Network intercommunication method and system, electronic equipment, storage medium and program product

The proposed network interconnectivity method addresses bandwidth bottlenecks and high costs in cloud computing by synchronizing route information between virtual and bare metal nodes using BGP tunnels and VRFs, improving network efficiency and reducing costs.

CN120281602AActive Publication Date: 2025-07-08JINAN INSPUR DATA TECH CO LTD

Patent Information

Application Number
CN202510775874.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-08
Estimated Expiration
2045-06-11

AI Technical Summary

Technical Problem

Cloud computing environments face issues with bandwidth bottlenecks and high costs in network interconnectivity between virtual machines and bare metal nodes due to the limitations of existing soft gateways, particularly in scenarios requiring high bandwidth and physical network card isolation.

Method used

Implement a network interconnectivity method using virtual routing and forwarding instances to synchronize route information between virtual machines and bare metal servers through a route reflection mechanism, leveraging BGP tunnels and VRFs to optimize traffic routing and reduce reliance on costly hardware solutions.

Benefits of technology

Enhances network interconnectivity between virtual machines and bare metal nodes by eliminating bandwidth bottlenecks and reducing costs, ensuring seamless, secure, and efficient communication in cloud environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281602A_ABST
    Figure CN120281602A_ABST
Patent Text Reader

Abstract

The invention discloses a network intercommunication method and system, electronic equipment, a storage medium and a program product, and relates to the field of cloud computing, and the method comprises the following steps: for first virtual machine traffic output by a virtual machine in a computing node, performing route matching on the first virtual machine flow through a routing table corresponding to a first virtual route and a forwarding instance in the computing node; and instructing a target switch to send the obtained second virtual machine traffic to the physical server node, so that network intercommunication between the virtual machine and the physical server node is realized, and the target switch is connected to the physical server node, the routing reflector and the computing node. The problem that the network intercommunication effect between the virtual machine and the bare metal node is poor due to the defects of bandwidth forwarding bottleneck and high scheme cost of a soft gateway used between the virtual machine and the bare metal node in the computing node in the cloud computing environment is solved, and the network intercommunication effect between the virtual machine and the bare metal node is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing, and in particular, to a network interconnection method, system, electronic device, storage medium, and program product. Background Art

[0002] With the rapid development of the cloud computing field, bare metal services (i.e., bare metal nodes), as a type of computing service that combines the elasticity of virtual machines and the performance of physical machines, can provide exclusive cloud-based physical servers for individuals or enterprises. It can provide excellent computing performance for key application systems, high-performance computing, big data, core databases, etc. and ensure data security. When creating a bare metal cloud physical machine, similar to creating a virtual machine, one only needs to specify the required hardware requirements (such as: Central Processing Unit (CPU for short), memory, etc.), image, and the required network to create the desired bare metal cloud physical machine. And users can apply flexibly and on demand.

[0003] In related technologies, the gateways of bare metal services are mainly soft gateways, which are divided into two categories: one is a centralized gateway, and the traffic of the bare metal service is forwarded through the primary and standby deployed gateway nodes. The other is a distributed gateway, which generally uses intelligent network cards, and the traffic is forwarded among each bare metal node; however, the centralized gateway has a bandwidth forwarding bottleneck and cannot meet the demands of high-bandwidth forwarding such as high-order services, and does not support physical network card isolation, so it cannot meet the physical network card isolation requirements of databases such as oracle; the distributed gateway faces problems such as high cost and high threshold of the intelligent network card solution.

[0004] In view of the defects of the soft gateway used between virtual machines and bare metal nodes in computing nodes in the cloud computing environment in related technologies, such as bandwidth forwarding bottleneck and high solution cost, and thus the problem of poor network interconnection effect between virtual machines and bare metal nodes has not been effectively solved. Summary of the Invention

[0005] This application provides a network interconnection method, system, electronic device, storage medium, and program product to at least solve the defects of the soft gateway used between virtual machines and bare metal nodes in computing nodes in the cloud computing environment, such as bandwidth forwarding bottleneck and high solution cost, and thus the problem of poor network interconnection effect between virtual machines and bare metal nodes.

[0006] The present application provides a network interconnection method, including: when the destination node of the first virtual machine traffic is a physical server node, performing route matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain second virtual machine traffic, where the computing node includes: a virtual machine that outputs the first virtual machine traffic and the first virtual routing and forwarding instance, and the routing information of the physical server node has been synchronized to the routing table through a route reflector connected to the computing node; sending the second virtual machine traffic to a target switch, and instructing the target switch to send the second virtual machine traffic to the physical server node, so that network interconnection is achieved between the virtual machine and the physical server node, where the target switch is respectively connected to the physical server node, the route reflector, and the computing node.

[0007] The present application further provides a network interconnection device, including: a computing node, configured to, when the destination node of the first virtual machine traffic is a physical server node, perform route matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain second virtual machine traffic, and send the second virtual machine traffic to a target switch, where the computing node includes: a virtual machine that outputs the first virtual machine traffic and the first virtual routing and forwarding instance, and the routing information of the physical server node has been synchronized to the routing table through a route reflector connected to the computing node; the target switch, respectively connected to the physical server node, the route reflector, and the computing node, and configured to send the second virtual machine traffic to the physical server node.

[0008] The present application further provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any of the above network interconnection methods when executing the computer program.

[0009] The present application further provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of any of the above network interconnection methods are implemented.

[0010] The present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of any of the above network interconnection methods are implemented.

[0011] With this application, for the first virtual machine traffic output by a virtual machine in a computing node and destined for a physical server node, the first virtual machine traffic is routed and matched through the routing table corresponding to the first virtual routing and forwarding instance in the computing node; the routing information of the physical server node has been synchronized to the routing table through a route reflector connected to the computing node; the obtained second virtual machine traffic is sent to a target switch, so that the target switch sends the second virtual machine traffic to the physical server node, thereby enabling network interconnection between the virtual machine and the physical server node, where the target switch is connected to the physical server node, the route reflector, and the computing node respectively. Therefore, it is possible to solve the defects of the soft gateway used between the virtual machine and the bare metal node in the computing node in the cloud computing environment in the related art, such as bandwidth forwarding bottlenecks and high solution costs, and further solve the technical problem of poor network interconnection effect between the virtual machine and the bare metal node, thereby improving the network interconnection effect between the virtual machine and the bare metal node. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0013] Figure 1 is a hardware structure block diagram of a computer terminal for a network interconnection method according to an embodiment of the present application;

[0014] Figure 2 is a flowchart of a network interconnection method according to an embodiment of the present application;

[0015] Figure 3 is a schematic diagram of the architecture of a network interconnection system according to an embodiment of the present application (I);

[0016] Figure 4 is a schematic diagram of the architecture of a network interconnection system according to an embodiment of the present application (II);

[0017] Figure 5 is an architecture diagram of a network interconnection system according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0019] It should be noted that in the description of this application, the terms "including", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0020] To enable those skilled in the art of this technology to better understand the solution of this application, the following further detailed description of this application will be given in conjunction with the accompanying drawings and specific embodiments.

[0021] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the network interconnection method depends, the specific application environment architecture or specific hardware architecture will be described herein.

[0022] The method embodiments provided in the embodiments of this application can be executed on a mobile terminal, a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 is the hardware structure block diagram of a computer terminal of a network interconnection method in the embodiments of this application. As Figure 1 shown, the computer terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 (the processors 102 may include, but are not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Among them, the above computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that, Figure 1 the structure shown in the figure is only for illustration and does not limit the structure of the above computer terminal. For example, the computer terminal may further include more or fewer components than those shown in Figure 1 the figure, or have a different configuration from that shown in Figure 1 the figure.

[0023] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the network interworking method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the above-mentioned method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories may be connected to the computer terminal through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.

[0024] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of a computer terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0025] Figure 2 is a flowchart of the network interworking method according to the embodiments of the present application, which is applied to a computing node in a cloud computing environment. As Figure 2 shown, the process includes the following steps:

[0026] Step S202, when the destination node of the first virtual machine traffic is a physical server node, perform route matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain the second virtual machine traffic, where the computing node includes: a virtual machine that outputs the first virtual machine traffic and the first virtual routing and forwarding instance, and the routing information of the physical server node has been synchronized to the routing table through a route reflector connected to the computing node;

[0027] It should be noted that the physical server node in the embodiments of the present application refers to a bare metal server (BareMetal, which can also be called a bare metal node, bare metal service, bare metal, or bare machine), generally used to indicate a physical server without an operating system installed. It should also be noted that in the field of cloud computing, the corresponding concept to the bare metal server in the cloud platform is the cloud physical machine, where the bare metal server with an operating system installed in the cloud platform can be called a cloud physical machine.

[0028] It should also be noted that Virtual Routing and Forwarding (VRF for short) is a technology that allows multiple virtual routing tables to coexist on the same router.

[0029] Step S204: Send the second virtual machine traffic to the target switch, and instruct the target switch to send the second virtual machine traffic to the physical server node, so that network interconnection between the virtual machine and the physical server node is achieved. The target switch is respectively connected to the physical server node, the route reflector, and the computing node.

[0030] Through the above steps, for the first virtual machine traffic output by the virtual machine in the computing node and destined for the physical server node, the first virtual routing and forwarding instance in the computing node performs route matching on the first virtual machine traffic through the corresponding routing table; the routing information of the physical server node has been synchronized to the routing table through the route reflector connected to the computing node; the obtained second virtual machine traffic is sent to the target switch, so that the target switch sends the second virtual machine traffic to the physical server node, thereby enabling network interconnection between the virtual machine and the physical server node. The target switch is respectively connected to the physical server node, the route reflector, and the computing node. Therefore, it is possible to solve the defects of the soft gateway used between the virtual machine and the bare metal node in the cloud computing environment, such as bandwidth forwarding bottlenecks and high solution costs in the related art, and further solve the technical problem of poor network interconnection effect between the virtual machine and the bare metal node, thereby improving the network interconnection effect between the virtual machine and the bare metal node.

[0031] An embodiment of the present application provides a network interconnection method. In combination with the execution process of the network interconnection method, the method is described in detail.

[0032] In an exemplary embodiment, before performing route matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain the second virtual machine traffic, the method further includes: obtaining the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier corresponding to the virtual machine from the control node connected to the computing node through the proxy component; establishing a first preset protocol tunnel between the computing node and the route reflector according to the autonomous system number and the preset protocol through the free range routing instance.

[0033] It should be noted that the above preset protocol is the Border Gateway Protocol (BGP for short), a protocol used to exchange routing information between different autonomous systems (AS for short). Furthermore, the above first preset protocol tunnel is a BGP tunnel established between the computing node and the route reflector. Specifically, this BGP tunnel refers to a logical connection established through the BGP protocol and is used to transmit routing information between different network nodes. Free Range Routing (FRR for short) is an open-source Internet Protocol (IP) routing protocol suite that provides dynamic routing capabilities for routers and supports multiple routing protocols, including BGP.

[0034] In the embodiments of this application, it describes how to effectively establish a network tunnel between the computing node and the route reflector through the interaction between the proxy component and the control node, as well as by using the Free Range Routing (FRR) instance and the preset protocol in the cloud computing environment, especially in the application scenario of the bare metal enhanced gateway (equivalent to the above target switch), so as to achieve accurate routing and efficient transmission of virtual machine traffic.

[0035] First, the proxy component obtains information from the control node. The proxy component (such as ovn-bgp-agent) on the computing node acts as the role of communicating with the control node. The control node is usually the central management platform in the cloud environment (such as Neutron, the network service of OpenStack), which is responsible for global network configuration and policies. When a virtual machine is created or the network configuration is changed, the proxy component will obtain relevant network parameters from the control node, including the autonomous system number (such as bgp as) corresponding to the virtual machine, the layer 2 virtual network identifier (l2 vni), and the layer 3 virtual network identifier (l3 vni).

[0036] Among them, the autonomous system number (bgp as): is used in the BGP protocol to identify an autonomous system on the Internet. In the cloud environment, the autonomous system number is used to establish a BGP tunnel between the computing node and the route reflector to achieve network isolation and communication in a multi-tenant environment.

[0037] L2 VNI and L3 VNI: The Virtual Network Identifier (VNI) in VXLAN (Virtual eXtensible Local Area Network) is used to identify different network spaces. L2 VNI is used for the isolation of layer 2 networks, while L3 VNI is used for the routing isolation of layer 3 networks. These VNIs are the key identifiers for enabling communication between different virtual machines or between virtual machines and bare metals in the overlay network.

[0038] Secondly, use the FRR instance to establish a tunnel. On the compute node, the FRR instance is used to establish a first preset protocol tunnel between the compute node and the route reflector according to the bgp as and the preset protocol obtained from the proxy component. This tunnel is used to transmit BGP control plane information, such as route updates, Media Access Control (MAC) addresses, etc., to ensure that the virtual machines on the compute node and the bare metal servers on the bare metal enhanced gateway side can share routing information and achieve layer 2 and layer 3 intercommunication.

[0039] Finally, each VRF on the compute node is an independent routing and forwarding environment with its own routing table. When the first virtual machine traffic arrives at the compute node, it will pass through the routing table of the first virtual routing and forwarding instance and perform layer 3 routing matching based on the obtained L3 VNI to determine the next-hop destination. The result of the routing match determines the subsequent flow of the traffic. For example, it can be sent to the bare metal enhanced gateway side or directly forwarded to the local network. It should be noted that the "second virtual machine traffic" actually refers to the encapsulated or unencapsulated state of the traffic after passing through the VRF routing match on the compute node and ready for the next step of transmission. If the traffic is destined for another virtual machine, it may need to be encapsulated again and sent out through VXLAN or other overlay technologies; if the destination is a resource within the same VRF, the traffic can be directly forwarded at layer 2 or layer 3.

[0040] Through the above steps, the embodiment of the present application combines a preset protocol (such as BGP), VRF instances, and VNI identifiers to establish an efficient and isolated network connection between the compute node and the route reflector, enabling seamless and secure communication between virtual machines and bare metal servers in a complex cloud environment, while optimizing network performance and resource utilization efficiency.

[0041] In an exemplary embodiment, obtaining the autonomous system number, layer 2 virtual network identifier, and layer 3 virtual network identifier corresponding to the virtual machine from a control node connected to the computing node through a proxy component includes: monitoring a southbound database in the control node through the proxy component; and extracting the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier from the external identifier when it is detected that the external identifier of the network port corresponding to the virtual machine is synchronized to the southbound database, where the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier are added to the external identifier by a driver component in the control node when the network port is created.

[0042] It should be noted that in the network controller of the cloud environment (such as Neutron of OpenStack, or the southbound database of Open Virtual Network (OVN for short)), the configuration information of all network ports (including network ports of resources such as virtual machines and bare metals) is stored. These configuration information includes external identifiers (external_ids), and the external identifiers contain additional parameters related to the network ports, such as autonomous system numbers, layer 2 virtual network identifiers, layer 3 virtual network identifiers, etc.

[0043] In the embodiment of the present application, a proxy component (such as ovn-bgp-agent) pre-deployed on the computing node continuously monitors the southbound database to capture any changes related to the virtual machine network port information. When a new virtual machine network port is created, a driver component (such as bgpvpn-ovn-driver) in the control node adds necessary network parameters, including autonomous system numbers, layer 2 virtual network identifiers, and layer 3 virtual network identifiers, to the external identifier of the port. When the proxy component detects that the external identifier of the virtual machine network port is synchronized to the southbound database, it extracts the autonomous system number, the layer 2 virtual network identifier, the layer 3 virtual network identifier, etc. from the external identifier. This process is automated, ensuring fast response and accuracy of the virtual machine network configuration, and avoiding delays and errors that may be caused by manual intervention.

[0044] In summary, through the real-time monitoring and automated parameter extraction capabilities of the proxy component, this embodiment constructs a dynamic and highly adaptable network environment. This mechanism ensures that even in a complex cloud architecture, it can quickly and accurately respond to network configuration changes, achieve efficient and secure communication between virtual machines and bare metal servers, while reducing the workload of operation and maintenance personnel and improving the overall network automation level and management efficiency.

[0045] In an exemplary embodiment, after a first preset protocol tunnel between the computing node and the route reflector is established by a free range routing instance according to the autonomous system number and a preset protocol, the method further includes: synchronizing the routing information of the virtual machine to the route reflector through the first preset protocol tunnel, so as to synchronize the routing information of the virtual machine to the target switch through the route reflector; and synchronizing the routing information in the route reflector to the routing table corresponding to the first virtual routing and forwarding instance through the first preset protocol tunnel, where the routing information in the route reflector includes: the routing information of the physical server node.

[0046] In a cloud computing environment, especially in scenarios involving bare metal enhanced gateways, ensuring the accurate and efficient synchronization of network information (such as routing information) among different computing nodes, route reflectors, and target switches is the key to achieving seamless communication between virtual machines and bare metal servers in an overlay network.

[0047] In an embodiment of the present application, after obtaining the autonomous system number, the computing node establishes a first preset protocol tunnel from the computing node to the route reflector through the FRR instance according to the obtained autonomous system number and the preset BGP protocol. Through the first preset protocol tunnel, control plane information such as routing updates and MAC address learning results can be transmitted between the computing node and the route reflector.

[0048] Based on the first preset protocol tunnel, the computing node synchronizes the routing information of the virtual machine, for example, the MAC of the virtual machine, VXLAN tunnel endpoint (VXLAN Tunnel Endpoint, abbreviated as VTEP) information, etc., to the route reflector. After receiving the routing information of the virtual machine, the route reflector reflects it to other computing nodes and target switches (i.e., bare metal enhanced gateways) connected to it, ensuring that all network devices in the entire cloud platform have the latest routing information to support efficient data forwarding.

[0049] The route reflector not only receives and reflects the routing information of the virtual machine, but also collects and manages the routing information of physical server nodes (such as bare metal servers). The routing information of these physical servers is also synchronized to the routing table corresponding to the first virtual routing and forwarding instance of the computing node through the preset first preset protocol tunnel.

[0050] Through this embodiment, network devices in the cloud environment (including computing nodes, route reflectors, and target switches) can maintain a unified and updated routing information database, ensuring that traffic can be forwarded along the optimal path whether it is destined for a virtual machine or a bare-metal server, avoiding the bandwidth bottleneck and latency problems that may be caused by traditional centralized gateways. At the same time, due to the adoption of the standardized BGP protocol, this solution has good scalability and hardware compatibility, and can support the network interconnection requirements in a large-scale cloud environment without increasing complexity.

[0051] In an exemplary embodiment, after obtaining the autonomous system number, layer-2 virtual network identifier, and layer-3 virtual network identifier corresponding to the virtual machine from a control node through a proxy component, the method further includes: creating the first virtual routing and forwarding instance according to the layer-3 virtual network identifier; establishing a virtual Ethernet pair between a first bridging device and a second bridging device, where the first bridging device is the bridging device corresponding to the first virtual routing and forwarding instance, and the second bridging device is the bridging device corresponding to the Open Virtual Switch; and configuring a target component in the first virtual routing and forwarding instance through the layer-2 virtual network identifier and the layer-3 virtual network identifier, where the target component includes: layer-2 ports and layer-3 ports corresponding to the layer-2 bridging device and the layer-3 bridging device respectively, and both the layer-2 port and the layer-3 port are used to transmit the first virtual machine traffic.

[0052] In the embodiment of the present application, the computing node creates a first virtual routing and forwarding instance according to the layer-3 virtual network identifier obtained from the control node. A VRF instance can be understood as a network isolation environment that contains an independent routing table and forwarding table, allowing multiple logical networks to be constructed on a physical network, and each logical network has its own routing policy and network resources.

[0053] On the computing node, a virtual Ethernet pair is also established between a first bridging device (br-vrf) and a second bridging device (br-int, i.e., the integrated bridge of OpenvSwitch (abbreviated as OVS)), allowing direct communication between the two bridging devices through this virtual Ethernet pair, thereby supporting transparent forwarding of traffic between VRF and OVS.

[0054] Further, in the computing node, according to the layer-2 virtual network identifier and the layer-3 virtual network identifier, corresponding layer-2 bridging devices and layer-3 bridging devices are configured in the created first virtual routing and forwarding instance. Each bridging device will have a corresponding port for receiving and sending the traffic of the first virtual machine. Specifically, the layer-2 port is responsible for handling layer-2 traffic, and performs VXLAN encapsulation and decapsulation through the l2 vni set in the first virtual routing and forwarding instance to ensure the intercommunication of the layer-2 network. The layer-3 port is responsible for routing and forwarding layer-3 traffic, performs VXLAN processing according to the l3 vni, and directs the traffic to the correct next hop to support the routing decision of the layer-3 network.

[0055] In an exemplary embodiment, after configuring the target components in the first virtual routing and forwarding instance through the layer-2 virtual network identifier and the layer-3 virtual network identifier, the method further includes: receiving, by the first virtual routing and forwarding instance, the physical server traffic sent by the physical server node; sending, by the virtual Ethernet pair, the physical server traffic to the open virtual switch; and in the case where the destination node of the physical server traffic is the virtual machine, sending, by the open virtual switch, the physical server traffic to the virtual machine.

[0056] When the physical server node sends traffic to the virtual machine, the traffic starts from the physical server node and enters the first virtual routing and forwarding instance of the computing node. The virtual Ethernet pair (veth pair) between the first virtual routing and forwarding instance and the OVS acts as a bridge between the two, enabling seamless transmission of traffic between the VRF environment and the OVS. After the physical server traffic is received and processed by the first virtual routing and forwarding instance, the traffic is sent to the OVS through the virtual Ethernet pair. Once the physical server traffic reaches the OVS, the OVS checks the destination node of the traffic according to the flow table rules. If it is determined that the destination of this traffic is a certain virtual machine, the OVS will follow the corresponding forwarding logic and directly deliver the traffic to the target virtual machine. In this way, the physical server traffic can quickly pass through the forwarding rules of the OVS and reach the target virtual machine directly, avoiding unnecessary network paths and processing delays, and achieving more efficient and direct packet transmission.

[0057] In an exemplary embodiment, after sending the second virtual machine traffic to a target switch and instructing the target switch to send the second virtual machine traffic to the physical server node to enable network intercommunication between the virtual machine and the physical server node, the method further includes: sending the second virtual machine traffic to the target switch through the first virtual routing and forwarding instance; instructing the target switch to send the second virtual machine traffic to the physical server node through a second virtual routing and forwarding instance in the target switch to enable network intercommunication between the virtual machine and the physical server node.

[0058] In an embodiment of the present application, when a computing node receives traffic sent by a first virtual machine and its destination node is identified as a physical server, the traffic will be processed through the first virtual routing and forwarding instance of the computing node. The routing table of the first virtual routing and forwarding already contains routing information of the physical server node, and this information is synchronized through a router-reflector connected to the computing node. Further, through route matching in the first virtual routing and forwarding instance, the first virtual machine traffic is converted into second virtual machine traffic, and this process includes VXLAN encapsulation of the traffic to meet the transmission requirements of the overlay network.

[0059] The computing node sends the second virtual machine traffic to the target switch through the first virtual routing and forwarding instance. The target switch acts as an enhanced gateway in this scenario for connecting the physical server node and the computing node (including virtual machines). The target switch is not only connected to the computing node, but also connected to the physical server node and the router-reflector, so that the target switch can not only receive traffic from the computing node, but also obtain routing information through the router-reflector and has the ability to communicate directly with the physical server node.

[0060] It should be noted that in all embodiments of the present application, connections (such as the connection between the target switch and any one of the computing node, the router-reflector, and the physical server node, the connection between the router-reflector and the computing node, and the connection between the computing node and the control node) include: physical connection and communication connection.

[0061] After the destination switch receives the second virtual machine traffic, it processes the second virtual machine traffic through the second virtual routing and forwarding instance inside it. This processing may include VXLAN decapsulation and two-layer or three-layer routing decisions based on the destination address. The second virtual routing and forwarding instance sends the processed second virtual machine traffic to the physical server node, thus realizing network intercommunication between the virtual machine and the physical server. This process ensures the security of the traffic. At the same time, it also utilizes the characteristics of hardware acceleration, improves the forwarding efficiency, optimizes the traffic management in the overlay network, thereby realizing efficient network intercommunication between the virtual machine and the physical server node, while ensuring the security and stability of the network.

[0062] In an exemplary embodiment, instructing the destination switch to send the second virtual machine traffic to the physical server node through the second virtual routing and forwarding instance in the destination switch includes: instructing the destination switch to resolve the target virtual network identifier corresponding to the second virtual machine traffic, where the target virtual network identifier includes one of the following: the two-layer virtual network identifier corresponding to the virtual machine, the three-layer virtual network identifier corresponding to the virtual machine; instructing the second virtual routing and forwarding instance to determine the tenant network identifier corresponding to the physical server node based on the target virtual network identifier; instructing the second virtual routing and forwarding instance to send the second virtual machine traffic to the physical server node through the tenant network identifier.

[0063] In the embodiment of the present application, when the second virtual machine traffic arrives at the destination switch, the primary step is to resolve the target virtual network identifier carried by it. This identifier can be a two-layer virtual network identifier or a three-layer virtual network identifier, depending on the nature of the traffic (i.e., whether it is two-layer traffic or three-layer traffic). The identification of the target virtual network identifier is the basis for subsequent traffic processing and routing decisions. It guides the destination switch on how to decapsulate, identify, and further process the traffic, ensuring that the traffic can enter the correct VRF instance and then be sent to the correct destination.

[0064] The second virtual routing and forwarding instance determines the tenant network identifier associated with the physical server node based on the resolved target virtual network identifier. This step is based on the configuration and mapping rules of the switch, which define the correspondence between different virtual network identifiers and specific tenant networks. Determining the tenant network identifier is the key to accurate traffic routing. It ensures that the traffic only flows in the correct network environment, effectively avoiding cross-tenant traffic mistransmission and improving the security and efficiency of the network.

[0065] The second virtual routing and forwarding instance uses the determined tenant network identifier to send the second virtual machine traffic to the corresponding physical server node. This process may involve the decapsulation of VXLAN and further forwarding decisions based on the MAC address (layer 2 traffic) or IP address (layer 3 traffic). Furthermore, through the precise processing of the second virtual routing and forwarding instance, the traffic can reach the physical server node efficiently and without error, realizing the network interconnection between the virtual machine and the physical server.

[0066] Through a series of operations of the second virtual routing and forwarding instance in the target switch, including the resolution of the target virtual network identifier, the determination of the tenant network identifier, and the final forwarding of the traffic, a precise transmission path from the virtual machine to the physical server is constructed. This mechanism not only ensures the efficient, secure processing and forwarding of traffic in the overlay network environment but also maintains network isolation between different tenants, improving the network performance and security of the entire cloud computing platform.

[0067] In an exemplary embodiment, before routing and matching the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain the second virtual machine traffic, the method further includes: instructing the target switch to create the second virtual routing and forwarding instance; instructing the target switch to establish a second preset protocol tunnel between the target switch and the route reflector through the second virtual routing and forwarding instance and a preset protocol, and instructing the target switch to synchronize routing information with the route reflector through the second preset protocol tunnel.

[0068] It should be noted that the preset protocol in this embodiment is the BGP protocol, and the second preset protocol tunnel is the BGP tunnel established between the target switch and the route reflector. Furthermore, the target switch synchronizes the routing information of the physical server node to the route reflector through the second preset protocol tunnel and obtains the routing information of the route reflector from the route reflector. Among them, the routing information of the route reflector includes the routing information of the virtual machine.

[0069] In summary, by pre-creating the second virtual routing and forwarding instance on the target switch, establishing the preset protocol tunnel between the target switch and the route reflector, and continuous routing information synchronization, this embodiment demonstrates how to optimize network interconnection in the cloud computing environment, providing a solid technical foundation for the network interconnection between the virtual machine and the physical server.

[0070] To better understand the process of the above network interconnection method, the following further describes the implementation process of the above network interconnection method in combination with optional embodiments, but it is not used to limit the technical solutions of the embodiments of the present application.

[0071] The existing centralized gateway and distributed gateway solutions for current bare-metal nodes each have their drawbacks. An enhanced gateway using switch forwarding can be employed to address the bandwidth forwarding bottleneck issue of the centralized gateway. Meanwhile, switches are used to replace smart network cards to solve the cost and threshold problems of smart network cards.

[0072] For the bare metal (i.e., bare-metal node) of the enhanced gateway, traffic is forwarded through the Top-of-Rack (TOR) switch at the top of the rack. This application provides a bare-metal enhanced gateway based on a hardware switch, which can achieve the interconnection of layer 2 and layer 3 under the overlay networking of bare metal and virtual machines within a cloud platform.

[0073] The bare-metal enhanced gateway can solve the problem of overlay network interconnection between virtual machines and bare metal in computing nodes in a cloud computing environment. In a cloud computing scenario, bare metal is generally provided independently to tenant users, and VXLAN encapsulation cannot be performed on bare metal under overlay networking. Therefore, an enhanced gateway is adopted to meet this scenario. During the process of layer 2 and layer 3 interconnection between bare metal and virtual machines under overlay, it is necessary to consider how bare metal and virtual machines share the same plane, how to establish layer 2 connectivity between virtual machines on the computing node side and bare metal on the enhanced gateway switch side, how the MAC address of the virtual machine on the computing node side can be learned by the bare metal on the enhanced gateway side, and how the traffic originating from the virtual machine side of the computing node can reach the bare metal on the enhanced gateway side.

[0074] Optionally, for the issues that need to be considered above, as Figure 3 shown, this application uses a router-reflector to solve the problem of the same plane between virtual machines on the computing node side and bare machines on the enhanced gateway (i.e., the target switch) side. The virtual machines on the computing node establish a Border Gateway Protocol (BGP) tunnel with the router-reflector through the computing node (equivalent to the first preset protocol tunnel in the above embodiment), and synchronize the MAC and VTEP information of the virtual machines to the router-reflector through the FRR service launched by the ovn-bgp-agent of the computing node. The existing routes of the router-reflector will also be learned and generated into the routing table of the Virtual Routing and Forwarding (VRF). Similarly, the enhanced gateway also establishes a BGP connection with the router-reflector (equivalent to the second preset protocol tunnel in the above embodiment), and synchronizes the MAC of the bare metal on the enhanced gateway side and the VTEP configured by the switch to the router-reflector through the BGP connection, and at the same time receives all the current routing information of the router-reflector.

[0075] The following is an explanation of the technical terms used in the above content:

[0076] 1) The overlay network is a virtual network layer built on top of the underlying physical network. It allows logical connections to be established between devices in the network without being restricted by the underlying physical topology or network addresses. This network structure is very suitable for multi-tenant environments such as cloud platforms because it can provide each tenant with an independent and isolated network space even though they share the same physical infrastructure.

[0077] 3) Media Access Control (MAC): The hardware address of a network device, used as a unique identifier for network communication.

[0078] 4) Route reflector: In the BGP protocol, a route reflector is a mechanism used to reduce the number of BGP sessions within an autonomous system. It reflects routing information to other BGP neighbors, avoiding the need for all BGP routers to be interconnected.

[0079] 5) VXLAN tunnel endpoint: The terminal of VXLAN, used for encapsulating and decapsulating network data packets.

[0080] Combined with Figure 3 , the traffic of the virtual machine in the compute node (equivalent to the first virtual machine traffic in the above embodiment) will first enter the integrated bridge of OVS (Integrated Bridge of Open vSwitch, abbreviated as br-int); then, it will make decisions based on the flow table rules added by the ovn-bgp-agent. If the traffic is destined for bare metal, this flow table rule will send the traffic to the VRF (i.e., the first virtual routing and forwarding instance in the above embodiment), and route matching will be performed in the VRF (this is because the routes of the bare metal have been synchronized to the VRF of the compute node through the router-reflector); the traffic of the virtual machine destined for bare metal will be encapsulated with overlay in the VRF of the compute node (the traffic after route matching or encapsulation is equivalent to the second virtual machine traffic in the above embodiment), and then the traffic will be sent to the VTEP of the enhanced gateway. After the traffic reaches the enhanced gateway, VXLAN decapsulation will be performed, and the corresponding VLAN will be found according to the VNI value of the VXLAN (equivalent to the target virtual network identifier in the above embodiment), and then the traffic will be sent to the bare metal according to the MAC address.

[0081] Furthermore, as Figure 4 shown, the specific implementation solution of the enhanced gateway, and the specific implementation solution for the two- and three-layer overlay network intercommunication between the bare metal and the virtual machine in combination with the enhanced gateway are as follows:

[0082] First, for the control panel process design on the compute node side:

[0083] Deploy the Network Service (abbreviated as Neutron), ovn-nb, ovn-sb, and the OVN plugin bgpvpn-ovn-driver of Neutron on the control node. Deploy the ovn-bgp-agent and ovn-controller components on the compute node. (Among them, the northbound database ovn-nb corresponds to Figure 4 the ovn-nb-db in Figure 4 and the southbound database ovn-sb corresponds to

[0084] the ovn-sb-db in

[0084] ). It is specifically implemented through the following steps 31 to 35.

[0084] Step 31: During the creation of the neutron port of the virtual machine (abbreviated as VM), the bgpvpn-ovn-driver adds additional information such as bgp as, l2 vni, and l3 vni to the external identifiers (abbreviated as external_ids) of the virtual machine port and writes it to ovn-nb. Then synchronize the data from ovn-nb to ovn-sb.

[0085] Step 32: Run the ovn-bgp-agent on the compute node. When the neutron port data of the virtual machine is synchronized from ovn-nb to ovn-sb, the ovn-bgp-agent can capture this action and extract bgp as, l2 vni, and l3 vni from the port information of ovn-sb and write it to the local memory. At this time, the attribute information in the external_ids of the port has been passed from the Neutron control node to the compute node where the virtual machine is located.

[0086] Step 33: The ovn-bgp-agent configures evpnbgp (where Enhanced Virtual Private Network is abbreviated as EVPN) according to the bgp as information extracted in Step 32 through frr vtysh, establishes a BGP link to the router-reflector, creates a VM route, synchronizes the route to the router-reflector through the evpn bgp protocol, and synchronizes other route information in the router-reflector to the VRF.

[0087] Step 34: For the l2 vni and l3 vni extracted by the ovn-bgp-agent, create a VRF according to the l3 vni and specify the vrf table as the l3 vni. Create a br-ovs and br-vrf veth pair (equivalent to the virtual Ethernet pair in the above embodiments), and connect the OVS traffic to the VRF; create a linux bridge in the VRF according to the l2 vni and l3 vni, and hang the br-vrf on the br-l2. The l2 vni is the VNI value of the tunnel, and the l3 vni is the one-to-one binding of the evpn l3 vni and the tenant. Create VXLAN interfaces on the br-l2 and br-l3 respectively, and the VNIs are the l2 vni and l3 vni respectively.

[0088] Step 35: The ovn-bgp-agent adds high-priority flow tables to the OVS. For ports of the baremetal type (a baremetal port refers to a network port connected to a bare metal server), the outgoing traffic will skip the geneve encapsulation process, introduce the traffic into the VRF, and perform layer 2 and layer 3 differentiation within the VRF, and send the traffic out from the corresponding l2-br vxlan interface or l3 vxlan interface respectively. Similarly, for incoming VXLAN traffic, it will enter the kernel for decapsulation, and then jump to the corresponding openflow table through the high-priority flow table of the br-ovs.

[0089] The following explains the technical terms in the above steps 31 to 35.

[0090] 1) Neutron: In the OpenStack cloud infrastructure, Neutron is a service that provides network functions for the cloud environment, supporting the creation and management of various virtual network resources, including but not limited to networks, subnets, routers, firewalls, load balancers, etc. It is a key component in OpenStack for defining and managing the network topology, allowing users to customize complex network structures to meet the network requirements of virtual machines, containers and other resources.

[0091] 2) ovn-nb-db: It is a database in the OVN architecture, used to store network topology information, including networks, ports, routes, etc. The northbound database is the place for data exchange between the controller and the network application, and is used for the logical network state of the control plane. ovn-sb-db: It is another database in OVN, mainly used to store state information related to the data plane, such as flow table rules. The southbound database is the place for data exchange between the controller and network devices (such as OVS switches), and is used to reflect the state of actual network devices.

[0092] 3) bgpvpn-ovn-driver: BGP-based Virtual Private Network for Open Virtual Network Driver, abbreviated as bgpvpn-ovn-driver. This Neutron plugin is used to implement the integration of bgpvpn and OVN in the OpenStack environment. It allows users to define and manage bgpvpn services and synchronize the service parameters to the ovn-nb-db, thus automatically configuring the OVN network to support bgpvpn.

[0093] 4) ovn-bgp-agent, the Open Virtual Network Border Gateway Protocol Agent, is a component running on compute nodes. It is responsible for exchanging routing information with Router-Reflector via the BGP protocol, enabling compute nodes to understand the reachability of other nodes in the network and synchronizing information such as the MAC address and VTEP of virtual machines to Router-Reflector.

[0094] 5) ovn-controller: the Open Virtual Network Controller, is the core component in the OVN architecture. It is responsible for processing requests from the northbound database and issuing instructions to the southbound database, ultimately affecting the behavior of the data plane. ovncontroller is the core for controlling network policies and flow table rules, ensuring the correct configuration of the network and the correct handling of traffic.

[0095] 6) Neutron Port: that is, Network Port. In the Neutron network service of OpenStack, a network port represents a connection point of network resources and can be attached to virtual machines, bare metal servers, or other network resources. Neutron Port is the basic unit for defining network connections and contains IP addresses, MAC addresses, security groups, and other network attributes.

[0096] 7) external_ids: In the ovn-nb-db, external_ids is a collection of key-value pairs used to store information that does not belong to the standard OVN database model. For example, when a virtual machine port is created, external_ids can be used to store additional metadata, such as the associated bgp as number, l2 vni, and l3 vni values.

[0097] 8) frr vtysh: A command-line interface (CLI) tool in the FRR software suite used to configure and manage routing protocols, allowing administrators to perform detailed configuration and status queries on routing devices through the command-line interface. FRR is an open-source software package for routing functions, supporting multiple routing protocols such as BGP, OSPF, RIP, etc.

[0098] 9) Layer 2 bridging device br-l2 and Layer 3 bridging device br-l3: br-l2 and br-l3 represent bridging devices for handling Layer 2 and Layer 3 traffic respectively. In the VXLAN and EVPN architectures, br-l2 is used to handle Layer 2 VXLAN traffic, while br-l3 processes Layer 3 routing information and traffic associated with EVPN.

[0099] 10) veth pair: Virtual Ethernet pair. A veth pair is a virtual network device provided by the Linux kernel that allows creating a pair of full-duplex virtual Ethernet devices within the kernel, typically used to establish connections between different network namespaces for traffic forwarding. In this application, the veth pair is used to connect br-ovs and br-vrf to ensure that traffic can correctly enter the VRF environment from the OVS bridging device.

[0100] 11) geneve: Generic Network Encapsulation (abbreviated as Geneve). Geneve is a network encapsulation protocol mainly used to build overlay networks within data centers. It can encapsulate Layer 2 network packets and transmit them through the Layer 3 network, while providing high efficiency, flexible header formats, and multiple encapsulation options.

[0101] 12) OpenFlow table: "OpenFlow Table". In Open vSwitch (OVS) or any network device implementing the OpenFlow protocol, flow tables are where flow rules are stored. Flow rules define how data packets are processed and forwarded in the device. Each flow table entry contains matching conditions and actions to be executed. When a data packet arrives at an OpenFlow switch, it is checked to determine if it matches a rule in the flow table. If there is a match, the data packet will be processed in the manner specified by the rule, such as being forwarded to a specific port, performing certain network operations, or being discarded. If no matching flow table entry is found, the data packet may be sent to the controller for further processing. In OVS, the flow table is located within the bridge device and is a core part of the OpenFlow architecture, used to filter and forward network data packets according to predefined rules. A controller, such as ovn-controller, can remotely modify these flow tables to adapt to network changes or policy updates, thus ensuring correct data packet processing and routing behavior.

[0102] Second, for the control panel process design of the switch logic test.

[0103] It is specifically implemented through the following steps 41 to 45.

[0104] Step 41: Uniformly plan the access VLAN for the switch ports accessed by the compute node vtep IP address, and create a vlan if (vlan Interface, which refers to the virtual interface associated with a specific VLAN) for the corresponding VLAN. Configure the vtep IP on the vlan if as the vtep IP on the bare metal side. This can ensure that the bare metal is interconnected with all compute node VTEPs through the switch. As shown in this application Figure 4 it is planned that 192.168.122.0 / 24 is used as the VTEP network, and the VLAN is planned to be 88. Among them, the vtep IP of the compute node is 192.168.122.8, the VTEP of the enhanced gateway is 192.168.122.6, and it is located on the vlan if of vlan 88 of the switch. The router-reflector node is configured with 192.168.122.4 to ensure the intercommunication of VTEP network BGP.

[0105] Step 42: Create an access VLAN for the tenant on the bare metal access side, the EVPN L3 VNI VLAN for the tenant, and the L2 VNI for the tunnel. Create a tenant VRF (equivalent to the second virtual routing and forwarding instance in the above embodiment), and bind the access VLAN, the EVPN L3 VNI VLAN, and the L2 VNI of the tunnel to the VRF.

[0106] Step 43: Configure the switch to establish BGP, and activate the neighbor router - reflector in the address - family l2vpn evpn, and advertise - all - vni. The tunnel uses the router bgp as instance for interaction to transmit EVPN type2 and type3 messages.

[0107] Step 44: Configure the switch to enable the EVPN to publish type - 5 routes in the corresponding VRF. The type - 5 routes can be published using the commands network and redistribute connected. Through steps 43 and 44, the route publishing and learning between the switch and the router - reflector can be achieved, and the learned routes will be synchronized to the corresponding VRF.

[0108] Step 45: Configure the switch L3 EVPN tunnel. Create an L3 EVPN tunnel, specify the access vlanif of the VTEP as the source IP address of the overlay - evpn, and configure the mapping relationship between the VRF and the VNI (equivalent to the target virtual network identifier in the above embodiment), and the mapping relationship between the bare metal access - side tenant vlan (equivalent to the tenant network identifier in the above embodiment) and the VNI in the L3 EVPN tunnel.

[0109] Combined with the above control - plane process design on the computing node side and the bare metal node side of the computing connection, the data - plane traffic transmission solution between the virtual machines in the computing node and the bare metal node is as follows:

[0110] 1) The two - layer and three - layer traffic from the virtual machine to the bare machine.

[0111] When the traffic of the virtual machine enters the ovs openflow table and after the control rules are matched, if the destination port is a bare metal port, the high-priority flow control rules will be matched and the traffic will enter the VRF through br-ovs. In the VRF, the two- and three-layer routing matching of the destination IP address is performed. According to the EVPN control rules, if the current traffic is two-layer traffic, the l2 vni will be encapsulated, and if the current traffic is three-layer traffic, the evpn l3 vni will be encapsulated and the packet will be sent out. When the packet reaches the corresponding bare metal switch VTEP, the switch will perform the de-encapsulation of the VTEP, map it to the corresponding VLAN and VRF through the VNI of VXLAN, and then send it to the corresponding bare metal through the route lookup.

[0112] 2) The two- and three-layer traffic from the bare metal to the virtual machine side.

[0113] Similarly, the traffic of the bare metal is matched to the corresponding VRF through the access vlan it accesses. After entering the VRF, the corresponding routing rules are matched through the destination IP for VXLAN encapsulation, and then it is sent to the vxlan vtep port of the corresponding computing node. After the VXLAN de-encapsulation, the traffic of the VRF is connected to the OVS through br-vrf and br-ovs veth pair, and the high-priority flow control rules are issued by the ovn-bgp-agent to directly jump to the corresponding table for processing.

[0114] In summary, as a network optimization solution in the cloud computing scenario, the bare metal enhanced gateway mainly brings the following beneficial effects:

[0115] 1) High performance and low latency.

[0116] The enhanced gateway multiplexes the TOR (Top-of-Rack switch) of the bare metal for VXLAN encapsulation / de-encapsulation. The data plane is completely processed by hardware devices without the participation of software gateways, avoiding the performance loss of the traditional virtualization layer.

[0117] It supports the same network bandwidth as physical machines. The end-to-end path is directly completed by hardware devices, reducing the intermediate forwarding links, and is suitable for high-throughput scenarios such as High Performance Computing (HPC) and core databases. Moreover, through the hardware acceleration of the switch, it can carry a higher density of network traffic, meeting the requirements of enterprise-level applications for stability and real-time performance.

[0118] 2) Significant cost-effectiveness.

[0119] There is no need to purchase additional intelligent network cards or dedicated gateway devices. Instead, the existing switches are directly utilized to implement the functions, significantly reducing the hardware investment cost. Compared with the intelligent network card solution, the enhanced gateway has a lower deployment cost, is compatible with multi-vendor devices, and has a more open ecosystem. Moreover, by adopting standardized switch hardware, the upgrade complexity and operation and maintenance risks caused by the tight coupling between the intelligent network card and the cloud platform are avoided.

[0120] 3) Enhanced security and stability.

[0121] The bare metal server itself provides physical-level isolation. The enhanced gateway realizes VPC network encapsulation through hardware devices, further ensuring the security of data transmission and avoiding potential attacks on the virtualization layer.

[0122] Through the description of the above implementation manners, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner.

[0123] In this embodiment, a network interconnection device is further provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0124] Figure 5 is the architecture diagram of the network interconnection system according to the embodiment of the present application. As Figure 5 shown, the system includes:

[0125] Computing node 52, route reflector 54, target switch 56, physical server node 58;

[0126] The computing node is used to, when the destination node of the first virtual machine traffic is the physical server node, perform route matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain the second virtual machine traffic, and send the second virtual machine traffic to the target switch. Among them, the computing node includes: a virtual machine that outputs the first virtual machine traffic and the first virtual routing and forwarding instance, and the routing information of the physical server node has been synchronized to the routing table through the route reflector connected to the computing node;

[0127] The target switch is respectively connected to the physical server node, the route reflector, and the computing node, and is used to send the second virtual machine traffic to the physical server node.

[0128] Through the above system, for the first virtual machine traffic output by the virtual machine in the computing node and destined for the physical server node, the first virtual machine traffic is routed and matched through the routing table corresponding to the first virtual routing and forwarding instance in the computing node; the routing information of the physical server node has been synchronized to the routing table through the route reflector connected to the computing node; the obtained second virtual machine traffic is sent to the target switch, so that the target switch sends the second virtual machine traffic to the physical server node, thereby enabling network intercommunication between the virtual machine and the physical server node. Among them, the target switch is respectively connected to the physical server node, the route reflector and the computing node. Therefore, it is possible to solve the defects of the soft gateway used between the virtual machine and the bare metal node in the computing node in the cloud computing environment, such as bandwidth forwarding bottleneck and high solution cost in the related art, and further solve the technical problem of poor network intercommunication effect between the virtual machine and the bare metal node, thereby improving the network intercommunication effect between the virtual machine and the bare metal node.

[0129] In an exemplary embodiment, the system further includes: a control node connected to the computing node; the computing node further includes: a proxy component and a free-range routing instance; the proxy component is configured to obtain the autonomous system number, the layer-2 virtual network identifier, and the layer-3 virtual network identifier corresponding to the virtual machine from the control node; the free-range routing instance is configured to establish a first preset protocol tunnel between the computing node and the route reflector according to the autonomous system number and a preset protocol.

[0130] In an exemplary embodiment, the control node further includes: a southbound database and a driver component; the driver component is configured to add the autonomous system number, the layer-2 virtual network identifier, and the layer-3 virtual network identifier to the external identifier of the network port when the network port corresponding to the virtual machine is created; the proxy component is further configured to monitor the southbound database in the control node, and extract the autonomous system number, the layer-2 virtual network identifier, and the layer-3 virtual network identifier from the external identifier when it is detected that the external identifier is synchronized to the southbound database.

[0131] In an exemplary embodiment, the computing node is further configured to synchronize the routing information of the virtual machine to the route reflector through the first preset protocol tunnel, and the route reflector is configured to synchronize the routing information of the virtual machine to the target switch; the computing node is further configured to synchronize the routing information in the route reflector to the routing table corresponding to the first virtual routing and forwarding instance through the first preset protocol tunnel, where the routing information in the route reflector includes: the routing information of the physical server node.

[0132] In an exemplary embodiment, the computing node further includes: a first virtual routing and forwarding instance created according to the three-layer virtual network identifier, and a virtual Ethernet pair established between a first bridging device and a second bridging device, where the first bridging device is the bridging device corresponding to the first virtual routing and forwarding instance, and the second bridging device is the bridging device corresponding to the open virtual switch; the first virtual routing and forwarding instance includes: a target component, and the target component includes: a second-layer port and a third-layer port corresponding to the second-layer bridging device and the third-layer bridging device respectively, where the target component is configured in the first virtual routing and forwarding instance through the second-layer virtual network identifier and the three-layer virtual network identifier, and both the second-layer port and the third-layer port are used to transmit the first virtual machine traffic.

[0133] In an exemplary embodiment, the computing node is further configured to receive physical server traffic sent by the physical server node through the first virtual routing and forwarding instance; the computing node is further configured to send the physical server traffic to the open virtual switch through the virtual Ethernet pair; the computing node is further configured to, when determining that the destination node of the physical server traffic is the virtual machine, send the physical server traffic to the virtual machine through the open virtual switch.

[0134] In an exemplary embodiment, the computing node is further configured to send the second virtual machine traffic to the target switch through the first virtual routing and forwarding instance; the target switch further includes: a second virtual routing and forwarding instance, configured to send the second virtual machine traffic to the physical server node, so that network intercommunication is achieved between the virtual machine and the physical server node.

[0135] In an exemplary embodiment, the target switch is further configured to resolve the target virtual network identifier corresponding to the second virtual machine traffic, where the target virtual network identifier includes one of the following: the second-layer virtual network identifier corresponding to the virtual machine, the three-layer virtual network identifier corresponding to the virtual machine; the second virtual routing and forwarding instance is further configured to determine the tenant network identifier corresponding to the physical server node based on the target virtual network identifier; and send the second virtual machine traffic to the physical server node through the tenant network identifier.

[0136] For the description of the features in the corresponding embodiment of the network intercommunication system, reference can be made to the relevant description in the corresponding embodiment of the network intercommunication method, which will not be elaborated here one by one.

[0137] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above-described network interconnection method embodiments.

[0138] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any of the above-described network interconnection method embodiments when running.

[0139] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media that can store computer programs such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs.

[0140] An embodiment of the present application further provides a computer program product. The computer program product includes a computer program, and the steps in any of the above-described network interconnection method embodiments are implemented when the computer program is executed by a processor.

[0141] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and the steps in any of the above-described network interconnection method embodiments are implemented when the computer program is executed by a processor.

[0142] Those skilled in the art can further realize that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.

[0143] The above provides a detailed introduction to a network interconnection provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.

Claims

1. A network interconnection method, characterized in that, Including: When the destination node of the first virtual machine traffic is a physical server node, route-match the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain second virtual machine traffic. Wherein, the computing node includes: a virtual machine that outputs the first virtual machine traffic and the first virtual routing and forwarding instance, and the routing information of the physical server node has been synchronized to the routing table through a route reflector connected to the computing node; Send the second virtual machine traffic to the target switch, and instruct the target switch to send the second virtual machine traffic to the physical server node, so that network intercommunication is achieved between the virtual machine and the physical server node. Wherein, the target switch is respectively connected to the physical server node, the route reflector and the computing node.

2. The network interconnection method according to claim 1, wherein Before route-matching the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain second virtual machine traffic, the method further includes: Obtain the autonomous system number, layer 2 virtual network identifier, and layer 3 virtual network identifier corresponding to the virtual machine from a control node connected to the computing node through a proxy component; Establish a first preset protocol tunnel between the computing node and the route reflector according to the autonomous system number and a preset protocol through a free-range routing instance.

3. The network interconnection method according to claim 2, wherein Obtaining the autonomous system number, layer 2 virtual network identifier, and layer 3 virtual network identifier corresponding to the virtual machine from a control node connected to the computing node through a proxy component includes: Monitoring the southbound database in the control node through the proxy component; When it is detected that the external identifier of the network port corresponding to the virtual machine is synchronized to the southbound database, extract the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier from the external identifier. Wherein, the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier are added to the external identifier by a driver component in the control node when the network port is created.

4. The network interconnection method according to claim 2, wherein After establishing a first preset protocol tunnel between the computing node and the route reflector according to the autonomous system number and a preset protocol through a free-range routing instance, the method further includes: Synchronize the routing information of the virtual machine to the route reflector through the first preset protocol tunnel, so as to synchronize the routing information of the virtual machine to the target switch through the route reflector; and Synchronize the routing information in the route reflector to the routing table corresponding to the first virtual routing and forwarding instance through the first preset protocol tunnel. Wherein, the routing information in the route reflector includes: the routing information of the physical server node.

5. The network interconnection method according to claim 2, wherein After obtaining the autonomous system number, layer 2 virtual network identifier, and layer 3 virtual network identifier corresponding to the virtual machine from a control node connected to the computing node through a proxy component, the method further includes: Create the first virtual routing and forwarding instance according to the layer 3 virtual network identifier; Establish a virtual Ethernet pair between a first bridging device and a second bridging device, where the first bridging device is the bridging device corresponding to the first virtual routing and forwarding instance, and the second bridging device is the bridging device corresponding to the open virtual switch; and Configure a target component in the first virtual routing and forwarding instance through the layer 2 virtual network identifier and the layer 3 virtual network identifier, where the target component includes: layer 2 ports and layer 3 ports corresponding to the layer 2 bridging device and the layer 3 bridging device respectively, and both the layer 2 port and the layer 3 port are used to transmit the first virtual machine traffic.

6. The network interconnection method according to claim 5, wherein After configuring the target component in the first virtual routing and forwarding instance through the layer 2 virtual network identifier and the layer 3 virtual network identifier, the method further includes:[[]] Receive physical server traffic sent by the physical server node through the first virtual routing and forwarding instance; Send the physical server traffic to the open virtual switch through the virtual Ethernet pair; When determining that the destination node of the physical server traffic is the virtual machine, send the physical server traffic to the virtual machine through the open virtual switch.

7. The network interconnection method according to claim 1, characterized in that Send the second virtual machine traffic to a target switch and instruct the target switch to send the second virtual machine traffic to the physical server node, so that the virtual machine and the physical server node achieve network intercommunication, including:[[]] Send the second virtual machine traffic to the target switch through the first virtual routing and forwarding instance; Instruct the target switch to send the second virtual machine traffic to the physical server node through the second virtual routing and forwarding instance in the target switch, so that the virtual machine and the physical server node achieve network intercommunication.

8. The network interconnection method according to claim 7, wherein Instruct the target switch to send the second virtual machine traffic to the physical server node through the second virtual routing and forwarding instance in the target switch, including:[[]] Instruct the target switch to resolve the target virtual network identifier corresponding to the second virtual machine traffic, where the target virtual network identifier includes one of the following: the layer 2 virtual network identifier corresponding to the virtual machine, the layer 3 virtual network identifier corresponding to the virtual machine; Instruct the second virtual routing and forwarding instance to determine the tenant network identifier corresponding to the physical server node based on the target virtual network identifier; Instruct the second virtual routing and forwarding instance to send the second virtual machine traffic to the physical server node through the tenant network identifier.

9. The network interconnection method according to claim 7, wherein Before performing route matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain the second virtual machine traffic, the method further includes:[[]] Instruct the target switch to create the second virtual routing and forwarding instance; Instruct the target switch to establish a second preset protocol tunnel between the target switch and the route reflector through the second virtual routing and forwarding instance and the preset protocol, and instruct the target switch to synchronize routing information with the route reflector through the second preset protocol tunnel.

10. A network interconnection system, characterized in that, It includes: A computing node, configured to, when the destination node of the first virtual machine traffic is a physical server node, perform routing matching on the first virtual machine traffic through the routing table corresponding to the first virtual routing and forwarding instance to obtain second virtual machine traffic, and send the second virtual machine traffic to a target switch, where the computing node includes: a virtual machine that outputs the first virtual machine traffic and the first virtual routing and forwarding instance, and the routing information of the physical server node has been synchronized to the routing table through a route reflector connected to the computing node; The target switch, which is respectively connected to the physical server node, the route reflector, and the computing node, is configured to send the second virtual machine traffic to the physical server node.

11. The network interconnection system according to claim 10, wherein The system further includes: a control node connected to the computing node; The computing node further includes: a proxy component and a free-range routing instance; The proxy component is configured to obtain the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier corresponding to the virtual machine from the control node; The free-range routing instance is configured to establish a first preset protocol tunnel between the computing node and the route reflector according to the autonomous system number and the preset protocol.

12. The network interconnection system according to claim 11, wherein The control node further includes: a southbound database and a driver component; the driver component is configured to add the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier to the external identifier of the network port when the network port corresponding to the virtual machine is created; The proxy component is further configured to monitor the southbound database in the control node, and extract the autonomous system number, the layer 2 virtual network identifier, and the layer 3 virtual network identifier from the external identifier when it detects that the external identifier is synchronized to the southbound database.

13. The network interconnection system according to claim 11, wherein The computing node is further configured to synchronize the routing information of the virtual machine to the route reflector through the first preset protocol tunnel; The route reflector is configured to synchronize the routing information of the virtual machine to the target switch; The computing node is further configured to synchronize the routing information in the route reflector to the routing table corresponding to the first virtual routing and forwarding instance through the first preset protocol tunnel, where the routing information in the route reflector includes: the routing information of the physical server node.

14. The network interconnection system according to claim 11, wherein The computing node further includes: the first virtual routing and forwarding instance created according to the three-layer virtual network identifier, and a virtual Ethernet pair established between a first bridging device and a second bridging device, where the first bridging device is the bridging device corresponding to the first virtual routing and forwarding instance, and the second bridging device is the bridging device corresponding to the open virtual switch; The first virtual routing and forwarding instance includes: a target component, and the target component includes: a second-layer port and a third-layer port corresponding to the second-layer bridging device and the third-layer bridging device respectively, where the target component is configured in the first virtual routing and forwarding instance through the second-layer virtual network identifier and the third-layer virtual network identifier, and both the second-layer port and the third-layer port are used for transmitting the first virtual machine traffic.

15. The network interconnection system according to claim 14, wherein The computing node is further configured to receive the physical server traffic sent by the physical server node through the first virtual routing and forwarding instance; The computing node is further configured to send the physical server traffic to the open virtual switch through the virtual Ethernet pair; The computing node is further configured to, when determining that the destination node of the physical server traffic is the virtual machine, send the physical server traffic to the virtual machine through the open virtual switch.

16. The network interconnection system according to claim 10, wherein The computing node is further configured to send the second virtual machine traffic to the target switch through the first virtual routing and forwarding instance; The target switch further includes: a second virtual routing and forwarding instance, configured to send the second virtual machine traffic to the physical server node, so that network interconnection is achieved between the virtual machine and the physical server node.

17. The network interconnection system according to claim 16, wherein The target switch is further configured to resolve the target virtual network identifier corresponding to the second virtual machine traffic, where the target virtual network identifier includes one of the following: the second-layer virtual network identifier corresponding to the virtual machine, the third-layer virtual network identifier corresponding to the virtual machine; The second virtual routing and forwarding instance is further configured to determine the tenant network identifier corresponding to the physical server node based on the target virtual network identifier; and send the second virtual machine traffic to the physical server node through the tenant network identifier.

18. An electronic device, characterized in that, including: a memory, configured to store a computer program; a processor, configured to implement the steps of the network interconnection method according to any one of claims 1 to 9 when executing the computer program.

19. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, where the computer program, when executed by the processor, implements the steps of the network interconnection method according to any one of claims 1 to 9.

20. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the network interconnection method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Container orchestration engine cluster management system based on virtual network bridge

    CN112491984A

  • Flow management method, device and apparatus based on virtual gateway

    CN113259272A

  • Network intercommunication method of virtual machine manager cluster, computing equipment and storage medium

    CN113630275A

  • Network intercommunication method and device, computer equipment and storage medium

    CN118590346A

  • Multiple virtual network interface support for virtual execution elements

    US20200073692A1

Cited By

  • Network communication establishment method and system and computer equipment

    CN120528866A

  • Fast range routing method based on key flow

    CN120602394A

  • Virtual machine MAC address learning method and device, equipment, medium and product

    CN120614324A

  • Power supply control method and device of double-node server, computer equipment and medium

    CN120762514A

  • Network intercommunication method, electronic device, storage medium and program product

    CN121193562A