VRRP routing redundancy optimization method and system
By creating network namespaces on VRRP devices and utilizing VETH interfaces, the synchronization and recovery of MAC table entries and ARP table entries in VRRP technology is solved, and efficient VRRP routing redundancy optimization is achieved.
Patent Information
- Application Number
- CN202510106397.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-06
AI Technical Summary
In the existing VRRP technology, MAC table entries cannot be saved synchronously, ARP table entries cannot distinguish between self-study and VRRP link transmission items, the transmitted table entries cannot be deleted when the backup device is switched when the main device is offline, and the ARP table entries learned before cannot be restored when the main device is online.
By creating a network namespace on a VRRP device, using the VETH interface to connect the VRRP device and the network namespace, running the VRRP protocol to synchronize MAC table entries and ARP table entries between the network namespaces, and using the disconnection or online of the VETH interface instead of the disconnection or online of the VRRP device.
It realizes synchronous storage of MAC table entries, distinguishes the source of ARP table entries, avoids resource consumption of re-learning ARP table entries, and simplifies the switching and recovery process of VRRP devices.
Smart Images

Figure CN119945912A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a VRRP routing redundancy optimization method and system. Background Art
[0002] VRRP is a protocol for router redundancy. Its main purpose is to form a virtual router through multiple physical routers to achieve high availability of the default gateway in the network. Through VRRP, a virtual gateway, that is, a virtual IP address, can be configured in the network and redundantly backed up in multiple physical routers to ensure that network communication can continue uninterrupted even if one of the routers fails.
[0003] The current usage scenarios of VRRP are as follows: Figure 1 As shown. Two three-layer switches DUT1 and DUT2 are connected by a layer 2 link VRRP line, and VRRP packets are exchanged in the same broadcast domain. In the master-slave mode, only one of DUT1 and DUT2 can have a gateway IP at the same time. When UDT2 is the backup device, the layer 3 data flow of PC2 needs to pass through the VRRP link to reach DUT1. The layer 2 data flow first checks the local MAC table entry. If it exists, it is forwarded at the second layer. If not, it is broadcast to DUT1 through the VRRP link, and then DUT1 searches for its own MAC table entry. When the table entries are shared, DUT1 and DUT2 cannot synchronize and save the MAC table entries of the VRRP group, and can only synchronize and save the ARP table entries. That is, the following problems exist in the current usage scenario:
[0004] 1) MAC table entries cannot be saved synchronously.
[0005] 2) The synchronized ARP entries can only exist in the same table, and it is impossible to distinguish which ones are learned by itself and which ones are transmitted from the VRRP link.
[0006] 3) When the master device goes offline, the backup device cannot delete the table items transmitted by the master device when it switches to the master device. All ARPs need to be relearned to age out the unconnected devices.
[0007] 4) When the master device comes online, it cannot restore the previously learned ARP entries. Summary of the invention
[0008] The present application provides a VRRP routing redundancy optimization method and system, which are used to solve at least one of the above technical problems.
[0009] This application adopts the following technical solutions:
[0010] On the one hand, the present application provides a VRRP routing redundancy optimization method, the method comprising: creating corresponding network namespace net_1_bak and network namespace net_2_bak on VRRP device net_1_0 and VRRP device net_2_0 respectively; using a VETH interface to connect VRRP device net_1_0 and network namespace net_1_bak, and to connect VRRP device net_2_0 and network namespace net_2_bak; running a VRRP protocol between network namespace net_1_bak and network namespace net_2_bak; and using the offline or online status of the VETH interface to replace the offline or online status of the VRRP device net_1_0 and / or the VRRP device net_2_0.
[0011] In a possible implementation of the present application, the network namespace net_1_bak is used to store the MAC table entries and ARP table entries of the VRRP device net_2_0, and the network namespace net_2_bak is used to store the MAC table entries and ARP table entries of the VRRP device net_2_0.
[0012] In a possible implementation of the present application, before running the VRRP protocol between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: adding the physical interfaces of the VRRP device net_1_0 and the VRRP device net_2_0 to the network namespace net_1_bak and the network namespace net_2_bak respectively; on the VRRP device net_1_0 and the VRRP device net_2_0, implementing a virtual router to correspond to the network namespace net_1_bak and the network namespace net_2_bak, and implementing a virtual interface to correspond to the VETH interface.
[0013] In a possible implementation of the present application, after the VRRP protocol is run between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: when the VRRP device net_1_0 learns the MAC table items and the ARP table items, broadcasting the MAC table items and the ARP table items to the network namespace net_1_bak through the VETH interface; the network namespace net_1_bak synchronizes the MAC table items and the ARP table items to the network namespace net_2_bak through the VRRP protocol; and the network namespace net_2_bak saves the MAC table items and the ARP table items learned by the VRRP device net_1_0.
[0014] In a possible implementation of the present application, after the VRRP protocol is run between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: when the VRRP device net_2_0 learns the MAC table items and the ARP table items, broadcasting the MAC table items and the ARP table items to the network namespace net_2_bak through the VETH interface; the network namespace net_2_bak synchronizes the MAC table items and the ARP table items to the network namespace net_1_bak through the VRRP protocol; and the network namespace net_1_bak saves the MAC table items and the ARP table items learned by the VRRP device net_2_0.
[0015] In a possible implementation of the present application, after the VRRP protocol is run between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: when the VRRP device net_1_0 forwards traffic, searching the table entry of the VRRP device net_1_0 itself to determine whether there is a forwarding path; if so, forwarding through the table entry of the VRRP device net_1_0 itself.
[0016] In a possible implementation of the present application, the method further includes: if there is no forwarding path in the table entry of the VRRP device net_1_0 itself, broadcasting the traffic to the network namespace net_1_bak through the VETH interface to find the table entry of the VRRP device net_2_0; if the forwarding path is found in the table entry of the VRRP device net_2_0, making the traffic reach the network namespace net_2_bak through the VRRP protocol, and then giving it to the VRRP device net_2_0 through the VETH interface to forward it through the table entry of the VRRP device net_2_0.
[0017] In a possible implementation of the present application, the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0 is replaced by the offline or online state of the VETH interface, including: when the VRRP device net_1_0 is offline, the VETH interface between the VRRP device net_2_0 and the network namespace net_2_bak is cut off.
[0018] In a possible implementation of the present application, the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0 is replaced by the offline or online state of the VETH interface, and further includes: when the VRRP device net_1_0 comes back online, restoring the VETH interface between the VRRP device net_2_0 and the network namespace net_2_bak to restore the table entry of the VRRP device net_1_0.
[0019] On the other hand, the present application also provides a VRRP routing redundancy optimization system, the system comprising: VRRP device net_1_0 and VRRP device net_2_0, network namespace net_1_bak and network namespace net_2_bak; wherein, the VRRP device net_1_0 and the network namespace net_1_bak are connected using a VETH interface, and the VRRP device net_2_0 and the network namespace net_2_bak are connected using a VETH interface; the VRRP protocol runs between the network namespace net_1_bak and the network namespace net_2_bak; the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0 is replaced by the offline or online state of the VETH interface.
[0020] The present application provides a VRRP routing redundancy optimization method and system, which has the following beneficial effects:
[0021] By creating a corresponding network namespace on the VRRP device, the characteristics of each network namespace having an independent MAC table entry and an independent ARP table entry are fully utilized to isolate, back up, and restore the MAC table entries and ARP table entries of the VRRP device, so that the MAC table entries can be saved synchronously on two interconnected ARRP devices, and in the ARP table entries, it is possible to distinguish which ones are learned by themselves and which ones are transmitted through the VRRP connection; then the virtual interface VETH interface is used to open up the network namespace, and the switch, that is, the virtual router of the VRRP device, is opened up, so that the up / down of the VETH interface can be used to replace the up / down of the VRRP device, eliminating the resource consumption of deleting the table entries and the process consumption of re-learning one by one when restoring the table entries. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in this application or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0023] Figure 1 A VRRP usage scenario diagram provided for this application;
[0024] Figure 2 A flow chart of a VRRP routing redundancy optimization method provided in this application;
[0025] Figure 3 A VRRP routing redundancy optimization system architecture diagram provided for this application. DETAILED DESCRIPTION
[0026] In order to enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in this application will be described clearly and completely below in conjunction with the drawings in this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of them. Based on the embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this application.
[0027] The method in this application is described in detail below with reference to the accompanying drawings.
[0028] Figure 2 A flow chart of a VRRP routing redundancy optimization method provided in this application, such as Figure 2 As shown, the method in this application at least includes the following execution steps:
[0029] Step 201: Create corresponding network namespace net_1_bak and network namespace net_2_bak on VRRP device net_1_0 and VRRP device net_2_0 respectively.
[0030] Network namespace is a feature of the Linux kernel that allows multiple independent network environments to be created on the same physical machine. Each network namespace has its own network interface, routing table, IP address, firewall rules, etc. Through network namespace, users can implement a virtualized network environment to isolate different applications or services so that they appear to be running on different physical hosts.
[0031] A VETH interface is a virtual network interface used to create virtual network devices in Linux systems. VETH interfaces are usually paired, and two VETH interfaces are connected through pipes (such as virtual bridges, containers, or network namespaces), similar to two physical network devices connected together through a network cable. The data traffic of a VETH interface is automatically passed to its paired VETH interface.
[0032] This application utilizes the above two concepts to optimize VRRP routing redundancy. Figure 3 This is a VRRP routing redundancy optimization system architecture diagram provided by this application. The content described below can be found in Figure 3 The devices and network namespaces shown.
[0033] Specifically, first create a network namespace net_1_bak on VRRP device net_1_0, and a network namespace net_2_bak on VRRP device net_2_0. Use the characteristics of each network namespace having an independent MAC table entry and an independent ARP table entry to isolate, back up, and restore the MAC table entry and ARP table entry of the VRRP device, which is equivalent to copying the VRRP device to the network namespace net_bak.
[0034] That is, in a possible implementation of the present application, the created network namespace net_1_bak is used to store the MAC table entries and ARP table entries of the peer VRRP device net_2_0, and the network namespace net_2_bak is used to store the MAC table entries and ARP table entries of the peer VRRP device net_1_0.
[0035] Step 202: Use the VETH interface to connect VRRP device net_1_0 and network namespace net_1_bak, and to connect VRRP device net_2_0 and network namespace net_2_bak.
[0036] Create a pair of VETH interfaces on each VRRP device to connect VRRP device net_1_0 and network namespace net_1_bak, and to connect VRRP device net_2_0 and network namespace net_2_bak, which is equivalent to virtualizing the VRRP link.
[0037] Furthermore, in a possible implementation of the present application, after the virtual interface VETH interface is created, the physical interfaces of the VRRP device net_1_0 and the VRRP device net_2_0 are added to the network namespace net_1_bak and the network namespace net_2_bak respectively, and then on the VRRP device net_1_0 and the VRRP device net_2_0, a virtual router is implemented to correspond to the network namespace net_1_bak and the network namespace net_2_bak, and a virtual interface is implemented to correspond to the VETH interface created above.
[0038] Step 203: Run the VRRP protocol between the network namespace net_1_bak and the network namespace net_2_bak.
[0039] VRRP device net_1_0 and network namespace net_1_bak, VRRP device net_2_0 and network namespace net_2_bak have been connected by the VETH interface. At this time, the second layer is connected, which is equivalent to two layer 2 switches.
[0040] In a possible implementation of the present application, when a VRRP device learns an entry, the specific process is as follows:
[0041] If VRRP device net_1_0 learns MAC table entries and ARP table entries, it broadcasts the MAC table entries and ARP table entries to network namespace net_1_bak through its corresponding VETH interface. Network namespace net_1_bak then synchronizes the received MAC table entries and ARP table entries to network namespace net_2_bak through the VRRP protocol. Finally, network namespace net_2_bak saves the MAC table entries and ARP table entries learned by VRRP device net_1_0.
[0042] If VRRP device net_2_0 learns MAC table entries and ARP table entries, it broadcasts the MAC table entries and ARP table entries to network namespace net_2_bak through its corresponding VETH interface. Network namespace net_2_bak then synchronizes the MAC table entries and ARP table entries to network namespace net_1_bak through the VRRP protocol. Finally, network namespace net_1_bak saves the MAC table entries and ARP table entries learned by VRRP device net_2_0.
[0043] In a possible implementation of the present application, when a VRRP device forwards traffic, the specific process is as follows:
[0044] When VRRP device net_1_0 forwards traffic, it searches for the table entry of VRRP device net_1_0 itself to determine whether there is a forwarding path. If so, it forwards the traffic through the table entry of VRRP device net_1_0 itself. If there is no forwarding path in the table entry of VRRP device net_1_0 itself, the traffic is broadcast to network namespace net_1_bak through the VETH interface to search for the table entry of VRRP device net_2_0. If a forwarding path is found in the table entry of VRRP device net_2_0, the traffic is made to reach network namespace net_2_bak through the VRRP protocol, and then given to VRRP device net_2_0 through the VETH interface to be forwarded through the table entry of VRRP device net_2_0.
[0045] Step 204: The offline or online state of the VETH interface is used to replace the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0.
[0046] In this application, the UP / DOWN of the VETH interface pair is used to virtually replace the UP / DOWN of the VRRP device members. When the VRRP device net_1_0 goes offline, the VRRP link is DOWN. There is no need to relearn the ARP table entries to age the ARP device like the traditional VRRP. It is only necessary to cut off the VETH interface corresponding to the VRRP device net_2_0, so as to cut off the connection between the VRRP device net_2_0 and the network namespace net_2_bak. When the VRRP device net_1_0 comes back online, it is only necessary to restore the VETH interface corresponding to the VRRP device net_2_0 to complete the table entry restoration of the VRRP device net_1_0.
[0047] Specifically, when VRRP device net_1_0 goes offline, the VETH interface between VRRP device net_2_0 and network namespace net_2_bak is cut off; and when VRRP device net_2_0 goes offline, the VETH interface between VRRP device net_1_0 and network namespace net_1_bak is cut off.
[0048] Furthermore, when the VRRP device net_1_0 comes back online, the VETH interface between the VRRP device net_2_0 and the network namespace net_2_bak is restored to restore the table entry of the VRRP device net_1_0; and when the VRRP device net_2_0 comes back online, the VETH interface between the VRRP device net_1_0 and the network namespace net_1_bak is restored to restore the table entry of the VRRP device net_2_0.
[0049] Based on the same inventive concept, the present application also provides a VRRP routing redundancy optimization system, whose architecture is as follows: Figure 3 shown.
[0050] Figure 3 A VRRP routing redundancy optimization system architecture diagram provided for this application. Figure 3 As shown, the system in the present application specifically includes: VRRP device net_1_0 and VRRP device net_2_0, network namespace net_1_bak and network namespace net_2_bak; wherein, the VRRP device net_1_0 and the network namespace net_1_bak are connected by using a VETH interface, and the VRRP device net_2_0 and the network namespace net_2_bak are connected by using a VETH interface; the VRRP protocol runs between the network namespace net_1_bak and the network namespace net_2_bak; the offline or online of the VRRP device net_1_0 and / or the VRRP device net_2_0 is replaced by the offline or online of the VETH interface.
[0051] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0052] The equipment and method provided in this application correspond one to one, and therefore, the system also has similar beneficial technical effects as the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the system will not be repeated here.
[0053] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, devices, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media that include computer-usable program code.
[0054] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0055] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A VRRP routing redundancy optimization method, characterized in that: The method comprises: Create corresponding network namespaces net_1_bak and net_2_bak on VRRP devices net_1_0 and VRRP devices net_2_0 respectively. Use the VETH interface to connect VRRP device net_1_0 and network namespace net_1_bak, and connect VRRP device net_2_0 and network namespace net_2_bak; Run the VRRP protocol between network namespace net_1_bak and network namespace net_2_bak; The offline or online state of the VETH interface is used to replace the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0.
2. A VRRP routing redundancy optimization method according to claim 1, characterized in that: The network namespace net_1_bak is used to store the MAC table entries and ARP table entries of the VRRP device net_2_0, and the network namespace net_2_bak is used to store the MAC table entries and ARP table entries of the VRRP device net_2_0.
3. A VRRP routing redundancy optimization method according to claim 1, characterized in that: Before running the VRRP protocol between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: Add the physical interfaces of the VRRP device net_1_0 and the VRRP device net_2_0 to the network namespace net_1_bak and the network namespace net_2_bak respectively; On the VRRP device net_1_0 and the VRRP device net_2_0, a virtual router is implemented to correspond to the network namespace net_1_bak and the network namespace net_2_bak, and a virtual interface is implemented to correspond to the VETH interface.
4. A VRRP routing redundancy optimization method according to claim 1, characterized in that: After running the VRRP protocol between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: When the VRRP device net_1_0 learns the MAC table entry and the ARP table entry, the MAC table entry and the ARP table entry are broadcasted to the network namespace net_1_bak through the VETH interface; The network namespace net_1_bak synchronizes the MAC table entry and the ARP table entry to the network namespace net_2_bak through the VRRP protocol; The network namespace net_2_bak stores the MAC table entries and ARP table entries learned by the VRRP device net_1_0.
5. A VRRP routing redundancy optimization method according to claim 1, characterized in that: After running the VRRP protocol between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: When the VRRP device net_2_0 learns the MAC table entry and the ARP table entry, the MAC table entry and the ARP table entry are broadcasted to the network namespace net_2_bak through the VETH interface; The network namespace net_2_bak synchronizes the MAC table entry and the ARP table entry to the network namespace net_1_bak through the VRRP protocol; The network namespace net_1_bak stores the MAC table entries and ARP table entries learned by the VRRP device net_2_0.
6. A VRRP routing redundancy optimization method according to claim 1, characterized in that: After running the VRRP protocol between the network namespace net_1_bak and the network namespace net_2_bak, the method further includes: When the VRRP device net_1_0 forwards traffic, the table entry of the VRRP device net_1_0 itself is searched to determine whether there is a forwarding path; If it exists, it is forwarded through the table entry of the VRRP device net_1_0 itself.
7. A VRRP routing redundancy optimization method according to claim 6, characterized in that: The method further comprises: If there is no forwarding path in the table entry of the VRRP device net_1_0 itself, broadcast the traffic to the network namespace net_1_bak through the VETH interface to search for the table entry of the VRRP device net_2_0; If a forwarding path is found in the table entry of the VRRP device net_2_0, the traffic is made to reach the network namespace net_2_bak through the VRRP protocol, and then given to the VRRP device net_2_0 through the VETH interface to be forwarded through the table entry of the VRRP device net_2_0.
8. A VRRP routing redundancy optimization method according to claim 1, characterized in that: Using the offline or online state of the VETH interface to replace the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0 includes: When the VRRP device net_1_0 goes offline, the VETH interface between the VRRP device net_2_0 and the network namespace net_2_bak is disconnected.
9. A VRRP routing redundancy optimization method according to claim 8, characterized in that: Using the offline or online state of the VETH interface to replace the offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0, further comprising: When the VRRP device net_1_0 comes back online, the VETH interface between the VRRP device net_2_0 and the network namespace net_2_bak is restored to restore the table entry of the VRRP device net_1_0.
10. A VRRP routing redundancy optimization system, characterized in that: The system comprises: VRRP device net_1_0 and VRRP device net_2_0, network namespace net_1_bak and network namespace net_2_bak; The VRRP device net_1_0 and the network namespace net_1_bak are connected by using a VETH interface, and the VRRP device net_2_0 and the network namespace net_2_bak are connected by using a VETH interface; The VRRP protocol runs between the network namespace net_1_bak and the network namespace net_2_bak; The offline or online state of the VRRP device net_1_0 and / or the VRRP device net_2_0 is replaced by the offline or online state of the VETH interface.