Intention verification method and device and related equipment
By collecting and modeling the operating status data of network devices, determining and verifying the intended path, the problem that traditional methods are difficult to cope with the complexity of data center networks is solved, and efficient and accurate network fault location and service verification are achieved.
Patent Information
- Application Number
- CN202510533746.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-09-23
AI Technical Summary
Traditional manual inspections and manual recording and analysis are unable to cope with the complexity and operation and maintenance challenges of data center networks, especially how to verify whether the network meets expectations after business changes, and how to use verification results to assist in confirming whether business changes have introduced problems.
Collect the operating status data of network devices, perform classification modeling, determine the reachable path for the intention to be verified, judge whether the path meets user expectations, and display the path through a panoramic operation and maintenance map.
It achieves accurate simulation and verification of network forwarding paths, ensures the correct implementation of services, solves service interruption or performance degradation in existing technologies, and provides rapid identification of network problems that may affect services.
Smart Images

Figure CN120692153A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to an intent verification method, apparatus, and related equipment. Background Art
[0002] Enterprise digital transformation is accelerating, data center networks continue to expand, and performance requirements are rising accordingly. Faced with massive amounts of data, complex network structures, and demanding O&M challenges, traditional O&M methods such as manual inspections, recording, and analysis are no longer sufficient. Furthermore, the widespread adoption of new technologies such as virtualization, containers, and active-active geo-location has improved business convenience but also increased the complexity of network O&M. For example, after a business change, how can the changed business be verified? How can the verification results be used to assist in confirming whether the business change meets expectations and whether any issues have been introduced? Therefore, users urgently need efficient and intelligent network device management and maintenance solutions to address the O&M challenges brought about by increasingly complex IT technologies. Summary of the Invention
[0003] The present application provides an intent verification method, apparatus, and related equipment.
[0004] In a first aspect, the present application provides a method for verifying intent, the method comprising:
[0005] Collect the operating status data of each network device included in the managed network;
[0006] Classify and model the collected operating status data of each network device to obtain data models corresponding to each type of operating status data;
[0007] Determine, based on the data models corresponding to the various types of operating status data, a reachable path between a source device and a destination device included in the intention to be verified, wherein the intention to be verified includes the source device address and the destination device address, and the reachable path includes the network devices and links traversed;
[0008] Determine whether the reachable path meets user expectations.
[0009] Optionally, the running status data includes ARP table entries, routing table entries, Layer 2 forwarding table entries, VSI information, VXLAN tunnel information, L2VPN MAC table entries and interface information of each network device.
[0010] Optionally, the step of determining a reachable path between a source device and a destination device included in the intention to be verified according to a data model corresponding to the various types of operating status data includes:
[0011] According to the source device address and the destination device address, the data model and network topology corresponding to the various types of operation status data are queried to determine the reachable path between the source device and the destination device included in the intention to be verified.
[0012] Optionally, the step of querying data models and network topologies corresponding to the various types of operating status data according to the source device address and the destination device address, and determining a reachable path between the source device and the destination device included in the intention to be verified includes:
[0013] Querying a data model corresponding to an ARP table entry according to the source device address to determine a first network device that has learned the source device address;
[0014] querying a routing table of the first network device according to the destination device address, and if it is determined that the route corresponding to the destination device address is an indirect route, querying an ARP table of the first network device according to a first address corresponding to the destination device address in the routing table of the first network device to determine an interface corresponding to the first address;
[0015] If the interface corresponding to the first address is a tunnel interface, querying the routing table of the first network device according to the first address to determine the second address corresponding to the first address, querying the ARP table of the first network device according to the second address to determine the physical output interface corresponding to the second address, and determining the second device directly connected to the physical output interface based on the network topology information;
[0016] querying a routing table of the second device according to the first address to determine a third address corresponding to the first address, querying an ARP table of the second device according to the third address to determine a physical outbound interface corresponding to the third address, and determining a third device connected to the physical outbound interface based on the network topology information;
[0017] querying the routing table of the third device according to the destination device address, and if it is determined that the route corresponding to the destination device address is a direct route and it is determined that the ARP table of the third device has learned the destination device address, determining the third device as a network device connected to the destination device;
[0018] The first device, the second device, and the third device, as well as the link between the first device and the second device, and the link between the second device and the third device, are determined as reachable paths between the source device and the destination device included in the intended verification.
[0019] Optionally, the method further includes:
[0020] The reachable path between the source device and the destination device included in the intention to be verified is displayed on the panoramic operation and maintenance map.
[0021] In a second aspect, the present application provides an intention verification device, the device comprising:
[0022] A collection unit is used to collect the operating status data of each network device included in the managed network;
[0023] A modeling unit is used to classify and model the collected operating status data of each network device to obtain a data model corresponding to each type of operating status data;
[0024] a determining unit, configured to determine, based on a data model corresponding to each type of operating status data, a reachable path between a source device and a destination device included in the intention to be verified, wherein the intention to be verified includes an address of the source device and an address of the destination device, and the reachable path includes network devices and links traversed;
[0025] The judging unit is configured to judge whether the reachable path meets the user's expectation.
[0026] Optionally, the running status data includes ARP table entries, routing table entries, Layer 2 forwarding table entries, VSI information, VXLAN tunnel information, L2VPN MAC table entries and interface information of each network device.
[0027] Optionally, when determining, according to the data models corresponding to the various types of operating status data, a reachable path between a source device and a destination device included in the intention to be verified, the determining unit is specifically configured to:
[0028] According to the source device address and the destination device address, the data model and network topology corresponding to the various types of operation status data are queried to determine the reachable path between the source device and the destination device included in the intention to be verified.
[0029] Optionally, when querying the data model and network topology corresponding to the various types of operating status data based on the source device address and the destination device address, and determining a reachable path between the source device and the destination device included in the intention to be verified, the determining unit is specifically configured to:
[0030] Querying a data model corresponding to an ARP table entry according to the source device address to determine a first network device that has learned the source device address;
[0031] querying a routing table of the first network device according to the destination device address, and if it is determined that the route corresponding to the destination device address is an indirect route, querying an ARP table of the first network device according to a first address corresponding to the destination device address in the routing table of the first network device to determine an interface corresponding to the first address;
[0032] If the interface corresponding to the first address is a tunnel interface, querying the routing table of the first network device according to the first address to determine the second address corresponding to the first address, querying the ARP table of the first network device according to the second address to determine the physical output interface corresponding to the second address, and determining the second device directly connected to the physical output interface based on the network topology information;
[0033] querying a routing table of the second device according to the first address to determine a third address corresponding to the first address, querying an ARP table of the second device according to the third address to determine a physical outbound interface corresponding to the third address, and determining a third device connected to the physical outbound interface based on the network topology information;
[0034] querying the routing table of the third device according to the destination device address, and if it is determined that the route corresponding to the destination device address is a direct route and it is determined that the ARP table of the third device has learned the destination device address, determining the third device as a network device connected to the destination device;
[0035] The first device, the second device, and the third device, as well as the link between the first device and the second device, and the link between the second device and the third device, are determined as reachable paths between the source device and the destination device included in the intended verification.
[0036] Optionally, the device further comprises:
[0037] A display unit is used to display the reachable path between the source device and the destination device included in the intention to be verified on a panoramic operation and maintenance map.
[0038] In a third aspect, an embodiment of the present application provides an intention verification device, the intention verification device comprising:
[0039] a memory for storing program instructions;
[0040] The processor is configured to call the program instructions stored in the memory and execute the steps of the method as described in any one of the first aspects above according to the obtained program instructions.
[0041] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the above-mentioned first aspects.
[0042] In summary, the intention verification method provided in the embodiment of the present application collects the operating status data of each network device included in the managed network; classifies and models the collected operating status data of each network device to obtain data models corresponding to each type of operating status data; determines the reachable path between the source device and the destination device included in the intention to be verified based on the data models corresponding to the various types of operating status data, wherein the intention to be verified includes the source device address and the destination device address, and the reachable path includes the network devices and links passed through; and determines whether the reachable path meets user expectations.
[0043] The intention verification method provided by the embodiment of the present application can accurately simulate the network forwarding path and ensure that the user's business intention is correctly implemented by comparing it with the actual forwarding behavior of the network. This high degree of accuracy helps to avoid business interruption or performance degradation due to configuration errors or network failures. After deploying new services or changing the network, network problems that may affect the business can be quickly identified. This helps to perform network fault location analysis before the business discovers the problem, thereby avoiding possible business risks and losses. When a network failure occurs, the intention verification algorithm can help operation and maintenance personnel quickly locate the problem. By comparing the expected network behavior with the actual behavior, the scope of troubleshooting can be quickly narrowed and the efficiency of troubleshooting can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments of the present application or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings of the embodiments of the present application.
[0045] Figure 1 A detailed flowchart of an intent verification method provided in an embodiment of the present application;
[0046] Figure 2 A schematic diagram of the first intention verification process provided in an embodiment of the present application;
[0047] Figure 3a-3d A schematic diagram of the second intention verification process provided in an embodiment of the present application;
[0048] Figure 4a-4b A schematic diagram of the third intention verification process provided in an embodiment of the present application;
[0049] Figure 5a-5b A schematic diagram of the fourth intention verification process provided in an embodiment of the present application;
[0050] Figure 6A schematic diagram of the structure of an intention verification device provided in an embodiment of the present application;
[0051] Figure 7 A schematic diagram of the hardware architecture of an intent verification device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0052] The terms used in the embodiments of this application are only for the purpose of describing specific embodiments and are not intended to limit this application. The singular forms "a," "the," and "the" used in this application and claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more associated listed items.
[0053] It should be understood that although the terms first, second, third, etc. may be used to describe various information in the embodiments of the present application, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" used may also be interpreted as "at the time of" or "when" or "in response to determining".
[0054] For example, see Figure 1 FIG. 1 is a detailed flow chart of an intention verification method provided in an embodiment of the present application, and the method includes the following steps:
[0055] Step 100: Collect the operating status data of each network device included in the managed network.
[0056] In an embodiment of the present application, the operating status data includes ARP (Address Resolution Protocol) table entries, routing table entries, Layer 2 forwarding table entries, VSI (Virtual Switching Instance, virtual router) information, VXLAN (Virtual Extensible LAN, virtual extensible local area network) tunnel information, L2VPN MAC table entries and interface information of each network device.
[0057] Specifically, the analyzer can interact with the network devices included in the managed network through the Netconf protocol (or other protocols) to collect configuration files, ARP table entries, routing table entries, Layer 2 forwarding table entries, VSI information, VXLAN tunnel information, L2VPN MAC table entries and interface information of each network device (such as network devices, switches, routers, firewalls, and load balancing devices in the production environment).
[0058] Step 110: Classify and model the collected operating status data of each network device to obtain a data model corresponding to each type of operating status data.
[0059] Specifically, after the operation status data of the network device is collected, snapshots of various types of operation status data collected are stored in a database to establish data models corresponding to the various types of operation status data.
[0060] For example, based on the collected ARP table entries of each network device, a data model corresponding to the ARP table entry is constructed; based on the collected routing table entries of each network device, a data model corresponding to the routing table entry is constructed.
[0061] Step 120: Determine a reachable path between the source device and the destination device included in the intention to be verified based on the data model corresponding to the various types of operating status data.
[0062] The intention to be verified includes the source device address and the destination device address, and the reachable path includes the network devices and links along the way.
[0063] In the embodiment of the present application, when determining the reachable path between the source device and the destination device included in the intention to be verified based on the data model corresponding to the various types of operating status data, a preferred implementation method is:
[0064] According to the source device address and the destination device address, the data model and network topology corresponding to the various types of operation status data are queried to determine the reachable path between the source device and the destination device included in the intention to be verified.
[0065] Specifically, when querying the data model and network topology corresponding to the various types of operating status data based on the source device address and the destination device address, and determining the reachable path between the source device and the destination device included in the verification intention, a preferred implementation method is:
[0066] Querying a data model corresponding to an ARP table entry according to the source device address to determine a first network device that has learned the source device address;
[0067] querying a routing table of the first network device according to the destination device address, and if it is determined that the route corresponding to the destination device address is an indirect route, querying an ARP table of the first network device according to a first address corresponding to the destination device address in the routing table of the first network device to determine an interface corresponding to the first address;
[0068] If the interface corresponding to the first address is a tunnel interface, querying the routing table of the first network device according to the first address to determine the second address corresponding to the first address, querying the ARP table of the first network device according to the second address to determine the physical output interface corresponding to the second address, and determining the second device directly connected to the physical output interface based on the network topology information;
[0069] querying a routing table of the second device according to the first address to determine a third address corresponding to the first address, querying an ARP table of the second device according to the third address to determine a physical outbound interface corresponding to the third address, and determining a third device connected to the physical outbound interface based on the network topology information;
[0070] querying the routing table of the third device according to the destination device address, and if it is determined that the route corresponding to the destination device address is a direct route and it is determined that the ARP table of the third device has learned the destination device address, determining the third device as a network device connected to the destination device;
[0071] The first device, the second device, and the third device, as well as the link between the first device and the second device, and the link between the second device and the third device, are determined as reachable paths between the source device and the destination device included in the intended verification.
[0072] In actual applications, the starting device is searched based on the source IP address of the path detection. This address may be the IP address of a network device or the IP address of a terminal device connected to the network (in VXLAN networking, the host is not connected to the network). Therefore, when discovering the starting device, the IP address is first used to check whether the device exists on the device. If so, the device is the starting verification device. If it is not the IP address of a network device, the ARP on the device is scanned based on the IP address and the outgoing interface is not a VXLAN tunnel port (if the outgoing interface is a VXLAN tunnel port, it was learned from the remote VTEP and is not a real access device). If the address is found, the device is the starting device. Otherwise, the starting device is not found.
[0073] After finding the starting device, the next-hop device corresponding to the starting device can be determined based on the destination device address and the data model corresponding to various operating status data of the starting device (such as routing table, ARP table, etc.). Then, the corresponding next-hop device can be determined according to the data module corresponding to various operating status data of the next-hop device, until the next-hop device is determined to be a network device accessing the destination device according to the data model corresponding to various operating status data of the next-hop device.
[0074] In the embodiment of the present application, the above method may further include the following steps:
[0075] The reachable path between the source device and the destination device included in the intention to be verified is displayed on the panoramic operation and maintenance map.
[0076] Step 130: Determine whether the reachable path meets user expectations.
[0077] The following describes the intent verification process provided by the embodiment of the present application in detail in conjunction with specific application scenarios. Assuming the current user scenario, it is necessary to verify the path from source IP 200.1.1.100 to destination IP 200.1.1.9.
[0078] 1. For example, see Figure 2 As shown in the figure, the source IP address detected by the path is used to find the originating device. The current source IP address is 200.1.1.10. The ARP table entries of all devices in the network are searched based on the source IP address to determine the access device. Leaf 1 learns the ARP information for the source IP address. Therefore, traffic from VM 1 (200.1.1.100) is determined to pass through Leaf 1.
[0079] 2. For example, see Figure 3a-3d As shown in the figure, based on the destination IP address 200.1.1.9, the routing table of Leaf 1 is queried, and the next hop address corresponding to 200.1.1.9 is determined to be 2.2.2.2. Based on 2.2.2.2, the ARP table information on Leaf 1 is further queried, and the traffic is determined to pass through the VXLAN tunnel. Based on 2.2.2.2, the routing table of Leaf 1 is further queried, and the next hop address corresponding to 2.2.2.2 is determined to be 20.1.1.4. Based on 20.1.1.4, the ARP table information on Leaf 1 is queried, and the outgoing interface is determined to be WGE1 / 0 / 1. Finally, combined with the network topology information (such as LLDP information), it is determined that the device connected to the physical network cable of WGE1 / 0 / 1 is a spine, and the traffic of VM1200.1.1.100 is determined to pass through Leaf 1 and the spine.
[0080] 3. See Figure 4a-4b As shown in the figure, based on 2.2.2.2, the Spine routing table is queried and the next hop address corresponding to 2.2.2.2 is determined to be 111.1.1.2. Based on 111.1.1.2, the Spine ARP table entry information is queried and the outgoing interface is determined to be WGE1 / 0 / 1. Finally, combined with the network topology information, the device connected to the physical network cable of WGE1 / 0 / 1 is determined to be Leaf 2. The traffic of VM1200.1.1.100 is determined to pass through Leaf 1, Spine, and Leaf 2.
[0081] 4. See Figure 5a-5bAs shown, based on the destination IP address 200.1.1.9, Leaf 2's routing table is queried and the next hop corresponding to 200.1.1.9 is 200.1.1.1, which is a direct route. Leaf 2's ARP table entry is then queried for the destination IP address 200.1.1.9, confirming that Leaf 2 has learned the destination address 200.1.1.9 for VM2. Traffic from VM1 200.1.1.100 to VM2 200.1.1.9 passes through Leaf 1, the spine, and Leaf 2, completing the forwarding path verification.
[0082] For example, see Figure 6 FIG. 1 is a schematic diagram of a structure of an intention verification device provided in an embodiment of the present application, the device comprising:
[0083] The collection unit 60 is used to collect the operating status data of each network device included in the managed network;
[0084] The modeling unit 61 is used to classify and model the collected operating status data of each network device to obtain a data model corresponding to each type of operating status data;
[0085] a determining unit 62, which determines, based on the data models corresponding to the various types of operating status data, a reachable path between a source device and a destination device included in the intention to be verified, wherein the intention to be verified includes the source device address and the destination device address, and the reachable path includes the network devices and links traversed;
[0086] The judging unit 63 is configured to judge whether the reachable path meets the user's expectation.
[0087] Optionally, the running status data includes ARP table entries, routing table entries, Layer 2 forwarding table entries, VSI information, VXLAN tunnel information, L2VPN MAC table entries and interface information of each network device.
[0088] Optionally, when determining a reachable path between a source device and a destination device included in the intention to be verified according to the data model corresponding to the various types of operating status data, the determining unit 62 is specifically configured to:
[0089] According to the source device address and the destination device address, the data model and network topology corresponding to the various types of operation status data are queried to determine the reachable path between the source device and the destination device included in the intention to be verified.
[0090] Optionally, when querying the data model and network topology corresponding to the various types of operating status data based on the source device address and the destination device address, and determining a reachable path between the source device and the destination device included in the intention to be verified, the determining unit 62 is specifically configured to:
[0091] Querying a data model corresponding to an ARP table entry according to the source device address to determine a first network device that has learned the source device address;
[0092] querying a routing table of the first network device according to the destination device address, and if it is determined that the route corresponding to the destination device address is an indirect route, querying an ARP table of the first network device according to a first address corresponding to the destination device address in the routing table of the first network device to determine an interface corresponding to the first address;
[0093] If the interface corresponding to the first address is a tunnel interface, querying the routing table of the first network device according to the first address to determine the second address corresponding to the first address, querying the ARP table of the first network device according to the second address to determine the physical output interface corresponding to the second address, and determining the second device directly connected to the physical output interface based on the network topology information;
[0094] querying a routing table of the second device according to the first address to determine a third address corresponding to the first address, querying an ARP table of the second device according to the third address to determine a physical outbound interface corresponding to the third address, and determining a third device connected to the physical outbound interface based on the network topology information;
[0095] querying the routing table of the third device according to the destination device address, and if it is determined that the route corresponding to the destination device address is a direct route and it is determined that the ARP table of the third device has learned the destination device address, determining the third device as a network device connected to the destination device;
[0096] The first device, the second device, and the third device, as well as the link between the first device and the second device, and the link between the second device and the third device, are determined as reachable paths between the source device and the destination device included in the intended verification.
[0097] Optionally, the device further comprises:
[0098] A display unit is used to display the reachable path between the source device and the destination device included in the intention to be verified on a panoramic operation and maintenance map.
[0099] The above units may be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs). For another example, when a unit is implemented by scheduling program code through a processing element, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0100] Furthermore, the intention verification device provided in the embodiment of the present application, from the hardware level, the hardware architecture diagram of the intention verification device can be found in Figure 7 As shown, the intention verification device may include: a memory 70 and a processor 71,
[0101] The memory 70 is used to store program instructions. The processor 71 calls the program instructions stored in the memory 70 and executes the above method embodiment according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.
[0102] Optionally, the present application also provides an intent verification device, comprising at least one processing element (or chip) for executing the above method embodiment.
[0103] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above method embodiments.
[0104] Here, the machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as CD, DVD, etc.), or similar storage media, or a combination thereof.
[0105] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or any combination of these devices.
[0106] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0107] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0108] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0109] Furthermore, these computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0111] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A method for verifying intent, characterized in that: The method comprises: Collect the operating status data of each network device included in the managed network; Classify and model the collected operating status data of each network device to obtain data models corresponding to each type of operating status data; Determine, based on the data models corresponding to the various types of operating status data, a reachable path between a source device and a destination device included in the intention to be verified, wherein the intention to be verified includes the source device address and the destination device address, and the reachable path includes the network devices and links traversed; Determine whether the reachable path meets user expectations.
2. The method according to claim 1, wherein The running status data includes ARP table entries, routing table entries, Layer 2 forwarding table entries, VSI information, VXLAN tunnel information, L2VPN MAC table entries and interface information of each network device.
3. The method according to claim 2, wherein The step of determining a reachable path between a source device and a destination device included in the intention to be verified according to the data model corresponding to the various types of operating status data includes: According to the source device address and the destination device address, the data model and network topology corresponding to the various types of operation status data are queried to determine the reachable path between the source device and the destination device included in the intention to be verified.
4. The method according to claim 3, wherein The steps of querying the data model and network topology corresponding to the various types of operation status data according to the source device address and the destination device address, and determining a reachable path between the source device and the destination device included in the intention to be verified include: Querying a data model corresponding to an ARP table entry according to the source device address to determine a first network device that has learned the source device address; querying a routing table of the first network device according to the destination device address, and if it is determined that the route corresponding to the destination device address is an indirect route, querying an ARP table of the first network device according to a first address corresponding to the destination device address in the routing table of the first network device to determine an interface corresponding to the first address; If the interface corresponding to the first address is a tunnel interface, querying the routing table of the first network device according to the first address to determine the second address corresponding to the first address, querying the ARP table of the first network device according to the second address to determine the physical output interface corresponding to the second address, and determining the second device directly connected to the physical output interface based on the network topology information; querying a routing table of the second device according to the first address to determine a third address corresponding to the first address, querying an ARP table of the second device according to the third address to determine a physical outbound interface corresponding to the third address, and determining a third device connected to the physical outbound interface based on the network topology information; querying the routing table of the third device according to the destination device address, and if it is determined that the route corresponding to the destination device address is a direct route and it is determined that the ARP table of the third device has learned the destination device address, determining the third device as a network device connected to the destination device; The first device, the second device, and the third device, as well as the link between the first device and the second device, and the link between the second device and the third device, are determined as reachable paths between the source device and the destination device included in the intended verification.
5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: The reachable path between the source device and the destination device included in the intention to be verified is displayed on the panoramic operation and maintenance map.
6. An intention verification device, characterized in that: The device comprises: A collection unit is used to collect the operating status data of each network device included in the managed network; A modeling unit is used to classify and model the collected operating status data of each network device to obtain a data model corresponding to each type of operating status data; a determining unit, configured to determine, based on a data model corresponding to each type of operating status data, a reachable path between a source device and a destination device included in the intention to be verified, wherein the intention to be verified includes an address of the source device and an address of the destination device, and the reachable path includes network devices and links traversed; The judging unit is configured to judge whether the reachable path meets the user's expectation.
7. The device according to claim 6, characterized in that The running status data includes ARP table entries, routing table entries, Layer 2 forwarding table entries, VSI information, VXLAN tunnel information, L2VPN MAC table entries and interface information of each network device.
8. The device according to claim 7, wherein When querying the data model and network topology corresponding to the various types of operating status data based on the source device address and the destination device address, and determining a reachable path between the source device and the destination device included in the intention to be verified, the determining unit is specifically configured to: Querying a data model corresponding to an ARP table entry according to the source device address to determine a first network device that has learned the source device address; querying a routing table of the first network device according to the destination device address, and if it is determined that the route corresponding to the destination device address is an indirect route, querying an ARP table of the first network device according to a first address corresponding to the destination device address in the routing table of the first network device to determine an interface corresponding to the first address; If the interface corresponding to the first address is a tunnel interface, querying the routing table of the first network device according to the first address to determine the second address corresponding to the first address, querying the ARP table of the first network device according to the second address to determine the physical output interface corresponding to the second address, and determining the second device directly connected to the physical output interface based on the network topology information; querying a routing table of the second device according to the first address to determine a third address corresponding to the first address, querying an ARP table of the second device according to the third address to determine a physical outbound interface corresponding to the third address, and determining a third device connected to the physical outbound interface based on the network topology information; querying the routing table of the third device according to the destination device address, and if it is determined that the route corresponding to the destination device address is a direct route and it is determined that the ARP table of the third device has learned the destination device address, determining the third device as a network device connected to the destination device; The first device, the second device, and the third device, as well as the link between the first device and the second device, and the link between the second device and the third device, are determined as reachable paths between the source device and the destination device included in the intended verification.
9. An intention verification device, characterized in that: The intention verification device includes: a memory for storing program instructions; The processor is configured to call the program instructions stored in the memory, and execute the steps of the method according to any one of claims 1 to 5 according to the obtained program instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method according to any one of claims 1 to 5.