WO2024222010A1 - 地址请求报文代答方法、装置、电子设备及存储介质 - Google Patents
地址请求报文代答方法、装置、电子设备及存储介质 Download PDFInfo
- Publication number
- WO2024222010A1 WO2024222010A1 PCT/CN2023/142081 CN2023142081W WO2024222010A1 WO 2024222010 A1 WO2024222010 A1 WO 2024222010A1 CN 2023142081 W CN2023142081 W CN 2023142081W WO 2024222010 A1 WO2024222010 A1 WO 2024222010A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network address
- tunnel
- address
- tunnel endpoint
- request message
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/25—Mapping addresses of the same type
- H04L61/2503—Translation of Internet protocol [IP] addresses
- H04L61/2592—Translation of Internet protocol [IP] addresses using tunnelling or encapsulation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4633—Interconnection of networks using encapsulation techniques, e.g. tunneling
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L47/00—Traffic control in data switching networks
- H04L47/10—Flow control; Congestion control
- H04L47/12—Avoiding congestion; Recovering from congestion
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/09—Mapping addresses
- H04L61/10—Mapping addresses of different types
- H04L61/103—Mapping addresses of different types across network layers, e.g. resolution of network layer into physical layer addresses or address resolution protocol [ARP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/59—Network arrangements, protocols or services for addressing or naming using proxies for addressing
Definitions
- the present application belongs to the field of communication technology, and in particular, relates to an address request message answering method, device, electronic device and non-volatile readable storage medium.
- VXLAN Virtual eXtensible local area network
- the access point of VXLAN is the virtual tunnel endpoint (VTEP).
- the local device in the VXLAN network will send Address Resolution Protocol (ARP) request messages to the corresponding VTEP.
- ARP Address Resolution Protocol
- VTEP can obtain the network address of the target device requested by the ARP request message from the VXLAN network, so that the local device and the target device can communicate based on the network address.
- Communication networks are generally configured with two types of tunnels: static tunnels and dynamic tunnels.
- static tunnels when a VTEP in a static tunnel receives an ARP request message, it broadcasts the ARP request message and obtains the network address of the target device from the VXLAN network by broadcasting, such as the medium access control (MAC) address.
- MAC medium access control
- the VXLAN network will experience message flooding, which will occupy a large amount of network resources and cause network performance to deteriorate.
- the present application provides an address request message answering method, device, electronic device and non-volatile readable storage medium to solve the problem of message flooding occupying a large amount of network resources and causing network performance degradation.
- some embodiments of the present application provide an address request message reply method, which is applied to a first tunnel endpoint, and the method includes:
- the first detection message is generated by the second tunnel endpoint according to the stored first network address, and the first network address is a network address of a first device corresponding to the second tunnel endpoint;
- a first target network address is obtained from the first network address, and the first target network address is sent to a second device to answer the first address request message; the first target network address is the first network address requested by the first address request message, and the second device is a device that sends the first address request message to the first tunnel endpoint.
- it also includes:
- the second network address is a network address of a third device corresponding to the first tunnel endpoint
- the second detection message is used for the second tunnel endpoint to obtain the second network address carried by the second detection message, and to obtain the first network address from the second network address when receiving the second address request message.
- the second target network address is a second network address requested by the second address request message
- the fourth device is a device that sends the second address request message to the second tunnel endpoint.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the method further includes:
- Generating a second detection message according to the second network address stored in the first tunnel endpoint includes:
- Sending a second detection message to the second tunnel endpoint includes:
- a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the method before generating the second detection message according to the second network address, the tunnel name, and the tunnel identifier stored in the first tunnel endpoint, the method further includes:
- Sending a second detection message to a second tunnel endpoint through the first target tunnel includes:
- a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the method further includes:
- Acquiring a first target network address from the first network address and sending the first target network address to the second device includes:
- a first target network address is obtained from the first network address stored in the first database, and the first target network address is sent to the second device.
- the method further comprises:
- the first network address stored in the first database is updated according to the latest first network address carried by the third detection message to obtain an updated first database; the third detection message is generated by the second tunnel endpoint according to the latest first network address;
- Acquiring a first target network address from a first network address stored in a first database includes:
- the first target network address is obtained from the first network addresses stored in the updated first database.
- the first network address stored in the first database is updated, and after obtaining the updated first database, the method further includes:
- the first timing parameter is used to characterize the duration of non-update of the first database
- the first network address stored in the first database is deleted.
- obtaining the first target network address from the first network address stored in the first database includes:
- a first network address corresponding to the first address identifier is obtained from the first network addresses stored in the first database, and is determined as the first target network address.
- Some embodiments of the present application propose an address request message reply method, which is applied to the second tunnel end.
- Points, methods include:
- the first network address is a network address of a first device corresponding to the second tunnel endpoint;
- a first detection message is sent to the first tunnel endpoint; the first detection message is used for the first tunnel endpoint to obtain a first network address, and upon receiving a first address request message, obtain a first target network address from the first network address, and send the first target network address to the second device to answer the first address request message; the first target network address is the first network address requested by the first address request message, and the second device is the device that sends the first address request message to the first tunnel endpoint.
- the method further comprises:
- the second detection message is generated by the first tunnel endpoint according to the stored second network address, and the second network address is a network address of a second device corresponding to the first tunnel endpoint;
- a second target network address is obtained from the second network address, and the second target network address is sent to a fourth device to answer the second address request message;
- the second target network address is the second network address requested by the second address request message, and the fourth device is a device that sends the second address request message to the second tunnel endpoint.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the method further includes:
- Generating a first detection message according to the first network address stored in the second tunnel endpoint includes:
- Sending a first detection message to a first tunnel endpoint includes:
- a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- the method before generating the first detection message according to the first network address, the tunnel name and the tunnel identifier stored in the second tunnel endpoint, the method further includes:
- Sending a first detection message to the first tunnel endpoint through the second target tunnel includes:
- a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- the method further includes:
- Acquiring a second target network address from the second network address, and sending the second target network address to the first device includes:
- the second target network address is acquired from the second network address stored in the second database, and the second target network address is sent to the fourth device.
- the method further comprises:
- the fourth detection message When receiving the fourth detection message sent by the first tunnel endpoint, updating the second network address stored in the second database according to the latest second network address carried by the fourth detection message to obtain an updated second database; the fourth detection message is generated by the first tunnel endpoint according to the latest second network address;
- Acquiring a second target network address from the second network address stored in the second database includes:
- the second target network address is obtained from the second network addresses stored in the updated second database.
- the second network address stored in the second database is updated, and after obtaining the updated second database, the method further includes:
- the preset second timing parameter is set to zero, and the second timing parameter is controlled to restart timing; the second timing parameter is used to represent the non-updated time of the second database;
- the second network address stored in the second database is deleted.
- obtaining the second target network address from the second network address stored in the second database includes:
- the second network address corresponding to the second address identifier is obtained from the second network addresses stored in the second database, and is determined as the second target network address.
- some embodiments of the present application provide an address request message answering device, which is applied to a first tunnel endpoint, and the device includes:
- a first receiving module used to receive a first detection message sent by a second tunnel endpoint
- a first acquisition module is used to acquire a first network address carried by a first detection message; the first detection message is generated by the second tunnel endpoint according to the stored first network address, and the first network address is a network address of a first device corresponding to the second tunnel endpoint;
- the first answering module is used to obtain the first target network address from the first network address when receiving the first address request message, and send the first target network address to the second device to answer the first address request message; the first target network address is the first network address requested by the first address request message, and the second device is the device that sends the first address request message to the first tunnel endpoint.
- the apparatus further comprises:
- a second generating module configured to generate a second detection message according to a second network address stored in the first tunnel endpoint; the second network address is a network address of a third device corresponding to the first tunnel endpoint;
- the second sending module is used to send a second detection message to the second tunnel endpoint; the second detection message is used for the second tunnel endpoint to obtain the second network address carried by the second detection message, and when receiving the second address request message, obtain the second target network address from the second network address, and send the second target network address to the fourth device to answer the second address request message; the second target network address is the second network address requested by the second address request message, and the fourth device is a device that sends the second address request message to the second tunnel endpoint.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the apparatus further includes:
- a second acquisition module used to acquire a tunnel name and a tunnel identifier of a static tunnel
- the second generation module is specifically used for:
- the second sending module is specifically used for:
- a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the apparatus further comprises:
- a first session module used for establishing a session between the first tunnel endpoint and the second tunnel endpoint according to the tunnel name and the tunnel identifier before the second generation module generates a second detection message according to the second network address, the tunnel name and the tunnel identifier stored in the first tunnel endpoint;
- the second sending module is further specifically used for:
- a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the apparatus further comprises:
- a first storage module configured to store the first network address in a first database after the first acquisition module acquires the first network address carried by the first detection message;
- the first answer module is specifically used for:
- a first target network address is obtained from the first network address stored in the first database, and the first target network address is sent to the second device.
- the apparatus further comprises:
- a first updating module is used to update the first network address stored in the first database according to the latest first network address carried in the third detection message when receiving the third detection message sent by the second tunnel endpoint, so as to obtain an updated first database; the third detection message is generated by the second tunnel endpoint according to the latest first network address;
- the first answering module is further specifically used to obtain the first target network address from the first network address stored in the updated first database.
- the apparatus further comprises:
- a first timing module configured for the first updating module to update the first network address stored in the first database according to the latest first network address carried by the third detection message, and after obtaining the updated first database, to reset the preset first timing parameter to zero and control the first timing parameter to restart timing; the first timing parameter is used to characterize the non-updated duration of the first database;
- the first deleting module is used to delete the first network address stored in the first database when the first timing parameter is greater than a preset time threshold.
- the first answering module is further configured to:
- a first network address corresponding to the first address identifier is obtained from the first network addresses stored in the first database, and is determined as the first target network address.
- some embodiments of the present application provide an address request message answering device, which is applied to a second tunnel endpoint, and the device includes:
- a first generating module configured to generate a first detection message according to a first network address stored in a second tunnel endpoint; the first network address is a network address of a first device corresponding to the second tunnel endpoint;
- the first sending module is used to send a first detection message to the first tunnel endpoint; the first detection message is used for the first tunnel endpoint to obtain a first network address, and when receiving a first address request message, obtain a first target network address from the first network address, and send the first target network address to the second device to answer the first address request message; the first target network address is the first network address requested by the first address request message, and the second device is a device that sends the first address request message to the first tunnel endpoint.
- the apparatus further comprises:
- a second receiving module used to receive a second detection message sent by the first tunnel endpoint
- a third acquisition module is used to acquire the second network address carried by the second detection message;
- the second detection message is generated by the first tunnel endpoint according to the stored second network address, and the second network address is the network address of the second device corresponding to the first tunnel endpoint;
- the second answering module is used to obtain the second target network address from the second network address when receiving the second address request message, and send the second target network address to the fourth device to answer the second address request message; the second target network address is the second network address requested by the second address request message, and the fourth device is the device that sends the second address request message to the second tunnel endpoint.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the apparatus further includes:
- a fourth acquisition module used to acquire a tunnel name and a tunnel identifier of a static tunnel
- the first generation module is specifically used for:
- the first sending module is specifically used for:
- a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- the apparatus further comprises:
- a second session module used for establishing a session between the first tunnel endpoint and the second tunnel endpoint according to the tunnel name and the tunnel identifier before the first generation module generates the first detection message according to the first network address, the tunnel name and the tunnel identifier stored in the second tunnel endpoint;
- the first sending module is further specifically used for:
- a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- the device after obtaining the second network address carried by the second detection message, the device further includes:
- a second storage module used for storing the second network address in a second database
- the second generation answering module is specifically used for:
- the second target network address is acquired from the second network address stored in the second database, and the second target network address is sent to the fourth device.
- the apparatus further comprises:
- a second updating module is used to update the second network address stored in the second database according to the latest second network address carried in the fourth detection message when receiving the fourth detection message sent by the first tunnel endpoint, so as to obtain an updated second database; the fourth detection message is generated by the first tunnel endpoint according to the latest second network address;
- the second generation answering module is also used for:
- the second target network address is obtained from the second network addresses stored in the updated second database.
- the second network address stored in the second database is updated, and after obtaining the updated second database, the device further includes:
- a second timing module used to reset a preset second timing parameter to zero and control the second timing parameter to restart timing; the second timing parameter is used to characterize the non-updated time of the second database;
- the second deleting module is used to delete the second network address stored in the second database when the second timing parameter is greater than a preset time threshold.
- the second answering module is further used to:
- a second network address corresponding to the second address identifier is obtained from the second network addresses stored in the second database, and is determined as the second target network address.
- some embodiments of the present application provide an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and running on the processor, wherein when the processor executes the program, it implements the address request message answering method of the first aspect or the second aspect.
- some embodiments of the present application provide a non-volatile readable storage medium.
- the electronic device can execute the address request message answering method of the first aspect or the second aspect.
- the first detection message since the first detection message is generated by the second tunnel endpoint according to the stored first network address, and the first network address is the network address of the first device corresponding to the second tunnel endpoint, the first detection message carries the network address of the first device corresponding to the second tunnel endpoint, and the first tunnel endpoint receives the first detection message sent by the second tunnel endpoint and obtains the first network address carried by the first detection message, then the first tunnel endpoint obtains the network address of the first device corresponding to the second tunnel endpoint, and when the second device sends the first address request message to the first tunnel endpoint and needs to request the network address of the first device corresponding to the second tunnel endpoint, the first tunnel endpoint can directly obtain the requested first target network address from the first network address and send the first target network address to the second device, thereby realizing the first tunnel endpoint to answer the first address request message on behalf of the first tunnel endpoint.
- the first tunnel endpoint can directly answer the first address request message based on the obtained first network address, avoiding the problem of message flooding caused by the VTEP broadcast message method in the related art, and can reduce the occupied network resources to a certain extent and improve network performance.
- FIG1 is a flowchart of a method for answering an address request message provided in some embodiments of the present application.
- FIG2 is a flowchart of another method for answering an address request message provided in some embodiments of the present application.
- FIG3 is a schematic diagram of ARP request message suppression in the related art
- FIG4 is a schematic diagram of ARP broadcast suppression in the related art
- FIG5 is a schematic diagram of an ARP proxy reply in the related art
- FIG6 is a schematic diagram of BFD (Bidirectional Forwarding Detection) remote MAC address publishing provided by some embodiments of the present application;
- BFD Bidirectional Forwarding Detection
- FIG7 is a schematic diagram of a service device architecture provided by some embodiments of the present application.
- FIG8 is a schematic diagram of a service control flow provided by some embodiments of the present application.
- FIG. 9 is a schematic diagram of a BFD keep-alive packet carrying a remote MAC address provided in some embodiments of the present application.
- FIG. 10 is a schematic diagram of a control flow of a BFD remote MAC address provided in some embodiments of the present application.
- FIG. 11 is a structural diagram of an address request message answering device provided in some embodiments of the present application.
- FIG. 12 is a structural diagram of another address request message answering device provided in some embodiments of the present application.
- FIG. 13 is a schematic diagram of an electronic device provided in some embodiments of the present application.
- FIG. 1 is a flowchart of a method for answering an address request message provided in some embodiments of the present application. As shown in FIG. 1 , the method is applied to a first tunnel endpoint, and the method includes:
- Step 101 Receive a first detection message sent by a second tunnel endpoint.
- the first tunnel endpoint and the second tunnel endpoint may be virtual tunnel endpoints (VTEPs) of a virtual local area network extension (VXLAN), and the first tunnel endpoint and the second tunnel endpoint may be connected via a tunnel.
- the tunnel is a virtual channel, and the two VXLAN communication parties, namely the first tunnel endpoint and the second tunnel endpoint, believe that they are communicating directly and are unaware of the existence of the underlying network.
- the first detection message may be a message for detecting a bidirectional forwarding path fault between a first tunnel endpoint and a second tunnel endpoint.
- a BFD message in a bidirectional forwarding detection (BFD) technology.
- the first detection message in addition to the content related to the bidirectional forwarding path fault detection, carries a first network address stored by the second tunnel endpoint, wherein the first network address is a network address of a local device learned by the second tunnel endpoint, and the network address may include an Internet protocol (IP) address and a medium access control (MAC) address.
- IP Internet protocol
- MAC medium access control
- BFD is a unified detection mechanism used to quickly detect and monitor the forwarding connectivity of links or IP routes in the network.
- BFD can establish a session between two network devices to detect the bidirectional forwarding path between network devices. After the session is established, a network device can periodically and quickly send BFD packets. If it does not receive a BFD packet from the peer network device within the detection time, it is considered that the bidirectional forwarding path between the two network devices has a fault, and the upper-layer application being served can be notified to perform corresponding fault processing.
- Step 102 obtaining the first network address carried by the first detection message; the first detection message is generated by the second tunnel endpoint according to the stored first network address, and the first network address is the network address of the first device corresponding to the second tunnel endpoint.
- the first device corresponding to the second tunnel endpoint may be a device connected to the second tunnel endpoint, and the first device may be one or more, which is not limited in some embodiments of the present application.
- the second tunnel endpoint may learn the network address of the connected first device, and specifically, may obtain and store the IP address and MAC address of the first device.
- the second tunnel endpoint when generating the first detection message, may add the first network address of each first device corresponding to the second tunnel endpoint to the field corresponding to the optional content according to the message format, so that the first detection message carries the first network address of each first device.
- the first detection message is a BFD message
- the first network address may be added to the optional content field after 48 bytes, so that the BFD message carries the first network address. This is only an example, and some embodiments of the present application do not limit this.
- the first tunnel endpoint receives the first detection message, can perform an unpacking operation, obtain the first network address from the first detection message, and store the first network address in a specified location, for example, it can be stored in a first database so that it can be queried and obtained from the first database when the first address request message is received.
- Step 103 when receiving the first address request message, obtain the first target network address from the first network address, and send the first target network address to the second device to answer the first address request message; the first target network address
- the network address is a first network address requested by the first address request message
- the second device is a device that sends the first address request message to the first tunnel endpoint.
- the second device may be one of the devices connected to the first tunnel endpoint, and the second device generates a first address request message according to the known IP address of the target device to be accessed and the MAC address of the requested target device, and sends the first address request message to the first tunnel endpoint.
- the target device may be any first device corresponding to the second tunnel endpoint.
- the first network address requested by the first address request message may be the MAC address of the target device, and the target device may be any first device corresponding to the second tunnel endpoint, that is, the first target network address may be the MAC address of any first device corresponding to the second tunnel endpoint.
- the first tunnel endpoint when a first address request message is received, can determine the IP address of the target device requested by the second device based on the first address request message, search and obtain the MAC address of the target device corresponding to the IP address of the target device from the stored first network address based on the IP address of the target device, as the first target network address, and send the first target network address, i.e., the MAC address of the target device, to the second device, thereby enabling the first tunnel endpoint to answer the first address request message, i.e., reply to the first target network address requested by the second device.
- the first address request message may be an ARP request message.
- the first tunnel endpoint When the first tunnel endpoint receives the ARP request message, it may obtain the MAC address of the target device corresponding to the IP address of the target device from the stored first network address according to the IP address of the target device requested by the ARP request message, and reply to the second device as the first target network address, thereby answering the ARP request message on behalf of the target device.
- the target device may be any first device corresponding to the second tunnel endpoint.
- the address request message reply method in some embodiments of the present application is compared to the related art in which VTEP broadcasts the ARP request message when it receives the ARP request message, and obtains the network address of the target device from the VXLAN network by broadcasting. This can avoid the first tunnel endpoint from broadcasting the first address request message.
- the first tunnel endpoint can directly reply to the address requested by the first address request message based on the obtained first network address, thereby avoiding the problem of message flooding. Further, it can reduce the occupied network resources and improve network performance.
- the first detection message since the first detection message is generated by the second tunnel endpoint according to the stored first network address, and the first network address is the network address of the first device corresponding to the second tunnel endpoint, the first detection message carries the network address of the first device corresponding to the second tunnel endpoint, and the first tunnel endpoint receives the first detection message sent by the second tunnel endpoint and obtains the first network address carried by the first detection message, then the first tunnel endpoint obtains the network address of the first device corresponding to the second tunnel endpoint, and when the second device sends the first address request message to the first tunnel endpoint and needs to request the network address of the first device corresponding to the second tunnel endpoint, the first tunnel endpoint can directly obtain the requested first target network address from the first network address and send the first target network address to the second device, thereby realizing the first tunnel endpoint to answer the first address request message on behalf of the first tunnel endpoint.
- the first tunnel endpoint can directly answer the first address request message based on the obtained first network address, avoiding the problem of message flooding caused by the VTEP broadcast message method in the related art, and can reduce the occupied network resources to a certain extent and improve network performance.
- the method further comprises:
- Step 201 generating a second detection message according to a second network address stored in a first tunnel endpoint; the second network address is a network address of a third device corresponding to the first tunnel endpoint.
- the third device corresponding to the first tunnel endpoint may be a device connected to the first tunnel endpoint.
- the third device may be one or more, and some embodiments of the present application do not limit this.
- the first tunnel endpoint may learn the network address of the connected third device. Specifically, it may obtain the IP address and MAC address of the third device and perform Row storage.
- the first tunnel endpoint may add the second network address of each third device corresponding to the first tunnel endpoint to the field corresponding to the optional content of the second detection message according to the message format of the detection message, and then determine the detection message with the second network address added as the second detection message, so that the second detection message carries the second network address of each third device.
- the second detection message is a BFD message
- the second network address may be added to the optional content field after 48 bytes of the BFD message, so that the BFD message carries the second network address. This is only an example, and some embodiments of the present application do not limit this.
- Step 202 sending a second detection message to the second tunnel endpoint;
- the second detection message is used for the second tunnel endpoint to obtain the second network address carried by the second detection message, and when receiving the second address request message, obtain the second target network address from the second network address, and send the second target network address to the fourth device to answer the second address request message;
- the second target network address is the second network address requested by the second address request message, and the fourth device is the device that sends the second address request message to the second tunnel endpoint.
- the first tunnel endpoint may send a second detection message to the second tunnel endpoint through a tunnel connected to the second tunnel endpoint.
- the second tunnel endpoint may perform an unpacking operation, obtain the second network address from the second detection message, and store the second network address in a specified location, for example, in a second database, so as to query and obtain the second address from the second database when receiving a second address request message.
- the fourth device may be one of the devices connected to the second tunnel endpoint, and the fourth device generates a second address request message according to the known IP address of the target device to be accessed and the MAC address of the requested target device, and sends the second address request message to the first tunnel endpoint.
- the target device may be any third device corresponding to the first tunnel endpoint.
- the second network address requested by the second address request message may be the MAC address of the target device, and the target device may be any third device corresponding to the first tunnel endpoint, that is, the second target network address may be the MAC address of any third device corresponding to the first tunnel endpoint.
- the second tunnel endpoint when a second address request message is received, can determine the IP address of the target device requested by the fourth device based on the second address request message, obtain the MAC address of the target device corresponding to the IP address of the target device from the stored second network address based on the IP address of the target device as the second target network address, and send the second target network address, i.e., the MAC address of the target device, to the fourth device, thereby enabling the second tunnel endpoint to answer the second address request message and reply to the second target network address requested by the fourth device.
- the second target network address i.e., the MAC address of the target device
- the second detection message since the second detection message is generated by the first tunnel endpoint according to the stored second network address, and the second network address is the network address of the third device corresponding to the first tunnel endpoint, the second detection message carries the network address of the third device corresponding to the first tunnel endpoint, and the first tunnel endpoint sends the second detection message to the second tunnel endpoint, so that the second tunnel endpoint receives and obtains the second network address carried by the second detection message, and the second tunnel endpoint obtains the network address of the third device corresponding to the first tunnel endpoint.
- the second tunnel endpoint can directly obtain the requested second target network address from the second network address, and send the second target network address to the fourth device, so as to realize the second tunnel endpoint to answer the second address request message.
- the second tunnel endpoint can directly answer the second address request message based on the obtained second network address, avoiding the problem of message flooding caused by the VTEP broadcast message method in the related art, and can reduce the occupied network resources to a certain extent and improve network performance.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the method further includes:
- Step 301 Obtain the tunnel name and tunnel identifier of the static tunnel.
- step 201 includes the following steps:
- Step 2011 Generate a second detection message according to the second network address, tunnel name and tunnel identifier stored in the first tunnel endpoint.
- step 202 includes the following steps:
- Step 2022 Determine the first target tunnel from the multiple static tunnels corresponding to the second tunnel endpoint according to the tunnel name and the tunnel identifier.
- Step 2023 Send a second detection message to the second tunnel endpoint through the first target tunnel.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint.
- static routing can be configured between the first tunnel endpoint and the second tunnel endpoint, and relevant settings of the virtual local area network (VLAN) can be performed, and then a VXLAN static tunnel interface instance is created, thereby establishing a static tunnel between the first tunnel endpoint and the second tunnel endpoint.
- VLAN virtual local area network
- the specific configuration method and creation method can refer to the description in the relevant technology, and some embodiments of the present application do not limit this.
- the first tunnel endpoint may obtain the tunnel name and tunnel identifier of the VXLAN static tunnel from the upper layer application of the VXLAN network, wherein the tunnel identifier may be an identification identifier (VXLAN network identifier, VNI) of the VXLAN network.
- the first tunnel endpoint may add the second network address of each third device corresponding to the first tunnel endpoint, as well as the obtained tunnel name and tunnel identifier, to the field corresponding to the optional content of the second detection message according to the message format of the detection message, and then determine the added detection message as the second detection message, so that the second detection message carries the second network address of each third device, and carries the tunnel name and tunnel identifier of the VXLAN static tunnel.
- the tunnel name and tunnel identifier of the VXLAN static tunnel can be used by the second tunnel endpoint to perform tunnel identification according to the tunnel name and tunnel identifier after receiving the second detection message, so as to determine the target tunnel connected to the first tunnel endpoint.
- the first tunnel endpoint may be connected to multiple static tunnels, and the first tunnel endpoint may be identified based on the tunnel name and tunnel identifier of the static tunnel connected to the second tunnel endpoint, and the static tunnel connected to the second tunnel endpoint may be determined from the multiple static tunnels as the first target tunnel.
- the static route corresponding to the static tunnel connected to the first tunnel endpoint and the second tunnel endpoint may be configured based on the tunnel name and tunnel identifier, that is, the tunnel name and tunnel identifier may be configured as the next hop of the static route, thereby determining the static tunnel connected to the first tunnel endpoint and the second tunnel endpoint as the first target tunnel.
- the tunnel name and tunnel identifier of the static tunnel are obtained; a second detection message is generated according to the second network address, tunnel name and tunnel identifier stored in the first tunnel endpoint; a first target tunnel is determined from multiple static tunnels corresponding to the first tunnel endpoint according to the tunnel name and tunnel identifier; and a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the first tunnel endpoint can conveniently identify the static tunnel connected to the second tunnel endpoint according to the tunnel name and tunnel identifier, determine the first target tunnel, and thus conveniently send the second detection message to the second tunnel endpoint through the first target tunnel, so that the second tunnel endpoint can receive the second detection message, which can improve the practicality of the address request message reply method of the embodiment of the present application to a certain extent.
- the method before step 2011, the method further includes:
- Step 401 Establish a session between a first tunnel endpoint and a second tunnel endpoint according to a tunnel name and a tunnel identifier.
- Step 2023 may include the following steps:
- Step 2023a When the session status is maintained, a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- a first tunnel endpoint can generate a session negotiation message based on the tunnel name, tunnel identifier and the identifier of the first tunnel endpoint, and send the session negotiation message to the second tunnel endpoint.
- the second tunnel endpoint can obtain the tunnel name and tunnel identifier carried in the session negotiation message, and match them with the tunnel name and tunnel identifier stored locally at the second tunnel endpoint. If the tunnel name and tunnel identifier are consistent, the match is successful, and the second tunnel endpoint learns the identifier of the first tunnel endpoint, thereby establishing a session with the first tunnel endpoint.
- normal two-way communication can be determined by periodically sending messages. If both parties can receive messages sent by the other party, the session status is maintained. If either party cannot receive messages sent by the other party, the session status is disconnected.
- the first tunnel endpoint when the session state established between the first tunnel endpoint and the second tunnel endpoint is maintained, indicating that the two-way communication between the first tunnel endpoint and the second tunnel endpoint is normal, the first tunnel endpoint sends a second detection message to the second tunnel endpoint through the first target tunnel, so that the second tunnel endpoint can receive the second detection message, which can improve the success rate of sending the second detection message to a certain extent. Furthermore, the second tunnel endpoint can obtain the second network address from the second detection message, thereby answering the second address request message sent to the second tunnel endpoint, which can improve the answering success rate of the address request message answering method in some embodiments of the present application.
- a session is established between the first tunnel endpoint and the second tunnel endpoint according to the tunnel name and the tunnel identifier; when the session status is maintained, a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the session status between the first tunnel endpoint and the second tunnel endpoint when the session status is maintained, it can be determined that the communication between the first tunnel endpoint and the second tunnel endpoint is normal, so that the second tunnel endpoint can receive the second detection message sent by the first tunnel endpoint, which can improve the success rate of sending the second detection message to a certain extent.
- the method further includes:
- Step 501 store a first network address in a first database.
- Step 103 may include the following steps:
- Step 1031 Obtain a first target network address from the first network address stored in the first database, and send the first target network address to the second device.
- the first database may be a database connected to the first tunnel endpoint, the first database may be a local database, or a network database, and some embodiments of the present application do not limit this.
- the first network address may be stored in the first database.
- the first network address may include the IP address and MAC address of the first device corresponding to the second tunnel endpoint, and the IP address and MAC address of the first device may be stored in the first database accordingly.
- the MAC address corresponding to the IP address can be queried from the first database according to the IP address of the target device requested in the first address request message, and the first target network address, i.e., the MAC address, can be sent to the second device as the first target network address to reply to the MAC address of the target device requested by the second device.
- the first tunnel endpoint by storing the first network address in the first database, it is convenient for the first tunnel endpoint to obtain the first target network address directly from the first network address stored in the first database when receiving the first address request, thereby improving the efficiency of obtaining the first target network address, and sending the first target network address to the second device, which can improve the answering efficiency of the address request message method improved in some embodiments of the present application to a certain extent.
- the method further comprises:
- Step 601 when receiving the third detection message sent by the second tunnel endpoint, update the first network address stored in the first database according to the latest first network address carried by the third detection message to obtain an updated first database; the third detection message is generated by the second tunnel endpoint according to the latest first network address.
- Step 1031 may include the following steps:
- Step 1031a Obtain a first target network address from the first network addresses stored in the updated first database.
- the first tunnel endpoint and the second tunnel endpoint can periodically send detection messages to the other end to determine that the bidirectional forwarding path between the first tunnel endpoint and the second tunnel endpoint is normal.
- the second tunnel endpoint can continuously learn the network address of the first device connected to the second tunnel, obtain the latest network address of each first device, and use it as the latest first network address.
- the second tunnel endpoint learns the latest first network address, it can generate a third detection message based on the latest first network address and send the third detection message to the first tunnel endpoint.
- the latest first network address can be added to the field corresponding to the optional content according to the message format of the detection message, and the added detection message can be used as the third detection message.
- the first tunnel endpoint when the first tunnel endpoint receives the third detection message sent by the second tunnel endpoint, it can perform an unpacking operation to obtain the latest first network address carried by the third detection message. Then, the first network address stored in the first database is updated to the latest first network address, and the first database of the updated first network address can be used as the updated first database.
- the first tunnel endpoint receives the first address request, it can obtain the first target network address from the first network address stored in the updated first database, so that the first target network address is the latest first network address. Furthermore, the first tunnel endpoint sends the first target network address to the second device, which can improve the accuracy of the address request message answering method provided in some embodiments of the present application.
- the first network address stored in the first database is updated according to the latest first network address carried in the third detection message, thereby obtaining an updated first database. Since the third detection message is generated by the second tunnel endpoint according to the latest first network address, the first tunnel endpoint can update the first network address stored in the first database to the latest first network address, so that the first network address stored in the updated first database is the latest first network address, and the updated first database is more accurate. Furthermore, the first tunnel endpoint obtains the first target network address from the first network address stored in the updated first database, so that the first target network address can be the latest first network address, and the accuracy of the first target network address can be improved to a certain extent.
- the method further includes:
- Step 701 reset a preset first timing parameter to zero, and control the first timing parameter to restart timing; the first timing parameter is used to represent the non-updated time length of the first database.
- Step 702 When the first timing parameter is greater than a preset duration threshold, the first network address stored in the first database is deleted.
- the duration of time that the first database has not been updated can be counted by using the first timing parameter, and after the first timing parameter is reset to zero and the timing is restarted, the duration of time that the first database has not been updated can be automatically recorded.
- the duration of time that the first database has not been updated represents the duration of time that the first network address stored in the first database has not been updated.
- the first tunnel endpoint after updating the first network address stored in the first database, can set the first timing parameter to zero, such as assigning the first timing parameter to zero, and control the first timing parameter to restart timing, so that the first timing parameter can automatically record the non-updated time of the first database.
- the preset duration threshold may represent the maximum non-update duration allowed by the first database, and the preset duration threshold may be set according to the actual application scenario, and some embodiments of the present application do not limit this.
- the first timing parameter is greater than the preset duration threshold, it indicates that the first network address stored in the first database has expired, and the first network address stored in the first database may be deleted to reduce the resource occupation of the first database by the expired first network address, thereby improving the resource utilization of the first database.
- the first timing parameter by setting the preset first timing parameter to zero and controlling the first timing parameter to restart timing; when the first timing parameter is greater than the preset duration threshold, the first network address stored in the first database is deleted. Since the first timing parameter is used to characterize the non-update duration of the first database, when the first timing parameter is greater than the preset duration threshold, it indicates that the non-update duration of the first database has been greater than the preset duration threshold, and the first network address stored in the first database has timed out and not been updated. Furthermore, by deleting the first network address stored in the first database, the resource occupation of the first database by the first network address that has timed out and not been updated can be reduced, and to a certain extent, the resource utilization rate of the first database can be improved.
- step 1031 may include the following steps:
- Step 1031b Determine the first address identifier according to the first address request message.
- Step 1031c Obtain the first network address corresponding to the first address identifier from the first network addresses stored in the first database according to the first address identifier, and determine it as the first target network address.
- the first address request message may be generated by the second device based on the known IP address of the target device to be accessed and the MAC address of the requested target device.
- the first address identifier may be the IP address of the target device in the first address request message.
- the first tunnel endpoint may unpack the first address request message to obtain the IP address of the target device in the first address request message as the first address identifier.
- the first tunnel endpoint may search the first database for the MAC address of the target device corresponding to the IP address of the target device according to the IP address of the target device, and determine the MAC address of the target device found, i.e., the first network address corresponding to the first address identifier, as the first target network address.
- the first address identifier is determined according to the first address request message; the first network address corresponding to the first address identifier is obtained from the first network address stored in the first database according to the first address identifier, and is determined as the first target network address.
- the first address identifier matches the first network address requested by the first address request message, and further, the first target network address can be conveniently determined from the first database according to the first address identifier, which can improve the efficiency of obtaining the first target network address to a certain extent.
- FIG. 2 is a flowchart of another method for answering an address request message provided in some embodiments of the present application. As shown in FIG. 2 , the method is applied to a second tunnel endpoint, and the method includes:
- Step 801 generating a first detection message according to a first network address stored in a second tunnel endpoint; the first network address is a network address of a first device corresponding to the second tunnel endpoint.
- Step 802 sending a first detection message to the first tunnel endpoint; the first detection message is used for the first tunnel endpoint to obtain the first network address, and when receiving the second address request message, obtain the second target network address from the second network address, and send the second target network address to the fourth device to answer the second address request message; the second target network address is the second network address requested by the second address request message, and the fourth device is the device that sends the second address request message to the second tunnel endpoint.
- the first device corresponding to the second tunnel endpoint may be a device connected to the second tunnel endpoint.
- the first device may be one or more, and some embodiments of the present application do not limit this.
- the second tunnel endpoint may learn the network address of the connected first device, and specifically, may obtain and store the IP address and MAC address of the first device.
- the second tunnel endpoint when generating a first detection message, can add the first network address of each first device corresponding to the second tunnel endpoint to the field corresponding to the optional content according to the message format, so that the first detection message carries the first network address of each first device.
- the steps performed by the first tunnel endpoint may refer to the relevant descriptions of steps 101 to 103 and will not be repeated here.
- the first detection message since the first detection message is generated by the second tunnel endpoint according to the stored first network address, and the first network address is the network address of the first device corresponding to the second tunnel endpoint, the first detection message carries the network address of the first device corresponding to the second tunnel endpoint, and the first tunnel endpoint receives the first detection message sent by the second tunnel endpoint and obtains the first network address carried by the first detection message, then the first tunnel endpoint obtains the network address of the first device corresponding to the second tunnel endpoint, and when the second device sends the first address request message to the first tunnel endpoint and needs to request the network address of the first device corresponding to the second tunnel endpoint, the first tunnel endpoint can directly obtain the requested first target network address from the first network address and send the first target network address to the second device, thereby realizing the first tunnel endpoint to answer the first address request message on behalf of the first tunnel endpoint.
- the first tunnel endpoint can directly answer the first address request message based on the obtained first network address, avoiding the problem of message flooding caused by the VTEP broadcast message method in the related art, and can reduce the occupied network resources to a certain extent and improve network performance.
- the method further comprises:
- Step 901 Receive a second detection message sent by a first tunnel endpoint.
- Step 902 obtaining a second network address carried in a second detection message; the second detection message is generated by the first tunnel endpoint according to the stored second network address, and the second network address is a network address of a second device corresponding to the first tunnel endpoint.
- Step 903 when the second address request message is received, obtain the second target network address from the second network address, and send the second target network address to the fourth device to answer the second address request message; the second target network address is the second network address requested by the second address request message, and the fourth device is the device that sends the second address request message to the second tunnel endpoint.
- the second tunnel endpoint receives the second detection message, can perform an unpacking operation, obtain the second network address from the second detection message, and store the second network address in a specified location, for example, it can be stored in a second database so that it can be queried from the database when the second address request message is received.
- the fourth device may be one of the devices connected to the second tunnel endpoint, and the fourth device generates a second address request message according to the known IP address of the target device to be accessed and the MAC address of the requested target device, and sends the second address request message to the first tunnel endpoint.
- the target device may be any third device corresponding to the first tunnel endpoint.
- the second network address requested by the second address request message may be the MAC address of the target device, and the target device may be any third device corresponding to the first tunnel endpoint, that is, the second target network address may be the MAC address of any third device corresponding to the first tunnel endpoint.
- the second tunnel endpoint when the second address request message is received, can determine the IP address of the target device requested by the fourth device according to the second address request message, and obtain the MAC address of the target device corresponding to the IP address of the target device from the stored second network address according to the IP address of the target device, as the second target network address. address, and sends the second target network address, that is, the MAC address of the target device, to the fourth device, so that the second tunnel endpoint answers the second address request message and replies to the second target network address requested by the fourth device.
- the second detection message since the second detection message is generated by the first tunnel endpoint according to the stored second network address, and the second network address is the network address of the third device corresponding to the first tunnel endpoint, the second detection message carries the network address of the third device corresponding to the first tunnel endpoint, and the first tunnel endpoint sends the second detection message to the second tunnel endpoint, so that the second tunnel endpoint receives and obtains the second network address carried by the second detection message, and the second tunnel endpoint obtains the network address of the third device corresponding to the first tunnel endpoint.
- the second tunnel endpoint can directly obtain the requested second target network address from the second network address, and send the second target network address to the fourth device, so as to realize the second tunnel endpoint to answer the second address request message.
- the second tunnel endpoint can directly answer the second address request message based on the obtained second network address, avoiding the problem of message flooding caused by the VTEP broadcast message method in the related art, and can reduce the occupied network resources to a certain extent and improve network performance.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the method further includes:
- Step 1001 Obtain the tunnel name and tunnel identifier of a static tunnel.
- Step 801 may include the following steps:
- Step 8011 Generate a first detection message according to the first network address, tunnel name and tunnel identifier stored in the second tunnel endpoint.
- Step 802 may include the following steps:
- Step 8021 Determine a second target tunnel from a plurality of static tunnels corresponding to a second tunnel endpoint according to the tunnel name and the tunnel identifier.
- Step 8022 Send a first detection message to the first tunnel endpoint through the second target tunnel.
- step 1001 may refer to the implementation of step 301 and will not be repeated here.
- the second tunnel endpoint may be connected to multiple static tunnels, and the second tunnel endpoint may be identified based on the tunnel name and tunnel identifier of the static tunnel connected to the second tunnel endpoint, and the static tunnel connected to the first tunnel endpoint may be determined from the multiple static tunnels as the second target tunnel.
- the static route corresponding to the static tunnel connected to the first tunnel endpoint and the second tunnel endpoint may be configured based on the tunnel name and tunnel identifier, that is, the tunnel name and tunnel identifier may be configured as the next hop of the static route, thereby determining the static tunnel connected to the first tunnel endpoint and the second tunnel endpoint as the second target tunnel.
- the second tunnel endpoint can conveniently identify the static tunnel connected to the second tunnel endpoint based on the tunnel name and tunnel identifier, determine the second target tunnel, and thus conveniently send the first detection message to the first tunnel endpoint through the second target tunnel, so that the first tunnel endpoint can receive the first detection message, which can improve the practicality of the address request message answering method of some embodiments of the present application to a certain extent.
- the method before step 8011, the method further includes:
- Step 1101 Establish a session between a first tunnel endpoint and a second tunnel endpoint according to a tunnel name and a tunnel identifier.
- Step 8022 may include the following steps:
- Step 8022a When the session status is maintained, a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- step 1101 can refer to the implementation of step 401, which will not be repeated here. Elaborate.
- the second tunnel endpoint when the session state established between the first tunnel endpoint and the second tunnel endpoint is maintained, indicating that the two-way communication between the first tunnel endpoint and the second tunnel endpoint is normal, the second tunnel endpoint sends a first detection message to the first tunnel endpoint through the second target tunnel, so that the first tunnel endpoint can receive the first detection message, which can improve the success rate of sending the first detection message to a certain extent. Furthermore, the first tunnel endpoint can obtain the first network address from the first detection message, thereby answering the first address request message sent to the first tunnel endpoint, which can improve the answering success rate of the address request message answering method in some embodiments of the present application.
- the method further includes:
- Step 1201 store the second network address in a second database.
- Step 903 may include the following steps:
- Step 9031 Obtain a second target network address from the second network address stored in the second database, and send the second target network address to the fourth device.
- the second database may be a database connected to the second tunnel endpoint, the second database may be a local database, or a network database, and the embodiments of the present application do not limit this.
- the second network address may be stored in the second database.
- the second network address may include the IP address and MAC address of the third device corresponding to the first tunnel endpoint, and the IP address and MAC address of the third device may be stored in the second database accordingly.
- the second tunnel endpoint When the second tunnel endpoint receives the second address request message, it can query the MAC address corresponding to the IP address from the second database according to the IP address of the target device requested in the second address request message, and send the second target network address, i.e., the MAC address, to the fourth device as the second target network address to reply to the MAC address of the target device requested by the fourth device.
- the second target network address i.e., the MAC address
- the second tunnel endpoint can obtain the second target network address directly from the second network address stored in the second database when receiving the second address request, thereby improving the efficiency of obtaining the second target network address and sending the second target network address to the fourth device, which can improve the efficiency of the address request message method improved in some embodiments of the present application to a certain extent.
- the method further comprises:
- Step 1301 when receiving the fourth detection message sent by the first tunnel endpoint, update the second network address stored in the second database according to the latest second network address carried by the fourth detection message to obtain an updated second database; the fourth detection message is generated by the first tunnel endpoint according to the latest second network address.
- Step 9031 may include the following steps:
- Step 9031a Obtain a second target network address from the second network addresses stored in the updated second database.
- the first tunnel endpoint when the first tunnel endpoint learns the latest second network address, it can generate a fourth detection message based on the latest second network address and send the fourth detection message to the second tunnel endpoint.
- the latest second network address can be added to the field corresponding to the optional content according to the message format of the detection message, and the added detection message is used as the fourth detection message.
- the second tunnel endpoint when the second tunnel endpoint receives the fourth detection message sent by the first tunnel endpoint, it can perform an unpacking operation to obtain the latest second network address carried by the fourth detection message; then, the second network address stored in the second database is updated to the latest second network address, and the second database with the updated second network address can be used as the updated second database.
- the second tunnel endpoint receives the second address request, it can update the second network address from the updated second database.
- the second target network address is obtained from the second network address stored in the second database, so that the second target network address is the latest second network address. Further, the second tunnel endpoint sends the second target network address to the fourth device, which can improve the answering accuracy of the address request message answering method provided in some embodiments of the present application.
- the second tunnel endpoint since the fourth detection message is generated by the first tunnel endpoint according to the latest second network address, the second tunnel endpoint can update the second network address stored in the second database to the latest second network address, so that the second network address stored in the updated second database is the latest second network address, and the updated second database can be more accurate. Further, the second tunnel endpoint obtains the second target network address from the second network address stored in the updated second database, so that the second target network address is the latest second network address, which can improve the accuracy of the second target network address to a certain extent.
- the method further includes:
- Step 1401 reset a preset second timing parameter to zero, and control the second timing parameter to restart timing; the second timing parameter is used to represent the non-updated time length of the second database.
- Step 1402 When the second timing parameter is greater than a preset duration threshold, the second network address stored in the second database is deleted.
- the duration of time that the second database has not been updated can be counted by a second timing parameter, and after the second timing parameter is reset to zero and the timing is restarted, the duration of time that the second database has not been updated can be automatically recorded.
- the duration of time that the second database has not been updated represents the duration of time that the second network address stored in the second database has not been updated.
- the second tunnel endpoint after updating the second network address stored in the second database, can set the second timing parameter to zero, such as assigning the second timing parameter to zero, and control the second timing parameter to restart timing, so that the second timing parameter can automatically record the non-updated time of the second database.
- the second timing parameter when the second timing parameter is greater than a preset duration threshold, it can be indicated that the second network address stored in the second database has expired, and the second network address stored in the second database can be deleted to reduce the resource occupation of the first database by the expired second network address and improve the resource utilization of the first database.
- the second timing parameter since the second timing parameter is used to characterize the non-updated time length of the second database, when the second timing parameter is greater than a preset time length threshold, it indicates that the non-updated time length of the second database has been greater than the preset time length threshold, and the second network address stored in the second database has timed out and not been updated. Furthermore, by deleting the second network address stored in the second database, the resource occupancy of the second database by the second network address that has timed out and not been updated can be reduced, and to a certain extent, the resource utilization rate of the second database can be improved.
- step 9031 may include the following steps:
- Step 9031b Determine the second address identifier according to the second address request message.
- Step 9031c Obtain the second network address corresponding to the second address identifier from the second network addresses stored in the second database according to the second address identifier, and determine it as the second target network address.
- the second address request message may be generated by the fourth device based on the known IP address of the target device to be accessed and the MAC address of the requested target device.
- the second address identifier may be the IP address of the target device in the second address request message.
- the second tunnel endpoint may unpack the second address request message to obtain the IP address of the target device in the second address request message as the second address identifier.
- the second tunnel endpoint may search the second database for the MAC address of the target device corresponding to the IP address of the target device according to the IP address of the target device, and determine the MAC address of the target device found, i.e., the second network address corresponding to the second address identifier, as the second target network address.
- the second address identifier since the second address identifier is determined based on the second address request message, the second address identifier matches the second network address requested by the second address request message. Furthermore, the second target network address can be conveniently determined from the second database based on the second address identifier, which can improve the efficiency of obtaining the second target network address to a certain extent.
- FIG3 is a schematic diagram of ARP request message suppression in the related art.
- Virtual Machine (VM) 1 sends an ARP request message to obtain the MAC address of Virtual Machine 7.
- Virtual Tunnel Endpoint (VTEP) 1 creates an ARP suppression table entry for Virtual Machine 1 and floods the ARP request message in the VXLAN network.
- the ARP suppression table entry of Virtual Machine 1 is sent to Virtual Tunnel Endpoint 2 and Virtual Tunnel Endpoint 3 through the Border Gateway Protocol (Border Gateway Protocol, BGP) Ethernet Virtual Private Network (EVPN), i.e., the transmission network in FIG3 .
- Virtual tunnel endpoint 2 and virtual tunnel endpoint 3 decapsulate the ARP request message and broadcast the ARP request message at the local site.
- Border Gateway Protocol Border Gateway Protocol
- BGP Border Gateway Protocol
- EVPN Virtual Private Network
- Virtual machine 7 sends an ARP reply to virtual tunnel endpoint 2.
- Virtual tunnel endpoint 2 creates an ARP suppression entry for virtual machine 7 and forwards the ARP reply to virtual tunnel endpoint 1. It also sends the ARP suppression entry of virtual machine 7 to virtual tunnel endpoint 1 and virtual tunnel endpoint 3 through BGP EVPN.
- Virtual tunnel endpoint 1 decapsulates the ARP reply and forwards the ARP reply to virtual machine 1.
- Virtual machine 4 sends an ARP request message to obtain the MAC address of virtual machine 1.
- Virtual tunnel endpoint 1 creates an ARP suppression entry for virtual machine 4 and replies to the ARP request message of virtual machine 4 according to the ARP suppression entry of virtual machine 1.
- Virtual machine 10 sends an ARP request message to obtain the MAC address of virtual machine 1.
- Virtual tunnel endpoint 3 creates an ARP suppression entry for virtual machine 10 and replies to the ARP request of virtual machine 10 according to the ARP suppression entry of virtual machine 1.
- FIG4 is a schematic diagram of ARP broadcast suppression in the related art.
- the VXLAN Layer 3 gateway L3 can dynamically learn the ARP suppression entries of server 1 and server 2, and then generate host information based on the ARP suppression entries.
- the host information includes the host IP address, MAC address, virtual tunnel endpoint (VTEP) address and virtual LAN extended identification (VNI ID) of server 1 and server 2 respectively, and publish the host information through BGP EVPN, so that other BGP neighbors, such as the VXLAN Layer 2 gateway L2 in FIG4 , can learn the host information of the L3 gateway.
- the host information learned by the VXLAN Layer 2 gateway L2 can be used for broadcast suppression.
- server 1 when server 1 first accesses server 2, server 1 will send an address resolution protocol (ARP) request message to server 2, requesting the MAC address of the destination host server 2.
- ARP address resolution protocol
- device 1 After receiving the ARP request message, device 1, which serves as the VXLAN Layer 2 gateway, queries the host information. If the MAC address of the destination host is in device 1, device 1 replaces the broadcast destination MAC address in the ARP request message with the MAC address of the destination host, and forwards it after VXLAN encapsulation. If there is no destination host information in device 1, the broadcast destination MAC address in the ARP request message remains unchanged, and device 1 forwards it after VXLAN encapsulation. After receiving the unicast ARP request message, server 2 sends an ARP response.
- ARP address resolution protocol
- Server 1 receives the ARP response message sent by server 2 to establish an ARP suppression table entry, and can communicate with server 2.
- ARP address resolution protocol
- FIG5 is a schematic diagram of ARP proxy in the related art.
- the L2GW1 gateway and L2GW2 gateway in FIG5 enable the ARP L2 proxy function based on the broadcast domain (BD)
- the source IP address, source MAC address, message input interface and other information in the ARP request message will be recorded in the local address resolution protocol (ARP) suppression table item as the basis for subsequent ARP L2 proxy.
- ARP local address resolution protocol
- the L2 gateway device receives the ARP request message again, the L2 gateway device first searches the local address resolution protocol suppression table item (including local listening and synchronization from other gateways) according to the destination IP in the ARP request message. If the destination MAC address search is successful, the ARP request message is directly answered with the found destination MAC address.
- the virtual LAN extension (VXLAN) tunnel can use the information published by BGP Type2 (MAC/IP) routing to access remote host information.
- the suppression table shows that the L2GW1 gateway has learned the MAC/IP addresses of remote hosts 3 and 4.
- the virtual LAN extension tunnel can implement ARP suppression and proxy functions through the BGP control plane.
- FIG6 is a schematic diagram of BFD remote MAC address release provided by some embodiments of the present application.
- device 05 is the first tunnel endpoint of the embodiment of the present application
- device 06 is the second tunnel endpoint of the embodiment of the present application.
- a bidirectional forwarding detection (BFD) session is established between device 05 and device 06.
- Packets from the virtual local area network (VLAN) 100 in the same network segment can pass through the VXLAN static tunnel between device 05 and device 06, and carry the virtual local area network extended identification (VNI), that is, the network identification identification (Identity document, ID) 1000 of the VXLAN, to reach the other end for access and get a response.
- VNI virtual local area network extended identification
- host 1, host 2, and host 3 are the third devices corresponding to the first tunnel endpoint in the embodiment of the present application
- host 4 and host 5 are the first devices corresponding to the second tunnel endpoint in the embodiment of the present application.
- Device 05 has learned the IP/MAC addresses of Host 1, Host 2, and Host 3, and configured the virtual tunnel endpoint source IP address (Source VTEP IP, VTEP SIP), virtual LAN extended identification identifier (VLAN VNI), and Bidirectional Forwarding Detection (BFD) neighbor information on Device 05.
- VLAN VNI virtual LAN extended identification identifier
- BFD Bidirectional Forwarding Detection
- the Bidirectional Forwarding Detection (BFD) neighbor information includes: Bidirectional Forwarding Detection neighbor 6.6.6.6 and multi-hop local address 5.5.5.5, and sets the Bidirectional Forwarding Detection remote MAC address to be published: Host 1 and Host 2.
- BFD Hello packets the BFD keep-alive packets
- the suffix in the BFD keep-alive packets carries the IP/MAC addresses of host 1 and host 2, the VLAN channel name, and the VLAN extended identification (VNI) channel identifier, i.e., 100/1000 in Figure 6, and is sent to the BFD neighbor, i.e., device 06.
- device 06 After receiving the Bidirectional Forwarding Detection (BFD) keep-alive packet sent by device 05, device 06 can obtain the remote MAC address table entry information of device 05, that is, the MAC addresses of host 1 and host 2. Furthermore, device 06 can enable the VXLAN proxy function by issuing Linux (operating system kernel) instructions to the kernel, that is, to reply to the ARP request message requesting the MAC address of host 1 and host 2, thereby realizing the ARP proxy of the VXLAN static tunnel, avoiding the problem of message flooding caused by broadcast, and suppressing the number of messages in the VXLAN network.
- Linux operating system kernel
- host 4 may be a device that sends a second address request message, i.e., an ARP request message, to the second tunnel endpoint device 06 in some embodiments of the present application.
- Host 4 wants to access the first tunnel endpoint, i.e., host 1 corresponding to device 05.
- Host 4 sends an ARP request message.
- device 06 has the VXLAN proxy function enabled, device 06 can obtain the MAC address of host 1 by looking up the table entry, and reply the MAC address of host 1 to host 4.
- device 06 can carry the IP/MAC address of host 4 in the suffix of the BFD keep-alive packet. After device 05 receives the BFD keep-alive packet sent by device 06, it can obtain the MAC address of host 4.
- Device 05 can answer the ARP request message requesting the MAC address of host 4.
- FIG7 is a schematic diagram of the service device architecture provided by some embodiments of the present application.
- device 05 and device 06 maintain a BFD session state by sending BFD keep-alive packets (BFD Hello packets), host 4 is set as the remote MAC address of device 06, and host 1 and host 2 are set as the remote MAC address of device 05.
- the application MAC address table
- the application is used to learn local MAC addresses such as the MAC addresses of host 1 and host 2.
- the application (address resolution protocol) is used to determine the correspondence between the IP address and MAC address of host 1 and host 2, and then write the IP/MAC addresses of host 1 and host 2 into a database shared by the application, i.e., the first database of the embodiment of the present application, for other applications (such as application BFD) to obtain.
- the application (bidirectional forwarding detection) is used to establish a BFD session between device 05 and device 06.
- the application can obtain the IP/MAC addresses of host 1 and host 2, the VXLAN tunnel name, and the VLAN/VNI tunnel identifier and other information that need to be published from the first database, and obtain the BFD keep-alive packet (BFD Hello packet) after packaging, and send the BFD keep-alive packet to Device 06.
- the application receives information such as the IP/MAC address, VXLAN tunnel name, and VLAN/VNI tunnel identifier of the host 4 published by the device 06, and stores it in the first database for the application (virtual LAN extension) to obtain.
- the application (virtual LAN extension) can perform tunnel identification and VNI matching on the device 06 according to the VXLAN tunnel name and VLAN/VNI tunnel identifier.
- host 1 can be a device that sends a first address request message, namely, an ARP request message, to the first tunnel endpoint device 05 in an embodiment of the present application.
- device 05 sends Linux instructions to the kernel through the command line interface to enable the VXLAN proxy function, when host 1 wants to send an ARP request message to the second tunnel endpoint, namely, host 4 corresponding to device 06, device 05 can obtain the MAC address of host 4 from the first database, thereby directly answering the ARP request message sent by host 1.
- FIG8 is a schematic diagram of a service control flow provided by some embodiments of the present application.
- static routing and virtual LAN related settings are configured, and then a virtual LAN extended static tunnel interface instance is created.
- a virtual LAN extended static tunnel interface instance is created.
- the virtual LAN extended static tunnel source IP, the virtual tunnel endpoint destination IP address (Destination VTEP IP, VTEP DIP), the virtual LAN extended identification identifier, and the bidirectional forwarding detection neighbor of the device may be set, such as the relevant settings of device 05 and device 06 in FIG6.
- the MAC address of the local host can be sent to the device at the other end of the tunnel, and the MAC address of the remote host published by the device at the other end of the tunnel can be received.
- the device can then answer the ARP request message requesting the remote host and reply the MAC address of the remote host to the device sending the ARP request message.
- FIG9 is a schematic diagram of a BFD keep-alive packet carrying a remote MAC address provided by some embodiments of the present application.
- the message format of the bidirectional forwarding detection (BFD) keep-alive packet includes: bidirectional forwarding detection protocol version number, diagnostic word, bidirectional forwarding detection local state, information flag, detection timeout multiple, message length, and local identifier and remote identifier in the session identifier, the minimum bidirectional forwarding detection message sending interval and the minimum bidirectional forwarding detection message receiving interval in the control data packet interval, and the minimum echo message receiving interval in the echo data packet interval, and the BFD optional type-length-value (Type Length Value, TLV) added in the optional content part of the bidirectional forwarding detection (BFD) message in the embodiment of the present application.
- BFD optional type-length-value
- the optional TLV of the bidirectional forwarding detection message includes TLV authentication type, TLV suffix information length, and TLV information content, wherein the TLV authentication type is remote MAC address release, and the TLV information content includes remote MAC address, remote IP address, virtual local area network extension identification (VLAN ID) and virtual local area network extension (VXLAN) tunnel name.
- TLV authentication type is remote MAC address release
- TLV information content includes remote MAC address, remote IP address, virtual local area network extension identification (VLAN ID) and virtual local area network extension (VXLAN) tunnel name.
- VLAN ID virtual local area network extension identification
- VXLAN virtual local area network extension
- FIG10 is a schematic diagram of a BFD remote MAC address control process provided by some embodiments of the present application.
- the first tunnel endpoint receives a first detection message
- the second tunnel endpoint receives a second detection message.
- the first detection message and the second detection message may be bidirectional forwarding detection (BFD) messages.
- BFD bidirectional forwarding detection
- the first tunnel endpoint or the second tunnel endpoint may determine whether the BFD message is a legitimate message.
- the legitimacy determination of the message may refer to the relevant technology, and some embodiments of the present application do not limit this.
- After verifying the legitimacy determine whether the session state between the first tunnel endpoint and the second tunnel endpoint is maintained. If the session state is maintained, further determine whether the BFD message carries TLV content.
- the BFD message In the case that the BFD message carries TLV content, analyze and obtain the remote MAC address carried in the TLV content, and write the obtained MAC address into the database corresponding to the first tunnel endpoint or the second tunnel endpoint.
- the first tunnel endpoint or the second tunnel endpoint may issue a Linux instruction to the kernel, instructing the kernel to add a new MAC address, and needs to answer the address request message requesting the MAC address.
- the first tunnel endpoint or the second tunnel endpoint can periodically check the database, obtain all MAC addresses in the database, check whether each MAC address is expired, and delete the expired remote MAC address from the database.
- the first tunnel endpoint or the second tunnel endpoint can issue a Linux instruction to the kernel. Instructs the kernel to delete expired MAC addresses.
- the Linux new instructions may be as follows:
- the Linux delete instruction may be as follows:
- some embodiments of the present application provide an address request message answering device, which is applied to a first tunnel endpoint.
- the device 15 includes:
- the first receiving module 1501 is used to receive a first detection message sent by a second tunnel endpoint
- a first acquisition module 1502 is used to acquire a first network address carried in a first detection message; the first detection message is generated by a second tunnel endpoint according to a stored first network address, and the first network address is a network address of a first device corresponding to the second tunnel endpoint;
- the first answering module 1503 is used to obtain the first target network address from the first network address when receiving the first address request message, and send the first target network address to the second device to answer the first address request message; the first target network address is the first network address requested by the first address request message, and the second device is the device that sends the first address request message to the first tunnel endpoint.
- the device 15 further comprises:
- a second generating module configured to generate a second detection message according to a second network address stored in the first tunnel endpoint; the second network address is a network address of a third device corresponding to the first tunnel endpoint;
- the second sending module is used to send a second detection message to the second tunnel endpoint; the second detection message is used for the second tunnel endpoint to obtain the second network address carried by the second detection message, and when receiving the second address request message, obtain the second target network address from the second network address, and send the second target network address to the fourth device to answer the second address request message; the second target network address is the second network address requested by the second address request message, and the fourth device is a device that sends the second address request message to the second tunnel endpoint.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the device 15 further includes:
- a second acquisition module used to acquire a tunnel name and a tunnel identifier of a static tunnel
- the second generation module is specifically used for:
- the second sending module is specifically used for:
- a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the device 15 further comprises:
- a first session module used for establishing a session between the first tunnel endpoint and the second tunnel endpoint according to the tunnel name and the tunnel identifier before the second generation module generates a second detection message according to the second network address, the tunnel name and the tunnel identifier stored in the first tunnel endpoint;
- the second sending module is further specifically used for:
- a second detection message is sent to the second tunnel endpoint through the first target tunnel.
- the device 15 further comprises:
- a first storage module configured to store the first network address in a first database after the first acquisition module 1502 acquires the first network address carried by the first detection message;
- the first answering module 1503 is specifically used for:
- a first target network address is obtained from the first network address stored in the first database, and the first target network address is sent to the second device.
- the device 15 further comprises:
- a first updating module is used to update the first network address stored in the first database according to the latest first network address carried in the third detection message when receiving the third detection message sent by the second tunnel endpoint, so as to obtain an updated first database; the third detection message is generated by the second tunnel endpoint according to the latest first network address;
- the first answering module 1503 is further specifically used to obtain the first target network address from the first network address stored in the updated first database.
- the device 15 further comprises:
- a first timing module configured for the first updating module to update the first network address stored in the first database according to the latest first network address carried by the third detection message, and after obtaining the updated first database, to reset the preset first timing parameter to zero and control the first timing parameter to restart timing; the first timing parameter is used to characterize the non-updated duration of the first database;
- the first deleting module is used to delete the first network address stored in the first database when the first timing parameter is greater than a preset time threshold.
- the first answering module 1503 is further configured to:
- a first network address corresponding to the first address identifier is obtained from the first network addresses stored in the first database, and is determined as the first target network address.
- some embodiments of the present application provide another device for answering an address request message, which is applied to a second tunnel endpoint.
- the device 16 includes:
- the first generating module 1601 is used to generate a first detection message according to the first network address stored in the second tunnel endpoint; the first network address is the network address of the first device corresponding to the second tunnel endpoint;
- the first sending module 1602 is used to send a first detection message to the first tunnel endpoint; the first detection message is used for the first tunnel endpoint to obtain a first network address, and when receiving a first address request message, obtain a first target network address from the first network address, and send the first target network address to the second device to answer the first address request message; the first target network address is the first network address requested by the first address request message, and the second device is the device that sends the first address request message to the first tunnel endpoint.
- the device 16 further comprises:
- a second receiving module used to receive a second detection message sent by the first tunnel endpoint
- a third acquisition module is used to acquire the second network address carried by the second detection message;
- the second detection message is generated by the first tunnel endpoint according to the stored second network address, and the second network address is the network address of the second device corresponding to the first tunnel endpoint;
- the second answering module is used to obtain the second target network address from the second network address when receiving the second address request message, and send the second target network address to the fourth device to answer the second address request message; the second target network address is the second network address requested by the second address request message, and the fourth device is to the second tunnel endpoint The device that sends the second address request message.
- a static tunnel is established between the first tunnel endpoint and the second tunnel endpoint, and the device 16 further includes:
- a fourth acquisition module used to acquire a tunnel name and a tunnel identifier of a static tunnel
- the first generating module 1601 is specifically used for:
- the first sending module 1602 is specifically used for:
- a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- the device 16 further comprises:
- a second session module used for establishing a session between the first tunnel endpoint and the second tunnel endpoint according to the tunnel name and the tunnel identifier before the first generation module 1601 generates the first detection message according to the first network address, the tunnel name and the tunnel identifier stored in the second tunnel endpoint;
- the first sending module 1602 is further specifically configured to:
- a first detection message is sent to the first tunnel endpoint through the second target tunnel.
- the device 16 after obtaining the second network address carried by the second detection message, the device 16 further includes:
- a second storage module used for storing the second network address in a second database
- the second generation answering module is specifically used for:
- the second target network address is acquired from the second network address stored in the second database, and the second target network address is sent to the fourth device.
- the device 16 further comprises:
- a second updating module is used to update the second network address stored in the second database according to the latest second network address carried in the fourth detection message when receiving the fourth detection message sent by the first tunnel endpoint, so as to obtain an updated second database; the fourth detection message is generated by the first tunnel endpoint according to the latest second network address;
- the second generation answering module is also used for:
- the second target network address is obtained from the second network addresses stored in the updated second database.
- the device 16 further includes:
- a second timing module used to reset a preset second timing parameter to zero and control the second timing parameter to restart timing; the second timing parameter is used to characterize the non-updated time of the second database;
- the second deleting module is used to delete the second network address stored in the second database when the second timing parameter is greater than a preset time threshold.
- the second answering module is further used to:
- a second network address corresponding to the second address identifier is obtained from the second network addresses stored in the second database, and is determined as the second target network address.
- the present application also provides an electronic device, see Figure 13, including: a processor 1701, a memory 1702, and a computer program 17021 stored in the memory and running on the processor, and when the processor executes the program, the address request message answering method of the aforementioned embodiment is implemented.
- the present application also provides a non-volatile readable storage medium.
- the instructions in the non-volatile readable storage medium are executed by a processor of an electronic device, the electronic device can execute the address request message answering method of the aforementioned embodiment.
- modules in the devices in the embodiments may be adaptively changed and arranged in one or more devices different from the embodiments.
- the modules or units or components in the embodiments may be combined into one module or unit or component, and in addition they may be divided into a plurality of submodules or subunits or subcomponents. Except that at least some of such features and/or processes or units are mutually exclusive, all features disclosed in this specification (including the accompanying claims, abstracts and drawings) and all processes or units of any method or device disclosed in this manner may be combined in any combination. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstracts and drawings) may be replaced by an alternative feature providing the same, equivalent or similar purpose.
- the various component embodiments of the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It should be understood by those skilled in the art that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all functions of some or all components in the sorting device according to the present application.
- DSP digital signal processor
- the present application can also be implemented as a device or apparatus program for executing part or all of the methods described herein.
- Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本申请实施例提供了一种地址请求报文代答方法、装置、电子设备及非易失性可读存储介质,属于通信技术领域,该方法应用于第一隧道端点,所述方法包括:接收第二隧道端点发送的第一检测报文;获取第一检测报文携带的第一网络地址;第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址;在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。可以降低占用的网络资源,提高网络性能。
Description
相关申请的交叉引用
本申请要求于2023年04月27日提交中国专利局,申请号为202310467846.5,申请名称为“地址请求报文代答方法、装置、电子设备及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请属于通信技术领域,特别是涉及一种地址请求报文代答方法、装置、电子设备及非易失性可读存储介质。
虚拟局域网扩展(virtual eXtensible local area network,VXLAN)是一种网络虚拟化技术,VXLAN的接入点是虚拟隧道端点(VXLAN tunnel endpoints,VTEP),VXLAN网络中的本地设备会向对应的VTEP发送地址解析协议(Address Resolution Protocol,ARP)请求报文,VTEP可以从VXLAN网络中获取ARP请求报文所请求的目标设备的网络地址,使得本地设备与目标设备基于网络地址进行通信。
通信网络一般都会配置静态隧道和动态隧道两种隧道,在VXLAN的应用场景下,静态隧道中的一个VTEP接收到ARP请求报文时,会将该ARP请求报文进行广播,通过广播的方式从VXLAN网络中获取目标设备的网络地址,比如介质访问控制(medium access control,MAC)地址。但是在该VTEP收到大量ARP请求报文并进行广播的情况下,VXLAN网络会出现报文泛滥的问题,造成占用大量网络资源,导致网络性能下降。
发明内容
本申请提供一种地址请求报文代答方法、装置、电子设备及非易失性可读存储介质,以便解决报文泛滥占用大量网络资源,导致网络性能下降的问题。
为了解决上述技术问题,本申请是这样实现的:
第一方面,本申请一些实施例提出一种地址请求报文代答方法,应用于第一隧道端点,方法包括:
接收第二隧道端点发送的第一检测报文;
获取第一检测报文携带的第一网络地址;第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址;
在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
在一些实施例中,还包括:
根据第一隧道端点存储的第二网络地址,生成第二检测报文;第二网络地址是第一隧道端点对应的第三设备的网络地址;
向第二隧道端点发送第二检测报文;第二检测报文用于供第二隧道端点获取第二检测报文携带的第二网络地址,并在接收到第二地址请求报文的情况下,从第二网络地址中获取第
二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,方法还包括:
获取静态隧道的隧道名称和隧道标识;
根据第一隧道端点存储的第二网络地址,生成第二检测报文,包括:
根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文;
向第二隧道端点发送第二检测报文,包括:
根据隧道名称和隧道标识从第一隧道端点对应的多个静态隧道中,确定第一目标隧道;
通过第一目标隧道向第二隧道端点发送第二检测报文。
在一些实施例中,根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文之前,方法还包括:
根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;
通过第一目标隧道向第二隧道端点发送第二检测报文,包括:
在会话的状态为保持的情况下,通过第一目标隧道向第二隧道端点发送第二检测报文。
在一些实施例中,获取第一检测报文携带的第一网络地址之后,方法还包括:
将第一网络地址存储在第一数据库中;
从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,包括:
从第一数据库存储的第一网络地址中,获取第一目标网络地址,并将第一目标网络地址发送给第二设备。
在一些实施例中,方法还包括:
在接收到第二隧道端点发送的第三检测报文的情况下,根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库;第三检测报文是第二隧道端点根据最新的第一网络地址生成的;
从第一数据库存储的第一网络地址中,获取第一目标网络地址,包括:
从更新后的第一数据库存储的第一网络地址中,获取第一目标网络地址。
在一些实施例中,根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库之后,方法还包括:
将预设的第一计时参数置零,并控制第一计时参数重新开始计时;第一计时参数用于表征第一数据库的未更新时长;
在第一计时参数大于预设时长阈值的情况下,将第一数据库中存储的第一网络地址删除。
在一些实施例中,从第一数据库存储的第一网络地址中,获取第一目标网络地址,包括:
根据第一地址请求报文,确定第一地址标识;
根据第一地址标识从第一数据库存储的第一网络地址中,获取第一地址标识对应的第一网络地址,并确定为第一目标网络地址。
第二方面,本申请一些实施例提出了一种地址请求报文代答方法,应用于第二隧道端
点,方法包括:
根据第二隧道端点存储的第一网络地址,生成第一检测报文;第一网络地址是第二隧道端点对应的第一设备的网络地址;
向第一隧道端点发送第一检测报文;第一检测报文用于供第一隧道端点获取第一网络地址,并在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
在一些实施例中,方法还包括:
接收第一隧道端点发送的第二检测报文;
获取第二检测报文携带的第二网络地址;第二检测报文是第一隧道端点根据存储的第二网络地址生成的,第二网络地址是第一隧道端点对应的第二设备的网络地址;
在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,方法还包括:
获取静态隧道的隧道名称和隧道标识;
根据第二隧道端点存储的第一网络地址,生成第一检测报文,包括:
根据第二隧道端点存储的第一网络地址,隧道名称和隧道标识,生成第一检测报文;
向第一隧道端点发送第一检测报文,包括:
根据隧道名称和隧道标识,从第二隧道端点对应的多个静态隧道中,确定第二目标隧道;
通过第二目标隧道向第一隧道端点发送第一检测报文。
在一些实施例中,根据第二隧道端点存储的第一网络地址,隧道名称和隧道标识,生成第一检测报文之前,方法还包括:
根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;
通过第二目标隧道向第一隧道端点发送第一检测报文,包括:
在会话的状态为保持的情况下,通过第二目标隧道向第一隧道端点发送第一检测报文。
在一些实施例中,获取第二检测报文携带的第二网络地址之后,方法还包括:
将第二网络地址存储在第二数据库中;
从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第一设备,包括:
从第二数据库存储的第二网络地址中,获取第二目标网络地址,并将第二目标网络地址发送给第四设备。
在一些实施例中,方法还包括:
在接收到第一隧道端点发送的第四检测报文的情况下,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库;第四检测报文是第一隧道端点根据最新的第二网络地址生成的;
从第二数据库存储的第二网络地址中,获取第二目标网络地址,包括:
从更新后的第二数据库存储的第二网络地址中,获取第二目标网络地址。
在一些实施例中,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库之后,方法还包括:
将预设的第二计时参数置零,并控制第二计时参数重新开始计时;第二计时参数用于表征第二数据库的未更新时长;
在第二计时参数大于预设时长阈值的情况下,将第二数据库中存储的第二网络地址删除。
在一些实施例中,从第二数据库存储的第二网络地址中,获取第二目标网络地址,包括:
根据第二地址请求报文,确定第二地址标识;
根据第二地址标识从第二数据库存储的第二网络地址中,获取第二地址标识对应的第二网络地址,并确定为所述第二目标网络地址。
第三方面,本申请一些实施例提供一种地址请求报文代答装置,应用于第一隧道端点,装置包括:
第一接收模块,用于接收第二隧道端点发送的第一检测报文;
第一获取模块,用于获取第一检测报文携带的第一网络地址;第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址;
第一代答模块,用于在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
在一些实施例中,装置还包括:
第二生成模块,用于根据第一隧道端点存储的第二网络地址,生成第二检测报文;第二网络地址是第一隧道端点对应的第三设备的网络地址;
第二发送模块,用于向第二隧道端点发送第二检测报文;第二检测报文用于供第二隧道端点获取第二检测报文携带的第二网络地址,并在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,装置还包括:
第二获取模块,用于获取静态隧道的隧道名称和隧道标识;
第二生成模块具体用于:
根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文;
第二发送模块具体用于:
根据隧道名称和隧道标识从第一隧道端点对应的多个静态隧道中,确定第一目标隧道;
通过第一目标隧道向第二隧道端点发送第二检测报文。
在一些实施例中,装置还包括:
第一会话模块,用于第二生成模块根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文之前,根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;
第二发送模块具体还用于:
在会话的状态为保持的情况下,通过第一目标隧道向第二隧道端点发送第二检测报文。
在一些实施例中,装置还包括:
第一存储模块,用于第一获取模块获取第一检测报文携带的第一网络地址之后,将第一网络地址存储在第一数据库中;
第一代答模块具体用于:
从第一数据库存储的第一网络地址中,获取第一目标网络地址,并将第一目标网络地址发送给第二设备。
在一些实施例中,装置还包括:
第一更新模块,用于在接收到第二隧道端点发送的第三检测报文的情况下,根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库;第三检测报文是第二隧道端点根据最新的第一网络地址生成的;
第一代答模块具体还用于:从更新后的第一数据库存储的第一网络地址中,获取第一目标网络地址。
在一些实施例中,装置还包括:
第一计时模块,用于第一更新模块根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库之后,将预设的第一计时参数置零,并控制第一计时参数重新开始计时;第一计时参数用于表征第一数据库的未更新时长;
第一删除模块,用于在第一计时参数大于预设时长阈值的情况下,将第一数据库中存储的第一网络地址删除。
在一些实施例中,第一代答模块具体还用于:
根据第一地址请求报文,确定第一地址标识;
根据第一地址标识从第一数据库存储的第一网络地址中,获取第一地址标识对应的第一网络地址,并确定为第一目标网络地址。
第四方面,本申请一些实施例提供一种地址请求报文代答装置,应用于第二隧道端点,装置包括:
第一生成模块,用于根据第二隧道端点存储的第一网络地址,生成第一检测报文;第一网络地址是第二隧道端点对应的第一设备的网络地址;
第一发送模块,用于向第一隧道端点发送第一检测报文;第一检测报文用于供第一隧道端点获取第一网络地址,并在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
在一些实施例中,装置还包括:
第二接收模块,用于接收第一隧道端点发送的第二检测报文;
第三获取模块,用于获取第二检测报文携带的第二网络地址;第二检测报文是第一隧道端点根据存储的第二网络地址生成的,第二网络地址是第一隧道端点对应的第二设备的网络地址;
第二代答模块,用于在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,装置还包括:
第四获取模块,用于获取静态隧道的隧道名称和隧道标识;
第一生成模块具体用于:
根据第二隧道端点存储的第一网络地址,隧道名称和隧道标识,生成第一检测报文;
第一发送模块具体用于:
根据隧道名称和隧道标识,从第二隧道端点对应的多个静态隧道中,确定第二目标隧道;
通过第二目标隧道向第一隧道端点发送第一检测报文。
在一些实施例中,装置还包括:
第二会话模块,用于第一生成模块根据第二隧道端点存储的第一网络地址,隧道名称和隧道标识,生成第一检测报文之前,根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;
第一发送模块具体还用于:
在会话的状态为保持的情况下,通过第二目标隧道向第一隧道端点发送第一检测报文。
在一些实施例中,获取第二检测报文携带的第二网络地址之后,装置还包括:
第二存储模块,用于将第二网络地址存储在第二数据库中;
第二代答模块具体用于:
从第二数据库存储的第二网络地址中,获取第二目标网络地址,并将第二目标网络地址发送给第四设备。
在一些实施例中,装置还包括:
第二更新模块,用于在接收到第一隧道端点发送的第四检测报文的情况下,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库;第四检测报文是第一隧道端点根据最新的第二网络地址生成的;
第二代答模块具体还用于:
从更新后的第二数据库存储的第二网络地址中,获取第二目标网络地址。
在一些实施例中,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库之后,装置还包括:
第二计时模块,用于将预设的第二计时参数置零,并控制第二计时参数重新开始计时;第二计时参数用于表征第二数据库的未更新时长;
第二删除模块,用于在第二计时参数大于预设时长阈值的情况下,将第二数据库中存储的第二网络地址删除。
在一些实施例中,第二代答模块具体还用于:
根据第二地址请求报文,确定第二地址标识;
根据第二地址标识从第二数据库存储的第二网络地址中,获取第二地址标识对应的第二网络地址,并确定为第二目标网络地址。
第五方面,本申请一些实施例提供一种电子设备,包括:处理器、存储器以及存储在存储器上并在处理器上运行的计算机程序,处理器执行程序时实现如第一方面或第二方面的地址请求报文代答方法。
第六方面,本申请一些实施例提供一种非易失性可读存储介质,当非易失性可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行如第一方面或第二方面的地址请求报文代答方法。
在本申请一些实施例中,由于第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址,因此,第一检测报文携带有第二隧道端点对应的第一设备的网络地址,第一隧道端点接收第二隧道端点发送的第一检测报文,并获取到第一检测报文携带的第一网络地址,则第一隧道端点获取到了第二隧道端点对应的第一设备的网络地址,在第二设备向第一隧道端点发送第一地址请求报文,需要请求第二隧道端点对应的第一设备的网络地址的情况下,第一隧道端点可以直接从第一网络地址中获取所请求的第一目标网络地址,并将第一目标网络地址发送给第二设备,从而实现由第一隧道端点对第一地址请求报文进行代答。这样,第一隧道端点可以直接基于获取到的第一网络地址,对第一地址请求报文进行代答,避免了相关技术中VTEP广播报文的方式造成的报文泛滥的问题,一定程度上可以降低占用的网络资源,提高网络性能。
为了更清楚地说明本申请一些实施例或相关技术中的技术方案,下面将对一些实施例或相关技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本申请一些实施例提供的一种地址请求报文代答方法的步骤流程图;
图2是本申请一些实施例提供的另一种地址请求报文代答方法的步骤流程图;
图3是相关技术中ARP请求报文抑制的示意图;
图4是相关技术中的ARP广播抑制的示意图;
图5是相关技术中的ARP代答的示意图;
图6是本申请一些实施例提供的BFD(Bidirectional Forwarding Detection,双向转发检测)远程MAC地址发布的示意图;
图7是本申请一些实施例提供的服务设备架构示意图;
图8是本申请一些实施例提供的服务控制流程示意图;
图9是本申请一些实施例提供的BFD保持活动状态封包携带远程MAC地址的示意图;
图10是本申请一些实施例提供的BFD远程MAC地址的控制流程示意图;
图11是本申请一些实施例提供的一种地址请求报文代答装置的结构图;
图12是本申请一些实施例提供的另一种地址请求报文代答装置的结构图;
图13是本申请一些实施例提供的电子设备的示意图。
下面将结合本申请一些实施例中的附图,对本申请一些实施例中的技术方案进行清楚、完整地描述,显然,所描述的一些实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的一些实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
图1是本申请一些实施例提供的一种地址请求报文代答方法的步骤流程图,如图1所示,该方法应用于第一隧道端点,方法包括:
步骤101,接收第二隧道端点发送的第一检测报文。
本申请一些实施例中,第一隧道端点和第二隧道端点可以是虚拟局域网扩展(VXLAN)的虚拟隧道端点(VTEP),第一隧道端点和第二隧道端点之间可以通过隧道连接。其中,隧道是一种虚拟通道,VXLAN通信双方即第一隧道端点和第二隧道端点认为自己是在直接通信,并不知道底层网络的存在。
本申请一些实施例中,第一检测报文可以是用于检测第一隧道端点和第二隧道端点之间的双向转发路径故障检测的报文。例如,双向转发检测(Bidirectional Forwarding Detection,BFD)技术中的BFD报文。本申请一些实施例中的第一检测报文中,在有关双向转发路径故障检测的内容以外,携带有第二隧道端点存储的第一网络地址,其中,第一网络地址是第二隧道端点学习到的本地设备的网络地址,网络地址可以包括互联网协议(Internet protocol,IP)地址和介质访问控制(medium access control,MAC)地址。
需要说明的是,BFD是一种统一的检测机制,用于快速检测、监控网络中链路或IP路由的转发连通情况。BFD可以在两台网络设备上建立会话,用来检测网络设备之间的双向转发路径,会话建立后一台网络设备可以周期性地快速发送BFD报文,如果在检测时间内没有收到对端网络设备回复的BFD报文,则认为两台网络设备之间的双向转发路径发生了故障,可以通知被服务的上层应用进行相应的故障处理。
步骤102,获取第一检测报文携带的第一网络地址;第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址。
本申请一些实施例实施例中,第二隧道端点对应的第一设备可以是与该第二隧道端点连接的设备,第一设备可以是一个也可以是多个,本申请一些实施例对此不做限制。第二隧道端点可以学习所连接的第一设备的网络地址,具体的,可以获取第一设备的IP地址和MAC地址并进行存储。
本申请一些实施例中,第二隧道端点在生成第一检测报文时,可以根据报文格式将第二隧道端点对应的各第一设备的第一网络地址,添加到可选内容对应的字段,使得第一检测报文携带各第一设备的第一网络地址。例如,第一检测报文是BFD报文,可以将第一网络地址添加到48个字节以后的可选内容字段,使得BFD报文携带第一网络地址。此处仅是举例说明,本申请一些实施例对此不做限制。
本申请一些实施例中,第一隧道端点接收到第一检测报文,可以进行解包操作,从第一检测报文中获取到第一网络地址,并将第一网络地址存储到指定的位置,比如,可以存储到第一数据库中,以便在接收到第一地址请求报文时从第一数据库中查询获取。
步骤103,在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标
网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
本申请一些实施例中,第二设备可以是第一隧道端点所连接的设备中的一个设备,第二设备根据已知的、所需访问的目标设备的IP地址,以及所请求目标设备的MAC地址生成第一地址请求报文,并将该第一地址请求报文发送给第一隧道端点。其中,目标设备可以是第二隧道端点对应的任一第一设备。
本申请一些实施例中,第一地址请求报文所请求的第一网络地址可以是目标设备的MAC地址,目标设备可以是第二隧道端点对应的任一第一设备,即第一目标网络地址可以是第二隧道端点对应的任一第一设备的MAC地址。
本申请一些实施例中,在接收到第一地址请求报文的情况下,第一隧道端点可以根据第一地址请求报文确定第二设备所请求的目标设备的IP地址,根据目标设备的IP地址从存储的第一网络地址中查找并获取与目标设备的IP地址对应的目标设备的MAC地址,作为第一目标网络地址,并将第一目标网络地址即目标设备的MAC地址发送给第二设备,从而实现由第一隧道端点对第一地址请求报文进行代答,即回复第二设备所请求的第一目标网络地址。
例如,第一地址请求报文可以是ARP请求报文,第一隧道端点在接收到ARP请求报文的情况下,可以根据ARP请求报文所请求的目标设备的IP地址,从存储的第一网络地址中获取与目标设备的IP地址对应的目标设备的MAC地址,作为第一目标网络地址回复给第二设备,从而对ARP请求报文进行代答。其中,目标设备可以是第二隧道端点对应的任一第一设备。
本申请一些实施例的地址请求报文代答方法,相比于相关技术中VTEP接收到ARP请求报文时,将ARP请求报文进行广播,通过广播的方式从VXLAN网络中获取目标设备的网络地址的操作,可以避免第一隧道端点对第一地址请求报文进行广播,第一隧道端点可以直接基于获取到的第一网络地址,对第一地址请求报文所请求的地址进行答复,可以避免报文泛滥的问题,进一步地,可以降低占用的网络资源,提高网络性能。
在本申请一些实施例中,由于第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址,因此,第一检测报文携带有第二隧道端点对应的第一设备的网络地址,第一隧道端点接收第二隧道端点发送的第一检测报文,并获取到第一检测报文携带的第一网络地址,则第一隧道端点获取到了第二隧道端点对应的第一设备的网络地址,在第二设备向第一隧道端点发送第一地址请求报文,需要请求第二隧道端点对应的第一设备的网络地址的情况下,第一隧道端点可以直接从第一网络地址中获取所请求的第一目标网络地址,并将第一目标网络地址发送给第二设备,从而实现由第一隧道端点对第一地址请求报文进行代答。这样,第一隧道端点可以直接基于获取到的第一网络地址,对第一地址请求报文进行代答,避免了相关技术中VTEP广播报文的方式造成的报文泛滥的问题,一定程度上可以降低占用的网络资源,提高网络性能。
在一些实施例中,方法还包括:
步骤201,根据第一隧道端点存储的第二网络地址,生成第二检测报文;第二网络地址是第一隧道端点对应的第三设备的网络地址。
本申请一些实施例中,第一隧道端点对应的第三设备可以是与该第一隧道端点连接的设备,第三设备可以是一个也可以是多个,本申请一些实施例对此不做限制。第一隧道端点可以学习所连接的第三设备的网络地址,具体的,可以获取第三设备的IP地址和MAC地址并进
行存储。
本申请一些实施例中,第一隧道端点可以根据检测报文的报文格式,将第一隧道端点对应的各第三设备的第二网络地址,添加到第二检测报文的可选内容对应的字段,然后将添加了第二网络地址的检测报文确定为第二检测报文,使得第二检测报文携带各第三设备的第二网络地址。例如,第二检测报文是BFD报文,可以将第二网络地址添加到BFD报文的48个字节以后的可选内容字段,使得BFD报文携带第二网络地址。此处仅是举例说明,本申请一些实施例对此不做限制。
步骤202,向第二隧道端点发送第二检测报文;第二检测报文用于供第二隧道端点获取第二检测报文携带的第二网络地址,并在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
本申请一些实施例中,第一隧道端点可以通过与第二隧道端点连接的隧道,向第二隧道端点发送第二检测报文。第二隧道端点接收到第二检测报文,可以进行解包操作,从第二检测报文中获取到第二网络地址,并将第二网络地址存储到指定的位置,比如,可以存储到第二数据库中,以便在接收到第二地址请求报文时从第二数据库中查询获取。
本申请一些实施例中,第四设备可以是第二隧道端点所连接的设备中的一个设备,第四设备根据已知的、所需访问的目标设备的IP地址,以及所请求目标设备的MAC地址生成第二地址请求报文,并将该第二地址请求报文发送给第一隧道端点。其中,目标设备可以是第一隧道端点对应的任一第三设备。
本申请一些实施例中,第二地址请求报文所请求的第二网络地址可以是目标设备的MAC地址,目标设备可以是第一隧道端点对应的任一第三设备,即第二目标网络地址可以是第一隧道端点对应的任一第三设备的MAC地址。
本申请一些实施例中,在接收到第二地址请求报文的情况下,第二隧道端点可以根据第二地址请求报文确定第四设备所请求的目标设备的IP地址,根据目标设备的IP地址从存储的第二网络地址中获取与目标设备的IP地址对应的目标设备的MAC地址,作为第二目标网络地址,并将第二目标网络地址即目标设备的MAC地址发送给第四设备,从而实现由第二隧道端点对第二地址请求报文进行代答,回复第四设备所请求的第二目标网络地址。
在本申请一些实施例中,由于第二检测报文是第一隧道端点根据存储的第二网络地址生成的,第二网络地址是第一隧道端点对应的第三设备的网络地址,因此,第二检测报文携带有第一隧道端点对应的第三设备的网络地址,第一隧道端点向第二隧道端点发送第二检测报文,使得第二隧道端点接收并获取到第二检测报文携带的第二网络地址,则第二隧道端点获取到了第一隧道端点对应的第三设备的网络地址,在第四设备向第二隧道端点发送第二地址请求报文,需要请求第一隧道端点对应的第三设备的网络地址的情况下,第二隧道端点可以直接从第二网络地址中获取所请求的第二目标网络地址,并将第二目标网络地址发送给第四设备,从而实现由第二隧道端点对第二地址请求报文进行代答。这样,第二隧道端点可以直接基于获取到的第二网络地址,对第二地址请求报文进行代答,避免了相关技术中VTEP广播报文的方式造成的报文泛滥的问题,一定程度上可以降低占用的网络资源,提高网络性能。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,方法还包括:
步骤301,获取静态隧道的隧道名称和隧道标识。
步骤201在一些实施例中包括以下步骤:
步骤2011,根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文。
步骤202在一些实施例中包括以下步骤:
步骤2022,根据隧道名称和隧道标识从第二隧道端点对应的多个静态隧道中,确定第一目标隧道。
步骤2023,通过第一目标隧道向第二隧道端点发送第二检测报文。
本申请一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,具体的,第一隧道端点与第二隧道端点之间可以配置静态路由以及进行虚拟局域网(Virtual Local Area Network,VLAN)的相关设定,然后创建VXLAN静态隧道接口实例,从而在第一隧道端点与第二隧道端点之间建立静态隧道。具体的配置方法和创建方法可以参考相关技术中的描述,本申请一些实施例对此不做限制。
本申请一些实施例中,第一隧道端点可以从VXLAN网络的上层应用获取VXLAN静态隧道的隧道名称和隧道标识,其中,隧道标识可以是VXLAN网络的识别标识(VXLAN network identifier,VNI)。第一隧道端点可以根据检测报文的报文格式,将第一隧道端点对应的各第三设备的第二网络地址,以及获取到的隧道名称和隧道标识一并添加到第二检测报文的可选内容对应的字段,然后将添加后的检测报文确定为第二检测报文,使得第二检测报文携带各第三设备的第二网络地址,并携带VXLAN静态隧道的隧道名称和隧道标识。VXLAN静态隧道的隧道名称和隧道标识可以供第二隧道端点在接收到第二检测报文后根据隧道名称和隧道标识进行隧道识别,以确定与第一隧道端点连接的目标隧道。
本申请一些实施例中,第一隧道端点可以连接有多个静态隧道,第一隧道端点可以根据与第二隧道端点连接的静态隧道的隧道名称和隧道标识进行识别,从多个静态隧道中确定与第二隧道端点连接的静态隧道,并作为第一目标隧道。具体的,可以根据隧道名称和隧道标识,对第一隧道端点和第二隧道端点连接的静态隧道对应的静态路由进行配置,即将隧道名称和隧道标识配置为该静态路由的下一跳,从而将第一隧道端点和第二隧道端点连接的静态隧道确定为第一目标隧道。
在本申请一些实施例中,通过获取静态隧道的隧道名称和隧道标识;根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文;根据隧道名称和隧道标识从第一隧道端点对应的多个静态隧道中,确定第一目标隧道;通过第一目标隧道向第二隧道端点发送第二检测报文。这样,第一隧道端点可以方便地根据隧道名称和隧道标识,对与第二隧道端点连接的静态隧道进行识别,确定第一目标隧道,从而方便地通过第一目标隧道向第二隧道端点发送第二检测报文,使得第二隧道端点可以接收到第二检测报文,一定程度上可以提高本申请实施例的地址请求报文代答方法的实用性。
在一些实施例中,步骤2011之前,方法还包括:
步骤401,根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话。
步骤2023可以包括以下步骤:
步骤2023a,在会话的状态为保持的情况下,通过第一目标隧道向第二隧道端点发送第二检测报文。
本申请一些实施例中,第一隧道端点可以根据隧道名称、隧道标识以及第一隧道端点的标识符生成会话协商报文,并将会话协商报文发送给第二隧道端点,第二隧道端点在接收到会话协商报文后,可以获取会话协商报文携带的隧道名称和隧道标识,并与第二隧道端点本地存储的隧道名称和隧道标识进行匹配,如果隧道名称和隧道标识一致则匹配成功,则第二隧道端点学习到第一隧道端点的标识符,从而与第一隧道端点建立会话。
本申请一些实施例中,第一隧道端点和第二隧道端点建立会话的情况下,可以通过周期性发送报文的方式确定双向沟通正常,若双方均可以接收到对端发送的报文,则会话状态为保持,若任一方接收不到对端发送的报文,则会话状态为断开。
本申请一些实施例中,在第一隧道端点和第二隧道端点建立的会话状态为保持的情况下,表征第一隧道端点和第二隧道端点之间的双向沟通正常,第一隧道端点通过第一目标隧道向第二隧道端点发送第二检测报文,使得第二隧道端点可以接收到第二检测报文,一定程度上可以提高第二检测报文的发送成功率。进一步地,使得第二隧道端点可以从第二检测报文获取到第二网络地址,从而对发送给第二隧道端点的第二地址请求报文进行代答,可以提高本申请一些实施例的地址请求报文代答方法的代答成功率。
在本申请一些实施例中,通过根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;在会话的状态为保持的情况下,通过第一目标隧道向第二隧道端点发送第二检测报文。这样,可以通过第一隧道端点和第二隧道端点之间的会话状态,在会话的状态为保持的情况下,可以确定第一隧道端点和第二隧道端点之间的沟通正常,使得第二隧道端点可以接收到第一隧道端点发送的第二检测报文,一定程度上可以提高第二检测报文的发送成功率。
在一些实施例中,获取第一检测报文携带的第一网络地址之后,方法还包括:
步骤501,将第一网络地址存储在第一数据库中。
步骤103可以包括以下步骤:
步骤1031,从第一数据库存储的第一网络地址中,获取第一目标网络地址,并将第一目标网络地址发送给第二设备。
本申请一些实施例中,第一数据库可以是第一隧道端点连接的数据库,第一数据库可以是本地数据库,也可以是网络数据库,本申请一些实施例对此不做限制。第一隧道端点获取到第一网络地址后,可以将第一网络地址存储到第一数据库中,具体的,第一网络地址可以包括第二隧道端点对应的第一设备的IP地址和MAC地址,可以将第一设备的IP地址和MAC地址对应存储在第一数据库中。
在第一隧道端点接收到第一地址请求报文的情况下,可以根据第一地址请求报文中所请求的目标设备的IP地址从第一数据库中查询该IP地址对应的MAC地址,并作为第一目标网络地址,将该第一目标网络地址即MAC地址发送给第二设备,以对第二设备所请求的目标设备的MAC地址进行答复。
在本申请一些实施例中,通过将第一网络地址存储在第一数据库中,可以方便第一隧道端点在接收到第一地址请求的情况下,直接从第一数据库存储的第一网络地址中,获取第一目标网络地址,可以提高第一目标网络地址的获取效率,并将第一目标网络地址发送给第二设备,一定程度上可以提高本申请一些实施例提高的地址请求报文方法的代答效率。
在一些实施例中,方法还包括:
步骤601,在接收到第二隧道端点发送的第三检测报文的情况下,根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库;第三检测报文是第二隧道端点根据最新的第一网络地址生成的。
步骤1031可以包括以下步骤:
步骤1031a,从更新后的第一数据库存储的第一网络地址中,获取第一目标网络地址。
本申请一些实施例中,在第一隧道端点和第二隧道端点之间建立会话的情况下,第一隧道端点和第二隧道端点可以周期性地通过向对端发送检测报文,来确定第一隧道端点和第二隧道端点之间的双向转发路径正常。第二隧道端点在周期性向第一隧道端点发送检测报文的过程中,可以不断学习与该第二隧道连接的第一设备的网络地址,获得最新的各第一设备的网络地址,并作为最新的第一网络地址。第二隧道端点在学习到最新的第一网络地址的情况下,可以根据该最新的第一网络地址生成第三检测报文,并向第一隧道端点发送该第三检测报文。具体的,可以根据检测报文的报文格式将最新的第一网络地址添加到可选内容对应的字段,并将添加后的检测报文作为第三检测报文。
本申请一些实施例中,第一隧道端点在接收到第二隧道端点发送的第三检测报文的情况下,可以进行解包操作,获取第三检测报文携带的最新的第一网络地址。然后,将第一数据库中存储的第一网络地址更新为最新的第一网络地址,可以将更新的第一网络地址的第一数据库作为更新后的第一数据库。第一隧道端点在接收到第一地址请求的情况下,可以从更新后的第一数据库存储的第一网络地址中,获取第一目标网络地址,使得第一目标网络地址为最新的第一网络地址。进一步地,第一隧道端点将第一目标网络地址发送给第二设备,可以提高本申请一些实施例提供的地址请求报文代答方法的代答准确度。
在本申请一些实施例中,通过在接收到第二隧道端点发送的第三检测报文的情况下,根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库。由于第三检测报文是第二隧道端点根据最新的第一网络地址生成的,因此,第一隧道端点可以将第一数据库中存储的第一网络地址更新为最新的第一网络地址,使得更新后的第一数据库中存储的第一网络地址为最新的第一网络地址,使得更新后的第一数据库更加准确。进一步地,第一隧道端点从更新后的第一数据库存储的第一网络地址中获取第一目标网络地址,可以使得第一目标网络地址是最新的第一网络地址,一定程度上可以提高第一目标网络地址的准确度。
在一些实施例中,步骤601之后,方法还包括:
步骤701,将预设的第一计时参数置零,并控制第一计时参数重新开始计时;第一计时参数用于表征第一数据库的未更新时长。
步骤702,在第一计时参数大于预设时长阈值的情况下,将第一数据库中存储的第一网络地址删除。
本申请一些实施例中,可以通过第一计时参数对第一数据库未更新的时长进行统计,第一计时参数被置零,并重新开始计时后,可以自动记录第一数据库的未更新时长。其中,第一数据库的未更新时长表征未对第一数据库中存储的第一网络地址进行更新的时长。
本申请一些实施例中,第一隧道端点在对第一数据库中存储的第一网络地址进行更新之后,可以将第一计时参数置零比如将第一计时参数赋值为零,并控制第一计时参数重新开始计时,使得第一计时参数可以自动记录第一数据库的未更新时长。
本申请一些实施例中,预设时长阈值可以表征第一数据库允许的最大未更新时长,预设时长阈值可以根据实际应用场景进行设置,本申请一些实施例对此不做限制。在第一计时参数大于预设时长阈值的情况下,表征第一数据库中存储的第一网络地址已经过期,可以将第一数据库中存储的第一网络地址删除,以减少过期的第一网络地址对第一数据库的资源占用,提高第一数据库的资源利用率。
在本申请一些实施例中,通过将预设的第一计时参数置零,并控制第一计时参数重新开始计时;在第一计时参数大于预设时长阈值的情况下,将第一数据库中存储的第一网络地址删除。由于第一计时参数用于表征第一数据库的未更新时长,在第一计时参数大于预设时长阈值的情况下,表征第一数据库的未更新时长已经大于预设时长阈值,第一数据库中存储的第一网络地址超时未更新,进一步地,通过将第一数据库中存储的第一网络地址删除,可以减少超时未更新的第一网络地址对第一数据库的资源占用,一定程度上,可以提高第一数据库的资源利用率。
在一些实施例中,步骤1031可以包括以下步骤:
步骤1031b,根据第一地址请求报文,确定第一地址标识。
步骤1031c,根据第一地址标识从第一数据库存储的第一网络地址中,获取第一地址标识对应的第一网络地址,并确定为第一目标网络地址。
本申请一些实施例中,第一地址请求报文可以是第二设备根据已知的所需访问的目标设备的IP地址,以及所请求目标设备的MAC地址生成的。第一地址标识可以是第一地址请求报文中目标设备的IP地址。
本申请一些实施例中,第一隧道端点可以对第一地址请求报文进行解包操作,得到第一地址请求报文中的目标设备的IP地址,作为第一地址标识。第一隧道端点可以根据目标设备的IP地址从第一数据库中查找目标设备的IP地址对应的目标设备的MAC地址,并将查找到的目标设备的MAC地址即第一地址标识对应的第一网络地址,确定为第一目标网络地址。
在本申请一些实施例中,通过根据第一地址请求报文,确定第一地址标识;根据第一地址标识从第一数据库存储的第一网络地址中,获取第一地址标识对应的第一网络地址,并确定为所述第一目标网络地址。这样,由于第一地址标识是根据第一地址请求报文确定,因此,第一地址标识与第一地址请求报文所请求的第一网络地址相匹配,进一步地,根据第一地址标识可以方便地从第一数据库中确定第一目标网络地址,一定程度上可以提高第一目标网络地址的获取效率。
图2是本申请一些实施例提供的另一种地址请求报文代答方法的步骤流程图,如图2所示,该方法应用于第二隧道端点,方法包括:
步骤801,根据第二隧道端点存储的第一网络地址,生成第一检测报文;第一网络地址是第二隧道端点对应的第一设备的网络地址。
步骤802,向第一隧道端点发送第一检测报文;第一检测报文用于供第一隧道端点获取第一网络地址,并在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
本申请一些实施例中,第二隧道端点对应的第一设备可以是与该第二隧道端点连接的设
备,第一设备可以是一个也可以是多个,本申请一些实施例对此不做限制。第二隧道端点可以学习所连接的第一设备的网络地址,具体的,可以获取第一设备的IP地址和MAC地址并进行存储。
本申请一些实施例中,第二隧道端点在生成第一检测报文时,可以根据报文格式将第二隧道端点对应的各第一设备的第一网络地址,添加到可选内容对应的字段,使得第一检测报文携带各第一设备的第一网络地址。
本申请一些实施例中,第一隧道端点所执行的步骤,可以参考步骤101~103的相关描述,此处不再赘述。
在本申请实施例中,由于第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是第二隧道端点对应的第一设备的网络地址,因此,第一检测报文携带有第二隧道端点对应的第一设备的网络地址,第一隧道端点接收第二隧道端点发送的第一检测报文,并获取到第一检测报文携带的第一网络地址,则第一隧道端点获取到了第二隧道端点对应的第一设备的网络地址,在第二设备向第一隧道端点发送第一地址请求报文,需要请求第二隧道端点对应的第一设备的网络地址的情况下,第一隧道端点可以直接从第一网络地址中获取所请求的第一目标网络地址,并将第一目标网络地址发送给第二设备,从而实现由第一隧道端点对第一地址请求报文进行代答。这样,第一隧道端点可以直接基于获取到的第一网络地址,对第一地址请求报文进行代答,避免了相关技术中VTEP广播报文的方式造成的报文泛滥的问题,一定程度上可以降低占用的网络资源,提高网络性能。
在一些实施例中,方法还包括:
步骤901,接收第一隧道端点发送的第二检测报文。
步骤902,获取第二检测报文携带的第二网络地址;第二检测报文是第一隧道端点根据存储的第二网络地址生成的,第二网络地址是第一隧道端点对应的第二设备的网络地址。
步骤903,在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
本申请一些实施例中,第二隧道端点接收到第二检测报文,可以进行解包操作,从第二检测报文中获取到第二网络地址,并将第二网络地址存储到指定的位置,比如,可以存储到第二数据库中,以便在接收到第二地址请求报文时从数据库中查询获取。
本申请一些实施例中,第四设备可以是第二隧道端点所连接的设备中的一个设备,第四设备根据已知的、所需访问的目标设备的IP地址,以及所请求目标设备的MAC地址生成第二地址请求报文,并将该第二地址请求报文发送给第一隧道端点。其中,目标设备可以是第一隧道端点对应的任一第三设备。
本申请一些实施例中,第二地址请求报文所请求的第二网络地址可以是目标设备的MAC地址,目标设备可以是第一隧道端点对应的任一第三设备,即第二目标网络地址可以是第一隧道端点对应的任一第三设备的MAC地址。
本申请一些实施例中,在接收到第二地址请求报文的情况下,第二隧道端点可以根据第二地址请求报文确定第四设备所请求的目标设备的IP地址,根据目标设备的IP地址从存储的第二网络地址中获取与目标设备的IP地址对应的目标设备的MAC地址,作为第二目标网络地
址,并将第二目标网络地址即目标设备的MAC地址发送给第四设备,从而实现由第二隧道端点对第二地址请求报文进行代答,回复第四设备所请求的第二目标网络地址。
在本申请一些实施例中,由于第二检测报文是第一隧道端点根据存储的第二网络地址生成的,第二网络地址是第一隧道端点对应的第三设备的网络地址,因此,第二检测报文携带有第一隧道端点对应的第三设备的网络地址,第一隧道端点向第二隧道端点发送第二检测报文,使得第二隧道端点接收并获取到第二检测报文携带的第二网络地址,则第二隧道端点获取到了第一隧道端点对应的第三设备的网络地址,在第四设备向第二隧道端点发送第二地址请求报文,需要请求第一隧道端点对应的第三设备的网络地址的情况下,第二隧道端点可以直接从第二网络地址中获取所请求的第二目标网络地址,并将第二目标网络地址发送给第四设备,从而实现由第二隧道端点对第二地址请求报文进行代答。这样,第二隧道端点可以直接基于获取到的第二网络地址,对第二地址请求报文进行代答,避免了相关技术中VTEP广播报文的方式造成的报文泛滥的问题,一定程度上可以降低占用的网络资源,提高网络性能。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,方法还包括:
步骤1001,获取静态隧道的隧道名称和隧道标识。
步骤801可以包括以下步骤:
步骤8011,根据第二隧道端点存储的所述第一网络地址,隧道名称和隧道标识,生成第一检测报文。
步骤802可以包括以下步骤:
步骤8021,根据隧道名称和所述隧道标识,从第二隧道端点对应的多个静态隧道中,确定第二目标隧道。
步骤8022,通过第二目标隧道向所述第一隧道端点发送第一检测报文。
本申请一些实施例中,步骤1001的实现方式可以参照步骤301中的实现方式,此处不再赘述。
本申请一些实施例中,第二隧道端点可以连接有多个静态隧道,第二隧道端点可以根据与第二隧道端点连接的静态隧道的隧道名称和隧道标识进行识别,从多个静态隧道中确定与第一隧道端点连接的静态隧道,并作为第二目标隧道。具体的,可以根据隧道名称和隧道标识,对第一隧道端点和第二隧道端点连接的静态隧道对应的静态路由进行配置,即将隧道名称和隧道标识配置为该静态路由的下一跳,从而将第一隧道端点和第二隧道端点连接的静态隧道确定为第二目标隧道。
在本申请一些实施例中,第二隧道端点可以方便地根据隧道名称和隧道标识对与第二隧道端点连接的静态隧道进行识别,确定第二目标隧道,从而方便地通过第二目标隧道向第一隧道端点发送第一检测报文,使得第一隧道端点可以接收到第一检测报文,一定程度上可以提高本申请一些实施例的地址请求报文代答方法的实用性。
在一些实施例中,步骤8011之前,方法还包括:
步骤1101,根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话。
步骤8022可以包括以下步骤:
步骤8022a,在会话的状态为保持的情况下,通过第二目标隧道向第一隧道端点发送第一检测报文。
本申请一些实施例中,步骤1101的实现方式可以参照步骤401中的实现方式,此处不再
赘述。
在本申请一些实施例中,在第一隧道端点和第二隧道端点建立的会话状态为保持的情况下,表征第一隧道端点和第二隧道端点之间的双向沟通正常,第二隧道端点通过第二目标隧道向第一隧道端点发送第一检测报文,可以使得第一隧道端点可以接收到第一检测报文,一定程度上可以提高第一检测报文的发送成功率。进一步地,使得第一隧道端点可以从第一检测报文获取到第一网络地址,从而对发送给第一隧道端点的第一地址请求报文进行代答,可以提高本申请一些实施例的地址请求报文代答方法的代答成功率。
在一些实施例中,获取第二检测报文携带的第二网络地址之后,方法还包括:
步骤1201,将第二网络地址存储在第二数据库中。
步骤903可以包括以下步骤:
步骤9031,从第二数据库存储的第二网络地址中,获取第二目标网络地址,并将第二目标网络地址发送给第四设备。
本申请一些实施例中,第二数据库可以是第二隧道端点连接的数据库,第二数据库可以是本地数据库,也可以是网络数据库,本申请实施例对此不做限制。第二隧道端点获取到第二网络地址后,可以将第二网络地址存储到第二数据库中,具体的,第二网络地址可以包括第一隧道端点对应的第三设备的IP地址和MAC地址,可以将第三设备的IP地址和MAC地址对应存储在第二数据库中。
在第二隧道端点接收到第二地址请求报文的情况下,可以根据第二地址请求报文中所请求的目标设备的IP地址从第二数据库中查询该IP地址对应的MAC地址,并作为第二目标网络地址,将该第二目标网络地址即MAC地址发送给第四设备,以对第四设备所请求的目标设备的MAC地址进行答复。
在本申请一些实施例中,通过将第二网络地址存储在第二数据库中,可以方便第二隧道端点在接收到第二地址请求的情况下,直接从第二数据库存储的第二网络地址中,获取第二目标网络地址,可以提高第二目标网络地址的获取效率,并将第二目标网络地址发送给第四设备,一定程度上可以提高本申请一些实施例提高的地址请求报文方法的代答效率。
在一些实施例中,方法还包括:
步骤1301,在接收到第一隧道端点发送的第四检测报文的情况下,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库;第四检测报文是第一隧道端点根据最新的第二网络地址生成的。
步骤9031可以包括以下步骤:
步骤9031a,从更新后的第二数据库存储的第二网络地址中,获取第二目标网络地址。
本申请一些实施例中,第一隧道端点在学习到最新的第二网络地址的情况下,可以根据该最新的第二网络地址生成第四检测报文,并向第二隧道端点发送该第四检测报文。具体的,可以根据检测报文的报文格式将最新的第二网络地址添加到可选内容对应的字段,并将添加后的检测报文作为第四检测报文。
本申请一些实施例中,第二隧道端点在接收到第一隧道端点发送的第四检测报文的情况下,可以进行解包操作,获取第四检测报文携带的最新的第二网络地址;然后,将第二数据库中存储的第二网络地址更新为最新的第二网络地址,可以将更新的第二网络地址的第二数据库作为更新后的第二数据库。第二隧道端点在接收到第二地址请求的情况下,可以从更新
后的第二数据库存储的第二网络地址中,获取第二目标网络地址,使得第二目标网络地址为最新的第二网络地址。进一步地,第二隧道端点将第二目标网络地址发送给第四设备,可以提高本申请一些实施例提供的地址请求报文代答方法的代答准确度。
在本申请一些实施例中,由于第四检测报文是第一隧道端点根据最新的第二网络地址生成的,因此,第二隧道端点可以将第二数据库中存储的第二网络地址更新为最新的第二网络地址,使得更新后的第二数据库中存储的第二网络地址为最新的第二网络地址,可以更新后的第二数据库更加准确。进一步地,第二隧道端点从更新后的第二数据库存储的第二网络地址中,获取第二目标网络地址,可以使得第二目标网络地址是最新的第二网络地址,一定程度上可以提高第二目标网络地址的准确度。
在一些实施例中,步骤1301之后,方法还包括:
步骤1401,将预设的第二计时参数置零,并控制第二计时参数重新开始计时;第二计时参数用于表征第二数据库的未更新时长。
步骤1402,在第二计时参数大于预设时长阈值的情况下,将第二数据库中存储的第二网络地址删除。
本申请一些实施例中,可以通过第二计时参数对第二数据库未更新的时长进行统计,第二计时参数被置零,并重新开始计时后,可以自动记录第二数据库的未更新时长。其中,第二数据库的未更新时长表征未对第二数据库中存储的第二网络地址进行更新的时长。
本申请一些实施例中,第二隧道端点在对第二数据库中存储的第二网络地址进行更新之后,可以将第二计时参数置零比如将第二计时参数赋值为零,并控制第二计时参数重新开始计时,使得第二计时参数可以自动记录第二数据库的未更新时长。
本申请一些实施例中,在第二计时参数大于预设时长阈值的情况下,可以表征第二数据库中存储的第二网络地址已经过期,可以将第二数据库中存储的第二网络地址删除,以减少过期的第二网络地址对第一数据库的资源占用,提高第一数据库的资源利用率。
在本申请一些实施例中,由于第二计时参数用于表征第二数据库的未更新时长,在第二计时参数大于预设时长阈值的情况下,表征第二数据库的未更新时长已经大于预设时长阈值,第二数据库中存储的第二网络地址超时未更新,进一步地,通过将第二数据库中存储的第二网络地址删除,可以减少超时未更新的第二网络地址对第二数据库的资源占用,一定程度上,可以提高第二数据库的资源利用率。
在一些实施例中,步骤9031可以包括以下步骤:
步骤9031b,根据第二地址请求报文,确定第二地址标识。
步骤9031c,根据第二地址标识从所述第二数据库存储的第二网络地址中,获取第二地址标识对应的第二网络地址,并确定为第二目标网络地址。
本申请一些实施例中,第二地址请求报文可以是第四设备根据已知的所需访问的目标设备的IP地址,以及所请求目标设备的MAC地址生成的。第二地址标识可以是第二地址请求报文中目标设备的IP地址。
本申请一些实施例中,第二隧道端点可以对第二地址请求报文进行解包操作,得到第二地址请求报文中的目标设备的IP地址,作为第二地址标识。第二隧道端点可以根据目标设备的IP地址从第二数据库中查找目标设备的IP地址对应的目标设备的MAC地址,并将查找到的目标设备的MAC地址即第二地址标识对应的第二网络地址,确定为第二目标网络地址。
在本申请一些实施例中,由于第二地址标识是根据第二地址请求报文确定,因此,第二地址标识与第二地址请求报文所请求的第二网络地址相匹配,进一步地,根据第二地址标识可以方便地从第二数据库中确定第二目标网络地址,一定程度上可以提高第二目标网络地址的获取效率。
图3是相关技术中ARP请求报文抑制的示意图,图3中(1)虚拟机(Virtual Machine,VM)1发送ARP请求报文获取虚拟机7的MAC地址,(2)虚拟隧道端点(VTEP)1接收到ARP请求报文后为虚拟机1创建ARP抑制表项,并在VXLAN网络中泛洪ARP请求报文,以及通过边界网关协议(Border Gateway Protocol,BGP)以太网虚拟专用网络(Ethernet Virtual Private Network,EVPN)即图3中的传输网络,将虚拟机1的ARP抑制表项发送给虚拟隧道端点2和虚拟隧道端点3。(3)虚拟隧道端点2和虚拟隧道端点3解封装ARP请求报文并在本地站点广播ARP请求报文,(4)虚拟机7向虚拟隧道端点2发送ARP回复,(5)虚拟隧道端点2为虚拟机7创建ARP抑制表项,并将ARP回复转发给虚拟隧道端点1,以及通过BGP EVPN将虚拟机7的ARP抑制表项发送给虚拟隧道端点1和虚拟隧道端点3。(6)虚拟隧道端点1解封装ARP回复并将ARP回复转发给虚拟机1。(7)虚拟机4发送ARP请求报文获取虚拟机1的MAC地址,(8)虚拟隧道端点1为虚拟机4创建ARP抑制表项,并根据虚拟机1的ARP抑制表项回复虚拟机4的ARP请求报文。(9)虚拟机10发送ARP请求报文获取虚拟机1的MAC地址。(10)虚拟隧道端点3为虚拟机10创建ARP抑制表项,并根据虚拟机1的ARP抑制表项回复虚拟机10的ARP请求。
图4是相关技术中的ARP广播抑制的示意图,如图4所示,VXLAN三层网关L3可以动态学习服务器1和服务器2的ARP抑制表项,再根据ARP抑制表项生成主机信息,主机信息包括服务器1和服务器2各自的主机IP地址、MAC地址、虚拟隧道端点(VTEP)地址和虚拟局域网扩展识别标识(VNI ID),并将主机信息通过BGP EVPN对外发布,使其他的BGP邻居比如图4中的VXLAN二层网关L2,可以学习到L3网关的主机信息,VXLAN二层网关L2学习到的主机信息可以用于广播抑制。具体的,服务器1初次访问服务器2时,服务器1会向服务器2发送地址解析协议(ARP)请求报文,请求目的主机服务器2的MAC地址,作为VXLAN二层网关的设备1收到ARP请求报文后查询主机信息,如果设备1中有目的主机的MAC地址,设备1将ARP请求报文中的广播目的MAC地址替换为目的主机的MAC地址,并进行VXLAN封装后转发。如果设备1中没有目的主机信息,ARP请求报文中的广播目的MAC地址不变,设备1进行VXLAN封装后转发。服务器2收到单播的ARP请求报文后,进行ARP应答。服务器1收到服务器2发送的ARP应答报文建立ARP抑制表项,并可以与服务器2通信。相关技术中,通过使能地址解析协议(ARP)广播变单播可以抑制广播ARP报文的数量,防止VXLAN网络二层广播报文泛滥。
图5是相关技术中的ARP代答的示意图,如图5所示,在二层网关设备比如图5中的L2GW1网关和L2GW2网关开启基于广播域(Broadcast domain,BD)的ARP二层代答功能之后,当收到ARP请求报文之后,会将ARP请求报文中的源IP地址、源MAC地址、报文的入接口等信息记录到本地的地址解析协议(ARP)抑制表项中,作为后续ARP二层代答的依据。当二层网关设备再收到ARP请求报文时,二层网关设备首先根据ARP请求报文中的目的IP查找本地的地址解析协议抑制表项(包括本地侦听的和从其他网关同步的)。如果目的MAC地址查找成功,则用查找到的目的MAC地址对ARP请求报文直接进行代答,如果查找失败,则按原有的流程处理该ARP请求报文。这样就可以显著减少VXLAN网络中的ARP广播报文。虚拟局域网扩展(VXLAN)隧道可以利用BGP Type2(MAC/IP)路由发布的信息来存取远程主机信息,从图5中的地址解析协
议抑制表项可以看出L2GW1网关学习到了远程主机3和主机4的MAC/IP地址,当二层网关设备的ARP代答功能启动,来自主机1去访问主机3或是主机4的ARP请求报文将会被L2GW1网关直接代答,虚拟局域网扩展隧道可以借着BGP控制平面实现ARP抑制以及代答功能。
图6是本申请一些实施例提供的BFD远程MAC地址发布的示意图,如图6所示,设备05即本申请实施例的第一隧道端点,设备06即本申请实施例的第二隧道端点。设备05与设备06之间建立有双向转发检测(BFD)会话,同个网段下来自虚拟局域网(Virtual Local Area Network,VLAN)100的封包可以通过设备05与设备06之间的VXLAN静态隧道,并携带虚拟局域网扩展识别标识(VNI)即VXLAN的网络识别标识(Identity document,ID)1000,到达对端去做访问并得到响应。图6中,主机1、主机2和主机3为本申请实施例中第一隧道端点对应的第三设备,主机4和主机5为本申请实施例中第二隧道端点对应的第一设备。设备05学习到了主机1、主机2和主机3的IP/MAC地址,并在设备05配置虚拟隧道端点源IP地址(Source VTEP IP,VTEP SIP)、虚拟局域网扩展识别标识(VLAN VNI)、双向转发检测(BFD)邻居信息,双向转发检测(BFD)邻居信息包括:双向转发检测邻居6.6.6.6和多跳本地地址5.5.5.5,以及设定双向转发检测远程MAC地址发布:主机1和主机2。设备05及设备06之间建立双向转发检测(BFD)会话后,可以通过发送双向转发检测(BFD)保持活动状态封包(BFD Hello封包)来确保双向转发检测(BFD)会话状态是保持,双向转发检测(BFD)保持活动状态封包中的后缀携带主机1和主机2的IP/MAC地址、虚拟局域网(VLAN)频道名称和虚拟局域网扩展识别标识(VNI)频道标识即图六中的100/1000,发送给BFD邻居即设备06。设备06接收到设备05发送的双向转发检测(BFD)保持活动状态封包后可以获取到设备05的远程MAC地址表项信息,即主机1和主机2的MAC地址,进一步地,设备06可以通过下发Linux(操作系统内核)指令给内核开启VXLAN代答功能,即对请求主机1和主机2的MAC地址的ARP请求报文进行代答,实现VXLAN静态隧道的ARP代答,避免了广播造成报文泛滥的问题,抑制VXLAN网络中的报文数量。
例如,主机4可以是本申请一些实施例中向第二隧道端点设备06发送第二地址请求报文即ARP请求报文的设备,主机4要访问第一隧道端点即设备05对应的主机1,主机4发出ARP请求报文,当设备06有开启VXLAN代答功能时,设备06可以通过查找表项获取主机1的MAC地址,并将主机1的MAC地址回复给主机4。同理,设备06可以在BFD保持活动状态封包中的后缀携带主机4的IP/MAC地址,设备05接收到设备06发送的BFD保持活动状态封包后可以获取到主机4的MAC地址,设备05可以对请求主机4的MAC地址的ARP请求报文进行代答。
图7是本申请一些实施例提供的服务设备架构示意图,如图7所示,设备05及设备06之间通过发送双向转发检测(BFD)保持活动状态封包(BFD Hello封包)保持双向转发检测(BFD)会话状态,主机4作为设备06远程MAC地址发布的设定,主机1和主机2作为设备05远程MAC地址发布的设定。图7中,应用程序(MAC地址表)用于学习本地MAC地址比如主机1和主机2的MAC地址。应用程序(地址解析协议)用于确定主机1和主机2的IP地址和MAC地址的对应关系,然后将主机1和主机2的IP/MAC地址写入应用程序共用的数据库即本申请实施例的第一数据库,以供其他应用程序(比如应用程序双向转发检测)获取。应用程序(双向转发检测)用于在设备05及设备06之间建立BFD会话,应用程序(双向转发检测)可以从第一数据库获取需要发布的主机1和主机2的IP/MAC地址、VXLAN隧道名称以及VLAN/VNI隧道标识等信息,并封包后得到BFD保持活动状态封包(BFD Hello封包),将BFD保持活动状态封包发送给
设备06。应用程序(双向转发检测)接收来自设备06发布的主机4的IP/MAC地址、VXLAN隧道名称以及VLAN/VNI隧道标识等信息,并存储在第一数据库中,以供应用程序(虚拟局域网扩展)获取。应用程序(虚拟局域网扩展)可以根据VXLAN隧道名称以及VLAN/VNI隧道标识对设备06进行隧道识别和VNI匹配。
例如,主机1可以为本申请实施例中向第一隧道端点设备05发送第一地址请求报文即ARP请求报文的设备,设备05通过命令行接口下发Linux指令给内核开启VXLAN代答功能后,当主机1要对第二隧道端点即设备06对应的主机4发送ARP请求报文时,设备05可以从第一数据库获取主机4的MAC地址,从而直接对主机1发送的ARP请求报文做代答。
图8是本申请一些实施例提供的服务控制流程示意图,如图8所示,首先配置静态路由以及虚拟局域网相关设定,然后创建虚拟局域网扩展静态隧道接口实例,具体的配置方法和创建方法可以参考相关技术中的相关描述,本申请实施例对此不做限制。创建虚拟局域网扩展静态隧道之后,可以对虚拟局域网扩展静态隧道源IP、虚拟隧道端点目的IP地址(Destination VTEP IP,VTEP DIP)、虚拟局域网扩展识别标识以及设备的双向转发检测邻居进行设定,如图6中设备05及设备06的相关设定,此处仅是举例说明,本申请一些实施例对此不做限制。设备开启双向转发检测远程MAC地址发布功能后,可以将本地主机的MAC地址发送给隧道对端的设备,并接收隧道对端的设备发布的远程主机的MAC地址,设备即可对请求远程主机的ARP请求报文进行代答,将远程主机的MAC地址回复给发送ARP请求报文的设备。
图9是本申请一些实施例提供的BFD保持活动状态封包携带远程MAC地址的示意图,如图9所示,双向转发检测(BFD)保持活动状态封包的报文格式包括:双向转发检测协议版本号、诊断字、双向转发检测本地状态、信息标志、检测超时倍数、报文长度,以及会话标识中的本地标识符、远端标识符,控制数据包间隔中的最小双向转发检测报文发送间隔、最小双向转发检测报文接收间隔,回声(Echo)数据包间隔中的最小回声(Echo)报文接收间隔,以及本申请实施例在双向转发检测(BFD)报文可选内容部分增加的BFD可选型态-长度-值(Type Length Value,TLV)。在双向转发检测报文可选TLV中包括TLV认证类型、TLV后缀信息长度、TLV信息内容,其中,TLV认证类型为远程MAC地址发布,TLV信息内容包括远程MAC地址、远程IP地址、虚拟局域网扩展识别标识(VLAN ID)和虚拟局域网扩展(VXLAN)隧道名称。
图10是本申请一些实施例提供的BFD远程MAC地址控制流程示意图,如图10所示,第一隧道端点接收到第一检测报文,或第二隧道端点接收到第二检测报文,第一检测报文和第二检测报文可以是双向转发检测(BFD)报文。第一隧道端点或第二隧道端点可以确定BFD报文是否为合法报文,报文的合法性判定可以参照相关技术,本申请一些实施例对此不做限制。验证合法性后确定第一隧道端点与第二隧道端点之间的会话状态是否为保持,若会话状态为保持,则进一步判定BFD报文是否携带TLV内容,在BFD报文携带TLV内容的情况下,分析并获取TLV内容中携带的远程MAC地址,将获得的MAC地址写入到第一隧道端点或第二隧道端点各自对应的数据库中,第一隧道端点或第二隧道端点可以向内核下达Linux指令,指示内核新增MAC地址,需要对请求该MAC地址的地址请求报文进行代答。第一隧道端点或第二隧道端点可以定时检查数据库,通过获取数据库中的所有MAC地址,检查每个MAC地址是否过期,从数据库中删除过期的远程MAC地址,第一隧道端点或第二隧道端点可以向内核下达Linux指令,指
示内核删除过期的MAC地址。在一些实施例中,Linux新增指令可以如以下所示:
bridge fdb add$REMOTE_MAC dev$VXLAN_TUNNEL$VLAN_ID master
bridge fdb add$REMOTE_MAC dev$VXLAN_TUNNEL dst$DIP self
在一些实施例中,Linux删除指令可以如以下所示:
bridge fdb del$REMOTE_MAC dev$VXLAN_TUNNEL$VLAN_ID master
bridge fdb del$REMOTE_MAC dev$VXLAN_TUNNEL dst$DIP self
此处仅是举例说明,本申请一些实施例对此不做限制。
参见图11,本申请一些实施例提供一种地址请求报文代答装置,应用于第一隧道端点,装置15包括:
第一接收模块1501,用于接收第二隧道端点发送的第一检测报文;
第一获取模块1502,用于获取第一检测报文携带的第一网络地址;第一检测报文是第二隧道端点根据存储的第一网络地址生成的,第一网络地址是所述第二隧道端点对应的第一设备的网络地址;
第一代答模块1503,用于在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
在一些实施例中,装置15还包括:
第二生成模块,用于根据第一隧道端点存储的第二网络地址,生成第二检测报文;第二网络地址是第一隧道端点对应的第三设备的网络地址;
第二发送模块,用于向第二隧道端点发送第二检测报文;第二检测报文用于供第二隧道端点获取第二检测报文携带的第二网络地址,并在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点发送第二地址请求报文的设备。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,装置15还包括:
第二获取模块,用于获取静态隧道的隧道名称和隧道标识;
第二生成模块具体用于:
根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文;
第二发送模块具体用于:
根据隧道名称和隧道标识从第一隧道端点对应的多个静态隧道中,确定第一目标隧道;
通过第一目标隧道向第二隧道端点发送第二检测报文。
在一些实施例中,装置15还包括:
第一会话模块,用于第二生成模块根据第一隧道端点存储的第二网络地址、隧道名称和隧道标识,生成第二检测报文之前,根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;
第二发送模块具体还用于:
在会话的状态为保持的情况下,通过第一目标隧道向第二隧道端点发送第二检测报文。
在一些实施例中,装置15还包括:
第一存储模块,用于第一获取模块1502获取第一检测报文携带的第一网络地址之后,将第一网络地址存储在第一数据库中;
第一代答模块1503具体用于:
从第一数据库存储的第一网络地址中,获取第一目标网络地址,并将第一目标网络地址发送给第二设备。
在一些实施例中,装置15还包括:
第一更新模块,用于在接收到第二隧道端点发送的第三检测报文的情况下,根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库;第三检测报文是第二隧道端点根据最新的第一网络地址生成的;
第一代答模块1503具体还用于:从更新后的第一数据库存储的第一网络地址中,获取第一目标网络地址。
在一些实施例中,装置15还包括:
第一计时模块,用于第一更新模块根据第三检测报文携带的最新的第一网络地址,对第一数据库中存储的第一网络地址进行更新,得到更新后的第一数据库之后,将预设的第一计时参数置零,并控制第一计时参数重新开始计时;第一计时参数用于表征第一数据库的未更新时长;
第一删除模块,用于在第一计时参数大于预设时长阈值的情况下,将第一数据库中存储的第一网络地址删除。
在一些实施例中,第一代答模块1503具体还用于:
根据第一地址请求报文,确定第一地址标识;
根据第一地址标识从第一数据库存储的第一网络地址中,获取第一地址标识对应的第一网络地址,并确定为第一目标网络地址。
参见图12,本申请一些实施例提供另一种地址请求报文代答装置,应用于第二隧道端点,装置16包括:
第一生成模块1601,用于根据第二隧道端点存储的第一网络地址,生成第一检测报文;第一网络地址是第二隧道端点对应的第一设备的网络地址;
第一发送模块1602,用于向第一隧道端点发送第一检测报文;第一检测报文用于供第一隧道端点获取第一网络地址,并在接收到第一地址请求报文的情况下,从第一网络地址中获取第一目标网络地址,并将第一目标网络地址发送给第二设备,以对第一地址请求报文进行代答;第一目标网络地址是第一地址请求报文所请求的第一网络地址,第二设备是向第一隧道端点发送第一地址请求报文的设备。
在一些实施例中,装置16还包括:
第二接收模块,用于接收第一隧道端点发送的第二检测报文;
第三获取模块,用于获取第二检测报文携带的第二网络地址;第二检测报文是第一隧道端点根据存储的第二网络地址生成的,第二网络地址是第一隧道端点对应的第二设备的网络地址;
第二代答模块,用于在接收到第二地址请求报文的情况下,从第二网络地址中获取第二目标网络地址,并将第二目标网络地址发送给第四设备,以对第二地址请求报文进行代答;第二目标网络地址是第二地址请求报文所请求的第二网络地址,第四设备是向第二隧道端点
发送第二地址请求报文的设备。
在一些实施例中,第一隧道端点与第二隧道端点之间建立有静态隧道,装置16还包括:
第四获取模块,用于获取静态隧道的隧道名称和隧道标识;
第一生成模块1601具体用于:
根据第二隧道端点存储的第一网络地址,隧道名称和隧道标识,生成第一检测报文;
第一发送模块1602具体用于:
根据隧道名称和隧道标识,从第二隧道端点对应的多个静态隧道中,确定第二目标隧道;
通过第二目标隧道向第一隧道端点发送第一检测报文。
在一些实施例中,装置16还包括:
第二会话模块,用于第一生成模块1601根据第二隧道端点存储的第一网络地址,隧道名称和隧道标识,生成第一检测报文之前,根据隧道名称和隧道标识,在第一隧道端点和第二隧道端点之间建立会话;
第一发送模块1602具体还用于:
在会话的状态为保持的情况下,通过第二目标隧道向第一隧道端点发送第一检测报文。
在一些实施例中,获取第二检测报文携带的第二网络地址之后,装置16还包括:
第二存储模块,用于将第二网络地址存储在第二数据库中;
第二代答模块具体用于:
从第二数据库存储的第二网络地址中,获取第二目标网络地址,并将第二目标网络地址发送给第四设备。
在一些实施例中,装置16还包括:
第二更新模块,用于在接收到第一隧道端点发送的第四检测报文的情况下,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库;第四检测报文是第一隧道端点根据最新的第二网络地址生成的;
第二代答模块具体还用于:
从更新后的第二数据库存储的第二网络地址中,获取第二目标网络地址。
在一些实施例中,根据第四检测报文携带的最新的第二网络地址,对第二数据库中存储的第二网络地址进行更新,得到更新后的第二数据库之后,装置16还包括:
第二计时模块,用于将预设的第二计时参数置零,并控制第二计时参数重新开始计时;第二计时参数用于表征第二数据库的未更新时长;
第二删除模块,用于在第二计时参数大于预设时长阈值的情况下,将第二数据库中存储的第二网络地址删除。
在一些实施例中,第二代答模块具体还用于:
根据第二地址请求报文,确定第二地址标识;
根据第二地址标识从第二数据库存储的第二网络地址中,获取第二地址标识对应的第二网络地址,并确定为第二目标网络地址。
地址请求报文代答装置与如前述实施例所述的地址请求报文代答方法相对于相关技术所具有的优势相同,此处不再赘述。
对于一些装置实施例而言,由于其与一些方法实施例基本相似,所以描述的比较简单,
相关之处参见方法实施例的部分说明即可。
本申请还提供了一种电子设备,参见图13,包括:处理器1701、存储器1702以及存储在存储器上并在处理器上运行的计算机程序17021,处理器执行程序时实现前述实施例的地址请求报文代答方法。
本申请还提供了一种非易失性可读存储介质,当非易失性可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行前述实施例的地址请求报文代答方法。
在此提供的算法和显示不与任何特定计算机、虚拟系统或者其他设备固有相关。根据上面的描述,构造这类系统所要求的结构是显而易见的。此外,本申请也不针对任何特定编程语言。应当明白,可以利用各种编程语言实现在此描述的本申请的内容,并且上面对特定语言所做的描述是为了披露本申请的最佳实施方式。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本申请的实施例可以在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本申请并帮助理解各个发明方面中的一个或多个,在上面对本申请的示例性实施例的描述中,本申请的各个特征有时被一起分组到单个实施例、图,或者对其的描述中。然而,并不应将该公开的方法解释成反映如下意图:即所要求保护的本申请要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本申请的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的的替代特征来代替。
本申请的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本申请的排序设备中的一些或者全部部件的一些或者全部功能。本申请还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序。这样的实现本申请的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
应该注意的是上述实施例对本申请进行说明而不是对本申请进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本申请可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举
了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
以上所述仅为本申请的较佳实施例而已,并不用以限制本申请,凡在本申请的精神和原则之内所做的任何修改、等同替换和改进等,均应包含在本申请的保护范围之内。
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以权利要求的保护范围为准。
需要说明的是,本申请实施例中获取各种数据相关过程,都是在遵照所在地国家相应的数据保护法规政策的前提下,并获得由相应装置所有者给予授权的情况下进行的。
Claims (21)
- 一种地址请求报文代答方法,其特征在于,应用于第一隧道端点,所述方法包括:接收第二隧道端点发送的第一检测报文;获取所述第一检测报文携带的第一网络地址;所述第一检测报文是所述第二隧道端点根据存储的所述第一网络地址生成的,所述第一网络地址是所述第二隧道端点对应的第一设备的网络地址;在接收到第一地址请求报文的情况下,从所述第一网络地址中获取第一目标网络地址,并将所述第一目标网络地址发送给第二设备,以对所述第一地址请求报文进行代答;所述第一目标网络地址是所述第一地址请求报文所请求的第一网络地址,所述第二设备是向所述第一隧道端点发送所述第一地址请求报文的设备。
- 根据权利要求1所述的方法,其特征在于,所述第一隧道端点和所述第二隧道端点之间建立有静态隧道,所述方法还包括:获取所述静态隧道的隧道名称和隧道标识;所述根据所述第二隧道端点存储的第一网络地址,生成第一检测报文,包括:根据所述第二隧道端点存储的所述第一网络地址,所述隧道名称和所述隧道标识,生成所述第一检测报文。
- 根据权利要求1所述的方法,其特征在于,所述方法还包括:根据所述第一隧道端点存储的第二网络地址,生成第二检测报文;所述第二网络地址是所述第一隧道端点对应的第三设备的网络地址;向所述第二隧道端点发送所述第二检测报文;所述第二检测报文用于供所述第二隧道端点获取所述第二检测报文携带的所述第二网络地址,并在接收到第二地址请求报文的情况下,从所述第二网络地址中获取第二目标网络地址,并将所述第二目标网络地址发送给第四设备,以对所述第二地址请求报文进行代答;所述第二目标网络地址是所述第二地址请求报文所请求的第二网络地址,所述第四设备是向所述第二隧道端点发送所述第二地址请求报文的设备。
- 根据权利要求3所述的方法,其特征在于,所述第一隧道端点与所述第二隧道端点之间建立有静态隧道,所述方法还包括:获取所述静态隧道的隧道名称和隧道标识;所述根据所述第一隧道端点存储的第二网络地址,生成第二检测报文,包括:根据所述第一隧道端点存储的所述第二网络地址、所述隧道名称和所述隧道标识,生成所述第二检测报文;所述向所述第二隧道端点发送所述第二检测报文,包括:根据所述隧道名称和所述隧道标识从所述第一隧道端点对应的多个静态隧道中,确定第一目标隧道;通过所述第一目标隧道向所述第二隧道端点发送所述第二检测报文。
- 根据权利要求4所述的方法,其特征在于,所述根据所述第一隧道端点存储的所述第二网络地址、所述隧道名称和所述隧道标识,生成所述第二检测报文之前,所述方法还包括:根据所述隧道名称和所述隧道标识,在所述第一隧道端点和所述第二隧道端点之间建立会话;所述通过所述第一目标隧道向所述第二隧道端点发送所述第二检测报文,包括:在所述会话的状态为保持的情况下,通过所述第一目标隧道向所述第二隧道端点发送所述第二检测报文。
- 根据权利要求1-5任一所述的方法,其特征在于,所述获取所述第一检测报文携带的第一网络地址之后,所述方法还包括:将所述第一网络地址存储在第一数据库中;所述从所述第一网络地址中获取第一目标网络地址,并将所述第一目标网络地址发送给第二设备,包括:从所述第一数据库存储的第一网络地址中,获取所述第一目标网络地址,并将所述第一目标网络地址发送给所述第二设备。
- 根据权利要求4所述的方法,其特征在于,所述方法还包括:在接收到所述第二隧道端点发送的第三检测报文的情况下,根据所述第三检测报文携带的最新的第一网络地址,对所述第一数据库中存储的所述第一网络地址进行更新,得到更新后的第一数据库;所述第三检测报文是所述第二隧道端点根据所述最新的第一网络地址生成的;所述从所述第一数据库存储的所述第一网络地址中,获取所述第一目标网络地址,包括:从所述更新后的第一数据库存储的第一网络地址中,获取所述第一目标网络地址。
- 根据权利要求5所述的方法,其特征在于,所述根据所述第三检测报文携带的最新的第一网络地址,对所述第一数据库中存储的所述第一网络地址进行更新,得到更新后的第一数据库之后,所述方法还包括:将预设的第一计时参数置零,并控制所述第一计时参数重新开始计时;所述第一计时参数用于表征所述第一数据库的未更新时长;在所述第一计时参数大于预设时长阈值的情况下,将所述第一数据库中存储的所述第一网络地址删除。
- 根据权利要求6所述的方法,其特征在于,所述从所述第一数据库存储的第一网络地址中,获取所述第一目标网络地址,包括:根据所述第一地址请求报文,确定第一地址标识;根据所述第一地址标识从所述第一数据库存储的第一网络地址中,获取所述第一地址标识对应的第一网络地址,并确定为所述第一目标网络地址。
- 一种地址请求报文代答方法,其特征在于,应用于第二隧道端点,所述方法包括:根据所述第二隧道端点存储的第一网络地址,生成第一检测报文;所述第一网络地址是所述第二隧道端点对应的第一设备的网络地址;向第一隧道端点发送所述第一检测报文;所述第一检测报文用于供所述第一隧道端点获取所述第一网络地址,并在接收到第一地址请求报文的情况下,从所述第一网络地址中获取第一目标网络地址,并将所述第一目标网络地址发送给第二设备,以对 所述第一地址请求报文进行代答;所述第一目标网络地址是所述第一地址请求报文所请求的第一网络地址,所述第二设备是向所述第一隧道端点发送所述第一地址请求报文的设备。
- 根据权利要求10所述的方法,其特征在于,所述方法还包括:接收所述第一隧道端点发送的第二检测报文;获取所述第二检测报文携带的第二网络地址;所述第二检测报文是所述第一隧道端点根据存储的所述第二网络地址生成的,所述第二网络地址是所述第一隧道端点对应的第二设备的网络地址;在接收到第二地址请求报文的情况下,从所述第二网络地址中获取第二目标网络地址,并将所述第二目标网络地址发送给第四设备,以对所述第二地址请求报文进行代答;所述第二目标网络地址是所述第二地址请求报文所请求的第二网络地址,所述第四设备是向所述第二隧道端点发送所述第二地址请求报文的设备。
- 根据权利要求10所述的方法,其特征在于,所述第一隧道端点与第二隧道端点之间建立有静态隧道,所述方法还包括:获取所述静态隧道的隧道名称和隧道标识;所述根据所述第二隧道端点存储的第一网络地址,生成第一检测报文,包括:根据所述第二隧道端点存储的所述第一网络地址,所述隧道名称和所述隧道标识,生成所述第一检测报文;所述向第一隧道端点发送所述第一检测报文,包括:根据所述隧道名称和所述隧道标识,从所述第二隧道端点对应的多个静态隧道中,确定第二目标隧道;通过所述第二目标隧道向所述第一隧道端点发送所述第一检测报文。
- 根据权利要求12所述的方法,其特征在于,所述根据所述第二隧道端点存储的所述第一网络地址,所述隧道名称和所述隧道标识,生成所述第一检测报文之前,所述方法还包括:根据所述隧道名称和所述隧道标识,在所述第一隧道端点和所述第二隧道端点之间建立会话;所述通过所述第二目标隧道向所述第一隧道端点发送所述第一检测报文,包括:在所述会话的状态为保持的情况下,通过所述第二目标隧道向所述第一隧道端点发送所述第一检测报文。
- 根据权利要求11所述的方法,其特征在于,所述获取所述第二检测报文携带的第二网络地址之后,所述方法还包括:将所述第二网络地址存储在第二数据库中;所述从所述第二网络地址中获取第二目标网络地址,并将所述第二目标网络地址发送给所述第一设备,包括:从所述第二数据库存储的第二网络地址中,获取所述第二目标网络地址,并将所述第二目标网络地址发送给所述第四设备。
- 根据权利要求14所述的方法,其特征在于,所述方法还包括:在接收到所述第一隧道端点发送的第四检测报文的情况下,根据所述第四检测报文携带的最新的第二网络地址,对所述第二数据库中存储的所述第二网络地址进行更 新,得到更新后的第二数据库;所述第四检测报文是所述第一隧道端点根据所述最新的第二网络地址生成的;所述从所述第二数据库存储的第二网络地址中,获取所述第二目标网络地址,包括:从所述更新后的第二数据库存储的第二网络地址中,获取所述第二目标网络地址。
- 根据权利要求15所述的方法,其特征在于,所述根据所述第四检测报文携带的最新的第二网络地址,对所述第二数据库中存储的所述第二网络地址进行更新,得到更新后的第二数据库之后,所述方法还包括:将预设的第二计时参数置零,并控制所述第二计时参数重新开始计时;所述第二计时参数用于表征所述第二数据库的未更新时长;在所述第二计时参数大于预设时长阈值的情况下,将所述第二数据库中存储的所述第二网络地址删除。
- 根据权利要求14所述的方法,其特征在于,所述从所述第二数据库存储的第二网络地址中,获取所述第二目标网络地址,包括:根据所述第二地址请求报文,确定第二地址标识;根据所述第二地址标识从所述第二数据库存储的第二网络地址中,获取所述第二地址标识对应的第二网络地址,并确定为所述第二目标网络地址。
- 一种地址请求报文代答装置,其特征在于,应用于第一隧道端点,所述装置包括:第一接收模块,用于接收第二隧道端点发送的第一检测报文;第一获取模块,用于获取所述第一检测报文携带的第一网络地址;所述第一检测报文是所述第二隧道端点根据存储的所述第一网络地址生成的,所述第一网络地址是所述第二隧道端点对应的第一设备的网络地址;第一代答模块,用于在接收到第一地址请求报文的情况下,从所述第一网络地址中获取第一目标网络地址,并将所述第一目标网络地址发送给第二设备,以对所述第一地址请求报文进行代答;所述第一目标网络地址是所述第一地址请求报文所请求的第一网络地址,所述第二设备是向所述第一隧道端点发送所述第一地址请求报文的设备。
- 一种地址请求报文代答装置,其特征在于,应用于第二隧道端点,所述装置包括:第一生成模块,用于根据所述第二隧道端点存储的第一网络地址,生成第一检测报文;所述第一网络地址是所述第二隧道端点对应的第一设备的网络地址;第一发送模块,用于向第一隧道端点发送所述第一检测报文;所述第一检测报文用于供所述第一隧道端点获取所述第一网络地址,并在接收到第一地址请求报文的情况下,从所述第一网络地址中获取第一目标网络地址,并将所述第一目标网络地址发送给第二设备,以对所述第一地址请求报文进行代答;所述第一目标网络地址是所述第一地址请求报文所请求的第一网络地址,所述第二设备是向所述第一隧道端点发送所述第一地址请求报文的设备。
- 一种电子设备,其特征在于,包括:处理器、存储器以及存储在所述存储器上并在所述处理器上运行的计算机程序,其特征在于,所述处理器执行所述程序时实现如权利要求1-17中任一所述的地址请求报文代答方法。
- 一种非易失性可读存储介质,其特征在于,当所述非易失性可读存储介质中的指令由电子设备的处理器执行时,使得电子设备能够执行权利要求1-17中任一所述的地址请求报文代答方法。
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US19/159,276 US20260113214A1 (en) | 2023-04-27 | 2023-12-26 | Method and apparatus for performing proxy reply to address request packet, electronic device, and storage medium |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202310467846.5A CN116192797B (zh) | 2023-04-27 | 2023-04-27 | 地址请求报文代答方法、装置、电子设备及存储介质 |
| CN202310467846.5 | 2023-04-27 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024222010A1 true WO2024222010A1 (zh) | 2024-10-31 |
Family
ID=86449320
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2023/142081 Ceased WO2024222010A1 (zh) | 2023-04-27 | 2023-12-26 | 地址请求报文代答方法、装置、电子设备及存储介质 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20260113214A1 (zh) |
| CN (1) | CN116192797B (zh) |
| WO (1) | WO2024222010A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116192797B (zh) * | 2023-04-27 | 2023-07-14 | 苏州浪潮智能科技有限公司 | 地址请求报文代答方法、装置、电子设备及存储介质 |
Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101577722A (zh) * | 2009-06-03 | 2009-11-11 | 中兴通讯股份有限公司 | 实现强制mac转发功能的方法和装置 |
| CN103404084A (zh) * | 2012-11-21 | 2013-11-20 | 华为技术有限公司 | Mac地址强制转发装置及方法 |
| CN104283980A (zh) * | 2014-10-09 | 2015-01-14 | 杭州华三通信技术有限公司 | 一种地址解析协议代答方法和装置 |
| US20170289033A1 (en) * | 2015-04-03 | 2017-10-05 | Hewlett Packard Enterprise Development Lp | Address cache for tunnel endpoint associated with an overlay network |
| CN108270878A (zh) * | 2016-12-31 | 2018-07-10 | 中国移动通信集团江西有限公司 | 在vxlan中发送arp报文的方法、vtep设备 |
| CN112866119A (zh) * | 2020-12-30 | 2021-05-28 | 迈普通信技术股份有限公司 | 虚拟可扩展局域网通信方法、装置、电子设备及存储介质 |
| CN113726632A (zh) * | 2021-07-31 | 2021-11-30 | 新华三信息安全技术有限公司 | 一种报文转发方法及设备 |
| CN116192797A (zh) * | 2023-04-27 | 2023-05-30 | 苏州浪潮智能科技有限公司 | 地址请求报文代答方法、装置、电子设备及存储介质 |
-
2023
- 2023-04-27 CN CN202310467846.5A patent/CN116192797B/zh active Active
- 2023-12-26 WO PCT/CN2023/142081 patent/WO2024222010A1/zh not_active Ceased
- 2023-12-26 US US19/159,276 patent/US20260113214A1/en active Pending
Patent Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101577722A (zh) * | 2009-06-03 | 2009-11-11 | 中兴通讯股份有限公司 | 实现强制mac转发功能的方法和装置 |
| CN103404084A (zh) * | 2012-11-21 | 2013-11-20 | 华为技术有限公司 | Mac地址强制转发装置及方法 |
| CN104283980A (zh) * | 2014-10-09 | 2015-01-14 | 杭州华三通信技术有限公司 | 一种地址解析协议代答方法和装置 |
| US20170289033A1 (en) * | 2015-04-03 | 2017-10-05 | Hewlett Packard Enterprise Development Lp | Address cache for tunnel endpoint associated with an overlay network |
| CN108270878A (zh) * | 2016-12-31 | 2018-07-10 | 中国移动通信集团江西有限公司 | 在vxlan中发送arp报文的方法、vtep设备 |
| CN112866119A (zh) * | 2020-12-30 | 2021-05-28 | 迈普通信技术股份有限公司 | 虚拟可扩展局域网通信方法、装置、电子设备及存储介质 |
| CN113726632A (zh) * | 2021-07-31 | 2021-11-30 | 新华三信息安全技术有限公司 | 一种报文转发方法及设备 |
| CN116192797A (zh) * | 2023-04-27 | 2023-05-30 | 苏州浪潮智能科技有限公司 | 地址请求报文代答方法、装置、电子设备及存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN116192797B (zh) | 2023-07-14 |
| US20260113214A1 (en) | 2026-04-23 |
| CN116192797A (zh) | 2023-05-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN112422481B (zh) | 网络威胁的诱捕方法、系统和转发设备 | |
| JP2020162146A (ja) | 仮想ネットワークにおける分散型フロー状態p2p設定のためのシステムおよび方法 | |
| US10616175B2 (en) | Forwarding information to forward data to proxy devices | |
| US11451466B2 (en) | Controlling route | |
| US20240323115A1 (en) | Loop Avoidance Communications Method, Device, and System | |
| CN107094110B (zh) | 一种dhcp报文转发方法及装置 | |
| CN105706420A (zh) | 用于实现提供商网络中的服务链的系统和方法 | |
| WO2017124886A1 (zh) | 按需获取路由的方法及网关 | |
| CN105591907B (zh) | 一种路由获取方法和装置 | |
| US11936614B2 (en) | Method and apparatus for sending reply packet, computing device, and storage medium | |
| WO2012088934A1 (zh) | 一种报文过滤方法和交换设备 | |
| WO2024222010A1 (zh) | 地址请求报文代答方法、装置、电子设备及存储介质 | |
| WO2017219777A1 (zh) | 一种报文处理方法及装置 | |
| CN109831378B (zh) | 一种报文超时回应方法及装置 | |
| WO2024108493A1 (zh) | 基于sdn与ndn的虚实结合动态流量调度方法及装置 | |
| CN113542099B (zh) | 数据的传输方法、装置、电子设备、介质和产品 | |
| CN119892407A (zh) | 一种请求报文发送方法、装置、设备、介质和产品 | |
| CN118233379A (zh) | 数据传输方法、装置、设备、存储介质及程序产品 | |
| JP5350333B2 (ja) | パケット中継装置及びネットワークシステム | |
| CN113300931B (zh) | 一种虚拟机迁移发现方法及vtep | |
| JP2020145568A (ja) | 中継装置及びプログラム | |
| WO2015039563A1 (zh) | 实现三层虚拟专用网的方法和设备 | |
| JP6014068B2 (ja) | 中継装置及び中継方法、並びにコンピュータ・プログラム | |
| WO2022174754A1 (zh) | 信息处理方法、装置、相关设备和存储介质 | |
| CN115334035A (zh) | 一种报文转发方法、装置、电子设备及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23935176 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |