CN101848161A - Communication method and equipment of MPLS L2VPN (Multiple protocol Label Switching Layer 2 Virtual Private Network) and MPLS L3VPN (Multiple protocol Label Switching Layer 3 Virtual Private Network) - Google Patents

Communication method and equipment of MPLS L2VPN (Multiple protocol Label Switching Layer 2 Virtual Private Network) and MPLS L3VPN (Multiple protocol Label Switching Layer 3 Virtual Private Network) Download PDF

Info

Publication number
CN101848161A
CN101848161A CN 201010186818 CN201010186818A CN101848161A CN 101848161 A CN101848161 A CN 101848161A CN 201010186818 CN201010186818 CN 201010186818 CN 201010186818 A CN201010186818 A CN 201010186818A CN 101848161 A CN101848161 A CN 101848161A
Authority
CN
Grant status
Application
Patent type
Prior art keywords
interface
network
l3vpn
mpls
ve
Prior art date
Application number
CN 201010186818
Other languages
Chinese (zh)
Inventor
叶金荣
郜忠华
Original Assignee
杭州华三通信技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date

Links

Abstract

The invention discloses a communication method and equipment of MPLS L2VPN and MPLS L3VPN. The communication between an MPLS L2VPN network and an MPLS L3VPN network can be realized by a uniform VE (Video Engineer) interface by applying the technical scheme of the invention, and thereby, the corresponding operational process is simplified, and since the corresponding strategy settings can be applied in different MPLS L2VPN network types to realize message processing and forwarding, and thereby, the processing efficiency of carrying out message interaction between the MPLS L2VPN network and the MPLS L3VPN network is effectively improved, and the hardware adaptation cost is reduced.

Description

一种MPLSL2VPN和MPLSL3VPN的通信方法和设备 MPLSL2VPN one kind of communication and a method and apparatus MPLSL3VPN

技术领域 FIELD

[0001] 本发明涉及通信技术领域,特别涉及一种MPLS L2VPN和MPLS L3VPN的通信方法和设备。 [0001] The present invention relates to communication technologies, and particularly to a MPLS L2VPN MPLS L3VPN communication method and apparatus.

背景技术 Background technique

[0002]在 MPLS (Multi-Protocol Label Switching,多协议标签交换)L3 (Layerf,三层) VPN(Virtual Private Network,虚拟专用网络)组网结构中进行报文转发的示意图如图1 所示。 Forwarding the message to [0002] in MPLS (Multi-Protocol Label Switching, MPLS) L3 (Layerf, three) VPN (Virtual Private Network, Virtual Private Network) network structure is shown in Fig.1.

[0003] CE (Customer Edge,用户网络边缘设备)通常是一台路由器,当CE与直接相连的PE(Provider Edge,服务提供商网络边缘设备)建立邻接关系后,CE把本节点的VPN路由发布给PE,PE从CE学到CE本地的VPN路由信息后,通过MP-IBGP (Multi-Protocol Internal Border Gateway Protocol,多协议内部边界网关协议)与其它PE交换VPN路由信息。 [0003] CE (Customer Edge, customer edge devices) is usually a router, when the CE and PE (Provider Edge, service provider network edge device) directly connected adjacency is established, the VPN routing node CE release after a PE, PE local VPN routes learned information CE from CE, through MP-IBGP (multi-protocol internal border gateway protocol, multi-protocol internal border gateway protocol) VPN routing information exchange with other PE.

[0004] 当在MPLS骨干网上传输VPN流量时,VPN报文转发采用标签堆栈: [0004] When the backbone network VPN traffic in MPLS, VPN packets are forwarded with the label stack:

[0005] 第一层(外层)标签,在骨干网内部进行交换,指示从PE到对端PE的一条LSP (Label Switched Path,标签交换路径)。 [0005] The first layer (outer layer) label switching inside the backbone network, indication from PE to PE, one pair of ends of LSP (Label Switched Path, LSP).

[0006] 利用这层标签,可以沿LSP到达对端PE ;在采用分层LSP隧道时,可能有多层标签。 [0006] The use of this label, can reach the remote PE along the LSP; when stratified LSP tunnel, there may be multilayered label.

[0007] 第二层(内层)标签,在报文到达对端PE指示报文应被送到哪个CE,也就是对端PE根据内层标签可以找发送报文的出接口。 [0007] The second layer (inner layer) label in the packet to reach the remote PE indicating which packets should be sent CE, i.e. can find peer PE to send packets out of the interface according to the inner label.

[0008] 同样以图1为例,说明VPN报文的转发: [0008] In the same FIG. 1 as an example, to illustrate the VPN packet forwarding:

[0009] (I)Site 1发出一个目的地址为1.1. 1.2的IP报文,由CE 1将报文发送至PE 1。 [0009] (I) Site 1 sends a destination address of IP packets 1.1. 1.2, 1 sends the packet to the PE from the CE 1.

[0010] (2) PE 1根据报文的入接口确定VRF (VPN Routing & Forwarding,虚拟专用网络路由转发),再根据报文IP (Internet Protocol,网络互连协议)目的地址在VRF中查找, 匹配后将报文转发出去,同时打上内层和外层两个标签。 [0010] (2) PE 1 packets into the interface determining VRF (VPN Routing & Forwarding, Virtual Private Network Routing Forwarding), in accordance with another packet IP (Internet Protocol, Internet Protocol) destination address lookup in the VRF, after matching forward the message and adds the inner and outer two labels.

[0011] (3)MPLS网络利用报文的外层标签,将报文传送到PE2,其中,报文在到达PE 2前一跳时已经被剥离外层标签,仅含内层标签。 [0011] (3) MPLS network by outer label packet, transmits the packet to the PE2, wherein packets arriving hop has been peeled off the outer label front PE 2, containing only the inner label.

[0012] (4)PE 2根据内层标签和目的地址查找VPN实例路由表,确定报文的出接口,将报文转发至CE2。 [0012] (4) PE 2 according to the inner label lookup and destination address VPN routing table to determine the outgoing interface forwards the packets to CE2.

[0013] (5) CE 2根据正常的IP转发过程将报文传送到目的地。 [0013] (5) CE 2 according to the normal IP forwarding process transmits the packet to the destination.

[0014] 而在MPLS L2 (Layer2,二层)VPN中,具体分为点对点方式的VPWS (Virtual Private Wire Services,虚拟专用线服务)和点对多点方式的VPLS(Virtual Private LAN Services,虚拟专用局域网服务)的通信方式。 [0014] In MPLS L2 (Layer2, second floor) in the VPN, divided into specific embodiment VPWS point (Virtual Private Wire Services, Virtual Private Wire Services) mode and a multipoint VPLS (Virtual Private LAN Services, Virtual Private LAN service) communication.

[0015] 其中,VPLS通过MAC (Media Access Control,媒体访问控制)地址学习来提供可达性。 [0015] where, VPLS provides reachability by MAC (Media Access Control, MAC) address learning. 每个PE设备会维护一张MAC地址表。 Each PE maintains a MAC address table. VPLS的典型操作是远程MAC地址学习: A typical operation of a remote VPLS MAC address learning:

[0016] PW(Pseudo Wire,虚链路)是由一对单向的VC(Virtual Circuit,虚电路)LSP 组成,其中,只有两个方向的VC LSP都up (被激活)才被认为PW是up的。 [0016] PW (Pseudo Wire, virtual link) is formed by a pair of unidirectional VC (Virtual Circuit, VC) consisting of the LSP, wherein the VC LSP are only two directions up (activated) was only PW is up of. [0017] 当从入方向的VC LSP上收到一个报文时,将报文的源MAC地址与出方向的VC LSP 形成映射关系。 [0017] When receiving a packet from the inbound VC LSP, the VC LSP packet with the source MAC address mapping relationship formed out direction. 如图2所示,实线的箭头表示以太网报文转发路径,当PE2从PWl上收到报文后,会在转发表中添加出端口为PWl的MAC转发表项。 2, solid arrows represent the Ethernet packet forwarding path, when PE2 receives the packets from the PWL, add a port in the forwarding table forwarding entry MAC PWl.

[0018] 报文在PW上发送时,跟L3VPN很类似,需要打上内层标签(PW标签)和外层隧道标签。 [0018] The packets are sent on the PW, L3VPN with very similar needs inner label marked with (PW label) and outer tunnel label. 外层标签主要用于通过隧道中间设备的标签交换,将报文送到对端PE设备,Pff 标签用于当报文达到对端PE后,对端PE能根据PW标签找到对应的VSI (Virtual Switch Instance,虚拟交换实例)。 Outer label by the label switching tunnel is mainly used for the intermediate apparatus, to transmit packets to a peer PE, Pff tag for, when the packet reaches the end of PE, PE peer can find the corresponding VSI based on the PW label (Virtual Switch instance, virtual switching instance).

[0019] 如图3所示,VPWS是VPLS的简化,从CE上来的报文只会在一条PW上转发,而不是像在VPLS中一样,需要查询MAC来决定在哪条PW上转发。 [0019] As shown in FIG. 3, a VPWS is a simplified VPLS, packets come from the CE in a PW forwarding only, rather than as in the VPLS, the need to query the MAC to determine which of the PW forwarding.

[0020] 在现有技术方案中,MPLS以其可靠性高、安全性好、基于IP层面具有好的运行维护能力和支持QoS(Quality of Service,服务质量)等优点,在运营商的接入网中得到广泛的应用。 [0020] In the prior art solutions, MPLS its high reliability, security, and has a good level of IP-based operation and maintenance capacity and support QoS (Quality of Service, Quality of Service), etc., in the operator's access network is widely used.

[0021] L2VPN提供基于MPLS网络的二层VPN服务,在MPLS网络上透明传输用户二层数据,能够为用户提供隧道化的路径,同时减少了中间设备需要维护的LSP链路。 [0021] L2VPN Layer 2 VPN services provide MPLS-based network, the transparent transmission of user data on Layer MPLS network, capable of providing a path for tunneling the user, while reducing the LSP is required to maintain the intermediate apparatus.

[0022] 而通过L2VPN隧道将用户接入公网或承载网的L3VPN业务,可以减少接入网设备中需要维护的用户信息,从而在接入网中使用较低端的设备,降低了组网成本。 [0022] tunneling through the L2VPN L3VPN service users accessing the public network or bearer network, the user information may be reduced in the access network device need to be maintained, so that the lower end of the apparatus used in the access network, the networking cost is reduced . 接入网对用户来说是透明的,用户好像以直连方式接入公网或L3VPN,使组网方式更加灵活。 The access network is transparent to the user, if the user to direct access to the public network or an L3VPN manner, so that more flexible networking.

[0023] 相应的,VPffS和VPLS接入到L3VPN的典型组网如图4所示。 Typical Networking [0023] appropriate, VPffS access to L3VPN and VPLS shown in Figure 4.

[0024] 现有技术中实现MPLS L2VPN和MPLS L3VPN通信的方案如下: [0024] prior art and to realize MPLS L2VPN MPLS L3VPN communication protocol is as follows:

[0025] (1) PE上需要建立一个虚拟二层接口,用以建立和用户的L2VPN业务,用以终结用户的L2VPN报文。 Need to build on [0025] (1) PE a virtual Layer 2 interfaces, and users to establish L2VPN service to the end user of L2VPN packets.

[0026] (2) PE上需要建立一个虚拟三层接口,绑定到L3VPN的VRF中,用以进行用户私网报文的三层转发。 We need to establish a [0026] (2) PE Layer a virtual interface is bound to the L3VPN VRF, the private network for performing Layer 3 forwarding packets.

[0027] (3)将上述虚拟二层接口和虚拟三层接口捆绑形成VE Group (VirtualEthernet Group,虚拟以太网组),实现L2VPN报文终结后接入L3VPN。 [0027] (3) The virtual interface and the virtual Layer Layer interfaces bundling VE Group (VirtualEthernet Group, virtual Ethernet group), to achieve the L2VPN packets are terminated access L3VPN.

[0028] 虚拟的二层接口和虚拟三层接口都使用VE (Virtual Ethernet,虚拟以太网)接口,配置VE Group时可以指定此接口为二层VE接口(实现VE Group 二层终结)或者是三层VE接口(实现VE Group的三层接入)。 [0028] virtual Layer 2 interfaces and virtual interfaces using a three-VE (Virtual Ethernet, virtual Ethernet) interface when configuring VE Group can specify this interface is a VE Interface Layer (Layer achieve VE Group termination) or three VE interface layer (three layers to achieve access Group VE). 一个VE Group中只允许一个二层VE主接口和一个三层VE主接口绑定,其中,一个三层VE接口可以创建多个三层VE子接口,用以进行Dotlq (—种VLAN的封装类型)终结,而L2VPN仅可以配置在二层VE主接口上。 A VE allows only a Group Layer Layer VE VE main interface and a master interface bindings, wherein a plurality of Layer Layer VE interface can create sub-VE interfaces for performing Dotlq (- VLAN encapsulation type species ) termination, but only L2VPN Layer VE may be disposed on the primary interface.

[0029] 比如: [0029] For example:

[0030] Interface VEl [0030] Interface VEl

[0031] 关联L2VPN [0031] associated L2VPN

[0032] Interface VE2 [0032] Interface VE2

[0033] 关联L3VPN VPNA [0033] associated L3VPN VPNA

[0034] Interface VE2. 1 #VE 逻辑接口的子接口 [0034] Interface VE2. 1 sub-interface is a logical interface #VE

[0035] 关联L3VPN VPNB [0035] associated L3VPN VPNB

[0036] VE Group # 创建一个VE 组 [0036] VE Group # Create a VE group

[0037] Interface VEl[0038] Interface VE2 [0037] Interface VEl [0038] Interface VE2

[0039] 其中,VE Group中的转发原理如图5所示,在VE Group中,只有一个二层VE接口和一个三层VE接口绑定,而三层VE接口可以有多个子接口用作Dotlq或QinQ终结。 [0039] wherein, in the forwarding Group VE principle as shown in Group VE, only a VE interface and a Layer Layer 5 interface binding VE, VE interface and three sub-interfaces can be used multiple Dotlq or QinQ termination.

[0040] 在实现本发明的过程中,发明人发现现有技术至少存在以下问题: [0040] During the implementation of the present invention, the inventors found that the prior art has at least the following problems:

[0041] 现有技术配置比较复杂,对于硬件转发的产品,驱动适配也比较复杂,因为硬件存储的转发表项信息往往都要求组合各种配置的信息,一次生成,而不是每条配置单独填写, 因此每条配置引发的联动比较多。 [0041] The prior art is complicated to configure the hardware for forwarding the products, adapted to drive more complex, because the hardware forwarding entries stored information often requires a combination of various configurations, once generated, each configured separately instead of fill out, so more of each configuration caused linkage.

[0042] 另外转发处理过程,可能因为涉及环节和查找的表项较多,因此转发速度效率比较低。 [0042] In addition to forward the process, probably because it involves many links and entries to find, so the efficiency is relatively low forward speed.

发明内容 SUMMARY

[0043] 本发明提供一种MPLS L2VPN和MPLS L3VPN的通信方法和设备,实现MPLS L2VPN 和MPLS L3VPN之间的互通。 [0043] The present invention provides an MPLS L2VPN and MPLS L3VPN communication method and apparatus, to implement interworking between MPLS L2VPN and MPLS L3VPN.

[0044] 为达到上述目的,本发明一方面提供了一种MPLS L2VPN和MPLSL3VPN的通信方法,应用于同时包括MPLS L2VPN网络和MPLS L3VPN网络的系统中,所述MPLS L2VPN网络和MPLS L3VPN网络之间通过NPE设备相连接,所述NPE设备上包括一个VE接口,其中,所述VE接口通过PW与所述MPLS L2VPN网络中的网络设备相连接,所述VE接口还与MPLSL3VPN 网络的L3VPN实例进行关联,并为所述L3VPN实例建立相应的路由转发表,所述方法具体包括以下步骤: [0044] To achieve the above object, an aspect of the present invention provides a communication method and MPLS L2VPN MPLSL3VPN, which is applied while the system comprising a network and a MPLS L3VPN L2VPN MPLS network, the MPLS network and the MPLS L3VPN between L2VPN Network NPE apparatus connected by the NPE device comprises a VE interface, wherein the VE interface is connected to the MPLS L2VPN PW via the network the network device, the VE interface also associated with a network L3VPN instance MPLSL3VPN and forwarding to the corresponding route establishing L3VPN instance, the method comprises the steps of:

[0045] 当所述NPE设备接收到所述MPLS L2VPN网络中的网络设备通过PW发送给所述VE 接口的报文时,所述NPE设备根据所述报文中的标识信息确定相对应的VE接口,并根据所述VE接口所关联的L3VPN实例的路由转发表进行所述报文的转发; [0045] When the device receives the NPE network MPLS L2VPN network device sends the packet to the VE interface when the PW, the NPE VE corresponding to the determined device according to the packet identification information interface and the forwarding table to forward packets associated with the routing L3VPN the VE interface instance;

[0046] 当所述NPE设备接收到所述MPLS L3VPN网络的L3VPN实例发送的报文时,所述NPE设备确定所述报文的目的IP地址在所述L3VPN实例的路由转发表中对应的转发信息, 并根据所述转发信息选择相对应的PW,通过所述PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 [0046] When the packet L3VPN instance NPE MPLS L3VPN apparatus receives the transmitted network, the apparatus determines NPE of the packet destination IP address forwarding table corresponding to the routing forwarding instance L3VPN information, and corresponding PW according to the forwarding information selected, for forwarding the packet to the MPLS L2VPN network via the network device PW.

[0047] 优选的, [0047] Preferably,

[0048] 所述VE接口还与MPLS L3VPN网络的L3VPN实例进行关联,并为所述L3VPN实例建立相应的路由转发表,具体为: [0048] The VE interface and also L3VPN MPLS L3VPN instance associated network, and establish the appropriate route for example by the L3VPN forwarding, specifically:

[0049] 当所述VE接口需要与MPLS L3VPN网络的多个L3VPN实例进行关联时,所述VE接口中进一步包含多个子接口,各所述子接口与MPLS L3VPN网络的各L3VPN实例进行关联, 并为各所述L3VPN实例建立相应的路由转发表。 [0049] When the VE interface needs to be associated with a plurality of network MPLS L3VPN L3VPN instance, the VE interface further comprises a plurality of sub-interfaces, each of the examples of each sub L3VPN MPLS L3VPN network interface associating, and up the corresponding route for the forwarding of the L3VPN instance.

[0050] 优选的,所述NPE设备上包括一个VE接口,具体为: [0051 ] 所述NPE设备通过接口配置命令创建一个VE接口; [0050] Preferably, said device comprising a NPE VE interface, in particular: [0051] The device creates a NPE VE interface configuration commands via the interface;

[0052] 所述NPE设备为所述VE接口配置物理接口属性参数; [0052] The device is a NPE interface configuration parameters of the physical properties of VE interfaces;

[0053] 所述NPE设备为所述VE接口分配识别标签,并建立所述识别标签与所述VE接口的对应关系; [0053] The NPE dispensing apparatus is the VE interface identification tags, and establishing a correspondence between said identification tag VE interface;

[0054] 所述NPE设备为所述VE接口的各子接口建立识别信息,并建立所述识别信息与所述子接口的对应关系。 [0054] The equipment of the respective sub-NPE VE establish the interface to the identification information, and establish a corresponding relationship between the identification information and the sub-interface. [0055] 优选的,所述VE接口通过PW与所述MPLS L2VPN网络中的网络设备相连接,具体为: [0055] Preferably, the VE interface is connected to the network via a network PW apparatus MPLS L2VPN, specifically:

[0056] 所述NPE设备确定所述VE接口需要连接的所述MPLS L2VPN网络中的网络设备, 所述NPE设备将所述VE接口的识别标签通过PW标签分发协议消息发送给所述MPLS L2VPN 网络中的网络设备,并建立所述VE接口与所述MPLS L2VPN网络中的网络设备之间的PW,以所述识别标签作为所述PW的PW标签; [0056] The apparatus determines the VE interfaces NPE MPLS L2VPN the network to be connected in a network device, the device, the identification tag NPE VE interface PW label distribution protocol messages sent to the network MPLS L2VPN network devices, and PW is established between the VE interface and the network devices in the network MPLS L2VPN, to the identification tag as the PW label of the PW;

[0057] 所述VE接口中进一步包含多个子接口,各所述子接口与MPLS L3VPN网络的各L3VPN实例进行关联,并为各所述L3VPN实例建立相应的路由转发表,具体为: [0057] The VE interface further comprises a plurality of sub-interfaces, each of the examples of each sub L3VPN MPLS L3VPN network interface associate and establish the appropriate routing for the forwarding of the L3VPN instance, specifically:

[0058] 所述NPE设备将所述VE接口的部分或全部子接口分别确定为各MPLSL3VPN网络的独占接口,将所述子接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN 实例建立相应的路由转发表。 [0058] The NPE, the VE interface part or all of the sub-interfaces are determined to be exclusive of each MPLSL3VPN network interfaces, the sub-interface instance with a respective MPLS L3VPN L3VPN network association, and examples for the L3VPN establish the appropriate routing and forwarding table.

[0059] 优选的,如果所述VE接口中包括多个子接口,当所述NPE设备接收到所述MPLS L2VPN网络中的网络设备通过PW发送给所述VE接口的报文时,所述NPE设备根据所述报文中的标识信息确定相对应的VE接口,并根据所述VE接口所关联的L3VPN实例的路由转发表进行所述报文的转发,具体为: [0059] Preferably, if the VE interface includes a plurality of sub-interfaces, when the apparatus receives the NPE MPLS L2VPN network device sends network packets to the VE interface through the PW, the apparatus NPE determining from the packet identification information corresponding to the VE interface, and the forwarding table to forward packets according to the routing L3VPN instance associated with the VE interface, in particular:

[0060] 当所述MPLS L2VPN网络具体为VPLS时,所述NPE设备根据所述报文的PW标签确定所述报文所对应的VE接口,并判断所述报文的目的MAC地址与所述VE接口的物理接口属性参数中的MAC地址信息是否相同,如果相同,则分析所述报文的报文头获取标识信息, 将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,并根据匹配成功的子接口所关联的L3VPN实例的路由转发表,通过所述子接口对所述报文进行IP转发,如果不相同,则查找MAC转发表,对所述报文进行MAC转发; [0060] When the MPLS L2VPN specifically to the VPLS network, the apparatus according to the NPE PW label of the packet to determine the packet corresponding VE interfaces, and determine whether the packet destination MAC address and the physical properties of the interface parameters of the VE interface is the same MAC address information, if the same, then the analysis of the packet header identification information is acquired, the identification information of each sub-interface and the identification information for the VE interface matching, forwarding and routing of the associated instance L3VPN successful matching sub-interface in accordance with the forwarding of IP packets via the sub-interface, if not identical, the MAC forwarding table lookup, the packet MAC forwarding;

[0061 ] 当所述MPLS L2VPN网络具体为VPWS时,所述NPE设备根据所述报文的PW标签确定所述报文所对应的VE接口,并分析所述报文的报文头获取标识信息,将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,并根据匹配成功的子接口所关联的L3VPN实例的路由转发表,通过所述子接口对所述报文进行IP转发。 [0061] When the MPLS L2VPN network VPWS specifically, the NPE device PW label of the packet to determine the packet corresponding to the VE interface, and analyzes the packet header in accordance with the identification information acquired , the identification information with the identification information of each sub-VE interface interfaces matches, routing and forwarding instance associated L3VPN successful matching sub-interface according to the IP packets by the said sub-interface forwarding.

[0062] 优选的,当所述NPE设备接收到所述MPLS L3VPN网络的L3VPN实例发送的报文时, 所述NPE设备确定所述报文的目的IP地址在所述L3VPN实例的路由转发表中对应的转发信息,并根据所述转发信息选择相对应的PW,通过所述PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发,具体为: [0062] Preferably, when the packet L3VPN instance NPE MPLS L3VPN apparatus receives the transmitted network, the apparatus determines NPE of the packet destination IP address in said L3VPN example of the routing tables forwarding information corresponding to the selection according to the forwarding information corresponding to the PW,, for forwarding the packet to the MPLS L2VPN network device through the network the PW, in particular:

[0063] 所述NPE设备学习所述MPLS L2VPN网络中的网络设备所对应的ARP信息,所述ARP信息至少包括所述MPLS L2VPN网络中的网络设备与目的终端相连接的接口的IP地址和MAC地址; [0063] ARP information of the MPLS L2VPN NPE apparatus learns the network corresponding to the network device, the ARP information includes at least the IP address of the network interface device and the destination terminal to the network MPLS L2VPN connected and MAC address;

[0064] 所述NPE设备根据所述MPLS L3VPN网络的L3VPN实例发送的报文的目的IP地址在所述L3VPN实例的路由转发表中确定所述报文的出接口和下一跳信息; [0064] The IP address of the destination transmission apparatus according NPE Examples of MPLS L3VPN L3VPN network packet routing in the L3VPN instance determining the packet outbound interface and next hop forwarding table;

[0065] 所述NPE设备根据所述报文的出接口和下一跳信息获取相对应的ARP信息,通过所述ARP信息对所述报文进行封装,并选择相对应的PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 [0065] obtaining the corresponding NPE apparatus according to the ARP information of the outgoing interface and next hop information carried by the package of the ARP packet information and the PW corresponding to the selection, to the MPLS L2VPN network devices of the network to forward packets.

[0066] 另一方面,本发明还提供了一种NPE设备,应用于同时包括MPLS L2VPN网络和MPLS L3VPN网络的系统中,所述MPLS L2VPN网络和MPLS L3VPN网络之间通过NPE设备相连接,其特征在于,包括: [0066] another aspect, the present invention also provides an apparatus NPE applied while the system comprising a network and a MPLS L3VPN L2VPN MPLS network, the MPLS NPE between devices connected by a network and MPLS L3VPN L2VPN network, which characterized by comprising:

[0067] 设置模块,用于创建一个VE接口,其中,所述VE接口通过PW与所述MPLS L2VPN 网络中的网络设备相连接,并与MPLSL3VPN网络的L3VPN实例进行关联,并为L3VPN实例建立相应的路由转发表; [0067] The setting module configured to create a VE interface, wherein the VE interface is connected via the MPLS L2VPN PW network equipment network, and associated with the instance MPLSL3VPN L3VPN network, and to establish the corresponding instance L3VPN the routing and forwarding table;

[0068] 处理模块,与所述设置模块相连接,用于当接收到所述MPLS L2VPN网络中的网络设备通过PW发送给所述VE接口的报文时,在所述设置模块所设置的VE接口的子接口中, 根据所述报文中的标识信息确定相对应的子接口,或当接收到所述MPLS L3VPN网络中的网络设备发送的报文时,确定所述报文的目的IP地址在所述L3VPN实例的路由转发表中对应的转发信息,在所述设置模块所设置的VE接口相连的PW中,根据所述转发信息选择相对应的PW; [0068] The processing module, connected to said setting module configured to, when receiving the MPLS L2VPN network device sends network packets to the VE interface through the PW, the setting module in the set VE interface, sub-interface, determining the corresponding sub-interface according to the packet identification information, or when the received message sent by the network MPLS L3VPN network, determines the destination address of the IP packet examples of the L3VPN routing forwarding table forwarding information corresponding to at PW VE interface connected to the setting module in the set, according to the forwarding information corresponding to the selection of the PW;

[0069] 转发模块,与所述处理模块相连接,用于根据所述所述处理模块所确定的子接口所关联的L3VPN实例的路由转发表进行所述报文的转发,或通过所述处理模块所选择的PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 [0069] The forwarding module, connected to the processing module for routing the L3VPN instance the processing module associated with the determined sub-interface forwarding the packet to be forwarded, or by the process selected module PW, for forwarding the packet to the MPLS L2VPN network devices in a network.

[0070] 优选的,当所述VE接口需要与MPLS L3VPN网络的多个L3VPN实例进行关联时,所述设置模块,还用于用于在所述VE接口创建多个子接口,各所述子接口与MPLS L3VPN网络的各L3VPN实例进行关联,并为各所述L3VPN实例建立相应的路由转发表。 [0070] Preferably, when the VE interface needs to be associated with a plurality of network MPLS L3VPN L3VPN example, the setting module is further configured to create a VE interface for the multiple sub-interfaces, each of said sub-interface for instance with the L3VPN MPLS L3VPN associated network, and establish the appropriate routing for the L3VPN forwarding instance.

[0071] 优选的,所述设置模块,用于创建一个VE接口,具体为: [0071] Preferably, the setting module is configured to create a VE interface, in particular:

[0072] 所述设置模块通过接口配置命令创建一个VE接口; [0072] The module creates a VE interface provided by the interface configuration commands;

[0073] 所述设置模块为所述VE接口配置物理接口属性参数; [0073] The setting module is a physical interface to the VE interface attributes parameter;

[0074] 所述设置模块为所述VE接口分配识别标签,并建立所述识别标签与所述VE接口的对应关系; [0074] The setting of the VE interface module is assigned an identification tag, and establishing a correspondence between said identification tag VE interface;

[0075] 所述设置模块为所述VE接口的各子接口建立识别信息,并建立所述识别信息与所述子接口的对应关系。 [0075] The setting of each sub-module interfaces to the VE interface to establish identification information, and establish a corresponding relationship between the identification information and the sub-interface.

[0076] 优选的,所述设置模块确定所述VE接口需要连接的所述MPLS L2VPN网络中的网络设备,将所述VE接口的识别标签通过PW标签分发协议消息发送给所述MPLS L2VPN网络中的网络设备,并建立所述VE接口与所述MPLSL2VPN网络中的网络设备之间的PW,以所述识别标签作为所述PW的PW标签; [0076] Preferably, the setting module determines the need to connect the VE interface network MPLS L2VPN network device, sending the VE interface identification tag the PW label distribution protocol message to the network MPLS L2VPN network equipment, and the establishment of the PW between the VE interface and the network devices in the network MPLSL2VPN to the identification tag as the PW, PW label;

[0077] 所述设置模块将所述VE接口的部分或全部子接口分别确定为各MPLSL3VPN网络的独占接口,将所述子接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN 实例建立相应的路由转发表。 [0077] The module is provided to the VE interface part or all of the sub-interfaces are determined to be exclusive of each MPLSL3VPN network interfaces, the sub-interface instance with a respective MPLS L3VPN L3VPN network association, and examples for the L3VPN establish the appropriate routing and forwarding table.

[0078] 优选的,当接收到所述MPLS L2VPN网络中的网络设备通过PW发送的报文时,所述转发模块,用于根据所述所述处理模块所确定的子接口所关联的L3VPN实例的路由转发表进行所述报文的转发,具体为: [0078] Preferably, when receiving a packet network in the MPLS L2VPN network device transmitted through the PW, the forwarding module, for example L3VPN module associated with the determined sub-interface according to the process route forwarding table of the packet forwarding, in particular:

[0079] 如果所述MPLS L2VPN网络具体为VPLS,所述处理模块根据所述报文的PW标签确定所述报文所对应的VE接口,并判断所述报文的目的MAC地址与所述VE接口的物理接口属性参数中的MAC地址信息是否相同,如果相同,则分析所述报文的报文头获取标识信息, 将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,所述转发模块通过所述处理模块匹配成功的子接口所关联的L3VPN实例的路由转发表,对所述报文进行IP转发, 如果不相同,则查找MAC转发表,由所述转发模块将所述报文进行MAC转发;[0080] 如果所述MPLS L2VPN网络具体为VPWS,所述处理模块根据所述报文的PW标签确定所述报文所对应的VE接口,并分析所述报文的报文头获取标识信息,将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,并由所述转发模块通过所述处理模块匹配成功的子接口 [0079] Specifically, if the MPLS L2VPN to the VPLS network, the processing module determines that the packet corresponding to the VE interfaces of the packet according to a PW label, and determines whether the destination MAC address of the packet with the VE MAC address of the physical attribute parameters of the interface in the interface information is the same, if the same, then the analysis of the packet header obtain identification information, the identification information for identifying each sub-interface information with the VE interface matches the forwarding module by matching the processing module associated routing L3VPN successful example of sub-interface forwarding, the IP packet forwarding, if not identical, the MAC forwarding table lookup by the forwarding module the MAC packet forwarding; [0080] specifically, if the network is MPLS L2VPN VPWS, the processing module determines that the packet corresponding to the VE interfaces of the packet according to a PW label, and the packet analyzing packet header identification information acquired, the identification information of each sub-interface and the identification information matching the VE interface, by the forwarding module successfully matched by the processing module subinterface 关联的L3VPN实例的路由转发表,对所述报文进行IP转发。 L3VPN routing instances associated with the forwarding of the IP packet forwarding.

[0081] 优选的,当接收到所述MPLS L3VPN网络中的网络设备发送的报文时,所述转发模块,用于通过所述处理模块所选择的PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发,具体为: [0081] Preferably, when the received message sent by the network MPLS L3VPN network, the forwarding module, the processing module for PW by the selected network to the MPLS L2VPN Network the apparatus for packet forwarding, specifically:

[0082] 所述处理模块学习所述MPLS L2VPN网络中的网络设备所对应的ARP信息,所述ARP信息至少包括所述MPLS L2VPN网络中的网络设备与目的终端相连接的接口的IP地址和MAC地址; [0082] The learning processing module ARP information L2VPN network corresponding to the network device MPLS, the ARP information includes at least the IP address of the interface network MPLS L2VPN network device and the destination terminal is connected and a MAC address;

[0083] 所述处理模块根据所述MPLS L3VPN网络的L3VPN实例发送的报文的目的IP地址在所述L3VPN实例的路由转发表中确定所述报文的出接口和下一跳信息; [0083] The processing module interface, and a next hop of the packet destination IP address of the MPLS L3VPN L3VPN instance sends network packets in said L3VPN instance determined according to the routing tables;

[0084] 所述处理模块根据所述报文的出接口和下一跳信息获取相对应的ARP信息,所述转发模块通过所述ARP信息中的MAC地址对所述报文进行二层封装,再通过所述ARP信息所指定的PW向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 [0084] The processing module obtaining information corresponding to the ARP packet according to the outgoing interface and next hop, the forwarding module through the MAC address information in the ARP packet Layer 2 encapsulation, then forwarding the packet to the MPLS L2VPN network device through the network ARP information designated PW.

[0085] 与现有技术相比,本发明具有以下优点: [0085] Compared with the prior art, the present invention has the following advantages:

[0086] 通过应用本发明的技术方案,可以通过统一的VE接口实现MPLS L2VPN网络和MPLS L3VPN网络之间的通信,简化了相应的操作流程,并且由于在不同的MPLS L2VPN网络类型中均可以应用相应的策略设置实现报文处理和转发,有效的提高了MPLS L2VPN网络和MPLS L3VPN网络之间进行报文交互的处理效率,降低了硬件适配成本。 [0086] By applying the technical solution of the present invention can be realized between the communication network and the MPLS L3VPN L2VPN MPLS network through a unified interface to VE, the corresponding operation is simplified processes, and since both can be used in different types of networks in MPLS L2VPN the appropriate policy settings to achieve packet processing and forwarding, effectively improve the processing efficiency to exchange messages between the network and MPLS L2VPN MPLS L3VPN network, reducing hardware adaptation costs.

附图说明 BRIEF DESCRIPTION

[0087] 图1为现有技术中VPN报文转发的示意图; [0087] FIG. 1 is a schematic diagram of the prior art VPN message forwarding;

[0088] 图2为现有技术中VPLS网络的报文转发示意图; [0088] FIG. 2 is a schematic view of forwarding packets prior art VPLS network;

[0089] 图3为现有技术中VPWS网络的报文转发示意图; [0089] FIG. 3 is a schematic view of forwarding packets VPWS prior art network;

[0090] 图4为现有技术中VPWS接入L3VPN的组网结构示意图 [0090] FIG. 4 is a schematic networking structure of the prior art L3VPN access VPWS

[0091] 图5为现有技术中VE Group中的报文转发示意图; [0091] FIG. 5 is a schematic view of the prior art forward VE Group of packets;

[0092] 图6为本发明所提出的一种MPLS L2VPN和MPLS L3VPN的通信方法的流程示意图; Flow communication method [0092] FIG. 6 of the present invention proposed a MPLS L2VPN and MPLS L3VPN schematic;

[0093] 图7为本发明所提出的一种具体应用场景下MPLS L2VPN和MPLSL3VPN的通信方法的流程示意图; MPLSL3VPN L2VPN and MPLS communication method in the one specific application scenario [0093] Figure 7 is a schematic flow diagram of the proposed invention;

[0094] 图8为本发明所提出的一种具体应用场景下MPLS L2VPN和MPLSL3VPN的通信方法的流程示意图 [0094] MPLS L2VPN communication method and the MPLSL3VPN schematic flow chart of a specific application scenario of FIG. 8 of the present invention proposed

[0095] 图9为本发明所提出的一种NPE设备的结构示意图。 [0095] FIG. 9 NPE configuration diagram of an apparatus of the present invention proposed. 具体实施方式 detailed description

[0096] 针对现有技术中的不足,需要提出一种方法,通过在NPE设备中配置VE接口来实现MPLS L2VPN网络和MPLS L3VPN网络的通信。 [0096] For the prior art deficiencies, a need for a method to implement the communication network and the MPLS L2VPN MPLS L3VPN network through NPE disposed in the VE interface device.

[0097] 基于上述目的,本发明提出了一种MPLS L2VPN和MPLS L3VPN的通信方法,应用于同时包括MPLS L2VPN网络和MPLS L3VPN网络的系统中,MPLS L2VPN网络和MPLS L3VPN 网络之间通过NPE设备相连接,NPE设备上包括一个VE接口,其中,VE接口通过PW与MPLS L2VPN网络中的网络设备相连接,该VE接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为L3VPN实例建立相应的路由转发表。 [0097] Based on the above-described object, the present invention proposes a communication method and the MPLS L3VPN MPLS L2VPN, MPLS L2VPN simultaneously applied in a system comprising a network and a MPLS L3VPN network, between the network and MPLS L2VPN MPLS L3VPN network through NPE device relative connection, the NPE device comprises a VE interface, wherein, the VE interface connected by PW and MPLS L2VPN network network device, the VE interface and the L3VPN instance corresponding MPLS L3VPN network association, and establish the appropriate routing for the L3VPN instance forwarding.

[0098] 如图6所示,为本发明所提出的一种MPLS L2VPN和MPLS L3VPN的通信方法的流程示意图,具体包括以下步骤: [0098] A schematic flow chart of a communication method and MPLS L2VPN MPLS L3VPN shown in Figure 6, the present invention proposes, includes the following steps:

[0099] 步骤S601、NPE设备配置VE接口。 [0099] Step S601, NPE VE interface device configuration. [0100] 该VE接口实现了MPLS L2VPN网络和MPLS L3VPN网络的互连,一方面,该VE接口通过PW与所述MPLS L2VPN网络中的网络设备相连接,另一方面,该VE接口与MPLS L3VPN 网络的L3VPN实例进行关联,并且,在VE接口中为该L3VPN实例建立相应的路由转发表。 [0100] The VE interface and network interconnection MPLS L2VPN MPLS L3VPN network, on the one hand, the VE interface is connected to the MPLS L2VPN PW via the network the network device, on the other hand, the VE interface and the MPLS L3VPN examples of associate L3VPN network, and establish the appropriate routing for the VE interface L3VPN forwarding instance.

[0101] 在具体的应用场景中,当所述VE接口需要与MPLS L3VPN网络的多个L3VPN实例进行关联时,该VE接口中进一步包含多个子接口,各子接口与MPLS L3VPN网络的各L3VPN 实例进行关联,并在VE接口中为各L3VPN实例建立相应的路由转发表。 [0101] In a specific application scenario, when the VE interface needs to be associated with a plurality of network MPLS L3VPN L3VPN instance, the VE interface further comprises a plurality of sub-interfaces, each instance of each sub L3VPN MPLS L3VPN network interface association and establish the appropriate routing for the VE interface L3VPN instance forwarding table.

[0102] 需要进一步指出的是,如果NPE设备中的VE接口只需要跟一个MPLSL3VPN实例进行关联,那么,在VE接口中可以不再建立多个子接口,而是将VE接口直接与该L3VPN相关联,这样,在转发时,无需分辨向哪个L3VPN实例进行转发,而当NPE设备所连接的MLPS L3VPN中存在多个MPLS [0102] It is further noted that, if the VE interface device NPE keep only associate a MPLSL3VPN example, then, the VE interface can not establish a plurality of sub-interfaces, but the VE interface directly associated with the L3VPN , so that, when forwarding, which without resolution L3VPN instance to be forwarded, and when there are a plurality MPLS MLPS L3VPN NPE device connected

[0103] L3VPN实例时,VE接口中需要建立多个子接口,并设置各子接口与各L3VPN实例相关联,并对应各子接口,分别为各所述L3VPN实例建立相应的路由转发表。 When [0103] L3VPN example, VE interface need to create a plurality of sub-interfaces, and interfaces with each sub-set L3VPN instance associated and corresponding to the respective sub-interfaces, are established corresponding to each of said L3VPN route forwarding instance.

[0104] 在具体的应用场景中,可以根据NPE设备所关联的MPLS L3VPN网络中的L3VPN实例的数量进行子接口设置的调整,这样的变化并不影响本发明的保护范围。 [0104] In a specific application scenario, the sub-interface settings may be adjusted according to the number of instances L3VPN MPLS L3VPN NPE associated network devices, such changes do not affect the scope of the present invention.

[0105] 为了方便说明,后续实施例中具体以多个子接口的情况为例进行说明。 [0105] For convenience of explanation, in the specific embodiment subsequent to a plurality of sub-interface described as an example.

[0106] 其中,该VE接口的具体配置过程为: [0106] wherein the specific configuration of the VE interface is:

[0107] 首先,NPE设备通过接口配置命令创建一个VE接口,即这个VE接口作为逻辑接口在NPE设备中建立。 [0107] First, the NPE create a VE interface configuration command through the interface, i.e., the VE interface as a logical interface establishing device in NPE.

[0108] 为了实现MPLS L2VPN网络和MPLS L3VPN网络的互连,NPE设备需要为该VE接口配置物理以太网接口的属性,从而,使系统中的其他网络设备可以感知到作为物理接口的该VE接口,并进行相应的物理层转发流程,其中,所配置的物理以太网接口的属性包括例如MAC地址和MTU等参数值。 [0108] In order to achieve the interconnection network and the MPLS L2VPN MPLS L3VPN network, the NPE device needs to configure the VE interface attributes for physical Ethernet interfaces to the other network devices in the system may be perceived as the VE interface physical interface , and the corresponding physical layer forwarding process, wherein the configured physical Ethernet interface attributes parameter values ​​include, for example, a MAC address and the like MTU.

[0109] 一方面,为了建立与MPLS L2VPN网络的互连,NPE设备为VE接口分配识别标签, 作为该VE接口的入标签,并建立识别标签与VE接口的对应关系,从而实现对PW中发往该VE接口的报文的标识。 [0109] In one aspect, in order to establish the interconnection network with MPLS L2VPN, the NPE equipment VE interfaces assigned identification tag, the tag as the VE interface, and establishing corresponding relationship between the identification tag to the VE interface, so that in the hair for a PW the message to the VE interface identifier.

[0110] 另一方面,NPE设备还需要为VE接口的各子接口建立识别信息,并建立识别信息与各子接口的对应关系 [0110] On the other hand, the NPE device further required Interface establish identification information of each sub-VE interface, and to establish identification information of each sub-interface correspondence relationship

[0111] 进一步的,在具体的应用场景中,上述的设置过程中具体的实现方式包括: [0111] Further, in a specific application scenario, the above arrangement specific implementation process comprising:

[0112] NPE设备确定VE接口需要连接的MPLS L2VPN网络中的网络设备,NPE设备将VE 接口的识别标签通过PW标签分发协议消息发送给MPLS L2VPN网络中的网络设备,并建立VE接口与MPLS L2VPN网络中的网络设备之间的PW,以该识别标签作为PW的PW标签,通过这样的设置,可以根据该PW标签对响应的报文进行二层封装,实现MPLS L2VPN网络的报文传输。 [0112] NPE device determines MPLS L2VPN Network VE interfaces to be connected in a network device, the NPE device transmits identification tag VE interface is the PW label distribution protocol message to the MPLS L2VPN network, network devices, and establish VE interface and the MPLS L2VPN PW between the network devices in the network, to the identification tag as the PW PW label, the response packets may be based on the Layer 2 encapsulation PW label With this arrangement, implementing packet transmission network MPLS L2VPN.

[0113] NPE设备将VE接口的部分或全部子接口分别确定为各MPLS L3VPN网络的独占接口,将子接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN实例建立相应的路由转发表。 [0113] NPE device part VE interface or all of the sub-interfaces are determined, the sub-interface L3VPN instance corresponding MPLS L3VPN network to associate an exclusive interface to the respective MPLS L3VPN network, and establish the appropriate routing and forwarding for the L3VPN instance published.

[0114] 由于在前述步骤中已经为各子接口建立了相应的识别信息,因此,在建立了相应的子接口与MPLS L3VPN网络的L3VPN实例的对应关系后,同样可以将上述的识别信息也加与相应的对应关系中,从而,在进行报文的目标网络查询的过程中,也可以通过相匹配的识别信息作为查询依据,具体的,可以将报文中目标网络识别信息与子接口的识别信息相匹配,在匹配成功时,确定相应的子接口所对应的MPLS L3VPN网络的L3VPN实例作为该报文的目标网络查询结果。 After [0114] Since in the preceding step has interface establishes the corresponding identification information for the sub, thus establishing the appropriate correspondence relationship L3VPN example of sub-interface with the MPLS L3VPN network, it may also be the above-mentioned identification information is also added corresponding to the corresponding relationship, so that, during the process of network packet destination query may be matched by the identification information as a query basis. specifically, the packet may be identified target sub-network interface identification information information matches, the matching is successful in determining a respective subinterface L3VPN instance corresponding MPLS L3VPN packet network as the target network query results.

[0115] 步骤S602、NPE设备识别接收到报文的来源。 [0115] Step S602, NPE device identifies the source of the received message.

[0116] 当NPE设备接收到MPLS L2VPN网络中的网络设备通过PW发送的报文时,执行步骤S603 ; [0116] When a device receives a packet NPE MPLS L2VPN network via the network device sends PW, executing step S603;

[0117] 当NPE设备接收到MPLS L3VPN网络的L3VPN实例发送的报文时,执行步骤S604。 [0117] When a packet received by the NPE example L3VPN MPLS L3VPN network transmitted, step S604.

[0118] 步骤S603、NPE设备根据该报文中的标识信息确定相对应的子接口,并根据该子接口所关联的L3VPN实例的路由转发表进行所述报文的转发。 [0118] Step S603, NPE device corresponding to the determined sub-interface according to the identification information of the packet and the forwarding table to forward packets based on the routing L3VPN associated with the sub-interface instance.

[0119] 在本步骤中,根据MPLS L2VPN网络的类型,具体分为以下两种情况: [0119] In this step, depending on the type of network MPLS L2VPN, particularly the following two cases:

[0120] 情况一、当MPLS L2VPN网络具体为VPLS时,对该报文进行了标签弹出处理,根据该报文中所携带的VE接口入标签,确定该报文确实是向VE接口发送的报文。 [0120] a case, particularly when the network is MPLS L2VPN the VPLS, the label of the packet has been ejection processing according to the VE interface tag carried in the packet, the packet is indeed determined packets sent to the VE interface Wen.

[0121] 进一步根据该报文的目的MAC地址确定该报文是在MPLS L2VPN网络中进行转发还是需要向MPLS L3VPN网络进行报文发送,由于在MPLSL2VPN网络中的网络设备看来,NPE 设备相当于一个网关设备,如果需要向MPLS L3VPN网络进行转发,则目的MAC地址应该设置为该NPE设备的MAC地址,否则,如果该报文是在MPLS L2VPN网络中进行转发,则直接以该MPLS L2VPN网络中的目标网络设备的MAC地址作为该报文的目的MAC地址。 [0121] Further object of the MAC address of the packet to determine the packet needs to be forwarded or transmitted to the packet network in the MPLS L3VPN MPLS L2VPN network, since the network device according to the opinion MPLSL2VPN network, the device corresponds to the NPE a gateway device, if need be forwarded to the MPLS L3VPN network, the destination MAC address should be set to the MAC address of the NPE device. otherwise, if the packet is forwarded in the MPLS L2VPN network, directly to the MPLS L2VPN network MAC address of the target network device as the packet destination MAC address.

[0122] 具体的处理方式是NPE设备判断该报文的目的MAC地址与VE接口的物理接口属性参数中的MAC地址信息是否相同,如果相同,则该报文需要向MPLS L3VPN网络进行转发,因此,NPE设备分析该报文的报文头以获取该报文的目标网络识别信息,将该目标网络标识信息与VE接口中各子接口的标识信息进行匹配,并根据匹配成功的子接口所关联的L3VPN实例的路由转发表,通过子接口对所述报文进行IP转发,如果不相同,则该报文是在MPLSL2VPN网络中进行转发,查找VE接口中存储的MPLS L2VPN网络的MAC转发表,将该报文向目的MAC地址所对应的网络设备进行MAC转发。 [0122] DETAILED processing mode is determined NPE device MAC address destination MAC address of the physical parameters of the interface attributes and the VE interface information in the packet is the same, if the same, then the packet needs to be forwarded to MPLS L3VPN network, , the NPE device analyzes the packet header for the destination network of the packet identification information, identification information of each of the target sub-interface network identification information matches the VE interface and sub-interface in accordance with the associated successful match examples L3VPN route forwarding table, forwarding the IP packets via the sub-interface, if not identical, the packet is forwarded MPLSL2VPN network, to find MAC VE interface MPLS L2VPN forwarding storage network, the message corresponding to the destination MAC address of the MAC forwarding network device.

[0123] 情况二、当MPLS L2VPN网络具体为VPWS时,对该报文进行了标签弹出处理,根据该报文中所携带的VE接口入标签,确定该报文确实是向VE接口发送的报文。 [0123] Case 2, particularly when the network is MPLS L2VPN VPWS, the label of the packet eject processing performed according to the VE interface tag carried in the packet, the packet is indeed determined packets sent to the VE interface Wen.

[0124] 由于在VPWS中,不会出现通过PW向VE接口发送需要在MPLS L2VPN中进行转发的报文,因此,NPE设备直接进行向MPLS L3VPN的转发处理,首先,分析该报文的报文头以获取该报文的目标网络识别信息,将该目标网络标识信息与VE接口中各子接口的标识信息进行匹配,然后,根据匹配成功的子接口所关联的L3VPN实例的路由转发表,通过子接口对所述报文进行IP转发。 [0124] Since the VPWS, PW will not need to send VE interfaces of forwarding packets in the MPLS L2VPN, therefore, the NPE equipment directly forwards the MPLS L3VPN process, first, the packets of the packet analysis head for the destination network of the packet identification information, identification information of each of the target sub-interface network identification information matches the VE interface, and routing of the associated instance L3VPN successfully matched according to sub-interface forwarding, by the sub-interface forwarding IP packets.

[0125] 步骤S604、NPE设备确定该报文的目的IP地址在L3VPN实例的路由转发表中对应的转发信息,并根据该转发信息选择相对应的PW,通过选择的PW向MPLS L2VPN网络中的网络设备进行该报文的转发。 [0125] Step S604, NPE device determines the packet's destination IP address in the L3VPN example routing tables corresponding to forwarding information and corresponding forwarding information selected according to the PW, PW selected by the network to the MPLS L2VPN network equipment for packet forwarding.

[0126] 在进行相应的转发处理之前,首先,NPE设备需要进行ARP学习过程,学习MPLS L2VPN网络中的网络设备所对应的ARP信息,该ARP信息至少包括MPLS L2VPN网络中的网络设备与目的终端相连接的接口的IP地址和MAC地址,该地址信息将作为该报文在MPLS L2VPN中进行转发的目的地址。 [0126] Prior to forwarding the corresponding, first of all, the device requires the NPE ARP learning process, the learning network MPLS L2VPN ARP information of the network device corresponding to the ARP information includes at least the network device and the destination terminal network MPLS L2VPN IP address and MAC address of the interface is connected, the address information as a destination address of the packet forwarding in the MPLS L2VPN.

[0127] 完成上述ARP学习后,NPE设备根据MPLS L3VPN网络的L3VPN实例发送的报文的目的IP地址在所述L3VPN实例的路由转发表中确定所述报文的出接口和下一跳信息,并根据出接口和下一跳信息获取相对应的ARP信息,通过获取到的ARP信息对该报文进行封装, 选择相对应的PW,向MPLSL2VPN网络中的网络设备进行该报文的转发。 [0127] After completing the above ARP study, published in the NPE device determines that the message transfer interface and next hop according to a routing object instance L3VPN IP address of the packet transmitted in the network MPLS L3VPN L3VPN instance, the acquisition and the next hop and the interface information corresponding ARP information, encapsulation, PW corresponding to the selection of the packet acquired by the ARP information, the packet is forwarded to the network device MPLSL2VPN network.

[0128] 与现有技术相比,本发明具有以下优点: [0128] Compared with the prior art, the present invention has the following advantages:

[0129] 通过应用本发明的技术方案,可以通过统一的VE接口实现MPLS L2VPN网络和MPLS L3VPN网络之间的通信,简化了相应的操作流程,并且由于在不同的MPLS L2VPN网络类型中均可以应用相应的策略设置实现报文处理和转发,有效的提高了MPLS L2VPN网络和MPLS L3VPN网络之间进行报文交互的处理效率,降低了硬件适配成本。 [0129] By applying the technical solution of the present invention can be realized between the communication network and the MPLS L3VPN L2VPN MPLS network through a unified interface to VE, the corresponding operation is simplified processes, and since both can be used in different types of networks in MPLS L2VPN the appropriate policy settings to achieve packet processing and forwarding, effectively improve the processing efficiency to exchange messages between the network and MPLS L2VPN MPLS L3VPN network, reducing hardware adaptation costs.

[0130] 为了进一步阐述本发明的技术思想,现结合具体的应用场景,对本发明的技术方案进行说明。 [0130] To further clarify the technical idea of ​​the present invention are combined with a specific application scenario, for the technical solution of the invention will be described.

[0131] 首先,为了实现上述的技术方案,需要在NPE设备上进行虚拟的互通接口的设置, 即在NPE设备上设置一个虚拟以太网接口(VE接口),为了让系统中的其它网络设备能够与该VE接口进行通信,需要为VE接口设置物理层状态和链路层状态,即进行相应的物理接口参数配置。 [0131] First, in order to achieve the above technical solution, the need for a virtual interface provided in the NPE interworking device, i.e. set up a virtual Ethernet interface (VE interface) in the NPE, in order to allow other network devices in the system can be communication with the VE interface is required to set the VE interface state and a physical layer link layer state, i.e., the corresponding physical interface parameters.

[0132] 在具体应用中,为了实现两种MPLS网络之间的交互通信,所以,该VE接口需要配置为双向接口,既可以接收报文,也可以发送报文。 [0132] In a particular application, in order to achieve interactive communication between the two MPLS networks, therefore, the VE interface be configured as bi-directional interface, both received packets, packets may be transmitted.

[0133] 在具体的应用场景中,VE接口建立的主要步骤包括: [0133] In a specific application scenario, the VE interface established major steps comprising:

[0134] (1)在NPE设备上,通过接口配置命令创建一个VE接口实体。 [0134] (1) on the NPE, create a VE interface entity via interface configuration commands.

[0135] (2)为这个VE接口配置物理以太网接口具有的一些参数属性,如MAC地址和MTU (Maximum Transmission Unit,最大传输单元),通过这样的配置,使系统中的其他网络设备将该VE接口作为物理接口来看待,并向其进行相应的报文收发处理。 [0135] (2) This is the VE interface Ethernet interface having a physical property parameters, such as the MAC address and MTU (Maximum Transmission Unit, the maximum transmission unit), by this arrangement, other network devices in the system VE interface as the physical interface to look at, and its corresponding packet reception processing.

[0136] (3)为这个VE接口分配一个标签(称为VE接口入标签),在NPE设备上建立这个标签与VE接口的对应关系,这样的标签设置主要是为了进行MPLS L2VPN网络中的报文收发处理。 [0136] (3) for the VE interface is assigned a tag (VE interface called the tag), establish this relationship tag VE interface on the NPE, such labels are provided primarily to perform packet network MPLS L2VPN send and receive text processing.

[0137] 与直连设备通信不同,在MPLS L2VPN网络中,NPE设备同作为远端设备的UPE设备的通信是建立在虚链路(或称为伪线,PW,Pseudo Wire)上的。 [0137] Direct different communication devices, the network MPLS L2VPN, the device with the NPE is the UPE communication with the remote device is based on a virtual link (or pseudo wire, PW, Pseudo Wire) a.

[0138] 因此,需要进行进一步的设置处理如下: [0138] Accordingly, a need for further processing is provided as follows:

[0139] (1)为VE接口指定通过此VE接口通信的MPLS L2VPN中的对端设备,同时需要指定与该对端设备进行通信的PW的PW标签。 [0139] (1) VE interface as MPLS L2VPN by this interface in communication with the peer device VE, while the need to specify the PW PW labels to communicate with the peer device.

[0140] (2)将上述设置过程中分配给VE接口的入标签,通过PW标签分发协议通告给对端设备,并与对端设备建立PW,在实际应用中,VE接口入标签就是该PW的PW标签。 [0140] (2) The above setup process assigned to the VE interface into the label advertised to the PW label distribution protocol terminal equipment, and establish a PW peer device, in practical applications, the VE interface into labels is that the PW the PW label.

[0141] (3)NPE设备向对端设备通告了PW标签,接收到了对端设备返回的PW标签确认,并找到了到达对端设备的MPLS隧道,从而,PW进入激活状态,在此之后,以太网逻辑接口的物理状态和链路状态就随之进入激活状态。 [0141] (3) NPE device announcement to the peer device PW label is received from the peer returned by the device PW label confirmed and found arrival MPLS tunnel to the remote device, thereby, PW into an active state, after this, physical status and link status of the Ethernet interface on the subsequent logic into an active state.

[0142] (4)为了建立与MPLS L3VPN之间的互通,如果需要关联的MPLSL3VPN实例的数量为一个,则直接将VE接口与该MPLS L3VPN实例相关联,而如果需要关联的MPLS L3VPN实例为多个,则VE接口可以创建多个子接口(子接口是一个逻辑接口,或称为虚拟接口),各子接口可以指定成特定的L3VPN独占接口。 [0142] (4) In order to establish interoperability between the MPLS L3VPN, if the number of instances MPLSL3VPN is a need to associate, directly to the VE interface and the associated MPLS L3VPN instance, if the MPLS L3VPN instance need to be correlated to multiple a, the VE interface can create a plurality of sub-interfaces (sub-interface is a logical interface, otherwise known as virtual interface), the sub-interface may be specified into specific L3VPN exclusive interface.

[0143]如: [0143] such as:

[0144] Interface VEl [0144] Interface VEl

[0145] peer 10. 10. 10. 10 pw-id 100 [0145] peer 10. 10. 10. 10 pw-id 100

[0146] mac-address HHH [0146] mac-address HHH

[0147] Interface VEl. 100 子接口 [0147] Interface VEl. 100 subinterface

[0148] ip vrf vpnl [0148] ip vrf vpnl

[0149] Interface VEl. 101 子接口 [0149] Interface VEl. 101 subinterface

[0150] ip vrf vpnl [0150] ip vrf vpnl

[0151] 在具体的VE接口报文转发处理过程中,系统中的其他网络设备将VE接口当作以太网物理端口来看待。 [0151] In particular forwarding packets during the VE interface, other network devices in the system as the VE interface Ethernet physical port to look at.

[0152] 进一步的,先以VPWS与MPLS L3VPN互通来说明,如图7所示。 [0152] Further, prior to VPWS interworking with MPLS L3VPN be described, as shown in FIG.

[0153] 首先,在此种应用场景下,VE接口上的PW本身就是一个VPWS实例,只需要将VE接口的各子接口分别与不同的MPLS L3VPN实例关联,即可实现多个MPLS L3VPN与一个VPWS互通。 [0153] First, in this scenario, the PW on the VE interface is itself a VPWS example, only the sub-VE interface of the interfaces are associated with different MPLS L3VPN instance, can be realized with a plurality of MPLS L3VPN VPWS exchange.

[0154]如: [0154] such as:

[0155] Interface VEl [0155] Interface VEl

[0156] peer 10. 10. 10. 10 pw-id 100 [0156] peer 10. 10. 10. 10 pw-id 100

[0157] Interface VEl. 100 子接口下文以这个子接口为例,其它子接口处理类似。 [0157] Interface VEl. 100 subinterface below as an example of this sub-interface, similar to the other sub-interface processing.

[0158] Ip vrf VPNl [0158] Ip vrf VPNl

[0159] Interface VEl. 101 子接口 [0159] Interface VEl. 101 subinterface

[0160] Ip vrf VPN2 [0160] Ip vrf VPN2

[0161] 进一步的,按照报文的具体转发方向,对VPWS与MPLS L3VPN之间的互通处理流程进行说明: [0161] Further, according to the specific direction of forwarding packets, the processing flow for interworking between MPLS L3VPN VPWS and will be described:

[0162] 情况一、在NPEl上,对于由VPWS向MPLS L3VPN方向转发报文的处理流程 [0162] a case where, in the NPEL, for forwarding packets to the MPLS L3VPN VPWS process flow direction

[0163] NPEl收到从UPEl发送来的报文(带两层标签,外层标签是UPEl到NPE的MPLS隧道的隧道标签,内层标签是VE接口入标签),首先要弹出隧道标签(这层标签可能在倒数第二跳设备上弹出,标签弹出是标签操作中的一种,也就是从报文上剥离一个标签),然后进一步弹出PW标签(也就是VE接口入标签),从而,根据已经建立的PW标签与VE接口的对应关系找到VE接口,将报文的描述符上报文接收接口的信息设置为VE接口,然后进行接口的接收处理。 [0163] NPEl UPEl to receive transmitted from the packet (with two labels, the outer label is UPEl NPE tunnel label of the MPLS tunnel, the inner label into the VE interface is the label), first to eject the tunnel label (which layer on the label may eject device penultimate hop, the label is a label pop operation, a label is peeled off from the packet), and then a further pop-PW label (i.e. the label VE interface), so that, in accordance with the correspondence relationship has been established and a PW label to find the VE interface VE interface, the packet descriptor information reporting packet receiving interface is provided for the VE interface, and the interface of the reception process.

[0164] VE接口接收到该报文之后,因为VPWS本身是点到点连接,因此不需要额外的查表转发,直接根据该报文的以太网报文头中的信息分析结果,进行VE接口的子接口匹配(在具体的应用场景中,可以将以太网协议头的802. IQVLAN tag与子接口上指定的tag比较,相同则认为匹配,不同则不匹配),根据匹配上的子接口对应的MPLS L3VPN实例的路由转发表转发,最终将报文转发到PEl或PE2,并进而由PEl或PE2发送给CE2或CE3。 [0164] VE interface after receiving the message, because the connection point VPWS itself, so no additional forwarding look-up table, directly from the Ethernet header in the message information analysis result, the VE interface matching sub-interface (in the specific application scenario, the comparison may be specified on the sub-interface 802. IQVLAN tag Ethernet protocol header tag, we believe that the same is matching, not matching different), corresponding to the matching sub-interface in accordance with routing MPLS L3VPN instance forwarding forwards, forwards the packet to the final PEl or PE2, and thus to CE2 or CE3 a PEl or PE2.

[0165] 情况二、在NPEl上,对于由MPLS L3VPN向VPWS方向转发报文的处理流程 [0165] Case 2 in NPEL, for forwarding packets to the MPLS L3VPN VPWS process flow direction

[0166] 这个方向的转发,NPEl上在转发前需要进行一个ARP学习过程,即解析在MPLS L2VPN网络中的CEl与UPE相连的接口的IP地址和MAC地址。 Forwarding [0166] in this direction, the NPEl before forwarding ARP require a learning process, i.e. CEl resolved interfaces connected with UPE in MPLS L2VPN network IP address and MAC address.

[0167] 在这样的ARP学习过程中,所学习到的ARP信息至少包括以下信息: [0167] In such an ARP learning process, the learned ARP information includes at least the following information:

[0168] 1、VE接口索引,即VE接口所对应的对端设备的地址信息,一边对于需要转发到MPLS L2VPN网络中的报文进行目标地址设置。 [0168] 1, VE interface index, i.e. VE interface address information corresponding to the end device, while the target address is set to forward a packet to the MPLS L2VPN network.

[0169] 2、接收到该报文的VE接口的子接口相对应的信息,如VLAN tag信息,这样的信息同样用于对转发报文的封装,从而使接收到转发后的报文的网络设备能够区分该报文的来源方向,如果需要进行报文交互,也可实现目标地址的设置。 [0169] 2, the VE interface receives the packet of information corresponding to the sub-interfaces, such as the VLAN tag information, such information is also received by the network for the packet and transfers the encapsulated packet forwarding, so that the device can distinguish the direction of the source of the message, if necessary packet interaction can also be set to achieve the target address.

[0170] 3、PW索引,通过该信息,可以直接找到VE接口所对应的PW,以确定二层转发的PW。 [0170] 3, PW index, this information can be found directly VE interface corresponding to the PW, to identify Layer 2 forwarding PW.

[0171] 需要进行报文转发时,首先,NPEl根据接收到的报文的目的IP地址在L3VPN路由转发表中进行查找,找到该IP地址所对应的出接口和下一跳。 [0171] required for packet forwarding, first, to find NPEL L3VPN route in the forwarding table according to the received destination IP address of the packet, to find the IP address corresponding to the interface and next hop.

[0172] 然后,根据查找到的出接口和下一跳查找相对应的ARP信息(即前述学习到的子接口VLAN tag、目的MAC地址、PW索引等)对该报文进行以太网网报文头的封装。 [0172] Then, according to the found outgoing interface and next hop ARP to find corresponding information (i.e., the sub-interface learned VLAN tag, destination MAC address, the PW index, etc.) of the Ethernet packet network packets the encapsulation header. 一方面, 设定该报文的转发目的MAC地址,另一方面,获取转发该报文的PW,并根据该PW为该报文打上PW标签和隧道标签,完成骨干网上转发需要的二层封装。 On the one hand, set the forwarding destination MAC address of the packet, on the other hand, acquiring forwards the packet of PW, and PW is based on the packet marked with PW label and tunnel label to complete the two-story package forwarding backbone network needs .

[0173] 上述处理完成后,因为VPWS本身是点到点连接,因此不需要额外的查表转发,直接指定VE接口执行物理接口发送过程(将VE接口当作是物理端口),通过PW向相应的对端设备(UPEl)发送该报文。 [0173] After the above process is completed, because VPWS point itself is connected, so no additional forwarding look-up table, which directly specifies the VE interface performs physical interface process (the VE interface as a physical port), through the corresponding PW transmitting the packet to the peer device (UPEl).

[0174] 再进一步的,以VPLS与MPLS L3VPN互通来说明,如图8所示。 [0174] Still further, in order to VPLS interworking with MPLS L3VPN be described, as shown in FIG.

[0175] 由于VPLS中可以实现点对多点的传输,所以,首先需要将VE接口加入到一个VPLS 实例,实现多个MPLS L3VPN与一个VPLS的互通。 [0175] Since the VPLS multipoint transmission can be achieved, therefore, first need to be added to a VE interface VPLS instance, you can communicate with a plurality of VPLS MPLS L3VPN.

[0176]如: [0176] such as:

[0177] Interface VEl [0177] Interface VEl

[0178] peer 10. 10. 10. 10 pw-id 100 [0178] peer 10. 10. 10. 10 pw-id 100

[0179] mac-address HHH [0179] mac-address HHH

[0180] 12 vsi vsil [0180] 12 vsi vsil

[0181] Interface VEl. 100 子接口 [0181] Interface VEl. 100 subinterface

[0182] ip vrf vpnl [0182] ip vrf vpnl

[0183] Interface VEl. 101 子接口 [0183] Interface VEl. 101 subinterface

[0184] ip vrf vpn2 [0184] ip vrf vpn2

[0185] 进一步的,按照报文的具体转发方向,对VPLS与MPLS L3VPN之间的互通处理流程进行说明: [0185] Further, according to the specific direction of forwarding packets, the processing flow for interworking between VPLS and MPLS L3VPN be described:

[0186] 情况一、在NPEl上,对于由VPLS向MPLS L3VPN方向转发报文的处理流程 [0186] I. NPEL on, for the packet to be forwarded by the VPLS MPLS L3VPN process flow direction

[0187] NPEl收到公网发送来的报文(带两层标签,外层标签是公网标签,内层标签是VE 接口入标签),首先要弹出公网标签,然后进一步弹出PW标签(也就是VE接口入标签),从而,根据已经建立的PW标签与VE接口的对应关系找到VE接口,将报文的描述符上报文接收接口的信息设置为VE接口,然后进行接口的接收处理。 [0187] NPEl receive the public network sends the packets (with two labels, label the outer label is a public network, the VE interface is the inner label tag), the first tab to eject the public network, and then a further pop-PW label ( VE interface is the label), thereby to find the correspondence relation VE interface PW label VE interface has been established, the packet descriptor information reporting packet receiving interface is provided for the VE interface, and an interface of the reception process .

[0188] VE接口接收到该报文之后,检查该报文的目的MAC是否跟VE接口的MAC地址相同。 [0188] After receiving the packet, checks whether the packet destination MAC address is the same as the MAC address of the VE interface with the VE interface.

[0189] 如果不相同,则判定需要进行二层转发,也就是查找VPLS实例的MAC转发表做MAC 转发。 [0189] If not, it is determined that the need for Layer 2 forwarding is to find VPLS MAC forwarding instances do MAC forwarding.

[0190] 如果相同,需要进行IP路由转发,也就是查找路由转发表做IP转发处理,在IP转发前,先对以该报文的以太网报文头进行分析,根据分析结果,进行VE接口的子接口匹配(在具体的应用场景中,可以将以太网协议头的802. IQVLAN tag与子接口上指定的tag比较,相同则认为匹配,不同则不匹配),根据匹配上的子接口对应的MPLS L3VPN实例的路由转发表进行报文转发,最终将该报文转发到PEl或PE2,并进而由PEl或PE2发送给CE2或CE3。 [0190] If the same, the need for IP routing and forwarding, which is to do the routing forwarding IP forwarding, IP forwarding before, first to be analyzed to Ethernet header of the packet, according to the analysis result, the VE interface matching sub-interface (in the specific application scenario, the comparison may be specified on the sub-interface 802. IQVLAN tag Ethernet protocol header tag, we believe that the same is matching, not matching different), corresponding to the matching sub-interface in accordance with examples of MPLS L3VPN route forwarding to forward packets, eventually forwards the packets to PEl or PE2, and thus to CE2 or CE3 a PEl or PE2.

[0191] 情况二、在NPEl上,对于由MPLS L3VPN向VPLS方向转发报文的处理流程[0192] 具体的转发过程同样包含ARP学习过程,即解析在MPLS L2VPN网络中的CEl与UPE相连的接口的IP地址和MAC地址,具体内容请参考前文,在此不再重复说明。 [0191] Case 2 in NPEL, for forwarding packets to the VPLS direction indicated by MPLS L3VPN process flow [0192] DETAILED forwarding process also comprises ARP learning process, i.e. resolved interfaces connected to CEl and UPE in MPLS L2VPN Network the IP address and MAC address, details, refer to the foregoing, the description will not be repeated.

[0193] 需要进行报文转发时,首先,NPEl根据接收到的报文的目的IP地址在L3VPN路由转发表中进行查找,找到该IP地址所对应的出接口和下一跳。 [0193] required for packet forwarding, first, to find NPEL L3VPN route in the forwarding table according to the received destination IP address of the packet, to find the IP address corresponding to the interface and next hop.

[0194] 然后,根据查找到的出接口和下一跳查找相对应的ARP信息(即前述学习到的子接口VLAN tag、目的MAC地址、PW索引等)并根据相应的查询结果对该报文进行以太网网报文头的封装。 [0194] Then, according to the found outgoing interface and next hop ARP to find corresponding information (i.e., the sub-interface learned VLAN tag, destination MAC address, the PW index, etc.) and a corresponding message according to a query result encapsulates the Ethernet packet header. 一方面,设定该报文的转发目的MAC地址,另一方面,获取转发该报文的PW, 并根据该PW为该报文打上PW标签和隧道标签,完成骨干网上转发需要的二层封装。 On the one hand, set the forwarding destination MAC address of the packet, on the other hand, acquiring forwards the packet of PW, and PW is based on the packet marked with PW label and tunnel label to complete the two-story package forwarding backbone network needs .

[0195] 上述处理完成后,指定VE接口执行物理接口发送过程(将VE接口当作是物理端口),通过PW向相应的对端设备(UPE2)发送该报文。 [0195] After the above process is completed, performing the specified VE interface physical interface process (the VE interface as a physical port), and send the packet to the corresponding peer device (UPE2) by PW.

[0196] 与现有技术相比,本发明具有以下优点: [0196] Compared with the prior art, the present invention has the following advantages:

[0197] 通过应用本发明的技术方案,可以通过统一的VE接口实现MPLS L2VPN网络和MPLS L3VPN网络之间的通信,简化了相应的操作流程,并且由于在不同的MPLS L2VPN网络类型中均可以应用相应的策略设置实现报文处理和转发,有效的提高了MPLS L2VPN网络和MPLS L3VPN网络之间进行报文交互的处理效率,降低了硬件适配成本。 [0197] By applying the technical solution of the present invention can be realized between the communication network and the MPLS L3VPN L2VPN MPLS network through a unified interface to VE, the corresponding operation is simplified processes, and since both can be used in different types of networks in MPLS L2VPN the appropriate policy settings to achieve packet processing and forwarding, effectively improve the processing efficiency to exchange messages between the network and MPLS L2VPN MPLS L3VPN network, reducing hardware adaptation costs.

[0198] 为了实现本发明的技术方案,本发明还提出了一种NPE设备,应用于同时包括MPLS L2VPN网络和MPLS L3VPN网络的系统中,MPLS L2VPN网络和MPLS L3VPN网络之间通过NPE设备相连接,其结构示意图如图9所示,包括: [0198] To achieve the aspect of the present invention, the present invention also proposes an apparatus NPE applied while the system comprising a network and a MPLS L2VPN MPLS L3VPN networks, connected by the NPE between the network and the MPLS L3VPN MPLS L2VPN Network , the structure diagram shown in Figure 9, comprising:

[0199] 设置模块91,用于创建一个VE接口,其中,VE接口通过PW与MPLSL2VPN网络中的网络设备相连接,并与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN实例建立相应的路由转发表。 [0199] module 91 is provided for creating a VE interface, wherein, the VE interface is connected via the PW MPLSL2VPN network devices in the network, and associated with a respective MPLS L3VPN L3VPN Examples network, and establish the corresponding example for the L3VPN the routing and forwarding table.

[0200] 其中,当VE接口需要与MPLS L3VPN网络的多个L3VPN实例进行关联时,设置模块91还用于用于在所述VE接口中创建多个子接口,各子接口与MPLS L3VPN网络的各L3VPN 实例进行关联,并为各L3VPN实例建立相应的路由转发表。 [0200] wherein, when a plurality of instances VE interface L3VPN MPLS L3VPN network needs to correlate, setting module 91 is further configured to create a plurality of sub-interfaces for the VE interface, each of the sub-network interface and the MPLS L3VPN L3VPN instance association, and to establish the appropriate route for the L3VPN instance forwarding table.

[0201] 在具体的应用场景中,可以根据NPE设备所关联的MPLS L3VPN网络中的L3VPN实例的数量进行子接口设置的调整,这样的变化并不影响本发明的保护范围。 [0201] In a specific application scenario, the sub-interface settings may be adjusted according to the number of instances L3VPN MPLS L3VPN NPE associated network devices, such changes do not affect the scope of the present invention.

[0202] 为了方便说明,后续实施例中具体以多个子接口的情况为例进行说明。 [0202] For convenience of explanation, in the specific embodiment subsequent to a plurality of sub-interface described as an example. [0203] 具体的建立VE接口的过程如下: [0203] The process of establishing the specific VE interfaces are as follows:

[0204] 设置模块91通过接口配置命令创建一个VE接口。 [0204] is set to create a VE interface module 91 via interface configuration command.

[0205] 设置模块91为VE接口配置物理接口属性参数。 [0205] setting the VE interface module 91 to the physical interface attributes parameter.

[0206] 设置模块91为VE接口分配识别标签,并建立识别标签与VE接口的对应关系,进一步的,设置模块91确定VE接口需要连接的MPLS L2VPN网络中的网络设备,将VE接口的识别标签通过PW标签分发协议消息发送给MPLS L2VPN网络中的网络设备,并建立VE接口与MPLS L2VPN网络中的网络设备之间的PW,以识别标签作为PW的PW标签。 [0206] setting module 91 is a VE interface is assigned an identification tag, and establishing corresponding relationship between the identification tag to the VE interface, further, the setting module 91 determines MPLS L2VPN Network VE interfaces to be connected in a network device, the identification tag VE interface the PW label distribution protocol MPLS L2VPN message to a network device in the network, and establish PW between the VE interface and the MPLS L2VPN network devices in the network, to identify the label as the PW PW label.

[0207] 设置模块91为VE接口的各子接口建立识别信息,并建立识别信息与子接口的对应关系,进一步的,设置模块91将VE接口的部分或全部子接口分别确定为各MPLS L3VPN 网络的独占接口,将子接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN 实例建立相应的路由转发表。 [0207] setting module 91 to the VE interface of each sub-interface to establish identification information, and establish a corresponding relationship between identification information and sub-interfaces, further, the setting module 91 portion of the VE interface, or all sub-interfaces are determined for the MPLS L3VPN network exclusive interfaces, sub-interfaces associated with the instance of the corresponding MPLS L3VPN L3VPN network, and to establish the appropriate route for the L3VPN instance forwarding table.

[0208] 处理模块92,与设置模块91相连接,用于当接收到MPLS L2VPN网络中的网络设备通过PW发送给VE接口的报文时,在设置模块91所设置的VE接口的子接口中,根据报文中的标识信息确定相对应的子接口,或当接收到MPLS L3VPN网络中的网络设备发送的报文时,确定报文的目的IP地址在L3VPN实例的路由转发表中对应的转发信息,在设置模块91 所设置的VE接口相连的PW中,根据转发信息选择相对应的PW。 [0208] The processing module 92, the module 91 is connected is provided, when receiving the MPLS L2VPN network packets sent from the network device via the PW VE interface, sub-interface VE interface setting module 91 provided in , the identification information packets corresponding to the determined sub-interface according to or when receiving the message sent by MPLS L3VPN network network, determining the packet destination IP address in the L3VPN example of the routing tables corresponding forwarding information, the PW VE module 91 is provided connected to the interface provided, the PW forwarding information corresponding to the selection.

[0209] 转发模块93,与处理模块92相连接,用于根据处理模块92所确定的子接口所关联的L3VPN实例的路由转发表进行报文的转发,或通过处理模块92所选择的PW,向MPLS L2VPN网络中的网络设备进行报文的转发。 [0209] forwarding module 93, processing module 92 is connected to a forwarding table for forwarding packets according to the routing L3VPN example of the processing module 92 associated with the determined sub-interfaces, or through the processing module 92 selected the PW, for packet forwarding MPLS L2VPN network to network devices.

[0210] 具体的应用场景中,当接收到MPLS L2VPN网络中的网络设备通过PW发送的报文时,转发模块93,用于根据处理模块92所确定的子接口所关联的L3VPN实例的路由转发表进行报文的转发,具体为: [0210] specific application scenario, when a packet is received MPLS L2VPN network via the network device sends the PW, forwarding module 93, according to an example of L3VPN routing processing module 92 associated with the determined sub-interface forwarding published for packet forwarding, in particular:

[0211 ] 如果MPLS L2VPN网络具体为VPLS,处理模块92根据报文的PW标签确定报文所对应的VE接口,并判断报文的目的MAC地址与VE接口的物理接口属性参数中的MAC地址信息是否相同,如果相同,则分析报文的报文头获取标识信息,将标识信息与VE接口中各子接口的标识信息进行匹配,转发模块93通过处理模块92匹配成功的子接口所关联的L3VPN 实例的路由转发表,对报文进行IP转发,如果不相同,则查找MAC转发表,由转发模块93将报文进行MAC转发; [0211] If the MPLS L2VPN network specifically the VPLS, the processing module 92 packets PW label determines the packet corresponding to the VE interface, and determines the MAC address of the physical interface attributes parameter destination MAC address of the VE interface packets of information in accordance with They are the same, if the same, then the analysis of the packet header obtain identification information, the identification information for identifying information with the VE interface of each sub-interface matching, forwarding module 93 through the L3VPN associated with the processing module 92 successfully matched subinterface examples of routing forwarding, forwarding of IP packets, if not identical, to find MAC forwarding, the forwarding module 93 forwards the packet MAC;

[0212] 如果MPLS L2VPN网络具体为VPWS,处理模块92根据报文的PW标签确定报文所对应的VE接口,并分析报文的报文头获取标识信息,将标识信息与VE接口中各子接口的标识信息进行匹配,并由转发模块93通过处理模块92匹配成功的子接口所关联的L3VPN实例的路由转发表,对报文进行IP转发。 [0212] If the MPLS L2VPN network specifically VPWS, the processing module 92 packets PW label determines the packet corresponding to the VE interface in accordance with and analyzes packet header obtain identification information, the identification information to the VE interface of each sub- interface identification information match by the forwarding module 9392 L3VPN sub-interface successfully matched by the processing module associated with the routing and forwarding table example of packet IP forwarding.

[0213] 另一方面,当接收到MPLS L3VPN网络中的网络设备发送的报文时,转发模块93, 用于通过处理模块92所选择的PW,向MPLS L2VPN网络中的网络设备进行报文的转发,具体为: [0213] On the other hand, when a packet is received MPLS L3VPN network device sends the network, the forwarding module 93, module 92 for processing by PW selected, for packet network to the MPLS L2VPN network device forward, in particular:

[0214] 处理模块92学习MPLS L2VPN网络中的网络设备所对应的ARP信息,ARP信息至少包括MPLS L2VPN网络中的网络设备与目的终端相连接的接口的IP地址和MAC地址; ARP information [0214] MPLS L2VPN learning processing module 92 in the network device corresponding to the network, ARP information includes at least the IP address of the network interface device and the destination terminal network MPLS L2VPN connected and a MAC address;

[0215] 处理模块92根据MPLS L3VPN网络的L3VPN实例发送的报文的目的IP地址在L3VPN实例的路由转发表中确定报文的出接口和下一跳信息;[0216] 处理模块92根据报文的出接口和下一跳信息获取相对应的ARP信息,转发模块93通过ARP信息中的MAC地址对报文进行二层封装,再通过ARP信息所指定的PW向MPLS L2VPN网络中的网络设备进行报文的转发。 [0215] destination IP addresses of packets transmitted according to the processing module 92 L3VPN MPLS L3VPN example network interface and next hop of the packet to determine routing information L3VPN instance in the forwarding table; [0216] The packet processing module 92 the outgoing interface and next hop information acquisition corresponding to the ARP information, the packet forwarding module 93 is performed by the MAC address in the ARP Layer 2 encapsulation information, and then specified PW ARP information for MPLS L2VPN network to network device packet forwarding.

[0217] 与现有技术相比,本发明具有以下优点: [0218] 通过应用本发明的技术方案,可以通过统一的VE接口实现MPLS L2VPN网络和MPLS L3VPN网络之间的通信,简化了相应的操作流程,并且由于在不同的MPLS L2VPN网络类型中均可以应用相应的策略设置实现报文处理和转发,有效的提高了MPLS L2VPN网络和MPLS L3VPN网络之间进行报文交互的处理效率,降低了硬件适配成本。 [0217] Compared with the prior art, the present invention has the following advantages: [0218] By applying the technical solution of the present invention can be realized between the communication network and the MPLS L2VPN unified network MPLS L3VPN VE interface, simplifies the corresponding operation flow, and because of the different network types in MPLS L2VPN can be applied to achieve the appropriate policy setting packet processing and forwarding, effectively improves the processing efficiency of interaction between a packet network and the MPLS L3VPN L2VPN MPLS network, reducing hardware adaptation costs.

[0219] 通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到本发明可以通过硬件实现,也可以借助软件加必要的通用硬件平台的方式来实现。 [0219] By the above described embodiments, those skilled in the art can understand that the present invention may be implemented by hardware, it may also be implemented by software plus a necessary universal hardware platform. 基于这样的理解,本发明的技术方案可以以软件产品的形式体现出来,该软件产品可以存储在一个非易失性存储介质(可以是⑶-ROM,U盘,移动硬盘等)中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施场景所述的方法。 Based on such understanding, the technical solutions of the present invention may be embodied in a software product out, the software product may be stored in a nonvolatile storage medium (which may be ⑶-ROM, U disk, mobile hard disk), and includes several instructions that enable a computer device (may be a personal computer, a server, or network device) to execute the methods described in the various embodiments of the present invention.

[0220] 本领域技术人员可以理解附图只是一个优选实施场景的示意图,附图中的模块或流程并不一定是实施本发明所必须的。 [0220] Those skilled in the art can accompanying drawings are merely schematic scene embodiment, the modules or processes in the accompanying drawings are not necessarily embodiments of the present invention to be understood.

[0221] 本领域技术人员可以理解实施场景中的装置中的模块可以按照实施场景描述进行分布于实施场景的装置中,也可以进行相应变化位于不同于本实施场景的一个或多个装置中。 [0221] It will be appreciated to those skilled in the scene apparatus embodiment that the modules can be located in the apparatus according to embodiments scene scene embodiment, corresponding changes can also be located in one or more devices according to the present embodiment is different from the scene. 上述实施场景的模块可以合并为一个模块,也可以进一步拆分成多个子模块。 The above-described embodiments of the scene module can be combined into one module, or split into multiple submodules.

[0222] 上述本发明序号仅仅为了描述,不代表实施场景的优劣。 [0222] Reference merely for description of the present invention, the merits embodiments do not represent the scene.

[0223] 以上公开的仅为本发明的几个具体实施场景,但是,本发明并非局限于此,任何本领域的技术人员能思之的变化都应落入本发明的保护范围。 Only a few [0223] above disclosed specific embodiments of the present invention, a scene, however, the present invention is not limited thereto, anyone skilled in the art can think of variations shall fall within the scope of the present invention.

Claims (12)

  1. 一种MPLS L2VPN和MPLS L3VPN的通信方法,应用于同时包括MPLS L2VPN网络和MPLS L3VPN网络的系统中,所述MPLS L2VPN网络和MPLS L3VPN网络之间通过NPE设备相连接,其特征在于,所述NPE设备上包括一个VE接口,其中,所述VE接口通过PW与所述MPLS L2VPN网络中的网络设备相连接,所述VE接口还与MPLS L3VPN网络的L3VPN实例进行关联,并为所述L3VPN实例建立相应的路由转发表,所述方法具体包括以下步骤:当所述NPE设备接收到所述MPLS L2VPN网络中的网络设备通过PW发送给所述VE接口的报文时,所述NPE设备根据所述报文中的标识信息确定相对应的VE接口,并根据所述VE接口所关联的L3VPN实例的路由转发表进行所述报文的转发;当所述NPE设备接收到所述MPLS L3VPN网络的L3VPN实例发送的报文时,所述NPE设备确定所述报文的目的IP地址在所述L3VPN实例的路由转发表中对应的转发信息,并根据所述 And in MPLS MPLS L3VPN L2VPN communication method, which is applied while the system comprising a network and a MPLS L3VPN L2VPN MPLS network, the MPLS NPE between devices connected by a network and MPLS L3VPN L2VPN network, characterized in that the NPE the apparatus comprising a VE interface, wherein the VE interface is connected to the MPLS L2VPN PW via the network the network device, the VE interface also associated with a network MPLS L3VPN L3VPN examples, examples and established as the L3VPN corresponding routing forwarding, said method comprises the steps of: when the device receives the NPE network MPLS L2VPN network device sends the packet to the VE interface through the PW, the apparatus according to the NPE identification information packets corresponding to the VE interface is determined, and the forwarding table to forward packets according to the routing L3VPN instance associated with the VE interface; NPE when the device receives the network MPLS L3VPN L3VPN examples of packets sent during the NPE device determines the packet destination IP address forwarding table forwarding information corresponding to said L3VPN routing instance, and according to the 发信息选择相对应的PW,通过所述PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 Send a message corresponding to the selected PW,, for forwarding the packet to the MPLS L2VPN network via the network device PW.
  2. 2.如权利要求1所述的方法,其特征在于,所述VE接口还与MPLSL3VPN网络的L3VPN 实例进行关联,并为所述L3VPN实例建立相应的路由转发表,具体为:当所述VE接口需要与MPLS L3VPN网络的多个L3VPN实例进行关联时,所述VE接口中进一步包含多个子接口,各所述子接口与MPLS L3VPN网络的各L3VPN实例进行关联,并为各所述L3VPN实例建立相应的路由转发表。 2. The method according to claim 1, wherein the VE interface also associated with L3VPN instance MPLSL3VPN network, and establish the appropriate route for example by the L3VPN forwarding, specifically: when the VE interface when needs to be associated with a plurality of network MPLS L3VPN L3VPN instance, the VE interface further comprises a plurality of sub-interfaces, each of the examples of each sub L3VPN MPLS L3VPN network interface associate and establish the corresponding instance of each of said L3VPN the routing and forwarding table.
  3. 3.如权利要求2所述的方法,其特征在于,所述NPE设备上包括一个VE接口,具体为:所述NPE设备通过接口配置命令创建一个VE接口;所述NPE设备为所述VE接口配置物理接口属性参数;所述NPE设备为所述VE接口分配识别标签,并建立所述识别标签与所述VE接口的对应关系;所述NPE设备为所述VE接口的各子接口建立识别信息,并建立所述识别信息与所述子接口的对应关系。 3. The method according to claim 2, wherein said NPE comprising a VE interface device, specifically: NPE device through the interface configuration command to create a VE interface; the NPE is the VE interface apparatus physical interface attributes parameter; NPE the dispensing apparatus is the VE interface identification tags, and establishing corresponding relationship between the identification tag of the VE interface; the NPE, VE of each said sub-identification information of the interface to establish and establishing correspondence between the identification information of the sub-interface.
  4. 4.如权利要求3所述的方法,其特征在于,所述VE接口通过PW与所述MPLS L2VPN网络中的网络设备相连接,具体为:所述NPE设备确定所述VE接口需要连接的所述MPLS L2VPN网络中的网络设备,所述NPE设备将所述VE接口的识别标签通过PW标签分发协议消息发送给所述MPLS L2VPN网络中的网络设备,并建立所述VE接口与所述MPLS L2VPN网络中的网络设备之间的PW,以所述识别标签作为所述PW的PW标签;所述VE接口中进一步包含多个子接口,各所述子接口与MPLS L3VPN网络的各L3VPN 实例进行关联,并为各所述L3VPN实例建立相应的路由转发表,具体为:所述NPE设备将所述VE接口的部分或全部子接口分别确定为各MPLSL3VPN网络的独占接口,将所述子接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN实例建立相应的路由转发表。 4. The method according to claim 3, wherein the VE interface is connected to the MPLS L2VPN PW via the network the network device, specifically: the NPE device determines the interface to be connected to the VE said MPLS network L2VPN network device, the device, the identification tag NPE VE interface PW label distribution protocol messages sent to the L2VPN MPLS network device in the network, and establishing the VE interface and the MPLS L2VPN PW between network devices in a network, as to the identification tag of the PW PW label; and the VE interface further comprises a plurality of sub-interfaces, each of the examples of each sub L3VPN MPLS L3VPN network interface associating, and establishing for the respective examples of the L3VPN routing and forwarding table, specifically: the NPE, part or all of the sub-VE interfaces for the interface are determined MPLSL3VPN exclusive network interfaces, the interfaces with the respective sub- examples L3VPN MPLS L3VPN network of associates, and to establish the appropriate route for the L3VPN instance forwarding table.
  5. 5.如权利要求4所述的方法,其特征在于,如果所述VE接口中包括多个子接口,当所述NPE设备接收到所述MPLS L2VPN网络中的网络设备通过PW发送给所述VE接口的报文时, 所述NPE设备根据所述报文中的标识信息确定相对应的VE接口,并根据所述VE接口所关联的L3VPN实例的路由转发表进行所述报文的转发,具体为:当所述MPLS L2VPN网络具体为VPLS时,所述NPE设备根据所述报文的PW标签确定所述报文所对应的VE接口,并判断所述报文的目的MAC地址与所述VE接口的物理接口属性参数中的MAC地址信息是否相同,如果相同,则分析所述报文的报文头获取标识信息,将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,并根据匹配成功的子接口所关联的L3VPN实例的路由转发表,通过所述子接口对所述报文进行IP转发,如果不相同,则查找MAC转发表,对所述报文进行MAC转 5. The method according to claim 4, wherein, if the VE interface includes a plurality of sub-interfaces, when the device receives the NPE MPLS L2VPN network via the network device transmits to the VE interface PW when the packet, the NPE device identification information in the packet according to the determined corresponding VE interface, and for forwarding to forward the packet according to the routing L3VPN instance associated with the VE interface, in particular : when the MPLS L2VPN specifically the VPLS network, the apparatus determines that the packet NPE corresponding VE interfaces of the packet according to a PW label, and determine whether the packet destination MAC address of the VE interface physical properties of the interface parameters of the MAC address information is the same, if the same, then the analysis of the packet header obtain identification information, the identification information with the identification information of each sub-VE interface matching interface, the routing and forwarding instance associated L3VPN successful matching sub-interface, the IP packet be forwarded by the sub-interface, if not identical, the MAC forwarding table lookup, the packet forwarding MAC 发;当所述MPLS L2VPN网络具体为VPWS时,所述NPE设备根据所述报文的PW标签确定所述报文所对应的VE接口,并分析所述报文的报文头获取标识信息,将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,并根据匹配成功的子接口所关联的L3VPN实例的路由转发表,通过所述子接口对所述报文进行IP转发。 Hair; when the network MPLS L2VPN VPWS specifically, the apparatus determines that the packet NPE corresponding VE interfaces of the packet according to a PW label, and analyzing the packet identification information acquired packet header, the identification information with the identification information of each sub-VE interface interfaces matches, routing and forwarding tables associated L3VPN instance successful matching sub-interface, the IP packet through the sub-interface forwarding .
  6. 6.如权利要求4所述的方法,其特征在于,当所述NPE设备接收到所述MPLS L3VPN网络的L3VPN实例发送的报文时,所述NPE设备确定所述报文的目的IP地址在所述L3VPN实例的路由转发表中对应的转发信息,并根据所述转发信息选择相对应的PW,通过所述PW, 向所述MPLS L2VPN网络中的网络设备进行所述报文的转发,具体为:所述NPE设备学习所述MPLS L2VPN网络中的网络设备所对应的ARP信息,所述ARP信息至少包括所述MPLS L2VPN网络中的网络设备与目的终端相连接的接口的IP地址和MAC 地址;所述NPE设备根据所述MPLS L3VPN网络的L3VPN实例发送的报文的目的IP地址在所述L3VPN实例的路由转发表中确定所述报文的出接口和下一跳信息;所述NPE设备根据所述报文的出接口和下一跳信息获取相对应的ARP信息,通过所述ARP信息对所述报文进行封装,并选择相对应的PW,向所述MPLS L2VPN网络中的 6. The method according to claim 4, wherein, when the packet L3VPN instance NPE MPLS L3VPN apparatus receives the transmitted network, the apparatus determines NPE of the packet destination IP address in examples of the L3VPN routing tables corresponding forwarding information according to the forwarding information corresponding to the selected the PW,, for forwarding the packet to the MPLS L2VPN network device through the network the PW, particularly is: ARP information of the MPLS L2VPN NPE device learns the network corresponding to the network device, the ARP information includes at least the IP address of the network interface device and the destination terminal MPLS L2VPN network and connected to the MAC address ; destination IP addresses of packets transmitted according to the apparatus NPE L3VPN examples of the network in the MPLS L3VPN L3VPN example of the routing tables and determines that the interface of the next hop of the packet; the NPE, the obtaining of the packet out interface and next hop ARP information corresponding to information, encapsulates the packet by the ARP information and the PW corresponding to the selection, to the network MPLS L2VPN 网络设备进行所述报文的转发。 The network device to forward packets.
  7. 7. 一种NPE设备,应用于同时包括MPLS L2VPN网络和MPLS L3VPN网络的系统中,所述MPLS L2VPN网络和MPLS L3VPN网络之间通过NPE设备相连接,其特征在于,包括:设置模块,用于创建一个VE接口,其中,所述VE接口通过PW与所述MPLS L2VPN网络中的网络设备相连接,并与MPLS L3VPN网络的L3VPN实例进行关联,并为L3VPN实例建立相应的路由转发表;处理模块,与所述设置模块相连接,用于当接收到所述MPLS L2VPN网络中的网络设备通过PW发送给所述VE接口的报文时,在所述设置模块所设置的VE接口的子接口中,根据所述报文中的标识信息确定相对应的子接口,或当接收到所述MPLS L3VPN网络中的网络设备发送的报文时,确定所述报文的目的IP地址在所述L3VPN实例的路由转发表中对应的转发信息,在所述设置模块所设置的VE接口相连的PW中,根据所述转发信息选择相对应的Pff ;转发模块, NPE An apparatus, comprising simultaneously applied to the system network and MPLS L3VPN L2VPN MPLS network, the MPLS NPE between devices connected by a network and MPLS L3VPN L2VPN network, characterized by comprising: a setting module, configured to Create a VE interface, wherein the VE interface is connected via the MPLS L2VPN PW network equipment network, and associated with the example MPLS L3VPN L3VPN network, and establish the appropriate routing for the forwarding instance L3VPN; a processing module , is connected to the setting module configured to, when receiving the MPLS L2VPN network device sends network packets to the VE interface through the PW, the VE interface module is provided in the set sub-interface identification information of the packet is determined according to the corresponding sub-interfaces, or when the received message sent by the network MPLS L3VPN network, determining the packet destination IP address in said L3VPN example routing forwarding table forwarding information corresponding to at PW VE interface connected to the setting module in the set, according to the forwarding information corresponding to the selected Pff; forwarding module, 所述处理模块相连接,用于根据所述所述处理模块所确定的子接口所关联的L3VPN实例的路由转发表进行所述报文的转发,或通过所述处理模块所选择的PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 The processing module is connected, for example the L3VPN routing module associated with the determined sub-interface processing in accordance with the forwarding table to forward packets, or by the processing module selected the PW, the the MPLS L2VPN network devices of the network to forward packets.
  8. 8.如权利要求7所述的NPE设备,其特征在于,当所述VE接口需要与MPLS L3VPN网络的多个L3VPN实例进行关联时,所述设置模块,还用于用于在所述VE接口中创建多个子接口,各所述子接口与MPLS L3VPN网络的各L3VPN实例进行关联,并为各所述L3VPN实例建立相应的路由转发表。 8. NPE apparatus according to claim 7, wherein, when the VE interface needs to be associated with a plurality of network MPLS L3VPN L3VPN example, the setting module is further configured for the VE interface create a plurality of sub-interfaces, each of the examples of each sub L3VPN MPLS L3VPN network interface association and establish the appropriate routing for the L3VPN forwarding instance.
  9. 9.如权利要求8所述的NPE设备,其特征在于,所述设置模块,用于创建一个VE接口, 具体为:所述设置模块通过接口配置命令创建一个VE接口;所述设置模块为所述VE接口配置物理接口属性参数;所述设置模块为所述VE接口分配识别标签,并建立所述识别标签与所述VE接口的对应关系;所述设置模块为所述VE接口的各子接口建立识别信息,并建立所述识别信息与所述子接口的对应关系。 The module is provided; the setting module to create a VE interface via interface configuration commands: NPE 9. The apparatus according to claim 8, wherein the setting module is configured to create a VE interface, in particular said physical interface the VE interface attributes parameter; setting the VE interface module to said identification tag allocation, and establish a correspondence between the identification tag of the VE interface; the interface module is provided for each of the sub-VE interface establishing identification information, and establish a corresponding relationship between the identification information and the sub-interface.
  10. 10.如权利要求9所述的NPE设备,其特征在于,所述设置模块确定所述VE接口需要连接的所述MPLS L2VPN网络中的网络设备,将所述VE接口的识别标签通过PW标签分发协议消息发送给所述MPLS L2VPN网络中的网络设备,并建立所述VE接口与所述MPLS L2VPN网络中的网络设备之间的PW,以所述识别标签作为所述PW的PW标签;所述设置模块将所述VE接口的部分或全部子接口分别确定为各MPLSL3VPN网络的独占接口,将所述子接口与相应的MPLS L3VPN网络的L3VPN实例进行关联,并为各L3VPN实例建立相应的路由转发表。 NPE 10. The apparatus according to claim 9, wherein the setting the VE interface module determines the need to connect the network MPLS L2VPN network device, the identification tag of the VE interface, the PW label distribution protocol message to the network device L2VPN MPLS network, and to establish PW between the VE interface and the MPLS network L2VPN network device, to the identification tag as the PW PW label; said setting the VE interface module part or all of the sub-interfaces are determined to be exclusive of each MPLSL3VPN network interfaces, the sub-interface instance with a respective MPLS L3VPN L3VPN network association, and establish the appropriate routing and forwarding instance for the L3VPN published.
  11. 11.如权利要求10所述的NPE设备,其特征在于,当接收到所述MPLSL2VPN网络中的网络设备通过PW发送的报文时,所述转发模块,用于根据所述所述处理模块所确定的子接口所关联的L3VPN实例的路由转发表进行所述报文的转发,具体为:如果所述MPLS L2VPN网络具体为VPLS,所述处理模块根据所述报文的PW标签确定所述报文所对应的VE接口,并判断所述报文的目的MAC地址与所述VE接口的物理接口属性参数中的MAC地址信息是否相同,如果相同,则分析所述报文的报文头获取标识信息,将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,所述转发模块通过所述处理模块匹配成功的子接口所关联的L3VPN实例的路由转发表,对所述报文进行IP转发,如果不相同,则查找MAC转发表,由所述转发模块将所述报文进行MAC转发;如果所述MPLS L2VPN网络具体为VPWS,所述处理模 NPE 11. The apparatus according to claim 10, wherein, when receiving a packet network, the network device MPLSL2VPN transmitted through the PW, the forwarding module configured in accordance with the processing module examples of the route of the associated L3VPN determined for the sub-interface forwarding the packet forwarding is specifically: if the particular MPLS L2VPN to the VPLS network, the packet processing module determines that the packet according to the PW label text corresponding VE interface, and determines the MAC address of the physical interface attributes parameter of the packet destination MAC address of the VE interface is the same as in the information, if the same, then the analysis of the packet header to obtain identification information, the identification information with the identification information of each of the sub-interface matching VE interfaces, the forwarding module through the processing module L3VPN instance associated sub-interface successfully matched routing and forwarding table, the packet forwarding the IP packet, if not identical, the MAC forwarding table lookup by the forwarding module to forward the packet MAC; particularly if the network is MPLS L2VPN VPWS, the processing module 块根据所述报文的PW标签确定所述报文所对应的VE接口,并分析所述报文的报文头获取标识信息,将所述标识信息与所述VE接口中各子接口的标识信息进行匹配,并由所述转发模块通过所述处理模块匹配成功的子接口所关联的L3VPN实例的路由转发表,对所述报文进行IP转发。 Determining said message block corresponding to the VE interfaces of the packet according to a PW label, and analysis of the packet header identification information acquired, the identification information identifying each of the sub-interfaces in the VE interface matching information by the forwarding module through the processing module associated with the matching route L3VPN successful example of sub-interface forwarding, the IP packet forwarding.
  12. 12.如权利要求10所述的NPE设备,其特征在于,当接收到所述MPLSL3VPN网络中的网络设备发送的报文时,所述转发模块,用于通过所述处理模块所选择的PW,向所述MPLS L2VPN网络中的网络设备进行所述报文的转发,具体为:所述处理模块学习所述MPLS L2VPN网络中的网络设备所对应的ARP信息,所述ARP信息至少包括所述MPLS L2VPN网络中的网络设备与目的终端相连接的接口的IP地址和MAC 地址;所述处理模块根据所述MPLS L3VPN网络的L3VPN实例发送的报文的目的IP地址在所述L3VPN实例的路由转发表中确定所述报文的出接口和下一跳信息;所述处理模块根据所述报文的出接口和下一跳信息获取相对应的ARP信息,所述转发模块通过所述ARP信息中的MAC地址对所述报文进行二层封装,再通过所述ARP信息所指定的PW向所述MPLS L2VPN网络中的网络设备进行所述报文的转发。 12. NPE apparatus according to claim 10, wherein, when receiving the packet MPLSL3VPN network device sends a network, the forwarding module is configured by the processing module PW selected, for forwarding the packet to the MPLS network L2VPN network equipment, in particular: the processing module to learn the L2VPN ARP information corresponding to the network devices in the MPLS, the ARP information includes at least MPLS IP address and MAC address of the network device and the destination terminal connected L2VPN network interface; destination IP addresses of packets transmitted according to the processing module MPLS L3VPN L3VPN examples of the routing network in a forwarding instance L3VPN determining the packet outbound interface and next hop information; processing module acquires the corresponding information according to the ARP packet is the next hop and the interface, the ARP module via the forwarding information MAC address of the packet Layer 2 encapsulation, and then forwards the packet to the MPLS L2VPN network device through the network ARP information designated PW.
CN 201010186818 2010-05-31 2010-05-31 Communication method and equipment of MPLS L2VPN (Multiple protocol Label Switching Layer 2 Virtual Private Network) and MPLS L3VPN (Multiple protocol Label Switching Layer 3 Virtual Private Network) CN101848161A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 201010186818 CN101848161A (en) 2010-05-31 2010-05-31 Communication method and equipment of MPLS L2VPN (Multiple protocol Label Switching Layer 2 Virtual Private Network) and MPLS L3VPN (Multiple protocol Label Switching Layer 3 Virtual Private Network)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 201010186818 CN101848161A (en) 2010-05-31 2010-05-31 Communication method and equipment of MPLS L2VPN (Multiple protocol Label Switching Layer 2 Virtual Private Network) and MPLS L3VPN (Multiple protocol Label Switching Layer 3 Virtual Private Network)

Publications (1)

Publication Number Publication Date
CN101848161A true true CN101848161A (en) 2010-09-29

Family

ID=42772625

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 201010186818 CN101848161A (en) 2010-05-31 2010-05-31 Communication method and equipment of MPLS L2VPN (Multiple protocol Label Switching Layer 2 Virtual Private Network) and MPLS L3VPN (Multiple protocol Label Switching Layer 3 Virtual Private Network)

Country Status (1)

Country Link
CN (1) CN101848161A (en)

Cited By (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101984607A (en) * 2010-11-16 2011-03-09 中兴通讯股份有限公司 Method of Ethernet interface to simultaneously support routing function and switching function
WO2011054263A1 (en) * 2009-11-03 2011-05-12 中兴通讯股份有限公司 Access method and access system for layer 3 virtual private networks(vpn)
CN102082738A (en) * 2011-03-10 2011-06-01 迈普通信技术股份有限公司 Method for extending MPLS VPN access through public network and PE equipment
CN102291317A (en) * 2011-09-15 2011-12-21 中兴通讯股份有限公司 Method and apparatus for forwarding packets of a virtual private network
CN102368726A (en) * 2011-09-14 2012-03-07 杭州华三通信技术有限公司 Forwarding method and device applied to L2VPN (layer 2 virtual private network)
CN102611603A (en) * 2012-03-16 2012-07-25 中兴通讯股份有限公司 Method and device for establishing static MPLS (Multi-Protocol Label Switch) tunnel forwarding table and transmitting data
CN102611618A (en) * 2012-02-23 2012-07-25 中兴通讯股份有限公司 Route protection converting method and device
CN102739501A (en) * 2011-04-01 2012-10-17 中兴通讯股份有限公司 Message forwarding method in two or three layer virtual private network (VPN) and system thereof
CN103491009A (en) * 2013-09-27 2014-01-01 华为技术有限公司 Flow forwarding method and device and gateway device
WO2014008802A1 (en) * 2012-07-10 2014-01-16 Hangzhou H3C Technologies Co., Ltd. Traffic forwarding in a layer 2 edge network
CN103634210A (en) * 2012-08-28 2014-03-12 杭州华三通信技术有限公司 Method and apparatus for discovering opposite-end provider?edge (PE) device of virtual?private?LAN?service (VPLS) instance
CN104243264A (en) * 2014-09-03 2014-12-24 烽火通信科技股份有限公司 System and method for connecting PW to L3VPN through N:1 model
CN105049316A (en) * 2015-08-26 2015-11-11 华为技术有限公司 Communication method and communication device
CN105530661A (en) * 2014-09-30 2016-04-27 中国电信股份有限公司 Method, router and system for measuring L2+L3 VPN network performance
EP3021529A1 (en) * 2013-09-23 2016-05-18 Huawei Technologies Co., Ltd. Method and device for implementing layer 3 virtual private network
WO2016119734A1 (en) * 2015-01-29 2016-08-04 Hangzhou H3C Technologies Co., Ltd. Access layer-2 virtual private network from layer-3 virtual private network
WO2016150093A1 (en) * 2015-03-20 2016-09-29 中兴通讯股份有限公司 Packet forward method, device, and pe apparatus
WO2016155394A1 (en) * 2015-03-31 2016-10-06 华为技术有限公司 Method and device for establishing link between virtual network functions

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050190757A1 (en) * 2004-02-27 2005-09-01 Cisco Technology Inc. Interworking between Ethernet and non-Ethernet customer sites for VPLS
CN1980176A (en) * 2006-11-15 2007-06-13 杭州华为三康技术有限公司 Mixed virtual private network system and backbone network edge apparatus and configuration method
WO2009021458A1 (en) * 2007-08-14 2009-02-19 Huawei Technologies Co., Ltd. Method, apparatus and system for connecting layer2 network and layer3 network

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050190757A1 (en) * 2004-02-27 2005-09-01 Cisco Technology Inc. Interworking between Ethernet and non-Ethernet customer sites for VPLS
CN1980176A (en) * 2006-11-15 2007-06-13 杭州华为三康技术有限公司 Mixed virtual private network system and backbone network edge apparatus and configuration method
WO2009021458A1 (en) * 2007-08-14 2009-02-19 Huawei Technologies Co., Ltd. Method, apparatus and system for connecting layer2 network and layer3 network

Cited By (32)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2011054263A1 (en) * 2009-11-03 2011-05-12 中兴通讯股份有限公司 Access method and access system for layer 3 virtual private networks(vpn)
CN101984607B (en) * 2010-11-16 2015-06-10 中兴通讯股份有限公司 Method of Ethernet interface to simultaneously support routing function and switching function
CN101984607A (en) * 2010-11-16 2011-03-09 中兴通讯股份有限公司 Method of Ethernet interface to simultaneously support routing function and switching function
CN102082738A (en) * 2011-03-10 2011-06-01 迈普通信技术股份有限公司 Method for extending MPLS VPN access through public network and PE equipment
CN102739501B (en) * 2011-04-01 2017-12-12 中兴通讯股份有限公司 Two three virtual packet forwarding method and system for private networks
CN102739501A (en) * 2011-04-01 2012-10-17 中兴通讯股份有限公司 Message forwarding method in two or three layer virtual private network (VPN) and system thereof
CN102368726A (en) * 2011-09-14 2012-03-07 杭州华三通信技术有限公司 Forwarding method and device applied to L2VPN (layer 2 virtual private network)
CN102368726B (en) 2011-09-14 2014-09-10 杭州华三通信技术有限公司 Forwarding method and device applied to L2VPN (layer 2 virtual private network)
WO2013037242A1 (en) * 2011-09-15 2013-03-21 中兴通讯股份有限公司 Method and device for forwarding message of virtual private network
CN102291317B (en) * 2011-09-15 2018-03-02 中兴通讯股份有限公司 Method and apparatus for forwarding packets of a virtual private network
CN102291317A (en) * 2011-09-15 2011-12-21 中兴通讯股份有限公司 Method and apparatus for forwarding packets of a virtual private network
CN102611618A (en) * 2012-02-23 2012-07-25 中兴通讯股份有限公司 Route protection converting method and device
CN102611618B (en) * 2012-02-23 2015-06-03 中兴通讯股份有限公司 Route protection converting method and device
CN102611603A (en) * 2012-03-16 2012-07-25 中兴通讯股份有限公司 Method and device for establishing static MPLS (Multi-Protocol Label Switch) tunnel forwarding table and transmitting data
CN103546374A (en) * 2012-07-10 2014-01-29 杭州华三通信技术有限公司 Message forwarding method and device in two-layered edge network
CN103546374B (en) * 2012-07-10 2016-08-03 杭州华三通信技术有限公司 An edge Layer forwarding network packets apparatus and method
WO2014008802A1 (en) * 2012-07-10 2014-01-16 Hangzhou H3C Technologies Co., Ltd. Traffic forwarding in a layer 2 edge network
US9154419B2 (en) 2012-07-10 2015-10-06 Hangzhou H3C Technologies Co., Ltd. Traffic forwarding in a layer 2 edge network
CN103634210B (en) * 2012-08-28 2016-10-19 杭州华三通信技术有限公司 Examples of peer discovery vpls device method and apparatus pe
CN103634210A (en) * 2012-08-28 2014-03-12 杭州华三通信技术有限公司 Method and apparatus for discovering opposite-end provider?edge (PE) device of virtual?private?LAN?service (VPLS) instance
EP3021529A4 (en) * 2013-09-23 2016-07-20 Huawei Tech Co Ltd Method and device for implementing layer 3 virtual private network
EP3021529A1 (en) * 2013-09-23 2016-05-18 Huawei Technologies Co., Ltd. Method and device for implementing layer 3 virtual private network
CN103491009A (en) * 2013-09-27 2014-01-01 华为技术有限公司 Flow forwarding method and device and gateway device
CN103491009B (en) * 2013-09-27 2017-01-04 华为技术有限公司 A method for forwarding traffic, equipment and the gateway device
CN104243264A (en) * 2014-09-03 2014-12-24 烽火通信科技股份有限公司 System and method for connecting PW to L3VPN through N:1 model
CN104243264B (en) * 2014-09-03 2017-11-07 烽火通信科技股份有限公司 PW pw in the n: 1 model system and method of access l3vpn
CN105530661A (en) * 2014-09-30 2016-04-27 中国电信股份有限公司 Method, router and system for measuring L2+L3 VPN network performance
WO2016119734A1 (en) * 2015-01-29 2016-08-04 Hangzhou H3C Technologies Co., Ltd. Access layer-2 virtual private network from layer-3 virtual private network
WO2016150093A1 (en) * 2015-03-20 2016-09-29 中兴通讯股份有限公司 Packet forward method, device, and pe apparatus
WO2016155394A1 (en) * 2015-03-31 2016-10-06 华为技术有限公司 Method and device for establishing link between virtual network functions
CN105049316A (en) * 2015-08-26 2015-11-11 华为技术有限公司 Communication method and communication device
CN105049316B (en) * 2015-08-26 2018-08-14 华为技术有限公司 The communication method and communication device

Similar Documents

Publication Publication Date Title
US8693323B1 (en) System and method for managing communications in an access network
US7221675B2 (en) Address resolution method for a virtual private network, and customer edge device for implementing the method
US20060146832A1 (en) Method and system for transporting data using pseudowire circuits over a bridged network
US20040202171A1 (en) Network and edge router
US20040213232A1 (en) Data mirroring in a service
US20030110268A1 (en) Methods of establishing virtual circuits and of providing a virtual private network service through a shared network, and provider edge device for such network
US6789121B2 (en) Method of providing a virtual private network service through a shared network, and provider edge device for such network
US20080019385A1 (en) System and method of mapping between local and global service instance identifiers in provider networks
US7009983B2 (en) Methods and apparatus for broadcast domain interworking
US20040151180A1 (en) Enhanced H-VPLS service architecture using control word
US20080170578A1 (en) Border Gateway Protocol Procedures for Multi-Protocol Label Switching and Layer-2 Virtual Private Networks Using Ethernet-Based Tunnels
US20120099602A1 (en) End-to-end virtualization
US20080159309A1 (en) System and method of mapping between local and global service instance identifiers in provider networks
US20040202199A1 (en) Address resolution in IP interworking layer 2 point-to-point connections
US20060120374A1 (en) Packet forwarding apparatus and communication network suitable for wide area ethernet service
US7339929B2 (en) Virtual private LAN service using a multicast protocol
US20040088389A1 (en) Methods and apparatus for automated edge device configuration in a heterogeneous network
US20090041023A1 (en) Method and Apparatus for Interworking VPLS and Ethernet Networks
US20070115913A1 (en) Method for implementing the virtual leased line
Xiao et al. Requirements for pseudo-wire emulation edge-to-edge (PWE3)
US20110164617A1 (en) Enhanced Hierarchical Virtual Private Local Area Network Service (VPLS) System and Method for Ethernet-Tree (E-Tree) Services
US20030037162A1 (en) Spanning tree protocol traffic in a transparent LAN
US20100329265A1 (en) Method and Apparatus for implementing L2 VPNs on an IP Network
US20090175274A1 (en) Transmission of layer two (l2) multicast traffic over multi-protocol label switching networks
CN101827009A (en) Routing frames in a trill network using service vlan identifiers

Legal Events

Date Code Title Description
C06 Publication
C10 Request of examination as to substance
C02 Deemed withdrawal of patent application after publication (patent law 2001)