Sdwan wide area network networking method
By utilizing the SDWAN wide area network topology, and leveraging the collaborative work of cloud servers and node devices, the problems of high complexity, poor scalability, and complex security management in traditional network topology are solved. This enables automated configuration, intelligent path selection, and centralized management, thereby improving network reliability and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING INHAND NETWORKS TECH
- Filing Date
- 2025-01-03
- Publication Date
- 2026-07-03
Smart Images

Figure CN122339872A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer network equipment management technology, and in particular to an SDWAN wide area network topology method. Background Technology
[0002] With the development of cloud computing and mobile office, the requirements for network reliability, maintainability, scalability, and performance are constantly increasing, and traditional networks can no longer meet these demands. Currently, traditional networks face the following multiple problems: 1. High network configuration complexity: Traditional networking requires manual configuration of each network device, which is cumbersome and prone to errors. 2. Poor network scalability: When adding branches or adjusting the network topology, traditional networking methods require replanning IP addresses, adjusting routing settings, etc., increasing the difficulty of expansion. 3. Lack of end-to-end visibility: Traditional networking lacks comprehensive network visualization capabilities, making global monitoring and management difficult. 4. Complex network security management: Security policies in traditional networks usually need to be configured individually on each device, making centralized and unified management difficult. These problems limit the flexibility and scalability of traditional networks, failing to meet the growing needs of modern enterprises.
[0003] Therefore, it is evident that a new WAN networking method is needed to overcome the shortcomings of existing WAN management technologies. Summary of the Invention
[0004] The technical objective of this invention is to provide an SDWAN wide area network (WAN) networking method. A WAN based on this method can achieve the following: 1. Automated deployment and configuration: This method uses a central controller to achieve automated network configuration and zero-contact deployment. 2. Intelligent path selection: This method can intelligently select routes based on real-time network conditions, optimizing application performance. 3. Centralized management and visibility: This method provides a unified management platform, enabling real-time monitoring and visualization of network status. 4. Integrated security functions: This method incorporates the IPsec protocol to achieve end-to-end data encryption, simplifying security management.
[0005] Based on the above technical objectives, this invention provides an SDWAN wide area network topology method, the method comprising:
[0006] S100: Determine the node devices for network formation and enable them to subscribe to the tunnel configuration topic published by the cloud server. The tunnel configuration topic is published by the cloud server based on the MQTT protocol, and each node device determined to form a network subscribes to the tunnel configuration topic before the network goes online.
[0007] S101, after the node device goes online, it reports to the cloud server, and the cloud server publishes the tunnel configuration information in the tunnel configuration topic, which is then received by the node devices that subscribe to the topic.
[0008] S102, Create network topology. The cloud server generates logical tunnel information based on the network topology and node device interfaces, and publishes it through tunnel configuration topics.
[0009] S103, after receiving the logical tunnel information published by the cloud server, the node device performs the following steps:
[0010] e. Establish point-to-point connections between routers between interfaces of connected node devices in the network topology based on the IPsec protocol;
[0011] f. Route distribution based on the Border Gateway Protocol;
[0012] g. Establish a one-to-one VXLAN interface for each node device;
[0013] h. Establish a tunnel connection using the VXLAN interface.
[0014] S104: After the node device completes the tunnel connection, it reports the tunnel status to the cloud server.
[0015] In one embodiment, when a node device detects an abnormality in the current network link status, the node device triggers a link switching mechanism.
[0016] In one embodiment, when a node device modifies its local network configuration, the cloud server reissues the tunnel configuration information to the node device.
[0017] Compared with the prior art, one or more embodiments of the present invention may have the following advantages:
[0018] 1. The networking method of the present invention can use a simple configuration interface, with built-in device negotiation and docking parameters, allowing users to quickly establish networks between branches and headquarters without professional network technology.
[0019] 2. The equipment establishes a network tunnel through multiple outgoing links, and link failures can be flexibly transferred.
[0020] 3. Easy expansion: When network expansion is needed, users only need to manage the network within the platform and add new devices to the network. Simple maintenance: Through cloud + edge collaboration, the health status of links can be remotely monitored on the cloud platform, allowing for timely detection of network problems. Overcoming performance bottlenecks: Devices establish tunnels through multiple links, achieving automatic failover.
[0021] 4. Network Security: IPsec encryption technology addresses security risks, preventing unauthorized access, data tampering, eavesdropping, and other security threats. Short Deployment Cycle: Cloud-based and client-side integration enables remote maintenance and plug-and-play functionality, with unified management across multiple sites, eliminating the need for maintenance personnel to configure each system individually on-site.
[0022] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the description and the drawings. Attached Figure Description
[0023] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with the embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0024] Figure 1 This is a schematic diagram of the SDWAN wide area network topology method of the present invention. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings.
[0026] It should be understood that when an element or layer is referred to as "on," "adjacent to," "connected to," or "coupled to" other elements or layers, it may be directly on, adjacent to, connected to, or coupled to other elements or layers, or there may be intervening elements or layers. Conversely, when an element is referred to as "directly on," "directly adjacent to," "directly connected to," or "directly coupled to" other elements or layers, there are no intervening elements or layers. It should be understood that although the terms first, second, third, etc., may be used to describe various elements, components, areas, layers, and / or portions, these elements, components, areas, layers, and / or portions should not be limited by these terms. These terms are only used to distinguish one element, component, area, layer, or portion from another element, component, area, layer, or portion. Therefore, without departing from the teachings of this invention, the first element, component, area, layer, or portion discussed below may be referred to as a second element, component, area, layer, or portion. And when a second element, component, area, layer, or portion is discussed, it does not imply that the first element, component, area, layer, or portion necessarily exists in this invention.
[0027] Spatial relation terms such as “below,” “under,” “below,” “under,” “above,” “above,” etc., are used herein for convenience of description to describe the relationship between one element or feature shown in the figure and other elements or features. It should be understood that, in addition to the orientation shown in the figure, spatial relation terms are intended to also include different orientations of the device in use and operation. For example, if the device in the figure is flipped, then the element or feature described as “below,” “under,” or “below” other elements or features will be oriented “above” other elements or features. Therefore, the exemplary terms “below” and “under” can include both above and below orientations. The device may be otherwise oriented (rotated 90 degrees or otherwise) and the spatial descriptive terms used herein will be interpreted accordingly.
[0028] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. When used herein, the singular forms “a,” “an,” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the terms “comprising” and / or “including,” when used in this specification, identify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups. When used herein, the term “and / or” includes any and all combinations of the associated listed items.
[0029] Example 1
[0030] like Figure 1 The SDWAN wide area network networking method of the present invention shown includes:
[0031] S100: Determine the node devices for network formation and enable them to subscribe to the tunnel configuration topic published by the cloud server. The tunnel configuration topic is published by the cloud server based on the MQTT protocol, and each node device determined to form a network subscribes to the tunnel configuration topic before the network goes online.
[0032] S101, after the node device goes online, it reports to the cloud server, and the cloud server publishes the tunnel configuration information in the tunnel configuration topic, which is then received by the node devices that subscribe to the topic.
[0033] S102, Create network topology. The cloud server generates logical tunnel information based on the network topology and node device interfaces, and publishes it through tunnel configuration topics.
[0034] S103, after receiving the logical tunnel information published by the cloud server, the node device performs the following steps:
[0035] i. Establish point-to-point connections between routers between the interfaces of connected node devices in the network topology based on the IPsec protocol;
[0036] j. Route distribution based on the Border Gateway Protocol;
[0037] k. Establish a one-to-one VXLAN interface for each node device;
[0038] l. Establish a tunnel connection using the VXLAN interface.
[0039] S104: After the node device completes the tunnel connection, it reports the tunnel status to the cloud server.
[0040] In this embodiment, when the device detects a poor current network link status (such as weak signal, high latency, or increased packet loss rate), it automatically triggers a link switching mechanism. The device quickly switches to a backup link based on the backup link in the configuration file to ensure network connectivity continuity and stability. During the link switching process, the device selects the optimal backup link through load monitoring and link health checks. To reduce service interruption time, the device uses a parallel switching mechanism, i.e., while the current link is still available, it tests the feasibility of the backup link in advance to ensure a seamless switching process. After a successful switch, the device periodically monitors the current link status and reports it to the cloud platform for network administrators to monitor and optimize.
[0041] In this embodiment, when a node device modifies its local network configuration, the cloud server reissues the tunnel configuration information to the node device.
[0042] The networking method of this invention combines the communication capabilities of cloud servers and devices. The cloud server can obtain the uplink status of devices, ensuring network connection stability and providing accurate link information monitoring. This communication capability provides a reliable foundation for device management and network optimization. On the cloud server platform, a network topology is first defined and constructed according to business requirements, allowing devices to dynamically join preset networks. The network topology can be flexibly adjusted to adapt to changes in business and supports efficient device access and expansion. Automatic configuration file generation: Based on the defined network topology, the cloud server automatically generates a corresponding configuration file for each device. The configuration file contains network parameters and other configurations customized according to business requirements, ensuring that devices can operate efficiently in the network. Configuration file distribution via task scheduling: Once the configuration file is generated, the cloud server distributes the configuration file to each device through a task scheduling system, realizing an automated deployment process. This effectively reduces errors from manual operation and improves the accuracy of device configuration and management efficiency. Device VPN tunnel establishment: After receiving the configuration file distributed by the cloud server, the device automatically initiates a VPN connection request according to the network parameters in the configuration. The device also needs to periodically monitor the VPN connection status. Once a connection interruption or anomaly is detected, the device should automatically retry to establish a connection according to the configuration, ensuring the continuous stability and availability of the network. Device link switching: The link switching mechanism ensures that the device can seamlessly switch to the backup link when the network condition is poor, while maintaining the secure connection of the VPN tunnel and ensuring the continuity and stability of services.
[0043] The networking method of this invention enables contactless configuration: allowing devices to be automatically configured upon network insertion, eliminating the need for manual on-site configuration and greatly simplifying the deployment process, especially for branch offices or remote sites. Centralized control and management: Centralized management and configuration of the entire WAN via a cloud platform enables network visualization, monitoring, policy push, and automated adjustment across multiple sites. Intelligent path selection: Automatically selects the optimal network path for traffic transmission based on real-time network conditions (such as latency, jitter, packet loss rate), ensuring efficient application operation. Dynamic link failover: When a network link fails or its performance degrades, traffic is automatically and in real-time switched to a backup link, ensuring uninterrupted service. Security integration and end-to-end encryption: Built-in encryption, intrusion prevention, and other security functions, and end-to-end data encryption via the IPsec protocol. Real-time monitoring and analysis: The ability to monitor network links, application performance, and device status in real-time, providing data analysis and visualization interfaces to help administrators quickly identify and optimize problems.
[0044] This invention can be any possible system, method, and / or computer program product at the level of integrated technical detail. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to execute aspects of the invention.
[0045] A computer-readable storage medium can be a tangible device that can hold and store instructions used by an instruction execution device. The computer-readable storage medium can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer floppy disk, a hard disk, random access memory (RAM), read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), a portable optical disc read-only memory (CD-ROM), a digital universal disc (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or raised structure in a groove on which instructions are recorded, and any suitable combination of the foregoing. A computer-readable storage medium, as used herein, should not be construed as a transient signal itself, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0046] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a suitable computing / processing device, or via a network, such as the Internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network, to an external computer or external storage device. This network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the suitable computing / processing device.
[0047] Computer-readable program instructions used to perform the operations of this invention may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, configuration data for integrated circuits, or source code or object code written in one or more programming languages and any combination of procedural programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer, partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet through an Internet service provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) may execute the computer-readable program instructions by utilizing state information from the computer-readable program instructions to personalize the electronic circuitry and thereby perform aspects of the invention.
[0048] This document describes aspects of the invention with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0049] These computer-readable program instructions can be provided to a computer's processor or other programmable data processing device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, create a mechanism for implementing flowcharts and / or blocks. Figure 1 Means of the functions / actions specified in one or more blocks. These computer-readable program instructions may also be stored in a computer-readable storage medium capable of guiding a computer, a programmable data processing apparatus and / or other apparatus operating in a particular manner, such that the computer-readable storage medium storing the instructions includes an article of manufacture comprising instructions for implementing aspects of the functions / actions specified in the flowchart and / or block diagram blocks.
[0050] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other apparatus to cause a series of operational steps to be performed on the computer, other programmable devices or other apparatuses for producing computer-implemented processes, such that the instructions executed on the computer, other programmable devices or other apparatuses perform the functions / actions specified in the flowchart and / or block diagram boxes.
[0051] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of instructions comprising one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions indicated in a block may occur outside the order indicated in the diagram. For example, two blocks shown consecutively may actually be completed as a single step, executed concurrently, substantially concurrently, in a manner that overlaps partially or entirely in time, depending on the functions involved, or sometimes these blocks may be executed in reverse order. It will also be noted that each block illustrated in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified function or action or executes a combination of dedicated hardware and computer instructions.
[0052] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, apparatus (devices), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0053] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0054] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
Claims
1. An SDWAN wide area network topology method, the topology method comprising: S100: Determine the node devices for network formation and enable them to subscribe to the tunnel configuration topic published by the cloud server. The tunnel configuration topic is published by the cloud server based on the MQTT protocol, and each node device selected for network formation subscribes to the tunnel configuration topic before the network goes live. S101, after the node device goes online, it reports to the cloud server, and the cloud server publishes the tunnel configuration information in the tunnel configuration topic, which is then received by the node devices that subscribe to the topic. S102, Create network topology. The cloud server generates logical tunnel information based on the network topology and node device interfaces, and publishes it through tunnel configuration topics. S103, after receiving the logical tunnel information published by the cloud server, the node device performs the following steps: a. Establish point-to-point connections between routers between the interfaces of connected node devices in the network topology based on the IPsec protocol; b. Route distribution based on the Border Gateway Protocol; c. Establish a one-to-one VXLAN interface for each node device; d. Establish a tunnel connection using the VXLAN interface; S104: After the node device completes the tunnel connection, it reports the tunnel status to the cloud server.
2. The method of claim 1, wherein, When a node device detects an abnormality in the current network link status, the node device triggers a link switching mechanism.
3. The method of claim 1, wherein, When a node device modifies its local network configuration, the cloud server reissues the tunnel configuration information to the node device.
4. A network system comprising a cloud server and a plurality of node devices, characterized by, The network system is constructed using the networking method described in any one of claims 1-3.
5. An electronic device, comprising: It includes a processor and a memory, the memory storing computer-readable instructions that, when executed by the processor, perform the method as described in any one of claims 1-3.