Virtual Private Network (VPN) routing control methods, network devices, and communication systems
By generating and sending VPN Prefix ORF entries on upstream devices, the problem of repeated filtering of VPN routes by upstream devices is solved, and efficient use of resources is achieved.
Patent Information
- Application Number
- CN202311054527.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-21
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-08-21
AI Technical Summary
Upstream devices need to continuously perform VPN routing filtering locally, which wastes resources and results in low resource utilization.
Generate VPN Prefix ORF entries and send them to the device at the next-hop address so that the device at the next-hop address can filter the VPN routes of the source PE, reducing redundant filtering operations by upstream devices.
By generating and sending VPN Prefix ORF entries from upstream devices, local processing pressure is reduced, resources are saved, and overall resource utilization is improved.
Smart Images

Figure CN119496734B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the fields of network technology and communication technology, and in particular to a control method, network device and communication system for virtual private network routing. Background Technology
[0002] In a VPN (Virtual Private Network), VPN Prefix ORF (Outbound Route Filters) entries are used to filter VPN routes from PE (Provider Equipment). Upstream devices stop sending VPN routes that match the filtering criteria to downstream devices based on the stored VPN Prefix ORF entries. Summary of the Invention
[0003] The inventors discovered that if an upstream device (e.g., a Route Reflector) stores VPN Prefix ORF (Outbound Route Filter) entries with the same filtering conditions for all downstream devices (e.g., PEs), it needs to send VPN routes that meet the filtering conditions to any downstream device. However, when a VPN route arrives, it still needs to continuously perform VPN route filtering locally, wasting the resources of the upstream device.
[0004] One of the technical problems that this disclosure aims to solve is: how to save resources and improve resource utilization.
[0005] According to some embodiments of this disclosure, a method for controlling virtual private network (VPN) routing is provided, comprising: generating a VPNPrefix ORF entry when the sending device of a VPN Prefix ORF entry with the same filtering conditions includes all internal border gateway (IBGP) neighbors of a network device other than the device with the next-hop address; wherein the next-hop address is the next-hop address of a network device in the direction of the source PE (Peer-to-Peer) device with the same filtering conditions, and the filtering conditions in the generated VPN Prefix ORF entry include the address of the source PE; and sending the generated VPNPrefix ORF entry to the device with the next-hop address so that the device with the next-hop address can filter the VPN routes sent by the source PE.
[0006] In some embodiments, the method further includes: determining the next-hop address corresponding to the source PE in the stored VPN Prefix ORF entry sending device and filtering conditions.
[0007] In some embodiments, determining the sending device of a stored VPN Prefix ORF entry includes: determining the port field corresponding to the stored VPN Prefix ORF entry in an egress route filter policy table; and determining the sending device of the stored VPN Prefix ORF entry based on the value of the port field corresponding to the stored VPN Prefix ORF entry.
[0008] In some embodiments, the filtering criteria for the stored VPN Prefix ORF entries may further include: the route identifier RD of the source PE and the route destination RT.
[0009] In some embodiments, determining the next-hop address of the source PE address in the filtering conditions of the stored VPN Prefix ORF entry includes: looking up the next-hop address corresponding to the source PE in the forwarding information base table.
[0010] In some embodiments, in Option B scenario, the network device is a route reflector (RR), the device with the next-hop address is an Autonomous System Border Router (ASBR) within its Autonomous System (AS), or the network device is an ASBR, the device with the next-hop address is an ASBR within an adjacent AS, and the sending device of the VPN Prefix ORF entry with the same filtering condition includes all internal border gateway (IBGP) neighbors of the network device other than the device with the next-hop address. This includes cases where, if the network device is an RR, the sending device of the VPN Prefix ORF entry with the same filtering condition includes all PEs within the AS where the RR is located; or if the network device is an ASBR, the sending device of the VPN Prefix ORF entry with the same filtering condition is an RR within the AS where the ASBR is located.
[0011] In some embodiments, in Option C scenario, the network device is a route reflector (RR), the device with the next-hop address is an RR within an adjacent autonomous system (AS), and the sending device of the VPN Prefix ORF entry with the same filtering condition includes all internal border gateway protocol (IBGP) neighbors of the network device other than the device with the next-hop address. This includes cases where the sending device of the VPN Prefix ORF entry with the same filtering condition includes all PEs within the AS where the RR is located.
[0012] In some embodiments, the filtering conditions in the generated VPN Prefix ORF entry may also include: the route identifier RD of the source PE and the route destination RT.
[0013] In some embodiments, the device that sends the generated VPN Prefix ORF entry to the next-hop address includes: a device that sends the generated VPN Prefix ORF entry to the next-hop address via a border gateway routing refresh message.
[0014] In some embodiments, the method further includes: receiving a VPN Prefix ORF entry sent by a sending device; determining whether the received VPN Prefix ORF entry has been stored; and storing the received VPN Prefix ORF entry if it has not been stored.
[0015] According to some other embodiments of this disclosure, a network device is provided, comprising: a generation module, configured to generate a VPNPrefix ORF entry when the sending device of a VPN Prefix ORF entry with the same filtering condition includes all internal border gateway (IBGP) neighbors of the network device other than the device with the next-hop address, wherein the next-hop address is the next-hop address of the network device in the direction of the source operator device (PE) with the same filtering condition, and the filtering condition in the generated VPN Prefix ORF entry includes the address of the source PE; and a sending module, configured to send the generated VPN Prefix ORF entry to the device with the next-hop address, so that the device with the next-hop address can filter the VPN route of the source PE.
[0016] According to further embodiments of this disclosure, a network device is provided, including: a processor; and a memory coupled to the processor for storing instructions, which, when executed by the processor, cause the processor to perform a virtual private network routing control method as described in any of the foregoing embodiments.
[0017] According to further embodiments of the present disclosure, a non-transitory computer-readable storage medium is provided, on which a computer program is stored, wherein the program, when executed by a processor, implements the virtual private network routing control method of any of the foregoing embodiments.
[0018] According to further embodiments of this disclosure, a communication system is provided, comprising: a network device of any of the foregoing embodiments; a transmitting device for transmitting VPN Prefix ORF entries to the network device; and a receiving device for receiving VPN Prefix ORF entries transmitted by the network device and filtering VPN routes based on the received VPN Prefix ORF entries, wherein the receiving device is a device with the next-hop address corresponding to the source operator device (PE) in the filtering conditions of the VPN Prefix ORF entries transmitted by the network device, and the next-hop address is the next-hop address of the network device in the direction of the source PE.
[0019] In this disclosure, if the network device stores VPN Prefix ORF entries with the same filtering conditions in all its IBGP neighbors (excluding the device at the next-hop address), it generates VPN Prefix ORF entries and sends them to the device at the next-hop address. The next-hop device then filters the VPN routes of the source PE. This way, the network device filters VPN routes directly upstream without sending VPN routes matching the filtering conditions to any downstream devices. This eliminates the need for repeated local checks of filtering conditions, reducing processing load, saving resources, and pushing the filtering work further to the VPN route sender, thus improving overall resource utilization.
[0020] Other features and advantages of this disclosure will become clear from the following detailed description of exemplary embodiments with reference to the accompanying drawings. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 A flowchart illustrating a virtual private network routing control method according to some embodiments of this disclosure is shown.
[0023] Figure 2 A schematic diagram illustrating the network architecture in Option B scenario of some embodiments of this disclosure is shown.
[0024] Figure 3 A schematic diagram illustrating the network architecture in Option C scenario of some embodiments of this disclosure is shown.
[0025] Figure 4 A schematic diagram of the structure of a network device according to some embodiments of the present disclosure is shown.
[0026] Figure 5 A schematic diagram of the structure of a network device according to other embodiments of this disclosure is shown.
[0027] Figure 6 A schematic diagram of the structure of a network device according to further embodiments of the present disclosure is shown.
[0028] Figure 7 A schematic diagram of the structure of a communication system according to some embodiments of the present disclosure is shown. Detailed Implementation
[0029] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit this disclosure or its application or use. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without creative effort are within the scope of protection of this disclosure.
[0030] This disclosure proposes a method for controlling routing in a Virtual Private Network (VPN), which is described below in conjunction with... Figures 1-3 Provide a description.
[0031] Figure 1 Flowcharts are shown for some embodiments of the virtual private network routing control method disclosed herein. For example... Figure 1 As shown, the method of this embodiment is executed by a network device and includes steps S102 to S106.
[0032] In step S102, the sending device of the stored VPN Prefix ORF entry and the next-hop address corresponding to the source PE in the filtering conditions are determined. Step S102 is optional.
[0033] In some embodiments, the network device receives a VPN Prefix ORF entry sent by the sending device; determines whether the received VPN Prefix ORF entry has been stored; and stores the received VPN Prefix ORF entry if it has not been stored.
[0034] For example, if the network device is RR and the sending device is PE, when a VRF (Virtual Routing and Forwarding) on PE experiences a routing limit issue, and other VRFs on PE do not need to receive the VPN route causing the limit issue, PE will send a VPN Prefix ORF entry to its upstream device (RR). Upon receiving this VPN Prefix ORF entry, RR will check if it already has the entry stored locally. If not, it will store the received VPN Prefix ORF entry and subsequently stop sending VPN routes matching the filtering criteria to PE based on the VPN Prefix ORF entry. If it already has the entry stored, it does not need to store any more received VPN Prefix ORF entries.
[0035] In some embodiments, the received VPN Prefix ORF entry is compared with the information stored in the ORF-Policy (Exit Routing Filter Policy) table to determine whether the received VPN Prefix ORF entry has been stored.
[0036] For example, the fields corresponding to each VPN Prefix ORF entry in the ORF-Policy table include: Action, Match, Offending VPN routes process method, Sequence, VRF prefix limit, Route Distinguisher (RD), Source PE, Route Target (RT), and Interface.
[0037] The VPN Prefix ORF entries are shown in Table 1, including: Action, Match, OffendingVPN routes process method, Length, Sequence, VRF prefix limit, Route Distinguisher (RD), and Optional TLVs. Optional TLVs can be configured with values such as Source PE, RT, and interface.
[0038] Table 1
[0039] Action (2 bits) Match (1 bit) Offending VPN Routes Process Method(1bit) Reserved (4 bits) Sequence (32 bits) Length (16 bits) VRF Prefix Limit (16 bits) Route Distinguisher (64 bits) Optional TLVs(variable)
[0040] By comparing the port, RD, RT, and source PE address corresponding to the received VPN Prefix ORF entry with the information stored in the ORF-Policy table, it can be determined whether the received VPN Prefix ORF entry has been stored.
[0041] In some embodiments, after each VPN Prefix ORF entry is received and stored, the sending device of the stored VPN Prefix ORF entry and the next-hop address corresponding to the source PE in the filtering conditions are determined. Alternatively, the sending device of the stored VPN Prefix ORF entry and the next-hop address corresponding to the source PE in the filtering conditions are determined every preset period. Step S102 can also be triggered in other ways, not limited to the examples given.
[0042] In some embodiments, the port field corresponding to the stored VPN Prefix ORF entry is determined in the ORF-Policy table; and the sending device of the stored VPN Prefix ORF entry is determined based on the value of the port field corresponding to the stored VPN Prefix ORF entry.
[0043] In some embodiments, the next-hop address corresponding to the source PE is the next-hop address of the network device in the direction of the source PE, that is, the next-hop address of the network device when the address of the source PE is the destination address. It should be noted that when the VPN route of the PE needs to be filtered through the VPN Prefix ORF entry, the PE is called the Source PE in the ORF-Policy table or VPNPrefix ORF entry. However, when determining the next-hop address corresponding to the PE, the address of the PE is used as the destination address for lookup, which is not contradictory.
[0044] In some embodiments, the next-hop address corresponding to the source PE is looked up in the FIB (Forwarding Information Base) table. For example, the address of the source PE is matched with the destination address (Destination / mask) field in the FIB table, and the next-hop address corresponding to the destination address that is the same as the address of the source PE is used as the next-hop address corresponding to the source PE.
[0045] In some embodiments, the filtering criteria for VPN Prefix ORF entries include: the RD, RT, and IP address of the source PE.
[0046] In step S104, if the VPN Prefix ORF entry sending device under the same filtering conditions includes all IBGP (Internal Border Gateway Protocol) neighbors of network devices other than the device with the next-hop address, a VPN Prefix ORF entry is generated.
[0047] VPN Prefix ORF entries with the same filtering conditions can include one or more VPN Prefix ORF entries. For example, if the network device is an ASBR (Autonomous System Boundary Router) and the sending device is an RR, there may only be one VPN Prefix ORF entry with the same filtering conditions. However, if the network device is an RR and the sending device is a PE, there may be multiple VPN Prefix ORF entries with the same filtering conditions.
[0048] In some embodiments, when the network device is RR, it is possible to first check whether there are VPN Prefix ORF entries with the same filtering conditions but different sending devices in the local ORF-Policy table. If they exist, it is determined whether the sending device of the VPN Prefix ORF entry with the same filtering conditions includes all IBGP neighbors of the network device other than the device with the next-hop address.
[0049] In some embodiments, when the network device is an ASBR, it can be directly determined whether the sending device of the VPNPrefix ORF entry with the same filtering conditions includes all IBGP neighbors of the network device other than the device with the next-hop address.
[0050] In some embodiments, in Option B scenario, where the network device is an RR and the device with the next-hop address is an ASBR within the same AS (Autonomous System), or the network device is an ASBR and the device with the next-hop address is an ASBR within an adjacent AS, the sending device of the VPN Prefix ORF entry with the same filtering condition includes all internal border gateway (IBGP) neighbors of the network device other than the device with the next-hop address. This includes cases where, if the network device is an RR, the sending device of the VPN Prefix ORF entry with the same filtering condition includes all PEs within the AS where the RR is located; or, if the network device is an ASBR, the sending device of the VPN Prefix ORF entry with the same filtering condition is an RR within the AS where the ASBR is located.
[0051] like Figure 2 As shown, in the cross-domain scenario of Option B, ASBR1 of AS1 and ASBR2 of AS2 are eBGP (External Border Gateway Protocol) peers. Within AS1, PE1, PE2, ASBR1 and RR1 are iBGP peers (neighbors), and within AS2, PE3, PE4, ASBR2 and RR2 are iBGP peers.
[0052] For RR1, both PE1 and PE2 sent VPN Prefix ORF entries to RR1 carrying the same filtering conditions (RD=RD1, Source PE=IP4, RT=RT1), i.e., the source PE is... Figure 2In the PE4 field, RR1 checks the local ORF-Policy table for VPN Prefix ORF entries with the same filtering conditions but different sending devices. If any exist, it checks the IP address value (IP4) of the Source PE (PE4) in the filtering conditions and looks up the next-hop address corresponding to the IP address (IP4) destined for PE4 in the FIB table. The next-hop address is the IP address of ASBR1. RR1 then determines whether the sending devices of VPN Prefix ORF entries with the same filtering conditions cover all IBGP neighbors (i.e., PE1 and PE2) except ASBR1. If so, RR1 generates a VPN Prefix ORF entry.
[0053] For ASBR1, RR1 sends a VPN Prefix ORF entry to ASBR1. ASBR1 checks the IP address value (IP4) of the Source PE (PE4) in the filter conditions and looks up the next-hop address corresponding to the IP address (IP4) destined for PE4 in the FIB table. The next-hop address is RR2. ASBR1 determines that the sending device of the VPN Prefix ORF entry with the same filter conditions (i.e., RR1) is the only connected IBGP neighbor, and therefore generates a VPN Prefix ORF entry.
[0054] In some embodiments, in Option C scenario, the network device is RR, the device with the next-hop address is RR within the adjacent AS, and the sending device of the VPN Prefix ORF entry with the same filtering condition includes all IBGP neighbors of the network device other than the device with the next-hop address. This includes the case where the sending device of the VPN Prefix ORF entry with the same filtering condition includes all PEs within the AS where the RR is located.
[0055] like Figure 3 As shown, in the cross-domain scenario of Option C, RR1 in AS1 and RR2 in AS2 are eBGP peers. Within AS1, PE1, PE2, PE3 and RR1 are iBGP peers (neighbors), and within AS2, PE4, PE5, PE6 and RR2 are iBGP peers.
[0056] For RR1, PE1, PE2, and PE3 all sent VPN Prefix ORF entries to RR1 carrying the same filtering conditions (RD=RD1, Source PE=IP4, RT=RT1), i.e., the source PE is... Figure 3In the case of PE4, RR1 checks its local ORF-Policy table for VPN Prefix ORF entries with the same filtering conditions but different sending devices. If an entry exists, it checks the IP address value (IP4) of the Source PE (PE4) in the filtering conditions and looks up the next-hop address corresponding to the IP address (IP4) destined for PE4 in the FIB table. The next-hop address is the IP address of RR2. RR1 then determines whether the sending devices of VPN Prefix ORF entries with the same filtering conditions cover all IBGP neighbors (i.e., PE1, PE2, PE3) except for RR2. If so, RR1 generates a VPN Prefix ORF entry.
[0057] The filtering criteria for the generated VPN Prefix ORF entries include: the source PE's RD, RT, and IP address.
[0058] In step S106, the generated VPN Prefix ORF entry is sent to the device at the next-hop address so that the device at the next-hop address can filter the route of the source PE.
[0059] The next-hop address is the device upstream of the network device in the direction from the source PE to the network device. Sending the generated VPN Prefix ORF entry to the upstream device allows for VPN route filtering at the upstream device. The network device can also mark corresponding stored VPN Prefix ORF entries as not to be matched when sending the generated VPN Prefix ORF entry, thus saving resources.
[0060] In some embodiments, the generated VPNPrefix ORF entry is sent to the device at the next-hop address via a Border Gateway Router Refresh (BGP ROUTE REFRESH) message.
[0061] like Figure 2 As shown, in the Option B cross-domain scenario, RR1 sends the generated VPN Prefix ORF entry to ASBR1 via a BGP ROUTE REFRESH message. Upon receiving this VPN Prefix ORF entry, ASBR1 stops sending VPN routes matching the filtering conditions to RR1. Since RR1 is ASBR1's only directly connected iBGP neighbor, ASBR1 also generates a VPN Prefix ORF entry carrying the corresponding filtering conditions (RD=RD1, Source PE=IP4, RT=RT1) and sends it to ASBR2 via a BGP ROUTE REFRESH message. Upon receiving this VPN Prefix ORF entry, ASBR2 stops sending VPN routes matching the filtering conditions to ASBR1.
[0062] like Figure 3 As shown, in the cross-domain scenario of Option C, RR1 sends the generated VPN Prefix ORF entry to RR2 via a BGP ROUTE REFRESH message. After receiving the VPN Prefix ORF entry, RR2 stops sending VPN routes that meet the filtering conditions to RR1.
[0063] In some embodiments, for a network device with multiple IBGP neighbors, the network device can first determine whether there are VPN Prefix ORF entries with the same filtering conditions but different sending devices. If so, it determines the next-hop address corresponding to the source PE in the filtering conditions, and determines whether the sending device of the VPN Prefix ORF entry with the same filtering conditions includes all IBGP neighbors of the network device other than the device with the next-hop address. If so, it generates a VPN Prefix ORF entry, including the filtering conditions corresponding to the source PE, and sends the generated VPN Prefix ORF entry to the upstream device (the device with the next-hop address corresponding to the source PE).
[0064] In some embodiments, for a network device with only one IBGP neighbor, after receiving a VPNPrefix ORF entry, the network device can directly generate a VPN Prefix ORF entry, including the filtering conditions corresponding to the source PE, and send the generated VPN Prefix ORF entry to the upstream device.
[0065] In some embodiments, the network device may determine whether the device corresponding to the next-hop address of the source PE in the filtering conditions of the received VPN Prefix ORF entry is a device within the same AS. If so, it may determine whether the sending device of the VPN Prefix ORF entry with the same filtering conditions includes all IBGP neighbors of the network device other than the device of the next-hop address. If so, it may generate a VPN Prefix ORF entry including the filtering conditions corresponding to the source PE and send the generated VPN Prefix ORF entry to the upstream device. Otherwise, it may directly generate a VPN Prefix ORF entry including the filtering conditions corresponding to the source PE and send the generated VPN Prefix ORF entry to the upstream device.
[0066] The upstream device filters VPN routes that meet the filtering criteria based on the received VPN Prefix ORF entries.
[0067] In the above embodiments, the network device determines the sending device of the stored VPN Prefix ORF entries and the next-hop address corresponding to the source PE in the filtering conditions. If the sending device of the VPN Prefix ORF entry with the same filtering conditions includes all IBGP neighbors of the network device other than the device at the next-hop address, then the VPN Prefix ORF entry is generated and sent to the device at the next-hop address, whereby the next-hop device filters the VPN route of the source PE. In this way, the network device filters VPN routes directly upstream of the network device without sending VPN routes that meet the filtering conditions to any downstream devices. This eliminates the need for repeated local judgment of filtering conditions, reducing its processing pressure, saving resources, and further pushing the route filtering work to the VPN route sending end, thereby improving overall resource utilization.
[0068] This disclosure also provides a network device, which is described below in conjunction with... Figure 4 Describe it.
[0069] Figure 4 This is a structural diagram of some embodiments of the network device disclosed herein. For example... Figure 4 As shown, the network device 40 in this embodiment includes a generation module 420 and a transmission module 430. In some embodiments, the network device 40 may further include a determination module 410.
[0070] The determination module 410 is used to determine the next-hop address corresponding to the source operator device (PE) in the sending device and filtering conditions of the stored VPN Prefix ORF entry, wherein the next-hop address is the next-hop address of the network device in the direction of the source PE.
[0071] In some embodiments, the determining module 410 is used to determine the port field corresponding to the stored VPNPrefix ORF entry in the egress route filter policy table; and to determine the sending device of the stored VPN Prefix ORF entry based on the value of the port field corresponding to the stored VPN Prefix ORF entry.
[0072] In some embodiments, the filtering criteria for the stored VPN Prefix ORF entries further include: the route identifier RD of the source PE and the route destination RT.
[0073] In some embodiments, the determining module 410 is used to look up the next-hop address corresponding to the source PE in the forwarding information base table.
[0074] The generation module 420 is used to generate VPN Prefix ORF entries in the case where the sending device of the VPN Prefix ORF entry with the same filtering conditions includes all internal border gateway IBGP neighbors of the network device other than the device with the next-hop address, wherein the filtering conditions in the generated VPN Prefix ORF entry include the address of the source PE.
[0075] In some embodiments, in Option B scenario, the network device is a route reflector (RR), the device with the next-hop address is an Autonomous System Border Router (ASBR) within its Autonomous System (AS), or the network device is an ASBR, the device with the next-hop address is an ASBR within an adjacent AS, and the sending device of the VPN Prefix ORF entry with the same filtering condition includes all internal border gateway (IBGP) neighbors of the network device other than the device with the next-hop address: when the network device is an RR, the sending device of the VPN Prefix ORF entry with the same filtering condition includes all PEs within the AS where the RR is located; or when the network device is an ASBR, the sending device of the VPN Prefix ORF entry with the same filtering condition is an RR within the AS where the ASBR is located.
[0076] In some embodiments, in Option C scenario, the network device is a route reflector (RR), the device with the next-hop address is an RR within an adjacent autonomous system (AS), and the sending device of the VPN Prefix ORF entry with the same filtering condition includes all internal border gateway protocol (IBGP) neighbors of the network device other than the device with the next-hop address. This includes cases where the sending device of the VPN Prefix ORF entry with the same filtering condition includes all PEs within the AS where the RR is located.
[0077] In some embodiments, the filtering conditions in the generated VPN Prefix ORF entry may also include: the route identifier RD of the source PE and the route destination RT.
[0078] The sending module 430 is used to send the generated VPN Prefix ORF entry to the device at the next-hop address so that the device at the next-hop address can filter the VPN route of the source PE.
[0079] In some embodiments, the sending module 430 is used to send the generated VPNPrefix ORF entry to the device at the next-hop address via a border gateway routing refresh message.
[0080] In some embodiments, the network device 40 further includes: a receiving module 440, configured to receive VPNPrefix ORF entries sent by a sending device; and a storage module 450, configured to determine whether the received VPN Prefix ORF entries have been stored; and to store the received VPN Prefix ORF entries if they have not been stored.
[0081] The network devices in the embodiments of this disclosure can be implemented by various computing devices or computer systems, as described below. Figure 5 as well as Figure 6 Describe it.
[0082] Figure 5 This is a structural diagram of some embodiments of the network device disclosed herein. For example... Figure 5 As shown, the network device 50 of this embodiment includes a memory 510 and a processor 520 coupled to the memory 510. The processor 520 is configured to execute a virtual private network routing control method in any of the embodiments of this disclosure based on instructions stored in the memory 510.
[0083] The memory 510 may include, for example, system memory, fixed non-volatile storage media, etc. The system memory may store, for example, an operating system, application programs, a boot loader, a database, and other programs.
[0084] Figure 6 This is a structural diagram of some other embodiments of the network device disclosed herein. For example... Figure 6 As shown, the network device 60 in this embodiment includes a memory 610 and a processor 620, which are similar to the memory 510 and processor 520, respectively. It may also include an input / output interface 630, a network interface 640, a storage interface 650, etc. These interfaces 630, 640, 650, and the memory 610 and processor 620 can be connected, for example, via a bus 660. The input / output interface 630 provides a connection interface for input / output devices such as a display, mouse, keyboard, and touchscreen. The network interface 640 provides a connection interface for various networked devices, such as connecting to a database server or cloud storage server. The storage interface 650 provides a connection interface for external storage devices such as SD cards and USB flash drives.
[0085] This disclosure also provides a communication system, which is described below in conjunction with... Figure 7 Describe it.
[0086] Figure 7 These are structural diagrams of some embodiments of the communication device disclosed herein. Figure 7As shown, the communication device 7 in this embodiment includes: network devices 40 / 50 / 60 of any of the foregoing embodiments, as well as transmitting device 72 and receiving device 74.
[0087] Sending device 72 is used to send VPN Prefix ORF entries to network devices.
[0088] The receiving device 74 is used to receive VPN Prefix ORF entries sent by the network device and filter VPN routes based on the received VPN Prefix ORF entries. The receiving device is the device with the next-hop address corresponding to the source operator device PE in the filtering conditions of the VPN Prefix ORF entries sent by the network device. The next-hop address is the next-hop address of the network device in the direction of the source PE.
[0089] Receiving device 74 is an upstream device of the network device in the direction from the source PE to the network device. The network device, transmitting device, and receiving device may be different for different scenarios. For details, please refer to the description of the foregoing embodiments, which will not be repeated here.
[0090] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more computer-usable non-transitory storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0091] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0092] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0093] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0094] The above description is only a preferred embodiment of this disclosure and is not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the protection scope of this disclosure.
Claims
1. A method for controlling routing in a virtual private network, executed by a network device, comprising: In the case where the sending device of the VPN Prefix ORF entry with the same filtering condition includes all internal border gateway (IBGP) neighbors of the network device except for the device with the next-hop address, a VPN Prefix ORF entry is generated, wherein the next-hop address is the next-hop address of the network device in the direction of the source PE in the same filtering condition, and the filtering condition in the generated VPN Prefix ORF entry includes the address of the source PE. The generated VPN Prefix ORF entry is sent to the device at the next-hop address so that the device at the next-hop address can filter the VPN routes sent by the source PE.
2. The control method according to claim 1 further includes: Determine the next-hop address corresponding to the source PE in the sending device and filtering conditions of the stored VPN Prefix ORF entry.
3. The control method according to claim 2, wherein, The device that determines the transmission of the stored VPN Prefix ORF entries includes: In the egress route filter policy table, determine the port field corresponding to the stored VPN Prefix ORF entry; The sending device of the stored VPNPrefix ORF entry is determined based on the value of the port field corresponding to the stored VPNPrefix ORF entry.
4. The control method according to claim 2, wherein, The filtering conditions for the stored VPN Prefix ORF entries also include: the route identifier RD of the source PE and the route destination RT.
5. The control method according to claim 2, wherein, The next-hop address corresponding to the source PE in the filtering conditions of the stored VPN Prefix ORF entry includes: Look up the next-hop address corresponding to the source PE in the forwarding information base table.
6. The control method according to claim 1, wherein, In Option B scenario, the network device is a route reflector (RR), and the device with the next-hop address is an Autonomous System Border Router (ASBR) within the same Autonomous System (AS), or the network device is an ASBR, and the device with the next-hop address is an ASBR within a neighboring AS. The sending devices for VPN Prefix ORF entries under the same filtering conditions include all internal border gateway (IBGP) neighbors of the network device, excluding the device with the next-hop address. When the network device is an RR, the sending devices of the VPN Prefix ORF entries with the same filtering conditions include all PEs within the AS where the RR is located; or When the network device is an ASBR, the sending device for the VPN Prefix ORF entry with the same filtering conditions is the RR within the AS where the ASBR is located.
7. The control method according to claim 1, wherein, In Option C scenario, the network device is a route reflector (RR), and the device with the next-hop address is an RR within a neighboring Autonomous System (AS). The sending devices for VPN Prefix ORF entries under the same filtering conditions include all internal border gateway protocol (IBGP) neighbors of the network device, excluding the device with the next-hop address. The sending devices for VPN Prefix ORF entries with the same filtering conditions include all PEs within the AS where the RR is located.
8. The control method according to claim 1, wherein, The filtering conditions in the generated VPN Prefix ORF entry also include: the route identifier RD of the source PE and the route destination RT.
9. The control method according to claim 1, wherein, The device that sends the generated VPN Prefix ORF entry to the next-hop address includes: The generated VPN Prefix ORF entry is sent to the device at the next-hop address via a border gateway route refresh message.
10. The control method according to any one of claims 1-9, further comprising: Receive VPN Prefix ORF entries sent by the sending device; Determine if the received VPN Prefix ORF entry has been stored; If the received VPN Prefix ORF entry is not stored, the received VPN Prefix ORF entry will be stored.
11. A network device, comprising: A generation module is used to generate VPN Prefix ORF entries when the sending device of a VPNPrefix ORF entry with the same filtering condition includes all internal border gateway (IBGP) neighbors of the network device other than the device with the next-hop address. The next-hop address is the next-hop address of the network device in the direction of the source PE in the same filtering condition, and the filtering condition in the generated VPN Prefix ORF entry includes the address of the source PE. The sending module is used to send the generated VPN Prefix ORF entry to the device at the next-hop address, so that the device at the next-hop address can filter the VPN route sent by the source PE.
12. A network device, comprising: processor; as well as A memory coupled to the processor is used to store instructions that, when executed by the processor, cause the processor to perform the virtual private network routing control method as described in any one of claims 1-10.
13. A non-transitory computer-readable storage medium having a computer program stored thereon, wherein, When executed by a processor, the program implements the steps of the method according to any one of claims 1-10.
14. A communication system, comprising: The network device as described in claim 11 or 12; as well as A transmitting device for sending VPN Prefix ORF entries to the network device; A receiving device is configured to receive VPN Prefix ORF entries sent by the network device and filter VPN routes based on the received VPN Prefix ORF entries. The receiving device is the device with the next-hop address corresponding to the source operator device (PE) in the filtering conditions of the VPN Prefix ORF entries sent by the network device, and the next-hop address is the next-hop address of the network device in the direction of the source PE.
Citation Information
Patent Citations
Method and device for routing filter based on BGP protocol
CN101155175A
Route configuration method, apparatus and device, and computer readable storage medium
CN112866031A