Traffic forwarding method and device, equipment, storage medium and computer program product
By using different routing strategies in the traffic speed limit gateway cluster to forward traffic in the cloud and outbound directions, the waste of storage space and business capacity expansion caused by redundant policy rules in the existing technology is solved, and efficient traffic management and business capacity optimization are achieved.
Patent Information
- Application Number
- CN202510167769.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-16
AI Technical Summary
The existing traffic speed limit gateway cluster has redundant traffic speed limit policy rules, resulting in wasted storage space, unable to achieve business capacity expansion, and high availability needs to be optimized.
Different routing strategies are used to forward traffic in the direction of incoming and outgoing clouds. By determining the priority of the gateway cluster and the priority of the gateway nodes, traffic is forwarded to the target gateway nodes, avoiding issuing traffic speed limit rules for all gateway nodes.
The redundant traffic speed limit policy rules are optimized to avoid business redundancy, improve the service capacity carrying capacity of the gateway cluster, and realize the reuse of the traffic speed limit policy.
Smart Images

Figure CN120017593A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of wireless traffic forwarding technology, and in particular to a traffic forwarding method, apparatus, device, storage medium and computer program product. Background Art
[0002] At present, with the rapid development of the Internet, the demand for enterprise network communication is increasing, and traffic management has become increasingly important. In order to ensure the stability and security of the network and the rational use of resources, a traffic speed limiting gateway cluster is introduced to control and manage traffic. However, the existence of redundant traffic speed limiting policy rules has caused a waste of storage space and failed to achieve the effect of business capacity expansion. Therefore, the high availability of the traffic speed limiting gateway cluster needs to be optimized. Summary of the invention
[0003] In view of this, embodiments of the present application hope to provide a traffic forwarding method, apparatus, device, storage medium and computer program product.
[0004] The technical solution of the embodiment of the present application is implemented as follows:
[0005] The present application provides a traffic forwarding method, which is applied to any gateway node in a gateway cluster. The method includes:
[0006] For the inbound traffic, the first routing strategy is adopted for forwarding; the first routing strategy is to forward the inbound traffic from the outside to the first target gateway node in the first target gateway cluster according to the first priority of the gateway cluster and the second priority of the gateway node in the gateway cluster, and then forward it to the cloud by the first target gateway node;
[0007] For outbound traffic, a second routing strategy is used for forwarding; the second routing strategy is to direct the outbound traffic to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud.
[0008] In addition, according to at least one embodiment of the present application, the method further includes:
[0009] Determine a first attribute value and a second attribute value of a Border Gateway Protocol (BGP) route corresponding to each gateway node in each gateway cluster; the first attribute value represents an autonomous system (AS) path length; the second attribute value represents a Multiple Exit Discriminator (MED) attribute value;
[0010] Determine, according to the first attribute value, a first priority of each gateway cluster; determine, according to the first priority, the first target gateway cluster from among the gateway clusters;
[0011] According to the second attribute value, the second priority of each gateway node in each gateway cluster is determined; according to the second priority of each gateway node in the first target gateway cluster, the first target gateway node in the first target gateway cluster is determined.
[0012] In addition, according to at least one embodiment of the present application, determining the first priority of each gateway cluster according to the first attribute value; and determining the first target gateway cluster from the various gateway clusters according to the first priority includes:
[0013] Determine the number of gateway nodes in each gateway cluster whose AS path length is less than or equal to a preset threshold;
[0014] Sorting the gateway clusters according to the number of gateway nodes to obtain a first sorting result; and using the first sorting result as a first priority of each gateway cluster;
[0015] The gateway cluster corresponding to the highest priority among the first priorities is used as the first target gateway cluster.
[0016] In addition, according to at least one embodiment of the present application, determining the second priority of each gateway node in each gateway cluster according to the second attribute value includes:
[0017] For each gateway cluster, perform the following operations:
[0018] Sorting the gateway nodes in the gateway cluster according to the second attribute value of each gateway node in the gateway cluster to obtain a second sorting result;
[0019] Using the second sorting result as the second priority of each gateway node in the gateway cluster;
[0020] Correspondingly, determining the first target gateway node in the first target gateway cluster according to the second priority of each gateway node in the first target gateway cluster includes:
[0021] The gateway node corresponding to the highest priority among the second priorities of each gateway node in the first target gateway cluster is used as the first target gateway node in the first target gateway cluster.
[0022] In addition, according to at least one embodiment of the present application, the method further includes:
[0023] In the event of a traffic forwarding failure, the first priority of each gateway cluster and the second priority of each gateway node in each gateway cluster are sent to the control node so that the control node can determine the failed gateway node.
[0024] In addition, according to at least one embodiment of the present application, the method further includes:
[0025] When forwarding using the second routing strategy, query whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route;
[0026] When it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster that matches the source route, the outbound traffic is directed to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud at a limited speed.
[0027] In addition, according to at least one embodiment of the present application, querying whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route includes:
[0028] Determine the virtual extensible local area network tunnel endpoint (VTEP, VXLAN Tunnel Endpoint) address of the gateway cluster corresponding to the next hop according to the public network address and route list carried by the outbound traffic.
[0029] Determine the gateway cluster corresponding to the next hop based on the VTEP address and gateway cluster list of the gateway cluster corresponding to the next hop;
[0030] Compare the gateway cluster corresponding to the next hop with the first target gateway cluster matched by the source route to obtain a comparison result;
[0031] When the comparison result indicates that the gateway cluster corresponding to the next hop is different from the first target gateway cluster matching the source route, it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster matching the source route.
[0032] In addition, according to at least one embodiment of the present application, the method further includes:
[0033] Monitor the working status of each gateway node in each gateway cluster except itself;
[0034] In the case where a first signal sent by a first gateway cluster in the other gateway clusters is not received, a second signal is sent to a second gateway cluster in the other gateway clusters except the first gateway cluster, wherein the second signal is used for the second gateway cluster to cancel one or more source routing data table entries in a database pointing to a gateway node in the first gateway cluster.
[0035] The present application provides a traffic forwarding device, including:
[0036] A first processing module is used to forward the inbound cloud traffic using a first routing strategy; the first routing strategy is to forward the inbound cloud traffic from the outside to a first target gateway node in a first target gateway cluster based on a first priority of the gateway cluster and a second priority of the gateway node in the gateway cluster, and then forward the traffic to the cloud by the first target gateway node;
[0037] The second processing module is used to forward the outbound traffic using a second routing strategy; the second routing strategy is to direct the outbound traffic to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud.
[0038] At least one embodiment of the present application provides a network device, including a processor and a memory for storing a computer program that can be run on the processor.
[0039] Wherein, when the processor is used to run the computer program, it executes the steps of any one of the above methods.
[0040] At least one embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of any of the above methods when executed by a processor.
[0041] At least one embodiment of the present application provides a computer program product, including a computer program, characterized in that when the computer program is executed by a processor, any of the above-mentioned methods is implemented.
[0042] The data processing method, apparatus, device, storage medium and computer program product provided by the embodiments of the present application include: for inbound cloud traffic, a first routing strategy is adopted for forwarding; the first routing strategy is to forward the inbound cloud traffic from the outside to the first target gateway node in the first target gateway cluster according to the first priority of the gateway cluster and the second priority of the gateway node in the gateway cluster, and then the first target gateway node forwards it to the cloud; for outbound cloud traffic, a second routing strategy is adopted for forwarding; the second routing strategy is to direct the outbound cloud traffic to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards it to the outside of the cloud.
[0043] By adopting the technical solution provided in the embodiment of the present application, for the traffic in the cloud direction, it is forwarded to the cloud through the first target gateway node in the first target gateway cluster; for the traffic in the cloud direction, it is also forwarded to the outside of the cloud through the first target gateway node in the first target gateway cluster. Since the traffic in the cloud direction and the traffic in the cloud direction pass through the same gateway node in the same gateway cluster, there is no need to issue traffic speed limit rules to each gateway node in all gateway clusters, thereby optimizing redundant traffic speed limit policy rules, thereby avoiding the occurrence of business redundancy and helping to improve the business capacity carried by the gateway cluster. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a schematic diagram of the implementation process of the traffic forwarding method of the embodiment of the present application;
[0045] Figure 2 is a schematic diagram of a gateway cluster and a gateway node according to an embodiment of the present application;
[0046] Figure 3 This is a schematic diagram of forwarding traffic in the cloud direction according to an embodiment of the present application. Figure 1 ;
[0047] Figure 4 This is a schematic diagram of forwarding traffic in the cloud direction according to an embodiment of the present application. Figure 2 ;
[0048] Figure 5 It is a schematic diagram of traffic forwarding in an embodiment of the present application;
[0049] Figure 6 It is a schematic diagram of the composition structure of the traffic forwarding device according to an embodiment of the present application;
[0050] Figure 7 It is a schematic diagram of the composition structure of the network device of the embodiment of the present application. DETAILED DESCRIPTION
[0051] Before introducing the technical solutions of the embodiments of the present application, the related technologies are first introduced.
[0052] In related technologies, with the rapid development of the Internet, the demand for enterprise network communication continues to increase, and traffic management becomes increasingly important. In order to ensure the stability and security of the network and the rational use of resources, many enterprises choose to introduce traffic speed limiting gateway clusters to control and manage traffic.
[0053] The patent application document entitled "Network Traffic Speed Limiting Method, Apparatus, Central Control Device and Gateway" discloses: This patent provides a network traffic speed limiting method, apparatus, central control device and gateway, wherein the central control device receives a traffic alarm sent by the first gateway in the speed-limiting gateway cluster, and then obtains the real-time bandwidth of the target service at each gateway in the speed-limiting gateway cluster; then updates the quota bandwidth of the target service at each gateway in the speed-limiting gateway cluster based on the current quota bandwidth of the target service at the first gateway, the real-time bandwidth at each gateway, and the pre-stored total quota bandwidth of the target service. In this method, when the real-time bandwidth of the target service of any gateway in the speed-limiting gateway cluster exceeds the specified bandwidth, a traffic alarm is promptly sent to the central control device, and the central control device reallocates the quota bandwidth of each gateway based on the real-time bandwidth of each gateway to the target service and the total quota bandwidth of the target service, so that the quota bandwidth of each gateway matches the real-time bandwidth of the target service at each gateway, thereby making the traffic speed limit of the target service more accurate.
[0054] The patent application document entitled "A traffic speed limiting method, device, gateway and computer-readable storage medium" discloses: This patent is a traffic speed limiting method, which is applied to the gateway, including: if there is a burst of traffic in the nth time period per unit time, obtain the traffic parameter of the burst of traffic; wherein n is a positive number; obtain the size relationship between the traffic parameter and the traffic threshold of the nth time period; obtain the speed limiting mechanism of the nth time period corresponding to the size relationship; based on the speed limiting mechanism of the nth time period, limit the burst of traffic. The application also discloses a traffic speed limiting device, a gateway and a computer-readable storage medium. The traffic speed limiting method provided by the application realizes that different size relationships correspond to different speed limiting mechanisms, and different speed limiting mechanisms include at least different speed limiting thresholds. When there is a burst of traffic, the gateway can select a suitable speed limiting threshold according to different traffic parameters, thereby realizing the dynamic traffic speed limiting and optimizing the speed limiting performance of the gateway.
[0055] The patent application document entitled Multi-active allocation method and device for cloud scene network address translation (NAT, Network Address Translation) gateway cluster based on multicast discloses: This application relates to a multi-active allocation method and device for cloud scene NAT gateway cluster based on multicast, the method includes: detecting whether a new elastic public network IP (EIP, Elastic IP) is added in the network, obtaining all NAT gateways in the network, judging whether the NAT gateway is faulty, if the NAT gateway fails, migrating the EIP of the NAT gateway to the queue of pending messages, calculating the configured bandwidth utilization of the NAT gateway, judging whether the NAT gateway can carry the newly added EIP according to the configured bandwidth utilization of the NAT gateway, if the NAT gateway can carry the newly added EIP, then allocating the newly added EIP to the NAT gateway, otherwise, migrating the newly added EIP to the queue of pending messages, periodically querying the NAT gateway that can allocate the newly added EIP, and allocating the EIP at the head of the queue in the queue of pending messages to the NAT gateway. In this way, the cluster bandwidth is improved, the loss of equipment services due to the limited carrying capacity of the NAT gateway in extreme cases is prevented, and the system's ability to cope with sudden services is improved.
[0056] In summary, the first two application documents focus on improving the internal flow rate limiting gateway, and fail to fully consider the design of the flow rate limiting gateway cluster. There are redundant flow rate limiting policy rules, which wastes storage space and fails to achieve the effect of business capacity expansion. The third application document does not provide an emergency plan for the failure of the entire cluster, and cannot quickly track down the problem nodes in the flow rate limiting gateway cluster.
[0057] Based on this, in an embodiment of the present application, for traffic in the direction of entering the cloud, a first routing strategy is adopted for forwarding; the first routing strategy is to forward the traffic in the direction of entering the cloud from the outside to the first target gateway node in the first target gateway cluster based on the first priority of the gateway cluster and the second priority of the gateway nodes in the gateway cluster, and then the first target gateway node forwards it to the cloud; for traffic out of the cloud, a second routing strategy is adopted for forwarding; the second routing strategy is to direct the traffic out of the cloud to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards it to outside the cloud.
[0058] See also Figure 1 , Figure 1 1 is a schematic diagram of the implementation flow of the traffic forwarding method of the embodiment of the present application, which is applied to any gateway node in the gateway cluster. The method includes steps 101 to 102:
[0059] Step 101: For the traffic in the cloud direction, the first routing strategy is adopted for forwarding; the first routing strategy is to forward the traffic in the cloud direction from the outside to the first target gateway node in the first target gateway cluster based on the first priority of the gateway cluster and the second priority of the gateway node in the gateway cluster, and then the first target gateway node forwards the traffic to the cloud.
[0060] It can be understood that the first routing strategy is to forward the inbound cloud traffic from the outside to the first target gateway node in the first target gateway cluster based on the first priority of each gateway cluster and the second priority of each gateway node in each gateway cluster, and then the first target gateway node will forward it to the cloud at a limited speed.
[0061] It is understandable that the inbound cloud traffic may refer to the network traffic entering the cloud device.
[0062] It can be understood that one gateway cluster may be composed of multiple gateway nodes.
[0063] It is understandable that the gateway node may refer to a gateway node with a flow rate limiting function, such as flow is not allowed to exceed a preset threshold, that is, a gateway node used to manage and control data flow on the network. Therefore, the gateway node may also be described as a flow rate limiting gateway, and a gateway cluster composed of flow rate limiting gateways may also be described as a flow rate limiting gateway cluster. The flow rate limiting gateway is used to manage and control data flow on the network. By setting a flow rate limiting strategy, it can ensure fair allocation of network resources, maintain network performance, improve security, and reduce the risk of network abuse, thus playing an important role in various organizations and network environments.
[0064] It can be understood that the first priority of each gateway cluster is used to determine the first target gateway cluster from the various gateway clusters; the second priority of each gateway node in each gateway cluster is used to determine the target gateway node from the various gateway clusters, wherein the target gateway node determined from the first gateway cluster is called the first target gateway node.
[0065] Step 102: For outbound traffic, a second routing strategy is used for forwarding; the second routing strategy is to direct the outbound traffic to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud.
[0066] It can be understood that the second routing strategy is to direct the outbound traffic to the first target gateway node in the first target gateway cluster according to the first target gateway cluster matching the source route, and then the first target gateway node forwards it to the outside of the cloud at a limited speed.
[0067] It can be understood that the traffic in the direction out of the cloud may refer to the network traffic flowing out of the cloud device.
[0068] It can be understood that the first target gateway cluster matching the source route may refer to the target gateway cluster through which the traffic enters the cloud.
[0069] It can be understood that the first target gateway node is determined according to the second priority of each gateway node in the first gateway cluster.
[0070] See Figure 2 , Figure 2 is a schematic diagram of the gateway cluster and gateway nodes in the embodiment of the present application. As Figure 2 shown, when multiple gateway nodes (which can also be described as traffic rate-limiting gateways) are adopted, every c traffic rate-limiting gateways form a gateway cluster, and there are a total of n gateway clusters. Among them, both c and n are integers greater than 1. Assume that the first traffic rate-limiting gateway in the i-th gateway cluster (0 < i <= n) is denoted as the (c * i - c + 1)-th, and the last traffic rate-limiting gateway is denoted as the (c * i)-th; each traffic rate-limiting gateway is divided into two planes, denoted as the in plane and the out plane respectively. Among them, the in plane is used to introduce traffic, and the out plane is used to lead out traffic. Each gateway cluster uses the same virtual extensible local area network tunnel endpoint (VTEP, VXLAN Tunnel Endpoint) address, and uses the Ethernet virtual private network (EVPN, Ethernet Virtual Private Network) to implement dynamic VXLAN tunnel establishment, and VXLAN tunnels are established pairwise between clusters.
[0071] The following describes the first routing policy adopted for the traffic in the direction into the cloud.
[0072] In practical applications, all gateway nodes (which can also be described as traffic rate-limiting gateways) publish Border Gateway Protocol (BGP) routes to the computing nodes, and set the BGP routes to different priorities by setting BGP attributes. Specifically, it is mainly divided into two types: intra-cluster priority and inter-cluster priority.
[0073] Based on this, in some embodiments, the method further includes:
[0074] Determine the first attribute value and the second attribute value of the BGP route corresponding to each gateway node in each gateway cluster; the first attribute value represents the AS path length; the second attribute value represents the MED attribute value;
[0075] Determine, according to the first attribute value, a first priority of each gateway cluster; determine, according to the first priority, the first target gateway cluster from among the gateway clusters;
[0076] According to the second attribute value, the second priority of each gateway node in each gateway cluster is determined; according to the second priority of each gateway node in the first target gateway cluster, the first target gateway node in the first target gateway cluster is determined.
[0077] In some embodiments, determining the first priority of each gateway cluster according to the first attribute value; and determining the first target gateway cluster from the various gateway clusters according to the first priority includes:
[0078] Determine the number of gateway nodes in each gateway cluster whose AS path length is less than or equal to a preset threshold;
[0079] Sorting the gateway clusters according to the number of gateway nodes to obtain a first sorting result;
[0080] Using the first sorting result as the first priority of each gateway cluster;
[0081] The gateway cluster corresponding to the highest priority among the first priorities is used as the first target gateway cluster.
[0082] It can be understood that the first attribute value may refer to the mandatory attribute of BGP routing, namely AS_PATH.
[0083] That is, the first priority of the gateway cluster can be distinguished by the length of the mandatory attribute AS_PATH of BGP.
[0084] It is understandable that the gateway clusters may be sorted from high to low according to the number of gateway nodes to obtain a first sorting result.
[0085] For example, assuming that there are n=3 gateway clusters, represented by gateway cluster 1, gateway cluster 2, and gateway cluster 3 respectively, the number of gateway nodes in the first gateway cluster (gateway cluster 1) whose AS path length is less than or equal to the preset threshold (for example, 10) is 20, the number of gateway nodes in the second gateway cluster (gateway cluster 2) whose AS path length is less than or equal to the preset threshold (for example, 10) is 10, and the number of gateway nodes in the third gateway cluster (gateway cluster 3) whose AS path length is less than or equal to the preset threshold (for example, 10) is 15. In this way, according to the number of gateway nodes, the gateway clusters are sorted from high to low to obtain the first sorting result, namely gateway cluster 1, gateway cluster 3, and gateway cluster 2. In this way, the gateway cluster corresponding to the highest priority, namely gateway cluster 1, is used as the first target gateway cluster.
[0086] It is understandable that the shorter the AS path length of the gateway nodes included in the gateway cluster, the higher the priority of the gateway cluster. Taking two gateway clusters as an example, assuming that the AS_PATH length of each gateway node in the i-th gateway cluster (which can also be described as a traffic speed-limiting gateway) is shorter than the AS_PATH length of each gateway node in the i+1-th gateway cluster (which can also be described as a traffic speed-limiting gateway), then the first priority of the i-th gateway cluster is higher than the first priority of the i+1-th gateway cluster.
[0087] In some embodiments, determining the second priority of each gateway node in each gateway cluster according to the second attribute value includes:
[0088] For each gateway cluster, perform the following operations:
[0089] Sorting the gateway nodes in the gateway cluster according to the second attribute value of each gateway node in the gateway cluster to obtain a second sorting result;
[0090] Using the second sorting result as the second priority of each gateway node in the gateway cluster;
[0091] Correspondingly, determining the first target gateway node in the first target gateway cluster according to the second priority of each gateway node in the first target gateway cluster includes:
[0092] The gateway node corresponding to the highest priority among the second priorities of each gateway node in the first target gateway cluster is used as the first target gateway node in the first target gateway cluster.
[0093] It can be understood that the second attribute value may refer to the MED attribute value of the BGP route.
[0094] It can be understood that the second priority of the gateway nodes within the gateway cluster (which can also be described as the traffic rate-limiting gateway) can be calculated using the optional attribute MED of BGP.
[0095] Here, according to the following formula (1), calculate the second attribute value of the BGP route corresponding to each gateway node in each gateway cluster. Among them, the second attribute value of the x-th gateway node (which can also be described as the traffic rate-limiting gateway) in the i-th gateway cluster can be expressed as follows:
[0096] P(x) = 2(x - 1) + P 0 (1)
[0097] Among them, P(x) represents the second attribute value, i.e., the MED attribute value, of the x-th gateway node in the i-th gateway cluster, 0 < i <= n, n represents the total number of gateway clusters, 0 < x <= c, c represents the total number of gateway nodes in the i-th gateway cluster; P 0 represents the second attribute value, i.e., the MED attribute value, of the first gateway node in the i-th gateway cluster.
[0098] It can be understood that the gateway nodes in each gateway cluster can be sorted from small to large according to the second attribute value of each gateway node in the gateway cluster to obtain a second sorting result.
[0099] That is, after determining the second attribute value of each gateway node in each gateway cluster, for each gateway cluster, perform the following operations: sort the gateway nodes in the gateway cluster from small to large according to the second attribute value of each gateway node in the gateway cluster to obtain a second sorting result, and use the second sorting result as the second priority of each gateway node in the gateway cluster; for the first target gateway cluster, the gateway node corresponding to the highest priority among the second priorities of each gateway node in the first target gateway cluster is used as the first target gateway node.
[0100] It can be understood that according to the second priority of each gateway node in each gateway cluster, the gateway node corresponding to the highest priority is used as the target gateway node (which can also be described as the main gateway node).
[0101] It can be understood that for the first target gateway cluster, the first target gateway node can also be described as the main gateway node in the main gateway cluster.
[0102] Here, in the case of no failure, the main gateway cluster is selected according to the first priority; in each gateway cluster, the gateway node (which can also be described as the traffic rate-limiting gateway) with the smallest second attribute value is determined as the main gateway node (or described as the main traffic rate-limiting gateway) according to the second priority.
[0103] Here, after the service subscription is successful, the speed limit rules are automatically sent to each traffic speed limit gateway in the main gateway cluster. According to the set first routing strategy, the inbound traffic is forwarded from the outside to the main gateway node (or described as the main traffic speed limit gateway) in the main gateway cluster, and then forwarded to the cloud by the main gateway node (or described as the main traffic speed limit gateway) with limited speed.
[0104] In actual application, the faulty cluster and faulty traffic rate limiting gateway can be quickly located based on the routing priority during message forwarding. Each traffic rate limiting gateway pushes the intra-cluster priority and inter-cluster priority to the control node, and the control node locates the fault based on these two pieces of information.
[0105] Based on this, in some embodiments, the method further includes:
[0106] In the event of a traffic forwarding failure, the first priority of each gateway cluster and the second priority of each gateway node in each gateway cluster are sent to the control node so that the control node can determine the failed gateway node.
[0107] Here, the process of the control node determining the failed gateway node may include:
[0108] First, according to the first attribute value of the BGP route, that is, the first priority of each gateway cluster determined by the AS_PATH attribute, the faulty gateway cluster (or described as a traffic speed-limiting gateway cluster) is quickly located. For example, there are three gateway clusters, represented by gateway cluster 1, gateway cluster 2, and gateway cluster 3, respectively. Among them, the first priority is sorted as: gateway cluster 1, gateway cluster 3, gateway cluster 2. It can be seen that gateway cluster 1 is the first target gateway cluster (or described as the main gateway cluster). Then, in the case of a traffic forwarding failure, since it is forwarded through the main gateway cluster, it is determined that the gateway cluster with the failure is gateway cluster 1;
[0109] Next, according to the following formula (2), the position of the currently used first target gateway node (or described as the main gateway node) in the first target gateway cluster (or described as the main gateway cluster) is calculated, as follows:
[0110] x=(PP 0 ) / 2+1 (2)
[0111] Wherein, x represents the position number of the currently used first target gateway node (or described as the main gateway node) in the first target gateway cluster (or described as the main gateway cluster), P 0The second attribute value of the BGP route corresponding to the first gateway node in the first target gateway cluster (or described as the main gateway cluster), namely the MED attribute value, is represented by P, and the second attribute value of the BGP route corresponding to the first target gateway node currently in use, namely the MED value. Therefore, it can be located that the gateway nodes with a position number less than the main gateway node of the current main gateway cluster (or described as the main traffic speed limit gateway) may have failed. Assuming that x is equal to 3, the gateway nodes with a position number less than 3, namely the first gateway node and the second gateway node in the main gateway cluster, may have failed, thereby achieving rapid fault location.
[0112] The second routing strategy used for outbound traffic is described below.
[0113] In actual application, the use of a speed-limiting gateway cluster can be well expanded, that is, the cluster can accommodate more traffic, but it will also bring problems. The upstream aggregation switch forwards traffic through equal cost multi-path (ECMP, Equal Cost Multi Path). The inbound and outbound traffic will not go through a fixed cluster and a fixed traffic speed-limiting gateway. The most urgent problem to be solved is that the corresponding inbound and outbound traffic are very likely to not go through the same speed-limiting gateway. The general solution is that each cluster carries the same business, which requires that when the business is issued, the traffic speed-limiting rules are issued to each traffic speed-limiting gateway in all clusters. This leads to serious business redundancy, limits the cluster's ability to carry business, and violates the original intention of expanding the speed-limiting gateway. In order to solve this key problem, the following method is proposed in this application to solve this problem, that is, the outbound traffic uses a source routing matching strategy. The source routing matching strategy is to query the traffic speed-limiting gateway cluster to which the corresponding speed-limiting rule belongs based on the source routing, thereby directing the traffic to the main gateway node device of the corresponding traffic speed-limiting gateway cluster.
[0114] Based on this, in some embodiments, the method further includes:
[0115] When forwarding using the second routing strategy, query whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route;
[0116] When it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster that matches the source route, the outbound traffic is directed to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud at a limited speed.
[0117] It can be understood that, when it is determined that the gateway cluster corresponding to the next hop is the first target gateway cluster that matches the source route, the first target gateway node in the first target gateway cluster forwards the outbound cloud traffic to outside the cloud.
[0118] See also Figure 3 , Figure 3 Schematic diagram of forwarding traffic in the cloud direction according to an embodiment of the present application. Figure 3 As shown, the forwarding scenario of outbound traffic is: when the VTEP address of the gateway cluster corresponding to the next hop obtained by the query is the VTEP address of the first target gateway cluster matched by the source route (that is, the VTEP address of the current traffic speed-limiting gateway cluster), that is, the gateway cluster corresponding to the outbound traffic and the gateway cluster corresponding to the inbound traffic are the same, then the current gateway cluster, that is, the first target gateway node in the first target gateway cluster (or described as the main gateway node or the main traffic speed-limiting gateway) performs the traffic speed-limiting forwarding.
[0119] In some embodiments, the querying whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route includes:
[0120] Determine the VTEP address of the gateway cluster corresponding to the next hop according to the public network address and the routing list carried by the outbound traffic.
[0121] Determine the gateway cluster corresponding to the next hop based on the VTEP address and gateway cluster list of the gateway cluster corresponding to the next hop;
[0122] Compare the gateway cluster corresponding to the next hop with the first target gateway cluster matched by the source route to obtain a comparison result;
[0123] When the comparison result indicates that the gateway cluster corresponding to the next hop is different from the first target gateway cluster matching the source route, it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster matching the source route.
[0124] It is understandable that the routing list stores the correspondence between the public network address and the VTEP address of the gateway cluster corresponding to the next hop.
[0125] It can be understood that the gateway cluster list stores the correspondence between the VTEP addresses of the gateway clusters and the gateway clusters.
[0126] See also Figure 4 , Figure 4 Schematic diagram of forwarding traffic in the cloud direction according to an embodiment of the present application. Figure 4As shown, the forwarding scenario of outbound traffic is: when the VTEP address of the gateway cluster corresponding to the next hop obtained by the query is not the VTEP address of the first target gateway cluster matched by the source route (that is, the VTEP address of the current traffic speed-limiting gateway cluster), that is, the gateway cluster corresponding to the outbound traffic is not the same as the gateway cluster corresponding to the inbound traffic, then the main gateway node (or described as the main traffic speed-limiting gateway) in the gateway cluster corresponding to the next hop obtained by the query will first perform traffic speed-limiting forwarding, and finally the outbound traffic will be directed to the first target gateway node (or described as the main gateway node or the main traffic speed-limiting gateway) in the first target gateway cluster (the gateway cluster corresponding to the inbound traffic) matched by the source route, and then the first target gateway node will perform speed-limited forwarding to outside the cloud.
[0127] Here, route matching can be performed based on the public network address carried by the outbound traffic and the route list, so as to select the VTEP address of the gateway cluster that is to receive the outbound traffic, and then determine the corresponding gateway cluster based on the VTEP address and the gateway cluster list. If the gateway cluster is not the first target gateway cluster matched by the source route, the outbound traffic is directed to the first target gateway node of the corresponding first target gateway cluster (or described as the main traffic speed limiting gateway), so that the speed limiting rules issued when subscribing to the service can be reused, and there is no need to issue traffic speed limiting rules to all gateway clusters.
[0128] Here, we can use the correspondence between the public network address (indicated by Pvm) carried by the outbound traffic, the routing list (indicated by LR), and the gateway cluster list (indicated by LC) to determine the target gateway node (indicated by R(Pvm,LR,LC)) in the gateway cluster corresponding to the next hop, as follows:
[0129] R(Pvm,LR,LC)=MTG(SC(RS(Pvm,LR),LC))
[0130] Among them, R(Pvm,LR,LC) represents the target gateway node (or described as the main gateway node) in the gateway cluster corresponding to the determined next hop, Pvm represents the public network address carried by the outbound traffic, LR represents the routing list, and LC represents the gateway cluster list; RS(Pvm,LR) is a function for selecting routes, which is used to represent the VTEP address of the gateway cluster corresponding to the next hop determined according to the public network address (Pvm) carried by the outbound traffic and the routing list (LR); SC(RS(Pvm,LR),LC) is a function for selecting gateway clusters, which is used to represent the gateway cluster corresponding to the next hop determined according to the VTEP address of the gateway cluster corresponding to the next hop and the gateway cluster list (LC); MTG(SC(RS(Pvm,LR),LC)) is a function for selecting the main gateway node, which is used to select the target gateway node (or described as the main gateway node) in the gateway cluster corresponding to the next hop, specifically determining the corresponding target gateway node according to the second priority of each gateway node in the gateway cluster corresponding to the next hop.
[0131] See also Figure 5 , Figure 5 Schematic diagram of traffic forwarding in an embodiment of the present application. Figure 5 As shown, the relevant settings in the traffic forwarding process may include: setting isolation domains such as bridge domains (BD) and virtual routing and forwarding (VRF) parameters according to the inbound port index corresponding to the inbound cloud traffic; judging whether layer 3 forwarding is required based on whether the destination media access control (MAC) address (expressed by dmac) matches the source MAC address (expressed by rmac); matching source routing (source route) rule, obtain the corresponding destination IP address according to the matching situation to modify the next hop (nexthop); find the tunnel index of the next hop according to the corresponding routing table; then find the corresponding next hop physical port according to the tunnel index; rewrite the destination mac address (dst_addr) according to the next hop (nexthop) physical port, and modify the isolation domain (such as the bridge domain (BD)); set the source mac (smac) index according to the output isolation domain, and rewrite the source mac (smac) address according to the source mac index; rewrite the destination mac (dmac) of the inner underlay according to the underlying network (underlay) routing; rewrite the source mac (smac) index according to the isolation domain (bd) for modifying the inner smac; modify the inner source mac (smac) address according to the source mac index; modify the tunnel source IP address (src_ip) according to the tunnel type.
[0132] In actual application, each gateway cluster can monitor the status of each gateway node (or described as a traffic speed-limiting gateway) in other gateway clusters except itself. When all gateway nodes (or described as traffic speed-limiting gateways) in the entire gateway cluster are down, the message cannot be detected and the reply packet cannot be received. Therefore, other gateway clusters will cancel one or more source routing data table items in the database pointing to the gateway node (or described as a traffic speed-limiting gateway) of the corresponding gateway cluster.
[0133] Based on this, in some embodiments, the method further includes:
[0134] Monitor the working status of each gateway node in each gateway cluster except itself;
[0135] In the case where a first signal sent by a first gateway cluster in the other gateway clusters is not received, a second signal is sent to a second gateway cluster in the other gateway clusters except the first gateway cluster, wherein the second signal is used for the second gateway cluster to cancel one or more source routing data table entries in a database pointing to a gateway node in the first gateway cluster.
[0136] It can be understood that the first signal may be a heartbeat signal or the like.
[0137] It can be understood that failure to receive the first signal sent by the first gateway cluster in the other gateway clusters can be understood as a result of all gateway nodes in the first gateway cluster being down.
[0138] It can be understood that the source routing table entry may refer to a field in a database, and the field represents the source routing.
[0139] For example, each gateway cluster can monitor other gateway clusters. A loopback address is configured in the gateway cluster. The BGP devices in the gateway nodes in the gateway cluster will periodically detect route reachability. When the last traffic-limiting gateway in a gateway cluster goes down, the bidirectional forwarding detection (BFD) protocol in the BGP device detects that the route is unreachable and the announcement of the loopback address will be revoked. When other gateway clusters detect that the route of the loopback address disappears, they will revoke the corresponding data in the source routing table, thereby revoking the use of the gateway cluster on the control plane and will no longer forward to the gateway cluster in the subsequent forwarding process. Both the control plane and the forwarding plane can synchronize changes at the physical level to achieve emergency escape of traffic.
[0140] In the embodiment of the present application, the following advantages are possessed:
[0141] (1) Provide a multi-active high-availability solution for traffic-limited gateways, mainly optimizing the cloud-entry and cloud-exit strategies of the traffic-limited gateway cluster to increase the business capacity that the cluster can carry.
[0142] In the present application, for the inbound traffic, the first routing strategy is adopted for forwarding; for the outbound traffic, the second routing strategy is adopted for forwarding. In this way, the inbound traffic is forwarded from the outside to the first target gateway node in the first target gateway cluster, and then the first target gateway node performs speed-limited forwarding to the cloud; the outbound traffic is directed to the first target gateway node in the first target gateway cluster, and then the first target gateway node performs speed-limited forwarding to the outside of the cloud, thereby optimizing redundant traffic speed-limiting policy rules, that is, there is no need to send traffic speed-limiting rules to each gateway node in all gateway clusters, thus avoiding the occurrence of service redundancy and improving the service capacity carried by the traffic speed-limiting gateway cluster.
[0143] That is, the cloud inbound strategy and cloud outbound strategy in the multi-active traffic rate limiting gateway cluster scenario are used to optimize redundant traffic rate limiting policy rules during capacity expansion. BGP optimization is used for inbound traffic, and source routing matching strategy is used for outbound traffic to achieve reuse of traffic rate limiting policies.
[0144] In addition, in the present application, different routing strategies are used in the cloud inbound and cloud outbound directions to prevent routing priority conflicts caused by the use of the same routing strategy for cloud inbound and cloud outbound traffic.
[0145] (2) It can not only realize emergency escape of the entire cluster failure, but also quickly locate the specific location of the faulty cluster and the faulty traffic rate-limiting gateway in the cluster.
[0146] In order to implement the traffic forwarding method of the embodiment of the present application, the embodiment of the present application also provides a traffic forwarding device, which is arranged in a network device. Figure 6 Schematic diagram of the structure of the traffic forwarding device according to the embodiment of the present application. Figure 6 As shown, the device comprises:
[0147] The first processing module 61 is used to forward the inbound cloud traffic using a first routing strategy; the first routing strategy is to forward the inbound cloud traffic from the outside to a first target gateway node in a first target gateway cluster according to a first priority of the gateway cluster and a second priority of the gateway node in the gateway cluster, and then forward the traffic to the cloud by the first target gateway node;
[0148] The second processing module 62 is used to forward the outbound traffic using a second routing strategy; the second routing strategy is to direct the outbound traffic to the first target gateway node in the first target gateway cluster, and then forward it to outside the cloud by the first target gateway node.
[0149] In some embodiments, the first processing module 61 is further configured to:
[0150] Determine a first attribute value and a second attribute value of a BGP route corresponding to each gateway node in each gateway cluster; the first attribute value represents an AS path length; the second attribute value represents a MED attribute value;
[0151] Determine, according to the first attribute value, a first priority of each gateway cluster; determine, according to the first priority, the first target gateway cluster from among the gateway clusters;
[0152] According to the second attribute value, the second priority of each gateway node in each gateway cluster is determined; according to the second priority of each gateway node in the first target gateway cluster, the first target gateway node in the first target gateway cluster is determined.
[0153] In some embodiments, the first processing module 61 is specifically used to:
[0154] Determine the number of gateway nodes in each gateway cluster whose AS path length is less than or equal to a preset threshold;
[0155] Sorting the gateway clusters according to the number of gateway nodes to obtain a first sorting result;
[0156] Using the first sorting result as the first priority of each gateway cluster;
[0157] The gateway cluster corresponding to the highest priority among the first priorities is used as the first target gateway cluster.
[0158] In some embodiments, the first processing module 61 is further configured to:
[0159] For each gateway cluster, perform the following operations:
[0160] Sorting the gateway nodes in the gateway cluster according to the second attribute value of each gateway node in the gateway cluster to obtain a second sorting result;
[0161] Using the second sorting result as the second priority of each gateway node in the gateway cluster;
[0162] The gateway node corresponding to the highest priority among the second priorities of each gateway node in the first target gateway cluster is used as the first target gateway node in the first target gateway cluster.
[0163] In some embodiments, the first processing module 61 is further configured to:
[0164] In the event of a traffic forwarding failure, the first priority of each gateway cluster and the second priority of each gateway node in each gateway cluster are sent to the control node so that the control node can determine the failed gateway node.
[0165] In some embodiments, the second processing module 62 is further configured to:
[0166] When forwarding using the second routing strategy, query whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route;
[0167] When it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster that matches the source route, the outbound traffic is directed to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud at a limited speed.
[0168] In some embodiments, the second processing module 62 is further configured to:
[0169] Determine the VTEP address of the gateway cluster corresponding to the next hop according to the public network address and the routing list carried by the outbound traffic.
[0170] Determine the gateway cluster corresponding to the next hop based on the VTEP address and gateway cluster list of the gateway cluster corresponding to the next hop;
[0171] Compare the gateway cluster corresponding to the next hop with the first target gateway cluster matched by the source route to obtain a comparison result;
[0172] When the comparison result indicates that the gateway cluster corresponding to the next hop is different from the first target gateway cluster matching the source route, it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster matching the source route.
[0173] In some embodiments, the second processing module 62 is further configured to:
[0174] Monitor the working status of each gateway node in each gateway cluster except itself;
[0175] In the case where a first signal sent by a first gateway cluster in the other gateway clusters is not received, a second signal is sent to a second gateway cluster in the other gateway clusters except the first gateway cluster, wherein the second signal is used for the second gateway cluster to cancel one or more source routing data table entries in a database pointing to a gateway node in the first gateway cluster.
[0176] In actual application, the first processing module 61 and the second processing module 62 can be implemented by a processor in a traffic forwarding device.
[0177] It should be noted that: the traffic forwarding device provided in the above embodiment only uses the division of the above program modules as an example when performing traffic forwarding. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the traffic forwarding device provided in the above embodiment and the traffic forwarding method embodiment belong to the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0178] The present application also provides a network device, such as Figure 7 As shown, including:
[0179] Communication interface 71, capable of exchanging information with other devices;
[0180] The processor 72 is connected to the communication interface 71 and is used to execute the method provided by one or more technical solutions of the network device side when running the computer program. The computer program is stored in the memory 73.
[0181] It should be noted that the specific processing process of the processor 72 and the communication interface 71 is detailed in the method embodiment and will not be repeated here.
[0182] Of course, in actual application, the various components in the network device 70 are coupled together through the bus system 74. It is understandable that the bus system 74 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 74 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 7 Various buses are labeled as bus system 74 .
[0183] The memory 73 in the embodiment of the present application is used to store various types of data to support the operation of the network device 70. Examples of such data include: any computer program used to operate on the network device 70.
[0184] The method disclosed in the above embodiment of the present application can be applied to the processor 72, or implemented by the processor 72. The processor 72 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 72. The above-mentioned processor 72 may be a general-purpose processor, a digital data processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 72 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiment of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the memory 73, and the processor 72 reads the information in the memory 73 and completes the steps of the above method in combination with its hardware.
[0185] In an exemplary embodiment, the network device 70 can be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), field programmable gate array (FPGA), general processor, controller, microcontroller (MCU), microprocessor, or other electronic components to execute the aforementioned method.
[0186] It can be understood that the memory (memory 73) of the embodiment of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a ferromagnetic random access memory, a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAMbus random access memory (DRRAM, Direct Rambus Random Access Memory).The memories described in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.
[0187] In an exemplary embodiment, the embodiment of the present invention further provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, a memory storing a computer program, and the computer program can be executed by the processor 72 of the network device 70 to complete the steps of the aforementioned network device side method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.
[0188] Exemplarily, an embodiment of the present application further provides a computer program product, including a computer program, which can be executed by a processor 72 of a network device 70 to complete the steps of any of the aforementioned methods.
[0189] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0190] In addition, the technical solutions described in the embodiments of the present invention can be arbitrarily combined without conflict.
[0191] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention.
Claims
1. A traffic forwarding method, characterized in that: Applied to any gateway node in a gateway cluster, the method comprises: For the inbound traffic, the first routing strategy is adopted for forwarding; the first routing strategy is to forward the inbound traffic from the outside to the first target gateway node in the first target gateway cluster according to the first priority of the gateway cluster and the second priority of the gateway node in the gateway cluster, and then forward it to the cloud by the first target gateway node; For outbound traffic, a second routing strategy is used for forwarding; the second routing strategy is to direct the outbound traffic to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud.
2. The method according to claim 1, characterized in that The method further comprises: Determine a first attribute value and a second attribute value of a Border Gateway Protocol BGP route corresponding to each gateway node in each gateway cluster; the first attribute value represents an autonomous system AS path length; the second attribute value represents a multi-exit identification MED attribute value; Determine, according to the first attribute value, a first priority of each gateway cluster; determine, according to the first priority, the first target gateway cluster from among the gateway clusters; According to the second attribute value, the second priority of each gateway node in each gateway cluster is determined; according to the second priority of each gateway node in the first target gateway cluster, the first target gateway node in the first target gateway cluster is determined.
3. The method according to claim 2, characterized in that determining a first priority of each gateway cluster according to the first attribute value; Determining the first target gateway cluster from the gateway clusters according to the first priority includes: Determine the number of gateway nodes in each gateway cluster whose AS path length is less than or equal to a preset threshold; Sorting the gateway clusters according to the number of gateway nodes to obtain a first sorting result; Using the first sorting result as the first priority of each gateway cluster; The gateway cluster corresponding to the highest priority among the first priorities is used as the first target gateway cluster.
4. The method according to claim 2, characterized in that: The determining, according to the second attribute value, a second priority of each gateway node in each gateway cluster includes: For each gateway cluster, perform the following operations: Sorting the gateway nodes in the gateway cluster according to the second attribute value of each gateway node in the gateway cluster to obtain a second sorting result; Using the second sorting result as the second priority of each gateway node in the gateway cluster; Correspondingly, determining the first target gateway node in the first target gateway cluster according to the second priority of each gateway node in the first target gateway cluster includes: The gateway node corresponding to the highest priority among the second priorities of each gateway node in the first target gateway cluster is used as the first target gateway node in the first target gateway cluster.
5. The method according to any one of claims 2 to 4, characterized in that: The method further comprises: In the event of a traffic forwarding failure, the first priority of each gateway cluster and the second priority of each gateway node in each gateway cluster are sent to the control node so that the control node can determine the failed gateway node.
6. The method according to claim 1, characterized in that The method further comprises: When forwarding using the second routing strategy, query whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route; When it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster that matches the source route, the outbound traffic is directed to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud at a limited speed.
7. The method according to claim 6, characterized in that The querying whether the gateway cluster corresponding to the next hop is the first target gateway cluster matching the source route includes: Determine the virtual scalable local area network tunnel endpoint VTEP address of the gateway cluster corresponding to the next hop according to the public network address and route list carried by the outbound traffic. Determine the gateway cluster corresponding to the next hop based on the VTEP address and gateway cluster list of the gateway cluster corresponding to the next hop; Compare the gateway cluster corresponding to the next hop with the first target gateway cluster matched by the source route to obtain a comparison result; When the comparison result indicates that the gateway cluster corresponding to the next hop is different from the first target gateway cluster matching the source route, it is determined that the gateway cluster corresponding to the next hop is not the first target gateway cluster matching the source route.
8. The method according to claim 1, characterized in that: The method further comprises: Monitor the working status of each gateway node in each gateway cluster except itself; In the case where a first signal sent by a first gateway cluster in the other gateway clusters is not received, a second signal is sent to a second gateway cluster in the other gateway clusters except the first gateway cluster, wherein the second signal is used for the second gateway cluster to cancel one or more source routing data table entries in a database pointing to a gateway node in the first gateway cluster.
9. A traffic forwarding device, characterized in that: include: A first processing module, configured to forward the inbound cloud traffic using a first routing strategy; The first routing strategy is to forward the cloud-entry traffic from the outside to the first target gateway node in the first target gateway cluster according to the first priority of the gateway cluster and the second priority of the gateway node in the gateway cluster, and then forward it to the cloud by the first target gateway node; A second processing module is used to forward the outbound traffic using a second routing strategy; The second routing strategy is to direct the outbound cloud traffic to the first target gateway node in the first target gateway cluster, and then the first target gateway node forwards the traffic to outside the cloud.
10. A network device, characterized in that: comprising a processor and a memory for storing a computer program capable of being executed on the processor, Wherein, when the processor is used to run the computer program, it executes the steps of the method described in any one of claims 1 to 8.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
12. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.