WO2019072165A1 - 虚拟化流镜像策略自动化管理方法及设备、存储介质 - Google Patents

虚拟化流镜像策略自动化管理方法及设备、存储介质 Download PDF

Info

Publication number
WO2019072165A1
WO2019072165A1 PCT/CN2018/109469 CN2018109469W WO2019072165A1 WO 2019072165 A1 WO2019072165 A1 WO 2019072165A1 CN 2018109469 W CN2018109469 W CN 2018109469W WO 2019072165 A1 WO2019072165 A1 WO 2019072165A1
Authority
WO
WIPO (PCT)
Prior art keywords
mirroring policy
flow
policy
traffic
vnf
Prior art date
Application number
PCT/CN2018/109469
Other languages
English (en)
French (fr)
Inventor
刘承志
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to RU2019145122A priority Critical patent/RU2729406C1/ru
Priority to EP18865925.4A priority patent/EP3633920A1/en
Publication of WO2019072165A1 publication Critical patent/WO2019072165A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0813Configuration setting characterised by the conditions triggering a change of settings
    • H04L41/0816Configuration setting characterised by the conditions triggering a change of settings the condition being an adaptation, e.g. in response to network events
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0876Aspects of the degree of configuration automation
    • H04L41/0886Fully automatic configuration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0896Bandwidth or capacity management, i.e. automatically increasing or decreasing capacities
    • H04L41/0897Bandwidth or capacity management, i.e. automatically increasing or decreasing capacities by horizontal or vertical scaling of resources, or by migrating entities, e.g. virtual resources or entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/40Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using virtualisation of network functions or resources, e.g. SDN or NFV entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/06Generation of reports
    • H04L43/062Generation of reports related to network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/12Network monitoring probes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/20Arrangements for monitoring or testing data switching networks the monitoring system or the monitored elements being virtualised, abstracted or software-defined entities, e.g. SDN or NFV

Definitions

  • the present disclosure relates to, but is not limited to, the field of communications, and in particular, to a virtualized flow mirroring policy automatic management method and apparatus, and a computer readable storage medium.
  • the carrier is analyzed for user signaling.
  • the NFV/SDN-based flow mirroring function provides mirroring policy configuration at the Network Function Virtualization Infrastructure (NFVI) layer, and uses the NFVI layer's mirroring policy configuration function. After configuring the VM mirroring policy.
  • the traffic mirroring policy cannot be automatically matched by the life cycle of the virtual machine, such as the automatic resiliency of the virtual machine, the migration of the virtual machine, and the re-emergence of the virtual machine. The manual intervention is required to take effect.
  • the present disclosure provides a method for automatically managing a virtualized flow mirroring policy, the method comprising: programming flow mirroring policy information in a network function virtualization orchestrator (NFVO) according to the received instruction; and creating a flow mirroring according to the flow mirroring policy information And configuring the flow mirroring policy to a virtual network function (VNF); and monitoring the VNF according to the flow mirroring policy, and performing a corresponding management operation when a preset operation is detected.
  • NFVO network function virtualization orchestrator
  • the present disclosure further provides a virtualization flow mirroring policy automation management device, where the virtualization flow mirroring policy automation management device includes a processor, a network interface, a user interface, and a memory, where the virtualized flow mirroring policy is automatically managed.
  • a program the processor configured to execute the virtualized flow mirroring policy automation management program to implement the following steps: programming flow mirroring policy information in a network function virtualization orchestrator (NFVO) according to the received instruction;
  • NFVO network function virtualization orchestrator
  • the mirroring policy information is used to create a traffic mirroring policy, and the traffic mirroring policy is deployed to a virtual network function (VNF); and the VNF is monitored according to the traffic mirroring policy, and when a preset operation is detected, a corresponding Manage operations.
  • the present disclosure also provides a computer readable storage medium having a virtualized flow mirroring policy automation management program stored thereon, the virtualized flow mirroring policy automation management program being implemented by a computer as described above Virtualized flow mirroring strategy automation management method.
  • FIG. 1 is a flowchart of a method for automatically managing a virtualization flow mirroring policy according to an embodiment of the present disclosure
  • FIG. 2 is a flowchart of performing a corresponding management operation when a virtualized flow mirroring policy automatic management method detects a preset operation according to an embodiment of the present disclosure
  • FIG. 3 is a flowchart of performing a corresponding management operation when a virtualized flow mirroring policy automatic management method detects a preset operation according to an embodiment of the present disclosure
  • FIG. 4 is a schematic structural diagram of a virtualization flow mirroring policy automatic management device according to an embodiment of the present disclosure.
  • An embodiment of the present disclosure provides a method for automatically managing a virtualized flow mirroring policy.
  • a flow mirroring policy information is programmed in a Network Functions Virtualization Orchestrator (NFVO) according to the received instructions, and then according to the flow mirroring.
  • the policy information is used to create a traffic mirroring policy, and the traffic mirroring policy is deployed to a virtual network function (VNF), and then the VNF is monitored according to the traffic mirroring policy, and corresponding management is performed when a preset operation is detected.
  • Operation that is, the flow mirroring policy can follow the life cycle change of the virtual machine and the automatic association takes effect, and no manual intervention is required.
  • FIG. 1 is a flowchart of a method for automatically managing a virtualization flow mirroring policy according to an embodiment of the present disclosure.
  • the virtualization flow mirroring policy automatic management method of the embodiment of the present disclosure may include the following steps S10 to S30.
  • step S10 the flow mirroring policy information is programmed in the network function virtualization orchestrator (NFVO) according to the received instruction.
  • NFVO network function virtualization orchestrator
  • the life cycle of the virtual machine is managed by the NFVO. Therefore, the flow mirroring policy information is first programmed in the Network Function Virtualization Orchestrator (NFVO).
  • the programmed objects include the traffic mirror source and related configurations, the traffic mirror destination port, and related configurations.
  • the policy information includes: a traffic mirroring policy source object, where the traffic mirroring policy source object includes a source cloud host information, a source cloud host port, a flow direction type, and description information; a traffic mirroring policy destination object, and the traffic mirroring policy destination object
  • the destination port type, the switch ID, the switch port ID, and the network name are included;
  • the traffic mirroring policy rule object includes a source IP network segment, a destination IP network segment, an IP protocol type, a transport layer source port, and a transport layer. Destination port parameters.
  • Step S20 Create a traffic mirroring policy according to the traffic mirroring policy information, and deploy the traffic mirroring policy to a virtual network function (VNF).
  • VNF virtual network function
  • a traffic mirroring policy may be created according to the traffic mirroring policy information, and the traffic mirroring policy is deployed to a virtual network function (VNF).
  • VNF virtual network function
  • the network function virtualization orchestrator (NFVO) queries the virtual machine information corresponding to the VNF of the flow mirroring source, and converts the flow mirror source object into a Tapflow object; the network function virtualization orchestrator (NFVO) queries the flow mirror destination port information.
  • the network function virtualization orchestrator converts the flow mirroring policy information object into a Flow Classifier object, and then the network function virtualization orchestrator (NFVO) will Tapflow object, TapService
  • the object, the Flow Classifier object is assembled into a flow mirroring policy object, and the flow mirroring policy object is delivered to the virtualized infrastructure manager (VIM); the flow mirroring delivered by the network function virtualization orchestrator (NFVO) by the VIM
  • VIM virtualized infrastructure manager
  • the policy object is transmitted to the SDN network controller; the SDN network controller utilizes the automatic deployment of the SDN and the mirroring flow table issuing capability, and specifies a virtual eXtensible LANs (VXLAN) tunnel between the mirror source point and the mirror destination port.
  • VXLAN virtual eXtensible LANs
  • VNF virtual networking features
  • Step S30 The VNF is monitored according to the flow mirroring policy, and when a preset operation is detected, a corresponding management operation is performed.
  • the VNF After the traffic mirroring policy is deployed to the virtual network function (VNF), the VNF needs to be monitored according to the traffic mirroring policy in real time or periodically, and when a preset operation is detected, a corresponding management operation is performed. For example, after the virtual machine migration is detected, the traffic mirroring policy is automatically migrated to the new installed OVS (OpenvSwitch) virtual machine, and the traffic mirroring policy on the original computing node OVS is automatically revoked; When the VNF is scaled out, the traffic mirroring policy can be automatically associated with the traffic mirroring policy.
  • the traffic mirroring server receives the GTP (GPRS Tunnel Protocol) packet defined by the policy of the new virtual machine.
  • GTP GPRS Tunnel Protocol
  • the policy of the virtual machine in which the Scale In operation occurs will be suppressed, and the traffic mirror server will no longer receive the message defined by the policy of the virtual machine. After the traffic mirroring policy is deleted, the mirror source will not receive the packets corresponding to this policy.
  • the flow Mirroring policy information is first programmed in the Network Function Virtualization Orchestrator (NFVO) according to the received command, and then the traffic mirroring policy is created according to the traffic mirroring policy information. And the flow mirroring policy is deployed to the virtual network function (VNF), and then the VNF is monitored according to the traffic mirroring policy, and when the preset operation is detected, the corresponding management operation is performed, that is, the traffic mirroring policy is Following the life cycle changes of the virtual machine (such as the auto-elasticity of the virtual machine, the migration of the virtual machine, the rebirth of the virtual machine), the automatic association (ie, matching) takes effect, and no manual intervention is required.
  • NFVO Network Function Virtualization Orchestrator
  • the virtualization flow mirroring policy automation management method further includes: performing security verification on the flow mirroring policy before step S30.
  • the traffic mirroring policy is verified by security.
  • the manner of the verification may include, but is not limited to, at least one of the following: a hash, an encrypted hash, or data. signature.
  • the virtual machine flow mirroring can be securely verified, including, for example, verifying the source of the virtual machine flow image.
  • the verification of the source of the virtual machine flow mirroring may include: determining whether the virtual machine flow mirroring requested by the virtual machine flow mirroring access request is a virtual machine flow mirroring from the trusted party, if it is from a trusted The VNF is monitored according to the flow mirroring policy. If the VM mirroring is not performed from the trusted party, the VNF is not allowed to be monitored according to the traffic mirroring policy.
  • FIG. 2 is a flowchart of a virtualized flow mirroring policy automatic management method for performing a corresponding management operation when a preset operation is monitored according to an embodiment of the present disclosure. That is, as shown in FIG. 2, the step S30 may include: step S31, monitoring whether the operation of the VNF where the flow mirror source is located is a Scale Out operation or a Scale In operation; and step S32, when the VNF of the flow mirror source is detected. The operation occurs when the Scale Out operation is performed, and the new virtual machine is associated with the flow mirroring policy; and in step S33, when the operation of detecting the VNF of the flow mirroring source is Scale In operation, the Scale In is automatically generated. The traffic mirroring policy associated with the operated VM is deleted.
  • the preset operation may be a migration, deletion, or the like of the virtual machine. Therefore, when the scale out operation of the VNF where the flow mirror source is located is detected, the new virtual machine and the flow mirroring policy are performed.
  • the network function virtualization orchestrator NFVO
  • NFVO automatically associates the new virtual machine to the configured flow mirroring policy and updates the associated traffic mirroring policy to, for example, the Openstack cloud computing platform, and the Openstack cloud computing platform receives the NFVO synchronization/update
  • the flow mirroring policy automatically synchronizes the flow mirroring update information to the SDN controller.
  • the SDN controller automatically updates the flow table according to the configuration information of the traffic mirroring policy, and delivers the updated flow table to the switch.
  • the traffic mirroring server The GTP packet of the new virtual machine can be received normally, and the service analyzed by the new virtual machine mirrored message is analyzed;
  • the traffic mirroring policy associated with the virtual machine in which the Scale In operation occurs is automatically deleted.
  • the Network Function Virtualization Orchestrator NFVO
  • the flow mirroring policy of the virtual machine where the Scale In operation occurs is automatically deleted.
  • FIG. 3 is a flowchart of a virtualized flow mirroring policy automatic management method for performing a corresponding management operation when a preset operation is monitored, according to an embodiment of the present disclosure.
  • the virtualized flow mirroring policy automatic management method further includes: step S34, after step S33, updating the information of deleting the flow mirroring policy to the Openstack cloud computing platform and the SDN controller; and step S35, according to the The configuration information of the deleted traffic mirroring policy automatically updates the flow table and delivers the updated flow table to the switch.
  • the information of the deleted traffic mirroring policy may be further updated to the Openstack cloud computing platform, and the Openstack cloud computing platform receives the NFVO deletion flow mirroring policy.
  • the flow mirroring policy deletion information is updated to the SDN controller.
  • the SDN controller automatically updates the flow table according to the configuration information of the deleted traffic mirroring policy, and sends the updated flow table to the switch, thereby generating Scale In.
  • the traffic mirroring policy of the operating VM is suppressed.
  • the traffic mirroring server will not receive the packets defined by this VM policy.
  • FIG. 4 is a schematic structural diagram of a virtualized flow mirroring policy automatic management device according to an embodiment of the present disclosure, where the virtualized flow mirroring policy automatic management device is a hardware operation of a virtualized flow mirroring policy automatic management method according to an embodiment of the present disclosure surroundings.
  • the virtualization flow mirroring policy automation management device may include a processor 1001, such as a central processing unit (CPU); a network interface 1002; a user interface 1003; and a memory 1004.
  • the connection and communication between the processor 1001, the network interface 1002, the user interface 1003, and the memory 1004 can be implemented by a communication bus.
  • the network interface 1002 may include a standard wired interface (for connecting to a wired network), a wireless interface (such as a WI-FI interface, a Bluetooth interface, an infrared interface, etc. for connecting to a wireless network).
  • the user interface 1003 can include a display, an input unit such as a keyboard.
  • the user interface 1003 may also include a standard wired interface (eg, for connecting a wired keyboard, a wired mouse, etc.) and/or a wireless interface (eg, for connecting a wireless keyboard, a wireless mouse, etc.).
  • the memory 1004 may be a high speed RAM memory or a non-volatile memory such as a magnetic disk memory.
  • the memory 1004 may also be a remote storage device independent of the processor 1001, for example, connectable and communicable to the processor 1001 via a network or the like.
  • the virtualization flow mirroring policy automation management device may further include a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a WiFi module, and the like.
  • RF radio frequency
  • the structure of the virtualized flow mirroring policy automation management device shown in FIG. 4 does not constitute a limitation on the virtualized flow mirroring policy automation management device, and the virtualized flow mirroring policy automatic management device may include More or fewer components than those illustrated, or some of the components illustrated may be combined or arranged in different ways.
  • the memory 1004 as a computer readable storage medium may include an operating system, a network communication module, a user interface module, and a virtualized flow mirroring policy automation management program.
  • the operating system can be a combination of hardware and software resources for managing and controlling the virtualized flow mirroring policy automation management device, and supports the operation of the network communication module, the user interface module, the virtualized flow mirroring policy automation management program, and other software programs.
  • the network communication module can be configured to manage and control the network interface 1002.
  • the user interface module can be configured to manage and control the user interface 1003.
  • the network interface 1002 can be connected to a database for data communication with the database, and the user interface 1003 can be connected to the client (which can be understood as a client), and is performed with the client.
  • Data communication such as displaying information to the client through a window, or receiving operation information sent by the client
  • the processor 1001 may be configured to execute a virtualized flow mirroring policy automation management program stored in the memory 1004 to implement the following steps:
  • the instructions are configured to configure flow mirroring policy information in a network function virtualization orchestrator (NFVO); create a traffic mirroring policy according to the traffic mirroring policy information, and deploy the traffic mirroring policy to a virtual network function (VNF);
  • NFVO network function virtualization orchestrator
  • VNF virtual network function
  • the flow mirroring policy monitors the VNF and performs a corresponding management operation when a preset operation is detected.
  • the processor 1001 is further configured to execute a virtualized flow mirroring policy automation hypervisor stored in the memory 1004 to implement the step of: performing the flow mirroring policy before monitoring the VNF safety verification.
  • the processor 1001 is further configured to execute a virtualized flow mirroring policy automation management program stored in the memory 1004 to implement the following steps: monitoring whether the operation of the VNF where the flow mirroring source is located is a Scale Out operation or a Scale In Operation, when the operation of the VNF where the flow mirroring source is located is a Scale Out operation, the new virtual machine is associated with the flow mirroring policy, and when the operation of the VNF where the traffic mirror source is located is monitored as a Scale In operation, The traffic mirroring policy associated with the virtual machine where the Scale In operation occurred is automatically deleted.
  • a virtualized flow mirroring policy automation management program stored in the memory 1004 to implement the following steps: monitoring whether the operation of the VNF where the flow mirroring source is located is a Scale Out operation or a Scale In Operation, when the operation of the VNF where the flow mirroring source is located is a Scale Out operation, the new virtual machine is associated with the flow mirroring policy, and when the operation of the VNF where the traffic mirror source is located
  • the processor 1001 is further configured to execute a virtualized flow mirroring policy automation management program stored in the memory 1004 to implement the following steps: updating information of the deleted flow mirroring policy to the Openstack cloud computing platform and SDN control
  • the flow table is automatically updated according to the configuration information of the deleted traffic mirroring policy, and the updated flow table is delivered to the switch.
  • the processor 1001 is further configured to execute a virtualized flow mirroring policy automation hypervisor stored in the memory 1004 to implement the steps of orchestrating/configuring a flow mirroring policy source object, the flow mirroring policy source object
  • the destination object of the traffic mirroring policy includes the port type, switch ID, switch port ID, and network name of the destination service.
  • configuring/configuring a traffic mirroring policy rule object where the traffic mirroring policy rule object includes a source IP network segment, a destination IP network segment, an IP protocol type, a transport layer source port, and a transport layer destination port parameter.
  • Embodiments of the present disclosure also provide a computer readable storage medium storing one or more computer programs, the one or more computer programs being readable by one or more computers And executing, to implement the following steps: configuring flow mirroring policy information in a network function virtualization orchestrator (NFVO) according to the received instruction; creating a traffic mirroring policy according to the traffic mirroring policy information, and deploying the traffic mirroring policy to a virtual network function (VNF); and monitoring the VNF according to the flow mirroring policy, and performing a corresponding management operation when a preset operation is detected.
  • NFVO network function virtualization orchestrator
  • the one or more computer programs can be read and executed by the one or more computers to implement the step of: performing the flow mirroring policy prior to monitoring the VNF safety verification.
  • the one or more computer programs can be read and executed by the one or more computers to implement the steps of: monitoring whether the operation of the VNF where the flow mirror source is located is a Scale Out operation or a Scale In Operation, when the operation of the VNF where the flow mirroring source is located is a Scale Out operation, the new virtual machine is associated with the flow mirroring policy, and when the operation of the VNF where the traffic mirror source is located is monitored as a Scale In operation, The traffic mirroring policy associated with the virtual machine where the Scale In operation occurred is automatically deleted.
  • the one or more computer programs can be read and executed by the one or more computers to implement the steps of: updating the information of the deleted flow mirroring policy to the Openstack cloud computing platform and SDN control And automatically updating the flow table according to the configuration information of the flow mirroring policy, and delivering the updated flow table to the switch.
  • the one or more computer programs can be read and executed by the one or more computers to implement the steps of orchestrating/configuring a flow mirroring policy source object, the flow mirroring policy source object
  • the destination object of the traffic mirroring policy includes the port type, switch ID, switch port ID, and network name of the destination service.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Automation & Control Theory (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本公开提供了一种虚拟化流镜像策略自动化管理方法,所述方法包括以下步骤:根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息;根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。本公开还提供了一种虚拟化流镜像策略自动化管理设备及一种计算机可读存储介质。

Description

虚拟化流镜像策略自动化管理方法及设备、存储介质
相关申请的交叉引用
本申请要求于2017年10月9日提交的题为“虚拟化流镜像策略自动化管理的方法、设备及介质”的中国专利申请NO.201710941198.7的优先权,该中国专利申请的内容通过引用的方式全文合并于此。
技术领域
本公开涉及但不限于通信领域,尤其涉及虚拟化流镜像策略自动化管理方法及设备、计算机可读存储介质。
背景技术
在虚拟演进分组核心网(Virtualized Evolved Packet Core,vEPC)和网络功能虚拟化(Network Function Virtualization,NFV)/软件定义网络(Software Defined Network,SDN)场景下,为了满足运营商对用户信令进行分析的需求、以及客户自身业务发展和网络优化要求的大数据分析的需求,需要对在网流量提供镜像功能,可镜像的最大流量需要达到100Gbps。但是,基于NFV/SDN的流镜像功能是在网络功能虚拟化基础设施(Network Function Virtualization Infrastructure,NFVI)层提供镜像策略配置功能,利用NFVI层的镜像策略配置功能,在配置虚拟机流镜像策略后,该流镜像策略无法跟随虚拟机的自动弹性、虚拟机的迁移、虚拟机的重生等虚拟机的生命周期操作而自动匹配生效,需要人工再次干预才能生效。
公开内容
本公开提供一种虚拟化流镜像策略自动化管理方法,所述方法包括:根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜 像策略信息;根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
本公开还提供一种虚拟化流镜像策略自动化管理设备,所述虚拟化流镜像策略自动化管理设备包括处理器、网络接口、用户接口及存储器,所述存储器中存储有虚拟化流镜像策略自动化管理程序,所述处理器配置为执行所述虚拟化流镜像策略自动化管理程序,以实现以下步骤:根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息;根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
本公开还提供一种计算机可读存储介质,所述计算机可读存储介质上存储有虚拟化流镜像策略自动化管理程序,所述虚拟化流镜像策略自动化管理程序被计算机执行时实现如上所述的虚拟化流镜像策略自动化管理方法。
附图说明
图1为本公开的实施例的虚拟化流镜像策略自动化管理方法的流程图;
图2为本公开的实施例的虚拟化流镜像策略自动化管理方法在监测到预设操作时执行对应的管理操作的流程图;
图3为本公开的实施例的虚拟化流镜像策略自动化管理方法在监测到预设操作时执行对应的管理操作的流程图;以及
图4为本公开的实施例的虚拟化流镜像策略自动化管理设备的结构示意图。
具体实施方式
通过以下参照附图和实施例的进一步说明,本公开的技术方案的实现、功能特点及优点将变得清晰。
应当理解,所描述的具体实施例仅仅用以解释本公开,并不用于限定本公开。
本公开的实施例提出一种虚拟化流镜像策略自动化管理方法,首先根据接收到的指令在网络功能虚拟化编排器(Network Functions Virtualization Orchestrator,NFVO)编排流镜像策略信息,然后根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF),然后根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作,即流镜像策略可跟随虚拟机的生命周期变化而自动关联生效,不需要人工再次进行干预。
图1为本公开的实施例的虚拟化流镜像策略自动化管理方法的流程图。如图1所示,本公开的实施例的虚拟化流镜像策略自动化管理方法可包括以下步骤S10至S30。
步骤S10,根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息。
在本实施例中,通过NFVO对虚拟机的生命周期进行管理,因此,首先在网络功能虚拟化编排器(NFVO)编排流镜像策略信息。编排的对象包含流镜像源及相关配置、流镜像目的端口及相关配置。所述策略信息包括:流镜像策略源对象,所述流镜像策略源对象包括源云主机信息、源云主机端口、流方向类型及描述信息;流镜像策略目的对象,所述流镜像策略目的对象包括目的端口类型、交换机ID、交换机端口ID及网络名称;流镜像策略规则对象,所述流镜像策略规则对象包括源IP网段、目的IP网段、IP协议类型、传输层源端口及传输层目的端口参数。
步骤S20,根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF)。
在编排流镜像策略信息之后,可以根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF)。例如,网络功能虚拟化编排器(NFVO)查询流镜像源所在VNF对应的 虚拟机信息,将流镜像源对象向转换成Tapflow对象;网络功能虚拟化编排器(NFVO)查询流镜像目的端口信息,将流镜像目的端口对象转换成TapService对象;网络功能虚拟化编排器(NFVO)将流镜像的策略信息对象转换成Flow Classifier对象,然后所述网络功能虚拟化编排器(NFVO)将Tapflow对象、TapService对象、Flow Classifier对象组装成流镜像策略对象,将流镜像策略对象下发到虚拟化基础设施管理器(Virtualized Infrastructure Manager,VIM);VIM将网络功能虚拟化编排器(NFVO)下发的流镜像策略对象传送给SDN网络控制器;SDN网络控制器利用SDN的自动部署和镜像流表下发能力,指定镜像源点和镜像目的端口之间建立可扩展虚拟局域网(Virtual eXtensible LANs,VXLAN)隧道,向镜像源点下发流镜像过滤规则,向流镜像网关下发流镜像报文转发规则,即首先创建流镜像策略,然后将所述流镜像策略部署至虚拟网络功能(VNF),以便后续监测虚拟机是否发生迁移、删除等操作。
步骤S30,根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
在将所述流镜像策略部署至虚拟网络功能(VNF)之后,需要实时或定时根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。比如,当监测到虚拟机迁移后,将流镜像策略自动迁移到新的已安装OVS(OpenvSwitch)的虚拟机,并自动撤销原有计算节点OVS上的流镜像策略;当监控到流镜像源所在VNF发生Scale Out(即扩展)操作时,可以自动关联流镜像策略,流镜像服务器将收到新的虚拟机的策略所定义的GTP(GPRS Tunnel Protocol)报文;当监测到流镜像源所在VNF发生Scale In(即缩减)操作时,发生Scale In操作的虚拟机的策略将会被抑制,流镜像服务器将不会再收到这个虚拟机的策略所定义的报文。将流镜像策略删除后,镜像源将不会收到这个策略所对应的报文。
本实施例提出的虚拟化流镜像策略自动化管理方法中,首先根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息,然后根据所述流镜像策略信息创建流镜像策略,并将所述流镜像 策略部署至虚拟网络功能(VNF),然后根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作,即流镜像策略可跟随虚拟机的生命周期变化(例如虚拟机的自动弹性、虚拟机的迁移、虚拟机的重生)而自动关联(即匹配)生效,不需要人工再次进行干预。
在一些实施方式中,所述虚拟化流镜像策略自动化管理方法还包括:在步骤S30之前,对所述流镜像策略进行安全验证。
在该实施方式中,在对所述VNF进行监测之前,对所述流镜像策略进行安全验证,验证所采用的方式可以包括但不限于以下至少之一:散列、经过加密的散列或者数据签名。此外,在一些实施方式中,可对虚拟机流镜像进行安全验证,例如包括对虚拟机流镜像的来源进行验证。举例而言,对虚拟机流镜像的来源的验证可以包括:判断虚拟机流镜像访问请求所请求访问的虚拟机流镜像是否为来自于可信方的虚拟机流镜像,若为来自于可信方的虚拟机流镜像,则根据所述流镜像策略对所述VNF进行监测,若不为来自可信方的虚拟机流镜像,则不允许根据所述流镜像策略对所述VNF进行监测。通过对所述流镜像策略进行安全验证,保证了虚拟机流镜像在整个生命周期内的安全。
图2为本公开的实施例的虚拟化流镜像策略自动化管理方法在监测到预设操作时执行对应的管理操作的流程图。也就是说,如图2所示,所述步骤S30可包括:步骤S31,监测流镜像源所在VNF发生的操作是Scale Out操作,还是Scale In操作;步骤S32,当监测到流镜像源所在VNF发生的操作为Scale Out操作时,将新的虚拟机与所述流镜像策略进行关联;以及步骤S33,当监测到流镜像源所在VNF发生的操作为Scale In操作时,自动将与发生Scale In操作的虚拟机关联的流镜像策略删除。
在本实施例中,所述预设操作可以为虚拟机的迁移、删除等操作,因此,当监测到流镜像源所在VNF发生Scale Out操作时,将新的虚拟机与所述流镜像策略进行关联,例如,网络功能虚拟化编排器(NFVO)监测到流镜像源所在VNF发生Scale Out操作时,查询新的 虚拟机的信息,所述虚拟机的信息包括虚拟机所在网元类型、虚拟机类型、虚拟机的端口类型,然后NFVO将该新的虚拟机自动关联到已配置的流镜像策略并将关联的流镜像策略更新到例如Openstack云计算平台,Openstack云计算平台收到NFVO同步/更新流镜像策略的消息后自动将流镜像更新信息同步到SDN控制器,SDN控制器根据流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机,然后,流镜像服务器就可以正常接收到新的虚拟机的GTP报文,并对新的虚拟机镜像过来的报文进行业务分析;当监测到流镜像源所在VNF发生Scale In操作时,自动将与发生Scale In操作的虚拟机关联的流镜像策略删除,例如网络功能虚拟化编排器(NFVO)监测到流镜像源所在VNF发生Scale In操作时,自动将发生Scale In操作的虚拟机的流镜像策略删除。
图3为本公开的实施例的虚拟化流镜像策略自动化管理方法在监测到预设操作时执行对应的管理操作的流程图。如图3所示,所述虚拟化流镜像策略自动化管理方法还包括:步骤S34,在步骤S33之后,将删除流镜像策略的信息更新至Openstack云计算平台及SDN控制器;步骤S35,根据被删除的流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机。
也就是说,在将与发生Scale In操作的虚拟机关联的流镜像策略删除之后,可以进一步将删除流镜像策略的信息更新到Openstack云计算平台,Openstack云计算平台收到NFVO删除流镜像策略的消息后自动将流镜像策略删除信息更新到SDN控制器,SDN控制器根据被删除的流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机上,从而发生Scale In操作的虚拟机的流镜像策略被抑制,流镜像服务器将不会收到这个虚拟机策略所定义的报文。
图4为本公开的实施例的虚拟化流镜像策略自动化管理设备的结构示意图,所述虚拟化流镜像策略自动化管理设备即为本公开的实施例的虚拟化流镜像策略自动化管理方法的硬件运行环境。
如图4所示,所述虚拟化流镜像策略自动化管理设备可以包括:处理器1001,例如中央处理单元(CPU);网络接口1002;用户接口1003;以及存储器1004。处理器1001、网络接口1002、用户接口1003以及存储器1004之间的连接及通信可以通过通信总线实现。网络接口1002可以包括标准的有线接口(用于连接有线网络)、无线接口(如WI-FI接口、蓝牙接口、红外线接口等,用于连接无线网络)。用户接口1003可以包括显示屏(Display)、输入单元(比如键盘(Keyboard))。用户接口1003还可以包括标准的有线接口(例如用于连接有线键盘、有线鼠标等)和/或无线接口(例如用于连接无线键盘、无线鼠标等)。存储器1004可以是高速RAM存储器,也可以是非易失的存储器(non-volatile memory),例如磁盘存储器。存储器1004还可以是独立于处理器1001的远程存储装置,例如,可通过网络等与处理器1001连接及通信。
在一些实施方式中,所述虚拟化流镜像策略自动化管理设备还可以包括摄像头、射频(Radio Frequency,RF)电路、传感器、音频电路、WiFi模块等等。
本领域技术人员可以理解,图4中示出的虚拟化流镜像策略自动化管理设备的结构并不构成对虚拟化流镜像策略自动化管理设备的限定,所述虚拟化流镜像策略自动化管理设备可以包括比图示更多或更少的部件,或者图示的一些部件可组合或以不同的方式布置。
如图4所示,作为一种计算机可读存储介质的存储器1004可以包括操作系统、网络通信模块、用户接口模块以及虚拟化流镜像策略自动化管理程序。操作系统可以是管理和控制虚拟化流镜像策略自动化管理设备的硬件与软件资源的结合,支持网络通信模块、用户接口模块、虚拟化流镜像策略自动化管理程序以及其他软件程序的运行。网络通信模块可配置为管理和控制网络接口1002。用户接口模块可配置为管理和控制用户接口1003。
在图4所示的虚拟化流镜像策略自动化管理设备中,网络接口1002可连接至数据库,与数据库进行数据通信,用户接口1003可连接至客户端(可以理解为用户端),与客户端进行数据通信,如通过 窗口展示信息给客户端,或者接收客户端发送的操作信息,而处理器1001可以配置为执行存储器1004中存储的虚拟化流镜像策略自动化管理程序,以实现以下步骤:根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息;根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
在一些实施方式中,所述处理器1001还配置为执行存储器1004中存储的虚拟化流镜像策略自动化管理程序,以实现以下步骤:在对所述VNF进行监测之前,对所述流镜像策略进行安全验证。
在一些实施方式中,所述处理器1001还配置为执行存储器1004中存储的虚拟化流镜像策略自动化管理程序,以实现以下步骤:监测流镜像源所在VNF发生的操作是Scale Out操作还是Scale In操作,当监测到流镜像源所在VNF发生的操作为Scale Out操作时,将新的虚拟机与所述流镜像策略进行关联,当监测到流镜像源所在VNF发生的操作为Scale In操作时,自动将与发生Scale In操作的虚拟机关联的流镜像策略删除。
在一些实施方式中,所述处理器1001还配置为执行存储器1004中存储的虚拟化流镜像策略自动化管理程序,以实现以下步骤:将删除流镜像策略的信息更新至Openstack云计算平台及SDN控制器;根据被删除的流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机。
在一些实施方式中,所述处理器1001还配置为执行存储器1004中存储的虚拟化流镜像策略自动化管理程序,以实现以下步骤:编排/配置流镜像策略源对象,所述流镜像策略源对象包括源云主机信息、源云主机端口、流方向类型及描述信息;编排/配置流镜像策略目的对象,所述流镜像策略目的对象包括目的服务的端口类型、交换机ID、交换机端口ID及网络名称;以及编排/配置流镜像策略规则对象,所述流镜像策略规则对象包括源IP网段、目的IP网段、IP协议类型、传输层源端口及传输层目的端口参数。
本公开的实施例还提供了一种计算机可读存储介质,所述计算机可读存储介质存储有一个或者多个计算机程序,所述一个或者多个计算机程序可被一台或者多台计算机读取和执行,以实现以下步骤:根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息;根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
在一些实施方式中,所述一个或者多个计算机程序可被所述一台或者多台计算机读取和执行,以实现以下步骤:在对所述VNF进行监测之前,对所述流镜像策略进行安全验证。
在一些实施方式中,所述一个或者多个计算机程序可被所述一台或者多台计算机读取和执行,以实现以下步骤:监测流镜像源所在VNF发生的操作是Scale Out操作还是Scale In操作,当监测到流镜像源所在VNF发生的操作为Scale Out操作时,将新的虚拟机与所述流镜像策略进行关联,当监测到流镜像源所在VNF发生的操作为Scale In操作时,自动将与发生Scale In操作的虚拟机关联的流镜像策略删除。
在一些实施方式中,所述一个或者多个计算机程序可被所述一台或者多台计算机读取和执行,以实现以下步骤:将删除流镜像策略的信息更新至Openstack云计算平台及SDN控制器;以及根据流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机。
在一些实施方式中,所述一个或者多个计算机程序可被所述一台或者多台计算机读取和执行,以实现以下步骤:编排/配置流镜像策略源对象,所述流镜像策略源对象包括源云主机信息、源云主机端口、流方向类型及描述信息;编排/配置流镜像策略目的对象,所述流镜像策略目的对象包括目的服务的端口类型、交换机ID、交换机端口ID及网络名称;以及编排/配置流镜像策略规则对象,所述流镜像策略规则对象包括源IP网段、目的IP网段、IP协议类型、传输层源端口及传输层目的端口参数。
需要说明的是,本文中的术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括所列出的那些要素,而且还可包括没有明确列出的其他要素,或者还包括这些过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的过程、方法、物品或者装置,并不排除包括另外的与所列出的要素相同的要素。
通过以上的实施例及实施方式的描述,本领域的技术人员可以清楚地了解到本公开的实施例的方法可借助软件加通用硬件平台的方式来实现,当然也可以仅通过硬件实现。基于这样的理解,本公开的技术方案本质上或者说相对现有技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品可存储在存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令,这些指令被执行时可以使得终端设备(例如手机、计算机、服务器、空调器、或者网络设备等)执行本公开的实施例的方法。
以上仅为本公开的示例性实施例,并不限制本公开的保护范围,基于本公开的说明书及附图内容所作的等效结构变换或等效流程变换、或者直接或间接将本公开的技术方案运用在其他相关的技术领域均应视为落入本公开的保护范围内。

Claims (10)

  1. 一种虚拟化流镜像策略自动化管理方法,包括以下步骤:
    根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息;
    根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及
    根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
  2. 如权利要求1所述的虚拟化流镜像策略自动化管理方法,还包括:
    在对所述VNF进行监测之前,对所述流镜像策略进行安全验证。
  3. 如权利要求1所述的虚拟化流镜像策略自动化管理方法,其中,在监测到预设操作时执行对应的管理操作的步骤包括:
    监测流镜像源所在VNF发生的操作是扩展操作还是缩减操作;
    当监测到流镜像源所在VNF发生的操作为扩展操作时,将新的虚拟机与所述流镜像策略进行关联;以及
    当监测到流镜像源所在VNF发生的操作为缩减操作时,自动将与发生缩减操作的虚拟机关联的流镜像策略删除。
  4. 如权利要求3所述的虚拟化流镜像策略自动化管理方法,还包括:
    在自动将与发生缩减操作的虚拟机关联的流镜像策略删除的步骤之后,将删除流镜像策略的信息更新至Openstack云计算平台及软件定义网络(SDN)控制器;以及
    根据被删除的流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机。
  5. 如权利要求1所述的虚拟化流镜像策略自动化管理方法,其中,所述流镜像策略信息包括:
    流镜像策略源对象,所述流镜像策略源对象包括源云主机信息、源云主机端口、流方向类型及描述信息;
    流镜像策略目的对象,所述流镜像策略目的对象包括目的服务的端口类型、交换机ID、交换机端口ID及网络名称;以及
    流镜像策略规则对象,所述流镜像策略规则对象包括源IP网段、目的IP网段、IP协议类型、传输层源端口及传输层目的端口参数。
  6. 一种虚拟化流镜像策略自动化管理设备,包括处理器、网络接口、用户接口及存储器,所述存储器中存储有虚拟化流镜像策略自动化管理程序,所述处理器配置为执行所述虚拟化流镜像策略自动化管理程序,以实现以下步骤:
    根据接收到的指令在网络功能虚拟化编排器(NFVO)编排流镜像策略信息;
    根据所述流镜像策略信息创建流镜像策略,并将所述流镜像策略部署至虚拟网络功能(VNF);以及
    根据所述流镜像策略对所述VNF进行监测,并在监测到预设操作时,执行对应的管理操作。
  7. 如权利要求6所述的虚拟化流镜像策略自动化管理设备,其中,所述处理器还配置为执行所述虚拟化流镜像策略自动化管理程序,以实现以下步骤:
    在对所述VNF进行监测之前,对所述流镜像策略进行安全验证。
  8. 如权利要求6所述的虚拟化流镜像策略自动化管理设备,其中,所述处理器还配置为执行所述虚拟化流镜像策略自动化管理程序,以实现以下步骤:
    监控流镜像源所在VNF发生的操作是扩展操作还是缩减操作;
    当监控到流镜像源所在VNF发生的操作为扩展操作时,将新的 虚拟机与所述流镜像策略进行关联;以及
    当监测到流镜像源所在VNF发生的操作为缩减操作时,自动将与发生缩减操作的虚拟机关联的流镜像策略删除。
  9. 如权利要求8所述的虚拟化流镜像策略自动化管理设备,其中,所述处理器还配置为执行所述虚拟化流镜像策略自动化管理程序,以实现以下步骤:
    将删除流镜像策略的信息更新至Openstack云计算平台及SDN控制器;以及
    根据被删除的流镜像策略的配置信息自动更新流表,并将更新后的流表下发到交换机。
  10. 一种计算机可读存储介质,所述计算机可读存储介质上存储有虚拟化流镜像策略自动化管理程序,所述虚拟化流镜像策略自动化管理程序被计算机执行时实现如权利要求1至5中任一项所述的虚拟化流镜像策略自动化管理方法。
PCT/CN2018/109469 2017-10-09 2018-10-09 虚拟化流镜像策略自动化管理方法及设备、存储介质 WO2019072165A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
RU2019145122A RU2729406C1 (ru) 2017-10-09 2018-10-09 Способ и устройство для автоматического управления политикой зеркалирования виртуализиванного потока, а также носитель данных
EP18865925.4A EP3633920A1 (en) 2017-10-09 2018-10-09 Method and device for automatically managing virtualized flow mirroring policy, and storage medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201710941198.7A CN109639449B (zh) 2017-10-09 2017-10-09 虚拟化流镜像策略自动化管理的方法、设备及介质
CN201710941198.7 2017-10-09

Publications (1)

Publication Number Publication Date
WO2019072165A1 true WO2019072165A1 (zh) 2019-04-18

Family

ID=66050842

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/109469 WO2019072165A1 (zh) 2017-10-09 2018-10-09 虚拟化流镜像策略自动化管理方法及设备、存储介质

Country Status (4)

Country Link
EP (1) EP3633920A1 (zh)
CN (1) CN109639449B (zh)
RU (1) RU2729406C1 (zh)
WO (1) WO2019072165A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111782227A (zh) * 2020-06-30 2020-10-16 普联技术有限公司 一种组件的数据处理方法、装置、设备及存储介质
CN114788239A (zh) * 2019-12-02 2022-07-22 思科技术公司 网络功能虚拟化计算元件镜像升级
CN115865825A (zh) * 2022-12-01 2023-03-28 南京中孚信息技术有限公司 一种基于云计算的分布式全流量分析系统
WO2023213164A1 (zh) * 2022-05-06 2023-11-09 中兴通讯股份有限公司 流量采集规则的配置方法及其系统、存储介质

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113328871B (zh) * 2020-02-28 2022-08-12 中国移动通信有限公司研究院 信令采集的配置方法、装置及存储介质
CN111669284B (zh) * 2020-04-28 2023-02-28 长沙证通云计算有限公司 OpenStack自动化部署方法、电子设备、存储介质及系统
CN114428620A (zh) * 2020-10-29 2022-05-03 华为技术有限公司 一种数据流镜像方法及装置
CN113411351B (zh) * 2021-06-07 2023-06-27 中国人民解放军空军工程大学 基于NFV和深度学习的DDoS攻击弹性防御方法

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106161049A (zh) * 2015-03-27 2016-11-23 中兴通讯股份有限公司 一种实现网络服务部署规格配置的方法及装置
US20160364226A1 (en) * 2014-03-28 2016-12-15 Ntt Docomo, Inc. Update management system and update management method
WO2016204903A1 (en) * 2015-06-16 2016-12-22 Intel Corporation Technologies for secure personalization of a security monitoring virtual network function
CN106681789A (zh) * 2015-11-09 2017-05-17 中兴通讯股份有限公司 一种网络功能弹性授权的方法和装置
CN107251514A (zh) * 2015-02-04 2017-10-13 英特尔公司 用于虚拟化网络的可扩缩安全架构的技术

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8607299B2 (en) * 2004-04-27 2013-12-10 Microsoft Corporation Method and system for enforcing a security policy via a security virtual machine
CN103051497B (zh) * 2012-12-28 2016-04-13 华为技术有限公司 业务流镜像方法及镜像设备
EP3094049B1 (en) * 2014-01-29 2018-01-10 Huawei Technologies Co., Ltd. Method for upgrading virtualized network function and network function virtualization orchestrator
GB2529698B (en) * 2014-08-29 2021-05-26 Metaswitch Networks Ltd Packet recording
CN104699570B (zh) * 2015-03-30 2017-11-17 福州大学 一种虚拟桌面与物理桌面共用镜像的智能网络流桌面方法
CN106375384B (zh) * 2016-08-28 2019-06-18 北京瑞和云图科技有限公司 一种虚拟网络环境中镜像网络流量的管理系统和控制方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160364226A1 (en) * 2014-03-28 2016-12-15 Ntt Docomo, Inc. Update management system and update management method
CN107251514A (zh) * 2015-02-04 2017-10-13 英特尔公司 用于虚拟化网络的可扩缩安全架构的技术
CN106161049A (zh) * 2015-03-27 2016-11-23 中兴通讯股份有限公司 一种实现网络服务部署规格配置的方法及装置
WO2016204903A1 (en) * 2015-06-16 2016-12-22 Intel Corporation Technologies for secure personalization of a security monitoring virtual network function
CN106681789A (zh) * 2015-11-09 2017-05-17 中兴通讯股份有限公司 一种网络功能弹性授权的方法和装置

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114788239A (zh) * 2019-12-02 2022-07-22 思科技术公司 网络功能虚拟化计算元件镜像升级
CN111782227A (zh) * 2020-06-30 2020-10-16 普联技术有限公司 一种组件的数据处理方法、装置、设备及存储介质
WO2023213164A1 (zh) * 2022-05-06 2023-11-09 中兴通讯股份有限公司 流量采集规则的配置方法及其系统、存储介质
CN115865825A (zh) * 2022-12-01 2023-03-28 南京中孚信息技术有限公司 一种基于云计算的分布式全流量分析系统

Also Published As

Publication number Publication date
RU2729406C1 (ru) 2020-08-06
CN109639449B (zh) 2021-09-03
EP3633920A1 (en) 2020-04-08
CN109639449A (zh) 2019-04-16

Similar Documents

Publication Publication Date Title
WO2019072165A1 (zh) 虚拟化流镜像策略自动化管理方法及设备、存储介质
US11394689B2 (en) Application based network traffic management
US20200167149A1 (en) Cloud Service Automation of Common Image Management
US10445082B2 (en) Persistent mobile device enrollment
US10270648B2 (en) Configuration information management method, device, network element management system and storage medium
US9870580B2 (en) Network-as-a-service architecture
US9027077B1 (en) Deploying policy configuration across multiple security devices through hierarchical configuration templates
US9021005B2 (en) System and method to provide remote device management for mobile virtualized platforms
JP6466003B2 (ja) Vnfフェイルオーバの方法及び装置
US20190121631A1 (en) Deployment of applications to managed devices
CN109842694B (zh) 一种同步mac地址的方法、网络设备和计算机可读存储介质
JP6712670B2 (ja) ネットワークインフラストラクチャのエンドポイント設定に基づく動的な展開
US10846120B2 (en) Configuration tracking in virtualized computing environments
CN108039968B (zh) 网络优化方法、设备及计算机可读存储介质
JP2019153894A (ja) 通信制御装置、通信制御方法および通信制御プログラム
US20200296671A1 (en) Event-driven policy based management of wireless beacon and tag devices
US20210326353A1 (en) Incremental change and deploy
WO2021231694A1 (en) Methods and systems for managing computing virtual machine instances
US11757976B2 (en) Unified application management for heterogeneous application delivery
EP3832972B1 (en) Methods and systems for accessing a network
US11494218B2 (en) Server and method for controlling packet transmission
KR102019927B1 (ko) 네트워크 기능 가상화 운영 장치 및 방법
WO2018179448A1 (ja) 制御プログラム、制御方法及び制御装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18865925

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2018865925

Country of ref document: EP

Effective date: 20191230

NENP Non-entry into the national phase

Ref country code: DE