Public network traffic forwarding method and device for cloud computing system, equipment and medium
By deploying virtual switches and virtualized gateways in the cloud computing system, allowing only the first packet to be processed through the gateway node to generate a high-speed forwarding table, the problem of high latency in public network traffic forwarding in the cloud computing network is solved, and efficient public network traffic forwarding is achieved.
Patent Information
- Application Number
- CN202511429493.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-09
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-10-09
Smart Images

Figure CN120956691A_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to the field of cloud computing technology, and in particular to a method, apparatus, device and medium for forwarding public network traffic in a cloud computing system. Background Technology
[0002] With the rapid development of network, virtualization and storage technologies, cloud computing technology has become one of the most popular network technologies. Major Internet companies and enterprises can build cloud computing networks based on cloud computing technology. A cloud computing network includes different host machines communicating within the same availability zone and auxiliary forwarding middleware. Each host machine has virtual machines deployed on it.
[0003] When the auxiliary forwarding middleware is a virtual gateway, virtual machine A forwards all public network traffic through its host machine to the virtual gateway, and then uses the virtual gateway to forward it to the host machine where virtual machine B is located. When the auxiliary forwarding middleware includes a virtual gateway and a smart switch, the virtual gateway and the smart switch are used to complete the forwarding of all public network traffic.
[0004] Since the forwarding of all public network traffic in the existing cloud computing network relies on the virtual gateway, the virtual gateway suffers from high load pressure and high latency in forwarding public network traffic. Summary of the Invention
[0005] In view of the above-mentioned defects or deficiencies in the existing technology, it is desirable to provide a method, apparatus, device and medium for public network traffic forwarding in cloud computing systems. This method enables only the first public network traffic packet within the cloud computing network to be forwarded and processed by the gateway node to generate a high-speed forwarding table. For all subsequent public network traffic packets that are not the first packet, the gateway node does not need to participate. Instead, the generated high-speed forwarding table and the host information table are used to directly forward public network traffic between hosts. This solves the technical problems of high load on the existing gateway node and high latency in public network traffic forwarding, significantly improves the forwarding efficiency of public network traffic within the cloud computing network, and also significantly reduces the loss and load pressure on the gateway node.
[0006] In a first aspect, this application provides a method for forwarding public network traffic in a cloud computing system. The cloud computing system includes a first host machine, a second host machine, and multiple cloud computing gateways communicating within the same availability zone. A first virtual switch and a first virtual machine are deployed on the first host machine, and a virtualization gateway is deployed on each of the cloud computing gateways. The method includes: When the first virtual switch determines that the first public network traffic packet sent by the first virtual machine is not the first packet and that the source IP and the peer public network IP of the first public network traffic packet are on different host machines, it determines the second MAC address corresponding to the management IP of the second host machine based on the host machine information table, the first high-speed forwarding table, and the peer public network IP of the first public network traffic packet. Then, it adds a header to the first public network traffic packet based on the second MAC address and the MAC address of the public network IP of the second virtual machine and forwards it to the second host machine. The second virtual machine is deployed on the second host machine. When the first virtual switch determines that the first public network traffic packet is the first packet, it selects the first virtual gateway that is currently running normally from among the multiple virtualization gateways, forwards the first packet through the first virtualization gateway, and generates the first high-speed forwarding table. The first high-speed forwarding table includes the correspondence between the public IP address accessed by the first virtual machine, the MAC address of the virtual machine's public IP address, and the management IP address of the host machine where the virtual machine is located. The host machine information table includes the correspondence between the host machine management IP address and the MAC address.
[0007] In conjunction with the first aspect, in one possible implementation, where a security policy script is deployed on the first virtual switch, the method further includes: The first virtual switch uses the security policy script to perform security verification on the received first public network traffic packet, and determines whether the first public network traffic packet that passes the security verification is the first packet.
[0008] In conjunction with the first aspect, in one possible implementation, forwarding the first packet through the first virtualization gateway includes: The first virtual switch adds a header to the first packet based on the MAC address of the first virtualization gateway, and forwards the resulting target packet to the first virtualization gateway; The first virtualization gateway parses the first packet from the target packet and forwards the first packet to the Internet if the public IP of the second virtual machine does not belong to the public IP of the cloud computing system. When the public IP address of the second virtual machine belongs to a public IP address within the cloud computing system, the first virtualization gateway adds a header to the first packet and forwards it to the second virtual machine based on the public network card MAC address of the second virtual machine and the management IP address of the second host machine obtained from the public IP information table. The public IP information table includes the public network card MAC address of the virtual machine to which each public IP address belongs in the cloud computing system and the management IP address of the host machine to which each public IP address belongs.
[0009] In conjunction with the first aspect, in one possible implementation, the method further includes: While the first virtualization gateway forwards packets to the second virtual machine, it also sends a high-speed forwarding table update command to the first virtual switch. The first virtual switch responds to the high-speed forwarding table update command by querying whether the first high-speed forwarding table exists; If the first high-speed forwarding table already exists, the first virtual switch updates the active time of the first high-speed forwarding table; If the first high-speed forwarding table does not exist, the first virtual switch creates the first high-speed forwarding table.
[0010] In conjunction with the first aspect, in one possible implementation, updating the active time of the first high-speed forwarding table includes: If the first time difference between the latest active time corresponding to the first high-speed forwarding table and the current time of the first host machine is less than a preset time threshold, the latest active time is modified to the current time.
[0011] In conjunction with the first aspect, in one possible implementation, the method further includes: The first virtual machine sends an ARP request message to the first virtual switch, the ARP request message being used to request the MAC address of the second virtual machine; The first virtual switch performs security verification on the ARP request packet, adds corresponding UDP header information to the ARP request packet that passes the security verification, and sends the obtained UDP request packet to the second virtualization gateway; the second virtualization gateway is a virtualization gateway that is running normally among the multiple virtualization gateways; The second virtualization gateway parses the ARP request message from the UDP request message, replies to the ARP request message, adds the corresponding UDP header information, obtains a UDP response message, and forwards it to the first host machine. The first virtual switch in the first host machine parses the ARP reply message from the UDP reply message and forwards the ARP reply message to the first virtual machine; The first virtual machine generates an ARP cache table based on the received ARP response message. The ARP cache table is used to store the mapping relationship between IP and MAC addresses. The ARP cache table includes the correspondence between the public IP of the first virtual machine in the same subnet and the default MAC address of the virtualization gateway, as well as the correspondence between the default gateway generated in different subnets and the default MAC address of the virtualization gateway.
[0012] In conjunction with the first aspect, in one possible implementation, the method further includes: In the case where the cloud computing system includes multiple hosts, including the first host and the second host, each host periodically broadcasts its current host address information to multiple virtualization gateways. The current host address information includes the management IP of the current host and the MAC address corresponding to the management IP. Each virtualization gateway summarizes and statistically analyzes all received current host machine address information to obtain the host machine information table.
[0013] Secondly, the present invention also provides a public network traffic forwarding device for a cloud computing system, the cloud computing system including a first host, a second host, and multiple cloud computing gateways communicating within the same availability zone, wherein a first virtual switch and a first virtual machine are deployed on the first host, and a virtualization gateway is deployed on each of the cloud computing gateways; the device includes: The first forwarding unit is configured to, when the first virtual switch determines that the first public network traffic packet sent by the first virtual machine is not the first packet and the source IP and the peer public network IP of the first public network traffic packet are on different host machines, determine the second MAC address corresponding to the management IP of the second host machine based on the host machine information table, the first high-speed forwarding table and the peer public network IP of the first public network traffic packet, and add a packet header to the first public network traffic packet based on the second MAC address and the MAC address of the public network IP of the second virtual machine before forwarding it to the second host machine; the second virtual machine is deployed on the second host machine; The second forwarding unit is used to determine the first virtual gateway that is currently running normally from among the multiple virtualization gateways when the first virtual switch determines that the first public network traffic packet is the first packet, and forward the first packet through the first virtualization gateway and generate the first high-speed forwarding table. The first high-speed forwarding table includes the correspondence between the public IP address accessed by the first virtual machine, the MAC address of the virtual machine's public IP address, and the management IP address of the host machine where the virtual machine is located. The host machine information table includes the correspondence between the host machine management IP address and the MAC address.
[0014] Thirdly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the public network traffic forwarding method for a cloud computing system as described in the first aspect.
[0015] Fourthly, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the public network traffic forwarding method for a cloud computing system as described in the first aspect.
[0016] This invention provides a method, apparatus, device, and medium for forwarding public network traffic in a cloud computing system. The method involves deploying virtual switches and virtual machines on the host machine and a virtualized gateway on the cloud computing gateway to build the cloud computing system. This allows only the first public network traffic packet within the cloud computing network to be forwarded by the gateway node, generating a high-speed forwarding table. Subsequent public network traffic packets (excluding the first packet) do not require gateway node involvement; the generated high-speed forwarding table and host machine information table are used directly for forwarding public network traffic between host machines. This solves the technical problems of high gateway node load and high latency in public network traffic forwarding, significantly improving the forwarding efficiency of public network traffic within the cloud computing network while also significantly reducing gateway node losses and load pressure. Attached Figure Description
[0017] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 This is one of the flowcharts illustrating a public network traffic forwarding method for a cloud computing system in one embodiment; Figure 2 This is a second flowchart illustrating a public network traffic forwarding method for a cloud computing system in one embodiment. Figure 3 This is the third flowchart of a public network traffic forwarding method for a cloud computing system in one embodiment; Figure 4 This is the fourth flowchart of a public network traffic forwarding method for a cloud computing system in one embodiment; Figure 5 This is the fifth flowchart illustrating a public network traffic forwarding method for a cloud computing system in one embodiment; Figure 6 This is a diagram showing the forwarding sequence of public network traffic within a cloud computing environment in one embodiment. Figure 7 This is a diagram illustrating the steps of forwarding public network traffic within a cloud computing environment in one embodiment. Figure 8 This is one of the diagrams showing the changes in the public network packet structure within a cloud computing environment in one embodiment; Figure 9 This is the second diagram showing the change in the public network packet structure within a cloud computing implementation; Figure 10 This is the third diagram illustrating the changes in the public network packet structure within a cloud computing implementation. Figure 11 This is a structural block diagram of a public network traffic forwarding device for a cloud computing system in one embodiment. Figure 12 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0018] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.
[0019] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The present application will now be described in detail with reference to the accompanying drawings and embodiments. Furthermore, the term "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The terms "first" and "second," etc., in the specification and claims of the embodiments of this application are used to distinguish different objects, not to describe a specific order of objects.
[0020] First, the relevant terms involved in this invention will be explained: Availability zone: refers to a physical area within the same region where power and network are independent of each other.
[0021] Host machine: A container that runs cloud instances, including but not limited to kernel-based virtual machines (kvm), xen, hyper-V, etc.; hyper-V is an open-source virtualization technology used to create and run virtual machines; xen is an open-source virtualization solution used to allow computer hardware to support multiple operating systems simultaneously.
[0022] Virtual machine: A complete computer system with full hardware system functionality.
[0023] Cloud computing gateway: A software method for establishing communication channels over Internet Protocol (IP) based networks. It is located between multiple breakpoints behind the same or different Network Address Translation (NAT) or firewalls, and can enable communication between the availability zone network and the Internet according to the forwarding rules on the gateway cluster.
[0024] Virtual switch: In the cloud computing field, a device that provides Ethernet packet forwarding for virtual machines or other types of virtual devices, and runs on the host machine.
[0025] Access Control List (ACL) rules are a set of conditions used to define how network devices filter and control data packets, allowing or blocking the transmission of specific traffic through permit or deny actions.
[0026] Media Access Control (MAC) address: also called physical address or hardware address, is burned into the flash memory chip of the Network Interface Card (NIC) by the network equipment manufacturer during production, and is a unique network identifier for each device in the network.
[0027] Public network traffic refers to traffic on the Internet that is accessible through public networks and is available to all users. Public network traffic is widely present on various public platforms and channels, such as search engines, social media, and e-commerce platforms. These platforms have a large user base and extensive dissemination channels, which can bring a large amount of traffic to websites or applications.
[0028] Private network traffic refers to traffic within a private network, typically used within an enterprise or by a specific user group. Private network traffic is transmitted through a private network, is not publicly accessible, and is limited to authorized users. Private network traffic is primarily used to improve the security of data transmission and control access permissions.
[0029] Public IP address: An address assigned by an Internet Service Provider (ISP) that uniquely identifies a device on the Internet. Every device connected to the Internet needs a public IP address so that other devices can find and communicate with it. Public IP addresses are globally unique and can be directly accessed by other devices on the Internet.
[0030] Management IP: Also known as a private IP, it is typically used within a local area network (LAN), such as a home network or corporate intranet. Management IP addresses are unique within the internal network but cannot be directly accessed from the internet. Common private IP address ranges include 10.0.0.0 / 8, 172.16.0.0 / 12, and 192.168.0.0 / 16.
[0031] With the rapid development of networking, virtualization, and storage technologies, cloud computing has become one of the most popular network technologies. It can be said that with the arrival of the cloud computing era, major internet companies and enterprises have established their own data centers to support and develop their businesses. Network data in cloud computing data centers is generally divided into two categories: one is east-west traffic that does not access the external network, usually referring to private networks, which is not billed; the other is north-south network traffic that accesses both internal and external networks, usually referring to public networks, which is billed.
[0032] With the continuous development of cloud computing, there are increasingly more north-south traffic patterns in cloud data centers. These can be categorized into two types: one is public network traffic accessed within the cloud computing system and not leaving the system; the other is public network traffic accessed from outside the cloud computing system and interacting with the external internet. Generally, under the same configuration, east-west network performance is better than north-south network performance. Furthermore, when both north-south traffic needs to be processed through gateway nodes, these nodes can easily reach performance bottlenecks, impacting the overall network performance and business operations of the cloud computing system, making it difficult to meet the data transmission requirements. Therefore, achieving fast forwarding of public network traffic within the cloud computing system is particularly important.
[0033] To achieve rapid forwarding of public network traffic within a cloud computing system, existing technologies employ the following two solutions; Method 1: Virtual machine A forwards all public network traffic through host machine A to the gateway, where the gateway verifies the security policies (such as security groups, ACLs, etc.) and then forwards it to host machine B where virtual machine B is located.
[0034] Option 2: By cooperating with gateway nodes and smart switches, traffic from each computing node is distributed and processed. The smart switch is responsible for the interaction of network data between computing nodes and is a physical device. It contains multiple virtual routers that distribute traffic from different network segments to different virtual bridges and can determine the type of traffic. For north-south public network traffic, the smart switch and gateway node functions are required to process it. That is, the smart switch hands the traffic packets over to the gateway node for processing and then forwards them to the other end.
[0035] Combining the two solutions mentioned above, it can be understood that cloud computing networks include different hosts communicating within the same availability zone, as well as auxiliary forwarding middleware (such as gateway nodes, or gateway nodes and smart switches). Each host has a virtual machine deployed on it, and the forwarding of all public network traffic depends on the virtual gateway, resulting in high load pressure on the virtual gateway and high latency in forwarding public network traffic.
[0036] To address the aforementioned technical problems, this application provides a method, apparatus, device, and medium for forwarding public network traffic in a cloud computing system. This method processes public network traffic that does not leave the cloud computing environment in a manner similar to that of east-west traffic, thereby overcoming the technical problems of high gateway node load and high latency in public network traffic forwarding.
[0037] The following is combined with Figures 1 to 12 This application describes a public network traffic forwarding method, apparatus, device, and medium for a cloud computing system. The public network traffic forwarding method for a cloud computing system is applied to a cloud computing system, which includes a first host machine, a second host machine, and multiple cloud computing gateways that communicate within the same availability zone. A first virtual switch and a first virtual machine are deployed on the first host machine, and a virtualization gateway is deployed on each cloud computing gateway.
[0038] To facilitate understanding of the public network traffic forwarding method for cloud computing systems provided in the embodiments of the present invention, the following will describe in detail the method through several exemplary embodiments. It is understood that these exemplary embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0039] refer to Figure 1 This is one of the flowcharts illustrating a public network traffic forwarding method for a cloud computing system provided in an embodiment of the present invention, such as... Figure 1 As shown, the public network traffic forwarding method for cloud computing systems includes the following steps 101 and 102.
[0040] Step 101: When the first virtual switch determines that the first public network traffic packet sent by the first virtual machine is not the first packet and that the source IP and the peer public network IP of the first public network traffic packet are on different host machines, the first virtual switch determines the second MAC address corresponding to the management IP of the second host machine according to the host machine information table, the first high-speed forwarding table and the peer public network IP of the first public network traffic packet. Then, it adds a packet header to the first public network traffic packet according to the second MAC address and the MAC address of the public network IP of the second virtual machine and forwards it to the second host machine. The second virtual machine is deployed on the second host machine.
[0041] The first high-speed forwarding table includes the correspondence between the public IP address accessed by the first virtual machine, the MAC address of the virtual machine's public IP address, and the management IP address of the host machine where the virtual machine resides. The host machine information table includes the correspondence between the host machine management IP address and the MAC address.
[0042] It should be noted that the cloud computing system provided in this embodiment of the invention supports multiple cloud computing gateways and multiple hosts. Each cloud computing gateway is a gateway node, and each host is a host node. Each gateway node and each host node are deployed on a physical server. All nodes can be deployed on the same physical server or on separate physical servers. If all nodes are deployed separately, the physical servers can be reached from each other through a Layer 2 network.
[0043] The virtualization gateway deployed in each cloud computing gateway can manage communication between virtualization resources in the corresponding gateway node and provide public network access services for the cloud computing system.
[0044] Each virtual switch is deployed on a corresponding host machine for network isolation and traffic management; it can be used for at least traffic management forwarding and high-speed forwarding table maintenance.
[0045] Each virtualization gateway and each virtual switch has a separate data forwarding module and a data receiving module. The data forwarding module is a software module used to receive network data from the cloud computing state, and the data receiving module is a software module used to parse and encapsulate network data packets and send the packets to the cloud computing network.
[0046] All virtualization gateways share the same default MAC address, which is not the actual physical network interface card (NIC) MAC address.
[0047] Specifically, in step 101, the first host and the second host can be different hosts among multiple hosts contained in the cloud computing system. For the first host, when its first virtual machine has the function of packet assembly and forwarding, its first virtual switch will receive the first public network traffic packet sent by the first virtual machine and determine whether the first public network traffic packet is the first packet. When it is determined that the first public network traffic packet is not the first packet, the management IP of the peer host can be determined from the maintained first high-speed forwarding table based on the peer public network IP of the first public network traffic packet, that is, the second management IP of the second host can be determined. At this time, the destination MAC address in the first public network traffic packet can be converted from the default MAC address of the virtualization gateway to the second MAC address of the public network IP of the second virtual machine recorded in the first high-speed forwarding table, and the management IP of the second virtual machine on the second host can be obtained from the first high-speed forwarding table.
[0048] Then, based on the management IP of the second host machine, the MAC address corresponding to the management IP of the peer host machine is looked up from the maintained host information table. That is, the second MAC address corresponding to the management IP of the second host machine is determined. In this way, a User Datagram Protocol (UDP) outer header can be added to the first public network traffic packet based on the second MAC address, and the inner header of the first public network traffic packet can be modified based on the MAC address of the public IP of the second virtual machine. For example, the destination MAC address in the first public network traffic packet can be modified to the MAC address of the public IP of the second virtual machine before forwarding it to the second host machine.
[0049] It should be noted that the first high-speed forwarding table is used to record information related to other public IP addresses within the cloud computing network that the first virtual machine in the first host machine has accessed from the public network. This information is used to achieve fast forwarding of public network traffic and has an aging mechanism. Specifically, the first high-speed forwarding table maintains information related to the public IP addresses that have been accessed, including the public IP address, MAC address, virtual network interface ID (internal identifier of the network interface), virtual network interface type, availability zone, and the management IP address of the host machine.
[0050] It should also be noted that not only can one virtual machine be deployed on the same host, but multiple virtual machines can also be deployed. When multiple virtual machines are deployed on the same host, the virtual switch within the host can directly forward non-first packets through the channel between the host and the virtual machines without adding an outer UDP header.
[0051] For example, if a first virtual machine and a second virtual machine are deployed on the first host machine at the same time, and the first public network traffic packet is not the first packet, then the peer public network IP and the source public network IP of the first public network traffic packet are in the same first host machine. The first virtual switch determines by querying the first high-speed forwarding table that the virtual machine where the peer IP is located is also on the first host machine. Then it will directly forward the first public network traffic packet to the peer virtual machine through the channel between the first host machine and the peer virtual machine, without adding an outer UDP header.
[0052] Step 102: When the first public network traffic packet is determined to be the first packet, the first virtual switch determines the currently operating first virtual gateway from among multiple virtualized gateways, forwards the first packet through the first virtualized gateway, and generates the first high-speed forwarding table.
[0053] Specifically, when the first virtual machine deployed on the first host machine determines that the first public network traffic packet is the first packet, it can use the currently running first virtualization gateway to forward the first packet.
[0054] It should be noted that for each host machine in the cloud computing system, after its virtualization process starts, it continuously and periodically sends heartbeat detection messages, ping packets, or UDP packets to each gateway node. The virtualized gateway deployed on the gateway node replies to the received messages and forwards the reply messages to the corresponding host machine. Each host machine's virtual switch continuously receives the reply messages and records whether the corresponding virtualized gateway is operating normally, generating and storing a gateway operation status table. Therefore, when the first virtual switch determines that the first public network traffic packet is the first packet, it can determine the first virtualized gateway that is currently operating normally from the stored gateway operation status table, so as to use the first virtualized gateway to complete the forwarding operation of the first packet and generate the first high-speed forwarding table.
[0055] The public network traffic forwarding method for cloud computing systems provided in this invention builds a cloud computing system by deploying virtual switches and virtual machines on the host machine and a virtualized gateway on the cloud computing gateway. This enables only the first public network traffic packet within the cloud computing network to be forwarded by the gateway node and generate a high-speed forwarding table. Subsequent public network traffic packets (excluding the first packet) do not require the gateway node's involvement; the generated high-speed forwarding table and the host machine information table are used to directly forward public network traffic between host machines. This solves the technical problems of high load on existing gateway nodes and high latency in public network traffic forwarding, significantly improving the forwarding efficiency of public network traffic within the cloud computing network, while also significantly reducing the loss and load pressure on gateway nodes.
[0056] It is understandable that, considering that existing technologies typically rely on security policies deployed on gateway nodes to verify the security of public network traffic packets sent by source virtual machines, this cannot guarantee the network security of the virtualization gateway. Therefore, in this embodiment of the invention, the security policy can be deployed on the virtual switch of the host machine to ensure high network security regardless of whether public network traffic packets pass through the virtualization gateway. Based on this, in one example embodiment, the public network traffic forwarding method for cloud computing systems provided by this invention may further include a virtual switch security verification process, the specific process of which can be implemented through the following steps.
[0057] When a security policy script is deployed on the first virtual switch, the first virtual switch uses the security policy script to perform security verification on the first public network traffic packet received, and determines whether the first public network traffic packet that passes the security verification is the first packet.
[0058] Specifically, when the first virtual switch receives the first public network traffic packet sent from the first virtual machine, it can first use a security policy script to perform security verification on the first public network traffic packet. After the first public network traffic packet passes the security verification, it can then further determine whether it is the first packet.
[0059] It should be noted that the deployed security policy script can be a script with firewall functionality, or it can be a password policy script, access control policy script, backup and recovery policy script, vulnerability management policy script, etc. This invention does not impose specific limitations on it.
[0060] Furthermore, it should be noted that determining whether the first public network traffic packet is the first packet can be based on the existence of a matching high-speed forwarding table. If a first high-speed forwarding table exists, the first public network traffic packet is considered a non-first packet; otherwise, it is considered the first packet.
[0061] Based on the above Figure 1 In one example embodiment of the method shown, step 102 involves forwarding the first packet through a first virtualization gateway. The specific process of this step can be described in this embodiment through… Figure 2 Steps 201 to 203 shown are implemented.
[0062] Step 201: The first virtual switch adds a header to the first packet based on the MAC address of the first virtualization gateway, and forwards the resulting target packet to the first virtualization gateway.
[0063] Step 202: The first virtualization gateway parses the first packet from the target packet and forwards the first packet to the Internet if the public IP of the second virtual machine does not belong to the public IP of the cloud computing system.
[0064] Step 203: If the public IP address of the second virtual machine belongs to the public IP address within the cloud computing system, the first virtualization gateway adds a header to the first packet and forwards it to the second virtual machine based on the public network card MAC address of the second virtual machine and the management IP address of the second host machine obtained from the public IP information table. The public IP information table includes the public network card MAC address of the virtual machine to which each public IP address belongs in the cloud computing system and the management IP address of the host machine to which each public IP address belongs.
[0065] Specifically, when the first virtual machine and the second virtual machine communicate over the public network, the first packet generated by the first virtual machine will be sent to the first virtual switch. The source IP in the first packet is the public IP of the first virtual machine, the destination IP is the public IP of the second virtual machine, the source MAC address is the MAC address of the public network card of the first virtual machine, and the destination MAC address is the MAC address of the first virtualization gateway. The MAC address of the first virtualization gateway is the same default MAC address shared by all virtualization gateways.
[0066] Upon receiving a security-verified first packet, the first virtual switch first checks whether a first high-speed forwarding table exists. That is, based on the peer's public IP address in the first packet, it determines whether the first virtual switch maintains a first high-speed forwarding table. If the first high-speed forwarding table does not exist, it determines that the first packet is an ARP request packet based on the packet type, obtains the private network management IP address of the first virtualization gateway, assembles an outer UDP header, and forwards it to the first cloud computing gateway, where it is received by the data receiving module of the first virtualization gateway.
[0067] The ARP request message is encapsulated with a UDP Layer 3 header, including an outer UDP header (transport layer), an outer IP header (network layer), and an outer Ethernet header (network interface layer). The source port of the UDP header is a random, unused port, and the destination port is the fixed receiving port of the data receiving module of the first virtualization gateway. The source IP of the outer IP header is the management IP of the first host machine, and the destination IP is the management IP of the first cloud computing gateway. The source MAC address of the outer Ethernet header does not need to be configured, and the destination MAC address is the MAC address of the management IP of the first cloud computing gateway. This yields a public network unicast target message, specifically a UDP request message. It should be noted that the fact that the source MAC address of the outer Ethernet header does not need to be configured does not mean that the source MAC address does not exist; rather, once created, its format does not need to be modified, and the default characters can be used.
[0068] The first virtualization gateway receives and parses the UDP request message from the first host machine to obtain its internal ARP request message (i.e., the first message). Based on the public IP information table it maintains, the first virtualization gateway determines whether the public IP of the second virtual machine belongs to the public IP of the cloud computing system.
[0069] If the public IP address of the second virtual machine is not a public IP address within the cloud computing system (i.e., it is an external public IP address), then the first virtualization gateway modifies the source MAC address of the first packet to the MAC address of the Internet card of the first cloud computing gateway and the uplink physical switch, and the destination address to the port MAC address of the uplink physical switch. The packet is then forwarded to the uplink physical switch of the cloud computing gateway via Layer 2 forwarding, and then forwarded to the Internet by the physical switch.
[0070] Conversely, if the public IP address of the second virtual machine belongs to the public IP address within the cloud computing system (i.e., it is a public IP address within the cloud computing system), then based on the public network card MAC address of the second virtual machine obtained from the public IP information table and the management IP address of the second host machine, the inner packet header is modified, the outer UDP header is assembled, and then it is forwarded to the data receiving module of the second virtual switch in the second host machine. When the data receiving module of the second virtual switch receives the packet, it removes the outer UDP header. The second virtual switch performs security verification on the first packet without the outer UDP header and injects the first packet that passes the security verification into the second virtual machine through the channel between the second host machine and the second virtual machine.
[0071] It should be noted that the public network traffic packets sent by the first virtual machine are usually unicast interaction packets. When this unicast interaction packet reaches the second virtual machine, the second virtual machine replies to the unicast interaction packet and receives an acknowledgment packet. If the second virtual machine does not have an ARP cache table for this interaction packet, the second virtual machine obtains the MAC address of the first virtual machine's public IP address by sending an ARP request to the first virtual machine, and finally obtains the MAC address of the first virtualization gateway, which is also the default MAC address of the virtualization gateway. An ARP cache table is then generated. This ARP cache table includes the correspondence between the public IP address of the first virtual machine obtained within the same subnet and the default MAC address of the virtualization gateway, as well as the correspondence between the default gateway generated in different subnets and the default MAC address of the virtualization gateway. The default gateway is the IP address used for interaction between different subnet segments.
[0072] The second virtual machine sends a response message to the first virtual machine, with the source IP being the public IP of the second virtual machine and the destination IP being the public IP of the first virtual machine, destined for the second virtual switch. If the second virtual switch has not generated a second high-speed forwarding table, it encapsulates the response message with a UDP outer header and forwards it to the first virtualization gateway. The data forwarding module on the first virtualization gateway obtains the MAC address of the first virtual machine's public network card from the public IP information table, uses it as the destination MAC header of the inner message, uses the virtualization gateway's default MAC address as the source MAC header of the inner message, and encapsulates the response message with the corresponding UDP outer header using the management IP of the first host machine obtained from the public IP information table, before sending it to the first virtual switch. At the same time, the first virtualization gateway notifies the second virtual switch to generate a second high-speed forwarding table. The second high-speed forwarding table includes the correspondence between the public IP addresses accessed by the second virtual machine, the MAC address of the virtual machine's public IP address, and the management IP of the host machine where the virtual machine resides.
[0073] When the first virtual switch receives the response message, it performs security verification on the response message and then injects it into the first virtual machine through the channel between the first host machine and the first virtual machine.
[0074] Based on the above Figure 2 In one example embodiment of the method shown, the first virtualization gateway in step 203 can instruct the first virtual switch to update the high-speed forwarding table while forwarding the first packet. Based on this, in one example embodiment, the public network traffic forwarding method for cloud computing systems provided by this invention can further include a high-speed forwarding table update process. The specific process in this embodiment can be described through… Figure 3 Steps 301 to 304 shown are implemented.
[0075] Step 301: While forwarding packets to the second virtual machine, the first virtualization gateway sends a high-speed forwarding table update command to the first virtual switch.
[0076] Step 302: The first virtual switch responds to the high-speed forwarding table update command and checks whether the first high-speed forwarding table exists; Step 303: If a first high-speed forwarding table already exists, the first virtual switch updates the active time of the first high-speed forwarding table.
[0077] Step 304: If the first high-speed forwarding table does not exist, the first virtual switch creates the first high-speed forwarding table.
[0078] Specifically, when the first virtual switch receives a high-speed forwarding table update instruction from the first virtualization gateway, it can use the public IP address as an identifier to query whether the first high-speed forwarding table exists. If the first high-speed forwarding table already exists, its active time is refreshed; otherwise, if the first high-speed forwarding table does not exist, it can be created during the process of forwarding the first packet to the second virtual machine using the first virtualization gateway.
[0079] It should be noted that after the second virtual machine on the other end replies to the received first message, the response message it generates can be used to check if a second high-speed forwarding table exists. If a second high-speed forwarding table exists, it can be forwarded to the first virtual machine without going through the gateway node, using the second high-speed forwarding table and the host information table. Conversely, if a second high-speed forwarding table does not exist, it can be created during the process of sending the response message from the first virtualization gateway to the first virtual machine.
[0080] In this way, when the first virtual machine continues to transmit public network traffic packets to the second virtual machine, the first virtual switch obtains the public network IP of the peer of the public network traffic packet. After discovering that there is information about the first high-speed forwarding table, it converts the destination MAC address in the packet from the default MAC address of the virtualization gateway to the MAC address of the public network IP of the second virtual machine according to the information in the first high-speed forwarding table. It also obtains the management IP of the second host machine where the second virtual machine is located from the first high-speed forwarding table, obtains the MAC address of the corresponding IP of the second host machine through the host machine information table, encapsulates the UDP outer header, and forwards it directly to the second host machine.
[0081] After receiving the packet, the data receiving module of the second virtual switch in the second host machine performs security verification and forwards it to the second virtual machine. Similarly, the forwarding operation of the message transmitted from the second virtual machine to the first virtual machine is also completed based on the second high-speed forwarding table maintained on the second virtual switch.
[0082] It should be noted that if the first and second high-speed forwarding tables determine that the first virtual machine and the second virtual machine are on the same host, then the packets of the first virtual machine will be directly injected back to the public network card of the second virtual machine through the first virtual switch.
[0083] Based on the above Figure 1 In one example embodiment of the method shown, in step 303, the first virtual switch updates the active time of the first high-speed forwarding table. The specific process can be implemented through the following steps in this embodiment.
[0084] If the first time difference between the latest active time corresponding to the first high-speed forwarding table and the current time of the first host machine is less than a preset time threshold, the latest active time will be modified to the current time.
[0085] The preset time threshold can be a pre-set fixed threshold.
[0086] Specifically, a separate task determines whether the time difference between the latest active time of the high-speed forwarding table and the current time of the host machine is greater than a fixed threshold. If it is less than the fixed threshold, no operation is performed; if it is greater than or equal to the fixed threshold, the corresponding high-speed forwarding table is directly deleted. Furthermore, the first virtual switch can record the hit time of each packet forwarding operation using the first high-speed forwarding table. Each hit indicates that the first high-speed forwarding table has been active once, and each hit time is the corresponding active time. Thus, when the first virtual switch responds to a high-speed forwarding table update command, it can be assumed that the first high-speed forwarding table has been hit this time. At this point, only the latest active time needs to be updated, that is, the latest active time corresponding to the first high-speed forwarding table is modified to the current time; this completes the purpose of updating the active time of the first high-speed forwarding table.
[0087] It is understandable that, considering that the source host needs to obtain the MAC address of the peer host before communicating with it within the same availability zone, the process of obtaining the peer host's MAC address can be performed before step 101. In this embodiment, the specific process can be achieved through... Figure 4 Steps 401 to 405 shown are implemented.
[0088] Step 401: The first virtual machine sends an ARP request message to the first virtual switch. The ARP request message is used to request the MAC address of the second virtual machine.
[0089] Step 402: The first virtual switch performs security verification on the ARP request packets, adds the corresponding UDP header information to the ARP request packets that pass the security verification, and sends the obtained UDP request packets to the second virtualization gateway; the second virtualization gateway is a virtualization gateway that is running normally among multiple virtualization gateways.
[0090] Step 403: The second virtualization gateway parses the ARP request message from the UDP request message, replies to the ARP request message, adds the corresponding UDP header information, obtains the UDP response message, and forwards it to the first host machine.
[0091] Step 404: The first virtual switch in the first host machine parses the ARP reply message from the UDP reply message and forwards the ARP reply message to the first virtual machine.
[0092] Step 405: The first virtual machine generates an ARP cache table based on the received ARP response message. The ARP cache table is used to store the mapping relationship between IP and MAC addresses. The ARP cache table includes the correspondence between the public IP of the first virtual machine in the same subnet and the default MAC address of the virtualization gateway, as well as the correspondence between the default gateway and the default MAC address of the virtualization gateway generated in different subnets.
[0093] It should be noted that the first virtualization gateway and the second virtualization gateway can be the same or different.
[0094] Specifically, for the ARP request message sent by the first virtual machine, if the public IP address of the second virtual machine and the public IP address of the first virtual machine are in the same subnet, then the destination IP address of the ARP request message is the public IP address of the second virtual machine; otherwise, if the public IP address of the second virtual machine and the public IP address of the first virtual machine are not in the same subnet, then the destination IP address of the ARP request message is the default gateway IP address.
[0095] The first virtual switch performs security verification on the ARP request packets received from the first virtual machine. For ARP request packets that pass security verification, it obtains the private network management IP of the second virtualization gateway. Using the private network management IP of the second virtualization gateway, it assembles the outer UDP header information. That is, it additionally encapsulates a three-layer UDP header outside the ARP request packet, including an outer UDP header (transport layer), an outer IP header (network layer), and an outer Ethernet header (network interface layer). The source port of the UDP header is a random unused port, and the destination port is the fixed receiving port of the data receiving module of the second virtualization gateway. The source IP of the outer IP header is the management IP of the first host machine, and the destination IP is the management IP of the first cloud computing gateway. The source MAC address of the outer Ethernet header does not need to be configured, and the destination MAC address is the MAC address of the management IP of the second cloud computing gateway obtained by querying the host machine information table. In this way, the UDP request packet is obtained and forwarded to the second virtualization gateway, where it is received by the data receiving module of the second virtualization gateway.
[0096] The second virtualization gateway receives a UDP request packet from the first host machine. After unpacking, it obtains the inner data packet, i.e., the ARP request packet. When it determines that the ARP request packet is an ARP request packet, it uses the ARP request packet as a basis to assemble an ARP response packet to reply to it. That is, it sets the source MAC address of the ARP request packet to the destination MAC address of the ARP response packet, sets the gateway's default MAC address to the source MAC address of the ARP response packet, sets the source IP address of the ARP request packet to the destination IP address, sets the destination IP address of the ARP request packet to the source IP address, changes the type of the ARP packet from a request packet to a response packet, and assembles the outer UDP header to obtain the UDP response packet before forwarding it to the first host machine where the first virtual machine is located.
[0097] For example, the source port of the UDP response message is a random unused port, the destination port is the fixed receiving port of the data receiving module of the first virtual switch, the destination MAC address is queried from the host information table, and the MAC address corresponding to the management IP of the first virtual machine is obtained according to the management IP of the first host machine, which is used as the peer MAC address. The management IP of the cloud computing gateway where the second virtualization gateway is located is used as the source IP, and the management IP of the first virtual machine is used as the destination IP, and the message is forwarded to the first host machine where the first virtual machine is located.
[0098] The first virtual machine receives a UDP response message from the second virtualization gateway, obtains the inner ARP response message, and forwards the ARP response message to the corresponding first virtual machine according to the destination IP of the ARP response message.
[0099] The first virtual machine generates an ARP cache table based on the received ARP reply packets, which is the mapping relationship between IP addresses and MAC addresses. The IP address is the source IP of the ARP reply packet (different mapping relationships are generated depending on whether they are on the same subnet), and the MAC address is the default MAC address of the virtualization gateway.
[0100] In one example embodiment, the public network traffic forwarding method for a cloud computing system provided by the present invention may further include an information table creation process, the specific process of which can be described in the present invention through... Figure 5 Steps 501 and 502 shown are implemented.
[0101] Step 501: In the case of a cloud computing system including multiple hosts, including a first host and a second host, each host periodically broadcasts its current host address information to multiple virtualization gateways. The current host address information includes the management IP of the current host and the MAC address corresponding to the management IP.
[0102] Step 502: Each virtualization gateway summarizes and statistically analyzes all received current host machine address information to obtain a host machine information table.
[0103] It should be noted that a cloud computing system may include multiple hosts, including a first host and a second host. The host information table can exist on both the virtualization gateway and the virtual machine switch. After each host starts the virtualization process, it will periodically broadcast the current host information to the virtualization gateway. Each current host information includes information such as the management IP of the current host and the MAC address corresponding to the management IP. After the virtualization gateway summarizes and statistically analyzes all the current host information received, it generates a host information table and sends it to the host, which is then stored on the virtual switch of the host.
[0104] For example, refer to Figure 6 The diagram showing the public network traffic forwarding sequence within the cloud computing infrastructure and... Figure 7 The diagram showing the steps for forwarding public network traffic within a cloud computing application is as follows: Figure 6 and Figure 7 In this diagram, host A is the first host, virtual machine A is the first virtual machine, virtual switch A is the first virtual switch, and the high-speed forwarding table in virtual switch A is the first high-speed forwarding table. Host B is the second host, virtual machine B is the second virtual machine, and virtual switch B is the second virtual switch. Figure 6 The virtualization gateway in the system can be either a first virtualization gateway or a second virtualization gateway. Figure 7 The specific processes involved can be referred to in the aforementioned embodiments. They will not be repeated here.
[0105] Reference Figure 8One of the diagrams showing the changes in the public network packet structure within cloud computing. Figure 9 The diagram showing the changes in the public network packet structure within the cloud computing infrastructure is shown in Part Two. Figure 10 The third diagram showing the changes in the public network packet structure within cloud computing is shown. Figures 8-10 Based on specific public network traffic packet examples Figure 7 The steps for forwarding public network traffic within the cloud computing infrastructure are explained in detail.
[0106] It should be noted that although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart can be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0107] In one embodiment, this application also provides a public network traffic forwarding device for a cloud computing system, wherein the cloud computing system includes a first host, a second host, and multiple cloud computing gateways communicating within the same availability zone. A first virtual switch and a first virtual machine are deployed on the first host, and a virtualized gateway is deployed on each cloud computing gateway. Figure 11 The diagram shows the structure of the public network traffic forwarding device 1100 for cloud computing systems. The device includes a first forwarding unit 1101 and a second forwarding unit 1102.
[0108] The first forwarding unit 1101 is used by the first virtual switch to determine the second MAC address corresponding to the management IP of the second host machine when it determines that the first public network traffic packet sent by the first virtual machine is not the first packet and the source IP and the peer public network IP of the first public network traffic packet are on different host machines. Based on the host machine information table, the first high-speed forwarding table and the peer public network IP of the first public network traffic packet, the first virtual switch adds a packet header to the first public network traffic packet based on the second MAC address and the MAC address of the public network IP of the second virtual machine and forwards it to the second host machine. The second virtual machine is deployed on the second host machine.
[0109] The second forwarding unit 1102 is used by the first virtual switch to determine the first virtual gateway that is currently running normally from multiple virtualized gateways when it determines that the first public network traffic packet is the first packet, and to forward the first packet through the first virtualized gateway and generate a first high-speed forwarding table.
[0110] The first high-speed forwarding table includes the correspondence between the public IP address accessed by the first virtual machine, the MAC address of the virtual machine's public IP address, and the management IP address of the host machine where the virtual machine resides. The host machine information table includes the correspondence between the host machine management IP address and the MAC address.
[0111] In one embodiment, the apparatus provided by the present invention further includes a security verification unit, which, when a security policy script is deployed on the first virtual switch, uses the security policy script to perform security verification on the received first public network traffic packet and determines whether the first public network traffic packet that passes the security verification is the first packet.
[0112] In one embodiment, the second forwarding unit 1102 is specifically configured to: 1. Add a header to the first packet based on the MAC address of the first virtualization gateway, and forward the resulting target packet to the first virtualization gateway; 2. Parse the first packet from the target packet, and if the public IP address of the second virtual machine does not belong to the public IP address within the cloud computing system, forward the first packet to the Internet; 3. If the public IP address of the second virtual machine belongs to the public IP address within the cloud computing system, the first virtualization gateway adds a header to the first packet based on the public network card MAC address of the second virtual machine obtained from the public IP information table and the management IP address of the second host machine, and then forwards it to the second virtual machine; the public IP information table includes the public network card MAC addresses of the virtual machines to which all public IP addresses in the cloud computing system belong, and the management IP addresses of their respective host machines.
[0113] In one embodiment, the second forwarding unit 1102 is specifically used to send a high-speed forwarding table update instruction to the first virtual switch while the first virtualization gateway forwards packets to the second virtual machine; the first virtual switch responds to the high-speed forwarding table update instruction and queries whether a first high-speed forwarding table exists; if a first high-speed forwarding table already exists, the first virtual switch updates the active time of the first high-speed forwarding table; if a first high-speed forwarding table does not exist, the first virtual switch creates a first high-speed forwarding table.
[0114] In one embodiment, the second forwarding unit 1102 is specifically used to modify the latest active time to the current time when the first time difference between the latest active time corresponding to the first high-speed forwarding table and the current time of the first host is less than a preset time threshold.
[0115] In one embodiment, the apparatus provided by this invention further includes a packet forwarding unit, configured to send an ARP request message to a first virtual machine via a first virtual switch, the ARP request message being used to request the MAC address of a second virtual machine; the first virtual switch performs a security check on the ARP request message, adds corresponding UDP header information to the ARP request message that passes the security check, and sends the obtained UDP request message to a second virtualization gateway; the second virtualization gateway is a normally functioning virtualization gateway among multiple virtualization gateways; the second virtualization gateway parses the ARP request message from the UDP request message and performs further processing on the ARP request message. After replying, the corresponding UDP header information is added, and the UDP response message is forwarded to the first host machine. The first virtual switch in the first host machine parses the ARP response message from the UDP response message and forwards the ARP response message to the first virtual machine. The first virtual machine generates an ARP cache table based on the received ARP response message. The ARP cache table is used to store the mapping relationship between IP and MAC addresses. The ARP cache table includes the correspondence between the public IP of the first virtual machine in the same subnet and the default MAC address of the virtualization gateway, as well as the correspondence between the default gateway generated in different subnets and the default MAC address of the virtualization gateway.
[0116] In one embodiment, the apparatus provided by the present invention further includes an information table creation unit, used to periodically broadcast current host machine address information to multiple virtualization gateways when the cloud computing system includes multiple host machines including a first host machine and a second host machine. The current host machine address information includes the management IP of the current corresponding host machine and the MAC address corresponding to the management IP. Each virtualization gateway summarizes and statistically analyzes all the received current host machine address information to obtain a host machine information table.
[0117] It should be understood that the units described in the public network traffic forwarding device used in cloud computing systems are related to the reference... Figure 1 The steps in the described method correspond accordingly. Therefore, the operations and features described above for the method are also applicable to a public network traffic forwarding device for a cloud computing system and the units contained therein, and will not be repeated here. The public network traffic forwarding device for a cloud computing system can be pre-implemented in the browser or other security applications of a computer device, or it can be loaded into the browser or its security applications of a computer device through download or other means. The corresponding units in the public network traffic forwarding device for a cloud computing system can cooperate with the units in the computer device to implement the solutions of the embodiments of this application.
[0118] The following is for reference. Figure 12 It shows a schematic diagram of the structure of a computer system 1200 suitable for implementing computer devices or servers in the embodiments of this application.
[0119] like Figure 12 As shown, the computer system 1200 includes a central processing unit (CPU) 1201, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 1202 or a program loaded from storage section 1208 into random access memory (RAM) 1203. The RAM 1203 also stores various programs and data required for the operation of the computer system 1200. The CPU 1201, ROM 1202, and RAM 1203 are interconnected via a bus 1204. An input / output (I / O) interface 1205 is also connected to the bus 1204.
[0120] The following components are connected to the input / output (I / O) interface 1205: an input section 1206 including a keyboard, mouse, etc.; an output section 1207 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1208 including a hard disk, etc.; and a communication section 1209 including a network interface card such as a LAN card, modem, etc. The communication section 1209 performs communication processing via a network such as the Internet. A drive 1210 is also connected to the input / output (I / O) interface 1205 as needed. A removable medium 1211, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1210 as needed so that computer programs read from it can be installed into the storage section 1208 as needed.
[0121] Specifically, according to embodiments of this application, the above references Figure 1 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program tangibly embodied on a machine-readable medium, the computer program containing instructions for performing... Figure 1 The program code for the method. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1209, and / or installed from the removable medium 1211.
[0122] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0124] The units or modules described in the embodiments of this application can be implemented in software or hardware. The described units or modules can also be located in a processor. The names of these units or modules do not, in certain circumstances, constitute a limitation on the unit or module itself.
[0125] On the other hand, this application also provides a computer-readable storage medium, which may be included in the computer device described in the above embodiments, or may exist independently and not assembled into the computer device. The aforementioned computer-readable storage medium stores one or more programs that, when used by one or more processors, execute the methods described in this application. For example, it may execute... Figure 1 The steps of the method shown.
[0126] This application provides a computer program product including instructions that, when executed, cause the method described in this application to be performed. For example, it can execute... Figure 1 The steps of the method shown.
[0127] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0128] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.
Claims
1. A method for forwarding public network traffic in a cloud computing system, characterized in that, The cloud computing system includes a first host, a second host, and multiple cloud computing gateways that communicate within the same availability zone. A first virtual switch and a first virtual machine are deployed on the first host, and a virtualization gateway is deployed on each of the cloud computing gateways. The method includes: When the first virtual switch determines that the first public network traffic packet sent by the first virtual machine is not the first packet and that the source IP and the peer public network IP of the first public network traffic packet are on different host machines, it determines the second MAC address corresponding to the management IP of the second host machine according to the host machine information table, the first high-speed forwarding table and the peer public network IP, and adds a packet header to the first public network traffic packet according to the second MAC address and the MAC address of the second virtual machine's public network IP before forwarding it to the second host machine; the second virtual machine is deployed on the second host machine; When the first virtual switch determines that the first public network traffic packet is the first packet, it selects the first virtual gateway that is currently running normally from among the multiple virtualization gateways, forwards the first packet through the first virtualization gateway, and generates the first high-speed forwarding table. The first high-speed forwarding table includes the correspondence between the public IP address accessed by the first virtual machine, the MAC address of the virtual machine's public IP address, and the management IP address of the host machine where the virtual machine is located. The host machine information table includes the correspondence between the host machine management IP address and the MAC address.
2. The method according to claim 1, characterized in that, When a security policy script is deployed on the first virtual switch, the method further includes: The first virtual switch uses the security policy script to perform security verification on the received first public network traffic packet, and determines whether the first public network traffic packet that passes the security verification is the first packet.
3. The method according to claim 1, characterized in that, The forwarding of the first packet through the first virtualization gateway includes: The first virtual switch adds a header to the first packet based on the MAC address of the first virtualization gateway, and forwards the resulting target packet to the first virtualization gateway; The first virtualization gateway parses the first packet from the target packet and forwards the first packet to the Internet if the public IP of the second virtual machine does not belong to the public IP of the cloud computing system. When the public IP address of the second virtual machine belongs to a public IP address within the cloud computing system, the first virtualization gateway adds a header to the first packet and forwards it to the second virtual machine based on the public network card MAC address of the second virtual machine and the management IP address of the second host machine obtained from the public IP information table. The public IP information table includes the public network card MAC address of the virtual machine to which each public IP address belongs in the cloud computing system and the management IP address of the host machine to which each public IP address belongs.
4. The method according to claim 3, characterized in that, The method further includes: While the first virtualization gateway forwards packets to the second virtual machine, it also sends a high-speed forwarding table update command to the first virtual switch. The first virtual switch responds to the high-speed forwarding table update command by querying whether the first high-speed forwarding table exists; If the first high-speed forwarding table already exists, the first virtual switch updates the active time of the first high-speed forwarding table; If the first high-speed forwarding table does not exist, the first virtual switch creates the first high-speed forwarding table.
5. The method according to claim 4, characterized in that, The step of updating the active time of the first high-speed forwarding table includes: If the first time difference between the latest active time corresponding to the first high-speed forwarding table and the current time of the first host machine is less than a preset time threshold, the latest active time is modified to the current time.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: The first virtual machine sends an ARP request message to the first virtual switch, the ARP request message being used to request the MAC address of the second virtual machine; The first virtual switch performs security verification on the ARP request packet, adds corresponding UDP header information to the ARP request packet that passes the security verification, and sends the obtained UDP request packet to the second virtualization gateway; the second virtualization gateway is a virtualization gateway that is running normally among the multiple virtualization gateways; The second virtualization gateway parses the ARP request message from the UDP request message, replies to the ARP request message, adds the corresponding UDP header information, obtains a UDP response message, and forwards it to the first host machine. The first virtual switch in the first host machine parses the ARP reply message from the UDP reply message and forwards the ARP reply message to the first virtual machine; The first virtual machine generates an ARP cache table based on the received ARP response message. The ARP cache table is used to store the mapping relationship between IP and MAC addresses. The ARP cache table includes the correspondence between the public IP of the first virtual machine in the same subnet and the default MAC address of the virtualization gateway, as well as the correspondence between the default gateway generated in different subnets and the default MAC address of the virtualization gateway.
7. The method according to any one of claims 1 to 5, characterized in that, The method further includes: In the case where the cloud computing system includes multiple hosts, including the first host and the second host, each host periodically broadcasts its current host address information to multiple virtualization gateways. The current host address information includes the management IP of the current host and the MAC address corresponding to the management IP. Each virtualization gateway summarizes and statistically analyzes all received current host machine address information to obtain the host machine information table.
8. A public network traffic forwarding device for a cloud computing system, characterized in that, The cloud computing system includes a first host, a second host, and multiple cloud computing gateways that communicate within the same availability zone. A first virtual switch and a first virtual machine are deployed on the first host, and a virtualization gateway is deployed on each of the cloud computing gateways. The device includes: The first forwarding unit is configured to, when the first virtual switch determines that the first public network traffic packet sent by the first virtual machine is not the first packet and the source IP and the peer public network IP of the first public network traffic packet are on different host machines, determine the second MAC address corresponding to the management IP of the second host machine according to the host machine information table, the first high-speed forwarding table and the peer public network IP, and add a packet header to the first public network traffic packet according to the second MAC address and the MAC address of the second virtual machine's public network IP before forwarding it to the second host machine; the second virtual machine is deployed on the second host machine; The second forwarding unit is used to determine the first virtual gateway that is currently running normally from among the multiple virtualization gateways when the first virtual switch determines that the first public network traffic packet is the first packet, and forward the first packet through the first virtualization gateway and generate the first high-speed forwarding table. The first high-speed forwarding table includes the correspondence between the public IP address accessed by the first virtual machine, the MAC address of the virtual machine's public IP address, and the management IP address of the host machine where the virtual machine is located. The host machine information table includes the correspondence between the host machine management IP address and the MAC address.
9. A computer device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the public network traffic forwarding method for a cloud computing system as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the public network traffic forwarding method for a cloud computing system as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Cloud computing network configuration method, cloud computing network system and a storage medium
CN112398687A
Flow table hardware unloading method, equipment and medium
CN115150328A
Private network interconnection method and device, equipment and storage medium
CN117459491A
Data processing method and device and electronic equipment
CN118714070A
Cloud computing gateway, cloud computing hypervisor, and methods for implementing same
US20100027552A1
Cited By
Data processing method, device and medium of four-layer load balancing system
CN122395203A