Route detection method, apparatus and storage medium

By filtering and verifying route advertising information in a virtual private network, the problem of service interruption caused by route conflicts is solved, and efficient and accurate route detection and fault prevention are achieved.

CN116614405BActive Publication Date: 2026-03-03CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310676234.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-07
Publication Date
2026-03-03
Estimated Expiration
2043-06-07

AI Technical Summary

Technical Problem

In IP bearer networks, routing information conflicts can occur between different autonomous systems within the same virtual private network, leading to service interruptions and other malfunctions. Furthermore, manual detection is inefficient and its accuracy cannot be guaranteed.

Method used

By acquiring routing advertisement information within the VPN, filtering target routing advertisement information using preset conditions, verifying its validity based on a preset set, generating detection results, and sending prompt messages to nodes that do not have validity for rectification.

Benefits of technology

It enables efficient and accurate detection of routing conflicts, timely discovery and avoidance of business failures, and improves detection efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116614405B_ABST
    Figure CN116614405B_ABST
Patent Text Reader

Abstract

The application provides a routing detection method and device and a storage medium, relates to the technical field of communication, and is used for efficiently and accurately detecting routing information and discovering routing conflict problems in time to avoid service failure. The method comprises the following steps: acquiring a plurality of routing publishing information in a first VPN; the routing publishing information comprises an IP address and an ASN; determining whether a plurality of target routing publishing information meeting preset conditions exist in the plurality of routing publishing information; the preset conditions comprise that the network segments to which the IP addresses belong are the same and the ASNs are different; when the plurality of target routing publishing information meeting the preset conditions exist, obtaining a detection result according to the plurality of target routing publishing information and a preset set; the preset set comprises a corresponding relationship among a plurality of network segments and a plurality of ASNs; and the detection result is used for representing whether each target routing publishing information is valid.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of communication technology, and in particular relates to a route detection method, apparatus and storage medium. Background Technology

[0002] In Internet Protocol (IP) bearer networks, network operators typically build different Virtual Private Networks (VPNs) for different services. A VPN can be divided into multiple Autonomous Systems (AS), and different ASs can be connected via Border Gateway Protocol (BGP) to achieve routing information dissemination and service data transmission.

[0003] If routing information published by different ASs within the same VPN conflicts, it can easily lead to service interruptions and other failures. Furthermore, operators typically build numerous VPNs, making manual detection of route conflicts inefficient and unreliable, hindering timely detection of routing conflicts to prevent service disruptions. Summary of the Invention

[0004] This application provides a route detection method, apparatus, and storage medium for efficiently and accurately detecting route information and promptly identifying route conflicts to avoid service failures.

[0005] To achieve the above objectives, this application adopts the following technical solution:

[0006] In a first aspect, a route detection method is provided, comprising: acquiring multiple route advertising information within a first Virtual Private Network (VPN); the route advertising information includes Internet Protocol (IP) addresses and Autonomous System Numbers (ASNs); determining whether multiple target route advertising information exists among the multiple route advertising information that meets preset conditions; the preset conditions include that the IP addresses belong to the same network segment and have different ASNs; when multiple target route advertising information that meets the preset conditions exists, obtaining a detection result based on the multiple target route advertising information and a preset set; the preset set includes the correspondence between multiple network segments and multiple ASNs; the detection result is used to indicate whether each target route advertising information is valid.

[0007] Optionally, the method for determining whether there are multiple target route advertisements that meet preset conditions among multiple route advertisements specifically includes: calling a first detection instruction to determine whether there are target route advertisements among multiple route advertisements that have the same IP address but different ASNs; and calling a second detection instruction to determine whether there are target route advertisements among multiple route advertisements that have the same IP address belonging to the same network segment, different mask lengths, and different ASNs.

[0008] Optionally, the method for obtaining the detection result based on multiple target route advertisements and a preset set specifically includes: determining the network segment to which the IP addresses included in the multiple target route advertisements belong as the target network segment; determining the ASNs in the preset set that correspond to the target network segment as the target ASNs; determining that target route advertisements with ASNs different from the target ASNs are not valid, and target route advertisements with ASNs the same as the target ASNs are valid, thereby obtaining the detection result.

[0009] Optionally, the route detection method further includes: sending a prompt message to the node corresponding to the target route publication information that does not have validity; the data type of the prompt message includes at least one of audio and text.

[0010] Secondly, a route detection device is provided, comprising: an acquisition unit, a determination unit, and a processing unit;

[0011] The acquisition unit is used to acquire multiple routing advertisement information within the first virtual private network (VPN); the routing advertisement information includes Internet Protocol (IP) addresses and Autonomous System Numbers (ASNs).

[0012] The determining unit is used to determine whether there are multiple target route advertisements that meet preset conditions among the multiple route advertisements obtained by the acquiring unit; the preset conditions include that the IP addresses belong to the same network segment and have different ASNs.

[0013] The processing unit is used to obtain a detection result based on the multiple target route advertisements and a preset set when the determining unit determines that there are multiple target route advertisements that meet the preset conditions; the preset set includes the correspondence between multiple network segments and multiple ASNs; the detection result is used to indicate whether each target route advertisement is valid.

[0014] Optionally, the unit is defined, specifically for:

[0015] Invoke the first detection command to determine whether there are target route advertisements with the same IP address but different ASNs among multiple route advertisements;

[0016] Invoke the second detection command to determine whether there are target route advertisements among multiple route advertisements that have the same IP address belonging to the same network segment, different mask lengths, and different ASNs.

[0017] Optionally, the processing unit is specifically used for:

[0018] The network segment to which the IP addresses included in the multiple target route advertisements belong is determined as the target network segment;

[0019] The ASNs in the preset set that correspond to the target network segment are identified as the target ASNs;

[0020] The detection results are obtained by determining that target route advertisements with different ASNs from the target ASN are invalid, and target route advertisements with the same ASN as the target ASN are valid.

[0021] Optionally, the route detection device further includes: a transmission unit;

[0022] The sending unit is used to send a prompt message to the node corresponding to the target route publication information that does not have validity; the data type of the prompt message includes at least one of audio and text.

[0023] Thirdly, a route detection device is provided, including a memory and a processor; the memory is used to store computer-executed instructions, and the processor is connected to the memory via a bus; when the route detection device is running, the processor executes the computer-executed instructions stored in the memory to cause the route detection device to perform the route detection method as described in the first aspect.

[0024] The route detection device can be a network device or a component of a network device, such as a chip system within the network device. This chip system supports the network device in implementing the functions involved in the first aspect and any of its possible implementations, such as receiving, determining, and routing the data and / or information involved in the aforementioned route detection method. The chip system includes a chip, but may also include other discrete devices or circuit structures.

[0025] Fourthly, a computer-readable storage medium is provided, including computer-executable instructions that, when executed on a computer, cause the computer to perform the routing detection method as described in the first aspect.

[0026] It should be noted that the aforementioned computer instructions may be stored, in whole or in part, on the first computer-readable storage medium. The first computer-readable storage medium may be packaged together with the processor of the routing detection device, or it may be packaged separately from the processor of the routing detection device; this application does not impose any limitations on this.

[0027] In this application, the name of the aforementioned route detection device does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear under other names. As long as the function of each device or functional module is similar to that of this application, it falls within the scope of the claims of this application and its equivalents.

[0028] These or other aspects of this application will become more readily apparent in the following description.

[0029] The technical solution provided in this application brings at least the following beneficial effects:

[0030] Based on any of the above aspects, in this application, after obtaining multiple route advertising information within the first VPN, it can be determined whether there are multiple target route advertising information that meet preset conditions among the multiple route advertising information. Furthermore, when there are multiple target route advertising information that meet the preset conditions, a detection result indicating whether each target route advertising information is valid can be obtained based on each target route advertising information and a preset set. Based on this, this application can achieve automatic detection of multiple route advertising information within the VPN.

[0031] Furthermore, considering that routing conflicts can easily arise when different ASs use the same network segment, and given that the preset conditions include IP addresses belonging to the same network segment but with different Autonomous System Numbers (ASNs), and the preset set includes the correspondence between multiple network segments and multiple ASNs, this application uses preset conditions to filter and obtain multiple target route advertising information. After verifying the validity of the multiple target route advertising information according to the preset set, it can accurately determine whether routing conflicts exist within the VPN. Therefore, this application can be used to efficiently and accurately detect routing information and promptly identify routing conflicts to avoid service failures. Attached Figure Description

[0032] Figure 1 This is a schematic diagram of the structure of a route detection system provided in an embodiment of this application;

[0033] Figure 2 A schematic diagram of the hardware structure of a core router provided in an embodiment of this application;

[0034] Figure 3 A schematic diagram of the hardware structure of another core router provided in an embodiment of this application;

[0035] Figure 4 A flowchart illustrating a route detection method provided in an embodiment of this application;

[0036] Figure 5A flowchart illustrating another route detection method provided in an embodiment of this application;

[0037] Figure 6 A flowchart illustrating another route detection method provided in an embodiment of this application;

[0038] Figure 7 A flowchart illustrating another route detection method provided in an embodiment of this application;

[0039] Figure 8 A schematic diagram of a route detection process provided in an embodiment of this application;

[0040] Figure 9 This is a schematic diagram of the structure of a route detection device provided in an embodiment of this application. Detailed Implementation

[0041] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0042] It should be noted that in the embodiments of this application, the words "exemplary" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0043] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0044] Furthermore, the terms "comprising" and "having" in the embodiments, claims, and drawings of this application are not exclusive. For example, a process, method, system, product, or device that includes a series of steps or modules is not limited to the listed steps or modules, but may also include steps or modules not listed.

[0045] To facilitate understanding of this application, the relevant elements involved in this application are described below.

[0046] In IP-based bearer networks, network operators typically build different VPNs for different services. A VPN can be divided into multiple Application Servers (ASs), and different ASs can be connected via BGP to achieve routing information dissemination and service data transmission.

[0047] If routing information published by different ASs within the same VPN conflicts, it can easily lead to service interruptions and other failures. Furthermore, operators typically build numerous VPNs, making manual detection of route conflicts inefficient and unreliable, hindering timely detection of routing conflicts to prevent service disruptions.

[0048] To address the aforementioned issues, this application provides a route detection method. After acquiring multiple route advertising information within a first VPN, it can determine whether multiple target route advertising information meets preset conditions. Furthermore, when multiple target route advertising information meeting preset conditions exists, a detection result indicating the validity of each target route advertising information is obtained based on each target route advertising information and a preset set. Therefore, this application can achieve automatic detection of multiple route advertising information within a VPN.

[0049] Furthermore, considering that routing conflicts can easily arise when different ASs use the same network segment, and given that the preset conditions include IP addresses belonging to the same network segment but with different ASNs, and the preset set includes the correspondence between multiple network segments and multiple ASNs, this application obtains multiple target route advertising information by filtering through preset conditions. After verifying the validity of multiple target route advertising information according to the preset set, it can accurately determine whether routing conflicts exist within the VPN. Therefore, this application can be used to efficiently and accurately detect routing information and promptly identify routing conflicts to avoid service failures.

[0050] This route detection method is applicable to route detection systems. Figure 1 One structure of the route detection system 100 is shown. For example... Figure 1 As shown, the route detection system 100 may include multiple core routers 101 and multiple border routers 102. The core routers 101 can communicate with one or more border routers 102. Different core routers 101 can communicate with each other.

[0051] It should be noted that this application does not limit the number of core routers 101 and border routers 102 in the routing detection system 100.

[0052] In one possible configuration, the core router 101, also known as the backbone router, is a router deployed at the core of the IP bearer network. The core router 101 can be configured with multiple static and dynamic routing tables for VPNs to support packet routing and forwarding of service data for different services, thus achieving high throughput.

[0053] In one possible approach, different border routers 102 can belong to different autonomous systems. The border router 102 can be a router deployed with multiple network protocols such as IP and BGP, used to connect the autonomous system to external networks.

[0054] Combination Figure 1 ,like Figure 2 The diagram shown is a hardware structure schematic of a core router 101 provided in an embodiment of this application. The core router 101 may include a data configuration unit, an instruction execution unit, a route detection unit, and a dispatch processing unit.

[0055] The data configuration unit can be configured with resource files such as a first detection command, a second detection command, and a preset set. The preset set refers to the network segment information pre-planned by the operator for each AS. Furthermore, the data configuration unit can also be configured with static and dynamic routing tables for different VPNs, as well as route advertising information from different VPNs.

[0056] The instruction execution unit can be used to execute the first detection instruction and the second detection instruction to determine whether there is route advertising information in each VPN that is likely to cause routing conflicts.

[0057] The route detection unit can identify the AS that incorrectly published the target route information when multiple target route advertisements that meet preset conditions exist. That is, the AS corresponding to the target route advertisement information where there is no corresponding relationship between the network segment to which the IP address belongs and the ASN.

[0058] The dispatch processing unit can be used to send prompts to nodes that have invalid target route publication information, so that staff can be informed that the target route publication information has been incorrectly published and can be rectified.

[0059] Combination Figure 1 ,like Figure 3 The diagram shown illustrates another hardware structure of the core router 101 provided in this application embodiment. The core router 101 includes a processor 21, a memory 22, a communication interface 23, and a bus 24. The processor 21, memory 22, and communication interface 23 are connected via the bus 24.

[0060] Processor 21 is the control center of the core router 101. It can be a single processor or a collective term for multiple processing elements. For example, processor 21 can be a CPU or other general-purpose processors. Among them, general-purpose processors can be microprocessors or any conventional processors.

[0061] As one embodiment, processor 21 may include one or more CPUs, for example Figure 3 CPU0 and CPU1 are shown in the diagram.

[0062] The memory 22 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0063] In one possible implementation, the memory 22 can exist independently of the processor 21. The memory 22 can be connected to the processor 21 via the bus 24 and is used to store instructions or program code. When the processor 21 calls and executes the instructions or program code stored in the memory 22, it can implement the routing detection method provided in the following embodiments of this application.

[0064] In another possible implementation, the memory 22 can also be integrated with the processor 21.

[0065] Communication interface 23 is used for the core router 101 to connect with other devices via a communication network, which may be Ethernet, wireless access network, wireless local area network (WLAN), etc. Communication interface 23 may include a receiving unit for receiving data and a sending unit for sending data.

[0066] Bus 24 can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0067] It should be pointed out that, Figure 3 The structure shown does not constitute a limitation on the core router 101, except... Figure 3 In addition to the components shown, the core router 101 may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0068] like Figure 4 The diagram shown is a flowchart illustrating a route detection method provided in an embodiment of this application. This route detection method can be applied to... Figure 1 The core router 101 in the route detection system 100 shown. The route detection method includes: S401-S403.

[0069] S401, the core router obtains multiple route advertisement information within the first VPN.

[0070] The route advertising information may include the IP address of the node sending the information and the ASN to which the node belongs. Route advertising information can be used to announce route entries to support data forwarding within the ASN.

[0071] Optionally, the route advertising information can be BGP routes, that is, routing information generated and sent by nodes based on BGP.

[0072] In one possible approach, the core router can be configured with a storage module. This storage module can be used to store routing information for the various VPNs built on the IP bearer network.

[0073] In one possible approach, the first VPN can be any one of multiple VPNs built on an IP-based bearer network. For example, the core router can sequentially identify each VPN as the first VPN through periodic polling. Alternatively, staff can designate any VPN as the first VPN from among multiple VPNs and pre-configure this in the core router. Based on this, after identifying the first VPN, the core router can read multiple route advertising information from the storage module within the first VPN.

[0074] In one possible approach, any node within the first VPN can send route advertising information. Correspondingly, the core router can receive the route advertising information from this arbitrary node. Furthermore, to avoid service failures caused by routing conflicts, the core router can read multiple route advertising messages from different ASs within the first VPN from the storage module before writing the route advertising information from this arbitrary node into the dynamic routing table. It can then further check whether the route advertising information from this arbitrary node conflicts with these multiple route advertising messages, i.e., whether the route advertising information from this arbitrary node is valid.

[0075] Based on this, the core router can determine in advance whether a route advertisement conflict with other recorded route advertisements before writing it into the router's dynamic routing table. This allows it to notify the node that published the incorrect advertisement to rectify the situation immediately, thus avoiding major service failures.

[0076] S402. The core router determines whether there are multiple target route advertisements that meet preset conditions among the multiple route advertisements.

[0077] The preset conditions may include IP addresses belonging to the same network segment but having different ASNs.

[0078] In one possible approach, after obtaining multiple route advertisements within the first VPN, the core router can determine whether any of these advertisements contain multiple target route advertisements that meet preset conditions. Specifically, if two route advertisements have the same IP address (i.e., the same network address and the same subnet mask length) but different ASNs, it indicates that the IP addresses of the two advertisements belong to the same network segment, but their ASNs are different. This means that nodes within different ASs have been assigned the same IP address, resulting in a routing conflict. In this case, the core router can determine that the two route advertisements meet the preset conditions.

[0079] If two routes advertised have different ASNs and different IP addresses but the same network address (meaning the IP addresses belong to the same network segment but have different subnet masks), it indicates that the IP addresses in the two routes advertised belong to the same network segment, but the ASNs are different. This suggests that different ASs are using the same network segment, potentially leading to routing conflicts due to incorrect route advertising. In this case, the core router can determine that the two routes advertised meet preset conditions.

[0080] If the core router does not find any route advertisements with the same IP address but different ASNs among multiple route advertisements, or route advertisements with the same IP address belonging to the same network segment but different subnet mask lengths and different ASNs, then the core router can determine that there are no multiple target route advertisements that meet the preset conditions among the multiple route advertisements. In this case, the core router can stop executing S403 and can output information indicating that there is no route conflict.

[0081] S403: When multiple target route advertisements that meet preset conditions exist, the core router obtains the detection result based on the multiple target route advertisements and the preset set.

[0082] The preset set can include the mapping relationship between multiple network segments and multiple ASNs. The preset set can also be understood as the network segments that the operator pre-plans for different ASs within each VPN.

[0083] In one possible example, the preset set can be as shown in Table 1 below. For VPNs providing website services, different network segments can be allocated in different regions, and one network segment can correspond to multiple ASNs.

[0084] Table 1

[0085] Serial Number VPN Name Area Name network segment ASN 1 Website business Area A 10.124.21.0 / 24 65195-65279 2 Website business Area b 10.124.22.0 / 24 65280-65369 3 Website business Area C 10.124.23.0 / 24 65370-65399 4 Website business d region 10.124.24.0 / 24 65400-65464 5 Website business e area 10.124.25.0 / 24 65465-65519 6 Website business f region 10.124.26.0 / 24 65520-65551

[0086] The detection results can be used to indicate the validity of each target route advertisement. If the network segment to which the IP address included in a target route advertisement belongs corresponds to the ASN included in the preset set, it indicates that the target route advertisement has been correctly advertised and is valid. If the network segment to which the IP address included in a target route advertisement belongs does not correspond to the ASN included in the preset set, it indicates that the target route advertisement has been incorrectly advertised and is invalid.

[0087] In one possible approach, when multiple target route advertisements that meet preset conditions exist among multiple route advertisements, the core router can determine the node that erroneously sent the route advertisement based on the multiple target route advertisements and a preset set, obtain the detection results, and remind relevant personnel to make corrections, thereby avoiding service failures caused by route conflicts.

[0088] Specifically, the core router can determine the network segment to which the IP address belongs in multiple target route advertisements belongs as the target network segment, and determine the ASN that corresponds to the target network segment in the preset set as the target ASN, so as to further determine that the target route advertisement with an ASN that is different from the target ASN is not valid, and the target route advertisement with the same ASN as the target ASN is valid, and thus obtain the detection result.

[0089] Alternatively, the core router can match the network segment corresponding to the ASN included in each target route advertisement information from the preset set, and determine that the target route advertisement information whose IP address belongs to a network segment different from the network segment corresponding to the ASN is not valid, and the target route advertisement information whose IP address belongs to a network segment different from the network segment corresponding to the ASN is valid, and obtain the detection result.

[0090] In one embodiment, combined with Figure 4 In S402 above, when the core router determines whether there are multiple target route advertisements that meet preset conditions among the multiple route advertisements, such as... Figure 5 As shown, this application embodiment provides an optional implementation method, including: S501-S502.

[0091] S501, the core router calls the first detection command to determine whether there is a target route advertisement with the same IP address but different ASN among multiple route advertisement information.

[0092] In one possible approach, staff can pre-configure a first detection command in the core router. This first detection command can be used to detect identical routing information originating from different ASs, specifically routing advertisements with the same network address and mask length.

[0093] In one possible approach, if the core router outputs target route advertising information after executing the first detection command, it indicates that a routing conflict exists.

[0094] In one possible example, the default first detection command is "disp bgp vpnv4 vpn-instance first VPN routing-table different-origin-as". After the core router executes the first detection command, it can obtain the first execution result. The first execution result is shown below:

[0095]

[0096]

[0097] From the last column of the first execution result, the "Path / Ogn" field, it can be determined that 10.124.21.0 / 24 originates from two ASes with ASNs 400 and 200 respectively. That is, the target route advertising information of the AS originating from ASN 400 and the AS with ASN 200 includes the same IP address, which meets the preset conditions. Subsequently, the core router can determine from the preset set the ASNs that correspond to 10.124.21.0 / 24, thus identifying the AS that incorrectly advertised the route among the two ASes with ASNs 400 and 200.

[0098] S502, the core router calls the second detection command to determine whether there are target route advertisements among multiple route advertisements that have the same IP address belonging to the same network segment, different mask lengths, and different ASNs.

[0099] In one possible approach, staff can pre-configure a second detection command in the core router. This second detection command can be used to detect whether there are erroneous distributions within the network segment and subnets.

[0100] In one possible example, the default second detection command is "disp bgp vpnv4 vpn-instance first VPN routing-table 10.124.23.0 / 24longer-prefixes". The parameter 10.124.23.0 / 24 represents the network address and subnet mask, which can be obtained by the core router through polling a default set, or specified by the operator. After the core router executes the second detection command, it will obtain a second execution result. The second execution result is shown below:

[0101]

[0102] From the first column "Network" and the last column "Path / Ogn" of the second execution result, it can be determined that network segment 10.124.23.0 / 24 originates from AS with ASN 500, and the two sub-network segments 10.124.23.0 / 27 and 10.124.23.192 / 27, which are contained within network segment 10.124.23.0 / 24, originate from AS with ASN 200. That is, the IP addresses of the target route advertisements originating from AS with ASN 500 and AS with ASN 200 belong to the same network segment, but their mask lengths are different, which meets the preset conditions. Furthermore, the core router can match the corresponding network segment in a preset set based on the ASN of each route advertisement in the second execution result to detect whether there is any incorrectly advertised route advertisement.

[0103] In one embodiment, combined with Figure 4 In S403 above, when the core router obtains the detection result based on multiple target route advertisements and a preset set, such as... Figure 6 As shown, this application embodiment provides an optional implementation method, including: S601-S603.

[0104] S601, the core router determines the network segment to which the IP address belongs, which is included in the multiple target routing advertisements, as the target network segment.

[0105] In one possible approach, if multiple target route advertisements meet preset conditions, then the IP addresses included in these multiple target route advertisements belong to the same network segment. Based on this, the core router can determine the network segment to which the IP addresses included in the multiple target route advertisements belong as the target network segment.

[0106] S602, The core router will identify the ASNs in the preset set that correspond to the target network segment as the target ASN.

[0107] In one possible approach, the core router can match ASNs that correspond to the target network segment from a preset set, and identify the matched ASN as the target ASN. The target ASN can be one or more ASNs used to mark ASs that are allowed to use the target network segment.

[0108] S603, the core router determines that target route advertising information with an ASN different from the target ASN is invalid, and target route advertising information with the same ASN as the target ASN is valid, and obtains the detection result.

[0109] In one possible approach, if a destination route advertisement includes an ASN that is different from the target ASN, it indicates that the AS to which the destination route advertisement belongs has not been configured with usage rights for the target network segment, meaning the destination route advertisement has been incorrectly advertised. In this case, the core router can determine that the destination route advertisement is invalid, that is, it determines that a destination route advertisement with an ASN different from the target ASN is invalid.

[0110] If a destination route advertisement includes an ASN that is the same as the target ASN, it indicates that the AS to which the destination route advertisement belongs has been configured with usage rights to the target network segment, meaning the destination route advertisement has been correctly advertised. In this case, the core router can determine that the destination route advertisement is valid, that is, it can confirm the validity of a destination route advertisement with the same ASN as the target ASN.

[0111] In one possible example, with the preset set as shown in Table 2, and referring to the example in S501, the core router can determine that the target network segment is 10.124.21.0 / 24, and the target ASN corresponding to the target network segment is 200. Further, the core router can determine that the target route advertisement information published by area A corresponding to AS with ASN 200 is valid, and the target route advertisement information published by area B corresponding to AS with ASN 400 is invalid. That is, the advertisement in area A is correct, and the advertisement in area B is incorrect. Subsequently, the core router can send a prompt message through the node corresponding to AS with ASN 400 to facilitate rectification by personnel in area B (e.g., canceling the route).

[0112] Referring to the example in S502, the core router can determine that the target network segment is 10.124.23.0 / 24, and the target ASN corresponding to the target network segment is 500. Furthermore, the core router can determine that the target route advertisement information published by area C corresponding to the AS with ASN 500 is valid, while the target route advertisement information published by area A corresponding to the AS with ASN 200 is invalid. That is, the advertisement in area C is correct, and the advertisement in area A is incorrect. Subsequently, the core router can send a notification message through the node corresponding to the AS with ASN 200 to facilitate rectification by personnel in area A.

[0113] Table 2

[0114] Serial Number VPN Name Area Name network segment ASN 1 FirstVPN Area A 10.124.21.0 / 24 200 2 FirstVPN Area B 10.124.22.0 / 24 400 3 FirstVPN Area C 10.124.23.0 / 24 500 4 FirstVPN Area D 10.124.24.0 / 24 600

[0115] Furthermore, the core router can also generate an error distribution details table as shown in Table 3 below.

[0116] Table 3

[0117] Serial Number Posting error entries The AS to which the error node belongs. The region to which the error node belongs. 1 10.124.21.0 / 24 400 Area B 2 10.124.23.0 / 27 200 Area A 3 10.124.23.192 / 27 200 Area A

[0118] Furthermore, assuming there are 23 route advertisements within the first VPN, the core router can also generate conflict detection reports and log information. For example, the advertisement statistics table shown in Table 4 below can include information such as the number of correctly advertised entries, the number of incorrectly advertised entries, and the number of incorrectly advertised nodes.

[0119] Table 4

[0120] Serial Number Number of correct entries published Number of published error entries Number of error nodes published 1 20 3 2

[0121] In one embodiment, combined with Figure 4 Following S403 above, such as Figure 7 As shown in the embodiment of this application, the route detection method further includes: S701.

[0122] S701, the core router sends a notification message to the node corresponding to the target route advertisement information that is not valid.

[0123] The data type of the notification message can include at least one of audio and text. For example, the notification message can be a voice message, a text message, or an email.

[0124] In one possible approach, once the core router determines that the target route advertisement information is invalid, it can send a notification message to the node corresponding to the invalid target route advertisement information, so that staff can make timely corrections and avoid service failures caused by routing conflicts.

[0125] In one embodiment, such as Figure 8 The diagram illustrates a route detection process provided in an embodiment of this application. The core router can be configured with a data configuration module, an instruction execution module, a data judgment module, a data retrieval module, a dispatch processing module, and a result generation module. The core router can preset a first detection instruction for a first VPN and a second detection instruction for the first VPN through the configured data configuration module. The core router can execute the first detection instruction and the second detection instruction through the configured instruction execution module. The core router can determine, through the configured data judgment module, whether there is output after the execution of the first and second detection instructions, i.e., whether there is target route advertising information with the same IP address but different ASNs, and whether there is target route advertising information with the same IP address belonging to the same network segment but different mask lengths and different ASNs.

[0126] If target route advertisements with the same IP address but different ASNs exist, and / or if target route advertisements with the same IP address belonging to the same network segment but different subnet mask lengths and different ASNs exist, the core router can obtain the detection result through its configured data retrieval module based on multiple target route advertisements and a preset set. Furthermore, the core router can use its configured dispatch processing module to send alerts to nodes corresponding to invalid target route advertisements.

[0127] If there is no target route advertising information with the same IP address but different ASN, the core router can update the route detection report through the configured result generation module.

[0128] If no target route advertising information exists that includes IP addresses belonging to the same network segment, but with different subnet masks and different ASNs, the core router can determine whether round-robin has been completed, i.e., whether the second detection command has completed the detection of all network points in the preset set. If round-robin has been completed, the core router can update the route detection report through the configured result generation module. If round-robin has not been completed, the core router can execute the second detection command through the configured command execution module.

[0129] In this embodiment, after obtaining multiple routing advertisements within the first VPN, the core router can determine whether there are multiple target routing advertisements that meet preset conditions. Furthermore, when multiple target routing advertisements that meet the preset conditions exist, the router can obtain a detection result indicating the validity of each target routing advertisement based on each target routing advertisement and a preset set. Based on this, this application can achieve automatic detection of multiple routing advertisements within the VPN.

[0130] Furthermore, considering that routing conflicts can easily arise when different ASs use the same network segment, and given that the preset conditions include IP addresses belonging to the same network segment but with different ASNs, and the preset set includes the correspondence between multiple network segments and multiple ASNs, this application obtains multiple target route advertising information by filtering through preset conditions. After verifying the validity of multiple target route advertising information according to the preset set, it can accurately determine whether routing conflicts exist within the VPN. Therefore, this application can be used to efficiently and accurately detect routing information and promptly identify routing conflicts to avoid service failures.

[0131] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, it includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0132] This application embodiment can divide the core router into functional modules according to the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0133] like Figure 9 The diagram shown is a structural schematic of a route detection device provided in an embodiment of this application. This route detection device can be used to perform tasks such as... Figures 4-7 The route detection method shown is described. The route detection device includes: an acquisition unit 801, a determination unit 802, and a processing unit 803.

[0134] Acquisition unit 801 is used to acquire multiple routing advertisement information within the first Virtual Private Network (VPN); the routing advertisement information includes Internet Protocol (IP) addresses and Autonomous System Numbers (ASNs); for example, combined with... Figure 4 The acquisition unit 801 can be used to execute S401.

[0135] Determining unit 802 is used to determine whether there are multiple target route advertisements that meet preset conditions among the multiple route advertisements obtained by obtaining unit 801; the preset conditions include that the IP addresses belong to the same network segment and have different ASNs; for example, combined with Figure 4 Unit 802 can be used to execute S402.

[0136] The processing unit 803 is configured to, when the determining unit 802 determines that multiple target route advertising information meets preset conditions, obtain a detection result based on the multiple target route advertising information and a preset set; the preset set includes the correspondence between multiple network segments and multiple ASNs; the detection result is used to indicate whether each target route advertising information is valid. For example, combined with... Figure 4Unit 802 can be used to execute S403.

[0137] Optionally, unit 802 is specifically used for:

[0138] Invoke the first detection instruction to determine whether there are target route advertisements with the same IP address but different ASNs among multiple route advertisements; for example, combining... Figure 5 Unit 802 can be used to execute S501.

[0139] The second detection command is invoked to determine whether any of the multiple route advertisements contain target route advertisements with the same IP address belonging to the same network segment, but different subnet mask lengths and different ASNs. For example, combining... Figure 5 Unit 802 can be used to execute S502.

[0140] Optionally, the processing unit 803 is specifically used for:

[0141] The network segment to which the IP addresses included in the multiple target route advertisements belong is determined as the target network segment; for example, combining... Figure 6 The processing unit 803 can be used to execute S601.

[0142] The ASNs in the preset set that correspond to the target network segment are identified as the target ASNs; for example, combining... Figure 6 The processing unit 803 can be used to execute S602.

[0143] The detection results are obtained by determining that target route advertisements with ASNs different from the target ASN are invalid, and target route advertisements with the same ASN as the target ASN are valid. For example, combining... Figure 6 The processing unit 803 can be used to execute S603.

[0144] Optionally, the route detection device further includes: a sending unit 804;

[0145] The sending unit 804 is used to send a prompt message to the node corresponding to the target route publication information that does not have validity; the data type of the prompt message includes at least one of audio and text. For example, combined with... Figure 7 The sending unit 804 can be used to execute S701.

[0146] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this application can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer-readable storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.

[0147] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0148] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and other division methods may exist in actual implementation. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate; components shown as units may be one physical unit or multiple physical units, i.e., they may be located in one place or distributed in multiple different places. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0149] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method of route detection, characterized by, The method comprises the following steps: obtaining a plurality of route publication information in a first virtual private network (VPN); the route publication information comprises an Internet Protocol (IP) address and an autonomous system number (ASN); determining whether a plurality of target route publication information meeting a preset condition exists in the plurality of route publication information, comprising: invoking a first detection instruction to determine whether target route publication information with the same IP address and different ASNs exists in the plurality of route publication information, and invoking a second detection instruction to determine whether target route publication information with the same network segment to which the IP address belongs, different mask lengths and different ASNs exists in the plurality of route publication information; the preset condition comprises the same network segment to which the IP address belongs and different ASNs; when the plurality of target route publication information meeting the preset condition exists, obtaining a detection result according to the plurality of target route publication information and a preset set; the preset set comprises a correspondence relationship between a plurality of network segments and a plurality of ASNs; the detection result is used to indicate whether each target route publication information has validity.

2. The method of claim 1, wherein, The detection result is obtained according to the plurality of target route publication information and the preset set, comprising: determining the network segment to which the IP address belonging to the plurality of target route publication information as a target network segment; determining the ASN in the preset set having the correspondence relationship with the target network segment as a target ASN; determining that the target route publication information with the ASN different from the target ASN does not have validity, and the target route publication information with the same ASN as the target ASN has validity, to obtain the detection result.

3. The method of claim 2, wherein, The method further comprises the following steps: sending prompt information to the node corresponding to the target route publication information without validity; the data type of the prompt information comprises at least one of audio and text.

4. A routing detection apparatus, characterized by, The method comprises the following steps: an obtaining unit, a determining unit and a processing unit; the obtaining unit is configured to obtain a plurality of route publication information in a first virtual private network (VPN); the route publication information comprises an Internet Protocol (IP) address and an autonomous system number (ASN); the determining unit is configured to determine whether a plurality of target route publication information meeting a preset condition exists in the plurality of route publication information obtained by the obtaining unit, comprising: invoking a first detection instruction to determine whether target route publication information with the same IP address and different ASNs exists in the plurality of route publication information, and invoking a second detection instruction to determine whether target route publication information with the same network segment to which the IP address belongs, different mask lengths and different ASNs exists in the plurality of route publication information; the preset condition comprises the same network segment to which the IP address belongs and different ASNs; the processing unit is configured to, when the determining unit determines that the plurality of target route publication information meeting the preset condition exists, obtain a detection result according to the plurality of target route publication information and a preset set; the preset set comprises a correspondence relationship between a plurality of network segments and a plurality of ASNs; the detection result is used to indicate whether each target route publication information has validity.

5. The routing detection apparatus according to claim 4, characterized by The processing unit is specifically configured to: The network segment to which the IP address included in the plurality of target route publishing information belongs is determined as a target network segment; An ASN in the preset set that has a corresponding relationship with the target network segment is determined as a target ASN; The target route publishing information whose ASN is different from the target ASN is determined as not having validity, and the target route publishing information whose ASN is the same as the target ASN is determined as having validity, to obtain the detection result.

6. The routing detection apparatus according to claim 5, characterized by Further comprising: a sending unit; The sending unit is configured to send prompt information to a node corresponding to the target route publishing information that does not have validity; and the data type of the prompt information includes at least one of audio and text.

7. A routing detection apparatus, characterized by, The route detection device comprises a memory and a processor; the memory is configured to store computer execution instructions; the processor is connected to the memory through a bus; when the route detection device is running, the processor executes the computer execution instructions stored in the memory, so that the route detection device executes the route detection method according to any one of claims 1-3.

8. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises computer execution instructions; when the computer execution instructions run on a computer, the computer executes the route detection method according to any one of claims 1-3.

Citation Information

Patent Citations

  • Route between fields abnormity detecting method based on multi view

    CN1764122A