System and method for monitoring network topology through graphical user interface
By using software instances and controllers in a multi-cloud network environment, a graphical user interface is provided to visualize and monitor network topology, which solves the problem that network administrators find it difficult to troubleshoot connectivity problems in multi-cloud networks, and realizes operational visibility and efficient management of multi-cloud networks.
Patent Information
- Application Number
- CN202380069258.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-08-03
- Filing Date
- 2023-08-01
- Publication Date
- 2025-05-16
AI Technical Summary
In the case where the network deployed by an enterprise relies on multiple public cloud networks, network administrators have difficulty effectively troubleshooting connectivity problems occurring within multi-cloud networks, and there is a lack of conventional solutions to visualize traffic exchange between network devices and monitor network health status.
Provides a system and method to collect and present a graphical user interface through software instances and controllers, provide connective interactive visual presentation between network constructs spanning multiple cloud computing environments, and generate a visual platform to monitor and filter network topology maps.
The operational visibility of multi-cloud networks is achieved, allowing administrators to intuitively build and monitor enterprise network topology, quickly detect network connectivity issues and potential network attacks, and improve network management efficiency and reliability.
Smart Images

Figure CN120019629A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of cloud networking. More specifically, one embodiment of the present disclosure relates to a system and method for providing operational visibility of an enterprise network spanning a single public cloud network or multiple public cloud networks, and for providing users with the ability to build and implement enterprise network topologies directly from a user interface that provides such operational visibility. Background Art
[0002] Until recently, enterprises have relied on application software installed on one or more electronic devices that reside in close proximity to their users (hereinafter referred to as "on-premise electronic devices"). These on-premise electronic devices may correspond to, for example, endpoint devices (e.g., personal computers, cellular smartphones, netbooks, etc.), locally maintained mainframes, or even local servers. Depending on the size of the enterprise, the purchase of on-premise electronic devices and their corresponding software requires significant upfront capital expenditures, as well as significant ongoing operating costs to maintain the operability of these on-premise electronic devices. These operating costs may include the costs of deploying, managing, maintaining, upgrading, repairing, and replacing these electronic devices.
[0003] Recently, more and more businesses and individuals have begun to rely on public cloud networks (hereinafter referred to as "public clouds") to provide users with a variety of services ranging from word processing application functions to network management. A "public cloud" is a fully virtualized environment with a multi-tenant architecture that provides tenants (i.e., users) with the ability to share computing and storage resources while maintaining data isolation within each user's cloud account. The virtualized environment includes an on-demand cloud computing platform provided by a collection of physical data centers, each of which includes numerous servers hosted by a cloud provider. Examples of different types of public cloud networks may include, but are not limited to, AMAZON WEB GOOGLECLOUD PLATFORM TM OR ORACLE CLOUD TM .
[0004] This growing reliance on public cloud networks is due in large part to the substantial cost-saving advantages provided by this particular deployment. However, for many types of services (such as, for example, network management), network administrators face many challenges when business operations depend on the operability of a single public cloud or the operability of multiple public cloud networks. For example, in the case where an enterprise deploys a network that depends on multiple public cloud networks (hereinafter referred to as a "multi-cloud network"), network administrators cannot effectively troubleshoot connectivity issues that occur within the multi-cloud network. One reason for this ineffective troubleshooting is that there are no conventional solutions available to administrators or users to visualize the connectivity of their multi-cloud network deployments. Another reason is that cloud network providers only allow users to access a limited number of configurations, thereby controlling the type and amount of network information that users can access. As a result, the type or amount of network information is rarely sufficient to enable administrators or users to quickly and effectively troubleshoot and correct network connectivity issues.
[0005] Likewise, there is no conventional solution to visually monitor traffic exchanges between network devices in different public cloud networks (multi-cloud networks) and retain state information associated with network devices in the multi-cloud network to more quickly detect operational anomalies that may suggest that a cyber attack is ongoing or the health of the multi-cloud network is compromised. In addition, what is needed is a system for generating a graphical user interface and a method for implementing the system that enables an administrator or other user to build a network topology map in an intuitive manner, wherein the system then automatically deploys constructs and applicable communication lines between such constructs to generate a fully operational network topology. Still further, what is needed is a graphical user interface that displays a network topology map in a visually scalable manner, i.e., the visual display of icons representing constructs, edges, and other aspects of the network topology map automatically adjusts to reduce visual clutter and provide viewing convenience. Such a system, method, and resulting graphical user interface should also provide various monitoring, searching, and filtering capabilities directly from the graphical user interface. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Embodiments of the present disclosure are illustrated by way of example and not limitation in the figures of the accompanying drawings in which like reference numerals indicate similar elements and in which:
[0007] Figure 1 is a diagram of an exemplary embodiment of a distributed cloud computing system including a controller that manages a fabric spanning multiple cloud networks, according to some embodiments;
[0008] Figure 2A is an exemplary diagram of a logical representation of a controller deployed within a cloud computing platform according to some embodiments;
[0009] Figure 2Bis an exemplary illustration of a logical representation of topology system logic deployed within a cloud computing platform according to some embodiments;
[0010] Figure 3 is an interface screen showing a portion of a dashboard of a visualization platform according to some embodiments, the interface screen being intended to illustrate information related to network traffic and configuration within a cloud computing environment;
[0011] Figures 4A-4I is an interface screen of a second embodiment of displaying a network topology map according to some embodiments, the interface screen includes a process of constructing a network topology map through user input, and as an execution Figure 1 The distributed cloud computing system is populated as a result of the operation of the distributed cloud computing system;
[0012] Figure 5A-5B According to some embodiments, the display Figures 4A-4I An interface screen of an example network topology diagram for monitoring network topology constructed using the method technology illustrated in FIG.
[0013] Figure 6-7 is a flow chart of an exemplary method of communication between topology system logic, a controller, and one or more gateways managed by the controller, according to some embodiments. DETAILED DESCRIPTION
[0014] Embodiments of the present disclosure are directed to a system configured to provide operational visibility of a network across one or more cloud computing environments. According to one embodiment, the system may include a software instance that is operating in one or more cloud computing resources and is configured to collect information and present a graphical user interface (GUI) that provides an interactive visual presentation of connectivity between network constructs across multiple (two or more) cloud computing environments (hereinafter referred to as "multi-cloud computing environments" or "multi-cloud networks"). In other embodiments, the system includes a software instance and a controller that is configured to manage constructs deployed in one or more cloud computing environments (such as within a multi-cloud environment) and communicate with the software instance.
[0015] As will be discussed in further detail below, the software instance may query the controller for information using one or more application programming interface (API) calls to retrieve information stored by the controller detailing state information for each structure managed by the controller. The controller obtains such information from one or more gateways deployed within the multi-cloud network, wherein the (one or more) gateways are configured to transmit the information to the controller on a periodic (or aperiodic) basis. It should be understood that, as discussed herein, the term "multi-cloud network" refers to multiple cloud networks, each of which may constitute a public cloud network provided by a different cloud computing environment resource provider (hereinafter referred to as a "cloud provider").
[0016] As is known in the art, the controller can be configured to program each gateway to control the routing of network traffic, such as by providing instructions to the gateway regarding how network traffic is routed between the various gateways. As an illustrative example, the controller can instruct the gateway regarding whether a virtual machine (VM) from one subnet (hereinafter referred to as a "subnet") can communicate directly with a VM from another subnet, or how network traffic will flow from a source to a destination within a cloud computing environment managed by the controller. In addition, embodiments of the present disclosure discuss instructions provided by a software instance to a controller that are then transmitted by the controller to one or more gateways, and include instructions for transmitting network data from a gateway to a routable address (e.g., an Internet Protocol "IP" address, etc.) of a software instance.
[0017] Thus, as a general embodiment, the software instance may query the controller for data indicating the state and metadata of each structure managed by the controller, and also receive network data from one or more gateways. The software instance includes logic that generates various visualizations when executed by one or more processors (e.g., as part of cloud computing resources), which are combinations of structure states and metadata (collectively referred to as "structure metadata") and network data. The visualization can be interactive and provided to users such as network administrators, information technology (IT) professionals, etc. In addition, the visualization can be configured to receive user input that causes the logic of the software instance ("topology system logic") to change the visualization. As discussed below and illustrated in the accompanying drawings, the visualization may include, but is not limited to, or be limited to, providing a dashboard view of the overall status and health of the network and specific network parameters; a dynamic topology map that provides a visual presentation of each structure and links that identify communications between structures; and a network flow visualization that provides various diagrams that describe in detail how network traffic flows (or has flowed) through a cloud computing environment managed by a controller. Each visualization can provide data across a multi-cloud network.
[0018] In some embodiments, in response to user input, the topology system logic can generate labels for one or more structures via a topology map visualization and store those labels for searching. For example, additional user input can be received so that the topology system logic searches a number of structures managed by the controller and displays the labeled structures and any links between them via the topology map. In still other embodiments, in response to receiving user input that includes one or more labels as search terms, the topology system logic can generate a visualization that illustrates the network flow of the corresponding (one or more) labeled structures.
[0019] By querying the controller for construction metadata and receiving network data from one or more gateways, the topology system logic can generate the exemplary visualizations described above and those shown in the accompanying drawings, which illustrate network traffic flows associated with one or more labeled constructions. As noted throughout, the illustrated network traffic flows can correspond to constructions deployed in multiple cloud networks. This operability provides users with numerous advantages over the prior art by enabling them to tag one or more gateways residing in different public cloud networks with meaningful tags and search for construction parameters, construction states, link states, and network traffic flows corresponding to the tags.
[0020] An additional function of the topology system logic is to generate visualizations that illustrate changes over time in various aspects of the network managed by the controller. For example and as discussed below, the topology system logic may store data (network data and construction metadata) received about the network at a given point in time, such as t1→ti (where i>1). Upon receiving user input corresponding to a request to display changes between two points in time (e.g., t1 and t2), the topology system logic compares the stored data at t1 and t2 and generates a visual that highlights the change(s) between the network at t1 and t2. The term "highlight" may refer to any visual indicator or combination of visual indicators, such as color coding constructions with changed parameters, changing the size of constructions with changed parameters, displaying a graphic (e.g., a ring) around constructions with changed parameters, displaying a window or other image that lists the network state changes detected between time t1 and time t2 (which may span multiple public cloud networks), or other types of visual indicators.
[0021] I. the term
[0022] In the following description, certain terms are used to describe features of the present invention. In some cases, the term "logic" represents hardware, firmware and / or software configured to perform one or more functions. As hardware, the logic may include circuits with data processing or storage functions. Examples of such circuits may include, but are not limited to, or be limited to, a microprocessor, one or more processor cores, a programmable gate array, a microcontroller, an application specific integrated circuit, a wireless receiver, a transmitter and / or transceiver circuit, a semiconductor memory, or a combinational logic.
[0023] Alternatively, or in combination with the above-mentioned hardware circuits, the logic can be software in the form of one or more software modules. (One or more) software modules may include executable applications, application programming interfaces (APIs), subroutines, functions, procedures, applets, servlets, routines, source code, shared libraries / dynamically loaded libraries, or one or more instructions. (One or more) software modules may be stored in any type of suitable non-transitory storage medium or temporary storage medium (e.g., electrical, optical, acoustic, or other forms of propagation signals, such as carrier waves, infrared signals, or digital signals). Examples of non-transitory storage media may include, but are not limited to, programmable circuits; semiconductor memories; non-permanent storage devices, such as volatile memory (e.g., any type of random access memory "RAM"); permanent storage devices, such as non-volatile memory (e.g., read-only memory "ROM", power-supported RAM, flash memory, phase change memory, etc.), solid-state drives, hard disk drives, optical disk drives, or portable memory devices. As firmware, executable code may be stored in permanent storage devices.
[0024] The term "computerized" generally means that any corresponding operations are performed by hardware in combination with software and / or firmware.
[0025] The term "construction" may be interpreted as virtual or physical logic for a particular function, such as a gateway, a virtual private cloud network (VPC), a subnet, etc. For example, as an illustrative example, the construct may correspond to virtual logic (e.g., a virtual machine) in the form of software that can assign device-specific addresses (e.g., media access control "MAC" addresses) and / or IP addresses within the range of IP addresses supported by a particular IP subnet to a particular IP subnet. Alternatively, in some embodiments, the construct may correspond to physical logic, such as an electronic device that is communicatively coupled to a network and is assigned (one or more) MAC and / or IP addresses. Examples of electronic devices may include, but are not limited to, personal computers (e.g., desktop computers, laptop computers, tablet computers, or netbooks), mobile phones, stand-alone devices, sensors, servers, or information routing devices (e.g., routers, bridge routers ("brouters"), etc.). It is contemplated that each construct may constitute at least logic that is part of a public network, although certain constructs may be deployed as part of an "on-premises" (or local) network.
[0026] The term "gateway" may refer to a software instance that is deployed within a public cloud network or a virtual private cloud network deployed in conjunction with a public cloud network and that controls the flow of data traffic within and from the public cloud network (e.g., to one or more remote sites, including computing devices that can process, store, and / or continue data routing). In this document, each gateway may operate as a "transit gateway" or a "branch gateway," which are gateways with similar architectures but are identified differently based on their location / configuration in a cloud computing environment. For example, a "branch" gateway is configured to interact with a target instance, while a "hub" gateway is configured to further assist in the propagation of data traffic (e.g., one or more messages) directed to a branch gateway or computing device within an on-premises network.
[0027] The term "network traffic metrics" may refer to measurements of network traffic transmission, including quantity, frequency, and / or latency. In some embodiments, network traffic metrics may include identification of the source and / or destination (e.g., IP address, originating / destination gateway, originating / destination VPC, originating / destination geographic region, etc.). Additionally, in some embodiments, network traffic metrics may also refer to analysis and / or filtering performed on measurements of network traffic transmission.
[0028] The term "controller" may refer to a software instance deployed within a cloud computing environment (e.g., resources of a public cloud network) that manages certain aspects of the operability of one or more cloud computing environments across different public cloud networks (multi-cloud networks). For example, a controller may be configured to collect information related to each VPC and / or each gateway instance, and configure one or more routing tables associated with one or more VPCs and / or gateway instances across the multi-cloud network to establish communication links (e.g., logical connections) between different sources and destinations. These sources and / or destinations may include, but are not limited to or restricted to, on-premises computing devices, gateway instances, or other types of cloud resources.
[0029] The term "message" generally refers to information transmitted in a specified format and according to an appropriate delivery protocol. Therefore, each message may be in the form of one or more packets, frames or any other bit sequence having a specified format.
[0030] The term "link" may generally be interpreted as a physical or logical communication path between two or more structures. For example, as a physical communication path, wired and / or wireless interconnections in the form of wires, optical fibers, cables, bus tracks, or wireless channels using infrared, radio frequency (RF) may be used. Logical communication paths include any communication scheme that enables information to be exchanged between multiple structures.
[0031] Finally, the terms "or" and "and / or" as used herein should be interpreted as inclusive or meaning any one or any combination. As an example, "A, B, or C" or "A, B, and / or C" means "any of the following: A; B; C; A and B; A and C; B and C; A, B, and C". An exception to this definition will only occur if a combination of elements, functions, steps, or actions are inherently mutually exclusive in some way.
[0032] As the invention is susceptible of embodiment in many different forms, it is intended that this disclosure be considered as an exemplification of the principles of the invention and is not intended to limit the invention to the specific embodiments shown and described.
[0033] II. Overall architecture - topology system
[0034] refer to Figure 1 , a diagram of an exemplary embodiment of a distributed cloud management system 100 is shown, wherein the cloud computing system features a controller 102 for managing fabrics residing in multiple cloud networks and a software instance 138 for visualizing the managed fabrics (hereinafter referred to as "topology system logic"). More specifically, the controller 102 is configured to manage multiple fabrics across multiple cloud networks, such as cloud (network) A 104 and cloud (network) B 106. In the exemplary illustration, cloud A 104 is associated with a virtual network (VNET) 116. 1 -116 2 Gateway 118 1 -118 2 The communication transit gateway 114 provides computing resources ("resources"). Cloud B 106 is associated with a virtual private cloud (VPC) 122 1 -122 2 Gateway 124 1 -124 2 Cloud B 106 also provides resources for a local transit hub 126 that communicates with VPCs 128 and 130. According to this embodiment of the present disclosure, Figure 1 As shown in , the transit gateways 114, 120 and the local transit hub 126 are in communication with each other. Thus, as should be clearly understood, the controller 102 is managing several configurations, such as the illustrated gateways, across multiple cloud networks.
[0035] Specifically, a first set of fabrics 108 is deployed within cloud A 104, and second and third sets of fabrics 110, 112 are deployed within cloud B 106. The controller 102 utilizes a set of APIs to provide instructions and receive data (state information) associated with each of these fabrics and state information (link state) associated with each connection between these fabrics. The fabric metadata returned by the fabric may depend on the type of fabric (e.g., region, VPC, gateway, subnet, instance within a VPC, etc.), where examples of fabric metadata may include, but are not limited to, one or more of the following fabric parameters (attributes): fabric name, fabric identifier, encryption enabled, properties of the VPC associated with the fabric (e.g., VPC name, identifier, and / or region, etc.), properties of the cloud in which the fabric is deployed (e.g., cloud provider, cloud type, etc., where the fabric resides), etc.
[0036] In addition, the cloud management system 100 includes a topology system logic 138 that is processed on the cloud computing resources 136. In some embodiments, the topology system logic 138 can be logic hosted on a user's Infrastructure as a Service (IaaS) cloud or multi-cloud environment. As an example, the topology system logic 138 can be launched as an instance within a public cloud network (e.g., as a In As an alternative example, the topology system logic 138 may be configured as When started, the topology system logic 138 is assigned a routable address, such as a static IP address, for example.
[0037] As shown, the topology system logic 138 communicates with the controller 102 via, for example, an API that enables the topology system logic 138 to transmit queries to the controller 102 via one or more API calls. The topology system logic 138, when executed by the cloud computing resources 136, performs operations including querying the controller 102 for construction metadata via the API call in response to a particular event. The particular event may be based on a periodic interval or an aperiodic interval or a triggering event, such as a user request for a visualization via user input.
[0038] In some embodiments, in response to receiving a query from the topology system logic 138 via an API call, the controller 102 accesses data stored on or by the controller 102 and returns the requested data via the API to the topology system logic 138. For example, the topology system logic 138 may initiate one or more queries to the controller 102 to obtain topology information associated with the fabrics managed by the controller 102 (e.g., a list of all gateways managed by the controller 102, a list of all VPCs or VNETs managed by the controller 102, or other data collected from a database table) and status information associated with each fabric as described above.
[0039] Upon receiving the requested construction metadata, the topology system logic 138 performs one or more analyses and determines whether any additional construction metadata needs to be requested. For example, the topology system logic 138 may provide a first query to the controller 102 requesting a list of all gateways managed by the controller 102. In response to receiving the requested construction metadata, the topology system logic 102 determines the interconnections between the listed gateways. Subsequently, the topology system logic 138 may provide a second query to the controller 102 requesting a list of all VPCs managed by the controller. In response to receiving the requested construction metadata, the topology system logic 138 determines an association between each VPC and a corresponding gateway.
[0040] For example, in some embodiments, the received construction metadata provides detailed information for each gateway, enabling the topology system logic 138 to generate a data object representing the gateway, such as a database table of construction metadata. The data objects representing multiple gateways are cross-referenced to establish a topology map based on the parameters of each gateway, which parameters may include, among others: cloud network user account name; cloud provider name; VPC name; gateway name; VPC region; sandbox IP address; gateway subnet identifier; gateway subnet CIDR; gateway zone; name of the associated cloud computing account; VPC identifier; VPC state; parent VPC name; VPC CIDR; etc. Similarly, construction metadata is also used to generate data objects representing each VPC object and each subnet object.
[0041] Additionally, to determine whether a connection within the network is between two transit gateways, the topology system logic 138 may utilize a separate API call to query the controller 102 for a list of all transit gateways. Thus, the topology system logic 138 is then able to determine whether a connection between the first gateway and the second gateway is between the two transit gateways. In some embodiments, as will be discussed below, connections between transit gateways and connections between branch gateways and transits may be visually represented in two different ways.
[0042] In addition to receiving fabric metadata from the controller 102, the topology system logic 138 may also receive network data from one or more gateways managed by the controller 102. For example, for each network packet, the network data may include, but is not limited to, the ingress interface, source IP address, destination IP address, IP protocol, UDP or TCP source port, UDP or TCP destination port, ICMP type and code, IP "service type", etc. In one embodiment, the network data may be transmitted from the gateway to the topology system logic 138 using an IP protocol (e.g., UDP). In some embodiments, the network data is collected and exported via the NetFlow network protocol.
[0043] To configure a gateway to transmit network data to topology system logic 138, topology system logic 138 may provide instructions to controller 102, which in turn provides instructions to each gateway managed by controller 102. These instructions provide the IP address of topology system logic 138, which is used as the IP address for addressing network data transmissions.
[0044] As will be discussed in detail below, the topology system logic 138 can generate a visualization platform including one or more interactive display screens. These display screens can include dashboards, topology maps, and network flow visualizations. In addition, the visualization platform can be configured to receive user input that causes filtering of the displayed data.
[0045] For example and still referring to Figure 1 , the topology system logic 138 can generate a topology map visualization of the connections linking the fabrics detected by the controller 102, which is illustrated by the fabric diagrams within the logical area 132 represented by cloud A 104 and cloud B 106. In addition, the topology system logic 138 can generate various graphical user interfaces (GUIs) that illustrate network traffic flows, traffic flow heat maps, packet captures, network health, link latency, encryption, firewalls, etc. of network traffic flowing between, to, and from fabrics managed by the controller 102, as illustrated by the second logical area 134.
[0046] Embodiments of the present disclosure provide numerous advantages over current systems that provide dashboards that illustrate controller parameters because current systems do not provide the ability to visualize connections between structures deployed across multiple cloud networks, resource states of multiple clouds and connections between resources, and network data flows through structures across multiple clouds. As an example, an enterprise network may utilize resources deployed in multiple cloud networks, and administrators of the enterprise network may desire to obtain a visualization of the status of all structures and connections associated with these resources. However, because the enterprise network spans multiple cloud networks, conventional systems are unable to provide such a solution. By only obtaining a textual representation of the status of each structure within a single cloud (e.g., through a command line interface), administrators cannot obtain a complete view of the structure of the entire enterprise network, the connections therebetween, and the status of each structure. In addition, detection of abnormal or malicious network traffic patterns may not be detected in the manner provided by current systems.
[0047] As used herein, a visualization (or visual display) of constructs, connections therebetween, and the state of each construct is referred to as a topology map. Current systems fail to provide topology maps across multiple cloud networks, and fail to allow administrators to search across multiple cloud networks, or to visualize how a change in the state of a construct or connection in a first cloud network affects the state of resources or connections in a second cloud network. In some embodiments, a topology map can automatically change as the state of a construct or connection changes, or automatically change upon receiving construct metadata updates in response to certain events (such as at periodic time intervals) (e.g., a "dynamic topology map").
[0048] In some embodiments, a network may be deployed across multiple cloud networks using multiple controllers to manage the operability of the network. In some such embodiments, each controller may collect information from the networks and fabrics it manages, and a single controller may obtain all such information, thereby enabling the visualization platform to provide visibility across a network (or networks) that spans multiple controllers.
[0049] refer to Figure 2A , an exemplary diagram of a logical representation of a controller 102 deployed within a cloud management system 100 is shown according to some embodiments. As noted above, the controller 102 can be a software instance deployed within a cloud network to help manage the operability of a configuration within multiple public cloud networks. According to this embodiment, the controller 102 can be configured with certain logic modules, including VPC gateway creation logic 200, communication interface logic 202, and data retrieval logic 204. The controller 102 can also include a routing table database 206.
[0050] In some embodiments, the gateway creation logic 200 performs operations to create a gateway within the VPC, including creating a virtual machine within the VPC, providing configuration data to the virtual machine, and prompting initialization of the gateway based on the configuration data. In one embodiment, the VPC gateway creation logic 200 starts a virtual machine in the VPC. EC2 instance. The virtual machine is started using a pre-configured virtual machine image published by the controller 102. In a specific embodiment, the virtual machine image is an Amazon Machine Image (AMI). When started, the virtual machine is able to receive and interpret instructions from the controller 102.
[0051] The communication interface logic 202 may be configured to communicate with the topology system logic 138 via an API. The controller 102 may receive queries from the topology system logic 138 via one or more API calls and respond with the requested data via the API.
[0052] The data retrieval logic 204 may be configured to access each fabric managed by the controller 102 and obtain fabric metadata therefrom. Alternatively or additionally, the data retrieval logic 204 may receive such fabric metadata transmitted (or "pushed") from the fabric without the controller 102 initiating one or more queries (e.g., API calls).
[0053] The routing table database 206 can store VPC routing table data. For example, the controller 102 can configure the VPC routing table associated with each VPC to establish a communication link (e.g., a logical connection) between a transit gateway and a cloud instance associated with a particular instance subnet. The VPC routing table is programmed to support communication links between different sources and destinations, such as on-premises computing devices, cloud instances within a particular instance subnet, etc. Therefore, the controller 102 obtains and stores information that reveals certain attributes of resources (e.g., structures such as gateways, subnets, VPCs, instances within VPCs, etc.) within the controller 102's authority and state information related to the connections (communication links) between these resources.
[0054] refer to Figure 2B, an exemplary diagram of a logical representation of a topology system logic 138 deployed within a cloud computing platform is shown according to some embodiments. The topology system logic 138 may be a software instance deployed using cloud computing resources 136 and configured to communicate with the controller 102 and each gateway managed by the controller 102. The topology system logic 138 is configured with certain logic modules, including a tag logic 208, a tag database 210, an interface generation logic 212, a communication interface logic 214, and a topology snapshot logic 216. In addition, the topology system logic 138 may include a snapshot database 218, a performance data DB 219, a construction metadata database 220, and a network data database 222. The performance data DB 219 may store certain data for filtering a network topology map, as described at least in reference below. Figure 5A-5B For example, performance data DB 219 may store data such as latency information between communicatively coupled gateways, as well as certain performance metrics of any applicable architecture, such as resource usage (eg, CPU, disk, memory).
[0055] In some embodiments, the tag logic 208, when executed by one or more processors, performs operations to generate tags and stores them in the tag database 210. In some embodiments, the topology snapshot logic 216, when executed by one or more processors, performs operations to obtain a snapshot (recorded data) of the current network topology state and stores it in the snapshot database 218. Additional details of the operations performed by the tag logic 208 and the topology snapshot logic 216 are discussed in U.S. Patent Application No. 17 / 127,920, filed on December 18, 2020, the entire contents of which are incorporated herein.
[0056] In some embodiments, the interface generation logic 212, when executed by one or more processors, performs the operations discussed below and results in the generation of the following: Figure 3 An exemplary interactive user interface is illustrated in A-7.
[0057] In some embodiments, the communication interface logic 214, when executed by one or more processors, performs operations as discussed herein with respect to querying the controller for construction metadata, receiving the requested construction metadata, and receiving network data from one or more gateways managed by the controller. In some embodiments, the received construction metadata and network data may be stored in a construction metadata database 220 and a network data database 222 (which may be separate or combined databases).
[0058] III. Example User Interface - Topology System Visualization Platform
[0059] Figure 3-5BThe exemplary user interface illustrated in FIG. 1 may be configured by the topology system logic 138 to be presented and displayed on various display screens and via various applications. For example, Figure 3-5B Each user interface illustrated in can be configured to be displayed on a computer display screen, laptop, mobile device or any other network device including a web browser through a web browser. In addition, Figure 3-5B Each of the user interfaces illustrated in the topology diagrams may be configured to be displayed by a dedicated software application that is installed and configured to execute on any of the network devices described above. For example, the topology system logic 138 may be configured to provide the data and user interfaces described herein to a software application (referred to in the art as an "app") that may be installed and configured to be executed by one or more processors of a network device. Thus, when executed, the app causes the user interfaces described herein to be presented on a display screen (or associated display screen) of the network device.
[0060] 1. Dashboard
[0061] Reference now Figure 3 , according to some embodiments, a graphical user interface (GUI) screen (or "interface screen") is shown that displays portions of a dashboard of a topology system visualization platform ("visualization platform"), wherein each portion is configured to illustrate information obtained or determined by a topology system. Figure 3 The interface screens may collectively include a “dashboard” 300 in conjunction with other interface screens as described in detail in U.S. patent application Ser. No. 17 / 127,920, filed Dec. 18, 2020, the entire contents of which are incorporated herein. Dashboard 300 displays various attributes related to a network deployed across one or more cloud providers, and in particular across multiple cloud providers.
[0062] For example, Figure 3 The dashboard 300 shown in FIG. 1 includes several display portions 302, 306, and 308. A navigation panel 304 is also shown as part of the visualization platform generated by the topology system logic 138. The display portion 302 displays information about the topology of the controller (e.g., Figure 1 The information displayed may include, but is not limited to, the number of deployed gateways, the number of current virtual private network (VPN) users, the number of user accounts, the number of transit gateways (TGWs), the number of network connections (optionally filtered by cloud computing service), the number of Border Gateway Protocol (BGP) connections, the number of active VPCs, the number of active regions, the number of instances, the connection status, etc.
[0063] Figure 3The display portion 306 of the dashboard 300 includes a list of virtual data centers that contain network resources (again, optionally across multiple cloud networks). Specifically, the display portion 306 includes a user input field (e.g., a check box) that is configured to receive user input that indicates how the content displayed by the dashboard 300 is to be used by one or more specific cloud networks (e.g., CLOUD (GCP), ORACLE CLOUD (OCI)) filtering. In some embodiments, a virtual data center is a pool of cloud computing resources that can be hosted on a public cloud.
[0064] In addition, display portion 308 illustrates a world map including a graphical representation (e.g., such as icon 309) of each virtual data center listed in display portion 306 and a location on the world map indicating its geographic location. Display portion 308 may be filtered according to a “filter by cloud” selection provided in display portion 306, and may be configured to receive user input to adjust the magnification of the map (e.g., “zoom in” or “zoom out”).
[0065] The navigation panel 304 includes links to each general visualization provided by the visualization platform including the dashboard 300, which is also described in detail in U.S. patent application Ser. No. 17 / 127,920, filed on December 18, 2020, the entire contents of which are incorporated herein.
[0066] 2. The process of building an elliptical layout of a topological network diagram
[0067] The following systems and methods provide user interactions to control the deployment functionality of cloud computing constructs through interface screens generated by the topology system logic 138. Current systems have several disadvantages, including providing difficult, complex, and unintuitive interfaces for building network topologies. Specifically, current systems do not provide a graphical user interface configured to receive user input that directly corresponds to deployment instructions when creating a network topology, wherein the network topology can be viewed as a network topology map that is created in real time when the user input is received. Current systems can provide a spider web-like network topology map layout; such a layout has several disadvantages. For example, the spider web-like layout is not scalable and viewable because the representation of the constructs and the connections therebetween becomes convoluted, making it impossible to visually understand the connections in a quick and concise manner. In addition, such a layout does not provide any easily perceived visual indications, either regarding the CSPs associated with the constructs or the layers associated with the constructs (see below). These are just a few of the disadvantages of the current system that are addressed by the systems and methods disclosed below.
[0068] Figures 4A-4Gis a series of interface screens that illustrate the process of building a network topology map using the Co-Pilot interface. Figures 4A-4G The technical improvements provided by the systems and methods of the present disclosure will become apparent when the present disclosure is completed. However, some technical improvements include, but are not limited to: providing a graphical user interface configured to receive user input, the user input directly corresponding to instructions that lead to building (e.g., generating) a network topology and its deployment; the graphical user interface is intuitive, which guides the user to build the network topology by providing step-by-step instructions (e.g., providing a single "select cloud region" button that leads to displaying additional user input (UI) elements "cloud provider", "access account", and "region") (see Figure 4A-4B ); providing visual indications of the placement of constructs within independent and different resources, within regions, and the connections between constructs provided by different cloud service providers (CSPs); providing an elliptical layout of a network topology map whose diameter is scalable and easily segmented by any of a variety of characteristics / parameters (such as CSP, region, account, etc.); providing a hierarchical elliptical layout of a network topology map so that constructs are placed within corresponding layers, allowing users, administrators, etc. to visualize each layer in a separate manner (examples of layers include: (i) transit VPCs and transit gateways, (ii) spoke VPCs and spoke gateways, (iii) subnets, (iv) VMs, etc.); providing visual adjustments to the elliptical layout of the network topology map to provide a visual indication of the size of each elliptical segment (for example, the size can be dynamically defined / selected to refer to various parameters, including geography, the number of constructs deployed therein, the percentage of total topology network traffic propagated by the construct within the segment, the size of the constructs, etc.); The invention also provides an elliptical layout for a network topology diagram, which is configured to visually aggregate certain segments (e.g., unselected segments, where a selected segment can be selected via user input for further investigation or viewing) and visually expand certain segments (e.g., selected segments); and provides an elliptical layout for a network topology diagram, which provides clear connections between constructions, where the connections span different layers and / or resources provided by different CSPs (e.g., visually illustrating that a first construction provided by a first CSP and deployed in a first cloud computing network is connected to a second construction provided by a second CSP and deployed in a second cloud computing network, where the first and second cloud computing networks are visually presented in different elliptical segments).
[0069] However, it should be understood that the elliptical layout is only one such geometric shape that has been contemplated. Other layout shapes contemplated include, but are not limited to, squares, rectangles, diamonds, pentagons, hexagons, octagons, trefoil shapes, and the like. It is also contemplated that the shape of the layout can be dynamically adjusted as the number of segments increases. For example, the topology system can be configured to generate a layout in a first shape when the network topology diagram includes a first number of segments, and adjust to a second shape when segments are added (e.g., a heptagon when the network topology diagram includes seven segments, and an octagon when the network topology diagram includes eight segments). However, as will be discussed below and illustrated in several figures, many embodiments relate to elliptical shapes (e.g., circles) in which the segments shrink or expand in size based on various factors, such as the number of structures deployed in association with each segment and / or the number of segments.
[0070] Reference now Figures 4A-4G According to some embodiments, an interface screen of a second embodiment of displaying a network topology map is shown, the interface screen including a process of constructing a network topology map through user input, and as an execution Figure 1 The distributed cloud computing system is populated with the result of the operation. Figure 4A , interface screen 400 is shown to include a "design" or "build" button (e.g., UI element) 401, which, when activated, is configured to cause the display / rendering of an oval layout building panel 402. Interface screen 400 may also include a navigation panel 403, which is similar to Figure 3 The navigation panel 304 of the system and method disclosed herein may include additional navigation options that provide access to (eg, cause such features to be displayed / presented). Figure 4A An initial interface screen showing the progress of building a network topology diagram with an elliptical layout ( Figure 5A-5B An exemplary network topology diagram having an oval layout is provided). The oval layout building panel 402 (panel 402) also includes a UI element 406, which, when activated by user input, provides a user or administrator (collectively referred to as "administrator") with the ability to select a cloud service provider (or simply "cloud provider"), access account, and region, such as Figure 4B as shown in .
[0071] Reference now Figure 4B, it is seen that interface screen 400 includes a panel 408 providing a plurality of UI elements, including a UI element 410 corresponding to selection of a cloud provider, a UI element 412 corresponding to selection of an access account (e.g., an account / user name corresponding to an account of the selected cloud provider), and a UI element 414 corresponding to selection of a region within the cloud resources of the selected cloud provider. Upon receiving user input indicating selection (or manual entry) of a cloud provider, access account, and region, panel 402 may be updated (revised or modified) to display cloud region annotations 416.
[0072] In some embodiments, after receiving user input corresponding to the selection of a cloud provider, selectable access accounts are populated for selection via UI element 412. In such embodiments, access account names may be stored for each cloud provider. In some cases, additional login criteria (e.g., passwords) may also be stored. However, in some cases, an administrator may be prompted to provide a password behind the access account section. Similarly, after receiving user input corresponding to the selection of an access account (and optionally, receiving additional login criteria), selectable areas may be populated for selection via UI element 414. Selectable areas may be stored for each cloud provider / access account.
[0073] Reference now Figure 4C , a third process of interface screens 400 is provided, which is configured to receive a selection of a configuration within the region selected during the second process, as described above with reference to Figure 4B discussed. Figure 4C The illustrated interface screen 400 may include a construct add panel 418 that includes a plurality of UI elements 420-432, each configured to receive user input corresponding to a particular parameter and / or feature of or associated with a construct. The panel 418 may display different UI elements that are configured to receive specific user input based on selection / activation of a layer-specific construct add button (e.g., buttons 446, 448). As will be discussed further below, upon activation, each layer-specific construct add button enables an administrator to add a construct to a particular layer within the oval layout of the topology network diagram (which corresponds to the deployment of the construct within a particular cloud region associated with a particular access account associated with a particular CSP).
[0074] Activation of button 446 results in an update to panel 402 to display a transit VPC / gateway icon 450 (e.g., a construction icon) on the display of the transit VPC / gateway layer 436 (discussed below) and panel 418. In some embodiments, the presentation of icon 450 represents a confirmation that the transit VPC / gateway has been deployed within the specified cloud region. Thus, the appearance of icon 450 can provide the administrator with a confirmation that the corresponding construction has been deployed and is operating correctly. However, in other embodiments. The construction corresponding to the icon placed in the network topology map can be deployed after receiving user input activating a particular button (or another UI element), such as a "Save" button 411. In some cases, receiving user input activating a particular button (or other UI element), such as a "Cancel" button 413, can result in the deletion of the network topology map (or editing since the last save action), or can prompt the administrator to save the network topology map for further editing or deployment at a subsequent time. In another alternative embodiment, activation of a particular button (or another UI element), such as a "Generate Script" button 581 ( Figure 4G ) can initiate the automatic generation of a script that, when executed, deploys the topology network. In some such embodiments, the script can be executed in a manner such as The script can be provided in any known programming language.
[0075] Figure 4C The UI elements displayed in panel 418 correspond to the addition of a transit VPC and gateway, which corresponds to the activation of button 448. UI element 420 is configured to receive user input corresponding to the selection of a transit VPC and gateway (or the creation of a new transit VPC and gateway). In some embodiments, the user elements provided in panel 418 may be pre-populated with user input previously generated in the same CSP region and corresponding to the user input in panel 408 ( Figure 4B ) associated with the same access account entered in the .
[0076] After selecting a transit VPC / gateway, the administrator can select an encryption mode including multiple tunnels for extending to / from the selected transit VPC / gateway via UI element 422. Details regarding the multiple tunnel encryption mode can be found in U.S. Patent Application No. 16 / 403,353 filed on May 3, 2019, the entire contents of which are incorporated herein.
[0077] In addition, UI element 424 is configured to receive user input corresponding to a subnet selection, UI element 426 is configured to receive user input corresponding to whether to allocate a new elastic Internet Protocol (EIP) address (and to which EIP to assign the transit gateway), UI element 428 is configured to receive user input corresponding to a gateway name selection, UI element 430 is configured to receive user input corresponding to a gateway size, and UI element 432 is configured to receive user input corresponding to a transit gateway high availability feature selection. Details regarding the high availability feature (or "active-active" feature) can be found in U.S. patent application Ser. No. 17 / 216,596, filed on March 29, 2021, the entire contents of which are incorporated herein. For further discussion of UI elements 424-432, refer at least to Figure 4D-4G Find out below.
[0078] Reference now Figure 4D , a fourth process of the interface screen 400 is provided. Figures 4A-4C Many of the Figure 4D For the purpose of clarity, some reference numerals are used in Figure 4D 4. After receiving user input corresponding to adding a transit VPC / gateway (represented by icon 450) and user input to panel 418, in particular selecting a transit VPC / gateway via UI element 420, UI element 424 may be populated with possible subnets corresponding to the transit VPC / gateway selected in UI element 420.
[0079] Figure 4D The receipt of user input representing the selection of subnet "192.2.128.0 / 28" to UI element 424 is illustrated, which also results in an update to panel 402, providing an icon 452 representing subnet "192.2.128.0 / 28" on the subnet layer and an edge 454 illustrating the coupling between the selected VPC / gateway and subnet "192.2.128.0 / 28". In addition, Figure 4D Receipt of user input to UI element 428 is illustrated, corresponding to selection of a gateway to be deployed within subnet “192.2.128.0 / 28,” and such user input results in an update of panel 402 to include icon 456 and edge 458 extending from subnet “192.2.128.0 / 28” to gateway icon 456 .
[0080] Reference now Figure 4E, a fifth progression of interface screens 400 is provided, which illustrates receiving user input selecting a “high availability” feature of a gateway selected via UI element 428. Specifically, UI element 432 is illustrated as being activated, indicating selection of the “high availability” feature, which results in an update to panel 402 to include a gateway icon 460, which in this embodiment is annotated with “ha” indicating high availability. Figure 4E Also illustrated is user input to UI element 430, which corresponds to the selection of a gateway size selected via UI element 428. Additionally, panel 418 may be updated to provide UI element 462 configured to receive user input corresponding to a subnet of a high availability gateway. The corresponding subnet is in Figure 4E 464, where edge 466 illustrates the connection from transit VPC / gateway icon 450 to subnet icon 464. High availability gateway icon 460 is shown connected to subnet icon 464 via edge 468. As discussed above, the icons of panel 402 illustrate configurations deployed within a cloud computing environment.
[0081] Figure 4E Panel 814 of also illustrates a user element 433, which is configured to receive user input, resulting in the generation of a window (eg, a pop-up) providing the user with the ability to establish a transfer peer (see Figures 4H-4I ). As noted above, transit peering refers to the communication coupling between transit gateways. Figures 4H-4I As discussed, user input selecting the transit peer option enables the user to select a previously deployed (and currently active / deployed) transit gateway with which to establish a communicative coupling with a transit gateway currently being deployed (eg, the transit gateway represented by icon 450).
[0082] Reference now Figure 4F , a sixth progression of interface screens 400 is provided, which illustrates receiving user input to add a branch gateway to the network topology map via UI element 448. Such user input corresponds to the above-discussed (e.g., at least Figure 4B ) within the selected cloud region of the branch gateway. The addition of a branch gateway follows the same process as adding a transit VPC / gateway discussed above. In particular, upon receiving user input activating UI element 448, panel 418 is updated to illustrate UI elements 466-480, which represent parameters or functions of the branch gateway, which correspond to the parameters or functions of the transit VPC / gateway (e.g., UI elements 420-432, 462), and therefore there is no need to repeat this discussion. This user input results in the addition of a branch gateway icon 464 within the selected cloud region discussed above.
[0083] Reference now Figure 4G, provides a seventh process of interface screen 400, which shows receiving user input, the user input assigning a subnet to Figure 4F The branch gateway of Figure 4E ) is associated with a branch gateway and connects the branch gateway to the transit VPC / gateway discussed above. As illustrated, user input received by UI elements 468-480 results in the addition of subnet icon 482, edge 484, gateway icon 486, and edges 488-490. In addition, Figure 4A The oval layout includes specific layers (or rings) for various configurations with layers. Each of the icons 482-490 (including edges) appears in a corresponding layer, or connects icons in two corresponding layers.
[0084] Reference now Figure 4H , an optional addition to the user interface 400 that enables the establishment of a transfer peer is shown according to some embodiments. The content window 435 may be displayed as an example. Figures 4A-4G 443 or cancel button 445, at which point the display returns to the network topology map. Alternatively, content window 435 may be a "pop-up" window that appears in front of the network topology map. Content window 435 includes a first list 437, which is a list of transit gateways that can be used to establish a transit peer with the selected transit gateway (e.g., represented by icon 450 and listed in UI field 420 of panel 418, as shown in FIG. 444). Figure 4E 4). Additionally, content window 435 includes a second list 439, which is a list of transit gateways with which the selected transit gateway has established a communicative coupling. In other words, first list 437 provides a list of transit gateways available for transit peering with the gateway selected via panel 418 ("transit gateways 450," which reference icon 450), and second list 439 provides a list of transit gateways with which transit gateway 450 has established a transit peering.
[0085] The transit gateway (or gateways) appearing in the first list 437 can be selected (e.g., directly clicked or the box to the left of the transit gateway name can be selected) and button 441A is activated. The selected gateway (or gateways) then appear in the second list 439. The transit gateways appearing on the second list 439 can be removed from the list by selecting the transit gateway and activating button 441B. Upon receiving user input selecting the "Save" button 443 (or similar UI element), moving the selected transit gateway from the first list 437 to the second list 439 will result in establishing a communication coupling between the selected transit gateway and the transit gateway 450. Moving the selected transit gateway from the second list 439 to the first list 437 will result in the termination of the communication coupling between the selected transit gateway and the transit gateway 450. Transit peering can be established or terminated by programming (or reprogramming) the corresponding routing table by the controller that has deployed and is now managing the two transit gateways. As noted, the changes can take effect when the save button 443 is selected.
[0086] refer to Fig. 4I , according to some embodiments, a user interface 400 is shown after a transit peer is established. Fig. 4I The diagram shows the deployment Figure 4E 447 and edge 451, which indicates that transit gateway 450 is involved in a transit peer with at least one other transit gateway. Icon 449 specifies the number of transit gateways with which transit gateway 450 is involved in a transit peer. In some cases, the user can directly access content window 435 ( Figure 4H ).
[0087] therefore, Figures 4A-4I A method technique is illustrated by which an administrator can build a network topology by building a network topology map via an intuitive user interface. In some embodiments, the structures that make up the network topology can be deployed after user input to add specific structures (e.g., add Figure 4C 402 ), so that the presentation of the corresponding icon (e.g., icon 450) confirms to the administrator that the configuration is deployed for normal operation. Alternatively, the configuration (or configurations) corresponding to the icons (or configurations) placed on panel 402 may be deployed upon receiving user input activating a particular UI element (e.g., a “Save” button represented by UI element 411). In yet other embodiments, activating a particular UI element (e.g., a “Save” button represented by UI element 411) may cause the administrator to be deployed to the configuration. Figure 4G User input (represented by a “Generate Script” button) in UI element 481 may initiate generation of a script that, when executed, results in deployment of the constructs and connections included in the network topology diagram.
[0088] although Figures 4A-4IThe deployment of a construct in a single cloud region provided by a single CSP is illustrated, but additional cloud regions provided by other CSPs may be selected (added to the cloud computing environment in which the network topology is deployed). As a result, user interface 400 enables an administrator to create a network topology that spans cloud resources provided by multiple CSPs, and also allows the administrator to connect a particular construct deployed in a first cloud region provided by a first CSP to a particular construct deployed in a second cloud region provided by a second CSP. In addition, it should be understood that multiple constructs may be added before any construct is deployed. For example, Figure 4C-4E An example of adding a transit VPC / gateway and corresponding subnet / virtual machine instance (with high availability) is illustrated. The process of adding a transit VPC / gateway and corresponding subnet / virtual machine instance (with or without high availability) can be repeated multiple times before deploying any added structures.
[0089] refer to Figure 5A-5B According to some embodiments, the display Figures 4A-4G An interface screen of an example network topology diagram for monitoring network topology constructed using the method technology illustrated in FIG. Figure 5A An interface screen 500 is provided that illustrates a network topology map 504 displayed on a display panel 502, and also includes a navigation panel 503 similar to the navigation panel 401. The topology map 504 includes a plurality of segments, wherein each segment represents a cloud region of cloud computing resources provided by a particular CSP. Segment 506 is a segment representing a first region of cloud computing resources provided by a first CSP (e.g., CloudInfrastructure (OCI) provided by the West region, segment 508 1 -508 3 is a segment representing three regions of cloud computing resources provided by a second CSP (e.g., provided by AMAZON WEB The segment 510 is a first region of cloud computing resources provided by a third CSP (e.g., North, West, and East regions provided by AWS). In addition, a plurality of edges 512 are shown, which represent communication paths between transit VPCs of the network topology represented by topology diagram 504. In some embodiments, edges 512 can provide a visual representation of the latency across edges 512. In some embodiments, the visual representation can be colored, such that the color of the edge depends on the latency of network traffic propagating between two corresponding transit VPCs. However, color is only one such distinction. Therefore, Figure 5A-5B It is illustrated that the methods, techniques, and systems described herein can be used to construct a network topology map that spans cloud computing resources provided by multiple CSPs.
[0090] Figure 5A Also included is a filter panel 518 that allows an administrator to filter the topology map 504 to illustrate certain aspects or configurations (or exclude them from display). For example, the filter panel 518 includes UI elements 522-528 that are configured to receive user input indicating a filter to be applied to aspects or configurations of the topology map 504 to be displayed. For example, UI element 522 represents a latency filter that is configured to receive user input indicating a latency metric (e.g., a number of seconds) that is used to filter the configurations displayed in the topology map 504 (e.g., only displaying configurations with a latency greater than or equal to the latency metric, or vice versa).
[0091] UI element 524 represents a gateway high availability filter configured to receive user input indicating whether to filter the gateways displayed in topology map 504 (and optionally any constructs in outer layers connected to such gateways) based on whether the gateways implement high availability functionality.
[0092] Reference now Figure 5B , UI element 526 represents various filters, such as name (of fabric, CSP, region, etc.), audit status (e.g., the state of the cloud access account that enables the controller deployed and configured to manage the fabric is valid (which can mean being properly logged in and authenticated), including correct permissions), instance size, instance state ("active / inactive" or "up / down"), tags, CPU usage, etc. As with UI elements 522-524, UI element 526 and its child elements 530 are configured to receive user input, which results in filtering of displayed aspects and / or fabrics of topology map 504. Figure 5B It is also illustrated that additional sub-elements can be added to sub-element 530 (e.g., filtering based on a text search, similar to filtering by name, filtering by adding tags to constructs discussed in U.S. patent application Ser. No. 17 / 127,920, filed on Dec. 18, 2020, the entire contents of which are incorporated herein, and / or selecting sub-elements from a pre-populated list, such as any network metric). UI element 528 represents an unmanaged VPC filter, such that when activated, all constructs except unmanaged VPCs can be filtered out (or vice versa).
[0093] It should be noted that discussion of filtering of aspects or configurations of topological map 504 may refer to: removing certain aspects or configurations from topological map 504; visual changes to certain aspects or configurations to be filtered out (e.g., a reduction in size, a change in opacity, a change in color, such as a change in grayscale, etc.); and / or visual changes to certain aspects or configurations that are not filtered out (e.g., an increase in size, emphasis via bold or underlining, an elevation in the view where such aspects or configurations appear to be closer to the viewer than certain aspects or configurations to be filtered out, etc.).
[0094] Figure 5A-5B Also illustrated is the aggregation feature of the oval layout topology diagram 504. Branch gateway icon 532 ( Figure 5A ) includes an aggregate icon ("10") indicating that the branch gateway icon 532 may be expanded to illustrate additional structures connected thereto, such as Figure 5B Specifically, Figure 5B As shown in , the branch gateway icon 532 has been expanded to display ten icons consistent with the "10" symbol of the aggregate icon: two branch gateways 536, three subnets 538, and five edge devices 540. In addition, Figure 5B The figure shows that in some embodiments, when an icon including an aggregate icon is expanded, other structures can be aggregated into a single icon with an aggregate icon (e.g., Figure 5A The subnet and edge devices shown in the figure are Figure 5B shown in an aggregated state).
[0095] The aggregation feature provided by the oval layout provides great advantages in improving the scalability of the interface screen to accommodate and intuitively display a topology diagram including a large number of structures in a single display. For example, zooming can be performed by aggregation and expansion of structure icons, for example, structures derived from branch gateways can be aggregated into a single branch gateway icon, which includes a symbol indicating icon aggregation (i.e., a bubble number), as shown.
[0096] The aggregation feature provides the ability to aggregate icons into a single icon with an aggregation symbol in various scenarios. For example, when the number of structures within a single cloud region exceeds a threshold, one or more branch gateways (and the outer structures connected to them) can be aggregated. The order in which the branch gateways are aggregated can be based on a predefined set of rules (for example, branch gateways can be aggregated based on: (i) the number of structures connected to them, starting with the largest number first; (ii) the time since instantiation, starting with the oldest, etc.). When the number of structures within the cloud region no longer exceeds the threshold, or based on user input indicating expansion, the expansion of the aggregation can occur automatically (in response, other gateways can be aggregated). In some embodiments, multiple branch gateways can be aggregated into a single aggregate icon (for example, when a cloud region is selected for inspection, the size of the selected cloud region can be increased, while the size of the unselected region can be reduced, where the gateways are aggregated individually or as multiple gateways). Note that the transit gateways and the structures connected to them can be aggregated in the same manner as discussed herein for the branch gateways.
[0097] Likewise Figures 4A-5B As illustrated in , each cloud region can be illustrated as a different slice within the oval layout, and visual distinctions can be included between cloud regions. In addition, cloud regions provided by the same CSP can be illustrated in a visually similar manner and different from cloud regions provided by other CSPs, which provides a quick visual indication of the regions according to the CSP (e.g., each CSP is associated with a specific color and / or CSP specific icon graphic).
[0098] In some embodiments, segments can be adjusted in size (e.g., based on the percentage of network resources deployed in the area, the percentage of network traffic flowing through the area, etc.), where the size can be adjusted automatically, such as after a fabric is added to one or more areas. Alternatively or additionally, the size can be adjusted at a time interval (e.g., every 2 minutes) after the network traffic flow is calculated. In some cases, the size of a segment can be adjusted when the change in the fabric percentage or the network traffic flow percentage exceeds a change threshold (e.g., a 10% change).
[0099] The monitoring capabilities provided by the oval layout of topology map 504 enable administrators to easily and directly Figure 5A-5B The user can perform troubleshooting operations within the interface screen of the network topology, which can include adding a fabric to the network topology via the interface screen, restarting a fabric via the interface screen, viewing latency between fabrics (e.g., gateways), etc. In some embodiments, selecting a fabric can provide additional details about these troubleshooting operations, for example, enabling specific actions to be taken, such as viewing latency between two selected gateways or restarting a fabric.
[0100] IV. Logical Flow
[0101] Reference now Figure 6 , a first flow chart of an exemplary method of communication between topology system logic, a controller, and one or more network fabrics deployed by the controller is shown according to some embodiments. Figure 6 Each block illustrated in represents an operation performed in method 600 of automatically generating a network topology by a controller in response to user input received by a graphical user interface generated by topology system logic.
[0102] When topological system logic (such as Figure 1 The method 600 is initiated when the topology system logic 138 of the system generates a graphical user interface and causes the presentation of the graphical user interface, the graphical user interface being configured to receive user input indicating a selection of a first cloud service provider, a first access account associated with the first cloud service provider, and a first cloud region of cloud computing resources of the first cloud service provider (block 602). As discussed above, a graphical user interface configured to receive such user input may include a display and a panel including several UI elements configured to receive specific user input (e.g., Figure 4A-4B ).
[0103] The method 600 continues as follows: the topology system logic updates the graphical user to display a first elliptical segment representing a first cloud region of a first CSP associated with a first access account (block 604). Figure 4C-5B As illustrated in , the elliptical layout of the network topology diagram may refer to a circular layout, where the first elliptical segment may be a first circular segment (eg, a "pie slice"). However, alternative shapes have been contemplated and are intended to be within the scope of the present disclosure.
[0104] The method 600 may then receive additional user input through a graphical user interface indicating a selection of one or more network configurations to be deployed in the first cloud region (block 606). The one or more network configurations may include, but are not limited to, transit gateways, branch gateways, subnets, private networks (VPC, VNET, etc.), firewalls, etc.
[0105] The method 600 continues as follows: the topology system logic updates the graphical user to display one or more network configurations at least partially within the first oval segment representing the first cloud region (block 608). As detailed above, various icons represent one or more network configurations and may be displayed within the first segment and / or on the edges of the first oval segment. In addition, the icons placed on or within the first oval segment may be arranged in a hierarchical configuration to facilitate visualization and improve scalability of the oval layout as detailed above.
[0106] The method 600 also includes an operation in which the topology system logic instructs the controller to deploy one or more network configurations in the first cloud region based on the first user input and the second user input (block 610). The topology system logic is communicatively coupled to the controller and can transmit such instructions. The topology system logic generating the instructions can be responsive to receiving additional user input indicating that the administrator desires to deploy the network topology map as a fully operational network topology.
[0107] In addition, additional user input may be received indicating that a subsequent oval segment is to be added to the oval layout. For example, after receiving user input that results in the generation of the first oval segment described above and the deployment of the indicated network configuration, the graphical user interface may receive subsequent user input corresponding to the selection of a second CSP for cloud computing resources provided by a second CSP, a second access account, and a second cloud region, and a second set of network configurations to be deployed within the second cloud region. As a result, the topology system logic may update the oval layout by adding a second oval segment including an icon representing the second set of network configurations, and deploy it.
[0108] In addition, the user input received by the topology system logic and the above Figure 6 The operations discussed include indications of how each construct is communicatively coupled to the other constructs (e.g., communicatively coupling of gateways operating within a virtual environment (e.g., a VPC), where coupling between two gateways both operating within a transit VPC may be referred to as "transit peering," and coupling between a gateway operating within a transit VPC and a gateway operating within a spoke VPC may be referred to as association of a spoke gateway with a transit gateway).
[0109] In addition to the disclosure of systems and methods for generating a network topology map based on user input and automatically generating a network topology by deploying network structures in a specific cloud region of cloud computing resources provided by a CSP, the systems and methods disclosed herein also provide a system for automatically generating a network topology map based on user input and automatically generating a network topology by deploying network structures in a specific cloud region of cloud computing resources provided by a CSP, and the system and method ... Figure 5A-5B ) to monitor the network topology.
[0110] In some embodiments, the network topology may have been generated by means other than via the graphical user interface described herein, and the graphical user interface is implemented for monitoring and troubleshooting purposes. Figure 7 The method technology provides a logical flow of operations performed by the topology system logic, which enables an administrator to monitor the network topology through the graphical user interface described in this article, especially the oval layout described in this article.
[0111] Reference now Figure 7, a second flow chart illustrating an exemplary method of communication between topology system logic, a controller, and one or more gateways managed by the controller, according to some embodiments.
[0112] Figure 7 Each box illustrated in FIG. 7 represents an operation performed in method 700, which is to exchange communications with a controller and receive data from one or more gateways managed by the controller. Before method 700 is initiated, it can be assumed that a gateway such as Figure 1 The distributed cloud management system shown in FIG. Figure 1 The topology system logic 138) sends a signal to a controller (such as Figure 1 When the controller 102 of the topology system 100 queries the construction metadata, the method 700 is initiated (block 702). As discussed above, the query can be via one or more API calls. Subsequently, the topology system logic 138 receives the requested construction metadata and stores the received data in a database, such as Figure 2B The metadata database 220 is constructed (block 704).
[0113] In addition, the topology system logic receives network data from one or more gateways managed by the controller (block 706). The topology system logic continues to store the received network data in a database, such as Figure 2B The network data database 222.
[0114] After receiving the construction metadata and network data, the topology system logic generates one or more visualizations based on the received data (block 708). Exemplary visualizations that may be generated are shown in FIG. Figures 4A-5B ; however, the visualizations that can be generated by the topology system logic are not limited to those illustrated.
[0115] The topology system logic disclosed herein can perform additional operations, such as receiving user input to mark certain aspects and / or structures of the network topology map, and / or operations to search and / or filter the display of the network topology map based on the marked aspects or structures. In addition, the topology system logic disclosed herein can perform operations related to recording the state of the network topology at time intervals and provide a replay function, where an administrator can compare topologies at different times for troubleshooting (for example, determine what changes have occurred within the topology in order to determine possible reasons for an increase in latency values or a failure to transmit network traffic to certain structures, etc.). Further details regarding marking and searching operations and replay operations are discussed in U.S. patent application No. 17 / 127,920 filed on December 18, 2020, the entire contents of which are incorporated herein.
[0116] In the foregoing description, the invention has been described with reference to specific exemplary embodiments thereof. It will, however, be evident that various modifications and changes may be made thereto without departing from the broader spirit and scope of the invention as set forth in the appended claims.
Claims
1. The distributed cloud computing system according to claim 1, wherein: The logic, when executed by one or more processors, causes the execution of further operations, including: a controller configured to deploy a first gateway in a first cloud computing network and to deploy a second gateway in a second cloud computing network; and Logic stored on a non-transitory computer medium, which, when executed by one or more processors, results in the performance of operations including: obtaining metadata associated with each of the first gateway and the second gateway from the controller, obtaining network data from each of the first gateway and the second gateway, wherein the combination of the metadata and the network data identifies each of the plurality of fabrics, a communication path between each of the fabrics, and in which cloud computing network each of the fabrics is deployed, generating an oval layout of a network topology diagram, the diagram of which includes a first segment including a first gateway representing a deployment in a first cloud network and a second segment including a second gateway representing a deployment in a second cloud computing network, and Causes the visualization to be rendered on a display screen of the network device.
2. The distributed cloud computing system according to claim 1, wherein: The first private network is communicatively coupled to the first gateway and deployed within a subnet of the first cloud computing network, and the second private network is communicatively coupled to the second gateway and deployed within a subnet of the second cloud computing network.
3. The distributed cloud computing system according to claim 2, wherein: The first private network and the second private network are any of a virtual private cloud (VPC) or a virtual network (VNET).
4. The distributed cloud computing system according to claim 1, wherein: The logic, when executed by one or more processors, causes the execution of further operations, including: determining a delay value of a first communication path between the first gateway and the second gateway, and Wherein the visualization includes a presentation of the first communication path that provides a visual indication of a latency value.
5. The distributed cloud computing system according to claim 1, wherein: Each of the plurality of structures is one of a transit gateway, a subnet, or a private network or a firewall.
6. The distributed cloud computing system according to claim 1, wherein: The logic, when executed by one or more processors, causes the execution of further operations, including: receiving user input corresponding to a selection of a first configuration of the plurality of configurations, and The visual presentation is updated to illustrate the parameters of the selected configuration.
7. The distributed cloud computing system according to claim 6, wherein: The parameters of the selected first construction include one or more of the following: a name of the selected first construction, whether the selected first construction is encrypted, a cloud provider corresponding to the selected first construction, a gateway name associated with the selected first construction, a virtual private cloud (VPC) identifier associated with the selected first construction, the VPC region of the selected first construction, or whether the selected first construction is a transit VPC.
8. The distributed cloud computing system according to claim 6, wherein: The logic, when executed by one or more processors, causes the execution of further operations, including: In response to receiving user input corresponding to a selection of a first construct, and wherein the first construct is an aggregate construct, updating the visual presentation to expand the aggregate construct to display each construct included within the aggregate construct.
9. A computerized method for notifying a user of a network topology, the computerized method comprising: obtaining metadata associated with each of a first gateway and a second gateway from a controller, wherein the controller is configured to deploy the first gateway in a first cloud computing network and to deploy the second gateway in a second cloud computing network; obtaining network data from each of the first gateway and the second gateway, wherein the combination of the metadata and the network data identifies each of the plurality of fabrics, a communication path between each of the fabrics, and in which cloud computing network each of the fabrics is deployed, generating an oval layout of a network topology diagram, the diagram of which includes a first segment including a first gateway representing a deployment in a first cloud network and a second segment including a second gateway representing a deployment in a second cloud computing network, and Causes the visualization to be rendered on a display screen of the network device.
10. The computerized method of claim 9, wherein: The first private network is communicatively coupled to the first gateway and deployed within a subnet of the first cloud computing network, and the second private network is communicatively coupled to the second gateway and deployed within a subnet of the second cloud computing network.
11. The computerized method of claim 10, wherein: The first private network and the second private network are any of a virtual private cloud (VPC) or a virtual network (VNET).
12. The computerized method of claim 9, further comprising: determining a delay value of a first communication path between the first gateway and the second gateway, and Wherein the visualization includes a presentation of the first communication path that provides a visual indication of a latency value.
13. The computerized method of claim 9, wherein: Each of the plurality of structures is one of a transit gateway, a subnet, or a private network or a firewall.
14. The computerized method of claim 9, further comprising: receiving user input corresponding to a selection of a first configuration of the plurality of configurations, and The visual presentation is updated to illustrate the parameters of the selected configuration.
15. The computerized method of claim 14, wherein: The parameters of the selected first construction include one or more of the following: a name of the selected first construction, whether the selected first construction is encrypted, a cloud provider corresponding to the selected first construction, a gateway name associated with the selected first construction, a virtual private cloud (VPC) identifier associated with the selected first construction, the VPC region of the selected first construction, or whether the selected first construction is a transit VPC.
16. The computerized method of claim 14, further comprising: In response to receiving user input corresponding to a selection of a first construct, and wherein the first construct is an aggregate construct, updating the visual presentation to expand the aggregate construct to display each construct included within the aggregate construct.
17. A non-transitory computer readable medium having stored thereon logic that, when executed by one or more processors, results in operations comprising: obtaining metadata associated with each of a first gateway and a second gateway from a controller, wherein the controller is configured to deploy the first gateway in a first cloud computing network and to deploy the second gateway in a second cloud computing network; obtaining network data from each of the first gateway and the second gateway, wherein the combination of the metadata and the network data identifies each of the plurality of fabrics, a communication path between each of the fabrics, and in which cloud computing network each of the fabrics is deployed, generating an oval layout of a network topology diagram, the diagram of which includes a first segment including a first gateway representing a deployment in a first cloud network and a second segment including a second gateway representing a deployment in a second cloud computing network, and Causes the visualization to be rendered on a display screen of the network device.
18. The non-transitory computer readable medium of claim 17, wherein: The first private network is communicatively coupled to the first gateway and deployed in a subnet of the first cloud computing network, and the second private network is communicatively coupled to the second gateway and deployed in a subnet of the second cloud computing network, and the first private network and the second private network are either a virtual private cloud (VPC) or a virtual network (VNET).
19. The non-transitory computer readable medium of claim 17, further comprising: determining a delay value of a first communication path between the first gateway and the second gateway, and Wherein the visualization includes a presentation of the first communication path that provides a visual indication of a latency value.
20. The non-transitory computer readable medium of claim 17, wherein: Each of the plurality of structures is one of a transit gateway, a subnet, or a private network or a firewall.
21. The non-transitory computer readable medium of claim 17, further comprising: receiving user input corresponding to a selection of a first configuration of the plurality of configurations, and The visual presentation is updated to illustrate the parameters of the selected configuration.
22. The non-transitory computer readable medium of claim 21, wherein: The parameters of the selected first construction include one or more of the following: a name of the selected first construction, whether the selected first construction is encrypted, a cloud provider corresponding to the selected first construction, a gateway name associated with the selected first construction, a virtual private cloud (VPC) identifier associated with the selected first construction, the VPC region of the selected first construction, or whether the selected first construction is a transit VPC.
23. The non-transitory computer readable medium of claim 21 , further comprising: In response to receiving user input corresponding to a selection of a first construct, and wherein the first construct is an aggregate construct, updating the visual presentation to expand the aggregate construct to display each construct included within the aggregate construct.
Citation Information
Patent Citations
Systems and methods for improving packet forwarding throughput for encapsulated tunnels
US10958620B1
System, method and apparatus for generating and searching a topology of resources among multiple cloud computing environments
US11671337B2
Systems and methods for firewall deployment in a cloud computing environment
US12231404B1