Flow control method of virtual network and computing device
By using multi-level rule flow tables to filter messages in virtual switches, the security problem of direct message transfer in virtual networks is solved, and security and filtering efficiency are improved.
Patent Information
- Application Number
- CN202510121934.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-07-25
AI Technical Summary
In the existing virtual network management method based on OVN implementation, when the packets meet a filtering level transfer rule, they will be transferred out directly, resulting in the ACL rules of other filtering levels not taking effect, reducing the security of the virtual network.
By using at least two rule flow tables in a virtual switch, the target packets are filtered at multiple levels, and different filtering rule flow tables are designed for inflow and outflow directions respectively to ensure that the packets are filtered at other levels before they meet one filtering level.
It improves the security and packet filtering efficiency of the virtual network, avoids the direct transfer of packets when they meet a single filtering level, and enhances the accuracy and stability of filtering.
Smart Images

Figure CN120378131A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of virtual networks, and in particular, to a method for controlling traffic of a virtual network and a computing device. Background Art
[0002] With the continuous progress of virtualized cloud computing technology, virtualized networks (referred to as virtual networks for short) have become an indispensable part of the virtualized technology system, and the security issues of virtual networks have become increasingly prominent. A common method for managing virtual networks is implemented based on Open Virtual Network (OVN).
[0003] However, in the network management method implemented based on OVN, during the process of a virtual switch (Open vSwitch, OVS) filtering received packets, when the packet meets the outgoing rule (i.e., the rule used to indicate forwarding the packet) in the access control list (ACL) rule corresponding to a certain filtering level (such as a firewall applicable to a logical router or a security group applicable to a logical port of a virtual machine), the packet will be forwarded to the next hop of the routing path of the packet (i.e., the network traffic will be directly forwarded); as a result, the ACL rules corresponding to other filtering levels become ineffective, thus reducing the security of the virtual network. Summary of the Invention
[0004] The embodiments of the present application provide a method for controlling traffic of a virtual network and a computing device, which are used to improve the security of the virtual network.
[0005] To achieve the above object, the embodiments of the present application adopt the following technical solutions:
[0006] In a first aspect, the embodiments of the present application provide a method for controlling traffic of a virtual network, which is applied to a virtual network. The virtual network includes a virtual switch. The method includes: receiving a target packet through the virtual switch; filtering the target packet according to at least two rule flow tables through the virtual switch; at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables are used to indicate filtering rules of different filtering levels; sending the filtered target packet through the above virtual switch.
[0007] An embodiment of the present application provides a method for traffic control of a virtual network. This method is applied to a virtual network, which includes a virtual switch. The method includes using the virtual switch to filter the received target packets according to at least two rule flow tables and sending the filtered target packets. Since the at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables in the at least two rule flow tables are used to indicate filtering rules for different filtering levels. Therefore, the present application filters the target packets based on the filtering rules in the rule flow tables corresponding to different filtering levels, thereby avoiding the problem that the packets are directly forwarded when they meet the forwarding rules in the ACL rules corresponding to a certain filtering level. Thus, the security of the virtual network is improved.
[0008] In a possible implementation manner, the above-mentioned filtering of the target packets by the virtual switch according to at least two rule flow tables includes: when the flow direction of the target packet is the incoming direction, the virtual switch uses the rule flow tables corresponding to each filtering level to filter the target packet in the first preset order; when the flow direction of the target packet is the outgoing direction, the virtual switch uses the rule flow tables corresponding to each filtering level to filter the above-mentioned target packet in the second preset order.
[0009] In a possible implementation manner, the order of the first preset order and the second preset order is opposite.
[0010] In a possible implementation manner, the rule flow tables corresponding to each filtering level include: the rule flow table corresponding to the first filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the third filtering level; different filtering levels correspond to different types of logical devices. Among them, the type of the logical device corresponding to the first filtering level is a logical router, the type of the logical device corresponding to the second filtering level is a logical switch, and the type of the logical device corresponding to the third filtering level is the logical port of a virtual machine.
[0011] In a possible implementation, when the flow direction of the target packet is the incoming direction, the virtual switch filters the target packet using the rule flow tables corresponding to each filtering level in the first preset order, including: filtering the target packet through the virtual switch based on the rule flow table corresponding to the first filtering level; when the result of filtering the target packet based on the rule flow table corresponding to the first filtering level is an outgoing packet, filtering the target packet through the virtual switch based on the rule flow table corresponding to the second filtering level; where the result of packet filtering includes: discarding the packet or an outgoing packet; when the result of filtering the target packet based on the rule flow table corresponding to the second filtering level is an outgoing packet, filtering the target packet through the virtual switch based on the rule flow table corresponding to the third filtering level.
[0012] In the above embodiment, when the flow direction of the target packet is the incoming direction, the target packet is first filtered through the rule flow table corresponding to the first filtering level; when the result of the packet filtering is an outgoing packet, the target packet is then filtered through the rule flow table corresponding to the second filtering level. When the result of the packet filtering is an outgoing packet, the target packet is then filtered through the rule flow table corresponding to the third filtering level; the target packet will not be transferred out when it meets the transfer rule in the rule flow table corresponding to a certain filtering level (such as: the first filtering level), but the target packet will continue to be filtered through the rules in the rule flow table corresponding to the next filtering level (such as: the second filtering level). Therefore, the security of the virtual network is improved.
[0013] In a possible implementation, filtering the target packet through the virtual switch based on the rule flow table corresponding to the first filtering level includes: creating, through the virtual switch, a first new packet of the type logical router based on the target packet; the first new packet includes: the target packet; filtering the target packet in the first new packet through the virtual switch based on the rule flow table corresponding to the first filtering level.
[0014] In a possible implementation, the rule flow table corresponding to each of the above filtering levels includes a rule flow table in the inflow direction and a rule flow table in the outflow direction; wherein, the rule flow table in the inflow direction is used to filter packets with a flow direction of the inflow direction; the rule flow table in the outflow direction is used to filter packets with a flow direction of the outflow direction; the above-mentioned use of the virtual switch to filter the target packet according to the rule flow tables corresponding to each filtering level in the first preset order when the flow direction of the target packet is the inflow direction includes: using the virtual switch to filter the target packet according to the rule flow tables in the inflow direction among the rule flow tables corresponding to each filtering level in the first preset order when the flow direction of the target packet is the inflow direction.
[0015] In the above embodiment, the rule flow table corresponding to each filtering level is divided into a rule flow table in the inflow direction and a rule flow table in the outflow direction; since the rule flow table in the inflow direction is used to filter packets with a flow direction of the inflow direction; the rule flow table in the outflow direction is used to filter packets with a flow direction of the outflow direction; then, when the flow direction of the target packet is the inflow direction, the rule flow table in the inflow direction among the rule flow tables corresponding to each filtering level is used in the first preset order to filter the target packet; the target packet will not be transferred out when the target packet meets the transfer rule in the rule flow table in the inflow direction corresponding to a certain filtering level, but the target packet is filtered according to the filtering rules in the rule flow table in the inflow direction in the rule flow table corresponding to the next filtering level, so the security of the virtual network is improved.
[0016] In addition, since when the flow direction of the target packet is the inflow direction, the rule flow table in the inflow direction among the rule flow tables corresponding to each filtering level is used, and not all the filtering rules in the rule flow tables corresponding to each filtering level are used to filter the target packet, the efficiency of packet filtering is improved.
[0017] In a possible implementation, before the above-mentioned use of the virtual switch to filter the target packet according to at least two rule flow tables, the method further includes: using the virtual switch to obtain the network configuration information of the target packet; the network configuration information includes the source address of the target packet and / or the destination address of the target packet; the above-mentioned use of the virtual switch to filter the target packet according to at least two rule flow tables includes: using the virtual switch to filter the target packet according to the matching situation between the network configuration information and the filtering rules in at least two rule flow tables.
[0018] In a possible implementation, the above virtual network further includes: a southbound database, which includes a plurality of logical flow tables. The plurality of logical flow tables are used to indicate filtering rules at different filtering levels configured by a user. The method further includes:
[0019] When the first logical flow table in the above southbound database changes, update the first rule flow table corresponding to the target filtering level, so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table. The target filtering level is the filtering level corresponding to the first logical flow table; wherein, the different filtering levels include the target filtering level.
[0020] In the above embodiment, when the first logical flow table corresponding to the target filtering level in the southbound database changes, update the first rule flow table corresponding to the target filtering level, so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table; subsequently, the virtual switch docks with the updated rule flow table to perform packet filtering on the received packets, thereby improving the maintainability of multiple rule flow tables in the virtual switch.
[0021] In a possible implementation, the above updating the first rule flow table corresponding to the target filtering level includes: obtaining the above first logical flow table; determining the target filtering level and the target filtering rules newly added in the first logical flow table according to the first logical flow table; determining the first rule flow table according to the identifier of the first logical flow table; and updating the filtering rules of the first rule flow table according to the target filtering level and the target filtering rules.
[0022] In the above embodiment, when the first logical flow table in the southbound database changes, determine the target filtering level corresponding to the first logical flow table and the target filtering rules newly added in the first logical flow table based on the first logical flow table; then, determine the first rule flow table corresponding to the target filtering level based on the identifier of the first logical flow table; and update the target filtering rules to the first rule flow table; it can be seen that different rule flow tables corresponding to different types of filtering levels are set on the above virtual switch; compared with the existing virtual switch that only has one rule flow table in the incoming direction and one rule flow table in the outgoing direction, the embodiments of the present application divide the rule flow tables on the virtual switch according to different types of filtering levels, thereby avoiding the problem that the filtering rules corresponding to different types of filtering levels affect each other when the virtual switch performs packet filtering, thereby improving the accuracy of packet filtering, and thus improving the security of the virtual network.
[0023] In a possible implementation, the above-mentioned target filtering rule indicates the flow direction of the packet to be processed, and the flow direction includes an incoming direction or an outgoing direction; the rule flow table on the computing device where the above-mentioned virtual switch is located includes a rule flow table in the incoming direction and a rule flow table in the outgoing direction; determining the first rule flow table according to the identifier of the first logical flow table includes: determining, from the above-mentioned at least two rule flow tables, the rule flow table corresponding to the identifier of the first logical flow table; and determining, from the rule flow table corresponding to the identifier of the first logical flow table, the first rule flow table corresponding to the flow direction of the packet to be processed.
[0024] Based on the above-mentioned embodiments, the rule flow table on the virtual switch is divided according to different types of filtering levels (i.e., logical flow tables corresponding to different filtering levels), and the rule flow table corresponding to each type of filtering level is further divided according to the flow direction of the processed packet; then, when a target filtering rule is added to the above-mentioned first logical flow table, the rule flow table corresponding to the identifier of the first logical flow table is determined from at least two rule flow tables, and the first rule flow table corresponding to the flow direction of the packet to be processed is determined from the rule flow table corresponding to the identifier of the first logical flow table, and the target filtering rule is updated to the first rule flow table. Subsequently, when the virtual switch performs packet filtering, it only performs packet filtering on the packet based on the filtering rules in the rule flow table corresponding to the flow direction of the packet to be filtered. Therefore, the efficiency of packet filtering is improved.
[0025] In a possible implementation, when the first logical flow table in the above-mentioned southbound database changes, before updating the first rule flow table corresponding to the target filtering level, the method further includes: obtaining a configuration request; wherein, the configuration request includes: a target filtering rule corresponding to the target filtering level configured by the user; and updating the filtering rule in the first logical flow table according to the target filtering rule and the target filtering level.
[0026] Before updating the first rule flow table corresponding to the target filtering level on the virtual switch in the embodiments of the present application, by obtaining the target filtering rule corresponding to the target filtering level configured by the user and updating the first logical flow table corresponding to the target filtering level according to the target filtering rule and the target filtering level, so that the first logical flow table includes the above-mentioned target filtering rule; then, during the process of synchronizing the filtering rules from the southbound database to the virtual switch, even if the filtering rule to be synchronized is lost, it can be continuously obtained from the southbound database, thereby improving the stability of synchronizing the filtering rules to the virtual switch.
[0027] In a possible implementation, updating the filtering rules in the first logical flow table according to the target filtering rules and the target filtering level includes: determining, from multiple logical flow tables included in the southbound database, the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level; and updating the target filtering rules to the first logical flow table.
[0028] In a possible implementation, the above-mentioned target filtering rules indicate the flow direction of the packet to be processed, and the flow direction includes an incoming direction or an outgoing direction; the logical flow table corresponding to each logical device includes a logical flow table in the incoming direction and a logical flow table in the outgoing direction; wherein, the logical flow table in the incoming direction is used to filter packets with a flow direction of the incoming direction; the logical flow table in the outgoing direction is used to filter packets with a flow direction of the outgoing direction; determining, from multiple logical flow tables included in the southbound database, the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level includes: determining, based on the type identifier of the first logical device corresponding to the target filtering level, the logical flow table corresponding to the first logical device from the above-mentioned multiple logical flow tables; and determining, from the logical flow table corresponding to the first logical device, the first logical flow table corresponding to the flow direction of the packet to be processed.
[0029] In a possible implementation, the above-mentioned virtual network further includes: a northbound database; before updating the filtering rules in the first logical flow table according to the target filtering rules and the identifier of the first logical device corresponding to the target filtering level, the above-mentioned method further includes: updating the target filtering rules to the filtering rules corresponding to the target filtering level in the northbound database.
[0030] Before updating the first logical flow table in the southbound database in the embodiments of the present application, the target filtering rules configured by the user corresponding to the target filtering level obtained are updated to the filtering rules corresponding to the target filtering level in the northbound database, so that the filtering rules corresponding to the target filtering level in the northbound database include the target filtering rules; subsequently, during the process of updating the first logical flow table in the southbound database, even if the target filtering rules are lost, they can be retrieved from the northbound database again, thereby improving the stability of updating the southbound database.
[0031] In a second aspect, the embodiments of the present application provide a traffic control device for a virtual network, which is applied to a virtual network. The traffic control device for the virtual network includes: a virtual switch; the virtual switch is used to receive a target packet; the virtual switch is used to filter the target packet according to at least two rule flow tables; at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables are used to indicate filtering rules for different filtering levels; the virtual switch is used to send the filtered target packet.
[0032] In a possible implementation, when the flow direction of the above target packet is the incoming direction, the virtual switch uses the rule flow tables corresponding to each filtering level to filter the target packet in the first preset order; when the flow direction of the above target packet is the outgoing direction, the virtual switch uses the rule flow tables corresponding to each filtering level to filter the target packet in the second preset order.
[0033] In a possible implementation, the first preset order is opposite to the second preset order.
[0034] In a possible implementation, the rule flow tables corresponding to each filtering level include: the rule flow table corresponding to the first filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the third filtering level; different filtering levels correspond to different types of logical devices. Among them, the type of the logical device corresponding to the first filtering level is a logical router, the type of the logical device corresponding to the second filtering level is a logical switch, and the type of the logical device corresponding to the third filtering level is the logical port of a virtual machine.
[0035] In a possible implementation, the virtual switch is used to filter the target packet based on the rule flow table corresponding to the first filtering level; when the result of filtering the target packet based on the rule flow table corresponding to the first filtering level is a forwarded packet, the virtual switch is used to filter the target packet based on the rule flow table corresponding to the second filtering level; among them, the result of packet filtering includes: discarding the packet or forwarding the packet; when the result of filtering the target packet based on the rule flow table corresponding to the second filtering level is a forwarded packet, the virtual switch is used to filter the target packet based on the rule flow table corresponding to the third filtering level.
[0036] In a possible implementation, the virtual switch is used to create a first new packet of the type of logical router based on the target packet; the first new packet includes: the target packet; the virtual switch is used to filter the target packet in the first new packet based on the rule flow table corresponding to the first filtering level.
[0037] In a possible implementation, the rule flow table corresponding to each filtering level includes an incoming direction rule flow table and an outgoing direction rule flow table; among them, the incoming direction rule flow table is used to filter packets with the flow direction of the incoming direction; the outgoing direction rule flow table is used to filter packets with the flow direction of the outgoing direction; when the flow direction of the target packet is the incoming direction, the virtual switch uses the incoming direction rule flow tables corresponding to each filtering level in the first preset order to filter the target packet.
[0038] In a possible implementation, the virtual switch is used to obtain the network configuration information of the target packet; the network configuration information includes the source address of the target packet and / or the destination address of the target packet; the virtual switch is used to filter the target packet according to the matching situation between the network configuration information and the filtering rules in at least two rule flow tables.
[0039] In a possible implementation, the above virtual network further includes: a southbound database, the southbound database includes a plurality of logical flow tables, and the plurality of logical flow tables are used to indicate the filtering rules of different filtering levels configured by the user. The traffic control device of the above virtual network includes: an OVN controller; the OVN controller is used to update the first rule flow table corresponding to the target filtering level when the first logical flow table in the southbound database changes, so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table, and the target filtering level is the filtering level corresponding to the first logical flow table; wherein, different filtering levels include the target filtering level.
[0040] In a possible implementation, the OVN controller is used to obtain the first logical flow table; the OVN controller is used to determine the target filtering level and the target filtering rules newly added in the first logical flow table according to the first logical flow table; the OVN controller is used to determine the first rule flow table according to the identifier of the first logical flow table; the OVN controller is used to update the filtering rules of the first rule flow table according to the target filtering level and the target filtering rules.
[0041] In a possible implementation, the OVN controller is used to determine the rule flow table corresponding to the identifier of the first logical flow table from at least two rule flow tables; the OVN controller is used to determine the first rule flow table corresponding to the flow direction of the packet to be processed from the rule flow table corresponding to the identifier of the first logical flow table.
[0042] In a third aspect, an embodiment of the present application provides a traffic control device for a virtual network, which is applied to a virtual network. The traffic control device of the virtual network includes: a user interface module and a southbound call module; the user interface module is used to obtain a configuration request; wherein, the configuration request includes: the target filtering rules corresponding to the target filtering level configured by the user; the southbound call module is used to update the filtering rules in the first logical flow table according to the target filtering rules and the target filtering level; the first logical flow table is the logical flow table corresponding to the target filtering level in the southbound database.
[0043] In a possible implementation, the southbound call module is used to determine the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level from the plurality of logical flow tables included in the southbound database; the southbound call module is used to update the target filtering rules to the first logical flow table.
[0044] In a possible implementation, the southbound call module is configured to determine the logical flow table corresponding to the first logical device based on the type identifier of the first logical device corresponding to the target filtering level from multiple logical flow tables; the southbound call module is configured to determine, from the logical flow table corresponding to the first logical device, the first logical flow table corresponding to the flow direction of the packet to be processed.
[0045] In a possible implementation, the above virtual network further includes: a northbound database; the traffic control device of the above virtual network includes: a northbound call module; the northbound call module is configured to update the target filtering rule to the filtering rule corresponding to the target filtering level in the northbound database.
[0046] In a fourth aspect, an embodiment of the present application provides a computing device, which includes a memory and a processor, and the memory is coupled to the processor; the memory is configured to store computer program code, and the computer program code includes computer instructions; when the computer instructions are executed by the processor, it is to implement receiving a target packet through a virtual switch; filtering the target packet according to at least two rule flow tables through the virtual switch; at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables are used to indicate filtering rules of different filtering levels; sending the filtered target packet through the virtual switch.
[0047] In a fifth aspect, an embodiment of the present application provides a computing device, which includes a memory and a processor, and the memory is coupled to the processor; the memory is configured to store computer program code, and the computer program code includes computer instructions; when the computer instructions are executed by the processor, it is to implement obtaining a configuration request; wherein, the configuration request includes: a target filtering rule corresponding to a target filtering level configured by a user; updating the filtering rule in the first logical flow table according to the target filtering rule and the target filtering level.
[0048] In a sixth aspect, a computer-readable storage medium is provided, and the computer-readable storage medium stores computer instructions. When the computer instructions in the computer-readable storage medium are executed by a computing device, the computing device is caused to execute the functions of the apparatus in the first aspect and its possible implementation manners.
[0049] In a seventh aspect, a computer program product containing instructions is provided. When it runs on a computing device, the computing device is caused to execute the functions of the apparatus in the above first aspect and its possible implementation manners.
[0050] It should be understood that the beneficial effects obtained by the technical solutions of the second to seventh aspects and the corresponding possible implementation manners of the embodiments of the present application can refer to the technical effects of the first aspect and its corresponding possible implementation manners described above, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 A schematic diagram of a virtual network architecture provided by an embodiment of the present application;
[0052] Figure 2 A schematic diagram of a traffic control system provided by an embodiment of the present application;
[0053] Figure 3 A schematic diagram of the hardware structure of a computing device provided by an embodiment of the present application;
[0054] Figure 4 A schematic flow chart of a traffic control method for a virtual network provided by an embodiment of the present application Figure 1 ;
[0055] Figure 5 A schematic flow chart of a traffic control method for a virtual network provided by an embodiment of the present application Figure 2 ;
[0056] Figure 6 A schematic flow chart of a traffic control method for a virtual network provided by an embodiment of the present application Figure 3 ;
[0057] Figure 7 A schematic flow chart of a traffic control method for a virtual network provided by an embodiment of the present application Figure 4 ;
[0058] Figure 8 A schematic flow chart of a method for updating a rule flow table provided by an embodiment of the present application;
[0059] Figure 9 Another schematic flow chart of a method for updating a rule flow table provided by an embodiment of the present application;
[0060] Figure 10 A schematic flow chart of a method for updating a logical flow table in a southbound database provided by an embodiment of the present application;
[0061] Figure 11 Another schematic flow chart of a method for updating a logical flow table in a southbound database provided by an embodiment of the present application;
[0062] Figure 12 Another schematic flow chart of a method for updating a logical flow table in a southbound database provided by an embodiment of the present application;
[0063] Figure 13 A schematic flow chart of a method for updating a southbound database and a northbound database provided by an embodiment of the present application;
[0064] Figure 14 A schematic flow chart of a method for updating a northbound flow table in a northbound database provided by an embodiment of the present application;
[0065] Figure 15 This is a schematic structural diagram of a traffic control device 100 for a virtual network provided by an embodiment of the present application;
[0066] Figure 16 This is a schematic structural diagram of a traffic control device 200 for a virtual network provided by an embodiment of the present application. Detailed implementation manners
[0067] In this article, the term "and / or" is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone.
[0068] In the description of the embodiments of the present application, the terms "first" and "second" in the specification and claims are used to distinguish different objects, rather than to describe a specific order of the objects. For example, the first logical flow table and the second logical flow table are used to distinguish different logical flow tables, rather than to describe the specific order of the rule flow table.
[0069] In the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0070] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" refers to two or more. For example, a plurality of logical flow tables refers to two or more logical flow tables.
[0071] First, some concepts involved in a traffic control method for a virtual network and a computing device provided by the embodiments of the present application are explained as follows:
[0072] Logical router: A router virtualized in a virtual network. This router searches for the target Internet Protocol (IP) address and forwards data packets to the appropriate destination to achieve communication between different networks.
[0073] Logical switch: A switch virtualized in a virtual network that learns and forwards data frames based on the Media Access Control (MAC) address.
[0074] Logical port of a virtual machine: A virtual port simulated for a virtual machine.
[0075] Access Control List (ACL): A list that includes multiple rules or instructions. Network devices determine which data packets can be forwarded out and which need to be discarded based on the filtering rules or instructions in this list.
[0076] Firewall: A network security system, which is the first line of defense for network security and is mostly applied to routers. It aims to monitor and control network traffic, and decides whether to allow the transmission of data packets according to the predefined security rules therein, so as to achieve traffic (such as packets) filtering, prevent malicious attacks and record network activities; specifically, this firewall is the ACL rule applied to routers.
[0077] Network ACL: An ACL rule mostly applied to switch interfaces.
[0078] Security group: Used to control the inbound and outbound traffic of virtual machines, thereby improving the security of virtual machines. A security group contains security group rules and cloud resources (such as virtual machines, elastic network interfaces, etc.) within the security group. Users can configure security group rules to allow or deny the passage of specified types of network traffic; specifically, this security group is the ACL rule applied to virtual machines.
[0079] Packet filtering: It means that when the filtering rule (such as: ACL rule) satisfied by or to which the received packet belongs is a discard rule, the received packet is deleted; when the ACL rule satisfied by or to which the received packet belongs is a forwarding rule, the received packet is forwarded out. Among them, whether an ACL rule is a discard rule is determined based on the processing action of the ACL rule. When the processing action of the ACL rule is to discard the packet, the ACL rule is a discard rule; when the processing action of the ACL rule is to forward the packet, the ACL rule is a forwarding rule.
[0080] In common virtualized network management methods, when the received packet satisfies the forwarding rule in the ACL rule corresponding to a filtering level (such as: the firewall of a logical router), the received packet will be directly forwarded out, resulting in the invalidation of the ACL rules corresponding to other filtering levels (such as: logical switches), thus reducing the security of the virtual network.
[0081] Based on this, an embodiment of the present application provides a traffic control method for a virtual network. This method is applied to a virtual network, which includes a virtual switch. The method includes filtering the received target packet through the virtual switch according to at least two rule flow tables, and sending the filtered target packet. Since the at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables in the at least two rule flow tables are used to indicate filtering rules for different filtering levels, the present application filters the target packet based on the filtering rules in the rule flow tables corresponding to different filtering levels, thereby avoiding the problem that the packet is directly forwarded when it meets the forwarding rule in the ACL rule corresponding to a certain filtering level. Therefore, the security of the virtual network is improved.
[0082] An embodiment of the present application provides a traffic control method for a virtual network, and this method is applicable to Figure 1 the virtual network architecture shown in the figure; this network architecture includes: a control plane and a data plane.
[0083] The above control plane is used to configure filtering rules (such as: ACL rules) corresponding to different filtering levels for the data plane; among them, different logical devices correspond to different filtering levels, that is to say, the filtering rules corresponding to a filtering level are the filtering rules corresponding to the logical device corresponding to this filtering level. For example, in the case where different types of logical devices include: logical routers, logical switches, and logical ports of virtual machines, the filtering level corresponding to the logical router is the firewall, the filtering level corresponding to the logical switch is the network ACL, and the filtering level corresponding to the logical port of the virtual machine is the security group.
[0084] Exemplarily, the control plane is used to obtain the ACL rules configured by the user for different filtering levels in the data plane; then, the control plane synchronizes the ACL rules to the corresponding rule flow tables (i.e., openflow tables) in the data plane; so that the data plane filters the packets based on the ACL rules in the rule flow tables corresponding to different filtering levels.
[0085] It should be noted that the virtual network realizes the functions of the network devices (i.e., routers and switches) corresponding to the logical devices in the non-virtual network by virtualizing different types of logical devices (such as: logical routers and logical switches).
[0086] It should be understood that the above control plane and data plane can be deployed on the same computing device or on different computing devices. Specifically, the embodiments of the present application do not specifically limit whether the control plane and the data plane are deployed on the same computing device.
[0087] The above control plane includes: a northbound database and a southbound database; among them, the northbound database includes ACL rules corresponding to different types of logical devices (i.e., different filtering levels). For example, the northbound database includes: ACL rules corresponding to logical routers, ACL rules corresponding to logical switches, and ACL rules corresponding to the logical ports of virtual machines.
[0088] The above southbound database includes: logical flow tables corresponding to different types of logical devices; among them, the filtering levels corresponding to different logical devices are different, and the logical flow tables corresponding to one type of logical device include: logical flow tables in the incoming direction and logical flow tables in the outgoing direction.
[0089] Exemplarily, the above southbound database includes: the logical flow table in the incoming direction corresponding to the logical router (i.e., the lr_in_acl table) and the logical flow table in the outgoing direction (i.e., the lr_out_acl table), the logical flow table in the incoming direction corresponding to the logical switch (i.e., the ls_in_acl table) and the logical flow table in the outgoing direction (i.e., the ls_out_acl table), the logical flow table in the incoming direction corresponding to the logical port of the virtual machine (i.e., the lsp_in_acl table) and the logical flow table in the outgoing direction (i.e., the lsp_out_acl table).
[0090] Among them, the lr_in_acl table is used to store the ACL rules bound or configured for the logical router to control (i.e., filter) the packets flowing in the incoming direction; among them, the packets flowing in the incoming direction refer to the packets received from the external network (i.e., outside the scope controlled by the current logical device). The lr_out_acl table is used to store the ACL rules bound or configured for the logical router to control the packets flowing in the outgoing direction; among them, the packets flowing in the outgoing direction refer to the packets that need to be sent to the external network. The ls_in_acl table is used to store the ACL rules bound or configured for the logical switch to control the packets flowing in the incoming direction. The ls_out_acl table is used to store the ACL rules bound or configured for the logical switch to control the packets flowing in the outgoing direction. The lsp_in_acl table is used to store the ACL rules bound or configured for the logical port of the virtual machine to control the packets flowing in the incoming direction; the lsp_out_acl table is used to store the ACL rules bound or configured for the logical port of the virtual machine to control the packets flowing in the outgoing direction.
[0091] The above Figure 1 The data plane in the above includes: an OVN controller and an OVS. Among them, the OVN controller is used to synchronize the newly added ACL rules in the logical flow tables of the southbound database to the corresponding rule flow tables in the OVS.
[0092] The memory of the computing device where the above OVS is located includes rule flow tables corresponding to different types of logical devices (i.e., different filtering levels), and the rule flow tables corresponding to each type of logical device include: the rule flow table in the incoming direction and the rule flow table in the outgoing direction.
[0093] Exemplarily, the memory of the computing device where the OVS is located includes: the rule flow table corresponding to the logical router, the rule flow table corresponding to the logical switch, and the rule flow table corresponding to the logical port of the virtual machine. Among them, the rule flow table corresponding to the logical router includes: the rule flow table in the incoming direction (Table 27) and the rule flow table in the outgoing direction (Table 46); the rule flow table corresponding to the logical switch includes: the rule flow table in the incoming direction (Table 17) and the rule flow table in the outgoing direction (Table 44); the rule flow table corresponding to the logical port includes: the rule flow table in the incoming direction (Table 35) and the rule flow table in the outgoing direction (Table 50).
[0094] In the case where the control plane and the data plane are deployed on different computing devices, the above virtual network architecture is applied to a Figure 2 traffic control system as shown. Among them, the system includes: a control plane node deploying the above control plane and a data plane node deploying the above data plane; among them, the control plane node includes: a user interface module, a northbound call module, a northbound database, a daemon process module, a southbound call module, and a southbound database, and the data plane node includes: an OVN controller and an OVS.
[0095] It should be understood that the above traffic control system may include multiple data plane nodes ( Figure 2 not shown), or may include one data plane node; the embodiments of the present application take the above traffic control system including one data plane node as an example for description, and will not be elaborated hereinafter.
[0096] It should be noted that in the case where the above traffic control system includes multiple data plane nodes, the multiple data plane nodes are respectively connected to the above control plane node, so that the control plane node can issue filtering rules to each of the multiple control plane nodes.
[0097] Next, in combination with Figure 2 , for Figure 1 the interaction process between the northbound database, the southbound database, the OVN controller, and the OVS shown, the specific interaction process is as follows:
[0098] When the user triggers to configure a target ACL rule for the filtering level (i.e., network ACL) corresponding to the above first logical device (such as a logical switch), the user interface module in the control plane node obtains a configuration request including the identifier of the filtering level (abbreviation: target filtering level) and the target ACL rule, and sends the configuration request to the northbound call module.
[0099] The northbound call module receives the configuration request sent by the above user interface module, parses the configuration request, and obtains the identifier of the above target filtering level and the target ACL rule; then, based on the identifier of the target filtering level, the northbound call module updates the target ACL rule to the ACL rule corresponding to the target filtering level (i.e., logical switch) in the above northbound database.
[0100] The northbound call module is further configured to encapsulate the identifier of the first logical device corresponding to the target filtering level and the target ACL rule into an OVSDB message body to obtain a northbound OVSDB message body; and send the northbound OVSDB message body to the above daemon process module; wherein, the identifier of a logical device is used to indicate the type of the logical device.
[0101] The daemon process module receives and parses the northbound OVSDB message body sent by the northbound call module to obtain the identifier of the first logical device and the target ACL rule; then, based on a preset rule, updates the identifier of the first logical device to obtain the target identifier of the first logical device.
[0102] In one implementation manner, the above preset rule includes: concatenating a target string, the first x bits of the identifier of the logical device, the first n bits of the identifier of the target ACL rule, and a preset string to obtain a target identifier; both x and n are positive integers. Wherein, the above target strings corresponding to different types of logical devices are different.
[0103] For example, the target string corresponding to a logical router is "lr", the target string corresponding to a logical switch is "ls", and the target string corresponding to the logical port of a virtual machine is "lsp".
[0104] Exemplarily, assume that the target string corresponding to a logical switch is "lr"; the target string corresponding to a logical switch is "ls"; the target string corresponding to the logical port of a virtual machine is "lsp"; the identifier of the first logical device is xxxx1; the identifier of the target ACL rule is yyyy1; the preset string is "acl". Assume further that the values of both x and n are 3; then, when the first logical device is a logical switch, the generated first type identifier is "ls_xx1_yy1_acl".
[0105] The daemon process module is further configured to encapsulate the target ACL rule and the target identifier of the first logical device into an OVSDB message body to obtain a daemon OVSDB message body; and send the daemon OVSDB message body to the southbound call module.
[0106] The southbound call module receives and parses the OVSDB message body to obtain the target ACL rule and the target identifier of the first logical device; and when the target ACL rule is used to control (i.e., filter) the packets with the flow direction of the outgoing direction, update the target ACL rule to the logical flow table of the outgoing direction corresponding to the first logical device in the southbound database. When the target ACL rule is used to control the packets with the flow direction of the incoming direction, the southbound call module updates the target ACL rule to the logical flow table of the incoming direction corresponding to the first logical device in the southbound database.
[0107] When the OVN controller in the above data plane node detects that there is a newly added target ACL rule in the logical flow table in the southbound database, it sends a fetch request to the southbound call module.
[0108] Correspondingly, in response to the fetch request, the southbound call module encapsulates the first logical flow table that has changed in the southbound database into an OVSDB message body to obtain a southbound OVSDB message body; and sends the southbound OVSDB message body to the OVN controller.
[0109] The OVN controller receives and parses the southbound OVSDB message body to obtain the target ACL rule and the identifier of the target filtering level corresponding to the first logical flow table; and determines the second rule flow table in the memory of the control plane node where the OVS is located according to the identifier of the target filtering level; where the second rule flow table is the rule flow table corresponding to the above target filtering level. Then, the OVN controller updates the target ACL rule to the second rule flow table.
[0110] It should be understood that when there is a newly added ACL rule in the above ls_out_acl table, update the ACL rule to the rule flow table of the outgoing direction corresponding to the logical switch in the OVS (i.e., Table 17); when there is a newly added ACL rule in the above ls_in_acl table, update the ACL rule to the rule flow table of the incoming direction corresponding to the logical switch in the OVS (i.e., Table 44).
[0111] When there is a newly added ACL rule in the above lr_out_acl table, update the ACL rule to the rule flow table of the outgoing direction corresponding to the logical router in the OVS (i.e., Table 27); when there is a newly added ACL rule in the above lr_in_acl table, update the ACL rule to the rule flow table of the incoming direction corresponding to the logical router in the OVS (i.e., Table 46).
[0112] When there is a newly added ACL rule in the above lsp_out_acl table, update the ACL rule to the rule flow table in the egress direction corresponding to the logical port in OVS (i.e., Table 35); when there is a newly added ACL rule in the above lsp_in_acl table, update the ACL rule to the rule flow table in the ingress direction corresponding to the logical port in OVS (i.e., Table 50).
[0113] The above OVS is used to receive the target packet to be filtered and filter the target packet according to the filtering rules (such as ACL rules) in the rule flow tables corresponding to different filtering levels; for the specific implementation, see S120 in the following embodiments and will not be elaborated here.
[0114] It should be noted that the above control plane node and data plane node can be integrated on the same computing device or can be deployed on different computing devices respectively. Specifically, the embodiments of the present application do not limit the deployment of the above control plane node and data plane node.
[0115] Exemplarily, Figure 1 The schematic diagram of the hardware structure of the computing device on which the control plane and / or data plane in Figure 3 is deployed is as shown. Taking this computing device as a server as an example, from the perspective of form, the server can be a high-density server, a rack server or a full rack server; from the perspective of performance, it can be a general-purpose server, a GPU (graphics processing unit) server, etc. or an artificial intelligence (AI) server.
[0116] Among them, the hardware part of the computing device includes a processor, an out-of-band controller and a memory. The software part includes an out-of-band management module, processor firmware and an operating system (OS) management unit.
[0117] The above out-of-band management module runs in the out-of-band controller, the OS management unit runs in the processor, and the processor firmware can be located in the processor. Among them, the out-of-band management module can be a management unit for non-business modules. For example, the out-of-band management module can perform remote maintenance and management on the computing device through a dedicated data channel. The out-of-band management module is completely independent of the operating system of the computing device and can communicate with the OS through the out-of-band management interface of the computing device.
[0118] Exemplarily, the out-of-band management module may include a management unit for the operating mode of the computing device, a management system in a management chip outside the processor, a baseboard management controller (BMC) of the computing device motherboard, a system management mode (SMM), etc. It should be noted that the specific form of the out-of-band management module in the embodiments of the present application is not limited, and the above is only an exemplary illustration. In the following embodiments, only the BMC is used as an example of the out-of-band management module for illustration.
[0119] Among them, the memory, also known as the internal memory or main memory, is installed in the memory slot on the motherboard of the computing device, and the memory communicates with the memory controller through a memory channel.
[0120] It should be noted that the system architecture and application scenarios described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0121] The embodiments of the present application provide a method for controlling the traffic of a virtual network, and this method is applicable to Figure 1 the virtual network shown including a virtual switch (i.e., OVS); when the control plane and the data plane in the above virtual network are deployed on the same computing device as shown in Figure 3 the case shown, this method is applied to the processor in the computing device shown in Figure 3 the case shown, and this method includes: S110 - S130 as shown in Figure 4 the case shown.
[0122] S110: Receive a target packet through the virtual switch.
[0123] It should be noted that the above target packet may be a packet sent by a device in the external network to the virtual switch, that is, the target packet is a packet with a flow direction of the incoming direction; it may also be a packet sent by a device in the network where the virtual switch is located to the external network, that is, the target packet is a packet with a flow direction of the outgoing direction.
[0124] The implementation manner of the above S110 is that the virtual switch receives the target packet through the target port in the virtual switch. Among them, when the flow direction of the target packet is the incoming direction, the target port is the external port of the virtual switch used to receive packets in the external network. When the flow direction of the target packet is the outgoing direction, the target port is the internal port of the virtual switch used to receive packets in the internal network.
[0125] S120. Filter the target packet according to at least two rule flow tables through a virtual switch.
[0126] It should be noted that there are no network devices such as switches and routers in the virtual network. Instead, different types of logical devices (such as logical routers and logical switches) are virtualized to implement the functions of the corresponding network devices (i.e., routers and switches) in the non-virtual network. Among them, the specific implementation of the above virtualization of different types of logical devices includes: setting rule flow tables corresponding to different filtering levels for different types of logical devices on the virtual switch, so that the virtual switch can implement the function of filtering packets by different types of logical devices based on the filtering rules of different filtering levels.
[0127] The above at least two rule flow tables are the openflow tables of the above virtual switch; among them, the at least two rule flow tables are stored in the computing device (such as in memory) where the virtual switch is located.
[0128] It should be noted that the rule flow tables corresponding to different filtering levels are different, that is, different rule flow tables in the above at least two rule flow tables are used to indicate the filtering rules of different filtering levels; among them, different filtering levels correspond to different types of logical devices, that is to say, different types of logical devices correspond to different rule flow tables in the at least two rule flow tables.
[0129] For example, in the case where different types of logical devices include: logical routers, logical switches, and logical ports of virtual machines, the filtering level corresponding to the logical router is the firewall, the filtering level corresponding to the logical switch is the network ACL, and the filtering level corresponding to the logical port of the virtual machine is the security group.
[0130] It should be understood that the above filtering of the target packet includes: filtering the network configuration information of the target packet (such as the source address of the target packet, and / or five-tuple information such as the destination address of the target packet), and / or filtering the packet body of the target packet (such as the size of the packet body); specifically, the embodiments of the present application do not limit the content filtered by the packet filtering.
[0131] Among them, in the case where the above packet filtering is to filter the network configuration information of the target packet, the above S120 filters the target packet according to the matching situation between the network configuration information and the filtering rules in at least two rule flow tables. In the case where the above packet filtering is to filter the packet body of the target packet, the above S120 filters the target packet according to the matching situation between the packet body of the target packet and the filtering rules in at least two rule flow tables.
[0132] For ease of description, the rule flow tables corresponding to the above-mentioned filtering levels in this application embodiment include: the rule flow table corresponding to the first filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the third filtering level; among them, the type of the logical device corresponding to the first filtering level is a logical router, the type of the logical device corresponding to the second filtering level is a switch, and the type of the logical device corresponding to the third filtering level is the logical port of a virtual machine as an example for illustration, and will not be elaborated hereinafter.
[0133] When the flow direction of the target packet is the incoming direction, the implementation manner of the above S120 includes: through the virtual switch, using the rule flow tables corresponding to each filtering level to filter the above target packet in the first preset order; for the specific implementation of the above S120, refer to the following S210-S250, which will not be elaborated here.
[0134] The above first preset order is in turn: the rule flow table corresponding to the first filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the third filtering level.
[0135] It should be understood that when the virtual switch receives the target packet, the virtual switch can determine the flow direction of the target packet based on the port that receives the target packet. For specific reference, refer to the related technology, which will not be elaborated here.
[0136] When the flow direction of the above target packet is the outgoing direction, the implementation manner of the above S120 includes: through the virtual switch, using the rule flow tables corresponding to each filtering level to filter the target packet in the second preset order; among them, the first preset order is opposite to the second preset order.
[0137] The above second preset order is in turn: the rule flow table corresponding to the third filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the first filtering level.
[0138] It should be noted that the specific implementation manner of the above S120 when the flow direction of the above target packet is the outgoing direction is similar to the implementation manner of the above S120 when the flow direction of the above target packet is the incoming direction, and will not be elaborated here.
[0139] S130: Send the filtered target packet through the virtual switch.
[0140] It should be noted that the above S130 is the step executed by the processor through the virtual switch when the packet filtering result in S120 is a forwarded packet; correspondingly, when the packet filtering result in S120 is a discarded packet, the processor deletes the above target packet through the virtual switch.
[0141] When the flow direction of the target packet is the outgoing direction, the implementation method of S130 above includes: sending the target packet to a computing device in an external network through a virtual switch.
[0142] When the flow direction of the target packet is the incoming direction, the implementation method of S130 above includes: sending the target packet to a computing device in the internal network where the virtual switch is located through the virtual switch.
[0143] The embodiment of the present application provides a traffic control method for a virtual network. This method is applied to a virtual network, which includes a virtual switch. The method includes filtering the received target packet by the virtual switch according to at least two rule flow tables, and sending the filtered target packet; since the at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables in the at least two rule flow tables are used to indicate filtering rules for different filtering levels; therefore, the present application filters the target packet based on the filtering rules in the rule flow tables corresponding to different filtering levels, thereby avoiding the problem that the packet is directly transferred out when it meets the outgoing rule in the ACL rule corresponding to a certain filtering level. Therefore, the security of the virtual network is improved.
[0144] In one implementation, each filtering level in the above different filtering levels corresponds to one rule flow table among the above multiple rule flow tables (that is, at least two rule flow tables), that is, the multiple rule flow tables of the virtual switch respectively correspond to different filtering levels. Based on this, when the flow direction of the above target packet is the incoming direction, combined with Figure 4 , as Figure 5 shown, the specific implementation method of S120 above includes: S210-S250.
[0145] S210. Filter the target packet by the virtual switch based on the rule flow table corresponding to the first filtering level.
[0146] The results of the above packet filtering include: discarding the packet or transferring out the packet; among them, when the above target packet meets the discard rule in the rule flow table corresponding to the first filtering level, the packet filtering result is to discard the packet; among them, the discard rule is a rule used to indicate deleting the target packet. When the above target packet meets the transfer-out rule in the rule flow table corresponding to the first filtering level, the packet filtering result is to transfer out the packet; among them, the transfer-out rule is a rule used to indicate transferring out the target packet.
[0147] The above S210 includes multiple implementation methods, specifically as follows:
[0148] In the first implementation method, the implementation method of S210 includes: S211-S212.
[0149] S211. Create a first new packet of the type of logical router based on the target packet through the virtual switch.
[0150] The above first new packet includes: the above target packet.
[0151] It should be noted that since the type of the above first new packet is the logical router corresponding to the first filtering level, the virtual switch takes the first new packet as the packet received by the logical router. Subsequently, in the following S212, the target packet in the first new packet is filtered based on the rule flow table corresponding to the first filtering level of the logical router.
[0152] The implementation manner of the above S211 can be to encapsulate the above target packet and the identifier of the above logical router into the above first new packet through the virtual switch, or to add the identifier of the above logical router to the reserved field or the newly added field of the target packet to obtain the updated target packet (i.e., the first new packet); specifically, the embodiments of the present application do not limit the implementation manner of the above S211.
[0153] S212. Filter the target packet in the first new packet based on the rule flow table corresponding to the first filtering level through the virtual switch.
[0154] The implementation manner of the above S212 includes: determining the rule flow table corresponding to the first filtering level according to the identifier of the logical router in the first new packet; and then filtering the target packet based on the filtering rules in the rule flow table corresponding to the first filtering level.
[0155] It should be noted that the implementation manner of determining the rule flow table corresponding to the first filtering level is similar to the implementation manner of the following S530. For specific reference, see the relevant description of S530, which will not be elaborated here.
[0156] The specific implementation of filtering the target packet based on the filtering rules in the rule flow table corresponding to the first filtering level includes: determining the target rule that the target packet (such as the destination address of the target packet and / or the size of the packet body of the target packet) conforms to from the filtering rules included in the rule flow table corresponding to the first filtering level; and based on the processing action of the target rule, execute the following S220.
[0157] Table 1
[0158]
[0159] Exemplarily, assume that the rule flow table corresponding to the above first filtering level includes, as shown in Table 1 above: the identifier of the ACL rule and the ACL rule; wherein, the ACL rule includes: the rule content of the ACL rule and the processing action for indicating when the rule content is met. The rule flow table includes 2 ACL rules; wherein, the rule content included in the first ACL rule is the ip range of 192.168.3.0 - 192.168.3.9, and the processing action is to forward out; the rule content included in the second ACL rule is the ip range of 192.168.2.0 - 192.168.2.9, and the processing action is to delete.
[0160] Then, when the destination address of the above target packet is 192.168.3.5, since this destination address belongs to the rule with the identifier of 1 in the ACL rule (abbreviation: Rule 1); and since the processing action of this Rule 1 is the operation of forwarding out, that is, this Rule 1 is a forwarding out rule; so the packet filtering result of the above S212 is to forward out the packet. When the destination address of the above target packet is 192.168.2.6, since this destination address belongs to the rule with the identifier of 2 in the ACL rule (abbreviation: Rule 2), and since the processing action of this Rule 2 is the operation of deleting, that is, this Rule 2 is a discard rule; so the packet filtering result of the above S212 is to discard the packet.
[0161] In the second implementation manner, when the above packet filtering is to filter the network configuration information in the target packet, the implementation manner of the above S210 includes: creating a second new packet of the type of logical router based on the network configuration information in the target packet, and this second new packet includes this network configuration information; and based on the filtering rules in the rule flow table corresponding to the first filtering level, performing packet filtering on the network configuration information in this second new packet; the specific implementation manner is similar to the above S211 - S212, and will not be elaborated here.
[0162] It should be understood that when the packet filtering in this application is to filter the network configuration information in the target packet, before the above virtual switch executes the above S120, it is necessary to obtain the network configuration information of this target packet from the target packet; wherein, this network configuration information includes: the source address of the target packet, and / or the destination address of the target packet.
[0163] Optionally, the above network configuration information further includes: source network port, and / or destination network port, and / or information such as the identifier of the transport protocol, etc.
[0164] In the third implementation manner, the implementation manner of the above S210 is to directly perform rule filtering on the above target packet based on the filtering rules in the rule flow table corresponding to the first filtering level. For details, refer to the related technology and will not be elaborated here.
[0165] S220. Determine, via the virtual switch, whether the first filtering result is a forwarded packet.
[0166] The above first filtering result is the filtering result of packet filtering performed in S210 above.
[0167] In the case where the first filtering result is a forwarded packet, execute S230 below.
[0168] In the case where the first filtering result is a discarded packet, delete the above target packet via the virtual switch.
[0169] S230. Filter the target packet via the virtual switch based on the rule flow table corresponding to the second filtering level.
[0170] It should be noted that the implementation method of S230 above is similar to that of S210. For the specific description of S230, reference can be made to the relevant description of S210 above, which will not be elaborated here.
[0171] S240. Determine, via the virtual switch, whether the second filtering result is a forwarded packet.
[0172] The above second filtering result is the filtering result of packet filtering performed in S230 above.
[0173] In the case where the second filtering result is a forwarded packet, execute S250 below.
[0174] In the case where the second filtering result is a discarded packet, delete the above target packet via the virtual switch.
[0175] S250. Filter the target packet via the virtual switch based on the rule flow table corresponding to the third filtering level.
[0176] It should be noted that the implementation method of S250 above is similar to that of S210. For the specific description of S250, reference can be made to the relevant description of S210 above, which will not be elaborated here.
[0177] In the case where the packet filtering result in S250 above is a forwarded packet, execute S130 above via the virtual switch.
[0178] In the case where the packet filtering result in S250 above is a discarded packet, delete the above target packet via the virtual switch.
[0179] In the case where the flow direction of the target packet is the inflow direction in the above embodiments, the target packet is first filtered based on the rule flow table corresponding to the first filtering level; in the case where the packet filtering result is an egress packet, the target packet is then filtered based on the rule flow table corresponding to the second filtering level. In the case where the packet filtering result is an egress packet, the target packet is further filtered based on the rule flow table corresponding to the third filtering level; the target packet will not be transferred out when it meets the egress rule in the rule flow table corresponding to a certain filtering level (such as: the first filtering level), but the target packet is continuously filtered based on the rules in the rule flow table corresponding to the next filtering level (such as: the second filtering level). Therefore, the security of the virtual network is improved.
[0180] In another implementation, the rule flow table corresponding to each filtering level in the above multiple filtering levels includes: a rule flow table in the inflow direction and a rule flow table in the outflow direction; wherein, the rule flow table in the inflow direction is used to filter packets with a flow direction of the inflow direction; the rule flow table in the outflow direction is used to filter packets with a flow direction of the outflow direction. Based on this, in the case where the flow direction of the above target packet is the inflow direction, combined with Figure 4 , such as Figure 6 shown, the implementation of the above S120 includes: S310.
[0181] S310. Use the rule flow table in the inflow direction in the rule flow table corresponding to each filtering level in the first preset order through the virtual switch to filter the target packet.
[0182] The implementation of the above S310 includes: filtering the target packet based on the rule flow table in the inflow direction corresponding to the first filtering level through the virtual switch to obtain a third filtering result; in the case where the third filtering result is an egress packet, filtering the target packet based on the rule flow table in the inflow direction corresponding to the second filtering level to obtain a fourth filtering result; in the case where the fourth filtering result is an egress packet, filtering the target packet based on the rule flow table in the inflow direction corresponding to the third filtering level; its specific implementation is similar to the above S210 - S250 and will not be elaborated here.
[0183] In the above embodiments, the rule flow table corresponding to each filtering level is divided into a rule flow table in the inflow direction and a rule flow table in the outflow direction; since the rule flow table in the inflow direction is used to filter packets with the flow direction being the inflow direction; the rule flow table in the outflow direction is used to filter packets with the flow direction being the outflow direction; then, when the flow direction of the target packet is the inflow direction, the rule flow table in the inflow direction in the rule flow tables corresponding to each filtering level is used in the first preset order to filter the target packet; and the target packet will not be transferred out when the target packet meets the transfer-out rule in the rule flow table in the inflow direction corresponding to a certain filtering level, but the target packet is filtered based on the filtering rules in the rule flow table in the inflow direction in the rule flow table corresponding to the next filtering level. Therefore, the security of the virtual network is improved.
[0184] In addition, since when the flow direction of the target packet is the inflow direction, the rule flow table in the inflow direction in the rule flow tables corresponding to each filtering level is used, rather than using all the filtering rules in the rule flow tables corresponding to each filtering level to filter the target packet, the efficiency of packet filtering is improved.
[0185] It should be noted that the multiple rule flow tables in the virtual switch are obtained based on Figure 1 the multiple logical flow tables in the southbound database included in the control plane in the virtual network architecture shown; that is, the filtering rules in the above multiple rule flow tables are synchronized from the multiple logical flow tables in the southbound database to the multiple rule flow tables.
[0186] Based on this, combined with Figures 4 to 6 , as Figure 7 shown, the traffic control method for the virtual network provided by the embodiments of the present application further includes: S410.
[0187] S410. When the first logical flow table in the southbound database changes, update the first rule flow table corresponding to the target filtering level so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table.
[0188] The above southbound database is Figure 1 the southbound database in the control plane shown, the southbound database includes multiple logical flow tables, and the multiple logical flow tables include the above first logical flow table, that is, the first logical flow table is any one of the multiple logical flow tables.
[0189] Among them, the logical flow tables corresponding to different filtering levels are different, that is, the multiple logical flow tables are used to indicate the filtering rules of different filtering levels configured by the user; that is to say, the above southbound database includes the logical flow tables corresponding to the above different filtering levels; among them, the above target filtering level is any one of the above different filtering levels.
[0190] It should be understood that the types of logical devices corresponding to the above different filtering levels are different, where one type of logical device corresponds to one filtering level; that is to say, the logical flow tables corresponding to the different filtering levels included in the above southbound database are the logical flow tables corresponding to different types of logical devices; among them, the filtering rules in the logical flow table corresponding to one logical device (such as: logical router) are the filtering rules configured for this logical device.
[0191] It should be noted that the multiple logical flow tables in the above southbound database are classified and extracted from the security policies issued by the user according to the types of multiple logical devices virtualized in the virtual network; among them, when the security policy is used to configure filtering rules for the logical router, the filtering rules are updated to the logical flow table corresponding to the logical router in the southbound database; when the security policy is used to configure filtering rules for the logical switch, the filtering rules are updated to the logical flow table corresponding to the logical switch in the southbound database.
[0192] The multiple rule flow tables in the above virtual switch correspond one-to-one with the multiple logical flow tables in the above southbound database; among them, the rule flow table corresponding to one filtering level (such as: the first filtering level) corresponds to the logical flow table corresponding to this filtering level (i.e., the first filtering level) in the southbound database.
[0193] The above target filtering level is the filtering level corresponding to the above first logical flow table; that is to say, the above first logical flow table corresponds to the above first rule flow table.
[0194] It should be noted that the filtering rules included in the above first rule flow table being the same as the filtering rules in the first logical flow table means that in the case where the first rule flow table includes a certain filtering rule (such as: filtering rule A), the first logical flow table also includes this filtering rule A; among them, the data format of filtering rule A in the first rule flow table may be the same as or different from the data format of this filtering rule A in the first logical flow table. Specifically, the embodiments of the present application do not limit the data formats of the first rule flow table and the first logical flow table.
[0195] It should be understood that in the case where the data formats of the first rule flow table and the first logical flow table are different, it is necessary to convert the changed filtering rules (abbreviation: target filtering rules) in the above first logical flow table into the data format of the first rule flow table.
[0196] For example: update the id of the target filtering rule in the first logical flow table to the cookie field in the first rule flow table, update the id of the first logical device corresponding to the target filtering rule to the port field in the first rule flow table, and update the content of the target filtering rule to the rule content field in the first rule flow table.
[0197] Based on this, the implementation of the above S410 includes: the above processor passes through Figure 2 the OVN controller in to update the newly added target filtering rules in the first logical flow table corresponding to the target filtering level in the southbound database to the rule flow table (i.e., the first rule flow table) corresponding to the target filtering level in the virtual switch, so that the rule flow table corresponding to the target filtering level in the virtual switch is the same as the filtering rules included in the logical flow table corresponding to the target filtering level in the southbound database; for the specific implementation, refer to the following S510-S540, which will not be elaborated here.
[0198] In the case where the first logical flow table corresponding to the target filtering level in the southbound database changes in the above embodiment, the first rule flow table corresponding to the target filtering level is updated, so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table; subsequently, the virtual switch docks with the updated rule flow table to perform message filtering on the received messages, thereby improving the maintainability of multiple rule flow tables in the virtual switch.
[0199] Combined with Figure 7 such as Figure 8 shown, in the case where the first logical flow table in the southbound database changes, the implementation of updating the first rule flow table corresponding to the target filtering level in the above S410 includes: S510-S540.
[0200] S510. Obtain the first logical flow table.
[0201] In a possible implementation manner, the implementation of the above S510 includes: when the OVN controller detects that there is a changed logical flow table in the southbound database, the OVN controller sends a fetch request to the southbound call module; in response to the fetch request, the southbound call module encapsulates the changed first logical flow table in the southbound database into an OVSDB message body and sends it to the above OVN controller, and the OVN controller obtains the above first logical flow table by parsing the above OVSDB message body.
[0202] S520. Determine the target filtering level and the newly added target filtering rules in the first logical flow table according to the first logical flow table.
[0203] The above target filtering level is the filtering level corresponding to the above first logical flow table, where the logical device corresponding to the target filtering level is the first logical device.
[0204] Determining the target filtering level according to the first logical flow table in S520 above includes: calling the OVN controller to parse the first logical flow table to obtain the identifier (e.g., name) of the first logical flow table; then, determining the target filtering level corresponding to the first logical flow table according to the identifier of the first logical flow table.
[0205] The implementation manner of determining the target filtering level according to the identifier of the first logical flow table above may be to determine the target filtering level based on all characters in the identifier of the first logical flow table; or to determine the target filtering level based on some characters in the identifier of the first logical flow table; specifically, the embodiments of the present application do not limit the implementation manner of determining the target filtering level according to the identifier of the first logical flow table.
[0206] For example, in the case of determining the target filtering level based on all characters in the identifier of the first logical flow table, assuming that the identifier of the first logical flow table is the table name of the first logical flow table; then, when the identifier of the first logical flow table is used to indicate "firewall", the first filtering level corresponding to the firewall is determined as the target filtering level; when the identifier of the first logical flow table is used to indicate "network ACL", the second filtering level corresponding to the network ACL is determined as the target filtering level; when the identifier of the first logical flow table is used to indicate "security group", the third filtering level corresponding to the security group is determined as the target filtering level.
[0207] Another example, in the case of determining the target filtering level based on some characters in the identifier of the first logical flow table, when the identifier of the first logical flow table includes the character "lr_", the first filtering level corresponding to the firewall is determined as the target filtering level; when the identifier of the first logical flow table includes the character "ls_", the second filtering level corresponding to the network ACL is determined as the target filtering level; when the identifier of the first logical flow table includes the character "lsp_", the third filtering level corresponding to the security group is determined as the target filtering level.
[0208] The implementation manner of determining the target filtering rule newly added in the first logical flow table in S520 above may be to determine the filtering rule with the most recent insertion time as the target filtering rule based on the insertion time of the filtering rules in the first logical flow table; or to determine the target filtering rule by comparing the first logical flow table before the change with the first logical flow table after the change. Specifically, the embodiments of the present application do not limit the implementation manner of determining the target filtering rule.
[0209] S530. Determine the first rule flow table according to the identifier of the first logical flow table.
[0210] In one implementation, when at least two rule flow tables (i.e., multiple rule flow tables) of the virtual switch respectively correspond to different filtering levels, the implementation of the above S530 includes: calling the OVN controller to determine the rule flow table corresponding to the identifier of the first logical flow table among the multiple rule flow tables of the virtual switch as the first rule flow table.
[0211] The above first rule flow table is the rule flow table corresponding to the above target filtering level.
[0212] The implementation method of determining the rule flow table corresponding to the identifier of the first logical flow table among the multiple rule flow tables of the virtual switch as the first rule flow table includes:
[0213] When the identifier of the first logical flow table indicates that the first logical flow table is the logical flow table corresponding to the first filtering level (i.e., firewall) (i.e., the identifier of the first logical flow table includes the character "lr"), determine the rule flow table corresponding to the first filtering level (such as the lr_rule_table table) among the multiple rule flow tables as the first rule flow table.
[0214] When the identifier of the first logical flow table indicates that the first logical flow table is the logical flow table corresponding to the second filtering level (i.e., network ACL) (i.e., the identifier of the first logical flow table includes the character "ls"), determine the rule flow table corresponding to the second filtering level (such as the ls_rule_table table) among the multiple rule flow tables as the first rule flow table.
[0215] When the identifier of the first logical flow table indicates that the first logical flow table is the logical flow table corresponding to the third filtering level (i.e., security group) (i.e., the identifier of the first logical flow table includes the character "lsp"), determine the rule flow table corresponding to the third filtering level (such as the lsp_rule_table table) among the multiple rule flow tables as the first rule flow table.
[0216] In another implementation, when the rule flow table corresponding to each filtering level includes a rule flow table in the inbound direction and a rule flow table in the outbound direction, the implementation of the above S530 is as Figure 9 shown and includes: S531 - S532.
[0217] S531. Determine the rule flow table corresponding to the identifier of the first logical flow table from at least two rule flow tables.
[0218] The above at least two rule flow tables are the rule flow tables stored in the computing device where the virtual switch is located.
[0219] The rule flow table corresponding to the identifier of the above first logical flow table includes: a rule flow table in the inbound direction and a rule flow table in the outbound direction.
[0220] Exemplarily, assume that multiple logical flow tables in the southbound database shown in Table 2 below include: the logical flow table corresponding to the firewall, the logical flow table corresponding to the network ACL, and the logical flow table corresponding to the security group; the identifier of the logical flow table corresponding to the firewall includes "lr", the identifier of the logical flow table corresponding to the network ACL includes "ls", and the identifier of the logical flow table corresponding to the security group includes "lsp". Among them, the rule flow table corresponding to "lr" (i.e., the rule flow table corresponding to the logical router) includes: the lr_in_rule_table table and the lr_out_rule_table table; the rule flow table corresponding to "ls" (i.e., the rule flow table corresponding to the logical switch) includes: the ls_in_rule_table table and the ls_out_rule_table table; the rule flow table corresponding to "lsp" (i.e., the rule flow table corresponding to the logical port of the virtual machine) includes: the lsp_in_rule_table table and the lsp_out_rule_table table.
[0221] Then, when the identifier of the first logical flow table includes "lr", the rule flow table corresponding to the identifier of the first logical flow table includes: the lr_in_rule_table table and the lr_out_rule_table table.
[0222] Table 2
[0223]
[0224] S532. Determine a first rule flow table corresponding to the flow direction of the to-be-processed packet from the rule flow table corresponding to the identifier of the first logical flow table.
[0225] The target filtering rule in S520 above indicates the flow direction of the to-be-processed packet, and the flow direction of the packet includes the inflow direction or the outflow direction; that is, the flow direction of the to-be-processed packet is the flow direction of the packet to be filtered by the target filtering rule.
[0226] The flow direction of the packet processed by the filtering rule in the first rule flow table is consistent with the flow direction of the to-be-processed packet indicated by the target filtering rule. Among them, when the flow direction of the to-be-processed packet is the inflow direction, the first rule flow table is the rule flow table in the inflow direction corresponding to the identifier of the first logical flow table (e.g., the lr_in_rule_table table); when the flow direction of the to-be-processed packet is the outflow direction, the first rule flow table is the rule flow table in the outflow direction corresponding to the identifier of the first logical flow table (e.g., the lr_out_rule_table table).
[0227] The implementation method of the above S532 includes: calling the OVN controller to determine the rule flow table whose packet flow direction for filtering included in the rule flow table in the incoming direction and the rule flow table in the outgoing direction corresponding to the identifier of the first logical flow table is the same as the packet flow direction of the above to-be-processed packet as the above first rule flow table.
[0228] Optionally, in the case that the above first rule flow table does not exist in the rule flow table corresponding to the identifier of the first logical flow table, call the OVN controller to create the first rule flow table in the computing device where the above virtual switch is located.
[0229] For example, in the case that the above first rule flow table is the rule flow table in the incoming direction corresponding to the firewall, call the OVN controller to create Table 27 as the first rule flow table; in the case that the above first rule flow table is the rule flow table in the outgoing direction corresponding to the firewall, create Table 46 as the first rule flow table. In the case that the above first rule flow table is the rule flow table in the incoming direction corresponding to the network ACL, create Table 17 as the first rule flow table; in the case that the above first rule flow table is the rule flow table in the outgoing direction corresponding to the network ACL, create Table 44 as the first rule flow table. In the case that the above first rule flow table is the rule flow table in the incoming direction corresponding to the security group, create Table 35 as the first rule flow table; in the case that the above first rule flow table is the rule flow table in the outgoing direction corresponding to the security group, create Table 50 as the first rule flow table.
[0230] Based on the division of the rule flow tables on the virtual switch according to different types of filtering levels (i.e., logical flow tables corresponding to different filtering levels) in the above embodiments, the rule flow tables corresponding to each type of filtering level are further divided according to the packet flow direction of the processed packets; then, in the case of adding a target filtering rule to the above first logical flow table, determine the rule flow table corresponding to the identifier of the first logical flow table from at least two rule flow tables, and determine the first rule flow table corresponding to the packet flow direction of the to-be-processed packet from the rule flow table corresponding to the identifier of the first logical flow table, and update the target filtering rule to the first rule flow table. Subsequently, when the above virtual switch performs packet filtering, it only filters the packet based on the filtering rules in the rule flow table corresponding to the packet flow direction of the to-be-filtered packet, so the efficiency of packet filtering is improved.
[0231] S540. Update the filtering rules of the first rule flow table according to the target filtering level and the target filtering rule.
[0232] It should be noted that in the above S520, when parsing the first logical flow table and obtaining the identifier of the first logical flow table, it is also necessary to parse the filtering rules in the first logical flow table; for example, by parsing the datapath field, the identifier of the filtering rule, the content of the filtering rule, the processing action of the filtering rule, and the type and identifier of the logical device corresponding to the filtering rule are obtained.
[0233] Exemplarily, the implementation method of the above S540 includes: storing the identifier of the target filtering rule parsed from the first logical flow table in the cookie field of the first rule flow table, storing the identifier of the logical device in the port field, storing the type of the logical device corresponding to the target filtering rule in the meta field, storing the target filtering rule in the rule content field, and storing the processing action of the target filtering rule in the processing action field.
[0234] It should be noted that the identifiers of the logical devices recorded in the rule flow tables corresponding to different filtering levels are different; specifically, in the rule flow table corresponding to the first filtering level of the firewall, the port field records the identifier of the logical router; in the rule flow table corresponding to the second filtering level of the network ACL, the port field records the identifier of the logical switch; in the rule flow table corresponding to the third filtering level of the security group, the port field records the identifier of the logical port of the virtual machine.
[0235] The updated first rule flow table above includes the above target filtering rule.
[0236] Exemplarily, assume that the above first rule flow table is as shown in Table 1 above; assume further that the rule content included in the above target filtering rule is the IP range of 192.168.13.0 - 192.168.14.9, and the processing action is deletion. Then, update the target filtering rule to the above first rule flow table to obtain the first rule flow table including the target filtering rule as shown in Table 3 below.
[0237] Table 3
[0238]
[0239] In the case where the first logical flow table in the southbound database in the above embodiments changes, determine a target filtering level corresponding to the first logical flow table and a target filtering rule newly added to the first logical flow table based on the first logical flow table; then, determine a first rule flow table corresponding to the target filtering level based on the identifier of the first logical flow table; and update the target filtering rule to the first rule flow table; it can be seen that different rule flow tables corresponding to different types of filtering levels are set on the above virtual switch; compared with the existing virtual switch that only has one rule flow table in the incoming direction and one rule flow table in the outgoing direction, the embodiments of the present application divide the rule flow tables on the virtual switch according to different types of filtering levels, thereby avoiding the problem that the filtering rules corresponding to different types of filtering levels affect each other when the virtual switch performs packet filtering, thereby improving the accuracy of packet filtering, and thus improving the security of the virtual network.
[0240] It should be noted that the filtering rules in the multiple logical flow tables in the above southbound database are configured by the user for different filtering levels; that is to say, after the user configures the filtering rules for a filtering level, the filtering rules will be updated to the logical flow table corresponding to the filtering level in the southbound database to cause the logical flow table to change.
[0241] Based on this, in combination with Figure 8 or Figure 9 , as Figure 10 shown, before the above S410 or S510, the method further includes: S610-S620.
[0242] S610. Obtain a configuration request.
[0243] The above configuration request is a request triggered by the user in the display interface, and the configuration request includes: the target filtering rule corresponding to the target filtering level configured by the user.
[0244] Among them, there are multiple ways to trigger the above configuration request, specifically as follows:
[0245] The first implementation method is that the user selects the target filtering level in the display interface and selects or enters the target filtering rule to be configured (or bound) for the target filtering level; then, clicks the OK button in the display interface; at this time, the processor obtains the above configuration request from the display interface.
[0246] In the second implementation method, the user selects the first logical device in the display interface and selects or enters the target filtering rule to be configured (or bound) for the first logical device; then, clicks the OK button in the display interface; at this time, the processor obtains the above configuration request from the display interface.
[0247] In the third implementation method, the user selects a first logical device in the first display interface, and then, in the second display interface, selects or inputs a target filtering rule to be configured (or bound) for the first logical device, and clicks an association button in the second display interface for associating the first logical device with the target filtering rule; at this time, the processor obtains the above configuration request from the display interface.
[0248] The implementation method of the above S610 includes: when the user triggers to configure the above target filtering rule for a target filtering level (such as: firewall or security group) from the display interface, the above processor obtains from the display interface a configuration request including: the above target filtering rule and the identifier of the target filtering level.
[0249] S620. Update the first logical flow table according to the target filtering rule and the target filtering level.
[0250] In one implementation method, the multiple logical flow tables in the above southbound database are respectively logical flow tables corresponding to different types of logical devices; that is to say, each of the above logical devices corresponds to a logical flow table in the southbound database.
[0251] Based on this, combined with Figure 10 , such as Figure 11 shown, the implementation method of the above S620 includes: S620A - S620B.
[0252] S620A. Determine the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level from the multiple logical flow tables in the southbound database.
[0253] The type identifier of the above first logical device is used to indicate the type of the first logical device; for example, when the type identifier of the first logical device is "lr", the above first logical device is a logical router; when the type identifier of the first logical device is "ls", the above first logical device is a logical switch; when the type identifier of the first logical device is "lsp", the above first logical device is the logical port of a virtual machine.
[0254] The implementation method of the above S620A includes: based on the identifier of the target filtering level, determine the identifier of the first logical device corresponding to the target filtering level, and then, based on the type identifier of the first logical device, determine the first logical flow table corresponding to the first logical device in the southbound database.
[0255] Exemplarily, assume that the relationships between different types of logical devices and multiple logical flow tables in the southbound database are as shown in Table 4 below; the type identifier of the logical port of the virtual machine is "lsp", the type identifier of the logical switch is "ls", and the type identifier of the logical router is "lr"; the logical flow tables in the southbound database include: lsp_acl_table, ls_acl_table, and lr_acl_table; among them, "lsp" corresponds to the lsp_acl_table, "ls" corresponds to the ls_acl_table, and "lr" corresponds to the lr_acl_table. Then, when the type identifier of the first logical device includes "lsp", the above-mentioned first logical flow table is the lsp_acl_table; when the type identifier of the first logical device includes "ls", the above-mentioned first logical flow table is the ls_acl_table; when the type identifier of the first logical device includes "lr", the above-mentioned first logical flow table is the lr_acl_table.
[0256] Table 4
[0257] Type identifier of the logical device Identifier of the logical flow table in the southbound database lsp (logical port of the virtual machine) lsp_acl_table ls (logical switch) ls_acl_table lr (logical router) lr_acl_table
[0258] S620B. Update the target filtering rule to the first logical flow table.
[0259] The implementation method of the above S620B includes: updating the target filtering rule to the first logical flow table so that the updated first
[0260] logical flow table includes the above target filtering rule.
[0261] Exemplarily, assume that the above-mentioned first logical flow table is as shown in Table 1 above; further assume that the rule content included in the above target filtering rule is the ip range from 192.168.13.0 to 192.168.14.9, and the processing action is deletion. Then, after updating the target filtering rule to the first logical flow table, the updated first logical flow table is as shown in Table 3 above and includes the target filtering rule.
[0262] In another implementation method, the logical flow tables corresponding to each type of logical device in the above southbound database include: the logical flow table in the incoming direction and the logical flow table in the outgoing direction. Among them, the filtering rule in the logical flow table in the incoming direction is a rule for filtering packets with a flow direction of the incoming direction; the filtering rule in the logical flow table in the outgoing direction is a rule for filtering packets with a flow direction of the outgoing direction.
[0263] Based on this, the implementation manner of the above S620 includes: determining a first logical flow table based on the type identifier of the first logical device corresponding to the target filtering level and the flow direction of the packet to be processed indicated by the target filtering rule; the flow direction of the packet to be processed is the flow direction of the packet to be processed by the target filtering rule; then, updating the target filtering rule to the first logical flow table so that the updated first logical flow table includes the above target filtering rule; for the specific implementation, refer to the following S620a - S620c, which will not be elaborated here.
[0264] Before updating the first rule flow table corresponding to the target filtering level on the virtual switch in the embodiment of the present application, by obtaining the target filtering rule corresponding to the target filtering level configured by the user, and based on the target filtering rule and the target filtering level, updating the first logical flow table corresponding to the target filtering level so that the first logical flow table includes the above target filtering rule; then, during the process of synchronizing the filtering rule from the southbound database to the virtual switch, even if the filtering rule to be synchronized is lost, it can be continuously obtained from the southbound database, thereby improving the stability of synchronizing the filtering rule to the virtual switch.
[0265] In an implementation manner, when the logical flow table corresponding to each type of logical device in the above southbound database includes: a logical flow table in the inflow direction and a logical flow table in the outflow direction, in combination with Figure 10 As Figure 12 shown, the implementation method of the above S620 includes: S620a - S620c.
[0266] S620a. Based on the type identifier of the first logical device corresponding to the target filtering level, determine the logical flow table corresponding to the first logical device from multiple logical flow tables.
[0267] The logical flow table corresponding to the first logical device includes: a logical flow table in the inflow direction and a logical flow table in the outflow direction.
[0268] Exemplarily, assume that the correspondence between different types of logical devices and multiple logical flow tables in the southbound database is as shown in Table 5 below; among them, the type identifiers of different types of logical devices include: "lsp", "ls", and "lr"; the above-mentioned multiple logical flow tables include: lsp_in_acl table (i.e., the logical flow table for the incoming direction corresponding to the logical port of the virtual machine), lsp_out_acl table (i.e., the logical flow table for the outgoing direction corresponding to the logical port of the virtual machine), ls_in_acl table (i.e., the logical flow table for the incoming direction corresponding to the logical switch), ls_out_acl table (i.e., the logical flow table for the outgoing direction corresponding to the logical switch), lr_in_acl table (i.e., the logical flow table for the incoming direction corresponding to the logical router), and lr_out_acl table (i.e., the logical flow table for the outgoing direction corresponding to the logical router). Among them, the logical flow tables corresponding to "lsp" include: lsp_in_acl table and lsp_out_acl table; the logical flow tables corresponding to "ls" include: ls_in_acl table and ls_out_acl table; the logical flow tables corresponding to "lr" include: lr_in_acl table and lr_out_acl table.
[0269] Then, when the type identifier of the first logical device is "lr", the sub-logical flow table for the incoming direction included in the logical flow table corresponding to the first logical device is the lr_in_acl table, and the sub-logical flow table for the outgoing direction is the lr_out_acl table.
[0270] Table 5
[0271]
[0272] It should be noted that the implementation manner of the above S620a is similar to that of S620A. For the specific description of S620a, reference can be made to the relevant description of S620A above, and it will not be elaborated here.
[0273] S620b. Determine the first logical flow table corresponding to the flow direction of the packet to be processed from the logical flow table corresponding to the first logical device.
[0274] The above target filtering rule indicates the flow direction of the packet to be processed, and the flow direction of the packet includes the incoming direction or the outgoing direction; that is, the flow direction of the packet to be processed is the flow direction of the packet to be filtered by the target filtering rule.
[0275] For example, when the flow direction of the packet to be processed is the incoming direction, the target filtering rule is used to filter packets with the incoming direction; when the flow direction of the packet to be processed is the outgoing direction, the target filtering rule is used to filter packets with the outgoing direction.
[0276] The flow direction of the packets processed by the filtering rules (such as: ACL rules) in the above-mentioned first logical flow table is consistent with the flow direction of the above-mentioned packets to be processed. Among them, when the flow direction of the above-mentioned packets to be processed is the incoming direction, the above-mentioned first logical flow table is the logical flow table in the incoming direction corresponding to the first logical device (such as: lr_in_acl table); when the flow direction of the above-mentioned packets to be processed is the outgoing direction, the above-mentioned first logical flow table is the logical flow table in the outgoing direction corresponding to the first logical device (such as: lr_out_acl table).
[0277] The implementation manner of the above S620b includes: using, as the above-mentioned first logical flow table, the logical flow table in which the flow direction of the packets filtered by the filtering rules included in the logical flow table in the incoming direction and the logical flow table in the outgoing direction corresponding to the first logical device is consistent with the flow direction of the above-mentioned packets to be processed.
[0278] Exemplarily, based on the example of the above S620a, when the flow direction of the above-mentioned packets to be processed is the incoming direction, the lr_in_acl table is determined as the first logical flow table; when the flow direction of the above-mentioned packets to be processed is the outgoing direction, the lr_out_acl table is determined as the first logical flow table.
[0279] Optionally, when the above-mentioned first logical flow table does not exist in the logical flow table corresponding to the first logical device, create the first logical flow table.
[0280] For example, when the above-mentioned first logical flow table is the logical flow table in the incoming direction corresponding to the logical router, create table 43 as the first logical flow table; when the above-mentioned first logical flow table is the logical flow table in the outgoing direction corresponding to the logical router, create table 76 as the first logical flow table. When the above-mentioned first logical flow table is the logical flow table in the incoming direction corresponding to the logical switch, create table 42 as the first logical flow table; when the above-mentioned first logical flow table is the logical flow table in the outgoing direction corresponding to the logical switch, create table 75 as the first logical flow table. When the above-mentioned first logical flow table is the logical flow table in the incoming direction corresponding to the logical port of the virtual machine, create table 41 as the first logical flow table; when the above-mentioned first logical flow table is the logical flow table in the outgoing direction corresponding to the logical port of the virtual machine, create table 74 as the first logical flow table.
[0281] S620c, update the target filtering rule to the first logical flow table.
[0282] The implementation manner of the above S620c is similar to the implementation manner of S620B. For the specific description of S620c, reference can be made to the relevant description of S620B above, and details are not described here again.
[0283] It should be noted that the above virtual network also includes: a northbound database, and the filtering rules in the northbound database need to be updated before updating the logical flow table in the southbound database.
[0284] Based on this, an embodiment of the present application provides a specific implementation method, in conjunction with Figures 10 to 12 , as Figure 13 shown, the method includes: S710 - S770.
[0285] S710. The user interface module obtains a configuration request including a target filtering rule corresponding to a target filtering level configured by the user.
[0286] The above user interface module is Figure 2 the user interface module included in the control plane node in
[0287] ; this user interface module is used to obtain the request from the display interface when the user triggers a request on the display interface (such as: a request for the user to configure a target filtering rule for the target filtering level).
[0288] The configuration request in S710 above is the same as the configuration request in S610. For the specific description of the configuration request in S710, reference can be made to the relevant description of S610 above, which will not be elaborated here.
[0289] The implementation manner of S720 above includes: the user interface module sends the above configuration request to the northbound call module through a communication link with Figure 2 the northbound call module in
[0290] S730. The northbound call module updates the target filtering rule to the northbound database.
[0291] It should be understood that after the northbound call module obtains the configuration request sent by the above user interface module, by parsing the configuration request, it obtains the identifier of the target filtering level and the target filtering rule; among them, the target filtering rule includes: the content of the target filtering rule and the processing action of the target filtering rule.
[0292] In the case that the above target filtering rule is a filtering rule selected by the user on the display interface, the above target filtering rule may further include: the identifier of the target filtering rule.
[0293] It should be noted that the filtering rules corresponding to different filtering levels in the northbound database are different; that is to say, the northbound database includes filtering rules corresponding to different filtering levels.
[0294] The implementation method of the above S730 includes: through the northbound call module, based on the identifier of the target filtering level obtained by the northbound call module, determining the filtering rule corresponding to the target filtering level in the northbound database, and updating the target filtering rule to the filtering rule corresponding to the target filtering level, so that the filtering rule corresponding to the updated target filtering level includes the target filtering rule; for the specific implementation, refer to the related technology and will not be elaborated here.
[0295] In one implementation, the northbound database includes multiple northbound flow tables, and the northbound flow tables corresponding to different filtering levels are different; among them, different filtering levels correspond to different types of logical devices, that is to say, the northbound flow tables corresponding to different types of logical devices are different; based on this, the implementation method of the above S730 is referred to S730A - S730B below and will not be elaborated here.
[0296] S740. The northbound call module sends a northbound OVSDB message body to the daemon process module.
[0297] The implementation method of the above S740 includes: the northbound call module determines the identifier of the first logical device corresponding to the target filtering level based on the identifier of the target filtering level; then, the northbound call module encapsulates the target filtering rule and the identifier of the first logical device into an OVSDB message body to obtain the northbound OVSDB message body; then, the northbound call module passes through the Figure 2 communication link with the daemon process module in to send the northbound OVSDB message body to the daemon process module.
[0298] S750. The daemon process module converts the northbound OVSDB message body into a daemon OVSDB message body.
[0299] After receiving the northbound OVSDB message body sent by the above northbound call module, the above daemon process module parses the OVSDB message body to obtain the target filtering rule and the identifier of the first logical device.
[0300] The implementation method of the above S750 includes: the daemon process module updates the identifier of the first logical device based on a preset rule to obtain the target identifier of the first logical device; then, the daemon process module encapsulates the target identifier of the first logical device and the target filtering rule into an OVSDB message body to obtain the daemon OVSDB message body.
[0301] The above preset rules include: concatenating the target string, the first x bits of the identifier of the logical device, the first n bits of the identifier of the target ACL rule, and the preset string to obtain the target identifier, where both x and n are positive integers. Among them, the above target strings corresponding to different types of logical devices are different. For example, the target string corresponding to a logical router is "lr", the target string corresponding to a logical switch is "ls", and the target string corresponding to the logical port of a virtual machine is "lsp".
[0302] Exemplarily, assume that the target string corresponding to a logical switch is "lr"; the target string corresponding to a logical switch is "ls"; the target string corresponding to the logical port of a virtual machine is "lsp"; the identifier of the first logical device is xxxx1; the identifier of the target ACL rule is yyyy1; the preset string is "acl". Assume further that the values of x and n are both 3; then, when the first logical device is a logical switch, the generated first type of identifier is "ls_xx1_yy1_acl".
[0303] S760. The daemon process module sends a daemon OVSDB message body to the southbound call module.
[0304] The implementation manner of the above S760 includes: the daemon process module sends the above daemon OVSDB message body to the southbound call module through the communication link with the Figure 2 southbound call module therein.
[0305] S770. The southbound call module updates the target filtering rule to the first logical flow table in the southbound database.
[0306] It should be noted that the implementation manner of the above S770 is the same as that of S620. For the specific description of S770, reference can be made to the relevant description of S620 above, which will not be elaborated here.
[0307] Before updating the first logical flow table in the southbound database in the embodiments of the present application, the target filtering rule corresponding to the target filtering level configured by the user obtained is updated to the filtering rule corresponding to the target filtering level in the northbound database, so that the filtering rule corresponding to the target filtering level in the northbound database includes the target filtering rule; then, subsequently, during the process of updating the first logical flow table in the southbound database, even if the target filtering rule is lost, it can be retrieved from the northbound database again, thereby improving the stability of updating the southbound database.
[0308] When there are multiple northbound flow tables in the northbound database and the northbound flow tables corresponding to different filtering levels are different, in combination with Figure 13 such as Figure 14 shown, the implementation manner of the above S730 includes: S730A - S730B.
[0309] S730A. The northbound call module determines the target northbound flow table corresponding to the first logical device based on the identifier of the first logical device corresponding to the target filtering level from multiple northbound flow tables.
[0310] It should be understood that since the logical device corresponding to the target filtering level is the above-mentioned first logical device, the target northbound flow table corresponding to the first logical device is the northbound flow table corresponding to the target filtering level.
[0311] In one implementation, the multiple northbound flow tables in the above-mentioned northbound database are respectively the northbound flow tables corresponding to different types of logical devices; that is to say, each of the above-mentioned logical devices respectively corresponds to a northbound flow table in the northbound database.
[0312] Based on this, the implementation of the above S730A includes: the northbound call module determines the target northbound flow table corresponding to the first logical device from multiple northbound flow tables; its specific implementation is similar to the implementation of the above S620A and will not be elaborated here.
[0313] In another implementation, the northbound flow tables corresponding to each type of logical device in the above-mentioned northbound database include: the northbound flow table in the inflow direction and the northbound flow table in the outflow direction. Among them, the filtering rules in the northbound flow table in the inflow direction are the rules for filtering packets with the flow direction of the inflow direction; the filtering rules in the northbound flow table in the outflow direction are the rules for filtering packets with the flow direction of the outflow direction.
[0314] Based on this, the implementation of the above S730A includes: calling the northbound call module to determine the northbound flow table corresponding to the first logical device from multiple northbound flow tables in the northbound database; and determining the target northbound flow table corresponding to the flow direction of the packet to be processed indicated by the target filtering rule from the northbound flow table corresponding to the first logical device; its specific implementation is similar to that of the above S620a - S620b and will not be elaborated here.
[0315] S730B. The northbound call module updates the target filtering rule to the target northbound flow table.
[0316] The implementation of the above S730B is similar to the implementation of S620B. For the specific description of S730B, reference can be made to the relevant description of S620B above and will not be elaborated here.
[0317] The above mainly introduces the solution provided by the embodiments of the present application from the perspective of methods. To implement the above functions, it includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving the hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0318] The embodiments of the present application can divide the function modules of the traffic control device for the virtual network according to the above method examples. For example, each function module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software function modules. It should be noted that the division of modules in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation.
[0319] In the case of dividing each function module corresponding to each function, Figure 15 FIG. shows a possible structural schematic diagram of the traffic control device 100 for the virtual network involved in the above embodiments; the device 100 is deployed in the data plane node in the virtual network. As Figure 15 shown, the traffic control device 100 for the virtual network includes: a virtual switch 1510.
[0320] The virtual switch 1510 is used to receive the target packet; for example, execute step S110 in the above method embodiment.
[0321] The virtual switch 1510 is used to perform packet filtering on the target packet according to at least two rule flow tables; for example, execute step S120 in the above method embodiment.
[0322] The virtual switch 1510 is used to send the filtered target packet; for example, execute step S130 in the above method embodiment.
[0323] Optionally, when the flow direction of the target packet is the incoming direction, the virtual switch 1510 is used to perform packet filtering on the target packet according to the rule flow tables corresponding to each filtering level in the first preset order.
[0324] When the flow direction of the target packet is the outgoing direction, the virtual switch 1510 is used to perform packet filtering on the target packet according to the rule flow tables corresponding to each filtering level in the second preset order.
[0325] Optionally, the order of the first preset order is opposite to that of the second preset order.
[0326] Optionally, the rule flow tables corresponding to the above filtering levels include: the rule flow table corresponding to the first filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the third filtering level; different filtering levels correspond to different types of logical devices, where the type of the logical device corresponding to the first filtering level is a logical router, the type of the logical device corresponding to the second filtering level is a logical switch, and the type of the logical device corresponding to the third filtering level is the logical port of a virtual machine.
[0327] Optionally, the virtual switch 1510 is used to perform packet filtering on the target packet based on the rule flow table corresponding to the first filtering level; for example, execute step S210 in the above method embodiment.
[0328] When the result of performing packet filtering on the target packet based on the rule flow table corresponding to the first filtering level by the virtual switch 1510 is an egress packet, the virtual switch 1510 is used to perform packet filtering on the target packet based on the rule flow table corresponding to the second filtering level; for example, execute step S230 in the above method embodiment.
[0329] When the result of performing packet filtering on the target packet based on the rule flow table corresponding to the second filtering level by the virtual switch 1510 is an egress packet, the virtual switch 1510 is used to perform packet filtering on the target packet based on the rule flow table corresponding to the third filtering level; for example, execute step S250 in the above method embodiment.
[0330] Optionally, the virtual switch 1510 is used to create a first new packet of the type of logical router based on the target packet.
[0331] The virtual switch 1510 is used to perform packet filtering on the target packet in the first new packet based on the rule flow table corresponding to the first filtering level.
[0332] Optionally, the virtual switch 1510 is used to use the rule flow tables in the ingress direction in the rule flow tables corresponding to each filtering level in the first preset order to perform packet filtering on the target packet; for example, execute step S310 in the above method embodiment.
[0333] Optionally, the virtual switch 1510 is used to obtain the network configuration information of the target packet.
[0334] The virtual switch 1510 is used to perform packet filtering on the target packet according to the matching situation between the network configuration information and the filtering rules in at least two rule flow tables.
[0335] Optionally, the traffic control device 100 of the virtual network further includes: an OVN controller 1520.
[0336] The OVN controller 1520 is used to update the first rule flow table corresponding to the target filtering level when the first logical flow table in the southbound database changes, so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table; for example, execute step S410 in the above method embodiment.
[0337] Optionally, the OVN controller 1520 is used to obtain the first logical flow table; for example, execute step S510 in the above method embodiment.
[0338] The OVN controller 1520 is used to determine the target filtering level and the target filtering rules newly added in the first logical flow table according to the first logical flow table; for example, execute step S520 in the above method embodiment.
[0339] The OVN controller 1520 is used to determine the first rule flow table according to the identifier of the first logical flow table; for example, execute step S530 in the above method embodiment.
[0340] The OVN controller 1520 is used to update the filtering rules of the first rule flow table according to the target filtering level and the target filtering rules; for example, execute step S540 in the above method embodiment.
[0341] Optionally, the OVN controller 1520 is used to determine the rule flow table corresponding to the identifier of the first logical flow table from at least two rule flow tables; for example, execute step S531 in the above method embodiment.
[0342] The OVN controller 1520 is used to determine the first rule flow table corresponding to the flow direction of the packet to be processed from the rule flow table corresponding to the identifier of the first logical flow table; for example, execute step S532 in the above method embodiment.
[0343] Each module of the above traffic control device 100 of the virtual network can also be used to execute other actions in the above method embodiment, and all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding function module, which will not be elaborated here.
[0344] In the case of dividing each function into corresponding function modules, Figure 16 A possible structural schematic diagram of the traffic control device 200 of the virtual network involved in the above embodiment is shown; the device 200 is deployed in the control plane node of the virtual network card. As Figure 16 shown, the traffic control device 200 of the virtual network includes: a user interface module 1610 and a southbound call module 1620.
[0345] The user interface module 1610 is used to obtain a configuration request; for example, to execute step S610 in the above method embodiments.
[0346] The southbound call module 1620 is used to update the first logical flow table according to the target filtering rule and the target filtering level; for example, to execute step S620 in the above method embodiments.
[0347] Optionally, the southbound call module 1620 is used to determine the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level from multiple logical flow tables in the southbound database; for example, to execute step S620A in the above method embodiments.
[0348] The southbound call module 1620 is used to update the target filtering rule to the first logical flow table; for example, to execute step S620B in the above method embodiments.
[0349] Optionally, the southbound call module 1620 is used to determine the logical flow table corresponding to the first logical device based on the type identifier of the first logical device corresponding to the target filtering level from multiple logical flow tables; for example, to execute step S620a in the above method embodiments.
[0350] The southbound call module 1620 is used to determine the first logical flow table corresponding to the flow direction of the message to be processed from the logical flow table corresponding to the first logical device; for example, to execute step S620b in the above method embodiments.
[0351] The southbound call module 1620 is used to update the target filtering rule to the first logical flow table; for example, to execute step S620c in the above method embodiments.
[0352] Optionally, the above traffic control device 200 of the virtual network further includes: a northbound call module 1630.
[0353] The northbound call module 1630 is used to update the target filtering rule to the northbound database; for example, to execute step S730 in the above method embodiments.
[0354] Each module of the above traffic control device 200 of the virtual network can also be used to execute other actions in the above method embodiments. All relevant contents of each step involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.
[0355] An embodiment of the present application provides a computing device, which includes a memory and a processor, and the memory is coupled to the processor; the memory is used to store computer program code, and the computer program code includes computer instructions; when the computer instructions are executed by the processor, it is to receive a target packet through a virtual switch; filter the target packet through the virtual switch according to at least two rule flow tables; at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables are used to indicate filtering rules at different filtering levels; send the filtered target packet through the virtual switch.
[0356] An embodiment of the present application provides a computing device, which includes a memory and a processor, and the memory is coupled to the processor; the memory is used to store computer program code, and the computer program code includes computer instructions; when the computer instructions are executed by the processor, it is to obtain a configuration request; wherein, the configuration request includes: a target filtering rule corresponding to a target filtering level configured by a user; update the filtering rule in the first logical flow table according to the target filtering rule and the target filtering level.
[0357] An embodiment of the present application further provides a computer-readable storage medium, on which computer instructions are stored. When the computer instructions run on a computing device, the computing device is enabled to execute any one of the methods executed by the above data plane node and / or control plane node.
[0358] For the explanations and beneficial effects descriptions of the relevant content in any one of the above computer-readable storage media, reference can be made to the corresponding embodiments above, and details are not described herein again.
[0359] An embodiment of the present application provides a computer program product, which when running on a computer enables the computer to execute any one of the methods executed by the above data plane node and / or control plane node.
[0360] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the processes or functions in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media integrated. The available medium can be a magnetic medium (such as a floppy disk, magnetic disk, magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid state drive (SSD)), etc.
[0361] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.
[0362] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, indirect couplings or communication connections of devices or units, and can be in electrical, mechanical, or other forms.
[0363] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0364] In addition, each functional unit in various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0365] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: flash memory, mobile hard disk, read-only memory, random access memory, magnetic disk, or optical disk and other various media that can store program codes.
[0366] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A traffic control method for a virtual network, characterized in that Applied to a virtual network, the virtual network including a virtual switch, the method comprising: Receiving, by the virtual switch, a target packet; Filtering, by the virtual switch, the target packet according to at least two rule flow tables; at least two rule flow tables are stored on a computing device where the virtual switch is located, and different rule flow tables are used to indicate filtering rules for different filtering levels; Sending, by the virtual switch, the filtered target packet.
2. The method according to claim 1, characterized in that, The filtering, by the virtual switch, of the target packet according to at least two rule flow tables includes: When the flow direction of the target packet is the incoming direction, filtering, by the virtual switch, the target packet using the rule flow tables corresponding to each filtering level in a first preset order; When the flow direction of the target packet is the outgoing direction, filtering, by the virtual switch, the target packet using the rule flow tables corresponding to each filtering level in a second preset order.
3. The method according to claim 2, wherein The first preset order is opposite to the second preset order.
4. The method according to any one of claims 2-3, characterized in that, The rule flow tables corresponding to each filtering level include: the rule flow table corresponding to the first filtering level, the rule flow table corresponding to the second filtering level, and the rule flow table corresponding to the third filtering level; different filtering levels correspond to different types of logical devices, wherein the type of the logical device corresponding to the first filtering level is a logical router, the type of the logical device corresponding to the second filtering level is a logical switch, and the type of the logical device corresponding to the third filtering level is a logical port of a virtual machine.
5. The method according to claim 4, characterized in that, The filtering, by the virtual switch, of the target packet using the rule flow tables corresponding to each filtering level in a first preset order when the flow direction of the target packet is the incoming direction includes: Filtering, by the virtual switch, the target packet based on the rule flow table corresponding to the first filtering level; When the result of filtering the target packet based on the rule flow table corresponding to the first filtering level is a forwarded packet, filtering, by the virtual switch, the target packet based on the rule flow table corresponding to the second filtering level; wherein, the result of packet filtering includes: discarding the packet or forwarding the packet; When the result of filtering the target packet based on the rule flow table corresponding to the second filtering level is a forwarded packet, filtering, by the virtual switch, the target packet based on the rule flow table corresponding to the third filtering level.
6. The method according to claim 5, wherein The filtering, by the virtual switch, of the target packet based on the rule flow table corresponding to the first filtering level includes: Creating, by the virtual switch, a first new packet of the type of the logical router based on the target packet; the first new packet includes: the target packet; Filtering, by the virtual switch, the target packet in the first new packet based on the rule flow table corresponding to the first filtering level.
7. The method according to any one of claims 2-4, characterized in that, The rule flow tables corresponding to each filtering level include the rule flow table in the incoming direction and the rule flow table in the outgoing direction; wherein, the rule flow table in the incoming direction is used to filter packets with the flow direction being the incoming direction; the rule flow table in the outgoing direction is used to filter packets with the flow direction being the outgoing direction; When the flow direction of the target packet is the incoming direction through the virtual switch, filtering the target packet using the rule flow tables corresponding to each filtering level in a first preset order includes: When the flow direction of the target packet is the incoming direction through the virtual switch, filtering the target packet using the rule flow table in the incoming direction in the rule flow tables corresponding to each filtering level in a first preset order.
8. The method according to any one of claims 1 to 7, characterized in that, Before filtering the target packet according to at least two rule flow tables through the virtual switch, the method further includes: Obtaining the network configuration information of the target packet through the virtual switch; the network configuration information includes the source address of the target packet and / or the destination address of the target packet; Filtering the target packet according to at least two rule flow tables through the virtual switch includes: Filtering the target packet according to the matching situation between the network configuration information and the filtering rules in the at least two rule flow tables through the virtual switch.
9. The method according to any one of claims 1 to 8, characterized in that, The virtual network further includes: a southbound database, the southbound database includes a plurality of logical flow tables, the plurality of logical flow tables are used to indicate the filtering rules of the different filtering levels configured by the user, and the method further includes: When the first logical flow table in the southbound database changes, updating the first rule flow table corresponding to the target filtering level so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table, and the target filtering level is the filtering level corresponding to the first logical flow table; wherein, the different filtering levels include the target filtering level.
10. The method according to claim 9, characterized in that, Updating the first rule flow table corresponding to the target filtering level includes: Obtaining the first logical flow table; Determining the target filtering level and the target filtering rules newly added in the first logical flow table according to the first logical flow table; Determining the first rule flow table according to the identifier of the first logical flow table; Updating the filtering rules of the first rule flow table according to the target filtering level and the target filtering rules.
11. The method according to claim 10, wherein The target filtering rules indicate the flow direction of the packet to be processed, and the flow direction includes the incoming direction or the outgoing direction; the rule flow tables on the computing device where the virtual switch is located include the rule flow table in the incoming direction and the rule flow table in the outgoing direction; Determining the first rule flow table according to the identifier of the first logical flow table includes: Determining the rule flow table corresponding to the identifier of the first logical flow table from the at least two rule flow tables; Determining the first rule flow table corresponding to the flow direction of the packet to be processed from the rule flow table corresponding to the identifier of the first logical flow table.
12. The method according to any one of claims 9-11, characterized in that, Before updating the first rule flow table corresponding to the target filtering level when the first logical flow table in the southbound database changes, the method further includes: Obtaining a configuration request; wherein, the configuration request includes: the target filtering rule corresponding to the target filtering level configured by the user; Updating the filtering rule in the first logical flow table according to the target filtering rule and the target filtering level.
13. The method according to claim 12, characterized in that, The updating the filtering rule in the first logical flow table according to the target filtering rule and the target filtering level includes: Determining, from multiple logical flow tables included in the southbound database, the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level; Updating the target filtering rule to the first logical flow table.
14. The method according to claim 13, wherein The target filtering rule indicates the flow direction of the packet to be processed, and the flow direction includes an incoming direction or an outgoing direction; the logical flow table corresponding to each logical device includes a logical flow table in the incoming direction and a logical flow table in the outgoing direction; wherein, the logical flow table in the incoming direction is used to filter packets with a flow direction of the incoming direction; the logical flow table in the outgoing direction is used to filter packets with a flow direction of the outgoing direction; The determining, from multiple logical flow tables included in the southbound database, the first logical flow table corresponding to the type identifier of the first logical device corresponding to the target filtering level includes: Based on the type identifier of the first logical device corresponding to the target filtering level, determining the logical flow table corresponding to the first logical device from the multiple logical flow tables; Determining, from the logical flow table corresponding to the first logical device, the first logical flow table corresponding to the flow direction of the packet to be processed.
15. The method according to any one of claims 12 - 14, characterized in that The virtual network further includes: a northbound database; before updating the filtering rule in the first logical flow table according to the target filtering rule and the target filtering level, the method further includes: Updating the target filtering rule to the filtering rule corresponding to the target filtering level in the northbound database.
16. A traffic control device for a virtual network, characterized in that Applied to a virtual network, the traffic control device of the virtual network includes: a virtual switch; The virtual switch is used to receive a target packet; The virtual switch is used to filter the target packet according to at least two rule flow tables; at least two rule flow tables are stored on the computing device where the virtual switch is located, and different rule flow tables are used to indicate filtering rules for different filtering levels; The virtual switch is used to send the filtered target packet.
17. The device according to claim 16, characterized in that, The virtual network further includes: a southbound database, the southbound database includes multiple logical flow tables, the multiple logical flow tables are used to indicate the filtering rules for different filtering levels configured by the user, and the traffic control device of the virtual network includes: an Open Virtual Network (OVN) controller; The OVN controller is used to update the first rule flow table corresponding to the target filtering level in the southbound database when the first logical flow table in the southbound database changes, so that the filtering rules included in the first rule flow table are the same as the filtering rules in the first logical flow table, and the target filtering level is the filtering level corresponding to the first logical flow table; wherein, the different filtering levels include the target filtering level.
18. A traffic control device for a virtual network, characterized in that, Applied to a virtual network, the traffic control device of the virtual network includes: a user interface module and a southbound call module; The user interface module is used to obtain a configuration request; wherein, the configuration request includes: the target filtering rules corresponding to the target filtering level configured by the user; The southbound call module is used to update the filtering rules in the first logical flow table according to the target filtering rules and the target filtering level; the first logical flow table is the logical flow table corresponding to the target filtering level in the southbound database.
19. A computing device, characterized in that, It includes a memory and a processor, and the memory is coupled to the processor; the memory is used to store computer program code, and the computer program code includes computer instructions; when the computer instructions are executed by the processor, the processor is caused to execute the method according to any one of claims 1 to 11, and / or 12 - 15.