WO2016180351A1 - Endpoint migration detection - Google Patents
Endpoint migration detection Download PDFInfo
- Publication number
- WO2016180351A1 WO2016180351A1 PCT/CN2016/081832 CN2016081832W WO2016180351A1 WO 2016180351 A1 WO2016180351 A1 WO 2016180351A1 CN 2016081832 W CN2016081832 W CN 2016081832W WO 2016180351 A1 WO2016180351 A1 WO 2016180351A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- immigration
- packet
- endpoint
- route entry
- address
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/34—Source routing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/02—Topology update or discovery
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L45/00—Routing or path finding of packets in data switching networks
- H04L45/74—Address processing for routing
- H04L45/745—Address table lookup; Address filtering
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2212/00—Indexing scheme relating to accessing, addressing or allocation within memory systems or architectures
- G06F2212/15—Use in a specific computing environment
- G06F2212/151—Emulated environment, e.g. virtual machine
Definitions
- the Locator/Identity Separation Protocol (LISP) networking scheme may provide two independent address spaces, namely Endpoint Identifier (ELD) address and Routing Locator (RLOC) address.
- ELD Endpoint Identifier
- RLOC Routing Locator
- the EID address is an address of a host of an endpoint, used to identify the identity of the host.
- the role of the EID address in the LISP is similar to a Domain Name System (DNS) , and the EID address possesses a separate address space.
- the EID address may be migrated independently of the RLOC address. During the migration of an endpoint, the EID address of the host of the endpoint is changeless.
- the RLOC address is an address of a LISP router, and may be routing forwarded in an Internet. The RLOC address may be globally routed, and may be aggregated according to network topologies.
- the endpoint may be a server, a virtual machine connected to a router, or a mobile terminal, such as a mobile phone, an iPAD, a notebook computer.
- FIG. 1 is a flow diagram illustrating a method for detecting immigration of an endpoint according an example of the present disclosure.
- FIG. 2 is a flow diagram illustrating a method for detecting immigration of an endpoint according another example of the present disclosure.
- FIG. 3 is a schematic diagram illustrating a LISP network in which a virtual machine migrates from one network segment to another network segment according to examples of the present disclosure.
- FIG. 4 is a schematic diagram illustrating a LISP network in which a virtual machine migrates in the same network segment according to examples of the present disclosure.
- FIG. 5 is a schematic diagram illustrating a device for detecting immigration of an endpoint according an example of the present disclosure.
- FIG. 6 is a schematic diagram illustrating a device for detecting immigration of an endpoint according another example of the present disclosure.
- the migration detection of an endpoint is usually achieved through a hardware chip of a router.
- the hardware chip of the router cannot support the detection function, the immigration of an endpoint cannot be detected by the router.
- software logic is utilized to perform the migration detection of the endpoint by taking the place of the hardware chip.
- migration data may be sent to a LISP thread, and then the migration detection of the endpoint may be performed by inquiring the data of the LISP thread.
- the migration data may include initial configuration data and running data generated during the running of the LISP thread.
- the configuration data may include at least one of the followings.
- Dynamic-EID strategy configuration the dynamic-EID strategy is used to specify information of an immigration network segment.
- the xTR is a router supporting the functions both of an Ingress Tunnel Router (ITR) and an Egress Tunnel Router (ETR) .
- ITR Ingress Tunnel Router
- ETR Egress Tunnel Router
- the number of the network segments may be specified as required.
- An endpoint matching the immigration network segment may immigrates, namely an endpoint of which the Internet Protocol (IP) address is within the immigration network segment is permitted to immigrate.
- IP Internet Protocol
- Interface migration configuration in order to migrate in the same network segment, it is necessary to configure an extend-subnet-mode command on an interface, on which an endpoint immigration event should be detected.
- an extend-subnet-mode command is configured on an interface, on which an endpoint immigration event should be detected. If the extend-subnet-mode command is not configured on the interface, it may be a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment, and an endpoint immigration event will not be reported.
- the dynamic-EID strategy may be enabled on the interface, on which an endpoint immigration event should be detected (namely the interface on which the immigration detection should be performed) .
- Multiple dynamic-EID strategies may be enabled on one interface. It is not necessary to perform endpoint immigration detection on an interface, on which no dynamic-EID strategy is enabled.
- Running data may include at least one of the followings.
- the network segment of the interface on which the immigration detection should be performed includes the immigration network segment configured by the dynamic-EID strategy, it is determined that there is a direct route.
- a direct route in a scenario of migration in the same network segment, namely a same-network segment immigration scenario, and there is not a direct route in a scenario of migration from one network segment to another network segment, namely a cross-network segment immigration scenario.
- the xTR will generates a Null0 route entry corresponding to the dynamic-EID strategy, and the Null0 route entry may be called configuration Null0 route entry.
- a network segment route entry of which the egress interface is Null, is generated corresponding to the immigration network segment specified by the dynamic-EID strategy. Since there does not exist a direct route in the cross-network segment immigration scenario, the xTR will generates a configuration Null0 route entry for detecting the cross-network segment immigration.
- the xTR may generate a 32-bit immigration host route entry, of which the egress interface is the interface receiving a packet of the endpoint.
- the immigration host route entry may be used to indicate that an endpoint immigrates to the site, and when a sequent packet matches the immigration host route entry, the endpoint immigration event will not be reported again.
- the xTR will send a map-register packet for the endpoint to a map-server (MS) .
- MS map-server
- the xTR may also send a multicast map-notify packet to other xTRs in the same multicast group.
- the map-server may determine whether information that the endpoint has been registered on an xTR in another data center is recorded in the map-server, when the information is recorded in the map-server, the map-server may send a map-notify packet to the xTR in the another data center, and update the register information of the endpoint.
- Emigration Null0 route entry namely a host route entry of which the egress interface is null.
- the xTR may generate a 32-bit emigration Null0 route entry to indicate that the endpoint emigrates from the site. That is to say, when receiving a map-notify packet sent by the map-server or a multicast map-notify packet sent by that xTR, the xTR in the another data center may determine whether there exists a immigration host route entry, namely a host route entry of which the egress interface is not null, when there exists the immigration host route entry, delete the immigration host route entry; and determine whether there exists a configuration Null0 route entry, when there exists the configuration Null0 route entry, ignores the map-notify packet; when there does not exist the configuration Null0 route entry, corresponding to the IP address of the endpoint, generate a host route entry, of which the egress interface is null, namely an emigration Null0 route entry.
- FIG. 1 is a flow diagram illustrating a method for detecting immigration of an endpoint according an example of the present disclosure. As shown in FIG. 1, the method may include the following processes.
- an xTR receives a packet sent by an endpoint, and searches for a migration route entry from the xTR utilizing a source IP address of the packet.
- the migration route entry may be an immigration host route entry, a configuration Null0 route entry, or an emigration Null0 route entry.
- the configuration Null0 route entry is a network segment route entry of which the egress interface is null; the emigration Null0 route entry is a host route entry of which the egress interface is null.
- the configuration Null0 route entry and the emigration Null0 route entry are respectively a route entry of which the egress interface is null.
- the xTR may report an endpoint immigration event.
- the route entry of which the egress interface is null is the emigration Null0 route entry, it may indicate a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment.
- the route entry of which the egress interface is null is the configuration Null0 route entry, it may indicate a scenario that an endpoint immigrates to this network segment for the first time, namely a cross-network segment immigration scenario.
- the xTR may not report the endpoint immigration event.
- the xTR may determine whether the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when determining that the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, the xTR may further determine whether an extend-subnet-mode command is configured on the interface receiving the packet, and when the extend-subnet-mode command is configured on the interface receiving the packet, report the endpoint immigration event; when determining that the source IP address of the packet and the IP address of the interface receiving the packet do not belong to the same network segment, or when the extend-subnet-mode command is not configured on the interface receiving the packet, not report the endpoint immigration event.
- the xTR may not report the endpoint immigration event.
- FIG. 2 is a flow diagram illustrating a method for detecting immigration of an endpoint according another example of the present disclosure. As shown in FIG. 2, the method may include the following processes.
- an xTR receives a packet sent by an endpoint.
- the xTR determines whether a dynamic-EID strategy is enabled on the interface receiving the packet, when the dynamic-EID strategy is enabled on the interface receiving the packet, block 203 is performed; otherwise, block 208 is performed.
- the xTR determines whether a source IP address of the packet matches an immigration network segment specified by the enabled dynamic-EID strategy, when the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, block 204 is performed; otherwise, block 208 is performed.
- the longest matching principle may be utilized to perform the match of the source IP address of the packet with the immigration network segment specified by the enabled dynamic-EID strategy.
- block 203 may be executed before block 202, namely, the xTR may determine whether a source IP address of the packet matches an immigration network segment specified by the enabled dynamic-EID strategy first, and when the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, the xTR determines whether a dynamic-EID strategy is enabled on the interface receiving the packet, and when the dynamic-EID strategy is enabled on the interface receiving the packet, block 204 is performed.
- the xTR locally searches for a migration route entry utilizing the source IP address of the packet.
- block 208 is performed; when finding a route entry of which the egress interface is null, block 207 is performed; when not finding a route entry of which the egress interface is null or the immigration host route entry, block 205 is performed.
- the route entry of which the egress interface is null may be a configuration Null0 route entry or an emigration Null0 route entry.
- the route entry of which the egress interface is null is the emigration Null0 route entry, it may indicate a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment.
- the route entry of which the egress interface is null is the configuration Null0 route entry, it may indicate a scenario that an endpoint immigrates to this network segment from other network segment.
- the immigration host route entry When there exist simultaneously the configuration Null0 route entry and the immigration host route entry, the immigration host route entry will be found first, and the configuration Null0 route entry will not be found.
- the xTR determines whether the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, block 206 is performed; otherwise, block 208 is performed.
- the xTR determines whether an extend-subnet-mode command is configured on the interface receiving the packet, when the extend-subnet-mode command is configured on the interface receiving the packet, block 207 is performed; otherwise, block 208 is performed.
- the xTR reports the endpoint immigration event, and generates an immigration host route entry corresponding to the source IP address of the packet, of which the egress interface is the interface receiving the packet. According to the immigration host route entry, the endpoint immigration event will not be reported again when a sequent packet matches the immigration host route entry.
- the xTR when the xTR reports the endpoint immigration event to a CPU of the xTR, and the CPU performs the relevant processing, the xTR may send a map-register packet for the endpoint to a map-server.
- the xTR may also send a multicast map-notify packet to other xTRs in the same multicast group.
- the xTRs in the same multicast group may send a valid forwarding route entry to the forwarding layer of the router, and the xTRs in a different multicast group may send an invalid forwarding route entry to the forwarding layer of the router.
- the map-server may determine whether information that the endpoint has been registered on an xTR in another data center is recorded in the map-server, when the information is recorded in the map-server, the map-server may send a map-notify packet to the xTR in the another data center, and update the register information of the endpoint.
- the xTR in the another data center may determine whether there exists a immigration host route entry, namely a host route entry of which the egress interface is not null, when there exists the immigration host route entry, delete the immigration host route entry; and determine whether there exists a configuration Null0 route entry, when there exists the configuration Null0 route entry, ignores the map-notify packet; when there does not exist the configuration Null0 route entry, corresponding to the IP address of the endpoint, generate a host route entry, of which the egress interface is null, namely an emigration Null0 route entry.
- the xTR does not report the endpoint immigration event.
- a dynamic-EID strategy may be configured to specify an immigration network segment, so that an endpoint of which the IP address is within the immigration network segment may immigrate.
- the dynamic-EID strategy may be enabled on an interface, on which an endpoint immigration event should be detected, so that endpoint immigration detection may be performed on the interface, namely the endpoint immigration detection may be performed in a limited range.
- the router By performing the endpoint immigration detection on a software level, the router may be not limited by the hardware.
- FIG. 3 is a schematic diagram illustrating a LISP network in which a virtual machine migrates from one network segment to another network segment according to examples of the present disclosure.
- xTR1 in data center (DC) 1 and xTR2 in data center (DC) 2 are respectively configured with a dynamic-EID strategy in which an immigration network segment 10.17.1.0/24 is specified.
- the dynamic-EID strategy is respectively enabled on the interface 1 ofxTR1 and the interface 2 ofxTR2.
- the address of the interface 1 is 10.17.1.5/24
- the address of the interface 2 is 10.17.2.9/24. Because there is not a direct route corresponding to the network segment 10.17.1.0/24 on xTR2, xTR2 generates a network segment route entry of which the egress interface is null, namely a configuration Null0 route entry.
- VM B (of which the IP address is 10.17.1.65/32) goes online in DC1, and sends a gratuitous ARP packet.
- XTR1 receives the gratuitous ARP packet sent by VM B through the interface 1, and determines that the source IP address of the gratuitous ARP packet matches the immigration network segment specified by the dynamic-EID strategy enabled on the interface 1, and searches for a migration route entry utilizing the source IP address of the gratuitous ARP packet.
- xTR1 does not find a migration route entry, namely not find an immigration host route entry (the host route entry corresponding to the IP address 10.17.1.65/32) , or a configuration Null0 route entry (the network segment route entry of which the egress interface is null) .
- XTR1 further determines that the IP address of the interface 1 and the source IP address of the gratuitous ARP packet belong to the same network segment, and no extend-subnet-mode command is configured on the interface 1, xTR1 does not report a VM B immigration event, namely VM B is not deemed as a VM immigrating to DC1.
- XTR2 receives an IP data packet sent by VM B through the interface 2, and determines that the source IP address of the IP data packet matches the immigration network segment specified by the dynamic-EID strategy enabled on the interface 2, searches for a migration route entry utilizing the source IP address of the IP data packet, and finds a configuration Null0 route entry, namely, utilizing the source IP address 10.17.1.65/32, finds a network segment route entry, of which the egress interface is null, corresponding to the network segment 10.17.1.0/24.
- XTR2 reports a VM B immigration event, and corresponding to the source IP address 10.17.1.65/32 of VM B, generates a host route entry of which the egress interface is the interface 2 receiving the IP data packet, namely an immigration host route entry.
- xTR2 When xTR2 reports the VM B immigration event to a CPU of the xTR2, and the CPU performs the relevant processing, xTR2 sends a map-register packet for VM B to a map-server.
- the map-server may send a map-notify packet to the xTR1 in DC1, and update the register information of VM B.
- xTR1 in DC1 determines that there is not an immigration host route entry corresponding to the IP address 10.17.1.65/32, and generates an emigration Null0 route entry corresponding to the IP address, namely a host route entry corresponding to the IP address, of which the egress interface is null, to indicate that the address 10.17.1.65/32 is an IP address of a VM which emigrates from DC1.
- VM B migrates from DC2 to DC1, and sends a data packet to xTR1 in DC1
- xTR1 will find the emigration Null0 route entry according to the source IP address 10.17.1.65/32, and will report a VM B immigration event.
- FIG. 4 is a schematic diagram illustrating a LISP network in which a virtual machine migrates in the same network segment according to examples of the present disclosure.
- xTR1 in DC 1 and xTR2 in DC 2 are respectively configured with a dynamic-EID strategy in which an immigration network segment 10.17.1.0/24 is specified.
- the dynamic-EID strategy is respectively enabled on the interface 1 ofxTR1 and the interface 2 ofxTR2.
- the address of the interface 1 is 10.17.1.5/24
- the address of the interface 2 is 10.17.1.9/24. Because the virtual machine immigration is performed in the same network segment, it is necessary to configure an extend-subnet-mode command on both the interface 1 and the interface 2.
- xTRs in different DCs may communicated with each other via a configured layer-2.
- VM B goes online in DC1, and sends a gratuitous ARP packet to xTR1
- XTR1 receives the gratuitous ARP packet sent by VM B through the interface 1, and does not find a route entry of which the egress interface is null. xTR1 determines that the IP address of the interface 1 and the source IP address of the gratuitous ARP packet belong to the same network segment, and an extend-subnet-mode command is configured on the interface 1, xTR1 reports a VM B immigration event.
- xTR1 After detecting the immigration of VM B, xTR1 generates an immigration host route entry, namely a host route entry, corresponding to the IP address 10.17.1.65/32, of which the egress interface is the interface 1, and sends a multicast map-notify packet to a multicast group configured on the interface 1.
- XTR1 simultaneously sends a map-register packet to a map-server to register VM B, after receiving the map-register packet sent by xTR1, the map-server records register information of VM B registered on xTR1.
- xTR2 determines whether there is a host route entry corresponding to the IP address 10.17.1.65/32, when there is not the host route entry corresponding to the IP address 10.17.1.65/32, generates an emigration Null0 route entry, namely a host route entry corresponding to the IP address, of which the egress interface is null; when there is the host route entry corresponding to the IP address 10.17.1.65/32 and the egress interface of the host route entry is null, remain unchanged; when there is the host route entry corresponding to the IP address 10.17.1.65/32 and the egress interface is not null, namely there is an immigration host route entry, deletes the immigration host route entry, and generates an emigration Null0 route entry.
- VM B sends a data packet to xTR2 in DC2.
- XTR2 receives the data packet sent by VM B, and finds an emigration Null0 route entry corresponding to the source IP address 10.17.1.65/32 of the data packet, namely a host route entry corresponding to the source IP address 10.17.1.65/32, and the egress interface of the host route entry is null, xTR2 reports a VM B immigration event.
- xTR2 After detecting the immigration of VM B, xTR2 generates an immigration host route entry, namely a host route entry, corresponding to the IP address 10.17.1.65/32, of which the egress interface is the interface 2, and sends a multicast map-notify packet to a multicast group configured on the interface 2; sends a map-register packet to the map-server to register VM B. After updating the register information of VM B, the map-server sends a map-notify packet to xTR1.
- xTR1 determines that there is a host route entry corresponding to the IP address 10.17.1.65/32 and the egress interface of the host route entry is the interface 1, namely an immigration host route entry corresponding to the IP address 10.17.1.65/32, xTR1 deletes the immigration host route entry, and generates an emigration Null0 route entry corresponding to the IP address 10.17.1.65/32.
- FIG. 5 is a schematic diagram illustrating a device for detecting immigration of an endpoint according an example of the present disclosure.
- the device may include a configuring and storing unit 501, a receiving unit 502, a matching unit 503 and a processing unit 504.
- the configuring and storing unit 501 is adapted to configure a dynamic-EID strategy to specify an immigration network segment; and generate a configuration Null0 route entry corresponding to the immigration network segment, when determining to perform cross-network segment endpoint immigration detection according to the immigration network segment.
- the receiving unit 502 is adapted to receive a packet sent by an endpoint.
- the matching unit 503 is adapted to, when the receiving unit 502 receives the packet sent by the endpoint, search for a migration route entry from the configuring and storing unit 501 utilizing a source IP address of the packet.
- the processing unit 504 is adapted to, when the matching unit503 finds a route entry of which the egress interface is null, report an endpoint immigration event.
- the route entry of which the egress interface is null may be a configuration Null0 route entry or an emigration Null0 route entry.
- the route entry of which the egress interface is null is the emigration Null0 route entry, it may indicate a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment.
- the route entry of which the egress interface is null is the configuration Null0 route entry, it may indicate a scenario that an endpoint immigrates to this network segment from other network segment for the first time, namely a cross-network segment immigration scenario.
- the processing unit 504 is further adapted to, when the matching unit 503 finds an immigration host route entry, namely a host route entry of which the egress interface is not null, not report the endpoint immigration event.
- the configuring and storing unit 501 is further adapted to configure an extend-subnet-mode command on an interface on which an endpoint immigration event should be detected when determining to perform same-network segment endpoint immigration detection according to the immigration network segment specified by the dynamic-EID strategy.
- the processing unit 504 is further adapted to, when the matching unit 503 does not find a migration route entry, namely a route entry of which the egress interface is null or an immigration host route entry, determine whether a source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, determine whether an extend-subnet-mode command is configured on the interface receiving the packet, when the extend-subnet-mode command is configured on the interface receiving the packet, report the endpoint immigration event; when the source IP address of the packet and the IP address of the interface receiving the packet do not belong to the same network segment, or when the extend-subnet-mode command is not configured on the interface receiving the packet, not report the endpoint immigration event.
- the receiving unit 502 is further adapted to receive a map-notify packet.
- the map-notify packet may be sent by a map-server or an xTR in another data center for indicating that the endpoint immigrates to that data center.
- the configuring and storing unit 501 is further adapted to, when the receiving unit receives the map-notify packet, determine whether there is an immigration host route entry corresponding to the endpoint, when there is the immigration host route entry, delete the immigration host route entry, and determine whether there is a configuration Null0 route entry, when there is the configuration Null0 route entry, ignore the packet; when there is not the configuration Null0 route entry, generate an emigration Null0 route entry corresponding to the IP address of the endpoint; when the processing unit 504 reports the endpoint immigration event, generate an immigration host route entry corresponding to the IP address of the endpoint, and the egress interface of the immigration host route entry is the interface receiving the packet.
- the configuring and storing unit 501 is further adapted to enable the dynamic-EID strategy on an interface, on which an endpoint immigration event should be detected.
- the processing unit 504 is further adapted to, when the receiving unit 502 receives the packet sent by the endpoint, and when determining that the dynamic-EID strategy is enabled on the interface receiving the packet, and the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, instruct the matching unit 503 to search for a migration route entry utilizing the source IP address of the packet; when determining that the dynamic-EID strategy is not enabled on the interface receiving the packet, or the source IP address of the packet does not match the immigration network segment specified by the enabled dynamic-EID strategy, not report the endpoint immigration event.
- the units in the device in above examples disclosed herein may be distributed in the device of the examples according to the descriptions of the examples, and may also be varied to be located in one or more devices different from that of the examples.
- the units of the above examples may be integrated into one unit or may be further divided into multiple sub-units.
- FIG. 6 is a schematic diagram illustrating a device for detecting immigration of an endpoint according another example of the present disclosure.
- the device may include a non-transitory storage medium 610, a processor 620 in communication with the non-transitory storage medium 610 and an interface 630.
- the non-transitory storage medium 610 may be configured to store a group of instructions for detecting immigration of an endpoint which may be executed by the processor 620 to implement the operations of any one of the methods shown in FIG. 1 to FIG. 4, or the operations of the units in the device shown in FIG. 5.
- an xTR when receiving a packet sent by an endpoint, an xTR may, according to a source IP address of the packet and an IP address of an interface receiving the packet, determine whether an endpoint immigration event should be reported.
- the endpoint immigration may be detected without depending on the hardware.
- the immigration detection of an endpoint within a specific network segment may be achieved according to requirements.
- the above examples may be implemented by hardware, software, firmware, or a combination thereof.
- the various methods, processes and functional modules described herein may be implemented by a processor (the term processor is to be interpreted broadly to include a CPU, processing unit/module, ASIC, logic module, or programmable gate array, etc. ) .
- the processes, methods and functional modules may all be performed by a single processor or split between several processors; reference in this disclosure or the claims to a ‘processor’ should thus be interpreted to mean ‘one or more processors’ .
- the processes, methods and functional modules are implemented as machine readable instructions executable by one or more processors, hardware logic circuitry of the one or more processors or a combination thereof.
- the modules if mentioned in the aforesaid examples, may be combined into one module or further divided into a plurality of sub-modules. Further, the examples disclosed herein may be implemented in the form of a software product.
- the computer software product is stored in a non-transitory storage medium and comprises a plurality of instructions for making an electronic device implement the method recited in the examples of the present disclosure.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
An endpoint immigration detection method includes: an xTR receives a packet sent by an endpoint, and searches for a migration route entry using a source IP address of the packet; when finding a route entry of which the egress interface is null, reports an endpoint immigration event.
Description
The Locator/Identity Separation Protocol (LISP) networking scheme may provide two independent address spaces, namely Endpoint Identifier (ELD) address and Routing Locator (RLOC) address.
The EID address is an address of a host of an endpoint, used to identify the identity of the host. The role of the EID address in the LISP is similar to a Domain Name System (DNS) , and the EID address possesses a separate address space. In the LISP network, the EID address may be migrated independently of the RLOC address. During the migration of an endpoint, the EID address of the host of the endpoint is changeless. The RLOC address is an address of a LISP router, and may be routing forwarded in an Internet. The RLOC address may be globally routed, and may be aggregated according to network topologies.
The endpoint may be a server, a virtual machine connected to a router, or a mobile terminal, such as a mobile phone, an iPAD, a notebook computer.
For a better understanding of the present disclosure, reference should be made to the Detailed Description below, in conjunction with the following drawings in which like reference numerals refer to corresponding parts throughout the figures.
FIG. 1 is a flow diagram illustrating a method for detecting immigration of an endpoint according an example of the present disclosure.
FIG. 2 is a flow diagram illustrating a method for detecting immigration of an endpoint according another example of the present disclosure.
FIG. 3 is a schematic diagram illustrating a LISP network in which a virtual machine migrates from one network segment to another network segment according to examples of the present disclosure.
FIG. 4 is a schematic diagram illustrating a LISP network in which a virtual machine migrates in the same network segment according to examples of the present disclosure.
FIG. 5 is a schematic diagram illustrating a device for detecting immigration of an endpoint according an example of the present disclosure.
FIG. 6 is a schematic diagram illustrating a device for detecting immigration of an endpoint according another example of the present disclosure.
Reference will now be made in detail to examples, which are illustrated in the accompanying drawings. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. Also, the figures are illustrations of an example, in which modules or procedures shown in the figures are not necessarily essential for implementing the present disclosure. In other instances, well-known methods, procedures, components, and circuits have not been described in detail so as not to unnecessarily obscure aspects of the examples.
At present, the migration detection of an endpoint is usually achieved through a hardware chip of a router. When the hardware chip of the router cannot support the detection function, the immigration of an endpoint cannot be detected by the router. In order to leave the router free from the hardware chip, in examples of the present disclosure, software logic is utilized to perform the migration detection of the endpoint by taking the place of the hardware chip.
In an example, migration data may be sent to a LISP thread, and then the migration detection of the endpoint may be performed by inquiring the data of the LISP thread. For instance, the migration data may include initial configuration data and running data generated during the running of the LISP thread.
The configuration data may include at least one of the followings.
1) Dynamic-EID strategy configuration: the dynamic-EID strategy is used to specify information of an immigration network segment.
Since the LISP network allows an endpoint to migrate from one data center to another data center, it is necessary for an xTR to configure a dynamic-EID strategy to specify an immigration network segment. The xTR is a router supporting the functions both of an
Ingress Tunnel Router (ITR) and an Egress Tunnel Router (ETR) . In the present disclosure, the number of the network segments may be specified as required. An endpoint matching the immigration network segment may immigrates, namely an endpoint of which the Internet Protocol (IP) address is within the immigration network segment is permitted to immigrate.
2) Interface migration configuration: in order to migrate in the same network segment, it is necessary to configure an extend-subnet-mode command on an interface, on which an endpoint immigration event should be detected.
In the scenario of migration in the same network segment, an extend-subnet-mode command is configured on an interface, on which an endpoint immigration event should be detected. If the extend-subnet-mode command is not configured on the interface, it may be a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment, and an endpoint immigration event will not be reported.
Furthermore, in order to reduce unnecessary attack performed by illegal packets on an interface, in the example, the dynamic-EID strategy may be enabled on the interface, on which an endpoint immigration event should be detected (namely the interface on which the immigration detection should be performed) . Multiple dynamic-EID strategies may be enabled on one interface. It is not necessary to perform endpoint immigration detection on an interface, on which no dynamic-EID strategy is enabled.
Running data may include at least one of the followings.
1) Configuration Null0 route entry, namely a network segment route entry of which the egress interface is null.
If the network segment of the interface on which the immigration detection should be performed includes the immigration network segment configured by the dynamic-EID strategy, it is determined that there is a direct route. In general, there exists a direct route in a scenario of migration in the same network segment, namely a same-network segment immigration scenario, and there is not a direct route in a scenario of migration from one network segment to another network segment, namely a cross-network segment immigration scenario. When there does not exist a direct route, the xTR will generates a Null0 route entry corresponding to the dynamic-EID strategy, and the Null0 route entry may be called
configuration Null0 route entry. That is to say, a network segment route entry, of which the egress interface is Null, is generated corresponding to the immigration network segment specified by the dynamic-EID strategy. Since there does not exist a direct route in the cross-network segment immigration scenario, the xTR will generates a configuration Null0 route entry for detecting the cross-network segment immigration.
2) Immigration host route entry, namely a host route entry of which the egress interface is not null.
When an xTR reports an endpoint immigration event, the xTR may generate a 32-bit immigration host route entry, of which the egress interface is the interface receiving a packet of the endpoint. The immigration host route entry may be used to indicate that an endpoint immigrates to the site, and when a sequent packet matches the immigration host route entry, the endpoint immigration event will not be reported again. In addition, the xTR will send a map-register packet for the endpoint to a map-server (MS) . When a condition for sending a multicast map-notify packet is satisfied, the xTR may also send a multicast map-notify packet to other xTRs in the same multicast group.
When receiving the map-register packet sent for the endpoint by the xTR, the map-server may determine whether information that the endpoint has been registered on an xTR in another data center is recorded in the map-server, when the information is recorded in the map-server, the map-server may send a map-notify packet to the xTR in the another data center, and update the register information of the endpoint.
3) Emigration Null0 route entry, namely a host route entry of which the egress interface is null.
When an endpoint emigrates, the xTR may generate a 32-bit emigration Null0 route entry to indicate that the endpoint emigrates from the site. That is to say, when receiving a map-notify packet sent by the map-server or a multicast map-notify packet sent by that xTR, the xTR in the another data center may determine whether there exists a immigration host route entry, namely a host route entry of which the egress interface is not null, when there exists the immigration host route entry, delete the immigration host route entry; and determine whether there exists a configuration Null0 route entry, when there exists the
configuration Null0 route entry, ignores the map-notify packet; when there does not exist the configuration Null0 route entry, corresponding to the IP address of the endpoint, generate a host route entry, of which the egress interface is null, namely an emigration Null0 route entry.
The process of performing endpoint migration detection by inquiring the data of the LISP thread will be described in detail hereinafter.
FIG. 1 is a flow diagram illustrating a method for detecting immigration of an endpoint according an example of the present disclosure. As shown in FIG. 1, the method may include the following processes.
At block 101, an xTR receives a packet sent by an endpoint, and searches for a migration route entry from the xTR utilizing a source IP address of the packet.
The migration route entry may be an immigration host route entry, a configuration Null0 route entry, or an emigration Null0 route entry. The configuration Null0 route entry is a network segment route entry of which the egress interface is null; the emigration Null0 route entry is a host route entry of which the egress interface is null. Namely, the configuration Null0 route entry and the emigration Null0 route entry are respectively a route entry of which the egress interface is null.
At block 102, when finding a route entry of which the egress interface is null (a configuration Null0 route entry or an emigration Null0 route entry) , the xTR may report an endpoint immigration event.
When the route entry of which the egress interface is null is the emigration Null0 route entry, it may indicate a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment. When the route entry of which the egress interface is null is the configuration Null0 route entry, it may indicate a scenario that an endpoint immigrates to this network segment for the first time, namely a cross-network segment immigration scenario.
When finding an immigration host route entry, for instance, a route entry with a 32-bit IP address, the xTR may not report the endpoint immigration event.
When not finding a route entry of which the egress interface is null or the immigration host route entry, the xTR may determine whether the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when determining that the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, the xTR may further determine whether an extend-subnet-mode command is configured on the interface receiving the packet, and when the extend-subnet-mode command is configured on the interface receiving the packet, report the endpoint immigration event; when determining that the source IP address of the packet and the IP address of the interface receiving the packet do not belong to the same network segment, or when the extend-subnet-mode command is not configured on the interface receiving the packet, not report the endpoint immigration event.
When determining that the source IP address of the packet and the IP address of the interface receiving the packet do not belong to the same network segment, the xTR may not report the endpoint immigration event.
FIG. 2 is a flow diagram illustrating a method for detecting immigration of an endpoint according another example of the present disclosure. As shown in FIG. 2, the method may include the following processes.
At block 201, an xTR receives a packet sent by an endpoint.
At block 202, the xTR determines whether a dynamic-EID strategy is enabled on the interface receiving the packet, when the dynamic-EID strategy is enabled on the interface receiving the packet, block 203 is performed; otherwise, block 208 is performed.
At block 203, the xTR determines whether a source IP address of the packet matches an immigration network segment specified by the enabled dynamic-EID strategy, when the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, block 204 is performed; otherwise, block 208 is performed.
In the example, the longest matching principle may be utilized to perform the match of the source IP address of the packet with the immigration network segment specified by the enabled dynamic-EID strategy.
In the example, the execution sequence of block 202 and block 203 is not limited to sequence shown in FIG. 2, for example, block 203 may be executed before block 202, namely, the xTR may determine whether a source IP address of the packet matches an immigration network segment specified by the enabled dynamic-EID strategy first, and when the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, the xTR determines whether a dynamic-EID strategy is enabled on the interface receiving the packet, and when the dynamic-EID strategy is enabled on the interface receiving the packet, block 204 is performed.
At block 204, the xTR locally searches for a migration route entry utilizing the source IP address of the packet. When finding an immigration host route entry, block 208 is performed; when finding a route entry of which the egress interface is null, block 207 is performed; when not finding a route entry of which the egress interface is null or the immigration host route entry, block 205 is performed.
The route entry of which the egress interface is null may be a configuration Null0 route entry or an emigration Null0 route entry. When the route entry of which the egress interface is null is the emigration Null0 route entry, it may indicate a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment. When the route entry of which the egress interface is null is the configuration Null0 route entry, it may indicate a scenario that an endpoint immigrates to this network segment from other network segment.
When there exist simultaneously the configuration Null0 route entry and the immigration host route entry, the immigration host route entry will be found first, and the configuration Null0 route entry will not be found.
At block 205, the xTR determines whether the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, block 206 is performed; otherwise, block 208 is performed.
At block 206, the xTR determines whether an extend-subnet-mode command is configured on the interface receiving the packet, when the extend-subnet-mode command is configured on the interface receiving the packet, block 207 is performed; otherwise, block 208 is performed.
At block 207, the xTR reports the endpoint immigration event, and generates an immigration host route entry corresponding to the source IP address of the packet, of which the egress interface is the interface receiving the packet. According to the immigration host route entry, the endpoint immigration event will not be reported again when a sequent packet matches the immigration host route entry.
In the example, when the xTR reports the endpoint immigration event to a CPU of the xTR, and the CPU performs the relevant processing, the xTR may send a map-register packet for the endpoint to a map-server.
When a condition for sending a multicast map-notify packet is satisfied, the xTR may also send a multicast map-notify packet to other xTRs in the same multicast group. When receiving the multicast map-notify packet, the xTRs in the same multicast group may send a valid forwarding route entry to the forwarding layer of the router, and the xTRs in a different multicast group may send an invalid forwarding route entry to the forwarding layer of the router.
When receiving the map-register packet sent for the endpoint by the xTR, the map-server may determine whether information that the endpoint has been registered on an xTR in another data center is recorded in the map-server, when the information is recorded in the map-server, the map-server may send a map-notify packet to the xTR in the another data center, and update the register information of the endpoint.
When receiving a map-notify packet sent by the map-server or a multicast map-notify packet sent by that xTR, the xTR in the another data center may determine whether there exists a immigration host route entry, namely a host route entry of which the egress interface is not null, when there exists the immigration host route entry, delete the immigration host route entry; and determine whether there exists a configuration Null0 route entry, when there exists the configuration Null0 route entry, ignores the map-notify packet; when there does not
exist the configuration Null0 route entry, corresponding to the IP address of the endpoint, generate a host route entry, of which the egress interface is null, namely an emigration Null0 route entry.
At block 208, the xTR does not report the endpoint immigration event.
In can be seen from above examples, a dynamic-EID strategy may be configured to specify an immigration network segment, so that an endpoint of which the IP address is within the immigration network segment may immigrate. In addition, the dynamic-EID strategy may be enabled on an interface, on which an endpoint immigration event should be detected, so that endpoint immigration detection may be performed on the interface, namely the endpoint immigration detection may be performed in a limited range. By performing the endpoint immigration detection on a software level, the router may be not limited by the hardware.
The process of detecting an endpoint migration in one network segment and cross different network segments will be respectively described in detail hereinafter by taking a virtual machine as example.
FIG. 3 is a schematic diagram illustrating a LISP network in which a virtual machine migrates from one network segment to another network segment according to examples of the present disclosure.
In FIG. 3, xTR1 in data center (DC) 1 and xTR2 in data center (DC) 2 are respectively configured with a dynamic-EID strategy in which an immigration network segment 10.17.1.0/24 is specified. The dynamic-EID strategy is respectively enabled on the interface 1 ofxTR1 and the interface 2 ofxTR2. The address of the interface 1 is 10.17.1.5/24, and the address of the interface 2 is 10.17.2.9/24. Because there is not a direct route corresponding to the network segment 10.17.1.0/24 on xTR2, xTR2 generates a network segment route entry of which the egress interface is null, namely a configuration Null0 route entry.
At first, the procedure that virtual machine (VM) B goes online in DC1 will be described hereinafter.
VM B (of which the IP address is 10.17.1.65/32) goes online in DC1, and sends a gratuitous ARP packet.
XTR1 receives the gratuitous ARP packet sent by VM B through the interface 1, and determines that the source IP address of the gratuitous ARP packet matches the immigration network segment specified by the dynamic-EID strategy enabled on the interface 1, and searches for a migration route entry utilizing the source IP address of the gratuitous ARP packet. xTR1 does not find a migration route entry, namely not find an immigration host route entry (the host route entry corresponding to the IP address 10.17.1.65/32) , or a configuration Null0 route entry (the network segment route entry of which the egress interface is null) . XTR1 further determines that the IP address of the interface 1 and the source IP address of the gratuitous ARP packet belong to the same network segment, and no extend-subnet-mode command is configured on the interface 1, xTR1 does not report a VM B immigration event, namely VM B is not deemed as a VM immigrating to DC1.
Secondly, the procedure that VM B migrates from DC1 to DC2, and sends an IP data packet to xTR2 in DC2 will be described hereinafter.
XTR2 receives an IP data packet sent by VM B through the interface 2, and determines that the source IP address of the IP data packet matches the immigration network segment specified by the dynamic-EID strategy enabled on the interface 2, searches for a migration route entry utilizing the source IP address of the IP data packet, and finds a configuration Null0 route entry, namely, utilizing the source IP address 10.17.1.65/32, finds a network segment route entry, of which the egress interface is null, corresponding to the network segment 10.17.1.0/24. XTR2 reports a VM B immigration event, and corresponding to the source IP address 10.17.1.65/32 of VM B, generates a host route entry of which the egress interface is the interface 2 receiving the IP data packet, namely an immigration host route entry.
Subsequently, when receiving a packet sent by the VM B again, and finding the immigration host route entry corresponding to the source IP address 10.17.1.65/32 of the packet, xTR2 will not report the VM B immigration event.
When xTR2 reports the VM B immigration event to a CPU of the xTR2, and the CPU performs the relevant processing, xTR2 sends a map-register packet for VM B to a map-server.
When receiving the map-register packet sent for VM B by xTR2, and determining that VM B has been registered on xTR1, the map-server may send a map-notify packet to the xTR1 in DC1, and update the register information of VM B.
When receiving the map-notify packet sent by the map-server, xTR1 in DC1 determines that there is not an immigration host route entry corresponding to the IP address 10.17.1.65/32, and generates an emigration Null0 route entry corresponding to the IP address, namely a host route entry corresponding to the IP address, of which the egress interface is null, to indicate that the address 10.17.1.65/32 is an IP address of a VM which emigrates from DC1.
So far, the process that VM B migrates from DC1 to DC2 is terminated.
When VM B migrates from DC2 to DC1, and sends a data packet to xTR1 in DC1, after receiving the data packet sent by VM B, xTR1 will find the emigration Null0 route entry according to the source IP address 10.17.1.65/32, and will report a VM B immigration event.
FIG. 4 is a schematic diagram illustrating a LISP network in which a virtual machine migrates in the same network segment according to examples of the present disclosure.
In FIG. 4, xTR1 in DC 1 and xTR2 in DC 2 are respectively configured with a dynamic-EID strategy in which an immigration network segment 10.17.1.0/24 is specified. The dynamic-EID strategy is respectively enabled on the interface 1 ofxTR1 and the interface 2 ofxTR2. The address of the interface 1 is 10.17.1.5/24, and the address of the interface 2 is 10.17.1.9/24. Because the virtual machine immigration is performed in the same network segment, it is necessary to configure an extend-subnet-mode command on both the interface 1 and the interface 2. In the LISP network shown in FIG. 4, xTRs in different DCs may communicated with each other via a configured layer-2.
At first, the procedure that VM B goes online in DC1 will be described hereinafter.
VM B goes online in DC1, and sends a gratuitous ARP packet to xTR1
XTR1 receives the gratuitous ARP packet sent by VM B through the interface 1, and does not find a route entry of which the egress interface is null. xTR1 determines that the IP address of the interface 1 and the source IP address of the gratuitous ARP packet belong to the same network segment, and an extend-subnet-mode command is configured on the interface 1, xTR1 reports a VM B immigration event.
After detecting the immigration of VM B, xTR1 generates an immigration host route entry, namely a host route entry, corresponding to the IP address 10.17.1.65/32, of which the egress interface is the interface 1, and sends a multicast map-notify packet to a multicast group configured on the interface 1.
XTR1 simultaneously sends a map-register packet to a map-server to register VM B, after receiving the map-register packet sent by xTR1, the map-server records register information of VM B registered on xTR1.
When receiving the multicast map-notify packet sent by xTR1, xTR2 determines whether there is a host route entry corresponding to the IP address 10.17.1.65/32, when there is not the host route entry corresponding to the IP address 10.17.1.65/32, generates an emigration Null0 route entry, namely a host route entry corresponding to the IP address, of which the egress interface is null; when there is the host route entry corresponding to the IP address 10.17.1.65/32 and the egress interface of the host route entry is null, remain unchanged; when there is the host route entry corresponding to the IP address 10.17.1.65/32 and the egress interface is not null, namely there is an immigration host route entry, deletes the immigration host route entry, and generates an emigration Null0 route entry.
Secondly, the procedure that VM B migrates from DC1 to DC2 will be described hereinafter.
VM B sends a data packet to xTR2 in DC2.
XTR2 receives the data packet sent by VM B, and finds an emigration Null0 route entry corresponding to the source IP address 10.17.1.65/32 of the data packet, namely a host route entry corresponding to the source IP address 10.17.1.65/32, and the egress interface of the host route entry is null, xTR2 reports a VM B immigration event.
After detecting the immigration of VM B, xTR2 generates an immigration host route entry, namely a host route entry, corresponding to the IP address 10.17.1.65/32, of which the egress interface is the interface 2, and sends a multicast map-notify packet to a multicast group configured on the interface 2; sends a map-register packet to the map-server to register VM B. After updating the register information of VM B, the map-server sends a map-notify packet to xTR1.
When receiving the multicast map-notify packet sent by xTR2 or the map-notify packet sent by the map-server, xTR1 determines that there is a host route entry corresponding to the IP address 10.17.1.65/32 and the egress interface of the host route entry is the interface 1, namely an immigration host route entry corresponding to the IP address 10.17.1.65/32, xTR1 deletes the immigration host route entry, and generates an emigration Null0 route entry corresponding to the IP address 10.17.1.65/32.
So far, the process that VM B migrates from DC1 to DC2 is terminated.
When VM B migrates from DC2 to DC1, the process is similar to above description, and no further descriptions will be provided here.
Examples in the present disclosure also provide a device for detecting immigration of an endpoint, which may be applied to an xTR in the LISP network. FIG. 5 is a schematic diagram illustrating a device for detecting immigration of an endpoint according an example of the present disclosure. As shown in FIG. 5, the device may include a configuring and storing unit 501, a receiving unit 502, a matching unit 503 and a processing unit 504.
The configuring and storing unit 501 is adapted to configure a dynamic-EID strategy to specify an immigration network segment; and generate a configuration Null0 route entry corresponding to the immigration network segment, when determining to perform cross-network segment endpoint immigration detection according to the immigration network segment.
The receiving unit 502 is adapted to receive a packet sent by an endpoint.
The matching unit 503 is adapted to, when the receiving unit 502 receives the packet sent by the endpoint, search for a migration route entry from the configuring and storing unit 501 utilizing a source IP address of the packet.
The processing unit 504 is adapted to, when the matching unit503 finds a route entry of which the egress interface is null, report an endpoint immigration event. The route entry of which the egress interface is null may be a configuration Null0 route entry or an emigration Null0 route entry. When the route entry of which the egress interface is null is the emigration Null0 route entry, it may indicate a scenario that an endpoint emigrated from this network segment re-immigrates to this network segment. When the route entry of which the egress interface is null is the configuration Null0 route entry, it may indicate a scenario that an endpoint immigrates to this network segment from other network segment for the first time, namely a cross-network segment immigration scenario.
In an example, the processing unit 504 is further adapted to, when the matching unit 503 finds an immigration host route entry, namely a host route entry of which the egress interface is not null, not report the endpoint immigration event.
In an example, the configuring and storing unit 501 is further adapted to configure an extend-subnet-mode command on an interface on which an endpoint immigration event should be detected when determining to perform same-network segment endpoint immigration detection according to the immigration network segment specified by the dynamic-EID strategy.
The processing unit 504 is further adapted to, when the matching unit 503 does not find a migration route entry, namely a route entry of which the egress interface is null or an immigration host route entry, determine whether a source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, determine whether an extend-subnet-mode command is configured on the interface receiving the packet, when the extend-subnet-mode command is configured on the interface receiving the packet, report the endpoint immigration event; when the source IP address of the packet and the IP address of the interface receiving the packet do
not belong to the same network segment, or when the extend-subnet-mode command is not configured on the interface receiving the packet, not report the endpoint immigration event.
In an example, the receiving unit 502 is further adapted to receive a map-notify packet. The map-notify packet may be sent by a map-server or an xTR in another data center for indicating that the endpoint immigrates to that data center.
The configuring and storing unit 501 is further adapted to, when the receiving unit receives the map-notify packet, determine whether there is an immigration host route entry corresponding to the endpoint, when there is the immigration host route entry, delete the immigration host route entry, and determine whether there is a configuration Null0 route entry, when there is the configuration Null0 route entry, ignore the packet; when there is not the configuration Null0 route entry, generate an emigration Null0 route entry corresponding to the IP address of the endpoint; when the processing unit 504 reports the endpoint immigration event, generate an immigration host route entry corresponding to the IP address of the endpoint, and the egress interface of the immigration host route entry is the interface receiving the packet.
In an example, the configuring and storing unit 501 is further adapted to enable the dynamic-EID strategy on an interface, on which an endpoint immigration event should be detected.
The processing unit 504 is further adapted to, when the receiving unit 502 receives the packet sent by the endpoint, and when determining that the dynamic-EID strategy is enabled on the interface receiving the packet, and the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, instruct the matching unit 503 to search for a migration route entry utilizing the source IP address of the packet; when determining that the dynamic-EID strategy is not enabled on the interface receiving the packet, or the source IP address of the packet does not match the immigration network segment specified by the enabled dynamic-EID strategy, not report the endpoint immigration event.
The units in the device in above examples disclosed herein may be distributed in the device of the examples according to the descriptions of the examples, and may also be varied
to be located in one or more devices different from that of the examples. The units of the above examples may be integrated into one unit or may be further divided into multiple sub-units.
FIG. 6 is a schematic diagram illustrating a device for detecting immigration of an endpoint according another example of the present disclosure. As shown in FIG. 6, the device may include a non-transitory storage medium 610, a processor 620 in communication with the non-transitory storage medium 610 and an interface 630.
The non-transitory storage medium 610 may be configured to store a group of instructions for detecting immigration of an endpoint which may be executed by the processor 620 to implement the operations of any one of the methods shown in FIG. 1 to FIG. 4, or the operations of the units in the device shown in FIG. 5.
As can be seen, in examples of the present disclosure, when receiving a packet sent by an endpoint, an xTR may, according to a source IP address of the packet and an IP address of an interface receiving the packet, determine whether an endpoint immigration event should be reported. Thus, the endpoint immigration may be detected without depending on the hardware. In addition, by configuring a dynamic-EID strategy, the immigration detection of an endpoint within a specific network segment may be achieved according to requirements.
The foregoing description, for purpose of explanation, has been described with reference to specific examples. However, the illustrative discussions above are not intended to be exhaustive or to limit the present disclosure to the precise forms disclosed. Many modifications and variations are possible in view of the above teachings. The examples were chosen and described in order to best explain the principles of the present disclosure and its practical applications, to thereby enable others skilled in the art to best utilize the present disclosure and various examples with various modifications as are suited to the particular use contemplated.
The above examples may be implemented by hardware, software, firmware, or a combination thereof. For example the various methods, processes and functional modules described herein may be implemented by a processor (the term processor is to be interpreted broadly to include a CPU, processing unit/module, ASIC, logic module, or programmable
gate array, etc. ) . The processes, methods and functional modules may all be performed by a single processor or split between several processors; reference in this disclosure or the claims to a ‘processor’ should thus be interpreted to mean ‘one or more processors’ . The processes, methods and functional modules are implemented as machine readable instructions executable by one or more processors, hardware logic circuitry of the one or more processors or a combination thereof. The modules, if mentioned in the aforesaid examples, may be combined into one module or further divided into a plurality of sub-modules. Further, the examples disclosed herein may be implemented in the form of a software product. The computer software product is stored in a non-transitory storage medium and comprises a plurality of instructions for making an electronic device implement the method recited in the examples of the present disclosure.
Claims (14)
- A method for detecting immigration of an endpoint, comprising:configuring, by an xTR in a Locator/Identity Separation Protocol (LISP) network, a dynamic-Endpoint Identifier (EID) strategy to specify an immigration network segment; and generating a configuration Null0 route entry corresponding to the immigration network segment when determining to perform cross-network segment endpoint immigration detection;receiving a packet sent by an endpoint, and searching for a route entry utilizing a source Internet Protocol (IP) address of the packet; andreporting an endpoint immigration event when finding the configuration Null0 route entry.
- The method according to claim 1, after reporting the endpoint immigration event, further comprising:generating an immigration host route entry corresponding to the source IP address of the packet, and the egress interface is an interface receiving the packet.
- The method according to claim 2, further comprising:not reporting the endpoint immigration event when finding the immigration host route entry.
- The method according to claim 2, further comprising:determining whether the source IP address of the packet and an IP address of the interface receiving the packet belong to a same network segment, when not finding the configuration Null0 route entry or the immigration host route entry; anddetermining whether an extend-subnet-mode command is configured on the interface receiving the packet when determining that the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment; and when the extend-subnet-mode command is configured on the interface receiving the packet, reporting the endpoint immigration event;when determining that the source IP address of the packet and the IP address of the interface receiving the packet do not belong to the same network segment, or when the extend-subnet-mode command is not configured on the interface receiving the packet, not reporting the endpoint immigration event.
- The method according to claim 2, further comprising:receiving a map-notify packet indicating that the endpoint emigrates to another data center sent by a map-server or an xTR in the another data center, determining whether there is an immigration host route entry corresponding to the endpoint, when there is the immigration host route entry corresponding to the endpoint, deleting the an immigration host route entry corresponding to the endpoint, and determining whether there is a configuration Null0 route entry, when there is the configuration Null0 route entry, ignoring the packet; when there is not the configuration Null0 route entry, generating an emigration Null0 route entry corresponding to the IP address of the endpoint.
- The method according to claim 5, further comprising:reporting the endpoint immigration event when finding the emigration route entry corresponding to the endpoint.
- The method according to claim 1, after receiving the packet sent by an endpoint, and before searching for the route entry, further comprising:determining whether the dynamic-EID strategy is enabled on the interface receiving the packet and whether the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy; andsearching for the route entry utilizing the source IP address of the packet, when determining that the dynamic-EID strategy is enabled on the interface receiving the packet and the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy.
- A device for detecting immigration of an endpoint, applied to an xTR in a Locator/Identity Separation Protocol (LISP) network, comprising: a processor and a non-transitory storage medium in communication with the processor;the non-transitory storage medium stores a group of instructions which may be executed by the processor to:configure a dynamic-Endpoint Identifier (EID) strategy to specify an immigration network segment; and generate a configuration Null0 route entry corresponding to the immigration network segment, when determining to perform cross-network segment endpoint immigration detection according to the immigration network segment;receive a packet sent by an endpoint;search for a migration route entry utilizing a source Internet Protocol (IP) address of the packet;when finding the configuration Null0 route entry, report an endpoint immigration event.
- The device according to claim 8, wherein, the processor is further to:when reporting the endpoint immigration event, generate an immigration host route entry corresponding to the IP address of the endpoint, and the egress interface of the immigration host route entry is the interface receiving the packet.
- The device according to claim 9, wherein, the processor is further to:when finding an immigration host route entry, not report the endpoint immigration event.
- The device according to claim 8, wherein, the processor is further to:configure an extend-subnet-mode command on an interface on which an endpoint immigration event should be detected when determining to perform same-network segment endpoint immigration detection according to the immigration network segment specified by the dynamic-EID strategy; andwhen not finding the configuration Null0 route entry or the immigration host route entry, determine whether a source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, when the source IP address of the packet and the IP address of the interface receiving the packet belong to the same network segment, determine whether an extend-subnet-mode command is configured on the interface receiving the packet, when the extend-subnet-mode command is configured on the interface receiving the packet, report the endpoint immigration event; when the source IP address of the packet and the IP address of the interface receiving the packet do not belong to the same network segment, or when the extend-subnet-mode command is not configured on the interface receiving the packet, not report the endpoint immigration event.
- The device according to any one of claims 8 to 11, wherein, the processor is further to:receive a map-notify packet; anddetermine whether there is an immigration host route entry corresponding to the endpoint, when there is the immigration host route entry, delete the immigration host route entry, and determine whether there is a configuration Null0 route entry, when there is the configuration Null0 route entry, ignore the packet; when there is not the configuration Null0 route entry, generate an emigration Null0 route entry corresponding to the IP address of the endpoint.
- The device according to claim 12, wherein, the processor is further to:when finding an emigration Null0 route entry, report the endpoint immigration event.
- The device according to any one of claims 8 to 11, wherein, the processor is further to:enable the dynamic-EID strategy on an interface, on which an endpoint immigration event should be detected;when receiving the packet sent by the endpoint, and when determining that the dynamic-EID strategy is enabled on the interface receiving the packet, and the source IP address of the packet matches the immigration network segment specified by the enabled dynamic-EID strategy, search for a migration route entry utilizing the source IP address of the packet; when determining that the dynamic-EID strategy is not enabled on the interface receiving the packet, or the source IP address of the packet does not match the immigration network segment specified by the enabled dynamic-EID strategy, not report the endpoint immigration event.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510243201.9 | 2015-05-13 | ||
| CN201510243201.9A CN106302171B (en) | 2015-05-13 | 2015-05-13 | A kind of virtual machine moves into detection method and device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2016180351A1 true WO2016180351A1 (en) | 2016-11-17 |
Family
ID=57247690
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/081832 Ceased WO2016180351A1 (en) | 2015-05-13 | 2016-05-12 | Endpoint migration detection |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN106302171B (en) |
| WO (1) | WO2016180351A1 (en) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2008103936A1 (en) * | 2007-02-22 | 2008-08-28 | Tienwei Chao | A system and methods for providing server virtualization assistance |
| US20100115080A1 (en) * | 2008-11-06 | 2010-05-06 | Kageyama Soshi | Method of controlling the communication between a machine using private addresses and a communication device connected to a global network |
| CN102447618A (en) * | 2011-10-31 | 2012-05-09 | 杭州华三通信技术有限公司 | Route switching method in LISP network and apparatus thereof |
| CN103095722A (en) * | 2013-02-01 | 2013-05-08 | 华为技术有限公司 | Method for updating network security table and network device and dynamic host configuration protocol (DHCP) server |
| CN104113459A (en) * | 2013-04-16 | 2014-10-22 | 杭州华三通信技术有限公司 | Method for smoothly migrating virtual machine in Ethernet virtual interconnection (EVI) network, and device for smoothly migrating virtual machine in EVI network |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9608901B2 (en) * | 2012-07-24 | 2017-03-28 | Telefonaktiebolaget Lm Ericsson (Publ) | System and method for enabling services chaining in a provider network |
| US9288162B2 (en) * | 2012-08-03 | 2016-03-15 | Cisco Technology, Inc. | Adaptive infrastructure for distributed virtual switch |
| CN103916320B (en) * | 2012-12-28 | 2017-09-15 | 中国移动通信集团公司 | Message processing method and device after a kind of VM equipment across-the-wire migration |
| CN104219142B (en) * | 2013-05-30 | 2017-06-16 | 中国电信股份有限公司 | Access method, system and the DCBR of the virtual machine migrated across IDC |
| CN103841028B (en) * | 2014-03-24 | 2017-02-08 | 杭州华三通信技术有限公司 | Method and device for forwarding messages |
-
2015
- 2015-05-13 CN CN201510243201.9A patent/CN106302171B/en active Active
-
2016
- 2016-05-12 WO PCT/CN2016/081832 patent/WO2016180351A1/en not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2008103936A1 (en) * | 2007-02-22 | 2008-08-28 | Tienwei Chao | A system and methods for providing server virtualization assistance |
| US20100115080A1 (en) * | 2008-11-06 | 2010-05-06 | Kageyama Soshi | Method of controlling the communication between a machine using private addresses and a communication device connected to a global network |
| CN102447618A (en) * | 2011-10-31 | 2012-05-09 | 杭州华三通信技术有限公司 | Route switching method in LISP network and apparatus thereof |
| CN103095722A (en) * | 2013-02-01 | 2013-05-08 | 华为技术有限公司 | Method for updating network security table and network device and dynamic host configuration protocol (DHCP) server |
| CN104113459A (en) * | 2013-04-16 | 2014-10-22 | 杭州华三通信技术有限公司 | Method for smoothly migrating virtual machine in Ethernet virtual interconnection (EVI) network, and device for smoothly migrating virtual machine in EVI network |
Also Published As
| Publication number | Publication date |
|---|---|
| CN106302171B (en) | 2019-09-17 |
| CN106302171A (en) | 2017-01-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10541913B2 (en) | Table entry in software defined network | |
| CN102143068B (en) | Method, device and system for learning MAC (Media Access Control) address | |
| US20150358232A1 (en) | Packet Forwarding Method and VXLAN Gateway | |
| CN107547349B (en) | Virtual machine migration method and device | |
| US9716687B2 (en) | Distributed gateways for overlay networks | |
| US9838314B1 (en) | Contextual service mobility in an enterprise fabric network environment | |
| CN103441932B (en) | A kind of Host routes list item generates method and apparatus | |
| WO2018040530A1 (en) | Method and apparatus for determining virtual machine migration | |
| US10122548B2 (en) | Services execution | |
| US10938679B2 (en) | Packet monitoring | |
| WO2016107594A1 (en) | Accessing external network from virtual network | |
| CN112565044B (en) | Message processing method and device | |
| CN110505621B (en) | Terminal migration processing method and device | |
| CN103501355B (en) | Internet protocol address collision detection method, device and gateway device | |
| US20180039505A1 (en) | Preventing flow interruption caused by migration of vm | |
| CN107770294A (en) | The processing method and processing device of IP address conflicts in EVPN | |
| CN108199968B (en) | Route processing method and device | |
| US20180091446A1 (en) | Packet forwarding | |
| US10764234B2 (en) | Method and system for host discovery and tracking in a network using associations between hosts and tunnel end points | |
| US10313274B2 (en) | Packet forwarding | |
| EP3026862B1 (en) | Routing loop determining method | |
| WO2018019146A1 (en) | Device detection | |
| CN104780110B (en) | Message transmitting method and equipment during a kind of virtual machine (vm) migration | |
| CN105991391A (en) | Method and device for uploading protocol message to CPU | |
| US9853891B2 (en) | System and method for facilitating communication |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16792201 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16792201 Country of ref document: EP Kind code of ref document: A1 |