Multi-gateway fusion method and device, computer program product and electronic equipment
By virtualizing the server's physical network card, multiple virtual network cards are generated and communicated with multiple gateway devices, the problem of only one gateway service can be run on a single network card server, and the deployment of multi-gateway services and efficient resource utilization are realized.
Patent Information
- Application Number
- CN202510279706.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-13
AI Technical Summary
In gateway devices using DPDK technology, after the server's PCI device is bound to the DPDK application process, other processes cannot use this PCI device, resulting in only one gateway service running on a single network card server, resulting in wasting physical resources.
By virtualizing the physical network cards of the host server, multiple virtual network cards are generated, and these virtual network cards are communicated and connected with different devices to be integrated to isolate the traffic of each gateway to be integrated. Then, multiple virtual network cards are bridged to the virtual switch to realize service traffic communication between the multiple virtual network cards and the physical network cards.
It realizes the deployment of multiple gateway services on the same physical server, improves the physical resource utilization rate of the physical server, and ensures the network forwarding performance of the gateway services.
Smart Images

Figure CN120151201A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of network services, and more particularly, to a multi-gateway fusion method, a multi-gateway fusion device, a computer program product, and an electronic device. Background Art
[0002] With the continuous development of network service technologies, the technical implementation of gateway devices in the virtual network of the cloud computing industry is also constantly iterating and innovating to improve the forwarding performance of gateway devices. Among them, the DPDK (Data Plane Development Kit) technology, a set of function libraries and drivers for fast packet processing, can greatly improve data processing performance and throughput, and improve the working efficiency of data plane applications.
[0003] However, although the DPDK technology can directly send the packets received by the network card to the application program in the user space and bypass the Linux kernel protocol stack, it is necessary to bind the PCI (Peripheral Component Interconnect, a high-speed serial computer expansion bus standard) device of the server and the DPDK application process. After binding, other processes cannot use this PCI device, resulting in generally only one gateway service running on a single network card server, which causes a great waste of physical resources in scenarios with a small cluster scale.
[0004] It should be noted that the information invented in the above background art section is only used to enhance the understanding of the background of the present disclosure, and thus may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0005] The purpose of the present disclosure is to provide a multi-gateway fusion method, a multi-gateway fusion device, a computer program product, and an electronic device, so as to deploy multiple gateway services on the same physical server and improve the utilization rate of physical resources of the physical server.
[0006] Other features and advantages of the present disclosure will become apparent through the following detailed description, or be learned in part through the practice of the present disclosure.
[0007] According to one aspect of the present disclosure, there is provided a multi-gateway fusion method, including: virtualizing a physical network card corresponding to a host server to obtain a plurality of virtual network cards of the physical network card, and respectively communicatively connecting the plurality of virtual network cards with different gateway devices to be fused to isolate the traffic of each gateway device to be fused; bridging the plurality of virtual network cards to a virtual switch, and implementing service traffic communication between the plurality of virtual network cards and the physical network card through the virtual switch.
[0008] In an exemplary embodiment of the present disclosure, virtualization processing is performed on the physical network cards corresponding to the host server to obtain multiple virtual network cards of the physical network cards, including: creating multiple Peripheral Component Interconnect Express (PCI-E) virtual devices of the physical network cards to obtain multiple virtual network cards, and determining the Media Access Control (MAC) address corresponding to each virtual network card; allocating the multiple virtual network cards to different gateway devices to be fused and binding them to enable communication connections between the multiple virtual network cards and different gateway devices to be fused respectively; wherein, the unique identification information of the gateway device to be fused is bound to the corresponding virtual network card.
[0009] In an exemplary embodiment of the present disclosure, allocating the multiple virtual network cards to different gateway devices to be fused and binding them to enable communication connections between the multiple virtual network cards and different gateway devices to be fused respectively includes: allocating at least one group of virtual network card pairs to each gateway device to be fused, and the virtual network cards in the virtual network card pair are respectively used for receiving service traffic data and sending service traffic data.
[0010] In an exemplary embodiment of the present disclosure, determining the Media Access Control (MAC) address corresponding to each virtual network card includes: generating the virtual MAC address corresponding to each virtual network card based on the MAC address information of the physical network card; determining the corresponding relationship between the MAC address information of the physical network card and each virtual MAC address.
[0011] In an exemplary embodiment of the present disclosure, before bridging the multiple virtual network cards to a virtual switch, the method further includes: performing link aggregation processing on at least two physical network cards of the host server to obtain a link aggregation port; performing virtualization processing on the physical network cards corresponding to the host server to obtain multiple virtual network cards of the physical network cards, including: creating multiple virtual network cards by using the link aggregation port.
[0012] In an exemplary embodiment of the present disclosure, bridging the multiple virtual network cards to a virtual switch and implementing service traffic communication between the multiple virtual network cards and the physical network cards through the virtual switch includes: obtaining a first data packet transmitted by the link aggregation port, and distributing the first data packet to the corresponding physical network card; for each physical network card, parsing the received data packet through the physical network card to obtain the destination MAC address, so as to match the forwarding rule based on the destination MAC address through the virtual switch, and forwarding the received data packet to the corresponding target virtual network card according to the matching result.
[0013] In an exemplary embodiment of the present disclosure, a plurality of virtual network cards are respectively communicatively connected to different gateway devices to be fused to isolate the traffic of each gateway device to be fused. It further includes: obtaining architecture requirement information of each gateway device to be fused; and allocating different physical resources to each gateway device to be fused based on the architecture requirement information, where the allocated physical resources at least include a CPU and physical memory.
[0014] According to one aspect of the present disclosure, there is provided a multi-gateway fusion device, including: a first processing module configured to virtualize a physical network card corresponding to a host server to obtain a plurality of virtual network cards of the physical network card, and respectively communicatively connect the plurality of virtual network cards to different gateway devices to be fused to isolate the traffic of each gateway device to be fused; and a second processing module configured to bridge the plurality of virtual network cards to a virtual switch, and implement service traffic communication between the plurality of virtual network cards and the physical network card through the virtual switch.
[0015] According to one aspect of the present disclosure, there is provided a computer program product including a computer program which, when executed by a processor, implements the method of any one of the above.
[0016] According to one aspect of the present disclosure, there is provided an electronic device, including: a processor; and a memory configured to store executable instructions of the processor; wherein the processor is configured to execute the method of any one of the above by executing the executable instructions.
[0017] In the multi-gateway fusion method in the exemplary embodiment of the present disclosure, a physical network card corresponding to a host server is virtualized to obtain a plurality of virtual network cards of the physical network card, and the plurality of virtual network cards are respectively communicatively connected to different gateway devices to be fused to isolate the traffic of each gateway device to be fused, and then the plurality of virtual network cards are bridged to a virtual switch, and service traffic communication between the plurality of virtual network cards and the physical network card is implemented through the virtual switch. This process can deploy a plurality of gateway devices to be fused on the same physical server (host server), and the plurality of gateway devices to be fused share a physical network card through virtual network cards, which can improve the utilization rate of physical resources of the physical server while ensuring the network forwarding performance of the gateway service.
[0018] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] By reading the following detailed description with reference to the accompanying drawings, the above and other objects, features and advantages of the exemplary embodiments of the present disclosure will become readily understood. In the drawings, several embodiments of the present disclosure are shown by way of example and not limitation, wherein:
[0020] Figure 1Shows a schematic diagram of an architecture for multi-gateway fusion according to an exemplary embodiment of the present disclosure.
[0021] Figure 2 Shows a flowchart of a multi-gateway fusion method according to an exemplary embodiment of the present disclosure.
[0022] Figure 3 Shows a flowchart of an implementation manner for obtaining multiple virtual network cards according to an exemplary embodiment of the present disclosure.
[0023] Figure 4 Shows a schematic diagram of binding a virtual network card to a gateway to be fused according to an exemplary embodiment of the present disclosure.
[0024] Figure 5 Shows a schematic diagram of creating a node underlying topology of a virtual network card according to an exemplary embodiment of the present disclosure.
[0025] Figure 6 Shows a schematic diagram of data interaction based on multi-gateway fusion according to an exemplary embodiment of the present disclosure.
[0026] Figure 7 Shows a schematic diagram of the composition of a multi-gateway fusion device according to an exemplary embodiment of the present disclosure.
[0027] Figure 8 Shows a block diagram of an electronic device according to an exemplary embodiment of the present disclosure.
[0028] In the drawings, the same or corresponding reference numerals indicate the same or corresponding parts. Detailed implementation manners
[0029] Now, exemplary embodiments will be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be more complete and comprehensive, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The same reference numerals in the figures denote the same or similar structures, and thus their detailed descriptions will be omitted.
[0030] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present disclosure. However, those skilled in the art will realize that the technical solutions of the present disclosure can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known structures, methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present disclosure.
[0031] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or these functional entities or parts of functional entities may be implemented in one or more software hardened modules, or these functional entities may be implemented in different networks and / or processor devices and / or microcontroller devices.
[0032] The technical implementation of gateway devices in the virtual network of the cloud computing industry is also constantly iterating and innovating to improve the forwarding performance of gateway devices. Among them, the function library and driver set used for fast data packet processing through DPDK (Data Plane Development Kit) technology can greatly improve data processing performance and throughput, and improve the work efficiency of data plane applications. Based on DPDK technology (such as By Pass Kernel technology), the messages received by the network card can be directly sent to the application processing in the user space, bypassing the Linux kernel protocol stack, and processing network packets directly in the user space. However, it is necessary to bind the server's PCI device and the DPDK application process, and other processes cannot use this PCI device after binding, resulting in only one gateway service running on a server with a single network card. This causes a huge waste of physical resources for scenarios with small cluster sizes.
[0033] Based on this, the exemplary embodiment of the present disclosure provides a multi-gateway fusion method, which virtualizes the physical network card of the host server into multiple virtual network cards based on hardware virtualization and allocates them to the corresponding gateway devices to be fused, and then bridges the multiple virtual gateways to the virtual switch to realize the service flow communication between the multiple virtual network cards and the physical network card. It is possible to deploy multiple gateway services on the same physical server, thereby improving the utilization rate of the physical resources of the physical server.
[0034] For example, Figure 1 A schematic diagram of a multi-gateway integration architecture is shown, Figure 1 By deploying gateway A, gateway B, gateway C and gateway D respectively on four physical servers, and performing multi-gateway integration deployment using the multi-gateway integration method of an exemplary embodiment of the present invention, four gateway services are deployed on one co-location server at the same time.
[0035] It should be noted that Figure 1 This is only an example, and the number of physical servers involved, the number and type of gateways deployed on a physical server can be flexibly set according to the actual gateway deployment architecture requirements, and there is no limitation on this. In addition, the multi-gateway fusion method of the exemplary embodiment of the present disclosure can be applied to a variety of network service architectures, and is used to deploy multiple types of gateway services on the same physical server, and there is no limitation on this either.
[0036] like Figure 2 FIG. 1 is a flow chart of a multi-gateway integration method according to an exemplary embodiment of the present disclosure. Figure 2 As shown, the multi-gateway integration method may include step S210 and step S220, which are specifically as follows:
[0037] In step S210, the physical network card corresponding to the host server is virtualized to obtain multiple virtual network cards of the physical network card, and the multiple virtual network cards are respectively connected to different gateway devices to be integrated to isolate the traffic of each gateway to be integrated.
[0038] In the exemplary embodiment of the present disclosure, the host server is a physical server that carries virtual machines, provides computing resources and hardware support, and is specifically used to run virtual machines and carry virtualized environments. The host server of the exemplary embodiment of the present disclosure is also a server on which multiple gateways are to be deployed. The gateway to be integrated refers to a gateway service that needs to be deployed on the same physical server. The types of multiple gateways to be integrated can be the same or different, and there is no restriction on this.
[0039] Among them, the physical network card is a computer hardware device used to connect the computer to the external local area network. It can be installed on the computer's motherboard and realize network communication through cables or wireless methods. The physical network card plays an important role in the OSI (Open System Interconnect) model and is mainly responsible for the communication of the data link layer. The physical network card realizes the sending and receiving of data through the physical layer (PHY, port physical layer) and the data link layer (MAC controller). Among them, the physical layer processes the electrical characteristics of the signal, while the data link layer is responsible for the assembly and disassembly of the frame to ensure the correct transmission of data.
[0040] A virtual network card is relative to a physical network card. A physical network card is an actual hardware device, while a virtual network card is a network environment simulated by software. A physical network card can be virtualized based on hardware virtualization technology to obtain multiple virtual network cards. For example, a physical network card is virtualized based on SR-IOV (Single Root I / O Virtualization) technology. Of course, other hardware virtualization technologies can also be used, such as VT-d (a directional virtualization) technology, DDIO (a hardware accelerated virtualization) technology, etc. The exemplary embodiment of the present disclosure is described by taking the SR-IOV technology as an example to virtualize a physical network card.
[0041] After the physical network card is virtualized, multiple virtual network cards can be assigned to different gateways to be integrated. By forwarding data packets of the virtual network cards, the gateways to be integrated can achieve network communication with the physical machine through their corresponding virtual network cards.
[0042] In step S220, multiple virtual network cards are bridged to a virtual switch, and service traffic communication between the multiple virtual network cards and a physical network card is implemented through the virtual switch.
[0043] In an exemplary embodiment of the present disclosure, the virtual switch can also be referred to as a virtual bridge. It is a network device that operates at the second layer (data link layer) of the OSI model and performs data exchange through MAC addresses. It bridges between the virtual network and the physical network to enable communication between virtual machines and physical machines. Among them, the virtual switch can bridge internal network traffic to the physical network adapter through SEA (Virtual Ethernet Adapter), and then bridge multiple virtual network cards to the virtual switch, so that service traffic communication between the multiple virtual network cards and the physical network card can be implemented through the virtual switch.
[0044] The multi-gateway fusion method in the exemplary embodiment of the present disclosure virtualizes the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card, and respectively communicatively connects the multiple virtual network cards to different gateway devices to be fused to isolate the traffic of each gateway device to be fused. Then, the multiple virtual network cards are bridged to a virtual switch, and service traffic communication between the multiple virtual network cards and the physical network card is implemented through the virtual switch. This process can deploy multiple gateways to be fused on the same physical server (host server), and the multiple gateways to be fused share a physical network card through virtual network cards, which can improve the utilization rate of physical resources of the physical server while ensuring the network forwarding performance of the gateway service.
[0045] In an exemplary embodiment, an implementation manner for obtaining multiple virtual network cards is provided. As Figure 3 shown, virtualizing the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card may include:
[0046] Step S310: Create multiple Peripheral Component Interconnect Express (PCI-E) virtual devices of the physical network card to obtain multiple virtual network cards, and determine the Media Access Control (MAC) address corresponding to each virtual network card.
[0047] The SR-IOV technology can be used to create multiple PCI-E physical devices of a physical network card. The SR-IOV technology allows multiple virtual functions (VFs) of a physical device to be directly assigned to different virtual machines. The physical device is called a physical function (PF), and the virtual function (VF) is a lightweight PCI-E function that can share physical resources with the physical function. Herein, the PCI-E physical device refers to a device that complies with the PCI-E interface standard. Multiple PCI-E physical devices are determined as multiple virtual network cards. Among them, the MAC address of the virtual network card can be obtained while creating the virtual network card, and the MAC addresses of each virtual network card are different.
[0048] Step S320: Assign multiple virtual network cards to different gateway devices to be fused and bind them to enable communication connections between multiple virtual network cards and different gateway devices to be fused respectively.
[0049] Among them, the unique identification information of the gateway device to be fused and the corresponding virtual network card can be bound. The unique identification information refers to the identifiers of the physical function (PF) and the virtual function (VF), and each VF can be accessed through its own identifier. For example, bind the gateway device to be fused with the PCI number of the virtual network card.
[0050] By virtualizing a physical network card into multiple lightweight PCI-E virtual devices and assigning these PCI-E virtual devices to different gateway devices to be fused for binding, traffic isolation between each gateway device to be fused can be achieved while multiplexing the resources of the same physical network card.
[0051] Based on the foregoing exemplary embodiments, assigning multiple virtual network cards to different gateway devices to be fused and binding them to enable communication connections between multiple virtual network cards and different gateway devices to be fused respectively may include:
[0052] Assign at least one pair of virtual network cards to each gateway device to be fused. The virtual network cards in the pair of virtual network cards are respectively used to receive service traffic data and send service traffic data.
[0053] Specifically, as Figure 4 shows a schematic diagram of binding a virtual network card to a gateway device to be fused. As Figure 4 , two virtual network cards (a pair of virtual network cards) can be assigned to each gateway device to be fused. One of the virtual network cards serves as a channel for receiving service traffic data, and the other virtual network card serves as a channel for sending service traffic data.
[0054] Through the gateway architecture design of assigning a group of virtual network card pairs to each gateway device to be fused, redundancy backup can also be achieved. For example, when a virtual network card fails or cannot work, another virtual network card can immediately take over the network connection to ensure the continuous online of the server, enhance the reliability of the network, and the network traffic can be shared by two virtual network cards. In addition, it can also meet the requirements of virtualization technology for network resource allocation and isolation, and ensure the processing power and response speed of the server.
[0055] Of course, a virtual network card can also be assigned to each gateway to be fused, and normal forwarding of service data packets can also be achieved, and flexible adjustment can be made according to the actual gateway design architecture.
[0056] Based on the foregoing exemplary embodiments, determining the media access control address (MAC address) corresponding to each virtual network card may include:
[0057] First, based on the MAC address information of the physical network card, generate the virtual MAC address corresponding to each virtual network card, and then determine the corresponding relationship between the MAC address information of the physical network card and each virtual MAC address.
[0058] Among them, based on the MAC address information of the physical network card, generate a virtual MAC address that can constrain the virtual network card, and the virtual MAC address is unique and identifiable in the network.
[0059] Exemplarily, the virtual MAC address of the virtual network card can be manually specified based on the setting options of the virtualization platform, or when creating the virtual network card of the physical network card, the virtualization platform automatically generates the virtual MAC address of the virtual network card based on the MAC address of the physical network card. Or, a script written in advance or an existing tool can also be used to randomly generate the virtual MAC address of the virtual network card or the virtual MAC addresses arranged in sequence. The exemplary embodiments of the present disclosure include, but are not limited to, the above methods for generating the virtual MAC address of the virtual network card.
[0060] Furthermore, the corresponding relationship between the MAC address information of the physical network card and each virtual MAC address can be determined. Based on this corresponding relationship, the data packets passing through the physical network card can be accurately forwarded to the corresponding virtual network card during data distribution.
[0061] In an exemplary embodiment, before bridging multiple virtual network cards to a virtual switch, it may further include: performing link aggregation processing on at least two physical network cards of the host server to obtain a link aggregation port.
[0062] Among them, performing link aggregation processing (Bond) on a physical network card means combining multiple physical network interfaces into a logical interface to improve the reliability, bandwidth, and load balancing ability of the network connection. The Bond technology is mainly applied in the Linux system, and multiple physical network cards are bound through specific drivers and configurations to form a virtual network interface. When data packets are transmitted through this logical interface, they are distributed to each physical interface through internal algorithms (such as hash functions) to achieve load balancing, thereby making full use of the bandwidth of each physical interface and improving the overall network throughput.
[0063] Based on this, virtualizing the physical network cards corresponding to the host server to obtain multiple virtual network cards of the physical network cards can be creating multiple virtual network cards using the link aggregation interface.
[0064] Exemplarily, Figure 5 shows a schematic diagram of the underlying topology of a node for creating virtual network cards, as Figure 5 shown. First, the physical network card (pf0) and the physical network card (pf1) can be subjected to link aggregation processing based on the VFLAG (a new flag in regular expressions) technology to obtain a link aggregation interface (mlx_bond0), and then multiple virtual network cards (such as vf0 to vf6) are created based on the SR-IOV technology using the link aggregation interface (mlx_bond0). The figure includes four different types of gateways to be fused (such as NATGW gateway, DR gateway, VR gateway, and OVS gateway). Furthermore, the virtual network cards vf6 and vf5 can be bound to the NATGW gateway, the virtual network cards vf4 and vf3 can be bound to the DR gateway, the virtual network cards vf2 and vf1 can be bound to the VR gateway, and the virtual network card vf0 can be bound to the OVS gateway.
[0065] By performing link aggregation on the physical network cards, multiple virtual network cards are virtualized on the link aggregation interface, and different virtual network cards are allocated to each gateway to be fused for use, thereby achieving high availability at the data link layer. In addition, link aggregation also provides functions of failover and redundant backup. If one of the physical interfaces fails or becomes unavailable, the data packets will automatically switch to other available interfaces to ensure the reliability and connectivity of the network.
[0066] It should be noted that Figure 5 is only an example of a network architecture. The number of physical network cards, the types and numbers of gateways to be fused, the number of virtual network cards, and the corresponding relationship between the virtual network cards and the gateways to be fused in the exemplary embodiments of the present disclosure can all be set according to actual network service requirements, and no specific limitations are made thereto.
[0067] In an exemplary embodiment, a service traffic communication method is further provided. Bridging multiple virtual network cards to a virtual switch and implementing service traffic communication between the multiple virtual network cards and a physical network card through the virtual switch may include:
[0068] First, obtain a first data packet transmitted by a link aggregation port and distribute the first data packet to the corresponding physical network card; then, for each physical network card, parse the received data packet through the physical network card to obtain a destination MAC address, so as to match a forwarding rule based on the destination MAC address through the virtual switch and forward the received data packet to the corresponding target virtual network card according to the matching result.
[0069] Such as Figure 6 shows a schematic diagram of data interaction based on multi-gateway fusion. As Figure 6 shown, taking a physical network card receiving a data packet as an example, since there is a pre-stored correspondence between the MAC address of the physical network card and the virtual MAC address of the virtual network card, by parsing the received data packet, the destination MAC address is parsed, so that the virtual switch (virtual bridge) matches the forwarding rule based on the target MAC address, and forwards the received data packet to the corresponding target virtual network card according to the matching result.
[0070] Among them, matching the forwarding rule based on the target MAC address through the virtual switch (virtual bridge) means determining how to forward data according to the destination MAC address. A MAC address table can be maintained in the virtual switch. This table records the MAC addresses of other devices learned by the virtual switch and the corresponding outgoing interfaces (the interfaces for sending and receiving data), etc. The virtual switch looks up the destination MAC address and searches in the MAC address table according to this address. If there is an entry in the MAC address table that matches the destination MAC address, the virtual switch will forward the data packet to the corresponding interface according to the outgoing interface information recorded in the entry, that is, the target virtual network card. If there is no entry in the MAC address table that matches the destination MAC address, the virtual switch may broadcast the data packet to all possible interfaces (virtual network cards) to try to find the target virtual network card.
[0071] Correspondingly, the data packet passing through the gateway to be fused can also reach the physical network card via its corresponding virtual network card and through the virtual switch. Similarly, based on the correspondence of the MAC addresses, this will not be elaborated here.
[0072] In the exemplary embodiment of the present disclosure, multiple gateways to be fused deployed on the same physical server can share a physical network card, which can not only ensure traffic isolation of each physical gateway to be fused, but also reuse the resources of the same physical network card.
[0073] It should be understood thatFigure 6 It is only an exemplary data interaction schematic diagram. The number of gateways, the number of virtual gateways, etc. are all examples and can be configured according to actual needs. For example, if the number of gateways is large, the number of generated virtual network cards is correspondingly increased to provide services for each gateway.
[0074] In an exemplary embodiment, communicating multiple virtual network cards with different gateway devices to be fused respectively to isolate the traffic of each gateway device to be fused may include:
[0075] First, obtain the architecture requirement information of each gateway device to be fused. Second, allocate different physical resources to each gateway device to be fused based on the architecture requirement information. The allocated physical resources at least include CPU and physical memory.
[0076] Specifically, the architecture requirement information of the gateway device to be fused may include conversion and translation function information, filtering and security performance information, connection and interconnection ability information, etc. Among them, the conversion and translation function information refers to the ability information of the gateway to repackage and translate the received information to meet the requirements of the destination system. The filtering and security performance information refers to that the gateway needs to provide filtering and security functions to protect the network from external attacks and malicious traffic, such as access control, firewall, and encrypted transmission. The connection and interconnection ability information refers to that the gateway can support multiple communication protocols, data formats, and languages to achieve effective communication between different networks.
[0077] When actually deploying the gateway device to be fused, each gateway device to be fused has its own architecture requirement information, including but not limited to the above requirement information. Then, different physical resources are allocated to each gateway device to be fused based on the architecture requirement information. For example, if the architecture requirement information of the gateway device to be fused indicates that the gateway device to be fused needs more CPU and physical memory support, more CPU and physical memory can be allocated to the gateway device to be fused. Among them, the corresponding relationship between the architecture requirement information and the physical resources or the range of physical resources can be set, so that based on this corresponding relationship, different physical resources are allocated to each gateway device to be fused according to the architecture requirement information.
[0078] For example, for the gateway device to be fused A: bind CPU IDs 1, 2, 3, 4, memory: 4G; for the gateway device to be fused B: bind CPU IDs 5, 6, 7, 8, memory: 2G; for the gateway device to be fused C: bind CPU IDs 9, 10, 11, 12, 13, 14, 15, memory: 16G; for the gateway device to be fused D: bind CPU IDs 16, 17, 18, 19, memory: 16G. It can be seen from this that the architecture requirement of the gateway device to be fused C is higher than that of the gateway device to be fused D, the architecture requirement of the gateway device to be fused D is higher than that of the gateway device to be fused A, and the architecture requirement of the gateway device to be fused A is higher than that of the gateway device to be fused B.
[0079] It should be noted that the allocated physical resources may include, in addition to the CPU and physical memory, storage devices, NICs (Network Interface Cards), power supplies, and the like.
[0080] By allocating different physical resources to each gateway to be fused according to the architecture requirement information, physical resources can be scheduled and allocated according to the gateway architecture requirements when multiple gateways are deployed on the same physical server, so that the physical resources are fully utilized, and the utilization rate of the physical resources is further improved.
[0081] In the multi-gateway fusion method according to an exemplary embodiment of the present disclosure, virtualization processing is performed on the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card, and the multiple virtual network cards are respectively communicatively connected to different gateways to be fused to isolate the traffic of each gateway to be fused. Then, the multiple virtual network cards are bridged to a virtual switch, and service traffic communication between the multiple virtual network cards and the physical network card is implemented through the virtual switch. This process can deploy multiple gateways to be fused on the same physical server (host server), and multiple gateways to be fused share a physical network card through virtual network cards. Without sacrificing the network forwarding performance of the gateway service, the utilization rate of the physical resources of the physical server can be improved.
[0082] In an exemplary embodiment of the present disclosure, a multi-gateway fusion device is also provided. Referring to Figure 7 as shown, the multi-gateway fusion device 700 may include a first processing module 710 and a second processing module 720. Specifically:
[0083] The first processing module 710 is configured to perform virtualization processing on the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card, and respectively communicatively connect the multiple virtual network cards to different gateways to be fused to isolate the traffic of each gateway to be fused; the second processing module 720 is configured to bridge the multiple virtual network cards to a virtual switch, and implement service traffic communication between the multiple virtual network cards and the physical network card through the virtual switch.
[0084] In an exemplary embodiment of the present disclosure, the first processing module 710 is configured to execute: creating multiple Peripheral Component Interconnect Express (PCI-E) virtual devices of the physical network card to obtain multiple virtual network cards, and determining the Media Access Control (MAC) address corresponding to each virtual network card; allocating the multiple virtual network cards to different gateways to be fused and binding them to implement the communicative connection between the multiple virtual network cards and different gateways to be fused respectively; wherein, binding the unique identification information of the gateway to be fused with the corresponding virtual network card.
[0085] In an exemplary embodiment of the present disclosure, the first processing module 710 is configured to perform: allocating at least one set of virtual network card pairs to each gateway device to be fused, where the virtual network cards in the virtual network card pair are respectively used to receive service traffic data and send service traffic data.
[0086] In an exemplary embodiment of the present disclosure, the first processing module 710 is configured to perform: generating a respective virtual MAC address for each virtual network card based on the MAC address information of the physical network card; determining the correspondence between the MAC address information of the physical network card and each of the virtual MAC addresses.
[0087] In an exemplary embodiment of the present disclosure, the second processing module 720 is further configured to perform: before bridging multiple virtual network cards to a virtual switch, performing link aggregation processing on at least two physical network cards of the host server to obtain a link aggregation port; the first processing module 710 is further configured to perform: creating multiple virtual network cards using the link aggregation port.
[0088] In an exemplary embodiment of the present disclosure, the second processing module 720 is further configured to perform: obtaining a first data packet transmitted by the link aggregation port, distributing the first data packet to the corresponding physical network card; for each physical network card, parsing the received data packet through the physical network card to obtain the destination MAC address, so as to match the forwarding rule based on the destination MAC address through the virtual switch, and forwarding the received data packet to the corresponding target virtual network card according to the matching result.
[0089] In an exemplary embodiment of the present disclosure, the first processing module 710 is further configured to perform: obtaining the architecture requirement information of each gateway to be fused; allocating different physical resources to each gateway to be fused based on the architecture requirement information, where the allocated physical resources at least include CPU and physical memory.
[0090] Since the detailed content of each functional module of the multi-gateway fusion device in the exemplary embodiment of the present disclosure has been described in the exemplary embodiment of the above multi-gateway fusion method, it will not be repeated here.
[0091] It should be noted that although several modules or units of the multi-gateway fusion device are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0092] An exemplary embodiment of the present disclosure also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the above multi-gateway fusion method is implemented.
[0093] In one embodiment, the computer program product may be a tangible product containing a computer program, such as a computer-readable storage medium storing the computer program. The readable storage medium may be a storage medium based on signals such as electricity, magnetism, light, electromagnetic, infrared, etc., including but not limited to: random access memory (RAM), read-only memory (ROM), magnetic tape, floppy disk, flash memory (Flash), hard disk drive (HDD), solid state drive (SSD), and so on. Exemplarily, the computer program product may be implemented as a non-volatile storage medium storing the computer program, such as read-only memory, Nand Flash, etc.
[0094] In one embodiment, the computer program product may be an intangible product containing a computer program. Exemplarily, the computer program product may be implemented as a virtual digital product, such as an executable file storing the computer program, an installation package, and other digital files.
[0095] The code of the computer program can be written in one or more programming languages. The program code can be executed entirely on the user's computing device, or partially on the user's computing device, or executed as an independent software package, or partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, such as a local area network (LAN), a wide area network (WAN), etc., or can be connected to an external computing device (for example, through an Internet connection provided by an operator).
[0096] The computer program can be carried or transmitted by signals such as electricity, magnetism, light, electromagnetic, infrared, etc. The electronic device can convert the signal carrying the computer program into a digital signal and then run the computer program. When the computer program runs on the electronic device, its code is used to cause the electronic device to execute (more specifically, can cause the processor of the electronic device to execute) the method steps of various exemplary embodiments of the present disclosure, such as the steps of the above multi-gateway fusion method, for example: virtualizing the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card, and respectively communicating and connecting the multiple virtual network cards with different gateway devices to be fused to isolate the traffic of each gateway device to be fused; bridging the multiple virtual network cards to a virtual switch and implementing service traffic communication between the multiple virtual network cards and the physical network card through the virtual switch.
[0097] In addition, in an exemplary embodiment of the present disclosure, an electronic device capable of implementing the above method is also provided. Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method, or a program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware embodiment, a complete software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software aspects, which can be collectively referred to as "circuitry", "module", or "system" herein.
[0098] Reference will now be made to Figure 8 describe the electronic device 800 according to such an embodiment of the present disclosure. Figure 8 The electronic device 800 shown is merely an example and should not impose any limitation on the functions and the scope of use of the embodiments of the present disclosure.
[0099] As Figure 8 shown, the electronic device 800 is presented in the form of a general-purpose computing device. The components of the electronic device 800 may include, but are not limited to: at least one of the above-mentioned processing units 810, at least one of the above-mentioned storage units 820, a bus 830 connecting different system components (including the storage unit 820 and the processing unit 810), and a display unit 840.
[0100] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 810, so that the processing unit 810 executes the steps according to various exemplary embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.
[0101] The storage unit 820 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 821 and / or a cache storage unit 822, and may further include a read-only storage unit (ROM) 823.
[0102] The storage unit 820 may further include a program / utilities 824 having a set (at least one) of program modules 825. Such program modules 825 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0103] The bus 830 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.
[0104] The electronic device 800 can also communicate with one or more external devices 900 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 800, and / or communicate with any device that enables the electronic device 800 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 850. Moreover, the electronic device 800 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 860. As shown in the figure, the network adapter 860 communicates with other modules of the electronic device 800 through the bus 830. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0105] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solution according to the embodiments of the present disclosure can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present disclosure.
[0106] In addition, the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present disclosure, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.
[0107] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include well-known common general knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and the embodiments are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the claims.
Claims
1. A multi-gateway fusion method, characterized in that: include: Virtualizing the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card, and respectively communicating and connecting the multiple virtual network cards with different gateway devices to be integrated to isolate the traffic of each gateway to be integrated; The multiple virtual network cards are bridged to a virtual switch, and service traffic communication between the multiple virtual network cards and the physical network card is implemented through the virtual switch.
2. The method according to claim 1, characterized in that The virtualizing the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card includes: Creating a plurality of peripheral component interconnection standard bus PCI-E virtual devices of the physical network card, obtaining the plurality of virtual network cards, and determining the media access control address MAC address corresponding to each of the virtual network cards; The multiple virtual network cards are allocated to different gateway devices to be integrated and bound to achieve communication connection between the multiple virtual network cards and different gateway devices to be integrated respectively; wherein the gateway device to be integrated is bound to the unique identification information of the corresponding virtual network card.
3. The method according to claim 2, characterized in that The allocating the multiple virtual network cards to different gateway devices to be integrated and binding them to achieve communication connection between the multiple virtual network cards and different gateway devices to be integrated, respectively, includes: At least one set of virtual network card pairs is allocated to each of the gateway devices to be merged, and the virtual network cards in the virtual network card pairs are respectively used for receiving business flow data and sending business flow data.
4. The method according to claim 2, characterized in that: The step of determining the media access control address MAC address corresponding to each of the virtual network cards includes: Based on the MAC address information of the physical network card, generate a virtual MAC address corresponding to each of the virtual network cards; Determine the correspondence between the MAC address information of the physical network card and each of the virtual MAC addresses.
5. The method according to claim 1, characterized in that Before bridging the multiple virtual network cards to the virtual switch, the method further includes: Perform link aggregation processing on at least two physical network cards of the host server to obtain a link aggregation port; The virtualizing the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card includes: The multiple virtual network cards are created using the link aggregation ports.
6. The method according to claim 5, characterized in that The bridging of the multiple virtual network cards to a virtual switch and implementing service traffic communication between the multiple virtual network cards and the physical network card through the virtual switch includes: Obtaining a first data packet transmitted by the link aggregation port, and distributing the first data packet to a corresponding physical network card; For each of the physical network cards, the received data packets are parsed by the physical network card to obtain the destination MAC address, so as to match the forwarding rules based on the destination MAC address through the virtual switch, and forward the received data packets to the corresponding target virtual network card according to the matching results.
7. The method according to claim 1, characterized in that The method of respectively connecting the plurality of virtual network cards to different gateway devices to be integrated to isolate traffic of each of the gateways to be integrated further includes: Obtaining architecture requirement information of each of the gateways to be integrated; Different physical resources are allocated to each of the to-be-converged gateways based on the architecture requirement information, wherein the allocated physical resources at least include a CPU and a physical memory.
8. A multi-gateway fusion device, characterized in that: include: The first processing module is used to virtualize the physical network card corresponding to the host server to obtain multiple virtual network cards of the physical network card, and respectively communicate and connect the multiple virtual network cards with different gateway devices to be integrated to isolate the traffic of each gateway to be integrated; The second processing module is used to bridge the multiple virtual network cards to the virtual switch, and realize the service flow communication between the multiple virtual network cards and the physical network card through the virtual switch.
9. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
10. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; The processor is configured to perform the method of any one of claims 1 to 7 by executing the executable instructions.