WO2017114362A1 - 一种报文转发方法、装置和系统 - Google Patents

一种报文转发方法、装置和系统 Download PDF

Info

Publication number
WO2017114362A1
WO2017114362A1 PCT/CN2016/112144 CN2016112144W WO2017114362A1 WO 2017114362 A1 WO2017114362 A1 WO 2017114362A1 CN 2016112144 W CN2016112144 W CN 2016112144W WO 2017114362 A1 WO2017114362 A1 WO 2017114362A1
Authority
WO
WIPO (PCT)
Prior art keywords
packet
identifier
forwarding
network side
network
Prior art date
Application number
PCT/CN2016/112144
Other languages
English (en)
French (fr)
Inventor
滕新东
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2017114362A1 publication Critical patent/WO2017114362A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing

Definitions

  • the present invention relates to the field of data processing, and in particular, to a packet forwarding method, apparatus, and system.
  • NFV network functions virtualization
  • the basic principle of network function virtualization is to provide a network that requires multiple device types (such as firewalls, load balancers, etc.) and multiple physical device forms through virtualization technology.
  • the service function is changed to provide the external function of the virtual device. This allows one physical device to support multiple virtual devices, and even supports one physical device to virtualize multiple virtual devices of different service types, thereby reducing costs.
  • the Virtual Broadband Network Gateway based on the NFV architecture is a virtual device obtained by virtualizing the functions of the traditional broadband network gateway.
  • vBNG can run in the hardware environment of a general-purpose server and implement related functions that traditional BNG devices can implement. For example, the vBNG can complete the user's online processing, user access, user authentication and accounting (Authentication, Authorization and Accounting, abbreviation: AAA), assign addresses to users from the configured address pool, and implement user data. The function of forwarding messages and networks to each other.
  • AAA Authentication, Authorization and Accounting
  • the vBNG may include a main control unit and a plurality of forwarding units, and the main control unit and the forwarding unit respectively run in different virtual machines (English: Virtual Machine, abbreviated: VM).
  • the terminal on the user side can implement data interaction with the network side through the forwarding unit of the vBNG.
  • Figure 1 shows a common vBNG application scenario.
  • a packet is forwarded from the network to a user on the user side, the packet needs to be forwarded to the vBNG through the router.
  • the packet forwarding path from the router to the vBNG needs to pass.
  • Check the routing forwarding table to obtain, for example, the Forward Information Base (English: Forward Information Base, abbreviation: FIB) table.
  • FIB Forward Information Base
  • the routing forwarding table is mainly obtained based on the convergence of the routing protocol.
  • the forwarding unit that receives the packet in the forwarding path is not considered to be a suitable forwarding unit, but only whether the logical aspect can be implemented. This may result in no vBNG
  • the forwarding unit that is suitable for processing the message receives the message.
  • the vBNG needs to transfer the message to another forwarding unit that is suitable for processing the message, and then the user interface of the forwarding unit is directed to the user side.
  • This message is forwarded to form, for example, the message forwarding path 1 shown in FIG.
  • the forwarding unit is in different VMs.
  • the forwarding of the packet in the forwarding unit of the vBNG can be understood as forwarding the packet across the VM.
  • the embodiment of the present invention provides a packet forwarding method, apparatus, and system, which reduces the situation in which vBNG needs to be forwarded from a network side to a VM, and the forwarding performance of the vBNG is ensured.
  • the embodiment of the present invention provides a packet forwarding method, which is applied to a forwarding network including a vBNG, where the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB, and the method includes :
  • the network side LB receives the first packet from the network side, where the first packet includes a destination identifier, and the destination identifier of the first packet is used to identify the target terminal.
  • the network side LB matches the destination information of the first packet to the first distribution entry, and determines the corresponding first forwarding unit identifier and the outbound interface information of the network side LB, where the first sharing is performed.
  • the entry is established and delivered by the controller, and the first share entry includes a correspondence between the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB.
  • the first forwarding unit corresponding to the first forwarding unit identifier is one of the at least two forwarding units in the vBNG, and the first forwarding unit is a forwarding unit that uplinks the target terminal;
  • the network side LB determines the first outbound interface identifier according to the outbound interface information, the network side LB forwards the first outbound interface identified by the first outbound interface identifier to the first forwarding unit.
  • the first outbound interface is an outbound interface on the network side LB.
  • it also includes:
  • the network side LB determines, according to the destination medium access control MAC address of the first packet, that the first forwarding unit identifier matches the outbound interface entry, and determines the corresponding first outbound interface identifier,
  • the destination MAC address of the first packet is used to identify the network interface of the first forwarding unit, the outbound interface entry is established by the controller, and the outbound interface entry includes the first forwarding unit network interface.
  • the network side LB forwards the first packet from the first outbound interface to the first forwarding unit.
  • the network side LB receives the update information for the first distribution entry that is sent by the controller, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface;
  • the network side LB updates the first distribution entry according to the update information of the first distribution entry, and the updated first distribution entry includes an outbound interface that can identify the first outgoing interface identifier. information.
  • the method further includes:
  • the network side LB sends a sharing parameter for the first packet to the controller, where the sharing parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the network side LB receives the update information for the first distribution entry that is sent by the controller, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface;
  • the network side LB determines that the first outbound interface identifier is determined according to the outbound interface information, according to the destination identifier of the first packet that is matched to the updated first distribution entry.
  • the first sharing entry further includes a check MAC address corresponding to the first packet, where the check MAC address is used by the destination forwarding unit to receive the first packet.
  • the network side LB according to the MAC address of the interface, before the network side LB forwards the first packet from the first egress interface identified by the first egress interface identifier to the first forwarding unit
  • the destination identifier of the first packet is matched to the first distribution entry, and the network side LB determines that the corresponding verification MAC address is matched according to the destination identifier of the first packet to the first distribution entry.
  • Address the method further includes:
  • it also includes:
  • the network side LB receives the second packet from the network side, where the second packet includes the destination identifier, and the destination identifier of the second packet is used to identify the network interface of the second forwarding unit, and the second forwarding unit And is a forwarding unit of at least two forwarding units in the vBNG;
  • the network side LB determines the second outbound interface identifier according to the second outbound interface information, The network side LB forwards the second packet to the second forwarding unit from the second outbound interface that is identified by the second outbound interface identifier, and the second outbound interface is an outbound interface on the network side LB. .
  • the embodiment of the present invention provides a packet forwarding apparatus, which is applied to a forwarding network including a vBNG, where the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB, where the apparatus includes :
  • a matching unit configured to determine, according to the first identifier of the first packet, the first forwarding unit identifier, and the outbound interface information of the network side LB, where the first sharing is performed.
  • the entry is established and delivered by the controller, and the first share entry includes a correspondence between the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB.
  • the first forwarding unit corresponding to the first forwarding unit identifier is one of at least two forwarding units in the vBNG, and the first forwarding unit is a forwarding unit that uplinks the target terminal; if the matching The unit determines the first outbound interface identifier according to the outbound interface information, and triggers the sending unit;
  • the sending unit is further configured to determine, in the matching unit, the corresponding first After the interface identifier is sent, the sharing parameter for the first packet is sent to the controller, where the sharing parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the receiving unit is further configured to receive, by the controller, update information for the first distribution entry, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface;
  • an update unit configured to update the first distribution entry according to the update information of the first distribution entry, where the updated first distribution entry includes an outbound interface that can determine the identifier of the first outgoing interface information.
  • the sending unit is further configured to: if the matching unit cannot determine the first outbound interface identifier according to the outbound interface information, send a sharing parameter for the first packet to the controller, where The sharing parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the receiving unit is further configured to receive, by the controller, update information for the first distribution entry, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface;
  • the matching unit is further configured to: determine, according to the outbound interface identifier, the first outbound interface identifier according to the outbound interface information, according to the first identifier of the first packet;
  • the sending unit is further configured to forward the first packet to the first forwarding unit from the first outbound interface that is identified by the first outbound interface identifier.
  • the first sharing entry further includes a check MAC address corresponding to the first packet, where the check MAC address is used by the destination forwarding unit to receive the first packet.
  • the MAC address of the interface, the matching unit is further configured to: determine, according to the destination identifier of the first packet, the matching first MAC address, and the corresponding check MAC address; the packet forwarding device further includes :
  • a judging unit configured to determine whether the check MAC address and the MAC address to be checked carried in the first packet are consistent; if they are consistent, triggering the first processing unit; if not, triggering the second processing unit yuan;
  • the second processing unit is configured to use the check MAC address as the destination MAC address of the first packet, and replace the to-be-checked MAC address carried in the first packet with the Verify the MAC address.
  • it also includes:
  • the receiving unit is further configured to receive a second packet from the network side, where the second packet includes a destination identifier, and the destination identifier of the second packet is used to identify a network interface of the second forwarding unit, where the second packet
  • the forwarding unit is one of at least two forwarding units in the vBNG;
  • the matching unit is further configured to: determine, according to the second identifier of the second packet, the second forwarding unit identifier and the outbound interface information of the network side LB according to the destination identifier of the second packet, where The second share entry is established and sent by the controller, and the second share entry includes the identifier of the second forwarding unit network interface, the second forwarding unit identifier, and the second outbound interface information of the network side LB. Correspondence between the three;
  • the sending unit is further configured to forward the first to the second forwarding unit from the second outbound interface that is identified by the second outbound interface identifier
  • the second outgoing interface is an outgoing interface on the network side LB.
  • the embodiment of the present invention provides a packet forwarding method, which is applied to a forwarding network including a vBNG, where the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB, and the method includes :
  • the controller receives an online success message sent by the vBNG, where the online success message is used to identify that the target terminal successfully goes online through the first forwarding unit, where the first forwarding unit is in at least two forwarding units in the vBNG. a forwarding unit;
  • the controller performs load sharing calculation on the network side to the user side according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message, to obtain a first sharing result, where the
  • the system parameter of the vBNG includes at least one forwarding unit of the vBNG Interface information and traffic statistics;
  • the controller establishes a first sharing entry according to the first sharing result, where the first sharing entry includes the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB. Correspondence between them;
  • it also includes:
  • the controller establishes an interface entry according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message, where the outbound interface entry includes an identifier of the network interface of the first forwarding unit, Corresponding relationship between the first forwarding unit identifier and the first outgoing interface identifier of the network side LB.
  • it also includes:
  • the controller sends the outbound interface entry to the network side LB, where the network side LB is configured to forward the packet according to the outbound interface entry.
  • it also includes:
  • the controller acquires a sharing parameter of the first packet sent by the network side LB, where the first packet is a packet sent from the network side to the user side, and the sharing parameter of the first packet includes the a destination identifier of the first packet and a destination media access control MAC address, where the destination identifier of the first packet is used to identify the target terminal, and the destination MAC address of the first packet is used to identify the first forwarding
  • the network interface of the unit
  • the controller sends the update information of the first distribution entry to the network side LB, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface.
  • it also includes:
  • the controller sends the second distribution entry to the network side LB, where the network side LB is configured to forward the packet according to the second distribution entry.
  • the embodiment of the present invention provides a packet forwarding apparatus, which is applied to a forwarding network including a vBNG, where the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB, where the apparatus includes :
  • a receiving unit configured to receive an online success message sent by the vBNG, where the online success message is used to identify that the target terminal successfully goes online through the first forwarding unit, where the first forwarding unit is at least two forwarding units in the vBNG.
  • a calculation unit configured to perform load sharing calculation on the network side to the user side of the target terminal according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message, to obtain a first sharing result,
  • the system parameter of the vBNG includes interface information and traffic statistics information of at least one forwarding unit of the vBNG;
  • a establishing unit configured to establish a first sharing entry according to the first sharing result, where the first sharing entry includes an identifier of the target terminal, a first forwarding unit identifier, and an outbound interface information of the network side LB. Correspondence between the two;
  • a sending unit configured to send the first sharing entry to the network side LB, to indicate that the network side LB forwards the packet according to the first sharing entry.
  • the establishing unit is further configured to establish an interface entry according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message, where the outbound interface entry includes the Corresponding relationship between the identifier of the forwarding unit network interface, the first forwarding unit identifier, and the first outgoing interface identifier of the network side LB.
  • the receiving unit is further configured to acquire a sharing parameter of the first packet sent by the network side LB, where the first packet is a packet sent from the network side to the user side, where the first Message segmentation
  • the destination parameter includes a destination identifier of the first packet and a destination media access control MAC address, where the destination identifier of the first packet is used to identify the target terminal, and the destination MAC address of the first packet is used to identify a network interface of the first forwarding unit;
  • a determining unit configured to determine, according to the sharing parameter of the first packet and the identifier of the first forwarding unit, the outbound interface information that can be determined by the first outbound interface identifier;
  • the sending unit is further configured to send the update information of the first sharing entry to the network side LB, where the update information includes the outbound interface information that can determine the identifier of the first outgoing interface.
  • the establishing unit is further configured to establish a second balancing entry according to the network topology information of the forwarding network and the system parameter of the vBNG, where the second sharing entry includes a second forwarding unit network interface.
  • the second forwarding unit is one of a plurality of forwarding units in the vBNG;
  • the sending unit is further configured to send the second sharing entry to the network side LB, where the network side LB is configured to forward the packet according to the second sharing entry.
  • the embodiment of the present invention provides a packet forwarding system, which is applied to a forwarding network including a vBNG, where the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB, where the system includes The network side LB and the controller, wherein the network side LB is configured with the apparatus in any one of the foregoing second aspects, wherein the controller is configured with the apparatus in any one of the foregoing fourth aspects.
  • the network side LB receives the first packet forwarded from the network side to the target terminal on the user side.
  • the first outbound interface of the network side LB that is pre-planned to be processed by the target terminal is determined by the first destination interface of the network side LB being determined by the first destination of the first packet.
  • Forwarding path of the first forwarding unit so that the first packet sent to the target terminal can be accurately forwarded to the first forwarding unit that processes the uplink of the target terminal, and the forwarding from the network side to the user side is avoided.
  • the packet may be forwarded to the forwarding unit that is not suitable in the vBNG, thereby reducing the situation in which the vBNG needs to be forwarded from the network side to the VM. Prove the forwarding performance of vBNG.
  • FIG. 1 is a schematic diagram of an application scenario of a vBNG
  • FIG. 2 is a schematic structural diagram of a network of a forwarding network according to an embodiment of the present invention
  • FIG. 3 is a flowchart of a method for forwarding a packet according to an embodiment of the present invention
  • FIG. 4 is a flowchart of a method for forwarding a packet according to an embodiment of the present invention
  • FIG. 5 is a flowchart of a method for updating an entry according to an embodiment of the present invention.
  • FIG. 6 is a flowchart of a method for forwarding a packet according to an embodiment of the present invention.
  • FIG. 7 is a structural diagram of a device of a message forwarding device according to an embodiment of the present disclosure.
  • FIG. 8 is a structural diagram of a device of a message forwarding device according to an embodiment of the present disclosure.
  • FIG. 9 is a schematic structural diagram of a system of a packet forwarding system according to an embodiment of the present disclosure.
  • FIG. 10 is a schematic structural diagram of a hardware of a network side LB according to an embodiment of the present disclosure.
  • FIG. 11 is a hardware structural diagram of a controller according to an embodiment of the present invention.
  • the NFV-based vBNG is a virtual device obtained by virtualizing the functions of the traditional broadband network gateway.
  • vBNG can run in the hardware environment of a general-purpose server and implement related functions that traditional BNG devices can implement.
  • a common vBNG includes at least one master unit and at least two forwarding units, a master unit and The forwarding units are respectively running in different VMs.
  • the terminal can be online through a forwarding unit in the vBNG, so that the terminal can implement data interaction with the network side through the vBNG.
  • the routing forwarding table queried by the network side router to the user side is mainly obtained based on the routing protocol.
  • the forwarding unit of the receiving packet in the forwarding path is not considered to be a suitable one. Forwarding the unit, but just focusing on whether it can be logically implemented.
  • the data and information associated with the terminal will be retained in the forwarding unit that processes the terminal's uplink.
  • the network interface of the forwarding unit the interface for receiving the message forwarded from the network side
  • the forwarding unit can effectively use the data provided when the terminal is online.
  • the packet is forwarded to the terminal, and basically no message is forwarded across the VM. If other forwarding units in the vBNG receive the packet through the network interface, it is likely that other forwarding units cannot forward the packet to the terminal because of the lack of necessary information.
  • the forwarding unit 1 may not have the necessary data to continue forwarding the message a to the user side, or the forwarding unit 1 may not have the function of forwarding the message.
  • the vBNG can only transfer the message a from the VM in which the forwarding unit 1 is located to the forwarding unit 2 in another VM, and the forwarding unit 2 continues to forward the message a to the target terminal. Forward.
  • the forwarding unit 1 and the forwarding unit 2 belong to the vBNG and belong to different VMs, thereby causing packet forwarding across VMs.
  • the inventor believes that the router forwards the packets on the network side to the wrong or inappropriate forwarding unit, which is the main reason for the cross-VM forwarding of packets in the vBNG.
  • the load balancing result of the packets forwarded by the network side to the user side is calculated in advance by the controller, and the load balancing item established according to the load sharing result is delivered to the network side load balancer (English: Load Balancer, abbreviated as LB).
  • the LB of the LB is used as the downlink packet.
  • the downlink is used to describe the packet forwarding direction from the network side to the user side.
  • the uplink can be understood as The forwarding direction of the packet forwarding direction from the user side to the network side is forwarded, so that the downlink packet can be accurately forwarded to the appropriate forwarding unit in the vBNG.
  • the embodiment of the present invention provides a packet forwarding method, apparatus, and system.
  • a forwarding network including a controller, a user side LB, a vBNG, and a network side LB
  • the network side LB receives the slave network side.
  • the network-side LB that is planned in advance is determined by the destination identifier of the first packet that is used to identify the target terminal is matched to the first distribution entry.
  • the first outbound interface is configured to process the forwarding path of the first forwarding unit that is online on the target terminal, so that the first packet sent to the target terminal can be accurately forwarded to the first line that processes the target terminal.
  • the forwarding unit prevents the packets forwarded from the network side to the user side from being forwarded to the forwarding unit that is not suitable in the vBNG, thereby reducing the situation that the vBNG needs to be forwarded across the VM from the network side.
  • the forwarding performance of vBNG is guaranteed.
  • packet forwarding accuracy from the user side to the network side is also required.
  • the inventor has found that when forwarding packets from the user side to the network side, the problem of forwarding messages across VMs in the vBNG may also occur. Specifically, when the user-side LB forwards the packet sent by the user-side terminal to the network side to the vBNG, if the packet is not forwarded to the forwarding unit of the terminal, the vBNG may also forward the message across the VM. .
  • the switch may forward the packet b to the forwarding unit 1 of the vBNG, and the forwarding unit 2 performs the online processing on the target terminal in the vBNG. Therefore, the forwarding unit 1 may not have the necessary data to continue forwarding the message b to the user side, or the forwarding unit 1 may not have the function of forwarding the message.
  • the vBNG can only transfer the message b from the VM in which the forwarding unit 1 is located to the forwarding unit 2 in another VM, and the forwarding unit 2 continues to forward the message b to the network device. Forward.
  • the forwarding unit 1 and the forwarding unit 2 belong to the vBNG and belong to different VMs, thereby causing packet forwarding across VMs.
  • the inventor believes that the phenomenon of forwarding packets across the VM in the vBNG that occurs when the user forwards the packet to the network is mainly caused by forwarding the packet to the wrong or inappropriate forwarding unit.
  • the inventor introduces the load balancing mode into the packet forwarding process of the user-side network side, and the controller pre-calculates the load sharing result of the packet forwarded by the user side to the network side, and the sharing entry established according to the load sharing result. It is delivered to the user-side LB, and the user-side LB uses the distribution entry as the forwarding basis for forwarding packets from the user side to the network side, so that the packets forwarded by the user side to the network side can be accurately forwarded to the appropriate forwarding in the vBNG. unit.
  • the packets forwarded from the user side to the network side may be forwarded to the forwarding unit that is not suitable in the vBNG, and the forwarding performance of the vBNG is guaranteed.
  • the controller may be a software defined network (English: Software Defined Networking, abbreviation: SDN) controller.
  • the load sharing calculation of the forwarding network is implemented by the controller, where the load sharing calculation includes the traffic from the network side to the user side, and also includes the traffic from the user side to the network side.
  • the controller may calculate a downlink traffic load sharing calculation for the target terminal according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message for the target terminal, and perform the first sharing according to the calculation.
  • the first distribution entry is established, and the first distribution entry is sent to the network side LB, and is used to instruct the network side LB to forward the packet according to the first distribution entry.
  • the controller can calculate the load balancing for the terminal from the network side to the user side, and pre-plan the forwarding route of the downlink packet. Therefore, the balancing entry established according to the calculation result can clearly indicate the network side LB.
  • the packet sent to the target terminal is forwarded to the forwarding unit of the target terminal online, so that the accurate packet forwarding from the network side LB to the forwarding unit is completed.
  • the forwarding network includes a controller, a user side LB, a vBNG, and a network side LB.
  • the specific connection relationship between the parts can be seen in FIG. 2 .
  • the network side LB and the user side LB may be the same network entity, or the functions of the network side LB and the user side LB may be implemented by the same network entity.
  • the network side LB and the user side LB may also be different network entities, and different networks.
  • the entities respectively implement the functions of the network side LB and the user side LB.
  • the network entity described here may be an LB or a switch with an LB function.
  • the network side LB and the user side LB may also be virtual LBs of function virtualization under the NFV architecture, and the vLB may be implemented by a server running related programs or software.
  • the user side LB has an interface (English: interface) that is connected to a local device such as a terminal, and is used to receive a packet sent by the terminal to the network side, or to send a packet forwarded by the network side to the terminal.
  • the user side LB further has an interface connected to the forwarding unit of the vBNG, and is configured to forward the packet sent by the terminal to the vBNG, where the user side LB further has an interface connected to the controller, where Sending data to the controller or receiving a delivered entry from the controller.
  • the interface connected to the forwarding unit of the vBNG is the outbound interface of the user side LB, and the user side LB has multiple outbound interfaces.
  • the network side LB has an interface connected to the network device (the network device here refers to the device on the right side of the network side LB, such as a router, for example, as shown in FIG. 2), and is configured to receive the packet forwarded by the network side to the user side, or The packet sent by the user side is sent to the network side.
  • the network side LB further has an interface connected to the forwarding unit of the vBNG, and is configured to forward the packet received from the network side to the vBNG, where the network side LB further has an interface connected to the controller. And used to send data to the controller or receive a delivered item from the controller.
  • the interface connected to the forwarding unit of the vBNG on the network side LB is called the egress interface of the network side LB, and the network side LB has multiple egress interfaces.
  • the vBNG has a master unit and a plurality of forwarding units.
  • a forwarding unit is running in a single VM.
  • the number of forwarding units included in the vBNG can be determined according to the requirements of the actual application scenario. For example, the number of forwarding units can be increased or decreased according to the scenario requirements.
  • the main control unit of the vBNG may be a virtual master process unit (vMPU), and the forwarding unit of the vBNG may be a virtual line process unit (vlPU). .
  • the vBNG mainly transmits data to the controller through the main control unit, for example, sending an online success message of the terminal or a system parameter of the vBNG to the controller.
  • the forwarding unit of the vBNG mainly has a user interface and a network interface, and the user interface of the forwarding unit is connected to the user-side LB, and is used for forwarding packets with the user-side LB.
  • the outbound interface of the user side LB has a corresponding relationship with the user interface of the forwarding unit of the vBNG.
  • the network interface of the forwarding unit is connected to the network side LB for forwarding packets with the network side LB.
  • the LB can be forwarded to the forwarding unit of the terminal online by the user side LB, and the network side LB can be guaranteed from the network.
  • the packet sent by the side terminal is accurately forwarded to the forwarding unit of the terminal. Therefore, in order to avoid the possibility of forwarding packets across VMs in the vBNG, in the vBNG, the restricted packets are forwarded in the same forwarding unit. That is, when the forwarding unit 1 receives the message a through the user interface, the network interface of the forwarding unit 1 is used to forward the message a. When the forwarding unit 2 receives the message b through the network interface, the user of the forwarding unit 2 is used. The interface forwards the packet b.
  • the vBNG can implement the function of limiting the forwarding of packets in the same forwarding unit by setting an internal forwarding routing table.
  • connection is not limited to a direct physical connection relationship, and may be an indirect connection relationship or a non-physical connection relationship.
  • the user side and the network side in the embodiment of the present invention are defined by the vBNG, and the user side of the vBNG refers to a physical entity (such as a forwarding unit) facing the terminal (including the terminal accessing the vBNG).
  • the user interface or function performs operations such as user authentication, IP address allocation, and user forwarding entry generation or deletion.
  • the network side of the vBNG refers to a physical entity (such as the network interface of the forwarding unit) or a function on the side of the network (for example, a network including vBNG to the metropolitan area network and the backbone network to forward data), and mainly performs routing with other devices in the network.
  • the protocol converges and performs IP packet forwarding operations based on the routing table.
  • the network topology information of the forwarding network mainly includes the correspondence between the network side LB, the user side LB, and the vBNG interface.
  • the controller may acquire network topology information of the forwarding network by using a topology discovery process.
  • the topology discovery process is implemented by the Link Layer Discovery Protocol (LLDP).
  • the controller obtains network topology information of the forwarding network by acquiring the LLDP carrying the topology relationship sent by the network side LB and the user side LB.
  • the controller can initiate the topology discovery process periodically.
  • the network topology information may include identifiers of the devices in the forwarding network (including the network side LB, the user side LB, the vBNG, and the forwarding unit in the vBNG), such as an ID and a media access control (English: Media Access Control, abbreviation: MAC) address and other forms, such as vBNG can be assigned 00:00:00:00:00:01. Interface name and interface identifier of each device. And the connection relationship between the interfaces, for example, the correspondence between an outbound interface of the network side LB and the network interface of a forwarding unit, or the network interface of the forwarding unit to which the outgoing interface of the network side LB can forward the packet. .
  • identifiers of the devices in the forwarding network including the network side LB, the user side LB, the vBNG, and the forwarding unit in the vBNG
  • the system parameter of the vBNG includes interface information and traffic statistics information of at least one forwarding unit of the vBNG, and the controller sends the system parameter of the vBNG by using the vBNG.
  • the interface information of the at least one forwarding unit of the vBNG may include the network interface of the forwarding unit and the identifier of the user interface, and the traffic statistics information may include the traffic statistics corresponding to the user interface and the network interface on the forwarding unit.
  • the system parameters of the vBNG may be periodically reported to the controller.
  • the controller also needs to obtain an online success message of the target terminal before establishing a forwarding entry for the target terminal.
  • the online success message is sent by the vBNG.
  • the first forwarding unit is one of a plurality of forwarding units in the vBNG.
  • the controller may clarify the identifier of the target terminal and the correspondence between the target terminal and the first forwarding unit by using the online success message.
  • the classification information may be stored in the shared information database, for example, the topology information of the forwarding unit and the network side LB and the user side LB, the hardware information of the forwarding unit, the interface identifier of the forwarding unit, and the user information of the forwarding unit (mainly here) Refers to the terminal statistics information that is sent through a forwarding unit), the load information of the forwarding unit (including the traffic statistics of the user interface and the network interface), the service type of the forwarding unit (the service type of the terminal on the forwarding unit).
  • the controller may perform network side to user side of the target terminal according to network topology information of the forwarding network, system parameters of the vBNG, and the online success message.
  • the load sharing calculation calculates the first shared result.
  • the first sharing result may understand the calculated downlink forwarding path from the network side LB to the vBNG for the target terminal.
  • the controller establishes a first sharing entry according to the first sharing result, where the first sharing entry includes the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB. Correspondence between them.
  • the lookup key of the first share entry may be an identifier of the target terminal (that is, a destination identifier of the first packet).
  • the controller may send the first sharing entry to the network side LB, where the network side LB is instructed to use the first sharing entry according to the first sharing entry.
  • the vBNG forwards the packet.
  • the load forwarding calculation may be used to calculate a downlink packet forwarding path for the target terminal between the network side LB and the first forwarding unit.
  • the network side LB receives the downlink packet for the target terminal, since the controller has performed the load sharing calculation for the target terminal in advance, the downlink report for the target terminal is planned in advance.
  • the forwarding path of the text so the network side LB can accurately determine the first forwarding unit by matching the first sharing entry.
  • the identifier of the target terminal described herein may be the IP address of the target terminal.
  • the controller can calculate the load balancing from the network side LB to the vBNG for one terminal, and pre-plan the forwarding route of the downlink packet. Therefore, the balancing entry established according to the calculation result can clearly indicate the network side LB.
  • the packet sent to the target terminal is forwarded to the forwarding unit of the target terminal online, so that the packet forwarding from the network side LB to the forwarding unit is accurately performed.
  • the outbound interface information of the network side LB in the first sharing entry may be a special value 0xff
  • the specific outgoing interface identifier may not be determined in the network side LB.
  • the forwarding unit having the same processing function (or processing the same data type) among the plurality of forwarding units can be configured.
  • the user interface is configured in a virtual user interface group and the network interface is also configured in a virtual network interface group.
  • the user interfaces of these forwarding units having the same processing function can be understood as group members in this virtual user interface group, and the network interfaces of these forwarding units having the same processing function can be understood as group members in this virtual network interface group.
  • a group member in a virtual user interface group will be assigned the same virtual MAC address in addition to the interface ID.
  • the virtual MAC address is used in the packet forwarding process.
  • a group member in a virtual network interface group will be assigned the same virtual MAC address in addition to the interface identifier.
  • the virtual MAC address is used in the packet forwarding process.
  • the controller may calculate the two downlink forwarding paths.
  • the two downlink forwarding paths are respectively implemented by two network interfaces of forwarding units that are in different virtual network interface groups.
  • one downlink forwarding path needs to pass through the network interface a of the forwarding unit 1, and another downlink forwarding path needs to pass through the forwarding unit. 1 network interface b.
  • the controller can clarify the specific outgoing interface of the network side LB in each downlink forwarding path, the controller is temporarily unnecessary before the network side LB does not select the downlink forwarding path.
  • the network side LB is provided with specific outbound interface information in the first sharing entry.
  • the network topology information of the forwarding network acquired by the controller may further include a virtual network interface group and a virtual MAC address allocated by the virtual user interface group.
  • the controller may establish the first sharing entry, and the controller may further The network topology information of the forwarding network, the system parameter of the vBNG, and the online success message establish an interface entry, where the outbound interface entry includes an identifier of the first forwarding unit network interface, and the first forwarding unit identifier And the first outbound interface identifies the correspondence between the three.
  • the lookup key of the outbound interface entry is the identifier of the first forwarding unit identifier and the first forwarding unit network interface (that is, the destination MAC address of the first packet).
  • the controller determines, by the load sharing calculation, that the target terminal is Each of the downlink forwarding paths corresponds to a network interface of a forwarding unit. Therefore, the controller can establish an outbound interface entry according to each downlink forwarding path, that is, multiple outbound interface entries.
  • the outbound interface entry in the embodiment of the present invention can be understood as an outbound interface entry determined according to the destination MAC address of the first packet sent by the network side LB from multiple outbound interface entries.
  • the controller may have two processing modes after the outbound interface entry is established.
  • the first processing mode is to keep the outbound interface entry in the controller, and not to send the same. Give the network side LB.
  • the second processing mode is to send the outbound interface entry to the network side LB.
  • the two treatment methods will be introduced separately.
  • the network side LB does not have the outbound interface entry, so after the first packet is received, the network side LB cannot match the first sharing entry.
  • a specific outbound interface is determined, and the network side LB sends the sharing parameter of the first packet to the controller.
  • the first packet is a packet sent from the network side to the user side, and the first packet carries the destination identifier and the destination MAC address when the network side LB is reached, and the destination identifier is used. And indicating the destination of the first message, that is, the identifier of the target terminal.
  • the destination MAC address may be an address identifier of the next device that is forwarded to the downlink packet forwarding path, and may be a virtual MAC address that is uniformly allocated by the network interface of the first forwarding unit.
  • the network side LB may send the sharing parameter of the first packet to the controller in two sending manners.
  • the first type of transmission is to send the sharing parameter of the first packet to the controller, and locally, that is, the network side LB temporarily saves the first packet.
  • the second sending mode is that the first packet that includes the sharing parameter is sent to the controller, and the first packet is not saved locally.
  • the controller may determine, according to the sharing parameter of the first packet, that the first forwarding unit identifier matches the reserved outbound interface entry, and determine that the outbound interface information of the first outgoing interface identifier is determined. .
  • the outbound interface information of the first outbound interface identifier may be directly determined by the first outbound interface identifier.
  • the controller when the controller obtains the sharing parameter of the first packet, the controller may be configured according to the destination MAC address of the first packet (that is, the virtual MAC of the first forwarding unit network interface) Addressing, determining the first forwarding in network topology information of the forwarding network
  • the outbound interface (the first outgoing interface) of the network side LB corresponding to the network interface of the first forwarding unit is determined.
  • the controller sends the update information of the first distribution entry to the network side LB, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface.
  • the update information of the first distribution entry may be only the outbound interface information that may determine the identifier of the first outbound interface, or may be determined by the identifier of the first outbound interface.
  • the first distribution entry of the outbound interface information may be only the outbound interface information that may determine the identifier of the first outbound interface, or may be determined by the identifier of the first outbound interface.
  • the network side LB may determine the first outbound interface identifier according to the identifier of the first outbound interface. Thereby, forwarding of the first packet is completed.
  • the network side LB may also update the first distribution entry of the network, so that the first packet may be matched by the updated first distribution entry when the first packet is received.
  • An outbound interface identifier can be used to forward the first packet without the assistance of the controller.
  • the controller may only issue the first message.
  • the update information of the first sharing entry is sent to the network side LB.
  • the controller may use the first packet and the The update information of the first distribution entry is sent to the network side LB, and the first packet is forwarded by the network side LB.
  • the controller sends the outbound interface entry to the network side LB, so that the network side LB forwards the packet according to the outbound interface entry.
  • the destination MAC address of the first packet is the same as the identifier of the first forwarding unit network interface, because the destination MAC address of the first packet is used to identify the network interface of the first forwarding unit.
  • the network side LB may obtain the first outbound interface identifier according to the first forwarding unit identifier and the destination MAC address of the first packet, so as to complete forwarding of the first packet.
  • the network side LB may send the sharing parameter of the first packet to the controller when the outbound interface entry is matched, and the controller determines, according to the sharing parameter of the first packet, Sending, to the network side LB, the update information of the first distribution entry that includes the outbound interface information that can identify the first outbound interface identifier, where the network side LB passes the first sharing table Update information for the item is updated If the first packet is received, the network side LB can perform the matching only once, that is, the first outbound interface identifier is determined only after the first uplink interface is matched. System resources have improved matching efficiency.
  • the destination identifier is used to identify the terminal, and may be used to identify the network interface of the forwarding unit. Therefore, in order to enable the network side LB to implement forwarding of the packet for identifying the interface of the forwarding unit, the controller may obtain the network topology information of the forwarding network and the system parameter of the vBNG. The corresponding entry can be created.
  • the controller establishes a second balancing entry according to the network topology information of the forwarding network and the system parameter of the vBNG, where the second sharing entry includes an identifier of the network interface of the second forwarding unit, a correspondence between the second forwarding unit identifier and the second outbound interface information of the network side LB, where the second forwarding unit is one of the plurality of forwarding units in the vBNG.
  • the controller sends the second distribution entry to the network side LB, where the network side LB is configured to forward the packet according to the second distribution entry.
  • the second forwarding unit may be the same forwarding unit as the first forwarding unit, or may be a different forwarding unit.
  • the interface identifier of the second forwarding unit in the second sharing entry may be the virtual network interface.
  • the identifier of the second forwarding unit network interface in the second sharing entry may be the network interface of the second forwarding unit Real interface identifier, such as interface IP.
  • FIG. 3 is a flowchart of a method for forwarding a packet according to an embodiment of the present disclosure, where the method includes:
  • the network side LB receives the first packet from the network side, where the first packet includes a destination identifier, and the destination identifier of the first packet is used to identify the target terminal.
  • the destination identifier of a packet is used to identify the forwarding destination of the packet.
  • the destination identifier of the first packet may be understood to be the same as the identifier of the target terminal.
  • the network side LB determines that the first forwarding unit identifier and the outbound interface information of the network side LB are determined according to the first identifier of the first packet, and the outbound interface information of the network side LB is determined.
  • a load sharing item is established and delivered by the controller, and the first sharing entry includes a correspondence between the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB.
  • the first forwarding unit corresponding to the first forwarding unit identifier is one of at least two forwarding units in the vBNG, and the first forwarding unit is a forwarding unit that uplinks the target terminal.
  • the network side LB determines the first outbound interface identifier according to the outbound interface information, the network side LB forwards the first outbound interface that is identified by the first outbound interface identifier to the first forwarding unit.
  • the first outbound interface is an outbound interface on the network side LB.
  • the network side LB passes the first packet when receiving the first packet forwarded from the network side to the target terminal on the user side.
  • the first outbound interface of the network side LB that is pre-planned to the first forwarding unit that processes the uplink of the target terminal may be determined by the first destination interface of the network side LB that is used to identify the target terminal.
  • a message is forwarded to the first forwarding unit that processes the uplink of the target terminal, so that packets forwarded from the network side to the user side may be forwarded to an unsuitable forwarding unit in the vBNG, thereby reducing the need for vBNG.
  • the forwarding of packets received from the network side across the VM ensures the forwarding performance of the vBNG.
  • the first outbound interface identifier may not be determined from the outbound interface information.
  • the possibility that the first outbound interface identifier cannot be determined has been explained in the foregoing, and will not be described again here.
  • the embodiment of the present invention provides two ways of implementing forwarding, The manner of implementing forwarding corresponds to the foregoing two methods of processing after the outbound interface entry is established by the controller.
  • the first method for implementing forwarding corresponds to the foregoing second processing mode, that is, the network side LB obtains the outbound interface entry delivered by the controller in advance.
  • FIG. 4 is a flowchart of a method for forwarding a packet according to an embodiment of the present invention.
  • the network side LB determines, according to the destination MAC address of the first packet, that the first forwarding unit identifier matches the outbound interface entry, and determines the corresponding first outbound interface identifier, where the The destination MAC address of the packet is used to identify the network interface of the first forwarding unit, the outbound interface entry is established by the controller, and the outbound interface entry includes the network interface of the first forwarding unit. Corresponding relationship between the identifier, the first forwarding unit identifier, and the first outgoing interface identifier.
  • the network side LB forwards the first packet from the first outbound interface to the first forwarding unit.
  • the first forwarding unit identifier is obtained, and the destination MAC address of the first packet is received by the first packet. Obtained, and because the destination MAC address of the packet is used to identify the network interface of the first forwarding unit, the destination MAC address of the packet is the same as the identifier of the network interface of the first forwarding unit, so The network side LB can match the outbound interface entry and directly obtain the first outbound interface identifier.
  • FIG. 5 is a flowchart of a method for updating an entry according to an embodiment of the present invention. include:
  • the network side LB sends a sharing parameter for the first packet to the controller, where the sharing parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the network side LB receives the update information sent by the controller for the first sharing entry.
  • the network side LB updates the first distribution entry according to the update information of the first distribution entry, and the updated first distribution entry includes the first outgoing interface identifier that can be determined. Outbound interface information.
  • the controller may send the first outbound interface identifier as update information to the network.
  • Side LB may update the first outbound interface identifier to the first distribution entry.
  • the first outbound interface identifier may be directly used as the outbound interface information of the network side LB.
  • the matching of the first sharing table can be directly matched by only one matching.
  • the item determines the first outbound interface identifier, thereby saving the matching process and saving system resources.
  • the second implementation of the forwarding mode is the same as the foregoing processing mode.
  • the network side LB does not obtain the outbound interface entry delivered by the controller.
  • FIG. 6 is a flowchart of a method for forwarding a packet according to an embodiment of the present invention.
  • the network side LB sends a sharing parameter for the first packet to the controller, where the sharing parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the network side LB sends the sharing parameter of the first packet to the controller, and the controller assists in determining the network side LB corresponding to the network interface of the first forwarding unit. Outbound interface.
  • the network side LB receives the update information sent by the controller for the first sharing entry.
  • the network side LB determines, according to the outbound interface identifier, the first outbound interface identifier according to the outbound interface information, according to the first identifier of the first packet.
  • the network side LB forwards the first packet to the first forwarding unit from the first egress interface that is identified by the first egress interface identifier.
  • the network side LB may determine the first outbound interface identifier according to the identifier that may be determined by the first outbound interface, thereby completing the Forwarding of the first message.
  • the network side LB may further update the first sharing entry, so that when the first packet is received, the updated first camping entry may match the first An outbound interface identifier can be used to forward the first packet without the assistance of the controller, thereby saving the matching process and saving system resources.
  • the network side LB forwarding the packet from the network side to the user side matches the distribution entry delivered by the controller, that is, the network side LB
  • the forwarding path to the forwarding unit of the vBNG is predetermined by the controller through load sharing calculation.
  • packets forwarded by other network devices on the network side to the user side may not follow the load balancing mode. Therefore, when the first packet is forwarded to the network side LB, the identifier (ie, the destination MAC address) of the device (ie, the forwarding unit) to be forwarded to is not the identifier of the network interface of the first forwarding unit.
  • the destination MAC address carried by the first packet is not the correct MAC address, which may cause incorrect forwarding guidance and needs to be corrected.
  • the embodiment of the present invention provides a method for verifying and correcting the destination MAC address of the packet.
  • the first distribution entry further includes a check MAC address corresponding to the first packet, where the check MAC address is used to identify that the destination forwarding unit is configured to receive the first packet. Interface.
  • the check MAC address described herein may be a MAC address of the network interface used by the first forwarding unit to receive the first packet.
  • the corresponding MAC address may also be determined. site.
  • the network side LB Before the network side LB forwards the first packet from the first egress interface that is identified by the first egress interface identifier to the first forwarding unit, the network side LB is configured according to the first packet.
  • the destination ID matches the first distribution entry. It also includes:
  • the network side LB matches the first distribution entry according to the destination identifier of the first packet, and determines the corresponding check MAC address.
  • the network side LB determines whether the check MAC address and the MAC address to be verified carried in the first packet are consistent.
  • the MAC address to be verified is used as the destination MAC address of the first packet.
  • the check MAC address is used as the destination MAC address of the first packet, and the to-be-checked MAC address carried in the first packet is replaced with the check MAC address.
  • the MAC address to be verified of the first packet can be understood as the destination MAC address carried by the first packet that has not been verified. If the MAC address to be verified of the first packet is the same as the MAC address to be verified, the MAC address of the device that is forwarded to the next packet is considered to be the first The destination MAC address of a message. If the MAC address to be verified of the first packet is different from the check MAC address, the MAC address of the device that is forwarded to the next packet is incorrect, and the check is performed. The MAC address is replaced with the MAC address to be verified, and the check MAC address is used as the destination MAC address of the first packet.
  • the network side LB matches the destination information of the second packet to the second distribution entry, and determines the corresponding second forwarding unit identifier and the outbound interface information of the network side LB.
  • the second extension interface entry includes the identifier of the second forwarding unit network interface, the second forwarding unit identifier, and the second outbound interface information of the network side LB. Correspondence between the people.
  • the controller may be configured to establish a corresponding entry in the case that the network topology information of the forwarding network and the system parameter of the vBNG are obtained, where the network side LB implements the destination identifier for identifying the forwarding unit.
  • the forwarding of the packets of the interface improves the applicability of the forwarding network.
  • FIG. 7 is a structural diagram of a device of a packet forwarding apparatus according to an embodiment of the present invention.
  • the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB.
  • the message forwarding device 700 includes:
  • the receiving unit 701 is configured to receive the first packet from the network side, where the first packet includes a destination identifier, and the destination identifier of the first packet is used to identify the target terminal.
  • the matching unit 702 is configured to determine, according to the first identifier of the first packet, the first forwarding unit identifier and the outbound interface information of the network side LB according to the destination identifier of the first packet, where the first The distribution entry is established and delivered by the controller, and the first distribution entry includes a correspondence between the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB.
  • the first forwarding unit corresponding to the first forwarding unit identifier is one of at least two forwarding units in the vBNG, and the first forwarding unit is a forwarding unit that goes online to the target terminal;
  • the matching unit determines the first outbound interface identifier according to the outbound interface information, and triggers the sending unit 703;
  • the sending unit 703 is configured to forward the first packet to the first forwarding unit from the first outbound interface that is identified by the first outbound interface identifier, where the first outbound interface is the network side LB An outbound interface.
  • the matching unit is further configured to: according to the destination MAC address of the first packet, and the first forwarding unit The identifier is matched to the previously obtained outbound interface entry, and the corresponding first outbound interface identifier is determined, and the destination MAC address of the first packet is used to identify the network interface of the first forwarding unit, and the outbound interface
  • the entry is established by the controller, and the outbound interface entry includes the first forwarding list a correspondence between the identifier of the meta-network interface, the first forwarding unit identifier, and the first outgoing interface identifier;
  • the sending unit is further configured to: after the matching unit determines the corresponding first outbound interface identifier, send a sharing parameter for the first packet to the controller, where the sharing The parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the receiving unit is further configured to receive, by the controller, update information for the first distribution entry, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface;
  • an update unit configured to update the first distribution entry according to the update information of the first distribution entry, where the updated first distribution entry includes an outbound interface that can determine the identifier of the first outgoing interface information.
  • the sending unit is further configured to: if the matching unit cannot determine the first outbound interface identifier according to the outbound interface information, send a sharing parameter for the first packet to the controller, where The sharing parameter includes a destination identifier of the first packet and a destination MAC address of the first packet.
  • the receiving unit is further configured to receive, by the controller, update information for the first distribution entry, where the update information includes the outbound interface information that can determine the identifier of the first outbound interface;
  • the matching unit is further configured to: determine, according to the outbound interface identifier, the first outbound interface identifier according to the outbound interface information, according to the first identifier of the first packet;
  • the sending unit is further configured to forward the first packet to the first forwarding unit from the first outbound interface that is identified by the first outbound interface identifier.
  • the first sharing entry further includes a check MAC address corresponding to the first packet, where the check MAC address is used by the destination forwarding unit to receive the first packet.
  • the MAC address of the interface, the matching unit is further configured to: determine, according to the destination identifier of the first packet, the matching first MAC address, and the corresponding check MAC address; the packet forwarding device further includes :
  • a determining unit configured to determine whether the check MAC address and the to-be-checked MAC address carried in the first packet are consistent; if they are consistent, triggering the first processing unit; if not, triggering the second processing unit;
  • the first processing unit is configured to use the MAC address to be verified as a destination MAC address of the first packet
  • the second processing unit is configured to use the check MAC address as the destination MAC address of the first packet, and replace the to-be-checked MAC address carried in the first packet with the Verify the MAC address.
  • the network side LB passes the first packet when receiving the first packet forwarded from the network side to the target terminal on the user side.
  • the first outbound interface of the network side LB that is pre-planned to the first forwarding unit that processes the uplink of the target terminal may be determined by the first destination interface of the network side LB that is used to identify the target terminal. Forwarding the path, so that the first packet sent to the target terminal can be forwarded to the first forwarding unit that processes the uplink of the target terminal, and the packet forwarded from the network side to the user side may be forwarded. It is not suitable for the forwarding unit in the vBNG, thereby reducing the situation that the vBNG needs to be forwarded across the VM from the network side, and the forwarding performance of the vBNG is guaranteed.
  • FIG. 8 is a schematic structural diagram of a device for forwarding a packet according to an embodiment of the present invention.
  • the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB.
  • the message forwarding device 800 includes:
  • the receiving unit 801 is configured to receive an online success message sent by the vBNG, where the online success message is used to identify that the target terminal successfully goes online through the first forwarding unit, where the first forwarding unit is at least two forwarding units in the vBNG. a forwarding unit in the middle;
  • the calculating unit 802 is configured to perform network-to-user-side load sharing calculation on the target terminal according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message, to obtain a first sharing result.
  • the system parameter of the vBNG includes interface information and traffic statistics information of at least one forwarding unit of the vBNG;
  • the establishing unit 803 is configured to establish a first sharing entry according to the first sharing result, where the first sharing entry includes an identifier of the target terminal, a first forwarding unit identifier, and an outbound interface information of the network side LB. Correspondence between the three;
  • the sending unit 804 is configured to send the first sharing entry to the network side LB, where the network side LB is configured to forward the packet according to the first sharing entry.
  • the establishing unit is further configured to establish an interface entry according to the network topology information of the forwarding network, the system parameter of the vBNG, and the online success message, where the outbound interface entry includes the Corresponding relationship between the identifier of the forwarding unit network interface, the first forwarding unit identifier, and the first outgoing interface identifier of the network side LB.
  • the sending unit is further configured to send the outbound interface entry to the network side LB, where the network side LB is configured to forward the packet according to the outbound interface entry.
  • the receiving unit is further configured to acquire a sharing parameter of the first packet sent by the network side LB, where the first packet is a packet sent from the network side to the user side, where the first The packet sharing parameter includes the destination identifier and the destination MAC address of the first packet, where the destination identifier of the first packet is used to identify the target terminal, and the destination MAC address of the first packet is used to identify a network interface of the first forwarding unit;
  • a determining unit configured to determine, according to the sharing parameter of the first packet and the identifier of the first forwarding unit, the outbound interface information that can be determined by the first outbound interface identifier;
  • the sending unit is further configured to send the update information of the first sharing entry to the network side LB, where the update information includes the outbound interface information that can determine the identifier of the first outgoing interface.
  • the establishing unit is further configured to establish a second balancing entry according to the network topology information of the forwarding network and the system parameter of the vBNG, where the second sharing entry includes a second forwarding unit network interface.
  • the second forwarding unit is one of a plurality of forwarding units in the vBNG;
  • the sending unit is further configured to send the second sharing entry to the network side LB, where the network side LB is configured to forward the packet according to the second sharing entry.
  • FIG. 9 is a system structural diagram of a message forwarding system according to an embodiment of the present invention.
  • the forwarding network includes a controller, a user side LB, the vBNG, and a network side LB
  • the packet forwarding system 900 includes the network side LB901 and the controller 902.
  • the network side LB 901 is configured with the apparatus of any one of the foregoing embodiments shown in FIG. 7
  • the controller 902 is configured with the apparatus of any one of the foregoing embodiments.
  • the network side LB 901 corresponds to the network side LB mentioned in the foregoing embodiments shown in FIG. 3, FIG. 4, FIG. 5 and FIG.
  • the controller 902 in this embodiment corresponds to the controller mentioned in the foregoing embodiment.
  • the specific implementation manners of the network side LB 901 and the controller 902 in this embodiment refer to the detailed description of the foregoing embodiment. This embodiment is not described here.
  • FIG. 10 is a hardware structure diagram of a network side LB according to an embodiment of the present invention.
  • the network side LB1000 is applied to a forwarding network including a vBNG, where the forwarding network further includes a controller, a user side LB, and The vBNG, the network side LB1000 includes a memory 1001, a receiver 1002, and a transmitter 1003, and a processor 1004 connected to the memory 1001, the receiver 1002, and the transmitter 1003, respectively, the memory 1001
  • the processor 1004 is configured to invoke the program instructions stored by the memory 1001 to perform the following operations:
  • the receiver 1002 is triggered to receive the first packet from the network side, where the first packet includes a destination identifier, and the destination identifier of the first packet is used to identify the target terminal.
  • the controller is set up and delivered, and the first distribution entry includes a correspondence between the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB, where the first forwarding is performed.
  • the first forwarding unit corresponding to the unit identifier is one of the at least two forwarding units in the vBNG, and the first forwarding unit is a forwarding unit that uplinks the target terminal;
  • the sender 1003 is triggered to forward the first packet to the first forwarding unit from the first outbound interface that is identified by the first outbound interface identifier.
  • the first outgoing interface is an outgoing interface on the network side LB.
  • the processor 1004 may be a central processing unit (CPU), and the memory 1001 may be an internal memory of a random access memory (RAM) type, the receiver 1002 and The transmitter 1003 may include a common physical interface, and the physical interface may be an Ethernet interface or an Asynchronous Transfer Mode (ATM) interface.
  • the processor 1004, the transmitter 1003, the receiver 1002, and the memory 1001 may be integrated into one or more independent circuits or hardware, such as an Application Specific Integrated Circuit (ASIC).
  • ASIC Application Specific Integrated Circuit
  • FIG. 11 is a schematic diagram of a hardware structure of a controller according to an embodiment of the present invention.
  • the controller 1100 is applied to a forwarding network including a vBNG, where the forwarding network further includes a user side LB, the vBNG, and The network side LB, the controller 1100 includes a memory 1101, a receiver 1102, and a transmitter 1103, and a processor 1104 connected to the memory 1101, the receiver 1102, and the transmitter 1103, respectively, the memory 1101
  • the processor 1104 is configured to invoke the program instructions stored by the memory 1101 to perform the following operations:
  • the receiver 1102 is configured to receive an online success message sent by the vBNG, where the online success message is used to identify that the target terminal successfully goes online through the first forwarding unit, where the first forwarding unit is at least two forwarding units in the vBNG. a forwarding unit in the middle;
  • the first sharing entry includes a correspondence between the identifier of the target terminal, the first forwarding unit identifier, and the outbound interface information of the network side LB. relationship;
  • the transmitter 1103 is configured to send the first distribution entry to the network side LB, where the network side LB is configured to forward the packet according to the first distribution entry.
  • the processor 1104 may be a CPU
  • the memory 1101 may be a RAM type internal memory
  • the receiver 1102 and the transmitter 1103 may include a common physical interface, and the physical interface may be an Ethernet ( Ethernet) interface or ATM interface.
  • the processor 1104, the transmitter 1103, the receiver 1102, and the memory 1101 can be integrated into one or more separate circuits or hardware, such as an ASIC.
  • the first packet, the first distribution entry, the first forwarding unit, and the first interface of the first outbound interface mentioned in the embodiment of the present invention are only used for name identification, and do not represent the first in the order. The same rule applies to the "second".

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明实施例公开了一种报文转发方法、装置和系统,在包括控制器、用户侧LB、vBNG和网络侧LB的转发网络中,所述网络侧LB在接收到从网络侧向用户侧的目标终端转发的第一报文时,通过所述第一报文的用于标识目标终端的目的标识匹配到第一分担表项,可以确定出预先规划好的所述网络侧LB的第一出接口到处理所述目标终端上线的第一转发单元的转发路径,从而可以准确的将发向所述目标终端的所述第一报文转发到处理所述目标终端上线的第一转发单元,避免了从网络侧向用户侧转发的报文可能被转发到所述vBNG中不适合的转发单元处,从而降低了vBNG出现需要将从网络侧接收的报文跨VM转发的情况,保证了vBNG的转发性能。

Description

一种报文转发方法、装置和系统
本申请要求于2015年12月31日提交中国专利局、申请号为CN201511030539.2、发明名称为“一种报文转发方法、装置和系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及数据处理领域,特别是涉及一种报文转发方法、装置和系统。
背景技术
网络功能虚拟化(英文:network functions virtualization,缩写:NFV)技术的基本原理是通过虚拟化技术将原来需要多种设备类型(如防火墙、负载均衡器等)、多个物理设备形态才能提供的网络业务功能,改为虚拟设备对外提供业务功能,这样可以实现一台物理设备支持多个虚拟设备,甚至支持一台物理设备虚拟出多种不同业务类型的虚拟设备,从而能够降低成本。
基于NFV架构的虚拟宽带网络网关(英文:virtual Broadband Network Gateway,缩写:vBNG)是通过对传统宽带网络网关功能的虚拟化得到的虚拟设备。vBNG可以运行在通用服务器的硬件环境中,并实现传统BNG设备能够实现的相关功能。例如,vBNG可以完成对用户的上线处理、用户接入、用户认证鉴权与计费(英文:Authentication,Authorization and Accounting,缩写:AAA)、从配置的地址池中为用户分配地址以及实现用户数据报文与网络的互相转发等功能。
vBNG可以包括一个主控单元和多个转发单元,主控单元和转发单元分别运行在不同的虚拟机(英文:Virtual Machine,缩写:VM)中。处于用户侧的终端可以通过vBNG的转发单元实现与网络侧的数据交互。图1所示的为一种常见的vBNG的应用场景,从网络侧向用户侧的一个终端转发一个报文时,这个报文需要通过路由器转发到vBNG,路由器到vBNG的报文转发路径需要通过查路由转发表获得,例如转发信息库(英文:Forward Information Base,缩写:FIB)表。该路由转发表主要是基于路由协议收敛得到,在转发报文的过程,不会考虑到转发路径中接收报文的转发单元是否是一个合适的转发单元,而只是关注在逻辑上是否能够实现。由此可能会导致vBNG中不 适合处理这个报文的转发单元接收到了这个报文,为此,vBNG需要将这个报文转移到自身的另一个适合处理这个报文的转发单元中,再由该转发单元的用户接口向用户侧转发这个报文,形成例如图1中所示的报文转发路径1。由于转发单元分别处于不同的VM中,转发报文过程中,将报文在vBNG的转发单元中转移的情况可以理解为跨VM转发报文。
在NFV环境下,vBNG转发性能本来就比专用的宽带远程接入服务器、宽带网络网关等物理设备的转发性能要低,在vBNG中跨VM转发报文会进一步降低vBNG的转发性能。可见,在vBNG中跨VM转发报文是一个亟需解决的技术问题。
发明内容
为了解决上述技术问题,本发明实施例提供了一种报文转发方法、装置和系统,降低了vBNG出现需要将从网络侧接收的报文跨VM转发的情况,保证了vBNG的转发性能。
第一方面,本发明实施例提供了一种报文转发方法,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述方法包括:
所述网络侧LB从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端;
所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元;
若所述网络侧LB根据所述出接口信息确定出第一出接口标识,所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
可选的,还包括:
若所述网络侧LB根据所述出接口信息不能确定出第一出接口标识,所述网络侧LB预先获取出接口表项;
所述网络侧LB根据所述第一报文的目的媒体访问控制MAC地址和所述第一转发单元标识匹配到所述出接口表项,确定出对应的所述第一出接口标识,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述出接口表项为由所述控制器建立,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系;
所述网络侧LB从所述第一出接口向所述第一转发单元转发所述第一报文。
可选的,所述网络侧LB确定出对应的所述第一出接口标识之后,还包括:
所述网络侧LB向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
所述网络侧LB接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
所述网络侧LB根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
可选的,若所述网络侧LB根据所述出接口信息不能确定出第一出接口标识,还包括:
所述网络侧LB向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
所述网络侧LB接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
所述网络侧LB根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接 口信息;
所述网络侧LB根据所述第一报文的目的标识匹配到更新后的所述第一分担表项,根据所述出接口信息确定出所述第一出接口标识;
所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文。
可选的,所述第一分担表项还包括与所述第一报文对应的校验MAC地址,所述校验MAC地址为所述目的转发单元用于接收所述第一报文的网络接口的MAC地址,在所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文之前,所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,还包括:所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述校验MAC地址;所述方法还包括:
所述网络侧LB判断所述校验MAC地址和所述第一报文中携带的待校验MAC地址是否一致;
若一致,将所述待校验MAC地址作为所述第一报文的目的MAC地址;
若不一致,将所述校验MAC地址作为所述第一报文的目的MAC地址,并将所述第一报文中携带的所述待校验MAC地址替换为所述校验MAC地址。
可选的,还包括:
所述网络侧LB从网络侧接收第二报文,所述第二报文包括目的标识,所述第二报文的目的标识用于标识第二转发单元的网络接口,所述第二转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
所述网络侧LB根据所述第二报文的目的标识匹配到第二分担表项,确定出对应的所述第二转发单元标识和所述网络侧LB的出接口信息,所述第二分担表项由所述控制器建立并下发,所述第二分担表项包括所述第二转发单元网络接口的标识、第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系;
若所述网络侧LB根据所述第二出接口信息确定出第二出接口标识,所述 网络侧LB从所述第二出接口标识所标识的第二出接口向所述第二转发单元转发所述第二报文,所述第二出接口为所述网络侧LB上的一个出接口。
第二方面,本发明实施例提供了一种报文转发装置,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述装置包括:
接收单元,用于从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端;
匹配单元,用于根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元;若所述匹配单元根据所述出接口信息确定出第一出接口标识,触发发送单元;
所述发送单元,用于从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
可选的,若所述匹配单元根据所述出接口信息不能确定出第一出接口标识,所述匹配单元,还用于根据所述第一报文的目的媒体访问控制MAC地址和所述第一转发单元标识匹配到预先获取的出接口表项,确定出对应的所述第一出接口标识,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述出接口表项为由所述控制器建立,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系;
所述发送单元,还用于从所述第一出接口向所述第一转发单元转发所述第一报文。
可选的,所述发送单元,还用于在所述匹配单元确定出对应的所述第一 出接口标识之后,向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
所述接收单元,还用于接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
更新单元,用于根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
可选的,所述发送单元,还用于若所述匹配单元根据所述出接口信息不能确定出第一出接口标识,向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
所述接收单元,还用于接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
所述更新单元,还用于根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息;
所述匹配单元,还用于根据所述第一报文的目的标识匹配到更新后的所述第一分担表项,根据所述出接口信息确定出所述第一出接口标识;
所述发送单元,还用于从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文。
可选的,所述第一分担表项还包括与所述第一报文对应的校验MAC地址,所述校验MAC地址为所述目的转发单元用于接收所述第一报文的网络接口的MAC地址,所述匹配单元,还用于根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述校验MAC地址;所述报文转发装置还包括:
判断单元,用于判断所述校验MAC地址和所述第一报文中携带的待校验MAC地址是否一致;若一致,触发第一处理单元;若不一致,触发第二处理单 元;
所述第一处理单元,用于将所述待校验MAC地址作为所述第一报文的目的MAC地址;
所述第二处理单元,用于将所述校验MAC地址作为所述第一报文的目的MAC地址,并将所述第一报文中携带的所述待校验MAC地址替换为所述校验MAC地址。
可选的,还包括:
所述接收单元还用于从网络侧接收第二报文,所述第二报文包括目的标识,所述第二报文的目的标识用于标识第二转发单元的网络接口,所述第二转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
所述匹配单元还用于根据所述第二报文的目的标识匹配到第二分担表项,确定出对应的所述第二转发单元标识和所述网络侧LB的出接口信息,所述第二分担表项由所述控制器建立并下发,所述第二分担表项包括所述第二转发单元网络接口的标识、第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系;
若根据所述第二出接口信息确定出第二出接口标识,所述发送单元还用于从所述第二出接口标识所标识的第二出接口向所述第二转发单元转发所述第二报文,所述第二出接口为所述网络侧LB上的一个出接口。
第三方面,本发明实施例提供了一种报文转发方法,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述方法包括:
所述控制器接收所述vBNG发送的上线成功消息,所述上线成功消息用于标识目标终端通过第一转发单元成功上线,所述第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
所述控制器根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果,所述vBNG的系统参数包括所述vBNG的至少一个转发单元 的接口信息和流量统计信息;
所述控制器根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系;
所述控制器向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。
可选的,还包括:
所述控制器根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息建立出接口表项,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和所述网络侧LB的第一出接口标识三者之间的对应关系。
可选的,还包括:
所述控制器向所述网络侧LB下发所述出接口表项,用于指示所述网络侧LB根据所述出接口表项转发报文。
可选的,还包括:
所述控制器获取所述网络侧LB发送的第一报文的分担参数,所述第一报文为从网络侧向用户侧发送的报文,所述第一报文的分担参数包括所述第一报文的目的标识和目的媒体访问控制MAC地址,所述第一报文的目的标识用于标识所述目标终端,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口;
所述控制器根据所述第一报文的分担参数和所述第一转发单元标识确定出可确定出所述第一出接口标识的出接口信息;
所述控制器向所述网络侧LB下发所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息。
可选的,还包括:
所述控制器根据所述转发网络的网络拓扑信息和所述vBNG的系统参数建立第二分担表项,所述第二分担表项包括第二转发单元网络接口的标识、所 述第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元;
所述控制器向所述网络侧LB下发所述第二分担表项,用于指示所述网络侧LB根据所述第二分担表项转发报文。
第四方面,本发明实施例提供了一种报文转发装置,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述装置包括:
接收单元,用于接收所述vBNG发送的上线成功消息,所述上线成功消息用于标识目标终端通过第一转发单元成功上线,所述第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
计算单元,用于根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果,所述vBNG的系统参数包括所述vBNG的至少一个转发单元的接口信息和流量统计信息;
建立单元,用于根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系;
发送单元,用于向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。
可选的,所述建立单元,还用于根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息建立出接口表项,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和所述网络侧LB的第一出接口标识三者之间的对应关系。
可选的,所述发送单元,还用于向所述网络侧LB下发所述出接口表项,用于指示所述网络侧LB根据所述出接口表项转发报文。
可选的,所述接收单元,还用于获取所述网络侧LB发送的第一报文的分担参数,所述第一报文为从网络侧向用户侧发送的报文,所述第一报文的分 担参数包括所述第一报文的目的标识和目的媒体访问控制MAC地址,所述第一报文的目的标识用于标识所述目标终端,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口;
确定单元,用于根据所述第一报文的分担参数和所述第一转发单元标识确定出可确定出所述第一出接口标识的出接口信息;
所述发送单元,还用于向所述网络侧LB下发所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息。
可选的,所述建立单元,还用于根据所述转发网络的网络拓扑信息和所述vBNG的系统参数建立第二分担表项,所述第二分担表项包括第二转发单元网络接口的标识、所述第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元;
所述发送单元,还用于向所述网络侧LB下发所述第二分担表项,用于指示所述网络侧LB根据所述第二分担表项转发报文。
第五方面,本发明实施例提供了一种报文转发系统,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述系统包括所述网络侧LB和所述控制器,所述网络侧LB配置有前述第二方面任意一种实施方式中的装置,所述控制器配置有前述第四方面任意一种实施方式中的装置。
由上述技术方案可以看出,在包括控制器、用户侧LB、vBNG和网络侧LB的转发网络中,所述网络侧LB在接收到从网络侧向用户侧的目标终端转发的第一报文时,通过所述第一报文的用于标识目标终端的目的标识匹配到第一分担表项,可以确定出预先规划好的所述网络侧LB的第一出接口到处理所述目标终端上线的第一转发单元的转发路径,从而可以准确的将发向所述目标终端的所述第一报文转发到处理所述目标终端上线的第一转发单元,避免了从网络侧向用户侧转发的报文可能被转发到所述vBNG中不适合的转发单元处,从而降低了vBNG出现需要将从网络侧接收的报文跨VM转发的情况,保 证了vBNG的转发性能。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。
图1为一种vBNG的应用场景示意图;
图2为本发明实施例提供的一种转发网络的网络结构示意图;
图3为本发明实施例提供的一种报文转发方法的方法流程图;
图4为本发明实施例提供的一种报文转发方法的方法流程图;
图5为本发明实施例提供的一种表项更新方法的方法流程图;
图6为本发明实施例提供的一种报文转发方法的方法流程图;
图7为本发明实施例提供的一种报文转发装置的装置结构图;
图8为本发明实施例提供的一种报文转发装置的装置结构图;
图9为本发明实施例提供的一种报文转发系统的系统结构图;
图10为本发明实施例提供的一种网络侧LB的硬件结构图;
图11为本发明实施例提供的一种控制器的硬件结构图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整的描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
基于NFV架构的vBNG是通过对传统宽带网络网关功能的虚拟化得到的虚拟设备。vBNG可以运行在通用服务器的硬件环境中,并实现传统BNG设备能够实现的相关功能。
常见的vBNG包括至少一个主控单元和至少两个转发单元,主控单元和 转发单元分别运行在不同的VM中。终端可以通过vBNG中的一个转发单元完成上线,从而该终端可以通过所述vBNG实现与网络侧的数据交互。但是,由网络侧路由器向用户侧转发报文所查询的路由转发表主要是基于路由协议得到,在转发报文的过程,不会考虑到转发路径中接收报文的转发单元是否是一个合适的转发单元,而只是关注在逻辑上是否能够实现。这里所述的是否合适可以理解为是否具有相应的功能(例如转发功能),若具有相应的功能,则可以认为是合适的。这里所述的是否合适也可以理解为是否具有处理报文所需的必要数据,若具有所需的数据,则可以认为是合适的。故在使用路由转发表向用户侧转发报文的过程中,可能会导致跨VM转发报文。
发明人发现,终端若希望通过vBNG的转发单元与网络进行数据交互,首先该终端需要通过vBNG中的一个转发单元完成上线。这个处理该终端上线的转发单元中将会保留与这个终端相关的数据和信息。之后,若这个转发单元的网络接口(用于接收从网络侧转发的报文的接口)接收到发向该终端的一个报文,这个转发单元可以利用该终端上线时提供的数据有效的将这个报文向该终端转发,基本上不会出现跨VM转发报文的情况。而若是vBNG中的其他转发单元通过网络接口接收到这个报文,很有可能会因为缺少必要信息导致其他转发单元无法实现向该终端转发这个报文。从而导致vBNG必须将这个报文从其他转发单元转移到这个处理该终端上线的转发单元,由这个转发单元继续完成对这个报文的转发。发明人认为,在从网络侧向用户侧转发报文的过程中,若未能将网络侧目的为终端的报文转发到处理该终端上线的转发单元,就很有可能导致vBNG中出现跨VM转发报文。例如,网络侧向用户侧的目标终端发送报文a时,路由器可能会根据路由转发表将报文a转发到vBNG的转发单元1,而vBNG中是由转发单元2对目标终端进行上线处理的,故转发单元1可能并不具备继续将报文a向用户侧转发的必要数据,或者转发单元1可能并不具备转发报文的功能。为了能够完成对报文a的转发,vBNG只能将报文a从转发单元1所处的VM中转移到处于另一个VM中的转发单元2,由转发单元2继续将报文a向目标终端转发。这里的转发单元1和转发单元2均属于所述vBNG,分属于不同的VM,由此造成了跨VM的报文转发。
故发明人认为,路由器将网络侧的报文转发到错误的或者说不合适的转发单元是造成出现vBNG中跨VM转发报文的主要原因。
针对NFV架构下的这种vBNG的跨VM转发报文问题,以及综合发明人发现造成这个问题的主要原因,发明人决定将负载分担的方式引入到网络侧向用户侧报文转发过程中。通过控制器预先计算网络侧到用户侧转发报文的负载分担结果,并将根据负载分担结果建立的分担表项下发到网络侧负载均衡器(英文:Load Balancer,缩写:LB),由网络侧LB将分担表项作为下行报文(这里所述的下行可以理解为站在用户侧角度上的定义,主要指从网络侧到用户侧的报文转发方向,相应的,上行可以理解为从用户侧到网络侧的报文转发方向)转发的转发依据,由此可以将下行报文准确的转发到vBNG中合适的转发单元。
为此,本发明实施例提供了一种报文转发方法、装置和系统,在包括控制器、用户侧LB、vBNG和网络侧LB的转发网络中,所述网络侧LB在接收到从网络侧向用户侧的目标终端转发的第一报文时,通过所述第一报文的用于标识目标终端的目的标识匹配到第一分担表项,可以确定出预先规划好的所述网络侧LB的第一出接口到处理所述目标终端上线的第一转发单元的转发路径,从而可以准确的将发向所述目标终端的所述第一报文转发到处理所述目标终端上线的第一转发单元,避免了从网络侧向用户侧转发的报文可能被转发到所述vBNG中不适合的转发单元处,从而降低了vBNG出现需要将从网络侧接收的报文跨VM转发的情况,保证了vBNG的转发性能。
需要注意的是,除了要保证从网络侧到用户侧的报文转发准确性,还需要保证从用户侧到网络侧的报文转发准确性。发明人发现,从用户侧向网络侧转发报文时,也可能出现vBNG中跨VM转发报文的问题。具体的,所述用户侧LB向vBNG转发用户侧的终端向网络侧发送的报文时,若未将该报文转发到该终端上线的转发单元,同样会造成vBNG的跨VM转发报文问题。例如,用户侧的目标终端向网络侧的网络设备发送报文b时,交换机可能会将报文b转发到vBNG的转发单元1,而vBNG中是由转发单元2对目标终端进行上线处理的,故转发单元1可能并不具备继续将报文b向用户侧转发的必要数据,或者转发单元1可能并不具备转发报文的功能。为了能够完成对报文b的转发,vBNG只能将报文b从转发单元1所处的VM中转移到处于另一个VM中的转发单元2,由转发单元2继续将报文b向网络设备转发。这里的转发单元1和转发单元2均属于所述vBNG,分属于不同的VM,由此造成了跨VM的报文转发。
故发明人认为,用户侧向网络侧转发报文过程出现的vBNG中跨VM转发报文现象,也主要是由将报文转发到错误的或者说不合适的转发单元造成的。
发明人通过将负载分担的方式引入到用户侧向网络侧报文转发过程中,通过控制器预先计算用户侧到网络侧转发报文的负载分担结果,并将根据负载分担结果建立的分担表项下发到用户侧LB,由用户侧LB将分担表项作为用户侧向网络侧转发报文的转发依据,由此可以将用户侧向网络侧转发的报文准确的转发到vBNG中合适的转发单元。避免了从用户侧向网络侧转发的报文可能被转发到所述vBNG中不适合的转发单元处,保证了vBNG的转发性能。
对于本发明实施例中的控制器来说,所述控制器可以是一个软件定义网络(英文:Software Defined Networking,缩写:SDN)控制器。在本发明实施例中,主要通过所述控制器实现对转发网络的负载分担的计算,其中,负载分担计算包括针对从网络侧到用户侧的流量,也包括从用户侧到网络侧的流量。所述控制器可以根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和针对目标终端的上线成功消息精确的计算针对目标终端的下行流量负载分担计算,并根据计算得到的第一分担结果建立第一分担表项,向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。可见,所述控制器可以计算针对一个终端从网络侧到用户侧的负载分担,预先规划好下行报文的转发路线,故根据计算结果建立的分担表项可以起到明确指示所述网络侧LB准确的将发向所述目标终端的报文转发到这个目标终端上线的转发单元的作用,从而完成准确的从网络侧LB到转发单元的报文转发。
本发明实施例中所述的终端可以是一种用户设备(英文:User Equipment,缩写:UE),也可以是个人计算机、平板电脑(英文:portable android device,缩写:Pad)、手机等。
接下来,将对本发明实施例中提到的所述转发网络进行描述。所述转发网络包括控制器、用户侧LB、vBNG和网络侧LB,其中,各部分之间的具体连接关系可以参见图2。需要注意的是,所述网络侧LB和用户侧LB可以为同一个网络实体,或者由同一个网络实体实现所述网络侧LB和用户侧LB的功能。所述网络侧LB和用户侧LB也可以是不同的网络实体,由不同网络 实体分别实现所述网络侧LB和用户侧LB各自的功能。这里所述的网络实体可以是LB,也可以是具有LB功能的交换机。或者,所述网络侧LB和用户侧LB还可以是在NFV架构下的功能虚拟化的virtual LB,vLB可以通过服务器运行相关的程序或软件实现。
用户侧LB具有与终端等本地设备连接的接口(英文:interface),用于接收终端向网络侧发送的报文,或者用于向终端发送网络侧转发来的报文。所述用户侧LB还具有与所述vBNG的转发单元相连的接口,用于将终端发送的报文向所述vBNG转发,所述用户侧LB还具有与所述控制器相连的接口,用于向所述控制器发送数据或者从所述控制器接收下发的表项。在本发明实施例中,所述用户侧LB与所述vBNG的转发单元相连的接口称为所述用户侧LB的出接口,所述用户侧LB具有多个出接口。
网络侧LB具有与网络设备(这里的网络设备特指如图2中所述网络侧LB右侧的设备,例如路由器等)连接的接口,用于接收网络侧向用户侧转发的报文,或者用于向网络侧发送用户侧转发来的报文。所述网络侧LB还具有与所述vBNG的转发单元相连的接口,用于将从网络侧接收的报文向所述vBNG转发,所述网络侧LB还具有与所述控制器相连的接口,用于向所述控制器发送数据或者从所述控制器接收下发的表项。在本发明实施例中,所述网络侧LB与所述vBNG的转发单元相连的接口称为所述网络侧LB的出接口,所述网络侧LB具有多个出接口。
所述vBNG具有一个主控单元和多个转发单元。一个转发单元运行在一个单独的VM中,所述vBNG所包括的转发单元的数量可以根据实际应用场景的需求确定,例如可以随着场景需求增加或减少转发单元的数量。所述vBNG的主控单元可以为虚拟主控单元(英文:virtual master process unit,缩写:vMPU),所述vBNG的转发单元可以是虚拟线路处理单元(英文:virtual line process unit,缩写:vLPU)。
所述vBNG主要通过主控单元与所述控制器传输数据,例如向所述控制器发送终端的上线成功消息或所述vBNG的系统参数。所述vBNG的转发单元主要具有用户接口和网络接口,其中转发单元的用户接口与所述用户侧LB相连,用于与所述用户侧LB之间进行报文转发。所述用户侧LB的出接口与所述vBNG的转发单元的用户接口之间具有对应关系。转发单元的网络接口与所述网络侧LB相连,用于与所述网络侧LB之间进行报文转发。
所述网络侧LB的出接口与所述vBNG的转发单元的网络接口之间具有对应关系。
通过前述所述控制器建立和下发表项,可以保证从所述用户侧LB可以将终端发送的报文准确的转发到该终端上线的转发单元,也可以保证所述网络侧LB可以将从网络侧向终端发送的报文准确的转发到该终端上线的转发单元。故为了避免所述vBNG中出现跨VM转发报文的可能,在vBNG中,将限定报文在同一个转发单元内转发。也就是说,当转发单元1通过用户接口接收报文a时,将使用转发单元1的网络接口转发报文a,当转发单元2通过网络接口接收报文b时,将使用转发单元2的用户接口转发报文b。vBNG可以通过设置内部的转发路由表实现限定报文在同一个转发单元内转发的功能。
前述的相连并不是限定为直接的物理连接关系,可以是间接的连接关系,也可以是非物理层面上的连接关系。
在本发明实施例中所述的用户侧和网络侧是以所述vBNG进行界定的,vBNG的用户侧指的是面向终端(包括终端接入到vBNG)一侧的物理实体(如转发单元的用户接口)或功能,主要完成用户的认证、IP地址分配、用户转发表项生成或删除等操作。vBNG的网络侧指面向网络(例如包括vBNG向城域网、骨干网转发数据的网络等)一侧的物理实体(如转发单元的网络接口)或功能,主要完成与网络中的其它设备的路由协议收敛、根据路由表进行IP报文转发操作等任务。
在描述本发明实施例的报文转发之前,先说明本发明实施例中所采用的各个转发表项是如何建立的。
所述网络侧LB和用户侧LB在报文转发中匹配的转发表项主要是由所述控制器建立并下发的。所述控制器主要会用到所述转发网络的网络拓扑信息和所述vBNG的系统参数作为建立表项的基础。
其中,所述转发网络的网络拓扑信息主要包括前述网络侧LB、用户侧LB和vBNG之间接口的对应关系。所述控制器可以通过拓扑发现过程获取所述转发网络的网络拓扑信息。拓扑发现过程通过链路层发现协议(英文:Link Layer Discovery Protocol,缩写:LLDP)实现。所述控制器通过获取所述网络侧LB和用户侧LB发送的携带有拓扑关系的LLDP来获知所述转发网络的网络拓扑信息。所述控制器可以周期性的启动拓扑发现过程。所述转发网络的 网络拓扑信息可以包括所述转发网络中各个设备(可以包括网络侧LB、用户侧LB、vBNG以及vBNG中的转发单元等)的标识,例如ID、媒体访问控制(英文:Media Access Control,缩写:MAC)地址等形式,如vBNG可分配00:00:00:00:00:01。各个设备的接口名称、接口标识等。以及接口之间的连接关系,例如网络侧LB的一个出接口与一个转发单元的网络接口之间的对应关系,或者说网络侧LB的一个出接口可以将报文转发到哪个转发单元的网络接口。
所述vBNG的系统参数包括所述vBNG的至少一个转发单元的接口信息和流量统计信息,所述控制器主要通过所述vBNG发送获取所述vBNG的系统参数。所述vBNG的至少一个转发单元的接口信息可以包括转发单元的网络接口和用户接口的标识,所述流量统计信息可以包括转发单元上用户接口和网络接口对应的流量统计信息等。所述vBNG的系统参数可以周期性上报所述控制器。
所述控制器在建立针对目标终端的转发表项之前还需要获取所述目标终端的上线成功消息,当所述目标终端在第一转发单元上成功上线时,所述上线成功消息由所述vBNG发送至所述控制器,所述第一转发单元为所述vBNG中多个转发单元中的一个转发单元。通过所述上线成功消息,所述控制器可以明确所述目标终端的标识以及所述目标终端与所述第一转发单元之间的对应关系。
这里所述的上线可以理解为访问网络,终端上线成功后可以访问网络,终端上线不成功将不能访问网络。常见的终端上线方式有以太网的点对点协议(英文:Point to Point Protocol over Ethernet,缩写:PPPoE)和动态主机配置协议(英文:Dynamic Host Configuration Protocol,缩写:DHCP)两种方式,分别对应PPPoE协议和DHCP协议。vBNG进行用户上线,主要是在上述协议的基础上,对用户进行认证(比如密码确认)、从地址池分配用户的IP地址(或向专门的服务器请求分配IP地址)、建议用户转发表项操作,其它还包含对用户进行流量统计,与策略服务器交互获取一些策略或上报流量统计结果等。这里最基本的就是上线成功就会生成用户转发表,允许用户后续报文通过,否则就没有用户转发表,用户不能访问网络。
所述控制器可以建立分担信息数据库用于统一存储和管理前述这些用于建立表项的所述转发网络的网络拓扑信息、所述vBNG的系统参数和终端的 上线成功消息,并在需要时从所述分担信息数据库中调取相应的信息。在所述分担信息数据库中可以进行分类存储,例如可以分为转发单元与网络侧LB和用户侧LB的拓扑信息,转发单元的硬件信息,转发单元的接口标识,转发单元的用户信息(这里主要指通过一个转发单元上线的终端统计信息),转发单元的负载信息(包括用户接口和网络接口的流量统计信息),转发单元的业务类型(在转发单元上线的终端的业务类型等)。
在获取所述目标终端的上线成功消息时,所述控制器可以根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果。所述第一分担结果可以理解计算得出的针对所述目标终端从所述网络侧LB向所述vBNG的下行转发路径。所述控制器根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系。所述第一分担表项的查找key可以是所述目标终端的标识(也就是所述第一报文的目的标识)。
在建立好所述第一分担表项后,所述控制器可以向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项向所述vBNG转发报文。
举例说明,通过负载分担计算,可以计算出所述网络侧LB和所述第一转发单元之间用于负担针对所述目标终端的下行报文转发路径。在所述网络侧LB接收到针对所述目标终端的下行报文时,由于所述控制器已经预先进行了针对所述目标终端的负载分担计算,预先规划好了针对所述目标终端的下行报文的转发路径,故所述网络侧LB可以通过匹配所述第一分担表项准确的确定出所述第一转发单元。这里所述的目标终端的标识可以是目标终端的IP地址。
可见,所述控制器可以计算针对一个终端从网络侧LB到vBNG的负载分担,预先规划好下行报文的转发路线,故根据计算结果建立的分担表项可以起到明确指示所述网络侧LB准确的将发向所述目标终端的报文转发到这个目标终端上线的转发单元的作用,从而实现准确的从网络侧LB到转发单元的报文转发。
需要注意的是,在有些情况下,通过所述第一分担表项中的所述网络侧LB的出接口信息(例如可以是特殊值0xff),并不能确定出所述网络侧LB中 具体的出接口标识。
发明人发现,在本发明实施例中所描述的这种具有多个转发单元的vBNG中,可以通过配置,将多个转发单元中具有相同处理功能(或者说处理相同数据类型)的转发单元的用户接口配置在一个虚拟用户接口组中,并将网络接口也配置爱一个虚拟网络接口组中。这些具有相同处理功能的转发单元的用户接口可以理解为这个虚拟用户接口组中的组成员,这些具有相同处理功能的转发单元的网络接口可以理解为这个虚拟网络接口组中的组成员。处于一个虚拟用户接口组的组成员除了具有上的接口标识以外,都会再被统一分配一个相同的虚拟MAC地址,在进行报文转发过程中,均使用这个虚拟MAC地址。同样,处于一个虚拟网络接口组的组成员除了具有上的接口标识以外,也都会再被统一分配一个相同的虚拟MAC地址,在进行报文转发过程中,均使用这个虚拟MAC地址。当所述vBNG中出现多个虚拟网络接口组时,例如vBNG的转发单元1的网络接口a被分在了虚拟网络接口组1,转发单元1的网络接口b被分在了虚拟网络接口组2的情况时,所述控制器在针对所述目标终端进行负载分担计算时,有可能会计算出经由两个下行转发路径。这两个下行转发路径会分别通过两个分别处于不同虚拟网络接口组的转发单元的网络接口实现,例如一条下行转发路径需要通过转发单元1的网络接口a,另一条下行转发路径需要通过转发单元1的网络接口b。这种情况下,虽然所述控制器能够明确每一条下行转发路径中所述网络侧LB的具体出接口,在所述网络侧LB未对下行转发路径进行选择前,所述控制器暂时没有必要在所述第一分担表项中为所述网络侧LB提供具体的出接口信息。其中,需要注意在这种情况下,前述所述控制器获取的所述转发网络的网络拓扑信息中还可以包括虚拟网络接口组和虚拟用户接口组分配的虚拟MAC地址。
为了解决这一问题,可选的,所述控制器在接收到所述目标终端的上线成功消息时,所述控制器除了可以建立所述第一分担表项,所述控制器还可以根据所述转发网络的网络拓扑信息所述vBNG的系统参数和所述上线成功消息建立出接口表项,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系。所述出接口表项的查找key是所述第一转发单元标识和第一转发单元网络接口的标识(也就是所述第一报文的目的MAC地址)。
在前述中,由于所述控制器通过负载分担计算确定出针对所述目标终端 的多条下行转发路径,每个下行转发路径对应一个转发单元的网络接口,所以所述控制器可以根据每一条下行转发路径建立一个出接口表项,也就是会有多个出接口表项。本发明实施例中所述的出接口表项可以理解为从多个出接口表项中,根据所述网络侧LB发送的所述第一报文的目的MAC地址确定的出接口表项。
在本发明实施例中,所述控制器在建立了所述出接口表项后可以有两种处理方式,第一种处理方式是将所述出接口表项保留在所述控制器,不下发给所述网络侧LB。第二种处理方式是将所述出接口表项下发给所述网络侧LB。接下来将分别介绍这两种处理方式。
针对所述第一种处理方式,由于所述网络侧LB没有所述出接口表项,故在所述网络侧LB在接收到第一报文后,若通过匹配所述第一分担表项无法确定出具体出接口,所述网络侧LB将会把所述第一报文的分担参数发送至所述控制器。
举例说明,所述第一报文为从网络侧向用户侧发送的报文,所述第一报文在达到所述网络侧LB时,携带有目的标识和目的MAC地址,所述目的标识用于指示所述第一报文的目的地,也就是所述目标终端的标识。所述目的MAC地址可以是指向下行报文转发路径中,从所述网络侧LB达到的下一个设备的地址标识,例如可以是所述第一转发单元的网络接口被统一分配的虚拟MAC地址。
在本发明实施例中,所述网络侧LB可以有两种发送方式向所述控制器发送所述第一报文的分担参数。第一种发送方式是只将所述第一报文的分担参数发给所述控制器,而在本地,也就是所述网络侧LB暂时保存所述第一报文。第二种发送方式是将包括分担参数的所述第一报文发送到所述控制器,在本地也就是所述网络侧LB不保存所述第一报文。
所述控制器可以根据所述第一报文的分担参数和所述第一转发单元标识匹配到保留的所述出接口表项,确定出可确定出所述第一出接口标识的出接口信息。这里所述的出可确定出所述第一出接口标识的出接口信息可以直接是所述第一出接口标识。
举例说明,当所述控制器获取所述第一报文的分担参数时,所述控制器可以根据所述第一报文的目的MAC地址(也就是所述第一转发单元网络接口的虚拟MAC地址),在所述转发网络的网络拓扑信息中确定出所述第一转发 单元的网络接口,进而确定出所述第一转发单元的网络接口所对应的所述网络侧LB的出接口(第一出接口)。
所述控制器向所述网络侧LB下发所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息。
举例说明,所述第一分担表项的更新信息可以仅是所述可确定出所述第一出接口标识的出接口信息,也可以是具有所述可确定出所述第一出接口标识的出接口信息的第一分担表项。
将所述第一分担表项的更新信息下发至所述网络侧LB后,所述网络侧LB可以根据所述可确定出所述第一出接口标识确定出所述第一出接口标识,从而完成对所述第一报文的转发。而且,所述网络侧LB还可以更新自身的所述第一分担表项,这样在之后接收到所述第一报文时,可以通过更新后的所述第一分担表项匹配出所述第一出接口标识,不再需要所述控制器协助就可以完成对所述第一报文的转发。
需要注意的是,若所述网络侧LB采取第一种发送方式发送所述第一报文的分担参数,也就是将所述第一报文保存在本地,所述控制器可以只下发所述第一分担表项的更新信息给所述网络侧LB。若所述网络侧LB采取第二种发送方式发送所述第一报文的分担参数,也就是在本地未保存所述第一报文,所述控制器可以将所述第一报文以及所述第一分担表项的更新信息下发至所述网络侧LB,再由所述网络侧LB转发所述第一报文。
针对所述第二种处理方式,所述控制器向所述网络侧LB下发所述出接口表项,用于指示所述网络侧LB根据所述出接口表项转发报文。由于所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,故所述第一报文的目的MAC地址与所述第一转发单元网络接口的标识相同,所述网络侧LB可以根据所述第一转发单元标识和所述第一报文的目的MAC地址匹配得到所述第一出接口标识,从而完成对所述第一报文的转发。
但是,转发一次报文匹配两次表项,会相对的消耗较多的系统资源。为了减少所述网络侧LB之后的匹配表项的次数,节约系统资源。所述网络侧LB在匹配所述出接口表项时,可以将所述第一报文的分担参数发送至所述控制器,由所述控制器根据所述第一报文的分担参数确定并向所述网络侧LB下发包括所述出可确定出所述第一出接口标识的出接口信息的所述第一分担表项的更新信息,所述网络侧LB通过所述第一分担表项的更新信息更新所述第 一分担表项后,若再接收到所述第一报文,所述网络侧LB可以只进行一次匹配,即只匹配所述第一分担表项就确定出所述第一出接口标识,节约了系统资源,提高了匹配效率。
在所述转发网络中,从网络侧接收的报文中,目的标识除了用于标识终端,还可以用于标识转发单元的网络接口。故为了能够指示所述网络侧LB实现针对目的标识用于标识转发单元的接口的报文的转发,所述控制器可以在获取所述转发网络的网络拓扑信息和所述vBNG的系统参数的情况下就可以建立相应的表项。
可选的,所述控制器根据所述转发网络的网络拓扑信息和所述vBNG的系统参数建立第二分担表项,所述第二分担表项包括第二转发单元网络接口的标识、所述第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元。
所述控制器向所述网络侧LB下发所述第二分担表项,用于指示所述网络侧LB根据所述第二分担表项转发报文。
举例说明,所述第二转发单元可以与所述第一转发单元为同一个转发单元,也可以为不同的转发单元。需要注意的是,当所述第二转发单元的网络接口是一个虚拟网络接口组的组成员时,所述第二分担表项中的所述第二转发单元的接口标识可以是这个虚拟网络接口组统一分配的虚拟MAC地址。当所述第二转发单元的网络接口不是虚拟网络接口组的组成员时,所述第二分担表项中的所述第二转发单元网络接口的标识可以是所述第二转发单元网络接口的真实接口标识,例如接口IP。
所述控制器还可以通过负载分担的计算方式,建立所述用户侧LB的分担表项。由于所述目标终端在上线前就需要所述用户侧LB将上线请求发送到所述vBNG,所以所述控制器可以在所述目标终端上线之前就完成对所述用户侧LB的转发表项的建立,针对所述用户侧LB建立的分担表项并不依赖所述目标终端的上线成功消息。下发到所述用户侧LB的分担表项可以包括目标终端的相关标识和所述网络侧LB出接口的对应关系。所述目标终端的相关标识可以包括MAC地址或所述目标终端所处虚拟局域网(英文:Virtual Local Area Network,缩写:VLAN)的标识。
说明完本发明实施例中所采用的各个表项是如何建立之后,接下来将通 过实施例说明在所述转发网络中的报文转发过程。本发明实施例中主要关注的是目标终端上线之后,针对所述目标终端的报文转发过程。
图3为本发明实施例提供的一种报文转发方法的方法流程图,所述方法包括:
301:所述网络侧LB从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端。
举例说明,一个报文的目的标识用于标识这个报文的转发目的地,在本发明实施例中,所述第一报文的目的标识可以理解为与所述目标终端的标识相同。
302:所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元。
在前述针对所述控制器的说明中,描述了所述控制器通过负载分担计算,根据分担结果,其中包括计算出的所述网络侧LB和所述第一转发单元之间用于负担针对所述目标终端的下行报文转发路径建立了所述第一分担表项。故所述网络侧LB在通过所述第一报文的目的标识匹配所述第一分担表项,确定出的所述网络侧LB的出接口信息可以是与所述第一转发单元的网络接口对应的出接口的相关信息,也就是下述的第一出接口的相关信息,例如第一出接口标识。
303:若所述网络侧LB根据所述出接口信息确定出第一出接口标识,所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
可见,在包括控制器、用户侧LB、vBNG和网络侧LB的转发网络中,所述网络侧LB在接收到从网络侧向用户侧的目标终端转发的第一报文时,通过所述第一报文的用于标识目标终端的目的标识匹配到第一分担表项,可以确定出预先规划好的所述网络侧LB的第一出接口到处理所述目标终端上线的第一转发单元的转发路径,从而可以准确的将发向所述目标终端的所述第 一报文转发到处理所述目标终端上线的第一转发单元,避免了从网络侧向用户侧转发的报文可能被转发到所述vBNG中不适合的转发单元处,从而降低了vBNG出现需要将从网络侧接收的报文跨VM转发的情况,保证了vBNG的转发性能。
需要注意的是,有些情况下,可能从所述出接口信息不能确定出第一出接口标识。出现不能确定出第一出接口标识的可能的情况已经在前述中说明,这里不再赘述。
若所述网络侧LB根据所述出接口信息不能确定出第一出接口标识,为了能够完成对所述第一报文的转发,本发明实施例提供了两种实现转发的方式,这两种实现转发的方式和前述的所述控制器在建立了所述出接口表项后的两种处理方式相对应。
第一种实现转发的方式与前述第二种处理方式相对应,即所述网络侧LB预先得到了所述控制器下发的所述出接口表项。
在图3所对应实施例的基础上,所述网络侧LB预先获取出接口表项,所述出接口表项和所述第一分担表项可以由所述控制器预先下发到所述网络侧LB。图4为本发明实施例提供的一种报文转发方法的方法流程图。
401:所述网络侧LB根据所述第一报文的目的MAC地址和所述第一转发单元标识匹配到所述出接口表项,确定出对应的所述第一出接口标识,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述出接口表项为由所述控制器建立,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系。
402:所述网络侧LB从所述第一出接口向所述第一转发单元转发所述第一报文。
举例说明,所述网络侧LB在匹配所述第一分担表项时,已经获得了所述第一转发单元标识,而所述第一报文的目的MAC地址在接收到所述第一报文时获得,且由于所述报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述报文的目的MAC地址与所述第一转发单元网络接口的标识相同,所以所述网络侧LB可以匹配到所述出接口表项,并直接得到所述第一出接口标识。
但是,转发一次报文匹配两次表项,会相对的消耗较多的系统资源。为了减少所述网络侧LB之后的匹配表项的次数,节约系统资源。可选的,所述 网络侧LB确定出对应的所述第一出接口标识之后,在图4所对应实施例的基础上,图5为本发明实施例提供的一种表项更新方法的方法流程图,所述方法包括:
501:所述网络侧LB向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址。
502:所述网络侧LB接收所述控制器发送的针对所述第一分担表项的更新信息。
503:所述网络侧LB根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
举例说明,所述控制器在根据接收到所述第一报文的分担参数,确定出所述第一出接口标识后,可以将所述第一出接口标识作为更新信息下发给所述网络侧LB。所述网络侧LB可以将所述第一出接口标识更新到所述第一分担表项中,例如可以将所述第一出接口标识直接作为所述网络侧LB的出接口信息。
可见,通过更新所述第一分担表项,当所述网络侧LB再次接收到目的标识为标识所述目标终端的报文时,只需一次匹配,就可以直接通过匹配所述第一分担表项确定出所述第一出接口标识,从而节约了匹配流程,节省了系统资源。
两种实现转发的方式中的第二种实现转发的方式与前述第一种处理方式相对应,即所述网络侧LB没有得到所述控制器下发的所述出接口表项。
在图3所对应实施例的基础上,若所述网络侧LB根据所述出接口信息不能确定出第一出接口标识,图6为本发明实施例提供的一种报文转发方法的方法流程图,
601:所述网络侧LB向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址。
举例说明,所述网络侧LB将所述第一报文的分担参数发送至所述控制器,由所述控制器协助确定出与所述第一转发单元的网络接口对应的所述网络侧LB的出接口。
602:所述网络侧LB接收所述控制器发送的针对所述第一分担表项的更新信息。
603:所述网络侧LB根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
604:所述网络侧LB根据所述第一报文的目的标识匹配到更新后的所述第一分担表项,根据所述出接口信息确定出所述第一出接口标识。
605:所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文。
举例说明,获取所述第一分担表项的更新信息后,所述网络侧LB可以根据所述可确定出所述第一出接口标识确定出所述第一出接口标识,从而完成对所述第一报文的转发。而且,所述网络侧LB还可以更新上的所述第一分担表项,这样在之后接收到所述第一报文时,可以通过更新后的所述第一分担表项匹配出所述第一出接口标识,不再需要所述控制器协助就可以完成对所述第一报文的转发,从而节约了匹配流程,节省了系统资源。
需要注意的是,在所述转发网络中,所述网络侧LB转发网络侧到用户侧的报文所匹配的是所述控制器下发的分担表项,也就是说,所述网络侧LB到vBNG的转发单元的转发路径是由所述控制器通过负载分担计算预先确定的。但是网络侧其他网络设备向用户侧转发的报文可能并不会遵循负载分担的方式。故有可能当所述第一报文转发到所述网络侧LB时,接下来转发到的设备(即转发单元)的标识(即目的MAC地址)并不是所述第一转发单元网络接口的标识,而是从逻辑上可以转发到所述目标终端的其他转发单元的网络接口的标识。而对于所述网络侧LB来说,所述第一报文所携带目的MAC地址并非正确的MAC地址,可能会造成不正确的转发指引,需要被修正。
为此,在图3所对应实施例的基础上,本发明实施例提供了一种校验并修正报文目的MAC地址的方法。可选的,所述第一分担表项还包括与所述第一报文对应的校验MAC地址,所述校验MAC地址用于标识所述目的转发单元用于接收所述第一报文的接口。
这里所述的校验MAC地址可以为所述第一转发单元用于接收所述第一报文的网络接口的MAC地址。相应的,所述网络侧LB在通过所述第一报文目的标识匹配所述第一分担表项时,还可以确定出对应的所述校验MAC地 址。
在所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文之前,所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,还包括:
所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述校验MAC地址。
所述网络侧LB判断所述校验MAC地址和所述第一报文中携带的待校验MAC地址是否一致。
若一致,将所述待校验MAC地址作为所述第一报文的目的MAC地址。
若不一致,将所述校验MAC地址作为所述第一报文的目的MAC地址,并将所述第一报文中携带的所述待校验MAC地址替换为所述校验MAC地址。
举例说明,所述第一报文的待校验MAC地址可以理解为尚未被校验的所述第一报文所携带的目的MAC地址。若所述第一报文的待校验MAC地址与所述校验MAC地址相同,则认为所述第一报文的携带的指向下一个转发到的设备的MAC地址正确,可以作为所述第一报文的目的MAC地址。若所述第一报文的待校验MAC地址与所述校验MAC地址不同,则认为所述第一报文的携带的指向下一个转发到的设备的MAC地址错误,将所述校验MAC地址替换所述待校验MAC地址,并将所述校验MAC地址作为所述第一报文的目的MAC地址。
通过上述的校验和修正,尽量避免会造成不正确的转发指引的出现,提高了所述第一报文转发的准确性。
在所述网络侧LB转发从网络侧接收的报文过程中,从网络侧接收的报文中除了发向用户侧终端的报文以外,还有些是目的标识为标识转发单元的接口的报文。为了能够实现对这类报文的转发,可选的,在图3所对应实施例的基础上,还包括:
所述网络侧LB从网络侧接收第二报文,所述第二报文包括目的标识,所述第二报文的目的标识用于标识第二转发单元的网络接口,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元。
所述网络侧LB根据所述第二报文的目的标识匹配到第二分担表项,确定出对应的所述第二转发单元标识和所述网络侧LB的出接口信息,所述第二分 担表项由所述控制器建立并下发,所述第二分担表项包括所述第二转发单元网络接口的标识、第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系。
若所述网络侧LB根据所述第二出接口信息确定出第二出接口标识,所述网络侧LB从所述第二出接口标识所标识的第二出接口向所述第二转发单元转发所述第二报文,所述第二出接口为所述网络侧LB上的一个出接口。
通过所述控制器可以在获取所述转发网络的网络拓扑信息和所述vBNG的系统参数的情况下就可以建立相应的表项,所述网络侧LB实现了针对目的标识用于标识转发单元的接口的报文的转发,提高了所述转发网络的适用性。
图7为本发明实施例提供的一种报文转发装置的装置结构图,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述报文转发装置700包括:
接收单元701,用于从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端;
匹配单元702,用于根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元;若所述匹配单元根据所述出接口信息确定出第一出接口标识,触发发送单元703;
所述发送单元703,用于从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
可选的,若所述匹配单元根据所述出接口信息不能确定出第一出接口标识,所述匹配单元,还用于根据所述第一报文的目的MAC地址和所述第一转发单元标识匹配到预先获取的出接口表项,确定出对应的所述第一出接口标识,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述出接口表项为由所述控制器建立,所述出接口表项包括所述第一转发单 元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系;
所述发送单元,还用于从所述第一出接口向所述第一转发单元转发所述第一报文。
可选的,所述发送单元,还用于在所述匹配单元确定出对应的所述第一出接口标识之后,向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
所述接收单元,还用于接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
更新单元,用于根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
可选的,所述发送单元,还用于若所述匹配单元根据所述出接口信息不能确定出第一出接口标识,向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
所述接收单元,还用于接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
所述更新单元,还用于根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息;
所述匹配单元,还用于根据所述第一报文的目的标识匹配到更新后的所述第一分担表项,根据所述出接口信息确定出所述第一出接口标识;
所述发送单元,还用于从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文。
可选的,所述第一分担表项还包括与所述第一报文对应的校验MAC地址,所述校验MAC地址为所述目的转发单元用于接收所述第一报文的网络接口的MAC地址,所述匹配单元,还用于根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述校验MAC地址;所述报文转发装置还包括:
判断单元,用于判断所述校验MAC地址和所述第一报文中携带的待校验MAC地址是否一致;若一致,触发第一处理单元;若不一致,触发第二处理单元;
所述第一处理单元,用于将所述待校验MAC地址作为所述第一报文的目的MAC地址;
所述第二处理单元,用于将所述校验MAC地址作为所述第一报文的目的MAC地址,并将所述第一报文中携带的所述待校验MAC地址替换为所述校验MAC地址。
可见,在包括控制器、用户侧LB、vBNG和网络侧LB的转发网络中,所述网络侧LB在接收到从网络侧向用户侧的目标终端转发的第一报文时,通过所述第一报文的用于标识目标终端的目的标识匹配到第一分担表项,可以确定出预先规划好的所述网络侧LB的第一出接口到处理所述目标终端上线的第一转发单元的转发路径,从而可以准确的将发向所述目标终端的所述第一报文转发到处理所述目标终端上线的第一转发单元,避免了从网络侧向用户侧转发的报文可能被转发到所述vBNG中不适合的转发单元处,从而降低了vBNG出现需要将从网络侧接收的报文跨VM转发的情况,保证了vBNG的转发性能。
图8为本发明实施例提供的一种报文转发装置的装置结构图,应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述报文转发装置800包括:
接收单元801,用于接收所述vBNG发送的上线成功消息,所述上线成功消息用于标识目标终端通过第一转发单元成功上线,所述第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
计算单元802,用于根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果,所述vBNG的系统参数包括所述vBNG的至少一个转发单元的接口信息和流量统计信息;
建立单元803,用于根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系;
发送单元804,用于向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。
可选的,所述建立单元,还用于根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息建立出接口表项,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和所述网络侧LB的第一出接口标识三者之间的对应关系。
可选的,所述发送单元,还用于向所述网络侧LB下发所述出接口表项,用于指示所述网络侧LB根据所述出接口表项转发报文。
可选的,所述接收单元,还用于获取所述网络侧LB发送的第一报文的分担参数,所述第一报文为从网络侧向用户侧发送的报文,所述第一报文的分担参数包括所述第一报文的目的标识和目的MAC地址,所述第一报文的目的标识用于标识所述目标终端,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口;
确定单元,用于根据所述第一报文的分担参数和所述第一转发单元标识确定出可确定出所述第一出接口标识的出接口信息;
所述发送单元,还用于向所述网络侧LB下发所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息。
可选的,所述建立单元,还用于根据所述转发网络的网络拓扑信息和所述vBNG的系统参数建立第二分担表项,所述第二分担表项包括第二转发单元网络接口的标识、所述第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元;
所述发送单元,还用于向所述网络侧LB下发所述第二分担表项,用于指示所述网络侧LB根据所述第二分担表项转发报文。
参见图9,图9为本发明实施例提供的一种报文转发系统的系统结构图。应用于包括vBNG的转发网络中,所述转发网络包括控制器、用户侧LB、所述vBNG和网络侧LB,所述报文转发系统900包括所述网络侧LB901和所述控制器902,所述网络侧LB901配置有前述图7所示的实施例中任一种实施方式的装置,所述控制器902配置有前述图8所对应实施例中任一种实施方式的装置。
需要说明的是,本实施例中所述网络侧LB901对应于前述图3、图4、图5和图6所示的实施例中提及的网络侧LB。本实施例中所述控制器902对应于前述实施例中提及的控制器,本实施例中网络侧LB901和控制器902的各种具体实施方式,可以参见前述所示的实施例的详细介绍,本实施例在此不再赘述。
参阅图10,图10为本发明实施例提供的一种网络侧LB的硬件结构图,所述网络侧LB1000应用于包括vBNG的转发网络中,所述转发网络还包括控制器、用户侧LB和所述vBNG,所述网络侧LB1000包括存储器1001、接收器1002和发送器1003,以及分别与所述存储器1001、所述接收器1002和所述发送器1003连接的处理器1004,所述存储器1001用于存储一组程序指令,所述处理器1004用于调用所述存储器1001存储的程序指令执行如下操作:
触发所述接收器1002从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端;
根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元;
若根据所述出接口信息确定出第一出接口标识,触发所述发送器1003从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
可选地,所述处理器1004可以为中央处理器(Central Processing Unit,CPU),所述存储器1001可以为随机存取存储器(Random Access Memory,RAM)类型的内部存储器,所述接收器1002和所述发送器1003可以包含普通物理接口,所述物理接口可以为以太(Ethernet)接口或异步传输模式(Asynchronous Transfer Mode,ATM)接口。所述处理器1004、发送器1003、接收器1002和存储器1001可以集成为一个或多个独立的电路或硬件,如:专用集成电路(Application Specific Integrated Circuit,ASIC)。
参阅图11,图11为本发明实施例提供的一种控制器的硬件结构示意图,所述控制器1100应用于包括vBNG的转发网络中,所述转发网络还包括用户侧LB、所述vBNG和网络侧LB,所述控制器1100包括存储器1101、接收器1102和发送器1103,以及分别与所述存储器1101、所述接收器1102和所述发送器1103连接的处理器1104,所述存储器1101用于存储一组程序指令,所述处理器1104用于调用所述存储器1101存储的程序指令执行如下操作:
触发所述接收器1102接收所述vBNG发送的上线成功消息,所述上线成功消息用于标识目标终端通过第一转发单元成功上线,所述第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果,所述vBNG的系统参数包括所述vBNG的至少一个转发单元的接口信息和流量统计信息;
根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系;
触发所述发送器1103向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。
可选地,所述处理器1104可以为CPU,所述存储器1101可以为RAM类型的内部存储器,所述接收器1102和所述发送器1103可以包含普通物理接口,所述物理接口可以为以太(Ethernet)接口或ATM接口。所述处理器1104、发送器1103、接收器1102和存储器1101可以集成为一个或多个独立的电路或硬件,如:ASIC。
本发明实施例中提到的第一报文、第一分担表项、第一转发单元和第一出接口的“第一”只是用来做名字标识,并不代表顺序上的第一。该规则同样适用于“第二”。
本领域普通技术人员可以理解:实现上述方法实施例的全部或部分步骤可以通过程序指令相关的硬件来完成,前述程序可以存储于一计算机可读取存储介质中,该程序在执行时,执行包括上述方法实施例的步骤;而前述的存储介质可以是下述介质中的至少一种:只读存储器(英文:read-only memory,缩写:ROM)、RAM、磁碟或者光盘等各种可以存储程序代码的介 质。
需要说明的是,本说明书中的各个实施例均采用递进的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于设备及系统实施例而言,由于其基本相似于方法实施例,所以描述得比较简单,相关之处参见方法实施例的部分说明即可。以上所描述的设备及系统实施例仅仅是示意性的,其中作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。本领域普通技术人员在不付出创造性劳动的情况下,即可以理解并实施。
以上所述,仅为本发明较佳的具体实施方式,但本发明的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内,可轻易想到的变化或替换,都应涵盖在本发明的保护范围之内。因此,本发明的保护范围应该以权利要求的保护范围为准。

Claims (21)

  1. 一种报文转发方法,其特征在于,应用于包括虚拟宽带网络网关vBNG的转发网络中,所述转发网络包括控制器、用户侧负载均衡器LB、所述vBNG和网络侧LB,所述方法包括:
    所述网络侧LB从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端;
    所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元;
    若所述网络侧LB根据所述出接口信息确定出第一出接口标识,所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
  2. 根据权利要求1所述的方法,其特征在于,还包括:
    若所述网络侧LB根据所述出接口信息不能确定出第一出接口标识,所述网络侧LB预先获取出接口表项;
    所述网络侧LB根据所述第一报文的目的媒体访问控制MAC地址和所述第一转发单元标识匹配到所述出接口表项,确定出对应的所述第一出接口标识,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述出接口表项为由所述控制器建立,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系;
    所述网络侧LB从所述第一出接口向所述第一转发单元转发所述第一报文。
  3. 根据权利要求2所述的方法,其特征在于,所述网络侧LB确定出对应的所述第一出接口标识之后,还包括:
    所述网络侧LB向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
    所述网络侧LB接收所述控制器发送的针对所述第一分担表项的更新信 息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
    所述网络侧LB根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
  4. 根据权利要求1所述的方法,其特征在于,若所述网络侧LB根据所述出接口信息不能确定出第一出接口标识,还包括:
    所述网络侧LB向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
    所述网络侧LB接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
    所述网络侧LB根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息;
    所述网络侧LB根据所述第一报文的目的标识匹配到更新后的所述第一分担表项,根据所述出接口信息确定出所述第一出接口标识;
    所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文。
  5. 根据权利要求1至4任一项所述的方法,其特征在于,所述第一分担表项还包括与所述第一报文对应的校验MAC地址,所述校验MAC地址为所述目的转发单元用于接收所述第一报文的网络接口的MAC地址,在所述网络侧LB从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文之前,所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,还包括:所述网络侧LB根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述校验MAC地址;所述方法还包括:
    所述网络侧LB判断所述校验MAC地址和所述第一报文中携带的待校验MAC地址是否一致;
    若一致,将所述待校验MAC地址作为所述第一报文的目的MAC地址;
    若不一致,将所述校验MAC地址作为所述第一报文的目的MAC地址,并将所述第一报文中携带的所述待校验MAC地址替换为所述校验MAC地址。
  6. 一种报文转发装置,其特征在于,应用于包括虚拟宽带网络网关vBNG 的转发网络中,所述转发网络包括控制器、用户侧负载均衡器LB、所述vBNG和网络侧LB,所述装置包括:
    接收单元,用于从网络侧接收第一报文,所述第一报文包括目的标识,所述第一报文的目的标识用于标识目标终端;
    匹配单元,用于根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述第一转发单元标识和所述网络侧LB的出接口信息,所述第一分担表项由所述控制器建立并下发,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系,所述第一转发单元标识对应的第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元,所述第一转发单元为将所述目标终端上线的转发单元;若所述匹配单元根据所述出接口信息确定出第一出接口标识,触发发送单元;
    所述发送单元,用于从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文,所述第一出接口为所述网络侧LB上的一个出接口。
  7. 根据权利要求6所述的装置,其特征在于,
    若所述匹配单元根据所述出接口信息不能确定出第一出接口标识,所述匹配单元,还用于根据所述第一报文的目的媒体访问控制MAC地址和所述第一转发单元标识匹配到预先获取的出接口表项,确定出对应的所述第一出接口标识,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口,所述出接口表项为由所述控制器建立,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和第一出接口标识三者之间的对应关系;
    所述发送单元,还用于从所述第一出接口向所述第一转发单元转发所述第一报文。
  8. 根据权利要求7所述的装置,其特征在于,
    所述发送单元,还用于在所述匹配单元确定出对应的所述第一出接口标识之后,向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
    所述接收单元,还用于接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口 信息;
    更新单元,用于根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息。
  9. 根据权利要求6所述的装置,其特征在于,
    所述发送单元,还用于若所述匹配单元根据所述出接口信息不能确定出第一出接口标识,向所述控制器发送针对所述第一报文的分担参数,所述分担参数包括所述第一报文的目的标识和所述第一报文的目的MAC地址;
    所述接收单元,还用于接收所述控制器发送的针对所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息;
    所述更新单元,还用于根据所述第一分担表项的更新信息更新所述第一分担表项,更新后的所述第一分担表项中包括可确定出所述第一出接口标识的出接口信息;
    所述匹配单元,还用于根据所述第一报文的目的标识匹配到更新后的所述第一分担表项,根据所述出接口信息确定出所述第一出接口标识;
    所述发送单元,还用于从所述第一出接口标识所标识的第一出接口向所述第一转发单元转发所述第一报文。
  10. 根据权利要求6至9任一项所述的装置,其特征在于,所述第一分担表项还包括与所述第一报文对应的校验MAC地址,所述校验MAC地址为所述目的转发单元用于接收所述第一报文的网络接口的MAC地址,所述匹配单元,还用于根据所述第一报文的目的标识匹配到第一分担表项,确定出对应的所述校验MAC地址;所述报文转发装置还包括:
    判断单元,用于判断所述校验MAC地址和所述第一报文中携带的待校验MAC地址是否一致;若一致,触发第一处理单元;若不一致,触发第二处理单元;
    所述第一处理单元,用于将所述待校验MAC地址作为所述第一报文的目的MAC地址;
    所述第二处理单元,用于将所述校验MAC地址作为所述第一报文的目的MAC地址,并将所述第一报文中携带的所述待校验MAC地址替换为所述校验MAC地址。
  11. 一种报文转发方法,其特征在于,应用于包括虚拟宽带网络网关vBNG的转发网络中,所述转发网络包括控制器、用户侧负载均衡器LB、所述vBNG和网络侧LB,所述方法包括:
    所述控制器接收所述vBNG发送的上线成功消息,所述上线成功消息用于标识目标终端通过第一转发单元成功上线,所述第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
    所述控制器根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果,所述vBNG的系统参数包括所述vBNG的至少一个转发单元的接口信息和流量统计信息;
    所述控制器根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系;
    所述控制器向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。
  12. 根据权利要求11所述的方法,其特征在于,还包括:
    所述控制器根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息建立出接口表项,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和所述网络侧LB的第一出接口标识三者之间的对应关系。
  13. 根据权利要求12所述的方法,其特征在于,还包括:
    所述控制器向所述网络侧LB下发所述出接口表项,用于指示所述网络侧LB根据所述出接口表项转发报文。
  14. 根据权利要求12或13所述的方法,其特征在于,还包括:
    所述控制器获取所述网络侧LB发送的第一报文的分担参数,所述第一报文为从网络侧向用户侧发送的报文,所述第一报文的分担参数包括所述第一报文的目的标识和目的媒体访问控制MAC地址,所述第一报文的目的标识用于标识所述目标终端,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口;
    所述控制器根据所述第一报文的分担参数和所述第一转发单元标识确定出可确定出所述第一出接口标识的出接口信息;
    所述控制器向所述网络侧LB下发所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息。
  15. 根据权利要求11所述的方法,其特征在于,还包括:
    所述控制器根据所述转发网络的网络拓扑信息和所述vBNG的系统参数建立第二分担表项,所述第二分担表项包括第二转发单元网络接口的标识、所述第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元;
    所述控制器向所述网络侧LB下发所述第二分担表项,用于指示所述网络侧LB根据所述第二分担表项转发报文。
  16. 一种报文转发装置,其特征在于,应用于包括虚拟宽带网络网关vBNG的转发网络中,所述转发网络包括控制器、用户侧负载均衡器LB、所述vBNG和网络侧LB,所述装置包括:
    接收单元,用于接收所述vBNG发送的上线成功消息,所述上线成功消息用于标识目标终端通过第一转发单元成功上线,所述第一转发单元为所述vBNG中至少两个转发单元中的一个转发单元;
    计算单元,用于根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息对所述目标终端进行网络侧到用户侧的负载分担计算,得到第一分担结果,所述vBNG的系统参数包括所述vBNG的至少一个转发单元的接口信息和流量统计信息;
    建立单元,用于根据所述第一分担结果建立第一分担表项,所述第一分担表项包括所述目标终端的标识、第一转发单元标识和所述网络侧LB的出接口信息三者之间的对应关系;
    发送单元,用于向所述网络侧LB下发所述第一分担表项,用于指示所述网络侧LB根据所述第一分担表项转发报文。
  17. 根据权利要求16所述的装置,其特征在于,
    所述建立单元,还用于根据所述转发网络的网络拓扑信息、所述vBNG的系统参数和所述上线成功消息建立出接口表项,所述出接口表项包括所述第一转发单元网络接口的标识、所述第一转发单元标识和所述网络侧LB的第一出接口标识三者之间的对应关系。
  18. 根据权利要求17所述的装置,其特征在于,
    所述发送单元,还用于向所述网络侧LB下发所述出接口表项,用于指示 所述网络侧LB根据所述出接口表项转发报文。
  19. 根据权利要求17或18所述的装置,其特征在于,
    所述接收单元,还用于获取所述网络侧LB发送的第一报文的分担参数,所述第一报文为从网络侧向用户侧发送的报文,所述第一报文的分担参数包括所述第一报文的目的标识和目的媒体访问控制MAC地址,所述第一报文的目的标识用于标识所述目标终端,所述第一报文的目的MAC地址用于标识所述第一转发单元的网络接口;
    确定单元,用于根据所述第一报文的分担参数和所述第一转发单元标识确定出可确定出所述第一出接口标识的出接口信息;
    所述发送单元,还用于向所述网络侧LB下发所述第一分担表项的更新信息,所述更新信息中包括所述可确定出所述第一出接口标识的出接口信息。
  20. 根据权利要求16所述的装置,其特征在于,
    所述建立单元,还用于根据所述转发网络的网络拓扑信息和所述vBNG的系统参数建立第二分担表项,所述第二分担表项包括第二转发单元网络接口的标识、所述第二转发单元标识和所述网络侧LB的第二出接口信息三者之间的对应关系,所述第二转发单元为所述vBNG中多个转发单元中的一个转发单元;
    所述发送单元,还用于向所述网络侧LB下发所述第二分担表项,用于指示所述网络侧LB根据所述第二分担表项转发报文。
  21. 一种报文转发系统,其特征在于,应用于包括虚拟宽带网络网关vBNG的转发网络中,所述转发网络包括控制器、用户侧负载均衡器LB、所述vBNG和网络侧LB,所述系统包括所述网络侧LB和控制器,所述网络侧LB配置有权利要求6至10任一项所述的这种,所述控制器配置有权利要求16至20任一项所述的装置。
PCT/CN2016/112144 2015-12-31 2016-12-26 一种报文转发方法、装置和系统 WO2017114362A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201511030539.2A CN105634956B (zh) 2015-12-31 2015-12-31 一种报文转发方法、装置和系统
CN201511030539.2 2015-12-31

Publications (1)

Publication Number Publication Date
WO2017114362A1 true WO2017114362A1 (zh) 2017-07-06

Family

ID=56049475

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/112144 WO2017114362A1 (zh) 2015-12-31 2016-12-26 一种报文转发方法、装置和系统

Country Status (2)

Country Link
CN (1) CN105634956B (zh)
WO (1) WO2017114362A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107517151A (zh) * 2017-09-30 2017-12-26 中国联合网络通信集团有限公司 用户接入方法、CPE、OLT、交换机、vBNG、SDN控制器和城域网
CN112003782A (zh) * 2020-09-02 2020-11-27 新华三信息安全技术有限公司 一种故障处理方法、装置、网络设备及机器可读存储介质
CN112751763A (zh) * 2019-10-30 2021-05-04 北京华为数字技术有限公司 一种报文转发方法、设备、存储介质及系统
EP4095691A4 (en) * 2020-02-29 2023-07-12 Huawei Technologies Co., Ltd. PROCEDURE FOR ERASING USER EQUIPMENT AND ASSOCIATED DEVICE

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105634956B (zh) * 2015-12-31 2018-11-16 华为技术有限公司 一种报文转发方法、装置和系统
CN107770067B (zh) * 2016-08-23 2021-05-11 中兴通讯股份有限公司 消息发送方法和装置
CN106487788B (zh) * 2016-09-30 2019-10-29 中国联合网络通信集团有限公司 一种用户接入方法、sdn控制器、转发设备及用户接入系统
CN110226307B (zh) * 2017-01-26 2021-01-29 华为技术有限公司 路由发布的方法和装置
CN109309627B (zh) * 2017-07-27 2022-05-20 中兴通讯股份有限公司 负荷分担方法、系统及计算机可读存储介质
US10560331B2 (en) 2018-02-07 2020-02-11 Juniper Networks, Inc. Self-driven and adaptable multi-vBNG management orchestration
CN110891028B (zh) * 2018-09-07 2021-12-21 华为技术有限公司 确定负载均衡策略的方法、装置及存储介质
CN113254165B (zh) * 2021-07-09 2021-10-08 易纳购科技(北京)有限公司 虚拟机和容器的负载流量分配方法、装置及计算机设备
CN114513458B (zh) * 2022-01-27 2023-12-08 新华三技术有限公司 通信方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104394083A (zh) * 2014-09-22 2015-03-04 华为技术有限公司 转发表项处理的方法、报文转发的方法及其装置和系统
CN104579732A (zh) * 2013-10-21 2015-04-29 华为技术有限公司 虚拟化网络功能网元的管理方法、装置和系统
US20150310043A1 (en) * 2013-04-24 2015-10-29 Charles Nathan Adelman Nested Media Container, Panel and Organizer
CN105634956A (zh) * 2015-12-31 2016-06-01 华为技术有限公司 一种报文转发方法、装置和系统

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104954218B (zh) * 2014-03-24 2018-02-09 新华三技术有限公司 分布式虚拟交换装置及转发方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150310043A1 (en) * 2013-04-24 2015-10-29 Charles Nathan Adelman Nested Media Container, Panel and Organizer
CN104579732A (zh) * 2013-10-21 2015-04-29 华为技术有限公司 虚拟化网络功能网元的管理方法、装置和系统
CN104394083A (zh) * 2014-09-22 2015-03-04 华为技术有限公司 转发表项处理的方法、报文转发的方法及其装置和系统
CN105634956A (zh) * 2015-12-31 2016-06-01 华为技术有限公司 一种报文转发方法、装置和系统

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107517151A (zh) * 2017-09-30 2017-12-26 中国联合网络通信集团有限公司 用户接入方法、CPE、OLT、交换机、vBNG、SDN控制器和城域网
CN112751763A (zh) * 2019-10-30 2021-05-04 北京华为数字技术有限公司 一种报文转发方法、设备、存储介质及系统
EP4095691A4 (en) * 2020-02-29 2023-07-12 Huawei Technologies Co., Ltd. PROCEDURE FOR ERASING USER EQUIPMENT AND ASSOCIATED DEVICE
US11856069B2 (en) 2020-02-29 2023-12-26 Huawei Technologies Co., Ltd. Method for deleting user equipment and related device
CN112003782A (zh) * 2020-09-02 2020-11-27 新华三信息安全技术有限公司 一种故障处理方法、装置、网络设备及机器可读存储介质
CN112003782B (zh) * 2020-09-02 2022-05-24 新华三信息安全技术有限公司 一种故障处理方法、装置、网络设备及机器可读存储介质

Also Published As

Publication number Publication date
CN105634956B (zh) 2018-11-16
CN105634956A (zh) 2016-06-01

Similar Documents

Publication Publication Date Title
WO2017114362A1 (zh) 一种报文转发方法、装置和系统
US9846591B2 (en) Method, device and system for migrating configuration information during live migration of virtual machine
US8875233B2 (en) Isolation VLAN for layer two access networks
EP3404878B1 (en) Virtual network apparatus, and related method
JP4919608B2 (ja) パケット転送装置
JP5398410B2 (ja) ネットワークシステム,パケット転送装置,パケット転送方法及びコンピュータプログラム
US9258266B2 (en) Host detection by top of rack switch devices in data center environments
EP3310025B1 (en) User migration
US10033736B2 (en) Methods, systems, and computer readable media for remote authentication dial-in user service (radius) topology hiding
US9084108B2 (en) Method, apparatus, and system for mobile virtual private network communication
US20150071289A1 (en) System and method for address resolution
WO2015117337A1 (zh) 网络规则条目的设置方法及装置
JP5987122B2 (ja) デバイス固有のトラフィックフローステアリングのためのネットワークアドレス変換されたデバイスの特定
US8719918B2 (en) Method and device for distributed security control in communication network system
TWI450535B (zh) 存取系統及其中之方法
JP3813571B2 (ja) 境界ルータ装置、通信システム、ルーティング方法、及びルーティングプログラム
US9756148B2 (en) Dynamic host configuration protocol release on behalf of a user
US10129207B1 (en) Network address translation within network device having multiple service units
US11265244B2 (en) Data transmission method, PNF SDN controller, VNF SDN controller, and data transmission system
US20130089092A1 (en) Method for preventing address conflict, and access node
JP2008066907A (ja) パケット通信装置
US9438475B1 (en) Supporting relay functionality with a distributed layer 3 gateway
JP2010187314A (ja) 認証機能付きネットワーク中継機器及びそれを用いた端末の認証方法
US11627130B2 (en) Systems and methods for changing a supplicant from one virtual local area network to another using a change of authorization message
US20220321565A1 (en) Forwarding method and device, and broadband remote access server forwarding plane

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16881151

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16881151

Country of ref document: EP

Kind code of ref document: A1