OpenStack Virtual Firewall With VPP Forwarding And Tenant-Specific Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual firewalls based on the OpenStack framework face limitations in forwarding efficiency due to bandwidth bottlenecks in native routing services and lack of differentiated data packet processing rules for different users in Vector Packet Processing (VPP) services.
Innovation Solution
Modify the firewall rule of a target data packet service using a preset rule, integrate a forwarding stack with higher performance, and provide a firewall configuration interface to set user-specific data packet processing rules, replacing the OpenStack routing service with a modified Vector Packet Processing (VPP) service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the native routing service of the OpenStack framework is used to control data packets based on the packet rule table, then the data packet control function is achieved, but the forwarding efficiency is limited by the bandwidth of the virtual routing
Solution Approach 1:
The patent changes the forwarding parameters by replacing the traditional routing service with a Vector Packet Processing (VPP) service that supports higher bandwidth forwarding. The VPP service uses optimized data structures and processing algorithms to achieve faster packet forwarding while maintaining the firewall rule-based control functionality.
Solution Approach 2:
The patent substitutes the mechanical routing service mechanism with a more advanced VPP service mechanism. The VPP service employs vectorized packet processing and optimized memory access patterns to replace the traditional routing table lookup and forwarding mechanism, achieving higher forwarding efficiency.
2Productivity
If the Vector Packet Processing (VPP) service is introduced to replace the packet processing mechanism of OpenStack, then the forwarding efficiency is improved, but the data packet processing rules are the same in one network and cannot meet the needs of different users
Solution Approach 1:
The patent segments the network into multiple virtual networks, each with its own set of data packet processing rules. The VPP service is configured to support multiple virtual networks independently, allowing each user or tenant to have customized firewall rules and packet processing policies specific to their virtual network requirements.
Solution Approach 2:
The patent makes the VPP service multi-functional by enabling it to handle both high-performance packet forwarding and differentiated packet processing rules for multiple virtual networks simultaneously. The service is designed to be universally applicable across different network scenarios while maintaining the ability to enforce user-specific policies.
Data Source
AI summary
A virtual firewall construction method based on an OpenStack framework, and a storage medium. The method includes: modifying a firewall rule of a target data packet service according to a preset rule, and obtaining a modified target data packet service, the modified target data packet service utilizes the modified firewall rule to perform data packet control, and a forwarding stack is provided in the modified target data packet service, a forwarding performance of the forwarding stack is higher than the forwarding performance of a routing service of the OpenStack framework; a firewall configuration interface is provided in the firewall rule of the modified target data packet service, and the firewall configuration interface is configured to, according to different users under different virtual networks, set a data packet processing rule meeting requirements of the users; and replacing the routing service of the OpenStack framework according to the modified target packet service.

