CN1773949A - Switching in method for virtual special network and realizing apparatus - Google Patents

Switching in method for virtual special network and realizing apparatus Download PDF

Info

Publication number
CN1773949A
CN1773949A CN 200510116994 CN200510116994A CN1773949A CN 1773949 A CN1773949 A CN 1773949A CN 200510116994 CN200510116994 CN 200510116994 CN 200510116994 A CN200510116994 A CN 200510116994A CN 1773949 A CN1773949 A CN 1773949A
Authority
CN
China
Prior art keywords
vpls
vlan
vpn
access path
path table
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 200510116994
Other languages
Chinese (zh)
Other versions
CN100382531C (en
Inventor
卢胜文
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou Huawei 3Com Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou Huawei 3Com Technology Co Ltd filed Critical Hangzhou Huawei 3Com Technology Co Ltd
Priority to CNB2005101169944A priority Critical patent/CN100382531C/en
Publication of CN1773949A publication Critical patent/CN1773949A/en
Application granted granted Critical
Publication of CN100382531C publication Critical patent/CN100382531C/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

A method for switching in virtual special web includes establishing the corresponding relation of VPLS identification to multiplayer VLAN countermark and port by setting up VPLS switch in path table, querying VPLS switch in path table according to multiplayer VLAN countermark to obtain corresponding VPLS domain identification for knowing special web to be switched in by input data packet when input data packet is received.

Description

The cut-in method of VPN and implement device
Technical field
The present invention relates to network communications technology field, be specifically related to a kind of cut-in method and implement device of VPN.
Background technology
Virtual private network VPN refers to the private data communication network that relies on ISP (ISP) and other NSP (Internet Service Provider) to set up in common network.In VPN, the connection between any two nodes does not have the required physical link end to end of traditional private network, but utilizes the resource dynamic of certain public network to form.VPN technologies commonly used at present have 2 layers of technology and 3 layers of technology.Virtual special local area network service VPLS is a kind of 2 layers L2VPN technology, and it shows as a VPN service VPLS territory just as 2 virtual layer switch, and same VPLS territory user belongs to same VPN, can be interconnected.
Be as the basis for estimation that inserts which VPLS territory during prior art access of virtual private network with outside VLAN ID virtual label.For example, certain metropolitan area network operator provides VOIP business, Internet business, and IP TV business, and every kind of business all wishes to insert corresponding VPN by VPLS.So for every kind of business provides a VPN service-domain VPLS, and with outside VLAN ID as inserting foundation, judge which VPLS the user should insert, thereby distinguish concrete type of service.
If every kind of professional corresponding VPLS territory adopts a VLAN ID to insert; this VLAN can be too huge so; so can use the two label techniques of QinQ to isolate usually, be used to identify the type of business or other type such as outside VLAN ID, inner VLAN ID is used for mark business-type.
But after being to use the two label techniques of QinQ, when certain user of business is an enterprise, and have its VPN, the user will go wrong when visiting public resource (business that the operator provides) so.For example, described enterprise has the virtual private network VPN of oneself, can distribute a specific VLAN to be used for public connection during the accessed enterprise public resource, supposes to distribute VLAN20 to be used for the VOIP business.Simultaneously, owing to adopted two label techniques, so also have one deck label VLAN 15 in the outside of vpn label VLAN20, VLAN15 is used to identify this type of business.When described enterprise wants to visit VOIP when professional, need be that 20 user inserts the VOIP private network by VPLS with the QinQ inner VLAN, but according to existing VPN access technology be with outside VLAN ID as basis for estimation, and nonrecognition inner VLAN label.So, can't be that the user of VLAN20 correctly inserts the VOIP private network with vpn label.
This shows,, when networking, lack flexibility, especially insert when having private network to insert again even can't realize at existing public network only with the cut-in method of outside VLAN ID as the basis for estimation that inserts which VPLS.
Summary of the invention
The problem to be solved in the present invention provides a kind of cut-in method of VPN, with solve prior art only with outside VLAN ID as inserting foundation, when networking, lack the technical problem of flexibility.
For solving the problems of the technologies described above, the objective of the invention is to be achieved through the following technical solutions: a kind of cut-in method of VPN, configuration virtual private network service VPLS access path table on switching equipment; Inquire about described VPLS access path table, obtain the VPLS domain identifier of input packet correspondence; Insert the corresponding virtual private network according to the VPLS domain identifier.
Described VPLS access path table comprises the virtual LAN VLAN information that participates in access under all VPLS territories.
Preferably, from described input packet, take out with the VPLS access path of configuration and support the corresponding multilayer VLAN label of the number of plies, be used to search described VPLS access path table.
Preferably, when the corresponding a plurality of different VPLS signs of the input port of input packet, press the VLAN label in the label depth-first coupling VPLS access path table.
Preferably, when the corresponding a plurality of different VPLS signs of input port of input packet, preferentially mate VLAN label in the VPLS access path table by the tag configurations order.
Purpose media access control MAC inquiry according to described VPLS domain identifier and described input packet is transmitted, and obtains outlet pathway;
If corresponding outlet pathway is arranged in described the transmitting, then obtains this outlet pathway; If there is not corresponding outlet pathway in transmitting, then obtain the corresponding whole outlet pathways of described VPLS sign.
Preferably, the source MAC of described input packet and outside VLAN label learnt to transmit.
A kind of device of realizing that VPN inserts is in comprising: module is set, is used for configuration virtual private network service VPLS access path table; Enquiry module is used to inquire about described VPLS access path table, obtains the VPLS domain identifier of input packet correspondence; Access module is used for inserting the corresponding virtual private network according to the VPLS domain identifier.
Preferably, also comprise study module, be used for the source MAC and the VLAN label of described input packet are learnt to transmit.
Above technical scheme as can be seen, the present invention is owing to disposed VPN service VPLS access path table on switching equipment, after packet arrives, according to himself with the described VPLS access path of multilayer VLAN searching label table, obtain the VPLS domain identifier of input packet correspondence, know promptly which VPN is the input packets need insert.This shows, when prior art inserts at VPN, serve as to judge the foundation that inserts which VPLS only with the outside VLAN label, and method disclosed by the invention is to be basis for estimation with multilayer VLAN label, and then make when the VPN networking more flexibly, also can realize flexibly when having private network to insert again even insert at existing public network.
Description of drawings
Fig. 1 is the networking schematic diagram of VPN;
Fig. 2 is the realization flow figure of VPN cut-in method first embodiment;
The realization flow figure of cut-in method second embodiment of Fig. 3 VPN;
Fig. 4 is with table 1 and table 2 flow chart for the VPN cut-in method of concrete reference.
Embodiment
Core of the present invention is by setting up VPLS access path table, in this table, comprise the vlan information that participates in access under all VPLS territories: VPLS sign, VLAN label, and port numbers, VPLS identifies and the corresponding relation of multilayer VLAN label and port thereby set up; After receiving the input packet, according to the multilayer VLAN searching label VPLS access path table of this packet, obtain corresponding VPLS domain identifier, know promptly which VPN is the input packets need insert.
In order to make those skilled in the art understand the present invention program better, at first introduce VPN and networking mode thereof.
VPN is the virtual proprietary network that operator provides to the user by its public network, promptly is user's a proprietary network at user's angle VPN.Public network comprises public backbone network and public operator edge device for operator.VPN member's website separated from one another on the geography is connected on the corresponding operator edge device (PE) by client device (CE), and then forms client's VPN network by the public network of operator.VPN technologies commonly used at present have 2 layers of technology and 3 layers of technology.Virtual special local area network service VPLS is the 2 layer VPN of a kind of point to multiple spot.That technical scheme disclosed in this invention is primarily aimed at is exactly 2 layer VPN VPLS.See also Fig. 1, it is the networking schematic diagram of VPN.
Comprise public network and private network in the group network system.Wherein, public network comprises two backbone devices and 3 operator edge devices (PE), wherein first backbone device 4 links to each other with second operator edge device 7 with first operator edge device 6 respectively, and second backbone device 5 links to each other with the 3rd operator edge device 8 with first operator edge device 6 respectively; Private network is VPN VPLS1, and VPLS1 is made up of three websites, and each website is connected to corresponding operator edge device (PE) by user network edge equipment (CE), and then forms client's VPN network (VPLS1) by the public network of operator.Concrete annexation is as follows: the first user network edge equipment (CE) 1 is connected on first operator edge device (PE) 6, the second user network edge equipment (CE) 2 is connected on second operator edge device (PE) 7, and the 3rd user network edge equipment (CE) 3 is connected on the 3rd operator edge device (PE) 8.Carry out the information transmission by first backbone device 4 and second backbone device 5 between the one PE6 and the 2nd PE7 and the 3rd PE8.
MPLS (Multi-Propocol Label Switching) is a multiple protocol label switching, and the label that the is similar to virtual circuit reciprocal exchange of business is provided, and this exchange based on label can provide the internet security that is similar to frame relay, ATM.The MPLS technology belongs to the third generation network architecture, is the IP high-speed backbone cross winding dehorn standard of a new generation, and the VPLS shown in the figure is exactly the VPLS that connects by MPLS, and MPLS can carry out the wide area networking, so VPLS can realize the wide area networking.
The networking mode of VPN as mentioned above because the demand of VPN is increasing, the class of business that operator provides also is gradually improved, every kind of business all wishes to insert corresponding VPN by VPLS.So it is following to insert the problem of which VPN.Embodiment below in conjunction with VPN cut-in method disclosed by the invention further describes.
Please refer to Fig. 2, it is the realization flow figure of VPN cut-in method first embodiment:
Step 201: configuration VPLS access path table on carrier side edge equipment PE, described VPLS access path table comprises the virtual LAN VLAN information that participates in access under all VPLS territories: VPLS sign, VLAN label, and the connectivity port information corresponding with it.
Virtual special local area network service VPLS is a kind of 2 layers VPN technologies, is the L2VPN of a kind of point to multiple spot, and it shows as a VPLS territory and just is equivalent to 2 virtual layer switch, and same VPLS territory user belongs to same VPN, can be interconnected.Wherein, described multilayer VLAN is private network or public network.
To support that two-layer VLAN is an example, the VPLS access path table of configuration is as shown in table 1 below below:
At table 1:
Insert VPLS ID Port Outside VLAN ID Inner VLAN ID
2 - - 5
2 1 12 6
3 - - 10
4 3 10 5
VPLS ID is a sign that shows certain VPLS territory, identifies identically, shows that inserting is same VPLS territory, promptly belongs to same VPN.Outside VLAN ID, inner VLAN ID, indicate have only satisfy VLAN ID condition could insert this VPLS.Port is the port that Ethernet inserts, and described port can be an ethernet port, also can be the corresponding empty port of a multiprotocol label switching (mpls) link (PW).MPLS virtual link correspondence be the packet that network side is come, empty port and VPLS concern one to one, if when therefore the MPLS virtual link being arranged in the VPLS access path table, need not the ID into this path configurations VLAN.
Port, outside VLAN ID and inner VLAN ID support wildcard, and just this is worth for arbitrary value and all mates.For example the 3rd record shows, as long as inner VLAN ID is 10, port, outside VLAN ID are that what value all inserts VPLS 3.
On expressed VPLS ID and be respectively and participate in the routing information that inserts in 2,3 and 4, by outside VLAN label, inner VLAN label (number of plies of configuration VLAN with need to support that the VLAN number of plies that inserts is consistent, present embodiment is example with two-layer) and port numbers formation.Wherein, the span of every layer of VLAN is 1 ∽ 4094, and "-" expression can be mated the VLAN of this layer arbitrarily.
VPLS ID is that the configuration information in 2 the VPLS territory is as follows:
Article 1, configuration information represents that inner VLAN is VLAN5, and outside VLAN and port numbers can be arbitrary value;
Article 2, configuration information represents that the outside VLAN of port one is VLAN12, and inner VLAN is VLAN6.
Above-mentioned two records have represented that VPLS ID is two access paths in 2 the VPLS territory.
VPLS ID is that the configuration information in 3 the VPLS territory is as follows:
Article 3, configuration information represents that inner VLAN is VLAN10, and outside VLAN and port numbers are that any value can.
VPLS ID is that the configuration information in 4 the VPLS territory is as follows:
Article 4, configuration information represents that the outside VLAN of port 3 is VLAN10, and inner VLAN is VLAN5;
In when configuration, the number of plies of VLAN label in the definition list 1 according to actual needs, the VLAN label of configuration different levels.Support the VLAN of two-layer label to insert if desired, then dispose two-layer VLAN label,, then dispose three layers of VLAN label if support the VLAN of three layers of label to insert.
Step 202: from the input packet, take out with the access path of configuration and support the corresponding multilayer labels VLAN ID of the number of plies.Which floor VLAN label the access path of configuration can support, which floor VLAN label of outermost of just maximum data fetch packet.
Step 203: with multilayer VLAN ID inquiry VPLS access path table.
Step 204: in judging whether to look into, obtain corresponding VPLS sign.If find corresponding VPLS sign, then enter step 205; If in looking into not, then enter step 206: do not insert any VPLS and carry out other processing.
After switching equipment is received the input packet, know this packet is from which port, according to this port numbers and the multilayer VLAN searching label VLAN access path table of getting, VLAN label in the coupling VPLS access path table, obtain corresponding VPLS ID, so just obtain this VLAN and should insert which VPLS territory.
When the corresponding a plurality of different VPLS ID of the input port of input packet, the VLAN label hits and can mate by depth-first or by the configuration sequence priority principle during coupling VLAN label.
So-called depth-first principle is meant the VLAN label that preferential accuracy at target is high, for example, if port 3 an outside VLAN ID be 10, inner VLAN ID is 5 packet, simultaneously can satisfy the 1st record and the 4th record, but the precision of the 4th record is higher than the 1st record, promptly port, outside VLAN ID be 10 and inner VLAN ID be that 5 three contents can both be mated, precision is the highest, so the VPLS territory of inserting is VPLS4.At this moment, two-layer VLAN label all need be peeled off.
So-called configuration sequence priority principle is meant according to the configuration sequence in the VLAN access path table and mates, to satisfy the matched record that is recorded as of coupling requirement at first.Therefore, the packet of the 3/VLAN10/VLAN5 of port described in the epimere is according to the configuration preference principle, and preferentially coupling is article one record, so the VPLS territory of inserting is VPLS2.
Step 205: media access control MAC address, source, port and the outside VLAN ID of learning data bag, so that the packet of returning can accurately recover original multilayer VLAN ID.
One skilled in the art will appreciate that the MAC Address that two layers of exchange are based on network node transmits data, need set up addresses forwarding table during forwarding, in this addresses forwarding table, shown the corresponding relation of MAC Address and port.The present invention need set up one equally and transmit the forwarding relation that shows the vlan data bag, specifically exchanges to which port.Transmitting that the present invention sets up comprises following information: VPLS ID, MAC Address, VLAN label and port numbers.This table is according to setting up after source MAC in the input packet and the study of outside VLAN label, therefore, can not obtaining required outlet pathway information when this table of first visit.
For example, the mac address forwarding table that obtains after the study is as shown in table 2 below:
Table 2 mac address forwarding table
VPLS ID MAC Address The outside VLAN label Port numbers
2 0x12345678 50 1
2 0x12345679 12 2
3 0x12345689 10 3
Step 207: with VPLS ID and purpose MAC inquiry mac address forwarding table.
Step 208: in judging whether to look into.
If can hit mac address forwarding table, then enter step 209: according to VPLS ID, directly described packet is sent to designated port, this port comprises that VPLS inserts the ethernet port of side and the MPLS link (PW) of VPLS network side, for the packaged corresponding outside VLAN of ethernet port, remain unchanged by original processing for empty port.
If can not hit mac address forwarding table, then enter step 210: obtain whole ports of VPLS ID correspondence, data broadcasting is arrived all of the port, all broadcast data encapsulation port corresponding outer layer VLANID.If VLAN ID is a wildcard, then transmit all corresponding VLAN.According to the VPLS standard, if being network side, packet comes, can not be broadcast to network side, promptly empty port.
The invention also discloses the realization flow figure of cut-in method second embodiment of VPN, see also Fig. 3:
Step 301: configuration VPLS access path table on carrier side edge switching equipment PE, described VPLS access path table comprises the virtual LAN VLAN information that participates in access under all VPLS territories: VPLS sign, VLAN label, and the connectivity port information corresponding with it.
Step 302: from the input packet, take out with the access path of configuration and support the corresponding multilayer VLAN label of the number of plies.Which floor VLAN label the access path of configuration can support, which floor VLAN label of outermost of just maximum data fetch packet.
Step 303: with multilayer VLAN ID inquiry VPLS access path table.
Step 304: in judging whether to look into.
If in looking into, obtain corresponding VPLS ID and enter step 305; Enter step 306 in looking into not: do not insert any VPLS, carry out other processing.
Step 305: with VPLS ID and purpose MAC inquiry mac address forwarding table.
Step 307: in judging whether to look into.
If can look into middle mac address forwarding table, then enter step 308: directly described packet is sent to designated port; If can not hit mac address forwarding table, then enter step 309: obtain whole ports of VPLS ID correspondence, data broadcasting is arrived all of the port, the multilayer VLAN ID of all broadcast data encapsulation port correspondences.If VLAN ID is a wildcard, then transmit all corresponding VLAN.According to the VPLS standard, if being network side, packet comes, can not be broadcast to network side, promptly empty port.
In addition, in also the VPLS ID of packet, two-layer (or multilayer) label, inbound port and the source MAC of going into VLAN will being learnt to transmit, i.e. step 310: two-layer (or multilayer) VLAN label, source MAC and the port of study inlet are learnt in the mac address forwarding table.
The main distinction of above-mentioned second embodiment and first embodiment is: when the label of study input packet, what first embodiment learnt only is the outside VLAN label, and second embodiment study is two-layer (perhaps multilayer) VLAN label.This be because: a kind of situation, if there is inner VLAN ID, VPLS does not change the VLAN ID of internal layer, then needs transparent transmission inner VLAN ID; Another kind of situation does not then need transparent transmission inner VLAN ID, is equivalent to that multilayer VLAN ID is combined into a VLAN ID and treats, and has been equivalent to expand the scope of VLAN ID.Therefore, two kinds of modes of learning can.In addition, the learning procedure among first embodiment be arranged on the inquiry transmit before the step, and the learning procedure of second embodiment be arranged on the inquiry transmit after the step.In brief, learning procedure both can be arranged on the inquiry transmit before, also can after, its position is flexibly, is not limited to shown in above-mentioned two embodiment.
VPLS access path table in above-mentioned two preferred embodiments can split into two tables, and one is used for configuration ethernet port and two-layer VLAN, and another is used for disposing MPLS virtual link (PW).Same mac address forwarding table is split up into 2 tables too, like this for it goes without doing any change of the list item of MPLS virtual link correspondence.Only need inquire about the ethernet port allocation list for the message that Ethernet inserts, but need inquire about two tables during inquiry VPLS corresponding interface during broadcasting, also need to inquire about simultaneously two during forwarding and transmit.
In addition, if large-scale access network, use open method of the present invention to limit and insert side broadcasting and forwarding, for example insert VOIP, insert Internet, insert certain network, requiring to insert between the data of side can not intercommunication and broadcasting, just insert side and can not directly transmit data, the data of user side only may be transmitted or broadcasting to relevant empty port in this case.
Below with reference to the forward-path of mac address forwarding table shown in the access path of the access path of VPLS shown in the table 1 table and the table 2, further specify the VPN access procedure of multilayer VLAN.Described workflow is as shown in Figure 4:
At first, in step 401: entering an outside VLAN from the port one of switching equipment is 8, and inner VLAN is 5 packet.
Step 402: from packet, obtain two-layer VLAN label VLAN 8/VLAN5.
Enter step 403 then: with the VPLS access path table shown in port numbers 1 and the two-layer label VLAN 8/VLAN5 question blank 1, the VPLS that obtains inserting sign 2.
Step 404: with the mac address forwarding table shown in VPLS2 and the purpose MAC 0x12345679 question blank 2.
According to forward-path shown in the mac address forwarding table shown in the table 2, obtaining the outlet pathway that VPLS is designated 2, target MAC (Media Access Control) address is 0x12345679 is port 2, and corresponding outer layer VLAN label is 12.So enter step 405: packaged outer layer label VLAN12 is sent to port 2 with packet.
The invention also discloses a kind of device of realizing that VPN inserts, described device comprises module, enquiry module and access module and study module is set.
Module is set is used for configuration virtual private network service VPLS access path table, described VPLS access path table comprises the virtual LAN VLAN information that participates in access under all VPLS territories: VPLS sign, VLAN label, and the connectivity port information corresponding with it.VPLS ID is a sign that shows certain VPLS territory, identifies identically, shows that inserting is same VPLS territory, promptly belongs to same VPN.Outside VLAN ID, inner VLAN ID, indicate have only satisfy VLAN ID condition could insert this VPLS.
Enquiry module is used to inquire about described VPLS access path table, obtains the VPLS domain identifier of input packet correspondence.After packet entered, enquiry module was provided with the VPLS access path table that disposes in the module according to the inbound port and the multilayer VLAN ID inquiry of described packet, and then obtains corresponding VPLS domain identifier, i.e. VPLS ID.Also comprise preferential matched sub-block in the enquiry module, be used to be provided with two kinds of match patterns: depth-first and configuration sequence are preferential.When the corresponding a plurality of different VPLS ID of the input port of input packet, the VLAN label hits and can mate by depth-first or by the configuration sequence priority principle during coupling VLAN label.So-called depth-first principle is meant the VLAN label that preferential accuracy at target is high.So-called configuration sequence priority principle is meant according to the configuration sequence in the VLAN access path table and mates, to satisfy the matched record that is recorded as of coupling requirement at first.
Access module is used for inserting the corresponding virtual private network according to the VPLS domain identifier.Those skilled in the art knows that the user in same VPLS territory belongs to a virtual private network VPN, so after obtaining corresponding VPLS domain identifier, promptly is equivalent to know insert which VPN.After obtaining the VPLS sign of input packet,, send to this VPLS territory corresponding port with described packet encapsulation skin or multilayer VLAN label.
The device that described realization VPN inserts also comprises study module, is used for that the source MAC of described input packet and VLAN label are learnt MAC and transmits, so that the packet of returning can accurately recover original multilayer VLAN ID.
More than the cut-in method and the implement device of VPN provided by the present invention is described in detail, used specific case herein principle of the present invention and execution mode are set forth, the explanation of above embodiment just is used for helping to understand method of the present invention and core concept thereof; Simultaneously, for one of ordinary skill in the art, according to thought of the present invention, the part that all can change in specific embodiments and applications, in sum, this description should not be construed as limitation of the present invention.

Claims (10)

1, a kind of cut-in method of VPN is characterized in that,
Configuration virtual private network service VPLS access path table on switching equipment;
Inquire about described VPLS access path table, obtain the VPLS domain identifier of input packet correspondence;
Insert the corresponding virtual private network according to the VPLS domain identifier.
2, the cut-in method of VPN as claimed in claim 1 is characterized in that, described VPLS access path table comprises the virtual LAN VLAN information that participates in access under all VPLS territories.
3, the cut-in method of VPN as claimed in claim 1 is characterized in that, takes out from described input packet with the VPLS access path of configuration and supports the corresponding multilayer VLAN label of the number of plies, is used to search described VPLS access path table.
4, the cut-in method of VPN as claimed in claim 3 is characterized in that: when the corresponding a plurality of different VPLS signs of the input port of input packet, press the VLAN label in the label depth-first coupling VPLS access path table.
5, the cut-in method of VPN as claimed in claim 3 is characterized in that: when the corresponding a plurality of different VPLS signs of input port of input packet, preferentially mate VLAN label in the VPLS access path table by the tag configurations order.
6, the cut-in method of VPN as claimed in claim 1 is characterized in that, transmits according to the purpose media access control MAC inquiry of described VPLS domain identifier and described input packet, obtains outlet pathway;
7, the cut-in method of VPN as claimed in claim 6 is characterized in that, if corresponding outlet pathway is arranged in described the transmitting, then obtains this outlet pathway; If there is not corresponding outlet pathway in transmitting, then obtain the corresponding whole outlet pathways of described VPLS sign.
8, the cut-in method of VPN as claimed in claim 1 is characterized in that, during the source MAC of described input packet and outside VLAN label are learnt to transmit.
9, a kind of device of realizing that VPN inserts is characterized in that comprising,
Module is set, is used for configuration virtual private network service VPLS access path table;
Enquiry module is used to inquire about described VPLS access path table, obtains the VPLS domain identifier of input packet correspondence;
Access module is used for inserting the corresponding virtual private network according to the VPLS domain identifier.
10, the device of realization VPN access as claimed in claim 9 is characterized in that also comprising,
Study module is used for the source MAC and the VLAN label of described input packet are learnt to transmit.
CNB2005101169944A 2005-10-28 2005-10-28 Switching in method for virtual special network and realizing apparatus Expired - Fee Related CN100382531C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2005101169944A CN100382531C (en) 2005-10-28 2005-10-28 Switching in method for virtual special network and realizing apparatus

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2005101169944A CN100382531C (en) 2005-10-28 2005-10-28 Switching in method for virtual special network and realizing apparatus

Publications (2)

Publication Number Publication Date
CN1773949A true CN1773949A (en) 2006-05-17
CN100382531C CN100382531C (en) 2008-04-16

Family

ID=36760717

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2005101169944A Expired - Fee Related CN100382531C (en) 2005-10-28 2005-10-28 Switching in method for virtual special network and realizing apparatus

Country Status (1)

Country Link
CN (1) CN100382531C (en)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101820394A (en) * 2010-03-22 2010-09-01 中兴通讯股份有限公司 Statistical method and equipment of access flow
CN101834803A (en) * 2010-05-24 2010-09-15 中兴通讯股份有限公司 Method and device for processing messages
CN101977123A (en) * 2010-10-28 2011-02-16 北京星网锐捷网络技术有限公司 Method, system and device for generating virtual private local area network site ID
CN102223279A (en) * 2011-06-14 2011-10-19 杭州华三通信技术有限公司 Method for processing multi-VLAN (virtual local area network) and nodes
CN101150493B (en) * 2006-09-20 2012-06-27 华为技术有限公司 A method and system for distributing service at access terminal
WO2013026384A1 (en) * 2011-08-23 2013-02-28 华为技术有限公司 Service data transmission method, network node and system
CN103209124A (en) * 2013-03-05 2013-07-17 华为技术有限公司 Message processing method, device and system
CN104854819A (en) * 2012-12-12 2015-08-19 爱立信(中国)通信有限公司 Method and device for vlan interface routing
CN106209485A (en) * 2015-04-30 2016-12-07 中国南方电网有限责任公司 A kind of VPN private network chain circuit detecting method and device

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1125545C (en) * 2001-12-31 2003-10-22 刘军民 Data forwarding method for implementing virtual channel transmission in LAN
US7515592B2 (en) * 2002-10-07 2009-04-07 Broadcom Corporation Fast-path implementation for transparent LAN services using double tagging
US7539185B2 (en) * 2002-10-07 2009-05-26 Broadcom Corporation Fast-path implementation for an uplink double tagging engine
ES2214112B2 (en) * 2002-10-09 2005-03-16 Diseño De Sistemas En Silicio, S.A. VIRTUAL LOCAL AREA NETWORK IMPLEMENTATION PROCEDURE ON COMMUNICATION SYSTEMS BY THE ELECTRICAL NETWORK.
US7180899B2 (en) * 2002-10-29 2007-02-20 Cisco Technology, Inc. Multi-tiered Virtual Local area Network (VLAN) domain mapping mechanism
CN100334849C (en) * 2003-07-31 2007-08-29 华为技术有限公司 Method for realizing address synchronization in independant virtual LAN learning mode
AU2003290477A1 (en) * 2003-12-16 2005-07-05 Telefonaktiebolaget Lm Ericsson (Publ) Ethernet dsl access multiplexer and method providing dynamic service selection and end-user configuration
WO2005091556A2 (en) * 2004-03-17 2005-09-29 Telefonaktiebolaget Lm Ericsson (Pub) Vlan mapping for multi-service provisioning

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101150493B (en) * 2006-09-20 2012-06-27 华为技术有限公司 A method and system for distributing service at access terminal
CN101820394B (en) * 2010-03-22 2015-06-03 中兴通讯股份有限公司 Statistical method and equipment of access flow
CN101820394A (en) * 2010-03-22 2010-09-01 中兴通讯股份有限公司 Statistical method and equipment of access flow
CN101834803A (en) * 2010-05-24 2010-09-15 中兴通讯股份有限公司 Method and device for processing messages
CN101977123A (en) * 2010-10-28 2011-02-16 北京星网锐捷网络技术有限公司 Method, system and device for generating virtual private local area network site ID
CN101977123B (en) * 2010-10-28 2012-05-30 北京星网锐捷网络技术有限公司 Method, system and device for generating virtual private local area network site ID
CN102223279A (en) * 2011-06-14 2011-10-19 杭州华三通信技术有限公司 Method for processing multi-VLAN (virtual local area network) and nodes
CN102223279B (en) * 2011-06-14 2013-11-06 杭州华三通信技术有限公司 Method for processing multi-VLAN (virtual local area network) and nodes
WO2013026384A1 (en) * 2011-08-23 2013-02-28 华为技术有限公司 Service data transmission method, network node and system
CN104854819A (en) * 2012-12-12 2015-08-19 爱立信(中国)通信有限公司 Method and device for vlan interface routing
CN104854819B (en) * 2012-12-12 2019-05-17 爱立信(中国)通信有限公司 Method and apparatus for VLAN interface routing
CN103209124A (en) * 2013-03-05 2013-07-17 华为技术有限公司 Message processing method, device and system
CN103209124B (en) * 2013-03-05 2017-04-12 华为技术有限公司 Message processing method, device and system
CN106209485A (en) * 2015-04-30 2016-12-07 中国南方电网有限责任公司 A kind of VPN private network chain circuit detecting method and device
CN106209485B (en) * 2015-04-30 2019-05-24 中国南方电网有限责任公司 A kind of VPN private network chain circuit detecting method and device

Also Published As

Publication number Publication date
CN100382531C (en) 2008-04-16

Similar Documents

Publication Publication Date Title
CN1773949A (en) Switching in method for virtual special network and realizing apparatus
CN1266913C (en) Tunneling through access network
CN1913523A (en) Method for implementing layer level virtual private exchange service
CN103416010B (en) The network automatic conversion between agreement
CN1809032A (en) Method of dynamically learning address on MAC layer
CN1863133A (en) Method and apparatus for transmitting message
CN1866904A (en) Method and apparatus for astringing two layer MAC address
CN1946041A (en) VLAN polymerizing method, converging exchanger and system based on ARP detector intercept
CN101047636A (en) Method and system for end-to-end pseudo-line simulation virtual leased line access virtual special network
JP5941223B2 (en) Edge router based on virtual private LAN service
CN101052022A (en) System and method for virtual special net user to access public net
CN101056267A (en) Layer 2 forwarding method and forwarding device
CN1863129A (en) System based on two layer VPN foreign medium communication and method thereof
CN1878135A (en) Method for judging pseudo wire connection state in packet-switching network and service apparatus
US20090073997A1 (en) Method and system for establishing hierarchical network with provider backbone bridges
CN100358322C (en) Method of multilayer VLAN switching
CN1716904A (en) Group broadcast realizing method based on multiple service transmission platform
CN1297105C (en) Method for implementing multirole main machine based on virtual local network
CN1691629A (en) Method for implementing layer-2 equipment interconnection in resilient packet ring (RPR) based network
CN1921441A (en) Method and device for message transfer of virtual private local area network
CN1863127A (en) Method for core network access to multi-protocol sign exchange virtual special network
CN1741499A (en) Virtual circuit exchanging method based on MAC studying
CN1870588A (en) Implementing method and system for support VPLS service on IP skeletal network
CN102801622A (en) Transmitting method and device for data messages
CN100508520C (en) Method for implementing VLAN based L2VPN

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.

CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20080416

Termination date: 20201028