Method and apparatus for processing routing, and method and apparatus for data transmission
By configuring the same SRv6 VPN SID in the PE device and establishing multiple paths, the problem of excessive resource occupation and long path switching time is solved, and fast path switching and multi-residence protection is achieved.
Patent Information
- Application Number
- CN202010688621.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2017-12-01
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2037-12-01
AI Technical Summary
In a virtual private network, PE devices need to deploy a large number of BFDs to detect path failures, resulting in excessive resource usage and long path switching time.
Configure the same SRv6 VPN SID in the PE device and establish multiple paths through the same SRv6 VPN SID to achieve fast path switching and reduce the deployment of BFD.
The number of BFDs in PE equipment is reduced, resource occupation is reduced, path switching speed is improved, and multi-residence protection is achieved.
Smart Images

Figure CN111901235B_ABST
Abstract
Description
[0001] This application is a divisional application of the application with the application number 201711258440.7, the application date of December 1, 2017, and the invention title of "Method and Device for Processing Routing, and Method and Device for Data Transmission". Technical Field
[0002] The present invention relates to the field of communication technologies, and in particular, to a method and device for processing routing, and a method and device for data transmission. Background Art
[0003] Currently, in a Virtual Private Network (VPN), it is a common networking form that a Customer Edge (CE) device connects to a Provider Edge (PE) device through a multi-homed connection. In this scenario, the CE device is connected to multiple PEs at the same time, and there are multiple paths for other CE devices to reach this CE device. During the data transmission process, when the source CE device sends a packet to the destination CE device, the source CE device sends the packet to the destination CE device to the PE device connected to it. The PE device connected to the source CE device can determine a path for transmitting the packet from multiple paths to the destination CE device and transmit the packet through this path.
[0004] During the data transmission process, in order to avoid the situation that the packet cannot be transmitted to the destination CE device due to the failure of the PE device connected to the destination CE device in the packet transmission path, Bidirectional Forwarding Detection (BFD) is usually configured between the PE device connected to the source CE device and the PE device connected to the destination CE device. When the PE device connected to the source CE device determines the path to the destination CE device, it can detect whether the PE device connected to the destination CE device in the path is faulty according to the BFD between it and the PE connected to the destination CE in the path. If it is detected that the PE device connected to the destination CE device in the path is faulty, the PE device connected to the source CE device will switch the packet to other paths to the destination CE device for transmission, so as to ensure that the packet can be transmitted to the destination CE device.
[0005] However, each PE device in the VPN will access multiple CE devices, and each PE device will establish paths with multiple other PE devices in the network. In order to ensure that each path can quickly detect faults, BFD needs to be deployed for each pair of PE devices that establish paths with each other. Therefore, the number of BFDs deployed for each PE device can reach the number of paths established between it and other PE devices, resulting in a large number of BFDs needing to be deployed for each PE device, occupying too much of its resources. Summary of the Invention
[0006] The present application provides a method and apparatus for processing routes, and a method and apparatus for data transmission, which can effectively reduce the number of Bidirectional Forwarding Detection (BFD) configured on each Provider Edge (PE).
[0007] In a first aspect, the present application provides a method for processing routes. The method is used in a network that bears an Internet Protocol Version 6 Segment Routing-based Virtual Private Network (SRv6-based VPN) service. The network includes a first Customer Edge (CE) device, a second CE device, an ingress Provider Edge (PE) device, N egress PE devices, and at least one Provider (P) device. The first CE device is connected to the ingress PE device. The second CE device is multi-homed and connected to the N egress PE devices. The ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first Internet Protocol Version 6 Segment Routing (SRv6) VPN Segment Identifier (SID). The first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID and a third SRv6 VPN SID. Both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. Here, N is an integer greater than or equal to 2. The method includes: the first PE device receives a first VPN route sent by the second PE device, and the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID; the first PE device determines that the second SRv6 VPN SID is the same as the first SRv6 VPN SID; the first PE device establishes a second path from the first PE device to the second PE device according to the third SRv6 VPN SID in the first VPN route. When a failure occurs in a first path directly connecting the first PE device and the second CE device, the second path is used by the first PE device to forward packets to the second CE device.
[0008] In this application, since the second SRv6 VPN SID is the same as the first SRv6 VPN SID, the paths to the first SRv6 VPN SID include two paths to the first PE device and the second PE device respectively. Therefore, when transmitting the packet sent by the first CE device to the second CE device, if the fifth path to the first PE fails, the sixth path to the second PE device can be determined, and then the packet can be switched to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path. Instead, when a fault of the egress PE device is detected during the packet transmission process, the packet is transmitted through the path to the PE device with the same SRv6 VPN SID as the egress PE device, so as to achieve fast path switching. Therefore, there is no need to deploy BFD between the PE devices that establish the path to detect faults, that is, there is no need to deploy BFD between the ingress PE device and the egress PE device to detect faults, thus reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for fault detection when the PE device determines the path, improving the speed of path switching. And in this application, the second PE device is configured with a third SRv6 VPN SID that is different from the first SRv6 VPN SID, which enables the first PE device to establish a second path through the third SRv6 VPN SID in the first VPN route, so that the packet transmitted by the first PE device to the second CE device can be switched to the second path for transmission when the path directly connecting the first PE device and the second CE device fails, thus achieving fast path switching and enabling the packet to be transmitted to the second CE device, thereby realizing multi-homing protection.
[0009] In combination with the first aspect, in the first implementation manner of the first aspect, the method further includes: the first PE device sends a second VPN route to the second PE device, and the second VPN route carries the first SRv6 VPN SID and the fourth SRv6 VPN SID, where the fourth SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the first PE device connecting to the second CE device, the fourth SRv6 VPN SID is used by the second PE device to establish a third path from the second PE device to the first PE device, and when the fourth path directly connecting the second PE device and the second CE device fails, the third path is used by the second PE device to transmit packets to the second CE device, the fourth SRv6 VPN SID is different from the first SRv6 VPN SID, and the first SRv6 VPN SID is the same as the second SRv6 VPN SID stored by the second PE device.
[0010] In this implementation manner, the first PE device configures the fourth SRv6 VPN SID, which enables the second PE device to establish a second path through the fourth SRv6 VPN SID, so that the packets transmitted by the second PE device to the second CE device can be switched to the third path for transmission when the path directly connecting the second PE device and the second CE device fails, thereby achieving fast path switching and enabling the packets to be transmitted to the second CE device, thus realizing multi-homing protection.
[0011] In combination with the first aspect or any implementation manner of the first aspect, in the second implementation manner of the first aspect, the first VPN route is carried in the Border Gateway Protocol-Prefix-SID (BGP-Prefix-SID) attribute field of a Multi-Protocol Border Gateway Protocol (MP-BGP) message. This BGP-Prefix-SID attribute field includes a Segment Routing IPv6-VPN SID type-length-value (TLV) field. This SRv6-VPN SID TLV field includes a type (T) field, a length (L) field, and a value (V) field, and the V field is used to carry the third SRv6 VPN SID.
[0012] In combination with the first aspect or any implementation manner of the first aspect, in the second implementation manner of the first aspect, the method further includes: the first PE device receives a first packet, the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID; the first PE device determines the first path failure; the first PE device determines to forward the first packet through the second path according to the first SRv6 VPN SID and the third SRv6 VPN SID.
[0013] In this implementation manner, when the first PE device transmits a packet to the second CE device, when a path failure occurs in the path directly connecting the first PE device and the second CE device, the packet can be switched to the second path for transmission, so as to achieve fast path switching, enable the packet to be transmitted to the second CE device, and thus achieve multi-homing protection.
[0014] Second aspect, the present application provides a data transmission method, which is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first SRv6 VPN SID, and the first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID and a third SRv6 VPN SID, and both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID, where N is an integer greater than or equal to 2. The method includes: The first PE device receives a first packet, the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID; The first PE device determines a first path for forwarding the first packet according to the first SRv6 VPN SID, where the first path is the path directly connecting the first PE device and the second CE device; The first PE device determines that the first path fails, and the first PE device determines to forward the first packet through a second path according to the first SRv6 VPN SID and the third SRv6 VPN SID sent by the second PE device and saved, where the first PE device connects to the second PE device through the second path; The first PE device forwards the first packet to the second CE through the second path.
[0015] In this application, the second SRv6 VPN SID is the same as the first SRv6 VPN SID. Therefore, the paths to the first SRv6 VPN SID include two paths that respectively reach the first PE device and the second PE device. Therefore, when transmitting the packet sent by the first CE device to the second CE device, if the fifth path to the first PE fails, the sixth path to the second PE device can be determined, and then the packet can be switched to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path. Instead, when a fault of the egress PE device is detected during the packet transmission process, the packet is transmitted through the path to the PE device with the same SRv6 VPN SID as the egress PE device, so as to achieve fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for fault detection when the PE device determines the path, and improving the speed of path switching. And in this application, when the first PE device transmits the first packet to the second CE device, when the path directly connecting the first PE device and the second CE device fails, the first PE device determines the second path according to the first SRv6 VPN SID and the third SRv6 VPN SID sent by the second PE device that is saved, and switches the first packet to the second path for transmission, so as to achieve fast path switching, so that the packet can be transmitted to the second CE device, thereby realizing multi-homing protection.
[0016] Combined with the second aspect, in the first implementation manner of the second aspect, before the first PE receives the first packet, the method further includes: the first PE device receives a first VPN route sent by the second PE device, and the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID; the first PE device determines that the second SRv6 VPN SID is the same as the first SRv6 VPN SID; the first PE device establishes the second path according to the third SRv6 VPN SID.
[0017] In a third aspect, the present application provides a method for processing routes, which is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed and connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The at least one P device includes a first P device, which is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device. Here, N is an integer greater than or equal to 2. The method includes: the first P device receives a first route sent by the first PE device, and the first route includes the network segment to which the first SRv6 VPN SID belongs; the first P device receives a second route sent by the second PE device, and the second route includes the network segment to which the second SRv6 VPN SID belongs; the first P device establishes a fifth path from the first P device to the first PE device according to the network segment to which the first SRv6 VPN SID belongs, and the fifth path is used by the first P device to forward packets to the second CE device; the first P device establishes a sixth path from the first P device to the second PE device according to the network segment to which the second SRv6 VPN SID belongs, and this sixth path is used by the first P device to forward packets to the second CE device when the fifth path fails.
[0018] In this application, since the second SRv6 VPN SID is the same as the first SRv6 VPN SID, the path for the first P device to reach the first SRv6 VPN SID includes two paths to the first PE device and the second PE device respectively. Therefore, when the first P device transmits the packet sent by the first CE device to the second CE device, if the fifth path to the first PE fails, the first P device can determine the sixth path to the second PE device, and then can switch the packet to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path, but when it detects that the egress PE device is faulty during the packet transmission process, it transmits the packet through the path to the PE device with the same SRv6 VPN SID as the egress PE device, thus realizing fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE devices, reducing the resources occupied by BFD in the PE devices, and reducing the time for fault detection when the PE devices determine the path, and improving the speed of path switching.
[0019] Combined with the third aspect, in the first implementation manner of the third aspect, the method further includes: the first P device receives a first packet, the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID; the first P device determines that the fifth path fails; the first P device determines to forward the first packet through the sixth path according to the first SRv6 VPN SID.
[0020] Fourthly, the present application provides a data transmission method, which is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homedly connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first SRv6 VPN SID, and the first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID, and the second SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The at least one P device includes a first P device, and the first P device is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device. Herein, N is an integer greater than or equal to 2. The method includes: The first P device receives a first packet, and the first packet is a packet sent by the first CE device to the second CE device. The outer destination address encapsulated in the first packet is the first SRv6 VPN SID; The first P device determines a fifth path for transmitting the first packet according to the first SRv6 VPN SID, and the first P device connects to the first PE device through the fifth path; The first P device determines that the fifth path fails, and the first P device determines to forward the first packet through a sixth path according to the first SRv6 VPN SID. The first P device connects to the second PE through the sixth path; The first P device forwards the first packet to the second CE device through the sixth path.
[0021] In this application, since the second SRv6 VPN SID is the same as the first SRv6 VPN SID, the path for the first P device to reach the first SRv6 VPN SID includes two paths that reach the first PE device and the second PE device respectively. Therefore, when the first P device transmits the packet sent by the first CE device to the second CE device, if the fifth path to the first PE fails, the first P device can determine the sixth path to the second PE device, and then can switch the packet to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, when the ingress PE device determines the packet transmission path, it does not need to detect whether the egress PE device in the path is faulty. Instead, when it detects that the egress PE device is faulty during the packet transmission process, it transmits the packet through the path to the PE device with the same SRv6 VPN SID as the egress PE device, thereby achieving fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thus reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for the PE device to detect faults when determining the path, and improving the speed of path switching.
[0022] Combined with the fourth aspect, in the first implementation manner of the fourth aspect, before the first P device receives the first packet, the method further includes: the first P device receives a first route sent by the first PE device, the first route includes the network segment to which the first SRv6 VPN SID belongs; the first P device receives a second route sent by the second PE device, the second route includes the network segment to which the second SRv6 VPN SID belongs; the first P device establishes the fifth path according to the network segment to which the first SRv6 VPN SID belongs; the first P device establishes the sixth path according to the network segment to which the second SRv6 VPN SID belongs, and this sixth path is used for the first P device to forward packets to the second CE device when the fifth path fails.
[0023] Fifth aspect, the present application provides a PE device, which is used as a first PE device in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. The N egress PE devices include the first PE device and the second PE device. The first PE device configures a first SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE connects to the second CE device. The second PE device configures a second SRv6 VPN SID and a third SRv6 VPN SID, both of which are used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. Wherein, N is an integer greater than or equal to 2. The first PE device includes:
[0024] A receiving unit, configured to receive a first VPN route sent by the second PE device, where the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID;
[0025] A processing unit, configured to determine that the second SRv6 VPN SID is the same as the first SRv6 VPN SID;
[0026] The processing unit is further configured to establish a second path from the first PE device to the second PE device according to the third SRv6 VPN SID in the first VPN route. When a failure occurs in a first path directly connecting the first PE device and the second CE device, the first PE device uses the second path to forward packets to the second CE device.
[0027] Combined with the fifth aspect, in the first implementation manner of the fifth aspect, it further includes:
[0028] A sending unit, configured to send a second VPN route to the second PE device, where the second VPN route carries the first SRv6 VPN SID and a fourth SRv6 VPN SID. The fourth SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface through which the first PE device connects to the second CE device. The second PE device uses the fourth SRv6 VPN SID to establish a third path from the second PE device to the first PE device. When a fourth path directly connecting the second PE device and the second CE device fails, the second PE device uses the third path to transmit packets to the second CE device. The fourth SRv6 VPN SID is different from the first SRv6 VPN SID, and the first SRv6 VPN SID is the same as the second SRv6 VPN SID saved by the second PE device.
[0029] Combined with the fifth aspect or any one of the implementation manners of the fifth aspect, in the second implementation manner of the fifth aspect, the first VPN route is carried in the BGP-Prefix-SID attribute field of an MP-BGP message. The BGP-Prefix-SID attribute field includes an SRv6-VPN SID TLV field, and the SRv6-VPN SID TLV field includes a T field, an L field, and a V field. The V field is used to carry the third SRv6 VPN SID.
[0030] Combined with the fifth aspect or any one of the implementation manners of the fifth aspect, in the third implementation manner of the fifth aspect, the receiving unit is further configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and an outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0031] The processing unit is further configured to determine the failure of the first path;
[0032] The processing unit is further configured to determine to forward the first packet through the second path according to the first SRv6 VPN SID and the third SRv6 VPN SID.
[0033] Sixth aspect, the present application provides a PE device. As the first PE device, it is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are the first PE device and the second PE device. The first PE device configures a first SRv6 VPN SID, and the first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface of the first PE device connecting to the second CE device. The second PE device configures a second SRv6 VPN SID and a third SRv6 VPN SID, and both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the egress interface of the second PE device connecting to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. Wherein, N is an integer greater than or equal to 2, and the first PE device includes:
[0034] A receiving unit, configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0035] A processing unit, configured to determine a first path for forwarding the first packet according to the first SRv6 VPN SID, where the first path is a path directly connecting the first PE device and the second CE device;
[0036] The processing unit is further configured to determine that the first path fails. The first PE device determines to forward the first packet through a second path according to the first SRv6 VPN SID and the saved third SRv6 VPN SID sent by the second PE device, where the first PE device connects to the second PE device through the second path;
[0037] A sending unit, configured to forward the first packet to the second CE through the second path.
[0038] In combination with the sixth aspect, in the first implementation manner of the sixth aspect, the receiving unit is further configured to receive a first VPN route sent by the second PE device, where the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID;
[0039] The processing unit is further configured to, when determining that the second SRv6 VPN SID is the same as the first SRv6 VPN SID, establish the second path according to the third SRv6 VPN SID.
[0040] In a seventh aspect, the present application provides a P device. As a first P device, the P device is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed to connect the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device, the first CE device and the second CE device belong to the same VPN, the N egress PE devices include a first PE device and a second PE device, the first PE device is configured with a first SRv6 VPN SID, and the first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device is configured with the second SRv6 VPN SID, and the second SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The at least one P device includes the first P device, and the first P device is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device. Wherein, N is an integer greater than or equal to 2, and the first P device includes:
[0041] A receiving unit, configured to receive a first route sent by the first PE device, where the first route includes the network segment to which the first SRv6 VPN SID belongs;
[0042] The receiving unit is further configured to receive a second route sent by the second PE device, where the second route includes the network segment to which the second SRv6 VPN SID belongs;
[0043] A processing unit, configured to establish a fifth path from the first P device to the first PE device according to the network segment to which the first SRv6 VPN SID belongs, and the fifth path is used by the first P device to forward packets to the second CE device;
[0044] The processing unit is further configured to establish a sixth path from the first P device to the second PE device according to the network segment to which the second SRv6 VPN SID belongs, and the sixth path is used by the first P device to forward packets to the second CE device when the fifth path fails.
[0045] Combined with the seventh aspect, in the first implementation manner of the seventh aspect, the receiving unit is further configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0046] The processing unit is further configured to determine to forward the first packet through the sixth path according to the first SRv6 VPN SID when the fifth path fails.
[0047] In an eighth aspect, the present application provides a P device. As the first P device, the P device is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device. The second CE device is multi-homed connected to the N egress PE devices. The ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first SRv6 VPN SID, and the first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID, and the second SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The at least one P device includes the first P device. The first P device is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device. Wherein, N is an integer greater than or equal to 2, and the first P device includes:
[0048] A receiving unit, configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0049] A processing unit, configured to determine a fifth path for transmitting the first packet according to the first SRv6 VPN SID, and the first P device is connected to the first PE device through the fifth path;
[0050] The processing unit is further configured to determine that the fifth path fails, and the first P device determines to forward the first packet through a sixth path according to the first SRv6 VPN SID, and the first P device is connected to the second PE through the sixth path;
[0051] A sending unit, configured to forward the first packet to the second CE device through the sixth path.
[0052] Combined with the eighth aspect, in the first implementation manner of the eighth aspect, the receiving unit is further configured to receive a first route sent by the first PE device, where the first route includes the network segment to which the first SRv6 VPN SID belongs;
[0053] The receiving unit is further configured to receive a second route sent by the second PE device, where the second route includes the network segment to which the second SRv6 VPN SID belongs;
[0054] The processing unit is further configured to establish the fifth path according to the network segment to which the first SRv6 VPN SID belongs, and establish the sixth path according to the network segment to which the second SRv6 VPN SID belongs. The sixth path is used by the first P device to forward packets to the second CE device when the fifth path fails.
[0055] In a ninth aspect, the present application provides a communication system, which includes a PE device as described in the fifth aspect or any implementation manner of the fifth aspect and a P device as described in the seventh aspect or any implementation manner of the seventh aspect.
[0056] In a tenth aspect, the present application provides a communication system, which includes a PE device as described in the fifth aspect or any implementation manner of the fifth aspect and a P device as described in the eighth aspect or any implementation manner of the eighth aspect.
[0057] In an eleventh aspect, the present application provides a communication system, which includes a PE device as described in the sixth aspect or any implementation manner of the sixth aspect and a P device as described in the seventh aspect or any implementation manner of the seventh aspect.
[0058] In a twelfth aspect, the present application provides a communication system, which includes a PE device as described in the sixth aspect or any implementation manner of the sixth aspect and a P device as described in the eighth aspect or any implementation manner of the eighth aspect.
[0059] In a thirteenth aspect, the present application provides an operator edge PE device, including: a processor, a memory, and a communication interface;
[0060] The memory and the communication interface are coupled to the processor;
[0061] The memory is used to store computer program code, and the computer program code includes instructions. When the processor executes the instructions, the PE device is used to execute the method for processing routes as described in the first aspect or any implementation manner of the first aspect.
[0062] In a fourteenth aspect, the present application provides an operator edge PE device, including: a processor, a memory, and a communication interface;
[0063] The memory and the communication interface are coupled to the processor;
[0064] The memory is used to store computer program code, and the computer program code includes instructions. When the processor executes the instructions, the PE device is used to execute the data transmission method described in the second aspect or any one of the implementation manners of the second aspect.
[0065] In a fifteenth aspect, the present application provides an operator P device, including: a processor, a memory, and a communication interface;
[0066] The memory and the communication interface are coupled to the processor;
[0067] The memory is used to store computer program code, and the computer program code includes instructions. When the processor executes the instructions, the P device is used to execute the routing processing method described in the third aspect or any one of the implementation manners of the third aspect.
[0068] In a sixteenth aspect, the present application provides an operator P device, including: a processor, a memory, and a communication interface;
[0069] The memory and the communication interface are coupled to the processor;
[0070] The memory is used to store computer program code, and the computer program code includes instructions. When the processor executes the instructions, the P device is used to execute the data transmission method described in the fourth aspect or any one of the implementation manners of the fourth aspect.
[0071] In a seventeenth aspect, the present application provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores instructions, and when the instructions run on a computer, the computer is caused to execute the routing processing method described in the first aspect or any one of the implementation manners of the first aspect.
[0072] In an eighteenth aspect, the present application provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores instructions, and when the instructions run on a computer, the computer is caused to execute the data transmission method described in the second aspect or any one of the implementation manners of the second aspect.
[0073] Nineteenth aspect, the present application provides a computer-readable storage medium, characterized in that instructions are stored in the computer-readable storage medium, and when the instructions are run on a computer, the computer is caused to execute the method for processing a route as described in the third aspect or any one of the implementation manners of the third aspect.
[0074] Twentieth aspect, the present application provides a computer-readable storage medium, characterized in that instructions are stored in the computer-readable storage medium, and when the instructions are run on a computer, the computer is caused to execute the method for data transmission as described in the fourth aspect or any one of the implementation manners of the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the accompanying drawings required to be used in the embodiments of the present invention.
[0076] Figure 1 FIG. is a schematic diagram of an SRv6 network architecture provided according to an embodiment of the present invention;
[0077] Figure 2 FIG. is a schematic diagram of a network architecture for carrying SRv6-based VPN services provided according to an embodiment of the present invention;
[0078] Figure 3 FIG. is a schematic flowchart of a method for processing a route provided according to an embodiment of the present invention;
[0079] Figure 4 FIG. is a schematic flowchart of a method for data transmission provided according to an embodiment of the present invention;
[0080] Figure 5 FIG. is a schematic flowchart of a method for processing a route provided according to another embodiment of the present invention;
[0081] Figure 6 FIG. is a schematic diagram of fields in the BGP-Prefix-SID attribute provided according to another embodiment of the present invention;
[0082] Figure 7 FIG. is a schematic flowchart of a method for data transmission provided according to another embodiment of the present invention;
[0083] Figure 8 FIG. is a schematic block diagram of a PE device provided according to an embodiment of the present invention;
[0084] Figure 9 FIG. is a schematic block diagram of another PE device provided according to an embodiment of the present invention;
[0085] Figure 10It is a schematic block diagram of a PE device provided according to another embodiment of the present invention;
[0086] Figure 11 It is a schematic block diagram of a P device provided according to an embodiment of the present invention;
[0087] Figure 12 It is a schematic block diagram of a P device provided according to another embodiment of the present invention;
[0088] Figure 13 It is a schematic block diagram of a PE device provided according to another embodiment of the present invention;
[0089] Figure 14 It is a schematic block diagram of a PE device provided according to yet another embodiment of the present invention;
[0090] Figure 15 It is a schematic block diagram of a P device provided according to another embodiment of the present invention;
[0091] Figure 16 It is a schematic block diagram of a P device provided according to yet another embodiment of the present invention. Detailed implementation manners
[0092] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0093] For the SRv6-based VPN technology involved in this application, reference can be made to the description in the draft of the Internet Engineering Task Force (IETF) "BGP Signaling of Ipv6-Segment-Routing-based VPN networks draft-dawra-idr-srv6-vpn-02.txt", and the content in this draft is incorporated into this application by reference in its entirety.
[0094] Unless otherwise stated, the ordinal numbers such as "first", "second", "third", "fourth", "fifth", and "sixth" mentioned in the embodiments of this application are used to distinguish multiple objects and are not used to limit the order of multiple objects.
[0095] The following combines Figure 1 The network scenario shown is used to give an exemplary introduction to the Internet Protocol Version 6 Segment Routing (SRv6) technology involved in the embodiments of this application. It should be understood that Figure 1The scenarios shown should not be construed as limitations of this application. For example, Figure 1 As shown, the source host is connected to the source PE, and the source PE is connected to the destination PE through Node 1 and Node 2, and the destination PE is connected to the destination host.
[0096] The SRv6 network is a network architecture formed by adopting segment routing (SR) tunnel encapsulation technology on the basis of the sixth version of the Internet Protocol (IPv6) network. In the SRv6 network, the SR tunnel technology is a tunnel encapsulation technology implemented based on the extension of the Interior Gateway Protocol (IGP). Among them, a segment is essentially a fragment identifier used to identify the corresponding route. For example, it can be an IPv6 address used to identify a link or the next hop. Routing represents routing. Therefore, it can be defined as Segment of Routing, abbreviated as Segment Routing (SR). The implementation modes of SR include but are not limited to the Segment Routing Traffic Engineering (SR-TE) mode and the Segment Routing Best Effort (SR-BE) mode, etc. For a network constructed based on the SR-BE tunnel technology, the service forwarding path is marked by setting the outer tunnel address and the inner tunnel address. Among them, the outer tunnel address can be, for example, the IPv6 address of the tunnel destination node device, and the inner tunnel address can be the IPv6 address of the tunnel source node device. At the source node device, encapsulating the outer tunnel address based on the SR-BE tunnel for the packet can control the packet forwarding path to the destination node device. In view of this, when configuring multi-homing protection based on the SR-BE tunnel technology, the configurations related to the intermediate path and path switching can be simplified, and only the outer tunnel address indicating the source node device to the destination node device needs to be configured. Therefore, configuring multi-homing protection based on the SR-BE technology is widely used. Take Figure 1For example, the source PE is the source node device of the SR tunnel, and the destination PE is the destination node device of the SR tunnel. The source PE, Node 1, Node 2, and the destination PE form a data transmission SR tunnel. The source PE is connected to the source host through Interface 1, and the destination PE is connected to the destination host. If the IPv6 address of the source PE is A and the IPv6 address of the destination PE is B, then when the source PE receives a packet sent from the source host to the destination host through Interface 1, the source PE searches the VPN routing forwarding table (Virtual Routing Forwarding, VRF) associated with Interface 1 to determine the tunnel information associated with the route, and encapsulates the packet. The inner layer of the packet encapsulates the source host address and the destination host address, and the outer layer of the packet encapsulates the IPv6 packet header. The outer destination address encapsulated in the IPv6 packet header is the IPv6 address B of the destination PE of the tunnel, and the inner source address in the IPv6 packet header is the IPv6 address A of the source PE of the tunnel. The packet forwarding is guided based on the outer destination address in the IPv6 packet header until the last hop of the SR tunnel, that is, the destination PE. After removing the IPv6 packet header of the packet, the destination PE sends the packet to the destination host.
[0097] The network based on the SR-TE tunnel is an SR tunnel encapsulation technology that strictly restricts the forwarding path, that is, between the source PE and the destination PE, every node passed by the forwarding path is strictly restricted. Taking Figure 1For example, the source PE is the source node device of the SR tunnel, and the destination PE is the destination node device of the SR tunnel. The source PE, Node 1, Node 2, and the destination PE form an SR tunnel for transmitting data. The source PE is connected to the source host through Interface 1, and the destination PE is connected to the destination host. If the IPv6 address of the source PE is A and the IPv6 address of the destination PE is B, then when the source PE receives a packet sent from the source host to the destination host through Interface 1, the source PE searches the VRF routing table associated with Interface 1 to determine the tunnel information associated with the route, and encapsulates the packet based on the tunnel information. The inner layer of the packet encapsulates the source host address and the destination host address, and then the addresses of the nodes specified by the SR tunnel are encapsulated in the outer layer of the packet, that is, the path specified by the tunnel information passes through Node 1 and Node 2 to the destination PE. Then, the packet is encapsulated with the addresses of Node 1, Node 2, and the destination PE from the inside out in sequence to determine the transmission path of the packet. Then, an IPv6 packet header is encapsulated on the outermost side of the packet. The outer destination address encapsulated in the IPv6 packet header is the address of the next-hop node (the address of Node 1) for the source PE to transmit the packet through the SR tunnel, and the inner source address in the IPv6 packet header is the IPv6 address A of the source PE of the tunnel. Node 1 receives the packet sent by the source PE, determines the address of the next hop based on the addresses of the nodes specified by the SR tunnel encapsulated in the packet, and determines the next-hop node (Node 2) according to the longest matching principle. Then, it modifies the outer destination address in the outermost IPv6 packet header of the packet to the address of the next-hop node of Node 1 (the address of Node 2), and sends the packet to Node 2. After receiving the packet, Node 2 determines the address of the next hop based on the addresses of the nodes specified by the SR tunnel encapsulated in the packet, and determines the next-hop node (the destination PE) according to the longest matching principle. At this time, Node 2 can also determine that it is the penultimate-hop node of the SR tunnel according to the addresses of the nodes specified by the SR tunnel. Then, it removes the addresses of the nodes specified by the SR tunnel encapsulated in the packet, and modifies the outer destination address in the outermost IPv6 packet header of the packet to the address of the destination PE, and sends the packet to the destination PE, thus completing the process of packet forwarding in the SR tunnel. After removing the IPv6 packet header of the packet, the destination PE sends the packet to the destination host.
[0098] The following Figure 2 introduces the possible SRv6-based VPN network by way of example in the network scenario shown. Those skilled in the art can understand that Figure 2 only the dual-homed scenario is introduced by way of example herein, and it should not be construed as a limitation to this application. For example, the CE device can also be multi-homed and connected to three or more egress PE devices, which will not be elaborated in this application.
[0099] As Figure 2As shown in the figure, PE1 and PE2 belong to egress PE devices, and PE3 and PE4 belong to ingress PE devices. PE3 is connected to PE1 through P1, PE3 is connected to PE2 through P1 and P2, PE4 is connected to PE2 through P2, and PE4 is connected to PE1 through P2 and P1. CE1 is dual-homed to connect PE3 and PE4, and CE2 is dual-homed to connect PE1 and PE2. CE1 and CE2 belong to the same VPN. It should be noted that in this application, ingress PE devices and source PE devices are often used interchangeably, and egress PE devices and destination PE devices are often used interchangeably.
[0100] The SRv6 VPN SID configured on PE1 is identified by the IPv6 address A, and the IPv6 address B configured on PE2 is used to represent it. Among them, the address A is used to identify the VPN to which CE2 belongs in PE1, or to identify the egress interface of PE1 connecting CE2. The address B is used to identify the VPN to which CE2 belongs in PE2, or to identify the egress interface of PE2 connecting CE2. The address A and the address B are different.
[0101] When CE1 sends a message to CE2, CE1 first sends the message to be sent to CE2 to PE3. PE3 can forward the message sent by CE1 to CE2 through tunneling technologies such as SR-BE. In Figure 2 In the network scenario shown in the figure, assume that PE3 determines to transmit the message sent by CE1 through P1 and PE1. Since after the message is transmitted to P1, the outer destination address in the outermost IPv6 header of the message is the address A, and P1 determines the next-hop node according to the outer destination address in the outermost IPv6 header of the message. Therefore, if PE1 fails, the message cannot be transmitted between P1 and PE1. So P1 needs to switch the message to the path where PE4 is located to transmit the message, that is, P1 modifies the outer destination address encapsulated by the message to the address B. After receiving the message, PE4 searches the corresponding VRF table according to the address B and finds the VPN identified by the address B. However, because the VPN identified by the address B is different from the VPN identified by the address A in the PE3 device, PE4 cannot determine the correct transmission path, which will cause PE4 to be unable to continue transmitting the message, resulting in the message being unable to be transmitted to CE2 and causing the multi-homed protection to fail to take effect.
[0102] Therefore, in order to ensure that the message can be transmitted to CE2, PE3 also needs to detect whether the egress PE device of the path is faulty when determining the path for transmitting the message. That is, after PE3 determines to transmit the message sent by CE1 through P1 and PE1, it needs to detect whether PE1 is faulty. If PE1 is faulty, PE3 needs to perform path switching and switch the message to other paths for transmission to avoid the situation where the message cannot be transmitted to CE2 due to the failure of PE1.
[0103] Currently, the fault detection between PE devices is usually completed through the configured BFD. That is, PE3 determines whether PE1 has a fault through the BFD configured between PE3 and PE1. If PE1 fails, path switching is required.
[0104] From the above process of message transmission between CE1 and CE2, it can be seen that when PE3 determines the path for transmitting the message sent by CE1, it needs to detect whether the path is faulty by configuring BFD between PEs to ensure that the message can be transmitted normally. In this way, BFD needs to be deployed after a path is established between each PE device and other PE devices to achieve fast fault detection, which leads to a large number of BFDs being deployed in each PE device, thus consuming excessive resources of the PE.
[0105] And Figure 2 In the network scenario shown, BFD based on interfaces also needs to be configured between neighbor devices, which can be used to detect whether the link between neighbor devices is faulty. After PE3 determines to transmit the message sent by CE1 through P1, it will detect whether the link between PE3 and P1 is faulty through the BFD configured between PE3 and P1. Therefore, when PE3 determines the path for transmitting the message sent by CE1, two layers of fault detection are required. One layer is the fault detection between PE3 and P1, and the other layer is the fault detection between PE3 and PE1. And usually, the fault detection between PE3 and P1 is preferentially performed. When there is no fault between PE3 and P1, the fault detection between PE3 and PE1 is performed to ensure the accuracy of path fault detection. Therefore, PE3 consumes the time of two layers of fault detection and path switching in the whole process of completing path switching.
[0106] For example, usually when detecting faults between PE3 and P1, generally 3 detection cycles are required to determine whether the link is faulty, and each cycle requires 10 milliseconds (ms), so the fault detection between PE3 and P1 usually requires 30 ms. When detecting faults between PE3 and PE1, the detection cycle between PE3 and PE1 is longer than that between PE3 and P1, that is, it needs to be at least 30 ms, and generally 3 detection cycles are required, so the fault detection between PE3 and PE1 requires at least 90 ms. Combining the above process and the time for path switching, PE3 requires at least 100 ms to determine a fault and complete the path switching process.
[0107] In view of this, an embodiment of the present invention proposes a method, which can be applied to, for example, Figure 2 the network scenario shown, to effectively reduce the number of BFDs deployed in PE devices while implementing multi-homing protection in a network carrying SRv6-based VPN services.
[0108] The method and apparatus provided by the embodiments of the present invention can be used in a network that carries SRv6-based VPN services. This network may include, but is not limited to, the following devices: PE devices, P devices, and CE devices. PE devices and P devices are devices in the operator network that provide SRv6-based VPN services, and CE devices are devices in the customer network that apply the SRv6-based VPN services. According to the data transmission direction, PE devices can be divided into ingress PE devices and egress PE devices. The ingress PE device is an ingress PE device of the public network and is connected to the source CE device according to the data transmission direction. Therefore, it can also be called the source PE device; the egress PE is connected to the destination CE device (or called the sink CE), so it can also be called the destination PE or the sink PE. The distinction between the ingress PE device and the egress PE device is related to the data transmission direction. The ingress PE device and the egress PE device can be connected through at least one P device. When a CE device is connected to a PE device, it can be multi-homed to connect to multiple PE devices.
[0109] Specifically, the CE device may include a first CE device and a second CE device, and the first CE device and the second CE device belong to the same VPN. Assume that the data transmission direction is from the first CE device to the second CE device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed to connect to N egress PE devices, and the ingress PE device communicates with the N egress PE devices through at least one P device. The N egress PE devices include a first PE device and a second PE device, and the at least one P device includes a first P device. The first P device is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device. Wherein, N is an integer greater than or equal to 2.
[0110] In the embodiments of the present invention, the network that carries SRv6-based VPN services can access various services, for example, Layer 3 VPN (L3VPN) services, Ethernet Virtual Private Network (EVPN) Virtual Private Wire Service (VPWS) services, EVPN Virtual Private Lan Service (VPLS), and so on.
[0111] In a network carrying SRv6-based VPN services, a PE device can be configured with one or more SRv6 VPN SIDs. Each SRv6 VPN SID is used to identify the VPN to which a CE device connected to the PE device belongs, or to identify the outgoing interface of the PE device connecting to the CE device. For example, in Figure 2 the network architecture shown, PE1 is configured with a first SRv6 VPN SID to identify the VPN to which CE2 belongs or the outgoing interface of PE1 connecting to CE2, and PE2 is configured with a second SRv6 VPN SID to identify the VPN to which CE2 belongs or the outgoing interface of PE2 connecting to CE2. At the same time, the SRv6 VPN SID configured in the PE device can be used as the IPv6 address of the PE device. When transmitting packets, the SRv6 VPN SID can be used as the IPv6 address of the corresponding PE for packet transmission.
[0112] It should be noted that in the embodiments of this application, the related expression of "SRv6 VPN SID configured by the PE device" or the related expression of "SRv6 VPN SID in the PE device" means that the PE device stores the SRv6 VPN SID. The PE device in this application can be, for example, a router, a layer 3 switch, or a Packet Transport Network (PTN) device. The CE device can be, for example, a router, a layer 3 switch, a host, or a PTN device. This application does not make specific limitations on this.
[0113] The SRv6 VPN SID includes two parts: a SID segment and an index. The SID segment represents an IPv6 network segment address, and the index is equivalent to the value of secondary allocation of addresses within the IPv6 network segment. For example, if PE1 configures the SID segment as 101::(64) and configures an index of 1001, then one SRv6 VPN SID of PE1 can be obtained as 101::1001. Multiple indexes can be configured in the PE device, and the indexes can be set based on the accessed services. For example, indexes can be configured according to VRF, VPN instance, or VPWS service instance, etc. Different indexes combined with the SID segment can enable each service to configure different SRv6 VPN SIDs.
[0114] In the control plane of a network carrying SRv6-based VPN, each device needs to exchange routing information. The routing exchange between P devices and other devices can be achieved through the publication of public network routes, for example, by means of Interior Gateway Protocol (IGP), routing protocols (such as Intermediate System-to-Intermediate System (IS-IS) protocol or Open Shortest Path First (OSPF) or Border Gateway Protocol (BGP)), and propagated in the network based on topology information such as the shortest path algorithm to generate SR tunnels. Between a CE device and the directly connected PE device, routing information can be exchanged, for example, by means of static routing or establishing neighbor relationships to publish routes. Between each PE device, an MP-BGP session can be established, and each PE device's VPN routes can be exchanged through MP-BGP messages. The PE device directly connected to the CE device will establish a corresponding Virtual Routing Forwarding (VRF) for the CE device to store the routing information of the corresponding CE device. Take Figure 2 the following network architecture as an example. A neighbor relationship can be established between CE1 and the directly connected PE3. For example, a neighbor relationship can be established through a Border Gateway Protocol (BGP) session. CE1 publishes the routing information of CE1 to the directly connected PE3 through BGP messages, enabling PE3 to learn the routing information of CE1. PE3 can exchange VPN routes with PE1 by establishing an MP-BGP session, allocate and mutually publish VPN labels. PE3 publishes the VPN routing information to PE1 and also publishes the VPN routing information to PE2 through the MP-BGP session established with PE2, enabling PE1 and PE2 to learn the VPN routing information of PE3. An adjacency relationship can also be established between PE1 and CE2 through MP-BGP, enabling CE2 to learn the routing information of PE3. Similarly, an adjacency relationship can be established between PE2 and CE2, enabling CE2 to learn the routing information of PE3.
[0115] The routing information published by each of the above devices includes its respective IP address or Media Access Control (MAC) address, so that the device that learns this routing information can determine the path to reach this device based on the above address. The source IP address in the routing information published by the PE device can be the SRv6 VPN SID configured for the PE device.
[0116] In the embodiments of the present invention, in order to reduce the number of BFDs deployed in the PE, at least two of the PE devices to which the CE device is multi-homed are respectively configured with two SRv6 VPN SIDs. The configured SRv6 VPN SIDs are both used to identify the VPN to which the CE belongs or the outgoing interface through which the PE device connects to the CE device. Specifically, the first PE device configures a first SRv6 VPN SID, which is used to identify the VPN to which the second CE belongs or the outgoing interface through which the first PE connects to the second CE. The second PE configures a second SRv6 VPN SID, which is used to identify the VPN to which the second CE belongs or the outgoing interface through which the second PE connects to the second CE. The first SRv6 VPN SID is the same as the second SRv6 VPN SID.
[0117] For example, in Figure 2 the network architecture shown, the SID segment of the first SRv6 VPN SID configured by PE1 is 101::(64), and the index is 1001. Then, the first SRv6 VPN SID of PE1 is 101::1001. At the same time, PE1 also configures the SID segment of the fourth SRv6 VPN SID to be 555::(64). Combining the index 1001 configured for the first SRv6 VPN SID, the fourth SRv6 VPN SID can be obtained as 555::1001. The first SRv6 VPN SID configured by PE1 is the same as the second SRv6 VPN SID configured by PE2. Therefore, the SID segment of the second SRv6 VPN SID configured by PE2 is 101::(64), and the index is 1001. Then, the second SRv6 VPN SID of PE2 is 101::1001. At the same time, PE2 also configures the SID segment of the third SRv6 VPN SID to be 666::(64). Combining the index 1001 configured for the second SRv6 VPN SID, the third SRv6 VPN SID of PE2 can be obtained as 666::1001.
[0118] In the process of the above CE1 sending a message to CE2, P1 determines the next-hop node according to the first SRv6 VPN SID encapsulated in the message. Therefore, after PE3 determines to transmit the message through path 1, when the message is transmitted to P1, even if the PE1 corresponding to the first SRv6 VPN SID fails and the message cannot be transmitted between P1 and PE1, P1 can still determine the path to reach PE2 according to the first SRv6 VPN SID to transmit the message. Therefore, P1 can transmit the message to PE2 through the path to reach PE2, so that PE2 transmits the message to CE2, thus ensuring the normal transmission of the message.
[0119] In the embodiment of the present invention, the second SRv6 VPN SID is the same as the first SRv6 VPN SID. Therefore, the paths for other devices to reach the first SRv6 VPN SID include the paths to the first PE device and the second PE device. Therefore, when the first CE device sends a message to the second CE device, if the path to the first PE device fails, the path to the second PE device can also be determined according to the first SRv6 VPN SID encapsulated in the message. Furthermore, the message can be transmitted through the path to the second PE device, so that the second PE device can send the message to the second CE device. In this way, when the first CE sends a message to the second CE, when determining the message transmission path, the ingress PE does not need to detect whether the egress PE in the path fails. Instead, when it is detected that the egress PE fails during the message transmission process, the message is transmitted through the path to the PE with the same SRv6 VPN SID as the egress PE, thereby realizing fast path switching. Therefore, there is no need to deploy BFD between the PE devices that establish the path to detect faults, thereby reducing the number of BFDs deployed in the PE devices and reducing the resources occupied by BFD in the PE devices.
[0120] Moreover, in the embodiment of the present invention, there is no need to deploy BFD between the PE devices that establish the path to detect faults. The path switching process only requires one layer of fault detection, that is, the fault detection between P1 and PE1, which can reduce the time for the PE device to detect faults when determining the path. Furthermore, the time required to complete the path switching can be reduced, the speed of path switching can be increased, and the performance of path switching can be improved.
[0121] For example, when detecting faults between P1 and PE1, it usually takes 30 ms. Combining with the time for switching the path, P1 can save at least 50 ms in the process of determining faults and completing the path switching compared with the above two-layer fault detection method, thereby increasing the speed of path switching and improving the performance of path switching.
[0122] The embodiments of the present invention will be described below from the control plane and the forwarding plane respectively.
[0123] An embodiment of the present invention provides a method for processing routes, which is used for the control plane of the above network carrying SRv6-based VPN services, and can be specifically used for Figure 2 the control plane of the network architecture shown in Figure 3 as shown, and the method includes the following steps.
[0124] 101. The first P device receives a first route sent by the first PE device.
[0125] Among them, the first route includes the network segment to which the first SRv6 VPN SID belongs. In the embodiment of the present invention, for the network carrying SRv6-based VPN services, the network segment to which the SRv6 VPN SID belongs is an IPv6 network segment. The SRv6 VPN SID includes two parts: a SID segment and an index. The SID segment represents the IPv6 network segment address. Therefore, the network segment to which the first SRv6 VPN SID belongs is the SID segment of the first PE device configuring the first SRv6 VPN SID.
[0126] Routing information needs to be exchanged between devices to determine the paths to each other. The routing exchange between the P device and other devices can be achieved by the way of public network route publication to exchange routing information. Therefore, the first P device will receive the routes sent by other devices, and the routes include the addresses of the corresponding devices. For example, the first PE device sends the first route to the first P device, and the first route includes the network segment to which the first SRv6 VPN SID of the first PE device belongs. The first P device will receive the first route sent by the first PE device, which includes the network segment to which the first SRv6 VPN SID belongs.
[0127] 102. The first P device receives the second route sent by the second PE device.
[0128] The second route includes the network segment to which the second SRv6 VPN SID belongs. Based on the same principle as in step 101, the first P device can also receive the second route sent by the second PE device, which includes the network segment to which the second SRv6 VPN SID belongs.
[0129] 103. The first P device establishes a fifth path from the first P device to the first PE device according to the network segment to which the first SRv6 VPN SID belongs.
[0130] After the first P device receives the first route sent by the first PE device and determines the network segment to which the first SRv6 VPN SID belongs from the first route, it can establish a fifth path from the first P device to the first PE device according to the network segment to which the first SRv6 VPN SID belongs. When transmitting packets from the first P device to the second CE subsequently, according to the longest matching principle, based on the outer destination address of the packet and the network segment to which the first SRv6 VPN SID belongs, it can be determined that the packet is transmitted to the first PE through the fifth path, and the first PE forwards the packet to the second CE.
[0131] 104. The first P device establishes a sixth path from the first P device to the second PE device according to the network segment to which the second SRv6 VPN SID belongs.
[0132] After the first P device receives the second route sent by the second PE device, it determines the network segment to which the second SRv6 VPN SID belongs from the second route, and then can establish a sixth path from the first P device to the second PE device according to the network segment to which the second SRv6 VPN SID belongs. When transmitting packets from the first P device to the second CE subsequently, the packets can be transmitted to the second PE through the sixth path, enabling the second PE to forward the packets to the second CE.
[0133] In the embodiment of the present invention, the first SRv6 VPN SID is the same as the second SRv6 VPN SID, and the network segment to which the first SRv6 VPN SID belongs is also the same as the network segment to which the second SRv6 VPN SID belongs. Therefore, the network segments reached by the fifth path and the sixth path established by the first P device are the same. So, when the first P device's data forwarding layer forwards packets with the destination address being the first SRv6 VPN SID, there can be two paths for forwarding. The control layer of the first P device will send a path to the forwarding layer to enable the data forwarding layer of the first P device to forward packets according to the path sent by the control layer. Since the first PE is a neighbor node of the first PE device and the first PE device is the next hop of the first P device, the control layer of the first P device usually prefers the fifth path. However, when the fifth path fails, the sixth path is used as a backup path, that is, the first P device switches the packets to the sixth path to forward the packets to the second CE device.
[0134] In the above process, the first P device receives the routes sent by the first PE device and the second PE device respectively. At the control layer, other P devices will also receive the routes sent by the first PE device and the second PE device through the same principle and establish corresponding paths for transmitting packets. Moreover, the first PE device and the second PE device will also send VPN routes to other PE devices (such as ingress PE devices). Specifically, the VPN routes can also be sent to other PE devices in the way carried by MP-BGP messages. For example, the second PE device can send a first VPN route to the ingress PE device, and the first VPN route includes the second SRv6 VPN SID; the first PE device can send a second VPN route to the ingress PE device, and the second VPN route includes the first SRv6 VPN SID. After receiving the first VPN route and the second VPN route, the ingress PE device establishes a path to the first PE device according to the first SRv6 VPN SID and establishes a path to the second PE device according to the second SRv6 VPN SID. Since the first SRv6 VPN SID is the same as the second SRv6 VPN SID, when the data forwarding layer of the ingress PE device forwards packets with the destination address being the first SRv6 VPN SID, there can be two paths for forwarding, and the control layer of the ingress PE device will send a path to the forwarding layer.
[0135] By controlling the exchange process of layer routing information, a transmission path can be established between devices. Based on the above embodiments, multi-homing protection can be achieved during the process of the first CE device sending the first packet to the second CE device, enabling the first packet to be transmitted to the second CE device.
[0136] Specifically, an embodiment of the present invention provides a data transmission method for the data forwarding layer of the above SRv6-based VPN, which can be specifically used for Figure 2 the data forwarding layer of the network architecture shown, such as Figure 4 shown, and the method includes the following steps.
[0137] 201, the first P device receives the first packet.
[0138] Among them, the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID.
[0139] In a network based on SRv6-based VPN services, the data forwarding layer is used to forward packets transmitted between two CEs. In the embodiments of the present invention, the example of the first CE device sending the first packet to the second CE device is taken.
[0140] In the embodiments of the present invention, the first CE device sends the first packet to the ingress PE device (such as Figure 2 PE3 in), at this time, the first packet includes the source CE address and the destination CE address. The source CE address is the address of the first CE device, and the destination CE address is the address of the second CE device. After receiving the first packet, the ingress PE device's control layer can determine the path for transmitting the first packet based on the destination CE address and the VRF corresponding to the first CE device, and send the determined path to the data forwarding layer of the ingress PE device. The data forwarding layer of the ingress PE device can encapsulate the first packet based on the determined path and tunnel technologies such as SR-BE, and forward the encapsulated first packet.
[0141] In the embodiments of the present invention, the egress PE device determined in the path for transmitting the first packet is the first PE device, and its address is the first SRv6 VPN SID. When the first packet reaches the first P device after transmission, the outer destination address encapsulated in the first packet received by the first P device is the first SRv6 VPN SID. The first P device determines that it needs to send the first packet to the device with the address of the first SRv6 VPN SID based on the outer destination address of the first packet. Therefore, the first P device can determine the path for transmitting the first packet according to the first SRv6 VPN SID.
[0142] 202. The first P device determines the fifth path for transmitting the first packet according to the first SRv6 VPN SID.
[0143] The fifth path is the path from the first P device to the first PE.
[0144] As can be seen from step 103, after the first device receives the first route sent by the first PE device, it establishes the fifth path to the first PE device through the network segment to which the first SRv6 VPN SID belongs. Then in this step, according to the outer destination address of the first packet, that is, the first SRv6 VPN SID, the fifth path for transmitting the first packet can be determined according to the longest matching principle.
[0145] It should be noted that since the first SRv6 VPN SID of the first PE device is the same as the second SRv6 VPN SID of the second PE device, and the network segment to which the first SRv6 VPN SID belongs is also the same as the network segment to which the second SRv6 VPN SID belongs, there are two paths in the first device to reach the first SRv6 VPN SID. One is the fifth path from the first P device to the first PE device, and the other is the sixth path from the first P device to the second PE device. Since the first PE device is the next hop of the first P device, the first P device usually prefers to transmit the first packet through the fifth path. Therefore, in the embodiment of the present invention, the first P device determines the fifth path from the first P device to the first PE device according to the destination address of the first packet to transmit the first packet.
[0146] 203. When the first P device determines that the fifth path fails, the first P device determines to forward the first packet through the sixth path according to the first SRv6 VPN SID.
[0147] The first P device connects to the second PE through the sixth path.
[0148] In a network based on SRv6-based VPN services, neighbor devices also need to perform fault detection when transmitting data. Usually, BFD is configured between neighbor devices for fast path fault detection. After the first P device determines the fifth path from the first P device to the first PE according to the first SRv6 VPN SID, and its next hop is the first PE device, the first P device can detect whether the fifth path fails according to the BFD configured with the first PE device. If the first P device detects that the fifth path fails, the first P device needs to perform path switching, that is, determine the sixth path to the second PE device according to the first SRv6 VPN SID and the longest matching principle to transmit the first packet.
[0149] It should be noted that when the first P device determines to transmit the first packet through the sixth path to the second PE, it can also perform path fault detection on the path from the first P device to the next hop to ensure that the first packet can be normally transmitted to the next hop.
[0150] 204, the first P device forwards the first packet to the second CE device through the sixth path.
[0151] After the first P device determines in step 203 to transmit the first packet through the sixth path, it then switches the first packet to the sixth path for transmission.
[0152] At this time, the first P device can determine the outgoing interface connected to the next hop according to the sixth path, and then forward the encapsulated first packet through the outgoing interface connected to the next hop. Since the second SRv6 VPN SID of the second PE device is the same as the first SRv6 VPN SID, and the VPNs identified by the second SRv6 VPN SID and the first SRv6 VPN SID are the same, after the first packet is transmitted to the second PE device, the second PE device can determine the correct path for forwarding the first packet by looking up the corresponding VRF table through the outer destination address encapsulated in the first packet, that is, the first SRv6 VPN SID, and then the second PE device can send the first packet to the second CE device, so that the multi-homing protection takes effect and ensures the accurate transmission of the packet.
[0153] In the embodiment of the present invention, since the second SRv6 VPN SID is the same as the first SRv6 VPN SID, the paths from the first P device to the first SRv6 VPN SID include two paths respectively reaching the first PE device and the second PE device. Therefore, when transmitting the packet sent by the first CE device to the second CE device, if the fifth path from the first P device to the first PE fails, the first P device can determine the sixth path to the second PE device, and then switch the packet to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device.
[0154] Thus, when the first CE device sends a packet to the second CE device, the ingress PE device may not detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path. Instead, when a fault of the egress PE device is detected during the packet transmission process, the packet is transmitted through the path to the PE device that has the same SRv6 VPN SID as the egress PE device, thereby achieving fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for fault detection when the PE device determines the path, and improving the speed of path switching.
[0155] Based on the above embodiments of the present invention, the second SRv6 VPN SID is the same as the first SRv6 VPN SID, and the network segment to which the first SRv6 VPN SID belongs is also the same as the network segment to which the second SRv6 VPN SID belongs. When transmitting the packet sent by the first CE device to the second CE device, if the fifth path from the first P device to the first PE is faulty, the first P device can determine the sixth path to the second PE device, so that the second PE device sends the packet to the second CE device. When the fifth path from the first P device to the first PE device is not faulty, the first P device sends the first packet to the first PE device. When the first PE device determines to transmit the first packet to the second CE device, it determines the first path directly connected between the first PE device and the second CE device to forward the first packet. At this time, the first PE device also needs to detect whether the first path directly connected between the first PE device and the second CE device is faulty. If the first path is faulty, path switching is required, that is, the first packet is switched to the second path connected to the second CE device through the second PE device for transmission. However, since the second SRv6 VPN SID is the same as the first SRv6 VPN SID between the second PE devices, the first PE device cannot achieve path switching of the first packet, and thus cannot achieve multi-homing path protection.
[0156] Based on the above problems, in the embodiments of the present invention, at least two of the PE devices to which the CE device is multi-homed are respectively configured with escape SRv6 VPN SIDs. The at least two PE devices are respectively configured with different escape SRv6 VPN SIDs. The escape SRv6 VPN SIDs configured by the at least two PE devices are also used to identify the VPN to which the CE belongs or the outgoing interface through which the PE device connects to the CE device. A path can be established between the at least two PE devices through the escape SRv6 VPN SIDs. Specifically, the first PE device is configured with a first SRv6 VPN SID and a fourth SRv6 VPN SID. Both the first SRv6 VPN SID and the fourth SRv6 VPN SID are used to identify the VPN to which the second CE belongs or the outgoing interface through which the first PE connects to the second CE. The second PE is configured with a second SRv6 VPN SID and a third SRv6 VPN SID. Both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE belongs or the outgoing interface through which the second PE connects to the second CE. The third SRv6 VPN SID and the fourth SRv6 VPN SID are the escape SRv6 VPN SIDs. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The first SRv6 VPN SID is different from the fourth SRv6 VPN SID. The fourth SRv6 VPN SID is different from the third SRv6 VPN SID. The third SRv6 VPN SID is different from the second SRv6 VPN SID.
[0157] The embodiments of the present invention will be described below from the control plane and the forwarding plane respectively.
[0158] In a network carrying SRv6-based VPN services, routing information needs to be exchanged between devices at the control plane. In Figure 3The process of the first PE device and the second PE device sending routes to the first P device is described in the illustrated embodiment. In the embodiment of the present invention, since the escape SRv6 VPN SIDs are respectively configured for the first PE device and the second PE device, the network segments to which their respective escape SRv6 VPN SIDs belong will also be carried in the sent routes. The first route sent by the first PE device includes the network segment to which the first SRv6 VPN SID belongs and the network segment to which the fourth SRv6 VPN SID belongs. After receiving the first route, the first P device will establish paths with the first PE device respectively according to the network segment to which the first SRv6 VPN SID belongs and the network segment to which the fourth SRv6 VPN SID belongs. The second route sent by the second PE device includes the network segment to which the second SRv6 VPN SID belongs and the network segment to which the third SRv6 VPN SID belongs. After receiving the second route, the first P device will establish paths with the second PE device respectively according to the network segment to which the second SRv6 VPN SID belongs and the network segment to which the third SRv6 VPN SID belongs. In the embodiment of the present invention, since the escape SRv6 VPN SIDs are respectively configured for the first PE device and the second PE device, the VPN routes sent between the PE devices will also be different. The process of sending VPN routes between the first PE device and the second PE device is taken as an example for illustration below.
[0159] An embodiment of the present invention provides another method for processing routes, which is used for the control plane of the network carrying SRv6-based VPN services, and can be specifically used for Figure 2 the control plane of the network architecture shown, such as Figure 5 shown, and the method includes the following steps.
[0160] 301. The first PE device receives the first VPN route sent by the second PE device.
[0161] Wherein, the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID.
[0162] In the network carrying SRv6-based VPN services, route information exchange is required between the PE devices at the control plane, that is, the first PE device publishes its own VPN route to the second PE device, and the second PE device also publishes its own VPN route to the first PE device. The PE devices usually publish their own VPN routes to each other through MP-BGP messages. The SRv6 VPN SIDs of their own will be included in the VPN routes published by the PE devices.
[0163] The first PE device and the second PE device are devices that are multi-homed to the second CE device. In the implementation of the present invention, both the second PE device and the second PE device are configured with two SRv6 VPN SIDs. The first PE device is configured with a first SRv6 VPN SID and a fourth SRv6 VPN SID. Both the first SRv6 VPN SID and the fourth SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the outgoing interface of the first PE device connecting to the second CE device. The second PE device is configured with a second SRv6 VPN SID and a third SRv6 VPN SID. Both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the outgoing interface of the second PE device connecting to the second CE device. Among them, the third SRv6 VPN SID and the fourth SRv6 VPN SID are escape SRv6 VPN SIDs. And the first SRv6 VPN SID is the same as the second SRv6 VPN SID, the fourth SRv6 VPN SID is different from the third SRv6 VPN SID, the fourth SRv6 VPN SID is different from the first SRv6 VPN SID, and the second SRv6 VPN SID is different from the third SRv6 VPN SID.
[0164] When the first PE device publishes VPN routes, the VPN routes include the first SRv6 VPN SID and the fourth SRv6 VPN SID. When the second PE device publishes VPN routes, the VPN routes include the second SRv6 VPN SID and the third SRv6 VPN SID.
[0165] Specifically, the first VPN route can be carried in the BGP-Prefix-SID attribute field of the MP-BGP message.
[0166] The BGP-Prefix-SID attribute field includes an SRv6-VPN SID TLV field. The SRv6-VPN SID TLV field includes a T field, an L field, a V field, and a reserved field. The specific structure can be as Figure 6 shown. Among them, the T field is used to indicate the type of the SRv6-VPN SID carried; the L field is used to indicate the total length of the V field, usually 16 bytes; the V field carries the specific SRv6-VPN SID information; the reserved field should be filled with 0 when sending the MP-BGP message and can be ignored when receiving the MP-BGP message, usually 8 bytes.
[0167] It should be noted that in the SRv6-based VPN, the function of the T field can be equivalent to the function of a VPN MPLS label attribute in a route including a Multi-Protocol Label Switching (MPLS) label, and can also be equivalent to the function of a VPN MPLS label attribute in a route including an EVPN route.
[0168] In the implementation of the present invention, the first VPN route includes a second SRv6 VPN SID and a third SRv6 VPN SID. Therefore, on the basis of carrying the second SRv6 VPN SID in the BGP-Prefix-SID attribute field, a new field needs to be extended to carry the third SRv6 VPN SID.
[0169] In a specific implementation manner, a TLV field can be extended to carry the above-mentioned third SRv6 VPN SID. The type T field in the TLV field is used to represent the type of the third SRv6 VPN SID. Specifically, it can be used to represent that the third SRv6 VPN SID is an escape SRv6 VPN SID, which is used to indicate that when a failure occurs between the first PE and the second CE or the second CE fails, it guides the first PE device to forward packets through the path between the first PE device and the second PE device, and the third SRv6 VPN SID is configured on the second PE device; the length L field in the TLV field is used to identify the length of the third SRv6 VPN SID, and the value V field in the TLV field.
[0170] In the implementation of the present invention, when carrying the third SRv6 VPN SID through the BGP-Prefix-SID attribute field, different Types can be set for the second SRv6 VPN SID and the third SRv6 VPN SID. For example, set the Type of the second SRv6 VPN SID to 1 and the Type of the third SRv6 VPN SID to 2. When the first PE device receives an MP-BGP message, it can identify the Type of the SRv6 VPN SID according to different TLV fields in the BGP-Prefix-SID attribute field, so as to distinguish the second SRv6 VPN SID and the third SRv6 VPN SID.
[0171] It should be noted that in the embodiments of the present invention, the above-mentioned third SRv6 VPN SID can also be carried through the NLRI field of the MP-BGP message.
[0172] The MP_REACH_NLRI can be understood as the multi - protocol extension attribute information of the NLRI, which includes three parts: the address family information field, the next - hop information field, and the network - layer reachability information (NLRI) field.
[0173] Among them, the address family information field includes an address family identifier field (2 bytes) and a sub - address family identifier field (1 byte). The Address Family Identifier (AFI) is used to identify the network - layer protocol. For example, when AFI takes the value of 1, it represents IPv4; when AFI takes the value of 2, it represents IPv6. The SAFI identifies the type of the sub - address family. For example, when SAFI takes the value of 1, it represents unicast; when SAFI takes the value of 2, it represents multicast; when SAFI takes the value of 128, it represents VPN. More specifically, when the AFI value is 1 and the SAFI value is 1, it means that the NLRI field carries IPv4 unicast routing; when the AFI value is 1 and the SAFI value is 128, it means that the NLRI field carries BGP - VPNv4 routing; when the AFI value is 1 and the SAFI value is 4, it means that the NLRI field carries BGP label routing.
[0174] The BGP synchronization address family can be understood as a sub - address family extended in the existing BGP protocol's IPv4 or IPv6 address family, that is, the AFI value can be 1 or 2. The value of SAFI can be determined according to the standards formulated by the Internet Engineering Task Force (IETF).
[0175] The next - hop information field includes a next - hop address length field (1 byte) and a next - hop address field (variable length). The next - hop address length field is used to identify the length of the next - hop address field, and the length of the next - hop address field is determined by the length indicated by the next - hop address length field.
[0176] There is a 1 - byte reserved field between the next - hop information field and the NLRI field.
[0177] The NLRI field includes the NLRI field.
[0178] The NLRI field can, for example, include TLV fields (variable length). The TLV field can include a T field, an L field, and a V field. Among them, the T field is used to represent the type of the carried third SRv6 VPN SID; the L field is used to represent the total length of the carried third SRv6 VPN SID, usually 16 bytes; the V field carries the third SRv6 VPN SID.
[0179] Those skilled in the art can understand that the third SRv6 VPN SID can also be carried in other ways, which will not be elaborated one by one in this application.
[0180] 302. The first PE device determines that the second SRv6 VPN SID is the same as the first SRv6 VPN SID.
[0181] In the embodiment of the present invention, at least two of the PE devices to which the CE device is multi-homed are configured with the same SRv6 VPN SID, which is used to identify the VPN to which the CE belongs in the PE device or the outgoing interface through which the PE device connects to the CE device. Therefore, after receiving the first VPN route from the second PE device, the first PE device can determine that the second SRv6 VPN SID in the first VPN route is the same as the first SRv6 VPN SID of the first PE device. Therefore, the first PE device can determine that the second PE device has also accessed the second CE device, and further determine that the second CE device is multi-homed to the first PE device and the second PE device.
[0182] 303. The first PE device establishes a second path from the first PE device to the second PE device according to the third SRv6 VPN SID in the first VPN route.
[0183] Wherein, when the first path directly connecting the first PE device and the second CE device fails, the second path is used by the first PE device to forward packets to the second CE device.
[0184] Since the first SRv6 VPN SID of the first PE device is the same as the second SRv6 VPN SID of the second PE device, the first PE device needs to establish a path with the second PE device through the third SRv6 VPN SID of the second PE device, and the second PE device will establish a path with the first PE device through the fourth SRv6 VPN SID of the first PE device, so that data can be transmitted between the first PE device and the second PE device.
[0185] Therefore, after determining that the second SRv6 VPN SID is the same as the first SRv6 VPN SID, the first PE device establishes a second path from the first PE device to the second PE device according to the third SRv6 VPN SID in the first VPN route. Thus, when the first PE device sends a packet to the second CE device, if the first path directly connecting the first PE device and the second CE device fails, the first PE device can switch the packet to the second path for transmission, so that the second PE device transmits the packet to the second CE device.
[0186] In an embodiment of the present invention, the second PE device is configured with a third SRv6 VPN SID different from the second SRv6 VPN SID, which enables the first PE device to establish a second path through the third SRv6 VPN SID, so that when the path directly connecting the first PE device and the second CE device fails for the packets transmitted by the first PE device to the second CE device, the packets can be switched to the second path for transmission, thereby realizing fast path switching, enabling the packets to be transmitted to the second CE device, and thus realizing multi-homing protection.
[0187] It should be noted that the first PE device can generate Fast Reroute (FRR) information by combining the third SRv6 VPN SID in the first VPN route and the route sent by the second CE device, and realize fast rerouting during the process of the first PE device transmitting packets.
[0188] In Figure 5 Based on the method shown above, an embodiment of the present invention may further include: the first PE device sends a second VPN route to the second PE device.
[0189] Among them, the second VPN route carries the first SRv6 VPN SID and the fourth SRv6 VPN SID. The fourth SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the first PE connecting to the second CE. The fourth SRv6 VPN SID is used by the second PE device to establish a third path from the second PE device to the first PE device. When the fourth path directly connecting the second PE device and the second CE device fails, the third path is used by the second PE device to transmit packets to the second CE device. The fourth SRv6 VPN SID is different from the first SRv6 VPN SID, and the first SRv6 VPN SID is the same as the second SRv6 VPN SID saved by the second PE device.
[0190] At the control plane, the first PE device also needs to send a VPN route, that is, the second VPN route, to the second PE device. The second VPN route includes the first SRv6 VPN SID and the fourth SRv6 VPN SID configured by the first PE device. The second VPN route can also be sent to the second PE device in a manner carried by an MP-BGP message, and the carried manner is the same as that of the first VPN route, which will not be elaborated here.
[0191] After the second PE device receives the second VPN route, if it determines that the first SRv6 VPN SID is the same as the second SRv6 VPN SID, it can determine that the first PE device is also connected to the second CE. Furthermore, it can be determined that the second CE device is multi-homed to connect the first PE device and the second PE device. Therefore, the second PE device can establish a third path from the second PE device to the first PE device through the fourth SRv6 VPN SID. Thus, when the second PE device sends a packet to the second CE device, if the fourth path directly connecting the second PE device and the second CE device fails, the second PE device can switch the packet to the third path for transmission, enabling the first PE device to transmit the packet to the second CE device, thereby achieving fast path switching.
[0192] In the embodiment of the present invention, at the control plane, the first PE device and the second PE device also need to send VPN routes to other PE devices (such as ingress PE devices). Taking the first PE device sending a VPN route to other PE devices as an example, the VPN route sent by the first PE device to other PE devices is the second VPN route, including the first SRv6 VPN SID and the fourth SRv6 VPN SID. After receiving the second VPN route, other PE devices can compare the first SRv6 VPN SID with the SRv6 VPN SID configured by themselves to determine whether they are the same. If they are the same, a path to the first PE device is established through the fourth SRv6 VPN SID; if they are different, a path to the first PE device is established through the first SRv6 VPN SID.
[0193] The second VPN route sent by the first PE device to other PE devices can also be sent in a manner carried by an MP-BGP message to other PE devices.
[0194] It should be noted that when other PE devices determine that the first SRv6 VPN SID is different from the SRv6 VPN SID configured by themselves, they can also establish a path to the first PE device through the fourth SRv6 VPN SID. However, when other PE devices transmit data to the first PE device, the first SRv6 VPN SID is usually used as the address of the first PE device, and the path established through the first SRv6 VPN SID is used for transmission, rather than the path established through the fourth SRv6 VPN SID.
[0195] In the embodiment of the present invention, at the control plane of the SRv6-based VPN, routes can also be published through the public network among devices, enabling P devices to exchange routing information with other devices.
[0196] In the embodiments of the present invention, through the process of exchanging routing information in the control plane, paths for transmitting data can be established between devices, and then data transmission can be carried out. In the embodiments of the present invention, at least two of the PE devices to which the CE device is multi-homed are respectively configured with escape SRv6 VPN SIDs. Paths can be established between at least two PE devices through the escape SRv6 VPN SIDs, and multi-homed path protection can be achieved. The following takes the process of the first PE device sending a first message to the second CE device as an example for explanation.
[0197] Another embodiment of the present invention provides a data transmission method for the data forwarding plane of the above SRv6-based VPN network, and specifically can be used for Figure 2 the data forwarding plane of the network architecture shown in Figure 7 as shown, and the method includes the following steps.
[0198] 401. The first PE device receives the first message.
[0199] Wherein, the first message is a message sent by the first CE device to the second CE device.
[0200] In the embodiments of the present invention, the first CE device sends the first message to the ingress PE device. At this time, the first message includes a source CE address and a destination CE address. The source CE address is the address of the first CE device, and the destination CE address is the address of the second CE device. After receiving the first message, the ingress PE device determines the path for transmitting the first message according to the destination CE address and the VRF corresponding to the first CE device. The ingress PE device sends the first message to the first PE device through the first P device. The first PE device receives the first message, and the outer destination address encapsulated in the first message is the first SRv6 VPN SID.
[0201] 402. The first PE device determines a first path for forwarding the first message according to the first SRv6 VPN SID.
[0202] Wherein, the first path is a path directly connecting the first PE device and the second CE device.
[0203] After receiving the first message, the first PE device can query the corresponding VRF table according to the first SRv6 VPN SID encapsulated in the first message, so as to determine the VPN identified by the first SRv6 VPN SID or the egress interface connected to the second CE device, and then can determine the first path for sending the first message to the second CE device.
[0204] The first PE device is directly connected to the second CE device. Therefore, usually, the first PE device determines a first path directly connecting the first PE device and the second CE device to transmit the first packet. So, after receiving the first packet, the first PE device can determine the first path directly connecting the first PE device and the second CE device.
[0205] 403. When the first PE device determines that the first path fails, the first PE device determines to forward the first packet through a second path according to the first SRv6 VPN SID and the third SRv6 VPN SID sent by the second PE device and saved.
[0206] Among them, the first PE device is connected to the second PE device through the second path.
[0207] When the first PE device determines the first path, it also detects whether the first path fails to avoid the situation where the first packet cannot be transmitted to the second CE device due to the failure of the first path.
[0208] If the first PE device detects that the first path fails, path switching is required. The path from the first PE device to the second CE device also includes a second path connecting the first PE device and the second PE device established based on the third SRv6 VPN SID of the second PE device. So at this time, the first PE device can switch the first packet to the second path from the first PE device to the second PE device, and forward the first packet to the second CE device through the second PE device.
[0209] 404. The first PE device forwards the first packet to the second CE through the second path.
[0210] In this step, after the first PE device switches the first packet to the second path for transmission, it determines that the next hop is the second PE device, and the address of the next hop is the third SRv6 VPN SID of the second PE device. So it can modify the outer destination address of the encapsulated first packet to the third SRv6 VPN SID, and send the encapsulated first packet to the second PE device through the outgoing interface connected to the second PE device. After receiving the encapsulated first packet, the second PE device de-encapsulates it and then sends the first packet to the second CE device.
[0211] In the embodiment of the present invention, the first PE device establishes a second path to the second PE device through the third SRv6 VPN SID, so that when the path directly connecting the first PE device and the second CE device for the packet transmitted by the first PE device fails, the packet can be switched to the second path for transmission, thereby realizing fast path switching and multi-homing path protection, and enabling the packet to be transmitted to the second CE device.
[0212] Figure 8 It is a schematic block diagram of a PE device 500 provided according to an embodiment of the present invention.
[0213] As the first PE device, the PE device 500 is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homedly connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are the first PE device and the second PE device. The first PE device is configured with a first SRv6 VPN SID, and the first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device is configured with a second SRv6 VPN SID and a third SRv6 VPN SID, and both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. Here, N is an integer greater than or equal to 2.
[0214] As Figure 8 shown, the PE device 500 may include:
[0215] A receiving unit 501, configured to receive a first VPN route sent by the second PE device, where the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID;
[0216] A processing unit 502, configured to determine that the second SRv6 VPN SID is the same as the first SRv6 VPN SID;
[0217] The processing unit 502 is further configured to establish a second path from the first PE device to the second PE device according to the third SRv6 VPN SID in the first VPN route. When a failure occurs in a first path directly connecting the first PE device and the second CE device, the first PE device uses the second path to forward packets to the second CE device.
[0218] In the embodiment of the present invention, the second SRv6 VPN SID is the same as the first SRv6 VPN SID. Therefore, the paths to the first SRv6 VPN SID include two paths that respectively reach the PE device 500 and the second PE device. Therefore, when transmitting the packet sent by the first CE device to the second CE device, if the fifth path to the PE device 500 fails, the sixth path to the second PE device can be determined. Furthermore, the packet can be switched to the sixth path and transmitted to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path. Instead, when a fault of the egress PE device is detected during the packet transmission process, the packet is transmitted through the path to the PE device with the same SRv6 VPN SID as the egress PE device, thereby achieving fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for fault detection when the PE device determines the path, and improving the speed of path switching. And the second PE device is configured with a third SRv6 VPN SID that is different from the first SRv6 VPN SID, which enables the PE device 500 to establish a second path through the third SRv6 VPN SID in the first VPN route, so that when the path directly connecting the PE device 500 and the second CE device for the packet transmitted by the PE device 500 fails, the packet can be switched to the second path for transmission, thereby achieving fast path switching and enabling the packet to be transmitted to the second CE device, thus achieving multi-homing protection.
[0219] Figure 9 It is a schematic block diagram of another PE device 500 according to an embodiment of the present invention.
[0220] It can be understood that as Figure 9 shown, the PE device 500 may further include:
[0221] A sending unit 503 is configured to send a second VPN route to the second PE device. The second VPN route carries the first SRv6 VPN SID and a fourth SRv6 VPN SID. The fourth SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface through which the first PE device connects to the second CE device. The second PE device uses the fourth SRv6 VPN SID to establish a third path from the second PE device to the first PE device. When a fourth path directly connecting the second PE device and the second CE device fails, the second PE device uses the third path to transmit packets to the second CE device. The fourth SRv6 VPN SID is different from the first SRv6 VPN SID, and the first SRv6 VPN SID is the same as the second SRv6 VPN SID stored in the second PE device.
[0222] It can be understood that the first VPN route is carried in the BGP-Prefix-SID attribute field of an MP-BGP message. The BGP-Prefix-SID attribute field includes an SRv6-VPN SID TLV field. The SRv6-VPN SID TLV field includes a T field, an L field, and a V field. The V field is used to carry the third SRv6 VPN SID.
[0223] It can be understood that the receiving unit 501 is further configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID.
[0224] The processing unit 502 is further configured to determine a failure of the first path.
[0225] The processing unit 502 is further configured to determine to forward the first packet through the second path according to the first SRv6 VPN SID and the third SRv6 VPN SID.
[0226] The PE device 500 according to an embodiment of the present invention can correspond to an execution entity in the method for processing routes according to an embodiment of the present invention. The above and other operations and / or functions of each module in the PE device 500 respectively implement Figure 3 the corresponding processes of each method executed by the first PE device in the illustrated embodiment. For the sake of brevity, details are not described herein again.
[0227] Figure 10 FIG. is a schematic block diagram of a PE device 600 according to another embodiment of the present invention.
[0228] The PE device 600, as the first PE device, is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homedly connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are the first PE device and the second PE device. The first PE device configures a first SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface of the first PE device connecting to the second CE device. The second PE device configures a second SRv6 VPN SID and a third SRv6 VPN SID, and both the second SRv6 VPN SID and the third SRv6 VPN SID are used to identify the VPN to which the second CE device belongs or the egress interface of the second PE device connecting to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID, where N is an integer greater than or equal to 2.
[0229] As Figure 10 shown, the PE device 600 may include:
[0230] A receiving unit 601, configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0231] A processing unit 602, configured to determine a first path for forwarding the first packet according to the first SRv6 VPN SID, where the first path is the path directly connecting the first PE device and the second CE device;
[0232] The processing unit 602 is further configured to determine that the first path fails. The first PE device determines to forward the first packet through a second path according to the first SRv6 VPN SID and the saved third SRv6 VPN SID sent by the second PE device, where the first PE device connects to the second PE device through the second path;
[0233] A sending unit 603, configured to forward the first packet to the second CE through the second path.
[0234] In the embodiment of the present invention, the second SRv6 VPN SID is the same as the first SRv6 VPN SID. Therefore, the paths to the first SRv6 VPN SID include two paths to the PE device 600 and the second PE device respectively. Therefore, when transmitting the packet sent by the first CE device to the second CE device, if the fifth path to the PE device 600 fails, the sixth path to the second PE device can be determined, and then the packet can be switched to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path, but when it detects that the egress PE device is faulty during the packet transmission process, it transmits the packet through the path to the PE device with the same SRv6 VPN SID as the egress PE device, so as to achieve fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for the PE device to detect faults when determining the path, and improving the speed of path switching. And when the PE device 600 transmits the first packet to the second CE device, the packet can be switched to the second path for transmission when the path directly connecting the PE device 600 and the second CE device fails, so as to achieve fast path switching, so that the packet can be transmitted to the second CE device, thereby achieving multi-homing protection.
[0235] It can be understood that the receiving unit 601 is further configured to receive a first VPN route sent by the second PE device, where the first VPN route includes the second SRv6 VPN SID and the third SRv6 VPN SID;
[0236] The processing unit 602 is further configured to, when determining that the second SRv6 VPN SID is the same as the first SRv6 VPN SID, establish the second path according to the third SRv6 VPN SID.
[0237] The PE device 600 according to the embodiment of the present invention can correspond to the execution subject in the data transmission method according to the embodiment of the present invention, and the above and other operations and / or functions of each module in the PE device 600 are respectively for implementing Figure 4 the corresponding processes of the respective methods executed by the first PE device in the illustrated embodiment. For the sake of brevity, they will not be described herein again.
[0238] Figure 11It is a schematic block diagram of a P device 700 provided according to an embodiment of the present invention.
[0239] As the first P device, the P device 700 is used in a network carrying SRv6-based VPN services. The network includes a first CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed and connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The at least one P device includes the first P device, and the first P device is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device, where N is an integer greater than or equal to 2.
[0240] As Figure 11 shown, the P device 700 may include:
[0241] A receiving unit 701, configured to receive a first route sent by the first PE device, where the first route includes the network segment to which the first SRv6 VPN SID belongs;
[0242] The receiving unit 701 is further configured to receive a second route sent by the second PE device, where the second route includes the network segment to which the second SRv6 VPN SID belongs;
[0243] A processing unit 702, configured to establish a fifth path from the first P device to the first PE device according to the network segment to which the first SRv6 VPN SID belongs, and the fifth path is used by the first P device to forward packets to the second CE device;
[0244] The processing unit 702 is further configured to establish a sixth path from the first P device to the second PE device according to the network segment to which the second SRv6 VPN SID belongs, and the sixth path is used by the first P device to forward packets to the second CE device when the fifth path fails.
[0245] In the embodiment of the present invention, the second SRv6 VPN SID is the same as the first SRv6 VPN SID, and the network segment to which the second SRv6 VPN SID belongs is also the same as the network segment to which the first SRv6 VPN SID belongs. Therefore, the paths for the P device 700 to reach the first SRv6 VPN SID include two paths to the first PE device and the second PE device respectively. Therefore, when the P device 700 transmits the packets sent by the first CE device to the second CE device, if the fifth path to the first PE fails, the P device 700 can determine the sixth path to the second PE device, and then can switch the packets to the sixth path for transmission to the second PE device, so that the second PE device can send the packets to the second CE device. In this way, when the first CE device sends packets to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path, but when it detects that the egress PE device is faulty during the packet transmission process, it transmits the packets through the path to the PE device with the same SRv6 VPN SID as the egress PE device, so as to achieve fast path switching. Therefore, there is no need to deploy BFD between the PE devices that establish the paths to detect faults, that is, there is no need to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE devices, reducing the resources occupied by BFD in the PE devices, and reducing the time for the PE devices to detect faults when determining paths, and improving the speed of path switching.
[0246] It can be understood that the receiving unit 701 is further configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0247] The processing unit 702 is further configured to, when the fifth path fails, determine to forward the first packet through the sixth path according to the first SRv6 VPN SID.
[0248] The P device 700 according to the embodiment of the present invention can correspond to the execution subject in the method for processing routes according to the embodiment of the present invention, and the above and other operations and / or functions of each module in the P device 700 are respectively for implementing Figure 5 the corresponding processes of the respective methods executed by the first P device in the illustrated embodiments. For the sake of brevity, they are not described herein again.
[0249] Figure 12 It is a schematic block diagram of a P device 800 provided according to another embodiment of the present invention.
[0250] The P device 800, as the first P device, is used in a network carrying SRv6-based VPN services. The SRv6-based VPN includes a first customer edge CE device, a second CE device, an ingress PE device, N egress PE devices, and at least one P device. The first CE device is connected to the ingress PE device, the second CE device is multi-homed and connected to the N egress PE devices, the ingress PE device is communicatively connected to the N egress PE devices through the at least one P device. The first CE device and the second CE device belong to the same VPN. Among the N egress PE devices, there are a first PE device and a second PE device. The first PE device configures a first SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the first PE device connects to the second CE device. The second PE device configures a second SRv6 VPN SID, which is used to identify the VPN to which the second CE device belongs or the egress interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID. The at least one P device includes the first P device, and the first P device is a neighbor node of the first PE device, and the first PE device is the next hop of the first P device. Here, N is an integer greater than or equal to 2.
[0251] As Figure 12 shown, the P device 800 may include:
[0252] A receiving unit 801, configured to receive a first packet, where the first packet is a packet sent by the first CE device to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID;
[0253] A processing unit 802, configured to determine a fifth path for transmitting the first packet according to the first SRv6 VPN SID, and the first P device is connected to the first PE device through the fifth path;
[0254] The processing unit 802 is further configured to determine that the fifth path fails, and the first P device determines to forward the first packet through the sixth path according to the first SRv6 VPN SID, and the first P device connects to the second PE through the sixth path;
[0255] The sending unit 803 is configured to forward the first packet to the second CE device through the sixth path.
[0256] In the embodiment of the present invention, the second SRv6 VPN SID is the same as the first SRv6 VPN SID. Therefore, the paths for the P device 800 to reach the first SRv6 VPN SID include two paths to the first PE device and the second PE device respectively. Therefore, when the P device 800 transmits the packet sent by the first CE device to the second CE device, if the fifth path to the first PE fails, the P device 800 can determine the sixth path to the second PE device, and then can switch the packet to the sixth path for transmission to the second PE device, so that the second PE device can send the packet to the second CE device. In this way, when the first CE device sends a packet to the second CE device, the ingress PE device does not need to detect whether the egress PE device in the path is faulty during the process of determining the packet transmission path, but when it detects that the egress PE device is faulty during the packet transmission process, it transmits the packet through the path to the PE device with the same SRv6 VPN SID as the egress PE device, so as to achieve fast path switching. Therefore, it is not necessary to deploy BFD between the PE devices that establish the path to detect faults, that is, it is not necessary to deploy BFD between the ingress PE device and the egress PE device to detect faults, thereby reducing the number of BFDs deployed in the PE device, reducing the resources occupied by BFD in the PE device, and reducing the time for the PE device to detect faults when determining the path, and improving the speed of path switching.
[0257] It can be understood that the receiving unit 801 is further configured to receive a first route sent by the first PE device, and the first route includes the network segment to which the first SRv6 VPN SID belongs;
[0258] The receiving unit 801 is further configured to receive a second route sent by the second PE device, and the second route includes the network segment to which the second SRv6 VPN SID belongs;
[0259] The processing unit 802 is further configured to establish the fifth path according to the network segment to which the first SRv6 VPN SID belongs, and establish the sixth path according to the network segment to which the second SRv6 VPN SID belongs. The sixth path is used for the first P device to forward packets to the second CE device when the fifth path fails.
[0260] The P device 800 according to an embodiment of the present invention may correspond to an execution subject in the method for data transmission according to an embodiment of the present invention, and the above and other operations and / or functions of each module in the P device 800 are respectively for implementing Figure 7 the corresponding processes of each method executed by the first PE device in the illustrated embodiment. For the sake of brevity, they will not be described herein again.
[0261] Figure 13 FIG. is a schematic structural diagram of another PE device 900 provided by an embodiment of the present invention. As Figure 13 shown, the PE device 900 includes a processor 901, a memory 902, and a communication interface 903.
[0262] The processor 901 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor 301 may further include a hardware chip. The above hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0263] The memory 902 may be an independent device or integrated in the processor 901. The memory 902 may include a volatile memory, such as a random-access memory (RAM); the memory may also include a non-volatile memory, such as a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the memory 902 may further include a combination of the above types of memories.
[0264] The communication interface 903 is used to communicate with external devices, and the communication interface 903 may be a wireless interface or a wired interface. Among them, the wireless interface may be a cellular mobile network interface, a wireless local area network interface, etc. The wired interface may be an Ethernet interface, such as an optical interface or an electrical interface.
[0265] The PE device 900 may further include a bus 904, which is used to connect the processor 901, the memory 902, and the communication interface 903, enabling the processor 901, the memory 902, and the communication interface 903 to communicate with each other through the bus 904. The bus 904 may be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity in representation, Figure 13 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0266] The PE device 900 is used to implement the corresponding processes executed by the first PE device in the method for processing routing shown in the embodiments of the present invention. For the sake of brevity, it will not be elaborated here. Figure 3 For the sake of brevity, it will not be elaborated here.
[0267] Optionally, the memory 902 may also be used to store program instructions. The processor 901 may call the program instructions stored in the memory 902 to execute Figure 3 one or more steps in the method shown in the figure, or optional implementation manners thereof.
[0268] The processor 901 is used to execute Figure 8 or Figure 9 all operations of the processing unit 502 of the PE device 500 as described above. The communication interface 903 may be used to execute Figure 8 or Figure 9 all operations of the receiving unit 501 of the PE device 500 and Figure 9 the sending unit 503 as shown in the figure.
[0269] Figure 14 FIG. is a schematic structural diagram of another PE device 1000 provided by the embodiments of the present invention. As Figure 14 shown in the figure, the PE device 1000 includes a processor 1001, a memory 1002, and a communication interface 1003.
[0270] The processor 1001 may be a CPU, a network processor, or a combination of a CPU and an NP. The processor 1001 may further include a hardware chip. The above-mentioned hardware chip may be an ASIC, a PLD, or a combination thereof. The above-mentioned PLD may be a CPLD, an FPGA, a general array logic, or any combination thereof.
[0271] The memory 1002 may be an independent device or integrated in the processor 1001. The memory 1002 may include volatile memory, such as RAM; the memory may also include non-volatile memory, such as flash memory, a hard disk, or a solid-state drive; the memory 1002 may further include a combination of the above types of memory.
[0272] The communication interface 1003 is used for communicating with external devices, and the communication interface 1003 can be a wireless interface or a wired interface. Among them, the wireless interface can be a cellular mobile network interface, a wireless local area network interface, etc. The wired interface can be an Ethernet interface, such as an optical interface or an electrical interface.
[0273] The PE device 1000 may further include a bus 1004, and the bus 1004 is used to connect the processor 1001, the memory 1002 and the communication interface 1003, so that the processor 1001, the memory 1002 and the communication interface 1003 communicate with each other through the bus 1004. The bus 1004 can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 14 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0274] The PE device 1000 is used to implement the corresponding processes executed by the first PE device in the data transmission method shown in the embodiments of the present invention. For the sake of brevity, it will not be elaborated here. Figure 4 shown.
[0275] Optionally, the memory 1002 can also be used to store program instructions, and the processor 1001 can execute Figure 4 one or more steps in the method shown, or optional embodiments thereof.
[0276] The processor 1001 is used to execute Figure 10 all operations of the processing unit 602 of the PE device 600, and the communication interface 1003 can be used to execute Figure 10 all operations of the receiving unit 601 and the sending unit 603 of the PE device 600.
[0277] Figure 15 This is a schematic structural diagram of another P device 1100 provided by the embodiments of the present invention. As Figure 15 shown, the P device 1100 includes a processor 1101, a memory 1102 and a communication interface 1103.
[0278] The processor 1101 can be a CPU, a network processor, or a combination of a CPU and an NP. The processor 1001 can further include a hardware chip. The above hardware chip can be an ASIC, a PLD or a combination thereof. The above PLD can be a CPLD, an FPGA, a GAL or any combination thereof.
[0279] The memory 1102 can be an independent device or integrated in the processor 1101. The memory 1102 can include volatile memory, such as RAM; the memory can also include non-volatile memory, such as flash memory, hard disk or solid state drive; the memory 1102 can also include a combination of the above types of memory.
[0280] The communication interface 1103 is used to communicate with external devices. The communication interface 1103 can be a wireless interface or a wired interface. Among them, the wireless interface can be a cellular mobile network interface, a wireless local area network interface, etc. The wired interface can be an Ethernet interface, such as an optical interface or an electrical interface.
[0281] The P device 1100 can also include a bus 1104. The bus 1104 is used to connect the processor 1101, the memory 1102 and the communication interface 1103, so that the processor 1101, the memory 1102 and the communication interface 1103 communicate with each other through the bus 1104. The bus 1104 can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 15 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.
[0282] The P device 1100 is used to implement the corresponding processes executed by the first P device in the method for processing routing shown in the embodiments of the present invention. For the sake of brevity, it will not be elaborated here. Figure 5 The P device 1100 is used to implement the corresponding processes executed by the first P device in the method for processing routing shown in the embodiments of the present invention. For the sake of brevity, it will not be elaborated here.
[0283] Optionally, the memory 1102 can also be used to store program instructions. The processor 1101 calls the program instructions stored in the memory 1102 and can execute Figure 5 one or more steps in the method shown in the figure, or optional implementation manners thereof.
[0284] The processor 1101 is used to execute Figure 11 all operations of the processing unit 702 of the P device 700. The communication interface 1103 can be used to execute Figure 11 all operations of the receiving unit 701 of the P device 700.
[0285] Figure 16 is a schematic structural diagram of another P device 1200 provided by the embodiments of the present invention. As Figure 16 shown, the P device 1200 includes a processor 1201, a memory 1202 and a communication interface 1203.
[0286] The processor 1201 can be a CPU, a network processor, or a combination of a CPU and an NP. The processor 1001 can further include a hardware chip. The above-mentioned hardware chip can be an ASIC, a PLD, or a combination thereof. The above-mentioned PLD can be a CPLD, a field programmable gate array FPGA, a generic array logic, or any combination thereof.
[0287] The memory 1202 can be an independent device or integrated in the processor 1101. The memory 1102 can include volatile memory, such as random access memory RAM; the memory can also include non-volatile memory, such as flash memory, a hard disk, or a solid-state drive; the memory 1202 can also include a combination of the above types of memory.
[0288] The communication interface 1203 is used to communicate with external devices. The communication interface 1203 can be a wireless interface or a wired interface. Among them, the wireless interface can be a cellular mobile network interface, a wireless local area network interface, etc. The wired interface can be an Ethernet interface, such as an optical interface or an electrical interface.
[0289] The P device 1200 can also include a bus 1204. The bus 1204 is used to connect the processor 1201, the memory 1202, and the communication interface 1203, enabling the processor 1201, the memory 1202, and the communication interface 1203 to communicate with each other through the bus 1204. The bus 1204 can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 16 only a thick line is used to represent it here, but it does not mean that there is only one bus or one type of bus.
[0290] The P device 1200 is used to implement the corresponding processes executed by the first P device in the method for processing routing shown in the embodiments of the present invention. For the sake of brevity, it will not be elaborated here. Figure 7 shown in the method for processing routing shown in the embodiments of the present invention. For the sake of brevity, it will not be elaborated here.
[0291] Optionally, the memory 1202 can also be used to store program instructions. The processor 1201 can call the program instructions stored in the memory 1202 and execute Figure 7 one or more steps in the method shown, or optional implementation manners thereof.
[0292] The processor 1201 is used to execute Figure 12 all operations of the processing unit 802 of the P device 800 described above. The communication interface 1203 can be used to execute Figure 12 all operations of the receiving unit 801 and the sending unit 803 of the P device 800 described above.
[0293] Embodiments of the present invention also provide a communication system, including the PE device 500 as described in Figure 8 or 9 and as described inFigure 11 The described P device 700.
[0294] An embodiment of the present invention also provides another communication system, including the Figure 8 PE device 500 as described in Figure 12 or 9 and the
[0295] P device 700 as described. Figure 10 Figure 11 Another embodiment of the present invention also provides another communication system, including the
[0296] PE device 600 as described in Figure 10 and the Figure 12 P device 800 as described.
[0297] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc.
[0298] It should be understood that those skilled in the art can, on the basis of reading the present application documents, make non-creative combinations of the optional features, steps, or methods described in the embodiments of the present application, which all belong to the embodiments disclosed in the present application, but are not repeated here due to the simplicity of description or writing.
[0299] It should be understood that in various embodiments of the present invention, the magnitudes of the serial numbers of the above processes do not imply the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0300] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0301] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0302] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0303] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0304] In addition, the functional units in various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
Claims
1. A method for establishing a path, characterized in that, This method is used in a network carrying SRv6-based VPN services based on the sixth version of Internet Protocol Segment Routing. The network includes a second Customer Edge (CE) device. The second CE device is multi-homed to connect to a first Provider Edge (PE) device and a second PE device. The first PE device configures a first SRv6 VPN Segment Identifier (SID). The first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the first PE device connecting to the second CE device. This method is executed by the first PE device connecting to the second Customer Edge CE device. The method includes: The first PE device determines a first path for forwarding the first packet according to the first SRv6 VPN SID. Among them, the first path is the path directly connecting the first PE device and the second CE device; Receive a first VPN route sent by the second PE device. The first VPN route carries a first SRv6 VPN SID configured by the second PE device for the virtual private network segment of the first escape sixth version of Internet Protocol Segment Routing. The first escape SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the second PE device connecting to the second CE device; Based on the first escape SRv6 VPN SID, establish a second path from the first PE device to the second PE device. Among them, when the first path fails, the first PE device uses the second path to forward packets to the second CE device.
2. The method according to claim 1, characterized in that, The method further includes: publishing a second VPN route to the second PE device. The second VPN route carries a second escape SRv6 VPN SID. The second PE device uses the second escape SRv6 VPN SID to establish a third path from the second PE device to the first PE device. When a fourth path directly connecting the second PE device and the second CE device fails, the second PE device uses the third path to transmit packets to the second CE device.
3. The method according to claim 1 or 2, characterized in that, The first SRv6 VPN SID is carried in the first SRv6-VPN SID TLV field. The first SRv6-VPN SID TLV field includes a type T field, a length L field, and a value V field. The V field is used to carry the first escape SRv6 VPN SID.
4. The method according to claim 1 or 2, characterized in that, The method further includes: Receive a first packet sent to the second CE device; When the first path fails, forward the first packet encapsulated with the first escape SRv6 VPN SID through the second path.
5. A method for data transmission, characterized in that, This method is used in a network carrying SRv6-based VPN services based on Internet Protocol Segment Routing version 6. The network includes a second Customer Edge (CE) device. The second CE device is multi-homed to connect to a first Provider Edge (PE) device and a second PE device. The first PE device configures a first SRv6 VPN Segment Identifier (SID). The first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the first PE device connecting to the second CE device. The second PE device configures a first escape SRv6 VPN SID. The first escape SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the second PE device connecting to the second CE device. The method includes: The first PE device receives a first packet destined for the second CE device. The outer destination address of the first packet is the first SRv6 VPN SID. The first PE device determines a first path for forwarding the first packet according to the first SRv6 VPN SID. Among them, the first path is the path directly connecting the first PE device and the second CE device. The first PE device determines that the first path fails. The first PE device re-encapsulates the first packet using the first escape SRv6 VPN SID as the outer destination address. The first PE device forwards the first packet with the outer destination address being the first escape SRv6 VPN SID through a second path. Among them, the first PE device connects to the second PE device through the second path.
6. The method according to claim 5, wherein Before the first PE device receives the first packet, the method further includes: The first PE device receives a first VPN route sent by the second PE device. The first VPN route includes the first escape SRv6 VPN SID. The first PE device establishes the second path according to the first escape SRv6 VPN SID.
7. A method for establishing a path, characterized in that, This method is used in a network carrying SRv6-based VPN services based on Internet Protocol Segment Routing version 6. The network includes a first Provider (P) device, a first Provider Edge (PE) device and a second PE device. The method includes: The first P device receives a first route sent by the first PE device. The first route includes the network segment to which the first SRv6 VPN SID belongs. The first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface of the first PE connecting to the second CE device. Among them, the second CE device is multi-homed to connect to the first PE device and the second PE device. The first P device receives a second route sent by the second PE device. The second route includes the network segment to which the second SRv6 VPN SID belongs. The second PE device configures the second SRv6 VPN SID, and the second SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID; The first P device establishes a fifth path from the first P device to the first PE device according to the network segment to which the first SRv6 VPN SID belongs, for forwarding packets to the second CE device; The first P device establishes a sixth path from the first P device to the second PE device according to the network segment to which the second SRv6 VPN SID belongs, for forwarding packets to the second CE device.
8. The method according to claim 7, wherein The method further includes: The first P device receives a first packet sent to the second CE device, and the outer destination address encapsulated in the first packet is the first SRv6 VPN SID; The first P device determines that the fifth path fails; The first P device forwards the first packet through the sixth path.
9. A method for data transmission, characterized in that, This method is used in a network carrying SRv6-based VPN services based on Internet Protocol Segment Routing version 6. The network includes a first carrier P device, a first carrier edge PE device, and a second PE device. The method includes: The first P device receives a first packet sent to the second CE device. The outer destination address encapsulated in the first packet is the first SRv6 VPN SID. The first SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface through which the first PE connects to the second CE device. Among them, the second CE device is multi-homed to access the first PE device and the second PE device. The second PE device is configured with a second SRv6 VPN SID, and the second SRv6 VPN SID is used to identify the VPN to which the second CE device belongs or the outgoing interface through which the second PE device connects to the second CE device. The first SRv6 VPN SID is the same as the second SRv6 VPN SID; The first P device determines a fifth path for transmitting the first packet according to the first SRv6 VPN SID, and the first P device connects to the first PE device through the fifth path; The first P device determines that the fifth path fails. The first P device determines to forward the first packet through the sixth path according to the second SRv6 VPN SID, and the first P device connects to the second PE through the sixth path; The first P device forwards the first packet to the second CE device through the sixth path.
10. The method according to claim 9, wherein Before the first P device receives the first packet, the method further includes: The first P device receives a first route sent by the first PE device, and the first route includes the network segment to which the first SRv6 VPN SID belongs; The first P device receives a second route sent by the second PE device, and the second route includes the network segment to which the second SRv6 VPN SID belongs; The first P device establishes the fifth path according to the network segment to which the first SRv6 VPN SID belongs; The first P device establishes the sixth path according to the network segment to which the second SRv6 VPN SID belongs.
11. An operator edge PE device, characterized in that, The PE device, as the first PE device, includes: A memory storing instructions; A processor connected to the memory, and when the processor executes the instructions, the first PE device executes the method according to any one of claims 1-6.
12. An operator P device, characterized in that, The P device, as the first P device, includes: A memory storing instructions; A processor connected to the memory, and when the processor executes the instructions, the first P device executes the method according to any one of claims 7-10.
13. A computer storage medium, characterized in that, It includes computer-readable instructions, and when executed by a computer, the computer executes the method according to any one of claims 1-10.
14. A communication system, characterized in that, It includes the PE device according to claim 11 and the P device according to claim 12.
Citation Information
Patent Citations
Method, controller, forwarding device, and network system for forwarding packets
CN105594167A
Distribution of segment identifiers in network functions virtualization and software defined network environments
US20170054626A1