Route issuing method, message transmission method, communication device and communication system
By modifying the next hop address in the route in the SRv6 technical network and keeping the SRv6 VPN SID unchanged, the problem of complex routing release process is solved, and resource conservation and routing release efficiency is improved.
Patent Information
- Application Number
- CN202311531749.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2025-05-16
AI Technical Summary
In networks based on MPLS technology, the routing release process is complex, resulting in low routing release efficiency. With the evolution of MPLS technology to SRv6 technology, this problem still exists in the network forwarding of SRv6 technology.
By modifying the next hop address in the received route during the routing release process, while keeping the SRv6 VPN SID unchanged, avoiding re-applying for the SRv6 VPN SID, thereby saving resources, reducing processing complexity, and improving routing release efficiency.
This method does not require re-applying SRv6 VPN SID, saving resources, reducing performance requirements, simplifying routing processing, and improving routing release efficiency.
Smart Images

Figure CN120017581A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network technology, and in particular to a routing publishing method, a message transmission method, a communication device, and a communication system. Background Art
[0002] Currently, different hosts belonging to the same virtual private network (VPN) can communicate across sites through a network that uses multiprotocol label switching (MPLS) technology to forward messages between hosts located at different sites.
[0003] For network deployment modes such as cross-domain VPN-Option B or hierarchical VPN (HVPN), when forwarding based on MPLS technology, some network devices in the network need to change the next hop and re-apply for labels during the route publishing process. For example, in the cross-domain VPN-Option B deployment mode, when an autonomous system border router (ASBR) in an autonomous system (AS) domain sends a route to an ASBR in another AS domain, it needs to re-apply for a VPN label locally and change the next hop of the route from the address of the provider edge (PE) device in the domain to its own local address. After receiving the route, the ASBR in another AS domain also needs to re-apply for a VPN label locally and change the next hop address in the route to its own local address before sending it to the PE device in the domain. For another example, in the HVPN deployment mode, the service provider-end PE (SPE) on the operator side needs to re-apply for a VPN label locally and change the next hop address for both the upstream and downstream routes and continue to transmit the route. The entire route publishing process is relatively complicated, resulting in low route publishing efficiency.
[0004] As MPLS technology evolves to segment routing over IPv6 (SRv6) technology based on Internet Protocol version 6 (IPv6), if the above-mentioned route publishing method continues to be applied to a network forwarded based on SRv6 technology, the same problems of complex route publishing process and low route publishing efficiency will also occur. Summary of the invention
[0005] The present application provides a routing publishing method, a message transmission method, a communication device, and a communication system.
[0006] In a first aspect, a route publishing method is provided. The method includes: a first communication device receives a first route announced by a second communication device. The first route includes a segment identification (SID) of a VPN of SRv6 (abbreviated as: SRv6 VPN SID) and a first next hop address. The first next hop address is an IPv6 address of the second communication device. The first communication device sends a second route to a third communication device. The second route includes the SRv6 VPN SID and a second next hop address. The second next hop address is the IPv6 address of the first communication device.
[0007] In the present application, the first communication device modifies the next hop address in the received route during the route publishing process, while keeping the original SRv6 VPN SID in the route unchanged. Since the first communication device does not need to reapply for the SRv6 VPNSID, the resources of the first communication device can be saved, and the performance requirements for the first communication device are relatively low. In addition, since the first communication device does not need to modify the SRv6 VPN SID carried in the route, the complexity of the first communication device in processing the route is reduced, so the efficiency of route publishing can be improved.
[0008] In a first specific implementation, the first communication device is an ASBR of a first AS domain, and the third communication device is an ASBR of a second AS domain.
[0009] In combination with the above-mentioned first specific implementation, the second communication device is a PE device of the first AS domain, and the SRv6 VPNSID is allocated by the second communication device.
[0010] In a second specific implementation, the second communication device is an ASBR of the first AS domain, and the first communication device is an ASBR of the second AS domain.
[0011] In combination with the second specific implementation described above, the SRv6 VPN SID is allocated by a PE device in the first AS domain.
[0012] In the above-mentioned first specific implementation and the second specific implementation, the first communication device, the second communication device and the third communication device may be network devices in a communication network adopting a cross-domain VPN-Option B networking mode.
[0013] In a third specific implementation, the first communication device is an SPE device, the second communication device is a user-end PE (UPE) device, and the third communication device is a network provider-end PE (NPE) device.
[0014] In a fourth specific implementation, the first communication device is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device.
[0015] In combination with the third or fourth specific implementation, the SRv6 VPN SID is allocated by the second communication device. Specifically, in the third specific implementation, the SRv6 VPN SID is allocated by the UPE device. In the fourth specific implementation, the SRv6 VPN SID is allocated by the NPE device.
[0016] In the third specific implementation and the fourth specific implementation, the first communication device, the second communication device and the third communication device may be network devices in a communication network that adopts an HVPN networking manner.
[0017] In a specific implementation, the first route is a layer 3 virtual private network (L3VPN) route based on Border Gateway Protocol (BGP) and Internet Protocol version 4 (IPv4) (referred to as BGP L3VPNv4 route), an L3VPN route based on BGP and IPv6 (referred to as BGP L3VPNv6 route), an L3VPN route based on BGP and IPv4 under an Ethernet virtual private network (EVPN) (referred to as BGP EVPN L3VPNv4 route), an L3VPN route based on BGP and IPv6 under EVPN (referred to as BGP EVPN L3VPNv6 route), or a layer 2 virtual private network (L2VPN) route based on BGP under EVPN (referred to as BGP EVPN L2VPN route). Among them, BGP L3VPNv4 routes, BGP L3VPNv6 routes, BGP EVPN L3VPNv4 routes and BGP EVPN L3VPNv6 routes are used to publish Internet Protocol (IP) routes, and BGP EVPN L2VPN routes are used to publish Media Access Control (MAC) routes.
[0018] In a specific implementation, after the first communication device receives the first route announced by the second communication device, the first communication device receives a first message, the first message includes the SRv6 VPN SID. The first communication device generates a second message based on the first message, the second message includes the SRv6 VPN SID. The first communication device sends the second message to the second communication device.
[0019] The present application uses the same SRv6 VPN SID for multi-hop forwarding. The first communication device does not need to modify the SRv6 VPN SID carried in the message during message forwarding, which can improve message forwarding efficiency.
[0020] In a second aspect, a message transmission method is provided. The method includes: a first communication device receives a first message, the first message includes an SRv6 VPN SID. The first communication device generates a second message according to the first message, the second message includes the SRv6 VPN SID. The first communication device sends the second message to the second communication device.
[0021] The present application uses the same SRv6 VPN SID for multi-hop forwarding. The first communication device does not need to modify the SRv6 VPN SID carried in the message during message forwarding, which can improve message forwarding efficiency.
[0022] In a first specific implementation, the first communication device is an ASBR of a first AS domain, and the third communication device is an ASBR of a second AS domain.
[0023] In combination with the above-mentioned first specific implementation, the second communication device is a PE device of the first AS domain, and the SRv6 VPNSID is allocated by the second communication device.
[0024] In a second specific implementation, the second communication device is an ASBR of the first AS domain, and the first communication device is an ASBR of the second AS domain.
[0025] In combination with the second specific implementation described above, the SRv6 VPN SID is allocated by a PE device in the first AS domain.
[0026] In a third specific implementation, the first communication device is an SPE device, the second communication device is a user-end PE (UPE) device, and the third communication device is a network provider-end PE (NPE) device.
[0027] In a fourth specific implementation, the first communication device is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device.
[0028] In combination with the third or fourth specific implementation, the SRv6 VPN SID is allocated by the second communication device.
[0029] In a third aspect, a communication device is provided, the communication device comprising a plurality of functional modules, the plurality of functional modules interacting with each other to implement the method in the first aspect or any possible implementation of the first aspect. The plurality of functional modules may be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules may be arbitrarily combined or divided based on specific implementations.
[0030] For example, the communication device is a first communication device, and the multiple functional modules include a receiving module and a sending module. In a specific implementation, the multiple functional modules also include a processing module.
[0031] The receiving module is used to receive the first route announced by the second communication device. The first route includes the SRv6 VPN SID and the first next hop address. The first next hop address is the IPv6 address of the second communication device. The sending module is used to send the second route to the third communication device. The second route includes the SRv6 VPN SID and the second next hop address. The second next hop address is the IPv6 address of the first communication device.
[0032] In a first specific implementation, the first communication device is an ASBR of a first AS domain, and the third communication device is an ASBR of a second AS domain.
[0033] In combination with the above-mentioned first specific implementation, the second communication device is a PE device of the first AS domain, and the SRv6 VPNSID is allocated by the second communication device.
[0034] In a second specific implementation, the second communication device is an ASBR of the first AS domain, and the first communication device is an ASBR of the second AS domain.
[0035] In combination with the second specific implementation described above, the SRv6 VPN SID is allocated by a PE device in the first AS domain.
[0036] In a third specific implementation, the first communication device is an SPE device, the second communication device is a UPE device, and the third communication device is an NPE device.
[0037] In a fourth specific implementation, the first communication device is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device.
[0038] In combination with the third or fourth specific implementation, the SRv6 VPN SID is allocated by the second communication device.
[0039] In a specific implementation, the first route is a BGP L3VPNv4 route, a BGP L3VPNv6 route, a BGP EVPN L3VPNv4 route, a BGP EVPN L3VPNv6 route or a BGP EVPN L2VPN route.
[0040] In a specific implementation, the receiving module is further used to receive a first message after receiving the first route announced by the second communication device, the first message including the SRv6 VPN SID. The processing module is used to generate a second message according to the first message, the second message including the SRv6 VPN SID. The sending module is further used to send the second message to the second communication device.
[0041] In a fourth aspect, a communication device is provided, the communication device comprising a plurality of functional modules, the plurality of functional modules interacting with each other to implement the method in the second aspect or any possible implementation of the second aspect. The plurality of functional modules may be implemented based on software, hardware, or a combination of software and hardware, and the plurality of functional modules may be arbitrarily combined or divided based on specific implementations.
[0042] For example, the communication device is a first communication device, and the multiple functional modules include a receiving module, a processing module, and a sending module.
[0043] The receiving module is used to receive a first message, wherein the first message includes the SRv6 VPN SID. The processing module is used to generate a second message according to the first message, wherein the second message includes the SRv6 VPN SID. The sending module is used to send the second message to the second communication device.
[0044] In a first specific implementation, the first communication device is an ASBR of a first AS domain, and the third communication device is an ASBR of a second AS domain.
[0045] In combination with the above-mentioned first specific implementation, the second communication device is a PE device of the first AS domain, and the SRv6 VPNSID is allocated by the second communication device.
[0046] In a second specific implementation, the second communication device is an ASBR of the first AS domain, and the first communication device is an ASBR of the second AS domain.
[0047] In combination with the second specific implementation described above, the SRv6 VPN SID is allocated by a PE device in the first AS domain.
[0048] In a third specific implementation, the first communication device is an SPE device, the second communication device is a UPE device, and the third communication device is an NPE device.
[0049] In a fourth specific implementation, the first communication device is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device.
[0050] In combination with the third or fourth specific implementation, the SRv6 VPN SID is allocated by the second communication device.
[0051] In a fifth aspect, a communication system is provided, comprising: a plurality of communication devices, wherein there is a communication device among the plurality of communication devices for executing the method in the first aspect or any possible implementation of the first aspect, and / or the method in the second aspect or any possible implementation of the second aspect.
[0052] In a specific implementation, the communication system adopts cross-domain VPN-Option B networking, and the ASBR in the communication system is used to execute the method in the above-mentioned first aspect or any possible implementation of the first aspect, and / or the method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0053] In a specific implementation, the communication system adopts HVPN networking, and the SPE in the communication system is used to execute the method in the above-mentioned first aspect or any possible implementation of the first aspect, and / or the method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0054] In a sixth aspect, a communication device is provided, comprising: a communication interface; and a processor connected to the communication interface; according to the communication interface and the processor, the method in the above-mentioned first aspect or any possible implementation manner of the first aspect, and / or the method in the above-mentioned second aspect or any possible implementation manner of the second aspect is implemented.
[0055] In a specific implementation, the communication device may be a network device, such as a router, a switch, or a packet transport network (PTN) device, etc. Alternatively, the communication device may also be a communication entity in a network device, such as a chip, an interface board, or a line card, etc., for performing some or all operations of the method described in the present application.
[0056] For example, the above-mentioned communication device is a chip, which may include a programmable logic circuit and / or program instructions. When the chip is running, it implements the method in the above-mentioned first aspect or any possible implementation of the first aspect, and / or the above-mentioned second aspect or any possible implementation of the second aspect.
[0057] In the seventh aspect, a computer-readable storage medium is provided, on which instructions are stored. When the instructions are executed by a processor, the method in the above-mentioned first aspect or any possible implementation of the first aspect is implemented, and / or the method in the above-mentioned second aspect or any possible implementation of the second aspect is implemented.
[0058] In an eighth aspect, a computer program product is provided, comprising a computer program, which, when executed by a processor, implements the method in the above-mentioned first aspect or any possible implementation of the first aspect, and / or the method in the above-mentioned second aspect or any possible implementation of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 This is a schematic diagram of a cross-domain VPN-Option B network;
[0060] Figure 2 It is a schematic diagram of route publishing based on MPLS technology in cross-domain VPN-Option B networking;
[0061] Figure 3 It is a schematic diagram of message forwarding based on MPLS technology in cross-domain VPN-Option B networking;
[0062] Figure 4 This is a schematic diagram of HVPN networking;
[0063] Figure 5 It is a schematic diagram of route publishing based on MPLS technology in HVPN networking;
[0064] Figure 6 It is a schematic diagram of message forwarding based on MPLS technology in HVPN networking;
[0065] Figure 7 This is a schematic diagram of an application scenario provided by an embodiment of the present application;
[0066] Figure 8 It is a flowchart of a routing publishing method provided in an embodiment of the present application;
[0067] Fig. 9 This is a schematic diagram of the structure of a BGP update message provided in an embodiment of the present application;
[0068] Fig.10 This is a schematic diagram of routing publication provided in an embodiment of the present application;
[0069] Fig.11 It is a flowchart of a message transmission method provided in an embodiment of the present application;
[0070] Fig.12This is a schematic diagram of message forwarding provided in an embodiment of the present application;
[0071] Fig.13 This is a schematic diagram of routing publication based on SRv6 technology in a cross-domain VPN-Option B network provided in an embodiment of the present application;
[0072] Fig.14 This is a schematic diagram of message forwarding based on SRv6 technology in a cross-domain VPN-Option B network provided in an embodiment of the present application;
[0073] Fig.15 This is a schematic diagram of routing release based on SRv6 technology in an HVPN network provided by an embodiment of the present application;
[0074] Fig.16 This is a schematic diagram of message forwarding based on SRv6 technology in an HVPN network provided by an embodiment of the present application;
[0075] Fig.17 is a structural diagram of a communication device provided in an embodiment of the present application;
[0076] Fig.18 is a block diagram of a communication device provided in an embodiment of the present application;
[0077] Fig.19 It is a block diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0078] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0079] Currently, hosts located at different sites can communicate across sites. A site can be considered as a local area network, such as a single network segment local area network or a multiple network segment local area network. Different sites can be deployed in different regions. One or more hosts can be deployed in a site. A host refers to a terminal device with a client installed, such as a smartphone, tablet computer, desktop computer, Internet of Things (IoT) device, network device, workstation or server.
[0080] Hosts within a site usually belong to a private network. Different hosts within a site can belong to the same private network or different private networks. Hosts within a private network are usually configured with an intranet address. Since the intranet addresses of different private networks can overlap, the intranet addresses configured for hosts within a private network can generally only be used to communicate within the private network. Private networks can be deployed across sites, that is, a private network can include multiple hosts deployed at different sites. For example, a private network is distributed and deployed at site A and site B, and site A and site B are connected through a carrier network, which means that the private network includes hosts located at site A and hosts located at site B. Private networks can be implemented using VPNs. For a private network, hosts deployed in the private network are intranet hosts, while carrier networks and other private networks are external networks. Among them, the carrier network used to connect different sites can be a wide area backbone network or a metropolitan area network established using MPLS technology or SRv6 technology. The private network here can be a private network of an enterprise. The network of an enterprise at a certain site is the enterprise's internal network, and the multiple networks of the enterprise deployed at multiple sites are called the enterprise's private network or multi-site private network.
[0081] For a private network distributed in multiple sites, if the intranet host of one site wants to send a message to the intranet host of another site, the transmission of the message needs to pass through the external network between the two sites. The intranet host of a site needs to communicate with the external network through the edge access device of the site. The edge access device of the site is usually called a customer edge (CE) device. CE devices can be, for example, routers, switches, or gateways. Taking the external network as an operator network as an example, the CE device of each site is connected to a PE device. When the intranet host of one site sends a message to the intranet host of another site, the message first arrives at the CE device of the local site, and then is transmitted by the CE device of the local site to the connected PE device. Then, the message arrives at the remote PE device after being transmitted via the operator network, and then is transmitted by the remote PE device to the CE device of the remote site, and finally is transmitted by the CE device of the remote site to the intranet host of the remote site.
[0082] Optionally, hosts at different sites can communicate via a Layer 2 network or a Layer 3 network. Different hosts communicate via a Layer 2 network, that is, different hosts communicate based on MAC routing. Different hosts communicate via a Layer 3 network, that is, different hosts communicate based on IP routing.
[0083] In existing networks, the network can be divided into different AS domains based on factors such as management, operation and maintenance, and device performance, or the network can be deployed in layers within the same AS domain. For example, cross-domain VPN-Option B is a commonly used cross-domain networking method. HVPN is a commonly used network layered networking method.
[0084] In the inter-domain VPN-Option B networking mode, ASBRs publish routes through the multiprotocol border gateway protocol (MP-BGP). For example, Figure 1 This is a schematic diagram of cross-domain VPN-Option B networking. Figure 1 As shown, the communication network includes two AS domains, AS100 and AS200. AS100 includes two PE devices, PE1 and PE2, two provider (P) devices, P1 and P2, and two ASBRs, ASBR1 and ASBR2. Among them, PE1 is connected to PE2, P1 is connected to P2, and ASBR1 is connected to ASBR2. PE1 is connected to P1, and PE2 is connected to P2. P1 is connected to ASBR1, and P2 is connected to ASBR2. CE1 dual-home connects PE1 and PE2 to access AS100, that is, PE1 and PE2 are dual-home access devices of CE1. AS200 includes two PE devices, PE3 and PE4, two P devices, P3 and P4, and two ASBRs, ASBR3 and ASBR4. Among them, PE3 is connected to PE4, P3 is connected to P4, and ASBR3 is connected to ASBR4. PE3 is connected to P3, and PE4 is connected to P4. P3 is connected to ASBR3, and P4 is connected to ASBR4. CE2 is dual-homed to PE3 and PE4 to access AS200, that is, PE3 and PE4 are dual-homed access devices of CE2. ASBR1 in AS100 is connected to ASBR2 in AS200, and ASBR2 in AS100 is connected to ASBR4 in AS200, so that communication between AS100 and AS200 is realized. If CE1 and CE2 belong to the same VPN, CE1 and CE2 can realize cross-domain communication through AS100 and AS200.
[0085] Below Figure 1 The communication network shown in the figure is forwarded based on MPLS technology as an example. Figure 2 and Figure 3 The route publishing process and the message forwarding process in the communication network are described respectively. A label switched path (LSP) (public network tunnel) is established between PE1 and ASBR1 through P1, and an LSP (public network tunnel) is established between PE3 and ASBR3 through P3.
[0086] For example, Figure 2 This is a schematic diagram of routing announcement based on MPLS technology in a cross-domain VPN-Option B network. Figure 2 As shown in the figure, after PE1 learns the IP route or MAC route (IP / MAC route for short) of CE1, it allocates a private network label VPN Label1 to the IP / MAC route, and then sends BGP route 11 containing the IP / MAC route and VPN Label1 to ASBR1. The next hop address in BGP route 11 is the IP address of PE1. After receiving BGP route 11, ASBR1 generates a forwarding table entry, which indicates that the next hop corresponding to VPN Label1 is PE1, and re-applies for private network label VPN Label2 locally, establishes a mapping relationship between VPN Label1 and VPN Label2, and sends BGP route 12 containing the IP / MAC route and VPN Label2 to ASBR3. The next hop address in BGP route 12 is the IP address of ASBR1. After receiving BGP route 12, ASBR3 generates a forwarding entry, which indicates that the next hop corresponding to VPN Label2 is ASBR1, and re-applies for private network label VPN Label3 locally, establishes a mapping relationship between VPN Label2 and VPN Label3, and sends BGP route 13 containing the IP / MAC route and VPN Label3 to PE3. The next hop address in BGP route 13 is the IP address of ASBR3. After receiving BGP route 13, PE3 generates a forwarding entry, which indicates that the next hop corresponding to VPN Label3 is ASBR3, and establishes a mapping relationship between the IP / MAC route and VPN Label3. Further, PE3 sends the IP / MAC route to CE2. For the sake of illustration, Figure 2 The P device is not shown in the figure. The private network label is also called VPN label, and the public network label is also called Label Distribution Protocol (LDP) label.
[0087] In the embodiment of the present application, the IP route of the CE learned by the PE may be issued by the CE to the PE. The MAC route of the CE learned by the PE may be learned by the PE based on the data traffic from the CE.
[0088] Accordingly, Figure 3 This is a schematic diagram of packet forwarding based on MPLS technology in a cross-domain VPN-Option B network. Figure 3As shown, CE2 sends an original message to CE1, and the original message is a layer 2 message or a layer 3 message. After PE3 receives the original message, it obtains the private network label VPN Label3 corresponding to the destination address of the original message based on the local mapping relationship, and then generates MPLS message 11. MPLS message 11 includes an MPLS header and a message payload. The MPLS header includes the public network label LDPLabel1 and the private network label VPN Label3 assigned by P3. The original message sent by CE2 is encapsulated in the message payload. PE3 sends MPLS message 11 to the next hop (ASBR3) based on the local forwarding table. After P3 receives the MPLS message 11 sent by PE3, it can pop out the public network label LDP Label1, and then continue to send MPLS message 12 to ASBR3. The MPLS message 12 received by ASBR3 includes an MPLS header and a message payload. The MPLS header includes the private network label VPN Label3 assigned by itself. ASBR3 obtains the private network label VPN Label2 corresponding to the private network label VPN Label3 based on the local mapping relationship, and modifies the private network label in the MPLS header of the received MPLS message 12 to VPN Label2, and obtains MPLS message 13. ASBR3 sends MPLS message 13 to the next hop (ASBR1) based on the local forwarding table. The MPLS message 13 received by ASBR1 includes an MPLS header and a message payload, and the MPLS header includes the private network label VPN Label2 allocated by itself. ASBR1 obtains the private network label VPN Label1 corresponding to the private network label VPNLabel2 based on the local mapping relationship, and modifies the private network label in the MPLS header of the received MPLS message 13 to VPN Label1, and encapsulates the public network label LDP Label2 allocated by P1 in the MPLS header, and obtains MPLS message 14. ASBR1 sends MPLS message 14 to the next hop (PE1) based on the local forwarding table. After P1 receives MPLS message 14 sent by ASBR1, it can pop out the public network label LDP Label2 and continue to send MPLS message 15 to PE1. MPLS message 15 received by PE1 includes an MPLS header and a message payload. The MPLS header includes the private network label VPN Label1 allocated by itself. Finally, PE1 strips off the MPLS header of MPLS message 15 and sends the original message from CE2 to CE1. Figure 3 The message structure shown is only used for exemplary description, and an actual MPLS message may further include an encapsulated outer MAC header before the MPLS header.
[0089] For ease of understanding, Figure 1 and Figure 3In the illustrated scenario, only one P device is drawn between the PE device and the ASBR. Those skilled in the art will appreciate that multiple P devices may be included between the PE device and the ASBR.
[0090] Based on the above Figure 2 It can be seen from the route publishing process shown that under the cross-domain VPN-Option B deployment mode, when the ASBR in one AS domain sends a route to the ASBR in another AS domain, it needs to re-apply for a VPN label locally and modify the next hop of the route from the address of the PE device in this domain to its own local address. After receiving the route, the ASBR in another AS domain also needs to re-apply for a VPN label locally and modify the next hop address in the route to its own local address. This process consumes a large amount of label resources of the ASBR and places high performance requirements on the ASBR. In addition, since the ASBR needs to re-apply for the VPN label and modify the VPN label in the route, the entire route publishing process will be more complicated, resulting in lower route publishing efficiency. Accordingly, based on the above Figure 3 It can be seen from the message forwarding process shown that when an ASBR in an AS domain forwards a message to an ASBR in another AS domain, and when an ASBR in an AS domain forwards a message to a PE device in the domain, it is necessary to query the mapping relationship between the private network label assigned to itself and the private network label assigned by the next hop, and modify the private network label carried in the message, which makes the message forwarding process more complicated and leads to low message forwarding efficiency.
[0091] HVPN is a hierarchical VPN that includes multiple PE devices with different roles and forms a hierarchical structure, which places lower performance requirements on UPE devices. Figure 4 This is a schematic diagram of HVPN networking. Figure 4 As shown, the communication network includes four UPE devices, UPE1 to UPE4, two SPE devices, SPE1 and SPE2, and two NPE devices, NPE1 and NPE2. UPE1 to UPE4, SPE1, SPE2, NPE1 and NPE2 are located in the same AS domain (AS100). Among them, the UPE device is used to access the CE device and mainly implement the user access function. The UPE device can be, for example, a cell site gateway (CSG). The SPE device is used to access the UPE device and mainly implement routing management and publishing. The SPE device can be, for example, an aggregation site gateway (ASG). The NPE device is connected to the SPE device and faces the network. The NPE device can be, for example, a radio network controller site gateway (RSG). See Figure 4, UPE1 is connected to UPE2, CE1 is dual-homed to UPE1 and UPE2 to access the communication network. UPE3 is connected to UPE4, CE2 is dual-homed to UPE3 and UPE4 to access the communication network. SPE1 is connected to UPE1 and UPE3 respectively, and SPE2 is connected to UPE2 and UPE4 respectively. NPE1 is connected to SPE1, and NPE2 is connected to SPE2. NPE1 is connected to NPE2, and CE3 is dual-homed to NPE1 and NPE2. CE1, CE2, and CE3 can be, for example, base stations or access points (APs).
[0092] Below Figure 4 The communication network shown in the figure is forwarded based on MPLS technology as an example. Figure 5 and Figure 6 The publishing process of the uplink route and the forwarding process of the downlink message in the communication network are described respectively. An LSP (public network tunnel) is established between UPE1 and SPE1, and an LSP (public network tunnel) is established between SPE1 and NPE1.
[0093] For example, Figure 5 This is a schematic diagram of route publishing based on MPLS technology in HVPN networking. Figure 5 As shown, after UPE1 learns the IP / MAC route of CE1, it assigns a private network label VPN Label1 to the IP / MAC route, and then sends a BGP route 21 containing the IP / MAC route and VPN Label1 to SPE1. The next hop address in BGP route 21 is the IP address of UPE1. After receiving BGP route 21, SPE1 generates a forwarding table entry, which indicates that the next hop corresponding to VPN Label1 is UPE1, and re-applies for private network label VPN Label2 locally, establishes a mapping relationship between VPN Label1 and VPN Label2, and sends a BGP route 22 containing the IP / MAC route and VPN Label2 to NPE1. The next hop address in BGP route 22 is the IP address of SPE1. After receiving BGP route 22, NPE1 generates a forwarding table entry, which indicates that the next hop corresponding to VPNLabel2 is SPE1, and establishes a mapping relationship between the IP / MAC route and VPN Label2. Further, NPE1 sends the IP / MAC route to CE3.
[0094] Accordingly, Figure 6 This is a schematic diagram of packet forwarding based on MPLS technology in HVPN networking. Figure 6As shown, CE3 sends an original message to CE1, and the original message is a layer 2 message or a layer 3 message. After receiving the original message, NPE1 obtains the private network label VPN Label2 corresponding to the destination address of the original message based on the local mapping relationship, and then generates MPLS message 21. MPLS message 21 includes an MPLS header and a message payload. The MPLS header includes the public network label LDP Label1 and the private network label VPN Label2 corresponding to the LSP between SPE1 and NPE1. The original message sent by CE3 is encapsulated in the message payload. NPE1 sends MPLS message 21 to the next hop (SPE1) based on the local forwarding table entry. After receiving MPLS message 21, SPE1 pops out the public network label LDP Label1, obtains the private network label VPN Label1 corresponding to the private network label VPN Label2 based on the local mapping relationship, pops out the private network label VPN Label2, and then generates MPLS message 22. MPLS message 22 includes an MPLS header and a message payload. The MPLS header includes the public network label LDP Label2 and the private network label VPN Label1 corresponding to the LSP between SPE1 and CPE1. The original message sent by CE3 is encapsulated in the message payload. SPE1 sends MPLS message 22 to the next hop (UPE1) based on the local forwarding entry. After receiving MPLS message 22, UPE1 strips off the MPLS header of MPLS message 22 and sends the original message from CE3 to CE1.
[0095] HVPN is divided into two deployment schemes: HoVPN and H-VPN. The uplink route publishing process and downlink message forwarding process in the communication network using the HoVPN scheme and the communication network using the H-VPN scheme are the same, refer to Figure 5 and Figure 6 The process of publishing downlink routes and forwarding uplink messages in a communication network using the H-VPN solution are respectively the same as those described above. Figure 5 and Figure 6 The process of publishing the upstream route shown is similar to the process of forwarding the downstream message, and the embodiments of the present application will not be repeated here. When a communication network using the HoVPN solution publishes a downstream route, the SPE device will convert the detailed route from the NPE device into a default route or an aggregated private network route and publish it to the UPE device. In this process, the SPE device will also re-apply for a VPN label to be carried in the route published to the UPE device, and modify the next hop address in the route published to the UPE device to its own local address.
[0096] Based on the above Figure 5It can be seen from the route publishing process shown that, under the HVPN deployment mode, the SPE device needs to re-apply for VPN labels locally for both upstream and downstream routes and continue to transmit the routes after changing the next hop. This process consumes a large amount of label resources of the SPE device and places high performance requirements on the SPE device. In addition, since the SPE device needs to re-apply for VPN labels and modify the VPN labels in the routes, the entire route publishing process will be more complicated, resulting in lower route publishing efficiency. Accordingly, based on the above Figure 6 It can be seen from the message forwarding process shown that when the SPE device forwards a message, it needs to query the mapping relationship between the private network label allocated by itself and the private network label allocated by the next hop, and modify the private network label carried in the message, which makes the message forwarding process more complicated and further leads to low message forwarding efficiency.
[0097] With the evolution of MPLS technology to SRv6 technology, the above-mentioned route publishing and message forwarding methods based on MPLS technology are applied to the network forwarded based on SRv6 technology in related technologies, and the next hop is changed and VPN SID (corresponding to the private network label under MPLS technology) is re-applied during the route publishing process through ASBR or SPE devices. Similarly, there will be problems such as high consumption of VPN SID resources of ASBR and SPE devices, high requirements on device performance, and low efficiency of route publishing and message forwarding.
[0098] Due to the MPLS technology, the VPN label assigned by the PE device to the private network route is globally unique only in this device, that is, the VPN label has only local meaning and cannot be used for multi-hop forwarding. Therefore, the ASBR in the cross-domain VPN-Option B network and the SPE in the HVPN network need to reapply for the VPN label when changing the next hop. Under the SRv6 technology, the VPN SID (referred to as SRv6VPN SID in this application) assigned by the PE device to the private network route is unique in the entire network. Based on this, this application proposes a technical solution for using SRv6 VPN SID for multi-hop forwarding. The route publishing process in the technical solution provided by this application is as follows: a first communication device receives a first route announced by a second communication device, the first route includes an SRv6 VPN SID and a first next hop address, and the first next hop address is the IPv6 address of the second communication device. The first communication device sends a second route to a third communication device, the second route includes the SRv6 VPN SID and a second next hop address, and the second next hop address is the IPv6 address of the first communication device. That is, during the route publishing process, the first communication device modifies the next hop address in the received route, while keeping the original SRv6 VPN SID in the route unchanged. Since the first communication device does not need to reapply for the SRv6VPN SID, the resources of the first communication device can be saved, and the performance requirements for the first communication device are relatively low. In addition, since the first communication device does not need to modify the SRv6 VPN SID carried in the route, the complexity of the first communication device in processing the route is reduced, so the efficiency of route publishing can be improved. Accordingly, the message transmission process in the technical solution provided by the present application is as follows: the first communication device receives a first message, and the first message includes the SRv6 VPN SID. The first message may be sent directly by the third communication device to the first communication device, or it may be sent indirectly by the third communication device to the first communication device through other communication devices. The first communication device generates a second message based on the first message, and the second message includes the SRv6 VPNSID. The first communication device sends a second message to the second communication device. The present application uses the same SRv6 VPN SID for multi-hop forwarding. The first communication device does not need to modify the SRv6 VPN SID carried in the message during message forwarding, which can improve message forwarding efficiency.
[0099] Among them, the SRv6 VPN SID is an instantiated IPv6 address with a length of 128 bits. The SRv6 VPN SID includes a location identifier (Locator) and a function (Function). The Locator in the SRv6 VPN SID mainly undertakes the routing function and is unique in the SR domain. After the communication device is configured with the Locator, the communication device will generate a Locator network segment route and spread it in the SR domain through the Interior Gateway Protocol (IGP). Other communication devices in the network can locate the communication device configured with the Locator through the Locator network segment route. At the same time, all SRv6 VPN SIDs published by the communication device configured with the Locator can also reach other communication devices through the Locator network segment route. The Function in the SRv6 VPN SID may be pre-set by the communication device that generates the SRv6 VPN SID, and is used to instruct the communication device that generates the SRv6 VPN SID to perform a corresponding functional operation, for example, instructing the communication device that generates the SRv6 VPN SID to perform a certain forwarding behavior, or instructing the communication device that generates the SRv6 VPN SID to implement a certain service, etc.
[0100] The following is a detailed introduction to the technical solution of this application from multiple angles, including application scenarios, method flow, virtual devices, physical devices, and systems.
[0101] The following is an illustration of the application scenarios involved in the embodiments of the present application.
[0102] The application scenarios of the embodiments of the present application include a communication network and a site accessing the communication network. The communication network is a VPN network based on SRv6, including but not limited to an EVPN L3VPN network based on SRv6 (EVPN L3VPN overSRv6), an L3VPN network based on SRv6 (L3VPN over SRv6), or an EVPN L2VPN network based on SRv6 (EVPNL2VPN over SRv6). The communication network is a bearer network, such as an IP-based wireless access network (IP radioaccess network, IPRAN) or a metropolitan area network, which can be used to carry EVPN services and / or L3VPN services. The communication network can be an operator network or an enterprise-built network. The networking method adopted by the communication network includes but is not limited to cross-domain VPN-Option B or HVPN.
[0103] The communication network provided in the embodiment of the present application includes multiple network devices for service forwarding, and the multiple network devices are communicatively connected. Each network device may be a switch, a router, or a PTN device, etc. Among them, the multiple network devices include edge network devices and core network devices. The edge network device is at the edge of the communication network and is used for sites to access the communication network. The core network device is connected between different edge network devices and is used to forward services between different edge network devices. Optionally, the site is connected to the edge network device of the communication network through an edge access device to access the communication network through the edge access device. The edge access device may be a switch, a router, or a gateway, etc. The embodiment of the present application takes the communication network as an operator network as an example for explanation, the edge network device is a PE device, the core network device is a P device, the edge access device is a CE device, and one or more hosts are deployed in the site accessing the communication network.
[0104] Optionally, after the PE device learns the IP / MAC route of the CE device, it needs to publish the learned IP / MAC route and its corresponding SRv6 VPN SID in the communication network. There are multiple ways for the PE device to allocate SRv6 VPN SIDs to IP / MAC routes. For example, the PE device can allocate an SRv6 VPN SID for each VPN instance configured in the PE device, so that the SRv6 VPN SIDs corresponding to all IP / MAC routes published by the same VPN instance in the PE device are the same SRv6VPN SID. Alternatively, the PE device can allocate an SRv6 VPN SID for each IP / MAC route. Alternatively, the PE device can allocate an SRv6 VPN SID for each connected CE, so that the SRv6 VPN SIDs corresponding to all IP / MAC routes of the same CE device learned by the PE device are the same SRv6 VPN SID. Alternatively, the PE device can allocate an SRv6 VPN SID for a broadcast domain, so that the SRv6 VPN SIDs corresponding to all MAC routes published by the PE device in the broadcast domain are the same SRv6 VPN SID. The embodiment of the present application does not limit the manner in which the PE device allocates the SRv6 VPN SID.
[0105] For example, Figure 7 This is a schematic diagram of an application scenario provided by an embodiment of the present application. Figure 7As shown, the application scenario includes a communication network and two CE devices, CE1 and CE2, connected to the communication network. The communication network includes at least three network devices A1 to A3. Among them, network device A1 is connected to network device A2, and network device A2 is connected to network device A3. CE1 is directly or indirectly connected to network device A1, and CE2 is directly or indirectly connected to network device A3. Among them, the indirect connection between the CE device and the network device can be that the CE device is connected to the network device through the PE device.
[0106] Optionally, Figure 7 The application scenario shown can be as follows Figures 1 to 3 Any of the application scenarios shown. Figure 7 For example, CE1 in Figures 1 to 3 CE1 in Figure 7 For example, CE2 in Figures 1 to 3 CE2 in . One possible situation is, Figure 7 The network device A1 in the example may be Figures 1 to 3 PE1 in Figure 7 The network device A2 in the example may be Figures 1 to 3 ASBR1 in Figure 7 For example, the network device A3 in Figures 1 to 3 Another possible scenario is Figure 7 The network device A1 in the example may be Figures 1 to 3 ASBR1 in Figure 7 The network device A2 in the example may be Figures 1 to 3 ASBR3 in Figure 7 For example, the network device A3 in Figures 1 to 3 PE3 in.
[0107] or, Figure 7 The application scenario shown can be as follows Figures 4 to 6 Any of the application scenarios shown. Figure 7 For example, CE1 in Figures 4 to 6 CE1 in Figure 7 For example, CE2 in Figures 4 to 6 CE3 in Figure 7 The network device A1 in the example may be Figures 4 to 6 UPE1 in Figure 7 The network device A2 in the example may be Figures 4 to 6 SPE1 in Figure 7 For example, the network device A3 in Figures 4 to 6 NPE1 in.
[0108] Optionally, network device A1 and network device A2 are BGP neighbors to each other, and network device A2 and network device A3 are BGP neighbors to each other. In the embodiment of the present application, two network devices are BGP neighbors to each other, which may be a BGP peer relationship established between the two network devices. Alternatively, the communication network also includes a route reflector (RR), and the two network devices are BGP neighbors to each other, or the two network devices respectively establish a BGP peer relationship with the route reflector, that is, the two network devices are indirectly connected through the route reflector. Among them, the route reflector is used to forward messages transmitted between different network devices, and the route reflector does not modify the received message during the forwarding process.
[0109] The following is an example of the method flow of the embodiment of the present application.
[0110] For example, Figure 8 FIG. 1 is a flow chart of a method for publishing a route provided in an embodiment of the present application. Figure 8 As shown, the method 800 includes but is not limited to steps 801 to 802. The first communication device, the second communication device and the third communication device in the method 800 may be network devices in a communication network, such as routers, switches or PTN devices. For example, the method 800 may be applied to Figure 7 For example, the first communication device in method 800 is Figure 7 The network device A2 shown, the second communication device in method 800 is Figure 7 The network device A1 shown, the third communication device in method 800 is Figure 7 The network device A3 shown. Alternatively, the first communication device, the second communication device, and the third communication device in the method 800 may also be communication entities in the network device for performing part or all of the operations of the method described in the present application, such as a chip, an interface board, or a line card. The embodiments of the present application do not limit the physical form of the communication device.
[0111] Step 801: A first communication device receives a first route announced by a second communication device, where the first route includes an SRv6VPN SID and a first next hop address, and the first next hop address is an IPv6 address of the second communication device.
[0112] The first route is a BGP route. Optionally, the first route is a BGP L3VPNv4 route, a BGP L3VPNv6 route, a BGP EVPN L3VPNv4 route, a BGP EVPN L3VPNv6 route or a BGP EVPN L2VPN route. Among them, the BGP L3VPNv4 route, the BGP L3VPNv6 route, the BGP EVPN L3VPNv4 route and the BGP EVPN L3VPNv6 route are used to publish IP routes. The BGP EVPN L2VPN route is used to publish MAC routes.
[0113] Optionally, the first route may be a BGP update message. For example, Fig. 9 Schematic diagram of the structure of a BGP update message provided by an embodiment of the present application. Fig. 9As shown, the BGP update message includes an Ethernet header, an IP header, a Transmission Control Protocol (TCP) header, a BGP data packet, and a frame check sequence (FCS). Among them, the BGP data packet includes a BGP header and a BGP message field. The BGP header includes a maker field, a length field, and a type field (not shown in the figure). The BGP message field includes an address family identifier (AFI), a subsequent address family identifier, a length of next hop network address, a next hop network address, a reserved field, network layer reachability information (NLRI), and other path attributes. Among them, the address family identifier, the subsequent address family identifier, the length of the next hop network address, the next hop network address, the reserved field, and the NLRI are collectively referred to as a multi-protocol reachable NLRI (MP_REACH_NLRI) attribute. In the case where the BGP update message is the above-mentioned first route, the content of the next-hop network address in the BGP message field is the IPv6 address of the second communication device, and other path attributes include SRv6VPN SID, and the NLRI carries the IP route or MAC route that needs to be published. In addition, different types of BGP routes are indicated by different values of the address family identifier in the BGP message field. For example, for the above-mentioned BGP L3VPNv4 route, BGPL3VPNv6 route, BGP EVPN L3VPNv4 route, BGP EVPN L3VPNv6 route and BGP EVPN L2VPN route, the address family identifier in the BGP message field has different values. For the explanation of other fields in the BGP message field, please refer to the definition in the request for comments (RFC) numbered 4760 (abbreviated as: RFC 4760), and the embodiments of the present application will not be repeated here.
[0114] Step 802: The first communication device sends a second route to the third communication device, where the second route includes the SRv6 VPNSID and a second next hop address, and the second next hop address is the IPv6 address of the first communication device.
[0115] After receiving the first route, the first communication device generates a second route according to the first route, specifically by modifying the next hop address in the first route from the IPv6 address of the second communication device to the IPv6 address of the first communication device to obtain the second route.
[0116] Optionally, the first communication device may also generate and save a forwarding table entry according to the first route, and the forwarding table entry indicates that the next hop corresponding to the SRv6 VPN SID is the second communication device. The forwarding table entry may include a correspondence between the SRv6 VPN SID and the IPv6 address of the second communication device. Or the forwarding table entry may include a correspondence between the SRv6 VPN SID and an identifier of an outbound interface from the first communication device to the second communication device. Alternatively, the forwarding table entry may include a correspondence between the SRv6 VPN SID, the IPv6 address of the second communication device, and an identifier of an outbound interface from the first communication device to the second communication device.
[0117] Optionally, the first route also includes a tunnel identifier corresponding to the SRv6 VPN SID, and the tunnel identifier is used to indicate an SRv6 tunnel from the first communication device to the second communication device. Accordingly, the identifier of the outbound interface from the first communication device to the second communication device in the forwarding table may be the tunnel identifier. Taking the example of multiple SRv6 Policy tunnels established between the first communication device and the second communication device, the tunnel identifier may be a color value, which is used to indicate an SRv6Policy tunnel configured with the color value. The tunnel identifier may be carried in Fig. 9 In other path attributes in the BGP message field shown. Alternatively, the first route may not include a tunnel identifier corresponding to the SRv6 VPN SID, and an SRv6 tunnel corresponding to the SRv6 VPN SID may be configured on the first communication device, which is not limited in this embodiment of the present application.
[0118] For example, the above method 800 is applied to Figure 7 Taking the communication network shown in the figure as an example, the route publishing process is described. Fig.10 Schematic diagram of a routing announcement provided by an embodiment of the present application. Fig.10As shown, after network device A1 learns the IP / MAC route of CE1, it allocates a network-wide unique SRv6 VPN SID to the IP / MAC route, and then sends a BGP route containing the IP / MAC route and the SRv6 VPN SID to network device A2. The next hop address in the BGP route is the IPv6 address of network device A1. After network device A2 receives the BGP route from network device A1, it generates a forwarding table entry, which indicates that the next hop corresponding to the SRv6 VPN SID is network device A1, and modifies the next hop address in the BGP route to the IPv6 address of network device A2, and then continues to send the BGP route containing the IP / MAC route and the SRv6VPN SID to network device A3. After network device A3 receives the BGP route from network device A2, it generates a forwarding table entry, which indicates that the next hop corresponding to the SRv6 VPN SID is network device A2, and establishes a mapping relationship between the IP / MAC route and the SRv6 VPN SID. Furthermore, the network device A3 sends the IP / MAC route to CE2.
[0119] In the embodiment of the present application, the first communication device modifies the next hop address in the received route during the route publishing process, while keeping the original SRv6 VPN SID in the route unchanged. Since the first communication device does not need to reapply for the SRv6 VPN SID, the resources of the first communication device can be saved, and the performance requirements for the first communication device are relatively low. In addition, since the first communication device does not need to modify the SRv6 VPN SID carried in the route, the complexity of the first communication device in processing the route is reduced, so the efficiency of route publishing can be improved.
[0120] Optionally, after the route is published in the communication network, message transmission may be further performed in the communication network. Fig.11 Schematic diagram of a message transmission method provided in an embodiment of the present application. Fig.11 As shown, method 1100 includes but is not limited to steps 1101 to 1103. Steps 1101 to 1103 may be performed after step 802 above.
[0121] Step 1101: A first communication device receives a first message, where the first message includes an SRv6 VPN SID.
[0122] Optionally, an SRv6 tunnel is established between the first communication device and the third communication device, and the SRv6 tunnel may be a tunnel based on SRv6 Policy or a tunnel based on segment routing best effort (SR-BE). The first communication device receives the first message sent by the third communication device through the SRv6 tunnel between the first communication device and the third communication device.
[0123] Step 1102: The first communication device generates a second message according to the first message, where the second message includes the SRv6 VPNSID.
[0124] Optionally, the first message includes a first segment routing header (SRH), an SRv6 VPNSID, and a message payload. Among them, the SRH is used for public network tunnel forwarding, and its function is similar to the public network label in MPLS technology. The SRv6VPN SID is used for private network forwarding, and its function is similar to the private network label in MPLS technology. The first communication device generates a second message according to the first message, which may be to re-encapsulate the first SRH in the first message into a second SRH to obtain the second message. The first SRH is used to guide the first message to traverse the network from the third communication device to the first communication device, that is, the first SRH is used to indicate the network devices that the first message passes through in sequence when it is transmitted through the SRv6 tunnel between the third communication device and the first communication device. The second SRH is used to guide the second message to traverse the network from the first communication device to the second communication device, that is, the second SRH is used to indicate the network devices that the second message passes through in sequence when it is transmitted through the SRv6 tunnel between the first communication device and the second communication device.
[0125] Step 1103: The first communication device sends a second message to the second communication device.
[0126] Optionally, an SRv6 tunnel is established between the first communication device and the second communication device, and the SRv6 tunnel may be an SRv6 Policy-based tunnel or an SR-BE-based tunnel. The first communication device sends the second message to the second communication device through the SRv6 tunnel between the first communication device and the second communication device.
[0127] Optionally, the first communication device determines, based on a locally stored forwarding entry, that the next hop corresponding to the SRv6 VPN SID is a second communication device, and then sends a second message to the second communication device.
[0128] For example, the above method 1100 is applied to Figure 7 Taking the communication network shown in the figure as an example, the message forwarding process is explained. Fig.12 This is a schematic diagram of message forwarding provided by an embodiment of the present application. Fig.12 As shown, CE2 sends an original message to CE1, and the original message is a layer 2 message or a layer 3 message. After receiving the original message, network device A3 obtains the SRv6 VPN SID corresponding to the destination address of the original message based on the local mapping relationship, and then generates an SRv6 message. The SRv6 message includes SRH1, SRv6 VPN SID and message payload. The original message sent by CE2 is encapsulated in the message payload. SRH1 is used to guide the message to be forwarded between network device A3 and network device A2. Network device A3 generates an SRv6 message to the next hop (network device A2) based on the local forwarding table. After receiving the SRv6 message from network device A3, network device A2 generates a new SRv6 message. The new SRv6 message includes SRH2, SRv6 VPN SID and message payload. SRH2 is used to guide the message to be forwarded between network device A2 and network device A1. Network device A2 sends the generated SRv6 message to the next hop (network device A1) based on the local forwarding entry. After receiving the SRv6 message from network device A2, network device A1 obtains the message payload of the SRv6 message and sends the original message from CE2 to CE1.
[0129] In the embodiment of the present application, the same SRv6 VPN SID is used for multi-hop forwarding, and the first communication device does not need to modify the SRv6 VPN SID carried in the message during the message forwarding process, which can improve the message forwarding efficiency.
[0130] In one implementation scenario, the above method 800 and method 1100 may be applied to a communication network that adopts cross-domain VPN-Option B networking. The communication network includes a first AS domain and a second AS domain.
[0131] In one possible scenario, the first communication device in the above methods 800 and 1100 is an ASBR of the first AS domain, and the third communication device is an ASBR of the second AS domain. Optionally, the second communication device is a PE device of the first AS domain, and the SRv6 VPN SID is allocated by the second communication device.
[0132] In another possible case, the second communication device in the above method 800 and method 1100 is an ASBR of the first AS domain, and the first communication device is an ASBR of the second AS domain. Optionally, the SRv6 VPN SID is allocated by a PE device of the first AS domain.
[0133] The above method 800 and method 1100 are applied to Figure 1 As an example of the communication network shown in FIG. 1 , the first AS domain may be Figure 1 In the AS100 shown, the second AS domain can be Figure 1The first communication device in the above method 800 and method 1100 may be Figure 1 The ASBR1 shown, the third communication device may be Figure 1 The ASBR3 shown, the second communication device may be Figure 1 The SRv6 VPN SID of PE1 shown in the figure may be assigned to the IP / MAC route after PE1 learns the IP / MAC route of CE1. Alternatively, the first communication device in the above method 800 and method 1100 may be Figure 1 The ASBR3 shown, the second communication device may be Figure 1 The ASBR1 shown, the third communication device may be Figure 1 In the illustrated PE3, the SRv6 VPN SID may be allocated to the IP / MAC route after PE1 learns the IP / MAC route of CE1.
[0134] Below Figure 1 The communication network shown is forwarded based on SRv6 technology as an example. Fig.13 and Fig.14 The route publishing process and the message forwarding process in the communication network are described respectively. An SRv6 tunnel (public network tunnel) is established between PE1 and ASBR1, and an SRv6 tunnel (public network tunnel) is established between PE3 and ASBR3.
[0135] For example, Fig.13 FIG. 1 is a schematic diagram of a route publication based on SRv6 technology in a cross-domain VPN-Option B network provided by an embodiment of the present application. Fig.13As shown in the figure, after PE1 learns the IP / MAC route of CE1, it allocates an SRv6VPN SID to the IP / MAC route, and then sends a BGP route containing the IP / MAC route and the SRv6 VPN SID to ASBR1. The next hop address in the BGP route is the IPv6 address of PE1. After ASBR1 receives the BGP route from PE1, it generates a forwarding entry indicating that the next hop corresponding to the SRv6 VPN SID is PE1, and modifies the next hop address in the BGP route to the IPv6 address of ASBR1, and then continues to send the BGP route containing the IP / MAC route and the SRv6 VPN SID to ASBR3. After ASBR3 receives the BGP route from ASBR1, it generates a forwarding entry indicating that the next hop corresponding to the SRv6 VPNSID is ASBR1, and modifies the next hop address in the BGP route to the IPv6 address of ASBR3, and then continues to send the BGP route containing the IP / MAC route and the SRv6 VPN SID to PE3. After PE3 receives the BGP route from ASBR3, it generates a forwarding entry indicating that the next hop corresponding to the SRv6 VPN SID is ASBR3, and establishes a mapping relationship between the IP / MAC route and the SRv6 VPN SID. Further, PE3 sends the IP / MAC route to CE2. For the sake of illustration, Fig.13 The P device is not shown.
[0136] Accordingly, Fig.14It is a schematic diagram of message forwarding based on SRv6 technology under a cross-domain VPN-Option B networking provided by an embodiment of the present application. As shown in 14, CE2 sends an original message to CE1, and the original message is a layer 2 message (corresponding to CE1 publishing a MAC route) or a layer 3 message (corresponding to CE1 publishing an IP route). If the original message is a layer 2 message, the destination address carried by the original message is the MAC address of CE1; if the original message is a layer 3 message, the destination address carried by the original message is the IP address of CE1. After PE3 receives the original message, it obtains the SRv6 VPN SID corresponding to the destination address of the original message based on the local mapping relationship, and then generates an SRv6 message, which includes SRH1, SRv6 VPN SID and message payload. The original message sent by CE2 is encapsulated in the message payload, and SRH1 is used to guide the message to be forwarded between PE3 and ASBR3. PE3 sends the generated SRv6 message to the next hop (ASBR3) based on the local forwarding table entry. After receiving the SRv6 message from PE3, ASBR3 sends an SRv6 message to the next hop based on the local forwarding table. The SRv6 message includes the SRv6VPN SID and the message payload. After receiving the SRv6 message from ASBR3, ASBR1 generates a new SRv6 message. The new SRv6 message includes SRH2, SRv6 VPN SID and the message payload. SRH2 is used to guide the message forwarding between ASBR1 and PE1. ASBR1 sends the generated SRv6 message to the next hop (PE1) based on the local forwarding table. After receiving the SRv6 message from ASBR1, PE1 obtains the message payload of the SRv6 message and sends the original message from CE2 to CE1. Fig.14 The message structure shown is only used for exemplary description. The actual SRv6 message also includes an encapsulated IPv6 extension header before the SRH.
[0137] In another implementation scenario, the above method 800 and method 1100 may be applied to a communication network using HVPN networking.
[0138] In one possible case, the first communication device in the above method 800 and the method 1100 is an SPE device, the second communication device is a UPE device, and the third communication device is an NPE device. That is, the above method 800 is an uplink route publishing process, and the above method 1100 is a downlink message forwarding process. Optionally, the SRv6 VPN SID is allocated by the second communication device (UPE device).
[0139] In another possible case, the first communication device in the above method 800 and the method 1100 is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device. That is, the above method 800 is a downlink route publishing process, and the above method 1100 is an uplink message forwarding process. Optionally, the SRv6 VPN SID is allocated by the second communication device (NPE device).
[0140] The above method 800 and method 1100 are applied to Figure 4 Taking the communication network shown in FIG. 1 as an example, the first communication device in the above method 800 and method 1100 may be Figure 4 The second communication device may be SPE1 shown. Figure 4 The third communication device may be UPE1 shown. Figure 4 The SRv6 VPN SID of NPE1 shown in the figure may be allocated to the IP / MAC route after UPE1 learns the IP / MAC route of CE1. Alternatively, the first communication device in the above method 800 and method 1100 may be Figure 4 The second communication device may be SPE1 shown. Figure 4 The third communication device may be NPE1 shown. Figure 4 The UPE1 and SRv6 VPNSID shown may be allocated to the IP / MAC route after NPE1 learns the IP / MAC route of CE3.
[0141] Below Figure 4 The communication network shown is forwarded based on SRv6 technology as an example. Fig.15 and Fig.16 The publishing process of the uplink route and the forwarding process of the downlink message in the communication network are described respectively. An SRv6 tunnel (public network tunnel) is established between UPE1 and SPE1, and an SRv6 tunnel is established between SPE1 and NPE1.
[0142] For example, Fig.15 FIG. 1 is a schematic diagram of routing release based on SRv6 technology in HVPN networking provided by an embodiment of the present application. Fig.15As shown in the figure, after UPE1 learns the IP / MAC route of CE1, it allocates an SRv6 VPN SID to the IP / MAC route, and then sends a BGP route containing the IP / MAC route and the SRv6 VPN SID to SPE1. The next hop address in the BGP route is the IPv6 address of UPE1. After SPE1 receives the BGP route from UPE1, it generates a forwarding entry, which indicates that the next hop corresponding to the SRv6 VPN SID is UPE1, and modifies the next hop address in the BGP route to the IPv6 address of SPE1, and then continues to send the BGP route containing the IP / MAC route and the SRv6 VPN SID to NPE1. After NPE1 receives the BGP route from SPE1, it generates a forwarding entry, which indicates that the next hop corresponding to the SRv6 VPN SID is SPE1, and establishes a mapping relationship between the IP / MAC route and the SRv6 VPN SID. Further, NPE1 sends the IP / MAC route to CE3.
[0143] Accordingly, Fig.16 FIG. 1 is a schematic diagram of message forwarding based on SRv6 technology in an HVPN network provided by an embodiment of the present application. Fig.16 As shown, CE3 sends an original message to CE1. The original message is a Layer 2 message or a Layer 3 message. After receiving the original message, NPE1 obtains the SRv6 VPN SID corresponding to the destination address of the original message based on the local mapping relationship, and then generates an SRv6 message. The SRv6 message includes SRH1, SRv6 VPN SID and message payload. The original message sent by CE3 is encapsulated in the message payload. SRH1 is used to guide the message to be forwarded between NPE1 and SPE1. NPE1 sends the generated SRv6 message to the next hop (SPE1) based on the local forwarding table. After receiving the SRv6 message from NPE1, SPE1 generates a new SRv6 message. The new SRv6 message includes SRH2, SRv6 VPN SID and message payload. SRH2 is used to guide the message to be forwarded between SPE1 and UPE1. SPE1 sends the generated SRv6 message to the next hop (UPE1) based on the local forwarding table. After receiving the SRv6 message from SPE1, UPE1 obtains the message payload of the SRv6 message and sends the original message from CE3 to CE1.
[0144] The sequence of the steps of the above-mentioned routing publishing method and message transmission method provided in the embodiment of the present application can be appropriately adjusted, and the steps can be increased or decreased accordingly according to the situation. Any technician familiar with the technical field can easily think of a method of change within the technical scope disclosed in this application, and it should be covered within the scope of protection of this application.
[0145] The following is an example of a virtual device according to an embodiment of the present application.
[0146] Fig.17 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. The communication device is, for example, a first communication device. Fig.17 As shown, the communication device 1700 includes a receiving module 1701 , a processing module 1702 and a sending module 1703 .
[0147] In a specific implementation, the communication device 1700 is used to publish a route. Specifically, the receiving module 1701 is used to receive a first route announced by a second communication device. The first route includes an SRv6 VPN SID and a first next hop address. The first next hop address is an IPv6 address of the second communication device. The sending module 1703 is used to send a second route to a third communication device. The second route includes the SRv6 VPN SID and the second next hop address. The second next hop address is the IPv6 address of the first communication device.
[0148] In a specific implementation, the communication device 1700 is used to forward a message. Specifically, the receiving module 1701 is used to receive a first message, the first message including the SRv6 VPN SID. The processing module 1702 is used to generate a second message according to the first message, the second message including the SRv6VPN SID. The sending module 1703 is used to send the second message to the second communication device.
[0149] In a first specific implementation, the first communication device is an ASBR of a first AS domain, and the third communication device is an ASBR of a second AS domain.
[0150] In combination with the above-mentioned first specific implementation, the second communication device is a PE device of the first AS domain, and the SRv6 VPNSID is allocated by the second communication device.
[0151] In a second specific implementation, the second communication device is an ASBR of the first AS domain, and the first communication device is an ASBR of the second AS domain.
[0152] In combination with the second specific implementation described above, the SRv6 VPN SID is allocated by a PE device in the first AS domain.
[0153] In a third specific implementation, the first communication device is an SPE device, the second communication device is a UPE device, and the third communication device is an NPE device.
[0154] In a fourth specific implementation, the first communication device is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device.
[0155] In combination with the third or fourth specific implementation, the SRv6 VPN SID is allocated by the second communication device.
[0156] In a specific implementation, the first route is a BGP L3VPNv4 route, a BGP L3VPNv6 route, a BGP EVPN L3VPNv4 route, a BGP EVPN L3VPNv6 route or a BGP EVPN L2VPN route.
[0157] The following is an illustration of the hardware structure involved in the embodiments of the present application.
[0158] Fig.18 1 is a block diagram of a communication device 1800 provided in an embodiment of the present application. For example, the communication device 1800 may be an ASBR in a cross-domain VPN-Option B network, or the communication device 1800 may be an SPE in a HVPN network. Fig.18 As shown, the communication device 1800 includes: a processor 1801 and a memory 1802 .
[0159] Memory 1802, for storing computer readable instructions;
[0160] Processor 1801 is used to call the computer-readable instructions and execute the above method 800 and / or the above method 1100 according to the instructions of the computer-readable instructions.
[0161] In a specific implementation manner, the communication device 1800 may further include a communication interface 1803. The memory 1802, the processor 1801 and the communication interface 1803 are communicatively connected with each other.
[0162] Fig.19 1 is a block diagram of another communication device 1900 provided in an embodiment of the present application. For example, the communication device 1900 may be an ASBR in a cross-domain VPN-Option B network, or the communication device 1900 may be an SPE in a HVPN network. Fig.19 As shown, the communication device 1900 includes: a communication interface 1901; and a processor 1902 connected to the communication interface 1901. According to the communication interface 1901 and the processor 1902, the communication device 1900 can execute the above method 800 and / or the above method 1100. The communication interface 1901 is used to implement the sending and receiving operations, and the processor 1902 is used to implement operations other than sending and receiving. For example, when the communication device 1900 is Figure 8 In the case of the first communication device in the method shown, the communication interface 1901 is used to receive the route sent by the second communication device and send the route to the third communication device.
[0163] In the embodiment of the present application, the processor may be, for example, but not limited to, any one or more of the following combinations: a central processing unit (CPU), a network processor (NP), a tensor processing unit (TPU), a neural network processor (NPU), an application-specific integrated circuit (ASIC), a programmable logic device (PLD). The PLD may be a complex programmable logic device (CPLD), a field programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. The processor may refer to one processor or may include multiple processors. The processor may include one or more processing cores, and the processor executes various functional applications and data processing by running a computer program. The processor may be connected to a memory and a communication interface via a communication bus.
[0164] The memory may include a volatile memory, such as a random access memory (RAM). The memory may also include a non-volatile memory, such as a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD). The memory may also include a combination of the above-mentioned types of memories. The memory may refer to one memory or may include multiple memories. In a specific embodiment, a computer-readable instruction is stored in the memory, and the computer-readable instruction includes multiple software modules, such as the sending module, the processing module and the receiving module described above. After the processor executes each software module, it can perform corresponding operations according to the instructions of each software module. In this embodiment, the operation performed by a software module actually refers to the operation performed by the processor according to the instructions of the software module. After the processor executes the computer-readable instruction in the memory, it can perform all or part of the operations that the communication device can perform according to the instructions of the computer-readable instruction.
[0165] There may be multiple communication interfaces, and the communication interfaces are used to communicate with other devices. The communication interface may include a wired communication interface, a wireless communication interface, or a combination thereof. Among them, the wired communication interface may be, for example, an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof, etc.
[0166] In the above embodiments, it can be implemented in whole or in part by hardware, firmware or any combination thereof. When software is involved in the specific implementation process, it can be embodied in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disc (DVD)), or a semiconductor medium (eg, an SSD), etc.
[0167] The following is an example of the system of the embodiment of the present application.
[0168] An embodiment of the present application further provides a communication system, including: a plurality of communication devices, wherein the plurality of communication devices may include, for example, the first communication device in the above method 800 or the above method 1100.
[0169] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0170] In the embodiments of the present application, the terms “first”, “second” and “third” are used for descriptive purposes only and should not be understood as indicating or implying relative importance.
[0171] The term "and / or" in this application is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0172] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.
[0173] The above description is only an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the concept and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A route publishing method, characterized in that: The method comprises: The first communication device receives a first route announced by the second communication device, wherein the first route includes a segment identifier SRv6 VPN SID of a virtual private network based on segment routing of the sixth version of the Internet Protocol and a first next hop address, and the first next hop address is the sixth version of the Internet Protocol IPv6 address of the second communication device; The first communication device sends a second route to a third communication device, where the second route includes the SRv6 VPNSID and a second next hop address, where the second next hop address is the IPv6 address of the first communication device.
2. The method according to claim 1, characterized in that The first communication device is an autonomous system border router ASBR of a first autonomous system AS domain, and the third communication device is an ASBR of a second AS domain.
3. The method according to claim 2, characterized in that The second communication device is an operator edge PE device of the first AS domain, and the SRv6 VPN SID is allocated by the second communication device.
4. The method according to claim 1, characterized in that: The second communication device is an ASBR of a first AS domain, and the first communication device is an ASBR of a second AS domain.
5. The method according to claim 4, characterized in that The SRv6 VPN SID is allocated by a PE device in the first AS domain.
6. The method according to claim 1, characterized in that The first communication device is an operator edge SPE device on the operator side, the second communication device is an operator edge UPE device on the user side, and the third communication device is an operator edge NPE device on the network side.
7. The method according to claim 1, characterized in that The first communication device is an SPE device, the second communication device is an NPE device, and the third communication device is a UPE device.
8. The method according to claim 6 or 7, characterized in that: The SRv6 VPN SID is allocated by the second communication device.
9. The method according to any one of claims 1 to 8, characterized in that: The first route is a three-layer virtual private network BGP L3VPNv4 route based on the Border Gateway Protocol and the fourth version of the Internet Protocol, a three-layer virtual private network BGP L3VPNv6 route based on the Border Gateway Protocol and the sixth version of the Internet Protocol, a three-layer virtual private network BGP EVPN L3VPNv4 route based on the Border Gateway Protocol and the fourth version of the Internet Protocol under the Ethernet virtual private network, a three-layer virtual private network BGP EVPN L3VPNv6 route based on the Border Gateway Protocol and the sixth version of the Internet Protocol under the Ethernet virtual private network, or a two-layer virtual private network BGP EVPN L2VPN route based on the Border Gateway Protocol under the Ethernet virtual private network.
10. The method according to any one of claims 1 to 9, characterized in that: After the first communication device receives the first route advertised by the second communication device, the method further includes: The first communication device receives a first message, where the first message includes the SRv6 VPN SID; The first communication device generates a second message according to the first message, wherein the second message includes the SRv6 VPNSID; The first communication device sends the second message to the second communication device.
11. A message transmission method, characterized in that: The method comprises: The first communication device receives a first message, wherein the first message includes a segment identifier SRv6 VPN SID of a virtual private network based on segment routing of Internet Protocol version 6; The first communication device generates a second message according to the first message, wherein the second message includes the SRv6 VPNSID; The first communication device sends the second message to the second communication device.
12. The method according to claim 11, characterized in that The first communication device is an autonomous system border router ASBR of a first autonomous system AS domain, and the second communication device is a provider edge PE device of the first AS domain.
13. The method according to claim 12, characterized in that The SRv6 VPN SID is allocated by the second communication device.
14. The method according to claim 11, characterized in that The second communication device is an ASBR of a first AS domain, and the first communication device is an ASBR of a second AS domain.
15. The method according to claim 14, characterized in that The SRv6 VPN SID is allocated by a PE device in the first AS domain.
16. The method according to claim 11, characterized in that The first communication device is an operator edge SPE device at the operator side, and the second communication device is an operator edge UPE device at the user side.
17. The method according to claim 11, characterized in that The first communication device is an SPE device, and the second communication device is an NPE device.
18. The method according to claim 16 or 17, characterized in that The SRv6 VPN SID is allocated by the second communication device.
19. A communication system, characterized in that: include: A plurality of communication devices, wherein a communication device among the plurality of communication devices is used to execute the method according to any one of claims 1 to 18.
20. A communication device, characterized in that: include: Communication interface; as well as a processor connected to the communication interface; According to the communication interface and the processor, the method according to any one of claims 1 to 18 is implemented.
21. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 18 is implemented.
22. A computer program product, characterized in that The method comprises a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 18.