Specific implementation mode
To make the purpose of the application, technical solution and advantage are more clearly understood, referring to the drawings to application scheme
It is described in further detail.
In order to solve the problems in the existing technology, the present invention provides a kind of message partition method and devices.
Fig. 1 is network environment schematic diagram where message partition method of the present invention, which includes multiple VTEP equipment (examples
Such as VTEP1, VTEP2 and VTEP3) and the host (such as the VM1 being connect with VTEP1) that is connect respectively with VTEP equipment, respectively
VTEP equipment has multiple ports (such as Port1, Port2 on VTEP1) again.
Referring to FIG. 2, for the processing flow schematic diagram of message partition method provided by the invention, which can
Applied to local VTEP equipment, which includes the following steps:
Step 201, message is received, source corresponding with the source address of the message is obtained and group information is isolated;
In each VTEP equipment of VXLAN networks create VXLAN examples after, each VTEP equipment can in same instance
Other VTEP equipment (distal end VTEP equipment) mutually send the isolation group information notification packet for carrying itself isolation group information, with logical
That accuses the host connected with each VTEP equipment is isolated group information.Wherein, which can be ISIS messages.
After local VTEP equipment receives the ISIS messages of distal end VTEP equipment (annunciator) transmission, the ISIS messages are obtained
Source IP address, that is, send ISIS messages the IP address of VTEP equipment (annunciator) and the TLV fields of the ISIS messages in
Annunciator's unique mark (System ID), isolation group information.The isolation group information includes being connect with the distal end VTEP equipment
Host where isolation group ID and corresponding isolation property.Wherein, isolation group ID is the mark of isolation group belonging to host;
Isolation property is for judging which kind of message will be isolated, for example, the isolation property may include unicast attribute isolation, multicast
Attribute isolation, broadcast nature isolation retain the isolation of MAC Address attribute and reservation protocol type attribute isolation etc..
Later, local VTEP equipment by the isolation group information of all VTEP equipment in same instance preserve to prestore every
From in group information list item.
The isolation group information list item to prestore may include two parts content:
1, group information (local isolation group information list item) is isolated with the All hosts of local VTEP equipment connection;
Isolation group information in local isolation group information list item may include that host identification, isolation group ID and isolation belong to
Property.
Wherein, host identification includes the port information and Vlan for the port that each host is connected in local VTEP equipment
(Virtual Local Area Network, virtual LAN) information.
2, group information (distal end isolation group is isolated with what other VTEP equipment of local VTEP equipment in same instance were sent
Information table).
The isolation group information that the distal end is isolated in group information list item may include the IP address of distal end VTEP equipment, distal end
The isolation group ID and corresponding isolation property that the host connected in VTEP equipment is added.
After creating VXLAN examples in each VTEP equipment of VXLAN networks, the host being connect with each VTEP equipment can
It is communicated with from other hosts in same instance.
Local VTEP equipment can receive the message that the host that is connect with the local VTEP equipment is sent and with institute
State the VXLAN messages that local VTEP equipment is sent in other VTEP equipment of same instance.
If the message received is the message that the host being connect with the local VTEP equipment is sent, and according to the message
When source address has not checked the corresponding host information of the source address in local forwarding-table item, believed according to the incoming interface of message
Breath is (i.e.:Host identification) corresponding source isolation group information (source isolation group ID) is searched in the isolation group information list item to prestore, and
The source address (source MAC) of the message, the incoming interface information of message and the correspondence of source isolation group ID three are protected
It deposits into the local forwarding-table item.
Wherein, which includes the MAC Address and incoming interface information for the host for sending the message.The incoming interface is believed
Breath (host identification) includes the Vlan letters carried in the port information and message for received in local VTEP equipment the port of message
Breath.
It is reported if the message is the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment
Text checks source isolation group information (source isolation group ID) whether is carried in the VXLAN messages, if it carries, and according to the VXLAN
When the source address of message has not checked the corresponding host information of the source address in local forwarding-table item, by the message
The correspondence of source address (source MAC), the incoming interface information of message and the source isolation group ID three is preserved to described
In local forwarding-table item.
Later, it obtains source corresponding with the source address of the message and group information is isolated.
Specifically, the message sent for the host that is connect with the local VTEP equipment, and with the local VTEP
The VXLAN messages that equipment is sent in other VTEP equipment of same instance, obtain source corresponding with the source address of the message
Group information, which is isolated, is respectively:
1, the message is the message that the host being connect with the local VTEP equipment is sent.
Obtain the incoming interface information of the message, if locally be isolated group information list item in do not find it is corresponding every
From group information, illustrate that any isolation group is not added for the host for sending the message, then by the message according to the prior art flow into
Row forwarding.
If finding corresponding isolation group information being locally isolated in group information list item, can will be isolated in group information
Isolation group ID as source isolation group ID, and further according to the target MAC (Media Access Control) address of the message judge the message be unicast message,
Broadcasting packet or multicast message.
If it is determined that the message is unicast message, i.e.,:The message attribute of the message is unicast attribute.So unicast category
Property and be locally isolated the source isolation group ID that finds in group information list item can be used as it is corresponding with the source address of the message
Group information is isolated in source.
It should be noted that determining that the message that the host being connect with the local VTEP equipment received is sent is unknown
When unicast message, broadcasting packet or multicast message, then it is not necessarily to obtain the source of the unknown unicast message, broadcasting packet or multicast message
Group information is isolated.Unknown unicast message, broadcasting packet or the multicast message can be encapsulated as to VXLAN messages, while will be at this
The head that the isolation group ID in corresponding isolation group information is added to the VXLAN messages is found in ground isolation group information list item
In portion's information, and in the header information of the VXLAN messages add isolated marks after, by it in the reality where local VETP equipment
Broadcast replication or multicast processing in example.It, can also be by the VXLAN messages to local when carrying out broadcast replication to VXLAN messages
Other interface broadcast replications in VTEP equipment in addition to the incoming interface of the message.
It wherein, can be by existing when adding isolation group ID and isolated marks into the header information of VXLAN messages
Some VXLAN messages are extended, and increase an isolated marks Sbit in the tag field of VXLAN messages, to identify this
VXLAN data frames need to carry out isolation group filtering, while will increase a VLAN TAG, the VLAN in user's two layer message head
TAG is Separation TAG, identifies the source isolation group ID of the message.
2, the message is that the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment is reported
Text.
It checks in the VXLAN messages and whether carries isolation group echo, if so, obtaining the source isolation carried in the message
ID is organized, and checks the message attribute of the message according to the target MAC (Media Access Control) address of the VXLAN messages.It can be by the report of VXLAN messages
Literary attribute group ID is isolated with the source carried in VXLAN messages, group information is isolated as the source.
Step 202, forwarding information corresponding with the destination address of the message in the forwarding-table item locally to prestore, root are obtained
Purpose corresponding with the destination address of the message is obtained according to the forwarding information, and group information is isolated;
Wherein, which includes the tunnel information of message and corresponding purpose isolation group ID.The tunnel information is again
Exit port information including message, VTEP device ids (System ID) corresponding with the destination address of message.
Specifically, the message sent for the host that is connect with the local VTEP equipment, and with the local VTEP
The VXLAN messages that equipment is sent in other VTEP equipment of same instance, obtain corresponding with the destination address of the message
Group information is isolated in purpose:
1, the message is the message that the host being connect with the local VTEP equipment is sent.
If the message received is unicast message, and finds the mesh with the unicast message in the forwarding-table item locally to prestore
The corresponding forwarding information in address, it may be determined that the unicast message be known unicast message, otherwise, it determines the unicast message be not
Know unicast message.
When the message of reception is known unicast message, check whether the forwarding information has and the known unicast message
The corresponding purpose isolation group ID of destination address can should if it is not, illustrate that group information is isolated without purpose in the known unicast message
Known unicast message is encapsulated as VXLAN messages, while what is found in the isolation group information list item to prestore enters to connect with message
Message ceases corresponding source isolation group ID and is added in the header information of the VXLAN messages, and to the header information of the VXLAN messages
After middle addition isolated marks, it is forwarded according to corresponding forwarding information.
If checking has purpose isolation group ID corresponding with the destination address of known unicast message in the forwarding information,
Further check purpose isolation group ID in forwarding information be isolated the source isolation group ID that is found in group information list item whether one
It causes, if inconsistent, the known unicast message is encapsulated as VXLAN messages, while the source isolation group ID of acquisition being added to
In the header information of the VXLAN messages, and in the header information of the VXLAN messages add isolated marks after, according to forwarding believe
Breath is forwarded;If consistent, the mesh with the known unicast message is determined according to the purpose VTEP device ids in forwarding information
The corresponding VTEP equipment in address be other VTEP equipment or local VTEP equipment.
If other VTEP equipment, searched in the tunnel information list item to prestore according to the purpose VTEP device ids described in
The IP address of other VTEP equipment, and search in the distal end isolation information list item with the IP address and the purpose every
Isolation property corresponding from group ID.Later, using in the forwarding information purpose isolation group ID and the isolation property as
Group information is isolated in the purpose.
If determining that VTEP corresponding with the destination address of known unicast message is set according to the purpose VTEP device ids
Standby is local VTEP equipment, is looked into the local isolation information list item to prestore according to the purpose isolation group ID in the forwarding information
Look for corresponding isolation property, by the forwarding information purpose isolation group ID and it is described it is corresponding with the destination address of message every
Group information is isolated as a purpose from attribute.
2, the message is that the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment is reported
Text.
When the VXLAN messages are unicast messages, according to forwarding information corresponding with the VXLAN messages in forwarding-table item
In purpose isolation group ID search corresponding isolation property in the local isolation information list item to prestore, and by the forwarding information
In purpose isolation group ID and the isolation property group information is isolated as a purpose.
Step 203, when determining that the source isolation group information is consistent with purpose isolation group information, according to the purpose
The isolation property being isolated in group information handles the message.
1, the message is the message that the host being connect with the local VTEP equipment is sent.
Specifically, if the message is known unicast message, believe determining that purpose is isolated group information group is isolated with the source
When ceasing consistent, the isolation property being isolated in group information according to the purpose can determine that the processing of the known unicast message acts,
And the known unicast message is handled according to the isolation property.
For example, the source isolation group information of the known unicast message is:Isolation group 1, message attribute are unicast attribute;It obtains
It is isolation group 1, unicast attribute isolation that group information, which is isolated, in purpose.It can determine that group information one is isolated with purpose for source isolation group information
It causes, the unicast attribute isolation being isolated in group information according to purpose can determine that the known unicast message is the report for needing to be isolated
Text, then, it is abandoned.
However, if to be isolated group information with the source inconsistent for purpose isolation group information, illustrate that the known unicast message is not
The known unicast message is encapsulated as VXLAN messages by segregate message according to the forwarding information found in forwarding-table item,
And the source isolation group ID and isolated marks that source is isolated in group information are added in the header information of the VXLAN messages, according to
Forwarding information forwards the VXLAN messages after the encapsulation, so that purpose VTEP equipment corresponding with the destination address of the VXLAN messages
After receiving the VXLAN messages, further judge that the VXLAN messages are according to the isolation group ID carried in the VXLAN messages
The no message to be isolated.Wherein, purpose VTEP equipment is judging to receive whether VXLAN messages are the report for needing to be isolated
Wen Shi, when process flow can receive the VXLAN messages of other VTEP equipment transmission of same instance with local VTEP equipment
Process flow it is consistent, details are not described herein.
2, the message is that the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment is reported
Text.
When consistent with source isolation group information in determining purpose isolation group information, illustrate that the VXLAN messages are local
VTEP equipment needs the message being isolated, then, the isolation property being isolated in group information according to the purpose can determine that this is known
The processing of unicast message acts, and handles the VXLAN messages according to the isolation property.
For example, the source isolation group information of the VXLAN messages is:Isolation group 2, message attribute are broadcast nature;The mesh of acquisition
Isolation group information be isolation group 2, broadcast nature isolation.It can determine that group information one is isolated with purpose for source isolation group information
It causing, the broadcast nature isolation being isolated in group information according to purpose can determine that the VXLAN messages are the message for needing to be isolated, that
By VXLAN packet loss.
However, if to be isolated group information with the source inconsistent for purpose isolation group information, illustrate the VXLAN messages be not by
The message of isolation, when the VXLAN messages are unknown unicast message, broadcasting packet or multicast message, by the unknown unicast report
Other interfaces broadcast of text, broadcasting packet or multicast message in local VTEP equipment in addition to the incoming interface of the message is multiple
System;When the VXLAN messages are known unicast messages, by the known unicast message according to corresponding forwarding information in forwarding-table item
It is sent to corresponding host.
The present invention is described further below in conjunction with Fig. 1.
After creating VXLAN examples in each VTEP equipment of VXLAN networks, each VTEP equipment is reported according to the mutual ISIS that sends
Text create with each VTEP equipment in same instance isolation group information list item (local isolation group information list item and distal end every
From group information list item).It is assumed that local VTEP equipment is VTEP2, local isolation group information list item and distal end that VTEP2 is preserved
Isolation group information list item can refer to shown in following table:
Isolation group ID |
Isolation property |
Host identification |
Isolation group 1 |
Broadcast nature is isolated |
Port4+Vlan1 |
Isolation group 2 |
Unicast attribute is isolated |
Port5+Vlan1 |
Table 1
VETP IP address of equipment |
Isolation group ID |
Isolation property |
VETP1-IP1 |
Isolation group 2 |
Unicast attribute is isolated |
VETP3-IP3 |
Isolation group 1 |
Broadcast nature is isolated |
Table 2
Table 1 shows that the local isolation group information list item that VTEP2 is preserved, table 2 show the distal end isolation group that VTEP2 is preserved
Information table.Only it is example to further understand the present invention, is not intended to restrict the invention in embodiment locally isolation group letter
It ceases list item and the particular content of group information list item is isolated in distal end.
If local VTEP equipment VTEP2 is respectively received the message that host VM2 is sent to the VM4 being connect with VTEP3, Yi Jiyu
The VM1 of VTEP1 connections is sent to the message of VM3.
Local VTEP equipment VTEP2 is specially for the process flow of the VM2 messages sent:
The incoming interface information of the message is obtained, which can be the host identification for the host for sending message,
I.e.:The port information (Port4) of the port of message is received in the Vlan information (Vlan1) and VTEP2 carried in message.According to
Vlan1 and Port4 finds corresponding isolation group information in locally isolation group information list item (table 1).
If finding, the source isolation group ID in local isolation group information, i.e. isolation group 1 are obtained, and further according to the report
The destination address of text judges that the message is unicast message, broadcasting packet or multicast message.
If the message is broadcasting packet or multicast message, the broadcasting packet or multicast message are subjected to VXLAN encapsulation process,
VXLAN messages are generated, while the isolation group 1 of acquisition being added in the Separation TAG of VXLAN headers, and
Increase an isolated marks in the tag field of VXLAN messages, such as the isolated marks are " 1 ".The VXLAN messages are existed later
With broadcast replication in the example where VTEP2.Wherein, in broadcast replication, it is also necessary to enter to connect except the message on VTEP2
Message described in other interfaces Port3, Port5 broadcast replication except mouth Port4.
If the message is unicast message, that is, the message attribute of the message is unicast attribute, then the unicast attribute and
The isolation group 1 obtained in local isolation group information is the source isolation group information of the message.
And then forwarding information corresponding with the destination address VM4 of the unicast message is searched in local forwarding-table item, and
When finding forwarding information corresponding with the unicast message, determine that the unicast message is known unicast message.
Check isolation group ID whether has been recorded in corresponding forwarding information, if not recording corresponding isolation in forwarding information
Group ID, it can be said that there is no addition isolation groups for the destination host of the bright known unicast message, then can be by the unicast message
VXLAN messages are encapsulated as, while the source isolation group ID isolation group 1 of acquisition being added to the Separation of VXLAN headers
In TAG, and in the tag field of VXLAN messages after one isolated marks " 1 " of increase, according to the forwarding information in forwarding-table item
Send VXLAN messages.
If having recorded corresponding isolation group ID in forwarding information, judge the isolation group ID recorded in forwarding information whether with
The isolation group 1 obtained in local isolation group information is consistent, if inconsistent, illustrates source host and the purpose master of the known unicast message
Machine is not isolated the known unicast message then not in the same isolation group, but the known unicast message is encapsulated as
VXLAN messages, while the source isolation group ID isolation group 1 of acquisition being added in the Separation TAG of VXLAN headers,
And in the tag field of VXLAN messages after one isolated marks " 1 " of increase, envelope is sent according to the forwarding information in forwarding-table item
VXLAN messages after dress.
If judging, the isolation group ID recorded in forwarding information is consistent with the source isolation group ID obtained in local isolation group information,
It is isolation group 1, illustrates that the known unicast message may be and need segregate message, then according in forwarding information
VTEP device ids determine VTEP equipment corresponding with the destination address of known unicast message be other VTEP equipment of distal end also
It is local VTEP equipment.
It is learnt in forwarding-table item according to destination host VM4, VTEP device ids corresponding with its VM4 are VTEP3, can be with
Determine that VTEP equipment corresponding with the destination address of known unicast message is other VTEP equipment of distal end.
Later, corresponding IP address is searched in the tunnel information list item to prestore according to VTEP3, it is assumed that the IP address
For VTEP3-IP3, it is isolated in the distal end according to the purpose isolation group ID isolation group 1 in the VTEP3-IP3 and forwarding-table item
Corresponding isolation property is searched in information table (table 2), i.e. broadcast nature is isolated.So, in the forwarding information every
It is that group information is isolated in purpose from group 1 and broadcast nature isolation.
Finally, it may be determined that it is that isolation group 1 and broadcast nature are isolated that group information, which is isolated, in purpose, be isolated with source group information every
It is inconsistent from group 1 and unicast attribute, illustrate that the known unicast message is not required to the message of isolation, then to the known unicast
Message is packaged and obtains VXLAN messages, while the source isolation group ID isolation group 1 is added to VXLAN headers
In Separation TAG, and in the tag field of VXLAN messages after one isolated marks " 1 " of increase, according to forwarding-table item
In forwarding information the VXLAN messages after encapsulation are sent.
If however, not searching forwarding letter corresponding with the destination address VM4 of the unicast message in local forwarding-table item
Breath illustrates that the unicast message is unknown unicast message, then needs the unknown unicast message as handling above-mentioned broadcasting packet
With copy broadcast in the example where VTEP2.
When carrying out copy broadcast, can also by the message on VTEP2 in addition to the incoming interface Port4 of the message
Other interfaces Port3, Port5 carry out broadcast replication.Later, VTEP2 obtains purpose corresponding with other interfaces Port3, Port5
Isolation group ID, and judge purpose isolation group ID corresponding with other interfaces Port3, Port5 whether be all be isolation group 2, if so,
The message can be handled according to isolation property.The place that local VTEP equipment VTEP2 is sent to the VXLAN messages of VM3 for receiving VM1
Managing flow is specially:
Decapsulation processing is carried out to the VXLAN messages, checks whether increased in the tag field of VXLAN messages extension
Isolated marks illustrate that the VXLAN messages need not be isolated if not increasing isolated marks, can will decapsulate
VXLAN messages are forwarded according to the prior art.
If there are isolated marks, the isolation group ID carried in the Separation TAG of VXLAN headers is obtained, it is assumed that
Isolation group ID is isolation group 2.
Then, judge that the VXLAN messages after decapsulation are unicast message, broadcast report according to the target MAC (Media Access Control) address of the message
Text or multicast message.
If the VXLAN messages after decapsulation are unicast messages, that is, the message attribute of the message is unicast attribute, then
Source that can be by the isolation group 2 obtained in the header information of the unicast attribute and VXLAN messages as the unicast message is isolated
Group information.
Further check in local forwarding-table item whether there is corresponding with the destination address VM3-MAC3 of the unicast message turn
Photos and sending messages, if so, illustrating that the unicast message is known unicast message.The isolation group ID (isolation group 2) in forwarding information is obtained, and
Corresponding isolation property is searched according to the isolation group 2 in locally isolation group information list item (table 1) for unicast attribute to be isolated.
It is that isolation group 2, unicast attribute are isolated group information to be isolated group information is isolated with source due to the purpose, determine purpose every
Consistent with source isolation group information from group information, the isolation property being isolated in group information according to purpose can be determined to the known list
The processing action for reporting text is isolation, then abandoning the known unicast message.
In conclusion message partition method provided by the invention and device obtain and message pair when receiving message
The source isolation group information and purpose isolation group information answered, and determining that purpose isolation group information is consistent with source isolation group information
When, message is handled according to isolation property.The present invention realizes the accurate isolation in a VXLAN example to message as a result, into
And effective machine utilization reduced in VXLAN networks, improve equipment performance.
The present invention also provides a kind of message isolating device, Fig. 3 is the structural schematic diagram of the message isolating device, which can
To apply in local VTEP equipment, which may include source information acquiring unit 301, purpose information acquisition unit
302 and message process unit 303, wherein:
Information acquisition unit 301 obtains source isolation group letter corresponding with the source address of the message for receiving message
Breath;
Purpose information acquisition unit 302, for obtaining the destination address in the forwarding-table item locally to prestore with the message
Corresponding forwarding information obtains purpose corresponding with the destination address of the message according to the forwarding information and group information is isolated;
Message process unit 303, for when determine source isolation group information and the purpose be isolated group information it is consistent when,
The isolation property being isolated in group information according to the purpose handles the message.
Further, the source information acquiring unit 301 is specific can be used for being determined according to the destination address of the message
Go out the message attribute of the message;If the message is the message that the host being connect with the local VTEP equipment is sent, obtain
The incoming interface information of the message, if finding source corresponding with the incoming interface information in the isolation group information list item to prestore
Isolation group ID believes the message attribute and source isolation group ID corresponding with the incoming interface information as the source isolation group
Breath, wherein the incoming interface information includes receiving the message in virtual LAN Vlan information and local VTEP equipment
The port information of port;It is sent if the message is other VTEP equipment with the local VTEP equipment in same instance
VXLAN messages check in the VXLAN messages whether carry isolation group echo, if so, obtain the source that is carried in the message every
From a group ID, group ID is isolated using the message attribute with the source carried in the VXLAN messages, group information is isolated as the source.
Further, the forwarding information include purpose isolation group ID corresponding with the destination address of the message and
Corresponding purpose VTEP device ids, if the purpose information acquisition unit 302 be specifically used for the message be and the local
The message that the host of VTEP equipment connection is sent, and the message is known unicast message, obtains the known unicast message
Incoming interface information searches the source isolation group letter according to the incoming interface information of the message in the isolation group information list item to prestore
Breath, and judge with the purpose in the forwarding information group ID is isolated whether in the source isolation group ID in the source isolation group information
Unanimously, if unanimously, VTEP corresponding with the destination address of known unicast message is determined according to the purpose VTEP device ids
Equipment is that other VTEP equipment or local VTEP equipment are looked into if other VTEP equipment in the tunnel information list item to prestore
Look for IP address corresponding with the purpose VTEP device ids, and search in the isolation information list item with the IP address and
The corresponding isolation property of the purpose isolation group ID, using the purpose isolation group ID and the isolation property as the purpose
Group information is isolated;If it is determined that VTEP equipment corresponding with the destination address of known unicast message is local VTEP equipment, root
It is searched in the isolation group information list item to prestore according to the purpose isolation group ID in the forwarding information corresponding with the destination address
Isolation property, using the purpose isolation group ID and the isolation property corresponding with the destination address as the purpose
Group information is isolated;If the message is the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment
Message, and the message is known unicast message, when carrying isolated marks in the known unicast message, described in acquisition
Know the source isolation group ID that unicast message carries, judges that group is isolated with the purpose in the forwarding information in the source isolation group ID
Whether ID is consistent, if unanimously, being looked into the isolation group information list item to prestore according to the purpose isolation group ID in the forwarding information
Corresponding isolation property is looked for, by the purpose isolation group ID and isolation property isolation group as a purpose in the forwarding information
Information.
Further, if it is to be connect with the local VTEP equipment that the message process unit 303, which is additionally operable to the message,
Host send message obtain the incoming interface information of the multicast message when judging the message for multicast message, if
Source isolation group ID corresponding with the incoming interface information is found in the isolation group information list item to prestore, by the source isolation group ID
And after isolated marks are added to the message, the message is forwarded;If the message is to be connect with the local VTEP equipment
Host send message obtain entering for the message when judging the message for unknown unicast message or broadcasting packet
Interface message will if finding source isolation group ID corresponding with the incoming interface information in the isolation group information list item to prestore
After the source isolation group ID and isolated marks are added to the message, by the message with belonging to the local VTEP equipment
Example in broadcast replication.Further, the message process unit 303 can be also used in local VTEP equipment except described
Message described in other interface broadcast replications except the incoming interface of message;Wherein, when carrying out the broadcast replication, acquisition and institute
The corresponding purpose isolation group ID of other interfaces judges whether the purpose isolation group ID is isolated group ID with the source consistent, if one
It causes, then handles the message according to isolation property.
Further, described device can also include information learning unit 304, for after receiving message, if according to
The source address of the message has not checked the corresponding host information of the source address in local forwarding-table item, according to local
Received in VTEP equipment the message port and message in the Vlan information that carries looked into the isolation group information list item to prestore
Corresponding source isolation group information is looked for, or obtains the source isolation group information carried in the message;
The source address of the message, the incoming interface of the message and the source are isolated to the correspondence of group information three
Preserve into the local forwarding-table item, the incoming interface information include in the local VTEP equipment with the transmission message
The Vlan information carried in the port information and the message of the port of host connection.
Further, the message process unit 303 is specific can be used for being isolated in group information not when the determining purpose
It, will if the message is the message that the host being connect with the local VTEP equipment is sent when group information is isolated including the source
The message is encapsulated as VXLAN messages, and source isolation group information and isolated marks are added to the VXLAN messages
Afterwards, it and is forwarded, wherein the isolation group information is source isolation group ID;Do not include when determining in the purpose isolation group information
When the source isolation group information, if the message is other VTEP equipment transmission in same instance with the local VTEP equipment
VXLAN messages, to the VXLAN messages decapsulate after, be forwarded with the forwarding information according in the forwarding-table item.
In addition, the present invention be applied to local VTEP equipment message isolating device in specific process flow can with it is upper
The process flow for stating message partition method is consistent, and details are not described herein.
Above-mentioned apparatus can be by software realization, can also be by hardware realization, and message isolating device place of the present invention is originally
The hardware structure schematic diagram of ground VTEP equipment can refer to shown in Fig. 4, and basic hardware environment includes central processor CPU, turns
Chip, memory and other hardware are sent out, wherein memory device includes machine readable instructions, and CPU reads and executes machine can
Reading instruction executes the function of each unit in Fig. 3.
From the embodiment of any of the above method and apparatus as can be seen that the present invention when receiving message, obtain with
Group information is isolated in the corresponding source isolation group information of message and purpose, and group information is isolated in the source that determines, group information is isolated with purpose
When consistent, the isolation property being isolated in group information according to purpose handles the message.It can be seen that the present invention is realized to same
Message in VXLAN examples is accurately isolated, and effective machine utilization reduced in VXLAN networks improves equipment performance.
The foregoing is merely illustrative of the preferred embodiments of the present invention, is not intended to limit the invention, all essences in the present invention
With within principle, any modification, equivalent substitution, improvement and etc. done should be included within the scope of protection of the invention god.