CN104468394B - Vxlan one kind of network packet forwarding method and apparatus - Google Patents

Vxlan one kind of network packet forwarding method and apparatus Download PDF

Info

Publication number
CN104468394B
CN104468394B CN201410727841.2A CN201410727841A CN104468394B CN 104468394 B CN104468394 B CN 104468394B CN 201410727841 A CN201410727841 A CN 201410727841A CN 104468394 B CN104468394 B CN 104468394B
Authority
CN
China
Prior art keywords
vtep
vxlan
tunnel
ip address
corresponding
Prior art date
Application number
CN201410727841.2A
Other languages
Chinese (zh)
Other versions
CN104468394A (en
Inventor
王茹萍
王伟
Original Assignee
新华三技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 新华三技术有限公司 filed Critical 新华三技术有限公司
Priority to CN201410727841.2A priority Critical patent/CN104468394B/en
Publication of CN104468394A publication Critical patent/CN104468394A/en
Application granted granted Critical
Publication of CN104468394B publication Critical patent/CN104468394B/en

Links

Abstract

本发明公开了一种VXLAN网络中报文转发方法及装置,所述VXLAN网络包括VXLAN隧道两端的第一虚拟通道终端VTEP和第二VTEP,其中该方法包括:在第一VTEP上配置多个VTEP IP地址;第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,且隧道两端的源和目的VTEP IP地址并不相同,用于第一VTEP下的用户报文在对应业务服务等级的VXLAN隧道上转发。 The present invention discloses a packet forwarding network VXLAN method and apparatus, the network comprising a first virtual channel VXLAN VTEP terminal ends of the tunnel and the second VXLAN VTEP, wherein the method comprises: in a first plurality VTEP VTEP IP address; a first VTEP were established using a tunnel VXLAN VTEP IP address of each IP address pair associated with each end of the second VTEP VTEP, each corresponding to a different tunnel VXLAN service level, and the source and destination IP tunnel ends VTEP address is not the same for users in the first VTEP packet forwarding on VXLAN tunnel corresponding service level of service. 该方法能优先保证特殊服务的带宽要求。 This method can give priority to ensuring the bandwidth requirements of special services.

Description

一种VXLAN网络中报文转发方法及装置 VXLAN one kind of network packet forwarding method and apparatus

技术领域 FIELD

[0001] 本发明涉及网络通信技术领域,特别涉及一种VXLAN网络中报文转发方法及装置。 [0001] The present invention relates to network communication technology field, particularly to a network packet forwarding VXLAN method and apparatus.

背景技术 Background technique

[0002]在云计算的多租户环境中,每个租户都需要分配一个能够与其它逻辑网络进行很好隔离的逻辑网络。 [0002] In the multi-tenant cloud computing environment, a need to assign each tenant can be sufficiently isolated from other logical network logical network. 逻辑网络的隔离一般通过虚拟局域网(VLAN,Virtual Local Area Network)技术来解决。 Isolation logic network is generally solved by virtual local area network (VLAN, Virtual Local Area Network) technology. 在IEEE802.1Q标准中,由于VLAN的标识最大12bit,所以一定范围内最大的VLAN个数只有4K。 In the IEEE802.1Q standard, since the maximum 12bit VLAN identifier, so the maximum number of VLAN only within a certain range 4K. 随着云环境下的多租户需求越来越多,4K个VLAN已经不能满足数据中心大规模网络部署的需求。 As more and more multi-tenant demand in the cloud, 4K a VLAN has been unable to meet the demand of large-scale data center network deployments. 另外,在云计算环境中,工作负载经常需要在多个数据中心和多个云平台中进行迀移,而当前基于IP子网的区域划分限制了二层连通性的应用。 Further, in a cloud computing environment, work load often need a plurality of shift Gan plurality of data centers and cloud platforms, and this limits the application area of ​​Layer connectivity based on IP subnets.

[0003] VXLAN是一种MAC-in-UDP技术,它通过在网络的2.5层设置一个新的网络分段模式,加入了一个24bit的段标识符,极大的扩充了云计算环境中所能支持的逻辑网络的数量;并且使得工作负载与物理网络脱离,实现逻辑网络跨越IP网络。 [0003] VXLAN is a MAC-in-UDP technology, which is provided by the network layer 2.5 of a new network segment model, 24bit adding a segment identifier, which greatly expands the cloud computing environment can the number of logical network support; and that the working load from the physical network, implementing logical network spans IP network.

[0004] VXLAN技术使同一个VXLAN中的多个虚拟机(VM,Virtual Machine)可以跨三层网络进行通信,在VXLAN技术中,每个租户对应一个虚拟叠加网,每个虚拟叠加网被认为是一个VXLAN网段,并且通过一个24位的虚拟可扩展局域网网络标识符(VXLAN Network I den tifi er,VNI)标识。 [0004] VXLAN VXLAN in the same technology allows multiple virtual machines (VM, Virtual Machine) to communicate across a network Layer, VXLAN in the art, each tenant corresponds to a virtual overlay network, each virtual overlay network to be considered VXLAN is a network segment, and by a 24-bit virtual local area network identifier may be extended (VXLAN network I den tifi er, VNI) identification. 只有拥有相同VNI的VM之间才允许进行通信。 Only allowed between VM with the same VNI communicate.

[0005] 目前VXLAN组网示意图如图1所示。 [0005] It VXLAN networking diagram shown in Fig. 虚拟通道终端(VTEP)设备(封装解封装VXLAN设备),可以是物理服务器的虚拟交换机(vSwitch),也可以是物理交换机。 Virtual Path Termination (the VTEP) Device (Package VXLAN decapsulation apparatus), a virtual switch may be a physical server (the vSwitch), may be a physical switch. 如图1,在一个物理服务器上跑多台虚拟机VM,同时在服务器上有vSwitch作为VTEP用于VXLAN报文的封装解封装。 1, running multiple virtual machines on a single physical server VM, while a vSwitch VTEP VXLAN for encapsulating packet decapsulation on the server. 两台物理服务器上都运行有如下三个VM,那么每个VM之间通过VXLAN接入公网,由于到同一个目的VTEP (即同一个目的vSwitch),因此第一VTEP和第二VTEP之间只建立一条VXLAN 隧道(Tunnel),三个VM之间的通信都使用这条隧道,如果隧道出现拥塞,无法区分业务进行带宽保证。 Between the following three VM runs on two physical servers, each VM between VXLAN access by the public network, since the same object VTEP (i.e. vSwitch same object), the first and second VTEP VTEP just build a VXLAN tunnel (tunnel), the communication between the three VM use this tunnel, if the tunnel congestion, can not distinguish between business bandwidth guarantee.

[0006] 所以,现有技术方案中提到的VXLAN流量转发都没有一个带宽保证机制,服务器上的多个VXLAN流量如果到同一个对端,那么将会使用同一条VXLAN隧道,当出现网络拥塞的时候,不同VXLAN的流量不能根据业务优先级得到带宽保证。 [0006] Therefore, VXLAN flow in the prior art mentioned in the program do not have a transponder bandwidth guarantee mechanism, VXLAN more traffic on to the same server if a peer, it will use the same tunnel VXLAN, when network congestion occurs when the flow of different VXLAN can not be guaranteed bandwidth based on business priorities.

发明内容 SUMMARY

[0007] 本发明的目的在于提供了一种VXLAN网络中报文转发方法及装置,允许高业务服务等级的流量经过其中的专用VXLAN隧道转发,使不同VXLAN的流量根据业务优先级得到带宽保证。 [0007] The object of the present invention to provide a packet forwarding network VXLAN method and apparatus allowing a high flow rate through a dedicated service level VXLAN wherein forwarding tunnel, the flow rate is obtained different VXLAN bandwidth assurance business priorities.

[0008] 本发明实施例提供了一种VXLAN网络中报文转发方法,所述VXLAN网络包括VXLAN 隧道两端的第一虚拟通道终端VTEP和第二VTEP,该方法包括:在第一VTEP上配置多个VTEP IP地址;第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,且隧道两端的源和目的VTEP IP地址并不相同,用于第一VTEP下的用户报文在对应业务服务等级的VXLAN隧道上转发。 [0008] The embodiments of the present invention provides a packet forwarding VXLAN network, said network comprising a first virtual channel VXLAN VTEP and second terminal ends VXLAN VTEP tunnel, the method comprising: on a first plurality arranged VTEP the IP address of a VTEP; VTEP were used for each first VTEP the IP address to establish a tunnel VXLAN VTEP the IP address for each end of the second VTEP of different VXLAN tunnel corresponding to each service level, and the source and destination ends of the tunnel VTEP IP address is not the same for users in the first VTEP packet forwarding on VXLAN tunnel corresponding service level of service.

[0009] 本发明实施例还提供了一种VXLAN网络中报文转发方法,应用于与所述第一虚拟通道终端VTEP直连的交换机;该方法包括:在所述交换机上配置指向第一VTEP的静态路由; 将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给第二VTEP,用于第一VTEP在接收流表前,将自身路由通告给第二VTEP。 [0009] The present invention further provides a VXLAN network packet forwarding method applied to the first terminal VTEP direct virtual channel switch; the method comprising: in a first point disposed on the switch VTEP static routing; static route for introduction of the routing protocol running on the public network, the routing protocol run by the advertisement to the second VTEP public network, for receiving a first stream before VTEP table, the route to a second VTEP advertise itself.

[0010] 本发明实施例还提供了一种VXLAN网络中报文转发装置,该装置应用于虚拟通道终端VTEP,包括:VTEP IP配置单元,在VTEP上配置多个VTEP IP地址;隧道建立单元,分别使用每个VTEP IP地址与对端VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,且隧道两端的源和目的VTEP IP地址并不相同,用于所述VTEP下的用户报文在对应业务服务等级的VXLAN隧道上转发。 [0010] Embodiments of the present invention further provides a VXLAN network packet forwarding device which is applied to the VTEP virtual channel terminal, comprising: VTEP IP configuration unit, a plurality of VTEP IP addresses on the VTEP; tunnel establishing unit, respectively, using the IP address of each VTEP VXLAN establish a tunnel to the IP address of each terminal VTEP VTEP, the source and destination address different from the IP VTEP VXLAN tunnel corresponding to each service level, and both ends of the tunnel are not the same, for the users under the above VTEP packet forwarding on VXLAN tunnel corresponding service level of service.

[0011] 本发明实施例还提供了一种VXLAN网络中报文转发装置,应用于与所述虚拟通道终端VTEP直连的交换机;该装置包括:静态路由配置单元,在所述交换机上配置指向所述VTEP的静态路由;路由通告单元,将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给对端VTEP,用于所述VTEP在接收流表前,将自身路由通告给对端VTEP。 [0011] The present invention further provides a VXLAN network packet forwarding device, the virtual channel is applied to the switch terminal directly connected VTEP; the apparatus comprising: static routing means arranged on the switch points VTEP the static route; route announcement unit, the static routing the routing protocol running on the public network, the routing protocol run by the public network to the peer advertisement VTEP, prior to receiving the VTEP flow table itself announce routes to the end VTEP.

[0012]本发明的有益效果在于,本发明建立多条VXLAN隧道,允许高业务服务等级的流量经过其中的专用VXLAN隧道转发,使不同VXLAN的流量根据业务优先级得到带宽保证。 [0012] Advantageous effects of the present invention, the present invention establishes a plurality of tunnels VXLAN, allow high flow rate through a dedicated service level VXLAN wherein forwarding tunnel, the flow rate is obtained different VXLAN bandwidth assurance business priorities. 避免了当出现网络拥塞的时候,不同VXLAN的流量不能根据业务优先级得到带宽保证。 To avoid when there is network congestion, traffic of different VXLAN can not be guaranteed bandwidth based on business priorities.

附图说明 BRIEF DESCRIPTION

[0013] 图1为VXLAN组网示意图; [0013] FIG 1 is a networking diagram VXLAN;

[0014]图2为本发明提供的一种VXLAN网络中报文转发方法的流程示意图; [0014] FIG. 2 VXLAN one kind of network of the present invention provides the method for forwarding packets of a schematic flow chart;

[0015]图3为本发明实施例一的应用组网场景示意图; [0015] FIG. 3 is a schematic In the networking embodiment of the invention;

[0016]图4为本发明实施例二的应用组网场景示意图; [0016] FIG. 4 is a schematic networking application scenario according to a second embodiment of the present invention;

[0017]图5为本发明实施例提出的一种VXLAN网络中报文转发装置,应用于VTEP的结构示意图; [0017] Figure 5 implement a proposed embodiment VXLAN network packet forwarding apparatus VTEP schematic structural diagram of the present invention is applied;

[0018]图6为本发明实施例提出的一种VXLA謂络中报文转发装置,应用于与VTEP直连的交换机的结构示意图。 [0018] FIG. 6 VXLA configuration diagram of a proposed embodiment for packets that the network forwarding device, is applied to the switch and directly connected VTEP embodiment of the invention.

具体实施方式 Detailed ways

[0019] 以下参照附图,对本发明实施例作进一步地详细说明。 [0019] Referring to the drawings, embodiments of the present invention will be described in further detail.

[0020] 如图2所示,本发明提供了一种VXLAN网络中报文转发方法,所述VXLAN网络包括VXLAN隧道两端的第一VTEP和第二VTEP,该方法包括: [0020] 2, the present invention provides a packet forwarding VXLAN network, said network comprising a first VXLAN VTEP VTEP and second ends VXLAN tunnel, the method comprising:

[0021] 步骤21、在第一VTEP上配置多个VTEP IP地址; [0021] Step 21, a plurality of first VTEP IP addresses on the VTEP;

[0022] 步骤22、第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,且隧道两端的源和目的VTEP IP地址并不相同,用于第一VTEP下的用户报文在对应业务服务等级的VXLAN隧道上转发。 [0022] Step 22, a first VTEP were established using a tunnel VXLAN the IP address of each VTEP VTEP the IP address of each end of the second VTEP, each corresponding to a different tunnel VXLAN service level, and the source and ends of the tunnel the purpose VTEP IP address is not the same for users in the first VTEP packet forwarding on VXLAN tunnel corresponding service level of service.

[0023]综上,通过本发明提供的VXLAN网络中报文转发方法,建立多条VXLAN隧道,允许高业务服务等级的流量经过其中的专用VXLAN隧道转发,使不同VXLAN的流量根据业务优先级得到带宽保证。 [0023] In summary, VXLAN network provided by the present invention, message forwarding method, establish multiple VXLAN tunnels, traffic is high service level through dedicated VXLAN tunnel wherein forwarding the traffic of different VXLAN obtained based on business priorities bandwidth guarantees.

[0024] 下面通过本发明实施例一和二进一步说明如何建立不同业务服务等级的隧道用于保证不同等级服务要求的业务。 [0024] The following examples further illustrate how to create business different service level of a tunnel and two different levels of service requirements for guaranteed by the present invention.

[0025] 实施例一 [0025] Example a

[0026]如图3所示,其为本发明实施例一的应用组网场景示意图。 [0026] 3, which is a flowchart of a schematic embodiment of the invention In the networking. 图3中第一VTEP下用户为VM1、VM2和VM3,第二VTEP下用户为VM4、VM5和VM6。 FIG 3 is a first user VTEP VM1, VM2 and VM3, the second user is VTEP VM4, VM5 and VM6. 第一VTEP和第二VTEP由控制设备控制, 交换机1和交换机2可由控制设备控制,也可以不由控制设备控制。 VTEP VTEP first and second control device may control device controls the switch 1 and switch 2 by the control device controls also may not be. 交换机1和交换机2分别与第一VTEP和第二VTEP直连,在第一VTEP和第二VTEP之间的VXLAN隧道上还包括其他多个中间设备,图中未示。 Switch 1 and switch 2 are connected directly to the first and second VTEP VTEP, on VXLAN VTEP tunnel between the first and second intermediate VTEP further comprises a plurality of other devices, not shown.

[0027]首先,根据业务服务等级的数量,确定在第一VTEP和第二VTEP之间所建立的VXLAN 隧道数量,本实施例中建立两条VXLAN隧道,Tunne 11用于普通业务,对应的业务服务等级较低;TUrmel2用于特殊业务,对应的业务服务等级较高,Timne12分配给优先保证带宽的VXLAN用户使用。 [0027] First, based on the number of service level, determining the number of VXLAN tunnel between the first and second VTEP VTEP established, establishing the present embodiment VXLAN two tunnels, Tunne 11 for normal traffic, a corresponding service a lower grade of service; TUrmel2 for special service, the service level corresponding to a higher, Timne12 guaranteed bandwidth allocated to the priority VXLAN users.

[0028]需要说明的是,本发明建立VXLAN隧道的数量,并不限于两条VXLAN隧道,可以根据业务服务等级的增加,相应得建立VXLAN隧道。 [0028] Incidentally, the number of tunnels to establish VXLAN the present invention is not limited to two VXLAN tunnels can increase the service level, the corresponding VXLAN may establish a tunnel.

[0029]然后,在第一VTEP上配置两个VTEP IP地址,1.1.1.1/32,1 • 1 • 1 • 2/32;在第二VTEP 上配置两个VTEP IP地址,2.2.2.1/32,2.2.2.2/32。 [0029] Then, two disposed on the first VTEP VTEP the IP address, 1.1.1.1 / 32,1 • 1 • 1 • 2/32; VTEP configure the IP address on two second VTEP, 2.2.2.1 / 32 , 2.2.2.2 / 32.

[0030] Tunnel 1 对应1 • 1 • 1 • 1/32和2 • 2 • 2 • 1/32。 [0030] Tunnel 1 corresponding to 1 • 1 • 1 • 1/32 and 2 • 2 • 2 • 1/32. 在第一VTEP 连接第二VTEP的Tunnell 中, 源VTEP IP地址为1 • 1 • 1 • 1/32,目的VTEP IP地址为2 • 2.2.1/32;在第二VTEP连接第一VTEP 的Tunnell中,源VTEP IP地址为2.2.2.1/32,目的VTEP IP地址为1.1.1.1/32。 In connecting the second Tunnell VTEP VTEP first, the source address of the IP VTEP 1 • 1 • 1 • 1/32, the IP address for the purpose of VTEP 2 • 2.2.1 / 32; Tunnell second connection in a first VTEP VTEP the source VTEP IP address 2.2.2.1/32, object VTEP IP address 1.1.1.1/32.

[0031] Tunnel2对应1 • 1 • 1 • 2/32和2.2 • 2 • 2/32。 [0031] Tunnel2 corresponding to 1 • 1 • 1 • 2/32 and 2.2 • 2 • 2/32. 在第一VTEP连接第二VTEP的Tunnel2中, 源VTEP IP地址为1.1.1.2/:32,目的VTEP IP地址为2.2.2.2/32;在第二VTEP连接第一VTEP 的Tunnel2中,源VTEP IP地址为2.2.2.2/32,目的VTEP IP地址为1.1.1.2/32。 In connecting the second Tunnel2 VTEP VTEP first, the source address is the IP VTEP 1.1.1.2/:32, the purpose of the IP address 2.2.2.2/32 VTEP; a second connector Tunnel2 VTEP VTEP in the first, the IP source VTEP address is 2.2.2.2/32, the purpose of VTEP IP address 1.1.1.2/32.

[0032]如果第一VTEP和第二VTEP为虚拟交换机,则虚拟交换机不运行路由协议,第一VTEP和第二VTEP无法发布路由。 [0032] If the first and second VTEP VTEP virtual switches, virtual switches do not run the routing protocol, the first and second VTEP VTEP not publish the route. 所以,为了第一VTEP和第二VTEP能够将自身路由通告给对端,需要在与VTEP直连的交换机上进行配置,如果该直连交换机由控制设备控制,则控制设备通过Netconf协议下配置,如果该直连交换机没有控制设备控制,则通过命令行的方式静态配置,具体配置如下,下面仅以Tunnel 1对应1.1.1.1/32和2.2.2.1/32的配置为例进行说明,Tunnel2对应1 • 1 • 1 •2/32和2 •2 • 2.2/32在直连交换机上的配置原理相同。 Therefore, for the first and second VTEP VTEP can be advertised to the peer routing itself, needs to be configured on the switch directly connected with VTEP, if the direction switch controlled by the control device, the control device by Netconf configuration protocol, If the switch is not directly connected to the control device controls, through the command line static configuration, the specific configuration is as follows, corresponding to the following only tunnel 1 1.1.1.1/32 and 2.2.2.1/32 configuration example will be described, corresponding to 1 Tunnel2 • 1 • 1 • 2/32 and 2 • 2 • 2.2 / 32 directly connected to the switch disposed on the same principle.

[0033] 在交换机1上配置指向第一VTEP的静态路由,该静态路由为目的IP: 1.1.1 • 1/32, 下一跳为第一VTEP;然后将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给第二VTEP,第二VTEP获得到达VTEP IP地址1 • 1 • 1 • 1/32的路由。 [0033] The switch 1 is arranged on a first static route VTEP of the static route for the purpose of IP: 1.1.1 • 1/32, the next hop is a first VTEP; the static route is then introduced into the public network running route protocols, routing protocols run by a public announcement to the second VTEP, second VTEP VTEP IP address of the router to get to reach 1 • 1 • 1 • 1/32 in.

[0034]同理,在交换机2上配置指向第二VTEP的静态路由,该静态路由为目的IP: 2.2.2.1/32,下一跳为第二VTEP;然后将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给第一VTEP,第一VTEP获得到达VTEP IP地址2.2.2.1/32的路由。 [0034] Similarly, in a second point disposed on the switch 2 VTEP static route, the route is a static object IP: 2.2.2.1/32, next hop to a second VTEP; static route is then introduced into the public network operation routing protocols, routing protocols running advertised to the public network by a first VTEP, a first VTEP obtain the IP address of the router VTEP arrival of 2.2.2.1/32.

[0035]上述内容对在第一VTEP和第二VTEP之间建立两条VXLAN隧道Tunnell和Tunnel2进行了说明。 [0035] The contents of the two build tunnels VXLAN Tunnell Tunnel2 between the first and second VTEP VTEP been described. 接下来,具体说明控制设备下发流表,用户报文通过匹配流表进行转发的过程。 Next, specifically described hair flow meter under control of the user packet forwarding process performed by matching flow table. [0036]第一VTEP接收控制设备下发的流表,第一条流表匹配项为用户报文丨的源MAC地址MAC1或者源IP地址IP1,动作项为对用户报文进行VXLAN封装,在用户报文的外层依次封装带有VNI1的VXLAN头,UDP头,外层IP头,其中外层IP头的源IP是Tunnell的源VTEP IP1.1 • 1 • 1/32,目的IP是Tunnel 1的目的VTEP IP2.2.2.1/32,在与交换机1直连的出接口上把经过VXLAN封装的用户报文转发出去;第二条流表匹配项为用户报文2的源MAC地址MAC2 或者源IP地址IP2,动作项为对用户报文进行VXLAN封装,在用户报文的外层依次封装带有VNI2的VXLAN头,UDP头,外层IP头,其中外层IP头的源IP是Tunnel2的源VTEP IP1 • 1 • 1 • 2/ 32,目的IP是Tunnel2的目的VTEP IP2.2 • 2.2/32,在与交换机1直连的出接口上把经过VXLAN封装的用户报文转发出去。 [0036] receiving a first control flow table VTEP delivered by the device, the first flow table entry matches the user packets Shu source MAC address or source IP address MAC1 IP1, action items for the user packets VXLAN package, user packet encapsulated into an outer head having VNI1 VXLAN of the UDP header source IP, the outer IP header, wherein the outer IP header is Tunnell source VTEP IP1.1 • 1 • 1/32, a destination IP Tunnel VTEP IP2.2.2.1 object 1/32, with a switch directly connected through the interface to forward user packets encapsulated VXLAN out; second flow table entry matches the user packet source MAC address MAC2 2 or the source IP address IP2, action items for the user packets VXLAN encapsulation, and encapsulated with a header VXLAN VNI2 user packet in an outer layer, the UDP header source IP address, the outer IP header, wherein the outer IP header is Tunnel2 source VTEP IP1 • 1 • 1 • 2/32, the purpose of IP is the object of the VTEP Tunnel2 IP2.2 • 2.2 / 32, forwards in the interface to the user through VXLAN encapsulated packets directly connected with a switch.

[0037] 这样,假设VM1的MAC地址为MAC1,来自VM1的用户报文通过匹配第一条流表,引入Tunnel 1转发;假设VM2的MAC地址为MAC2,来自VM2的用户报文通过匹配第二条流表,引入Tunnel2转发。 [0037] Thus, assuming a MAC address MACl VM1, VM1 from the user by matching the first packet of flow table, the introduction of forward Tunnel 1; assuming a MAC address MAC2 VM2, VM2 user from the second packet by matching table of flow, is introduced Tunnel2 forwarding. 由于Tunnel2承载特殊业务,业务服务等级较高,可以在下流表时允许匹配较少的源地址,这样,在Tunnell和Tunnel2带宽相同的情况下,由于Tunnel2使用的人少可以优先保证特殊服务的带宽要求。 Since Tunnel2 bearer service specific, high service level, may allow less when downflow matching source address table, so that, at the same Tunnell and Tunnel2 bandwidth, because few people use Tunnel2 priority bandwidth guarantee special services Claim.

[0038] 实施例二 [0038] Second Embodiment

[0039]如图4所示,其为本发明实施例二的应用组网场景示意图。 [0039] As shown in FIG 4, which is a schematic diagram of networking application scenario according to the second embodiment of the invention. 图4中第一VTEP下挂用户1、用户2和用户3,第二VTEP下挂用户4、用户5和用户6。 In FIG. 4 the first user hanging VTEP 1, user 2 and user 3, user 4 linked to the user and user 5 6 second VTEP. 由于本实施例中VTEP和交换机都没有控制设备控制,所以下面各配置,都是通过命令行的方式静态配置。 Since the present embodiment are not VTEP and switches the control device controls, so that each of the following configuration, the command line is through static configuration. 交换机1和交换机2 分别与第一VTEP和第二VTEP直连,在第一VTEP和第二VTEP之间的VXLAN隧道上还包括其他多个中间设备,图中未示。 Switch 1 and switch 2 are connected directly to the first and second VTEP VTEP, on VXLAN VTEP tunnel between the first and second intermediate VTEP further comprises a plurality of other devices, not shown.

[0040] 首先,根据业务服务等级的数量,确定在第一VTEP和第二VTEP之间所建立的VXLAN 隧道数量,本实施例中建立两条VXLAN隧道,Tunnel 1用于普通业务,对应的业务服务等级较低;Tunnel2用于特殊业务,对应的业务服务等级较高,TUnnel2分配给优先保证带宽的VXLAN用户使用。 [0040] First, based on the number of service level, determining the number of VXLAN tunnel between the first and second VTEP VTEP established, establishing the present embodiment two tunnels VXLAN embodiment, Tunnel 1 for ordinary traffic, corresponding service a lower grade of service; Tunnel2 for special service, the service level corresponding to a higher, tunnel2 guaranteed bandwidth allocated to the priority VXLAN users.

[0041]需要说明的是,本发明建立VXLAN隧道的数量,并不限于两条VXLAN隧道,业务服务等级越多,建立的VXLAN隧道数量越多。 [0041] Incidentally, the number of tunnels to establish VXLAN the present invention is not limited to two VXLAN tunnels, more service level, the greater the number VXLAN tunnel establishment.

[0042] 然后,在第一VTEP上配置两个VTEP IP地址,1.1.1.1/32,1 • 1.1.2/32;在第二VTEP 上配置两个VTEP IP地址,2.2.2.1/32,2.2.2.2/32。 [0042] Then, two disposed on the first VTEP VTEP the IP address, 1.1.1.1 / 32,1 • 1.1.2 / 32; VTEP the IP address configured on the two second VTEP, 2.2.2.1 / 32,2.2 .2.2 / 32.

[0043] Tunnel 1 对应1 • 1 • 1 • 1/32和2 • 2 • 2 • 1/32。 [0043] Tunnel 1 corresponding to 1 • 1 • 1 • 1/32 and 2 • 2 • 2 • 1/32. 在第一VTEP 连接第二VTEP的Tunnell 中, 源VTEP IP地址为1.1.1.1/32,目的VTEP IP地址为2.2.2.1/32;在第二VTEP连接第一VTEP 的Tunnell中,源VTEP IP地址为2.2.2.1/32,目的VTEP IP地址为1.1.1.1/32。 In connecting the second Tunnell VTEP VTEP first, the source address is the IP VTEP 1.1.1.1/32, the IP address for the purpose of VTEP 2.2.2.1/32; a second connector Tunnell VTEP VTEP in the first, the IP address of the source VTEP is 2.2.2.1/32, the purpose of VTEP IP address 1.1.1.1/32.

[0044] Tunnel2对应1 • 1 • 1 • 2/32和2.2.2 • 2/32。 [0044] Tunnel2 corresponding to 1 • 1 • 1 • 2/32 and 2.2.2 • 2/32. 在第一VTEP 连接第二VTEP的Tunnel2 中, 源VTEP IP地址为1.1.1.2/32,目的VTEP IP地址为2.2.2.2/32;在第二VTEP连接第一VTEP 的Tunne 12中,源VTEP IP地址为2_2_2_2/32,目的VTEP IP地址为1.1.1.2/32。 In connecting the second Tunnel2 VTEP VTEP first, the source address is the IP VTEP 1.1.1.2/32, the IP address for the purpose of VTEP 2.2.2.2/32; VTEP a first connector in the second VTEP Tunne 12, the IP source VTEP address 2_2_2_2 / 32, the purpose of VTEP IP address 1.1.1.2/32.

[0045]如果第一VTEP和第二VTEP为普通物理交换机,则普通物理交换机可以运行路由协议,第一VTEP和第二VTEP之间相互通告路由。 [0045] The routes advertised to each other if the first and second VTEP VTEP ordinary physical switch, can switch between the ordinary physical routing protocol, the first and second VTEP VTEP operation. 第一VTEP获得到达第二VTEP的两个VTEP IP地址2.2.2.1/32和2.2 • 2• 2/32路由。 VTEP get first to the second VTEP two VTEP IP address 2.2.2.1/32 and 2.2 • 2 • 2/32 routing. 同样的第二VTEP能够获得到达第一VTEP的两个VTEP IP 地址1 • 1 • 1.1/和1.1.1.2/32 的路由。 The same can be obtained reaching the first second VTEP VTEP the IP addresses of the two VTEP 1 • 1 • 1.1 / and routing of 1.1.1.2/32.

[0046]第一VTEP创建Tunnell,在Tunnell中配置源VTEP IP地址1.1.1.1/32,目的VTEP IP地址2 •2.2.1/32;创建VSI1,VSI1对应VNI1和Tunnel 1;将VSI1绑定到用户接口1。 [0046] First VTEP Tunnell create, configure the IP address of the source VTEP 1.1.1.1/32, the IP address of the object VTEP 2 • 2.2.1 / 32 in the Tunnell; VSI1 created, the corresponding VNI1 VSI1 and Tunnel 1; bind to VSI1 a user interface. 如此,用户报文从用户接口1进入VSI1,根据VSI1对应的VNI1和Tunnell中的源VTEP IP1.1.1 • 1/32 和目的VTEP IP2.2 • 2.1/32进行VXLAN封装,从对应的VXLAN隧道Tunnel 1,将用户报文从第一VTEP发送至第二VTEP。 Thus, the user packets from the user interface to enter VSI1 1, the package 1 according VXLAN source and the VTEP VSI1 corresponding VNI1 Tunnell IP1.1.1 • 1/32 and the object VTEP IP2.2 • 2.1 / 32, from the corresponding tunnel Tunnel VXLAN 1, the user packets from a first to a second VTEP VTEP.

[0047] 第一VTEP创建Tunne 12,在Tunne 12中配置源VTEP IP地址1 • 1 • 1 • 2/32,目的VTEP IP地址2.2.2.2/32;创建VSI2,VSI2对应VNI2和Tunnel2;将VSI2绑定到用户接口2。 [0047] First Tunne 12 VTEP create, configure the IP address of the source VTEP 1 • 1 • 1 • 2/32 in Tunne 12, the purpose of the IP address 2.2.2.2/32 VTEP; VSI2 created, the corresponding VNI2 VSI2 and Tunnel2; the VSI2 bound to the user interface 2. 如此,用户报文从用户接口2进入VSI2,根据VSI2对应的VNI2和Tunnel2中的源VTEP IP1 • 1 • 1 _2/32 和目的VTEP IP2.2.2.2/32进行VXLAN封装,从对应的VXLAN隧道Tunnel2,将用户报文从第一VTEP发送至第二VTEP。 Thus, the user packets from the user interface to enter VSI2 2, a package 1 according VXLAN source and the VTEP VSI2 corresponding VNI2 Tunnel2 of IP1 • 1 • 1 _2 / 32 and object VTEP IP2.2.2.2 / 32, from the corresponding tunnel VXLAN tunnel2, the user packets from a first to a second VTEP VTEP.

[0048] 由于TUnnel2承载特殊业务,业务服务等级较高,可以在绑定用户接口时,允许绑定较少的用户接口,这样,在Tunnell和Tunnel2带宽相同的情况下,由于Tunnel2使用的用户少可以优先保证特殊服务的带宽要求。 [0048] Due to the special traffic bearer TUnnel2, higher service level, can bind when the user interface allows a user interface to bind less so, and in the same Tunnell Tunnel2 bandwidth, since users use less Tunnel2 It may give priority to ensuring the bandwidth requirements of special services.

[0049] 进一步地,如果一个VTEP某个用户接口下挂多个用户,所创建的VSI中还对应有VLAN。 [0049] Further, if a plurality of users linked to a user interface VTEP, created corresponding to the VSI also have VLAN. 因此用户报文携带不同的VLAN可以进不同的VSI转发,也就可以进不同的VXLAN隧道转发。 Therefore, the user packets carry different VLAN can enter different VSI forwarding, you can enter different VXLAN tunnel forwarding. 那么,第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道的方法包括: Then, using each method respectively a first VTEP VTEP the IP address to establish a tunnel with each VXLAN VTEP the IP address of the end of the second VTEP comprises:

[0050] 为创建的所述第一VTEP连接所述第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; [0050] IP address is configured to create the second connects the first VTEP VTEP VXLAN of each tunnel, wherein each of said first and second IP address VTEP VTEP respectively as the source and destination IP addresses VTEP VTEP IP address; VXLAN assign IP addresses for each of said created tunnel connecting the first second VTEP VTEP, wherein each of the second and the IP address of the first VTEP VTEP were used as the source IP address and VTEP The purpose VTEP IP address;

[0051] 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道,并对应有VLAN;用于用户报文根据VLAN进入VSI,根据VSI对应的VNI和VXLAN隧道中的源VTEP IP和目的VTEP IP进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 [0051] VSI created, each corresponding to a specified VSI VXLAN VNI and a tunnel, and should VLAN; for the user to enter VSI according to the VLAN packets, corresponding to the VSI according VNI and VXLAN VTEP IP tunnel source and destination VTEP IP VXLAN for encapsulation, from the corresponding VXLAN tunnel, the user packets from a first to a second VTEP VTEP.

[0052]这样,不同业务服务等级的报文划分在不同的VLAN,业务服务等级较高的用户报文可以通过VLAN识别进入不同的VSI,从而配置进入对应业务服务等级较高的Tunnel2,从而优先保证特殊服务的带宽要求。 [0052] Thus, different service level packet divided different VLAN, higher service levels user can enter different packets through the VLAN identifier VSI, thereby entering the configuration corresponding to the service level higher Tunnel2 to preferentially ensure special service bandwidth requirements.

[0053]根据实施例一和二的描述,本发明建立对应不同业务服务等级的隧道,用于保证不同等级服务要求的业务,将不同等级服务要求的业务导入不同服务等级的隧道,确保高级别服务要求的业务优先通过;当网络拥塞时,可以保证高级别服务要求的业务仍然正常使用。 [0053] as described in Example I and II, the present invention establishes a tunnel corresponding to different service level for different levels of service guaranteed service requirements, different classes of service requirements of different services introduced tunneling service level, to ensure high-level service required by business priority; when the network is congested, can ensure a high level of service required by the business still normal use.

[0054] 实施例三 [0054] Example three

[0055]进一步地,参照图3或者图4,在实施例一或二的基础上,虽然两台VTEP使用的不同的地址,两条Tunnel使用的目的地址和源地址也是不同的,但是两条隧道经过的路径也有可能相同,如此,假设在Tunnell和Tunnel2的路径上都需要经过交换机1,且出接口都是交换机1的port2,那么即使有优先导入隧道的功能也不能保证用户总流量超过出接口port2 带宽时高业务服务等级用户的流量不被丢弃,所以本实施例提出,通过在所有中间交换机上设置QoS策略,当报文通过每个交换机时,根据该交换机上设置的Qos策略,将匹配高业务服务等级对应的VXLAN隧道上,封装有外层VTEP IP的VXLAN报文,对应进入高优先级的转发队列,进行优先转发,从而进一步保证高业务服务等级的报文能够顺利到达对端VTEP。 [0055] Further, referring to FIG. 3 or FIG. 4, on the basis of the embodiment of the one or two, although two different addresses VTEP use two Tunnel destination address and source addresses are different, but the two tunnel passes also may be the same, thus, assumed that the path Tunnell and Tunnel2 the need to go through the switch 1, and the interfaces are switch port2, 1, then even if there is introduced preferentially tunnel function can not guarantee that a total flow rate exceeds a high traffic service level user interfaces are not discarded when port2 bandwidth, the present embodiment proposes embodiment, by providing the QoS policy on all intermediate switches, when each switch packets, according to Qos policy settings on the switch, the matching the service level corresponding to the high VXLAN tunnel, an outer layer enclosing the VXLAN VTEP IP packets, the corresponding forward into the high priority queue, the priority for forwarding, to further ensure a high service level of the packet can smoothly reach the peer VTEP.

[0056]例如,对于图3或者图4中的交换机1,在交换机1报文入口porti上匹配高优先级VXLAN报文的外层IP地址,让这种报文入最高优先级的队列,那么交换机丨就可以在出端口p〇rt2优先转发这个队列的报文。 [0056] For example, the switch 4 in FIG. 1 or FIG. 3, matching the outer IP address of the high priority packets on VXLAN 1 packet switch inlet Porti, so that the packets into the highest priority queue, then Shu switch can forward the priority queue of packets in the port p〇rt2. 本实施例中,因为报文经过交换机1时,正在经过VXLAN隧道,报文带有VXLAN封装,所以匹配的是高业务服务等级所对应的Tunnel2上的源VTEP IP1.1.1 • 2/32或者目的VTEP IP2• 2.2.2/32,进而让这个用户的流量优先走Tunnel2转发到对端,其他用户的报文如果带宽还有剩余,那么随机进入Tunnell转发。 In this embodiment, since a packet passes through the switch, after being VXLAN tunnel packet with VXLAN packaging, it is the source VTEP IP1.1.1 match on a high service level corresponding to the object or Tunnel2 • 2/32 VTEP IP2 • 2.2.2 / 32, thereby allowing the user to go Tunnel2 priority traffic is forwarded to the remote, the other user's message if there is a surplus of bandwidth, then randomly assigned to Tunnell forward.

[0057]基于同样的发明构思,本发明一实施例还提出一种VXLAN网络中报文转发装置,应用于VTEP,参见图5。 [0057] Based on the same inventive concept, an embodiment of the present invention further provides a VXLAN network packet forwarding device, the VTEP applied, see Fig. 该装置500包括: The apparatus 500 comprises:

[0058] VTEP IP配置单元501,在VTEP上配置多个VTEP IP地址; [0058] VTEP IP configuration unit 501, a plurality of VTEP IP address on the VTEP;

[0059] 隧道建立单元502,分别使用每个VTEP IP地址与对端VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,且隧道两端的源和目的VTEP IP地址并不相同,用于所述VTEP下的用户报文在对应业务服务等级的VXLAN隧道上转发。 [0059] tunnel establishing unit 502, respectively, using the IP address of each VTEP VTEP establish the IP address of each end of a VTEP VXLAN tunnel, the IP source and destination VTEP different VXLAN tunnel corresponding to each service level, and both ends of the tunnel addresses are not the same, for the user under VTEP VXLAN packet forwarding on the service level corresponding to a tunnel.

[0060] 对于由控制设备控制,流表指导转发的VXLAN网络,该装置进一步包括: [0060] for forwarding by the control device controls the flow table VXLAN guidance network, the apparatus further comprising:

[0061] 流表接收单元503,接收控制设备下发的流表,其流表匹配项包括用户报文的源地址,流表动作项包括在对应的VXLAN隧道上,根据源地址对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP地址对报文进行VXLAN封装,在与交换机直连的出接口上将报文转发出去。 [0061] The stream table receiving unit 503, the reception control flow table issued by the device, the flow table matching entry includes a source address of the user packet, the flow table action items included in the corresponding VXLAN tunnel, according to the source address corresponding to the VNI and VTEP IP source address and destination address VXLAN VTEP IP tunnels for packet encapsulation VXLAN, forwarded directly connected with the switch on the interface of the packets.

[0062] 对于运行路由协议的VXLAN网络,所述隧道建立单元502具体用于: [0062] For VXLAN network running routing protocols, the tunnel establishing unit 502 is specifically configured to:

[0063] 为创建的所述第一VTEP连接所述第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; [0063] IP address is configured to create the second connects the first VTEP VTEP VXLAN of each tunnel, wherein each of said first and second IP address VTEP VTEP respectively as the source and destination IP addresses VTEP VTEP IP address; VXLAN assign IP addresses for each of said created tunnel connecting the first second VTEP VTEP, wherein each of the second and the IP address of the first VTEP VTEP were used as the source IP address and VTEP The purpose VTEP IP address;

[0064] 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道; [0064] VSI created, each corresponding to a specified VSI VXLAN VNI and a tunnel;

[0065] 将VSI绑定到用户接口;用于用户报文从用户接口进入VSI,根据VSI对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP地址进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 [0065] The user interface is bound to the VSI; for user packets from the user interface to enter VSI, a package 1 according VXLAN VTEP IP source address and destination address corresponding to the VSI VTEP IP VNI and VXLAN tunnel, the tunnel from the corresponding VXLAN the user packets from a first to a second VTEP VTEP.

[0066] 对于运行路由协议的VXLAN网络,所述隧道建立单元502还具体用于:: [0066] For VXLAN network running routing protocols, the tunnel establishing unit 502 configured to further ::

[0067] 为创建的所述第一VTEP连接所述第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; [0067] IP address is configured to create the second connects the first VTEP VTEP VXLAN of each tunnel, wherein each of said first and second IP address VTEP VTEP respectively as the source and destination IP addresses VTEP VTEP IP address; VXLAN assign IP addresses for each of said created tunnel connecting the first second VTEP VTEP, wherein each of the second and the IP address of the first VTEP VTEP were used as the source IP address and VTEP The purpose VTEP IP address;

[0068] 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道,并对应有VLAN;用于用户报文根据VLAN进入VSI,根据VSI对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP 地址进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 [0068] VSI created, each corresponding to a specified VSI VXLAN VNI and a tunnel, and should the VLAN; for a user to enter VSI according to the VLAN packets, the source address and destination VTEP IP VNI and the VTEP VXLAN corresponding to the VSI in the tunnel VXLAN encapsulation IP address, from the corresponding VXLAN tunnel, the user packets from a first to a second VTEP VTEP.

[0069]该装置进一步包括:路由学习单元504,向对端VTEP通告路由,并接收对端VTEP向其通告的路由,以使所述VTEP和对端VTEP学习到对方的VTEP IP地址。 [0069] The apparatus further comprises: routing learning unit 504, to the end VTEP advertised routes, and receives the peer routing advertisement VTEP thereto, and so that the opposite end VTEP VTEP VTEP learn the IP address of the other party.

[0070] 本发明另一实施例还提出一种VXLAN网络中报文转发装置,应用于与VTEP直连的交换机,参见图6。 Another embodiment [0070] The present invention further provides a packet forwarding network VXLAN means VTEP applied directly connected with the switch, see Fig. 该装置600包括: The apparatus 600 comprises:

[0071] 静态路由配置单元601,在所述交换机上配置指向所述VTEP的静态路由; [0071] The static route configuration unit 601, configured to point the VTEP static routes on the switch;

[0072] 路由通告单元602,将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给对端VTEP,用于所述VTEP在接收流表前,将自身路由通告给对端VTEP。 [0072] The router advertisement unit 602, the static routing the routing protocol running on the public network, the routing protocol run by the public network to the peer advertisement VTEP, prior to receiving the VTEP flow table itself advertises a route to peer VTEP.

[0073] 该装置进一步包括: [0073] The apparatus further comprises:

[0074]优先转发单元6〇3,根据所述交换机上设置的服务质量QoS策略,将匹配高业务服务等级对应的VXLAN隧道上,封装有外层VTEP IP地址的VXLAN报文,对应进入高优先级的转发队列,进行优先转发。 [0074] 6〇3 priority forwarding unit, according to the QoS policy settings on the switch, the matching tunnel VXLAN high service level corresponding to an outer VTEP IP encapsulated packets VXLAN address, corresponding to the high priority into the class forwarding queue, prioritize forwarding.

[0075]以上所述,仅为本发明的较佳实施例而已,并非用于限定本发明的保护范围。 [0075] The above are only preferred embodiments of the present invention but are not intended to limit the scope of the present invention. 凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。 Any modification within the spirit and principle of the present invention, made, equivalent substitutions, improvements, etc., should be included within the scope of the present invention.

Claims (14)

1.一种VXLAN网络中报文转发方法,所述VXLAN网络包括VXLAN隧道两端的第一虚拟通道终端VTEP和第二VTEP,该方法包括: 在第一VTEP和第二VTEP上分别配置多个VTEP IP地址; 第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,用于第一VTEP下的用户报文在对应业务服务等级的VXLAN險道上转发。 VXLAN CLAIMS 1. A method of forwarding a network packet, the network comprising a first virtual channel VXLAN VTEP and second terminal ends VXLAN VTEP tunnel, the method comprising: VTEP respectively disposed on the first plurality and second VTEP VTEP IP address; a first VTEP VTEP were used for each IP address to establish a tunnel to each VXLAN VTEP IP address of the end of the second VTEP, each corresponding to a different service level VXLAN tunnel for user packets in a first VTEP forwarding VXLAN steep trail in the corresponding business service levels.
2. 如权利要求1所述的方法,其特征在于,对于由控制设备控制,流表指导转发的VXLAN 网络,隧道建立之后,该方法进一步包括: 第一VTEP接收控制设备下发的流表,其流表匹配项包括用户报文的源地址,流表动作项包括在对应的VXLAN隧道上,根据源地址对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP地址对报文进行VXLAN封装,在与交换机直连的出接口上将报文转发出去。 2. The method according to claim 1, characterized in that, for the control by the control device, the flow table VXLAN network forward the packets after the tunnel is established, the method further comprising: receiving a first control flow table VTEP delivered by the device, which flow table matching entry includes a source address of the user packet, the flow table action items included in the corresponding VXLAN tunnel, according to the source VTEP IP address and destination VTEP IP source address corresponding to the VNI and VXLAN tunnel for packet VXLAN package, with a switch directly connected to the interface will forward the message.
3. 如权利要求1所述的方法,其特征在于,对于运行路由协议的VXLAN网络,所述第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道的方法包括: 为创建的所述第一VTEP连接所述第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道; 将VSI绑定到用户接口;用于用户报文从用户接口进入VSI,根据VSI对应的VNI和VXLAN 隧道中的源VTEP IP地址和目的VTEP IP地址进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 3. The method according to claim 1, characterized in that, for VXLAN network running routing protocols, the first one VXLAN VTEP were established using the IP address of each VTEP VTEP the IP address of each of the second ends of VTEP tunnel method comprising: creating said first VTEP VTEP is connected to the second tunnel configuration VXLAN each IP address, wherein each of said first and second IP address VTEP VTEP were used as the source IP address VTEP VTEP and destination IP address; to create the second connects the first VTEP VTEP VXLAN each tunnel configuration of IP addresses, wherein each of the second and the IP address of the first VTEP VTEP respectively as the source IP VTEP VTEP IP address and a destination address; VSI created, each corresponding to a specified VSI VXLAN VNI and a tunnel; the user interface to bind the VSI; a user packet from the user interface to enter VSI, corresponding to the VSI according VXLAN tunnel and VNI VTEP the IP source and destination address the IP address VTEP VXLAN package, from the corresponding VXLAN tunnel, the user packets from a first to a second VTEP VTEP.
4. 如权利要求1所述的方法,其特征在于,对于运行路由协议的VXLAN网络,所述第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道的方法包括: 为创建的所述第一VTEP连接所述第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道,并对应有VLAN;用于用户报文根据VLAN进入VSI,根据VSI对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP地址进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 4. The method according to claim 1, characterized in that, for VXLAN network running routing protocols, the first one VXLAN VTEP were established using the IP address of each VTEP VTEP the IP address of each of the second ends of VTEP tunnel method comprising: creating said first VTEP VTEP is connected to the second tunnel configuration VXLAN each IP address, wherein each of said first and second IP address VTEP VTEP were used as the source IP address VTEP VTEP and destination IP address; to create the second connects the first VTEP VTEP VXLAN each tunnel configuration of IP addresses, wherein each of the second and the IP address of the first VTEP VTEP respectively as the source IP VTEP VTEP IP address and destination address; create a VSI, each corresponding to a specified VSI VNI and a VXLAN tunnel, and there should be VLAN; VLAN for user packets based on enter VSI, according to VSI corresponding VNI and VXLAN tunnel source VTEP IP VTEP the IP address and the destination address VXLAN package from VXLAN tunnel corresponding to the user packets from a first to a second VTEP VTEP.
5. 如权利要求3或4所述的方法,其特征在于,在第一VTEP分别使用每个VTEP IP地址与对端第二VTEP的每个VTEP IP地址建立一条VXLAN隧道之前,该方法进一步包括:所述第一VTEP向对端所述第二VTEP通告路由,并接收所述第二VTEP向其通告的路由,以使所述第一VTEP和所述第二VTEP学习到对方的VTEP IP地址。 5. A method as claimed in claim 3 or claim 4, wherein the IP address establishment until each VTEP a tunnel VXLAN VTEP the IP address of each of the second, respectively first VTEP VTEP used, the method further comprising : VTEP to said first end of said second VTEP advertised routes, and receiving the second route advertisement VTEP thereto, such that said first and said second VTEP VTEP learn the IP address of the other party VTEP .
6. —种VXLAN网络中报文转发方法,应用于与权利要求1所述第一虚拟通道终端VTEP直连的交换机;该方法包括: 在所述交换机上配置指向第一VTEP的静态路由; 将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给第二VTEP, 用于第一VTEP在接收流表前,将自身路由通告给第二VTEP。 6. - Species VXLAN packet forwarding network, said first virtual channel 1 is directly connected to the switch terminal VTEP applied with claim 1; the method comprising: configuring a static route point on said first switch VTEP; and the static routes into a routing protocol running on the public network, the routing protocol run by the advertisement to the second VTEP public network, for receiving a first stream before VTEP table, the route to a second VTEP advertise itself.
7. 如权利要求6所述的方法,当报文通过交换机时,该方法进一步包括: 根据所述交换机上设置的服务质量QoS策略,将匹配高业务服务等级对应的VXLAN隧道上,封装有外层VTEP IP地址的VXLAN报文,对应进入高优先级的转发队列,进行优先转发。 7. The method according to claim 6, when the switch packets, the method further comprising: according to the QoS policy settings on the switch, matching the high service level corresponding VXLAN tunnel encapsulation outer VXLAN VTEP IP packet layer address, the corresponding forward into the high priority queue, the priority for forwarding.
8. —种VXLAN网络中报文转发装置,该装置应用于虚拟通道终端VTEP,包括: VTEP IP配置单元,在VTEP上配置多个VTEP IP地址; 隧道建立单元,分别使用每个VTEP IP地址与对端VTEP的每个VTEP IP地址建立一条VXLAN隧道,每一条VXLAN隧道对应不同的业务服务等级,用于所述VTEP下的用户报文在对应业务服务等级的VXLAN險道上转发。 8. - Species VXLAN packet forwarding network apparatus which is applied to the VTEP virtual channel terminal, comprising: VTEP IP configuration unit, a plurality of VTEP IP addresses on the VTEP; tunnel establishing unit, respectively, and using each VTEP IP address establishing a tunnel VXLAN VTEP the IP address of each terminal VTEP, each corresponding to a different tunnel VXLAN the service level for a user to lower the risk VXLAN VTEP packets corresponding to track forwarding service level.
9. 如权利要求8所述的装置,其特征在于,对于由控制设备控制,流表指导转发的VXLAN 网络,该装置进一步包括: 流表接收单元,接收控制设备下发的流表,其流表匹配项包括用户报文的源地址,流表动作项包括在对应的VXLAN隧道上,根据源地址对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP地址对报文进行VXLAN封装,在与交换机直连的出接口上将报文转发出去。 9. The apparatus according to claim 8, characterized in that, for the control by the control device, the flow guide table VXLAN forwarding network, the apparatus further comprising: a flow table receiving means for receiving the control flow delivered by the device table, the flow table matching entry including a user packet source address, flow table action items included in the corresponding VXLAN tunnel, according to the source address corresponding to the VNI and VXLAN tunnel source VTEP IP address and destination VTEP IP address of the packet VXLAN encapsulation, in the switch directly connected to the outbound interface will forward the message.
10. 如权利要求8所述的装置,其特征在于,对于运行路由协议的VXLAN网络,所述隧道建立单元具体用于: 为创建的第一VTEP连接第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道; 将VSI绑定到用户接口;用于用户报文从用户接口进入VSI,根据VSI对应的VNI和VXLAN 隧道中的源VTEP IP地址和目的VTEP IP地址进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 10. The apparatus according to claim 8, characterized in that for running routing protocols VXLAN network, the tunnel establishing unit is configured to: configure the IP address connected to a first VTEP VTEP of each second tunnel created VXLAN , wherein each of said first and second IP address VTEP VTEP VTEP respectively as the source IP address and destination IP address VTEP; to create the second connects the first VTEP VTEP IP tunnel configuration of each VXLAN address, wherein each of the second and the IP address of the first VTEP VTEP VTEP respectively as the source IP address and destination IP address VTEP; VSI created, each corresponding to a specified VSI VXLAN VNI and a tunnel; bind to the VSI a user interface; for a user to enter VSI packets from the user interface for the source encapsulation VXLAN VTEP IP address and a destination address corresponding to the VSI VTEP IP VNI and VXLAN tunnel, the tunnel VXLAN from the corresponding user packets from a first VTEP sent to the second VTEP.
11. 如权利要求8所述的装置,其特征在于,对于运行路由协议的VXLAN网络,所述隧道建立单元还具体用于: 为创建的第一VTEP连接第二VTEP的每条VXLAN隧道配置IP地址,其中,所述第一VTEP和第二VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址;为创建的所述第二VTEP连接所述第一VTEP的每条VXLAN隧道配置IP地址,其中,所述第二VTEP和第一VTEP的每个IP地址分别作为源VTEP IP地址和目的VTEP IP地址; 创建VSI,每一个VSI指定对应一个VNI和一条VXLAN隧道,并对应有VLAN;用于用户报文根据VLAN进入VSI,根据VSI对应的VNI和VXLAN隧道中的源VTEP IP地址和目的VTEP IP地址进行VXLAN封装,从对应的VXLAN隧道,将用户报文从第一VTEP发送至第二VTEP。 11. The apparatus according to claim 8, characterized in that for running routing protocols VXLAN network, the tunnel establishing unit is further configured to: configure a first IP connection VTEP VTEP of each second tunnel created VXLAN address, wherein each of said first and second IP address VTEP VTEP VTEP respectively as the source IP address and destination IP address VTEP; to create the second connects the first VTEP VTEP of each tunnel configuration VXLAN IP address, wherein each of the second and the IP address of the first VTEP VTEP VTEP respectively as the source IP address and destination IP address VTEP; VSI created, each corresponding to a specified VSI VXLAN VNI and a tunnel, and VLAN should ; for the user to enter VSI according to the VLAN packets, according to the package for VXLAN VTEP the IP source address and destination address of the IP corresponding to the VSI VTEP VNI and VXLAN tunnel, the user packets from the tunnel VXLAN corresponding to the first VTEP The second VTEP.
12. 如权利要求10或11所述的装置,其特征在于,该装置进一步包括:路由学习单元,向对端VTEP通告路由,并接收对端VTEP向其通告的路由,以使所述VTEP和对端VTEP学习到对方的VTEP IP地址。 12. The apparatus of claim 10 or claim 11, wherein the apparatus further comprises: routing learning unit, to the end VTEP advertised routes, and receives the peer routing advertisement VTEP thereto, and so that the VTEP VTEP peer learning each other's VTEP IP address.
13. —种VXLAN网络中报文转发装置,应用于与权利要求8所述虚拟通道终端VTEP直连的交换机;该装置包括: 静态路由配置单元,在所述交换机上配置指向所述VTEP的静态路由; 路由通告单元,将该静态路由引入公网运行的路由协议中,由公网运行的路由协议通告给对端VTEP,用于所述VTEP在接收流表前,将自身路由通告给对端VTEP。 13. - Species VXLAN network packet forwarding device, the virtual channel 8 directly connected to a switch terminal VTEP applied to the claims; the apparatus comprising: static routing means arranged on the switch point of the static VTEP route; route announcement unit, the static routing the routing protocol running on the public network, the routing protocol run by the public network to the peer advertisement VTEP, prior to receiving the VTEP flow table, the route to the end of their advertised VTEP.
14.如权利要求13所述的装置,该装置进一步包括: 优先转发单元,根据所述交换机上设置的服务质量Q〇S策略,将匹配高业务服务等级对应的VXLAN隧道上,封装有外层VTEP Ip地址的VXLAN报文,对应进入高优先级的转发队列, 进行优先转发。 14. The apparatus according to claim 13, the apparatus further comprising: a priority forwarding unit, according to the QoS policy Q〇S disposed on the switch, matching the high service level corresponding VXLAN tunnel enclosing the outer VXLAN VTEP Ip packet address, the corresponding forward into the high priority queue, the priority for forwarding.
CN201410727841.2A 2014-12-04 2014-12-04 Vxlan one kind of network packet forwarding method and apparatus CN104468394B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410727841.2A CN104468394B (en) 2014-12-04 2014-12-04 Vxlan one kind of network packet forwarding method and apparatus

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410727841.2A CN104468394B (en) 2014-12-04 2014-12-04 Vxlan one kind of network packet forwarding method and apparatus

Publications (2)

Publication Number Publication Date
CN104468394A CN104468394A (en) 2015-03-25
CN104468394B true CN104468394B (en) 2018-02-09

Family

ID=52913790

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410727841.2A CN104468394B (en) 2014-12-04 2014-12-04 Vxlan one kind of network packet forwarding method and apparatus

Country Status (1)

Country Link
CN (1) CN104468394B (en)

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106161259B (en) * 2015-03-27 2019-02-12 新华三技术有限公司 The multicast data packet forwarding method and apparatus of virtual extended local area network VXLAN
CN105490884B (en) * 2015-12-14 2019-04-02 迈普通信技术股份有限公司 A kind of VXLAN tunnel detection method and device
CN106921573A (en) * 2015-12-28 2017-07-04 华为技术有限公司 Method and device for releasing tenant routes in NVo3 (Network Virtualization over Layer3) network
CN106230668A (en) * 2016-07-14 2016-12-14 杭州华三通信技术有限公司 Access control method and device
CN106209562A (en) * 2016-07-27 2016-12-07 华为技术有限公司 Method and controller for distributing VLAN (Virtual Local Area Network) IDs (Identifiers) in network
CN106341299A (en) * 2016-08-23 2017-01-18 杭州华三通信技术有限公司 Packet forwarding method and packet forwarding device in VXLAN
CN106302258B (en) * 2016-09-08 2019-06-04 杭州迪普科技股份有限公司 A kind of message forwarding method and device
CN108075969A (en) * 2016-11-17 2018-05-25 新华三技术有限公司 Message forwarding method and device
CN106878199A (en) * 2016-12-20 2017-06-20 新华三技术有限公司 Access information configuration method and apparatus
CN106878136A (en) * 2016-12-28 2017-06-20 新华三技术有限公司 Message forwarding method and apparatus

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6529499B1 (en) * 1998-09-22 2003-03-04 Lucent Technologies Inc. Method for providing quality of service for delay sensitive traffic over IP networks
CN101945046A (en) * 2010-09-15 2011-01-12 中兴通讯股份有限公司 Method and system for configuring mapping of qualify of service of virtual private LAN service network
CN103618596A (en) * 2013-05-15 2014-03-05 盛科网络(苏州)有限公司 Encryption method for inner layer information in VXLAN (Virtual Extensible Local Area Net) tunnel
CN103841028A (en) * 2014-03-24 2014-06-04 杭州华三通信技术有限公司 Method and device for forwarding messages

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100496984B1 (en) * 2002-08-21 2005-06-23 한국전자통신연구원 A Method of Setting the QoS supported bi-directional Tunnel and distributing L2 VPN membership Information for L2VPN using LDP-extension
US7565436B2 (en) * 2003-12-24 2009-07-21 Nortel Networks Limited Ethernet to frame relay interworking with multiple quality of service levels
US9036639B2 (en) * 2012-11-29 2015-05-19 Futurewei Technologies, Inc. System and method for VXLAN inter-domain communications

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6529499B1 (en) * 1998-09-22 2003-03-04 Lucent Technologies Inc. Method for providing quality of service for delay sensitive traffic over IP networks
CN101945046A (en) * 2010-09-15 2011-01-12 中兴通讯股份有限公司 Method and system for configuring mapping of qualify of service of virtual private LAN service network
CN103618596A (en) * 2013-05-15 2014-03-05 盛科网络(苏州)有限公司 Encryption method for inner layer information in VXLAN (Virtual Extensible Local Area Net) tunnel
CN103841028A (en) * 2014-03-24 2014-06-04 杭州华三通信技术有限公司 Method and device for forwarding messages

Also Published As

Publication number Publication date
CN104468394A (en) 2015-03-25

Similar Documents

Publication Publication Date Title
US8660129B1 (en) Fully distributed routing over a user-configured on-demand virtual network for infrastructure-as-a-service (IaaS) on hybrid cloud networks
EP2491684B1 (en) Method and apparatus for transparent cloud computing with a virtualized network infrastructure
CN102594711B (en) Message forwarding method and edge device therefor
CN100505746C (en) Method for implement virtual leased line
US8825829B2 (en) Routing and service performance management in an application acceleration environment
US7907595B2 (en) Method and apparatus for learning endpoint addresses of IPSec VPN tunnels
US8819267B2 (en) Network virtualization without gateway function
US8098656B2 (en) Method and apparatus for implementing L2 VPNs on an IP network
US20150117256A1 (en) Extended ethernet fabric switches
US9419892B2 (en) Methods and apparatus for implementing connectivity between edge devices via a switch fabric
CN104170331B (en) The l3 gateway for vxlan
JP5413517B2 (en) Communication system, control apparatus, communication method, and program
CN105791463B (en) A kind of method and apparatus for realizing virtual machine communication
CN103259727B (en) OSPF packets forwarding method and apparatus
US8351329B2 (en) Universal load-balancing tunnel encapsulation
US20050147104A1 (en) Apparatus and method for multihop MPLS/IP/ATM/frame relay/ethernet pseudo-wire
JP6189942B2 (en) Routing vlan tagged packet to the far-end address of the virtual transfer instance using a separate management scheme
CN104285416B (en) In the storage area network termination cover tunnel virtual router
US9451056B2 (en) Method for mapping packets to network virtualization instances
CN104106240B (en) Overlay network forwarding and address resolution of the balance
CN103595648B (en) A method for load balancing in a receiving side system and a server
CN104704778B (en) A method and system for virtual and physical network integration
US20120099602A1 (en) End-to-end virtualization
US10270843B2 (en) Chaining service zones by way of route re-origination
US8830834B2 (en) Overlay-based packet steering

Legal Events

Date Code Title Description
C06 Publication
C10 Entry into substantive examination
CB02
GR01