Network switch, method for network switching, and computer storage medium

By sharing the role information of host devices in BGP update message announcements, the problem of ineffective sharing of role information between access switches is solved, seamless roaming and the application of appropriate network policies are achieved, and network performance and security are improved.

CN116938809BActive Publication Date: 2025-09-30HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211313650.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-04
Filing Date
2022-10-25
Publication Date
2025-09-30
Estimated Expiration
2042-10-25

AI Technical Summary

Technical Problem

In a VXLAN network, access switches cannot effectively share host device role information, resulting in the inability to correctly apply role-based network policies, affecting network performance and security.

Method used

Incorporating host device role information into BGP update message announcements enables access switches to share this information in the VXLAN network, thereby distributing role information between access switches and implementing network policies based on role information.

Benefits of technology

It enables seamless roaming of host devices between network switches while maintaining appropriate network policies, avoids the overhead of new role information communication protocols, and solves scalability barriers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116938809B_ABST
    Figure CN116938809B_ABST
Patent Text Reader

Abstract

Role information propagation in an access switch. In an example, the switch may receive an authentication request from a host associated with a first wireless access point (WAP) connected to the switch. The switch acts as a VXLAN tunnel endpoint (VTEP) in a virtual extensible local area network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN). The switch forwards the authentication request to an authentication server, and upon successful authentication of the host, may associate the role information with the host based on an authentication response from the authentication server. In addition, the switch may create a BGP extended community field that carries a role identifier indicating a network policy implemented for the host, and the switch attaches a route advertisement to the BGP extended community field. The switch then sends the route advertisement to another switch. The other switch is configured as a peer VTEP in the VXLAN. The switch and the other switch are configured in a single virtual local area network (VLAN).
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Communications networks are typically divided into three layers: the core layer, the access layer, and the distribution layer. The core layer provides high-speed communications to network devices (such as switches and routers) located in the distribution and access layers. The access layer provides communications to host devices. The distribution layer serves as the interface between the core and access layers. It manages routing, filtering, and Quality of Service (QoS) policies for the communications network.

[0002] A communication network topology can be arranged with physical links connecting switches. Multiple physically linked switches can form a local area network (LAN). A collection of such LANs can form a network access layer. The switches in the access layer can be connected to one or more wireless access points (WAPs). A WAP can serve as an access point for wireless host devices. Summary of the Invention

[0003] This disclosure describes a technique for incorporating host device role information into BGP update message announcements to share this role information between access switches in a VXLAN network. Therefore, when a BGP update message announcement is shared between access switches, the access switch also receives role information associated with a specific host device. This allows role information to be distributed between access switches. Access switches can implement network policies based on role information. This allows host devices to roam seamlessly between network switches while maintaining role-appropriate network policies. Furthermore, using the BGP EVPN infrastructure to transmit role information avoids the overhead associated with creating a new role information communication protocol. This can help remove scalability barriers.

[0004] In one or more embodiments, a network switch is disclosed, comprising: a processor; and a non-transitory computer-readable medium comprising instructions, which, when executed by the processor, cause the network switch to: receive an authentication request message from a host device associated with a first wireless access point (WAP) connected to the network switch, wherein the network switch is configured as a VXLAN tunnel endpoint (VTEP) in a virtual extensible local area network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet virtual private network (EVPN); forward the authentication request message to an authentication server; in response to receiving an authentication response message from the authentication server, associate role information with the host device based on the authentication response message, wherein the role information indicates a group or category of a user of the host device; and send a route advertisement message to the host device based on the role information. The route advertisement message adds a role identifier, wherein the route advertisement message indicates a mapping between the Internet Protocol IP address of the host device and the Media Access Control MAC address of the host device, wherein in order to add the role identifier, the network switch is to: create a BGP extended community field, the BGP extended community field carrying the role identifier indicating the network access policy to be implemented for the host device; and append the BGP extended community field to the route advertisement message; and send the route advertisement message to another network switch, wherein the other network switch is configured as a peer VTEP in the VXLAN, and the network switch and the other network switch are configured in a single virtual local area network VLAN, and wherein upon receiving the route advertisement message, the other network switch knows the network access policy to be implemented for the host device.

[0005] In one or more embodiments, a method for network switching is disclosed, comprising: receiving, by a network switch, an authentication request message from a host device associated with a first wireless access point (WAP) connected to the network switch, wherein the network switch is configured as a VXLAN tunnel endpoint (VTEP) in a virtual extensible local area network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet virtual private network (EVPN); forwarding, by the network switch, the authentication request message to an authentication server; in response to successful authentication of the host device, associating, by the network switch, role information with the host device based on an authentication response message from the authentication server, wherein the role information indicates a group or category of a user of the host device; and adding, by the network switch, a role tag in a routing advertisement message of the host device based on the role information. identifier, wherein the route advertisement message indicates a mapping between an Internet Protocol (IP) address of the host device and a Media Access Control (MAC) address of the host device, wherein adding the role identifier comprises: creating a BGP extended community field, the BGP extended community field carrying the role identifier indicating a network policy to be implemented for the host device; and appending the BGP extended community field to the route advertisement message; and sending the route advertisement message by the network switch to another network switch, wherein the another network switch is configured as a peer VTEP in the VXLAN, the network switch and the another network switch are configured in a single virtual local area network (VLAN), and wherein upon receiving the route advertisement message, the another network switch knows the network access policy to be implemented for the host device.

[0006] In one or more embodiments, a non-transitory computer-readable medium is disclosed that includes instructions that, when executed by a processor, cause a network switch to: receive an authentication request message from a host device associated with a first wireless access point (WAP) connected to the network switch, wherein the network switch is configured as a VXLAN tunnel endpoint (VTEP) in a virtual extensible local area network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet virtual private network (EVPN); forward the authentication request message to an authentication server; in response to successful authentication of the host device, associate role information with the host device based on an authentication response message from the authentication server, wherein the role information indicates a group or category of a user of the host device; and add a role to a route advertisement message of the host device based on the role information. identifier, wherein the route advertisement message indicates a mapping between an Internet Protocol (IP) address of the host device and a Media Access Control (MAC) address of the host device, wherein in order to add the role identifier, the network switch is to: create a BGP extended community field, the BGP extended community field carrying the role identifier indicating the network policy to be implemented for the host device; and append the BGP extended community field to the route advertisement message; and send the route advertisement message to another network switch, wherein the other network switch is configured as a peer VTEP in the VXLAN, the network switch and the other network switch are configured in a single virtual local area network (VLAN), and wherein upon receiving the route advertisement message, the other network switch knows the network access policy to be implemented for the host device. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] For a more complete understanding of the present disclosure, examples according to the various features described herein may be more readily understood by reference to the following detailed description taken in conjunction with the accompanying drawings, wherein like reference numerals represent like structural elements, and wherein:

[0008] Figure 1A schematically illustrates a computing network implementing a wired network switch for role information propagation according to an example;

[0009] Figure 1B is a block diagram of an example network switch for role information propagation according to an example;

[0010] Figure 1C schematically illustrates a Border Gateway Protocol (BGP) extended community field for role information propagation according to an example;

[0011] Figure 2 is a flow chart illustrating a method for role information propagation according to an example;

[0012] Figure 3A and Figure 3B is a flow chart illustrating another method for role information propagation according to an example; and

[0013] Figure 4 A computing device for implementing a role information propagation method according to an example is illustrated.

[0014] Some examples have features in addition to or instead of those shown in the above-described drawings.For clarity, some reference numerals may be omitted from some of the drawings. DETAILED DESCRIPTION

[0015] A communication network deployment such as a campus area network (CAN) can include the interconnection of a local area network (LAN) with wireless access points (WAPs) connected to LAN switches. The switches can be connected to the WAPs via physical links. They can act as network connection points for the WAPs. The switches in the access layer, also known as access switches, can be connected to one or more WAPs. Each WAP can serve wireless host devices (such as laptops and cell phones) within a specific range. For example, a WAP can serve a specific floor of a campus building where the CAN is deployed. Host devices moving between different floors of the building can switch or roam between the WAPs serving different floors to maintain connectivity.

[0016] In some examples, WAPs employ fast roaming technology to enable seamless mobility of host devices within a network. Fast roaming allows mobile host devices to move around the network without being disconnected or dropped from the network. Fast roaming can help host devices roam to new WAPs without reauthenticating. To avoid host reauthentication, WAPs in the same access layer can share host device authentication information.

[0017] Host device information shared between WAPs can include network prefixes and IP addresses. To share this information securely, access switches typically form a virtual extensible local area network (VXLAN) that uses Ethernet Virtual Private Network (EVPN) to exchange control plane information. Control plane information includes information in the switch routing table that defines what to do with incoming packets. VXLAN is a network virtualization technology that uses encapsulation technology to encapsulate Open Systems Interconnection (OSI) Layer 2 Ethernet frames within Layer 4 User Datagram Protocol (UDP) datagrams. A VXLAN endpoint that terminates a VXLAN tunnel and can be a virtual or physical switch port is called a VXLAN Tunnel Endpoint (VTEP). EVPN is based on the Border Gateway Protocol (BGP), which allows network prefixes and IP addresses to be shared in the form of Network Layer Reachability Information (NLRI). Access switches act as VTEPs, also known as VXLAN peers, which exchange BGP EVPN update messages to share NLRIs between them. The exchange of NLRIs allows access switches in a VXLAN to know which host device is connected to which access switch via which WAP and forward data accordingly.

[0018] However, different host devices connected to the network may be subject to different network policies based on their role information. Network policies may include rules, permissions, conditions, and settings that define which host devices are authorized to connect to the network, as well as the circumstances under which different host devices are permitted to connect to the network. Role information indicates the group or category of the host device user. Network policies applied to each host device can be determined based on this role information. Examples of roles include guest, student, employee, salesperson, and manager. Examples of network policies applied to these roles may include various conditions. For example, a "guest" cell phone may not be allowed to use the office network for more than one hour. As another example, a "student" host may be blocked from accessing certain URLs. With BGP EVPN VXLAN implemented in access switches, even though the host device NLRI is shared between access switches, the access switches remain unaware of host device role information. This presents challenges in implementing role-based network policies, particularly when a host device roams from a first WAP to a second WAP connected to two different access switches.

[0019] When a host device first connects to the network, the first WAP can receive role information. This is because role information can be provided to the WAP during authentication. For example, a WAP can act as a proxy for authentication services such as Remote Authentication Dial-In User Service (RADIUS) or RADIUS over Transport Layer Security (TLS). However, when a host device roams from a first WAP to a second WAP in the same access layer, the second access switch to which the WAP is connected may not know the host device's role. Access switches typically do not share host device role information between them. Therefore, although the host device can seamlessly transition between the first and second WAPs due to fast roaming, and data can be correctly routed through the second WAP due to NLRI sharing, the second access switch may not implement role-based network policies. If network policies are not properly implemented at the second access switch, the conditions for exchanging data with the host device may not be correctly applied. This can affect overall network performance, throughput, and security. It can also leave network nodes vulnerable or overloaded. This can lead to security threats or failures that affect service availability.

[0020] This disclosure describes a technique for incorporating host device role information into BGP update message announcements to share this role information between access switches in a VXLAN network. Therefore, when a BGP update message announcement is shared between access switches, the access switch also receives role information associated with a specific host device. This allows role information to be distributed between access switches. Access switches can implement network policies based on role information. This allows host devices to roam seamlessly between network switches while maintaining role-appropriate network policies. Furthermore, using the BGP EVPN infrastructure to transmit role information avoids the overhead associated with creating a new role information communication protocol. This can help remove scalability barriers.

[0021] In an example, a network switch is described. The network switch (also referred to as a switch) includes a processor and a non-transitory computer-readable medium including instructions that, when executed by the processor, cause the switch to receive an authentication request message from a host device associated with a first WAP connected to the switch. The switch can be configured as a VTEP in a VXLAN based on BGP EVPN. In the VXLAN, there can be other switches configured as peer VTEPs. The switches can be configured in a single virtual local area network (VLAN) to allow host devices to quickly roam between WAPs connected to the switches. The switch forwards the authentication request message to an authentication server (such as a RADIUS server). In response to successful authentication of the host device, the switch associates role information with the host device based on an authentication response message from the authentication server. The switch adds a role identifier in a route advertisement message of the host device based on the role information. The route advertisement message indicates a mapping between an Internet Protocol (IP) address of the host device and a Media Access Control (MAC) address of the host device. In this example, to add a role identifier, a switch creates a BGP extended community field that carries a role identifier indicating the network policy to be implemented for the host device, and the switch appends the BGP extended community field to a route advertisement message. The switch then sends the route advertisement message to another switch, and upon receiving the route advertisement message, the other switch learns the network access policy to be implemented for the host device. When the host device transitions from a first WAP to a second WAP connected to another switch, the other switch learns the host device's role information based on the role identifier in the received route advertisement message. Using the role identifier in the route advertisement message, the other switch can configure its data plane to enforce the network policy for the host device and can accordingly forward traffic to and from the host device associated with the second WAP. Thus, the host device's role information is propagated between switches, allowing the switch to implement the network policy based on the host device's role even if the host device roams through WAPs connected to different access switches.

[0022] The described systems and methods can be implemented in various switches that implement the functionality of a network switch in the access layer of a communication network. Although the above description refers to an access switch, the methods and described techniques can be implemented in other types of switches that implement different communication technologies (albeit with some variations). Various implementations of the present subject matter are described below with reference to a number of examples.

[0023] refer to Figures 1A to 4The above-described systems and methods are further described. It should be noted that the description and drawings are merely illustrative of the principles of the present subject matter and the examples described herein, and should not be construed as limiting the present subject matter. Therefore, it should be understood that various arrangements embodying the principles of the present subject matter may be devised, even though not explicitly described or shown herein. Furthermore, all statements herein reciting principles, aspects, and embodiments of the present subject matter, as well as specific examples thereof, are intended to encompass their equivalents.

[0024] Figure 1A A computing network 100 according to an example of the present subject matter is schematically illustrated. For example, the computing network 100 can be a public distributed environment, a private closed computing environment, or the like. The computing network 100 can be implemented for an organization such as a business, an educational institution, a government entity, a healthcare institution, or other organization. The figure shows an example of a configuration implemented with an organization having multiple users (or at least multiple host devices). The computing network 100 can be implemented at a geographic site that can include a primary network, for example, an office network, a home network, or other network setup. The primary network can be a private network, such as a private network that can include security controls and access controls to limit access to authorized users. For example, authorized users can include employees of a company at the geographic site, residents of a residence, customers of a business, students at a school, and the like. In the example, the computing network 100 is a campus area network (CAN).

[0025] As shown in FIG1 , according to an example of the present subject matter, a computing network 100 may include an access layer A, a distribution layer D, and a core layer C. Access layer A may implement a plurality of network switches, such as switch 102-1, switch 102-2, and switch 102-3. For ease of description, switch 102-1, switch 102-2, and switch 102-3 are hereinafter generally referred to as switches 102. In addition, the terms "network switch" and "switch" are used interchangeably in the specification. Each of switches 102 may provide connectivity between each other and between hosts. Each of switches 102 may be implemented as, but not limited to, an access layer switching unit, a switch router, or any device capable of exchanging data packets at access layer A and providing connectivity between devices in distribution layer D and host devices, and between host devices.

[0026] Each switch 102 can be connected to one or more WAPs. As shown in FIG1 , switch 102-1 is connected to WAP 103-1, and switch 102-2 is connected to WAPs 103-2 and 103-3. WAPs 103-1, 103-2, and 103-3 are collectively referred to as WAPs 103. In an example, each of switches 102 can be an access switch and facilitate the connection of host devices to computing network 100. Each of switches 102 includes multiple ports. In an example, a network administrator can designate a port in switch 102 as a network port or a wireless access port. A network port serves as an interface between switch 102 and network devices in upper layers (such as distribution layer D). A wireless access port serves as an interface between switch 102 and WAPs 103 connected to switch 102.

[0027] WAP 103 is included as an example of a point of access to computing network 100 for wireless host devices, such as host device 110. WAP 103 can control network access for host device 110 and can allow authentication of host device 110 for connecting to WAP 103 and, through WAP 103, to other devices within computing network 100. WAP 103 can use switch 102 and an authentication server, such as a RADIUS or RADSec server (not shown), to allow this authentication. Each of WAP 103 can be a combination of hardware, software, and / or firmware configured to provide wireless network connectivity to wireless host devices. In the illustrated example, WAP 103 can be implemented in a distributed WLAN architecture, where WAP 103 provides independent distributed intelligence but works together as a system to collaboratively provide control mechanisms.

[0028] Switches 102-1 and 102-2 are configured in a single broadcast domain. A broadcast domain can be understood as a logical division of a computer network in which all nodes can reach each other via broadcasts at the data link layer. Broadcasting refers to the transmission of data packets to every device on the network. Broadcast domains can be within the same LAN segment or bridged to other LAN segments. In this example, a single VLAN 120 is configured in switches 102-1 and 102-2. For example, a common VLAN identifier can be configured for each of the wireless access ports in switches 102-1 and 102-2 that are connected to WAPs 103-1, 103-2, and 103-3.

[0029] Distribution layer D includes network devices 104-1 and 104-2, which manage connectivity between wired network devices 102 in access layer A and core layer C. Core layer C may include network devices 106-1 and 106-2. Examples of network devices 106-1 and 106-2 include routers, layer 3 switches, and the like. Network devices 106-1 and 106-2 connect devices in the distribution and access layers to data center 108. Data center 108 may connect to one or more devices in an external network or the internet.

[0030] Now turn Figure 1B , shows an example network switch 150. The switch 150 may be similar to Figure 1A One or more switches are shown, such as switch 102-1, switch 102-2, and switch 102-3 in access layer A. Switch 150 may include a processor 152 and a memory 154 that may be coupled to each other via a communication link (e.g., a bus). Processor 152 may include a single or multiple central processing units (CPUs) or other suitable hardware processor(s) such as a network ASIC. Memory 154 may be a machine-readable storage medium that may store machine-readable instructions for execution by processor 152. Memory 154 may include any suitable combination of volatile and / or non-volatile memory, such as a combination of random access memory (RAM), read-only memory (ROM), flash memory, and / or other suitable memory.

[0031] Memory 154 includes non-transitory computer-readable media including instructions executable by processor 152. Memory 154 stores instructions to be executed by processor 152, including instructions for authentication manager 156, role manager 158, and routing manager 160.

[0032] The processor 152 can execute the authentication manager 156 to receive an authentication request message from a host device associated with a first WAP connected to the network switch 150. In an example, the network switch 150 can be configured as a VTEP in a VXLAN based on BGPEVPN. In an example, the authentication manager 156 can communicate with an authentication server such as a RADIUS / RADSec server and can include proxy authentication services. In an example, the authentication request message can be a RADIUS access request originating from the host device. The RADIUS access request can include access credentials (such as a username and password or a security certificate provided by the user) and the network address of the host device.

[0033] The processor 152 can execute the authentication manager 156 to forward the authentication request message to the authentication server. Based on the access credentials, the authentication server can authorize the host device to access. In an example, in response to successful authentication of the host device, the authentication server can send an authentication response message to the authentication manager 156 in the network switch 150. For example, the authentication response message can be a "RADIUS: Access-Accept" message indicating that network access is permitted to the host device. In an example, the authentication server can use the authentication response message to return role information of the host device. The role information of the host device indicates the purpose or function of the user of the host device to connect to the network. Based on the role information of the host device, the network policy for access is applied on the host device.

[0034] In response to successful authentication of the host device, processor 152 can execute role manager 158 to associate role information with the host device based on the authentication response message from the authentication server. Associating role information with the host device includes implementing network policies at switch 150 based on the role of the host device.

[0035] Furthermore, processor 152 may execute role manager 160 to add a role identifier to a route advertisement message from the host device based on the role information. The role identifier indicates a network policy implemented for the host device. In an example, the role identifier is a 16-bit value indicating the role associated with the host device upon authentication. The route advertisement message may be a BGP EVPN Type 2 route indicating a mapping between the host device's Internet Protocol (IP) address and the host device's Media Access Control (MAC) address. For example, the route advertisement message may include the host device's IP address mapped to the host device's MAC address, as well as an Address Resolution Protocol (ARP) entry. BGP is a routing protocol that makes dynamic routing decisions based on paths, network policies, and the like, and enables the exchange of routing and reachability information between network devices (such as switches) connected via BGP. BGP enables two remote sites connected via a VPN tunnel to exchange routing information. EVPN may utilize a multi-protocol BGP (MP-BGP) mechanism and define new sub-address families, such as the EVPN address family, within the Layer 2 VPN address family. EVPN Network Layer Reachability Information (NLRI) may be added to the EVPN address family. The EVPN NLRI can define several types of BGP EVPN routes, which carry information such as host IP addresses, MAC addresses, and VXLAN network identifiers (VNIs). After a switch 102, acting as a VTEP, learns the IP and MAC addresses of connected hosts, the VTEP can send this information to other switches (VTEPs) via BGP EVPN routes. This allows the host IP and MAC address information to be learned within the control plane of a BGP EVPN-based VXLAN. Therefore, BGP EVPN routes can be used to exchange control plane information between switches 102. This type of BGP EVPN route, which includes a MAC address-to-IP address mapping for a host device, is referred to as a BGP EVPN Type 2 route.

[0036] Furthermore, processor 152 may execute role manager 160 to create a BGP extended community field that carries a role identifier. In an example, a BGP community comprises a group of destinations that share common attributes. Information about the BGP community is included as a path attribute in a BGP update message. BGP update messages are typically used to exchange NLRIs between VTEPs in a BGP EVPN-based VXLAN. Information about the BGP community identifies community members and allows actions to be performed on the destination group. The BGP extended community field may be vendor-specific or provider-specific.

[0037] Processor 152 may execute role manager 158 to append a BGP extended community field to a route advertisement message. The route advertisement message may be a BGP EVPN Type 2 route that indicates a mapping between an Internet Protocol (IP) address of a host device and a Media Access Control (MAC) address of the host device. In an example, appending the BGP extended community field may include marking an attribute in a BGP EVPN Type 2 route shared between BGP EVPN peers in a VXLAN.

[0038] In addition, the processor 152 can execute the routing manager 160 to send a route advertisement message to another network switch. The other network switch is configured as a peer VTEP in the VXLAN. Upon receiving the route advertisement message, the other switch knows the network access policy to be implemented for the host device. The network switch and the other network switch are configured in a single virtual local area network (VLAN).

[0039] Turn again Figure 1A , host device 110 may send an authentication request message to WAP 103-1 to access network 100. Host device 110 may be a wireless host device capable of connecting to a WAP. Examples of host device 110 may include a laptop, a smartphone, a tablet computer, etc. WAP 103-1 may forward the authentication request to switch 102-1. In an example, switch 102-1 may interact with an authentication server (not shown) to process the authentication request message. The authentication request may include access credentials such as a username and password for the host device.

[0040] Based on the access credentials, an authentication server such as RADIUS can verify the identity of the host device and authorize network access for the host device. In an example, the authentication manager 156 in the switch 102-1 can include an authentication client proxy service that forwards the authentication request from the host device 110 to the authentication server (not shown). The authentication server can maintain a central database of user profiles. The authentication server matches the user credentials with the database of user profiles. If there is a match, the authentication server can check the role information associated with the user. The role information indicates the group / category of the user of the host device connected to the network, based on which the network access policy or user profile of the user is determined. The authentication server can send an authentication response message indicating that the host device 110 has been successfully authenticated. The authentication response message can include the role information of the user of the host device 110.

[0041] In response to the successful authentication of host device 110, switch 102-1 may associate the role information with the host device based on the authentication response message from the authentication server. In an example, role manager 158 of switch 102-1 may configure the data plane of switch 102-1 to forward data based on the role information of host device 110, thereby associating the role information with host device 110. The data plane (also known as the forwarding plane) may include a combination of hardware and software in the switch that carries user traffic. The data plane allows data transmission to and from clients, handles multiple sessions over multiple protocols, and manages sessions with remote peers.

[0042] Since the switch 102-1 receives the authentication response message from the authentication server, and the authentication manager 156 in the switch 102-1 includes an authentication client proxy service, the switch 102-1 learns the role information of the host device 110 when receiving the authentication response message. In an example, the role manager 158 of the switch 102-1 can create a mapping between the MAC of the host device and the role information (e.g., "guest") from the authentication response message. In an example, the role identifier is a 16-bit value indicating the role information of the host device. The role manager 158 can obtain a role identifier corresponding to the role information of the host device from a role identifier table. The role identifier table may include a mapping of role information to role identifiers. In an example, the role identifier table may be stored in the switch 102-1 and may be pre-defined by a network administrator.

[0043] In addition, the role manager 158 can create a BGP extended community field that carries the role identifier. In an example, the BGP extended community field is marked as an attribute of a route advertisement message (such as an EVPN type 2 message) that publishes the NLRI between BGP EVPN peers in the VXLAN. Figure 1C As shown in the example, the BGP extended partition is a 4-octet value that can be divided into three main parts. The first octet of the BGP extended community field encodes the type field, the second octet encodes the subtype field, and the last two octets carry a unique data set in a format defined by the type field and the subtype field.

[0044] In the example, the BGP extended community field is an opaque community field. In the example, the role manager 158 defines the type of the BGP extended community field as (0*43), indicating that the community field is an extended community, and defines the subtype of the BGP extended community field as (0*03), indicating that it is an opaque field. The opaque field indicates that members classified within the community are allowed to read the information in the community field, while non-members of the community that cannot recognize the BGP extended community field are configured to ignore the BGP extended community field and forward the packet to their next hop. In the example, the members of the community include switches manufactured by a specific original equipment manufacturer (OEM). Switches from other OEMs that forward messages received from switch 102-1 may not be able to read the extended community field, and because the BGP extended community field is opaque, such switches are configured to ignore the field and forward the packet to its next hop or destination. In the example, the BGP extended community field is a non-transitive community field, that is, the field is not applicable when it exceeds the boundary of an autonomous system (AS). Additionally, the role manager 158 of the switch 102 - 1 appends the route advertisement message to the BGP extended community field.

[0045] Routing manager 160 of switch 102-1 then sends a route advertisement message to another network switch. In this example, switch 102-1 broadcasts the route advertisement message in VLAN 120. Since switch 102-2 is part of VLAN 120, it receives the broadcasted route advertisement message, which includes the BGP extended community field carrying the role identifier. Upon receiving the route advertisement message, the other network switch knows the network access policy to be implemented for the host device.

[0046] In response to receiving the route advertisement message, switch 102-2 can create a mapping of the host media access control (MAC) address to the role based on the role identifier. This MAC address to role mapping can be stored in the switching table of switch 102-2. The switching table typically includes the MAC address of the host device and the switch port on which the MAC address is learned or statically configured. In response to receiving the route advertisement message, the MAC to role mapping can be added to the switching table of switch 102-2. The frame is forwarded by looking up the destination MAC address in the switching table. The frame is sent to the corresponding switch port.

[0047] Consider the case where host device 110 roams out of range of WAP 103-1 and transitions into range of WAP 103-2, as indicated by arrow 112. Figure 1A, host device 110, shown as a dashed line, depicts the new location of host device 110 when it roams from WAP 103-1 to WAP 103-2. In an example, a user of host device 110 may move from one floor of a building to another, which may cause host device 110 to roam from WAP 103-1 to WAP 103-2. Once host device 110 roams from WAP 103-1 to WAP 103-2, host device 110 may send a request to associate with WAP 103-2. In an example, WAP 103-2 may authenticate host device 110 and associate with it. In some other examples, host device 110 may roam using fast roaming techniques, which may allow it to immediately associate with WAP 103-2 once it leaves the range of WAP 103-1 and transitions into the range of WAP 103-2. Fast roaming (also known as IEEE 802.11r or Fast BSS Transition (FT)) allows a host device to roam very quickly in an environment that implements WPA2 Enterprise security, so that the client device does not need to re-authenticate with an authentication server (such as a RADIUS server) each time it roams from one WAP to another. In an example, in the case of fast roaming, after the host device 110 connects to the WAP 103-1, the WAP 103-1 identifies the host device 110 as a WAP for a broadcast domain (such as Figure 1A VLAN 120). When a host device roams to a new WAP, information from the original association is passed to the new WAP to provide credentials to the host device. Thus, the new WAP knows that the host device has been approved by the authentication server and does not need to repeat the entire authentication process, which enables faster / instantaneous association with the new WAP.

[0048] In response to host device 110 transitioning from WAP 103-1 to WAP 103-2 connected to switch 102-2 and becoming associated with WAP 103-2, switch 102-2 may determine that host device 110 is locally connected to switch 102-2. A host device locally connected to a switch may be understood as a host device associated with a WAP connected to the switch. In an example, switch 102-2 may scan wireless access ports of switch 102-2 and determine that host device 110 is locally connected to switch 102-2 based on the MAC address learned by WAP 103-2. In response to determining that host device 110 is locally connected to switch 102-2, switch 102-2 may compare the MAC address of host device 110 to an entry in its switching table. If a match is found, switch 102-2 may configure its data plane based on the MAC address-to-role mapping for network policy enforcement for host device 110. Therefore, in response to host device 110 transitioning from WAP 103-1 to 103-2, the network policy associated with the role information of host device 110 can be implemented in switch 102-2 because the role information of host device 110 has already been propagated to switch 102-2. Furthermore, in the example, in response to host device 110 disconnecting from WAP 103-2, switch 102-2 can clear the network policy from its data plane. Therefore, if the host device is not locally attached to switch 102-2, no hardware space in the data plane of switch 102-2 is consumed when storing the network policy.

[0049] Figure 2 1 is a flow chart illustrating a method 200 for role information propagation in a switch according to an example. The method 200 may be performed on a wired network switch, such as the switch 102-1 in the access layer A of the computing environment 100 of FIG1.

[0050] At block 202, a switch may receive an authentication request message from a host device associated with a first WAP connected to the switch. In an example, the switch is configured as a VTEP in a VXLAN over BGP EVPN. The switch may be one of a plurality of switches in an access layer of a CAN. Each of the plurality of switches may be configured to perform the method of block 202. The host device may send an authentication request to establish a connection to the network.

[0051] At block 204, the switch may forward the authentication request message to an authentication server, such as a RADIUS server. In an example, the switch may act as an authentication proxy service that forwards and receives authentication messages on behalf of the host device.

[0052] At block 206, in response to successful authentication of the host device, the switch may associate role information with the host device based on an authentication response message from the authentication server. In an example, the authentication response message from the authentication server may include the role information.

[0053] At block 208, the switch may add a role identifier in a route advertisement message of the host device based on the role information. In an example, the switch may create a BGP extended community field that carries a role identifier indicating a network policy implemented for the host device, and may append the BGP extended community field to the route advertisement message.

[0054] At block 210, the switch may send a route advertisement message to another network switch, where the other network switch is configured as a peer VTEP in a VXLAN. In this example, the network switch and the other network switch are configured in a single VLAN. Upon receiving the route advertisement message, the other network switch learns the network access policy to be implemented for the host device.

[0055] 3 is a flow chart illustrating a method 300 for role information propagation in a switch, according to an example. The method 300 may be performed on a wired switch, such as the switch 102-1 in the access layer A of the computing environment 100 of FIG.

[0056] Consider a network with multiple interconnected switches in the access layer. At block 302, the switch may receive an authentication request message from a host device associated with a first WAP connected to the switch. In an example, the switch may interact with an authentication server (not shown) to process the authentication request message. The authentication request message may include access credentials, such as a username and password for a user of the host device. At block 304, the switch forwards the authentication request to the authentication server.

[0057] Based on the access credentials, an authentication server (such as RADIUS) can verify the identity of the user of the host device and authorize network access for the user of the host device. In an example, the switch can include an authentication client proxy service that forwards authentication request messages from the host device to the authentication server. The authentication server can maintain a central database of user profiles. The authentication server matches the user credentials with the database of user profiles. If a match is found, the authentication server can check the role information associated with the user. The role information indicates the group / category of the user of the host device connected to the network, based on which the network access policy or user profile of the user is determined. The authentication server can send an authentication response message indicating that authentication of the host device was successful. At block 306, the switch can check whether the authentication was successful. Upon receiving the authentication response message from the authentication server indicating successful authentication, the switch can determine that authentication was successful ("Yes" branch from block 306). If no authentication success message is received, the switch determines that authentication has failed ("No" branch from block 306) and can continue checking for authentication requests from other host devices at block 308.

[0058] In response to successful authentication of the host device, the switch may associate the role information with the host device based on the authentication response message from the authentication server. Thus, at block 310, the switch may configure its data plane based on the role of the host device to process data to / from the host device, and thus associate the role information with the host device.

[0059] Since the switch receives the authentication response message from the authentication server, the switch knows the role information included in the authentication response message. At block 312, the switch can create a mapping between the MAC address of the host device and the role information (e.g., "Guest") from the authentication response message. In an example, the role identifier is a 16-bit value that indicates the role of the host device. At block 314, the switch can obtain a role identifier corresponding to the host device role information from a role identifier table. The role identifier table can include a mapping of role information to role identifiers. In an example, the role identifier table can be stored in the switch and can be pre-defined by a network administrator.

[0060] At block 316, the switch may create a BGP extended community field that carries the role identifier. In an example, the BGP extended community field is marked as an attribute of a route advertisement message (such as an EVPN Type 2 message) that advertises the NLRI between peer VTEPs over BGP EVPN in a VXLAN. In an example, the BGP extended community is a 4-octet value that can be divided into three main parts. The first octet of the BGP extended community field encodes the type field, the second octet encodes the subtype field, and the last two octets carry a unique data set in a format defined by the type and subtype fields.

[0061] In the example, the BGP extended community field is an opaque community field. In the example, the switch defines the type of the BGP extended community field as (0*43), indicating that the community field is an extended community, and defines the subtype of the BGP extended community field as (0*03), indicating that it is an opaque field. The opaque field indicates that members classified within the community are allowed to read the information in the community field, while non-members of the community that cannot recognize the BGP extended community field are configured to ignore the BGP extended community field and forward the packet to their next hop. In the example, the members of the community include switches manufactured by a specific original equipment manufacturer (OEM). Switches from other OEMs that forward messages received from the switch may not be able to read the extended community field, and because the BGP extended community field is opaque, such switches ignore the field and forward the packet to their next hop. An example of a BGP extended community field is in Figure 1C Then, at block 318, the switch appends the BGP extended community field to the route advertisement message.

[0062] At block 320, the switch broadcasts a route advertisement message in its broadcast domain. Thus, other switches in the same broadcast domain receive the route advertisement message with the BGP extended community field. Upon receiving the route advertisement message, the other network switches know the network access policy to be implemented for the host device.

[0063] Figure 3B The steps of the method 300 are shown as being performed by another switch that receives a route advertisement message. Figure 3BAt block 322, in response to receiving the route advertisement message, another switch in the broadcast domain creates a mapping of the host media access control (MAC) address to the role based on the role identifier. The MAC address to role mapping can be stored in the switching table of the other switch. The switching table typically includes the MAC address of the host device and the switch port on which the MAC address is learned or statically configured. In response to receiving the route advertisement message, the MAC to role mapping can be added to the switching table of switch 102-2. The frame is forwarded by looking up the destination MAC address in the switching table. The frame is sent to the corresponding switch port.

[0064] Consider a scenario where a host device roams out of range of a first WAP and transitions into range of a second WAP connected to a different switch. In an example, a user of the host device may move from one floor of a building to another, which may cause the host device to roam from the first WAP to the second WAP. Once the host device roams from the first WAP to the second WAP, the host device may send a request to associate with the second WAP. In an example, the second WAP may authenticate the host device and associate with it. In some other examples, the host device may roam using fast roaming technology and immediately associate with the second WAP once it roams out of range of the first WAP and transitions into range of the second WAP.

[0065] At block 324, the switch may scan its wireless access ports. Using the MAC address learned by the second WAP, the switch may check whether the host device's MAC address matches any MAC address learned by one of its wireless access ports. If a match exists, the switch may determine, at block 326, that the host device is locally connected to it. A host device locally connected to the switch may be understood as a host device associated with a WAP connected to the switch. At block 328, in response to determining that the host device is locally connected to the switch, the switch may compare the host device's MAC address with an entry in its switching table. At block 330, in response to a successful match, the switch may configure its data plane for network policy enforcement for the host device based on the MAC address-to-role mapping. Therefore, in response to the host device transitioning from the first WAP to the second WAP, network policies associated with the host device's role information may be implemented in other switches. This is because the host device's role information has already been propagated to the other switches along with the route advertisement message. In response to the host device roaming from the first WAP to the second WAP, the other switches may enforce the network policy of the host device based on the role information of the host device obtained as a result of the MAC address-to-role mapping created by the other switches.

[0066] Figure 4An example computing device 400 is shown having a hardware processor 401 and accessible machine-readable instructions for implementing an example system stored on a machine-readable medium 402 in accordance with one or more disclosed example implementations. In an example, the computing device 400 may be a network switch, such as the switch 102 described above with reference to FIG. 1 . Figure 4 The diagram illustrates a computing device 400 configured to execute instructions 404 to 412 described below. However, the computing device 400 may also be configured to execute other methods, techniques, functions, or process flows described in this disclosure, such as, for example, Figure 2 Method 200.

[0067] A processing element such as processor 401 may include one or more hardware processors, each of which may have a single or multiple processor cores. In one embodiment, processor 401 may include at least one shared cache that stores data (e.g., computational instructions) used by one or more other components of processor 401. For example, a shared cache may be a local cache of data stored in a memory for faster access by components making up the processing element of processor 401. In one or more embodiments, a shared cache may include one or more mid-level caches (such as level 2 (L2), level 3 (L3), level 4 (L4), or other levels of cache), a last level cache (LLC), or a combination thereof. Examples of processors include, but are not limited to, a central processing unit (CPU), a microprocessor. Although not described in Figure 4 Although described in the figure, the processing elements that make up processor 401 may also include one or more other types of hardware processing components, such as a graphics processing unit (GPU), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) and / or a digital signal processor (DSP).

[0068] The processor 401 can be operatively and communicatively coupled to the memory. The memory can be a non-transient computer-readable medium, such as a machine-readable storage medium 402 configured to store various types of data. For example, the memory can include one or more storage devices, and the one or more storage devices include non-volatile storage devices and / or volatile memory. Volatile memory such as random access memory (RAM) can be any suitable non-permanent storage device. The non-volatile storage device can include one or more disk drives, optical drives, solid-state drives (SSDs), tap drives, flash memory, read-only memory (ROM) and / or any other type of memory designed to maintain data for a period of time after power failure or shutdown operation. In some aspects, if the allocated RAM is not enough to accommodate all working data, then the non-volatile storage device can be used to store overflow data. The non-volatile storage device can also be used to store programs that are loaded into the RAM when selected for execution.

[0069] Figure 4 The machine-readable storage medium 402 may include volatile and non-volatile, removable and non-removable media, and may be any electronic, magnetic, optical, or other physical storage device that contains or stores executable instructions, data structures, program modules, or other data accessible by a processor, such as firmware, erasable programmable read-only memory (EPROM), random access memory (RAM), non-volatile random access memory (NVRAM), optical disks, solid-state drives (SSDs), flash memory chips, etc. The machine-readable storage medium may be a non-transitory storage medium, where the term “non-transitory” does not include transitory propagating signals.

[0070] The machine-readable medium 402 includes instructions 404 that, when executed by the processor 401 , cause the switch to receive an authentication request message from a host device associated with a first WAP connected to the switch. The switch is configured as a VTEP in a VXLAN based on BGP EVPN.

[0071] Instruction 406, when executed by processor 401, causes the switch to forward an authentication request message to an authentication server. In response to successful authentication of the host device, instruction 408, when executed by processor 401, causes the switch to associate role information with the host device based on an authentication response message from the authentication server. Instruction 410, when executed by processor 401, causes the switch to add a role identifier to a route advertisement message from the host device based on the role information. In an example, the switch may create a BGP extended community field that carries a role identifier indicating a network policy implemented for the host device, and append the BGP extended community field to the route advertisement message. Instruction 412, when executed by processor 401, causes the switch to send a route advertisement message to another network switch, where the other network switch is configured as a peer VTEP in a VXLAN. The switch and the other network switch are configured in a single virtual local area network (VLAN). Upon receiving the route advertisement message, the other network switch becomes aware of the network access policy to be implemented for the host device.

[0072] As used in the examples herein, a network switch or switches forwards data (in control packets) between a sender device and a receiver device (or multiple receiver devices) based on forwarding information (or equivalently, "routing information") accessible by the switch. The forwarding information may include entries that map network addresses (e.g., MAC addresses or IP addresses) and / or ports to corresponding network paths toward the receiver device(s).

[0073] A WAP is included as an example of an access point to a network (such as network 100 of FIG. 1 ). The WAP can control network access for a host device and can authenticate the host device for connection to the WAP, as well as for connection to other devices within the network through the WAP. Each of the WAPs can be a combination of hardware, software, and / or firmware configured to provide wireless network connectivity to a wireless host device. In the example shown, the WAP can be managed and configured by a controller. The WAP communicates with the controller and the network via a connection that can be a wired interface or a wireless interface.

[0074] Certain terms are used throughout the specification and claims to refer to specific system components. As will be understood by those skilled in the art, different parties may refer to components by different names. This disclosure is not intended to distinguish between components that have different names but the same function. In this disclosure and the claims, the terms "including" and "comprising" are used in an open-ended manner and should, therefore, be interpreted to mean "including but not limited to." Additionally, the terms "couple" or "coupled" are intended to mean an indirect or direct wired or wireless connection. Thus, if a first device is coupled to a second device, that connection may be through a direct connection or through an indirect connection via other devices and connections. The expression "based on" is intended to mean "based at least in part on." Thus, if X is based on Y, then X can be a function of Y and any number of other factors.

[0075] The above discussion is intended to illustrate the principles and various implementations of the present disclosure. Once the above disclosure is fully understood, many changes and modifications will become apparent to those skilled in the art. The appended claims are intended to be interpreted as including all such changes and modifications.

Claims

1. A network switch, comprising: processor; as well as a non-transitory computer-readable medium comprising instructions that, when executed by the processor, cause the network switch to: receiving an authentication request message from a host device associated with a first wireless access point (WAP) connected to the network switch, wherein the network switch is configured as a VXLAN tunnel endpoint (VTEP) in a Virtual Extensible Local Area Network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN); Forwarding the authentication request message to an authentication server; in response to receiving an authentication response message from the authentication server, associating role information with the host device based on the authentication response message, wherein the role information indicates a group or category of a user of the host device; Adding a role identifier to a route advertisement message of the host device based on the role information, wherein the route advertisement message indicates a mapping between an Internet Protocol (IP) address of the host device and a Media Access Control (MAC) address of the host device, wherein to add the role identifier, the network switch is to: creating a BGP extended community field, the BGP extended community field carrying the role identifier indicating a network access policy to be implemented for the host device; and Appending the BGP extended community field to the routing advertisement message; as well as The route advertisement message is sent to another network switch, wherein the other network switch is configured as a peer VTEP in the VXLAN, and the network switch and the other network switch are configured in a single virtual local area network (VLAN), and wherein upon receiving the route advertisement message, the other network switch knows the network access policy to be implemented for the host device. 2 . The network switch according to claim 1 , wherein the BGP extended community field is an opaque community field. 3 . The network switch of claim 1 , wherein the BGP extended community field is a non-transitive community field. The network switch of claim 1 , wherein the route advertisement message is a BGP EVPN Type 2 route.

5. The network switch of claim 1, wherein the BGP extended community field comprises four octets. 6 . The network switch of claim 1 , wherein the role identifier is a 16-bit value starting from the least significant bit of the BGP extended community field.

7. The network switch according to claim 1, wherein the BGP extended community field comprises: Type information, indicating that the BGP extended community field is a non-transitive opaque extended community; as well as The subtype information indicates that the BGP extended community field carries the role identifier.

8. The network switch of claim 1, wherein the network switch is an access switch at a customer edge.

9. A method for network switching, comprising: Receiving, by a network switch, an authentication request message from a host device associated with a first wireless access point (WAP) connected to the network switch, wherein the network switch is configured as a VXLAN tunnel endpoint (VTEP) in a virtual extensible local area network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet virtual private network (EVPN); Forwarding the authentication request message to the authentication server by the network switch; In response to successful authentication of the host device, associating, by the network switch, role information with the host device based on an authentication response message from the authentication server, wherein the role information indicates a group or category of a user of the host device; Adding, by the network switch, a role identifier in a route advertisement message of the host device based on the role information, wherein the route advertisement message indicates a mapping between an Internet Protocol (IP) address of the host device and a Media Access Control (MAC) address of the host device, wherein adding the role identifier comprises: creating a BGP extended community field, the BGP extended community field carrying the role identifier indicating the network policy to be implemented for the host device; and Appending the BGP extended community field to the route advertisement message; and The network switch sends the route advertisement message to another network switch, wherein the other network switch is configured as a peer VTEP in the VXLAN, the network switch and the other network switch are configured in a single virtual local area network (VLAN), and upon receiving the route advertisement message, the other network switch knows the network access policy to be implemented for the host device.

10. The method according to claim 9, wherein the BGP extended community field is an opaque community field. The method of claim 9 , wherein the BGP extended community field is a non-transitive community field.

12. The method of claim 9, wherein the route advertisement message is a BGP EVPN Type 2 route.

13. The method of claim 9, wherein the BGP extended community field comprises four octets.

14. The method according to claim 9, wherein the BGP extended community field comprises: Type information, indicating that the BGP extended community field is a non-transitive opaque extended community; as well as The subtype information indicates that the BGP extended community field carries the role identifier.

15. The method of claim 9, wherein the network switch is an access switch at a customer edge.

16. The method of claim 9, further comprising creating, by the other network switch, a host media access control (MAC) address to role mapping based on the role identifier obtained from the route advertisement message, the route advertisement message being received from the network switch.

17. The method of claim 16 , further comprising, in response to the host device roaming from the first WAP to a second WAP connected to the another network switch, enforcing, by the another network switch and as a result of the creating the MAC address-to-role mapping, a network policy of the host device based on the role of the host device.

18. The method of claim 16, further comprising configuring, by the other network switch, a data plane for network policy enforcement for the host device based on the MAC address-to-role mapping in response to the host device roaming from the first WAP to a second WAP connected to the other network switch.

19. A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause a network switch to: receiving an authentication request message from a host device associated with a first wireless access point (WAP) connected to the network switch, wherein the network switch is configured as a VXLAN tunnel endpoint (VTEP) in a Virtual Extensible Local Area Network (VXLAN) based on a Border Gateway Protocol (BGP) Ethernet Virtual Private Network (EVPN); Forwarding the authentication request message to an authentication server; In response to successful authentication of the host device, associating role information with the host device based on an authentication response message from the authentication server, wherein the role information indicates a group or category of a user of the host device; Adding a role identifier to a route advertisement message of the host device based on the role information, wherein the route advertisement message indicates a mapping between an Internet Protocol (IP) address of the host device and a Media Access Control (MAC) address of the host device, wherein to add the role identifier, the network switch is to: creating a BGP extended community field, the BGP extended community field carrying the role identifier indicating the network policy to be implemented for the host device; and Appending the BGP extended community field to the routing advertisement message; as well as The route advertisement message is sent to another network switch, wherein the other network switch is configured as a peer VTEP in the VXLAN, the network switch and the other network switch are configured in a single virtual local area network (VLAN), and wherein upon receiving the route advertisement message, the other network switch knows the network access policy to be implemented for the host device.

20. The non-transitory computer-readable medium of claim 19, wherein the BGP extended community field is an opaque and non-transitive community field.

Citation Information

Patent Citations

  • Security in software defined network

    CN106464659A

  • MAC address synchronization method and VTEP

    CN107911495A