CN101488925A - Method for collecting and designing VPN flow by using Netflow - Google Patents

Method for collecting and designing VPN flow by using Netflow Download PDF

Info

Publication number
CN101488925A
CN101488925A CNA2009101263272A CN200910126327A CN101488925A CN 101488925 A CN101488925 A CN 101488925A CN A2009101263272 A CNA2009101263272 A CN A2009101263272A CN 200910126327 A CN200910126327 A CN 200910126327A CN 101488925 A CN101488925 A CN 101488925A
Authority
CN
China
Prior art keywords
vpn
information
flow
packet
identification
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CNA2009101263272A
Other languages
Chinese (zh)
Other versions
CN101488925B (en
Inventor
陶文强
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CN2009101263272A priority Critical patent/CN101488925B/en
Publication of CN101488925A publication Critical patent/CN101488925A/en
Application granted granted Critical
Publication of CN101488925B publication Critical patent/CN101488925B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

A method for acquiring and counting virtual private network VPN flow by using Netflow includes the following steps: VPN routing list information is configured on entrance service provider edge-node PE, wherein the corresponding relation with access port VPN identification and remote end PE identification is stored; expanded Netflow V9 template message carried with the VPN identification and remote end PE identification is sent to a top management server; the entrance PE samples the data flow flowing therethrough, corresponding VPN identification is obtained according to the access port of the data flow, the identification of remote-end PE is obtained and the data packet information obtained by sampling is buffered in the combined with the VPN routing list information; the data packet information is sent to the top management server after the sample message obtained by packaging according to the expanded Netflow V9 template; and the top management server analyzes the sample message according to the template message, and the VPN flow is counted.

Description

A kind of method of utilizing Netflow to gather and add up the VPN flow
Technical field
The present invention relates to the communications field, relate in particular to a kind of method of utilizing network flow Netflow (standard of IETF RFC3954 definition) to gather and add up VPN (Virtual Private Network, VPN (virtual private network)) flow.
Background technology
In recent years, the Internet makes it become indispensable information-bearing instrument in people's routine work life in developing rapidly of the whole world and popularizing fast of various application.Yet, being accompanied by the normal use flow of the Internet, panoramic abnormal flow is also following on the network, has influence on the normal operation of the Internet, threatens the safety and normal use of subscriber's main station.
Angle from the network operation management, need the flow in the network be managed and monitor, charge according to flow, feature to internet traffic is analysed in depth, analyze message characteristic, identify abnormal flow, and then cook up accordingly at measure, implement traffic engineering and optimize network configuration, thereby guarantee quality of services for users.
In recent years, Netflow V9 agreement (RFC3954-Cisco Systems Netflow ServicesExport Version 9) is widely adopted, and many data equipment manufacturers have all realized Netflow V9 agreement, and utilize it that flow is gathered.
Netflow is a kind of data exchange ways, its operation principle is: the Netflow buffer memory is gathered and generated to the network equipment according to certain sampling policy to the data of its forwarding, same subsequently data are transmitted in same data flow based on cache information, no longer mate relevant strategies such as access control, comprised the statistical information of follow-up data in the Netflow buffer memory simultaneously.The network equipment sends to Netflow flow collecting device with the data in buffer stream information by Netflow V9 message format according to the aging strategy of data flow, is further analyzed by Netflow flow collecting device.
A traditional Netflow data flow is defined as an one-way data bag stream that transmits between source IP address and purpose IP address, and wherein all packets have common transport layer, source/destination slogan and protocol number.
According to MPLS (Multi-Protocol Label Switching, when multi protocol label switching protocol) carrying out the VPN networking, L3VPN (L 3 virtual local area network (LAN)) is at entry PE (Provider Edge, the Provider Edge node) according to VRF (the Virtual Routing Forwarding that inserts, virtual routing forwarding), encapsulation private network tags and public network label and be forwarded to remote outlet PE.
But under actual network environment, may exist a plurality of far-end PE to belong to the situation of same VPN.At this moment, operator just needs the flow situation of statistics entry PE to certain particular remote PE path, accurately adds up the flow of VPN inside, carries out message analysis.But can't add up the data packet stream that belongs to different VPN according to traditional Netflow IP message five-tuple information (source/purpose IP address, source/destination slogan and protocol number), also can't add up the inner data packet flow of same VPN to different far-end PE equipment.
Summary of the invention
The technical problem to be solved in the present invention provides the method that a kind of Netflow of utilization gathered and added up the VPN flow, makes traditional Netflow data flow information statistic based on the IP five-tuple can expand to the data flow information statistic that arrives certain particular remote PE in the VPN.
For addressing the above problem, the invention provides a kind of method of utilizing network flow Netflow collection and counting virtual private VPN flow, comprising:
Configuration VPN routing table information is preserved the corresponding relation of access port VPN identification and remote end PE identification in the described routing table on entrance service provider edge-node PE; And the Netflow V9 template message that carries VPN sign and remote end PE identification after will expanding sends to top management server;
Described entry PE is sampled to the data flow that flows into wherein, obtains corresponding VPN sign according to the access interface of described data flow, in conjunction with described VPN routing table information, obtains the sign of far-end PE and the packet information that the buffer memory sampling obtains;
Described entry PE packages and will organize the sampling message that obtains behind the bag according to the Netflow V9 template after expanding described packet information and sends to described top management server;
Described top management server is resolved described sampling message according to the Netflow V9 template message after expanding, and counts the VPN flow.
Further, said method also can have following feature:
Described entry PE is sampled to the data flow that flows into wherein, comprising:
Dispose the sampling ratio on the described entry PE, described entry PE is sampled according to the data flow that described sampling comparison flows into wherein.
Further, said method also can have following feature:
The packet information that the buffer memory sampling obtains, comprise: the packet information that described sampling is obtained is cached to the buffer area at information place that belongs to the packet of same data flow with this packet, wherein, the packet that belongs to same data flow has identical VPN sign, remote end PE identification and IP five-tuple information.
Further, said method also can have following feature:
Described packet information comprise this packet flow information, flow to information and VPN sign and remote end PE identification.
Further, said method also can have following feature:
Dispose aging strategy on the described entry PE;
Further comprising the steps of before described entry PE packages according to the Netflow V9 form after expanding to described packet information:
Described entry PE judges whether to satisfy aging strategy, if satisfy, the packet information that belongs to same data flow of buffer memory is carried out the subsequent group packet procedures; Otherwise, upgrade sample information, continue the data flow that flows into is wherein sampled.
Further, said method also can have following feature:
Described sample information comprises following any one or combination in any: flow statistic, the message number that adds up, byte number, stream update time, sampling time.
Further, said method also can have following feature:
Described VPN is designated the name information of described VPN, and described remote end PE identification is the address information of described far-end PE.
After adopting the present invention, by expanding message template form in the Netflow V9 agreement, traditional Netflow data flow information statistic based on the IP five-tuple can be expanded at the data flow information statistic that arrives the specific PE of certain bar far-end in the VPN, for operator analyzes network traffics in the VPN, message characteristic provides a strong instrument, operator can utilize statistics to optimize in the MPLS VPN network management to flow, carry out on-premise network optimization targetedly, implement traffic engineering, identify abnormal flow, and abnormal flow is implemented stream supervise, thereby guaranteed quality of services for users with more becoming more meticulous.
Description of drawings
Fig. 1 gathers and adds up the method flow diagram of VPN flow for utilizing Netflow in the embodiment of the invention;
Fig. 2 is a kind of typical network environment figure in the embodiment of the invention.
Embodiment
Below in conjunction with drawings and Examples technical scheme of the present invention is described in detail.
Utilize Netflow V9 can expand the characteristic of masterplate, the present invention proposes a kind of masterplate form, and regularly sending to top management server, top management server is resolved the follow-up data message of receiving according to the data format of this masterplate definition, to reach the purpose of statistics VPN flow information.
Before the data flow in the inflow entry PE is gathered, should dispose parameters such as Netflow message version (the present invention requires to dispose the V9 version), aging strategy on this entry PE, also dispose the VPN routing table information, preserve the corresponding relation of each access port VPN identification and remote end PE identification in this routing table, and also have buffer area on this entry PE, be used for the packet information that buffer memory collects.
As shown in Figure 1, may further comprise the steps:
101: entry PE is sampled to the data flow that flows into wherein, and this sampling process can be sampled for stochastical sampling or according to the sampling ratio of configuration it on, and sampling is than the ratio that is the sampling message and E-Packets, as 1 message of sampling when transmitting 1000 messages;
102: this entry PE obtains VPN sign (as VPNNAME) according to the access interface of this data flow, and utilize on it VPN routing table information of preserving, after the sign (as the address information of far-end PE) of the far-end PE that corresponding acquisition is corresponding with this VPN sign, the information of the packet that the buffer memory sampling obtains, wherein, the information of packet comprise packet flow information, flow to information and VPN sign and remote end PE identification; Preferably, the information of this packet can be deposited in the buffer area at information place that belongs to the packet of same data flow with this packet, wherein, the packet of same data flow has identical VPN sign, remote end PE identification and IP five-tuple information;
Behind completing steps 102, can think the gatherer process of having finished a packet information, and after carrying out following step again, be statistic processes.
103: judge whether to satisfy above-mentioned aging strategy, if, execution in step 105, otherwise execution in step 104;
104: upgrade sample information (as any one or the combination in any in flow statistic, the message number that adds up, byte number, stream update time and sampling time), execution in step 101 then;
105: the form to the information of the packet that belongs to same data flow in the buffer area NetflowV9 after according to expansion packages, and the sampling message that obtains behind the group bag is sent to top management server.Should carry the VPN sign and the remote end PE identification of data flow in the sampling message of the Netflow V9 form after the expansion, its template can adopt the form shown in the table 1.
The data format of the Netflow V9 sampling message after table 1 expands
FlowSet?ID=0 The Length=Field Count
TemplateID=1025 Field?Count=14
Field?Type?1=200(VPN_NAME) Field?Length?1=32
Field?Type?2=201(IPV4_RPE_ADDR) Field?Length?2=4
Field?Type?3=8(IPV4_SRC_ADDR) Field?Length?2=4
Field?Type?4=12(IPV4_DST_ADDR) Field?Length?4=4
Field?Type?5=21(LAST_SWITCHED) Field?Length?5=4
Field?Type?6=22(FIRST_SWITCHED) Field?Length?6=4
Field?Type?7=1(IN_BYTES) Field?Length?7=4
Field?Type?8=2(IN_PACKETS) Field?Length?8=4
Field?Type?9=7(L4_SRC_PORT) Field?Length?9=2
Field?Type?10=11(L4_DST_PORT) Field?Length?10=2
Field?Type?11=4(PROTOCOL) Field?Length?11=1
Field?Type?12=6(TCP_FLAGS) Field?Length?12=1
Field?Type?13=60(IP_PROTOCOL_VERSION) Field?Length?13=1
Field?Type?12=5(TOS) Field?Length?14=1
Wherein, the length of each field is 2 bytes in the masterplate; VPN_NAME (being the VPN sign) for operator is the recognizable character string of user access network configuration, is the distinguishing mark of user's VLAN, and length is 1~32 English character; IPV4_RPE_ADDR is the IP address (being remote end PE identification) of the far-end PE in the Virtual Local Area Network for MPLS VPN.Because what entry PE can repeat sends the data package template that carries sampling message data format information as shown in table 1 to top management server, therefore, top management server can be analyzed the sampling message that send on the entry PE according to the data package template that receives.
In sum, add the IP five-tuple information of packet according to the sign of the VPN of entry PE sign and far-end PE the packet that samples is carried out traffic differentiation, refinement the granularity of traffic classification, can accurately add up among certain bar VPN the flow information of certain far-end PE.
Fig. 2 shows typical MPLS VPN network environment.Wherein, as VPN A access carrier network, the public network transmission is carried out by the MPLS backbone network in the centre to user network A by the equipment PE1 of operator.The PE2 of far-end inserts user network C, PE3 inserts user network B, and user network A, B and C belong to VPN A, then the data flow among the VPN A has two paths, be respectively PE1 to PE2 and PE1 to PE3, PE1 can collect the flow information of this two paths respectively and send to top management server by said method, is counted the VPN flow information of each paths by top management server.
Certainly; the present invention also can have other various embodiments; under the situation that does not deviate from spirit of the present invention and essence thereof; those of ordinary skill in the art work as can make various corresponding changes and distortion according to the present invention, but these corresponding changes and distortion all should belong to the protection range of the appended claim of the present invention.

Claims (7)

1, a kind of method of utilizing network flow Netflow collection and counting virtual private VPN flow is characterized in that,
Configuration VPN routing table information is preserved the corresponding relation of access port VPN identification and remote end PE identification in the described routing table on entrance service provider edge-node PE; And the Netflow V9 template message that carries VPN sign and remote end PE identification after will expanding sends to top management server;
Described entry PE is sampled to the data flow that flows into wherein, obtains corresponding VPN sign according to the access interface of described data flow, in conjunction with described VPN routing table information, obtains the sign of far-end PE and the packet information that the buffer memory sampling obtains;
Described entry PE packages and will organize the sampling message that obtains behind the bag according to the Netflow V9 template after expanding described packet information and sends to described top management server;
Described top management server is resolved described sampling message according to the Netflow V9 template message after expanding, and counts the VPN flow.
2, the method for claim 1 is characterized in that, described entry PE is sampled to the data flow that flows into wherein, comprising:
Dispose the sampling ratio on the described entry PE, described entry PE is sampled according to the data flow that described sampling comparison flows into wherein.
3, the method for claim 1 is characterized in that,
The packet information that the buffer memory sampling obtains, comprise: the packet information that described sampling is obtained is cached to the buffer area at information place that belongs to the packet of same data flow with this packet, wherein, the packet that belongs to same data flow has identical VPN sign, remote end PE identification and IP five-tuple information.
4, as claim 1 or 3 described methods, it is characterized in that,
Described packet information comprise this packet flow information, flow to information and VPN sign and remote end PE identification.
5, method as claimed in claim 3 is characterized in that,
Dispose aging strategy on the described entry PE;
Further comprising the steps of before described entry PE packages according to the Netflow V9 form after expanding to described packet information:
Described entry PE judges whether to satisfy aging strategy, if satisfy, the packet information that belongs to same data flow of buffer memory is carried out the subsequent group packet procedures; Otherwise, upgrade sample information, continue the data flow that flows into is wherein sampled.
6, method as claimed in claim 5 is characterized in that,
Described sample information comprises following any one or combination in any: flow statistic, the message number that adds up, byte number, stream update time, sampling time.
7, as claim 1 or 3 described methods, it is characterized in that,
Described VPN is designated the name information of described VPN, and described remote end PE identification is the address information of described far-end PE.
CN2009101263272A 2009-03-03 2009-03-03 Method for collecting and designing VPN flow by using Netflow Active CN101488925B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2009101263272A CN101488925B (en) 2009-03-03 2009-03-03 Method for collecting and designing VPN flow by using Netflow

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2009101263272A CN101488925B (en) 2009-03-03 2009-03-03 Method for collecting and designing VPN flow by using Netflow

Publications (2)

Publication Number Publication Date
CN101488925A true CN101488925A (en) 2009-07-22
CN101488925B CN101488925B (en) 2011-08-24

Family

ID=40891607

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2009101263272A Active CN101488925B (en) 2009-03-03 2009-03-03 Method for collecting and designing VPN flow by using Netflow

Country Status (1)

Country Link
CN (1) CN101488925B (en)

Cited By (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102082727A (en) * 2010-05-28 2011-06-01 烽火通信科技股份有限公司 Packet transport network (PTN) traffic flow management method
CN101631089B (en) * 2009-08-27 2012-04-18 杭州华三通信技术有限公司 Flow calculating method, flow calculating device and flow calculating system based on private network VPN
CN102611626A (en) * 2012-03-30 2012-07-25 北京英诺威尔科技股份有限公司 System and method for analyzing network flow
CN102932285A (en) * 2012-10-26 2013-02-13 华为技术有限公司 Message packaging method and message analysis method and device
CN103957118A (en) * 2014-04-18 2014-07-30 国家电网公司 Real-time intelligent analysis method for network flow of electric power data communication network and system thereof
CN104734981A (en) * 2015-04-11 2015-06-24 广州咨元信息科技有限公司 Device interconnectional relation-based method of precisely recognizing service traffic of MPLS VPN (multi-protocol label switching virtual private network)
CN106470143A (en) * 2016-08-26 2017-03-01 杭州迪普科技股份有限公司 A kind of method and apparatus of MPLS VPN traffic filtering
CN106899443A (en) * 2015-12-18 2017-06-27 北京神州泰岳软件股份有限公司 The acquisition method and equipment of a kind of Netflow datas on flows
CN110191109A (en) * 2019-05-17 2019-08-30 杭州迪普信息技术有限公司 A kind of packet sampling method and device
CN110703817A (en) * 2016-03-29 2020-01-17 华为技术有限公司 Control method, device and system for statistical flow
CN110868352A (en) * 2019-11-14 2020-03-06 迈普通信技术股份有限公司 Private network application identification system and method, SDN controller and P device
CN111131041A (en) * 2019-11-28 2020-05-08 中盈优创资讯科技有限公司 VPN flow obtaining method and device based on NetFlow and BGP
CN111866025A (en) * 2020-08-06 2020-10-30 北京上下文系统软件有限公司 Method for realizing quick decoding of Netflow protocol of V9 version
CN117729054A (en) * 2024-02-07 2024-03-19 北京马赫谷科技有限公司 VPN flow identification method and system based on full flow storage

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100372336C (en) * 2004-07-13 2008-02-27 华为技术有限公司 MPLS VPN and its control and forwarding method

Cited By (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101631089B (en) * 2009-08-27 2012-04-18 杭州华三通信技术有限公司 Flow calculating method, flow calculating device and flow calculating system based on private network VPN
CN102082727B (en) * 2010-05-28 2012-09-26 烽火通信科技股份有限公司 Packet transport network (PTN) traffic flow management method
CN102082727A (en) * 2010-05-28 2011-06-01 烽火通信科技股份有限公司 Packet transport network (PTN) traffic flow management method
CN102611626B (en) * 2012-03-30 2014-11-26 北京英诺威尔科技股份有限公司 System and method for analyzing network flow
CN102611626A (en) * 2012-03-30 2012-07-25 北京英诺威尔科技股份有限公司 System and method for analyzing network flow
CN102932285A (en) * 2012-10-26 2013-02-13 华为技术有限公司 Message packaging method and message analysis method and device
CN102932285B (en) * 2012-10-26 2015-10-21 华为技术有限公司 Message encapsulating method, analytic method and device
CN103957118A (en) * 2014-04-18 2014-07-30 国家电网公司 Real-time intelligent analysis method for network flow of electric power data communication network and system thereof
CN104734981A (en) * 2015-04-11 2015-06-24 广州咨元信息科技有限公司 Device interconnectional relation-based method of precisely recognizing service traffic of MPLS VPN (multi-protocol label switching virtual private network)
CN104734981B (en) * 2015-04-11 2017-10-27 广州咨元信息科技有限公司 A kind of method that MPLS VPN service traffics are accurately recognized based on equipment interconnecting relation
CN106899443A (en) * 2015-12-18 2017-06-27 北京神州泰岳软件股份有限公司 The acquisition method and equipment of a kind of Netflow datas on flows
CN106899443B (en) * 2015-12-18 2020-06-26 北京神州泰岳软件股份有限公司 Netflow flow data acquisition method and equipment
CN110703817A (en) * 2016-03-29 2020-01-17 华为技术有限公司 Control method, device and system for statistical flow
US11716262B2 (en) 2016-03-29 2023-08-01 Huawei Technologies Co., Ltd. Control method, apparatus, and system for collecting traffic statistics
US11381480B2 (en) 2016-03-29 2022-07-05 Huawei Technologies Co., Ltd. Control method, apparatus, and system for collecting traffic statistics
CN106470143A (en) * 2016-08-26 2017-03-01 杭州迪普科技股份有限公司 A kind of method and apparatus of MPLS VPN traffic filtering
CN110191109A (en) * 2019-05-17 2019-08-30 杭州迪普信息技术有限公司 A kind of packet sampling method and device
CN110191109B (en) * 2019-05-17 2021-11-02 杭州迪普信息技术有限公司 Message sampling method and device
CN110868352B (en) * 2019-11-14 2022-04-15 迈普通信技术股份有限公司 Private network application identification system and method, SDN controller and P device
CN110868352A (en) * 2019-11-14 2020-03-06 迈普通信技术股份有限公司 Private network application identification system and method, SDN controller and P device
CN111131041B (en) * 2019-11-28 2022-05-17 中盈优创资讯科技有限公司 VPN flow obtaining method and device based on NetFlow and BGP
CN111131041A (en) * 2019-11-28 2020-05-08 中盈优创资讯科技有限公司 VPN flow obtaining method and device based on NetFlow and BGP
CN111866025A (en) * 2020-08-06 2020-10-30 北京上下文系统软件有限公司 Method for realizing quick decoding of Netflow protocol of V9 version
CN117729054A (en) * 2024-02-07 2024-03-19 北京马赫谷科技有限公司 VPN flow identification method and system based on full flow storage
CN117729054B (en) * 2024-02-07 2024-04-16 北京马赫谷科技有限公司 VPN flow identification method and system based on full flow storage

Also Published As

Publication number Publication date
CN101488925B (en) 2011-08-24

Similar Documents

Publication Publication Date Title
CN101488925B (en) Method for collecting and designing VPN flow by using Netflow
EP3896932B1 (en) Message processing method and network device
US7995477B2 (en) Collecting network traffic information
JP5958570B2 (en) Network system, controller, switch, and traffic monitoring method
CN106101015B (en) Mobile internet traffic class marking method and system
WO2021109610A1 (en) Transmission quality test method and apparatus, system, and storage medium
CN103765839B (en) Variable-based forwarding path construction for packet processing within a network device
JP4774357B2 (en) Statistical information collection system and statistical information collection device
EP3151470B1 (en) Analytics for a distributed network
CN100382517C (en) Network QoS test method and system
US8661292B2 (en) Network communication at unaddressed network devices
WO2015165212A1 (en) Packet processing method, device and computer storage medium
US7869450B2 (en) Method and apparatus for processing labeled flows in a communication access network
CN111953604A (en) Method and device for providing service for service flow
JP2001203691A (en) Network traffic monitor system and monitor method to be used for it
JP5405498B2 (en) Inbound mechanism for monitoring end-to-end QOE of services using application awareness
JP6092409B2 (en) Method and apparatus for evaluating wireless network capillary performance
EP2712130B1 (en) Service control method and system for autonomous network
CN108141387A (en) The length of packet header sampling is controlled
CN105262682B (en) A kind of software defined network system and its traffic grooming method for electric power data communication
KR101364090B1 (en) System and method for traffic account between each ISPs using identification number of ISP network
Fatemipour et al. Design and implementation of a monitoring system based on IPFIX protocol
JP2012151689A (en) Traffic information collection device, network control unit, and traffic information collection method
JP4410432B2 (en) Flow search method
KR100676712B1 (en) Method for discriminating network and classifying traffic of subscribers in order to monitor network in multi-protocol label switching virtual private network

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant