Background technology
Three-layer equipment such as main frame or router is transmitted data message according to the IP address in the local area network (LAN); And three-layer equipment or two-layer equipment send, receive ethernet data frame according to MAC (Medium Access Control, medium access control) address.Described MAC Address is called physical address or hardware address again, is assigned in the Ethernet interface when being manufacturing equipment.IP address and MAC Address are separate, thereby, in the network of reality, need a kind of mechanism of address resolution to come to provide mapping for these two kinds of different address formats.
Initiatively send ARP (the Address Resolution Protocol of broadcast type in the network by three-layer equipment, address resolution protocol) probe messages between the realization equipment mapping relations of IP address and MAC Address learns mutually, carry its IP address and MAC Address in the described ARP probe packet, and the IP address of the equipment that will survey of described three-layer equipment, thereby receive the mapping relations of the learning equipment of described ARP probe packet to described three-layer equipment IP address and MAC Address; When the equipment that will survey when described ARP probe packet is received described ARP probe packet, send the ARP back message using, carry its own IP address and MAC Address, for described three-layer equipment study at described ARP back message using to described three-layer equipment.
MAC (Medium Access Control, medium access control) address can be divided into broadcasting MAC Address, multicast mac address and unicast mac address; When Layer 2 switch equipment receives that target MAC (Media Access Control) address is the message of broadcasting MAC Address or multicast mac address, can on the every other interface except that the message receiving interface, carry out broadcast replication and transmit; When receiving that target MAC (Media Access Control) address is the message of unicast mac address, Layer 2 switch equipment is then inquired about its built-in MAC earlier and is transmitted, each list item during described MAC transmits has write down the corresponding relation of MAC Address and forwarding interface, transmit by inquiring about described MAC, Layer 2 switch equipment obtains the pairing forwarding interface of described target MAC (Media Access Control) address, and described message is forwarded from described forwarding interface.
It not is to be changeless that described MAC transmits, when having main frame or router to exit network in the network, for preventing still occupying system resources of the pairing MAC address entries of its MAC Address, MAC address entries during Layer 2 switch equipment need be transmitted its MAC is regularly deleted, if do not receive in 5 minutes that generally speaking with MAC Address in the MAC address entries be the message that source MAC sends, Layer 2 switch equipment will be deleted described MAC address entries.
Generally speaking, three-layer equipment can be encapsulated as the source MAC by the message of its forwarding the MAC Address of the interface of self transmitting described message, in addition, described three-layer equipment is regular broadcast transmission ARP probe packet in network also, the source MAC of described ARP probe packet also is the MAC Address of self, so other two-layer equipments can be to the MAC address entries mistake deletion of described three-layer equipment in the network.
For improving the reliability of local area network (LAN) host access external network, IETF (Internet Engineering Task Force, the internet engineering task group) released VRRP (Virtual Router Redundancy Protocol, Virtual Router Redundacy Protocol), as shown in Figure 1, VRRP constitutes jointly a VRRP groups of routers (being router-A and router B in this figure) at least two routers, described VRRP groups of routers is equivalent to a virtual router, in network, has unique sign, i.e. VRRPID; Described VRRP groups of routers also has its own IP address and MAC Address, promptly empty IP and virtual MAC; Main frame in the local area network (LAN) communicates by whole VRRP groups of routers and other network according to described empty IP and virtual MAC.
At a time, have only a router to bear message forwarding between the interior main frame of local area network (LAN) and other networks in the VRRP groups of routers, this router is called VRRP Master (the main VRRP router of using), and all the other are not born the professional router of message forwarding and are called VRRP Slave (standby VRRP router).When VRRP Master breaks down, a certain VRRP Slave router can become new VRRP Master automatically and continue to finish message forwarding and transport service, whole process is transparent fully to the user, realized the uninterrupted communication between the interior main frame of local area network (LAN) and other external networks, thus continuity of keeping in communication and reliability.
VRRP Master can periodic broadcasting send gratuitous ARP packet, and the source MAC that described gratuitous ARP packet carries is the existence of described virtual MAC address in order to this VRRP of other equipment groups of routers in the informing network.
Yet, because a large amount of broadcasting packets can increase the burden of network, reduce the performance of network, therefore in some application scenarios, may the forwarding of broadcasting packet be limited.As shown in Figure 2, for preventing under the Layer 2 switch B that the broadcasting packet in the suspended network passes through Layer 2 switch C and arrives under the Layer 2 switch A in the suspended network, and the broadcasting packet in the suspended network passes through Layer 2 switch C and arrives under the Layer 2 switch B in the suspended network under the Layer 2 switch A, the interface configuration that Layer 2 switch C and Layer 2 switch A are linked to each other with B is for forbidding sending broadcasting packet, but allow to receive broadcasting packet, thereby isolate between the following suspended network to Layer 2 switch A and Layer 2 switch B, alleviated the burden of network.
Because the configuration of Layer 2 switch C interface makes and can't pass through Layer 2 switch C by the gratuitous ARP packet that VRRP Master periodic broadcasting sends, and arrives the following suspended network of Layer 2 switch C.Therefore in realizing process of the present invention, the inventor finds that have following problem in said process: the equipment under the Layer 2 switch C in the suspended network can miss deletion to the virtual MAC list item.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the invention, the technical scheme in the embodiment of the invention is clearly and completely described, obviously, described embodiment only is the present invention's part embodiment, rather than whole embodiment.Based on the embodiment among the present invention, those of ordinary skills belong to the scope of protection of the invention not making all other embodiment that obtained under the creative work prerequisite.
As shown in Figure 3, a kind of method that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch that the embodiment of the invention provided comprises:
301, the VRRP groups of routers sign of whether having judged under the Layer 2 switch in the suspended network in the ARP list item of equipment correspondence mark;
If 302, judge then whether this machine is that described VRRP groups of routers identifies the primary route device in the corresponding VRRP groups of routers;
303, when this machine is primary route device in the described VRRP groups of routers, send unicast message, the source MAC of described unicast message is that described VRRP groups of routers identifies pairing virtual MAC address, and target MAC (Media Access Control) address is the MAC Address of equipment in the suspended network under the described Layer 2 switch.
The embodiment of the invention provides prevents under the Layer 2 switch that equipment is to the method for virtual MAC list item mistake deletion in the suspended network, send unicast message by suspended network equipment under Layer 2 switch, the source MAC of described unicast message is the virtual MAC address of VRRP groups of routers, thereby the described VRRP groups of routers of described device learns is not exitted network yet, avoided mistake deletion described virtual MAC address list item.
In order more clearly to describe technical solution of the present invention, will specifically describe the part embodiment of technical solution of the present invention below, so that those skilled in the art can implement the present invention not making under the creative work prerequisite.
As shown in Figure 4, a kind of method that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch that the embodiment of the invention provided may further comprise the steps:
401, receive the address resolution protocol probe messages that suspended network equipment sends under the Layer 2 switch, described address resolution protocol probe messages content comprises: sender IP address and source MAC;
Whether what 402, judge that described address resolution protocol probe messages surveys is the virtual IP address of this VRRP groups of routers;
403, when described address resolution protocol probe messages survey be the virtual IP address of this VRRP groups of routers the time, obtain sender IP address, source MAC and the described virtual IP address of described address resolution protocol probe messages;
404, the VRRP ID of described virtual IP address correspondence is added to the sender IP address corresponding address analytic protocol table entry of this address resolution protocol probe messages;
That adds in the pairing address analysis protocol table item in described sender IP address in embodiments of the present invention is the VRRP ID of described virtual IP address correspondence, in other embodiments of the invention, can add other signs of can be unique determining the VRRP groups of routers of described virtual IP address correspondence, the present invention does not limit this yet.
405, broadcast according to described address analysis protocol table item suspended network tables of equipment under Layer 2 switch and send ARP probe packet;
Suspended network tables of equipment under Layer 2 switch broadcast send ARP probe packet before, at first to judge in described IP address of equipment corresponding address analytic protocol table entry and whether be added with VRRP ID, send ARP probe packet if no, then described equipment is not carried out clean culture;
If have, then obtain described VRRP ID, and judge further whether current machine is the main VRRP router of using, if not, then described equipment is not carried out clean culture and send ARP probe packet;
If, then carrying out clean culture and send ARP probe packet to described equipment, the target MAC (Media Access Control) address of described ARP probe packet is the MAC Address of described equipment, source MAC is the pairing virtual MAC of the VRRP ID address of adding in the described address analysis protocol table item.
The embodiment of the invention is broadcast by tables of equipment in the suspended network under Layer 2 switch and is sent ARP probe packet, the target MAC (Media Access Control) address of described ARP probe packet is the MAC Address of described equipment, source MAC is the pairing virtual MAC of the empty IP address that described equipment was once surveyed, because described ARP probe packet is a unicast message, therefore can arrive described equipment by described Layer 2 switch, thereby the mistake deletion to described virtual MAC address list item has been avoided in the existence of VRRP groups of routers that made described device learns.
As shown in Figure 5, the embodiment of the invention provides a kind of method that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch, comprising:
501, receive the address resolution protocol probe messages that suspended network equipment sends under the Layer 2 switch, described address resolution protocol probe messages content comprises: sender IP address, source MAC;
Whether what 502, judge that described address resolution protocol probe messages surveys is the virtual IP address of this VRRP groups of routers;
503, when described address resolution protocol probe messages survey be the virtual IP address of this VRRP groups of routers the time, obtain sender IP address, source MAC and the described virtual IP address of described address resolution protocol probe messages;
504, the VRRP ID of described virtual IP address correspondence is added to the sender IP address corresponding address analytic protocol table entry of this address resolution protocol probe messages;
That adds in the pairing address analysis protocol table item in described sender IP address in embodiments of the present invention is the VRRP ID of described virtual IP address correspondence, in other embodiments of the invention, can add other signs of can be unique determining the VRRP groups of routers of described virtual IP address correspondence, the present invention does not limit this yet.
505, according to described address analysis protocol table item suspended network device forwards data message under Layer 2 switch, the source MAC of described data message is the pairing virtual MAC of described VRRP ID address;
Described data message is a unicast message, and target MAC (Media Access Control) address is the source MAC of described address resolution protocol probe messages; Receive after the described data message, at first to judge in the described address analysis protocol table item of described equipment correspondence and whether be added with VRRP ID, if do not have, then transmit described data message, this moment, the source MAC of described data message was the pairing MAC Address of physical interface of transmitting described data message, but not the virtual MAC address of described groups of routers;
If have, then obtain described VRRP ID, and judge further whether current machine is the main VRRP router of using, if not, then transmit described data message, this moment, the source MAC of described data message was the pairing MAC Address of physical interface of transmitting described data message, but not the virtual MAC address of described groups of routers;
If then transmitting described source MAC is the data message of the pairing virtual MAC of described VRRP ID address, its concrete steps can comprise:
In described address analysis protocol table item, obtain the pairing VRRP groups of routers in described data message purpose IP address;
The pairing virtual MAC of described VRRP groups of routers address is encapsulated as the source MAC of described data message;
Transmit the data message after encapsulating.
The embodiment of the invention by suspended network under Layer 2 switch in the device forwards source MAC be the data message of the pairing virtual MAC of described VRRP ID address, because described data message is a unicast message, therefore can arrive described equipment by described Layer 2 switch, thereby the mistake deletion to described virtual MAC address list item has been avoided in the existence of VRRP groups of routers that made described device learns.
In other embodiments of the invention; also can comprehensively use the above embodiment of the present invention; can be according to condition; by being configured in different scenes or implementing above-mentioned a certain embodiment respectively in the moment; perhaps also can implement the foregoing description simultaneously; preventing under the Layer 2 switch in the suspended network equipment more reliably to the deletion of virtual MAC list item mistake, this for those skilled in the art can according to content provided by the invention the embodiment that can expect easily, ought to be within protection scope of the present invention.
As shown in Figure 6, the embodiment of the invention provides a kind of device that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch, comprising:
First judge module 601, the VRRP groups of routers sign that whether has been used for judging in the ARP list item of suspended network equipment correspondence under the Layer 2 switch mark;
Second judge module 602 is used for judging whether this machine is the primary route device of the corresponding VRRP groups of routers of described VRRP groups of routers sign;
Sending module 603, be used for when second judge module 602 judges that this machine is the primary route device of described VRRP groups of routers, send unicast message, the source MAC of described unicast message is that described VRRP groups of routers identifies pairing virtual MAC address, and target MAC (Media Access Control) address is the MAC Address of equipment in the suspended network under the described Layer 2 switch.
The embodiment of the invention provides prevents under the Layer 2 switch that equipment is to the device of virtual MAC list item mistake deletion in the suspended network, send unicast message by suspended network equipment under Layer 2 switch, the source MAC of described unicast message is the virtual MAC address of VRRP groups of routers, thereby the described VRRP groups of routers of described device learns is not exitted network yet, avoided mistake deletion described virtual MAC address list item.
Still as shown in Figure 6, a kind of device that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch that the embodiment of the invention provides also comprises:
First receiver module 604, be used for receiving the first address resolution protocol probe messages that suspended network equipment sends under the Layer 2 switch, this first address resolution protocol probe messages content comprises: the virtual IP address of sender IP address, source MAC and described VRRP groups of routers, wherein said source MAC are exactly the MAC Address of equipment in the suspended network under the described Layer 2 switch;
Mark module 605 is used for the VRRP groups of routers sign of the described virtual IP address correspondence of mark in the ARP list item of suspended network equipment correspondence under described Layer 2 switch.
The embodiment of the invention is by adding VRRP groups of routers sign in the source IP address corresponding address analytic protocol table entry of address resolution protocol probe messages, thereby when sending unicast message, can be according to the IP address of suspended network equipment under the Layer 2 switch, inquire described VRRP groups of routers sign, the virtual MAC address of the VRRP groups of routers that described VRRP groups of routers sign is corresponding is encapsulated as the source MAC of described unicast message, send to described equipment, thereby the described VRRP groups of routers of described device learns is not exitted network yet, avoided mistake deletion described virtual MAC address list item.
As shown in Figure 7, a kind of device that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch that the embodiment of the invention provides, except that comprising first judge module 601, second judge module 602, sending module 603, first receiver module 604 and mark module 605, also comprise:
Second receiver module 706 is used to receive the data message that will transmit, and the purpose IP address of described data message is the sender IP address of the described first address resolution protocol probe messages;
In embodiments of the present invention, described sending module 603 specifically comprises:
Acquiring unit is used for obtaining the pairing VRRP groups of routers sign in described data message purpose IP address at described address analysis protocol table item;
Transmitting element is used for the corresponding virtual MAC address of described VRRP groups of routers sign is encapsulated as the source MAC of described data message, and transmits the described data message after the encapsulation.
The embodiment of the invention provides prevents under the Layer 2 switch that equipment is to the device of virtual MAC list item mistake deletion in the suspended network, by device forwards source MAC in the suspended network under Layer 2 switch is the data message of the virtual MAC of described VRRP groups of routers, because described data message is a unicast message, therefore can arrive described equipment by described Layer 2 switch, thereby the mistake deletion to described virtual MAC address list item has been avoided in the existence of VRRP groups of routers that made described device learns.
The embodiment of the invention provides a kind of device that prevents that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch again, comprises first judge module 601, second judge module 602, sending module 603, first receiver module 604 and mark module 605; Wherein, sending module specifically comprises:
Acquiring unit is used for obtaining at described address analysis protocol table item the VRRP groups of routers sign of described virtual IP address correspondence;
Transmitting element, be used to send described unicast message, described unicast message is the second address resolution protocol probe messages, and source MAC is that described VRRP groups of routers identifies pairing virtual MAC address, and target MAC (Media Access Control) address is the source MAC of the described first address resolution protocol probe messages.
The embodiment of the invention provides prevents under the Layer 2 switch that equipment is to the device of virtual MAC list item mistake deletion in the suspended network, broadcast by tables of equipment in the suspended network under Layer 2 switch and to send ARP probe packet, the target MAC (Media Access Control) address of described ARP probe packet is the MAC Address of described equipment, source MAC is the virtual MAC address of the VRRP groups of routers once surveyed of described equipment, because described ARP probe packet is a unicast message, therefore can arrive described equipment by described Layer 2 switch, thereby the mistake deletion to described virtual MAC address list item has been avoided in the existence of VRRP groups of routers that made described device learns.
The embodiment of the invention provides a kind of router, described router can comprise provides any one to prevent the device that equipment is deleted virtual MAC list item mistake in the suspended network under the Layer 2 switch in the embodiment of the invention, thereby make described router suspended network equipment under Layer 2 switch send unicast message, the source MAC of described unicast message is the virtual MAC address of VRRP groups of routers, thereby the described VRRP groups of routers of described device learns is not exitted network yet, avoided mistake deletion described virtual MAC address list item.
One of ordinary skill in the art will appreciate that all or part of step that realizes in the foregoing description method is to instruct relevant hardware to finish by program, described program can be stored in the computer-readable recording medium, as ROM/RAM, magnetic disc or CD etc.
The above; only be the specific embodiment of the present invention, but protection scope of the present invention is not limited thereto, anyly is familiar with those skilled in the art in the technical scope that the present invention discloses; can expect easily changing or replacing, all should be encompassed within protection scope of the present invention.Therefore, protection scope of the present invention should be as the criterion by described protection range with claim.