WO2014127629A1 - 报文转发系统、方法及装置 - Google Patents

报文转发系统、方法及装置 Download PDF

Info

Publication number
WO2014127629A1
WO2014127629A1 PCT/CN2013/083685 CN2013083685W WO2014127629A1 WO 2014127629 A1 WO2014127629 A1 WO 2014127629A1 CN 2013083685 W CN2013083685 W CN 2013083685W WO 2014127629 A1 WO2014127629 A1 WO 2014127629A1
Authority
WO
WIPO (PCT)
Prior art keywords
switching unit
local
frame
central
protocol
Prior art date
Application number
PCT/CN2013/083685
Other languages
English (en)
French (fr)
Inventor
叶傲
杨骐
周海山
何清
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to US14/769,266 priority Critical patent/US9998366B2/en
Priority to EP13875436.1A priority patent/EP2961112B1/en
Publication of WO2014127629A1 publication Critical patent/WO2014127629A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/44Distributed routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4604LAN interconnection over a backbone network, e.g. Internet, Frame Relay
    • H04L12/462LAN interconnection over a bridge based backbone
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/24Multipath
    • H04L45/245Link aggregation, e.g. trunking

Definitions

  • the present invention relates to the field of communications, and in particular to a message forwarding system, method and apparatus.
  • BACKGROUND OF THE INVENTION The rapid development of Internet services and mobile communications places extremely high demands on the capacity and scalability of backbone routers.
  • high-end core routers have high requirements in terms of capacity, security and reliability, and multi-service bearer capabilities.
  • the core routers of backbone networks must have good scalability and upgrade capabilities to adapt.
  • the trend of the Internet is changing and developing rapidly. While the network is convenient for others, it will also be attacked and shackled. Because the TCP/IP protocol that constitutes the Internet itself lacks security, network security becomes a practical problem that must be faced.
  • the present invention provides a message forwarding system, method, and apparatus, which at least solve the problem that the control message and the protocol message go through the same channel in the related art, which reduces the reliability and security of the cluster router.
  • a message forwarding system including: a line card frame including a first local frame switching unit and a second local frame switching unit; and a first central switching frame including a first central switching unit; a second central switching frame including a second central switching unit; wherein, the first local frame switching unit and the second local frame switching unit are separated from the first central switching unit and the second central switching unit Control message channel and protocol message channel.
  • a separate control message channel and a protocol message channel exist between the first local frame switching unit and the second local frame switching unit and the first central switching unit and the second central switching unit.
  • the link between the first local switching unit and the first central switching unit is a control message channel
  • the link between the second local switching unit and the second central switching unit is a protocol packet.
  • a link between the first local switching unit and the second central switching unit is a control message channel
  • a chain between the second local switching unit and the first central switching unit The road is the protocol message channel.
  • the method further includes: a local switching unit, connected to the first local frame switching unit and the second local frame switching unit, configured to exchange with the first local frame switching unit and the second local frame respectively Unit interaction control messages and protocol messages.
  • the method further includes: a central control unit CPU with a dual network card connected to the local switching unit, wherein one network card is used to exchange control messages with the local switching unit, and another network card is used to communicate with the local switching unit.
  • Interactive protocol packet a packet forwarding method is provided, including: determining a first central switching unit and a second local switching unit in a line card frame and a first central switching unit in a first central switching frame; a control message channel and a protocol message channel separated by the second central switching unit in the second central switching frame; respectively, transmitting the control message and the protocol message according to the determined control message channel and the protocol message channel.
  • the message channel and the protocol packet channel include: stacking the first local frame switching unit and the second local frame switching unit, where the first central switching unit and the second central switching unit are stacked, wherein stacking is implemented
  • the port information of the port for forming the channel is synchronized between the switching units; the control message channel and the protocol message channel are determined by the manner in which the port message negotiation is added to the link aggregation group.
  • the method before transmitting the control message and the protocol message respectively according to the determined control message channel and the protocol message channel, the method further includes: pairing the local switching unit with the first frame exchange unit and the second Load balancing is performed on each port of the link switching unit that performs link aggregation.
  • the method before the control message and the protocol message are respectively transmitted according to the determined control message channel and the protocol message channel, the method further includes: configuring a central controller CPU with a dual network card to perform interaction control with the local exchange unit The network card of the information has a higher quota than the network card used to exchange protocol packets with the local switching unit.
  • a packet forwarding apparatus including: a determining module, configured to determine a first local frame switching unit and a second local frame switching unit in a line card frame and a first central switching frame One center exchange a separate control message channel and a protocol message channel between the unit and the second central switching unit in the second central switching frame; and a transmitting module configured to separately transmit the control message according to the determined control message channel and the protocol message channel And protocol messages.
  • the determining module includes: a stacking unit, configured to stack the first local frame switching unit and the second local frame switching unit, and the first central switching unit and the second central switching unit are stacked The port information of the port for forming the channel between the switching units of the stack is synchronized; the determining unit is configured to determine the control message channel and the manner by whether the port message negotiation is added to the link aggregation group Protocol message channel.
  • the method further includes: an allocating module, configured to perform load distribution on each port that performs link aggregation between the local switching unit and the first local frame switching unit and the second local frame switching unit.
  • the method further includes: a configuration module, configured to configure a network card with a dual network card to exchange control information for the network card with the local switching unit, and a packet quota higher than that used to exchange protocol packets with the local switching unit Network card.
  • a configuration module configured to configure a network card with a dual network card to exchange control information for the network card with the local switching unit, and a packet quota higher than that used to exchange protocol packets with the local switching unit Network card.
  • a line card frame including a first local frame switching unit and a second local frame switching unit is used; a first central switching frame including a first central switching unit; and a second central switching frame including a second central switching unit;
  • the first local frame switching unit and the second local frame switching unit have separate control message channels and protocol message channels between the first central switching unit and the second central switching unit, and the related information is solved.
  • FIG. 2 is a block diagram showing a preferred structure of a message forwarding system according to an embodiment of the present invention
  • FIG. 4 is a flowchart of a packet forwarding method according to an embodiment of the present invention
  • FIG. 5 is a structural block diagram of a message forwarding device according to an embodiment of the present invention
  • FIG. 6 is a block diagram of a preferred structure of a determining module 52 in a message forwarding device according to an embodiment of the present invention
  • FIG. 7 is a report according to an embodiment of the present invention.
  • FIG. 8 is a block diagram of a preferred structure of a message forwarding device according to an embodiment of the present invention.
  • FIG. 9 is a diagram showing a structure of a control message channel and a protocol message channel separating system according to a preferred embodiment of the present invention
  • FIG. 10 is a flowchart of a packet forwarding process according to an embodiment of the present invention
  • FIG. 11 is a schematic structural diagram of channel separation of a control message and a protocol packet after removing a link that does not forward a packet according to an embodiment of the present invention
  • FIG. 1 is a structural block diagram of a packet forwarding system according to an embodiment of the present invention.
  • the system includes: a first local frame switching unit 31 and a line card frame 11 of the second frame exchange unit 32; a first center switch frame 13 including a first center switch unit 21; a second center switch frame 14 including a second center switch unit 22; wherein the first frame A separate control message channel and protocol message channel exist between the switching unit 31 and the second local frame switching unit 32 and the first central switching unit 21 and the second central switching unit 22.
  • control message channel and the protocol message channel separated in the cluster router the control message and the protocol message can be separately forwarded, and the control message and the protocol message are transmitted in the same channel in the related art, which not only effectively avoids
  • the reliability and security of the cluster router It should be noted that there may be multiple combinations of the control message channel and the protocol message channel between the first central switching unit and the second local switching unit and the first central switching unit and the second central switching unit.
  • the preferred combination mode is: the link between the first frame switching unit and the first central switching unit is a control message channel, and the link between the second local frame switching unit and the second central switching unit is Protocol message channel;
  • the preferred combination mode is: the link between the first frame switching unit and the second central switching unit is a control message channel, and the link between the second frame switching unit and the first central switching unit is Protocol message channel.
  • 2 is a block diagram of a preferred structure of a message forwarding system according to an embodiment of the present invention. As shown in FIG. 2, the system includes a local switching unit 222 in addition to all the structures in FIG. The local switching unit 222 will be described.
  • the local switching unit 222 is connected to the first local frame switching unit 31 and the second local frame switching unit 32, and is configured to exchange control messages and protocols with the first local frame switching unit and the second local frame switching unit, respectively.
  • Message it should be noted that, in the system that separates the control message channel from the protocol packet channel, the link between the local switching unit in the line card frame and the first local frame switching unit and the second local frame switching unit may also be Separation, but with separate processing, not only can separate the control message channel from the protocol message channel, but also has the advantage of achieving link redundancy and increasing bandwidth.
  • 3 is a block diagram of a preferred structure of a message forwarding system according to an embodiment of the present invention. As shown in FIG.
  • the system includes a central control unit with a dual network card (Central Processing Unit, in addition to all the structures in FIG. , referred to as CPU) 32, the following description of the CPU with dual network card.
  • the dual-NIC CPU 32 is connected to the local switching unit.
  • One network card 1 is used to exchange control messages with the local switching unit, and the other network card 2 is used to exchange protocol packets with the local switching unit.
  • FIG. 4 is a flowchart of a packet forwarding method according to an embodiment of the present invention. As shown in FIG. 4, the process includes the following steps: Step S402: Determine a line card frame.
  • Step S404 The control message and the protocol message are respectively transmitted according to the determined control message channel and the protocol message channel.
  • the control message channel for transmitting the control message is separated from the protocol message channel for transmitting the protocol message, and the control message and the protocol message are transmitted in the same channel in the related art, not only Effectively avoids the interaction between the transmission control message and the transmission protocol message, and improves the reliability and security of the cluster router to some extent.
  • the method for determining the control message channel and the protocol packet channel that are separated from each other may be in various manners, for example, the line card frame including the first local frame switching unit and the second local frame switching unit, and the first network including the first central switching unit. Determining, between the central switching frame and the second central switching frame including the second central switching unit, the separation between the first local switching unit and the second local switching unit and the first central switching unit and the second central switching unit.
  • the control message channel and the protocol packet channel can be processed in the following manner: The first frame switching unit and the second frame switching unit are stacked, and the first central switching unit and the second central switching unit are stacked, wherein stack switching is implemented.
  • the port information of the ports for forming the channel between the units is synchronized, that is, the two switching units that implement the stack can timely obtain the status information of the ports of the opposite switching unit, so that the control message channel and the protocol message channel are formed.
  • Ports are in an aggregation group; then, the port packets are negotiated to join the link aggregation group.
  • the control message channel and the protocol packet channel are determined.
  • the packet carries the frame number of the corresponding switching unit (the number of the central switching unit) and the slot number (the number of the switching unit of the frame).
  • the switch is configured to distinguish the corresponding switch, and the number specified in the packet is used to determine whether the port connected to the aggregation group is added to the aggregation group.
  • the port that is not added to the aggregation group is not used to forward control messages and protocol packets.
  • the link forwarded by the packet, so that the link between the ports joining the aggregation group is a control message channel for transmitting control messages, and a protocol message channel for transmitting protocol packets.
  • the local exchange unit and the first local frame exchange unit and the second local frame exchange unit are The load balancing is performed on each port of the link aggregation.
  • the port is determined to be sent from the port in the aggregation group according to the load sharing principle.
  • the load sharing principle can be various.
  • the source can be based on the source.
  • MAC Media Access Control
  • VLAN Virtual Local Area Network
  • the transmission bandwidth of the control message channel and the protocol message channel is configured.
  • the central controller CPU with dual network cards can be configured to interact with the local exchange unit.
  • the quotation quota of the NIC of the information is higher than that of the NIC used to exchange protocol packets with the local switching unit.
  • FIG. 5 is a structural block diagram of a message forwarding device according to an embodiment of the present invention. As shown in FIG. 5, the device includes a determining module 52 and a transmitting module 54, which are described below.
  • the determining module 52 is configured to determine between the first local box switching unit and the second local box switching unit in the line card frame, and the first central switching unit in the first central switching frame and the second central switching unit in the second central switching frame
  • the transmitting module 54 is connected to the determining module 52, and configured to respectively transmit the control message and the protocol message according to the determined control message channel and the protocol message channel.
  • FIG. 6 is a block diagram of a preferred structure of the determining module 52 in the message forwarding device according to the embodiment of the present invention. As shown in FIG. 6, the determining module 52 includes a stacking unit 62 and a determining unit 64. Description.
  • the stacking unit 62 is configured to stack the first local frame switching unit and the second local frame switching unit, and the first central switching unit and the second central switching unit are stacked, wherein the ports for forming channels between the stacked switching units are implemented.
  • the port information is synchronized;
  • the determining unit 64 is connected to the stacking unit 62, and is configured to determine the control message channel and the protocol message channel by using the port message negotiation to join the link aggregation group.
  • FIG. 7 is a block diagram of a preferred structure of a message forwarding apparatus according to an embodiment of the present invention. As shown in FIG. 7, the preferred structure includes an allocating module 72 in addition to all the modules in FIG. 72 for explanation.
  • FIG. 8 is a block diagram of a preferred structure of a packet forwarding apparatus according to an embodiment of the present invention. As shown in FIG. 8, the preferred structure includes: a configuration module 82, and the configuration is as follows. Module 82 is described. The configuration module 82 is connected to the determining module 52 and the transmitting module 54, and is configured to configure a network card with dual network cards to exchange control information for the network exchange with the local switching unit. The network card of the unit interaction protocol message.
  • the internal control plane security technology in the cluster router involved in the embodiments and the preferred embodiments of the present invention provides a system for improving the reliability and security of the cluster router, and the system includes a control message channel and a protocol.
  • the system for controlling the separation of the message channel and the protocol packet channel includes: at least two central switching frames, at least two central switching units, at least one line card frame, at least two local switching units, at least two local switching units, At least two CPUs with dual NICs, at least one interface card.
  • the central switching frame functions to connect the various line card frames.
  • the central switching unit is in the central switching frame, and each line card frame is connected to the central switching unit.
  • the central switching frame and the line card frame have a local switching unit, a local switching unit, and a CPU, and each frame has at least two local switching units.
  • the local switching unit on the line card frame and the central switching frame is connected to the central switching unit and the local switching unit of the local frame, and the local switching unit is connected to the local switching unit and the CPU.
  • the central switching frame is the box where the central switching unit is located.
  • Each central switching frame must have at least one central switching unit.
  • the central switching unit is responsible for the exchange between the switching units of the local frame.
  • the switching between one of the local switching units of one frame and one of the other switching units of the other frame must pass through the central switching unit.
  • the link between the central switching unit and the local switching unit is link-aggregated through the LACP protocol.
  • the central switching unit implements stacking, which is like a switching unit for the frame switching unit.
  • the two central switching units can achieve mutual backup and improve reliability, and can separate the control message channel from the protocol message channel, one central switching unit exchanges protocol messages, and the other exchanges control messages.
  • In the line card box there is a local switching unit and a local switching unit, and a CPU that processes messages.
  • This frame exchange unit has two functions. One is used to connect the frame to the central switch frame to enable communication between this frame and other frames.
  • the other is used to implement the interconnection of the local switching units in this frame, so that the local exchanges in this box can communicate with each other and also communicate with other boxes.
  • the frame exchange unit also implements stacking, and the external presentation is like an exchange unit.
  • the local switching unit is mainly responsible for exchanging protocol packets and control messages of the local CPU to the central switching unit, and receiving protocol packets and control messages from the local switching unit.
  • the local switching unit has a link connection with the two local switching units, which performs link redundancy on one hand and increases bandwidth. On the other hand, it can separate the control message channel from the protocol message channel.
  • the port connected to the switching unit of the local device is configured to link aggregation through the LACP protocol.
  • Link aggregation allows one or more links to be aggregated together to form a link aggregation group.
  • a packet When a packet is sent through an aggregation group, it determines the port to be sent from the aggregation group according to the load sharing principle.
  • the load sharing principle is generally various. For example, according to the source and destination MAC addresses, the source and destination MAC addresses plus the VLAN, the source. , destination IP, etc.
  • a CPU with dual NICs one of which is responsible for sending and receiving protocol messages, and the other for sending and receiving control messages, thus achieving the effect of separating the control message channel from the protocol message channel.
  • the packet quota of the two network cards of the CPU is configured to be higher than the network card of the transceiver protocol message, the control message can be preferentially
  • the CPU receives the processing, which improves the reliability inside the router.
  • the MAC address of each CPU NIC should be allocated reasonably.
  • the interface card is connected to the external network and receives packets from the external network. If the packet is detected by the router, it will be forwarded to the internal CPU of the router. When the internal CPU of the router needs to forward packets to other routers, it also needs to be forwarded through the interface card.
  • the process of separating the control message channel and the protocol message channel includes the following aspects: (1) Two central switching units implement stacking.
  • FIG. 9 is a schematic structural diagram of a control message channel and a protocol message channel separation system according to a preferred embodiment of the present invention. As shown in FIG.
  • the system includes: two central switching frames and two line card frames.
  • Each frame is identified by the frame number.
  • the number of the line card frame and the center frame can be consecutively numbered or separately numbered. Now set the upper line card frame to No. 1, and the lower line card frame to No. 2, the left center.
  • the switch frame is number 3, and the right center switch frame is number 4.
  • the frame exchange unit in each frame is also numbered. The number is the slot number. The slot number on the left is smaller than the right one. These numbers are all Not fixed, just for the convenience of the description behind.
  • the central switching frame may also have a local switching unit, a local switching unit, and a CPU.
  • the line card frame 11 may also have an interface card.
  • the message channel separation can be between the line card frame and the line card frame, or between the line card frame and the center frame.
  • the frame exchange unit 31 or the frame exchange unit 33 in the figure is equivalent to the first frame exchange unit 31 described above.
  • the local frame switching unit 32 or the local frame switching unit 34 is equivalent to the second local frame switching unit 32 described above; the central switching frame 13 in the figure is equivalent to the first central switching frame 13 described above, and the central switching frame 14 in the figure Corresponding to the second central switching frame 14 described above; the central switching unit 21 in the figure is equivalent to the first central switching unit 21 described above, and the central switching unit 22 in the figure is equivalent to the second central switching unit 22 described above; Local The switching unit 41 and the local switching unit 42 are equivalent to the local switching unit 222 described above; the control network card 1 or the control network card 2 corresponds to the network card 1, and the protocol network card 1 or the protocol network card 2 corresponds to the network card 2; the CPU 1 and the CPU 2 are equivalent.
  • the CPU is connected to the two local switching units of the local frame.
  • the local switching unit of each line card frame is connected to the two central switching units.
  • Each local switching unit can forward packets to any center.
  • the switching unit but the protocol message coming in from outside the router and the control message channel inside the router cannot be separated, and will pass through the same central switching unit or the same local switching unit.
  • the two central switching units need to be stacked, and the local switching units in each frame are also stacked.
  • the stacking switching units synchronize the stacking information through timing and changing synchronization.
  • the two ports are used to maintain the ports of the stack switching unit, that is, the other port is added to or removed from the aggregation group of the switching unit, and the information about the ports and aggregation groups between the switching units is implemented. Consistent.
  • the port of each switch unit is added to or removed from the aggregation group through LACP.
  • the port information is the information that the port is added to or deleted from the aggregation group and the aggregation group number corresponding to the port.
  • it is necessary to periodically synchronize the port information to another switching unit and after receiving the synchronization port information, the other switching unit compares and updates the port information previously reserved by itself.
  • the synchronization port information is changed to another switching unit.
  • the local end adds the port to the aggregation group or deletes it from the aggregation group, and immediately sends a notification message.
  • the addition or deletion of the port is completed in the aggregation group corresponding to the port.
  • the stacking switch unit maintains a global table of ports that have been added to the aggregation group.
  • the content of the port is: the aggregation group number of the port, the port number, the chip number of the device to which the port belongs, and the chip number of the device. The number of the cells to distinguish them.
  • Timing synchronization ensures the consistency of the content in the global table, and the synchronization synchronization ensures the real-time nature of the content in the global table. Timing synchronization is mainly to make up for the lack of synchronization failure. If the synchronization fails, the timing synchronization can ensure the consistency of the information at both ends. Now that the two central switching units and the local switching unit in each frame are stacked, the ports on the local switching unit of each line card frame and the central switching unit are in an aggregation group.
  • the frame switching unit 31 and the central switching unit 21 only forward control messages.
  • the local switching unit 32 and the central switching unit 22 only forward protocol packets.
  • the control message of the local switching unit 31 may be forwarded to the central switching unit 22, then The channels still cannot be separated.
  • How to enable the local switching unit of the forwarding protocol packet to forward only the protocol packet to the central switching unit that forwards only the protocol packet, and the local switching unit of the forwarding control message only forwards the control message The link between the central switching unit and the local switching unit is set up so that the cross-link does not forward packets.
  • the cross-link is the forwarding protocol packet.
  • the port of the local switching unit parses the frame number and slot number of the central switching unit from the source MAC address of the LACP packet to check whether the packets of the two central switching units are received. If only one is received, the port is added to the aggregation group through LACP packet negotiation. If the local switching unit receives the LACP packets of the two central switching units, compare the size of the frame number of the central switching frame. If the two central switching units are inserted into one frame, compare the slot numbers. The port connected to the central switch unit with the smaller frame number is added to the aggregation group through the LACP packet negotiation. The port connected to the central switch unit with the large frame number is only reported by LACP.
  • the port status is the BLOCK state of the packet.
  • the LACP packet reservation field sent to the central switch unit with a large frame number is added to the aggregation group.
  • the flag is set to be sent to the aggregation group without being added to the aggregation group.
  • the location of the flag in the LACP packet is the Aggregation_Flag field.
  • the central switching unit After receiving the flag, the central switching unit will also make the local port not join the aggregation group and set to the BLOCK state. According to this reason, the port connected to the central switching unit with the large frame number is added to the aggregation group through the LACP packet negotiation, and the port connected to the central switching unit with a small frame number.
  • FIG. 10 is a flowchart of a packet forwarding process according to an embodiment of the present invention.
  • the method includes the following steps: Step S1002, the central switching unit port sends an LACP packet with the frame number and the slot number information, and proceeds to step S1004; In step S1004, it is determined whether the frame exchange unit has a small slot number. If the determination is yes, the process proceeds to step S1006. Otherwise, the process proceeds to step S1008.
  • step S1006 it is determined whether the LACP message received by the frame switching unit is centered. If the determination is yes, the process proceeds to step S1010. Otherwise, the process proceeds to step S1012.
  • Step S1008 it is determined whether the LACP message received by the frame switching unit is the central switching unit 22, and the determination is yes. Go to step S1018, otherwise go to step S1020; Step S1010, the port joins the aggregation group through LACP packet negotiation, and proceeds to step S1014; Step S1012, the port only performs LACP packet negotiation but does not join the aggregation group, and proceeds to step S1016; Step S1014 The link 91 is faulty, and is deleted from the aggregation group, and the process proceeds to step S1016.
  • step S1016 the link is added to the aggregation group.
  • step S1018 the port joins the aggregation group through the LACP packet negotiation, and the process proceeds to step S1022.
  • step S1020 the port only performs LACP.
  • the packet is negotiated but not added to the aggregation group, and the process proceeds to step S1024.
  • step S1022 the link 94 is faulty, and is deleted from the aggregation group.
  • Step S1024; Step S1024, the link 93 joins the aggregation group.
  • FIG. 11 is a schematic structural diagram of channel separation of the control message and the protocol packet after removing the link that does not forward the packet according to the embodiment of the present invention.
  • the connection relationship of each switching unit in the whole system at this time is:
  • the CPU of the line card frame 11 communicates with the CPU and the interface card of the line card frame 12 physically, and there are two separate channels, which are control messages. It has laid a solid foundation for the separation of channels from protocol messages.
  • the link between the switching unit and the central switching unit is the link that is successfully negotiated by the LACP but is not added to the aggregation group.
  • the communication link between the frame switching unit 31 and the central switching unit 21 is within 150 milliseconds.
  • the route is switched to the link between the local switching unit 31 and the central switching unit 22, and the link is added to the aggregation group.
  • the link 92 is deleted from the aggregation group, and the control message and the protocol message cannot be forwarded.
  • Two physically separated channels have been formed. How to make the protocol message and the control message go through a channel. This requires setting the MAC address of the network card and the interface card, and setting the central switching unit, the local switching unit, and the local. The load sharing rule of the switching unit.
  • the steps are as follows: Set the lower three bits of the protocol network port MAC of the CPU and the MAC address of the interface card to 100.
  • the MAC address is of the form BYTEO: BYTE1: BYTE2: BYTE3: BYTE4: BYTE5, then the lower three bits of the byte BYTE5 The bit is 100.
  • the central switching unit with a small frame number and the local switching unit with a small slot number forward control messages that is, the switching units only forward the packets with the bottom three bits of the source MAC in the packet as 000.
  • the switching unit forwards only the packets with the bottom three bits of the source MAC address in the packet.
  • Configure the port connected to the local switching unit of the local switching unit to forward only control messages that is, when a packet needs to be forwarded from the local switching unit to the local switching unit, if the source MAC address of the packet is received. When the three-bit bit is 000, it is forwarded from this port.
  • the channel of the control message is: the local switching unit 31 - the central switching unit 21 - the local switching unit 33, and the channel of the protocol packet is: the local switching unit 32 - central switching unit 22 - present frame switching unit 34.
  • a channel is controlled by a control message, and a channel is not fixed. The channel on the left of the control message shown in FIG. 11 is used to forward the protocol message, and the other is That one forwards the control message.
  • modules or steps of the present invention can be implemented by a general-purpose computing device, which can be concentrated on a single computing device or distributed over a network composed of multiple computing devices. Alternatively, they may be implemented by program code executable by the computing device, such that they may be stored in the storage device by the computing device and, in some cases, may be different from The steps shown or described are performed sequentially, or they are separately fabricated into individual integrated circuit modules, or a plurality of modules or steps thereof are fabricated into a single integrated circuit module. Thus, the invention is not limited to any specific combination of hardware and software.
  • the above is only the preferred embodiment of the present invention, and is not intended to limit the present invention, and various modifications and changes can be made to the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the present invention are intended to be included within the scope of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明提供了一种报文转发系统、方法及装置,该系统包括:第一本框交换单元和第二本框交换单元的线卡框;包括第一中心交换单元的第一中心交换框;包括第二中心交换单元的第二中心交换框;其中,该第一本框交换单元和第二本框交换单元与第一中心交换单元和第二中心交换单元之间存在分离的控制消息通道和协议报文通道,通过本发明,解决了相关技术中控制消息和协议报文走同一通道,会降低集群路由器的可靠性和安全性的问题,进而达到了使控制消息和协议报文在集群路由器中分离转发,增强集群路由器的可靠性及安全性的效果。

Description

报文转发系统、 方法及装置 技术领域 本发明涉及通信领域, 具体而言, 涉及一种报文转发系统、 方法及装置。 背景技术 互联网业务以及移动通信的高速发展对骨干网核心路由器的容量和扩展性提出了 极高的要求。例如,在 IP网络的电信化过程中对高端核心路由器在容量、安全可靠性、 多业务承载能力等方面提出了极高的要求, 骨干网核心路由器必须具有良好的扩展性 和升级能力, 以适应互联网多变、 飞速发展的趋势。 网络在带给别人方便的同时, 自 身也会收到攻击而陷入瘫痪, 由于构成 Internet的 TCP/IP协议本身缺乏安全性, 网络 安全成为必须面对的一个实际问题。 网络上存在着各种类型的攻击方式, 包括: 窃听 报文、 IP地址欺骗、源路由攻击、 端口扫描、拒绝服务攻击和应用层攻击等等, 另外, 网络本身的可靠性与线路安全也是一个重要的问题。 在相关技术中的集群路由器存在一些问题: 例如, 集群路由器内部所有报文都走 同一通道, 包括控制消息和协议报文。 控制消息是集群路由器内部控制面消息, 优先 级比协议报文高, 要求传送的可靠性也高。 随着网络被广泛的应用, 协议报文也随之 增加, 再加上网络攻击的存在, 有时一部分攻击报文进入网络内部也在所难免, 这样 势必使协议报文急剧增加, 而协议报文的流量增大时, 就会占用控制面消息的带宽, 导致控制面消息拥塞或被丢弃, 而控制面消息有时丢失一个就会影响到整个系统的运 行。 集群路由器内部的控制面消息有时也会很多, 这样就影响到协议报文的传送。 由 此可见, 控制消息和协议报文走同一通道, 会降低集群路由器的可靠性和安全性。 发明内容 本发明提供了一种报文转发系统、 方法及装置, 以至少解决相关技术中控制消息 和协议报文走同一通道, 会降低集群路由器的可靠性和安全性的问题。 根据本发明的一个方面, 提供了一种报文转发系统, 包括: 包括第一本框交换单 元和第二本框交换单元的线卡框; 包括第一中心交换单元的第一中心交换框; 包括第 二中心交换单元的第二中心交换框; 其中, 所述第一本框交换单元和第二本框交换单 元与所述第一中心交换单元和所述第二中心交换单元之间存在分离的控制消息通道和 协议报文通道。 优选地, 所述第一本框交换单元和第二本框交换单元与所述第一中心交换单元和 所述第二中心交换单元之间存在分离的控制消息通道和协议报文通道包括: 所述第一 本框交换单元与所述第一中心交换单元之间的链路为控制消息通道, 所述第二本框交 换单元与所述第二中心交换单元之间的链路为协议报文通道; 或者, 所述第一本框交 换单元与所述第二中心交换单元之间的链路为控制消息通道, 所述第二本框交换单元 与所述第一中心交换单元之间的链路为协议报文通道。 优选地, 还包括: 本地交换单元, 连接于所述第一本框交换单元和所述第二本框 交换单元, 用于分别与所述第一本框交换单元和所述第二本框交换单元交互控制消息 和协议报文。 优选地, 还包括: 带双网卡的中央控制单元 CPU, 连接于所述本地交换单元, 其 中, 一个网卡用于与所述本地交换单元交互控制消息, 另一个网卡用于与所述本地交 换单元交互协议报文。 根据本发明的另一方面, 提供了一种报文转发方法, 包括: 确定线卡框中第一本 框交换单元和第二本框交换单元与第一中心交换框中第一中心交换单元和第二中心交 换框中第二中心交换单元之间分离的控制消息通道和协议报文通道; 根据确定的所述 控制消息通道和所述协议报文通道分别传送控制消息和协议报文。 优选地, 确定线卡框中第一本框交换单元和第二本框交换单元与第一中心交换框 中第一中心交换单元和第二中心交换框中第二中心交换单元之间分离的控制消息通道 和协议报文通道包括: 将所述第一本框交换单元与所述第二本框交换单元堆叠, 所述 第一中心交换单元与所述第二中心交换单元堆叠, 其中, 实现堆叠的交换单元之间用 于形成通道的端口的端口信息同步; 通过所述端口报文协商是否加入链路聚合组的方 式确定所述控制消息通道和所述协议报文通道。 优选地, 在根据确定的所述控制消息通道和所述协议报文通道分别传送控制消息 和协议报文之前, 还包括: 对本地交换单元与所述第一本框交换单元和所述第二本框 交换单元之间进行链路聚合的各个端口进行负荷分配。 优选地, 在根据确定的所述控制消息通道和所述协议报文通道分别传送控制消息 和协议报文之前, 还包括: 配置带双网卡的中央控制器 CPU中用于与本地交换单元交 互控制信息的网卡的收包配额高于用于与所述本地交换单元交互协议报文的网卡。 根据本发明的还一方面, 提供了一种报文转发装置, 包括: 确定模块, 设置为确 定线卡框中第一本框交换单元和第二本框交换单元与第一中心交换框中第一中心交换 单元和第二中心交换框中第二中心交换单元之间分离的控制消息通道和协议报文通 道; 传送模块, 设置为根据确定的所述控制消息通道和所述协议报文通道分别传送控 制消息和协议报文。 优选地, 所述确定模块包括: 堆叠单元, 设置为将所述第一本框交换单元与所述 第二本框交换单元堆叠,所述第一中心交换单元与所述第二中心交换单元堆叠,其中, 实现堆叠的交换单元之间用于形成通道的端口的端口信息同步; 确定单元, 设置为通 过所述端口报文协商是否加入链路聚合组的方式确定所述控制消息通道和所述协议报 文通道。 优选地, 还包括: 分配模块, 设置为对本地交换单元与所述第一本框交换单元和 所述第二本框交换单元之间进行链路聚合的各个端口进行负荷分配。 优选地, 还包括: 配置模块, 设置为配置带双网卡的中央控制器 CPU中用于与本 地交换单元交互控制信息的网卡的收包配额高于用于与所述本地交换单元交互协议报 文的网卡。 通过本发明, 采用包括第一本框交换单元和第二本框交换单元的线卡框; 包括第 一中心交换单元的第一中心交换框; 包括第二中心交换单元的第二中心交换框; 其中, 所述第一本框交换单元和第二本框交换单元与所述第一中心交换单元和所述第二中心 交换单元之间存在分离的控制消息通道和协议报文通道, 解决了相关技术中控制消息 和协议报文走同一通道, 会降低集群路由器的可靠性和安全性的问题, 进而达到了使 控制消息和协议报文在集群路由器中分离转发, 增强集群路由器的可靠性及安全性的 效果。 附图说明 此处所说明的附图用来提供对本发明的进一步理解, 构成本申请的一部分, 本发 明的示意性实施例及其说明用于解释本发明, 并不构成对本发明的不当限定。 在附图 中- 图 1是根据本发明实施例的报文转发系统的结构框图; 图 2是根据本发明实施例的报文转发系统的优选结构框图一; 图 3是根据本发明实施例的报文转发系统的优选结构框图二; 图 4是根据本发明实施例的报文转发方法的流程图; 图 5是根据本发明实施例的报文转发装置的结构框图; 图 6是根据本发明实施例的报文转发装置中确定模块 52的优选结构框图一; 图 7是根据本发明实施例的报文转发装置的优选结构框图一; 图 8是根据本发明实施例的报文转发装置的优选结构框图二; 图 9是根据本发明优选实施例的控制消息通道和协议报文通道分离系统的结构示 意图; 图 10是根据本发明实施例的报文转发过程的流程图; 图 11 是根据本发明实施例的去除不转发报文的链路后的控制消息和协议报文的 通道分离的结构示意图。 具体实施方式 下文中将参考附图并结合实施例来详细说明本发明。 需要说明的是, 在不冲突的 情况下, 本申请中的实施例及实施例中的特征可以相互组合。 在本实施例中提供了一种报文转发系统, 图 1是根据本发明实施例的报文转发系 统的结构框图, 如图 1所示, 该系统包括: 包括第一本框交换单元 31和第二本框交换 单元 32的线卡框 11 ; 包括第一中心交换单元 21的第一中心交换框 13 ; 包括第二中心 交换单元 22的第二中心交换框 14; 其中, 该第一本框交换单元 31和第二本框交换单 元 32与第一中心交换单元 21和第二中心交换单元 22之间存在分离的控制消息通道和 协议报文通道。 根据在集群路由器中分离的控制消息通道和协议报文通道, 使得控制消息与协议 报文能够单独地转发, 相对于相关技术中控制消息与协议报文在同一通道中传送, 不 仅有效地避免了传送控制消息与传送协议报文之间的相互影响, 而且, 在线卡框与中 心交换框中均存在对应的两个交换单元, 有利地实现了互为备份的功能, 即在一定程 度上提高了集群路由器的可靠性和安全性。 需要说明的是, 上述第一本框交换单元和第二本框交换单元与第一中心交换单元 和第二中心交换单元之间存在分离的控制消息通道和协议报文通道可以有多种组合方 式, 例如, 优选的组合方式一为: 第一本框交换单元与第一中心交换单元之间的链路 为控制消息通道,第二本框交换单元与第二中心交换单元之间的链路为协议报文通道; 又例如, 优选的组合方式二为: 第一本框交换单元与第二中心交换单元之间的链路为 控制消息通道, 第二本框交换单元与第一中心交换单元之间的链路为协议报文通道。 图 2是根据本发明实施例的报文转发系统的优选结构框图一, 如图 2所示, 该系 统除包括图 1 中的所有结构外, 还包括本地交换单元 222, 下面对该优选地本地交换 单元 222进行说明。 该本地交换单元 222, 连接于上述第一本框交换单元 31和上述第二本框交换单元 32, 设置为分别与上述第一本框交换单元和上述第二本框交换单元交互控制消息和协 议报文。 需要指出的是, 在实现控制消息通道与协议报文通道分离的系统中, 线卡框 中的本地交换单元与第一本框交换单元和第二本框交换单元之间的链路也可以不分 离, 但采用分离的处理, 相对于不分离不仅能够使得控制消息通道与协议报文通道分 离, 而且具有实现链路冗余, 提高带宽的好处。 图 3是根据本发明实施例的报文转发系统的优选结构框图二, 如图 3所示, 该系 统除包括图 2中的所有结构外, 还包括带双网卡的中央控制单元 (Central Processing Unit, 简称为 CPU) 32, 下面对该带双网卡的 CPU进行说明。 该带双网卡的 CPU 32, 连接于上述本地交换单元, 其中, 一个网卡 1用于与该本 地交换单元交互控制消息, 另一个网卡 2用于与该本地交换单元交互协议报文。 通过 这样的处理, 不仅实现了控制消息通道与协议报文通道分离的效果, 而且, 为对控制 消息通道与协议报文通道的配置也提供了基础, 例如, 对于分离的控制消息通道和协 议报文通道, 可以设置收发控制消息的网卡的收发包配置的额度高于收发协议报文的 网卡, 通过这样的配置, 可以在一定程度上保护收发控制消息的可靠性。 在本实施例中提供了一种报文转发方法, 图 4是根据本发明实施例的报文转发方 法的流程图, 如图 4所示, 该流程包括如下步骤: 步骤 S402,确定线卡框中第一本框交换单元和第二本框交换单元与第一中心交换 框中第一中心交换单元和第二中心交换框中第二中心交换单元之间分离的控制消息通 道和协议报文通道; 步骤 S404,根据确定的上述控制消息通道和协议报文通道分别传送控制消息和协 议报文。 通过上述步骤, 将用于传送控制消息的控制消息通道与用于传送协议报文的协议 报文通道相分离, 相对于相关技术中控制消息和协议报文在同一通道中传送, 不仅有 效地避免了传送控制消息与传送协议报文之间的相互影响, 而且在一定程度上提高了 集群路由器的可靠性和安全性。 在确定相互分离的控制消息通道和协议报文通道可以采用多种方式, 例如, 在包 括第一本框交换单元和第二本框交换单元的线卡框、 包括第一中心交换单元的第一中 心交换框和包括第二中心交换单元的第二中心交换框的系统中, 确定该第一本框交换 单元和第二本框交换单元与第一中心交换单元和第二中心交换单元之间分离的控制消 息通道和协议报文通道可以采用以下处理方式: 将第一本框交换单元与第二本框交换 单元堆叠, 第一中心交换单元与第二中心交换单元堆叠, 其中, 实现堆叠的交换单元 之间用于形成通道的端口的端口信息同步,,即实现堆叠的双方交换单元能够及时地获 知对端交换单元的端口的状态信息, 这样就使得用于形成控制消息通道和协议报文通 道的端口都在一个聚合组中; 然后, 通过端口报文协商是否加入链路聚合组的方式确 定控制消息通道和协议报文通道, 在确定的过程中, 可以通过报文中携带对应交换单 元的框号(中心交换单元的编号), 槽位号(本框交换单元的编号)的方式进行区分对 应的交换单元, 以及报文中指定的编号确定与之相连的端口是否加入聚合组, 不加入 聚合组的端口不用于转发控制消息和协议报文, 从而去除了不进行控制消息和协议报 文转发的链路, 从而确定加入聚合组的端口之间的链路为用于传送控制消息的控制消 息通道, 和用于传送协议报文的协议报文通道。 为了使得用于传送报文的资源合理, 在根据确定的控制消息通道和协议报文通道 传送控制消息和协议报文之前, 对本地交换单元与第一本框交换单元和第二本框交换 单元之间进行链路聚合的各个端口进行负荷分配, 报文经过该聚合链路时, 根据负荷 分担原则, 决定从聚合组中的哪个端口发送, 负荷分担原则可以有多种, 例如, 可以 根据源媒体接入控制 (Media Access Control, 简称为 MAC) 地址、 源、 目的 MAC地 址加上虚拟局域网 (Virtual Local Area Network, 简称为 VLAN), 源、 目的 IP等。 为了更有效地控制传送控制消息的控制消息通道和用于传送协议报文的协议报文 通道的带宽资源, 可以在根据确定的控制消息通道和协议报文通道传送控制消息和协 议报文之前, 对该控制消息通道与协议报文通道的传送带宽进行配置, 例如, 为了在 一定程度上保证控制消息通道的可靠性,可以配置带双网卡的中央控制器 CPU中用于 与本地交换单元交互控制信息的网卡的收包配额高于用于与本地交换单元交互协议报 文的网卡, 经过这样的处理, 提高了路由器内部的可靠性。 在本实施例中还提供了一种报文转发装置, 该装置用于实现上述实施例及优选实 施方式, 已经进行过说明的不再赘述。 如以下所使用的, 术语"模块"可以实现预定功 能的软件和 /或硬件的组合。 尽管以下实施例所描述的装置较佳地以软件来实现, 但是 硬件, 或者软件和硬件的组合的实现也是可能并被构想的。 图 5是根据本发明实施例的报文转发装置的结构框图, 如图 5所示, 该装置包括 确定模块 52和传送模块 54, 下面对该装置进行说明。 确定模块 52, 设置为确定线卡框中第一本框交换单元和第二本框交换单元与第一 中心交换框中第一中心交换单元和第二中心交换框中第二中心交换单元之间分离的控 制消息通道和协议报文通道; 传送模块 54, 连接至上述确定模块 52, 设置为根据确定 的上述控制消息通道和协议报文通道分别传送控制消息和协议报文。 图 6是根据本发明实施例的报文转发装置中确定模块 52的优选结构框图一,如图 6所示, 该确定模块 52包括堆叠单元 62和确定单元 64, 下面对该确定模块 52进行说 明。 堆叠单元 62, 设置为将第一本框交换单元与第二本框交换单元堆叠, 第一中心交 换单元与第二中心交换单元堆叠, 其中, 实现堆叠的交换单元之间用于形成通道的端 口的端口信息同步; 确定单元 64, 连接至上述堆叠单元 62, 设置为通过上述端口报文 协商是否加入链路聚合组的方式确定控制消息通道和协议报文通道。 图 7是根据本发明实施例的报文转发装置的优选结构框图一, 如图 7所示, 该优 选结构除包括图 5中的所有模块外, 还包括分配模块 72, 下面对该分配模块 72进行 说明。 该分配模块 72, 连接至上述确定模块 52和传送模块 54, 设置为对本地交换单元 与第一本框交换单元和第二本框交换单元之间进行链路聚合的各个端口进行负荷分 配。 图 8是根据本发明实施例的报文转发装置的优选结构框图二, 如图 8所示, 该优 选结构除包括图 5中的所有模块外, 还包括: 配置模块 82, 下面对该配置模块 82进 行说明。 该配置模块 82, 连接至上述确定模块 52和传送模块 54, 设置为配置带双网卡的 中央控制器 CPU 中用于与本地交换单元交互控制信息的网卡的收包配额高于用于与 本地交换单元交互协议报文的网卡。 本发明实施例及优选实施方式中所涉及的集群路由器中内部控制面安全技术, 提 供的是一种提高集群路由器可靠性、 安全性的系统, 该系统包括控制消息通道和协议 报文通道分离的报文传送模型及其实现方法。 当集群路由器受到外部攻击或者在协议 报文很多的情况下, 保证内部控制消息的可靠传送和处理。 其中, 控制消息通道和协议报文通道分离的系统包括: 至少两个中心交换框、 至 少两个中心交换单元、 至少一个线卡框、 至少两个本框交换单元、 至少两个本地交换 单元、 至少两个带双网卡的 CPU、 至少一个接口卡。 中心交换框起到把各个线卡框连接起来的作用, 中心交换单元在中心交换框中, 各个线卡框连到中心交换单元上。 中心交换框和线卡框中都有本框交换单元、 本地交 换单元和 CPU, 并且每个框至少有两个本框交换单元。 线卡框和中心交换框上的本框 交换单元连接到中心交换单元和本框的本地交换单元, 本地交换单元连接到本框交换 单元和 CPU。 中心交换框是中心交换单元所在的框, 每个中心交换框至少要有一个中心交换单 元, 另外还有至少两个本框交换单元, 若干个本地交换单元和 CPU。 中心交换单元主要负责本框交换单元之间的交换, 一个框的某个本框交换单元与 另一个框的某个本框交换单元进行交换必须经过中心交换单元。 中心交换单元与本框 交换单元之间的链路通过 LACP协议进行链路聚合。 中心交换单元实现堆叠, 对本框 交换单元来说就像一个交换单元。两个中心交换单元既可以实现互为备份提高可靠性, 又可以让控制消息通道和协议报文通道分开, 一个中心交换单元交换协议报文, 另一 个交换控制消息。 线卡框中有本框交换单元和本地交换单元还有处理报文的 CPU。 本框交换单元有两个作用, 一个是用来把本框连接到中心交换框, 使本框与其它 框之间能通信。 另一个用作是实现本框中本地交换单元的互联, 使本框中的本地交换 之间能通信, 也使它们与其它框进行通信。 本框交换单元也实现堆叠, 对外呈现就像 一个交换单元一样。 本地交换单元主要负责把本地 CPU的协议报文和控制消息交换到中心交换单元, 并且从本框交换单元接收协议报文和控制消息。 本地交换单元与两个本框交换单元都 有链路连接, 一方面进行链路冗余, 提高带宽, 另一方面也是能让控制消息通道和协 议报文通道分开。 其与本框交换单元相连的端口通过 LACP协议进行链路聚合, 链路 聚合允许一条或多条链路聚合到一起, 形成链路聚合群。 报文经过聚合组发送时, 根 据负荷分担原则, 决定从此聚合组中的哪个端口发送, 负荷分担原则一般有很多种, 例如, 根据源、 目的 MAC地址, 源、 目的 MAC地址加上 VLAN, 源、 目的 IP等。 带双网卡的 CPU, 其中一个网卡负责收发协议报文, 另一个收发控制消息, 这样 也达到了控制消息通道和协议报文通道分开的效果。当把 CPU的两个网卡的收包配额 配置为收发控制消息的网卡比收发协议报文的网卡高, 则保证了控制消息能优先被
CPU接收处理, 也就是提高了路由器内部的可靠性。每个 CPU网卡的 MAC地址要合 理分配,让聚合组进行负荷分担时可以把协议报文和控制消息从不同的端口发送出去。 接口卡主要是与外部网络相连, 从外部网络接收报文, 如果检测到报文是协议报 文需要本路由器处理, 那么会转发给路由器内部的 CPU。 当本路由器内部的 CPU需 要转发报文给其它的路由器时, 也需要通过接口卡转发出去。 根据本发明实施例所提供的控制消息通道和协议报文通道分离的处理包括以下几 个方面: (1 ) 两个中心交换单元实现堆叠。 (2) 决策中心交换单元与本框交换单元之 间的链路是否加入聚合组。 (3 ) 设置中心交换单元的负荷分担规则, 设定一个中心交 换单元交换协议报文, 另一个交换控制消息。 (4) 设置网卡的 MAC地址。 (5 ) 端口 通过 LACP报文协商加入链路聚合, 同时设定为发送协议报文的端口还是发送控制消 息的端口。 下面结合附图对本发明优选实施例的控制消息通道和协议报文通道分离系统进行 说明。 图 9是根据本发明优选实施例的控制消息通道和协议报文通道分离系统的结构示 意图, 如图 9所示, 该系统包括: 两个中心交换框、 两个线卡框。 每个框都由框号来进行标识, 线卡框和中心框的 编号可以连续编号, 也可以分开进行编号, 现在设定上面线卡框为 1号, 下面线卡框 为 2号, 左边中心交换框为 3号, 右边中心交换框为 4号, 每个框中的本框交换单元 也设置有编号, 该编号为槽位号, 在左边的其槽位号比右边的小, 这些编号都不是固 定的, 只是为了后边的描述方便。 需要说明的是, 其中的中心交换框也可以有本框交 换单元、 本地交换单元以及 CPU, 线卡框 11 中也可以有接口卡; 另外, 在本发明实 施例及优选实施例中所指的报文通道分离既可以是线卡框和线卡框之间, 也可以是线 卡框和中心框之间。 为了更容易把组成结构原理和方法说明清楚, 在图 9中作了一些 简化, 例如, 图中的本框交换单元 31或本框交换单元 33与上述的第一本框交换单元 31相当, 图中的本框交换单元 32或本框交换单元 34与上述的第二本框交换单元 32 相当; 图中的中心交换框 13与上述的第一中心交换框 13相当, 图中的中心交换框 14 与上述的第二中心交换框 14相当; 图中的中心交换单元 21与上述的第一中心交换单 元 21相当, 图中的中心交换单元 22与上述的第二中心交换单元 22相当; 图中的本地 交换单元 41和本地交换单元 42与上述的本地交换单元 222相当; 控制网卡 1或控制 网卡 2相当于上述网卡 1,协议网卡 1或协议网卡 2相当于上述网卡 2; CPU 1和 CPU 2相当于上述带双网卡的 CPU 32。
CPU分别连到本框的两个本框交换单元, 每个线卡框的本框交换单元都会连接到 两个中心交换单元上, 这样每个本框交换单元都可以转发报文给任何一个中心交换单 元,但是这样导致路由器外部进来的协议报文和路由器内部的控制消息通道不能分开, 会经过同一个中心交换单元或同一个本框交换单元。 要把协议报文和控制消息通道分离, 两个中心交换单元之间需要堆叠, 同时每个 框中的本框交换单元之间也要堆叠。 堆叠的交换单元之间要通过定时和变化的同步方 式来同步堆叠信息。 通过这两种同步方式来维护堆叠交换单元的端口, 也就是把对方 端口加入到本交换单元的聚合组中或从聚合组中删除, 并实现堆叠的各个交换单元之 间端口和聚合组的信息一致。 各个交换单元的端口通过 LACP协议加入聚合组或从聚 合组删除, 端口信息就是指端口加入到聚合组或从聚合组删除的信息, 以及端口对应 的聚合组编号。 一方面需要定时同步端口信息到另一个交换单元, 另一个交换单元接收到该同步 端口信息后, 要和自己之前保留的此端口信息进行比较并更新。 另一方面是变化同步 端口信息到另一个交换单元, 当本交换单元的端口状态发生了改变, 本端就要将这个 端口添加到聚合组中或者从聚合组中删除, 同时要立即发送通知消息到另一个交换单 元, 对端接收到端口的状态信息发生改变后, 就在这个端口对应的聚合组中, 完成对 这个端口添加或者删除动作。 堆叠的交换单元要保持一张对端已加入聚合组中端口的 全局表, 内容有: 端口的聚合组号, 端口号, 端口所属设备的芯片号, 设备的芯片号 也就是指参与堆叠的交换单元的编号, 以区分它们。 当收到对端的变化同步或定时同 步报文后, 把报文中的信息和全局表中的信息进行比较, 更新全局表中的信息, 以此 来达到本端与对端的信息同步。 定时同步保证全局表中内容的一致性, 变化同步保证 全局表中内容的实时性。 定时同步主要是弥补变化同步失败的不足, 如果变化同步失 败, 过一定时间定时同步还是能保证两端信息的一致。 现在两个中心交换单元以及每个框中的本框交换单元都完成了堆叠, 那么每个线 卡框的本框交换单元上与中心交换单元的端口就都在一个聚合组了, 当规定本框交换 单元 31和中心交换单元 21只转发控制消息, 本框交换单元 32和中心交换单元 22只 转发协议报文, 本框交换单元 31的控制消息还是可能会转发到中心交换单元 22上, 那么通道还是不能分开。 怎么让转发协议报文的本框交换单元只把协议报文转发给只 转发协议报文的中心交换单元, 以及让转发控制消息的本框交换单元只把控制消息转 发给只转发控制消息的中心交换单元, 那么还需要设置中心交换单元与本框交换单元 之间的链路, 让交叉的链路不转发报文, 交叉的链路也就是转发协议报文的本框交换 单元与转发控制消息的中心交换单元之间的链路, 同理还包括转发控制消息的本框交 换单元与转发协议报文的中心交换单元之间的链路, 但不是让这种交叉链路永远不能 转发报文, 当直连链路故障时, 交叉链路要能在一百五十毫秒的时间内完成能转发报 文的准备。 为了达到这种效果, 需要按照以下原理完成下面几步: 首先, 中心交换单元的端口发送 LACP报文时, 此报文的源 MAC中两个字节分 别为中心交换单元的框号、 槽位号, 两个中心交换单元的框号、 槽位号至少有一个不 同, 这样根据此两项就可以把两个中心交换单元区分开来。 本框交换单元的端口收到中心交换单元的 LACP报文后,从 LACP报文的源 MAC 中解析出中心交换单元的框号、 槽位号, 看是否收到两个中心交换单元的报文, 如果 只收到一个的, 那么此端口正常通过 LACP报文协商加入聚合组。 如果本框交换单元收到两个中心交换单元的 LACP报文, 那么比较中心交换框的 框号的大小, 如果两个中心交换单元插到一个框内, 那么比较槽位号大小。 当是框中 左边的本框交换单元时, 其与框号小的中心交换单元相连的端口正常通过 LACP报文 协商加入聚合组, 其与框号大的中心交换单元相连的端口只是通过 LACP报文协商但 是协商成功后不加入聚合组, 端口状态是为不转发报文的 BLOCK状态, 并且还要依 赖在发给框号大的中心交换单元的 LACP 报文保留字段中添加是否加入聚合组的标 志, 然后把此标志设置为不加入聚合组发送出去, 该标志在 LACP 报文中的位置为 Aggregation—Flag字段。中心交换单元收到此标志后,也会让本端的端口不加入聚合组 且设置为 BLOCK状态。 按此推理, 当为框中右边的本框交换单元时, 其与框号大的中心交换单元相连的 端口正常通过 LACP报文协商加入聚合组, 其与框号小的中心交换单元相连的端口只 是通过 LACP 报文协商但是协商成功后不加入聚合组, 且为 BLOCK状态, 还要把 LACP报文中是否加入聚合组的标志设置为不加入聚合组。 结合附图 9 所示的结构, 在本优选实施例中还提供了一种报文转发方法, 图 10 是根据本发明实施例的报文转发过程的流程图, 如图 10所示, 该流程包括如下步骤: 步骤 S1002, 中心交换单元端口发送带有框号、 槽位号信息的 LACP报文, 进入 步骤 S1004; 步骤 S1004, 判断是否为槽位号小的本框交换单元, 在判断为是的情况下, 进入 步骤 S1006, 否则进入步骤 S1008; 步骤 S1006, 判断是否本框交换单元收到的 LACP报文为中心交换单元 21的, 在 判断为是的情况下, 进入步骤 S1010, 否则进入步骤 S1012; 步骤 S1008, 判断是否本框交换单元收到的 LACP报文为中心交换单元 22的, 在 判断为是的情况下, 进入步骤 S1018, 否则进入步骤 S1020; 步骤 S1010, 端口通过 LACP报文协商加入聚合组, 进入步骤 S1014; 步骤 S1012, 端口只进行 LACP报文协商但不加入聚合组, 进入步骤 S1016; 步骤 S1014, 链路 91故障, 从聚合组中删除, 进入步骤 S1016; 步骤 S1016, 链路 92加入聚合组; 步骤 S1018, 端口通过 LACP报文协商加入聚合组, 进入步骤 S1022; 步骤 S1020, 端口只进行 LACP报文协商但不加入聚合组, 进入步骤 S1024; 步骤 S1022, 链路 94故障, 从聚合组中删除, 进入步骤 S1024; 步骤 S1024, 链路 93加入聚合组。 按照上述方法处理之后, 把那些不转发报文的链路去除后, 图 11是根据本发明实 施例的去除不转发报文的链路后的控制消息和协议报文的通道分离的结构示意图, 如 图 11所示, 此时整个系统中各个交换单元的连接关系为: 线卡框 11的 CPU与线卡框 12的 CPU、接口卡通信在物理上就存在两条单独的通道, 为控制消息和协议报文的通 道分离打下了坚实的基础。 需要说明的是, 本框交换单元与中心交换单元之间交叉的链路, 也就是 LACP协 商成功了但不加入聚合组的链路, 它们并不是一直不加入聚合组, 当槽位号小的本框 交换单元 31与框号小的中心交换单元 21的链路故障不能正常通信时, 那么会在一百 五十毫秒的时间内, 本框交换单元 31与中心交换单元 21之间的通信链路会切换到本 框交换单元 31 和中心交换单元 22之间的链路, 此链路会被加入聚合组。 当链路 91 的通信恢复正常后, 链路 92又被从聚合组中删除, 且不能转发控制消息和协议报文。 物理上隔开的两条通道已经形成了, 那么怎么让协议报文和控制消息各走一条通 道, 这就需要设置网卡和接口卡的 MAC地址, 以及设置中心交换单元、 本框交换单 元、 本地交换单元的负荷分担规则。 步骤如下: 设置 CPU的协议网口 MAC和接口卡 MAC地址的低三位比特为 100,例如, MAC 地址的形式为 BYTEO: BYTE1: BYTE2: BYTE3: BYTE4: BYTE5, 那么字节 BYTE5的 低三位比特为 100。 设置 CPU的控制面网口 MAC的底三位比特为 000。 设置框号小的中心交换单元和槽位号小的本框交换单元转发控制消息, 就是这些 交换单元只转发报文中源 MAC的底三位比特为 000的报文。 设置框号大的中心交换单元和槽位号大的本框交换单元转发协议报文, 就是这些 交换单元只转发报文中源 MAC的底三位比特为 100的报文。 设置本地交换单元上与槽位号小的本框交换单元相连的端口只转发控制消息, 即 当某个报文需要从本地交换单元转发到本框交换单元时, 如果此报文源 MAC 的底三 位比特为 000时, 则从此端口转发出去。 设置本地交换单元上与槽位号大的本框交换单元相连的端口只转发协议报文, 即 当某个报文需要从本地交换单元转发到本框交换单元时, 如果此报文源 MAC 的底三 位比特为 100时, 则从此端口转发出去。 如果一个中心交换单元故障,那么所有报文都从另外一个中心交换单元转发出去。 同理当一个框中的某个本框交换单元故障时, 另外一个则会转发所有报文。 另外本地 交换单元的某个端口故障时, 则另外一个端口会转发和接收所有报文。 综上所述全部设置完成后,如图 11所示,控制消息的通道为:本框交换单元 31— 中心交换单元 21——本框交换单元 33, 协议报文的通道为: 本框交换单元 32——中 心交换单元 22—本框交换单元 34。这里所划分的一条通道走控制消息, 一条通道走 协议报文, 不是固定不变的, 也可以是图 11中所示左边的那条走控制消息的通道用来 转发协议报文, 而另外的那一条转发控制消息。 显然, 本领域的技术人员应该明白, 上述的本发明的各模块或各步骤可以用通用 的计算装置来实现, 它们可以集中在单个的计算装置上, 或者分布在多个计算装置所 组成的网络上, 可选地, 它们可以用计算装置可执行的程序代码来实现, 从而, 可以 将它们存储在存储装置中由计算装置来执行, 并且在某些情况下, 可以以不同于此处 的顺序执行所示出或描述的步骤, 或者将它们分别制作成各个集成电路模块, 或者将 它们中的多个模块或步骤制作成单个集成电路模块来实现。 这样, 本发明不限制于任 何特定的硬件和软件结合。 以上所述仅为本发明的优选实施例而已, 并不用于限制本发明, 对于本领域的技 术人员来说, 本发明可以有各种更改和变化。 凡在本发明的精神和原则之内, 所作的 任何修改、 等同替换、 改进等, 均应包含在本发明的保护范围之内。

Claims

权 利 要 求 书
1. 一种报文转发系统, 包括:
包括第一本框交换单元和第二本框交换单元的线卡框;
包括第一中心交换单元的第一中心交换框;
包括第二中心交换单元的第二中心交换框;
其中, 所述第一本框交换单元和第二本框交换单元与所述第一中心交换单 元和所述第二中心交换单元之间存在分离的控制消息通道和协议报文通道。
2. 根据权利要求 1所述的系统, 其中, 所述第一本框交换单元和第二本框交换单 元与所述第一中心交换单元和所述第二中心交换单元之间存在分离的控制消息 通道和协议报文通道包括:
所述第一本框交换单元与所述第一中心交换单元之间的链路为控制消息通 道, 所述第二本框交换单元与所述第二中心交换单元之间的链路为协议报文通 道; 或者,
所述第一本框交换单元与所述第二中心交换单元之间的链路为控制消息通 道, 所述第二本框交换单元与所述第一中心交换单元之间的链路为协议报文通 道。
3. 根据权利要求 1所述的系统, 其中, 还包括:
本地交换单元, 连接于所述第一本框交换单元和所述第二本框交换单元, 设置为分别与所述第一本框交换单元和所述第二本框交换单元交互控制消息和 协议报文。
4. 根据权利要求 3所述的系统, 其中, 还包括:
带双网卡的中央控制单元 CPU, 连接于所述本地交换单元, 其中, 一个网 卡用于与所述本地交换单元交互控制消息, 另一个网卡用于与所述本地交换单 元交互协议报文。
5. 一种报文转发方法, 包括: 确定线卡框中第一本框交换单元和第二本框交换单元与第一中心交换框中 第一中心交换单元和第二中心交换框中第二中心交换单元之间分离的控制消息 通道和协议报文通道;
根据确定的所述控制消息通道和所述协议报文通道分别传送控制消息和协 议报文。 根据权利要求 5所述的方法, 其中, 确定线卡框中第一本框交换单元和第二本 框交换单元与第一中心交换框中第一中心交换单元和第二中心交换框中第二中 心交换单元之间分离的控制消息通道和协议报文通道包括: 将所述第一本框交换单元与所述第二本框交换单元堆叠, 所述第一中心交 换单元与所述第二中心交换单元堆叠, 其中, 实现堆叠的交换单元之间用于形 成通道的端口的端口信息同步;
通过所述端口报文协商是否加入链路聚合组的方式确定所述控制消息通道 和所述协议报文通道。 根据权利要求 6所述的方法, 其中, 在根据确定的所述控制消息通道和所述协 议报文通道分别传送控制消息和协议报文之前, 还包括:
对本地交换单元与所述第一本框交换单元和所述第二本框交换单元之间进 行链路聚合的各个端口进行负荷分配。 根据权利要求 6所述的方法, 其中, 在根据确定的所述控制消息通道和所述协 议报文通道分别传送控制消息和协议报文之前, 还包括:
配置带双网卡的中央控制器 CPU 中用于与本地交换单元交互控制信息的 网卡的收包配额高于用于与所述本地交换单元交互协议报文的网卡。 一种报文转发装置, 包括:
确定模块, 设置为确定线卡框中第一本框交换单元和第二本框交换单元与 第一中心交换框中第一中心交换单元和第二中心交换框中第二中心交换单元之 间分离的控制消息通道和协议报文通道;
传送模块, 设置为根据确定的所述控制消息通道和所述协议报文通道分别 传送控制消息和协议报文。 根据权利要求 9所述的装置, 其中, 所述确定模块包括: 堆叠单元,设置为将所述第一本框交换单元与所述第二本框交换单元堆叠, 所述第一中心交换单元与所述第二中心交换单元堆叠, 其中, 实现堆叠的交换 单元之间用于形成通道的端口的端口信息同步;
确定单元, 设置为通过所述端口报文协商是否加入链路聚合组的方式确定 所述控制消息通道和所述协议报文通道。 根据权利要求 10所述的装置, 其中, 还包括:
分配模块, 设置为对本地交换单元与所述第一本框交换单元和所述第二本 框交换单元之间进行链路聚合的各个端口进行负荷分配。 根据权利要求 10所述的装置, 其中, 还包括:
配置模块,设置为配置带双网卡的中央控制器 CPU中用于与本地交换单元 交互控制信息的网卡的收包配额高于用于与所述本地交换单元交互协议报文的 网卡。
PCT/CN2013/083685 2013-02-21 2013-09-17 报文转发系统、方法及装置 WO2014127629A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US14/769,266 US9998366B2 (en) 2013-02-21 2013-09-17 System, method and device for forwarding packet
EP13875436.1A EP2961112B1 (en) 2013-02-21 2013-09-17 Message forwarding system, method and device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310055687.4 2013-02-21
CN201310055687.4A CN103152260B (zh) 2013-02-21 2013-02-21 报文转发系统、方法及装置

Publications (1)

Publication Number Publication Date
WO2014127629A1 true WO2014127629A1 (zh) 2014-08-28

Family

ID=48550132

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/083685 WO2014127629A1 (zh) 2013-02-21 2013-09-17 报文转发系统、方法及装置

Country Status (4)

Country Link
US (1) US9998366B2 (zh)
EP (1) EP2961112B1 (zh)
CN (1) CN103152260B (zh)
WO (1) WO2014127629A1 (zh)

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103152260B (zh) * 2013-02-21 2019-02-15 中兴通讯股份有限公司 报文转发系统、方法及装置
CN103532853B (zh) * 2013-10-21 2016-11-09 杭州华三通信技术有限公司 异构型堆叠模型的实现方法和装置
CN105721234B (zh) * 2014-12-05 2019-04-05 杭州迪普科技股份有限公司 端口聚合方法及装置
CN105812288B (zh) * 2014-12-29 2020-04-10 中兴通讯股份有限公司 一种数据交换方法、多框互联系统及其框设备
CN106330781B (zh) * 2015-06-26 2020-02-07 中兴通讯股份有限公司 堆叠系统协议控制和转发链路分离的方法、装置及交换机
WO2017071729A1 (en) * 2015-10-26 2017-05-04 Abb Schweiz Ag Methods, nodes and system for establishing independent network paths
CN106533771B (zh) * 2016-11-24 2019-12-06 新华三技术有限公司 一种网络设备以及控制信息传输方法
CN106878180B (zh) * 2016-12-23 2020-01-03 新华三技术有限公司 集群路由器路由控制方法、装置和集群路由器
US10476815B2 (en) * 2017-12-11 2019-11-12 Ciena Corporation Adaptive communication network with cross-point switches
CN109688017A (zh) * 2019-01-31 2019-04-26 山东超越数控电子股份有限公司 一种双星型冗余拓扑架构系统及架构实现方法
CN112398731B (zh) 2019-08-15 2022-05-13 华为技术有限公司 一种处理报文的方法和第一网络设备
CN111181845B (zh) * 2019-12-31 2022-03-15 苏州盛科通信股份有限公司 实现lacp主备高可用性的方法和基于lacp的堆叠系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007131523A1 (en) * 2006-05-15 2007-11-22 Telecom Italia S.P.A. Out-of-band authentication method and system for communication over a data network
CN101753438A (zh) * 2009-12-08 2010-06-23 中兴通讯股份有限公司 实现通道分离的路由器及其通道分离的传输方法
CN102724099A (zh) * 2012-06-01 2012-10-10 中兴通讯股份有限公司 提升多处理机系统控制面内部通信Qos的装置及方法
CN103152260A (zh) * 2013-02-21 2013-06-12 中兴通讯股份有限公司 报文转发系统、方法及装置

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030200330A1 (en) 2002-04-22 2003-10-23 Maxxan Systems, Inc. System and method for load-sharing computer network switch
US7292581B2 (en) * 2002-10-24 2007-11-06 Cisco Technology, Inc. Large-scale layer 2 metropolitan area network
US7804769B1 (en) * 2005-12-01 2010-09-28 Juniper Networks, Inc. Non-stop forwarding in a multi-chassis router
CN100563145C (zh) * 2006-03-03 2009-11-25 华为技术有限公司 Rpr中的捆绑接口及其实现方法和装置
KR101504723B1 (ko) * 2007-10-24 2015-03-20 삼성전자 주식회사 스패닝트리 프로토콜을 지원하는 네트워크 시스템과 그연결장치 및 스패닝트리 생성 방법
CN101631081B (zh) * 2009-08-12 2011-06-08 华为技术有限公司 一种多级交换网
GB2482118B (en) 2010-07-19 2017-03-01 Cray Uk Ltd Ethernet switch with link aggregation group facility
CN102821033B (zh) * 2011-06-10 2017-04-12 中兴通讯股份有限公司 一种报文传输方法及装置
US8942139B2 (en) * 2011-12-07 2015-01-27 International Business Machines Corporation Support for converged traffic over ethernet link aggregation (LAG)
CN102724030A (zh) * 2012-06-29 2012-10-10 杭州迪普科技有限公司 一种高可靠性的堆叠系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007131523A1 (en) * 2006-05-15 2007-11-22 Telecom Italia S.P.A. Out-of-band authentication method and system for communication over a data network
CN101753438A (zh) * 2009-12-08 2010-06-23 中兴通讯股份有限公司 实现通道分离的路由器及其通道分离的传输方法
CN102724099A (zh) * 2012-06-01 2012-10-10 中兴通讯股份有限公司 提升多处理机系统控制面内部通信Qos的装置及方法
CN103152260A (zh) * 2013-02-21 2013-06-12 中兴通讯股份有限公司 报文转发系统、方法及装置

Also Published As

Publication number Publication date
US9998366B2 (en) 2018-06-12
CN103152260B (zh) 2019-02-15
EP2961112A4 (en) 2016-03-09
US20160065458A1 (en) 2016-03-03
EP2961112B1 (en) 2019-08-07
CN103152260A (zh) 2013-06-12
EP2961112A1 (en) 2015-12-30

Similar Documents

Publication Publication Date Title
CN103152260B (zh) 报文转发系统、方法及装置
US9143439B2 (en) System and method for cluster link aggregation control in a network environment
US9088511B2 (en) Multi-hop error recovery
US11418629B2 (en) Methods and systems for accessing remote digital data over a wide area network (WAN)
CN101325497B (zh) 在不存在自动协商标准的接口上的自动协商
EP2701342A1 (en) Method and system for implementing elastic network interface and interconnection
US20140325038A1 (en) Technique for Configuring a Software-Defined Network
US20080137669A1 (en) Network of nodes
CN103986663A (zh) 数据中心及其实现数据处理的方法和网络控制器
EP2911355B1 (en) Method and device for flow path negotiation in link aggregation group
WO2021082812A1 (zh) 报文的发送方法和第一网络设备
CN110740093B (zh) 一种基于虚拟主机的数据转发装置
WO2020078043A1 (zh) 一种确定组播流的df的方法、设备及系统
CN106533771B (zh) 一种网络设备以及控制信息传输方法
WO2011140873A1 (zh) 光传输层的数据传输方法及装置
WO2013004115A1 (zh) 网络设备中单板间进行报文交互的方法及网络设备
US20220224636A1 (en) System and method for performing synchronization of maximum transmission unit with router redundancy
KR101503717B1 (ko) 네트워크 장치 및 이에 이용되는 데이터 송수신 방법
WO2016082516A1 (zh) 一种链路捆绑方法及系统
CN107659499B (zh) 一种路由的方法及转发设备
WO2008148330A1 (fr) Système et procédé d'acheminement de données
EP4109862A1 (en) Data transmission method, system, device, and storage medium
KR20130134422A (ko) 링 네트워크 토폴로지에서 프레임기반 라우팅을 이용한 프레임 무손실 통신 방법
WO2022143572A1 (zh) 一种报文处理方法及相关设备
KR101308089B1 (ko) 고가용성을 지원하기 위한 IPSec VPN 시스템 및 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13875436

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2013875436

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 14769266

Country of ref document: US