Source load balancing of data packets

By receiving notifications from the destination end through the source-side load balancer, identifying and transmitting network traffic, the latency and complexity issues caused by destination-side load balancing are resolved, achieving more efficient network traffic management.

CN121967417APending Publication Date: 2026-05-01CISCO TECHNOLOGY INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CISCO TECHNOLOGY INC
Filing Date
2024-11-06
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, load balancing is usually performed at the destination side, which leads to increased delays in the initial handshake establishment and increased complexity in routing decisions, affecting network performance and reliability.

Method used

The load balancing logic is moved to the source side. The source load balancer receives the destination's advertisement, determines the network traffic distribution, and transmits the traffic to the destination. It uses BGP advertisements and other methods to transmit available subnet prefixes for load balancing.

Benefits of technology

It reduces the processing burden at the destination, improves the efficiency and flexibility of network traffic, reduces latency, and enhances network reliability and availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967417A_ABST
    Figure CN121967417A_ABST
Patent Text Reader

Abstract

The invention discloses source-end load balancing for data packets. Disclosed is a method of load balancing on the source side rather than the destination side of a network. The destination network can communicate with the source-end load balancer over a transport network protocol advertisement, such as a border gateway protocol (BGP) advertisement. The announcements can deliver prefixes representing available subnets to achieve the purpose of load balancing. Then, the source-end load balancer will load balance the network traffic, and transmit the network traffic along a path composed of at least part of the prefix advertised by the network.
Need to check novelty before this filing date? Find Prior Art

Description

Source load balancing of data packets Technical Field

[0001] This application relates to network communications, and more specifically to load balancing of data packets within a network. Background Technology

[0002] Load balancing is a complex problem in networking. It involves distributing network traffic across multiple servers or resources to prevent a single server from becoming overwhelmed. This can optimize performance, improve response times, and enhance the reliability and availability of applications or services. Summary of the Invention

[0003] According to a first aspect of this disclosure, a method is provided, comprising: receiving, at a load balancer at a source end, an advertisement from a network device at a destination end, the advertisement including a prefix indicating an available subnet at the destination end; determining, via the load balancer at the source end, a distribution of network traffic from the source end; and transmitting, via the load balancer at the source end, the network traffic to the destination end.

[0004] According to a second aspect of this disclosure, a load balancer is provided, comprising: a storage device configured to store instructions; and at least one processor configured to execute the instructions and cause the at least one processor to perform the following operations: at a source end, receiving an advertisement from a network device at a destination end, the advertisement including a prefix indicating an available subnet at the destination end; at the source end, determining the distribution of network traffic from the source end; and at the source end, transmitting the network traffic to the destination end.

[0005] According to a third aspect of this disclosure, a non-transitory computer-readable storage medium is provided, including instructions that, when executed by at least one processor, cause the at least one processor to perform the following operations: at a source end, receiving a notification from a destination end network device, the notification including a prefix indicating an available subnet at the destination end; at the source end, determining the distribution of network traffic from the source end; and at the source end, transmitting the network traffic to the destination end. Attached Figure Description

[0006] To describe how the above and other advantages and features of this application can be obtained, the principles briefly described above will be described in more detail with reference to specific embodiments shown in the accompanying drawings. It should be understood that these drawings depict only exemplary embodiments of this application and are therefore not intended to be considered as limiting its scope. The principles herein are described and explained in more detail through the use of the drawings, in which:

[0007] Figure 1 illustrates an example of a high-level network architecture according to at least some embodiments of the present disclosure.

[0008] Figure 2 illustrates an example communication network comprising one or more Autonomous Systems (ASes) according to at least some embodiments of the present disclosure.

[0009] Figure 3 shows a schematic diagram conceptually illustrating the transmission of data packets between data centers according to at least some embodiments of the present disclosure.

[0010] Figure 4 illustrates a routine for load balancing network traffic at the source location according to at least some embodiments of the present disclosure.

[0011] Figure 5 shows an example of a system used to implement certain aspects of this disclosure. Detailed Implementation

[0012] Various embodiments of this application will now be discussed in detail. While specific implementations are discussed, it should be understood that this is merely illustrative. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of this application. Therefore, the following description and drawings are merely illustrative and should not be construed as limiting. Numerous specific details are described herein to provide a comprehensive understanding of this application. However, in some cases, well-known or conventional details have not been described to avoid obscuring the description. References to one embodiment or an embodiment in this application may be references to the same embodiment or any embodiment; and such references mean at least one embodiment of the described embodiments.

[0013] The reference to "an embodiment" or "an embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of this application. The phrase "in one embodiment" appearing in various locations throughout the specification does not necessarily refer to the same embodiment, and individual or alternative embodiments are not mutually exclusive with other embodiments. Furthermore, the various features described may be exhibited in some embodiments but not others.

[0014] As used herein, the term "configurable" should be considered interchangeable with "configurable" and "configurable," except where the terms "configurable" and "configurable" are explicitly distinguished. The correct understanding of the term will be apparent to those skilled in the art in the context of its use.

[0015] The terms used in this specification generally have their ordinary meaning in the art, in the context of this application, and in the specific context in which each term is used. Any one or more terms discussed herein may be replaced with alternative language and synonyms, and should not have any particular significance in whether a particular term is set forth or discussed herein. In some cases, synonyms for certain terms are provided. The description of one or more synonyms does not preclude the use of other synonyms. Examples used anywhere in this specification (including examples of any terms discussed herein) are for illustrative purposes only and are not intended to further limit the scope and meaning of this application or any example terms. Similarly, this application is not limited to the various different embodiments given in this specification.

[0016] Without intending to limit the scope of this application, examples of instruments, apparatus, methods, and related results according to embodiments of this application are given below. It should be noted that headings or subheadings may be used in the examples for ease of reading, but this should in no way limit the scope of this application. Unless otherwise defined, the technical and scientific terms used herein have the meanings commonly understood by one of ordinary skill in the art related to this application. In case of any conflict, this document, including the definitions, shall prevail.

[0017] Additional features and advantages of this application will be set forth in the description below, and in part will be apparent from the description, or may be learned by practicing the principles disclosed herein. The features and advantages of this application can be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. These and other features of this application will become more apparent from the following description and the appended claims, or may be learned by practicing the principles set forth herein.

[0018] Overview

[0019] Many years ago, in an era when technology was still booming, making a phone call was an adventure in itself. In those days, people picked up a rotary phone and summoned the familiar voice of a local telephone operator. This operator, often a friendly and familiar person in a small town, would write down the required number and then connect the call by plugging and unplugging wires onto a giant switchboard. The local operator ensured that voices from faraway places could be brought together, weaving connections across miles.

[0020] Current load balancing methods are the opposite of past operator methods. Load balancing typically occurs on the destination side, not the source side. Load balancing at the destination data center introduces latency to the initial handshake, as routing decisions add additional processing time. Furthermore, moving data packets up the chain of command can be delayed due to the increased complexity and potential bottlenecks in the load balancer's decision-making process.

[0021] The currently disclosed technology draws inspiration from the historical telephone operator, moving network logic closer to the source, rather than leaving traffic distribution to the destination. More specifically, the currently disclosed technology performs load balancing at the source, not the destination. The destination network can communicate with the source load balancer via network protocol advertisements (such as Border Gateway Protocol (BGP) advertisements). These advertisements can convey prefixes indicating available subnets for load balancing purposes. The source load balancer then load balances the network traffic and transmits it along paths defined by the prefixes advertised by the network.

[0022] Therefore, the currently disclosed technology avoids placing an excessive burden on the destination side of the network in terms of packet processing and load balancing operations. It also allows the destination side to move more virtual IP addresses to a single node (if preferred), thus providing flexibility. In the event of a failure, the destination side can also move virtual IP addresses to a working node instead of retaining them on the failed node.

[0023] In some embodiments, this disclosure includes a method, load balancer, or computer-readable medium having instructions for performing the following: at a load balancer at a source end, receiving an advertisement from a destination-end network device, the advertisement including a prefix indicating an available subnet at the destination end; determining the distribution of network traffic from the source end via the load balancer at the source end; and transmitting the network traffic to the destination end via the load balancer at the source end.

[0024] In some embodiments, the announcement is a Border Gateway Protocol (BGP) announcement.

[0025] In some embodiments, this disclosure includes receiving an indication from a network device at the destination end, indicating that an IP address within the available subnet is capable of receiving the network traffic from the source end.

[0026] In some embodiments, this disclosure includes receiving a second announcement from the network device, the second announcement being based on network analysis or user input from a user on the network device at the destination end, announcing different pools of IP addresses as the available subnets.

[0027] In some embodiments, this disclosure includes determining the destination IP address of the available subnet including the network traffic by means of a load balancer at the source end, wherein transmitting the network traffic includes transmitting the network traffic to an available subnet including the destination IP address.

[0028] In some embodiments, transmitting the network traffic to the destination via a load balancer at the source end includes: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the destination IP address is included in the IP addresses of the available subnet; and providing an indication within the network traffic indicating that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address, or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.

[0029] In some embodiments, the destination is at least one of a data center, server, cloud computing environment, virtual machine, network storage device, router, switch, or firewall.

[0030] Example Implementation

[0031] Figure 1 illustrates an example of a network architecture 100 used to implement various aspects of this disclosure. An example of an implementation of the network architecture 100 is... SD-WAN architecture. However, those skilled in the art will understand that for network architecture 100 and any other system discussed in this application, there may be more or fewer components in similar or alternative configurations. For the sake of brevity, illustrations and examples are provided in this application. Other embodiments may include different numbers and / or types of elements, but those skilled in the art will understand that such variations do not depart from the scope of this application.

[0032] In this example, network architecture 100 may include an orchestration plane 102, a management plane 106, a control plane 112, and a data plane 116. Orchestration plane 102 can assist edge network devices 118 (e.g., switches, routers, etc.) in automatically boarding up the overlay network. Orchestration plane 102 may include one or more physical or virtual network orchestrator devices 104. Network orchestrator device 104 can perform initial authentication of the edge network devices 118 and orchestrate connectivity between devices in the control plane 112 and the data plane 116. In some embodiments, network orchestrator device 104 can also enable devices located behind Network Address Translation (NAT) to communicate. In some embodiments, physical or virtual... The SD-WAN vBond device can operate as a network orchestrator device 104.

[0033] The management plane 106 is responsible for the central configuration and monitoring of the network. The management plane 106 may include one or more physical or virtual network management devices 110. In some embodiments, the network management device 110 may provide centralized management of the network via a graphical user interface, enabling users to monitor, configure, and maintain edge network devices 118 and links (e.g., Internet transport network 128, MPLS network 130, 4G / mobile network 132) in the underlay network and upper-layer network. The network management device 110 may support multi-tenancy and provide centralized management of logically isolated networks associated with different entities (e.g., enterprises, departments within enterprises, groups within departments, etc.). Alternatively or additionally, the network management device 110 may also be a dedicated network management system for a single entity. In some embodiments, physical or virtual The SD-WAN vManage device can operate as a network management device 110. The management plane 106 may also include an analytics engine 108, which is well known in the art.

[0034] Control plane 112 can build and maintain network topology and make decisions on traffic flow. Control plane 112 may include one or more physical or virtual network control devices 114. Network control devices 114 can establish secure connections with each edge network device 118 and distribute routing and policy information via control plane protocols (e.g., Upper Management Protocol (OMP) (discussed in further detail below), Open Shortest Path First (OSPF), Intermediate System to Intermediate System (IS-IS), Border Gateway Protocol (BGP), Protocol Independent Multicast (PIM), Internet Group Management Protocol (IGMP), Internet Control Message Protocol (ICMP), Address Resolution Protocol (ARP), Bidirectional Forwarding Detection (BFD), Link Aggregation Control Protocol (LACP), etc.). In some embodiments, network control device 114 may operate as a route reflector. Network control device 114 can also orchestrate secure connectivity between edge network devices 118 in data plane 116. For example, in some embodiments, network control device 114 may distribute encryption key information among edge network devices 118. This allows the network to support secure network protocols or applications (e.g., Internet Protocol Security (IPSec), Transport Layer Security (TLS), Secure Shell (SSH), etc.) without using Internet Key Exchange (IKE), and enables network scalability. In some embodiments, physical or virtual The SD-WAN vSmart controller can operate as a network control device 114.

[0035] Data plane 116 is responsible for forwarding packets based on decisions from control plane 112. Data plane 116 may include edge network device 118, which may be a physical or virtual edge network device. Edge network device 118 can operate at the edge of various network environments within an organization, such as in one or more data centers 126, campus networks 124, branch office networks 122, headquarters networks 120, etc., or in the cloud (e.g., Infrastructure as a Service (IaaS), Platform as a Service (PaaS), SaaS, and other cloud service provider networks). Edge network device 118 can provide secure data plane connectivity between sites via one or more WAN transports, such as via one or more Internet transport networks 128 (e.g., Digital Subscriber Line (DSL), cable, etc.), MPLS network 130 (or other private packet switching networks (e.g., Metro Ethernet)). Edge network devices 118 can handle tasks such as traffic forwarding, security, encryption, quality of service (QoS), and routing (e.g., BGP, OSPF). In some embodiments, physical or virtual... The SD-WAN vEdge router can operate as an edge network device 118.

[0036] A computer network is a geographically distributed collection of nodes interconnected by communication links and segments, used to transmit data between end nodes (such as personal computers and workstations) or other network devices (such as sensors). Various types of networks are available, ranging from Local Area Networks (LANs) to Wide Area Networks (WANs). LANs typically connect nodes via dedicated, private communication links located in the same conventional physical location, such as a building or campus. WANs, on the other hand, typically connect geographically dispersed nodes via long-distance communication links. The Internet is an example of a WAN, connecting disparate networks around the world to provide global communication between nodes on various different networks. Nodes typically communicate over a network by exchanging discrete data frames or packets according to predefined protocols, such as Transmission Control Protocol / Internet Protocol (TCP / IP). In this context, the protocol consists of a set of rules that define how nodes interact.

[0037] Because managing interconnected computer networks can be burdensome, smaller groups of computer networks can be maintained as routing domains or autonomous systems. An Autonomous System (AS) is a network or group of networks under common control and sharing a common routing policy. A typical example of an AS is a network controlled and maintained by an Internet Service Provider (ISP). Customer networks (such as universities or companies) connect to the ISP, and the ISP routes network traffic from the customer network to network destinations, which may be within the same ISP or reachable only through other ISPs.

[0038] To facilitate network traffic routing through one or more Access Gateways (ASes), network elements within an ASe need to exchange routing information to various network destinations. Border Gateway Protocol (BGP) is an Exterior Gateway Protocol (EGP) used to exchange routing information between network elements (e.g., routers) within the same or different ASes. The computer host executing the BGP process is typically called a BGP host or BGP network device. To exchange BGP routing information, two BGP hosts or peers must first establish a Transport Protocol (TPP) connection. Initially, BGP peers exchange messages to open a BGP session. Once the BGP session is open, the BGP peers exchange all of their routing information. Afterward, BGP peers only exchange or advertise updates or changes to routing information. During the BGP session, the exchanged routing information is maintained by the BGP peers.

[0039] Networks within an AS are typically interconnected by regular "intra-domain" routers configured to perform intra-domain routing protocols and are generally governed by a common authority. To improve routing scalability, service providers (e.g., ISPs) can divide an AS into multiple "areas" or "levels." However, it may be necessary to increase the number of nodes capable of exchanging data; in this case, inter-domain routers performing inter-domain routing protocols are used to interconnect the nodes of various different ASes. Furthermore, it is also desirable to interconnect various different ASes operating under different regulatory domains. AS, area, or level as used herein are collectively referred to as a "domain."

[0040] Figure 2 is a schematic block diagram of an example computer network 200, which exemplarily includes network devices 214 interconnected by various different communication methods. For example, communication path 202 can be any suitable combination of wired links and shared media (e.g., wireless links, Internet exchange points, etc.), wherein some network devices 214 (such as, for example, routers, computers, etc.) can communicate with other network devices 214 (e.g., based on distance, signal strength, current operating status, location, etc.). Those skilled in the art will understand that any number of network devices 214, links, etc., can be used in a computer network, and the views shown herein are for simplicity only.

[0041] The network devices 214 of computer network 200 may exchange data packets (e.g., traffic and / or messages sent between network devices 214) using predefined network communication protocols (such as certain known wired protocols, as well as wireless protocols or other shared medium protocols (where appropriate)).

[0042] Computer network 200 comprises a set of Autonomous Systems (AS), designated AS204, AS206, AS208, AS210, and AS212. Computer network 200 can be located in any suitable network environment or communication architecture that uses any appropriate routing protocol or data management standard to manage or otherwise direct information. For example, computer network 200 can be configured in conjunction with the Border Gateway Protocol (BGP).

[0043] As described above, an AS can be a collection of Internet Protocol (IP) routing network devices 214 connected under the control of one or more network operators, providing a common, well-defined routing policy to a network (e.g., the Internet). Typically, an AS includes network devices 214 established at the edge of the system and serving as the ingress and egress points for network traffic. Furthermore, network devices 214 can be considered as edge network devices, border routers, or core network devices within their respective ASs. These network devices are typically (but not always) routers or any other element of the network infrastructure suitable for exchanging or forwarding data packets according to routing or switching protocols. For the purposes of this application, network devices 214 located within an AS can also be referred to as "forwarding network devices" or "intermediate network devices." Furthermore, for ease of illustration, the number of network devices 214 shown within AS204, AS206, AS208, AS210, and AS212 is limited. However, in actual implementations, an AS typically includes numerous routers, switches, and other components.

[0044] Each AS204, AS206, AS208, AS210, and AS212 can be associated with an Internet Service Provider (ISP). Even if a single ISP supports multiple ASes, the internet can only see the ISP's routing policies. ISPs must have officially registered Autonomous System Numbers (ASNs). Therefore, each AS is assigned a unique ASN for BGP routing. ASNs are important primarily because they uniquely identify each network on the internet.

[0045] To facilitate the routing of network traffic through ASs (more specifically, network devices 214 within ASes), network devices can exchange routing information to various different network destinations. As mentioned above, BGP is conventionally used to exchange routing and reachability information between network devices 214 within a single AS or between different ASes. A specific example of BGP is BGPv4, as defined in the Internet Engineering Task Force (IETF) Request for Comment (RFC) 1771. However, various different embodiments can also implement other versions of BGP, and the use of BGPv4 is not required. The data collector uses the router's BGP logic to collect BGP AS path information from the BGP tables of the AS's border routers, such as the "AS_PATH" attribute, which will be described further below, to construct paths to prefixes.

[0046] To exchange BGP routing information, two BGP hosts (network device 214) or peers must first establish a transport protocol connection with each other. Initially, the BGP peers exchange messages to open a BGP session. After the BGP session is open, the BGP peers exchange all of their routing information. Subsequently, in some embodiments, the BGP peers only exchange or announce updates or changes to routing information (e.g., the "BGPUPDATE" attribute). The exchanged routing information is maintained by the BGP peers during the BGP session.

[0047] BGP routing information can include a complete route from a BGP host to each network destination (e.g., a "destination network device"). A route or path includes the address destination, typically indicated by an address prefix (also called a prefix), and information describing the path to that address destination. An address prefix can be represented as a combination of a network address and a mask indicating how many bits in the address are used to identify the network portion of the address. For example, in Internet Protocol version 4 (IPv4) addressing, an address prefix might be represented as "9.2.0.2 / 16". " / 16" indicates that the first 16 bits are used to identify a unique network, and the remaining bits in the address are used to identify a specific host within that network.

[0048] A path that combines multiple ASes (e.g., communication path 202) can be called an "AS_PATH". The AS_PATH attribute indicates a list of ASes that must be traversed to reach the address destination. For example, as shown in Figure 2, AS212 can store the AS_PATH attribute "204 206 210 212", where the address destination is AS212 (or a specific IP address within AS212). Here, the AS_PATH attribute indicates that the path from AS208 to the address destination AS212 passes through AS204, AS206, and AS210 in sequence.

[0049] While it may be preferred that all network devices 214 in AS204, AS206, AS208, AS210, and AS212 are configured according to BGP, in practical implementations, it may be impractical for every network device to communicate using BGP. Therefore, the disclosed embodiments are applicable to scenarios where all network devices 214 in computer network 200 are configured according to BGP, as well as scenarios where only a subset of network devices 214 are configured according to BGP. Furthermore, as shown in FIG2, there may be a single communication path 202 between any AS, for example, between AS204 and AS208, or there may be multiple communication paths 202, for example, between AS208 and AS210. Therefore, the disclosed embodiments are applicable to either situation, which will be described in further detail below.

[0050] Furthermore, a security extension to BGP, called BGPSEC, has been developed, providing improved security for BGP routes. BGP does not include a mechanism that allows ASs to verify the legitimacy and authenticity of BGP route advertisements. Resource Public Key Infrastructure (RPKI) has taken the first step towards addressing the validity of BGP route data. BGPSEC extends RPKI by adding an additional type of certificate called a BGPSEC router certificate, which binds an AS number to a public signature verification key, with the corresponding private key held by one or more BGP speakers within that AS. The private key corresponding to the public key in this type of certificate can be used within BGPSEC, allowing BGP speakers to sign on behalf of their AS. Therefore, the certificate allows dependent parties to verify that the BGPSEC signature was generated by a BGP speaker belonging to a given AS. Thus, the goal of BGPSEC is to use signatures to protect the AS path attributes of BGP update messages so that BGP speakers can evaluate the validity of the AS path in the update messages they receive. However, it should be understood that the embodiments disclosed herein for implementing AS path security are not limited to BGPSEC; some embodiments may also be adapted to other suitable protocols, including, for example, SoBGP, S-BGP, and PGPBGP.

[0051] Figure 3 illustrates a conceptual diagram of the transmission of data packets between data centers according to at least some embodiments of the present disclosure. As shown, network 300 includes a source end 302 and a destination end 304. For example, source end 302 may be a client device capable of transmitting network traffic, such as a computer, smartphone, or IoT device. Alternatively, source end 302 may be a collection of such devices (e.g., one or more devices having a source IP address (represented as source IP address 306 in Figure 3) and connected to a load balancer 308 that determines the distribution of network traffic from source end 302). Destination end 304 may be a single device, multiple devices, a subnet, a collection of subnets, or a geographical area. For example, as shown, destination end 304 may be at least one of a data center, server, cloud computing environment, virtual machine, network storage device, router, switch, or firewall.

[0052] As shown in the figure, the destination 304 may include multiple subnets, including a first subnet 310, a second subnet 312, and a third subnet 314. The destination 304 may also include multiple terminal IP addresses, namely the destination IP address 316 in the figure. In this way, this disclosure can transmit data packets or other network traffic from the source 302 to the destination IP address 316 via the load balancer 308. The load balancer 308 can transmit network traffic via the first subnet 310, which serves as the "next-hop subnet," instead of the conventional routing method of sending traffic via a next-hop IP address with Layer 2 connectivity from a neighboring router. For example, and without limitation, the load balancer 308 can transmit network traffic to an IP address that includes a netmask representing the subnet. The load balancer 308 may do this by advertising the prefixes of the IP addresses to which the load balancer can transmit network traffic based on network protocol advertisements (e.g., BGP advertisements). Then, the first subnet 310 can route network traffic to the second subnet 312 or the third subnet 314, depending on which subnet is configured to receive network traffic based on the load balancing algorithm received at the load balancer 308. The second subnet 312 or the third subnet 314 can then route the traffic to the destination subnet 318 and the appropriate destination IP address.

[0053] The above process allows source 302 to transfer network traffic from its load balancer 308 to destination IP address 316 of destination 304. In this process, destination 304 does not need to set up a load balancer within its destination network, but can benefit from the load balancer 308 of source 302. Destination 304 can also enjoy flexibility by configuring which available subnets (e.g., first subnet 310, second subnet 312, third subnet 314, or destination subnet 318) receive network traffic from external load balancers. Destination 304 can identify available subnets by advertising BGP or other network protocols to source 302. Of course, the schematic diagram in Figure 3 is merely exemplary, and network traffic can be directly transferred from source 302 to first subnet 310, second subnet 312, third subnet 314, or destination subnet 318 as needed by the network controller associated with destination 304.

[0054] Figure 4 illustrates a routine for load balancing network traffic at the source location according to at least some embodiments of the present disclosure. Although example routine 400 depicts a specific sequence of operations, the sequence can be changed without departing from the scope of this application. For example, some of the depicted operations may be performed in parallel or in a different order, without materially affecting the functionality of routine 400. In other examples, different components of the example device or system implementing routine 400 may perform functions at substantially the same time or in a specific sequence.

[0055] According to some examples, routine 400 includes, at block 402, receiving an advertisement from a destination network device at the source end of the load balancer. This advertisement includes a prefix indicating an available subnet at the destination end. For example, load balancer 308 in Figure 3 could receive an advertisement from a destination network device that includes a prefix indicating an available subnet at the destination end. A network mask can be included in the advertisement, and the load balancer can use this network mask to calculate the number of hosts that may exist in the subnet and determine whether the subnet can accommodate incoming traffic load.

[0056] The advertisement may include prefixes of available IP addresses, for which data traffic can be routed by the load balancer 308. As discussed above, the advertisement may be a BGP advertisement. However, this disclosure is not limited to this, and the advertisement may be an advertisement of any network protocol. For example, the advertisement may be an OSPF (Open Shortest Path First) advertisement, in which routes are shared within the autonomous system to optimize routing decisions. It may also be an EIGRP (Enhanced Interior Gateway Routing Protocol) advertisement, which is known for its efficiency and fast convergence in large network environments. Other possibilities include RIP (Routing Information Protocol) advertisements, which are relatively simple and often used in smaller networks, or IS-IS (Intermediate System to Intermediate System) advertisements, used in complex networks, such as those operated by Internet Service Providers.

[0057] According to some examples, routine 400 includes block 404, where a load balancer at the source end determines the distribution of network traffic originating from the source. For example, load balancer 308 in Figure 3 can determine the distribution of network traffic originating from the source. Therefore, load balancer 308 can perform load balancing at source 302 based on available prefixes advertised by destination 304. For example, destination 304 can include a subnet defined using a specific network mask in its advertisement, effectively advertising a "next-hop subnet" instead of the regular next-hop IP address. This approach allows for a wider range of networks to be included in routing information, which is particularly useful in large-scale or hierarchical networks. By specifying a network mask and IP prefixes (such as "192.168.0.0 / 16" or "10.0.0.0 / 8"), the destination end can transmit not only a single IP address but also an entire range of IP addresses belonging to a subnet. These subnets (or networks containing subnets) can then transmit packets to the next subnet based on a load balancing algorithm implemented at the source by the load balancer 308 but determined by the destination 304. Thus, although there is no physically present load balancer at the destination 304, the destination 304 can still benefit from flexible, user-customized load balancing.

[0058] According to some examples, routine 400 includes block 406, which transmits network traffic to the destination via a load balancer at the source end. For example, load balancer 308 in Figure 3 can transmit network traffic to the destination end. This transmission can be based on a load balancing algorithm determined by the destination end 304, such as an algorithm advertised by a BGP advertisement from a router within the subnet at the destination end. In one embodiment, the advertisement can be advertised to a group of network devices (e.g., routers). These nodes will generate routing information, including metadata about the routes they can handle. This metadata may include traffic handling capabilities, routing preferences, or other relevant information that helps in making routing decisions. Multiple route advertisements are then merged into a single unified route advertisement and sent to the source end. The benefit of doing this is that it simplifies the routing table and reduces the overhead of routers processing multiple advertisements. By aggregating routes, the network can improve efficiency and reduce the amount of routing information that must be exchanged between routers. The next-hop IP address can be encoded not as a single IP address, but as the origin of another network. Specifically, it can be encoded using an IP address network mask to qualify the subnet.

[0059] Therefore, this disclosure differs from conventional BGP routing that routes packets to the next-hop address. Here, the technique routes packets to a next-hop prefix encoded as a specific community. Therefore, this technique can support a wide range of load balancing methods, such as Equal Cost Multipath (ECMP) load balancing or weighted load balancing configured at the destination subnet. Administrators at the destination subnet can allocate more IP addresses on the same edge node, giving that node a higher weight than nodes serving a single IP address.

[0060] In some embodiments, routine 400 may include a load balancer at the source end determining the destination IP address of the subnet containing network traffic. For example, load balancer 308 in FIG3 may determine the destination IP address of the subnet containing network traffic. The load balancer may do this by analyzing advertisements from the source end and the available destination IP addresses of the subnet. The load balancer may then route the network traffic to the destination end. For example, routing network traffic may include routing network traffic to the subnet containing the destination IP address. In this way, the load balancer can understand which subnet at the destination end contains the destination IP address and efficiently route network traffic to that subnet as part or in part of the load balancing algorithm, thereby improving efficiency.

[0061] In some embodiments, routine 400 may include routing network traffic to a gateway router in a subnet; providing a destination IP address to the gateway router in the subnet to allow the gateway router to determine whether the network traffic includes a destination IP address contained within the IP address set of the subnet; and providing an indication within the network traffic indicating that if the destination IP address is within the subnet, the network traffic should be routed to that destination IP address, or if the destination IP address is not within the subnet, the network traffic should be routed to a second subnet. For example, load balancer 308 may route network traffic to a gateway router in a subnet; provide a destination IP address to the gateway router in the subnet to allow the gateway router to determine whether the network traffic includes a destination IP address contained within the IP address set of the subnet; and provide an indication within the network traffic indicating that if the destination IP address is within the subnet, the network traffic should be routed to that destination IP address, or if the destination IP address is not within the subnet, the network traffic should be routed to a second subnet. In this process, load balancer 308 may dynamically adjust its routing table based on real-time analysis of network traffic and IP address availability, thereby directing the destination gateway router. Load balancers can use protocol extensions or custom fields to tag packets with specific routing instructions or priorities. This allows load balancers to efficiently route traffic, ensuring that packets are sent to the appropriate gateway based on current network conditions and routing policies.

[0062] In some embodiments, routine 400 may include receiving an indication from a destination network device indicating that IP addresses within a subnet are capable of receiving network traffic from the source. Routine 400 may also include receiving a second advertisement from the network device, which, based on network analysis or user input on the destination network device, advertises different pools of IP addresses as subnets. For example, load balancer 308 in Figure 3 may receive this information. These indications from the destination may be provided after the destination server configures the destination to receive data according to a certain load balancing algorithm. For example, traffic is typically sent to the entry point of a data center, and load balancing is performed locally within the data center. However, here, load balancing may be performed by load balancer 308 at the source 302, and then the destination 304 may configure itself according to a preferred algorithm. The source and its associated subnets are responsible for verifying that all destination IP addresses are owned or accessible by the source network device advertised by the transport protocol. By doing so, the receiving side gains greater flexibility even if load balancing is performed on the source side. The receiving side can place more IP addresses on a node / subnet as needed, or move these IP addresses to another node / subnet.

[0063] Therefore, routine 400 avoids the loss of information exchange in the destination data center. It eliminates the need for a handshake every time data traffic moves up or down a layer, yet still achieves load balancing.

[0064] Figure 5 illustrates an example of a computing system 500, which can be, for example, any computing device constituting a controller (e.g., a controller for an SD-WAN network, or any component thereof, wherein components of the system communicate with each other using connection 502). Connection 502 can be a physical connection via a bus, or it can be a direct connection to a processor 504, such as in a chipset architecture. Connection 502 can also be a virtual connection, a networked connection, or a logical connection.

[0065] In some embodiments, the computing system 500 is a distributed system, wherein the functions described herein may be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more of the system components represent a plurality of such components, each component performing some or all of the functions of the component. In some embodiments, a component may be a physical or virtual device.

[0066] The example computing system 500 includes at least one processing unit (CPU or processor) 504 and connections 502 that link various system components, including system memory 508, such as read-only memory (ROM) 510 and random access memory (RAM) 512, to the processor 504. The computing system 500 may include a cache 506 of high-speed memory, which is directly connected to, close to, or integrated into the processor 504.

[0067] Processor 504 may include any general-purpose processor and hardware or software services, such as services 516, 518, and 520 stored in storage device 514, which are configured to control processor 504 and dedicated processors that incorporate software instructions into the actual processor design. Processor 504 can essentially be a completely self-contained computing system, containing multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors can be symmetric or asymmetric.

[0068] To enable user interaction, the computing system 500 includes an input device 526, which can represent any number of input mechanisms, such as a microphone for speech, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice input, etc. The computing system 500 may also include an output device 522, which can be one or more of a variety of output mechanisms known to those skilled in the art. In some cases, a multimodal system allows users to provide multiple types of input / output to communicate with the computing system 500. The computing system 500 may include a communication interface 524, which typically controls and manages user input and system output. It is not limited to operation on any particular hardware layout; therefore, these basic features can be easily replaced once an improved hardware or firmware layout is developed.

[0069] Storage device 514 may be a non-volatile storage device and may be a hard disk or other type of computer-readable medium that can store computer-accessible data, such as magnetic tape, flash memory card, solid-state storage device, digital multifunction disk, magnetic tape cassette, random access memory (RAM), read-only memory (ROM), and / or a combination of these devices.

[0070] Storage device 514 may include software services, servers, etc., which, when the code defining such software is executed by processor 504, cause the system to perform a certain function. In some embodiments, hardware services that perform a specific function may include software components stored in a computer-readable medium, which are connected to necessary hardware components (such as processor 504, connection 502, output device 522, etc.) to perform the function.

[0071] For ease of explanation, in some cases, this disclosure may be described as including individual functional blocks, including functional blocks containing devices, device components, steps or routines in a method embodied in software, or combinations of hardware and software.

[0072] Any step, operation, function, or process described herein may be performed or implemented by hardware and software services or combinations of services, alone or in combination with other devices. In some embodiments, a service may be software residing in the memory of a client device and / or in one or more servers of a content management system, which performs one or more functions when the processor executes the software associated with the service. In some embodiments, a service is a program or collection of programs that performs a specific function. In some embodiments, a service may be considered a server. Memory may be a non-transitory computer-readable medium.

[0073] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, by reference, non-transitory computer-readable storage media explicitly exclude media such as energy, carrier signals, electromagnetic waves, and the signals themselves.

[0074] The methods described in the examples above can be implemented using computer-executable instructions, which may be stored in or otherwise obtained from a computer-readable medium. Such instructions may include, for example, instructions and data that cause or otherwise configure a general-purpose computer, special-purpose computer, or special-purpose processing device to perform a function or a set of functions. A portion of the computer resources used may be accessible via a network. Executable computer instructions may be, for example, binary files, intermediate format instructions (such as assembly language), firmware, or source code. Examples of computer-readable media that may be used to store the instructions, information, and / or information created during the methods according to the examples include disks or optical discs, solid-state storage devices, flash memory, USB devices with non-volatile memory, networked storage devices, etc.

[0075] Devices implementing the methods according to the above disclosure may include hardware, firmware, and / or software, and may take on various form factors. Typical examples of such form factors include servers, laptop computers, smartphones, minicomputers, personal digital assistants, etc. The functionality described herein may also be embodied in peripherals or expansion cards. Further examples include implementations between different chips on a circuit board or in different processes executing within a single device.

[0076] Instructions, media for transmitting such instructions, computing resources for executing such instructions, and other structures for supporting such computing resources are all means of providing the functionality described in these disclosures.

[0077] Aspect 1. A method comprising: receiving, at a load balancer at a source end, an advertisement from a network device at a destination end, the advertisement including a prefix indicating an available subnet at the destination end; determining, via the load balancer at the source end, a distribution of network traffic from the source end; and transmitting, via the load balancer at the source end, the network traffic to the destination end.

[0078] Aspect 2. The method according to aspect 1, wherein the announcement is a Border Gateway Protocol (BGP) announcement.

[0079] Aspect 3. The method according to aspect 1 further includes receiving an indication from a network device at the destination end, indicating that an IP address within the available subnet is capable of receiving the network traffic from the source end.

[0080] Aspect 4. The method according to aspect 1 further includes receiving a second announcement from the network device, the second announcement being based on network analysis or user input from a user on the network device at the destination end, announcing different pools of IP addresses as the available subnets.

[0081] Aspect 5. The method according to aspect 1 further includes determining the destination IP address of the available subnet including the network traffic by means of a load balancer at the source end, wherein transmitting the network traffic includes transmitting the network traffic to an available subnet including the destination IP address.

[0082] Aspect 6. The method according to Aspect 1, wherein transmitting the network traffic to the destination via a load balancer at the source end comprises: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the destination IP address is included in the IP addresses of the available subnet; and providing an indication within the network traffic indicating that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address, or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.

[0083] Aspect 7. The method according to aspect 1, wherein the destination is at least one of a data center, server, cloud computing environment, virtual machine, network storage device, router, switch or firewall.

[0084] Aspect 8. A load balancer, comprising: a storage device configured to store instructions; and at least one processor configured to execute the instructions and cause the at least one processor to perform the following operations: at a source end, receiving an advertisement from a destination end network device, the advertisement including a prefix indicating an available subnet at the destination end; at the source end, determining the distribution of network traffic from the source end; and at the source end, transmitting the network traffic to the destination end.

[0085] Aspect 9. The load balancer according to aspect 8, wherein the announcement is a Border Gateway Protocol (BGP) announcement.

[0086] Aspect 10. The load balancer according to aspect 8, wherein the at least one processor is configured to execute the instructions, and further causes the at least one processor to receive an indication from a network device at the destination end, indicating that an IP address within the available subnet is capable of receiving the network traffic from the source end.

[0087] Aspect 11. The load balancer according to aspect 8, wherein the at least one processor is configured to execute the instructions, and further causes the at least one processor to receive a second announcement from the network device, the second announcement being based on network analysis or user input from a user on the network device at the destination end, announcing different pools of IP addresses as the available subnets.

[0088] Aspect 12. The load balancer according to aspect 8, wherein the at least one processor is configured to execute the instructions, and further causes the at least one processor to perform the following operations: at the source end, determining the destination IP address of the available subnet including the network traffic, wherein transmitting the network traffic includes transmitting the network traffic to the available subnet including the destination IP address.

[0089] Aspect 13. The load balancer according to Aspect 8, wherein the instruction to transmit the network traffic to the destination via the load balancer at the source end includes: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the network traffic includes a destination IP address contained within the IP address of the available subnet; and providing an indication within the network traffic indicating that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address, or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.

[0090] Aspect 14. The load balancer according to aspect 8, wherein the destination is at least one of a data center, server, cloud computing environment, virtual machine, network storage device, router, switch or firewall.

[0091] Aspect 15. A non-transitory computer-readable storage medium comprising instructions that, when executed by at least one processor, cause the at least one processor to perform the following operations: at a source end, receiving an advertisement from a destination end network device, the advertisement including a prefix indicating an available subnet at the destination end; at the source end, determining a distribution of network traffic from the source end; and at the source end, transmitting the network traffic to the destination end.

[0092] Aspect 16. The non-transitory computer-readable storage medium according to aspect 15, wherein the announcement is a Border Gateway Protocol (BGP) announcement.

[0093] Aspect 17. The non-transitory computer-readable storage medium according to aspect 15, wherein the at least one processor is configured to execute the instructions, and further causes the at least one processor to receive an indication from a network device at the destination end, indicating that an IP address within the available subnet is capable of receiving the network traffic from the source end.

[0094] Aspect 18. The non-transitory computer-readable storage medium according to aspect 15, wherein the at least one processor is configured to execute the instructions, and further causes the at least one processor to receive a second announcement from the network device, the second announcement being based on network analysis or user input from a user on the network device at the destination end, announcing different pools of IP addresses as the available subnets.

[0095] Aspect 19. The non-transitory computer-readable storage medium according to aspect 15, wherein the at least one processor is configured to execute the instructions, and further causes the at least one processor to perform the following operations: at the source end, determining the available subnet including the destination IP address of the network traffic, wherein transmitting the network traffic includes transmitting the network traffic to the available subnet including the destination IP address.

[0096] Aspect 20. The non-transitory computer-readable storage medium according to aspect 15, wherein the instruction to transmit the network traffic at the source end to the destination end includes: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the destination IP address is included in the IP addresses of the available subnet; and providing an indication within the network traffic indicating that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address, or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.

Claims

1. A method comprising: At the load balancer at the source end, an advertisement from the network device at the destination end is received, the advertisement including a prefix indicating the availability of a subnet at the destination end; The distribution of network traffic from the source is determined by the load balancer at the source. And the network traffic is transmitted to the destination via the load balancer at the source end.

2. The method according to claim 1, wherein, The announcement is a Border Gateway Protocol (BGP) announcement.

3. The method of claim 1, further comprising receiving an indication from the network device at the destination end, indicating that an IP address within the available subnet is capable of receiving the network traffic from the source end.

4. The method of claim 1, further comprising receiving a second announcement from the network device, the second announcement being based on network analysis or user input at the network device at the destination end, announcing different pools of IP addresses as the available subnets.

5. The method according to claim 1, further comprising: The load balancer at the source end determines the destination IP address of the network traffic within the available subnet, wherein transmitting the network traffic includes transmitting the network traffic to the available subnet that includes the destination IP address.

6. The method according to claim 1, wherein, Transmitting the network traffic to the destination via the load balancer at the source end includes: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the destination IP address is included in the IP addresses of the available subnet; and providing an indication within the network traffic indicating that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address; or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.

7. The method according to claim 1, wherein, The destination is at least one of a data center, server, cloud computing environment, virtual machine, network storage device, router, switch or firewall.

8. A load balancer, comprising: Storage devices, configured to store instructions; And at least one processor configured to execute the instructions and cause the at least one processor to perform the following operations: at the source end, receiving an announcement from a network device at the destination end, the announcement including a prefix indicating an available subnet at the destination end; at the source end, determining the distribution of network traffic from the source end; and at the source end, transmitting the network traffic to the destination end.

9. The load balancer according to claim 8, wherein, The announcement is a BGP announcement.

10. The load balancer according to claim 8, wherein, The at least one processor is configured to execute the instructions and further enable the at least one processor to receive an indication from the network device at the destination end, indicating that the IP address within the available subnet is capable of receiving the network traffic from the source end.

11. The load balancer according to claim 8, wherein, The at least one processor is configured to execute the instructions and further cause the at least one processor to receive a second announcement from the network device, the second announcement being based on network analysis or user input at the network device at the destination end, announcing different pools of IP addresses as the available subnets.

12. The load balancer according to claim 8, wherein, The at least one processor is configured to execute the instructions and further cause the at least one processor to perform the following operations: at the source end, determining the available subnet containing the destination IP address of the network traffic, wherein transmitting the network traffic includes transmitting the network traffic to an available subnet containing the destination IP address.

13. The load balancer according to claim 8, wherein, The instruction to transmit the network traffic to the destination via the load balancer at the source end includes: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the network traffic includes a destination IP address contained within the IP address of the available subnet; and providing an indication within the network traffic that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address; or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.

14. The load balancer according to claim 8, wherein, The destination is at least one of a data center, server, cloud computing environment, virtual machine, network storage device, router, switch or firewall.

15. A non-transitory computer-readable storage medium comprising instructions that, when executed by at least one processor, cause the at least one processor to perform the following operations: at a source end, receiving an advertisement from a destination end network device, the advertisement including a prefix indicating an available subnet at the destination end; at the source end, determining the distribution of network traffic from the source end; and at the source end, transmitting the network traffic to the destination end.

16. The non-transitory computer-readable storage medium according to claim 15, wherein, The announcement is a BGP announcement.

17. The non-transitory computer-readable storage medium according to claim 15, wherein, The at least one processor is configured to execute the instructions and further enable the at least one processor to receive an indication from the network device at the destination end, indicating that the IP address within the available subnet is capable of receiving the network traffic from the source end.

18. The non-transitory computer-readable storage medium according to claim 15, wherein, The at least one processor is configured to execute the instructions and further cause the at least one processor to receive a second announcement from the network device, the second announcement being based on network analysis or user input from the user on the network device at the destination end, announcing different pools of IP addresses as the available subnets.

19. The non-transitory computer-readable storage medium according to claim 15, wherein, The at least one processor is configured to execute the instructions and further cause the at least one processor to perform the following operations: at the source end, determining the available subnet containing the destination IP address of the network traffic, wherein transmitting the network traffic includes transmitting the network traffic to an available subnet containing the destination IP address.

20. The non-transitory computer-readable storage medium according to claim 15, wherein, The instruction to transmit the network traffic from the source end to the destination end includes: transmitting the network traffic to a gateway router of the available subnet; providing a destination IP address to the gateway router of the available subnet to allow the gateway router to determine whether the destination IP address is included in the IP addresses of the available subnet; and providing an indication within the network traffic that if the destination IP address is within the available subnet, the network traffic is transmitted to the destination IP address; or if the destination IP address is not within the available subnet, the network traffic is transmitted to a second subnet.