WO2019011144A1 - Virtual network device, routing device and virtual network connection method - Google Patents

Virtual network device, routing device and virtual network connection method Download PDF

Info

Publication number
WO2019011144A1
WO2019011144A1 PCT/CN2018/093995 CN2018093995W WO2019011144A1 WO 2019011144 A1 WO2019011144 A1 WO 2019011144A1 CN 2018093995 W CN2018093995 W CN 2018093995W WO 2019011144 A1 WO2019011144 A1 WO 2019011144A1
Authority
WO
WIPO (PCT)
Prior art keywords
virtual
virtual network
network
interface
network device
Prior art date
Application number
PCT/CN2018/093995
Other languages
French (fr)
Chinese (zh)
Inventor
吕彪
孙成浩
祝顺民
肖寒
刘宝春
邓立龙
周嘉文
赵巍
程钢
Original Assignee
阿里巴巴集团控股有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 阿里巴巴集团控股有限公司 filed Critical 阿里巴巴集团控股有限公司
Publication of WO2019011144A1 publication Critical patent/WO2019011144A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/02Topology update or discovery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/58Association of routers
    • H04L45/586Association of routers of virtual routers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/54Store-and-forward switching systems 
    • H04L12/56Packet switching systems
    • H04L12/5601Transfer mode dependent, e.g. ATM
    • H04L2012/5619Network Node Interface, e.g. tandem connections, transit switching
    • H04L2012/562Routing

Definitions

  • the present application relates to the field of network communication technologies, and in particular, to a virtual network device, a routing device, and a connection method of a virtual network.
  • VPCs virtual private networks
  • VSwitches virtual switches
  • RouteTable virtual routing tables
  • VRouters virtual routers
  • VPCs virtual private networks
  • VSwitches virtual switches
  • RVouteTable virtual routing tables
  • VRouters virtual routers
  • one physical network device can be virtualized into multiple virtual network devices (logical network devices) through software.
  • the virtualized virtual network device can run on the physical device. Through the cooperation of software and hardware virtualization, it can have certain physical device functions. It can have independent software environment and data. For example, the virtual router can have physical router routing. Table storage and routing forwarding.
  • the purpose of the present application is to provide a method for connecting a virtual network device, a routing device, and a virtual network, and the independently configured communication between the virtual network and the plurality of virtual networks/physical networks can be realized through the newly designed virtual device interface.
  • a virtual network device, a routing device, and a virtual network connection method provided by the present application are implemented as follows:
  • a virtual network device that accesses a first virtual network and communicates with a second virtual network device in a second network, the virtual network device including at least one virtual device interface, the virtual device interface configured to
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • a virtual network device accessing the first physical network and communicating with a second virtual network device in the second network, the virtual network device including at least one virtual device interface, the virtual device interface configured to
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • a routing device comprising a memory storing computer executable instructions, accessing a virtual device interface of a first virtual network, and communicating with a second virtual network device in a second network, the instructions being executed by the processor
  • the virtual device interface implements at least:
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • a method for connecting a virtual network comprising: accessing a first virtual network device of a first network, and a second virtual network device accessing a second network, where the first virtual network device is configured with at least one first virtual device interface, The second virtual network device is configured with at least one second virtual device interface, and at least one of the first network and the second network is a virtual network.
  • the first virtual device interface sends a connection request to the second virtual device interface, where the connection request is generated according to the configuration information of the first virtual device interface and the verification information of the second virtual device interface;
  • the second virtual network device verifies the connection request, and after the verification succeeds, configures the second virtual device interface according to the configuration information of the first virtual device interface, and returns verification to the first virtual network device. Success message
  • the first virtual network device After receiving the verification success message, the first virtual network device configures the first virtual device interface according to the configuration information of the virtual device interface of the second network, and establishes an interface with the second virtual device. Communication connection.
  • a computer readable storage medium having stored thereon computer instructions for accessing a first virtual network and communicating with a second virtual network device in a second network, the virtual network device including at least one virtual device interface
  • the virtual device interface is implemented at least when the instructions are executed:
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • a virtual network device comprising: a processor, and a memory storing computer executable instructions, the instructions being executed by the processor, configuring a virtual network device for the first virtual network, and configuring the virtual network device
  • the virtual device interface on the at least:
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device is established.
  • a virtual network device includes at least one virtual device interface, the virtual device interface configured to
  • the present invention provides a virtual network device, a routing device, and a virtual network connection method, and constructs a new virtual network device, and implements a virtual network and one or more virtual networks/physical through a virtual device interface configured on the virtual network device.
  • the connection between the networks When multiple virtual/physical networks need to be connected, multiple virtual device interfaces can be created to complete the connection with multiple virtual/physical networks.
  • the embodiment of the present application adds the concept of a router interface like a physical router, and is expanded based on the characteristics of the virtual network and the physical network.
  • the virtual network device in the present application can connect to different virtual networks and connect multiple virtual networks. / Physical network, and can also better realize private line access in the physical network to meet the functions and scenarios of inter-network interworking.
  • an implementation scheme of an extended virtual network and a plurality of different virtual network/physical networks is realized, and an independent connection point management function is provided, so that virtual network design, resource service/sharing, inter-network interworking, and node management are implemented. More flexible and convenient, it is conducive to improving the product service experience of virtual networks.
  • FIG. 1 is a schematic diagram of a network topology structure of a network environment in which a virtual network device is provided according to the present application;
  • FIG. 2 is a schematic diagram of an implementation scenario of a virtual network device in a virtual network provided by the present application
  • FIG. 3 is a schematic diagram of a virtual network device configured after a routing table is persistent on a DB in an embodiment of the present application;
  • FIG. 4 is a schematic diagram of virtual device interface configuration information of a virtual network device configuration according to the present application.
  • FIG. 5 is a schematic diagram of processing of a state machine of a virtual device interface provided by the present application.
  • FIG. 6 is a schematic diagram of data configuration of a border virtual network device in an embodiment
  • FIG. 7 is a schematic diagram of configuration of routing table information configured on a border virtual network device in an embodiment of the present application.
  • FIG. 8 is a schematic diagram of a process flow of a scenario of a method for connecting a virtual network according to the present application.
  • the virtual network described in the present application generally refers to a computer network including at least a part of a virtual network link, where the virtual network link may refer to not including a physical connection between two computing devices, but through network virtualization.
  • a virtual network of a scenario is usually based on the exchange technology, and the network node is divided into several "logical work groups" according to the nature of work and needs, and a "logical work group" can be a virtual local area network ( VLAN, Virtual Local Area Network, virtual local area network, a protocol-based virtual network).
  • VLAN Virtual Local Area Network
  • virtual local area network a protocol-based virtual network
  • the present application provides a novel virtual network device, which not only has the functions and features of the existing virtual router, but also adds the concept of a router interface like a physical router, and can also be extended based on the characteristics of the virtual network and the physical network (for example) Adding user information, tunnel/encapsulation information of the virtual network, physical network VLAN, physical port information, circuit coding, etc., enables the new virtual network device to connect to different virtual networks as well as virtual and physical networks.
  • the virtual network device described in the present application may include a network connection virtual machine, a virtual switch, a virtual router, and the like inside a hypervisor (an intermediate software layer running between a physical server and an operating system).
  • the virtual network device described in this application may specifically include virtualizing one physical network device into multiple virtual network devices by using network device virtualization technology.
  • the virtual network device in the embodiment of the present application can be run on a physical device, and can have a certain physical device function through the cooperation of software and hardware virtualization, and can have a separate software environment and data.
  • a virtual network device, such as an embodiment of the present application may be configured to run on a physical router having a routing table storage and routing forwarding function, and implement a virtual network and multiple virtual networks/physical networks through a virtual device interface configured on the virtual network device. Independently manageable connectivity.
  • FIG. 1 is a schematic diagram of a network topology structure of a network environment in which a virtual network device is provided according to the present application.
  • the virtual network device may be in a virtual network (eg, the virtual network device is in the first virtual network VNetDev-1), has a routing function, and has a virtual device interface on the device, based on the interface.
  • the function of the above physical network can be better realized, the routing function of the virtual network accessed by the local end, and the connection between the virtual network and other network VNetDev-2 (virtual network), or between the virtual network and the physical network.
  • the virtual network is connected to the physical network (VNetDev-3).
  • Each virtual network device provided by the present application can simultaneously connect multiple virtual network/physical networks (which can be done by establishing multiple virtual device interfaces on the virtual network device). Moreover, each virtual network device can independently manage the connection with other virtual network/physical networks (which can be done by activating/deactivating the virtual device interface on the device). In addition, the virtual network device may also complete the configuration of the firewall and the security domain based on the virtual device interface.
  • the virtual network device may be classified into multiple implementation types according to the network environment in which the virtual network device is located (in the virtual network/on the border device, etc.).
  • 2 is a schematic diagram of an implementation scenario of a virtual network device in a virtual network provided by the present application, which may provide a routing function in the virtual network and communicate with the other network (virtual network or physical network). Specifically, as shown in FIG.
  • the virtual network device is in the virtual network (for example, the virtual network device is in the first virtual network VNetDev-1), has a routing function, and has a virtual device interface on the device, based on The interface can better implement the functions of the above physical network, provide the routing function of the virtual network accessed by the local end, and connect the virtual network with other networks VNetDev-2 (virtual network or physical network).
  • the virtual network device accesses the first virtual network, and may communicate with a second virtual network device in the second network, where the virtual network device may include At least one virtual device interface, the virtual device interface can be configured to
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • the virtual network in which the virtual network device is located (which may be referred to as the first virtual network in this embodiment) and the virtual network connected to the peer end may be configured with virtual network devices (here A virtual network device on the other side with respect to the side of the local end is referred to as a second virtual network device, and a virtual device interface (Inf) may be separately created on a virtual network device (VNetDevice) on the two virtual networks.
  • the information of the second network virtual device, the second virtual device interface of the second virtual network device, the second virtual network device owner, and the like may be configured in the created Inf for the handshake of the communication parties.
  • At least one side of the communication is a virtual network. Therefore, in some embodiments, the second network may be a virtual network or a physical network.
  • the verification information of the second network virtual device, the second virtual device interface of the second virtual network device, the second virtual network device owner, and the like, and the configuration information of the first virtual network information may be placed in the request.
  • the connection information of the device, the interface, the owner, and the like in the request may be checked. If the information is correct, the connection request is returned and the configuration information of the virtual network is attached.
  • the virtual device interface of the first network and the second network can enter the state of connection, and configure the configuration information of the virtual network of the other party to the Encap/Decap configuration of the virtual device interface, and enter the Active state after the configuration is completed. . If the connection request information is incorrect, the connection request can be rejected. Therefore, in one embodiment, the configuring the virtual device interface based on the configuration information of the second network returned by the second virtual network device may include:
  • the virtual device interface is set to an active state based on the verification success message.
  • the virtual network device is in a virtual network, and the virtual network device may be configured with the following characteristic information:
  • ID indicates the internal ID of the virtual network device, used to persist the internal ID of the storage, such as the primary key (initial key) on the user DB (Database);
  • Name the name of the virtual network device
  • VirtualNetworkID ID of the virtual network where the virtual device is located
  • OwnerID The owner ID of this virtual network device.
  • FIG. 3 is a schematic diagram of a virtual network device configured after the routing table is persistent on the DB in an embodiment of the present application.
  • the created virtual device interface can be configured with the following feature information:
  • the internal ID of the virtual device interface used to persist the internal ID of the storage, such as the primarykey on the user DB;
  • Name the name of the virtual device interface
  • VirtualNetworkDeviceID ID of the virtual network device where the virtual device interface is located.
  • OppositeVirtualNetworkDeviceID the ID of the virtual network device of the second network to which the virtual device interface is connected;
  • OppositeVirtualDeviceInterfaceID ID of the router interface of the virtual device interface of the second network to which the virtual device interface is connected;
  • OppositeVirtualNetworkDeviceOwnerID The owner ID of the virtual network device of the second network to which the virtual device interface is connected. It is used to handshake and authenticate the identity when the two virtual device interfaces are connected.
  • FIG. 4 is the present application.
  • a schematic diagram of virtual device interface configuration information of a virtual network device configuration wherein Encap/Decap can save the unpacking logic of the data packets between the interface virtual networks (data packets of different virtual networks need to be converted) or virtual network
  • the unpacking logic of the packet with the physical network the packet between the virtual network and the physical network needs to be translated).
  • the Encap/Decap configuration acquires configuration information from the second virtual network device and configures it on its own virtual network device after the virtual device interface initiates the connection request.
  • the device may also:
  • the decapsulation logic information of the data packet used by the second network and generating the first virtual network according to the decapsulation logic information of the data packet used by the first virtual network.
  • Decapsulation processing logic of a data packet between the second networks configuring the decapsulation processing logic in configuration information of a virtual device interface corresponding to the second network.
  • each virtual network device may also complete a firewall and a security domain configuration based on the virtual device interface, and implement interface-level security protection settings.
  • the interface that can be flexibly managed and configured according to the embodiment of the present application can implement the security protection function application of the physical router conveniently and flexibly, and improve the flexibility and scalability of the virtual network security and configuration.
  • the connection may be initiated from the second virtual Obtaining, by the network device, the decapsulation logic information of the data packet used by the second network, and generating, according to the decapsulation logic information of the data packet used by the first virtual network, between the first virtual network and the second network. Decapsulation processing logic of the data packet;
  • the decapsulation processing logic is configured in configuration information of a virtual device interface corresponding to the second network.
  • the verification information of the connected second network and the configuration information of the first virtual network may be sent to the second network, where the second network is a virtual network or a physical network, and the first virtual
  • the configuration information of the network is used for configuration of the second virtual device interface of the virtual network device in the second network, so that the second virtual network device verifies the connection request.
  • it can be verified whether the configuration information of the second virtual network device included in the connection request is correct/legal, such as whether the virtual network device name in the connection request is correct, whether the connected virtual device interface is stored, and second. Whether the owner information of the virtual network device is consistent with its own network information. If the verification passes, you can return a message that the verification was successful.
  • the second virtual network device After receiving the verification success message sent by the second virtual network device (also referred to as a connection confirmation message), setting the virtual device interface set in the connection request to an active state, and according to the configuration information of the second network Configure the virtual device interface of the first virtual network. After the configuration is completed, a communication connection with the second virtual device interface of the second network can be established.
  • At least one of the local network and the second network is a virtual network, for example, the local network is a virtual network, and the second network is a physical network.
  • the virtual network in which the determined virtual network device is located may be referred to as a first virtual network
  • the other network is referred to as a second network.
  • the second network may be a virtual network or a physical network.
  • the first network and the second network which are described below in the present application, refer to two networks connected in one virtual network, which are distinguished names of the local network that initiates the connection and the second network that needs to be connected.
  • the first network may also be connected to other virtual networks other than the second network.
  • another network connected may be referred to as a third network with respect to the second network.
  • the third network may be relatively described as the second network with respect to the first network.
  • the first virtual network may establish a communication connection with the second network by means of communication establishment of the virtual device interface on the virtual network device.
  • the connection request sent to the second network virtual device may further include the following verification information:
  • the identification identifier of the second virtual network device the identification identifier of the second virtual device interface in the second virtual network device, and the identification identifier of the owner of the second virtual network device.
  • the verification information may include an identification identifier of the second virtual network device to which the virtual device interface of the first virtual network is connected, an identification identifier of the second virtual device interface to which the virtual device interface of the first virtual network is connected, and The identification of the owner of the second virtual network device, and the like.
  • the configuration information of the local network may include, for example, an identification identifier of the virtual network device in the first virtual network, an identification identifier of the first virtual network, and an identifier of the virtual device interface used to establish a connection with the second network. Wait.
  • connection request may further include other field information, a network type/mode of the first virtual network, a timestamp, and the like in the actual application implementation process.
  • the specific settings can be made according to the application scenario.
  • the authentication information of the peer end and the configuration information of the local end are combined into a connection request and sent to the second virtual network device.
  • the present application does not exclude the configuration or location of the local end.
  • the virtual network device of the first virtual network acts as the sender of the connection request
  • the virtual network device of the second network acts as the recipient of the connection request.
  • the virtual network device of the second network may also be used as the sender of the connection request
  • the virtual network device of the first virtual network is the receiver of the connection request.
  • the virtual device interface entering the Active may interrupt the connection from the first virtual network by the anti-activation operation (the virtual device interface enters the Inactive state).
  • the data traffic of the first virtual network cannot flow through the Inactive virtual device interface, and the data traffic of the second network cannot flow through the Inactive virtual device interface. Therefore, in another embodiment of the method, the virtual device interface is further configured to
  • the inactive state is set to be inactive based on the received anti-activation command to prohibit the virtual device interface from transmitting and receiving data.
  • the first virtual device interface may be deactivated according to the anti-activation command to prohibit the first virtual device interface from performing data transmission and reception.
  • the second virtual device interface when the second virtual device interface is activated, the second virtual device interface may also be deactivated according to the anti-activation command to prohibit the second virtual device interface from performing data transmission and reception.
  • the virtual device interface entering the active state may interrupt the connection from the first virtual network by using a reverse activation operation (for example, bringing the virtual device interface into an anti-active state), and the traffic of the first virtual network is Unable to flow out through the deactivated virtual device interface, traffic of the second network cannot flow through the deactivated virtual device interface, so that each virtual network device can independently manage the connection with other virtual network or physical network, making virtual Network connection management and more are more flexible, and can also improve the security of the network.
  • a reverse activation operation for example, bringing the virtual device interface into an anti-active state
  • the virtual device interface in the activated state may be deleted from the virtual network device by the deletion operation, and the interface occupation of the virtual network device is released, thereby reducing the virtual network device to the resource. Consumption. Therefore, in another embodiment, the virtual network device further deletes the virtual device interface in the inactive state specified in the virtual network device based on the received interface deletion instruction.
  • FIG. 5 is a schematic diagram of processing of a state machine of a virtual device interface provided by the present application.
  • the first network may establish a connection with multiple virtual networks or physical networks such as the third network and the fourth network.
  • the third network may establish a connection between the virtual network and the virtual network and the physical network by establishing a connection between the network virtual device and the fifth network and the sixth network, which are also provided with the network virtual device. Therefore, in an embodiment of the virtual network device of the present application, the first virtual network may establish a communication connection with the K second networks through the virtual device interfaces of the K active states of the virtual network device, respectively. K ⁇ 2.
  • the first virtual device interface inf-1 is configured on the first virtual network device VNetDev-1 in the first virtual network VNet-1, and the second virtual network device in the second virtual network VNet-2 is configured.
  • the second virtual device interface inf-2 is configured on VNetDev-2.
  • the first virtual network VNet-1 and the second virtual network VNet-2 can establish a communication connection by handshaking and identity verification through the first virtual device interface inf-1 and the second virtual device interface inf-2 to implement interworking.
  • the first virtual network device may be configured with multiple virtual device interfaces.
  • the first virtual network device is further configured with a virtual device interface inf-10, and multiple virtual network/physical networks may be connected at the same time, such as inf- with the second virtual network device.
  • the 20 interfaces are connected, or at the same time, the virtual device of the physical network VNet-3 can be connected to the Inf-302, and the implementation of the interworking between the extended virtual network and multiple different virtual networks/physical networks can make the virtual network design, Resource service/sharing, inter-network interoperability, etc. are more flexible and convenient, which is conducive to improving the product service experience of virtual networks.
  • the implementation of the virtual device interface activation/deactivation, the deletion of the virtual device interface, and the like can completely virtualize the function that can be completed only by the physical network interface to the virtual network interface.
  • the implementation provided by the present application can completely virtualize the function that can be completed only by the physical network interface to the virtual network interface.
  • the virtual network device in the foregoing embodiment can process the routing function in the virtual network and the interworking between the virtual network and the virtual network/physical network.
  • the virtual network device may be on a border device connected to a physical network.
  • a virtual network device on the border device can connect to one or more physical interfaces on the border device.
  • multiple virtual LAN VLANs can be configured on the physical interface.
  • different virtual network devices cannot share a single VLAN on the same physical interface.
  • the routing table of the virtual network device is also persistent on the DB and then configured on the virtual network device.
  • the present application provides another implementation manner of the virtual network device. Specifically, the virtual network device accesses the first physical network, accesses the first physical network, and communicates with the second virtual network device in the second network, where the virtual network device includes at least one virtual device interface.
  • the virtual device interface is configured to
  • connection request includes configuration information of the first physical network, and configuration information of the first physical network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • the virtual network device on the border device can be configured to include the following characteristic information:
  • ID the internal ID of the virtual network device, used to persist the internal ID of the storage, such as the primarykey on the user DB;
  • Name the name of the virtual network device
  • PhysicalDeviceID The physical device ID of the virtual device
  • PhysicalInterfaceInfo Interface information on the physical device accessed by the virtual device, which may include one or more interfaces;
  • OwnerID The owner ID of this virtual network device.
  • the feature information can be persisted on the DB (storing the data to a non-volatile storage device) and then can be configured on the virtual network device, as shown in FIG. 6.
  • FIG. 6 is an embodiment of the present application. Schematic diagram of the data configuration of the boundary virtual network device.
  • a virtual network device on a border device between a virtual network and a physical network can provide connectivity between the virtual network and the physical network.
  • a boundary virtual device interface is created for the virtual network device, and a communication connection between the virtual network and the physical network is implemented through the boundary virtual device interface.
  • the virtual network device on the border device can connect to one or more physical interfaces on the border device, and multiple VLANs can be configured on the physical interface. In general, different virtual network devices cannot share a single VLAN on the same physical interface.
  • the virtual network device on the edge device may also be configured with a border virtual device interface, where the boundary virtual device interface is connected to a physical interface on the border device of the first physical network. At least one virtual local area network is configured on the physical interface, and the same virtual network device shares the same virtual local area network on the same physical interface.
  • the boundary virtual device interface connected to the physical network end may be configured to have the following characteristic information:
  • the internal ID of the virtual device interface used to persist the internal ID of the storage, such as the primarykey on the user DB;
  • Descriptio a description of the boundary virtual device interface
  • Name the name of the virtual device interface
  • VirtualNetworkDeviceID ID of the virtual network device where the border virtual device interface is located.
  • PhysicalInterfaceID ID of the physical interface where the virtual device interface is located.
  • VLAN The VLAN used by this border virtual device interface.
  • the border virtual device interface corresponds to the configuration of each ⁇ physical interface: VLAN> configured on the virtual device.
  • the above-mentioned interface characteristic information can be persistent on the DB, and then can be configured on the virtual network device, as shown in FIG. 7.
  • FIG. 7 is the routing table information configured on the border virtual network device in an embodiment of the present application. Schematic diagram of the configuration.
  • a virtual network device can be connected to a physical interface on one or more border devices (such as a router).
  • the physical network can also communicate with multiple virtual networks through a configured virtual local area network VLAN. Multiple VLANs can also be configured on the physical interface. Generally, different virtual network devices cannot share one VLAN on the same physical interface.
  • the virtual network can communicate with multiple physical networks, and the physical network can also communicate with multiple virtual networks through the configured virtual local area network VLAN, and the virtual network device on the border device has more
  • the independent connection point management function makes virtual network design, resource service/sharing, inter-network interworking, node management, etc. more flexible and convenient, and can improve the product service experience of the virtual network.
  • the virtual network device described in this application may specifically include virtualizing one physical network device into multiple virtual network devices by using network device virtualization technology.
  • the virtual network device in the embodiment of the present application may be configured to run on a physical device, and may have a function of a physical device by using a combination of software and hardware virtualization, and may have an independent software environment and data, such as a virtual network in the embodiment of the present application.
  • the device is configured to run on a physical router with routing table storage and routing forwarding functions, and realizes independently manageable communication between the virtual network and multiple virtual networks/physical networks through a virtual device interface configured on the virtual network device.
  • the present application provides a routing device, which may be a processing device that can communicate between a virtual network and a virtual network/physical network, and implement communication between the virtual network and the virtual network/physical network. Connection and independent connection point management.
  • a routing device including a memory storing computer executable instructions, accessing a virtual device interface of a first virtual network, and communicating with a second virtual network device in a second network. The instructions are executed by the processor to cause the virtual device interface to at least:
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • the routing device may further set the corresponding virtual device interface to an inactive state based on the received anti-activation command to prohibit data transmission and reception.
  • the routing device deletes the corresponding inactive virtual device interface based on the received deletion instruction, and the second network is a virtual network or a physical network.
  • FIG. 8 is a schematic flowchart of a process of connecting a method for connecting a virtual network according to an embodiment of the present disclosure.
  • At least one of the first network and the second network is a virtual network.
  • the first virtual device interface sends a connection request to the second virtual device interface, where the connection request is generated according to the configuration information of the first virtual device interface and the verification information of the second virtual device interface.
  • the second virtual network device verifies the connection request, and after the verification succeeds, configures the second virtual device interface according to the configuration information of the first virtual device interface, and sends the second virtual device interface to the first virtual network device. Return verification success message;
  • the first virtual device interface is configured according to the configuration information of the virtual device interface of the second network, and the second virtual device is established.
  • the communication connection of the interface is
  • the method or the virtual network device (including the configuration of the virtual device interface) in the foregoing embodiment of the present application may implement the business logic by using a computer program and record on the storage medium, and the storage medium may be read and executed by the computer to implement the present Apply the effects of the scheme described in the embodiment. Therefore, the present application further provides a computer readable storage medium having computer instructions stored thereon, accessing a first virtual network, and communicating with a second virtual network device in a second network, the virtual network device including at least a virtual device interface that, when executed, causes the virtual device interface to at least:
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  • the computer readable storage medium may include physical means for storing information, typically by digitizing the information and then storing it in a medium that utilizes electrical, magnetic or optical means.
  • the computer readable storage medium of this embodiment may include: means for storing information by means of electrical energy, such as various types of memories, such as RAM, ROM, etc.; means for storing information by means of magnetic energy, such as hard disk, floppy disk, magnetic tape, magnetic core Memory, bubble memory, U disk; means for optically storing information such as CD or DVD.
  • electrical energy such as various types of memories, such as RAM, ROM, etc.
  • means for storing information by means of magnetic energy such as hard disk, floppy disk, magnetic tape, magnetic core Memory, bubble memory, U disk
  • means for optically storing information such as CD or DVD.
  • quantum memories graphene memories, and the like.
  • the application further provides an apparatus embodiment, which may specifically include: a processor, and a memory storing computer executable instructions, when the instructions are executed by the processor, configuring a virtual network device for the first virtual network, And configuring a virtual device interface on the virtual network device to implement at least:
  • connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
  • the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device is established.
  • the present disclosure also provides another embodiment of a virtual network device, including at least one virtual device interface, the virtual device interface configured to
  • the foregoing description of the device, the routing device, the virtual network device, and the like may further include other implementation manners according to the description of the related method embodiments.
  • the description of the method embodiment and the description is not made herein. Narration.
  • the various embodiments in the specification are described in a progressive manner, and the same or similar parts between the various embodiments may be referred to each other, and each embodiment focuses on the differences from the other embodiments.
  • the hardware + program type embodiment since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
  • the present invention provides a virtual network device, a routing device, and a virtual network connection method, and constructs a new virtual network device, and implements a virtual network and one or more virtual networks/physical through a virtual device interface configured on the virtual network device.
  • the connection between the networks When multiple virtual/physical networks need to be connected, multiple virtual device interfaces can be created to complete the connection with multiple virtual/physical networks.
  • the embodiment of the present application adds the concept of a router interface like a physical router, and is expanded based on the characteristics of the virtual network and the physical network.
  • the virtual network device in the present application can connect to different virtual networks and connect multiple virtual networks. / Physical network, and can also better realize private line access in the physical network to meet the functions and scenarios of inter-network interworking.
  • an implementation scheme of an extended virtual network and a plurality of different virtual network/physical networks is realized, and an independent connection point management function is provided, so that virtual network design, resource service/sharing, inter-network interworking, and node management are implemented. More flexible and convenient, it is conducive to improving the product service experience of virtual networks.
  • the present application does not It must be limited to the conditions described in the industry data communication standards, routing interface configuration standards, or embodiments. Certain industry standards or implementations that have been modified in a manner that uses a custom approach or an embodiment described above may also achieve the same, equivalent, or similar, or post-deformation implementation effects of the above-described embodiments. Embodiments obtained by applying these modified or modified data definitions, interface information configurations, data processing methods, etc., may still fall within the scope of alternative embodiments of the present application.
  • the present application provides method operational steps or apparatus/topology and interface configuration information of a virtual network device as described in the preceding embodiments or the accompanying drawings, it may be included in the method or apparatus based on conventional or no inventive labor. More or some of the implementation steps after the merger.
  • the execution order of the steps or the module structure of the device is not limited to the execution order or device structure shown in the embodiment of the present application or the drawings.
  • the device or the terminal product of the method or structure it may be sequentially executed or executed in parallel according to the method or the module structure shown in the embodiment or the drawing (for example, a parallel processor or a multi-thread processing environment, Even the implementation environment for distributed processing).
  • PLD Programmable Logic Device
  • FPGA Field Programmable Gate Array
  • HDL Hardware Description Language
  • the controller can be implemented in any suitable manner, for example, the controller can take the form of, for example, a microprocessor or processor and a computer readable medium storing computer readable program code (eg, software or firmware) executable by the (micro)processor.
  • computer readable program code eg, software or firmware
  • examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, The Microchip PIC18F26K20 and the Silicone Labs C8051F320, the memory controller can also be implemented as part of the memory's control logic.
  • the controller can be logically programmed by means of logic gates, switches, ASICs, programmable logic controllers, and embedding.
  • Such a controller can therefore be considered a hardware component, and the means for implementing various functions included therein can also be considered as a structure within the hardware component.
  • a device for implementing various functions can be considered as a software module that can be both a method of implementation and a structure within a hardware component.
  • the system, device, module or unit illustrated in the above embodiments may be implemented by a computer chip or an entity, or by a product having a certain function.
  • a typical implementation device is a computer.
  • the computer can be, for example, a personal computer, a laptop computer, a car-mounted human-machine interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet.
  • each module may be implemented in the same software or software, or the modules that implement the same function may be implemented by a plurality of sub-modules or a combination of sub-units.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or integrated. Go to another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • the controller can be logically programmed by means of logic gates, switches, ASICs, programmable logic controllers, and embedding.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
  • the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
  • a computing device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
  • processors CPUs
  • input/output interfaces network interfaces
  • memory volatile and non-volatile memory
  • the memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium, such as read only memory (ROM) or flash memory.
  • RAM random access memory
  • ROM read only memory
  • Memory is an example of a computer readable medium.
  • Computer readable media includes both permanent and non-persistent, removable and non-removable media.
  • Information storage can be implemented by any method or technology.
  • the information can be computer readable instructions, data structures, modules of programs, or other data.
  • Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, Magnetic tape cartridges, magnetic tape storage or other magnetic storage devices or any other non-transportable media can be used to store information that can be accessed by a computing device.
  • computer readable media does not include temporary storage of computer readable media, such as modulated data signals and carrier waves.
  • embodiments of the present application can be provided as a method, system, or computer program product.
  • the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment in combination of software and hardware.
  • the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
  • the application can be described in the general context of computer-executable instructions executed by a computer, such as a program module.
  • program modules include routines, programs, objects, components, data structures, and the like that perform particular tasks or implement particular abstract data types.
  • the present application can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network.
  • program modules can be located in both local and remote computer storage media including storage devices.

Abstract

Provided are a virtual network device, a routing device, and a virtual network connection method. The virtual network device accesses a first virtual network and communicates with a second virtual network device in a second network, comprises at least one virtual device interface, and is configured to: send, to the second virtual network device, a connection request comprising configuration information about the first virtual network; configure, based on configuration information, returned by the second virtual network device, about the second network, the virtual device interface; and enter an activated state after configuration is completed, and establish a communication connection with a second virtual device interface of the second virtual network device in the second network. In the embodiments of the present application, communication, which can be independently managed, between a virtual network and multiple virtual networks/physical networks can be realized by means of a newly designed and configured virtual device interface, thereby realizing the functions of communication across networks and between multiple networks and the independent management of connection points, and improving virtual network management and resource/service efficiency.

Description

一种虚拟网络设备、路由设备及虚拟网络的连接方法Virtual network device, routing device and connection method of virtual network
本申请要求2017年07月11日递交的申请号为201710560716.0、发明名称为“一种虚拟网络设备、路由设备及虚拟网络的连接方法”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。The present application claims priority to Chinese Patent Application No. JP-A No. No. No. No. No. No. No. No. No. No. No. No. No. No. No. No. No. In this application.
技术领域Technical field
本申请涉及网络通讯技术领域,尤其涉及一种虚拟网络设备、路由设备及虚拟网络的连接方法。The present application relates to the field of network communication technologies, and in particular, to a virtual network device, a routing device, and a connection method of a virtual network.
背景技术Background technique
随机计算机和互联网技术的迅速发展,目前各种虚拟网络也越来越得到广泛的应用和重视。目前,虚拟网络中不同虚拟网络之间是隔离的,虚拟网络与物理网络直接也是隔离的。但是在很多场景下这些虚拟网络需要能够互相访问对方的服务/资源,甚至有些虚拟网络需要访问物理网络中的服务和资源。With the rapid development of random computers and Internet technologies, various virtual networks are now being widely used and valued. Currently, different virtual networks in a virtual network are isolated, and the virtual network and the physical network are directly isolated. However, in many scenarios, these virtual networks need to be able to access each other's services/resources, and even some virtual networks need to access services and resources in the physical network.
在虚拟网络中,为了能将虚拟网络的功能和部署与物理网络保持一致,许多虚拟网络设备被设计出来,包括虚拟专有网络(VPC)、虚拟的交换机(VSwitch)、虚拟的路由表(RouteTable)以及虚拟的路由器(VRouter)等。通过网络设备虚拟化技术,可以通过软件将一台物理网络设备虚拟化成多台虚拟网络设备(逻辑网络设备)。虚拟化出来的虚拟网络设备可以运行于物理设备之上,通过软、硬件虚拟化的配合,可以具有一定类似物理设备的功能,可以有独立软件环境和数据,如虚拟路由器可以具有物理路由器的路由表存储和路由转发功能。但是受到虚拟路由器自身的限制,目前的这些虚拟设备在虚拟网络实现专线接入以及跨网络互通的过程中难以甚至无法实现的物理网络中的一些功能,如一个虚拟网络不能够与多个其它的虚拟网络同时互通,也不能与多个物理网络同时互通,从而阻碍了虚拟网络与多个网络的互通,使得虚拟网络之间的资源/服务的共享效率极低。并且现有的虚拟路由器通常只是进行路由功能,缺少物理路由器上独立的连接点管理等功能,使得虚拟网络设计、资源服务、跨网互通、节点管理等受到严重制约。In a virtual network, in order to keep the function and deployment of the virtual network consistent with the physical network, many virtual network devices are designed, including virtual private networks (VPCs), virtual switches (VSwitches), and virtual routing tables (RouteTable). ) and virtual routers (VRouters). Through network device virtualization technology, one physical network device can be virtualized into multiple virtual network devices (logical network devices) through software. The virtualized virtual network device can run on the physical device. Through the cooperation of software and hardware virtualization, it can have certain physical device functions. It can have independent software environment and data. For example, the virtual router can have physical router routing. Table storage and routing forwarding. However, due to the limitations of the virtual router itself, some of the functions of the virtual network in the virtual network to achieve private line access and inter-network interworking are difficult or impossible to achieve, such as a virtual network cannot be combined with multiple other Virtual networks can communicate with each other at the same time, and cannot communicate with multiple physical networks at the same time. This hinders the interworking between virtual networks and multiple networks, making the sharing of resources/services between virtual networks extremely inefficient. Moreover, the existing virtual routers usually only perform routing functions, and lack of functions such as independent connection point management on the physical router, which seriously restricts virtual network design, resource service, inter-network communication, and node management.
发明内容Summary of the invention
本申请目的在于提供一种虚拟网络设备、路由设备及虚拟网络的连接方法,可以通过新设计配置的虚拟设备接口来实现虚拟网络与多个虚拟网络/物理网络之间的可独立 管理的连通,实现跨网络、多网络互通和连接点独立管理的功能,提高虚拟网络管理和资源/服务效率。The purpose of the present application is to provide a method for connecting a virtual network device, a routing device, and a virtual network, and the independently configured communication between the virtual network and the plurality of virtual networks/physical networks can be realized through the newly designed virtual device interface. Improve cross-network, multi-network interworking and connection point independent management to improve virtual network management and resource/service efficiency.
本申请提供的一种虚拟网络设备、路由设备及虚拟网络的连接方法是这样实现的:A virtual network device, a routing device, and a virtual network connection method provided by the present application are implemented as follows:
一种虚拟网络设备,接入第一虚拟网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,a virtual network device that accesses a first virtual network and communicates with a second virtual network device in a second network, the virtual network device including at least one virtual device interface, the virtual device interface configured to
向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
一种虚拟网络设备,接入第一物理网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,A virtual network device accessing the first physical network and communicating with a second virtual network device in the second network, the virtual network device including at least one virtual device interface, the virtual device interface configured to
向第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
一种路由设备,包括存储计算机可执行指令的存储器,接入第一虚拟网络的虚拟设备接口,并与第二网络中的第二虚拟网络设备进行通信,所述指令被处理器执行时使所述虚拟设备接口至少实现:A routing device comprising a memory storing computer executable instructions, accessing a virtual device interface of a first virtual network, and communicating with a second virtual network device in a second network, the instructions being executed by the processor The virtual device interface implements at least:
向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
一种虚拟网络的连接方法,包括接入第一网络的第一虚拟网络设备、接入第二网络的第二虚拟网络设备,所述第一虚拟网络设备配置至少一个第一虚拟设备接口,所述第 二虚拟网络设备配置至少一个第二虚拟设备接口,所述第一网络、第二网络中至少一个为虚拟网络,A method for connecting a virtual network, comprising: accessing a first virtual network device of a first network, and a second virtual network device accessing a second network, where the first virtual network device is configured with at least one first virtual device interface, The second virtual network device is configured with at least one second virtual device interface, and at least one of the first network and the second network is a virtual network.
所述第一虚拟设备接口向所述第二虚拟设备接口发送连接请求,所述连接请求根据所述第一虚拟设备接口的配置信息和所述第二虚拟设备接口的验证信息生成;The first virtual device interface sends a connection request to the second virtual device interface, where the connection request is generated according to the configuration information of the first virtual device interface and the verification information of the second virtual device interface;
所述第二虚拟网络设备对所述连接请求进行验证,以及验证成功后基于所述第一虚拟设备接口的配置信息对所述第二虚拟设备接口进行配置,并向第一虚拟网络设备返回验证成功消息;The second virtual network device verifies the connection request, and after the verification succeeds, configures the second virtual device interface according to the configuration information of the first virtual device interface, and returns verification to the first virtual network device. Success message
所述第一虚拟网络设备收到所述验证成功消息后,根据所述第二网络的虚拟设备接口的配置信息对所述第一虚拟设备接口进行配置,建立与所述第二虚拟设备接口的通信连接。After receiving the verification success message, the first virtual network device configures the first virtual device interface according to the configuration information of the virtual device interface of the second network, and establishes an interface with the second virtual device. Communication connection.
一种计算机可读存储介质,其上存储有计算机指令,接入第一虚拟网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述指令被执行时使所述虚拟设备接口至少实现:A computer readable storage medium having stored thereon computer instructions for accessing a first virtual network and communicating with a second virtual network device in a second network, the virtual network device including at least one virtual device interface The virtual device interface is implemented at least when the instructions are executed:
向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
一种虚拟网络设备,包括:处理器,以及存储计算机可执行指令的存储器,所述指令被所述处理器执行时,配置用于第一虚拟网络的虚拟网络设备,并配置所述虚拟网络设备上的虚拟设备接口以至少实现:A virtual network device comprising: a processor, and a memory storing computer executable instructions, the instructions being executed by the processor, configuring a virtual network device for the first virtual network, and configuring the virtual network device The virtual device interface on the at least:
向第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device is established.
一种虚拟网络设备,包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,A virtual network device includes at least one virtual device interface, the virtual device interface configured to
向第二虚拟网络设备发送连接请求;Sending a connection request to the second virtual network device;
基于所述第二虚拟网络设备返回的用于第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to configuration information for the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the virtual device interface is configured, a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
本申请提供的一种虚拟网络设备、路由设备及虚拟网络的连接方法,构建一种新的虚拟网络设备,通过虚拟网络设备上配置的虚拟设备接口实现虚拟网络与一个或多个虚拟网络/物理网络之间的连接。当需要与多个虚拟网络/物理网络连接时,可以创建出多个虚拟设备接口,从而完成与多个虚拟网络/物理网络之间的连接。本申请实施方案增加了如同物理路由器上的路由器接口的概念,并基于虚拟网络和物理网络得特性加以扩充使得本申请中的虚拟网络设备既能连接不同的虚拟网络,也能连接多个虚拟网络/物理网络,并且还可以更好的实现物理网络中专线接入,满足跨网络互通的功能和场景需求。利用本申请实施方案,实现扩展虚拟网络与多个不同的虚拟网络/物理网络的互通实施方案,并具有独立的连接点管理功能,使得虚拟网络设计、资源服务/共享、跨网互通、节点管理等更加灵活、便利,有利于提高虚拟网络的产品服务体验。The present invention provides a virtual network device, a routing device, and a virtual network connection method, and constructs a new virtual network device, and implements a virtual network and one or more virtual networks/physical through a virtual device interface configured on the virtual network device. The connection between the networks. When multiple virtual/physical networks need to be connected, multiple virtual device interfaces can be created to complete the connection with multiple virtual/physical networks. The embodiment of the present application adds the concept of a router interface like a physical router, and is expanded based on the characteristics of the virtual network and the physical network. The virtual network device in the present application can connect to different virtual networks and connect multiple virtual networks. / Physical network, and can also better realize private line access in the physical network to meet the functions and scenarios of inter-network interworking. With the implementation of the present application, an implementation scheme of an extended virtual network and a plurality of different virtual network/physical networks is realized, and an independent connection point management function is provided, so that virtual network design, resource service/sharing, inter-network interworking, and node management are implemented. More flexible and convenient, it is conducive to improving the product service experience of virtual networks.
附图说明DRAWINGS
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请中记载的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings to be used in the embodiments or the prior art description will be briefly described below. Obviously, the drawings in the following description are only It is a few embodiments described in the present application, and other drawings can be obtained from those skilled in the art without any inventive labor.
图1是本申请提供的一种虚拟网络设备所处网络环境的网络拓扑结构示意图;1 is a schematic diagram of a network topology structure of a network environment in which a virtual network device is provided according to the present application;
图2是本申请提供的处于虚拟网络中的一个虚拟网络设备的实施场景示意图;2 is a schematic diagram of an implementation scenario of a virtual network device in a virtual network provided by the present application;
图3是本申请一个实施例中路由表在DB上持久化后被配置的虚拟网络设备上的示意图;3 is a schematic diagram of a virtual network device configured after a routing table is persistent on a DB in an embodiment of the present application;
图4是本申请所述虚拟网络设备配置的虚拟设备接口配置信息的一个示意图;4 is a schematic diagram of virtual device interface configuration information of a virtual network device configuration according to the present application;
图5是本申请提供的一种虚拟设备接口的状态机的处理示意图;5 is a schematic diagram of processing of a state machine of a virtual device interface provided by the present application;
图6是申请一种实施例中的边界虚拟网络设备的数据配置示意图;6 is a schematic diagram of data configuration of a border virtual network device in an embodiment;
图7是本申请一种实施例中配置到边界虚拟网络设备上的路由表信息的配置示意图;7 is a schematic diagram of configuration of routing table information configured on a border virtual network device in an embodiment of the present application;
图8是本申请所述一种虚拟网络的连接方法一种实施例场景的处理流程示意图。FIG. 8 is a schematic diagram of a process flow of a scenario of a method for connecting a virtual network according to the present application.
具体实施方式Detailed ways
为了使本技术领域的人员更好地理解本申请中的技术方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。The technical solutions in the embodiments of the present application are clearly and completely described in the following, in which the technical solutions in the embodiments of the present application are clearly and completely described. The embodiments are only a part of the embodiments of the present application, and not all of them. All other embodiments obtained by a person of ordinary skill in the art based on the embodiments of the present application without departing from the inventive scope shall fall within the scope of the application.
本申请中所述的虚拟网络通常是指一种包含至少部分是虚拟网络链接的计算机网络,这里的虚拟网络链接可以是指在两个计算设备间不包含物理连接,而是通过网络虚拟化来实现。例如一种场景的虚拟网络通常是在交换技术的基础上,将网络结点按工作性质与需要划分成若干个“逻辑工作组”,一个“逻辑工作组”可以为划分出的一个虚拟局域网(VLAN,Virtual Local Area Network,虚拟局域网,一种基于协议的虚拟网络)。通过划分虚拟网络,可以把广播限制在各个虚拟网的范围内,从而减少整个网络范围内广播包的传输,提高了网络的传输效率。各虚拟网络之间不能直接进行通讯,通常是通过路由器进行数据转发。一般的,物理位置不同的多个主机如果划分属于同一个虚拟局域网,则这些主机之间可以相互通信;物理位置相同的多个主机如果属于不同的虚拟局域网,则这些主机之间不能直接通信。虚拟网络之间的通信通常可以在交换机或路由器上实现,例如在以太网帧中增加VLAN标签来大于以太网帧进行分类,具有相同VLAN标签的以太网帧在同一个广播域中传送。The virtual network described in the present application generally refers to a computer network including at least a part of a virtual network link, where the virtual network link may refer to not including a physical connection between two computing devices, but through network virtualization. achieve. For example, a virtual network of a scenario is usually based on the exchange technology, and the network node is divided into several "logical work groups" according to the nature of work and needs, and a "logical work group" can be a virtual local area network ( VLAN, Virtual Local Area Network, virtual local area network, a protocol-based virtual network). By dividing the virtual network, the broadcast can be restricted to the range of each virtual network, thereby reducing the transmission of broadcast packets throughout the network and improving the transmission efficiency of the network. There is no direct communication between virtual networks, usually through routers for data forwarding. Generally, if multiple hosts with different physical locations belong to the same virtual local area network, the hosts can communicate with each other; if multiple hosts with the same physical location belong to different virtual local area networks, the hosts cannot directly communicate with each other. Communication between virtual networks can usually be implemented on a switch or router. For example, adding VLAN tags to Ethernet frames to classify them over Ethernet frames, Ethernet frames with the same VLAN tag are transmitted in the same broadcast domain.
本申请提供一种新型的虚拟网络设备,不仅可以具有现有虚拟路由器的功能和特性,并且增加了如同物理路由器上的路由器接口的概念,还可以基于虚拟网络和物理网络得特性加以扩充(比如增加用户信息、虚拟网络的隧道/封装信息、物理网络VLAN、物理端口信息、电路编码等),使得该新型虚拟网络设备既能连接不同的虚拟网络,也能连接虚拟网络和物理网络。本申请所述的虚拟网络设备可以包括在hypervisor(一种运行在物理服务器和操作系统之间的中间软件层)内部的网络连接虚拟机、虚拟交换机、虚拟路由器等。The present application provides a novel virtual network device, which not only has the functions and features of the existing virtual router, but also adds the concept of a router interface like a physical router, and can also be extended based on the characteristics of the virtual network and the physical network (for example) Adding user information, tunnel/encapsulation information of the virtual network, physical network VLAN, physical port information, circuit coding, etc., enables the new virtual network device to connect to different virtual networks as well as virtual and physical networks. The virtual network device described in the present application may include a network connection virtual machine, a virtual switch, a virtual router, and the like inside a hypervisor (an intermediate software layer running between a physical server and an operating system).
本申请中所述的虚拟网络设备,具体的可以包括通过网络设备虚拟化技术,将一台物理网络设备虚拟化成多台虚拟网络设备。本申请实施例的虚拟网络设备可以运行于物理设备之上,通过软、硬件虚拟化的配合,可以具有一定的物理设备的功能,可以有独 立软件环境和数据。如本申请一个实施例的虚拟网络设备可以配置在运行在具有路由表存储和路由转发功能物理路由器上,通过虚拟网络设备上配置的虚拟设备接口来实现虚拟网络与多个虚拟网络/物理网络之间的可独立管理的连通。The virtual network device described in this application may specifically include virtualizing one physical network device into multiple virtual network devices by using network device virtualization technology. The virtual network device in the embodiment of the present application can be run on a physical device, and can have a certain physical device function through the cooperation of software and hardware virtualization, and can have a separate software environment and data. A virtual network device, such as an embodiment of the present application, may be configured to run on a physical router having a routing table storage and routing forwarding function, and implement a virtual network and multiple virtual networks/physical networks through a virtual device interface configured on the virtual network device. Independently manageable connectivity.
图1是本申请提供的一种虚拟网络设备所处网络环境的网络拓扑结构示意图。如图1所示,虚拟网络设备可以处于虚拟网络内(如虚拟网络设备处于第一虚拟网络VNetDev-1中),具有路由功能,并且在该设备上有虚拟设备接口(interface),基于该接口可以更好的实现以上物理网络的功能,提供本端接入的虚拟网络的路由功能以及该虚拟网络与其他网络VNetDev-2(虚拟网络)的连通,也可以处于虚拟网络与物理网络之间的边界设备上,实现虚拟网络与物理网络(VNetDev-3)的连通。本申请提供的每个虚拟网络设备可以同时连接多个虚拟网络/物理网络(可以通过在虚拟网络设备上建立多个虚拟设备接口来完成)。并且,每个虚拟网络设备可以独立管理与其他虚拟网络/物理网络之间的连接情况(可以通过激活/反激活该设备上虚拟设备接口来完成)。另外,所述虚拟网络设备还可以基于虚拟设备接口来完成防火墙以及安全域的配置。FIG. 1 is a schematic diagram of a network topology structure of a network environment in which a virtual network device is provided according to the present application. As shown in FIG. 1, the virtual network device may be in a virtual network (eg, the virtual network device is in the first virtual network VNetDev-1), has a routing function, and has a virtual device interface on the device, based on the interface. The function of the above physical network can be better realized, the routing function of the virtual network accessed by the local end, and the connection between the virtual network and other network VNetDev-2 (virtual network), or between the virtual network and the physical network. On the border device, the virtual network is connected to the physical network (VNetDev-3). Each virtual network device provided by the present application can simultaneously connect multiple virtual network/physical networks (which can be done by establishing multiple virtual device interfaces on the virtual network device). Moreover, each virtual network device can independently manage the connection with other virtual network/physical networks (which can be done by activating/deactivating the virtual device interface on the device). In addition, the virtual network device may also complete the configuration of the firewall and the security domain based on the virtual device interface.
以下结合附图描述对本申请的虚拟网络设备进行描述。在本申请中,根据虚拟网络设备所在网络环境(虚拟网络中/边界设备上等),虚拟网络设备可以被分为多个实施类型。图2是本申请提供的处于虚拟网络中的一个虚拟网络设备的实施场景示意图,可以提供该虚拟网络内的路由功能以及该虚拟网络与其他网络(虚拟网络或者物理网络)连通。具体的,如图2所示,虚拟网络设备处于虚拟网络内(如虚拟网络设备处于第一虚拟网络VNetDev-1中),具有路由功能,并且在该设备上有虚拟设备接口(interface),基于该接口可以更好的实现以上物理网络的功能,提供本端接入的虚拟网络的路由功能以及该虚拟网络与其他网络VNetDev-2(虚拟网络或物理网络)的连通。本申请提供的一种虚拟网络设备的一个实施例中,所述虚拟网络设备接入第一虚拟网络,并可以与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备可以包括至少一个虚拟设备接口,所述虚拟设备接口可以被配置成,The description of the virtual network device of the present application will be described below with reference to the accompanying drawings. In the present application, the virtual network device may be classified into multiple implementation types according to the network environment in which the virtual network device is located (in the virtual network/on the border device, etc.). 2 is a schematic diagram of an implementation scenario of a virtual network device in a virtual network provided by the present application, which may provide a routing function in the virtual network and communicate with the other network (virtual network or physical network). Specifically, as shown in FIG. 2, the virtual network device is in the virtual network (for example, the virtual network device is in the first virtual network VNetDev-1), has a routing function, and has a virtual device interface on the device, based on The interface can better implement the functions of the above physical network, provide the routing function of the virtual network accessed by the local end, and connect the virtual network with other networks VNetDev-2 (virtual network or physical network). In an embodiment of the virtual network device provided by the present application, the virtual network device accesses the first virtual network, and may communicate with a second virtual network device in the second network, where the virtual network device may include At least one virtual device interface, the virtual device interface can be configured to
向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
如图2所示的实施场景中,虚拟网络设备所处的虚拟网络(在本实施例中可以称为第一虚拟网络)和所连接的对端的虚拟网络均可以配置有虚拟网络设备(在此将相对于本端一侧而言另一侧的虚拟网络设备称为第二虚拟网络设备),可以在两个虚拟网络上的虚拟网络设备(VNetDevice)上分别创建虚拟设备接口(Inf)。创建的Inf中可以配置第二网络虚拟设备、第二虚拟网络设备的第二虚拟设备接口、第二虚拟网络设备所有者等的信息,用于通信双方握手。通信的双方至少一侧为虚拟网络,因此,一些实施例中,所述第二网络可以为虚拟网络,也可以为物理网络。In the implementation scenario shown in FIG. 2, the virtual network in which the virtual network device is located (which may be referred to as the first virtual network in this embodiment) and the virtual network connected to the peer end may be configured with virtual network devices (here A virtual network device on the other side with respect to the side of the local end is referred to as a second virtual network device, and a virtual device interface (Inf) may be separately created on a virtual network device (VNetDevice) on the two virtual networks. The information of the second network virtual device, the second virtual device interface of the second virtual network device, the second virtual network device owner, and the like may be configured in the created Inf for the handshake of the communication parties. At least one side of the communication is a virtual network. Therefore, in some embodiments, the second network may be a virtual network or a physical network.
任何一端发起连接后可以将第二网络虚拟设备、第二虚拟网络设备的第二虚拟设备接口、第二虚拟网络设备所有者等的验证信息以及第一虚拟网络信息的配置信息放到请求内发给第二网络。连接请求到达第二网络的第二虚拟网络设备后,可以核对连接对请求里的设备、接口,所有者等验证信息,如果信息正确,则回复连接请求并附带自己的虚拟网络的配置信息。此时第一网络和第二网络的虚拟设备接口可以进入连接中(Connecting)的状态,并把对方的虚拟网络的配置信息配置到虚拟设备接口的Encap/Decap配置中,配置完成后进入Active状态。如果连接请求信息有误,则可以拒绝连接请求。因此,一个实施例中,所述基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置,可以包括:After the connection is initiated by any one end, the verification information of the second network virtual device, the second virtual device interface of the second virtual network device, the second virtual network device owner, and the like, and the configuration information of the first virtual network information may be placed in the request. Give the second network. After the connection request reaches the second virtual network device of the second network, the connection information of the device, the interface, the owner, and the like in the request may be checked. If the information is correct, the connection request is returned and the configuration information of the virtual network is attached. At this time, the virtual device interface of the first network and the second network can enter the state of connection, and configure the configuration information of the virtual network of the other party to the Encap/Decap configuration of the virtual device interface, and enter the Active state after the configuration is completed. . If the connection request information is incorrect, the connection request can be rejected. Therefore, in one embodiment, the configuring the virtual device interface based on the configuration information of the second network returned by the second virtual network device may include:
接收所述第二虚拟网络设备发送的验证成功消息,所述验证成功消息包括所述第二虚拟网络设备对所述连接请求中的第一虚拟网络的配置信息验证成功时返回给所述虚拟网络设备的消息;Receiving the verification success message sent by the second virtual network device, where the verification success message includes the second virtual network device returning to the virtual network when the configuration information of the first virtual network in the connection request is successfully verified. Device message
基于所述验证成功消息将所述虚拟设备接口设置为激活状态。The virtual device interface is set to an active state based on the verification success message.
具体的一个示例中,所述虚拟网络设备处于虚拟网络内,该虚拟网络设备可以配置有包含以下的特性信息:In a specific example, the virtual network device is in a virtual network, and the virtual network device may be configured with the following characteristic information:
ID(identification,身份标识):表示该虚拟网络设备的内部ID,用于持久化存储时的内部ID,比如用户DB(Database,数据库)上的primarykey(初始密钥);ID (identification): indicates the internal ID of the virtual network device, used to persist the internal ID of the storage, such as the primary key (initial key) on the user DB (Database);
Description:用于该虚拟网络设备的描述;Description: A description for the virtual network device;
Name:该虚拟网络设备的名字;Name: the name of the virtual network device;
VirtualNetworkID:该虚拟设备所在的虚拟网络的ID;VirtualNetworkID: ID of the virtual network where the virtual device is located;
OwnerID:该虚拟网络设备的所有者ID。OwnerID: The owner ID of this virtual network device.
当然,根据网络环境或路由处理需求等还可以包括虚拟网络设备的其他特性信息。这些虚拟网络设备的特征信息可以持久化在存储设备上,如虚拟网络设备所在的物理路 由器。虚拟网络中的资源/服务(比如虚拟机等)当被设置为连接到该虚拟网络设备上时,这些虚拟网络中的资源/服务的数据包可以在该虚拟网络设备被路由到该虚拟网络内或者虚拟网络外的其他地方,这样,虚拟网络内的虚拟机或者其他虚拟网络可以获取该虚拟网络的配置信息,包括虚拟网络设备的配置信息。具体的路由逻辑可以基于预先设置在该虚拟网络设备上的路由表进行配置。路由表可以先在DB上持久化,然后被配置到虚拟网络设备上。如图3所示,图3是本申请一个实施例中路由表在DB上持久化后被配置的虚拟网络设备上的一个示意图。Of course, other characteristic information of the virtual network device may also be included according to the network environment or routing processing requirements and the like. The feature information of these virtual network devices can be persisted on the storage device, such as the physical router where the virtual network device is located. When resources/services (such as virtual machines, etc.) in the virtual network are set to connect to the virtual network device, data packets of resources/services in the virtual networks can be routed to the virtual network device within the virtual network device. Or other places outside the virtual network, such that the virtual machine or other virtual network in the virtual network can obtain configuration information of the virtual network, including configuration information of the virtual network device. The specific routing logic can be configured based on a routing table preset on the virtual network device. The routing table can be persisted on the DB and then configured on the virtual network device. As shown in FIG. 3, FIG. 3 is a schematic diagram of a virtual network device configured after the routing table is persistent on the DB in an embodiment of the present application.
在第一虚拟网络的虚拟网络设备上,创建的虚拟设备接口可以配置有包含以下的特性信息:On the virtual network device of the first virtual network, the created virtual device interface can be configured with the following feature information:
ID:该虚拟设备接口的内部ID,用于持久化存储时的内部ID,比如用户DB上的primarykey;ID: The internal ID of the virtual device interface, used to persist the internal ID of the storage, such as the primarykey on the user DB;
Description:该虚拟设备接口的描述;Description: Description of the virtual device interface;
Name:该虚拟设备接口的名字;Name: the name of the virtual device interface;
VirtualNetworkDeviceID:该虚拟设备接口所在虚拟网络设备的ID;VirtualNetworkDeviceID: ID of the virtual network device where the virtual device interface is located.
OppositeVirtualNetworkDeviceID:该虚拟设备接口所连接的第二网络的虚拟网络设备的ID;OppositeVirtualNetworkDeviceID: the ID of the virtual network device of the second network to which the virtual device interface is connected;
OppositeVirtualDeviceInterfaceID:该虚拟设备接口所连接的第二网络的虚拟设备接口的路由器接口的ID;OppositeVirtualDeviceInterfaceID: ID of the router interface of the virtual device interface of the second network to which the virtual device interface is connected;
OppositeVirtualNetworkDeviceOwnerID:该虚拟设备接口所连接的第二网络的虚拟网络设备的所有者ID,用于连接双方虚拟设备接口建立连接时握手和鉴定身份。OppositeVirtualNetworkDeviceOwnerID: The owner ID of the virtual network device of the second network to which the virtual device interface is connected. It is used to handshake and authenticate the identity when the two virtual device interfaces are connected.
当然,这些虚拟设备接口的特性信息可以在DB上持久化,然后可以根据连接请求和/或连确认消息中的配置信息配置到虚拟网络设备上,如图4所示,图4是本申请所述虚拟网络设备配置的虚拟设备接口配置信息的一个示意图,其中,Encap/Decap中可以保存接口虚拟网络之间的数据包的解包封包逻辑(不同虚拟网路的数据包需要转换)或者虚拟网络与物理网络之间的数据包的解包封包逻辑(虚拟网络与物理网络之间的数据包需要转换)。该Encap/Decap配置在虚拟设备接口发起连接请求后根据从第二虚拟网络设备获取配置信息并配置到自己的虚拟网络设备上。具体的一种实现方式中,虚拟网络设备的虚拟设备接口发送连接请求后,还可以:Certainly, the characteristic information of the virtual device interfaces can be persistent on the DB, and then can be configured on the virtual network device according to the connection request and/or the configuration information in the confirmation message, as shown in FIG. 4, FIG. 4 is the present application. A schematic diagram of virtual device interface configuration information of a virtual network device configuration, wherein Encap/Decap can save the unpacking logic of the data packets between the interface virtual networks (data packets of different virtual networks need to be converted) or virtual network The unpacking logic of the packet with the physical network (the packet between the virtual network and the physical network needs to be translated). The Encap/Decap configuration acquires configuration information from the second virtual network device and configures it on its own virtual network device after the virtual device interface initiates the connection request. In a specific implementation manner, after the virtual device interface of the virtual network device sends the connection request, the device may also:
从所述第二虚拟网络设备获取所述第二网络使用的数据包的解封包逻辑信息,并根据所述第一虚拟网络使用的数据包的解封包逻辑信息,生成所述第一虚拟网络与第二网 络之间的数据包的解封包处理逻辑;将所述解封包处理逻辑配置在与所述第二网络对应的虚拟设备接口的配置信息中。Obtaining, according to the second virtual network device, the decapsulation logic information of the data packet used by the second network, and generating the first virtual network according to the decapsulation logic information of the data packet used by the first virtual network. Decapsulation processing logic of a data packet between the second networks; configuring the decapsulation processing logic in configuration information of a virtual device interface corresponding to the second network.
进一步的,其他的实施场景中,每个虚拟网络设备还可以基于虚拟设备接口来完成防火墙以及安全域的配置等,可以实现接口级的安全防护设置。并且基于本申请实施例所述的可以灵活管理和配置的接口,可以十分便捷、灵活的实现物理路由器的安全防护功能应用,提高虚拟网络安全性和配置的灵活性、可扩展性。Further, in other implementation scenarios, each virtual network device may also complete a firewall and a security domain configuration based on the virtual device interface, and implement interface-level security protection settings. And the interface that can be flexibly managed and configured according to the embodiment of the present application can implement the security protection function application of the physical router conveniently and flexibly, and improve the flexibility and scalability of the virtual network security and configuration.
本申请提供的一种虚拟网络设备的一种实施例中,若确认所述第一网络与所述第二网络使用的数据包格式不相同,则可以发起连接请求后,从所述第二虚拟网络设备获取所述第二网络使用的数据包的解封包逻辑信息,并根据所述第一虚拟网络使用的数据包的解封包逻辑信息,生成所述第一虚拟网络与第二网络之间的数据包的解封包处理逻辑;In an embodiment of the virtual network device provided by the present application, if it is confirmed that the data format used by the first network and the second network is different, the connection may be initiated from the second virtual Obtaining, by the network device, the decapsulation logic information of the data packet used by the second network, and generating, according to the decapsulation logic information of the data packet used by the first virtual network, between the first virtual network and the second network. Decapsulation processing logic of the data packet;
然后,将所述解封包处理逻辑配置在与所述第二网络对应的虚拟设备接口的配置信息中。Then, the decapsulation processing logic is configured in configuration information of a virtual device interface corresponding to the second network.
在本实施例应用场景中,可以将所连接的第二网络的验证信息以及第一虚拟网络的配置信息发送给第二网络,所述第二网络为虚拟网络或物理网络,所述第一虚拟网络的配置信息用于所述第二网络中虚拟网络设备的第二虚拟设备接口的配置,以使所述第二虚拟网络设备对所述连接请求进行验证。具体的例如可以验证连接请求中包含的第二虚拟网络设备的配置信息是否正确/合法,如具体的可以核对连接请求里的虚拟网设备名称是否正确、所连接的虚拟设备接口是否存储、第二虚拟网络设备的所有者信息是否与自身的网络信息一致等。如果验证通过,则可以返回验证成功的消息。In the application scenario of the embodiment, the verification information of the connected second network and the configuration information of the first virtual network may be sent to the second network, where the second network is a virtual network or a physical network, and the first virtual The configuration information of the network is used for configuration of the second virtual device interface of the virtual network device in the second network, so that the second virtual network device verifies the connection request. Specifically, for example, it can be verified whether the configuration information of the second virtual network device included in the connection request is correct/legal, such as whether the virtual network device name in the connection request is correct, whether the connected virtual device interface is stored, and second. Whether the owner information of the virtual network device is consistent with its own network information. If the verification passes, you can return a message that the verification was successful.
在接收到所述第二虚拟网络设备发送的验证成功消息后(也可以称为连接确认消息),将连接请求中设置的虚拟设备接口设置为激活状态,并根据所述第二网络的配置信息对第一虚拟网络的虚拟设备接口进行配置。配置完成后即可建立与所述第二网络的第二虚拟设备接口的通信连接。After receiving the verification success message sent by the second virtual network device (also referred to as a connection confirmation message), setting the virtual device interface set in the connection request to an active state, and according to the configuration information of the second network Configure the virtual device interface of the first virtual network. After the configuration is completed, a communication connection with the second virtual device interface of the second network can be established.
在本实施例应用场景中,所述本地网络、第二网络中至少一个为虚拟网络,如本地网络为虚拟网络,第二网络为物理网络。为了区分第一虚拟网络设备和第二虚拟网络设备所在的虚拟网络环境,在描述中,可以将确定的虚拟网络设备所处的虚拟网络称为第一虚拟网络,另一方网络称为第二网络,第二网络可以是虚拟网络,也可以是物理网。需要说明的是,包括本申请下述所述的第一网络、第二网络是指在一次虚拟网络连接的两个网络,是区别发起连接的本地网络和需要连接的第二网络的识别名称。所述的第一网络也可以连接除所述第二网络的其他虚拟网络,根据上述,所连接的另一个网络相对 于第二网络而言可以被称为第三网络。但在具体与第一网络实施连接的交互过程中,相对于第一网络而言,所述的第三网络可以相对的被描述为第二网络。In the application scenario of the embodiment, at least one of the local network and the second network is a virtual network, for example, the local network is a virtual network, and the second network is a physical network. In order to distinguish the virtual network environment where the first virtual network device and the second virtual network device are located, in the description, the virtual network in which the determined virtual network device is located may be referred to as a first virtual network, and the other network is referred to as a second network. The second network may be a virtual network or a physical network. It should be noted that the first network and the second network, which are described below in the present application, refer to two networks connected in one virtual network, which are distinguished names of the local network that initiates the connection and the second network that needs to be connected. The first network may also be connected to other virtual networks other than the second network. According to the above, another network connected may be referred to as a third network with respect to the second network. However, in the interaction process specifically implementing the connection with the first network, the third network may be relatively described as the second network with respect to the first network.
在本申请实施例中,第一虚拟网络可以借助虚拟网络设备上虚拟设备接口的通信建立实现与第二网络的通信连接。在发送连接过程中,发送给第二网络虚拟设备的连接请求还可以包括下述验证信息:In the embodiment of the present application, the first virtual network may establish a communication connection with the second network by means of communication establishment of the virtual device interface on the virtual network device. In the process of sending a connection, the connection request sent to the second network virtual device may further include the following verification information:
所述第二虚拟网络设备的识别标识、所述第二虚拟网络设备中第二虚拟设备接口的识别标识、所述第二虚拟网络设备的所有者的识别标识。The identification identifier of the second virtual network device, the identification identifier of the second virtual device interface in the second virtual network device, and the identification identifier of the owner of the second virtual network device.
例如所述验证信息可以包括所述第一虚拟网络的虚拟设备接口所连接的第二虚拟网络设备的识别标识、第一虚拟网络的虚拟设备接口所连接的第二虚拟设备接口的识别标识、第二虚拟网络设备的所有者的识别标识等。进一步的,所述本地网络的配置信息相应的可以包括例如第一虚拟网络中虚拟网络设备的识别标识、第一虚拟网络的识别标识、与第二网络建立连接所使用的虚拟设备接口的识别标识等。For example, the verification information may include an identification identifier of the second virtual network device to which the virtual device interface of the first virtual network is connected, an identification identifier of the second virtual device interface to which the virtual device interface of the first virtual network is connected, and The identification of the owner of the second virtual network device, and the like. Further, the configuration information of the local network may include, for example, an identification identifier of the virtual network device in the first virtual network, an identification identifier of the first virtual network, and an identifier of the virtual device interface used to establish a connection with the second network. Wait.
当然,所述的连接请求在实际应用实施过程中还可以包括其他的字段信息,第一虚拟网络的网络类型/模式、时间戳等。具体的可以根据应用场景进行设置。Certainly, the connection request may further include other field information, a network type/mode of the first virtual network, a timestamp, and the like in the actual application implementation process. The specific settings can be made according to the application scenario.
上述所述的方式中,任何一端发起连接后可以将对端的验证信息以及本端的配置信息一并组合成连接请求后发给第二虚拟网络设备,但本申请不排除可以将本端的配置或所述验证信息单独进行方式的实施方式。在本公开内容的具体示例中,第一虚拟网络的虚拟网络设备作为连接请求的发送方,第二网络的虚拟网络设备作为连接请求的接收方。可以理解的是,在本公开内容的其它示例中,也可以将第二网络的虚拟网络设备作为连接请求的发送方,第一虚拟网络的虚拟网络设备作为连接请求的接收方。In the foregoing manner, after the connection is initiated, the authentication information of the peer end and the configuration information of the local end are combined into a connection request and sent to the second virtual network device. However, the present application does not exclude the configuration or location of the local end. The implementation manner in which the verification information is performed separately. In a specific example of the present disclosure, the virtual network device of the first virtual network acts as the sender of the connection request, and the virtual network device of the second network acts as the recipient of the connection request. It can be understood that in other examples of the present disclosure, the virtual network device of the second network may also be used as the sender of the connection request, and the virtual network device of the first virtual network is the receiver of the connection request.
本申请提供的一种虚拟网络设备的另一种实施例中,进入Active的虚拟设备接口可以通过反激活操作让连接从第一虚拟网络中断掉(虚拟设备接口进入Inactive状态)。第一虚拟网络的数据流量无法通过Inactive的虚拟设备接口流出,第二网络的数据流量也无法通过Inactive的虚拟设备接口流入。因此,所述方法的另一种实施例中,所述虚拟设备接口还被配置成,In another embodiment of the virtual network device provided by the present application, the virtual device interface entering the Active may interrupt the connection from the first virtual network by the anti-activation operation (the virtual device interface enters the Inactive state). The data traffic of the first virtual network cannot flow through the Inactive virtual device interface, and the data traffic of the second network cannot flow through the Inactive virtual device interface. Therefore, in another embodiment of the method, the virtual device interface is further configured to
基于接收到的反激活指令设置为非激活状态,以禁止所述虚拟设备接口进行数据收发。The inactive state is set to be inactive based on the received anti-activation command to prohibit the virtual device interface from transmitting and receiving data.
如图1所示,例如当第一虚拟设备接口被激活后,可以根据反激活指令反激活第一虚拟设备接口,以禁止第一虚拟设备接口进行数据收发。当然,在第二网络的第二虚拟 网络设备中,当第二虚拟设备接口被激活后同样可以根据反激活指令反激活第二虚拟设备接口,以禁止第二虚拟设备接口进行数据收发。本申请实施例提供的实施方案,进入激活状态的虚拟设备接口可以通过反激活操作让连接从第一虚拟网络中断掉(例如,使虚拟设备接口进入反激活状态),第一虚拟网络的流量便无法通过反激活的虚拟设备接口流出,第二网络的流量也无法通过反激活的虚拟设备接口流入,从而使每个虚拟网络设备可以独立管理与其他虚拟网络或物理网络之间的连接,使得虚拟网络连接管理等更加灵活,还可以提升网络的安全性。As shown in FIG. 1 , for example, after the first virtual device interface is activated, the first virtual device interface may be deactivated according to the anti-activation command to prohibit the first virtual device interface from performing data transmission and reception. Of course, in the second virtual network device of the second network, when the second virtual device interface is activated, the second virtual device interface may also be deactivated according to the anti-activation command to prohibit the second virtual device interface from performing data transmission and reception. In the embodiment provided by the embodiment of the present application, the virtual device interface entering the active state may interrupt the connection from the first virtual network by using a reverse activation operation (for example, bringing the virtual device interface into an anti-active state), and the traffic of the first virtual network is Unable to flow out through the deactivated virtual device interface, traffic of the second network cannot flow through the deactivated virtual device interface, so that each virtual network device can independently manage the connection with other virtual network or physical network, making virtual Network connection management and more are more flexible, and can also improve the security of the network.
进一步的,本申请所述虚拟网络的另一种实施例中,处于激活状态的虚拟设备接口可以通过删除操作从虚拟网络设备上删除,释放虚拟网络设备的接口占用,从而降低虚拟网络设备对资源的消耗。因此,另一种实施例中,所述虚拟网络设备还基于接收到的接口删除指令删除所述虚拟网络设备中指定的非激活状态的虚拟设备接口。Further, in another embodiment of the virtual network of the present application, the virtual device interface in the activated state may be deleted from the virtual network device by the deletion operation, and the interface occupation of the virtual network device is released, thereby reducing the virtual network device to the resource. Consumption. Therefore, in another embodiment, the virtual network device further deletes the virtual device interface in the inactive state specified in the virtual network device based on the received interface deletion instruction.
如图1所示,当第一虚拟设备接口被反激活后,可以根据删除指令删除第一虚拟设备接口。同样的,第二网络的第二虚拟设备中状态为非激活状态的第二虚拟设备接口也可以根据删除指令进行删除。因此,本实施例方案,当虚拟设备接口被反激活,从虚拟网络设备中删除后,不仅可以降低虚拟网络设备对资源的消耗,还可以使网络接口节点具体灵活的独立管理能力,并可以因此提供网络安全性。图5是本申请提供的一种虚拟设备接口的状态机的处理示意图。As shown in FIG. 1, after the first virtual device interface is deactivated, the first virtual device interface may be deleted according to the deletion instruction. Similarly, the second virtual device interface whose state is inactive in the second virtual device of the second network may also be deleted according to the deletion instruction. Therefore, in the solution of the embodiment, when the virtual device interface is deactivated and deleted from the virtual network device, the virtual network device can not only reduce the consumption of resources, but also enable the network interface node to have flexible and independent management capabilities, and thus Provide network security. FIG. 5 is a schematic diagram of processing of a state machine of a virtual device interface provided by the present application.
通过上述与第二网络建立连接实施描述方式,以此类推,所述第一网络可以与第三网络、第四网络等多个虚拟网络或者物理网络建立连接。或者进一步的,第三网络又可以通过网络虚拟设备与同样设置有网络虚拟设备的第五网络、第六网络建立连接,实现多个虚拟网络之间、虚拟网络与物理网络之间的通信连接。因此,在本申请所述的虚拟网络设备的一个实施例中,所述第一虚拟网络可以通过所述虚拟网络设备的K个激活状态的虚拟设备接口分别与K个第二网络建立通信连接,K≥2。The foregoing description is implemented by establishing a connection with the second network, and so on, the first network may establish a connection with multiple virtual networks or physical networks such as the third network and the fourth network. Alternatively, the third network may establish a connection between the virtual network and the virtual network and the physical network by establishing a connection between the network virtual device and the fifth network and the sixth network, which are also provided with the network virtual device. Therefore, in an embodiment of the virtual network device of the present application, the first virtual network may establish a communication connection with the K second networks through the virtual device interfaces of the K active states of the virtual network device, respectively. K ≥ 2.
如图1所示,在第一虚拟网络VNet-1中的第一虚拟网络设备VNetDev-1上配置第一虚拟设备接口inf-1,在第二虚拟网络VNet-2中的第二虚拟网络设备VNetDev-2上配置第二虚拟设备接口inf-2。然后第一虚拟网络VNet-1和第二虚拟网络VNet-2便可以通过第一虚拟设备接口inf-1和第二虚拟设备接口inf-2握手和身份验证后建立通信连接,实现互通。第一虚拟网络设备可以设置多个虚拟设备接口,如第一虚拟网络设备还配置有虚拟设备接口inf-10,可以同时连接多个虚拟网络/物理网络,如与第二虚拟网络设备 的inf-20接口相连接,或者同时可以与物理网络VNet-3的边界虚拟设备即可Inf-302相连接,实现扩展虚拟网络与多个不同的虚拟网络/物理网络的互通实施方案可以使得虚拟网络设计、资源服务/共享、跨网互通等更加灵活、便利,有利于提高虚拟网络的产品服务体验。As shown in FIG. 1, the first virtual device interface inf-1 is configured on the first virtual network device VNetDev-1 in the first virtual network VNet-1, and the second virtual network device in the second virtual network VNet-2 is configured. The second virtual device interface inf-2 is configured on VNetDev-2. Then, the first virtual network VNet-1 and the second virtual network VNet-2 can establish a communication connection by handshaking and identity verification through the first virtual device interface inf-1 and the second virtual device interface inf-2 to implement interworking. The first virtual network device may be configured with multiple virtual device interfaces. For example, the first virtual network device is further configured with a virtual device interface inf-10, and multiple virtual network/physical networks may be connected at the same time, such as inf- with the second virtual network device. The 20 interfaces are connected, or at the same time, the virtual device of the physical network VNet-3 can be connected to the Inf-302, and the implementation of the interworking between the extended virtual network and multiple different virtual networks/physical networks can make the virtual network design, Resource service/sharing, inter-network interoperability, etc. are more flexible and convenient, which is conducive to improving the product service experience of virtual networks.
由上述实施例描述的虚拟设备接口激活/反激活、虚拟设备接口的删除等可以看出,本申请提供的实施方案可以将原先只有物理网络接口才能完成的功能完全的虚拟化到虚拟网络接口上,实现对虚拟/物理网络接口级的激活控制,突破了原先虚拟网络设备只有单一控制和连接管理的局限性。It can be seen that the implementation of the virtual device interface activation/deactivation, the deletion of the virtual device interface, and the like, the implementation provided by the present application can completely virtualize the function that can be completed only by the physical network interface to the virtual network interface. To achieve activation control of the virtual/physical network interface level, breaking through the limitations of the original virtual network device with only a single control and connection management.
上述实施例所述的虚拟网络设备可以处理虚拟网络内,提供该虚拟网络内的路由功能以及虚拟网络与虚拟网络/物理网络的互通。另一种实施例应用场景中,所述虚拟网络设备可以处于与物理网络连接的边界设备上。边界设备上的虚拟网络设备可以连接一个或者多个该边界设备上的物理接口。当然,可以在该物理接口上可以配置多个虚拟局域网VLAN。一般的,不同的虚拟网络设备不能在同一个物理接口上共用一个VLAN。该虚拟网络设备的路由表也会先在DB上持久化,然后被配置到虚拟网络设备上在该实施场景中,本申请提供所述虚拟网络设备的另一种实施方式。具体的,所述虚拟网络设备接入第一物理网络,接入第一物理网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,The virtual network device in the foregoing embodiment can process the routing function in the virtual network and the interworking between the virtual network and the virtual network/physical network. In another embodiment application scenario, the virtual network device may be on a border device connected to a physical network. A virtual network device on the border device can connect to one or more physical interfaces on the border device. Of course, multiple virtual LAN VLANs can be configured on the physical interface. In general, different virtual network devices cannot share a single VLAN on the same physical interface. The routing table of the virtual network device is also persistent on the DB and then configured on the virtual network device. In this implementation scenario, the present application provides another implementation manner of the virtual network device. Specifically, the virtual network device accesses the first physical network, accesses the first physical network, and communicates with the second virtual network device in the second network, where the virtual network device includes at least one virtual device interface. The virtual device interface is configured to
向第二虚拟网络设备发送连接请求,所述连接请求包括所述第一物理网络的配置信息,所述第一物理网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first physical network, and configuration information of the first physical network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
一种示例中,所述处于边界设备上的虚拟网络设备可以被配置成包含以下特性信息:In one example, the virtual network device on the border device can be configured to include the following characteristic information:
ID:该虚拟网络设备的内部ID,用于持久化存储时的内部ID,比如用户DB上的primarykey;ID: the internal ID of the virtual network device, used to persist the internal ID of the storage, such as the primarykey on the user DB;
Description:该虚拟网络设备的描述;Description: Description of the virtual network device;
Name:该虚拟网络设备的名字;Name: the name of the virtual network device;
PhysicalDeviceID:该虚拟设备所在的物理设备ID;PhysicalDeviceID: The physical device ID of the virtual device;
PhysicalInterfaceInfo:该虚拟设备所接入的物理设备上的接口信息,可以包含一个或 多个接口;PhysicalInterfaceInfo: Interface information on the physical device accessed by the virtual device, which may include one or more interfaces;
OwnerID:本虚拟网络设备的所有者ID。OwnerID: The owner ID of this virtual network device.
这些特性信息可以在DB上持久化(把数据保存到非易失性的存储设备中),然后可以被配置到虚拟网络设备上,如图6所示,图6是本申请一种实施例中的边界虚拟网络设备的数据配置示意图。The feature information can be persisted on the DB (storing the data to a non-volatile storage device) and then can be configured on the virtual network device, as shown in FIG. 6. FIG. 6 is an embodiment of the present application. Schematic diagram of the data configuration of the boundary virtual network device.
处于虚拟网络与物理网络之间的边界设备上的虚拟网络设备,可以提供虚拟网络与物理网络的连通。具体的实现方式上,可以通过为虚拟网络设备创建边界虚拟设备接口,通过边界虚拟设备接口实现虚拟网络和物理网络之间的通信连接。边界设备上的虚拟网络设备可以连接一个或者多个该边界设备上的物理接口,并在在该物理接口上可以配置多个VLAN。一般的,不同的虚拟网络设备不能在同一个物理接口上共用一个VLAN。具体的一个实施例中,所述的处于边界设备上的虚拟网络设备还可以配置有边界虚拟设备接口,所述边界虚拟设备接口与所述第一物理网络的边界设备上的物理接口相连接,所述物理接口上配置至少一个虚拟局域网,且同一个虚拟网络设备在同一个物理接口上共用相同的虚拟局域网。A virtual network device on a border device between a virtual network and a physical network can provide connectivity between the virtual network and the physical network. In a specific implementation manner, a boundary virtual device interface is created for the virtual network device, and a communication connection between the virtual network and the physical network is implemented through the boundary virtual device interface. The virtual network device on the border device can connect to one or more physical interfaces on the border device, and multiple VLANs can be configured on the physical interface. In general, different virtual network devices cannot share a single VLAN on the same physical interface. In a specific embodiment, the virtual network device on the edge device may also be configured with a border virtual device interface, where the boundary virtual device interface is connected to a physical interface on the border device of the first physical network. At least one virtual local area network is configured on the physical interface, and the same virtual network device shares the same virtual local area network on the same physical interface.
具体的一个示例中,连接物理网络端的边界虚拟设备接口可以被配置成具有以下特性信息:In a specific example, the boundary virtual device interface connected to the physical network end may be configured to have the following characteristic information:
ID:该虚拟设备接口的内部ID,用于持久化存储时的内部ID,比如用户DB上的primarykey;ID: The internal ID of the virtual device interface, used to persist the internal ID of the storage, such as the primarykey on the user DB;
Descriptio:该边界虚拟设备接口的描述;Descriptio: a description of the boundary virtual device interface;
Name:该虚拟设备接口的名字;Name: the name of the virtual device interface;
VirtualNetworkDeviceID:该边界虚拟设备接口所在虚拟网络设备的ID;VirtualNetworkDeviceID: ID of the virtual network device where the border virtual device interface is located.
PhysicalInterfaceID:该边界虚拟设备接口所在物理接口的ID;PhysicalInterfaceID: ID of the physical interface where the virtual device interface is located.
VLAN:该边界虚拟设备接口所用的VLAN。VLAN: The VLAN used by this border virtual device interface.
该边界虚拟设备接口对应了每一个配置在虚拟设备上的<物理接口:VLAN>的配置。上述的这些接口特性信息可以在DB上持久化,然后可以被配置到虚拟网络设备上,如图7所示,图7是本申请一种实施例中配置到边界虚拟网络设备上的路由表信息的配置示意图。The border virtual device interface corresponds to the configuration of each <physical interface: VLAN> configured on the virtual device. The above-mentioned interface characteristic information can be persistent on the DB, and then can be configured on the virtual network device, as shown in FIG. 7. FIG. 7 is the routing table information configured on the border virtual network device in an embodiment of the present application. Schematic diagram of the configuration.
虚拟网络设备可以连接一个或者多个边界设备(如路由器)上的物理接口,物理网络也可以通过配置的虚拟局域网VLAN同时与多个虚拟网络进行互通。所述的物理接口上也可以配置多个VLAN,一般的,不同的虚拟网络设备不能在同一个物理接口上共用 一个VLAN。这样,利用本实施例的实施方案,可以实现虚拟网络与多个物理网络的互通,物理网络也可以通过配置的虚拟局域网VLAN同时与多个虚拟网络进行互通,并且边界设备上虚拟网络设备具有更好独立的连接点管理功能,使得虚拟网络设计、资源服务/共享、跨网互通、节点管理等更加灵活、便利,可以提高虚拟网络的产品服务体验。A virtual network device can be connected to a physical interface on one or more border devices (such as a router). The physical network can also communicate with multiple virtual networks through a configured virtual local area network VLAN. Multiple VLANs can also be configured on the physical interface. Generally, different virtual network devices cannot share one VLAN on the same physical interface. In this way, with the implementation of the embodiment, the virtual network can communicate with multiple physical networks, and the physical network can also communicate with multiple virtual networks through the configured virtual local area network VLAN, and the virtual network device on the border device has more The independent connection point management function makes virtual network design, resource service/sharing, inter-network interworking, node management, etc. more flexible and convenient, and can improve the product service experience of the virtual network.
本申请中所述的虚拟网络设备,具体的可以包括通过网络设备虚拟化技术,将一台物理网络设备虚拟化成多台虚拟网络设备。本申请实施例的虚拟网络设备可以运行于物理设备之上,通过软、硬件虚拟化的配合,可以具有一定的物理设备的功能,可以有独立软件环境和数据,如本申请实施例的虚拟网络设备配置在运行在具有路由表存储和路由转发功能物理路由器上,通过虚拟网络设备上配置的虚拟设备接口来实现虚拟网络与多个虚拟网络/物理网络之间的可独立管理的连通。因此,基于上述实施例所述,本申请提供一种路由设备,可以为一种可以虚拟网络与虚拟网络/物理网络之间互通的处理装置,实现虚拟网络与虚拟网络/物理网络之间的通信连接和独立的连接点管理。具体的,本申请提供一种路由设备的一个实施例中,包括存储计算机可执行指令的存储器,接入第一虚拟网络的虚拟设备接口,并与第二网络中的第二虚拟网络设备进行通信,所述指令被处理器执行时使所述虚拟设备接口至少实现:The virtual network device described in this application may specifically include virtualizing one physical network device into multiple virtual network devices by using network device virtualization technology. The virtual network device in the embodiment of the present application may be configured to run on a physical device, and may have a function of a physical device by using a combination of software and hardware virtualization, and may have an independent software environment and data, such as a virtual network in the embodiment of the present application. The device is configured to run on a physical router with routing table storage and routing forwarding functions, and realizes independently manageable communication between the virtual network and multiple virtual networks/physical networks through a virtual device interface configured on the virtual network device. Therefore, based on the foregoing embodiments, the present application provides a routing device, which may be a processing device that can communicate between a virtual network and a virtual network/physical network, and implement communication between the virtual network and the virtual network/physical network. Connection and independent connection point management. Specifically, the present application provides an embodiment of a routing device, including a memory storing computer executable instructions, accessing a virtual device interface of a first virtual network, and communicating with a second virtual network device in a second network. The instructions are executed by the processor to cause the virtual device interface to at least:
向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
当然,其他的实施例中,所述路由设备还可以基于接收到的反激活指令将对应的虚拟设备接口设置为非激活状态,以禁止进行数据收发。以及其他实施例中,所述路由设备基于接收到的删除指令删除相应的非激活状态的虚拟设备接口、所述第二网络为虚拟网络或物理网络等的实施方式。Certainly, in other embodiments, the routing device may further set the corresponding virtual device interface to an inactive state based on the received anti-activation command to prohibit data transmission and reception. In other embodiments, the routing device deletes the corresponding inactive virtual device interface based on the received deletion instruction, and the second network is a virtual network or a physical network.
利用本申请提供的虚拟网络设备或集成该虚拟网络设备的路由设备,可以实现虚拟网络与多个虚拟网络/物理网络之间的通信连接和独立的连接点管理,使得虚拟网络设计、资源服务/共享、跨网互通、节点管理等更加灵活、便利,有利于提高虚拟网络的产 品服务体验。因此,本申请还提供一种虚拟网络的连接方法,如图8所示,图8是本申请所述一种虚拟网络的连接方法一种实施例场景的处理流程示意图,可以包括接入第一网络的第一虚拟网络设备、接入第二网络的第二虚拟网络设备,所述第一虚拟网络设备配置至少一个第一虚拟设备接口,所述第二虚拟网络设备配置至少第二虚拟设备接口,所述第一网络、第二网络中至少一个为虚拟网络,With the virtual network device provided by the present application or the routing device integrated with the virtual network device, communication connection and independent connection point management between the virtual network and multiple virtual network/physical networks can be realized, so that virtual network design and resource service/ Sharing, inter-network interworking, and node management are more flexible and convenient, which is conducive to improving the product service experience of virtual networks. Therefore, the present application further provides a method for connecting a virtual network, as shown in FIG. 8. FIG. 8 is a schematic flowchart of a process of connecting a method for connecting a virtual network according to an embodiment of the present disclosure. a first virtual network device of the network, a second virtual network device accessing the second network, the first virtual network device configuring at least one first virtual device interface, and the second virtual network device configuring at least a second virtual device interface At least one of the first network and the second network is a virtual network.
S10:所述第一虚拟设备接口向所述第二虚拟设备接口发送连接请求,所述连接请求根据所述第一虚拟设备接口的配置信息和所述第二虚拟设备接口的验证信息生成;S10: The first virtual device interface sends a connection request to the second virtual device interface, where the connection request is generated according to the configuration information of the first virtual device interface and the verification information of the second virtual device interface.
S20:所述第二虚拟网络设备对所述连接请求进行验证,以及验证成功后基于所述第一虚拟设备接口的配置信息对所述第二虚拟设备接口进行配置,并向第一虚拟网络设备返回验证成功消息;S20: The second virtual network device verifies the connection request, and after the verification succeeds, configures the second virtual device interface according to the configuration information of the first virtual device interface, and sends the second virtual device interface to the first virtual network device. Return verification success message;
S30:所述第一虚拟网络设备收到所述验证成功消息后,根据所述第二网络的虚拟设备接口的配置信息对所述第一虚拟设备接口进行配置,建立与所述第二虚拟设备接口的通信连接。After the first virtual network device receives the verification success message, the first virtual device interface is configured according to the configuration information of the virtual device interface of the second network, and the second virtual device is established. The communication connection of the interface.
本申请上述实施例所述的方法或虚拟网络设备(包括虚拟设备接口的配置)可以通过计算机程序实现业务逻辑并记录在存储介质上,所述的存储介质可以由计算机读取并执行,实现本申请实施例所描述方案的效果。因此,本申请还提供一种计算机可读存储介质,其上存储有计算机指令,接入第一虚拟网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述指令被执行时使所述虚拟设备接口至少实现:The method or the virtual network device (including the configuration of the virtual device interface) in the foregoing embodiment of the present application may implement the business logic by using a computer program and record on the storage medium, and the storage medium may be read and executed by the computer to implement the present Apply the effects of the scheme described in the embodiment. Therefore, the present application further provides a computer readable storage medium having computer instructions stored thereon, accessing a first virtual network, and communicating with a second virtual network device in a second network, the virtual network device including at least a virtual device interface that, when executed, causes the virtual device interface to at least:
向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
所述计算机可读存储介质可以包括用于存储信息的物理装置,通常是将信息数字化后再以利用电、磁或者光学等方式的媒体加以存储。本实施例所述的计算机可读存储介质可以包括:利用电能方式存储信息的装置如,各式存储器,如RAM、ROM等;利用磁能方式存储信息的装置如,硬盘、软盘、磁带、磁芯存储器、磁泡存储器、U盘;利用光学方式存储信息的装置如,CD或DVD。当然,还有其他方式的可读存储介质,例 如量子存储器、石墨烯存储器等等。The computer readable storage medium may include physical means for storing information, typically by digitizing the information and then storing it in a medium that utilizes electrical, magnetic or optical means. The computer readable storage medium of this embodiment may include: means for storing information by means of electrical energy, such as various types of memories, such as RAM, ROM, etc.; means for storing information by means of magnetic energy, such as hard disk, floppy disk, magnetic tape, magnetic core Memory, bubble memory, U disk; means for optically storing information such as CD or DVD. Of course, there are other ways of readable storage media, such as quantum memories, graphene memories, and the like.
需要说明的是,虽然上述实施例提供了一些虚拟网络设备、路由设备、虚拟网络连接方法、计算机可读存储介质的实施例的描述,但基于前述其他相关实施例的描述,所述的设备、方法计算机可读存储介质还可以包括其他的实施方式,具体的可以参照相关实施例的描述,在此不再一一举例赘述。It should be noted that, although the above embodiments provide descriptions of some embodiments of a virtual network device, a routing device, a virtual network connection method, and a computer readable storage medium, the device, according to the foregoing description of other related embodiments, The method of the computer readable storage medium may also include other embodiments. For details, refer to the description of the related embodiments, and no further details are provided herein.
本申请还提供一种装置实施例,具体的可以包括:处理器,以及存储计算机可执行指令的存储器,所述指令被所述处理器执行时,配置用于第一虚拟网络的虚拟网络设备,并配置所述虚拟网络设备上的虚拟设备接口以至少实现:The application further provides an apparatus embodiment, which may specifically include: a processor, and a memory storing computer executable instructions, when the instructions are executed by the processor, configuring a virtual network device for the first virtual network, And configuring a virtual device interface on the virtual network device to implement at least:
向第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
基于所述第二虚拟网络设备返回的第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to configuration information of the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后进入激活状态,建立与第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device is established.
本说明还提供一种虚拟网络设备的另一种实施例,包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,The present disclosure also provides another embodiment of a virtual network device, including at least one virtual device interface, the virtual device interface configured to
向第二虚拟网络设备发送连接请求;Sending a connection request to the second virtual network device;
基于所述第二虚拟网络设备返回的用于第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to configuration information for the second network returned by the second virtual network device, the virtual device interface;
所述虚拟设备接口配置完成后建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the virtual device interface is configured, a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
需要说明的是,上述所述的装置、路由设备或虚拟网络设备等根据相关方法实施例的描述还可以包括其他的实施方式,具体的实现方式可以参照方法实施例的描述,在此不作一一赘述。本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于硬件+程序类实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。It should be noted that the foregoing description of the device, the routing device, the virtual network device, and the like may further include other implementation manners according to the description of the related method embodiments. For the specific implementation manner, reference may be made to the description of the method embodiment, and the description is not made herein. Narration. The various embodiments in the specification are described in a progressive manner, and the same or similar parts between the various embodiments may be referred to each other, and each embodiment focuses on the differences from the other embodiments. In particular, for the hardware + program type embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
上述对本说明书特定实施例进行了描述。其它实施例在所附权利要求书的范围内。在一些情况下,在权利要求书中记载的动作或步骤可以按照不同于实施例中的顺序来执行并且仍然可以实现期望的结果。另外,在附图中描绘的过程不一定要求示出的特定顺 序或者连续顺序才能实现期望的结果。在某些实施方式中,多任务处理和并行处理也是可以的或者可能是有利的。The foregoing description of the specific embodiments of the specification has been described. Other embodiments are within the scope of the following claims. In some cases, the actions or steps recited in the claims can be performed in a different order than the embodiments and still achieve the desired results. In addition, the processes depicted in the figures are not necessarily required to be in a particular order or in a sequential order to achieve a desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
本申请提供的一种虚拟网络设备、路由设备及虚拟网络的连接方法,构建一种新的虚拟网络设备,通过虚拟网络设备上配置的虚拟设备接口实现虚拟网络与一个或多个虚拟网络/物理网络之间的连接。当需要与多个虚拟网络/物理网络连接时,可以创建出多个虚拟设备接口,从而完成与多个虚拟网络/物理网络之间的连接。本申请实施方案增加了如同物理路由器上的路由器接口的概念,并基于虚拟网络和物理网络得特性加以扩充使得本申请中的虚拟网络设备既能连接不同的虚拟网络,也能连接多个虚拟网络/物理网络,并且还可以更好的实现物理网络中专线接入,满足跨网络互通的功能和场景需求。利用本申请实施方案,实现扩展虚拟网络与多个不同的虚拟网络/物理网络的互通实施方案,并具有独立的连接点管理功能,使得虚拟网络设计、资源服务/共享、跨网互通、节点管理等更加灵活、便利,有利于提高虚拟网络的产品服务体验。The present invention provides a virtual network device, a routing device, and a virtual network connection method, and constructs a new virtual network device, and implements a virtual network and one or more virtual networks/physical through a virtual device interface configured on the virtual network device. The connection between the networks. When multiple virtual/physical networks need to be connected, multiple virtual device interfaces can be created to complete the connection with multiple virtual/physical networks. The embodiment of the present application adds the concept of a router interface like a physical router, and is expanded based on the characteristics of the virtual network and the physical network. The virtual network device in the present application can connect to different virtual networks and connect multiple virtual networks. / Physical network, and can also better realize private line access in the physical network to meet the functions and scenarios of inter-network interworking. With the implementation of the present application, an implementation scheme of an extended virtual network and a plurality of different virtual network/physical networks is realized, and an independent connection point management function is provided, so that virtual network design, resource service/sharing, inter-network interworking, and node management are implemented. More flexible and convenient, it is conducive to improving the product service experience of virtual networks.
尽管本申请内容中提到虚拟设备接口的配置字段和方式、连接请求消息包含的信息、接口反激活和删除操作等的概念描述、接口数据配置、消息交互处理等描述,但是,本申请并不局限于必须是符合行业数据通信标准、路由接口配置标准或实施例所描述的情况。某些行业标准或者使用自定义方式或实施例描述的实施基础上略加修改后的实施方案也可以实现上述实施例相同、等同或相近、或变形后可预料的实施效果。应用这些修改或变形后的数据定义、接口信息配置、数据处理方式等获取的实施例,仍然可以属于本申请的可选实施方案范围之内。Although the description of the configuration field and mode of the virtual device interface, the information contained in the connection request message, the interface description of the interface deactivation and deletion operation, the interface data configuration, the message interaction processing, etc. are mentioned in the present application, the present application does not It must be limited to the conditions described in the industry data communication standards, routing interface configuration standards, or embodiments. Certain industry standards or implementations that have been modified in a manner that uses a custom approach or an embodiment described above may also achieve the same, equivalent, or similar, or post-deformation implementation effects of the above-described embodiments. Embodiments obtained by applying these modified or modified data definitions, interface information configurations, data processing methods, etc., may still fall within the scope of alternative embodiments of the present application.
虽然本申请提供了如前述实施例或附图所示的方法操作步骤或虚拟网络设备的装置/拓扑结构以及接口配置信息,但基于常规或者无需创造性的劳动在所述方法或装置中可以包括更多或者部分合并后更少的实施步骤。在逻辑性上不存在必要因果关系的步骤或结构中,这些步骤的执行顺序或设备的模块结构不限于本申请实施例或附图所示的执行顺序或设备结构。所述的方法或结构的在实际中的装置或终端产品应用时,可以按照实施例或者附图所示的方法或模块结构进行顺序执行或者并行执行(例如并行处理器或者多线程处理的环境、甚至包括分布式处理的实施环境)。Although the present application provides method operational steps or apparatus/topology and interface configuration information of a virtual network device as described in the preceding embodiments or the accompanying drawings, it may be included in the method or apparatus based on conventional or no inventive labor. More or some of the implementation steps after the merger. In the steps or structures in which the necessary causal relationship does not exist logically, the execution order of the steps or the module structure of the device is not limited to the execution order or device structure shown in the embodiment of the present application or the drawings. When the device or the terminal product of the method or structure is applied, it may be sequentially executed or executed in parallel according to the method or the module structure shown in the embodiment or the drawing (for example, a parallel processor or a multi-thread processing environment, Even the implementation environment for distributed processing).
在20世纪90年代,对于一个技术的改进可以很明显地区分是硬件上的改进(例如,对二极管、晶体管、开关等电路结构的改进)还是软件上的改进(对于方法流程的改进)。然而,随着技术的发展,当今的很多方法流程的改进已经可以视为硬件电路结构的直接 改进。设计人员几乎都通过将改进的方法流程编程到硬件电路中来得到相应的硬件电路结构。因此,不能说一个方法流程的改进就不能用硬件实体模块来实现。例如,可编程逻辑器件(Programmable Logic Device,PLD)(例如现场可编程门阵列(Field Programmable Gate Array,FPGA))就是这样一种集成电路,其逻辑功能由用户对器件编程来确定。由设计人员自行编程来把一个数字系统“集成”在一片PLD上,而不需要请芯片制造厂商来设计和制作专用的集成电路芯片。而且,如今,取代手工地制作集成电路芯片,这种编程也多半改用“逻辑编译器(logic compiler)”软件来实现,它与程序开发撰写时所用的软件编译器相类似,而要编译之前的原始代码也得用特定的编程语言来撰写,此称之为硬件描述语言(Hardware Description Language,HDL),而HDL也并非仅有一种,而是有许多种,如ABEL(Advanced Boolean Expression Language)、AHDL(Altera Hardware Description Language)、Confluence、CUPL(Cornell University Programming Language)、HDCal、JHDL(Java Hardware Description Language)、Lava、Lola、MyHDL、PALASM、RHDL(Ruby Hardware Description Language)等,目前最普遍使用的是VHDL(Very-High-Speed Integrated Circuit Hardware Description Language)与Verilog。本领域技术人员也应该清楚,只需要将方法流程用上述几种硬件描述语言稍作逻辑编程并编程到集成电路中,就可以很容易得到实现该逻辑方法流程的硬件电路。In the 1990s, improvements to a technology could clearly distinguish between hardware improvements (eg, improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (for process flow improvements). However, as technology advances, many of today's method flow improvements can be seen as direct improvements in hardware circuit architecture. Designers almost always get the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that the improvement of a method flow cannot be implemented by hardware entity modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is an integrated circuit whose logic function is determined by the user programming the device. Designers can program themselves to "integrate" a digital system on a single PLD without having to ask the chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, today, instead of manually making integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in programming development, but before compiling The original code has to be written in a specific programming language. This is called the Hardware Description Language (HDL). HDL is not the only one, but there are many kinds, such as ABEL (Advanced Boolean Expression Language). AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., are currently the most commonly used VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. It should also be apparent to those skilled in the art that the hardware flow for implementing the logic method flow can be easily obtained by simply programming the method flow into the integrated circuit with a few hardware description languages.
控制器可以按任何适当的方式实现,例如,控制器可以采取例如微处理器或处理器以及存储可由该(微)处理器执行的计算机可读程序代码(例如软件或固件)的计算机可读介质、逻辑门、开关、专用集成电路(Application Specific Integrated Circuit,ASIC)、可编程逻辑控制器和嵌入微控制器的形式,控制器的例子包括但不限于以下微控制器:ARC 625D、Atmel AT91SAM、Microchip PIC18F26K20以及Silicone Labs C8051F320,存储器控制器还可以被实现为存储器的控制逻辑的一部分。本领域技术人员也知道,除了以纯计算机可读程序代码方式实现控制器以外,完全可以通过将方法步骤进行逻辑编程来使得控制器以逻辑门、开关、专用集成电路、可编程逻辑控制器和嵌入微控制器等的形式来实现相同功能。因此这种控制器可以被认为是一种硬件部件,而对其内包括的用于实现各种功能的装置也可以视为硬件部件内的结构。或者甚至,可以将用于实现各种功能的装置视为既可以是实现方法的软件模块又可以是硬件部件内的结构。The controller can be implemented in any suitable manner, for example, the controller can take the form of, for example, a microprocessor or processor and a computer readable medium storing computer readable program code (eg, software or firmware) executable by the (micro)processor. In the form of logic gates, switches, application specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers, examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, The Microchip PIC18F26K20 and the Silicone Labs C8051F320, the memory controller can also be implemented as part of the memory's control logic. Those skilled in the art will also appreciate that in addition to implementing the controller in purely computer readable program code, the controller can be logically programmed by means of logic gates, switches, ASICs, programmable logic controllers, and embedding. The form of a microcontroller or the like to achieve the same function. Such a controller can therefore be considered a hardware component, and the means for implementing various functions included therein can also be considered as a structure within the hardware component. Or even a device for implementing various functions can be considered as a software module that can be both a method of implementation and a structure within a hardware component.
上述实施例阐明的系统、装置、模块或单元,具体可以由计算机芯片或实体实现,或者由具有某种功能的产品来实现。一种典型的实现设备为计算机。具体的,计算机例如可以为个人计算机、膝上型计算机、车载人机交互设备、蜂窝电话、相机电话、智能 电话、个人数字助理、媒体播放器、导航设备、电子邮件设备、游戏控制台、平板计算机、可穿戴设备或者这些设备中的任何设备的组合。The system, device, module or unit illustrated in the above embodiments may be implemented by a computer chip or an entity, or by a product having a certain function. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a car-mounted human-machine interaction device, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet. A computer, wearable device, or a combination of any of these devices.
虽然本申请提供了如实施例或流程图所述的方法操作步骤,但基于常规或者无创造性的手段可以包括更多或者更少的操作步骤。实施例中列举的步骤顺序仅仅为众多步骤执行顺序中的一种方式,不代表唯一的执行顺序。在实际中的装置或终端产品执行时,可以按照实施例或者附图所示的方法顺序执行或者并行执行(例如并行处理器或者多线程处理的环境,甚至为分布式数据处理环境)。术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、产品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、产品或者设备所固有的要素。在没有更多限制的情况下,并不排除在包括所述要素的过程、方法、产品或者设备中还存在另外的相同或等同要素。Although the present application provides method operational steps as described in the embodiments or flowcharts, more or fewer operational steps may be included based on conventional or non-creative means. The order of the steps recited in the embodiments is only one of the many steps of the order of execution, and does not represent a single order of execution. When the actual device or terminal product is executed, it may be executed sequentially or in parallel according to the embodiment or the method shown in the drawings (for example, a parallel processor or a multi-threaded environment, or even a distributed data processing environment). The terms "comprising," "comprising," or "comprising" or "comprising" or "the" Elements, or elements that are inherent to such a process, method, product, or device. In the absence of further limitations, it is not excluded that there are additional identical or equivalent elements in the process, method, product, or device.
为了描述的方便,描述以上装置时以功能分为各种模块分别描述。当然,在实施本申请时可以把各模块的功能在同一个或多个软件和/或硬件中实现,也可以将实现同一功能的模块由多个子模块或子单元的组合实现等。以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。For the convenience of description, the above devices are described as being separately divided into various modules by function. Of course, in the implementation of the present application, the functions of each module may be implemented in the same software or software, or the modules that implement the same function may be implemented by a plurality of sub-modules or a combination of sub-units. The device embodiments described above are merely illustrative. For example, the division of the unit is only a logical function division. In actual implementation, there may be another division manner, for example, multiple units or components may be combined or integrated. Go to another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
本领域技术人员也知道,除了以纯计算机可读程序代码方式实现控制器以外,完全可以通过将方法步骤进行逻辑编程来使得控制器以逻辑门、开关、专用集成电路、可编程逻辑控制器和嵌入微控制器等的形式来实现相同功能。因此这种控制器可以被认为是一种硬件部件,而对其内部包括的用于实现各种功能的装置也可以视为硬件部件内的结构。或者甚至,可以将用于实现各种功能的装置视为既可以是实现方法的软件模块又可以是硬件部件内的结构。Those skilled in the art will also appreciate that in addition to implementing the controller in purely computer readable program code, the controller can be logically programmed by means of logic gates, switches, ASICs, programmable logic controllers, and embedding. The form of a microcontroller or the like to achieve the same function. Therefore, such a controller can be considered as a hardware component, and a device for internally implementing it for implementing various functions can also be regarded as a structure within a hardware component. Or even a device for implementing various functions can be considered as a software module that can be both a method of implementation and a structure within a hardware component.
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指 定的功能的装置。The present invention has been described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (system), and computer program products according to embodiments of the invention. It will be understood that each flow and/or block of the flowchart illustrations and/or FIG. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing device to produce a machine for the execution of instructions for execution by a processor of a computer or other programmable data processing device. Means for implementing the functions specified in one or more of the flow or in a block or blocks of the flow chart.
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。The computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device. The apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device. The instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
在一个典型的配置中,计算设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。In a typical configuration, a computing device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。The memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium, such as read only memory (ROM) or flash memory. Memory is an example of a computer readable medium.
计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括暂存电脑可读媒体(transitory media),如调制的数据信号和载波。Computer readable media includes both permanent and non-persistent, removable and non-removable media. Information storage can be implemented by any method or technology. The information can be computer readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, Magnetic tape cartridges, magnetic tape storage or other magnetic storage devices or any other non-transportable media can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary storage of computer readable media, such as modulated data signals and carrier waves.
本领域技术人员应明白,本申请的实施例可提供为方法、系统或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。Those skilled in the art will appreciate that embodiments of the present application can be provided as a method, system, or computer program product. Thus, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment in combination of software and hardware. Moreover, the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
本申请可以在由计算机执行的计算机可执行指令的一般上下文中描述,例如程序模块。一般地,程序模块包括执行特定任务或实现特定抽象数据类型的例程、程序、对象、 组件、数据结构等等。也可以在分布式计算环境中实践本申请,在这些分布式计算环境中,由通过通信网络而被连接的远程处理设备来执行任务。在分布式计算环境中,程序模块可以位于包括存储设备在内的本地和远程计算机存储介质中。The application can be described in the general context of computer-executable instructions executed by a computer, such as a program module. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform particular tasks or implement particular abstract data types. The present application can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including storage devices.
本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于系统实施例而言,由于其基本相似于方法实施例,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本申请的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不必须针对的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任一个或多个实施例或示例中以合适的方式结合。此外,在不相互矛盾的情况下,本领域的技术人员可以将本说明书中描述的不同实施例或示例以及不同实施例或示例的特征进行结合和组合。The various embodiments in the specification are described in a progressive manner, and the same or similar parts between the various embodiments may be referred to each other, and each embodiment focuses on the differences from the other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment. In the description of the present specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" and the like means a specific feature described in connection with the embodiment or example. A structure, material or feature is included in at least one embodiment or example of the application. In the present specification, the schematic representation of the above terms is not necessarily directed to the same embodiment or example. Furthermore, the particular features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. In addition, various embodiments or examples described in the specification and features of various embodiments or examples may be combined and combined without departing from the scope of the invention.
以上所述仅为本申请的实施例而已,并不用于限制本申请。对于本领域技术人员来说,本申请可以有各种更改和变化。凡在本申请的精神和原理之内所作的任何修改、等同替换、改进等,均应包含在本申请的权利要求范围之内。The above description is only an embodiment of the present application and is not intended to limit the application. Various changes and modifications can be made to the present application by those skilled in the art. Any modifications, equivalents, improvements, etc. made within the spirit and scope of the present application are intended to be included within the scope of the appended claims.

Claims (25)

  1. 一种虚拟网络设备,其特征在于,接入第一虚拟网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,A virtual network device, configured to access a first virtual network and to communicate with a second virtual network device in a second network, the virtual network device including at least one virtual device interface, the virtual device interface being Configured to
    向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
    基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
    所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  2. 如权利要求1所述的虚拟网络设备,其特征在于,所述第二网络为虚拟网络或物理网络。The virtual network device of claim 1, wherein the second network is a virtual network or a physical network.
  3. 如权利要求1所述的虚拟网络设备,其特征在于,所述基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置,包括:The virtual network device according to claim 1, wherein the configuring the virtual device interface based on the configuration information of the second network returned by the second virtual network device comprises:
    接收所述第二虚拟网络设备发送的验证成功消息,所述验证成功消息包括所述第二虚拟网络设备对所述连接请求中的第一虚拟网络的配置信息验证成功时返回给所述虚拟网络设备的消息;Receiving the verification success message sent by the second virtual network device, where the verification success message includes the second virtual network device returning to the virtual network when the configuration information of the first virtual network in the connection request is successfully verified. Device message
    基于所述验证成功消息将所述虚拟设备接口设置为激活状态。The virtual device interface is set to an active state based on the verification success message.
  4. 如权利要求1所述的虚拟网络设备,其特征在于,所述连接请求还包括下述验证信息:The virtual network device of claim 1, wherein the connection request further comprises the following verification information:
    所述第二网虚拟网络设备的识别标识、所述第二虚拟网络设备中第二虚拟设备接口的识别标识、所述第二虚拟网络设备的所有者的识别标识。The identification identifier of the second network virtual network device, the identification identifier of the second virtual device interface in the second virtual network device, and the identification identifier of the owner of the second virtual network device.
  5. 如权利要求1所述的虚拟网络设备,其特征在于,所述虚拟设备接口还被配置成,The virtual network device of claim 1, wherein the virtual device interface is further configured to
    基于接收到的反激活指令设置为非激活状态,以禁止所述虚拟设备接口进行数据收发。The inactive state is set to be inactive based on the received anti-activation command to prohibit the virtual device interface from transmitting and receiving data.
  6. 如权利要求1所述的虚拟网络设备,其特征在于,所述虚拟网络设备还基于接收到的接口删除指令删除所述虚拟网络设备中指定的非激活状态的虚拟设备接口。The virtual network device according to claim 1, wherein the virtual network device further deletes the virtual device interface in the inactive state specified in the virtual network device based on the received interface deletion instruction.
  7. 如权利要求1至4中任意一项所述的虚拟网络设备,其特征在于,所述第一虚拟网络通过所述虚拟网络设备的K个激活状态的虚拟设备接口分别与K个第二网络建立通信连接,K≥2。The virtual network device according to any one of claims 1 to 4, wherein the first virtual network is established with the K second networks by the virtual device interfaces of the K active states of the virtual network device, respectively. Communication connection, K≥2.
  8. 如权利要求1至4中任意一项所述的虚拟网络设备,其特征在于,发送连接请求后,还包括:The virtual network device according to any one of claims 1 to 4, further comprising: after transmitting the connection request,
    从所述第二虚拟网络设备获取所述第二网络使用的数据包的解封包逻辑信息,并根据所述第一虚拟网络使用的数据包的解封包逻辑信息,生成所述第一虚拟网络与第二网络之间的数据包的解封包处理逻辑;Obtaining, according to the second virtual network device, the decapsulation logic information of the data packet used by the second network, and generating the first virtual network according to the decapsulation logic information of the data packet used by the first virtual network. Decapsulation processing logic for data packets between the second networks;
    将所述解封包处理逻辑配置在与所述第二网络对应的虚拟设备接口的配置信息中。The decapsulation processing logic is configured in configuration information of a virtual device interface corresponding to the second network.
  9. 如权利要求1至4中任意一项所述的虚拟网络设备,其特征在于,还包括:基于所述虚拟设备接口进行安全防护设置。The virtual network device according to any one of claims 1 to 4, further comprising: performing security protection setting based on the virtual device interface.
  10. 一种虚拟网络设备,其特征在于,接入第一物理网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,A virtual network device, configured to access a first physical network and to communicate with a second virtual network device in a second network, the virtual network device including at least one virtual device interface, the virtual device interface being Configured to
    向第二虚拟网络设备发送连接请求,所述连接请求包括所述第一物理网络的配置信息,所述第一物理网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first physical network, and configuration information of the first physical network is used for an interface configuration of the second virtual network device;
    基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
    所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  11. 如权利要求10所述的虚拟网络设备,其特征在于,还配置有边界虚拟设备接口,所述边界虚拟设备接口与所述第一物理网络的边界设备上的物理接口相连接,所述物理接口上配置至少一个虚拟局域网,且同一个虚拟网络设备在同一个物理接口上共用 相同的虚拟局域网。The virtual network device according to claim 10, further configured with a border virtual device interface, wherein the border virtual device interface is connected to a physical interface on a border device of the first physical network, the physical interface At least one virtual local area network is configured, and the same virtual network device shares the same virtual local area network on the same physical interface.
  12. 一种路由设备,其特征在于,包括存储计算机可执行指令的存储器,接入第一虚拟网络的虚拟设备接口,并与第二网络中的第二虚拟网络设备进行通信,所述指令被处理器执行时使所述虚拟设备接口至少实现:A routing device, comprising: a memory storing computer executable instructions, accessing a virtual device interface of a first virtual network, and communicating with a second virtual network device in a second network, the instructions being processed by a processor The virtual device interface is implemented at least when executed:
    向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
    基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
    所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  13. 如权利要求12所述的路由设备,其特征在于,所述第二网络为虚拟网络或物理网络。The routing device of claim 12, wherein the second network is a virtual network or a physical network.
  14. 如权利要求12所述的路由设备,其特征在于,所述基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置,包括:The routing device according to claim 12, wherein the configuring the virtual device interface based on the configuration information of the second network returned by the second virtual network device comprises:
    接收所述第二虚拟网络设备发送的验证成功消息,所述验证成功消息包括所述第二虚拟网络设备对所述连接请求中的第一虚拟网络的配置信息验证成功时返回给所述虚拟网络设备的消息;Receiving the verification success message sent by the second virtual network device, where the verification success message includes the second virtual network device returning to the virtual network when the configuration information of the first virtual network in the connection request is successfully verified. Device message
    基于所述验证成功消息将所述虚拟设备接口设置为激活状态。The virtual device interface is set to an active state based on the verification success message.
  15. 如权利要求12所述的路由设备,其特征在于,所述路由设备基于接收到的反激活指令将对应的虚拟设备接口设置为非激活状态,以禁止进行数据收发。The routing device according to claim 12, wherein the routing device sets the corresponding virtual device interface to an inactive state based on the received anti-activation command to prohibit data transmission and reception.
  16. 如权利要求12所述的路由设备,其特征在于,所述路由设备基于接收到的删除指令删除相应的非激活状态的虚拟设备接口。The routing device according to claim 12, wherein said routing device deletes a corresponding virtual device interface in an inactive state based on the received deletion instruction.
  17. 如权利要求12-16中任意一项所述的路由设备,其特征在于,所述路由设备还实现:The routing device according to any one of claims 12-16, wherein the routing device further implements:
    基于所述虚拟设备接口进行安全防护设置。Security protection settings are made based on the virtual device interface.
  18. 一种虚拟网络的连接方法,其特征在于,包括接入第一网络的第一虚拟网络设备、接入第二网络的第二虚拟网络设备,所述第一虚拟网络设备配置至少一个第一虚拟设备接口,所述第二虚拟网络设备配置至少一个第二虚拟设备接口,所述第一网络、第二网络中至少一个为虚拟网络,A method for connecting a virtual network, comprising: a first virtual network device accessing a first network, and a second virtual network device accessing a second network, where the first virtual network device is configured with at least one first virtual a device interface, the second virtual network device is configured with at least one second virtual device interface, and at least one of the first network and the second network is a virtual network.
    所述第一虚拟设备接口向所述第二虚拟设备接口发送连接请求,所述连接请求根据所述第一虚拟设备接口的配置信息和所述第二虚拟设备接口的验证信息生成;The first virtual device interface sends a connection request to the second virtual device interface, where the connection request is generated according to the configuration information of the first virtual device interface and the verification information of the second virtual device interface;
    所述第二虚拟网络设备对所述连接请求进行验证,以及验证成功后基于所述第一虚拟设备接口的配置信息对所述第二虚拟设备接口进行配置,并向第一虚拟网络设备返回验证成功消息;The second virtual network device verifies the connection request, and after the verification succeeds, configures the second virtual device interface according to the configuration information of the first virtual device interface, and returns verification to the first virtual network device. Success message
    所述第一虚拟网络设备收到所述验证成功消息后,根据所述第二网络的虚拟设备接口的配置信息对所述第一虚拟设备接口进行配置,建立与所述第二虚拟设备接口的通信连接。After receiving the verification success message, the first virtual network device configures the first virtual device interface according to the configuration information of the virtual device interface of the second network, and establishes an interface with the second virtual device. Communication connection.
  19. 一种计算机可读存储介质,其上存储有计算机指令,其特征在于,接入第一虚拟网络,并与第二网络中的第二虚拟网络设备进行通信,所述虚拟网络设备包括至少一个虚拟设备接口,所述指令被执行时使所述虚拟设备接口至少实现:A computer readable storage medium having stored thereon computer instructions, configured to access a first virtual network and to communicate with a second virtual network device in a second network, the virtual network device including at least one virtual a device interface that, when executed, causes the virtual device interface to at least:
    向所述第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
    基于所述第二虚拟网络设备返回的所述第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to the configuration information of the second network returned by the second virtual network device, the virtual device interface;
    所述虚拟设备接口配置完成后进入激活状态,建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  20. 一种装置,包括:处理器,以及存储计算机可执行指令的存储器,所述指令被所述处理器执行时,配置用于第一虚拟网络的虚拟网络设备,并配置所述虚拟网络设备上的虚拟设备接口以至少实现:An apparatus comprising: a processor, and a memory storing computer executable instructions, the instructions being executed by the processor, configuring a virtual network device for the first virtual network, and configuring the virtual network device The virtual device interface is implemented to at least:
    向第二虚拟网络设备发送连接请求,所述连接请求包括所述第一虚拟网络的配置信息,所述第一虚拟网络的配置信息用于所述第二虚拟网络设备的接口配置;Sending a connection request to the second virtual network device, where the connection request includes configuration information of the first virtual network, and configuration information of the first virtual network is used for an interface configuration of the second virtual network device;
    基于所述第二虚拟网络设备返回的第二网络的配置信息,对所述虚拟设备接口进行 配置;And configuring, according to configuration information of the second network returned by the second virtual network device, the virtual device interface;
    所述虚拟设备接口配置完成后进入激活状态,建立与第二虚拟网络设备的第二虚拟设备接口的通信连接。After the configuration of the virtual device interface is completed, the active state is entered, and a communication connection with the second virtual device interface of the second virtual network device is established.
  21. 一种虚拟网络设备,其特征在于,包括至少一个虚拟设备接口,所述虚拟设备接口被配置成,A virtual network device, comprising: at least one virtual device interface, the virtual device interface configured to
    向第二虚拟网络设备发送连接请求;Sending a connection request to the second virtual network device;
    基于所述第二虚拟网络设备返回的用于第二网络的配置信息,对所述虚拟设备接口进行配置;And configuring, according to configuration information for the second network returned by the second virtual network device, the virtual device interface;
    所述虚拟设备接口配置完成后建立与所述第二网络的第二虚拟网络设备的第二虚拟设备接口的通信连接。After the virtual device interface is configured, a communication connection with the second virtual device interface of the second virtual network device of the second network is established.
  22. 如权利要求21所述的一种虚拟网络设备,其特征在于,所述虚拟设备接口还被配置成,A virtual network device according to claim 21, wherein said virtual device interface is further configured to
    基于接收到的反激活指令设置为非激活状态,以禁止所述虚拟设备接口进行数据收发。The inactive state is set to be inactive based on the received anti-activation command to prohibit the virtual device interface from transmitting and receiving data.
  23. 如权利要求21所述的虚拟网络设备,其特征在于,所述虚拟网络设备还基于接收到的接口删除指令删除所述虚拟网络设备中指定的非激活状态的虚拟设备接口。The virtual network device according to claim 21, wherein the virtual network device further deletes the virtual device interface in the inactive state specified in the virtual network device based on the received interface deletion instruction.
  24. 如权利要求21所述的虚拟网络设备,其特征在于,通过所述虚拟网络设备的K个激活状态的虚拟设备接口分别与K个第二网络建立通信连接,K≥2。The virtual network device according to claim 21, wherein the virtual device interfaces of the K active states of the virtual network device respectively establish a communication connection with the K second networks, K≥2.
  25. 如权利要求21至24中任意一项所述的虚拟网络设备,其特征在于,还基于所述虚拟设备接口进行安全防护设置。The virtual network device according to any one of claims 21 to 24, wherein the security protection setting is further performed based on the virtual device interface.
PCT/CN2018/093995 2017-07-11 2018-07-02 Virtual network device, routing device and virtual network connection method WO2019011144A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710560716.0A CN109245983B (en) 2017-07-11 2017-07-11 Virtual network equipment, routing equipment and virtual network connection method
CN201710560716.0 2017-07-11

Publications (1)

Publication Number Publication Date
WO2019011144A1 true WO2019011144A1 (en) 2019-01-17

Family

ID=65001405

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/093995 WO2019011144A1 (en) 2017-07-11 2018-07-02 Virtual network device, routing device and virtual network connection method

Country Status (2)

Country Link
CN (1) CN109245983B (en)
WO (1) WO2019011144A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112671890A (en) * 2020-12-21 2021-04-16 深圳云天励飞技术股份有限公司 Network connection device and network system

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114666395B (en) * 2022-03-29 2024-03-08 青岛海信移动通信技术有限公司 Dual-system network sharing method and device

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1503506A (en) * 2002-11-20 2004-06-09 日立通讯技术株式会社 Virtual insertion router
US20150163072A1 (en) * 2013-12-05 2015-06-11 Broadcom Corporation Virtual Port Extender
CN104954253A (en) * 2014-03-31 2015-09-30 瞻博网络公司 PCIe-based host network accelerators (HNAS) for data center overlay network
CN106383736A (en) * 2016-09-21 2017-02-08 杭州华三通信技术有限公司 Port extension method and apparatus

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8744516B2 (en) * 2004-02-05 2014-06-03 Sri International Generic client for communication devices
US8615014B2 (en) * 2010-03-03 2013-12-24 Iwebgate Technology Limited System and method for multiple concurrent virtual networks
CN101986666B (en) * 2010-11-05 2013-07-24 清华大学 Network data transmission method based on virtual network interface and reverse address resolution
US9712438B2 (en) * 2014-01-08 2017-07-18 Microsoft Technology Licensing, Llc Routing messages between virtual networks

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1503506A (en) * 2002-11-20 2004-06-09 日立通讯技术株式会社 Virtual insertion router
US20150163072A1 (en) * 2013-12-05 2015-06-11 Broadcom Corporation Virtual Port Extender
CN104954253A (en) * 2014-03-31 2015-09-30 瞻博网络公司 PCIe-based host network accelerators (HNAS) for data center overlay network
CN106383736A (en) * 2016-09-21 2017-02-08 杭州华三通信技术有限公司 Port extension method and apparatus

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112671890A (en) * 2020-12-21 2021-04-16 深圳云天励飞技术股份有限公司 Network connection device and network system

Also Published As

Publication number Publication date
CN109245983B (en) 2021-11-16
CN109245983A (en) 2019-01-18

Similar Documents

Publication Publication Date Title
TWI696079B (en) Multi-blockchain network data processing method, device and server
US10698717B2 (en) Accelerator virtualization method and apparatus, and centralized resource manager
RU2571536C2 (en) Method, system and controlling bridge for obtaining port extension topology information
US9825808B2 (en) Network configuration via abstraction components and standard commands
US9244817B2 (en) Remote debugging in a cloud computing environment
US8819211B2 (en) Distributed policy service
US10164866B2 (en) Virtual extensible LAN intercommunication mechanism for multicast in networking
US20170109176A1 (en) iSCSI BASED BARE METAL OS IMAGE DEPLOYMENT AND DISKLESS BOOT
US9628374B1 (en) Ethernet link aggregation with shared physical ports
WO2017162043A1 (en) Access method, configuration method and apparatus used for inter-device service
US20210314144A1 (en) Modifiable client-side encrypted data in the cloud
US20120291024A1 (en) Virtual Managed Network
US20120278878A1 (en) Systems and methods for establishing secure virtual private network communications using non-privileged vpn client
US9537798B1 (en) Ethernet link aggregation with shared physical ports
US9712376B2 (en) Connector configuration for external service provider
WO2013049990A1 (en) Live logical partition migration with stateful offload connections using context extraction and insertion
JP2017516410A (en) Connection to public network private network resources
WO2016206171A1 (en) Secure networking method based on network isolation, and terminal
US9590855B2 (en) Configuration of transparent interconnection of lots of links (TRILL) protocol enabled device ports in edge virtual bridging (EVB) networks
US9967139B2 (en) Remote zone management of JBOD systems
WO2018054047A1 (en) Data processing method and related storage apparatus
WO2023179715A1 (en) Data channel construction method and apparatus
WO2024021414A1 (en) Data transmission
WO2019011144A1 (en) Virtual network device, routing device and virtual network connection method
WO2017067486A1 (en) Terminal and data transmission method and device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18831273

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18831273

Country of ref document: EP

Kind code of ref document: A1