WO2021051935A1 - 一种防止流量绕行的方法及装置 - Google Patents

一种防止流量绕行的方法及装置 Download PDF

Info

Publication number
WO2021051935A1
WO2021051935A1 PCT/CN2020/099022 CN2020099022W WO2021051935A1 WO 2021051935 A1 WO2021051935 A1 WO 2021051935A1 CN 2020099022 W CN2020099022 W CN 2020099022W WO 2021051935 A1 WO2021051935 A1 WO 2021051935A1
Authority
WO
WIPO (PCT)
Prior art keywords
access device
mac
layer
route
gateway
Prior art date
Application number
PCT/CN2020/099022
Other languages
English (en)
French (fr)
Inventor
张岳同
Original Assignee
南京中兴软件有限责任公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 南京中兴软件有限责任公司 filed Critical 南京中兴软件有限责任公司
Priority to EP20864927.7A priority Critical patent/EP4020903A4/en
Publication of WO2021051935A1 publication Critical patent/WO2021051935A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4633Interconnection of networks using encapsulation techniques, e.g. tunneling
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4637Interconnected ring systems
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • H04L12/4645Details on frame tagging
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • H04L12/4645Details on frame tagging
    • H04L12/4666Operational details on the addition or the stripping of a tag in a frame, e.g. at a provider edge node
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4641Virtual LANs, VLANs, e.g. virtual private networks [VPN]
    • H04L12/4675Dynamic sharing of VLAN information amongst network nodes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/02Topology update or discovery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/38Flow based routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/50Routing or path finding of packets in data switching networks using label swapping, e.g. multi-protocol label switch [MPLS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/66Layer 2 routing, e.g. in Ethernet based MAN's
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/74Address processing for routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/46Interconnection of networks
    • H04L12/4604LAN interconnection over a backbone network, e.g. Internet, Frame Relay
    • H04L2012/4629LAN interconnection over a backbone network, e.g. Internet, Frame Relay using multilayer switching, e.g. layer 3 switching

Definitions

  • the present invention relates to the field of communication technology, and in particular to a method and device for preventing traffic bypassing.
  • Ethernet Virtual Private Network is a Layer 2 network interconnection Virtual Private Network (Virtual Private Network, VPN) technology, which can be based on an Extensible Virtual Local Area Network (VXLAN) tunnel , Multi-Protocol Label Switching (MPLS) or Provider Backbone Bridge (PBB).
  • EVPN technology communicates media access control (MAC)/Address Resolution Protocol (Address Resolution Protocol, ARP) between Layer 2 networks by establishing MultiProtocol-Border Gateway Protocol (MP-BGP) neighbors.
  • MP-BGP MultiProtocol-Border Gateway Protocol
  • Layer 2 or Layer 3 message forwarding is performed through the generated address forwarding entries. That is, the transmission of entries such as MAC/ARP/routes does not depend on the data plane to complete, but is completed through the EVPN control plane.
  • VXLAN Tunnel End Point VXLAN Tunnel End Point
  • ARP request packets and normal VXLAN data packets.
  • the packets are sent to the VTEP at the other end through the tunnel
  • the encapsulated message is sent, and the VTEP at the other end receives the encapsulated message, and then forwards it according to the encapsulated MAC address after decapsulation.
  • VTEP can be implemented by hardware devices or software that support VXLAN.
  • the gateway when communicating across the access ring, the gateway only advertises the route of the IP network segment, and does not advertise the detailed IP route of the host inside the access ring .
  • IRB Integrated Routing and Bridge
  • the first VXLAN tunnel endpoint VTEP1 and the first gateway GW1 belong to the first access ring (access ring 1), and the first IRB (IRB1) interface is deployed in the first access ring.
  • the second VXLAN tunnel endpoint VTEP2 and the second gateway GW2 belong to the second access ring (access ring 2), the second IRB (IRB2) interface is deployed on the second gateway, and the second access device (VM2 (virtual machine 2)) Access to the second access ring.
  • the third VXLAN tunnel endpoint VTEP3 and the third gateway GW3 belong to the third access ring (access ring 3), the third IRB (IRB3) interface is deployed on the third gateway, and the third access device (VM3 (virtual machine 3)) Access to the third access ring.
  • GW1, GW2, and GW3 belong to the same core ring.
  • the access ring is a network established by devices at the access layer and the convergence layer through ring networking.
  • the core ring is a network established by devices at the core layer and the convergence layer through ring networking.
  • the convergence layer is located between the access layer and the core layer and serves as a communication bridge between the access layer and the core layer.
  • the first VXLAN tunnel is between GW1 and VTEP1
  • the second VXLAN tunnel is between GW2 and VTEP2
  • the third VXLAN tunnel is between GW3 and VTEP3.
  • GW1 notifies GW2 and GW3 of the first EVPN MAC/IP advertisement route, which carries the Layer 3 forwarding information of IRB1.
  • GW3 notifies GW1 and GW2 of the third EVPN MAC/IP advertisement route, which carries the Layer 3 forwarding information of IRB3.
  • the Layer 3 forwarding information carried by the first EVPN MAC/IP advertised route can be generated on GW2 with a 24-bit masked network segment routing entry, and the third EVPN MAC/IP advertised route can also be generated on GW2 for the Layer 3 forwarding information carried by 24 Network segment routing entry with bit mask.
  • VM1, VM3, IRB1, and IRB3 are in the same network segment, and the IP addresses of IRB3 and IRB1 are the same
  • GW2 queries where VM3 is located The routing and forwarding entries of the network segment are inquired about the route forwarded by GW1 and the route forwarded by GW3, and the route entry with the highest route priority is selected from the routing entries of the same network segment according to the priority of the route.
  • the priority of the route forwarded by GW1 is higher than the priority of the route forwarded by GW3, the next hop of the route on GW2 to the network segment is the Layer 3 interface IRB1 of GW1.
  • GW2 first sends the message sent to VM3 to GW1, and GW1 forwards the message to GW3 through Layer 2 forwarding, and finally sends it to VM3. Since the traffic sent to VM3 in the third access ring is forwarded to GW3 in the third access ring through GW1 in the first access ring, the problem of traffic detour occurs.
  • the present disclosure provides a method and device for preventing traffic detour, which can prevent traffic detour when accessing ring communication across an Ethernet virtual private network, and improve transmission efficiency.
  • an embodiment of the present invention provides a method for preventing traffic circumvention, including: notifying other gateways of the EVPN media access control MAC/MAC of the first access device in the first access ring where the gateway is located.
  • Internet Protocol IP advertising route the EVPN MAC/IP advertising route of the first access device carries the Layer 2 forwarding information and Layer 3 forwarding information of the first access device; the second in the second access ring is received
  • the EVPN MAC/IP advertising route of the second access device in the second access ring advertised by the gateway, and the second access device carried in the EVPN MAC/IP advertising route of the second access device
  • the detailed route of the second access device is generated from the layer 2 forwarding information and the layer 3 forwarding information of the forwarding information; when a packet is forwarded to the second access device, the detailed route of the second access device is used to
  • the packet is encapsulated in Layer 2 and Layer 3 encapsulation, and the encapsulated packet is forwarded to the second gateway.
  • an embodiment of the present invention provides a device for preventing traffic detour, which is applied to a gateway of an Ethernet virtual private network EVPN, and includes: a route notification module configured to notify other gateways of the first connection of the gateway.
  • the EVPN media access control MAC/Internet Protocol IP advertising route of the first access device in the ring the EVPN MAC/IP advertising route of the first access device carries the Layer 2 forwarding information of the first access device and Layer 3 forwarding information; detailed route generation module, set to receive the EVPN MAC/IP advertising route of the second access device in the second access ring announced by the second gateway in the second access ring, according to all Generating the detailed route of the second access device by the layer 2 forwarding information and the layer 3 forwarding information of the second access device carried in the EVPN MAC/IP advertising route of the second access device; a message forwarding module, When it is set to forward a message to the second access device, the message is subjected to Layer 2 encapsulation and Layer 3 encapsulation according to the detailed route of the second access device, and the encapsulated message is forwarded to the The second gateway.
  • an embodiment of the present invention provides a device for preventing traffic circumvention, including: a memory, a processor, and a traffic circumvention preventing device stored in the memory and running on the processor A program for implementing the steps of the method for preventing traffic circumvention when the program for preventing traffic circumvention is executed by the processor.
  • an embodiment of the present invention provides a computer-readable storage medium, the computer-readable storage medium stores a program for preventing traffic circumvention, and the program for preventing traffic circumvention is executed by a processor When realizing the steps of the above method to prevent traffic bypassing.
  • the embodiment of the present invention provides a method and device for preventing traffic circumvention.
  • the first gateway notifies other gateways of the EVPN media access control of the first access device in the first access ring where the gateway is located.
  • MAC/Internet Protocol IP advertising route the EVPN MAC/IP advertising route of the first access device carries the layer 2 forwarding information and the layer 3 forwarding information of the first access device;
  • the EVPN MAC/IP advertising route of the second access device in the second access ring advertised by the second gateway is based on the second access carried in the EVPN MAC/IP advertising route of the second access device.
  • the layer 2 forwarding information and the layer 3 forwarding information of the incoming device generate a detailed route for the second access device; when forwarding a message to the second access device, the detailed route of the second access device is used to The message is subjected to two-layer encapsulation and three-layer encapsulation, and the encapsulated message is forwarded to the second gateway.
  • the technical solution of the embodiment of the present invention can prevent traffic from detouring when accessing ring communication across an Ethernet virtual private network, and improve transmission efficiency.
  • FIG. 1 is a schematic diagram of a cross-access ring communication architecture of an Ethernet virtual private network in the prior art
  • Figure 2 is a flowchart of a method for preventing traffic detours according to Embodiment 1 of the present invention
  • Figure 3 is a schematic diagram of a device for preventing traffic bypassing according to Embodiment 2 of the present invention.
  • FIG. 4 is a flowchart of a method for preventing traffic bypass in Example 1 of the present invention.
  • Fig. 5 is a flowchart of a method for preventing traffic detour according to Example 2 of the present invention.
  • the embodiment of the present invention provides a method for preventing traffic detour, which is applied to the gateway of the Ethernet virtual private network EVPN, including:
  • Step S210 Notify other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located, and the EVPN MAC/IP notification route of the first access device carries Layer 2 forwarding information and Layer 3 forwarding information of the first access device;
  • Step S220 Receive the EVPN MAC/IP advertised route of the second access device in the second access ring announced by the second gateway in the second access ring, according to the EVPN MAC of the second access device /IP advertisement route carried in the second access device's layer 2 forwarding information and layer 3 forwarding information to generate the detailed route of the second access device;
  • Step S230 When forwarding the message to the second access device, perform Layer 2 encapsulation and Layer 3 encapsulation on the message according to the detailed route of the second access device, and forward the encapsulated message to all The second gateway;
  • the detailed route is a route with more bits than the network segment route mask; for example, the network segment route refers to the route with a 24-bit mask, and the detailed route refers to the route with a 32-bit mask; that is, compared to the detailed route Network segment routing, matching IP prefix digits more, more accurate matching.
  • the method before notifying other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located, the method further includes:
  • the EVPN MAC/IP advertisement route of the first access device carries the following information:
  • the MAC address field carries the MAC address information of the first access device;
  • the IP address field carries the IP address information of the first access device;
  • the multiprotocol label switching label 1 field carries the second layer of the first access ring Scalable virtual local area network network identifier VNI (VXLAN network identifier) information;
  • the next hop attribute carries the IP address information of the first scalable virtual local area network tunnel endpoint;
  • notifying other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located includes:
  • the modification includes the following content: the multi-protocol label switching label 1 field is modified to carry the layer 2 extensible virtual local area network identification information of the core ring where the gateway is located; the multi-protocol label switching label 2 field carries the core ring where the gateway is located The second-layer extensible virtual local area network identification information; the next hop attribute is modified to carry the IP address information of the gateway; the "routed MAC" extended attribute is added, and the first "routed MAC” extended attribute is carried MAC address information of the access device.
  • the method before notifying other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located, the method further includes:
  • the EVPN MAC/IP advertisement route of the first access device carries the following information:
  • the MAC address field carries the MAC address information of the first access device;
  • the IP address field carries the IP address information of the first access device;
  • the multiprotocol label switching label 1 field carries the second layer of the first access ring Scalable virtual local area network network identification information;
  • the multi-protocol label switching label 2 field carries the layer two scalable virtual local area network network identification information of the first access ring;
  • the next hop attribute carries the end point of the first scalable virtual local area network tunnel IP address information;
  • the "routed MAC" extended attribute carries the MAC address information of the first access device;
  • notifying other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located includes:
  • the modification includes the following content: modify the multi-protocol label switching label 1 field to carry the layer 2 extensible virtual local area network identification information of the core ring where the gateway is located; modify the multi-protocol label switching label 2 field to carry the location of the gateway
  • the third layer of the core ring can extend the virtual LAN network identification information; the value of the next hop attribute is modified to carry the IP address information of the gateway; the value of the "routed MAC" extended attribute is modified to carry the MAC address information of the gateway .
  • the EVPN MAC/IP advertisement route of the second access device carries the layer 2 forwarding information and the layer 3 forwarding information of the second access device, including:
  • the MAC address field carries the MAC address of the second access device
  • the IP address field carries the IP address of the second access device
  • the multi-protocol label switching label 1 field carries the identification information of the layer 2 extensible virtual local area network network of the core ring where the second gateway is located;
  • the multi-protocol label switching label 2 field carries the identification information of the layer 2 extensible virtual local area network network of the core ring where the second gateway is located;
  • the next hop attribute carries the IP address information of the second gateway
  • the "routed MAC" extended attribute carries the MAC address information of the second access device
  • the EVPN MAC/IP advertisement route of the second access device carries the layer 2 forwarding information and the layer 3 forwarding information of the second access device, including:
  • the MAC address field carries the MAC address of the second access device
  • the IP address field carries the IP address of the second access device
  • the multi-protocol label switching label 1 field carries the identification information of the layer 2 extensible virtual local area network network of the core ring where the second gateway is located;
  • the multi-protocol label switching label 2 field carries the identification information of the Layer 3 scalable virtual local area network of the core ring where the second gateway is located;
  • the next hop attribute carries the IP address information of the second gateway
  • the "routed MAC" extended attribute carries the MAC address information of the second gateway.
  • an embodiment of the present invention provides a device for preventing traffic detour, which is applied to the gateway of the Ethernet virtual private network EVPN, including:
  • the route notification module 10 is configured to notify other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located, and the EVPN MAC/ The IP advertising route carries the layer 2 forwarding information and the layer 3 forwarding information of the first access device;
  • the detailed route generation module 20 is configured to receive the EVPN MAC/IP advertisement route of the second access device in the second access ring notified by the second gateway in the second access ring, and according to the second access ring Generating the detailed route of the second access device by the layer 2 forwarding information and the layer 3 forwarding information of the second access device carried in the EVPN MAC/IP advertisement route of the incoming device;
  • the message forwarding module 30 is configured to, when forwarding the message to the second access device, perform Layer 2 encapsulation and Layer 3 encapsulation on the message according to the detailed route of the second access device, and encapsulate the encapsulated Forwarding the message to the second gateway;
  • the device further includes: a first route advertisement receiving module 40;
  • the first route advertisement receiving module is configured to receive the EVPN MAC/IP advertisement route of the first access device announced by the first extensible virtual local area network tunnel endpoint of the first access ring;
  • the EVPN MAC/IP advertisement route of the first access device carries the following information:
  • the MAC address field carries the MAC address information of the first access device; the IP address field carries the IP address information of the first access device; the multiprotocol label switching label 1 field carries the second layer of the first access ring Extensible virtual local area network network identification information; the next hop attribute carries the IP address information of the first extensible virtual local area network tunnel endpoint.
  • the route notification module is configured to notify other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located in the following manner:
  • the modification includes the following content: the multi-protocol label switching label 1 field is modified to carry the layer 2 extensible virtual local area network identification information of the core ring where the gateway is located; the multi-protocol label switching label 2 field carries the core ring where the gateway is located The second-layer extensible virtual local area network identification information; the next hop attribute is modified to carry the IP address information of the gateway; the "routed MAC" extended attribute is added, and the first "routed MAC” extended attribute is carried MAC address information of the access device.
  • the device further includes: a second route advertisement receiving module 60;
  • the second route advertisement receiving module is configured to receive the EVPN MAC/IP advertisement route of the first access device announced by the first extensible virtual local area network tunnel endpoint of the first access ring;
  • the EVPN MAC/IP advertisement route of the first access device carries the following information:
  • the MAC address field carries the MAC address information of the first access device; the IP address field carries the IP address information of the first access device; the multiprotocol label switching label 1 field carries the second layer of the first access ring Scalable virtual local area network network identification information; the multi-protocol label switching label 2 field carries the layer two scalable virtual local area network network identification information of the first access ring; the next hop attribute carries the end point of the first scalable virtual local area network tunnel IP address information; the "routed MAC" extended attribute carries the MAC address information of the first access device.
  • the route notification module is configured to notify other gateways of the EVPN media access control MAC/Internet Protocol IP notification route of the first access device in the first access ring where the gateway is located in the following manner:
  • the modification includes the following content: modify the multi-protocol label switching label 1 field to carry the layer 2 extensible virtual local area network identification information of the core ring where the gateway is located; modify the multi-protocol label switching label 2 field to carry the location of the gateway
  • the third layer of the core ring can extend the virtual LAN network identification information; the value of the next hop attribute is modified to carry the IP address information of the gateway; the value of the "routed MAC" extended attribute is modified to carry the MAC address information of the gateway .
  • the EVPN MAC/IP advertisement route of the second access device carries the layer 2 forwarding information and the layer 3 forwarding information of the second access device, including:
  • the MAC address field carries the MAC address of the second access device
  • the IP address field carries the IP address of the second access device
  • the multi-protocol label switching label 1 field carries the identification information of the layer 2 extensible virtual local area network network of the core ring where the second gateway is located;
  • the multi-protocol label switching label 2 field carries the identification information of the layer 2 extensible virtual local area network network of the core ring where the second gateway is located;
  • the next hop attribute carries the IP address information of the second gateway
  • the "routed MAC" extended attribute carries the MAC address information of the second access device.
  • the EVPN MAC/IP advertisement route of the second access device carries the layer 2 forwarding information and the layer 3 forwarding information of the second access device, including:
  • the MAC address field carries the MAC address of the second access device
  • the IP address field carries the IP address of the second access device
  • the multi-protocol label switching label 1 field carries the identification information of the layer 2 extensible virtual local area network network of the core ring where the second gateway is located;
  • the multi-protocol label switching label 2 field carries the identification information of the Layer 3 scalable virtual local area network of the core ring where the second gateway is located;
  • the next hop attribute carries the IP address information of the second gateway
  • the "routed MAC" extended attribute carries the MAC address information of the second gateway.
  • the embodiment of the present invention provides a device for preventing traffic bypass, including:
  • An embodiment of the present invention provides a computer-readable storage medium, the computer-readable storage medium stores a program for preventing traffic circumvention, and when the program for preventing traffic circumvention is executed by a processor, the foregoing embodiment 1 is implemented. Steps in the method to prevent traffic bypassing.
  • the first VXLAN tunnel endpoint VTEP1 and the first gateway GW1 belong to the first access ring (access ring 1), and the first IRB (IRB1) interface is deployed on the first gateway.
  • An access device (VM1 (Virtual Machine 1)) accesses the first access ring.
  • the second VXLAN tunnel endpoint VTEP2 and the second gateway GW2 belong to the second access ring (access ring 2), the second IRB (IRB2) interface is deployed on the second gateway, and the second access device (VM2 (virtual machine 2)) Access to the second access ring.
  • the third VXLAN tunnel endpoint VTEP3 and the third gateway GW3 belong to the third access ring (access ring 3), the third IRB (IRB3) interface is deployed on the third gateway, and the third access device (VM3 (virtual machine 3)) Access to the third access ring.
  • GW1, GW2, and GW3 belong to the same core ring.
  • VM1 and VM3 are on the same network segment.
  • the first VXLAN tunnel is between GW1 and VTEP1
  • the second VXLAN tunnel is between GW2 and VTEP2
  • the third VXLAN tunnel is between GW3 and VTEP3.
  • the second access device wants to send a message to the first access device (VM1).
  • VM1 The second access device
  • a detailed route of VM1 is generated on GW2, and the message can be directly sent to the first access device (VM1).
  • the first gateway GW1 of an access ring does not bypass other gateways (for example, GW3).
  • a method for preventing traffic detours may include the following steps:
  • VTEP1 advertises the first EVPN MAC/IP advertising route to GW1.
  • the first EVPN MAC/IP advertising route includes the following content: the MAC address field carries the MAC address information of VM1, the IP address field carries the IP address information of VM1, and MPLS
  • the tag 1 field carries the Layer 2 VNI information of the first access ring, and the next hop attribute carries the IP address information of VTEP1;
  • GW1 receives the first EVPN MAC/IP advertised route, and forms a MAC entry in the local MAC-VRF (Virtual Routing Forwarding) table;
  • GW1 determines that the first EVPN MAC/IP advertisement route carries MPLS label 1 but does not carry MPLS label 2, and forms a MAC entry in the local MAC-VRF table.
  • the value of the destination MAC field of the MAC entry is set to the MAC address of VM1, and the value of the outbound interface field of the MAC entry is set to the first VXLAN tunnel from GW1 to VTEP1;
  • the destination of the first VXLAN tunnel IP is the IP of VTEP1, and the VNI of the first VXLAN tunnel is the Layer 2 VNI of the first access ring;
  • the modified first EVPN MAC/IP advertisement route includes the following content: the MAC address field carries the MAC address information of VM1, the IP address field carries the IP address information of VM1, and the MPLS label The 1 field carries the layer 2 VNI information of the core ring, the MPLS label 2 field carries the layer 2 VNI information of the core ring, the next hop attribute carries the IP address information of GW1, and the "routed MAC" extended attribute carries the MAC address information of VM1.
  • the MPLS label 2 field is optional. If the EVPN MAC/IP advertising route carries the MPLS label 2 field, the receiver of the advertising route will generate a detailed route in the IP-VRF table.
  • GW1 advertises the modified first EVPN MAC/IP advertising route to GW2 and GW3;
  • GW2 receives the first EVPN MAC/IP advertised route advertised by GW1, and forms the detailed route of VM1 in the IP-VRF forwarding table;
  • the destination IP address is set to the value of the IP address field of the first EVPN MAC/IP advertising route (that is, the IP address of VM1), and the next hop value is the IP address of GW1 ( The IP address of IRB1), the outgoing interface is the VXLAN tunnel from GW2 to GW1.
  • the VNI of the VXLAN tunnel from GW2 to GW1 is the Layer 2 VNI of the core ring (that is, the first EVPN MAC/IP advertising route MPLS Label2 field value).
  • GW2 upon receiving a message from VTEP2 that needs to be forwarded to VM1, queries the IP-VRF forwarding table according to the IP address of VM1, matches the detailed route to VM1, and performs Layer 2 on the message according to the detailed route of VM1 Encapsulation and three-layer encapsulation and forward to GW1;
  • the original message encapsulates the inner MAC header
  • the destination MAC field of the inner MAC header is set to the MAC address of VM1
  • the source MAC field is set to the MAC address of GW2.
  • the VXLAN header is encapsulated, and the VNI field of the VXLAN header is set to the layer 2 VNI of the core ring.
  • the outer IP header is encapsulated, and the destination IP field of the outer IP header is set to the IP address of GW1.
  • GW1 receives the message forwarded by GW2, parses the VXLAN header of the message, searches the MAC-VRF table according to the VNI field of the VXLAN header, and sends the message according to the MAC forwarding entry in the MAC-VRF table Give it to VTEP1, and then forward it to VM1 by VTEP1.
  • GW2 generates the detailed route of VM1 after receiving the first EVPN MAC/IP advertisement route advertised by GW1. According to the detailed route of VM1, the message with the destination address of VM1 can be directly forwarded to GW1. There will be traffic bypassing other gateways.
  • the first VXLAN tunnel endpoint VTEP1 and the first gateway GW1 belong to the first access ring (access ring 1), and the first IRB (IRB1) interface is deployed on the first gateway.
  • An access device (VM1 (Virtual Machine 1)) accesses the first access ring.
  • the second VXLAN tunnel endpoint VTEP2 and the second gateway GW2 belong to the second access ring (access ring 2), the second IRB (IRB2) interface is deployed on the second gateway, and the second access device (VM2 (virtual machine 2)) Access to the second access ring.
  • the third VXLAN tunnel endpoint VTEP3 and the third gateway GW3 belong to the third access ring (access ring 3), the third IRB (IRB3) interface is deployed on the third gateway, and the third access device (VM3 (virtual machine 3)) Access to the third access ring.
  • GW1, GW2, and GW3 belong to the same core ring.
  • VM1 and VM3 are on the same network segment.
  • the first VXLAN tunnel is between GW1 and VTEP1
  • the second VXLAN tunnel is between GW2 and VTEP2
  • the third VXLAN tunnel is between GW3 and VTEP3.
  • the second access device wants to send a message to the first access device (VM1).
  • VM1 The second access device
  • a detailed route of VM1 is generated on GW2, and the message can be directly sent to the first access device (VM1).
  • the first gateway GW1 of an access ring does not bypass other gateways (for example, GW3).
  • a method for preventing traffic detours may include the following steps:
  • VTEP1 advertises the first EVPN MAC/IP advertising route to GW1.
  • the first EVPN MAC/IP advertising route includes the following content: the MAC address field carries the MAC address information of VM1, the IP address field carries the IP address information of VM1, and MPLS
  • the label 1 field carries the layer 2 VNI information of the first access ring, the MPLS label 2 field carries the layer 2 VNI information of the first access ring, the next hop attribute carries the IP address information of VTEP1, and the "routed MAC" extended attribute carries MAC address information of VM1;
  • GW1 receives the first EVPN MAC/IP advertised route, and forms a detailed route of VM1 in the local IP-VRF table;
  • GW1 determines that the first EVPN MAC/IP advertisement route carries both MPLS label 1 and MPLS label 2 and forms a detailed route of VM1 in the local IP-VRF table.
  • the destination IP address is set to the value of the IP address field of the first EVPN MAC/IP advertising route (that is, the IP address of VM1), the next hop value is the IP address of VTEP1, and the outgoing interface It is the first VXLAN tunnel from GW1 to VTEP1, and the VNI of the first VXLAN tunnel is the Layer 2 VNI of the first access ring (that is, the value of the MPLS Label2 field of the first EVPN MAC/IP advertising route).
  • the modified first EVPN MAC/IP advertisement route includes the following content: the MAC address field carries the MAC address information of VM1, the IP address field carries the IP address information of VM1, and the MPLS label The 1 field carries the layer 2 VNI information of the core ring, the MPLS label 2 field carries the layer 3 VNI information of the core ring, the next hop attribute carries the IP address information of GW1, and the "routed MAC" extended attribute carries the MAC address information of GW1.
  • GW1 advertises the modified first EVPN MAC/IP advertising route to GW2 and GW3;
  • GW2 receives the first EVPN MAC/IP advertised route advertised by GW1, and forms the detailed route of VM1 in the IP-VRF forwarding table;
  • the destination IP address is set to the value of the IP address field of the first EVPN MAC/IP advertising route (that is, the IP address of VM1), and the next hop value is the IP address of GW1 ( The IP address of IRB1), the outgoing interface is the VXLAN tunnel from GW2 to GW1, and the VNI of the VXLAN tunnel from GW2 to GW1 is the Layer 3 VNI of the core ring (that is, the MPLS Label2 field of the first EVPN MAC/IP advertising route). value).
  • GW2 upon receiving a message from VTEP2 that needs to be forwarded to VM1, queries the IP-VRF forwarding table according to the IP address of VM1, matches the detailed route to VM1, and performs Layer 2 on the message according to the detailed route of VM1 Encapsulation and three-layer encapsulation and forward to GW1;
  • the original message encapsulates the inner MAC header
  • the destination MAC field of the inner MAC header is set to the MAC address of VM1
  • the source MAC field is set to the MAC address of GW2.
  • the VXLAN header is encapsulated, and the VNI field of the VXLAN header is set to the Layer 3 VNI of the core ring.
  • the outer IP header is encapsulated, and the destination IP field of the outer IP header is set to the IP address of GW1.
  • GW1 receives the message forwarded by GW2, parses the VXLAN header of the message, searches the IP-VRF table according to the VNI field of the VXLAN header, and sends the message according to the route forwarding entry in the IP-VRF table Give it to VTEP1, and then forward it to VM1 by VTEP1.
  • GW2 generates the detailed route of VM1 after receiving the first EVPN MAC/IP advertised route advertised by GW1. According to the detailed route of VM1, the message with the destination address of VM1 can be directly forwarded to GW1. There will be traffic bypassing other gateways.
  • Such software may be distributed on a computer-readable medium, and the computer-readable medium may include a computer storage medium (or a non-transitory medium) and a communication medium (or a transitory medium).
  • the term computer storage medium includes volatile and non-volatile data implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Sexual, removable and non-removable media.
  • Computer storage media include but are not limited to RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or Any other medium used to store desired information and that can be accessed by a computer.
  • communication media usually contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as carrier waves or other transmission mechanisms, and may include any information delivery media. .
  • a method and device for preventing traffic bypassing is provided.
  • a first gateway notifies other gateways of the EVPN media access control MAC/Internet Protocol IP notification of the first access device in the first access ring where the gateway is located Routing, the EVPN MAC/IP advertising route of the first access device carries the layer 2 forwarding information and the layer 3 forwarding information of the first access device; all the information advertised by the second gateway in the second access ring is received
  • the EVPN MAC/IP advertising route of the second access device in the second access ring is based on the Layer 2 forwarding of the second access device carried in the EVPN MAC/IP advertising route of the second access device Information and Layer 3 forwarding information to generate a detailed route of the second access device; when forwarding a message to the second access device, perform Layer 2 on the message according to the detailed route of the second access device Encapsulation and three-layer encapsulation, forward the encapsulated message to the second gateway.
  • the technical solution of the embodiment of the present invention can prevent traffic from de

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本公开提供了一种防止流量绕行的方法及装置。所述防止流量绕行的方法,应用于EVPN的网关,包括:向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN MAC/IP通告路由,其中携带第一接入设备的二层转发信息和三层转发信息;接收到第二接入环内的第二网关通告的第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据其中携带的第二接入设备的二层转发信息和三层转发信息生成第二接入设备的明细路由;向第二接入设备转发报文时,根据第二接入设备的明细路由对报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。本公开的技术方案能够跨以太虚拟专用网络接入环通信时防止流量绕行,提高传输效率。

Description

一种防止流量绕行的方法及装置 技术领域
本发明涉及通信技术领域,尤其涉及的是一种防止流量绕行的方法及装置。
背景技术
以太虚拟专用网络(Ethernet Virtual Private Network,简称EVPN)是一种二层网络互联虚拟专用网络(Virtual Private Network,简称VPN)技术,可以基于可扩展虚拟局域网(Virtual Extensible Local Area Network,简称VXLAN)隧道、多协议标签交换(Multi-Protocol Label Switching,简称MPLS)或者运营商骨干桥接技术(Provider Backbone Bridge,简称PBB)。EVPN技术通过建立多协议边界网关协议(MultiProtocol-Border Gateway Protocol,MP-BGP)邻居来传递二层网络间的媒体访问控制(Media Access Control,MAC)/地址解析协议(Address Resolution Protocol,ARP)/路由信息,通过生成的地址转发表项进行二层或者三层报文转发。即其MAC/ARP/路由等条目的传递不依赖数据面完成,而是通过EVPN控制面完成。
VXLAN隧道端点(VXLAN Tunnel End Point,简称VTEP)用于对VXLAN报文进行封装/解封装,包括ARP请求报文和正常的VXLAN数据报文,在一端VTEP封装报文后通过隧道向另一端VTEP发送封装报文,另一端VTEP接收到封装的报文,解封装后根据封装的MAC地址进行转发。VTEP可由支持VXLAN的硬件设备或软件来实现。
对于将集成路由与桥(Integrated Routing and Bridge,IRB)接口部署在网关设备的场景,跨接入环通信时,网关只会通告IP网段路由,不会通告接入环内部主机的IP明细路由。
如图1所示的跨接入环通信的网络场景中,第一VXLAN隧道端点VTEP1和第一网关GW1属于第一接入环(接入环1),第一IRB(IRB1)接口部署在第一网关,第一接入设备(VM1(虚拟机1))接入所述第一接入环。第二VXLAN隧道端点VTEP2和第二网关GW2属于第二接入环(接入环2),第二IRB(IRB2)接口部署在第二网关,第二接入设备(VM2(虚拟机2))接入所述第二接入环。第三VXLAN隧道端点VTEP3和第三网关GW3属于第三接入环(接入环3),第三IRB(IRB3)接口部署在第三网关,第三接入设备(VM3(虚拟机3))接入所述第三接入环。GW1、GW2和GW3属于同一个核心环。其中,接入环是接入层和汇聚层的设备通过环形组网建立的网络。核心环是核心层和汇聚层的设备通过环形组网建立的网络。汇聚层位于接入层和核心层之间,起到接入层和核心层之间通信桥梁的作用。
GW1和VTEP1之间是第一VXLAN隧道,GW2和VTEP2之间是第二VXLAN隧道,GW3和VTEP3之间是第三VXLAN隧道。
GW1向GW2和GW3通告第一EVPN MAC/IP通告路由,其中携带IRB1的三层转发信息。GW3向GW1和GW2通告第三EVPN MAC/IP通告路由,其中携带IRB3的三层转发信息。第一EVPN MAC/IP通告路由携带的三层转发信息可以在GW2上生成24位掩码的网段路由条目,第三EVPN MAC/IP通告路由携带的三层转发信息也可以在GW2上生成24位掩码的网段路由条目。假设VM1、VM3、IRB1和IRB3都处于相同网段,IRB3与IRB1的IP地址相同,那么当第二接入环内的VM2向第三接入环内的VM3发送报文时,GW2查询VM3所在的网段的路由转发条目,查询到由GW1进行转发的路由和由GW3进行转发的路由,根据路由优先级的高低从相同网段的路由条目中选择路由优先级最高的路由条目。假设由GW1进行转发的路由的优先级高于由GW3进行转发的路由的优先级,则GW2上到所述网段的路由下一跳是GW1的三层接口IRB1。因此,GW2将发给VM3的报文首先发给GW1,GW1通过二层转发再将报文转发到GW3上,并最终发送到VM3。由于发送给第三接入环内的VM3的流量 通过第一接入环内的GW1转发给第三接入环的GW3,因此产生了流量绕行的问题。
因此,相关技术中跨以太虚拟专用网络接入环通信时,存在流量绕行的现象,降低了传输效率,增加了网络资源的消耗。
发明内容
本公开提供一种防止流量绕行的方法及装置,能够在跨以太虚拟专用网络接入环通信时防止流量绕行,提高传输效率。
根据本申请的第一方面,本发明实施例提供一种防止流量绕行的方法,包括:向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。
根据本申请的第二方面,本发明实施例提供一种防止流量绕行的装置,应用于以太虚拟专用网络EVPN的网关,包括:路由通告模块,设置为向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;明细路由生成模块,设置为接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;报文转发模块,设置为 向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。
根据本申请的第三方面,本发明实施例提供一种防止流量绕行的装置,包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的防止流量绕行的程序,所述防止流量绕行的程序被所述处理器执行时实现上述防止流量绕行的方法的步骤。
根据本申请的第四方面,本发明实施例提供一种计算机可读存储介质,所述计算机可读存储介质上存储有防止流量绕行的程序,所述防止流量绕行的程序被处理器执行时实现上述防止流量绕行的方法的步骤。
与相关技术相比,本发明实施例提供的一种防止流量绕行的方法及装置,第一网关向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。本发明实施例的技术方案能够在跨以太虚拟专用网络接入环通信时防止流量绕行,提高传输效率。
附图说明
图1为现有技术中以太虚拟专用网络跨接入环通信架构的示意图;
图2为本发明实施例1的一种防止流量绕行的方法的流程图;
图3为本发明实施例2的一种防止流量绕行的装置的示意图;
图4为本发明示例1的一种防止流量绕行的方法的流程图;
图5为本发明示例2的一种防止流量绕行的方法的流程图。
具体实施方式
为使本发明的目的、技术方案和优点更加清楚明白,下文中将结合附图对本发明的实施例进行详细说明。需要说明的是,在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互任意组合。
在附图的流程图示出的步骤可以在诸如一组计算机可执行指令的计算机系统中执行。并且,虽然在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于此处的顺序执行所示出或描述的步骤。
实施例1
如图2所示,本发明实施例提供了一种防止流量绕行的方法,应用于以太虚拟专用网络EVPN的网关,包括:
步骤S210,向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;
步骤S220,接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;
步骤S230,向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关;
其中,明细路由是比网段路由掩码位数更多的路由;比如,网段路由是指24位掩码的路由,明细路由是指32位掩码的路由;也即,明细路由 相比网段路由,匹配的IP前缀位数更多,匹配更精确。
在一种实施方式中,向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由之前,所述方法还包括:
接收所述第一接入环的第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由;
其中,所述第一接入设备的EVPN MAC/IP通告路由携带以下信息:
MAC地址字段携带所述第一接入设备的MAC地址信息;IP地址字段携带所述第一接入设备的IP地址信息;多协议标签交换标签1字段携带所述第一接入环的二层可扩展虚拟局域网网络标识VNI(VXLAN Network identifier)信息;下一跳属性携带所述第一可扩展虚拟局域网隧道端点的IP地址信息;
在一种实施方式中,向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,包括:
对第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由进行修改,将修改后的第一接入设备的EVPN MAC/IP通告路由通告给其他网关;
其中,所述修改包括以下内容:将多协议标签交换标签1字段修改为携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;在多协议标签交换标签2字段携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;将下一跳属性修改为携带本网关的IP地址信息;新增“路由的MAC”扩展属性,在所述“路由的MAC”扩展属性中携带第一接入设备的MAC地址信息。
在一种实施方式中,向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由之前,所述方法还包括:
接收所述第一接入环的第一可扩展虚拟局域网隧道端点通告的第一 接入设备的EVPN MAC/IP通告路由;
其中,所述第一接入设备的EVPN MAC/IP通告路由携带以下信息:
MAC地址字段携带所述第一接入设备的MAC地址信息;IP地址字段携带所述第一接入设备的IP地址信息;多协议标签交换标签1字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;多协议标签交换标签2字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;下一跳属性携带所述第一可扩展虚拟局域网隧道端点的IP地址信息;“路由的MAC”扩展属性携带第一接入设备的MAC地址信息;
在一种实施方式中,向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,包括:
对第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由进行修改,将修改后的第一接入设备的EVPN MAC/IP通告路由通告给其他网关;
其中,所述修改包括以下内容:将多协议标签交换标签1字段修改为携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;将多协议标签交换标签2字段修改为携带本网关所在核心环的三层可扩展虚拟局域网网络标识信息;下一跳属性的取值修改为携带本网关的IP地址信息;将“路由的MAC”扩展属性的取值修改为携带本网关的MAC地址信息。
在一种实施方式中,所述第二接入设备的EVPN MAC/IP通告路由中携带所述第二接入设备的二层转发信息和三层转发信息,包括:
MAC地址字段携带第二接入设备的MAC地址;
IP地址字段携带第二接入设备的IP地址;
多协议标签交换标签1字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
多协议标签交换标签2字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
下一跳属性携带第二网关的IP地址信息;
“路由的MAC”扩展属性携带第二接入设备的MAC地址信息;
在一种实施方式中,所述第二接入设备的EVPN MAC/IP通告路由中携带所述第二接入设备的二层转发信息和三层转发信息,包括:
MAC地址字段携带第二接入设备的MAC地址;
IP地址字段携带第二接入设备的IP地址;
多协议标签交换标签1字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
多协议标签交换标签2字段携带第二网关所在核心环的三层可扩展虚拟局域网网络标识信息;
下一跳属性携带第二网关的IP地址信息;
“路由的MAC”扩展属性携带第二网关的MAC地址信息。
实施例2
如图3所示,本发明实施例提供了一种防止流量绕行的装置,应用于以太虚拟专用网络EVPN的网关,包括:
路由通告模块10,设置为向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;
明细路由生成模块20,设置为接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;
报文转发模块30,设置为向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后 的报文转发至所述第二网关;
在一种实施方式中,所述装置还包括:第一路由通告接收模块40;
所述第一路由通告接收模块,设置为接收所述第一接入环的第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由;
其中,所述第一接入设备的EVPN MAC/IP通告路由携带以下信息:
MAC地址字段携带所述第一接入设备的MAC地址信息;IP地址字段携带所述第一接入设备的IP地址信息;多协议标签交换标签1字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;下一跳属性携带所述第一可扩展虚拟局域网隧道端点的IP地址信息。
在一种实施方式中,所述路由通告模块,设置为采用以下方式向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由:
对第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由进行修改,将修改后的第一接入设备的EVPN MAC/IP通告路由通告给其他网关;
其中,所述修改包括以下内容:将多协议标签交换标签1字段修改为携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;在多协议标签交换标签2字段携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;将下一跳属性修改为携带本网关的IP地址信息;新增“路由的MAC”扩展属性,在所述“路由的MAC”扩展属性中携带第一接入设备的MAC地址信息。
在一种实施方式中,所述装置还包括:第二路由通告接收模块60;
所述第二路由通告接收模块,设置为接收所述第一接入环的第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由;
其中,所述第一接入设备的EVPN MAC/IP通告路由携带以下信息:
MAC地址字段携带所述第一接入设备的MAC地址信息;IP地址字 段携带所述第一接入设备的IP地址信息;多协议标签交换标签1字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;多协议标签交换标签2字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;下一跳属性携带所述第一可扩展虚拟局域网隧道端点的IP地址信息;“路由的MAC”扩展属性携带第一接入设备的MAC地址信息。
在一种实施方式中,所述路由通告模块,设置为采用以下方式向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由:
对第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由进行修改,将修改后的第一接入设备的EVPN MAC/IP通告路由通告给其他网关;
其中,所述修改包括以下内容:将多协议标签交换标签1字段修改为携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;将多协议标签交换标签2字段修改为携带本网关所在核心环的三层可扩展虚拟局域网网络标识信息;下一跳属性的取值修改为携带本网关的IP地址信息;将“路由的MAC”扩展属性的取值修改为携带本网关的MAC地址信息。
在一种实施方式中,所述第二接入设备的EVPN MAC/IP通告路由中携带所述第二接入设备的二层转发信息和三层转发信息,包括:
MAC地址字段携带第二接入设备的MAC地址;
IP地址字段携带第二接入设备的IP地址;
多协议标签交换标签1字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
多协议标签交换标签2字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
下一跳属性携带第二网关的IP地址信息;
“路由的MAC”扩展属性携带第二接入设备的MAC地址信息。
在一种实施方式中,所述第二接入设备的EVPN MAC/IP通告路由中携带所述第二接入设备的二层转发信息和三层转发信息,包括:
MAC地址字段携带第二接入设备的MAC地址;
IP地址字段携带第二接入设备的IP地址;
多协议标签交换标签1字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
多协议标签交换标签2字段携带第二网关所在核心环的三层可扩展虚拟局域网网络标识信息;
下一跳属性携带第二网关的IP地址信息;
“路由的MAC”扩展属性携带第二网关的MAC地址信息。
实施例3
本发明实施例提供了一种防止流量绕行的装置,包括:
存储器、处理器及存储在所述存储器上并可在所述处理器上运行的防止流量绕行的程序,所述防止流量绕行的程序被所述处理器执行时实现上述实施例1中的防止流量绕行的方法的步骤。
实施例4
本发明实施例提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有防止流量绕行的程序,所述实防止流量绕行的程序被处理器执行时实现上述实施例1中的防止流量绕行的方法的步骤。
示例1
在图1所示的以太虚拟专用网络中,第一VXLAN隧道端点VTEP1和第一网关GW1属于第一接入环(接入环1),第一IRB(IRB1)接口部 署在第一网关,第一接入设备(VM1(虚拟机1))接入所述第一接入环。第二VXLAN隧道端点VTEP2和第二网关GW2属于第二接入环(接入环2),第二IRB(IRB2)接口部署在第二网关,第二接入设备(VM2(虚拟机2))接入所述第二接入环。第三VXLAN隧道端点VTEP3和第三网关GW3属于第三接入环(接入环3),第三IRB(IRB3)接口部署在第三网关,第三接入设备(VM3(虚拟机3))接入所述第三接入环。GW1、GW2和GW3属于同一个核心环。VM1和VM3在同一个网段。GW1和VTEP1之间是第一VXLAN隧道,GW2和VTEP2之间是第二VXLAN隧道,GW3和VTEP3之间是第三VXLAN隧道。
第二接入设备(VM2)想要给第一接入设备(VM1)发送报文,采用本申请的防止流量绕行的方法后,GW2上生成VM1的明细路由,报文能够直接发送给第一接入环的第一网关GW1而不会绕行其他网关(比如,GW3)。
如图4所示,一种防止流量绕行的方法可以包括以下步骤:
S101:VTEP1向GW1通告第一EVPN MAC/IP通告路由,所述第一EVPN MAC/IP通告路由包括以下内容:MAC地址字段携带VM1的MAC地址信息,IP地址字段携带VM1的IP地址信息,MPLS标签1字段携带第一接入环的二层VNI信息,下一跳属性携带VTEP1的IP地址信息;
S102:GW1接收到所述第一EVPN MAC/IP通告路由,在本地MAC-VRF(Virtual Routing Forwarding,虚拟路由转发)表中形成MAC条目;
其中,GW1确定第一EVPN MAC/IP通告路由中携带MPLS标签1而没有携带MPLS标签2,在本地MAC-VRF表中形成MAC条目。
其中,所述MAC条目的目的MAC字段的取值设置为VM1的MAC地址,所述MAC条目的出接口字段的取值设置为GW1到VTEP1的第一VXLAN隧道;所述第一VXLAN隧道的目的IP是VTEP1的IP,所述第一VXLAN隧道的VNI是第一接入环的二层VNI;
S103:GW1修改第一EVPN MAC/IP通告路由,修改后的第一EVPN MAC/IP通告路由包括以下内容:MAC地址字段携带VM1的MAC地址信息,IP地址字段携带VM1的IP地址信息,MPLS标签1字段携带核心环的二层VNI信息,MPLS标签2字段携带核心环的二层VNI信息,下一跳属性携带GW1的IP地址信息,“路由的MAC”扩展属性携带VM1的MAC地址信息。
其中,MPLS标签2字段是可选字段,如果EVPN MAC/IP通告路由中携带MPLS标签2字段,则通告路由的接收方会在IP-VRF表中生成明细路由。
S104:GW1将修改后的第一EVPN MAC/IP通告路由通告给GW2和GW3;
S105:GW2收到GW1通告过来的第一EVPN MAC/IP通告路由,在IP-VRF转发表中形成VM1的明细路由;
其中,所述VM1的明细路由中,目的IP地址设置为第一EVPN MAC/IP通告路由的IP地址字段的取值(也即VM1的IP地址),下一跳取值是GW1的IP地址(IRB1的IP地址),出接口是GW2到GW1的VXLAN隧道,所述GW2到GW1的VXLAN隧道的VNI是核心环的二层VNI(也即第一EVPN MAC/IP通告路由的MPLS Label2字段的取值)。
S106,GW2在收到VTEP2发来的需要转发给VM1的报文,根据VM1的IP地址查询IP-VRF转发表,匹配到VM1的明细路由,根据所述VM1的明细路由对报文进行二层封装和三层封装并转发至GW1;
其中,为原始报文封装内层MAC头,所述内层MAC头的目的MAC字段设置为VM1的MAC地址,源MAC字段设置为GW2的MAC地址。然后封装VXLAN头,所述VXLAN头的VNI字段设置为核心环的二层VNI。然后封装外层IP头,所述外层IP头的目的IP字段设置为GW1的IP地址。
S107,GW1接收到GW2转发的报文,解析报文的VXLAN头,根据 所述VXLAN头的VNI字段去查找MAC-VRF表,根据所述MAC-VRF表中的MAC转发条目,将报文发送给VTEP1,再由VTEP1转发给VM1。
在上述示例1中,GW2接收到GW1通告的第一EVPN MAC/IP通告路由后生成VM1的明细路由,根据所述VM1的明细路由能够将目的地址为VM1的报文直接转发给GW1,而不会出现流量绕行其他网关的现象。
示例2
在图1所示的以太虚拟专用网络中,第一VXLAN隧道端点VTEP1和第一网关GW1属于第一接入环(接入环1),第一IRB(IRB1)接口部署在第一网关,第一接入设备(VM1(虚拟机1))接入所述第一接入环。第二VXLAN隧道端点VTEP2和第二网关GW2属于第二接入环(接入环2),第二IRB(IRB2)接口部署在第二网关,第二接入设备(VM2(虚拟机2))接入所述第二接入环。第三VXLAN隧道端点VTEP3和第三网关GW3属于第三接入环(接入环3),第三IRB(IRB3)接口部署在第三网关,第三接入设备(VM3(虚拟机3))接入所述第三接入环。GW1、GW2和GW3属于同一个核心环。VM1和VM3在同一个网段。GW1和VTEP1之间是第一VXLAN隧道,GW2和VTEP2之间是第二VXLAN隧道,GW3和VTEP3之间是第三VXLAN隧道。
第二接入设备(VM2)想要给第一接入设备(VM1)发送报文,采用本申请的防止流量绕行的方法后,GW2上生成VM1的明细路由,报文能够直接发送给第一接入环的第一网关GW1而不会绕行其他网关(比如,GW3)。
如图5所示,一种防止流量绕行的方法可以包括以下步骤:
S101:VTEP1向GW1通告第一EVPN MAC/IP通告路由,所述第一EVPN MAC/IP通告路由包括以下内容:MAC地址字段携带VM1的MAC地址信息,IP地址字段携带VM1的IP地址信息,MPLS标签1字段携带第一接入环的二层VNI信息,MPLS标签2字段携带第一接入环的二层 VNI信息,下一跳属性携带VTEP1的IP地址信息,“路由的MAC”扩展属性携带VM1的MAC地址信息;
S102:GW1收到第一EVPN MAC/IP通告路由,在本地IP-VRF表中形成VM1的明细路由;
其中,GW1确定第一EVPN MAC/IP通告路由中同时携带MPLS标签1和MPLS标签2,在本地IP-VRF表中形成VM1的明细路由。
所述VM1的明细路由中,目的IP地址设置为第一EVPN MAC/IP通告路由的IP地址字段的取值(也即VM1的IP地址),下一跳取值是VTEP1的IP地址,出接口是GW1到VTEP1的第一VXLAN隧道,所述第一VXLAN隧道的VNI是第一接入环的二层VNI(也即第一EVPN MAC/IP通告路由的MPLS Label2字段的取值)。
S103:GW1修改第一EVPN MAC/IP通告路由,修改后的第一EVPN MAC/IP通告路由包括以下内容:MAC地址字段携带VM1的MAC地址信息,IP地址字段携带VM1的IP地址信息,MPLS标签1字段携带核心环的二层VNI信息,MPLS标签2字段携带核心环的三层VNI信息,下一跳属性携带GW1的IP地址信息,“路由的MAC”扩展属性携带GW1的MAC地址信息。
S104:GW1将修改后的第一EVPN MAC/IP通告路由通告给GW2和GW3;
S105:GW2收到GW1通告过来的第一EVPN MAC/IP通告路由,在IP-VRF转发表中形成VM1的明细路由;
其中,所述VM1的明细路由中,目的IP地址设置为第一EVPN MAC/IP通告路由的IP地址字段的取值(也即VM1的IP地址),下一跳取值是GW1的IP地址(IRB1的IP地址),出接口是GW2到GW1的VXLAN隧道,所述GW2到GW1的VXLAN隧道的VNI是核心环的三层VNI(也即第一EVPN MAC/IP通告路由的MPLS Label2字段的取值)。
S106,GW2在收到VTEP2发来的需要转发给VM1的报文,根据VM1 的IP地址查询IP-VRF转发表,匹配到VM1的明细路由,根据所述VM1的明细路由对报文进行二层封装和三层封装并转发至GW1;
其中,为原始报文封装内层MAC头,所述内层MAC头的目的MAC字段设置为VM1的MAC地址,源MAC字段设置为GW2的MAC地址。然后封装VXLAN头,所述VXLAN头的VNI字段设置为核心环的三层VNI。然后封装外层IP头,所述外层IP头的目的IP字段设置为GW1的IP地址。
S107,GW1接收到GW2转发的报文,解析报文的VXLAN头,根据所述VXLAN头的VNI字段去查找IP-VRF表,根据所述IP-VRF表中的路由转发条目,将报文发送给VTEP1,再由VTEP1转发给VM1。
在上述示例2中,GW2接收到GW1通告的第一EVPN MAC/IP通告路由后生成VM1的明细路由,根据所述VM1的明细路由能够将目的地址为VM1的报文直接转发给GW1,而不会出现流量绕行其他网关的现象。
本领域普通技术人员可以理解,上文中所公开方法中的全部或某些步骤、系统、装置中的功能模块/单元可以被实施为软件、固件、硬件及其适当的组合。在硬件实施方式中,在以上描述中提及的功能模块/单元之间的划分不一定对应于物理组件的划分;例如,一个物理组件可以具有多个功能,或者一个功能或步骤可以由若干物理组件合作执行。某些物理组件或所有物理组件可以被实施为由处理器,如中央处理器、数字信号处理器或微处理器执行的软件,或者被实施为硬件,或者被实施为集成电路,如专用集成电路。这样的软件可以分布在计算机可读介质上,计算机可读介质可以包括计算机存储介质(或非暂时性介质)和通信介质(或暂时性介质)。如本领域普通技术人员公知的,术语计算机存储介质包括在用于存储信息(诸如计算机可读指令、数据结构、程序模块或其他数据)的任何方法或技术中实施的易失性和非易失性、可移除和不可移除介质。计算机存储介质包括但不限于RAM、ROM、EEPROM、闪存或其他存储器 技术、CD-ROM、数字多功能盘(DVD)或其他光盘存储、磁盒、磁带、磁盘存储或其他磁存储装置、或者可以用于存储期望的信息并且可以被计算机访问的任何其他的介质。此外,本领域普通技术人员公知的是,通信介质通常包含计算机可读指令、数据结构、程序模块或者诸如载波或其他传输机制之类的调制数据信号中的其他数据,并且可包括任何信息递送介质。
需要说明的是,本发明还可有其他多种实施例,在不背离本发明精神及其实质的情况下,熟悉本领域的技术人员可根据本发明作出各种相应的改变和变形,但这些相应的改变和变形都应属于本发明所附的权利要求的保护范围。
工业实用性
本发明实施例提供的一种防止流量绕行的方法及装置,第一网关向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。本发明实施例的技术方案能够在跨以太虚拟专用网络接入环通信时防止流量绕行,提高传输效率。

Claims (10)

  1. 一种防止流量绕行的方法,应用于以太虚拟专用网络EVPN的网关,包括:
    向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;
    接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;
    向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。
  2. 如权利要求1所述的方法,其中:
    向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由之前,所述方法还包括:
    接收所述第一接入环的第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由;
    其中,所述第一接入设备的EVPN MAC/IP通告路由携带以下信息:
    MAC地址字段携带所述第一接入设备的MAC地址信息;IP地址字段携带所述第一接入设备的IP地址信息;多协议标签交换标签1字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;下一跳属性携带所述第一可扩展虚拟局域网隧道端点的IP地址信息。
  3. 如权利要求2所述的方法,其中:
    向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,包括:
    对第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN  MAC/IP通告路由进行修改,将修改后的第一接入设备的EVPN MAC/IP通告路由通告给其他网关;
    其中,所述修改包括以下内容:将多协议标签交换标签1字段修改为携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;在多协议标签交换标签2字段携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;将下一跳属性修改为携带本网关的IP地址信息;新增“路由的MAC”扩展属性,在所述“路由的MAC”扩展属性中携带第一接入设备的MAC地址信息。
  4. 如权利要求1所述的方法,其中:
    向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由之前,所述方法还包括:
    接收所述第一接入环的第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由;
    其中,所述第一接入设备的EVPN MAC/IP通告路由携带以下信息:
    MAC地址字段携带所述第一接入设备的MAC地址信息;IP地址字段携带所述第一接入设备的IP地址信息;多协议标签交换标签1字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;多协议标签交换标签2字段携带所述第一接入环的二层可扩展虚拟局域网网络标识信息;下一跳属性携带所述第一可扩展虚拟局域网隧道端点的IP地址信息;“路由的MAC”扩展属性携带第一接入设备的MAC地址信息。
  5. 如权利要求4所述的方法,其中:
    向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,包括:
    对第一可扩展虚拟局域网隧道端点通告的第一接入设备的EVPN MAC/IP通告路由进行修改,将修改后的第一接入设备的EVPN MAC/IP通告路由通告给其他网关;
    其中,所述修改包括以下内容:将多协议标签交换标签1字段修改为携带本网关所在核心环的二层可扩展虚拟局域网网络标识信息;将多协议标签交换标签2字段修改为携带本网关所在核心环的三层可扩展虚拟局域网网络标识信息;下一跳属性的取值修改为携带本网关的IP地址信息;将“路由的MAC”扩展属性的取值修改为携带本网关的MAC地址信息。
  6. 如权利要求1或2或3所述的方法,其中:
    所述第二接入设备的EVPN MAC/IP通告路由中携带所述第二接入设备的二层转发信息和三层转发信息,包括:
    MAC地址字段携带第二接入设备的MAC地址;
    IP地址字段携带第二接入设备的IP地址;
    多协议标签交换标签1字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
    多协议标签交换标签2字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
    下一跳属性携带第二网关的IP地址信息;
    “路由的MAC”扩展属性携带第二接入设备的MAC地址信息。
  7. 如权利要求1或4或5所述的方法,其中:
    所述第二接入设备的EVPN MAC/IP通告路由中携带所述第二接入设备的二层转发信息和三层转发信息,包括:
    MAC地址字段携带第二接入设备的MAC地址;
    IP地址字段携带第二接入设备的IP地址;
    多协议标签交换标签1字段携带第二网关所在核心环的二层可扩展虚拟局域网网络标识信息;
    多协议标签交换标签2字段携带第二网关所在核心环的三层可扩展虚拟局域网网络标识信息;
    下一跳属性携带第二网关的IP地址信息;
    “路由的MAC”扩展属性携带第二网关的MAC地址信息。
  8. 一种防止流量绕行的装置,应用于以太虚拟专用网络EVPN的网关,包括:
    路由通告模块,设置为向其他网关通告本网关所在第一接入环内的第一接入设备的EVPN媒体访问控制MAC/互联网协议IP通告路由,所述第一接入设备的EVPN MAC/IP通告路由携带所述第一接入设备的二层转发信息和三层转发信息;
    明细路由生成模块,设置为接收到第二接入环内的第二网关通告的所述第二接入环内的第二接入设备的EVPN MAC/IP通告路由,根据所述第二接入设备的EVPN MAC/IP通告路由中携带的所述第二接入设备的二层转发信息和三层转发信息生成所述第二接入设备的明细路由;
    报文转发模块,设置为向所述第二接入设备转发报文时,根据所述第二接入设备的明细路由对所述报文进行二层封装和三层封装,将封装后的报文转发至所述第二网关。
  9. 一种防止流量绕行的装置,包括:存储器、处理器及存储在所述存储器上并可在所述处理器上运行的防止流量绕行的程序,所述防止流量绕行的程序被所述处理器执行时实现上述权利要求1至7中任一项所述的防止流量绕行的方法的步骤。
  10. 一种计算机可读存储介质,所述计算机可读存储介质上存储有防止流量绕行的程序,所述防止流量绕行的程序被处理器执行时实现上述权利要求1至7中任一项所述的防止流量绕行的方法的步骤。
PCT/CN2020/099022 2019-09-16 2020-06-29 一种防止流量绕行的方法及装置 WO2021051935A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP20864927.7A EP4020903A4 (en) 2019-09-16 2020-06-29 METHOD AND APPARATUS FOR PREVENTING TRAFFIC BYPASS

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201910871043.XA CN112511398B (zh) 2019-09-16 2019-09-16 一种防止流量绕行的方法及装置
CN201910871043.X 2019-09-16

Publications (1)

Publication Number Publication Date
WO2021051935A1 true WO2021051935A1 (zh) 2021-03-25

Family

ID=74883951

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/099022 WO2021051935A1 (zh) 2019-09-16 2020-06-29 一种防止流量绕行的方法及装置

Country Status (3)

Country Link
EP (1) EP4020903A4 (zh)
CN (1) CN112511398B (zh)
WO (1) WO2021051935A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114338507B (zh) * 2021-12-23 2022-11-22 武汉绿色网络信息服务有限责任公司 一种实现改变云网关系统中流量转发路径的方法和装置
CN117377020A (zh) * 2022-06-30 2024-01-09 中兴通讯股份有限公司 路由发布方法、电子设备和计算机可读存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107124347A (zh) * 2017-06-13 2017-09-01 杭州迪普科技股份有限公司 一种基于bgp evpn的vxlan控制平面的优化方法及装置
CN107342941A (zh) * 2017-06-01 2017-11-10 杭州迪普科技股份有限公司 一种vxlan控制平面的优化方法及装置
CN108322376A (zh) * 2017-06-26 2018-07-24 新华三技术有限公司 路由同步方法、装置及机器可读存储介质
CN108924052A (zh) * 2018-07-17 2018-11-30 迈普通信技术股份有限公司 报文转发方法、汇聚网关、接入网关及系统
CN109729010A (zh) * 2017-10-27 2019-05-07 华为技术有限公司 一种网络中确定流量传输路径的方法、设备和系统

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2015180084A1 (zh) * 2014-05-29 2015-12-03 华为技术有限公司 一种报文转发方法和VxLAN网关
US20170373973A1 (en) * 2016-06-27 2017-12-28 Juniper Networks, Inc. Signaling ip address mobility in ethernet virtual private networks
CN108199945B (zh) * 2017-12-23 2019-10-01 华为技术有限公司 报文传输方法、网络设备及报文处理系统
CN108306825B (zh) * 2018-01-31 2021-06-29 新华三技术有限公司 一种等价转发表项生成方法和vtep设备

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107342941A (zh) * 2017-06-01 2017-11-10 杭州迪普科技股份有限公司 一种vxlan控制平面的优化方法及装置
CN107124347A (zh) * 2017-06-13 2017-09-01 杭州迪普科技股份有限公司 一种基于bgp evpn的vxlan控制平面的优化方法及装置
CN108322376A (zh) * 2017-06-26 2018-07-24 新华三技术有限公司 路由同步方法、装置及机器可读存储介质
CN109729010A (zh) * 2017-10-27 2019-05-07 华为技术有限公司 一种网络中确定流量传输路径的方法、设备和系统
CN108924052A (zh) * 2018-07-17 2018-11-30 迈普通信技术股份有限公司 报文转发方法、汇聚网关、接入网关及系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP4020903A4 *

Also Published As

Publication number Publication date
EP4020903A1 (en) 2022-06-29
CN112511398A (zh) 2021-03-16
CN112511398B (zh) 2023-11-28
EP4020903A4 (en) 2022-09-07

Similar Documents

Publication Publication Date Title
EP3836490B1 (en) Vpn cross-domain implementation method, device, and border node
US10484203B2 (en) Method for implementing communication between NVO3 network and MPLS network, and apparatus
WO2020182086A1 (zh) 一种bier报文的发送方法和装置
CN111786884B (zh) 一种路由方法及路由设备
JP7405923B2 (ja) 通信方法、デバイス、及びシステム
US8898334B2 (en) System for network deployment and method for mapping and data forwarding thereof
US11671352B2 (en) Message sending method, binding relationship advertising method, apparatus, and storage medium
WO2022048417A1 (zh) 报文处理方法、边界设备和计算机可读存储介质
WO2021135624A1 (zh) 基于虚电路的数据报文处理方法、转发表项的构建方法
WO2021051935A1 (zh) 一种防止流量绕行的方法及装置
WO2022184169A1 (zh) 报文转发方法、系统、存储介质及电子装置
US11929923B2 (en) Packet transmission method and apparatus
US11824779B2 (en) Traffic forwarding processing method and device
WO2023274083A1 (zh) 路由发布和转发报文的方法、装置、设备和存储介质
CN113726653B (zh) 报文处理方法及装置
WO2021017590A1 (zh) 一种实现dci三层通信的方法、系统及第一gw
WO2020244304A1 (zh) 路由信息发送的方法、路由选路的方法和装置
CN112291234B (zh) 流量回注方法、装置、设备及计算机可读存储介质
RU2777661C1 (ru) Способ и устройство для предотвращения обхода трафика
WO2021259271A1 (zh) 信息处理方法、节点及存储介质
WO2024001553A1 (zh) 路由发布方法、电子设备和计算机可读存储介质
JP2023551938A (ja) パケット送信方法、対応関係取得方法、装置、およびシステム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20864927

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2020864927

Country of ref document: EP

Effective date: 20220323