A virtual machine network connectivity testing method, device, medium and product
By using a single test network card to connect multiple l2gateway ports and the ovsdb protocol to monitor the southbound database status during virtual machine network connectivity testing, the hardware cost and management complexity issues caused by the large number of virtual routers are resolved, and efficient and automated network connectivity testing and simplified test service deployment are achieved.
Patent Information
- Application Number
- CN202511013883.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-07-23
AI Technical Summary
Given limited hardware resources, how can we efficiently and automatically test network connectivity for virtual machines, simplify the deployment of detection services, and avoid the increased hardware costs and management complexity caused by the large number of virtual routers?
A single preset detection network card is used to connect multiple l2gateway ports. Each port corresponds to a virtual router. The mapping relationship between network labels and virtual routers is recorded in a preset mapping relationship table. The l2gateway port with the same IP and MAC address is used to send detection messages. The southbound database status is monitored through the ovsdb protocol to dynamically adjust the IP list.
It reduces the number of network cards required for detection service nodes, saves hardware resources, improves the real-time performance and result reliability of network connectivity testing, reduces network congestion and response delays, and simplifies the deployment process of detection services.
Smart Images

Figure CN120528842B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and in particular to a method, device, medium and product for testing network connectivity of a virtual machine. Background Art
[0002] With the rapid development of cloud computing technology, the number of virtual machines (VMs) in cloud platforms has exploded. Cloud platforms provide network communication capabilities for VMs through virtual networks. However, the complexity of virtual networks can lead to VM network anomalies, such as communication interruptions caused by network component failures or configuration errors.
[0003] Currently, testing virtual machine network connectivity primarily involves deploying a detection service. However, in traditional solutions, each virtual router requires a separate physical network interface card (NIC) to communicate with the detection service. This increases the number of virtual routers and necessitates deploying numerous NICs across the detection service nodes, increasing hardware costs and management complexity.
[0004] In summary, given limited hardware resources, how to efficiently and automatically perform network connectivity testing on virtual machines and simplify the deployment of detection services is an issue that needs to be addressed. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a virtual machine network connectivity testing method, device, medium and product, which can efficiently and automatically perform network connectivity testing on virtual machines under limited hardware resources, and simplify the deployment of testing services. The specific solution is as follows:
[0006] In a first aspect, the present application discloses a method for testing virtual machine network connectivity, which is applied to a detection service. The detection service is configured with a single preset detection network card, which is connected to multiple L2Gateway ports. Each L2Gateway port corresponds to a virtual router, and the IP address and MAC address of each L2Gateway port are the same. The method includes:
[0007] Determine the target virtual machine to be tested, and determine the target network label corresponding to the target virtual machine from a preset mapping relationship table; the preset mapping relationship table is used to record the mapping relationship between each network label and all virtual machines in the corresponding virtual router;
[0008] The detection message is encapsulated based on the target network label, and the detection message is sent to the target l2gateway port that matches the target network label using the preset detection network card;
[0009] A target virtual router matching the target l2gateway port is determined so that the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router to perform a network connectivity test on the target virtual machine.
[0010] Optionally, the virtual machine network connectivity testing method of the present application further includes:
[0011] Create a corresponding detection network for each virtual router in advance, and configure a corresponding l2gateway port for each detection network; different detection networks are configured with the same network segment information;
[0012] Accordingly, the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router, including:
[0013] A target detection network corresponding to the target l2gateway port is determined to forward the detection message to the matching target detection network through the target l2gateway port, so that the target detection network forwards the detection message to the target virtual machine in the target virtual router.
[0014] Optionally, each virtual router is connected to the corresponding detection network via a router interface; wherein each router interface is pre-configured with a target MAC table for recording the correspondence between the IP address and MAC address of each l2gateway port, so that the target virtual machine returns a response message corresponding to the detection message based on the target MAC table.
[0015] Optionally, the detection service is deployed on at least one physical node, and each l2gateway port corresponding to the same physical node is configured with a different network name;
[0016] Accordingly, the virtual machine network connectivity testing method of the present application further includes:
[0017] A network bridge is created in the physical node where the detection service is deployed, and the network name of each l2gateway port on the same physical node is mapped to the network bridge; wherein the network bridge is connected to the preset detection network card.
[0018] Optionally, use a preset detection network card to send the detection message to the target l2gateway port that matches the target network label, including:
[0019] Use the preset detection network card to send the detection message to the bridge so that the bridge sends the detection message to the target l2gateway port that matches the target network label.
[0020] Optionally, each l2gateway port corresponding to the same physical node is configured with a different request tag, and the request tag of any l2gateway port has the same value as the network tag corresponding to the matching virtual router;
[0021] Accordingly, the detection message is sent to the target l2gateway port that matches the target network label using the preset detection network card, including:
[0022] Determine a target l2gateway port that matches the target network label based on the request labels of each l2gateway port connected to the preset detection network card;
[0023] Use the preset detection network card to send the detection message to the target l2gateway port.
[0024] Optionally, the virtual machine network connectivity testing method of the present application further includes:
[0025] Under the preset network isolation conditions, the detection service and the preset detection network card are deployed simultaneously in the preset network namespace;
[0026] Under the preset non-network isolation conditions, the detection service and the preset detection network card are deployed on the host machine at the same time.
[0027] Optionally, the process of testing the network connectivity of the target virtual machine also includes:
[0028] Determine whether a response message to the detection message sent by the target virtual machine is obtained within a preset time period;
[0029] If a response message is obtained, it is determined that the network connectivity test of the target virtual machine has passed; otherwise, it is determined that the network connectivity test of the target virtual machine has failed.
[0030] Optionally, after determining that the target virtual machine fails the network connectivity test, the following steps are further included:
[0031] Get the current status monitoring result of the target table in the southbound database;
[0032] Determine the fault type based on the status monitoring results and output corresponding log data or alarm information.
[0033] Optionally, the target tables include the Port_Binding table, the Chassis_Private table, and the SB_Global table;
[0034] Accordingly, the fault type is determined based on the status monitoring results, and the corresponding log data or alarm information is output, including:
[0035] If the value of the up field of the port corresponding to the target virtual machine in the Port_Binding table is false, a log message indicating that the target virtual machine has been shut down is output;
[0036] If the nb_cfg field in the Chassis_Private table is inconsistent with the nb_cfg field in the SB_Global table, an alarm message indicating a node abnormality is output;
[0037] If a change in the version number field in the Port_Binding table is detected, an alarm message indicating a change in the control plane is output.
[0038] Optionally, the detection service continuously monitors the virtual machine status information recorded in the southbound database based on the ovsdb protocol to adjust the target IP list based on the virtual machine status information; wherein the target IP list is used to record the IP address of the virtual machine currently to be tested.
[0039] Optionally, adjust the target IP list based on the VM status information, including:
[0040] If a new virtual machine is detected in the Port_Binding table, the IP address of the new virtual machine is added to the target IP list;
[0041] If the IP address of the first virtual machine in the Port_Binding table is monitored to change, the changed IP address of the first virtual machine is updated to the target IP list;
[0042] If the value of the up field of the port corresponding to the second virtual machine in the monitored Port_Binding table is false, the IP address corresponding to the second virtual machine is deleted from the target IP list.
[0043] In a second aspect, the present application discloses an electronic device, comprising:
[0044] Memory, used to store computer programs;
[0045] The processor is configured to execute a computer program to implement the steps of the aforementioned disclosed method for testing virtual machine network connectivity.
[0046] In a third aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed virtual machine network connectivity testing method are implemented.
[0047] In a fourth aspect, the present application discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the aforementioned virtual machine network connectivity testing method.
[0048] It can be seen that the present application discloses a method for testing network connectivity of a virtual machine applied to a detection service. The detection service is configured with a single preset detection network card, which is connected to multiple l2gateway ports. Each l2gateway port corresponds to a virtual router, and the IP address and MAC address of each l2gateway port are the same. The method includes: determining a target virtual machine to be tested, and determining a target network label corresponding to the target virtual machine from a preset mapping relationship table; the preset mapping relationship table is used to record the mapping relationship between each network label and all virtual machines in the corresponding virtual router; encapsulating a detection message based on the target network label, and sending the detection message to a target l2gateway port matching the target network label using the preset detection network card; determining a target virtual router matching the target l2gateway port so that the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router to perform a network connectivity test on the target virtual machine.
[0049] Beneficial effect: The detection service in the present application is configured with a single preset detection network card, which is connected to multiple l2gateway ports, and each l2gateway port corresponds to a virtual router. That is, the present application discloses a solution for communicating with virtual machines based on l2gateway ports, and all l2gateway ports share the same detection network card, so there is no need to configure an independent physical network card for each virtual router to communicate with the detection service, which greatly reduces the number of network cards required for the detection service node and saves hardware resources. In addition, the present application pre-establishes a preset mapping relationship table for recording the mapping relationship between each network label and all virtual machines in the corresponding virtual router, that is, the present application uses different network labels to distinguish different virtual routers. After determining the target virtual machine to be tested, the detection service can directly determine the target network label corresponding to the target virtual machine from the preset mapping relationship table, and accurately encapsulate the detection message based on the target network label. Since there is a corresponding relationship between the network label and the virtual router, and each l2gateway port also corresponds to a unique virtual router, the detection message can be quickly routed to the target virtual router through the target l2gateway port, and then reach the final target virtual machine to perform a network connectivity test, avoiding network congestion and response delays, and improving the real-time performance and result reliability of the connectivity test. In addition, each l2gateway port in this application uses the same IP address and MAC address, which can ensure that the detection service uses the same IP address when sending the detection message, making it convenient for the virtual machine to quickly identify the detection message, and this method of fixing the source IP can also ensure that it is only used for the detection service to prevent abuse. In this way, through the above solution, the detection service only needs one detection network card to test the network connectivity of the virtual machines in multiple virtual routers, significantly reducing resource usage. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0051] Figure 1 This is a flow chart of a virtual machine network connectivity testing method disclosed in this application;
[0052] Figure 2 This is a schematic diagram of a specific node configuration result disclosed in this application;
[0053] Figure 3 This is a flowchart of a specific virtual machine network connectivity testing method disclosed in this application;
[0054] Figure 4 This is a structural diagram of a virtual machine network connectivity testing device disclosed in this application;
[0055] Figure 5 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0056] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0057] Currently, the network connectivity of virtual machines is primarily tested by deploying a detection service. However, in traditional solutions, each virtual router must be configured with an independent physical network card to communicate with the detection service. When the number of virtual routers is large, the detection service node must deploy a large number of network cards, thereby increasing hardware costs and management complexity. To this end, the embodiments of the present application disclose a method, device, medium, and product for testing virtual machine network connectivity. These methods enable the detection service to efficiently and automatically test the network connectivity of virtual machines with limited hardware resources, and simplify the deployment of the detection service.
[0058] See also Figure 1 As shown, the embodiment of the present application discloses a method for testing virtual machine network connectivity, which is applied to a detection service. The detection service is configured with a single preset detection network card, which is connected to multiple L2gateway ports. Each L2gateway port corresponds to a virtual router, and the IP address and MAC address of each L2gateway port are the same. The method includes:
[0059] Step S11: Determine the target virtual machine to be tested, and determine the target network label corresponding to the target virtual machine from a preset mapping relationship table; the preset mapping relationship table is used to record the mapping relationship between each network label and all virtual machines in the corresponding virtual router.
[0060] In this embodiment, the detection service is configured with a single pre-set detection network card, which is connected to multiple L2Gateway ports, each corresponding to a virtual router. Specifically, this application discloses a solution for communicating with virtual machines based on L2Gateway ports. All L2Gateway ports share the same detection network card, eliminating the need to configure a separate physical network card for each virtual router to communicate with the detection service. This significantly reduces the number of network cards required for the detection service node and saves hardware resources. An L2Gateway port is a type of logical port in OVN (Open Virtual Network); OVN is an open source network virtualization solution based on Open vSwitch (OVS), designed to implement the construction and management of Software Defined Networks (SDN) through automated rules. It includes components such as a southbound database, a northbound database, and a distributed controller. Specifically, this application detects the connectivity of virtual machine networks within the OVN architecture.
[0061] In addition, OVN's l2gateway port is mostly used to connect physical VLAN networks and in-cloud tunnel networks. Generally, a specific IP address (Internet Protocol Address) is not configured, but it is configured as Unknown, thus ensuring that any other IP can pass through the port. In this application, each l2gateway port is configured with the same IP address and MAC address (Media Access Control Address, LAN address or physical address), which can ensure that when the detection service sends a detection message, the source IP uses the same IP address, making it easier for the virtual machine to quickly identify the detection message. The user can then decide whether to be detected by configuring security groups, firewalls within the virtual machine, etc. In addition, this fixed source IP method can also ensure that it is only used for detection services, preventing abuse and ensuring security.
[0062] Furthermore, the present application pre-establishes a preset mapping table to record the mapping between each network tag and all virtual machines in the corresponding virtual router. This means that different network tags are used to distinguish different virtual routers. Once the target virtual machine to be tested is determined, the detection service can directly determine the target network tag corresponding to the target virtual machine from the preset mapping table. Specifically, the network tag refers to a VLAN tag, which identifies the virtual local area network (VLAN) to which a data frame belongs. Specifically, the detection service establishes a preset mapping table that lists VLAN tags and the IP addresses of all virtual machines in the corresponding virtual router. When a virtual machine needs to be tested, the detection service encapsulates the VLAN according to the preset mapping table, adding the VLAN tag corresponding to the target virtual machine to the data frame. The detection message is then sent through the preset detection network card. Furthermore, it should be noted that each virtual router can connect to multiple virtual machine networks. This means that a virtual router can associate multiple independent virtual machine networks through different ports to achieve network isolation and routing forwarding. Each virtual machine network can contain multiple virtual machine ports, each corresponding to a virtual machine. This means that a single virtual machine network can host multiple virtual machines, sharing the network's subnet resources.
[0063] In addition, the above method also includes: under the preset network isolation condition, the detection service and the preset detection network card are simultaneously deployed in the preset network namespace; under the preset non-network isolation condition, the detection service and the preset detection network card are simultaneously deployed on the host. That is, in this embodiment, it can be determined whether the current network isolation condition or the non-network isolation condition is met based on security requirements, thereby deciding whether to use the network namespace for isolation. If isolation from the host network is required, the preset detection network can be added to a network namespace, and the detection service can be deployed together with the preset detection network card in the network command space. In this way, the detection service process needs to run in the network namespace, avoiding the detection traffic from interfering with the host business, and after isolation, even if the detection service is attacked, it will not affect the host network, and the host network cannot directly access the preset detection network card, thereby improving security. When isolation is not required, the detection service and the preset detection network card can be deployed on the host at the same time, that is, the detection service runs directly on the host and sends and receives messages through the preset detection network card.
[0064] Furthermore, the above method also includes: creating a corresponding detection network for each virtual router in advance, and configuring a corresponding l2gateway port for each detection network; wherein different detection networks are configured with the same network segment information. That is, the embodiment of the present application creates a corresponding detection network for each virtual router, and each detection network is configured with the same network segment information. In a specific implementation, a network segment for detection services can be pre-set, and it is stipulated that other network segments used in the cloud platform cannot overlap with the network segment. In addition, a corresponding l2gateway port is configured for each detection network, and each l2gateway port is configured with the same IP address and MAC address. In other words, one l2gateway port corresponds to one detection network and one virtual router.
[0065] Step S12: encapsulate a detection message based on the target network label, and use a preset detection network card to send the detection message to the target l2gateway port that matches the target network label.
[0066] In this embodiment, a detection message is precisely encapsulated based on the target network label, and then a preset detection network card is used to send the detection message to the target l2gateway port that matches the target network label. Because network labels correspond to virtual routers, and virtual routers correspond to l2gateway ports, the preset detection network card can accurately send the detection message to the target l2gateway port that matches the target network label.
[0067] This embodiment does not restrict the specific method for sending detection messages. A self-developed method using the Python Scapy library or an existing tool such as hping3 can be used. As long as the VLAN message can be encapsulated and the required detection protocol can be issued, any method will suffice. Furthermore, this embodiment does not restrict the protocol used to send the detection message. It can be either ICMP (Internet Control Message Protocol) or TCP (Transmission Control Protocol). Configuring the detection protocol based on the specific services of the virtual machine is also possible.
[0068] It should also be pointed out that the detection service is deployed on at least one physical node, and each l2gateway port corresponding to the same physical node is configured with a different network name; accordingly, the virtual machine network connectivity testing method of the present application also includes: creating a bridge in the physical node where the detection service is deployed, and mapping the network name of each l2gateway port on the same physical node to the bridge; wherein, the bridge establishes a connection relationship with the preset detection network card.
[0069] It is understood that this application also requires configuring chassis information for each L2gateway port. Chassis information is used to indicate the physical node where the detection service is deployed. The detection service can be deployed on at least one physical node. Each L2gateway port can be configured with the same chassis or different chassis. Identical chassis indicate the same physical node. In this embodiment, each L2gateway port corresponding to the same physical node is configured with a different network name (network_name). In other words, L2gateway ports configured with the same chassis need to be configured with different network_names.
[0070] Furthermore, the embodiment of the present application also needs to create a bridge in the physical node where the detection service is deployed, and map the network name of each l2gateway port on the same physical node to the bridge; wherein the bridge establishes a connection relationship with the preset detection network card. That is, this embodiment configures mapping (i.e., mapping) according to the network_name of each l2gateway port configured to the physical node. For example, the chassis configured with l2gateway port 1, l2gateway port 2, and l2gateway port 3 is physical node node1, and the network_name of l2gateway port 1, l2gateway port 2, and l2gateway port 3 are t1, t2, and t3 respectively; then it is necessary to configure the mapping corresponding to the network_name on the physical node node1: t1:br-tvm, t2:br-tvm, t3:br-tvm. Create the bridge identified in the mapping, i.e., br-tvm. It can be seen that this application configures different network_names, such as t1, t2, and t3, for the l2gateway ports configured with the same chassis, so as to configure a mapping relationship (mapping) on the physical node where the detection service is deployed, so as to associate the detection networks of different virtual routers with the bridges (such as br-tvm) on the physical node, ensuring that the detection messages can be correctly routed to the target virtual router.
[0071] In a specific embodiment, using a pre-set detection network card to send a detection message to a target L2Gateway port that matches the target network tag includes: using the pre-set detection network card to send the detection message to a bridge, so that the bridge sends the detection message to the target L2Gateway port that matches the target network tag. That is, because the bridge is connected to the pre-set detection network card, traffic from all L2Gateway ports must be forwarded through the same physical bridge (br-tvm), achieving traffic aggregation. This allows the detection service to send detection messages through a single pre-set detection network card, which is then automatically diverted by the bridge based on the VLAN tag and sent to the matching target L2Gateway port.
[0072] Furthermore, it should be noted that each l2gateway port corresponding to the same physical node is configured with a different request tag, and the request tag of any l2gateway port has the same value as the network tag corresponding to the matching virtual router. Accordingly, using a preset detection network card to send a detection message to a target l2gateway port that matches the target network tag includes: determining a target l2gateway port that matches the target network tag based on the request tags of each l2gateway port connected to the preset detection network card; and sending the detection message to the target l2gateway port using the preset detection network card. It is understood that, in addition to being configured with different network names, l2gateway ports configured with the same chassis also need to be configured with different request tags (tag_request), and that the request tag of any l2gateway port has the same value as the network tag (VLAN tag) corresponding to the matching virtual router. In this way, when the preset detection network card sends the detection message to the target l2gateway port that matches the target network label, it can determine the target l2gateway port that matches the target network label based on the request labels of each l2gateway port connected to the preset detection network card, and then send the detection message to the target l2gateway port, thereby realizing a fast matching process.
[0073] It's also worth noting that since VLAN tags occupy 12 binary bits, they can theoretically represent 4096 different values, ranging from 0 to 4095. However, VLAN 0 is used to identify frame priority, and 4095 (FFF) is a reserved value that cannot be used in ordinary VLAN configurations. Therefore, a single node's detection service can connect to up to 4094 virtual routers. Beyond this number, the detection service can be deployed on multiple physical nodes to achieve scalability and support large-scale clusters. Furthermore, in specific implementations, virtual machines can be assigned to different physical nodes based on the number of virtual machines, and splitting to different physical nodes does not necessarily require reaching the limit.
[0074] Understandably, deploying a detection service on a single node can become a performance bottleneck, such as tens of thousands of detection requests per second. As the cloud platform scales up, to tens of thousands of virtual machines, it may face the following issues: Single-node performance bottleneck: The CPU / network card throughput of a single detection service instance cannot support high concurrent detection requests;
[0075] Uneven latency: Some virtual machines experience delayed result feedback due to a backlog of detection tasks, impacting real-time performance. Poor fault tolerance: A single node failure can lead to widespread detection interruption. Therefore, in real-world scenarios, multiple physical nodes are often used to deploy detection services. In solutions that employ multiple physical nodes, detection tasks can be intelligently allocated based on multiple indicators, such as node load, network topology, and virtual machine location, to achieve load balancing. Each indicator can be pre-set with a different weight. In specific implementations, a Master-Worker distributed architecture can be employed. The Master node (scheduler) is responsible for maintaining the global detection task queue, monitoring the status of Worker nodes (CPU, memory, and network load), and dynamically allocating detection tasks to Worker nodes. The Worker node (detection executor) deploys detection service instances, binds to local l2gateway ports, executes detection tasks issued by the Master, and returns results.
[0076] Step S13: Determine a target virtual router that matches the target l2gateway port, so that the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router to perform a network connectivity test on the target virtual machine.
[0077] In this embodiment, since each l2gateway port also corresponds to a unique virtual router, the test message can be quickly routed through the target l2gateway port to the target virtual router, and then to the final target virtual machine for network connectivity testing. This avoids network congestion and response delays, improving the real-time performance and reliability of connectivity testing. Thus, through the above solution, the detection service only needs a single detection network card to test the network connectivity of virtual machines in multiple virtual routers, significantly reducing resource usage.
[0078] In a specific embodiment, the target L2gateway port forwards the detection message to the target virtual machine in the target virtual router by determining the target detection network corresponding to the target L2gateway port, forwarding the detection message to the matching target detection network via the target L2gateway port, and then forwarding the detection message to the target virtual machine in the target virtual router. Specifically, since each L2gateway port corresponds to a detection network and a virtual router, the target L2gateway port first forwards the detection message to the matching target detection network, which then forwards the detection message to the target virtual machine in the target virtual router. However, throughout this process, the detection message's network tag (VLAN tag) is used to identify the entire communication path for transmission to the target virtual router.
[0079] Furthermore, each virtual router in the present application is connected to the corresponding detection network via a router interface; each router interface is pre-configured with a target MAC table that records the correspondence between the IP address and MAC address of each l2gateway port, so that the target virtual machine can return a response message corresponding to the detection message based on the target MAC table. It is understood that this embodiment configures a target MAC table for the router interface connected to the detection network on the virtual router, wherein the target MAC table records the correspondence between the IP address and MAC address of the l2gateway. This enables the target virtual machine to return a response message corresponding to the detection message based on the target MAC table. That is, the target virtual machine does not need to dynamically learn ARP (Address Resolution Protocol) when responding to the detection service.
[0080] Figure 2 This is a schematic diagram of a specific node configuration result disclosed in this application. Figure 2 The example shown in FIG. 1 specifically illustrates the above scheme.
[0081] 1. Preset a network segment for detecting services, such as Figure 2 The network segment 10.200.10.0 / 30 shown in the figure cannot overlap with the network segment used in the cloud platform.
[0082] 2. Preset a physical node for deploying detection services, such as Figure 2 The node node1 shown;
[0083] 3. Create a detection network for each virtual router and configure the same network segment information 10.200.10.0 / 30;
[0084] 4. Create an l2gateway port for each detection network and configure the same IP address and MAC address, for example Figure 2 As shown in the figure, the IP address is configured as 10.200.10.2, and the chassis information is configured, that is, node1, where the detection service is deployed. The same chassis can be configured, or different chassis can be configured. In addition, the l2gateway port of the same chassis needs to be configured with a different network name (network_name) and a different request tag (tag_request);
[0085] 5. Configure the physical node node1 and configure the mapping according to the network_name of each l2gateway port configured to the node, for example Figure 2 As shown in the figure, the chassis configured for l2gateway port 1, l2gateway port 2, and l2gateway port 3 is node1. Therefore, you need to configure the mappings corresponding to network_name on node1: t1:br-tvm, t2:br-tvm, and t3:br-tvm. Create the bridge identified in the mapping, for example, br-tvm.
[0086] 6. Configure the detection service and add an ovs internal type interface to the bridge. The interface can be named as needed, for example Figure 2 As shown in the figure, if you need to isolate the network from the host, you can add the T-NIC network card to a network namespace, and deploy the detection service along with the T-NIC network card to the network command space, or directly deploy it to the host.
[0087] 7. Configure the target MAC table for the router interface connected to the detection network on the virtual router, and configure the mapping between the IP address and MAC address of the l2gateway to implement the virtual machine reverse reply detection service without the need for dynamic ARP learning;
[0088] 8. The detection service establishes a corresponding table between VLAN tags and virtual machine IP addresses. When you want to detect a virtual machine, you can encapsulate the VLAN according to the corresponding table and send a detection message through the T-NIC network card. For example Figure 2 As shown in the figure, when accessing VM port 1, it is necessary to go through l2gateway port 1. The tag_request corresponding to l2gateway port 1, that is, the VLAN tag, is 1, so the VLAN of the encapsulated detection message is 1. Similarly, when accessing VM port 2, the encapsulation VLAN is 1, and when accessing VM port 4, the encapsulation VLAN is 2.
[0089] It can be seen that the detection service in this application is configured with a single preset detection network card, which is connected to multiple l2gateway ports, and each l2gateway port corresponds to a virtual router. That is, this application discloses a solution for communicating with virtual machines based on l2gateway ports, and all l2gateway ports share the same detection network card, so there is no need to configure an independent physical network card for each virtual router to communicate with the detection service, which greatly reduces the number of network cards required for the detection service node and saves hardware resources. In addition, this application pre-establishes a preset mapping relationship table for recording the mapping relationship between each network label and all virtual machines in the corresponding virtual router, that is, this application uses different network labels to distinguish different virtual routers. After determining the target virtual machine to be tested, the detection service can directly determine the target network label corresponding to the target virtual machine from the preset mapping relationship table, and accurately encapsulate the detection message based on the target network label. Since there is a corresponding relationship between the network label and the virtual router, and each l2gateway port also corresponds to a unique virtual router, the detection message can be quickly routed to the target virtual router through the target l2gateway port, and then reach the final target virtual machine to perform a network connectivity test, avoiding network congestion and response delays, and improving the real-time performance and result reliability of the connectivity test. In addition, each l2gateway port in this application uses the same IP address and MAC address, which can ensure that the detection service uses the same IP address when sending the detection message, making it convenient for the virtual machine to quickly identify the detection message, and this method of fixing the source IP can also ensure that it is only used for the detection service to prevent abuse. In this way, through the above solution, the detection service only needs one detection network card to test the network connectivity of the virtual machines in multiple virtual routers, significantly reducing resource usage.
[0090] See also Figure 3 As shown, the embodiment of the present application discloses a specific method for testing virtual machine network connectivity. Compared with the previous embodiment, this embodiment further illustrates and optimizes the technical solution. Specifically, it includes:
[0091] Step S21: Determine the target virtual machine to be tested, and determine the target network label corresponding to the target virtual machine from a preset mapping relationship table; the preset mapping relationship table is used to record the mapping relationship between each network label and all virtual machines in the corresponding virtual router.
[0092] Step S22: encapsulate a detection message based on the target network label, and use a preset detection network card to send the detection message to the target l2gateway port that matches the target network label.
[0093] Step S23: Determine a target virtual router that matches the target l2gateway port, so that the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router.
[0094] Step S24: determining whether a response message to the detection message sent by the target virtual machine is obtained within a preset time period.
[0095] In this embodiment, after the detection message is successfully sent to the target virtual machine, the detection service can use a timer to perform a timing operation and determine whether a response message to the detection message is received from the target virtual machine within a preset time period. The specific value of the preset time period can be set according to specific circumstances.
[0096] Step S25: If a response message is obtained, it is determined that the network connectivity test of the target virtual machine has passed.
[0097] In this embodiment, if a response message to the detection message sent by the target virtual machine is obtained within a preset time period, it is determined that the network connectivity test of the target virtual machine has passed.
[0098] Step S26: If no response message is obtained, it is determined that the network connectivity test of the target virtual machine has failed, and the current status monitoring result of the target table in the southbound database is obtained to determine the fault type based on the status monitoring result, and output corresponding log data or alarm information.
[0099] In this embodiment, if no response message is received from the target virtual machine in response to the test message within a preset time period, the target virtual machine's network connectivity test has failed. If this fails, the system can further obtain the status monitoring results of the target table in the southbound database to determine the fault type, that is, the specific reason for the current network connectivity test failure, based on the status monitoring results. The system then outputs corresponding log data or alarm information.
[0100] In a specific implementation, the target tables include a Port_Binding table, a Chassis_Private table, and a SB_Global table; accordingly, the fault type is determined based on the status monitoring result, and corresponding log data or alarm information is output, including: if the value of the up field of the port corresponding to the target virtual machine in the Port_Binding table is false, then log information indicating that the target virtual machine has been shut down is output; if the nb_cfg field in the Chassis_Private table is inconsistent with the nb_cfg field in the SB_Global table, then alarm information indicating node abnormality is output; if the version number field in the Port_Binding table is changed, then alarm information indicating that the control plane has changed is output.
[0101] It's important to note that the detection service monitors the status of southbound database resources in the OVN (OVSwitch Database) protocol, primarily monitoring the Port_Binding, Chassis_Private, SB_Global, and Chassis tables. The Port_Binding table primarily records the binding relationship between virtual network ports (such as VM NICs and logical switch ports) and physical / logical resources. The "up" field indicates the port status: "true" indicates active, and "false" indicates down or unbound. The "type" field indicates the port type: a blank value indicates a VM port, while "external" indicates a bare metal port. The "external_ids" field indicates an extension field: "neutron:revision_number" indicates the Neutron port configuration version number. The "chassis" field indicates the node to which the port is bound; if it's blank, the port is unbound. The Chassis_Private table is used to store the node's private state information, such as the configuration version number and internal identifier. It is only visible to the current node. The nb_cfg field involved indicates the local configuration version number of the current node, which should be consistent with the nb_cfg field in the SB_Global table. If it is inconsistent, it means that the node has not synchronized the latest configuration. The SB_Global table mainly stores global configuration and version numbers, and is used to coordinate the state synchronization of the entire OVN cluster. The nb_cfg field must be consistent with the nb_cfg field in the Chassis_Private table. The Chassis table is used to record metadata for all physical or virtual nodes, such as compute nodes and gateway nodes. The name field involved indicates the name of the physical node, such as node1.
[0102] Therefore, after obtaining the status monitoring results of the target table above, if the value of the up field for the port corresponding to the target virtual machine in the Port_Binding table is false, indicating that the network card has been removed or the virtual machine has been shut down, a log message indicating that the target virtual machine has been shut down can be directly output without generating an alarm. If the nb_cfg field in the Chassis_Private table corresponding to the chassis bound to the Port_Binding table is inconsistent with the nb_cfg field in the SB_Global table, an alarm message indicating a node abnormality is output, requiring operations personnel to determine the host machine status. If the version number field in the Port_Binding table (external_ids:neutron:revision_number) is changed, it indicates that the control plane may have changed and needs to be identified. In this case, an alarm message indicating the change in the control plane is output. In addition, if none of the above abnormal conditions exist, an error message is printed to alert operations personnel to investigate.
[0103] In addition, it should be noted that the detection service will continuously monitor the virtual machine status information recorded in the southbound database based on the ovsdb protocol, and adjust the target IP list based on the virtual machine status information; among them, the target IP list is used to record the IP address of the virtual machine currently to be tested.
[0104] In a specific embodiment, the target IP list is adjusted based on the virtual machine status information, including: if a new virtual machine is detected in the Port_Binding table, the IP address of the new virtual machine is added to the target IP list; if a change is detected in the IP address of the first virtual machine in the Port_Binding table, the changed IP address of the first virtual machine is updated to the target IP list; if the value of the up field of the port corresponding to the second virtual machine in the Port_Binding table is detected to be false, the IP address corresponding to the second virtual machine is deleted from the target IP list. That is, the detection service will continue to monitor the Port_Binding table, and if a new virtual machine is detected in the Port_Binding table, the IP address of the new virtual machine is added to the target IP list to achieve dynamic adjustment of the target IP list; wherein, if type=empty character, it is identified as a new virtual machine port, and if type=external, it is identified as a new bare metal port. If a change is detected in the IP address of the first virtual machine in the Port_Binding table, the changed IP address of the first virtual machine needs to be updated to the target IP list. Furthermore, if the value of the "up" field for the port corresponding to the second VM in the Port_Binding table is false, the second VM may be powered off, so there's no need to probe that IP address. Therefore, the IP address corresponding to the second VM can be removed from the target IP list. Conversely, if the value of the "up" field for the port corresponding to the second VM is true, probing can continue. Furthermore, changes in the Chassis_Private table can be monitored. If the nb_cfg field in a node's Chassis_Private does not change with the nb_cfg field in SB_Global, or if each change takes a long time to follow, an alert can be issued.
[0105] For more specific processing procedures of the above steps S21, S22 and S23, reference may be made to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.
[0106] It can be seen that this application provides a cloud platform virtual machine network testing solution based on OVN, which can detect all virtual machine networks in the cloud platform. Specifically, it realizes the aggregation connection of the detection network based on the l2gateway port, greatly reducing the number of network cards used for detection, reducing the complexity of the OVN network introduced by the detection, and reducing the complexity of the detection program maintenance. In addition, this application dynamically monitors the southbound database of OVN through the ovsdb protocol, maintains the target IP list according to data changes, reduces the operation and maintenance work, and automatically predicts some cluster situations, which is convenient for operation and maintenance personnel to check when problems are found.
[0107] See also Figure 4As shown, the embodiment of the present application discloses a virtual machine network connectivity test device, which is applied to a detection service. The detection service is configured with a single preset detection network card, which is connected to multiple L2Gateway ports. Each L2Gateway port corresponds to a virtual router, and the IP address and MAC address of each L2Gateway port are the same. The device includes:
[0108] The network label determination module 11 is used to determine the target virtual machine to be tested and determine the target network label corresponding to the target virtual machine from a preset mapping relationship table; the preset mapping relationship table is used to record the mapping relationship between each network label and all virtual machines in the corresponding virtual router;
[0109] The message encapsulation and sending module 12 is used to encapsulate the detection message based on the target network label and send the detection message to the target l2gateway port matching the target network label using the preset detection network card;
[0110] The message forwarding module 13 is configured to determine a target virtual router that matches the target l2gateway port, so that the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router to perform a network connectivity test on the target virtual machine.
[0111] It can be seen that the detection service in this application is configured with a single preset detection network card, which is connected to multiple l2gateway ports, and each l2gateway port corresponds to a virtual router. That is, this application discloses a solution for communicating with virtual machines based on l2gateway ports, and all l2gateway ports share the same detection network card, so there is no need to configure an independent physical network card for each virtual router to communicate with the detection service, which greatly reduces the number of network cards required for the detection service node and saves hardware resources. In addition, this application pre-establishes a preset mapping relationship table for recording the mapping relationship between each network label and all virtual machines in the corresponding virtual router, that is, this application uses different network labels to distinguish different virtual routers. After determining the target virtual machine to be tested, the detection service can directly determine the target network label corresponding to the target virtual machine from the preset mapping relationship table, and accurately encapsulate the detection message based on the target network label. Since there is a corresponding relationship between the network label and the virtual router, and each l2gateway port also corresponds to a unique virtual router, the detection message can be quickly routed to the target virtual router through the target l2gateway port, and then reach the final target virtual machine to perform a network connectivity test, avoiding network congestion and response delays, and improving the real-time performance and result reliability of the connectivity test. In addition, each l2gateway port in this application uses the same IP address and MAC address, which can ensure that the detection service uses the same IP address when sending the detection message, making it convenient for the virtual machine to quickly identify the detection message, and this method of fixing the source IP can also ensure that it is only used for the detection service to prevent abuse. In this way, through the above solution, the detection service only needs one detection network card to test the network connectivity of the virtual machines in multiple virtual routers, significantly reducing resource usage.
[0112] Since the embodiments of the device part correspond to the above embodiments, the embodiments of the device part please refer to the description of the embodiments of the method part, and will not be repeated here.
[0113] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Specifically, the device may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps of the virtual machine network connectivity testing method performed by the electronic device as disclosed in any of the aforementioned embodiments.
[0114] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0115] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.
[0116] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon include an operating system 221, a computer program 222 and data 223, etc. The storage method can be temporary storage or permanent storage.
[0117] The operating system 221 is used to manage and control the hardware devices and computer programs 222 on the electronic device 20, so as to enable the processor 21 to calculate and process the massive amount of data 223 in the memory 22. The operating system 221 can be Windows, Unix, Linux, etc. In addition to including computer programs capable of performing the virtual machine network connectivity testing method performed by the electronic device 20 as disclosed in any of the aforementioned embodiments, the computer programs 222 can further include computer programs capable of performing other specific tasks. In addition to data received by the electronic device and transmitted from external devices, the data 223 can also include data collected by its own input and output interface 25.
[0118] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the steps of the virtual machine network connectivity testing method disclosed in any of the aforementioned embodiments are implemented.
[0119] An embodiment of the present invention further discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the virtual machine network connectivity testing method disclosed in any of the aforementioned embodiments.
[0120] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.
[0121] Those skilled in the art may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0122] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a compact disc read-only memory (CD-ROM), or any other form of storage medium known in the art.
[0123] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0124] The above is a detailed introduction to a virtual machine network connectivity testing method, device, equipment and storage medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method and core ideas of the present invention. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A method for testing virtual machine network connectivity, characterized in that: Applied to a detection service, the detection service is configured with a single preset detection network card, the preset detection network card is connected to multiple l2gateway ports, each l2gateway port corresponds to a virtual router, and the IP address and MAC address of each l2gateway port are the same, the method includes: Determine a target virtual machine to be tested, and determine a target network label corresponding to the target virtual machine from a preset mapping relationship table; the preset mapping relationship table is used to record the mapping relationship between each network label and all virtual machines in the corresponding virtual router; Encapsulating a detection message based on the target network label, and sending the detection message to a target l2gateway port that matches the target network label using the preset detection network card; Determine the target virtual router that matches the target l2gateway port so that the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router to perform a network connectivity test on the target virtual machine; Wherein, the method further includes: A corresponding detection network is created for each virtual router in advance, and a corresponding l2gateway port is configured for each detection network; wherein different detection networks are configured with the same network segment information.
2. The method for testing virtual machine network connectivity according to claim 1, wherein the target l2gateway port forwards the detection message to the target virtual machine in the target virtual router, comprising: A target detection network corresponding to the target l2gateway port is determined to forward the detection message to the matching target detection network through the target l2gateway port, so that the target detection network forwards the detection message to the target virtual machine in the target virtual router.
3. The virtual machine network connectivity testing method according to claim 2, wherein: Each virtual router is connected to the corresponding detection network via a router interface; wherein each router interface is pre-configured with a target MAC table for recording the correspondence between the IP address and MAC address of each l2gateway port, so that the target virtual machine returns a response message corresponding to the detection message based on the target MAC table.
4. The virtual machine network connectivity testing method according to claim 1, wherein: The detection service is deployed on at least one physical node, and each l2gateway port corresponding to the same physical node is configured with a different network name; Accordingly, the method further includes: A network bridge is created in a physical node where a detection service is deployed, and the network name of each l2gateway port on the same physical node is mapped to the network bridge; wherein a connection relationship is established between the network bridge and the preset detection network card.
5. The virtual machine network connectivity testing method according to claim 4, characterized in that: The step of using the preset detection network card to send the detection message to a target l2gateway port that matches the target network label includes: The detection message is sent to the network bridge using the preset detection network card, so that the network bridge sends the detection message to the target l2gateway port that matches the target network label.
6. The virtual machine network connectivity testing method according to claim 4, characterized in that: Each l2gateway port corresponding to the same physical node is configured with a different request label. The request label of any l2gateway port has the same value as the network label corresponding to the matching virtual router; Correspondingly, the using the preset detection network card to send the detection message to the target l2gateway port that matches the target network label includes: Determine a target l2gateway port that matches the target network label based on the request labels of each l2gateway port connected to the preset detection network card; The detection message is sent to the target l2gateway port using the preset detection network card.
7. The virtual machine network connectivity testing method according to claim 1, wherein: Also includes: Under the preset network isolation condition, the detection service and the preset detection network card are simultaneously deployed in a preset network namespace; Under the preset non-network isolation condition, the detection service and the preset detection network card are deployed on the host machine at the same time.
8. The virtual machine network connectivity testing method according to claim 1, wherein: The process of performing a network connectivity test on the target virtual machine further includes: Determining whether a response message to the detection message sent by the target virtual machine is obtained within a preset time period; If the response message is obtained, it is determined that the network connectivity test of the target virtual machine has passed; otherwise, it is determined that the network connectivity test of the target virtual machine has failed.
9. The virtual machine network connectivity testing method according to claim 8, characterized in that: After determining that the network connectivity test of the target virtual machine fails, the method further includes: Get the current status monitoring result of the target table in the southbound database; The fault type is determined based on the status monitoring result, and corresponding log data or alarm information is output.
10. The method for testing virtual machine network connectivity according to claim 9, wherein: The target tables include Port_Binding table, Chassis_Private table and SB_Global table; Accordingly, the fault type is determined based on the status monitoring result, and corresponding log data or alarm information is output, including: If the value of the up field of the port corresponding to the target virtual machine in the Port_Binding table is monitored to be false, then outputting log information indicating that the target virtual machine has been shut down; If it is detected that the nb_cfg field in the Chassis_Private table is inconsistent with the nb_cfg field in the SB_Global table, an alarm message indicating a node abnormality is output; If a change in the version number field in the Port_Binding table is detected, an alarm message indicating that the control plane has changed is output.
11. The method for testing virtual machine network connectivity according to claim 10, wherein: The detection service continuously monitors the virtual machine status information recorded in the southbound database based on the ovsdb protocol to adjust the target IP list based on the virtual machine status information; wherein, the target IP list is used to record the IP address of the virtual machine currently to be tested.
12. The virtual machine network connectivity testing method according to claim 11, characterized in that: The adjusting the target IP list based on the virtual machine state information includes: If a new virtual machine is detected in the Port_Binding table, the IP address of the new virtual machine is added to the target IP list; If a change in the IP address of the first virtual machine in the Port_Binding table is detected, the changed IP address of the first virtual machine is updated to the target IP list; If the value of the up field of the port corresponding to the second virtual machine in the Port_Binding table is monitored to be false, the IP address corresponding to the second virtual machine is deleted from the target IP list.
13. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor is configured to execute the computer program to implement the steps of the virtual machine network connectivity testing method according to any one of claims 1 to 12.
14. A computer-readable storage medium, characterized in that Used to store a computer program; wherein, when the computer program is executed by a processor, the steps of the virtual machine network connectivity testing method according to any one of claims 1 to 12 are implemented.
15. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the virtual machine network connectivity testing method according to any one of claims 1 to 12 are implemented.
Citation Information
Patent Citations
Link detection method and server
CN118041811A
Method, device and equipment for testing open type virtual network cluster and medium
CN118433061A