WO2019178756A1 - Sd-wan系统、sd-wan系统的使用方法及相关装置 - Google Patents

Sd-wan系统、sd-wan系统的使用方法及相关装置 Download PDF

Info

Publication number
WO2019178756A1
WO2019178756A1 PCT/CN2018/079701 CN2018079701W WO2019178756A1 WO 2019178756 A1 WO2019178756 A1 WO 2019178756A1 CN 2018079701 W CN2018079701 W CN 2018079701W WO 2019178756 A1 WO2019178756 A1 WO 2019178756A1
Authority
WO
WIPO (PCT)
Prior art keywords
wan
layer
network
access data
wan system
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/079701
Other languages
English (en)
French (fr)
Inventor
张永
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Cloudminds Shenzhen Robotics Systems Co Ltd
Original Assignee
Cloudminds Shenzhen Robotics Systems Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Cloudminds Shenzhen Robotics Systems Co Ltd filed Critical Cloudminds Shenzhen Robotics Systems Co Ltd
Priority to CN201880001213.2A priority Critical patent/CN108713309B/zh
Priority to PCT/CN2018/079701 priority patent/WO2019178756A1/zh
Publication of WO2019178756A1 publication Critical patent/WO2019178756A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/02Topology update or discovery
    • H04L45/04Interdomain routing, e.g. hierarchical routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • H04L41/145Network analysis or design involving simulating, designing, planning or modelling of a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks

Definitions

  • the present application relates to the field of communications technologies, and in particular, to an SD-WAN system, a method for using an SD-WAN system, and related devices.
  • Enterprise WAN Wide Area Network, WideArea Network, also known as Longhaulnetwor
  • TDM Time Division Multiplexing
  • MPLS multi-protocol label interaction, Multi- ProtocolLabelSwitching
  • WAN bandwidth is still very expensive, and it takes a long time to configure WAN services.
  • SD-WAN Software-Defined Wide Area Network, SoftwareDefinedWAN
  • SoftwareDefinedWAN is a company that offers a fast, low-cost deployment and is designed to help users reduce WAN expenses and increase their connectivity flexibility. , operators and communications equipment vendors are sought after.
  • the present application provides an SD-WAN system, a method of using the SD-WAN system, and related devices to solve the above technical problems.
  • An embodiment of the present application provides an SD-WAN system including: a virtual logical network layer, a physical network layer, a network interconnection layer, and a user layer; the virtual logical network layer is physically connected to the physical network layer, Communicating with the network interconnection layer; the network interconnection layer is physically connected to the physical network layer, and is in communication with the user layer; wherein, the network interconnection layer is configured to receive user layer access data to the physical network layer, and generate data according to the access data.
  • the access request is sent to the virtual logical network layer, and the access data is transferred to the physical network layer under the control of the virtual logical network layer; the virtual logical network layer is used to control the network interconnection layer to transmit the access data to the physical according to the access request.
  • Network layer
  • An embodiment of the present application provides a method for using an SD-WAN system.
  • the method for using the SD-WAN system is applied to a virtual logical network layer in any system embodiment of the present application, including: acquiring an SD-WAN system.
  • the layer transfers the access data to the physical network layer.
  • An embodiment of the present application further provides a method for using an SD-WAN system.
  • the method for using the SD-WAN system is applied to a network interconnection layer in any system embodiment of the present application, including: receiving an SD-WAN system.
  • User layer access data to the physical network layer in the SD-WAN system; generate access requests based on the access data, and send the access request to the virtual logical network layer in the SD-WAN system; under the control of the virtual logical network layer Access data is transferred to the physical network layer.
  • An embodiment of the present application provides an apparatus for using an SD-WAN system, where the apparatus for using the SD-WAN system is applied to a virtual logic network layer in any system embodiment of the present application, including: an acquisition module and a control module; a module for obtaining an access request sent by a network interconnection layer in an SD-WAN system; wherein the access request is accessed by a network interconnection layer according to a user layer in the SD-WAN system to a physical network layer in the SD-WAN system Data generation; a control module, configured to control the network interconnection layer to transmit the access data to the physical network layer according to the access request.
  • An embodiment of the present application further provides a device for using an SD-WAN system, where the device for using the SD-WAN system is applied to a network interconnection in any system embodiment of the present application, including: a receiving module, and a first sending module. And a second sending module, configured to receive access data of a user layer in the SD-WAN system to a physical network layer in the SD-WAN system; and a first sending module, configured to generate an access request according to the access data, and The access request is sent to the virtual logical network layer in the SD-WAN system; the second sending module is configured to transfer the access data to the physical network layer under the control of the virtual logical network layer.
  • An embodiment of the present application provides an electronic device including at least one processor; and a memory communicatively coupled to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being At least one processor is executed to enable at least one processor to perform the method of use of the SD-WAN system applied to the virtual logical network layer of the present application.
  • One embodiment of the present application provides a network interconnection device including at least one processor; and a memory communicatively coupled to the at least one processor; wherein the memory is stored for execution by the at least one processor The instructions are executed by at least one processor to enable at least one processor to perform the method of use of the SD-WAN system applied to the network interconnect layer of the present application.
  • An embodiment of the present application provides a computer readable storage medium storing computer instructions for causing a computer to execute the application of the present application to an SD-WAN system of a virtual logical network layer .
  • One embodiment of the present application provides a computer readable storage medium storing computer instructions for causing a computer to execute the application of the present application to an SD-WAN system of a network interconnection layer .
  • the embodiment of the present application deploys a virtual logical network layer on an existing physical network layer (ie, a WAN network), and sets a physical connection between the virtual logical network layer and the physical network layer, and the existing The network interconnection layer communicates with each other, so that when the network interconnection layer receives the access data of the user layer to the physical network layer, the network interconnection layer can generate an access request according to the access data, and send the access request to the virtual logical network layer, the virtual logical network. After receiving the access request, the layer can control the network interconnection layer to transmit the access data to the physical network layer according to the access request.
  • the WAN network is transformed into an SD-WAN network conveniently and quickly, and there is no need to replace the devices in the existing network interconnection layer.
  • FIG. 1 is a block diagram showing an SD-WAN system in a first embodiment of the present application
  • FIG. 2 is a block diagram showing an SD-WAN system in a second embodiment of the present application.
  • FIG. 3 is a schematic diagram of an SD-WAN system in a second embodiment of the present application.
  • FIG. 4 is a flow chart showing a method of using the SD-WAN system in the third embodiment of the present application.
  • FIG. 5 is a flowchart of a method of using an SD-WAN system in a fourth embodiment of the present application.
  • FIG. 6 is a flowchart of a method of using an SD-WAN system in a fifth embodiment of the present application.
  • FIG. 7 is a block diagram showing a device for using an SD-WAN system in a sixth embodiment of the present application.
  • FIG. 8 is a block diagram showing a device for using an SD-WAN system in a seventh embodiment of the present application.
  • FIG. 9 is a block diagram showing an electronic device in an eighth embodiment of the present application.
  • FIG. 10 is a block diagram showing a network interconnection device in a ninth embodiment of the present application.
  • the first embodiment of the present application relates to an SD-WAN system mainly comprising: a virtual logical network layer 101, a physical network layer 102, a network interconnect layer 103, and a user layer 104.
  • the virtual logical network layer 101 is physically connected to the physical network layer 102 and is in communication with the network interconnection layer 103.
  • the network interconnection layer 103 is physically connected to the physical network layer 102 and is in communication with the user layer 104.
  • the specific structure is as shown in FIG. Show.
  • the network interconnection layer 103 in the SD-WAN system is mainly used to receive access data of the user layer 104 to the physical network layer 102, and then generate an access request according to the received access data, and generate the generated access.
  • the request is sent to the virtual logical network layer 101 for processing, and then the access data is transferred to the physical network layer 102 under the control of the virtual logical network layer 101.
  • the virtual logical network layer 101 in the SD-WAN system is used to control the network interconnect layer 103 to transfer the access data to the physical network layer 102 according to the access request uploaded by the network interconnect layer 103.
  • the virtual logical network layer 101 specifically includes an SD-WAN controller 1011.
  • the SD-WAN controller 1011 is mainly configured to determine, according to an access request sent by the network interconnection layer 103, a routing policy (for determining access data from the user layer, which gateway device is to be redirected), According to the routing policy, the gateway device that controls the network interconnection layer 103 receiving the access data forwards the access data to other gateway devices, and the other gateway devices transmit the access data to the physical network layer 102.
  • routing policy in this embodiment may be generated by the SD-WAN controller 1011 according to the current network situation and the size of the access data, or may be generated in advance through a large amount of simulated data. Way, there is no limit here.
  • the SD-WAN controller 1011 referred to in the present application is only for indicating that the controller can control the entire SD-WAN system, and any device and program having the function can be used as a control in the SD-WAN system in practical applications. Device.
  • SD-WAN controller 1011 in the present application may be specifically deployed on a cloud server or a local server. Specifically, those skilled in the art may set the requirements as needed, and are not limited herein.
  • the SD-WAN controller 1011 in this embodiment is also used to control network interconnection, in order to ensure that the access data requested by the user layer 104 does not leak during the transmission process, thereby ensuring the security of the user information.
  • the gateway device that forwards and transmits the access data in layer 103 encrypts the access data.
  • the SD-WAN controller 1011 first determines whether the content in the access data involves user privacy or the like. When it is determined that encryption is required, a control command is generated to control the gateway device to access and transmit the access data in the network interconnection layer 103. Encrypt.
  • the encryption may be performed by encrypting only the access data, or encrypting the information of which gateway device is forwarded, so that the forwarded access data can only be received by the designated gateway device, thereby avoiding other gateway devices.
  • the device accessing the network steals the forwarded access data.
  • the physical network layer 102 is specifically a WAN network.
  • the WAN network is a WAN network that has been deployed and put into use by existing enterprises, vendors, and the like, and is not redeployed.
  • the network interconnection layer 103 specifically includes a plurality of gateway devices, which are specifically various gateway devices used in the existing WAN network system, such as an Internet Protocol "IP” router, a multi-protocol label interaction "MPLS", a packet optical switch, An Ethernet switch, etc., is not intended to implement a gateway device that is specifically customized for the SD-WAN system and is used with the SD-WAN controller 1011.
  • IP Internet Protocol
  • MPLS multi-protocol label interaction
  • An Ethernet switch etc.
  • FIG. 1 three gateway devices are taken as an example, and the first gateway device 1031 is separately distinguished for convenience.
  • the second gateway device 1032 and the third gateway device 1033 represent.
  • Any one of the gateway devices includes: a first WAN port, a second WAN port, and a third WAN port (the above three WAN ports are not shown in FIG. 1), and any one of the gateway devices passes through the first WAN port.
  • the SD-WAN controller communicates to form a logical control line, and any one of the gateway devices is physically connected to the physical network layer through the third WAN port to form a physical communication line, and any two gateway devices are connected through the second WAN port to form a logical forwarding. line.
  • logical control lines and logical forwarding lines can specifically pass GRE (Generic Routing Encapsulation Protocol, Generic) Routing Encapsulation, IPSec (Internet Connection Protocol, IP Security), VxLAN (Virtual Extensible Local Area Network), and other technical implementations, specific implementations, those skilled in the art can select according to needs, no restrictions here. .
  • GRE Generic Routing Encapsulation Protocol
  • Generic Generic Routing Encapsulation
  • IPSec Internet Connection Protocol, IP Security
  • VxLAN Virtual Extensible Local Area Network
  • the first WAN port specifically refers to an interface that establishes a logical control line with the SD-WAN controller.
  • the second WAN port specifically refers to an interface for forwarding access data with other gateway devices in the network interconnection layer 103, and any two gateway devices are communicably connected through the interface, so that any two gateway devices can be performed. Interconnection enables the gateway device that receives the access data to forward the access data to other gateway devices under the control of the SD-WAN controller, and the other gateway devices transmit the access data to the physical network layer 102.
  • the third WAN port specifically refers to an existing interface for data interaction with the WAN network, and is mainly used for transmitting the access data from the user layer 104 to the physical network layer 102 (ie, the WAN network).
  • the multiple gateway devices in the network interconnection layer 103 may be the same gateway device, or may be different, and are not limited herein.
  • the gateway devices in the network interconnection layer 103 in this embodiment can forward the access data to each other because the SD-WAN controller 1011 performs all the gateway devices in the network interconnection layer 103.
  • the compilation enables all gateway devices in the network interconnection layer 103 to have data forwarding attributes, such as compiling the attributes of the gateway device through an implant program.
  • the user layer 104 specifically includes a plurality of user terminals, such as a smart phone, a tablet computer, a notebook computer, a desktop computer, and a networked device among various workstations, and is not mentioned here.
  • user terminals such as a smart phone, a tablet computer, a notebook computer, a desktop computer, and a networked device among various workstations, and is not mentioned here.
  • three user terminals are taken as an example, and are respectively represented by a first user terminal 1041, a second user terminal 1042, and a third user terminal 1043 for convenience of distinction.
  • the physical connection (indicated by the solid line in FIG. 1) in the embodiment may be specifically connected by using a communication bus or an optical cable, and the communication connection (shown by a broken line in FIG. 1) ), specifically by using communication protocols such as BGP (Border Gateway Protocol, Border) Gateway Protocol) implements communication.
  • BGP Border Gateway Protocol
  • the SD-WAN system deploys a virtual logical network layer and sets virtual logic on the existing physical network layer (ie, WAN network) compared with the prior art.
  • the network layer is physically connected to the physical network layer and communicates with the existing network interconnection layer, so that when the network interconnection layer receives the access data of the user layer to the physical network layer, the network interconnection layer can generate an access request according to the access data, and The access request is sent to the virtual logical network layer, and after receiving the access request, the virtual logical network layer can control the network interconnection layer to transmit the access data to the physical network layer according to the access request.
  • the WAN network is transformed into an SD-WAN network conveniently and quickly, and there is no need to replace the devices in the existing network interconnection layer.
  • a second embodiment of the present application relates to an SD-WAN system.
  • the embodiment is further improved on the basis of the first embodiment.
  • the specific improvement is that the virtual logic network layer further includes an SD-WAN manager, and the specific structure is as shown in FIG. 2 .
  • the SD-WAN system in this embodiment includes an SD-WAN manager 1012 in the virtual logical network layer 101 in addition to the module shown in FIG.
  • the SD-WAN manager 1012 is physically connected to the SD-WAN controller 1011, and is mainly used for performing service scheduling on user terminals in the user layer 104.
  • the SD-WAN manager 1012 in this embodiment is further configured to control the SD-WAN controller to perform network monitoring on each gateway device in the network interconnection layer 103, and formulate a routing policy according to the access request generated by the access data.
  • the physical connection between the SD-WAN manager 1012 and the SD-WAN controller 1011 may be specifically connected through a communication bus or the like, and based on a network configuration protocol, such as the Netconf protocol, IPFIX ( IP data flow information output, IP Flow Information Export) protocol for communication.
  • a network configuration protocol such as the Netconf protocol, IPFIX ( IP data flow information output, IP Flow Information Export) protocol for communication.
  • the service scheduling performed by the SD-WAN manager 1012 on the user terminal in the user layer 104 may specifically generate corresponding compiling information after determining how many gateway devices are in the network interconnection layer 103 of the entire SD-WAN system.
  • Each of the gateway devices is compiled by the SD-WAN controller 1011, and when it is determined to which gateway device the access data is forwarded according to the access request, the specific service arrangement content can be set by the person skilled in the art as needed. Make restrictions.
  • the SD-WAN manager 1012 in the present application is only for indicating that the manager can implement the routing policy and the service scheduling operation for the user terminal. In practical applications, any device with the local function is required. Programs can be used as managers in SD-WAN systems.
  • SD-WAN manager 1012 described in this application may be specifically deployed on a cloud server or a local server. Specifically, those skilled in the art may set as needed, and are not limited herein.
  • the SD-WAN controller and the SD-WAN manager in the virtual logical network layer 101 may specifically be servers respectively deployed with corresponding functions.
  • the physical network layer 102 may be specifically composed of 4G/LTE (Telecom-known LTE network standard such as TD-LTE (Time Division Long Term Evolution) and FDD-LTE (Long Term Evolution)), MPLS, and broadband Internet.
  • 4G/LTE Telecom-known LTE network standard such as TD-LTE (Time Division Long Term Evolution) and FDD-LTE (Long Term Evolution)
  • MPLS Packet Control Protocol Secure Digital (G) network standard
  • broadband Internet broadband Internet.
  • gateway devices such as routers, switches, and connectors, are listed in the network interconnect layer 103.
  • the user terminal in the user layer 104 may specifically be a portable computer (laptop), a networkable device in the workstation, a host, or the like.
  • the SD-WAN system provided in this embodiment is determined by setting an SD-WAN manager physically connected to the SD-WAN controller in the virtual logical network layer as compared with the prior art.
  • the routing policy and the service orchestration of the user terminal are handled by the SD-WAN manager, which can alleviate the working pressure of the SD-WAN controller and enable the SD-WAN controller to access the user terminal in the SD-WAN system.
  • the gateway device in the network interconnection layer can also be quickly and accurately controlled.
  • the third embodiment of the present application relates to a method for using an SD-WAN system.
  • the method for using the SD-WAN system is mainly applied to a virtual logical network layer in an SD-WAN system, and the specific process is shown in FIG. 4 .
  • step 401 an access request sent by the network interconnect layer in the SD-WAN system is obtained.
  • the access request obtained in this embodiment is generated by the network interconnection layer according to the access data of the user layer in the SD-WAN system to the physical network layer in the SD-WAN system.
  • step 402 based on the access request, the control network interconnect layer transfers the access data to the physical network layer.
  • the control network interconnection layer transmits the access data to the physical network layer, which may be implemented as follows:
  • the routing policy is determined directly by the SD-WAN controller according to the access request. Then, the SD-WAN controller controls the gateway device that receives the access data in the network interconnection layer to forward the access data to the other gateway device according to the routing policy, and the other gateway device transmits the access data to the physical network layer.
  • the SD-WAN manager can directly submit the routing policy according to the access request. Alternatively, according to the current resource occupancy of the SD-WAN controller, if the access request cannot be processed in time, the SD-WAN manager processes it.
  • the SD-WAN manager When the routing policy is determined by the SD-WAN manager, the SD-WAN manager needs to control the SD-WAN controller to perform network monitoring on each gateway device in the network interconnection layer, and then formulate a routing policy according to the access request generated by the access data. .
  • both the SD-WAN controller and the SD-WAN manager can be implemented in the following manner, such as obtaining the current network status of the physical network layer, such as currently available in the idle gateway device and the gateway device.
  • the routing policy is determined according to network conditions and network requests.
  • the SD-WAN controller connects the network interconnection layer. All the gateway devices are compiled, so that all gateway devices in the network interconnection layer have data forwarding properties, such as compiling the properties of the gateway device through the implant program.
  • SD-WAN manager can also perform service orchestration for user terminals in the user layer, and the specific programming manner can be as follows:
  • the SD-WAN manager first acquires the information and the access request of the user terminal in the user layer, and then performs service scheduling on the user terminal in the user layer according to the information of the user terminal and the access request.
  • the method for using the SD-WAN system is to deploy a virtual logical network layer on an existing physical network layer (ie, a WAN network), and compared with the prior art.
  • the virtual logical network layer is physically connected to the physical network layer, so that when the gateway device requested by the user terminal in the user layer cannot satisfy the user request, the virtual logical network layer can control the gateway device to forward the access data to other working.
  • the gateway device, and the gateway device capable of working normally uploads the user's access data to the physical network layer in time, and while ensuring the user experience, the gateway device in the network interconnection layer is reasonably scheduled, so that the gateway device is obtained.
  • Dahua The use of Dahua.
  • a fourth embodiment of the present application relates to a method of using an SD-WAN system.
  • the embodiment is further improved on the basis of the third embodiment, and the specific improvement is: before controlling the network interconnection layer to transfer the access data to the physical network layer according to the access request, the network interconnection layer needs to be controlled first.
  • the gateway device that forwards and transmits the access data encrypts the access data, and the specific process is shown in FIG. 5.
  • the steps 501 and 503 are included, and the steps 501 and 503 are substantially the same as the steps 401 and 402 in the third embodiment, and are not described here.
  • the steps 501 and 503 are substantially the same as the steps 401 and 402 in the third embodiment, and are not described here.
  • the technical details that are not described in detail in this embodiment refer to the method for using the SD-WAN system provided by the third embodiment of the present application, or the SD-WAN system provided by any embodiment of the present application, where No longer.
  • step 502 the gateway device that controls the forwarding and transmission of access data in the network interconnect layer encrypts the access data.
  • the encryption operation is specifically controlled by an SD-WAN controller in the virtual logical network layer.
  • the SD-WAN controller first determines whether the content in the access data relates to user privacy, etc., and when determining that encryption is required, generates a control command, and controls the gateway device that forwards and transmits the access data in the network interconnection layer 103 to perform access data. encryption.
  • the encryption may be performed by encrypting only the access data, or encrypting the information of which gateway device is forwarded, so that the forwarded access data can only be received by the designated gateway device, thereby avoiding other gateway devices.
  • the device accessing the network steals the forwarded access data.
  • SD-WAN controller encrypts the access data by controlling the gateway device that forwards and transmits the access data in the network interconnection layer, thereby ensuring that the access data requested by the user terminal in the user layer does not leak during the transmission process, thereby ensuring the user information.
  • a fifth embodiment of the present application relates to a method of using an SD-WAN system.
  • the usage of the SD-WAN system is mainly applied to the network interconnection layer in the SD-WAN system, and the specific process is shown in FIG. 6.
  • step 601 access data of the user layer in the SD-WAN system to the physical network layer in the SD-WAN system is received.
  • step 602 an access request is generated based on the access data and the access request is sent to the virtual logical network layer in the SD-WAN system.
  • the operation of sending the access request to the virtual logical network layer in the SD-WAN system may be implemented in the following manner, for example, by using the first WAN port by the gateway device that receives the access data.
  • the request is sent to the virtual logical network layer, ie the access request is sent to the virtual logical network layer using a virtual logical control line established with the SD-WAN controller in the virtual path network layer.
  • step 603 the access data is transferred to the physical network layer under the control of the virtual logical network layer.
  • the transmission of the access data to the physical network layer under the control of the virtual logical network layer may be implemented in the following manner, such as the gateway device that sends the access request and the route determined according to the virtual logical network layer.
  • the policy uses the second WAN port to forward the access data to other gateway devices, and the third WAN port of the other gateway device uploads the access data to the physical network layer.
  • each gateway device of the network interconnection layer can be reasonably set by a person skilled in the art according to requirements. There are no restrictions here.
  • the existing physical network layer ie, the WAN network
  • the data forwarding attribute is provided, so that when the gateway device requested by the user terminal in the user layer cannot satisfy the user request, the access data requested by the user can be forwarded to other working gateways according to the control instruction of the virtual logical network layer.
  • the device and the gateway device capable of working normally upload the user's access data to the physical network layer in time, and while ensuring the user experience, the gateway device in the network interconnection layer is reasonably scheduled, so that the gateway device is greatly enlarged. Use.
  • a sixth embodiment of the present application relates to a device for using an SD-WAN system.
  • the device for using the SD-WAN system is mainly applied to a virtual logical network layer in an SD-WAN system, and the specific structure is as shown in FIG. 7.
  • the device for using the SD-WAN system mainly includes an acquisition module 701 and a control module 702.
  • the obtaining module 701 is configured to obtain an access request sent by a network interconnection layer in the SD-WAN system.
  • the control module 702 is configured to control the network interconnection layer to transmit the access data to the physical network layer according to the access request.
  • the access request is generated by the network interconnection layer according to the access data of the user layer in the SD-WAN system to the physical network layer in the SD-WAN system.
  • this embodiment is a virtual device embodiment corresponding to the method embodiment, and thus the technical details not described in detail in this embodiment, reference may be made to the application of the SD provided in any embodiment of the present application. - The method of using the SD-WAN system of the virtual logical network layer in the WAN system will not be described here.
  • the seventh embodiment of the present application relates to a device for using an SD-WAN system.
  • the device for using the SD-WAN system is mainly applied to a network interconnection layer in an SD-WAN system, and the specific structure is as shown in FIG. 8.
  • the device for using the SD-WAN system mainly includes: a receiving module 801, a first sending module 802, and a second sending module 803.
  • the receiving module 801 is configured to receive access data of a user layer in the SD-WAN system to a physical network layer in the SD-WAN system.
  • the first sending module 802 is configured to generate an access request according to the access data, and send the access request to the virtual logical network layer in the SD-WAN system.
  • the second sending module 803 is configured to transmit the access data to the physical network layer under the control of the virtual logical network layer.
  • the receiving module 801 when the second sending module 803 transmits the access data to the physical network layer, the receiving module 801 receives the control command issued by the virtual logical network layer, thereby implementing the virtual logic.
  • the access data is transferred to the physical network layer under the control of the network layer.
  • this embodiment is a virtual device embodiment corresponding to the method embodiment, and thus the technical details not described in detail in this embodiment, reference may be made to the application of the SD provided in any embodiment of the present application. - The method of using the SD-WAN system of the network interconnection layer in the WAN system will not be described here.
  • An eighth embodiment of the present application relates to an electronic device, and the specific structure is as shown in FIG.
  • the electronic device may specifically include at least one processor 901; and a memory 902 communicatively coupled to the at least one processor 901 and a communication component 903 that receives and/or transmits under the control of the processor 901. data.
  • the memory 902 stores instructions executable by the at least one processor 901, the instructions being executed by the at least one processor 901 to enable the at least one processor 901 to perform the application of the virtual logical network layer provided in any of the above embodiments. How to use the SD-WAN system.
  • the electronic device in this embodiment may specifically be any electronic device having the functions of an SD-WAN controller and an SD-WAN manager, such as a PC, or a server (the server may be local or a cloud server). Wait.
  • an SD-WAN controller and an SD-WAN manager such as a PC
  • the server may be local or a cloud server.
  • Wait a PC
  • the server may be local or a cloud server.
  • the ninth embodiment of the present application relates to a network interconnection device, and the specific structure is as shown in FIG.
  • the network interconnection device may specifically include at least one processor 1001; and a memory 1002 communicatively coupled to the at least one processor 1001 and a communication component 1003, and the communication component 1003 is received under the control of the processor 1001 and/or Or send data.
  • the memory 1002 stores instructions executable by the at least one processor 1001, the instructions being executed by the at least one processor 1001 to enable the at least one processor 1001 to perform the application of the network interconnection layer provided in any of the above embodiments. How to use the SD-WAN system.
  • the network interconnection device in this embodiment may be any gateway device, such as a router or a switch. Specifically, those skilled in the art can make reasonable choices according to needs, and are not listed here, nor are they specifically limited.
  • the processors in the eighth embodiment and the ninth embodiment may be a CPU (Central Processing Unit), and the memory may be a RAM (read/write memory, Random). Access Memory), the communication component can be a communication interface with communication functions, pins, and the like.
  • the processor and the memory may be connected by a bus or other means, and the bus connection is taken as an example in FIGS. 9 and 10.
  • the memory is a non-volatile computer readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs, and modules. As in the present application, the routing policy is stored in the memory.
  • the processor performs various functional applications and data processing of the device by running non-volatile software programs, instructions, and modules stored in the memory, that is, implementing the above-mentioned SD- applied to the virtual logical network layer in the SD-WAN system.
  • the memory may include a storage program area and a storage data area, wherein the storage program area may store an operating system, an application required for at least one function; the storage data area may store a list of options, and the like. Further, the memory may include a high speed random access memory, and may also include a nonvolatile memory such as at least one magnetic disk storage device, flash memory device, or other nonvolatile solid state storage device. In some embodiments, the memory optionally includes a memory remotely located relative to the processor, the remote memory being connectable to the external device over a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
  • One or more modules are stored in the memory, and when executed by one or more processors, perform the use of the SD-WAN system in any of the above method embodiments.
  • a tenth embodiment of the present application is directed to a computer readable storage medium, which is a computer readable storage medium having stored therein computer instructions that enable a computer to perform the above-described
  • a program instructing related hardware may be completed by a program instructing related hardware, and the program is stored in a storage medium, and includes a plurality of instructions for making a device (which may be a single chip microcomputer). , a chip, etc. or a processor performs all or part of the steps of the methods described in various embodiments of the present application.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请涉及通信技术领域,公开了一种SD-WAN系统、SD-WAN系统的使用方法及相关装置。本申请中,SD-WAN系统包括:虚拟逻辑网络层、物理网络层、网络互连层和用户层;虚拟逻辑网络层与物理网络层物理连接,与网络互连层通信连接;网络互连层与物理网络层物理连接,与用户层通信连接;其中,网络互连层,用于接收用户层对物理网络层的访问数据,将根据访问数据生成的访问请求发送给虚拟逻辑网络层,并在虚拟逻辑网络层的控制下将访问数据传送至物理网络层;虚拟逻辑网络层,用于根据访问请求,控制网络互连层将访问数据传送至物理网络层。该SD-WAN系统,实现了将现有的WAN改造为SD-WAN。

Description

SD-WAN系统、SD-WAN系统的使用方法及相关装置 技术领域
本申请涉及通信技术领域,特别涉及一种SD-WAN系统、SD-WAN系统的使用方法及相关装置。
背景技术
企业WAN(广域网,WideAreaNetwork,也称远程传输网(longhaulnetwor))已经从专用TDM(时分复用)电路转移到Packet-over-SONET(同步光纤网上分组数据)和MPLS(多协议标签交互,Multi-ProtocolLabelSwitching),而现在又转移到以太网接入服务。然而,在这个过程中有两件事情保持不变,那就是,WAN带宽仍然很昂贵,配置WAN服务需要很长时间。此外,WAN还面临很多方面的挑战,包括备份链路利用率、远程站点的安全性、流量工程、服务质量、非接触式配置以及流量可视性。而SD-WAN(软件定义广域网,SoftwareDefinedWAN)由于其提供了一种快速、低成本的部署方式,并且旨在帮助用户降低WAN的开支和提高其连接灵活性,能够有效解决上述问题,因而受到企业、运营商以及通讯设备商的追捧。
技术问题
但是,发明人发现现有技术中至少存在如下问题:虽然为企业部署SD-WAN能够大大降低WAN的开支,并且显著提高其连接的灵活性,但是直接舍弃现有的WAN系统,重新部署SD-WAN,一方面会导致现有WAN系统的浪费,另一方面由于现有的SD-WAN在部署过程中,需要采用配套的,甚至是相同生产厂商提供的SD-WAN控制器和具有流量转发功能的转发器,导致SD-WAN受设备的限制,并且重新部署SD-WAN,需要投入的大量的精力和物力。不论上述那种因素,都会严重增加企业的成本。
因此,提供一种将现有WAN改造为SD-WAN,并且无需限制SD-WAN控制器与转发器是否配套的方案显得尤为重要。
技术解决方案
本申请提供了一种SD-WAN系统、SD-WAN系统的使用方法及相关装置,以解决上述技术问题。
本申请的一个实施例提供了一种SD-WAN系统,该SD-WAN系统包括:虚拟逻辑网络层、物理网络层、网络互连层和用户层;虚拟逻辑网络层与物理网络层物理连接,与网络互连层通信连接;网络互连层与物理网络层物理连接,与用户层通信连接;其中,网络互连层,用于接收用户层对物理网络层的访问数据,将根据访问数据生成的访问请求发送给虚拟逻辑网络层,并在虚拟逻辑网络层的控制下将访问数据传送至物理网络层;虚拟逻辑网络层,用于根据访问请求,控制网络互连层将访问数据传送至物理网络层。
本申请的一个实施例提供了一种SD-WAN系统的使用方法,该SD-WAN系统的使用方法应用于本申请任意系统实施例中的虚拟逻辑网络层,包括:获取SD-WAN系统中的网络互连层发送的访问请求;其中,访问请求由网络互连层根据SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据生成;根据访问请求,控制网络互连层将访问数据传送至物理网络层。
本申请的一个实施例还提供了一种SD-WAN系统的使用方法,该SD-WAN系统的使用方法应用于本申请任意系统实施例中的网络互连层,包括:接收SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据;根据访问数据生成访问请求,并将访问请求发送给SD-WAN系统中的虚拟逻辑网络层;在虚拟逻辑网络层的控制下将访问数据传送至物理网络层。
本申请的一个实施例提供了一种SD-WAN系统的使用装置,该SD-WAN系统的使用装置应用于本申请任意系统实施例中的虚拟逻辑网络层,包括:获取模块和控制模块;获取模块,用于获取SD-WAN系统中的网络互连层发送的访问请求;其中,访问请求由网络互连层根据SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据生成;控制模块,用于根据访问请求,控制网络互连层将访问数据传送至物理网络层。
本申请的一个实施例还提供了一种SD-WAN系统的使用装置,该SD-WAN系统的使用装置应用于本申请任意系统实施例中的网络互连,包括:接收模块、第一发送模块和第二发送模块;接收模块,用于接收SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据;第一发送模块,用于根据访问数据生成访问请求,并将访问请求发送给SD-WAN系统中的虚拟逻辑网络层;第二发送模块,用于在虚拟逻辑网络层的控制下将访问数据传送至物理网络层。
本申请的一个实施例提供了一种电子设备,该电子设备包括至少一个处理器;以及与至少一个处理器通信连接的存储器;其中,存储器存储有可被至少一个处理器执行的指令,指令被至少一个处理器执行,以使至少一个处理器能够执行本申请应用于虚拟逻辑网络层的SD-WAN系统的使用方法。
本申请的一个实施例提供了一种网络互连设备,该网络互连设备包括至少一个处理器;以及与至少一个处理器通信连接的存储器;其中,存储器存储有可被至少一个处理器执行的指令,指令被至少一个处理器执行,以使至少一个处理器能够执行本申请应用于网络互连层的SD-WAN系统的使用方法。
本申请的一个实施例提供了一种计算机可读存储介质,该计算机可读存储介质存储有计算机指令,计算机指令用于使计算机执行本申请应用于虚拟逻辑网络层的SD-WAN系统的使用方法。
本申请的一个实施例提供了一种计算机可读存储介质,该计算机可读存储介质存储有计算机指令,计算机指令用于使计算机执行本申请应用于网络互连层的SD-WAN系统的使用方法。
有益效果
本申请实施例相对于现有技术而言,通过在现有的物理网络层(即WAN网络)上部署一个虚拟逻辑网络层,并设置虚拟逻辑网络层与物理网络层物理连接,与现有的网络互连层通信连接,从而使得网络互连层在接收到用户层对物理网络层的访问数据时,能够根据访问数据生成访问请求发,并将访问请求送给虚拟逻辑网络层,虚拟逻辑网络层在接收到该访问请求后,能够根据访问请求,控制网络互连层将访问数据传送至物理网络层。基于上述方式,方便、快捷的实现了将WAN网络改造为SD-WAN网络,并且无需替换现有网络互连层中的设备。
附图说明
一个或多个实施例通过与之对应的附图中的图片进行示例性说明,这些示例性说明并不构成对实施例的限定,附图中具有相同参考数字标号的元件表示为类似的元件,除非有特别申明,附图中的图不构成比例限制。
图1是本申请第一实施例中SD-WAN系统的方框示意图;
图2是本申请第二实施例中SD-WAN系统的方框示意图;
图3是本申请第二实施例中SD-WAN系统的示意图;
图4是本申请第三实施例中SD-WAN系统的使用方法的流程图;
图5是本申请第四实施例中SD-WAN系统的使用方法的流程图;
图6是本申请第五实施例中SD-WAN系统的使用方法的流程图;
图7是本申请第六实施例中SD-WAN系统的使用装置的方框示意图;
图8是本申请第七实施例中SD-WAN系统的使用装置的方框示意图;
图9是本申请第八实施例中电子设备的方框示意图;
图10是本申请第九实施例中网络互连设备的方框示意图。
本发明的实施方式
为了使本申请的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本申请部分实施例进行进一步详细说明。应当理解,此处所描述的具体实施例仅仅用以解释本申请,并不用于限定本申请。
本申请的第一实施例涉及一种SD-WAN系统,该SD-WAN系统主要包括:虚拟逻辑网络层101、物理网络层102、网络互连层103和用户层104。其中,虚拟逻辑网络层101与物理网络层102物理连接,与网络互连层103通信连接;网络互连层103与物理网络层102物理连接,与用户层104通信连接,具体结构如图1所示。
在实际应用中,该SD-WAN系统中的网络互连层103,主要用于接收用户层104对物理网络层102的访问数据,然后根据接收到的访问数据生成访问请求,并将生成的访问请求发送给虚拟逻辑网络层101进行处理,然后在虚拟逻辑网络层101的控制下将访问数据传送至物理网络层102。
SD-WAN系统中的虚拟逻辑网络层101则用于根据网络互连层103上传的访问请求,控制网络互连层103将访问数据传送至物理网络层102。
具体的说,在本实施例中,虚拟逻辑网络层101中具体包括SD-WAN控制器1011。
在本实施例中,SD-WAN控制器1011主要用于根据网络互连层103发送的访问请求,确定路由策略(用于决定来自用户层的访问数据,将要跳转到哪一个网关装置),并根据路由策略,控制网络互连层103中接收到访问数据的网关装置将访问数据转发至其他网关装置,由其他网关装置将访问数据传送至物理网络层102。
需要说明的是,本实施例中的路由策略,具体可以由SD-WAN控制器1011根据当前的网络情况以及访问数据的大小来生成,也可以是通过大量模拟数据,预先生成的,具体的确定方式,此处不做限制。
另外,本申请中所说的SD-WAN控制器1011只是为了表示该控制器能够管控整个SD-WAN系统,在实际应用中任何具备该功能的设备、程序都可以作为SD-WAN系统中的控制器。
另外,本申请中所说的SD-WAN控制器1011具体可以部署在云端服务器,或本地服务器上,具体的,本领域的技术人员可以根据需要设置,此处不做限制。
另外,值得一提的是,为了保证用户层104请求的访问数据在传输过程中不泄漏,进而保证了用户信息的安全,本实施例中的SD-WAN控制器1011还用于控制网络互连层103中转发及传输访问数据的网关装置对访问数据进行加密。
比如,由SD-WAN控制器1011先判断访问数据中的内容是否涉及用户隐私等,在确定需要加密时,生成控制命令,控制网络互连层103中转发及传输访问数据的网关装置对访问数据进行加密。
另外,加密的方式可以是仅设置对访问数据加密,也可以是对转发到哪一个网关装置的信息进行加密,这样转发的访问数据就只能由指定的网关装置接收,从而避免通过其他网关装置接入网络的设备盗取转发的访问数据。
需要说明的是,以上仅为举例说明,并不对本申请的技术方案和要保护的范围构成限定,本领域的技术人员可以根据需要进行设置,此处不做限制。
物理网络层102具体为WAN网络。在本实施例中该WAN网络为现有各个企业、厂商等已经部署并投入使用的WAN网络,并非重新部署。
网络互连层103具体包括若干个网关装置,该网关装置具体为现有WAN网络系统中使用的各种网关设备,如因特网协议“IP”路由器、多协议标签交互“MPLS”、分组光学交换机、以太网交换机等,并非为了实现SD-WAN系统专门定制的与SD-WAN控制器1011配套使用的网关设备,图1中以3个网关装置为例,并且为了方便区别分别以第一网关装置1031、第二网关装置1032和第三网关装置1033表示。
其中,任意一个网关装置包括:第一WAN口、第二WAN口和第三WAN口(上述3个WAN口,均未在图1中示出),并且任意一个网关装置通过第一WAN口与SD-WAN控制器通信连接,形成逻辑控制线路,任意一个网关装置通过第三WAN口与物理网络层物理连接,形成物理通信线路,任意两个网关装置通过第二WAN口通信连接,形成逻辑转发线路。
另外,上述逻辑控制线路和逻辑转发线路具体可以通过GRE (通用路由封装协议,Generic Routing Encapsulation)、IPSec(因特网连接协议,IP Security)、VxLAN(虚拟扩展局域网,Virtual Extensible Local Area Network)等技术实现,具体的实现方式,本领域的技术人员可以根据需要选择,此处不做限制。
为了便于理解本申请中,网关装置的工作原理,以下对上述三个WAN口进行具体说明:
在本实施例中,第一WAN口具体是指与SD-WAN控制器建立逻辑控制线路的接口。
第二WAN口具体是指与网络互连层103中的其他网关装置建立用于转发访问数据的接口,通过该接口将任意两个网关装置通信连接,使得任意两个网关装置之间都可以进行互连互通,从而能够使接收到访问数据的网关装置,在SD-WAN控制器的控制下,将访问数据转发至其他网关装置,由其他网关装置将访问数据传送至物理网络层102。
第三WAN口具体是指现有与WAN网络进行数据交互的接口,主要用于将来自用户层104的访问数据传送至物理网络层102(即WAN网络)。
需要说明的是,在实际应用中,网络互连层103中的多个网关装置可以为相同网关设备,也可以为不同的,此处不做限制。
另外,值得一提的是,本实施例中网络互连层103中的各个网关装置之所以可以相互转发访问数据,是因为SD-WAN控制器1011对网络互连层103中所有的网关装置进行了编译,使网络互连层103中所有的网关装置具备了数据转发属性,如通过植入程序对网关装置的属性进行编译。
用户层104具体包括若干个用户终端,如智能手机、平板电脑、笔记本电脑、台式机、各种工作站中能够连网的设备等,此处不再一一例举。图1中以3个用户终端为例,并且为了方便区别分别以第一用户终端1041、第二用户终端1042和第三用户终端1043表示。
另外,值得一提的是,本实施例中所说的物理连接(图1中采用实线表示)方式,具体可以是采用通信总线、光缆的方式进行连接,通信连接(图1中采用虚线表示)方式,具体可以是利用通信协议,如BGP(边界网关协议,Border Gateway Protocol)实现通讯。在实际应用中,本领域的技术人员可以根据需要合理选取连接方式,此处不做限制。
通过上述描述不难发现,与现有技术相比,本实施例中提供的SD-WAN系统,通过在现有的物理网络层(即WAN网络)上部署一个虚拟逻辑网络层,并设置虚拟逻辑网络层与物理网络层物理连接,与现有的网络互连层通信连接,从而使得网络互连层在接收到用户层对物理网络层的访问数据时,能够根据访问数据生成访问请求发,并将访问请求送给虚拟逻辑网络层,虚拟逻辑网络层在接收到该访问请求后,能够根据访问请求,控制网络互连层将访问数据传送至物理网络层。基于上述方式,方便、快捷的实现了将WAN网络改造为SD-WAN网络,并且无需替换现有网络互连层中的设备。
本申请的第二实施例涉及一种SD-WAN系统。本实施例在第一实施例的基础上做了进一步改进,具体改进之处为:虚拟逻辑网络层中还包括SD-WAN管理器,具体结构如图2所示。
如图2所示,本实施例中的SD-WAN系统除了包括图1中所示的模块之外,在虚拟逻辑网络层101中还包括SD-WAN管理器1012。
其中,SD-WAN管理器1012与SD-WAN控制器1011物理连接,主要用于对用户层104中的用户终端进行业务编排。
另外,本实施例中的SD-WAN管理器1012还用于控制SD-WAN控制器对网络互连层103中的各个网关装置进行网络监控,并根据访问数据生成的访问请求制定路由策略。
具体的说,在本实施例中SD-WAN管理器1012与SD-WAN控制器1011之间的物理连接,具体可以是通过通信总线等方式连通,并且基于网络配置协议,如Netconf协议、IPFIX(IP数据流信息输出,IP Flow Information Export)协议进行通讯。
另外,SD-WAN管理器1012对用户层104中的用户终端进行的业务编排,具体可以是在确定整个SD-WAN系统的网络互连层103中有多少网关装置后,生成对应的编译信息,由SD-WAN控制器1011对各个网关装置进行编译,以及在根据访问请求确定访问数据转发至哪一个网关装置时,具体的业务编排内容,本领域的技术人员可以根据需要进行设置,此处不做限制。
需要说明的是,本申请中所说的SD-WAN管理器1012只是为了表示该管理器能够实现路由策略的制定以及对用户终端的业务编排操作等,在实际应用中,任何局部该功能的设备、程序都可以作为SD-WAN系统中的管理器。
另外,本申请中所述的SD-WAN管理器1012具体可以部署在云端服务器,或本地服务器上,具体的,本领域的技术人员可以根据需要设置,此处不做限制。
为了对本申请中的SD-WAN系统有一个更加清楚、完整的理解,以下结合图3进行具体说明。
如图3所示,虚拟逻辑网络层101中的SD-WAN控制器和SD-WAN管理器具体可以是分别部署有相应功能的服务器。
物理网络层102具体可以是由4G/LTE(TD-LTE(分时长期演进)和FDD-LTE(长期演进技术)等LTE网络制式的统称)、MPLS以及宽带互联网等构成的。
网络互连层103中列举了几种常见的网关装置,如路由器、交换机、连接器。
用户层104中的用户终端具体可以是便携式电脑(笔记本电脑)、工作站中能够连网的设备、主机等。
需要说明的是,以上仅为举例说明,并不对本申请的技术方案和要保护的范围构成限定,本领域的技术人员可以根据需要进行设置,此处不做限制。
通过上述描述不难发现,与现有技术相比,本实施例中提供的SD-WAN系统,通过在虚拟逻辑网络层中设置与SD-WAN控制器物理连接的SD-WAN管理器,将确定路由策略、对用户终端进行业务编排的工作交由SD-WAN管理器进行处理,从而可以缓解SD-WAN控制器的工作压力,使得SD-WAN控制器在SD-WAN系统中接入用户终端较多,数据处理量较大的情况下,也可以快速、准确的控制网络互连层中的网关装置。
本申请的第三实施例涉及一种SD-WAN系统的使用方法,该SD-WAN系统的使用方法主要应用于SD-WAN系统中的虚拟逻辑网络层,具体流程如图4所示。
在步骤401中,获取SD-WAN系统中的网络互连层发送的访问请求。
具体的说,本实施例中获取到的访问请求是由网络互连层根据SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据生成的。
在步骤402中,根据访问请求,控制网络互连层将访问数据传送至物理网络层。
具体的说,在本实施例中,根据访问请求,控制网络互连层将访问数据传送至物理网络层,具体可以采用如下方式实现:
若虚拟逻辑网络层中仅有SD-WAN控制器时,直接由SD-WAN控制器根据访问请求,确定路由策略。然后,由SD-WAN控制器,根据路由策略,控制网络互连层中接收到访问数据的网关装置将访问数据转发至其他网关装置,由其他网关装置将访问数据传送至物理网络层。
若虚拟逻辑网络层中还包括SD-WAN管理器,则可以直接交由SD-WAN管理器根据访问请求,确定路由策略。或者,根据SD-WAN控制器当前的资源占用情况,在当前无法及时处理该访问请求的情况下,交由SD-WAN管理器处理。
在由SD-WAN管理器确定路由策略的时候,SD-WAN管理器需要控制SD-WAN控制器对网络互连层中的各个网关装置进行网络监控,然后根据访问数据生成的访问请求制定路由策略。
关于确定路由策略的方式,不论是SD-WAN控制器,还是SD-WAN管理器均可以采用如下方式实现,如先获取物理网络层当前的网络状况,如当前闲置的网关装置、网关装置中可用的数据传输关口、支持的带宽以及当前时刻带宽的占有率等。在获得上述信息后,根据网络状况和网络请求,确定路由策略了。
另外,为了使本实施例中网络互连层中的各个网关装置能够实现相互转发访问数据,需要在构建SD-WAN系统时,在进行数据转发之前,由SD-WAN控制器对网络互连层中所有的网关装置进行了编译,使网络互连层中所有的网关装置具备了数据转发属性,如通过植入程序对网关装置的属性进行编译。
另外,需要说明的是,SD-WAN管理器还可以对用户层中的用户终端进行业务编排,具体的编排方式可以如下所述:
SD-WAN管理器先获取用户层中的用户终端的信息和访问请求,然后根据用户终端的信息和访问请求,对用户层中的用户终端进行业务编排。
需要说明的是,以上仅为举例说明,并不对本申请的技术方案和要保护的范围构成限定,本领域的技术人员可以根据需要进行设置,此处不做限制。
通过上述描述不难发现,与现有技术相比,本实施例中提供的SD-WAN系统的使用方法,通过在现有的物理网络层(即WAN网络)上部署一个虚拟逻辑网络层,并设置虚拟逻辑网络层与物理网络层物理连接,从而可以在用户层中的的用户终端请求的网关装置无法满足用户请求时,虚拟逻辑网络层能控制该网关装置将访问数据转发到其他可以正常工作的网关装置,并由能够正常工作的网关装置及时将用户的访问数据上传到物理网络层,在保证用户体验的同时,对网络互连层中的网关装置进行了合理调度,使网关装置得到对大化的利用。
本申请的第四实施例涉及一种SD-WAN系统的使用方法。本实施例在第三实施例的基础上做了进一步改进,具体改进之处为:在根据访问请求,控制网络互连层将访问数据传送至物理网络层之前,需要先控制网络互连层中转发及传输访问数据的的网关装置对访问数据进行加密,具体流程如图5所示。
具体的说,在本实施例中,包含步骤501至步骤503,其中,步骤501和步骤503分别与第三实施例中的步骤401和步骤402大致相同,此处不再赘述,下面主要介绍不同之处,未在本实施例中详尽描述的技术细节,可参见本申请第三实施例所提供的SD-WAN系统的使用方法,或者本申请任意实施例所提供的SD-WAN系统,此处不再赘述。
在步骤502中,控制网络互连层中转发及传输访问数据的的网关装置对访问数据进行加密。
具体的说,该加密操作具体为由虚拟逻辑网络层中的SD-WAN控制器控制完成的。
比如,由SD-WAN控制器先判断访问数据中的内容是否涉及用户隐私等,在确定需要加密时,生成控制命令,控制网络互连层103中转发及传输访问数据的网关装置对访问数据进行加密。
另外,加密的方式可以是仅设置对访问数据加密,也可以是对转发到哪一个网关装置的信息进行加密,这样转发的访问数据就只能由指定的网关装置接收,从而避免通过其他网关装置接入网络的设备盗取转发的访问数据。
需要说明的是,以上仅为举例说明,并不对本申请的技术方案和要保护的范围构成限定,本领域的技术人员可以根据需要进行设置,此处不做限制。
通过上述描述不难发现,与现有技术相比,本实施例中提供的SD-WAN系统的使用方法,在根据访问请求,控制网络互连层将访问数据传送至物理网络层之前,SD-WAN控制器通过控制网络互连层中转发及传输访问数据的的网关装置对访问数据进行加密,从而保证了用户层中的用户终端请求的访问数据在传输过程中不泄漏,进而保证了用户信息的安全。
本申请的第五实施例涉及一种SD-WAN系统的使用方法。该SD-WAN系统的使用方法主要应用于SD-WAN系统中的网络互连层,具体流程如图6所示。
在步骤601中,接收SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据。
在步骤602中,根据访问数据生成访问请求,并将访问请求发送给SD-WAN系统中的虚拟逻辑网络层。
具体的说,在本实施例中,将访问请求发送给SD-WAN系统中的虚拟逻辑网络层的操作具体可以采用如下方式实现,如由接收到访问数据的网关装置利用第一WAN口将访问请求发送给虚拟逻辑网络层,即利用与虚拟路径网络层中的SD-WAN控制器建立的虚拟逻辑控制线路将访问请求发送给虚拟逻辑网络层。
在步骤603中,在虚拟逻辑网络层的控制下将访问数据传送至物理网络层。
具体的说,在本实施例中,在虚拟逻辑网络层的控制下将访问数据传送至物理网络层具体可以采用如下方式实现,如由发送访问请求的网关装置,根据虚拟逻辑网络层确定的路由策略,利用第二WAN口将访问数据转发至其他网关装置,由其他网关装置的第三WAN口,将访问数据上传至物理网络层。
需要说明的是,由于本实施例中提供的应用于网络互连层的SD-WAN系统的使用方法,需要与应用于虚拟逻辑网络层的SD-WAN系统的使用方法配合使用,因而未在本实施例中详尽描述的技术细节,可参见本申请任一实施例所提供的应用于SD-WAN系统中的网络互连层的SD-WAN系统的使用方法以及SD-WAN系统,此处不再赘述。
另外,需要说明的是,本实施例给出的仅为一种具体的实现方案,在实际应用中,网络互连层的各个网关装置的工作逻辑,本领域的技术人员可以根据需要合理设置,此处不做限制。
通过上述描述不难发现,与现有技术相比,本实施例中提供的SD-WAN系统的使用方法,现有的物理网络层(即WAN网络)根据新增的虚拟逻辑网络层的编译下,具备数据转发属性,从而可以在用户层中的的用户终端请求的网关装置无法满足用户请求时,能根据虚拟逻辑网络层的控制指令,将用户请求的访问数据转发到其他可以正常工作的网关装置,并由能够正常工作的网关装置及时将用户的访问数据上传到物理网络层,在保证用户体验的同时,对网络互连层中的网关装置进行了合理调度,使网关装置得到对大化的利用。
本申请的第六实施例涉及一种SD-WAN系统的使用装置,该SD-WAN系统的使用装置主要应用于SD-WAN系统中的虚拟逻辑网络层,具体结构如图7所示。
如图7所示,SD-WAN系统的使用装置主要包括:获取模块701和控制模块702。
其中,获取模块701,用于获取SD-WAN系统中的网络互连层发送的访问请求。控制模块702,用于根据访问请求,控制网络互连层将访问数据传送至物理网络层。
需要说明的是,在本实施例中,访问请求是由网络互连层根据SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据生成的。
另外,需要说明的是,由于本实施例为与方法实施例对应的虚拟装置实施例,因而未在本实施例中详尽描述的技术细节,可参见本申请任一实施例所提供的应用于SD-WAN系统中的虚拟逻辑网络层的SD-WAN系统的使用方法,此处不再赘述。
本申请的第七实施例涉及一种SD-WAN系统的使用装置,该SD-WAN系统的使用装置主要应用于SD-WAN系统中的网络互连层,具体结构如图8所示。
如图8所示,SD-WAN系统的使用装置主要包括接:接收模块801、第一发送模块802和第二发送模块803。
其中,接收模块801,用于接收SD-WAN系统中的用户层对SD-WAN系统中的物理网络层的访问数据。第一发送模块802,用于根据访问数据生成访问请求,并将访问请求发送给SD-WAN系统中的虚拟逻辑网络层。第二发送模块803,用于在虚拟逻辑网络层的控制下将访问数据传送至物理网络层。
需要说明的是,在本实施例中,第二发送模块803在将访问数据传送至物理网络层时,具体也是 由接收模块801来接收虚拟逻辑网络层下发的控制命令,从而实现在虚拟逻辑网络层的控制下将访问数据传送至物理网络层。
另外,需要说明的是,由于本实施例为与方法实施例对应的虚拟装置实施例,因而未在本实施例中详尽描述的技术细节,可参见本申请任一实施例所提供的应用于SD-WAN系统中的网络互连层的SD-WAN系统的使用方法,此处不再赘述。
另外,需要说明的是,以上所描述的装置实施例仅仅是示意性的,并不对本申请的保护范围构成限定,在实际应用中,本领域的技术人员可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的,此处不做限制。
本申请的第八实施例涉及一种电子设备,具体结构如图9所示。
具体的说,该电子设备内部具体可以包括至少一个处理器901;以及,与至少一个处理器901通信连接的存储器902以及通信组件903,通信组件903在处理器901的控制下接收和/或发送数据。其中,存储器902存储有可被至少一个处理器901执行的指令,指令被至少一个处理器901执行,以使至少一个处理器901能够执行上述任一实施例中提供的应用于虚拟逻辑网络层的SD-WAN系统的使用方法。
本实施例中所说的电子设备具体可以是具备SD-WAN控制器和SD-WAN管理器功能的任意电子设备,如PC机,或者服务器(该服务器可以是本地的,也可以是云端服务器)等。具体的,本领域的技术人员可以根据需要合理选择,此处不再一一列举,也不做具体限制。
需要说明的是,以上仅为举例,并不对本发明的技术方案和要保护的范围构成限定。
本申请的第九实施例涉及一种网络互连设备,具体结构如图10所示。
具体的说,该网络互连设备内部具体可以包括至少一个处理器1001;以及,与至少一个处理器1001通信连接的存储器1002以及通信组件1003,通信组件1003在处理器1001的控制下接收和/或发送数据。其中,存储器1002存储有可被至少一个处理器1001执行的指令,指令被至少一个处理器1001执行,以使至少一个处理器1001能够执行上述任一实施例中提供的应用于网络互连层的SD-WAN系统的使用方法。
本实施例中所说的网络互连设备具体可以是任意网关设备,如路由器、交换机等。具体的,本领域的技术人员可以根据需要合理选择,此处不再一一列举,也不做具体限制。
需要说明的是,以上仅为举例,并不对本发明的技术方案和要保护的范围构成限定。
另外,值得一提的是,在实际应用中,第八实施例和第九实施例中的处理器可以是CPU(中央处理器,Central Processing Unit),存储器可以是RAM(可读写存储器,Random Access Memory),通信组件可以是具有通信功能的通信接口、引脚等。另外,处理器、存储器可以通过总线或者其他方式连接,图9和图10中以通过总线连接为例。存储器作为一种非易失性计算机可读存储介质,可用于存储非易失性软件程序、非易失性计算机可执行程序以及模块,如本申请实施例中路由策略就存储于存储器中。处理器通过运行存储在存储器中的非易失性软件程序、指令以及模块,从而执行设备的各种功能应用以及数据处理,即实现上述应用于SD-WAN系统中的虚拟逻辑网络层的SD-WAN的使用方法,或者应用于SD-WAN系统中的网络互连层的SD-WAN的使用方法。
存储器可以包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需要的应用程序;存储数据区可存储选项列表等。此外,存储器可以包括高速随机存取存储器,还可以包括非易失性存储器,例如至少一个磁盘存储器件、闪存器件、或其他非易失性固态存储器件。在一些实施例中,存储器可选包括相对于处理器远程设置的存储器,这些远程存储器可以通过网络连接至外接设备。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
一个或者多个模块存储在存储器中,当被一个或者多个处理器执行时,执行上述任意方法实施例中的SD-WAN系统的使用方法。
上述产品可执行本发明实施例所提供的方法,具备执行方法相应的功能模块和有益效果,未在本实施例中详尽描述的技术细节,可参见本发明任意实施例中所提供的方法。
本申请的第十实施例涉及一种计算机可读存储介质,该可读存储介质为计算机可读存储介质,该计算机可读存储介质中存储有计算机指令,该计算机指令使计算机能够执行实现上述任一实施例中所描述的应用于SD-WAN系统中的虚拟逻辑网络层的SD-WAN的使用方法,或者应用于SD-WAN系统中的网络互连层的SD-WAN的使用方法。
本领域技术人员可以理解实现上述实施例方法中的全部或部分步骤是可以通过程序来指令相关的硬件来完成,该程序存储在一个存储介质中,包括若干指令用以使得一个设备(可以是单片机,芯片等)或处理器(processor)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
本领域的普通技术人员可以理解,上述各实施例是实现本申请的具体实施例,而在实际应用中,可以在形式上和细节上对其作各种改变,而不偏离本申请的精神和范围。

Claims (25)

  1. 一种SD-WAN系统,包括:虚拟逻辑网络层、物理网络层、网络互连层和用户层;
    所述虚拟逻辑网络层与所述物理网络层物理连接,与所述网络互连层通信连接;
    所述网络互连层与所述物理网络层物理连接,与所述用户层通信连接;
    其中,所述网络互连层,用于接收所述用户层对所述物理网络层的访问数据,将根据所述访问数据生成的访问请求发送给所述虚拟逻辑网络层,并在所述虚拟逻辑网络层的控制下将所述访问数据传送至所述物理网络层;
    所述虚拟逻辑网络层,用于根据所述访问请求,控制所述网络互连层将所述访问数据传送至所述物理网络层。
  2. 如权利要求1所述的SD-WAN系统,其中,所述网络互连层包括若干个网关装置;
    任意一个所述网关装置包括:第一WAN口、第二WAN口和第三WAN口;
    其中,任意一个所述网关装置通过所述第一WAN口与所述SD-WAN控制器通信连接,通过所述第三WAN口与所述物理网络层物理连接;
    任意两个所述网关装置通过所述第二WAN口通信连接。
  3. 如权利要求2所述的SD-WAN系统,其中,所述虚拟逻辑网络层具体包括:SD-WAN控制器;
    所述SD-WAN控制器,用于根据所述访问请求,确定路由策略,控制所述网络互连层中接收到所述访问数据的网关装置将所述访问数据转发至其他网关装置,由其他网关装置将所述访问数据传送至所述物理网络层。
  4. 如权利要求3所述的SD-WAN系统,其中,所述SD-WAN控制器,还用于对所述网络互连层中所有的网关装置进行编译,使所述网络互连层中所有的网关装置具备数据转发属性。
  5. 如权利要求3或4所述的SD-WAN系统,其中,所述SD-WAN控制器,还用于控制所述网络互连层中转发及传输所述访问数据的网关装置对所述访问数据进行加密。
  6. 如权利要求3至5任意一项所述的SD-WAN系统,其中,所述虚拟逻辑网络层还包括:SD-WAN管理器;
    所述SD-WAN管理器与所述SD-WAN控制器物理连接,用于对所述用户层中的用户终端进行业务编排。
  7. 如权利要求6所述的SD-WAN系统,其中,所述SD-WAN管理器,还用于控制所述SD-WAN控制器对所述网络互连层中的各个网关装置进行网络监控,并根据所述访问数据生成的访问请求制定所述路由策略。
  8. 如权利要求1至7任意一项所述的SD-WAN系统,其中,所述物理网络层为WAN网络。
  9. 一种SD-WAN系统的使用方法,应用于权利要求1至8任意一项所述的SD-WAN系统中的虚拟逻辑网络层;所述SD-WAN系统的使用方法包括:
    获取所述SD-WAN系统中的网络互连层发送的访问请求;其中,所述访问请求由所述网络互连层根据所述SD-WAN系统中的用户层对所述SD-WAN系统中的物理网络层的访问数据生成;
    根据所述访问请求,控制所述网络互连层将所述访问数据传送至所述物理网络层。
  10. 如权利要求9所述的SD-WAN系统的使用方法,其中,所述根据所述访问请求,控制所述网络互连层将所述访问数据传送至所述物理网络层,具体包括:
    所述虚拟逻辑网络层中的SD-WAN控制器根据所述访问请求,确定路由策略;
    所述SD-WAN控制器,根据所述路由策略,控制所述网络互连层中接收到所述访问数据的网关装置将所述访问数据转发至其他网关装置,由其他网关装置将所述访问数据传送至所述物理网络层。
  11. 如权利要求10所述的SD-WAN系统的使用方法,其中,所述根据所述访问请求,确定路由策略,具体包括:
    所述SD-WAN控制器获取所述物理网络层当前的网络状况;
    所述SD-WAN控制器根据所述网络状况和所述网络请求,确定所述路由策略。
  12. 如权利要求9至11任意一项所述的SD-WAN系统的使用方法,其中,在根据所述访问请求,控制所述网络互连层将所述访问数据传送至所述物理网络层之前,所述SD-WAN系统的使用方法还包括:
    所述SD-WAN控制器控制所述网络互连层中转发及传输所述访问数据的的网关装置对所述访问数据进行加密。
  13. 如权利要求9至12任意一项所述的SD-WAN系统的使用方法,其中,在根据所述访问请求,控制所述网络互连层将所述访问数据传送至所述物理网络层之前,所述SD-WAN系统的使用方法还包括:
    所述SD-WAN控制器对所述网络互连层中所有的网关装置进行编译,使所述网络互连层中所有的网关装置具备数据转发属性。
  14. 如权利要求9至13任意一项所述的SD-WAN系统的使用方法,其中,所述SD-WAN系统的使用方法还包括:
    所述虚拟逻辑网络层中的SD-WAN管理器对所述用户层中的用户终端进行业务编排。
  15. 如权利要求14所述的SD-WAN系统的使用方法,其中,所述SD-WAN管理器对所述用户层中的用户终端进行业务编排,具体包括:
    所述SD-WAN管理器获取所述用户层中的用户终端的信息和所述访问请求,并根据所述用户终端的信息和所述访问请求,对所述用户层中的用户终端进行业务编排。
  16. 如权利要求14或15所述的SD-WAN系统的使用方法,其中,所述SD-WAN管理器根据所述用户终端的信息和所述访问请求,对所述用户层中的用户终端进行业务编排之后,所述SD-WAN系统的使用方法还包括:
    所述SD-WAN管理器控制所述SD-WAN控制器对所述网络互连层中的各个网关装置进行网络监控,并根据所述访问数据生成的访问请求制定所述路由策略。
  17. 一种SD-WAN系统的使用方法,应用于权利要求1至8任意一项所述的SD-WAN系统中的网络互连层;所述SD-WAN系统的使用方法包括:
    接收所述SD-WAN系统中的用户层对所述SD-WAN系统中的物理网络层的访问数据;
    根据所述访问数据生成访问请求,并将所述访问请求发送给所述SD-WAN系统中的虚拟逻辑网络层;
    在所述虚拟逻辑网络层的控制下将所述访问数据传送至所述物理网络层。
  18. 如权利要求17所述的SD-WAN系统的使用方法,其中,所述将所述访问请求发送给所述SD-WAN系统中的虚拟逻辑网络层,具体包括:
    接收到所述访问数据的网关装置利用第一WAN口将所述访问请求发送给所述虚拟逻辑网络层。
  19. 如权利要求17或18所述的SD-WAN系统的使用方法,其中,所述在所述虚拟逻辑网络层的控制下将所述访问数据传送至所述物理网络层,具体包括:
    发送所述访问请求的网关装置,根据所述虚拟逻辑网络层确定的路由策略,利用第二WAN口将所述访问数据转发至其他网关装置,由所述其他网关装置的第三WAN口,将所述访问数据上传至所述物理网络层。
  20. 一种SD-WAN系统的使用装置,应用于权利要求1至8任意一项所述的SD-WAN系统中的虚拟逻辑网络层;所述SD-WAN系统的使用装置包括:获取模块和控制模块;
    所述获取模块,用于获取所述SD-WAN系统中的网络互连层发送的访问请求;其中,所述访问请求由所述网络互连层根据所述SD-WAN系统中的用户层对所述SD-WAN系统中的物理网络层的访问数据生成;
    所述控制模块,用于根据所述访问请求,控制所述网络互连层将所述访问数据传送至所述物理网络层。
  21. 一种SD-WAN系统的使用装置,应用于权利要求1至8任意一项所述的SD-WAN系统中的网络互连层;所述SD-WAN系统的使用装置包括:接收模块、第一发送模块和第二发送模块;
    所述接收模块,用于接收所述SD-WAN系统中的用户层对所述SD-WAN系统中的物理网络层的访问数据;
    所述第一发送模块,用于根据所述访问数据生成访问请求,并将所述访问请求发送给所述SD-WAN系统中的虚拟逻辑网络层;
    所述第二发送模块,用于在所述虚拟逻辑网络层的控制下将所述访问数据传送至所述物理网络层。
  22. 一种电子设备,包括:
    至少一个处理器;以及,
    与所述至少一个处理器通信连接的存储器;其中,
    所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器能够执行如权利要求9至16任意一项所述的SD-WAN系统的使用方法。
  23. 一种网络互连设备,包括:
    至少一个处理器;以及,
    与所述至少一个处理器通信连接的存储器;其中,
    所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器能够执行如权利要求17至19任意一项所述的SD-WAN系统的使用方法。
  24. 一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求9至16任意一项所述的SD-WAN系统的使用方法。
  25. 一种计算机可读存储介质,所述计算机可读存储介质中存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求17至19任意一项所述的SD-WAN系统的使用方法。
PCT/CN2018/079701 2018-03-21 2018-03-21 Sd-wan系统、sd-wan系统的使用方法及相关装置 Ceased WO2019178756A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201880001213.2A CN108713309B (zh) 2018-03-21 2018-03-21 Sd-wan系统、sd-wan系统的使用方法及相关装置
PCT/CN2018/079701 WO2019178756A1 (zh) 2018-03-21 2018-03-21 Sd-wan系统、sd-wan系统的使用方法及相关装置

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2018/079701 WO2019178756A1 (zh) 2018-03-21 2018-03-21 Sd-wan系统、sd-wan系统的使用方法及相关装置

Publications (1)

Publication Number Publication Date
WO2019178756A1 true WO2019178756A1 (zh) 2019-09-26

Family

ID=63873601

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/079701 Ceased WO2019178756A1 (zh) 2018-03-21 2018-03-21 Sd-wan系统、sd-wan系统的使用方法及相关装置

Country Status (2)

Country Link
CN (1) CN108713309B (zh)
WO (1) WO2019178756A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111726253A (zh) * 2020-06-18 2020-09-29 北京天润融通科技股份有限公司 云计算核心网络系统
CN113938383A (zh) * 2021-10-19 2022-01-14 广东奥飞数据科技股份有限公司 一种sd-wan集中策略管理方法
CN117729062A (zh) * 2024-02-07 2024-03-19 北京中核华辉科技发展有限公司 用于企业网络的组网方法、装置及系统

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109918109B (zh) * 2019-03-12 2022-07-19 赛特斯信息科技股份有限公司 针对sd-wan系统实现软件版本平滑升级功能的系统及方法
CN110611658B (zh) * 2019-08-20 2020-10-09 烽火通信科技股份有限公司 一种基于sd-wan的设备认证方法及系统
WO2021118717A1 (en) * 2019-12-12 2021-06-17 Vmware, Inc. Collecting an analyzing data regarding flows associated with dpi parameters
CN111148056B (zh) * 2020-04-03 2020-12-01 南京华智达网络技术有限公司 可运营网络配置方法及系统
US11296947B2 (en) 2020-06-29 2022-04-05 Star2Star Communications, LLC SD-WAN device, system, and network
CN112040170B (zh) * 2020-09-11 2023-02-28 国泰新点软件股份有限公司 基于5g的远程异地评标系统
CN114640626B (zh) * 2020-12-01 2023-07-18 中国联合网络通信集团有限公司 一种基于软件定义广域网sd-wan的通信系统和方法
CN114338500B (zh) * 2021-12-30 2023-10-31 北京青云科技股份有限公司 一种数据转发方法、装置、设备及存储介质
CN115426238A (zh) * 2022-06-02 2022-12-02 深圳市高德信通信股份有限公司 一种sd-wan系统及网络终端设备的远程管理方法和装置

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104506403A (zh) * 2014-12-05 2015-04-08 国云科技股份有限公司 一种支持多级隔离的虚拟网络管理方法
CN105391568A (zh) * 2014-09-05 2016-03-09 华为技术有限公司 一种软件定义网络sdn的实现方法、装置和系统
CN106534325A (zh) * 2016-11-24 2017-03-22 深圳市永达电子信息股份有限公司 一种铁路轨道交通的异构网络通信系统
CN106685730A (zh) * 2017-01-23 2017-05-17 郑州云海信息技术有限公司 一种配置管理与控制分离的sdn网络系统
CN106953848A (zh) * 2017-02-28 2017-07-14 浙江工商大学 一种基于ForCES的软件定义网络实现方法
US20170279722A1 (en) * 2016-03-23 2017-09-28 International Business Machines Corporation Load balancing with software defined network controllers

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105391568A (zh) * 2014-09-05 2016-03-09 华为技术有限公司 一种软件定义网络sdn的实现方法、装置和系统
CN104506403A (zh) * 2014-12-05 2015-04-08 国云科技股份有限公司 一种支持多级隔离的虚拟网络管理方法
US20170279722A1 (en) * 2016-03-23 2017-09-28 International Business Machines Corporation Load balancing with software defined network controllers
CN106534325A (zh) * 2016-11-24 2017-03-22 深圳市永达电子信息股份有限公司 一种铁路轨道交通的异构网络通信系统
CN106685730A (zh) * 2017-01-23 2017-05-17 郑州云海信息技术有限公司 一种配置管理与控制分离的sdn网络系统
CN106953848A (zh) * 2017-02-28 2017-07-14 浙江工商大学 一种基于ForCES的软件定义网络实现方法

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111726253A (zh) * 2020-06-18 2020-09-29 北京天润融通科技股份有限公司 云计算核心网络系统
CN111726253B (zh) * 2020-06-18 2023-10-17 北京天润融通科技股份有限公司 云计算核心网络系统
CN113938383A (zh) * 2021-10-19 2022-01-14 广东奥飞数据科技股份有限公司 一种sd-wan集中策略管理方法
CN117729062A (zh) * 2024-02-07 2024-03-19 北京中核华辉科技发展有限公司 用于企业网络的组网方法、装置及系统
CN117729062B (zh) * 2024-02-07 2024-05-28 北京中核华辉科技发展有限公司 用于企业网络的组网方法、装置及系统

Also Published As

Publication number Publication date
CN108713309A (zh) 2018-10-26
CN108713309B (zh) 2021-04-16

Similar Documents

Publication Publication Date Title
WO2019178756A1 (zh) Sd-wan系统、sd-wan系统的使用方法及相关装置
JP7641276B2 (ja) マルチテナントソフトウェア定義ワイドエリアネットワーク(sd-wan)ノードを提供するための方法、システム、およびコンピュータ読取可能媒体
CN114374581B (zh) 企业虚拟专用网络(vpn)与虚拟私有云(vpc)粘连
TWI521437B (zh) 用於網路的方法和系統
US11184267B2 (en) Intelligent in-band telemetry auto-configuration for IP networks
CN115918139A (zh) 网络切片的主动保证
US11748132B2 (en) Apparatus and method for configuring and enabling virtual applications
CN116366449A (zh) 在软件定义网络上的用户定制和自动化操作的系统和方法
US12052175B2 (en) Controlling a destination of network traffic
CN109088820B (zh) 一种跨设备链路聚合方法、装置、计算装置和存储介质
KR20120052981A (ko) 적어도 하나의 가상 네트워크를 온더플라이 및 온디맨드 방식으로 배치하는 방법 및 시스템
US20130014106A1 (en) Information processing apparatus, computer-readable medium storing information processing program, and management method
JP5866083B1 (ja) ソフトウェア定義ネットワークにおける制御方法、制御装置およびプロセッサ
US20220272156A1 (en) AUTOMATICALLY SCALING A NUMBER OF DEPLOYED APPLICATION DELIVERY CONTROLLERS (ADCs) IN A DIGITAL NETWORK
WO2015188331A1 (zh) 转发控制方法、驱动器及sdn网络
US9736027B2 (en) Centralized enterprise image upgrades for distributed campus networks
CN103607347A (zh) 建立传输通道的方法及控制器
JP5063726B2 (ja) 仮想ノード装置のコンフィグ制御方法
CN106817149A (zh) 一种基于电力线通信的信号控制方法及其服务器
CN116530130A (zh) 用于虚拟化服务的主动保证
CN116888940A (zh) 利用虚拟联网的容器化路由器
US12363073B1 (en) System and method for establishing cryptographically secure tunnels
US11609776B1 (en) Elastic internet protocol (IP) address for hypervisor and virtual router management in a branch environment
Jakovlev et al. Application of the OpenFlow protocol based on the mininet network emulator with the installation of a floodlight controller
de Cock Buning et al. Architecting Multi-Cluster Layer-2 Connectivity for Cloud Native Network Slicing

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18910536

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 21/01/2021)

122 Ep: pct application non-entry in european phase

Ref document number: 18910536

Country of ref document: EP

Kind code of ref document: A1