Message forwarding method, device and system
By directly sensing tenant host connectivity failures and configuring policy routing through Spine devices, the problem of service interruption caused by Peer-Link bandwidth bottlenecks in MLAG technology in cloud data centers was solved, achieving seamless switching and low-latency traffic forwarding.
Patent Information
- Application Number
- CN202511336840.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2026-01-23
AI Technical Summary
In cloud data centers, existing MLAG technology suffers from service interruptions for critical tenants when server access links fail due to Peer-Link bandwidth bottlenecks, failing to meet the millisecond-level seamless switching requirements.
By directly detecting connectivity failures of tenant hosts through Spine devices, configuring policy-based routing, ensuring that traffic does not detour through the Peer-Link link, and using status announcement messages and policy-based routing mechanisms to quickly switch traffic paths.
It achieves non-blocking, low-latency, and seamless switching in a distributed VXLAN gateway environment, avoiding service packet loss caused by Peer-Link link bandwidth bottlenecks and improving fault detection and response speed.
Smart Images

Figure CN121396884A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the field of data communication, and particularly relates to a message forwarding method, device and system. BACKGROUND
[0002] With the rapid development of AI, 5G and other technologies, cloud data centers, as the key infrastructure of digital economy, are evolving to support higher cloud computing demands. Their network architecture presents two major trends:
[0003] Large Layer 2 flattening: Break through the limit of traditional VLAN (Virtual Local Area Network) with a maximum of 4096 by VXLAN (Virtual Extensible Local Area Network) technology, realize Layer 2 extension across Layer 3 network.
[0004] Spine-Leaf architecture popularization: Replace traditional Layer 3 network, provide non-blocking, low-latency connection, support large-scale migration of tenant hosts and resource pooling management.
[0005] In the cloud data center environment, key businesses such as finance and government require up to 99.999% availability, and single-point access cannot meet the reliability requirements, so high availability needs to be achieved through multi-homing access technology. In the current cloud data center, server multi-homing access to VXLAN network mainly relies on two technologies: ESI (Ethernet Segment Identifier) and MLAG (Multichassis Link Aggregation Group). Among them, ESI technology relies on BGP (Border Gateway Protocol) EVPN (Ethernet Virtual Private Network) protocol to realize remote VTEP (VXLAN Tunnel Endpoint) to perceive the state of local access link. The fault switching speed is slow, usually reaching seconds, which is difficult to meet the millisecond-level switching requirements of key businesses. MLAG technology virtualizes two physical devices as a single logical device to realize link aggregation and fault redundancy. The link fault switching rate can reach milliseconds, which is widely used in multi-homing access of key businesses. However, the existing MLAG technology relies on Peer-Link link for traffic switching after failure. The link bandwidth of Peer-link between MLAG devices is usually smaller than the bandwidth of the uplink, and once the access link fails, the traffic detours to Peer-Link, which is easy to cause business interruption due to insufficient bandwidth.
[0006] In a cloud data center network of a distributed VXLAN gateway, when a key tenant service is connected to a VXLAN network through multi-homing access, the following challenges are faced: when a server access link fails, the existing MLAG technology may cause service interruption due to the bandwidth bottleneck of the Peer-Link. Therefore, a new high-reliability mechanism is urgently needed to provide a multi-homing access solution for key tenant services in a distributed VXLAN gateway environment, which is non-blocking, low-latency and seamless switching. SUMMARY
[0007] To solve the above problems, the embodiments of the present application provide a packet forwarding method, device and system, which can enable the Spine device to quickly and directly perceive the connectivity failure between the Spine device and the tenant host, greatly shortening the fault detection and response time. The problem of the prior art that the link connectivity failure of the tenant host accessed by the local VTEP device needs to be indirectly perceived by the remote VTEP device through the BGP EVPN protocol, which is slow in response speed and affects service recovery, is solved.
[0008] Based on the above purpose, the packet forwarding method, device and system provided by the embodiments of the present application ensure that when a single-point link failure occurs between a Leaf device in an MLAG group and an accessed tenant host, the traffic from the Spine device to the Leaf device no longer detours the Peer-Link link, thereby fundamentally avoiding the problem of service packet loss caused by the bandwidth bottleneck of the Peer-Link link.
[0009] In a first aspect, the embodiments of the present application provide a packet forwarding method applied to a Spine device, wherein the Spine device is in communication connection with a first Leaf device and a second Leaf device, the first Leaf device and the second Leaf device form an MLAG group, and the method comprises the following steps:
[0010] receiving a state advertisement packet carrying route unreachable indication information sent by the first Leaf device, obtaining the IP address of the tenant host in the state advertisement packet, and configuring a policy route for the tenant host based on the IP address of the tenant host; the policy route is used to indicate that a data packet with a destination IP address being the IP address of the tenant host is forwarded through the second Leaf device;
[0011] After receiving the data packet with the destination IP address being the IP address of the tenant host, the data packet is forwarded through the second Leaf device according to the policy route.
[0012] In a possible implementation, before the step of configuring the policy route for the tenant host based on the IP address of the tenant host, the method further comprises the following steps:
[0013] receiving a first address advertisement message sent by the first Leaf device, and obtaining a first loopback interface address and a second loopback interface address of the first Leaf device carried in the first address advertisement message;
[0014] receiving a second address advertisement message sent by the second Leaf device, and obtaining a first loopback interface address and a second loopback interface address of the second Leaf device carried in the second address advertisement message;
[0015] establishing a correspondence table of the first loopback interface address and the second loopback interface address of the first Leaf device and the first loopback interface address and the second loopback interface address of the second Leaf device;
[0016] The first loopback interface address of the first Leaf device is different from the first loopback interface address of the second Leaf device, and the second loopback interface address of the first Leaf device is the same as the second loopback interface address of the second Leaf device.
[0017] In a possible implementation, the step of configuring a policy route for the tenant host based on the IP address of the tenant host comprises:
[0018] configuring a policy route for the tenant host according to the correspondence table, a matching rule of the policy route being that a type of a message is VXLAN encapsulation, an outer destination IP address of the message is the second loopback interface address of the first Leaf device, a VNI corresponding to a tenant to which the tenant host belongs, and an inner destination IP address of the message is the IP address of the tenant host, and a next hop of the policy route being directed to the first loopback interface address of the second Leaf device.
[0019] In a possible implementation, the method further comprises:
[0020] receiving a state advertisement message carrying route reachability indication information sent by the first Leaf device, and deleting the policy route according to an IP address of a tenant host in the state advertisement message.
[0021] In a second aspect, an embodiment of the present application provides a message forwarding method applied to a first Leaf device, the first Leaf device being in communication connection with a Spine device, the Spine device further being in communication connection with a second Leaf device, the first Leaf device and the second Leaf device forming an MLAG group, and the method comprising:
[0022] detecting connectivity of a tenant host in communication connection with the Leaf device;
[0023] When detecting that a tenant host connected with the Leaf device has a connectivity failure, encapsulate the IP address of the tenant host and route unreachable indication information into a state advertisement packet and send to the Spine device.
[0024] In a possible implementation, the state advertisement packet is a VXLAN encapsulation, and the step of encapsulating the IP address of the tenant host and the route unreachable information into the state advertisement packet and sending to the Spine device includes:
[0025] If the inner packet of the state advertisement packet is an ARP request packet, encapsulate the IP address of the tenant host into a sender IP address field of the ARP request packet, and encapsulate the route unreachable indication information into an operation type field of the ARP request packet; encapsulate a first loopback interface address of the Leaf device into an outer source IP address of the state advertisement packet, encapsulate a loopback interface address of the Spine device into an outer destination IP address of the state advertisement packet, and send the state advertisement packet to the Spine device; or,
[0026] If the inner packet of the state advertisement packet is an ICMPv6 neighbor request packet, encapsulate the IP address of the tenant host and the route unreachable indication information into an option field of the ICMPv6 neighbor request packet; encapsulate the first loopback interface address of the Leaf device into an outer source IP address of the state advertisement packet, encapsulate the loopback interface address of the Spine device into an outer destination IP address of the state advertisement packet, and send the state advertisement packet to the Spine device.
[0027] In a possible implementation, the method further includes:
[0028] Encapsulate the first loopback interface address and the second loopback interface address of the Leaf device into an address advertisement packet and send to the Spine device.
[0029] In a possible implementation, the address advertisement packet is a VXLAN encapsulation, and the step of encapsulating the first loopback interface address and the second loopback interface address of the Leaf device into the address advertisement packet and sending to the Spine device includes:
[0030] if the inner-layer message of the address announcement message is an ARP request message, encapsulating a second loopback interface address of the Leaf device into a sender IP address field of the ARP request message, encapsulating a first loopback interface address of the Leaf device into an outer-layer source IP address of the address announcement message, encapsulating a loopback interface address of the Spine device into an outer-layer destination IP address of the address announcement message, and sending the address announcement message to the Spine device; or
[0031] if the inner-layer message of the address announcement message is an ICMPv6 neighbor request message, encapsulating a second loopback interface address of the Leaf device into an option field of the ICMPv6 neighbor request message, encapsulating a first loopback interface address of the Leaf device into an outer-layer source IP address of the address announcement message, encapsulating a loopback interface address of the Spine device into an outer-layer destination IP address of the address announcement message, and sending the address announcement message to the Spine device.
[0032] In a third aspect, an embodiment of the present application provides a packet forwarding apparatus applied to a Spine device, wherein the Spine device is in communication connection with a first Leaf device and a second Leaf device respectively, the first Leaf device and the second Leaf device form an MLAG group, and the apparatus comprises:
[0033] a receiving module configured to receive a state announcement message carrying route unreachable indication information sent by the first Leaf device;
[0034] a configuration module configured to acquire an IP address of a tenant host in the state announcement message, and configure a policy route for the tenant host based on the IP address of the tenant host, wherein the policy route is used to indicate that a data packet with a destination IP address being the IP address of the tenant host is forwarded through the second Leaf device;
[0035] the receiving module is further configured to receive the data packet with the destination IP address being the IP address of the tenant host;
[0036] a sending module configured to forward the data packet through the second Leaf device according to the policy route.
[0037] In a fourth aspect, an embodiment of the present application provides a packet forwarding apparatus applied to a first Leaf device, wherein the first Leaf device is in communication connection with a Spine device, the Spine device is further in communication connection with a second Leaf device, the first Leaf device and the second Leaf device form an MLAG group, and the apparatus comprises:
[0038] The detection module is used to detect the connectivity of tenant hosts that are connected to this Leaf device.
[0039] The sending module is used to encapsulate the IP address and route unreachability information of a tenant host that is connected to this Leaf device into a status announcement message and send it to the Spine device when a connectivity failure is detected.
[0040] Fifthly, embodiments of the present invention provide a packet forwarding system, the system comprising at least a Spine device, a first Leaf device, a second Leaf device, and a server. The Spine device is communicatively connected to the first Leaf device and the second Leaf device, respectively. The first Leaf device and the second Leaf device form an MLAG group. The server deploys tenant hosts and is dual-homed to both the first Leaf device and the second Leaf device. The Spine device executes the packet forwarding method as described in the first aspect above, and the first Leaf device or the second Leaf device executes the packet forwarding method as described in the second aspect above.
[0041] This invention provides a packet forwarding method, apparatus, and system. When a Leaf device detects a connectivity failure with a tenant host, it proactively sends a status notification message to the Spine device. This enables the Spine device to quickly and directly detect the connectivity failure between the Leaf device and the tenant host, significantly reducing fault detection and response time. Simultaneously, by configuring policy routing on the Spine device, it ensures that when a single point of failure occurs between a Leaf device in an MLAG group and an access tenant host, traffic from the Spine device to that tenant host will no longer be routed through the Peer-Link link, avoiding packet loss issues caused by Peer-Link link bandwidth bottlenecks. Attached Figure Description
[0042] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0043] Figure 1 This is a schematic diagram illustrating an example application scenario;
[0044] Figure 2 This is a flowchart illustrating a message forwarding method provided in an embodiment of the present invention;
[0045] Figure 3A flowchart of a packet forwarding method provided by an embodiment of the present application is shown in FIG. 1.
[0046] Figure 4 A structural diagram of a packet forwarding device provided by an embodiment of the present application is shown in FIG. 2.
[0047] Figure 5 A structural diagram of a packet forwarding device provided by an embodiment of the present application is shown in FIG. 2.
[0048] Figure 6 A schematic diagram of an example packet forwarding system provided by an embodiment of the present application is shown in FIG. 3. DETAILED DESCRIPTION
[0049] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0050] The system architecture and business scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art can know that, as the system architecture evolves and new business scenarios appear, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0051] The above method will be described in detail below with reference to specific embodiments.
[0052] First, a brief introduction is given to the Spine-Leaf architecture in the embodiments of the present application. In the Spine-Leaf architecture, Leaf devices are directly connected to servers, firewalls, load balancers and other devices. Each Leaf device is connected to all other Spine devices. Spine devices are core switching devices, which are only responsible for high-speed forwarding of traffic and do not connect to servers.
[0053] In current cloud data centers, the server multi-homing access VXLAN network mainly relies on two technologies: ESI and MLAG. Among them, the ESI technology relies on the BGP EVPN protocol to realize the remote VTEP device to perceive the local access link state. The fault switching speed is slow, usually reaching seconds, which is difficult to meet the millisecond switching demand of key business. The MLAG technology realizes link aggregation and fault redundancy by virtualizing two physical devices as a single logical device. The link fault switching rate can reach milliseconds, which is widely used in the industry for key business multi-homing access. However, the existing MLAG technology relies on Peer-Link link for fault traffic switching. The link bandwidth of the Peer-link link between MLAG devices is usually smaller than the bandwidth of the uplink link. Once the access link fails, the traffic is easy to cause business interruption due to insufficient bandwidth when it is detoured to Peer-Link.
[0054] In the cloud data center network of the distributed VXLAN gateway, when the key tenant business is connected to the VXLAN network through multi-homing access, the following challenges are faced: when the server access link fails, the existing MLAG technology may cause business interruption due to the bandwidth bottleneck of Peer-Link. Therefore, a new high-reliability mechanism is needed to provide a multi-homing access solution for key tenant business with no blocking, low delay and seamless switching in the distributed VXLAN gateway environment.
[0055] In order to solve the above problems, the embodiment of the application provides a message forwarding method, device and system, which can enable the Spine device to quickly and directly perceive the connectivity fault between the Leaf device and the tenant host, greatly shortening the fault detection and response time. The existing technology needs to indirectly perceive the link connectivity fault of the tenant host accessed by the local VTEP device through the remote VTEP device relying on the BGP EVPN protocol, which has a slow response speed and affects business recovery. Meanwhile, the message forwarding method, device and system provided by the embodiment of the application ensure that when a single point link fault occurs between a Leaf device in the MLAG group and the accessed tenant host, the traffic from the Spine to the tenant host no longer detours the Peer-Link link, avoiding the problem of business packet loss caused by the bandwidth bottleneck of the Peer-Link link.
[0056] The specific implementation process of the message forwarding method provided by the embodiment of the application will be described in detail below in combination with specific embodiments. For example, Figure 1As shown, an example application scenario diagram is provided, in which a Leaf1-1 device, a Leaf1-2 device are in communication connection with a Spine1 device and a Spine2 device respectively, a Leaf2 device is in communication connection with the Spine1 device and the Spine2 device respectively, a Server1 multi-homing accesses the Leaf1-1 device and the Leaf1-2 device, and a tenant host is deployed in the Server1, which can be a bare-metal server or a virtual machine. The Leaf1-1 device and the Leaf1-2 device form an MLAG group, the Leaf1-1 device and the Leaf1-2 device form a logical VTEP (VXLAN Tunnel Endpoint) device (namely a local VTEP device), and a Server2 accesses the Leaf2 device, and the Leaf2 device is a remote VTEP device.
[0057] In the embodiment of the application, the Leaf1-1 device and the Leaf1-2 device respectively create a first loopback interface configured with different IP addresses as local loopback interface addresses of the MLAG group member devices. The Leaf1-1 device and the Leaf1-2 device respectively create a second loopback interface configured with the same IP address as a public VTEP address of the MLAG group. The Leaf1-1 device and the Leaf1-2 device in the MLAG group use the public VTEP address to establish a VXLAN tunnel with the Leaf2 device. The corresponding loopback interfaces of the Leaf device and the Spine device ensure route reachability through static routing or dynamic routing.
[0058] In the embodiment of the application, the Leaf device encapsulates the first loopback interface address and the second loopback interface address of the Leaf device in an address advertisement packet and sends the address advertisement packet to all Spine devices in communication connection with the Leaf device. For example, the address advertisement packet can be a VXLAN tunnel packet or other packet encapsulated by VXLAN. Figure 1 In the application scenario shown, the Leaf1-1 device encapsulates the first loopback interface address and the second loopback interface address of the Leaf device in an address advertisement packet and sends the address advertisement packet to the Spine1 device and the Spine2 device respectively. Similarly, the Leaf1-2 device encapsulates the first loopback interface address and the second loopback interface address of the Leaf device in an address advertisement packet and sends the address advertisement packet to the Spine1 device and the Spine2 device respectively.
[0059] In one possible implementation, the address advertisement message is a VXLAN tunnel message. The Leaf1-1 and Leaf1-2 devices send VXLAN tunnel messages to the Spine1 and Spine2 devices respectively, with the loopback interface addresses of the Spine1 and Spine2 devices (such as the Loopback0 address) as the outer destination IP address and their respective first loopback interface addresses as the outer source IP address. If the Underlay network is of IPv4 type, the outer and inner IP headers of the VXLAN tunnel message are in IPv4 format, and the inner message is an ARP request message. The second loopback interface addresses of the Leaf1-1 and Leaf1-2 devices are encapsulated in the IP Address of Sender field of the inner ARP request message. If the VXLAN Underlay network is of IPv6 type, the outer and inner IP header formats of the VXLAN tunnel packet encapsulation are IPv6 format, and the inner packet is an ICMP v6 neighbor request packet. The second loopback interface addresses of Leaf1-1 and Leaf1-2 devices are encapsulated in the Options field of the ICMP v6 neighbor request packet, and the Options field adopts TLV format.
[0060] In this embodiment of the invention, after receiving the address advertisement message sent by the Leaf device, the Spine device obtains the first loopback interface address and the second loopback interface address of the Leaf device carried in the address advertisement message; and establishes a correspondence table between the first loopback interface address and the second loopback interface address of the Leaf device. Combined with... Figure 1 In the application scenario shown, the first loopback interface addresses of Leaf1-1 and Leaf1-2 are different, but their second loopback interface addresses are the same. After receiving the address announcement message from Leaf1-1, Spine1 obtains the first and second loopback interface addresses of Leaf1-1. Similarly, after receiving the address announcement message from Leaf1-2, Spine1 obtains the first and second loopback interface addresses of Leaf1-2. Spine1 then associates these addresses with those of Leaf1-1, establishing a mapping table of Leaf device loopback interface addresses on Spine1. Table 1 below provides an example of a mapping table of Leaf device loopback interface addresses recorded on Spine1. This example only lists the relevant parameters required for this embodiment of the invention; obviously, other parameters may also be included, but no specific limitations are made here.
[0061] Table 1: An example of a Leaf device's loopback interface address correspondence table recorded on a Spine1 device
[0062] Device Name MLAG Group First Loopback Interface Address Second Loopback Interface Address Leaf1-1 MLAG1 1.1.1.1 10.10.10.10 Leaf1-2 MLAG1 1.1.1.2 10.10.10.10 Leaf2 MLAG2 2.2.2.2 20.20.20.20
[0063] In a possible implementation, in a case where the link connectivity of the Server1 multi-homing access Leaf1-1 device and the Leaf1-2 device is normal, the Leaf1-1 device or the Leaf1-2 device receives an ARP request message or an ND (neighbor discovery) request message through a downlink, and obtains an ARP entry or an ND entry of a tenant host from the ARP request message or the ND request message.
[0064] In another possible implementation, in a case where the link connectivity of the Server1 multi-homing access Leaf1-1 device,
[0065] The Leaf1-1 device or the Leaf1-2 device learns an ARP entry or an ND entry of a tenant host through a Peer-link control plane synchronization.
[0066] The Leaf1-1 device and the Leaf1-2 device obtain tenant host information from the ARP entry or the ND entry. The tenant host information includes an IP address of the tenant host and the like. The Leaf1-1 device and the Leaf1-2 device can detect the connectivity of a link between the Leaf device and the tenant host through a BFD fast detection mechanism.
[0067] In the embodiment of the application, two Leaf devices as MLAG members respectively detect a routing reachable state between the Leaf device and a tenant host. The routing reachable state (divided into two states of routing reachable and routing unreachable) between the Leaf device and the tenant host is carried in a state advertisement message and sent to all Spine devices in communication connection with the Leaf device, for announcing the routing unreachable state when detecting that the connectivity between the Leaf device and the tenant host fails, or quickly announcing the routing reachable state of the Leaf device to the tenant host to the Spine device after the connectivity failure is recovered. Specifically, after the Leaf device detects that the access link of the tenant host fails, the Leaf device where the failure link is located sends a state advertisement message indicating the routing unreachable to the Spine device, and the state advertisement message carries the routing unreachable indication information at this time. After the Leaf device detects that the access link connectivity failure is recovered, the corresponding Leaf device sends a state advertisement message carrying the routing reachable indication information to the Spine device.
[0068] In the embodiment of the present application, the state advertisement message of the tenant host routing reachable state can be encapsulated in the VXLAN tunnel message format. The loopback interface address of the Spine device is taken as the outer destination IP address, the first loopback interface address of the Leaf device is taken as the outer source IP address, and the inner message is the ARP Request message or the ICMPv6 neighbor request message. The OP field of the ARP Request message or the Options field of the ICMPv6 neighbor request message carries the custom information to indicate that the message type is the state advertisement message of the tenant host routing reachable state and simultaneously indicate the state information of the routing reachable or the routing unreachable. If the Underlay network is of the IPv4 type, the outer IP header of the VXLAN tunnel message is encapsulated in the IPv4 format, if the Underlay network is of the Ipv6 type, the outer IP header of the VXLAN tunnel message is encapsulated in the Ipv6 format, if the Overlay network is of the IPv4 type, the inner message is the ARP Request message, and if the Overlay network is of the Ipv6 type, the inner message is the ICMPv6 neighbor request message. The VNI (VXLAN network identifier) field of the VXLAN tunnel header indicates the tenant identifier. The IP Address of Sender field of the ARP Request message carries the IPv4 address of the tenant host, and the Options field (TLV format) of the ICMPv6 neighbor request message carries the IPv6 address of the tenant host.
[0069] When the Spine device receives the state advertisement message of the Leaf device and finds that the state advertisement message carries the routing unreachable indication information, the Spine device acquires the IP address of the tenant host in the state advertisement message, globally configures a policy routing for guiding the traffic forwarding of the tenant host, the matching rule of the policy routing is to simultaneously match the VXLAN encapsulation, the outer destination IP address being the second loopback interface address of the Leaf device (the public VTEP address of the MLAG group), the VNI corresponding to the tenant to which the tenant host belongs, and the inner destination IP address being the IP address of the tenant host, the next hop IP address of the policy routing is directed to the first loopback interface address of the other Leaf device in the same MLAG group which has no downlink fault, and the Spine device finds the egress information directly connected with the Leaf device to which the first loopback interface address belongs in an iterative routing manner according to the first loopback interface address.
[0070] When the Spine device receives the state advertisement message of the Leaf device and finds that the state advertisement message carries the routing unreachable indication information, the Spine device acquires the IP address of the tenant host in the state advertisement message, globally configures a policy routing for guiding the traffic forwarding of the tenant host, the matching rule of the policy routing is to simultaneously match the VXLAN encapsulation, the outer destination IP address being the second loopback interface address of the Leaf device (the public VTEP address of the MLAG group), the VNI corresponding to the tenant to which the tenant host belongs, and the inner destination IP address being the IP address of the tenant host, the next hop IP address of the policy routing is directed to the first loopback interface address of the other Leaf device in the same MLAG group which has no downlink fault, and the Spine device finds the egress information directly connected with the Leaf device to which the first loopback interface address belongs in an iterative routing manner according to the first loopback interface address.
[0071] After the data packet encapsulated by the VXLAN tunnel is encapsulated by the public VTEP address of the MLAG group, the VNI corresponding to the tenant to which the tenant host belongs, and the inner layer destination IP address of the IP address of the tenant host, the Spine device forwards the data packet to the Leaf device directly connected to the next hop IP address of the policy routing according to the next hop IP address found by the iterative routing.
[0072] For example, if the Spine device receives the VXLAN packet forwarded from the Leaf2, and based on the policy routing, matches that the VXLAN packet is encapsulated by the VXLAN, the outer layer destination IP address of the VXLAN packet is the second loopback interface address of the Leaf1-1 device, the VNI corresponding to the tenant to which the tenant host belongs, and the inner layer destination IP address of the IP address of the tenant host, the VXLAN packet is forwarded to the Leaf1-2 device according to the next hop of the policy routing.
[0073] Obviously, when the Leaf1-2 device detects that the connectivity between the Leaf device and the tenant host fails or recovers, the operation performed by the Leaf1-2 device is the same as that of the Leaf1-1 device, which will not be described here.
[0074] It can be understood that the present application only takes the execution process of the Leaf1-1 device as an example to describe the processing flow of one of the two Leaf devices in the logical VTEP device when the connectivity between the Leaf device and the accessed tenant host fails or recovers, and the processing flow of any Leaf device when the connectivity between the Leaf device and the accessed tenant host fails or recovers is the same as the execution flow of the Leaf1-1 device described above, which will not be described here.
[0075] The packet forwarding method provided by the embodiment of the present application enables the Spine device to perceive the routing connectivity fault between the Leaf device and the tenant host based on the tenant host granularity through the state advertisement packet combined with the policy routing, which is more accurate than the current mainstream technology based on the link level fault protection technology. In the case that the multi-homing access physical link of the accessed tenant host is normal and the logical link is unreachable, the Spine device can accurately guide the flow based on the tenant host.
[0076] The present application adopts the Spine device to quickly perceive the routing reachable state between the Leaf device and the multi-homing access tenant host, which is more rapid than the response speed of the traditional scheme using the BGP protocol to advertise the remote VTEP device to perceive the routing reachable state between the Leaf device and the multi-homing access tenant host.
[0077] The Spine device can quickly switch the traffic with the IP address of the tenant host as the destination IP address to the non-faulty Leaf device belonging to the same MLAG group as the Leaf device after the connectivity of the Leaf device of the MLAG multi-homing access tenant host fails, avoids the traffic passing through
[0078] The Peer-link bypass avoids the problem of packet loss caused by insufficient bandwidth of the Peer-link after the multi-homing access traffic is switched.
[0079] In the embodiment of the application, if the Spine device identifies that the routes between the two Leaf devices in the MLAG group and the tenant host are all reachable or all unreachable, the policy route guiding the traffic forwarding with the IP address of the tenant host as the destination IP address is deleted, so as to prevent the occupation of the policy route table item resources of the Spine device in the case that the multi-homing access link connectivity is normal or completely unreachable, and ensure that the policy routing rule is configured on the Spine device only when the route of one Leaf device in the MLAG group is unreachable. In the case that the multi-homing access link connectivity is normal, the Spine device only needs to forward the traffic to the tenant host according to the multiple path load sharing forwarding mode of the next hop ECMP (equal cost multi-path) of the routing table
[0080] The traffic of the two Leaf devices in the MLAG group to the tenant host does not need to be configured with the policy route to guide the traffic forwarding. In the case that all the multi-homing access links are completely unreachable, the Leaf device in the MLAG group will advertise the tenant host route unreachable to the remote VTEP device through the BGP EVPN control plane. After the remote VTEP device senses that the tenant host route is completely unreachable, the routing table item to the tenant host is cleared, and the traffic to the tenant host will not be forwarded through the Spine device, so the policy route does not need to be configured on the Spine device to guide the traffic forwarding. In the embodiment of the application, the Spine device configures and deletes the policy route according to the tenant host route reachable state information, and accurately guides the routing forwarding path of the tenant host traffic.
[0081] In the embodiment of the application, the Spine device can identify that the routes between the two Leaf devices in the MLAG group and the tenant host are all unreachable according to the configured policy route and the newly received state advertisement packet. For example, in combination with the route reachable state information of the tenant host, the Spine device can identify that the routes between the two Leaf devices in the MLAG group and the tenant host are all unreachable. Figure 1In the application scenario shown, when the Leaf1-1 device detects that the route between the Leaf device and the tenant host is unreachable, the Leaf1-1 device sends a state notification message carrying route unreachable indication information and the IP address of the tenant host, the Spine1 device configures a policy route for guiding the tenant host traffic to be forwarded through the Leaf1-2 device based on the IP address of the tenant host, and then receives the state notification message sent by the Leaf1-2 device, which carries route unreachable indication information and the IP address of the tenant host, and informs that the route between the Leaf1-2 device and the tenant host is unreachable. At this time, the Spine1 device identifies that the routes between the Leaf1-1 device and the Leaf1-2 device and the tenant host are both unreachable, and the Spine1 device deletes the policy route configured for the tenant host.
[0082] In the embodiment of the application, the Spine device can identify that the routes between the two Leaf devices in the MLAG group and the tenant host are both reachable according to the state notification message carrying route reachable indication information. For example, in combination with the application scenario shown in FIG. 1, when the Leaf1-1 device detects that the route between the Leaf device and the tenant host is reachable, the Leaf1-1 device sends a state notification message carrying route reachable indication information to the Spine1 device. Figure 1 In the application scenario shown, after the Leaf1-1 device detects that the connectivity between the Leaf device and the tenant host recovers, the Leaf1-1 device sends a state notification message carrying route reachable indication information to the Spine1 device. After the Spine1 device receives the state notification message carrying route reachable indication information sent by the Leaf1-1 device, the Spine1 device identifies that the route between the Leaf1-1 device and the tenant host is reachable, and then the Spine1 device deletes the policy route configured for the tenant host.
[0083] The packet forwarding method provided by the embodiment of the application can automatically configure or delete a policy route in a Spine device according to the connectivity state between a Leaf device and a multi-homing access tenant host, so that the policy route rule is configured in the Spine device only when connectivity failure exists between one Leaf device in an MLAG group and an access tenant host, the limited hardware chip resources of the Spine device are efficiently utilized, and the problem that the hardware chip resources of the Spine device are exhausted due to an increase in the number of tenant hosts does not occur.
[0084] For example, in combination with the application scenario shown in FIG. 1, Figure 1 In the application scenario shown, if the Leaf1-1 device (hereinafter referred to as the first Leaf device) detects that connectivity failure occurs between the Leaf device and the tenant host, the specific implementation of the packet forwarding method provided by the embodiment of the application on the Spine device is as follows: Figure 2 As shown in the figure, Figure 2A flowchart of a packet forwarding method provided by an embodiment of the present application is applied to a Spine device, the Spine device is in communication connection with a first Leaf device and a second Leaf device respectively, the first Leaf device and the second Leaf device form an MLAG group, and the method comprises the following steps:
[0085] In step 201, a state advertisement packet carrying a route unreachable indication information sent by the first Leaf device is received, an IP address of a tenant host in the state advertisement packet is acquired, and a policy route is configured for the tenant host based on the IP address of the tenant host; the policy route is used to indicate that a data packet with a destination IP address being the IP address of the tenant host is forwarded through the second Leaf device.
[0086] In step 202, after receiving the data packet with the destination IP address being the IP address of the tenant host, the data packet is forwarded through the second Leaf device according to the policy route.
[0087] In a possible implementation, before the step of configuring the policy route for the tenant host based on the IP address of the tenant host in step 201, the method further comprises the following steps:
[0088] A first address advertisement packet sent by the first Leaf device is received, and a first loopback interface address and a second loopback interface address of the first Leaf device carried in the first address advertisement packet are acquired.
[0089] A second address advertisement packet sent by the second Leaf device is received, and a first loopback interface address and a second loopback interface address of the second Leaf device carried in the second address advertisement packet are acquired.
[0090] A correspondence table of the first loopback interface address and the second loopback interface address of the first Leaf device and the first loopback interface address and the second loopback interface address of the second Leaf device is established. The first loopback interface address of the first Leaf device is different from the first loopback interface address of the second Leaf device, and the second loopback interface address of the first Leaf device is the same as the second loopback interface address of the second Leaf device. In the embodiment of the present application, the first loopback interfaces of all Leaf devices in the same MLAG are respectively configured with different IP addresses as local loopback interface addresses of MLAG member devices; the second loopback interfaces of all Leaf devices in the same MLAG group are respectively configured with the same IP address as a public VTEP address of the MLAG group. The first Leaf device and the second Leaf device form a logical VTEP device.
[0091] In a possible implementation, the step of configuring the policy route for the tenant host based on the IP address of the tenant host in step 201 specifically comprises the following steps:
[0092] The policy routing is configured for the tenant host according to the correspondence table, a matching rule of the policy routing is that a message type is a VXLAN encapsulation, an outer destination IP address of the message is a second loopback interface address of the first Leaf device, a VNI corresponding to a tenant to which the tenant host belongs, and an inner destination IP address of the message is an IP address of the tenant host, and a next hop of the policy routing is pointed to the first loopback interface address of the second Leaf device.
[0093] Optionally, the packet forwarding method provided by the embodiment of the application further includes: when the Spine device determines that all the routes from all the Leaf devices in the same MLAG group to the tenant host are reachable or unreachable, the Spine device deletes the policy routing for guiding the tenant host traffic forwarding. In the specific implementation, the route reachable indication information is carried in the state advertisement message, and the Spine device determines that all the routes from all the Leaf devices in the same MLAG group to the tenant host are reachable based on the route reachable indication information, so as to delete the previously created policy routing. Alternatively, the route unreachable indication information is carried in the state advertisement message, and the Spine device determines that all the routes from all the Leaf devices in the same MLAG group to the tenant host are unreachable based on the route unreachable indication information, so as to delete the previously created policy routing.
[0094] The packet forwarding method provided by the embodiment of the application can quickly switch the traffic with the IP address of the tenant host to the non-faulty Leaf device belonging to the same MLAG group as the Leaf device after the Leaf device of the MLAG multi-homing access tenant host appears connectivity failure, avoids the traffic bypassing through the Peer-link, and avoids the problem of packet loss caused by insufficient bandwidth of the Peer-link after the multi-homing access traffic switching.
[0095] For example, in the application scenario shown in Figure 1 For example, in the application scenario shown in Figure 3 For example, in the application scenario shown in Figure 3 The flowchart of the packet forwarding method provided by the embodiment of the application is shown in
[0096] Step 301: detecting the connectivity of the tenant host in communication connection with the Leaf device.
[0097] Step 302: encapsulating the IP address of the tenant host and the route unreachable indication information into a state advertisement packet and sending the state advertisement packet to the Spine device when detecting that the tenant host connected with the Leaf device has a connectivity failure.
[0098] In a possible implementation, the state advertisement packet is a VXLAN encapsulation, and the step of encapsulating the IP address of the tenant host and the route unreachable indication information into the state advertisement packet and sending the state advertisement packet to the Spine device in step 302 specifically includes:
[0099] If the inner packet of the state advertisement packet is an ARP request packet, the IP address of the tenant host is encapsulated into an IP Address of Sender field of the ARP request packet, and the route unreachable indication information is encapsulated into an OP field of the ARP request packet; a first loopback interface address of the Leaf device is encapsulated into an outer source IP address of the state advertisement packet, a loopback interface address of the Spine device is encapsulated into an outer destination IP address of the state advertisement packet, and the state advertisement packet is sent to the Spine device.
[0100] The step of encapsulating the IP address of the tenant host and the route unreachable indication information into the state advertisement packet and sending the state advertisement packet to the Spine device in step 302 specifically further includes: if the inner packet of the state advertisement packet is an ICMPv6 neighbor solicitation packet, the IP address of the tenant host and the route unreachable indication information are encapsulated into an Options field of the ICMPv6 neighbor solicitation packet; the first loopback interface address of the Leaf device is encapsulated into the outer source IP address of the state advertisement packet, the loopback interface address of the Spine device is encapsulated into the outer destination IP address of the state advertisement packet, and the state advertisement packet is sent to the Spine device.
[0101] In a possible implementation, the message forwarding method provided by the embodiment of the present application further includes:
[0102] The first loopback interface address and the second loopback interface address of the Leaf device are encapsulated in an address advertisement packet and sent to the Spine device.
[0103] In a possible implementation, the address advertisement packet is a VXLAN encapsulation, and the step of encapsulating the first loopback interface address and the second loopback interface address of the Leaf device in the address advertisement packet and sending the address advertisement packet to the Spine device specifically includes:
[0104] If the inner-layer message of the address announcement message is an ARP request message, the second loopback interface address of the Leaf device is encapsulated into the IP Address of Sender field of the ARP request message; the first loopback interface address of the Leaf device is encapsulated into the outer-layer source IP address of the address announcement message, the loopback interface address of the Spine device is encapsulated into the outer-layer destination IP address of the address announcement message, and the address announcement message is sent to the Spine device.
[0105] The step of encapsulating the first loopback interface address and the second loopback interface address of the Leaf device into the address announcement message and sending the address announcement message to the Spine device further comprises:
[0106] If the inner-layer message of the address announcement message is an ICMPv6 neighbor request message, the second loopback interface address of the Leaf device is encapsulated into the Options field of the ICMPv6 neighbor request message; the first loopback interface address of the Leaf device is encapsulated into the outer-layer source IP address of the address announcement message, the loopback interface address of the Spine device is encapsulated into the outer-layer destination IP address of the address announcement message, and the address announcement message is sent to the Spine device.
[0107] The packet forwarding method provided by the embodiment of the present application can make the Spine device quickly and directly perceive the connectivity failure between the Leaf device and the tenant host when the Leaf device detects the connectivity failure with the tenant host and actively sends a state notification message to inform the Spine device, thereby greatly shortening the fault detection and response time.
[0108] The packet forwarding device provided by the embodiment of the present application is applied to a Spine device, the Spine device is in communication connection with a first Leaf device and a second Leaf device, the first Leaf device and the second Leaf device form an MLAG group, as shown in Figure 4 The device 40 comprises:
[0109] The receiving module 401 is configured to receive a state notification message carrying a routing unreachable indication information sent by the first Leaf device.
[0110] The configuration module 402 is configured to acquire the IP address of the tenant host carried by the state notification message, and configure a policy route for the tenant host based on the IP address of the tenant host; the policy route is used to indicate that a data packet with the IP address of the tenant host as a destination IP address is forwarded through the second Leaf device.
[0111] The receiving module 401 is further configured to receive the data packet with the IP address of the tenant host as the destination IP address.
[0112] The sending module 403 is configured to forward the data packet through the second Leaf device according to the policy routing.
[0113] In a possible implementation, the receiving module 401 is further configured to receive a first address advertisement packet sent by the first Leaf device, and acquire the first loopback interface address and the second loopback interface address of the first Leaf device carried in the first address advertisement packet.
[0114] The receiving module 401 is further configured to receive a second address advertisement packet sent by the second Leaf device, and acquire the first loopback interface address and the second loopback interface address of the second Leaf device carried in the second address advertisement packet.
[0115] The receiving module 401 is further configured to establish a correspondence table of the first loopback interface address and the second loopback interface address of the first Leaf device and the first loopback interface address and the second loopback interface address of the second Leaf device. The first loopback interface address of the first Leaf device is different from the first loopback interface address of the second Leaf device, and the second loopback interface address of the first Leaf device is the same as the second loopback interface address of the second Leaf device. In a specific implementation, the first loopback interfaces of all Leaf devices in the same MLAG group are respectively configured with different IP addresses as the local loopback interface addresses of the MLAG member devices, and the second loopback interfaces of all Leaf devices in the same MLAG group are respectively configured with the same IP address as the public VTEP address of the MLAG group. The first Leaf device and the second Leaf device form a logical VTEP device.
[0116] The configuration module 402 is specifically configured to configure a policy routing for the tenant host according to the correspondence table, the matching rule of the policy routing is that the type of the packet is VXLAN encapsulation, the outer destination IP address of the packet is the second loopback interface address of the first Leaf device, the VNI corresponding to the tenant to which the tenant host belongs, and the inner destination IP address of the packet is the IP address of the tenant host, and the next hop of the policy routing is directed to the first loopback interface address of the second Leaf device.
[0117] The packet forwarding device provided by the embodiment of the application can quickly switch the traffic with the IP address of the tenant host to the non-fault Leaf device belonging to the same MLAG group as the Leaf device after the Leaf device of the MLAG multi-homing tenant host appears connectivity failure, avoids the traffic bypassing through the Peer-link, and avoids the problem of packet loss caused by insufficient bandwidth of the Peer-link after the multi-homing traffic is switched.
[0118] The embodiment of the present application provides a message forwarding device, which is applied to a first Leaf device, the first Leaf device is in communication connection with a Spine device, the Spine device is also in communication connection with a second Leaf device, the first Leaf device and the second Leaf device form an MLAG group, as shown in Figure 5 The device 50 comprises:
[0119] The detection module 501 is configured to detect the connectivity of a tenant host in communication connection with the Leaf device.
[0120] The sending module 502 is configured to encapsulate the IP address of the tenant host and route unreachable indication information into a state advertisement message and send the state advertisement message to the Spine device when detecting that the connectivity of the tenant host in communication connection with the Leaf device fails.
[0121] In a possible implementation, the state advertisement message is a VXLAN encapsulation, and the sending module 502 is specifically configured to: if the inner message of the state advertisement message is an ARP request message, encapsulate the IP address of the tenant host into an IPAddress of Sender field of the ARP request message, encapsulate the route unreachable indication information into an OP field of the ARP request message; encapsulate a first loopback interface address of the Leaf device into an outer source IP address of the state advertisement message, encapsulate a loopback interface address of the Spine device into an outer destination IP address of the state advertisement message, and send the state advertisement message to the Spine device.
[0122] The sending module 502 is specifically configured to: if the inner message of the state advertisement message is an ICMPv6 neighbor request message, encapsulate the IP address of the tenant host and the route unreachable indication information into an Options field of the ICMPv6 neighbor request message; encapsulate the first loopback interface address of the Leaf device into an outer source IP address of the state advertisement message, encapsulate the loopback interface address of the Spine device into an outer destination IP address of the state advertisement message, and send the state advertisement message to the Spine device.
[0123] The sending module 502 is specifically configured to: if the inner message of the state advertisement message is an ICMPv6 neighbor request message, encapsulate the IP address of the tenant host and the route unreachable indication information into an Options field of the ICMPv6 neighbor request message; encapsulate the first loopback interface address of the Leaf device into an outer source IP address of the state advertisement message, encapsulate the loopback interface address of the Spine device into an outer destination IP address of the state advertisement message, and send the state advertisement message to the Spine device.
[0124] The sending module 502 is also configured to encapsulate the first loopback interface address and the second loopback interface address of the Leaf device in an address advertisement message and send the address advertisement message to the Spine device.
[0125] In a possible implementation, the address announcement message is a VXLAN encapsulation, the sending module 502 is specifically further configured to, if the inner message of the address announcement message is an ARP request message, encapsulate the second loopback interface address of the Leaf device into an IP Address of Sender field of the ARP request message; encapsulate the first loopback interface address of the Leaf device into an outer source IP address of the address announcement message, encapsulate the loopback interface address of the Spine device into an outer destination IP address of the address announcement message, and send the address announcement message to the Spine device.
[0126] The sending module 502 is specifically further configured to, if the inner message of the address announcement message is an ICMPv6 neighbor request message, encapsulate the second loopback interface address of the Leaf device into an Options field of the ICMPv6 neighbor request message; encapsulate the first loopback interface address of the Leaf device into an outer source IP address of the address announcement message, encapsulate the loopback interface address of the Spine device into an outer destination IP address of the address announcement message; and send the address announcement message to the Spine device.
[0127] The packet forwarding device provided by the embodiment of the present application can actively send a state notification message to inform the Spine device when the Leaf device detects that connectivity failure occurs between the Leaf device and the tenant host, so that the Spine device can quickly and directly perceive the connectivity failure between the Leaf device and the tenant host, and the fault detection and response time is greatly shortened.
[0128] The packet forwarding system provided by the embodiment of the present application, as shown in Figure 6 The system includes a Spine device, a first Leaf device, a second Leaf device and a server, the Spine device is in communication connection with the first Leaf device and the second Leaf device, and the first Leaf device and the second Leaf device form an MLAG group. The first Leaf device and the second Leaf device form a logical VTEP device. The server is deployed with a tenant host, and the tenant host can be a physical server, or the tenant host can be a virtual machine created by a tenant in the server. The server is dual-homed to the first Leaf device and the second Leaf device. The Spine device performs the packet forwarding method applied to the Spine device as described in each of the above embodiments, and the first Leaf device or the second Leaf device performs the packet forwarding method applied to the Leaf device as described in each of the above embodiments. For specific implementation, refer to each of the above embodiments, which will not be described here.
[0129] The packet forwarding system provided by the embodiment of the present application can make the Spine device quickly and directly perceive the connectivity failure between the Leaf device and the tenant host, greatly shortening the fault detection and response time. Meanwhile, by configuring a policy route in the Spine device, it is ensured that the traffic from the Spine device to the tenant host no longer detours the Peer-Link link after the single-point link failure between the Leaf device in the MLAG group and the accessed tenant host, thereby avoiding the service packet loss problem caused by the bandwidth bottleneck of the Peer-Link link.
[0130] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to realize the packet forwarding method disclosed by the above embodiments. The computer readable storage medium can be an electronic storage such as a flash memory, an EEPROM (Electric Erasable Programmable Read-Only Memory), an EPROM (Erasable Programmable Read-Only Memory), a RAM (Random Access Memory), a ROM (Read Only Memory), a magnetic disc or an optical disc, and the like, which can store program codes. Alternatively, the computer readable storage medium includes a non-transitory computer readable medium. The computer readable storage medium has a storage space for storing program codes for executing any method steps in the above method. The program codes can be read from or written into one or more computer program products. The program codes can be compressed in a suitable form.
[0131] The embodiment of the present application further provides a computer program product, which is executed by a processor to realize the packet forwarding method disclosed by the above embodiments.
[0132] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A message forwarding method, characterized in that, Applied to a Spine device, the Spine device is communicatively connected to a first Leaf device and a second Leaf device, the first Leaf device and the second Leaf device forming a cross-device link aggregation group (MLAG). The method includes: The system receives a status announcement message carrying route unreachable indication information sent by the first Leaf device, obtains the IP address of the tenant host in the status announcement message, and configures policy routing for the tenant host based on the IP address of the tenant host; the policy routing is used to indicate that data packets whose destination IP address is the IP address of the tenant host are forwarded through the second Leaf device. Upon receiving a data packet whose destination IP address is the IP address of the tenant host, the data packet is forwarded through the second Leaf device according to the policy routing.
2. The message forwarding method according to claim 1, characterized in that, Before the step of configuring policy routing for the tenant host based on the tenant host's IP address, the method further includes: Receive the first address announcement message sent by the first Leaf device, and obtain the first loopback interface address and the second loopback interface address of the first Leaf device carried in the first address announcement message; Receive the second address announcement message sent by the second Leaf device, and obtain the first loopback interface address and the second loopback interface address of the second Leaf device carried in the second address announcement message; Establish a correspondence table between the first loopback interface address and the second loopback interface address of the first Leaf device and the first loopback interface address and the second loopback interface address of the second Leaf device; The first loopback interface address of the first Leaf device is different from that of the second Leaf device, while the second loopback interface address of the first Leaf device is the same as that of the second Leaf device.
3. The message forwarding method according to claim 2, characterized in that, The step of configuring policy routing for the tenant host based on the tenant host's IP address includes: Configure policy routing for the tenant host according to the corresponding relationship table. The matching rule of the policy routing is to match the packet type as VXLAN encapsulation, the outer destination IP address of the packet as the second loopback interface address of the first Leaf device, the VNI corresponding to the tenant to which the tenant host belongs, and the inner destination IP address of the packet as the IP address of the tenant host. The next hop of the policy routing points to the first loopback interface address of the second Leaf device.
4. The message forwarding method according to claim 1, characterized in that, The method further includes: The system receives a status announcement message carrying route reachability indication information sent by the first Leaf device, and deletes the policy route based on the IP address of the tenant host in the status announcement message.
5. A message forwarding method, characterized in that, The method is applied to a first Leaf device, which is communicatively connected to a Spine device, and the Spine device is also communicatively connected to a second Leaf device. The first Leaf device and the second Leaf device form a cross-device link aggregation group (MLAG). The method includes: Detect the connectivity of tenant hosts that are communicatively connected to this Leaf device; When a connectivity failure is detected in a tenant host that is communicating with this Leaf device, the IP address of the tenant host and the route unreachable indication information are encapsulated in a status announcement message and sent to the Spine device.
6. The message forwarding method according to claim 5, characterized in that, The status announcement message is VXLAN encapsulated. The step of encapsulating the tenant host's IP address and route unreachable information into a status announcement message and sending it to the Spine device includes: If the inner packet of the status announcement message is an ARP request message, then the IP address of the tenant host is encapsulated in the sender IP address field of the ARP request message, and the route unreachable indication information is encapsulated in the operation type field of the ARP request message; the first loopback interface address of this Leaf device is encapsulated in the outer source IP address of the status announcement message, the loopback interface address of the Spine device is encapsulated in the outer destination IP address of the status announcement message, and the status announcement message is sent to the Spine device; or, If the inner message of the status announcement message is an ICMPv6 neighbor request message, then the IP address of the tenant host and the route unreachable indication information are encapsulated into the option field of the ICMPv6 neighbor request message; the first loopback interface address of this Leaf device is encapsulated into the outer source IP address of the status announcement message, the loopback interface address of the Spine device is encapsulated into the outer destination IP address of the status announcement message, and the status announcement message is sent to the Spine device.
7. The message forwarding method according to claim 5 or 6, characterized in that, The method further includes: The first loopback interface address and the second loopback interface address of this Leaf device are encapsulated in an address advertisement message and sent to the Spine device.
8. The message forwarding method according to claim 7, characterized in that, The address advertisement message is VXLAN encapsulated. The step of encapsulating the first loopback interface address and the second loopback interface address of this Leaf device in the address advertisement message and sending them to the Spine device includes: If the inner message of the address advertisement message is an ARP request message, then the second loopback interface address of this Leaf device is encapsulated into the sender IP address field of the ARP request message; the first loopback interface address of this Leaf device is encapsulated into the outer source IP address of the address advertisement message; the loopback interface address of the Spine device is encapsulated into the outer destination IP address of the address advertisement message; and the address advertisement message is sent to the Spine device. If the inner message of the address advertisement message is an ICMPv6 neighbor request message, then the second loopback interface address of this Leaf device is encapsulated into the option field of the ICMPv6 neighbor request message; the first loopback interface address of this Leaf device is encapsulated into the outer source IP address of the address advertisement message; the loopback interface address of the Spine device is encapsulated into the outer destination IP address of the address advertisement message; and the address advertisement message is sent to the Spine device.
9. A message forwarding device, characterized in that, Applied to a Spine device, the Spine device is communicatively connected to a first Leaf device and a second Leaf device, the first Leaf device and the second Leaf device forming a cross-device link aggregation group (MLAG). The device includes: The receiving module is used to receive the status announcement message carrying route unreachable indication information sent by the first Leaf device; The configuration module is used to obtain the IP address of the tenant host in the status notification message, and configure policy routing for the tenant host based on the IP address of the tenant host; the policy routing is used to indicate that data packets whose destination IP address is the IP address of the tenant host are forwarded through the second Leaf device; The receiving module is also configured to receive data packets whose destination IP address is the IP address of the tenant host; The sending module is used to forward the data packet through the second Leaf device according to the policy.
10. A message forwarding device, characterized in that, An application is made to a first Leaf device, which is communicatively connected to a Spine device, and the Spine device is also communicatively connected to a second Leaf device. The first Leaf device and the second Leaf device form a cross-device link aggregation group (MLAG). The device includes: The detection module is used to detect the connectivity of tenant hosts that are connected to this Leaf device. The sending module is used to encapsulate the IP address of the tenant host and the route unreachable indication information into a status announcement message and send it to the Spine device when a connectivity failure is detected in the tenant host that is communicating with this Leaf device.
11. A message forwarding system, characterized in that, The system includes at least a Spine device, a first Leaf device, a second Leaf device, and a server. The Spine device is communicatively connected to the first Leaf device and the second Leaf device. The first Leaf device and the second Leaf device form a cross-device link aggregation group (MLAG). The server is equipped with tenant hosts and is dual-homed to both the first Leaf device and the second Leaf device. The Spine device executes the packet forwarding method as described in any one of claims 1-4, and the first Leaf device or the second Leaf device executes the packet forwarding method as described in any one of claims 5-8.