Summary of the invention
In view of this, first purpose of the present invention is to provide a kind of method that Customer Edge router CE is carried out local monitor, under the situation of other flow, can realize the monitoring to monitored CE neatly in not influencing MPLS L3VPN network.
Second purpose of the present invention is to provide a kind of routing device, under the situation of other flow, can realize the monitoring to monitored CE neatly in not influencing MPLS L3VPN network.
The 3rd purpose of the present invention is to provide a kind of method that Customer Edge router CE is carried out remote monitoring, under the situation of other flow, can realize the monitoring to monitored CE neatly in not influencing MPLS L3VPN network.
The 4th purpose of the present invention is to provide a kind of routing device, under the situation of other flow, can realize the monitoring to monitored CE neatly in not influencing MPLS L3VPN network.
The 5th purpose of the present invention is to provide a kind of routing device, under the situation of other flow, can realize the monitoring to monitored CE neatly in not influencing MPLS L3VPN network.
In order to achieve the above object, the technical scheme of the present invention's proposition is:
A kind of Customer Edge router CE is carried out the method for local monitor, be applied in three layers of MPLS VPN network MPLS L3VPN three-layer network, this method comprises:
By provider edge router PE is that monitoring CE is provided with specific next jumping that comprises local virtual dedicated network VPN_Local label, the outgoing interface of this specific next jumping is the interface of the local monitor CE of PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface;
Described PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
After described PE receives and comes and go to the message of monitored CE from common CE, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
Described PE receives behind the next message of monitoring CE, and message is forwarded to monitored CE or common CE.
After PE receives message, message is transmitted to monitoring CE comprises:
After PE receives message, be described packet labeling incoming interface attribute; To mark the message of incoming interface attribute carry out route querying, be its outgoing interface attribute of the packet labeling after the described route querying; To mark the message of incoming interface attribute and outgoing interface attribute judge, determine next jumping of this message.
A kind of routing device, be applied in three layers of MPLS VPN network MPLS L3VPN three-layer network, as provider edge router PE Customer Edge router CE is carried out local monitor, this routing device comprises: this locality is provided with unit, the first local retransmission unit, the second local retransmission unit and the 3rd local retransmission unit, wherein
Described this locality is provided with the unit, be used to monitoring CE that specific next jumping that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local monitor CE of PE, with incoming interface or outgoing interface is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first local retransmission unit, be used to receive behind the next message of monitored CE, according to the outgoing interface of the described incoming interface that the unit setting the is set message that is monitored CE interface for monitoring CE, with described message redirecting to be provided with the unit for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described second local retransmission unit, be used to receive come and go to the message of monitored CE from common CE after, according to the outgoing interface of the described outgoing interface that the unit setting the is set message that is monitored CE interface for monitoring CE, with described message redirecting to be provided with the unit for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described the 3rd local retransmission unit is used to receive behind the next message of monitoring CE, and message is forwarded to monitored CE or common CE.
A kind of method that Customer Edge router CE is carried out remote monitoring is applied in three layers of MPLS VPN network MPLS L3VPN three-layer network, and this method comprises:
Be respectively monitoring CE by monitoring provider edge router PE and monitored PE specific next jumping that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE; Is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, and the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE;
When monitored PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived specific next jumping that is provided with for monitoring CE, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
When monitored PE receive come from common CE and go to the message of monitored CE after, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived specific next jumping that is provided with for monitoring CE, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
When monitored PE receives behind the next message of monitoring CE, message is forwarded to monitored CE or common CE;
When monitoring PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
When the monitoring PE receive from common CE and go to the message of monitored CE after, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
After monitoring PE receives from monitoring CE and after going to the message of monitored CE, and message stamped the VPN_Local label, be forwarded to monitored PE, message be forwarded to monitored CE by monitored PE.
After monitored PE receives message, message is transmitted to monitoring CE comprises:
After monitored PE receives message, be described packet labeling incoming interface attribute; To mark the message of incoming interface attribute carry out route querying, and be the packet labeling outgoing interface attribute after the described route querying; To mark the message of incoming interface attribute and outgoing interface attribute judge, when determining the incoming interface of this message or outgoing interface and be monitored CE, this message routing is specific during next jumps to what be provided with for monitoring CE, and the outgoing interface by specific next jumping is forwarded to monitoring CE with message.
A kind of routing device, be applied in three layers of MPLS VPN network MPLS L3VPN three-layer network, as monitored provider edge router PE Customer Edge router CE is carried out remote monitoring, this routing device comprises long-range unit, the first long-range monitored retransmission unit, the second long-range monitored retransmission unit and the 3rd long-range monitored retransmission unit of being provided with, wherein
The described long-range unit that is provided with, be used to monitoring CE that specific next jumping that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE, and be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first long-range monitored retransmission unit, be used to receive behind the next message of monitored CE, according to the outgoing interface of the described long-range incoming interface that the unit setting the is set message that is monitored CE interface for monitoring CE, is specific next jumping that monitoring CE is provided with described message redirecting to the long-range unit that is provided with, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described second long-range monitored retransmission unit, be used to receive come and go to the message of monitored CE from common CE after, according to the outgoing interface of the described long-range outgoing interface that the unit setting the is set message that is monitored CE interface for monitoring CE, is specific next jumping that monitoring CE is provided with described message redirecting to the long-range unit that is provided with, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described the 3rd long-range monitored retransmission unit is used to receive behind the next message of monitoring CE, and message is forwarded to monitored CE or common CE.
A kind of routing device, be applied in three layers of MPLS VPN network MPLS L3VPN three-layer network, PE carries out remote monitoring to Customer Edge router CE as the monitoring provider edge router, this routing device comprises long-range unit, the first remote monitoring retransmission unit, the second remote monitoring retransmission unit and the 3rd remote monitoring retransmission unit of being provided with, wherein
The described long-range unit that is provided with, be used to monitoring CE that specific next jumping that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of local monitor CE, and the outgoing interface that will carry the message of VPN_Local label is arranged to monitor the interface of CE;
The described first remote monitoring retransmission unit, be used to receive behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described second remote monitoring retransmission unit, be used to receive come and go to the message of monitored CE from common CE after, according to the outgoing interface of the described long-range outgoing interface that the unit setting the is set message that is monitored CE interface for monitoring CE, with described message redirecting to described long-range be provided with that the unit is provided with for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
Described the 3rd remote monitoring retransmission unit, be used to receive from the monitoring CE and go to the message of monitored CE after, message stamped describedly long-rangely be forwarded to monitored PE after the VPN_Local label that the unit is provided with for monitoring CE is set, message is forwarded to monitored CE by monitored PE.
In sum, the method that CE is monitored of the present invention, by being respectively monitoring CE specific next jumping that comprises local virtual dedicated network (VPN_Local) label is set by monitoring PE and monitored PE, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE, thereby make message by monitored CE can only be redirected to specific next jump out among the local monitor CE of monitoring PE of interface correspondence, transmit again after CE handles it by monitoring, and when message need be forwarded to long-range monitored CE, message is delivered to monitored PE after being added the VPN_Local label, monitored PE bullet is carried out normal IP forwarding after falling label, message by other CE is then transmitted according to normal flow process, also promptly can be in not influencing MPLS L3VPN network under the situation of other flow, can realize monitoring neatly to monitored CE.
Embodiment
In order to solve problems of the prior art, the present invention proposes a kind of method of in MPLS L3VPN network, CE being monitored, promptly be respectively monitoring CE specific next jumping that comprises the VPN_Local label is set by monitoring PE and monitored PE, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE, thereby make message by monitored CE can only be redirected to specific next jump out among the local monitor CE of monitoring PE of interface correspondence, transmit again after CE handles it by monitoring, and when message need be forwarded to long-range monitored CE, message is delivered to monitored PE after being added the VPN_Local label, monitored PE bullet is carried out normal IP forwarding after falling label, then transmits according to normal flow process by the message of other CE.
For convenience, follow-uply will need monitored CE to be called monitored CE, the CE of the monitored CE of monitoring will be called monitoring CE, will remove the CE that monitors CE and the monitored CE and be called common CE.Simultaneously,, can carry out remote monitoring to CE again, and when CE was carried out local monitor, monitoring PE and monitored PE were same, the unified PE that is referred to as because the present invention both can carry out local monitor to CE; When CE is carried out remote monitoring, will be called monitored PE with the PE that monitored CE directly links to each other, will be called monitoring PE with the PE that monitoring CE directly links to each other, will be called common PE except that the CE monitoring PE and the monitored PE.
Based on above-mentioned introduction, the specific implementation of scheme of the present invention comprises:
When CE is carried out local monitor,
By PE is monitoring CE be provided with one comprise the VPN_Local label specific next jump, the outgoing interface of this specific next jumping is the interface of the local monitor CE of PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface;
Described PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
After described PE receives and comes and go to the message of monitored CE from common CE, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
Described PE receives behind the next message of monitoring CE, and message is forwarded to monitored CE or common CE.
When CE is carried out remote monitoring,
Be respectively monitoring CE by PE and monitored PE specific next jumping that comprises the VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE; Is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, and the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE;
When monitored PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived specific next jumping that is provided with for monitoring CE, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
When monitored PE receive come from common CE and go to the message of monitored CE after, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived specific next jumping that is provided with for monitoring CE, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
When monitored PE receives behind the next message of monitoring CE, message is forwarded to monitored CE or common CE;
When monitoring PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
When the monitoring PE receive from common CE and go to the message of monitored CE after, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, with described message redirecting to be provided with for monitoring CE specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
After monitoring PE receives from monitoring CE and after going to the message of monitored CE, and message stamped the VPN_Local label, be forwarded to monitored PE, message be forwarded to monitored CE by monitored PE.
For making the purpose, technical solutions and advantages of the present invention clearer, the present invention is described in further detail below in conjunction with the accompanying drawings and the specific embodiments.
Embodiment one
In the present embodiment, monitored CE is carried out local monitor, also promptly by with PE that monitored CE directly links to each other on other CE as monitoring CE, realize monitoring to monitored CE.
Be that example illustrates the specific implementation process of monitored CE being carried out local monitor with the described workflow that CE is monitored of Fig. 3 below, and this process is based on the described MPLS L3VPN of Fig. 1 basic network topology, when CE41 as monitored CE, CE40 is as monitoring CE, and when CE41 visit CE10, this flow process may further comprise the steps:
Step 301:CE41 sends to message among the PE4.
In this step, the source IP address that sends to the message of PE4 is the CE41 address, and purpose IP address is the CE10 address.
Need to prove, before carrying out this step, need for the monitoring CE in each VPN instance on it specific next jumping that comprises the VPN_Local label be set by PE4, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE, with incoming interface or outgoing interface is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that carries the message of VPN_Local label is arranged to monitor the interface of CE.Wherein, described specific next jump by static mode and generate and trigger without ARP, the outgoing interface of this specific next jumping is the interface of monitoring CE, the ARP index ARP index for monitoring CE, and carry out specific next when jumping the TTL in the header do not subtract 1.
After step 302-303:PE4 receives the message that is sent by CE41, message routing to specific next jumping, is sent to CE40 with message.
In this step, PE4 is specially message routing: at first, after PE4 receives message, be its incoming interface attribute of described packet labeling, show promptly that also this message sends over from CE41 after receiving the message that is sent by CE41 to specific next jumping; Secondly, this message carried out route querying after, be its outgoing interface attribute of described packet labeling, the outgoing interface that shows this message is CE10; Once more, to mark the message of incoming interface attribute and outgoing interface attribute judge, determine next jumping of described message, be specially: if message incoming interface attribute is monitored CE side, then message be redirected to into monitoring CE be provided with specific during next jumps; If the message outgoing interface is monitored CE side, and incoming interface is common CE side or common public network side, then message be redirected to into monitoring CE be provided with specific during next jumps; If the message incoming interface is monitoring CE, then message routing is in normal next jumping.
Need to prove, in this step, can distinguish this two kinds of different CE, be as the criterion with the realization that does not influence the embodiment of the invention in the reality for monitoring CE is provided with different signs respectively with monitored CE.
After step 304~305:CE40 receives message, message is correspondingly handled, thereby finished monitoring work, simultaneously, also need the message that receives is transmitted back PE4 again the message that sends by CE41.
In this step, CE40 handles message can be for duplicating portion with message, and the content of message after duplicating is resolved, and can also be as the criterion with the realization that does not influence the embodiment of the invention in the reality for other operation that message is handled.
Step 306:PE4 carries out route querying to the message that is returned by CE40 that receives, determine its next jump to behind the PE1, stamp the VPN private network tags and the public network tunnel label sends among the PE1.
PE4 receive the monitoring CE40 return message the time, this moment, the source IP and the purpose IP of message did not change, at this moment, PE4 does not carry out uRpf and checks, but directly inquire about the interior routing table of VPN, next is jumped to behind the PE1 to determine it, stamps normal VPN private network tags and public network tunnel label message is sent from specifying the public network interface.
Need to prove specifically how in message, to stamp the VPN private network tags and the public network tunnel label is a prior art, repeat no more here.
Step 307~308:PE1 receives the laggard walking along the street of message of PE4 transmission by searching, and next is jumped to behind the CE10 to determine it, and message is transmitted to CE10.
Carry VPN private network tags and public network tunnel label in the message by the PE4 transmission that PE1 receives, PE1 can fall VPN private network tags and the public network tunnel label that carries in the message by bullet before carrying out route querying.
In this step, how PE1 carries out route querying also is prior art, repeats no more here.
Step 309~310:CE10 handles the message by the PE1 transmission that receives, and produces response message, and described response message is transmitted to PE1.
CE10 can reply after receiving message to message, produces response message, and the purpose IP in the response message is the IP of CE41, and source IP is the IP of CE10.
Step 311~312:PE1 receives the laggard walking along the street of response message that sent by CE10 by searching, and next is jumped to behind the PE4 to determine it, is transmitted to PE4 after response message is stamped VPN private network tags and public network tunnel label.
Step 313~314:PE4 receives the laggard walking along the street of response message by searching, and it is routed to specific after next jumps, and response message is transmitted to CE40.
In this step, PE4 receives the laggard walking along the street of response message by searching, it is routed to specific next jumping is specially: carry VPN private network tags and public network tunnel label in the response message by the PE1 transmission that PE4 receives, before carrying out route querying, PE4 can fall VPN private network tags and the public network tunnel label that carries in the response message by bullet, afterwards, in the VPN routing table, carry out route querying, because purpose IP is the CE41 address in the response message header information at this moment, outgoing interface is monitored CE, incoming interface is common public network side, therefore the bullet response message that falls label is redirected to specific next jumping, its outgoing interface is CE40, TTL does not subtract one, the ARP index is the ARP index of CE40 equipment, and message is directly delivered to CE40.
After step 315~316:CE40 handles response message, finish monitoring work, simultaneously, response message is transmitted back PE4 the message that sends to CE41.
In this step, the concrete operations that CE40 handles response message repeat no more here with step 304~305.
Step 317:PE4 will be transmitted to CE41 after will being routed to next jumping by the response message that CE40 transmits back.
After CE41 receives response message, also need response message is carried out corresponding process operations, to realize visit work to CE10.
That so far, has finished promptly that present embodiment adopted carries out the whole workflow of local monitor to monitored CE.
Need to prove, in the present embodiment, on the one hand,, also just realized going out the monitoring of monitored CE41 because all messages that send from monitored CE41 all are forwarded to monitoring CE40 in advance; On the other hand, the destination address that sends from other all CE all is forwarded to monitoring CE40 in advance for all flows of monitoring CE41, has also realized going into the traffic monitoring of monitored CE41 equipment.And monitored CE, the IP header fields of the message that it receives such as purpose IP, source IP and TTL do not have to change, therefore for not influence of the upper layer application on the monitored CE.
Also it should be noted that, in the monitoring environment of local CE, to the quantity of monitored CE without limits, that is to say and allow a plurality of monitored CE on the PE4 equipment, the data traffic of a plurality of monitored CE is identical with single CE, and difference is that the outflow of a plurality of monitored CE and inbound traffics all can be forwarded to monitoring CE in advance.In addition, the flow in the MPLS L3VPN network between other non-monitoring CE is transmitted and is still continued to use original forward-path, is not subjected to the influence of monitored PE (PE that has connected monitored CE) and monitoring PE (PE that has been connected monitoring CE).
Based on said method, Fig. 4 has provided being applied in the MPLS L3VPN three-layer network that present embodiment adopted, CE is carried out the structural representation of the routing device of local monitor as PE, as shown in Figure 4, this routing device comprises: this locality is provided with unit 41, first local retransmission unit 42, second local retransmission unit 43 and the 3rd local retransmission unit 44, wherein
Described this locality is provided with unit 41, be used to monitoring CE that specific next jumping that comprises the VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local monitor CE of PE, with incoming interface or outgoing interface is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first local retransmission unit 42, be used to receive behind the next message of monitored CE, the outgoing interface that is the message of monitored CE according to the described incoming interface that unit 41 settings are set is the interface of monitoring CE, with described message redirecting to be provided with unit 41 for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described second local retransmission unit 43, be used to receive come and go to the message of monitored CE from common CE after, the outgoing interface that is the message of monitored CE according to the described outgoing interface that unit 41 settings are set is the interface of monitoring CE, with described message redirecting to be provided with unit 41 for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described the 3rd local retransmission unit 44 is used to receive behind the next message of monitoring CE, and message is forwarded to monitored CE or common CE.
So far, promptly having obtained of the present invention being used for carries out the routing device of local monitor as PE to CE, and the concrete workflow of routing device shown in Figure 4 can repeat no more here referring to the workflow of the described method of Fig. 3.
Embodiment two
In the present embodiment, monitored CE is carried out remote monitoring, also, realize monitoring monitored CE promptly by being different from CE on other PE that directly links to each other with monitored CE as monitoring CE.
Fig. 5 has provided the specific implementation process of monitored CE being carried out remote monitoring, the same with embodiment one, present embodiment also is based on the described MPLS L3VPN of Fig. 1 basic network topology, when CE41 as monitored CE, CE60 is as monitoring CE, similarly, when CE41 visit CE10, this flow process may further comprise the steps:
Step 501:CE41 sends to message among the PE4.
In this step, the source IP address that sends to the message of PE4 is the CE41 address, and purpose IP address is the CE10 address.
With the step 301 among the embodiment one, before carrying out this step, need be respectively CE60 by PE6 and PE4 specific next jumping that comprises the VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local CE60 of PE6, is the interface that the outgoing interface of the message of CE41 is arranged to CE60 by PE4 with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to the interface of CE60, and the outgoing interface that will carry the message of VPN_Local label by PE6 is arranged to the interface of CE60.Wherein, described specific next jumping generates by static mode and triggers without ARP, the outgoing interface of this specific next jumping for monitoring PE, be the local monitor CE60 interface of PE60, the ARP index that the ARP index is local monitor CE60, and carry out specific next when jumping the TTL in the header do not subtract 1.
After step 502~503:PE4 receives the message that CE41 sends, with message routing to specific next jump, and after getting access to specific next VPN_Local in jumping, will send to PE6 behind message packaging V PN_Local label and the public network tunnel label.
In this step, after PE4 receives the message of CE41 transmission, message routing is arrived specific next jumping, and the VPN_Local that gets access in specific next jumping is specially: at first, after PE4 receives message, specify the incoming interface attribute for described message, promptly incoming interface is monitored CE; Secondly, this message is carried out route querying, the outgoing interface of this message that finds is set to the outgoing interface of described message, and the outgoing interface that shows this message is CE10; Once more, the incoming interface and the outgoing interface of the message that added attribute are judged, determine this message relevant with monitored CE after, with message routing to specific during next jumps, and get access to specific next VPN_Local in jumping, at this moment, TTL do not subtract one and next jump and be PE6.
Bullet fell the VPN_Local label after step 504~505:PE6 received message, and message is sent to CE60.
Carried VPN_Local label and public network tunnel label in the message that PE6 receives, before PE6 transmits message, can fall VPN_Local label and the public network tunnel label that carries in the message by bullet by the PE4 transmission.
In this step, the data I P field of message is without any modification, and promptly source IP still is the IP address of CE41, and purpose IP still is the IP address of CE10.
After step 506~507:CE60 receives message, message is correspondingly handled, thereby finished monitoring work, simultaneously, the message that receives is transmitted back PE6 again the message that sends by CE41.
In this step, the operation that monitoring CE handles message repeats no more here with embodiment one.
Step 508:PE6 to next jumping, and sends to PE1 after message stamped VPN private network tags and public network tunnel label with message routing.
After PE2 receives the message that is returned by CE60, because the source IP address of message is the IP address of CE41, purpose IP address is the IP address of CE10, therefore, PE6 will carry out route querying, next is jumped to behind the PE10 to find out it, behind normal VPN private network tags and the public network tunnel label message is transmitted to PE1 in the encapsulation.
Specifically how in message, to stamp VPN private network tags and public network tunnel label and be prior art, repeat no more here.
Bullet fell the VPN private network tags after step 509~510:PE1 received the message that PE6 sends, and message is transmitted to CE10.
Carry VPN private network tags and public network tunnel label in the message that PE1 receives, before message is transmitted, can fall VPN private network tags and the public network tunnel label that carries in the message by bullet by the PE6 transmission.
Step 511~512:CE10 handles the message by the PE1 transmission that receives, and produces response message, and described response message is transmitted to PE1.
CE10 can reply after receiving message to message, produces response message, and the source IP address in the response message is the IP address of CE10, and purpose IP address is the IP address of CE41.
Step 513~514:PE1 receives the laggard walking along the street of response message that sent by CE10 by searching, and next is jumped to behind the PE4 to determine it, is transmitted to PE4 after response message is stamped VPN private network tags and public network tunnel label.
Step 515:PE4 carries out route querying with response message, with its be routed to specific next jump, get access to specific next VPN_Local in jumping after, the VPN_Local label is gone up in the response message encapsulation and the public network tunnel label sends to PE6.
In this step, the response message that PE4 receives carries VPN label and public network tunnel label, need bullet to fall VPN label and the laggard walking along the street of public network tunnel label by searching, because purpose IP address is that CE41, outgoing interface are monitored CE, therefore response message is routed to specific next jumping, from this specific next jump the VPN_Local label, TTL do not subtract one and next jump to behind the PE6, response message packaging V PN_Loacl label and public network tunnel label are sent to PE6.
Bullet fell the VPN_Loacl label after step 516~517:PE6 received response message, and response message is transmitted to CE60.
After step 518~519:CE60 handles response message, finish monitoring work, simultaneously, response message is transmitted back PE6 the message that sends to CE41.
In this step, the concrete operations that CE60 handles response message repeat no more here with step 506~507.
Step 520:PE6 will carry out route querying by the response message that CE60 transmits back, and send to PE4 after it is stamped VPN_Local label and public network tunnel label.
In this step, after PE6 receives the message of monitoring CE transmission, directly carry out route querying, after purpose IP address in the discovery response message is the IP address of CE41, because the purpose IP address in the message is the IP address of CE41, next jumps its public network and to be monitored PE, so the private network tags of message is arranged to the VPN_Local label, is about to send to PE4 after response message is stamped VPN_Local label and public network tunnel label.
Step 521:PE4 will be transmitted to CE41 by the response message that PE6 transmits.
PE4 receives the response message that is sent by PE6 and carries the VPN_Local label, bullet falls the laggard walking along the street of label by searching, find its next jumping and be CE41, because message carries the VPN_Local label, PE4 is provided with the message incoming interface and is monitoring CE side, and directly carry out normal IP routing operations, message is transmitted to CE41.
After CE41 receives response message, also need response message is carried out corresponding process operations, to realize visit work to CE10.
So far, the whole workflow that monitored CE is carried out remote monitoring of having finished promptly that present embodiment adopted.
Need to prove that in the present embodiment, on the one hand, all messages that send from monitored CE41 all are forwarded to monitoring PE in advance on monitored PE, be forwarded to monitoring CE60, the traffic monitoring that has realized monitored CE41 by monitoring PE; On the other hand, the destination address that sends from other all CE is after all flows of CE41 are sent to the monitored PE of purpose, all is forwarded to monitoring PE in advance, and is transmitted to monitoring CE60 by monitoring PE, has realized going into the traffic monitoring of monitored CE41.And for monitored CE, the IP header fields of the message that it receives does not change as purpose IP, source IP and TTL etc., therefore for not influence of the upper layer application on the monitored CE.
Based on said method, present embodiment adopted is used for CE being carried out the structural representation of routing device of remote monitoring respectively referring to Fig. 6 and Fig. 7 as monitored PE and monitoring PE, as shown in Figure 6, be used for comprising: long-range unit 61, first long-range monitored retransmission unit 62, second long-range monitored retransmission unit 63 and the 3rd long-range monitored retransmission unit 64 that be provided with as the routing device of monitored PE, wherein
The described long-range unit 61 that is provided with, be used to monitoring CE that specific next jumping that comprises the VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE, and be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first long-range monitored retransmission unit 62, be used to receive behind the next message of monitored CE, long-range what be provided with that unit 61 is provided with is that the outgoing interface of the message of monitored CE is the interface of monitoring CE by incoming interface according to described, is specific next jumping that monitoring CE is provided with described message redirecting to the long-range unit 61 that is provided with, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described second long-range monitored retransmission unit 63, be used to receive come and go to the message of monitored CE from common CE after, the outgoing interface that is the message of monitored CE according to the described long-range outgoing interface that unit 61 settings are set is the interface of monitoring CE, is specific next jumping that monitoring CE is provided with described message redirecting to the long-range unit 61 that is provided with, after obtaining described specific next VPN_Local label in jumping, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described the 3rd long-range monitored retransmission unit 64 is used to receive behind the next message of monitoring CE, and message is forwarded to monitored CE or common CE.
So far, promptly obtained the structural representation that is used for CE being carried out the routing device of remote monitoring of the present invention as monitored PE.
Fig. 7 is described to be used for as monitoring PE the routing device that CE carries out remote monitoring being comprised: long-range unit 71, the first remote monitoring retransmission unit 72, the second remote monitoring retransmission unit 73 and the 3rd remote monitoring retransmission unit 74 of being provided with, wherein,
The described long-range unit 71 that is provided with, be used to monitoring CE that specific next jumping that comprises the VPN_Local label is set, the outgoing interface of this specific next jumping is the interface of local monitor CE, and the outgoing interface that will carry the message of VPN_Local label is arranged to monitor the interface of CE;
The described first remote monitoring retransmission unit 72, be used to receive behind the next message of monitored CE, the outgoing interface that is the message of monitored CE according to the described long-range incoming interface that unit 71 settings are set is the interface of monitoring CE, with described message redirecting to described long-range be provided with unit 71 for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
The described second remote monitoring retransmission unit 73, be used to receive come and go to the message of monitored CE from common CE after, the outgoing interface that is the message of monitored CE according to the described long-range outgoing interface that unit 71 settings are set is the interface of monitoring CE, with described message redirecting to described long-range be provided with unit 71 for monitoring CE be provided with specific next jump, the outgoing interface by specific next jumping is forwarded to monitoring CE with message;
Described the 3rd remote monitoring retransmission unit 74, be used to receive from the monitoring CE and go to the message of monitored CE after, message stamped describedly long-rangely be forwarded to monitored PE after the VPN_Local label that unit 71 is provided with for monitoring CE is set, message is forwarded to monitored CE by monitored PE.
So far, promptly obtained of the present invention being used for as monitoring PE carries out remote monitoring to CE routing device.The concrete workflow of Fig. 6 and the described routing device of Fig. 7 can repeat no more here referring to Fig. 5.
In a word, the method of in MPLS L3VPN network, CE being monitored of the present invention, by being respectively monitoring CE specific next jumping that comprises the VPN_Local label is set by monitoring PE and monitored PE, the outgoing interface of this specific next jumping is the interface of the local monitor CE of monitoring PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE, thereby make message by monitored CE can only be redirected to specific next jump out among the local monitor CE of monitoring PE of interface correspondence, transmit again after CE handles it by monitoring, and when message need be forwarded to long-range monitored CE, message is delivered to monitored PE after being added the VPN_Local label, monitored PE bullet is carried out normal IP forwarding after falling label, message by other CE is then transmitted according to normal flow process, also promptly can be in not influencing MPLS L3VPN network under the situation of other flow, can realize monitoring neatly to monitored CE.
The above only is preferred embodiment of the present invention, and is in order to restriction the present invention, within the spirit and principles in the present invention not all, any modification of being made, is equal to replacement, improvement etc., all should be included within the scope of protection of the invention.