WO2018054156A1 - 一种vxlan报文的转发方法、设备及系统 - Google Patents

一种vxlan报文的转发方法、设备及系统 Download PDF

Info

Publication number
WO2018054156A1
WO2018054156A1 PCT/CN2017/093887 CN2017093887W WO2018054156A1 WO 2018054156 A1 WO2018054156 A1 WO 2018054156A1 CN 2017093887 W CN2017093887 W CN 2017093887W WO 2018054156 A1 WO2018054156 A1 WO 2018054156A1
Authority
WO
WIPO (PCT)
Prior art keywords
vtep device
tunnel
vxlan
state
vxlan tunnel
Prior art date
Application number
PCT/CN2017/093887
Other languages
English (en)
French (fr)
Inventor
高远
李文辉
丁申宇
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP17852226.4A priority Critical patent/EP3451593B1/en
Publication of WO2018054156A1 publication Critical patent/WO2018054156A1/zh
Priority to US16/358,191 priority patent/US10917262B2/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • H04L12/4675Dynamic sharing of VLAN information amongst network nodes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/22Alternate routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/28Routing or path finding of packets in data switching networks using route fault recovery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/302Route determination based on requested QoS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/33Flow control; Congestion control using forward notification
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/10Mapping addresses of different types
    • H04L61/103Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • H04L47/125Avoiding congestion; Recovering from congestion by balancing the load, e.g. traffic engineering

Definitions

  • the present application relates to the field of communications technologies, and in particular, to a Virtual eXtensible Local Area Network (VxLAN) technology.
  • VxLAN Virtual eXtensible Local Area Network
  • VXLAN is a technology for encapsulating Layer 2 packets with a Layer 3 protocol.
  • VXLAN technology involves messages in the MAC-in-UDP format. Specifically, the Ethernet frame based on the Media Access Control (MAC) protocol is encapsulated in a User Datagram Protocol (UDP) message. Further, the UDP packet is encapsulated in an Internet Protocol (IP) packet, and the IP packet can be transmitted in the Layer 3 network. Therefore, Ethernet frames are transmitted in a three-layer network.
  • the VXLAN technology uses the VXLAN Network Identifier (VNI) to identify the VXLAN network segment. Different VXLAN segments correspond to different VNIs. Different VXLAN segments are isolated. Two virtual machines (VMs) in the same VNI can communicate directly.
  • VNI VXLAN Network Identifier
  • VXLAN L3Gateway Two VM communications located in different VNIs respectively need to pass through a VXLAN Layer 3 gateway.
  • the VNI field contains 24 bits.
  • An administrative domain can contain up to 216 VXLAN segments.
  • a VXLAN Tunnel End Point (VTEP) device is an edge device in VXLAN.
  • the VTEP device transmits VXLAN traffic through the VXLAN tunnel.
  • a VXLAN tunnel is a point-to-point logical tunnel between two VTEP devices.
  • the VXLAN network can adopt a multi-active gateway.
  • VTEP devices communicate with two VXLAN Layer 3 gateway devices through a VXLAN tunnel.
  • the two VXLAN Layer 3 gateway devices form a load balancing group to forward traffic received from the VTEP device to the IP network (for example, Layer 3 Virtual Private Network (L3VPN)).
  • the gateway interfaces that the two VXLAN Layer 3 gateways communicate with the VTEP device are configured with the same IP address and MAC address, and the two VXLAN Layer 3 gateways are configured with the same virtual VTEP IP address.
  • the VTEP device forms a Layer 3 gateway to the VXLAN.
  • ECMP Equal and Weighted Cost Multi-path
  • the multi-active gateway cannot provide a complete redundancy protection mechanism, and because of the load balancing mode, the requirements for synchronization and delay are high.
  • the embodiment of the present application provides a method, a device, and a system for forwarding a VXLAN packet, so as to improve the redundancy protection capability of the VXLAN network and reduce the requirements for synchronization and delay.
  • a method for forwarding a VXLAN packet includes: a first VTEP setting The tunnel state of the first VXLAN tunnel is set to be an active state according to the priority of the first VXLAN tunnel, and the first VXLAN tunnel is a VXLAN tunnel between the first VTEP device and the second VTEP device. And the first VTEP device sets the tunnel state of the second VXLAN tunnel to an inactive Inactive state according to the priority of the second VXLAN tunnel, where the second VXLAN tunnel is the first VTEP device and the third VTEP device.
  • the priority of the first VXLAN tunnel is higher than the priority of the second VXLAN tunnel, and the IP address of the second VTEP device is different from the IP address of the third VTEP device.
  • the first VTEP device advertises, by the first VXLAN tunnel, the first VTEP device with first state information carrying an Active state, where the first state information is used to indicate a tunnel of the first VXLAN tunnel status.
  • the first VTEP device advertises the second VTEP device with the second state information carrying the Inactive state, where the second VTEP device is used to indicate the tunnel of the second VXLAN tunnel. status.
  • the first VTEP device forwards the VXLAN message via the first VXLAN tunnel whose tunnel state is an active state.
  • the first VTEP device negotiates the tunnel state with the second VTEP device and the third VTEP device that are the VXLAN gateways, so that the VXLAN tunnel in the active state is in the working state, and the forwarding of the traffic is performed, in the Inactive state.
  • the VXLAN tunnel is in a non-working state and does not forward traffic.
  • the solution provided by the embodiment is used to improve the redundancy protection capability of the VXLAN network.
  • the method further includes: the first VTEP device via the first VXLAN The tunnel receives the first response information of the first state information from the second VTEP device, where the first response information is used to indicate that the second VTEP device confirms the tunnel status of the first VXLAN tunnel as Active. a state, the first VTEP device receiving, by the second VXLAN tunnel, second response information of the second state information from the third VTEP device, the second response information being used to indicate the third VTEP The device confirms the tunnel status of the second VXLAN tunnel as an Inactive state.
  • the method further includes: when the first VTEP device determines the first When the VXLAN tunnel is faulty, the first VTEP device sets the tunnel state of the first VXLAN tunnel to an Inactive state, and the first VTEP device sets the tunnel state of the second VXLAN tunnel to an Active state; Transmitting, by the VTEP device, the third VTEP device to the third VTEP device, the third state information carrying the active state, where the third state information is used to indicate the tunnel state of the second VXLAN tunnel; Receiving, by the VTEP device, third acknowledgement information of the third state information from the third VTEP device via the second VXLAN tunnel, the third response information being used to indicate that the third VTEP device is to be the third The tunnel state of the two VXLAN tunnels is updated to an Active state; the first VTEP device forwards the VXLAN message via the second VXLAN tunnel whose tunnel
  • the method further includes: the first VTEP device via the first VXLAN The tunnel receives a link failure message from the second VTEP device, where the link failure message is used Determining that there is a fault in the link between the second VTEP device and the IP network, the IP network is configured to send traffic to the host connected to the first VTEP device and to receive a connection from the first VTEP device The traffic of the host; the first VTEP device sets the tunnel state of the first VXLAN tunnel to an Inactive state, and the first VTEP device sets the tunnel state of the second VXLAN tunnel to an Active state; Transmitting, by the VTEP device, the third VTEP device to the third VTEP device, the third state information carrying the active state, where the third state information is used to indicate the tunnel state of the second VXLAN tunnel; Receiving, by the VTEP device, third acknowledgement information of the third state
  • the first VTEP device receives an address resolution protocol (ARP) request message from the host, where the ARP request message is used to request a media access control MAC address of the VXLAN gateway; Sending, by the VTEP device, the ARP request message to the second VTEP device and the third VTEP device via the first VXLAN tunnel and the second VXLAN tunnel, respectively, so that the second VTEP device and the The third VTEP device generates an ARP entry according to the ARP request packet.
  • ARP address resolution protocol
  • the ARP entry of the VXLAN Layer 3 gateway is synchronized with the MAC address entry.
  • the VXLAN Layer 3 gateway does not need to establish an entry backup link between the Layer 3 gateways.
  • the first VTEP device generates the ARP entry according to the ARP request packet; the first VTEP device stores the ARP entry; when the first VTEP device determines that the faulty VXLAN tunnel is faulty The ARP request message is generated according to the stored ARP entry, and the ARP request message is sent to the destination VTEP device via the fault recovery VXLAN tunnel; or when the first VTEP device determines When there is a newly established VXLAN tunnel, the ARP request packet is generated according to the stored ARP entry, and the ARP request packet is sent to the destination VTEP device via the newly established VXLAN tunnel.
  • the ARP packet is not required to be re-interacted when the fault is rectified or a VXLAN tunnel is created.
  • a second aspect provides a method for forwarding a VXLAN message, the method comprising: receiving, by a second VTEP device, first state information from a first VTEP device by using a first VXLAN tunnel, the first state information being used to indicate The tunnel state of the first VXLAN tunnel.
  • the tunnel state carried by the first state information is an active state
  • the second VTEP device confirms the first VXLAN tunnel as an active state, and sets a route priority of the IP network to the second VTEP device.
  • the IP network is configured to send traffic to a host connected to the first VTEP device and to receive traffic from the host connected to the first VTEP device, where the first priority is greater than a second priority, where the second priority is a route priority of the IP network to the second VTEP device when the first VXLAN tunnel is in an inactive state. Then, the second VTEP device forwards the VXLAN message via the first VXLAN tunnel whose tunnel state is an active state.
  • the redundancy protection capability of the VXLAN network is improved, and the direction of the upstream traffic and the downstream traffic are consistent.
  • the second VTEP device sends the first VTEP device to the first VTEP device. Transmitting the first response information of the first state information, where the first response information is used to indicate a tunnel state of the first VXLAN tunnel confirmed by the second VTEP device.
  • the second VTEP device when the second VTEP device determines that the first VXLAN tunnel whose tunnel state is the active state is faulty, the second VTEP device switches the tunnel state of the first VXLAN tunnel to an Inactive state. And switching the routing priority of the IP network to the second VTEP device to the second priority.
  • the second VTEP device determines that the link between the second VTEP device and the IP network is faulty, generating a link failure message, where the link failure message is used to indicate the The link between the VTEP device and the IP network is faulty; the second VTEP device sends the link failure message to the first VTEP device via the first VXLAN tunnel whose tunnel state is activated in an active state.
  • the second VTEP device receives second state information from the first VTEP device via the first VXLAN tunnel, and the second state information carries an Inactive state, used to indicate a tunnel state of the first VXLAN tunnel.
  • the second VTEP device switches the tunnel state of the first VXLAN tunnel to an Inactive state according to the second state information, and switches a route priority of the IP network to the second VTEP device to a second state. priority.
  • a first VTEP device having a function of implementing the behavior of the first VTEP device in the above method.
  • the functions may be implemented based on hardware, or may be implemented based on hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the first VTEP device includes a processor and an interface configured to support the first VTEP device to perform the corresponding functions of the above methods.
  • the interface is configured to support communication between the first VTEP device and the second VTEP device, send information or instructions involved in the foregoing method to the second VTEP device, or receive information involved in the foregoing method from the second VTEP device. Or instructions.
  • the first VTEP device can also include a memory for coupling with the processor that holds the necessary program instructions and data for the first VTEP device.
  • a second VTEP device having a function of implementing the behavior of the second VTEP device in the above method.
  • the functions may be implemented based on hardware, or may be implemented based on hardware.
  • the hardware or software includes one or more modules corresponding to the functions described above.
  • the structure of the second VTEP device includes a processor and an interface configured to support the second VTEP device to perform the corresponding function in the above method.
  • the interface is configured to support communication between the second VTEP device and the first VTEP device, send information or instructions involved in the foregoing method to the first VTEP device, or receive information involved in the foregoing method from the first VTEP device. Or instructions.
  • the second VTEP device can also include a memory for coupling with the processor that holds the necessary program instructions and data for the second VTEP device.
  • a computer storage medium for storing a program, code or instruction for use in the first VTEP device, and the processor or the hardware device can perform the first of the above aspects when executing the program, code or instruction The function or step of the VTEP device.
  • a computer storage medium for storing a program, code or instruction for use in the second VTEP device, and the processor or the hardware device can perform the second of the above aspects when executing the program, code or instruction.
  • the function or step of the VTEP device is provided.
  • FIG. 1 is a schematic structural diagram of a VXLAN network according to an embodiment of the present application.
  • FIG. 2 is a flowchart of a VXLAN packet forwarding method according to an embodiment of the present application
  • FIG. 3 is a flowchart of another VXLAN packet forwarding method according to an embodiment of the present application.
  • FIG. 4 is a flowchart of still another VXLAN packet forwarding method according to an embodiment of the present application.
  • FIG. 5 is a schematic structural diagram of another VXLAN network according to an embodiment of the present application.
  • FIG. 6 is a schematic structural diagram of another VXLAN network according to an embodiment of the present application.
  • FIG. 7 is a schematic structural diagram of another VXLAN network according to an embodiment of the present application.
  • FIG. 8 is a schematic structural diagram of a first VTEP device according to an embodiment of the present invention.
  • FIG. 9 is a schematic structural diagram of hardware of a first VTEP device according to an embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of a second VTEP device according to an embodiment of the present invention.
  • FIG. 11 is a schematic structural diagram of hardware of a second VTEP device according to an embodiment of the present invention.
  • the embodiment of the present invention provides a method, a device, and a system for forwarding a VXLAN packet, so as to improve the redundancy protection capability of the VXLAN network and ensure that the uplink traffic direction and the downstream traffic direction are consistent.
  • FIG. 1 is a schematic structural diagram of a VXLAN network according to an embodiment of the present application.
  • the VXLAN network includes a first VTEP device, a second VTEP device, and a third VTEP device.
  • the first VTEP device communicates with the second VTEP device via a first VXLAN tunnel, the first VTEP device communicating with the third VTEP device via a second VXLAN tunnel.
  • the first VTEP device is further connected to the first host, so that the first VTEP device can receive traffic from the first host and forward to the second VTEP device through the first VXLAN tunnel, or Forwarding to the third VTEP device through the second VXLAN tunnel.
  • the first VTEP device may receive traffic from the second VTEP device via the first VXLAN tunnel, and deliver the traffic to the first host; or the first VTEP device The traffic from the third VTEP device may be received via the second VXLAN tunnel and sent to the first host.
  • the first host may be a VM.
  • the application does not limit the number of VMs, and the first VTEP device can connect multiple VMs.
  • the VM can run on the server.
  • a server can contain at least one VM. In one possible implementation, one server may include multiple VMs. Different VMs can belong to different VXLAN network segments.
  • a VTEP device can also be called a Network Virtualization Edge (NVE) device. Ready.
  • NVE Network Virtualization Edge
  • a VTEP device is understood to be a module integrated in an NVE device. In this application, the VTEP device is equivalent to the NVE device without special explanation.
  • the second VTEP device communicates with an IP network via a communication link to forward traffic from the first host to the IP network, or receive from the IP network. The traffic is forwarded to the first host.
  • the third VTEP device communicates with the IP network via a communication link to forward traffic from the first host to the IP network, or receive traffic from the IP network to the first Host forwarding.
  • the IP network may also be connected to the second host, so as to complete the traffic transmission of the first host to the second host via the network structure described above, or, according to the second host, The network structure described above transmits traffic to the first host.
  • the specific implementation manner of the IP network is not limited in this application.
  • the IP network may be represented as an Internet network or an L3VPN network.
  • the second host may be a server.
  • the first VTEP device After receiving the traffic from the first host, the first VTEP device encapsulates the traffic into a VXLAN message, respectively, to the second VTEP device or the second VXLAN tunnel via the first VXLAN tunnel and the second VXLAN tunnel The third VTEP device forwards.
  • the second VTEP device or the third VTEP device decapsulates the received VXLAN message and re-encapsulates it into an IP packet, and sends the packet to the IP network, so that the traffic reaches the second host.
  • the IP network After receiving the traffic from the second host, the IP network encapsulates the traffic into an IP packet and sends the packet to the second VTEP device or the third VTEP device.
  • the second VTEP device or the third VTEP device decapsulates the received IP packet and re-encapsulates it into a VXLAN message, and sends the packet to the first VTEP device, so that the traffic reaches the first host. .
  • the traffic direction of the first host to the second host via the first VTEP device, the second VTEP device, the third VTEP device, and the IP network is called The upstream traffic direction; the traffic direction of the second host to the first host via the first VTEP device, the second VTEP device, the third VTEP device, and the IP network is referred to as a downlink traffic direction.
  • the second VTEP device and the third VTEP both serve as VXLAN Layer 3 gateways to complete transmission between the VXLAN network and the IP network.
  • a network composed of the first host, the first VTEP device, the second VTEP device, and the third VTEP device is referred to as a VXLAN network side; the second host, the IP is A network composed of a network, a second VTEP device, and a third VTEP device is referred to as an IP network side.
  • the network structure composed of the first host and the first VTEP device is referred to as an access link (AC) on the VXLAN network side; similarly, in the IP network side.
  • the network structure composed of the second host and the IP network is referred to as an AC on the IP network side. Therefore, the interface for connecting the first host on the first VTEP device is called an AC side interface of the VXLAN network; and the interface for connecting to the VXLAN tunnel is disposed on the first VTEP device. It is called the VXLAN tunnel interface.
  • the second VTEP device and the third VTEP device form a load balancing group.
  • the second VTEP device and the third VTEP device act as a VXLAN Layer 3 gateway.
  • the gateway interfaces that the two VXLAN Layer 3 gateways communicate with the first VTEP device are configured with the same IP address and MAC address, and the two VXLAN Layer 3 gateways are configured with the same virtual VTEP IP address.
  • the first VTEP device balances traffic to the first VXLAN tunnel and the second VXLAN tunnel by using a hash algorithm to Forward to the second a VTEP device and the third VTEP device.
  • the scenario of the multiple active gateway requires higher synchronization and delay.
  • a VXLAN tunnel or a certain gateway such as a first VXLAN tunnel or a second VTEP device
  • the traffic can bypass the faulty VXLAN tunnel or gateway based on the principle of Route Convergence, thereby The traffic is not transmitted via the first VXLAN tunnel, but is switched to the second tunnel.
  • a fault occurs on the IP network side, for example, the link between the second VTEP device and the IP network fails.
  • the multi-active gateway is based on the ECMP mode, the first VTEP device still learns the routes of the two VXLAN Layer 3 gateways. Therefore, the load balancing mode on the VXLAN network side is not changed. Therefore, in a multi-active gateway scenario, a complete redundancy protection mechanism cannot be provided.
  • the ECMP method is adopted, so that the uplink traffic direction and the downstream traffic direction cannot be consistent.
  • traffic from the first host arrives at the second VTEP device via the first VXLAN tunnel and eventually reaches the second host.
  • the traffic sent by the second host to the first host may reach the first host via the third VTEP device and the second VXLAN tunnel. This is not conducive to the firewall to detect traffic.
  • the embodiment of the present application provides a method, a device, and a system for forwarding a VXLAN packet, so as to improve the redundancy protection capability of the VXLAN network. Further, by setting the routing priority of the IP network to the VXLAN Layer 3 gateway, the uplink traffic direction and the downstream traffic direction are consistent.
  • the IP may be the fourth version of the Internet Protocol (Internet Protocol version 4, IPv4) or the sixth version of the Internet Protocol (IPv6), unless otherwise specified. IP that can appear in the future.
  • FIG. 2 to FIG. 4 are flowcharts of a VXLAN packet forwarding method according to an embodiment of the present application.
  • this embodiment will be described with reference to the schematic diagram of the VXLAN network structure shown in FIG. 1 and FIG. It should be understood that the implementation manners shown in FIG. 1 to FIG. 7 are only partial implementation manners of the technical solutions provided by the present application, and not all embodiments. In the embodiment of the present application, as shown in FIG. 1 and FIG. 5 to FIG.
  • VXLAN tunnels ie, a first VXLAN tunnel and a second VXLAN tunnel
  • two corresponding VTEP devices ie, a second VTEP device and The third VTEP device
  • the third VTEP device is described as an example. It should be understood that embodiments of the present application may include more than two VXLAN tunnels and corresponding VTEP devices.
  • the third VXLAN tunnel and the corresponding fourth VTEP device are further included, and the third VXLAN tunnel is between the first VTEP device and the fourth VTEP device. VXLAN tunnel.
  • one of the more than two VXLAN tunnels acts as the primary VXLAN tunnel, and the other VXLAN tunnels act as the standby VXLAN tunnel.
  • the first VXLAN tunnel is used as the primary VXLAN tunnel, and the first VXLAN tunnel and the third VXLAN tunnel are used as the standby tunnel.
  • the tunnel state of the VXLAN tunnel includes two states: an active state and an inactive state.
  • the status information is used to indicate the tunnel status of the VXLAN tunnel.
  • the status information carries the Active status
  • the VXLAN tunnel is activated.
  • the data traffic is allowed to be transmitted.
  • the status information carries the Inactive state
  • the VXLAN tunnel is inactive. .
  • FIG. 2 is a flowchart of a VXLAN packet forwarding method according to an embodiment of the present application.
  • the method shown in FIG. 2 can be applied to the network structure shown in FIG. 1. Specifically, the method shown in FIG. 2 can be implemented together with the process of establishing a VXLAN tunnel, or can be implemented after establishing a VXLAN tunnel.
  • the method includes:
  • the first VTEP device sets the tunnel state of the first VXLAN tunnel to an active state according to a priority of the first VXLAN tunnel.
  • S102 Set a tunnel state of the second VXLAN tunnel to an Inactive state according to a priority of the second VXLAN tunnel, where the priority of the first VXLAN tunnel is higher than a priority of the second VXLAN tunnel.
  • the first VXLAN tunnel is a VXLAN tunnel between the first VTEP device and the second VTEP device; the second VXLAN tunnel is the first VTEP device and the third VTEP VXLAN tunnel between devices.
  • the priority of the VXLAN tunnel is configured, specifically including the priority of the first VXLAN tunnel and the priority of the second VXLAN tunnel.
  • the priority of the VXLAN tunnel may be statically configured by the network administrator on the first VTEP device.
  • the priority of the VXLAN tunnel may be automatically configured by the controller according to the network topology, and then sent to the first VTEP device.
  • the priority of the VXLAN tunnel may be automatically configured by the first VTEP device.
  • the priority of the VXLAN tunnel may be set to two levels, such as a first priority and a second priority, and the first priority is higher than the second priority.
  • a VXLAN tunnel configured with a high priority (eg, a first priority) may be referred to as a primary VXLAN tunnel, and a VXLAN tunnel configured with a low priority (eg, a second priority) may be referred to as a standby VXLAN tunnel.
  • the priorities of the first VXLAN tunnel and the second VXLAN tunnel are configured such that the priority of the first VXLAN tunnel is higher than the priority of the second VXLAN tunnel. .
  • the first VXLAN tunnel is a primary VXLAN tunnel
  • the second VXLAN tunnel is a standby VXLAN tunnel.
  • the first VXLAN tunnel is equivalent to the primary VXLAN tunnel
  • the second VXLAN tunnel is equivalent to the standby VXLAN tunnel without special explanation or limitation.
  • a high priority e.g., first priority
  • a low priority e.g., second priority
  • the network structure includes three VXLAN tunnels.
  • the VXLAN tunnel 1 is configured with a first priority, which is called a primary VXLAN tunnel.
  • the VXLAN tunnel 2 and the VXLAN tunnel 3 are respectively configured with a second priority, which is called a standby VXLAN tunnel.
  • the priority of the VXLAN tunnel may be set to multiple levels, such as a first priority, a second priority, and a third priority. And, the first priority is higher than the second priority and the third priority, and the second priority is higher than the third priority.
  • the VXLAN tunnel 1 is configured with a first priority, which is called a primary VXLAN tunnel; and the VXLAN tunnel 2 and the VXLAN tunnel 3 are respectively configured with a second priority and a third priority, which are called standby VXLAN tunnels.
  • the priority of the VXLAN tunnel may be identified by using tunnel priority information or an IP address of a tunnel destination VTEP device.
  • the network administrator configures the tunnel priority information of the first VXLAN tunnel to 10 on the first VTEP device
  • the tunnel priority information of the second VXLAN tunnel is configured to be 5, so that the priority of the first VXLAN tunnel is higher than the priority of the second VXLAN tunnel.
  • FIG. 1 in the implementation of the priority of the static configuration of the VXLAN tunnel, the network administrator configures the tunnel priority information of the first VXLAN tunnel to 10 on the first VTEP device,
  • the tunnel priority information of the second VXLAN tunnel is configured to be 5, so that the priority of the first VXLAN tunnel is higher than the priority of the second VXLAN tunnel.
  • the first VTEP device compares a value of an IP address of the second VTEP device with the third The value of the IP address of the VTEP device, thereby determining that the priority of the first VXLAN tunnel is higher than the priority of the second VXLAN tunnel.
  • the first VTEP device further sets a tunnel state of the VXLAN tunnel according to a priority of the VXLAN tunnel, where the tunnel state includes an active active state and an inactive Inactive state.
  • the Active state is used to indicate that the VTEP device at both ends of the VXLAN tunnel is allowed to forward VXLAN messages through the VXLAN tunnel.
  • the Inactive state is used to indicate that the VTEP device at both ends of the VXLAN tunnel is not allowed to forward VXLAN messages via the VXLAN tunnel.
  • the first VTEP device sets the tunnel state of the primary VXLAN tunnel (high priority VXLAN tunnel) to the active state, and sets the tunnel state of the standby VXLAN tunnel (low priority VXLAN tunnel) to Inactive. status. Therefore, in the network structure shown in FIG. 1, the first VTEP device sets the tunnel state of the first VXLAN tunnel to an active state, and sets the tunnel state of the second VXLAN tunnel to an Inactive state.
  • both the second VTEP device and the third VTEP device act as a VXLAN Layer 3 gateway to complete the transmission between the VXLAN network and the IP network.
  • the IP address of the second VTEP device is different from the IP address of the third VTEP device to ensure that the traffic can be transmitted via the VXLAN tunnel in the active state without flowing into the VXLAN tunnel in the Inactive state.
  • the IP address of the second VTEP device is 2.2.2.2
  • the IP address of the third VTEP device is 3.3.3.3.
  • the gateway interface is called the Bridge Domain Interface (BDIF).
  • the BDIF is a three-layer logical interface created based on a Bridge Domain (BD) to implement communication between VMs of different subnets or between VXLAN networks and non-VXLAN networks.
  • BDIF_10 is provided on both the second VTEP device and the third VTEP device, the IP address of the BDIF_10 is IP_10, and the MAC address of the BDIF_10 is MAC_10.
  • a plurality of BDIFs may be set on the second VTEP device and the third VTEP device to distinguish different VXLAN network segments by the BDIF.
  • BDIF_20 is provided, the IP address of the BDIF_20 is IP_20, and the MAC address of the BDIF_20 is MAC_20.
  • BDIF_10 corresponds to VXLAN segment 1, so that the second VTEP device and the third VTEP device are used to forward uplink traffic from VMs belonging to VXLAN segment 1 or to downlinks belonging to VMs belonging to VXLAN segment 1 Traffic;
  • BDIF_20 corresponds to VXLAN network segment 2, so that the second VTEP device and the third VTEP device are used to forward uplink traffic from VMs belonging to VXLAN network segment 2, or to send downstream traffic to VMs belonging to VXLAN network segment 2 .
  • the VXLAN network segment 1 is identified by VNI_10
  • the VXLAN network segment 2 is identified by VNI_20 to distinguish different VXLAN network segments.
  • S103-S105 describes a process in which the first VTEP device and the second VTEP device configure a tunnel state of the first VXLAN tunnel; similarly, S106-S108 describes the first VTEP device and the first The process of configuring the tunnel state of the second VXLAN tunnel by the three VTEP devices. It should be understood that the processes described in S103-S105 and the processes described in S106-S108 do not have a strict execution sequence, and the two processes can be executed in parallel without affecting each other.
  • the first VTEP device advertises, by using the first VXLAN tunnel, the first VTEP device with first state information that carries an active state, where the first state information is used to indicate a tunnel of the first VXLAN tunnel. status.
  • the second VTEP device receives the first VTEP device from the first VXLAN tunnel. First status information.
  • the first VTEP device sets the tunnel state of the first VXLAN tunnel to an active state, and the Active state may be carried in the first state information, and sent to the second VTEP device via the first VXLAN tunnel. .
  • the second VTEP device receives the first state information.
  • the first state information is used to indicate a tunnel state of the first VXLAN tunnel.
  • the Active state is sent during the establishment of the first VXLAN tunnel.
  • the VXLAN tunnel can be established based on a Border Gateway Protocol Ethernet Virtual Private Network (BGP EVPN).
  • BGP EVPN is used to implement a control plane of the VXLAN.
  • a Border Gateway Protocol (BGP) is established between the first VTEP device and the second VTEP device, and between the first VTEP device and the third VTEP device.
  • an integrated multicast route (Inclusive Multicast Route) is transmitted between the first VTEP device and the second VTEP device, and between the first VTEP device and the third VTEP device,
  • the integrated multicast route is used to generate a broadcast, unknown unicast and multicast (Broadcast, Unknown Unicast, and Multicast, BUM) forwarding table, and is used to automatically establish a VXLAN tunnel for transmitting VXLAN messages. Therefore, in the implementation, the first VTEP device adds a type-length-value (TLV) to the integrated multicast route when sending the integrated multicast route to the second VTEP device. ), thereby forming the first state information.
  • the type of the TLV is Tunnel_Status, the length is 1 byte, and the value is identified as Active.
  • the Active state is sent after the establishment of the first VXLAN tunnel.
  • the BGP EVPN includes a notification message, and the notification message is used for the notification message sent by the local VTEP device to the peer VTEP device when the error is detected by the local VTEP device.
  • the Notification message is multiplexed to carry the tunnel status of the VXLAN tunnel.
  • the Notification message is not used to notify the error message, but is used to notify the tunnel status of the VXLAN tunnel. Therefore, the first status information may be a Notification message.
  • the first VTEP device sends a Notification message to the second VTEP device, where the Notification message carries an Active state.
  • the Active state is sent after the establishment of the first VXLAN tunnel.
  • the tunnel state of the VXLAN tunnel is carried in the PPP over VXLAN packet.
  • the first state information may be a PPP over VXLAN message.
  • the PPP over VXLAN packet includes a VXLAN header and a VXLAN payload
  • the VXLAN payload includes a Point-to-Point Protocol (PPP) packet, where the PPP packet includes a PPP header and a PPP payload
  • the PPP payload includes the tunnel status of the VXLAN tunnel.
  • the first VTEP device sends a PPP over VXLAN message to the second VTEP device, and the PPP over VXLAN message carries an Active state.
  • the second VTEP device receives the PPP over VXLAN packet, decapsulates the PPP over VXLAN packet, and obtains an Active state.
  • the second VTEP device confirms the first VXLAN tunnel as an active state, and sets a routing priority of the IP network to the second VTEP device as a first priority.
  • the second VTEP device After receiving the first state information, the second VTEP device carries according to the first state information.
  • the Active state confirms the first VXLAN tunnel as an Active state.
  • the second VTEP device may receive uplink traffic from the first host via the first VXLAN tunnel and forward the uplink traffic to the IP network.
  • the second VTEP device may also receive downlink traffic from the IP network, and forward the downlink traffic to the first host via the first VXLAN tunnel.
  • the second VTEP device sets the routing priority of the IP network to the second VTEP device to the first priority, and The IP network announces the first priority.
  • the IP network includes a router, and the second VTEP device advertises the first priority to a router in the IP network. The first priority is higher than a route priority of the IP network to the third VTEP device.
  • the IP network After receiving the traffic from the second host, the IP network forwards the traffic from the second host according to the path that the first priority preferentially selects the IP network to reach the second VTEP device.
  • traffic from the second host is directed to the second VTEP device.
  • the second VTEP device may forward traffic from the second host via the first VXLAN tunnel of the Active state. Therefore, the implementation provided by the embodiment can ensure that both the uplink traffic and the downlink traffic can be transmitted through the first VXLAN tunnel in the active state.
  • the first VTEP device advertises, by using the second VXLAN tunnel, the second VTEP device with the second state information that carries the Inactive state, where the second state information is used to indicate the tunnel of the second VXLAN tunnel. status.
  • S107 Receive second state information from the first VTEP device via a second VXLAN tunnel.
  • the first VTEP device sets the tunnel state of the second VXLAN tunnel to an Inactive state, and the Inactive state may be carried in the second state information, and sent to the third VTEP device by using the second VXLAN tunnel. .
  • the third VTEP device receives the second state information.
  • the second status information is used to indicate a tunnel status of the second VXLAN tunnel.
  • the value of the TLV is Tunnel_Status
  • the length is 1 byte
  • the value identifier is Inactive.
  • the Notification message carries an Inactive state.
  • the PPP over VXLAN packet carries the Inactive state.
  • the third VTEP device confirms the second VXLAN tunnel as an Inactive state, and sets a routing priority of the IP network to the third VTEP device to a second priority, where the first priority is Higher than the second priority.
  • the third VTEP device receives the second state information, and confirms the second VXLAN tunnel to an Inactive state according to the Inactive state carried by the second state information.
  • the second VXLAN tunnel in the inactive state is in a blocked (non-working) state, and does not forward uplink traffic and downlink traffic.
  • the third VTEP device sets a routing priority of the IP network to the third VTEP device to a second priority, the first priority being higher than the second priority.
  • the first priority is a route priority of the IP network to the second VTEP device.
  • the IP network preferentially selects the IP network to reach the second VTEP according to the first priority.
  • the standby path forwards traffic from the second host.
  • traffic from the second host is directed to the second VTEP device and does not reach the third VTEP device. Thereby preventing traffic from the second host from flowing into the second VXLAN tunnel.
  • the first VTEP device and the second VTEP device forward VXLAN messages via the first VXLAN tunnel.
  • the first VTEP device and the second VTEP device After completing the process of setting the first VXLAN tunnel to an Active state and setting a second VXLAN tunnel to an Inactive state, the first VTEP device and the second VTEP device forward upstream traffic via an Active state first VXLAN tunnel. And the downstream traffic, while the second VXLAN tunnel in the Inactive state is in a blocked (non-working) state, and does not forward traffic.
  • the local VTEP device sets the tunnel state of at least two VXLAN tunnels connected to the local VTEP device according to the priority of the VXLAN tunnel. Then, the tunnel state of the VXLAN tunnel is sent to at least two peer VTEP devices, and the at least two VXLAN tunnels are in one-to-one correspondence with the at least two peer VTEP devices. The at least two peer VTEP devices respectively confirm the tunnel status of the received VXLAN tunnel. Therefore, the VXLAN tunnel in the active state is in the working state, and the traffic is forwarded. The VXLAN tunnel in the inactive state is in a non-working state, and the traffic is not forwarded.
  • the method provided by the embodiment is used to improve the redundancy protection capability of the VXLAN network.
  • the remote VTEP device connected to the VXLAN tunnel in the active state sets the route priority of the IP network to the peer VTEP device to the first priority; the peer VTEP device connected to the VXLAN tunnel in the Inactive state will be the IP address.
  • the route priority of the network to the peer VTEP device is set to a second priority, and the first priority is higher than the second priority, thereby ensuring the consistency of the uplink traffic direction and the downlink traffic direction.
  • the method for forwarding a VXLAN packet between the S105 and the S113 further includes:
  • the second VTEP device sends the first response information of the first state information to the first VTEP device via the first VXLAN tunnel.
  • the first VTEP device receives first response information of the first state information from the second VTEP device via the first VXLAN tunnel.
  • the second VTEP device confirms the tunnel state of the first VXLAN tunnel as an active state according to the first state information, and sets a route priority of the IP network to the second VTEP device as a first priority, Then, the first response information is generated according to the first state information. The first response information is used to instruct the second VTEP device to confirm the tunnel status of the first VXLAN tunnel as an active state.
  • the second VTEP device sends the first response information to the first VTEP device via the first VXLAN tunnel.
  • the first VTEP device determines that the second VTEP has processed the first state information according to the received first response information.
  • the implementation manner of the first response information may be implemented by using the first state information in S103 and S104, and details are not described herein.
  • the first VTEP device triggers the forwarding of the traffic when the second VTEP device receives and processes the first state information, thereby effectively improving the reliability of the forwarding execution process and avoiding the setting process. Packet loss caused by out of sync with the traffic forwarding process.
  • the method for forwarding a VXLAN message between S108 and S113 further includes:
  • the third VTEP device sends the second response information of the second state information to the first VTEP device via the second VXLAN tunnel.
  • the first VTEP device receives second response information of the second state information from the third VTEP device via the second VXLAN tunnel.
  • the third VTEP device after processing the second state information, the third VTEP device sends the second response information to the first VTEP device.
  • the second response information is used to instruct the third VTEP device to confirm the tunnel status of the second VXLAN tunnel as an Inactive state.
  • the first VTEP device determines that the third VTEP has processed the second state information according to the received second response information.
  • the implementation manner of the second response information may be implemented by using the first state information in S103 and S104, and details are not described herein.
  • FIG. 3 is a flowchart of another VXLAN packet forwarding method according to an embodiment of the present application.
  • the method shown in FIG. 3 is based on the method shown in FIG. 2 above, and is implemented in the VXLAN message forwarding method when there is a fault in the active state VXLAN tunnel.
  • the method shown in FIG. 3 can be applied to the network structure shown in FIG. As shown in FIG. 5, the first VXLAN tunnel has a fault.
  • the method includes:
  • the first VTEP device determines that the first VXLAN tunnel is faulty.
  • the first VXLAN tunnel in the active state is in a working state, and the traffic is forwarded.
  • the second VXLAN tunnel in the inactive state is in a non-working state, and the traffic is not forwarded.
  • the first VTEP device may send a first failure detection message to the second VTEP device via the first VXLAN tunnel, and the first VTEP device receives the second VTEP device from the second VTEP device via the first VXLAN tunnel The first response packet of the first fault detection message.
  • the first VTEP device determines that the first VXLAN tunnel is faulty.
  • the first VTEP device periodically sends the first fault detection message to the second VTEP device.
  • the specific implementation manner of the first fault detection packet is not limited in this application.
  • the first fault detection packet is a Bidirectional Forwarding Detection (BFD) packet.
  • the first fault detection message is an Ethernet operation, administration, and maintenance (ETH OAM) message.
  • the first fault detection message is a BGP EVPN based Keepalive message.
  • the first VTEP device sets a tunnel state of the first VXLAN tunnel to an Inactive state, and sets a tunnel state of the second VXLAN tunnel to an Active state.
  • the first VTEP device determines that the action of switching the VXLAN tunnel is triggered after the first VXLAN tunnel in the active state has a fault. Specifically, the first VTEP device switches the first VXLAN tunnel in the active state to the Inactive state, and switches the second VXLAN tunnel in the Inactive state to the active state.
  • the first VTEP device advertises, by using the second VXLAN tunnel, the third VTEP device with third state information that carries an active state, where the third state information is used to indicate the second VXLAN.
  • the tunnel status of the tunnel is used to indicate the second VXLAN.
  • the third VTEP device receives third state information from the first VTEP device via a second VXLAN tunnel.
  • the first VTEP device After the first VTEP device switches the second VXLAN tunnel in the Inactive state to the Active state, the first VTEP device advertises the third VTEP device with the third state carrying the Active state to the third VTEP device via the second VXLAN tunnel. information.
  • the third VTEP device receives the third state information.
  • the third status information is used to indicate a tunnel status of the second VXLAN tunnel.
  • the third VTEP device confirms the second VXLAN tunnel as an active state, and sets a routing priority of the IP network to the third VTEP device as a first priority.
  • the third VTEP device After receiving the third state information, the third VTEP device confirms the second VXLAN tunnel as an Active state according to the Active state carried by the third state information, and reaches the third network by the IP network.
  • the routing priority of the VTEP device is set to the first priority.
  • the third VTEP device sends the third response information of the third state information to the first VTEP device via the second VXLAN tunnel.
  • the first VTEP device receives third acknowledgement information of the third state information from the third VTEP device via the second VXLAN tunnel.
  • the third VTEP device After processing the third state information, the third VTEP device generates third response information according to the third state information.
  • the third response information is used to instruct the third VTEP device to update the tunnel status of the second VXLAN tunnel to an active state.
  • the third VTEP device sends the third response information to the first VTEP device via the second VXLAN tunnel.
  • the first VTEP device determines that the third VTEP has processed the third state information according to the received third response information.
  • the first VTEP device and the third VTEP device forward the VXLAN message via the second VXLAN tunnel.
  • the first VTEP device and the third VTEP device After completing the switching of the tunnel state of the second VXLAN tunnel, the first VTEP device and the third VTEP device forward the uplink traffic and the downlink traffic via the Active state second VXLAN tunnel.
  • the first VTEP device and the VTEP device perform the processes of S201 and S210
  • the second VETP device performs the processes of S209 and S210. It should be understood that the processes described in S209 and S210 and the processes described in S201-S208 do not have a strict execution sequence, and the two processes can be executed in parallel without affecting each other.
  • the second VTEP device determines that the first VXLAN tunnel is faulty.
  • the first VTEP device sends a first failure detection message to the second VTEP device via the first VXLAN tunnel
  • the second VTEP device passes the first VXLAN tunnel to the first A VTEP device sends a second fault detection message.
  • the second VTEP device receives the second response packet of the second fault detection message from the first VTEP device via the first VXLAN tunnel.
  • the second VTEP device determines that the first VXLAN tunnel is faulty.
  • the second VTEP device periodically sends the second fault detection message to the first VTEP device.
  • the second fault detection packet refer to the corresponding description in the foregoing S201, and details are not described herein.
  • the second VTEP device switches the tunnel state of the first VXLAN tunnel to Inactive. a state, and switching a routing priority of the IP network to the second VTEP device to a second priority.
  • the second VTEP device After determining that the first VXLAN tunnel is faulty, the second VTEP device switches the first VXLAN tunnel in an active state to an Inactive state, and reaches the IP network to the second VTEP.
  • the routing priority of the device is switched to the second priority.
  • the first priority is higher than the second priority.
  • the second VTEP device actively switches the first VXLAN tunnel in the active state to the Inactive state according to the fault condition of the first VXLAN tunnel, and does not adopt the receiving state from the first VTEP device.
  • the way the information is executed is switched. This is advantageous in avoiding the problem that state information cannot be delivered due to a failure of the first VXLAN tunnel.
  • the first VTEP device and the second VTEP device switch the active state of the primary VXLAN tunnel to the Inactive state, and the first VTEP device and the third The VTEP device switches the standby VXLAN tunnel in the Inactive state to the Active state, which effectively improves the redundancy protection capability.
  • the switching of the routing priority of the IP network to the VTEP device ensures the consistency of the upstream traffic direction and the downstream traffic direction after the primary and backup VXLAN tunnels are switched.
  • the first VTEP device, the second VTEP device, and the third VTEP may switch the tunnel state of the first VXLAN tunnel from the Inactive state to the Active state, and switch the tunnel state of the second VXLAN tunnel from the Active state to the Inactive state, in combination with the implementation manners provided in FIG. 2 and FIG. And switching the routing priority of the IP network to the second VTEP device and the routing priority of the IP network to the third VTEP device.
  • the failure of the first VXLAN tunnel may be a complete physical disconnection or a communication failure of the data plane.
  • the communication of the control plane may not be affected, that is, if the data plane is unreachable, the control plane may perform normal communication.
  • the method shown in FIG. 3 may further include:
  • the second VTEP device sends a handover confirmation message to the first VTEP device via the first VXLAN tunnel.
  • the second VTEP device sends a handover confirmation message to the first VTEP device. If the failure of the first VXLAN tunnel belongs to a communication failure of the data plane, and the control plane can communicate normally, the first VTEP device will receive the handover confirmation message. Therefore, S211 helps to improve the reliability of tunnel state switching.
  • the implementation of the handover confirmation message may be implemented by using the Notification message or the PPP over VXLAN message in the foregoing embodiment.
  • the method shown in FIG. 3 may further include:
  • the first VTEP device advertises, by using the first VXLAN tunnel, the fourth VTEP device with the fourth state information that carries the Inactive state, where the fourth state information is used to indicate the tunnel of the first VXLAN tunnel. status.
  • the second VTEP device receives the fourth state information from the first VTEP device via the first VXLAN tunnel.
  • the first VTEP device notifies the second VTEP device of the fourth state information carrying the Inactive state. If the failure of the first VXLAN tunnel belongs to a communication failure of the data plane, and the control plane can communicate normally, the second VTEP device may receive the fourth state information. According to the foregoing S209 and S210, the second VTEP device confirms that the tunnel state of the first VXLAN tunnel has been confirmed to be an Inactive state. Generating, by the second VTEP device, fourth response information of the fourth state information, and transmitting the fourth response information to the first VTEP device, so that the first VTEP device can learn the second VTEP The device has been switched to the tunnel state. Therefore, S212-S214 helps to improve the reliability of tunnel state switching.
  • the first VTEP device determines that the first VXLAN tunnel is faulty according to the first fault detection message. However, the first VTEP device cannot sense the cause of the fault according to the first fault detection message.
  • the fault is as shown in FIG. 5.
  • the first VTEP device and the second VTEP device will implement switching of a tunnel state according to the method shown in FIG. 3.
  • the fault is as shown in FIG. 6, and the second VTEP device has a fault.
  • the second VTEP device will not be able to complete the operations of S209 and S210, and the optional operations of S211, S213, and S214 cannot be completed.
  • the first VTEP device and the third VTEP device may perform normal switching of the tunnel state of the second VXLAN tunnel according to the method shown in FIG. 3.
  • the uplink traffic direction may be forwarded through the second VXLAN tunnel in the active state, and is not forwarded through the first VXALN tunnel. .
  • the route of the IP network to the second VTEP device is revoked according to the route convergence principle due to the failure of the second VTEP device.
  • the IP network does not send downstream traffic to the second VTEP device, but to the third VTEP device, so that downstream traffic passes through the second VXLAN tunnel to the first VTEP device. Therefore, the method shown in FIG. 3 can be applied to the fault scenario shown in FIG. 5, and also to the fault scenario shown in FIG. 6.
  • the implementation of the third state information, the third response information, the fourth state information, and the fourth response information may be implemented by using the Notification message or the PPP over VXLAN message in the foregoing embodiment.
  • FIG. 4 is a flowchart of still another VXLAN packet forwarding method according to an embodiment of the present application.
  • the method shown in FIG. 4 is based on the method shown in FIG. 2 above, and when the link between the second VTEP device and the IP network is faulty, the VXLAN message forwarding method is implemented.
  • the method shown in FIG. 4 can be applied to the network structure shown in FIG. As shown in FIG. 7, the link between the second VTEP device and the IP network is faulty.
  • the method includes:
  • the second VTEP device determines that the link between the second VTEP device and the IP network is faulty, the second VTEP device generates a link failure message.
  • the second VTEP device determines whether a link between the second VTEP device and the IP network is faulty by sending a fault detection message to the IP network.
  • the fault detection report For the implementation of the text, refer to the description of the step S201 in the foregoing embodiment, and details are not described herein.
  • the second VTEP device generates a link failure message when it is determined that the link between the second VTEP device and the IP network is faulty.
  • the implementation of the link fault message may be implemented by using the Notification message or the PPP over VXLAN message in the foregoing embodiment.
  • the second VTEP device sends the link failure message to the first VTEP device via the first VXLAN tunnel.
  • the first VTEP device receives the link failure message from the first VTEP device via the first VXLAN tunnel.
  • the link failure message is sent to the first VTEP device, and the first VTEP device receives the link failure message.
  • the first VTEP device sets a tunnel state of the first VXLAN tunnel to an Inactive state, and sets a tunnel state of the second VXLAN tunnel to an Active state.
  • the first VTEP device determines that the link between the second VTEP device and the IP network is faulty according to the link failure message, and triggers an action of switching the VXLAN tunnel. Specifically, the first VTEP device switches the first VXLAN tunnel in the active state to the Inactive state, and switches the second VXLAN tunnel in the Inactive state to the active state.
  • the first VTEP device notifies the third VTEP device of the third state information carrying the Active state, and notifies the second VTEP device to carry the second VTEP device via the second VXLAN tunnel.
  • the third state information is used to indicate a tunnel state of the second VXLAN tunnel, and the fourth state information is used to indicate a tunnel state of the first VXLAN tunnel.
  • the first VTEP device generates third state information carrying an Active state, and sends the third state information to the third VTEP device; and the first VTEP device generates a fourth state that carries an Inactive state. And transmitting the fourth status information to the second VTEP device.
  • the third VTEP device receives third state information from the first VTEP device via a second VXLAN tunnel.
  • the third VTEP device confirms the second VXLAN tunnel as an active state, and sets a routing priority of the IP network to the third VTEP device as a first priority.
  • the third VTEP device sends the third response information of the third state information to the first VTEP device via the second VXLAN tunnel.
  • the first VTEP device receives third response information of the third state information from the third VTEP device via the second VXLAN tunnel.
  • the first VTEP device and the third VTEP device forward the VXLAN message via the second VXLAN tunnel.
  • S306-S309 describe a process in which the first VTEP device and the third VTEP device configure a tunnel state of the second VXLAN tunnel; similarly, S311-S314 describe the first VTEP device and the second VTEP device. The process of configuring the tunnel state of the first VXLAN tunnel. It should be understood that S306-S309 has described The process described in the process and S311-S314 does not have a strict execution sequence, and the two processes can be executed in parallel without affecting each other.
  • the method further includes:
  • the second VTEP device receives fourth state information from the first VTEP device via a first VXLAN tunnel.
  • the second VTEP device switches the tunnel state of the first VXLAN tunnel to an Inactive state, and switches a routing priority of the IP network to the second VTEP device to a second priority.
  • the second VTEP device sends the fourth response information of the fourth state information to the first VTEP device via the first VXLAN tunnel.
  • the first VTEP device receives fourth response information of the fourth state information from the second VTEP device via the first VXLAN tunnel.
  • the implementation of the third state information, the third response information, the fourth state information, and the fourth response information may be implemented by using the Notification message or the PPP over VXLAN message in the foregoing embodiment.
  • the first VTEP device and the second VTEP when the primary VXLAN tunnel in the active state receives a link failure message that the link between the second VTEP device and the IP network is faulty, the first VTEP device and the second VTEP The device switches the active state of the primary VXLAN tunnel to the inactive state, and the first VTEP device and the third VTEP device switch the standby VXLAN tunnel in the inactive state to the active state, thereby effectively improving the redundancy protection capability. Moreover, the switching of the routing priority of the IP network to the VTEP device ensures the consistency of the upstream traffic direction and the downstream traffic direction after the primary and backup VXLAN tunnels are switched.
  • the first VTEP device can switch the tunnel state of the first VXLAN tunnel from the Inactive state to the Active state, and switch the tunnel state of the second VXLAN tunnel from the Active state to the Inactive state, in combination with the implementation manners provided in FIG. 2 and FIG. a state, and switching a routing priority of the IP network to the second VTEP device and a routing priority of the IP network to the third VTEP device.
  • the method further includes:
  • the first VTEP device receives an Address Resolution Protocol (ARP) request message from the host, and the ARP request message is used to request a MAC address of the VXLAN gateway.
  • the first VTEP device sends the ARP request message to the second VTEP device and the third VTEP device via the first VXLAN tunnel and the second VXLAN tunnel, respectively, so that the second VTEP device And generating, by the third VTEP device, an ARP entry according to the ARP request packet.
  • ARP Address Resolution Protocol
  • the host needs to exchange ARP packets with the VXLAN Layer 3 gateway.
  • the first VXLAN tunnel is in an Active state.
  • the host generates an ARP request packet, where the source MAC address of the ARP request packet is the MAC address of the host, the source IP address is the IP address of the host, and the destination IP address of the ARP request packet is the second
  • the IP address of the BDIF of the VTEP device according to the foregoing embodiment, for example, the IP address of the BDIF is IP_10 of BDIF_10.
  • the ARP request message is used to request a MAC address of the VXLAN gateway.
  • the ARP request message is used to request the second VTEP The MAC address of the device (for example, MAC_10).
  • the first VTEP device After receiving the ARP request packet, the first VTEP device encapsulates the ARP request packet into a VXLAN message, and sends the message to the second VTEP device via the first VXLAN tunnel.
  • the second VTEP device After obtaining the ARP request packet, the second VTEP device generates an ARP entry and generates a MAC entry according to the ARP entry.
  • the second VTEP device further sends an ARP response packet to the host, where the ARP response packet carries the MAC address of the BDIF of the second VTEP device.
  • the MAC address of the BDIF is BDIF_10.
  • the VXLAN tunnel in the active state is used to transmit VXLAN packets, and the VXLAN tunnel in the inactive state does not transmit VXLAN packets.
  • the ARP request packet is sent to the second VTEP device through the first VXLAN tunnel in the active state according to the foregoing method. And transmitting the ARP request message to the third VTEP device via a second VXLAN tunnel in an Inactive state.
  • the third VTEP device after obtaining the ARP request packet, the third VTEP device generates an ARP entry and generates a MAC entry according to the ARP entry.
  • the third VTEP device also sends an ARP response packet to the host, where the ARP response packet carries the MAC address of the BDIF of the third VTEP device.
  • the first VXLAN tunnel in the active state transmits an ARP request packet, so that the second VTEP device can learn the ARP entry and the MAC entry, and the second VTEP device can learn the ARP entry and the MAC entry.
  • the second VXLAN tunnel in the inactive state also transmits an ARP request packet, so that the third VTEP device can also learn the ARP entry and the MAC entry. Therefore, the synchronization between the ARP entries and the MAC entries of the VXLAN Layer 3 gateway is implemented, and the entry backup link between the VXLAN Layer 3 gateways is not required.
  • the VXLAN packet forwarding method of the present application can use the existing ARP table between the VXLAN Layer 3 gateways by establishing an entry backup link between the VXLAN Layer 3 gateways. Synchronization of items and MAC entries.
  • the forwarding method of the VXLAN packet of the present application may also use the foregoing preferred implementation manner to implement synchronization of ARP entries and MAC entries between the VXLAN Layer 3 gateways.
  • the method further includes:
  • the first VTEP device generates an ARP entry according to the ARP request packet.
  • the first VTEP device stores the ARP entry.
  • the ARP request packet is generated according to the stored ARP entry, and the ARP request packet is sent to the destination VTEP device via the faulty VXLAN tunnel.
  • the first VTEP device determines that there is a newly established VXLAN tunnel, generating the ARP request packet according to the stored ARP entry, and sending the message to the destination VTEP device via the newly established VXLAN tunnel.
  • the ARP request message is
  • an ARP request packet may not be sent to the second VTEP device.
  • the fourth VTEP device joins the network structure described in FIG. 1 as a new VXLAN Layer 3 gateway.
  • the fourth VTEP device is connected to the first VTEP device through a third VXLAN tunnel.
  • the fourth VTEP device does not store the ARP entry and the MAC entry because the fourth VTEP device is a newly added VXLAN Layer 3 gateway.
  • the first VTEP device after receiving the ARP request packet, the first VTEP device generates an ARP entry according to the ARP request packet.
  • the first VTEP device stores the ARP entry to the first Temporary memory of the VTEP device.
  • the first VTEP device determines the fault recovery of the first VXLAN tunnel, the first VTEP device generates the ARP request packet according to the stored ARP entry, And sending the ARP request message to the second VTEP device via the first VXLAN tunnel.
  • the first VTEP device when the first VTEP device determines that the third VXLAN tunnel exists, the first VTEP device generates the ARP request packet according to the stored ARP entry, And sending the ARP request message to the fourth VTEP device via the third VXLAN tunnel.
  • FIG. 8 is a schematic structural diagram of a first VTEP device 1000 according to an embodiment of the present invention.
  • the first VTEP device shown in FIG. 8 can perform the respective steps performed by the first VTEP device in the method of the above embodiment.
  • the first VTEP device 1000 includes a processing unit 1002, a transmitting unit 1004, and a message forwarding unit 1006, where:
  • the processing unit 1002 is configured to set a tunnel state of the first VXLAN tunnel to an active state according to a priority of the first VXLAN tunnel, where the first VXLAN tunnel is between the first VTEP device and the second VTEP device VXLAN tunnel;
  • the processing unit 1002 is further configured to set a tunnel state of the second VXLAN tunnel to an Inactive state according to a priority of the second VXLAN tunnel, where the second VXLAN tunnel is between the first VTEP device and the third VTEP device The priority of the first VXLAN tunnel is higher than the priority of the second VXLAN tunnel, and the IP address of the second VTEP device is different from the IP address of the third VTEP device;
  • the sending unit 1004 is configured to notify the second VTEP device, by using the first VXLAN tunnel, first state information that carries an Active state, where the first state information is used to indicate a tunnel of the first VXLAN tunnel. status;
  • the sending unit 1004 is further configured to notify, by using the second VXLAN tunnel, the second VTEP device with second state information carrying an Inactive state, where the second state information is used to indicate a tunnel of the second VXLAN tunnel. status;
  • the message forwarding unit 1006 is configured to forward the VXLAN message by using the first VXLAN tunnel whose tunnel state is an active state.
  • the first VTEP device further includes a receiving unit, where the receiving unit is configured to: before the packet forwarding unit forwards the VXLAN message by using the first VXLAN tunnel with the tunnel state being the active state. Specifically for:
  • the The unit 1002 is further configured to set a tunnel state of the first VXLAN tunnel to an Inactive state, and set a tunnel state of the second VXLAN tunnel to an Active state.
  • the sending unit 1004 is further configured to notify, by using the second VXLAN tunnel, the third VTEP device with third state information that carries an Active state, where the third state information is used to indicate a tunnel of the second VXLAN tunnel. status;
  • the receiving unit is configured to receive, by the second VXLAN tunnel, third response information of the third state information from the third VTEP device, where the third response information is used to indicate that the third VTEP device is to The tunnel status of the second VXLAN tunnel is updated to an Active state;
  • the message forwarding unit 1006 is configured to forward the VXLAN message by using the second VXLAN tunnel whose tunnel state is an active state.
  • the receiving unit is configured to receive, by using the first VXLAN tunnel, a link failure message from the second VTEP device, where the link failure message is used to indicate between the second VTEP device and the IP network.
  • the IP network is configured to send traffic to a host connected to the first VTEP device and to receive traffic from the host connected to the first VTEP device;
  • the processing unit 1002 is further configured to set a tunnel state of the first VXLAN tunnel to an Inactive state, and set, by the first VTEP device, a tunnel state of the second VXLAN tunnel to an Active state;
  • the sending unit 1004 is further configured to notify, by using the second VXLAN tunnel, the third VTEP device with third state information that carries an Active state, where the third state information is used to indicate a tunnel of the second VXLAN tunnel. status;
  • the receiving unit is further configured to receive, by using the second VXLAN tunnel, third response information of the third state information from the third VTEP device, where the third response information is used to indicate the third VTEP device Updating the tunnel status of the second VXLAN tunnel to an Active state;
  • the message forwarding unit 1006 is configured to forward the VXLAN message by using the second VXLAN tunnel whose tunnel state is an active state.
  • the receiving unit is further configured to receive an address resolution protocol ARP request packet from the host, where the ARP request packet is used to request a media access control MAC address of the VXLAN gateway;
  • the sending unit 1004 is further configured to send the ARP request message to the second VTEP device and the third VTEP device via the first VXLAN tunnel and the second VXLAN tunnel, respectively, so that the second The VTEP device and the third VTEP device generate an ARP entry according to the ARP request packet.
  • processing unit 1002 is further configured to generate the ARP entry according to the ARP request packet.
  • a storage unit configured to store the ARP entry
  • the processing unit 1002 is further configured to: when determining a fault recovery of the faulty VXLAN tunnel, generate the ARP request packet according to the stored ARP entry, and the sending unit is further configured to use the VXLAN tunnel recovered by the fault. Sending the ARP request packet to the destination VTEP device; or
  • the processing unit 1002 is further configured to: when it is determined that there is a newly established VXLAN tunnel, generate the ARP request packet according to the stored ARP entry, and the sending unit is further configured to use the newly established VXLAN The tunnel sends the ARP request packet to the destination VTEP device.
  • the first VTEP device shown in FIG. 8 can perform the respective steps performed by the first VTEP device in the method of the above embodiment.
  • the VXLAN tunnel in the active state is in a working state, and the forwarding of traffic is performed, Inactive
  • the VXLAN tunnel in the state is inactive and does not forward traffic.
  • the method provided by the embodiment is used to improve the redundancy protection capability of the VXLAN network.
  • FIG. 9 is a schematic structural diagram of hardware of a first VTEP device 1100 according to an embodiment of the present invention.
  • the first VTEP device shown in FIG. 9 can perform the respective steps performed by the first VTEP device in the method of the above embodiment.
  • the first VTEP device 1100 includes a processor 1101, a memory 1102, an interface 1103, and a bus 1104.
  • the interface 1103 can be implemented in a wireless or wired manner, and specifically, may be, for example, a network card or the like.
  • the processor 1101, the memory 1102, and the interface 1103 are connected by a bus 1104.
  • the interface 1103 may specifically include a transmitter and a receiver for transmitting and receiving information between the first VTEP device and the second VTEP device in the foregoing embodiment; or for the first VTEP device and the third VTEP in the foregoing embodiment. Send and receive information between devices.
  • the interface 1103 can also be used to send and receive information between the first VTEP device and the host connected to the first VTEP device.
  • the interface 1103 is used to support the processes S103, S106, S110, S112, S113, S203, S207, S208, S212, S303, S305, S309, S310 and S314 in FIGS.
  • the processor 1101 is configured to perform processing performed by the first VTEP device in the above embodiment.
  • the processor 1101 is configured to support the processes S101, S102, S201, S202, and S304 in FIGS.
  • the memory 1102 includes an operating system 11021 and an application 11022 for storing programs, codes, or instructions that can be completed when the processor or hardware device executes the programs, codes, or instructions. .
  • Figure 9 only shows a simplified design of the first VTEP device.
  • the first VTEP device can include any number of interfaces, processors, memories, etc., and all of the first VTEP devices that can implement the present invention are within the scope of the present invention.
  • an embodiment of the present invention provides a computer storage medium for storing computer software instructions for use in the first VTEP device, which includes a program designed to execute the embodiments shown in FIG. 2 to FIG.
  • FIG. 10 is a schematic structural diagram of a second VTEP device 1200 according to an embodiment of the present invention.
  • the second VTEP device shown in FIG. 10 can perform the corresponding steps performed by the second VTEP device in the method of the above embodiment.
  • the second VTEP device 1200 includes a receiving unit 1202, a processing unit 1204, and a message forwarding unit 1206, where:
  • the receiving unit 1202 is configured to receive, by using a first VXLAN tunnel, first state information from a first VTEP device, where the first state information is used to indicate a tunnel state of the first VXLAN tunnel;
  • the processing unit 1204 is configured to: when the tunnel state carried by the first state information is an active state, confirm the first VXLAN tunnel as an active state, and prioritize a route of the IP network to the second VTEP device.
  • the level is set to a first priority
  • the IP network is configured to send traffic to a host connected to the first VTEP device and to receive traffic from the host connected to the first VTEP device, the first priority
  • the level is greater than the second priority, where the second priority is the route priority of the IP network to the second VTEP device when the first VXLAN tunnel is in the inactive state;
  • the message forwarding unit 1206 is configured to forward the VXLAN message by using the first VXLAN tunnel whose tunnel state is an active state.
  • the second VTEP device further includes a sending unit, configured to send first response information of the first state information to the first VTEP device via the first VXLAN tunnel, The first response information is used to indicate a tunnel status of the first VXLAN tunnel confirmed by the second VTEP device.
  • the processing unit is further configured to switch the tunnel state of the first VXLAN tunnel to an Inactive state when the first VXLAN tunnel whose tunnel state is the active state is determined to be faulty, and the IP is The route priority of the network reaching the second VTEP device is switched to the second priority.
  • the processing unit is further configured to: when it is determined that the link between the second VTEP device and the IP network is faulty, generate a link failure message, where the link failure message is used to indicate the The link between the second VTEP device and the IP network is faulty;
  • the sending unit is configured to send the link failure message to the first VTEP device by using the first VXLAN tunnel whose tunnel state is an active active state;
  • the receiving unit is further configured to receive, by using the first VXLAN tunnel, second state information from the first VTEP device, where the second state information carries an Inactive state, and is used to indicate a tunnel state of the first VXLAN tunnel. ;
  • the processing unit is further configured to switch a tunnel state of the first VXLAN tunnel to an Inactive state according to the second state information, and switch a route priority of the IP network to the second VTEP device to a second state. priority.
  • the second VTEP device shown in FIG. 10 can perform the corresponding steps performed by the second VTEP device in the method of the above embodiment.
  • the method provided by the embodiment is adopted to improve the redundancy protection capability of the VXLAN network and ensure the consistency of the uplink traffic direction and the downlink traffic direction.
  • FIG. 11 is a schematic structural diagram of hardware of a second VTEP device 1300 according to an embodiment of the present invention.
  • the second VTEP device shown in FIG. 11 can perform the corresponding steps performed by the second VTEP device in the method of the above embodiment.
  • the second VTEP device 1300 includes a processor 1301, a memory 1302, an interface 1303, and a bus 1304.
  • the interface 1303 can be implemented by using a wireless or wired manner, and specifically, for example, a network card or the like.
  • the processor 1301, the memory 1302, and the interface 1303 are connected by a bus 1304.
  • the interface 1303 may specifically include a transmitter and a receiver for transmitting and receiving information between the second VTEP device and the first VTEP device in the foregoing embodiment, or for the second VTEP device and the IP network in the foregoing embodiment. Send and receive information.
  • the interface 1303 is used to support the processes S104, S109, S113, S211, S213, S214, S302, S311 and S313 in FIGS.
  • the processor 1301 is configured to perform processing performed by the second VTEP device in the above embodiment.
  • the processor 1301 is configured to support the processes S105, S209, S210, S301, and S312 in FIGS. 2-4.
  • the memory 1202 includes an operating system 12021 and an application 12022 for storing programs, codes, or instructions that can be completed when the processor or hardware device executes the programs, codes, or instructions. .
  • Figure 11 only shows a simplified design of the second VTEP device.
  • the second VTEP device can include any number of interfaces, processors, memories, etc., and all second VTEP devices that can implement the present invention are within the scope of the present invention.
  • an embodiment of the present invention provides a computer storage medium for storing computer software instructions for use in the second VTEP device, which includes a program designed to execute the embodiments shown in FIG. 2 to FIG.
  • the steps of a method or algorithm described in connection with the present disclosure may be implemented in a hardware, or may be implemented by a processor executing software instructions.
  • the software instructions may be comprised of corresponding software modules that may be stored in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, removable hard disk, CD-ROM, or any other form of storage well known in the art.
  • An exemplary storage medium is coupled to the processor to enable the processor to read information from, and write information to, the storage medium.
  • the storage medium can also be an integral part of the processor.
  • the processor and the storage medium can be located in an ASIC. Additionally, the ASIC can be located in the user equipment.
  • the processor and the storage medium may also reside as discrete components in the user equipment.
  • the functions described herein can be implemented in hardware, software, firmware, or any combination thereof.
  • the functions may be stored in a computer readable medium or transmitted as one or more instructions or code on a computer readable medium.
  • Computer readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another.
  • a storage medium may be any available media that can be accessed by a general purpose or special purpose computer.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

一种VXLAN报文的转发方法、设备及系统。所述方法包括:本端VTEP设备根据VXLAN隧道的优先级设置与所述本端VTEP设备连接的至少两条VXLAN隧道的隧道状态。然后,将VXLAN隧道的隧道状态发送给至少两台对端VTEP设备,所述至少两条VXLAN隧道与所述至少两台对端VTEP设备一一对应。所述至少两台对端VTEP设备分别对接收到的VXLAN隧道的隧道状态进行确认。从而,Active状态的VXLAN隧道处于工作状态,Inactive状态的VXLAN隧道处于非工作状态,提高了VXLAN网络的冗余保护能力。

Description

一种VXLAN报文的转发方法、设备及系统
本申请要求于2016年9月20日提交中国专利局、申请号为201610836569.0、申请名称为“一种VXLAN报文的转发方法、设备及系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及通信技术领域,尤其涉及对虚拟可扩展局域网(Virtual eXtensible Local Area Network,VxLAN)技术。
背景技术
VXLAN是一种将二层报文用三层协议进行封装的技术。VXLAN技术涉及MAC-in-UDP格式的报文。具体地,将基于媒体接入控制(Media Access Control,MAC)协议的以太网帧封装在用户数据报协议(User Datagram Protocol,UDP)报文中。进一步地,将UDP报文封装在因特网协议(Internet Protocol,IP)报文中,可以在三层网络中传输IP报文。因此,实现了以太网帧在三层网络中传送。VXLAN技术使用VXLAN网络标识符(VXLAN Network Identifier,VNI)标识VXLAN网段。不同的VXLAN网段分别对应不同的VNI。不同的VXLAN网段之间是隔离的。同一个VNI内的两个虚拟机(Virtual Machine,VM)可以直接通信。也就是说,同一个VNI内的两个VM进行通信时不需要经由VXLAN三层网关(VXLAN L3Gateway)。分别位于不同VNI中的两个VM通信需要经由VXLAN三层网关。VNI字段包含24比特。一个管理域最多可以包含216个VXLAN网段。
VXLAN隧道端点(VXLAN Tunnel End Point,VTEP)设备是VXLAN中的边缘设备。VTEP设备通过VXLAN隧道传输VXLAN的流量。VXLAN隧道是指两个VTEP设备之间的点到点逻辑隧道。
为了增加网络的可靠性,VXLAN网络可以采用多活网关。例如,VTEP设备分别通过VXLAN隧道与两台VXLAN三层网关设备通信。两台VXLAN三层网关设备形成一个负载均衡组,将从VTEP设备接收的流量转发到IP网络中(例如三层虚拟专用网(Layer 3 Virtual Private Network,L3VPN))。两台VXLAN三层网关与VTEP设备通信的网关接口配置相同的IP地址和MAC地址,并且两台VXLAN三层网关配置相同的虚拟VTEP IP地址,如此这样,VTEP设备形成了到达VXLAN三层网关的等价路由负荷分担(Equal and Weighted Cost Multi-path,ECMP)。
但是,在实际应用中,多活网关无法提供完善的冗余保护机制,并且由于使用负载均衡模式,对同步和时延的要求较高。
发明内容
有鉴于此,本申请实施例提供了一种VXLAN报文的转发方法、设备及系统,以提高VXLAN网络的冗余保护能力,降低对同步和时延的要求。
本申请实施例提供的技术方案如下。
第一方面,提供了一种VXLAN报文的转发方法,所述方法包括:第一VTEP设 备根据第一VXLAN隧道的优先级设置所述第一VXLAN隧道的隧道状态为激活Active状态,所述第一VXLAN隧道为所述第一VTEP设备与第二VTEP设备之间的VXLAN隧道。并且,所述第一VTEP设备根据第二VXLAN隧道的优先级设置所述第二VXLAN隧道的隧道状态为非激活Inactive状态,所述第二VXLAN隧道为所述第一VTEP设备与第三VTEP设备之间的VXLAN隧道,所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级,所述第二VTEP设备的IP地址与所述第三VTEP设备的IP地址不相同。然后,所述第一VTEP设备经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Active状态的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态。并且,所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Inactive状态的第二状态信息,所述第二状态信息用于指示所述第二VXLAN隧道的隧道状态。最后,所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
基于实施例提供的方案,第一VTEP设备通过与作为VXLAN网关的第二VTEP设备和第三VTEP设备协商隧道状态,从而使得Active状态的VXLAN隧道处于工作状态,执行对流量的转发,Inactive状态的VXLAN隧道处于非工作状态,不对流量的进行转发。通过实施例提供的方案,以提高VXLAN网络的冗余保护能力。
可选的,在所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之前,所述方法还包括:所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备将所述第一VXLAN隧道的隧道状态确认为Active状态;所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第二状态信息的第二应答信息,所述第二应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态确认为Inactive状态。
通过上述实施方式,有效提高了转发执行过程的可靠性,避免设置过程与流量转发过程不同步造成的丢包。
可选的,在所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之后,所述方法还包括:当所述第一VTEP设备确定所述第一VXLAN隧道存在故障时,所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及所述第一VTEP设备设置所述第二VXLAN隧道的隧道状态为Active状态;所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;所述第一VTEP设备经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
可选的,在所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之后,所述方法还包括:所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的链路故障消息,所述链路故障消息用 于指示所述第二VTEP设备与IP网络之间的链路存在故障,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量;所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及所述第一VTEP设备设置所述第二VXLAN隧道的隧道状态为Active状态;所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;所述第一VTEP设备经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
可选的,所述第一VTEP设备接收来自主机的地址解析协议(Address Resolution Protocol,ARP)请求报文,所述ARP请求报文用于请求VXLAN网关的媒体接入控制MAC地址;所述第一VTEP设备分别经由所述第一VXLAN隧道和所述第二VXLAN隧道向所述第二VTEP设备和所述第三VTEP设备发送所述ARP请求报文,以便所述第二VTEP设备和所述第三VTEP设备根据所述ARP请求报文生成ARP表项。
通过上述实施方式,实现VXLAN三层网关之间的ARP表项和MAC表项的同步,无需VXLAN三层网关之间建立表项备份链路。
可选的,所述第一VTEP设备根据所述ARP请求报文生成所述ARP表项;所述第一VTEP设备存储所述ARP表项;当所述第一VTEP设备确定故障VXLAN隧道的故障恢复时,根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述故障恢复的VXLAN隧道向目的VTEP设备发送所述ARP请求报文;或者,当所述第一VTEP设备确定存在有新建立的VXLAN隧道时,根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述新建立的VXLAN隧道向目的VTEP设备发送所述ARP请求报文。
通过上述实施方式,实现当故障恢复或新建VXLAN隧道时,无需重新交互ARP报文。
第二方面,提供了一种VXLAN报文的转发方法,所述方法包括:第二VTEP设备经由第一VXLAN隧道接收来自第一VTEP设备的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态。当所述第一状态信息携带的隧道状态为Active状态时,所述第二VTEP设备将所述第一VXLAN隧道确认为Active状态,并且将IP网络到达所述第二VTEP设备的路由优先级设置为第一优先级,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量,所述第一优先级大于第二优先级,所述第二优先级为所述第一VXLAN隧道是Inactive状态时,所述IP网络到达所述第二VTEP设备的路由优先级。然后,所述第二VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
通过上述实施方式,提高了VXLAN网络的冗余保护能力,并且确保上行流量方向和下行流量方向的一致。
可选的,所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备 发送所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备确认的所述第一VXLAN隧道的隧道状态。
可选的,当所述第二VTEP设备确定隧道状态为激活Active状态的所述第一VXLAN隧道存在故障时,所述第二VTEP设备将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为所述第二优先级。
可选的,当所述第二VTEP设备确定所述第二VTEP设备与所述IP网络之间的链路存在故障时,生成链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与所述IP网络之间的链路存在故障;所述第二VTEP设备经由隧道状态为激活Active状态的所述第一VXLAN隧道向所述第一VTEP设备发送所述链路故障消息;所述第二VTEP设备经由所述第一VXLAN隧道接收来自所述第一VTEP设备的第二状态信息,所述第二状态信息携带Inactive状态,用于指示所述第一VXLAN隧道的隧道状态;所述第二VTEP设备根据所述第二状态信息将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。
第三方面,提供了第一VTEP设备,所述第一VTEP设备具有实现上述方法中第一VTEP设备行为的功能。所述功能可以基于硬件实现,也可以基于硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。
在一个可能的设计中,第一VTEP设备的结构中包括处理器和接口,所述处理器被配置为支持第一VTEP设备执行上述方法中相应的功能。所述接口用于支持第一VTEP设备与第二VTEP设备之间的通信,向第二VTEP设备发送上述方法中所涉及的信息或者指令,或者从第二VTEP设备接收上述方法中所涉及的信息或者指令。所述第一VTEP设备还可以包括存储器,所述存储器用于与处理器耦合,其保存第一VTEP设备必要的程序指令和数据。
第四方面,提供了第二VTEP设备,所述第二VTEP设备具有实现上述方法中第二VTEP设备行为的功能。所述功能可以基于硬件实现,也可以基于硬件执行相应的软件实现。所述硬件或软件包括一个或多个与上述功能相对应的模块。
在一个可能的设计中,第二VTEP设备的结构中包括处理器和接口,所述处理器被配置为支持第二VTEP设备执行上述方法中相应的功能。所述接口用于支持第二VTEP设备与第一VTEP设备之间的通信,向第一VTEP设备发送上述方法中所涉及的信息或者指令,或者从第一VTEP设备接收上述方法中所涉及的信息或者指令。所述第二VTEP设备还可以包括存储器,所述存储器用于与处理器耦合,其保存第二VTEP设备必要的程序指令和数据。
第五方面,提供了一种计算机存储介质,用于储存为上述第一VTEP设备所用的程序、代码或指令,当处理器或硬件设备执行这些程序、代码或指令时可以完成上述方面中第一VTEP设备的功能或步骤。
第六方面,提供了一种计算机存储介质,用于储存为上述第二VTEP设备所用的程序、代码或指令,当处理器或硬件设备执行这些程序、代码或指令时可以完成上述方面中第二VTEP设备的功能或步骤。
附图说明
图1为本申请实施例的一种VXLAN网络结构示意图;
图2为本申请实施例的一种VXLAN报文转发方法的流程图;
图3为本申请实施例的另一种VXLAN报文转发方法的流程图;
图4为本申请实施例的又一种VXLAN报文转发方法的流程图;
图5为本申请实施例的另一种VXLAN网络结构示意图;
图6为本申请实施例的又一种VXLAN网络结构示意图;
图7为本申请实施例的又一种VXLAN网络结构示意图;
图8为本发明实施例的第一VTEP设备的结构示意图;
图9为本发明实施例的第一VTEP设备的硬件结构示意图;
图10为本发明实施例的第二VTEP设备的结构示意图;
图11为本发明实施例的第二VTEP设备的硬件结构示意图。
具体实施方式
本申请实施例提供了一种VXLAN报文的转发方法、设备及系统,以提高VXLAN网络的冗余保护能力,确保上行流量方向和下行流量方向的一致。
下面通过具体实施例,分别进行详细的说明。
为使得本申请的发明目的、特征、优点能更加的明显和易懂,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚地描述,显然下面所描述的实施例仅仅是本申请一部分实施例,而非全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动的前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书及附图中的术语“第一”、“第二”、“第三”和“第四”等是用于区别不同对象,而不是用于描述特定顺序。此外,术语“包括”和“具有”不是排他的。例如包括了一系列步骤或单元的过程、方法、系统、产品或设备没有限定于已列出的步骤或单元,还可以包括没有列出的步骤或单元。
图1为本申请实施例的一种VXLAN网络结构示意图。如图1所示,该VXLAN网络包括第一VTEP设备、第二VTEP设备和第三VTEP设备。所述第一VTEP设备经由第一VXLAN隧道与所述第二VTEP设备通信,所述第一VTEP设备经由第二VXLAN隧道与所述第三VTEP设备通信。而且,所述第一VTEP设备还连接有第一主机,以便所述第一VTEP设备能够从所述第一主机接收流量,并通过所述第一VXLAN隧道向所述第二VTEP设备转发,或者通过所述第二VXLAN隧道向所述第三VTEP设备转发。类似的方式,所述第一VTEP设备可以经由所述第一VXLAN隧道接收来自所述第二VTEP设备的流量,并将该流量下发给所述第一主机;或者,所述第一VTEP设备可以经由所述第二VXLAN隧道接收来自所述第三VTEP设备的流量,并将该流量下发给所述第一主机。其中,所述第一主机可以是VM。并且本申请对VM的数量不进行限定,所述第一VTEP设备可以连接多台VM。VM可以运行在服务器中。一台服务器可以包含至少一台VM。在一种可能的实现方式中,一台服务器可以包括多个VM。不同的VM可以属于不同的VXLAN网段。在VXLAN的应用场景中,VTEP设备也可以称为网络虚拟边缘(Network Virtualization Edge,NVE)设 备。在一些应用场景中,VTEP设备被理解为集成在NVE设备中的模块。本申请中,在不进行特殊说明的情况下,VTEP设备等同于NVE设备。
在图1所示的网络中,所述第二VTEP设备经由通信链路与IP网络通信,以便将来自所述第一主机的流量向所述IP网络转发,或者,接收来自所述IP网络的流量向所述第一主机转发。类似的,所述第三VTEP设备经由通信链路与IP网络通信,以便将来自所述第一主机的流量向所述IP网络转发,或者,接收来自所述IP网络的流量向所述第一主机转发。在实际的场景中,所述IP网络还可以连接第二主机,以便完成所述第一主机经由上述描述的网络结构向所述第二主机的流量传输,或者,按成所述第二主机经由上述描述的网络结构向所述第一主机的流量传输。其中,本申请对IP网络的具体实现方式不进行限定,例如,IP网络可以表现为Internet网络或L3VPN网络。所述第二主机可以是服务器。
所述第一VTEP设备从第一主机接收流量后,将所述流量封装成VXLAN报文,以便经由所述第一VXLAN隧道和所述第二VXLAN隧道分别向所述第二VTEP设备或所述第三VTEP设备转发。所述第二VTEP设备或所述第三VTEP设备再将接收到的VXLAN报文进行解封装,并重新封装成IP报文,发送到IP网络,以便流量到达所述第二主机。类似的,IP网络从所述第二主机接收到流量后,将所述流量封装成IP报文,发送到所述第二VTEP设备或所述第三VTEP设备。所述第二VTEP设备或所述第三VTEP设备再将接收到的IP报文进行解封装,并重新封装成VXLAN报文,发送到所述第一VTEP设备,以便流量到达所述第一主机。
为了方便描述,本申请的后续实施例中,将所述第一主机经由所述第一VTEP设备、第二VTEP设备、第三VTEP设备和IP网络,到达所述第二主机的流量方向称为上行流量方向;将所述第二主机经由所述第一VTEP设备、第二VTEP设备、第三VTEP设备和IP网络,到达所述第一主机的流量方向称为下行流量方向。其中,所述第二VTEP设备和所述第三VTEP均充当VXLAN三层网关,以便完成VXLAN网络和IP网络之间的传输。为了方便描述,本申请的后续实施例中,将所述第一主机、第一VTEP设备、第二VTEP设备和第三VTEP设备组成的网络称为VXLAN网络侧;将所述第二主机、IP网络、第二VTEP设备和第三VTEP设备组成的网络称为IP网络侧。进一步,在VXLAN网络侧中,将所述第一主机与所述第一VTEP设备组成的网络结构称为VXLAN网络侧的接入链路(Access Circuit,AC);同样的,在IP网络侧中,将所述第二主机与所述IP网络组成的网络结构称为IP网络侧的AC。因此,设置在所述第一VTEP设备上的,用于连接所述第一主机的接口称为VXLAN网络的AC侧接口;设置在所述第一VTEP设备上的,用于连接VXLAN隧道的接口称为VXLAN隧道接口。
在多活网关的场景中,所述第二VTEP设备和所述第三VTEP设备组成了一个负载均衡组。所述第二VTEP设备和所述第三VTEP设备充当VXLAN三层网关。两台VXLAN三层网关与所述第一VTEP设备通信的网关接口配置相同的IP地址和MAC地址,并且两台VXLAN三层网关配置相同的虚拟VTEP IP地址。例如上行流量方向,所述第一VTEP设备接收到所述第一主机的流量后,通过哈希(Hash)算法将流量均衡到所述第一VXLAN隧道和所述第二VXLAN隧道,以便将流量转发到所述第二 VTEP设备和所述第三VTEP设备。因此,多活网关的场景对同步和时延要求较高。而且,当某条VXLAN隧道或某个网关,例如第一VXLAN隧道或第二VTEP设备,出现故障时,可以基于路由收敛(Route Convergence)的原则,使得流量绕行故障的VXLAN隧道或网关,从而流量不在经由第一VXLAN隧道传送,而是切换到第二隧道传送。如果故障出现在IP网络侧,例如所述第二VTEP设备与IP网络之间的链路出现故障。由于多活网关基于ECMP方式,所述第一VTEP设备依然学习两个VXLAN三层网关的路由,因此,VXLAN网络侧的负载均衡模式不会被改变。因此,多活网关场景中,无法提供完善的冗余保护机制。
进一步,在多活网关场景中,由于采用ECMP方式,因此,无法确保上行流量方向和下行流量方向的一致。例如,对于上行流量方向,来自所述第一主机的流量经由所述第一VXLAN隧道到达所述第二VTEP设备,最终到达所述第二主机。但是,对于下行流量方向,所述第二主机发往所述第一主机的流量可能经由所述第三VTEP设备和第二VXLAN隧道到达所述第一主机。这不利于防火墙对流量进行检测。
本申请实施例提供了一种VXLAN报文的转发方法、设备及系统,以提高VXLAN网络的冗余保护能力。进一步,通过对IP网络到达VXLAN三层网关的路由优先级的设置,确保上行流量方向和下行流量方向的一致。
在本申请的实施例中,没有特殊说明的情况下,IP可以是第四版因特网协议(Internet Protocol version 4,IPv4),也可以是第六版因特网协议(Internet Protocol version 6,IPv6),还可以未来出现的IP。
图2-图4为本申请实施例的VXLAN报文转发方法的流程图。为了清楚的描述本申请实施例的VXLAN报文转发方法,本实施例将结合图1,图5-图7所示VXLAN网络结构示意图进行说明。应当理解,图1-图7所示的实现方式仅为本申请提供的技术方案的部分实施方式,不是全部实施方式。本申请实施例中,如图1,图5-图7所示,均以两条VXLAN隧道(即第一VXLAN隧道和第二VXLAN隧道)及对应的两台VTEP设备(即第二VTEP设备和第三VTEP设备)为例进行说明。应当理解,本申请实施例可以包括多于两条的VXLAN隧道及对应的VTEP设备。例如,图1,图5-图7所示的场景中,还包括第三VXLAN隧道及对应的第四VTEP设备,所述第三VXLAN隧道为所述第一VTEP设备与第四VTEP设备之间的VXLAN隧道。在包括多于两条的VXLAN隧道的场景中,所述多于两条的VXLAN隧道中的一条作为主VXLAN隧道,其他VXLAN隧道作为备VXLAN隧道。例如,在包括3条VXLAN隧道的场景中,将第一VXLAN隧道作为主VXLAN隧道,将第一VXLAN隧道和第三VXLAN隧道作为备隧道。
在本申请实施例中,VXLAN隧道的隧道状态包括激活(Active)状态和非激活(Inactive)两种状态。状态信息用于指示VXLAN隧道的隧道状态,当状态信息携带Active状态时指示VXLAN隧道处于激活状态,允许传输数据流量;当状态信息携带Inactive状态时指示VXLAN隧道处于非激活状态,不允许传输数据流量。
图2为本申请实施例的一种VXLAN报文转发方法的流程图。图2所示的方法可以应用在图1所示的网络结构中,具体的,图2所示的方法可以与建立VXLAN隧道的过程共同实施,也可以在建立VXLAN隧道后进行实施。该方法包括:
S101、第一VTEP设备根据第一VXLAN隧道的优先级设置所述第一VXLAN隧道的隧道状态为Active状态。
S102、根据第二VXLAN隧道的优先级设置所述第二VXLAN隧道的隧道状态为Inactive状态,所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级。
结合图1所示的网络结构,所述第一VXLAN隧道为所述第一VTEP设备与第二VTEP设备之间的VXLAN隧道;所述第二VXLAN隧道为所述第一VTEP设备与第三VTEP设备之间的VXLAN隧道。在所述第一VTEP设备中,配置有VXLAN隧道的优先级,具体包括所述第一VXLAN隧道的优先级和所述第二VXLAN隧道的优先级。在一种可能的实现方式中,所述VXLAN隧道的优先级可以由网络管理员在所述第一VTEP设备上静态配置。在另一种可能的实现方式中,所述VXLAN隧道的优先级可以由控制器根据网络拓扑结构自动的配置,然后下发给所述第一VTEP设备。在又一种可能的实现方式中,所述VXLAN隧道的优先级可以由所述第一VTEP设备进行自动的配置。
所述VXLAN隧道的优先级可以设置为两个级别,例如第一优先级和第二优先级,并且所述第一优先级高于第二优先级。配置有高优先级(例如第一优先级)的VXLAN隧道可以被称为主VXLAN隧道,配置有低优先级(例如第二优先级)的VXLAN隧道可以被称为备VXLAN隧道。在图1所示的网络结构中,通过配置所述第一VXLAN隧道和所述第二VXLAN隧道的优先级,以便所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级。因此,所述第一VXLAN隧道是主VXLAN隧道,所述第二VXLAN隧道是备VXLAN隧道。在本申请的本实施例和后续的实施例中,不加特殊说明或限定的情况下,第一VXLAN隧道等同主VXLAN隧道,第二VXLAN隧道等同备VXLAN隧道。在多于两条VXLAN隧道的网络结构中,可以将高优先级(例如第一优先级)配置给其中一条VXLAN隧道,将低优先级(例如第二优先级)配置给其余的VXLAN隧道。例如,该网络结构包括3条VXLAN隧道。VXLAN隧道1配置第一优先级,称为主VXLAN隧道;VXLAN隧道2和VXLAN隧道3分别配置第二优先级,称为备VXLAN隧道。对于多于两条VXLAN隧道的网络结构,另一种可能的实现方式,所述VXLAN隧道的优先级可以设置为多个级别,例如第一优先级、第二优先级和第三优先级。并且,第一优先级高于第二优先级和第三优先级,第二优先级高于第三优先级。如此这样,VXLAN隧道1配置第一优先级,称为主VXLAN隧道;VXLAN隧道2和VXLAN隧道3分别配置第二优先级和第三优先级,称为备VXLAN隧道。
所述VXLAN隧道的优先级可以使用隧道优先级信息或隧道目的VTEP设备的IP地址标识。例如,结合图1,在静态配置VXLAN隧道的优先级的实现方式中,网络管理员在所述第一VTEP设备上,将所述第一VXLAN隧道的隧道优先级信息配置为10,将所述第二VXLAN隧道的隧道优先级信息配置为5,以便所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级。又例如,结合图1,在所述第一VTEP设备自动配置VXLAN隧道的优先级的实现方式中,所述第一VTEP设备通过比较所述第二VTEP设备的IP地址的值与所述第三VTEP设备的IP地址的值,从而确定所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级。
所述第一VTEP设备还根据VXLAN隧道的优先级设置VXLAN隧道的隧道状态,所述隧道状态包括激活Active状态和非激活Inactive状态。其中,所述Active状态用于指示允许VXLAN隧道两端的VTEP设备经由所述VXLAN隧道转发VXLAN报文。所述Inactive状态用于指示不允许VXLAN隧道两端的VTEP设备经由所述VXLAN隧道转发VXLAN报文。在默认的情况下,所述第一VTEP设备将主VXLAN隧道(高优先级的VXLAN隧道)的隧道状态设置为Active状态,将备VXLAN隧道(低优先级的VXLAN隧道)的隧道状态设置为Inactive状态。因此,在图1所示的网络结构中,所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Active状态,设置所述第二VXLAN隧道的隧道状态为Inactive状态。
结合前述实施例,所述第二VTEP设备和所述第三VTEP设备均充当VXLAN三层网关,以便完成VXLAN网络和IP网络之间的传输。在本申请中,第二VTEP设备的IP地址与所述第三VTEP设备的IP地址不相同,以确保流量能够经由Active状态的VXLAN隧道传输,而不会流入Inactive状态的VXLAN隧道。例如,第二VTEP设备的IP地址为2.2.2.2,第三VTEP设备的IP地址为3.3.3.3。进一步,将所述第二VTEP设备与所述第一VTEP设备通信的网关接口的IP地址和MAC地址和所述第三VTEP设备与所述第一VTEP设备通信的网关接口的IP地址和MAC地址配置为相同,该网关接口称为桥域接口(Bridge Domain Interface,BDIF)。所述BDIF是基于桥域(Bridge Domain,BD)创建的三层逻辑接口,用以实现不同子网VM之间或VXLAN网络与非VXLAN网络之间的通信。例如,在所述第二VTEP设备和所述第三VTEP设备上均设置有BDIF_10,所述BDIF_10的IP地址为IP_10,所述BDIF_10的MAC地址为MAC_10。在所述第二VTEP设备和所述第三VTEP设备上可以设置多个BDIF,以便通过BDIF区分不同的VXLAN网段。例如,在所述第二VTEP设备和所述第三VTEP设备上,除去设置有BDIF_10之外,还设置有BDIF_20,所述BDIF_20的IP地址为IP_20,所述BDIF_20的MAC地址为MAC_20。如此这样,BDIF_10对应VXLAN网段1,从而所述第二VTEP设备和所述第三VTEP设备用于转发来自属于VXLAN网段1的VM的上行流量,或者向属于VXLAN网段1的VM发送下行流量;BDIF_20对应VXLAN网段2,从而所述第二VTEP设备和所述第三VTEP设备用于转发来自属于VXLAN网段2的VM的上行流量,或者向属于VXLAN网段2的VM发送下行流量。相应的,VXLAN网段1通过VNI_10进行标识,VXLAN网段2通过VNI_20进行标识,以便区别不同的VXLAN网段。
接下来,S103-S105描述所述第一VTEP设备与所述第二VTEP设备配置所述第一VXLAN隧道的隧道状态的过程;类似的,S106-S108描述所述第一VTEP设备与所述第三VTEP设备配置所述第二VXLAN隧道的隧道状态的过程。应当理解,S103-S105描述的过程与S106-S108描述的过程并没有严格的执行先后顺序,两个过程可以互不影响的并行执行。
S103、所述第一VTEP设备经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Active状态的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态。
S104、所述第二VTEP设备经由第一VXLAN隧道接收来自所述第一VTEP设备 的第一状态信息。
所述第一VTEP设备将所述第一VXLAN隧道的隧道状态设置为Active状态,可以将Active状态携带在所述第一状态信息中,经由所述第一VXLAN隧道向所述第二VTEP设备发送。相应的,所述第二VTEP设备接收所述第一状态信息。其中,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态。
本申请对于第一状态信息的具体实现方式不进行限定。在一种可能的实现方式中,所述Active状态在所述第一VXLAN隧道的建立过程中发送。具体的,在VXLAN网络中,VXLAN隧道可以基于边界网关协议以太网虚拟私有网络(Border Gateway Protocol Ethernet Virtual Private Network,BGP EVPN)建立。所述BGP EVPN用于实现VXLAN的控制平面。根据BGP EVPN的实现方式,当所述第一VTEP设备与所述第二VTEP设备之间,以及所述第一VTEP设备与所述第三VTEP设备之间建立边界网关协议(Border Gateway Protocol,BGP)连接关系后,所述第一VTEP设备与所述第二VTEP设备之间,以及所述第一VTEP设备与所述第三VTEP设备之间传递集成多播路由(Inclusive Multicast Route),所述集成多播路由用于生成广播,未知单播和组播(Broadcast,Unknown Unicast,and Multicast,BUM)转发表,并用于自动建立传送VXLAN报文的VXLAN隧道。因此,在该实现方式中,所述第一VTEP设备在向所述第二VTEP设备发送集成多播路由时,在所述集成多播路由中增加一个类型长度值(type-length-value,TLV),从而形成所述第一状态信息。所述TLV的类型为Tunnel_Status,长度为1字节,值标识为Active。从而,在所述第一VXLAN隧道的建立过程中,完成所述第一状态信息的传送。
在另一种可能的实现方式中,所述Active状态在所述第一VXLAN隧道的建立后发送。具体的,BGP EVPN包括通知(Notification)消息,所述Notification消息用于本端VTEP设备检测到错误时向对端VTEP设备发送的通知消息。本申请中,复用所述Notification消息,以便携带VXLAN隧道的隧道状态。从而使Notification消息不用于通知错误消息,而是用于通知VXLAN隧道的隧道状态。因此,所述第一状态信息可以是Notification消息。例如,所述第一VTEP设备向所述第二VTEP设备发送Notification消息,所述Notification消息携带Active状态。
在又一种可能的实现方式中,所述Active状态在所述第一VXLAN隧道的建立后发送。具体的,VXLAN隧道的隧道状态携带在PPP over VXLAN报文中。因此,所述第一状态信息可以是PPP over VXLAN报文。其中,所述PPP over VXLAN报文包括VXLAN头和VXLAN载荷,所述VXLAN载荷包括点对点协议(Point-to-Point Protocol,PPP)报文,所述PPP报文包括PPP头和PPP载荷,所述PPP载荷包括所述VXLAN隧道的隧道状态。例如,所述第一VTEP设备向所述第二VTEP设备发送PPP over VXLAN报文,所述PPP over VXLAN报文携带Active状态。所述第二VTEP设备接收到PPP over VXLAN报文,对所述PPP over VXLAN报文进行解封装,获取Active状态。
S105、所述第二VTEP设备将所述第一VXLAN隧道确认为Active状态,并且将IP网络到达所述第二VTEP设备的路由优先级设置为第一优先级。
所述第二VTEP设备在接收到所述第一状态信息后,根据所述第一状态信息携带 的Active状态,将所述第一VXLAN隧道确认为Active状态。所述第二VTEP设备可以经由所述第一VXLAN隧道接收来自第一主机的上行流量,并将该上行流量向IP网络转发。所述第二VTEP设备也可以从IP网络接收下行流量,并将该下行流量经由所述第一VXLAN隧道向所述第一主机转发。
如图1所示,在下行流量方向,从第二主机发出的流量经过IP网络可以到达所述第二VTEP设备,也可以到达所述第三VTEP设备。为了确保上行流量和下行流量都能经由Active状态的所述第一VXLAN隧道传输,所述第二VTEP设备将IP网络到达所述第二VTEP设备的路由优先级设置为第一优先级,并向IP网络通告所述第一优先级。具体的,IP网络包括路由器,所述第二VTEP设备向IP网络中的路由器通告所述第一优先级。其中,所述第一优先级高于所述IP网络到达所述第三VTEP设备的路由优先级。IP网络在接收到来自所述第二主机的流量后,根据所述第一优先级优先选择IP网络到达所述第二VTEP设备的路径转发来自所述第二主机的流量。从而,来自所述第二主机的流量被引流到所述第二VTEP设备。所述第二VTEP设备可以经由Active状态的所述第一VXLAN隧道转发来自所述第二主机的流量。因此,实施例提供的实现方式,能够保证上行流量和下行流量都能经由Active状态的所述第一VXLAN隧道传输。
S106、所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Inactive状态的第二状态信息,所述第二状态信息用于指示所述第二VXLAN隧道的隧道状态。
S107、经由第二VXLAN隧道接收来自所述第一VTEP设备的第二状态信息。
所述第一VTEP设备将所述第二VXLAN隧道的隧道状态设置为Inactive状态,可以将Inactive状态携带在所述第二状态信息中,经由所述第二VXLAN隧道向所述第三VTEP设备发送。相应的,所述第三VTEP设备接收所述第二状态信息。其中,所述第二状态信息用于指示所述第二VXLAN隧道的隧道状态。
所述第二状态信息的具体实现方式可以参见上述针对S103和S104的相应解释,此处不进行赘述。其中,在采用集成多播路由的实现方式中,所述TLV的类型为Tunnel_Status,长度为1字节,值标识为Inactive。在采用Notification消息的实现方式中,所述Notification消息携带Inactive状态。在采用PPP over VXLAN报文的实现方式中,所述PPP over VXLAN报文携带Inactive状态。
S108、所述第三VTEP设备将所述第二VXLAN隧道确认为Inactive状态,并且将所述IP网络到达所述第三VTEP设备的路由优先级设置为第二优先级,所述第一优先级高于所述第二优先级。
所述第三VTEP设备在接收到所述第二状态信息,根据所述第二状态信息携带的Inactive状态,将所述第二VXLAN隧道确认为Inactive状态。Inactive状态的所述第二VXLAN隧道为阻塞(非工作)状态,不对上行流量和下行流量进行转发。
结合上述S105的解释,所述第三VTEP设备将所述IP网络到达所述第三VTEP设备的路由优先级设置为第二优先级,所述第一优先级高于所述第二优先级。其中所述第一优先级是IP网络到达所述第二VTEP设备的路由优先级。IP网络在接收到来自所述第二主机的流量后,根据所述第一优先级优先选择IP网络到达所述第二VTEP设 备的路径转发来自所述第二主机的流量。从而,来自所述第二主机的流量被引流到所述第二VTEP设备,不会到达所述第三VTEP设备。从而防止来自所述第二主机的流量流入所述第二VXLAN隧道。
S113、所述第一VTEP设备和所述第二VTEP设备经由所述第一VXLAN隧道转发VXLAN报文。
在完成将所述第一VXLAN隧道设置为Active状态和将第二VXLAN隧道设置为Inactive状态的过程后,所述第一VTEP设备和所述第二VTEP设备经由Active状态第一VXLAN隧道转发上行流量和下行流量,而Inactive状态的所述第二VXLAN隧道处于阻塞(非工作)状态,不转发流量。
本实施例提供的VXLAN报文转发方法,通过本端VTEP设备根据VXLAN隧道的优先级设置与所述本端VTEP设备连接的至少两条VXLAN隧道的隧道状态。然后,将VXLAN隧道的隧道状态发送给至少两台对端VTEP设备,所述至少两条VXLAN隧道与所述至少两台对端VTEP设备一一对应。所述至少两台对端VTEP设备分别对接收到的VXLAN隧道的隧道状态进行确认。从而,Active状态的VXLAN隧道处于工作状态,执行对流量的转发,Inactive状态的VXLAN隧道处于非工作状态,不对流量的进行转发。通过实施例提供的方法,以提高VXLAN网络的冗余保护能力。进一步,所述Active状态的VXLAN隧道连接的对端VTEP设备将IP网络到达该对端VTEP设备的路由优先级设置为第一优先级;所述Inactive状态的VXLAN隧道连接的对端VTEP设备将IP网络到达该对端VTEP设备的路由优先级设置为第二优先级,并且使得所述第一优先级高于所述第二优先级,从而确保上行流量方向和下行流量方向的一致。
可选的,在S105和S113之间,所述VXLAN报文转发方法还包括:
S109、所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第一状态信息的第一应答信息。
S110、所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第一状态信息的第一应答信息。
所述第二VTEP设备根据所述第一状态信息将所述第一VXLAN隧道的隧道状态确认为Active状态,并且将IP网络到达所述第二VTEP设备的路由优先级设置为第一优先级,然后,根据所述第一状态信息生成第一应答信息。所述第一应答信息用于指示所述第二VTEP设备将所述第一VXLAN隧道的隧道状态确认为Active状态。所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第一应答信息。所述第一VTEP设备根据接收到的所述第一应答信息,确定所述第二VTEP已经对所述第一状态信息进行了处理。
所述第一回应信息的实现方式可以采用S103和S104中所述第一状态信息的实现方式,此处不进行赘述。
通过上述实现方式,所述第一VTEP设备在确定所述第二VTEP设备接收并处理所述第一状态信息的情况下,触发流量的转发,有效提高了转发执行过程的可靠性,避免设置过程与流量转发过程不同步造成的丢包。
可选的,在S108和S113之间,所述VXLAN报文转发方法还包括:
S111、所述第三VTEP设备经由所述第二VXLAN隧道向所述第一VTEP设备发送所述第二状态信息的第二应答信息。
S112、所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第二状态信息的第二应答信息。
类似上述S109和S110,所述第三VTEP设备处理所述第二状态信息后,向所述第一VTEP设备发送第二应答信息。所述第二应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态确认为Inactive状态。所述第一VTEP设备根据接收到的所述第二应答信息,确定所述第三VTEP已经对所述第二状态信息进行了处理。
所述第二回应信息的实现方式可以采用S103和S104中所述第一状态信息的实现方式,此处不进行赘述。
应当理解,S109和S110描述的过程与S111和S112描述的过程并没有严格的执行先后顺序,两个过程可以互不影响的并行执行。
图3为本申请实施例的另一种VXLAN报文转发方法的流程图。图3示出的方法是基于上述图2所示的方法基础上,当处于Active状态VXLAN隧道存在故障时,VXLAN报文转发方法的实现方式。例如,图3所示的方法可以应用于图5示出的网络结构。如图5所示,第一VXLAN隧道存在故障。该方法包括:
S201、第一VTEP设备确定第一VXLAN隧道存在故障。
基于图2所示的方法,在正常的运行情况下,Active状态的第一VXLAN隧道处于工作状态,执行对流量的转发,Inactive状态的第二VXLAN隧道处于非工作状态,不对流量的进行转发。所述第一VTEP设备可以经由所述第一VXLAN隧道向第二VTEP设备发送第一故障检测报文,并且所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第一故障检测报文的第一回应报文。当所述第一VTEP设备无法接收到第一回应报文时,所述第一VTEP设备确定所述第一VXLAN隧道存在故障。为了确保检测可靠性,所述第一VTEP设备向所述第二VTEP设备周期性的发送所述第一故障检测报文。本申请对所述第一故障检测报文的具体实现方式不进行限定。在一种可能的实现方式中,所述第一故障检测报文是双向转发故障检测(Bidirectional Forwarding Detection,BFD)报文。在另一种可能的实现方式中,所述第一故障检测报文是以太网操作、管理、维护(Ethernet operation,administration and maintenance,ETH OAM)报文。在又一种可能的实现方式中,所述第一故障检测报文是基于BGP EVPN的Keepalive消息。
S202、所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及设置所述第二VXLAN隧道的隧道状态为Active状态。
所述第一VTEP设备确定处于Active状态的第一VXLAN隧道存在故障后,触发切换VXLAN隧道的动作。具体的,所述第一VTEP设备将处于Active状态的第一VXLAN隧道切换为Inactive状态,以及将处于Inactive状态的第二VXLAN隧道切换为Active状态。
S203、所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN 隧道的隧道状态。
S204、所述第三VTEP设备经由第二VXLAN隧道接收来自所述第一VTEP设备的第三状态信息。
所述第一VTEP设备将处于Inactive状态的第二VXLAN隧道切换为Active状态后,所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息。所述第三VTEP设备接收所述第三状态信息。其中,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态。
S205、所述第三VTEP设备将所述第二VXLAN隧道确认为Active状态,并且将IP网络到达所述第三VTEP设备的路由优先级设置为第一优先级。
所述第三VTEP设备在接收到所述第三状态信息后,根据所述第三状态信息携带的Active状态,将所述第二VXLAN隧道确认为Active状态,并且将IP网络到达所述第三VTEP设备的路由优先级设置为第一优先级。具体的实现方式参见前述实施例中S105的描述,此处不进行赘述。
S206、所述第三VTEP设备经由所述第二VXLAN隧道向所述第一VTEP设备发送所述第三状态信息的第三应答信息。
S207、所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息。
所述第三VTEP设备在处理所述第三状态信息后,根据所述第三状态信息生成第三应答信息。所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态。所述第三VTEP设备经由所述第二VXLAN隧道向所述第一VTEP设备发送所述第三应答信息。所述第一VTEP设备根据接收到的所述第三应答信息,确定所述第三VTEP已经对所述第三状态信息进行了处理。
S208、所述第一VTEP设备和所述第三VTEP设备经由第二VXLAN隧道转发VXLAN报文。
在完成将所述第二VXLAN隧道的隧道状态切换后,所述第一VTEP设备和所述第三VTEP设备经由Active状态第二VXLAN隧道转发上行流量和下行流量。
所述第一VTEP设备与所述VTEP设备在执行上述S201-S208过程中,所述第二VETP设备执行S209和S210过程。应当理解,S209和S210描述的过程与S201-S208描述的过程并没有严格的执行先后顺序,两个过程可以互不影响的并行执行。
S209、所述第二VTEP设备确定所述第一VXLAN隧道存在故障。
结合前述实施例的S201,在所述第一VTEP设备经由所述第一VXLAN隧道向第二VTEP设备发送第一故障检测报文同时,所述第二VTEP设备经由所述第一VXLAN隧道向第一VTEP设备发送第二故障检测报文。并且所述第二VTEP设备经由所述第一VXLAN隧道接收来自所述第一VTEP设备的所述第二故障检测报文的第二回应报文。当所述第二VTEP设备无法接收到第二回应报文时,所述第二VTEP设备确定所述第一VXLAN隧道存在故障。为了确保检测可靠性,所述第二VTEP设备向所述第一VTEP设备周期性的发送所述第二故障检测报文。所述第二故障检测报文的实现方式参见前述S201的相应描述,此处不进行赘述。
S210、所述第二VTEP设备将所述第一VXLAN隧道的隧道状态切换为Inactive 状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。
所述第二VTEP设备在确定所述第一VXLAN隧道存在故障后,所述第二VTEP设备将处于Active状态的第一VXLAN隧道切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。所述第一优先级高于所述第二优先级。通过将第一优先级切换为第二优先级,确保来自所述第二主机的流量被引流到所述第三VTEP设备,不会到达所述第二VTEP设备。从而防止来自所述第二主机的流量流入所述第一VXLAN隧道。
在S210中,所述第二VTEP设备根据检测所述第一VXLAN隧道的故障情况,主动的将处于Active状态的第一VXLAN隧道切换为Inactive状态,而没有采用从所述第一VTEP设备接收状态信息的方式执行切换。这样有利于避免由于所述第一VXLAN隧道出现的故障导致状态信息无法送达的问题。
通过上述实现方式,当处于Active状态的主VXLAN隧道存在故障时,所述第一VTEP设备和第二VTEP设备将主VXLAN隧道的Active状态切换为Inactive状态,并且所述第一VTEP设备和第三VTEP设备将处于Inactive状态的备VXLAN隧道切换为Active状态,从而有效提高了冗余保护的能力。而且,IP网络到VTEP设备的路由优先级的切换确保了在主备VXLAN隧道切换后,上行流量方向和下行流量方向的一致性。
进一步,当所述第一VTEP设备和所述第二VTEP设备根据故障检测报文检测到主VXLAN隧道的故障恢复后,所述第一VTEP设备、所述第二VTEP设备和所述第三VTEP设备可以结合图2和图3所提供的实现方式,重新将所述第一VXLAN隧道的隧道状态由Inactive状态切换为Active状态,将所述第二VXLAN隧道的隧道状态由Active状态切换为Inactive状态,并且切换IP网络到所述第二VTEP设备的路由优先级和IP网络到所述第三VTEP设备的路由优先级。
所述第一VXLAN隧道存在的故障可能是完全的物理断路,也可能是数据平面的通信故障。当所述第一VXLAN隧道存在的故障属于数据平面的通信故障,可能不会影响控制平面的通信,也就是说,在数据平面不通的情况下,控制平面可能进行正常的通信。
可选的,在S208之前,图3所示的方法还可以包括:
S211、所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备发送切换确认消息。
在该步骤中,所述第二VTEP设备向所述第一VTEP设备发送切换确认消息。如果第一VXLAN隧道的故障属于数据平面的通信故障,而控制平面能够正常通信的情况下,所述第一VTEP设备将收到所述切换确认消息。因此S211有助于提高隧道状态切换的可靠性。所述切换确认消息的实现方式可以采用前述实施例的Notification消息或PPP over VXLAN报文实现。
可选的,在S208之前,图3所示的方法还可以包括:
S212、所述第一VTEP设备经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Inactive状态的第四状态信息,所述第四状态信息用于指示所述第一VXLAN隧道的隧道状态。
S213、所述第二VTEP设备经由所述第一VXLAN隧道接收来自所述第一VTEP设备的所述第四状态信息。
S214、经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第四状态信息的第四应答信息。
在S212中,所述第一VTEP设备向所述第二VTEP设备通告携带有Inactive状态的第四状态信息。如果第一VXLAN隧道的故障属于数据平面的通信故障,而控制平面能够正常通信的情况下,所述第二VTEP设备将可以收到所述所述第四状态信息。根据前述S209和S210,所述第二VTEP设备确认已经将所述第一VXLAN隧道的隧道状态确认为Inactive状态。所述第二VTEP设备生成所述第四状态信息的第四应答信息,并且将所述第四回应信息发送给所述第一VTEP设备,以便所述第一VTEP设备能够获知所述第二VTEP设备已进进行了隧道状态的切换。因此S212-S214有助于提高隧道状态切换的可靠性。
在S201中,所述第一VTEP设备根据所述第一故障检测报文确定所述第一VXLAN隧道存在故障。但所述第一VTEP设备不能根据所述第一故障检测报文感知故障的原因。
在一种可能的实现方式中,所述故障如图5所示,所述第一VTEP设备和所述第二VTEP设备将按照图3所示的方法实现隧道状态的切换。
在另一种可能的实现方式中,所述故障如图6所示,所述第二VTEP设备存在故障。这种情况下,所述第二VTEP设备将无法完成S209和S210的操作,以及无法完成S211、S213和S214的可选操作。所述第一VTEP设备和所述第三VTEP设备可以依据图3所示的方法完成第二VXLAN隧道的隧道状态的正常切换。并且,由于所述第一VTEP设备设置了所述第一隧道的隧道状态为Inactive状态,因此,上行流量方向可以经由处于Active状态的第二VXLAN隧道进行转发,不会经由第一VXALN隧道进行转发。对于下行流量方向,由于所述第二VTEP设备故障,根据路由收敛原则,IP网络到所述第二VTEP设备的路由被撤销。IP网络不会将下行流量发送给所述第二VTEP设备,而是发送给所述第三VTEP设备,以便下行流量经过所述第二VXLAN隧道到达所述第一VTEP设备。因此,图3所示的方法即可以适用于图5所示的故障场景,也适用于图6所示的故障场景。
所述第三状态信息、所述第三应答信息、所述第四状态信息和所述第四应答信息的实现方式可以采用前述实施例的Notification消息或PPP over VXLAN报文实现。
图4为本申请实施例的又一种VXLAN报文转发方法的流程图。图4示出的方法是基于上述图2所示的方法基础上,当第二VTEP设备与IP网络之间的链路存在故障时,VXLAN报文转发方法的实现方式。例如,图4所示的方法可以应用于图7示出的网络结构。如图7所示,第二VTEP设备与IP网络之间的链路存在故障。该方法包括:
S301、当第二VTEP设备确定所述第二VTEP设备与所述IP网络之间的链路存在故障时,所述第二VTEP设备生成链路故障消息。
所述第二VTEP设备确定可以通过向所述IP网络发送故障检测报文的方式确定所述第二VTEP设备与所述IP网络之间的链路是否存在故障。具体的,所述故障检测报 文的实现方式可以参见前述实施例中S201步骤的描述,此处不进行赘述。所述第二VTEP设备在确定所述第二VTEP设备与所述IP网络之间的链路存在故障时,生成链路故障消息。所述链路故障消息的实现方式可以采用前述实施例的Notification消息或PPP over VXLAN报文实现。
S302、所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备发送所述链路故障消息。
S303、所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第一VTEP设备的所述链路故障消息。
所述第二VTEP设备生成所述链路故障消息后,向所述第一VTEP设备发送所述链路故障消息,所述第一VTEP设备接收所述链路故障消息。
S304、所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及设置所述第二VXLAN隧道的隧道状态为Active状态。
所述第一VTEP设备根据所述链路故障消息确定所述第二VTEP设备与所述IP网络之间的链路存在故障,触发切换VXLAN隧道的动作。具体的,所述第一VTEP设备将处于Active状态的第一VXLAN隧道切换为Inactive状态,以及将处于Inactive状态的第二VXLAN隧道切换为Active状态。
S305、所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,并且经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Inactive状态的第四状态信息。其中,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;所述第四状态信息用于指示所述第一VXLAN隧道的隧道状态。
所述第一VTEP设备生成携带有Active状态的第三状态信息,将所述第三状态信息发送给所述第三VTEP设备;以及,所述第一VTEP设备生成携带有Inactive状态的第四状态信息,将所述第四状态信息发送给所述第二VTEP设备。
S306、所述第三VTEP设备经由第二VXLAN隧道接收来自所述第一VTEP设备的第三状态信息。
S307、所述第三VTEP设备将所述第二VXLAN隧道确认为Active状态,并且将IP网络到达所述第三VTEP设备的路由优先级设置为第一优先级。
S308、所述第三VTEP设备经由所述第二VXLAN隧道向所述第一VTEP设备发送所述第三状态信息的第三应答信息。
S309、所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息。
S310、所述第一VTEP设备与所述第三VTEP设备经由第二VXLAN隧道转发VXLAN报文。
S306-S310的具体实现方式参见前述实施例中S204-S208的对应描述,此处不进行赘述。
S306-S309描述所述第一VTEP设备与所述第三VTEP设备配置所述第二VXLAN隧道的隧道状态的过程;类似的,S311-S314描述所述第一VTEP设备与所述第二VTEP设备配置所述第一VXLAN隧道的隧道状态的过程。应当理解,S306-S309描述的过 程与S311-S314描述的过程并没有严格的执行先后顺序,两个过程可以互不影响的并行执行。
在S310之前,所述方法还包括:
S311、所述第二VTEP设备经由第一VXLAN隧道接收来自所述第一VTEP设备的第四状态信息。
S312、所述第二VTEP设备将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。
S313、所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第四状态信息的第四应答信息。
S314、所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第四状态信息的第四应答信息。
S311-S314的具体实现方式参见前述实施例中图2和图3的对应描述,此处不进行赘述。
所述第三状态信息、所述第三应答信息、所述第四状态信息和所述第四应答信息的实现方式可以采用前述实施例的Notification消息或PPP over VXLAN报文实现。
通过上述实现方式,当处于Active状态的主VXLAN隧道接收到所述第二VTEP设备与所述IP网络之间的链路存在故障的链路故障消息时,所述第一VTEP设备和第二VTEP设备将主VXLAN隧道的Active状态切换为Inactive状态,并且所述第一VTEP设备和第三VTEP设备将处于Inactive状态的备VXLAN隧道切换为Active状态,从而有效提高了冗余保护的能力。而且,IP网络到VTEP设备的路由优先级的切换确保了在主备VXLAN隧道切换后,上行流量方向和下行流量方向的一致性。
进一步,当所述第一VTEP设备接收到所述第二VTEP设备与所述IP网络之间的链路故障恢复消息后,所述第一VTEP设备、所述第二VTEP设备和所述第三VTEP设备可以结合图2和图4所提供的实现方式,重新将所述第一VXLAN隧道的隧道状态由Inactive状态切换为Active状态,将所述第二VXLAN隧道的隧道状态由Active状态切换为Inactive状态,并且切换IP网络到所述第二VTEP设备的路由优先级和IP网络到所述第三VTEP设备的路由优先级。
在图2-图4所示的方法中,可选的,所述方法还包括:
所述第一VTEP设备接收来自主机的地址解析协议(Address Resolution Protocol,ARP)请求报文,所述ARP请求报文用于请求VXLAN网关的MAC地址。所述第一VTEP设备分别经由所述第一VXLAN隧道和所述第二VXLAN隧道向所述第二VTEP设备和所述第三VTEP设备发送所述ARP请求报文,以便所述第二VTEP设备和所述第三VTEP设备根据所述ARP请求报文生成ARP表项。
为了指导流量的转发,主机需要与VXLAN三层网关交互ARP报文。例如,在图2所示的方法中,第一VXLAN隧道处于Active状态。主机生成ARP请求报文,所述ARP请求报文的源MAC地址是所述主机的MAC地址,源IP地址为所述主机的IP地址;所述ARP请求报文目的IP地址为所述第二VTEP设备的BDIF的IP地址,根据前述实施例,例如BDIF的IP地址是BDIF_10的IP_10。所述ARP请求报文用于请求VXLAN网关的MAC地址。根据前述实例,所述ARP请求报文用于请求所述第二VTEP 设备的MAC地址(例如MAC_10)。所述第一VTEP设备收到所述ARP请求报文后,将所述ARP请求报文封装为VXLAN报文,经由所述第一VXLAN隧道发送给所述第二VTEP设备。所述第二VTEP设备获得所述ARP请求报文后,生成ARP表项,并且根据ARP表项生成MAC表项。另外,所述第二VTEP设备还向主机发送ARP应答报文,所述ARP应答报文中携带所述第二VTEP设备的BDIF的MAC地址,根据前述实施例,例如BDIF的MAC地址是BDIF_10的MAC_10。
按照图2-图4所示的方法,处于Active状态的VXLAN隧道用于传输VXLAN报文,而处于Inactive状态的VXLAN隧道不对VXLAN报文进行传输。在本实施例中,当所述第一VTEP设备接收来自主机的ARP请求报文时,不仅按照上述方法将所述ARP请求报文经由Active状态的第一VXLAN隧道发送到所述第二VTEP设备,而且还将所述ARP请求报文经由Inactive状态的第二VXLAN隧道发送到所述第三VTEP设备。如此这样,所述第三VTEP设备获得所述ARP请求报文后,生成ARP表项,并且根据ARP表项生成MAC表项。另外,所述第三VTEP设备还向主机发送ARP应答报文,所述ARP应答报文中携带所述第三VTEP设备的BDIF的MAC地址。
通过上述实现方式,基于第一VTEP设备双发ARP请求报文的方式,使得处于Active状态的第一VXLAN隧道传输ARP请求报文,从而第二VTEP设备能够学习ARP表项和MAC表项;并且使得处于Inactive状态的第二VXLAN隧道也传输ARP请求报文,从而所述第三VTEP设备也能够学习ARP表项和MAC表项。从而,实现VXLAN三层网关之间的ARP表项和MAC表项的同步,无需VXLAN三层网关之间建立表项备份链路。
应当理解,在实际的应用场景中,本申请的VXLAN报文的转发方法可以使用现有的,通过VXLAN三层网关之间建立表项备份链路的方式实现VXLAN三层网关之间的ARP表项和MAC表项的同步。为了达到更优的有益效果,本申请的VXLAN报文的转发方法也可以使用上述较佳的实施方式,实现VXLAN三层网关之间的ARP表项和MAC表项的同步。
进一步可选的,所述方法还包括:
所述第一VTEP设备根据所述ARP请求报文生成ARP表项。所述第一VTEP设备存储所述ARP表项。当所述第一VTEP设备确定故障VXLAN隧道的故障恢复时,根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述故障VXLAN隧道向目的VTEP设备发送所述ARP请求报文;或者,当所述第一VTEP设备确定存在有新建立的VXLAN隧道时,根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述新建立的VXLAN隧道向目的VTEP设备发送所述ARP请求报文。
如图5和图6所示,当第一VXLAN隧道或第二VTEP设备发生故障时,可能导致ARP请求报文无法发送到所述第二VTEP设备。又例如,第四VTEP设备以新的VXLAN三层网关的身份加入图1所述的网络结构中。所述第四VTEP设备通过第三VXLAN隧道与所述第一VTEP设备连接。由于所述第四VTEP设备为新加入的VXLAN三层网关,因此所述第四VTEP设备没有存储ARP表项和MAC表项。
在本实施方式中,所述第一VTEP设备接收到所述ARP请求报文后,根据所述ARP请求报文生成ARP表项。所述第一VTEP设备将所述ARP表项存储到所述第一 VTEP设备的暂时性存储器中。在一种可能的实现方式中,当所述第一VTEP设备确定所述第一VXLAN隧道的故障恢复时,所述第一VTEP设备根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述所述第一VXLAN隧道向第二VTEP设备发送所述ARP请求报文。在另一种可能的实现方式中,当所述第一VTEP设备确定存在有所述第三VXLAN隧道时,所述第一VTEP设备根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述第三VXLAN隧道向所述第四VTEP设备发送所述ARP请求报文。
通过上述实现方式,当故障恢复或新建VXLAN隧道时,无需重新交互ARP报文。
图8为本发明实施例的第一VTEP设备1000的结构示意图。图8所示的第一VTEP设备可以执行上述实施例的方法中第一VTEP设备执行的相应步骤。如图8所示,所述第一VTEP设备1000包括处理单元1002,发送单元1004和报文转发单元1006,其中:
所述处理单元1002,用于根据第一VXLAN隧道的优先级设置所述第一VXLAN隧道的隧道状态为Active状态,所述第一VXLAN隧道为所述第一VTEP设备与第二VTEP设备之间的VXLAN隧道;
所述处理单元1002还用于根据第二VXLAN隧道的优先级设置所述第二VXLAN隧道的隧道状态为Inactive状态,所述第二VXLAN隧道为所述第一VTEP设备与第三VTEP设备之间的VXLAN隧道,所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级,所述第二VTEP设备的IP地址与所述第三VTEP设备的IP地址不相同;
所述发送单元1004,用于经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Active状态的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态;
所述发送单元1004还用于经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Inactive状态的第二状态信息,所述第二状态信息用于指示所述第二VXLAN隧道的隧道状态;
所述报文转发单元1006,用于经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
可选的,所述第一VTEP设备还包括接收单元,所述接收单元用于在所述报文转发单元经1006由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之前,具体用于:
经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备将所述第一VXLAN隧道的隧道状态确认为Active状态;
经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第二状态信息的第二应答信息,所述第二应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态确认为Inactive状态。
可选的,当所述第一VTEP设备确定所述第一VXLAN隧道存在故障时,所述处 理单元1002还用于设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及设置所述第二VXLAN隧道的隧道状态为Active状态;
所述发送单元1004还用于经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;
接收单元用于经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;
所述报文转发单元1006,用于经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
可选的,接收单元用于经由所述第一VXLAN隧道接收来自所述第二VTEP设备的链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与IP网络之间的链路存在故障,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量;
所述处理单元1002还用于设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及所述第一VTEP设备设置所述第二VXLAN隧道的隧道状态为Active状态;
所述发送单元1004还用于经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;
所述接收单元还用于经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;
所述报文转发单元1006,用于经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
可选的,所述接收单元还用于接收来自主机的地址解析协议ARP请求报文,所述ARP请求报文用于请求VXLAN网关的媒体接入控制MAC地址;
所述发送单元1004还用于分别经由所述第一VXLAN隧道和所述第二VXLAN隧道向所述第二VTEP设备和所述第三VTEP设备发送所述ARP请求报文,以便所述第二VTEP设备和所述第三VTEP设备根据所述ARP请求报文生成ARP表项。
可选的,所述处理单元1002还用于根据所述ARP请求报文生成所述ARP表项;
存储单元,用于存储所述ARP表项;
所述处理单元1002还用于当确定故障VXLAN隧道的故障恢复时,根据存储的所述ARP表项生成所述ARP请求报文,并且所述发送单元还用于经由所述故障恢复的VXLAN隧道向目的VTEP设备发送所述ARP请求报文;或者,
所述处理单元1002还用于当确定存在有新建立的VXLAN隧道时,根据存储的所述ARP表项生成所述ARP请求报文,并且所述发送单元还用于经由所述新建立的VXLAN隧道向目的VTEP设备发送所述ARP请求报文。
图8所示的第一VTEP设备可以执行上述实施例的方法中第一VTEP设备执行的相应步骤。从而,Active状态的VXLAN隧道处于工作状态,执行对流量的转发,Inactive 状态的VXLAN隧道处于非工作状态,不对流量的进行转发。通过实施例提供的方法,以提高VXLAN网络的冗余保护能力。
图9为本发明实施例的第一VTEP设备1100的硬件结构示意图。图9所示的第一VTEP设备可以执行上述实施例的方法中第一VTEP设备执行的相应步骤。
如图9所示,所述第一VTEP设备1100包括处理器1101、存储器1102、接口1103和总线1104,其中接口1103可以通过无线或有线的方式实现,具体来讲可以是例如网卡等元件,上述处理器1101、存储器1102和接口1103通过总线1104连接。
所述接口1103具体可以包括发送器和接收器,用于第一VTEP设备与上述实施例中的第二VTEP设备之间收发信息;或者用于第一VTEP设备与上述实施例中的第三VTEP设备之间收发信息。另外,接口1103还可以用于第一VTEP设备与所述第一VTEP设备连接的主机之间收发信息。作为举例,所述接口1103用于支持图2-图4中的过程S103,S106,S110,S112,S113,S203,S207,S208,S212,S303,S305,S309,S310和S314。所述处理器1101用于执行上述实施例中由第一VTEP设备进行的处理。作为举例,所述处理器1101用于支持图2-图4中的过程S101,S102,S201,S202和S304。存储器1102包括操作系统11021和应用程序11022,用于存储程序、代码或指令,当处理器或硬件设备执行这些程序、代码或指令时可以完成图2-图4中涉及第一VTEP设备的处理过程。
可以理解的是,图9仅仅示出了第一VTEP设备的简化设计。在实际应用中,第一VTEP设备可以包含任意数量的接口,处理器,存储器等,而所有可以实现本发明的第一VTEP设备都在本发明的保护范围之内。
另外,本发明实施例提供了一种计算机存储介质,用于储存为上述第一VTEP设备所用的计算机软件指令,其包含用于执行上述图2-图4所示实施例所设计的程序。
图10为本发明实施例的第二VTEP设备1200的结构示意图。图10所示的第二VTEP设备可以执行上述实施例的方法中第二VTEP设备执行的相应步骤。如图10所示,所述第二VTEP设备1200包括接收单元1202,处理单元1204和报文转发单元1206,其中:
所述接收单元1202,用于经由第一VXLAN隧道接收来自第一VTEP设备的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态;
所述处理单元1204,用于当所述第一状态信息携带的隧道状态为Active状态时,将所述第一VXLAN隧道确认为Active状态,并且将IP网络到达所述第二VTEP设备的路由优先级设置为第一优先级,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量,所述第一优先级大于第二优先级,所述第二优先级为所述第一VXLAN隧道是Inactive状态时,所述IP网络到达所述第二VTEP设备的路由优先级;
所述报文转发单元1206,用于经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
可选的,所述第二VTEP设备还包括发送单元,所述发送单元用于经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备确认的所述第一VXLAN隧道的隧道状态。
可选的,所述处理单元还用于当确定隧道状态为激活Active状态的所述第一VXLAN隧道存在故障时,将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为所述第二优先级。
可选的,所述处理单元还用于当确定所述第二VTEP设备与所述IP网络之间的链路存在故障时,生成链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与所述IP网络之间的链路存在故障;
所述发送单元用于经由隧道状态为激活Active状态的所述第一VXLAN隧道向所述第一VTEP设备发送所述链路故障消息;
所述接收单元还用于经由所述第一VXLAN隧道接收来自所述第一VTEP设备的第二状态信息,所述第二状态信息携带Inactive状态,用于指示所述第一VXLAN隧道的隧道状态;
所述处理单元还用于根据所述第二状态信息将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。
图10所示的第二VTEP设备可以执行上述实施例的方法中第二VTEP设备执行的相应步骤。通过实施例提供的方法,以提高VXLAN网络的冗余保护能力,并且确保上行流量方向和下行流量方向的一致。
图11为本发明实施例的第二VTEP设备1300的硬件结构示意图。图11所示的第二VTEP设备可以执行上述实施例的方法中第二VTEP设备执行的相应步骤。
如图11所示,所述第二VTEP设备1300包括处理器1301、存储器1302、接口1303和总线1304,其中接口1303可以通过无线或有线的方式实现,具体来讲可以是例如网卡等元件,上述处理器1301、存储器1302和接口1303通过总线1304连接。
所述接口1303具体可以包括发送器和接收器,用于第二VTEP设备与上述实施例中的第一VTEP设备之间收发信息;或者用于第二VTEP设备与上述实施例中的IP网络之间收发信息。作为举例,所述接口1303用于支持图2-图4中的过程S104,S109,S113,S211,S213,S214,S302,S311和S313。所述处理器1301用于执行上述实施例中由第二VTEP设备进行的处理。作为举例,所述处理器1301用于支持图2-图4中的过程S105,S209,S210,S301和S312。存储器1202包括操作系统12021和应用程序12022,用于存储程序、代码或指令,当处理器或硬件设备执行这些程序、代码或指令时可以完成图2-图4中涉及第二VTEP设备的处理过程。
可以理解的是,图11仅仅示出了第二VTEP设备的简化设计。在实际应用中,第二VTEP设备可以包含任意数量的接口,处理器,存储器等,而所有可以实现本发明的第二VTEP设备都在本发明的保护范围之内。
另外,本发明实施例提供了一种计算机存储介质,用于储存为上述第二VTEP设备所用的计算机软件指令,其包含用于执行上述图2-图4所示实施例所设计的程序。
结合本发明公开内容所描述的方法或者算法的步骤可以硬件的方式来实现,也可以是由处理器执行软件指令的方式来实现。软件指令可以由相应的软件模块组成,软件模块可以被存放于RAM存储器、闪存、ROM存储器、EPROM存储器、EEPROM存储器、寄存器、硬盘、移动硬盘、CD-ROM或者本领域熟知的任何其它形式的存储 介质中。一种示例性的存储介质耦合至处理器,从而使处理器能够从该存储介质读取信息,且可向该存储介质写入信息。当然,存储介质也可以是处理器的组成部分。处理器和存储介质可以位于ASIC中。另外,该ASIC可以位于用户设备中。当然,处理器和存储介质也可以作为分立组件存在于用户设备中。
本领域技术人员应该可以意识到,在上述一个或多个示例中,本发明所描述的功能可以用硬件、软件、固件或它们的任意组合来实现。当使用软件实现时,可以将这些功能存储在计算机可读介质中或者作为计算机可读介质上的一个或多个指令或代码进行传输。计算机可读介质包括计算机存储介质和通信介质,其中通信介质包括便于从一个地方向另一个地方传送计算机程序的任何介质。存储介质可以是通用或专用计算机能够存取的任何可用介质。
以上所述的具体实施方式,对本发明的目的、技术方案和有益效果进行了进一步详细说明,所应理解的是,以上所述仅为本发明的具体实施方式而已,并不用于限定本发明的保护范围,凡在本发明的技术方案的基础之上,所做的任何修改、等同替换、改进等,均应包括在本发明的保护范围之内。

Claims (20)

  1. 一种虚拟可扩展局域网VXLAN报文的转发方法,其特征在于,所述方法包括:
    第一虚拟可扩展局域网隧道端点VTEP设备根据第一VXLAN隧道的优先级设置所述第一VXLAN隧道的隧道状态为激活Active状态,所述第一VXLAN隧道为所述第一VTEP设备与第二VTEP设备之间的VXLAN隧道;
    所述第一VTEP设备根据第二VXLAN隧道的优先级设置所述第二VXLAN隧道的隧道状态为非激活Inactive状态,所述第二VXLAN隧道为所述第一VTEP设备与第三VTEP设备之间的VXLAN隧道,所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级,所述第二VTEP设备的因特网协议IP地址与所述第三VTEP设备的IP地址不相同;
    所述第一VTEP设备经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Active状态的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态;
    所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Inactive状态的第二状态信息,所述第二状态信息用于指示所述第二VXLAN隧道的隧道状态;
    所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
  2. 根据权利要求1所述的方法,其特征在于,在所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之前,所述方法还包括:
    所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备将所述第一VXLAN隧道的隧道状态确认为Active状态;
    所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第二状态信息的第二应答信息,所述第二应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态确认为Inactive状态。
  3. 根据权利要求1或2所述的方法,其特征在于,在所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之后,所述方法还包括:
    当所述第一VTEP设备确定所述第一VXLAN隧道存在故障时,所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及所述第一VTEP设备设置所述第二VXLAN隧道的隧道状态为Active状态;
    所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;
    所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;
    所述第一VTEP设备经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
  4. 根据权利要求1或2所述的方法,其特征在于,在所述第一VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之后,所述方法还包括:
    所述第一VTEP设备经由所述第一VXLAN隧道接收来自所述第二VTEP设备的链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与IP网络之间的链路存在故障,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量;
    所述第一VTEP设备设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及所述第一VTEP设备设置所述第二VXLAN隧道的隧道状态为Active状态;
    所述第一VTEP设备经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;
    所述第一VTEP设备经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;
    所述第一VTEP设备经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
  5. 根据权利要求1至4任一项所述的方法,其特征在于,所述方法还包括:
    所述第一VTEP设备接收来自主机的地址解析协议ARP请求报文,所述ARP请求报文用于请求VXLAN网关的媒体接入控制MAC地址;
    所述第一VTEP设备分别经由所述第一VXLAN隧道和所述第二VXLAN隧道向所述第二VTEP设备和所述第三VTEP设备发送所述ARP请求报文,以便所述第二VTEP设备和所述第三VTEP设备根据所述ARP请求报文生成ARP表项。
  6. 根据权利要求5所述的方法,其特征在于,所述方法还包括:
    所述第一VTEP设备根据所述ARP请求报文生成所述ARP表项;
    所述第一VTEP设备存储所述ARP表项;
    当所述第一VTEP设备确定故障VXLAN隧道的故障恢复时,根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述故障恢复的VXLAN隧道向目的VTEP设备发送所述ARP请求报文;或者,当所述第一VTEP设备确定存在有新建立的VXLAN隧道时,根据存储的所述ARP表项生成所述ARP请求报文,并且经由所述新建立的VXLAN隧道向目的VTEP设备发送所述ARP请求报文。
  7. 一种虚拟可扩展局域网VXLAN报文的转发方法,其特征在于,所述方法包括:
    第二虚拟可扩展局域网隧道端点VTEP设备经由第一VXLAN隧道接收来自第一VTEP设备的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态;
    当所述第一状态信息携带的隧道状态为激活Active状态时,所述第二VTEP设备将所述第一VXLAN隧道确认为Active状态,并且将因特网协议IP网络到达所述第二 VTEP设备的路由优先级设置为第一优先级,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量,所述第一优先级大于第二优先级,所述第二优先级为所述第一VXLAN隧道是非激活Inactive状态时,所述IP网络到达所述第二VTEP设备的路由优先级;
    所述第二VTEP设备经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
  8. 根据权利要求7所述的方法,其特征在于,所述方法还包括:
    所述第二VTEP设备经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备确认的所述第一VXLAN隧道的隧道状态。
  9. 根据权利要求7或8所述的方法,其特征在于,所述方法还包括:
    当所述第二VTEP设备确定隧道状态为激活Active状态的所述第一VXLAN隧道存在故障时,所述第二VTEP设备将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为所述第二优先级。
  10. 根据权利要求7或8所述的方法,其特征在于,所述方法还包括:
    当所述第二VTEP设备确定所述第二VTEP设备与所述IP网络之间的链路存在故障时,生成链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与所述IP网络之间的链路存在故障;
    所述第二VTEP设备经由隧道状态为激活Active状态的所述第一VXLAN隧道向所述第一VTEP设备发送所述链路故障消息;
    所述第二VTEP设备经由所述第一VXLAN隧道接收来自所述第一VTEP设备的第二状态信息,所述第二状态信息携带Inactive状态,用于指示所述第一VXLAN隧道的隧道状态;
    所述第二VTEP设备根据所述第二状态信息将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。
  11. 一种第一虚拟可扩展局域网隧道端点VTEP设备,其特征在于,所述第一VTEP设备包括:
    处理单元,用于根据第一虚拟可扩展局域网VXLAN隧道的优先级设置所述第一VXLAN隧道的隧道状态为激活Active状态,所述第一VXLAN隧道为所述第一VTEP设备与第二VTEP设备之间的VXLAN隧道;
    所述处理单元还用于根据第二VXLAN隧道的优先级设置所述第二VXLAN隧道的隧道状态为非激活Inactive状态,所述第二VXLAN隧道为所述第一VTEP设备与第三VTEP设备之间的VXLAN隧道,所述第一VXLAN隧道的优先级高于所述第二VXLAN隧道的优先级,所述第二VTEP设备的因特网协议IP地址与所述第三VTEP设备的IP地址不相同;
    发送单元,用于经由所述第一VXLAN隧道向所述第二VTEP设备通告携带有Active状态的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧 道状态;
    所述发送单元还用于经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Inactive状态的第二状态信息,所述第二状态信息用于指示所述第二VXLAN隧道的隧道状态;
    报文转发单元,用于经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
  12. 根据权利要求11所述的第一VTEP设备,其特征在于,所述第一VTEP设备还包括接收单元,所述接收单元用于在所述报文转发单元经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文之前,具体用于:
    经由所述第一VXLAN隧道接收来自所述第二VTEP设备的所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备将所述第一VXLAN隧道的隧道状态确认为Active状态;
    经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第二状态信息的第二应答信息,所述第二应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态确认为Inactive状态。
  13. 根据权利要求11所述的第一VTEP设备,其特征在于,所述第一VTEP设备还包括接收单元,
    当所述第一VTEP设备确定所述第一VXLAN隧道存在故障时,所述处理单元还用于设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及设置所述第二VXLAN隧道的隧道状态为Active状态;
    所述发送单元还用于经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;
    所述接收单元还用于经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;
    所述报文转发单元,用于经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
  14. 根据权利要求11所述的第一VTEP设备,其特征在于,所述第一VTEP设备还包括接收单元,
    所述接收单元用于经由所述第一VXLAN隧道接收来自所述第二VTEP设备的链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与IP网络之间的链路存在故障,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量;
    所述处理单元还用于设置所述第一VXLAN隧道的隧道状态为Inactive状态,以及所述第一VTEP设备设置所述第二VXLAN隧道的隧道状态为Active状态;
    所述发送单元还用于经由所述第二VXLAN隧道向所述第三VTEP设备通告携带有Active状态的第三状态信息,所述第三状态信息用于指示所述第二VXLAN隧道的隧道状态;
    所述接收单元还用于经由所述第二VXLAN隧道接收来自所述第三VTEP设备的所述第三状态信息的第三应答信息,所述第三应答信息用于指示所述第三VTEP设备将所述第二VXLAN隧道的隧道状态更新为Active状态;
    所述报文转发单元,用于经由隧道状态为Active状态的所述第二VXLAN隧道转发所述VXLAN报文。
  15. 根据权利要求11至14任一项所述的第一VTEP设备,其特征在于,
    所述接收单元还用于接收来自主机的地址解析协议ARP请求报文,所述ARP请求报文用于请求VXLAN网关的媒体接入控制MAC地址;
    所述发送单元还用于分别经由所述第一VXLAN隧道和所述第二VXLAN隧道向所述第二VTEP设备和所述第三VTEP设备发送所述ARP请求报文,以便所述第二VTEP设备和所述第三VTEP设备根据所述ARP请求报文生成ARP表项。
  16. 根据权利要求15所述的第一VTEP设备,其特征在于,
    所述处理单元还用于根据所述ARP请求报文生成所述ARP表项;
    存储单元,用于存储所述ARP表项;
    所述处理单元还用于当确定故障VXLAN隧道的故障恢复时,根据存储的所述ARP表项生成所述ARP请求报文,并且所述发送单元还用于经由所述故障恢复的VXLAN隧道向目的VTEP设备发送所述ARP请求报文;或者,
    所述处理单元还用于当确定存在有新建立的VXLAN隧道时,根据存储的所述ARP表项生成所述ARP请求报文,并且所述发送单元还用于经由所述新建立的VXLAN隧道向目的VTEP设备发送所述ARP请求报文。
  17. 一种第二虚拟可扩展局域网隧道端点VTEP设备,其特征在于,所述第二VTEP设备包括:
    接收单元,用于经由第一虚拟可扩展局域网VXLAN隧道接收来自第一VTEP设备的第一状态信息,所述第一状态信息用于指示所述第一VXLAN隧道的隧道状态;
    处理单元,用于当所述第一状态信息携带的隧道状态为激活Active状态时,将所述第一VXLAN隧道确认为Active状态,并且将因特网协议IP网络到达所述第二VTEP设备的路由优先级设置为第一优先级,所述IP网络用于向所述第一VTEP设备连接的主机发送流量和用于接收来自所述第一VTEP设备连接的所述主机的流量,所述第一优先级大于第二优先级,所述第二优先级为所述第一VXLAN隧道是非激活Inactive状态时,所述IP网络到达所述第二VTEP设备的路由优先级;
    报文转发单元,用于经由隧道状态为Active状态的所述第一VXLAN隧道转发所述VXLAN报文。
  18. 根据权利要求17所述的所述第二VTEP设备,其特征在于,所述第二VTEP设备还包括发送单元,
    所述发送单元用于经由所述第一VXLAN隧道向所述第一VTEP设备发送所述第一状态信息的第一应答信息,所述第一应答信息用于指示所述第二VTEP设备确认的所述第一VXLAN隧道的隧道状态。
  19. 根据权利要求17或18所述的第二VTEP设备,其特征在于,
    所述处理单元还用于当确定隧道状态为激活Active状态的所述第一VXLAN隧道 存在故障时,将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为所述第二优先级。
  20. 根据权利要求17所述的第二VTEP设备,其特征在于,所述第二VTEP设备还包括发送单元,
    所述处理单元还用于当确定所述第二VTEP设备与所述IP网络之间的链路存在故障时,生成链路故障消息,所述链路故障消息用于指示所述第二VTEP设备与所述IP网络之间的链路存在故障;
    所述发送单元用于经由隧道状态为激活Active状态的所述第一VXLAN隧道向所述第一VTEP设备发送所述链路故障消息;
    所述接收单元还用于经由所述第一VXLAN隧道接收来自所述第一VTEP设备的第二状态信息,所述第二状态信息携带Inactive状态,用于指示所述第一VXLAN隧道的隧道状态;
    所述处理单元还用于根据所述第二状态信息将所述第一VXLAN隧道的隧道状态切换为Inactive状态,并且将所述IP网络到达所述第二VTEP设备的路由优先级切换为第二优先级。
PCT/CN2017/093887 2016-09-20 2017-07-21 一种vxlan报文的转发方法、设备及系统 WO2018054156A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP17852226.4A EP3451593B1 (en) 2016-09-20 2017-07-21 Vxlan message forwarding method, device and system
US16/358,191 US10917262B2 (en) 2016-09-20 2019-03-19 VXLAN packet forwarding method, device, and system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610836569.0A CN107846342B (zh) 2016-09-20 2016-09-20 一种vxlan报文的转发方法、设备及系统
CN201610836569.0 2016-09-20

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US16/358,191 Continuation US10917262B2 (en) 2016-09-20 2019-03-19 VXLAN packet forwarding method, device, and system

Publications (1)

Publication Number Publication Date
WO2018054156A1 true WO2018054156A1 (zh) 2018-03-29

Family

ID=61657369

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/093887 WO2018054156A1 (zh) 2016-09-20 2017-07-21 一种vxlan报文的转发方法、设备及系统

Country Status (4)

Country Link
US (1) US10917262B2 (zh)
EP (1) EP3451593B1 (zh)
CN (1) CN107846342B (zh)
WO (1) WO2018054156A1 (zh)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110995610A (zh) * 2019-12-30 2020-04-10 杭州迪普科技股份有限公司 Vxlan隧道报文处理方法、装置及vtep设备
CN111224887A (zh) * 2018-11-27 2020-06-02 中国电信股份有限公司 设备配置方法、系统和相关设备
CN114338278A (zh) * 2021-12-29 2022-04-12 北京天融信网络安全技术有限公司 隧道通信方法、装置、设备及介质

Families Citing this family (24)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10637821B2 (en) * 2017-10-30 2020-04-28 Nicira, Inc. Fast relearning of workload MAC addresses multi-homed to active and backup gateways
CN108600069B (zh) * 2018-03-29 2020-12-25 新华三技术有限公司 链路切换方法及装置
CN108768845B (zh) * 2018-04-03 2021-04-27 新华三技术有限公司 一种多归属主机路由同步方法及装置
CN108600074B (zh) * 2018-04-20 2021-06-29 新华三技术有限公司 组播数据报文的转发方法及装置
CN110417569B (zh) * 2018-04-28 2021-09-21 华为技术有限公司 一种网络链路故障处理方法和隧道端点设备
CN108881024B (zh) * 2018-05-31 2021-03-23 新华三技术有限公司 一种组播流量转发方法及装置
CN109005097B (zh) * 2018-06-29 2020-12-01 新华三技术有限公司 报文转发方法及装置
CN108881013B (zh) * 2018-06-29 2021-05-07 新华三技术有限公司 控制网关模式的方法、系统、sdn控制器和接入设备
CN109347717B (zh) * 2018-09-26 2021-06-08 新华三技术有限公司 Vxlan隧道切换方法及装置
CN109412859A (zh) * 2018-11-15 2019-03-01 盛科网络(苏州)有限公司 一种vxlan隧道的oam方法及系统
CN109246016B (zh) * 2018-11-27 2021-01-26 杭州迪普科技股份有限公司 跨vxlan的报文处理方法和装置
CN111262665B (zh) * 2018-11-30 2022-04-12 北京金山云网络技术有限公司 数据通信方法、装置、控制器及系统
CN111371666B (zh) * 2018-12-26 2021-12-31 华为技术有限公司 一种处理报文的方法、设备及系统
CN111628921B (zh) * 2019-02-27 2021-07-20 华为技术有限公司 一种报文的处理方法、报文转发装置以及报文处理装置
CN110061899B (zh) * 2019-04-28 2021-08-06 新华三技术有限公司 一种数据报文传输方法、装置及系统
CN112152920B (zh) * 2019-06-28 2021-12-28 华为技术有限公司 一种实现表项备份的方法和装置
CN115665008A (zh) * 2019-10-22 2023-01-31 华为技术有限公司 报文检测方法、连通性协商关系建立方法以及相关设备
CN112714006A (zh) * 2019-10-24 2021-04-27 中兴通讯股份有限公司 链路故障状态通告方法、装置、设备及介质
CN113141290B (zh) * 2020-01-19 2023-12-19 华为技术有限公司 一种报文传输方法、装置及设备
CN111404816B (zh) * 2020-03-06 2021-06-15 联想(北京)有限公司 一种跨网络发送组播报文的方法、装置、系统及存储介质
CN111865751B (zh) * 2020-07-24 2022-07-12 迈普通信技术股份有限公司 集中式网关部署方法、装置、集中式网关及电子设备
WO2022176030A1 (ja) * 2021-02-16 2022-08-25 日本電信電話株式会社 通信制御装置、通信制御方法、通信制御プログラム及び通信制御システム
US11546253B2 (en) * 2021-03-31 2023-01-03 Juniper Networks, Inc Fast reroute for ethernet virtual private networks—virtual extensible local area network
CN113286011B (zh) * 2021-04-27 2023-08-22 锐捷网络股份有限公司 基于vxlan的ip地址分配方法及装置

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104270298A (zh) * 2014-09-30 2015-01-07 杭州华三通信技术有限公司 一种vxlan网络中的报文转发方法及装置
US20150058470A1 (en) * 2013-08-20 2015-02-26 Arista Networks, Inc. System and method for sharing vxlan table information with a network controller
CN104660508A (zh) * 2013-11-25 2015-05-27 华为技术有限公司 一种报文转发方法及装置
CN105490957A (zh) * 2014-10-11 2016-04-13 华为技术有限公司 一种负载分担方法及装置
CN105577417A (zh) * 2014-11-06 2016-05-11 杭州华三通信技术有限公司 基于vxlan网络的报文转发方法及装置

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015100656A1 (zh) * 2013-12-31 2015-07-09 华为技术有限公司 一种实现虚拟机通信的方法和装置
US9548873B2 (en) * 2014-02-10 2017-01-17 Brocade Communications Systems, Inc. Virtual extensible LAN tunnel keepalives
US9893988B2 (en) 2014-03-27 2018-02-13 Nicira, Inc. Address resolution using multiple designated instances of a logical router
US9413644B2 (en) * 2014-03-27 2016-08-09 Nicira, Inc. Ingress ECMP in virtual distributed routing environment
CN105471740B (zh) * 2014-07-09 2018-10-12 新华三技术有限公司 基于软件定义网络的网关迁徙处理方法及装置
US9819511B2 (en) * 2015-01-16 2017-11-14 Alcatel Lucent Bidirectional forwarding detection over a virtual extensible local area network
CN106612224B (zh) * 2015-10-26 2019-11-01 新华三技术有限公司 应用于vxlan的报文转发方法和装置
US10050855B1 (en) * 2015-12-17 2018-08-14 Juniper Networks, Inc. Maintaining a tunnel liveness session in a multi-chassis link aggregation group topology
US10454877B2 (en) * 2016-04-29 2019-10-22 Cisco Technology, Inc. Interoperability between data plane learning endpoints and control plane learning endpoints in overlay networks

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150058470A1 (en) * 2013-08-20 2015-02-26 Arista Networks, Inc. System and method for sharing vxlan table information with a network controller
CN104660508A (zh) * 2013-11-25 2015-05-27 华为技术有限公司 一种报文转发方法及装置
CN104270298A (zh) * 2014-09-30 2015-01-07 杭州华三通信技术有限公司 一种vxlan网络中的报文转发方法及装置
CN105490957A (zh) * 2014-10-11 2016-04-13 华为技术有限公司 一种负载分担方法及装置
CN105577417A (zh) * 2014-11-06 2016-05-11 杭州华三通信技术有限公司 基于vxlan网络的报文转发方法及装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3451593A4 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111224887A (zh) * 2018-11-27 2020-06-02 中国电信股份有限公司 设备配置方法、系统和相关设备
CN111224887B (zh) * 2018-11-27 2023-06-27 天翼云科技有限公司 设备配置方法、系统和相关设备
CN110995610A (zh) * 2019-12-30 2020-04-10 杭州迪普科技股份有限公司 Vxlan隧道报文处理方法、装置及vtep设备
CN114338278A (zh) * 2021-12-29 2022-04-12 北京天融信网络安全技术有限公司 隧道通信方法、装置、设备及介质

Also Published As

Publication number Publication date
US20190215190A1 (en) 2019-07-11
EP3451593A1 (en) 2019-03-06
CN107846342A (zh) 2018-03-27
CN107846342B (zh) 2020-11-06
US10917262B2 (en) 2021-02-09
EP3451593B1 (en) 2020-06-03
EP3451593A4 (en) 2019-06-12

Similar Documents

Publication Publication Date Title
WO2018054156A1 (zh) 一种vxlan报文的转发方法、设备及系统
US11012355B2 (en) Route processing method, device, and system
CN113765829B (zh) 软件定义联网分布式系统中的活性检测和路由收敛
CN113765782B (zh) 使用前缀独立收敛对底层故障的局部修复
US10938627B2 (en) Packet processing method, device, and network system
US9755958B2 (en) Fast convergence in VRRP with multipoint bidirectional forwarding detection
JP4796184B2 (ja) エッジノード冗長システム
US11349687B2 (en) Packet processing method, device, and system
WO2021043086A1 (zh) 一种sbfd会话的建立方法、设备及系统
US11349749B2 (en) Node protection for bum traffic for multi-homed node failure
EP3675431B1 (en) Core isolation for logical tunnels stitching multi-homed evpn and l2 circuit
WO2012075731A1 (zh) 基于arp交互的链路故障检测与恢复的方法和设备
CN102638389A (zh) 一种trill网络的冗余备份方法及系统
US11601335B2 (en) Methods and systems for neighbor-acknowledged graceful insertion/removal protocol
US20220124033A1 (en) Method for Controlling Traffic Forwarding, Device, and System
CN111064659A (zh) 多宿主节点故障的bum流量的节点保护
CN107547347B (zh) 基于vni的路径调整方法和装置
WO2022246693A1 (en) Method and apparatus for path switchover management

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17852226

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2017852226

Country of ref document: EP

Effective date: 20181127

NENP Non-entry into the national phase

Ref country code: DE