Route introduction method, device and system

By using ERT and IRT matching and attribute information in the EVPN network, the routing information introduction and isolation between VPN instances is achieved, and the complexity and security problems of routing interoperability in the prior art are solved, simplified configuration and ensured the stability of VM communication.

CN114070778BActive Publication Date: 2025-08-29HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010785452.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-06
Publication Date
2025-08-29
Estimated Expiration
2040-08-06

AI Technical Summary

Technical Problem

In the prior art, the routing interoperability between local VPN instances and remote VPN instances cannot be achieved in the local crossover scenario in the EVPN network. The configuration in the remote crossover scenario is complex and can easily lead to loops and faults spread, affecting VM communication and service security.

Method used

The first network device introduces the routing information of the VPN instance of the second network device locally, and realizes interoperability between different VPN instances in a local crossover mode, avoids configuring a large number of paired ERTs and IRTs in the network device, and uses ERT and IRT matching and attribute information to introduce and isolate the routing information.

Benefits of technology

It simplifies business logic and configuration, ensures effective isolation between VPN instances, avoids loops and fault spread, and realizes normal VM communication under different network devices, with a wide range of application scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114070778B_ABST
    Figure CN114070778B_ABST
Patent Text Reader

Abstract

The present application provides a routing introduction method, device and system, which belong to the field of network technology. After the first network device introduces the routing information of the first VPN instance in the second network device from the first VPN instance to the second VPN instance in the first network device, the routing information of the first VPN instance is introduced from the second VPN instance to the third VPN instance in the first network device, rather than introducing the routing information of the first VPN instance from the first VPN instance to the second VPN instance and the third VPN instance respectively. Therefore, it is not necessary to configure a large number of paired ERTs and IRTs in the first network device and the second network device to achieve mutual access between a large number of VPN instances between the first network device and the second network device, which helps to simplify business logic and configuration, ensure business security, avoid loops and fault propagation, and achieve normal communication between virtual machines mounted on different network devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network technology, and in particular to a route introduction method, device, and system. Background Art

[0002] The provider edge (PE) device in an Ethernet virtual private network (EVPN) network is configured with at least one virtual private network (VPN) instance. Each VPN instance corresponds to at least one virtual machine (VM) connected to the PE device. Each VPN instance is used to forward VM messages, enabling communication between different VMs.

[0003] When VMs in two different VPN instances need to communicate, they can import routes from one VPN instance into the other VPN instance through route crossover, enabling intercommunication between the two VPN instances. VPN instances are configured with an import route target (IRT) and an export route target (ERT). Route crossover involves importing routes from one VPN instance into the other VPN instance by matching the ERT with the IRT. Depending on the source of the routes, route crossover is categorized as local crossover and remote crossover. As an example of local crossover, a PE device matches the ERT in a local VPN instance with the IRT in another local VPN instance. If the ERT in the VPN instance matches the IRT in another VPN instance, the Border Gateway Protocol (BGP) route (BGP-based route) of the VPN instance containing the ERT is written into the routing table of the matching VPN instance, importing the BGP route into the matching VPN instance. As an example of remote crossing: After the PE device learns the BGP EVPN route (referring to the route based on the BGP EVPN protocol, which is an extended protocol of BGP) of the VPN instance in the remote PE device from the remote PE device, the ERT carried in the BGP EVPN route is matched with the IRT in the VPN instance in the PE device. If the ERT carried in the BGP EVPN route can match the IRT in a local VPN instance of the PE device, the BGP EVPN route is converted into a BGP route, and the BGP route is written into the routing table of the matching VPN instance to introduce the BGP EVPN route into the matching VPN instance.

[0004] However, in local cross-connect scenarios, existing mechanisms cannot achieve routing interoperability between local VPN instances and remote VPN instances (referring to VPN instances in remote PEs), affecting normal communication between VMs mounted on different PE devices, resulting in limited application scenarios for routing introduction. In remote cross-connect scenarios, to achieve interoperability between a large number of VPN instances across multiple PE devices, a large number of paired ERTs and IRTs must be configured on these multiple PE devices, resulting in complex business logic and configuration, easily destroying the effective isolation between VPN instances, failing to ensure business security, and increasing the possibility of loops and fault propagation. Summary of the Invention

[0005] This application provides a method, device, and system for introducing routes, which helps simplify service logic and configuration, ensure service security, avoid loops and fault propagation, and has a wide range of application scenarios. The technical solutions of this application are as follows:

[0006] In a first aspect, a route import method is provided, comprising: a first network device importing routing information of a first VPN instance in a second network device from the first VPN instance into a second VPN instance in the first network device, wherein the routing information of the first VPN instance corresponds to a first ERT in the first VPN instance, and the first ERT matches an IRT in the second VPN instance; and the first network device importing the routing information of the first VPN instance from the second VPN instance into a third VPN instance in the first network device. The routing information of the first VPN instance may be information from one or more routes belonging to the first VPN instance. That is, when the one or more routes in the first VPN instance of the second network device are imported into the second VPN instance of the first network device, the routing information of the first VPN instance is also imported into the second VPN instance. The routing information is related information of the one or more routes.

[0007] The technical solution provided by the present application first introduces the routing information in the VPN instance of the second network device into the first network device, and then the first network device communicates the routing information between different VPN instances of the first network device in a local cross-link manner. Without configuring a large number of paired ERTs and IRTs in the first network device and the second network device, mutual access of a large number of VPN instances between the first network device and the second network device can be achieved, which helps to simplify business logic and configuration, and can ensure effective isolation between different VPN instances to ensure business security, avoid loops and fault propagation, and can achieve normal communication between VMs under different network devices. The application scenarios of route introduction are wide.

[0008] Optionally, the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, including: the first network device determining a second ERT in the second VPN instance, the second ERT corresponding to the routing information of the first VPN instance in the second VPN instance; and the first network device importing the routing information of the first VPN instance from the second VPN instance to the third VPN instance based on matching the second ERT with the IRT in the third VPN instance. The routing information of the first VPN instance in the second VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the second VPN instance, and the routing information of the first VPN instance in the second VPN instance is obtained by importing the routing information of the first VPN instance in the first VPN instance.

[0009] The technical solution provided by this application is that the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance by matching ERT with IRT, which helps to improve the accuracy of route introduction. Introducing routes by matching ERT with IRT is also called introducing routes by route crossing. Since the second VPN instance and the third VPN instance are both located in the first network device, the routing information of the first VPN instance is imported from the second VPN instance to the third VPN instance by route crossing, that is, the routing information of the first VPN instance is imported from the second VPN instance to the third VPN instance by local crossing.

[0010] Optionally, the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, including: the first network device determining, based on the acquired attribute information, routing information in the second VPN instance that matches the attribute information, where the routing information in the second VPN instance that matches the attribute information includes the routing information of the first VPN instance in the second VPN instance; and the first network device importing the routing information in the second VPN instance that matches the attribute information from the second VPN instance to the third VPN instance. Because the routing information in the second VPN instance that matches the attribute information includes the routing information of the first VPN instance in the second VPN instance, importing the routing information in the second VPN instance that matches the attribute information from the second VPN instance to the third VPN instance can implement importing the routing information of the first VPN instance in the second VPN instance from the second VPN instance to the third VPN instance.

[0011] The technical solution provided in the present application is that the first network device introduces the routing information of the first VPN instance from the second VPN instance to the third VPN instance through attribute matching. Therefore, the routing information of the first VPN instance can be introduced from the second VPN instance to the third VPN instance without configuring paired ERT and IRT in the second VPN instance and the third VPN instance, thereby achieving routing intercommunication between the first VPN instance and the third VPN instance, which helps to simplify service configuration.

[0012] Optionally, the attribute information includes a route type and an identifier of the second VPN instance; and the first network device determines, based on the acquired attribute information, routing information in the second VPN instance that matches the attribute information, including: the first network device determines, based on the route type and the identifier of the second VPN instance, routing information in the second VPN instance that matches the attribute information, including one or more routes of the route type in the second VPN instance, where the one or more routes include routing information of the first VPN instance. The route type may be, for example, a BGP route, a static route, or the like.

[0013] In the technical solution provided by the present application, a first network device determines routing information matching attribute information in the second VPN instance based on the routing type and the identifier of the second VPN instance, thereby facilitating the first network device to introduce routing information matching the attribute information in the second VPN instance from the second VPN instance into the third VPN instance.

[0014] Optionally, before the first network device imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance, the method further includes: the first network device allowing the routing information of the first VPN instance to be imported from the second VPN instance into the third VPN instance according to the acquired instruction.

[0015] The technical solution provided by the present application allows the first network device to introduce the routing information of the first VPN instance from the second VPN instance to the third VPN instance according to the obtained instructions, which helps to improve the security of route introduction and ensure route isolation between VPN instances that do not need to perform route mutual introduction, thereby ensuring business security.

[0016] Optionally, after the first network device imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance, the method further includes: the first network device adding an import tag corresponding to the routing information of the first VPN instance to the third VPN instance, the import tag being used to indicate that the routing information of the first VPN instance in the third VPN instance is imported from a local VPN instance of the first network device. The routing table of the third VPN instance may include an import field, and the first network device may add the import tag to the import field.

[0017] The technical solution provided by the present application is that the first network device adds an introduction tag corresponding to the routing information of the first VPN instance in the third VPN instance, which can facilitate the first network device to distinguish the routing information imported from the local VPN instance in the third VPN instance from other routing information in the third VPN instance.

[0018] Optionally, after the first network device adds an import tag corresponding to the routing information of the first VPN instance to the third VPN instance, the method further includes: the first network device determining, based on the import tag in the third VPN instance, not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device. The routing information of the first VPN instance in the third VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the third VPN instance.

[0019] In the technical solution provided by the present application, since the introduction tag is used to indicate that the routing information of the first VPN instance in the third VPN instance is introduced from the local VPN instance of the first network device, the first network device determines, based on the introduction tag in the third VPN instance, not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device. This prevents the routing information introduced from the second VPN instance to the third VPN instance from being introduced back to the second VPN instance, thereby avoiding routing loops and preventing excessive storage of identical routing information in the same VPN instance.

[0020] Optionally, after the first network device imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance, the method further includes: the first network device determining a third ERT in the third VPN instance, the third ERT corresponding to the routing information of the first VPN instance in the third VPN instance; and the first network device determining not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device based on the mismatch between the third ERT and the IRT in the local VPN instance of the first network device. The routing information of the first VPN instance in the third VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the third VPN instance.

[0021] The technical solution provided by this application determines that the first network device will not import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device because the third ERT corresponds to the routing information of the first VPN instance in the third VPN instance and the third ERT does not match the IRT in the local VPN instance of the first network device. By setting a third ERT that does not match the IRT in the local VPN instance of the first network device, routing information imported from the second VPN instance to the third VPN instance can be prevented from being imported back to the second VPN instance, thereby avoiding routing loops and excessive storage of identical routing information in the same VPN instance.

[0022] Optionally, after the first network device introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance, the method further includes: the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance, the routing information of the first VPN instance in the third VPN instance corresponds to a third ERT in the third VPN instance, and the third ERT is used to instruct the third network device to introduce the routing information of the first VPN instance from the third VPN instance into a fourth VPN instance in the third network device.

[0023] The technical solution provided in this application is that the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance, which can facilitate the third network device to introduce the routing information of the first VPN instance from the third VPN instance to the fourth VPN instance in the third network device, thereby realizing routing interconnection between the first VPN instance and the fourth VPN instance.

[0024] Optionally, the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance, including: the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance based on the first network device having an external publishing function. The external publishing function may be configured in the first network device by an operation and maintenance personnel, or configured in the first network device by a management device of the first network device. The first network device having an external publishing function means that all VPN instances in the first network device have an external publishing function. Alternatively, some VPN instances in the first network device may be configured to have an external publishing function, while other VPN instances may not have an external publishing function. For example, at least the third VPN instance in the first network device may be configured to have an external publishing function.

[0025] The technical solution provided in the present application is that the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device based on the first network device's external publishing function, which helps to ensure the security of the routing information of the first VPN instance and facilitates the first network device to control the extraction of routing information.

[0026] Optionally, both the first network device and the second network device are PE devices.

[0027] In a second aspect, a route importing method is provided, the method comprising: a first network device importing routing information of a first VPN instance in the first network device from the first VPN instance to a second VPN instance in the first network device; the first network device sending the routing information of the first VPN instance in the second VPN instance to a second network device via the second VPN instance, wherein the routing information of the first VPN instance in the second VPN instance corresponds to a first ERT in the second VPN instance, and the first ERT is used to instruct the second network device to import the routing information of the first VPN instance from the second VPN instance to a third VPN instance in the second network device. The routing information of the first VPN instance is information in the routes of the first VPN instance, and the routing information of the first VPN instance includes one or more pieces of information in the routes of the first VPN instance belonging to the first VPN instance.

[0028] The technical solution provided in this application allows the routing information after local cross-linking of the first network device to be introduced into the second network device, thereby enabling mutual access of a large number of VPN instances between the first network device and the second network device, helping to simplify business logic and configuration, and enabling normal communication of VMs under different network devices. The application scenarios of route introduction are wide.

[0029] Optionally, the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, including: the first network device importing the routing information of the first VPN instance from the first VPN instance to the second VPN instance based on a matching between the second ERT in the first VPN instance and the IRT in the second VPN instance, wherein the second ERT corresponds to the routing information of the first VPN instance in the first VPN instance; or the first network device determining, based on the acquired attribute information, routing information in the first VPN instance that matches the attribute information, importing the routing information in the first VPN instance that matches the attribute information from the first VPN instance to the second VPN instance, wherein the routing information in the first VPN instance that matches the attribute information includes the routing information of the first VPN instance in the first VPN instance. The routing type may be, for example, BGP routing, static routing, or the like.

[0030] The technical solution provided by this application enables a first network device to import routing information of a first VPN instance from a second VPN instance to a third VPN instance by matching ERT and IRT, thereby improving the accuracy of route import. Furthermore, the first network device imports routing information of a first VPN instance from a second VPN instance to a third VPN instance by matching attributes. This allows importing routing information of the first VPN instance from the second VPN instance to the third VPN instance without configuring paired ERT and IRT on the second and third VPN instances, thereby simplifying service configuration.

[0031] Optionally, the routing information of the first VPN instance is generated by the first VPN instance in the first network device; or, the routing information of the first VPN instance is learned by the first VPN instance in the first network device from a BGP neighbor of the first network device; or, the routing information of the first VPN instance is imported by the first VPN instance in the first network device from a fourth VPN instance among the BGP EVPN neighbors of the first network device. This can increase the diversity of imported routes.

[0032] Optionally, before the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the method further includes: the first network device allowing the routing information of the first VPN instance to be imported from the first VPN instance to the second VPN instance according to the acquired instruction.

[0033] The technical solution provided by the present application allows the first network device to introduce the routing information of the first VPN instance from the first VPN instance to the second VPN instance according to the obtained instructions, which helps to improve the security of route introduction and ensure route isolation between VPN instances that do not need to perform route mutual introduction, thereby ensuring business security.

[0034] Optionally, after the first network device imports the routing information of the first VPN instance from the first VPN instance into the second VPN instance, the method further includes: the first network device adding an import tag corresponding to the routing information of the first VPN instance to the second VPN instance, the import tag being used to indicate that the routing information of the first VPN instance in the second VPN instance is imported from a local VPN instance of the first network device. The routing table of the second VPN instance may include an import field, and the first network device may add the import tag to the import field.

[0035] The technical solution provided by the present application is that the first network device adds an introduction tag corresponding to the routing information of the first VPN instance in the second VPN instance, which can facilitate the first network device to distinguish the routing information imported from the local VPN instance in the second VPN instance from other routing information in the second VPN instance.

[0036] Optionally, after the first network device adds an import tag corresponding to the routing information of the first VPN instance to the second VPN instance, the method further includes: the first network device determining, based on the import tag in the second VPN instance, not to import the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device. The routing information of the first VPN instance in the second VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the second VPN instance.

[0037] In the technical solution provided by the present application, since the introduction tag is used to indicate that the routing information of the first VPN instance in the second VPN instance is introduced from the local VPN instance of the first network device, the first network device determines, based on the introduction tag in the second VPN instance, not to introduce the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device. This prevents the routing information introduced from the first VPN instance to the second VPN instance from being introduced back to the first VPN instance, thereby avoiding routing loops and storage of excessive amounts of identical routing information in the same VPN instance.

[0038] Optionally, after the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the method further includes: the first network device determining the first ERT in the second VPN instance; and the first network device determining not to import the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device based on the mismatch between the first ERT and the IRT in the local VPN instance of the first network device. The routing information of the first VPN instance in the second VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the second VPN instance.

[0039] The technical solution provided by the present application is that, since the first ERT corresponds to the routing information of the first VPN instance in the second VPN instance, and the first ERT does not match the IRT in the local VPN instance of the first network device, the first network device determines not to introduce the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device. This can prevent the routing information introduced from the first VPN instance to the second VPN instance from being introduced back to the first VPN instance, avoid causing a routing loop, and avoid storing too much identical routing information in the same VPN instance.

[0040] Optionally, the first network device sends the routing information of the first VPN instance in the second VPN instance to the second network device via the second VPN instance, including: the first network device sends the routing information of the first VPN instance in the second VPN instance to the second network device via the second VPN instance based on the first network device having an external publishing function. The external publishing function may be configured in the first network device by an operation and maintenance personnel, or configured in the first network device by a management device of the first network device. The first network device having an external publishing function means that all VPN instances in the first network device have an external publishing function. Alternatively, some VPN instances in the first network device may be configured to have an external publishing function, while other VPN instances may not have an external publishing function. For example, at least the second VPN instance in the first network device may be configured to have an external publishing function.

[0041] The technical solution provided in the present application is that the first network device sends the routing information of the first VPN instance in the second VPN instance to the second network device based on the first network device's external publishing function, which helps to ensure the security of the routing information of the first VPN instance and facilitates the first network device to control the extraction of routing information.

[0042] Optionally, both the first network device and the second network device are PE devices.

[0043] It should be noted that the concepts of first, second, third, and fourth in the first aspect are independent of the concepts of first, second, third, and fourth in the second aspect. The first network device in the first aspect may not be the same network device as the first network device in the second aspect, the first VPN instance in the first aspect may not be the same VPN instance as the first VPN instance in the second aspect, and the first ERT in the first aspect may not be the same ERT as the first ERT in the second aspect. The same applies to the concepts of second, third, and fourth.

[0044] According to a third aspect, a first network device is provided, the first network device comprising:

[0045] A first import module is configured to import, by a first network device, routing information of a first VPN instance in a second network device from the first VPN instance to a second VPN instance in the first network device, wherein the routing information of the first VPN instance corresponds to a first ERT in the first VPN instance, and the first ERT matches an IRT in the second VPN instance;

[0046] The second introducing module is configured to introduce, into the first network device, the routing information of the first VPN instance from the second VPN instance to a third VPN instance in the first network device.

[0047] Optionally, the second introduction module is specifically used to: the first network device determines the second ERT in the second VPN instance, and the second ERT corresponds to the routing information of the first VPN instance in the second VPN instance; the first network device introduces the routing information of the first VPN instance from the second VPN instance to the third VPN instance based on matching the second ERT with the IRT in the third VPN instance.

[0048] Optionally, the second introduction module is specifically used to: the first network device determines the routing information matching the attribute information in the second VPN instance based on the acquired attribute information, and the routing information matching the attribute information in the second VPN instance includes the routing information of the first VPN instance in the second VPN instance; the first network device introduces the routing information matching the attribute information in the second VPN instance from the second VPN instance into the third VPN instance.

[0049] Optionally, the attribute information includes a routing type and an identifier of the second VPN instance; the second introduction module is specifically configured to: cause the first network device to determine routing information in the second VPN instance that matches the attribute information based on the routing type and the identifier of the second VPN instance, wherein the routing information in the second VPN instance that matches the attribute information includes one or more routes having the routing type in the second VPN instance, and the one or more routes include routing information of the first VPN instance.

[0050] Optionally, the first network device further includes: an allowing module, configured to allow, before the first network device introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance, the first network device to allow, according to the acquired instruction, the introduction of the routing information of the first VPN instance from the second VPN instance into the third VPN instance.

[0051] Optionally, the first network device further includes: an adding module, configured to, after the first network device introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance, add an introduction tag corresponding to the routing information of the first VPN instance into the third VPN instance, wherein the introduction tag is used to indicate that the routing information of the first VPN instance in the third VPN instance is introduced from the local VPN instance of the first network device.

[0052] Optionally, the first network device further includes: a first determination module, which is used for, after the first network device adds an introduction tag corresponding to the routing information of the first VPN instance in the third VPN instance, the first network device determines, based on the introduction tag in the third VPN instance, not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device.

[0053] Optionally, the first network device further includes:

[0054] a second determining module, configured to, after the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, determine, by the first network device, a third ERT in the third VPN instance, the third ERT corresponding to the routing information of the first VPN instance in the third VPN instance;

[0055] The third determining module is configured to determine, by the first network device, that the routing information of the first VPN instance in the third VPN instance is not introduced into the local VPN instance of the first network device according to the mismatch between the third ERT and the IRT in the local VPN instance of the first network device.

[0056] Optionally, the first network device further includes: a sending module, which is used for, after the first network device introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance, the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance, the routing information of the first VPN instance in the third VPN instance corresponds to a third ERT in the third VPN instance, and the third ERT is used to instruct the third network device to introduce the routing information of the first VPN instance from the third VPN instance into a fourth VPN instance in the third network device.

[0057] Optionally, the sending module is specifically configured to: according to the first network device having an external publishing function, send the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance.

[0058] Optionally, both the first network device and the second network device are PE devices.

[0059] The technical effects of the various optional solutions of the third aspect are the same as the technical effects of the various optional solutions of the first aspect mentioned above, and will not be repeated here.

[0060] According to a fourth aspect, a first network device is provided, the first network device comprising:

[0061] An introduction module, configured for the first network device to introduce routing information of the first VPN instance in the first network device from the first VPN instance to the second VPN instance in the first network device;

[0062] A sending module is configured to send, by the first network device, the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance, wherein the routing information of the first VPN instance in the second VPN instance corresponds to a first ERT in the second VPN instance, and the first ERT is used to instruct the second network device to introduce the routing information of the first VPN instance from the second VPN instance into a third VPN instance of the second network device.

[0063] Optionally, the introduction module is specifically used to: the first network device introduces the routing information of the first VPN instance from the first VPN instance into the second VPN instance based on the matching of the second ERT in the first VPN instance with the IRT in the second VPN instance, and the second ERT corresponds to the routing information of the first VPN instance in the first VPN instance; or, the first network device determines the routing information in the first VPN instance that matches the attribute information based on the acquired attribute information, and introduces the routing information in the first VPN instance that matches the attribute information from the first VPN instance into the second VPN instance, and the routing information in the first VPN instance that matches the attribute information includes the routing information of the first VPN instance in the first VPN instance.

[0064] Optionally, the routing information of the first VPN instance is generated by the first VPN instance in the first network device; or, the routing information of the first VPN instance is learned by the first VPN instance in the first network device from the BGP neighbor of the first network device; or, the routing information of the first VPN instance is introduced by the first VPN instance in the first network device from a fourth VPN instance in the BGP EVPN neighbor of the first network device.

[0065] Optionally, the first network device further includes: an allowing module, configured to allow, before the first network device introduces the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the first network device to allow, according to the acquired instruction, the introduction of the routing information of the first VPN instance from the first VPN instance to the second VPN instance.

[0066] Optionally, the first network device further includes: an adding module, configured to, after the first network device introduces the routing information of the first VPN instance from the first VPN instance into the second VPN instance, add an introduction tag corresponding to the routing information of the first VPN instance in the second VPN instance, wherein the introduction tag is used to indicate that the routing information of the first VPN instance in the second VPN instance is introduced from the local VPN instance of the first network device.

[0067] Optionally, the first network device further includes: a first determination module, which is used for, after the first network device adds an introduction tag corresponding to the routing information of the first VPN instance in the second VPN instance, the first network device determines, based on the introduction tag in the second VPN instance, not to introduce the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device.

[0068] Optionally, the first network device further includes:

[0069] a second determining module, configured to, after the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, determine the first ERT in the second VPN instance by the first network device;

[0070] The third determining module is configured to determine, by the first network device, that the routing information of the first VPN instance in the second VPN instance is not introduced into the local VPN instance of the first network device according to the mismatch between the first ERT and the IRT in the local VPN instance of the first network device.

[0071] Optionally, the sending module is specifically configured to: according to the first network device having an external publishing function, send the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance.

[0072] Optionally, both the first network device and the second network device are PE devices.

[0073] The technical effects of the various optional solutions of the fourth aspect are the same as the technical effects of the various optional solutions of the above-mentioned second aspect, and will not be repeated here.

[0074] It should be noted that the concepts of "first, second, third, and fourth" in the third aspect are independent of the concepts of "first, second, third, and fourth" in the fourth aspect. The first network device in the third aspect may not be the same network device as the first network device in the fourth aspect, the first VPN instance in the third aspect may not be the same VPN instance as the first VPN instance in the fourth aspect, and the first ERT in the third aspect may not be the same ERT as the first ERT in the fourth aspect. The same applies to the concepts of "second, third, and fourth."

[0075] In a fifth aspect, a network device is provided, comprising a memory and a processor;

[0076] The memory is used to store computer programs;

[0077] The processor is used to execute the computer program stored in the memory to enable the network device to execute the route introduction method provided by the first aspect or any optional manner of the first aspect, or to execute the route introduction method provided by the second aspect or any optional manner of the second aspect.

[0078] In a sixth aspect, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, the computer implements the routing introduction method provided in the first aspect or any optional manner of the first aspect, or implements the routing introduction method provided in the second aspect or any optional manner of the second aspect.

[0079] In the seventh aspect, a computer program product comprising instructions is provided. When the computer program product is run on a computer, the computer is caused to execute the routing introduction method provided in the first aspect or any optional manner of the first aspect, or to execute the routing introduction method provided in the second aspect or any optional manner of the second aspect.

[0080] In an eighth aspect, a chip is provided, which includes a programmable logic circuit and / or program instructions, and when the chip is running, it is used to implement the routing introduction method provided by the first aspect or any optional method of the first aspect, or to implement the routing introduction method provided by the second aspect or any optional method of the second aspect.

[0081] In the ninth aspect, a communication system is provided, which includes: at least two network devices, the first network device among the at least two network devices is the network device provided by any one of the third to fifth aspects above, and the other network devices among the at least two network devices are used to send routing information to the first network device, or to receive routing information sent by the first network device.

[0082] Optionally, the network device is a PE device.

[0083] The beneficial effects of the technical solution provided by this application are:

[0084] The routing introduction method, device and system provided by the present application first introduce the routing information of the first VPN instance in the second network device from the first VPN instance into the second VPN instance in the first network device, and then introduce the routing information of the first VPN instance from the second VPN instance into the third VPN instance in the first network device, instead of introducing the routing information of the first VPN instance from the first VPN instance into the second VPN instance and the third VPN instance respectively. Therefore, it is not necessary to configure a large number of paired ERTs and IRTs in the first network device and the second network device to achieve mutual access between a large number of VPN instances between the first network device and the second network device, which helps to simplify business logic and configuration, can ensure effective isolation between VPN instances to ensure business security, avoid loops and fault propagation, and can achieve normal communication between VMs under different network devices. The application scenarios of routing introduction are wide. The routing introduction solution provided by the present application can be applied to EVPN three-segment VXLAN networks. The routing introduction solution can achieve mutual access between different VPN instances without protocol extension. The configuration is flexible and simple, and it is easy to implement and control. BRIEF DESCRIPTION OF THE DRAWINGS

[0085] Figure 1This is a schematic diagram of the structure of an EVPN network provided in an embodiment of the present application;

[0086] Figure 2 This is a schematic diagram of the structure of another EVPN network provided in an embodiment of the present application;

[0087] Figure 3 This is a schematic diagram of the structure of another EVPN network provided in an embodiment of the present application;

[0088] Figure 4 This is a schematic diagram of a local crossover provided in an embodiment of the present application;

[0089] Figure 5 is a schematic diagram of a distal crossover provided in an embodiment of the present application;

[0090] Figure 6 This is a flow chart of a route introduction method provided by an embodiment of the present application;

[0091] Figure 7 This is a schematic diagram of route introduction provided by an embodiment of the present application;

[0092] Figure 8 This is a schematic diagram of another route introduction provided by an embodiment of the present application;

[0093] Figure 9 This is a flow chart of an embodiment of the present application providing a method for importing routing information of a first VPN instance from a second VPN instance into the third VPN instance;

[0094] Figure 10 This is another flowchart of an embodiment of the present application for importing routing information of a first VPN instance from a second VPN instance to a third VPN instance;

[0095] Figure 11 This is a flowchart of an embodiment of the present application for determining not to introduce routing information of a first VPN instance in a third VPN instance into a local VPN instance;

[0096] Figure 12 This is another flowchart of determining not to introduce routing information of a first VPN instance in a third VPN instance into a local VPN instance provided by an embodiment of the present application;

[0097] Figure 13 This is a flowchart of another route introduction method provided by an embodiment of the present application;

[0098] Figure 14 This is a schematic diagram of another route introduction provided in an embodiment of the present application;

[0099] Figure 15 This is a schematic diagram of another route introduction provided in an embodiment of the present application;

[0100] Figure 16 This is a schematic diagram of the logical structure of a first network device provided in an embodiment of the present application;

[0101] Figure 17 This is a schematic diagram of the logical structure of another first network device provided in an embodiment of the present application;

[0102] Figure 18 This is a schematic diagram of the hardware structure of a network device provided in an embodiment of the present application;

[0103] Figure 19 This is a schematic diagram of the hardware structure of another network device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0104] To make the principles, technical solutions and advantages of the present application clearer, the route introduction method, device and system provided in the embodiments of the present application will be described below with reference to the accompanying drawings.

[0105] It should be understood that "at least one" in this document refers to one or more, and "plurality" refers to two or more. "At least two" refers to two or more. In this application, unless otherwise specified, " / " means or. For example, A / B can mean A or B. "And / or" in this application is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, for the sake of clarity of description, in this application, words such as "first", "second", and "third" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first", "second", and "third" do not limit the quantity and order of execution.

[0106] Before explaining the embodiments of the present application, the application scenarios of the embodiments of the present application are first explained.

[0107] The technical solutions provided in the embodiments of the present application can be applied to EVPN networks. For example, they can be applied to EVPN segmented virtual extensible local area networks (VXLANs), typically EVPN segmented VXLANs, which can be three-segment VXLANs.

[0108] The EVPN network includes multiple PE devices, and communication connections are established between the PE devices. Each PE device is configured with at least one VPN instance, and each PE device is connected to at least one user device. The VPN instance in each PE device corresponds to at least one user device connected to the PE device. Each VPN instance is used to forward messages from the corresponding user device to achieve communication between different user devices. Among them, the PE devices can be directly connected to each other, or they can be connected through other network devices (such as core devices), which is not limited in the embodiments of the present application. For example, the PE device can be a network device such as a router, a switch, a virtual router, or a virtual switch. The user device can be various types of devices such as a host, a user terminal, a server, or a virtual machine (VM) created on a server.

[0109] For example, please refer to Figure 1 , which shows a structural diagram of an EVPN network provided by an embodiment of the present application. The EVPN network includes three PE devices, PE1, PE2, and PE3. PE2 and PE3 are connected to PE1 respectively. PE1 and PE2 are BGP PEVPN neighbors, and PE1 and PE3 are BGP EVPN neighbors. PE1 is connected to VM11 and VM12 respectively, and PE1 is configured with at least one VPN instance corresponding to VM11 and VM12 ( Figure 1 PE2 is connected to VM21, and PE2 is configured with a VPN instance corresponding to VM21 ( Figure 1 PE3 is connected to VM31, and a VPN instance corresponding to VM31 is configured in PE3 ( Figure 1 (not shown). Each VPN instance is used to forward packets from the corresponding VM, enabling communication between different VMs. For example, the VPN instance corresponding to VM11 in PE1 forwards packets from VM11 to the VPN instance corresponding to VM12 in PE1. The VPN instance corresponding to VM12 in PE1 then forwards the packets to VM12, enabling communication between VM11 and VM12. For another example, the VPN instance corresponding to VM11 in PE1 forwards packets from VM11 to the VPN instance corresponding to VM21 in PE2. The VPN instance corresponding to VM21 in PE2 then forwards the packets to VM21, enabling communication between VM11 and VM21.

[0110] Typically, an EVPN network also includes access devices, which are connected to PE devices. User devices are connected to PE devices through the access devices. That is, user devices are mounted on the access devices and connected to PE devices through the access devices. The access devices are also configured with at least one VPN instance, and each VPN instance in the access device corresponds to at least one user device mounted on the access device. The access devices can be customer edge (CE) devices. For example, the CE devices can be network devices such as routers, switches, virtual routers, or virtual switches. For example, the CE devices can be top of rack (TOR) switches.

[0111] For example, please refer to Figure 2 , which shows a structural diagram of another EVPN network provided by an embodiment of the present application, Figure 1 Based on the EVPN network, the network also includes three CE devices, CE1, CE2, and CE3. CE1 is connected to PE1, VM11 and VM12 are mounted under CE1, VM11 and VM12 can connect to PE1 through CE1, and CE1 is configured with at least one VPN instance corresponding to VM11 and VM12 ( Figure 2 CE2 is connected to PE2, VM21 is mounted under CE2 (that is, VM21 is connected to PE2 through CE2), and CE2 is configured with a VPN instance corresponding to VM21 ( Figure 2 CE3 is connected to PE3, VM31 is mounted under CE3 (that is, VM31 is connected to PE3 through CE3), and CE3 is configured with a VPN instance corresponding to VM31 ( Figure 2 (not shown). Each VPN instance is used to forward the message of the corresponding VM, thereby realizing communication between different VMs. For example, the VPN instance corresponding to VM11 in CE1 forwards the message of VM11 to the VPN instance corresponding to VM12 in CE1, and the VPN instance corresponding to VM12 in CE1 forwards the message to VM12, thereby realizing communication between VM11 and VM12. For another example, the VPN instance corresponding to VM11 in CE1 forwards the message of VM11 to the VPN instance corresponding to VM11 in PE1, and the VPN instance corresponding to VM11 in PE1 forwards the message to the VPN instance corresponding to VM21 in PE2, and the VPN instance corresponding to VM21 in PE2 forwards the message to the VPN instance corresponding to VM21 in CE2, and the VPN instance corresponding to VM21 in CE2 forwards the message to VM21, thereby realizing communication between VM11 and VM21.

[0112] In an EVPN network, access devices can connect directly to PE devices or through other network devices. For example, access devices can connect to PE devices through a gateway (GW). If an access device connects to a PE device through a GW, the GW can also be configured with at least one VPN instance. Each VPN instance in the GW corresponds to at least one user device attached to the access device to which the GW is connected, thereby forwarding packets from the user device. The GW can be a network device such as a router, switch, virtual router, or virtual switch.

[0113] For example, please refer to Figure 3 , which shows a structural diagram of another EVPN network provided in an embodiment of the present application, Figure 2 Based on the above, the EVPN network also includes three GW devices, GW1, GW2 and GW3. GW1 is connected to CE1 and PE1 respectively (that is, CE1 is connected to PE1 through GW1), and GW1 is configured with at least one VPN instance corresponding to VM11 and VM12 ( Figure 3 GW2 is connected to CE2 and PE2 respectively (ie CE2 is connected to PE2 via GW2), and GW2 is configured with a VPN instance corresponding to VM21 ( Figure 3 GW3 is connected to CE3 and PE3 respectively (ie CE3 is connected to PE3 via GW3), and GW3 is configured with a VPN instance corresponding to VM31 ( Figure 3 (not shown). Each VPN instance is used to forward messages from the corresponding VM, enabling communication between different VMs. For example, the VPN instance corresponding to VM11 in CE1 forwards the message from VM11 to the VPN instance corresponding to VM11 in GW1. The VPN instance corresponding to VM11 in GW1 forwards the message to the VPN instance corresponding to VM11 in PE1. The VPN instance corresponding to VM11 in PE1 forwards the message to the VPN instance corresponding to VM21 in PE2. The VPN instance corresponding to VM21 in PE2 forwards the message to the VPN instance corresponding to VM21 in GW2. The VPN instance corresponding to VM21 in GW2 forwards the message to the VPN instance corresponding to VM21 in CE2. The VPN instance corresponding to VM21 in CE2 then forwards the message to VM21, enabling communication between VM11 and VM21.

[0114] The EVPN network provided in the embodiment of the present application may be an EVPN segmented VXLAN network. Figures 1 to 3As shown, the EVPN network includes three VXLAN networks, VXLAN1, VXLAN2, and VXLAN3. PE1, CE1, GW1, VM11, and VM12 belong to VXLAN1, PE2, CE2, GW2, and VM21 belong to VXLAN2, and PE3, CE3, GW3, and VM31 belong to VXLAN3. Those skilled in the art will understand that Figures 1 to 3 The EVPN network shown is only used as an example and is not intended to limit the technical solutions of the embodiments of the present application. In the specific implementation process, PE devices, CE devices, and GW devices can be configured as needed. In addition, the EVPN network can also include other network devices, for example, the EVPN network can also include route reflectors (RRs). In addition, Figure 2 and Figure 3 The example in which VM11 and VM12 are connected to PE1 through the same CE device is used for explanation. In actual applications, VM11 and VM12 are mounted on different CE devices connected to PE1, and this embodiment of the present application does not limit this.

[0115] In an embodiment of the present application, each VPN instance in a network device (including a PE device, a CE device, and a GW device) corresponds to a routing table that is locally valid on the network device, for example, a virtual routing forwarding (VRF) table. Each VPN instance forwards packets according to the routing information recorded in its routing table to achieve communication between different VMs. When VMs in two different VPN instances (the two VPN instances can be located in the same network device or in different network devices) need to communicate, the route of one VPN instance can be introduced into the other VPN instance by means of route crossover, so that the routes of the two VPN instances can be interconnected. Each VPN instance is configured with a route target (RT), and the route target of a VPN instance can also be called a vpn-target. RT is a BGP extended community attribute, and each VPN instance needs to be configured with two types of RT: ERT and IRT. Route crossover refers to importing routes from one VPN instance into another VPN instance by matching ERT with IRT. For example, if the ERT in one VPN instance matches the IRT in another VPN instance (that is, the ERT value in one VPN instance is equal to the IRT value in the other VPN instance), the routes of the one VPN instance can be imported into the other VPN instance.

[0116] Depending on the route source, route crossing is categorized as local crossing and remote crossing. As an example of local crossing, a PE device matches the ERT in a local VPN instance with the IRT in another local VPN instance. If the ERT in the VPN instance matches the IRT in one of the other VPN instances, the PE device writes the BGP route for the VPN instance containing the ERT into the routing table of the matching VPN instance, thereby importing the BGP route into the matching VPN instance. As an example of remote crossing, a PE device learns a BGP EVPN route for the VPN instance in the remote PE device from the remote PE device. It then matches the ERT carried in the BGP EVPN route with the IRT in the VPN instance in the PE device. If the ERT carried in the BGP EVPN route matches the IRT in the local VPN instance of the PE device, the PE device converts the BGP EVPN route into a BGP route and writes the BGP route into the routing table of the matching VPN instance, thereby importing the BGP EVPN route into the matching VPN instance.

[0117] As an example, see Figure 4 , which shows a schematic diagram of a local cross provided by an embodiment of the present application, see Figure 4 Combined with Figure 1 , PE1 is configured with two VPN instances, VPN11 and VPN12. VPN11 is configured with ERT 1:1 and IRT 1:1, and VPN12 is configured with ERT 1:1 and IRT 1:1. Assume that VM11 is under VPN11 and VM12 is under VPN12. If VM11 and VM12 need to communicate, VPN11 and VPN12 need to have routing connectivity. Figure 4 As shown, the ERT in VPN11 matches the IRT in VPN12 in a 1:1 manner, and the ERT in VPN12 matches the IRT in VPN11 in a 1:1 manner. Therefore, the routes of VPN11 can be introduced into VPN12, and the routes of VPN12 can be introduced into VPN11, thereby achieving route intercommunication between VPN11 and VPN12. That is, route intercommunication between VPN11 and VPN12 is achieved through local cross-connection.

[0118] As an example, see Figure 5 , which shows a schematic diagram of a distal cross provided by an embodiment of the present application, see Figure 5 Combined with Figures 1 to 3, PE1 is configured with two VPN instances, VPN11 and VPN12. VPN11 is configured with ERT 1:1, IRT 1:1, and IRT 2:2. VPN12 is configured with ERT 2:2, IRT 1:1, and IRT 2:2. PE2 is configured with one VPN instance, VPN21. VPN21 is configured with ERT 1:1 and IRT 1:1. PE3 is configured with one VPN instance, VPN31. VPN31 is configured with ERT 2:2 and IRT 2:2. Assume that VM11 is under VPN11, VM12 is under VPN12, VM21 is under VPN21, and VM31 is under VPN31. If VM11 and VM21 need to communicate, VPN11 and VPN21 need to have routing connectivity. Figure 5 As shown in the figure, the ERT 1:1 in VPN11 matches the IRT 1:1 in VPN21, and the ERT 1:1 in VPN21 matches the IRT 1:1 in VPN11. Therefore, the routes of VPN11 can be introduced into VPN21, and the routes of VPN21 can be introduced into VPN11, so that the routes of VPN11 and VPN21 can be interconnected. That is, the routes of VPN11 and VPN21 can be interconnected through remote cross-connection. If VM21 and VM12 need to communicate, the routes of VPN21 and VPN12 need to be interconnected. Figure 5 As shown in the figure, the ERT in VPN21 matches the IRT in VPN12, so the routes of VPN21 can be introduced into VPN12, that is, the routes of VPN21 are introduced into VPN12 through remote cross-connection. Similarly, if VM31 and VM11 need to communicate, the routes of VPN31 and VPN11 need to be interoperable. Figure 5 As shown in the figure, the ERT 2:2 in VPN31 matches the IRT 2:2 in VPN11, so the routes of VPN31 can be introduced into VPN11, that is, the routes of VPN31 are introduced into VPN11 through remote cross-connection. If VM12 and VM31 need to communicate, the routes of VPN12 and VPN31 need to be interoperable. Figure 5 As shown, ERT 2:2 in VPN12 matches IRT 2:2 in VPN31, and ERT 2:2 in VPN31 matches IRT 2:2 in VPN12. Therefore, the routes of VPN12 can be introduced into VPN31, and the routes of VPN31 can be introduced into VPN12, so that the routes of VPN12 and VPN31 can be interconnected. In other words, the routes of VPN12 and VPN31 can be interconnected through remote cross-connection.

[0119] It should be pointed out that the embodiment of the present application takes the network device as a PE device as an example to introduce local cross-connection and remote cross-connection. It is easy for those skilled in the art to understand that local cross-connection behavior can be performed in any network device in the EVPN network, and remote cross-connection behavior can be performed between any two connected network devices. For example, local cross-connection behavior can be performed in PE devices, local cross-connection behavior can be performed in CE devices, local cross-connection behavior can also be performed in GW devices, remote cross-connection behavior can be performed between PE devices, remote cross-connection behavior can be performed between CE devices and PE devices, between CE devices and GW devices, and between GW devices and PE devices, and the embodiment of the present application does not limit this. For example, if Figure 2 As shown, if VM11 needs to send a message to VM21, the message of VM11 is forwarded by the VPN instance corresponding to VM11 in CE1 to PE1, forwarded by the VPN instance corresponding to VM11 in PE1 to PE2, forwarded by the VPN instance corresponding to VM21 in PE2 to CE2, and forwarded by the VPN instance corresponding to VM21 in CE2 to VM21. Therefore, remote cross-connection behavior is required between CE1 and PE1, between PE1 and PE2, and between PE2 and CE2 to enable the corresponding VPN instance routes to communicate with each other. For another example, Figure 3 As shown, if VM31 needs to send a message to VM12, the message of VM31 is forwarded by the VPN instance corresponding to VM31 in CE3 to GW3, forwarded by the VPN instance corresponding to VM31 in GW3 to PE3, forwarded by the VPN instance corresponding to VM31 in PE3 to PE1, forwarded by the VPN instance corresponding to VM12 in PE1 to GW1, forwarded by the VPN instance corresponding to VM12 in GW1 to CE1, and forwarded by the VPN instance corresponding to VM12 in CE1 to VM12. Therefore, remote cross-connection behavior is required between CE3 and GW3, between GW3 and PE3, between PE3 and PE1, between PE1 and GW1, and between GW1 and CE1 to enable the corresponding VPN instance routes to communicate with each other.

[0120] It should be noted that in an EVPN network, a VPN instance corresponding to a VM exists in a network device directly connected to the VM (e.g., a CE device), and the VM is mounted under this VPN instance. For a network device indirectly connected to the VM (e.g., a network device connected to the VM via a CE device), the VPN instance corresponding to the VM in the network device can be determined by matching ERT with IRT. For example, Figure 2 As shown, the ERT of the VPN instance corresponding to VM11 in CE1 can be matched with the IRT in the VPN instance in PE1 to determine the VPN instance corresponding to VM11 in PE1. Figure 3As shown, the ERT of the VPN instance corresponding to VM11 in CE1 can be matched with the IRT in the VPN instance in GW1 to determine the VPN instance corresponding to VM11 in GW1, and then the ERT of the VPN instance corresponding to VM11 in GW1 can be matched with the IRT in the VPN instance in PE1 to determine the VPN instance corresponding to VM11 in PE1.

[0121] As mentioned above, it is easy to understand that in a remote cross-over scenario, if you want to achieve mutual access between a large number of VPN instances between multiple network devices (such as PE devices), you need to configure a large number of paired ERTs and IRTs in the multiple network devices. In this way, the business logic and configuration become very complicated, which can easily destroy the effective isolation between VPN instances, making it impossible to ensure business security, and increasing the possibility of loops and fault propagation. In a local cross-over scenario, the existing mechanism cannot achieve routing intercommunication between local VPN instances and remote VPN instances (referring to VPN instances in remote PEs), affecting the normal communication between VMs connected to different PE devices, resulting in limited application scenarios for routing introduction. For example, Figure 5 In the remote cross-connect scenario shown in the figure, if you want to implement mutual access between VPN21 in PE2 and VPN11 and VPN12 in PE1, you need to configure ERT 1:1 in VPN21 in PE2 and IRT 1:1 in VPN11 and VPN12 in PE1 respectively. If you want to implement mutual access between VPN31 in PE3 and VPN11 and VPN12 in PE1, you need to configure ERT 2:2 in VPN31 in PE3 and IRT 2:2 in VPN11 and VPN12 in PE1 respectively. This makes the service logic and configuration very complicated, easily destroys the effective isolation between VPN instances, cannot guarantee service security, and increases the possibility of loops and fault propagation. Figure 4 The local cross-connection scenario shown can only realize mutual access between VPN11 and VPN12 in PE1, and cannot realize mutual access between VPN11 and VPN12 in PE1 and VPN21 in the remote PE2. This affects the normal communication between VM11 mounted under VPN11 and VM21 mounted under VPN21, and also affects the normal communication between VM12 mounted under VPN12 and VM21 mounted under VPN21, resulting in limited application scenarios of route introduction.

[0122] In view of this, the embodiments of the present application provide a method, device, and system for introducing routes. In the technical solution provided in the embodiments of the present application, it is possible to achieve mutual access between a large number of VPN instances between multiple network devices without configuring a large number of paired ERTs and IRTs, which helps to simplify business logic and configuration, ensure effective isolation between VPN instances, thereby ensuring business security, and help avoid loops and fault propagation. It can also achieve normal communication between VMs under different network devices, and the application scenarios of route introduction are wide-ranging. The technical solution of the present application is described in detail below.

[0123] It should be noted that the concepts of first, second, third, and fourth in any of the following embodiments are independent of the concepts of first, second, third, and fourth in other embodiments. For example, the first network device in one embodiment may not be the same network device as the first network device in another embodiment, the first VPN instance in one embodiment may not be the same VPN instance as the first VPN instance in another embodiment, and the first ERT in one embodiment may not be the same ERT as the first ERT in another embodiment. The same applies to the concepts of second, third, and fourth. Each of these concepts will be described in detail in the following embodiments.

[0124] Please refer to Figure 6 , which shows a flow chart of a route introduction method provided by an embodiment of the present application, the route introduction method can be executed by a first network device in an EVPN network, the first network device can be a PE device, or a CE device or a GW device. Figure 6 As shown, the method may include the following steps:

[0125] Step 601: A first network device imports routing information of a first VPN instance in a second network device from the first VPN instance to a second VPN instance in the first network device, where the routing information of the first VPN instance corresponds to a first ERT in the first VPN instance, and the first ERT matches an IRT in the second VPN instance.

[0126] Optionally, the first network device and the second network device are both PE devices, the second network device may be a remote device of the first network device, and the first network device and the second network device are BGP EVPN neighbors. Figures 1 to 3 As shown, the first network device may be PE1, and the second network device may be PE2.

[0127] In an EVPN network, each network device (e.g., a PE device, a CE device, a GW device, etc.) is configured with at least one VPN instance. Each VPN instance corresponds to a locally valid routing table on the network device where it resides. This routing table can be, for example, a VRF table. The routes in each VPN instance are recorded in the routing table corresponding to the VPN instance. A first network device and a second network device, as network devices in the EVPN network, are each configured with at least one VPN instance. The first VPN instance can be any VPN instance in the second network device. The routing information of the first VPN instance is information in the routes of the first VPN instance. The routing information of the first VPN instance can be information in one or more routes belonging to the first VPN instance. That is, when one or more routes in the first VPN instance of the second network device are imported into the second VPN instance of the first network device, the routing information of the first VPN instance is also imported into the second VPN instance. The routing information is related information in the one or more routes. In an embodiment of the present application, the routing information of the first VPN instance may be generated by the first VPN instance in the second network device, or learned by the first VPN instance from a BGP neighbor of the second network device, or introduced by the first VPN instance from a BGP EVPN neighbor of the second network device. This embodiment of the present application is not limited to this.

[0128] In an EVPN network, each VPN instance in a network device is configured with at least one ERT and at least one IRT. Routing information for a first VPN instance in a second network device is located in the first VPN instance. The routing information for the first VPN instance in the first VPN instance corresponds to the first ERT in the first VPN instance (e.g., the routing information for the first VPN instance carries the first ERT). The first network device can import the routing information for the first VPN instance from the first VPN instance to the second VPN instance in the first network device through remote routing cross-connection. Optionally, based on the first ERT corresponding to the routing information for the first VPN instance in the first VPN instance, the first network device determines, within the VPN instance in the first network device, a VPN instance whose IRT matches the first ERT, identifies the VPN instance in the VPN instance in the first network device whose IRT matches the first ERT as the second VPN instance in the first network device, and imports the routing information for the first VPN instance from the first VPN instance to the second VPN instance. For example, the first network device copies the routing information for the first VPN instance from the first VPN instance to the routing table of the second VPN instance.

[0129] Please refer to Figure 7 and Figure 8, which shows a schematic diagram of two routing introductions provided in an embodiment of the present application, the first network device is PE1, the second network device is PE2, two VPN instances VPN11 and VPN12 are configured in PE1, one VPN instance VPN21 is configured in PE2, IRT 2:2 is configured in VPN11, and ERT 2:2 and IRT 2:2 are configured in VPN21. Assuming that VPN21 in PE2 is the first VPN instance, the first ERT of VPN21 is ERT 2:2, the routing information of VPN21 recorded in VPN21 includes A1 (that is, the routing information of the first VPN instance recorded in the first VPN instance includes A1), and the routing information A1 of VPN21 corresponds to the ERT 2:2. PE1 can introduce the routing information A1 of VPN21 from the VPN21 to the second VPN instance of PE1 by remote routing crossover. Specifically, PE1 determines the VPN instance whose IRT matches the ERT 2:2 in the VPN instance in PE1, such as Figure 7 and Figure 8 As shown, the IRT 2:2 in VPN11 in PE1 matches the ERT 2:2 in VPN21 in PE2, so PE1 determines VPN11 as the second VPN instance and copies the routing information A1 of VPN21 from VPN21 to the routing table of VPN11.

[0130] Step 602: The first network device imports routing information of the first VPN instance from the second VPN instance in the first network device to the third VPN instance in the first network device.

[0131] After the first network device imports the routing information of the first VPN instance from the first VPN instance into the second VPN instance, the routing information of the first VPN instance can be imported from the second VPN instance into the third VPN instance in the first network device. This allows for mutual access between a large number of VPN instances between the first network device and the second network device without configuring a large number of paired ERTs and IRTs in the first network device and the second network device, thus simplifying service logic and configuration. The third VPN instance can be any VPN instance in the first network device except the second VPN instance. For example, Figure 7 and Figure 8 As shown, the second VPN instance is VPN11 in PE1 (first network device), and the third VPN instance may be VPN12 in PE1.

[0132] In this embodiment of the present application, the first network device can import the routing information of the first VPN instance from the second VPN instance to the third VPN instance through route cross-connection, or can import the routing information of the first VPN instance from the second VPN instance to the third VPN instance through attribute matching. Depending on the route importation method, step 602 may include two possible implementations, which are described in detail below.

[0133] A first implementation manner: the first network device introduces the routing information of the first VPN instance from the second VPN instance in the first network device to the third VPN instance in the first network device by means of route cross-connection.

[0134] Please refer to Figure 9 , which shows a flowchart of a first network device introducing routing information of a first VPN instance from the second VPN instance to the third VPN instance provided by an embodiment of the present application, see Figure 9 , the method may include:

[0135] Sub-step 6021a: The first network device determines a second ERT in the second VPN instance in the first network device, where the second ERT corresponds to routing information of the first VPN instance in the second VPN instance.

[0136] The second ERT can be any ERT in the second VPN instance, and the routing information of the first VPN instance in the second VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the second VPN instance. As previously described, it is easy to understand that the routing information of the first VPN instance in the second VPN instance is the routing information of the first VPN instance imported from the remote first VPN instance, and the routing information of the first VPN instance in the second VPN instance is obtained by importing the routing information of the first VPN instance in the first VPN instance.

[0137] After the first network device imports the routing information of the first VPN instance from the first VPN instance of the second network device into the local second VPN instance, it allocates an ERT from the ERT configured in the second VPN instance and associates the allocated ERT with the routing information of the first VPN instance in the second VPN instance, so that the ERT, as a second ERT, corresponds to the routing information of the first VPN instance in the second VPN instance. Alternatively, the first network device generates a new ERT in the second VPN instance and associates the generated ERT with the routing information of the first VPN instance in the second VPN instance, so that the ERT, as a second ERT, corresponds to the routing information of the first VPN instance in the second VPN instance. This is not a limitation in the present embodiment.

[0138] For example, Figure 7 As shown, the first VPN instance is VPN21 in PE2, the second VPN instance is VPN11 in PE1, and the second ERT may be ERT 2:3 in VPN11. ERT 2:3 corresponds to the routing information of VPN21 in VPN11, that is, ERT 2:3 corresponds to the routing information of VPN21 recorded (or stored) in VPN11. For example, the routing information of VPN21 in VPN21 includes A1, which corresponds to ERT 2:2 in VPN21 of PE2 and is imported into VPN11 by VPN11 of PE1 through IRT 2:2 matching ERT 2:2. That is, after route import, VPN11 also includes routing information A1, and PE1 allocates ERT 2:3 corresponding to routing information A1 in VPN11.

[0139] Sub-step 6022a: The first network device imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance based on the matching of the second ERT in the second VPN instance in the first network device and the IRT in the third VPN instance in the first network device.

[0140] Optionally, the first network device determines, based on the second ERT in the second VPN instance in the first network device, a VPN instance in the VPN instance in the first network device whose IRT matches the second ERT, determines the VPN instance in the VPN instance in the first network device whose IRT matches the second ERT as a third VPN instance, and imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance. For example, the first network device copies the routing information of the first VPN instance from the second VPN instance to the routing table of the third VPN instance.

[0141] For example, Figure 7As shown, the first network device is PE1. VPN11 and VPN12 in PE1 are two VPN instances in PE1. VPN11 is the second VPN instance. The second ERT in VPN11 is ERT 2:3. VPN12 is configured with IRT 2:3 and IRT 1:1. PE1 determines, among the VPN instances in PE1, a VPN instance whose IRT matches ERT 2:3 (i.e., the second ERT). IRT 2:3 in VPN12 matches ERT 2:3 in VPN11. Therefore, PE1 determines VPN12 as the third VPN instance and imports the routing information of VPN21 from VPN11 into VPN12. As described in sub-step 6021a, the routing information of VPN21 in VPN11 is A1. Therefore, PE1 imports the routing information A1 from VPN11 into VPN12.

[0142] It should be noted that this first implementation provides for importing the routing information of the first VPN instance from the second VPN instance to the third VPN instance through route crossover. The actual meaning of route crossover is ERT and IRT matching. Importing the routing information of the first VPN instance from the second VPN instance to the third VPN instance through route crossover is equivalent to importing the routing information of the first VPN instance from the second VPN instance to the third VPN instance through ERT and IRT matching. Since in this first implementation, the second and third VPN instances are both located in the first network device, the route crossover provided in this first implementation is also a local crossover.

[0143] Second implementation manner: The first network device imports the routing information of the first VPN instance from the second VPN instance in the first network device to the third VPN instance in the first network device through attribute matching.

[0144] Please refer to Figure 10 , which shows another flow chart of a first network device introducing routing information of a first VPN instance from the second VPN instance to the third VPN instance provided by an embodiment of the present application, see Figure 10 , the method may include:

[0145] Sub-step 6021b: The first network device determines, based on the acquired attribute information, routing information in the second VPN instance in the first network device that matches the attribute information, where the routing information in the second VPN instance that matches the attribute information includes routing information of the first VPN instance in the second VPN instance.

[0146] The first network device may be configured with attribute information so that, based on the attribute information, the first network device may import routes matching the attribute information under the second VPN instance into the third VPN instance. For example, the attribute information may be configured in the second VPN instance to match routes having attributes identified by the attribute information. For example, if one or more routes to which the routing information of the first VPN instance belongs all have the attributes identified by the attribute information, the first network device may determine, through attribute matching, that the routing information matching the attribute information in the second VPN instance includes the routing information of the first VPN instance in the second VPN instance.

[0147] Optionally, the attribute information is configured in the first network device by an operation and maintenance personnel via a command line. The attribute information may include a route type and an identifier of the second VPN instance. The route type may be, for example, BGP routing, static routing, etc. The identifier of the second VPN instance may be the name of the second VPN instance, or a unique serial number of each VPN instance in the first network device. The identifier of the second VPN instance may be the serial number of the second VPN instance. The first network device may determine, based on the route type and the identifier of the second VPN instance, routing information in the second VPN instance that matches the attribute information through attribute matching. The routing information in the second VPN instance that matches the attribute information may belong to one or more routes of the second VPN instance having the route type. For example, the first network device first determines the second VPN instance based on the identifier of the second VPN instance in the attribute information, and then determines one or more routes with the route type in the second VPN instance based on the route type in the attribute information, and determines the one or more routes with the route type in the second VPN instance as routes that match the attribute information, and the one or more routes include the routing information of the first VPN instance.

[0148] Sub-step 6022b: The first network device imports the routing information matching the attribute information in the second VPN instance in the first network device from the second VPN instance in the first network device to the third VPN instance in the first network device.

[0149] Optionally, the first network device determines the VPN instance in the first network device into which routes are to be imported as a third VPN instance, and copies the routing information in the second VPN instance in the first network device that matches the acquired attribute information from the second VPN instance to the routing table of the third VPN instance. Because the routing information in the second VPN instance that matches the attribute information includes the routing information of the first VPN instance in the second VPN instance, the first network device can import the routing information of the first VPN instance in the second VPN instance into the third VPN instance through sub-step 6022b.

[0150] For example, Figure 8 As shown, the first network device is PE1, VPN11 is the second VPN instance, and VPN12 is the third VPN instance. PE1 imports routing information in VPN11 that matches the acquired attribute information from VPN11 into VPN12 through attribute matching. The routing information in VPN11 that matches the attribute information includes routing information A1 of VPN21 in VPN11. Therefore, in sub-step 6022b, PE1 imports routing information A1 of VPN21 in VPN11 from VPN11 to VPN12.

[0151] It should be noted that the two implementation methods provided in step 602 are merely exemplary. The first network device may also adopt other implementation methods to import the routing information of the first VPN instance from the second VPN instance to the third VPN instance, which will not be described in detail in this embodiment of the present application.

[0152] In summary, the routing introduction method provided in the embodiment of the present application is that the first network device first introduces the routing information of the first VPN instance in the second network device from the first VPN instance into the second VPN instance in the first network device, and then introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance in the first network device, rather than introducing the routing information of the first VPN instance from the first VPN instance into the second VPN instance and the third VPN instance respectively. Therefore, it is not necessary to configure a large number of paired ERTs and IRTs in the first network device and the second network device to achieve mutual access between a large number of VPN instances between the first network device and the second network device, which helps to simplify business logic and configuration, can ensure effective isolation between VPN instances to ensure business security, avoid loops and fault propagation, and can achieve normal communication between VMs under different network devices. The application scenarios of routing introduction are wide. The routing introduction method provided in the embodiment of the present application can be applied to EVPN three-segment VXLAN networks. The routing introduction method can achieve mutual access between different VPN instances without protocol extension, and the configuration is flexible and simple, easy to implement and control.

[0153] In an embodiment of the present application, as a possible implementation, before a first network device imports routing information of a first VPN instance from a second VPN instance within the first network device to a third VPN instance within the first network device, the method further includes: the first network device, based on an acquired instruction, allowing the import of routing information of the first VPN instance from the second VPN instance within the first network device to the third VPN instance within the first network device. This step may include the following two implementations, which are described in detail below.

[0154] Implementation method 1): A first enabling switch is configured in the first network device, and the first enabling switch can be a master enabling switch in the first network device. The first network device allows the routing information of the first VPN instance to be introduced from the second VPN instance in the first network device to the third VPN instance in the first network device according to the state of the first enabling switch.

[0155] Optionally, the first enabling switch is used by the first network device to determine whether to allow routing mutual reference between VPN instances in the first network device. When the first enabling switch is in the enabled state, the first network device determines that routing mutual reference is allowed between VPN instances in the first network device. When the first enabling switch is in the disabled state, the first network device determines that routing mutual reference is not allowed between VPN instances in the first network device.

[0156] The first network device may obtain the state of the first enabling switch. If the first enabling switch is in the enabled state, the first network device allows the routing information of the first VPN instance to be imported from the second VPN instance to the third VPN instance. If the first enabling switch is in the disabled state, the first network device does not allow the routing information of the first VPN instance to be imported from the second VPN instance to the third VPN instance. For example, Figure 7 and Figure 8 As shown, if the first enabling switch in PE1 is in the enabled state, PE1 allows the routing information of VPN21 (ie, the first VPN instance) to be imported from VPN11 (ie, the second VPN instance) to VPN12 (ie, the third VPN instance).

[0157] Implementation method 2): A second enabling switch is configured in the first network device, and the second enabling switch can be a VPN enabling switch. The first network device allows the routing information of the first VPN instance to be introduced from the second VPN instance in the first network device to the third VPN instance in the first network device according to the state of the second enabling switch.

[0158] Optionally, the second enabling switch is located in the second VPN instance. The second enabling switch is used by the first network device to determine whether to allow route referencing between the second VPN instance and the third VPN instance, or whether to allow route referencing between the second VPN instance and all or some other VPN instances in the first network device, where the all or some VPN instances include the third VPN instance. Thus, when the second enabling switch is in an enabled state, the first network device determines that route referencing is allowed between the second VPN instance and the third VPN instance; and when the second enabling switch is in a disabled state, the first network device determines that route referencing is not allowed between the second VPN instance and the third VPN instance. The second enabling switch is located in the second VPN instance (i.e., the source VPN instance for route referencing). Optionally, the second enabling switch can also be located in the third VPN instance (i.e., the destination VPN instance for route referencing). When the second enabling switch is located in the third VPN instance, the second enabling switch can be used by the first network device to determine whether to allow routing between other parts or all VPN instances including the second VPN instance and the third VPN instance. Figure 7 and Figure 8 As shown, the second enabling switch may be located in VPN11 (i.e., the second VPN instance), and is used by PE1 to determine whether to allow route referrals between VPN11 and VPN12 (i.e., the third VPN instance), or whether to allow route referrals between VPN11 and all or some other VPN instances in PE1, where the all or some VPN instances include VPN12. Alternatively, the second enabling switch may be located in VPN12 (i.e., the third VPN instance), and is used by PE1 to determine whether to allow route referrals between VPN12 and some or all other VPN instances, including VPN11 (i.e., the second VPN instance).

[0159] Optionally, the second enabling switch is located in the second VPN instance. The second enabling switch is used by the first network device to determine whether to allow the routes in the second VPN instance to be introduced into the third VPN instance, or whether to allow the routes in the second VPN instance to be introduced into all or part of the other VPN instances in the first network device, which all or part of the VPN instances include the third VPN instance. Thus, when the second enabling switch is in the enabled state, the first network device determines that the routes in the second VPN instance are allowed to be introduced into the third VPN instance, and when the second enabling switch is in the disabled state, the first network device determines that the routes in the second VPN instance are not allowed to be introduced into the third VPN instance. The second enabling switch is located in the second VPN instance (that is, the source VPN instance for route introduction). Optionally, the second enabling switch can also be located in the third VPN instance (that is, the destination VPN instance for route introduction). When the second enabling switch is located in the third VPN instance, the second enabling switch can be used by the first network device to determine whether to allow the routes in other part or all of the VPN instances, including the second VPN instance, to be introduced into the third VPN instance. For example, as Figure 7 and Figure 8 As shown, the second enabling switch may be located in VPN11 (i.e., the second VPN instance), and is used by PE1 to determine whether to allow routes in VPN11 to be imported into VPN12 (i.e., the third VPN instance), or whether to allow routes in VPN11 to be imported into all or part of other VPN instances in PE1, where the all or part of VPN instances include VPN12 (i.e., the third VPN instance). Alternatively, the second enabling switch may be located in VPN12 (i.e., the third VPN instance), and is used by PE1 to determine whether to allow routes in all or part of other VPN instances, including VPN11, to be imported into VPN12.

[0160] Optionally, when the second enabling switch is located in the second VPN instance or the third VPN instance, as a specific implementation of the second enabling switch, a route reference table is maintained in the second enabling switch, and the route reference table records all or part of the VPN instances in the first network device, including the second VPN instance and the third VPN instance. Route reference can be performed between the VPN instances in the route reference table. The route reference table indicates that the second enabling switch is in an enabled state for route reference between the second VPN instance and the third VPN instance. The first network device determines that routing information of the first VPN instance is allowed to be introduced from the second VPN instance to the third VPN instance. As another specific implementation of the second enabling switch, the second enabling switch maintains a correspondence between VPN instances, where each VPN instance recorded in the correspondence can refer routes to a corresponding VPN instance. The correspondence includes a correspondence between the second VPN instance and the third VPN instance. The correspondence indicates that the second enabling switch is in an enabled state for referring routes between the second VPN instance and the third VPN instance, and the first network device determines to allow routing information of the first VPN instance to be imported from the second VPN instance to the third VPN instance.

[0161] Optionally, when the second enabling switch is located in the second VPN instance, as a specific implementation of the second enabling switch, a route import table is maintained in the second enabling switch, the route import table records all or part of the VPN instances in the first network device, including the third VPN instance, and the routes in the second VPN instance can be imported into the VPN instance recorded in the route import table. The route import table indicates that the second enabling switch is in an enabled state for importing the routes in the second VPN instance into the third VPN instance, and the first network device determines to allow the routing information of the first VPN instance to be imported from the second VPN instance into the third VPN instance.

[0162] Optionally, when the second enabling switch is located in the third VPN instance, as a specific implementation of the second enabling switch, the second enabling switch maintains a route export table, the route export table records all or part of the VPN instances in the first network device, including the second VPN instance, the routes in the VPN instances recorded in the route export table can be introduced into the second VPN instance, the route export table indicates that the second enabling switch is in an enabled state for introducing the routes in the second VPN instance into the third VPN instance, and the first network device determines to allow the routing information of the first VPN instance to be introduced from the second VPN instance to the third VPN instance.

[0163] Those skilled in the art will readily appreciate that the description of the internal implementation of the second enabling switch herein is merely exemplary. In actual applications, the second enabling switch may also be implemented in other ways. For example, as one implementation of the second enabling switch, the second enabling switch records all or part of the VPN instances in the first network device and the enable flag corresponding to each VPN instance. The value of the enable flag indicates whether the corresponding VPN instance enables route import or export. The first network device determines whether to allow the corresponding VPN instance to import or export routes based on the value of the enable flag. The value of the enable flag can be configured, modified, and updated so that the second enabling switch can enable route import or export for different VPN instances at the same time, and can enable route import or export for the same VPN instance at different times. Furthermore, it should be noted that the above-described schemes regarding the first enabling switch and the second enabling switch are merely exemplary. The first network device may also employ other implementations to allow routing information of the first VPN instance to be imported from the second VPN instance in the first network device to the third VPN instance in the first network device. This is not limited in the present embodiment.

[0164] In an embodiment of the present application, as a possible implementation method, after the first network device introduces the routing information of the first VPN instance from the second VPN instance in the first network device to the third VPN instance in the first network device, the method further includes: the first network device determines not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device. This can prevent the routing information introduced from the second VPN instance to the third VPN instance from being introduced back to the second VPN instance, avoid causing routing loops, and avoid storing too much identical routing information in the same VPN instance. The routing information of the first VPN instance in the third VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the third VPN instance, the routing information of the first VPN instance in the third VPN instance is introduced from the second VPN instance, and the routing information of the first VPN instance in the third VPN instance is obtained by introducing the routing information of the first VPN instance in the second VPN instance. For example, Figure 7 and Figure 8 As shown, VPN12 is a third VPN instance. VPN12 imports routing information A1 of remote VPN21 (ie, the first VPN instance) through local VPN11.

[0165] Optionally, the first network device can determine not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device by adding an import flag, or can determine not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device by configuring ERT and IRT. Accordingly, the first network device can determine not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device in the following two possible implementations, which are described in detail below.

[0166] A first implementation manner: the first network device determines not to introduce the routing information of the first VPN instance in the third VPN instance in the first network device into the local VPN instance of the first network device by adding an introduction mark.

[0167] Please refer to Figure 11 , which shows a flowchart of a first network device determining not to introduce routing information of a first VPN instance in a third VPN instance into a local VPN instance provided by an embodiment of the present application, see Figure 11 , the method may include:

[0168] Step S11: The first network device adds an import tag corresponding to the routing information of the first VPN instance in the third VPN instance in the first network device, where the import tag is used to indicate that the routing information of the first VPN instance in the third VPN instance is imported from the local VPN instance of the first network device.

[0169] After a first network device imports the routing information of a first VPN instance from a second VPN instance within the first network device to a third VPN instance within the first network device, it may add an import tag corresponding to the routing information of the first VPN instance to the third VPN instance. The import tag indicates that the routing information of the first VPN instance in the third VPN instance is imported from the local VPN instance of the first network device. The import tag may be local-import or local-crossed. Optionally, the routing table of the third VPN instance contains one or more import fields corresponding to the routing information of the first VPN instance. The one or more import fields may respectively correspond to one or more routes to which the routing information of the first VPN instance belongs. The first network device may add the import tag to the one or more import fields. For example, the first network device may configure the value of the one or more import fields to be 1 to add the import tag to the import fields.

[0170] For example, Figure 7 and Figure 8As shown, VPN12 is the third VPN instance, the routing information of VPN21 (that is, the first VPN instance) in VPN12 is A1, and PE1 adds local-import corresponding to the routing information A1 in VPN12 to indicate that the routing information A1 in VPN12 is introduced from the local VPN instance of PE1.

[0171] Step S12: The first network device determines not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device according to the import flag in the third VPN instance in the first network device.

[0172] Optionally, the first network device detects whether there is an introduction mark corresponding to the routing information of the first VPN instance in the third VPN instance in the third VPN instance; if the introduction mark is present in the routes corresponding to the routing information of the first VPN instance in the third VPN instance, it indicates that the routing information of the first VPN instance in the third VPN instance is introduced from the local VPN instance of the first network device, and the first network device determines not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device; if the introduction mark is not present in some routes in the third VPN instance, it indicates that these routes in the third VPN instance are not introduced from the local VPN instance of the first network device, and the first network device may allow these routes in the third VPN instance to be introduced into the local VPN instance of the first network device.

[0173] For example, Figure 7 and Figure 8 As shown, VPN12 is the third VPN instance, and the routing information of VPN21 (i.e., the first VPN instance) in VPN12 is A1. PE1 can detect whether a local-import corresponding to routing information A1 exists in VPN12. If a local-import corresponding to routing information A1 exists in VPN12, PE1 determines not to import routing information A1 into PE1's local VPN instance. If a local-import corresponding to routing information A1 does not exist in VPN12, PE1 determines that routing information A1 can be imported into PE1's local VPN instance. As can be seen from the description of step S11, a local-import corresponding to routing information A1 exists in VPN12, so PE1 determines not to import routing information A1 into PE1's local VPN instance again.

[0174] Second implementation: The first network device determines, through configuration of ERT and IRT, not to introduce routing information of the first VPN instance in the third VPN instance in the first network device into the local VPN instance of the first network device.

[0175] Please refer to Figure 12 , which shows another flowchart of a first network device determining not to introduce routing information of a first VPN instance in a third VPN instance into a local VPN instance provided by an embodiment of the present application, see Figure 12 , the method may include:

[0176] Step S21: The first network device determines a third ERT in a third VPN instance in the first network device, where the third ERT corresponds to routing information of the first VPN instance in the third VPN instance.

[0177] The implementation method of step S21 can refer to the aforementioned sub-step 6021a, which will not be repeated here.

[0178] For example, Figure 7 and Figure 8 As shown, the third VPN instance is VPN12 in PE1, the third ERT is ERT1:1 in VPN12, the routing information of VPN21 in VPN12 (that is, the first VPN instance) is A1, and the ERT 1:1 corresponds to the routing information A1 of VPN21 recorded in VPN12.

[0179] As can be seen from the preceding description, routing information A1 is imported into PE1's VPN11 and VPN12 via VPN21 of PE2, either remotely or locally. Routing information A1 corresponds to ERT 2:2 in VPN21, ERT 2:3 in VPN11, and ERT 1:1 in VPN12. After being imported into the VPN instances, routing information A1 may correspond to, for example, one or more routes in VRF21 of VPN21, one or more routes in VRF11 of VPN11, and one or more routes in VRF12 of VPN12. The one or more routes in VRF21, VRF11, and VRF12 may contain different content, but all include routing information A1.

[0180] Step S22: The first network device determines not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device based on the mismatch between the third ERT in the third VPN instance in the first network device and the IRT in the local VPN instance of the first network device.

[0181] Optionally, the third ERT in the third VPN instance of the first network device, determined by the first network device, is an ERT in the third VPN instance that can only be used for remote import. Therefore, no IRT matching the third ERT can be found in the local VPN instance of the first network device. The first network device thus determines that no VPN instance in the first network device exists with an IRT matching the third ERT. Therefore, the first network device determines not to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device.

[0182] For example, Figure 7 and Figure 8 As shown, the third VPN instance is VPN12 in PE1, and the third ERT is ERT1:1 in VPN12. There is no VPN instance in PE1 whose IRT matches the ERT 1:1. Therefore, PE1 determines not to introduce the routing information A1 of VPN21 (that is, the first VPN instance) in VPN12 into the local VPN instance of PE1.

[0183] It should be pointed out that the two implementation methods provided in the embodiments of the present application for the first network device to determine not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance are merely exemplary. The first network device can also use other implementation methods to determine not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance. The embodiments of the present application will not be repeated here.

[0184] In an embodiment of the present application, as a possible implementation method, after the first network device introduces the routing information of the first VPN instance from the second VPN instance in the first network device to the third VPN instance in the first network device, or after the first network device determines not to introduce the routing information of the first VPN instance in the third VPN instance to the local VPN instance, the method further includes: the first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance in the first network device, the routing information of the first VPN instance in the third VPN instance corresponds to the third ERT in the third VPN instance, and the third ERT is used to instruct the third network device to introduce the routing information of the first VPN instance from the third VPN instance to the fourth VPN instance in the third network device. Optionally, the third network device is a PE device, the third network device can be a remote device of the first network device, and the first network device and the third network device are BGP EVPN neighbors to each other. For example, Figures 1 to 3 As shown, the first network device may be PE1, and the third network device may be PE3.

[0185] Optionally, the first network device first determines a third ERT in a third VPN instance in the first network device. The first network device then sends routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance. Optionally, based on the first network device having an external publishing function, the first network device sends routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance. Specifically, the first network device first detects whether the first network device has an external publishing function. If so, the first network device sends routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance. If not, the first network device does not send routing information of the first VPN instance in the third VPN instance to the third network device. The external publishing function can be configured on the first network device by operations and maintenance personnel or by the management device of the first network device. Among them, the first network device having the external publishing function means that all VPN instances in the first network device have the external publishing function. Optionally, some VPN instances in the first network device can also be configured to have the external publishing function, while other VPN instances do not have the external publishing function. For example, at least the third VPN instance in the first network device is configured to have the external publishing function. This embodiment of the present application does not limit this.

[0186] After receiving the routing information of the first VPN instance in the third VPN instance sent by the first network device via the third VPN instance in the first network device, the third network device imports the routing information of the first VPN instance in the third VPN instance into the fourth VPN instance of the third network device. Optionally, the routing information of the first VPN instance in the third VPN instance sent by the first network device to the third network device carries the third ERT. After receiving the routing information, the third network device determines a VPN instance in the VPN instance in the third network device whose IRT matches the third ERT, determines the VPN instance in the VPN instance in the third network device whose IRT matches the third ERT as the fourth VPN instance, and imports the routing information into the fourth VPN instance.

[0187] For example, Figure 7 and Figure 8As shown, the first network device is PE1, the third network device is PE3, the third VPN instance is VPN12 in PE1, the third ERT is ERT 1:1 in VPN12, ERT 1:1 corresponds to the routing information A1 of VPN21 (that is, the first VPN instance) in VPN12, and the fourth VPN instance is VPN31 in PE3. The ERT 1:1 is used to instruct PE3 to introduce the routing information A1 of VPN21 from the VPN12 to the VPN31. After PE1 determines the ERT 1:1 in VPN12, if PE1 has the external publishing function, PE1 sends the routing information A1 of VPN21 in VPN12 to PE3 through VPN12. The routing information A1 sent by PE1 to PE3 carries the ERT 1:1 (that is, the third ERT). After receiving the routing information A1, PE3 determines the VPN instance whose IRT matches the ERT 1:1 in PE3 according to the ERT 1:1 carried in the routing information A1, such as Figure 7 and Figure 8 As shown, the VPN instance whose IRT in PE3 matches the ERT 1:1 is VPN31, so PE3 imports the routing information A1 into VPN31.

[0188] In summary, the routing introduction method provided in the embodiment of the present application is that the first network device first introduces the routing information of the first VPN instance in the second network device from the first VPN instance into the second VPN instance in the first network device, and then introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance in the first network device, rather than introducing the routing information of the first VPN instance from the first VPN instance into the second VPN instance and the third VPN instance respectively. Therefore, it is not necessary to configure a large number of paired ERTs and IRTs in the first network device and the second network device to achieve mutual access between a large number of VPN instances between the first network device and the second network device, which helps to simplify business logic and configuration, can ensure effective isolation between VPN instances to ensure business security, avoid loops and fault propagation, and can achieve normal communication between VMs under different network devices. The application scenarios of routing introduction are wide. The routing introduction method provided in the embodiment of the present application can be applied to EVPN three-segment VXLAN networks. The routing introduction method can achieve mutual access between different VPN instances without protocol extension, and the configuration is flexible and simple, easy to implement and control.

[0189] Please refer to Figure 13 , which shows a flowchart of another route introduction method provided by an embodiment of the present application, the route introduction method can be executed by a first network device in an EVPN network, the first network device can be a PE device, or a CE device or a GW device. Figure 13 As shown, the method may include the following steps:

[0190] Step 1301: A first network device imports routing information of a first VPN instance in the first network device from the first VPN instance to a second VPN instance in the first network device.

[0191] The first VPN instance and the second VPN instance can be any two VPN instances in the first network device, and the routing information of the first VPN instance is information in one or more routes of the first VPN instance. The routing information of the first VPN instance is generated by the first VPN instance; or learned by the first VPN instance from a BGP neighbor of the first network device; or imported by the first VPN instance from a fourth VPN instance among the BGP EVPN neighbors of the first network device. This embodiment of the present application is not limited to this. In the embodiment of the present application, the first network device can import the routing information of the first VPN instance from the first VPN instance to the second VPN instance through route cross-connection, or import the routing information of the first VPN instance from the first VPN instance to the second VPN instance through attribute matching. Depending on the route import method, step 1301 can include two possible implementation methods.

[0192] A first implementation manner: the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance in the first network device by means of route cross-connection.

[0193] Optionally, the first network device determines a second ERT in the first VPN instance in the first network device, the second ERT corresponding to the routing information of the first VPN instance in the first VPN instance, and then, the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance based on matching the second ERT in the first VPN instance with the IRT in the second VPN instance. The implementation process of the first implementation method can be referred to Figure 9 The embodiments shown and related descriptions will not be repeated here for the embodiments of the present application.

[0194] For example, please refer to Figure 14, which shows a schematic diagram of route introduction provided by an embodiment of the present application, where the first network device is PE1, and two VPN instances, VPN11 and VPN12, are configured in PE1. The first VPN instance is VPN11, and the second VPN instance is VPN12. The routing information of VPN11 in VPN11 (that is, the routing information of the first VPN instance) includes B1, and the second ERT is ERT 1:1 in VPN11. The routing information B1 corresponds to the ERT 1:1 in VPN11. PE1 matches the ERT 1:1 in VPN11 with the IRT 1:1 in VPN12, and introduces the routing information B1 of VPN11 in VPN11 into VPN12.

[0195] It should be noted that, since in the first implementation, the first VPN instance and the second VPN instance are both located in the first network device, the route crossing provided in the first implementation is also local crossing.

[0196] Second implementation manner: The first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance in the first network device through attribute matching.

[0197] Optionally, the first network device determines the routing information matching the attribute information in the first VPN instance based on the acquired attribute information, and introduces the routing information matching the attribute information in the first VPN instance from the first VPN instance to the second VPN instance, and the routing information matching the attribute information in the first VPN instance includes the routing information of the first VPN instance in the first VPN instance. The implementation process of the second implementation method can be referred to Figure 10 The embodiments shown and related descriptions will not be repeated here for the embodiments of the present application.

[0198] For example, please refer to Figure 15 , which shows a schematic diagram of route introduction provided by an embodiment of the present application. The first network device is PE1, and two VPN instances, VPN11 and VPN12, are configured in PE1. The first VPN instance is VPN11, and the second VPN instance is VPN12. The routing information of VPN11 in VPN11 (that is, the routing information of the first VPN instance) includes B1. PE1 introduces the routing information in VPN11 that matches the acquired attribute information from the VPN11 into VPN12 by attribute matching. The routing information in the VPN11 that matches the attribute information includes the routing information B1 of VPN11 in the VPN11. Therefore, through the second implementation method, PE1 introduces the routing information B1 of VPN11 in the VPN11 from the VPN11 to the VPN12.

[0199] Step 1302: The first network device sends the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance in the first network device. The routing information of the first VPN instance in the second VPN instance corresponds to the first ERT in the second VPN instance. The first ERT is used to instruct the second network device to introduce the routing information of the first VPN instance from the second VPN instance to the third VPN instance of the second network device.

[0200] Optionally, the second network device is a PE device, and the second network device may be a remote device of the first network device, and the first network device and the second network device are BGP EVPN neighbors. Figures 1 to 3 As shown, the first network device may be PE1, and the second network device may be PE2.

[0201] Optionally, the first network device determines a first ERT in a second VPN instance within the first network device. The first ERT corresponds to routing information of the first VPN instance within the second VPN instance. The first ERT is used to instruct the second network device to import the routing information of the first VPN instance from the second VPN instance to a third VPN instance within the second network device. Subsequently, the first network device transmits the routing information of the first VPN instance within the second VPN instance to the second network device via the second VPN instance. Optionally, based on the first network device having an external publishing capability, the first network device transmits the routing information of the first VPN instance within the second VPN instance to the second network device via the second VPN instance. Specifically, the first network device first detects whether the first network device has an external publishing capability. If so, the first network device transmits the routing information of the first VPN instance within the second VPN instance to the second network device via the second VPN instance. If not, the first network device does not transmit the routing information of the first VPN instance within the second VPN instance to the second network device. The external publishing function can be configured in the first network device by an operation and maintenance personnel, or configured in the first network device by a management device of the first network device. The first network device having the external publishing function means that all VPN instances in the first network device have the external publishing function. Optionally, some VPN instances in the first network device can be configured to have the external publishing function, while other VPN instances cannot. For example, at least the second VPN instance in the first network device can be configured to have the external publishing function. This embodiment of the present application does not limit this.

[0202] After receiving the routing information of the first VPN instance in the second VPN instance sent by the first network device via the second VPN instance in the first network device, the second network device introduces the routing information of the first VPN instance in the second VPN instance into the third VPN instance of the second network device. Optionally, the routing information of the first VPN instance in the second VPN instance sent by the first network device to the second network device carries the first ERT. After receiving the routing information, the second network device determines, among the VPN instances in the second network device, a VPN instance whose IRT matches the first ERT, determines the VPN instance in the VPN instance in the second network device whose IRT matches the first ERT as a third VPN instance, and introduces the routing information into the third VPN instance.

[0203] For example, Figure 14 and Figure 15 As shown, the first network device is PE1, the second network device is PE2, the second VPN instance is VPN12 in PE1, the first ERT is ERT 2:2 in VPN12, ERT 2:2 corresponds to the routing information B1 of VPN11 (that is, the first VPN instance) in VPN12, and the third VPN instance is VPN21 in PE2. The ERT 2:2 is used to instruct PE2 to introduce the routing information B1 of VPN11 from VPN12 to VPN21. After PE1 determines ERT 2:2 in VPN12, if PE1 has an external publishing function, PE1 sends the routing information B1 of VPN11 in VPN12 to PE2 through VPN12. The routing information B1 sent by PE1 to PE2 carries ERT 2:2 (that is, the first ERT). After PE2 receives the routing information B1, it determines the VPN instance whose IRT matches ERT 2:2 in PE2 according to the ERT 2:2 carried in the routing information B1, such as Figure 14 and Figure 15 As shown, the VPN instance whose IRT in PE2 matches the ERT 2:2 is VPN21, so PE2 imports the routing information B1 into VPN21.

[0204] In summary, the routing introduction method provided in the embodiment of the present application is that the first network device first introduces the routing information of the first VPN instance in the first network device from the first VPN instance to the second VPN instance in the first network device, and then sends the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance. Therefore, mutual access between a large number of VPN instances between the first network device and the second network device can be achieved, which helps to simplify business logic and configuration, can ensure effective isolation between VPN instances to ensure business security, and can achieve normal communication between VMs under different network devices. The application scenarios of routing introduction are wide. The routing introduction method provided in the embodiment of the present application can be applied to EVPN three-segment VXLAN networks. The routing introduction method can achieve mutual access between different VPN instances without protocol extension, and the configuration is flexible and simple, easy to implement and control.

[0205] In an embodiment of the present application, as a possible implementation, before the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the method further includes: the first network device, based on the obtained instruction, allowing the import of the routing information of the first VPN instance from the first VPN instance to the second VPN instance. The implementation process of this step can refer to the aforementioned embodiment and is not limited in this embodiment of the present application.

[0206] For example, Figure 14 and Figure 15 As shown, the first network device is PE1, and two VPN instances, VPN11 and VPN12, are configured in PE1. The first VPN instance is VPN11, and the second VPN instance is VPN12. PE1 allows the routing information B1 of VPN11 in VPN11 to be introduced from VPN11 to VPN12 according to the obtained instruction.

[0207] In an embodiment of the present application, as a possible implementation, after a first network device imports routing information of a first VPN instance from the first VPN instance to a second VPN instance, the method further includes: the first network device determining not to import routing information of the first VPN instance in the second VPN instance of the first network device into the local VPN instance of the first network device. This prevents routing information imported from the first VPN instance to the second VPN instance from being imported back to the first VPN instance, thereby preventing routing loops and excessive storage of identical routing information within the same VPN instance. The routing information of the first VPN instance in the second VPN instance refers to the routing information of the first VPN instance recorded (or stored) in the second VPN instance.

[0208] Optionally, the first network device can determine not to import the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device by adding an import tag, or can determine not to import the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device by configuring ERT and IRT. Accordingly, the first network device can determine not to import the routing information of the first VPN instance in the second VPN instance in the first network device into the local VPN instance of the first network device in the following two possible implementations, which are described in detail below.

[0209] A first implementation manner: the first network device determines not to introduce the routing information of the first VPN instance in the second VPN instance in the first network device into the local VPN instance of the first network device by adding an introduction mark.

[0210] Optionally, the first network device adds an introduction tag corresponding to the routing information of the first VPN instance in the second VPN instance, and the introduction tag is used to indicate that the routing information of the first VPN instance in the second VPN instance is introduced from the local VPN instance of the first network device. The first network device determines not to introduce the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device based on the introduction tag in the second VPN instance. The implementation process of the first implementation method can be referred to Figure 11 The embodiments shown and related descriptions will not be repeated here for the embodiments of the present application.

[0211] For example, Figure 14 and Figure 15 As shown, VPN12 is the second VPN instance, and the routing information of VPN11 (that is, the first VPN instance) in VPN12 is B1. PE1 adds the introduction tag local-import corresponding to the routing information B1 in VPN12. PE1 determines not to introduce the routing information B1 into the local VPN instance of PE1 based on the introduction tag local-import corresponding to the routing information B1 in VPN12.

[0212] Second implementation: The first network device determines, through configuration of ERT and IRT, not to introduce routing information of the first VPN instance in the second VPN instance in the first network device into the local VPN instance of the first network device.

[0213] Optionally, the first network device determines the first ERT in the second VPN instance, and the first ERT corresponds to the routing information of the first VPN instance in the second VPN instance. The first network device determines not to introduce the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device based on the fact that the first ERT in the second VPN instance does not match the IRT in the local VPN instance of the first network device. The implementation process of this second implementation method can be referred to Figure 12 The embodiments shown and related descriptions will not be repeated here for the embodiments of the present application.

[0214] For example, Figure 14 and Figure 15 As shown, VPN12 is the second VPN instance, and the routing information of VPN11 (that is, the first VPN instance) in VPN12 is B1. PE1 determines that the first ERT in VPN12 is ERT 2:2, which corresponds to VPN11 routing information B1 in VPN12. Because ERT 2:2 does not match the IRT in PE1's local VPN instance (e.g., VPN11), PE1 determines not to import VPN11 routing information B1 in VPN12 into PE1's local VPN instance.

[0215] In summary, the routing introduction method provided in the embodiment of the present application is that the first network device first introduces the routing information of the first VPN instance in the first network device from the first VPN instance to the second VPN instance in the first network device, and then sends the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance. Therefore, mutual access between a large number of VPN instances between the first network device and the second network device can be achieved, which helps to simplify business logic and configuration, and can ensure effective isolation between VPN instances to ensure business security, avoid loops and fault propagation, and achieve normal communication between VMs under different network devices. The application scenarios of routing introduction are wide. The routing introduction method provided in the embodiment of the present application can be applied to EVPN three-segment VXLAN networks. The routing introduction method can achieve mutual access between different VPN instances without protocol extension, and the configuration is flexible and simple, easy to implement and control.

[0216] The following are device embodiments of the present application, which can be used to implement the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.

[0217] Please refer to Figure 16 , which shows a logical structure diagram of a first network device 1600 provided in an embodiment of the present application. Figure 16The first network device 1600 may include but is not limited to:

[0218] First import module 1610 is configured to import, from first network device 1600, routing information of a first VPN instance in a second network device to a second VPN instance in first network device 1600. The routing information of the first VPN instance corresponds to a first ERT in the first VPN instance, and the first ERT matches the IRT in the second VPN instance. The implementation of the functionality of first import module 1610 can be found in the description of step 601 above.

[0219] The second importing module 1620 is configured to import the routing information of the first VPN instance from the second VPN instance to the third VPN instance in the first network device 1600. The implementation of the function of the second importing module 1620 can refer to the description of step 602 above.

[0220] Optionally, the second introduction module 1610 is specifically used to: the first network device 1600 determines the second ERT in the second VPN instance, and the second ERT corresponds to the routing information of the first VPN instance in the second VPN instance; the first network device 1600 introduces the routing information of the first VPN instance from the second VPN instance to the third VPN instance based on matching the second ERT with the IRT in the third VPN instance.

[0221] Optionally, the second introduction module 1620 is specifically used to: the first network device 1600 determines the routing information that matches the attribute information in the second VPN instance based on the acquired attribute information, and the routing information that matches the attribute information in the second VPN instance includes the routing information of the first VPN instance in the second VPN instance; the first network device 1600 introduces the routing information that matches the attribute information in the second VPN instance from the second VPN instance into the third VPN instance.

[0222] Optionally, the attribute information includes a routing type and an identifier of the second VPN instance; the second introduction module 1620 is specifically used to: the first network device 1600 determines the routing information in the second VPN instance that matches the attribute information based on the routing type and the identifier of the second VPN instance, and the routing information in the second VPN instance that matches the attribute information includes one or more routes with the routing type in the second VPN instance, and the one or more routes include the routing information of the first VPN instance.

[0223] Optionally, please continue to refer to Figure 16The first network device 1600 further includes an enabling module 1630 configured to, before the first network device 1600 enables the routing information of the first VPN instance to be imported from the second VPN instance to the third VPN instance, based on the acquired instruction. The functionality of enabling module 1630 can be implemented with reference to the description of the first network device enabling the routing information of the first VPN instance to be imported from the second VPN instance to the third VPN instance in the aforementioned method embodiment.

[0224] Optionally, please continue to refer to Figure 16 First network device 1600 further includes an adding module 1640 configured to, after first network device 1600 imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance, add an import tag corresponding to the routing information of the first VPN instance to the third VPN instance, the import tag being used to indicate that the routing information of the first VPN instance in the third VPN instance is imported from the local VPN instance of first network device 1600. The implementation of the functions of adding module 1640 may refer to the description of step S11 above.

[0225] Optionally, please continue to refer to Figure 16 The first network device 1600 further includes a first determining module 1650 configured to, after the first network device 1600 adds an import flag corresponding to the routing information of the first VPN instance to the third VPN instance, determine, based on the import flag in the third VPN instance, whether to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device 1600. The implementation of the functions of the first determining module 1650 may refer to the description of step S12 above.

[0226] Optionally, please continue to refer to Figure 16 , the first network device 1600 further includes:

[0227] Second determination module 1660 is configured to, after first network device 1600 imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, determine a third ERT in the third VPN instance, where the third ERT corresponds to the routing information of the first VPN instance in the third VPN instance. The implementation of the functionality of second determination module 1660 can be found in the description of step S21 above.

[0228] A third determining module 1670 is configured to determine, based on the mismatch between the third ERT and the IRT in the local VPN instance of the first network device 1600, whether to import the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device 1600. The implementation of the functions of the third determining module 1670 may refer to the description of step S22 above.

[0229] Optionally, please continue to refer to Figure 16 The first network device 1600 further includes a sending module 1680, which is configured to, after the first network device 1600 imports the routing information of the first VPN instance from the second VPN instance into the third VPN instance, send the routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance. The routing information of the first VPN instance in the third VPN instance corresponds to a third ERT in the third VPN instance, and the third ERT is used to instruct the third network device to import the routing information of the first VPN instance from the third VPN instance into the fourth VPN instance in the third network device. The functional implementation of sending module 1680 can refer to the description of the first network device sending the routing information of the first VPN instance in the third VPN instance to the third network device via the third VPN instance in the aforementioned method embodiment.

[0230] Optionally, the sending module 1680 is specifically configured to: according to the external publishing function of the first network device 1600 , send the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance.

[0231] Optionally, both the first network device 1600 and the second network device are PE devices.

[0232] In summary, the first network device provided in the embodiment of the present application first introduces the routing information of the first VPN instance in the second network device from the first VPN instance into the second VPN instance in the first network device, and then introduces the routing information of the first VPN instance from the second VPN instance into the third VPN instance in the first network device, rather than introducing the routing information of the first VPN instance from the first VPN instance into the second VPN instance and the third VPN instance respectively. Therefore, it is not necessary to configure a large number of paired ERTs and IRTs in the first network device and the second network device to achieve mutual access between a large number of VPN instances between the first network device and the second network device, which helps to simplify business logic and configuration, can ensure effective isolation between VPN instances to ensure business security, avoid loops and fault propagation, and can achieve normal communication between VMs under different network devices. The application scenarios of route introduction are wide. The route introduction solution provided in the embodiment of the present application can be applied to EVPN three-segment VXLAN networks. The route introduction solution can achieve mutual access between different VPN instances without protocol extension, and the configuration is flexible and simple, easy to implement and control.

[0233] Please refer to Figure 17 , which shows a logical structure diagram of another first network device 1700 provided in an embodiment of the present application. Figure 17 The first network device 1700 may include but is not limited to:

[0234] The import module 1710 is configured to import the routing information of the first VPN instance in the first network device 1700 from the first VPN instance to the second VPN instance in the first network device 1700. The implementation of the function of the import module 1710 can refer to the description of step 1301 above.

[0235] Sending module 1720 is configured to enable first network device 1700 to send routing information of the first VPN instance in the second VPN instance to a second network device via the second VPN instance. The routing information of the first VPN instance in the second VPN instance corresponds to a first ERT in the second VPN instance. The first ERT is used to instruct the second network device to import the routing information of the first VPN instance from the second VPN instance to a third VPN instance of the second network device. For the implementation of the functions of sending module 1720, refer to the description of step 1302 above.

[0236] Optionally, the introduction module 1710 is specifically used to: the first network device 1700 introduces the routing information of the first VPN instance from the first VPN instance into the second VPN instance based on the matching of the second ERT in the first VPN instance with the IRT in the second VPN instance, and the second ERT corresponds to the routing information of the first VPN instance in the first VPN instance; or, the first network device 1700 determines the routing information in the first VPN instance that matches the attribute information based on the acquired attribute information, and introduces the routing information in the first VPN instance that matches the attribute information from the first VPN instance into the second VPN instance, and the routing information in the first VPN instance that matches the attribute information includes the routing information of the first VPN instance in the first VPN instance.

[0237] Optionally, the routing information of the first VPN instance is generated by the first VPN instance in the first network device 1700; or, the routing information of the first VPN instance is learned by the first VPN instance in the first network device 1700 from the BGP neighbor of the first network device 1700; or, the routing information of the first VPN instance is introduced by the first VPN instance in the first network device 1700 from a fourth VPN instance in the BGP EVPN neighbor of the first network device 1700.

[0238] Optionally, please continue to refer to Figure 17 The first network device 1700 further includes an enabling module 1730 configured to, before the first network device 1700 enables the routing information of the first VPN instance to be enabled from the first VPN instance to the second VPN instance, based on the acquired instruction. The functionality of enabling module 1730 can be implemented with reference to the description of enabling the first network device to enable the routing information of the first VPN instance to be enabled from the first VPN instance to the second VPN instance in the aforementioned method embodiment.

[0239] Optionally, please continue to refer to Figure 17 The first network device 1700 further includes an adding module 1740 configured to, after the first network device 1700 imports the routing information of the first VPN instance from the first VPN instance into the second VPN instance, add an import tag corresponding to the routing information of the first VPN instance to the second VPN instance, the import tag being used to indicate that the routing information of the first VPN instance in the second VPN instance is imported from the local VPN instance of the first network device 1700. The implementation of the functions of the adding module 1740 may refer to the description of step S11 above.

[0240] Optionally, please continue to refer to Figure 17 The first network device 1700 further includes a first determining module 1750 configured to, after the first network device 1700 adds an import flag corresponding to the routing information of the first VPN instance to the second VPN instance, determine, based on the import flag in the second VPN instance, whether to import the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device 1700. The implementation of the functions of the first determining module 1750 may refer to the description of step S12 above.

[0241] Optionally, please continue to refer to Figure 17 , the first network device 1700 further includes:

[0242] Second determination module 1760 is configured to determine the first ERT in the second VPN instance after first network device 1700 imports the routing information of the first VPN instance from the first VPN instance into the second VPN instance. The implementation of the function of second determination module 1760 can refer to the description of step S21 above.

[0243] A third determining module 1770 is configured to determine, based on the mismatch between the first ERT and the IRT in the local VPN instance of the first network device 1700, whether to import the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device 1700. The implementation of the functions of the third determining module 1770 may refer to the description of step S22 above.

[0244] Optionally, the sending module 1720 is specifically configured to: according to the external publishing function of the first network device 1700 , send the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance.

[0245] Optionally, both the first network device 1700 and the second network device are PE devices.

[0246] In summary, the first network device provided in the embodiment of the present application first introduces the routing information of the first VPN instance in the first network device from the first VPN instance into the second VPN instance in the first network device, and then sends the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance. Therefore, it is not necessary to configure a large number of paired ERTs and IRTs in the first network device and the second network device to achieve mutual access between a large number of VPN instances between the first network device and the second network device, which helps to simplify business logic and configuration, and can ensure effective isolation between VPN instances to ensure business security, avoid loops and fault propagation, and achieve normal communication between VMs under different network devices. The application scenarios of route introduction are wide. The route introduction solution provided in the embodiment of the present application can be applied to EVPN three-segment VXLAN networks. The route introduction solution can achieve mutual access between different VPN instances without protocol extension, and the configuration is flexible and simple, easy to implement and control.

[0247] It should be understood that the network device provided in the embodiments of the present application can also be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), wherein the PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The routing introduction method provided in the above method embodiment can also be implemented by software. When the message sending method provided in the above method embodiment is implemented by software, each module in the PE device can also be a software module or a module that combines software and hardware.

[0248] Please refer to Figure 18 , which shows a hardware structure diagram of a network device 1800 provided in an embodiment of the present application. The network device 1800 can be the first network device in any of the above embodiments. The network device 1800 can be a switch, a router, or other network device that forwards packets. In this embodiment, the network device 1800 includes: a main control board 1810, an interface board 1830, and an interface board 1840. In the case of multiple interface boards, a switching network board (not shown in the figure) can be included, which is used to complete data exchange between the interface boards (interface boards are also called line cards or service boards).

[0249] Main control board 1810 is used to perform system management, device maintenance, and protocol processing. Interface boards 1830 and 1840 provide various service interfaces (e.g., POS, GE, and ATM) and implement message forwarding. Main control board 1810 primarily includes three functional units: a system management and control unit, a system clock unit, and a system maintenance unit. Main control board 1810, interface board 1830, and interface board 1840 are interconnected via a system bus and the system backplane. Interface board 1830 includes one or more processors 1831. Processors 1831 control and manage the interface boards, communicate with the central processing unit on the main control board, and import routes. Memory 1832 on interface board 1830 stores the ERT and IRT information for VPN instances. Processor 1831 performs route import between VPN instances by searching the ERT and IRT information stored in memory 1832.

[0250] The interface board 1830 includes one or more network interfaces 1833 for receiving routing information and forwarding the routing information according to the instructions of the processor 1831. The specific implementation process is not described in detail here. The specific functions of the processor 1831 are also not described in detail here.

[0251] It is understandable that Figure 18 As shown, this embodiment includes multiple interface boards and adopts a distributed forwarding mechanism. Under this mechanism, the operation on the interface board 1840 is basically similar to the operation of the interface board 1830. For the sake of brevity, it will not be repeated. In addition, it can be understood that Figure 18 The processor 1831 in interface board 1830 and / or the processor 1841 in interface board 1840 can be dedicated hardware or chips, such as a network processor or an application-specific integrated circuit, to implement the aforementioned functions. This implementation is commonly referred to as using dedicated hardware or chips for forwarding plane processing. In other embodiments, the processor 1831 and / or the processor 1841 in interface board 1840 can also be a general-purpose processor, such as a general-purpose CPU, to implement the aforementioned functions.

[0252] It should also be noted that there may be one or more main control boards, including a primary and backup main control board. There may also be one or more interface boards. The greater the data processing capabilities of the network device, the more interface boards are provided. With multiple interface boards, they can communicate with each other through one or more switching fabric boards, and when there are multiple boards, they can collectively implement load balancing and redundant backup. In a centralized forwarding architecture, the network device may not require a switching fabric board; the interface board handles the entire system's service data processing. In a distributed forwarding architecture, the network device includes multiple interface boards, which can exchange data between them through the switching fabric board, providing high-capacity data exchange and processing capabilities. Therefore, network devices with a distributed architecture have greater data access and processing capabilities than those with a centralized architecture. The specific architecture to adopt depends on the specific network deployment scenario and is not limited here.

[0253] In a specific embodiment, the memory 1832 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1832 can exist independently and be connected to the processor 1831 via a communication bus. The memory 1832 can also be integrated with the processor 1831.

[0254] The memory 1832 is used to store program codes, and is controlled by the processor 1831 to execute the routing introduction method provided in the above embodiment. The processor 1831 is used to execute the program codes stored in the memory 1832. The program codes may include one or more software modules. The one or more software modules may be the above Figure 16 and Figure 17 The functional modules provided in any embodiment.

[0255] In a specific embodiment, the network interface 1833 can be a device such as any transceiver for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.

[0256] Please refer to Figure 19 , which shows a hardware structure diagram of another network device 1900 provided in an embodiment of the present application. The network device 1900 can be the first network device in any of the above embodiments. The network device 1900 can be a switch, a router or other network device that forwards messages. Figure 19 The network device 1900 includes a processor 1902, a memory 1904, a communication interface 1906, and a bus 1908. The processor 1902, the memory 1904, and the communication interface 1906 are communicatively connected to each other via the bus 1908. It should be understood by those skilled in the art that Figure 19 The connection method between the processor 1902, memory 1904 and communication interface 1906 shown is merely exemplary. During implementation, the processor 1902, memory 1904 and communication interface 1906 may also be communicatively connected to each other using other connection methods besides the bus 1908.

[0257] Memory 1904 may be used to store a computer program 19042, which may include instructions and data. In embodiments of the present application, memory 1904 may be various types of storage media, such as RAM, ROM, non-volatile RAM (NVRAM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), flash memory, optical storage, and registers. Memory 1904 may include a hard disk and / or memory.

[0258] The processor 1902 may be a general-purpose processor. A general-purpose processor may be a processor that performs specific steps and / or operations by reading and executing a computer program (e.g., computer program 19042) stored in a memory (e.g., memory 1904). The general-purpose processor may use data stored in the memory (e.g., memory 1904) during the execution of the above steps and / or operations. The general-purpose processor may be, for example, but not limited to, a central processing unit (CPU). In addition, the processor 1902 may also be a special-purpose processor. A special-purpose processor may be a processor specially designed to perform specific steps and / or operations. The special-purpose processor may be, for example, but not limited to, a digital signal processor (DSP), an ASIC, and an FPGA. In addition, the processor 1902 may also be a combination of multiple processors, such as a multi-core processor. The processor 1902 may include at least one circuit to execute all or part of the steps of the route introduction method provided in the above embodiment.

[0259] The communication interface 1906 may include input / output (I / O) interfaces, physical interfaces, and logical interfaces, etc., for interconnecting components within the network device 1900, as well as interfaces for interconnecting the network device 1900 with other devices (e.g., network devices or user devices). The physical interface may be a gigabit Ethernet (GE) interface, which may be used to interconnect the network device 1900 with other devices (e.g., network devices or user devices). The logical interface is an interface within the network device 1900, which may be used to interconnect components within the network device 1900. It will be readily understood that the communication interface 1906 may be used for communication between the network device 1900 and other network devices and / or user devices. For example, the communication interface 1906 may be used to send and receive information between the network device 1900 and other network devices.

[0260] The bus 1908 may be any type of communication bus for interconnecting the processor 1902 , the memory 1904 , and the communication interface 1906 , such as a system bus.

[0261] The above-mentioned devices can be provided on separate chips, or at least partially or entirely on the same chip. Whether to provide each device independently on different chips or to integrate them on one or more chips often depends on the product design requirements. The embodiments of this application do not limit the specific implementation of the above-mentioned devices.

[0262] Figure 19The network device 1900 shown is only exemplary. During implementation, the network device 1900 may also include other components, which are not listed here. Figure 19 The network device 1900 shown can perform route introduction between VPN instances by executing all or part of the steps of the route introduction method provided in the above embodiment.

[0263] An embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the computer implements all or part of the steps of the route introduction method provided in the above method embodiment.

[0264] An embodiment of the present application provides a computer program product comprising instructions. When the computer program product is run on a computer, the computer is caused to execute all or part of the steps of the route introduction method provided in the above method embodiment.

[0265] An embodiment of the present application provides a chip, which includes a programmable logic circuit and / or program instructions, and when the chip is running, is used to implement all or part of the steps of the route introduction method provided in the above method embodiment.

[0266] The embodiment of the present application further provides a communication system, which includes at least two network devices, wherein a first network device of the at least two network devices is as follows: Figures 16 to 19 For any provided network device, the other network device among the at least two network devices is used to send routing information to the first network device, or to receive routing information sent by the first network device.

[0267] Optionally, the network device may be a PE device, and the communication system may be Figures 1 to 3 Optionally, the communication system further includes a user device (eg, VM) mounted on the network device. For example, Figure 1 As shown in the figure, VM11 and VM12 are mounted on PE1, VM21 is mounted on PE2, and VM31 is mounted on PE3.

[0268] Optionally, the communication system further includes a CE device, and the user equipment is mounted on the PE device through the CE device. Figure 2 As shown in the figure, VM11 and VM12 are mounted on PE1 through CE1, VM21 is mounted on PE2 through CE2, and VM31 is mounted on PE3 through CE3.

[0269] Optionally, the communication system further includes a GW device, and the user equipment CE device and the GW device are mounted under the PE device. Figure 3As shown in the figure, VM11 and VM12 are mounted on PE1 through CE1 and GW1, VM21 is mounted on PE2 through CE2 and GW2, and VM31 is mounted on PE3 through CE3 and GW3.

[0270] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product, which includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium, or a semiconductor medium (e.g., a solid-state hard disk).

[0271] The method embodiments and device embodiments provided in the embodiments of this application can refer to each other. The naming or numbering of steps in this application does not mean that the steps in the method flow must be executed in the time or logical sequence indicated by the naming or numbering. The execution order of the named or numbered process steps can be changed according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved.

[0272] In the corresponding embodiments provided in this application, it should be understood that the disclosed devices, etc. can be implemented through other structural methods. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.

[0273] The units described as separate components may or may not be physically separate, and the components described as units may or may not be physical units, and may be located in one place or distributed across multiple network devices (e.g., user equipment). Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0274] The above description is merely an exemplary embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and such modifications or substitutions should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A route introduction method, characterized in that: The method comprises: The first network device imports routing information of a first virtual private network (VPN) instance in the second network device from the first VPN instance to a second VPN instance in the first network device, where the routing information of the first VPN instance corresponds to a first outbound routing target (ERT) in the first VPN instance, and the first ERT matches an inbound routing target (IRT) in the second VPN instance. The first network device imports the routing information of the first VPN instance from the second VPN instance to a third VPN instance in the first network device; wherein the second ERT in the second VPN instance corresponds to the routing information of the first VPN instance in the second VPN instance, and the second ERT matches the IRT in the third VPN instance; or, the second VPN instance includes routing information matching the attribute information obtained by the first network device, and the routing information in the second VPN instance matching the attribute information includes the routing information of the first VPN instance in the second VPN instance.

2. The method according to claim 1, characterized in that The first network device importing the routing information of the first VPN instance from the second VPN instance to the third VPN instance includes: Determining, by the first network device, the second ERT in the second VPN instance; The first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance according to a match between the second ERT and the IRT in the third VPN instance.

3. The method according to claim 1, characterized in that The first network device importing the routing information of the first VPN instance from the second VPN instance to the third VPN instance includes: The first network device determines, based on the acquired attribute information, routing information in the second VPN instance that matches the attribute information; The first network device imports the routing information matching the attribute information in the second VPN instance from the second VPN instance to the third VPN instance.

4. The method according to claim 3, characterized in that The attribute information includes a route type and an identifier of the second VPN instance; and the first network device determines, based on the acquired attribute information, route information in the second VPN instance that matches the attribute information, including: The first network device determines, based on the route type and the identifier of the second VPN instance, routing information in the second VPN instance that matches the attribute information, where the routing information in the second VPN instance that matches the attribute information includes one or more routes of the route type in the second VPN instance, where the one or more routes include routing information of the first VPN instance.

5. The method according to any one of claims 1 to 4, characterized in that Before the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, the method further includes: The first network device allows, according to the acquired instruction, the import of the routing information of the first VPN instance from the second VPN instance into the third VPN instance.

6. The method according to any one of claims 1 to 4, characterized in that After the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, the method further includes: The first network device adds an import tag corresponding to the routing information of the first VPN instance in the third VPN instance, where the import tag is used to indicate that the routing information of the first VPN instance in the third VPN instance is imported from a local VPN instance of the first network device.

7. The method according to claim 6, characterized in that After the first network device adds an import tag corresponding to the routing information of the first VPN instance in the third VPN instance, the method further includes: The first network device determines, based on the introduction flag in the third VPN instance, not to introduce the routing information of the first VPN instance in the third VPN instance into a local VPN instance of the first network device.

8. The method according to any one of claims 1 to 4 and 7, characterized in that After the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, the method further includes: The first network device determines a third ERT in the third VPN instance, where the third ERT corresponds to routing information of the first VPN instance in the third VPN instance; The first network device determines not to introduce the routing information of the first VPN instance in the third VPN instance into the local VPN instance of the first network device based on the mismatch between the third ERT and the IRT in the local VPN instance of the first network device.

9. The method according to any one of claims 1 to 4 and 7, characterized in that: After the first network device imports the routing information of the first VPN instance from the second VPN instance to the third VPN instance, the method further includes: The first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance, where the routing information of the first VPN instance in the third VPN instance corresponds to a third ERT in the third VPN instance, and the third ERT is used to instruct the third network device to introduce the routing information of the first VPN instance from the third VPN instance to a fourth VPN instance in the third network device.

10. The method according to claim 9, characterized in that The first network device sending, through the third VPN instance, the routing information of the first VPN instance in the third VPN instance to the third network device, includes: The first network device sends the routing information of the first VPN instance in the third VPN instance to the third network device through the third VPN instance according to the external publishing function of the first network device.

11. The method according to any one of claims 1 to 4, 7 and 10, characterized in that: The first network device and the second network device are both operator edge PE devices.

12. A route introduction method, characterized in that: The method comprises: The first network device imports routing information of a first virtual private network VPN instance in the first network device from the first VPN instance to a second VPN instance in the first network device; The first network device sends the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance, where the routing information of the first VPN instance in the second VPN instance corresponds to a first egress routing target (ERT) in the second VPN instance, and the first ERT is used to instruct the second network device to import the routing information of the first VPN instance from the second VPN instance to a third VPN instance of the second network device.

13. The method according to claim 12, characterized in that The first network device importing the routing information of the first VPN instance from the first VPN instance to the second VPN instance includes: The first network device imports routing information of the first VPN instance from the first VPN instance to the second VPN instance based on a match between the second ERT in the first VPN instance and the inbound routing target IRT in the second VPN instance, where the second ERT corresponds to the routing information of the first VPN instance in the first VPN instance; or, The first network device determines, based on the acquired attribute information, routing information in the first VPN instance that matches the attribute information, and imports the routing information in the first VPN instance that matches the attribute information from the first VPN instance to the second VPN instance, where the routing information in the first VPN instance that matches the attribute information includes routing information of the first VPN instance in the first VPN instance.

14. The method according to claim 12, characterized in that The routing information of the first VPN instance is generated by the first VPN instance in the first network device; or, The routing information of the first VPN instance is learned by the first VPN instance in the first network device from a Border Gateway Protocol (BGP) neighbor of the first network device; or, The routing information of the first VPN instance is imported by the first VPN instance in the first network device from a fourth VPN instance in a Border Gateway Protocol Ethernet Virtual Private Network (BGP EVPN) neighbor of the first network device.

15. The method according to any one of claims 12 to 14, characterized in that Before the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the method further includes: The first network device allows, according to the acquired instruction, the routing information of the first VPN instance to be imported from the first VPN instance to the second VPN instance.

16. The method according to any one of claims 12 to 14, characterized in that After the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the method further includes: The first network device adds an import tag corresponding to the routing information of the first VPN instance in the second VPN instance, where the import tag is used to indicate that the routing information of the first VPN instance in the second VPN instance is imported from a local VPN instance of the first network device.

17. The method according to claim 16, characterized in that After the first network device adds an import tag corresponding to the routing information of the first VPN instance to the second VPN instance, the method further includes: The first network device determines, based on the introduction flag in the second VPN instance, not to introduce the routing information of the first VPN instance in the second VPN instance into a local VPN instance of the first network device.

18. The method according to any one of claims 12 to 14 and 17, characterized in that After the first network device imports the routing information of the first VPN instance from the first VPN instance to the second VPN instance, the method further includes: Determining, by the first network device, the first ERT in the second VPN instance; The first network device determines not to introduce the routing information of the first VPN instance in the second VPN instance into the local VPN instance of the first network device based on the mismatch between the first ERT and the IRT in the local VPN instance of the first network device.

19. The method according to any one of claims 12 to 14 and 17, characterized in that The first network device sending, through the second VPN instance, the routing information of the first VPN instance in the second VPN instance to the second network device, includes: The first network device sends the routing information of the first VPN instance in the second VPN instance to the second network device through the second VPN instance according to the external publishing function of the first network device.

20. The method according to any one of claims 12 to 14 and 17, characterized in that: The first network device and the second network device are both operator edge PE devices.

21. A network device, characterized in that: including memory and processor; The memory is used to store computer programs; The processor is configured to execute the computer program stored in the memory so that the network device executes the route introduction method according to any one of claims 1 to 11, or executes the route introduction method according to any one of claims 12 to 20.

22. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, enables a computer to implement the route introduction method according to any one of claims 1 to 11, or the route introduction method according to any one of claims 12 to 20.

23. A communication system, characterized in that: The communication system includes: a first network device and a second network device, the first network device is the network device according to claim 21, the second network device sends routing information of the first VPN instance to the first network device, or the first network device sends routing information of the first VPN instance to the second network device.

Citation Information

Patent Citations

  • Route insertion method and device

    CN106059882A