Background technique
Calculating is one of the topic that IT infrastructure field is most popular in recent years, to the various moneys such as calculating, network, storage
The virtualization abstraction in source provides extremely convenient resource using mode and flexible resource expansion ability for user.
Mixed cloud is one of most important application model of field of cloud calculation in recent years, has merged public cloud and private clound
Advantage, provide more flexible, convenient, fast, efficient cloud computing service ability for enterprise.
From the angle of safety and scalability, the demand that user usually has mixed cloud to apply, such as by enterprise's secret
Data and service operation are in private clound, and the public service externally provided is then deployed in public cloud, therefore user's is publicly-owned
Cloud VPC (virtual private cloud) and private clound have the demand to interconnect.
A kind of cloud computing operating system of the Openstack as open source has all obtained extensively in public cloud and private clound field
General application.Publicly-owned cloud platform based on openstack and other cloud platforms carry out mixed cloud and interconnect to be also at present in the industry
Compare urgent demand.Currently the way of mainstream is realized based on IP Sec VPN technologies in the industry, and the defect of this method is
Directly interconnected by internet, and internet is that data packet is forwarded by the way of doing one's best, therefore it is general difficult
To guarantee the quality of mixed cloud interconnection, Openstack lacks the tenability interconnected to VPC special line.
For the mixed cloud interconnection problem for being currently based on Openstack, the present invention devises a kind of mixed cloud network interconnection
Method and system, to realize the interconnection of the several scenes such as public cloud and private clound, private clound and private clound, public cloud and public cloud
Intercommunication.
Summary of the invention
In order to compensate for the shortcomings of the prior art, the present invention provides a kind of mixed cloud network interconnecting method being simple and efficient and
System.
The present invention is achieved through the following technical solutions:
A kind of mixed cloud network interconnecting method, which comprises the following steps:
1) it is interconnected firstly, buying physics special line from operator for mixed cloud;
2) No. vlan for planning a special line internet;
3) special line vlan is transparent on the business network of Openstack by L2 link layer;
4) the provider network of an Openstack is created, and creates a special line on the provider network
Forwarding router vrouter;
5) one piece of network interface card is added on special line forwarding router vrouter, which is located at the public affairs that need to carry out special line interconnection
Have in cloud VPC;
6) addition reaches mixed cloud pair on the routing table qrouter of public cloud VPC and special line forwarding router vrouter
The special line at end interconnects routing entry;
7) addition reaches the special line interconnection routing entry of local terminal and passes through at the special line Internet exportation of mixed cloud opposite end
IGP advertisement is gone out.
System based on mixed cloud network interconnecting method of the present invention, it is characterised in that: including northbound interface, VPC special line number
According to library, special line forwarding router vrouter management module and special line interconnect routing table management module, and the northbound interface module is
Cloud management platform provides the entrance of dedicated line operation, and the VPC special line database is responsible for recording the special line configuration information of user, described
Line forwarding router vrouter management module is responsible for the management of special line forwarding virtual router, and the special line interconnects routing table pipe
The special line managed on module maintenance vrouter and qrouter interconnects routing table information.
The northbound interface supports the newly-built of opposite end routing table special line, deletes and modification operates.
The special line configuration information of the VPC special line data-base recording includes special line number, special line anchor point address, special line vlan
Number, the route prefix list of special line opposite end, the vrouter that special line uses, the associated qrouter information of special line and user pass through
Operation information of the northbound interface to special line.
When special line breaks down, special line recovery or reconstruction can be carried out according to the relevant information in VPC special line database.
The special line forwarding router vrouter management module includes addition to the management of special line forwarding virtual router
Vrouter deletes the addition and deletion of virtual interface on vrouter and vrouter.
When user adds a special line, the special line forwarding router vrouter management module is needed the user's
A vrouter is created on provider network, and adds one piece of network interface card on the vrouter, which, which is located at, needs to interconnect
Public cloud VPC in;When user deletes special line, then special line forwarding router vrouter management module is needed to delete
vrouter。
When user creates a vpc special line, a vrouter can be created first, is then interconnected and is routed by the special line
Table management module adds the routing for reaching interconnection opposite end route prefix in the routing table on the vrouter, instructs vrouter will
The flow of special line interconnection is sent to the special line anchor point of opposite end, and is also added in the routing table qrouter of local terminal VPC up to interconnection opposite end
Their next-hop is directed toward vrouter, makes VPC special line flow that can smoothly reach opposite end special line anchor by the routing of route prefix
Point, to finally be sent to destination;The VPC prefix that opposite end need to only configure an arrival local terminal vrouter at special line anchor point is anti-
To routing.
The beneficial effects of the present invention are: the mixed cloud network interconnecting method and system, using the VPC mutual contact mode of special line,
Have the characteristics that high security, physical isolation, ensure that the reliability and safety of mixed cloud interconnection, can be used for public cloud and private
There is the special line of the several scenes such as cloud, private clound and private clound, public cloud and public cloud to interconnect.
Specific embodiment
In order to which technical problems, technical solutions and advantages to be solved are more clearly understood, tie below
Drawings and examples are closed, the present invention will be described in detail.It should be noted that specific embodiment described herein is only used
To explain the present invention, it is not intended to limit the present invention.
The mixed cloud network interconnecting method, comprising the following steps:
1) it is interconnected firstly, buying physics special line from operator for mixed cloud;
2) No. vlan for planning a special line internet;
3) special line vlan is transparent on the business network of Openstack by L2 link layer;
4) the provider network of an Openstack is created, and creates a special line on the provider network
Forwarding router vrouter;
5) one piece of network interface card is added on special line forwarding router vrouter, which is located at the public affairs that need to carry out special line interconnection
Have in cloud VPC;
6) addition reaches mixed cloud pair on the routing table qrouter of public cloud VPC and special line forwarding router vrouter
The special line at end interconnects routing entry;
7) addition reaches the special line interconnection routing entry of local terminal and passes through at the special line Internet exportation of mixed cloud opposite end
IGP advertisement is gone out.
Based on the system of the mixed cloud network interconnecting method, including northbound interface, VPC special line database, special line forwards road
Routing table management module is interconnected by device vrouter management module and special line, the northbound interface module provides for cloud management platform
The entrance of dedicated line operation, the VPC special line database are responsible for recording the special line configuration information of user, the line forwarding router
Vrouter management module is responsible for the management of special line forwarding virtual router, the special line interconnection routing table management module maintenance
Special line on vrouter and qrouter interconnects routing table information.
The northbound interface supports the newly-built of opposite end routing table special line, deletes and modification operates.
For example, a newly-built mixed cloud interconnects special line, deletes an existing special line, adds opposite end into an existing special line
Routing entry etc..
The special line configuration information of the VPC special line data-base recording includes special line number, special line anchor point address, special line vlan
Number, the route prefix list of special line opposite end, the vrouter that special line uses, the associated qrouter information of special line and user pass through
Operation information of the northbound interface to special line.
When special line breaks down, special line recovery or reconstruction can be carried out according to the relevant information in VPC special line database.
The special line forwarding router vrouter management module includes addition to the management of special line forwarding virtual router
Vrouter deletes the addition and deletion of virtual interface on vrouter and vrouter.
When user adds a special line, the special line forwarding router vrouter management module is needed the user's
A vrouter is created on provider network, and adds one piece of network interface card on the vrouter, which, which is located at, needs to interconnect
Public cloud VPC in;When user deletes special line, then special line forwarding router vrouter management module is needed to delete
vrouter。
When user creates a vpc special line, a vrouter can be created first, is then interconnected and is routed by the special line
Table management module adds the routing for reaching interconnection opposite end route prefix in the routing table on the vrouter, instructs vrouter will
The flow of special line interconnection is sent to the special line anchor point of opposite end, and is also added in the routing table qrouter of local terminal VPC up to interconnection opposite end
Their next-hop is directed toward vrouter, makes VPC special line flow that can smoothly reach opposite end special line anchor by the routing of route prefix
Point, to finally be sent to destination;The VPC prefix that opposite end need to only configure an arrival local terminal vrouter at special line anchor point is anti-
To routing.
It is illustrated below using adding a VPC special line as embodiment.
Assuming that preparation is ready for, having built up such as special line provider network (10.1.0.0/24) is tool below
Body executes process.
1, CMS (cloud management systems) calls special line management northbound interface to create a special line;
2, special line northbound interface will be in the relevant information write-in special line database of the special line;
3, vrouter management module creates a vrouter, such as vr-1 in provider network;
4, Vrouter management module adds one piece of network interface card into vr-1, which is located in vpc-1, and address is
10.2.0.26;
5, special line routing management module adds the routing iinformation for reaching all route prefix of user's private clound into vr-1, under
One jumps as VPC special line opposite end anchor point 10.1.0.1;
6, the routing iinformation for reaching all route prefix of user's private clound is added in special line routing management module case qr-1, under
One jumps the entry address vpc-1 for being vrouter, i.e. 10.2.0.26;
7, the reverse route of VPC prefix is added on the special line anchor point of opposite end, and this routing is passed through in local private clound
IGP advertisement is gone out.
So far, special line addition work is completed, and the empty machine in local terminal VPC and the host in the private clound of opposite end can realize interconnection
Intercommunication.The forwarding road of message when special line interconnects is introduced so that the empty machine in VPC sends message to opposite end private clound as an example below
Diameter and detailed process, empty machine address are 10.2.0.1, far-end address 20.0.0.1.
Request message process, comprising the following steps:
1, certain host of empty machine into opposite end private clound initiates communication in Vpc, it is assumed that peer IP address 20.0.0.1 is then reported
Text is sent to the gateway qr-1 of vpc-1 first;
2, gateway qr-1 searches local routing table after receiving message, it is found that the next-hop of 20.0.0.1 is vr-1, then will
Message is sent to vr-1;
3, Vr-1 searches local routing table after receiving message, it is found that the next-hop of 20.0.0.1 is special line opposite end anchor point
10.1.0.1, message is then sent to special line opposite end anchor point;
4, after special line opposite end anchor point receives message, message is sent into the private clound of opposite end, to be sent to destination host.
Response message process, comprising the following steps:
1, the response message of private clound host reaches opposite end by IGP (Interior Gateway Protocol) routing
Special line anchor point 10.1.0.1;
2, special line anchor point searches local routing table after receiving message, it is found that the next-hop of 10.2.0.1 is vr-1
(10.1.0.2), then gives message to vr-1;
3, after Vr-1 receives message, discovery has direct-connected routing up to 10.2.0.1, and message is directly then sent to empty machine, and
Need not move through qr-1.
Therefore forward and reverse path of message forwarding is asymmetric, this is because existing on the virtual forwarding router of special line
Direct-connected routing in VPC, therefore reverse route is no longer needed to by VPC gateway.