will not be sent to the BGP domain below in the OSPF domain, so it will not affect the cross-zone mutual access traffic of the underlying servers.
[0315] 5. Switch cross-VRF inter-access traffic to the new Super-spine.
[0316] On the new Super-spine, inject the routes in the OSPF process into BGP. However, be careful to filter the content.
[0317] In the data subnet, OSPF routes are imported into the BGP process, and route filtering is performed to import only the summary routes of the application area.
[0318] In the public subnet, import OSPF routes into the BGP process, perform route filtering, and only import summary routes in the data area.
[0319] After this step is completed, all the spines below will have large cross-zone routes with higher priority than the original all-0 default routes. Cross-zone traffic will go through the new Super-spine. If the route changes are not synchronized, there is no problem, and the old Super-spine and the old firewall can also pass. This is because the any any permit policy is enabled and status monitoring is disabled. After the traffic switch is completed and runs stably for 30 minutes, turn off the any any permit policy. Enable status monitoring.
[0320] For ease of understanding, Fig. 9 In the figure, taking the big data core spine as an example, the traffic between the database core spine in the same VRF is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines; the east-west traffic between the application core spines across VRFs is transmitted through the new Super-spine in the second switch set and the new east-west firewall, and the traffic transmission process is specifically represented by bold lines.
[0321] like Fig.10 As shown, Fig.10 It is a schematic diagram showing the principle of traffic migration between another sub-network and external devices of a data center according to an embodiment of the present disclosure.
[0322] Among them, the third step of traffic migration is to migrate the traffic in and out of the server area to the new Super-spine and north-south firewalls.
[0323] 1. Clarify the concept of traffic entering and leaving the server area.
[0324] The server area is divided into the data area and the application area, which are divided into two VRFs. There are two default routes pointing to the north and south firewalls, and external mutual access is enabled.
[0325] 2. Work on the north-south firewall.
[0326] The north-south firewall should be bypassed first. The old Super-spine is directly connected to the functional core through the bypass line. Then the north-south firewall is set to dynamic operation mode.
[0327] 3. Preparatory work on the core functions.
[0328] First, the functional core points the large routes to the data zone servers and application zone servers to the bypass lines in the data zone and the bypass lines in the application zone, respectively. Configure track to monitor the connectivity of the bypass lines. Associate the above two static routes. Then, the large routes to the data zone and application zone in the functional core are directed to the north-south firewall. This is a floating route with a cost added. When the bypass line is blocked, switch the route to the north-south firewall.
[0329] 4. Preparation for routing on the north and south firewalls.
[0330] On the north and south firewalls, point the all-0 static default route to the functional core and advertise this route to OSPF so that the new Super-spine receives this default route.
[0331] 5. Preparation work on the new Super-spine.
[0332] The new Super-spine will redistribute the all-0 default route learned through OSPF to BGP, and lower the localprefer to make it less preferred. It cannot compete with the all-0 default route sent by the old Super-spine.
[0333] 6. Preparation work on the old Super-spine.
[0334] On the old Super-spine, in both VRFs, point the default route to the Bypass line. Configure track to monitor the connectivity of the Bypass line and associate it with the default route.
[0335] 7. Switch traffic across server zones.
[0336] On the functional core, close the bypass lines in the data area and application area. Make the track detection in both directions fail. The downstream traffic of the functional core is switched to the north-south firewall. The all-0 default route of the old Super-spine is invalid and cannot be sent down to the BGP domain below. The all-0 default route sent by the new Super-spine takes effect. The outgoing traffic is switched to the new Super-spine.
[0337] For ease of understanding, Fig.10In the figure, taking the big data core spine as an example, the traffic between the database core spine in the same VRF is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines; the east-west traffic between the application core spines across VRFs is transmitted through the new Super-spine in the second switch set and the new east-west firewall, and the traffic transmission process is specifically represented by bold lines; the north-south access traffic is transmitted through the new Super-spine in the second switch set, and the traffic transmission process is specifically represented by bold lines.
[0338] This embodiment can achieve at least the following effects.
[0339] 1. The routing convergence time can be effectively controlled by pre-configuration and step-by-step changes, so that the interruption time can be controlled at the millisecond level.
[0340] 2. Through the three steps of "migrating the traffic across the spine within the VRF to the new Super-spine", "migrating the cross-region (cross-VRF) traffic to the new Super-spine and the new east-west firewall", and "migrating the traffic in and out of the server area to the new Super-spine and the north-south firewall", the amount of routing convergence can be effectively controlled, the scope of business damage can be clarified, and targeted positioning can be carried out. If problems occur, large-scale rollbacks can be avoided.
[0341] This embodiment aims to protect the core switches in the physical network from being stacked with east-west and north-south hardware firewalls. The core switches are logically stacked and their services are split. The overall change is smooth and stable, minimizing the impact on the services.
[0342] Corresponding to the above method embodiment, the present disclosure also provides a device embodiment.
[0343] like Fig.11 As shown, Fig.11 It is a structural schematic diagram of a flow migration device according to an embodiment of the present disclosure.
[0344] The device can be applied to a data center network, which may include: a first switch set and multiple sub-networks.
[0345] The apparatus may include the following units.
[0346] A first traffic migration unit 201 is used to migrate the first traffic in any sub-network transmitted by the first switch set to the second switch set; the second switch set is pre-set in the data center network;
[0347] A second traffic migration unit 202, configured to migrate second traffic between different sub-networks transmitted by the first switch set to the second switch set;
[0348] The third traffic migration unit 203 is used to migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.
[0349] Optionally, the first switch set includes at least two stacked first switches; and the second switch set includes at least one independent second switch.
[0350] Optionally, the data center network further includes a first route and a second route, the first route is used to transmit the first target traffic through the first switch set, the second route is used to transmit the first target traffic through the second switch set, and the first target traffic is any one of the first traffic, the second traffic and the third traffic;
[0351] The device may also include:
[0352] The control unit 204 is used to control the priority of the first route to be lower than the priority of the second route during the migration of the first target traffic.
[0353] Optionally, the data center network further includes a first east-west firewall and a second east-west firewall; the method further includes: in the process of transmitting the second traffic through the first switch set, transmitting the second traffic through the first east-west firewall;
[0354] The second traffic migration unit 202 is configured to:
[0355] Migrate second traffic between different sub-networks transmitted by the first switch set and the first east-west firewall to the second switch set and the second east-west firewall.
[0356] Optionally, the second traffic migration unit 202 is configured to:
[0357] When the first traffic migration is completed and the duration of the first traffic failure-free transmission based on the second switch set is greater than the first preset duration, the second traffic between different sub-networks transmitted by the first switch set is migrated to the second switch set.
[0358] Optionally, the third traffic migration unit 203 is configured to:
[0359] When the second traffic migration is completed and the duration of the fault-free transmission of the second traffic based on the second switch set is greater than the second preset duration, the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set is migrated to the second switch set.
[0360] Optionally, the device may further include:
[0361] The supplementing unit 205 is used to transmit the traffic in the second target traffic that has not been migrated to the second switch set through the first switch set during the migration of the second target traffic; the second target traffic is any one of the first traffic, the second traffic and the third traffic.
[0362] Optionally, the device may further include:
[0363] The rollback unit 206 is used to migrate the third target flow that has been migrated to the second switch set from the second switch set to the first switch set when rolling back the third target flow that has been migrated to the second switch set; the third target flow is any one of the first flow, the second flow and the third flow.
[0364] Optionally, the device may further include:
[0365] The inspection unit 207 is used to inspect the equipment and / or route related to the fourth target flow when the transmission of the fourth target flow fails; the fourth target flow is any one of the first flow, the second flow and the third flow.
[0366] For specific explanations, please refer to the above method embodiments.
[0367] Corresponding to the above method embodiment, the embodiment of the present disclosure also provides a system embodiment.
[0368] A data center network may include: a first switch set and a plurality of sub-networks;
[0369] The data center network can be used to: migrate first traffic within any sub-network transmitted by the first switch set to a second switch set; the second switch set is pre-set in the data center network;
[0370] Migrating second traffic between different sub-networks transmitted by the first switch set to the second switch set;
[0371] The third traffic between any sub-network and a device outside the data center network transmitted by the first switch set is migrated to the second switch set.
[0372] Optionally, the first switch set includes at least two stacked first switches; and the second switch set includes at least one independent second switch.
[0373] Optionally, the data center network further includes a first route and a second route, the first route is used to transmit the first target traffic through the first switch set, the second route is used to transmit the first target traffic through the second switch set, and the first target traffic is any one of the first traffic, the second traffic and the third traffic;
[0374] Data center networks are also used for:
[0375] During the migration of the first target traffic, the priority of the first route is controlled to be lower than the priority of the second route.
[0376] Optionally, the data center network further includes a first east-west firewall and a second east-west firewall; the method further includes: in the process of transmitting the second traffic through the first switch set, transmitting the second traffic through the first east-west firewall;
[0377] Data center networks are used for:
[0378] Migrate second traffic between different sub-networks transmitted by the first switch set and the first east-west firewall to the second switch set and the second east-west firewall.
[0379] Optionally, the data center network is used to:
[0380] When the first traffic migration is completed and the duration of the first traffic failure-free transmission based on the second switch set is greater than the first preset duration, the second traffic between different sub-networks transmitted by the first switch set is migrated to the second switch set.
[0381] Optionally, the data center network is used to:
[0382] When the second traffic migration is completed and the duration of the fault-free transmission of the second traffic based on the second switch set is greater than the second preset duration, the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set is migrated to the second switch set.
[0383] Optionally, the data center network is also used to: during the migration of the second target traffic, transmit the traffic in the second target traffic that has not been migrated to the second switch set through the first switch set; the second target traffic is any one of the first traffic, the second traffic and the third traffic.
[0384] Optionally, the data center network is also used to:
[0385] When rolling back the third target flow that has been migrated to the second switch set, the third target flow is migrated from the second switch set to the first switch set; the third target flow is any one of the first flow, the second flow and the third flow.
[0386] Optionally, the data center network is also used to:
[0387] In the event of a transmission failure of the fourth target flow, equipment and / or routing related to the fourth target flow are checked; the fourth target flow is any one of the first flow, the second flow and the third flow.
[0388] For specific explanations, please refer to the above method embodiments.
[0389] The embodiment of the present disclosure further provides a computer device, which at least includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein any of the above method embodiments is implemented when the processor executes the program.
[0390] An embodiment of the present disclosure also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the above-mentioned method embodiments.
[0391] Fig.12 1 is a schematic diagram of the hardware structure of a computer device configured with the method of the embodiment of the present disclosure according to an embodiment of the present disclosure, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040 and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030 and the communication interface 1040 are connected to each other in communication within the device through the bus 1050.
[0392] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present disclosure.
[0393] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solution provided by the embodiment of the present disclosure is implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.
[0394] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.
[0395] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).
[0396] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).
[0397] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present disclosure, and does not necessarily include all the components shown in the figure.
[0398] The embodiments of the present disclosure further provide a computer-readable storage medium having a computer program stored thereon, and when the program is executed by a processor, any of the above method embodiments is implemented.
[0399] The embodiments of the present disclosure further provide a computer-readable storage medium storing a computer program, wherein the computer program implements any of the above method embodiments when executed by a processor.
[0400] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0401] The embodiment of the present disclosure further provides a computer software, including a computer program / instruction, wherein when the computer program / instruction is executed by a processor, any of the above method embodiments is implemented.
[0402] It can be known from the description of the above implementation methods that those skilled in the art can clearly understand that the embodiments of the present disclosure can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the embodiments of the present disclosure is essentially or the part that contributes can be embodied in the form of a software product, which can be stored in a storage medium such as ROM / RAM, a disk, an optical disk, etc., including several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present disclosure or some parts of the embodiments.
[0403] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.
[0404] Each embodiment in this specification is described in a progressive manner, and the same and similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. The device embodiment described above is merely illustrative, wherein the modules described as separate components may or may not be physically separated, and the functions of each module can be implemented in the same one or more software and / or hardware when implementing the embodiment of the present disclosure. It is also possible to select some or all of the modules according to actual needs to achieve the purpose of the embodiment. A person of ordinary skill in the art can understand and implement it without paying creative labor.
[0405] The above is only a specific implementation of the embodiment of the present disclosure. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the embodiment of the present disclosure. These improvements and modifications should also be regarded as protection for the embodiment of the present disclosure.
[0406] In the present disclosure, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance. The term "plurality" refers to two or more, unless otherwise clearly defined.
[0407] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the disclosure disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are to be considered exemplary only, and the true scope and spirit of the present disclosure are indicated by the following claims.
[0408] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A traffic migration method, characterized in that: Applied to a data center network, the data center network comprising a first switch set and a plurality of sub-networks; The method comprises: Migrating the first traffic within any sub-network transmitted by the first switch set to a second switch set; the second switch set is pre-set in the data center network; Migrating second traffic between different sub-networks transmitted by the first switch set to the second switch set; Migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.
2. The method according to claim 1, characterized in that The first switch set includes at least two stacked first switches; the second switch set includes at least one independent second switch.
3. The method according to claim 1, characterized in that The data center network further includes a first route and a second route, the first route is used to transmit a first target flow through the first switch set, the second route is used to transmit the first target flow through the second switch set, and the first target flow is any one of the first flow, the second flow and the third flow; The method further comprises: During the migration of the first target traffic, the priority of the first route is controlled to be lower than the priority of the second route.
4. The method according to claim 1, characterized in that: The data center network further includes a first east-west firewall and a second east-west firewall; the method further includes: in the process of transmitting the second traffic by the first switch set, transmitting the second traffic through the first east-west firewall; The step of migrating the second traffic between different sub-networks transmitted by the first switch set to the second switch set includes: Migrate second traffic between different subnetworks transmitted by the first switch set and the first east-west firewall to the second switch set and the second east-west firewall.
5. The method according to claim 1, characterized in that The step of migrating the second traffic between different sub-networks transmitted by the first switch set to the second switch set includes: When the first traffic migration is completed and the duration of the first traffic failure-free transmission based on the second switch set is greater than a first preset duration, the second traffic between different sub-networks transmitted by the first switch set is migrated to the second switch set.
6. The method according to claim 1, characterized in that The step of migrating the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set includes: When the migration of the second traffic is completed and the duration of the fault-free transmission of the second traffic based on the second switch set is greater than the second preset duration, the third traffic between any subnet and the device outside the data center network transmitted by the first switch set is migrated to the second switch set.
7. The method according to any one of claims 1 to 6, characterized in that The method further includes: in the process of migrating the second target traffic, transmitting, through the first switch set, traffic in the second target traffic that has not been migrated to the second switch set; The second target flow rate is any one of the first flow rate, the second flow rate and the third flow rate.
8. The method according to any one of claims 1 to 6, characterized in that The method further comprises: In the case of rolling back the third target traffic that has been migrated to the second switch set, migrating the third target traffic from the second switch set to the first switch set; The third target flow rate is any one of the first flow rate, the second flow rate and the third flow rate.
9. The method according to any one of claims 1 to 6, characterized in that The method further comprises: In the event that a transmission failure occurs in the fourth target traffic, inspecting devices and / or routes related to the fourth target traffic; The fourth target flow rate is any one of the first flow rate, the second flow rate and the third flow rate.
10. A flow migration device, characterized in that: Applied to a data center network, the data center network comprising: a first switch set and a plurality of sub-networks; The device comprises: A first traffic migration unit, configured to migrate first traffic within any sub-network transmitted by the first switch set to a second switch set; the second switch set is pre-set in the data center network; A second traffic migration unit, configured to migrate second traffic between different sub-networks transmitted by the first switch set to the second switch set; The third traffic migration unit is used to migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.
11. A data center network, characterized in that: The data center network includes: a first switch set and multiple sub-networks; the data center network is used to: Migrating the first traffic within any sub-network transmitted by the first switch set to a second switch set; the second switch set is pre-set in the data center network; Migrating second traffic between different sub-networks transmitted by the first switch set to the second switch set; Migrate the third traffic between any sub-network and the device outside the data center network transmitted by the first switch set to the second switch set.