VXLAN tunnel creation method and device
By adding single-package authentication during the VXLAN tunnel creation process and using the path attribute field of the BGP Update message for VTEP node authentication, the security problem of EVPN data center is solved, the prevention of malicious traffic is achieved, and network security is improved.
Patent Information
- Application Number
- CN202510660272.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, EVPN has insufficient security considerations in data centers, and cannot effectively avoid access to malicious traffic, which poses security risks.
During the VXLAN tunnel creation process, a target routing attribute unit is added through the path attribute field of the BGP Update message, which contains single-package authentication information. The single-package authentication server is used to authenticate the source VTEP node. The VXLAN tunnel is created only when the authentication is passed.
Ensure that the VTEP nodes that create VXLAN tunnels are trustworthy, avoid malicious access, and improve the security of the data center network.
Smart Images

Figure CN120455109A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network communication technology, and in particular to a VXLAN tunnel creation method and device. Background Art
[0002] Ethernet Virtual Private Network (EVPN) is a next-generation, full-service VPN (Virtual Private Network) solution that overturns the traditional Layer 2 VPN mechanism of learning MAC (Media Access Control) addresses through the forwarding plane. EVPN introduces a control plane and uses MP-BGP (Multi-Protocol BGP), an extension of BGP (Border Gateway Protocol), to transmit MAC information.
[0003] EVPN has been widely used in modern data centers. Data center security considerations are becoming increasingly important in system management. How to enhance data center security and prevent devices from accessing malicious traffic is a key research direction in this field. Summary of the Invention
[0004] To overcome the problems existing in the related art, the present application provides a VXLAN tunnel creation method and device.
[0005] According to a first aspect of an embodiment of the present application, a VXLAN tunnel creation method is provided, the method being applied to a target VTEP node, the method comprising:
[0006] After receiving the BGP Update message, determine whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node, where the source VTEP node refers to the VTEP node that sent the BGP Update message;
[0007] If the judgment result is yes, extracting the first single-packet authentication information from the path attribute field of the BGP Update message, and sending the first single-packet authentication information to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information;
[0008] Obtain a first single-packet authentication result of the source VTEP node from the single-packet authentication server, and when the first single-packet authentication result is authentication passed, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
[0009] According to a second aspect of an embodiment of the present application, a VXLAN tunnel creation method is provided. The method is applied to a source VTEP node, and the method includes:
[0010] Generate a BGP Update message, wherein the path attribute field of the BGP Update message includes the first single packet authentication information of the source VTEP node;
[0011] Sending the BGP Update message to the target VTEP node, so that when the target VTEP node determines that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node, the target VTEP node extracts the first single-packet authentication information from the BGP Update message and sends the extracted first single-packet authentication information to a single-packet authentication server, thereby causing the single-packet authentication server to perform single-packet authentication on the source VTEP node according to the first single-packet authentication information and generate a first single-packet authentication result;
[0012] When the first single packet authentication result is authentication passed, work together with the target VTEP node to create a VXLAN tunnel between the source VTEP node and the target VTEP node.
[0013] According to a third aspect of an embodiment of the present application, a VXLAN tunnel creation device is provided, the device being applied to a target VTEP node, the device including:
[0014] A determination module, configured to determine whether a VXLAN tunnel needs to be created between a source VTEP node and a target VTEP node after receiving a BGP Update message, wherein the source VTEP node refers to the VTEP node that sends the BGP Update message;
[0015] an authentication module, configured to, if the judgment result is yes, extract first single-packet authentication information from the path attribute field of the BGP Update message, and send the first single-packet authentication information to a single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information;
[0016] A creation module is used to obtain a first single-packet authentication result of the source VTEP node from the single-packet authentication server, and when the first single-packet authentication result is authentication passed, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
[0017] According to a fourth aspect of an embodiment of the present application, a VXLAN tunnel creation device is provided, the device being applied to a source VTEP node, the device including:
[0018] A generating module, configured to generate a BGP Update message, wherein the path attribute field of the BGP Update message includes the first single packet authentication information of the source VTEP node;
[0019] a sending module, configured to send the BGP Update message to a target VTEP node, so that when the target VTEP node determines that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node, the target VTEP node extracts the first single-packet authentication information from the BGP Update message and sends the extracted first single-packet authentication information to a single-packet authentication server, thereby causing the single-packet authentication server to perform single-packet authentication on the source VTEP node according to the first single-packet authentication information and generate a first single-packet authentication result;
[0020] A collaboration module is used to collaborate with the target VTEP node to create a VXLAN tunnel between the source VTEP node and the target VTEP node when the first single packet authentication result is authentication passed.
[0021] According to a fifth aspect of the embodiments of the present application, there is provided an electronic device, including:
[0022] A memory, one or more processors; the memory is coupled to the processor; wherein computer program code is stored in the memory, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method as described above.
[0023] According to a sixth aspect of an embodiment of the present application, a computer-readable storage medium is provided, comprising computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the method described above.
[0024] According to a seventh aspect of the embodiments of the present application, a computer program product is provided. When the computer program product is run on a computer, the computer is caused to execute the method described above.
[0025] The technical solutions provided by the embodiments of the present application may have the following beneficial effects:
[0026] In an embodiment of the present application, BGP EVPN routes are transmitted through BGP Update messages. This embodiment of the present application utilizes the feature that the path attribute field of the BGP Update message can add a new path attribute unit, and adds a target route attribute unit containing single-packet authentication information in the route attribute field, thereby achieving the purpose of transmitting single-packet authentication information through the BGP Update message. Therefore, when the VTEP node in the data center receives a BGP Update message to create a VXLAN tunnel, it can first extract the single-packet authentication information contained in the BGPUpdate message and send it to the single-packet authentication server, thereby triggering the single-packet authentication process. If and only if the authentication is successful, the VXLAN tunnel is created between the two VTEP nodes. In this way, it is ensured that the VTEP node that needs to create a VXLAN tunnel is trustworthy, malicious access is avoided, and the security of the data center network is improved.
[0027] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0029] Figure 1 A schematic diagram of a first flow chart of a VXLAN tunnel creation method applied to a target VTEP node provided in an embodiment of the present application;
[0030] Figure 2 A schematic diagram of a target route attribute unit in the path attribute field of a BGP Update message provided in an embodiment of the present application;
[0031] Figure 3 A schematic diagram of the process of establishing a VXLAN tunnel provided in an embodiment of the present application;
[0032] Figure 4 A second flow chart of a VXLAN tunnel creation method applied to a target VTEP node provided in an embodiment of the present application;
[0033] Figure 5 A schematic diagram of a flow chart of a VXLAN tunnel creation method applied to a source VTEP node provided in an embodiment of the present application;
[0034] Figure 6 A schematic diagram of a VXLAN tunnel creation device applied to a target VTEP node provided in an embodiment of the present application;
[0035] Figure 7A schematic diagram of a VXLAN tunnel creation device applied to a source VTEP node provided in an embodiment of the present application;
[0036] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0037] The technical solutions in the embodiments of the present application are described below in conjunction with the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing specific embodiments and are not intended to limit the present application.
[0038] It should be noted that in this application, "at least one" means one or more, and "more than one" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The terms "first", "second", "third", etc. (if any) in the specification, claims and drawings of this application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0039] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0040] First, the relevant technical background is introduced.
[0041] EVPN is a Layer 2 VPN technology that meets Layer 2 network requirements within and between data centers, providing virtualization and isolation. BGP supports EVPN through MP-BGP extensions, leveraging its proven route distribution mechanism to deliver EVPN routing information. BGP Update messages are core BGP messages used in EVPN scenarios to transmit MAC addresses, VTEP information, and other information, enabling control plane communication and data plane optimization.
[0042] EVPN has been widely used in modern data centers. Data center security considerations are becoming increasingly important among system administrators. To ensure that VTEP nodes in the environment are controllable and secure, this application provides a VXLAN tunnel creation method that adds a single-packet authentication process for VTEP nodes during the VXLAN tunnel creation process, thereby enhancing the security of the data center and preventing devices with malicious traffic from accessing.
[0043] Next, the embodiments of the present application are described in detail.
[0044] The present invention provides a VXLAN tunnel creation method, which is applied to a target VTEP node, such as Figure 1 As shown, the method may include the following steps:
[0045] Step 110: After receiving the BGP Update message, determine whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node, where the source VTEP node refers to the VTEP node that sent the BGP Update message; if the judgment result is yes, proceed to step 120; otherwise, terminate the process;
[0046] Step 120: Extract the first single-packet authentication information from the path attribute field of the BGP Update message, and send the first single-packet authentication information to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information.
[0047] Step 130: Obtain a first single-packet authentication result of the source VTEP node from the single-packet authentication server. When the first single-packet authentication result is authentication passed, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
[0048] In a data center, after a VXLAN Tunnel Endpoint (VTEP) node receives a BGP Update message from another VTEP node, it determines whether a VXLAN tunnel needs to be established between the two nodes based on the EVPN route type (such as Type 2, Type 3, Type 5, etc.) and related attributes (such as the VTEP node's IP address / IP prefix, the VXLAN network identifier (VNI) supported by the VTEP node) recorded in the message, as well as local traffic requirements.
[0049] Therefore, step 110 specifically determines whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node by:
[0050] Determine the EVPN route type based on the received BGP Update message.
[0051] Scenario 1: If the BGP Update message contains a Type 3 route, extract the VNI supported by the source VTEP node from the BGP Update message, and determine whether the target VTEP node needs to forward BUM (Broadcast, Unknown Unicast, Multicast) traffic belonging to the VNI supported by the source VTEP node. If the determination result is yes, determine that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node; and / or,
[0052] Scenario 2: If the BGP Update message contains a Type 2 route, extract the MAC address of the source VTEP node from the BGP Update message, and determine whether the destination VTEP node has received a data packet whose MAC address matches the MAC address of the source VTEP node. If so, determine that a VXLAN tunnel needs to be established between the source VTEP node and the destination VTEP node; and / or,
[0053] In scenario 3, if the BGP Update message contains a Type 5 route, the source VTEP node's IP prefix is extracted from the BGP Update message. The target VTEP node determines whether it has received a packet whose destination IP address matches the source VTEP node's IP prefix. If so, a VXLAN tunnel needs to be established between the source and target VTEP nodes.
[0054] It is worth mentioning that the source VTEP node mentioned in the embodiment of the present application refers to the VTEP node that sends the BGP Update message. In actual applications, the source VTEP node can be a newly added VTEP node in the data center, or it can be a VTEP node in the data center that needs to recreate the VXLAN tunnel (such as fault recovery and going back online).
[0055] In this embodiment, a single-packet authentication process is added to the VXLAN tunnel creation process of the VTEP node in the data center. Only if the authentication passes is the VTEP node allowed to create the VXLAN tunnel. If the authentication fails, the VXLAN tunnel cannot be created. This ensures that the VTEP node creating the VXLAN tunnel is trustworthy, prevents malicious access, and improves the security of the data center network.
[0056] BGP Update message is the core mechanism for dynamically updating routing information in BGP protocol. BGP Update message includes path attribute field, which is a variable length field containing the list of routing attribute units to be updated. Figure 2As shown in FIG, each routing attribute unit is encoded in TLV format and includes three parts: attribute type, attribute length, and attribute value.
[0057] This embodiment of the present application adds a new route attribute unit, called the target route attribute unit, to the path attribute field of the BGP Update message. This target route attribute unit contains single-packet authentication information, enabling the BGP Update message to support single-packet authentication through the newly added path attribute field of the target route attribute unit. The following describes the configuration of each component of the target route attribute unit:
[0058] The target route attribute unit consists of three parts: attribute type, attribute length, and attribute value. The attribute type further includes a 1-byte attribute tag Attr.Flags and a 1-byte attribute type value Attr.Type Code.
[0059] like Figure 2 As shown, in the embodiment of the present application, the attribute tag Attr.Flags of the target route attribute unit is configured as 11010000, and the meaning of each bit is as follows:
[0060] Number of bits meaning 0 1, indicating that the attribute is optional 1 1, indicating that the attribute must be passed 2 0, indicating that the attribute is complete 3 1, indicating that the following attribute length occupies 2 bytes 4-7 0000, indicating that the lower 4 bits are not used
[0061] like Figure 2 As shown, in this embodiment of the present application, the attribute type value Attr.Type Code of the target route attribute unit is configured as a preset threshold (such as 191). The preset threshold represents the addition of a single packet authentication process during the VXLAN tunnel creation process. The meaning of the attribute type value is as follows:
[0062]
[0063] The attribute value of the routing attribute unit is filled with different contents according to the type of different attributes. In the embodiment of the present application, the attribute value of the target routing attribute unit is used to fill in the single packet authentication information, that is, Figure 2 The SPA field is shown.
[0064] As can be seen from the above, BGP EVPN routes are transmitted through BGP Update messages. The embodiment of the present application utilizes the feature that the path attribute field of the BGPUpdate message can add a new path attribute unit, and adds a target route attribute unit containing single-packet authentication information in the route attribute field, thereby achieving the purpose of transmitting single-packet authentication information through the BGP Update message.
[0065] Therefore, when the VTEP node in the data center receives a BGP Update message to create a VXLAN tunnel, it first extracts the single-packet authentication information in the BGP Update message and performs single-packet authentication. Only when the authentication passes is the VXLAN tunnel created between the two VTEP nodes. In this way, the VTEP node that needs to create the VXLAN tunnel is ensured to be trustworthy, avoiding malicious access and thus improving the security of the data center network.
[0066] In order to perform single packet authentication (SPA) on the VTEP node, it is necessary to obtain single packet authentication information from the VTEP node. This information is used to verify the identity of the VTEP node and ensure the source and integrity of the data packet. The single packet authentication information includes hardware information. In the embodiment of the present application, this hardware information is encapsulated in the SPA field in the form of AID information, such as Figure 2 shown.
[0067] When performing single-packet authentication on a VTEP node in the host overlay, the single-packet authentication information that needs to be obtained includes any one or more of the following hardware information:
[0068] 1. Processor (CPU): Indicates the model, speed, number of cores, and architecture of the central processing unit used by the server;
[0069] 2. Memory (RAM): Indicates the amount of random access memory on the server, including type (e.g., DDR4) and speed (e.g., 2400MHz);
[0070] 3. Storage: Indicates the storage devices used by the server, including the capacity, type, and interface of hard disk drives (HDDs) and solid-state drives (SSDs);
[0071] 4. Motherboard: Indicates the motherboard model and manufacturer used by the server. Each server has a unique system serial number that uniquely identifies the server.
[0072] 5. Network Adapter: Indicates the model and speed of the server's network interface card (NIC), such as an Ethernet card or fiber optic network card, and the MAC address of the network card;
[0073] 6. Power Supply: Indicates the capacity and efficiency level of the server's power supply;
[0074] 7. Expansion Slots: Indicates the available expansion slots on the server motherboard, such as PCIe slots or memory slots;
[0075] 8. Operating System: Indicates the operating system and version currently installed on the server, such as Windows Server, Linux, etc.
[0076] 9. Chassis: Indicates the external chassis type of the server, such as tower chassis, rack chassis, or blade chassis.
[0077] When performing single-packet authentication on a VTEP node in a network overlay, the single-packet authentication information that needs to be obtained includes any one or more of the following hardware information:
[0078] 1. Model and Manufacturer: Information indicating the switch model and manufacturer;
[0079] 2. MAC address: A unique identifier assigned to a device by the manufacturer at the factory;
[0080] 3. Port quantity and type: Indicates the number and type of ports available on the switch, such as Ethernet port, fiber port, etc.
[0081] 4. Speed and protocol: Indicates the maximum speed and protocol supported by the switch, such as Gigabit Ethernet, 10 Gigabit Ethernet, etc.
[0082] 5. Processing capacity: Indicates the processing capacity of the switch, including forwarding rate, flow control and packet processing capacity;
[0083] 6. Power supply: Indicates the power supply mode of the switch, such as AC power (AC Power) or DC power (DC Power);
[0084] 7. Cooling and Fan: Indicates the heat dissipation and fan system of the switch, which is used to keep the temperature of the device stable.
[0085] Therefore, the embodiment of the present application specifically extracts the first single packet authentication information from the path attribute field of the BGP Update message in the following manner:
[0086] Determine the target route attribute unit whose attribute type value in the path attribute field of the BGP Update message is a preset threshold value, i.e., 191, and extract the attribute value from the target route attribute unit as the first single packet authentication information. Specifically, extract the SPA field from the attribute value attribute value of the target route attribute unit as the first single packet authentication information, such as Figure 2 As shown, by further extracting the AID information from the SPA field, the hardware information described above can be obtained.
[0087] That is to say, the single-packet authentication information in the embodiment of the present application may include the hardware information of the VTEP node.
[0088] In summary, in a specific example, the VXLAN tunnel creation method applied to the target VTEP node provided in the embodiment of the present application can be as follows: Figure 3 As shown:
[0089] 1. VETP node 1 (equivalent to the source VETP node) sends a BGP Update message containing a destination path attribute field that carries single-packet authentication information.
[0090] 2. When VTEP node 2 (equivalent to the target VTEP node) receives the BGP Update message, it determines whether a new VXLAN tunnel needs to be added.
[0091] 3. If a new VXLAN tunnel needs to be added, VTEP node 2 extracts the single-packet authentication information from the path attribute field of the received BGP Update message. Specifically, it extracts the single-packet authentication information from the target route attribute unit with the attribute type value of 191 in the path attribute field and sends it to the single-packet authentication server.
[0092] 4. The single-packet authentication server performs single-packet authentication based on the single-packet authentication information to check whether the data carried meets the requirements. If the authentication succeeds, a success response message is sent to VTEP node 2, and a VXLAN tunnel is established between the two VTEP nodes. If the authentication fails, an authentication failure response message is sent to VTEP node 2, and the VXLAN tunnel is not established between the VTEP nodes.
[0093] Furthermore, when the first single-packet authentication result is authentication failure, the target VTEP node may generate a prompt message indicating that the VXLAN tunnel cannot be created because the source VTEP node fails the single-packet authentication.
[0094] As a preferred implementation, based on the above embodiments, the present application not only adds a single-packet authentication process for the source VTEP node during the VXLAN tunnel creation process, but also adds a single-packet authentication process for the target VTEP node.
[0095] For the purpose of distinguishing descriptions, in the embodiment of the present application, the single-packet authentication information of the source VTEP node is referred to as the first single-packet authentication information, and the single-packet authentication information of the target VTEP node is referred to as the second single-packet authentication information.
[0096] At this time, the VXLAN tunnel creation method applied to the target VTEP node provided in the embodiment of the present application can be as follows: Figure 4 As shown:
[0097] Step 410: After receiving the BGP Update message, determine whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node, where the source VTEP node refers to the VTEP node that sent the BGP Update message; if the determination result is yes, continue with the subsequent process; otherwise, terminate the process;
[0098] Step 420: Extract the first single-packet authentication information from the path attribute field of the BGP Update message, and send the first single-packet authentication information to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information.
[0099] Step 430: Obtain the first single-packet authentication result of the source VTEP node from the single-packet authentication server;
[0100] Step 440: Send the second single-packet authentication information of the target VTEP node to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the target VTEP node according to the second single-packet authentication information.
[0101] Step 450: Obtain a second single-packet authentication result of the target VTEP node from the single-packet authentication server;
[0102] Step 460: When both the first single-packet authentication result and the second single-packet authentication result are authentication passed, a VXLAN tunnel is created between the source VTEP node and the target VTEP node.
[0103] Through the above method, during the process of creating a VXLAN tunnel, the VTEP node in the embodiment of the present application can not only perform single-packet authentication on the source VTEP node that sends the BGP Update message, but also perform single-packet authentication on the target VTEP node that receives the BGP Update message. That is, not only can the single-packet authentication information of the source VTEP node be extracted from the BGP Update message and sent to the single-packet authentication server, but the single-packet authentication information of the target VTEP node can also be sent to the single-packet authentication server, and at the same time, the single-packet authentication process of the two VTEP nodes by the single-packet authentication server can be triggered. If and only if the single-packet authentication results of the two VTEP nodes are both authenticated, the VXLAN tunnel between the two will continue to be created. In this way, the security of the data center is further improved.
[0104] Based on the same inventive concept, the present application also provides a VXLAN tunnel creation method, which is applied to the source VTEP node, such as Figure 5 Said method comprises the following steps:
[0105] Step 510: Generate a BGP Update message, wherein the path attribute field of the BGP Update message includes the first single packet authentication information of the source VTEP node;
[0106] Step 520: Send a BGP Update message to the target VTEP node, so that when the target VTEP node determines that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node, the target VTEP node extracts the first single-packet authentication information from the BGP Update message and sends the extracted first single-packet authentication information to the single-packet authentication server. The single-packet authentication server then performs single-packet authentication on the source VTEP node based on the first single-packet authentication information and generates a first single-packet authentication result.
[0107] Step 530: When the first single packet authentication result is authentication passed, work together with the target VTEP node to create a VXLAN tunnel between the source VTEP node and the target VTEP node.
[0108] The present application also provides a VXLAN tunnel creation device, which is applied to a target VTEP node, such as Figure 6 As shown, the device includes:
[0109] A determination module 610 is configured to determine whether a VXLAN tunnel needs to be created between a source VTEP node and a target VTEP node after receiving a BGP Update message, wherein the source VTEP node refers to the VTEP node that sends the BGP Update message;
[0110] The authentication module 620 is configured to, if the judgment result is yes, extract first single-packet authentication information from the path attribute field of the BGP Update message, and send the first single-packet authentication information to a single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information;
[0111] The creation module 630 is configured to obtain a first single-packet authentication result of the source VTEP node from the single-packet authentication server, and when the first single-packet authentication result is authentication passed, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
[0112] In some specific embodiments, the determination module 610 determines whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node by:
[0113] If the BGP Update message includes a Type 3 route, extracting the VNI supported by the source VTEP node from the BGP Update message, determining whether the target VTEP node needs to forward BUM traffic belonging to the VNI supported by the source VTEP node, and if so, determining that a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node; and / or,
[0114] If the BGP Update message includes a Type 2 route, extracting the MAC address of the source VTEP node from the BGP Update message, determining whether the target VTEP node has received a data packet whose MAC address matches the MAC address of the source VTEP node, and if so, determining that a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node; and / or,
[0115] If the BGP Update message contains a Type 5 route, the IP prefix of the source VTEP node is extracted from the BGP Update message, and a determination is made as to whether the target VTEP node has received a data packet whose IP address matches the IP prefix of the source VTEP node. If so, a determination is made as to whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node.
[0116] In some specific embodiments, the creation module 630 creates a VXLAN tunnel between the source VTEP node and the target VTEP node in the following manner:
[0117] The second single-packet authentication information of the target VTEP node is sent to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the target VTEP node according to the second single-packet authentication information; the second single-packet authentication result of the target VTEP node is obtained from the single-packet authentication server, and when the first single-packet authentication result and the second single-packet authentication result are both authenticated, a VXLAN tunnel is created between the source VTEP node and the target VTEP node.
[0118] In some specific embodiments, the authentication module 620 extracts the first single packet authentication information from the path attribute field of the BGP Update message in the following manner:
[0119] If the source VTEP node is a VTEP node of a host overlay, extract any one or more of the following from the path attribute field of the BGP Update message as the first single packet authentication information: processor information, memory information, storage information, motherboard information, network adapter information, power supply information, expansion slot information, operating system information, chassis information; and / or,
[0120] If the source VTEP node is a VTEP node of a network overlay, any one or more of the following are extracted from the path attribute field of the BGP Update message as the first packet authentication information: model and manufacturer information, MAC address, number and type of ports, maximum speed and protocol, processing capacity, power supply mode, heat dissipation and fan information.
[0121] In some specific embodiments, the authentication module 620 extracts the first single packet authentication information from the path attribute field of the BGP Update message in the following manner:
[0122] A target route attribute unit having an attribute type value of a preset threshold in a path attribute field of a BGP Update message is determined, and an attribute value is extracted from the target route attribute unit to serve as first single packet authentication information.
[0123] In some specific embodiments, the device further comprises:
[0124] The prompt module is used to generate a prompt message when the first single-packet authentication result is authentication failure, indicating that the VXLAN tunnel cannot be created because the source VTEP node fails the single-packet authentication.
[0125] The present application also provides a VXLAN tunnel creation device, which is applied to a source VTEP node, such as Figure 7 As shown, the device includes:
[0126] A generating module 710 is configured to generate a BGP Update message, wherein the path attribute field of the BGP Update message includes the first single packet authentication information of the source VTEP node;
[0127] A sending module 720 is configured to send the BGP Update message to a target VTEP node, so that when the target VTEP node determines that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node, the target VTEP node extracts the first single-packet authentication information from the BGP Update message and sends the extracted first single-packet authentication information to a single-packet authentication server, thereby causing the single-packet authentication server to perform single-packet authentication on the source VTEP node according to the first single-packet authentication information and generate a first single-packet authentication result.
[0128] The collaboration module 730 is configured to collaborate with the target VTEP node to create a VXLAN tunnel between the source VTEP node and the target VTEP node when the first single packet authentication result is authentication passed.
[0129] An embodiment of the present application provides an electronic device that may include a memory and one or more processors. The memory is configured to store computer program code, which includes computer instructions. When the processor executes the computer instructions, the electronic device may perform the functions or steps of the above-described method embodiments.
[0130] The structure of the electronic device can refer to Figure 8 The structure of the electronic device 100 is shown.
[0131] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components.
[0132] An embodiment of the present application further provides a computer-readable storage medium, which includes computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes each function or step of the above method embodiment.
[0133] The computer-readable storage medium includes but is not limited to any one of the following: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.
[0134] The embodiment of the present application further provides a computer program product, which, when executed on a computer, enables the computer to execute the functions or steps of the above method embodiment.
[0135] The electronic device, computer-readable storage medium, and computer program product provided in the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects of the corresponding methods provided above, and will not be repeated here.
[0136] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0137] In the several embodiments provided in this application, it should be understood that the disclosed methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation; for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of modules or units, which can be electrical, mechanical or other forms.
[0138] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0139] The above is only a specific embodiment of the present application, but the scope of protection of this application is not limited to this. Any changes or substitutions within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A VXLAN tunnel creation method, characterized in that: The method is applied to a target VTEP node, and the method includes: After receiving the BGP Update message, determine whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node, where the source VTEP node refers to the VTEP node that sent the BGP Update message; If the judgment result is yes, extracting the first single-packet authentication information from the path attribute field of the BGP Update message, and sending the first single-packet authentication information to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information; Obtain a first single-packet authentication result of the source VTEP node from the single-packet authentication server, and when the first single-packet authentication result is authentication passed, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
2. The method according to claim 1, characterized in that The method specifically determines whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node by: If the BGP Update message contains a Type 3 route, extract the VNI supported by the source VTEP node from the BGP Update message, and determine whether the target VTEP node needs to forward BUM traffic belonging to the VNI supported by the source VTEP node. If the judgment result is yes, determine that a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node. and / or, If the BGP Update message contains a Type 2 route, extract the MAC address of the source VTEP node from the BGP Update message, and determine whether the target VTEP node has received a data packet whose MAC address matches the MAC address of the source VTEP node. If so, determine that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node. and / or, If the BGP Update message contains a Type 5 route, the IP prefix of the source VTEP node is extracted from the BGP Update message, and a determination is made as to whether the target VTEP node has received a data packet whose IP address matches the IP prefix of the source VTEP node. If so, a determination is made as to whether a VXLAN tunnel needs to be created between the source VTEP node and the target VTEP node.
3. The method according to claim 1, characterized in that The method specifically creates a VXLAN tunnel between a source VTEP node and a target VTEP node in the following manner: Sending the second single-packet authentication information of the target VTEP node to the single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the target VTEP node according to the second single-packet authentication information; Obtain a second single-packet authentication result of the target VTEP node from the single-packet authentication server, and when both the first single-packet authentication result and the second single-packet authentication result are authenticated, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
4. The method according to claim 1, wherein The method specifically extracts the first single packet authentication information from the path attribute field of the BGP Update message in the following manner: If the source VTEP node is a VTEP node of a host overlay, extract any one or more of the following from the path attribute field of the BGP Update message as the first single packet authentication information: processor information, memory information, storage information, motherboard information, network adapter information, power supply information, expansion slot information, operating system information, and chassis information; and / or, If the source VTEP node is a VTEP node of a network overlay, any one or more of the following are extracted from the path attribute field of the BGP Update message as the first packet authentication information: model and manufacturer information, MAC address, number and type of ports, maximum speed and protocol, processing capacity, power supply mode, heat dissipation and fan information.
5. The method according to claim 1, wherein The method specifically extracts the first single packet authentication information from the path attribute field of the BGP Update message in the following manner: A target route attribute unit having an attribute type value of a preset threshold in a path attribute field of a BGP Update message is determined, and an attribute value is extracted from the target route attribute unit to serve as first single packet authentication information.
6. The method according to claim 1, characterized in that The method further comprises: When the first single-packet authentication result is authentication failure, a prompt message is generated indicating that the VXLAN tunnel cannot be created because the source VTEP node fails the single-packet authentication.
7. A VXLAN tunnel creation method, characterized in that: The method is applied to a source VTEP node, and includes: Generate a BGP Update message, wherein the path attribute field of the BGP Update message includes the first single packet authentication information of the source VTEP node; Sending the BGP Update message to the target VTEP node, so that when the target VTEP node determines that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node, the target VTEP node extracts the first single-packet authentication information from the BGP Update message and sends the extracted first single-packet authentication information to a single-packet authentication server, thereby causing the single-packet authentication server to perform single-packet authentication on the source VTEP node according to the first single-packet authentication information and generate a first single-packet authentication result; When the first single packet authentication result is authentication passed, work together with the target VTEP node to create a VXLAN tunnel between the source VTEP node and the target VTEP node.
8. A VXLAN tunnel creation device, characterized in that: The device is applied to a target VTEP node, and includes: A determination module, configured to determine whether a VXLAN tunnel needs to be created between a source VTEP node and a target VTEP node after receiving a BGP Update message, wherein the source VTEP node refers to the VTEP node that sends the BGP Update message; an authentication module, configured to, if the judgment result is yes, extract first single-packet authentication information from the path attribute field of the BGP Update message, and send the first single-packet authentication information to a single-packet authentication server, so that the single-packet authentication server performs single-packet authentication on the source VTEP node according to the first single-packet authentication information; A creation module is used to obtain a first single-packet authentication result of the source VTEP node from the single-packet authentication server, and when the first single-packet authentication result is authentication passed, create a VXLAN tunnel between the source VTEP node and the target VTEP node.
9. A VXLAN tunnel creation device, characterized in that: The device is applied to a source VTEP node, and includes: A generating module, configured to generate a BGP Update message, wherein the path attribute field of the BGP Update message includes the first single packet authentication information of the source VTEP node; a sending module, configured to send the BGP Update message to a target VTEP node, so that when the target VTEP node determines that a VXLAN tunnel needs to be established between the source VTEP node and the target VTEP node, the target VTEP node extracts the first single-packet authentication information from the BGP Update message and sends the extracted first single-packet authentication information to a single-packet authentication server, thereby causing the single-packet authentication server to perform single-packet authentication on the source VTEP node according to the first single-packet authentication information and generate a first single-packet authentication result; A collaboration module is used to collaborate with the target VTEP node to create a VXLAN tunnel between the source VTEP node and the target VTEP node when the first single packet authentication result is authentication passed.
10. An electronic device, characterized in that: include: A memory, one or more processors; the memory is coupled to the processor; wherein the memory stores computer program code, the computer program code includes computer instructions, and when the computer instructions are executed by the processor, the electronic device executes the method according to any one of claims 1 to 7.
11. A computer-readable storage medium comprising computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 7.
12. A computer program product, characterized in that When the computer program product is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 7.