A flow control method and related equipment

By carrying indication information in the BGP route announcement message to generate VRF table entries, the problem that PE devices in the existing technology cannot realize private network redirection and forwarding is solved, and flexible flow control and compatibility with various network scenarios are achieved.

CN115118659BActive Publication Date: 2025-09-19HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110475646.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-03-19
Filing Date
2021-04-29
Publication Date
2025-09-19
Estimated Expiration
2041-04-29

Smart Images

  • Figure CN115118659B_ABST
    Figure CN115118659B_ABST
Patent Text Reader

Abstract

The present application discloses a traffic control method and related equipment. A control management device notifies a PE device of a private network VPN route based on the VPNv4 or VPNv6 address family or the L3EVPN address family. The VPN route includes the IP address prefix of the destination host and the network address of the next hop to reach the IP address prefix, where the network address of the next hop is a private network IP address. Based on the VPN route, the PE device generates a VRF table entry including the IP address prefix and outbound interface information, where the outbound interface information identifies the outbound interface of the PE device connected to the next hop. In this way, the VPN route iterates to the private network next hop, and the control management device implements lightweight and flexible VPN route transmission to the PE device, enabling the PE device to support private network redirection and forwarding in a variety of different network scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on March 19, 2021, with application number CN202110305257.8 and application name “A Communication Method and Device”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a flow control method and related equipment. Background Art

[0003] According to the definition in Request for Comments (RFC) 4364, a control and management device advertises VPN routes to provider edge (PE) devices based on the VPNv4 address family, the VPNv6 address family, or the Layer 3 Ethernet virtual private network (L3EVPN) address family. Based on these VPN routes, the PE device can only iterate over the public network tunnel, forcing the PE device to forward received traffic only through this public network tunnel. With increasing network demands, this solution cannot provide flexible traffic control.

[0004] Based on this, it is urgent to provide a traffic control method, which can control the management device to send VPN routes for traffic control to PE devices in a lightweight and flexible manner, so that the traffic control of PE devices based on the VPN routes can be applicable to various network scenarios. Summary of the Invention

[0005] Based on this, an embodiment of the present application provides a traffic control method and related equipment, in which the VPN routes sent by the control management device to the PE device enable the PE device to support private network redirection and forwarding, thereby realizing lightweight and flexible control of the PE device by the control management device and achieving compatibility with various different network scenarios.

[0006] In a first aspect, an embodiment of the present application provides a traffic control method, in which a control management device can send a first Border Gateway Protocol (BGP) route announcement message to a first PE device, and announce a private network VPN route - a first VPN route - based on a VPNv4 or VPNv6 address family or an L3EVPN address family. The first VPN route may include indication information, an Internet Protocol (IP) address prefix of a destination host, and a network address of a first next hop to reach the IP address prefix, wherein the network address of the first next hop is a private network IP address; then, the first PE device that receives the first BGP route announcement message can generate a first virtual routing and forwarding (VRF) table entry according to the indication information, wherein the first VRF table entry includes the IP address prefix and a first outbound interface information, wherein the first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop. In this way, in this method, by carrying indication information in the VPN route announced using the VPNv4 address family, VPNv6 address family, or L3EVPN address family, the PE device is instructed to iterate to the next hop in the private network based on the VPN route. That is, the control and management device can send the VPN route for traffic control to the PE device in a lightweight and flexible manner, so that the traffic control of the PE device based on the VPN route can be applicable to a variety of different network scenarios. For example, the control and management device publishes the above-mentioned first VPN route to the PE device, so that when the PE device receives traffic whose destination address and the IP address prefix belong to the same network segment, it can forward the traffic to the first next hop based on the first outbound interface corresponding to the first outbound interface information in the first VRF table entry. This overcomes the problem that the VPN route currently published by the control and management device to the PE device only supports iteration to the public network tunnel, so that the PE device only supports forwarding the received traffic through the public network tunnel, and cannot support the private network redirection and forwarding function. Moreover, the VPN routes that enable PE devices to support private network redirection functions are published based on the existing VPN address family, without the need to use other address families (such as the FlowSpec address family), simplifying the network configuration and route publishing process, thereby enabling the control and management device to achieve lightweight and flexible traffic control of the PE device.

[0007] The first PE device generates the first VRF table entry according to the instruction information, which can also be understood as: the instruction information instructs the first PE device to generate the first VRF table entry.

[0008] As an example, the indication information in the first BGP route advertisement message may indicate that the network address of the first next hop is a private network IP address, or may indicate that the first VPN route is a private network route. Then, the first PE device generating a first VRF table entry based on the indication information may include: the first PE device searching for the corresponding private network based on the indication information, subscribing to first outbound interface information in the route management module based on the network address of the first next hop in the found private network; and then generating the first VRF table entry based on the first outbound interface information and the IP address prefix.

[0009] As another example, the indication information in the first BGP route advertisement message may also instruct the first PE device to determine, in a local VRF table, first outbound interface information for reaching the first next hop. This first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop. In this case, the first PE device generates a first VRF table entry based on the indication information without having to worry about whether the network address of the first next hop is a private IP address or whether the first VPN route is a private route. The first PE device only needs to determine, in the local VRF table, the first outbound interface information for reaching the first next hop as instructed by the indication information, to generate a first VRF table entry including the first outbound interface information and the IP address prefix.

[0010] In this way, the first PE device can cross traffic to the private network based on the first VPN route sent by the control management device, and generate a VRF table entry with the outbound interface information indicating the next hop in the private network, making it possible for the first PE device to support the private network redirection forwarding function.

[0011] As an example, the first BGP route announcement message includes a next-hop address field, and the indication information may be a route distinguisher RD included in the next-hop address field, where the RD is a non-zero value. In one case, if the destination host and the first next hop belong to the same VPN, the value of the RD field may be any non-zero value. In another case, if the destination host and the first next hop belong to different VPNs, the value of the RD field may be a non-zero value used to identify the VPN to which the first next hop belongs, so that the first PE device can accurately generate the first VRF table entry based on the RD field. In this way, after receiving the first BGP route announcement message, the first PE device can obtain the indication information and the network address of the first next hop by parsing the next-hop address field, making it possible for the first PE device to quickly process the first VPN route.

[0012] As another example, the indication information may also be carried through other fields. For example, an extended attribute may be included in the first BGP route advertisement message, and the extended attribute is used to carry the indication information. When the first BGP route advertisement message received by the first PE device includes the extended attribute, the first PE device may determine that the first BGP route advertisement message includes the indication information. Conversely, if the first BGP route advertisement message received by the first PE device does not include the extended attribute, the first PE device may determine that the first BGP route advertisement message does not include the indication information.

[0013] It should be noted that as long as the first PE device can identify the indication information after receiving the first BGP route announcement message and generate a first VRF table entry based on the indication information, the embodiment of the present application does not limit the way in which the indication information is carried in the first BGP route announcement message.

[0014] In one implementation, the first next hop can be a traffic cleaning server. This method is suitable for directing traffic to the traffic cleaning server for analysis and statistics, and for identifying traffic that poses security risks, such as attacks or tampering. In different scenarios, the traffic to be directed to the traffic cleaning server can be configured based on actual needs.

[0015] As an example, the destination host and the first next hop belong to the same VPN. Then, the first BGP route announcement message may include: the route distinguisher (English: Route Distinguisher, abbreviated: RD) of the same VPN as indication information. The first BGP route announcement message may also include a route target (English: Route-Target, abbreviated: RT). The values ​​of RD and RT may be the same or different. The first PE device stores the correspondence between the local RT and the private network. Then, after the first PE device receives the first BGP route announcement message, the first PE device parses the first BGP route announcement message to obtain the RT, and searches for the local RT that matches the RT, thereby crossing the first VPN route to the private network corresponding to the local RT; and the first PE device can also subscribe to the route management module to obtain the first output interface information through the network address of the first next hop in the first BGP route announcement message; thereby, the first PE device generates a first VRF table entry including the first output interface information in the private network crossed. The method provided in the embodiment of the present application controls the first VPN route published by the management device to enable the first PE device to forward traffic to the private network without crossing the private network, thereby realizing private network redirection forwarding.

[0016] As another example, the destination host and the first next hop belong to different VPNs. Then, the first BGP route advertisement message can include: an RD indicating the VPN to which the first next hop belongs, and an export route target (ERT), where the ERT corresponds to the VPN to which the destination host belongs. After receiving the first BGP route advertisement message, the first PE device can parse the first BGP route advertisement message to obtain the ERT and RD. The first PE device can then search for a local import route target (IRT) that matches the ERT, thereby cross-linking the first VPN route to the VPN corresponding to the local IRT. Furthermore, the first PE device can also subscribe to the first outbound interface information from the routing management module using the RD and next-hop network address in the first BGP route advertisement message. Thus, the first PE device can generate a first VRF table entry including the first outbound interface information in the VPN corresponding to the crossed destination host. It can be seen that the method provided in the embodiment of the present application, in which the first VPN route published by the control management device enables the first PE device to forward traffic to the private network even in a cross-private network scenario, thereby implementing private network redirection forwarding.

[0017] In the above example, for different VPNs, RD and RT can take the same value, so that the first VRF table entry can be accurately generated in the cross-VPN scenario. If the destination host belongs to the first VPN and the first next hop belongs to the second VPN, then the ERT in the first BGP route announcement message corresponds to the first VPN, and the RD corresponds to the second VPN. In this way, after the first PE device receives the first BGP route announcement message, it can cross the first VPN route to the first VPN based on RT (or ERT); then, the first PE device matches the VRF table of the second VPN through the value of RD, searches the VRF table of the second VPN for the first outbound interface information corresponding to the network address of the first next hop, and then adds the first outbound interface information and the first VRF table entry corresponding to the IP address prefix to the first VPN. In this way, since the CE device and the destination host both belong to the first VPN, when the first PE device receives traffic from the CE device, the interface receiving the traffic corresponds to the first VPN. Then, the first PE device will search the VRF table corresponding to the first VPN for the first VRF table entry that matches the destination address of the traffic, and guide the forwarding of the traffic based on the first outbound interface information in the first VRF table entry, and forward the traffic to the first next hop belonging to the second VPN.

[0018] In one implementation, after generating the first VRF table entry on the first PE device, the method may further include: the first PE device receives the first traffic sent by the first customer edge (English: Customer Edge, abbreviated as: CE) device, and the destination address of the first traffic and the IP address prefix belong to the same network segment; then, the first PE device can forward the first traffic to the first next hop through the first output interface. For example, when the first PE device receives the first traffic sent by the first CE device, it can determine the VPN to which the interface receiving the first traffic belongs, and search the VRF table of the VPN for the first VRF table entry whose IP address prefix belongs to the same network segment as the destination address of the first traffic. Thus, the first PE device obtains the first output interface information in the first VRF table entry, and sends the first traffic to the first next hop through the first output interface corresponding to the first output interface information. It can be seen that based on the method provided in the embodiment of the present application, the first VPN route issued by the control management device can enable the first PE device to forward traffic to the private network, thereby realizing private network redirection forwarding.

[0019] In one implementation, the first PE device may also receive a second BGP route advertisement message sent by the control and management device. The second BGP route advertisement message advertises a second VPN route. The first and second BGP route advertisement messages use the same VPN address family. The second VPN route includes an IP address prefix and the network address of a second next hop to the IP address prefix. The second next hop is a second PE device. The first PE device communicates with the second PE device via a public network tunnel. Thus, the first PE device generates a second VRF table entry based on the second BGP route advertisement message. The second VRF table entry includes the IP address prefix and second outbound interface information. The second outbound interface information is used to identify the second outbound interface of the first PE device corresponding to the public network tunnel. That is, the first PE device enters the public network tunnel via the second outbound interface. In this way, the control and management device can issue a second VPN route to the first PE device that supports iterating traffic to the public network tunnel, enabling the first PE device to forward traffic through the public network tunnel.

[0020] As an example, in this implementation, the first PE device generates a second VRF table entry based on the second VPN route. This may include: the first PE device determines the second outgoing interface information in a local VRF table; thereby, the first PE device generates the second VRF table entry based on the IP address prefix and the second outgoing interface information. The first PE device determines the second outgoing interface information in the local VRF table by iterating the public network tunnel based on the second VPN route and determining the second outgoing interface information corresponding to the public network tunnel to the second next hop in the local VRF table. In this way, based on the second VPN route sent by the control and management device, the first PE device can cross traffic to the public network tunnel and generate a second VRF table entry with outgoing interface information indicating the public network tunnel, enabling the first PE device to support iteration to the public network tunnel. That is, when the first PE device receives traffic whose destination address belongs to the same network segment as the IP address prefix, it can forward the traffic to the public network tunnel based on the second outgoing interface information in the second VRF table entry.

[0021] In one implementation, in a scenario where traffic is directed to the first next hop, the first PE device may include two different modes: Mode 1, redirection, and Mode 2, traffic replication.

[0022] As an example, if the first PE device supports mode 1, only the first VRF table entry can be generated on the first PE device. Then, after the first PE device receives traffic whose destination address and IP address prefix belong to the same network segment, it directly forwards the traffic from the first outbound interface to the first next hop according to the first VRF table entry.

[0023] As another example, if the first PE device supports Mode 2, the first PE device can generate a first VRF entry and a second VRF entry. The method can also include: the first PE device receives and copies the second traffic sent by the second CE device to obtain third traffic; thereby, forwarding the second traffic to the first next hop via the first outbound interface, and forwarding the third traffic to the second PE device via the second outbound interface. This achieves the goal of forwarding traffic destined for the private network through both the private and public network tunnels.

[0024] In one implementation, if the first PE device and the destination host are connected via a first path and a second path, respectively, and the first path includes a first next hop, then the method may further include implementing load balancing or active / standby safe switching of traffic between the first PE device and the destination host. For example, if the first PE device receives fourth traffic sent by a third CE device to the destination host, the fourth traffic may be load balanced via the first path and the second path. For another example, if both paths are fault-free, the first path serves as the working path, and the first PE device may send the received traffic to the first next hop via the private network based on the first outgoing interface corresponding to the first outgoing interface information in the first VRF table entry, and the first next hop then forwards the traffic to the destination host. If the first path fails, the first PE device may use the second path as the working path, and at this time, the first PE device may send the received traffic to the destination host via the public network tunnel based on the second outgoing interface corresponding to the second outgoing interface information in the second VRF table entry.

[0025] In one implementation, the first PE device may be a first Autonomous System Boundary Router (ASBR), the first next hop being a second ASBR, a private network interface and a public network interface between the first ASBR and the second ASBR, the first ASBR reaching the IP address prefix through the second ASBR, and the first outbound interface being the private network interface connecting the first ASBR to the second ASBR. In this scenario, the method provided in this embodiment of the present application may further include: the first ASBR receiving fifth traffic, where the destination address of the fifth traffic and the IP address prefix belong to the same network segment; then, the first ASBR forwarding the fifth traffic to the second ASBR via the first outbound interface. This scenario may be referred to as Option D, for example. In the current Option D scenario, ASBRs need to apply for private network labels for themselves before forwarding traffic across domains, and send the applied private network labels to the other ASBR. When forwarding traffic between ASBRs, the next hop address needs to be modified to the private network label of the other ASBR. However, based on the technical solution provided in the embodiment of the present application, the first VPN route issued by the control management device can enable the first PE device to directly forward traffic through the private network interface to the PE device of another domain based on the first VRF table entry, without applying for a private network label for itself, and without exchanging private network labels during cross-domain forwarding, thereby saving private network label resources and the workload of label exchange.

[0026] In the second aspect, an embodiment of the present application also provides a traffic control method, which is executed by a control and management device. The method may, for example, include: the control and management device generates a first BGP route announcement message, and sends the first BGP route announcement message to the first PE device, wherein the first BGP route announcement message announces the first VPN route based on the VPNv4 address family or the VPNv6 address family or the L3EVPN address family, and the first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix, wherein the indication information is used to instruct the first PE device to generate a first VRF table entry, the first VRF table entry includes the IP address prefix and the first output interface information, and the first output interface information is used to identify the first output interface of the first PE device connected to the first next hop. In this way, in this method, the control and management device carries indication information in the VPN route announced using the VPNv4 address family, the VPNv6 address family, or the L3EVPN address family, instructing the PE device to iterate to the next hop in the private network based on the VPN route, thereby achieving the purpose of lightweight and flexible sending of VPN routes for traffic control to the PE device, so that the traffic control of the PE device based on the VPN route can be applied to a variety of different network scenarios, such as enabling the PE device to support private network redirection and forwarding functions.

[0027] In one implementation, the first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, where the RD is a non-zero value. For example, the RD is used to identify the VPN to which the first next hop belongs.

[0028] In one implementation, the first next hop may be a traffic cleaning server.

[0029] In one implementation, the destination host and the first next hop may belong to the same VPN, or they may belong to different VPNs.

[0030] In one implementation, the method may further include: the control management device generating a second BGP route advertisement message; and the control management device sending the second BGP route advertisement message to the first PE device, wherein the second BGP route advertisement message announces a second VPN route, the first BGP route advertisement message and the second BGP route advertisement message use the same VPN address family, the second VPN route includes an IP address prefix and a network address of a second next hop to reach the IP address prefix, the second next hop being a second PE device, the first PE device communicating with the second PE device via a public network tunnel, the second BGP route advertisement message instructing the first PE device to generate a second VRF table entry, the second VRF table entry including the IP address prefix and second outbound interface information, the second outbound interface information identifying the second outbound interface of the first PE device corresponding to the public network tunnel, i.e., the first PE device enters the public network tunnel via the second outbound interface. In this way, the control management device can enable the first PE device to forward traffic via the public network tunnel by issuing the second VPN route supporting traffic iteration to the public network tunnel to the first PE device.

[0031] In a third aspect, an embodiment of the present application further provides a flow control device, which is applied to a first PE device, and the device may include: a receiving unit and a generating unit. The receiving unit is used to receive a first Border Gateway Protocol (BGP) route announcement message sent by a control and management device, the first BGP route announcement message being based on the fourth version of the Virtual Private Network (VPNv4) address family or the sixth version of the Virtual Private Network (VPNv6) address family or the Layer 3 Ethernet Virtual Private Network (L3EVPN) address family to announce a first VPN route, the first VPN route including indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix; the generating unit is used to generate a first virtual route forwarding (VRF) table entry according to the indication information, the first VRF table entry including the IP address prefix and the first outbound interface information, wherein the first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop.

[0032] The generating of the first VRF table entry according to the instruction information may also be expressed as: the instruction information instructs the first PE device to generate the first VRF table entry.

[0033] Among them, the indication information in the first BGP route announcement message can indicate that the network address of the first next hop is a private network IP address, or it can also indicate that the first VPN route is a private network route; or, the indication information can also indicate that the first PE device determines the first output interface information to reach the first next hop in the local VRF table, and the first output interface information is used to identify the output interface of the PE device connected to the next hop.

[0034] In one implementation, the generating unit may include: a first determining subunit and a first generating subunit. The first determining subunit is configured to determine, in a local VRF table, first outbound interface information for reaching the first next hop based on the indication information and the network address of the first next hop; and the first generating subunit is configured to generate a first VRF table entry based on the IP address prefix and the first outbound interface information.

[0035] In one implementation, the first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, where the RD is a non-zero value. For example, the RD is used to identify the VPN to which the first next hop belongs.

[0036] In one implementation, the first next hop is a traffic cleaning server.

[0037] In one implementation, the destination host and the first next hop may belong to the same VPN, or they may belong to different VPNs.

[0038] In one implementation, the receiving unit in the device is also used to receive the first traffic sent by the first user edge CE device, and the destination address of the first traffic and the IP address prefix belong to the same network segment; then, the device may also include: a first sending unit, which is used to forward the first traffic to the first next hop through the first output interface.

[0039] In one implementation, the receiving unit in the device is also used to receive a second BGP route announcement message sent by the control and management device, the second BGP route announcement message announces the second VPN route, the first BGP route announcement message and the second BGP route announcement message use the same VPN address family, the second VPN route includes an IP address prefix, and the network address of the second next hop to reach the IP address prefix, the second next hop is a second PE device, and the first PE device communicates with the second PE device through a public network tunnel; the generating unit is also used to generate a second VRF table entry based on the second BGP route announcement message, the second VRF table entry includes the IP address prefix and second outbound interface information, the second outbound interface information is used to identify the second outbound interface of the first PE device corresponding to the public network tunnel, that is, the first PE device enters the public network tunnel through the second outbound interface.

[0040] In one implementation, the generating unit may further include: a second determining subunit and a second generating subunit, wherein the second determining subunit is configured to determine the second outgoing interface information in the local VRF table; and the second generating subunit is configured to generate a second VRF table entry based on the IP address prefix and the second outgoing interface information.

[0041] In one implementation, the receiving unit in the device is also used to receive the second traffic sent by the second CE device; then, the device may also include: a copying unit and a second sending unit, wherein the copying unit is used to copy the second traffic to obtain the third traffic; the second sending unit is used to forward the second traffic to the first next hop through the first output interface; the second sending unit is also used to forward the third traffic to the second PE device through the second output interface.

[0042] In one implementation, a first PE device is connected to a destination host via a first path and a second path, respectively, where the first path includes a first next hop. The receiving unit in the apparatus is further configured to receive fourth traffic sent by a third CE device. The apparatus may further include a third sending unit configured to load balance the fourth traffic via the first path and the second path.

[0043] In one implementation, the first PE device is a first ASBR, the first next hop is a second ASBR, and the first outbound interface is a private network interface connecting the first ASBR to the second ASBR. The receiving unit in the apparatus is further configured to receive fifth traffic, where the destination address of the fifth traffic and the IP address prefix belong to the same network segment; and the apparatus further includes a fourth sending unit configured to forward the fifth traffic to the second ASBR via the first outbound interface.

[0044] It should be noted that the specific implementation method and effect achieved by the flow control device provided in the third aspect of the embodiment of the present application can be found in the relevant description of the embodiment shown in the first aspect above, and will not be repeated here.

[0045] In a fourth aspect, an embodiment of the present application further provides a flow control device, which is applied to a control management device, and the device may include: a generating unit and a sending unit. The generating unit is used to generate a first BGP route announcement message; the sending unit is used to send the first BGP route announcement message to the first operator edge PE device, wherein the first BGP route announcement message is based on the fourth version of the virtual private network VPNv4 address family or the sixth version of the virtual private network VPNv6 address family or the three-layer Ethernet virtual private network L3EVPN address family to announce the first VPN route, the first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix, the indication information is used to instruct the first PE device to generate a first virtual route forwarding VRF table entry, the first VRF table entry includes the IP address prefix and the first outbound interface information, and the first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop.

[0046] In one implementation, the first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, where the RD is a non-zero value. For example, the RD is used to identify the VPN to which the first next hop belongs.

[0047] In one implementation, the first next hop is a traffic cleaning server.

[0048] In one implementation, the destination host and the first next hop may belong to the same VPN, or they may belong to different VPNs.

[0049] In one implementation, the generating unit in the apparatus is further configured to generate a second BGP route announcement message; the sending unit is further configured to send the second BGP route announcement message to the first PE device, wherein the second BGP route announcement message announces the second VPN route, the first BGP route announcement message and the second BGP route announcement message use the same VPN address family, the second VPN route includes an IP address prefix and a network address of a second next hop to reach the IP address prefix, the second next hop is a second PE device, the first PE device communicates with the second PE device through a public network tunnel, the second BGP route announcement message is used to instruct the first PE device to generate a second VRF table entry, the second VRF table entry includes an IP address prefix and second outgoing interface information, the second outgoing interface information is used to identify the second outgoing interface of the first PE device corresponding to the public network tunnel, that is, the first PE device enters the public network tunnel through the second outgoing interface.

[0050] It should be noted that the specific implementation method and effect achieved by the flow control device provided in the fourth aspect of the embodiment of the present application can be found in the relevant description of the embodiment shown in the above second aspect, and will not be repeated here.

[0051] In a fifth aspect, the present application provides a communication device, comprising a memory and a processor; the memory is used to store program code; the processor is used to run instructions in the program code, so that the communication device executes the method described in the first aspect and any one of the first aspects above, or the communication device executes the method described in the second aspect and any one of the second aspects above.

[0052] In the sixth aspect, the present application provides a communication system, which includes a first PE device and a control and management device; wherein the first PE device is used to execute the method described in the first aspect and any one of the first aspects above; the control and management device is used to execute the method described in the second aspect and any one of the second aspects above.

[0053] In the seventh aspect, the present application provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computer, it enables the computer to execute the method described in the first aspect and any one of the first aspects above, or enables the computer to execute the method described in the second aspect and any one of the second aspects above.

[0054] In an eighth aspect, the present application provides a computer program product, comprising a program, which, when running on a processor, implements the method described in the first aspect and any one of the first aspects, or implements the method described in the second aspect and any one of the second aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0056] Figure 1a A schematic diagram of a network framework involved in an application scenario provided in an embodiment of the present application;

[0057] Figure 1b A schematic diagram of a network framework involved in another application scenario provided in an embodiment of the present application;

[0058] Figure 1c A schematic diagram of a network framework involved in another application scenario provided in an embodiment of the present application;

[0059] Figure 1d A schematic diagram of a network framework involved in another application scenario provided in an embodiment of the present application;

[0060] Figure 2a A schematic diagram of the current MP_REACH_NLRI format;

[0061] Figure 2b A schematic diagram of a format of an MP_REACH_NLRI provided in an embodiment of the present application;

[0062] Figure 3 A flow chart of a flow control method 100 provided in an embodiment of the present application;

[0063] Figure 4 A flow chart of another flow control method 200 provided in an embodiment of the present application;

[0064] Figure 5 A schematic structural diagram of a flow control device 500 provided in an embodiment of the present application;

[0065] Figure 6 A schematic structural diagram of a flow control device 600 provided in an embodiment of the present application;

[0066] Figure 7 A schematic structural diagram of a communication device 700 provided in an embodiment of the present application;

[0067] Figure 8 A schematic structural diagram of a communication system 800 provided in an embodiment of the present application. DETAILED DESCRIPTION

[0068] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings. The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions in the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0069] In this application, ordinal numbers such as "1", "2", "3", "first", "second" and "third" are used to distinguish multiple objects and are not used to limit the order of multiple objects.

[0070] “A and / or B” mentioned in this application should be understood to include the following situations: only A, only B, or both A and B.

[0071] The routing forwarding table entries that guide the forwarding behavior of the PE device can be generated by the PE device based on the routes published to it by the control management device, or can be determined by the PE device based on the access control list (English: Access-control list, abbreviated as: ACL) manually configured on the PE device. Considering that the ACL is manually configured on the PE device, the control management device cannot manipulate the forwarding behavior of the PE device. Therefore, the technical solutions involved in the embodiments of the present application are all that the control management device publishes routes to the PE device to guide the forwarding behavior of the PE device.

[0072] Currently, in one scenario, a control and management device can publish flow specification (FlowSpec) routes to PE devices, instructing them to adjust traffic forwarding based on the FlowSpec routes. However, this requires establishing a FlowSpec neighbor relationship between the control and management device and the PE devices, and the control and management device must publish FlowSpec routes to the PE devices based on the FlowSpec address family, making the process relatively complex. For example, both the control and management device and the PE devices must support not only the conventional VPNv4, VPNv6, or L3EVPN address family, but also the FlowSpec address family. In another scenario, the control and management device can advertise VPN routes to the PE devices based on the VPNv4, VPNv6, or L3EVPN address family. However, the PE devices can only iterate over public network tunnels based on these VPN routes. Consequently, the PE devices can only forward received traffic through public network tunnels and cannot implement private network redirection. In other words, the control and management device cannot advertise VPN routes to the PE devices based on the VPNv4, VPNv6, or L3EVPN address family to instruct them to implement private network redirection. However, with increasing network demands, many network scenarios (such as scenarios where PE devices direct traffic to traffic cleaning servers, load balancing scenarios, or Option D scenarios) require PE devices to have the function of redirecting and forwarding traffic to the private network. Therefore, the above solution cannot flexibly control traffic.

[0073] The private network redirection and forwarding mentioned in the embodiments of the present application can be the PE device rerouting traffic to the next hop on the private network. For example, traffic received by a PE device should normally be forwarded to a remote PE device via a public network tunnel based on the destination address of the traffic. However, if the PE device performs private network redirection and forwarding on the traffic, then, through the VRF table entry on the PE device that matches the destination address of the traffic, the traffic is ultimately redirected to a CE device on the private network, which is not the device indicated by the destination address of the traffic. However, regardless of whether the PE device performs private network redirection and forwarding, the PE device controls traffic based on the VRF table entry.

[0074] Based on this, an embodiment of the present application provides a traffic control method, in which a control management device sends a BGP route announcement message to a PE device. The BGP route announcement message can announce a VPN route based on the VPNv4 address family, the VPNv6 address family, or the L3EVPN address family. The VPN route may include indication information, the IP address prefix of the destination host, and the network address of the next hop to reach the IP address prefix; then, the PE device that receives the route announcement message can generate a VRF table entry according to the indication of the indication information in the route announcement message. The VRF table entry includes the IP address prefix and the outgoing interface information, and the outgoing interface information is used to identify the outgoing interface of the PE device connected to the next hop.

[0075] In this way, by carrying indication information in the VPN routes announced using the VPNv4 address family, the VPNv6 address family, or the L3EVPN address family, and instructing the PE device to generate a VRF table entry for directing private network redirection, the control and management device can lightweight and flexibly send VPN routes for traffic control to the PE device, enabling the PE device's traffic control based on the VPN routes to be applicable to a variety of different network scenarios. This overcomes the problem that the VPN routes currently issued by the control and management device to the PE device only support iteration to the public network tunnel, causing the PE device to only support forwarding received traffic through the public network tunnel and unable to support private network redirection and forwarding. In other words, based on the method provided in the embodiments of the present application, the control and management device can not only issue the above-mentioned VPN routes to the PE device, so that the PE device has the function of private network redirection and forwarding, but also issue VPN routes that only support iterating traffic to the public network tunnel to the PE device, so that the PE device has the function of forwarding through the public network tunnel. In this way, the control and management device can achieve lightweight and flexible control of the PE device and achieve compatibility with a variety of different network scenarios.

[0076] As an example, the indication information in the BGP route advertisement message may indicate that the next-hop network address is a private network IP address, or may indicate that the VPN route is a private network route. Then, the PE device generating a VRF table entry based on the indication information may include: the PE device searching for the corresponding private network according to the indication information, subscribing to outbound interface information from the routing management module based on the next-hop network address in the found private network; and then generating a VRF table entry based on the outbound interface information and the IP address prefix.

[0077] As another example, the indication information in the BGP route advertisement message may also instruct the PE device to determine the outgoing interface information for reaching the next hop in the local VRF table, where the outgoing interface information is used to identify the outgoing interface through which the PE device connects to the next hop. Then, the first PE device generating a first VRF table entry based on the indication information may include: determining the outgoing interface information for reaching the next hop in the local VRF table according to the indication information, and generating a VRF table entry including the outgoing interface information and an IP address prefix. In this manner, there is no need to worry about whether the network address of the next hop is a private IP address, nor is there any need to worry about whether the VPN route is a private network route. Instead, the first PE device only needs to perform the action of searching for the outgoing interface information according to the indication information.

[0078] The following describes the specific implementation of the embodiments of the present application and the technical effects brought about by several possible network scenarios.

[0079] As an example, the embodiment of the present application can be applied to the scenario of diverting traffic to a private network. Figure 1a The network shown may include: a control and management device 10, a PE device 21, a PE device 22, a customer edge (CE) device 31, a CE device 32, and a CE device 34. CE device 31 is connected to CE device 32 via PE device 21 and PE device 22 in sequence. PE device 21 is also connected to CE device 34. PE devices 21 and 22 communicate via a public network tunnel, and the control and management device 10 is connected to PE device 21. According to the current technical solution, the control and management device 10 may send a BGP route advertisement message 1 to PE device 21. The BGP route advertisement message 1 advertises a VPN route 1 based on the VPNv4 address family, the VPNv6 address family, or the L3EVPN address family. The VPN route 1 includes the IP address prefix 1 of the destination host and the network address of the next hop to reach the IP address prefix 1 (i.e., the network address of PE device 22). According to the definition of VPN routing in RFC 4364 and the definition of Multiprotocol Reachable Network Layer Reachability Information (MP_REACH_NLRI) in RFC 4760, the format of MP_REACH_NLRI in the BGP route advertisement message 1 is as follows: Figure 2aAs shown, the following fields may be included: Address Family Identifier (AFI), Subsequent Address Family Identifier (SAFI), Length of Next Hop Network Address, Network Address of Next Hop, Reserved, and Network Layer Reachability Information (NLRI). The combination of the AFI and SAFI indicates the address family based on which VPN route 1 is published. The value of the Length of Next Hop Network Address field indicates the length of the Next Hop Network Address field. The Next Hop Network Address field is a variable-length field used to indicate the next-hop network address. For example, the Next Hop Network Address field may be: 000000000000000002020202. The first 8 bytes are the RD field. RFC 4364 stipulates that the value of the RD field is 0. The remaining bytes (i.e., 02020202) represent the address 2.2.2.2 of PE device 22. PE device 21, having received BGP route advertisement message 1, can then iterate the public network tunnel based on VPN route 1, determine the outgoing interface information 1 corresponding to the public network tunnel that reaches PE device 22 in its local VRF table, and generate VRF table entry 1. VRF table entry 1 includes IP address prefix 1 and outgoing interface information 1. Outgoing interface information 1 is used to identify interface 1' of PE device 21 corresponding to the public network tunnel. That is, PE device 21 enters the public network tunnel through interface 1'. Outgoing interface information 1 can be, for example, the address of interface 1'. Thus, when PE device 21 receives traffic 1 sent by CE device 31, if the destination address of traffic 1 and the IP address prefix 1 in VRF table entry 1 belong to the same network segment, PE device 21, based on outgoing interface information 1 in VRF table entry 1, sends traffic 1 through interface 1' via the public network tunnel to PE device 22. PE device 22 then forwards traffic 1 to the destination host (i.e., CE device 32 or a host directly connected to CE device 32). It can be seen that in the current technical solution, according to the VPN route issued by the control management device 10, the PE device 21 cannot send traffic to the private network next hop (such as the CE device 34) to achieve private network redirection and forwarding.

[0080] against Figure 1aIn the network shown, if there is a need to introduce traffic with certain characteristics into the CE device 34, for example, to introduce traffic with a destination address of 100.1.1.1 into the CE device 34, then, based on the method provided in the embodiment of the present application, the existing BGP route announcement message can be extended, and indication information can be set in the BGP route announcement message. Thus, the PE device that receives the BGP route announcement message can generate corresponding VRF table entries according to the indication of the indication information in the extended BGP route announcement message. For example, the control and management device 10 can send a BGP route announcement message 2 to the PE device 21, and the BGP route announcement message 2 announces VPN route 2 based on the VPNv4 address family or the VPNv6 address family or the L3EVPN address family. The VPN route 2 may include indication information 1, the IP host prefix 1 of the destination host, and the network address 12.1.1.2 of the next hop to reach the IP address prefix 1, and the next hop is the CE device 34. Among them, the format of MP_REACH_NLRI in the BGP route announcement message 2 is as follows: Figure 2b As shown, for example, it may include: AFI, SAFI, length of the next-hop network address, next-hop network address, reserved, and NLRI fields. The next-hop network address field may be: 00000001000000010C010102. The first 8 bytes are the value of the RD field, which is used to represent indication information 1 in this embodiment and takes a non-zero value. The remaining bytes (i.e., 0C010102) represent the network address 12.1.1.2 of CE device 34. Then, PE device 21, which receives the BGP route advertisement message 2, can generate VRF table entry 2 according to the indication of indication information 1. The VRF table entry 2 includes IP address prefix 1 and outbound interface information 2. The outbound interface information 2 is used to indicate interface 1 of PE device 21 connected to CE device 34. Thus, when PE device 21 receives traffic 2 sent by CE device 31, if the destination address of traffic 2 belongs to the same network segment as the IP address prefix 1 in VRF table entry 2, PE device 21 sends traffic 2 to CE device 34 through interface 1 corresponding to outgoing interface information 2 in VRF table entry 2. It can be seen that based on the technical solution provided by the embodiment of the present application, the VPN routes published by the control management device 10 can enable PE device 21 to direct traffic with certain characteristics to CE device 34 to achieve private network redirection and forwarding.

[0081] in, Figure 2a and Figure 2b In the [1] field, AFI=1, SAFI=128 indicates that BGP route advertisement messages advertise VPN routes based on VPNv4; AFI=2, SAFI=128 indicates that BGP route advertisement messages advertise VPN routes based on the VPNv6 address family; AFI=25, SAFI=70 indicates that BGP route advertisement messages advertise VPN routes based on the L3EVPN address family.

[0082] In this scenario, the CE device 34 can be, for example, a traffic cleaning server, used to analyze and collect statistics on traffic, and can also be used to identify traffic that poses security risks such as attacks or tampering. In different scenarios, the traffic that needs to be introduced to the traffic cleaning server can be set according to actual needs. For example, the control and management device 10 can determine the traffic characteristics that the PE device 21 needs to introduce to the traffic cleaning server based on actual needs, and publish the corresponding private network VPN route based on the traffic characteristics. The traffic characteristics that need to be diverted can include, but are not limited to, at least one of the source IP address, destination IP address, source port number, or destination port number of the traffic. If the traffic characteristic that needs to be diverted is the destination IP address, then the IP address prefix 1 in the above-mentioned VPN route 2 can belong to the same network segment as the destination IP address. In this way, the PE device 21 can generate a VRF table entry 2 based on the received private network VPN route 2, so that the PE device 21 can introduce the traffic to the traffic cleaning server based on the VRF table entry 2.

[0083] In this example, traffic directed to CE device 34 can generally be directed in two different modes: Mode 1, redirection, and Mode 2, traffic replication. When traffic 2 reaches PE device 21, whether it should be redirected or replicated before forwarding can be configured on PE device 21 based on actual needs. Alternatively, control and management device 10 can send the corresponding VPN route to PE device 21 based on actual needs. In one scenario, PE device 21 can support Mode 1, meaning that PE device 21 can directly send traffic 2 to CE device 34 according to VRF table entry 2. PE device 21 can support Mode 1, for example, by receiving only BGP route advertisement message 2 from control and management device 10 but not BGP route advertisement message 1. Alternatively, PE device 21 can receive both BGP route advertisement message 2 and BGP route advertisement message 1 from control and management device 10, but VRF table entry 1 set on PE device 21 is invalid or has a higher priority than VRF table entry 1. In another case, PE device 21 may also support mode 2, that is, PE device 21 may first copy received traffic 2 to obtain traffic 2' that is identical to traffic 2. Since the destination addresses of traffic 2 and traffic 2' belong to the same network segment as the IP address prefix 1 in VRF table entry 1 and VRF table entry 2, PE device 21 may send traffic 2 from interface 1' to PE device 22 according to VRF table entry 1, and PE device 22 may then forward traffic 2 to the destination host. Simultaneously, PE device 21 may also send traffic 2' from interface 1 to CE device 34 according to VRF table entry 2. For example, PE device 21 may support mode 2 when it receives BGP route advertisement message 2 and BGP route advertisement message 1 sent by control and management device 10, and VRF table entry 1 and VRF table entry 2 are set on PE device 21 to have the same priority.

[0084] The CE device may be a network device such as a switch or a router, or may be a host directly connected to the PE device.

[0085] It should be noted that the above Figure 1aIn the illustrated scenario, CE device 34 and CE device 31 belong to the same VPN 1. BGP route advertisement message 2 may include the route distinguisher (RD) of the same VPN 1 as indication information 1. BGP route advertisement message 2 may also include a route target (RT). The values ​​of RD and RT may be the same or different. PE device 21 stores the correspondence between the local RT and the private network. Then, after PE device 21 receives BGP route advertisement message 2, the process of generating VRF table entry 2 based on BGP route advertisement message 2 may include: PE device 21 parses BGP route advertisement message 2 to obtain RT 1:1, and searches for a local RT that matches the RT, thereby crossing VPN route 2 to private network 1 corresponding to the local RT; PE device 21 may also subscribe to outbound interface information 2 from the routing management module using the RD and next-hop network address 12.1.1.2 in BGP route advertisement message 2; thereby, PE device 21 generates VRF table entry 2 including outbound interface information 2 in the crossed private network 1. The RT in BGP route advertisement message 2 matches the local RT, which may, for example, mean that the RT in BGP route advertisement message 2 and the local RT are the same value. Optionally, RD and RT can take the same value (e.g., 1:1). In this case, PE device 21 subscribes to the routing management module to obtain outbound interface information 2 using RD 1:1 and the next-hop network address 12.1.1.2. This may include: PE device 21 matches the VRF table in VPN 1 using RD 1:1, and searches for outbound interface information 2 corresponding to 12.1.1.2 in the VRF table of VPN 1. PE device 21 may then add VRF entry 2 corresponding to outbound interface information 2 and IP address prefix 1 to the VRF table corresponding to VPN 1.

[0086] In addition, Figure 1a Based on the network shown in FIG, a CE device 33 belonging to VPN 2 may also be included. The CE device 33 is connected to the PE device 21. Figure 1b shown. Figure 1bIn the network shown, CE device 33 can be, for example, a traffic scrubbing server configured for PE devices connected to multiple private networks. The BGP route advertisement message 2' sent by control and management device 10 includes an RD of 1:3, an ERT of 1:1, and a next-hop network address field of 00000001000000030D010102, i.e., RD ​​1:3 + the network address 13.1.1.2 of CE device 33. RD 1:3 can serve as indication information 1' in BGP route advertisement message 2'. On PE device 21, the RD corresponding to VPN 1 is IRT = 1:1, and the RD corresponding to VPN 2 is IRT = 1:3. PE device 21 also stores the correspondence between IRTs and private networks, including, for example, the correspondence between IRT 1:1 and VPN 1, and the correspondence between IRT 1:3 and VPN 2. After receiving the BGP route advertisement message 2', PE device 21 can parse the BGP route advertisement message 2' to obtain the ERT and RD. Then, PE device 21 can search for the local IRT 1:1 that matches the ERT 1:1, thereby crossing the VPN route 2' to VPN 1 corresponding to the local IRT 1:1. Furthermore, PE device 21 can subscribe to the routing management module using the RD 1:3 and the next-hop network address 13.1.1.2 in the BGP route advertisement message 2' to obtain the outgoing interface information 3. Thus, PE device 21 can generate a VRF table entry 3 including the outgoing interface information 3 in the crossed VPN 1. The outgoing interface information 3 is used to identify the interface 2 of PE device 21 connected to CE device 33, which can be, for example, the address of interface 2. The ERT in the BGP route advertisement message 2' matches the local IRT, which can mean, for example, that the ERT in the BGP route advertisement message 2 and the local IRT have the same value. It should be noted that for the same VPN, RD and RT can take the same value, so that VRF table entry 3 can be accurately generated in cross-VPN scenarios. After receiving BGP route advertisement message 2', PE device 21 can cross VPN route 2' to VPN 1 based on ERT. Then, PE device 21 matches the RD value to the VRF table of VPN 2, searches for outbound interface information 3 corresponding to 13.1.1.2 in the VRF table of VPN 2, and then adds VRF table entry 3 corresponding to outbound interface information 3 and IP address prefix 1 to VPN 1.In this way, when PE device 21 receives traffic 3 sent by CE device 31, it can determine that the interface receiving traffic 3 belongs to VPN 1, and search the VRF table of VPN 1 for VRF entry 3 whose IP address prefix belongs to the same network segment as the destination address of traffic 3. Thus, PE device 21 obtains outgoing interface information 3 in VRF entry 3 and sends traffic 3 to CE device 33 through interface 2 corresponding to outgoing interface information 3. That is, PE device 21 searches the VRF table corresponding to VPN 1 for traffic 3, but the outgoing interface information 3 in VRF entry 3 in the VRF table belongs to VPN 2. It can be seen that based on the technical solution provided in the embodiment of the present application, the VPN route issued by the control management device 10 can enable PE device 21 to forward traffic to the private network in a cross-private network scenario, thereby realizing private network redirection forwarding.

[0087] As another example, the embodiment of the present application can also be applied to the scenario where the PE device is dual-homed to the destination host. Figure 1c The network shown may include: a control and management device 10, a PE device 21, a PE device 22, a CE device 31, a CE device 32, a CE device 33, and a CE device 34. CE device 31 is connected to CE device 32 via PE device 21 and PE device 22 in sequence. PE device 21 is also connected to CE device 32 via CE devices 33 and CE device 34. The control and management device 10 is connected to PE device 21. CE devices 33 and 34 may be connected via a Layer 2 virtual private network (L2VPN) dedicated line. The path from PE device 21 to CE device 32 via CE devices 33 and CE devices 34 is denoted as path 1. The path from PE device 21 to CE device 32 via PE device 22 is denoted as path 2. Path 2 includes the public network tunnel between PE device 21 and PE device 22. Path 1 and path 2 can perform load balancing or active / standby secure switching. See [Note: The following sentences appear to be unrelated and should likely be omitted.] Figure 1a In the relevant description of the current technical solution, the VPN route 1 published by the control management device 10 to the PE device 21 enables the PE device 21 to only support sending traffic to the CE device 32 through path 2, and cannot send traffic to the CE device 32 through path 1. However, if based on the method provided in the embodiment of the present application, the PE device 21 can include both VRF table entry 1 and VRF table entry 2. In this way, taking the load sharing scenario as an example, when the PE device 21 receives traffic 4 sent to the CE device 32, it can load share the traffic 4 based on path 1 and path 2 respectively. It can be seen that based on the technical solution provided in the embodiment of the present application, the VPN route published by the control management device 10 can not only enable the PE device 21 to perform public network tunnel forwarding, but also perform private network forwarding, so as to achieve load sharing of the received traffic.

[0088] exist Figure 1c In the network shown, path 1 and path 2 can also serve as active / standby safe switching paths to implement fault protection. For example, path 2 is the active path and path 1 is the standby path. When both paths are fault-free, path 2 serves as the working path. PE device 21 can send received traffic 5 to PE device 22 via the public network tunnel based on interface 1' corresponding to outgoing interface information 1 in VRF table entry 1. PE device 22 then forwards traffic 5 to CE device 32. That is, PE device 21 sends traffic 5 based on path 2. If path 2 fails, PE device 21 can use the standby path (i.e., path 1) as the working path. In this case, PE device 21 sends received traffic 5 to CE device 33 based on interface 1 corresponding to outgoing interface information 2 in VRF table entry 2. CE device 33 then sends traffic 5 to CE device 32 via CE device 34. That is, PE device 21 sends traffic 5 based on path 1. It should be noted that the implementation method of PE device 21 using the backup path as the working path may include: setting VRF table entry 1 to an invalid state, or setting the priority of VRF table entry 2 to be higher than the priority of VRF table entry 1. It can be seen that the technical solution provided by the embodiment of the present application enables, in certain failure scenarios, when the public network route is unavailable and there is no backup public network route, the PE device can forward traffic to the destination address based on the private network route, thereby achieving route redirection based on the private network route, avoiding service interruption, and improving network reliability.

[0089] It should be noted that, see Figure 1c The network may also include path 3, which is the path from PE device 21 to CE device 32 via CE device 35 and PE device 23. When the network includes at least two of path 1, path 2, and path 3, for example, including path 2 and path 3, or including path 1 and path 3, or including path 1, path 2, and path 3, load balancing or active / standby safe switching can be achieved in all scenarios where multiple paths from PE device 21 to CE device 32 are included.

[0090] As another example, the embodiment of the present application is also applicable to cross-domain interconnected network scenarios. Figure 1dThe network shown may include: a control and management device 10, a PE device 21, and a PE device 22, and may also include: a PE device 23 and a PE device 24. PE devices 23 and 21 belong to the first domain, and PE devices 22 and 24 belong to the second domain. Path 4 directly connected via private network interface 1 and path 5 directly connected via public network interface 1' are located between PE devices 21 and 22. It should be noted that the connection between the PE devices 21 and 22 may include no other devices, or may include other devices that are not perceived by the PE devices 21 and 22. Therefore, regardless of whether there are other devices between the PE devices 21 and 22, the PE devices 21 and 22 can be considered to be directly connected devices. See Figure 1a In the relevant description of the current technical solution, the VPN route 1 published by the control management device 10 to the PE device 21 can enable the PE device 21 to only support sending traffic to the PE device 22 through the path 5, and cannot forward traffic from the path 4 based on the private network interface 1. However, if based on the method provided in the embodiment of the present application, the PE device 21 can generate a VRF table entry 2. In this way, when the PE device 21 receives traffic 6, it can send traffic 6 to the PE device 22 based on the interface 1 corresponding to the outgoing interface information 2 in the VRF table entry 2. The outgoing interface information 2 can be, for example, the address of the private network interface (i.e., interface 1) on the PE device 21. Among them, the PE device 21 and the PE device 22 can be, for example, an autonomous system boundary router (English: Autonomous System Boundary Router, abbreviated as: ASBR) 21 and ASBR 22. This scenario can be called Option D. In the current Option D scenario, ASBR 21 and ASBR 22 both need to apply for private network labels for themselves before forwarding traffic across domains, and send the applied private network labels to the peer ASBR. When ASBR 21 forwards traffic to ASBR 22, it needs to modify the private network label with the next hop address being ASBR 22. Similarly, when ASBR 22 forwards traffic to ASBR 21, it needs to modify the private network label with the next hop address being ASBR 21. However, based on the technical solution provided in the embodiment of the present application, the VPN route 2 issued by the control management device 10 enables PE device 21 to directly forward traffic to PE device 22 in another domain through private network interface 1 based on VRF table entry 2. PE device 21 does not need to apply for a private network label for itself, nor does it need to perform private network label exchange (i.e., modify the next hop address to the private network label of PE device 22) during cross-domain forwarding, thereby saving private network label resources and the workload of label exchange.

[0091] It should be noted that in the embodiments of the present application, the PE device may be a network device such as a switch, router, or firewall. The CE device may be a device with private network access capabilities, for example, a switch, router, Internet of Things (IoT) terminal, host, or other device. The control and management device may be a device that has BGP functionality and supports the VPNv4 address family, the VPNv6 address family, or the L3EVPN address family, and has control and management capabilities for the PE device. For example, the control and management device may be an independent communication device (such as an independent server); for another example, the control and management device may be a functional module integrated into other communication devices (such as a newly added service board on the PE device 21); for another example, the control and management device may be a functional module integrated into a public cloud, which is not specifically limited in the embodiments of the present application.

[0092] The above Figure 1a 、 Figure 1b 、 Figure 1c and Figure 1d Taking the scenarios shown as an example, the application of the technical solutions of the embodiments of the present application in different network scenarios is introduced respectively. These are only a few scenario examples provided by the embodiments of the present application and do not constitute a limitation on the embodiments of the present application.

[0093] The flow control method provided in the embodiments of the present application is described below with reference to the accompanying drawings.

[0094] Figure 3 A flow chart of a flow control method 100 provided in an embodiment of the present application. The method 100 is described by the interaction between the control management device and the first PE device. For example, the control management device in the method 100 may be Figure 1a 、 Figure 1b or Figure 1c The control management device 10 in the first PE device can be Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d PE device 21 in. Figure 3 The method 100 may include, for example, S101 to S104:

[0095] S101: A control management device generates a first BGP route advertisement message.

[0096] S102: The control management device sends a first BGP route advertisement message to the first PE device.

[0097] S103, the first PE device receives the first BGP route announcement message sent by the control management device, the first BGP route announcement message announces the first VPN route based on the VPNv4 address family or the VPNv6 address family or the L3EVPN address family, the first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop of the IP address prefix, where the network address of the first next hop is a private network IP address.

[0098] The first BGP route announcement message may be a VPN message generated by the control management device and sent to the first PE device. The VPN message may be a control message based on the VPNv4 address family, or a control message based on the VPNv6 address family, or a control message based on the L3EVPN address family. Figure 1a 、 Figure 1c and Figure 1d In the scenario shown, the first BGP route announcement message corresponds to the above BGP route announcement message 2, the indication information corresponds to indication information 1, the network address of the first next hop corresponds to 12.1.1.2, and the IP address prefix of the destination host corresponds to IP address prefix 1; corresponding to the above Figure 1b In the illustrated scenario, the first BGP route advertisement message corresponds to BGP route advertisement message 2', the indication information corresponds to indication information 1', the first next hop network address corresponds to 13.1.1.2, and the destination host IP address prefix corresponds to IP address prefix 1. If CE device 32 is a network device such as a switch or router, the destination host is a host directly connected to CE device 32; if CE device 32 is a host, the destination host is CE device 32.

[0099] Currently, RFC 4364 defines that the value of the 8-byte RD in a VPN route is 0. After receiving the VPN route, the first PE device can subscribe to the second outbound interface information from the tunnel management module based on the next-hop network address (i.e., the address of the second PE device to which the first PE device is connected via the public network tunnel), and generate a second VRF table entry containing the second outbound interface information. The second outbound interface information indicates the second outbound interface of the first PE device corresponding to the public network tunnel, so that the first PE device forwards the received traffic from the second outbound interface through the public network tunnel based on the second outbound interface information in the second VRF table entry. For specific implementation methods, see the description of S201 to S204 in method 200 below.

[0100] In this application, the network address of the first next hop in the first BGP route announcement message can be used to indicate the next hop of the first PE device after the first VPN route is crossed to the private network. The next hop of the first PE device after crossing to the private network is recorded as the first next hop in this embodiment. If the first PE device is PE device 21, then the corresponding Figure 1a In the network shown, the first next hop may be the CE device 34. For example, the first next hop may be a traffic cleaning server. The network address of the first next hop may be the address 12.1.1.2 of the CE device 34. Figure 1b In the network shown, the first next hop may be the CE device 33, and the network address of the first next hop may be the address 13.1.1.2 of the CE device 33; corresponding to Figure 1c In the network shown, the first next hop may be the CE device 33 (or CE device 35), and the network address of the first next hop may be the address of the CE device 33 (or CE device 35); corresponding to Figure 1d In the network shown, the first next hop may be the PE device 22 , and the network address of the first next hop may be the address of the private network interface 1 of the PE device 22 .

[0101] The IP address prefix of the destination host in the first BGP route announcement message is used to indicate the destination host. The IP address prefix and the IP address of the destination host belong to the same network segment. The destination host can be a CE device or a host connected to the CE device. If the first PE device is PE device 21, then the corresponding Figure 1a and Figure 1b In the network shown, the device corresponding to the IP address prefix can be the CE device 32 or a host directly connected to the CE device 32; Figure 1c In the network shown, the device corresponding to the IP address prefix can be the CE device 32 or a host directly connected to the CE device 32; Figure 1d In the network shown, the device corresponding to the IP address prefix may be a CE device connected to the PE device 24 or a host directly connected to the CE device.

[0102] The indication information in the first BGP route announcement message can, in one case, indicate that the network address of the first next hop is a private IP address, or it can also be used to indicate that the first VPN route announced by the first BGP route announcement message is a private network route. In another case, the indication information can also be used to indicate that the first PE device determines the first outbound interface information to reach the first next hop in the local VRF table, and the first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop. It should be noted that as long as the first PE device can identify the indication information after receiving the first BGP route announcement message and generate the first VRF table entry based on the indication information, the embodiment of the present application does not limit the carrying method of the indication information.

[0103] As an example, the indication information can be the non-zero RD carried in the next-hop network address field (also referred to as the next-hop address field), which is distinguished from the RD with a value of 0 in the current VPN route that guides crossing to the public network tunnel. In this way, after receiving the first BGP route announcement message, the first PE device can obtain the indication information and the network address of the first next hop by parsing the next-hop network address field in the MP_REACH_NLRI, making it possible for the first PE device to quickly process the first VPN route. In one case, if the destination host and the first next hop belong to the same VPN, the value of the RD field can be any non-zero value. In another case, if the destination host and the first next hop belong to different VPNs, the value of the RD field can be a non-zero value used to identify the VPN to which the first next hop belongs. Figure 1b Taking the example where CE device 33 belongs to VPN 2 but CE devices 32 and CE devices 31 belong to VPN 1, the RD in BGP route advertisement message 2' can be 1:3, and RD 1:3 corresponds to VPN 2. In this way, after PE device 21 receives BGP route advertisement message 2', it can cross VPN route 2' to VPN 1 based on ERT. Then, PE device 21 matches the VRF table of VPN 2 with the RD value 1:3, searches for the outgoing interface information 3 corresponding to 13.1.1.2 in the VRF table of VPN 2, and then adds the outgoing interface information 3 and the VRF table entry 3 corresponding to IP address prefix 1 to VPN 1.

[0104] As another example, the indication information may also be carried through other fields. For example, an extended attribute may be added to the first BGP route advertisement message, and the extended attribute is used to carry the indication information. When the first BGP route advertisement message received by the first PE device includes the extended attribute, the first PE device may determine that the first BGP route advertisement message includes the indication information. Conversely, if the first BGP route advertisement message received by the first PE device does not include the extended attribute, the first PE device may determine that the first BGP route advertisement message does not include the indication information.

[0105] It can be seen that when the control management device determines that the control traffic needs to be redirected and forwarded on the private network on the first PE device, the above S101 to S102 can be executed. At this time, according to S103, the first PE device can receive the first BGP route announcement message, so that the first PE device can complete the preparation for forwarding the traffic based on S104, and prepare for redirecting and forwarding the traffic to the private network when the traffic is received subsequently.

[0106] S104: The first PE device generates a first VRF table entry according to the instruction information. The first VRF table entry includes an IP address prefix and first outbound interface information. The first outbound interface information is used to identify a first outbound interface of a first next hop connected to the first PE device.

[0107] In a specific implementation, S104 may include, for example: S1041, the first PE device obtains the indication information and the network address of the first next hop by parsing the received first BGP route advertisement message; S1042, the first PE device determines the first outgoing interface information to the first next hop in the local VRF table based on the indication information and the network address of the first next hop; S1043, the first PE device generates a first VRF table entry based on the IP address prefix and the first outgoing interface information. When the indication information indicates that the network address of the first next hop is a private network IP address, or indicates that the first VPN route is a private network route, S1042 may include, for example: the first PE device searches for the corresponding private network according to the indication information, and then subscribes to the first outgoing interface information in the route management module based on the network address of the first next hop from the found private network. When the indication information is used to instruct the first PE device to determine the first outbound interface information reaching the first next hop in the local VRF table, then S1042 may include, for example: the first PE device determines the first outbound interface information reaching the first next hop in the local VRF table according to the indication information. In this way, the first PE device does not need to pay attention to whether the network address of the first next hop is a private network IP address, nor does it need to pay attention to whether the first VPN route is a private network route. If the first PE device is the PE device 21 in the above embodiment, then corresponding to Figure 1a 、 Figure 1c or Figure 1d In the embodiment shown, the first VPN route may be the VPN route 2, the first VRF table entry is the VRF table entry 2, the first outgoing interface information is the outgoing interface information 2, and the first outgoing interface is the interface 1; corresponding to Figure 1b In the illustrated embodiment, the first VPN route may be the aforementioned VPN route 2 ′, the first VRF table entry is VRF table entry 3 , the first outgoing interface information is outgoing interface information 3 , and the first outgoing interface is interface 2 .

[0108] If the first next hop and the destination host belong to the same VPN (i.e., the first VPN), then S104 may specifically include: the first PE device determines a local RT (i.e., IRT) that matches the RT (also referred to as ERT) in the first BGP route advertisement message, and crosses the first VPN route announced in the first BGP route advertisement message to the private network corresponding to the local RT; then, the first PE device subscribes to the routing management module through the network address of the first next hop in the first BGP route advertisement message to obtain the first outbound interface information reaching the first next hop; thereby, the first PE device generates a first VRF table entry including the first outbound interface information in the private network crossed. The correspondence between different RTs and private networks can be pre-saved on the first PE device, and each private network maintains its own VRF table; the RT in the first BGP route advertisement message matches the local RT, for example, the RT in the first BGP route advertisement message and the local RT have the same value.

[0109] If the first next hop and the destination host belong to different VPNs, then S104 may specifically include: the first PE device determines a local IRT that matches the ERT in the first BGP route advertisement message, and crosses the first VPN route advertised in the first BGP route advertisement message to the private network corresponding to the local IRT; then, the first PE device subscribes to the routing management module using the RD in the first BGP route advertisement message and the network address of the first next hop to obtain the first outgoing interface information reaching the first next hop; thereby, the first PE device generates a first VRF table entry including the first outgoing interface information in the cross-linked private network. Assuming that the first next hop belongs to the second VPN and the destination host belongs to the first VPN, the IRT corresponding to the first VPN is IRT1 and the RD is RD1; the IRT corresponding to the second VPN is IRT2 and the RD is RD2, and the first PE device stores the correspondence between IRT1 and private network 1, and the correspondence between IRT2 and private network 2. If the ERT included in the first BGP route advertisement message matches IRT 1, but the RD included in the first BGP route advertisement message is used to identify the first next hop in private network 2, then the first PE device can cross the first VPN route to private network 1 based on the first BGP route advertisement message. However, in the first VRF table entry generated in private network 1, the first outbound interface information is used to identify the first outbound interface of the first PE device to reach the first next hop in private network 2. The first PE device subscribes to the routing management module for the first outbound interface information to reach the first next hop using the RD in the first BGP route advertisement message and the network address of the first next hop. For example, the first PE device matches the VRF table of the second VPN based on the value of the RD in the first BGP route advertisement message, searches the VRF table of the second VPN for the first outbound interface information corresponding to the network address of the first next hop, and then adds the first outbound interface information and the first VRF table entry corresponding to the IP address prefix to the first VPN corresponding to the destination host.

[0110] If the first PE device is PE device 21, then the first outbound interface information is used to identify the first outbound interface connected to the first next hop on PE device 21. Figure 1a In the network shown, the first outbound interface information can identify the interface 1 on the PE device 21 connected to the CE device 34. For example, the first outbound interface information can be the address of the interface 1 on the PE device 21 connected to the CE device 34, or it can be the address of the interface on the CE device 34 connected to the PE device 21. The addresses of the above two interfaces belong to the same network segment and can both be used to identify the interface 1 on the PE device 21. Figure 1bIn the network shown, the first outbound interface information may identify the interface 2 on the PE device 21 connected to the CE device 33. For example, the first outbound interface information may be the address of the interface 2 on the PE device 21 connected to the CE device 33. Figure 1c In the network shown, the first outbound interface information may identify the interface 1 on the PE device 21 connected to the CE device 33 (or the interface on the PE device 21 connected to the CE device 35). For example, the first outbound interface information may be the address of the interface on the PE device 21 connected to the CE device 33 (or the CE device 35). Figure 1d In the network shown, the first outbound interface information may identify the private network interface 1 on the PE device 21 connected to the PE device 22 . For example, the first outbound interface information may be the address of the private network interface 1 on the PE device 21 connected to the PE device 22 .

[0111] Thus, according to the method provided in the embodiment of the present application, the first PE device has the function of forwarding traffic whose destination address matches the IP address prefix in the first VRF table entry from the first outbound interface to the first next hop. Then, after S104, the method 100 may further include:

[0112] S105: The first PE device receives first traffic sent by the first CE device, where the destination address of the first traffic and the IP address prefix belong to the same network segment;

[0113] S106: The first PE device forwards the first traffic to the first next hop through the first outbound interface.

[0114] In specific implementation, after receiving the first traffic, the first PE device can first parse the first traffic to obtain the destination address of the first traffic, and search the VRF table through the destination address; when the first PE device determines that the destination address of the first traffic and the IP address prefix in the first VRF table item of the VRF table belong to the same network segment (that is, the destination address of the first traffic matches the IP address prefix in the first VRF table item), then, the first outbound interface information of the first VRF table item is obtained, thereby forwarding the first traffic from the first outbound interface corresponding to the first outbound interface information to the first next hop, thereby realizing the private network redirection forwarding of the first traffic on the first PE device. Among them, if the first PE device is the PE device 21 in the above embodiment, then, corresponding to Figure 1a In the illustrated embodiment, the first VRF entry is VRF entry 2 , the first outbound interface is interface 1 , and the first flow is flow 2 .

[0115] It should be noted that, for the scenario where the first next hop and the destination host belong to different VPNs, the first VRF table entry belongs to the VPN instance corresponding to the destination host, but the first outbound interface information in the first VRF table entry indicates the first outbound interface of the first next hop belonging to another VPN instance to which the first PE device is connected.

[0116] For example, for Figure 1d In the scenario shown, if the first PE device is a first ASBR, the first next hop is a second ASBR, and the first ASBR reaches the IP address prefix through the second ASBR, the first path and the second ASBR are connected through a private network interface, the first path is connected through a public network interface, and the first outgoing interface information is the private network interface connecting the first ASBR to the second ASBR. Then, after S104, the following may also be included:

[0117] S105', the first ASBR receives fifth traffic, the destination address of the fifth traffic and the IP address prefix belong to the same network segment;

[0118] S106': The first ASBR forwards the fifth traffic to the second ASBR through the first outbound interface.

[0119] In specific implementation, after the first ASBR receives the fifth traffic, it can first parse the fifth traffic to obtain the destination address of the fifth traffic, and search the VRF table through the destination address; when the first ASBR determines that the destination address of the fifth traffic and the IP address prefix in the first VRF table item of the VRF table belong to the same network segment, then the first outbound interface information of the first VRF table item is obtained, thereby forwarding the fifth traffic from the first outbound interface corresponding to the first outbound interface information (i.e., the private network interface on the above-mentioned first path) to the second ASBR, thereby realizing the forwarding of the fifth traffic on the first ASBR. In this way, the ASBR does not need to apply for a private network label or exchange private network labels during cross-domain forwarding, saving the resources required for private network label allocation and private network label exchange on the ASBR. Among them, if the first PE device is the PE device 21 in the above embodiment, then, corresponding to Figure 1d In the illustrated embodiment, the first VRF table entry is VRF table entry 2 , the first outbound interface is interface 1 (ie, private network interface), and the first flow is flow 6 .

[0120] It can be seen that through this method 100, the control and management device carries indication information in the VPN route announced using the VPNv4 or VPNv6 address family or the L3EVPN address family, instructing the PE device to iterate to the next hop in the private network based on the VPN route, thereby realizing that the control and management device can send the private network VPN route to the PE device in a lightweight and flexible manner, so that the PE device generates a VRF table entry for controlling traffic forwarding based on the private network VPN route, overcoming the problem that the VPN route currently issued by the control and management device to the PE device only supports iteration to the public network tunnel, so that the PE device only supports forwarding the received traffic through the public network tunnel, and cannot support the private network redirection and forwarding function.

[0121] In some possible implementations, in order to adapt to the needs of more network scenarios, the flow control method provided in the embodiment of the present application may include, in addition to the above method 100, the following method 200. In the method 200, the control management device may issue a second VPN route supporting iterating the flow to the public network tunnel to the first PE device, so that the first PE device has the function of forwarding through the public network tunnel. The control management device in the method 200 may be Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d The control management device 10 in the first PE device can be Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d The PE device 21 in the second PE device can be Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d PE device 22 in.

[0122] It should be noted that method 100 and method 200 can be executed successively or simultaneously, can exist separately or as a whole embodiment, and are not limited in the embodiments of the present application.

[0123] like Figure 4 As shown, the method 200 may include, for example, the following S201 to S204:

[0124] S201: Control the management device to generate a second BGP route advertisement message.

[0125] S202: The control management device sends the second BGP route advertisement message to the first PE device.

[0126] S203, the first PE device receives the second BGP route announcement message sent by the control and management device, the second BGP route announcement message announces the second VPN route, the first BGP route announcement message and the second BGP route announcement message use the same VPN address family, the second VPN route includes an IP address prefix and a network address of the second next hop to reach the IP address prefix, the second next hop is the second PE device, and the first PE device communicates with the second PE device through a public network tunnel.

[0127] The second BGP route announcement message may be a VPN message generated by the control management device and sent to the first PE device. The VPN message may be a control message based on the VPNv4 address family, or a control message based on the VPNv6 address family, or a control message based on the L3EVPN address family. Figure 1a to Figure 1c In the scenario shown, the second BGP route advertisement message format corresponds to the above-mentioned BGP route advertisement message 1, wherein the RD value in the next hop address field can be, for example, Figure 2a In the RD shown as having all zero values, the second next hop is the PE device 22 . The network address of the second next hop may correspond to the address of the PE device 22 : 2.2.2.2, and the IP address prefix corresponds to the IP address prefix 1.

[0128] In specific implementation, when the control management device determines that the control traffic needs to be forwarded through the public network tunnel on the first PE device, the above S201 to S202 can be executed. At this time, according to S203, the first PE device can receive the second BGP route announcement message, so that the second PE device can complete the preparation for forwarding the traffic based on S204, and prepare for forwarding the traffic through the public network tunnel when the traffic is received subsequently.

[0129] S204: The first PE device generates a second VRF table entry according to the second BGP route advertisement message. The second VRF table entry includes the IP address prefix and second outbound interface information. The second outbound interface information is used to identify the second outbound interface of the first PE device corresponding to the public network tunnel.

[0130] The first PE device enters the public network tunnel through the second outbound interface identified by the second outbound interface information.

[0131] In a specific implementation, S204 may include, for example: S2041, the first PE device obtains the second IP address prefix and the network address of the second next hop by parsing the received second BGP route announcement message; S2042, the first PE device determines the second outbound interface information in the local VRF table; S2043, the first PE device determines the second VRF table entry based on the IP address prefix and the second outbound interface information. If the first PE device is the PE device 21 in the above embodiment, and the second PE device (i.e., the second next hop) is the PE device 22, then, corresponding to Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d In the embodiment shown, the second VPN route may be the VPN route 1, the second VRF table entry is the VRF table entry 1, the second outgoing interface information is the outgoing interface information 1, and the second outgoing interface is the interface 1'. Figure 1a and Figure 1b In the network shown, the network address of the second next hop may be the address of the PE device 22. Figure 1c In the network shown, the network address of the second next hop may be the address of the PE device 22. Figure 1d In the network shown, the network address of the second next hop may be the address of the public network interface 1 ′ on the PE device 22 .

[0132] Thus, according to the method provided in the embodiment of the present application, the first PE device has the function of forwarding traffic whose destination address matches the IP address prefix in the second VRF table entry through the public network tunnel. Then, after S204, the method 200 may also include the operation of forwarding traffic whose destination address matches the above-mentioned IP address prefix through the public network tunnel.

[0133] As an example, if the first PE device supports replicating the received traffic and forwarding the traffic through the private network and the public network tunnel respectively, then after S104 and S204, the following steps may be further included:

[0134] S305, the first PE device receives and copies the second traffic sent by the second CE device to obtain third traffic;

[0135] S306: The first PE device forwards the second traffic to the first next hop through the first outbound interface.

[0136] S307: The first PE device forwards the third traffic to the second PE device through the second outbound interface.

[0137] In a specific implementation, after receiving the second traffic sent by the second CE device, the first PE device can copy the second traffic to obtain a third traffic that is identical to the second traffic. It can also parse the second traffic (or third traffic) to obtain the destination address of the received traffic and search the VRF table using the destination address. On the one hand, the first PE device determines that the destination address of the received traffic and the IP address prefix in the first VRF entry in the VRF table belong to the same network segment. Thus, according to step S306, the first outbound interface information of the first VRF entry is obtained, and either the second traffic or the third traffic is forwarded from the first outbound interface corresponding to the first outbound interface information to the first next hop, thereby implementing private network redirection and forwarding of the traffic on the first PE device. On the other hand, the first PE device determines that the destination address of the received traffic and the IP address prefix in the second VRF entry in the VRF table belong to the same network segment. Thus, according to step S307, the second outbound interface information of the second VRF entry is obtained, and either the second traffic or the third traffic is forwarded from the public network tunnel indicated by the second outbound interface to the second next hop (i.e., the second PE device), thereby implementing public network tunnel forwarding of the traffic on the first PE device.

[0138] It should be noted that the second CE device and the first CE device in method 100 may be the same CE device. For example, the first CE device and the second CE device both correspond to Figure 1a Alternatively, the second CE device and the first CE device in method 100 may also be two different CE devices connected to the first PE device.

[0139] As another example, if the first PE device and the destination host include: a first path and a second path, wherein the first path includes the first next hop and the second path includes the second next hop, then it can be applied to Figure 1c In the network scenario shown, load balancing or active / standby safe switching is implemented. Taking load balancing as an example, after S104 and S204, the following steps may also be included:

[0140] S305′, the first PE device receives fourth traffic sent by the third CE device;

[0141] S306': The first PE device performs load balancing on the fourth traffic through the first path and the second path.

[0142] In a specific implementation, after the first PE device receives the fourth traffic sent by the third CE device, it can split the fourth traffic into the first sub-traffic and the second sub-traffic according to the actual network situation (such as the congestion on the first path and the second path); it can also parse the fourth traffic to obtain the destination address of the fourth traffic, and search the VRF table through the destination address; on the one hand, the first PE device determines that the destination address of the fourth traffic and the IP address prefix in the first VRF table item belong to the same network segment, obtains the first outbound interface information of the first VRF table item, and thus forwards the first sub-flow from the first outbound interface to the first next hop. On the other hand, the first PE device determines that the destination address of the fourth traffic and the IP address prefix in the second VRF table item belong to the same network segment, obtains the second outbound interface information of the second VRF table item, and thus forwards the second sub-traffic from the public network tunnel to the second next hop.

[0143] If the destination host is Figure 1c CE device 32 in the flow, then the second next hop is PE device 22. After PE device 22 receives the second sub-flow, it also needs to send the second sub-flow to CE device 32; the first next hop is CE device 33 (or CE device 35). After CE device 33 (or CE device 35) receives the first sub-flow, it also needs to send the first sub-flow to CE device 32.

[0144] It should be noted that the third CE device and the first CE device in method 100 may be the same CE device. For example, the first CE device and the third CE device both correspond to Figure 1a Alternatively, the third CE device and the first CE device in the method 100 may also be two different CE devices connected to the first PE device.

[0145] As can be seen, based on the method provided in the embodiments of the present application, the control and management device can not only publish the above-mentioned private network VPN routes to PE devices, enabling the PE devices to have the private network redirection and forwarding function, but also publish VPN routes that only support iterating traffic to the public network tunnel to PE devices, enabling the PE devices to forward traffic through the public network tunnel. This achieves lightweight and flexible control of PE devices by the control and management device, and also achieves compatibility with various different network scenarios.

[0146] In addition, the present invention also provides a flow control device 500, see Figure 5 shown. Figure 5 Schematic diagram of a flow control device 500 provided in an embodiment of the present application. The flow control device 500 is applied to a first PE device and includes a receiving unit 501 and a generating unit 502. The device 500 can be used to execute the method 100 or the method 200 in the above embodiment.

[0147] Among them, the receiving unit 501 is used to receive a first border gateway protocol BGP route announcement message sent by the control and management device. The first BGP route announcement message is based on the fourth version virtual private network VPNv4 address family or the sixth version virtual private network VPNv6 address family or the three-layer Ethernet virtual private network L3EVPN address family to announce the first VPN route. The first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix. The network address of the first next hop is a private network IP address.

[0148] The generating unit 502 is configured to generate a first virtual routing forwarding VRF table entry according to the indication information, where the first VRF table entry includes an IP address prefix and first outbound interface information, wherein the first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop.

[0149] The specific implementation of the operation performed by the receiving unit 501 and the effect achieved can be found in the description of S103 in the method 100. The specific implementation of the operation performed by the generating unit 502 and the effect achieved can be found in the description of S104 in the method 100.

[0150] In one implementation, the generating unit 502 may include: a first determining subunit and a first generating subunit. The first determining subunit is configured to determine, in a local VRF table, first outbound interface information for reaching the first next hop based on the indication information and the network address of the first next hop; and the first generating subunit is configured to generate a first VRF table entry based on the IP address prefix and the first outbound interface information.

[0151] In one implementation, the first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, where the RD is a non-zero value. For example, the RD is used to identify the VPN to which the first next hop belongs.

[0152] In one implementation, the first next hop is a traffic cleaning server.

[0153] In one implementation, the destination host and the first next hop may belong to the same VPN, or they may belong to different VPNs.

[0154] In one implementation, the receiving unit 501 in the device 500 is further configured to receive first traffic sent by a first user edge CE device, where the destination address of the first traffic and the IP address prefix belong to the same network segment; then, the device 500 may further include: a first sending unit, configured to forward the first traffic to a first next hop via a first output interface. For the specific implementation of the operation performed by the receiving unit 501 in this implementation and the effect achieved, please refer to the relevant description of S105 in method 100. For the specific implementation of the operation performed by the first sending unit and the effect achieved, please refer to the relevant description of S106 in method 100.

[0155] In one implementation, the receiving unit 501 in the apparatus 500 is further configured to receive a second BGP route advertisement message sent by the control and management device, the second BGP route advertisement message announcing a second VPN route, the first BGP route advertisement message and the second BGP route advertisement message using the same VPN address family, the second VPN route including an IP address prefix and a network address of a second next hop to the IP address prefix, the second next hop being a second PE device, and the first PE device communicating with the second PE device via a public network tunnel; and the generating unit 502 is further configured to generate a second VRF table entry based on the second BGP route advertisement message, the second VRF table entry including an IP address prefix and second outgoing interface information, the second outgoing interface information being used to identify the second outgoing interface of the first PE device corresponding to the public network tunnel. The specific implementation of the operation performed by the receiving unit 501 in this implementation and the effects achieved can be found in the description of S203 in method 200. The specific implementation of the operation performed by the generating unit 502 and the effects achieved can be found in the description of S204 in method 200.

[0156] In one implementation, the generating unit 502 may further include: a second determining subunit and a second generating subunit, wherein the second determining subunit is configured to determine the second outgoing interface information in the local VRF table; and the second generating subunit is configured to generate a second VRF table entry based on the IP address prefix and the second outgoing interface information.

[0157] In one implementation, the receiving unit 501 in the apparatus 500 is further configured to receive second traffic sent by a second CE device. The apparatus 500 may further include: a replication unit and a second transmission unit, wherein the replication unit is configured to replicate the second traffic to obtain third traffic; the second transmission unit is configured to forward the second traffic to the first next hop via the first output interface; and the second transmission unit is further configured to forward the third traffic to the second PE device via the second output interface. The specific implementation of the operation performed by the receiving unit 501 in this implementation and the effects achieved can be found in the description of S305 in method 200. The specific implementation of the operation performed by the replication unit and the effects achieved can be found in the description of S305 in method 200. The specific implementation of the operation performed by the second transmission unit and the effects achieved can be found in the description of S306 and S307 in method 200.

[0158] In one implementation, the first PE device connects to the destination host via a first path and a second path, respectively, and the first path includes a first next hop. Then, the receiving unit 501 in the apparatus 500 is further configured to receive fourth traffic sent by a third CE device; the apparatus may further include: a third sending unit configured to load balance the fourth traffic via the first path and the second path. The specific implementation of the operation performed by the receiving unit 501 in this implementation and the effects achieved can be found in the description of S305' in method 200. The specific implementation of the operation performed by the third sending unit and the effects achieved can be found in the description of S306' in method 200.

[0159] In one implementation, the first PE device is a first ASBR, the first next hop is a second ASBR, a private network interface is provided between the first ASBR and the second ASBR, and the first outbound interface is the private network interface connecting the first ASBR to the second ASBR. The receiving unit 501 in the apparatus 500 is further configured to receive fifth traffic, where the destination address and the IP address prefix belong to the same network segment. The apparatus 500 also includes a fourth sending unit configured to forward the fifth traffic to the second ASBR via the first outbound interface. The specific implementation of the operations performed by the receiving unit 501 in this implementation and the effects achieved can be found in the description of S105' in method 100. The specific implementation of the operations performed by the fourth sending unit and the effects achieved can be found in the description of S106' in method 100.

[0160] In addition, the present invention also provides a flow control device 600, see Figure 6 shown. Figure 6Schematic diagram of a flow control device 600 provided in an embodiment of the present application. The flow control device 600 is applied to a control management device, and includes a generating unit 601 and a sending unit 602. The device 600 can be used to execute the method 100 or the method 200 in the above embodiment.

[0161] Wherein, the generating unit 601 is configured to generate a first BGP route advertisement message;

[0162] A sending unit 602 is configured to send a first BGP route announcement message to a first operator edge PE device, wherein the first BGP route announcement message announces a first VPN route based on the fourth version virtual private network VPNv4 address family or the sixth version virtual private network VPNv6 address family or the three-layer Ethernet virtual private network L3EVPN address family. The first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix. The network address of the first next hop is a private network IP address. The indication information instructs the first PE device to generate a first virtual route forwarding VRF table entry. The first VRF table entry includes the IP address prefix and the first outbound interface information. The first outbound interface information is used to identify the first outbound interface of the first PE device connected to the first next hop.

[0163] The specific implementation of the operation performed by the generating unit 601 and the effect achieved can be found in the description of S101 in the method 100. The specific implementation of the operation performed by the sending unit 602 and the effect achieved can be found in the description of S102 in the method 100.

[0164] In one implementation, the first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, where the RD is a non-zero value. For example, the RD is used to identify the VPN to which the first next hop belongs.

[0165] In one implementation, the first next hop is a traffic cleaning server.

[0166] In one implementation, the destination host and the first next hop may belong to the same VPN, or they may belong to different VPNs.

[0167] In one implementation, the generating unit 601 in the apparatus 600 is further configured to generate a second BGP route advertisement message; and the sending unit 602 is further configured to send the second BGP route advertisement message to the first PE device, wherein the second BGP route advertisement message announces a second VPN route, the first BGP route advertisement message and the second BGP route advertisement message use the same VPN address family, the second VPN route includes an IP address prefix and a network address of a second next hop to reach the IP address prefix, the second next hop being a second PE device, the first PE device communicating with the second PE device via a public network tunnel, and the second BGP route advertisement message is used to instruct the first PE device to generate a second VRF table entry, the second VRF table entry including the IP address prefix and second outbound interface information, the second outbound interface information being used to identify the second outbound interface of the first PE device corresponding to the public network tunnel. In this implementation, the specific implementation of the operations performed by the generating unit 601 and the effects achieved can be found in the description of S201 in method 200. The specific implementation of the operations performed by the sending unit 602 and the effects achieved can be found in the description of S202 in method 200.

[0168] In addition, the present application embodiment also provides a communication device 700, see Figure 7 As shown, Figure 7 The structure diagram of a communication device 700 provided in an embodiment of the present application is shown in FIG. The communication device 700 can be used to execute the method 100 or the method 200 in the above embodiment.

[0169] like Figure 7As shown, the communication device 700 may include a processor 710 and a memory 720 coupled to the processor 710. The processor 710 may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor may also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 710 may refer to a single processor or may include multiple processors. The memory 720 may include volatile memory, such as random-access memory (RAM); the memory may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid-state drive (SSD); the memory 720 may also include a combination of the above-mentioned types of memory. The memory 720 may refer to a single memory or may include multiple memories. In one embodiment, the memory 720 stores computer-readable instructions, which include multiple software modules, such as a first processing module 721 and a second processing module 722. In addition, the memory 720 may include at least one of a third processing module, a fourth processing module, and a fifth processing module, which may each correspond to a functional module in the generation unit 502 of the flow control device 500 or a functional module in the generation unit 601 of the flow control device 600. After executing each software module, the processor 710 may perform corresponding operations according to the instructions of each software module. In this embodiment, the operation executed by a software module actually refers to the operation performed by the processor 710 according to the instructions of the software module.For example, the “generating a first virtual routing forwarding VRF table entry according to the indication information” executed by the first processing module 721 may actually refer to the “generating a first virtual routing forwarding VRF table entry according to the indication information” executed by the processor 710 according to the instruction of the first processing module 721. At this time, the first processing module 721 may correspond to the generation unit 502 in the communication device 500.

[0170] In one example, the communication device 700 may execute the method 100 in the above embodiment. When the communication device 700 is used to execute the method 100 in the above embodiment: the processor 710 is used to execute all processing-related operations in the method 100. For example, the processor 710 is used to generate a first virtual routing forwarding (VRF) table entry based on the indication information, where the first VRF table entry includes an IP address prefix and first outbound interface information, where the first outbound interface information is used to identify a first outbound interface of the first PE device connected to the first next hop.

[0171] In one example, the communication device 700 may execute the method 200 in the above embodiment. When the communication device 700 is configured to execute the method 200 in the above embodiment: the processor 710 is configured to execute all processing-related operations in the method 200. For example, the processor 710 is configured to generate a first BGP route advertisement message.

[0172] In addition, the present embodiment also provides a communication system 800, see Figure 8 shown. Figure 8 The structure diagram of a communication system 800 provided in an embodiment of the present application is shown in FIG. The communication system 800 may include a first PE device 801 and a control management device 802 .

[0173] The first PE device 801 may be, for example, Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d The PE device 21 in the method is used to execute the operations implemented by the first PE device in method 100 and method 200.

[0174] The control management device 802 may be, for example, Figure 1a 、 Figure 1b 、 Figure 1c or Figure 1d The control management device 10 in the method is used to execute the operations implemented by the control management device in the method 100 and the method 200.

[0175] For the specific implementation and effects achieved by the communication system 800, please refer to the relevant descriptions of the above-mentioned method 100 and method 200.

[0176] The present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computer, it enables the computer to perform any one or more operations of the method described in any of the aforementioned embodiments (for example, method 100 or method 200).

[0177] The present application also provides a computer program product, including a computer program, which, when executed on a computer, enables the computer to perform any one or more operations of the method described in any of the aforementioned embodiments (eg, method 100 or method 200).

[0178] The terms "first," "second," "third," "fourth," and the like (if any) in the specification and claims of this application and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions, e.g., a process, method, system, product, or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0179] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0180] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical business division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0181] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0182] In addition, each business unit in each embodiment of the present application can be integrated into a processing unit, each unit can exist physically separately, or two or more units can be integrated into a single unit. The above-mentioned integrated units can be implemented in the form of hardware or software business units.

[0183] If the integrated unit is implemented in the form of a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0184] Those skilled in the art will appreciate that, in one or more of the examples above, the services described herein may be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these services may be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one location to another. Storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0185] The above specific implementation methods further describe in detail the purpose, technical solutions and beneficial effects of this application. It should be understood that the above are only specific implementation methods of this application.

[0186] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A flow control method, characterized in that: The method is performed by a first operator edge PE device, and includes: Receiving a first Border Gateway Protocol (BGP) route advertisement message sent by a control and management device, the first BGP route advertisement message being based on a fourth-version Virtual Private Network (VPNv4) address family, a sixth-version Virtual Private Network (VPNv6) address family, or a Layer 3 Ethernet Virtual Private Network (L3EVPN) address family to advertise a first VPN route, the first VPN route including indication information, an Internet Protocol (IP) address prefix of a destination host, and a network address of a first next hop to reach the IP address prefix, wherein the network address of the first next hop is a private network IP address, and the indication information is used to instruct to iterate the first VPN route to the private network next hop; According to the indication information, a first virtual routing forwarding VRF table entry is generated, wherein the first VRF table entry includes the IP address prefix and the first outgoing interface information, wherein the first outgoing interface information is used to identify the first outgoing interface of the first PE device connected to the first next hop, and the first outgoing interface information corresponds to the network address of the first next hop.

2. The method according to claim 1, characterized in that Generating a first virtual routing forwarding VRF table entry according to the indication information includes: Determining, in a local VRF table, information about the first outbound interface that reaches the first next hop according to the indication information and the network address of the first next hop; Generate the first VRF table entry according to the IP address prefix and the first outbound interface information.

3. The method according to claim 1, characterized in that The first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, and the RD is a non-zero value.

4. The method according to claim 3, characterized in that The RD is used to identify the VPN to which the first next hop belongs.

5. The method according to claim 1, wherein The first next hop is a traffic cleaning server.

6. The method according to claim 1, characterized in that The destination host and the first next hop belong to the same VPN.

7. The method according to claim 1, characterized in that The destination host and the first next hop belong to different VPNs.

8. The method according to claim 1, characterized in that The method further comprises: Receive first traffic sent by a first user edge CE device, where a destination address of the first traffic and the IP address prefix belong to the same network segment; Forward the first traffic to the first next hop through the first outbound interface.

9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: receiving a second BGP route advertisement message sent by the control and management device, where the second BGP route advertisement message advertises a second VPN route, the first BGP route advertisement message and the second BGP route advertisement message use the same VPN address family, the second VPN route includes the IP address prefix and a network address of a second next hop to reach the IP address prefix, the second next hop being a second PE device, and the first PE device communicating with the second PE device through a public network tunnel; A second VRF table entry is generated according to the second BGP route announcement message, where the second VRF table entry includes the IP address prefix and second outbound interface information, where the second outbound interface information is used to identify the second outbound interface of the first PE device corresponding to the public network tunnel.

10. The method according to claim 9, characterized in that Generating a second VRF table entry according to the second BGP route advertisement message includes: Determine the second outbound interface information in the local VRF table; Generate the second VRF table entry according to the IP address prefix and the second outbound interface information.

11. The method according to claim 9, characterized in that The method further comprises: receiving and copying the second traffic sent by the second CE device to obtain third traffic; forwarding the second traffic to the first next hop through the first outbound interface; Forward the third traffic to the second PE device through the second outbound interface.

12. The method according to any one of claims 1 to 8, characterized in that The first PE device is connected to the destination host via a first path and a second path respectively, the first path includes the first next hop, and the method further includes: receiving fourth traffic sent by a third CE device to the destination host; The fourth traffic is load-balanced through the first path and the second path.

13. The method according to any one of claims 1 to 8, characterized in that The first PE device is a first autonomous system boundary router (ASBR), the first next hop is a second ASBR, and the first outbound interface is a private network interface of the first ASBR connected to the second ASBR. The method further includes: receiving fifth traffic, where a destination address of the fifth traffic and the IP address prefix belong to the same network segment; Forward the fifth traffic to the second ASBR through the first outbound interface.

14. A flow control method, characterized in that: Executed by a control management device, the method includes: Generate a first Border Gateway Protocol (BGP) route advertisement message; The first BGP route announcement message is sent to the first operator edge PE device, wherein the first BGP route announcement message announces the first VPN route based on the fourth version virtual private network VPNv4 address family or the sixth version virtual private network VPNv6 address family or the three-layer Ethernet virtual private network L3EVPN address family, the first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix, wherein the network address of the first next hop is a private network IP address, the indication information instructs the first PE device to generate a first virtual route forwarding VRF table entry, the first VRF table entry includes the IP address prefix and first outgoing interface information, the first outgoing interface information is used to identify the first outgoing interface of the first PE device connected to the first next hop, the indication information is used to instruct to iterate the first VPN route to the private network next hop, and the first outgoing interface information corresponds to the network address of the first next hop.

15. The method according to claim 14, characterized in that The first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, and the RD is a non-zero value.

16. The method according to claim 15, characterized in that The RD is used to identify the VPN to which the first next hop belongs.

17. The method according to claim 14, characterized in that The first next hop is a traffic cleaning server.

18. The method according to claim 14, characterized in that The destination host and the first next hop belong to the same VPN.

19. The method according to claim 14, wherein The destination host and the first next hop belong to different VPNs.

20. The method according to any one of claims 14 to 19, characterized in that: The method further comprises: Generate a second BGP route advertisement message; Send the second BGP route announcement message to the first PE device, wherein the second BGP route announcement message announces the second VPN route, the first BGP route announcement message and the second BGP route announcement message use the same VPN address family, the second VPN route includes the IP address prefix and the network address of the second next hop to reach the IP address prefix, the second next hop is the second PE device, the first PE device communicates with the second PE device through a public network tunnel, the second BGP route announcement message instructs the first PE device to generate a second VRF table entry, the second VRF table entry includes the IP address prefix and second outbound interface information, and the second outbound interface information is used to identify the second outbound interface of the first PE device corresponding to the public network tunnel.

21. A flow control device, characterized in that: Applied to a first operator's edge PE device, the apparatus includes: a receiving unit, configured to receive a first Border Gateway Protocol (BGP) route advertisement message sent by a control and management device, the first BGP route advertisement message being based on a version 4 Virtual Private Network (VPNv4) address family, a version 6 Virtual Private Network (VPNv6) address family, or a Layer 3 Ethernet Virtual Private Network (L3EVPN) address family, advertising a first VPN route, the first VPN route including indication information, an IP address prefix of a destination host, and a network address of a first next hop to reach the IP address prefix, the network address of the first next hop being a private network IP address, and the indication information being used to instruct iterating the first VPN route to the private network next hop; A generation unit is used to generate a first virtual routing forwarding VRF table entry according to the indication information, wherein the first VRF table entry includes the IP address prefix and the first output interface information, wherein the first output interface information is used to identify the first output interface of the first PE device connected to the first next hop, and the first output interface information corresponds to the network address of the first next hop.

22. The device according to claim 21, characterized in that The generating unit comprises: A first determining subunit, configured to determine, in a local VRF table, information about the first outbound interface that reaches the first next hop according to the indication information and the network address of the first next hop; The first generating subunit is configured to generate the first VRF table entry according to the IP address prefix and the first outbound interface information.

23. The device according to claim 21, characterized in that The first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, and the RD is a non-zero value.

24. The device according to claim 23, characterized in that The RD is used to identify the VPN to which the first next hop belongs.

25. The device according to claim 21, characterized in that The first next hop is a traffic cleaning server.

26. The device according to claim 21, characterized in that The destination host and the first next hop belong to the same VPN.

27. The device according to claim 21, characterized in that The destination host and the first next hop belong to different VPNs.

28. The device according to claim 21, characterized in that The receiving unit is further configured to receive first traffic sent by a first user edge CE device, where the destination address of the first traffic and the IP address prefix belong to the same network segment; The device further includes: a first sending unit, The first sending unit is configured to forward the first traffic to the first next hop through the first outbound interface.

29. The device according to any one of claims 21 to 28, characterized in that The receiving unit is further configured to receive a second BGP route advertisement message sent by the control and management device, where the second BGP route advertisement message advertises a second VPN route, the first BGP route advertisement message and the second BGP route advertisement message use the same VPN address family, the second VPN route includes the IP address prefix and a network address of a second next hop to reach the IP address prefix, the second next hop is a second PE device, and the first PE device communicates with the second PE device through a public network tunnel; The generating unit is further used to generate a second VRF table entry according to the second BGP route announcement message, wherein the second VRF table entry includes the IP address prefix and the second outgoing interface information, and the second outgoing interface information is used to identify the second outgoing interface of the first PE device corresponding to the public network tunnel.

30. The device according to claim 29, characterized in that The generating unit further includes: A second determining subunit, configured to determine the second outbound interface information in a local VRF table; The second generating subunit is used to generate the second VRF table entry according to the IP address prefix and the second outbound interface information.

31. The device according to claim 29, characterized in that The receiving unit is further configured to receive second traffic sent by a second CE device; The device further includes: a copying unit and a second sending unit, The replication unit is configured to replicate the second flow to obtain a third flow; The second sending unit is configured to forward the second traffic to the first next hop through the first outbound interface; The second sending unit is further configured to forward the third traffic to the second PE device through the second outbound interface.

32. The device according to any one of claims 21 to 28, characterized in that The first PE device is connected to the destination host via a first path and a second path respectively, the first path includes the first next hop, The receiving unit is further configured to receive fourth traffic sent by a third CE device; The device further includes: a third sending unit, The third sending unit is configured to load balance the fourth traffic through the first path and the second path.

33. The device according to any one of claims 21 to 28, characterized in that The first PE device is a first autonomous system boundary router (ASBR), the first next hop is a second ASBR, and the first outbound interface is a private network interface connecting the first ASBR to the second ASBR. The receiving unit is further configured to receive fifth traffic, wherein the destination address of the fifth traffic and the IP address prefix belong to the same network segment; The device further includes: a fourth sending unit, The fourth sending unit is configured to forward the fifth traffic to the second ASBR through the first outbound interface.

34. A flow control device, characterized in that: Applied to control and manage equipment, the device includes: A generating unit, configured to generate a first BGP route advertisement message; A sending unit is used to send the first BGP route announcement message to a first operator edge PE device, wherein the first BGP route announcement message is based on the fourth version of the virtual private network VPNv4 address family or the sixth version of the virtual private network VPNv6 address family or the three-layer Ethernet virtual private network L3EVPN address family to announce the first VPN route, the first VPN route includes indication information, the IP address prefix of the destination host, and the network address of the first next hop to reach the IP address prefix, the network address of the first next hop is a private network IP address, the indication information instructs the first PE device to generate a first virtual route forwarding VRF table entry, the first VRF table entry includes the IP address prefix and first outgoing interface information, the first outgoing interface information is used to identify the first outgoing interface of the first PE device connected to the first next hop, the indication information is used to instruct to iterate the first VPN route to the private network next hop, and the first outgoing interface information corresponds to the network address of the first next hop.

35. The device according to claim 34, characterized in that The first BGP route advertisement message includes a next hop address field, and the indication information is a route distinguisher RD included in the next hop address field, and the RD is a non-zero value.

36. The device according to claim 35, characterized in that The RD is used to identify the VPN to which the first next hop belongs.

37. The device according to claim 34, characterized in that The first next hop is a traffic cleaning server.

38. The device according to claim 34, characterized in that The destination host and the first next hop belong to the same VPN.

39. The device according to claim 34, characterized in that The destination host and the first next hop belong to different VPNs.

40. The device according to any one of claims 34 to 39, characterized in that The generating unit is further configured to generate a second BGP route advertisement message; The sending unit is further used to send the second BGP route announcement message to the first PE device, wherein the second BGP route announcement message announces a second VPN route, the first BGP route announcement message and the second BGP route announcement message use the same VPN address family, the second VPN route includes the IP address prefix and the network address of the second next hop to reach the IP address prefix, the second next hop is the second PE device, the first PE device communicates with the second PE device through a public network tunnel, the second BGP route announcement message instructs the first PE device to generate a second VRF table entry, the second VRF table entry includes the IP address prefix and second outbound interface information, and the second outbound interface information is used to identify the second outbound interface of the first PE device corresponding to the public network tunnel.

41. A communication device, characterized in that The communication device includes a memory and a processor; The memory is used to store program code; The processor is configured to execute instructions in the program code so that the communication device executes the method according to any one of claims 1 to 13.

42. A communication device, characterized in that The communication device includes a memory and a processor; The memory is used to store program code; The processor is configured to execute instructions in the program code so that the communication device executes the method according to any one of claims 14 to 20.

43. A communication system, characterized in that The communication system includes a first operator edge PE device and a control management device; The first PE device is configured to execute the method according to any one of claims 1 to 13 above; The control and management device is used to execute the method described in any one of claims 14 to 20 above.

44. A computer program product, characterized in that The invention comprises a program, which implements the method according to any one of claims 1 to 20 when the program is run on a processor.

45. A computer-readable storage medium, characterized in that The computer-readable storage medium includes instructions, which, when executed on a processor, implement the method according to any one of claims 1 to 20.

Citation Information

Patent Citations

  • VPN route advertisement method, data flow forwarding method and related equipment

    CN107026796A