Method, system and related device for monitoring flow direction of VPN traffic in MPLS network
By generating LSP and VPN label information for VPN service flow data in MPLS networks, traffic flow classification information is generated, which solves the problem of low monitoring accuracy in existing technologies and realizes accurate traffic flow monitoring of VPN service flow data, adapting to diverse business scenarios.
Patent Information
- Application Number
- CN202411998300.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2044-12-31
AI Technical Summary
Existing technologies cannot accurately monitor the traffic flow of VPN services in MPLS networks, especially at the service level. Furthermore, Netflow V9 technology suffers from having too many monitoring fields and low monitoring accuracy.
By generating traffic flow classification information containing LSP label information and VPN label information for VPN service flow data in MPLS networks, the traffic flow direction of different VPN service flow data is marked, and they are scheduled to the corresponding monitoring queues. The VPN service flow data of each monitoring queue is counted to obtain the traffic flow direction monitoring results.
It enables accurate monitoring of VPN service flow data in MPLS networks across various traffic flows, improving monitoring accuracy and flexibility, and adapting to the monitoring needs of different service flows.
Smart Images

Figure CN119788618B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network, and particularly relates to a VPN traffic flow direction monitoring method and system in MPLS network and related equipment. BACKGROUND
[0002] With the development of MPLS VPN service in global operators, the requirement of VPN service is higher and higher, especially for high-end customers, it is needed to provide VPN service information flow analysis service to customers. At present, the service of monitoring the size of traffic of service port is provided for VPN users, which cannot meet the end-to-end traffic monitoring requirement of customers.
[0003] At present, the monitoring method of VPN traffic flow direction is Netflow V9 technology. The technology effectively records and analyzes the one-way packet flow transmitted between a source address and a destination address through the template-based statistical data output mode, and all packets share the same source port number and destination port number in the transmission layer. Netflow V9 is analyzed by collecting data in the preset field (about 100 fields) in the packet, which has the problem of large data volume. Moreover, the monitoring can only be based on the physical port or the whole traffic, and the network traffic flow direction monitoring in the service dimension cannot be realized, and the monitoring precision is low.
[0004] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information which does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0005] The present disclosure provides a VPN traffic flow direction monitoring method and system in MPLS network and related equipment, which at least partly overcomes the technical problems of multiple monitoring fields and low monitoring precision in the VPN traffic flow direction monitoring scheme in MPLS network.
[0006] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.
[0007] According to one aspect of the present disclosure, a method for monitoring traffic flow direction of VPN service in an MPLS network is provided, comprising: generating traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, wherein the traffic flow direction classification information is used to mark each traffic flow direction of different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue; scheduling different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data; and counting the VPN service flow data transmitted in each monitoring queue to obtain a monitoring result of VPN service traffic flow direction of the MPLS network; wherein the LSP label information is LSP label information used to identify a label switched path (LSP) in the MPLS network and is obtained through a label distribution protocol (LDP) message; and the VPN label information is VPN service label information used to identify a VPN service instance in a VPN network and is obtained through a border gateway protocol (BGP) message.
[0008] In some embodiments, generating the traffic flow direction classification information containing the LSP label information and the VPN label information for different VPN service flow data in the MPLS network comprises: obtaining VPN service flow monitoring configuration information, wherein the VPN service flow monitoring configuration information is used to configure to-be-monitored VPN service information and / or to-be-monitored traffic flow direction information; and determining field information of a label switched path (LSP) identification and / or service label identification monitoring field between MPLS network node devices in a monitoring field according to the service flow monitoring configuration information, i.e., generating the traffic flow direction classification information containing the LSP label information and the VPN label information.
[0009] In some embodiments, after determining the field information of the LSP identification and / or the service label identification monitoring field between the MPLS network node devices in the monitoring field according to the service flow monitoring configuration information, the method further comprises: monitoring whether the VPN service flow monitoring configuration information is changed; and if the VPN service flow monitoring configuration information is changed, updating the field information of the LSP identification and / or the service label identification monitoring field between the MPLS network node devices in the monitoring field according to the changed service flow monitoring configuration information.
[0010] In some embodiments, after determining the field information of the inter-network node device label switched path identification and / or service label identification monitoring field in the monitoring field according to the service flow monitoring configuration information, the method further comprises: monitoring whether the MPLS network signaling message and / or the VPN service routing signaling message changes; if the MPLS network signaling message and / or the VPN service routing signaling message changes, updating the field information of the MPLS network node device inter-path identification and / or the VPN service identification monitoring field in the monitoring field according to the changed MPLS network signaling message and / or the VPN service routing signaling message.
[0011] In some embodiments, the VPN service flow direction monitoring result of the MPLS network comprises at least one of: a VPN service flow direction byte number statistical result, a VPN service flow direction data packet number statistical result, and a VPN service flow direction flow rate statistical result.
[0012] In some embodiments, after obtaining the VPN service flow data transmitted in each monitoring queue and obtaining the VPN service flow direction monitoring result of the MPLS network, the method further comprises: obtaining a customized data reporting model, wherein the data reporting model uses an on-demand collection and active pushing manner to report data; and using the data reporting model to encapsulate and report the VPN service flow direction monitoring result of the MPLS network.
[0013] In some embodiments, the VPN service flow data comprises at least one of: service flow data of a single VPN service in a single flow direction, service flow data of a single VPN service in multiple flow directions, and service flow data of multiple VPN services in multiple flow directions.
[0014] In some embodiments, the VPN service flow data comprises at least one of: service flow data of a single VPN service in a single flow direction, service flow data of a single VPN service in multiple flow directions, and service flow data of multiple VPN services in multiple flow directions.
[0015] In some embodiments, before generating the traffic flow direction classification information containing the LSP label information and the VPN label information for different VPN service flow data in the MPLS network, the method further comprises: if the VPN service flow data is service flow data of a single VPN service instance on a single traffic flow direction, obtaining, as the VPN label information in the traffic flow direction classification information, Loopback addresses of a single destination device involved by the VPN service instance and VPN service routing information involved by the VPN service instance in a BGP message through ingress direction routing configuration parameters configured by the VPN service instance; and obtaining, as the LSP label information in the traffic flow direction classification information, LSP label information of the single destination device in an LDP message through the Loopback addresses of the single destination device involved by the VPN service instance; if the VPN service flow data is service flow data of a single VPN service instance on multiple traffic flow directions, obtaining, as the VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved by the VPN service instance and VPN service routing information involved by the VPN service instance in a BGP message through ingress direction routing configuration parameters configured by the VPN service instance; and obtaining, as the LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved by the VPN service instance in an LDP message through the Loopback addresses of the multiple destination devices involved by the VPN service instance; if the VPN service flow data is service flow data of multiple VPN service instances on multiple traffic flow directions, obtaining, as the VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved by each VPN service instance and VPN service routing information involved by each VPN service instance in a BGP message through ingress direction routing configuration parameters configured by each VPN service instance; and obtaining, as the LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved by each VPN service instance in an LDP message through the Loopback addresses of the multiple destination devices involved by each VPN service instance.
[0016] In some embodiments, before generating the traffic flow direction classification information containing the LSP label information and the VPN label information for different VPN service flow data in the MPLS network, the method further comprises: if the VPN service routing signaling message changes, updating the VPN label information in the traffic flow direction classification information; and if the MPLS network signaling message changes, updating the LSP label information in the traffic flow direction classification information.
[0017] According to another aspect of the present disclosure, a device for monitoring traffic flow direction of VPN service in an MPLS network is also provided, comprising: a VPN service flow data monitoring module configured to generate traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, wherein the traffic flow direction classification information is used to mark each traffic flow direction of different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue; a VPN service flow data scheduling module configured to schedule different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data; and a VPN service flow data statistics module configured to count the VPN service flow data transmitted in each monitoring queue to obtain a monitoring result of VPN service traffic flow direction of the MPLS network; wherein the LSP label information is LSP label information used to identify a label switched path (LSP) in the MPLS network obtained through a label distribution protocol (LDP) message; and the VPN label information is VPN service label information used to identify a VPN service instance in a VPN network obtained through a border gateway protocol (BGP) message.
[0018] According to another aspect of the present disclosure, a system for monitoring traffic flow direction of VPN service in an MPLS network is also provided, comprising: a source router, a destination router and a monitoring controller; wherein the source router is configured to generate traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network after receiving VPN service flow data in the MPLS network, and schedule different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data, wherein the traffic flow direction classification information is used to mark each traffic flow direction of different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue; and the monitoring controller is configured to count the VPN service flow data transmitted in each monitoring queue to obtain a monitoring result of VPN service traffic flow direction of the MPLS network; wherein the LSP label information is LSP label information used to identify a label switched path (LSP) in the MPLS network obtained through a label distribution protocol (LDP) message; and the VPN label information is VPN service label information used to identify a VPN service instance in a VPN network obtained through a border gateway protocol (BGP) message.
[0019] In some embodiments, the system further comprises: a user terminal device in communication with the monitoring controller, configured to receive the monitoring result of VPN service traffic flow direction of the MPLS network reported by the monitoring controller; wherein the monitoring controller is further configured to use a custom data reporting model to package and report the monitoring result of VPN service traffic flow direction of the MPLS network.
[0020] According to another aspect of the present disclosure, an electronic device is also provided, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to perform the MPLS network VPN traffic flow monitoring method according to any one of the preceding aspects by executing the executable instructions.
[0021] According to another aspect of the present disclosure, a computer readable storage medium having stored thereon a computer program is also provided, the computer program, when executed by a processor, implements the MPLS network VPN traffic flow monitoring method according to any one of the preceding aspects.
[0022] According to another aspect of the present disclosure, a computer program product is also provided, comprising: a computer program or instructions, the computer program or instructions, when executed by a processor, implements the MPLS network VPN traffic flow monitoring method according to any one of the preceding aspects.
[0023] The MPLS network VPN traffic flow monitoring method, system and related device provided in the embodiments of the present disclosure, by generating flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, to mark each flow direction of different VPN service flow data, so that each flow direction corresponds to a monitoring queue, and then according to the flow direction classification information of different VPN service flow data, different VPN service flow data is scheduled to the monitoring queue of the corresponding flow direction, and finally the VPN service flow data transmitted in each monitoring queue is counted to obtain the VPN service traffic flow monitoring result of the MPLS network.
[0024] Through the embodiments of the present disclosure, the accurate monitoring of the data situation of the VPN service flow data in the MPLS network in each flow direction can be realized.
[0025] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0026] The accompanying drawings incorporated in and forming a part of the specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the disclosure. It is expressly understood that the drawings are only exemplary of some embodiments of the present disclosure, and that, as such, they should not be too narrowly construed. Persons skilled in the art, with access to the drawings, will be able to appreciate variations and alternatives in the embodiments of the present disclosure.
[0027] Figure 1 A packet header format diagram of a data packet when network traffic monitoring is performed using the Netflow V9 technology in the related art is shown;
[0028] Figure 2 A flow chart of a method for monitoring traffic flow direction of VPN service in MPLS network is shown in the embodiments of the present disclosure;
[0029] Figure 3 A flow chart of an alternative method for monitoring traffic flow direction of VPN service in MPLS network is shown in the embodiments of the present disclosure;
[0030] Figure 4 A flow chart of adding traffic flow direction classification information in service flow data is shown in the embodiments of the present disclosure;
[0031] Figure 5 A schematic diagram of a system for monitoring traffic flow direction of MPLS layer 3 VPN service is shown in the embodiments of the present disclosure;
[0032] Figure 6 A flow chart of a method for monitoring traffic flow direction of MPLS layer 3 VPN service is shown in the embodiments of the present disclosure;
[0033] Figure 7 A schematic diagram of a process for obtaining traffic flow direction classification information is shown in the embodiments of the present disclosure;
[0034] Figure 8 A schematic diagram of a process for scheduling different VPN service flow data to corresponding traffic flow direction monitoring queue based on traffic flow direction classification information is shown in the embodiments of the present disclosure;
[0035] Figure 9 A schematic diagram of a device for monitoring traffic flow direction of VPN service in MPLS network is shown in the embodiments of the present disclosure;
[0036] Figure 10 A schematic diagram of a system for monitoring traffic flow direction of VPN service in MPLS network is shown in the embodiments of the present disclosure;
[0037] Figure 11 A structural block diagram of an electronic device is shown in the embodiments of the present disclosure. DETAILED DESCRIPTION
[0038] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations can be implemented in any
[0039] In addition, the accompanying drawings are merely schematic and are not intended to be drawn to scale. Identical reference numerals denote like or similar elements throughout the several views, and thus repeated description thereof will be omitted. Some of the blocks in the drawings are functional entities that do not necessarily have to correspond to physically or logically independent entities. These functional entities can be implemented in software, or in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0040] For the convenience of understanding, before introducing the embodiments of the present disclosure, first, several terms involved in the embodiments of the present disclosure are explained as follows:
[0041] MPLS: Multi-Protocol Label Switching, a new technology for high-speed and efficient transmission of data in an open communication network using label guidance. Multi-protocol refers to the fact that MPLS not only supports multiple network layer (third layer) protocols, but also can be compatible with multiple data link layer (second layer) technologies.
[0042] VPN: Virtual Private Network, a private network established on a public network, which can provide encrypted communication services. It is widely used in enterprise networks. VPN gateways achieve remote access by encrypting data packets and converting destination addresses. VPN can be implemented through servers, hardware, software, and other ways.
[0043] LDP: Label Distribution Protocol, a key protocol in MPLS networks. In MPLS networks, two label switching routers (LSRs) must agree on the labels they use to forward traffic between them or through them.
[0044] VRF: Virtual Routing Forwarding, also known as VPN service instance. The PE (Provider Edge Router, provider edge router) establishes and maintains a dedicated entity for directly connected sites (Site). Each site has its own VPN service instance on the PE, and each VPN service instance contains one or more routing and forwarding tables for the CE (Customer Edge Router, customer edge router) directly connected to the PE. To enable intercommunication between sites within the same VPN, the VPN service instance also contains routing information for sites belonging to the same VPN located on other PEs.
[0045] The specific embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings.
[0046] As introduced in the part of the background of the present disclosure, the current network traffic monitoring means generally adopts NetFlow V9 technology. Figure 1 The packet header format of a data packet when network traffic is monitored by using the Netflow V9 technology in the related art is shown as follows: Figure 1 As shown in the figure, the meanings of the fields are described as follows:
[0047] Version Number: the data stream record format version number of the output data packet.
[0048] Count: the total number of template, information, and optional template summary records in the output data packet.
[0049] SysUpTime: the running time (millisecond level count) of the device after being enabled.
[0050] UNIX Secs: the time (second level count) experienced by the output data packet after being sent out by the exporter.
[0051] Sequence Number: the sequence number is accumulated with the number of data packets output by the exporter in a certain observation field, which can be used by the collector to determine whether there is a phenomenon of missing output data packets.
[0052] Source ID: indicates the observation field where the exporter is located (uses a 32-bit value to represent), and the collector can distinguish different output streams output by the same exporter according to the source IP address and the Source ID field of the data packet.
[0053] In actual application, the NetFlow V9 technology has some disadvantages as follows:
[0054] 1) The NetFlow V9 technology cannot monitor the VPN service of a specific customer, which limits its application in specific service scenarios.
[0055] 2) When the NetFlow V9 technology is used to monitor network traffic, a large number of monitoring fields are required, the mechanism is complex, and the device performance requirement is high. In actual operation, in order to reduce the burden of the device, the technology will use a sampling monitoring method to monitor network traffic. Although this sampling monitoring method can reflect the condition of network traffic to a certain extent, the sampling result is often not accurate enough, especially in the case of large network traffic, such as using a sampling ratio of 1000:1 or 5000:1 for monitoring, which will greatly reduce the accuracy of traffic monitoring.
[0056] 3) NetFlow V9 technology needs to regenerate the corresponding NetFlow V9 table when monitoring network traffic, which increases the complexity and maintenance cost of the operation of the existing network monitoring.
[0057] Therefore, the current NetFlow V9 technology has the problems of low monitoring accuracy and high operation and maintenance cost when monitoring network traffic.
[0058] With the continuous development of MPLS VPN services, the requirements of VPN service are getting higher and higher, especially for high-end customers, it is necessary to provide VPN service traffic flow analysis service to customers. For MPLS VPN service traffic flow monitoring, the current traffic flow monitoring method using NetFlow V9 technology can only monitor physical ports or the whole machine, and there are a lot of irrelevant data in the collection process, which requires high requirements for equipment and system, and the low accuracy caused by proportional sampling makes it difficult to be applied in operators; and because it cannot monitor the traffic flow of a single VPN service, it cannot meet the requirements of traffic flow monitoring and analysis of different levels.
[0059] To realize the accurate monitoring of traffic flow in the service dimension, the present embodiment provides a VPN service traffic flow monitoring scheme in an MPLS network, which defines new traffic flow classification information to mark each traffic flow of VPN service flow data, so that each traffic flow corresponds to a monitoring queue, and then according to the traffic flow classification information of different VPN service flow data, the different VPN service flow data is scheduled to the monitoring queue of the corresponding traffic flow, and finally the VPN service flow data transmitted in each monitoring queue is counted to obtain the VPN service traffic flow monitoring result of the MPLS network. Through the present embodiment, the accurate monitoring of each traffic flow of service flow data can be realized.
[0060] Figure 1 An exemplary application system architecture schematic diagram to which the method in the present embodiment can be applied is shown. As shown in the figure, the system architecture can include a terminal device 101, a network 102 and a server 103. Figure 1
[0061] The network 102 is a medium for providing a communication link between the terminal device 101 and the server 103, which can be a wired network or a wireless network.
[0062] Optionally, the wireless or wired networks described above use standard communications technologies and / or protocols. The network can be the Internet, but can also include any combination of LANs, MANs, WANs, mobile, wired, or wireless networks, networks of networks, and / or intranets. In some embodiments, technologies used include, without limitation, Hypertext Markup Language (HTML), Extensible Markup Language (XML), and / or the like, to create and transmit data over the network. In addition, conventional encryption technologies such as the Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Networks (VPNs), Internet Protocol Security (IPSec), and / or the like, can be used to encrypt all or some of the links between nodes in the network. In other embodiments, custom and / or proprietary data communications technologies can be used in place of, or in addition to, the above technologies.
[0063] The terminal device 101 can be various electronic devices, including but not limited to a smartphone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a wearable device, an augmented reality device, a virtual reality device, and the like.
[0064] Optionally, the application clients installed in different terminal devices 101 are the same, or are clients of the same type of application based on different operating systems. Depending on the terminal platform, the specific form of the application client can also be different, for example, the application client can be a mobile phone client, a PC client, and the like.
[0065] The server 103 can be a server that provides various services, for example, a background management server that provides support for the device operated by the user using the terminal device 101. The background management server can analyze and process received request data and the like, and feed back the processing result to the terminal device.
[0066] Optionally, the server can be a stand-alone physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud service, cloud database, cloud computing, cloud function, cloud storage, network service, cloud communication, middleware service, domain name service, security service, CDN (Content Delivery Network), and basic cloud computing services such as big data and artificial intelligence platform.
[0067] Those skilled in the art can know that, Figure 1 The number of terminal devices, networks and servers in the above system architecture is only illustrative, and can have any number of terminal devices, networks and servers according to actual needs. The embodiments of the present disclosure do not limit this.
[0068] Those skilled in the art can know that, Figure 1 The number of terminals, networks and network side devices in the above system architecture is only illustrative, and can have any number of terminals, networks and network side devices according to actual needs. The embodiments of the present disclosure do not limit this.
[0069] Under the above system architecture, the present disclosure provides a VPN traffic flow monitoring method in an MPLS network, which can be executed by any electronic device with computing processing capability.
[0070] In some embodiments, the MPLS network VPN traffic flow monitoring method provided in the embodiments of the present disclosure can be executed by the terminal device of the above system architecture; in other embodiments, the MPLS network VPN traffic flow monitoring method provided in the embodiments of the present disclosure can be executed by the server in the above system architecture; in other embodiments, the MPLS network VPN traffic flow monitoring method provided in the embodiments of the present disclosure can be realized by the terminal device and the server in the above system architecture through interaction.
[0071] Figure 2 A flow chart of a VPN traffic flow monitoring method in an MPLS network is shown in the embodiments of the present disclosure, as shown in Figure 2 The MPLS network VPN traffic flow monitoring method provided in the embodiments of the present disclosure can include the following steps:
[0072] S202, generating traffic flow classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, wherein the traffic flow classification information is used to mark each traffic flow direction of different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue.
[0073] It should be noted that the traffic flow direction classification information in the embodiments of the present disclosure is newly defined information that can be used to mark each traffic flow direction of the VPN service flow data in the MPLS network. Different service flow data, different traffic flow directions, and different traffic flow direction classification information. The traffic flow direction classification information defined in the embodiments of the present disclosure refers to information that can distinguish different services and different traffic flow directions. For different service flow data, different traffic flow direction classification information can be defined.
[0074] In some embodiments, when the service flow data to be monitored is MPLS VPN data (VPN service flow data in the MPLS network), the traffic flow direction classification information defined in the embodiments of the present disclosure is determined by the LSP label information used to identify the LSP in the MPLS network and the VPN service label information used to identify the VPN service instance in the VPN network. To meet the diversified monitoring scenarios of service traffic flow direction, in specific implementation, the traffic flow direction classification information can be defined as the combination information composed of LSP label information and VPN label information, wherein the LSP label information represents the LSP label information used to identify the LSP in the MPLS network, and the VPN label information represents the VPN service label information used to identify the VPN service instance in the VPN network.
[0075] S204, according to the traffic flow direction classification information of different VPN service flow data, the different VPN service flow data is scheduled into the monitoring queue of the corresponding traffic flow direction.
[0076] In the embodiments of the present disclosure, the VPN service flow data can be, but is not limited to, any one of the following: ① service flow data of a single VPN service in a single traffic flow direction; ② service flow data of a single VPN service in multiple traffic flow directions; and ③ service flow data of multiple VPN services in multiple traffic flow directions. To meet the diversified service monitoring scenarios, a corresponding monitoring queue can be created for each traffic flow direction of each service, so as to schedule different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data.
[0077] S206, the VPN service flow data transmitted in each monitoring queue is counted to obtain the VPN service traffic flow direction monitoring result of the MPLS network.
[0078] It should be noted that after the different VPN service flow data is scheduled into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data, the VPN service flow data transmitted in each monitoring queue is counted, and the data situation of any one service in any one traffic flow direction can be obtained.
[0079] In some embodiments, the VPN traffic flow direction monitoring result of the MPLS network in the embodiments of the present disclosure includes, but is not limited to, any one or more of the following: a traffic flow direction byte number statistical result, a traffic flow direction packet number statistical result, and a traffic flow direction flow rate statistical result.
[0080] In some embodiments, as shown in FIG. 8, after the VPN traffic flow direction monitoring result of the MPLS network is obtained by counting the VPN service flow data transmitted in each monitoring queue, the VPN traffic flow direction monitoring method in the MPLS network provided in the embodiments of the present disclosure can further include the following steps: Figure 3
[0081] S208, obtaining a customized data reporting model, the data reporting model reporting data in a manner of on-demand collection and active pushing.
[0082] S210, encapsulating and reporting the VPN traffic flow direction monitoring result of the MPLS network by using the data reporting model.
[0083] It should be noted that the data reporting model in the embodiments of the present disclosure is a pre-defined structured data model for collecting and reporting data, and the data (the VPN traffic flow direction monitoring result of the MPLS network) to be reported can be encapsulated according to the format of the data reporting model.
[0084] In some embodiments, the VPN traffic flow direction monitoring method in the MPLS network provided in the embodiments of the present disclosure can collect the VPN traffic flow direction monitoring result of the MPLS network by using a YANG data model and encapsulate the result; and report the encapsulated data based on a Telemetry data reporting mechanism.
[0085] YANG (Yet Another Next Generation) is a data modeling language, which, as a machine-oriented model interface, clearly defines data structures and their constraints, and can more flexibly and completely describe data. Telemetry, also known as Network Telemetry, is a technology for collecting data at a high speed from physical devices or virtual devices. These physical devices or virtual devices periodically and actively report data to collectors in a push mode, and compared with the traditional pull mode of data reporting, this technology can provide more real-time and high-speed data collection functions. Telemetry only needs to be configured once, and the device can continuously report data, thereby reducing the pressure of the device to process query requests.
[0086] In some embodiments, the LSP label information in the traffic flow classification information is acquired through a label distribution protocol (LDP) message, and the VPN label information in the traffic flow classification information is acquired through a border gateway protocol (BGP) message.
[0087] In some embodiments, before the traffic flow classification information containing the LSP label information and the VPN label information is generated for different VPN service flow data in the MPLS network, the MPLS network VPN service traffic flow monitoring method provided in the embodiments of the present disclosure can further include: if a VPN service routing signaling message changes, updating the VPN label information in the traffic flow classification information; and if an MPLS network signaling message changes, updating the LSP label information in the traffic flow classification information.
[0088] In some embodiments, as shown in FIG. 5, the MPLS network VPN service traffic flow monitoring method provided in the embodiments of the present disclosure can generate the traffic flow classification information containing the LSP label information and the VPN label information for different VPN service flow data in the MPLS network through the following steps: Figure 4
[0089] S402, acquiring VPN service flow monitoring configuration information, wherein the service flow monitoring configuration information is used to configure to-be-monitored service information and / or to-be-monitored traffic flow information;
[0090] S404, determining the field information of the label switched path (LSP) identification and / or the service label identification in the monitoring field between the MPLS network node devices according to the VPN service flow monitoring configuration information, and generating the traffic flow classification information containing the LSP label information and the VPN label information.
[0091] It should be noted that the MPLS network VPN service traffic flow monitoring method provided in the embodiments of the present disclosure can realize the monitoring of a single VPN service on a single traffic flow (such as any one traffic flow of a certain service), the monitoring of a single VPN service on multiple traffic flows (such as all traffic flows of a certain service), and the monitoring of multiple VPN services on multiple traffic flows (such as all traffic flows of all services). In specific implementation, the to-be-monitored service information or the to-be-monitored traffic flow information can be configured through the service flow monitoring configuration information.
[0092] It should be noted that after the to-be-monitored service information and / or the to-be-monitored traffic flow information is configured through the service flow monitoring configuration information, the corresponding monitoring queue can be created according to the required service and / or traffic flow to be monitored. In some embodiments, in order to realize the flexible monitoring of the service and / or the traffic flow, one corresponding monitoring queue can be created for each traffic flow of each to-be-monitored service.
[0093] In some embodiments, after determining the field information of the label switched path identification and / or the service label identification monitoring field in the monitoring field according to the VPN service flow monitoring configuration information, and generating the LSP label information and the VPN label information for use in the traffic flow direction classification, the MPLS network VPN service traffic flow direction monitoring method provided in the embodiments of the present disclosure can further include the following steps as shown in Figure 4
[0094] S406, monitoring whether the service flow monitoring configuration information is changed;
[0095] S408, if the service flow monitoring configuration information is changed, updating the field information of the label switched path identification and / or the service label identification monitoring field in the monitoring field according to the changed service flow monitoring configuration information.
[0096] It should be noted that the change of the service flow monitoring configuration information can result in the change of the monitoring field to be monitored. Therefore, by monitoring whether the service flow monitoring configuration information is changed, and automatically updating the field information of the label switched path identification and / or the service label identification monitoring field in the monitoring field according to the changed service flow monitoring configuration information when the service flow monitoring configuration information is changed, and generating the LSP label information and the VPN label information for use in the traffic flow direction classification, the MPLS network VPN service traffic flow direction monitoring method provided in the embodiments of the present disclosure can quickly adapt to different monitoring requirements.
[0097] In some embodiments, after determining the field information of the label switched path identification and / or the service label identification monitoring field in the monitoring field according to the VPN service flow monitoring configuration information, and generating the LSP label information and the VPN label information for use in the traffic flow direction classification, the MPLS network VPN service traffic flow direction monitoring method provided in the embodiments of the present disclosure can further include the following steps as shown in Figure 4
[0098] S412, monitoring whether the MPLS network signaling message and / or the VPN service routing signaling message is changed;
[0099] S414, if the MPLS network signaling message and / or the VPN service routing signaling message is changed, updating the field information of the label switched path identification and / or the service label identification monitoring field in the monitoring field according to the changed MPLS network signaling message and / or the VPN service routing signaling message.
[0100] It should be noted that the network signaling message in the embodiment of the present disclosure can be various signaling messages related to network transmission data, and the change of the network signaling message can cause the field information of the path identifier between the network node devices to change; the service routing signaling message in the embodiment of the present disclosure can be various signaling messages related to network transmission service data, and the change of the service routing signaling message can cause the field information of the label switching path identifier and / or the service label identifier monitoring field between the MPLS network node devices in the service monitoring field to change, and the LSP label information and the VPN label information are generated to be used for the change of the traffic flow direction classification. Thus, in the embodiment of the present disclosure, by monitoring whether the MPLS network signaling message and / or the VPN service routing signaling message changes, and updating the field information of the label switching path identifier and / or the service label identifier monitoring field in the monitoring field in time when the MPLS network signaling message and / or the VPN service routing signaling message changes, the traffic flow direction classification information added in the VPN service flow data can be updated in time based on the updated monitoring field information, so that different VPN service flow data can be accurately scheduled to the monitoring queue of the corresponding traffic flow direction for statistical analysis based on the updated traffic flow direction classification information.
[0101] In some embodiments, when the service flow data to be monitored is MPLS VPN data, the LSP label information in the traffic flow direction classification information is obtained through a label distribution protocol LDP message, and the VPN label information in the traffic flow direction classification information is obtained through a border gateway protocol BGP message.
[0102] Specifically, the MPLS network VPN service traffic flow direction monitoring method provided in the embodiment of the present disclosure can obtain the LSP label information and the VPN label information through the following steps:
[0103] 1) If the VPN service flow data is service flow data of a single VPN service instance on a single traffic flow direction, the Loopback address of a single destination device related to the VPN service instance and the VPN service routing information are obtained in the BGP message as the VPN label information in the traffic flow direction classification information through the ingress direction routing configuration parameter configured by the VPN service instance, and the LSP label information of the destination device is obtained in the LDP message as the LSP label information in the traffic flow direction classification information through the Loopback address of the single destination device related to the VPN service instance;
[0104] 2) If the VPN service flow data is service flow data of a single VPN service instance in multiple traffic flow directions, the Loopback address and VPN service routing information of multiple destination devices involved in the VPN service instance are obtained in the BGP message as the VPN label information in the traffic flow direction classification information through the ingress direction routing configuration parameter configured by the VPN service instance; the LSP label information of the multiple destination devices involved in the VPN service instance is obtained in the LDP message as the LSP label information in the traffic flow direction classification information through the Loopback address of the multiple destination devices involved in the VPN service instance;
[0105] 3) If the VPN service flow data is service flow data of multiple VPN service instances in multiple traffic flow directions, the Loopback address and VPN service routing information of multiple destination devices involved in each VPN service instance are obtained in the BGP message as the VPN label information in the traffic flow direction classification information through the ingress direction routing configuration parameter configured by each VPN service instance; the LSP label information of the multiple destination devices involved in each VPN service instance is obtained in the LDP message as the LSP label information in the traffic flow direction classification information through the Loopback address of the multiple destination devices involved in each VPN service instance.
[0106] Further, in some embodiments, the MPLS network VPN service traffic flow direction monitoring method provided in the embodiments of the present disclosure can further include the following steps: if the VPN service routing signaling message changes, updating the VPN label information in the traffic flow direction classification information; if the MPLS network signaling message changes, updating the LSP label information in the traffic flow direction classification information.
[0107] Next, the MPLS network VPN service traffic flow direction monitoring method provided in the embodiments of the present disclosure is described in detail below by taking MPLS layer 3 VPN service as an example:
[0108] Table 1
[0109]
[0110]
[0111] As shown in Table 1, for MPLS three-layer VPN service, LSP label representing LSP label information and VPN label representing VPN service instance label information can be combined (the combination manner is not specifically limited in the embodiment of the present disclosure) to serve as classification information for distinguishing VPN service traffic flow direction, and through a mechanism associated with MPLS networking protocol and VPN service protocol processing, field information of the LSP label and the VPN label is obtained to realize L+V-based traffic classification processing, and the classified service flow data is scheduled to a corresponding monitoring queue for counting statistics and / or flow rate calculation; further, through tracking dynamic changes of service monitoring configuration information, network networking or service signaling messages, a dynamic updating processing mechanism of the traffic flow direction marking field is realized to achieve dynamic adaptation of traffic flow direction statistics, and finally, accurate and dynamic monitoring of traffic flow direction is achieved. Further, through defining a data reporting model and field of traffic statistics, based on a Telemetry reporting mechanism, the VPN service traffic flow direction monitoring result of the MPLS network is updated and reported to an NMS (Network Management System) in real time to realize accurate monitoring of service traffic flow direction.
[0112] Figure 5 A traffic flow direction monitoring system for MPLS three-layer VPN service in the embodiment of the present disclosure is shown in Figure 5 As shown, the Loopback address of source route A is 100.1.1.100, and the Loopback address of destination route B is 100.1.1.200; in the embodiment of the present disclosure, the traffic flow direction information of A-R3-R4-B link is taken as an example for illustration.
[0113] As a source router, source route A can adopt “L+V” two-dimensional field as traffic flow direction classification information to mark the traffic flow direction of VPN service from the source device to the destination device. The VPN service traffic flow direction monitoring method provided in the MPLS network in the embodiment of the present disclosure can be processed by the source device based on the VPN service instance, and taking source route A as an example, the following label combination is possible for the route to route B, route C and route D.
[0114] In the embodiment of the present disclosure, the subscript of the LSP label identifies the label information of the segment from the source route to the destination route; for example, from A route to B route, it is L AB The subscript of the VPN label identifies the outflow of the current route, which is identified by the outflow route and the VPN; for example, the outflow of A is represented as V Ax ; wherein x can be arbitrarily valued according to different VPN service instances.
[0115] Figure 6 A traffic flow direction monitoring method for MPLS three-layer VPN service in the embodiment of the present disclosure is shown inFigure 6 As shown, the MPLS three-layer VPN MPLS network VPN service traffic flow monitoring method provided in the embodiment of the disclosure includes the following steps:
[0116] S602, service flow monitoring information configuration (service, traffic flow direction, time).
[0117] S604, acquire monitoring fields, and generate traffic flow classification information containing LSP label information and VPN label information.
[0118] It should be noted that the LSP label information in the traffic flow classification information is MPLS LSP label information, and the VPN label information in the traffic flow classification information is VPN service label information.
[0119] In specific implementation, in different VPN service flow monitoring configuration scenarios, corresponding service traffic flow feature fields are acquired, and after network service routing is stable, traffic flow classification information of the VPN service is generated.
[0120] S606, according to the traffic flow classification information of different VPN service flow data, different VPN service flow data is scheduled into corresponding monitoring queues, and VPN service traffic flow monitoring results of the MPLS network are obtained through statistics.
[0121] In specific implementation, based on traffic flow monitoring classification matching, through a queue scheduling mechanism, service traffic flows of different VPNs are scheduled into queues, and traffic flow service byte number and data packet number statistics are implemented; at the same time, based on a settable time interval, traffic flow speed statistics are implemented.
[0122] S608, whether service flow monitoring configuration information / network signaling messages (LDP) / service routing signaling messages (BGP) change.
[0123] If yes, S610 is executed; if no, S604 is returned to be executed.
[0124] It should be noted that in the case of VPN MPLS network VPN service traffic flow monitoring configuration change, LDP change caused by network state, and VPN service change, LDP and VPN service BGP signaling messages need to be reanalyzed and processed to acquire new VPN service traffic flow classification information, that is, L+V information.
[0125] S610, whether data reporting is performed.
[0126] If yes, S612 is executed; if no, S606 is returned to be executed.
[0127] S612, encapsulating the reported data using the YANG data model; and reporting the data based on a Telemetry data reporting mechanism.
[0128] In a specific implementation, the flow direction statistics are collected at a defined time according to the YANG data model, and the flow direction data of the traffic is reported to the management analysis system at a defined time based on the Telemetry data reporting mechanism, so as to realize the centralized monitoring and analysis of the service flow direction.
[0129] In some embodiments, the method for obtaining service flow direction classification information is as shown in Figure 7 The VPN service monitoring flow direction is started at a service origin node, and is divided into the following configuration modes:
[0130] 1) Mode 1: specific VPN service specific direction monitoring, in this mode, the flow direction monitoring of a specific direction is started for a specific VPN service instance, and a BGP Loopback address of a destination direction device VPN service route advertisement needs to be specified, which is suitable for monitoring a specific direction for a key VPN service
[0131] 2) Mode 2: specific VPN service monitoring, in this mode, the flow direction monitoring of each direction of a VPN service is started for a specific VPN service instance, which is suitable for starting the monitoring for a key VPN service
[0132] 3) Mode 3: global VPN service monitoring, in this mode, the flow direction monitoring of all VPN services is started, that is, the flow direction monitoring is implemented for all VPN instances and all directions on a VPN service router
[0133] It should be noted that the granularity of mode 1, mode 2 and mode 3 is from small to large, and the combination of the former mode constitutes the latter mode.
[0134] In the mode 1 working condition, after starting the VPN service flow direction monitoring, the L label information is obtained in the LDP processing process through the configured VPN service route advertisement BGP Loopback address; at the same time, the source router obtains the VPN service route label information V through the route parameter import route-target (RT) configured by the VPN service VRF instance in the BGP processing process by matching the destination Loopback address and the RT.
[0135] In the working condition of mode 2, after starting the VPN service flow direction monitoring, the source router acquires the next-hop IP address of the VPN service instance route, i.e., the destination device Loopback address and the VPN service route label information V corresponding to the RT pair, based on the configured route parameter import route-target (RT) and through the BGP processing result, for the specific VPN service VRF instance; on this basis, all the destination device Loopback addresses involved in the VPN instance are acquired, and the destination device L label information of the VPN instance is acquired based on the LDP processing.
[0136] In the working condition of mode 3, after starting the VPN service flow direction monitoring, the source router acquires the next-hop IP address of each VPN service instance route, i.e., the destination device Loopback address and the VPN instance service route label information V corresponding to the RT pair, based on the configured route parameter import route-target (RT) and through the BGP processing result, for all the VPN service VRF instances; on this basis, all the destination device Loopback addresses of the VPN instances are acquired, and the L label information is acquired based on the LDP processing.
[0137] Through the above processing mechanism, the VPN service traffic flow direction L+V classification label can be acquired, and for the purpose of realizing the VPN service monitoring traffic flow direction monitoring management, the corresponding configured VPN instance name, the configured route-distinguisher (RD) label information, the VPN service source / destination Loopback address information, and the device internal queue number need to be associated.
[0138] In some embodiments, the process of scheduling different VPN service flow data to the corresponding traffic flow direction monitoring queue based on the traffic flow direction classification information is as shown in Figure 8 After acquiring the classification labels L and V of the traffic flow direction monitoring, there is one L and multiple V values in a single flow direction of a VPN instance, and the production process of introducing the traffic into the queue can be implemented using the following pseudo code:
[0139] if L match J and V match-any(K1,K2,...,Km)
[0140] then forwarding the packet through queue <n>.
[0141] For example, to monitor the flow direction of A-R3-R4-B, the source node A to the destination node B segment of the VPN <x>The traffic flow direction identifier can be obtained by L AB +V XB The two-dimensional field is represented by L
[0142] 1) The queue counts the number of data packets for forwarding, and the statistical value includes the total number of data packets and the number of bytes forwarded, which are processed using a 64-bit counter.
[0143] 2) The number of data packets and the number of bytes forwarded in the queue are obtained at a certain time interval, and the difference in the time interval range is calculated to obtain the flow rate of the calculated data packet and byte / bit number. The monitoring action can define the time interval, set the unit to minutes, and can be configured according to the operation requirements.
[0144] The dynamic processing process of traffic flow direction monitoring includes the following two aspects:
[0145] 1) Service flow direction monitoring configuration change processing:
[0146] ① New service flow direction monitoring configuration processing: At this time, there is no VPN service traffic flow direction monitoring queue in the MPLS network, the L+V label is obtained according to three modes to form a matching rule, and the incoming traffic is queued for number statistics.
[0147] ② Service flow monitoring configuration change processing:
[0148] In the case of mode 1 monitoring configuration change, if the original configuration monitoring direction is no longer needed for monitoring, the corresponding L+V matching rule is deleted, and the corresponding monitoring queue is released. For the newly added direction of monitoring configuration, the corresponding L+V label is obtained to form a matching rule, and the incoming traffic is queued for number statistics. When mode 1 is closed, the L+V matching rule under the VPN instance is deleted, and whether to monitor the statistical queue.
[0149] In the case of mode 2 monitoring configuration change, if the original configuration VPN instance is no longer needed for monitoring, all L+V matching rules under the VPN instance are deleted, and the corresponding monitoring queue is released. At the same time, for the newly added VPN instance, the corresponding L+V label is obtained to form a matching rule, and the incoming traffic is queued for number statistics.
[0150] In case of change of mode 3 monitoring configuration, when mode 3 is opened, if there are mode 1 and mode 2 monitoring configurations, these monitoring modes remain unchanged, and all other VPN instance flow directions monitoring L+V labels are acquired, matching rules are formed, and traffic is imported into the queue for quantity statistics; when mode 3 is closed, if there are mode 1 and mode 2 monitoring configurations, the monitoring queue is retained, and the monitoring L+V matching rules of other VPN instances are deleted and the corresponding monitoring queue is released.
[0151] 2) Network and service signaling change processing procedure:
[0152] ① Network signaling change: link state change or protocol process change occurs in network operation process, causing IGP route recalculation, thereby causing LDP in MPLS network to redistribute labels, thereby causing LSP of MPLS label exchange path to change, that is, L label corresponding to target Loopback address changes. Therefore, advertisement message in LDP session needs to be monitored, and when FEC / LABEL mapping relationship of destination Loopback address changes, corresponding Loopback flow direction monitoring label L label needs to be updated.
[0153] ② Service route signaling change: the following two types of changes may occur and are processed respectively:
[0154] The first type: update source of VPN service route BGP notification corresponding to Loopback address changes, at this time, L label of original monitoring queue needs to be replaced with L label corresponding to new Loopback address, and address information of destination-loopback field in data reporting model needs to be updated.
[0155] The second type: route and configuration parameter of VPN service instance change, device BGP route process changes, etc., all of which will cause V label of VPN instance to change. Update message in BGP session (usually session between service route and RR) needs to be monitored, real-time adaptation signaling change needs to be monitored, and latest VPN instance V label needs to be acquired through update / withdrawal new information analysis, and V label of monitoring queue traffic matching needs to be updated on this basis.
[0156] In the embodiments of the present disclosure, for the Loopback address information binding monitoring of source routing and destination routing, when LDP in L label information occurs (label information is updated) or V label changes (RT and RD routes of VPN in BGP change), time notification message information is generated, and VA1 changes, assuming that it is VA2. The present application can realize dynamic tracking and real-time adaptation to signaling changes. According to the operations of update, withdrawal, delete, increase, etc., the purpose of dynamically monitoring the flow direction can be realized. An example of a configuration model of a precise monitoring method of MPLS three-layer VPN flow direction is as follows:
[0157] The corresponding configuration parameter information is shown in Table 2.
[0158] Table 2
[0159]
[0160]
[0161] For example, for the VPN instance vpn1 under the path A-R3-R4-B, the total byte size of the VPN instance statistical flow direction is total-byte, the total packet number is total-packet, the flow rate in a certain time interval is interval-byte-rate BPS (byte / second) and interval-pkt-rate PPS (packet / second).
[0162] Based on the same inventive concept, the present disclosure also provides a device for monitoring the flow direction of VPN service traffic in an MPLS network, as described in the following embodiments. Since the principles of the device embodiments for solving problems are similar to the above-mentioned method embodiments, the implementation of the device embodiments can be referred to the implementation of the above-mentioned method embodiments, and the repeated parts will not be described here.
[0163] Figure 9 A schematic diagram of a device for monitoring the flow direction of VPN service traffic in an MPLS network in the embodiments of the present disclosure is shown, as shown in Figure 9 The device includes a VPN service flow data monitoring module 901, a VPN service flow data scheduling module 902, and a VPN service flow data statistical module 903.
[0164] The VPN service flow data monitoring module 901 is configured to generate flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, wherein the flow direction classification information is used to mark each flow direction of different VPN service flow data, and each flow direction corresponds to a monitoring queue.
[0165] It should be noted that, in the embodiments of the present disclosure, the flow direction classification information generated for different VPN service flow data in the MPLS network contains LSP label information and VPN label information. The LSP label information is LSP label information used to identify a label switched path (LSP) in the MPLS network, and the VPN label information is VPN service label information used to identify a VPN service instance in the VPN network. The LSP label information in the flow direction classification information is obtained through a label distribution protocol (LDP) message, and the VPN label information in the flow direction classification information is obtained through a border gateway protocol (BGP) message.
[0166] In some embodiments, the VPN service flow data described above can include, but is not limited to, at least one of the following: service flow data of a single VPN service in a single flow direction; service flow data of a single VPN service in multiple flow directions; service flow data of multiple VPN services in multiple flow directions.
[0167] In some embodiments, the VPN service flow direction monitoring result of the MPLS network described above can include, but is not limited to, at least one of the following: a service flow direction byte number statistical result, a service flow direction packet number statistical result, and a service flow direction flow rate statistical result.
[0168] In an embodiment, the VPN traffic flow monitoring device in the MPLS network provided in the embodiments of the present disclosure can further include: a service flow monitoring configuration module 904 configured to acquire VPN service flow monitoring configuration information, wherein the service flow monitoring configuration information is used to configure to-be-monitored service information and / or to-be-monitored traffic flow direction information; and a monitoring field determination module 905 configured to determine field information of a label switching path identification between MPLS network node devices and / or a service label identification monitoring field in a monitoring field according to the VPN service flow monitoring configuration information, and generate LSP label information and VPN label information contained in the monitoring field for traffic flow direction classification. In this embodiment, the VPN service flow data monitoring module 901 is further configured to generate LSP label information and VPN label information contained in the monitoring field for traffic flow direction classification according to the field information of the label switching path identification between MPLS network node devices and / or the service label identification monitoring field in the monitoring field.
[0169] In some embodiments, the VPN traffic flow monitoring device in the MPLS network provided in the embodiments of the present disclosure can further include: a first monitoring field updating module 906 configured to monitor whether the service flow monitoring configuration information is changed; and if the service flow monitoring configuration information is changed, update the field information of the label switching path identification between MPLS network node devices and / or the service label identification monitoring field in the monitoring field according to the changed service flow monitoring configuration information.
[0170] In some embodiments, the VPN traffic flow monitoring device in the MPLS network provided in the embodiments of the present disclosure can further include: a second monitoring field updating module 907 configured to monitor whether MPLS network signaling messages and / or VPN service routing signaling messages are changed; and if the MPLS network signaling messages and / or the VPN service routing signaling messages are changed, update the field information of the label switching path identification between MPLS network node devices and / or the service label identification monitoring field in the monitoring field according to the changed MPLS network signaling messages and / or the VPN service routing signaling messages.
[0171] In some embodiments, the VPN traffic flow monitoring device in the MPLS network provided in the embodiments of the present disclosure can further include: a data reporting module 908 configured to: acquire a custom data reporting model, wherein the data reporting model is used to report data in a manner of on-demand collection and active pushing; and use the data reporting model to encapsulate and report the VPN traffic flow monitoring result of the MPLS network.
[0172] In some embodiments, the data reporting module 908 is further configured to: collect and encapsulate the VPN traffic flow monitoring result of the MPLS network using a YANG data model; and report the encapsulated data based on a Telemetry data reporting mechanism.
[0173] In some embodiments, the VPN service flow data monitoring module 901 is further configured to: if the VPN service flow data is service flow data of a single VPN service instance in a single traffic flow direction, obtain, as VPN label information in the traffic flow direction classification information, Loopback addresses of a single destination device involved in the single VPN service instance and VPN service routing information of the single VPN service instance in the BGP message according to ingress direction routing configuration parameters configured by the single VPN service instance; obtain, as LSP label information in the traffic flow direction classification information, LSP label information of the single destination device in the LDP message according to the Loopback addresses of the single destination device involved in the single VPN service instance; if the VPN service flow data is service flow data of a single VPN service instance in multiple traffic flow directions, obtain, as VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved in the single VPN service instance and VPN service routing information of the single VPN service instance in the BGP message according to ingress direction routing configuration parameters configured by the single VPN service instance; obtain, as LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved in the single VPN service instance in the LDP message according to the Loopback addresses of the multiple destination devices involved in the single VPN service instance; if the VPN service flow data is service flow data of multiple VPN service instances in multiple traffic flow directions, obtain, as VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved in each VPN service instance and VPN service routing information of each VPN service instance in the BGP message according to ingress direction routing configuration parameters configured by each VPN service instance; and obtain, as LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved in each VPN service instance in the LDP message according to the Loopback addresses of the multiple destination devices involved in each VPN service instance.
[0174] In some embodiments, the VPN service flow data monitoring module 901 is further configured to: if the VPN service routing signaling message changes, update the VPN label information in the traffic flow direction classification information; and if the MPLS network signaling message changes, update the LSP label information in the traffic flow direction classification information.
[0175] It should be noted that each module in the apparatus embodiments and the corresponding steps in the method embodiments have the same examples and application scenarios, but are not limited to the content disclosed in the above method embodiments. It should be noted that the above modules as part of the apparatus can be executed in a computer system such as a group of computer executable instructions.
[0176] Based on the same inventive concept, the embodiment of the present disclosure also provides a system for monitoring traffic flow direction of VPN service in MPLS network, as described in the following embodiment. Since the principle of solving problems of the system embodiment is similar to the above-mentioned method embodiment, the implementation of the system embodiment can be referred to the implementation of the above-mentioned method embodiment, and the repeated parts will not be described here.
[0177] Figure 10 A schematic diagram of a system for monitoring traffic flow direction of VPN service in MPLS network is shown in the embodiment of the present disclosure, as shown in the figure, the system comprises a source router 10, a destination router 20 and a monitoring controller 30. Figure 10
[0178] The source router 10 is configured to generate traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network after receiving the VPN service flow data, and schedule different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data, wherein the traffic flow direction classification information is used to mark each traffic flow direction of different VPN service flow data from the source router 10 to the destination router 20, and each traffic flow direction corresponds to a monitoring queue; the monitoring controller 30 is configured to count the VPN service flow data transmitted in each monitoring queue to obtain the monitoring result of VPN service traffic flow direction of the MPLS network.
[0179] It should be noted that in the embodiment of the present disclosure, the traffic flow direction classification information generated for different VPN service flow data in the MPLS network contains LSP label information and VPN label information, the LSP label information is the LSP label information used to identify the label switching path LSP in the MPLS network, and the VPN label information is the VPN service label information used to identify the VPN service instance in the VPN network. Among them, the LSP label information in the traffic flow direction classification information is obtained through the label distribution protocol LDP message; the VPN label information in the traffic flow direction classification information is obtained through the border gateway protocol BGP message.
[0180] In some embodiments, the system for monitoring traffic flow direction of VPN service in MPLS network provided in the embodiment of the present disclosure can further comprise a user terminal device 40 in communication with the monitoring controller 30, configured to receive the monitoring result of VPN service traffic flow direction of the MPLS network reported by the monitoring controller 30; wherein the monitoring controller 30 is further configured to use a custom data reporting model to package and report the monitoring result of VPN service traffic flow direction of the MPLS network.
[0181] In some embodiments, the source router 10 is further configured to: acquire VPN traffic flow monitoring configuration information, wherein the traffic flow monitoring configuration information is used to configure to-be-monitored traffic information and / or to-be-monitored traffic flow direction information; determine the field information of the MPLS network inter-node label switching path identification and / or service label identification monitoring field in the monitoring field according to the VPN traffic flow monitoring configuration information, generate the LSP label information and VPN label information contained in the traffic flow direction classification, and use the traffic flow direction classification for traffic flow direction classification, wherein the MPLS network inter-node path identification service identification monitoring field is generated; generate the LSP label information and VPN label information contained in the traffic flow direction classification according to the field information of the MPLS network inter-node label switching path identification and / or service label identification monitoring field in the monitoring field, and use the traffic flow direction classification for traffic flow direction classification, and generate the traffic flow direction classification information containing the LSP label information and VPN label information.
[0182] In some embodiments, the monitoring controller 30 is further configured to: monitor whether the traffic flow monitoring configuration information is changed; if the traffic flow monitoring configuration information is changed, the source router 10 is further configured to update the field information of the MPLS network inter-node label switching path identification and / or service label identification monitoring field in the monitoring field according to the changed traffic flow monitoring configuration information, and generate the LSP label information and VPN label information contained in the traffic flow direction classification.
[0183] In some embodiments, the monitoring controller 30 is further configured to: monitor whether the MPLS network signaling message and / or VPN service routing signaling message is changed; if the MPLS network signaling message and / or VPN service routing signaling message is changed, the source router 10 is further configured to update the field information of the MPLS network inter-node label switching path identification and / or service label identification monitoring field in the monitoring field according to the changed MPLS network signaling message and / or VPN service routing signaling message, and generate the LSP label information and VPN label information contained in the traffic flow direction classification.
[0184] In some embodiments, the VPN traffic flow direction monitoring result of the MPLS network obtained by the monitoring controller 30 can include, but is not limited to, at least one of: traffic flow direction byte number statistical result, traffic flow direction packet number statistical result, and traffic flow direction flow rate statistical result.
[0185] In some embodiments, the monitoring controller 30 is further configured to: collect the VPN traffic flow direction monitoring result of the MPLS network using the YANG data model and encapsulate; and report the encapsulated data based on the Telemetry data reporting mechanism.
[0186] In some embodiments, the VPN traffic flow direction monitoring system provided in the MPLS network of the embodiments of the present disclosure can be used for, but not limited to, monitoring of the following service flow data: service flow data of a single VPN service in a single traffic flow direction; service flow data of a single VPN service in multiple traffic flow directions; service flow data of multiple VPN services in multiple traffic flow directions.
[0187] Based on the above embodiments, in some embodiments, the source router 10 is further configured to: if the VPN service flow data is service flow data of a single VPN service instance in a single traffic flow direction, obtain, as VPN label information in the traffic flow direction classification information, Loopback addresses of a single destination device involved in the VPN service instance and VPN service routing information of the VPN service instance involved in the VPN service instance through ingress direction routing configuration parameters configured by the VPN service instance in a BGP message; obtain, as LSP label information in the traffic flow direction classification information, LSP label information of the destination device through the Loopback addresses of the single destination device involved in the VPN service instance in an LDP message; if the VPN service flow data is service flow data of a single VPN service instance in multiple traffic flow directions, obtain, as VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved in the VPN service instance and VPN service routing information of the VPN service instance involved in the VPN service instance through ingress direction routing configuration parameters configured by the VPN service instance in a BGP message; obtain, as LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved in the VPN service instance through the Loopback addresses of the multiple destination devices involved in the VPN service instance in an LDP message; if the VPN service flow data is service flow data of multiple VPN service instances in multiple traffic flow directions, obtain, as VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved in each VPN service instance and VPN service routing information of each VPN service instance involved in the VPN service instance through ingress direction routing configuration parameters configured by each VPN service instance in a BGP message; obtain, as LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved in each VPN service instance through the Loopback addresses of the multiple destination devices involved in each VPN service instance in an LDP message.
[0188] In some embodiments, the source router 10 is further configured to: if the VPN service routing signaling message changes, update the VPN label information in the traffic flow direction classification information; if the MPLS network signaling message changes, update the LSP label information in the traffic flow direction classification information.
[0189] In summary, the MPLS network VPN service traffic flow monitoring scheme provided in the embodiments of the present disclosure can achieve the following technical effects, but is not limited thereto: ① By defining a new network node device path identifier (L+V) between devices, the traffic flow direction of the VPN service flow data can be marked, and the accurate monitoring of the service traffic flow direction can be achieved; ② Multiple links can be uniformly routed, and the accurate information of the VPN traffic flow direction of different links can be monitored, which eliminates the current mechanism of complex port monitoring network node device path identifier; ③ The traffic flow direction information of the current network link can be updated in real time, the monitoring of the remote traffic flow direction is achieved, and more intuitive traffic information is provided for VPN service customers; ④ For network supervision, network management personnel can know the source and destination of the packet, the type of network service, and the cause of network congestion.
[0190] The MPLS network VPN service traffic flow monitoring scheme provided in the embodiments of the present disclosure can be applied to, but is not limited to, accurate monitoring of government or cloud VPN service traffic flow, can provide user service monitoring value-added services, is conducive to user network optimization and adjustment, and improves user service quality experience; it can also be applied to monitoring of VPN service traffic flow in self-operated key MPLS networks, can monitor the size and trend of key local traffic, can implement effective network bandwidth planning, and meets the needs of business development; the MPLS VPN service is developing rapidly at present, and the MPLS network VPN service traffic flow monitoring method provided in the embodiments of the present disclosure can be applied to accurate monitoring of MPLS VPN service traffic flow, and has wide application prospects.
[0191] Those skilled in the art can understand that each aspect of the present disclosure can be implemented in the form of a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system".
[0192] Based on the same inventive concept, the present disclosure further provides an electronic device, which comprises a processor and a memory for storing executable instructions of the processor, wherein the processor is configured to execute the MPLS network VPN service traffic flow monitoring method of any one of the above embodiments by executing the executable instructions. Since the principle of solving problems of the electronic device embodiment is similar to that of the above method embodiment, the implementation of the electronic device embodiment can be referred to the implementation of the above method embodiment, and the repeated parts will not be described herein.
[0193] The electronic device 1100 according to this embodiment of the present disclosure will be described below with reference to Figure 11 Figure 11 The electronic device 1100 shown is merely an example, and should not impose any limitation on the functions and use range of the embodiments of the present disclosure.
[0194] As shown in Figure 11 The electronic device 1100 is in the form of a general computing device. Components of the electronic device 1100 can include, but are not limited to, the at least one processing unit 1110 described above, the at least one storage unit 1120 described above, and a bus 1130 that connects the different system components, including the storage unit 1120 and the processing unit 1110.
[0195] The storage unit stores program codes that can be executed by the processing unit 1110, so that the processing unit 1110 performs the steps according to various exemplary embodiments of the present disclosure described in the "Exemplary Method" section of the present specification. For example, the processing unit 1110 can perform the following steps of the above method embodiments: generating traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in an MPLS network, wherein the traffic flow direction classification information is used to mark each traffic flow direction of different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue; scheduling different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data; and counting the VPN service flow data transmitted in each monitoring queue to obtain a VPN service traffic flow direction monitoring result of the MPLS network.
[0196] The storage unit 1120 can include a readable medium in the form of a volatile storage unit, such as a random access memory (RAM) 11201 and / or a cache memory 11202, and can further include a read-only memory (ROM) 11203.
[0197] The storage unit 1120 can also include program / utility 11204 having a set of programs / modules 11205, including but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or some combination thereof can include implementation of a network environment.
[0198] The bus 1130 can represent one or more of several types of bus structures, including a storage unit bus or storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit bus, or a local bus using any of a variety of bus architectures.
[0199] The electronic device 1100 can also communicate with one or more external devices 1140 such as a keyboard, a pointing device, a Bluetooth device, etc.; and can communicate with one or more devices that enable a user to interact with the electronic device 1100 and / or one or more devices (e.g. routers, modems, etc.) that enable the electronic device 1100 to communicate with one or more other computing devices. Such communication can occur via Input / Output (I / O) interface 1150. Still yet, the electronic device 1100 can communicate with one or more networks such as a local area network (LAN), a wide area network (WAN), and / or the Internet through network adapter 1160. As depicted, network adapter 1160 communicates with the other components of the electronic device 1100 through bus 1130. It should be appreciated that although not shown, other hardware and / or software modules could be used in connection with the electronic device 1100. Such modules can include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.
[0200] From the above description of the embodiments, those skilled in the art will readily appreciate that the example embodiments described herein can be implemented by software and / or by hardware coupled with software. Accordingly, the technical solutions of the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or a network, and includes a number of instructions for causing a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.
[0201] Based on the same inventive concept, the present disclosure also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the VPN traffic flow monitoring method in an MPLS network according to any one of the above embodiments. Since the computer-readable storage medium embodiment solves problems in a similar manner to the above method embodiments, the implementation of the computer-readable storage medium embodiment can be referred to the implementation of the above method embodiments, and repeated descriptions are not repeated.
[0202] More specific examples of the computer-readable storage medium in the present disclosure can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0203] In this disclosure, a computer readable storage medium can include a data signal transporting or broadcasting computer readable program code embodied in the data signal. The data signal can also be transmitted over a network including the Internet. Additionally, the computer readable storage medium can also be any tangible storage medium which can be used to store and / or carry the program codes.
[0204] Optionally, program code embodied on a computer readable storage medium can also be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0205] In an implementation, the program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++ and the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider (ISP).
[0206] Based on the same inventive concept, the present disclosure further provides a computer program product, comprising a computer program or instructions, which, when executed by a processor, implement the MPLS network VPN service traffic flow monitoring method of any one of the above method embodiments. Since the problem-solving principle of this computer program product embodiment is similar to that of the above method embodiments, the implementation of this computer program product embodiment can be referred to the implementation of the above method embodiments, and repeated descriptions are omitted.
[0207] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided into multiple modules or units.
[0208] Moreover, although individual steps of the methods in the present disclosure are described in a particular order in the drawings, this is not required or implied, nor is it necessary to perform all of the steps shown to achieve the desired result. Additionally or alternatively, certain steps can be omitted, combined into a single step, performed in a different order, broken down into multiple steps, and / or the like.
[0209] Those skilled in the art will readily understand that the example embodiments described herein can be implemented by software and / or by hardware coupled with software, as described above. Thus, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or on a network, and includes a number of instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.
[0210] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure following the general principles thereof and including such departures from the present disclosure that come within known use or custom in the art to which the present disclosure pertains. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure are indicated by the appended claims.< / x> < / n>
Claims
1. A method for monitoring traffic flow direction of a virtual private network (VPN) service in a multi-protocol label switching (MPLS) network, characterized in that, The method comprises the following steps: generating flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in an MPLS network, wherein the flow direction classification information is used for marking different flow directions of the different VPN service flow data, and each flow direction corresponds to a monitoring queue; scheduling different VPN service flow data into the monitoring queue of the corresponding flow direction according to the flow direction classification information of the different VPN service flow data; counting the VPN service flow data transmitted in each monitoring queue to obtain a VPN service flow direction monitoring result of the MPLS network; wherein the LSP label information is LSP label information used for identifying a label switching path (LSP) in the MPLS network and obtained through a label distribution protocol (LDP) message; and the VPN label information is VPN service label information used for identifying a VPN service instance in a VPN network and obtained through a border gateway protocol (BGP) message; wherein generating the flow direction classification information containing the LSP label information and the VPN label information for the different VPN service flow data in the MPLS network comprises the following steps: obtaining VPN service flow monitoring configuration information, wherein the VPN service flow monitoring configuration information is used for configuring to-be-monitored VPN service information and / or to-be-monitored flow direction information; determining field information of a label switching path (LSP) identification and / or a VPN service label identification monitoring field in a monitoring field according to the VPN service flow monitoring configuration information; and generating the flow direction classification information containing the LSP label information and the VPN label information for flow direction classification.
2. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, After determining the field information of the LSP identification and / or the VPN service label identification monitoring field in the monitoring field according to the VPN service flow monitoring configuration information, the method further comprises the following steps: monitoring whether the VPN service flow monitoring configuration information is changed; if the VPN service flow monitoring configuration information is changed, updating the field information of the LSP identification and / or the VPN service label identification monitoring field in the monitoring field according to the changed service flow monitoring configuration information.
3. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, After determining the field information of the LSP identification and / or the VPN service label identification monitoring field in the monitoring field according to the service flow monitoring configuration information, the method further comprises the following steps: monitoring whether MPLS network signaling messages and / or VPN service routing signaling messages are changed; if the MPLS network signaling messages and / or the VPN service routing signaling messages are changed, updating the field information of the LSP identification and / or the VPN service label identification monitoring field in the monitoring field according to the changed MPLS network signaling messages and / or the VPN service routing signaling messages.
4. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, The VPN traffic flow direction monitoring result of the MPLS network comprises at least one of the following: a VPN traffic flow direction byte number statistical result, a VPN traffic flow direction packet number statistical result, and a VPN traffic flow direction flow rate statistical result.
5. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, After the VPN service flow data transmitted in each monitoring queue is counted to obtain the VPN traffic flow direction monitoring result of the MPLS network, the method further comprises: obtaining a custom data reporting model, wherein the data reporting model reports data in a manner of on-demand collection and active pushing; using the data reporting model to encapsulate and report the VPN traffic flow direction monitoring result of the MPLS network.
6. The method for monitoring VPN traffic flow direction in an MPLS network according to claim 5, wherein, using the data reporting model to encapsulate and report the VPN traffic flow direction monitoring result of the MPLS network, comprising: using a YANG data model to encapsulate the VPN traffic flow direction monitoring result collected by the MPLS network; reporting the encapsulated data based on a Telemetry data reporting mechanism.
7. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, The VPN service flow data comprises at least one of the following: service flow data of a single VPN service in a single traffic flow direction; service flow data of a single VPN service in multiple traffic flow directions; service flow data of multiple VPN services in multiple traffic flow directions.
8. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, Before generating traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, the method further comprises: if the VPN service flow data is service flow data of a single VPN service instance in a single traffic flow direction, obtaining, as VPN label information in the traffic flow direction classification information, Loopback addresses of a single destination device involved in the VPN service instance and VPN service routing information of the VPN service instance in a BGP message through ingress direction routing configuration parameters configured by the VPN service instance; and obtaining, as LSP label information in the traffic flow direction classification information, LSP label information of the destination device in an LDP message through the Loopback addresses of the single destination device involved in the VPN service instance; if the VPN service flow data is service flow data of a single VPN service instance in multiple traffic flow directions, obtaining, as VPN label information in the traffic flow direction classification information, Loopback addresses of multiple destination devices involved in the VPN service instance and VPN service routing information of the VPN service instance in a BGP message through ingress direction routing configuration parameters configured by the VPN service instance; and obtaining, as LSP label information in the traffic flow direction classification information, LSP label information of the multiple destination devices involved in the VPN service instance in an LDP message through the Loopback addresses of the multiple destination devices involved in the VPN service instance; If the VPN service flow data is service flow data of multiple VPN service instances in multiple traffic flow directions, the Loopback address of multiple destination devices involved in each VPN service instance and VPN service routing information are obtained in the BGP message as the VPN label information in the traffic flow direction classification information through the ingress direction routing configuration parameter configured by each VPN service instance, and the LSP label information of the multiple destination devices involved in each VPN service instance is obtained in the LDP message as the LSP label information in the traffic flow direction classification information through the Loopback address of the multiple destination devices involved in each VPN service instance.
9. The method for monitoring VPN traffic flow direction in MPLS network according to claim 1, characterized in that, Before generating the traffic flow direction classification information containing the LSP label information and the VPN label information for different VPN service flow data in the MPLS network, the method further comprises: If the VPN service routing signaling message changes, the VPN label information in the traffic flow direction classification information is updated; If the MPLS network signaling message changes, the LSP label information in the traffic flow direction classification information is updated.
10. A device for monitoring the flow of VPN traffic in an MPLS network, characterized in that it comprises: Comprise: a VPN service flow data monitoring module for generating traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network, wherein the traffic flow direction classification information is used to mark each traffic flow direction of different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue; a VPN service flow data scheduling module for scheduling different VPN service flow data into the monitoring queue of the corresponding traffic flow direction according to the traffic flow direction classification information of different VPN service flow data; a VPN service flow data statistics module for counting the VPN service flow data transmitted in each monitoring queue to obtain a VPN service traffic flow direction monitoring result of the MPLS network; wherein the LSP label information is LSP label information used to identify a label switching path LSP in the MPLS network obtained through a label distribution protocol LDP message; and the VPN label information is VPN service label information used to identify a VPN service instance in the VPN network obtained through a border gateway protocol BGP message; wherein the VPN service flow data monitoring module is further configured to: obtain VPN service flow monitoring configuration information, wherein the VPN service flow monitoring configuration information is used to configure to-be-monitored VPN service information and / or to-be-monitored traffic flow direction information; determine field information of a label switching path identification between MPLS network node devices and / or a VPN service label identification monitoring field in a monitoring field according to the VPN service flow monitoring configuration information, and generate traffic flow direction classification information containing LSP label information and VPN label information for traffic flow direction classification.
11. A system for monitoring traffic flow direction of VPN services in an MPLS network, characterized in that, Comprise: a source router, a destination router and a monitoring controller; The source router is configured to generate traffic flow direction classification information containing LSP label information and VPN label information for different VPN service flow data in the MPLS network after receiving the VPN service flow data in the MPLS network, and schedule different VPN service flow data to a corresponding monitoring queue of the traffic flow direction according to the traffic flow direction classification information of the different VPN service flow data, wherein the traffic flow direction classification information is used to mark each traffic flow direction of the different VPN service flow data, and each traffic flow direction corresponds to a monitoring queue. The monitoring controller is configured to count the VPN service flow data transmitted in each monitoring queue to obtain the VPN service traffic flow direction monitoring result of the MPLS network. The LSP label information is LSP label information used to identify a label switched path (LSP) in the MPLS network and obtained through a label distribution protocol (LDP) message; and the VPN label information is VPN service label information used to identify a VPN service instance in a VPN network and obtained through a border gateway protocol (BGP) message. The source router is further configured to obtain VPN service flow monitoring configuration information, wherein the VPN service flow monitoring configuration information is used to configure to-be-monitored VPN service information and / or to-be-monitored traffic flow direction information; determine field information of a label switched path (LSP) identification and / or a VPN service label identification monitoring field in a monitoring field according to the VPN service flow monitoring configuration information, and generate traffic flow direction classification information containing LSP label information and VPN label information for traffic flow direction classification.
12. The system for monitoring VPN traffic flow direction in an MPLS network according to claim 11, wherein, The system further comprises: A user terminal device in communication with the monitoring controller, configured to receive the VPN service traffic flow direction monitoring result of the MPLS network reported by the monitoring controller. The monitoring controller is further configured to use a self-defined data reporting model to package and report the VPN service traffic flow direction monitoring result of the MPLS network.
13. An electronic device, comprising: The system further comprises: A processor; and A memory configured to store executable instructions of the processor; The processor is configured to execute the executable instructions to perform the VPN service traffic flow direction monitoring method in the MPLS network according to any one of claims 1 to 9.
14. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the VPN service traffic flow direction monitoring method in the MPLS network according to any one of claims 1 to 9.
15. A computer program product, comprising: The computer program or instructions are executed by the processor to implement the VPN service traffic flow direction monitoring method in the MPLS network according to any one of claims 1 to 9.
Citation Information
Patent Citations
Service scheduling method and service scheduling device based on Layer 2 Virtual Private Networks (L2VPN)
CN102546395A
Security attack test system for electric power MPLS VPN as well as test method
CN109347790A