Networking method and device, network equipment and computer readable storage medium

By identifying associated devices and establishing tunnels in the SD-WAN network, the problems of high network transmission latency and cloud silos in SD-WAN networking are solved, achieving efficient data transmission and simplified management.

CN121864684APending Publication Date: 2026-04-14GUANGZHOU HUYA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-16
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing SD-WAN networking methods, the center-radial networking method results in high network transmission latency and low efficiency, while the cloud-center networking method leads to increased management complexity and multi-cloud silos, resulting in high management costs.

Method used

By receiving registration requests from gateway devices in the SD-WAN network, associated devices are identified, and tunnels are established between the gateway devices and associated devices based on tunnel configuration information. This enables data transmission within the same communication network and between different communication networks, avoiding the central node in a center-radiating network. FOU tunnel configuration information is generated using a pre-set private network and communication network to ensure efficient interconnection.

Benefits of technology

It enables efficient interconnection between gateway devices without the need for a central node in a centrally located, radial network, avoiding the problem of cloud silos and reducing management complexity and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864684A_ABST
    Figure CN121864684A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication networks, and provides a networking method and device, network equipment and a computer readable storage medium, and the method comprises the steps: receiving a registration request sent by gateway equipment when the gateway equipment joins an SD-WAN network; determining associated equipment from the SD-WAN network based on the registration request, the associated equipment and gateway equipment belonging to the same communication network, and the gateway equipment of which the type is a central gateway in the SD-WAN network being connected with a plurality of communication networks; and tunnel configuration information between the gateway equipment and the associated equipment is sent to the gateway equipment, so that the gateway equipment establishes a tunnel between the gateway equipment and the associated equipment based on the tunnel configuration information. According to the invention, data transmission in the same communication network and among different communication networks is realized on the premise that a central node of a central radiation type network does not need to be arranged, and the problem of'multi-cloud island 'is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication network technology, and more specifically, to a networking method, apparatus, network equipment, and computer-readable storage medium. Background Technology

[0002] SD-WAN (Software-Defined Wide Area Network) is a solution that enables network nodes distributed in various locations to communicate intelligently, efficiently, and flexibly. It is designed to address the challenges of current large-scale distributed network environments, especially those involving edge nodes and central data centers of multiple cloud vendors, as well as the internal network interconnection between edge nodes of different cloud vendors, particularly the performance bottlenecks and management complexity in high-traffic transmission scenarios.

[0003] Currently, SD-WAN networking methods mainly include hub-and-spoke and cloud-centric approaches. Hub-and-spoke networking can easily make the central node a performance bottleneck, resulting in high network latency and low efficiency. Cloud-centric networking suffers from poor interoperability across heterogeneous environments such as cloud platforms and carrier platforms, easily creating "multi-cloud islands" and increasing management costs. Summary of the Invention

[0004] The purpose of this invention is to provide a networking method, apparatus, network device, and computer-readable storage medium.

[0005] The embodiments of the present invention can be implemented as follows: In a first aspect, the present invention provides a networking method, the method comprising: Receive the registration request sent by the gateway device when it joins the SD-WAN network; Based on the registration request, an associated device is determined from the SD-WAN network. The associated device and the gateway device belong to the same communication network. The gateway device in the SD-WAN network, which is of the type of central gateway, is connected to multiple communication networks. The tunnel configuration information between the gateway device and the associated device is sent to the gateway device so that the gateway device can establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

[0006] In an optional implementation, the gateway device is a central gateway, and the step of sending the tunnel configuration information between the gateway device and the associated device to the gateway device includes: The first FOU tunnel configuration information between the gateway device and the associated device of type central gateway is generated based on the preset private network. The preset private network is used to connect the gateway device of type central gateway in the SD-WAN network. Based on the communication network, a second FOU tunnel configuration information is generated between the gateway device and the associated device of type edge gateway; The first FOU tunnel configuration information and the second FOU tunnel configuration information are sent to the gateway device.

[0007] In an optional implementation, the gateway device is an edge gateway, and the step of sending the tunnel configuration information between the gateway device and the associated device to the gateway device includes: Based on the communication network, FOU tunnel configuration information is generated between the gateway device and the associated device; The FOU tunnel configuration information is sent to the gateway device.

[0008] In an optional implementation, the gateway device acting as the primary device in the SD-WAN network belongs to the first logical plane, and the gateway device acting as the backup device in the SD-WAN network belongs to the second logical plane. The step of determining the associated device of the gateway device from the SD-WAN network based on the registration request includes: Based on the registration request, the target logical plane to which the gateway device belongs is obtained; The associated device is determined from other gateway devices in the SD-WAN network that belong to the target logical plane.

[0009] In an optional implementation, the method further includes: Based on the tunnel configuration information, BGP configuration information between the gateway device and the associated device is generated; The BGP configuration information is sent to the gateway device so that the gateway device can establish a neighbor relationship between the gateway device and the associated device based on the tunnel between the gateway device and the associated device and the BGP configuration information.

[0010] Secondly, the present invention provides a networking method, the method comprising: When a gateway device joins an SD-WAN network, it sends a registration request to the SD-WAN controller in the SD-WAN network. The system receives tunnel configuration information between the gateway device and the associated device sent by the SD-WAN controller. The associated device is determined by the SD-WAN controller from the SD-WAN network based on the registration request and belongs to the same communication network as the gateway device. The gateway device in the SD-WAN network is of type central gateway and is connected to multiple communication networks. Based on the tunnel configuration information, a tunnel is established between the gateway device and the associated device.

[0011] In an optional implementation, there are multiple associated devices, and the gateway device is communicatively connected to the server. The method further includes: Receive data packets sent by the server to the destination device; If the target device and the gateway device belong to the same communication network, the target associated device is determined from the associated devices of type edge gateway; otherwise, the target associated device is determined from the associated devices of type central gateway. The data packet is sent through a tunnel between the gateway device and the target associated device so that the data packet reaches the destination device.

[0012] Thirdly, the present invention provides a networking device, the device comprising: The registration request receiving module is used to receive registration requests sent by gateway devices when they join the SD-WAN network; The determination module is used to determine the associated device from the SD-WAN network based on the registration request. The associated device and the gateway device belong to the same communication network. The gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks. The configuration information sending module is used to send tunnel configuration information between the gateway device and the associated device to the gateway device, so that the gateway device can establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

[0013] Fourthly, the present invention provides a networking device, the device comprising: The registration request sending module is used to send a registration request to the SD-WAN controller in the SD-WAN network when the gateway device joins the SD-WAN network; The configuration information receiving module is used to receive tunnel configuration information between the gateway device and the associated device sent by the SD-WAN controller. The associated device is determined by the SD-WAN controller from the SD-WAN network based on the registration request and belongs to the same communication network as the gateway device. A configuration module is used to establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

[0014] Fifthly, the present invention provides a network device, including a controller and a memory, the memory being used to store a program, and the controller being used to implement the networking method as described in the first aspect, or the networking method as described in the second aspect, when executing the program.

[0015] In a sixth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a controller, implements the networking method as described in the first aspect, or implements the networking method as described in the second aspect.

[0016] Compared with the prior art, the present invention has the following beneficial effects: When the SD-WAN controller receives a registration request from a gateway device, it determines the associated devices belonging to the same communication network as the gateway device based on the registration request. The controller then sends tunnel configuration information between the gateway device and the associated devices to the gateway device, enabling the gateway device to establish a tunnel between itself and the associated devices based on this configuration information. Since a gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks, it can communicate directly with other gateway devices within the same communication network through the tunnel, and it can also communicate with gateway devices belonging to other communication networks through a gateway device of type central gateway. This achieves interconnection between gateway devices in the SD-WAN network. Because this invention enables data transmission within the same communication network and between different communication networks without requiring a central node in a centrally located radial network, it avoids the problem of "multi-cloud islands." Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is an example diagram illustrating an application scenario provided in this embodiment.

[0019] Figure 2 This is a block diagram of a network device provided in this embodiment.

[0020] Figure 3 This is a flowchart illustrating the networking method applied to the SD-WAN controller provided in this embodiment.

[0021] Figure 4 This is an example diagram of a tunnel connection provided in this embodiment.

[0022] Figure 5 This is an example diagram of a tunnel connection for an example scenario provided in this embodiment.

[0023] Figure 6 This is a flowchart illustrating the networking method applied to a gateway device provided in this embodiment.

[0024] Figure 7 This is a block diagram illustrating a networking device applied to an SD-WAN controller, as provided in this embodiment.

[0025] Figure 8 This is a block diagram illustrating a networking device applied to a gateway device, as provided in this embodiment.

[0026] Icons: 10-SD-WAN controller; 20-Central gateway; 30-Edge gateway; 40-Server; 50-Network device; 51-Processor; 52-Memory; 53-Bus; 100-Networking device applied to SD-WAN controller; 110-Registration request receiving module; 120-Determination module; 130-Configuration information sending module; 200-Networking device applied to gateway device; 210-Registration request sending module; 220-Configuration information receiving module; 230-Configuration module; 240-Packet sending module. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0028] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0029] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0030] In the description of this invention, it should be noted that if terms such as "upper," "lower," "inner," or "outer" are used to indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship in which the product of this invention is usually placed, they are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this invention.

[0031] Furthermore, the terms "first" and "second" are used only to distinguish descriptions and should not be interpreted as indicating or implying relative importance.

[0032] It should be noted that, where there is no conflict, the features in the embodiments of the present invention can be combined with each other.

[0033] Currently, the two main SD-WAN networking methods, namely, the center-radial type and the cloud-center type, have the following drawbacks: Traffic backhaul: Because communication between edge gateways needs to be backhauled to the central node in the center-radial type, the communication efficiency between edge gateways is low.

[0034] Poor interoperability in heterogeneous environments: In cloud-centric SD-WAN networks, when cross-cloud platform communication between multiple cloud vendors is involved, there is a lack of unified management and policy distribution capabilities, which can easily lead to the formation of "multi-cloud islands" and fragmented management.

[0035] Poor scalability of central nodes: In a centrally-radiating SD-WAN network, the central node, as the traffic aggregation point, faces performance bottlenecks and high availability challenges.

[0036] High costs and complex operation and maintenance: Large-scale deployment and management and maintenance costs are high.

[0037] In view of this, this embodiment provides a networking method, apparatus, network device, and computer-readable storage medium, which enables data transmission within the same communication network and between different communication networks without the need for a central node in a radial network, thus avoiding the problem of "multi-cloud islands". It will be described in detail below.

[0038] Please refer to Figure 1 , Figure 1 This is an example diagram illustrating an application scenario provided in this embodiment. Figure 1 There are four central computer rooms: the first central computer room to the fourth central computer room. Each central computer room includes multiple servers 40 and gateway devices. The gateway devices in the first and third central computer rooms are central gateways 20, and the gateway devices in the second and fourth central computer rooms are edge gateways 30. All four gateway devices communicate with the SD-WAN controller 10.

[0039] The SD-WAN Controller 10 is a centralized management and control platform, typically deployed in a high-availability cluster environment. It is responsible for functions such as gateway device registration and authentication, network topology management, automated configuration generation and distribution, and path optimization decision support.

[0040] The central gateway 20 is an SD-WAN gateway node deployed in a core data center (such as a company headquarters or regional center computer room) with a dedicated line connection. It is usually located in the "center" of the network topology and can be built by deploying an SD-WAN agent on a server in the central computer room.

[0041] Edge gateway 30 is an SD-WAN gateway deployed at edge nodes (such as branch offices in various locations or public cloud edge instances). It is typically located at the network edge, but can also be built by deploying an SD-WAN proxy on a server in the central data center. The difference between central gateway 20 and edge gateway 30 is that central gateway 20s are connected by dedicated lines and one central gateway 20 can support various communication networks, while edge gateways 30s do not have dedicated lines and typically only support one communication network.

[0042] Server 40 refers to general-purpose x86 architecture physical or virtual servers deployed in various central data centers (including self-built IDCs and cloud environments). When multiple network components are installed and running on Server 40, such as SD-WAN gateway agent, Bird routing process, Keepalived keep-alive module, and FOU tunnel module, it functions as a gateway device. Bird routing process is an open-source dynamic routing daemon whose core function is to implement and manage various routing protocols and exchange routing information between different routing protocols and between protocols and the operating system kernel. Keepalived keep-alive module monitors the system status through VRRP (Virtual Router Redundancy Protocol) and automatically switches services to backup nodes when the primary node fails, thus ensuring service continuity and availability. FOU (Foo Over UDP) tunnel is used to encapsulate various network data packets in UDP packets for transmission.

[0043] Please refer to Figure 2 , Figure 2 This is a block diagram illustrating the network device 50 provided in this embodiment. The network device 50 may be... Figure 1 The SD-WAN controller 10, central gateway 20, or edge gateway 30 in the configuration can be used to forward data packets between data centers or between servers within a data center. When network device 50 is SD-WAN controller 10, it is used to implement the networking method applied to SD-WAN controller 10 in this embodiment. When network device 50 is central gateway 20 or edge gateway 30, it is used to implement the networking method applied to gateway devices in this embodiment.

[0044] Figure 2In the network device 50, there are a processor 51, a memory 52 and a bus 53, with the processor 51 and the memory 52 connected via the bus 53.

[0045] The processor 51 can be an integrated circuit chip with signal processing capabilities. During implementation, each step of the networking method in this embodiment can be completed through the integrated logic circuits in the processor 51 or through software instructions. The processor 51 in this embodiment can be a general-purpose processor, including a CPU (Central Processing Unit), an NP (Network Processor), etc.; it can also be a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Logic Gate Array), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0046] The memory 52 is used to store programs that implement the networking method. These programs can be software functional modules stored in the memory 52 in the form of software or firmware, or embedded in the OS (Operating System) of the network device 50. For example, in this embodiment, the networking device applied to the SD-WAN controller 10, or the networking device applied to the gateway device.

[0047] After receiving the execution instruction, the processor 51 executes the program to implement the networking method of the aforementioned embodiment.

[0048] based on Figure 1 and Figure 2 This embodiment first introduces the networking method of SD-WAN controller applied in SD-WAN network. Please refer to [link / reference]. Figure 3 , Figure 3 Figure 3 This is a flowchart illustrating a networking method applied to an SD-WAN controller provided in this embodiment. The method includes the following steps: Step S101: Receive the registration request sent by the gateway device when it joins the SD-WAN network.

[0049] In this embodiment, after the gateway device starts up, in order to join the SD-WAN network, it will actively send a registration request to the SD-WAN controller. The registration request includes identity information for identifying the gateway device, such as device serial number, pre-shared key or certificate information, and possibly communication network identifier.

[0050] Step S102: Based on the registration request, determine the associated device from the SD-WAN network. The associated device and the gateway device belong to the same communication network. The gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks.

[0051] In this embodiment, upon receiving the registration request, the SD-WAN controller processes it as a new device access event and initiates subsequent network configuration procedures based on the identity and context information contained in the registration request. To avoid network complexity and increased maintenance and management costs caused by establishing connections between the gateway device and every other gateway device in the SD-WAN network, the gateway device only needs to establish connections with a subset of other gateway devices in the SD-WAN network that meet the requirements, i.e., associated devices. Associated devices refer to other gateway devices belonging to the same communication network as the gateway device initiating registration. The filtering logic for associated devices can rely on the communication network identifier or other attribute information that can be mapped to the communication network reported by the gateway device during registration.

[0052] It should be noted that communication networks include, but are not limited to, carrier networks, enterprise networks, and cloud networks. Carrier networks include, but are not limited to, wired networks, mobile cellular networks, and satellite internet networks. Multiple communication networks may include different carrier networks, different enterprise networks, different cloud networks, or at least two of the following: carrier networks, enterprise networks, and cloud networks.

[0053] Step S103: Send the tunnel configuration information between the gateway device and the associated device to the gateway device so that the gateway device can establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

[0054] In this embodiment, the tunnel configuration information may include configuration parameters required for establishing communication tunnels between the gateway device and its associated devices, including but not limited to the peer IP address, encapsulation protocol type, encryption algorithm, authentication method, and key negotiation mechanism. The gateway device can autonomously establish tunnels between itself and its associated devices based on the received tunnel configuration information. This allows newly added gateway devices to the SD-WAN network to automatically integrate into the established SD-WAN topology without manual intervention.

[0055] The method provided in this embodiment achieves interconnection between gateway devices in the SD-WAN network. Since the gateway device (type 1) is connected to multiple communication networks within the SD-WAN network, it can communicate directly with other gateway devices within the same communication network via tunnels, and it can also communicate with gateway devices belonging to other communication networks through the gateway device (type 1). This eliminates the need for a central node in a centrally-radial network, enabling data transmission within the same communication network and between different communication networks, thus avoiding the problem of "multi-cloud islands."

[0056] In an optional implementation, to ensure that data packets between central gateways are preferentially transmitted through the high-performance private network and avoid being routed through the public network, when the gateway device type is a central gateway, the SD-WAN controller processes the tunnel configuration information as follows: First, based on the preset private network, the first FOU tunnel configuration information between the gateway device and the associated device of type central gateway is generated. The preset private network is used to connect the gateway device of type central gateway in the SD-WAN network. In this embodiment, different types of gateway devices undertake differentiated forwarding and control functions. Among them, gateway devices of the central gateway type serve as core nodes and are typically deployed in data centers or regional aggregation points, possessing high reliability and access capabilities to multiple communication networks. To achieve efficient communication between central gateways, they are usually connected through a pre-set private network. This pre-set private network refers to a logical network plane dedicated to connecting central gateway type devices in the SD-WAN network. Its physical bearer can be built based on leased lines, MPLS (Multiprotocol Label Switching) links, or encrypted public network channels, featuring high stability and low latency. The first FOU tunnel configuration information includes configuration information for establishing the first FOU tunnel, which aims to achieve efficient interconnection between central gateways through a unified transmission mechanism.

[0057] Secondly, based on the communication network, a second FOU tunnel configuration information is generated between the gateway device and the associated device of type edge gateway; In this embodiment, when a gateway device of type central gateway joins the SD-WAN network, its networking requirements include not only interconnection with other central gateways but also secure connections with gateway devices of type edge gateway, thereby constructing a hierarchical communication topology. Taking the communication network as an example of a carrier network, the central gateway is connected through the carrier network. Compared to a pre-defined private network, the carrier network refers to the IP bearer network provided by various external carriers, typically based on the public internet, characterized by wide coverage but significant fluctuations in service quality. The second FOU tunnel configuration information includes configuration information for establishing the second FOU tunnel, which ensures that the central gateway can stably establish tunnel connections with edge gateways located in different geographical locations.

[0058] Third, send the configuration information of the first FOU tunnel and the configuration information of the second FOU tunnel to the gateway device.

[0059] In this embodiment, the first FOU tunnel configuration information and the second FOU tunnel configuration information are independent and complementary datasets, serving different networking objectives at different levels: the first FOU tunnel configuration information supports highly reliable interconnection within the central layer, while the second FOU tunnel configuration information enables wide-area extension between the central and edge layers. The receiving end can parse and apply these configurations locally to autonomously trigger the concurrent tunnel establishment process with multiple peer devices. The differentiation between the two configuration information types satisfies the technical distinction and optimized response to different types of terminal node communication scenarios.

[0060] It should be noted that the steps of generating the first FOU tunnel configuration information and generating the second FOU tunnel configuration information can also be performed in parallel. This embodiment does not limit the execution order of these two steps.

[0061] In an optional implementation, to enable servers to interconnect across communication networks via edge gateways, when the gateway device is an edge gateway, the SD-WAN controller sends tunnel configuration information in the following manner: First, FOU tunnel configuration information between the gateway device and associated devices is generated based on the communication network; Secondly, the FOU tunnel configuration information is sent to the gateway device.

[0062] In this embodiment, a gateway device of type edge gateway needs to be interconnected not only with a gateway device of type central gateway, but also with other gateway devices of type edge gateway. Since the edge gateway is connected to other gateway devices in the SD-WAN network through the communication network, the gateway device establishes a FOU tunnel based on the communication network, whether it is an edge gateway or a central gateway.

[0063] In this embodiment, whether it's the FOU tunnel configuration information between central gateways, the FOU tunnel configuration information between the central gateway and edge gateways, or the FOU tunnel configuration information between edge gateways, as one implementation method, the FOU tunnel configuration information between the gateway device and associated devices can contain multiple tunnel target entries corresponding to the associated devices. Each entry explicitly indicates the peer's identity, network reachability parameters, and security context. After receiving this information, the gateway device parses the various configurations and initiates the FOU tunnel negotiation process with each associated device based on the local network interface state. Thus, the control plane completes the information transmission from centralized decision-making to distributed execution, realizing the automated deployment of networking strategies.

[0064] In an optional implementation, to improve the reliability and stability of the SD-WAN network, gateway devices typically include primary and backup devices. To ensure orderly and smooth links between gateway devices, this embodiment assigns the gateway device acting as the primary device in the SD-WAN network to the first logical plane and the gateway device acting as the backup device to the second logical plane. In this case, the SD-WAN controller determines the associated devices as follows: First, based on the registration request, obtain the target logical plane to which the gateway device belongs; Secondly, identify the associated devices from other gateway devices in the SD-WAN network that belong to the target logical plane.

[0065] In this embodiment, in SD-WAN deployments with high availability requirements, a primary / backup redundancy architecture is typically used to ensure service continuity. Under this architecture, gateway devices are divided into two operating modes based on their role in the failover mechanism: acting as the primary device and acting as the backup device, respectively handling real-time traffic forwarding and hot backup standby functions. To avoid confusing control policies and network conflicts, devices with different roles need to be isolated and managed in an independent logical control plane.

[0066] In this embodiment, the SD-WAN controller obtains the target logical plane to which the gateway device belongs based on the received registration request. As one implementation, the registration request may include information fields identifying the device's operating role, such as a role label like "primary device" or "backup device," or its category may be indirectly determined through a pre-configured device policy table. The target logical plane, as a virtual grouping unit maintained internally by the controller, is used to distinguish device sets under different failover roles. The first logical plane corresponds to the gateway device acting as the primary device, and the second logical plane corresponds to the gateway device acting as the backup device. The SD-WAN controller determines associated devices from other gateway devices belonging to the target logical plane within the SD-WAN network, ensuring that the associated devices are within the device list covered by the target logical plane where the gateway device resides. The associated devices and the gateway devices belong to the same logical plane, eliminating device interference across role planes. This ensures the clarity of the network topology and policy consistency, effectively avoiding improper interconnection or control loop problems between primary and backup devices, and improving the organizational efficiency and operational stability of the SD-WAN network under complex redundant architectures.

[0067] To more intuitively demonstrate the tunnel between the gateway device and the associated device, please refer to [link / reference]. Figure 4 , Figure 4 This is an example diagram of the tunnel connection provided in this embodiment. Figure 4 In the context of communication networks, taking a carrier network as an example, an SD-WAN network includes five gateway devices: two central gateways and three edge gateways. Each gateway device includes a primary device and a backup device. The primary device belongs to the first logical plane, and the backup device belongs to the second logical plane. For example... Figure 4 As shown by the red line, the primary devices of the central gateway are interconnected, and the backup devices of the central gateway are interconnected. For example... Figure 4 As shown by the blue line, the main devices of the central gateway and the edge gateways are interconnected, and the backup devices of the central gateway and the edge gateways are interconnected. Since the central gateway simultaneously accesses multiple different carrier networks, therefore... Figure 4 Each central gateway can interconnect with edge gateways. For example... Figure 4 As shown by the green line, the main devices of the edge gateways of the same operator ISP1 are interconnected, the backup devices of the edge gateways of the same operator ISP1 are interconnected, and the edge gateways of different operators ISP1 and ISP2 are not interconnected.

[0068] based on Figure 4 This embodiment also provides an example of a tunnel connection in an exemplary scenario. Please refer to [link / reference]. Figure 5 , Figure 5 This is an example diagram of a tunnel connection for an example scenario provided in this embodiment. Figure 5In this embodiment, the communication network is taken as an example of the operator network. The central NC is the central gateway in this embodiment, and the edge EC is the edge gateway in this embodiment. The central NCs establish FOU tunnels through a preset private network, the central NC and the edge EC establish FOU tunnels through the operator network, and the edge ECs of the same ISP establish FOU tunnels through the operator network. Figure 5 The SD-WAN SW in the diagram refers to an SD-WAN switch, and the central NC is connected to the backbone network through the SD-WAN switch. The primary devices in the central NC and edge EC belong to plane A, while the backup devices in the central NC and edge EC belong to plane B.

[0069] In an optional implementation, to achieve optimal path selection, this embodiment also establishes a neighbor relationship between the gateway device and the associated device based on the tunnel between them. One implementation method is as follows: First, BGP configuration information between the gateway device and associated devices is generated based on the tunnel configuration information; Secondly, the BGP configuration information is sent to the gateway device so that the gateway device can establish a neighbor relationship between the gateway device and the associated device based on the tunnel between the gateway device and the associated device and the BGP configuration information.

[0070] In this embodiment, BGP configuration information is used to establish neighbor relationships based on the BGP (Border Gateway Protocol). These neighbor relationships enable routing-level interoperability, supporting dynamic forwarding of cross-site service traffic. The BGP configuration information is a set of necessary configuration parameters for establishing BGP neighbor relationships, including, but not limited to, the local AS number (Autonomous System Number), the peer AS number, the BGP router identifier (RouterID), the update source interface, the keep-alive time, the retransmission interval, and the authentication key.

[0071] In this embodiment, the SD-WAN controller sends the generated BGP configuration information to the gateway device as the configuration input for initializing its local BGP process. This information is transmitted through a secure and reliable signaling channel and, after being parsed by the gateway device, is written into the configuration context of its local routing protocol module. When the gateway device receives the BGP configuration information, it uses the previously established FOU tunnel based on the tunnel configuration information as the underlying transmission path, starts the BGP state machine on the encrypted data channel, and initiates Open message interactions with each associated device, thereby completing the establishment of BGP neighbor relationships. This achieves routing protocol bearing over a secure tunnel, enabling each gateway device to maintain a unified routing view while remaining logically isolated.

[0072] The above describes the networking method provided in this embodiment from the perspective of the SD-WAN controller. The following describes the networking method from the perspective of the gateway device. Please refer to [link / reference]. Figure 6 , Figure 6 This is a flowchart illustrating a networking method applied to a gateway device provided in this embodiment. The method includes the following steps: Step S201: When the gateway device joins the SD-WAN network, it sends a registration request to the SD-WAN controller in the SD-WAN network.

[0073] Step S202: Receive tunnel configuration information between the gateway device and the associated device sent by the SD-WAN controller. The associated device is determined by the SD-WAN controller from the SD-WAN network based on the registration request, and belongs to the same communication network as the gateway device. The gateway device in the SD-WAN network is of type central gateway and is connected to multiple communication networks.

[0074] Step S203: Based on the tunnel configuration information, establish a tunnel between the gateway device and the associated device.

[0075] The method provided in this embodiment achieves interconnection between gateway devices in the SD-WAN network. Since the gateway device (type 1) is connected to multiple communication networks within the SD-WAN network, it can communicate directly with other gateway devices within the same communication network via tunnels, and it can also communicate with gateway devices belonging to other communication networks through the gateway device (type 1). This eliminates the need for a central node in a centrally-radial network, enabling data transmission within the same communication network and between different communication networks, thus avoiding the problem of "multi-cloud islands."

[0076] In this embodiment, based on establishing a tunnel, a method for forwarding data packets is also provided: First, receive data packets sent by the server to the destination device; In this embodiment, the gateway device receives a data packet sent by a server to a destination device. This data packet originates from a server directly connected to the gateway device or reachable via a local area network (LAN), and its destination address points to a specific destination device. This destination device may be located within the same communication network or distributed across other communication networks. Upon receiving the data packet, the gateway device resolves its destination IP address and, in conjunction with its locally maintained routing table or the mapping information of the communication network identifier, determines whether the destination device belongs to the same communication network as the current gateway device.

[0077] Secondly, if the target device and the gateway device belong to the same communication network, the target associated device is determined from the associated devices of type edge gateway; otherwise, the target associated device is determined from the associated devices of type central gateway. Finally, data packets are sent through a tunnel between the gateway device and the target associated device to ensure that the data packets reach the destination device.

[0078] In this embodiment, if the destination device and the gateway device are determined to belong to the same communication network, the target associated device is determined from the associated devices of type edge gateway; otherwise, the target associated device is determined from the associated devices of type central gateway. When the destination device is in the same communication network, selecting an associated device of type edge gateway as the target enables direct forwarding at the same layer, reducing the latency overhead caused by cross-layer transmission. When the destination device is in different communication networks, selecting an associated device of type central gateway as the target leverages the ability of the central gateway to pre-establish connections with multiple communication networks, ensuring that cross-domain traffic can be routed and transferred through a core node with multi-network access capabilities.

[0079] It should also be noted that when neighbor relationships are established over tunnels in an SD-WAN network, SD-WAN will monitor the performance of each link in real time (e.g., latency and packet loss rate) and map it to the length information of the BGP AS-Path as a metric for route optimization. The central gateway has the ability to dynamically adjust the AS-Path length, first determining an optimal path based on the AS-Path length, and then determining the target associated devices based on the optimal path. In addition, load balancing and fault avoidance can also be performed based on the AS-Path length.

[0080] To perform the corresponding steps of the networking method applied to the SD-WAN controller in the above embodiments and various possible implementations, an implementation of a networking device 100 applied to the SD-WAN controller is given below. Please refer to... Figure 7 , Figure 7 This is a block diagram of a networking device applied to an SD-WAN controller provided in this embodiment. It should be noted that the basic principle and technical effects of the networking device 100 applied to an SD-WAN controller provided by the present invention are the same as those of the corresponding embodiments described above. For the sake of brevity, this embodiment does not mention or specify these aspects.

[0081] The networking device 100 applied to the SD-WAN controller includes a registration request receiving module 110, a determination module 120, and a configuration information sending module 130.

[0082] The registration request receiving module 110 is used to receive the registration request sent by the gateway device when it joins the SD-WAN network.

[0083] The determination module 120 is used to determine the associated device from the SD-WAN network based on the registration request. The associated device and the gateway device belong to the same communication network. The gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks.

[0084] The configuration information sending module 130 is used to send tunnel configuration information between the gateway device and the associated device to the gateway device, so that the gateway device can establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

[0085] In an optional implementation, the gateway device is a central gateway, and the configuration information sending module 130 is specifically used for: Based on the configuration information of the first FOU tunnel between the gateway device and the associated device of type central gateway generated by the preset private network, the preset private network is used to connect the gateway device of type central gateway in the SD-WAN network; The second FOU tunnel configuration information between the gateway device and the associated device of type edge gateway is generated based on the communication network; Send the configuration information of the first FOU tunnel and the configuration information of the second FOU tunnel to the gateway device.

[0086] In an optional implementation, the gateway device is an edge gateway, and the configuration information sending module 130 is further used for: Generate FOU tunnel configuration information between the gateway device and associated devices based on the communication network; Send the FOU tunnel configuration information to the gateway device.

[0087] In an optional implementation, the gateway device acting as the primary device in the SD-WAN network belongs to the first logical plane, and the gateway device acting as the backup device in the SD-WAN network belongs to the second logical plane. The determining module 120 is specifically used for: Based on the registration request, obtain the target logical plane to which the gateway device belongs; Identify the associated devices from other gateway devices in the SD-WAN network that belong to the target logical plane.

[0088] In an optional implementation, the configuration information sending module 130 is further configured to: Generate BGP configuration information between the gateway device and associated devices based on the tunnel configuration information; The BGP configuration information is sent to the gateway device so that the gateway device can establish a neighbor relationship between the gateway device and the associated device based on the tunnel between the gateway device and the associated device and the BGP configuration information.

[0089] To perform the corresponding steps of the networking method applied to a gateway device in the above embodiments and various possible implementations, an implementation of a networking device 200 applied to a gateway device is given below. Please refer to... Figure 8 , Figure 8 This is a block diagram of a networking device applied to a gateway device provided in this embodiment. It should be noted that the basic principle and technical effects of the networking device 200 applied to a gateway device provided by the present invention are the same as those of the corresponding embodiments described above. For the sake of brevity, some parts of this embodiment are not mentioned.

[0090] The networking device 200 applied to the gateway device includes a registration request sending module 210, a configuration information receiving module 220, and a configuration module 230.

[0091] The registration request sending module 210 is used to send a registration request to the SD-WAN controller in the SD-WAN network when the gateway device joins the SD-WAN network.

[0092] The configuration information receiving module 220 is used to receive tunnel configuration information between the gateway device and the associated device sent by the SD-WAN controller. The associated device is determined by the SD-WAN controller from the SD-WAN network based on the registration request and belongs to the same communication network as the gateway device. The gateway device in the SD-WAN network is of the type of central gateway and is connected to multiple communication networks. Configuration module 230 is used to establish a tunnel between the gateway device and the associated device based on tunnel configuration information.

[0093] In an optional implementation, multiple associated devices are used. The gateway device communicates with the server. The networking device applied to the gateway device further includes a packet sending module 240, which is used for: Receive data packets sent by the server to the destination device; If the target device and the gateway device belong to the same communication network, the target associated device is determined from the associated devices of type edge gateway; otherwise, the target associated device is determined from the associated devices of type central gateway. Data packets are sent through a tunnel between the gateway device and the target associated device to ensure that the data packets reach the destination device.

[0094] This invention provides a computer-readable storage medium storing a computer program thereon. When executed by a controller, the computer program implements the networking method applied to an SD-WAN controller as described in the foregoing embodiments, or implements the networking method applied to a gateway device as described in the foregoing embodiments.

[0095] In summary, the present invention provides a networking method, apparatus, network device, and computer-readable storage medium. The method includes: receiving a registration request sent by a gateway device when joining an SD-WAN network; determining associated devices from the SD-WAN network based on the registration request, wherein the associated devices are other gateway devices belonging to the same communication network as the gateway device, and the gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks; and sending tunnel configuration information between the gateway device and the associated devices to the gateway device so that the gateway device establishes a tunnel between the gateway device and the associated devices based on the tunnel configuration information. Compared with the prior art, the present invention has at least the following advantages: (1) Since the gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks, the gateway device can communicate directly with other gateway devices in the same communication network through a tunnel, and can also communicate with gateway devices belonging to other communication networks through the gateway device of type central gateway, thereby realizing the interconnection between the gateway devices in the SD-WAN network. Because this invention achieves data transmission within the same communication network and between different communication networks without the need to set up a central node in a central radial network, it avoids the problem of "multi-cloud islands", realizes efficient and reliable interconnection of a large number of heterogeneous edge nodes, and has strong fault self-healing capabilities, ensuring network stability and efficient data transmission; (2) After receiving the configuration information from the SD-WAN controller, the gateway device automatically completes the gateway initialization and creates a FOU tunnel locally, so that all gateway devices form a logically interconnected network, and each gateway device automatically publishes the local network segment route of its computer room to the network; (3) The central gateway and the data center inside SD-WAN switches establish BGP neighbor relationships and inject routing information (including edge network segments) in the SD-WAN network into the data center network, thereby achieving seamless interconnection between the data center and all edge nodes; (4) When a central computer room fails, data packets can automatically bypass through the internal network of other central computer rooms to ensure uninterrupted service; (5) Through the tunnel between the central gateway and the edge gateway and the tunnel based on the private network between the central gateways, the problem of mutual access between different communication networks is solved, and seamless communication between edge devices is achieved through the central node; (6) Based on AS-Path and network performance, traffic paths can be finely controlled to adapt to various scenarios such as cutover and cost optimization.

[0096] The above descriptions are merely various embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A networking method, characterized in that, The method includes: Receive the registration request sent by the gateway device when it joins the SD-WAN network; Based on the registration request, an associated device is determined from the SD-WAN network. The associated device and the gateway device belong to the same communication network. The gateway device in the SD-WAN network, which is of the type of central gateway, is connected to multiple communication networks. The tunnel configuration information between the gateway device and the associated device is sent to the gateway device so that the gateway device can establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

2. The method according to claim 1, characterized in that, The gateway device is a central gateway, and the step of sending the tunnel configuration information between the gateway device and the associated device to the gateway device includes: The first FOU tunnel configuration information between the gateway device and the associated device of type central gateway is generated based on the preset private network. The preset private network is used to connect the gateway device of type central gateway in the SD-WAN network. Based on the communication network, a second FOU tunnel configuration information is generated between the gateway device and the associated device of type edge gateway; The first FOU tunnel configuration information and the second FOU tunnel configuration information are sent to the gateway device.

3. The method according to claim 1, characterized in that, The gateway device is an edge gateway, and the step of sending the tunnel configuration information between the gateway device and the associated device to the gateway device includes: Based on the communication network, FOU tunnel configuration information is generated between the gateway device and the associated device; The FOU tunnel configuration information is sent to the gateway device.

4. The method according to claim 1, characterized in that, In the SD-WAN network, the gateway device acting as the primary device belongs to the first logical plane, and the gateway device acting as the backup device belongs to the second logical plane. The step of determining the associated device of the gateway device from the SD-WAN network based on the registration request includes: Based on the registration request, the target logical plane to which the gateway device belongs is obtained; The associated device is determined from other gateway devices in the SD-WAN network that belong to the target logical plane.

5. The method according to any one of claims 1-4, characterized in that, The method further includes: Based on the tunnel configuration information, BGP configuration information between the gateway device and the associated device is generated; The BGP configuration information is sent to the gateway device so that the gateway device can establish a neighbor relationship between the gateway device and the associated device based on the tunnel between the gateway device and the associated device and the BGP configuration information.

6. A networking method, characterized in that, The method includes: When a gateway device joins an SD-WAN network, it sends a registration request to the SD-WAN controller in the SD-WAN network. The system receives tunnel configuration information between the gateway device and the associated device sent by the SD-WAN controller. The associated device is determined by the SD-WAN controller from the SD-WAN network based on the registration request and belongs to the same communication network as the gateway device. The gateway device in the SD-WAN network is of type central gateway and is connected to multiple communication networks. Based on the tunnel configuration information, a tunnel is established between the gateway device and the associated device.

7. The method according to claim 6, characterized in that, The associated devices are multiple, the gateway device is communicatively connected to the server, and the method further includes: Receive data packets sent by the server to the destination device; If the target device and the gateway device belong to the same communication network, the target associated device is determined from the associated devices of type edge gateway; otherwise, the target associated device is determined from the associated devices of type central gateway. The data packet is sent through a tunnel between the gateway device and the target associated device so that the data packet reaches the destination device.

8. A networking device, characterized in that, The device includes: The registration request receiving module is used to receive registration requests sent by gateway devices when they join the SD-WAN network; The determination module is used to determine the associated device from the SD-WAN network based on the registration request. The associated device and the gateway device belong to the same communication network. The gateway device of type central gateway in the SD-WAN network is connected to multiple communication networks. The configuration information sending module is used to send tunnel configuration information between the gateway device and the associated device to the gateway device, so that the gateway device can establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

9. A networking device, characterized in that, The device includes: The registration request sending module is used to send a registration request to the SD-WAN controller in the SD-WAN network when the gateway device joins the SD-WAN network; The configuration information receiving module is used to receive tunnel configuration information between the gateway device and the associated device sent by the SD-WAN controller. The associated device is determined by the SD-WAN controller from the SD-WAN network based on the registration request and belongs to the same communication network as the gateway device. A configuration module is used to establish a tunnel between the gateway device and the associated device based on the tunnel configuration information.

10. A network device, characterized in that, It includes a controller and a memory, the memory being used to store a program, and the controller being used to implement the networking method as described in any one of claims 1-5, or the networking method as described in any one of claims 6-7, when executing the program.

11. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by the controller, implements the networking method as described in any one of claims 1-8, or implements the networking method as described in any one of claims 6-7.