Method and system for segmented multi-station SPB network
By using the IS-IS Level 2 interface and Level 1 internal connections of the segmented SPB network, combined with site IDs and name identifiers, SMN is instantiated, which solves the scalability limitations of the flat SPB network and enables efficient multi-site network management and fast convergence.
Patent Information
- Application Number
- CN202380099888.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-29
- Publication Date
- 2026-01-30
AI Technical Summary
Existing flat SPB networks have scalability limitations in terms of the number of nodes and resource utilization, resulting in network deployment approaching its maximum limit. Furthermore, the hierarchical configuration cannot provide visibility and management simplification for a single network, leading to suboptimal network operation and management.
A segmented SPB network is adopted, which connects site boundary nodes through IS-IS Level 2 interface to form an inter-site network, and connects intra-site nodes within IS-IS Level 1 interface. It uses a unique site ID and name for identification, and instantiates site meta nodes (SMN) to manage network topology and resource allocation.
It implements a highly scalable SPB network, supporting the deployment of tens of thousands of nodes, providing simplified configuration and management of network resources, and ensuring rapid convergence and efficient inter-site connectivity.
Smart Images

Figure CN121444408A_ABST
Abstract
Description
Technical Field
[0001] This technology relates to networks, and more specifically, to a method and system for a segmented SPB network, the segmented SPB network comprising at least two sites and an IS-IS network topology for SPB. Background Technology
[0002] The currently deployed Shortest Path Bridging (SPB) network operates with a flat topology, also known as a Level 1 network. Bridging nodes form Level 1 adjacencies, thus constructing the SPB network. While this simplifies configuration and maintenance, it also imposes limitations on network scalability. These limitations manifest in both the control plane and the data plane.
[0003] In the control plane, IEEE 802.1aq SPB implements multipath routing by using IS-IS as defined in ISO / IEC 10589 as a routing protocol for transmitting information by determining the best path (i.e., shortest path) for data packets throughout the packet-switched network. The limitations of the control plane stem from the resources and computing power required by the IS-IS protocol for SPB in establishing and actively managing the reachability of all nodes in the network.
[0004] The limitation of the data plane lies in the number of service tunnels that can be established between nodes in the network. The total number of nodes supported by a flat SPB network is typically limited to between 500 and 1000 nodes, depending on the CPUs and switching ASICs associated with each node in the SPB network. Due to its versatility and ease of deployment, SPB networks have been rapidly adopted, and many of these deployments are approaching their maximum scalability limits.
[0005] To address these limitations, networks are typically configured as segmented networks. A separate low-level interface is established between these segmented SPB networks to provide textured interconnection. The interconnecting network can be an additional Layer 2 or Layer 3 overlay network, requiring additional configuration and management of the core network. This layering often fails to provide the visibility and management simplicity of a single network, hinders rapid SPB network convergence, and leads to header bloat due to the layering of the protocol stack over the payload. Furthermore, the transport network is independent of the edge SPB networks and their resources. Ultimately, this results in a suboptimal network configuration in both operation and management. This network configuration is also not feasible for deployments requiring a highly scalable native SPB solution.
[0006] In summary, this technology aims to provide a segmented SPB network and a method for constructing such a network. The segmented SPB network includes at least two sites, each site including at least one site boundary node. The site boundary nodes are connected via an IS-IS Level 2 interface for SPB, thereby forming an inter-site network operating at IS-IS Level 2 for SPB. Simultaneously, within each site, each site boundary node is connected to other nodes via an IS-IS Level 1 interface for SPB, thereby forming an intra-site network operating at IS-IS Level 1 for SPB.
[0007] The topics discussed in the Background section should not be assumed to be prior art simply because they are mentioned therein. Similarly, any problems mentioned in the Background section or related to its topics should not be assumed to be problems previously recognized in the prior art. The topics in the Background section merely represent different approaches. Summary of the Invention
[0008] The implementation of this technology is based on the developer's understanding of the shortcomings associated with existing technologies, particularly the limitations of building highly scalable and secure Service SPB networks. One aspect of this technology aims to eliminate these limitations by developing a segmented SPB network comprising at least two sites and an IS-IS network topology for SPB. Each of the at least two sites includes at least one Site Border Node (SBN) and at least one node, which can be an endpoint node or an intermediate node, connected to at least one SBN via an IS-IS Level 1 interface for SPB, thereby forming an intra-site network operating at IS-IS Level 1 for SPB, wherein each of the at least one SBN and at least one node is identified by a unique system ID; and all SBNs are connected via an IS-IS Level 2 interface for SPB, thereby forming an inter-site network operating at IS-IS Level 2 for SPB.
[0009] In one implementation of a segmented SPB network, each of at least two stations is associated with a unique station ID, which is assigned as a 3-byte area address field of the TLV of the control frame constructed and announced by all SBNs of each station on the IS-ISLevel 2 interface for SPB of the SBN.
[0010] In another implementation of the segmented SPB network, each of at least two stations is associated with a unique station name, which is assigned as a 32-byte system name field of the TLV of the control frames constructed and announced by all SBNs of each station on the IS-IS Level 2 interface for SPB of the SBN.
[0011] In another implementation of the segmented SPB network, a unique site ID is also assigned as a 3-byte area address field of the TLV of the control frame constructed and announced by all SBNs of each site on the IS-IS Level 1 interface for SPB of the SBN.
[0012] In another implementation of the segmented SPB network, a unique site ID is also assigned as a 3-byte area address field of the TLV of the control frame constructed and announced by all nodes of the network within each site on the node's IS-IS Level 1 interface for SPB.
[0013] In another implementation of the segmented SPB network, each SBN in a site that is a local site discovers all other SBNs in the segmented SPB network that are local sites and all SBNs in other sites that are remote sites, and maintains a list of all discovered SBNs and local or remote sites that include all discovered SBNs based on the site ID value obtained by parsing the area address field of the TLV of the received control frame.
[0014] In another implementation of a segmented SPB network, each SBN of a local site discovers other SBNs (as peer SBNs) included in the local site in the following manner: - Determine that the site ID value obtained by parsing the area address field of the TLV of the control frame received on the IS-IS Level 2 interface for SPB of each SBN is the same as the site ID value of the local site; and - The peer SBN is determined to be operating in IS-IS Level 1 for SPB by identifying a unique first system ID in the control frame received from the peer SBN on the peer SBN’s IS-IS Level 1 interface for SPB.
[0015] In another implementation of a segmented SPB network, each SBN of a local site discovers a remote site's SBN as a remote SBN by determining that the site ID value obtained by parsing the area address field of the TLV of the control frame received on the IS-IS Level 2 interface for SPB of each SBN is different from the site ID value of the local site.
[0016] In another implementation of the segmented SPB network, after establishing an adjacency relationship between at least two SBNs included in two different sites, a site meta node (SMN) is instantiated on each of the at least two SBNs, wherein the SMN is identified using a unique second system ID that is different from any of the first system IDs in the first system IDs, wherein the SMN hosts a representation of the segmented SPB network, the representation of which includes information related to all discovered SBNs and the local or remote site containing all discovered SBNs.
[0017] In another implementation of the segmented SPB network, the unique second system ID is a 6-byte value obtained by concatenating the 3-byte Organization Unique Identifier (OUI) and the site ID of the site in the SBN to which the SMN is instantiated.
[0018] In another implementation of the segmented SPB network, the SMN is instantiated in the Level 1 intranet of the local site, including activating the SMN Link State Packet (LSP). The local site includes the SBN to which the SMN is instantiated, wherein peer SBNs have the same cost as neighbors and have the maximum path weight supported by the network to ensure that the SMN functions as an endpoint node in the segmented SPB network.
[0019] In another implementation of the segmented SPB network, the instantiated SMN provides full-activity and failover modes for the connection between nodes at the local site and nodes at the remote site.
[0020] In another implementation of the segmented SPB network, one SBN is selected from the peer SBNs of the local site as the designated activator DA, wherein the DA performs the instantiation of the SMN and the activation and management of the SMN LSP.
[0021] In another implementation of segmented SPB networks, the DA is selected from the peer SBNs based on the SBN with the lowest unique first system ID.
[0022] In another implementation of a segmented SPB network, all peer SBNs of the local site perform SMN instantiation and activate and manage the SMN LSP.
[0023] In another implementation of a segmented SPB network, each SBN of a local site: - Mine LSP frames received from all SBNs in the inter-site network and maintain a list of ISID TLVs included in the LSP frames mined from the inter-site network; - Mine LSP frames received from nodes of local sites in the site's intranet and maintain a list of ISID TLVs included in the LSP frames mined from the intranet; - Maintain ownership of each SBN path from the SMN to the local site, where ownership is determined by ECT / BVLAN; and - The local site's ISID TLV is advertised to the Level 2 inter-site network via the LSP frame generated by the SBN.
[0024] In another implementation of a segmented SPB network, the local site's peer SBN discovers a subset of ISID TLVs shared between the local and remote sites.
[0025] In another implementation of a segmented SPB network, each SBN of a local site advertises a subset of the ISID TLV to the network within the site by encoding the LSP of the SMN instantiated on the SBN.
[0026] In another implementation of a segmented SPB network, the administrator enters policy rules on the peer SBN of the local site, the policy rules being designed to filter out at least one of the following: - The ISID TLV included in the LSP frame received from the inter-site network, and - The ISID TLV of the local site advertised to the inter-site network in the generated LSP frame.
[0027] In another implementation of the segmented SPB network, after establishing an IS-IS Level 1 adjacency relationship for SPB between an SBN and at least one node, a check is performed on the site ID, wherein an adjacency relationship is established only if the site ID values of each SBN in the SBN match the site ID values on all Level 1 paths (circuit) of at least one node.
[0028] In another implementation of the segmented SPB network, after verifying the site ID value obtained by parsing the area address field of the received control frame's TLV, a check is performed on the local site to ensure that the obtained site ID value is the same as the site ID value associated with the local site. If the obtained site ID value is different from the site ID value associated with the local site, any backdoors between the local site's node and the remote site's node are disabled.
[0029] On the other hand, various embodiments of this technology provide a computer-implemented method for constructing a segmented SPB network, the segmented SPB network including at least two sites and an IS-IS network topology for SPB, the method comprising: - Assign a unique site ID to each of at least two sites; and - Associate at least one site boundary node (SBN) with each of at least two sites; - Connect all SBNs in the segmented SPB network through the IS-IS Level 2 interface for SPB to form an inter-site network operating in IS-IS Level 2 for SPB. - Assign a unique site ID to each SBN associated with the site. The unique site ID is assigned as a 3-byte area address field of the TLV of the control frame constructed and advertised by each SBN on the IS-IS Level 2 interface for SPB of each SBN.
[0030] In one implementation, the method further includes: - Connect to at least one SBN and at least one node (the node being the endpoint node) via the IS-IS Level 1 interface for the SPB. ij ) or intermediate node (BCB 103) ik This forms an intrasite network operating at IS-IS Level 1 for SPB, wherein each of at least one SBN and at least one node is identified by a unique first system ID; and - Also assign a unique site ID to each SBN associated with the site of each SBN. The unique site ID is assigned as a 3-byte area address field of the TLV of the control frame built and advertised by each SBN on the IS-IS Level 1 interface for SPB of each SBN.
[0031] In another implementation, the method further includes assigning a unique site ID to each node, the unique site ID being assigned as a 3-byte area address field of the TLV of the control frame constructed and announced by each node on the IS-ISLevel 1 interface for SPB on each node.
[0032] In yet another implementation, the method further includes enabling each SBN in a site that is a local site to discover all other SBNs of the local site and all SBNs of other sites that are remote sites in the segmented SPB network, and maintaining a list of all discovered SBNs and a list of local or remote sites that include all discovered SBNs based on the site ID value obtained by parsing the area address field of the TLV of the received control frame.
[0033] In yet another implementation, the method further includes enabling each SBN of the local site to discover other SBNs included in the local site as peer SBNs in such a way as follows: - Determine that the site ID value obtained by parsing the area address field of the TLV of the control frame received on the IS-IS Level 2 interface for SPB of each SBN is the same as the site ID value of the local site; and - The peer SBN is determined to be operating in IS-IS Level 1 for SPB by identifying a unique first system ID in the control frame received from the peer SBN on the peer SBN’s IS-IS Level 1 interface for SPB.
[0034] In yet another embodiment, the method further includes enabling each SBN of a local site to discover a remote site's SBN as a remote SBN by determining that the site ID value obtained by parsing the area address field of the TLV of the control frame received on the IS-IS Level 2 interface for SPB of each SBN is different from the site ID value of the local site.
[0035] In another embodiment, the method further includes: after establishing an adjacency relationship between at least two SBNs included in two different sites, instantiating a site meta node (SMN) on each of the at least two SBNs, wherein the SMN is identified using a unique second system ID that is different from any of the first system IDs in the first system IDs, wherein the SMN hosts a representation of a segmented SPB network, the representation of which includes information relating to all discovered SBNs and local or remote sites containing all discovered SBNs.
[0036] In another embodiment, the method further includes obtaining a unique second system ID, which is a 6-byte value obtained by concatenating a 3-byte Organization Unique Identifier (OUI) with a site ID containing the site of the SBN to which the SMN is instantiated.
[0037] In another embodiment, the method further includes instantiating the SMN in the Level 1 site-internal network of a local site, including activating the SMN Link State Packet (LSP), wherein the local site includes the SBN to which the SMN is instantiated, wherein peer SBNs have the same cost as neighbors and have the maximum path weight supported by the network, to ensure that the SMN functions as an endpoint node in the segmented SPB network.
[0038] In yet another implementation, the method further includes enabling the instantiated SMN to provide full-activity and failover modes for connections between nodes at a local site and nodes at a remote site.
[0039] In yet another implementation, the method further includes selecting one SBN from the peer SBNs of the local site as the designated activator DA, wherein the DA performs the instantiation of the SMN and the activation and management of the SMN LSP.
[0040] In yet another embodiment, the method further includes selecting the DA from the peer SBNs based on the SBN with the lowest unique first system ID among the peer SBNs.
[0041] In yet another implementation, the method further includes instantiating the SMN and activating and managing the SMN LSP for all peer SBNs of the local site.
[0042] In yet another implementation, the method further includes causing each SBN of the local site to perform the following operations: - Mine LSP frames received from all SBNs in the inter-site network and maintain a list of ISID TLVs included in the LSP frames mined from the inter-site network; - Mine LSP frames received from nodes of local sites in the site's intranet and maintain a list of ISID TLVs included in the LSP frames mined from the intranet; - Maintain ownership of each SBN path from the SMN to the local site, where ownership is determined by ECT / BVLAN; and - The local site's ISIDTLV is advertised to the Level 2 inter-site network via the LSP frames generated by the SBN.
[0043] In yet another implementation, the method further includes enabling the local site's peer SBN to discover a subset of ISID TLVs shared between the local and remote sites.
[0044] In yet another implementation, the method further includes enabling each SBN of the local site to advertise a subset of ISID TLVs to the intranet by encoding the LSP of the SMN instantiated on the SBN.
[0045] In yet another implementation, the method further includes an administrator entering policy rules on the peering SBN of the local site, the policy rules being designed to filter out at least one of the following: - The ISID TLV included in the LSP frame received from the inter-site network, and - The ISID TLV of the local site advertised to the inter-site network in the generated LSP frame.
[0046] In yet another implementation, the method further includes performing a check on the site ID after establishing an IS-IS Level 1 adjacency relationship for the SPB between the SBN and at least one node, wherein the adjacency relationship is established only if the site ID values of each SBN in the SBN match the site ID values on all Level 1 paths of at least one node.
[0047] In another embodiment, the method further includes: after verifying the site ID value obtained by parsing the area address field of the received control frame's TLV, performing a check on the local site to confirm that the obtained site ID value is the same as the site ID value associated with the local site. If the obtained site ID value is different from the site ID value associated with the local site, then any backdoors between the local site's node and the remote site's node are disabled.
[0048] In another aspect, various embodiments of the present technology provide a computer-readable medium comprising computer-readable instructions that, when executed by a system, cause the system to perform various embodiments of the methods described above.
[0049] In the context of this specification, unless otherwise expressly stated, computing system may refer to, but is not limited to, “electronic device,” “operating system,” “system,” “computer-based system,” “controller unit,” “monitoring device,” “control device,” and / or any combination thereof suitable for the relevant task at hand.
[0050] In the context of this specification, the term "FPGA" is intended to include field-programmable gate array computing systems commercially available at the time of filing of this patent application, such as the Xilinx VU9P or Intel Stratix V, and any subsequently available equivalent technologies, regardless of their names, in software-programmed computing system hardware.
[0051] In the context of this specification, the term "processor" is intended to include a single dedicated processor, a single shared processor, or multiple separate processors, some of which may be shared. In some aspects of this technology, a processor may be, for example, a general-purpose processor, such as a central processing unit (CPU), a processor dedicated to a specific purpose, or a processor implemented in an FPGA. Other conventional and / or custom hardware may also be included.
[0052] In the context of this specification, unless otherwise expressly stated, the term "memory" is intended to include random access memory systems commercially available at the time of filing this patent application, as well as any subsequently available equivalent technologies, regardless of their names, included in the computing system medium used to store digital information. An example of such memory may be a four-times data rate (QDR) static random access memory (SRAM).
[0053] In the context of this specification, the functional steps shown in the accompanying drawings can be provided using dedicated hardware and hardware capable of executing software associated with appropriate software.
[0054] Within the context of this specification, “a” computer-readable medium and “the” computer-readable medium should not be construed as the same computer-readable medium. Rather, and where appropriate, “a” computer-readable medium and “the” computer-readable medium may also be construed as a first computer-readable medium and a second computer-readable medium.
[0055] In the context of this specification, unless otherwise expressly stated, the words “first,” “second,” “third,” etc., are used as adjectives only to distinguish the nouns they modify, and not to describe any particular relationship between those nouns.
[0056] The implementations of this technology each have at least one of the aforementioned objectives and / or aspects, but not necessarily all of them. It should be understood that some aspects of this technology that have been obtained from attempting to achieve the aforementioned objectives may not satisfy those objectives and / or may satisfy other objectives not specifically listed herein.
[0057] Additional and / or alternative features, aspects and advantages of the implementation of this technology will become apparent from the following description, the accompanying drawings and the appended claims. Attached Figure Description
[0058] To better understand this technology, as well as other aspects and additional features, reference will be made to the following description used in conjunction with the accompanying drawings, wherein: Figure 1 An exemplary network architecture according to this technology is shown; Figure 2 useFigure 1 The exemplary network architecture illustrates the configuration and site discovery process of SBN; Figure 3 Provided with Figure 1 The logical representation of the exemplary network architecture includes metasites and site metanodes; Figure 4 The IS-IS LEVEL 1 network for SPB within the site is described, as well as its connection with... Figure 1 The site meta node LSP associated with a specific site in the exemplary network architecture is activated; Figure 5 express Figure 1 An example of an inter-site forwarding data path between two sites in a network; Figure 6 The steps of a computer-implemented method according to one aspect of the present technology are described; Figure 7 The method steps for a computer implementation according to a second aspect of the present technology are described; Figure 8 Examples of computing systems that can be used to perform methods and process steps according to this technology.
[0059] It should be noted that, unless otherwise expressly stated herein, the accompanying drawings are not drawn to scale. Furthermore, the same elements share the same reference numerals from one figure to the next. Detailed Implementation
[0060] The examples and conditional language listed herein are primarily intended to help the reader understand the principles of this technology, rather than limiting its scope to these specific examples and conditions. It should be understood that those skilled in the art can devise various arrangements, although these arrangements are not explicitly described or shown herein, but still embody the principles of this technology and are included within its spirit and scope.
[0061] Furthermore, to aid understanding, the following description may depict a relatively simplified implementation of this technology. Those skilled in the art will understand that various implementations of this technology may involve greater complexity.
[0062] In some cases, useful examples that are considered modifications to the present technology may also be illustrated. This is done merely to aid understanding and, again, is not intended to limit the scope of the present technology or to define its boundaries. These modifications are not an exhaustive list, and other modifications can be made by those skilled in the art, while such other modifications remain within the scope of the present technology. Furthermore, the absence of examples illustrating modifications should not be construed as impossibility of modification and / or as the only way to implement that element of the present technology.
[0063] Furthermore, all statements herein that illustrate the principles, aspects, and implementations of the present technology, and specific examples thereof, are intended to cover their structural and functional equivalents, whether they are currently known or will be developed in the future. Therefore, for example, those skilled in the art will understand that any block diagram herein represents a conceptual view of an illustrative circuit embodying the principles of the present technology. Similarly, it should be understood that any flowchart, diagram, state transition diagram, pseudocode, etc., represents various processes that can be substantially represented in a computer-readable medium and executed by a computer or processor, whether or not such a computer or processor is explicitly shown.
[0064] A software module, or simply a module implied as software, may be represented herein as any combination of flowchart elements or other elements indicating the execution of process steps and / or textual descriptions. Such a module may be executed by hardware, whether explicitly or implicitly indicated. Furthermore, it should be understood that a module may include (e.g., but not limited to) computer program logic, computer program instructions, software, protocol stacks, firmware, hardware circuitry, or combinations thereof, capable of providing the required functionality.
[0065] With this foundational knowledge in mind, we will now consider some non-restrictive examples to illustrate various implementations of different aspects of this technology.
[0066] Figure 1 An exemplary network architecture of this technology is illustrated. Such an architecture includes i sites 102 i (The image only shows four stations as examples). 102 per station. i It can include: - j (j>= 0) backbone edge bridges (BEB) 104 ij (As an example, 102 are shown for each site) i (j=1 and j=2); and - k (k>= 0) backbone core bridges (BCB) 103 ik (As an example, 102 are shown for each site) i (where k=0 or k=1). And 102 for each site i You can connect to Level 2 SPB network 101 as follows: - l Site boundary nodes (SBN) 105 il (As an example, 102 are shown for each site) i (where l=1 or l=2).
[0067] 105 per SBN il All can be connected to BCB 103 via Level 1 interface. ik And BEB 104ij It connects to the Level 2 SPB network 101 via the Level 2 interface.
[0068] According to this technology, a hierarchical SPB network, MS-SPB network 100, has been implemented, operating in a multi-site (MS) topology and providing ultra-high scalability and secure inter-site access. MS-SPB network 100 is deployed as a segmented SPB network, with segments comprising at least two local sites 102 connected via a core Level 2 SPB network 101. i This technology is applicable to MS-SPB networks 100 spanning multiple sites 102. i It provides a simplified model for the configuration, operation, and maintenance of network devices and network resources.
[0069] Station 102 i The nodes within and SBN 105 il Together they operate under IS-IS Level 1 for SPB, thus establishing Level 1 adjacency relationships. Connecting site 102 i The nodes then operate under IS-IS Level 2 for SPB. Therefore, this technology can be viewed as an evolution of the single-layer / flat IS-IS Level 1 for SPB as specified in the IEEE Std 802.1Q-2018 standard.
[0070] 102 per site i Each site is identified by a unique site ID, and optionally by a site name. "Unique" here means that each site has a different site ID. Optionally, the site ID can be based on geographic location, such as the geographic location of a group of nodes. Each site has 102... i All of them possess the characteristics of the specified gateway node as follows: SBN 105 il Used to facilitate communication between sites. SBN 105 il Interconnection is achieved using dedicated pathways for Level 2 operations to form Level 2 adjacency relationships within the Layer 2 SPB network 101. Inter-site connectivity is provided by the Level 2 SPB network 101. Since the entire deployment is unified under a single SPB network, it will be apparent to those skilled in the art that network service resources such as Instance Service Identifiers (ISIDs) and Virtual Private Network (VPN) routes can be shared across sites 102. i This enables seamless Tier 2 and Tier 3 accessibility across multiple sites.
[0071] Resource utilization in the control and data planes of the SPB protocol at site 102 operating as a Level 1 network. iAssignment is made between Level 2 SPB network 101 and site 102 for a given i. i All nodes can only see other local nodes within that site (BEB 104) ij and BCB 103 ik ) and gateway node (SBN 105) il Link-state packets (LSPs) are distributed only to site-local nodes. Similarly, Level 2 SPB networks 101 can only see packets across all sites 102. i SBN 105 il LSP distribution is also limited to SBN 105. il All connections between sites are via SBN 105. il accomplish.
[0072] Resource segmentation provides greater scalability for both the control plane and the data plane. When site 102... i When the available network capacity is exceeded, or when site 102 needs to be modified... i When partitioning to achieve segmentation, site 102 i It can be split to form new sites, thereby accommodating additional network resources. The deployment of a green field (newly built) SPB network (i.e., a less constrained "fresh" network, rather than migrating an existing "brown field" network) can be designed based on isolating bridging node groups into different sites, taking into account their geographical locations. Using this technology, the deployment of MS-SPB network 100 only requires SBN 105. il Coordination will be carried out within SBN 105. This means that all site-specific configurations (site ID and, depending on the case, site name) and inter-site policy assignments can be coordinated solely within SBN 105. il Defined in the standard. This simplification of deployment also makes it easy to convert any existing brownfield SPB network into a segmented MS-SPB network by deploying SBN105. il This allows segmented networks to be interconnected without requiring any changes to the local nodes of the sites.
[0073] Service scalability / connectivity can be selectively restricted to a single site or automatically distributed across sites or subsets of sites in a segmented network. For this purpose, a policy manager (in SBN 105)... ilKnown applications running on this network can enforce security policies and / or boundary policies on segmented network resources. For example, network administrators can configure various rules in the policy manager to control the allocation of network resources across inter-site and intra-site networks, thereby flexibly managing which resources within a site can be shared with other sites on the network. In one aspect of this technology, all peer SBNs of a given site are configured with the same security policies and / or boundary policies.
[0074] This segmentation of the network can support network deployments several orders of magnitude larger than the current limit of 500 to 1000 nodes. The MS-SPB network 100 can be scaled up to support tens of thousands of nodes deployed at multiple sites on a hierarchical SPB network.
[0075] Using IS-IS Level 2 adjacencies for SPB in SBN 105 il And site 102 i Discovery of MS-SPB network 100 configuration Figure 2 Figure 1 use Figure 2 An exemplary network architecture is shown for SBN 105. il The configuration and site discovery process. MS-SPB network 100 is configured with isolated site 102. i 102 per site i Each site is assigned a unique site ID and (depending on the situation) a site name. For example, such as Figure 2 As shown, sites 1021 to 1024 were assigned the following: - Site IDs: 1.1.1, 2.2.2, 3.3.3, 4.4.4; - Site names: Loc1, Loc2, Loc3, Loc4.
[0076] The site name can optionally be a string used to highlight the site's geographic location.
[0077] All SBNs (called "peer SBNs") of the local site are configured with the same unique site ID and (depending on the situation) site name. For example, for site 1021, SBN 105 11 and 105 12All are configured with a site ID of 1.1.1 and a site name of Loc1. The site ID can be set to a 3-byte value and converted to a local site's area ID. This area ID can be assigned to all sites in the segmented SPB network as the area field of the TLV of the control frames for all SBN construction and announcements for a given site, either on the IS-IS Level 2 interface for SPB of each site or, optionally, on the IS-IS Level 1 interface for SPB of each site. It will be apparent to those skilled in the art that the ability to configure a site ID / area ID (in the sense of IS-IS for SPB) for a given site only in the peer SBN will avoid updating all local nodes (potentially hundreds of nodes) of the site with a unique area ID. Typically, nodes in a Level 1 network (a network within a site) may not be configured with a unique area ID for use in IS-IS operations for SPB. They may be optionally assigned a default area ID of 0.0.0.
[0078] 102 per site i One, two or more SBN 105 can be configured. il Peer-to-peer SBN operates in full-activity mode, providing load balancing and redundancy for local nodes accessing resources on remote sites. Specific operational details are as follows.
[0079] All SBNs 105 in MS-SPB network 100 il All are connected via a path designed to operate at IS-IS Level 2 for SPB. In SBN 105 il This communication can function once the site ID of its peer site is configured. For example, in SBN 105 11 and 105 12 The site ID 1.1.1 configured in the configuration will be used as the area ID for the IS-IS Level 2 of the SPB when establishing Level 2 adjacency with other SBNs in the Level 2 SPB network 101.
[0080] Level 2 SPB network 101, SBN 105 il Communication between them can employ a ring or mesh topology. Optionally, SBN 105 il The fully meshed Level 2 network can provide higher link utilization and accelerate the convergence speed of the Level 2 SPB network 101. Figure 2 Reference numeral 201 in the figure illustrates SBN 105 in a fully meshed Level 2 network. 11Interconnection with all other SBNs in Level 2 SPB network 101. It will be apparent to those skilled in the art that although such interconnection is not shown in the figure, it will be present in SBN 105. 12 105 21 105 22 105 31 105 32 105 41 and 105 42 Each of them and Peer SBN and remote SBN Level 2 adjacency procedures All other SBNs shown exist.
[0081] For SBN 105 running in Level 2 SPB network 101 il The IS-IS Level 2 pathway for SPB is used to compute the path tree and equivalence tree (ECT). This ECT is compared with site 102 operating at IS-IS Level 1 for SPB. i The ECT is different.
[0082] Alternatively, each SBN can use a separate backbone VLAN (BVLAN) to run site 102. i And Level 2SPB network 101. This can especially solve site 102. i This also applies to cases where there is no matching BVLAN or no identical ECT set. Furthermore, this also facilitates the consolidation of heterogeneous sites (see below) into the MS-SPB network 100.
[0083] To achieve connectivity between sites, each local site 102 i Only a common BVLAN and ECT operation are required in the Level 2 SPB network 101 between sites. A given ISID tunnel can be established at site 102. i It operates in different BVLANs within the Level 2 SPB network 101 between networks and sites, while also providing local site 102. i The connectivity between them.
[0084] 105 per SBN il The IS-IS protocol used for SPB will calculate and maintain the shortest path first (SPF) path to other SBNs discovered in the Level 2 adjacency relationships of the Level 2 SPB network 101. This SPF path is calculated independently of the SPF paths that may occur in the Level 1 SPB network.
[0085] Figure 2 In the following text, SBN 105 ilAlso known as local (own) SBN and remote (belonging to a remote site) SBN. SBN105 il Each SBN in the network can form Level 2 adjacency relationships with other peer SBN nodes and remote SBN nodes, and the topology of reachability for all SBNs in the IS-IS Level 2 network used for SPB can be calculated. Therefore, ECT paths in the data plane can be computed and programmed to achieve SBN 105. il Reachability between nodes. The segmentation of the MS-SPB network 100 and the limited number of nodes (SBNs) participating in the SPB protocol in each segment enable the network to converge quickly.
[0086] Because each SBN 105 il All of them can determine the site IDs configured in MS-SPB network 100 by resolving the area address of Level 2 LSP Protocol Data Unit (PDU) messages received from the remote SBN, thus it can know: - Remote site 102 available in MS-SPB network 100 i The number of such sites and the site ID associated with each of them; and - A specific remote SBN associated with each remote site.
[0087] After establishing Level 2 adjacency relationships and updating the LSP, SBN 105 il This will establish inter-site connectivity between them.
[0088] Optionally, the link can be configured as a Level 1 / Level 2 interface between peer SBNs, for example... Peer SBN discovery procedures SBN105 11 and 105 12 Link 202 between them. Such a link can operate simultaneously with both IS-IS Level 1 and Level 2 for SPB to ensure that in SBN 105 11 and 105 12 If all Level 2 links in any SBN fail, the inter-site connection will not be interrupted: therefore, the inter-site connection can become available in Level 1 and Level 2 of the tunnel connection via the peer link (i.e., link 202).
[0089] After establishing the adjacency relationships between Level 1 and Level 2, each SBN 105 il It can also be found that the given site 102 i The equivalent SBN 105 il .
[0090] Metasite logical representation 105 per SBN il It can also identify, discover, and list sites 102 that are also related to the local site. i All associated specific peer SBNs: When an SBN receives an IS-IS LSP PDU for SPB on a Level 2 path (circuit, link, line), it can verify whether the area ID in the LSP frame matches the locally configured site ID. Optionally, each SBN 105 il It can also identify any peer SBNs operating in islanded mode (i.e., connected to Level 2 tiers but not connected to Level 1 tiers).
[0091] 105 per SBN il It can also compare the IS-IS LSP PDUs received for SPB on its Level 1 path with the list of discovered SBNs, and maintain the active list of peer SBNs for the local site based on monitoring of PDU frames on Level 1 and Level 2 LSPs. This process forms the basis for the instantiation of the site meta node as described below.
[0092] Metasite The coordination process for Layer 2 and Layer 3 communication between stations in the MS-SPB network 100 can be accomplished by establishing a logical representation of network resources. This logical representation can include the following logical objects: - Site metanode A metasite can be considered a transport site for this technology. It captures information about all sites (local and remote sites) and their associated SBNs, as well as the resources and constraints enforced on the local site by the local SBN through security policies. This includes site information such as site ID and (depending on) site name, the SBN associated with the site, and the Layer 2 and Layer 3 VPN resources advertised by these SBNs. Transport services coordinated on the local SBN include: IS-IS Level 1 tunnels for SPB to the local BEB / BCB, and IS-IS Level 2 tunnels for SPB to the remote SBN.
[0093] - Metasite metanodeThe site metanode is used to coordinate metasite functions. In one aspect of this technology, the site metanode includes a summary representation of all sites and their associated nodes that adopt the representation design of all external sites, as well as a summary representation of the neighbor list of the local site's peer SBNs (both itself and those already discovered), which is maintained according to the peer SBN discovery process described above. The site metanode is activated on all SBNs of each site; that is, a site metanode is instantiated on each SBN to represent all discovered sites in the network, and is only visible locally, i.e., visible within the site, but it supports all inter-site communication from the local BEB.
[0094] - Site metanode activation The logical representation of a supernode provides access to all site metanodes in the MS-SPB network 100. It exists only as a topology graph.
[0095] The process of instantiating and maintaining the connection between the local site and the remote site using the above logical representation can be completed in the following three steps: - Metasite Discovery: Discover and maintain site-specific resources (ISID-based Layer 2 and Layer 3 VPNs) from each site in the MS-SPB network 100. - Metasite Coordination: Identifies common / permitted resources between local and remote sites to facilitate inter-site forwarding; and - Figure 3 Instantiate and maintain site meta nodes and their LSPs in IS-IS Level 1 for SPB, including the neighbor list (peer SBN) of the site meta node LSPs; coordinate data plane Level 1 and Level 2 tunnels.
[0096] Go to List of events for instantiation and maintenance of site metanodes As part of logical representation 300, the following is represented: - Metasite 304 i For each site i, as remote and local site information 303 im The set of (m=1 to the maximum value of i in MS-SPB network 100), especially in its relationship with SBN 105 il When related to site-specific resources, it reaches the visible range of each site i in the MS-SPB network 100; and - For each site i, the site meta node 302 i .
[0097] As mentioned above, the site ID and SBN 105 il The configuration of IS-IS Level 2 adjacency relationships for SPB may trigger the startup and operation of this logic representation 300.
[0098] Designated activator (DA) In each local SBN 105 il The site meta node is instantiated in the upper part of the city 302 i For SBN 105 il To initiate instantiation, at least one IS-IS Level 2 adjacency relationship for SPB must be established with the remote SBN. Furthermore, the aforementioned peer SBN and remote SBN Level 2 adjacency discovery process populates the site meta node with remote and peer site information.
[0099] Site Meta Node 302 i Through the IS-IS Level 1 network (site-specific network, consisting of 102) used for SPB i The site meta node LSP generated in the representation is instantiated in the Level 1 network of local site i. Site meta node 302 i Activation is performed using a network-unique system ID conforming to the IEEE 802.1Q-2018 standard (IS-IS Link-State Protocol for SPB). Here, "unique" means that the site metanode system ID is different from all other system IDs in the network (SBN system IDs, other nodes, etc.). The site metanode system ID can be a combination of a 3-byte Organization Unique Identifier (OUI) and a 3-byte site ID / area ID. This generates a network-unique 6-byte system ID to represent the site metanode to the local site. The OUI and site ID are combined as part of the system ID, making the site metanode LSP stand out in the site-internal LSP database on any node in the local site network. The network administrator can then identify whether the site metanode is running and check the contents of the LSP. Instantiating the site metanode on all peer nodes will create a unique system ID for all local BEB104 nodes in local site i. ij Inter-site communication provides full-activity load balancing and redundancy.
[0100] In SBN 105 il The instantiation and management of site meta nodes (LSPs) can be based on one of the following two operational mechanisms: Alternatively, all activators When SBN 105 il SBN 105 was found on the local site. il After selecting peer nodes, peer SBN 105 will be chosen. il One of them is used as the DA. For example, the selection can be based on the SBN 105 with the lowest system ID announced in the Level 2 LSP. il To proceed. Only SBN 105 selected as DA.il Only when there are no other SBNs can a site meta node LSP be generated for an IS-IS Level 1 network (intra-site network) used for SPB. A DA can instantiate a site meta node LSP and treat all peer SBNs within the local site as neighbors of the site meta node. Other peer SBNs within the site will treat this site meta node as the network LSP. However, all peer SBNs (DA and non-DA) that have enabled site meta node operations (after enabling at least one IS-IS Level 2 adjacency for SPB) will use the site meta node LSP as the root for running Level 1 SPF operations.
[0101] If the DA is removed, the peer SBN, as a removed node in the system, will discover this removal via Level 2 LSP updates. In this case, the next SBN with the lowest system ID can take over the site's DA. Therefore, it will convert all existing site meta nodes from the network LSP to its own site meta node LSP and regenerate the site meta node LSP in the IS-IS Level 1 network within the site used for SPB to update the state of all nodes.
[0102] The advantage of the DA mechanism is that only the DA needs to activate the remote site ISID and routing resources in the site meta node LSP. Therefore, since only one owner is responsible for activating and managing this LSP, it does not need to maintain any order in which resources are added to the LSP.
[0103] Path computation: Each SBN at the local site will instantiate the same Site Meta Node LSP on its local node and generate a self-generated LSP on each peer SBN. This Site Meta Node LSP will be created with all peer SBNs of the local site as neighbors (peer SBNs are discovered through the peer SBN discovery process described above). During this process, each SBN must activate the ISID and routing resources of the remote site in the same order as other peer SBNs.
[0104] In both activation mechanisms described above, special auditing can be performed to ensure that the activation of the site meta node LSP remains consistent across all peer LSPs. When an SBN receives a site meta node LSP from another peer SBN, it can audit the received LSP's Type Length Value (TLV) information against its local site meta node resources (the remote site's Layer 2 and Layer 3 ISID resources) to verify any inconsistencies in the resources (Layer 2 and Layer 3 objects) advertised between peers. If the audit fails, the network administrator will be notified. Sequence number refresh can be performed to ensure that self-generated site meta node LSPs always reflect the latest sequence numbers. After any audit update to the site meta node LSP, the checksum can also be updated, thus keeping the site meta node LSP synchronized across all peer SBNs.
[0105] Under the aforementioned DA mechanism, only the DA SBN can update the site meta node LSP sequence number and checksum when the resource information announced by the site meta node LSP is updated.
[0106] Under all the activator mechanisms described above, any update to the Site Meta Node LSP by any SBN will cause it to regenerate an updated Site Meta Node LSP to its local site. The sequence number, checksum, and remaining lifetime fields of this LSP will also be updated. When a peer SBN receives this Site Meta Node LSP, it will trigger an audit of the Site Meta Node LSP on each SBN. If the MT and Reach TLV values of the Site Meta Node LSPs are synchronized across peer SBNs, the Site Meta Node LSP will also maintain a separate meta-remaining lifetime field, independent of the LSP remaining lifetime field. During Site Meta Node LSP auditing, this new field will be updated to reflect the maximum remaining lifetime value of all instances of Site Meta Node LSPs across the peer SBNs. Level 1 SPB-IS-IS uses this lifetime value when sending updated Partial Sequence Number PDUs (PSNPs) to neighboring nodes to ensure that Send Router Messages (SRM) and Send Sequence Numbers (SSNs) operations between adjacencies are not affected by Site Meta Node instantiation.
[0107] Figure 4 Peer-to-peer SBNs must run two Site-Specific Flow (SPF) operations for Level 1 networks. The first SPF runs based on the root node of the local SBN to determine reachability from the local node to nodes within the site. The second SPF runs based on the root node of the site meta node and is called the "meta SPF". This meta SPF will run on all peer-to-peer SBNs of the site using a generic site meta node LSP that is already active across all peer nodes. This SPF will establish path connectivity from the meta node to nodes within the site (BEB and BCB).
[0108] The path metric for each SBN neighbor of a site meta node must be set to the maximum supported metric. This maximum metric is required to ensure that the logical site meta node entity itself is not considered an intermediate path node in path calculations between nodes within a site. Essentially, a site meta node should only serve as an endpoint in the IS-IS Level 1 intra-site network used for SPB, and never as a backbone core bridge (BCB).
[0109] All BEBs and BCBs within the local site will receive and process the site meta node LSP. Each node will calculate the path to the site meta node and establish the shortest path to it. This is essentially the shortest path to the local SBN hosting the site meta node. Additionally, ECT paths will be established for load balancing between peering SBNs.
[0110] On the local SBN, the IS-IS Level 1 SPF used for SPB calculates path information from the site meta node to all nodes within the local site. Path calculation is performed according to the procedure described in RFC 6329, following BVLAN / ECT. All SBNs of the site meta node (its own SBN and peer SBNs) are used as neighbor nodes for path calculation.
[0111] Therefore, each SBN can maintain three independent lists of paths for calculating the IS-IS SPF for the SPB: - A list of Level 1 paths used to calculate intra-site connectivity from the local / self SBN to all nodes within the site; - A Level 1 path list used to calculate the connectivity between a site's meta node and all nodes within the site; and - A list of Level 2 paths used to calculate inter-site connectivity between all SBNs in the core inter-site network (Level 2 SPB network 101).
[0112] Path ownership from the site meta node to any node in the local site can be determined by the backbone VLAN ID (BVID) + backbone MAC (BMAC) tuple of each node in the local site.
[0113] Only paths with the local SBN as the next hop are instantiated in the data plane. If the next hop of the route is determined to be another peer SBN, the tuple will not be instantiated in the data plane because the other peer SBN is known to have a better path to the local node (BEB, BCB). This operation also ensures path symmetry and consistency between the site meta node and the local node of the local site.
[0114] Figure 3The diagram shows the IS-IS Level 1 network used for SPB within the site, and the activation of the site meta node LSP associated with the specific site 1021. The diagram also shows BEB (104). 11 and 104 12 ) and SBN 105 11 and 105 12 The physical link between them is 401. For simplicity, the BCB node is omitted from the diagram. The steps for instantiating and maintaining the site meta node are detailed below: - SBN 105 11 and 105 12 Each SBN in the network can create a metasite object that captures the multisite resources of the MS-SPB network 100 and then initiates the instantiation of the site meta node as a logical representation of all remote sites. - Site meta node SMN1 ( Figure 4 3021) is instantiated in the Level 1 network of local site 1021 by generating a site meta node LSP in the IS-IS Level 1 network (site-internal network) used for SPB. SBN 105 11 and 105 12 Each SBN in the network instantiates the same Site Meta Node LSP on its local node as a self-generated LSP on the SBN. This Site Meta Node LSP will be created with all peer SBNs of local site 1021 as neighbor nodes (therefore, in the example shown: SBN 105). 11 It is SBN 105 12 The neighboring nodes (and vice versa) will be discovered using the peer-to-peer SBN discovery process described above. The path metric of each SBN neighbor of the site meta node will be set to the maximum supported metric. This ensures that the logical site meta node entity itself is not considered an intermediate path node in path calculations between nodes within the site. Essentially, the site meta node should only operate as an endpoint of the IS-IS Level 1 intra-site network used for SPB, and never as a BCB.
[0115] - All BEB (104) on the local site 11 and 104 12 ) and BCB nodes ( Figure 4 (Not shown) Receives and processes the Site Meta Node LSP. Each such node then runs path calculation to the Site Meta Node and establishes the shortest path to that Meta Node. This is actually the shortest path to the local SBN node hosting the Site Meta Node. ECT paths can also be established for load balancing between peering SBNs. Via Meta Link 403, in BEB 104 11 and 10412 An SPB tunnel is established between the site meta node 3021 and the site meta node 3021. The site meta node 3021 will represent all external site resources to the site's internal network. Based on the full-activity mode implementation of this technology, load balancing and failover mechanisms are seamlessly integrated. BEB ( Figure 4 104 in the example 11 and 104 12 A path to the site meta node can be established. Figure 4 In the example, 3021) per tuple (BVLAN + BMAC) tunneling allows the tunnel to run on peer SBN ( Maintenance of neighbor list for site metanodes 105 in the example 11 and 105 12 Load balancing is performed between BVLANs via ECT (BVLAN). This is because the site meta node LSP is activated with local peer SBNs as its neighbors, and these peer SBNs have the same overhead as the site meta node. By applying the ECT algorithm of RFC 6329 (Section 12), each BEB can establish a unique tunnel path to the site meta node for each BVLAN (ECT), so that the tunnel for each ECT terminates at a different peer SBN. Furthermore, if one of the peer SBNs in the local site goes offline, the site meta node will be activated, so that SBN will not exist in the neighbor list of the site meta node LSP. The updated site meta node LSP will be advertised to the local site by the SBN. The local BEB will recalculate the tunnel path and failover the tunnel path to the set of available peer SBNs. This provides proactive load balancing between peer SBNs for inter-site connectivity and seamless failover in the event of SBN failure. This provides stability, simplicity, and robustness for the highly scalable MS-SPB network based on this technology.
[0116] Inter-site service connectivity for MS-SPB: service extension (LSP mining) As a reminder, regarding SBN 105 il To instantiate a site meta node, at least one IS-IS Level 2 adjacency for SPB must be established with a remote SBN. If a site meta node was previously enabled but no such Level 2 adjacency was established, the site meta node will be removed. Furthermore, in order to construct a site meta node, the SBN must discover other peer SBNs in the network that will constitute the list of neighbors for the site meta node and are also necessary for constructing the site meta node LSP frame.
[0117] Upon receiving a Level 2 LSP from a peering SBN (same site ID), the local SBN will also verify whether a corresponding Level 1 LSP update exists for the same peering SBN: - If the peer SBN LSP exists in both Level 1 and the active Level 2 with a remote SBN, then add this peer SBN as a site meta node 302. i Neighbors; - If the peer SBN LSP does not exist in Level 1, the local SBN will wait until the retention period expires before checking the peer SBN's Level 1 LSP status: if there is no Level 1 LSP update, the peer SBN is assumed to be operating as an island within this local site. The site meta node neighbor list will be constructed to exclude this peer SBN. Optionally, the site meta node neighbor list can reflect this status of the peer SBN, and this status can be used to generate traps to repair the Level 1 network, thereby preventing islands (peer SBNs in the Level 1 network that are not visible to each other) from appearing in the local network.
[0118] The result of this process is: - Duplicate site ID configurations may be found throughout the SPB network; - The site meta node neighbor list cannot include any remote SBNs because Level 1 LSP updates cannot be received from such remote SBNs.
[0119] The site meta node retain timer is activated after any changes to the site meta node neighbor list. If any changes occur to the site meta node neighbor list or the allocation of Layer 2 / 3 resources between sites, the site meta node will be updated in the control plane (site meta node LSP) and data plane after the retain time expires.
[0120] Optionally, before the network is operational, all peer SBNs are allowed sufficient time to reflect the same changes to their site metanode instances, resulting in identical information, including the site metanode neighbor list service resource associated with the site metanode. This is done to ensure the robustness of the multi-site SPB network according to this technology.
[0121] Using the aforementioned site metanode neighbor list and configured site IDs, the SBN can generate / build LSP PDUs to represent the site metanode to local sites. Management of the LSPs associated with the site metanode can be based on the DA mode or all activator modes described above. As described below, based on the discovery of remote site resources and the application of local site resource distribution security policies, Layer 2 and Layer 3 ISID resources can subsequently be added to the site metanode LSP. These security policies are unrestricted and can be configured by the network administrator to control which Layer 2 and Layer 3 objects can be distributed across sites. This security policy-based control can be applied to resource distribution within or between sites.
[0122] Figure 1 As mentioned above, metasite discovery will automatically discover ISID resources deployed in the MS-SPB network and establish ISID tunnels between sites.
[0123] Each SBN in an MS-SPB network collects all running ISIDs at its local site to determine if resource matching exists between sites. This can be done by the local SBN by mining LSP information from all local BEBs at its local site, thus determining the list of running ISIDs at the site. Each SBN can then advertise this list of ISID resources as part of a Level 2 LSP announcement to other SBNs at remote sites.
[0124] When two SBNs located at remote sites identify a common / matching ISID resource, an inter-site tunnel will be established for this service to facilitate inter-site forwarding of the service.
[0125] Since a remote site has been discovered to also be running the ISID resource, the local SBN will propagate this ISID to the site metanode. The site metanode will activate this ISID in its site metanode LSP and propagate it to the local site. The local site's BEB will process this site metanode LSP update and establish a tunnel to the site metanode hosted on the local SBN. This LSP mining operation will enable services to scale across sites and facilitate inter-site connectivity.
[0126] The local SBN will also establish an ISID tunnel connecting to the local BEB that has a path to the site meta node via the local SBN. If, for a given ISID BVLAN / ECT, the path ownership from the site meta node to the BEB does not pass through this local SBN, the establishment of the data path will be skipped, and another peer SBN with a better path to the BEB will be expected to establish the ISID tunnel.
[0127] To ensure service access is limited to the local site and to prevent resources from being advertised to any remote sites, security policy constraints can be introduced on the local SBN to determine whether it can establish inter-site tunnels for a given ISID resource. Furthermore, other security policies can be defined to allow access only to certain remote sites. Therefore, this technology provides security, flexibility, and ease of configuration, thereby facilitating inter-site connectivity of SPB ISID resources.
[0128] The site meta node ISID resource distribution of the local site is derived based on the LSP mining process described above. For MS-SPB network 100, the peer SBN (SBN A 105) of site 1 1021 is... 11 And SBN B 105 12The ISID mining process on the site will automatically discover a subset of ISIDs shared by the local site and a set of remote sites. This subset of ISIDs can be represented by the following formula and will be coordinated in the site meta node to provide ISID connectivity between sites.
[0129] The following is a summary Inter-site service connectivity for MS-SPB: data path for multi-site SPB network Sample example of service activation in the network shown: - Site meta node of Site 1: intersection (union (Site2, Site3, Site4), Site1) -or-
[0130] - Site 1 transport service: AND (SBN A, SBN B) - OR - ISID
[0131] The ISID list will then be dynamically updated in the site meta node LSP and advertised in the Level 1 network within the site, enabling the local BEB to establish a tunnel connection with the site meta node, thereby achieving inter-site reachability. Security policies defined on the SBN related to service distribution conditions will further control the ISID advertisement of the site meta node and the distribution of Level 2 LSPs between SBNs.
[0132] Figure 5 like Inter-site service connectivity for MS-SPB: service concatenation operation mode As shown, when two customer edge devices (CE1 and CE2) 501 11 and 501 21 During connection, the data forwarding path between sites includes three different segments: 504, 505, and 506.
[0133] Within the site's entry segment 504, BEB B1 104 11 Forward the SPB frame to the hosting address on SBN 105 11 and 105 12 The site meta node is SMN1 3021. The source address (MAC_SA) encapsulated here is BEB B1 104. 11 The destination address (MAC_DA) is the address of the site metanode SMN1 3021. Here, the destination MAC_DA SMN1 is a network-unique site metanode system ID, generated by concatenating a 3-byte OUI and a 3-byte site ID. BEB B1 104 11 Based on BEB B1 104 11The shortest path between SMN13021 and the tunnel endpoint is calculated only with one of the local site SBNs. When the tunnel is in SBN (represented in this example as: SBN A 105)... 11 When ) terminates, SBN A 105 11 It will target BEB B1 104 11 Tunnel learning CE1501 11 The MAC address. SBN will look up CE2 501 in ISID-ID1. 21 The target MAC address. If the lookup is successful, the frame will be forwarded to the remote SBN (represented in this example as SBN C 105) via a Level 2 tunnel between SBNs. 21 If the search is unsuccessful, SBN A 105 11 The frame will be flooded to all available Level 2 tunnels in ISID-ID1. Split Horizontal Check will prevent the frame from being flooded to Level 1 tunnels in ISID-ID1, thus avoiding loops in the network within the site.
[0134] In inter-site transport segment 505, the SPB frame originates from the SBN (represented in this example as SBN A 105) on the local site. 11 Forwarded to the SBN on the remote site (represented in this example as: SBN C 105) 21 After the tunnel terminates, SBN (represented in this example as: SBN C 105) 21 This will target a remote SBN (represented in this example as: SBN A 105). 11 Tunnel learning CE1 501 11 The MAC address.
[0135] In exit section 506 within the station, SBN C 105 21 This will cause the SPB-encapsulated frame to be forwarded to the local BEB B2 104. 21 The source node here is SBN C 105. 21 The address of the host site's meta node SMN2 3022. Forwarding here is based on a successful lookup of CE2 501. 21 The target MAC address is used. If the address is not found on the SBN, it is flooded to all Level 1 tunnels of ISID-ID1. Split Horizontal Check prevents frames from being flooded to Level 2 tunnels of ISID-ID1 to avoid loops in the inter-site network.
[0136] All SBNs will block traffic received from an SPB tunnel at a remote site from being forwarded to tunnels at different sites. ISID tunnels established between SBNs in an IS-IS Level 2 network for SPB will operate in different split-horizon groups, relative to IS-IS Level 1 tunnels for SPB established between a BEB and a site metanode. Traffic forwarding between tunnels in the same group will be disabled. However, traffic forwarding between two different types of tunnels (i.e., between Level 1 and Level 2) is allowed. This split-horizon setup follows the procedures described in IEEE 802.1aq. This procedure is crucial for preventing traffic loops in the core network.
[0137] BEB establishes tunnels only with site meta nodes to set up inter-site connections. This method of aggregating the entire inter-site network solely through site meta nodes enables the data plane to achieve extremely high scalability and access resources on tens of thousands of nodes in remote sites without explicitly connecting to each tunnel endpoint across multiple inter-site networks.
[0138] Detection and prevention of backdoor access According to this technology, the serving ISID can still be configured to operate in cascaded mode (also known as Bud mode) to reduce broadcast traffic in the network. It is well known that in an MS-SPB topology, each part of the serving ISID (ingress, transport, and egress) can be independently configured to operate in frontend mode or cascaded mode according to network requirements.
[0139] However, enabling concatenated mode operation on the transport path, relative to PtoP frontend mode, may result in data frames being forwarded to all sites in the MS-SPB network (point-to-multipoint, PtoMP). This PtoMP flooding may ignore security and / or boundary policy restrictions that typically limit service reachability to specific sites. Alternatively, when strict service isolation is required between MS-SPB sites, frontend-based services may be used only in the transport area.
[0140] In case of greenfield deployment: In the multi-site SPB topology used in this technology, site 102 i All traffic forwarded between sites (inter-site traffic) is only within the site's SBN 105. il Inter-site transmission. Inter-site tunnel paths are established only within the core Level 2 SPB network 101 to facilitate this connection. This is for detecting and handling events occurring during network configuration or deployment (e.g., at site 102). i The local node (BEB 104) ij Or BCB 103 ikIt may have been established to another node BEB 104 in the remote site. ij Or BCB 103 ik (Backdoor links), which can selectively implement loop prevention mechanisms based on this technology.
[0141] The mechanism based on this technology will depend on the network deployment type: - In case of brownfield deployment For any given site 102 i All SPB nodes (SBN 105) il BEB104 ij and BCB 103 i All nodes should be configured with the same site ID. A site ID check is performed when establishing a Level 1 SPB IS-IS adjacency, and the adjacency is only established if all Level 1 paths on each node are configured with matching site IDs. This check prevents the establishment of SPB adjacencies between backdoor links and detects incorrectly configured or missing site IDs on any node in the network.
[0142] - Figure 1 The nodes within the site are running on legacy code lacking MS-SPB functionality. Because zone verification is not performed on these nodes, they may establish backdoor adjacencies and data channels to forward traffic between sites, bypassing the paths defined by the site's SBN. Such connections can lead to network traffic loops, potentially causing network crashes and security vulnerabilities, as the nodes within the site are bypassing local SBN 105. il Enforceable security policy constraints. The following procedures can be implemented to detect such vulnerabilities and trigger remediation, including disabling local SBN 105. il It runs and sends security vulnerability alerts to network administrators.
[0143] Step 1: Detect remote site meta node LSPs during Level 1 LSP processing: 105 per SBN il The system monitors the Level 1 LSP database to look for any additional site metanodes besides the local site's site metanode. A simple check of the OUI and site ID (derived from the system ID of the LSP-ID) of all received LSPs can reveal whether a site metanode LSP from a leaked remote site is connected via a backdoor. Furthermore, the neighbor list of the local site metanode LSP can be checked to ensure that the site metanode adjacency only includes the local SBN. Otherwise, it is considered a leaked site metanode LSP from a remote site.
[0144] For example, refer to Figure 3 and Figure 1Site 1 1021 SBN A 105 11 The presence of an external site meta node LSP SMN2 3022 from site 2 1022 has been detected. During Level 1 LSP processing, an OUI check is performed on the received Level 1 LSP. This will determine the existence of an external site meta node LSP SMN2 3022 whose site ID portion differs from that of the local site meta node LSP SMN1 3021. This will cause the SPF run of the Level 1 LSP to issue an alert to the next-level SPF run, for example, of type: "L1-LSP-Loop-Dectected Alert for Alien-LSP-ID: SMN2".
[0145] Step 2: Detecting Remote SBN LSPs During Level 1 LSP Processing: To address situations where a remote site's site meta node is interrupted (indicating a backdoor connection to the remote site), backdoor loops can be detected by checking for remote SBNs leaked into the local Level 1 LSP database. Running Level 2 SPF on the local SBN will collect all remote SBNs and their associated site IDs. During Level 1 LSP processing, each LSP can be checked for existence in the Level 2 LSP database, which only includes remote SBNs. The system ID of the Level 1 LSP is compared with the system ID in the Level 2 LSP database for a match. If a match is found, it indicates a backdoor loop. Path checks can be performed on external LSPs during MetaSPF execution.
[0146] For example, refer to Figure 3 and Network evolution Site 1 1021 SBN A 105 11 An external LSP SBN C 105 from site 2 1022 was detected. 21 During Level 1 LSP processing, if the OUI check fails to detect an external site meta node LSP, then SBN A 105 11 The LSP processor on the device checks whether the received LSP-ID matches the Level 2 LSP database (including LSP SBN C 105). 21 Matching. If a match is found in the Level 2 database, it indicates a backdoor loop between the two sites. Note that if meta-operations are not enabled on site 2, the site meta node SMN2 3022 will not be published to the network. However, SBN C 105 21The Level 1 LSP will be provided by BEB 104 11 Distribute to local site 1. This will cause the Level 1 LSP to issue an alert of type "L1-LSP-Loop-Dectected Alertfor Alien-LSP-ID: SBN C" to the next run of the Meta Node SPF.
[0147] Step 3: When an external LSP is detected on the local SBN, the Meta SPF defined above can be notified to determine the path to that external LSP during the next SPF run. At the end of the next Meta SPF run, the Level 1 path to that LSP can be determined and published to the network administrator to help identify offending nodes in the network. Simultaneously, site meta node operations on the SBN can be disabled until any backdoor loops are fixed.
[0148] Regarding the two examples provided above: On the next run, the meta-SPF will detect that an L1-LSP-Loop-Dectected alarm has been issued. At the end of the Level 1 meta-SPF run, SBN A 105 11 SBN A 105 will be closed 11 Before performing operations on the site meta node, publish the path to the tagged external LSP, for example: - If the destination node is SMN2 3022: "Path SMN1 3021->SBNA 105" 11 ->BCB 103 11 ->BEB104 11 ->BEB 104 21 ->BCB 103 21 ->SBN C 105 21 ”; - If the destination node is SBN C 105 21 "Path SMN1 3021->SBN A 105" 11 ->BCB 103 11 ->BEB 104 11 ->BEB 104 21 ->BCB 103 21 ".
[0149] Using appropriate system naming rules, network administrators should be able to identify BEB 104. 11 (Site 1) and BEB104 21The backdoor link between (site 2) is the cause of the loop. Error notifications sent to the network administrator may appear as traps to correct configuration errors. These traps may provide path details about a leaked remote site meta node LSP, or the remote site's SBN, to help identify the problematic local BEB within the local site.
[0150] Homogeneous or heterogeneous MS-SPB network design Large networks are typically distributed across multiple geographically dispersed but interconnected locations. These networks often expand over time (brownfield networks). This technology provides space for the organic expansion of these networks or the interconnection of independent SPB networks, minimizing disruption. Furthermore, large networks may require merging different SPB networks, breaking down existing large SPB networks into smaller segments to reduce control plane complexity, or enforcing security policies across different locations. In other cases, it may be necessary to add or remove sites within the network. This technology provides a highly efficient and simple method for achieving network integration or segmentation.
[0151] To partition an existing network, existing nodes can be converted into SBNs, or additional SBNs can be added to the network at the logical boundaries of sites (or within sites for redundancy and load balancing) by configuring Level 2 interfaces on nodes to enable them to act as SBNs. In this context: - A site can be a logical group of nodes (including BEB and BCB) that share a globally unique site ID and a Level 1 address. All nodes within a Level 1 address share the same area ID and follow the SPB structure within that site. Each LSP within an area does not cross that area and forms an adjacency relationship within each area. - Configure a site ID on each created SBN and distribute it as a region ID on the Level 2 interface via the SBN; Each site can have its own control plane and control BVID, which may be valid only within the site. All sites can share the same control BVID, but this is not mandatory. Using different BVIDs in the Level 2 domain or other sites is also reasonable. Tunnels within a site terminate at the SBN.
[0152] Therefore, the steps involved in dividing the network are as follows: - Create a site (split an existing Level 1 network): - Configure the site ID (converted to a unique region ID for Level 1 / Level 2 nodes) for each SBN. - Instantiate a site meta node for each SBN of each site; - Activate the SBN with Level 2 links between them. This will instantiate the site meta node as a Level 1 node in the local Level 1 network.
[0153] - The configuration on the Level 1 node remains unchanged (where region id=0).
[0154] Conversely, reverting to a single-domain flat SPB network simply requires removing the SBN configuration. No further changes are needed for the Level 1 network. This simple and easy implementation can be seamlessly integrated into efficient and simple network partitioning or integration as needed for network evolution.
[0155] Therefore, the steps involved in merging networks are as follows: - Merge sites (merge Level 1 / Level 2 networks into a Level 1 network); - Delete and clear the Level 1 site meta nodes. Configure the Level 2 links between SBNs as Level 1 links.
[0156] - Delete site ID (unique zone ID): The default zone ID for Level 1 nodes remains zone-id=0.
[0157] Figure 6 Those skilled in the art know that the three invariant configurable parameters in a flat SPB network are the region ID, BVID, and ISID (RFC 6329, 7623, and 7734). According to this technology, these three parameters are configured at site 102. i The same parameters can be used between Level 2 network 101 (for isomorphic solutions applicable to green space networks), or one, two, or three of these parameters can be used at site 102. i This can differ from Level 2 network 101 (for heterogeneous solutions in brownfield networks). If a parameter is at site 102... i If the differences are between them, then the conversion performed on the SBN will benefit site 102. i Integration. The policy manager residing on each SBN can enforce this boundary policy and perform the transition when sending Level 2 LSPs across sites. This provides a simple and effective way to enable each site to evolve independently and helps network administrators manage the combined complexity of these three parameters across sites.
[0158] The control BVIDs for Level 1 and Level 2 domains may differ. Integrating new sites with different control BVIDs into the global network simply requires adding SBN resources. The control BVID for a local site can differ from other sites and terminates at the SBN. Control BVIDs in the Level 2 domain can be configured on the Level 2 interface of the SBN. This flexibility simplifies integrating new campus vertical networks or adding new sites from a network management perspective. Because the ingress tunnel terminates at the SBN and a separate control plane exists within the transport tunnel, the BVIDs within the transport tunnel maintain contextual relevance only within the network structure. A logical extension of the heterogeneous BVID concept is the duality of supporting Layer 2 multicast options (BUM traffic). The choice between headend or serial mode within the same site is independent of the transport mode in the Level 2 tunnel. This allows network administrators the flexibility to choose the optimal replication mechanism for each site. It's important to note that although the singular form is used above, "network administrator" generally refers to anyone with at least a minimum level of management authority over the network.
[0159] Each local site's Area-id is likely unique. All peer SBNs of a local site are configured with the same Site-id. The Level 1 interface on the SBN matches the Area-id of the nodes within the site. The SBN can use this Site-id as its local Area-id when establishing Level 2 adjacencies with other SBNs. If, as mentioned earlier, the control BVIDs of each site are different, separate BVIDs can also be configured for the Level 2 SPB path. The SBN creates a separate SPF path for Level 2, independent of the Level 1 path. Therefore, network merging or splitting can be achieved with only easily manageable configuration changes to the SBN.
[0160] As described above, ISID extension is performed on the SBN. If an existing site is being split, the ISID (service) is already configured, and there's no need to translate the ISID over the transport tunnel. On the other hand, if a new site is being integrated with an existing site, the new site's ISID may differ from the existing site's, thus requiring translation to perform ISID extension. This operation is performed on the SBN when the ingress tunnel terminates at the local SBN. Therefore, sites with different ISIDs can be integrated / merged. In addition to security policies (allowing or denying ISID extension), the SBN performs a lookup at the ingress tunnel termination to translate the ISID to the appropriate ISID for the target site. For example, HR-related services in Site 1 and Site 2 may have different ISIDs, but there's no need to reconfigure the ISID in either site. Enforcing translation on the SBN extends the scope of ISID extension and restricts configuration changes, thus simplifying site integration.
[0161] Figure 7 A computer-implemented method step according to one aspect of the present technology is described. For example, the first aspect of the method may involve constructing a segmented SPB network from an existing brownfield SPB network. In step 601, a unique site ID may be assigned to each of at least two sites included in the segmented SPB network having an IS-IS network topology for SPB. Here, "unique" means that each site is assigned a different site ID. In step 602, at least one SBN may be associated with each of the at least two sites. In step 603, all SBNs in the segmented SPB network may be connected via an IS-IS Level 2 interface for SPB, thereby forming an inter-site network operating at IS-IS Level 2 for SPB. In step 604, a unique site ID may be assigned to the site associated with each SBN as a 3-byte area address field of the TLV of the control frames constructed and advertised by that SBN on its IS-IS Level 2 interface for SPB.
[0162] Figure 6 The method steps for a computer implementation based on the second aspect of this technology are described. For example, the second aspect of this method may be involved in constructing a segmented SPB network for green spaces. In the second aspect, the execution of... Figure 8 The same steps 601 to 604 apply. In step 701, at least one node (which can be an endpoint node or an intermediate node) can be connected to each of the at least one SBN via an IS-IS Level 1 interface for SPB, thereby forming an intra-site network operating in IS-IS Level 1 for SPB. Each SBN and each node can be identified by a unique first system ID. In step 702, a unique site ID can also be assigned to the site associated with each SBN as a 3-byte area address field of the TLV of the control frames constructed and advertised by that SBN on its IS-IS Level 1 interface for SPB.
[0163] While the above implementation has been described and illustrated with reference to specific steps performed in a particular order, it should be understood that these steps can be combined, subdivided, or rearranged without departing from the teachings of this disclosure. At least some steps can be performed in parallel or sequentially. Therefore, the order and grouping of steps are not a limitation of this technique. It should be clearly understood that not all technical effects mentioned herein need to be enjoyed in every and every embodiment of this technique.
[0164] The methods and procedures described above can be implemented in computing systems, examples of which are provided, but not limited to, regarding... It can be found. As those skilled in the art will understand, such a computing system can be implemented in any other suitable hardware, software and / or firmware, or a combination thereof, and can be a single physical entity or several separate physical entities with distributed functionality.
[0165] In some aspects of this technology, the computing system 800 may include various hardware components, including one or more single-core or multi-core processors, collectively represented by processor 801, solid-state drive 802, memory 803, and input / output interface 804. In this case, processor 801 may or may not be included in an FPGA. In some other aspects, the computing system 800 may be an "off-the-shelf" general-purpose computing system. In some aspects, the computing system 800 may also be distributed across multiple systems. The computing system 800 may also be specifically designed for implementations of this technology. As will be understood by those skilled in the art, various variations regarding how to implement the computing system 800 can be conceived without departing from the scope of this technology.
[0166] Communication between various components of the computing system 800 can be enabled via one or more internal and / or external buses 805 (e.g., PCI bus, Universal Serial Bus, IEEE 1394 FireWire bus, SCSI bus, Serial ATA bus, ARINC bus, etc.), with various hardware components electrically coupled to the buses.
[0167] Input / output interface 804 may enable networking capabilities, such as wired or wireless access. As an example, input / output interface 804 may include a network interface, such as, but not limited to, a network port, a network connector, a network interface controller, etc. Several examples of how a network interface can be implemented will become apparent to those skilled in the art. According to embodiments of the present invention, solid-state drive 802 may store program instructions, such as portions of libraries, applications, etc., suitable for loading into memory 803 and execution by processor 801 according to the methods and process steps of the present invention.
[0168] Modifications and improvements to the above embodiments of this technology will be readily apparent to those skilled in the art. The foregoing description is intended to be exemplary and not restrictive. Therefore, the scope of this technology is intended to be limited only by the scope of the appended claims.
Claims
1. A segmented SPB network (100) comprising at least two sites (102 i ) and an IS-IS network topology for SPB, wherein: - each of the at least two sites (102 i ) comprises at least one site border node SBN (105 il ) and at least one node, which is either an endpoint node (BEB 104 ij ) or an intermediate node (BCB 103 ik ), connected to the at least one SBN over an IS-IS Level 1 interface for SPB, forming an intra-site network running IS-IS Level 1 for SPB, wherein each of the at least one SBN and the at least one node is identified with a unique first system id; and - All SBNs are connected over IS-IS Level 2 interfaces for SPB, forming an inter-site network running IS-IS Level 2 for SPB.
2. The segmented SPB network of claim 1, wherein, Each of the at least two sites is associated with a unique site id assigned as a 3- byte area address field of a TLV of a control frame built and advertised by all SBNs of each site respectively over IS-IS Level 2 interfaces of the SBNs for SPB.
3. The segmented SPB network of claim 2 wherein, Each of the at least two sites is associated with a unique site name assigned as a 32-byte system name field of a TLV of a control frame built and advertised by all SBNs of each site respectively over IS-IS Level 2 interfaces of the SBNs for SPB.
4. The segmented SPB network of claim 2, wherein, The unique site id is also assigned as a 3-byte area address field of a TLV of a control frame built and advertised by all SBNs of each site respectively over IS-IS Level 1 interfaces of the SBNs for SPB.
5. The segmented SPB network of claim 2 wherein, The unique site id is also assigned as a 3-byte area address field of a TLV of a control frame built and advertised by all nodes of a network within each site respectively over IS-IS Level 1 interfaces of the nodes for SPB.
6. The segmented SPB network of claim 2 wherein, Each SBN in a site that is a local site discovers all other SBNs of the local site in the segmented SPB network and all SBNs of other sites that are remote sites and maintains a list of all discovered SBNs and local or remote sites comprising all discovered SBNs based on site id values obtained by parsing area address fields of TLVs of received control frames.
7. The segmented SPB network of claim 6, wherein, Each SBN of the local site discovers other SBNs comprised in the local site as peer SBNs by: - determining that a site id value obtained by parsing an area address field of a TLV of a control frame received on an IS-IS Level 2 interface for SPB of each SBN is identical to a site id value of the local site; and - determining that the peer SBN runs IS-IS Level 1 for SPB by recognizing the unique first system id in a control frame received from the peer SBN on an IS-IS Level 1 interface for SPB of the peer SBN.
8. The segmented SPB network of claim 6, wherein, Each SBN of the local site discovers SBNs of remote sites as remote SBNs by determining that a site id value obtained by parsing an area address field of a TLV of a control frame received on an IS-IS Level 2 interface for SPB of each SBN is different from a site id value of the local site.
9. The segmented SPB network of claim 7, wherein, After establishing adjacency between at least two SBNs comprised in two different sites, instantiating a site meta-node SMN on each of the at least two SBNs, wherein the SMN is identified using a unique second system id different from any of the first system ids, wherein the SMN hosts a representation of the segmented SPB network comprising information about all discovered SBNs and local or remote sites containing all discovered SBNs.
10. The segmented network of claim 9, wherein, The unique second system id is a 6 byte value obtained by concatenation of a 3 byte Organization Unique Identifier OUI and a site id of the site of the SBN on which the SMN is instantiated.
11. The segmented SPB network of claim 9, wherein, The SMN is instantiated in a Level 1 site intra-network of a local site comprising the SBN on which the SMN is instantiated, wherein the peer SBNs have the same cost as neighbors and have a maximum path weight supported by the network to ensure that the SMN functions as an endpoint node of the segmented SPB network.
12. The segmented SPB network of claim 11, wherein, The instantiated SMN provides full active and failover modes for connections between nodes of the local site and nodes of a remote site.
13. The segmented SPB network of claim 11, wherein, One SBN is elected from the peer SBNs of the local site as a designated activator DA, wherein the DA performs instantiation of the SMN and activation and management of the SMN LSP.
14. The segmented SPB network of claim 13, wherein, The DA is elected from the peer SBNs based on the SBN having the lowest unique first system id among the peer SBNs.
15. The segmented SPB network of claim 11, wherein, All peer SBNs of the local site perform instantiation of the SMN and activation and management of the SMN LSP.
16. The segmented SPB network of claim 11, wherein, Each SBN of the local site: - mines LSP frames received from all SBNs of the inter-site network and maintains a list of ISID TLVs included in the mined LSP frames from the inter-site network; - mines LSP frames received from nodes of the local site of the intra-site network and maintains a list of ISID TLVs included in the mined LSP frames from the intra-site network; - maintains ownership of each SBN path from the SMN to nodes of the local site, wherein the path ownership is determined per ECT / BVLAN; and - advertises ISID TLVs of the local site to the Level 2 inter-site network through LSP frames generated by the SBNs.
17. The segmented SPB network of claim 16, wherein, The peer SBNs of the local site discover a subset of ISID TLVs common between the local site and the remote site.
18. The segmented SPB network of claim 17, wherein, Each SBN of the local site advertises the subset of ISID TLVs to the intra-site network by encoding the LSP of the SMN instantiated on the SBN.
19. The segmented SPB network of claim 16, wherein, An administrator enters a policy rule on the peer SBNs of the local site, the policy rule aiming at filtering out at least one of: - ISID TLVs included in LSP frames received from the inter-site network, and - ISID TLVs of the local site advertised in generated LSP frames to the inter-site network.
20. The segmented SPB network of claim 6 wherein, After establishing IS-IS Level 1 adjacency for SPB between the SBNs and the at least one node, a check is performed on the site id, wherein the adjacency is established only if the site id value on all Level 1 paths of each SBN in the SBNs and the at least one node match.
21. The segmented SPB network of claim 6 wherein, After checking the site id value obtained by parsing the area address field of the TLV of the received control frame, a check is performed on the local site as to whether the obtained site id value is the same as the site id value associated with the local site, wherein if the obtained site id value is different from the site id value associated with the local site, any backdoor between the node of the local site and the nodes of the remote site is disabled.
22. A computer-implemented method of constructing a segmented SPB network (100) comprising at least two sites (102 i ) and an IS-IS network topology for SPB, the method comprising: - assigning a unique site id to each of the at least two sites; and - associating at least one site border node SBN with each of the at least two sites; - connecting all SBNs in the segmented SPB network through IS-IS Level 2 interfaces for SPB, thereby forming an inter-site network running IS-IS Level 2 for SPB; - assigning to each SBN a unique site id of the site associated with each SBN, the unique site id being assigned as a 3-byte area address field of a TLV of a control frame built and advertised by each SBN respectively on the IS-IS Level 2 interface for SPB of each SBN.
23. The method of claim 22, further comprising: - connecting to each of the at least one SBN and at least one node, the node being an endpoint node (BEB 104 ij ) or an intermediate node (BCB 103 ik ) over an IS-IS Level 1 interface for SPB, thereby forming an intra-site network running IS-IS Level 1 for SPB, wherein each of the at least one SBN and the at least one node is identified with a unique first system id; and - further assigning to each SBN a unique site id of the site associated with each SBN, the unique site id being assigned as a 3-byte area address field of a TLV of a control frame built and advertised by each SBN on the IS-IS Level 1 interface for SPB of each SBN.
24. The method of claim 23, further comprising assigning to each node a unique site id of the site associated with each node, the unique site id being assigned as a 3-byte area address field of a TLV of a control frame built and advertised by each node respectively on the IS-IS Level 1 interface for SPB of each node.
25. The method of claim 22, comprising causing each SBN in a site that is a local site to discover all other SBNs of the local site and all SBNs of other sites that are remote sites in the segmented SPB network and to maintain a list of all discovered SBNs and local or remote sites that include all discovered SBNs based on site id values obtained by parsing area address fields of TLVs of control frames received.
26. The method of claim 25, comprising causing each SBN of the local site to discover other SBNs included in the local site as peer SBNs by: - determining that a site id value obtained by parsing area address fields of TLVs of control frames received on each SBN's IS-IS Level 2 interface for SPB is the same as a site id value of the local site; and - determining that the peer SBN has IS-IS Level 1 running for SPB by recognizing a unique first system id in control frames received from the peer SBN on the peer SBN's IS-IS Level 1 interface for SPB.
27. The method of claim 25, comprising causing each SBN of the local site to discover SBNs of remote sites as remote SBNs by determining that a site id value obtained by parsing area address fields of TLVs of control frames received on each SBN's IS-IS Level 2 interface for SPB is different from a site id value of the local site.
28. The method of claim 26, comprising: Upon establishing an adjacency relationship between at least two SBNs included in two different sites, instantiating a site master node, SMN, on each of the at least two SBNs, wherein the SMN is identified using a unique second system id that is different from any of the first system ids, wherein the SMN hosts a representation of the segmented SPB network that includes information about all discovered SBNs and local or remote sites that contain all discovered SBNs.
29. The method of claim 28, comprising obtaining a unique second system id that is a 6-byte value that is obtained by concatenating a 3-byte Organization Unique Identifier, OUI, and a site id of a site that contains the SBN in which the SMN is instantiated.
30. The method of claim 28, comprising instantiating the SMN in a Level 1 site- within-network at the local site, comprising activating an SMN link state packet (LSP), the local site comprising the SBN in which the SMN is instantiated, wherein, The peer SBNs have the same cost as neighbors and have a maximum path weight supported by the network to ensure that the SMNs function as end node nodes of the segmented SPB network.
31. The method of claim 30, comprising causing the instantiated SMN to provide full active and failover modes for connections between nodes of the local site and nodes of the remote site.
32. The method of claim 30, comprising electing one SBN from the peer SBNs of the local site as a Designated Activator (DA), wherein, The DA performs instantiation of the SMN and activation and management of the SMN LSP.
33. The method of claim 32, comprising having election of the DA be made from among the peer SBNs in the inter-site network based on the SBN having the lowest unique first system id among the peer SBNs.
34. The method of claim 30, comprising having all peer SBNs of the local site perform instantiation of the SMN and activation and management of the SMN LSP.
35. The method of claim 30, comprising having each SBN of the local site: - mine LSP frames received from all SBNs in the inter-site network and maintain a list of ISID TLVs included in the LSP frames mined from the inter-site network; - mine LSP frames received from nodes of the local site in the intra-site network and maintain a list of ISID TLVs included in the LSP frames mined from the intra-site network; - maintain per SBN path ownership from the SMN to nodes of the local site, wherein the path ownership is determined per ECT / BVLAN; and - advertise ISID TLVs of the local site to the Level 2 inter-site network via LSP frames generated by the SBN.
36. The method of claim 35, comprising having the peer SBNs of the local site discover a subset of ISID TLVs common to the local site and the remote site.
37. The method of claim 36, comprising having each SBN of the local site advertise the subset of ISID TLVs to the intra-site network by encoding LSPs of the SMN instantiated on the SBN.
38. The method of claim 35, comprising having an administrator input policy rules on the peer SBNs of the local site, the policy rules intended to filter out at least one of: - ISID TLVs included in LSP frames received from the inter-site network, and - ISID TLVs of the local site advertised to the inter-site network in generated LSP frames.
39. The method of claim 25, comprising performing a check on the site id after establishing IS-IS Level 1 adjacency for SPB between the SBN and the at least one node, wherein, An adjacency is established only if the site id value on all Level 1 paths from each of the SBNs and the at least one node matches.
40. The method of claim 25, comprising: After verifying the site id value obtained by parsing the area address field of the TLV of the received control frame, the local site is subjected to a verification that the obtained site id value is the same as the site id value associated with the local site, wherein if the obtained site id value is different from the site id value associated with the local site, any backdoor between the nodes of the local site and the nodes of the remote site is disabled.
41. A computer-readable medium comprising computer-readable instructions that, when executed by a system, cause the system to perform the method of any one of claims 22-40.
Citation Information
Patent Citations
Address corresponding relationship sending method of layer 2 protocol utilizing link state routing
CN102404181A
Neighbor multilink processing method and device
CN103501275A
Improved shortest path bridging in a multi-area network
CN104067566A
Shortest path bridging (SPB) multi area
US20220255841A1
Method and system for using is-is for SPB in the context of a service provider network
US20230198889A1