CN104780089B - Message partition method and device - Google Patents

Message partition method and device Download PDF

Info

Publication number
CN104780089B
CN104780089B CN201510184344.7A CN201510184344A CN104780089B CN 104780089 B CN104780089 B CN 104780089B CN 201510184344 A CN201510184344 A CN 201510184344A CN 104780089 B CN104780089 B CN 104780089B
Authority
CN
China
Prior art keywords
message
information
isolation
source
group
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201510184344.7A
Other languages
Chinese (zh)
Other versions
CN104780089A (en
Inventor
宋小恒
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing H3C Technologies Co Ltd
Original Assignee
New H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by New H3C Technologies Co Ltd filed Critical New H3C Technologies Co Ltd
Priority to CN201510184344.7A priority Critical patent/CN104780089B/en
Publication of CN104780089A publication Critical patent/CN104780089A/en
Application granted granted Critical
Publication of CN104780089B publication Critical patent/CN104780089B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Small-Scale Networks (AREA)

Abstract

A kind of message partition method of present invention offer and device, wherein this method include:Message is received, source corresponding with the source address of the message is obtained and group information is isolated;Forwarding information corresponding with the destination address of the message in the forwarding-table item locally to prestore is obtained, obtaining purpose corresponding with the destination address of the message according to the forwarding information is isolated group information;When determining that the source isolation group information is consistent with purpose isolation group information, the isolation property being isolated in group information according to the purpose handles the message.The present invention, which realizes, is accurately isolated the message in same VXLAN examples, and effective machine utilization reduced in VXLAN networks improves equipment performance.

Description

Message partition method and device
Technical field
The present invention relates to field of communication technology more particularly to a kind of message partition method and devices.
Background technology
It, can be by VTEP (the VXLAN Tunnel that are connect with source VM when the intercommunication of each host in VXLAN networks End Point, VXLAN endpoint of a tunnel) equipment identifies the VXLAN examples belonging to the VM of source, and learns this and belong to same VXLAN examples Source VM information, the VM messages sent in source are encapsulated as VXLAN messages later, according to the destination address of the message search it is corresponding Tunnel information, and the VXLAN messages are forwarded to the VTEP equipment being connect with purpose VM according to the tunnel information.If VTEP equipment Corresponding tunnel information is not found according to the destination address of the message, then after the message being encapsulated as VXLAN messages, in the source It floods in VXLAN examples belonging to VM.So, in VXLAN examples, then there can be the message for largely needing to flood, To cause the equipment heavy-duty service in VXLAN networks, equipment performance is reduced.
In the prior art, it to avoid the message that largely needs to flood from influencing equipment performance, is usually being connect with host Control strategy is issued in VTEP equipment, message is isolated with realizing.However, this isolation method is only capable of connecting VTEP equipment The message that sends of All hosts be isolated, cannot achieve and the message that the host that is connected in the VTEP equipment of distal end is sent is carried out Accurate isolation.
Invention content
In view of the drawbacks of the prior art, the present invention provides a kind of message partition method and devices.
The present invention provides a kind of message partition method, the local endpoint of a tunnel VTEP equipment being applied in VXLAN, the party Method includes:
Message is received, source corresponding with the source address of the message is obtained and group information is isolated;
Forwarding information corresponding with the destination address of the message in the forwarding-table item locally to prestore is obtained, according to described turn Photos and sending messages obtain purpose corresponding with the destination address of the message and group information are isolated;
When determining that the source isolation group information is consistent with purpose isolation group information, believed according to the purpose isolation group Isolation property in breath handles the message.
The present invention also provides a kind of message isolating device, the local VTEP equipment being applied in VXLAN networks, described device Including:
Source information acquiring unit obtains source corresponding with the source address of the message and group information is isolated for receiving message;
Purpose information acquisition unit, it is corresponding with the destination address of the message in the forwarding-table item locally to prestore for obtaining Forwarding information, corresponding with the destination address of message purpose isolation group information is obtained according to the forwarding information;
Message process unit, for obtaining in the forwarding-table item locally to prestore corresponding with the destination address of the message turn Photos and sending messages obtain purpose corresponding with the destination address of the message according to the forwarding information and group information are isolated.
The present invention provides a kind of message partition method and devices, when receiving message, obtain corresponding with message Group information is isolated in source and group information is isolated in purpose, and when determining that source isolation group information is consistent with purpose isolation group information, root The isolation property being isolated in group information according to purpose handles the message.The present invention is realized in same VXLAN examples as a result, Message is accurately isolated, and effective machine utilization reduced in VXLAN networks improves equipment performance.
Description of the drawings
Fig. 1 is the network environment schematic diagram that the embodiment of the present invention is applied;
Fig. 2 is a kind of message partition method flow diagram in the embodiment of the present invention;
Fig. 3 is a kind of logical construction schematic diagram of message isolating device in the embodiment of the present invention;
Fig. 4 is the hardware structure schematic diagram of local VTEP equipment where message isolating device in the embodiment of the present invention.
Specific implementation mode
To make the purpose of the application, technical solution and advantage are more clearly understood, referring to the drawings to application scheme It is described in further detail.
In order to solve the problems in the existing technology, the present invention provides a kind of message partition method and devices.
Fig. 1 is network environment schematic diagram where message partition method of the present invention, which includes multiple VTEP equipment (examples Such as VTEP1, VTEP2 and VTEP3) and the host (such as the VM1 being connect with VTEP1) that is connect respectively with VTEP equipment, respectively VTEP equipment has multiple ports (such as Port1, Port2 on VTEP1) again.
Referring to FIG. 2, for the processing flow schematic diagram of message partition method provided by the invention, which can Applied to local VTEP equipment, which includes the following steps:
Step 201, message is received, source corresponding with the source address of the message is obtained and group information is isolated;
In each VTEP equipment of VXLAN networks create VXLAN examples after, each VTEP equipment can in same instance Other VTEP equipment (distal end VTEP equipment) mutually send the isolation group information notification packet for carrying itself isolation group information, with logical That accuses the host connected with each VTEP equipment is isolated group information.Wherein, which can be ISIS messages.
After local VTEP equipment receives the ISIS messages of distal end VTEP equipment (annunciator) transmission, the ISIS messages are obtained Source IP address, that is, send ISIS messages the IP address of VTEP equipment (annunciator) and the TLV fields of the ISIS messages in Annunciator's unique mark (System ID), isolation group information.The isolation group information includes being connect with the distal end VTEP equipment Host where isolation group ID and corresponding isolation property.Wherein, isolation group ID is the mark of isolation group belonging to host; Isolation property is for judging which kind of message will be isolated, for example, the isolation property may include unicast attribute isolation, multicast Attribute isolation, broadcast nature isolation retain the isolation of MAC Address attribute and reservation protocol type attribute isolation etc..
Later, local VTEP equipment by the isolation group information of all VTEP equipment in same instance preserve to prestore every From in group information list item.
The isolation group information list item to prestore may include two parts content:
1, group information (local isolation group information list item) is isolated with the All hosts of local VTEP equipment connection;
Isolation group information in local isolation group information list item may include that host identification, isolation group ID and isolation belong to Property.
Wherein, host identification includes the port information and Vlan for the port that each host is connected in local VTEP equipment (Virtual Local Area Network, virtual LAN) information.
2, group information (distal end isolation group is isolated with what other VTEP equipment of local VTEP equipment in same instance were sent Information table).
The isolation group information that the distal end is isolated in group information list item may include the IP address of distal end VTEP equipment, distal end The isolation group ID and corresponding isolation property that the host connected in VTEP equipment is added.
After creating VXLAN examples in each VTEP equipment of VXLAN networks, the host being connect with each VTEP equipment can It is communicated with from other hosts in same instance.
Local VTEP equipment can receive the message that the host that is connect with the local VTEP equipment is sent and with institute State the VXLAN messages that local VTEP equipment is sent in other VTEP equipment of same instance.
If the message received is the message that the host being connect with the local VTEP equipment is sent, and according to the message When source address has not checked the corresponding host information of the source address in local forwarding-table item, believed according to the incoming interface of message Breath is (i.e.:Host identification) corresponding source isolation group information (source isolation group ID) is searched in the isolation group information list item to prestore, and The source address (source MAC) of the message, the incoming interface information of message and the correspondence of source isolation group ID three are protected It deposits into the local forwarding-table item.
Wherein, which includes the MAC Address and incoming interface information for the host for sending the message.The incoming interface is believed Breath (host identification) includes the Vlan letters carried in the port information and message for received in local VTEP equipment the port of message Breath.
It is reported if the message is the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment Text checks source isolation group information (source isolation group ID) whether is carried in the VXLAN messages, if it carries, and according to the VXLAN When the source address of message has not checked the corresponding host information of the source address in local forwarding-table item, by the message The correspondence of source address (source MAC), the incoming interface information of message and the source isolation group ID three is preserved to described In local forwarding-table item.
Later, it obtains source corresponding with the source address of the message and group information is isolated.
Specifically, the message sent for the host that is connect with the local VTEP equipment, and with the local VTEP The VXLAN messages that equipment is sent in other VTEP equipment of same instance, obtain source corresponding with the source address of the message Group information, which is isolated, is respectively:
1, the message is the message that the host being connect with the local VTEP equipment is sent.
Obtain the incoming interface information of the message, if locally be isolated group information list item in do not find it is corresponding every From group information, illustrate that any isolation group is not added for the host for sending the message, then by the message according to the prior art flow into Row forwarding.
If finding corresponding isolation group information being locally isolated in group information list item, can will be isolated in group information Isolation group ID as source isolation group ID, and further according to the target MAC (Media Access Control) address of the message judge the message be unicast message, Broadcasting packet or multicast message.
If it is determined that the message is unicast message, i.e.,:The message attribute of the message is unicast attribute.So unicast category Property and be locally isolated the source isolation group ID that finds in group information list item can be used as it is corresponding with the source address of the message Group information is isolated in source.
It should be noted that determining that the message that the host being connect with the local VTEP equipment received is sent is unknown When unicast message, broadcasting packet or multicast message, then it is not necessarily to obtain the source of the unknown unicast message, broadcasting packet or multicast message Group information is isolated.Unknown unicast message, broadcasting packet or the multicast message can be encapsulated as to VXLAN messages, while will be at this The head that the isolation group ID in corresponding isolation group information is added to the VXLAN messages is found in ground isolation group information list item In portion's information, and in the header information of the VXLAN messages add isolated marks after, by it in the reality where local VETP equipment Broadcast replication or multicast processing in example.It, can also be by the VXLAN messages to local when carrying out broadcast replication to VXLAN messages Other interface broadcast replications in VTEP equipment in addition to the incoming interface of the message.
It wherein, can be by existing when adding isolation group ID and isolated marks into the header information of VXLAN messages Some VXLAN messages are extended, and increase an isolated marks Sbit in the tag field of VXLAN messages, to identify this VXLAN data frames need to carry out isolation group filtering, while will increase a VLAN TAG, the VLAN in user's two layer message head TAG is Separation TAG, identifies the source isolation group ID of the message.
2, the message is that the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment is reported Text.
It checks in the VXLAN messages and whether carries isolation group echo, if so, obtaining the source isolation carried in the message ID is organized, and checks the message attribute of the message according to the target MAC (Media Access Control) address of the VXLAN messages.It can be by the report of VXLAN messages Literary attribute group ID is isolated with the source carried in VXLAN messages, group information is isolated as the source.
Step 202, forwarding information corresponding with the destination address of the message in the forwarding-table item locally to prestore, root are obtained Purpose corresponding with the destination address of the message is obtained according to the forwarding information, and group information is isolated;
Wherein, which includes the tunnel information of message and corresponding purpose isolation group ID.The tunnel information is again Exit port information including message, VTEP device ids (System ID) corresponding with the destination address of message.
Specifically, the message sent for the host that is connect with the local VTEP equipment, and with the local VTEP The VXLAN messages that equipment is sent in other VTEP equipment of same instance, obtain corresponding with the destination address of the message Group information is isolated in purpose:
1, the message is the message that the host being connect with the local VTEP equipment is sent.
If the message received is unicast message, and finds the mesh with the unicast message in the forwarding-table item locally to prestore The corresponding forwarding information in address, it may be determined that the unicast message be known unicast message, otherwise, it determines the unicast message be not Know unicast message.
When the message of reception is known unicast message, check whether the forwarding information has and the known unicast message The corresponding purpose isolation group ID of destination address can should if it is not, illustrate that group information is isolated without purpose in the known unicast message Known unicast message is encapsulated as VXLAN messages, while what is found in the isolation group information list item to prestore enters to connect with message Message ceases corresponding source isolation group ID and is added in the header information of the VXLAN messages, and to the header information of the VXLAN messages After middle addition isolated marks, it is forwarded according to corresponding forwarding information.
If checking has purpose isolation group ID corresponding with the destination address of known unicast message in the forwarding information, Further check purpose isolation group ID in forwarding information be isolated the source isolation group ID that is found in group information list item whether one It causes, if inconsistent, the known unicast message is encapsulated as VXLAN messages, while the source isolation group ID of acquisition being added to In the header information of the VXLAN messages, and in the header information of the VXLAN messages add isolated marks after, according to forwarding believe Breath is forwarded;If consistent, the mesh with the known unicast message is determined according to the purpose VTEP device ids in forwarding information The corresponding VTEP equipment in address be other VTEP equipment or local VTEP equipment.
If other VTEP equipment, searched in the tunnel information list item to prestore according to the purpose VTEP device ids described in The IP address of other VTEP equipment, and search in the distal end isolation information list item with the IP address and the purpose every Isolation property corresponding from group ID.Later, using in the forwarding information purpose isolation group ID and the isolation property as Group information is isolated in the purpose.
If determining that VTEP corresponding with the destination address of known unicast message is set according to the purpose VTEP device ids Standby is local VTEP equipment, is looked into the local isolation information list item to prestore according to the purpose isolation group ID in the forwarding information Look for corresponding isolation property, by the forwarding information purpose isolation group ID and it is described it is corresponding with the destination address of message every Group information is isolated as a purpose from attribute.
2, the message is that the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment is reported Text.
When the VXLAN messages are unicast messages, according to forwarding information corresponding with the VXLAN messages in forwarding-table item In purpose isolation group ID search corresponding isolation property in the local isolation information list item to prestore, and by the forwarding information In purpose isolation group ID and the isolation property group information is isolated as a purpose.
Step 203, when determining that the source isolation group information is consistent with purpose isolation group information, according to the purpose The isolation property being isolated in group information handles the message.
1, the message is the message that the host being connect with the local VTEP equipment is sent.
Specifically, if the message is known unicast message, believe determining that purpose is isolated group information group is isolated with the source When ceasing consistent, the isolation property being isolated in group information according to the purpose can determine that the processing of the known unicast message acts, And the known unicast message is handled according to the isolation property.
For example, the source isolation group information of the known unicast message is:Isolation group 1, message attribute are unicast attribute;It obtains It is isolation group 1, unicast attribute isolation that group information, which is isolated, in purpose.It can determine that group information one is isolated with purpose for source isolation group information It causes, the unicast attribute isolation being isolated in group information according to purpose can determine that the known unicast message is the report for needing to be isolated Text, then, it is abandoned.
However, if to be isolated group information with the source inconsistent for purpose isolation group information, illustrate that the known unicast message is not The known unicast message is encapsulated as VXLAN messages by segregate message according to the forwarding information found in forwarding-table item, And the source isolation group ID and isolated marks that source is isolated in group information are added in the header information of the VXLAN messages, according to Forwarding information forwards the VXLAN messages after the encapsulation, so that purpose VTEP equipment corresponding with the destination address of the VXLAN messages After receiving the VXLAN messages, further judge that the VXLAN messages are according to the isolation group ID carried in the VXLAN messages The no message to be isolated.Wherein, purpose VTEP equipment is judging to receive whether VXLAN messages are the report for needing to be isolated Wen Shi, when process flow can receive the VXLAN messages of other VTEP equipment transmission of same instance with local VTEP equipment Process flow it is consistent, details are not described herein.
2, the message is that the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment is reported Text.
When consistent with source isolation group information in determining purpose isolation group information, illustrate that the VXLAN messages are local VTEP equipment needs the message being isolated, then, the isolation property being isolated in group information according to the purpose can determine that this is known The processing of unicast message acts, and handles the VXLAN messages according to the isolation property.
For example, the source isolation group information of the VXLAN messages is:Isolation group 2, message attribute are broadcast nature;The mesh of acquisition Isolation group information be isolation group 2, broadcast nature isolation.It can determine that group information one is isolated with purpose for source isolation group information It causing, the broadcast nature isolation being isolated in group information according to purpose can determine that the VXLAN messages are the message for needing to be isolated, that By VXLAN packet loss.
However, if to be isolated group information with the source inconsistent for purpose isolation group information, illustrate the VXLAN messages be not by The message of isolation, when the VXLAN messages are unknown unicast message, broadcasting packet or multicast message, by the unknown unicast report Other interfaces broadcast of text, broadcasting packet or multicast message in local VTEP equipment in addition to the incoming interface of the message is multiple System;When the VXLAN messages are known unicast messages, by the known unicast message according to corresponding forwarding information in forwarding-table item It is sent to corresponding host.
The present invention is described further below in conjunction with Fig. 1.
After creating VXLAN examples in each VTEP equipment of VXLAN networks, each VTEP equipment is reported according to the mutual ISIS that sends Text create with each VTEP equipment in same instance isolation group information list item (local isolation group information list item and distal end every From group information list item).It is assumed that local VTEP equipment is VTEP2, local isolation group information list item and distal end that VTEP2 is preserved Isolation group information list item can refer to shown in following table:
Isolation group ID Isolation property Host identification
Isolation group 1 Broadcast nature is isolated Port4+Vlan1
Isolation group 2 Unicast attribute is isolated Port5+Vlan1
Table 1
VETP IP address of equipment Isolation group ID Isolation property
VETP1-IP1 Isolation group 2 Unicast attribute is isolated
VETP3-IP3 Isolation group 1 Broadcast nature is isolated
Table 2
Table 1 shows that the local isolation group information list item that VTEP2 is preserved, table 2 show the distal end isolation group that VTEP2 is preserved Information table.Only it is example to further understand the present invention, is not intended to restrict the invention in embodiment locally isolation group letter It ceases list item and the particular content of group information list item is isolated in distal end.
If local VTEP equipment VTEP2 is respectively received the message that host VM2 is sent to the VM4 being connect with VTEP3, Yi Jiyu The VM1 of VTEP1 connections is sent to the message of VM3.
Local VTEP equipment VTEP2 is specially for the process flow of the VM2 messages sent:
The incoming interface information of the message is obtained, which can be the host identification for the host for sending message, I.e.:The port information (Port4) of the port of message is received in the Vlan information (Vlan1) and VTEP2 carried in message.According to Vlan1 and Port4 finds corresponding isolation group information in locally isolation group information list item (table 1).
If finding, the source isolation group ID in local isolation group information, i.e. isolation group 1 are obtained, and further according to the report The destination address of text judges that the message is unicast message, broadcasting packet or multicast message.
If the message is broadcasting packet or multicast message, the broadcasting packet or multicast message are subjected to VXLAN encapsulation process, VXLAN messages are generated, while the isolation group 1 of acquisition being added in the Separation TAG of VXLAN headers, and Increase an isolated marks in the tag field of VXLAN messages, such as the isolated marks are " 1 ".The VXLAN messages are existed later With broadcast replication in the example where VTEP2.Wherein, in broadcast replication, it is also necessary to enter to connect except the message on VTEP2 Message described in other interfaces Port3, Port5 broadcast replication except mouth Port4.
If the message is unicast message, that is, the message attribute of the message is unicast attribute, then the unicast attribute and The isolation group 1 obtained in local isolation group information is the source isolation group information of the message.
And then forwarding information corresponding with the destination address VM4 of the unicast message is searched in local forwarding-table item, and When finding forwarding information corresponding with the unicast message, determine that the unicast message is known unicast message.
Check isolation group ID whether has been recorded in corresponding forwarding information, if not recording corresponding isolation in forwarding information Group ID, it can be said that there is no addition isolation groups for the destination host of the bright known unicast message, then can be by the unicast message VXLAN messages are encapsulated as, while the source isolation group ID isolation group 1 of acquisition being added to the Separation of VXLAN headers In TAG, and in the tag field of VXLAN messages after one isolated marks " 1 " of increase, according to the forwarding information in forwarding-table item Send VXLAN messages.
If having recorded corresponding isolation group ID in forwarding information, judge the isolation group ID recorded in forwarding information whether with The isolation group 1 obtained in local isolation group information is consistent, if inconsistent, illustrates source host and the purpose master of the known unicast message Machine is not isolated the known unicast message then not in the same isolation group, but the known unicast message is encapsulated as VXLAN messages, while the source isolation group ID isolation group 1 of acquisition being added in the Separation TAG of VXLAN headers, And in the tag field of VXLAN messages after one isolated marks " 1 " of increase, envelope is sent according to the forwarding information in forwarding-table item VXLAN messages after dress.
If judging, the isolation group ID recorded in forwarding information is consistent with the source isolation group ID obtained in local isolation group information, It is isolation group 1, illustrates that the known unicast message may be and need segregate message, then according in forwarding information VTEP device ids determine VTEP equipment corresponding with the destination address of known unicast message be other VTEP equipment of distal end also It is local VTEP equipment.
It is learnt in forwarding-table item according to destination host VM4, VTEP device ids corresponding with its VM4 are VTEP3, can be with Determine that VTEP equipment corresponding with the destination address of known unicast message is other VTEP equipment of distal end.
Later, corresponding IP address is searched in the tunnel information list item to prestore according to VTEP3, it is assumed that the IP address For VTEP3-IP3, it is isolated in the distal end according to the purpose isolation group ID isolation group 1 in the VTEP3-IP3 and forwarding-table item Corresponding isolation property is searched in information table (table 2), i.e. broadcast nature is isolated.So, in the forwarding information every It is that group information is isolated in purpose from group 1 and broadcast nature isolation.
Finally, it may be determined that it is that isolation group 1 and broadcast nature are isolated that group information, which is isolated, in purpose, be isolated with source group information every It is inconsistent from group 1 and unicast attribute, illustrate that the known unicast message is not required to the message of isolation, then to the known unicast Message is packaged and obtains VXLAN messages, while the source isolation group ID isolation group 1 is added to VXLAN headers In Separation TAG, and in the tag field of VXLAN messages after one isolated marks " 1 " of increase, according to forwarding-table item In forwarding information the VXLAN messages after encapsulation are sent.
If however, not searching forwarding letter corresponding with the destination address VM4 of the unicast message in local forwarding-table item Breath illustrates that the unicast message is unknown unicast message, then needs the unknown unicast message as handling above-mentioned broadcasting packet With copy broadcast in the example where VTEP2.
When carrying out copy broadcast, can also by the message on VTEP2 in addition to the incoming interface Port4 of the message Other interfaces Port3, Port5 carry out broadcast replication.Later, VTEP2 obtains purpose corresponding with other interfaces Port3, Port5 Isolation group ID, and judge purpose isolation group ID corresponding with other interfaces Port3, Port5 whether be all be isolation group 2, if so, The message can be handled according to isolation property.The place that local VTEP equipment VTEP2 is sent to the VXLAN messages of VM3 for receiving VM1 Managing flow is specially:
Decapsulation processing is carried out to the VXLAN messages, checks whether increased in the tag field of VXLAN messages extension Isolated marks illustrate that the VXLAN messages need not be isolated if not increasing isolated marks, can will decapsulate VXLAN messages are forwarded according to the prior art.
If there are isolated marks, the isolation group ID carried in the Separation TAG of VXLAN headers is obtained, it is assumed that Isolation group ID is isolation group 2.
Then, judge that the VXLAN messages after decapsulation are unicast message, broadcast report according to the target MAC (Media Access Control) address of the message Text or multicast message.
If the VXLAN messages after decapsulation are unicast messages, that is, the message attribute of the message is unicast attribute, then Source that can be by the isolation group 2 obtained in the header information of the unicast attribute and VXLAN messages as the unicast message is isolated Group information.
Further check in local forwarding-table item whether there is corresponding with the destination address VM3-MAC3 of the unicast message turn Photos and sending messages, if so, illustrating that the unicast message is known unicast message.The isolation group ID (isolation group 2) in forwarding information is obtained, and Corresponding isolation property is searched according to the isolation group 2 in locally isolation group information list item (table 1) for unicast attribute to be isolated.
It is that isolation group 2, unicast attribute are isolated group information to be isolated group information is isolated with source due to the purpose, determine purpose every Consistent with source isolation group information from group information, the isolation property being isolated in group information according to purpose can be determined to the known list The processing action for reporting text is isolation, then abandoning the known unicast message.
In conclusion message partition method provided by the invention and device obtain and message pair when receiving message The source isolation group information and purpose isolation group information answered, and determining that purpose isolation group information is consistent with source isolation group information When, message is handled according to isolation property.The present invention realizes the accurate isolation in a VXLAN example to message as a result, into And effective machine utilization reduced in VXLAN networks, improve equipment performance.
The present invention also provides a kind of message isolating device, Fig. 3 is the structural schematic diagram of the message isolating device, which can To apply in local VTEP equipment, which may include source information acquiring unit 301, purpose information acquisition unit 302 and message process unit 303, wherein:
Information acquisition unit 301 obtains source isolation group letter corresponding with the source address of the message for receiving message Breath;
Purpose information acquisition unit 302, for obtaining the destination address in the forwarding-table item locally to prestore with the message Corresponding forwarding information obtains purpose corresponding with the destination address of the message according to the forwarding information and group information is isolated;
Message process unit 303, for when determine source isolation group information and the purpose be isolated group information it is consistent when, The isolation property being isolated in group information according to the purpose handles the message.
Further, the source information acquiring unit 301 is specific can be used for being determined according to the destination address of the message Go out the message attribute of the message;If the message is the message that the host being connect with the local VTEP equipment is sent, obtain The incoming interface information of the message, if finding source corresponding with the incoming interface information in the isolation group information list item to prestore Isolation group ID believes the message attribute and source isolation group ID corresponding with the incoming interface information as the source isolation group Breath, wherein the incoming interface information includes receiving the message in virtual LAN Vlan information and local VTEP equipment The port information of port;It is sent if the message is other VTEP equipment with the local VTEP equipment in same instance VXLAN messages check in the VXLAN messages whether carry isolation group echo, if so, obtain the source that is carried in the message every From a group ID, group ID is isolated using the message attribute with the source carried in the VXLAN messages, group information is isolated as the source.
Further, the forwarding information include purpose isolation group ID corresponding with the destination address of the message and Corresponding purpose VTEP device ids, if the purpose information acquisition unit 302 be specifically used for the message be and the local The message that the host of VTEP equipment connection is sent, and the message is known unicast message, obtains the known unicast message Incoming interface information searches the source isolation group letter according to the incoming interface information of the message in the isolation group information list item to prestore Breath, and judge with the purpose in the forwarding information group ID is isolated whether in the source isolation group ID in the source isolation group information Unanimously, if unanimously, VTEP corresponding with the destination address of known unicast message is determined according to the purpose VTEP device ids Equipment is that other VTEP equipment or local VTEP equipment are looked into if other VTEP equipment in the tunnel information list item to prestore Look for IP address corresponding with the purpose VTEP device ids, and search in the isolation information list item with the IP address and The corresponding isolation property of the purpose isolation group ID, using the purpose isolation group ID and the isolation property as the purpose Group information is isolated;If it is determined that VTEP equipment corresponding with the destination address of known unicast message is local VTEP equipment, root It is searched in the isolation group information list item to prestore according to the purpose isolation group ID in the forwarding information corresponding with the destination address Isolation property, using the purpose isolation group ID and the isolation property corresponding with the destination address as the purpose Group information is isolated;If the message is the VXLAN sent in other VTEP equipment of same instance with the local VTEP equipment Message, and the message is known unicast message, when carrying isolated marks in the known unicast message, described in acquisition Know the source isolation group ID that unicast message carries, judges that group is isolated with the purpose in the forwarding information in the source isolation group ID Whether ID is consistent, if unanimously, being looked into the isolation group information list item to prestore according to the purpose isolation group ID in the forwarding information Corresponding isolation property is looked for, by the purpose isolation group ID and isolation property isolation group as a purpose in the forwarding information Information.
Further, if it is to be connect with the local VTEP equipment that the message process unit 303, which is additionally operable to the message, Host send message obtain the incoming interface information of the multicast message when judging the message for multicast message, if Source isolation group ID corresponding with the incoming interface information is found in the isolation group information list item to prestore, by the source isolation group ID And after isolated marks are added to the message, the message is forwarded;If the message is to be connect with the local VTEP equipment Host send message obtain entering for the message when judging the message for unknown unicast message or broadcasting packet Interface message will if finding source isolation group ID corresponding with the incoming interface information in the isolation group information list item to prestore After the source isolation group ID and isolated marks are added to the message, by the message with belonging to the local VTEP equipment Example in broadcast replication.Further, the message process unit 303 can be also used in local VTEP equipment except described Message described in other interface broadcast replications except the incoming interface of message;Wherein, when carrying out the broadcast replication, acquisition and institute The corresponding purpose isolation group ID of other interfaces judges whether the purpose isolation group ID is isolated group ID with the source consistent, if one It causes, then handles the message according to isolation property.
Further, described device can also include information learning unit 304, for after receiving message, if according to The source address of the message has not checked the corresponding host information of the source address in local forwarding-table item, according to local Received in VTEP equipment the message port and message in the Vlan information that carries looked into the isolation group information list item to prestore Corresponding source isolation group information is looked for, or obtains the source isolation group information carried in the message;
The source address of the message, the incoming interface of the message and the source are isolated to the correspondence of group information three Preserve into the local forwarding-table item, the incoming interface information include in the local VTEP equipment with the transmission message The Vlan information carried in the port information and the message of the port of host connection.
Further, the message process unit 303 is specific can be used for being isolated in group information not when the determining purpose It, will if the message is the message that the host being connect with the local VTEP equipment is sent when group information is isolated including the source The message is encapsulated as VXLAN messages, and source isolation group information and isolated marks are added to the VXLAN messages Afterwards, it and is forwarded, wherein the isolation group information is source isolation group ID;Do not include when determining in the purpose isolation group information When the source isolation group information, if the message is other VTEP equipment transmission in same instance with the local VTEP equipment VXLAN messages, to the VXLAN messages decapsulate after, be forwarded with the forwarding information according in the forwarding-table item.
In addition, the present invention be applied to local VTEP equipment message isolating device in specific process flow can with it is upper The process flow for stating message partition method is consistent, and details are not described herein.
Above-mentioned apparatus can be by software realization, can also be by hardware realization, and message isolating device place of the present invention is originally The hardware structure schematic diagram of ground VTEP equipment can refer to shown in Fig. 4, and basic hardware environment includes central processor CPU, turns Chip, memory and other hardware are sent out, wherein memory device includes machine readable instructions, and CPU reads and executes machine can Reading instruction executes the function of each unit in Fig. 3.
From the embodiment of any of the above method and apparatus as can be seen that the present invention when receiving message, obtain with Group information is isolated in the corresponding source isolation group information of message and purpose, and group information is isolated in the source that determines, group information is isolated with purpose When consistent, the isolation property being isolated in group information according to purpose handles the message.It can be seen that the present invention is realized to same Message in VXLAN examples is accurately isolated, and effective machine utilization reduced in VXLAN networks improves equipment performance.
The foregoing is merely illustrative of the preferred embodiments of the present invention, is not intended to limit the invention, all essences in the present invention With within principle, any modification, equivalent substitution, improvement and etc. done should be included within the scope of protection of the invention god.

Claims (14)

1. a kind of message partition method, the local endpoint of a tunnel VTEP equipment being applied in expansible Virtual Local Area Network VXLAN, It is characterized in that, the method includes:
Message is received, source corresponding with the source address of the message is obtained and group information is isolated;
Forwarding information corresponding with the destination address of the message in the forwarding-table item locally to prestore is obtained, is believed according to the forwarding Breath obtains purpose corresponding with the destination address of the message and group information is isolated;
When determining that the source isolation group information is consistent with purpose isolation group information, it is isolated in group information according to the purpose Isolation property handle the message;
When determine the purpose be isolated group information be isolated with the source group information it is inconsistent when, if the message for and the local The message is encapsulated as VXLAN messages by the message that the host of VTEP equipment connection is sent, and by the source be isolated group information with And isolated marks be added to the VXLAN messages after be forwarded;
When determine the purpose be isolated group information be isolated with the source group information it is inconsistent when, if the message for and the local The VXLAN messages that VTEP equipment is sent in other VTEP equipment of same instance, after being decapsulated to the VXLAN messages, according to It is forwarded with the forwarding information in the forwarding-table item.
2. the method as described in claim 1, which is characterized in that after receiving message, the method further includes:
The message attribute of the message is determined according to the destination address of the message;
It is described obtain corresponding with the source address of the message source group information be isolated specifically include:
If the message is the message that the host being connect with the local VTEP equipment is sent, the incoming interface letter of the message is obtained Breath, if source isolation group ID corresponding with the incoming interface information is found in the isolation group information list item to prestore, by the report Group information is isolated as the source in literary attribute and source isolation group ID corresponding with the incoming interface information, wherein described to enter to connect Message breath includes the port information for the port that the message is received in virtual LAN Vlan information and local VTEP equipment;
If the message is the VXLAN messages sent in other VTEP equipment of same instance with the local VTEP equipment, inspection It looks into the VXLAN messages and whether carries isolation group echo, if so, the source isolation group ID carried in the message is obtained, by institute It states message attribute and group ID is isolated with the source carried in the VXLAN messages as source isolation group information.
3. the method as described in claim 1, which is characterized in that the forwarding information includes the destination address pair with the message The purpose isolation group ID and corresponding purpose VTEP device ids answered, it is described to be obtained and the message according to the forwarding information Destination address corresponding purpose isolation group information specifically include:
If the message is the message that the host being connect with the local VTEP equipment is sent, and the message is known unicast report Text obtains the incoming interface information of the known unicast message, is believed in the isolation group to prestore according to the incoming interface information of the message The source isolation group information is searched in breath list item, and judges that the source isolation group ID in the source isolation group information believes with the forwarding Whether the purpose isolation group ID in breath is consistent, if unanimously, being determined and the known list according to the purpose VTEP device ids The corresponding VTEP equipment of destination address for reporting text is other VTEP equipment or local VTEP equipment, if other VTEP are set It is standby, IP address corresponding with the purpose VTEP device ids is searched in the tunnel information list item to prestore, and believe in the isolation It ceases and searches isolation property corresponding with the IP address and the purpose isolation group ID in list item, by the purpose isolation group ID And as the purpose group information is isolated with the isolation property;If it is determined that the destination address pair with the known unicast message The VTEP equipment answered is local VTEP equipment, according to the purpose isolation group ID in the forwarding information in the isolation group information to prestore Isolation property corresponding with the destination address is searched in list item, by the purpose isolation group ID and the described and destination Group information is isolated as the purpose in the corresponding isolation property in location;
If the message is the VXLAN messages sent in other VTEP equipment of same instance with the local VTEP equipment, and The message is that known unicast message obtains the known unicast when carrying isolated marks in the known unicast message The source isolation group ID that message carries, judges with the purpose in the forwarding information group ID is isolated whether in the source isolation group ID Unanimously, if unanimously, searching correspondence in the isolation group information list item to prestore according to the purpose isolation group ID in the forwarding information Isolation property, by the forwarding information purpose isolation group ID and the isolation property group information is isolated as a purpose.
4. the method as described in claim 1, which is characterized in that the method further includes:
If the message is the message that the host that is connect with the local VTEP equipment is sent, when judging that the message is to organize report Wen Shi obtains the incoming interface information of the multicast message, if finding to enter to connect with described in the isolation group information list item to prestore Message ceases corresponding source isolation group ID, after the source isolation group ID and isolated marks are added to the message, described in forwarding Message;
If the message is the message that the host that is connect with the local VTEP equipment is sent, when judging the message for unknown list When reporting text or broadcasting packet, the incoming interface information of the message is obtained, if being searched in the isolation group information list item to prestore To source isolation group ID corresponding with the incoming interface information, the source isolation group ID and isolated marks are added to the message Afterwards, by the message with broadcast replication in the example belonging to the local VTEP equipment.
5. method as claimed in claim 4, which is characterized in that it is described by the message with belonging to the local VTEP equipment Example in broadcast replication specifically include:
Message described in other interface broadcast replications in local VTEP equipment in addition to the incoming interface of the message;
Wherein, when carrying out the broadcast replication, purpose isolation group ID corresponding with other described interfaces is obtained, judges the mesh Isolation group ID whether be isolated group ID with the source consistent, if unanimously, the message is handled according to isolation property.
6. the method as described in claim 1, which is characterized in that the method further includes:
After receiving message, if not checked the source address in local forwarding-table item according to the source address of the message Corresponding host information, according to the Vlan information carried in the port and message for receiving the message in local VTEP equipment pre- Corresponding source isolation group information is searched in the isolation group information list item deposited, or obtains the source isolation group letter carried in the message Breath;
The source address of the message, the incoming interface information of the message and the source are isolated to the correspondence of group information three Preserve into the local forwarding-table item, the incoming interface information include in the local VTEP equipment with the transmission message The Vlan information carried in the port information and the message of the port of host connection.
7. the method as described in claim 1, which is characterized in that wherein, the isolation group information is source isolation group ID.
8. a kind of message isolating device, the local VTEP equipment being applied in VXLAN networks, which is characterized in that described device packet It includes:
Source information acquiring unit obtains source corresponding with the source address of the message and group information is isolated for receiving message;
Purpose information acquisition unit, for obtaining in the forwarding-table item locally to prestore corresponding with the destination address of the message turn Photos and sending messages obtain purpose corresponding with the destination address of the message according to the forwarding information and group information are isolated;
Message process unit, for when determine source isolation group information and the purpose be isolated group information it is consistent when, according to institute The isolation property stated in purpose isolation group information handles the message;
The message process unit is specifically used for:Do not include that group information is isolated in the source when determining in the purpose isolation group information When, if the message is the message that the host being connect with the local VTEP equipment is sent, the message is encapsulated as VXLAN reports Text, and the source is isolated after group information and isolated marks are added to the VXLAN messages, and be forwarded;When determining State purpose isolation group information in include the source isolation group information when, if the message be with the local VTEP equipment same The VXLAN messages that other VTEP equipment of one example are sent, after being decapsulated to the VXLAN messages, according to the forwarding-table item In be forwarded with the forwarding information.
9. device as claimed in claim 8, which is characterized in that the source information acquiring unit is specifically used for:
The message attribute of the message is determined according to the destination address of the message;
If the message is the message that the host being connect with the local VTEP equipment is sent, the incoming interface letter of the message is obtained Breath, if source isolation group ID corresponding with the incoming interface information is found in the isolation group information list item to prestore, by the report Group information is isolated as the source in literary attribute and source isolation group ID corresponding with the incoming interface information, wherein described to enter to connect Message breath includes the port information for the port that the message is received in virtual LAN Vlan information and local VTEP equipment;
If the message is the VXLAN messages sent in other VTEP equipment of same instance with the local VTEP equipment, inspection It looks into the VXLAN messages and whether carries isolation group echo, if so, the source isolation group ID carried in the message is obtained, by institute It states message attribute and group ID is isolated with the source carried in the VXLAN messages as source isolation group information.
10. device as claimed in claim 8, which is characterized in that the forwarding information includes the destination address with the message Corresponding purpose isolation group ID and corresponding purpose VTEP device ids, the purpose information acquisition unit are specifically used for:
If the message is the message that the host being connect with the local VTEP equipment is sent, and the message is known unicast report Text obtains the incoming interface information of the known unicast message, is believed in the isolation group to prestore according to the incoming interface information of the message The source isolation group information is searched in breath list item, and judges that the source isolation group ID in the source isolation group information believes with the forwarding Whether the purpose isolation group ID in breath is consistent, if unanimously, being determined and the known list according to the purpose VTEP device ids The corresponding VTEP equipment of destination address for reporting text is other VTEP equipment or local VTEP equipment, if other VTEP are set It is standby, IP address corresponding with the purpose VTEP device ids is searched in the tunnel information list item to prestore, and believe in the isolation It ceases and searches isolation property corresponding with the IP address and the purpose isolation group ID in list item, it will be in the forwarding information Group information is isolated as the purpose in purpose isolation group ID and the isolation property;If it is determined that with the known unicast message The corresponding VTEP equipment of destination address is local VTEP equipment, is being prestored according to purpose isolation group ID in the forwarding information It is isolated in group information list item and searches isolation property corresponding with the destination address, by the purpose isolation group in the forwarding information Group information is isolated as the purpose in ID and the isolation property corresponding with the destination address;
If the message is the VXLAN messages sent in other VTEP equipment of same instance with the local VTEP equipment, and The message is that known unicast message obtains the known unicast when carrying isolated marks in the known unicast message The source isolation group ID that message carries, judges with the purpose in the forwarding information group ID is isolated whether in the source isolation group ID Unanimously, if unanimously, searching correspondence in the isolation group information list item to prestore according to the purpose isolation group ID in the forwarding information Isolation property, by the forwarding information purpose isolation group ID and the isolation property group information is isolated as a purpose.
11. device as claimed in claim 8, which is characterized in that the message process unit is additionally operable to:
If the message is the message that the host that is connect with the local VTEP equipment is sent, when judging that the message is to organize report Wen Shi obtains the incoming interface information of the multicast message, if finding to enter to connect with described in the isolation group information list item to prestore Message ceases corresponding source isolation group ID, after the source isolation group ID and isolated marks are added to the message, described in forwarding Message;
If the message is the message that the host that is connect with the local VTEP equipment is sent, when judging the message for unknown list When reporting text or broadcasting packet, the incoming interface information of the message is obtained, if being searched in the isolation group information list item to prestore To source isolation group ID corresponding with the incoming interface information, the source isolation group ID and isolated marks are added to the message Afterwards, by the message with broadcast replication in the example belonging to the local VTEP equipment.
12. device as claimed in claim 11, which is characterized in that the message process unit is additionally operable to:
Message described in other interface broadcast replications in local VTEP equipment in addition to the incoming interface of the message;Wherein, exist When carrying out the broadcast replication, obtain with the institute corresponding purpose isolation group ID of other interfaces, judge the purpose isolation group ID and Whether the source isolation group ID is consistent, if unanimously, the message is handled according to isolation property.
13. device as claimed in claim 8, which is characterized in that described device further includes information learning unit, is used for:
After receiving message, if not checked the source address in local forwarding-table item according to the source address of the message Corresponding host information, according to the Vlan information carried in the port and message for receiving the message in local VTEP equipment pre- Corresponding source isolation group information is searched in the isolation group information list item deposited, or obtains the source isolation group letter carried in the message Breath;
The source address of the message, the incoming interface information of the message and the source are isolated to the correspondence of group information three Preserve into the local forwarding-table item, the incoming interface information include in the local VTEP equipment with the transmission message The Vlan information carried in the port information and the message of the port of host connection.
14. device as claimed in claim 8, which is characterized in that the wherein described isolation group information is source isolation group ID.
CN201510184344.7A 2015-04-17 2015-04-17 Message partition method and device Active CN104780089B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510184344.7A CN104780089B (en) 2015-04-17 2015-04-17 Message partition method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510184344.7A CN104780089B (en) 2015-04-17 2015-04-17 Message partition method and device

Publications (2)

Publication Number Publication Date
CN104780089A CN104780089A (en) 2015-07-15
CN104780089B true CN104780089B (en) 2018-07-24

Family

ID=53621344

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510184344.7A Active CN104780089B (en) 2015-04-17 2015-04-17 Message partition method and device

Country Status (1)

Country Link
CN (1) CN104780089B (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112311737A (en) * 2019-07-31 2021-02-02 中兴通讯股份有限公司 Flow isolation method, device and equipment and storage medium
CN111541651B (en) * 2020-03-31 2022-10-21 新华三技术有限公司 Communication method and device

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101232446A (en) * 2008-02-01 2008-07-30 华为技术有限公司 Message processing method and apparatus
CN101719877A (en) * 2010-01-15 2010-06-02 福建星网锐捷网络有限公司 Message forwarding device, network equipment and method
CN102594834A (en) * 2012-03-09 2012-07-18 北京星网锐捷网络技术有限公司 Method and device for defending network attack and network equipment

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102404181B (en) * 2010-09-08 2014-10-08 华为技术有限公司 Address corresponding relationship sending method of layer 2 protocol utilizing link state routing
JP5880570B2 (en) * 2010-12-27 2016-03-09 日本電気株式会社 Mapping server device, network system, packet transfer method and program

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101232446A (en) * 2008-02-01 2008-07-30 华为技术有限公司 Message processing method and apparatus
CN101719877A (en) * 2010-01-15 2010-06-02 福建星网锐捷网络有限公司 Message forwarding device, network equipment and method
CN102594834A (en) * 2012-03-09 2012-07-18 北京星网锐捷网络技术有限公司 Method and device for defending network attack and network equipment

Also Published As

Publication number Publication date
CN104780089A (en) 2015-07-15

Similar Documents

Publication Publication Date Title
US9525563B2 (en) Forwarding packets in an edge device
US10200212B2 (en) Accessing IP network and edge devices
CN103200069B (en) A kind of method and apparatus of Message processing
CN103841023B (en) The method and apparatus of data forwarding
US9641352B2 (en) Packet forwarding
CN107645431B (en) Message forwarding method and device
CN109729012B (en) Unicast message transmission method and device
WO2019137355A1 (en) Method and device for transmitting data, and network system
CN104243269A (en) Processing method and device of messages in VxLAN (virtual extensible local area network)
CN106209557B (en) Message forwarding method and device
CN105187311B (en) A kind of message forwarding method and device
WO2016045608A1 (en) Processing a flow entry in vxlan
CN103401781B (en) It is applied to cut-in method and the equipment of multilink transparent interconnection network
WO2013029440A1 (en) Method and apparatus for implementing layer-2 interconnection of data centers
CN106330719B (en) A kind of VXLAN message forwarding method and device
CN107659484B (en) Method, device and system for accessing VXLAN network from VLAN network
CN108199968A (en) Route processing method and device
CN104780090B (en) Method, apparatus, the PE equipment of VPN multicast transmissions
CN114095460B (en) Message broadcasting method and device
CN106992918A (en) Message forwarding method and device
CN104780089B (en) Message partition method and device
WO2019128612A1 (en) Method and device for processing routing protocol packet
CN110391984B (en) Message forwarding method and device
WO2016035306A1 (en) Control system, communication system, communication method, and recording medium
EP3913865B1 (en) Message decapsulation method and device, message encapsulation method and device, electronic device, and storage medium

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
EXSB Decision made by sipo to initiate substantive examination
SE01 Entry into force of request for substantive examination
CB02 Change of applicant information
CB02 Change of applicant information

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Applicant after: Xinhua three Technology Co., Ltd.

Address before: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Applicant before: Huasan Communication Technology Co., Ltd.

GR01 Patent grant
GR01 Patent grant
TR01 Transfer of patent right
TR01 Transfer of patent right

Effective date of registration: 20190628

Address after: Room 101, 1st floor, No. 1 Building, No. 8 Courtyard, Yongjiabei Road, Haidian District, Beijing 100094

Patentee after: Beijing Huasan Communication Technology Co., Ltd.

Address before: 310052 Changhe Road, Binjiang District, Hangzhou, Zhejiang Province, No. 466

Patentee before: Xinhua three Technology Co., Ltd.