Summary of the invention
In view of this, first purpose of the present invention is to provide a kind of method that Customer Edge router CE is carried out local monitor, in the situation of other flow, can realize neatly the monitoring to monitored CE in not affecting MPLS L3 VPN network.
Second purpose of the present invention is to provide a kind of routing device, in the situation of other flow, can realize neatly the monitoring to monitored CE in not affecting MPLS L3 VPN network.
The 3rd purpose of the present invention is to provide a kind of method that Customer Edge router CE is carried out remote monitoring, in the situation of other flow, can realize neatly the monitoring to monitored CE in not affecting MPLS L3 VPN network.
The 4th purpose of the present invention is to provide a kind of routing device, in the situation of other flow, can realize neatly the monitoring to monitored CE in not affecting MPLS L3 VPN network.
The 5th purpose of the present invention is to provide a kind of routing device, in the situation of other flow, can realize neatly the monitoring to monitored CE in not affecting MPLS L3 VPN network.
In order to achieve the above object, the technical scheme of the present invention's proposition is:
A kind of Customer Edge router CE is carried out the method for local monitor, be applied in three layers of MPLS VPN network MPLS L3 VPN three-layer network, the method comprises:
By provider edge router PE be the monitoring CE a specific down hop that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface;
Described PE receives behind the next message of monitored CE, be the interface that the outgoing interface of the message of monitored CE is set to monitor CE according to described incoming interface, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
After described PE receives and comes and go to the message of monitored CE from common CE, be the interface that the outgoing interface of the message of monitored CE is set to monitor CE according to described outgoing interface, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
Described PE receives behind the next message of monitoring CE, forwards the packet to monitored CE or common CE.
After PE receives message, forward the packet to monitoring CE and comprise:
After PE receives message, be described packet labeling incoming interface attribute; To mark the message of incoming interface attribute carry out route querying, be its outgoing interface attribute of the packet labeling after the described route querying; To mark the message of incoming interface attribute and outgoing interface attribute judge, determine the down hop of this message.
A kind of routing device, be applied in three layers of MPLS VPN network MPLS L3 VPN three-layer network, as provider edge router PE Customer Edge router CE is carried out local monitor, this routing device comprises: local setting unit, the first local retransmission unit, the second local retransmission unit and the 3rd local retransmission unit, wherein
Described local setting unit, be used to monitoring CE that a specific down hop that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of PE, be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first local retransmission unit, be used for receiving behind the next message of monitored CE, it is the outgoing interface of the message of monitored CE is set to monitor CE by local setting unit interface according to described incoming interface, the specific down hop that described message redirecting is arranged for monitoring CE to setting unit, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described second local retransmission unit, be used for receiving from common CE and after going to the message of monitored CE, it is the outgoing interface of the message of monitored CE is set to monitor CE by local setting unit interface according to described outgoing interface, the specific down hop that described message redirecting is arranged for monitoring CE to setting unit, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described the 3rd local retransmission unit is used for receiving behind the next message of monitoring CE, forwards the packet to monitored CE or common CE.
A kind of method that Customer Edge router CE is carried out remote monitoring is applied in three layers of MPLS VPN network MPLS L3 VPN three-layer network, and the method comprises:
Be respectively monitoring CE by monitoring provider edge router PE and monitored PE a specific down hop that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE; Be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, and the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE;
When monitored PE receives behind the next message of monitored CE, be the interface that the outgoing interface of the message of monitored CE is set to monitor CE according to described incoming interface, described message redirecting is arrived the specific down hop that arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
After monitored PE receives next from common CE and goes to the message of monitored CE, be the interface that the outgoing interface of the message of monitored CE is set to monitor CE according to described outgoing interface, described message redirecting is arrived the specific down hop that arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
When monitored PE receives behind the next message of monitoring CE, forward the packet to monitored CE or common CE;
When monitoring PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
After monitoring PE receives next from common CE and goes to the message of monitored CE, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
After monitoring PE receives from monitoring CE and after going to the message of monitored CE, and message stamped the VPN_Local label, be forwarded to monitored PE, forward the packet to monitored CE by monitored PE.
After monitored PE receives message, forward the packet to monitoring CE and comprise:
After monitored PE receives message, be described packet labeling incoming interface attribute; To mark the message of incoming interface attribute carry out route querying, and be the packet labeling outgoing interface attribute after the described route querying; To mark the message of incoming interface attribute and outgoing interface attribute judge, when determining the incoming interface of this message or outgoing interface and being monitored CE, in the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with this message routing.
A kind of routing device, be applied in three layers of MPLS VPN network MPLS L3 VPN three-layer network, as monitored provider edge router PE Customer Edge router CE is carried out remote monitoring, this routing device comprises long-range setting unit, the first long-range monitored retransmission unit, the second long-range monitored retransmission unit and the 3rd long-range monitored retransmission unit, wherein
Described long-range setting unit, be used to monitoring CE that a specific down hop that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE, and be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first long-range monitored retransmission unit, be used for receiving behind the next message of monitored CE, it is the outgoing interface of the message of monitored CE is set to monitor CE by long-range setting unit interface according to described incoming interface, described message redirecting is arrived the specific down hop that long-range setting unit arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described second long-range monitored retransmission unit, be used for receiving from common CE and after going to the message of monitored CE, it is the outgoing interface of the message of monitored CE is set to monitor CE by long-range setting unit interface according to described outgoing interface, described message redirecting is arrived the specific down hop that long-range setting unit arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described the 3rd long-range monitored retransmission unit is used for receiving behind the next message of monitoring CE, forwards the packet to monitored CE or common CE.
A kind of routing device, be applied in three layers of MPLS VPN network MPLS L3 VPN three-layer network, PE carries out remote monitoring to Customer Edge router CE as the monitoring provider edge router, this routing device comprises long-range setting unit, the first remote monitoring retransmission unit, the second remote monitoring retransmission unit and the 3rd remote monitoring retransmission unit, wherein
Described long-range setting unit, be used to monitoring CE that a specific down hop that comprises local virtual dedicated network VPN_Local label is set, the outgoing interface of this specific down hop is the interface of local monitor CE, and the outgoing interface that will carry the message of VPN_Local label is arranged to monitor the interface of CE;
Described the first remote monitoring retransmission unit, be used for receiving behind the next message of monitored CE, it is the outgoing interface of the message of monitored CE is set to monitor CE by long-range setting unit interface according to described incoming interface, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
Described the second remote monitoring retransmission unit, be used for receiving from common CE and after going to the message of monitored CE, it is the outgoing interface of the message of monitored CE is set to monitor CE by long-range setting unit interface according to described outgoing interface, the specific down hop that arranges for monitoring CE that described message redirecting is arranged to described long-range setting unit, the outgoing interface by specific down hop forwards the packet to monitoring CE;
Described the 3rd remote monitoring retransmission unit, be used for receiving from monitoring CE and after going to the message of monitored CE, be forwarded to monitored PE after message stamped the VPN_Local label that described long-range setting unit arranges for monitoring CE, forward the packet to monitored CE by monitored PE.
In sum, the method that CE is monitored of the present invention, by being respectively monitoring CE by monitoring PE and monitored PE a specific down hop that comprises local virtual dedicated network (VPN_Local) label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE, be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE, thereby so that can only be redirected among the local monitor CE of monitoring PE corresponding to specific down hop outgoing interface by the message of monitored CE, transmit again after CE processes it by monitoring, and when message need to be forwarded to long-range monitored CE, message is delivered to monitored PE after being added the VPN_Local label, monitored PE bullet is carried out normal IP forwarding after falling label, message by other CE is then transmitted according to normal flow process, also namely can be in not affecting MPLS L3 VPN network in the situation of other flow, can realize neatly the monitoring to monitored CE.
Embodiment
In order to solve problems of the prior art, the present invention proposes a kind of method of in MPLS L3 VPN network, CE being monitored, namely be respectively monitoring CE by monitoring PE and monitored PE a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE, be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE, thereby so that can only be redirected among the local monitor CE of monitoring PE corresponding to specific down hop outgoing interface by the message of monitored CE, transmit again after CE processes it by monitoring, and when message need to be forwarded to long-range monitored CE, message is delivered to monitored PE after being added the VPN_Local label, monitored PE bullet is carried out normal IP forwarding after falling label, then transmits according to normal flow process by the message of other CE.
For convenience, follow-uply will need monitored CE to be called monitored CE, the CE of the monitored CE of monitoring will be called monitoring CE, the CE except monitoring CE and monitored CE will be called common CE.Simultaneously, because the present invention both can carry out local monitor to CE, can carry out remote monitoring to CE again, and when CE was carried out local monitor, monitoring PE and monitored PE were same, the unified PE that is referred to as; When CE is carried out remote monitoring, will be called with the PE that monitored CE directly links to each other monitored PE, will be called with the PE that monitoring CE directly links to each other monitoring PE, the CE except monitoring PE and monitored PE is called common PE.
Based on above-mentioned introduction, the specific implementation of scheme of the present invention comprises:
When CE is carried out local monitor,
Be that monitoring CE arranges a specific down hop that comprises the VPN_Local label by PE, the outgoing interface of this specific down hop is the interface of the local monitor CE of PE, is the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface;
Described PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
After described PE receives and comes and go to the message of monitored CE from common CE, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
Described PE receives behind the next message of monitoring CE, forwards the packet to monitored CE or common CE.
When CE is carried out remote monitoring,
Be respectively monitoring CE by PE and monitored PE a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE; Be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, and the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE;
When monitored PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived the specific down hop that arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
After monitored PE receives next from common CE and goes to the message of monitored CE, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived the specific down hop that arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
When monitored PE receives behind the next message of monitoring CE, forward the packet to monitored CE or common CE;
When monitoring PE receives behind the next message of monitored CE, the outgoing interface that according to the incoming interface of described setting is the message of monitored CE is the interface of monitoring CE, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
After monitoring PE receives next from common CE and goes to the message of monitored CE, the outgoing interface that according to the outgoing interface of described setting is the message of monitored CE is the interface of monitoring CE, to the specific down hop that arranges for monitoring CE, the outgoing interface by specific down hop forwards the packet to monitoring CE with described message redirecting;
After monitoring PE receives from monitoring CE and after going to the message of monitored CE, and message stamped the VPN_Local label, be forwarded to monitored PE, forward the packet to monitored CE by monitored PE.
For making the purpose, technical solutions and advantages of the present invention clearer, the present invention is described in further detail below in conjunction with the accompanying drawings and the specific embodiments.
Embodiment one
In the present embodiment, monitored CE is carried out local monitor, also namely by with PE that monitored CE directly links to each other on other CE as monitoring CE, realize the monitoring to monitored CE.
The below illustrates the specific implementation process of monitored CE being carried out local monitor take the described workflow that CE is monitored of Fig. 3 as example, and this process is based on the described MPLS L3 of Fig. 1 VPN basic network topology, when CE41 as monitored CE, CE40 is as monitoring CE, and when CE41 access CE10, this flow process may further comprise the steps:
Step 301:CE41 sends to message among the PE4.
In this step, the source IP address that sends to the message of PE4 is the CE41 address, and purpose IP address is the CE10 address.
Need to prove, before carrying out this step, need to for the monitoring CE in each VPN instance on it specific down hop that comprises the VPN_Local label be set by PE4, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE, be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that carries the message of VPN_Local label is arranged to monitor the interface of CE.Wherein, described specific down hop generates by static mode and triggers without ARP, and the outgoing interface of this specific down hop is the ARP index of monitoring CE for interface, the ARP index of monitoring CE, and the TTL in the header does not subtract 1 when carrying out specific down hop.
After step 302-303:PE4 receives the message that is sent by CE41, message routing to specific down hop, is sent to CE40 with message.
In this step, PE4 is specially message routing: at first, after PE4 receives message, be its incoming interface attribute of described packet labeling, show namely that also this message sends over from CE41 after receiving the message that is sent by CE41 to specific down hop; Secondly, this message carried out route querying after, be its outgoing interface attribute of described packet labeling, the outgoing interface that shows this message is CE10; Again, to mark the message of incoming interface attribute and outgoing interface attribute judge that determine the down hop of described message, be specially: if message incoming interface attribute is monitored CE side, then message is redirected in the specific down hop that arranges into monitoring CE; If the message outgoing interface is monitored CE side, and incoming interface is common CE side or common public network side, and then message is redirected in the specific down hop that arranges into monitoring CE; If the message incoming interface is monitoring CE, then message routing is in normal down hop.
Need to prove, in this step, can distinguish this two kinds of different CE for monitoring CE arranges respectively different signs with monitored CE, be as the criterion with the realization that does not affect the embodiment of the invention in the reality.
After step 304 ~ 305:CE40 receives message, message is correspondingly processed, thereby finished monitoring work to the message that is sent by CE41, simultaneously, also need the message that receives is forwarded back to PE4 again.
In this step, CE40 processes message can be for copying portion with message, and the content of the message after copying is resolved, and can also for other operation that message is processed, be as the criterion with the realization that does not affect the embodiment of the invention in the reality.
Step 306:PE4 carries out route querying to the message that is returned by CE40 that receives, and after determining its down hop and being PE1, stamps the VPN private network tags and the public network tunnel label sends among the PE1.
PE4 receive the monitoring CE40 return message the time, this moment, source IP and the purpose IP of message did not change, at this moment, PE4 does not carry out uRpf and checks, but directly inquire about the interior routing table of VPN, after determining its down hop and being PE1, stamp normal VPN private network tags and public network tunnel label with message from specifying the public network interface to send.
Need to prove specifically how in message, to stamp the VPN private network tags and the public network tunnel label is prior art, repeat no more here.
Step 307 ~ 308:PE1 receives the laggard walking along the street of message that PE4 sends by searching, and after determining its down hop and being CE10, forwards the packet to CE10.
Carry VPN private network tags and public network tunnel label in the message by the PE4 transmission that PE1 receives, PE1 can fall VPN private network tags and the public network tunnel label that carries in the message by bullet before carrying out route querying.
In this step, how PE1 carries out route querying also is prior art, repeats no more here.
Step 309 ~ 310:CE10 processes the message by the PE1 transmission that receives, and produces response message, and described response message is transmitted to PE1.
CE10 can reply message after receiving message, produces response message, and the purpose IP in the response message is the IP of CE41, and source IP is the IP of CE10.
Step 311 ~ 312:PE1 receives the laggard walking along the street of response message that sent by CE10 by searching, and after determining its down hop and being PE4, is transmitted to PE4 after response message stamped VPN private network tags and public network tunnel label.
Step 313 ~ 314:PE4 receives the laggard walking along the street of response message by searching, it is routed to specific down hop after, response message is transmitted to CE40.
In this step, PE4 receives the laggard walking along the street of response message by searching, it is routed to specific down hop is specially: carry VPN private network tags and public network tunnel label in the response message by the PE1 transmission that PE4 receives, before carrying out route querying, PE4 can fall VPN private network tags and the public network tunnel label that carries in the response message by bullet, afterwards, in the VPN routing table, carry out route querying, because purpose IP is the CE41 address in the response message header information at this moment, outgoing interface is monitored CE, incoming interface is common public network side, therefore the bullet response message that falls label is redirected to specific down hop, its outgoing interface is CE40, TTL does not subtract one, the ARP index is the ARP index of CE40 equipment, and message is directly delivered to CE40.
After step 315 ~ 316:CE40 processes response message, finish the monitoring work to the message that sends to CE41, simultaneously, response message is forwarded back to PE4.
In this step, the concrete operations that CE40 processes response message repeat no more here with step 304 ~ 305.
Step 317:PE4 will be transmitted to CE41 after will being routed to down hop by the response message that CE40 is forwarded back to.
After CE41 receives response message, also need response message is processed operation accordingly, to realize the access work to CE10.
That so far, has finished namely that present embodiment adopts carries out the whole workflow of local monitor to monitored CE.
Need to prove, in the present embodiment, on the one hand, because all messages that send from monitored CE41 all are forwarded to monitoring CE40 in advance, also just realized going out the monitoring of monitored CE41; On the other hand, the destination address that sends from other all CE all is forwarded to monitoring CE40 in advance for all flows of monitoring CE41, has also realized entering the traffic monitoring of monitored CE41 equipment.And monitored CE, the IP header fields of the message that it receives such as purpose IP, source IP and TTL do not have to change, therefore for not impact of the upper layer application on the monitored CE.
Also it should be noted that, in the monitoring environment of local CE, to the quantity of monitored CE without limits, that is to say and allowed a plurality of monitored CE on the PE4 equipment, the data traffic of a plurality of monitored CE is identical with single CE, and difference is that the outflow of a plurality of monitored CE and inbound traffics all can be forwarded to monitoring CE in advance.In addition, the traffic forwarding in the MPLS L3 VPN network between other non-supervised CE is still continued to use original forward-path, is not subjected to monitored PE(to connect the PE of monitored CE) with the PE that is connected PE(and has connected monitoring CE) impact.
Based on said method, Fig. 4 has provided being applied in the MPLS L3 VPN three-layer network that present embodiment adopts, CE is carried out the structural representation of the routing device of local monitor as PE, as shown in Figure 4, this routing device comprises: local setting unit 41, the first local retransmission unit 42, the second local retransmission unit 43 and the 3rd local retransmission unit 44, wherein
Described local setting unit 41, be used to monitoring CE that a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of PE, be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first local retransmission unit 42, be used for receiving behind the next message of monitored CE, the incoming interface that arranges according to described setting unit 41 is that the outgoing interface of the message of monitored CE is the interface of monitoring CE, the specific down hop that described message redirecting is arranged for monitoring CE to setting unit 41, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described second local retransmission unit 43, be used for receiving from common CE and after going to the message of monitored CE, the outgoing interface that arranges according to described setting unit 41 is that the outgoing interface of the message of monitored CE is the interface of monitoring CE, the specific down hop that described message redirecting is arranged for monitoring CE to setting unit 41, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described the 3rd local retransmission unit 44 is used for receiving behind the next message of monitoring CE, forwards the packet to monitored CE or common CE.
So far, namely obtained of the present inventionly for as PE CE being carried out the routing device of local monitor, the specific works flow process of routing device shown in Figure 4 can referring to the workflow of the described method of Fig. 3, repeat no more here.
Embodiment two
In the present embodiment, monitored CE is carried out remote monitoring, also namely by being different from CE on other PE that directly links to each other with monitored CE as monitoring CE, realize the monitoring to monitored CE.
Fig. 5 has provided the specific implementation process of monitored CE being carried out remote monitoring, with embodiment one, present embodiment also is based on the described MPLS L3 of Fig. 1 VPN basic network topology, when CE41 as monitored CE, CE60 is as monitoring CE, similarly, when CE41 access CE10, this flow process may further comprise the steps:
Step 501:CE41 sends to message among the PE4.
In this step, the source IP address that sends to the message of PE4 is the CE41 address, and purpose IP address is the CE10 address.
With the step 301 among the embodiment one, before carrying out this step, need to be respectively CE60 by PE6 and PE4 a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local CE60 of PE6, be the interface that the outgoing interface of the message of CE41 is arranged to CE60 by PE4 with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to the interface of CE60, and the outgoing interface that will carry the message of VPN_Local label by PE6 is arranged to the interface of CE60.Wherein, described specific down hop generates by static mode and triggers without ARP, the outgoing interface of this specific down hop is monitoring PE, is the local monitor CE60 interface of PE60, the ARP index that the ARP index is local monitor CE60, and the TTL in the header does not subtract 1 when carrying out specific down hop.
After step 502 ~ 503:PE4 receives the message that CE41 sends, message routing to specific down hop, and after getting access to VPN_Local in the specific down hop, will be sent to PE6 behind message packaging V PN_Local label and the public network tunnel label.
In this step, after PE4 receives the message of CE41 transmission, message routing is arrived specific down hop, and the VPN_Local that gets access in the specific down hop is specially: at first, after PE4 receives message, specify the incoming interface attribute for described message, namely incoming interface is monitored CE; Secondly, this message is carried out route querying, the outgoing interface of this message that finds is set to the outgoing interface of described message, and the outgoing interface that shows this message is CE10; Again, incoming interface and the outgoing interface of the message that added attribute are judged, determine this message relevant with monitored CE after, with message routing in specific down hop, and get access to the VPN_Local in the specific down hop, at this moment, TTL do not subtract one and down hop be PE6.
Bullet fell the VPN_Local label after step 504 ~ 505:PE6 received message, and message is sent to CE60.
Carry VPN_Local label and public network tunnel label in the message by the PE4 transmission that PE6 receives, before PE6 forwards the packet, can fall VPN_Local label and the public network tunnel label that carries in the message by bullet.
In this step, the data I P field of message is without any modification, and namely source IP still is the IP address of CE41, and purpose IP still is the IP address of CE10.
After step 506 ~ 507:CE60 receives message, message is correspondingly processed, thereby finished monitoring work to the message that is sent by CE41, simultaneously, the message that receives is forwarded back to PE6 again.
In this step, the operation that monitoring CE processes message repeats no more here with embodiment one.
Step 508:PE6 to down hop, and sends to PE1 after message stamped VPN private network tags and public network tunnel label with message routing.
After PE2 receives the message that is returned by CE60, because the source IP address of message is the IP address of CE41, purpose IP address is the IP address of CE10, therefore, PE6 will carry out route querying, after finding out its down hop and being PE10, forward the packet to PE1 behind normal VPN private network tags and the public network tunnel label in the encapsulation.
Specifically how in message, to stamp VPN private network tags and public network tunnel label and be prior art, repeat no more here.
Bullet fell the VPN private network tags after step 509 ~ 510:PE1 received the message that PE6 sends, and forwarded the packet to CE10.
Carry VPN private network tags and public network tunnel label in the message by the PE6 transmission that PE1 receives, before message is transmitted, can fall VPN private network tags and the public network tunnel label that carries in the message by bullet.
Step 511 ~ 512:CE10 processes the message by the PE1 transmission that receives, and produces response message, and described response message is transmitted to PE1.
CE10 can reply message after receiving message, produces response message, and the source IP address in the response message is the IP address of CE10, and purpose IP address is the IP address of CE41.
Step 513 ~ 514:PE1 receives the laggard walking along the street of response message that sent by CE10 by searching, and after determining its down hop and being PE4, is transmitted to PE4 after response message stamped VPN private network tags and public network tunnel label.
Step 515:PE4 carries out route querying with response message, and it is routed to specific down hop, get access to the VPN_Local in the specific down hop after, the upper VPN_Local label of response message encapsulation and public network tunnel label are sent to PE6.
In this step, the response message that PE4 receives carries VPN label and public network tunnel label, need bullet to fall VPN label and the laggard walking along the street of public network tunnel label by searching, because purpose IP address is that CE41, outgoing interface are monitored CE, therefore response message is routed to specific down hop, VPN_Local label from this specific down hop, TTL do not subtract one and after down hop is PE6, and response message packaging V PN_Loacl label and public network tunnel label are sent to PE6.
Bullet fell the VPN_Loacl label after step 516 ~ 517:PE6 received response message, and response message is transmitted to CE60.
After step 518 ~ 519:CE60 processes response message, finish the monitoring work to the message that sends to CE41, simultaneously, response message is forwarded back to PE6.
In this step, the concrete operations that CE60 processes response message repeat no more here with step 506 ~ 507.
Step 520:PE6 will carry out route querying by the response message that CE60 is forwarded back to, and send to PE4 after it is stamped VPN_Local label and public network tunnel label.
In this step, after PE6 receives the message of monitoring CE transmission, directly carry out route querying, after purpose IP address in the discovery response message is the IP address of CE41, because the purpose IP address in the message is the IP address of CE41, its public network down hop is monitored PE, so the private network tags of message is arranged to the VPN_Local label, is about to send to PE4 after response message is stamped VPN_Local label and public network tunnel label.
Step 521:PE4 will be transmitted to CE41 by the response message that PE6 transmits.
PE4 receives the response message that is sent by PE6 and carries the VPN_Local label, bullet falls the laggard walking along the street of label by searching, finding its down hop is CE41, because message carries the VPN_Local label, PE4 arranges the message incoming interface and is monitoring CE side, and directly carry out normal IP routing operations, forward the packet to CE41.
After CE41 receives response message, also need response message is processed operation accordingly, to realize the access work to CE10.
So far, the whole workflow that monitored CE is carried out remote monitoring of having finished namely that present embodiment adopts.
Need to prove that in the present embodiment, on the one hand, all messages that send from monitored CE41 all are forwarded to monitoring PE in advance on monitored PE, be forwarded to monitoring CE60, the traffic monitoring that has realized monitored CE41 by monitoring PE; On the other hand, the destination address that sends from other all CE is after all flows of CE41 are sent to the monitored PE of purpose, all is forwarded in advance monitoring PE, and is transmitted to monitoring CE60 by monitoring PE, has realized entering the traffic monitoring of monitored CE41.And for monitored CE, the IP header fields of the message that it receives does not change such as purpose IP, source IP and TTL etc., therefore for not impact of the upper layer application on the monitored CE.
Based on said method, present embodiment adopts is used for CE being carried out the structural representation of routing device of remote monitoring respectively referring to Fig. 6 and Fig. 7 as monitored PE and monitoring PE, as shown in Figure 6, be used for comprising as the routing device of monitored PE: long-range setting unit 61, the first long-range monitored retransmission unit 62, the second long-range monitored retransmission unit 63 and the 3rd long-range monitored retransmission unit 64, wherein
Described long-range setting unit 61, be used to monitoring CE that a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE, and be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE;
The described first long-range monitored retransmission unit 62, be used for receiving behind the next message of monitored CE, what arrange according to described long-range setting unit 61 is that the outgoing interface of the message of monitored CE is the interface of monitoring CE by incoming interface, described message redirecting is arrived the specific down hop that long-range setting unit 61 arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described second long-range monitored retransmission unit 63, be used for receiving from common CE and after going to the message of monitored CE, the outgoing interface that arranges according to described long-range setting unit 61 is that the outgoing interface of the message of monitored CE is the interface of monitoring CE, described message redirecting is arrived the specific down hop that long-range setting unit 61 arranges for monitoring CE, after obtaining the VPN_Local label in the described specific down hop, the outgoing interface by specific down hop forwards the packet to monitoring CE;
The described the 3rd long-range monitored retransmission unit 64 is used for receiving behind the next message of monitoring CE, forwards the packet to monitored CE or common CE.
So far, namely obtained the structural representation for CE being carried out the routing device of remote monitoring as monitored PE of the present invention.
Fig. 7 is described for as monitoring PE the routing device that CE carries out remote monitoring being comprised: long-range setting unit 71, the first remote monitoring retransmission unit 72, the second remote monitoring retransmission unit 73 and the 3rd remote monitoring retransmission unit 74, wherein,
Described long-range setting unit 71, be used to monitoring CE that a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of local monitor CE, and the outgoing interface that will carry the message of VPN_Local label is arranged to monitor the interface of CE;
Described the first remote monitoring retransmission unit 72, be used for receiving behind the next message of monitored CE, the incoming interface that arranges according to described long-range setting unit 71 is that the outgoing interface of the message of monitored CE is the interface of monitoring CE, the specific down hop that described message redirecting is arranged for monitoring CE to described long-range setting unit 71, the outgoing interface by specific down hop forwards the packet to monitoring CE;
Described the second remote monitoring retransmission unit 73, be used for receiving from common CE and after going to the message of monitored CE, the outgoing interface that arranges according to described long-range setting unit 71 is that the outgoing interface of the message of monitored CE is the interface of monitoring CE, the specific down hop that described message redirecting is arranged for monitoring CE to described long-range setting unit 71, the outgoing interface by specific down hop forwards the packet to monitoring CE;
Described the 3rd remote monitoring retransmission unit 74, be used for receiving from monitoring CE and after going to the message of monitored CE, be forwarded to monitored PE after message stamped the VPN_Local label that described long-range setting unit 71 arranges for monitoring CE, forward the packet to monitored CE by monitored PE.
So far, namely obtained the routing device for CE being carried out remote monitoring as monitoring PE of the present invention.The specific works flow process of Fig. 6 and the described routing device of Fig. 7 can referring to Fig. 5, repeat no more here.
In a word, the method of in MPLS L3 VPN network, CE being monitored of the present invention, by being respectively monitoring CE by monitoring PE and monitored PE a specific down hop that comprises the VPN_Local label is set, the outgoing interface of this specific down hop is the interface of the local monitor CE of monitoring PE, be the interface that the outgoing interface of the message of monitored CE is arranged to monitor CE by monitored PE with incoming interface or outgoing interface, the incoming interface that carries the message of VPN_Local label is arranged to monitor the interface of CE, the outgoing interface that will carry the message of VPN_Local label by monitoring PE is arranged to monitor the interface of CE, thereby so that can only be redirected among the local monitor CE of monitoring PE corresponding to specific down hop outgoing interface by the message of monitored CE, transmit again after CE processes it by monitoring, and when message need to be forwarded to long-range monitored CE, message is delivered to monitored PE after being added the VPN_Local label, monitored PE bullet is carried out normal IP forwarding after falling label, message by other CE is then transmitted according to normal flow process, also namely can be in not affecting MPLS L3 VPN network in the situation of other flow, can realize neatly the monitoring to monitored CE.
The above only is preferred embodiment of the present invention, and is in order to limit the present invention, within the spirit and principles in the present invention not all, any modification of making, is equal to replacement, improvement etc., all should be included within the scope of protection of the invention.