Traffic forwarding method and device, equipment and storage medium
By using switches as enhanced gateways in the cloud platform system and combining virtual forwarding routing tables for traffic forwarding, the bandwidth bottleneck and physical network card isolation problems between virtual machines and bare metal service machines are solved, efficient and stable layer 2 and 3 traffic communication is achieved, and deployment complexity and hardware costs are reduced.
Patent Information
- Application Number
- CN202510514431.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-07-25
AI Technical Summary
The existing traffic forwarding solutions have bandwidth bottlenecks in cloud platform systems, difficulty in achieving physical network card isolation, complex deployment and high-cost hardware dependence, especially in layer 2 and 3 traffic communication between virtual machines and bare metal servers.
The switch is used as an enhanced gateway to parse the source and destination addresses of the access traffic, combine it with the virtual forwarding routing table to determine the flow direction, and encapsulate or decapsulate it to achieve efficient forwarding of traffic.
It solves the bandwidth bottleneck problem, realizes efficient and stable layer 2 and 3 traffic communication between virtual machines and bare metal service machines, meets the needs of physical network card isolation, and reduces deployment costs and complexity.
Smart Images

Figure CN120378359A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of traffic forwarding, and in particular to a traffic forwarding method, apparatus, device, and storage medium. Background Art
[0002] With the rapid development of cloud computing, bare metal servers have become increasingly widely used in scenarios such as cloud platform systems due to their advantages of combining the elasticity of virtual machines and the performance of physical machines. Bare metal services provide users with flexible hardware and network configurations, supporting on-demand application and elastic expansion. However, in the existing bare metal network architecture, especially in the overlay network, the traffic between virtual machines and bare metal servers is encapsulated and decapsulated through tunnel interfaces to cross the limitations of the physical network, bringing higher network flexibility, but also making the two- and three-layer traffic communication between virtual machines and bare metal servers more complex, posing higher requirements for traffic forwarding solutions.
[0003] In the existing traffic forwarding solutions, on the one hand, traffic forwarding is achieved through a centralized gateway, and traffic is forwarded through a single gateway node, but it is prone to bandwidth bottlenecks and physical network card isolation cannot be achieved; on the other hand, traffic forwarding is achieved through a distributed gateway. Although the traffic load can be shared through intelligent network cards, its high cost and technical complexity make it difficult to deploy widely. To overcome these limitations, the enhanced gateway solution forwards traffic through a switch, avoiding bandwidth bottlenecks and reducing hardware costs, meeting bandwidth, performance, and physical network card isolation while avoiding high-cost hardware dependencies. Summary of the Invention
[0004] This application provides a traffic forwarding method, apparatus, device, and storage medium that can use a switch as an enhanced gateway for traffic forwarding, thereby realizing efficient and stable two- and three-layer traffic communication between virtual machines and bare metal servers, to at least solve the problems of bandwidth forwarding bottlenecks, difficulty in achieving physical network card isolation, complex deployment, and high-cost hardware dependencies in related technologies.
[0005] This application provides a traffic forwarding method, which is applied to a cloud platform system. In the cloud platform system, a bare metal server, a computing node, and a switch are deployed. A virtual machine and a node bridge are deployed on the computing node. The method is characterized in that it includes:
[0006] In response to the access traffic received by the port of the switch, parse the access traffic to obtain the access source address and the access destination address;
[0007] Obtain the virtual forwarding routing table corresponding to the port, and combine the access source address and the access destination address to determine the flow direction of the access traffic;
[0008] In response to the access traffic flowing from the virtual machine to the bare metal server, it is determined that the access traffic has been encapsulated by the tunnel interface deployed on the node bridge, and the access traffic is decapsulated through the tunnel sub-interface corresponding to the tunnel interface deployed on the switch and then forwarded to the bare metal server;
[0009] In response to the access traffic flowing from the bare metal server to the virtual machine, it is determined that the access traffic has not been encapsulated, and the access traffic is encapsulated through the tunnel sub-interface and then forwarded to the computing node.
[0010] This application also provides a traffic forwarding device, which is applied to a cloud platform system. In the cloud platform system, a bare metal server, a computing node, and a switch are deployed. On the computing node, a virtual machine and a node bridge are deployed, including:
[0011] A traffic parsing module, which is used to respond to the access traffic received by the port of the switch, parse the access traffic, and obtain the access source address and the access destination address;
[0012] A flow direction judgment module, which is used to obtain the virtual forwarding routing table corresponding to the port, and combine the access source address and the access destination address to judge the flow direction of the access traffic;
[0013] A decapsulation forwarding module, which is used to respond to the access traffic flowing from the virtual machine to the bare metal server, determine that the access traffic has been encapsulated by the tunnel interface deployed on the node bridge, and decapsulate the access traffic through the tunnel sub-interface corresponding to the tunnel interface deployed on the switch and then forward it to the bare metal server;
[0014] An encapsulation forwarding module, which is used to respond to the access traffic flowing from the bare metal server to the virtual machine, determine that the access traffic has not been encapsulated, and encapsulate the access traffic through the tunnel sub-interface and then forward it to the computing node.
[0015] This application also provides an electronic device, including: a memory, which is used to store a computer program; a processor, which is used to implement the steps of any of the above traffic forwarding methods when executing the computer program.
[0016] This application also provides a computer-readable storage medium, in which a computer program is stored. Wherein, when the computer program is executed by a processor, the steps of any of the above traffic forwarding methods are implemented.
[0017] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of any of the above traffic forwarding methods are implemented.
[0018] Through this application, on the one hand, since a switch is used as an enhanced gateway to implement traffic forwarding, it avoids the limitation that all traffic passes through a single gateway node, enabling the simultaneous processing of a large number of concurrent traffic, flexible allocation of bandwidth resources, significantly improving the traffic forwarding efficiency, thus effectively solving the bandwidth bottleneck problem and meeting the application scenarios of large-scale cloud platforms and high-bandwidth requirements; on the other hand, due to the introduction of the combination of the switch and the virtual forwarding routing table, the traffic can be accurately encapsulated and decapsulated according to requirements, enabling the traffic between different virtual machines and bare-metal servers to be logically isolated, and at the same time, managed and routed through the switch in the physical network, ensuring that the physical network cards of each computing node can safely isolate different network traffic, guaranteeing high security and avoiding chaos and conflicts during traffic forwarding, meeting the requirements of physical network card isolation; in addition, since the switch is used to replace the smart network card to handle traffic forwarding, not only is the deployment cost low and easy to manage, avoiding the high hardware cost and complex configuration requirements of the smart network card, but also ports and bandwidth can be flexibly added according to needs, simplifying the system deployment and maintenance. Therefore, it can solve the problems of bandwidth forwarding bottleneck, difficulty in achieving physical network card isolation, complex deployment, and high-cost hardware dependence in the related technologies, achieving the technical effect of efficient and stable two- and three-layer traffic communication between virtual machines and bare-metal servers. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0020] Figure 1 FIG. is a schematic diagram of an application environment provided by an embodiment of the present application;
[0021] Figure 2 FIG. is a flowchart of a traffic forwarding method provided by an embodiment of the present application;
[0022] Figure 3 FIG. is a schematic diagram of a route reflection service provided by an embodiment of the present application;
[0023] Figure 4 FIG. is a schematic diagram of the internal structure of a computing node provided by an embodiment of the present application;
[0024] Figure 5 FIG. is a block diagram of the structure of a traffic forwarding device provided by an embodiment of the present application;
[0025] Figure 6 FIG. is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without making creative efforts belong to the protection scope of the present application.
[0027] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0028] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0029] A service verification method provided by the present application can be applied to, for example Figure 1The cloud platform system shown, in which a bare metal server 103, computing nodes 102, and a switch 101 are deployed in the cloud platform system. Virtual machines and node bridges are deployed on the computing nodes. The bare metal server 103 and the computing nodes 102 are respectively connected to the ports on the switch 101 through physical data transmission cables. After the switch 101 receives access traffic through the ports, it will judge the flow direction of the access traffic according to the access traffic, and thus forward the access traffic sent by the bare metal server 103 to the virtual machine after encapsulation on the switch 101 to the computing node 102, and forward the access traffic sent by the virtual machine to the bare metal server 103 after decapsulation on the switch 101 to the bare metal server. Among them, the switch 101 can be an enhanced layer 2 or layer 3 switch, supporting dynamic generation of a virtual forwarding routing table and intelligently forwarding traffic according to the source address and destination address of the access traffic, and can perform flexible traffic management through virtualized network interfaces and tunnel interfaces; the computing node 102 can be a physical server or a server cluster built by multiple physical servers, running a virtualization management program, on which multiple virtual machines are deployed. The virtual machines can communicate with the bare metal server through a virtual network; the node bridge deployed on the computing node 102 is responsible for forwarding traffic from the virtual machine to the switch, or from the switch to the virtual machine or the bare metal server, and can be a software-implemented virtual network bridging layer for managing the network connection between the virtual machine and the physical device; the bare metal server 103 is a physical server with dedicated hardware resources, directly providing computing, storage, and network resources, and supporting direct control of the physical hardware.
[0030] As Figure 2 shown, an embodiment of the present application provides a traffic forwarding method, which is applied to Figure 1 the application environment shown. Taking the switch 101 as an example, the method includes:
[0031] Step 201, in response to the switch port receiving access traffic, parse the access traffic to obtain the access source address and the access destination address.
[0032] Step 202, obtain the virtual forwarding routing table corresponding to the port, and combine the access source address and the access destination address to judge the flow direction of the access traffic.
[0033] Step 203, in response to the flow direction of the access traffic being from the virtual machine to the bare metal server for access, determine that the access traffic has been encapsulated by the tunnel interface deployed on the node bridge, and forward the access traffic after decapsulation through the tunnel sub-interface corresponding to the tunnel interface deployed on the switch to the bare metal server.
[0034] Step 204: In response to the access traffic flowing from the bare metal server to the virtual machine, it is determined that the access traffic is not encapsulated. After encapsulating the access traffic through the tunnel sub-interface, it is forwarded to the computing node.
[0035] Among them, tunneling is a technology that encapsulates packets of one protocol within packets of another protocol, enabling data to traverse different networks, especially between physical networks and virtual networks; a tunnel interface is a logical interface that can be deployed on a switch or router, or on a node bridge, and is used to process the data stream of tunnel transmission, responsible for encapsulating and decapsulating tunnel data; a tunnel sub-interface is a branch or division of the tunnel interface. Multiple virtual sub-interfaces can be configured on a tunnel interface, and each sub-interface can have independent configurations, such as virtual local area network segments (VLANs), network (IP) addresses, etc., to handle different network traffic or different types of virtual networks.
[0036] A traffic forwarding method provided by the present invention realizes traffic forwarding by using a switch as an enhanced gateway, avoiding the limitation that all traffic converges through a single gateway node, enabling the simultaneous processing of a large number of concurrent traffic, flexibly allocating bandwidth resources, significantly improving the traffic forwarding efficiency, thus effectively solving the bandwidth bottleneck problem and meeting the application scenarios of large-scale cloud platforms and high-bandwidth requirements; moreover, by introducing the combination of a switch and a virtual forwarding routing table, traffic can be accurately encapsulated and decapsulated according to requirements, enabling logical isolation of traffic between different virtual machines and bare metal servers, and at the same time, being managed and routed through the switch on the physical network to ensure that the physical network cards of each computing node can safely isolate different network traffic, ensuring high security and avoiding chaos and conflicts in traffic during the forwarding process, meeting the requirements of physical network card isolation; in addition, by using a switch to replace the smart network card to handle traffic forwarding, not only is the deployment cost low and easy to manage, avoiding the high hardware cost and complex configuration requirements of the smart network card, but also ports and bandwidth can be flexibly added according to needs, simplifying the system deployment and maintenance; generally, it can dynamically encapsulate and decapsulate traffic according to the direction of access traffic, optimize network performance and reduce unnecessary traffic latency, and achieve effective communication between virtual machines and bare metal servers, realizing efficient and stable two- and three-layer traffic communication between virtual machines and bare metal servers.
[0037] In one embodiment, as Figure 3 shown, a route reflector is also deployed in the cloud platform system. Before the switch obtains the virtual forwarding routing table of the port, it further includes:
[0038] In response to the computing node and the switch initiating the route reflection service, obtain the route reflector in the same network segment as the computing node, and the route reflector receives the binding information of the address of the tunnel interface and the address of the virtual machine;
[0039] The route reflector groups the received binding information based on the virtual forwarding route, generates a number of route information and distributes it to the computing node and the switch;
[0040] The computing node and the switch generate a virtual forwarding routing table according to the received number of route information;
[0041] The switch associates the virtual forwarding routing table with the virtual LAN segment where the computing node is located and the virtual LAN segment where the bare metal server is located.
[0042] Among them, the route reflection service is a routing distribution mechanism commonly used in the Border Gateway Protocol (BGP) environment. In a BGP network, there are usually multiple routers (called BGP peers), and these routers exchange routing information through the BGP protocol. Each BGP router maintains a routing table and exchanges routing information with other directly connected BGP routers; the route reflector is one or more routers designated as "route reflector" in the route reflection service, responsible for receiving routing information from other BGP routers and reflecting (i.e., rebroadcasting) it to other routers, and is a centralized BGP node.
[0043] Specifically, in this embodiment, by introducing a route reflector, the distribution of the binding information of the tunnel interface and the virtual machine address is realized, so that the switch and the computing node can accurately obtain the virtual forwarding routing table, providing a distributed routing information management method, which helps to reduce network congestion and improve network scalability, optimizes the routing information synchronization between the virtual machine and the bare metal server, and further improves the processing efficiency and stability of network traffic.
[0044] In one embodiment, according to the access source address and the access destination address, combined with the virtual forwarding routing table, judge the flow direction of the access traffic, including:
[0045] Query the virtual forwarding routing table to obtain the tunnel interface address and the address of the virtual machine;
[0046] In response to the access source address being the address of the bare metal server and the access destination address being the address of the virtual machine, it is determined that the flow direction of the access traffic is from the bare metal server to the virtual machine for access;
[0047] Obtain the address of the tunnel sub-interface. In response to the access source address being the tunnel interface address and the access destination address being the address of the tunnel sub-interface, it is determined that the access traffic is generated by the virtual machine and the access traffic has been encapsulated by the tunnel interface;
[0048] If the access traffic is generated by a virtual machine, the access traffic is decapsulated through a tunnel sub-interface to obtain the original traffic;
[0049] Parse the original traffic to obtain the original source address and the original destination address;
[0050] If the original destination address is the address of the bare metal server, it is determined that the flow direction of the access traffic is from the virtual machine to the bare metal access.
[0051] Specifically, in this embodiment, by matching the access source address and the access destination address, combining with the virtual forwarding routing table, the flow direction of the traffic is judged, and the encapsulated traffic is decapsulated to ensure the correct transmission of the network traffic; moreover, through accurate address parsing and traffic encapsulation and decapsulation, the reliability and efficiency of the traffic transmission between the virtual machine and the bare metal server are ensured, and the errors that may occur during the traffic forwarding process are reduced; at the same time, by combining the switch with the virtual forwarding routing table, it can be ensured that the physical network cards of each computing node can safely isolate different network traffics, avoid the confusion of traffics between different virtual machines and the bare metal server, and meet the requirements of physical network card isolation.
[0052] In one embodiment, if the original destination address is the address of the bare metal server, it further includes:
[0053] The switch determines whether the corresponding port direct connection information is stored according to the address of the bare metal server;
[0054] If it is stored, the switch obtains the corresponding direct connection port and forwards the decapsulated original traffic to the bare metal server through the direct connection port;
[0055] If it is not stored, the switch broadcasts the decapsulated original traffic to the virtual LAN segment where the bare metal server is located;
[0056] If the switch receives the feedback information from the bare metal server, the port that receives the feedback information is recorded as the direct connection port of the bare metal server, and the corresponding port direct connection information is generated and stored.
[0057] Specifically, in this embodiment, after the switch performs decapsulation, it further determines whether there is a directly connected port by querying the stored port direct connection information, ensuring that data can be directly and accurately forwarded to the bare metal server. When the directly connected port is not recorded, the switch broadcasts the traffic to the virtual LAN segment where the bare metal server is located, reducing the latency and complexity of data transmission. At the same time, it also ensures the efficient routing of traffic, avoids unnecessary network topology complexity, and ensures the flexibility and scalability of the network. In addition, through reasonable traffic routing and switch management, the physical network card isolation is further strengthened to ensure that the traffic between different virtual machines and the bare metal server does not conflict or leak.
[0058] In one embodiment, a first switch and a second switch are deployed inside the cloud platform system. The computing node where the virtual machine is located is connected to the first switch, and the bare metal server is connected to the second switch. When the bare metal server accesses the virtual machine, it includes:
[0059] The bare metal server sends a communication request to the virtual machine, using the address of the virtual machine as the destination address and the address of the bare metal server as the source address, and generates a first request traffic to send to the second switch.
[0060] The second switch receives the first request traffic and parses it. According to the virtual forwarding routing table, it determines whether the request target is a virtual machine and whether the computing node where the target virtual machine is located is connected to the second switch. Among them, the second switch, the first switch, and the computing node obtain a consistent virtual forwarding routing table through the route reflection service.
[0061] If the second switch determines that the target is a virtual machine and the tunnel interface address corresponding to the target virtual machine address is bound to the first switch, the second switch encapsulates the first request traffic through the connected tunnel set between it and the first switch, using the connected tunnel interface address set on the first switch as the destination address and the connected tunnel sub-interface address set on the second switch as the source address, and generates a second request traffic.
[0062] The first switch receives the second request traffic sent by the second switch, decapsulates and parses the second request traffic through the connected tunnel interface, and obtains the destination address of the first request traffic.
[0063] The first switch queries the virtual forwarding routing table according to the destination address of the first request traffic, determines that the target virtual machine address is bound to the first switch, and obtains the tunnel interface address and tunnel sub-interface address corresponding to the destination virtual machine address.
[0064] The first switch encapsulates the first request traffic through the tunnel sub-interface, using the tunnel interface address as the destination address and the tunnel sub-interface address as the source address, and generates a third request traffic.
[0065] The first switch sends the third request traffic to the computing node where the virtual machine is located through the port connected to the computing node where the destination virtual machine is located.
[0066] Specifically, in this embodiment, communication is established through the connected tunnels between different switches, without relying on the direct connection of the physical network. This enables bare metal servers and virtual machines on different physical machines or switches to achieve seamless communication as long as they rely on correctly configured tunnel interfaces and routing information, reducing the dependence on the physical network topology. At the same time, different switches obtain a consistent virtual forwarding routing table through the route reflection service, enabling traffic to be forwarded to the target device efficiently and accurately, avoiding the complexity brought by traditional cross-switch routing, and improving the accuracy and timeliness of traffic forwarding. In addition, the nodes where the bare metal servers and virtual machines are located are connected to different switches, enhancing isolation and security while improving the scalability of the network topology, making it more suitable for cloud platforms and large-scale virtualization environments.
[0067] In one embodiment, as Figure 4 shown, a first bridge and a second bridge are also deployed in the computing node. The node bridge is respectively connected to the first bridge and the second bridge, and the first bridge and the second bridge are respectively connected to the virtual machine. The access traffic has been encapsulated by the tunnel interface deployed on the node bridge, including:
[0068] The virtual machine uses its own address as the original source address and the address of the bare metal server as the original destination address to generate the original traffic;
[0069] The virtual machine obtains the network segment where the bare metal server is located according to the virtual forwarding routing table and determines whether the access is cross-segment;
[0070] In response to the access not being cross-segment, the virtual machine encapsulates the first network identifier for the original traffic through the first tunnel set on the first bridge to generate the same-network traffic and sends it to the node bridge;
[0071] In response to the access being cross-segment, the virtual machine encapsulates the second network identifier for the original traffic through the second tunnel set on the second bridge to generate the cross-network traffic and sends it to the node bridge.
[0072] In response to the node bridge receiving the same-network traffic or cross-network traffic, the node bridge performs pre-encapsulation on both the same-network traffic and cross-network traffic through the tunnel interface, uses the address of the tunnel sub-interface as the access destination address, and uses the address of the tunnel interface as the access source address to generate the access traffic;
[0073] The node bridge sends the access traffic to the receiving port of the switch, and the receiving port, the computing node, and the tunnel sub-interface are all bound to the same virtual local area network.
[0074] Among them, the destination address and the source address can be physical addresses (MAC addresses) or network addresses (IP addresses). If they are physical addresses, it is determined whether the destination address and the source address are in the same virtual local area network segment (VLAN). If so, the virtual machine and the bare metal server perform access within the same network segment, and the access traffic is layer 2 traffic. Otherwise, the virtual machine and the bare metal server perform cross-network segment access, and the access traffic is layer 3 traffic. If they are network addresses, it is determined whether the access destination address and the access source address are in the same virtual local area network segment (VLAN) and whether they are in the same subnet. If both results are yes, the virtual machine and the bare metal server perform access within the same network segment, and the access traffic is layer 2 traffic. Otherwise, the virtual machine and the bare metal server perform cross-network segment access, and the access traffic is layer 3 traffic. Among them, if the traffic is layer 2 traffic, the switch directly forwards the traffic according to the physical address without involving layer 3 routing. If the traffic is layer 3 traffic, the switch needs to further perform layer 3 routing forwarding in combination with the network address.
[0075] Specifically, in this embodiment, by deploying a first bridge and a second bridge inside the computing node to process traffic within the same network segment and cross-network segment traffic respectively, and performing pre-encapsulation and de-encapsulation through the node bridge, it is ensured that the traffic from the virtual machine to the bare metal server can be reasonably encapsulated according to the network identifier, effectively improving the traffic transfer efficiency between the virtual machine and the bare metal server, and at the same time avoiding unnecessary traffic encapsulation and de-encapsulation, improving the accuracy and flexibility of traffic processing.
[0076] In one embodiment, encapsulating the access traffic through the tunnel sub-interface and forwarding it to the computing node includes:
[0077] Query the virtual forwarding routing table to obtain the address of the virtual machine corresponding to the access destination address, the binding information of the address of the virtual machine and the address of the tunnel interface, and the connection port of the tunnel interface;
[0078] Determine the corresponding tunnel interface and encapsulate the access traffic through the corresponding tunnel sub-interface according to the address of the tunnel interface, using the address of the tunnel interface as the destination address and the address of the tunnel sub-interface as the source address to generate the switch forwarding traffic;
[0079] Forward the switch forwarding traffic to the corresponding computing node through the connection port of the tunnel interface.
[0080] Specifically, in this embodiment, by precisely encapsulating the access traffic and forwarding the traffic through the corresponding tunnel interface, combined with the information in the virtual forwarding routing table, the traffic forwarding can be optimized according to specific requirements, being able to flexibly handle different types of network traffic and transmission requirements, reducing the complexity of routing and forwarding, improving the processing efficiency of network traffic, and ensuring that different types of network traffic are properly managed and forwarded.
[0081] In one embodiment, after encapsulating the access traffic through a tunnel sub-interface and forwarding it to the computing node, the following steps are further included:
[0082] Upon receiving the switch-forwarded traffic, the node bridge de-encapsulates the switch-forwarded traffic through the tunnel interface to obtain the access traffic;
[0083] The node bridge parses the access traffic to obtain a first network identifier or a second network identifier. The first network identifier is generated when the bare metal accesses the virtual machine within the same network segment, and the second network identifier is generated when the bare metal accesses the virtual machine across network segments;
[0084] Upon obtaining the first network identifier, the node bridge sends the access traffic to the first bridge for de-encapsulation through the first tunnel;
[0085] Upon obtaining the second network identifier, the node bridge sends the access traffic to the second bridge for de-encapsulation through the second tunnel;
[0086] The first bridge or the second bridge parses the de-encapsulated access traffic to obtain the access destination address and sends the access traffic to the corresponding virtual machine.
[0087] Specifically, in this embodiment, after the switch forwards the traffic, the node bridge de-encapsulates and parses the network identifier of the traffic, and finally sends the traffic to the corresponding virtual machine. The de-encapsulation process ensures the accurate transmission of network traffic, and through reasonable traffic parsing, the traffic at each network layer can be precisely managed and routed, effectively reducing the latency in cross-network access and improving the overall performance and stability of the network.
[0088] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0089] The embodiment of the present application further provides a traffic forwarding device, which is applied to a cloud platform system. In the cloud platform system, a bare metal server, a computing node, and a switch are deployed. On the computing node, a virtual machine and a node bridge are deployed. As Figure 5 shown, the device includes:
[0090] A traffic parsing module, configured to parse the access traffic upon receiving the access traffic at the port of the switch to obtain the access source address and the access destination address;
[0091] A flow direction judgment module, configured to obtain the virtual forwarding routing table corresponding to the port, and combine the access source address and the access destination address to judge the flow direction of the access traffic;
[0092] The decapsulation and forwarding module is used to determine that the access traffic has been encapsulated by the tunnel interface deployed on the node bridge when the flow direction of the access traffic is from the virtual machine to the bare metal server, and forward the access traffic to the bare metal server after decapsulating it through the tunnel sub-interface corresponding to the tunnel interface deployed on the switch;
[0093] The encapsulation and forwarding module is used to determine that the access traffic has not been encapsulated when the flow direction of the access traffic is from the bare metal server to the virtual machine, and forward the access traffic to the computing node after encapsulating it through the tunnel sub-interface.
[0094] The device is connected to a route reflector, which is used to obtain the route reflector in the same network segment as the computing node when the computing node and the switch initiate the route reflection service, and the route reflector receives the binding information of the address of the tunnel interface and the address of the virtual machine; the route reflector groups the received binding information based on the virtual forwarding route, generates several route information and distributes it to the computing node and the switch; the computing node and the switch generate a virtual forwarding routing table according to the received several route information; the switch associates the virtual forwarding routing table with the virtual LAN segment where the computing node is located and the virtual LAN segment where the bare metal server is located.
[0095] The flow direction judgment module is also used to query the virtual forwarding routing table to obtain the tunnel interface address and the address of the virtual machine; when the access source address is the address of the bare metal server and the access destination address is the address of the virtual machine, it is determined that the flow direction of the access traffic is from the bare metal server to the virtual machine; obtain the address of the tunnel sub-interface, and when the access source address is the tunnel interface address and the access destination address is the address of the tunnel sub-interface, it is determined that the access traffic is generated by the virtual machine and the access traffic has been encapsulated by the tunnel interface; when the access traffic is generated by the virtual machine, the access traffic is decapsulated through the tunnel sub-interface to obtain the original traffic; the original traffic is parsed to obtain the original source address and the original destination address; when the original destination address is the address of the bare metal server, it is determined that the flow direction of the access traffic is from the virtual machine to the bare metal access.
[0096] The decapsulation and forwarding module is also used for the switch to determine whether the corresponding port direct connection information has been stored according to the address of the bare metal server; if it has been stored, the switch obtains the corresponding direct connection port and forwards the decapsulated original traffic to the bare metal server through the direct connection port; if it has not been stored, the switch broadcasts the decapsulated original traffic to the virtual LAN segment where the bare metal server is located; when the switch receives the feedback information from the bare metal server, the port that receives the feedback information is recorded as the direct connection port of the bare metal server, and the corresponding port direct connection information is generated and stored.
[0097] The computing node to which the device is connected is also deployed with a first bridge and a second bridge. The node bridge is respectively connected to the first bridge and the second bridge. The first bridge and the second bridge are respectively connected to virtual machines. The device is also used to control the virtual machines to use their own addresses as the original source addresses and the addresses of the bare metal servers as the original destination addresses to generate original traffic. The virtual machines obtain the network segment where the bare metal servers are located according to the virtual forwarding routing table and determine whether the access is across network segments. In response to the access not being across network segments, the virtual machines encapsulate the first network identifier for the original traffic through the first tunnel set on the first bridge to generate same-network traffic and send it to the node bridge. In response to the access being across network segments, the virtual machines encapsulate the second network identifier for the original traffic through the second tunnel set on the second bridge to generate cross-network traffic and send it to the node bridge. In response to the node bridge receiving the same-network traffic or cross-network traffic, the node bridge pre-encapsulates both the same-network traffic and cross-network traffic through the tunnel interface, uses the address of the tunnel sub-interface as the access destination address, and uses the address of the tunnel interface as the access source address to generate access traffic. The node bridge sends the access traffic to the receiving port of the switch, and the receiving port, the computing node, and the tunnel sub-interface are all bound to the same virtual local area network.
[0098] The encapsulation and forwarding module is also used to query the virtual forwarding routing table to obtain the address of the virtual machine corresponding to the access destination address, the binding information of the address of the virtual machine and the address of the tunnel interface, and the connection port of the tunnel interface; determine the corresponding tunnel interface and encapsulate the access traffic through the corresponding tunnel sub-interface according to the address of the tunnel interface, use the address of the tunnel interface as the destination address, and use the address of the tunnel sub-interface as the source address to generate switch forwarding traffic; forward the switch forwarding traffic to the corresponding computing node through the connection port of the tunnel interface.
[0099] The device is also used to control the node bridge to, in response to the node bridge receiving the switch forwarding traffic, de-encapsulate the switch forwarding traffic through the tunnel interface to obtain the access traffic; the node bridge parses the access traffic to obtain the first network identifier or the second network identifier. The first network identifier is generated when the bare metal accesses the virtual machine in the same network segment, and the second network identifier is generated when the bare metal accesses the virtual machine across network segments. In response to obtaining the first network identifier, the node bridge sends the access traffic to the first bridge for de-encapsulation through the first tunnel. In response to obtaining the second network identifier, the node bridge sends the access traffic to the second bridge for de-encapsulation through the second tunnel. The first bridge or the second bridge parses the de-encapsulated access traffic to obtain the access destination address and sends the access traffic to the corresponding virtual machine.
[0100] For the description of the features in the corresponding embodiments of the traffic forwarding device, reference can be made to the relevant descriptions in the corresponding embodiments of the traffic forwarding method, which will not be elaborated here one by one.
[0101] An embodiment of the present application further provides an electronic device, such as Figure 6 shown, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above embodiments of the traffic forwarding method.
[0102] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any of the above embodiments of the traffic forwarding method when running.
[0103] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media that can store computer programs such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs.
[0104] An embodiment of the present application further provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the traffic forwarding method.
[0105] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the traffic forwarding method.
[0106] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0107] The traffic forwarding method, device, equipment, and storage medium provided by the present application have been introduced in detail above. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A traffic forwarding method is applied to a cloud platform system. In the cloud platform system, a bare metal server, computing nodes, and switches are deployed. Virtual machines and node bridges are deployed on the computing nodes. The method is characterized in that The method includes: In response to the access traffic received by the port of the switch, parsing the access traffic to obtain the access source address and the access destination address; Obtaining the virtual forwarding routing table corresponding to the port, and combining the access source address and the access destination address to determine the flow direction of the access traffic; In response to the flow direction of the access traffic being from the virtual machine to the bare metal server, determining that the access traffic has been encapsulated by the tunnel interface deployed on the node bridge, and de-encapsulating the access traffic through the tunnel sub-interface corresponding to the tunnel interface deployed on the switch and then forwarding it to the bare metal server; In response to the flow direction of the access traffic being from the bare metal server to the virtual machine, determining that the access traffic has not been encapsulated, and encapsulating the access traffic through the tunnel sub-interface and then forwarding it to the computing node.
2. The flow forwarding method according to claim 1, wherein A route reflector is also deployed in the cloud platform system. Before the switch obtains the virtual forwarding routing table of the port, it further includes: In response to the computing node and the switch initiating a route reflection service, obtaining the route reflector in the same network segment as the computing node, and the route reflector receives the binding information of the address of the tunnel interface and the address of the virtual machine; The route reflector groups the received binding information based on the virtual forwarding route, generates a number of route information and distributes it to the computing node and the switch; The computing node and the switch generate the virtual forwarding routing table according to the received a number of route information; The switch associates the virtual forwarding routing table with the virtual LAN segment where the computing node is located and the virtual LAN segment where the bare metal server is located.
3. A traffic forwarding method according to claim 2, wherein The determining the flow direction of the access traffic by combining the virtual forwarding routing table according to the access source address and the access destination address includes: Querying the virtual forwarding routing table to obtain the tunnel interface address and the address of the virtual machine; In response to the access source address being the address of the bare metal server and the access destination address being the address of the virtual machine, determining that the flow direction of the access traffic is from the bare metal server to the virtual machine; obtaining the address of the tunnel sub-interface, and in response to the access source address being the tunnel interface address and the access destination address being the address of the tunnel sub-interface, determining that the access traffic is generated by the virtual machine and the access traffic has been encapsulated by the tunnel interface; In response to the access traffic being generated by the virtual machine, de-encapsulating the access traffic through the tunnel sub-interface to obtain the original traffic; Parsing the original traffic to obtain the original source address and the original destination address; In response to the original destination address being the address of the bare metal server, determining that the flow direction of the access traffic is from the virtual machine to the bare metal access.
4. A traffic forwarding method according to claim 3, characterized in that, After the response that the original destination address is the address of the bare metal server, it further includes: The switch determines whether the corresponding port direct connection information has been stored according to the address of the bare metal server; In response to successful storage, the switch obtains the corresponding direct connection port and forwards the decapsulated original traffic to the bare metal server through the direct connection port; In response to non-storage, the switch broadcasts the decapsulated original traffic to the virtual LAN segment where the bare metal server is located; In response to the switch receiving the feedback information from the bare metal server, the port that receives the feedback information is recorded as the direct connection port of the bare metal server, and the corresponding port direct connection information is generated and stored.
5. A traffic forwarding method according to claim 3, characterized in that, A first bridge and a second bridge are also deployed in the computing node. The node bridge is respectively connected to the first bridge and the second bridge. The first bridge and the second bridge are respectively connected to the virtual machines. The access traffic has been encapsulated by the tunnel interfaces deployed on the node bridge, including: The virtual machine uses its own address as the original source address and the address of the bare metal server as the original destination address to generate the original traffic; The virtual machine obtains the network segment where the bare metal server is located according to the virtual forwarding routing table and determines whether the access is cross-network segment; In response to the access not being cross-network segment, the virtual machine encapsulates the first network identifier for the original traffic through the first tunnel set on the first bridge to generate the same-network traffic and sends it to the node bridge; In response to the access being cross-network segment, the virtual machine encapsulates the second network identifier for the original traffic through the second tunnel set on the second bridge to generate the cross-network traffic and sends it to the node bridge; In response to the node bridge receiving the same-network traffic or the cross-network traffic, the node bridge performs the pre-encapsulation on both the same-network traffic and the cross-network traffic through the tunnel interface, uses the address of the tunnel sub-interface as the access destination address, and uses the address of the tunnel interface as the access source address to generate the access traffic; The node bridge sends the access traffic to the receiving port of the switch. The receiving port, the computing node, and the tunnel sub-interface are all bound to the same virtual LAN.
6. A traffic forwarding method according to claim 3, characterized in that, The encapsulating the access traffic through the tunnel sub-interface and then forwarding it to the computing node includes: Query the virtual forwarding routing table to obtain the address of the virtual machine corresponding to the access destination address, the binding information between the address of the virtual machine and the address of the tunnel interface, and the connection port of the tunnel interface; Determine the corresponding tunnel interface and, according to the address of the tunnel interface, encapsulate the access traffic through the corresponding tunnel sub-interface, use the address of the tunnel interface as the destination address, and use the address of the tunnel sub-interface as the source address to generate the switch forwarding traffic; Forward the switch forwarding traffic to the corresponding computing node through the connection port of the tunnel interface.
7. A traffic forwarding method according to claim 6, characterized in that After the encapsulating the access traffic through the tunnel sub-interface and then forwarding it to the computing node, it further includes: In response to the node bridge receiving the switch forwarding traffic, the node bridge decapsulates the switch forwarding traffic through the tunnel interface to obtain the access traffic; The node bridge parses the access traffic to obtain the first network identifier or the second network identifier. The first network identifier is generated when the bare metal accesses the virtual machine in the same network segment, and the second network identifier is generated when the bare metal accesses the virtual machine across network segments; In response to obtaining the first network identifier, the node bridge sends the access traffic to the first bridge for decapsulation through the first tunnel; In response to obtaining the second network identifier, the node bridge sends the access traffic to the second bridge for decapsulation through the second tunnel; The first bridge or the second bridge parses the decapsulated access traffic to obtain the access destination address and sends the access traffic to the corresponding virtual machine.
8. A traffic forwarding device is applied to a cloud platform system, in which a bare metal server, computing nodes and switches are deployed. Virtual machines and node bridges are deployed on the computing nodes, and it is characterized in that The device includes: a traffic parsing module, configured to parse the access traffic to obtain the access source address and the access destination address in response to the access traffic received by the port of the switch; A flow direction determination module, configured to obtain the virtual forwarding routing table corresponding to the port, and determine the flow direction of the access traffic in combination with the access source address and the access destination address; A decapsulation and forwarding module, configured to determine that the access traffic has been encapsulated by the tunnel interface deployed on the node bridge in response to the flow direction of the access traffic being from the virtual machine to the bare metal server, and forward the access traffic to the bare metal server after decapsulation through the tunnel sub-interface corresponding to the tunnel interface deployed on the switch; An encapsulation and forwarding module, configured to determine that the access traffic has not been encapsulated in response to the flow direction of the access traffic being from the bare metal server to the virtual machine, and forward the access traffic to the compute node after encapsulation through the tunnel sub-interface.
9. An electronic device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to implement the steps of the traffic forwarding method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the traffic forwarding method according to any one of claims 1 to 7 when executed by a processor.