A method, apparatus and system for controlling traffic forwarding
Patent Information
- Application Number
- CN202011622415.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-21
- Filing Date
- 2020-12-30
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2040-12-30
AI Technical Summary
然而,在上述实现方式中,控制设备无法对转发路径进行干预和控制
[0038] Through the above scheme, the control device intervenes in and controls the forwarding path of the data stream to which the message belongs, based on the message sent by the network device; correspondingly, the network device forwards the message stream according to the forwarding policy and the intervention and control requirements of the control device.
Smart Images

Figure CN114389992B_ABST
Abstract
Description
[0001] This application claims priority to Chinese Patent Application No. CN202011133176.6, filed with the State Intellectual Property Office of China on October 21, 2020, entitled "A method, device and system for controlling traffic forwarding paths", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, and in particular to a method, device and system for controlling traffic forwarding. Background Technology
[0003] An underlay network is a distributed network without a central control node. Devices in an underlay network learn network reachability information through protocol transmission and each device decides how to forward data. This directly results in a lack of overall perspective and an inability to regulate traffic from the perspective of the entire network.
[0004] Overlay networking is a virtualization technology model that overlays virtualization onto an existing network architecture. The basic framework of an overlay network is to enable application transport on the network without large-scale modifications to the underlying network, and to separate it from other network services. An overlay network is a virtual network built on an existing network and consists of logical nodes and logical links. It has an independent control and forwarding plane, and the physical network is transparent to terminal systems connected to edge devices outside the overlay network. Deploying an overlay network allows for deep extension of the physical network to the cloud and virtualization, enabling cloud resource pooling capabilities to overcome the limitations of the physical network, which is key to achieving cloud-network convergence. An overlay network is also a network, but it is built on top of an underlay network. Nodes in an overlay network communicate through virtual or logical links. Each virtual or logical link corresponds to a path in the underlay network, consisting of multiple interconnected links.
[0005] Border Gateway Protocol (BGP) is a core decentralized autonomous routing protocol on the Internet. It achieves reachability between autonomous systems (AS) by maintaining Internet Protocol (IP) routing tables or 'prefix' tables, and is a vector routing protocol. The basic idea of Ethernet Virtual Private Network (EVPN) is to use BGP to learn Media Access Control (MAC) addresses at the control plane, thereby realizing Layer 2 Virtual Private Network (L2VPN) functionality.
[0006] In overlay network scenarios, the control device can proactively disseminate routing information to network devices via protocols, enabling the network devices to forward packets normally; for example, the BGP EVPN implementation. In another possible implementation, network devices can query routing information from the control device on demand, such as in implementations based on the Locator Identity Separation Protocol (LISP). However, in these implementations, the control device cannot intervene in or control the forwarding path. Summary of the Invention
[0007] This application provides a method, device, and system for controlling traffic forwarding paths, thereby enabling the control device to intervene in and control the forwarding path of the data stream to which the message belongs, based on the message sent by the network device.
[0008] Firstly, a method for controlling traffic forwarding is provided. A control device receives a first packet sent by a first network device. The first packet includes a first service packet, the destination of which is the control device, and the destination of the first service packet is a first user equipment (User Equipment). The first User Equipment is connected to the network via a second network device. Then, the control device determines a first forwarding policy based on the first packet and a first routing table entry. The first forwarding policy guides the forwarding of a first data flow to which the first service packet belongs. Furthermore, the control device sends the first forwarding policy to the first network device.
[0009] Based on the solution provided in this application embodiment, the control device intervenes in and controls the forwarding path of the data stream to which the packet belongs, according to the packet sent by the network device. The control device controls the path of the data stream sent by the network device based on the current network state by issuing forwarding policies. Optionally, the control device receives the first packet sent by the first network device via a first tunnel.
[0010] In one possible implementation of the first aspect, the control device determines a first forwarding policy based on the first packet and a first routing table entry, including: the control device determining that the destination of the first packet is the control device based on the destination address of the first packet; the control device determining the first routing table entry based on the destination address of the first service packet; and the control device determining the first forwarding policy based on the first routing table entry.
[0011] In another possible implementation of the first aspect, the first forwarding policy includes a second routing table entry, the second routing table entry including second address information and second next-hop information, the second address information being used to identify the first user equipment, and the second next-hop information being used to identify a third network device. The method further includes the control device sending a second forwarding policy to the third network device, the second forwarding policy including the first routing table entry. Optionally, before the control device determines the first forwarding policy based on the first message and the first routing table entry, the method further includes the control device determining link congestion or link failure from the first network device to the second network device based on the first message and the first routing table entry. Optionally, the third network device is a firewall.
[0012] In another possible implementation of the first aspect, before the control device receives the first message sent by the first network device, the method further includes the control device receiving first user equipment information sent by the second network device, the first user equipment information including the first address information and the first location information, the first location information indicating the first next-hop information; the control device determining the first routing table entry based on the first user equipment information. Optionally, the first user equipment information further includes at least one of the following: a second priority and a second virtual private network (VPN) identifier, the second priority indicating the priority of the first user equipment, and the second VPN identifier indicating the VPN to which the first user equipment belongs.
[0013] In another possible implementation of the first aspect, the control device forwards the first packet to the second network device according to the first routing table entry.
[0014] In another possible implementation of the first aspect, the control device receives a third message sent by the first network device, the third message including a third service message, the destination of the third message being the control device, the destination of the third service message being a second user equipment, and the second user equipment being connected to the network through the second network device; the control device determines that the destination of the third message is the control device based on the destination address of the third message; the control device determines a third routing table entry based on the destination address of the third service message, the third routing table entry including third address information and third next-hop information, the third address information being used to identify the second user equipment, and the third next-hop information being used to identify the second network device; the control device determines the session level from the third user equipment to the second user equipment based on the third service message, the source address of the third service message identifying the third user equipment; the control device blocks the sending of a third forwarding policy to the first network device based on the level, the third forwarding policy being used to guide the forwarding of the second data stream to which the third service message belongs. Optionally, the control device forwards the third message to the second network device based on the third routing table entry. Optionally, the control device receives the third message sent by the first network device via the first tunnel.
[0015] Secondly, a method for controlling traffic forwarding is provided. A first network device receives a first service packet sent by a third user equipment (User Equipment), the destination of which is the first User Equipment, and the first User Equipment is connected to the network through a second network device. Then, the first network device determines, based on the destination address of the first service packet, that it does not include a first routing table entry, which indicates the forwarding path of the first service packet. In response to the first network device determining that it does not include a first routing table entry, the first network device sends a first packet to a control device, the destination of which is the control device, and the first packet includes the first service packet. Furthermore, the first network device receives a first forwarding policy sent by the control device, the first forwarding policy being used to guide the forwarding of a first data stream to which the first service packet belongs.
[0016] Based on the solution provided in this application embodiment, when a network device determines that it cannot find a corresponding forwarding table entry, it sends the packet to a control device through a tunnel for processing. The control device, based on the packet sent by the network device, intervenes in and controls the forwarding path of the data stream to which the packet belongs. The control device controls the path of the data stream sent by the network device according to the current network state by issuing forwarding policies. Optionally, the first network device sends the first packet to the control device via a first tunnel.
[0017] In one possible implementation of the second aspect, before the first network device sends the first message to the control device, the method further includes the first network device generating the first message according to a default routing table entry, wherein the default routing table entry includes default address information and default next-hop information, and the default next-hop information is used to identify the control device. Optionally, the default address information includes a default IP address and a default mask, wherein the value of the default IP address is zero and the value of the default mask is 0. Optionally, the default address information includes a default MAC address, wherein the value of the default MAC address is zero.
[0018] In another possible implementation of the second aspect, the method further includes: the first network device receiving a second service message sent by the third user equipment, the destination of the second service message being the first user equipment; and the first network device sending the second service message to the second network device according to the first forwarding policy.
[0019] In another possible implementation of the second aspect, the first forwarding policy includes a second routing table entry, the second routing table entry including second address information and second next-hop information, the second address information being used to identify the first user equipment, and the second next-hop information being used to identify the third network device. Optionally, the method further includes the first network device receiving a second service packet sent by the third user equipment, the destination of the second service packet being the first user equipment; the first network device sending the second service packet to the third network device according to the first forwarding policy.
[0020] Optionally, in the first or second aspect described above, the first forwarding policy includes the first routing table entry.
[0021] Optionally, in the first or second aspect described above, the first forwarding policy may further include at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
[0022] Optionally, in the first or second aspect described above, the first tunnel is any of the following: a Virtual Extensible Local Area Network (VXLAN) tunnel, a Multi-Protocol Label Switching (MPLS) tunnel, a Segment Routing (SR) tunnel, and a Generic Routing Encapsulation (GRE) tunnel.
[0023] Optionally, in the first or second aspect described above, the network is a campus network, which includes the control device, the first network device, and the second network device, wherein the control device is a core network device, and the first network device and the second network device are edge network devices.
[0024] Another method for controlling traffic forwarding. A control device receives a third packet sent by a first network device. The third packet includes a third service packet, the destination of which is the control device, and the destination of the third service packet is a second user equipment (User Equipment), which is connected to the network through the second network device. The control device determines that the destination of the third packet is the control device based on its destination address. The control device determines a third routing table entry based on the destination address of the third service packet. The third routing table entry includes third address information and third next-hop information. The third address information identifies the second User Equipment, and the third next-hop information identifies the second network device. The control device determines the session level from the third User Equipment to the second User Equipment based on the third service packet, and the source address of the third service packet identifies the third User Equipment. The control device blocks the sending of a third forwarding policy to the first network device based on the session level. The third forwarding policy guides the forwarding of the second data stream to which the third service packet belongs. Optionally, the control device forwards the third packet to the second network device based on the third routing table entry. Optionally, the control device receives the third message sent by the first network device via the first tunnel.
[0025] Thirdly, a control device is provided, which has the function of controlling the behavior of the control device as described in the above method. The function can be implemented in hardware or in software executed from hardware. The hardware or software includes one or more modules corresponding to the above function.
[0026] In one possible design, the control device includes a processor and an interface. The processor is configured to support the control device in performing the corresponding functions described in the above-described methods. The interface supports communication between the control device and a first network device, receiving information or instructions involved in the above-described methods from the first network device. The interface also supports communication between the control device and other network devices. The control device may further include a memory coupled to the processor, which stores necessary program instructions and data for the control device.
[0027] In another possible design, the control device includes a processor, a transmitter, a receiver, random access memory (RAM), read-only memory (ROM), and a bus. The processor is coupled to the transmitter, receiver, RAM, and ROM via the bus. When the control device needs to be operated, it is booted via a basic input / output system embedded in the ROM or a bootloader in the embedded system, guiding the control device into normal operation. After the control device enters normal operation, an application program and action system are run in the RAM, causing the processor to execute the methods of the first aspect or any possible implementation thereof.
[0028] Fourthly, a control device is provided, comprising: a main control board and an interface board, and further, a switching network board. The control device is used to execute the methods of the first aspect or any possible implementation thereof. Specifically, the control device includes modules for executing the methods of the first aspect or any possible implementation thereof.
[0029] Fifthly, a control device is provided, comprising a controller and a first forwarding sub-device. The first forwarding sub-device includes an interface board, and further may include a switching network board. The first forwarding sub-device is used to perform the functions of the interface board in the fourth aspect, and further may also perform the functions of the switching network board in the fourth aspect. The controller includes a receiver, a processor, a transmitter, random access memory, read-only memory, and a bus. The processor is coupled to the receiver, transmitter, random access memory, and read-only memory via the bus. When the controller needs to be run, it is booted by a bootloader embedded in the read-only memory or a basic input / output system, or the bootloader of the embedded system, to guide the controller into normal operation. After the controller enters normal operation, an application program and an action system are run in the random access memory, enabling the processor to perform the functions of the main control board in the fourth aspect.
[0030] In a sixth aspect, a computer storage medium is provided for storing programs, code, or instructions used by the aforementioned control device, which, when executed by a processor or hardware device, can perform the functions or steps of the control device described in the first aspect.
[0031] In a seventh aspect, a first network device is provided, which has the function of implementing the behavior of the first network device in the above method. The function can be implemented in hardware or in software executed from hardware. The hardware or software includes one or more modules corresponding to the above function.
[0032] In one possible design, the first network device includes a processor and an interface. The processor is configured to support the first network device in performing the corresponding functions described in the above methods. The interface supports communication between the first network device and a control device, sending information or instructions involved in the above methods to the control device, or receiving information or instructions involved in the above methods from the control device. The interface also supports communication between the control device and other network devices and user equipment. The first network device may further include a memory coupled to the processor, which stores necessary program instructions and data for the first network device.
[0033] In another possible design, the first network device includes a processor, a transmitter, a receiver, random access memory (RAM), read-only memory (ROM), and a bus. The processor is coupled to the transmitter, receiver, RAM, and ROM via the bus. When the first network device needs to operate, it is booted by a bootloader embedded in the ROM or a basic input / output system, guiding the first network device into normal operation. After the first network device enters normal operation, an application program and action system are run in the RAM, causing the processor to execute the methods of the second aspect or any possible implementation thereof.
[0034] Eighthly, a first network device is provided, the first network device comprising: a main control board and an interface board, and further comprising a switching board. The first network device is used to execute the methods of the second aspect or any possible implementation thereof. Specifically, the first network device includes a module for executing the methods of the second aspect or any possible implementation thereof.
[0035] A ninth aspect provides a first network device, the first network device including a controller and a second forwarding sub-device. The second forwarding sub-device includes an interface board, and further may include a switching board. The second forwarding sub-device is used to perform the functions of the interface board in the eighth aspect, and further may also perform the functions of the switching board in the eighth aspect. The controller includes a receiver, a processor, a transmitter, random access memory, read-only memory, and a bus. The processor is coupled to the receiver, transmitter, random access memory, and read-only memory via the bus. When the controller needs to run, it is booted by a bootloader embedded in the read-only memory or a basic input / output system, guiding the controller into normal operation. After the controller enters normal operation, an application program and an action system are run in the random access memory, enabling the processor to perform the functions of the main control board in the eighth aspect.
[0036] In a tenth aspect, a computer storage medium is provided for storing programs, code, or instructions used by the first network device described above, which, when executed by a processor or hardware device, can perform the functions or steps of the first network device described in the second aspect.
[0037] Eleventhly, a network system is provided, the network system including a control device and a first network device, the control device being the control device of the aforementioned third, fourth, or fifth aspect, and the first network device being the first network device of the aforementioned seventh, eighth, or ninth aspect.
[0038] Through the above scheme, the control device intervenes in and controls the forwarding path of the data stream to which the message belongs, based on the message sent by the network device; correspondingly, the network device forwards the message stream according to the forwarding policy and the intervention and control requirements of the control device. Attached Figure Description
[0039] Figure 1 This is a schematic diagram of a communication network structure according to an embodiment of this application;
[0040] Figure 2 This is a flowchart of a traffic forwarding control method according to an embodiment of this application;
[0041] Figure 3 This is a schematic diagram of the structure of the first network device according to an embodiment of this application;
[0042] Figure 4 This is a schematic diagram of the hardware structure of the first network device according to an embodiment of this application;
[0043] Figure 5 This is a schematic diagram of the hardware structure of another first network device according to an embodiment of this application;
[0044] Figure 6 This is a schematic diagram of the structure of the second network device according to an embodiment of this application;
[0045] Figure 7 This is a schematic diagram of the hardware structure of the second network device according to an embodiment of this application;
[0046] Figure 8 This is a schematic diagram of the hardware structure of another second network device according to an embodiment of this application. Detailed Implementation
[0047] The technical solution of this application will be described in detail below through specific embodiments.
[0048] Figure 1 This is a schematic diagram of a communication network structure according to an embodiment of this application. The communication network can be, for example, a campus network. The communication network includes multiple network devices, which include a control device and multiple forwarding devices. The multiple forwarding devices include a first network device, a second network device, a third network device, and a fourth network device. The multiple forwarding devices can be switches or routers, and the control device can be a switch or a router. In one possible implementation, the control device can be a route reflector (RR). Figure 1In the scenario shown, the multiple forwarding devices can be edge network devices, such as edge switches or edge routers; the network devices can be core network devices, such as core switches or core routers. The control device communicates with each of the multiple forwarding devices via a communication link. Any two network devices among the multiple forwarding devices can communicate via a communication link. The communication link can be a wired link or a wireless link. The communication link can be a direct link or may include other network devices. Each network device among the multiple forwarding devices can connect to one or more user devices, for example... Figure 1 In this configuration, the first network device is connected to a third user device, and the second network device is connected to both the first and second user devices. Figure 1 The user equipment in this context can be a server, a virtual machine (VM), or a terminal device. Specifically, a terminal device can be a personal computer, laptop, smartphone, tablet, etc. The control device can be connected to an egress network device, which is used to communicate with other networks outside the communication network. For example, the control device receives traffic from the multiple forwarding devices and forwards it to other networks through the egress network device. Alternatively, the egress network device receives traffic from other networks and sends it to the multiple forwarding devices through the control device, with the traffic ultimately reaching the user equipment.
[0049] The control device can establish tunnels with the multiple forwarding devices. For example, a first tunnel exists between the control device and the first network device, a second tunnel exists between the control device and the second network device, a third tunnel exists between the control device and the third network device, and a fourth tunnel exists between the control device and the fourth network device. In a Virtual Extensible Local Area Network (VXLAN) scenario... Figure 1 The communication network shown is VXLAN, and the tunnel mentioned above can be a VXLAN tunnel. In a segment routing (SR) scenario, Figure 1 The communication network shown is an SR network, and the tunnel mentioned above can be an SR tunnel. In a multi-protocol label switching (MPLS) scenario, Figure 1 The communication network shown is an MPLS network, and the tunnel described above can be an MPLS-based tunnel. In the Generic Routing Encapsulation (GRE) protocol scenario, Figure 1 The communication network shown is a GRE network, and the tunnel mentioned above can be a GRE tunnel.
[0050] The control device includes the entire network topology of the communication network, that is, the control device stores the routing table entries of the entire communication network.
[0051] In one possible implementation, the control device can act as a route selector (RR) and establish peer relationships with the multiple forwarding devices based on BGP. For example, the control device establishes a peer relationship with the first network device, and the control device publishes routing table entries to the first network device based on BGP. Furthermore, when the topology of the communication network changes (e.g., a new forwarding device comes online, or an existing forwarding device goes offline), the control device can also publish routing table entries to the first network device based on BGP to notify of the routing change. The first network device updates its local routing table based on the received routing table entries. Thus, a network device can generate multiple forwarding table entries based on the routing table to guide traffic forwarding. These multiple forwarding table entries can be stored in the first network device's local forwarding table. Similarly, the control device can also publish routing table entries to the second, third, and fourth network devices. Optionally, the above implementation can be based on the BGP EVPN protocol.
[0052] In another possible implementation, the forwarding devices in the communication network can obtain the corresponding routes by querying routes on demand. Based on a LISP-based implementation, the control device acts as a server, and the multiple forwarding devices act as clients. For example, the first network device sends a request message (e.g., a map-request message) to the control device based on traffic received from the third user equipment. The request message requests the first network device to provide routing table entries for forwarding the traffic. The control device generates a corresponding response message (e.g., a map-reply message), which carries routing table entries for forwarding the traffic. The control device sends the response message to the first network device. The first network device updates its locally stored routing table based on the response message.
[0053] In the above implementations, the BGP-based approach requires the control device to publish a large number of routing table entries to the forwarding devices. Furthermore, the communication network may contain non-fixed user devices, such as mobile terminals accessing access points (APs) via Wireless Fidelity (Wi-Fi). The roaming of mobile terminals will restrict BGP route publication. In the LISP-based approach, the control device needs to complete the on-demand route query process based on request and response messages. Moreover, in both of these implementations, the control device publishes and queries routes based on stored routing table entries, and cannot intervene in or control the forwarding path of the data stream to which the packet belongs.
[0054] To address the above problems, this application proposes corresponding solutions. For example... Figure 1 As shown, a first network device receives a first service packet sent by a third user equipment. If the first network device does not find a matching forwarding entry in its forwarding table based on the destination address information of the first service packet, it encapsulates the first service packet according to a tunneling protocol to obtain a first packet. The first network device sends the first packet to the control device for processing. The control device generates a first forwarding policy based on the first packet and routing table entries stored in the control device. This first forwarding policy guides the forwarding of the first data flow to which the first service packet belongs. In generating the first forwarding policy, the control device considers not only the forwarding path of the first data flow based on the routing table entries stored in the control device, but also factors such as the current link quality and the security and privilege levels of the source user equipment of the first data flow. Therefore, the first forwarding policy generated by the control device can intervene in and control the forwarding path of the data flow to which the packet belongs. The control device sends the first forwarding policy to the first network device via a first tunnel. The first network device can update the routing table entries in its local routing table according to the first forwarding policy, and update the corresponding forwarding table entries based on the updated routing table entries. The first network device forwards the first data stream according to the updated forwarding table entries. Therefore, through the above implementation, the control device can intervene and control the forwarding path of the data stream to which the packet belongs based on the packet sent by the network device; correspondingly, the network device forwards the packet stream according to the forwarding policy and the intervention and control requirements of the control device.
[0055] Figure 2 This is a flowchart of a traffic forwarding control method according to an embodiment of this application. Figure 2The method shown can be applied to Figure 1 In the network structure shown. In the embodiments of this application, for Figure 1 The interaction between the first network device and the control device is described in the present invention. It should be understood that the communication link between the first network device and the control device may include other network devices. In the explanation of the embodiments of this application, the following are used: Figure 1 The communication network described is illustrated using VXLAN as an example. Accordingly, the tunnel between the first network device and the control device is a VXLAN tunnel. It should be understood that... Figure 2 The method described can also be applied to other overlay network scenarios, specifically, such as the aforementioned SR network, MPLS network, or GRE network. The method includes:
[0056] S101, the first network device receives a first service message sent by the third user equipment, the destination of the first service message being the first user equipment.
[0057] like Figure 1 As shown, a first network device can communicate with a third user equipment (User Equipment), and a second network device can communicate with the first User Equipment. The third User Equipment wishes to send traffic data to the first User Equipment. The third User Equipment encapsulates the traffic data to obtain a first service packet. The header of the first service packet includes a source address and a destination address. The source address identifies the third User Equipment and indicates the sending device of the first service packet. The source address can be an IP address, i.e., the source IP address; or the source address can be a MAC address, i.e., the source MAC address. The source IP address can be the device IP address of the third User Equipment, and the source MAC address can be the device MAC address of the third User Equipment. The destination address identifies the first User Equipment and indicates the receiving device of the first service packet. That is, the destination of the first service packet is the first User Equipment. The destination address can be an IP address, i.e., the destination IP address; or the destination address can be a MAC address, i.e., the destination MAC address. The destination IP address can be the device IP address of the first User Equipment, and the destination MAC address can be the device MAC address of the first User Equipment. The second network device connects to the first user equipment (User Equipment). Traffic destined for the first User Equipment needs to be forwarded through the second network device. Therefore, the next-hop device for the first User Equipment is the second network device. Specifically, the next-hop device mentioned above refers to the routing next-hop device; that is, the routing next-hop device for the first User Equipment is the second network device. In other words, the first User Equipment connects to the network through the second network device, and this network can be a campus network.
[0058] After generating the first service message, the third user equipment sends the first service message to the first network device. The first network device receives the first service message.
[0059] S102. The first network device determines that it does not include a first routing table entry based on the destination address of the first service message. The first routing table entry includes first address information and first next-hop information. The first address information is used to identify the first user equipment, and the first next-hop information is used to identify the second network device.
[0060] After receiving the first service packet, the first network device parses the first service packet. The first network device obtains the destination address from the first service packet. The first network device then looks up a forwarding table entry in the first network device based on the destination address of the first service packet.
[0061] If the first network device can find the corresponding forwarding table entry, it indicates that the first network device's local routing table includes a first routing table entry. The first routing table entry includes first address information and first next-hop information. The first address information identifies the first user equipment, and the first next-hop information identifies the second network device. Specifically, the first network device can match the first address information with the destination address of the first service packet. When the two match, the first network device can determine the corresponding first next-hop information. In this way, the first network device can encapsulate the first service packet according to the corresponding forwarding table entry and directly forward the encapsulated first service packet to the second network device. Therefore, after receiving the encapsulated first service packet, the second network device obtains the first service packet and forwards it to the first user equipment.
[0062] If the first network device does not find a corresponding forwarding table entry based on the destination address of the first service packet, the first network device can determine that the first network device does not include the first routing table entry.
[0063] In the implementation of this application, the address information can be an IPv4 address, an IPv6 address, a MAC address, or a segment identifier (SID) tag.
[0064] S103. The first network device sends a first message to the control device, the first message including the first service message. Optionally, the first network device sends the first message to the control device via a first tunnel.
[0065] As can be seen from step S102, the first network device determines that it does not include a first routing table entry based on the destination address of the first service packet. Therefore, the first network device will forward the first service packet to the control device through a first tunnel, where the first tunnel is a tunnel between the first network device and the control device. This application embodiment uses a VXLAN scenario as an example for explanation; therefore, in the following description, the first tunnel will be referred to as a first VXLAN tunnel.
[0066] The following section describes the specific implementation of the first network device forwarding the first service packet to the control device through the first VXLAN tunnel.
[0067] In a VXLAN scenario, the first network device is a VXLAN tunnel endpoint (VTEP) device, located at one end of the first VXLAN tunnel. The control device can act as a VTEP device, located at the other end of the first VXLAN tunnel. The first network device determines that it does not include a first routing table entry based on the destination address of the first service packet. The first network device encapsulates the first service packet to obtain a first packet. The first packet includes the first service packet and a first tunnel header. The first packet can be a VXLAN packet, and the first tunnel header can include a VXLAN header. The first tunnel header includes a source address and a destination address. The source address identifies the first network device and indicates the sending device of the first packet. The source address can be an IP address, i.e., a source IP address; or the source address can be a MAC address, i.e., a source MAC address. The source IP address can be the device IP address of the first network device, and the source MAC address can be the device MAC address of the first network device. The destination address identifies the control device and indicates the receiving device of the first packet. That is, the destination of the first packet is the control device. The destination address can be an IP address, i.e., the destination IP address; or the destination address can be a MAC address, i.e., the destination MAC address. The destination IP address can be the device IP address of the control device, and the destination MAC address can be the device MAC address of the control device. In a VXLAN scenario, the source and destination addresses are typically IP addresses, also known as VTEP addresses. After generating the first packet, the first network device sends the first packet to the control device via the first tunnel.
[0068] In the above implementation, rules can be configured in the first network device to cause it to forward a data packet to the control device via tunnel forwarding when it determines that a data packet cannot be matched with a routing table entry. For example, the first network device includes a default routing table entry, which includes default address information and default next-hop information. The default address information indicates the address information used when the first routing table entry is not found in the first network device. The default next-hop information is used to identify the control device. For example, the value of the default address information is set to all zeros, and the value of the default next-hop information is set to the address of the control device. After determining that the first routing table entry is not found, the first network device generates the first packet according to the default routing table entry and forwards the first packet to the control device. Specifically, after determining that the first routing table entry is not found, the first network device will determine that the destination address of the first service packet matches the default address information. Then, the first network device uses the default next-hop information as the destination address of the first packet, thereby obtaining the first packet. Thus, the first network device can send the first packet to the control device through the first tunnel.
[0069] In one possible implementation, the first network device can forward the first packet based on Layer 2 (physical layer) and according to the default routing table entry. In this case, the default routing table entry can be referred to as a default MAC routing table entry, which includes a default MAC address and the default next-hop information. The value of the default MAC address is zero.
[0070] In another possible implementation, the first network device can forward the first packet based on Layer 3 (network layer) and according to the default routing table entry. In this case, the default routing table entry can be referred to as a default IP routing table entry, which includes a default IP address, a default mask, and the default next-hop information. The default IP address has a value of zero, and the default mask has a value of zero. The default IP address and the default mask correspond to the aforementioned default address information.
[0071] S104. The control device receives the first message sent by the first network device. Optionally, the control device receives the first message sent by the first network device via the first tunnel.
[0072] For example, the control device receives the first message sent by the first network device via the first tunnel. In a VXLAN scenario, the first tunnel is a first VXLAN tunnel, the first message is a first VXLAN message, and the control device can act as a VTEP device of the first VXLAN tunnel to receive the first VXLAN message.
[0073] S105. The control device determines a first forwarding policy based on the first message and the first routing table entry. The first forwarding policy is used to guide the forwarding of the first data stream to which the first service message belongs.
[0074] After receiving the first message, the control device parses the first message to obtain a first service message. Further, the control device determines a first forwarding policy based on the first message and the first routing table entry. The first forwarding policy is used for forwarding the first data flow to which the first service message belongs. Therefore, the first network device can forward the first data flow according to the first forwarding policy. In this embodiment, a data flow can also be referred to as a service flow, i.e., the first data flow can also be referred to as the first service flow. The data flow includes multiple service messages. After the multiple service messages are sent by the user equipment to the network device, the network device encapsulates the multiple service messages to send the encapsulated messages through a tunnel. Since the encapsulated messages include service messages, the encapsulated messages can also be considered as messages belonging to the data flow.
[0075] Optionally, the control device can determine whether to send a first forwarding policy to the first network device based on the first message. Specifically, the control device determines whether to send a first forwarding policy to the first network device based on the destination address of the first message and the destination address of the first service message.
[0076] In one possible implementation, the control device determines that the destination of the first packet is itself based on the destination address of the first packet. Furthermore, the control device checks whether it stores the first routing table entry based on the destination address of the first service packet. If the control device stores the first routing table entry, it can determine that the next-hop device corresponding to the destination address of the first service packet is a second network device, not the control device itself. Thus, the control device determines that the network device indicated by the destination address of the first packet is inconsistent with the network device indicated by the first next-hop information in the first routing table entry. Therefore, the control device determines that the first forwarding policy needs to be sent to the first network device. That is, based on the above inconsistency determination, the control device can determine that the first network device generated and sent the first packet according to the default routing table entry. Then, the control device determines the first forwarding policy based on the first routing table entry. If the control device does not include the first routing table entry, it can determine that the first service packet is not forwarded to a user equipment within the communication network, but rather to a user equipment outside the communication network, such as a user equipment in another communication network. Thus, the control device determines that the first forwarding policy does not need to be sent to the first network device. The control device may follow a conventional forwarding process, via... Figure 1 The network device in the network forwards the first message to the outside of the communication network.
[0077] The first forwarding strategy determined by the control device will be explained below.
[0078] In one possible implementation, the first forwarding policy includes the first routing table entry. After determining that the first forwarding policy needs to be sent to the first network device, the control device generates the first forwarding policy based on the first routing table entry. Specifically, the control device determines, based on the first routing table entry and the source address of the first packet, that the first data flow to which the first service packet belongs is a data flow from the first network device to the second network device. Therefore, the control device can determine that the first link between the first network device and the second network device is used to transmit the first data flow. Then, the control device determines the link quality of the first link. The link quality may be information related to packet loss rate, congestion, faults, signal-to-noise ratio, or latency. For example, the control device can determine the link quality of the first link by establishing a Bidirectional Forwarding Detection (BFD) session between the first network device and the second network device. Then, the first network device and the second network device send BFD packets to each other. The first network device and the second network device perform link quality checks based on the BFD packets. After the detection, the first network device and the second network device report the detection results to the control device. Optionally, the first network device and the second network device can report the detection results based on BGP. The control device determines that the first link is capable of carrying the first data stream based on its link quality. For example, if the first link is not congested or fault-free, the control device determines that the first link can be used to transmit the first data stream. Alternatively, if the packet loss rate of the first link is below a threshold, the control device determines that the first link can be used to transmit the first data stream. After determining that the first link can be used to transmit the first data stream, the control device generates the first forwarding policy, which includes the first routing table entry.
[0079] In one possible implementation, the first forwarding policy includes a second routing table entry, which includes second address information and second next-hop information. The second address information is used to indicate the first user equipment, and the second next-hop information is used to identify the third network device. After determining that the first forwarding policy needs to be sent to the first network device, the control device generates the first forwarding policy based on the first routing table entry. Specifically, in conjunction with the above implementation, the control device determines that the first link does not meet the requirements for transmitting the first data stream based on the link quality of the first link. For example, if the first link is congested or faulty, the control device determines not to use the first link to transmit the first data stream. Another example is that if the packet loss rate of the first link is higher than a threshold, the control device determines not to use the first link to transmit the first data stream. The control device determines that the path from the first network device to the second network device also includes a backup path, which is the path from the first network device to the second network device via the third network device. Optionally, the control device can detect the link quality between the first network device and the third network device, and the link quality between the third network device and the second network device, according to the aforementioned testing method. When the link quality meets the requirements for transmitting the first data stream, the control device generates a corresponding routing table entry for the backup path. Specifically, the control device generates a second routing table entry, which includes second address information and second next-hop information. The second address information is used to identify the first user equipment, and the second next-hop information is used to identify the third network device. Then, the control device generates a first forwarding policy and a second forwarding policy, where the first forwarding policy includes the second routing table entry, and the second forwarding policy includes the first routing table entry. The control device then sends the first forwarding policy to the first network device and the second forwarding policy to the third network device. Thus, based on the first forwarding policy including the second routing table entry, packets belonging to the first data stream can be sent from the first network device to the third network device. Then, the third network device forwards packets belonging to the first data stream to the second network device according to the second forwarding policy including the first routing table entry. Therefore, the first data stream reaches the second network device via the backup path, and the second network device forwards the service traffic in the first data stream to the first user equipment. It should be understood that a variant implementation of the above method is that the control device determines the possible paths from the first network device to the second network device based on the first message, then detects the link quality of these paths, selects the path with the best link quality, determines the routing table entry, and sends the forwarding policy to the network device associated with the routing table entry.
[0080] In the above implementation, the control device determines to select the backup path to transmit the first data stream based on the link quality of the forwarding path, rather than selecting a link directly from the first network device to the second network device. In another possible implementation, the control device may not determine to select the backup path to transmit the first data stream based on the link quality of the forwarding path. After receiving the first packet, the control device determines that the first data stream originates from a network device with a lower security level. Furthermore, the third network device is a firewall. Therefore, the control device selects the backup path to transmit the first data stream so that the first data stream can pass through the firewall (third network device) before reaching the second network device.
[0081] In the above implementation, optionally, the first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first virtual private network (VPN) identifier, wherein the first priority indicates the priority at which the first network device sends the first data stream, the first rate indicates the rate at which the first network device sends the first data stream, and the first VPN identifier indicates the VPN to which the first user equipment belongs. The control device can not only carry routing table entries in the forwarding policy and send them to the network device, but also carry policy control parameters in the forwarding policy. The policy control parameters can be priority, rate, or VPN identifier. For example, based on the first packet, the control device determines that the first data stream is a video service with high real-time requirements. The control device increases the transmission rate of the first data stream by issuing a first forwarding policy carrying the first rate to the first network device. For example, based on the first packet, the control device determines the VPN to which the first user equipment belongs, and then carries the first VPN identifier in the first forwarding policy so that the first network device can send packets belonging to the first data stream according to the VPN identifier. In this application embodiment, the VPN identifier can be a VXLAN Network Identifier (VNI) or an EVPN identifier.
[0082] In the above implementation, the control device can send forwarding policies to the network device based on BGP messages.
[0083] In conjunction with the foregoing, the control device stores topology information so that it can generate corresponding routing table entries. Therefore, before the communication network in which the control device resides is operational, the control device collects user equipment information from each user device. Alternatively, during the operation of the communication network, the control device may also receive update messages carrying user equipment information. For example, before the control device receives a first message sent by a first network device via a first tunnel, the control device receives first user equipment information sent by a second network device. This first user equipment information includes first address information and first location information, where the first location information indicates the first next-hop information. Corresponding to the aforementioned implementation, the first user equipment information also includes at least one of the following: a second priority and a second VPN identifier, where the second priority indicates the priority of the first user device, and the second VPN identifier indicates the VPN to which the first user device belongs. In this way, the control device can obtain user equipment information from the user devices connected to the first network device, the second network device, the third network device, and the fourth network device. The control device generates corresponding routing table entries based on the obtained user equipment information from each user device. In one possible implementation, network devices can report user equipment information to the control device by sending BGP messages. Alternatively, the control device can obtain user device information for each user device from a Dynamic Host Configuration Protocol (DHCP) server; or the control device can obtain user device information for each user device based on data packet learning.
[0084] As described above, after the first network device receives the first service packet sent by the third user equipment, it cannot find a corresponding first routing table entry for the destination address of the first service packet. The first network device encapsulates the first service packet into a first packet and sends it to the control device via the first tunnel. Therefore, the first network device requests the control device to forward the first packet on its behalf. In conjunction with the foregoing, after receiving the first packet, the control device generates a first forwarding policy based on the first packet and sends the first forwarding policy to the first network device. Thus, the first forwarding policy can guide the first network device to send the first data stream. In this way, the first network device no longer needs to send packets from the first data stream to the control device, but instead sends the packets from the first data stream directly to the destination. Correspondingly, the control device forwards the first packet to the second network device according to the first routing table entry, thereby avoiding packet loss caused by the first network device's inability to find the first routing table entry.
[0085] For example, the first network device receives a second service message sent by the third user equipment, the destination of which is the first user equipment. The first network device then sends a second message to the second network device according to the first forwarding policy; this second message includes the second service message.
[0086] For example, the control device may select an alternative path for transmitting packets in the first data stream. In this case, the first network device receives a second service packet sent by the third user equipment, the destination of which is the first user equipment. The first network device sends a second packet, including the second service packet, to the third network device according to the first forwarding policy. Correspondingly, the third network device forwards the second packet to the second network device according to the second forwarding policy.
[0087] In conjunction with the foregoing, the control device can forward packets on behalf of the network device based on the session level, without sending forwarding policies to the network device. The session level can be the permission level or security level of the session from the packet's source to its destination. For example, the control device may consider the packet's source to be an insecure user equipment; or the control device may consider the user equipment as the packet's source to have a low permission level. In such cases, the control device will not send forwarding policies to the network device. For instance, the control device receives a third packet sent by the first network device via the first tunnel. This third packet includes a third service packet, the destination of which is the control device. The destination of this third service packet is a second user equipment, and the next-hop device for the second user equipment is a second network device. That is, the second user equipment connects to the network through the second network device, which can be a campus network. The control device determines that the destination of the third packet is itself based on the destination address of the third packet. The control device determines, based on the destination address of the third service packet, that it stores a third routing table entry. This third routing table entry includes third address information and third next-hop information. The third address information identifies the second user equipment, and the third next-hop information identifies the second network device. The control device determines the session level from the third user equipment to the second user equipment based on the third service packet, where the source address of the third service packet identifies the third user equipment. Based on the session level, the control device blocks the transmission of a third forwarding policy to the first network device. This third forwarding policy guides the forwarding of the second data stream to which the third service packet belongs.
[0088] Optionally, the network is a campus network, which includes the control device, the first network device, and the second network device. The control device is a core network device, such as a core switch or a core router. The first network device and the second network device are edge network devices, such as edge switches or edge routers.
[0089] In this implementation, when the control device sends a forwarding policy to the network device, the control device can use the address information of the receiving user equipment as an index. For example, the control device sends a first forwarding policy to the first network device. The first forwarding policy includes index information, which includes the address information of the first user equipment. After receiving the first forwarding policy, the first network device can determine, based on the index information, that the first forwarding policy is a forwarding policy sent to itself. Optionally, the index information may also include a VPN identifier.
[0090] Figure 3 This is a schematic diagram of the structure of the control device 1000 according to an embodiment of this application. Figure 3 The control device 1000 shown can perform the corresponding steps executed by the control device in the method of the above embodiments. The control device 1000 is deployed in a communication network, which also includes a first network device; optionally, the communication network further includes a second network device, a third network device, and a fourth network device. Figure 3 As shown, the control device 1000 includes a receiving unit 1002, a processing unit 1004, and a sending unit 1006.
[0091] The receiving unit 1002 is used to receive a first message sent by a first network device. The first message includes a first service message. The destination of the first message is the control device. The destination of the first service message is a first user equipment. The first user equipment is connected to the network through a second network device.
[0092] The processing unit 1004 is configured to determine a first forwarding policy based on the first packet and a first routing table entry. The first forwarding policy is used to guide the forwarding of the first data stream to which the first service packet belongs. The first routing table entry includes first address information and first next-hop information. The first address information is used to identify the first user equipment, and the first next-hop information is used to identify the second network device.
[0093] The sending unit 1006 is used to send the first forwarding policy to the first network device.
[0094] Optionally, the receiving unit 1002 is used to receive a first message sent by the first network device via the first tunnel.
[0095] Optionally, in the process of the processing unit 1004 determining the first forwarding policy based on the first packet and the first routing table entry, the processing unit 1004 is specifically used to: determine that the destination of the first packet is the control device based on the destination address of the first packet; determine the first routing table entry based on the destination address of the first service packet; and determine the first forwarding policy based on the first routing table entry.
[0096] Optionally, the first forwarding policy includes the first routing table entry.
[0097] Optionally, the first forwarding policy includes a second routing table entry, the second routing table entry includes second address information and second next-hop information, the second address information is used to identify the first user equipment, the second next-hop information is used to identify the third network device, and the sending unit 1006 is further used to send the second forwarding policy to the third network device, the second forwarding policy including the first routing table entry.
[0098] Optionally, before the processing unit 1004 determines the first forwarding policy based on the first message and the first routing table entry, the processing unit 1004 is further configured to determine link congestion or link failure from the first network device to the second network device based on the first message and the first routing table entry.
[0099] Optionally, the third network device is a firewall.
[0100] Optionally, the first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
[0101] Optionally, before the receiving unit 1002 receives the first message sent by the first network device, the receiving unit 1002 is further configured to receive first user equipment information sent by the second network device, the first user equipment information including the first address information and the first location information, the first location information indicating the first next hop information; the processing unit 1004 is further configured to determine the first routing table entry based on the first user equipment information.
[0102] Optionally, the first user equipment information may further include at least one of the following: a second priority and a second VPN identifier, wherein the second priority is used to indicate the priority of the first user equipment and the second VPN identifier is used to indicate the VPN to which the first user equipment belongs.
[0103] Optionally, the processing unit 1004 is further configured to forward the first packet to the second network device according to the first routing table entry.
[0104] Optionally, the receiving unit 1002 is further configured to receive a third message sent by the first network device, the third message including a third service message, the destination of the third message being the control device, the destination of the third service message being a second user equipment, and the second user equipment connecting to the network through the second network device; the processing unit 1004 is further configured to determine that the destination of the third message is the control device based on the destination address of the third message; the processing unit 1004 is further configured to determine a third routing table entry based on the destination address of the third service message, the third routing table entry including third address information and third next-hop information, the third address information being used to identify the second user equipment, and the third next-hop information being used to identify the second network device; the processing unit 1004 is further configured to determine the session level from the third user equipment to the second user equipment based on the third service message, the source address of the third service message identifying the third user equipment; the processing unit 1004 is further configured to block the sending of a third forwarding policy to the first network device based on the level, the third forwarding policy being used to guide the forwarding of the second data stream to which the third service message belongs. Optionally, the receiving unit 1002 is configured to receive a third message sent by the first network device via the first tunnel.
[0105] Optionally, the sending unit 1006 is further configured to forward the third message to the second network device according to the third routing table entry.
[0106] Optionally, the first tunnel is any of the following types of tunnels: VXLAN tunnel, MPLS-based tunnel, SR tunnel, and GRE tunnel.
[0107] Figure 3 The control device 1000 shown can execute the corresponding steps performed by the control device in the method of the above embodiments. Through the above implementation, the control device intervenes in and controls the forwarding path of the data stream to which the message belongs, based on the message sent by the network device. Correspondingly, the network device forwards the message stream according to the forwarding policy and the intervention and control requirements of the control device.
[0108] Figure 4 This is a schematic diagram of the hardware structure of the control device 1100 according to an embodiment of this application. Figure 4 The control device 1100 shown can perform the corresponding steps executed by the control device in the method of the above embodiments.
[0109] like Figure 4 As shown, the control device 1100 includes a processor 1101, a memory 1102, an interface 1103, and a bus 1104. The interface 1103 can be implemented wirelessly or via a wired connection. The processor 1101, memory 1102, and interface 1103 are connected via the bus 1104.
[0110] The interface 1103 may specifically include a transmitter and a receiver, used for sending and receiving information between the control device and the first network device in the above embodiments, and for sending and receiving information between the control device and the second or third network device in the above embodiments. For example, the interface 1103 is used to support receiving a first message sent by the first network device. Also, the interface 1103 is used to support sending a first forwarding policy to the first network device. As an example, the interface 1103 is used to support... Figure 2 The processes S104 and S106 are described above. The processor 1101 is used to execute the processes performed by the control device in the above embodiments. For example, the processor 1101 is used to execute processes for determining the first forwarding policy; and / or other processes for the techniques described herein. As an example, the processor 1101 is used to support... Figure 2 The process S105 is described above. Memory 1102 stores programs, code, or instructions, such as an action system 11021 and an application program 11022. When the processor or hardware device executes these programs, code, or instructions, the processing involving the control device in the method embodiment can be completed. Optionally, the memory 1102 may include read-only memory (ROM) and random access memory (RAM). The ROM includes a Basic Input / Output System (BIOS) or an embedded system; the RAM includes the application program and the action system. When the control device 1100 needs to be run, the system is booted via the BIOS embedded in the ROM or the bootloader in the embedded system, guiding the control device 1100 into normal operation. After the control device 1100 enters normal operation, the application program and the action system running in the RAM complete the processing involving the control device in the method embodiment.
[0111] Understandable Figure 4 Only a simplified design of the control device 1100 is shown. In practical applications, the control device can contain any number of interfaces, processors, or memory.
[0112] Figure 5 This is a schematic diagram of the hardware structure of another control device 1200 according to an embodiment of this application. Figure 5 The control device 1200 shown can perform the corresponding steps executed by the control device in the method of the above embodiments.
[0113] like Figure 5 The control device 1200 includes a main control board 1210, an interface board 1230, a switching network board 1220, and an interface board 1240. The main control board 1210, interface boards 1230 and 1240, and the switching network board 1220 are interconnected with the system backplane via a system bus. The main control board 1210 is used for system management, equipment maintenance, and protocol processing. The switching network board 1220 is used for data exchange between the interface boards (also called line cards or service boards). Interface boards 1230 and 1240 provide various service interfaces (e.g., POS interface, GE interface, ATM interface, etc.) and forward data packets.
[0114] The interface board 1230 may include a central processing unit 1231, a forwarding table entry memory 1234, a physical interface card 1233, and a network processor 1232. The central processing unit 1231 is used to control and manage the interface board and communicate with the central processing unit on the main control board. The forwarding table entry memory 1234 is used to store forwarding table entries. The physical interface card 1233 is used to receive and send traffic. The network memory 1232 is used to control the physical interface card 1233 to send and receive traffic according to the forwarding table entries.
[0115] Specifically, the physical interface card 1233 is used to receive the first message sent by the first user equipment. The physical interface card 1233 can also be used to send the first forwarding policy to the first network device.
[0116] After receiving the first message, the physical interface card 1233 sends the first message to the central processing unit 1231. The central processing unit 1231 determines that the first message needs to be processed by the central processing unit 1231 based on the information in the message header of the first message. Accordingly, the central processing unit 1231 processes the first message.
[0117] Optionally, after receiving the first message, the physical interface card 1233 sends the first message to the central processing unit 1231. The central processing unit 1231 determines that the first message needs to be processed by the central processing unit 1211 based on the information in the message header of the first message. The central processing unit 1231 then uploads the first message to the central processing unit 1211, which processes the first message.
[0118] The central processing unit 1231 is also configured to control the network memory 1232 to retrieve forwarding entries from the forwarding entry memory 1234, and the central processing unit 1231 is also configured to control the network memory 1232 to send the first forwarding policy to the first network device via the physical interface card 1233.
[0119] It should be understood that the actions on interface board 1240 in this embodiment of the invention are consistent with the actions on interface board 1230, and for the sake of simplicity, they will not be described again. It should be understood that the control device 1200 in this embodiment may correspond to the functions and / or various steps implemented in the above method embodiments, and will not be described again here.
[0120] Furthermore, it should be noted that there may be one or more main control boards, including a primary main control board and a backup main control board. There may also be one or more interface boards; the stronger the data processing capability of the control device, the more interface boards it provides. Each interface board may also have one or more physical interface cards. There may be no switching network board, or one or more; multiple boards can share the load for redundancy and backup. In a centralized forwarding architecture, the control device may not need a switching network board, as the interface boards handle the processing of the entire system's business data. In a distributed forwarding architecture, the control device can have at least one switching network board, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture control device are greater than those of a centralized architecture device. The specific architecture adopted depends on the specific network deployment scenario, and no restrictions are imposed here.
[0121] In addition, embodiments of this application provide a computer storage medium for storing computer software instructions used by the control device described above, which includes a program designed to execute the method embodiments described above.
[0122] Figure 6 This is a schematic diagram of the structure of the first network device 2000 according to an embodiment of this application. Figure 6 The first network device 2000 shown can perform the corresponding steps executed by the first network device in the method of the above embodiments. The first network device is deployed in a communication network, which also includes a control device, a second network device, a third network device, and a fourth network device. Figure 6 As shown, the first network device 2000 includes a receiving unit 2002, a processing unit 2004, and a sending unit 2006.
[0123] The receiving unit 2002 is used to receive a first service message sent by a third user equipment, the destination of the first service message being the first user equipment, and the first user equipment being connected to the network through a second network device.
[0124] The processing unit 2004 is configured to determine, based on the destination address of the first service packet, that the first network device does not include a first routing table entry, wherein the first routing table entry includes first address information, and the first address information is used to identify the first user equipment.
[0125] The sending unit 2006 is used to send a first message to the control device, the destination of the first message being the control device, and the first message including the first service message;
[0126] The receiving unit 2002 is further configured to receive a first forwarding policy sent by the control device, the first forwarding policy being used to guide the forwarding of the first data stream to which the first service message belongs.
[0127] Optionally, the sending unit 2006 is used to send a first message to the control device via the first tunnel.
[0128] Optionally, the first routing table entry may further include first next-hop information, which is used to identify the second network device.
[0129] Optionally, before the sending unit 2006 sends the first message to the control device, the processing unit 2004 is further configured to generate the first message according to a default routing table entry, wherein the default routing table entry includes default address information and default next-hop information, and the default next-hop information is used to identify the control device.
[0130] Optionally, the first forwarding policy includes the first routing table entry.
[0131] Optionally, the receiving unit 2002 is further configured to receive a second service message sent by the third user equipment, the destination of which is the first user equipment; the sending unit 2006 is further configured to send the second service message to the second network device according to the first forwarding policy.
[0132] Optionally, the first forwarding policy includes a second routing table entry, which includes second address information and second next-hop information. The second address information is used to identify the first user equipment, and the second next-hop information is used to identify the third network device.
[0133] Optionally, the receiving unit 2002 is further configured to receive a second service message sent by the third user equipment, the destination of which is the first user equipment; the sending unit 2006 is further configured to send the second service message to the third network device according to the first forwarding policy.
[0134] Optionally, the first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
[0135] Optionally, the default address information includes a default IP address and a default mask, wherein the value of the default IP address is zero and the value of the default mask is 0.
[0136] Optionally, the default address information includes a default MAC address, the value of which is zero.
[0137] Optionally, the first tunnel is any of the following types of tunnels: VXLAN tunnel, MPLS-based tunnel, SR tunnel, and GRE tunnel.
[0138] Figure 6 The first network device 2000 shown can execute the corresponding steps performed by the first network device in the method of the above embodiments. Through the above implementation, the control device intervenes in and controls the forwarding path of the data stream to which the message belongs, based on the message sent by the network device. Correspondingly, the network device forwards the message stream according to the forwarding policy and the intervention and control requirements of the control device.
[0139] Figure 7 This is a schematic diagram of the hardware structure of the first network device 2100 according to an embodiment of this application. Figure 7 The first network device 2100 shown can perform the corresponding steps executed by the first network device in the method of the above embodiments.
[0140] like Figure 7 As shown, the first network device 2100 includes a processor 2101, a memory 2102, an interface 2103, and a bus 2104. The interface 2103 can be implemented wirelessly or via a wired connection. The processor 2101, memory 2102, and interface 2103 are connected via the bus 2104.
[0141] The interface 2103 may specifically include a transmitter and a receiver, used for sending and receiving information or data between the first network device and the control device in the above embodiments. For example, the interface 2103 is used to support receiving a first service message sent by the third user equipment; the interface 2103 is also used to support sending the first message to the control device; the interface 2103 is also used to support receiving a first forwarding policy sent by the control device. As an example, the interface 2103 is used to support Figure 2The processes S101, S103, and S107 are described above. The processor 2101 is used to execute the processing performed by the first network device in the above embodiments. For example, the processor 2101 is used to determine whether the first network device includes a first routing table entry based on the destination address of the first service packet; the processor 2101 is used to generate a corresponding forwarding table entry according to a first forwarding policy; and / or other processes used in the technology described herein. As an example, the processor 2101 is used to support... Figure 2 The process S102 is described above. The memory 2102 includes an operating system 21021 and an application program 21022, used to store programs, code, or instructions. When the processor or hardware device executes these programs, code, or instructions, the processing involving the first network device in the method embodiment can be completed. Optionally, the memory 2102 may include read-only memory (ROM) and random access memory (RAM). The ROM includes a Basic Input / Output System (BIOS) or an embedded system; the RAM includes the application program and the operating system. When the first network device 2100 needs to be run, the system is booted through the BIOS embedded in the ROM or the bootloader in the embedded system, guiding the first network device 2100 into normal operation. After the first network device 2100 enters normal operation, the application program and the operating system running in the RAM complete the processing involving the first network device in the method embodiment.
[0142] Understandable Figure 7 Only a simplified design of the first network device 2100 is shown. In practical applications, the first network device can contain any number of interfaces, processors, or memory.
[0143] Figure 8 This is a schematic diagram of the hardware structure of another first network device 2200 according to an embodiment of this application. Figure 8 The first network device 2200 shown can perform the corresponding steps executed by the first network device in the method of the above embodiments.
[0144] like Figure 8The first network device 2200 includes a main control board 2210, an interface board 2230, a switching network board 2220, and an interface board 2240. The main control board 2210, interface boards 2230 and 2240, and the switching network board 2220 communicate with each other via a system bus connected to the system backplane. The main control board 2210 performs system management, equipment maintenance, and protocol processing functions. The switching network board 2220 performs data exchange between the interface boards (also called line cards or service boards). Interface boards 2230 and 2240 provide various service interfaces (e.g., POS interface, GE interface, ATM interface, etc.) and forward data packets. In one possible implementation, the first network device 2200 is a blade server.
[0145] The interface board 2230 may include a central processing unit 2231, a forwarding table entry memory 2234, a physical interface card 2233, and a network processor 2232. The central processing unit 2231 is used to control and manage the interface board and communicate with the central processing unit 2211 on the main control board 2210. The forwarding table entry memory 2234 is used to store forwarding table entries. The physical interface card 2233 is used to receive and send traffic. The network memory 2232 is used to control the physical interface card 2233 to send and receive traffic according to the forwarding table entries.
[0146] Specifically, the physical interface card 2233 is used to receive the first service message sent by the third user equipment. The physical interface card 2233 is also used to send the first message; the physical interface card 2233 is also used to receive the first forwarding policy.
[0147] After receiving the first service message, the physical interface card 2233 sends the first service message to the central processing unit 2231. The central processing unit 2231 determines that the first service message needs to be processed by the central processing unit 2231 based on the information in the header of the first service message. Accordingly, the central processing unit 2231 processes the first service message.
[0148] Optionally, after receiving the first service message, the physical interface card 2233 sends the first service message to the central processing unit 2231. The central processing unit 2231 determines that the first service message needs to be processed by the central processing unit 2211 based on the information in the header of the first service message. The central processing unit 2231 then uploads the first service message to the central processing unit 2211, which processes the first service message.
[0149] The central processing unit 2231 is also used to control the network memory 2232 to retrieve forwarding entries from the forwarding entry memory 2234, and the central processing unit 2231 is also used to control the network memory 2232 to complete the reception and transmission of traffic via the physical interface card 2233.
[0150] It should be understood that the actions on interface board 2240 in this embodiment are consistent with the actions on interface board 2230, and will not be described again for the sake of brevity. It should also be understood that the first network device 2200 in this embodiment may correspond to the functions and / or steps implemented in the above method embodiments, and will not be described again here.
[0151] Furthermore, it should be noted that there may be one or more main control boards, including a primary main control board and a backup main control board. There may also be one or more interface boards; the stronger the data processing capability of the first network device, the more interface boards it provides. Each interface board may also have one or more physical interface cards. There may be no switching network board, or one or more; multiple boards can share the load and provide redundancy. In a centralized forwarding architecture, the first network device may not need a switching network board, as the interface boards handle the entire system's business data processing. In a distributed forwarding architecture, the first network device can have at least one switching network board, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture first network device are greater than those of a centralized architecture device. The specific architecture adopted depends on the specific network deployment scenario, and no limitations are made here.
[0152] In addition, embodiments of this application provide a computer storage medium for storing computer software instructions used by the first network device described above, which includes a program designed to execute the method embodiments described above.
[0153] This application embodiment also includes a network system, the network system comprising a control device and a first network device, wherein the control device is the aforementioned... Figure 3 or Figure 4 or Figure 5 The control device in the middle, the first network device is the aforementioned Figure 6 or Figure 7 or Figure 8 The first network device in the system.
[0154] The steps of the methods or algorithms described in conjunction with the disclosure of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in RAM, flash memory, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEOROM), registers, hard disks, portable hard disks, compact disc read-only memory (CD-ROM), or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the ASIC can reside in a user equipment. Of course, the processor and storage medium can also exist as discrete components in the user equipment.
[0155] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in the embodiments of this application can be implemented in hardware or a combination of hardware and software. When implemented using a combination of hardware and software, the software can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transfer of a computer program from one place to another. Storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0156] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above descriptions are merely specific embodiments of this application.
Claims
1. A method for controlling traffic forwarding, characterized in that, The method includes: The control device receives a first message sent by a first network device. The first message includes a first service message. The destination of the first message is the control device. The destination of the first service message is a first user equipment. The first user equipment is connected to the network through a second network device. The control device determines that the destination of the first packet is the control device based on the destination address of the first packet; the control device determines a first routing table entry based on the destination address of the first service packet; the control device determines a first forwarding policy based on the first routing table entry, the first forwarding policy being used to guide the forwarding of the first data stream to which the first service packet belongs, the first routing table entry including first address information and first next-hop information, the first address information being used to identify the first user equipment, the first next-hop information being used to identify the second network device; the first routing table entry is stored in the control device; The control device sends the first forwarding policy to the first network device.
2. The method as described in claim 1, characterized in that, The first forwarding policy includes the first routing table entry.
3. The method as described in claim 1, characterized in that, The first forwarding policy includes a second routing table entry, the second routing table entry including second address information and second next-hop information, the second address information being used to identify the first user equipment, and the second next-hop information being used to identify a third network device. The method further includes: The control device sends a second forwarding policy to the third network device, the second forwarding policy including the first routing table entry.
4. The method as described in claim 3, characterized in that, Before the control device determines the first forwarding policy based on the first message and the first routing table entry, the method further includes: The control device determines whether the link from the first network device to the second network device is congested or faulty based on the first message and the first routing table entry.
5. The method as described in claim 3, characterized in that, The third network device is a firewall.
6. The method according to any one of claims 2-5, characterized in that, The first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
7. The method according to any one of claims 1-5, characterized in that, Before the control device receives the first message sent by the first network device, the method further includes: The control device receives first user equipment information sent by the second network device. The first user equipment information includes the first address information and the first location information, and the first location information indicates the first next hop information. The control device determines the first routing table entry based on the first user equipment information.
8. The method as described in claim 7, characterized in that, The first user equipment information further includes at least one of the following: a second priority and a second VPN identifier, wherein the second priority is used to indicate the priority of the first user equipment and the second VPN identifier is used to indicate the VPN to which the first user equipment belongs.
9. The method according to any one of claims 1-5, characterized in that, The method further includes: The control device forwards the first packet to the second network device according to the first routing table entry.
10. The method according to any one of claims 1-5, characterized in that, The method further includes: The control device receives a third message sent by the first network device. The third message includes a third service message. The destination of the third message is the control device. The destination of the third service message is a second user equipment. The second user equipment connects to the network through the second network device. The control device determines that the destination of the third message is the control device based on the destination address of the third message; The control device determines a third routing table entry based on the destination address of the third service message. The third routing table entry includes third address information and third next-hop information. The third address information is used to identify the second user equipment, and the third next-hop information is used to identify the second network device. The control device determines the session level from the third user equipment to the second user equipment based on the third service message, wherein the source address of the third service message identifies the third user equipment; The control device blocks the sending of a third forwarding policy to the first network device according to the level, and the third forwarding policy is used to guide the forwarding of the second data stream to which the third service packet belongs.
11. The method as described in claim 10, characterized in that, The method further includes: The control device forwards the third message to the second network device according to the third routing table entry.
12. The method according to any one of claims 1-5, characterized in that, The control device receives a first message sent by a first network device, including: the control device receives the first message sent by the first network device via a first tunnel, wherein the first tunnel is any of the following types of tunnels: Virtual Extended Local Area Network (VXLAN) tunnel, Multiprotocol Label Switching (MPLS) tunnel, Segmented Routing (SR) tunnel, and Generic Routing Encapsulation Protocol (GRE) tunnel.
13. The method according to any one of claims 1-5, characterized in that, The network is a campus network, which includes the control device, the first network device, and the second network device. The control device is a core network device, and the first and second network devices are edge network devices.
14. A method for controlling traffic forwarding, characterized in that, The method includes: The first network device receives a first service message sent by the third user equipment. The destination of the first service message is the first user equipment, and the first user equipment connects to the network through the second network device. The first network device determines that it does not include a first routing table entry based on the destination address of the first service packet. The first routing table entry includes first address information and next-hop address information. The first address information is used to identify the first user equipment, and the next-hop address information is used to identify the second network device. The first network device sends a first message to the control device, the destination of the first message being the control device, and the first message including the first service message; The first network device receives a first forwarding policy sent by the control device. The first forwarding policy is used to guide the forwarding of the first data stream to which the first service packet belongs. The first forwarding policy is determined by the control device based on the first routing table entry. The first routing table entry is determined by the control device based on the destination address of the first service packet. The first routing table entry is stored in the control device.
15. The method as described in claim 14, characterized in that, Before the first network device sends the first message to the control device, the method further includes: The first network device generates the first packet based on a default routing table entry, wherein the default routing table entry includes default address information and default next-hop information, and the default next-hop information is used to identify the control device.
16. The method as described in claim 14 or 15, characterized in that, The first forwarding policy includes the first routing table entry, and the first routing table entry further includes first next-hop information, which is used to identify the second network device.
17. The method as described in claim 16, characterized in that, The method further includes: The first network device receives a second service message sent by the third user equipment, the destination of which is the first user equipment; The first network device sends the second service message to the second network device according to the first forwarding policy.
18. The method as described in claim 14 or 15, characterized in that, The first forwarding policy includes a second routing table entry, which includes second address information and second next-hop information. The second address information is used to identify the first user equipment, and the second next-hop information is used to identify the third network device.
19. The method as described in claim 18, characterized in that, The method further includes: The first network device receives a second service message sent by the third user equipment, the destination of which is the first user equipment; The first network device sends the second service message to the third network device according to the first forwarding policy.
20. The method as described in claim 16, characterized in that, The first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
21. The method as described in claim 15, characterized in that, The default address information includes a default Internet Protocol (IP) address and a default subnet mask. The default IP address has a value of zero, and the default subnet mask has a value of 0.
22. The method as described in claim 15, characterized in that, The default address information includes a default media access control MAC address, and the value of the default MAC address is zero.
23. The method as described in claim 14 or 15, characterized in that, The first network device sends a first message to the control device, including sending the first message to the control device via a first tunnel, wherein the first tunnel is any one of the following tunnels: Virtual Extended Local Area Network (VXLAN) tunnel, Multiprotocol Label Switching (MPLS) tunnel, Segmented Routing (SR) tunnel, and Generic Routing Encapsulation Protocol (GRE) tunnel.
24. The method as described in claim 14 or 15, characterized in that, The network is a campus network, which includes the control device, the first network device, and the second network device. The control device is a core network device, and the first and second network devices are edge network devices.
25. A control device, characterized in that, The control device includes: The receiving unit is configured to receive a first message sent by a first network device, the first message including a first service message, the destination of the first message being the control device, the destination of the first service message being a first user equipment, and the first user equipment being connected to the network through a second network device. The processing unit is configured to determine that the destination of the first packet is the control device based on the destination address of the first packet; determine a first routing table entry based on the destination address of the first service packet; determine a first forwarding policy based on the first routing table entry, the first forwarding policy being used to guide the forwarding of the first data stream to which the first service packet belongs, the first routing table entry including first address information and first next-hop information, the first address information being used to identify the first user equipment, the first next-hop information being used to identify the second network device; the first routing table entry is stored in the control device; The sending unit is used to send the first forwarding policy to the first network device.
26. The control device as described in claim 25, characterized in that, The first forwarding policy includes the first routing table entry.
27. The control device as described in claim 25, characterized in that, The first forwarding policy includes a second routing table entry, which includes second address information and second next-hop information. The second address information is used to identify the first user equipment, and the second next-hop information is used to identify the third network device. The sending unit is further configured to send a second forwarding policy to the third network device, the second forwarding policy including the first routing table entry.
28. The control device as described in claim 27, characterized in that, Before the processing unit determines the first forwarding policy based on the first message and the first routing table entry, the processing unit is further configured to determine link congestion or link failure from the first network device to the second network device based on the first message and the first routing table entry.
29. The control device as described in any one of claims 26-28, characterized in that, The first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
30. The control device as described in any one of claims 25-28, characterized in that, Before the receiving unit receives the first message sent by the first network device, The receiving unit is further configured to receive first user equipment information sent by the second network device, the first user equipment information including the first address information and the first location information, the first location information indicating the first next hop information; The processing unit is further configured to determine the first routing table entry based on the first user equipment information.
31. The control device as described in claim 30, characterized in that, The first user equipment information further includes at least one of the following: a second priority and a second VPN identifier, wherein the second priority is used to indicate the priority of the first user equipment and the second VPN identifier is used to indicate the VPN to which the first user equipment belongs.
32. The control device as described in any one of claims 25-28, characterized in that, The processing unit is further configured to forward the first packet to the second network device according to the first routing table entry.
33. The control device as described in any one of claims 25-28, characterized in that, The receiving unit is further configured to receive a third message sent by the first network device, the third message including a third service message, the destination of the third message being the control device, the destination of the third service message being the second user equipment, and the second user equipment being connected to the network through the second network device; The processing unit is further configured to determine, based on the destination address of the third message, that the destination of the third message is the control device; The processing unit is further configured to determine a third routing table entry based on the destination address of the third service message. The third routing table entry includes third address information and third next-hop information. The third address information is used to identify the second user equipment, and the third next-hop information is used to identify the second network device. The processing unit is further configured to determine the session level from the third user equipment to the second user equipment based on the third service message, wherein the source address of the third service message identifies the third user equipment; The processing unit is further configured to block the transmission of a third forwarding policy to the first network device according to the level, the third forwarding policy being used to guide the forwarding of the second data stream to which the third service packet belongs.
34. The control device as described in claim 33, characterized in that, The sending unit is also configured to forward the third message to the second network device according to the third routing table entry.
35. A first network device, characterized in that, The first network device includes: The receiving unit is configured to receive a first service message sent by a third user equipment, wherein the destination of the first service message is the first user equipment, and the first user equipment is connected to the network through a second network device. The processing unit is configured to determine, based on the destination address of the first service packet, that the first network device does not include a first routing table entry, wherein the first routing table entry includes first address information and next-hop address information, the first address information being used to identify the first user equipment, and the next-hop address information being used to identify the second network device; A sending unit is configured to send a first message to a control device, wherein the destination of the first message is the control device, and the first message includes the first service message; The receiving unit is further configured to receive a first forwarding policy sent by the control device, the first forwarding policy being used to guide the forwarding of the first data stream to which the first service packet belongs; the first forwarding policy is determined by the control device based on the first routing table entry; the first routing table entry is determined by the control device based on the destination address of the first service packet; the first routing table entry is stored in the control device.
36. The first network device as described in claim 35, characterized in that, Before the sending unit sends the first message to the control device The processing unit is further configured to generate the first message based on a default routing table entry, wherein the default routing table entry includes default address information and default next-hop information, and the default next-hop information is used to identify the control device.
37. The first network device as described in claim 35 or 36, characterized in that, The first forwarding policy includes the first routing table entry, and the first routing table entry further includes first next-hop information, which is used to identify the second network device.
38. The first network device as described in claim 37, characterized in that, The receiving unit is further configured to receive a second service message sent by the third user equipment, wherein the destination of the second service message is the first user equipment; The sending unit is further configured to send the second service message to the second network device according to the first forwarding strategy.
39. The first network device as described in claim 35 or 36, characterized in that, The first forwarding policy includes a second routing table entry, which includes second address information and second next-hop information. The second address information is used to identify the first user equipment, and the second next-hop information is used to identify the third network device.
40. The first network device as claimed in claim 39, characterized in that, The receiving unit is further configured to receive a second service message sent by the third user equipment, wherein the destination of the second service message is the first user equipment; The sending unit is further configured to send the second service message to the third network device according to the first forwarding strategy.
41. The first network device as claimed in claim 37, characterized in that, The first forwarding policy further includes at least one of the following: a first priority, a first rate, and a first VPN identifier, wherein the first priority is used to indicate the priority at which the first network device sends the first data stream, the first rate is used to indicate the rate at which the first network device sends the first data stream, and the first VPN identifier is used to indicate the VPN to which the first user equipment belongs.
42. A communication network system, characterized in that, The communication network system includes a control device and a first network device, wherein the control device is the control device according to any one of claims 25-34, and the first network device is the first network device according to any one of claims 35-41.
Citation Information
Patent Citations
Method and equipment for processing flow table item in OpenFlow network
CN104348727A
Control method and device for data flow forwarding route
CN104660507A
Software-defined networking (SDN) data plane strip state exchange device, SDN exchange system and SDN data plane strip state forwarding and processing method
CN104836753A