A multi-path VPN fusion automatic monitoring and regulation method
By constructing a serialized abstract graph and generating data alarms through communication detection and routing configuration schemes for VPN information data, the problem of difficulty in identifying anomalies and adjusting routes in multi-VPN access scenarios is solved. This enables adaptive adjustment and anomaly response of VPN tunnels, improving the reliability and efficiency of VPN converged processing.
Patent Information
- Application Number
- CN202511960416.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-24
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-12-24
AI Technical Summary
In scenarios with multiple VPN accesses, it is difficult to determine the specific status of a VPN based on its overall operational status, making it difficult to address single points of risk and implement systematic deployment. Furthermore, access control requires verification of network performance, multi-tunnel collaboration efficiency, abnormal situation response, and resource allocation.
By performing communication detection on the received VPN information data, extracting user needs, constructing routing configuration schemes, forming a serialized abstract graph of multiple VPN tunnels and optimization targets, generating data alarms, clustering alarm types to identify anomalies and adjust routing strategies, and achieving adaptive adjustment of VPN tunnels.
It improves the reliability and responsiveness of VPN converged processing, enhances the efficiency of alarm tracing in abnormal situations, dynamically adjusts routing policies to cope with changes in VPN access scenarios, and ensures that network resources elastically serve business needs.
Smart Images

Figure CN121396850B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information transmission, in particular to a multi-path VPN fusion automatic monitoring and regulation method. BACKGROUND
[0002] With the development of information technology, office scenarios are gradually diversified, and VPN needs to be configured according to the running environment of different customers; however, multiple accessed VPNs are independent of each other, and it is difficult to determine the specific situation of different VPNs in the access customer running environment according to the overall running state, resulting in single point risk and difficulty in forming systematic deployment processing.
[0003] For example, Chinese patent publication No. CN116389194A discloses a VPN service generation method, system, device and medium based on a cloud computing platform. The method obtains a VPN service request sent by a cloud user through an API interface by a VPN interface component of a VPN service generation system integrated in the cloud computing platform, and then creates a corresponding VPN instance through a VPN execution module component of the VPN service generation system in response to the VPN service request. The user specified target open source VPN software is run through the VPN instance to provide VPN service for the cloud user, so that the cloud user accesses the target tenant network, and the secure connection between each cloud user and each tenant network is realized.
[0004] For example, Chinese patent publication No. CN119743483A discloses a method for high availability deployment of federal peer-to-peer clusters in edge environment, relating to the technical field of edge clusters. The federal peer-to-peer cluster includes multiple edge clusters. The method comprises: deploying a federal peer-to-peer control plane component and a federal peer-to-peer data plane component in each edge cluster, and each federal peer-to-peer control plane component is in a peer-to-peer relationship. When network peer-to-peer connection is established between any two edge clusters, if authentication is successful, the federal peer-to-peer control plane components of the two edge clusters create virtual nodes of the opposite cluster in their respective clusters through their respective federal peer-to-peer data plane components, realizing resource mapping and management of the opposite cluster.
[0005] In the prior art, VPN services are constructed in the form of tenants, and the transmission of data is managed through the two-way communication of edge clusters under resource mapping management. However, when VPN access control is performed, in addition to checking the network performance of VPN, multi-tunnel coordination efficiency, abnormal situation response and resource allocation under multi-VPN tunnel are also needed to determine the processing mode of the current VPN access scenario. SUMMARY
[0006] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is: a multi-path VPN fusion automatic monitoring and control method, including: S1, performing communication detection on the received VPN information data to determine the VPN information data under different communication abnormal states.
[0007] S2 extracts user requirements under abnormal communication conditions, and based on the triggering conditions corresponding to the user requirements, retrieves multiple VPN tunnels from VPN information data to construct a routing configuration scheme corresponding to the user requirements.
[0008] S3 responds to traffic forwarding based on routing configuration schemes, and determines the optimization goals based on user needs through multi-route distribution.
[0009] S4. Based on the routing configuration scheme corresponding to each optimization target, the optimization targets obtained within a certain time period are associated with the corresponding VPN tunnels to form a serialized abstract graph between multiple VPN tunnels and optimization targets. Based on the minimum deployment cost of the serialized abstract graph within a certain time period, the response order of the optimization targets is determined, and data alarms are generated for the optimization targets according to the response order.
[0010] S5, based on the alarm type of the data alarm, performs path clustering of the data alarm according to the serialization abstract graph, and determines the target VPN tunnel under fusion monitoring based on the alarm type transmitted along each path.
[0011] The beneficial effects of this invention are as follows: First, this invention constructs routing policies by extracting metadata such as VPN tunnel type, service scenario, and performance indicators like latency, packet loss rate, and bandwidth utilization; it dynamically prioritizes routing ports based on abnormal state frequencies and synchronously corrects routing configurations; it marks abnormal ports for latency / packet loss rate, triggering routing policy adjustments. This determines the VPN fluctuation status of the current access customer environment and identifies whether there are cases of slow abnormal location and false data reports.
[0012] Second, this invention maps user needs to database instances to trigger VPN tunnel peering; it verifies abnormal tunnel status through an automatic detection mechanism and dynamically activates backup tunnels; it reconfigures routes based on trigger conditions to generate a routing configuration scheme. This determines the specific configuration of the current scheme under implementation, enabling adaptive adjustments to the scheme. Then, by aggregating performance metrics after traffic forwarding, it generates optimization targets, performs isolation, remapping, and route reconstruction on unavailable tunnels, and determines route adjustments under changes in VPN access scenarios or their own anomalies, making the VPN convergence processing method more reliable.
[0013] Thirdly, the application takes the optimization target and VPN tunnel as the vertex, the average value of the index as the edge weight, constructs a serialized abstract graph, calculates the deployment cost based on the delay, service label and the like, generates a response sequence; triggers an alarm through the confidence interval and the sorting change threshold, monitors multiple VPN tunnels in real time, clusters the obtained alarm types, further focuses on the reaction efficiency and the dynamic switching mode of the VPN under the VPN fusion, and improves the alarm tracing efficiency and the service effect under the abnormal situation. BRIEF DESCRIPTION OF DRAWINGS
[0014] The application will be further described below in combination with the drawings and embodiments.
[0015] Figure 1 It is a flowchart of a multi-path VPN fusion automatic monitoring and regulation method.
[0016] Figure 2 It is a flowchart of step S1 of a multi-path VPN fusion automatic monitoring and regulation method.
[0017] Figure 3 It is a flowchart of step S2 of a multi-path VPN fusion automatic monitoring and regulation method.
[0018] Figure 4 It is a flowchart of step S3 of a multi-path VPN fusion automatic monitoring and regulation method.
[0019] Figure 5 It is a flowchart of step S4 of a multi-path VPN fusion automatic monitoring and regulation method.
[0020] Figure 6 It is a flowchart of step S5 of a multi-path VPN fusion automatic monitoring and regulation method. DETAILED DESCRIPTION
[0021] The embodiments of the application will be described in detail below. The embodiments described below are exemplary and are only used to explain the application, and cannot be understood as a limitation of the application. If the specific technology or condition is not indicated in the embodiments, the technology or condition described in the literature in the art or according to the product instruction is used.
[0022] Reference Figure 1 A multi-path VPN fusion automatic monitoring and regulation method, comprising: S1, performing communication detection on the received VPN information data, and determining the VPN information data under different communication abnormal states.
[0023] S2, extracting the user demand under the communication abnormal state, and based on the trigger condition corresponding to the user demand, calling multiple VPN tunnels from the VPN information data, and constructing a routing configuration scheme corresponding to the user demand.
[0024] S3, in response to the traffic forwarding of the routing configuration scheme, determining the optimization target under the user demand in the form of multi-routing distribution.
[0025] S4, based on the routing configuration scheme corresponding to each optimization target, associating the optimization target obtained within a certain time period with the corresponding VPN tunnel to form a serialized abstract graph between the multi-VPN tunnel and the optimization target; based on the minimum deployment cost of the serialized abstract graph within a certain time period, determining the response order of the optimization target, and generating data alarms for the optimization target according to the response order.
[0026] S5, according to the alarm type of the data alarm, clustering the data alarm according to the serialized abstract graph, and determining the target VPN tunnel under the fusion monitoring according to the alarm type transmitted by each path.
[0027] The received VPN information data is represented as a structured data packet containing source / destination VPN instance identification, tunnel type (such as IPSec / MPLS / SRv6 / openvpn, etc.), protocol parameters (encryption algorithm, key), routing policy, QoS configuration and APN6 application identification. These data will indicate the information data involved in the control and management of the current VPN, such as subnet IP, virtual private cloud information, routing table configuration, database IP and port, VPN gateway, etc. These information data will be based on the logs marked with abnormal conditions in the historical data, and by checking the abnormal information existing in these data logs, these abnormalities will be taken as the content of subsequent processing.
[0028] The collected data includes data in abnormal states such as connection failure, performance degradation, security anomaly, etc. The performance indicators corresponding to these data are taken as the main monitoring targets under the current multi-VPN fusion.
[0029] It should be noted that the current collected data is obtained based on the business scenario where the VPN tunnel has been established and is working, and is mainly used to identify abnormal problems in the scenario of fusion control of multiple VPN tunnels in the scene of accessing multiple different VPN configurations of customers, and to analyze these problems according to the traffic properties of the transmission data to obtain a relative VPN tunnel control mode.
[0030] The extracted performance indicators include time delay, packet loss rate, bandwidth utilization, time of established connection, traffic statistics in the tunnel, and system recorded log information of routing configuration, etc.
[0031] According to the collection of these data, the output and input under the VPN fusion are detected for abnormalities and root cause analysis is performed to confirm the abnormal position and abnormal reason of the database when processing the multi-path VPN fusion, and the abnormal data is synchronized to the user processing process to adjust the multi-environment running scene of the multi-path VPN establishment. For example, the scene configured by each VPN is used for service management of a customer, and the needs of multiple users in different scenes are met through multi-path abnormal detection and fusion monitoring.
[0032] When performing VPN fusion monitoring, the following steps can be used to illustrate the process.
[0033] Step 1: A new cloud networking instance is created, and a source VPC (virtual private cloud) and a target VPC are associated.
[0034] Step 2: Adjust the routing table, enable cloud networking routing, and disable peer-to-peer connection routing.
[0035] Step 3: Verify whether the traffic is forwarded through cloud networking, and delete the redundant peer-to-peer connection.
[0036] The three steps represent the processing process contained in the VPN information data, directly indicating the routing table, associated source VPC, and corresponding forwarding traffic data of the current VPN configuration when adjusting, to illustrate the control needs in the centralized fusion monitoring scene of multi-path VPN.
[0037] When performing multi-path VPN fusion automatic monitoring and regulation, the system will shield the underlying differences between different VPN protocols (such as OpenVPN, IPSec, EasyConnect, and WireGuard) and different vendors (such as Deepin, Huawei, and Cisco), and apply a unified metadata label to each VPN tunnel to schedule and manage all manageable physical links.
[0038] As shown in Figure 2 The implementation of step S1 further includes: S11, extracting the VPN tunnel type, business scenario, performance index, and application identifier corresponding to the VPN information data, and determining the routing policy of the current VPN information data.
[0039] When processing the communication abnormal state in the VPN information data, the configuration of the routing port is collected, and the data is processed according to the corresponding parts of the VPN tunnel, business scenario, performance index, and application identifier. The application identifier represents the customer or business system to which the traffic belongs, facilitating subsequent data tracing.
[0040] At this time, by determining the current specific configuration of the VPN, the specific situation of the actual collection of VPN information is determined, and the specific scene of the VPN when working is determined.
[0041] S12, the routing strategy is issued to each router, and the abnormal state at the time of monitoring is bound to the routing port of the VPN information data.
[0042] At this time, the specific data of the VPN running after the tunnel is established is determined, the data such as interface downtime and performance falling below the threshold value monitored by the current VPN is associated with a specific network interface or next hop gateway, and the routing port under the current data transmission is bound. In essence, it is to monitor the processing part of the firewall and the processing part of the gateway switching under the VPN.
[0043] S13, when the configuration at the routing port changes, the VPN information data is synchronized and corrected, and if the VPN information data after synchronization and correction is available, the VPN information data is output as the VPN information data under the communication abnormal state.
[0044] At this time, the part of the synchronization correction is to judge whether the current strategy is still effective. If the specified VPN tunnel has been interrupted when performance degradation occurs, it is considered that the VPN information data is unavailable. At this time, the processing of the synchronization correction is that the system adjusts automatically or switches to the standby tunnel according to the initial configuration of the routing strategy. If the device or terminal represented by the current VPN information data can continue to work, it is considered that the data after synchronization correction is available.
[0045] At this time, the configuration change at the routing port is driven based on events such as monitoring alarms and policy changes under abnormal state, and the data part completed by the current router after active verification is used as the updated system state at this time. The information data related before and after the communication abnormal state is checked to complete the fusion monitoring of the subsequent VPN tunnel and other parts.
[0046] Preferably, the implementation process of step S12 further comprises: S121, scanning the routing port range contained in the routing strategy, dividing the routing port range, and determining the priority of each routing port based on the frequency of abnormal state under multiple range scanning. The network scanning tool such as nmap or the self-defined script is used to scan the IP segment and specific port of the port range defined in the routing strategy.
[0047] When dividing the routing port range, the ports are divided into multiple sub-ranges according to business requirements or network topology, such as 3306-3308 for database ports and 3309-3310 for API ports. The priority is set according to the frequency of scanning to abnormal state, and the frequency of abnormal state is normalized. The normalized value is used as the priority of the corresponding port.
[0048] S122, based on the priority of each abnormal state corresponding to the routing port, at least once for each routing port, data update processing is performed, the scanned routing port is taken as a target routing port, the target routing port is fused to obtain the scanning result of each routing port range.
[0049] For routing ports under different priorities, different ways are adopted for data update processing, and the implementation manner includes: when performing data update processing, based on each identified abnormal state, the time delay, packet loss rate and bandwidth utilization of the routing port are used to execute abnormal marking on routing ports of each priority to obtain a single scanning result.
[0050] Based on the priority of the routing port, the routing strategy of the routing port under abnormal marking is adjusted, and the output content under the adjusted routing strategy is taken as a repair result. By triggering the repair operation immediately for the high-priority port, such as restarting the service, adjusting the routing table and other operations, the routing port is directly processed; the low-priority port is marked as "to be observed", and the abnormal marking of the low-priority port is recorded. The single scanning result includes the abnormal marking of the low-priority port and the processing process of directly executing repair for the high-priority port, and these data are fused into the output scanning result.
[0051] The multiple single scanning results and the repair result are fused to obtain the scanning result of each routing port range.
[0052] When performing comprehensive fusion, according to the time delay, packet loss rate and bandwidth utilization corresponding to the multiple scanning results and the repair result, the three data are normalized, and then a weighted sum is used to indicate whether the output scanning result meets the expected situation, for example, the weights are set to 0.5, 0.3 and 0.2, and the greater the weighted sum is, the worse the communication effect of the routing port under the established VPN tunnel is.
[0053] S123, based on the scanning result of each routing port range, the scanning result is synchronized to each routing port, and the binding of the VPN information data is completed.
[0054] According to the weighted sum in the scanning result, the values are synchronized to each routing port, which indicates whether the time delay, packet loss rate and bandwidth utilization of the routing port under the execution of port switching, restart and other operations and normal scanning meet the normal port use demand, and the values are synchronized to each actual use routing port, which is convenient for backtracking to the corresponding VPN tunnel to complete the comprehensive monitoring of the multi-way VPN fusion processing.
[0055] In step S1, the connection with the customer test environment and the production environment after the VPN tunnel is established is tested, and is specific to which protocol port, IP and the like, and the specific situation of the gateway / gateway group where the current access port is located, and the abnormal data form recognized by the current firewall in the case of identifying abnormal situations is viewed to determine the composition form of the basic data under the VPN processing, and a data acquisition chain under the flow source-gateway-firewall connection is formed.
[0056] In an embodiment of the application, in step S2, the target that needs to be optimized and processed is determined by analyzing the user demand to migrate the demand, and the target is specific to the trigger condition. The network resource list is continuously monitored, and each VPN tunnel is labeled. According to the combination of the label and the trigger condition, multiple VPN options that are currently needed are selected to form a specific and executable routing configuration scheme.
[0057] The routing configuration scheme described in step S2 is the executable part after the corresponding routing configuration is adjusted after collecting the routing configurations from different sources. Although it is judged in step S1 whether the data is available, the availability of this part of the judgment is based on the current data connection, and there is no situation that cannot be connected or cannot be accessed. At this time, the processing of the routing strategy is more inclined to the corresponding part of the user demand, and the routing configuration and VPN tunnel configuration corresponding to the user demand are further processed to obtain the VPN tunnel available to the user demand.
[0058] As shown in Figure 3 The implementation mode of step S2 includes: S21, mapping the user demand to the database to determine the instance information of the user demand mapped in multiple abnormal states, so that each user demand corresponds to at least one instance information. The user demand includes but is not limited to remote access demand, cross-regional network interconnection demand, multi-tenant virtualization demand, and high reliability and fault recovery demand. At this time, the instance information of the user demand mapping will directly represent the specific description of the VPN tunnel, the identity verification method, and the business isolation of the user demand directly configured by the remote access demand and the like user demand.
[0059] Remote access demand: users such as remote employees and mobile office personnel need to access enterprise intranet resources through the Internet securely. L2TP / PPTP tunnel can be used, which is suitable for dial-up Internet access scenarios, and the user initiates connection PPTP or establishes L2TP through NAS. Or IPSec tunnel, which provides end-to-end encryption and supports multiple users sharing public IP. It can meet the needs of identity authentication (such as pre-shared key, digital certificate verification), data encryption (such as AES, 3DES encryption method), dynamic address allocation (such as PPP protocol negotiation).
[0060] Cross-region network interconnection demand: the enterprise branch or data center needs to establish a safe and stable private network. GRE tunnel and MPLS TE tunnel can be used; bandwidth reservation (such as CR-LSP of MPLS TE), fault switching (such as load sharing or standby tunnel), and multi-service isolation (such as different VPN services binding dedicated tunnel) can be realized.
[0061] Multi-tenant virtualization demand: providing independent virtual networks for multiple users (such as different enterprises) on the same physical device. Virtual systems and tunnel selectors are often used to dynamically match routing and tunnel policies. Resource isolation (such as interface, IP address, and security policy), and flexible policy configuration (such as IPSec policy binding to a specific virtual system) can be realized.
[0062] High reliability and fault recovery demand: ensure that the tunnel automatically switches the path when the link fails or is congested. Tunnel binding policy and dynamic routing protocol are usually used to automatically adjust the route combined with the tunnel state. Fast fault detection (such as BFD protocol) and automatic path switching (such as load sharing) can be realized.
[0063] The above requirements represent the specific requirements that can be realized after the user prefers to establish a VPN tunnel and the connected customer scenario under the current VPN fusion processing scenario, to complete the security configuration of the interface, gateway, firewall, etc.
[0064] As for the trigger conditions corresponding to the user requirements, these data directly represent the related files configured under the current connected customer scenario, and the channel type connected, from which the trigger conditions corresponding to the user requirements are selected; that is, the trigger conditions will directly elaborate the data part that needs to be isolated, such as multi-service, fault switching, bandwidth reservation, and resource isolation, which will be used as the current corresponding trigger condition.
[0065] S22, when the VPN connection described in the instance information is normal, the corresponding VPN tunnel is interconnected.
[0066] S23, when the VPN connection described in the instance information is abnormal, check whether the current instance information satisfies the trigger condition for execution. If the trigger condition is not satisfied, the abnormal VPN tunnel is verified through the automatic detection mechanism of the VPN tunnel, and when the VPN tunnel is converted to an active state, the corresponding VPN tunnel is interconnected.
[0067] If the trigger condition is not satisfied, it represents that the current VPN tunnel has partial abnormalities, such as temporary performance decline, and then the duration of the decline is too small, etc. At this time, whether the routing information configured under the VPN tunnel can remain active is continuously detected, and then the VPN tunnel that can remain active and complete communication is interconnected.
[0068] The trigger condition can be selected by the following specific description of example information, which needs to be triggered by the subsequent user to trigger the content of the mapping.
[0069] IF Tunnel Anomaly Type == High Latency AND Affected Service == Video Conference THEN Trigger Condition = Find low latency path.
[0070] IF Tunnel Anomaly Type == Interruption THEN Trigger Condition = Find any available backup path.
[0071] IF Tunnel Anomaly Type == High Packet Loss AND Affected Service == Data Backup THEN Trigger Condition = Find high stability path.
[0072] The content contained in the three described IF-THEN statements represents example information, which directly represents the specific expression of the current VPN. These expressions will be combined into a rule base that meets the current processing. These rules can be defined by historical data or pre-defined rules in the database, which indicate the data form that needs to be triggered under specific user demand.
[0073] S24, if the trigger condition is met, reconfigure the route based on the VPN tunnel corresponding to the trigger condition, and perform peer interconnection on the reconfigured VPN tunnel. The VPN tunnel that takes effect after completing the peer interconnection is used as the output route configuration scheme.
[0074] When reconfiguring the route, three ways can be used for route configuration, such as static route, policy route, and dynamic route. Static route makes the next hop of the network segment point to the gateway address of the selected tunnel. Policy route generates a firewall rule that matches the source IP or destination IP, and sets the action of the route, such as allowing and other configurations, and specifies the gateway of the selected tunnel as the egress. If dynamic route is used, a path pointing to the target network segment is injected into the process, and the MED, Local Preference, etc. attributes of BGP (Border Gateway Protocol) are used to affect routing.
[0075] When configuring peer interconnection, route information needs to be exchanged between tunnels, and route redistribution is configured; for example, OSPF route (link state routing protocol) is redistributed to BGP or BGP Peer relationship is established to realize the exchange of information between multiple VPN tunnels.
[0076] When these configured route information takes effect, the peer interconnection related route information under the current processing is output as a route configuration scheme; for example: rule ID: Policy_1001, target: 10.1.1.0 / 24, use tunnel: Tunnel_C, status: has taken effect, to construct a configuration table composed of route information under multiple VPN tunnels corresponding to the current user demand.
[0077] In one embodiment of the present invention, when determining the optimization target, the feasibility of the currently selected routing configuration scheme is verified by multi-route distribution based on the routing configuration scheme. If feasible, the specific optimization target is determined to adjust the handling method under VPN tunnel communication anomalies. Ultimately, this enables network resources to elastically and intelligently serve upper-layer business needs.
[0078] It should be noted that after completing the routing configuration scheme for user needs in step S2, the traffic forwarding at this time is to verify the traffic characteristics after route distribution, such as packet loss rate, transmission speed and other traffic characteristics that directly reflect the data processing speed under the VPN tunnel. This indicates whether the current routing configuration scheme can directly correspond to an optimization goal for user needs, and adjust the VPN tunnel of subsequent output configuration.
[0079] like Figure 4 As shown, the implementation of step S3 includes: S31, determining the VPN tunnel under traffic forwarding by receiving the routing configuration scheme, and judging whether the VPN tunnel under forwarding is available.
[0080] Availability is determined by verifying tunnel connectivity using ICMP ping or BFD (Bidirectional Forwarding Detection); then, it is verified whether the tunnel bandwidth meets the current traffic requirements. If the current VPN tunnel belongs to the initially bound VPN tunnel, it is necessary to determine whether the specified tunnel is available, such as whether it is in the Up state; after all conditions are met, it is marked as available.
[0081] S32, if available, aggregate and calculate the performance metrics in the routing configuration scheme after traffic forwarding, and aggregate the data corresponding to the performance metrics with the metric values corresponding to the aggregated performance metrics as the optimization target; the optimization target output here is not a specific performance metric, but a specific data structure consisting of verifiable and quantifiable data structure, which includes a set of policy instructions that implement the routing configuration scheme, traffic distribution and initial VPN data.
[0082] In the aggregation calculation, the data such as the packet loss rate contained in the performance index is normalized, and the weighted sum is taken as the aggregation calculation result at this time, that is, the data at multiple time points after the traffic forwarding is aggregated and calculated, the weight is set according to the ratio of the corresponding data to the total data, the corresponding data is normalized as its value, the calculation of the weighted sum is completed, and the performance index of the weighted sum will be averaged according to the number of the currently monitored VPN tunnels, the average value indicates the index value of the multiple tunnels in the load balancing processing scene under the current traffic distribution, and the calculated value is combined with the corresponding tunnel to form a structural data, and this structural output is output as an optimization target. For example, the packet loss rate can be aggregated as an optimization target alone, the time delay, bandwidth utilization, etc. can be aggregated as an optimization target respectively, or can be aggregated as an optimization target, and the related data is aggregated into a structured form for output.
[0083] S33, if not available, the VPN tunnel that exists is remapped to a new address space, and the routing configuration scheme is called again.
[0084] When there is an unavailability, it means that the current VPN tunnel does not meet the bandwidth requirement or the bound VPN tunnels cannot work together under the traffic distribution, at this time, the available VPN tunnels are called in a loop to monitor the VPN tunnels in the overall fusion environment and how to run in the multi-client scene.
[0085] That is, the implementation process of step S33 also includes isolating the unavailable VPN tunnel, gradually marking the next hop of the unavailable VPN tunnel as invalid, and releasing the binding relationship with the current route.
[0086] The isolated VPN tunnel is re-distributed until the current VPN tunnel is marked as available.
[0087] At this time, the main implementation is that the distributed VPN tunnel of the VPN tunnel under the traffic forwarding can meet the use demand of the business scene, if it does not meet the demand, it is not considered as available, then the part of the bound VPN tunnel is identified, if there is an unavailability in the part of the initial binding, the related routing configuration scheme is re-acquired to realize the selection of the dynamic tunnel.
[0088] In an embodiment of the present application, the structured data corresponding to the optimization target in step S4 is associated and is comprehensively processed according to the optimization target obtained within a certain time period, at this time, the multiple available VPN tunnels are bound in the form of the structure of the optimization target, and are abstracted into a sequence diagram according to the topological relationship between the VPN tunnels, the optimization target and the VPN tunnel are abstracted into vertices in the diagram, and then the connection relationship of the optimization target to the VPN tunnel and the VPN tunnel pointed to by each optimization target are illustrated in the form of a bipartite graph, at this time, the connection relationship between the vertices will be according to the index value corresponding to the optimization target, and the value will be used as the weight of the edge between the vertices; since it is pointed to a certain time period at this time, the weight value will be averaged according to the weight of the VPN tunnel pointed to by each optimization target within the corresponding time period to further quantify the weight between the vertices in the serialized abstract graph; if there is only one index value within the current time period, the index value corresponding to the optimization target will be directly used as the weight of the corresponding VPN tunnel.
[0089] It should be noted that the above certain time period can be data collected within 1 day, 3 days, etc.
[0090] As shown in Figure 5 , the implementation mode of step S4 includes: S41, taking the optimization target obtained within a certain time period and the VPN tunnel corresponding to the optimization target as the vertices of a serialized abstract graph, taking the average value of the index value of the optimization target and the corresponding VPN tunnel within a certain time period as the weight, and constructing a serialized abstract graph.
[0091] S42, using the delay, service label and bandwidth utilization of each vertex in the serialized abstract graph to query the deployment cost, and calculating the priority score of each vertex in the serialized abstract graph.
[0092] At this time, the delay, service label and bandwidth utilization are used to query the deployment cost, and the implementation mode includes: respectively mapping the delay, service label and bandwidth utilization into scores, and sequentially calculating the scores corresponding to the delay, service label and bandwidth utilization under different VPN tunnels.
[0093] The service label is mapped into a score to obtain the score corresponding to the service label, the service label is used to distinguish different service types, such as video conference, internal communication, data backup, etc., the greater the score, the more it indicates that the current service is in the part of priority processing, such as video conference > department meeting > background data backup, at this time, the score of the service label mapping will be set according to the demand of VPN data processing and transmission under the scene.
[0094] The delay is set according to the deviation proportion of the normal running state, and the delay corresponding score is set; at this time, the ratio of the current delay to the average delay of the corresponding VPN tunnel in the historical data is judged, and the value is taken as the score of the delay. The greater the delay corresponding score is, the greater the delay is, and the VPN tunnel needs to be adjusted in time.
[0095] The bandwidth utilization rate is mapped to the score, and the proportion of the remaining unused bandwidth is taken as the score of the bandwidth utilization rate. The greater the bandwidth utilization rate score is, the lower the channel utilization rate is, and the higher the utilization rate is, the lower the score is.
[0096] The scores corresponding to the delay, service label and bandwidth utilization rate are weighted and summed to be regarded as the output priority score. The weights of the delay, service label and bandwidth utilization rate can be set to 0.3, 0.5 and 0.2 in turn.
[0097] S43, according to the priority score from high to low, the minimum deployment cost of the serialized abstract graph in a certain time period is determined by combining the weights of each vertex, and the order of the VPN tunnel using priority score under the minimum deployment cost is regarded as the output response order.
[0098] Since the weight of each vertex in the serialized abstract graph represents the degree value of the optimization target biasing to a VPN tunnel, after knowing the priority score of the VPN tunnel in performance, the priority scores of the optimization target and the VPN tunnel are weighted and summed with the edge weight to obtain the deployment cost consumed by the current optimization target for processing the VPN tunnel.
[0099] As for the minimum deployment cost, the minimum value of the deployment cost is obtained in a certain time period, and when the deployment cost has a minimum value, the performance consumption generated under the current VPN tunnel combination is the minimum deployment cost. The response order provides the trade-off processing condition when the time delay, bandwidth and service scenario conflict, and the given VPN tunnel is in a relatively stable state as a whole; the calculable optimization target avoids the waste of resources caused by subjective configuration.
[0100] Preferably, subsequent data alarms are generated for the optimization target according to the response order, which is essentially processed by threshold alarm, order change alarm and service association alarm.
[0101] For example, under the corresponding order of the minimum deployment cost, there is a large ranking fluctuation amplitude of a certain VPN tunnel, and the current minimum deployment cost value is too large, or the associated service scenario has threshold alarm and order change alarm for many times in succession, so that the service association alarm is triggered to complete the generation of data alarm.
[0102] Preferably, the implementation of the data alarm of the optimization target according to the response sequence in step S4 includes: setting the confidence interval with the minimum deployment cost value, and setting the threshold alarm for the part exceeding the upper limit value of the confidence interval; the confidence interval can be set to the range of the average value of the minimum deployment cost plus or minus twice the standard deviation, and the minimum deployment cost will be extracted from the historical data to complete the setting of the confidence interval; the obtained threshold alarm will represent the periodic fluctuation of the network performance after the combination of the VPN tunnels, and when the fluctuation is too large, the VPN tunnel is considered to be processed.
[0103] Based on the ranking position of the VPN tunnel in the response sequence, when the change amplitude of the ranking position exceeds the preset threshold, a ranking change alarm is set; the preset threshold of the change amplitude of the ranking position is 20%, to illustrate whether there is performance deterioration such as latency surge of the VPN tunnel in multiple tests and traversals, which needs to be paid attention to in time and trigger the response alarm. The ranking change alarm directly reflects the allocation efficiency of the network resources. For example, if the minimum cost tunnel of the high-priority service suddenly becomes high cost, it indicates that the current network cannot meet its QoS demand, which may be caused by link congestion, device failure or configuration error.
[0104] If the threshold alarm or the ranking change alarm of the current response sequence associated with the service scenario appears continuously, the VPN tunnel under the current response sequence is set with a service association alarm. The service association alarm will illustrate that the risk is prone to occur in the corresponding scenario, and at this time, the alarm needs to be given in time.
[0105] The finally output data alarm will be in the form of a list, including the alarm type (threshold alarm, ranking change alarm, service association alarm), the involved VPN tunnel, the involved optimization target, the timestamp, and other metadata (such as the deployment cost value).
[0106] When the path clustering is performed subsequently, each alarm type is mapped to the corresponding path, that is, the optimization target-VPN tunnel pair, which is composed into an alarm-path association matrix, the row represents the alarm, the column represents the path, and the matrix value represents the correlation of the alarm and the path, that is, the correlation value is set for the optimization target-VPN tunnel pair corresponding to the alarm, and the correlation value is set according to the ratio of the occurrence frequency of the corresponding alarm type to the occurrence frequency of all alarm types of the optimization target-VPN tunnel pair.
[0107] It should be noted that the alarm types identified at this time include but are not limited to the above-mentioned threshold alarm, ranking change alarm and service association alarm, and the alarm types will be further refined according to the actual use scene of the VPN to illustrate the specific form of the current data alarm.
[0108] For example, Figure 6As shown, the implementation of step S5 includes: S51, regarding the optimization target and the corresponding VPN tunnel as a path, mapping each alarm type to the corresponding path to form an alarm-path association matrix.
[0109] S52, according to the alarm type of the data alarm, clustering the elements of the alarm-path association matrix, and taking the clustered data as the output target VPN tunnel; at this time, the clustering is performed through the matrix values of the alarm-path association matrix, and the core form of the output is a series of alarm clusters and the VPN tunnel corresponding to each cluster, which is a VPN tunnel list extracted from all alarm clusters and needs to be focused on.
[0110] The above clustering mode can adopt a k-means clustering mode, the matrix values are clustered to indicate that there are similarity frequency ratio VPN tunnels, and these VPN tunnels are output to facilitate subsequent monitoring of the corresponding VPN tunnel and prevent tunnel congestion and other problems, thereby improving the processing efficiency of the multiple VPN tunnels.
[0111] Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application, which are still covered by the protection scope of the present application.
Claims
1. A multi-VPN fusion automatic monitoring and control method, characterized in that, include: S1, perform communication detection on the received VPN information data to determine the VPN information data under different communication abnormal states; S2, extract user needs under abnormal communication conditions, and based on the triggering conditions corresponding to user needs, retrieve multiple VPN tunnels from VPN information data to construct a routing configuration scheme corresponding to user needs; S3 responds to traffic forwarding based on routing configuration schemes, and determines the optimization goals based on user needs through multi-route distribution; S4. Based on the routing configuration scheme corresponding to each optimization target, the optimization targets obtained within a certain time period are associated with the corresponding VPN tunnels to form a serialized abstract graph between multiple VPN tunnels and optimization targets. Based on the minimum deployment cost of the serialized abstract graph within a certain time period, the response order of the optimization targets is determined, and data alarms are generated for the optimization targets according to the response order. S5, based on the alarm type of the data alarm, performs path clustering of the data alarm according to the serialization abstract graph, and determines the target VPN tunnel under fusion monitoring based on the alarm type transmitted along each path.
2. The multi-VPN fusion automatic monitoring and control method according to claim 1, characterized in that, The implementation of step S1 also includes: S11, extract the VPN tunnel type, business scenario, performance indicators and application identifier corresponding to the VPN information data, and determine the routing strategy for the current VPN information data; S12, distribute the routing policy to each router, and bind the routing port of VPN information data according to the abnormal status during monitoring; S13: When the configuration at the routing port changes, the VPN information data is synchronously corrected. If the synchronously corrected VPN information data is available, the VPN information data is output as VPN information data in the communication abnormal state.
3. The multi-VPN fusion automatic monitoring and control method according to claim 2, characterized in that, The implementation process of step S12 also includes: S121, Scan the range of routing ports included in the routing policy, divide the range of routing ports, and determine the priority of each routing port based on the frequency of abnormal states under multiple range scans; S122, based on the priority of the routing port corresponding to each abnormal state, perform at least one data update process for each routing port, take the scanned routing port as the target routing port, and perform fusion processing on the target routing ports to obtain the scan results of each routing port range; S123 synchronizes the scan results to each routing port based on the scan results of each routing port range and completes the binding of VPN information data.
4. The multi-VPN fusion automatic monitoring and control method according to claim 3, characterized in that, The implementation methods for data update processing include: When performing data update processing, based on the identified abnormal status, the routing port latency, packet loss rate and bandwidth utilization are used to perform abnormal marking on the routing ports of each priority to obtain the single scan result; Based on the priority of the routing port, the routing policy is adjusted for the routing ports marked as abnormal, and the output content under the adjusted routing policy is used as the repair result.
5. The multi-VPN fusion automatic monitoring and control method according to claim 1, characterized in that, Step S2 can be implemented in the following ways: S21, map user requirements to the database, determine the instance information of user requirement mapping under multiple abnormal states, so that each user requirement corresponds to at least one instance information; S22, when the VPN connection described in the instance information is normal, the corresponding VPN tunnel will be interconnected peer by peer; S23, when the VPN connection described in the instance information is abnormal, check whether the current instance information meets the triggering conditions for execution. If the triggering conditions are not met, continuously verify the existence of abnormal VPN tunnels through the VPN tunnel automatic detection mechanism. When the VPN tunnel becomes active, perform peer-to-peer interconnection with the corresponding VPN tunnel. S24. If the triggering condition is met, the route is reconfigured based on the VPN tunnel corresponding to the triggering condition. The VPN tunnel with the reconfigured route is then peered through. The VPN tunnel that takes effect after peering through is used as the output route configuration scheme.
6. The multi-VPN fusion automatic monitoring and control method according to claim 1, characterized in that, Step S3 can be implemented in the following ways: S31, by receiving the routing configuration scheme, determines the VPN tunnel under traffic forwarding and judges whether the VPN tunnel under forwarding is available; S32, if available, aggregate the performance metrics in the routing configuration scheme after traffic forwarding, and aggregate the data corresponding to the performance metrics as optimization targets based on the metric values corresponding to the aggregated performance metrics. S33, if unavailable, will remap the unavailable VPN tunnel to a new address space and re-invoke the routing configuration scheme.
7. The multi-VPN fusion automatic monitoring and control method according to claim 6, characterized in that, The implementation process of step S33 also includes: Isolate unusable VPN tunnels, gradually mark the next hop of unusable VPN tunnels as invalid, and unbind the unusable VPN tunnels from each other; For isolated VPN tunnels, reroute routes until the current VPN tunnel is marked as available.
8. The multi-VPN fusion automatic monitoring and control method according to claim 1, characterized in that, Step S4 can be implemented in the following ways: S41, take the optimization target and the VPN tunnel corresponding to the optimization target obtained within a certain time period as the vertices of the serialization abstract graph, and take the average value of the index value of the optimization target and the corresponding VPN tunnel within a certain time period as the weight to construct the serialization abstract graph. S42, use the latency, service label and bandwidth utilization of each vertex in the serialized abstract graph to query the deployment cost and calculate the priority score of each vertex in the serialized abstract graph; S43. Sort according to priority scores from high to low, and combine the weight of each vertex to determine the minimum deployment cost of the serialized abstract graph within a certain time period. The order in which VPN tunnels are sorted by priority scores under the minimum deployment cost is regarded as the output response order.
9. The multi-VPN fusion automatic monitoring and control method according to claim 1, characterized in that, The implementation methods for generating data alarms for the optimization target based on the response order in step S4 include: Set the confidence interval with the value that minimizes deployment cost, and set a threshold alarm for the portion that exceeds the upper limit of the confidence interval; Based on the VPN tunnel's position in the response sequence, an alarm is set for a change in the order when the change in the order exceeds a preset threshold. If threshold alarms or sorting change alarms occur consecutively in the business scenarios associated with the current response order, set the VPN tunnel under the current response order to a business-related alarm.
10. The multi-VPN fusion automatic monitoring and control method according to claim 1, characterized in that, Step S5 can be implemented in the following ways: S51 treats the optimization target and the corresponding VPN tunnel as a path, and maps each alarm type to the corresponding path to form an alarm-path association matrix. S52, based on the alarm type of the data alarm, controls the elements of the alarm-path association matrix to be clustered, and uses the clustered data as the output target VPN tunnel.
Citation Information
Patent Citations
VPN service generation method, system and device based on cloud computing platform and medium
CN116389194A
Method for high-availability deployment of federated peer-to-peer cluster in edge environment
CN119743483A
Method and device for optimizing VPN (Virtual Private Network) equipment, processor and VPN equipment
CN117914648A
VPN tunnel communication optimization method based on intelligent routing
CN120281676A