WO2006096560A2 - System and methods for network reachability detection - Google Patents

System and methods for network reachability detection Download PDF

Info

Publication number
WO2006096560A2
WO2006096560A2 PCT/US2006/007722 US2006007722W WO2006096560A2 WO 2006096560 A2 WO2006096560 A2 WO 2006096560A2 US 2006007722 W US2006007722 W US 2006007722W WO 2006096560 A2 WO2006096560 A2 WO 2006096560A2
Authority
WO
WIPO (PCT)
Prior art keywords
stack
response
path
successive
node
Prior art date
Application number
PCT/US2006/007722
Other languages
French (fr)
Other versions
WO2006096560A3 (en
Inventor
Thomas D. Nadeau
Mohammed Azhar Sayeed
Michael T. Piecuch
James N. Guichard
Jean-Philippe Vasseur
Original Assignee
Cisco Technology, Inc.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Cisco Technology, Inc. filed Critical Cisco Technology, Inc.
Priority to EP06736961.1A priority Critical patent/EP1856862B1/en
Priority to CN200680004044.5A priority patent/CN101124785B/en
Publication of WO2006096560A2 publication Critical patent/WO2006096560A2/en
Publication of WO2006096560A3 publication Critical patent/WO2006096560A3/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/50Testing arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/02Topology update or discovery
    • H04L45/04Interdomain routing, e.g. hierarchical routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/36Backward learning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/50Routing or path finding of packets in data switching networks using label swapping, e.g. multi-protocol label switch [MPLS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/16Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]

Definitions

  • Virtual Private Networks are becoming an increasingly popular mechanism to interconnect multiple remote sites of a common entity, such as a corporation, university, governmental institution, or other enterprise.
  • a VPN allows remote sites to interconnect as if colocated by providing message transport, security, and node addressing.
  • Such a VPN interconnects multiple subnetworks, or local area networks (LANs), of an enterprise such as a corporation, university, or distributor, for example.
  • the subnetworks in turn, interconnect with each other via a private or public access network such as the Internet, intranets, VPNs and the like.
  • Such a subnetwork interconnection is typically known as a core network, and includes service providers having a high speed backbone of routers and trunk lines.
  • Each of the subnetworks and the core networks have entry points known as edge routers, through which traffic ingressing and egressing from the network flows.
  • the core network has ingress/egress points handled by nodes known as provider edge (PE) routers, while the subnetworks have ingress/egress points known as customer edge (CE) routers, discussed further in Internet Engineering Task Force (IETF) RFC 2547bis, concerning Virtual Private Networks (VPNs).
  • PE provider edge
  • CE customer edge
  • An interconnection between the subnetworks of a VPN therefore, typically includes one or more core networks.
  • Each of the core networks is usually one or many autonomous systems (AS), meaning that it employs and enforces a common routing policy among the nodes (routers) included therein.
  • AS autonomous systems
  • the nodes of the core networks often employ a protocol operable to provide high-volume transport with path based routing, meaning that the protocol not only specifies a destination (as in TCP/IP), Thus, the protocol does not merely specify a destination, as in TCP/IP; it implements an addressing strategy that allows for unique identification of end points, and also allows specification of a particular routing path through the core network.
  • One such protocol is the Multiprotocol Label Switching (MPLS) protocol, defined in Internet Engineering Task Force (IETF) RFC 3031.
  • MPLS is a protocol that combines the label-based forwarding of ATM networks, with the packet-based forwarding of IP networks and then builds applications upon this infrastructure.
  • G-MPLS Generalized MPLS
  • IP protocols to expedite the forwarding scheme used by conventional IP routers, particularly through core networks employed by service providers (as opposed to end-user connections or taps).
  • Routers to date, have used complex and time-consuming route lookups and address matching schemes to determine the next hop for a received packet, primarily by examining the destination address in the header of the packet.
  • MPLS has greatly simplified this operation by basing the forwarding decision on a simple label.
  • Another major feature of MPLS is its ability to place IP traffic on a particular defined path through the network. Such path specification capability is generally not available with conventional IP traffic. In this way, MPLS provides bandwidth guarantees and other differentiated service features for a specific user application (or flow).
  • Current IP-based MPLS networks are emerging for providing advanced services such as bandwidth-based guaranteed service, priority-based bandwidth allocation, and preemption services.
  • a table for a forwarding equivalence class is created to represent a group of flows with the same traffic-engineering requirements.
  • a specific label is then bound to an FEC.
  • incoming IP packets are examined and assigned a "label" by a label edge router (LER).
  • LER label edge router
  • the labeled packets are then forwarded along an LSP, where each label-switched router (LSR) makes a switching decision based on the packet's label field.
  • LSRs avoid examining the IP headers of the packets to find an output port (next hop).
  • An LSR simply strips off the existing label and applies a new label for the next hop.
  • the label information base provides an outgoing label (to be inserted into the packet) and an outgoing interface (based on an incoming label on an incoming interface).
  • MPLS uses a technique called label switching (or swapping or popping) as a means to transport data across a network.
  • the routers within an MPLS network that are responsible for label processing are known as Label Switching Routers (LSRs), and the path , followed by data is known as a Label Switched Path (LSP).
  • LSRs Label Switching Routers
  • LSP Label Switched Path
  • the MPLS header contains a stack of labels - one or more - that uniquely identify the switching path between any two LSRs. This label tells adjacent switching nodes how to process and forward the data.
  • each packet As each packet is received by a node, it may push a new label onto the stack of a packet before forwarding it on, pop one from the stack, or swap one or more of the labels with new ones.
  • the path of the packet through the network is defined by its initial labeling. Accordingly, the subsequent mapping of labels is consistent at each node so as to fonn a complete label switched path between the ingress to and the egress from the MPLS network.
  • a Virtual Private Network typically employs one or more core networks to interconnect a plurality of local networks, such as LANs, by a VPN service operable to provide transport, routing and security to message traffic between the subnetworks, such that nodes of each sub-LAN can communicate with nodes of other sub- LANs as members of the same VPN.
  • the particular subnetworks may be individual sites of a large business enterprise, such as a bank, retail, or large corporation, having multiple distinct sites each with a substantial subnetwork.
  • a conventional VPN in such an environment is well suited to provide the transparent protection of communication between the subnetworks, such as ensuring protection of transported data via security and encryption, routing policies, and access control among valid users via privileges and access credentials, for example.
  • Message traffic between the VPN subnetworks therefore, egresses from an originating subnet via a CE router, enters a core network denoting an autonomous system (AS) via a PE router, and traverses one or more AS core networks to a remote PE router, where it enters a remote VPN subnet via a CE router operable to deliver the message traffic to an IP destination.
  • AS autonomous system
  • VPNs are a popular mechanism for interconnecting remote related sites of an organization or enterprise, including various configurations such as LANs, intranets, extranets, and other interconnection mechanisms employed between multiple related but remote sites to provide secure, seamless interconnection to the organization or enterprise as a whole.
  • a VPN interconnects multiple subnetworks, or local area networks (LANs), of an enterprise such as a corporation, university, or distributor, for example.
  • the subnetworks in turn, interconnect with each other via a public access network such as the Internet.
  • LANs local area networks
  • Such a subnetwork interconnection is typically known as a core network, and includes service providers having a high speed backbone of routers and trunk lines.
  • routers refers to the various types of high-speed data switching devices typically employed in such networks, including but not limited to routers, switches, hubs, bridges and other connectivity devices employing a variety of mediums, such as electronic, optical, cellular, RF or other medium.
  • Each of the subnetworks and the core networks has entry points known as edge routers, through which traffic ingressing and egressing from the network flows.
  • the core network has ingress/egress points handled by nodes known as provider edge (PE) routers, while the subnetworks have ingress/egress points known as customer edge (CE) routers.
  • PE provider edge
  • CE customer edge
  • the core network may include multiple segments, in which each of the core network segments interconnects with other core network segments, also known as autonomous systems.
  • An Autonomous System (AS) is defined by a common routing policy among the nodes of the AS.
  • ASBRs Autonomous System Border Routers (ASBRs) define ingress/egress points between one or more Autonomous Systems.
  • the edge routers often employ a specialized protocol particularly operable for serving network to network interconnections- i.e. edge router connections.
  • One such protocol is the Border Gateway Protocol (BGP), for example, which interconnects CE and PE routers at the edge of the core network.
  • Border Gateway Protocol BGP
  • BGP Border Gateway Protocol
  • MPLS MPLS protocol.
  • packets are often forwarded using the so-called LSP routing mechanism by employing the path label provided by such networks, by various techniques such as forwarding, autorouting, and static routing, as is known to those of skill in the art.
  • MPLS is typically well suited for service provider core networks or medium to large enterprise networks, rather than end-user connections via a local LAN.
  • LSRs are core devices (i.e. Labeled Switch Routers) that switch packets
  • LERs are edge devices (i.e. Labeled Edge Routers) that connect with external networks, determine routes, and add or remove labels.
  • An LSP therefore, is a concatenation of switch hops that form an end-to-end forwarding path.
  • An LSP starts at an ingress LER, crosses one or more LSRs, and ends at an egress LER.
  • the ingress LER When a packet arrives at an MPLS network, the ingress LER performs a substantial portion of the work of handling the packet. It examines the IP address of the packet, determines a route, assigns an LSP, and attaches a label. The packet is then forwarded into the LSP, where it is switched across a series of LSRs until it reaches the egress LER. The label is removed and the packet is forwarded on its way via standard IP routing.
  • One particular feature of MPLS is the ability to build virtual paths or circuits across IP networks. These Virtual Connections (VCs) are called label switched paths (LSPs). LSPs are similar to virtual circuits in ATM and frame relay networks in that they define a specific path between two points in a network. Labels are attached to packets, which assist MPLS nodes in forwarding packets along an LSP. The labels are like tracking slips on express
  • a typical ping is a small message sent to the remote node for which reachability status is sought.
  • the message informs the remote node to send a response message, or acknowledgment, back to the sender to indicate the reachability of the remote node.
  • the sending node identifies, based on the response or lack thereof, of the availability of the remote node and any associated subnetworks.
  • a ping may be employed to determine availability of a node or remote subnetwork, such as by pinging the PE router serving the remote VPN subnet. Such messages may also be used to trace the path taken by the LSP.
  • an MPLS network often operates as a core network between VPN subnetworks. Such an MPLS network often includes multiple autonomous systems (AS), each operating a particular routing policy. Often, an address of a particular node in an AS may not be recognized outside the AS.
  • AS autonomous systems
  • LSP labeled switch path routing
  • Message traffic i.e. packets
  • ASBR Autonomous System Border Router
  • ASBR Autonomous System Border Router
  • the assigned label identifies a path through the AS to an egress ASBR on a remote side of the AS. Therefore, the LSP label is not known outside the AS.
  • a message (packet) traversing multiple autonomous systems is transported between ASBRs at each ingress/egress point.
  • ASBR routers therefore, connect to other ASBR routers on the route to the destination.
  • Each intermediate AS transports the packet from the ingress ASBR to the egress ASBR via the assigned label and corresponding LSP, and the egress ASBR transmits the packet to the ingress ASBR at the next AS along the route.
  • pinging in such conventional MPLS systems suffer from several shortcomings.
  • the identity of the ping initiator may not be recognized beyond the originating AS.
  • Traditional MPLS Pings do not span beyond an AS, due to difficulty with propagating an intra-AS address outside it's native AS.
  • such conventional ASBRs employ a Time-To-Live (TTL) attribute or router alert label in Ping messages.
  • TTL Time-To-Live
  • the ASBRs set the TTL to 1 hop, indicating that the Ping message is to be terminated before leaving the originating AS. Setting the TTL to 1 ensured that packets did not propagate beyond the originating AS. Therefore, there is not a mechanism to perform a conventional MPLS ping beyond the ASBR.
  • conventional pings cannot span multiple autonomous systems because the conventional ASBRs employing LSP routing cannot provide a return address for outgoing pings to a remote AS, VPN subnet (i.e. CE or PE router), or other destination.
  • configurations discussed further below substantially overcome the shortcoming of conventional MPLS ping operations by identifying the originating node, or router, in an LSP conversant AS, and maintaining the identity of the originating node and successive nodes in subsequent autonomous systems along the path (route) to the node to be pinged.
  • the identity of the transporting nodes is stored in a stack or other object associated with the ping request (ping), such that the pinged node may employ the stored identity as a set of return addresses, or return path routing information.
  • Successive ASBRs store their identity on the stack, in an ordered manner, along the path to the destination.
  • the destination node Upon reaching the destination (ping) node, the destination node employs the identity of the first node on the stack to send the acknowledgment, or ping response.
  • the first node from the stack upon receiving the ping response, pops (retrieves) the second node from the stack as the node to redirect the ping response to.
  • Each successive ASBR therefore, pops (retrieves) the next node identity from the stack and redirects (sends) the ping response to the retrieved node. Since the identities of each of the ASBRs are pushed onto the stack in order, and since the ping response travels the same path as the ping (due to the nature of LSP), the identities (addresses) retrieved from the stack are valid LSP addresses according to each respective ASBR on the response path.
  • the method of assessing the state of a remote node via a labeled switch path as disclosed herein includes identifying a remote node from which an acknowledging response is requested, in which the remote node corresponds to a path including a sequence of border routers, and storing an entry indicative of an originator node of the acknowledging response request in a response request message.
  • the originator transmits, from the originator node, the response request message to an egress border router included in the path to the remote node.
  • the egress ASBR transmits the response request message to successive border routers on the path to the remote node in an iterative manner, and accumulates, in a nondestructive manner at each successive border router, an entry indicative of the identity of each the successive border routers on the path to the remote node.
  • accumulating entries indicative of successive border routers traversed on the path to the identified remote node includes building a stack of successive edge nodes, in which the stack corresponds to a normalized field in the acknowledgement request message, such as via a protocol specification.
  • the response request message (i.e. ping) is operable to traverse a plurality of subnetworks defined by border routers indicative of ingress points to the respective subnetwork, each of the subnetworks being an autonomous system having an independent routing policy.
  • a path is defined through each of the subnetworks via a predetermined label, in which the predetermined label is operable to be recognized by the border routers within the respective subnetwork.
  • the accumulated entries are written to a stack and the non- destructive manner avoids overwriting successive accumulated entries such that retrieval of the entries is performable in a reverse order from which they were written.
  • the stack has a first address and successive addresses indicative of an ordered set of border nodes traversed by the acknowledgment request. Therefore, the accumulated entries are written to the stack of return path routing info ⁇ nation in an ordered manner indicative of the path.
  • the destination (pinged) node generates the acknowledgment response, or ping reply, by receiving, at the destination node, the acknowledgment request, building an acknowledgment request response including the stack of return path routing information accumulated in the acknowledgment request, and transmitting the acknowledgment request response to the first return address on the stack.
  • Return transmission further includes forwarding the acknowledgment response back to the originator by retrieving the first address on the stack, such that the return address placed on the stack previous to the first address is the current first return address on the stack, transmitting the acknowledgment response to the retrieved first address, and repeating the retrieval and transmitting for each successive address on the return path routing information stack until the originator receives the acknowledgement response.
  • the network forwards the acknowledgement response message, in the exemplary configuration, according to forwarding rules, in which the forwarding rules further include transmitting, if an acknowledgment request is received, to the next route toward the ping destination, redirecting, if an acknowledgment response is received, to the next address on the stack, the ping response, and identifying, if the destination cannot be reached, the AS encountering the unreachability condition.
  • forwarding rules enable bi-directional logic for handling acknowledgement request and response messages according to a single rule set. For security any privacy, upon encountering an error transmitting one of the acknowledgement request and the acknowledgment response, the receiving router may erase the routing history indicative of its specific portion of the path, such that successive interceptors of the message would be unable to examine the stack indicative of the path.
  • successive return addresses may be stored by border routers, in which the border routers retain an identity of the previous border router indicative of the last hop in the previous autonomous system traversed by the message.
  • multiple paths may exist between a first subnetwork and a second subnetwork (i.e. autonomous systems), and the accumulated addresses are indicative of the path of the acknowledgement request such that the same path is enabled for the acknowledgement response. Otherwise, the request response may be unable to determine the proper AS corresponding to the original request.
  • Alternate configurations of the invention include a multiprogramming or multiprocessing computerized device such as a workstation, handheld or laptop computer or dedicated computing device or the like configured with software and/or circuitry (e.g., a processor as summarized above) to process any or all of the method operations disclosed herein as embodiments of the invention.
  • Still other embodiments of the invention include software programs such as a Java Virtual Machine and/or an operating system that can operate alone or in conjunction with each other with a multiprocessing computerized device to perform the method embodiment steps and operations summarized above and disclosed in detail below.
  • One such embodiment comprises a computer program product that has a computer-readable medium including computer program logic encoded thereon that, when performed in a multiprocessing computerized device having a coupling of a memory and a processor, programs the processor to perform the operations disclosed herein as embodiments of the invention to carry out data access requests.
  • Such arrangements of the invention are typically provided as software, code and/or other data (e.g., data structures) arranged or encoded on a computer readable medium such as an optical medium (e.g., CD-ROM), floppy or hard disk or other medium such as firmware or microcode in one or more ROM or RAM or PROM chips, field programmable gate arrays (FPGAs) or as an Application Specific Integrated Circuit (ASIC).
  • a computer readable medium such as an optical medium (e.g., CD-ROM), floppy or hard disk or other medium such as firmware or microcode in one or more ROM or RAM or PROM chips, field programmable gate arrays (FPGAs) or as an Application Specific Integrated Circuit (
  • the software or firmware or other such configurations can be installed onto the computerized device (e.g., during operating system for execution environment installation) to cause the computerized device to perform the techniques explained herein as embodiments of the invention.
  • Fig. 1 is a context diagram of a network communications environment having a core network including multiple Autonomous Systems (AS) operable for use with the present invention
  • AS Autonomous Systems
  • Fig. 2 is a flowchart of a ping operation via Labeled Switch Path routing between Autonomous System Border Routers (ASBRs) in a core network as in Fig. 1;
  • ASBRs Autonomous System Border Routers
  • Fig. 3 is a block diagram illustrating the LSP Ping between ASBRs in the exemplary network of Fig. 1;
  • Figs. 4-7 are a flowchart of the LSP Ping between a plurality of autonomous systems in greater detail;
  • Fig. 8 is a block diagram of a Labeled Switch Path between two autonomous systems. DETAILED DESCRIPTION
  • the identity of the transporting nodes is stored in a stack or other object associated with the ping request (ping), such that the pinged node may employ the stored identity as a set of return addresses, return path routing information, or other information suitable for identifying the path of the response request message (i.e. ping).
  • Successive ASBRs store their identity on the stack, in an ordered manner, along the path to the destination, such that the collective routing information of nodes traversed enables a reverse traversal to the originating node.
  • routing information may be an IP address or other identifier to enable recreation of the path from the pinged recipient back to the originator.
  • the destination node Upon reaching the destination (ping) node, the destination node employs the identity of the first node on the stack to send the acknowledgment, or ping response.
  • the first node from the stack upon receiving the ping response, pops (retrieves) the second node from the stack as the node to redirect the ping response to.
  • Each successive ASBR therefore, pops (retrieves) the next node identity from the stack and redirects (sends) the ping response to the retrieved node. Since the identities of each of the ASBRs are pushed onto the stack in order, and since the ping response travels the same path as the ping (due to the nature of LSP), the identities (addresses) retrieved from the stack are valid LSP addresses according to each respective ASBR on the response path.
  • Fig. 1 is a context diagram of a network communications environment having a core network including multiple Autonomous Systems (AS) operable for use with the present invention.
  • an exemplary VPN environment 100 includes a plurality of autonomous systems 110-1..110-3 (110, generally) interconnecting remote local LANs, or prefixes 112-1..112-5 (112, generally), for providing VPN connectivity to users (not specifically shown) connected to the LANs 112.
  • the autonomous systems 110 collectively define a core network 150 interconnecting the remote prefixes 112 as such a Virtual Private Network (VPN) environment 100.
  • the prefixes 112 are typically local LANs supporting a particular corporate, institutional, or enterprise site, for example, and the core network 150 includes the Internet, various intranets, or a combination of both.
  • a router In the course of normal routing operations, it is common for a router, or node, to "ping" another node to confirm connectivity or other path status such as delay, jitter, packet loss, etc.
  • ping operations involve sending an acknowledgement request message, or ping, to the node for which status is sought, and receiving an acknowledgment response message, or ping reply, from the pinged node to indicate availability.
  • routing protocols typically employ pings to verify reachability of certain nodes to ascertain availability of various paths and subnetworks available via the pinged node. Further, such pings may be used by a Path Verification Protocol (PVP), discussed further in copending U.S.
  • PVP Path Verification Protocol
  • pings cannot span multiple autonomous systems because the path information is local to each respective AS 110.
  • the path to the pinged node may traverse a plurality of autonomous systems 110, as a series of hops shown as arrows 122-N, 124-N, for the ping and ping reply, respectively.
  • the LSP ping mechanism discussed further helow, provides a mechanism for identifying the complete path 125 defined by the set of hops 122, 124, therefore enabling a ping and ping reply between nodes 126 and across multiple autonomous systems 110.
  • an acknowledgment request message 132 sent by an originating node 126, follows the series of hops 122-1..122-4 to a destination node 128.
  • the destination node 128, in a positive ping scenario receives the acknowledgment request 132, and sends an acknowledgment response message 134, back over the same set of hops 124-1..124- 4 defining the path 125 to the originator 126. If the acknowledgment response 134 (i.e. ping reply), denoted by hops 124-1..124-4, fails to reach the originator 126, then the remote "pinged" node 128 is deemed unavailable.
  • the ping originator 126 and destination 128 maybe any router, such as customer or provider edge (CE or PE) routers, autonomous system border routers (ASBRs), carrier's carrier PE or CE or other switching device interconnecting two or more autonomous systems, internal label switch (LSR) routers, or others.
  • PE routers employ the LSP ping, however alternate configurations may employ the LSP ping other nodes.
  • carrier's carrier the exemplary ASBRs would actually be called CsC-PEs.
  • the return address that is pushed on at a CsC-PE includes an identifier to specify which routing table the address came from.
  • the originating node 126 such as a CE node in a typical LSP ping scenario, may be unaware of the inter- AS nature of the ping recipient 128. Accordingly, the path information retained by the response request 132 is not indicative of an inter- AS scenario until reaching the ASBR egressing from the originating AS.
  • Fig. 2 is a flowchart of a ping operation via Labeled Switch Path routing between Autonomous System Border Routers (ASBRs) in a core network 150 as in Fig. 1.
  • ASBRs Autonomous System Border Routers
  • the method for performing an LSP ping involves assessing the state of a remote node 128 (i.e. the "pinged" router) via a labeled switch path through each respective AS 110.
  • the node originating the ping 126 identifies a remote node 128 from which an acknowledging response 134 is requested, in which the remote node 128 corresponds to a path 125 including a sequence of border routers (discussed further below in Fig.
  • the originating node 126 stores an entry indicative of the address of the originator node 126 of the acknowledging response request in a response request message 132, as depicted at step 201.
  • the originator 126 then transmits, from the originator node (itself), the response request message 132 to a border router included in the path 125 to the remote node 128, such as an ASBR of the AS 110-1 on the path 125 to the remote node 128, as shown at step 202.
  • the ASBR of the AS 110-1 transmits the response request message 132 to successive border routers on the path 125 to the remote node 128, according to forwarding rules 152, as depicted at step 203.
  • the method accumulates, in a nondestructive manner at each successive border router, an entry indicative of the identity (i.e. address) of each the successive border routers on the path 134 to the remote node 128, as depicted at step 204, thus building a set of return path routing information operable to be employed for returning a request response message 134.
  • Fig. 3 is a block diagram illustrating the LSP Ping between ASBRs in the exemplary network of Fig. 1.
  • router PEl 140 attempts to ping node PE5 142.
  • Router PEl in AS 110-11, generates an acknowledgment request message 132 including a return address stack 160, for storing the identity of successive routers traversed by the message 132.
  • the stack 160 is shown at various stages of population 160-1..160-N (160, generally), having an ordered set of entries 160-1..160-N (160 generally), discussed further below.
  • PEl stores its identity as an element 162-1 in the return address stack 160-1, and transmits the message 132 to ASBRl 150, the border router to the adjacent AS 110-12.
  • ASBRl 150-1 stores its identity in the next element 162-2 in the stack 160, and forwards the message to ASBR2 150-2, denoting the entry into AS 110-12.
  • ASBR2 writes element 162-3 to the stack 160-3, and transmits to ASBR3 150-3, defined as an egress router from AS 110-12, which writes the next return address 162-4 in stack 160-4.
  • ASBR4 150-4 receives the acknowledgment request 132, stores its identity as element 162-5 in the stack 160-5, and sends the message 132 to the destination PE5 142.
  • Exemplary destination router 142 is operational, and accordingly, generates the acknowledgment response message 134, including the return address stack 160.
  • PE5 142 then pops the first return address 162-5 off the stack 160-5 and employs the value (ASBR4) 150-4 as the first routing hop for the acknowledgment response message 134.
  • ASBR4 the value
  • the routers LSRn and ARBRn are employing a label switch path routing mechanism, as indicated above, IP addresses are not employed to identify the next hop. Rather, the path identity, local within the AS 110, identifies each respective router 150. Accordingly, each successive router 150-1..150-4 on the path 170 pops (retrieves) the next successive return address 162 off the stack 160 as the next hop for the acknowledgment response 134.
  • a set of forwarding rules 152 enables routing decisions and logic for directing the messages 132 and 134.
  • Figs.4-7 are a flowchart of the LSP ping control flow and routing decisions between a plurality of autonomous systems 110 in greater detail in the exemplary network of Fig. 3.
  • an originator node 140 assesses the state (i.e. reachability) of a remote node 142 via a series of labeled switch paths through autonomous systems 110.
  • the originator 140 identifies the remote node 142 from which an acknowledging response (i.e.
  • the remote node corresponds to a path 170 including a sequence of border routers 150- L.150-4 (150, generally), as depicted at step 300.
  • the path 170 includes the series of LSPs through each of the respective AS encountered between the originator 140 and destination 142, since, as indicated above, each particular LSP assigned by an ASBR does not persist beyond the assigning AS.
  • the originating node 140 stores an entry PEl as entry 162-1 in the stack 160-1 indicative of the originator (itself) 140 of the acknowledgment response request message 132, as disclosed at step 201.
  • the entry is a return address stack 160 stored in the message 132, and the stored entry 162-1 yields the return address PEL
  • the originating node 140 then transmits, from the originator node 140, the response request message 132 to a border router 150-1 included in the path 170 to the remote node 142, as shown at step 302.
  • the ASBR 150-nodes are LSP routers and employ a label to identify a specific path to the next ASBR 150.
  • the path 170 is defined through each of the subnetworks, or autonomous systems 110, via a predetermined label, or labeled switch path, in which the predetermined label is operable to be recognized by the border routers 150 within the respective subnetwork 110, as depicted at step 303.
  • the border router ASBRl 150-1 therefore receives the response request message 132 including the return address stack 160-1.
  • the ASBRs 150 accumulate, in a nondestructive manner, an entry 162 indicative of the identity of each the successive border routers 150 on the path 170 to the remote node 142, as shown at step 304.
  • the set of accumulated entries 162 is stored as a stack 160 to facilitate redirection of the response 134 back along the path 125.
  • Such accumulation of entries 162 indicative of successive border routers 150 traversed on the path 170 to the identified remote node 142 further includes building the stack 160 of successive edge nodes 150, in which the stack 160 corresponds to a normalized field in the acknowledgement request message 132, as depicted at step 305.
  • Each of the ASBRs 150 stores the accumulated entries 162 as a stack of return address 160-N, in which the stack has a first address (i.e. the originator PEl) and successive addressees indicative of the ordered set of border routers 150 traversed by the response request 132, in which each node 150 (e.g. router) writes its identity to the next element 162 on the stack 160, as shown at step 306.
  • the non destructive manner avoids overwriting successive accumulated entries 162-N such that retrieval of the entries is performable in a reverse order from which they were written, as depicted at step 307.
  • ASBRl writes entry 162-2, building the return address stack shown atl60-2
  • ASBR2 writes entry 162-3, shown as stack 160-3
  • ASBR3 writes entry 162-4, shown as stack 160-4
  • ASBR4 pushes entry 162-5, shown as return address stack 160-5, therefore transmitting the response request message 132 to each of the successive border routers 150 on the path 170 to the remote node 142, as disclosed at step 308.
  • an alert flag such as the above described TTL field is set to ensure examination by successive border routers (ASBRs).
  • ASBRs successive border routers
  • the acknowledgment request message 132 is passed to the next ASBR 150, thus continuing to traverse the plurality of subnetworks 110 defined by border routers 150 indicative of ingress points to the respective subnetwork 110, in which each of the subnetworks is an autonomous system having an independent routing policy, as shown at step 310, and control iterates to step 304 accordingly.
  • successive return addresses are stored by the border routers 150, such that the border routers 150 retain an identity of the previous border router 150 indicative of the last hop in the previous autonomous system traversed by the message, rather than or in addition to retaining the stack 160 and return address entries 162-N in the response request message 132.
  • the destination node 142 Upon ingress into the last AS 110-13 on the path 170, the destination node 142 receives the acknowledgment request message 132, and builds an acknowledgment request response 134 including the stack 160 of return path routing information 162 accumulated in the acknowledgment (response) request 132; as depicted at step 311. It should be noted that, as will be discussed further below, if the response request 132 cannot be routed to the ping destination 142, thus indicating unreachability of the destination "ping" node 142, the ASBR 150 encountering unreachability identifies an error in routing, thus indicating a nonresponsive ping.
  • the destination 142 forwards the recently generated request response 134, or acknowledgment response, to the originator 140, as disclosed at step 312. Accordingly, the originator 142 retrieves the first address 162-5 on the stack 160-5, such that the return address 162-N placed on the stack previous 162-(N-I) to the first address is the current first return address on the stack (i.e. a "pop" operation, as is known in the art), as shown at step 312. PE5 142 then transmits the acknowledgment request response 134 to the first (i.e. "popped") return address ASBR4 from the stack 160-5, as depicted at step 313. Similar to the response request 132, the acknowledgment response 134 causes the
  • ASBRs 150 to repeat the retrieval and transmitting for each successive address 162 on the return address stack 160 until the originator 140 receives the acknowledgement response 134, as depicted at step 314.
  • forwarding occurs according to forwarding rules, as depicted at step 315, in which the forwarding rules 152 further include a bi-directional analysis of the response request 132 or acknowledgment response 134, as the case may be.
  • the forwarding rules 152 analyze the messages 132, 134 and direct the ASBR 150 to transmit, if an acknowledgment request 132 is received, to the next route toward the ping destination 142, as shown at step 316; to redirect, if an acknowledgment response 134 is received, to the next address 162 on the stack 160, the ping response 134, as shown at step 317; and to identify, if the destination cannot be reached, the AS 110 or ASBR 150 encountering the unreachability condition, as depicted at step 318.
  • a check is performed, at step 319, to determine if an error is encountered by an ASBR 150 in routing (forwarding or redirecting) the request/response message 132/134, as disclosed at step 319. If an ASBR 150 encounters an error transmitting one of the acknowledgement request 132 and the acknowledgment response 134, the ASBR erases a routing history indicative of the path 170, therefore avoiding dissemination of security sensitive routing/path information, as shown at step 320.
  • ASBR address 162 retrieved from the stack 160. If multiple paths exist between a first subnetwork 110-A and a second subnetwork HO-B, the accumulated addresses 162 are indicative of the path 170 of the acknowledgement request 132 such that the same path is enabled for the acknowledgement response 134, as depicted at step 322. Therefore, the return address stack 160 overrides routing table or other information indicative of an alternative path from a particular ASBR 150. Further, a LSP route is typically indicative of a particular path to an ASBR from within the ASBR, and therefore avoids forwarding to an ASBR which represents an alternate path.
  • the receiving routers interoperate with an already existing equal-cost multipath (ECMP) tree trace.
  • Configurations disclosed herein interoperate by 1) preserving the original IP source address or other structures such as address/path hashing, with respect to the multipath acknowledgement request message even across AS boundaries, and 2) Not modifying/destroying any of the existing structures of the LSP ping (such as the downstream mapping object).
  • private address information may need be removed from downstream mapping, so it may have to be modified non-destructively.
  • a check is performed to determine if there are additional border routers 150 to traverse on the path 170 to the originator node 140, as shown at step 323. If so, then control reverts to step 314 to transport the acknowledgment response 134 back to the originating node 140, using successively popped return addresses 162 from the return address stack 160 which collectively define the path 170 including the LSP routes through each AS 110.
  • Fig. 8 is a block diagram of an alternate router configuration illustrative of other aspects of the LSP ping operation.
  • an exemplary routing sequence including customer edge routers (CE), provider edge routers (PE), provider routers (P), such as LSR routers, and ASBR routers.
  • Stack 162 progression is shown via an LSP ping, or acknowledgment request message, between PE routers showing the stack 162 at increments 162-11..162-17.
  • the ASBRs 150 pop the last address on the stack 162 to retain the path for the subsequent request response (ack) message.
  • the intermediate (P) routers replace the last entry with their own.
  • the first pop occurs at 162-13 with respect to label 11.
  • the second pop occurs at 162-17 with respect to label 13.
  • the diagram indicates that the ASBRs and PE receive the inner label only (i.e. that has TTL or other alert flag set to 1).
  • Fig. 8 illustrates the label stack 162 that is being sent for the packets between each router. Notice that some have 2 labels. Labels are in a stack 162, so between PE and P there are actually 2 labels on each packet. In the initial stack 162-11 from the originating PE, Label 10 is at the top of the stack above label 20. Notice there is no label between CE and PE.
  • the LSP for this network actually goes from PE to PE, thus illustrating differences in employing the address stack in conjunction with LSP ping, rather than an IP ping. In this particular arrangement, the LSP ping traverses from PE to PE, not CE to CE (standard IP ping goes from CE to CE).
  • labeled packets are fast switched though routers. Accordingly, unless something "happens" to the packet, it merely traverses through the network without scrutiny.
  • the exemplary LSP Ping scenario if we blindly send a labeled acknowledgement request packet, it would be fast switched all the way to the CE where it would be dropped. To force it to be "looked at” (i.e. scrutinized by an ASBR), some kind of router alert is introduced.
  • the TTL value is employed accordingly to trigger responsiveness to the LSP Ping messages. Similar to IP packets, each label has a TTL value. So for the packets between PE and P, there are actually 3 separate TTL values.
  • each ASBR sets the TTL (or some other mechanism like the special router alert label) in such a way that it gets "looked at” (interrupted) by the next ASBR or the final destination. Note that such processing does not apply to the reply message; routers will send these ASBR-to-ASBR via the stack that the acknowledgment request message 132 generated.
  • an IP or LSP address may be augmented with, for example, a route distinguisher or some other mechanism to specify which VPN the address came from.
  • a route distinguisher or some other mechanism to specify which VPN the address came from.
  • the P routers should always be hidden to any outside AS. In many cases PEs should be as well.
  • ASBRs are normally "publicly" known however.
  • ASBRs may be known only by their directly neighboring AS. So as an acknowledgement reply is returned to each ASBR, the ASBR may remove all information about P and PE routers, as discussed above. Further, the stack 162 may also maintain a list of the ASBRs 150-N that the reply 134 has passed through so when the reply 134 reaches the originator 140, it has exactly the path of ASBRs 150 that the ping reached.
  • peering Such visibility is often known as a "peering" between routers. Normally the peering is a private peering so the ASBRs 150 are known between the two peering entities. Such an approach may trigger security implications in particular configurations. However, the sender may not have a peering agreement with the receiver and in this case we should not divulge any IP information to the sender. Configurations discussed herein, therefore, maintain such information within the transiting AS so that the end-to-end path can be determined.
  • the ASBR is known between the two entities, hence even in private peering ASBRs are well known to the routers in the network because the Border Gateway Protocol (BGP) next hop is advertised. Accordingly, the designation "publicly known” is relevant to the two networks in question. Such unknown PEs may be taken to imply that no PE loopbacks are leaked.
  • Private means that A only knows about B but may learn information about C via B.
  • A,B&C are AS's. In this case, any destinations reachable via C are known to A as being reachable via B. A does not know anything about Cs addresses. However, if you put that IP information within the LSP-ping return then A now has this information which it did not have before.
  • the VPN context is distinguishable from a general Internet environment, as the VPN/MPLS overlays and/or supplements Internet connectivity with various transparent security and connectivity measures to provide the VPN environment. Accordingly, methods and operations discussed herein are operable on the Internet, within a private intranet, and over various combinations of public and proprietary networks.
  • the method in order to preserve the original functionality of the LSP ping in a topology with just a single AS, the method adds the address stack at the first ASBR instead of at the originator 140. Accordingly, the LSP ping messages do not need to be changed at all unless an inter-AS situation is encountered.
  • the first ASBR 150 in the path 125 can push on both its address and the address of the originator (originator being the IP source address of the ping).
  • the programs and methods for performing ping operations between ASBRs using LSP routing as defined herein are deliverable to a processing device in many forms, including but not limited to a) information permanently stored on non-writeable storage media such as ROM devices, b) information alterably stored on writeable storage media such as floppy disks, magnetic tapes, CDs, RAM devices, and other magnetic and optical media, or c) information conveyed to a computer through communication media, for example using baseband signaling or broadband signaling techniques, as in an electronic network such as the Internet or telephone modem lines.
  • the operations and methods may be implemented in a software executable object or as a set of instructions embedded in a carrier wave.
  • ASICs Application Specific Integrated Circuits
  • FPGAs Field Programmable Gate Arrays
  • state machines controllers or other hardware components or devices, or a combination of hardware, software, and firmware components.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

A mechanism for ASBRs to identify the originating node, or router, in an LSP conversant autonomous system (AS), such as an MPLS VPN environment, maintains the identity of the originating node and successive nodes in subsequent autonomous systems along the path to the node to be pinged. The identity of the transporting nodes is stored in a stack or other object associated with the ping request (ping), such that the pinged node may employ the stored identity as a set of return path routing information. Successive ASBRs store their identity on the stack, in an ordered manner, along the path to the destination. Upon reaching the destination (ping) node, the destination node employs the identity of the first node on the stack to send the acknowledgment, or ping response.

Description

SYSTEM AND METHODS FOR NETWORK REACHABILITY DETECTION
BACKGROUND
Virtual Private Networks are becoming an increasingly popular mechanism to interconnect multiple remote sites of a common entity, such as a corporation, university, governmental institution, or other enterprise. A VPN allows remote sites to interconnect as if colocated by providing message transport, security, and node addressing. Such a VPN interconnects multiple subnetworks, or local area networks (LANs), of an enterprise such as a corporation, university, or distributor, for example. The subnetworks, in turn, interconnect with each other via a private or public access network such as the Internet, intranets, VPNs and the like.
Such a subnetwork interconnection is typically known as a core network, and includes service providers having a high speed backbone of routers and trunk lines. Each of the subnetworks and the core networks have entry points known as edge routers, through which traffic ingressing and egressing from the network flows. The core network has ingress/egress points handled by nodes known as provider edge (PE) routers, while the subnetworks have ingress/egress points known as customer edge (CE) routers, discussed further in Internet Engineering Task Force (IETF) RFC 2547bis, concerning Virtual Private Networks (VPNs). An interconnection between the subnetworks of a VPN, therefore, typically includes one or more core networks. Each of the core networks is usually one or many autonomous systems (AS), meaning that it employs and enforces a common routing policy among the nodes (routers) included therein. Accordingly, the nodes of the core networks often employ a protocol operable to provide high-volume transport with path based routing, meaning that the protocol not only specifies a destination (as in TCP/IP), Thus, the protocol does not merely specify a destination, as in TCP/IP; it implements an addressing strategy that allows for unique identification of end points, and also allows specification of a particular routing path through the core network. One such protocol is the Multiprotocol Label Switching (MPLS) protocol, defined in Internet Engineering Task Force (IETF) RFC 3031. MPLS is a protocol that combines the label-based forwarding of ATM networks, with the packet-based forwarding of IP networks and then builds applications upon this infrastructure.
Traditional MPLS, and more recently Generalized MPLS (G-MPLS) networks as well, extend the suite of IP protocols to expedite the forwarding scheme used by conventional IP routers, particularly through core networks employed by service providers (as opposed to end-user connections or taps). Routers, to date, have used complex and time-consuming route lookups and address matching schemes to determine the next hop for a received packet, primarily by examining the destination address in the header of the packet. MPLS has greatly simplified this operation by basing the forwarding decision on a simple label. Another major feature of MPLS is its ability to place IP traffic on a particular defined path through the network. Such path specification capability is generally not available with conventional IP traffic. In this way, MPLS provides bandwidth guarantees and other differentiated service features for a specific user application (or flow). Current IP-based MPLS networks are emerging for providing advanced services such as bandwidth-based guaranteed service, priority-based bandwidth allocation, and preemption services.
For each specific service, a table for a forwarding equivalence class (FEC) is created to represent a group of flows with the same traffic-engineering requirements. A specific label is then bound to an FEC. At the ingress of an MPLS network, incoming IP packets are examined and assigned a "label" by a label edge router (LER). The labeled packets are then forwarded along an LSP, where each label-switched router (LSR) makes a switching decision based on the packet's label field. Such LSRs avoid examining the IP headers of the packets to find an output port (next hop). An LSR simply strips off the existing label and applies a new label for the next hop. The label information base (LIB) provides an outgoing label (to be inserted into the packet) and an outgoing interface (based on an incoming label on an incoming interface).
Therefore, MPLS uses a technique called label switching (or swapping or popping) as a means to transport data across a network. The routers within an MPLS network that are responsible for label processing are known as Label Switching Routers (LSRs), and the path , followed by data is known as a Label Switched Path (LSP). Upon entry to an MPLS network, such as from a CE router via a PE router, an MPLS-specific header is inserted at the front of each packet to in effect, re-encapsulate it. The MPLS header contains a stack of labels - one or more - that uniquely identify the switching path between any two LSRs. This label tells adjacent switching nodes how to process and forward the data. As each packet is received by a node, it may push a new label onto the stack of a packet before forwarding it on, pop one from the stack, or swap one or more of the labels with new ones. The path of the packet through the network is defined by its initial labeling. Accordingly, the subsequent mapping of labels is consistent at each node so as to fonn a complete label switched path between the ingress to and the egress from the MPLS network.
Therefore, a Virtual Private Network (VPN) typically employs one or more core networks to interconnect a plurality of local networks, such as LANs, by a VPN service operable to provide transport, routing and security to message traffic between the subnetworks, such that nodes of each sub-LAN can communicate with nodes of other sub- LANs as members of the same VPN. In a typical VPN arrangement, the particular subnetworks may be individual sites of a large business enterprise, such as a bank, retail, or large corporation, having multiple distinct sites each with a substantial subnetwork. A conventional VPN in such an environment is well suited to provide the transparent protection of communication between the subnetworks, such as ensuring protection of transported data via security and encryption, routing policies, and access control among valid users via privileges and access credentials, for example. Message traffic between the VPN subnetworks, therefore, egresses from an originating subnet via a CE router, enters a core network denoting an autonomous system (AS) via a PE router, and traverses one or more AS core networks to a remote PE router, where it enters a remote VPN subnet via a CE router operable to deliver the message traffic to an IP destination.
SUMMARY Virtual Private Networks, or VPNs, therefore, are a popular mechanism for interconnecting remote related sites of an organization or enterprise, including various configurations such as LANs, intranets, extranets, and other interconnection mechanisms employed between multiple related but remote sites to provide secure, seamless interconnection to the organization or enterprise as a whole. A VPN interconnects multiple subnetworks, or local area networks (LANs), of an enterprise such as a corporation, university, or distributor, for example. The subnetworks, in turn, interconnect with each other via a public access network such as the Internet. Such a subnetwork interconnection is typically known as a core network, and includes service providers having a high speed backbone of routers and trunk lines. Note that "routers," as discussed herein, refers to the various types of high-speed data switching devices typically employed in such networks, including but not limited to routers, switches, hubs, bridges and other connectivity devices employing a variety of mediums, such as electronic, optical, cellular, RF or other medium. -A-
Each of the subnetworks and the core networks has entry points known as edge routers, through which traffic ingressing and egressing from the network flows. The core network has ingress/egress points handled by nodes known as provider edge (PE) routers, while the subnetworks have ingress/egress points known as customer edge (CE) routers. Further, the core network may include multiple segments, in which each of the core network segments interconnects with other core network segments, also known as autonomous systems. An Autonomous System (AS) is defined by a common routing policy among the nodes of the AS. Autonomous System Border Routers (ASBRs) define ingress/egress points between one or more Autonomous Systems. The edge routers often employ a specialized protocol particularly operable for serving network to network interconnections- i.e. edge router connections. One such protocol is the Border Gateway Protocol (BGP), for example, which interconnects CE and PE routers at the edge of the core network. In a VPN interconnecting multiple AS segments, certain protocols are often employed to favor such VPN routing. One such protocol is the MPLS protocol. In an MPLS environment, as indicated above, packets are often forwarded using the so-called LSP routing mechanism by employing the path label provided by such networks, by various techniques such as forwarding, autorouting, and static routing, as is known to those of skill in the art. MPLS is typically well suited for service provider core networks or medium to large enterprise networks, rather than end-user connections via a local LAN. Therefore, MPLS is often employed in an inter AS context in the core network. In such a core network, multiple autonomous systems interconnect using routers conversant in label switched routing via LSRs and LERs. LSRs are core devices (i.e. Labeled Switch Routers) that switch packets, and LERs are edge devices (i.e. Labeled Edge Routers) that connect with external networks, determine routes, and add or remove labels. An LSP, therefore, is a concatenation of switch hops that form an end-to-end forwarding path. An LSP starts at an ingress LER, crosses one or more LSRs, and ends at an egress LER.
When a packet arrives at an MPLS network, the ingress LER performs a substantial portion of the work of handling the packet. It examines the IP address of the packet, determines a route, assigns an LSP, and attaches a label. The packet is then forwarded into the LSP, where it is switched across a series of LSRs until it reaches the egress LER. The label is removed and the packet is forwarded on its way via standard IP routing. One particular feature of MPLS is the ability to build virtual paths or circuits across IP networks. These Virtual Connections (VCs) are called label switched paths (LSPs). LSPs are similar to virtual circuits in ATM and frame relay networks in that they define a specific path between two points in a network. Labels are attached to packets, which assist MPLS nodes in forwarding packets along an LSP. The labels are like tracking slips on express
* delivery packages. They contain an index into a forwarding table, which specifies the next hop for the packet. As indicated above, nodes in the core MPLS network need not examine packets and perform next-hop routing tasks. The label carries the information that determines which path a packet should take. Conventional network systems often employ a so-called "Ping" to assess availability of a remote node. A typical ping is a small message sent to the remote node for which reachability status is sought. The message informs the remote node to send a response message, or acknowledgment, back to the sender to indicate the reachability of the remote node. The sending node identifies, based on the response or lack thereof, of the availability of the remote node and any associated subnetworks. Further, other information may be included, such as the latency time of the ping and the path traveled by the ping. In a VPN context, such as a VPN supported by MPLS, a ping may be employed to determine availability of a node or remote subnetwork, such as by pinging the PE router serving the remote VPN subnet. Such messages may also be used to trace the path taken by the LSP. However, as indicated above, an MPLS network often operates as a core network between VPN subnetworks. Such an MPLS network often includes multiple autonomous systems (AS), each operating a particular routing policy. Often, an address of a particular node in an AS may not be recognized outside the AS. For example, in an environment employing labeled switch path routing (LSP), the path defined by such a label is specific to the AS, for traversing the particular AS employing the LSP, and may be known only to labeled switch routers (LSRs) within the particular autonomous system. Message traffic (i.e. packets) are assigned a label from an Autonomous System Border Router (ASBR) upon entering the AS. The assigned label identifies a path through the AS to an egress ASBR on a remote side of the AS. Therefore, the LSP label is not known outside the AS. In a conventional VPN/MPLS environment, a message (packet) traversing multiple autonomous systems is transported between ASBRs at each ingress/egress point. Conventional ASBR routers, therefore, connect to other ASBR routers on the route to the destination. Each intermediate AS transports the packet from the ingress ASBR to the egress ASBR via the assigned label and corresponding LSP, and the egress ASBR transmits the packet to the ingress ASBR at the next AS along the route.
However, pinging in such conventional MPLS systems suffer from several shortcomings. The identity of the ping initiator may not be recognized beyond the originating AS. Traditional MPLS Pings do not span beyond an AS, due to difficulty with propagating an intra-AS address outside it's native AS. Accordingly, such conventional ASBRs employ a Time-To-Live (TTL) attribute or router alert label in Ping messages. The ASBRs set the TTL to 1 hop, indicating that the Ping message is to be terminated before leaving the originating AS. Setting the TTL to 1 ensured that packets did not propagate beyond the originating AS. Therefore, there is not a mechanism to perform a conventional MPLS ping beyond the ASBR. Accordingly, conventional pings cannot span multiple autonomous systems because the conventional ASBRs employing LSP routing cannot provide a return address for outgoing pings to a remote AS, VPN subnet (i.e. CE or PE router), or other destination.
Accordingly, configurations discussed further below substantially overcome the shortcoming of conventional MPLS ping operations by identifying the originating node, or router, in an LSP conversant AS, and maintaining the identity of the originating node and successive nodes in subsequent autonomous systems along the path (route) to the node to be pinged. The identity of the transporting nodes is stored in a stack or other object associated with the ping request (ping), such that the pinged node may employ the stored identity as a set of return addresses, or return path routing information. Successive ASBRs store their identity on the stack, in an ordered manner, along the path to the destination. Upon reaching the destination (ping) node, the destination node employs the identity of the first node on the stack to send the acknowledgment, or ping response. The first node from the stack, upon receiving the ping response, pops (retrieves) the second node from the stack as the node to redirect the ping response to. Each successive ASBR, therefore, pops (retrieves) the next node identity from the stack and redirects (sends) the ping response to the retrieved node. Since the identities of each of the ASBRs are pushed onto the stack in order, and since the ping response travels the same path as the ping (due to the nature of LSP), the identities (addresses) retrieved from the stack are valid LSP addresses according to each respective ASBR on the response path. In further detail, in an autonomous system border router (ASBR), the method of assessing the state of a remote node via a labeled switch path as disclosed herein includes identifying a remote node from which an acknowledging response is requested, in which the remote node corresponds to a path including a sequence of border routers, and storing an entry indicative of an originator node of the acknowledging response request in a response request message. The originator transmits, from the originator node, the response request message to an egress border router included in the path to the remote node. The egress ASBR transmits the response request message to successive border routers on the path to the remote node in an iterative manner, and accumulates, in a nondestructive manner at each successive border router, an entry indicative of the identity of each the successive border routers on the path to the remote node.
In the exemplary arrangement, accumulating entries indicative of successive border routers traversed on the path to the identified remote node includes building a stack of successive edge nodes, in which the stack corresponds to a normalized field in the acknowledgement request message, such as via a protocol specification.
The response request message (i.e. ping) is operable to traverse a plurality of subnetworks defined by border routers indicative of ingress points to the respective subnetwork, each of the subnetworks being an autonomous system having an independent routing policy. At each respective AS subnetwork, a path is defined through each of the subnetworks via a predetermined label, in which the predetermined label is operable to be recognized by the border routers within the respective subnetwork. The accumulated entries are written to a stack and the non- destructive manner avoids overwriting successive accumulated entries such that retrieval of the entries is performable in a reverse order from which they were written. In the stack of return path routing information, the stack has a first address and successive addresses indicative of an ordered set of border nodes traversed by the acknowledgment request. Therefore, the accumulated entries are written to the stack of return path routing infoπnation in an ordered manner indicative of the path.
The destination (pinged) node generates the acknowledgment response, or ping reply, by receiving, at the destination node, the acknowledgment request, building an acknowledgment request response including the stack of return path routing information accumulated in the acknowledgment request, and transmitting the acknowledgment request response to the first return address on the stack. Return transmission further includes forwarding the acknowledgment response back to the originator by retrieving the first address on the stack, such that the return address placed on the stack previous to the first address is the current first return address on the stack, transmitting the acknowledgment response to the retrieved first address, and repeating the retrieval and transmitting for each successive address on the return path routing information stack until the originator receives the acknowledgement response.
The network forwards the acknowledgement response message, in the exemplary configuration, according to forwarding rules, in which the forwarding rules further include transmitting, if an acknowledgment request is received, to the next route toward the ping destination, redirecting, if an acknowledgment response is received, to the next address on the stack, the ping response, and identifying, if the destination cannot be reached, the AS encountering the unreachability condition. Such forwarding rules enable bi-directional logic for handling acknowledgement request and response messages according to a single rule set. For security any privacy, upon encountering an error transmitting one of the acknowledgement request and the acknowledgment response, the receiving router may erase the routing history indicative of its specific portion of the path, such that successive interceptors of the message would be unable to examine the stack indicative of the path. In such cases, it is required that the ASBR still indicate the globally unique AS number, so as to facilitate troubleshooting of the failure condition. Further, in alternate configurations, successive return addresses may be stored by border routers, in which the border routers retain an identity of the previous border router indicative of the last hop in the previous autonomous system traversed by the message.
In particular VPN contexts, multiple paths may exist between a first subnetwork and a second subnetwork (i.e. autonomous systems), and the accumulated addresses are indicative of the path of the acknowledgement request such that the same path is enabled for the acknowledgement response. Otherwise, the request response may be unable to determine the proper AS corresponding to the original request.
Alternate configurations of the invention include a multiprogramming or multiprocessing computerized device such as a workstation, handheld or laptop computer or dedicated computing device or the like configured with software and/or circuitry (e.g., a processor as summarized above) to process any or all of the method operations disclosed herein as embodiments of the invention. Still other embodiments of the invention include software programs such as a Java Virtual Machine and/or an operating system that can operate alone or in conjunction with each other with a multiprocessing computerized device to perform the method embodiment steps and operations summarized above and disclosed in detail below. One such embodiment comprises a computer program product that has a computer-readable medium including computer program logic encoded thereon that, when performed in a multiprocessing computerized device having a coupling of a memory and a processor, programs the processor to perform the operations disclosed herein as embodiments of the invention to carry out data access requests. Such arrangements of the invention are typically provided as software, code and/or other data (e.g., data structures) arranged or encoded on a computer readable medium such as an optical medium (e.g., CD-ROM), floppy or hard disk or other medium such as firmware or microcode in one or more ROM or RAM or PROM chips, field programmable gate arrays (FPGAs) or as an Application Specific Integrated Circuit (ASIC). The software or firmware or other such configurations can be installed onto the computerized device (e.g., during operating system for execution environment installation) to cause the computerized device to perform the techniques explained herein as embodiments of the invention. BRIEF DESCRIPTION OF THE DRAWINGS
The foregoing and other objects, features and advantages of the invention will be apparent from the following more particular description of preferred embodiments of the invention, as illustrated in the accompanying drawings in which like reference characters refer to the same parts throughout the different views. The drawings are not necessarily to scale, emphasis instead being placed upon illustrating the principles of the invention.
Fig. 1 is a context diagram of a network communications environment having a core network including multiple Autonomous Systems (AS) operable for use with the present invention;
Fig. 2 is a flowchart of a ping operation via Labeled Switch Path routing between Autonomous System Border Routers (ASBRs) in a core network as in Fig. 1;
Fig. 3 is a block diagram illustrating the LSP Ping between ASBRs in the exemplary network of Fig. 1; Figs. 4-7 are a flowchart of the LSP Ping between a plurality of autonomous systems in greater detail; and
Fig. 8 is a block diagram of a Labeled Switch Path between two autonomous systems. DETAILED DESCRIPTION
Pinging remote nodes over routes or paths spanning autonomous systems employing LSP routing encounters the issue that the identity of the ping initiator may not be recognized beyond the originating AS. Traditional Pings do not span beyond an AS, due to difficulty with propagating an intra-AS address outside it's native AS. Conventional MPLS ASBRs and other LSRs employ a Time-To-Live (TTL) attribute in conjunction with such Ping messages, typically as part of the MPLS header. Each of the ASBRs set the TTL to 1 or introduce a router alert label, indicating that the ping message is to be intercepted before leaving the originating AS. Setting the TTL to 1 ensured that packets did not propagate beyond the originating AS. Therefore, there is not a mechanism to perform a conventional ping beyond the ASBR. Accordingly, conventional pings cannot span multiple autonomous systems because the conventional ASBRs employing LSP routing cannot provide return path routing information for outgoing pings to a remote AS, VPN subnet (i.e. CE or PE router), or other destination. Configurations discussed herein provide a mechanism for ASBRs to identify the originating node, or router, in an LSP conversant AS, and maintain the identity of the originating node and successive nodes in subsequent autonomous systems along the path (route) to the node to be pinged. The identity of the transporting nodes is stored in a stack or other object associated with the ping request (ping), such that the pinged node may employ the stored identity as a set of return addresses, return path routing information, or other information suitable for identifying the path of the response request message (i.e. ping). Successive ASBRs store their identity on the stack, in an ordered manner, along the path to the destination, such that the collective routing information of nodes traversed enables a reverse traversal to the originating node. Such routing information may be an IP address or other identifier to enable recreation of the path from the pinged recipient back to the originator. Upon reaching the destination (ping) node, the destination node employs the identity of the first node on the stack to send the acknowledgment, or ping response. The first node from the stack, upon receiving the ping response, pops (retrieves) the second node from the stack as the node to redirect the ping response to. Each successive ASBR, therefore, pops (retrieves) the next node identity from the stack and redirects (sends) the ping response to the retrieved node. Since the identities of each of the ASBRs are pushed onto the stack in order, and since the ping response travels the same path as the ping (due to the nature of LSP), the identities (addresses) retrieved from the stack are valid LSP addresses according to each respective ASBR on the response path.
Fig. 1 is a context diagram of a network communications environment having a core network including multiple Autonomous Systems (AS) operable for use with the present invention. Referring to Fig. 1, an exemplary VPN environment 100 includes a plurality of autonomous systems 110-1..110-3 (110, generally) interconnecting remote local LANs, or prefixes 112-1..112-5 (112, generally), for providing VPN connectivity to users (not specifically shown) connected to the LANs 112. The autonomous systems 110 collectively define a core network 150 interconnecting the remote prefixes 112 as such a Virtual Private Network (VPN) environment 100. In the exemplary configuration, the prefixes 112 are typically local LANs supporting a particular corporate, institutional, or enterprise site, for example, and the core network 150 includes the Internet, various intranets, or a combination of both.
In the course of normal routing operations, it is common for a router, or node, to "ping" another node to confirm connectivity or other path status such as delay, jitter, packet loss, etc. Such ping operations, as indicated above, involve sending an acknowledgement request message, or ping, to the node for which status is sought, and receiving an acknowledgment response message, or ping reply, from the pinged node to indicate availability. For example, routing protocols typically employ pings to verify reachability of certain nodes to ascertain availability of various paths and subnetworks available via the pinged node. Further, such pings may be used by a Path Verification Protocol (PVP), discussed further in copending U.S. Patent Application No, 11/001,149 entitled "SYSTEM AND METHODS FOR DETECTING NETWORK FAILURE," filed December 1, 2004 (Atty. Docket No. CIS04-40(10083) assigned to the assignee of the present application and incorporated herein by reference. Other uses for such pings are common and known to those of skill in the art.
As shown in Fig. 1, in routers employing LSP routing, conventional pings cannot span multiple autonomous systems because the path information is local to each respective AS 110. However, the path to the pinged node may traverse a plurality of autonomous systems 110, as a series of hops shown as arrows 122-N, 124-N, for the ping and ping reply, respectively. The LSP ping mechanism, discussed further helow, provides a mechanism for identifying the complete path 125 defined by the set of hops 122, 124, therefore enabling a ping and ping reply between nodes 126 and across multiple autonomous systems 110. In Fig. 1, an acknowledgment request message 132, sent by an originating node 126, follows the series of hops 122-1..122-4 to a destination node 128. The destination node 128, in a positive ping scenario (e.g. pinged node reachable), receives the acknowledgment request 132, and sends an acknowledgment response message 134, back over the same set of hops 124-1..124- 4 defining the path 125 to the originator 126. If the acknowledgment response 134 (i.e. ping reply), denoted by hops 124-1..124-4, fails to reach the originator 126, then the remote "pinged" node 128 is deemed unavailable. Note that the ping originator 126 and destination 128 maybe any router, such as customer or provider edge (CE or PE) routers, autonomous system border routers (ASBRs), carrier's carrier PE or CE or other switching device interconnecting two or more autonomous systems, internal label switch (LSR) routers, or others. In an exemplary configuration, discussed below with respect to Fig. 3, PE routers employ the LSP ping, however alternate configurations may employ the LSP ping other nodes. In the case of a so called "carrier's carrier," the exemplary ASBRs would actually be called CsC-PEs. The difference in such an embodiment is that the return address that is pushed on at a CsC-PE includes an identifier to specify which routing table the address came from. Further, the originating node 126, such as a CE node in a typical LSP ping scenario, may be unaware of the inter- AS nature of the ping recipient 128. Accordingly, the path information retained by the response request 132 is not indicative of an inter- AS scenario until reaching the ASBR egressing from the originating AS.
Fig. 2 is a flowchart of a ping operation via Labeled Switch Path routing between Autonomous System Border Routers (ASBRs) in a core network 150 as in Fig. 1. Referring to Figs. 1 and 2, the method for performing an LSP ping involves assessing the state of a remote node 128 (i.e. the "pinged" router) via a labeled switch path through each respective AS 110. The node originating the ping 126 (originating node) identifies a remote node 128 from which an acknowledging response 134 is requested, in which the remote node 128 corresponds to a path 125 including a sequence of border routers (discussed further below in Fig. 3) through one or more autonomous systems 110, as depicted at step 200. The originating node 126 stores an entry indicative of the address of the originator node 126 of the acknowledging response request in a response request message 132, as depicted at step 201. The originator 126 then transmits, from the originator node (itself), the response request message 132 to a border router included in the path 125 to the remote node 128, such as an ASBR of the AS 110-1 on the path 125 to the remote node 128, as shown at step 202. The ASBR of the AS 110-1, as well as each subsequent border router in the traversed autonomous systems HO-N, transmits the response request message 132 to successive border routers on the path 125 to the remote node 128, according to forwarding rules 152, as depicted at step 203. The method accumulates, in a nondestructive manner at each successive border router, an entry indicative of the identity (i.e. address) of each the successive border routers on the path 134 to the remote node 128, as depicted at step 204, thus building a set of return path routing information operable to be employed for returning a request response message 134. In the exemplary configuration, the set of return path routing information is an ordered stack indicative of the path 125, as will now be described in further detail, however alternate mechanisms for accumulating the identify of the traversed autonomous systems 110 may be performed. Fig. 3 is a block diagram illustrating the LSP Ping between ASBRs in the exemplary network of Fig. 1. Referring to Figs. 1 and 3, router PEl 140 attempts to ping node PE5 142. Router PEl, in AS 110-11, generates an acknowledgment request message 132 including a return address stack 160, for storing the identity of successive routers traversed by the message 132. The stack 160 is shown at various stages of population 160-1..160-N (160, generally), having an ordered set of entries 160-1..160-N (160 generally), discussed further below. PEl stores its identity as an element 162-1 in the return address stack 160-1, and transmits the message 132 to ASBRl 150, the border router to the adjacent AS 110-12. ASBRl 150-1 stores its identity in the next element 162-2 in the stack 160, and forwards the message to ASBR2 150-2, denoting the entry into AS 110-12. Similarly, ASBR2 writes element 162-3 to the stack 160-3, and transmits to ASBR3 150-3, defined as an egress router from AS 110-12, which writes the next return address 162-4 in stack 160-4. ASBR4 150-4 receives the acknowledgment request 132, stores its identity as element 162-5 in the stack 160-5, and sends the message 132 to the destination PE5 142.
Exemplary destination router 142 is operational, and accordingly, generates the acknowledgment response message 134, including the return address stack 160. PE5 142 then pops the first return address 162-5 off the stack 160-5 and employs the value (ASBR4) 150-4 as the first routing hop for the acknowledgment response message 134. Since the routers LSRn and ARBRn are employing a label switch path routing mechanism, as indicated above, IP addresses are not employed to identify the next hop. Rather, the path identity, local within the AS 110, identifies each respective router 150. Accordingly, each successive router 150-1..150-4 on the path 170 pops (retrieves) the next successive return address 162 off the stack 160 as the next hop for the acknowledgment response 134. Upon arrival at ASBRl 150, only the originator 140 return address 162-1 remains on the stack 160, and ASBRl forwards the acknowledgment response 134 to PEl 140, completing the exemplary acknowledgment response indicating a positive (reachable) path from PEl to PE5. Further, additional routing logic, including negative (node unreachable) operation is performable by the ASBR and LSR routers in the event of unreachability of the destination 142, discussed further below. A set of forwarding rules 152 enables routing decisions and logic for directing the messages 132 and 134.
Figs.4-7 are a flowchart of the LSP ping control flow and routing decisions between a plurality of autonomous systems 110 in greater detail in the exemplary network of Fig. 3. Referring to Figs. 3-7, in an exemplary VPN network environment 101 suitable for use with the present invention including multiple autonomous systems 110 interconnected by autonomous system border routers (ASBRs) 150, an originator node 140 assesses the state (i.e. reachability) of a remote node 142 via a series of labeled switch paths through autonomous systems 110. The originator 140 identifies the remote node 142 from which an acknowledging response (i.e. ping reply) is requested, in which the remote node corresponds to a path 170 including a sequence of border routers 150- L.150-4 (150, generally), as depicted at step 300. It should be noted that the path 170 includes the series of LSPs through each of the respective AS encountered between the originator 140 and destination 142, since, as indicated above, each particular LSP assigned by an ASBR does not persist beyond the assigning AS.
The originating node 140 stores an entry PEl as entry 162-1 in the stack 160-1 indicative of the originator (itself) 140 of the acknowledgment response request message 132, as disclosed at step 201. In the exemplary configuration disclosed, the entry is a return address stack 160 stored in the message 132, and the stored entry 162-1 yields the return address PEL The originating node 140 then transmits, from the originator node 140, the response request message 132 to a border router 150-1 included in the path 170 to the remote node 142, as shown at step 302. As indicated above, the ASBR 150-nodes are LSP routers and employ a label to identify a specific path to the next ASBR 150. Accordingly, the path 170 is defined through each of the subnetworks, or autonomous systems 110, via a predetermined label, or labeled switch path, in which the predetermined label is operable to be recognized by the border routers 150 within the respective subnetwork 110, as depicted at step 303. The border router ASBRl 150-1 therefore receives the response request message 132 including the return address stack 160-1.
At each of the successive border routers 150-2, 150-3 and 150-4 in the exemplary network, the ASBRs 150 accumulate, in a nondestructive manner, an entry 162 indicative of the identity of each the successive border routers 150 on the path 170 to the remote node 142, as shown at step 304. In the exemplary configuration discussed herein, the set of accumulated entries 162 is stored as a stack 160 to facilitate redirection of the response 134 back along the path 125. Such accumulation of entries 162 indicative of successive border routers 150 traversed on the path 170 to the identified remote node 142 further includes building the stack 160 of successive edge nodes 150, in which the stack 160 corresponds to a normalized field in the acknowledgement request message 132, as depicted at step 305. Each of the ASBRs 150 stores the accumulated entries 162 as a stack of return address 160-N, in which the stack has a first address (i.e. the originator PEl) and successive addressees indicative of the ordered set of border routers 150 traversed by the response request 132, in which each node 150 (e.g. router) writes its identity to the next element 162 on the stack 160, as shown at step 306. As each ASBR 150 accumulates the entries 162 by writing the entries to the stack 160, the non destructive manner avoids overwriting successive accumulated entries 162-N such that retrieval of the entries is performable in a reverse order from which they were written, as depicted at step 307. Therefore, ASBRl writes entry 162-2, building the return address stack shown atl60-2, ASBR2 writes entry 162-3, shown as stack 160-3, ASBR3 writes entry 162-4, shown as stack 160-4, and ASBR4 pushes entry 162-5, shown as return address stack 160-5, therefore transmitting the response request message 132 to each of the successive border routers 150 on the path 170 to the remote node 142, as disclosed at step 308. In the particular exemplary configuration, an alert flag such as the above described TTL field is set to ensure examination by successive border routers (ASBRs). At each AS 110 traversed, a check is performed to determine if another AS is to be traversed to reach the destination node 142, as depicted at step 309. Accordingly, if there are more border routers 150 to traverse, then the acknowledgment request message 132 is passed to the next ASBR 150, thus continuing to traverse the plurality of subnetworks 110 defined by border routers 150 indicative of ingress points to the respective subnetwork 110, in which each of the subnetworks is an autonomous system having an independent routing policy, as shown at step 310, and control iterates to step 304 accordingly. Further, in alternate configurations, successive return addresses are stored by the border routers 150, such that the border routers 150 retain an identity of the previous border router 150 indicative of the last hop in the previous autonomous system traversed by the message, rather than or in addition to retaining the stack 160 and return address entries 162-N in the response request message 132. Upon ingress into the last AS 110-13 on the path 170, the destination node 142 receives the acknowledgment request message 132, and builds an acknowledgment request response 134 including the stack 160 of return path routing information 162 accumulated in the acknowledgment (response) request 132; as depicted at step 311. It should be noted that, as will be discussed further below, if the response request 132 cannot be routed to the ping destination 142, thus indicating unreachability of the destination "ping" node 142, the ASBR 150 encountering unreachability identifies an error in routing, thus indicating a nonresponsive ping.
In the positive ping scenario (i.e. pinged node is reachable), the destination 142 forwards the recently generated request response 134, or acknowledgment response, to the originator 140, as disclosed at step 312. Accordingly, the originator 142 retrieves the first address 162-5 on the stack 160-5, such that the return address 162-N placed on the stack previous 162-(N-I) to the first address is the current first return address on the stack (i.e. a "pop" operation, as is known in the art), as shown at step 312. PE5 142 then transmits the acknowledgment request response 134 to the first (i.e. "popped") return address ASBR4 from the stack 160-5, as depicted at step 313. Similar to the response request 132, the acknowledgment response 134 causes the
ASBRs 150 to repeat the retrieval and transmitting for each successive address 162 on the return address stack 160 until the originator 140 receives the acknowledgement response 134, as depicted at step 314. In particular configurations, at each successive border router 150, forwarding occurs according to forwarding rules, as depicted at step 315, in which the forwarding rules 152 further include a bi-directional analysis of the response request 132 or acknowledgment response 134, as the case may be. The forwarding rules 152 analyze the messages 132, 134 and direct the ASBR 150 to transmit, if an acknowledgment request 132 is received, to the next route toward the ping destination 142, as shown at step 316; to redirect, if an acknowledgment response 134 is received, to the next address 162 on the stack 160, the ping response 134, as shown at step 317; and to identify, if the destination cannot be reached, the AS 110 or ASBR 150 encountering the unreachability condition, as depicted at step 318.
A check is performed, at step 319, to determine if an error is encountered by an ASBR 150 in routing (forwarding or redirecting) the request/response message 132/134, as disclosed at step 319. If an ASBR 150 encounters an error transmitting one of the acknowledgement request 132 and the acknowledgment response 134, the ASBR erases a routing history indicative of the path 170, therefore avoiding dissemination of security sensitive routing/path information, as shown at step 320.
For such LSP failure cases, it is often the case that MPLS is not enabled on a router, or the label is missing, etc. In operation, it may be the case that the router with the failure could not just fast switch the labeled packet and would be forced to "look at" (i.e. examine) the message due to the error condition. This "failure" router could be any type of router including PE, LSR or ASBR. Accordingly, if the stack of ASBR addresses that we have constructed is present on the request, then the "failing" router replies to the first ASBR address on our list, even though it might not itself be an ASBR. At step 321, a check is performed to determine if multiple routing paths exist to an
ASBR address 162 retrieved from the stack 160. If multiple paths exist between a first subnetwork 110-A and a second subnetwork HO-B, the accumulated addresses 162 are indicative of the path 170 of the acknowledgement request 132 such that the same path is enabled for the acknowledgement response 134, as depicted at step 322. Therefore, the return address stack 160 overrides routing table or other information indicative of an alternative path from a particular ASBR 150. Further, a LSP route is typically indicative of a particular path to an ASBR from within the ASBR, and therefore avoids forwarding to an ASBR which represents an alternate path.
Further, in particular configurations, when a LSP Ping encounters such a multipath situation, the receiving routers interoperate with an already existing equal-cost multipath (ECMP) tree trace. Configurations disclosed herein interoperate by 1) preserving the original IP source address or other structures such as address/path hashing, with respect to the multipath acknowledgement request message even across AS boundaries, and 2) Not modifying/destroying any of the existing structures of the LSP ping (such as the downstream mapping object). However, private address information may need be removed from downstream mapping, so it may have to be modified non-destructively. As with the transport of the response request 132, a check is performed to determine if there are additional border routers 150 to traverse on the path 170 to the originator node 140, as shown at step 323. If so, then control reverts to step 314 to transport the acknowledgment response 134 back to the originating node 140, using successively popped return addresses 162 from the return address stack 160 which collectively define the path 170 including the LSP routes through each AS 110.
Fig. 8 is a block diagram of an alternate router configuration illustrative of other aspects of the LSP ping operation. Referring to Figs. 3 and 8, an exemplary routing sequence including customer edge routers (CE), provider edge routers (PE), provider routers (P), such as LSR routers, and ASBR routers. Stack 162 progression is shown via an LSP ping, or acknowledgment request message, between PE routers showing the stack 162 at increments 162-11..162-17. As indicated above, the ASBRs 150 pop the last address on the stack 162 to retain the path for the subsequent request response (ack) message. The intermediate (P) routers replace the last entry with their own. The first pop occurs at 162-13 with respect to label 11. The second pop occurs at 162-17 with respect to label 13. Accordingly, the diagram indicates that the ASBRs and PE receive the inner label only (i.e. that has TTL or other alert flag set to 1).
Fig. 8 illustrates the label stack 162 that is being sent for the packets between each router. Notice that some have 2 labels. Labels are in a stack 162, so between PE and P there are actually 2 labels on each packet. In the initial stack 162-11 from the originating PE, Label 10 is at the top of the stack above label 20. Notice there is no label between CE and PE. The LSP for this network actually goes from PE to PE, thus illustrating differences in employing the address stack in conjunction with LSP ping, rather than an IP ping. In this particular arrangement, the LSP ping traverses from PE to PE, not CE to CE (standard IP ping goes from CE to CE).
In accordance with typical LSP routing, labeled packets are fast switched though routers. Accordingly, unless something "happens" to the packet, it merely traverses through the network without scrutiny. In the exemplary LSP Ping scenario, if we blindly send a labeled acknowledgement request packet, it would be fast switched all the way to the CE where it would be dropped. To force it to be "looked at" (i.e. scrutinized by an ASBR), some kind of router alert is introduced. As indicated above, the TTL value is employed accordingly to trigger responsiveness to the LSP Ping messages. Similar to IP packets, each label has a TTL value. So for the packets between PE and P, there are actually 3 separate TTL values. One for the underlying IP packet, one for label 20 and one for label 10. Only the outer-most TTL is ever decremented at each hop (the one for label 10 in this case). To make the packet get "looked at" by an ASBR, we set the TTL value for the inner label (label 20) to a value of 1. So what happens is that an ASBR is the first router to ever see an outer label of 20. This label had its TTL set to 1 at the originator, so the packet will "TTL expire" at the ASBR. When the expiry happens, the ASBR 150 actually "looks at" the packet and notices that it is LSP ping. It then adds its own address to the stack and can restore it back onto the LSP. In doing so, it sets the inner most label TTL to 1 (now its a new label 30) so that the request will expire at the successive ASBR and the process continues. Accordingly, the acknowledgement request may not appear seamlessly sent from one ASBR 150 to the next ASBR, but rather is interrupted in its travel across the whole path 125 by such forced TTL expiries at each ASBR. Therefore, each ASBR sets the TTL (or some other mechanism like the special router alert label) in such a way that it gets "looked at" (interrupted) by the next ASBR or the final destination. Note that such processing does not apply to the reply message; routers will send these ASBR-to-ASBR via the stack that the acknowledgment request message 132 generated.
It is often mentioned above about the stack of ASBRs stored as a list of addresses. However, such a stack may be construed as reachability information, or other type of return path routing information, in alternate implementations. In particular configurations, an IP or LSP address may be augmented with, for example, a route distinguisher or some other mechanism to specify which VPN the address came from. On aspect of this approach is that when the response 134 comes back to an ASBR 150, it has sufficient information to get the response back to the next ASBR 150 (or the originator 140). In a typical exemplary VPN, it may be an observed practice that the P routers should always be hidden to any outside AS. In many cases PEs should be as well. ASBRs are normally "publicly" known however. Alternatively, ASBRs may be known only by their directly neighboring AS. So as an acknowledgement reply is returned to each ASBR, the ASBR may remove all information about P and PE routers, as discussed above. Further, the stack 162 may also maintain a list of the ASBRs 150-N that the reply 134 has passed through so when the reply 134 reaches the originator 140, it has exactly the path of ASBRs 150 that the ping reached.
Such visibility is often known as a "peering" between routers. Normally the peering is a private peering so the ASBRs 150 are known between the two peering entities. Such an approach may trigger security implications in particular configurations. However, the sender may not have a peering agreement with the receiver and in this case we should not divulge any IP information to the sender. Configurations discussed herein, therefore, maintain such information within the transiting AS so that the end-to-end path can be determined.
In further detail regarding peering, in particular arrangement, for the two networks that are peering, the ASBR is known between the two entities, hence even in private peering ASBRs are well known to the routers in the network because the Border Gateway Protocol (BGP) next hop is advertised. Accordingly, the designation "publicly known" is relevant to the two networks in question. Such unknown PEs may be taken to imply that no PE loopbacks are leaked. A distinction should be made between a VPN context and the Internet at large. Public means "Internet" to most observers. However, it may not be sufficient to assume that only 2 AS's are involved. Take a topology such as A - B - C, for example. Public generally means that A knows the addresses of B and C, as they would typically be advertised. Private means that A only knows about B but may learn information about C via B. For example, in the case where you have A - B - C, A,B&C are AS's. In this case, any destinations reachable via C are known to A as being reachable via B. A does not know anything about Cs addresses. However, if you put that IP information within the LSP-ping return then A now has this information which it did not have before. In the exemplary configurations herein, the VPN context is distinguishable from a general Internet environment, as the VPN/MPLS overlays and/or supplements Internet connectivity with various transparent security and connectivity measures to provide the VPN environment. Accordingly, methods and operations discussed herein are operable on the Internet, within a private intranet, and over various combinations of public and proprietary networks.
In particular configurations, in order to preserve the original functionality of the LSP ping in a topology with just a single AS, the method adds the address stack at the first ASBR instead of at the originator 140. Accordingly, the LSP ping messages do not need to be changed at all unless an inter-AS situation is encountered. The first ASBR 150 in the path 125 can push on both its address and the address of the originator (originator being the IP source address of the ping). Those skilled in the art should readily appreciate that the programs and methods for performing ping operations between ASBRs using LSP routing as defined herein are deliverable to a processing device in many forms, including but not limited to a) information permanently stored on non-writeable storage media such as ROM devices, b) information alterably stored on writeable storage media such as floppy disks, magnetic tapes, CDs, RAM devices, and other magnetic and optical media, or c) information conveyed to a computer through communication media, for example using baseband signaling or broadband signaling techniques, as in an electronic network such as the Internet or telephone modem lines. The operations and methods may be implemented in a software executable object or as a set of instructions embedded in a carrier wave. Alternatively, the operations and methods disclosed herein may be embodied in whole or in part using hardware components, such as Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), state machines, controllers or other hardware components or devices, or a combination of hardware, software, and firmware components.
While the system and method for performing ping operations between ASBRs using LSP routing has been particularly shown and described with references to embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the scope of the invention encompassed by the appended claims. Accordingly, the present invention is not intended to be limited except by the following claims.

Claims

CLAIMS What is claimed is:
1. In an autonomous system border router (ASBR), a method of assessing the state of a remote node via a labeled switch path comprising: identifying a remote node from which an acknowledging response is requested, the remote node corresponding to a path including a sequence of border routers; storing an entry indicative of an originator node of the acknowledging response request in a response request message; transmitting, from the originator node, the response request message to a border router included in the path to the remote node; transmitting the response request message to successive border routers on the path to the remote node; and accumulating, in a nondestructive manner at each successive border router, an entry indicative of the identity of each the successive border routers on the path to the remote node.
2. The method of claim 1 wherein accumulating entries indicative of successive border routers .traversed on the path to the identified remote node further comprises building a stack of successive edge nodes, the stack corresponding to a normalized field in the acknowledgement request message.
3. The method of claim 2 further comprising traversing a plurality of subnetworks defined by border routers indicative of ingress points to the respective subnetwork, each of the subnetworks being an autonomous system having an independent routing policy.
4. The method of claim 3 wherein the path is defined through each of the subnetworks via a predetermined label, the predetermined label operable to be recognized by the border routers within the respective subnetwork.
5. The method of claim 4 wherein the accumulated entries are written to a stack and the non destructive manner avoids overwriting successive accumulated entries such that retrieval of the entries is performable in a reverse order from which they were written.
6. The method of claim 1 further comprising storing the accumulated entries as a stack of return address, the stack having a first address and successive addressees indicative of an ordered set of border nodes traversed by the acknowledgment request.
7. The method of claim 6 wherein the accumulated entries are written to the stack of return path routing information in an ordered manner indicative of the path, further comprising: receiving, at the destination node, the acknowledgment request; building an acknowledgment request response including the stack of return path routing information accumulated in the acknowledgment request; and transmitting the acknowledgment request response to the first return address on the stack.
8. The method of claim 7 further comprising forwarding the acknowledgment response to the originator, forwarding further comprising: retrieving the first address on the stack, such that the return address placed on the stack previous to the first address is the current first return address on the stack; transmitting the acknowledgment response to the retrieved first address; and repeating the retrieval and transmitting for each successive address on the return address stack until the originator receives the acknowledgement response.
9. The method of claim 8 wherein the forwarding occurs according to forwarding rules, the forwarding rules further including: transmitting, if an acknowledgment request is received, to the next route toward the ping destination; redirecting, if an acknowledgment response is received, to the next address on the stack, the ping response; and identifying, if the destination cannot be reached, the AS encountering the unreachability condition.
10. The method of claim 9 further comprising, upon traversing an AS, transmitting one of the acknowledgement request and the acknowledgment response, erasing a routing history indicative of the path; and selectively, if an error condition is encountered, sending the response request to last address on stack.
11. The method of claim 10 wherein multiple paths exist between a first subnetwork and a second subnetwork, and the accumulated addresses are indicative of the path of the acknowledgement request such that the same path is enabled for the acknowledgement response.
12. The method of claim 11 wherein successive return path routing information are stored by border routers, the border routers retaining an identity of the previous border router indicative of the last hop in the previous autonomous system traversed by the message.
13. A data communications device for performing ping operations between ASBRs using LSP routing comprising: a network interface operable to identify a remote node from which an acknowledging response is requested, the remote node corresponding to a path including a sequence of border routers; a return address stack operable to store an entry indicative of an originator node of the acknowledging response request in a response request message; forwarding rules operable to transmit, from the originator node, the response request message to a border router included in the path to the remote node, the forwarding rules further operable to transmit the response request message to successive border routers on the path to the remote node; and a routing processor operable to accumulate, in a nondestructive manner at each successive border router, a return address stack entry indicative of the identity of each the successive border routers on the path to the remote node.
14. The method of claim 13 wherein the return address stack is operable to accumulate entries indicative of successive border routers traversed on the path to the identified remote node fUrther comprises building a stack of successive edge nodes, the stack corresponding to a normalized field in the acknowledgement request message.
15. The method of claim 14 wherein the network interface couples a plurality of subnetworks defined by border routers indicative of ingress points to the respective subnetwork, each of the subnetworks being an autonomous system having an independent routing policy.
16. The method of claim 15 wherein the path is defined through each of the subnetworks via a predetermined label, the predetermined label operable to be recognized by the border routers within the respective subnetwork.
17. The method of claim 16 wherein the return address stack is operable to accumulate entries in a non destructive manner which avoids overwriting successive accumulated entries such that retrieval of the entries is performable in a reverse order from which they were written.
18. The method of claim 13 wherein the router processor is operable to store the accumulated entries as a stack of return address, the stack having a first address and successive addressees indicative of an ordered set of border nodes traversed by the acknowledgment request.
19. The method of claim 18 wherein the accumulated entries are written to the stack of return path routing information in an ordered manner indicative of the path, the destination node further operable to: receive, at the destination node, the acknowledgment request; build an acknowledgment request response including the stack of return path routing information accumulated in the acknowledgment request; and transmit the acknowledgment request response to the first return address on the stack.
20. The method of claim 19 wherein the receiver further comprises forwarding rules, the forwarding rules operable to forward the acknowledgment response to the originator by: retrieving the first address on the stack, such that the return address placed on the stack previous to the first address is the current first return address on the stack; transmitting the acknowledgment response to the retrieved first address; and repeating the retrieval and transmitting for each successive address on the return address stack until the originator receives the acknowledgement response.
21. The method of claim 20 wherein the forwarding rules are further operable to direct the routing processor to: transmit, if an acknowledgment request is received, to the next route toward the ping destination; redirect, if an acknowledgment response is received, to the next address on the stack, the ping response; and identify, if the destination cannot be reached, the AS encountering the unreachability condition.
22. The method of claim 18 wherein the stack is operable to preserve the original IP source address of the acknowledgement request message across AS boundaries, and further operable to avoid modification of existing structures of the LSP ping routing history.
23. The method of claim 22 further comprising maintaining a list of the ASBRs that the reply has passed through such that the acknowledgment response message delivers to the originator the path of ASBRs that the response request message reached.
24. The method of claim 18 further comprising setting, by each ASBR traversed by the acknowledgment request message, a router alert label, operable for triggering an interrupt response and examination by at least one of successive ASBRs and the destination, such that label switch routing avoids ignoring the acknowledgment request message.
25. The method of claim 24 further comprising appending additional routing identifiers corresponding to the return addresses operable to identify an appropriate routing table for routing the acknowledgement response message.
26. A computer program product having a computer readable medium operable to store computer program logic embodied in computer program code encoded thereon for assessing the state of a remote node via a labeled switch path comprising: computer program code for identifying a remote node from which an acknowledging response is requested, the remote node corresponding to a path including a sequence of border routers; computer program code for storing an entry indicative of an originator node of the acknowledging response request in a response request message; computer program code for transmitting, from the originator node, the response request message to a border router included in the path to the remote node; computer program code for transmitting the response request message to successive border routers on the path to the remote node; and computer program code for accumulating, in a nondestructive manner at each successive border router, an entry indicative of the identity of each the successive border routers on the path to the remote node; computer program code for accumulating entries indicative of successive border routers by building a stack of successive edge nodes, the stack corresponding to a normalized field in the acknowledgement request message; computer program code for receiving, at the destination node, the acknowledgment request; computer program code for building an acknowledgment request response including the stack of return path routing information accumulated in the acknowledgment request; and computer program code for transmitting the acknowledgment request response to the first return address on the stack.
27. A data communications device for performing ping operations between ASBRs using LSP routing comprising: means for identifying a remote node from which an acknowledging response is requested, the remote node corresponding to a path including a sequence of border routers; means for storing an entry indicative of an originator node of the acknowledging response request in a response request message; means for transmitting, from the originator node, the response request message to a border router included in the path to the remote node; means for transmitting the response request message to successive border routers on the path to the remote node; accumulating, in a nondestructive manner at each successive border router, an entry indicative of the identity of each the successive border routers on the path to the remote node; means for coupling to a plurality of subnetworks defined by border routers indicative of ingress points to the respective subnetwork, each of the subnetworks being an autonomous system having an independent routing policy; means for forwarding to the plurality of subnetworks, the forwarding occurring according to forwarding rules, the forwarding rules further including: transmitting, if an acknowledgment request is received, to the next route toward the ping destination; redirecting, if an acknowledgment response is received, to the next address on the stack, the ping response; and identifying, if the destination cannot be reached, the AS encountering the unreachability condition.
PCT/US2006/007722 2005-03-04 2006-03-03 System and methods for network reachability detection WO2006096560A2 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP06736961.1A EP1856862B1 (en) 2005-03-04 2006-03-03 System and method for network reachability detection
CN200680004044.5A CN101124785B (en) 2005-03-04 2006-03-03 System and methods for network reachability detection

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US11/072,082 US7990888B2 (en) 2005-03-04 2005-03-04 System and methods for network reachability detection
US11/072,082 2005-03-04

Publications (2)

Publication Number Publication Date
WO2006096560A2 true WO2006096560A2 (en) 2006-09-14
WO2006096560A3 WO2006096560A3 (en) 2007-10-04

Family

ID=36944049

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2006/007722 WO2006096560A2 (en) 2005-03-04 2006-03-03 System and methods for network reachability detection

Country Status (4)

Country Link
US (1) US7990888B2 (en)
EP (1) EP1856862B1 (en)
CN (1) CN101124785B (en)
WO (1) WO2006096560A2 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102857418A (en) * 2012-08-30 2013-01-02 杭州华三通信技术有限公司 VPN (virtual private network)-based fast re-route (FRR) switch method and VPN-based fast re-route switch equipment
WO2020135190A1 (en) * 2018-12-28 2020-07-02 华为技术有限公司 Secure route identification method and device

Families Citing this family (88)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7463591B1 (en) * 2001-06-25 2008-12-09 Juniper Networks, Inc. Detecting data plane liveliness of a label-switched path
US9154402B2 (en) * 2005-07-08 2015-10-06 At&T Intellectual Property Ii, L.P. Method and system for gateway selection in inter-region communication on IP networks
JP4732874B2 (en) * 2005-11-28 2011-07-27 株式会社エヌ・ティ・ティ・ドコモ Software behavior modeling device, software behavior monitoring device, software behavior modeling method, and software behavior monitoring method
US7912934B1 (en) 2006-01-09 2011-03-22 Cisco Technology, Inc. Methods and apparatus for scheduling network probes
US7889655B2 (en) * 2006-01-17 2011-02-15 Cisco Technology, Inc. Techniques for detecting loop-free paths that cross routing information boundaries
US7852778B1 (en) * 2006-01-30 2010-12-14 Juniper Networks, Inc. Verification of network paths using two or more connectivity protocols
US7619990B2 (en) * 2006-06-30 2009-11-17 Alcatel-Lucent Usa Inc. Two tiered packet labeling for data network traceback
US8848711B1 (en) 2006-08-04 2014-09-30 Brixham Solutions Ltd. Global IP-based service-oriented network architecture
US7609672B2 (en) * 2006-08-29 2009-10-27 Cisco Technology, Inc. Method and apparatus for automatic sub-division of areas that flood routing information
US7899005B2 (en) * 2006-09-12 2011-03-01 Cisco Technology, Inc. Method and apparatus for passing routing information among mobile routers
FR2906426A1 (en) * 2006-09-25 2008-03-28 France Telecom SYSTEM FOR SECURING ACCESS TO A DESTINATION OF A VIRTUAL PRIVATE NETWORK
US7746796B2 (en) * 2006-09-29 2010-06-29 Cisco Technology, Inc. Directed echo requests and reverse traceroute
US8009591B2 (en) * 2006-11-30 2011-08-30 Cisco Technology, Inc. Automatic overlapping areas that flood routing information
US8116227B1 (en) 2006-12-20 2012-02-14 Cisco Technology, Inc. Optimal automated exploration of hierarchical multiprotocol label switching label switch paths
WO2008114007A1 (en) * 2007-03-22 2008-09-25 British Telecommunications Public Limited Company Data communication method and apparatus
US7940695B1 (en) * 2007-06-08 2011-05-10 Juniper Networks, Inc. Failure detection for tunneled label-switched paths
US7936732B2 (en) * 2007-09-27 2011-05-03 Cisco Technology, Inc. Selecting aggregation nodes in a network
US8355347B2 (en) * 2007-12-19 2013-01-15 Cisco Technology, Inc. Creating multipoint-to-multipoint MPLS trees in an inter-domain environment
US9338083B2 (en) 2007-12-28 2016-05-10 At&T Intellectual Property I, Lp ECMP path tracing in an MPLS enabled network
US7808919B2 (en) * 2008-03-18 2010-10-05 Cisco Technology, Inc. Network monitoring using a proxy
US8559334B2 (en) * 2008-03-28 2013-10-15 Telefonaktiebolaget L M Ericsson (Publ) End-to end inter-domain routing
US8804718B2 (en) * 2008-04-23 2014-08-12 Cisco Technology, Inc. Preventing traffic flooding to the root of a multi-point to multi-point label-switched path tree with no receivers
US7779123B2 (en) * 2008-06-13 2010-08-17 International Business Machines Corporation System and method for building network model in network management application
US7937492B1 (en) * 2008-09-30 2011-05-03 Juniper Networks, Inc. LSP ping and traceroute for bypass tunnels
US8798045B1 (en) 2008-12-29 2014-08-05 Juniper Networks, Inc. Control plane architecture for switch fabrics
US8391163B2 (en) 2009-03-23 2013-03-05 Cisco Technology, Inc. Operating MPLS label switched paths and MPLS pseudowire in loopback mode
US8374095B2 (en) 2009-03-23 2013-02-12 Cisco Technology, Inc. Connection verification for MPLS label switched paths and pseudowires
CN101651582B (en) * 2009-09-24 2011-12-07 中兴通讯股份有限公司 Method and system for detecting link connectivity of multi-protocol label switching (MPLS) network
US8630297B2 (en) * 2010-02-08 2014-01-14 Force10 Networks, Inc. Method and apparatus for the distribution of network traffic
US8611251B2 (en) * 2010-02-08 2013-12-17 Force10 Networks, Inc. Method and apparatus for the distribution of network traffic
US8467289B2 (en) * 2010-02-22 2013-06-18 Telefonaktiebolaget L M Ericsson (Publ) Optimized fast re-route in MPLS ring topologies
US8406243B2 (en) * 2010-02-22 2013-03-26 Telefonaktiebolaget L M Ericsson (Publ) Fast LSP alert mechanism
US8694654B1 (en) 2010-03-23 2014-04-08 Juniper Networks, Inc. Host side protocols for use with distributed control plane of a switch
US8718063B2 (en) 2010-07-26 2014-05-06 Juniper Networks, Inc. Methods and apparatus related to route selection within a network
US8339973B1 (en) 2010-09-07 2012-12-25 Juniper Networks, Inc. Multicast traceroute over MPLS/BGP IP multicast VPN
US8560660B2 (en) 2010-12-15 2013-10-15 Juniper Networks, Inc. Methods and apparatus for managing next hop identifiers in a distributed switch fabric system
US9282060B2 (en) 2010-12-15 2016-03-08 Juniper Networks, Inc. Methods and apparatus for dynamic resource management within a distributed control plane of a switch
US9106527B1 (en) 2010-12-22 2015-08-11 Juniper Networks, Inc. Hierarchical resource groups for providing segregated management access to a distributed switch
US9391796B1 (en) 2010-12-22 2016-07-12 Juniper Networks, Inc. Methods and apparatus for using border gateway protocol (BGP) for converged fibre channel (FC) control plane
HUE024948T2 (en) 2011-02-19 2016-01-28 Deutsche Telekom Ag Cutting mpls paths at forwarding level for connectionless mpls networks
CN102882906A (en) * 2011-07-14 2013-01-16 华为技术有限公司 Method and device of data communication in constrained application protocol
US8717909B1 (en) * 2011-08-03 2014-05-06 Juniper Networks, Inc. Methods and apparatus for route installation acknowledgement and acknowledgement aggregation in BGP
US8630291B2 (en) 2011-08-22 2014-01-14 Cisco Technology, Inc. Dynamic multi-path forwarding for shared-media communication networks
CN102957573B (en) * 2011-08-24 2017-05-17 中兴通讯股份有限公司 Path detection realizing method and node
US9013983B2 (en) 2011-09-12 2015-04-21 Cisco Technology, Inc. Proactive source-based reverse path validation in computer networks
US8862774B2 (en) 2011-09-12 2014-10-14 Cisco Technology, Inc. Dynamic keepalive parameters for reverse path validation in computer networks
US9565159B2 (en) 2011-12-21 2017-02-07 Juniper Networks, Inc. Methods and apparatus for a distributed fibre channel control plane
US8902780B1 (en) 2012-09-26 2014-12-02 Juniper Networks, Inc. Forwarding detection for point-to-multipoint label switched paths
US9258234B1 (en) 2012-12-28 2016-02-09 Juniper Networks, Inc. Dynamically adjusting liveliness detection intervals for periodic network communications
US8953460B1 (en) 2012-12-31 2015-02-10 Juniper Networks, Inc. Network liveliness detection using session-external communications
CN104009918B (en) 2013-02-22 2018-03-27 华为技术有限公司 A kind of service message processing method, apparatus and system
CN104219147B (en) * 2013-06-05 2018-10-16 中兴通讯股份有限公司 The VPN of edge device realizes processing method and processing device
US9319451B2 (en) 2013-07-15 2016-04-19 Google Inc. Systems and methods for selecting an accounting technique for interactions with electronic content
US9083676B2 (en) * 2013-07-15 2015-07-14 Google Inc. Systems and methods for reliably using ping to account for interactions with electronic content
US10708182B2 (en) * 2013-07-26 2020-07-07 Cisco Technology, Inc. MPLS LSP connectivity test when the initiator address is unknown
US9577845B2 (en) 2013-09-04 2017-02-21 Nicira, Inc. Multiple active L3 gateways for logical networks
US9769068B2 (en) 2013-09-30 2017-09-19 Cisco Technology, Inc. Virtual LDP session
US9225597B2 (en) 2014-03-14 2015-12-29 Nicira, Inc. Managed gateways peering with external router to attract ingress packets
US9590901B2 (en) 2014-03-14 2017-03-07 Nicira, Inc. Route advertisement by managed gateways
CN114726786B (en) * 2014-03-14 2024-06-21 Nicira股份有限公司 Route advertisement for managed gateways
WO2015168948A1 (en) * 2014-05-09 2015-11-12 华为技术有限公司 Path detecting method and communication node
CN104168157B (en) * 2014-08-14 2017-05-03 中国联合网络通信集团有限公司 Network connectivity detection method and device
US9769017B1 (en) 2014-09-26 2017-09-19 Juniper Networks, Inc. Impending control plane disruption indication using forwarding plane liveliness detection protocols
CN104468349B (en) * 2014-11-27 2017-11-14 中国科学院计算机网络信息中心 A kind of BGP routing authentication methods based on hop-by-hop supervision
CN104518960B (en) * 2014-12-05 2018-01-19 华为技术有限公司 A kind of method, equipment and the system of the switchback that is delayed
US9313154B1 (en) 2015-03-25 2016-04-12 Snapchat, Inc. Message queues for rapid re-hosting of client devices
US10038628B2 (en) 2015-04-04 2018-07-31 Nicira, Inc. Route server mode for dynamic routing between logical and physical networks
US10243848B2 (en) 2015-06-27 2019-03-26 Nicira, Inc. Provisioning logical entities in a multi-datacenter environment
US9992056B2 (en) * 2015-10-20 2018-06-05 Cisco Technology, Inc. Triggered in-band operations, administration, and maintenance in a network environment
US10374936B2 (en) 2015-12-30 2019-08-06 Juniper Networks, Inc. Reducing false alarms when using network keep-alive messages
US10333849B2 (en) 2016-04-28 2019-06-25 Nicira, Inc. Automatic configuration of logical routers on edge nodes
US10091161B2 (en) 2016-04-30 2018-10-02 Nicira, Inc. Assignment of router ID for logical routers
US10560320B2 (en) 2016-06-29 2020-02-11 Nicira, Inc. Ranking of gateways in cluster
US10397085B1 (en) 2016-06-30 2019-08-27 Juniper Networks, Inc. Offloading heartbeat responses message processing to a kernel of a network device
US10237123B2 (en) 2016-12-21 2019-03-19 Nicira, Inc. Dynamic recovery from a split-brain failure in edge nodes
US10616045B2 (en) 2016-12-22 2020-04-07 Nicira, Inc. Migration of centralized routing components of logical router
CN107800573B (en) * 2017-10-31 2018-09-28 清华大学 A kind of broadband promotion method and system based on network reachability calculating
US10587937B2 (en) * 2018-04-09 2020-03-10 Futurewei Technologies, Inc. Packet and optical integration
US11750441B1 (en) 2018-09-07 2023-09-05 Juniper Networks, Inc. Propagating node failure errors to TCP sockets
US10917330B1 (en) * 2019-01-28 2021-02-09 Juniper Networks, Inc. Minimizing or reducing traffic loss when an external border gateway protocol (eBGP) peer goes down
US11025522B2 (en) 2019-05-04 2021-06-01 Juniper Networks, Inc. Path monitoring system (PMS) controller or ingress node based multiprotocal label switching (MPLS) ping and traceroute in inter- autonomous system (AS) segment routing (SR) networks
EP4029209B1 (en) * 2019-09-09 2024-08-14 Telefonaktiebolaget LM Ericsson (publ) Method and network node for label switched path traceroute
US11165681B2 (en) 2019-09-27 2021-11-02 Juniper Networks, Inc. Inter-autonomous system trace route message
CN112688871B (en) * 2019-10-18 2023-07-25 阿尔格布鲁控股有限公司 Route control in external autonomous systems using customer-specific tunnels
US11336569B2 (en) * 2020-02-11 2022-05-17 Juniper Networks, Inc. Ping and traceroute in inter-autonomous system (AS) segment routing (SR) networks without requiring headend router or path monitoring system (PMS) controller knowledge of topology outside of origin as
US11736383B2 (en) 2020-04-06 2023-08-22 Vmware, Inc. Logical forwarding element identifier translation between datacenters
CN113872854B (en) * 2020-06-30 2022-12-30 华为技术有限公司 Packet loss processing method and network equipment
CN112511371A (en) * 2020-10-29 2021-03-16 中国农业银行股份有限公司福建省分行 Method, device, equipment and medium for monitoring wide area network communication line

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11490404B2 (en) 2019-08-23 2022-11-01 At&T Intellectual Property I, L.P. Demodulation reference signal patterns for dynamic spectrum sharing with increased spectral efficiency for 5G or other next generation network

Family Cites Families (84)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB9521831D0 (en) 1995-10-25 1996-01-03 Newbridge Networks Corp Crankback and loop detection in ATM SVC routing
US6459682B1 (en) 1998-04-07 2002-10-01 International Business Machines Corporation Architecture for supporting service level agreements in an IP network
US6222824B1 (en) 1998-04-24 2001-04-24 International Business Machines Corporation Statistical call admission control
US6501755B1 (en) * 1998-06-11 2002-12-31 Alcatel Canada Inc. Stacked address transport in connection oriented networks
US6205488B1 (en) 1998-11-13 2001-03-20 Nortel Networks Limited Internet protocol virtual private network realization using multi-protocol label switching tunnels
JP3623680B2 (en) 1999-01-11 2005-02-23 株式会社日立製作所 Network system having path verification function, path management apparatus, and exchange
US6856627B2 (en) 1999-01-15 2005-02-15 Cisco Technology, Inc. Method for routing information over a network
US6337861B1 (en) * 1999-02-02 2002-01-08 Cisco Technology, Inc. Method and apparatus to properly route ICMP messages in a tag-switching network
US6813242B1 (en) 1999-05-07 2004-11-02 Lucent Technologies Inc. Method of and apparatus for fast alternate-path rerouting of labeled data packets normally routed over a predetermined primary label switched path upon failure or congestion in the primary path
US6556557B1 (en) * 1999-06-02 2003-04-29 At&T Corp. Method and system for reducing of peak-to-average power ratio of transmission signals comprising overlapping waveforms
US6477522B1 (en) 1999-06-10 2002-11-05 Gateway, Inc. Dynamic performance based server selection
US6813240B1 (en) 1999-06-11 2004-11-02 Mci, Inc. Method of identifying low quality links in a telecommunications network
US7154858B1 (en) 1999-06-30 2006-12-26 Cisco Technology, Inc. System and method for measuring latency of a selected path of a computer network
US6662223B1 (en) 1999-07-01 2003-12-09 Cisco Technology, Inc. Protocol to coordinate network end points to measure network latency
US6396810B1 (en) 1999-09-08 2002-05-28 Metasolv Software, Inc. System and method for analyzing communication paths in a telecommunications network
US7315510B1 (en) 1999-10-21 2008-01-01 Tellabs Operations, Inc. Method and apparatus for detecting MPLS network failures
US7076559B1 (en) * 1999-12-28 2006-07-11 Nortel Networks Limited System, device, and method for establishing label switched paths across multiple autonomous systems
JP2001217839A (en) 2000-01-31 2001-08-10 Fujitsu Ltd Node device
JP3575381B2 (en) 2000-03-24 2004-10-13 日本電気株式会社 Link state routing communication device and link state routing communication method
US7237138B2 (en) 2000-05-05 2007-06-26 Computer Associates Think, Inc. Systems and methods for diagnosing faults in computer networks
US20020093954A1 (en) 2000-07-05 2002-07-18 Jon Weil Failure protection in a communications network
GB2364851B (en) * 2000-07-15 2002-07-31 3Com Corp Identifying an edge switch and port to which a network user is attached
US6963927B1 (en) 2000-08-29 2005-11-08 Lucent Technologies Inc. Method and apparatus for computing the shortest path between nodes based on the bandwidth utilization link level
WO2002023934A1 (en) 2000-09-15 2002-03-21 Mspect, Inc. Wireless network monitoring
US7336613B2 (en) 2000-10-17 2008-02-26 Avaya Technology Corp. Method and apparatus for the assessment and optimization of network traffic
US20020118636A1 (en) 2000-12-20 2002-08-29 Phelps Peter W. Mesh network protection using dynamic ring
US20040179471A1 (en) 2001-03-07 2004-09-16 Adisak Mekkittikul Bi-directional flow-switched ring
US7269157B2 (en) 2001-04-10 2007-09-11 Internap Network Services Corporation System and method to assure network service levels with intelligent routing
US20020165957A1 (en) 2001-05-02 2002-11-07 Devoe Jiva Gandhara Intelligent dynamic route selection based on active probing of network operational characteristics
US6744739B2 (en) 2001-05-18 2004-06-01 Micromuse Inc. Method and system for determining network characteristics using routing protocols
US7463591B1 (en) * 2001-06-25 2008-12-09 Juniper Networks, Inc. Detecting data plane liveliness of a label-switched path
US7002927B2 (en) 2001-08-01 2006-02-21 International Business Machines Corporation Self-scaling network
US20030055925A1 (en) 2001-08-06 2003-03-20 Mcalinden Paul Discovering client capabilities
EP1289191A1 (en) 2001-09-03 2003-03-05 Agilent Technologies, Inc. (a Delaware corporation) Monitoring communications networks
US7113485B2 (en) 2001-09-04 2006-09-26 Corrigent Systems Ltd. Latency evaluation in a ring network
US6834139B1 (en) 2001-10-02 2004-12-21 Cisco Technology, Inc. Link discovery and verification procedure using loopback
US7120118B2 (en) 2001-10-18 2006-10-10 Intel Corporation Multi-path analysis for managing machine communications in a network
US7561517B2 (en) 2001-11-02 2009-07-14 Internap Network Services Corporation Passive route control of data networks
US7120819B1 (en) 2001-11-15 2006-10-10 3Com Corporation Method and system for fault diagnosis in a data network
US7330435B2 (en) 2001-11-29 2008-02-12 Iptivia, Inc. Method and system for topology construction and path identification in a routing domain operated according to a link state routing protocol
US7068608B2 (en) 2001-12-21 2006-06-27 Nortel Networks Limited Automated method for connection discovery within consolidated network elements
US7139278B2 (en) 2001-12-21 2006-11-21 Nortel Networks Limited Routing traffic in a communications network
WO2003056758A1 (en) 2001-12-31 2003-07-10 Eci Telecom Ltd. Technique of determining connectivity solutions for network elements
US7373401B1 (en) 2001-12-31 2008-05-13 Nortel Networks Limited Label switched path OAM wrapper
JP2003229888A (en) 2002-02-01 2003-08-15 Nec Corp Label switching network and label switching path setting method to be used for the network
US7099277B2 (en) 2002-02-20 2006-08-29 Mitsubishi Electric Research Laboratories, Inc. Dynamic optimal path selection in multiple communications networks
US7080141B1 (en) 2002-04-12 2006-07-18 Cisco Technology, Inc. Arrangement for automated fault detection and fault resolution of a network device
US6744774B2 (en) 2002-06-27 2004-06-01 Nokia, Inc. Dynamic routing over secure networks
JP3890061B2 (en) * 2002-07-31 2007-03-07 ケイティーフリーテル カンパニー リミテッド Method and apparatus for explicit multicast receiveability and reachability testing
US20040132409A1 (en) 2002-08-28 2004-07-08 Siemens Aktiengesellschaft Test method for message paths in communications networks and redundant network arrangements
US7280481B2 (en) 2002-10-10 2007-10-09 Guangyi David Rong Shortest path search method “Midway”
US7881214B2 (en) 2002-10-25 2011-02-01 General Instrument Corporation Method for performing remote testing of network using IP measurement protocol packets
US7584298B2 (en) 2002-12-13 2009-09-01 Internap Network Services Corporation Topology aware route control
US7277936B2 (en) 2003-03-03 2007-10-02 Hewlett-Packard Development Company, L.P. System using network topology to perform fault diagnosis to locate fault between monitoring and monitored devices based on reply from device at switching layer
CA2422258A1 (en) 2003-03-14 2004-09-14 Alcatel Canada Inc. Ethernet route trace
US7680920B2 (en) 2003-03-24 2010-03-16 Netiq Corporation Methods, systems and computer program products for evaluating network performance using diagnostic rules identifying performance data to be collected
US7394809B2 (en) 2003-03-31 2008-07-01 Intel Corporation Method and apparatus for packet classification using a forest of hash tables data structure
CA2425442A1 (en) 2003-04-15 2004-10-15 Felix Katz Connectivity verification for internet protocol/multi-protocol label switching data communications networks
MXPA05011578A (en) 2003-04-28 2006-07-06 Alcatel Ip Networks Inc Oam echo messaging to verify a service-based network distribution path.
US7872976B2 (en) 2003-05-02 2011-01-18 Alcatel-Lucent Usa Inc. System and method for multi-protocol label switching network tuning
CN1188984C (en) 2003-07-11 2005-02-09 清华大学 Selecting method based on path-time delay probability distribution
US7385937B2 (en) 2003-07-23 2008-06-10 International Business Machines Corporation Method and system for determining a path between two points of an IP network over which datagrams are transmitted
US7085290B2 (en) 2003-09-09 2006-08-01 Harris Corporation Mobile ad hoc network (MANET) providing connectivity enhancement features and related methods
US7466655B1 (en) 2003-09-16 2008-12-16 Cisco Technology, Inc. Ant-based method for discovering a network path that satisfies a quality of service equipment
JP4318520B2 (en) 2003-09-26 2009-08-26 富士通株式会社 Terminal status control system
US7382738B2 (en) 2003-11-24 2008-06-03 Nortel Networks Limited Method and apparatus for computing metric information for abstracted network links
ATE393534T1 (en) * 2003-12-19 2008-05-15 Mitsubishi Electric Corp ADDRESS MANAGEMENT PROCEDURES
US7280486B2 (en) * 2004-01-07 2007-10-09 Cisco Technology, Inc. Detection of forwarding problems for external prefixes
JP2005269460A (en) * 2004-03-19 2005-09-29 Intec Netcore Inc System and method for measuring communication quality, and presentation server unit
US7284165B2 (en) 2004-06-15 2007-10-16 International Business Machines Corporation Computer generated documentation including diagram of computer system
US7746793B2 (en) 2004-06-18 2010-06-29 Cisco Technology, Inc. Consistency between MPLS forwarding and control planes
US7733856B2 (en) * 2004-07-15 2010-06-08 Alcatel-Lucent Usa Inc. Obtaining path information related to a virtual private LAN services (VPLS) based network
US7583593B2 (en) 2004-12-01 2009-09-01 Cisco Technology, Inc. System and methods for detecting network failure
JP4576249B2 (en) 2005-01-27 2010-11-04 株式会社クラウド・スコープ・テクノロジーズ Network management apparatus and method
US7733876B2 (en) 2005-02-11 2010-06-08 Cisco Technology, Inc. Inter-autonomous-system virtual private network with autodiscovery and connection signaling
US20060215577A1 (en) 2005-03-22 2006-09-28 Guichard James N System and methods for identifying network path performance
US7447167B2 (en) 2005-03-28 2008-11-04 Cisco Technology, Inc. Method and apparatus for the creation and maintenance of a self-adjusting repository of service level diagnostics test points for network based VPNs
US20060262772A1 (en) 2005-05-23 2006-11-23 Guichard James N System and methods for providing a network path verification protocol
US7586841B2 (en) 2005-05-31 2009-09-08 Cisco Technology, Inc. System and method for protecting against failure of a TE-LSP tail-end node
US7599303B2 (en) * 2005-07-26 2009-10-06 Cisco Technology, Inc. System and methods for sending trace messages
KR101221594B1 (en) 2005-10-24 2013-01-14 삼성전자주식회사 Method and apparatus of performing tunnel signaling over ip tunneling path
US7746796B2 (en) 2006-09-29 2010-06-29 Cisco Technology, Inc. Directed echo requests and reverse traceroute
US8369213B2 (en) 2006-12-22 2013-02-05 Cisco Technology, Inc. Optimization of distributed tunnel rerouting in a computer network with path computation at an intermediate node
US8111627B2 (en) 2007-06-29 2012-02-07 Cisco Technology, Inc. Discovering configured tunnels between nodes on a path in a data communications network

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11490404B2 (en) 2019-08-23 2022-11-01 At&T Intellectual Property I, L.P. Demodulation reference signal patterns for dynamic spectrum sharing with increased spectral efficiency for 5G or other next generation network

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102857418A (en) * 2012-08-30 2013-01-02 杭州华三通信技术有限公司 VPN (virtual private network)-based fast re-route (FRR) switch method and VPN-based fast re-route switch equipment
CN102857418B (en) * 2012-08-30 2015-09-23 杭州华三通信技术有限公司 A kind of Quickly regroup changing method based on VPN and equipment
WO2020135190A1 (en) * 2018-12-28 2020-07-02 华为技术有限公司 Secure route identification method and device
US11388083B2 (en) 2018-12-28 2022-07-12 Huawei Technologies Co., Ltd. Secure route identification method and apparatus

Also Published As

Publication number Publication date
CN101124785A (en) 2008-02-13
EP1856862B1 (en) 2019-06-19
EP1856862A2 (en) 2007-11-21
WO2006096560A3 (en) 2007-10-04
CN101124785B (en) 2014-09-24
US7990888B2 (en) 2011-08-02
US20060198321A1 (en) 2006-09-07
EP1856862A4 (en) 2015-07-01

Similar Documents

Publication Publication Date Title
EP1856862B1 (en) System and method for network reachability detection
US10164838B2 (en) Seamless segment routing
US20220407800A1 (en) Traceroute for multi-path routing
US7693047B2 (en) System and method for PE-node protection
US11805010B2 (en) Signaling IP path tunnels for traffic engineering
US7477593B2 (en) Loop prevention techniques using encapsulation manipulation of IP/MPLS field
US8462790B2 (en) Label switching in fibre channel networks
US7433320B2 (en) System and methods for network path detection
US7957306B2 (en) Providing reachability information in a routing domain of an external destination address in a data communications network
US20090252161A1 (en) Method And Systems For Routing A Data Packet Based On Geospatial Information
CN111064596B (en) Node protection for BUM traffic for multi-homed node failure
US10972377B2 (en) Coordinated offloaded recording of in-situ operations, administration, and maintenance (IOAM) data to packets traversing network nodes
KR102245989B1 (en) Redundancy Administrating Method for a Virtual Private Network and Network Switching Apparatus with the method implemented on it
US20230126279A1 (en) Fast reroute for bum traffic in ethernet virtual private networks
JP5426024B2 (en) Connecting the inner MPLS label and the outer MPLS label
CN107682261B (en) Flow forwarding method and device
US9853881B2 (en) Autonomous system border router (ASBR) advertising routes with a same forwarding label
JP2004247858A (en) Information providing system and information providing method
KR20230093015A (en) Information processing method, node and computer readable storage medium

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200680004044.5

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 2006736961

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

NENP Non-entry into the national phase

Ref country code: RU