Transmission of vpn traffic with reduced header information
By transmitting headerless VPN services between PE network devices and updating the data structure using announcement messages, the problem of increased computing resources caused by headers in VPN services is solved, thus improving device performance.
Patent Information
- Application Number
- CN202211649841.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-30
- Filing Date
- 2022-12-21
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-12-21
AI Technical Summary
In VPN service transmission, the presence of IP and UDP headers in existing technologies increases the size of the service, which in turn increases the utilization of computing resources of PE network devices and affects performance.
By transmitting headerless VPN services between PE network devices, the data structure is updated using announcement messages to include tags and service information. PE network devices can remove or add IP and UDP headers as needed to reduce service size and improve device performance.
This reduces the computational resource usage of VPN services in processing and forwarding between PE network devices, and improves the bandwidth performance, latency performance, and reliability performance of the devices.
Smart Images

Figure CN116346533B_ABST
Abstract
Description
[0001] Related Applications Cross Reference To
[0002] This application claims priority to U.S. Patent Application No. 63 / 265,879, filed December 22, 2021, entitled “PSEUDOWIRE FOR INTERNET PROTOCOL OR USER DATAGRAM PROTOCOL PAYLOAD WITHOUT HEADERS.” The entire contents of the aforementioned application are hereby expressly incorporated by reference. BACKGROUND
[0003] Virtual private networks (VPNs) can provide virtual multipoint bridging connections between different Layer 2 domains, such as over Internet Protocol (IP) or IP / Multi-Protocol Label Switching (MPLS) backbone networks. VPN instances are configured on provider edge (PE) network devices (e.g., routers, switches, etc.) to maintain logical service separation between customer edge (CE) network devices (e.g., routers, switches, host devices, etc.). The PE network devices are connected to the CE network devices. In some cases, the CE network devices can be network function (NF) elements of a cellular network (e.g., a Fifth Generation (5G) network or a Fourth Generation (4G) network). SUMMARY
[0004] In some implementations, a method includes receiving, by a first PE network device associated with a VPN and from a first CE network device, traffic including at least an IP header; determining, by the first PE network device, whether the first PE network device is to remove the IP header, or the IP header and a UDP header, included in the traffic from the traffic; and sending, by the first PE network device and to one or more second PE network devices, the traffic, wherein when the first PE network device makes the removal determination, the first PE network device updates the traffic by removing the IP header, or the IP header and the UDP header, prior to sending the traffic, and wherein when the first PE network device does not make the removal determination, the first PE network device does not update the traffic prior to sending the traffic.
[0005] In some implementations, a method includes receiving, by a first PE network device associated with a VPN and from a second PE network device, traffic including a MPLS label stack; regenerating, by the first PE network device and based on an inner label of the MPLS label stack, an IP header, or an IP header and a UDP header; and sending, to a CE network device, the traffic with the IP header, or the IP header and the UDP header, included in the traffic.
[0006] In some implementations, a first PE network device associated with a VPN includes one or more memories; and one or more processors to: receive traffic including at least an IP header from a first CE network device; determine whether the first PE network device is to remove the IP header, or the IP header and a UDP header, included in the traffic from the traffic; and send the traffic to one or more second PE network devices, wherein when the first PE network device makes the removal determination, the first PE network device updates the traffic by removing the IP header, or the IP header and the UDP header, prior to sending the traffic, and wherein when the first PE network device does not make the removal determination, the first PE network device does not update the traffic prior to sending the traffic.
[0007] In some implementations, a method includes: receiving, by a network device and from another network device, virtual private network (VPN) traffic; identifying, by the network device, a label included in the VPN traffic; identifying, by the network device and based on the label, an entry in a data structure; updating, by the network device and based on the entry in the data structure, the VPN traffic by: removing at least the label from the VPN traffic, and including in the VPN traffic at least IP header information indicated by the entry; and after updating the VPN traffic, forwarding, by the network device, the VPN traffic to the other device.
[0008] In some implementations, a network device includes one or more memories; and one or more processors to: receive VPN traffic from another network device; identify IP header information and user datagram protocol (UDP) header information included in the VPN traffic; identify an entry in a data structure based on the IP header information and the UDP header information; update the VPN traffic based on the entry in the data structure by: removing at least the IP header information from the VPN traffic, and including in the VPN traffic at least a label indicated by the entry; and after updating the VPN traffic, forward the VPN traffic to another network associated with the entry.
[0009] In some implementations, a non-transitory computer-readable medium storing a set of instructions includes one or more instructions that, when executed by one or more processors of a network device, cause the network device to: send, to another network device, an advertisement message, wherein the advertisement message includes a label, a route distinguisher, and traffic information indicating at least a destination IP address; and update a data structure to include an entry, wherein the entry includes the label, the route distinguisher, and reconstruction information including at least IP header information, wherein the IP header information includes the destination IP address.
[0010] An aspect of the disclosure provides a method comprising: receiving, by a first PE network device associated with a VPN and from a first CE network device, traffic comprising at least an IP header; determining, by the first PE network device, whether the first PE network device is to remove, from the traffic, the IP header, or the IP header and a UDP header, included in the traffic; and sending, by the first PE network device and to one or more second PE network devices, the traffic, wherein when the first PE network device makes a removal determination, the first PE network device updates the traffic by removing the IP header, or the IP header and the UDP header, prior to sending the traffic, and wherein when the first PE network device does not make a removal determination, the first PE network device does not update the traffic prior to sending the traffic.
[0011] According to one or more embodiments, wherein after the first PE network device updates the traffic, the traffic comprises a MPLS label stack, wherein an inner label of the MPLS label stack is used to regenerate, by a PE network device receiving the traffic, a new IP header, or a new IP header and a new UDP header.
[0012] According to one or more embodiments, wherein the first PE network device determines the inner label included in the MPLS label stack based on an advertisement received from at least one of the one or more second PE network devices or a controller.
[0013] According to one or more embodiments, wherein the advertisement comprises the inner label and traffic information, wherein the traffic information comprises at least one of: a destination IP address, a source IP address, a destination UDP port, or a source UDP port.
[0014] According to one or more embodiments, further comprising: updating a data structure for the VPN to include an entry, the entry comprising the inner label and the traffic information.
[0015] According to one or more embodiments, wherein determining whether the first PE network device is to remove, from the traffic, the IP header, or the IP header and the UDP header, included in the traffic, comprises: determining, based on the IP header, or the IP header and the UDP header, whether a data structure for the VPN includes an entry; and determining that the first PE network device is to: remove, based on a determination that the data structure includes the entry, the IP header, or the IP header and the UDP header, included in the traffic, not remove, based on a determination that the data structure does not include the entry, the IP header, or the IP header and the UDP header, included in the traffic.
[0016] Another aspect of the disclosure provides a method comprising: receiving, by a first PE network device associated with a VPN and from a second PE network device, traffic comprising a MPLS label stack; regenerating, by the first PE network device and based on an inner label of the MPLS label stack, an IP header, or an IP header and a UDP header; sending, by the first PE network device, the traffic to a CE network device, wherein the IP header, or the IP header and the UDP header, are included in the traffic.
[0017] According to one or more embodiments, further comprising: sending, to the second PE network device and prior to receiving the traffic, an advertisement, wherein the advertisement comprises the inner label and traffic information.
[0018] According to one or more embodiments, wherein the traffic information comprises at least one of: a destination IP address, a source IP address, a destination UDP port, or a source UDP port.
[0019] According to one or more embodiments, further comprising: updating a data structure for the VPN to include an entry, the entry comprising the inner label and the traffic information.
[0020] According to one or more embodiments, further comprising: receiving, from a controller and prior to receiving the traffic, an advertisement, wherein the advertisement comprises the inner label and traffic information.
[0021] According to one or more embodiments, further comprising: updating a data structure for the VPN to include an entry, the entry comprising the inner label and the traffic information.
[0022] According to one or more embodiments, wherein regenerating the IP header, or the IP header and the UDP header, comprises: identifying, based on the inner label of the MPLS label stack, an entry in a data structure for the VPN; and regenerating the IP header, or the IP header and the UDP header, based on the entry.
[0023] Yet another aspect of the disclosure provides a first PE network device associated with a VPN, comprising: one or more memories; and one or more processors to: receive, from a first CE network device, traffic comprising at least an IP header; determine whether the first PE network device is to remove, from the traffic, the IP header, or the IP header and a UDP header, included in the traffic; and send, to one or more second PE network devices, the traffic, wherein when the first PE network device makes a removal determination, the first PE network device updates the traffic by removing the IP header, or the IP header and the UDP header, prior to sending the traffic, and wherein when the first PE network device does not make the removal determination, the first PE network device does not update the traffic prior to sending the traffic.
[0024] According to one or more embodiments, wherein after the first PE network device updates the traffic, the traffic comprises a MPLS label stack, wherein an inner label of the MPLS label stack is used to regenerate, by the PE network device receiving the traffic, a new IP header, or a new IP header and a new UDP header.
[0025] According to one or more embodiments, wherein the first PE network device determines the inner label included in the MPLS label stack based on an advertisement received from at least one of the one or more second PE network devices or the controller.
[0026] According to one or more embodiments, wherein the advertisement comprises the inner label and traffic information.
[0027] According to one or more embodiments, wherein the traffic information comprises at least one of: a destination IP address, a source IP address, a destination UDP port, or a source UDP port.
[0028] According to one or more embodiments, wherein the one or more processors are further to: update a data structure for the VPN to include an entry, the entry comprising the inner label and the traffic information.
[0029] According to one or more embodiments, wherein to determine whether the first PE network device is to remove, from the traffic, an IP header, or an IP header and a UDP header, included in the traffic, the one or more processors are to: determine, based on the IP header, or the IP header and the UDP header, whether a data structure for the VPN includes an entry; and determine that the first PE network device is to: remove, based on a determination that the data structure includes the entry, the IP header, or the IP header and the UDP header, included in the traffic, not remove, based on a determination that the data structure does not include the entry, the IP header, or the IP header and the UDP header, included in the traffic. BRIEF DESCRIPTION OF DRAWINGS
[0030] Figures 1A-1C is a schematic diagram of one or more example implementations described herein.
[0031] Figure 2 is a schematic diagram of an example advertisement message.
[0032] Figure 3 is a schematic diagram of an example environment in which the systems and / or methods described herein can be implemented.
[0033] Figure 4 is a schematic diagram of example components of a device that can correspond to a CE network device and / or a PE network device.
[0034] Figure 5 is a schematic diagram of example components of a device that can correspond to a CE network device and / or a PE network device.
[0035] Figures 6-9 is a flow diagram of an example procedure related to the transmission of VPN traffic with reduced header information. DETAILED DESCRIPTION
[0036] The following detailed description of example implementations refers to the accompanying drawings. The same reference numbers in different drawings can identify the same or similar elements.
[0037] In some cases, CE network devices communicate with each other via a General Packet Radio Service (GPRS) Tunneling Protocol (GTP) tunnel (e.g., via one or more PE network devices). To do so, a source CE device encapsulates GTP traffic with an IP header, a User Datagram Protocol (UDP) header, and a GTP header to enable the transmission of the traffic to a destination CE device via the one or more PE network devices. However, when the CE network devices communicate GTP traffic via an IP data plane (e.g., that supports IPv6 and / or Segment Routing (SR) v6), an ingress PE network device must add an IPv6 header (e.g., in addition to the IP header, the UDP header, and the GTP header) to the GTP traffic to route the GTP traffic to an egress PE network device. This increases the size of the GTP traffic, which increases the usage of computing resources (e.g., processing resources, memory resources, communication resources, and / or power resources, etc.) of the PE network devices used to process and forward the GTP traffic between the CE devices and / or impacts the performance of the PE network devices (e.g., in terms of bandwidth performance, latency performance, and / or reliability performance, etc.).
[0038] In some implementations described herein, CE network devices communicate with each other via VPN connections (e.g., over an MPLS data plane, an IP data plane, or another data plane) (e.g., via one or more PE network devices). For example, a first PE network device advertises (e.g., sends) an advertisement message that advertises a label (e.g., that is associated with a source CE network device; a destination CE network device; and / or a payload type, such as an IP and / or UDP payload type). Then, the source CE network device sends VPN traffic (e.g., VPN traffic associated with the VPN connection, VPN traffic destined for the destination CE network device, and VPN traffic that includes IP header information and UDP header information) to a second PE network device. The second PE network device removes the IP header information (and in some implementations, the UDP header information) from the VPN traffic based on the advertisement message provided by the first PE network device, and includes the label in the VPN traffic. Then, the second PE network device sends the VPN traffic to the first PE network device. The first PE network device receives the VPN traffic, and adds the IP header information (and in some implementations, the UDP header information) to the VPN traffic based on the label included in the VPN traffic, and removes the label from the VPN traffic. The first PE network device sends the traffic to the destination CE network device.
[0039] In this way, some implementations described herein enable the transmission of VPN traffic between PE network devices without header information (e.g., without IP header information, and in some implementations, without UDP header information). This reduces the size of the VPN traffic (e.g., which still includes the payload), which reduces the usage of computing resources (e.g., processing resources, memory resources, communication resources, and / or power resources, etc.) of the PE network devices used to process and forward the VPN traffic between the CE devices (e.g., compared to processing and forwarding traffic that includes header information). Additionally, this improves the performance of the PE network devices (e.g., in terms of bandwidth performance, latency performance, and / or reliability performance, etc.) compared to PE devices that process and forward traffic that includes header information.
[0040] Figures 1A-1C is a schematic diagram of one or more example implementations 100 described herein. The example implementation(s) 100 can include a source CE network device CE1, a destination CE network device CE2, and a plurality of PE network devices (shown in Figures 1A-1C as PE network devices PE1-PE3) in a network, which will be described in more detail below in connection with Figures 2-4 FIG. 1. As shown in Figure 1AAs shown, a VPN connection (e.g., an IP-VPN connection) can be established between the source CE network device CE1 and the destination CE network device CE2. Therefore, VPN services (e.g., IP-VPN services) can be transmitted between the source CE network device CE1 and the destination CE network device CE2 via multiple network devices described herein.
[0041] like Figure 1A As shown, and by reference numeral 102, PE network device PE1 can send an advertisement message (also referred to herein as an advertisement) to one or more other PE network devices among a plurality of PE network devices. For example, PE network device PE1 can advertise the advertisement message to one or more other PE network devices (e.g., according to a protocol such as Border Gateway Protocol (BGP) or Interior Gateway Protocol (IGP). PE network device PE1 can send the advertisement message via the control plane of the network associated with the plurality of PE network devices. In some implementations, a controller associated with the network (e.g., another network device) can advertise the advertisement message to PE network device PE1 and one or more other PE network devices.
[0042] The announcement message may include labels (e.g., Multiprotocol Label Switching (MPLS) labels or another label, also referred to herein as an internal label), routing identifiers (RDs), and / or service information. The RD may be associated with a VPN connection between the source CE network device CE1 and the destination CE network device CE2 (e.g., ...). Figure 1A (As shown) The service information may include a destination IP address (e.g., the IP address of the destination CE network device CE2, also known as DST-IP), and may also include a source IP address (e.g., the IP address of the source CE network device CE1, also known as SRC-IP), a source UDP address (e.g., the UDP port of the source CE network device CE1, also known as SRC-UDP), and / or a destination UDP address (e.g., the UDP port of the destination CE network device CE2, also known as DST-IP). The advertisement message may be formatted as a tuple of fields, such as (tag, RD, DST-IP, SRC-IP, SRC-UDP, DST-UDP), where SRC-IP, SRC-UDP, and DST-UDP are optional fields. In some implementations, one or more of SRC-IP, DST-IP, SRC-UDP, or DST-UDP may have specific values (e.g., a specific IP address or a specific UDP port). Alternatively or alternatively, one or more of SRC-IP, DST-IP, SRC-UDP, or DST-UDP may have a "wildcard" value (e.g., an asterisk or other wildcard value) that represents any value (e.g., any IP address or any UDP port).
[0043] As shown by reference number 104, PE network device PE1 can update a first data structure (e.g., a database, a table, a file, and / or another data structure) included in and / or accessible by PE network device PE1. For example, PE network device PE1 can update the first data structure based on or in association with sending the advertisement message (or based on receiving the advertisement message from the controller). The first data structure can be used for a VPN (e.g., that is maintained by PE network device PE1), and / or can be a routing and forwarding table of PE network device PE1, such as a virtual routing and forwarding table or a global routing and forwarding table of PE network device PE1.
[0044] PE network device PE1 can update the first data structure to cause the first data structure to include an entry such that the entry includes the label, the RD, and / or the reconstruction information. The reconstruction information can include traffic information. Additionally or alternatively, the reconstruction information can include IP header information, and can also include UDP header information. The IP header information can include a destination IP address (e.g., DST-IP) that is included in the traffic information, and can also include a source IP address (e.g., SRC-IP), such as when the traffic information includes the source IP address. The UDP header information can include a destination UDP address (e.g., DST-UDP), such as when the traffic information includes the destination UDP address, and can also include a source UDP address (e.g., SRC-UDP), such as when the traffic information includes the source UDP address. The entry can be formatted as a tuple of fields, such as (label, RD, DST-IP, SRC-IP, SRC-UDP, DST-UDP), where SRC-IP, SRC-UDP, and DST-UDP are optional fields. In this way, the entry indicates that the label is associated with the RD and the reconstruction information.
[0045] As shown by reference number 106, PE network device PE2 can receive the advertisement message from PE network device PE1 (or from the controller, not shown), and can therefore update a second data structure (e.g., a database, a table, a file, and / or another data structure) included in and / or accessible by PE network device PE2. The second data structure can be used for a VPN (e.g., that is maintained by PE network device PE2), and / or can be a routing and forwarding table of PE network device PE2, such as a virtual routing and forwarding table or a global routing and forwarding table of PE network device PE2.
[0046] The PE network device PE2 can update the second data structure to include entries, such that these entries include tags, RDs, and / or service information (e.g., included in an announcement message). As described above, the service information may include a destination IP address (e.g., DST-IP), and may also include a source IP address (e.g., SRC-IP), a source UDP address (e.g., SRC-UDP), and / or a destination UDP address (e.g., DST-IP). Therefore, the entry can be formatted as a tuple of fields such as tag, RD, DST-IP, SRC-IP, SRC-UDP, and DST-UDP, where SRC-IP, SRC-UDP, and DST-UDP are optional fields. In this way, the PE network device PE2 can be configured to handle VPN services that match some or all of the information included in the entry, as described herein.
[0047] like Figure 1B As shown, and via reference numeral 108, source CE network device CE1 can send VPN services (e.g., IP-VPN services, also referred to herein as services) to destination CE network device CE2. For example, source CE network device CE1 can send VPN services (e.g., IP-VPN services, also referred to herein as services) via a VPN connection between source CE network device CE1 and destination CE network device CE2. Figure 1A (As shown) VPN services are sent. Therefore, the PE network device PE2 can receive VPN services (e.g., as an entry point for a VPN connection). VPN services may include IP header information, or IP header information and UDP header information, and a payload. The IP header information (also referred to herein as the IP header) may include the destination IP address and the source IP address. The UDP header information (also referred to herein as the UDP header) may include the destination UDP address and the source UDP address.
[0048] As shown by reference numeral 110 in the attached figure, PE network device PE2 can handle VPN services. For example, PE network device PE2 can parse and / or read VPN services to identify the IP header information and UDP header information included in the VPN service.
[0049] As shown by reference number 112, PE network device PE2 can identify an entry in the second data structure (e.g., based on IP header information and UDP header information included in the VPN traffic). For example, PE network device PE2 can search the second data structure for an entry that includes information matching the IP header information and the UDP header information. As a specific example, PE network device PE2 can identify an entry in the second data structure when IP header information (which includes a destination IP address and a source IP address) and / or UDP header information (which includes a destination UDP address and a source UDP address) included in the VPN traffic matches one or more corresponding fields of a field tuple (label, RD, DST-IP, SRC-IP, SRC-UDP, DST-UDP) of an entry. As described herein, the second data structure can be stored at PE network device PE2 and / or can be received by PE network device PE2 from another PE network device (e.g., PE network device PE1). Figure 1A
[0050] As shown by reference number 114, PE network device PE2 can update the VPN traffic (e.g., based on the entry in the second data structure). For example, PE network device PE2 can update the VPN traffic based on successfully identifying the entry in the second data structure, as described further herein. Alternatively, when PE network device PE2 does not successfully identify an entry in the second data structure (e.g., when no entry of the second data structure includes information matching the IP header information and the UDP header information of the VPN traffic), PE network device PE2 can refrain from updating the VPN traffic and can forward the un-updated (as described herein) VPN traffic to another PE network device of the plurality of PE network devices. In this way, PE network device PE2 can determine whether to remove the IP header information or the IP header information and the UDP header information from the traffic (e.g., as described herein).
[0051] In some implementations, PE network device PE2 can update the VPN traffic by removing IP header information from the VPN traffic. Additionally, in some implementations, PE network device PE2 can also update the VPN traffic by removing UDP header information. For example, PE network device PE2 can identify the traffic information included in the entry of the second data structure (e.g., by parsing and / or reading the entry). Accordingly, PE network device PE2 can determine whether the traffic information includes a source UDP address (e.g., SRC-UDP) and / or a destination UDP address (e.g., DST-UDP). PE network device PE2 can determine that the traffic information includes at least one of the source UDP address or the destination UDP address (e.g., includes at least one of SRC-UDP or DST-UDP), and from this can remove the IP header information and the UDP header information from the VPN traffic (e.g., because the traffic information includes at least some UDP information). Alternatively, PE network device PE2 can determine that the traffic information does not include the source UDP address and the destination UDP address (e.g., does not include SRC-UDP and DST-UDP), and from this can remove the IP header information (but not the UDP header information) from the VPN traffic (e.g., because the traffic information does not include UDP information).
[0052] In some implementations, PE network device PE2 can update the VPN traffic by including a label in the VPN traffic that is included in the entry of the second data structure (e.g., to indicate that the IP header information, and in some implementations, the UDP header information, has been removed from the VPN traffic). For example, PE network device PE2 can update the VPN traffic to include a MPLS label stack that includes a label as an inner label of the MPS label stack. In this manner, the label is used to regenerate a new IP header or a new IP header and a new UDP header by a PE network device that receives the VPN traffic.
[0053] Additionally, in some implementations, PE network device PE2 can update the VPN traffic by including a control word in the VPN traffic. The control word can be included to prevent intermediate PE network devices (e.g., that receive and forward the VPN traffic between PE network device PE2 and PE network device PE1) from misinterpreting the VPN traffic as IP traffic or other non-updated VPN traffic. For example, the control word can set a first nibble to 0 to indicate that the VPN traffic is updated VPN traffic.
[0054] As shown by reference numeral 116 in the attached figure, PE network device PE2 can forward (e.g., send) VPN traffic (e.g., after updating VPN traffic). In some implementations, the PE network device can forward VPN traffic to another PE network device associated with an entry in the second data structure. For example, PE network device PE2 can determine that PE network device PE1 is associated with the entry based on the entry's tag, DT, and / or service information, and therefore can forward VPN traffic to PE network device PE1. In some implementations, PE network device PE2 can forward VPN traffic to another PE network device (e.g., PE network device PE3) to allow forwarding of VPN traffic to PE network device PE1.
[0055] Therefore, PE network device PE1 can receive VPN services directly or indirectly from PE network device PE2 (e.g., as an exit point for the VPN connection). Because the VPN services have been updated by PE network device PE2, the VPN services can include labels (e.g., internal labels as part of the MPLS label stack of the VPN services) (and, in some implementations, control words), and may not include IP header information (and, in some implementations, may not include UDP header information).
[0056] like Figure 1C As shown, and via reference numeral 118, PE network device PE1 can process VPN services. For example, PE network device PE1 can parse and / or read VPN services to identify tags within the VPN service (e.g., in the MPLS tag stack of the VPN service). In some implementations, PE network device PE1 can parse and / or read VPN services to identify tags and control words within the VPN service.
[0057] As indicated by reference numeral 120 in the attached figure, the PE network device PE1 can identify entries in a first data structure (e.g., based on tags in a VPN service). For example, the PE network device PE1 can search the first data structure to find entries that include tags matching tags in a VPN service. As a specific example, the PE network device PE1 can identify entries in the first data structure that include those referenced herein. Figure 1A The labels, DT, and reconstruction information described in Figure 104.
[0058] As shown by reference number 122, the PE network device PE 1 can update the VPN traffic (e.g., based on the entry in the first data structure). For example, as described further herein, the PE network device PE 1 can update the VPN traffic based on successfully identifying the entry in the first data structure. Alternatively, when the PE network device PE 1 does not successfully identify the entry in the first data structure (e.g., when no entry of the first data structure includes information matching the label and / or RD of the VPN traffic), the PE network device PE 1 can refrain from updating the VPN traffic. For example, the PE network device PE 1 can forward the un-updated VPN traffic to another network device, such as the destination CE network device CE 2, or alternatively, can discard the VPN traffic.
[0059] In some implementations, the PE network device PE 1 can update the VPN traffic by removing a label from the VPN traffic (e.g., by removing a label from a MPLS label stack of the VPN traffic). Additionally, in some implementations, the PE network device PE 1 can update the VPN traffic by also removing a control word from the VPN traffic (e.g., when the control word is included in the VPN traffic).
[0060] In some implementations, the PE network device PE 1 can update the VPN traffic by including in the VPN traffic the reconstitution information included in the entry of the first data structure (e.g., which is identified by the PE network device PE 1). As described above with reference to Figure 1A As described above with reference to Figure 1AAs further described by reference number 104, the reconstruction information can include UDP header information. Accordingly, PE network device PE1 can update the VPN traffic by including the IP header information and the UDP header information. The UDP header information can include a destination UDP address (e.g., DST-UDP), and can also include a source UDP address (e.g., SRC-UDP). Accordingly, PE network device PE1 can update the VPN traffic to further include the destination UDP address (e.g., DST-UDP), and in some implementations, the source UDP address (e.g., SRC-UDP). In this way, PE network device PE1 can regenerate a new IP header, or a new IP header and a new UDP header, and include them in the VPN traffic.
[0061] In a particular example, when the reconstruction information includes UDP header information that includes a source UDP address (and thus also includes a destination UDP address), PE network device PE1 can update the VPN traffic by including the IP header information and the UDP header information. As another example, when the reconstruction information includes UDP header information that includes a destination UDP address but does not include a source UDP address (or the source UDP address has a wildcard value), PE network device PE1 can update the VPN traffic by including the IP header information and the UDP header information (e.g., that includes the destination UDP address) and a particular source UDP address (e.g., that is not indicated by the UDP header information). The particular source UDP address can be a preconfigured value (e.g., that is based on configuration information of PE network device PE1). As another example, when the reconstruction information includes IP header information that includes a destination IP address but does not include a source IP address (or the source IP address has a wildcard value), PE network device PE1 can update the VPN traffic by including the IP header information (e.g., that includes the destination IP address) and a particular source IP address (e.g., that is not indicated by the IP header information). The particular source IP address can be a preconfigured value (e.g., that is based on configuration information of PE network device PE1).
[0062] As shown by reference number 124, the PE network device PE1 can forward the VPN traffic (e.g., after updating the VPN traffic). In some implementations, the PE network device PE1 can forward the VPN traffic to another network device associated with the entry in the first data structure. For example, the PE network device PE1 can determine that the destination CE network device CE2 is associated with the entry based on the label, the DT, and / or the reconstitution information of the entry, and thus can forward the VPN traffic to the destination CE network device CE2. Additionally or alternatively, the PE network device PE1 can forward the VPN traffic based on IP header information and / or UDP header information included in the VPN traffic. For example, the PE network device PE1 can forward the VPN traffic to the destination CE network device CE2 based on a destination IP address of the IP header information and / or a destination UDP address of the UDP header information of the VPN traffic. Thus, the destination CE network device CE2 can receive the VPN traffic from the PE network device PE1.
[0063] As described above, Figures 1A-1C are provided by way of one or more examples only. Other examples can be different from those described Figures 1A-1C .
[0064] Figure 2 is a diagram 200 of an example advertisement message. As shown in Figure 2 , the advertisement message can be a network layer reachability information (NLRI) message, which can include a "length" field (e.g., that indicates a length of the advertisement message), a "label" field (e.g., that indicates a label of the advertisement message), an "RD" field (e.g., that indicates a route distinguisher associated with the advertisement message), a "DST address" field (e.g., that indicates a destination IP address, such as an IP address of the destination CE network device CE2), a "SRC prefix" field (e.g., that indicates a source IP address, such as an IP address or a prefix of IP addresses of the source CE network device CE1), a "DST UDP" field (e.g., that indicates a destination UDP address, such as a UDP port of the destination CE network device CE2), and / or a "SRC UDP" field (e.g., that indicates a source UDP address, such as a UDP port of the source CE network device CE1). When the SRC prefix is a host prefix (e.g., of a CE network device), the DST UDP field can be present, and thus the length field can indicate at least 176 bits (22 octets for an IPv4 address) or 368 bits (46 octets for an IPv6 address). When the DST UDP field is also present, the SRC UDP field can be present, and thus the length field can indicate at least 192 bits (24 octets for an IPv4 address) or 384 bits (48 octets for an IPv6 address).
[0065] As described above, Figure 2 are provided by way of example only. Other examples can differ from those described Figure 2 without departing from the scope of the description.
[0066] Figure 3 is a schematic diagram of an example environment 300 in which systems and / or methods described herein can be implemented. As shown, environment 300 can include a CE network device 310, a plurality of PE network devices 320 (shown as PE devices 320-1 through 320-N), and a network 330. The devices of environment 300 can be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections. Figure 3
[0067] CE network device 310 includes one or more devices capable of generating, sending, receiving, processing, storing, routing, and / or providing traffic (e.g., VPN traffic) in the manner described herein. For example, CE network device 310 can include a firewall, a gateway, a switch, a hub, a bridge, a reverse proxy, a server (e.g., a proxy server), a security appliance, an intrusion detection appliance, a load balancer, or a similar type of device. Additionally or alternatively, CE network device 310 can include a router, such as a label switched router (LSR), a label edge router (LER), an ingress router, an egress router, a provider router (e.g., a provider edge router or a provider core router), a virtual router, or another type of router. In some implementations, CE network device 310 can include a mobile phone (e.g., a smartphone or a wireless phone), a laptop computer, a tablet computer, a desktop computer, a handheld computer, or a similar type of device. CE network device 310 can be connected to PE network devices 320 via links (e.g., uplinks) of PE network devices 320. In some implementations, CE network device 310 can send traffic (e.g., VPN traffic) to PE network devices 320 and receive traffic from PE network devices 320, as described elsewhere herein. CE network device 310 can be a physical device implemented within a housing (e.g., a chassis). In some implementations, CE network device 310 can be a virtual device implemented by one or more computer devices of a cloud computing environment or a data center.
[0068] The PE network devices 320 include one or more devices capable of receiving, processing, storing, routing and / or providing traffic (e.g., VPN traffic) in the manner described herein. For example, the PE network devices 320 can include a firewall, a gateway, a switch, a hub, a bridge, a proxy server, a server (e.g., a proxy server), a security device, an intrusion detection device, a load balancer, or similar type of devices. Additionally or alternatively, the PE network devices 320 can include a router, such as an LSR, an LER, an ingress router, an egress router, a provider router (e.g., a provider edge router or a provider core router), a virtual router, or another type of router. In some implementations, the PE network devices 320 can include links connecting the PE network devices 320 to the CE network devices 310. In some implementations, the PE network devices 320 can transmit traffic between the CE network devices 310 and the network 330, as described elsewhere herein. The PE network devices 320 can be physical devices implemented within a housing (e.g., a chassis). In some implementations, the PE network devices 320 can be virtual devices implemented by one or more computer devices of a cloud computing environment or a data center.
[0069] The network 330 includes one or more wired and / or wireless networks. For example, the network 330 can include a packet-switched network, a cellular network (e.g., a fifth generation (5G) network, a fourth generation (4G) network such as a Long Term Evolution (LTE) network, a third generation (3G) network, a code division multiple access (CDMA) network), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., the Public Switched Telephone Network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber optic-based network, a cloud computing network, and / or the like, and / or a combination of these or other types of networks.
[0070] Figure 3 The number and arrangement of devices and networks shown is provided as one or more examples. In practice, there can be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or differently arranged devices and / or networks than those shown in Figure 3 Furthermore, two or more devices shown in Figure 3 may be implemented within a single device, or Figure 3 a single device shown in may be implemented as multiple, distributed devices. Additionally or alternatively, a set of devices (e.g., one or more devices) of environment 300 can perform one or more functions described as being performed by another set of devices of environment 300.
[0071] Figure 4This is a schematic diagram of example components of device 400, which may correspond to CE network device 310 and / or PE network device 320. In some implementations, CE network device 310 and / or PE network device 320 may include one or more devices 400 and / or one or more components of device 400. For example... Figure 4 As shown, device 400 may include bus 410, processor 420, memory 430, input component 440, output component 450 and communication component 460.
[0072] Bus 410 includes one or more components that enable wired and / or wireless communication between components of device 400. Bus 410 can connect components via, for example, operative coupling, communicative coupling, electronic coupling, and / or electrical coupling. Figure 4 Two or more components are coupled together. Processor 420 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and / or another type of processing component. Processor 420 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, processor 420 includes one or more processors capable of being programmed to perform one or more operations or processes described elsewhere herein.
[0073] Memory 430 includes volatile and / or non-volatile memory. For example, memory 430 may include random access memory (RAM), read-only memory (ROM), hard disk drive, and / or another type of memory (e.g., flash memory, magnetic storage, and / or optical storage). Memory 430 may include internal memory (e.g., RAM, ROM, or hard disk drive) and / or removable memory (e.g., removable via a universal serial bus connection). Memory 430 may be a non-transient computer-readable medium. Memory 430 stores information, instructions, and / or software (e.g., one or more software applications) related to the operation of device 400. In some implementations, memory 430 includes one or more memories coupled to one or more processors (e.g., processor 420), for example, via bus 410.
[0074] Input component 440 enables device 400 to receive input, such as user input and / or sensed input. For example, input component 440 may include a touchscreen, keyboard, keypad, mouse, button, microphone, switch, sensor, GPS sensor, accelerometer, gyroscope, and / or actuator. Output component 450 enables device 400 to provide output, for example, via a display, speaker, and / or light-emitting diode. Communication component 460 enables device 400 to communicate with other devices via wired and / or wireless connections. For example, communication component 460 may include a receiver, transmitter, transceiver, modem, network interface card, and / or antenna.
[0075] Device 400 can perform one or more operations or processes described herein. For example, a non-transitory computer-readable medium (e.g., memory 430) can store a set of instructions (e.g., one or more instructions or code) for execution by processor 420. Processor 420 may
[0076] Figure 4 The number and arrangement of components shown in FIG. 4 are provided as an example. Device 400 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 4. Additionally or alternatively, a set of components (e.g., one or more components) of device 400 can perform one or more functions described as being performed by another set of components of device 400. Figure 4 As shown, device 500 can include one or more input components 510-1 through 510-B (B > 1) (hereinafter collectively referred to as input components 510, and individually as input component 510), a switching component 520, one or more output components 530-1 through 530-C (C > 1) (hereinafter collectively referred to as output components 530, and individually as output component 530), and a controller 540.
[0077] Figure 5 FIG. 5 is a schematic diagram of example components of a device 500. Device 500 can correspond to CE network device 310 and / or PE network device 320. In some implementations, CE network device 310 and / or PE network device 320 can include one or more devices 500 and / or one or more components of device 500. As shown, device 500 can include one or more input components 510-1 through 510-B (B > 1) (hereinafter collectively referred to as input components 510, and individually as input component 510), a switching component 520, one or more output components 530-1 through 530-C (C > 1) (hereinafter collectively referred to as output components 530, and individually as output component 530), and a controller 540. Figure 5
[0078] Input components 510 can be one or more attachment points for physical links and can be one or more ingress points for incoming traffic, e.g., packets. Input components 510 can process incoming traffic, e.g., by performing data link layer encapsulation or decapsulation. In some implementations, input components 510 can transmit and / or receive packets. In some implementations, input components 510 can include input line cards that include one or more packet processing components (e.g., in the form of integrated circuits), e.g., one or more interface cards (IFCs), packet forwarding components, line card controller components, input ports, processors, memories, and / or input queues. In some implementations, device 500 can include one or more input components 510.
[0079] Switching components 520 can interconnect input components 510 with output components 530. In some implementations, switching components 520 can be implemented via one or more crossbars, via buses, and / or with shared memory. Shared memory can be used as a temporary buffer to store packets from input components 510 before the packets are finally scheduled for delivery to output components 530. In some implementations, switching components 520 can enable input components 510, output components 530, and / or controller 540 to communicate with one another.
[0080] Output components 530 can store packets and can schedule packets for transmission on output physical links. Output components 530 can support data link layer encapsulation or decapsulation and / or various higher layer protocols. In some implementations, output components 530 can transmit packets and / or receive packets. In some implementations, output components 530 can include output line cards that include one or more packet processing components (e.g., in the form of integrated circuits), e.g., one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memories, and / or output queues. In some implementations, device 500 can include one or more output components 530. In some implementations, input components 510 and output components 530 can be implemented by the same set of components (e.g., and the input / output components can be a combination of input components 510 and output components 530).
[0081] Controller 540 includes a processor, e.g., in the form of a CPU, GPU, APU, microprocessor, microcontroller, DSP, FPGA, ASIC, and / or other type of processor. The processor is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, controller 540 can include one or more processors that can be programmed to perform functions.
[0082] In some implementations, the controller 540 can include RAM, ROM, and / or another type of dynamic or static storage device (e.g., flash memory, magnetic storage, optical storage, etc.). It stores information and / or instructions for use by the controller 540.
[0083] In some implementations, the controller 540 can communicate with other devices, networks, and / or systems connected to the device 500 to exchange information about a network topology. The controller 540 can create a routing table based on the network topology information, can create a forwarding table based on the routing table, and can forward the forwarding table to the input component 510 and / or the output component 530. The input component 510 and / or the output component 530 can use the forwarding table to perform route lookups for incoming and / or outgoing packets.
[0084] The controller 540 can perform one or more processes described herein. The controller 540 can perform these processes in response to execution of software instructions stored by a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes a single physical storage location, or multiple physical storage locations, within a single physical device or spread across multiple physical devices.
[0085] The software instructions can be read into the memory and / or storage components associated with the controller 540 from another computer-readable medium or from another device via a communication interface. When executed, the software instructions stored in the memory and / or storage components associated with the controller 540 can cause the controller 540 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry can be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, implementations described herein are not limited to any specific combination of hardware circuitry and software.
[0086] Figure 5 The number and arrangement of components shown in FIG. 5 are provided as an example. In practice, device 500 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 5. Additionally or alternatively, a set of components (e.g., one or more components) of device 500 can perform one or more functions described as being performed by another set of components of device 500. Figure 5 As an example, a set of components (e.g., one or more components) of device 500 can perform one or more functions of another set of components of device 500.
[0087] Figure 6 is a flow diagram of an example process 600 related to transmission of VPN traffic with reduced header information. In some implementations, one or more process blocks of Figure 6 are performed by a network device (e.g., PE network device 320). In some implementations, Figure 6One or more of the process blocks are performed by another device or set of devices separate from or including the network device, such as another network device (e.g., CE network device 310 or another PE network device 320). Additionally or alternatively, Figure 6 One or more of the process blocks can be performed by one or more components of device 400, such as processor 420, memory 430, input component 440, output component 450, and / or communication component 460; one or more components of device 500, such as input component 510, switch component 520, output component 530, and / or controller 540; and / or one or more other components.
[0088] As shown in FIG. 6, process 600 can include receiving VPN traffic (block 610). For example, the network device can receive VPN traffic from another network device, as described above. Figure 6
[0089] As further shown in FIG. 6, process 600 can include identifying a label included in the VPN traffic (block 620). For example, the network device can identify a label included in the VPN traffic, as described above. Figure 6
[0090] As further shown in FIG. 6, process 600 can include identifying an entry in a data structure (block 630). For example, the network device can identify an entry in a data structure based on the label, as described above. Figure 6
[0091] As further shown in FIG. 6, process 600 can include updating the VPN traffic (block 640). For example, the network device can update the VPN traffic based on the entry in the data structure, as described above. The network device can update the VPN traffic by removing at least the label from the VPN traffic and including at least IP header information indicated by the entry in the VPN traffic. Figure 6
[0092] As further shown in FIG. 6, process 600 can include forwarding the VPN traffic (block 650). For example, the network device can forward the VPN traffic after updating the VPN traffic and forwarding the VPN traffic to another device, as described above. Figure 6 Process 600 can include additional implementations, such as any single implementation described below or any combination of the implementations described below and / or in connection with one or more other processes described elsewhere herein.
[0093] In a first implementation, the data structure is a virtual routing and forwarding table of the network device, or a global routing and forwarding table of the network device.
[0094]
[0095] In a second implementation, alone or in combination with the first implementation, the process 600 includes sending an advertisement message to another network device prior to receiving the VPN traffic and including a label, a route distinguisher, and traffic information indicating at least a destination IP address in the advertisement message, and updating a data structure to include an entry including the label, the route distinguisher, and reconstruction information including at least IP header information including the destination IP address.
[0096] In a third implementation, alone or in combination with one or more of the first and second implementations, the traffic information includes at least a destination IP address and a source IP address, a source UDP address, or a destination UDP address.
[0097] In a fourth implementation, alone or in combination with one or more of the first through third implementations, updating the VPN traffic includes removing the label and the control word from the VPN traffic.
[0098] In a fifth implementation, alone or in combination with one or more of the first through fourth implementations, updating the VPN traffic includes including in the VPN traffic the IP header information indicated by the entry and the UDP header information indicated by the entry.
[0099] In a sixth implementation, alone or in combination with one or more of the first through fifth implementations, updating the VPN traffic includes including in the VPN traffic at least one of a particular source IP address and a particular source UDP address, where each of the particular source IP address and the particular source UDP address is not indicated by the entry.
[0100] Although Figure 6 Example blocks of the process 600 are shown, but in some implementations, the process 600 includes additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Figure 7 Additionally or alternatively, two or more of the blocks of the process 600 can be performed in parallel.
[0101] Figure 7 is a flow diagram of an example process 700 related to transmission of VPN traffic with reduced header information. In some implementations, one or more of the process blocks of Figure 7 are performed by a network device (e.g., the PE network device 320). In some implementations, one or more of the process blocks of Figure 7 are performed by another device or set of devices separate from or including the network device, such as another network device (e.g., the CE network device 310 or another PE network device 320). Additionally or alternatively, one or more of the process blocks of Figure 7One or more process blocks can be performed by one or more components of the device 400, such as the processor 420, the memory 430, the input component 440, the output component 450, and / or the communication component 460; one or more components of the device 500, such as the input component 510, the switch component 520, the output component 530, and / or the controller 540; and / or one or more other components.
[0102] As further shown, the process 700 can include receiving VPN traffic (block 710). For example, the network device can receive virtual private network (VPN) traffic from another network device, as described above. Figure 7
[0103] As further shown, the process 700 can include identifying IP header information and UDP header information included in the VPN traffic (block 720). For example, the network device can identify IP header information and UDP header information included in the VPN traffic, as described above. Figure 7
[0104] As further shown, the process 700 can include identifying an entry in a data structure (block 730). For example, the network device can identify an entry in a data structure based on the IP header information and the UDP header information, as described above. Figure 7
[0105] As further shown, the process 700 can include updating the VPN traffic (block 740). For example, the network device can update the VPN traffic based on the entry in the data structure, as described above. The network device can update the VPN traffic by removing at least the IP header information from the VPN traffic and including at least a label indicated by the entry in the VPN traffic. Figure 7
[0106] As further shown, the process 700 can include forwarding the VPN traffic (block 750). For example, the network device can forward the VPN traffic to another network associated with the entry after updating the VPN traffic, as described above. Figure 7 The process 700 can include additional implementations, such as any single implementation described in the following or any combination of the implementations described in conjunction with one or more other processes described elsewhere in this document.
[0107] In a first implementation, the data structure is a virtual routing and forwarding table of the network device, or a global routing and forwarding table of the network device.
[0108]
[0109] In a second implementation, alone or in combination with the first implementation, the process 700 includes receiving an advertisement message from another network device prior to receiving the VPN traffic, where the advertisement message includes the label, the route identifier, and traffic information indicating at least a destination IP address, and updating the data structure to include an entry based on the advertisement message, where the entry includes the label, the route identifier, and the traffic information.
[0110] In a third implementation, alone or in combination with one or more of the first and second implementations, the traffic information includes at least one of a destination IP address and a source IP address, a source UDP address, or a destination UDP address.
[0111] In a fourth implementation, alone or in combination with one or more of the first through third implementations, updating the VPN traffic includes including the label and a control word indicated by the entry in the VPN traffic.
[0112] In a fifth implementation, alone or in combination with one or more of the first through fourth implementations, updating the VPN traffic includes removing IP header information and UDP header information from the VPN traffic.
[0113] In a sixth implementation, alone or in combination with one or more of the first through fifth implementations, updating the VPN traffic includes identifying the traffic information included in the entry, determining that the traffic information includes at least one of a source UDP address or a destination UDP address, and removing the IP header information and the UDP header information from the VPN traffic and based on the determination that the traffic information includes at least one of the source UDP address or the destination UDP address.
[0114] In a seventh implementation, alone or in combination with one or more of the first through sixth implementations, updating the VPN traffic includes identifying the traffic information included in the entry, determining that the traffic information does not include a source UDP address and a destination UDP address, and removing the IP header information from the VPN traffic and based on the determination that the traffic information does not include the source UDP address and the destination UDP address.
[0115] Although Figure 8 Example blocks of the process 700 are shown, but in some implementations, the process 700 includes additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Figure 8 Additionally or alternatively, two or more of the blocks of the process 700 can be performed in parallel.
[0116] Figure 8 is a flow diagram of an example process 800 related to transmission of VPN traffic with reduced header information. In some implementations, the process 800 includes receiving an advertisement message from another network device prior to receiving the VPN traffic, where the advertisement message includes a label, a route identifier, and traffic information indicating at least a destination IP address, and updating a data structure to include an entry based on the advertisement message, where the entry includes the label, the route identifier, and the traffic information. Figure 8One or more of the process blocks are performed by a first PE network device (e.g., PE network device 320) associated with the VPN. In some implementations, Figure 8 One or more of the process blocks are performed by another device or set of devices separate from or including the network device, such as another network device (e.g., CE network device 310 or another PE network device 320). Additionally or alternatively, Figure 8 One or more of the process blocks can be performed by one or more components of device 400, such as processor 420, memory 430, input component 440, output component 450, and / or communication component 460; one or more components of device 500, such as input component 510, switch component 520, output component 530, and / or controller 540; and / or one or more other components.
[0117] As shown in Figure 8 Process 800 can include receiving traffic including at least an IP header (block 810). For example, the first PE network device can receive traffic including at least an IP header from the first CE network device, as described above.
[0118] As further shown in Figure 8 Process 800 can include determining whether the first PE network device is to remove the IP header included in the traffic, or the IP header and a UDP header, from the traffic (block 820). For example, the first PE network device can determine whether the first PE network device is to remove the IP header included in the traffic, or the IP header and a UDP header, from the traffic, as described above.
[0119] As further shown in Figure 8 Process 800 can include sending the traffic (block 830). For example, the first PE network device can send the traffic to one or more second PE network devices, as described above. In some implementations, when the first PE network device makes the removal determination, the first PE network device updates the traffic by removing the IP header, or the IP header and the UDP header, prior to sending the traffic. In some implementations, when the first PE network device does not make the removal determination, the first PE network device does not update the traffic prior to sending the traffic.
[0120] Process 800 can include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other processes described elsewhere herein.
[0121] In a first implementation, after the first PE network device updates the traffic, the traffic includes a MPLS label stack, wherein an inner label of the MPLS label stack is used to regenerate a new IP header or a new IP header and a new UDP header by a PE network device that receives the traffic.
[0122] In a second implementation, alone or in combination with the first implementation, the first PE network device determines the inner label to include in the MPLS label stack based on an advertisement received from at least one of the one or more second PE network devices or the controller.
[0123] In a third implementation, alone or in combination with one or more of the first and second implementations, the advertisement includes the inner label and traffic information, where the traffic information includes at least one of a destination IP address, a source IP address, a destination UDP port, or a source UDP port.
[0124] In a fourth implementation, alone or in combination with one or more of the first through third implementations, the process 800 includes updating a data structure of the VPN to include an entry including the inner label and the traffic information.
[0125] In a fifth implementation, alone or in combination with one or more of the first through fourth implementations, determining whether the first PE network device is to remove the IP header, or the IP header and the UDP header, included in the traffic from the traffic includes: determining, based on the IP header, or the IP header and the UDP header, whether a data structure of the VPN includes an entry; and determining, based on a determination that the data structure includes the entry, that the first PE network device is to remove the IP header, or the IP header and the UDP header, included in the traffic, based on a determination that the data structure does not include the entry, not removing the IP header, or the IP header and the UDP header.
[0126] Although Figure 9 Example blocks of the process 800 are shown, but in some implementations, the process 800 includes additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in Figure 9 Additionally or alternatively, two or more of the blocks of the process 800 can be performed in parallel.
[0127] Figure 9 is a flow diagram of an example process 900 related to transmission of VPN traffic with reduced header information. In some implementations, Figure 9 One or more of the process blocks of the process 900 are performed by a first PE network device (e.g., the PE network device 320) associated with the VPN. In some implementations, Figure 9 One or more of the process blocks of the process 900 are performed by another device or set of devices separate from the network device or including the network device, such as another network device (e.g., the CE network device 310 or another PE network device 320). Additionally or alternatively, Figure 9One or more process blocks can be performed by one or more components of the device 400, such as the processor 420, the memory 430, the input component 440, the output component 450, and / or the communication component 460; one or more components of the device 500, such as the input component 510, the switch component 520, the output component 530, and / or the controller 540; and / or one or more other components.
[0128] As shown, the process 900 can include receiving traffic including an MPLS label stack (block 910). For example, the first PE network device can receive, from the second PE network device, traffic including an MPLS label stack, as described above. Figure 9
[0129] As further shown, the process 900 can include regenerating an IP header, or an IP header and a UDP header (block 920). For example, the first PE network device can regenerate an IP header, or an IP header and a UDP header, based on the inner label of the MPLS label stack, as described above. Figure 9
[0130] As further shown, the process 900 can include sending the traffic with the IP header, or the IP header and the UDP header, included in the traffic (block 930). For example, the first PE network device can send, to the CE network device, the traffic with the IP header, or the IP header and the UDP header, included in the traffic, as described above. Figure 9 The process 900 can include additional implementations, such as any single implementation described below or any combination of the one or more other processes described in connection with the other places described herein.
[0131] In a first implementation, the process 900 includes sending, to the second PE network device and prior to receiving the traffic, an advertisement, where the advertisement includes the inner label and the traffic information.
[0132] In a second implementation, alone or in combination with the first implementation, the traffic information includes at least one of a destination IP address, a source IP address, a destination UDP port, or a source UDP port.
[0133] In a third implementation, alone or in combination with one or more of the first and second implementations, the process 900 includes updating a data structure of the VPN to include an entry including the inner label and the traffic information.
[0134] In a fourth implementation, alone or in combination with one or more of the first through third implementations, the process 900 includes receiving, from a controller and prior to receiving the traffic, an advertisement, where the advertisement includes the inner label and the traffic information.
[0135] In a fourth implementation, alone or in combination with one or more of the first through third implementations, the process 900 includes receiving, from a controller and prior to receiving the traffic, an advertisement, where the advertisement includes the inner label and the traffic information.
[0136] In a fifth implementation, alone or in combination with one or more of the first through fourth implementations, the process 900 includes updating a data structure of the VPN to include an entry that includes the inner label and the traffic information.
[0137] In a sixth implementation, alone or in combination with one or more of the first through fifth implementations, regenerating the IP header, or the IP header and the UDP header, includes: identifying an entry in a data structure of the VPN based on the inner label of the MPLS label stack; and regenerating the IP header, or the IP header and the UDP header, based on the entry.
[0138] Although Example blocks of the process 900 are shown, but in some implementations, the process 900 includes additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in In addition or as an alternative, two or more of the blocks of the process 900 can be performed in parallel.
[0139] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit implementations to the precise form disclosed. Modifications and variations can be possible in light of the above disclosure or can be acquired from practice of the implementations. Additionally, other implementations can be possible.
[0140] As used herein, traffic or content can include a set of packets. A packet can refer to a communication structure used to convey information, such as a protocol data unit (PDU), a service data unit (SDU), a network packet, a datagram, a segment, a message, a block, a frame (e.g., an Ethernet frame), a portion of any of the above, and / or another type of formatted or unformatted data unit capable of being transported via a network.
[0141] As used herein, the term "component" is intended to be broadly construed as hardware, firmware, or a combination of hardware and software. It will be apparent that systems and / or methods described herein can be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the implementations. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code — it being understood that software and hardware can be used to implement the systems and / or methods, as would be understood by those skilled in the art.
[0142] Even if a combination is not specifically recited in the claims or in the specification, the disclosure of various implementations includes that combination. Even if a dependent claim is not directly dependent on another claim, the disclosure of various implementations includes each and every combination of the dependent claim and each and every other claim in the claim set. As used herein, the phrase “at least one of” a list of items refers to any combination of those items, including single members. As an example, “at least one of a, b, or c” is intended to cover a, b, c, a-b, a-c, b-c, and a-b-c, as well as any combination with multiples of the same item (e.g., a-a, a-a-a, a-b-a, a-a-b, a-b-b, a-b-b-b, and so on). As used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, or a combination of related and unrelated items), and can be used interchangeably with “one or more.” As used herein, the term “has,” “have,” “having,” or variants thereof are intended to be open-ended terms. Further, the phrase “based on” is intended to be similarly open-ended, and is not intended to be limiting. As used herein, the term “or” is intended to be inclusive, unless explicitly indicated otherwise (e.g., in an “either / or” scenario). Further, unless otherwise indicated, use of the “of’ construction to a list of items should be interpreted as including at least one of the items in the list.
[0143] No element, act, or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items, and can be used interchangeably with “one or more.” Furthermore, as used herein, the article “the” is intended to include one or more items unless otherwise indicated. Also, as used herein, the term “set” is intended to include one or more items (e.g., related items, unrelated items, or a combination of related and unrelated items), and can be used interchangeably with “one or more.” If only one item is intended, the phrase “only one” or similar language is used. Also, as used herein, the terms “has,” “have,” “having,” or variants thereof are intended to be open-ended terms. Further, the phrase “based on” is intended to be similarly open-ended, and is not intended to be limiting. Also, as used herein, the term “or” is intended to be inclusive, unless explicitly indicated otherwise (e.g., in an “either / or” scenario). Further, unless otherwise indicated, use of the “of’ construction to a list of items should be interpreted as including at least one of the items in the list.
Claims
1. A method comprising: The service, including at least an Internet Protocol (IP) header, is received by a first provider edge PE network device associated with a Virtual Private Network (VPN) and from a first customer edge CE network device. The first PE network device determines whether it wants to remove the IP header, or the IP header and UDP header, which are included in the service. as well as The service is sent from the first PE network device to one or more second PE network devices. When the first PE network device determines to remove a service, it updates the service by removing the IP header, or the IP header and the UDP header, before sending the service. Once the removal determination is made, the tag associated with the IP header or the UDP header is included in the service, and If the first PE network device does not make a removal determination, the first PE network device will not update the service before sending the service.
2. The method according to claim 1, wherein after the first PE network device updates the service, the service includes a Multiprotocol Label Switching (MPLS) label stack. The internal labels of the MPLS label stack are used by the PE network device receiving the service to regenerate a new IP header, or a new IP header and a new UDP header.
3. The method of claim 2, wherein the first PE network device determines the internal label included in the MPLS label stack based on a notification received from at least one of the one or more second PE network devices or controllers.
4. The method according to claim 3, wherein the notification includes the internal tag and business information. The business information mentioned therein includes at least one of the following: destination IP address, source IP address, destination UDP port, or source UDP port.
5. The method according to claim 4, further comprising: Update the data structure for the VPN to include entries, which include the internal tags and the business information.
6. The method of claim 1, wherein determining whether the first PE network device needs to remove the IP header, or the IP header and the UDP header included in the service, from the service comprises: Based on the IP header, or the IP header and the UDP header, determine whether the data structure for the VPN includes an entry; and The first PE network device must: Based on the determination that the data structure includes entries, the IP header, or the IP header and the UDP header included in the service, are removed. Based on the determination that the data structure does not include entries, the IP header, or the IP header and the UDP header included in the service, will not be removed.
7. A method comprising: The service, including a Multiprotocol Label Switching (MPLS) label stack, is received by a first provider edge PE network device associated with a Virtual Private Network (VPN) and from a second PE network device. The MPLS label stack mentioned therein includes internal labels, which are included based on the removal of the header from the service, and The header is removed before the service is received; The first PE network device regenerates the Internet Protocol (IP) header, or the IP header and User Datagram Protocol (UDP) header, based on the internal tags of the MPLS tag stack. The service is sent to the customer edge CE network device, wherein the IP header, or the IP header and the UDP header are included in the service.
8. The method according to claim 7, further comprising: Send a notification to the second PE network device before receiving the service. The notices mentioned therein include the internal tags and business information.
9. The method according to claim 8, wherein the service information includes at least one of the following: destination IP address, source IP address, destination UDP port, or source UDP port.
10. The method of claim 9, further comprising: Update the data structure for the VPN to include entries, which include the internal tags and the business information.
11. The method of claim 8, further comprising: The controller receives a notification before receiving the service. The notices mentioned therein include the internal tags and business information.
12. The method of claim 11, further comprising: Update the data structure for the VPN to include entries, which include the internal tags and the business information.
13. The method of claim 7, wherein regenerating the IP header, or the IP header and the UDP header, comprises: Based on the internal tags of the MPLS tag stack, entries in the data structure for the VPN are identified; as well as The IP header, or the IP header and the UDP header, are regenerated based on the entry.
14. A first provider edge PE network device associated with a Virtual Private Network (VPN), comprising: One or more memory units; as well as One or more processors, used to: Receive services, including at least an Internet Protocol (IP) header, from the first customer edge (CE) network device; Determine whether the first PE network device needs to remove the IP header, or the IP header and UDP header included in the service, from the service; as well as Send the service to one or more second PE network devices. When the first PE network device determines to remove a service, it updates the service by removing the IP header, or the IP header and UDP header, before sending the service. Once the removal determination is made, the tag associated with the IP header or the UDP header is included in the service, and When the first PE network device does not make a removal determination, the first PE network device does not update the service before sending the service.
15. The first PE network device according to claim 14, wherein after the first PE network device updates the service, the service includes a Multiprotocol Label Switching (MPLS) label stack. The internal labels of the MPLS label stack are used by the PE network device receiving the service to regenerate a new IP header, or a new IP header and a new UDP header.
16. The first PE network device of claim 15, wherein the first PE network device determines the internal tag included in the MPLS tag stack based on a notification received from at least one of the one or more second PE network devices or controllers.
17. The first PE network device according to claim 16, wherein the announcement includes the internal tag and service information.
18. The first PE network device according to claim 17, wherein the service information includes at least one of the following: destination IP address, source IP address, destination UDP port or source UDP port.
19. The first PE network device according to claim 17, wherein the one or more processors are further configured to: Update the data structure for the VPN to include entries, which include the internal tags and the business information.
20. The first PE network device of claim 14, wherein, in order to determine whether the first PE network device wants to remove the IP header, or the IP header and the UDP header included in the service, from the service, the one or more processors are configured to: Based on the IP header, or the IP header and the UDP header, determine whether the data structure for the VPN includes entries; and The first PE network device must: Based on the determination that the data structure includes entries, the IP header, or the IP header and the UDP header included in the service, are removed. Based on the determination that the data structure does not include entries, the IP header, or the IP header and the UDP header included in the service, will not be removed.