Security entry maintenance method, device, network equipment and storage medium

By deleting remote MAC-IP entries when the protocol connection is interrupted, the resource waste and security issues caused by the interruption of the connection between the access device and the aggregation device are resolved, and the protection of legitimate packets and the blocking of illegal packets are achieved.

CN119325697BActive Publication Date: 2025-10-28NEW H3C TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380009125.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-17
Publication Date
2025-10-28
Estimated Expiration
2043-05-17

AI Technical Summary

Technical Problem

When the protocol connection between the access device and the aggregation device is interrupted, the existing technology cannot effectively manage MAC-IP entries, resulting in legitimate packets being dropped or illegal packets entering the network, and wasting resources.

Method used

By obtaining the valid lifetime value of the remote MAC-IP entry when the protocol connection is interrupted, and deleting the entry after the connection interruption continues until the lifetime value is reached, resource consumption and the discarding of legitimate packets are avoided.

Benefits of technology

Effective management of MAC-IP entries prevents legitimate packets from being dropped and illegal packets from entering, saving resources and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119325697B_ABST
    Figure CN119325697B_ABST
Patent Text Reader

Abstract

This application provides a security entry maintenance method, apparatus, network device, and storage medium, relating to the field of communication technology. The method includes: when a protocol connection with a second network device is interrupted, obtaining the valid lifetime value of each remote MAC-IP entry, whereby the valid lifetime value indicates the valid lifetime of the IP address included in the remote MAC-IP entry; if the duration of the protocol connection interruption reaches the valid lifetime value, deleting at least one remote MAC-IP entry. This avoids unauthorized packets entering the network and resource waste, thus improving network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, network device, and storage medium for maintaining security entries. Background Technology

[0002] To improve network security, a source address security check mechanism can be deployed on the access device. The access device can perform a validity check on the received packets based on the Media Access Control address-Internet Protocol address (MAC-IP) table entries, thereby preventing illegal packets from passing through.

[0003] After generating a MAC-IP entry for a terminal, access device 1 can advertise the MAC-IP entry to the aggregation device via a protocol connection. The aggregation device then advertises the MAC-IP entry to other access devices. Thus, when a terminal moves from an access point (AP) connected to access device 1 to an AP connected to access device 2, access device 2 can perform a legitimacy check on the terminal based on the MAC-IP entry.

[0004] If access device 2 is connected to only one aggregation device, and the protocol connection between access device 2 and the aggregation device is interrupted, access device 2 can delete the MAC-IP entry from that protocol connection. In this case, if the energy address security check mechanism is enabled, access device 2 cannot perform a validity check based on the MAC-IP entry, resulting in the dropping of legitimate packets; if the energy address security check mechanism is not enabled, illegitimate packets can also enter the network, leading to a reduction in network security.

[0005] If access device 2 does not delete the MAC-IP entry from this protocol connection, and if the subsequent protocol connection is not restored, the MAC-IP entry will occupy hardware resources for a long time, resulting in resource waste. Therefore, how to maintain the MAC-IP entry in the event of a protocol connection interruption is an urgent problem to be solved. Summary of the Invention

[0006] The purpose of this application is to provide a method, apparatus, network device, and storage medium for maintaining security entries, which can avoid resource waste and the discarding of legitimate packets. The specific technical solution is as follows:

[0007] In a first aspect, embodiments of this application provide a security entry maintenance method applied to a first network device, the first network device including a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by a second network device, the method comprising:

[0008] When the protocol connection with the second network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry;

[0009] If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

[0010] In one possible implementation, the method further includes:

[0011] When the first network device generates a DHCP relay entry, it establishes a local MAC-IP entry based on the DHCP relay entry and sends the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address.

[0012] Send a first MAC-IP advertisement message to a third network device so that the third network device establishes a first remote MAC-IP entry;

[0013] The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value.

[0014] The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0015] In one possible implementation, after issuing the forwarded MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources, the method further includes:

[0016] When the access entry that matches the local MAC-IP entry is deleted, the forwarding MAC-IP entry is deleted.

[0017] In one possible implementation, before obtaining the valid lifetime value included in each remote MAC-IP entry when the protocol connection with the second network device is interrupted, the method further includes:

[0018] The system receives a second MAC-IP advertisement message sent by the second network device. The second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number.

[0019] Create a second remote MAC-IP entry, which includes the second valid lifetime value and the second sequence number.

[0020] In one possible implementation, the first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry;

[0021] After establishing the second remote MAC-IP entry, the method further includes:

[0022] The receiving terminal sends a first message, the first message including the terminal's MAC address and IP address;

[0023] If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, then an access probe is performed on the terminal.

[0024] If an access response is received from the terminal, a composite MAC-IP entry is generated, which includes the terminal's MAC address and IP address, port identifier, and VLAN identifier.

[0025] A forwarding MAC-IP entry is generated based on the synthesized MAC-IP entry, and the forwarding MAC-IP entry includes the MAC address and IP address of the terminal;

[0026] The forwarding MAC-IP entries are distributed to the hardware resources.

[0027] In one possible implementation, after the forwarding MAC-IP entry is sent to the hardware resources, the method further includes:

[0028] When the terminal access entry is deleted, the composite MAC-IP entry and the forwarding MAC-IP entry are also deleted.

[0029] In one possible implementation, the first network device includes a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry, the first local MAC-IP entry including a third sequence number; after establishing the second remote MAC-IP entry, the method further includes:

[0030] If the second remote MAC-IP entry matches the first local MAC-IP entry, and the second sequence number is greater than the third sequence number, then the first local MAC-IP entry is deleted, and the DHCP relay entry corresponding to the first local MAC-IP entry is also deleted.

[0031] In one possible implementation, the MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0032] In one possible implementation, the MAC-IP advertisement message sent by the first network device further includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0033] Secondly, embodiments of this application provide a security entry maintenance method applied to a second network device, the second network device including a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry advertised by a fourth network device, the method including:

[0034] When the protocol connection with the fourth network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry;

[0035] If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

[0036] In one possible implementation, before obtaining the valid lifetime value included in each remote MAC-IP entry when the protocol connection with the fourth network device is interrupted, the method further includes:

[0037] The system receives a first MAC-IP announcement message sent by the fourth network device. The first MAC-IP announcement message includes a first valid lifetime value of the first IP address and a first sequence number.

[0038] A first remote MAC-IP entry is established, which includes the first valid lifetime value and the first sequence number.

[0039] In one possible implementation, the second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; after establishing the first remote MAC-IP entry, the method further includes:

[0040] If the first sequence number is greater than the second sequence number, a second MAC-IP announcement message is sent to other network devices besides the fourth network device. The second MAC-IP announcement message includes the first valid lifetime value and the first sequence number.

[0041] In one possible implementation, the second remote device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; after deleting the at least one remote MAC-IP entry, the method further includes:

[0042] For each deleted remote MAC-IP entry, if no matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to all network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address from the remote MAC-IP entry; or...

[0043] For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP announcement message is sent to all network devices except the fifth network device. The third MAC-IP announcement message includes the second valid lifetime value and the third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

[0044] In one possible implementation, the MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0045] In one possible implementation, the MAC-IP advertisement message sent by the second network device further includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0046] Thirdly, embodiments of this application provide a security entry maintenance device applied to a first network device, the first network device including a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by a second network device, the device comprising:

[0047] The acquisition module is configured to acquire the valid lifetime value of each remote MAC-IP entry when the protocol connection with the second network device is interrupted. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0048] The deletion module is used to delete at least one remote MAC-IP entry if the duration of the interruption of the protocol connection reaches the effective lifecycle value.

[0049] In one possible implementation, the device further includes:

[0050] The module is configured to establish a local MAC-IP entry based on the DHCP relay entry when the first network device generates a DHCP relay entry, and to issue the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address.

[0051] The sending module is used to send a first MAC-IP announcement message to a third network device so that the third network device can establish a first remote MAC-IP entry.

[0052] The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value.

[0053] The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0054] In one possible implementation, the deletion module is further configured to delete the forwarding MAC-IP entry when the access entry matching the local MAC-IP entry is deleted.

[0055] In one possible implementation, the device further includes:

[0056] The receiving module is configured to receive a second MAC-IP advertisement message sent by the second network device, wherein the second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number;

[0057] A module is established to create a second remote MAC-IP entry, which includes the second valid lifetime value and the second sequence number.

[0058] In one possible implementation, the first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry;

[0059] The device further includes: a detection module, a generation module, and a transmission module;

[0060] The receiving module is further configured to receive a first message sent by the terminal, the first message including the MAC address and IP address of the terminal;

[0061] The detection module is used to perform access detection on the terminal if there is no local MAC-IP table entry that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP table entry.

[0062] The generation module is used to generate a composite MAC-IP entry if it receives an access response from the terminal. The composite MAC-IP entry includes the MAC address and IP address of the terminal, port identifier, and VLAN identifier.

[0063] The generation module is further configured to generate forwarding MAC-IP entries based on the synthesized MAC-IP entries, wherein the forwarding MAC-IP entries include the MAC address and IP address of the terminal;

[0064] The distribution module is used to distribute the forwarding MAC-IP entries to hardware resources.

[0065] In one possible implementation, the deletion module is further configured to delete the composite MAC-IP entry and the forwarding MAC-IP entry when the access entry of the terminal is deleted.

[0066] In one possible implementation, the first network device includes a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry, the first local MAC-IP entry including a third sequence number;

[0067] The deletion module is further configured to delete the first local MAC-IP entry and the corresponding DHCP relay entry if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number.

[0068] In one possible implementation, the MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0069] In one possible implementation, the MAC-IP advertisement message sent by the first network device further includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0070] Fourthly, embodiments of this application provide a security entry maintenance device applied to a second network device, the second network device including a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry announced by a fourth network device, the device comprising:

[0071] The acquisition module is configured to acquire the valid lifetime value of each remote MAC-IP entry when the protocol connection with the fourth network device is interrupted. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0072] The deletion module is used to delete at least one remote MAC-IP entry if the duration of the interruption of the protocol connection reaches the effective lifecycle value.

[0073] In one possible implementation, the device further includes:

[0074] The receiving module is configured to receive a first MAC-IP announcement message sent by the fourth network device, wherein the first MAC-IP announcement message includes a first valid lifetime value of a first IP address and a first sequence number;

[0075] A module is established to create a first remote MAC-IP entry, which includes the first valid lifetime value and the first sequence number.

[0076] In one possible implementation, the second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; the device further includes:

[0077] The sending module is configured to send a second MAC-IP announcement message to network devices other than the fourth network device if the first sequence number is greater than the second sequence number. The second MAC-IP announcement message includes the first valid lifetime value and the first sequence number.

[0078] In one possible implementation, the second remote device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; the device further includes a transmission module;

[0079] The sending module is used for:

[0080] For each deleted remote MAC-IP entry, if no matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to all network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address from the remote MAC-IP entry; or...

[0081] For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP announcement message is sent to all network devices except the fifth network device. The third MAC-IP announcement message includes the second valid lifetime value and the third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

[0082] In one possible implementation, the MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0083] In one possible implementation, the MAC-IP advertisement message sent by the second network device further includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0084] Fifthly, embodiments of this application provide a first network device, the first network device including a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by a second network device; the first network device includes:

[0085] processor;

[0086] transceiver;

[0087] A machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the machine-executable instructions cause the processor to perform the following steps:

[0088] When the protocol connection with the second network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry;

[0089] If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

[0090] In one possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0091] When the first network device generates a DHCP relay entry, it establishes a local MAC-IP entry based on the DHCP relay entry and sends the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address.

[0092] The transceiver sends a first MAC-IP advertisement message to the third network device, so that the third network device can establish a first remote MAC-IP entry.

[0093] The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value.

[0094] The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0095] In one possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0096] When the access entry that matches the local MAC-IP entry is deleted, the forwarding MAC-IP entry is deleted.

[0097] In one possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0098] The transceiver receives a second MAC-IP advertisement message sent by the second network device. The second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number.

[0099] Create a second remote MAC-IP entry, which includes the second valid lifetime value and the second sequence number.

[0100] In one possible implementation, the first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry;

[0101] The machine-executable instructions also cause the processor to perform the following steps:

[0102] The transceiver receives a first message sent by the terminal, the first message including the terminal's MAC address and IP address;

[0103] If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, then an access probe is performed on the terminal.

[0104] If an access response is received from the terminal, a composite MAC-IP entry is generated, which includes the terminal's MAC address and IP address, port identifier, and VLAN identifier.

[0105] A forwarding MAC-IP entry is generated based on the synthesized MAC-IP entry, and the forwarding MAC-IP entry includes the MAC address and IP address of the terminal;

[0106] The forwarding MAC-IP entries are distributed to the hardware resources.

[0107] In one possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0108] When the access entry of the terminal is deleted, the composite MAC-IP entry and the forwarding MAC-IP entry are also deleted.

[0109] In one possible implementation, the first network device includes a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry, the first local MAC-IP entry including a third serial number; the machine-executable instructions further cause the processor to perform the following steps:

[0110] If the second remote MAC-IP entry matches the first local MAC-IP entry, and the second sequence number is greater than the third sequence number, then the first local MAC-IP entry is deleted, and the DHCP relay entry corresponding to the first local MAC-IP entry is also deleted.

[0111] In one possible implementation, the MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0112] In one possible implementation, the MAC-IP advertisement message sent by the first network device further includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0113] Sixthly, embodiments of this application provide a second network device, the second network device including a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry advertised by a fourth network device, the second network device including:

[0114] processor;

[0115] transceiver;

[0116] A machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the machine-executable instructions cause the processor to perform the following steps:

[0117] When the protocol connection with the fourth network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry;

[0118] If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

[0119] In one possible implementation, the machine-executable instructions further cause the processor to perform the following steps:

[0120] The transceiver receives a first MAC-IP announcement message sent by the fourth network device. The first MAC-IP announcement message includes a first valid lifetime value of a first IP address and a first sequence number.

[0121] A first remote MAC-IP entry is established, which includes the first valid lifetime value and the first sequence number.

[0122] In one possible implementation, the second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry that matches a first remote MAC-IP entry, the second remote MAC-IP entry including a second serial number; the machine-executable instructions cause the processor to perform the following steps:

[0123] If the first sequence number is greater than the second sequence number, a second MAC-IP announcement message is sent to other network devices besides the fourth network device. The second MAC-IP announcement message includes the first valid lifetime value and the first sequence number.

[0124] In one possible implementation, the second remote device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; the machine-executable instructions cause the processor to perform the following steps:

[0125] For each deleted remote MAC-IP entry, if no matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to all network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address from the remote MAC-IP entry; or...

[0126] For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP announcement message is sent to all network devices except the fifth network device. The third MAC-IP announcement message includes the second valid lifetime value and the third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

[0127] In one possible implementation, the MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0128] In one possible implementation, the MAC-IP advertisement message sent by the second network device further includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0129] In a seventh aspect, embodiments of this application provide a machine-readable storage medium storing machine-executable instructions, which, when invoked and executed by a processor, cause the processor to implement the method described in the first or second aspect.

[0130] Eighthly, embodiments of this application provide a computer program product that causes the processor to implement the method described in the first or second aspect.

[0131] Using the above technical solution, the remote MAC-IP entry in the first network device includes a validity lifetime value, which indicates the validity lifetime of the IP address included in the remote MAC-IP entry. If the duration of the protocol connection interruption reaches the validity lifetime value, it indicates that the IP address included in the MAC-IP entry is invalid. That is, the terminal that originally obtained the IP address can no longer use it. Deleting the remote MAC-IP entry at this time will not affect the subsequent verification of the terminal's legitimacy, will not affect network security, and can prevent the remote MAC-IP entry from continuing to occupy the resources of the first network device. Before the duration of the protocol connection interruption reaches the validity lifetime value, the first network device will not delete the remote MAC-IP entry. Therefore, even with the power address security check mechanism in place, legitimate packets matching the remote MAC-IP entry will not be discarded, and illegal packets can be prevented from entering the network, thus improving network security. Attached Figure Description

[0132] The accompanying drawings, which are provided to further understand this application and constitute a part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application.

[0133] Figure 1 A schematic diagram of a Spine-Leaf networking system structure is provided for an embodiment of this application;

[0134] Figure 2 A flowchart illustrating a security entry maintenance method provided in this application embodiment;

[0135] Figure 3 An exemplary schematic diagram of a MAC-IP NLRI format provided for embodiments of this application;

[0136] Figure 4 An exemplary schematic diagram illustrating a Route Type format provided in an embodiment of this application;

[0137] Figure 5 An exemplary schematic diagram of a first extended community attribute format provided for an embodiment of this application;

[0138] Figure 6 An exemplary schematic diagram of a second extended community attribute format provided for an embodiment of this application;

[0139] Figure 7 A flowchart illustrating another security entry maintenance method provided in this application embodiment;

[0140] Figure 8 This application provides another schematic diagram of a Spine-Leaf networking system architecture.

[0141] Figure 9 A schematic diagram of another Spine-Leaf networking system structure provided in this application embodiment;

[0142] Figure 10 A schematic diagram of another Spine-Leaf networking system structure provided in this application embodiment;

[0143] Figure 11 A schematic diagram of a safety entry maintenance device provided in this application embodiment;

[0144] Figure 12 A schematic diagram of another safety entry maintenance device provided in this application embodiment;

[0145] Figure 13 This is a schematic diagram of the structure of a first network device provided in an embodiment of this application;

[0146] Figure 14 This is a schematic diagram of the structure of a second network device provided in an embodiment of this application. Detailed Implementation

[0147] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this invention are within the scope of protection of this invention.

[0148] The networking system used in this application embodiment can be a spine-leaf network, such as... Figure 1 As shown, the network system includes two levels of aggregation devices, where Spine3 is the upstream aggregation device of Spine1 in region 1 and Spine2 in region 2.

[0149] Spine3 connects to a Dynamic Host Configuration Protocol Version 6 (DHCPv6) server and an Access Controller (AC). The DHCPv6 server is used to assign Internet Protocol Version 6 (IPv6) addresses to terminals.

[0150] Spine1 is located in Zone 1, which also includes three access devices: Leaf1, Leaf2, and Leaf3. Leaf1, Leaf2, and Leaf3 are all connected to Spine1.

[0151] AP1 is connected to Leaf1, AP2 is connected to Leaf2, and AP3 is connected to Leaf3. The terminal can communicate with the APs. Figure 1 The example shown is a terminal accessing AP1.

[0152] It should be noted that Figure 1 The number of devices shown is for illustrative purposes only; in actual implementation, Figure 1 The number of devices in the system is not limited to this.

[0153] The access device is equipped with a security inspection mechanism, which includes a control plane inspection mechanism and a data plane inspection mechanism.

[0154] The control plane inspection mechanism refers to the legality check of received protocol messages. For example, it filters the Media Access Control (MAC) address and Internet Protocol (IP) address of the sender of Neighbor Discovery (ND) and Address Resolution Protocol (ARP) probe messages to prevent the generation of illegal ND and ARP entries.

[0155] The data plane inspection mechanism refers to filtering and controlling the source MAC address and source IP address of received service packets to prevent illegal service packets from passing through.

[0156] Both the control plane inspection mechanism and the data plane inspection mechanism rely on pre-generated MAC-IP entries. Currently, the methods for dynamically generating MAC-IP entries include: generating MAC-IP entries based on Dynamic Host Configuration Protocol (DHCP) relay entries and generating MAC-IP entries through DHCP snooping. This application does not limit the method by which the access device generates local security entries.

[0157] It should be noted that if a user sets an IP address for a terminal without authorization, the access device will not generate a MAC-IP entry, and the access device will discard packets from that terminal.

[0158] The IP address in this application embodiment can be an Internet Protocol Version 4 (IPv4) address or an IPv6 address.

[0159] This application provides a method for maintaining security entries. This method is applied to a first network device, which can be an access device, such as a Leaf device in a Spine-Leaf architecture. The first network device includes a remote MAC-IP table, which includes at least one remote MAC-IP entry advertised by a second network device. Figure 2 As shown, the method includes:

[0160] S201. When the protocol connection with the second network device is interrupted, obtain the valid lifetime value included in each remote MAC-IP entry.

[0161] The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0162] The second network device can be an aggregation device. Figure 1 Taking the network system shown as an example, the first network device can be Figure 1 The first network device can be Leaf1, Leaf2, or Leaf3, and the second network device can be Spine1. The protocol connection between the first and second network devices can be a Border Gateway Protocol (BGP) connection; or the protocol connection between the first and second network devices can be a custom private protocol connection. In the case of a private protocol connection, each network device advertises MAC-IP entries through the private protocol.

[0163] S202. If the duration of the protocol connection interruption reaches the effective lifecycle value, delete at least one remote MAC-IP entry.

[0164] Understandably, when the remote MAC-IP table includes a MAC-IP entry, the first network device can obtain the valid lifetime value included in that MAC-IP entry. The first network device saves the valid lifetime value of the remote MAC-IP entry starting from the moment it detects a protocol connection interruption. That is, after detecting a protocol connection interruption, the first network device maintains the valid lifetime value of the remote MAC-IP entry and will not delete it until the valid lifetime value is reached.

[0165] If the protocol connection is not restored after the effective lifetime value has been reached from the start time, the remote MAC-IP entry will be deleted.

[0166] For example, if the effective lifetime value is 100,000 seconds, the first network device will start timing after detecting a protocol connection interruption and retain the remote MAC-IP entry for 100,000 seconds. If the protocol connection is not restored after 100,000 seconds, the first network device will delete the remote MAC-IP entry.

[0167] When the remote MAC-IP table includes multiple MAC-IP entries, the first network device can obtain the valid lifetime values ​​of multiple remote MAC-IP entries.

[0168] In one implementation, after the duration of the protocol connection interruption reaches all the acquired valid lifetime values, that is, after the duration of the protocol connection interruption reaches the maximum lifetime value among the acquired valid lifetime values, the remote MAC-IP table, including multiple MAC-IP entries, is deleted all at once.

[0169] In another implementation, for each valid lifetime value, if the duration of the protocol connection interruption reaches that valid lifetime value, the MAC-IP entry to which that valid lifetime value belongs is deleted.

[0170] Using the above method, the remote MAC-IP entry in the first network device includes a validity lifetime value, which indicates the validity lifetime of the IP address included in the remote MAC-IP entry. If the duration of the protocol connection interruption reaches the validity lifetime value, it indicates that the IP address included in the MAC-IP entry is invalid. That is, the terminal that originally obtained the IP address can no longer use it. Deleting the remote MAC-IP entry at this time will not affect the subsequent legitimacy verification of the terminal, will not affect network security, and can prevent the remote MAC-IP entry from continuing to occupy the resources of the first network device. Before the duration of the protocol connection interruption reaches the validity lifetime value, the first network device will not delete the remote MAC-IP entry. Therefore, even with the power address security check mechanism enabled, legitimate packets matching the remote MAC-IP entry will not be discarded, and illegal packets can be prevented from entering the network, thus improving network security.

[0171] The following explanation uses specific examples to illustrate this point. Figure 1 Taking Leaf1 as the first network device and Spine1 as the second network device as an example, Leaf1 receives MAC-IP entry 1 and MAC-IP entry 2 advertised by Spine1 and saves them as remote MAC-IP entry 1 and remote MAC-IP entry 2. Assume the validity period of the IP address in remote MAC-IP entry 1 is 90,000 seconds, and the validity period of the IP address in remote MAC-IP entry 2 is 100,000 seconds.

[0172] In one implementation, if Leaf1 detects an interruption in the protocol connection with Spine1, Leaf1 retains Remote MAC-IP entry 1 and Remote MAC-IP entry 2 for 100,000 seconds, starting from the moment the interruption was detected. If the protocol connection between Leaf1 and Spine1 is not restored after 100,000 seconds, Leaf1 deletes Remote MAC-IP entry 1 and Remote MAC-IP entry 2.

[0173] In this way, the first network device can delete multiple remote MAC-IP entries at once, avoiding resource waste without affecting network security, and saving the processing overhead of the first network device in the process of deleting remote entries.

[0174] In another embodiment, taking leaf1 as an example that includes the aforementioned remote MAC-IP entry 1 and remote MAC-IP entry 2, if leaf1 detects an interruption in the protocol connection with Spine1, leaf1 will retain remote MAC-IP entry 1 for 90,000 seconds, starting from the moment the interruption is detected. If the protocol connection is not restored after 90,000 seconds, remote MAC-IP entry 1 will be deleted. Leaf1 will retain remote MAC-IP entry 2 for 100,000 seconds, starting from the moment the interruption is detected. If the protocol connection is still not restored after 100,000 seconds, remote MAC-IP entry 2 will be deleted.

[0175] In this way, each expired remote MAC-IP entry can be deleted in a timely and accurate manner, avoiding the consumption of resources by expired remote MAC-IP entries without affecting network security.

[0176] The first network device in this embodiment can also generate a local MAC-IP entry and advertise the local MAC-IP entry to other network devices. This process specifically includes:

[0177] When the first network device generates a DHCP relay entry, it establishes a local MAC-IP entry based on the DHCP relay entry and sends the corresponding forwarding MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address.

[0178] In this embodiment, the first network device can act as a DHCP relay device. After requesting an IP address from the DHCP server for the terminal, the DHCP relay device can obtain the first IP address assigned to the terminal by the DHCP server, as well as the preferred lifetime value and effective lifetime value of the first IP address. In this embodiment, the first network device can add the first effective lifetime value of the first IP address to a local MAC-IP table entry. Optionally, it can also add the preferred lifetime value of the first IP address to a local MAC-IP table entry.

[0179] Taking an IPv6 network as an example, the local MAC-IP entry must include at least the fields shown in Table 1:

[0180] Table 1

[0181]

[0182] The local MAC-IP entry is the same as the control MAC-IP entry. The control MAC-IP entry is maintained by the network device's software and can be stored in the network device's memory. The control plane can perform validity checks on control plane protocol messages based on the control MAC-IP entries, such as checking the validity of ND messages.

[0183] The forwarding MAC-IP entries corresponding to the local MAC-IP entries include the aforementioned MAC address and IPv6 address fields. These entries are stored in the hardware resources of the hardware forwarding chip and consume MAC-IP entry resources within the chip. They are used to perform validity checks on service packets in the forwarding plane. The MAC-IP entry resources in the hardware forwarding chip are relatively scarce.

[0184] After the first network device generates the aforementioned local MAC-IP entry, it can send a first MAC-IP announcement message to the third network device, so that the third network device can establish a first remote MAC-IP entry.

[0185] The first MAC-IP advertisement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry also includes a first sequence number and a first valid lifetime value. The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0186] Understandably, the first MAC-IP advertisement message also includes the MAC address and the first IP address in the local MAC-IP table entry, and correspondingly, the first remote MAC-IP table entry also includes the MAC address and the first IP address.

[0187] The third network device is an aggregation device. The third network device and the second network device can be the same aggregation device or different aggregation devices.

[0188] A remote MAC-IP entry that matches a local MAC-IP entry refers to a remote MAC-IP entry that has the same MAC address and IP address as the local MAC-IP entry. If the first network device stores a remote MAC-IP entry that matches a local MAC-IP entry, it indicates that the terminal was migrated from another access device. Each remote MAC-IP entry includes a sequence number. The larger the sequence number carried in the remote MAC-IP entry, the later the remote MAC-IP entry was generated.

[0189] Taking an IPv6 network as an example, the first MAC-IP advertisement message may include the fields shown in Table 2:

[0190] Table 2

[0191]

[0192] Based on the above embodiments, the first network device may delete ARP entries or ND entries. For example, in an IPv6 scenario, some terminals, when in a locked state, may not respond to ND entry aging probe messages initiated by the first network device, causing the ND entry corresponding to that terminal in the first network device to be aged out and deleted. Alternatively, if the access device detects that the terminal's access interface is disconnected, the access device can delete the ND entries of terminals that came online from that access interface.

[0193] After the first network device issues the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources, the forwarding MAC-IP entry is deleted when the access entry matching the local MAC-IP entry is deleted.

[0194] The access entry is either an ND entry or an ARP entry.

[0195] In this embodiment, deleting the forwarding MAC-IP entry from the hardware resources saves hardware resources. Furthermore, since the local MAC-IP entry stored in memory is not deleted at this time, if the terminal accesses the network again and learns its access entry again, it can re-issue the forwarding MAC-IP entry to the hardware resources based on the local MAC-IP entry. This prevents legitimate packets from being discarded due to the deletion of the forwarding MAC-IP entry, thus improving network security.

[0196] Furthermore, the deletion of an ND or ARP entry does not mean that the IP address lease requested by the terminal has expired. Therefore, deleting an ND or ARP entry will not delete the corresponding DHCP relay entry for that terminal.

[0197] In this embodiment, the first network device may also receive MAC-IP entries advertised by other network devices. Therefore, before obtaining the valid lifetime value of each remote MAC-IP entry in S201 when the protocol connection with the second network device is interrupted, the method further includes:

[0198] The system receives a second MAC-IP advertisement message from a second network device and establishes a second remote MAC-IP entry. The second MAC-IP advertisement message includes the second valid lifetime value and the second sequence number of the second IP address; the second remote entry also includes the second valid lifetime value and the second sequence number of the second IP address. It is understood that the second MAC-IP advertisement message also includes the MAC address and the second IP address. Correspondingly, the second remote MAC-IP entry also includes the MAC address and the second IP address.

[0199] Optionally, the second MAC-IP advertisement message may also include the preferred lifetime value of the second IP address, and correspondingly, the remote MAC-IP entry also includes the preferred lifetime value of the second IP address.

[0200] Understandably, the second network device will advertise MAC-IP entries received from other network devices (excluding the first network device) to the first network device. This allows the first network device to use the second remote MAC-IP entries to perform validity checks on the terminal's packets after a terminal migrates from other access devices to the first network device, rejecting unauthorized packets and improving network security. Furthermore, since the second MAC-IP advertisement message includes a second sequence number, if a terminal subsequently migrates to the first network device, the first network device can determine the terminal's migration status based on the sequence number.

[0201] The first network device can store the second remote MAC-IP entry in memory. In this case, the second remote MAC-IP entry does not occupy the control MAC-IP entry resources in memory. That is, the first network device can utilize free memory resources other than the control MAC-IP entry resources to store the second remote MAC-IP entry, and the remote MAC-IP entry does not occupy hardware resources. The first network device can maintain a remote MAC-IP entry for the second network device, and the second remote MAC-IP entry is stored in this remote MAC-IP table.

[0202] Taking IPv6 application scenarios as an example, the fields included in the second remote MAC-IP entry are shown in Table 3:

[0203] Table 3

[0204]

[0205] In this embodiment of the application, the first network device further includes a local MAC-IP table, which includes a first local MAC-IP entry, and the first local MAC-IP entry includes a third serial number.

[0206] After the second remote MAC-IP entry is created, if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, then the first local MAC-IP entry is deleted, and the corresponding DHCP relay entry is also deleted.

[0207] The matching of the second remote MAC-IP entry with the first local MAC-IP entry means that the MAC address and IP address included in the second remote MAC-IP entry are the same as those included in the first local MAC-IP entry.

[0208] Understandably, if the second sequence number is greater than the third sequence number, it indicates that the terminal corresponding to the first local MAC-IP entry has been migrated to another access device. That is, the first network device will not receive service packets sent by this terminal until the terminal is migrated back. Accordingly, the first network device will not continue to use the first local MAC-IP entry to perform validity checks on the terminal's service packets, so the first local MAC-IP entry can be deleted, along with the corresponding DHCP relay entry.

[0209] Specifically, the first network device can delete the first local MAC-IP entry from memory and also delete the corresponding forwarding MAC-IP entry stored in the hardware resources of the hardware forwarding chip. This saves the memory and hardware resources of the first network device without compromising network security.

[0210] It should be noted that after generating the first local MAC-IP entry, the first network device will announce this first local MAC-IP entry to other network devices. Correspondingly, after the first network device deletes the first local MAC-IP entry, the first network device needs to send a MAC-IP revocation message to other network devices so that the other network devices will delete the remote MAC-IP entries corresponding to the first local MAC-IP entry.

[0211] In addition, when the first network device deletes a DHCP relay entry due to reasons such as terminal releasing IP addresses or IP address lease aging, the corresponding local MAC-IP entry can be deleted simultaneously.

[0212] In another embodiment of this application, the first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry. After establishing the second remote MAC-IP entry, the method further includes:

[0213] Step A: Receive the first message sent by the terminal. The first message includes the terminal's MAC address and IP address.

[0214] Step B: If there is no local MAC-IP entry in the local MAC-IP table that matches the terminal's MAC address and IP address, and the terminal's MAC address and IP address match the second remote MAC-IP entry, then perform an access probe on the terminal.

[0215] It is understandable that if there is no local MAC-IP entry in the local MAC-IP table that matches the terminal's MAC address and IP address, but the terminal's MAC address and IP address match the second remote MAC-IP entry, it means that the terminal was migrated from another access device.

[0216] Optionally, after the terminal is migrated to the AP connected to the first network device, if the terminal does not immediately renew the IP address lease, the first network device can receive a first message from the terminal, which can be a protocol message or a service message.

[0217] After the first network device receives the first packet, its forwarding plane generates a first packet event for the source MAC address of the first packet. In an IPv6 scenario, this first packet event will trigger an ND probe; in an IPv4 scenario, it will trigger an ARP probe.

[0218] Step C: If an access response is received from the terminal, a composite MAC-IP entry is generated. The composite MAC-IP entry includes the terminal's MAC address and IP address, port identifier, and VLAN identifier.

[0219] In an IPv4 scenario, after the first network device performs an ARP probe, if it receives an access response from the terminal, it can generate an ARP entry. The ARP entry includes the port identifier and VLAN identifier of the terminal access. Then, the first network device can generate a composite MAC-IP entry based on the second remote MAC-IP entry and the ARP entry.

[0220] In an IPv6 scenario, after the first network device performs ND detection, if it receives an access response from the terminal, it can generate an ND entry. The ND entry includes the port identifier and VLAN identifier of the terminal access. Then, the first network device can generate a composite MAC-IP entry based on the second remote MAC-IP entry and the ND entry.

[0221] Taking the IPv6 scenario as an example, the fields included in the synthesized MAC-IP entry are shown in Table 4:

[0222] Table 4

[0223]

[0224] It should be noted that the synthesized MAC-IP entry is only used by the first network device that generates the synthesized MAC-IP entry, and the first network device will not advertise the synthesized MAC-IP entry to other network devices.

[0225] The synthesized MAC-IP entry occupies memory resources in the first network device used for storing control MAC-IP entries.

[0226] Step D: Generate forwarding MAC-IP entries based on the synthesized MAC-IP entries. The forwarding MAC-IP entries include the terminal's MAC address and IP address.

[0227] Step E: Save the forwarded MAC-IP table entry to the hardware resources.

[0228] Among them, hardware resources refer to the hardware resources in the hardware forwarding chip used to store and forward MAC-IP entries.

[0229] Using the above method, after the first network device generates the second remote MAC-IP entry, the terminal may not have migrated to a terminal connected to the first network device at this time. Therefore, there is no need to use the second remote MAC-IP entry for security checks, and consequently, there is no need to distribute the corresponding forwarding MAC-IP entry to hardware resources, thus avoiding the occupation of scarce hardware resources. When the first network device determines that the terminal corresponding to the second remote MAC-IP entry has accessed the first network device, it generates a composite MAC-IP entry and distributes the corresponding forwarding MAC-IP entry to hardware resources. This enables control plane and forwarding plane checks on the terminal's packets, preventing unauthorized packets from entering the network and improving network security.

[0230] Based on the above embodiments, the first network device may delete ARP entries or ND entries. For example, in an IPv6 scenario, some terminals, when in a locked state, may not respond to ND entry aging probe messages initiated by the first network device, causing the ND entry corresponding to that terminal in the first network device to be aged out and deleted. Alternatively, if the access device detects that the terminal's access interface is disconnected, the access device can delete the ND entries of terminals that came online from that access interface.

[0231] When a terminal's access entry is deleted, the first network device can delete the aforementioned composite MAC-IP entry and forwarding MAC-IP entry.

[0232] The access entry for a terminal is either the ND entry or the ARP entry corresponding to that terminal.

[0233] Since the first network device only deletes ND or ARP entries when it deems the terminal disconnected, it temporarily eliminates the need to perform legitimacy checks on packets from that terminal. Therefore, it can delete the synthesized MAC-IP entry stored in memory, along with the corresponding forwarding MAC-IP entry. This reduces the memory and hardware resource consumption of the first network device. Because the second remote MAC-IP entry corresponding to the synthesized MAC-IP entry in the first network device is not deleted, if the terminal reconnects, the first network device can still generate a new synthesized MAC-IP entry based on that second remote MAC-IP entry. This prevents legitimate packets from that terminal from being discarded. The first network device's use of the synthesized MAC-IP entry for packet security checks improves network security.

[0234] The following describes the MAC-IP advertisement message sent by the first network device.

[0235] The MAC-IP advertisement message includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0236] Optionally, the MAC-IP advertisement message includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0237] The first network device can send MAC-IP announcement messages and MAC-IP revocation messages based on the BGP protocol, and both MAC-IP announcement messages and MAC-IP revocation messages can be BGP update messages.

[0238] The MAC-IP advertisement message can be a BGP update message carrying the Multiprotocol_Reachable_Network Layer Reachability Information (MP_REACH_NLRI) attribute. The MP_REACH_NLRI attribute indicates that the terminal corresponding to the MAC-IP entry is reachable from the device that sent the MAC-IP advertisement message.

[0239] A MAC-IP revocation message can be a BGPUpdate message carrying Multiprotocol_UNReachable_Network Layer Reachability Information (MP_UNREACH_NLRI) attribute. The MP_UNREACH_NLRI attribute indicates that the terminal corresponding to the MAC-IP entry is unreachable from the device that sent the MAC-IP revocation message.

[0240] Both the MP_REACH_NLRI and MP_UNREACH_NLRI attributes include MAC-IP NLRI. The format of MAC-IP NLRI is as follows: Figure 3 As shown, it includes: Route Type, Length, and RouteType specific.

[0241] The Route Type indicates the type of MAC-IP NLRI, occupying 1 octet. In this embodiment, the route type can be defined as a route type used to transmit MAC-IP entries.

[0242] Length indicates the length of the MAC-IP NLRI, occupying 1 octet;

[0243] Route Type specific indicates the routing type of MAC-IP NLRI, and the number of bits used is variable.

[0244] like Figure 4 As shown, the Route Type specific includes: Route Distinguisher (RD), Ethernet Segment Identifier, Ethernet Tag ID, MAC Address Length, MAC Address, IP Address Length, and IP Address.

[0245] Of these, RD occupies 8 octets;

[0246] The Ethernet Segment Identifier is a unique non-zero identifier that identifies an Ethernet segment and occupies 10 octets.

[0247] Ethernet Tag ID is used to store the VLAN identifier of the VLAN where the terminal is located, occupying 4 octets;

[0248] MAC Address Length is used to record the length of the terminal's MAC address, occupying 1 octet;

[0249] The MAC Address is used to record the terminal's MAC address and occupies 6 octets;

[0250] IP Address Length is used to record the length of the terminal's IP address, occupying 1 octet;

[0251] IP Address is used to record the IP address of the terminal, occupying 0, 4, or 16 octets.

[0252] To include the lifetime value of an IP address from a MAC-IP entry in a BGP Update message, the BGP protocol can be extended by introducing a first extended community attribute for the MAC-IP entry. This first extended community attribute can be 16 bytes long and has the following structure: Figure 5 As shown.

[0253] Wherein, Type represents the type of the first extended community attribute, and its length is 1 byte; as an example, the value of Type can be 0x8d, and the value of Type can be set according to the actual situation, which is not limited in this embodiment of the application.

[0254] Sub-Type represents the subtype of the first extended community property, and its length is 1 byte. As an example, the value of Sub-Type can be 0x01. The value of Sub-Type can be set according to the actual situation, and this application embodiment does not limit it.

[0255] Reserved is a reserved space with a length of 2 bytes. As an example, the value of Reserved can be 0. The value of Reserved can be set according to the actual situation, and this application embodiment does not limit it.

[0256] The preferred lifetime is the preferred lifetime value of the IP address in the local MAC-IP table entry, with a length of 4 bytes. This parameter is not used in this embodiment.

[0257] Valid lifetime is the valid lifetime value of the IP address in the local MAC-IP table entry, with a length of 4 bytes.

[0258] Similarly, to carry sequence numbers in BGP Update messages, the BGP protocol can be extended by introducing a second extended community attribute corresponding to the MAC-IP entry. This second extended community attribute can be 8 bytes long, and its structure is as follows: Figure 6 As shown.

[0259] Wherein, Type represents the type of the second extended community attribute, and its length is 1 byte; as an example, the value of Type can be 0x8e, and the value of Type can be set according to the actual situation, which is not limited in this embodiment of the application.

[0260] Sub-Type represents the subtype of the second extended community property, and its length is 1 byte. As an example, the value of Sub-Type can be 0x01. The value of Sub-Type can be set according to the actual situation, and this application embodiment does not limit it.

[0261] Reserved is a reserved space with a length of 2 bytes. As an example, the value of Reserved can be 0. The value of Reserved can be set according to the actual situation, and this application embodiment does not limit it.

[0262] The Sequence Number is the sequence number corresponding to the MAC-IP entry, and its length is 4 bytes.

[0263] Corresponding to the above embodiments, this application also provides a security entry maintenance method, which is applied to a second network device, the second network device being... Figure 1 The second network device includes a first remote MAC-IP table, which includes at least one remote MAC-IP entry advertised by the fourth network device, such as Spine1, Spine2, or Spine3. Figure 7 As shown, the method includes:

[0264] S701. When the protocol connection with the fourth network device is interrupted, obtain the valid lifetime value included in each remote MAC-IP entry.

[0265] The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0266] The second network device can be an aggregation device. The fourth network device can be an access device or aggregation device that has a protocol connection with the second network device.

[0267] by Figure 1 Taking the network system shown as an example, the second network device is Figure 1In the case of Spine1, the fourth network device can be Leaf1, Leaf2, or Leaf3, or it can be Spine3.

[0268] Or, in the second network device Figure 1 In the case of Spine3, the fourth network device can be either Spine1 or Spine2.

[0269] The protocol connection between the second and fourth network devices can be a BGP protocol connection. Alternatively, the protocol connection between the second and fourth network devices can also be a custom private protocol connection. In the case of a private protocol connection, each network device advertises MAC-IP entries through the private protocol.

[0270] S702. If the duration of the protocol connection interruption reaches the effective lifecycle value, delete at least one remote MAC-IP entry.

[0271] Understandably, if the first remote MAC-IP table includes a MAC-IP entry, the second network device can obtain the valid lifetime value included in that MAC-IP entry. The second network device maintains the valid lifetime value of the remote MAC-IP entry starting from the moment it detects a protocol connection interruption. That is, after detecting a protocol connection interruption, the second network device keeps the remote MAC-IP entry valid for its lifetime and will not delete it until the valid lifetime value is reached.

[0272] If the protocol connection is not restored after the effective lifetime value has been reached from the start time, the remote MAC-IP entry will be deleted.

[0273] For example, if the effective lifetime is 100,000 seconds, the second network device will start timing after detecting a protocol connection interruption and retain the remote MAC-IP entry for 100,000 seconds. If the protocol connection is not restored after 100,000 seconds, the second network device will delete the remote MAC-IP entry.

[0274] If the first remote MAC-IP table contains multiple MAC-IP entries, the second network device can obtain the valid lifetime values ​​of multiple remote MAC-IP entries.

[0275] In one implementation, after the duration of the protocol connection interruption reaches all the acquired valid lifetime values, that is, after the duration of the protocol connection interruption reaches the maximum lifetime value among the acquired valid lifetime values, the second remote MAC-IP table, which includes multiple MAC-IP entries, is deleted all at once.

[0276] In another implementation, for each valid lifetime value, if the duration of the protocol connection interruption reaches that valid lifetime value, the MAC-IP entry to which that valid lifetime value belongs is deleted.

[0277] Using the above method, the remote MAC-IP entry in the second network device includes a validity lifetime value, which indicates the validity lifetime of the IP address included in the remote MAC-IP entry. If the duration of the protocol connection interruption reaches the validity lifetime value, it indicates that the IP address included in the MAC-IP entry is invalid. That is, the terminal that originally obtained the IP address can no longer use it. Deleting the remote MAC-IP entry at this time will not affect the subsequent legitimacy verification of the terminal, will not affect network security, and can prevent the remote MAC-IP entry from continuing to occupy the resources of the second network device. Before the duration of the protocol connection interruption reaches the validity lifetime value, the second network device will not delete the remote MAC-IP entry. Therefore, even with the power address security check mechanism in place, legitimate packets matching the remote MAC-IP entry will not be discarded, and illegal packets can be prevented from entering the network, thus improving network security.

[0278] In another embodiment of this application, the second network device can receive MAC-IP entries advertised by other network devices. Based on this, before obtaining the valid lifetime value in each remote MAC-IP entry in S701 when the protocol connection with the fourth network device is interrupted, the method further includes:

[0279] Receive the first MAC-IP advertisement message sent by the fourth network device and establish the first remote MAC-IP entry.

[0280] The first MAC-IP advertisement message includes the first valid lifetime value and the first sequence number of the first IP address. Correspondingly, the first remote MAC-IP entry includes the first valid lifetime value and the first sequence number.

[0281] Understandably, the first MAC-IP advertisement message also includes the MAC address and the first IP address, and the first remote MAC-IP entry also includes the MAC address and the first IP address.

[0282] Optionally, the first MAC-IP advertisement message may also include the preferred lifetime value of the first IP address, and correspondingly, the first remote MAC-IP entry also includes the preferred lifetime value of the first IP address.

[0283] Understandably, network devices can advertise MAC-IP entries to each other, allowing the access device to which the terminal is connected to to still perform legality checks on the terminal's packets based on the remote MAC-IP entries after the terminal has migrated, thus rejecting illegal packets from entering the network and improving network security.

[0284] In one embodiment of this application, the second network device further includes at least one second remote MAC-IP table, the at least one second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number. After establishing the remote MAC-IP entry, the method further includes:

[0285] If the first sequence number is greater than the second sequence number, a second MAC-IP announcement message is sent to all network devices except the fourth network device. The second MAC-IP announcement message includes a first valid lifetime value and a first sequence number.

[0286] If the first sequence number is greater than the second sequence number, it means that there is no remote MAC-IP table in the second network device that matches the first remote MAC-IP table entry and includes a remote table entry with a sequence number greater than the first sequence number.

[0287] Understandably, for remote MAC-IP entries with the same IP address and MAC address, the larger the sequence number, the later the remote MAC-IP entry was generated. Therefore, if the first sequence number is greater than the second sequence number, it means that the first remote MAC-IP entry is the most recently generated MAC-IP entry, and thus it needs to be advertised to all network devices except the fourth network device.

[0288] Using the above method, since the sequence number indicates the generation order of MAC-IP entries corresponding to the same terminal, the larger the sequence number, the later the MAC-IP entry was generated. Therefore, a remote MAC-IP entry with a smaller sequence number may no longer be applicable to the terminal corresponding to that remote MAC-IP entry. If the first sequence number is greater than the second sequence number, a second MAC-IP advertisement message is sent to all network devices except the fourth network device. This improves the timeliness and accuracy of MAC-IP advertisements.

[0289] In another embodiment of this application, in Figure 7 Based on the corresponding embodiments, the second network device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry.

[0290] Understandably, after generating a remote MAC-IP entry, the second network device will advertise the generated remote MAC-IP entry to all network devices except the fourth network device. Correspondingly, after deleting a remote MAC-IP entry, the second network device also needs to send a MAC-IP revocation message or a MAC-IP advertisement message based on the deleted remote MAC-IP entry. After the second network device deletes at least one remote MAC-IP entry, the following two scenarios are specifically included:

[0291] Scenario 1: For each deleted remote MAC-IP entry, if at least one third remote MAC-IP table does not contain a matching remote MAC-IP entry, a first MAC-IP revocation message is sent to all network devices except the fourth network device.

[0292] The first MAC-IP revocation message includes the MAC address and IP address in the remote MAC-IP entry.

[0293] Furthermore, after receiving the first MAC-IP revocation message, other network devices besides the fourth network device can promptly update their stored remote MAC-IP entries, avoiding the continued use of invalid remote MAC-IP entries and thus improving network security.

[0294] Scenario 2: For each deleted remote MAC-IP entry, if at least one third MAC-IP entry exists that matches the deleted remote MAC-IP entry, then select the third remote MAC-IP entry with the largest sequence number from the other matching MAC-IP entries and send a fifth MAC-IP announcement message to all network devices except the fifth network device.

[0295] The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. Correspondingly, the third MAC-IP advertisement message includes this second valid lifetime value and the third sequence number. The fifth network device is the source device for the third remote MAC-IP entry. The fifth network device can be an access device or a superior aggregation device of an aggregation device.

[0296] In other words, if the second network device has other remote MAC-IP entries that match the deleted remote MAC-IP entry, the second network device needs to re-advertise a remote MAC-IP entry with the same IP address and MAC address as the deleted remote MAC-IP entry and the largest sequence number.

[0297] It should be noted that among the remote MAC-IP entries matching this remote MAC-IP entry, there may be multiple remote MAC-IP entries with the highest sequence numbers, meaning multiple remote MAC-IP entries have the same sequence number and are tied for the highest. The second network device can then randomly select one of these multiple remote MAC-IP entries with the highest sequence number and use it as the aforementioned third remote MAC-IP entry, and announce it to all network devices except the fifth network device.

[0298] For example, the second network device stores:

[0299] The remote MAC-IP entry 1 from network device A has a sequence number of 3;

[0300] Remote MAC-IP entry 2 from network device B, with sequence number 2;

[0301] Remote MAC-IP entry 3 from network device C, with sequence number 1;

[0302] And remote MAC-IP entry 4 from network device D, with sequence number 2.

[0303] Since the MAC addresses and IP addresses in the above four remote entries are all the same, after the protocol connection between the second network device and network device A is interrupted, and after deleting remote MAC-IP entry 1 according to the method described in the above embodiment, it can be determined that the sequence numbers of remote MAC-IP entry 2 and remote MAC-IP entry 4 are the largest. The second network device randomly selects remote MAC-IP entry 2 from remote MAC-IP entry 2 and remote MAC-IP entry 4, and then the second network device announces remote MAC-IP entry 2 to network device C and network device D.

[0304] After receiving the remote MAC-IP entry 2 from the second network device, network device C will find the remote MAC-IP entry 1 from the second network device's last announcement and modify its own stored remote MAC-IP entry 1 to remote MAC-IP entry 2.

[0305] After receiving the remote MAC-IP entry 2 from the second network device, network device D will find the remote MAC-IP entry 1 from the second network device's previous announcement and modify its own stored remote MAC-IP entry 1 to remote MAC-IP entry 2.

[0306] In this way, if the second network device still stores other remote MAC-IP entries with the same MAC address and IP address after deleting the remote MAC-IP entry, it can promptly re-announce the remote MAC-IP entries to other network devices. This can prevent other network devices from continuing to use invalid remote MAC-IP entries, ensure the accuracy of the remote MAC-IP entries stored in each network device, and improve network security.

[0307] The following explains the MAC-IP advertisement message sent by the second network device:

[0308] The MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifespan value of the IP address.

[0309] The MAC-IP advertisement message sent by the second network device includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0310] The format of the MAC-IP announcement message can be found in the relevant description in the above embodiments.

[0311] The following describes the method for maintaining security entries provided in the embodiments of this application, in conjunction with specific application scenarios.

[0312] like Figure 8 As shown, the structure of 8 and Figure 1 The same applies, where Leaf1, Leaf2, and Leaf3 are access devices, Spine1 and Spine2 are aggregation devices, and Spine3 is the upstream aggregation device of Spine1 and Spine2.

[0313] After Leaf1 in Zone 1 generates a new local MAC-IP entry, it sends a MAC-IP advertisement message to Spine1 via a protocol connection. The MAC-IP advertisement message includes the IP address, MAC address, sequence number (SN), and the valid lifetime value of the IP address from the local MAC-IP entry. The sequence number in this MAC-IP advertisement message is 1.

[0314] After receiving the MAC-IP advertisement message sent by Leaf1, Spine1 generates a remote MAC-IP entry. This remote MAC-IP entry includes the IP address, MAC address, SN, and the effective lifetime value of the IP address from the MAC-IP advertisement message.

[0315] At this time, Spine1 only stores a remote MAC-IP entry with serial number 1 corresponding to the terminal. Spine1 can send MAC-IP announcement messages to Leaf2, Leaf3 and Spine3. The MAC-IP announcement message includes the contents of the remote MAC-IP entry.

[0316] After receiving the MAC-IP announcement message, Leaf2, Leaf3, and Spine3 can also generate remote MAC-IP entries.

[0317] Furthermore, assuming that there are no other remote MAC-IP entries in Spine3 that match this remote MAC-IP entry, Spine3 sends a MAC-IP announcement message to Spine2 in region 2, which includes the contents of the remote MAC-IP entry.

[0318] After receiving a MAC-IP advertisement message, spine2 can also generate remote MAC-IP entries.

[0319] Furthermore, in Figure 8 Based on this, if the terminal is migrated to AP2 connected to Leaf2, then as follows Figure 9 As shown, in one implementation, if the terminal immediately initiates an IPv6 address lease update to the DHCPv6 server, Leaf2 can generate a DHCP relay entry and generate a local MAC-IP entry based on the DHCP relay entry.

[0320] Then, Leaf2 can send a MAC-IP advertisement message to Spine1, which carries a sequence number of 2. After receiving the MAC-IP advertisement message, Spine1 generates a remote MAC-IP entry based on the MAC-IP advertisement message, which includes a sequence number of 2.

[0321] At this point, Spine1 determines that it still stores a remote MAC-IP with sequence number 1, which is identical to the MAC address and IP address in the newly generated remote MAC-IP entry.

[0322] Because the sequence number in the newly generated remote MAC-IP entry is large, Spine1 advertises the remote MAC-IP entry with sequence number 2 to Spine3, Leaf1, and Leaf3.

[0323] After receiving the MAC-IP advertisement message, Spine3, Leaf1, and Leaf3 generate a remote MAC-IP entry with sequence number 2. At this time, both Spine3 and Leaf3 have a remote MAC-IP entry with sequence number 1 from Spine1. The MAC address and IP address in this remote MAC-IP entry are the same as those in the received MAC-IP advertisement message. Therefore, Spine3 and Leaf3 modify the remote MAC-IP entry with sequence number 1 to the remote MAC-IP entry with sequence number 2.

[0324] Spine3 will also send a MAC-IP advertisement message to Spine2, which will then change the remote MAC-IP entry with sequence number 1 to the remote MAC-IP entry with sequence number 2.

[0325] If the terminal adopts another implementation method, Figure 8 Based on this, if the terminal is migrated to AP2 connected to Leaf2, then as follows Figure 10 As shown, if the terminal does not immediately initiate an IPv6 address lease update to the DHCPv6 server, and Leaf2 receives a message sent by the terminal (which could be a protocol message or a service message), Leaf2 will be triggered to perform ND probing on the terminal via the first packet event. Leaf2 learns the ND entry corresponding to the terminal and generates a composite MAC-IP entry based on the ND entry and the remote MAC-IP entry corresponding to the terminal stored on Leaf2.

[0326] It should be noted that, in Figure 10 Based on the previous example, after Leaf2 generates the synthetic MAC-IP entry corresponding to the terminal, if a subsequent terminal initiates an IPv6 address lease renewal to the DHCPv6 server, the access device can perform... Figure 9 The process described in the document means that Leaf2 can also generate local MAC-IP entries for the terminal.

[0327] Based on the same concept, embodiments of this application provide a security entry maintenance device applied to a first network device. The first network device includes a remote MAC-IP table, which includes at least one remote MAC-IP entry advertised by a second network device, such as... Figure 11 As shown, the device includes:

[0328] The acquisition module 1101 is used to acquire the valid lifetime value of each remote MAC-IP entry when the protocol connection with the second network device is interrupted. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0329] The deletion module 1102 is used to delete at least one remote MAC-IP entry if the duration of the protocol connection interruption reaches the valid lifetime value.

[0330] Optionally, the device further includes:

[0331] The module is used to establish a local MAC-IP entry based on the DHCP relay entry when the first network device generates a DHCP relay entry, and to send the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address.

[0332] The sending module is used to send a first MAC-IP advertisement message to a third network device so that the third network device can establish a first remote MAC-IP entry.

[0333] The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes a first sequence number and a first valid lifetime value.

[0334] The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0335] Optionally, the deletion module 1102 is also used to delete the forwarding MAC-IP entry when the access entry matching the local MAC-IP entry is deleted.

[0336] Optionally, the device further includes:

[0337] The receiving module is used to receive a second MAC-IP advertisement message sent by the second network device. The second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number.

[0338] The module is used to create a second remote MAC-IP entry, which includes a second valid lifetime value and a second sequence number.

[0339] Optionally, the first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry;

[0340] The device also includes: a detection module, a generation module, and a transmission module;

[0341] The receiving module is also used to receive a first message sent by the terminal, the first message including the terminal's MAC address and IP address;

[0342] The detection module is used to perform access detection on the terminal if there is no local MAC-IP table entry that matches the terminal's MAC address and IP address, and the terminal's MAC address and IP address match the second remote MAC-IP table entry.

[0343] The generation module is used to generate a composite MAC-IP entry if an access response is received from the terminal. The composite MAC-IP entry includes the terminal's MAC address and IP address, port identifier, and VLAN identifier.

[0344] The generation module is also used to generate forwarding MAC-IP entries based on the synthesized MAC-IP entries. The forwarding MAC-IP entries include the MAC address and IP address of the terminal.

[0345] The distribution module is used to distribute forwarded MAC-IP entries to hardware resources.

[0346] Optionally, the deletion module 1102 is also used to delete the composite MAC-IP entry and the forwarding MAC-IP entry when the access entry of the terminal is deleted.

[0347] Optionally, the first network device includes a local MAC-IP table, the local MAC-IP table includes a first local MAC-IP table entry, and the first local MAC-IP table entry includes a third sequence number;

[0348] The deletion module 1102 is also used to delete the first local MAC-IP entry and the corresponding DHCP relay entry if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number.

[0349] Optionally, the MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0350] Optionally, the MAC-IP advertisement message sent by the first network device may also include a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0351] Based on the same concept, embodiments of this application also provide a security entry maintenance device applied to a second network device. The second network device includes a first remote MAC-IP table, which includes at least one remote MAC-IP entry advertised by a fourth network device, such as... Figure 12 As shown, the device includes:

[0352] The acquisition module 1201 is used to acquire the valid lifetime value of each remote MAC-IP entry when the protocol connection with the fourth network device is interrupted. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0353] The deletion module 1202 is used to delete at least one remote MAC-IP entry if the duration of the protocol connection interruption reaches the valid lifetime value.

[0354] Optionally, the device further includes:

[0355] The receiving module is used to receive a first MAC-IP advertisement message sent by a fourth network device. The first MAC-IP advertisement message includes a first valid lifetime value of a first IP address and a first sequence number.

[0356] The module is used to create a first remote MAC-IP entry, which includes a first valid lifetime value and a first sequence number.

[0357] Optionally, the second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, and the second remote MAC-IP entry including a second sequence number; the device further includes:

[0358] The sending module is configured to send a second MAC-IP announcement message to network devices other than the fourth network device if the first sequence number is greater than the second sequence number. The second MAC-IP announcement message includes a first valid lifetime value and a first sequence number.

[0359] Optionally, the second remote device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; the device also includes a transmission module;

[0360] The sending module is used for:

[0361] For each deleted remote MAC-IP entry, if no matching remote MAC-IP entry exists in at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to all network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address from the remote MAC-IP entry; or...

[0362] For each deleted remote MAC-IP entry, if at least one third remote MAC-IP entry exists that matches the deleted entry, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP advertisement message is sent to all network devices except the fifth network device. The third MAC-IP advertisement message includes a second valid lifetime value and a third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

[0363] Optionally, the MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0364] Optionally, the MAC-IP advertisement message sent by the second network device may also include a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0365] Based on the same concept, embodiments of this application also provide a first network device, the first network device including a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by a second network device; as Figure 13 As shown, the first network device includes:

[0366] Processor 1301;

[0367] Transceiver 1304;

[0368] Machine-readable storage medium 1302 stores machine-executable instructions that can be executed by processor 1301; the machine-executable instructions cause processor 1301 to perform the following steps:

[0369] When the protocol connection with the second network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0370] If the duration of the protocol connection interruption reaches the valid lifetime value, at least one remote MAC-IP entry is deleted.

[0371] Optionally, the machine-executable instructions also cause the processor 1301 to perform the following steps:

[0372] When the first network device generates a DHCP relay entry, it establishes a local MAC-IP entry based on the DHCP relay entry and sends the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address.

[0373] The transceiver 1304 sends a first MAC-IP advertisement message to the third network device so that the third network device can establish a first remote MAC-IP entry.

[0374] The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes a first sequence number and a first valid lifetime value.

[0375] The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0376] Optionally, the machine-executable instructions also cause the processor 1301 to perform the following steps:

[0377] When a local MAC-IP entry that matches an access entry is deleted, the forwarding MAC-IP entry is also deleted.

[0378] Optionally, the machine-executable instructions also cause the processor 1301 to perform the following steps:

[0379] The transceiver 1304 receives a second MAC-IP advertisement message sent by the second network device. The second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number.

[0380] Create a second remote MAC-IP entry, which includes a second valid lifetime value and a second sequence number.

[0381] Optionally, the first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry;

[0382] The machine-executable instructions also cause the processor 1301 to perform the following steps:

[0383] The transceiver 1304 receives the first message sent by the terminal, the first message including the terminal's MAC address and IP address;

[0384] If there is no local MAC-IP table entry that matches the terminal's MAC address and IP address, and the terminal's MAC address and IP address match the second remote MAC-IP table entry, then an access probe will be performed on the terminal.

[0385] If an access response is received from the terminal, a composite MAC-IP entry is generated. The composite MAC-IP entry includes the terminal's MAC address and IP address, port identifier, and VLAN identifier.

[0386] Generate forwarding MAC-IP entries based on the synthesized MAC-IP entries. The forwarding MAC-IP entries include the terminal's MAC address and IP address.

[0387] Forward MAC-IP entries to hardware resources.

[0388] Optionally, the machine-executable instructions also cause the processor 1301 to perform the following steps:

[0389] When a terminal's access entry is deleted, the composite MAC-IP entry and the forwarding MAC-IP entry are also deleted.

[0390] Optionally, the first network device includes a local MAC-IP table, which includes a first local MAC-IP entry, the first local MAC-IP entry including a third serial number; the machine-executable instructions also cause the processor 1301 to perform the following steps:

[0391] If the second remote MAC-IP entry matches the first local MAC-IP entry, and the second sequence number is greater than the third sequence number, then the first local MAC-IP entry is deleted, and the corresponding DHCP relay entry is also deleted.

[0392] Optionally, the MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0393] Optionally, the MAC-IP advertisement message sent by the first network device may also include a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0394] exist Figure 13 The system may also include a communication bus 1303. The processor 1301, machine-readable storage medium 1302, and transceiver 1304 communicate with each other via the communication bus 1303. The communication bus 1303 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0395] The transceiver 1304 can be a wireless communication module. Under the control of the processor 1301, the transceiver 1304 interacts with other devices for data exchange.

[0396] The machine-readable storage medium 1302 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the machine-readable storage medium may also be at least one storage device located remotely from the aforementioned processor.

[0397] Processor 1301 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0398] Based on the same concept, embodiments of this application also provide a second network device, the second network device including a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry advertised by a fourth network device, such as... Figure 14 As shown, the second network device includes:

[0399] Processor 1401;

[0400] Transceiver 1404;

[0401] Machine-readable storage medium 1402 stores machine-executable instructions that can be executed by processor 1401; the machine-executable instructions cause processor 1401 to perform the following steps:

[0402] When the protocol connection with the fourth network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0403] If the duration of the protocol connection interruption reaches the valid lifetime value, at least one remote MAC-IP entry is deleted.

[0404] Optionally, the machine-executable instructions also cause the processor 1401 to perform the following steps:

[0405] The transceiver 1404 receives a first MAC-IP advertisement message sent by a fourth network device. The first MAC-IP advertisement message includes a first valid lifetime value of a first IP address and a first sequence number.

[0406] Create the first remote MAC-IP entry, which includes the first valid lifetime value and the first sequence number.

[0407] Optionally, the second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, the second remote MAC-IP entry including a second serial number; machine-executable instructions cause processor 1401 to perform the following steps:

[0408] If the first sequence number is greater than the second sequence number, a second MAC-IP announcement message is sent to all network devices except the fourth network device. The second MAC-IP announcement message includes a first valid lifetime value and a first sequence number.

[0409] Optionally, the second remote device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP table entry; machine-executable instructions cause the processor 1401 to perform the following steps:

[0410] For each deleted remote MAC-IP entry, if no matching remote MAC-IP entry exists in at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to all network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address from the remote MAC-IP entry; or...

[0411] For each deleted remote MAC-IP entry, if at least one third remote MAC-IP entry exists that matches the deleted entry, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP advertisement message is sent to all network devices except the fifth network device. The third MAC-IP advertisement message includes a second valid lifetime value and a third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

[0412] Optionally, the MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

[0413] Optionally, the MAC-IP advertisement message sent by the second network device may also include a second extended community attribute, which includes the sequence number of the MAC-IP entry.

[0414] exist Figure 14 The system may also include a communication bus 1403. The processor 1401, machine-readable storage medium 1402, and transceiver 1404 communicate with each other via the communication bus 1403. The communication bus 1403 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into an address bus, a data bus, a control bus, etc.

[0415] The transceiver 1404 can be a wireless communication module, which interacts with other devices under the control of the processor 1401.

[0416] The machine-readable storage medium 1402 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Alternatively, the machine-readable storage medium may also be at least one storage device located remotely from the aforementioned processor.

[0417] Processor 1401 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0418] Based on the same inventive concept, and according to the security entry maintenance method provided in the above embodiments of this application, this application also provides a machine-readable storage medium storing machine-executable instructions that can be executed by a processor. The processor is prompted by the machine-executable instructions to implement the steps of any of the above-described security entry maintenance methods.

[0419] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to perform the steps of any of the security entry maintenance methods described in the above embodiments.

[0420] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

[0421] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0422] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for maintaining safety entries, characterized in that, Applied to a first network device, the first network device including a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by a second network device, the method includes: When the protocol connection with the second network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry; If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

2. The method according to claim 1, characterized in that, The method further includes: When the first network device generates a DHCP relay entry, it establishes a local MAC-IP entry based on the DHCP relay entry and sends the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address. Send a first MAC-IP advertisement message to a third network device so that the third network device establishes a first remote MAC-IP entry; The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value. The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

3. The method according to claim 2, characterized in that, After issuing the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources, the method further includes: When the access entry that matches the local MAC-IP entry is deleted, the forwarding MAC-IP entry is deleted.

4. The method according to claim 1, characterized in that, Before obtaining the valid lifetime value included in each remote MAC-IP entry when the protocol connection with the second network device is interrupted, the method further includes: The system receives a second MAC-IP advertisement message sent by the second network device. The second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number. Create a second remote MAC-IP entry, which includes the second valid lifetime value and the second sequence number.

5. The method according to claim 4, characterized in that, The first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry; After establishing the second remote MAC-IP entry, the method further includes: The receiving terminal sends a first message, the first message including the terminal's MAC address and IP address; If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, then an access probe is performed on the terminal. If an access response is received from the terminal, a composite MAC-IP entry is generated, which includes the terminal's MAC address and IP address, port identifier, and VLAN identifier. A forwarding MAC-IP entry is generated based on the synthesized MAC-IP entry, and the forwarding MAC-IP entry includes the MAC address and IP address of the terminal; The forwarding MAC-IP entries are distributed to the hardware resources.

6. The method according to claim 5, characterized in that, After the forwarding MAC-IP entry is sent to the hardware resources, the method further includes: When the access entry of the terminal is deleted, the composite MAC-IP entry and the forwarding MAC-IP entry are also deleted.

7. The method according to claim 4, characterized in that, The first network device includes a local MAC-IP table, the local MAC-IP table includes a first local MAC-IP entry, and the first local MAC-IP entry includes a third sequence number; after establishing the second remote MAC-IP entry, the method further includes: If the second remote MAC-IP entry matches the first local MAC-IP entry, and the second sequence number is greater than the third sequence number, then the first local MAC-IP entry is deleted, and the DHCP relay entry corresponding to the first local MAC-IP entry is also deleted.

8. The method according to any one of claims 1-7, characterized in that, The MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

9. The method according to claim 8, characterized in that, The MAC-IP advertisement message sent by the first network device also includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

10. A method for maintaining safety entries, characterized in that, Applied to a second network device, the second network device including a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry advertised by a fourth network device, the method includes: When the protocol connection with the fourth network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry; If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

11. The method according to claim 10, characterized in that, Before obtaining the valid lifetime value included in each remote MAC-IP entry when the protocol connection with the fourth network device is interrupted, the method further includes: The system receives a first MAC-IP announcement message sent by the fourth network device. The first MAC-IP announcement message includes a first valid lifetime value of the first IP address and a first sequence number. A first remote MAC-IP entry is established, which includes the first valid lifetime value and the first sequence number.

12. The method according to claim 11, characterized in that, The second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; after establishing the first remote MAC-IP entry, the method further includes: If the first sequence number is greater than the second sequence number, a second MAC-IP announcement message is sent to other network devices besides the fourth network device. The second MAC-IP announcement message includes the first valid lifetime value and the first sequence number.

13. The method according to claim 10, characterized in that, The second network device also includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; After deleting the at least one remote MAC-IP entry, the method further includes: For each deleted remote MAC-IP entry, if there is no matching remote MAC-IP entry in the at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to other network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address in the remote MAC-IP entry. or, For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP announcement message is sent to all network devices except the fifth network device. The third MAC-IP announcement message includes the second valid lifetime value and the third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

14. The method according to any one of claims 10-13, characterized in that, The MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

15. The method according to claim 14, characterized in that, The MAC-IP advertisement message sent by the second network device also includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

16. A safety meter maintenance device, characterized in that, Applied to a first network device, the first network device including a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by a second network device, the apparatus comprising: The acquisition module is configured to acquire the valid lifetime value of each remote MAC-IP entry when the protocol connection with the second network device is interrupted. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry. The deletion module is used to delete at least one remote MAC-IP entry if the duration of the interruption of the protocol connection reaches the effective lifecycle value.

17. The apparatus according to claim 16, characterized in that, The device further includes: The module is configured to establish a local MAC-IP entry based on the DHCP relay entry when the first network device generates a DHCP relay entry, and to issue the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address. The sending module is used to send a first MAC-IP announcement message to a third network device so that the third network device can establish a first remote MAC-IP entry. The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value. The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

18. The apparatus according to claim 17, characterized in that, The deletion module is further configured to delete the forwarding MAC-IP entry when the access entry matching the local MAC-IP entry is deleted.

19. The apparatus according to claim 16, characterized in that, The device further includes: The receiving module is configured to receive a second MAC-IP advertisement message sent by the second network device, wherein the second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number; A module is established to create a second remote MAC-IP entry, which includes the second valid lifetime value and the second sequence number.

20. The apparatus according to claim 19, characterized in that, The first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry; The device further includes: a detection module, a generation module, and a transmission module; The receiving module is further configured to receive a first message sent by the terminal, the first message including the MAC address and IP address of the terminal; The detection module is used to perform access detection on the terminal if there is no local MAC-IP table entry that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP table entry. The generation module is used to generate a composite MAC-IP entry if it receives an access response from the terminal. The composite MAC-IP entry includes the MAC address and IP address of the terminal, port identifier, and VLAN identifier. The generation module is further configured to generate forwarding MAC-IP entries based on the synthesized MAC-IP entries, wherein the forwarding MAC-IP entries include the MAC address and IP address of the terminal; The distribution module is used to distribute the forwarding MAC-IP entries to hardware resources.

21. The apparatus according to claim 20, characterized in that, The deletion module is further configured to delete the composite MAC-IP entry and the forwarding MAC-IP entry when the access entry of the terminal is deleted.

22. The apparatus according to claim 19, characterized in that, The first network device includes a local MAC-IP table, the local MAC-IP table includes a first local MAC-IP entry, and the first local MAC-IP entry includes a third sequence number; The deletion module is further configured to delete the first local MAC-IP entry and the corresponding DHCP relay entry if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number.

23. The apparatus according to any one of claims 16-22, characterized in that, The MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

24. The apparatus according to claim 23, characterized in that, The MAC-IP advertisement message sent by the first network device also includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

25. A safety meter maintenance device, characterized in that, Applied to a second network device, the second network device including a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry advertised by a fourth network device, the apparatus comprising: The acquisition module is configured to acquire the valid lifetime value of each remote MAC-IP entry when the protocol connection with the fourth network device is interrupted. The valid lifetime value is used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry. The deletion module is used to delete at least one remote MAC-IP entry if the duration of the interruption of the protocol connection reaches the effective lifecycle value.

26. The apparatus according to claim 25, characterized in that, The device further includes: The receiving module is configured to receive a first MAC-IP announcement message sent by the fourth network device, wherein the first MAC-IP announcement message includes a first valid lifetime value of a first IP address and a first sequence number; A module is established to create a first remote MAC-IP entry, which includes the first valid lifetime value and the first sequence number.

27. The apparatus according to claim 26, characterized in that, The second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; the device further includes: The sending module is configured to send a second MAC-IP announcement message to network devices other than the fourth network device if the first sequence number is greater than the second sequence number. The second MAC-IP announcement message includes the first valid lifetime value and the first sequence number.

28. The apparatus according to claim 25, characterized in that, The second network device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; the device further includes a transmission module; The sending module is used for: For each deleted remote MAC-IP entry, if there is no matching remote MAC-IP entry in the at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to other network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address in the remote MAC-IP entry. or, For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP announcement message is sent to all network devices except the fifth network device. The third MAC-IP announcement message includes the second valid lifetime value and the third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

29. The apparatus according to any one of claims 25-28, characterized in that, The MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

30. The apparatus according to claim 29, characterized in that, The MAC-IP advertisement message sent by the second network device also includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

31. A first network device, characterized in that, The first network device includes a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry advertised by the second network device; the first network device includes: processor; transceiver; A machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the machine-executable instructions cause the processor to perform the following steps: When the protocol connection with the second network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry; If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

32. The first network device according to claim 31, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: When the first network device generates a DHCP relay entry, it establishes a local MAC-IP entry based on the DHCP relay entry and sends the forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resources. The local MAC-IP entry includes the first valid lifetime value of the first IP address. The transceiver sends a first MAC-IP advertisement message to the third network device, so that the third network device can establish a first remote MAC-IP entry. The first MAC-IP announcement message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value. The first sequence number is the sum of the largest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

33. The first network device according to claim 32, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: When the access entry that matches the local MAC-IP entry is deleted, the forwarding MAC-IP entry is deleted.

34. The first network device according to claim 31, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: The transceiver receives a second MAC-IP advertisement message sent by the second network device. The second MAC-IP advertisement message includes a second valid lifetime value of the second IP address and a second sequence number. Create a second remote MAC-IP entry, which includes the second valid lifetime value and the second sequence number.

35. The first network device according to claim 34, characterized in that, The first network device includes a local MAC-IP table, which includes at least one local MAC-IP entry; The machine-executable instructions also cause the processor to perform the following steps: The transceiver receives a first message sent by the terminal, the first message including the terminal's MAC address and IP address; If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, then an access probe is performed on the terminal. If an access response is received from the terminal, a composite MAC-IP entry is generated, which includes the terminal's MAC address and IP address, port identifier, and VLAN identifier. A forwarding MAC-IP entry is generated based on the synthesized MAC-IP entry, and the forwarding MAC-IP entry includes the MAC address and IP address of the terminal; The forwarding MAC-IP entries are distributed to the hardware resources.

36. The first network device according to claim 35, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: When the access entry of the terminal is deleted, the composite MAC-IP entry and the forwarding MAC-IP entry are also deleted.

37. The first network device according to claim 34, characterized in that, The first network device includes a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry, the first local MAC-IP entry including a third serial number; the machine-executable instructions further cause the processor to perform the following steps: If the second remote MAC-IP entry matches the first local MAC-IP entry, and the second sequence number is greater than the third sequence number, then the first local MAC-IP entry is deleted, and the DHCP relay entry corresponding to the first local MAC-IP entry is also deleted.

38. The first network device according to any one of claims 31-37, characterized in that, The MAC-IP advertisement message sent by the first network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

39. The first network device according to claim 38, characterized in that, The MAC-IP advertisement message sent by the first network device also includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

40. A second network device, characterized in that, The second network device includes a first remote MAC-IP table, which includes at least one remote MAC-IP entry advertised by the fourth network device. The second network device includes: processor; transceiver; A machine-readable storage medium storing machine-executable instructions that can be executed by the processor; the machine-executable instructions cause the processor to perform the following steps: When the protocol connection with the fourth network device is interrupted, obtain the valid lifetime value of each remote MAC-IP entry, the valid lifetime value being used to indicate the valid lifetime of the IP address included in the remote MAC-IP entry; If the duration of the interruption of the protocol connection reaches the effective lifecycle value, then the at least one remote MAC-IP entry is deleted.

41. The second network device according to claim 40, characterized in that, The machine-executable instructions also cause the processor to perform the following steps: The transceiver receives a first MAC-IP announcement message sent by the fourth network device. The first MAC-IP announcement message includes a first valid lifetime value of a first IP address and a first sequence number. A first remote MAC-IP entry is established, which includes the first valid lifetime value and the first sequence number.

42. The second network device according to claim 41, characterized in that, The second network device further includes at least one second remote MAC-IP table, the at least one second remote table including a second remote MAC-IP entry, the second remote MAC-IP entry matching a first remote MAC-IP entry, the second remote MAC-IP entry including a second serial number; the machine-executable instructions cause the processor to perform the following steps: If the first sequence number is greater than the second sequence number, a second MAC-IP announcement message is sent to other network devices besides the fourth network device. The second MAC-IP announcement message includes the first valid lifetime value and the first sequence number.

43. The second network device according to claim 40, characterized in that, The second network device further includes at least one third remote MAC-IP table, each third remote MAC-IP table including at least one remote MAC-IP entry; the machine-executable instructions cause the processor to perform the following steps: For each deleted remote MAC-IP entry, if there is no matching remote MAC-IP entry in the at least one third remote MAC-IP table, a first MAC-IP revocation message is sent to other network devices except the fourth network device. The first MAC-IP revocation message includes the MAC address and IP address in the remote MAC-IP entry. or, For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the at least one third remote MAC-IP table, then the third remote MAC-IP entry with the largest sequence number is selected from the matching entries. The third remote MAC-IP entry includes a second valid lifetime value and a third sequence number. A third MAC-IP announcement message is sent to all network devices except the fifth network device. The third MAC-IP announcement message includes the second valid lifetime value and the third sequence number. The fifth network device is the source device of the third remote MAC-IP entry.

44. The second network device according to any one of claims 40-43, characterized in that, The MAC-IP advertisement message sent by the second network device includes a first extended community attribute, which includes the effective lifetime value of the IP address.

45. The second network device according to claim 44, characterized in that, The MAC-IP advertisement message sent by the second network device also includes a second extended community attribute, which includes the sequence number of the MAC-IP entry.

46. ​​A machine-readable storage medium, characterized in that, The device stores machine-executable instructions that, when invoked and executed by a processor, cause the processor to: implement the method of any one of claims 1-9 or 10-15.

47. A computer program product, characterized in that, The computer program product causes the processor to implement the method of any one of claims 1-9 or 10-15.

Citation Information

Patent Citations

  • Data forwarding method and system, and related device

    CN106789667A

  • Method and device for generating ARP suppression entry

    CN109462609A