Background
Computing is one of the most popular topics in the field of IT infrastructure in recent years, and provides users with an extremely convenient resource use mode and flexible resource expansion capability by virtualizing various resources such as computing, network, storage and the like in an abstract manner.
The hybrid cloud is one of the most important application modes in the field of cloud computing in recent years, integrates the advantages of public cloud and private cloud, and provides more flexible, convenient, fast and efficient cloud computing service capability for enterprises.
From the perspective of security and extensibility, a user generally has a requirement of a hybrid cloud application, for example, private data and business of an enterprise are operated on a private cloud, and public service provided to the outside is deployed on a public cloud, so that a vpc (virtual private cloud) of the user and the private cloud have a requirement of interconnection.
Openstack is widely applied to the fields of public cloud and private cloud as an open-source cloud computing operating system. Hybrid cloud interconnection and intercommunication between the public cloud platform based on openstack and other cloud platforms are also more urgent needs in the industry at present. The mainstream practice in the industry at present is realized based on the IP Sec VPN technology, and the method has the defects that interconnection and intercommunication are directly performed through the internet, and the internet forwards data packets in a best-effort manner, so that the quality of hybrid cloud interconnection is generally difficult to guarantee, and Openstack lacks the support capability for VPC private line interconnection.
Aiming at the problem of interconnection of mixed clouds based on Openstack, the invention designs a method and a system for interconnection of mixed cloud networks, so as to realize interconnection and intercommunication of various scenes such as public clouds and private clouds, private clouds and private clouds, public clouds and the like.
Disclosure of Invention
In order to make up for the defects of the prior art, the invention provides a simple and efficient hybrid cloud network interconnection method and system.
The invention is realized by the following technical scheme:
a hybrid cloud network interconnection method is characterized by comprising the following steps:
1) firstly, purchasing a physical special line from an operator for hybrid cloud interconnection;
2) planning a vlan number of a private internet;
3) transparently transmitting the private line vlan to an Openstack service network through an L2 link layer;
4) creating a provider network of Openstack, and creating a private line forwarding router vrouter on the provider network;
5) adding a network card on a private line forwarding router vrouter, wherein the network card is positioned in a public cloud VPC needing private line interconnection;
6) adding a special line interconnection route entry reaching a hybrid cloud opposite end on a route table qrouter and a special line forwarding router vrouter of a public cloud VPC;
7) and adding a special line interconnection route entry reaching the local terminal at the special line Internet exit of the opposite terminal of the hybrid cloud and advertising the entry through the IGP.
The system based on the hybrid cloud network interconnection method is characterized in that: the system comprises a northbound interface, a VPC special line database, a special line forwarding router vRouter management module and a special line interconnection routing table management module, wherein the northbound interface module provides an entrance for special line operation for a cloud management platform, the VPC special line database is responsible for recording special line configuration information of a user, the line forwarding router vRouter management module is responsible for managing a special line forwarding virtual router, and the special line interconnection routing table management module maintains special line interconnection routing table information on the vRouter and the qrRouter.
The northbound interface supports the operations of creating, deleting and modifying the special line of the opposite-end routing table.
The special line configuration information recorded in the VPC special line database comprises the number of special lines, the anchor address of the special lines, the vlan number of the special lines, a route prefix list of opposite ends of the special lines, vrouter used by the special lines, qrouter information related to the special lines and operation information of a user on the special lines through a northbound interface.
When the private line has a fault, the private line can be recovered or rebuilt according to the related information in the VPC private line database.
The management of the private line forwarding virtual router by the private line forwarding router vrouter management module comprises adding the vrouter, deleting the vrouter, and adding and deleting a virtual interface on the vrouter.
When a user adds a special line, the special line forwarding router vrouter management module needs to create a vrouter on the provider network of the user, and adds a network card on the vrouter, wherein the network card is positioned in a public cloud VPC needing interconnection; when the user deletes the private line, the private line is needed to forward the router vrouter management module to delete the vrouter.
When a user creates a VPC special line, a vrouter is created firstly, then a route reaching the route prefix of an interconnection opposite end is added to a route table on the vrouter by the special line interconnection route table management module, the vrouter is guided to send the flow of special line interconnection to the special line anchor point of the opposite end, the route reaching the route prefix of the interconnection opposite end is also added to the route table qrouter of the VPC of the local end, and the next hop of the route is pointed to the vrouter, so that the flow of the VPC special line can smoothly reach the special line anchor point of the opposite end, and finally the VPC special line flow is sent to a destination; the opposite end only needs to configure a VPC prefix reverse route reaching the local end vrouter at the anchor point of the special line.
The invention has the beneficial effects that: the hybrid cloud network interconnection method and system adopt a private line VPC interconnection mode, have the characteristics of high safety, physical isolation and the like, ensure the reliability and safety of hybrid cloud interconnection, and can be used for private line interconnection of various scenes such as public cloud and private cloud, private cloud and private cloud, public cloud and the like.
Detailed Description
In order to make the technical problems, technical solutions and advantageous effects to be solved by the present invention more clearly apparent, the present invention is described in detail below with reference to the accompanying drawings and embodiments. It should be noted that the specific embodiments described herein are only for explaining the present invention and are not used to limit the present invention.
The hybrid cloud network interconnection method comprises the following steps:
1) firstly, purchasing a physical special line from an operator for hybrid cloud interconnection;
2) planning a vlan number of a private internet;
3) transparently transmitting the private line vlan to an Openstack service network through an L2 link layer;
4) creating a provider network of Openstack, and creating a private line forwarding router vrouter on the provider network;
5) adding a network card on a private line forwarding router vrouter, wherein the network card is positioned in a public cloud VPC needing private line interconnection;
6) adding a special line interconnection route entry reaching a hybrid cloud opposite end on a route table qrouter and a special line forwarding router vrouter of a public cloud VPC;
7) and adding a special line interconnection route entry reaching the local terminal at the special line Internet exit of the opposite terminal of the hybrid cloud and advertising the entry through the IGP.
The system based on the hybrid cloud network interconnection method comprises a northbound interface, a VPC (virtual private network) private line database, a private line forwarding router vrouter management module and a private line interconnection routing table management module, wherein the northbound interface module provides a private line operation entrance for a cloud management platform, the VPC private line database is responsible for recording private line configuration information of a user, the line forwarding router vrouter management module is responsible for managing a private line forwarding virtual router, and the private line interconnection routing table management module maintains private line interconnection routing table information on the vrouter and the qrouter.
The northbound interface supports the operations of creating, deleting and modifying the special line of the opposite-end routing table.
For example, a hybrid cloud interconnection private line is newly established, an existing private line is deleted, an opposite-end routing entry is added to an existing private line, and the like.
The special line configuration information recorded in the VPC special line database comprises the number of special lines, the anchor address of the special lines, the vlan number of the special lines, a route prefix list of opposite ends of the special lines, vrouter used by the special lines, qrouter information related to the special lines and operation information of a user on the special lines through a northbound interface.
When the private line has a fault, the private line can be recovered or rebuilt according to the related information in the VPC private line database.
The management of the private line forwarding virtual router by the private line forwarding router vrouter management module comprises adding the vrouter, deleting the vrouter, and adding and deleting a virtual interface on the vrouter.
When a user adds a special line, the special line forwarding router vrouter management module needs to create a vrouter on the provider network of the user, and adds a network card on the vrouter, wherein the network card is positioned in a public cloud VPC needing interconnection; when the user deletes the private line, the private line is needed to forward the router vrouter management module to delete the vrouter.
When a user creates a VPC special line, a vrouter is created firstly, then a route reaching the route prefix of an interconnection opposite end is added to a route table on the vrouter by the special line interconnection route table management module, the vrouter is guided to send the flow of special line interconnection to the special line anchor point of the opposite end, the route reaching the route prefix of the interconnection opposite end is also added to the route table qrouter of the VPC of the local end, and the next hop of the route is pointed to the vrouter, so that the flow of the VPC special line can smoothly reach the special line anchor point of the opposite end, and finally the VPC special line flow is sent to a destination; the opposite end only needs to configure a VPC prefix reverse route reaching the local end vrouter at the anchor point of the special line.
The following description will be made by taking an example of adding a VPC line.
Assuming that the preparation has been done, the specific implementation flow is as follows as the private provider network (10.1.0.0/24) has been built.
1. CMS (cloud management systems) calls a special line management north interface to create a special line;
2. the special line north interface writes the relevant information of the special line into a special line database;
3. the method comprises the steps that a vrouter management module creates a vrouter in a provider network, such as vr-1;
4. the Vouter management module adds a network card to vr-1, the network card is located in vpc-1, and the address is 10.2.0.26;
5. the special line route management module adds route information reaching all route prefixes of the private cloud of the user to vr-1, and the next hop is a VPC special line opposite end anchor point 10.1.0.1;
6. adding routing information reaching all routing prefixes of the private cloud of the user into the special routing management module box qr-1, wherein the next hop is a vpc-1 entry address of the vrouter, namely 10.2.0.26;
7. and adding a reverse route of the VPC prefix on the opposite-end private line anchor point, and advertising the route in the local private cloud through the IGP.
And at this point, the private line adding work is finished, and the virtual machine in the VPC at the home terminal and the host machine in the private cloud at the opposite terminal can realize interconnection. Next, a forwarding path and a detailed process of a message when a private line is interconnected are described by taking an example in which a virtual machine in a VPC sends a message to an opposite private cloud, where the virtual machine address is 10.2.0.1 and the remote address is 20.0.0.1.
The message requesting process comprises the following steps:
1. a virtual machine in the Vpc initiates communication to a host in an opposite-end private cloud, and if an opposite-end IP address 20.0.0.1 is assumed, a message is firstly sent to a gateway qr-1 of the Vpc-1;
2. after receiving the message, the gateway qr-1 searches a local routing table, finds that the next hop of 20.0.0.1 is vr-1, and then sends the message to vr-1;
3. vr-1 searches a local routing table after receiving the message, finds that the next hop of 20.0.0.1 is a special line opposite terminal anchor point 10.1.0.1, and then sends the message to the special line opposite terminal anchor point;
4. after receiving the message, the anchor point of the opposite end of the private line sends the message into the private cloud of the opposite end, thereby sending the message to the target host.
The message response process comprises the following steps:
1. the response message of the private cloud host reaches an opposite-end special line anchor point 10.1.0.1 through an IGP (inter air Gateway protocol) route;
2. after receiving the message, the private line anchor point searches a local routing table, finds that the next hop of 10.2.0.1 is vr-1(10.1.0.2), and then sends the message to vr-1;
3. after Vr-1 receives the message, it finds that the direct connection route can reach 10.2.0.1, and then directly sends the message to the virtual machine without going through qr-1.
As can be seen from the above, the forward and reverse paths for forwarding the packet are asymmetric, because the direct route in the VPC exists on the private virtual forwarding router, the reverse route does not need to pass through the VPC gateway.