Hybrid cloud network construction support system and hybrid cloud network construction support method

The hybrid cloud network construction system addresses the challenge of high man-hours in SD-WAN configuration by evaluating and optimizing virtual network designs, ensuring efficient provisioning between on-premises and public clouds.

JP2025122464APending Publication Date: 2025-08-21HITACHI INFORMATION & TELECOMM ENG LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024017976
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-08
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing technologies for connecting on-premises and public clouds via SD-WAN products do not adequately account for virtual networks, leading to increased man-hours for designing and verifying configurations, as they lack the ability to quantitatively estimate the effort required and determine optimal configuration patterns.

Method used

A hybrid cloud network construction system that uses a computer to evaluate virtual network configurations via SD-WAN connected to the Internet, determining whether requirements are met based on connection and traffic specifications, and enumerating configuration patterns to calculate throughput and scores, thereby outputting the optimal configuration pattern.

Benefits of technology

Enables quantitative estimation of man-hours required for design and verification, facilitating faster and more efficient provisioning of virtual networks between on-premises and public clouds.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025122464000001_ABST
    Figure 2025122464000001_ABST
Patent Text Reader

Abstract

To evaluate the configuration of a virtual network via SD-WAN and quantitatively estimate the design and man-hour of verification required for provisioning.SOLUTION: An integrated configuration server lists virtual network configuration patterns that meet requirements on the basis of the requirements for connections and traffic between an on-premises environment and a public cloud environment, a topology table that manages the connection configuration of the SD-WAN router and virtual SD-WAN router, and a table that defines conditions for software control functions held by the router, calculates the throughput and score for each of the listed configuration patterns on the basis of the patterns, a hybrid cloud network realization environment, the software control functions, and a table that defines scores that indicate the ratio of an actual throughput to theoretical values of throughput and line speed when the functions are applied, and outputs the configuration pattern whose calculated throughput and score meet specified conditions.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a hybrid cloud network construction support system and a hybrid cloud network construction support method. [Background technology]

[0002] Recently, hybrid clouds, which combine on-premise environments such as data centres with public clouds to build systems, have become increasingly important. On-premise environments offer detailed tenant configurations that go beyond templates, while public clouds allow resources to be scaled according to requirements. Each has its own advantages, and it is important to take advantage of the benefits of both to deploy applications and data in the right places.

[0003] In the past, storage for storing data was primarily deployed on-premises, with each company providing its own appliances with their own reliability and management tools. In order to keep up with the current trend toward hybrid cloud configurations, companies are now offering virtual appliances that offer the same reliability and management capabilities as those running on public cloud virtual environments.

[0004] Data transfer methods are being developed along with storage appliances to accommodate requirements such as daily backups and disaster recovery with recovery points, as well as to move data between storage appliances deployed both on-premise and in the public cloud.

[0005] The network that supports data transfer needs to connect both on-premise and public cloud environments. Recently, a method has been supported in which a dedicated line is laid from an on-premise data centre and a designated data centre in the public cloud accepts the connection via the dedicated line. However, there are issues such as the lead time and initial costs tending to be high, making it difficult to apply this method universally when extending the connection destination of the public cloud.

[0006] Therefore, when connecting on-premises and public clouds via a closed network connection using the Internet, there is a need to cover the network for data transfer. Because the Internet is shared with other users, a single line lacks reliability and throughput. For this reason, it is known to use software-defined network technology to define a virtual network based on one or more physical Internet lines as an overlay according to requirements, and to improve performance by applying software control functions. Products with such functions are called software-defined wide area network (SD-WAN) products. An overlay generally refers to the definition of a network layer that is abstracted using software in order to run multiple independent virtualized networks on the physical layer.

[0007] SD-WAN products enable flexible reliability and throughput designs by combining flexible virtual network overlay configurations and software control functions. Furthermore, because virtual networks can be changed without changing the physical configuration, once an SD-WAN product router is deployed in an on-premises environment, the network between on-premises and public clouds can be provided as a service in accordance with the deployment of public cloud storage virtual appliance resources. This allows for faster and more flexible provisioning by providing both public cloud storage and its connecting network as a service. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] Special Publication No. 2017-518696 [Patent Document 2] Patent Publication No. 2021-87190 Summary of the Invention [Problem to be solved by the invention]

[0009] While the above-mentioned patent documents 1 and 2 both establish a connection between on-premises and public clouds, they have a problem in that they do not take into account virtual networks, including the application of software control of SD-WAN products connected to the Internet. For example, using an SD-WAN product connected to the Internet increases the number of possible configuration patterns for virtual networks, increasing the man-hours required for designing and verifying each configuration. In other words, with conventional technologies, users were unable to quantitatively estimate the man-hours required for designing and verifying when provisioning a virtual network via an SD-WAN connected to the Internet, and were unable to determine which configuration pattern would be optimal and require the least man-hours.

[0010] The present invention aims to provide a technology that can evaluate the configuration of a virtual network via an SD-WAN connected to the Internet and quantitatively estimate the design and verification effort required for provisioning. [Means for solving the problem]

[0011] The hybrid cloud network construction system according to the present invention is a hybrid cloud network construction support system that uses a computer having a processor and memory to support the construction of a hybrid cloud network in which an on-premises environment and a public cloud environment are connected via the Internet, and the processor determines whether the requirements are met based on requirements regarding connection and traffic between the on-premises environment and the public cloud environment specified by a user, a topology table for managing the network connection form via an SD-WAN router and a virtual SD-WAN router that constitute the hybrid cloud network, and a table that defines the conditions of software control functions to be held as the SD-WAN and the virtual SD-WAN. The system is configured as a hybrid cloud network construction support system, characterized in that it enumerates configuration patterns of virtual networks to be constructed, calculates the throughput and the score for each of the enumerated configuration patterns based on the enumerated configuration patterns, an environment for constructing the hybrid cloud network, the software control functions of the SD-WAN router and the virtual SD-WAN router in the environment, and a table that defines scores that are indicators showing the throughput of the hybrid cloud network when the functions are applied and the ratio of actual throughput to the theoretical value of the line speed of the hybrid cloud network, and outputs the configuration pattern for which the calculated throughput and score satisfy predetermined conditions. [Effects of the Invention]

[0012] According to the present invention, it is possible to evaluate the configuration of a virtual network via an SD-WAN connected to the Internet and quantitatively estimate the man-hours required for design and verification when performing provisioning. [Brief explanation of the drawings]

[0013] [Figure 1A] FIG. 1 is a diagram illustrating an example of the overall configuration of a hybrid cloud. [Figure 1B] FIG. 1 is a diagram illustrating an example of a computer schematic. [Figure 2] FIG. 10 is a diagram illustrating an example of a sequence for constructing a virtual network between an on-premises environment and a public cloud environment. [Figure 3] FIG. 10 is a diagram illustrating an example of an SD-WAN router topology table. [Figure 4] FIG. 10 is a diagram illustrating an example of an SD-WAN configuration pattern condition table. [Figure 5] FIG. 10 is a diagram illustrating an example of an SD-WAN function performance contribution table. [Figure 6A] 3 is a flowchart showing the operation in step 202 shown in FIG. 2. [Figure 6B] FIG. 2 is a diagram illustrating an example of a virtual network configuration pattern. [Figure 7] 3 is a flowchart showing the operation in step 203 shown in FIG. 2. [Figure 8] FIG. 10 is a diagram showing an example of output data to be displayed on the administrator terminal in step 204. [Figure 9] FIG. 10 is a diagram illustrating an example of a screen displayed on an administrator terminal. [Figure 10] FIG. 10 is a diagram illustrating an example of a sequence for constructing a virtual network between an on-premises environment and a public cloud environment. [Figure 11] FIG. 10 is a diagram showing an example of a flowchart of a process in which a setting template output unit outputs a setting template in step S1001. [Figure 12] FIG. 11 is a diagram showing an example of output data output to the administrator terminal in step 1103. [Figure 13] FIG. 10 is a diagram illustrating an example of a line status table held by the integrated setting server. [Figure 14] FIG. 10 is a flowchart illustrating an example of an operation of a setting template output unit. [Figure 15] FIG. 13 is a diagram showing an example of output data output in step 1305. [Figure 16] FIG. 1 is a diagram illustrating an example of the overall configuration of a hybrid cloud. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. The following description and drawings are examples for explaining the present invention, and some omissions and simplifications have been made as appropriate for clarity of explanation. The present invention can be implemented in various other forms. Unless otherwise specified, each component may be singular or plural.

[0015] In order to facilitate understanding of the invention, the position, size, shape, range, etc. of each component shown in the drawings may not represent the actual position, size, shape, range, etc. Therefore, the present invention is not necessarily limited to the position, size, shape, range, etc. disclosed in the drawings.

[0016] In the following explanation, various types of information may be described using expressions such as "database," "table," and "list," but the various types of information may also be expressed in data structures other than these. To indicate that the information is not dependent on the data structure, "XX table," "XX list," etc. may be referred to as "XX information." When describing identification information, expressions such as "identification information," "identifier," "name," "ID," and "number" are used, and these are interchangeable.

[0017] When there are multiple components with the same or similar functions, they may be described using the same reference numeral with different subscripts. However, when there is no need to distinguish between these multiple components, the subscripts may be omitted.

[0018] Furthermore, in the following description, processing performed by executing a program may be described, but the program is executed by a processor (e.g., a CPU or a GPU (Graphics Processing Unit)) to perform the specified processing while appropriately using storage resources (e.g., memory) and / or interface devices (e.g., communication ports), and therefore the processor may be the subject of the processing. Similarly, the subject of the processing performed by executing a program may be a controller, device, system, computer, or node having a processor. The subject of the processing performed by executing a program may be any computing unit, and may include a dedicated circuit (e.g., an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit)) that performs specific processing.

[0019] A program may be installed on a device such as a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable storage medium. If the program source is a program distribution server, the program distribution server may include a processor and storage resources for storing the program to be distributed, and the processor of the program distribution server may distribute the program to be distributed to other computers. Also, in the following description, two or more programs may be realized as one program, and one program may be realized as two or more programs. [Example]

[0020] In Example 1, a form is shown in which a virtual network using an SD-WAN product in a hybrid cloud is constructed through GUI operations by an administrator.

[0021] 1A is an overall configuration diagram of a hybrid cloud in this embodiment. As shown in FIG. 1A, a hybrid cloud 1000 is configured such that an on-premises environment 120 and a public cloud environment 130 are connected via the Internet 140, and the connection is managed by an integrated setting server 100. The integrated setting server 100 holds at least a configuration pattern enumeration unit 101, a configuration pattern evaluation unit 102, a configuration template output unit 103, an SD-WAN router topology table 111, an SD-WAN configuration pattern condition table 112, an SD-WAN function performance contribution table 113, and a GUI 115.

[0022] The specific processing performed by each unit of the integrated setting server 100 will be described later, but the integrated setting server 100 can be realized by a general computer 1600, for example, as shown in FIG. 1B (schematic diagram of a computer), which includes a CPU 1601, a memory 1602, an external storage device 1603 such as an HDD (Hard Disk Drive), a reading / writing device 1607 for reading and writing information to a portable storage medium 1608 such as a CD (Compact Disk) or USB memory, an input device 1606 such as a microphone, keyboard, or mouse for receiving input of various information including voice, an output device 1605 such as a display for outputting various information that has been input and is used for processing, a communication device 1604 such as an NIC (Network Interface Card) for connecting to a communication network, and an internal communication line (referred to as a system bus) 1609 such as a system bus that connects these together.

[0023] The CPU 1601 can read and use various data stored in or used for processing in the integrated setting server 100 from the memory 1602 or the external storage device 1603 (for example, the SD-WAN router topology table 111, the SD-WAN configuration pattern condition table 112, and the SD-WAN function performance contribution table 113). The CPU 1601 can implement each of the functional units (for example, the configuration pattern enumeration unit 101, the configuration pattern evaluation unit 102, and the configuration template output unit 103) of the integrated setting server 100 by loading a predetermined program stored in the external storage device 1603 into the memory 1602 and executing it.

[0024] The above-mentioned predetermined program may be stored (downloaded) into the external storage device 1603 from the storage medium 1608 via the reading / writing device 1607 or from a network via the communication device 1604, and then loaded onto the memory 1602 and executed by the CPU 1601. Alternatively, the program may be directly loaded onto the memory 1602 from the storage medium 1608 via the reading / writing device 1607 or from a network via the communication device 1604, and then executed by the CPU 1601.

[0025] In the following, an example is given in which the integrated setting server 100 is configured by a single computer, but all or part of these functions may be distributed across one or more computers, such as a cloud, and similar functions may be realized by communicating with each other via a network.

[0026] Returning to FIG. 1A, one or more SD-WAN routers 121 are deployed in the on-premises environment 120. In this example, multiple SD-WAN routers 121 are provided, including an SD-WAN router 121-1 that connects the on-premises device connection switch 123 to Internet gateways 122-1 and 122-2, and an SD-WAN router 121-2 that connects the on-premises device connection switch 123 to Internet gateway 122-3. While this example illustrates two SD-WAN routers, 121-1 and 121-2, the number of SD-WAN routers may be determined arbitrarily depending on the environment. Furthermore, the SD-WAN router 121 is connected to an SD-WAN configuration controller 150, and the SD-WAN router 121 configures the virtual network overlay via the SD-WAN router 121, which is implemented by the SD-WAN configuration controller 150. The SD-WAN router 121 may be a router having a conventionally known hardware configuration.

[0027] Furthermore, one or more Internet gateways (GW) 122 are provided in the on-premises environment 120 as connection ports to the Internet 140. In this example, multiple Internet gateways 122 are provided, including Internet gateway 122-1 and Internet gateway 122-2 that connect the SD-WAN router 121-1 and the Internet 140, and Internet gateway 122-3 that connects the SD-WAN router 121-2 and the Internet 140. In this example, three Internet gateways 122-1, 122-2, and 122-3 are illustrated, but the number may be determined arbitrarily depending on the environment. The Internet gateway 122 may be a gateway having a conventionally known general configuration as hardware.

[0028] Furthermore, one or more on-premises device connection switches 123 are arranged in the on-premises environment 120 to connect one or more on-premises devices 124 to one or more SD-WAN routers 121. In this example, multiple on-premises device connection switches 123 are provided, including the on-premises device connection switch 123. In this example, one on-premises device connection switch 123 is illustrated, but the number may be determined arbitrarily depending on the environment. The on-premises device connection switch 123 may be a switch having a conventionally known general configuration as hardware.

[0029] Furthermore, the on-premise environment 120 is provided with one or more on-premise devices 124 connected to the on-premise device connection switch 123. In this example, a plurality of on-premise devices 124 are provided, including an on-premise device 124-1 and an on-premise device 124-2. Here, two on-premise devices 124 are illustrated as an example, but the number may be determined arbitrarily depending on the environment. The on-premise devices 124 may be connected to devices (e.g., computers) having a conventionally known general configuration as hardware.

[0030] The on-premise environment 120 also includes an on-premise device connection switch 123 and an on-premise configuration setting tool 125 for uniformly setting the connection configuration of the on-premise devices 124. The on-premise configuration setting tool 125 runs software that reflects settings based on descriptions in a .yaml file or the like using Infrastructure as Code (IaC), and an example of such a tool is Ansible. The on-premise configuration setting tool 125 is installed on a computer having a typical hardware configuration, for example, as shown in FIG. 1B.

[0031] One or more virtual SD-WAN routers 131 are running in the public cloud environment 130. In this example, multiple virtual SD-WAN routers 131 are running, including virtual SD-WAN router 131-1, which connects the connection service 133 to virtual Internet gateways 132-1 and 132-2, and virtual SD-WAN router 131-2, which connects the connection service 133 to virtual Internet gateway 132-3. While this example illustrates two virtual SD-WAN routers, virtual SD-WAN router 131-1 and virtual SD-WAN router 131-2, the number of virtual SD-WAN routers may be determined arbitrarily depending on the environment. Furthermore, the virtual SD-WAN router 131 is connected to an SD-WAN configuration controller 150, and the virtual network overlay configuration by the virtual SD-WAN router 131 is performed by the SD-WAN configuration controller 150. The virtual SD-WAN router 131 is implemented, for example, by software installed on a computer such as the server shown in FIG. 1B, which controls the packet routing function.

[0032] Furthermore, one or more virtual internet gateways (GW) 132 are allocated to the public cloud environment 130 as connection ports to the Internet 140. In this example, multiple virtual internet gateways 132 are allocated, including virtual internet gateways 132-1 and 132-2 that connect the virtual SD-WAN router 131-1 and the Internet 140, and virtual internet gateway 132-3 that connects the virtual SD-WAN router 131-2 and the Internet 140. In this example, three virtual internet gateways 132-1, 132-2, and 132-3 are illustrated, but the number may be determined arbitrarily depending on the environment. The virtual internet gateway 132 is realized, for example, by software installed on a computer such as the server shown in FIG. 1B, and the computer controls the packet gateway function.

[0033] In addition, a connection service 133 that performs routing and the like for connecting to the virtual appliance 134 is allocated to the public cloud environment 130. In this example, multiple connection services 133 including the connection service 133 are provided. In this example, one connection service 133 is illustrated, but the number may be determined arbitrarily depending on the environment. The connection service 133 is realized, for example, by software installed on a computer such as the server shown in FIG. 1B, and the computer controls the routing function.

[0034] Furthermore, one or more virtual appliances 134 connected to the connection service 133 are allocated to the public cloud environment 130. In this example, multiple virtual appliances 134 are allocated, including a virtual appliance 134-1 and a virtual appliance 134-2. In this example, two virtual appliances 134 are illustrated, but the number may be determined arbitrarily depending on the environment. The virtual appliance 134 is configured as a virtualized machine provided by software installed on a computer such as the server shown in FIG. 1B, for example.

[0035] In addition, a public cloud configuration setting service 135 is allocated to the public cloud environment 130 to uniformly set the declaration of the virtual appliance 134 of the virtual SD-WAN router 131 and the connection settings with the connection service 133. The public cloud configuration setting service 135 is a service that reflects settings based on descriptions in a YAML file or the like using IaC, and an example of such a service is AWS CloudFormation.

[0036] The hybrid cloud 1000 also includes an SD-WAN configuration controller 150 connected via the Internet 140. The SD-WAN configuration controller 150 is a device that monitors the availability of the network between the SD-WAN router 121, Internet gateway 122, on-premises device connection switch 123, and on-premises device 124 in the on-premises environment 120 and the virtual SD-WAN router 131, virtual Internet gateway 132, connection service 133, and virtual appliance 134 in the public cloud 130 via the Internet 140, and selects paths according to the network status and manages and operates these configurations. The device is configured, for example, by a computer such as the server shown in FIG. 1B, and the above-mentioned functions are realized by software installed on the computer.

[0037] Furthermore, in the hybrid cloud 1000, the administrator operates the administrator terminal 160 to access the GUI 115 of the integrated setting server 100. The administrator terminal 160 may be configured by a general computer as shown in FIG. 1B.

[0038] Figure 2 shows a sequence diagram for constructing a virtual network overlay between the SD-WAN router 121 and the virtual SD-WAN 131 to connect the on-premises environment 120 and the public cloud environment 130 in the hybrid cloud configuration of Figure 1.

[0039] In step 201, the administrator inputs virtual network requirements from the administrator terminal 160 to the integrated setting server 100 via the GUI 115. For example, the administrator terminal 160 accepts input from the user: (1) a connection requirement for connecting the on-premise device A 124-1 and the virtual appliance 134-2; and (2) a traffic requirement for operating a storage volume copy as a single unit, and transmits the received information to the integrated setting server 100.

[0040] Step 202 is the operation of the configuration pattern enumeration unit 101. Using the connection requirements and traffic requirements received in step 201, the configuration pattern enumeration unit 101 refers to the SD-WAN router topology table 111 and the SD-WAN configuration pattern condition table 112, and enumerates virtual network configuration patterns that conform to the above-mentioned connection requirements and traffic requirements.

[0041] Step 203 is the operation of the configuration pattern evaluation unit 102. The configuration pattern evaluation unit 102 references the virtual network configuration patterns enumerated in step 202 and the SD-WAN function performance contribution table 113, and calculates quantitative scores for the enumerated virtual network configuration patterns in both normal and degenerated states. In other words, the configuration pattern evaluation unit 102 references the SD-WAN function performance contribution table 113, and calculates the normal score and the degenerated score (the rate of deterioration relative to the normal score) of the enumerated configuration patterns. A degenerated state refers to, for example, a situation in which a failure has occurred in part of the network.

[0042] Step 204 is the operation of the configuration template output unit 103. The configuration template output unit 103 receives the score for each virtual network configuration pattern calculated in step 203, and outputs to the administrator terminal 160 a notification to create a configuration template corresponding to the virtual network configuration pattern with the highest score.

[0043] In step 205, when the user creates a configuration template corresponding to the virtual network configuration pattern with the highest score, the administrator terminal 160 inputs the created configuration template of the virtual network configuration pattern into the SD-WAN configuration controller 150, the on-premises configuration setting tool 125, and the public cloud configuration setting service 135.

[0044] In step 206, upon receiving the input from step 205, the SD-WAN router 121, virtual SD-WAN router 131, on-premises device connection switch 123, and connection service 133 each apply settings according to the created setting template. Through these steps, a virtual network overlay is configured between the on-premises environment 120 and the public cloud environment 130.

[0045] Figure 3 is a diagram showing an example of the SD-WAN router topology table 111. The SD-WAN router topology table 111 is a table for managing the connection topology of SD-WAN routers and virtual SD-WAN routers that make up a hybrid cloud network. As shown in Figure 3, the SD-WAN router topology table 111 has columns 301 to 305. The SD-WAN router topology table 111 is predetermined by an administrator.

[0046] Column 301 indicates SD-WAN products such as the SD-WAN router 121 and virtual SD-WAN router 131. Column 302 indicates the physical connection destination for each SD-WAN router 301. Specifically, the Internet gateway 122, virtual Internet gateway 123, other SD-WAN routers 121, virtual SD-WAN routers 131, on-premises device connection switches 123, and connection services 133 are stored. Column 303 indicates the throughput of the Internet line to which the connection destination 302 is connected. Column 304 indicates the type of the connected Internet line. Column 305 indicates information about the vendor of the connected Internet line.

[0047] 3, for example, column 301 shows that the connection destination of the SD-WAN product "SD-WAN Router A" (SD-WAN Router 121-1) is "Internet GW A1" (Internet Gateway 122-1). Also, it shows that the contract form with Vendor A provides a "bandwidth guarantee" of "1 Gbps" for the throughput of the SD-WAN Router 121-1 via the Internet Gateway 122-1.

[0048] Figure 4 is a diagram showing an example of the SD-WAN configuration pattern condition table 112. The SD-WAN configuration pattern condition table 112 is a table that defines the conditions for software control functions to be maintained as SD-WAN routers and virtual SD-WAN routers. As shown in Figure 4, the SD-WAN configuration pattern condition table 112 is a table having columns 401 and 402. Column 401 indicates the software control functions of the SD-WAN, and column 402 indicates the conditions under which the software control functions can be applied.

[0049] Line 411 shows a transport route extension. This extension represents, for example, a TLOC (Transport LOCation) extension. TLOC extension extends the route so that not only the Internet gateway 122 and virtual Internet gateway 132 connected to the SD-WAN router 121 and virtual SD-WAN router 131, respectively, but also the Internet gateway 122 and virtual Internet gateway 132 connected to adjacent SD-WAN routers 121 and virtual SD-WAN routers 131 can be used to connect to the Internet 140. Applying TLOC extension requires mutual connection between the SD-WAN router 121 and virtual SD-WAN router 131. In other words, applying this function requires that multiple SD-WAN routers 121 are installed in a single on-premises environment 120.

[0050] Line 412 describes ECMP (Equal Cost Multi Path). ECMP is a function that assigns multiple Internet connections to a single virtual network overlay. Traffic on a single virtual network is physically distributed across multiple Internet connections. To apply ECMP, there must be connections from the SD-WAN router 121 and virtual SD-WAN router 131 to multiple Internet gateways 122 and 132, or the function of line 414 (described later) must not be applied.

[0051] Line 413 describes the TCP optimization function. TCP optimization is a function that edits traffic parameters in the virtual network between the SD-WAN router 121 in the on-premises environment 120 and the virtual SD-WAN router 131 in the public cloud 130. An example of a parameter to be edited is the TCP window size, which indicates the maximum amount of data that can be sent without receiving a receipt confirmation. Another example is the application of the congestion control algorithm BBR (Bottleneck Bandwidth and Round-trip propagation time), which has the advantage of preventing throughput degradation at the expense of traffic fairness. Applying the TCP optimization function requires that the virtual network in question be configured between the physically identical SD-WAN router 121 and virtual SD-WAN router 131 in order to maintain parameter consistency, and also requires that the function described in line 412 above not be applied.

[0052] Line 414 describes the packet duplication function. In order to mitigate the impact of packet loss between the SD-WAN router 121 and the virtual SD-WAN router 131, the packet duplication function assigns two or more physical Internet connections to one virtual network, duplicates one packet, and distributes it to multiple Internet connections. To apply the packet duplication function, there must be connections to multiple Internet gateways 122 and virtual Internet gateways 132, or TLOC extension must be used in combination. Another condition is that the function of line 412 is not applied.

[0053] Line 415 indicates FEC (Forward Error Collection). FEC is a function that adds one error correction packet to every several packets before sending them. This function can prevent the effects of a single packet loss, but reduces the bandwidth by the amount of the error correction packet. This function has a restriction that it is in an exclusive relationship with packet duplication 414. In other words, it must be used only if the function in line 414 is not applied.

[0054] Figure 5 shows an example of the SD-WAN function performance contribution table 113. The SD-WAN function performance contribution table 113 defines the environment for realizing a hybrid cloud network via an internet line, the software control functions of the SD-WAN router and virtual SD-WAN router placed in that environment, and the throughput and score of the hybrid cloud network when those functions are applied. The throughput is the actual line speed of the hybrid cloud network when a specified amount of traffic is generated in the above environment. The score is an index showing the ratio of the actual throughput to the theoretical line speed of the hybrid cloud network.

[0055] 5, the SD-WAN function performance contribution table 113 has columns 501 to 507. Values ​​in columns 501 to 504 are determined in advance based on the results of tests on traffic between the on-premises environment 120 and the public cloud 130. That is, the SD-WAN function performance contribution table 113 shown in FIG. 5 stores the function shown in column 501, the level of throughput and score that can be obtained under normal conditions, and the level of throughput and score that can be obtained under degenerated conditions, in the environment shown in column 502 and the traffic shown in column 503.

[0056] Column 501 indicates the software control function of the SD-WAN, similar to column 401 shown in Figure 4. Note that if the software control function indicated in column 501 is "packet duplication," operation using only the secondary line is not possible.

[0057] Column 502 indicates, as environmental conditions, information such as connection information for one or more Internet lines to be used, vendor information for the public cloud 130, and network delay caused by traffic between the public cloud 130 and the on-premises environment 120. The delay is determined by the distance between the public cloud 130 and the on-premises environment 120, i.e., the distance between these regions.

[0058] Column 503 shows traffic information. The traffic name is indicated as file copy or volume copy. If more detailed information, such as the expected number of parallel sessions or window size, is known, this information is stored together as the traffic name and used to find traffic that is relatively similar.

[0059] Columns 504 to 507 show the expected throughput values ​​and score values ​​when software control function 501 is applied to traffic 503 for each environmental condition 502 based on a prior evaluation.

[0060] Column 504 shows the throughput that can be expected from the hybrid cloud network under normal circumstances when there is no Internet congestion or other issues. When ECMP is used, traffic on one virtual network is allocated to multiple Internet connections, which can lead to imbalances when the number of sessions is small. This column stores the expected value relative to the theoretical value, which is a generalization of these numerical values, as the actual throughput. The theoretical value is, for example, the value stored as the bandwidth guarantee, which is one of the environmental conditions shown in column 502, and is the theoretical throughput of the hybrid cloud network obtained under those environmental conditions.

[0061] Column 505 shows the score value obtained by calculating the effective utilization rate of the line from the expected normal throughput value shown in column 504 relative to the theoretical value of the throughput of the line allocated to one virtual network. The effective utilization rate of the line is determined in advance by a communication test or the like.

[0062] Column 506 stores the expected value relative to the theoretical value as the actual throughput when a degradation occurs, such as when one Internet connection becomes inoperable due to a failure or the like.

[0063] Column 507 holds the score value at the time of the above-mentioned reduction, calculated in the same way as column 505.

[0064] 5, for example, record 508 stores, as environmental conditions, that communication between a certain on-premises environment 120 and a certain public cloud 130 is performed using either a telecommunications carrier (Vendor A) and a public cloud vendor (#8) (the vendor indicated in the vendor information of record 306 shown in FIG. 3) that guarantee a bandwidth of 1 Gbps and tolerate a latency of up to 4 ms or more, or a telecommunications carrier (Vendor B) and the public cloud vendor (#8) that guarantee a bandwidth of 1 Gbps at Best Effort (BE) and tolerate a latency of up to 5 ms. Under these environmental conditions, when the number of TCP sessions is set to 1 and an application "File Copy #1" (which copies files as a unit) is executed and traffic is generated, the realistic throughput value expected under normal circumstances between the certain on-premises environment 120 and the certain public cloud 130 is 0.8 Gbps, and the score value is 0.4. Similarly, the realistic throughput value expected during degeneration is "0.4Gbps", and the score value is "0.2".

[0065] 6A is a flowchart showing the operation in step 202 shown in Fig. 2. This step is executed by the configuration pattern enumeration unit 101. The following describes a case where the operation is started in step 201, triggered by the administrator terminal 160 accepting an operation from the user and inputting connection requirements (e.g., between the on-premise device A 124-1 and the virtual appliance 134-2) and traffic (e.g., storage volume copy #1, a copy in which a volume is used as a unit) via the GUI 115 of the integrated setting server 100.

[0066] In step 601, the configuration pattern enumeration unit 101 acquires the contents of the SD-WAN router topology table 111 and the SD-WAN configuration pattern condition table 112.

[0067] In step 602, the configuration pattern enumeration unit 101 determines whether the SD-WAN router 121 and the virtual SD-WAN router 131 can be configured in a redundant configuration by referring to the SD-WAN router topology table 111 and the SD-WAN configuration pattern condition table 112.

[0068] As a specific example of the determination, the determination is made based on whether both the SD-WAN router 121 and the virtual SD-WAN router 131 are connected to the on-premises device connection switch 123 or the connection service 133. In FIG. 2, for example, the SD-WAN router 121 (SD-WAN router 121-1) indicated as "SD-WAN router A" is connected to the on-premises device connection switch 123 as shown in record 307. Therefore, the configuration pattern enumeration unit 101 determines that the SD-WAN router 121-1 can be configured redundantly. Similarly, the configuration pattern enumeration unit 101 determines that the virtual SD-WAN router 131 (virtual SD-WAN router 131-1) indicated as "virtual SD-WAN router A" is connected to the connection service 133 as shown in record 308. Therefore, the configuration pattern enumeration unit 101 determines that the virtual SD-WAN router 131-1 can be configured redundantly.

[0069] Furthermore, the configuration pattern enumeration unit 101 refers to the SD-WAN router topology table 111 and the SD-WAN configuration pattern condition table 112, and enumerates virtual network configuration patterns that indicate redundant network configurations using the SD-WAN router 121 and virtual SD-WAN router 131 that have been determined to be capable of redundant configuration in the above determination, as well as a list of SD-WAN software control functions to be applied to the redundant network configuration. After step 602 is executed, all combinations of software control functions in the SD-WAN configuration pattern condition table 112 that apply to each of the above redundant network configurations are enumerated as the virtual network configuration patterns that can be configured redundantly.

[0070] 6B is a diagram showing an example of a virtual network configuration pattern. As shown in Fig. 6B, virtual network configuration pattern 601B stores the determined on-premise router (SD-WAN router 121) and the on-premise gateway (Internet gateway 122) connected to the router, the determined public cloud router (virtual SD-WAN router 131) and the public cloud gateway (virtual Internet gateway 132) connected to the router, SD-WAN software control functions to be applied to the network via these routers and gateways, and the redundant network configuration, all in association with each other.

[0071] FIG. 6B shows, for example, record 602B, which shows the combination of the following virtual network configuration patterns. Specifically, the on-premises network configuration, consisting of on-premises routers "SD-WAN Router A" and "SD-WAN Router B" and on-premises gateways "Internet GW A1," "Internet GW A2," and "Internet GW B1," and the public cloud network configuration, consisting of public cloud routers "Virtual SD-WAN Router A" and "Virtual SD-WAN Router B" and public cloud gateways "Virtual Internet GW A01," "Virtual Internet GW A02," and "Virtual Internet GW B01," shows that the network between on-premises device A124-1 and virtual appliance 134-2 is configured as a virtual network configuration pattern that allows for redundant configuration. This virtual network configuration pattern also shows that "Forwarding Route Extension" and "ECMP (Systems A and B)" are applied as SD-WAN software control functions. Furthermore, it shows that both redundant networks in this virtual network configuration pattern are configured as primary systems.

[0072] Whether a redundant system is a primary system or a secondary system can be determined, for example, by the configuration pattern enumeration unit 101 by referencing the SD-WAN router topology table 111 and determining the size of the throughput (column 303) corresponding to the SD-WAN product (column 301) included in the network configuration. That is, a network configuration with a large throughput size can be designated as a "primary system," and a network configuration with a smaller throughput size can be designated as a "secondary system." If the throughputs of the network configurations are the same, both can be designated as "primary systems" (double primary systems). Furthermore, if a redundant configuration is not possible in the redundant system, it is stored as a "single system," as described below. In this way, in step 602, all other combinations between the software-controlled functions stored in the SD-WAN configuration pattern condition table 112 and the network configurations are stored in the same manner as record 602B.

[0073] In step 603, the configuration pattern enumeration unit 101 refers to the SD-WAN configuration pattern condition table 112 and determines whether or not there is a pattern that violates the application conditions for each of the listed virtual network configuration patterns. If the configuration pattern enumeration unit 101 determines that there is a pattern that violates the application conditions (step 603; YES), it excludes the pattern from the virtual network configuration pattern 601B (step 604). On the other hand, if the configuration pattern enumeration unit 101 determines that there is no pattern that violates the application conditions (step 603; NO), it leaves the pattern in the virtual network configuration pattern 601B (step 605).

[0074] In step 606, the configuration pattern enumeration unit 101 stores the virtual network configuration pattern including the record excluded in step 604 and left in step 605 as a virtual network configuration pattern 601B having the redundant configuration determined in step 602.

[0075] In step 607, the configuration pattern enumeration unit 101 refers to the SD-WAN router topology table 111 and the SD-WAN configuration pattern condition table 112, and for the SD-WAN router 121 and the virtual SD-WAN router 131 that it determined in step 602 cannot be configured as a redundant configuration, enumerates virtual network configuration patterns, including the network configuration when the SD-WAN router 121 and the virtual SD-WAN router 131 are used as a single system and whether or not the SD-WAN software control function is applied, as in step 602. For example, if the SD-WAN router 121 and the virtual SD-WAN router 131 are not connected to the on-premises device connection switch 123 or the connection service 133, the configuration pattern enumeration unit 101 determines that the SD-WAN router 121 and the virtual SD-WAN router 131 can be configured as a single system, and enumerates virtual network configuration patterns that indicate the single system network configuration and a list of SD-WAN software control functions to be applied to the network configuration.

[0076] For example, the configuration pattern enumeration unit 101 outputs the following combination of virtual network configuration patterns as record 603B of virtual network configuration pattern 601B. Specifically, the record 603B indicates that the network between on-premises device A124-1 and virtual appliance 134-2 is configured as a virtual network configuration pattern using an on-premises network configuration consisting of an on-premises router "SD-WAN router C" and on-premises gateways "Internet GW C1" and "Internet GW B1," and a public cloud network configuration consisting of a public cloud router "virtual SD-WAN router C" and a public cloud gateway "virtual Internet GW C01." The record 603B indicates that the virtual network configuration pattern is a virtual network configuration pattern to which "TCP optimization" and "single system" are applied as SD-WAN software control functions.

[0077] After step 607 is executed, all combinations of software control functions in the SD-WAN configuration pattern condition table 112 that apply to each of the above-mentioned single network configurations are listed as the virtual network configuration pattern for the single configuration that does not allow redundant configuration. In this way, in step 607, all combinations between all software control functions stored in the SD-WAN configuration pattern condition table 112 and the above-mentioned single network configurations are stored in the same way as record 602B.

[0078] In step 608, similarly to step 603, the configuration pattern enumeration unit 101 refers to the SD-WAN configuration pattern condition table 112 and determines whether or not there is a pattern that violates the application conditions for each of the virtual network configuration patterns enumerated in step 607. If the configuration pattern enumeration unit 101 determines that there is a pattern that violates the application conditions (step 608; YES), it excludes the pattern in question from the virtual network configuration pattern 601B (step 609). On the other hand, if the configuration pattern enumeration unit 101 determines that there is no pattern that violates the application conditions (step 607; NO), it leaves the pattern in question in the virtual network configuration pattern 601B (step 610).

[0079] In step 611, the configuration pattern enumeration unit 101 stores the virtual network configuration pattern including the record excluded in step 609 and remaining in step 610 as a virtual network configuration pattern 601B that does not have a redundant configuration (i.e., a single-system configuration) as determined in step 602.

[0080] In step 612 , the configuration pattern enumeration unit 101 merges the virtual network configuration pattern 601 B held in step 606 with the virtual network configuration pattern 601 B held in step 611 .

[0081] Finally, in step 613, the configuration pattern enumeration unit 101 outputs the merged virtual network configuration pattern as a final virtual network configuration pattern 601B as shown in Fig. 6B. When the processing of step 613 ends, the processing of the configuration pattern enumeration unit 101 shown in Fig. 6A ends. Note that in Fig. 6A, the processing related to the redundant configuration (steps 602 to 606) is executed before the processing related to the single configuration (steps 607 to 611), but the processing related to the single configuration may be executed before the processing related to the redundant configuration.

[0082] 7 is a flowchart showing the operation in step 203 shown in FIG. 2. This process is executed by the configuration pattern evaluation unit 102. In the following, the process starts after the configuration pattern enumeration unit 101 enumerates the virtual network configuration patterns described using FIGS. 6A and 6B in step 202. In the following, one virtual network configuration pattern will be described as an example, but the same process is performed for all of the other enumerated virtual network configuration patterns.

[0083] In step 701, the configuration pattern evaluation unit 102 acquires the contents of the SD-WAN function performance contribution table 113.

[0084] In step 702, the configuration pattern evaluation unit 102 compares each record included in the virtual network configuration pattern finally listed in FIG. 6A with each record in the SD-WAN function performance contribution table 113, and searches the SD-WAN function performance contribution table 113 for records that match each record in the virtual network configuration pattern.

[0085] Specifically, the configuration pattern evaluation unit 102 reads the contents of each of the items (on-premises router, on-premises gateway, public cloud router, public cloud gateway, SD-WAN function, and redundant system) for each record stored as the finally output virtual network configuration pattern 601B. The configuration pattern evaluation unit 102 compares the contents of these read items with the SD-WAN software control function shown in column 501 of the SD-WAN function performance contribution table 113, the environmental condition shown in column 502, and the traffic (application) shown in column 503, and searches for a record having columns 501 to 503 of the SD-WAN function performance contribution table 113 that matches the contents of the above items.

[0086] For example, the contents of each item of record 602B shown in FIG. 6B include an on-premises network configuration consisting of on-premises routers "SD-WAN Router A" and "SD-WAN Router B" and on-premises gateways "Internet GW A1," "Internet GW A2," and "Internet GW B1," a public cloud network configuration consisting of public cloud routers "Virtual SD-WAN Router A" and "Virtual SD-WAN Router B," and public cloud gateways "Virtual Internet GW A01," "Virtual Internet GW A02," and "Virtual Internet GW B01," and the SD-WAN software control functions "Forwarding Route Extension," "ECMP (Systems A and B)," and a redundant system "Double Main System." The configuration pattern evaluation unit 102 determines that the virtual network configuration pattern indicated by record 602B allows for a redundant configuration because, among the items read, multiple routers and gateways are stored as on-premises routers and on-premises gateways, and multiple virtual routers and virtual gateways are stored as public cloud routers and public cloud gateways.

[0087] Furthermore, the configuration pattern evaluation unit 102 searches for a record including the environmental conditions having the redundant configuration for which the above-mentioned determination was made from the SD-WAN function performance contribution table 113. For example, since the configuration pattern evaluation unit 102 has the above-mentioned multiple routers and gateways and the above-mentioned multiple virtual routers and virtual gateways, it searches for records in which multiple vendors are stored (#1 to #14 in FIG. 5) from the SD-WAN function performance contribution table 113 in FIG. 5.

[0088] Furthermore, the configuration pattern evaluation unit 102 confirms that the redundant system for record 602B of the finally output virtual network configuration pattern 601B is the "dual main system" that was read above. Because the redundant system is "dual main system," the configuration pattern evaluation unit 102 searches for records with the same values ​​of throughput and delay among the searched records #1 to #14. Furthermore, the configuration pattern evaluation unit 102 searches for a record that stores the same function as the SD-WAN function of record 602B from the searched records with the same values ​​of throughput and delay. In this example, because the SD-WAN functions of record 602B are "transfer route extension" and "ECMP (A, B systems)," the two corresponding records 509 and 510 (#4 and #6 in FIG. 5) are searched for. Although the SD-WAN function "transfer route extension" is not illustrated in FIG. 5, this function is also searched for in the same way as for "ECMP (A, B systems)."

[0089] Then, in step 201, since traffic (e.g., storage volume copy #1) is input by the user, the configuration pattern evaluation unit 102 identifies record 509 (#4 in Figure 5) from the two records above, which contains the same traffic as the input traffic, "volume copy #1."

[0090] In this example, the configuration pattern evaluation unit 102 identified one record that matches each record of the virtual network configuration pattern 601B from the SD-WAN function performance contribution table 113. However, when searching for each record in Figures 5 and 6B, even if the contents of each item in both records do not necessarily match perfectly, they may be identified as the matching record as long as they are similar to a certain degree. A certain degree of similarity means, for example, when only some items match, such as when the vendors are the same, or when the difference in the guaranteed bandwidth value when the contract type is "bandwidth guaranteed" is within a predetermined range (for example, "1.1 Gbps" is 10% wider than "1 Gbps").

[0091] In step 703, the configuration pattern evaluation unit 102 calculates a normal-state score for each record included in the virtual network configuration pattern finally listed in FIG. 6A. For example, the score in column 505 of the SD-WAN function performance contribution table 113 may be used. However, if there is no perfectly matching column and there are multiple similar columns, the score may be determined after weighting or other adjustments. For example, for record 602B in FIG. 6B searched in step 702, the configuration pattern evaluation unit 102 obtains the expected normal-state throughput of "0.8 Gbps" and the normal-state score of "0.4" stored as the identified record 509, and sets these as the expected normal-state throughput and normal-state score for record 602B. For example, the configuration pattern evaluation unit 102 reads the expected normal-state throughput of "0.8 Gbps" from record 509. Furthermore, the configuration pattern evaluation unit 102 may read the value "1Gbps" corresponding to "Vendor A Bandwidth Guarantee" and the value "1Gbps" corresponding to "Vendor B BE" stored as environmental conditions 502, and calculate the normal state score "0.4" (0.8Gbps / 2Gbps=0.4) for the above record 602B based on the ratio between the sum of these values, "2Gbps," and the read normal state expected throughput of "0.8Gbps."

[0092] In step 704, the configuration pattern evaluation unit 102 determines whether communication is possible even in a degenerated state, for each scored virtual network configuration pattern, for example, when the main physical Internet connection is interrupted. The configuration pattern evaluation unit 102 mainly references columns 506 and 507 to determine a degenerated score for each of the virtual network configuration patterns. The configuration pattern evaluation unit 102 determines that communication is not possible in a degenerated state when, for example, the value in column 507 is "N / A." Furthermore, when multiple columns are candidates, the determination may be made by weighting the one with the worse throughput in a degenerated state.

[0093] For example, the configuration pattern evaluation unit 102 reads the value of the redundant system in the record 602B being processed in step 703, and determines whether communication is possible through degeneration when a failure occurs. In this example, the redundant system "both main systems" is stored in the record 602B, so the configuration pattern evaluation unit 102 determines that communication is possible even in the degenerated state. The criterion for this determination may be, for example, that communication is possible in the degenerated state when the value of the redundant system is "both main systems," "main system," and "secondary system," other than a single system.

[0094] In step 705, if configured pattern evaluation section 102 determines in step 704 that communication is not possible even in the degenerate state (step 704: NO), it determines the degenerate state score as "N / A."

[0095] In step 706, if it is determined that communication is not possible even in the degenerate state in step 704 (step 704: YES), the configuration pattern evaluation unit 102 calculates the expected throughput value in normal mode and the throughput value in the degenerate state, and determines the calculated values ​​as the score in the degenerate state. For example, if the ratio of the throughput value in the degenerate state to the expected throughput value in normal mode is 60%, the configuration pattern evaluation unit 102 determines the value that is 60% of the normal score as the score in the degenerate state.

[0096] In step 707, the configuration pattern evaluation unit 102 sorts the records of the virtual network configuration patterns in descending order of the normal state score calculated in step 703, and selects and lists them up to a predetermined upper limit. The upper limit is, for example, the upper limit of the number that can be displayed on the screen of the administrator terminal 160 (for example, 10 records).

[0097] In step 708, the configuration pattern evaluation unit 102 determines whether or not there is any record (for example, the 11th or later record as a result of the above-mentioned rearrangement) other than the record of the virtual network configuration pattern selected in step 707 whose degenerate score is higher than the degenerate score of the record of the above-mentioned selected virtual network configuration pattern. If it is determined that there is no record whose degenerate score is higher than the degenerate score of the record of the above-mentioned selected virtual network configuration pattern (step 708; NO), the process proceeds to step 710. On the other hand, if it is determined that there is a record whose degenerate score is higher than the degenerate score of the record of the above-mentioned selected virtual network configuration pattern (step 708; YES), the process proceeds to step 709.

[0098] In step 709, the configuration pattern evaluation unit 102 replaces the record determined in step 708 to have a higher degeneration score than the degeneration score of the record of the selected virtual network configuration pattern with the record that was the subject of the above determination among the records of virtual network configuration patterns with high normal scores sorted in step 707. This process is performed to determine whether there is a virtual network configuration pattern that has a better rate of score degradation during degeneration (that is, is less likely to deteriorate even during degeneration) even among the records selected in step 707 after sorting the normal scores. As a result of the above replacement, a virtual network configuration pattern with better values ​​for both the normal score and the degeneration score is selected.

[0099] In step 710, the configuration pattern evaluation unit 102 outputs the record of the virtual network configuration pattern determined in step 708 (or the record of the virtual network configuration pattern replaced in step 709), and the flow ends. Figure 8 is a diagram showing an example of output data shown on the administrator terminal 160 in step 204 in the first embodiment. The output data output in step 204 is data representing the record output in step 710 in Figure 7. This data shows, as virtual network configurations, a configuration 801 of the SD-WAN router 121 on the on-premises side, a configuration 802 of the virtual SD-WAN router 131 on the public cloud side, and an SD-WAN software control function 803. In addition, as expected throughput information, a score 804 under normal conditions and a score degradation 805 under degeneration are shown.

[0100] For example, in Figure 8, data corresponding to record 602B shown in Figure 6B is output as record 806. Specifically, Figure 8 outputs the on-premises routers "SD-WAN Router A" and "SD-WAN Router B," the public cloud routers "Virtual SD-WAN Router A" and "Virtual SD-WAN Router B," and the on-premises Internet routers "Internet GW A1," "Internet GW A2," and "Internet GW B1" of record 602B in Figure 6. Also, it shows that in the virtual network configuration of this virtual network configuration pattern, the normal score calculated in step 703 is set to "0.7," and the degenerate score calculated in step 706 is set to "75% (of the normal score)."

[0101] As described above, in this embodiment, a list of virtual network combination patterns that satisfy the requirements specified by the administrator is created for the current on-premises environment 120 and public cloud environment 130. From among these, an environment equivalent to (or somewhat similar to) the environment previously obtained through testing (SD-WAN function performance contribution table 113 shown in FIG. 5) is identified (final virtual network configuration pattern 601B shown in FIG. 6B). It is then determined that the identified environment is likely to achieve throughput and scores similar to those expected in the tested environment (columns 504 and 505 in FIG. 5), and the values ​​of the throughput and score are applied to the identified environment. Furthermore, a score for degeneration is calculated from columns 504, 505, and 506 shown in FIG. 5, and the calculated value is used as the score for when a network failure occurs in the identified environment.

[0102] This will output the output data shown in Figure 8, allowing users to list the configuration of the virtual network to be overlaid in a hybrid cloud system that connects on-premises and public clouds via the Internet and SD-WAN, evaluate the configuration of the virtual network via SD-WAN connected to the Internet, and quantitatively estimate the design and verification labor required for provisioning.

[0103] Fig. 9 is a diagram showing an example of a screen output as GUI 115 in the first embodiment and displayed on administrator terminal 160. Fig. 9 includes an input form 900A input by the administrator and an output form 900B on which the data output after the above-described processing is performed is displayed.

[0104] In the input form 900A, in step 201, the user can select the connection requirements and traffic to input from the administrator terminal 160. In this example, connection source information 901 and connection destination information 902 can be selected as connection requirements. The connection source information 901 and connection destination information 902 include terminal connection devices and appliances, and devices and appliances that make up the virtual network for connecting these are input. Note that it is also possible to narrow down the search by whether or not the SD-WAN router is redundant, the SD-WAN router ID to be used for redundancy, etc.

[0105] In the traffic information 903, application information can be selected as traffic. Furthermore, the operation mode of the application can be selected as a property. If there is no application registered in advance, specific communication content (for example, whether it is TCP or UDP, how the session is established, etc.) or an application that performs similar operations can be selected.

[0106] The output form 900B mainly outputs a list of virtual network configuration patterns and scores 904.

[0107] When the various pieces of information described above are entered into input form 900A in FIG. 9, the entire process shown in FIG. 3 begins. The results of the processes shown in FIGS. 6A and 7 are then output as output form 900B. The items in the output form are the same as those in the output data shown in FIG. 8, and therefore will not be described here. By checking output form 900B in FIG. 9, a user can determine what combination of virtual networks satisfies the requirements they specify. Furthermore, by checking the normal and degenerate scores for the combination, the user can evaluate the configuration of the virtual network via SD-WAN used in that combination and quantitatively estimate the design and verification effort required for provisioning. For example, a user can determine at a glance that a combination with a higher normal score indicates a virtual network configuration with higher throughput, and a combination with a higher degenerate score indicates a virtual network configuration with higher tolerance for network failures. [Example]

[0108] In the first embodiment, by checking the output data as shown in FIG. 8, the administrator, who is the user, can evaluate the configuration of a virtual network that meets the requirements specified by the user and estimate the man-hours required for provisioning. In the second embodiment, a technology is further described that facilitates the construction of the virtual network configuration included in the output data as shown in FIG. 8. In this case, the SD-WAN router 121 in the on-premises environment 120 is installed under a contract such as a lease. The user can provision the virtual network configuration as needed so that the functions on the public cloud 130 can be applied to the SD-WAN router 121 in the on-premises environment 120.

[0109] 10 shows a sequence diagram for constructing a virtual network overlay between the SD-WAN router 121 and the virtual SD-WAN 131 in this embodiment to connect the on-premises environment 120 and the public cloud environment 130. Steps 201 to 203 are the same as those in the first embodiment, so their description will be omitted here, and only the processing from step 1001 onwards will be described.

[0110] In step 1001, when the scores of the virtual network construction patterns are calculated in step 203, the configuration template output unit 103 refers to the scores for each virtual network configuration pattern calculated in step 203, and outputs the configuration template corresponding to the virtual network configuration pattern with the highest score to the administrator terminal 160.

[0111] 11 is a diagram showing an example of a flowchart of the process in step S1001 in which the configuration template output unit 103 outputs a configuration template. This process starts after the scores are calculated in step 203 (FIGS. 2 and 6A) and the final enumerated virtual network configuration patterns are output.

[0112] In step 1101, the configuration template output unit 103 creates a format for settings to be made to the SD-WAN configuration controller 150, the on-premise configuration setting tool 125, and the public cloud configuration setting service 135 in order to build a virtual network configuration of the virtual network configuration pattern finally enumerated above. This format is a template for a file required when building a virtual network configuration of the virtual network configuration pattern finally enumerated above for the SD-WAN configuration controller 150, the on-premise configuration setting tool 125, and the public cloud configuration setting service 135.

[0113] An example of the on-premise configuration tool 125 is Ansible. Furthermore, an example of the public cloud configuration service 135 is AWS Cloud Formation, which supports YAML files as one format. Regarding the SD-WAN configuration controller 150, if the vendor expects GUI operation rather than a configuration file, the configuration template output unit 103 creates a format that indicates the details of the operation procedure.

[0114] In step 1102, the setting template output unit 103 edits the format created in step 1101 so as to reflect the above-mentioned finally enumerated virtual network configuration patterns. For example, the setting template output unit 103 reads the contents of each item constituting each record of the above-mentioned finally enumerated virtual network configuration patterns shown in FIG. 8, and applies the read contents to the format created in step 1101.

[0115] In step 1103, the setting template output unit 103 outputs the format edited in step 1102 as a setting template.

[0116] 12 is a diagram showing an example of output data output to administrator terminal 160 in step 1103. As shown in FIG. 12, output data 1200 stores setting templates 1201 in association with each of the virtual network configuration patterns, in addition to the virtual network configuration patterns finally listed above shown in FIG. 8. That is, files necessary for constructing a virtual network configuration in the environment shown in columns 801 to 803 are stored as setting templates 1201. By checking and selecting setting template 1201, the user does not need to create files necessary for constructing a virtual network configuration from scratch, thereby reducing the workload when constructing a virtual network.

[0117] Returning to Figure 10, in step 1002, when the user selects the configuration template 1201 shown in Figure 12, in step 1003, the configuration template output unit 103 inputs the configuration template of the selected virtual network configuration pattern to the SD-WAN configuration controller 150, the on-premises configuration setting tool 125, and the public cloud configuration setting service 135.

[0118] In step 1004, upon receiving the input from step 1003, the SD-WAN router 121, virtual SD-WAN router 131, on-premises device connection switch 123, and connection service 133 each apply settings according to the selected setting template. Through these steps, a virtual network overlay is configured between the on-premises environment 120 and the public cloud environment 130.

[0119] By performing the processing described above, it is possible to complete the construction of a virtual network using the configuration template obtained from the integrated configuration server 100, and it is also possible to synchronize the procedure with the provisioning of virtual appliances on the public cloud. [Example]

[0120] In the third embodiment, the construction of a virtual network is similar to that of the first embodiment. In this embodiment, when selecting an Internet connection to be used by the SD-WAN router 121, optimization including cost is performed by taking into account information such as the vendor, Internet line type, and expected throughput, cost, and lead time for the plan. Furthermore, although Internet lines are rarely selected for public clouds, throughput trends may differ depending on the public cloud vendor and region, even for Internet connections with similar throughput. Therefore, these factors may be taken into account depending on the connection destination.

[0121] 13 is a diagram showing an example of a line status table held by the integrated setting server 100 in this embodiment. This table pre-stores the characteristics of each Internet line based on actual measurements, evaluations, and the collection of related information. That is, the line status table 1300 pre-stores the characteristics of various types of Internet lines, including the actual throughput expected for each Internet line, the theoretical throughput, the cost of using the line, and the lead time, which is the time required to build a virtual network configuration using the line.

[0122] Columns 1301 to 1301 store information about the internet line, such as provider or public cloud vendor information, internet line type, and plan information.

[0123] Columns 1304 to 1306 hold information such as expected throughput, cost, and lead time as characteristics of the internet line. Additionally, columns may be added as needed to add information required for estimates, etc.

[0124] 13, for example, record 1307 (#1) indicates that a plan is set that guarantees a bandwidth of "1 Gbps" as the theoretical throughput when using "Vendor A," that the actual throughput expected with that plan is "950 Mbps," that an initial cost of "500K" and a monthly cost of "500K" are required, and that the lead time for building a virtual network configuration with that plan is "2 months."

[0125] Although Example 3 mainly assumes a configuration in which both on-premise and public clouds are connected, optimization may be performed using similar steps when connecting on-premise to on-premise and public cloud to public cloud.

[0126] FIG. 14 is a diagram showing an example of a flowchart illustrating the operation of the setting template output unit 103 in the third embodiment. This process starts in response to the calculation of the score and the output of the finally enumerated virtual network configuration patterns in step 203 (FIGS. 2 and 6A). In this embodiment, the Internet line to be used in the virtual network configuration of the finally enumerated virtual network configuration pattern does not have to be specified. "An Internet line has not been specified" means, for example, that an Internet service contract has not yet been signed.

[0127] In step 1401, the setting template output unit 103 acquires the contents of the line status table 1300 shown in FIG.

[0128] In step 1402, the configuration template output unit 103 references the SD-WAN router topology table 111 shown in Fig. 3 and the line status table 1300 acquired in step 1301, and acquires a combination of line information that can be used for each of the virtual network configuration patterns finally listed above. Furthermore, the configuration template output unit 103 references the expected throughput 1304, and calculates a score for the virtual network configuration pattern as necessary.

[0129] For example, the configuration template output unit 103 reads each item (on-premise router, public cloud router, SD-WAN function) of record 602B of the virtual network configuration pattern finally listed above shown in Figure 6B, obtains records from the SD-WAN router topology table 111 that contain items that match these read items, and identifies a combination that satisfies the contents of each item of record 602B above.

[0130] Furthermore, the configuration template output unit 103 reads the throughput of the record corresponding to the identified combination from the SD-WAN router topology table 111. For example, if the terminal connection device and appliance are the on-premises device 124-1 and the virtual appliance 134-2, the configuration template output unit 103 reads the combination of the SD-WAN router 121 and the virtual SD-WAN router 131 to which they can be connected. The configuration template output unit 103 then reads the throughput 303 corresponding to each SD-WAN product 301 that makes up the read combination, and calculates a statistical value (for example, an average value) for each of the read throughputs.

[0131] Then, the setting template output unit 103 identifies a record including the closest expected throughput from among the expected throughputs 1304 that satisfy the calculated throughput statistics, from the line status table 1300 shown in Fig. 13. For example, if the calculated throughput statistics is "950 Mbps," the setting template output unit 103 identifies record 1307 as the record including the closest expected throughput.

[0132] The configuration template output unit 103 also searches the SD-WAN function performance contribution table 113 shown in FIG. 5 for a record containing environmental conditions 502 with the same content as the “vendor,” “line type,” and “plan” of the identified record 1307. From the records obtained by the search, the configuration template output unit 103 selects a record containing a SW control function 501 that contains the same function as the SD-WAN software control function 803 (FIG. 8) output in step 203 (FIG. 7) and the same traffic as that selected in step 201. The configuration template output unit 103 reads the normal score and degenerate score of the selected record and replaces the normal score 804 and degenerate score 805 shown in FIG. 8 with the read normal score and degenerate score. The records to be replaced in FIG. 8 are records containing the configuration 801 of the on-premises SD-WAN router 121 and the configuration 802 of the virtual SD-WAN router 131 on the public cloud side, identified by the above combination.

[0133] In step 1403, the setting template output unit 103 refers to the cost 1305 and lead time 1306 stored in the record 1307 of the specified line status table 1300, and sets them as the cost and lead time of the record for which the replacement was performed. Steps 1402 and 1403 are performed for all records of the output data shown in Fig. 8, and the cost and lead time are set for each record.

[0134] In step 1404, the setting template output unit 103 compares the finally enumerated virtual network configuration patterns with combinations that satisfy the expected throughput 1304, and determines whether there is a combination that is better in cost and lead time than the finally enumerated virtual network configuration patterns. If the setting template output unit 103 determines that there is no combination that is better in cost and lead time than the finally enumerated virtual network configuration patterns (step 1404; NO), the setting template output unit 103 proceeds to step 1406.

[0135] In step 1406, if the configuration template output unit 103 determines that there is a combination that is superior in cost and lead time to the finally enumerated virtual network configuration pattern (step 1404; YES), it replaces the superior combination with the finally enumerated virtual network configuration pattern that it compared with.

[0136] In step 1305, the configuration template output unit 103 outputs output data including the virtual network configuration pattern, score, cost, and lead time, and ends the operation. When step 1305 is performed, a combination with excellent cost and lead time is output from the output data shown in FIG.

[0137] 15 is a diagram showing an example of the output data output in step 1305. As shown in FIG. 15, output data 1500 has columns 801 to 805 similar to those of output data 800 shown in FIG. 8, and further has associated therewith cost 1501 and lead time 1502. By checking the output data 1500 on the screen, a user can list the configurations of virtual networks to be overlaid in a hybrid cloud system that connects on-premises and public clouds via the Internet and SD-WAN, evaluate the configuration of the virtual network via SD-WAN taking into account the cost and lead time, and quantitatively estimate the man-hours required for design and verification when performing provisioning. [Example]

[0138] In the fourth embodiment, a form is shown in which the line status table 1300 described in the third embodiment is updated based on the results of monitoring a virtual network in operation.

[0139] Figure 16 is an overall configuration diagram of Example 4. In the hybrid cloud 2000 of this example, the integrated setting server 100 holds the line status table 1300 and line status update unit 1600 shown in Figure 13 in addition to the components of Example 1. Furthermore, the SD-WAN setting controller 150 not only sets the SD-WAN router 121 and virtual SD-WAN router 131, but also monitors traffic passing through the SD-WAN router 121 and virtual SD-WAN router 131 and acquires actual measured values ​​of throughput.

[0140] The line status update unit 1600 periodically or at any timing acquires throughput from the SD-WAN configuration controller 150 without specifying user traffic. The acquired information includes, for example, the throughput between an on-premises router, an on-premises gateway, a public cloud router, a public cloud gateway, and an end-point connected device (e.g., the on-premises device 124) and an appliance (e.g., the virtual appliance 134) via the SD-WAN function that configures the virtual network configuration pattern. The line status update unit 1600 determines whether the change in the actual measured value of the throughput significantly deviates from the expected throughput 1304 in the line status table 1300 by a predetermined value or more. If the line status update unit 1600 determines that the actual measured value and the expected throughput 1304 significantly deviate from each other by a predetermined value or more, it rewrites the value of the expected throughput 1304 to the actual measured value.

[0141] By performing such processing, it is possible to obtain the expected throughput according to the communication conditions of the actual virtual network configuration, and as a result, it is possible to output output data 1500 according to the current environment, and to output a combination that is excellent in terms of cost and lead time.

[0142] As described above, this system makes it possible to enumerate the configuration of overlaid virtual networks and estimate quantitative evaluations in a hybrid cloud system that connects on-premises and public clouds via the Internet and SD-WAN.

[0143] For example, as described using Example 1, FIGS. 2, 6A, 6B, 7, 8, etc., in a hybrid cloud network construction support system (e.g., integrated setting server 100) that supports construction of a hybrid cloud network in which an on-premises environment (e.g., on-premises environment 120) and a public cloud environment (e.g., public cloud environment 130) are connected via the Internet by a computer having a processor and a memory, the processor performs the following operations based on requirements regarding connection and traffic between the on-premises environment and the public cloud environment specified by a user (e.g., virtual network requirements input in step 201 of FIG. 2), a topology table (e.g., SD-WAN router topology table 111) for managing the connection forms of SD-WAN routers and virtual SD-WAN routers that constitute the hybrid cloud network, and a table (e.g., SD-WAN configuration pattern condition table 112) that defines conditions for software control functions to be held as the SD-WAN router and the virtual SD-WAN router. Based on this, the configuration pattern enumeration unit 101 enumerates configuration patterns of a virtual network that meet the above requirements (for example, the configuration pattern enumeration unit 101, step 202 in FIG. 2, FIGS. 6A and 6B), and calculates the throughput and score for each of the listed configuration patterns based on the listed configuration patterns, the environment for realizing the hybrid cloud network, the software control functions of the SD-WAN router and the virtual SD-WAN router in that environment, and a table (for example, the SD-WAN function performance contribution table 113) that defines scores that are indicators that indicate the ratio of the actual throughput to the theoretical value of the throughput of the hybrid cloud network and the line speed of the hybrid cloud network when the functions are applied (for example, the configuration pattern evaluation unit 102, step 203 in FIG. 2, FIG. 7), and outputs the configuration patterns whose calculated throughput and score satisfy predetermined conditions (for example, the top 10 scores) (for example, the setting template output unit 102, step 204 in FIG. 2, output data 800 shown in FIG. 8).Therefore, for hybrid cloud connections using SD-WAN products, it is possible to automatically enumerate and compare virtual network construction patterns that meet the user's intended requirements. As a result, it becomes possible to evaluate the configuration of a virtual network via SD-WAN connected to the Internet and quantitatively estimate the design and verification efforts required for provisioning.

[0144] 10-12, the processor applies the configuration pattern to a predetermined format for configuring the hybrid cloud network, thereby generating a configuration template required for building the hybrid cloud network including the SD-WAN and the virtual SD-WAN, and outputs the generated template in association with the configuration pattern (for example, the configuration template output unit 102, the configuration template 1201 shown in FIG. 12). This eliminates the need for the user to create files required for building a virtual network configuration from scratch, thereby reducing the workload required for building a virtual network.

[0145] As explained using Figures 13-15 and the like, the computer has a line status table (e.g., line status table 1300) that includes, as characteristics of the network via the SD-WAN router and virtual SD-WAN router that make up the hybrid cloud network via the Internet, at least the cost of using the network and the lead time, which is the time it takes to build a virtual network configuration using the network, and the processor rearranges the configuration pattern according to the cost and lead time in the line status table and outputs the rearranged configuration pattern. This makes it possible to enumerate virtual network configurations that take the cost and lead time into consideration and estimate their evaluation.

[0146] 16 and other figures, the hybrid cloud network construction support system includes a controller (e.g., SD-WAN setting controller 150) that monitors the availability of the hybrid cloud network via the Internet, and the line status table stores the expected throughput of the network as the characteristic. The processor periodically or at any timing acquires the actual measured value of the throughput from the controller (e.g., line status update unit 1600), and if the acquired throughput and the expected throughput differ by a predetermined value or more, rewrites the expected throughput with the actual measured value of the throughput. This makes it possible to enumerate virtual network configurations and estimate their evaluation, taking into account the actual line speed, cost, and lead time of the hybrid cloud network via the Internet.

[0147] Although the present invention has been described in detail above using the drawings, it is not limited to the various examples described above, and various modifications are possible within the scope of the invention. [Explanation of symbols]

[0148] 1000, 2000 Hybrid Cloud 120 On-premise environment 130 Public Cloud Environments 140 Internet 100 Integrated Configuration Server 101 Configuration pattern enumeration section 102 Configuration Pattern Evaluation Unit 103 Setting template output section 111 SD-WAN Router Topology Table 112 SD-WAN Configuration Pattern Condition Table 113 SD-WAN Feature Performance Contribution Table 115 GUI 121 SD-WAN router 122 Internet Gateway 123 On-premise device connection switch 124 On-Premise Equipment 131 Virtual SD-WAN Router 132 Virtual Internet Gateways 133 Connection Service 134 Virtual Appliances 140 Internet 150 SD-WAN Configuration Controller 1300 Line Status Table 601B Virtual Network Configuration Pattern 800, 1200, 1500 output data 1600 Line Status Update Unit

Claims

1. A hybrid cloud network construction support system that supports construction of a hybrid cloud network in which an on-premises environment and a public cloud environment are connected via the Internet by a computer having a processor and a memory, comprising: The processor: Based on requirements for connection and traffic between the on-premises environment and the public cloud environment specified by a user, a topology table for managing the connection forms of the SD-WAN routers and virtual SD-WAN routers that make up the hybrid cloud network, and a table that defines the conditions for software control functions to be held by the SD-WAN routers and the virtual SD-WAN routers, enumerate configuration patterns of virtual networks that meet the requirements; Calculating the throughput and the score for each of the listed configuration patterns based on the listed configuration patterns, an environment for realizing the hybrid cloud network, software control functions of the SD-WAN router and the virtual SD-WAN router in the environment, and a table that defines scores that are indicators showing the throughput of the hybrid cloud network when the functions are applied and the ratio of the actual throughput to the theoretical value of the line speed of the hybrid cloud network; outputting the configuration pattern in which the calculated throughput and score satisfy a predetermined condition; A hybrid cloud network construction support system characterized by:

2. The processor: By applying the configuration pattern to a predetermined format for configuring the hybrid cloud network, a configuration template required for constructing the hybrid cloud network including the SD-WAN and the virtual SD-WAN is generated; outputting the generated template and the configuration pattern in association with each other; The hybrid cloud network construction support system according to claim 1 .

3. The computer a line status table including, as characteristics of a network via an SD-WAN router and a virtual SD-WAN router that configure the hybrid cloud network via the Internet, at least a cost when using the network and a lead time that is the time required to build a virtual network configuration using the network; The processor: replacing the configuration patterns according to the cost and the lead time of the line status table, and outputting the configuration patterns after the replacement. The hybrid cloud network construction support system according to claim 1 .

4. The hybrid cloud network construction support system includes: a controller that monitors availability of the hybrid cloud network over the Internet; The line status table stores an expected throughput expected for the network as the characteristic, The processor: acquiring an actual measurement value of the throughput from the controller periodically or at an arbitrary timing; If the acquired throughput and the expected throughput differ by a predetermined value or more, the expected throughput is rewritten to the actual measured value of the throughput. The hybrid cloud network construction support system according to claim 3 .

5. A hybrid cloud network construction support method for supporting construction of a hybrid cloud network in which an on-premises environment and a public cloud environment are connected via the Internet by a computer having a processor and a memory, comprising: The computer Based on requirements for connection and traffic between the on-premises environment and the public cloud environment specified by a user, a topology table for managing the connection forms of the SD-WAN routers and virtual SD-WAN routers that make up the hybrid cloud network, and a table that defines the conditions for software control functions to be held by the SD-WAN routers and the virtual SD-WAN routers, enumerate configuration patterns of virtual networks that meet the requirements; Calculating the throughput and the score for each of the listed configuration patterns based on the listed configuration patterns, an environment for realizing the hybrid cloud network, software control functions of the SD-WAN router and the virtual SD-WAN router in the environment, and a table that defines scores that are indicators showing the throughput of the hybrid cloud network when the functions are applied and the ratio of the actual throughput to the theoretical value of the line speed of the hybrid cloud network; outputting the configuration pattern in which the calculated throughput and score satisfy a predetermined condition; A hybrid cloud network construction support method comprising:

6. The computer By applying the configuration pattern to a predetermined format for configuring the hybrid cloud network, a configuration template required for constructing the hybrid cloud network including the SD-WAN and the virtual SD-WAN is generated; outputting the generated template and the configuration pattern in association with each other; The hybrid cloud network construction support method according to claim 5 .

7. The computer a line status table including, as characteristics of a network via an SD-WAN router and a virtual SD-WAN router that configure the hybrid cloud network via the Internet, at least a cost when using the network and a lead time that is the time required to build a virtual network configuration using the network; replacing the configuration patterns according to the cost and the lead time of the line status table, and outputting the configuration patterns after the replacement. The hybrid cloud network construction support method according to claim 5 .

8. The line status table stores an expected throughput expected for the network as the characteristic, The computer periodically or at any timing, acquiring the actual measured value of the throughput from a controller that monitors the availability of the hybrid cloud network via the Internet, the controller being included in the hybrid cloud network construction support system; If the acquired throughput and the expected throughput differ by a predetermined value or more, the expected throughput is rewritten to the actual measured value of the throughput. The hybrid cloud network construction support method according to claim 7 .

Citation Information

Patent Citations

  • Connection with private network resources in public cloud

    JP2017518696A

  • Network system and connection method

    JP2021087190A