Flow transmission method and device and tenant gateway
By utilizing the forwarding mechanism of virtual MAC addresses in the cloud network, the problem of virtual machine traffic interruption during the tenant gateway master-shop switching is solved, and uninterrupted traffic transmission and service continuity are achieved, reducing costs.
Patent Information
- Application Number
- CN202510681020.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-07-22
AI Technical Summary
In the cloud network, when the tenant gateway master and backup gateway switches, the traffic of the virtual machine accessing the Internet is interrupted for a long time, affecting business continuity.
The controller's forwarding configuration information instructions are received through the original main gateway, and the target traffic is forwarded to the new main gateway using the virtual MAC address, avoiding waiting for the table entry of the previous switch and computing node to update, and forwarding traffic directly to the new main gateway.
It realizes the uninterrupted transmission of virtual machine access to Internet traffic, improves business continuity, reduces the demand for switch hardware upgrades, and reduces the cost of cloud networks.
Smart Images

Figure CN120358136A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud network technologies, and in particular, to a traffic transmission method, an apparatus, and a tenant gateway. Background Art
[0002] In a cloud network, the Virtual Router Redundancy Protocol (VRRP) technology is adopted to implement redundant backup of tenant gateways in a primary-backup mode. A tenant gateway deployed with VRRP includes a primary gateway (Master) and at least one backup gateway (Backup), and the primary gateway implements the actual forwarding function. When the primary gateway fails, the backup gateway becomes the new primary gateway and takes over the work of the original primary gateway.
[0003] In related technologies, in the scenario where the primary and backup gateways of a tenant gateway in a cloud network are switched, the upstream switch of the tenant gateway needs to update the Media Access Control (MAC) address entry, and the virtual switch in the computing node needs to update the ARP entry so that traffic can reach the new primary gateway.
[0004] However, in related technologies, there is a problem that the traffic of virtual machines in the computing node accessing the Internet is interrupted for a long time, which affects service continuity. Summary of the Invention
[0005] Based on this, this application provides a traffic transmission method, an apparatus, and a tenant gateway, which can avoid the problem that the traffic of virtual machines accessing the Internet is interrupted for a long time and improve service continuity.
[0006] In a first aspect, this application provides a traffic transmission method, which is applied to a tenant gateway deployed with primary and backup gateways. The method includes:
[0007] When a primary-backup gateway switch occurs in the tenant gateway, the original primary gateway in the tenant gateway sends gateway switch indication information to a controller;
[0008] The original primary gateway receives a forwarding configuration information instruction sent by the controller; the forwarding configuration information instruction instructs the original primary gateway to forward target traffic to the new primary gateway, and the gateway address corresponding to the target traffic is a virtual Media Access Control (MAC) address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong;
[0009] The original primary gateway determines the target traffic from the traffic sent by the virtual switch in the computing node according to the forwarding configuration information instruction, and forwards the target traffic to the new primary gateway;
[0010] The new primary gateway forwards the target traffic to the Internet.
[0011] In some embodiments, the forwarding configuration information instruction includes an access control list rule and a forwarding rule based on the access control list;
[0012] The access control list rule indicates that in the virtual extensible local area network (VXLAN) header encapsulating the received traffic, when the MAC address is any MAC address and the destination MAC address is the virtual MAC address, the received traffic is the target traffic;
[0013] The forwarding rule based on the access control list indicates that the original primary gateway forwards the target traffic to the new primary gateway.
[0014] In some embodiments, the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction, and forwards the target traffic to the new primary gateway, including:
[0015] The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node according to the access control list rule in the forwarding configuration information instruction;
[0016] The original primary gateway forwards the target traffic to the new primary gateway according to the forwarding rule based on the access control list in the forwarding configuration information instruction.
[0017] In some embodiments, the method further includes:
[0018] The original primary gateway determines other traffic other than the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction, and the original primary gateway forwards the other traffic to the new primary gateway;
[0019] The new primary gateway forwards the other traffic to the gateway of another backup group according to the destination MAC address in the VXLAN header encapsulating the other traffic, so that the gateway of the other backup group forwards the other traffic to the Internet.
[0020] In some embodiments, the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction, including:
[0021] The original primary gateway determines the destination MAC address in the VXLAN header of the traffic sent by the virtual switch of the computing node;
[0022] According to the forwarding configuration information instruction, the traffic with the destination MAC address in the VXLAN header being the virtual MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong is determined as the target traffic.
[0023] In some embodiments, the method further includes:
[0024] In the case of a primary / standby gateway switchover occurring at the tenant gateway, the new primary gateway broadcasts Address Resolution Protocol (ARP) packets, which are used by the upper-level switch device of the tenant gateway to update the egress interface corresponding to the new primary gateway in the MAC address table entry;
[0025] The original primary gateway receives traffic sent by the virtual switch of the compute node, including:
[0026] Before the upper-level switch device updates the egress interface corresponding to the new primary gateway in the MAC address table entry, the original primary gateway receives the traffic sent by the virtual switch of the compute node through the upper-level switch device.
[0027] In some embodiments, the traffic received by the original primary gateway is encapsulated in a VXLAN packet, which is a packet obtained by the virtual switch encapsulating the traffic sent by the virtual machine in the compute node;
[0028] The original primary gateway forwards the target traffic to the new primary gateway, including: the original primary gateway forwards the VXLAN packet encapsulating the target traffic to the new primary gateway;
[0029] Before the new primary gateway forwards the target traffic to the Internet, the method further includes: the new primary gateway decapsulates the VXLAN packet to obtain the target traffic.
[0030] In some embodiments, the method further includes:
[0031] In the case of the original primary gateway resuming use, the original primary gateway deletes the forwarding configuration information instruction saved in the original primary gateway;
[0032] The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node and sends the target traffic to the Internet.
[0033] In a second aspect, the present application provides a traffic transmission device, which includes:
[0034] A handover indication sending module, configured to, in the case of a primary / standby gateway switchover occurring at the tenant gateway, the original primary gateway in the tenant gateway sends gateway handover indication information to the controller;
[0035] A configuration receiving module, configured to the original primary gateway receives the forwarding configuration information instruction sent by the controller; the forwarding configuration information instruction instructs the original primary gateway to forward the target traffic to the new primary gateway, the gateway address corresponding to the target traffic is the virtual Media Access Control (MAC) address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong;
[0036] A traffic forwarding module is used for the original primary gateway to determine target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, and forward the target traffic to the new primary gateway; the new primary gateway forwards the target traffic to the Internet.
[0037] In a third aspect, the present application provides a tenant gateway, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps of the method according to any one of the first aspect are implemented.
[0038] In the technical solution provided by the embodiments of the present application, the original primary gateway receives the forwarding configuration information instruction sent by the controller, and when the original primary gateway receives the target traffic, it forwards the target traffic to the new primary gateway, so that the new primary gateway forwards the target traffic to the Internet, thus eliminating the need to wait for the MAC address table entry of the upper-level switch of the tenant gateway to be updated. In this way, even if the MAC address table entry is not updated, when the target traffic is forwarded to the original primary gateway, the original primary gateway can still forward the target traffic to the new primary gateway, and the new primary gateway forwards the target traffic to the Internet, thereby avoiding the problem of long-term interruption of the traffic for virtual machines to access the Internet, and even achieving the effect of uninterrupted traffic transmission, improving the business continuity; and by using the gateway address corresponding to the target traffic as the virtual media access control (MAC) address, and the virtual MAC address being the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong, even if the primary and standby gateways of the tenant gateway are switched, the MAC addresses of the original primary gateway and the new primary gateway are the same, without the need to update the ARP table entry of the virtual switch in the compute node, and the virtual switch in the compute node can also forward the target traffic to the new primary gateway, avoiding the phenomenon that the MAC addresses of the original primary gateway and the new primary gateway are different, resulting in the need to wait for the ARP table entry of the virtual switch in the compute node to be updated before the target traffic can be forwarded to the new primary gateway, thereby further reducing the probability of long-term interruption of the traffic for virtual machines to access the Internet and improving the business continuity; and, this solution does not require hardware upgrade of the switch, avoiding the phenomenon of upgrading the switch in the related art to reduce the interruption duration of the traffic for virtual machines to access the Internet, so this solution can also reduce the cost of the cloud network. Description of the Drawings
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can be obtained according to these drawings.
[0040] Figure 1 A schematic diagram of the cloud network architecture provided for some embodiments;
[0041] Figure 2 Flow transmission method flow schematic diagram provided for some embodiments;
[0042] Figure 3 Schematic diagram of the traffic format sent by a virtual machine in a computing node provided for some embodiments;
[0043] Figure 4 Schematic diagram of the format of a VXLAN packet after VXLAN encapsulation of the traffic sent by a virtual machine when a virtual switch uses the MAC address of the primary gateway as the MAC address of the virtual IP provided for some embodiments;
[0044] Figure 5 Schematic diagram of the traffic format sent by the primary gateway in a tenant gateway after decapsulation provided for some embodiments;
[0045] Figure 6 Schematic diagram of the format of a VXLAN packet after VXLAN encapsulation of the traffic sent by a virtual machine when a virtual switch uses the virtual MAC address of VRRP as the MAC address of the virtual IP provided for some embodiments;
[0046] Figure 7 Schematic diagram of the format of an ACL rule in an ABF policy configuration provided for some embodiments;
[0047] Figure 8 Schematic diagram of the traffic forwarding path for a virtual machine to access the Internet when the MAC address table entry of the upper-level switch device of the tenant gateway is not updated in the case of a primary / standby gateway switchover in the tenant gateway provided for some embodiments;
[0048] Figure 9 Schematic diagram of the traffic forwarding path for a virtual machine to access the Internet when the MAC address table entry of the upper-level switch device of the tenant gateway is updated and completed in the case of a primary / standby gateway switchover in the tenant gateway provided for some embodiments;
[0049] Figure 10 Flow schematic diagram of the method for a tenant gateway to process packets in the case of enabling the uninterrupted primary / standby switchover function provided for some embodiments;
[0050] Figure 11 Schematic diagram of the structure of a traffic transmission device provided for some embodiments;
[0051] Figure 12 Schematic diagram of the structure of a tenant gateway provided for some embodiments. Detailed implementation manners
[0052] The embodiments of the technical solution of the present application will be described in detail below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present application, so they are only examples and cannot be used to limit the protection scope of the present application.
[0053] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above accompanying drawings are intended to cover non-exclusive inclusion.
[0054] In the description of the embodiments of this application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity, specific order or primary-secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "a plurality" is more than two, unless otherwise specifically defined. In the description of the embodiments of this application, "each" means every one or every one of a plurality, unless otherwise specifically defined.
[0055] Referring to "embodiments" herein means that the specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of this application. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0056] In the description of the embodiments of this application, the term "and / or" is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally means that the associated objects before and after are in an "or" relationship.
[0057] At present, from the perspective of the development of the market situation, the application of energy storage systems is becoming more and more widespread, bringing great convenience in electricity use to daily production and life. Among various energy storage technologies, the high-voltage direct-connected energy storage system has gradually been developed and applied because of its highly modular structure, which can meet the requirements of high efficiency, high reliability, economy and safety.
[0058] Before introducing the embodiments of this application, some terms are explained:
[0059] The Internet Communication Protocol, also known as the Internet Protocol (IP), is a network layer protocol in the Transmission Control Protocol (TCP) / IP system.
[0060] A virtual machine (VM) refers to a complete computer system with the functions of a complete hardware system simulated by software and running in a completely isolated environment.
[0061] The Virtual Router Redundancy Protocol (VRRP) is a fault-tolerant protocol used to solve the problem of single point of failure in the configuration of static gateways in a local area network. VRRP is usually deployed on the egress gateway device in a local area network. By including routing devices with the same egress in the same backup group and advertising them as a virtual router as the default gateway, the backup of the gateway device within the local area network is achieved.
[0062] The Virtual Router Redundancy Protocol Identifier (VRID) is the unique identifier of a virtual router, used to distinguish multiple VRRP backup groups within a local area network. Each VRRP backup group will be assigned a unique VRID to ensure that routers within the group can correctly identify and participate in the corresponding backup group.
[0063] The Virtual eXtensible Local Area Network (VXLAN) Tunnel Endpoint (VTEP) is responsible for the encapsulation and decapsulation of VXLAN packets.
[0064] The virtual switch (Open vSwitch, OVS) is a switch that exists in the virtual network in software form.
[0065] The Address Resolution Protocol (ARP) is one of the core protocols in the TCP / IP protocol stack. The task of ARP is to query the corresponding MAC address based on the target IP address and establish and maintain the IP-MAC mapping table (ARP table). Gratuitous ARP (GARP), also known as Unsolicited ARP or Broadcast ARP, is a special ARP request message. In this message, the source IP address and the destination IP address are the same, and the destination MAC address is the broadcast address (all Fs, i.e., FF-FF-FF-FF-FF-FF). The main purpose of this message is to announce or notify other devices in the network of the correspondence between an IP address and a MAC address, rather than to request information.
[0066] Access Control Lists (ACL) can filter data packets on an interface according to the set conditions, allowing them to pass through or be discarded.
[0067] ACL Based Forwarding (ABF) is a type of policy-based routing forwarding.
[0068] Figure 1 Schematic diagram of the cloud network architecture provided for some embodiments, as Figure 1 shown, the network architecture in the cloud network includes computing nodes, tenant gateways, the Internet, Leaf switches, and Spine switches. Among them, the Leaf switches include service Leaf switches and border Leaf switches, etc.
[0069] A virtual switch (OVS) and multiple virtual machines (VM) are deployed in the computing node. The traffic (also known as data) generated by the virtual switch is sent to the virtual switch. After the virtual machine switch performs VXLAN encapsulation on this traffic, a VXLAN message is obtained, and it is sent to a primary gateway in the tenant gateway through the Leaf switch and the Spine switch and then back to the Leaf switch. For example, it is sent to the primary gateway in the tenant gateway through Leaf switch 1 and Spine switch 1 and then back to service Leaf switch 1. Exemplarily, gateway 1 can be the primary gateway, and gateway 2 can be the standby gateway.
[0070] A tenant gateway is a key component used in a cloud network architecture, mainly for implementing network traffic management, isolation, and security control for different tenants (users, organizations, or business units). Multiple gateways are deployed for the tenant gateway, and multiple gateways can be included in a VRRP backup group (which can also be simply referred to as a backup group in this article), and a unique VRID will be assigned to each VRRP backup group. In a VRRP backup group, only one master gateway performs the operations of VXLAN packet decapsulation and traffic forwarding to the Internet at each moment. When the master gateway is working properly, it will send heartbeat packets to other gateways in the VRRP backup group at preset intervals. When other gateways do not receive the heartbeat packets sent by the master gateway for several intervals, it indicates that the master gateway cannot perform the operations of VXLAN packet decapsulation and traffic forwarding to the Internet, and the gateway with a higher priority among other gateways becomes the new master gateway, and the new master gateway replaces the original master gateway to perform the operations of VXLAN packet decapsulation and traffic forwarding to the Internet.
[0071] However, the above solution has the following problems: As long as the gateways belonging to the same backup group in the tenant gateway are switched, the new master gateway (i.e., the original standby gateway, such as gateway 2) will broadcast Address Resolution Protocol packets (including gratuitous ARP packets) to broadcast that it has become the new master gateway. At this time, it is necessary to update the MAC address entries corresponding to the virtual IP (VIP pair) of the upper-level switch of the tenant gateway (for example, Figure 1 the service leaf switch 1 and service leaf switch 2 in), for example, the MAC address of the original gateway in the MAC address entry needs to be updated to the MAC address of the new gateway, and the outgoing interface corresponding to the original master gateway needs to be updated to the outgoing interface of the new master gateway, so that the VXLAN packets can be forwarded to the new master gateway. In addition, the virtual switch in the compute node also needs to update the ARP entry, that is, update the MAC address of the original gateway to the MAC address of the new gateway, so that the VXLAN packets can be forwarded to the new master gateway through the update of the MAC address. However, if the update of the MAC address entry of the upper-level switch is not timely, or due to the performance problem of the switch between the compute node and the tenant gateway, the delay of the switch in forwarding the gratuitous ARP packets is high, which will cause the virtual switch in the compute node to update the ARP entry not timely, and both will cause the traffic of the virtual machines in the compute node accessing the Internet to be interrupted for a long time, affecting business continuity.
[0072] That is to say, due to the inability to update the ARP entry of the virtual switch in the compute node in a timely manner, or the inability to update the MAC address entry of the upper-level switch of the tenant gateway in a timely manner, the problem of long-term traffic interruption caused by the master-slave switchover of the tenant gateway will occur.
[0073] Among them, the virtual switch in the computing node updates the ARP table entries through self-learning, and the upper-level switch updates the MAC address table entries through self-learning. In applications, the leaf switch and the backbone switch bear a very large pressure of information processing. In the switch, the number of packets per second (PPS) of various protocols on the central processing unit (CPU) is fixed at several hundred. When the leaf switch and the backbone switch reach the performance limit and cannot process gratuitous ARP packets in time, there will be a problem that the table entry update is not timely, resulting in a long traffic interruption time after the primary / backup switchover.
[0074] Figure 2 A schematic flow diagram of a traffic transmission method provided for some embodiments is shown as Figure 2 shown. This method is applied to a tenant gateway with a primary / backup gateway deployed. The method includes:
[0075] S201. In the case of a primary / backup gateway switchover in the tenant gateway, the original primary gateway in the tenant gateway sends gateway switchover indication information to the controller.
[0076] Among them, after the primary / backup gateway switchover, the primary gateway is the original primary gateway, and the standby gateway is the new primary gateway. Therefore, it should be noted that Figure 2 the original primary gateway shown in the figure is the primary gateway in the primary / backup gateway of the tenant gateway, and the new primary gateway is the standby gateway in the primary / backup gateway of the tenant gateway. The same applies to other figures in the embodiments of the present application, and details will not be repeated here.
[0077] In some embodiments, the gateway switchover indication information indicates that a primary / backup gateway switchover has occurred in the tenant gateway.
[0078] In some embodiments, it can be determined that a primary / backup gateway switchover has occurred in the tenant gateway when the original primary gateway stops sending heartbeat packets, and the original primary gateway sends gateway switchover indication information to the controller. In some embodiments, the gateway switchover indication information can indicate that the original primary gateway has switched, but does not indicate to the controller which gateway it has switched to.
[0079] In some other embodiments, when the original primary gateway receives a gratuitous ARP packet sent by the new primary gateway, the original primary gateway determines that a primary / backup gateway switchover has occurred in the tenant gateway. In some embodiments, the gateway switchover indication information can indicate that the original primary gateway has switched to the new primary gateway, that is, it indicates to the controller that it has switched to the new primary gateway.
[0080] S202. The original primary gateway receives the forwarding configuration information instruction sent by the controller; the forwarding configuration information instruction instructs the original primary gateway to forward the target traffic to the new primary gateway, the gateway address corresponding to the target traffic is the virtual media access control (MAC) address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong.
[0081] When the original primary gateway sends the gateway switch indication information to the controller, it can open a listening time window and listen for the forwarding configuration information instruction sent by the controller within this time window. In some embodiments, within a listening time window, if the original primary gateway does not receive the forwarding configuration information instruction sent by the controller, it can, at the end of the listening time window, resend the gateway switch indication information to the controller and reopen a listening time window to listen for the forwarding configuration information instruction sent by the controller. In this way, it is possible to avoid the problem of loss of the forwarding configuration information instruction caused by occasional factors such as instantaneous network latency, signal interference, or controller processing load, thereby effectively improving the reliability of obtaining the forwarding configuration information instruction during the gateway switch process.
[0082] The forwarding configuration information instruction can not only indicate the characteristics of the target traffic but also instruct the original primary gateway to forward the target traffic to the new primary gateway.
[0083] In some embodiments, the gateway address corresponding to the target traffic can be the destination address in the VXLAN header encapsulating the target traffic, and the destination address in the VXLAN header is a gateway address. Exemplarily, a backup group corresponds to a unique virtual address. Since the original primary gateway and the new primary gateway belong to the same backup group, the original primary gateway and the new primary gateway share a virtual MAC address.
[0084] S203. The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, and forwards the target traffic to the new primary gateway.
[0085] Among them, the original primary gateway can receive the traffic sent by the virtual switch of the compute node, determine the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, and forward the target traffic to the new primary gateway.
[0086] For example, in the case of a primary / standby gateway switchover of the tenant gateway, even if a virtual MAC address is used, if the MAC address entry of the upper-level switch of the tenant gateway cannot be updated in a timely manner, the VXLAN packet (carrying the target traffic) sent by the virtual switch will still reach the original primary gateway. However, in the case of a primary / standby gateway switchover of the tenant gateway, the original primary gateway can no longer perform the decapsulation operation on the VXLAN packet and send the decapsulated traffic to the Internet. At this time, the original primary gateway can forward the VXLAN packet to the new primary gateway so that the new primary gateway can perform the decapsulation operation on the VXLAN packet and send the decapsulated traffic to the Internet.
[0087] S204. The new primary gateway forwards the target traffic to the Internet.
[0088] In the technical solution provided by the embodiments of the present application, the original primary gateway receives the forwarding configuration information instruction sent by the controller, and when the original primary gateway receives the target traffic, it forwards the target traffic to the new primary gateway, so that the new primary gateway forwards the target traffic to the Internet, thus eliminating the need to wait for the update of the MAC address entry of the upper-level switch of the tenant gateway. In this way, even if the MAC address entry is not updated completely, when the target traffic reaches the original primary gateway, the original primary gateway can still forward the target traffic to the new primary gateway, and the new primary gateway forwards the target traffic to the Internet, thereby avoiding the problem of long-term interruption of the traffic of the virtual machine accessing the Internet, and even achieving the effect of uninterrupted traffic transmission, improving the continuity of the service. And since the gateway address corresponding to the target traffic is a virtual media access control (MAC) address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong, even if there is a primary / standby gateway switchover of the tenant gateway, the MAC addresses of the original primary gateway and the new primary gateway are the same, eliminating the need for the ARP table entry of the virtual switch in the computing node to be updated. The virtual switch in the computing node can also forward the target traffic to the new primary gateway, avoiding the phenomenon that the target traffic cannot be forwarded to the new primary gateway until the ARP table entry of the virtual switch in the computing node is updated due to the different MAC addresses of the original primary gateway and the new primary gateway, thereby further reducing the probability of long-term interruption of the traffic of the virtual machine accessing the Internet and improving the service continuity. And this solution does not require the hardware of the switch to be upgraded, avoiding the phenomenon of upgrading the switch in the related art to reduce the interruption duration of the traffic of the virtual machine accessing the Internet. Therefore, this solution can also reduce the cost of the cloud network.
[0089] In some embodiments, the forwarding configuration information instruction includes an access control list rule and a forwarding rule based on the access control list. The access control list rule (hereinafter referred to as the ACL rule) indicates that in the case where the MAC address in the virtual extensible local area network VXLAN header encapsulating the received traffic is any MAC address and the destination MAC address is the virtual MAC address, the received traffic is the target traffic; the forwarding rule based on the access control list (hereinafter referred to as the ABF rule) indicates that the original primary gateway forwards the target traffic to the new primary gateway.
[0090] In the technical solution provided by the embodiments of the present application, the range of target traffic to be processed is accurately defined through the ACL rule, and a clear traffic forwarding path is established by using the ABF rule, forming a complete logical chain from traffic identification to forwarding execution. It can not only ensure that the target traffic in the network is accurately screened, but also realize the directional transmission of traffic between the old and new primary gateways through rule linkage, effectively improving the accuracy and controllability of traffic management, and providing rule-level support for the accurate implementation of traffic forwarding after the gateway.
[0091] In some embodiments, the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction and forwards the target traffic to the new primary gateway, including: the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node according to the access control list rule in the forwarding configuration information instruction; the original primary gateway forwards the target traffic to the new primary gateway according to the forwarding rule based on the access control list in the forwarding configuration information instruction.
[0092] In the technical solution provided by the embodiments of the present application, based on the mechanism of hierarchical rule execution, the original primary gateway can first accurately identify and screen the traffic through the ACL rule, and then use the ABF rule to achieve the directional forwarding of the target traffic, forming a closed-loop processing logic from identification to forwarding, ensuring that the network traffic can be accurately transmitted according to the preset strategy during the gateway switching process, avoiding the interference and mis-forwarding of non-target traffic, and effectively improving the accuracy and efficiency of traffic forwarding.
[0093] In some embodiments, the method further includes: the original primary gateway determines other traffic other than the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction, and the original primary gateway forwards the other traffic to the new primary gateway; the new primary gateway forwards the other traffic to the gateway of another backup group according to the destination MAC address in the VXLAN header encapsulating the other traffic, so that the gateway of the other backup group forwards the other traffic to the Internet.
[0094] In some embodiments, the original primary gateway may receive the traffic sent by the virtual switch of the compute node (actually, it receives VXLAN packets, and the traffic is encapsulated in the VXLAN packets). When it is determined that the received traffic is the target traffic according to the forwarding configuration information instruction, the original primary gateway forwards the target traffic to the new primary gateway (substantially, it forwards the VXLAN packet encapsulated with the target traffic), and may send the decapsulation instruction information to the new primary gateway, so that the new primary gateway decapsulates the VXLAN packet encapsulated with the target traffic according to the decapsulation instruction information to obtain the target traffic and sends the target traffic to the Internet.
[0095] In some embodiments, the original primary gateway may receive the traffic sent by the virtual switch of the compute node (actually, it receives VXLAN packets, and the traffic is encapsulated in the VXLAN packets). When it is determined that the received traffic is not the target traffic (i.e., other traffic) according to the forwarding configuration information instruction, the original primary gateway forwards the other traffic to the new primary gateway (substantially, it forwards the VXLAN packet encapsulated with the other traffic), and may send the forwarding instruction information to the new primary gateway, so that the new primary gateway forwards the VXLAN packet encapsulated with the other traffic to the gateway of another backup group according to the forwarding instruction information.
[0096] In some embodiments, the decapsulation instruction information or the forwarding instruction information may be carried in the reserved bit of the VXLAN packet. Exemplarily, the VXLAN header in the VXLAN packet has a reserved bit, and the decapsulation instruction information or the forwarding instruction information may be set in this reserved bit to indicate the decapsulation or forwarding of the VXLAN packet to the new primary gateway.
[0097] In the technical solution provided by the embodiments of the present application, when the original primary gateway determines that the received traffic is other traffic other than the target traffic according to the forwarding configuration information instruction, the original primary gateway forwards the other traffic to the new primary gateway. The new primary gateway then further forwards it to the gateway of another backup group according to the gateway address corresponding to the other traffic, and finally the gateway of the other backup group forwards it to the Internet. Thus, through the multi-level forwarding mechanism, the efficient processing and accurate routing of non-target traffic are realized, avoiding traffic retention or mistransmission, and effectively improving the reliability and stability of network transmission.
[0098] In some embodiments, the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, including: the original primary gateway determines the destination MAC address in the VXLAN header of the traffic sent by the virtual switch of the compute node; according to the forwarding configuration information instruction, the traffic with the destination MAC address in the VXLAN header being the virtual MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong is determined as the target traffic.
[0099] In some embodiments, the original primary gateway may, according to the forwarding configuration information instruction, determine that the destination MAC address in the VXLAN packet header is the virtual media access control MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong when the destination MAC address in the VXLAN packet header includes a backup group identifier and the backup group identifier is the identifier of the backup group to which the original primary gateway and the new primary gateway belong.
[0100] In the technical solution provided by the embodiments of the present application, the original primary gateway forwards the configuration information instruction, and by reading whether the destination MAC address in the packet header encapsulated by the received traffic is the virtual MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong, accurately identifies that the traffic is the target traffic to be processed, and thus establishes an accurate traffic identification mechanism by comparing the destination MAC address of the traffic packet header with the virtual MAC address. It can quickly and accurately screen out the target traffic in a complex network environment, avoid misjudging other irrelevant traffic as the target traffic for processing, effectively improve the accuracy and reliability of traffic identification, reduce unnecessary consumption of processing resources, and ensure the efficiency and stability of network data processing.
[0101] In some embodiments, the method further includes: when a primary / backup gateway switch occurs in the tenant gateway, the new primary gateway broadcasts an address resolution protocol packet, and the address resolution protocol packet is used for the upper-level switch device of the tenant gateway to update the outgoing interface corresponding to the new primary gateway in the MAC address table entry; the original primary gateway receives the traffic sent by the virtual switch of the computing node, including: before the upper-level switch device updates the outgoing interface corresponding to the new primary gateway in the MAC address table entry, the original primary gateway receives the traffic sent by the virtual switch of the computing node through the upper-level switch device.
[0102] In some embodiments, when the upper-level switch device completes updating the outgoing interface corresponding to the new primary gateway in the MAC address table entry, the new primary gateway receives the traffic sent by the virtual switch of the computing node through the upper-level switch device.
[0103] In the technical solution provided by the embodiments of the present application, when a primary / backup gateway switch occurs in the tenant gateway, the new primary gateway actively broadcasts an address resolution protocol packet to enable the upper-level switch device of the tenant gateway to update the outgoing interface corresponding to the new primary gateway in the MAC address table entry in a timely manner. Before the update is completed, the original primary gateway can still receive the traffic sent by the virtual switch in the computing node through the upper-level switch device. This method ensures the continuity of network traffic transmission during the gateway switch. The upper-level switch device can adjust the data forwarding path by whether to update the MAC address table entry, avoiding problems such as traffic loss or transmission interruption caused by gateway changes, realizing seamless connection of traffic processing between the old and new gateways, enhancing the reliability and stability of traffic transmission in the tenant network in the gateway switch scenario, and improving service continuity.
[0104] In some embodiments, the traffic received by the original primary gateway is encapsulated in a VXLAN packet, and the VXLAN packet is a packet obtained by encapsulating the traffic sent by the virtual switch to the virtual machine in the computing node; the original primary gateway forwards the target traffic to the new primary gateway, including: the original primary gateway forwards the VXLAN packet encapsulating the target traffic to the new primary gateway; before the new primary gateway forwards the target traffic to the Internet, the method further includes: the new primary gateway decapsulates the VXLAN packet to obtain the target traffic.
[0105] Exemplarily, as Figure 1 shown, when there is a primary / standby gateway switch for the tenant gateway and the virtual machine in the computing node needs to send traffic to the Internet through the tenant gateway, the virtual machine in the computing node sends the target traffic to the virtual switch in the computing node. The virtual switch encapsulates the target traffic using the VXLAN protocol to obtain a VXLAN packet, which is sent to leaf switch 3 or 4 through leaf switch 1 or 2 and spine switch 1 or 2. In the case where leaf switch 3 or 4 has not updated the MAC address entry, leaf switch 3 or 4 forwards the VXLAN packet to the original primary gateway (such as gateway 1), and the original primary gateway forwards the VXLAN packet to the new primary gateway (such as gateway 2). The new primary gateway decapsulates the VXLAN packet to obtain the target traffic and forwards the target traffic to the Internet.
[0106] In the technical solution provided by the embodiments of the present application, when the original primary gateway receives a VXLAN packet (encapsulating the target traffic) encapsulated by the virtual switch, it directly forwards the VXLAN packet to the new primary gateway. The new primary gateway completes VXLAN decapsulation before forwarding to the Internet to restore the target traffic, so that after the gateway switch in the tenant gateway, the original primary gateway that does not support VXLAN packet decapsulation and traffic transmission to the Internet forwards the VXLAN packet to the new primary gateway. The new primary gateway that supports VXLAN packet decapsulation and traffic transmission to the Internet decapsulates the VXLAN packet and forwards the target traffic to the Internet. Through the division of labor and cooperation between the old and new gateways, it is ensured that the target traffic encapsulated by VXLAN is not interrupted during the gateway switch process, which not only enables the VXLAN packet to reach the new primary gateway smoothly, but also realizes normal traffic egress through the decapsulation function of the new primary gateway, effectively guaranteeing the continuity of tenant services during gateway switch and the reliability of network transmission.
[0107] In some embodiments, after the new primary gateway forwards the target traffic to the Internet, the method may further include: in the case where the original primary gateway resumes use, the original primary gateway deletes the forwarding configuration information instruction saved in the original primary gateway; the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node and sends the target traffic to the Internet.
[0108] Exemplarily, if the original primary gateway returns to normal, it can be restored for use through gateway switching. At this time, the original primary gateway becomes the latest primary gateway again.
[0109] Exemplarily, when the original primary gateway is a standby gateway and receives a forwarding configuration information instruction, it can save the forwarding configuration information instruction. Thus, each time traffic is received, the corresponding forwarding operation can be determined according to the forwarding configuration information. When the original primary gateway is re-enabled and becomes the new primary gateway, the original primary gateway will delete the forwarding configuration information instruction and directly forward the traffic. Among them, the method of re-enabling the original primary gateway and forwarding traffic can be similar to the method of the new primary gateway forwarding traffic as described above, which will not be elaborated here.
[0110] In some embodiments, when the original primary gateway switches to the new primary gateway and the upstream switch device of the tenant gateway has not updated the outgoing interface corresponding to the new primary gateway in the MAC address table entry, the target traffic will be forwarded to the original primary gateway, so that the new primary gateway can forward the target traffic to the new primary gateway until, when the original primary gateway is restored for use, the original primary gateway can broadcast a gratuitous ARP packet. If the upstream switch device of the tenant gateway has not updated the outgoing interface corresponding to the new primary gateway in the MAC address table entry, at this time, the upstream switch device does not need to update the MAC address table entry either, and the target traffic will still be forwarded to the original primary gateway, and the original primary gateway sends the target traffic to the Internet.
[0111] In some embodiments, when the original primary gateway switches to the new primary gateway and the upstream switch device of the tenant gateway has not updated the outgoing interface corresponding to the new primary gateway in the MAC address table entry, the target traffic will be forwarded to the original primary gateway, so that the original primary gateway forwards the target traffic to the new primary gateway, and the new primary gateway forwards the target traffic to the Internet until the upstream switch device of the tenant gateway completes the update of the outgoing interface corresponding to the new primary gateway in the MAC address table entry, and the target traffic is forwarded to the new primary gateway, and the new primary gateway forwards the target traffic to the Internet; when the original primary gateway is restored for use, the original primary gateway can broadcast a gratuitous ARP packet. If the upstream switch device of the tenant gateway has not updated the outgoing interface corresponding to the original primary gateway in the MAC address table entry, the target traffic will be forwarded to the new primary gateway, and the new primary gateway forwards the target traffic to the original primary gateway so that the original primary gateway sends the target traffic to the Internet until the upstream switch device of the tenant gateway completes the update of the outgoing interface corresponding to the original primary gateway in the MAC address table entry, and the target traffic will be forwarded to the original primary gateway, and the original primary gateway forwards the target traffic to the Internet.
[0112] The traffic transmission method provided by the embodiments of this application can achieve uninterrupted traffic transmission when the primary and standby gateways of the tenant gateway are switched. The improvements are at least reflected in the following two aspects: (1) The virtual MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong is used as the gateway address corresponding to the target traffic. As a result, the virtual switch in the compute node does not need to update the ARP entry, thus avoiding the problem of traffic interruption caused by untimely update of the ARP entry in the virtual switch of the compute node. (2) After the VRRP primary and standby switchover occurs, it is necessary to report to the controller. The controller intervenes in the forwarding path of the primary and standby gateways through forced control, thus solving the problem that when the upstream switch device of the tenant gateway cannot update the outgoing interface corresponding to the new primary gateway in the MAC address table in time, and thus the traffic is still sent to the original primary gateway, resulting in traffic blockage. Exemplarily, when each gateway in the tenant gateway is configured to enable the uninterrupted primary and standby switchover function, or when each gateway in the tenant gateway is configured to enable the uninterrupted primary and standby switchover function, when the tenant gateway undergoes a primary and standby switch, the original primary gateway will report to the controller through the Network Configuration Protocol (NETCONF). The controller will configure the ABF policy (i.e., the forwarding configuration information instruction) for the original primary gateway of the tenant gateway, including configurations such as ACL rules and ABF rules. The original primary gateway performs policy-based routing on the matching traffic and forwards it to the internal network interface of the new primary gateway.
[0113] In some embodiments, the process of processing packets by the tenant gateway after the primary and standby switchover is defined. The traffic is diverted to the new primary gateway for forwarding through ACL rules and ABF rules until all entries are updated normally.
[0114] Figure 3 Schematic diagram of the traffic format sent by the virtual machine in the compute node provided for some embodiments, as Figure 3 shown, the traffic format sent by the virtual machine VM1 includes the source MAC address being the MAC address of VM1 (VM1_MAC), the destination MAC address being the corresponding MAC address of the subnet gateway on the tenant gateway (GW_Subnet_MAC or GW_MAC), the source IP address being the IP address of VM1 (VM1_IP), the destination IP address being the IP address of the Internet (Internet_IP), and the IP data packet.
[0115] Figure 4 Schematic diagram of the VXLAN packet format after VXLAN encapsulation of the traffic sent by the virtual machine when the virtual switch uses the MAC address of the primary gateway as the MAC address of the virtual IP for some embodiments, as Figure 4 shown, the VXLAN packet is in Figure 3Based on the format shown, a VXLAN header is added. In the VXLAN header, the source MAC address of the VXLAN packet is the MAC address of the virtual switch (OVS_MAC), the destination MAC address of the VXLAN packet is the physical MAC address of the internal network port of the master gateway (GW_VRRP_Master_MAC), the source IP address of the VXLAN packet is the IP address of the virtual switch as the VXLAN tunnel endpoint (OVS_VETP_IP), the destination IP address of the VXLAN packet is the virtual IP address of the gateway (GW_VRRP_VIP), and the VXLAN header also includes a UDP header (such as UDP4789) and a VXLAN header.
[0116] Among them, after the VXLAN packet on the virtual switch (OVS) is sent to the master gateway of the tenant gateway for traffic decapsulation and traffic transmission to the Internet, the master gateway in the tenant gateway finds that the destination MAC is its own, removes the outer encapsulation, and exposes the inner packet for forwarding to the leaf switch.
[0117] In Figure 4 In the embodiment shown, the MAC address of the VIP changes with the master - standby switch. If the ARP of the VIP on the computing node cannot be updated in time, traffic interruption will occur. Therefore, the embodiment of this application proposes a solution using the virtual MAC address of VRRP. According to RFC2338, the virtual MAC address of the VIP of VRRP can be generated in the format of 00 - 00 - 5E - 00 - 01 - {VRID}, where VRID is the unique identifier of the virtual router, usually an integer from 0 to 255.
[0118] Figure 5 A schematic diagram of the traffic format after decapsulation by the master gateway in the tenant gateway provided for some embodiments, as Figure 5 shown. The traffic format sent by this master gateway includes the source MAC address as the corresponding MAC address of the subnet gateway on the tenant gateway (GW_Subnet_MAC or GW_MAC), the destination MAC address as the MAC address of the next - hop device of the tenant gateway (GW next - hop MAC), the source IP address as the IP address of VM1 (VM1_IP), the destination IP address as the IP address of the Internet (Internet_IP), and an IP data packet.
[0119] Figure 6 A schematic diagram of the VXLAN packet format after VXLAN encapsulation of the traffic sent by the virtual machine when the virtual switch uses the virtual MAC address of VRRP as the MAC address of the virtual IP for some embodiments, as Figure 6 shown, Figure 6 The format shown in Figure 4The difference in the format shown is that the destination MAC address of the VXLAN packet is the virtual MAC address (GW_VRRP_VIP_VMAC) of the VRRP VIP.
[0120] Through Figure 6 In the format shown, when the primary and standby tenant gateways are switched, the destination MAC address of the VXLAN packet will not change with the gateway switch, thus eliminating the traffic interruption problem caused by the ARP update time difference on the compute node.
[0121] After enabling the non-stop primary and standby switchover function in the primary and standby gateway configuration of the tenant gateway, when the primary and standby tenant gateways are switched, the original primary gateway will report to the controller through the TCP connection of the Network Configuration Protocol (NETCONF). The controller will configure the ABF policy for the original primary gateway of the tenant gateway, including ACL rules and ABF rules, etc. The original primary gateway will perform policy-based routing on the matching traffic and forward it to the internal network interface of the new primary gateway, thus strongly controlling and intervening in the scenario of VRRP primary and standby switchover.
[0122] When the primary and standby switchover occurs, the controller configures the ABF policy for the gateway that has switched to the original primary gateway through the TCP connection of NETCONF.
[0123] Figure 7 A schematic diagram of the format of the ACL rule in the ABF policy configuration provided for some embodiments. Among them, the ACL rule in the ABF policy configuration is a layer 2 ACL, mainly used to match the source MAC address and destination MAC address of the packet. The source MAC address matches all MAC addresses (any), and the destination MAC address matches the virtual MAC address of the VIP. Taking VRID 01 as an example, the virtual MAC address is 00-00-5E-00-01-01. That is to say, any packet with the destination MAC address being the virtual MAC address of the VIP will match this ACL rule. Exemplarily, the ACL rule may include a rule identifier (Rule_Id), for example, the rule identifier is 10. Exemplarily, the ACL rule may also include a mask corresponding to the source MAC address, for example, ffff-ffff-ffff, indicating that each bit of the source MAC address needs to be exactly matched. Exemplarily, the ACL rule may also include a mask corresponding to the destination MAC address, for example, ffff-ffff-ffff, indicating that each bit of the destination MAC address needs to be exactly matched.
[0124] When the controller issues ACL rules, it also issues ABF rules (i.e., ACL-based forwarding rules), which means that the traffic that matches the ACL rules will be redirected and drained to the internal network port of the new master device. In this way, even if due to some abnormality, the MAC address table entry on the upper-level switch device of the tenant gateway is not updated in time, and the traffic still reaches the original master gateway (which is actually in the standby state at this time), the original master gateway will still redirect the traffic to the new master gateway according to the ABF rules, and there will be no traffic interruption caused by the master-standby switch of VRRP.
[0125] Figure 8 Schematic diagram of the traffic forwarding path for virtual machines to access the Internet when the MAC address table entry of the upper-level switch device of the tenant gateway is not updated in the case of master-standby gateway switch of the tenant gateway for some embodiments, as Figure 8 shown, in this scenario, the traffic sent by the virtual machine (such as virtual machine 1) through the virtual switch (OVS) will be forwarded to the original master gateway (such as gateway 1), and the original master gateway will, according to the received ABF policy, forcefully redirect the traffic that matches the virtual MAC address with the destination MAC being the VIP to the new master gateway (such as gateway 2). After receiving the traffic, the new master gateway finds that the destination MAC is its own, and then it will remove the outer encapsulation and forward the traffic to the Internet.
[0126] Figure 9 Schematic diagram of the traffic forwarding path for virtual machines to access the Internet when the MAC address table entry of the upper-level switch device of the tenant gateway is updated in the case of master-standby gateway switch of the tenant gateway for some embodiments, as Figure 9 shown, in this scenario, the traffic sent by the virtual machine (such as virtual machine 1) through the virtual switch (OVS) will be forwarded to the new master gateway. After receiving the traffic, the new master gateway finds that the destination MAC is its own, and then it will remove the outer encapsulation and forward the traffic to the Internet.
[0127] Figure 10 Schematic diagram of the flow of the method for the tenant gateway to process packets in the case of enabling the uninterrupted master-standby switch function of the tenant gateway for some embodiments, as Figure 10 shown, the method includes the following steps:
[0128] S1001. When there is a master-standby gateway switch of the tenant gateway, the original master gateway receives the VXLAN packet encapsulating the traffic.
[0129] S1002. The original master gateway determines whether the traffic matches the ACL rules.
[0130] When the traffic matches the ACL rule, S1003 and S1004 are executed. When the traffic does not match the ACL rule, S1005 and S1006 are executed. Among them, when the traffic does not match the ACL rule, it indicates that the traffic is not for accessing the virtual MAC address, and then it is directly forwarded.
[0131] S1003. The original primary gateway forcibly forwards the traffic to the new primary gateway through the ABF rule.
[0132] S1004. The new primary gateway looks up the table and forwards the traffic to the Internet.
[0133] S1005. The original primary gateway forwards the traffic to the new primary gateway.
[0134] S1006. The new primary gateway forwards the traffic to other gateways so that the other gateways forward the traffic to the Internet.
[0135] Based on the same inventive concept, the embodiment of the present application also provides a traffic transmission device for implementing the traffic transmission method involved above. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the traffic transmission device provided below can refer to the limitations on the traffic transmission method in the above text, and will not be repeated here.
[0136] In an exemplary embodiment, Figure 11 For the structural schematic diagram of the traffic transmission device provided in some embodiments, as Figure 11 shown, the traffic transmission device 1100 includes:
[0137] A switching indication sending module 1101, configured to, when a primary / backup gateway switch occurs in the tenant gateway, the original primary gateway in the tenant gateway sends gateway switching indication information to the controller;
[0138] A configuration receiving module 1102, configured to the original primary gateway receives the forwarding configuration information instruction sent by the controller; the forwarding configuration information instruction instructs the original primary gateway to forward the target traffic to the new primary gateway, the gateway address corresponding to the target traffic is the virtual media access control MAC address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong;
[0139] A traffic forwarding module 1103, configured to the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction, and forwards the target traffic to the new primary gateway; the new primary gateway forwards the target traffic to the Internet.
[0140] In some embodiments, the forwarding configuration information instruction includes an access control list rule and a forwarding rule based on the access control list; the access control list rule indicates that traffic meeting the conditions that the source MAC address is any MAC address and the destination MAC address is a virtual MAC address is target traffic; the forwarding rule based on the access control list indicates that the original primary gateway forwards the target traffic to the new primary gateway.
[0141] In some embodiments, the traffic forwarding module 1103 is further configured to enable the original primary gateway to determine target traffic from the traffic sent by the virtual switch of the computing node according to the access control list rule in the forwarding configuration information instruction; and the original primary gateway forwards the target traffic to the new primary gateway according to the forwarding rule based on the access control list in the forwarding configuration information instruction.
[0142] In some embodiments, the traffic forwarding module 1103 is further configured to enable the original primary gateway to determine other traffic other than the target traffic from the traffic sent by the virtual switch of the computing node according to the forwarding configuration information instruction, and the original primary gateway forwards the other traffic to the new primary gateway; the new primary gateway forwards the other traffic to the gateway of another backup group according to the destination MAC address in the VXLAN header encapsulating the other traffic, so that the gateway of the other backup group forwards the other traffic to the Internet.
[0143] In some embodiments, the traffic forwarding module 1103 includes a MAC address acquisition unit and a traffic forwarding unit. The MAC address acquisition unit is configured to enable the original primary gateway to determine the destination MAC address in the VXLAN header of the traffic sent by the virtual switch of the computing node; the traffic forwarding unit is configured to determine, according to the forwarding configuration information instruction, traffic with the destination MAC address in the VXLAN header being the virtual MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong as target traffic.
[0144] In some embodiments, the traffic transmission device 1100 further includes a broadcast module. The broadcast module is configured to enable the new primary gateway to broadcast an address resolution protocol packet in the case of a primary / backup gateway switch of the tenant gateway. The address resolution protocol packet is used for the upper-level switch device of the tenant gateway to update the outgoing interface corresponding to the new primary gateway in the MAC address table entry; wherein, before the upper-level switch device updates the outgoing interface corresponding to the new primary gateway in the MAC address table entry, the original primary gateway receives the traffic sent by the virtual switch of the computing node through the upper-level switch device.
[0145] In some embodiments, the traffic received by the original primary gateway is encapsulated in a Virtual eXtensible Local Area Network (VXLAN) packet, and the VXLAN packet is a packet obtained by the virtual switch encapsulating the traffic sent by the virtual machine in the computing node; the traffic forwarding module 1103 is further configured to forward the VXLAN packet encapsulating the target traffic from the original primary gateway to the new primary gateway, and is further configured to unencapsulate the VXLAN packet by the new primary gateway to obtain the target traffic.
[0146] In some embodiments, the traffic transmission device 1100 further includes a configuration deletion module, and the configuration deletion module is configured to, when the original primary gateway resumes use, delete the forwarding configuration information instruction saved in the original primary gateway; the traffic forwarding module 1103 is further configured to determine the target traffic from the traffic sent by the virtual switch of the computing node by the original primary gateway and send the target traffic to the Internet.
[0147] The description of the above device embodiments is similar to the description of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0148] Each module in the above traffic transmission device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the tenant gateway in hardware form or be independent of it, or can be stored in the memory of the tenant gateway in software form so that the processor can call and execute the operations corresponding to the above respective modules.
[0149] In an exemplary embodiment, Figure 12Schematic diagram of the structure of a tenant gateway provided for some embodiments. The tenant gateway includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the tenant gateway is used to provide computing and control capabilities. The memory of the tenant gateway includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the tenant gateway is used to exchange information between the processor and external devices. The communication interface of the tenant gateway is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be implemented through Wireless Fidelity (WIFI), a mobile cellular network, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a traffic transmission method. The display unit of the tenant gateway is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the tenant gateway can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the tenant gateway, or an external keyboard, touchpad, or mouse, etc.
[0150] Those skilled in the art can understand that Figure 12 the structure shown in
[0151] is only a block diagram of some parts of the structure related to the solution of this application, and does not constitute a limitation on the tenant gateway to which the solution of this application is applied. The specific tenant gateway may include more or fewer parts than those shown in the figure, or combine some parts, or have a different arrangement of parts.
[0152] In one embodiment, a computer-readable storage medium is provided. When the computer program is executed by the processor, it implements the steps of the method provided in any of the above embodiments.
[0153] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, it implements the steps of the method provided in any of the above embodiments.
[0154] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods.
[0155] The processor, each functional module or each functional unit in any embodiment of the present application may include any one or more of the following integrations: general-purpose processor, application specific integrated circuit (ASIC), digital signal processor (DSP), digital signal processing device (DSPD), programmable logic device (PLD), field programmable gate array (FPGA), central processing unit (CPU), graphics processing unit (GPU), embedded neural network processor (NPU), controller, microcontroller, microprocessor, programmable logic device, discrete gate or transistor logic device, discrete hardware component, quantum computing-based data processing logic unit, artificial intelligence (AI) processor, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.
[0156] The memory or computer-readable storage medium in any embodiment of the present application may include at least one of non-volatile memory and volatile memory. The non-volatile memory includes the integration of one or more of the following: Read Only Memory (ROM), Programmable Read-Only Memory (PROM), Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Ferromagnetic Random Access Memory (FRAM), Flash Memory, magnetic surface memory, optical disc, Compact Disc Read-Only Memory (CD-ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, Resistive Random Access Memory (ReRAM), Magnetoresistive Random Access Memory (MRAM), Ferroelectric Random Access Memory (FRAM), Phase Change Memory (PCM), graphene memory, volatile memory, etc. The volatile memory includes the integration of one or more of the following: Random Access Memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM), etc.
[0157] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope recorded in the present application.
[0158] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A flow transmission method, characterized in that, Applied to a tenant gateway with a primary and standby gateway deployed, the method includes: In the case of a primary and standby gateway switch in the tenant gateway, the original primary gateway in the tenant gateway sends gateway switch indication information to the controller; The original primary gateway receives a forwarding configuration information instruction sent by the controller; the forwarding configuration information instruction instructs the original primary gateway to forward target traffic to the new primary gateway, and the gateway address corresponding to the target traffic is a virtual media access control (MAC) address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong; The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, and forwards the target traffic to the new primary gateway; The new primary gateway forwards the target traffic to the Internet.
2. The method according to claim 1, characterized in that The forwarding configuration information instruction includes an access control list rule and a forwarding rule based on the access control list; The access control list rule indicates that in the virtual extensible local area network (VXLAN) header encapsulating the received traffic, when the MAC address is any MAC address and the destination MAC address is the virtual MAC address, the received traffic is the target traffic; The forwarding rule based on the access control list instructs the original primary gateway to forward the target traffic to the new primary gateway.
3. The method according to claim 2, wherein The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, and forwards the target traffic to the new primary gateway, including: The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the access control list rule in the forwarding configuration information instruction; The original primary gateway forwards the target traffic to the new primary gateway according to the forwarding rule based on the access control list in the forwarding configuration information instruction.
4. The method according to any one of claims 1 to 3, characterized in that The method further includes: The original primary gateway determines other traffic other than the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, and the original primary gateway forwards the other traffic to the new primary gateway; The new primary gateway forwards the other traffic to the gateway of another backup group according to the destination MAC address in the VXLAN header encapsulating the other traffic, so that the gateway of the other backup group forwards the other traffic to the Internet.
5. The method according to any one of claims 1 to 3, characterized in that The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction, including: The original primary gateway determines the destination MAC address in the VXLAN header of the traffic sent by the virtual switch of the compute node; According to the forwarding configuration information instruction, the traffic with the destination MAC address in the VXLAN header being the virtual MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong is determined as the target traffic.
6. The method according to any one of claims 1 to 3, characterized in that, The method further includes: In the case of the primary-standby gateway switchover of the tenant gateway, the new primary gateway broadcasts Address Resolution Protocol (ARP) packets, which are used for the upper-level switch device of the tenant gateway to update the outgoing interface corresponding to the new primary gateway in the MAC address table entry; The original primary gateway receives the traffic sent by the virtual switch of the compute node, including: Before the upper-level switch device updates the outgoing interface corresponding to the new primary gateway in the MAC address table entry, the original primary gateway receives the traffic sent by the virtual switch of the compute node through the upper-level switch device.
7. The method according to any one of claims 1 to 3, characterized in that, The traffic received by the original primary gateway is encapsulated in a VXLAN packet, which is a packet obtained by the virtual switch encapsulating the traffic sent by the virtual machine in the compute node; The original primary gateway forwards the target traffic to the new primary gateway, including: the original primary gateway forwards the VXLAN packet encapsulating the target traffic to the new primary gateway; Before the new primary gateway forwards the target traffic to the Internet, the method further includes: the new primary gateway de-encapsulates the VXLAN packet to obtain the target traffic.
8. The method according to any one of claims 1 to 3, characterized in that, The method further includes: In the case of the original primary gateway resuming use, the original primary gateway deletes the forwarding configuration information instruction saved in the original primary gateway; The original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node and sends the target traffic to the Internet.
9. A flow transmission device, characterized in that, The traffic transmission device includes: A handover indication sending module, configured to, in the case of the primary-standby gateway switchover of the tenant gateway, the original primary gateway in the tenant gateway sends gateway handover indication information to the controller; A configuration receiving module, configured to the original primary gateway receives the forwarding configuration information instruction sent by the controller; the forwarding configuration information instruction instructs the original primary gateway to forward the target traffic to the new primary gateway, the gateway address corresponding to the target traffic is the virtual Media Access Control (MAC) address, and the virtual MAC address is the MAC address corresponding to the backup group to which the original primary gateway and the new primary gateway belong; A traffic forwarding module, configured to the original primary gateway determines the target traffic from the traffic sent by the virtual switch of the compute node according to the forwarding configuration information instruction and forwards the target traffic to the new primary gateway; the new primary gateway forwards the target traffic to the Internet.
10. A tenant gateway, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.