System and method for implementing unicast routing in segmented multi-site SPB network

By segmenting site boundary nodes into Fabric VPN and site meta VPN components in a segmented SPB network, and configuring gateway IP interfaces and routing distribution policies, the problem of unicast Layer 3 connectivity in segmented multi-site SPB networks is solved, enabling efficient inter-site route announcements and traffic routing, and improving network flexibility and security.

CN121444409APending Publication Date: 2026-01-30ALE AMERICA INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202580003516.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2026-01-30

AI Technical Summary

Technical Problem

In segmented multi-site (SPB) networks, existing technologies struggle to achieve efficient unicast Layer 3 connectivity, especially in inter-site networks where end-to-end Layer 3 route announcements and traffic routing are difficult to implement.

Method used

By dividing the Site Border Node (SBN) into Fabric VPN components and Site Meta VPN components, and setting a gateway IP interface in each component, configuring a common ISID and route distribution policy, Layer 3 route announcements and traffic routing between and within sites are achieved.

Benefits of technology

It enables efficient end-to-end unicast Layer 3 connectivity in segmented SPB networks, providing seamless and multi-path reachability between sites, and improving network flexibility and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121444409A_ABST
    Figure CN121444409A_ABST
Patent Text Reader

Abstract

A method and system for implementing a unicast layer 3 connection in an MS-SPB network (100) is described, the MS-SPB network comprising at least two stations (102i) and an ISIS network topology for SPB. The technique includes partitioning each SBN (105il) of any given site in the MS-SPB network as a local site into: a Fabric VPN component configured to advertise on an inter-site network all layer 3 routes located within an intra-site network of the local site to all other sites in the MS-SPB network as remote sites; and a site meta VPN component configured to advertise, on the intra-site network of the local site, all Layer 3 routes located within the intra-site network of the local site. A gateway IP interface in each of the Fabric VPN component and the site meta VPN component is configured to route layer 3 traffic from one node of the local site to a node of one of the remote sites in the MS-SPB network over the inter-site network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This technology relates to methods and systems for networking in a segmented SPB network, and more specifically to methods and systems for implementing unicast routing or Layer 3 connectivity in a segmented SPB network comprising at least two sites and an intermediate system-to-intermediate system (SPB with ISIS) network topology for shortest path bridging. Background Technology

[0002] PCT patent application WO2025 / 005920, entitled "Method and System for Segmented Multi-Site SPB Network" published on January 2, 2025 (the entire contents of which are incorporated herein by reference), discloses a segmented SPB network and its construction method, comprising at least two sites, each site including at least one site boundary node. The site boundary nodes are interconnected via an SPB ISIS Level 2 interface to form an inter-site network operating in SPB ISIS Level 2. Simultaneously, within each site, each site boundary node is connected to other nodes via an SPB ISIS Level 1 interface to form an intra-site network operating in SPB ISIS Level 1.

[0003] In this example of a segmented multisite (MS) SPB network, or in networks with similar characteristics, there is a need for methods and systems capable of implementing unicast routing or Layer 3 connectivity.

[0004] The topics discussed in the background section should not be construed as prior art simply because they are mentioned therein. Similarly, issues mentioned in the background or related to the topics in the background section should not be construed as having been known prior in the prior art. The topics in the background section merely represent different approaches. Summary of the Invention

[0005] Implementations of this technology were developed based on the developer's recognition of the drawbacks associated with existing technologies.

[0006] In one aspect, various embodiments of the present technology provide a computer-implemented method for implementing unicast Layer 3 connectivity in an MS-SPB network, the MS-SPB network comprising: at least two stations, each assigned a unique station ID, and an SPB ISIS network topology, wherein: - Each site in the MS-SPB network includes at least one Site Border Node (SBN) and at least one Endpoint Node (BEB) and Intermediate Node (BCB), which is connected to at least one SBN via an SPB ISIS Level 1 interface to form an intra-site network operating in SPB ISIS Level 1, wherein each of the at least one SBN and at least one node is identified by a unique system ID; and All SBNs in the MS-SPB network are connected via the SPB using an ISIS Level 2 interface to form an inter-site network operating in SPB using ISIS Level 2; the method includes: - Each SBN, which is any given site serving as a local site in the MS-SPB network, is segmented into a Layer 3 VPN component. Each corresponding Layer 3 VPN provides end-to-end Layer 3 connectivity across tunnel end points. Such Layer 3 VPN components include at least: - Fabric VPN components, which are configured to advertise all Layer 3 routes of a local site's intranet to all other sites in the MS-SPB network that are remote sites over an intersite network; and - A site meta VPN component, configured to advertise all Layer 3 routes within the site's intranet; and - Configure a gateway IP interface in each of the Fabric VPN components and the site meta VPN, which is configured to route Layer 3 traffic from a node of a local site to a node of one of the remote sites in the MS-SPB network over the inter-site network.

[0007] In an embodiment, the method further includes targeting all SBNs in the MS-SPB network: - Configure a public Fabric VPN ISID in the VRF of each SBN; and - Configure the gateway IP interface of the Fabric VPN component to a public subnet with a Fabric VPN ISID.

[0008] In an embodiment, the method further includes targeting all SBNs in the MS-SPB network and at least one node for each site: - Configure a common site meta VPN ISID in the VRF of each SBN and the VRF of each node; and - Configure the gateway IP interface used for the site meta VPN component to be in a public subnet with the site meta VPN ISID.

[0009] In an embodiment, the method further includes associating the ISID VPN type in the VRF of each SBN.

[0010] In an embodiment, the method further includes applying a routing distribution policy to exchange Layer 3 routes between inter-site networks and intra-site networks.

[0011] In an embodiment, the method further includes a FabricVPN component for each SBN of a local site within the MS-SPB network: - Create a public Fabric VPN ISID with Fabric VPN attributes; - Create a gateway IP interface for Fabric VPN components based on VRF; - Establish a routing distribution policy between the VRF and the tuple consisting of the Fabric VPN ISID and the gateway IP interface created for the Fabric VPN component, including: - Receive and learn the site ID associated with each route announced by the SBN of a remote site in the MS-SPB network; -Redistribute all routes from the site meta VPN component to the Fabric VPN component; and - Import all routes from the Fabric VPN component into VRF.

[0012] In an embodiment, the method further includes: For each node of a local site in the MS-SPB network: - Create a node ISID that is the same as the node ISID of the site meta VPN component of the local site, and establish an SPB tunnel to the SBN of the local site. - Create a node gateway IP interface based on VRF, located in the same subnet as the site meta VPN component of the local site; - Establish a routing distribution policy between the VRF and the tuple consisting of the created node ISID and the created node gateway IP, including: - Export all prefix routes from VRF; and - Import all prefix routes from the created node ISID into the VRF; For each SBN of a local site in the MS-SPB network: Site meta node component: - Create a public site meta VPN ISID with site meta VPN attributes; - Create a gateway IP interface for the local site using VRF for the site meta VPN ISID; - Establish a routing distribution policy between the VRF and a tuple consisting of the created public site meta VPN ISID and the gateway IP created for the site meta VPN ISID, including: -Redistribute all routes from the Fabric VPN component to the Site Meta VPN component; and - Import all routes from the site meta VPN component into VRF.

[0013] In embodiments of this method, the Layer 3 VPN component is presented as a Layer 3 interface based on IPv4 and / or IPv6.

[0014] In another aspect, various embodiments of the present technology provide a computer-readable medium containing computer-readable instructions that, when executed by a system, cause the system to perform the methods described above.

[0015] In another aspect, various embodiments of the present technology provide a segmented SPB network comprising at least two sites (each site assigned a unique site ID) and an SPB ISIS network topology, wherein: Each site in the -MS-SPB network comprises at least one Site Border Node (SBN) and at least one Endpoint Node (BEB) and / or Intermediate Node (BCB), which are connected to at least one SBN via an SPB ISIS Level 1 interface to form an intra-site network operating in SPB ISIS Level 1, wherein at least one SBN and at least one node are each identified by a unique system ID. All SBNs in the MS-SPB network are connected via the SPB using ISIS Level 2 interfaces to form an inter-site network operating in SPB using ISIS Level 2; In an MS-SPB network, each SBN of any given site acting as a local site is segmented into a Layer 3 VPN component, each corresponding Layer 3 VPN providing end-to-end Layer 3 connectivity across tunnel endpoints. Such Layer 3 VPN components include at least: - A Fabric VPN component configured to advertise all Layer 3 routes in the local site's intra-site network over the inter-site network to all other sites in the MS-SPB network that are remote sites; and - A site meta VPN component configured to advertise all Layer 3 routes within the site's intranet on the local site; and - Each of the Fabric VPN component and the Site Meta VPN component has a gateway IP interface configured to route Layer 3 traffic from a node of a local site to a node of one of the remote sites in the MS-SPB network over the inter-site network.

[0016] In an embodiment of a segmented SPB network: - A public Fabric VPN ISID is configured in the VRF of each SBN in the MS-SPB network; and - The gateway IP interface used for Fabric VPN components is configured in a public subnet with that Fabric VPN ISID.

[0017] In an embodiment of a segmented SPB network: - The public site meta VPN ISID is configured in the VRF of each SBN in the MS-SPB network and in the VRF of at least one node of each site in the MS-SPB network; and - The gateway IP interface used for the site meta VPN component is configured in a public subnet that has the site meta VPN ISID.

[0018] In a segmented SPB network embodiment, configuring the public Fabric VPN ISID and / or the public site meta VPN ISID also includes associating the ISID VPN type in the VRF of each SBN.

[0019] In an embodiment of a segmented SPB network, a route distribution strategy is applied to exchange Layer 3 routes between inter-site networks and intra-site networks.

[0020] In a segmented SPB network embodiment, the Layer 3 VPN component presents a Layer 3 interface based on IPv4 and / or IPv6.

[0021] In another aspect, various embodiments of the present technology provide a site boundary node (i.e., SBN) of a local site with a unique site ID, the SBN being located in an MS-SPB network having an ISIS network topology for SPB, the SBN being configured to: - Local nodes connected to the local site via the SPB ISIS Level 1 interface to form an intrasite network operating in SPB ISIS Level 1; - Remote SBNs connected to remote sites in the MS-SPB network via SPB ISIS Level 2 interfaces to form an inter-site network operating at SPB ISIS Level 2; - Divided into Layer 3 VPN components, each corresponding Layer 3 VPN providing end-to-end Layer 3 connectivity across tunnel endpoints, such Layer 3 VPN components include at least: - A Fabric VPN component configured to advertise all Layer 3 routes within the intra-site network of a local site to all remote sites in the MS-SPB network over an inter-site network; and - A site meta VPN component that is configured to advertise all Layer 3 routes within the site's intranet on the local site. Each of the Fabric VPN component and the Site Meta VPN component is configured with a gateway IP interface, which is configured to route Layer 3 traffic from a local node of a local site to a remote node of a remote site in the MS-SPB network over the inter-site network.

[0022] In SBN implementations, the Layer 3 VPN component presents a Layer 3 interface based on IPv4 and / or IPv6.

[0023] In the context of this specification, unless otherwise expressly stated, “computing system” may refer to, but is not limited to, “electronic device,” “operating system,” “system,” “computer-based system,” “controller unit,” “monitoring device,” “control device,” and / or any combination of the foregoing suitable for the relevant task at hand.

[0024] In the context of this specification, the term "FPGA" is intended to include field-programmable gate array computing systems (such as Xilinx VU9P or Intel Stratix V, etc.) that were commercially available at the time of filing of this patent application, as well as any equivalent technologies (whatever their name may be) that exist in computing system hardware that can be programmed by software.

[0025] In the context of this specification, the term "processor" is intended to include a single dedicated processor, a single shared processor, or multiple independent processors (some of which may be shared). In some aspects of this technology, a processor can be, for example, a general-purpose processor (such as a central processing unit (CPU)), a processor dedicated to a specific purpose, or a processor implemented in an FPGA. Other conventional and / or custom hardware may also be included.

[0026] In the context of this specification, unless otherwise expressly stated, the term "memory" is intended to include random access memory systems commercially available at the time of filing this patent application, as well as any equivalent technologies (whatever their name may be) that are subsequently available and exist in computing system media used to store digital information. An example of such memory may be a four-times data rate (QDR) static random access memory (SRAM).

[0027] In the context of this specification, the functional steps shown in the figures can be provided using dedicated hardware and hardware capable of executing software in association with appropriate software.

[0028] In the context of this specification, "a" computer-readable medium and "the" computer-readable medium should not be construed as the same computer-readable medium. Rather, where appropriate, "a" computer-readable medium and "the" computer-readable medium may also be construed as a first computer-readable medium and a second computer-readable medium.

[0029] In the context of this specification, unless otherwise expressly stated, the words “first,” “second,” “third,” etc., are used only as adjectives to distinguish the nouns they modify, and not to describe any particular relationship between those nouns.

[0030] The implementations of this technology each have at least one of the above-described objectives and / or aspects, but not necessarily all of them. It should be understood that some aspects of this technology, developed in an attempt to achieve the above objectives, may not satisfy those objectives and / or may satisfy other objectives not specifically described herein.

[0031] Additional and / or alternative features, aspects and advantages of this technical implementation will become apparent from the following description, drawings and appended claims. Attached Figure Description

[0032] To better understand this technology, as well as other aspects and further features, reference will be made to the following description used in conjunction with the accompanying drawings, wherein: Figure 1 An exemplary architecture of a segmented MS-SPB network to which this technology can be applied is shown; Figure 2 It shows the span Figure 1 MS-SPB Layer 3 connectivity in an example network; Figure 3a and Figure 3b It shows in Figure 1 The example network shows the SPB distributed using the ISIS control plane in the case of a Layer 3 inter-site connection between two sites; Figure 4 Indicates used for Figure 3a and Figure 3b The forwarding data path between two sites in a Layer 3 connection between sites; Figure 5a and Figure 5b It shows in Figure 1 In the example network, where there is an inter-site Layer 3 connection between two sites, ECMP is provided by routing in the ISIS control plane distribution based on SPB. Figure 6 The computer-implemented method steps according to various aspects of this technology are described; and Figure 7 Examples of computing systems that can be used to perform the methods and process steps according to this technology are shown.

[0033] It should be noted that, unless otherwise expressly stated herein, the accompanying drawings are not drawn to scale. Furthermore, the same elements share the same reference numerals from one figure to the next. Detailed Implementation

[0034] The examples and conditional language listed herein are primarily intended to help readers understand the principles of this technology, rather than limiting its scope to such specific examples and conditions. It should be understood that those skilled in the art can devise various arrangements that, while not explicitly described or shown herein, still embody the principles of this technology and are included within its spirit and scope.

[0035] Furthermore, to aid understanding, the following description illustrates a relatively simplified implementation of this technology. Those skilled in the art will understand that various implementations of this technology may involve greater complexity.

[0036] In some cases, examples that are considered helpful to modifications of this technology may also be illustrated. This is done merely to aid understanding and again not to limit the scope of this technology or to define its boundaries. These modifications are not an exhaustive list, and those skilled in the art can make other modifications that still fall within the scope of this technology. Furthermore, the absence of examples illustrating modifications should not be construed as impossibility of making any modifications and / or as describing the only way to implement that element of this technology.

[0037] Furthermore, all statements herein that enumerate the principles, aspects, and implementations of the present technology, and specific examples thereof, are intended to cover their structural and functional equivalents, whether they are currently known or will be developed in the future. Therefore, for example, those skilled in the art will understand that any block diagram herein represents a conceptual view of an illustrative circuit embodying the principles of the present technology. Similarly, it should be understood that any diagrams, flowcharts, state transition diagrams, pseudocode, etc., represent a variety of processes that can be adequately represented in a non-transitory computer-readable medium and thus executed by a computer or processor, whether or not such computer or processor is explicitly shown.

[0038] A software module, or a simple module implied as software, may be represented herein as any combination of diagrammatic elements or other elements indicating process steps and / or textual descriptions of execution. Such a module may be executed by hardware, whether explicitly or implicitly shown. Furthermore, it should be understood that a module may include, for example, but not limited to, computer program logic, computer program instructions, software, a stack, firmware, hardware circuitry, or combinations thereof, providing the required capabilities.

[0039] With this foundational knowledge in mind, we will now consider some non-limiting examples to illustrate the various ways in which aspects of this technology can be implemented.

[0040] Figure 1 An exemplary architecture for a segmented MS-SPB network to which this technology can be applied is shown. As more fully described in the aforementioned PCT patent application WO2025 / 005920, this architecture includes i sites 102 i (Four examples are shown). 102 per site i It may include: - j 104 backbone edge bridges (BEB) with j>=0 ij (102 per site) i (Examples are given for j=1 and j=2); and - k 103 backbone core bridges (BCB) with k>=0 ik (102 per site) i (Example: k=0 or k=1) And it can be done through: - l 105 Site Boundary Nodes (SBN) il (102 per site) i of l =1 or l (For example, =2) It is then connected to the Level 2 SPB network 101.

[0041] 105 per SBNil It can be connected to BCB 103 via Level 1 interface. ik And BEB 104 ij It connects to the Level 2 SPB network 101 via the Level 2 interface.

[0042] A hierarchical SPB network, MS-SPB network 100, is implemented, operating in a multi-site (MS) topology and providing hyperscalability and secure access between sites. This MS-SPB network 100 is deployed as a segmented SPB network, with segments consisting of local sites 102 connected via a core-level 2 SPB network 101. i It consists of at least two components.

[0043] Station 102 i The nodes within and SBN 105 il Together, they run on SPB using ISIS Level 1, establishing Level 1 adjacency relationships. Connecting site 102. i The nodes then run at SPB using ISIS level 2.

[0044] 102 per site i Identified by a unique site ID, and optionally by a site name. "Unique" here means that each site has a different site ID. Optionally, the site ID can be based on geographic location, such as the geographic location of a set of nodes of the site. Each site has 102 unique IDs. i Its distinguishing feature is the designated gateway node: SBN 105, which facilitates inter-site communication. il SBN 105 il Interconnections are made using circuits specified for Level 2 operation to form Level 2 adjacency relationships in Layer 2 SPB network 101. Inter-site connectivity is provided by Level 2 SPB network 101. Since the entire deployment is unified under a single SPB network, those skilled in the art will clearly understand that network service resources such as Instance Service Identifier (ISID) and Virtual Private Network (VPN) routing can be used across site 102. i It is carried to provide seamless accessibility across multiple sites, enabling both Tier 2 and Tier 3 accessibility simultaneously.

[0045] The resource utilization of the SPB protocol's control plane and data plane is distributed across 102 sites running in the Level 1 network. i Between Level 2 SPB network 101. For a given i Site 102 i All nodes may only have other local nodes (BEB 104) ij and BCB 103ik ) and the gateway node within the site (SBN 105) il The visibility of the link-state packet (LSP) is limited to the site-local node. Similarly, a level 2 SPB network 101 may only have visibility across all sites 102. i SBN 105 il Visibility. LSP distribution is limited to SBN 105. il All inter-site connections are via SBN 105. il It was achieved.

[0046] Unicast Layer 3 Connection : Those skilled in the art will understand that Figure 1 The MS-SPB network 100 is based on bridging connections within the same ISID across multiple sites. The following presents a solution for unicast Layer 3 connections, specifically a solution for ISID-based routing connections between Layer 3 VPN services based on BEB, conforming to RFC 6329 (and the IEEE 802.1aq standard) and utilizing the Layer 3 VPN TLV defined in the RFC to support Layer 3 VPN routing between service connections based on SPB ISID.

[0047] The Layer 3 inter-site connectivity in this technology is established based on each Virtual Router and Forwarder (VRF). A VRF provides a segmentation method for network IP routes (Layer 3) (where VLANs provide network segmentation at Layer 2). Therefore, multiple VRFs may exist in the network, each containing a set of router interfaces (forwarding tables).

[0048] RFC 4364 provides detailed information on VRF-based Layer 3 segmentation. A per-VRF-based VPN mechanism is used in the MS-SPB network 100 overlay to provide routing capabilities between BEBs of MS-SPB network 100. While the setup and operation of a Layer 3 VPN for multi-site Layer 3 connectivity in VRF-X is described below, similar setups can be performed in other VRFs of the network to establish inter-site reachability.

[0049] As those skilled in the art will know, each node in the network will have a route repository, commonly referred to as a global routing table. Individual VRF segments of a node can register, export, and import routes in this repository. The SPB ISID-based VPN interface will also obtain (import) local routes from this repository to advertise them to other nodes in the network using the SPB control plane. When the VPN receives routes from other SPB nodes in the network, it will export those remote routes to this repository. Policies can be defined to control the scope of route redistribution between the VRF and the VPN, thus providing fine-grained control over which routes can be exported or imported into the VRF to establish Layer 3 connections with remote resources.

[0050] Figure 2 Showing cross Figure 1 The example network implements the features of unicast Layer 3 connectivity. SBN 105 il It is divided into two components: - Inter-site components (e.g.) Figure 2 China targets SBN 105 12 202 shown 12 ), which is used to advertise route reachability on the Level 2 SPB network 101 within the core network structure of a Layer 3 VPN (hereinafter referred to as "Fabric VPN," a service responsible for advertising all local routes within a site to remote sites on the MS-SPB network); and - Site Meta VPN component (e.g.) Figure 2 China targets SBN 105 12 201 shown 12 ), used to make route reachability announcements within a site / meta-level 1 network (e.g., site 1 1021).

[0051] The Layer 3 segmentation and Layer 3 connections between sites in the MS-SPB network are achieved through SBN 105. il This is accomplished by configuring the gateway interfaces in both components as follows. Inter-site routing from the local site's BEB to the remote site's BEB is facilitated by these gateway interfaces.

[0052] Fabric VPN componentsTo ensure Layer 3 connectivity in the core network operates within an ISID dedicated to such a core network: On each SBN of the MS-SPB network participating in Layer 3 VPN route distribution, a public Fabric VPN service (identified as "ISID X") is configured for each VRF. The Fabric VPN for the SBN is set up in a public "subnet [X]", and each SBN has a unique IP interface set up within the designated subnet of Fabric VPN ISID X. Therefore, the Fabric VPN interface acts as a gateway for routing between SBNs in the Level 2 SPB network 101. The Fabric VPN service operates within the core network (Level 2 SPB network 101) and can form tunnels only between SBNs (inter-site nodes).

[0053] It's important to note that if a site does not wish to initiate inter-site Layer 3 connections, its SBN will not have Fabric VPN ISID X configured. In this case, the site will not advertise any of its site-local routes (intra-site routes) to other SBNs in the inter-site network.

[0054] It's important to note that if Fabric VPN ISID X has ever been configured in the local site's BEB, the SBN will ignore any similar ISID X advertised to the local site's SBN from any BEB, because the same ISID X has already been designated as Fabric VPN. As a result, if such an ISID is operating within the local site, it will only provide intra-site tunneling bridging, not inter-site bridging. For these reasons, network administrators are likely to avoid configuring Fabric VPN ISID X in this way in the BEB.

[0055] Site Meta VPN Component To enable Layer 3 intra-site connectivity or routing from the BEB to the SBN, a dedicated ISID is configured between the BEB and the SBN. This ISID is identified as the "Site Meta VPN". The Site Meta VPN is the intra-site gateway and is responsible for advertising all remote routes of the inter-site MS-SPB network to the BEB of the local site that has a tunnel connection with the SBN.

[0056] The site meta VPN ISID service is configured on each VRF on the local SBN. Note that this is on the same VRF where the Fabric VPN was configured above. This ISID service is also configured on the local site BEB, which needs to advertise its local prefix routes to the MS SPB network, thus establishing a tunnel path from BEB to the local site SBN within the site meta VPN. The site meta VPN has a unique gateway interface configured within its configured subnet.

[0057] Since multiple peering SBNs may be running on any local site to provide all-active multipath connectivity in the MS-SPB network, the site meta VPN is configured in the same way on all local peering SBNs of the site. The site meta node (as an SMN LSP) advertised to the local site node by the SBN therefore contains a single site meta VPN gateway interface associated with the site meta VPN ISID. Furthermore, the SBN automatically generates the site meta node MAC address as the virtual MAC address for the site meta VPN gateway interface. The same site meta node MAC address is applied to the site meta VPN for all VRFs. This identical site meta VPN configuration on all SBNs of the local site is to provide an anycast gateway IP interface and anycast gateway MAC address to be advertised to the site's local BEB by the site meta node.

[0058] Therefore, the Site Meta VPN interface acts as a routing gateway for routing remote site-to-site prefix routes from the local node of the site (BEB) to the local SBN. The Site Meta VPN service operates in a Level 1 SPB network, thus allowing tunnel bindings to nodes within the site to be formed only.

[0059] To represent any given SBN as either a Fabric VPN component or a site meta VPN component, during the setup of the Layer 3 VPN ISID on the SBN, a new attribute is associated with the ISID service configured on the SBN: ISID VPN Type (Site Meta VPN vs. Fabric VPN). This VPN type enables the SPB to enforce, using the ISIS protocol, that ISIDs with a VPN type having a site meta VPN operate only within the intra-site domain, while ISIDs with a VPN type having a Fabric VPN operate only between the site domains. This allows the system to impose run-level checks during ISID tunneling connections, ensuring that the VPN operates only at the level (1 or 2) in which it is configured. If no ISID VPN type is specified, the ISID will not be considered a Layer 3 VPN gateway for this SBN.

[0060] Therefore, the configuration properties for SBN Layer 3 VPN include: - Configure a Layer 3 VPN ISID with associated VPN attributes (i.e., Fabric VPN or Site Meta VPN) to ensure that only tunnels within the same domain (Level 1 or Level 2) can be bound to the service: ISID <id>vpn-type<FabricVPN | Site Meta VPN | Layer 2 VPN> The default value is<Layer 2 VPN> (Service extension, i.e.: such a Layer 2 VPN can advertise ISIDs in intra-site and inter-site connections within the SBN, making the ISIDs available to provide bridging connections between BEBs between sites.) - Bind the ISID to the associated VRF and apply a redistribution policy to exchange routes between inter-site Layer 3 VPNs and intra-site Layer 3 VPNs; - Apply site-specific routing distribution policies and route label-based policies as needed to control routes exported and imported into the Routing Information Base (RIB) of the VRF to / from the site meta VPN and Fabric VPN.

[0061] For BEBs that need to advertise local prefixes learned from the VPN's VRF to remote sites and receive prefix routes from remote sites, they must be configured with the same Layer 3 VPN service with site-meta VPN attributes and the same IP address (within the same subnet of the site-meta VPN). The site-meta VPN ISID should be unique within a site. Each site can define its own per-VRF site-meta VPN.

[0062] Sequence of setup steps for route distribution The first sequence implements route distribution between BEB and site meta nodes (within the site), while the second sequence implements route distribution between SBNs (between sites) in the MS-SPB network.

[0063] Based on the first sequence, the following steps can be performed: - For BEB: - Create an ISID identical to the site meta VPN and establish an SPB tunnel to the local SBN; - Create a VRF-based IP interface in the same subnet as the site meta VPN; - Establish a routing distribution policy between the VRF and the VPN ISID / gateway tuple; - Export prefix routes from VRF; - Import the prefix route from ISID to VRF.

[0064] - For SBN (as a site meta node; configured identically on all peering SBNs): - Create an ISID with site meta VPN attributes; - Create a VRF-based IP interface for the site meta VPN ISID (configured in mirror mode on all peering SBNs). - Establish a routing distribution policy between the VRF and the site meta VPN ISID / gateway tuple; - Redistribute all routes from Fabric VPN to Site Meta VPN (for intra-site distribution). - Import all routes from the site meta VPN to the VRF (for route reachability in the data plane).

[0065] Based on the second sequence, the following steps can be performed for each SBN: - Create an ISID with Fabric VPN attributes; - Create a VRF-based IP interface for the Fabric VPN ISID; - Establish a routing distribution policy between the VRF and the Fabric VPN ISID / gateway tuple; - For routes learned from a remote SBN, capture the site ID associated with that route; - Redistribute all routes from the site meta VPN to the Fabric VPN (for inter-site distribution); - Import all routes from Fabric VPN to VRF (for route reachability in the data plane).

[0066] It's important to note that because Fabric VPN and Site Meta VPN operate at different tiers, they do not need to be mapped to the same ECT. Similar to Layer 2 VPNs (Service Extensions), each tier can operate within a different ECT allocation set.

[0067] It should also be noted that although the above sequences are labeled "first" and "second", this technique does not imply that these sequences must be executed in a specific order.

[0068] Route announcement In both Fabric VPN and Site Meta VPN scenarios described above, route advertisement (distribution) can be accomplished using TLV 184 (prefix routing based on IPv4) or TLV 185 (prefix routing based on IPv6) of LSP frames in the standard "Implementation of SPB with ISIS". This is used, for example, for Layer 3 VPN route distribution, but only for route distribution within a site.

[0069] Then, the TLV can contain information about the following: - The ISID associated with this VPN, and the ECT / BVLAN of that ISID; and - The VPN's gateway IP address; this gateway information may be followed by a list of advertised routes reachable through this gateway. Each route may also include additional sub-TLV attributes consisting of prefix length, prefix value, route hop count, and route label. The route label attribute can be used, for example, to enable additional filtering capabilities when the advertised routes are imported into the RIB.

[0070] Equal Cost Multipath (ECMP) based routing: ECMP-based routing can be used to improve efficiency and redundancy in routing between remote sites. Routes can be advertised via multipath reachability within intra-site MS-SPB networks or inter-site MS-SPB networks, as Fabric VPN and site meta VPN can be configured to provide multipath reachability.

[0071] When ECT paths exist between nodes in an MS-SPB network, VPN configurations can leverage the MS-SPB site metanode design and utilize all available local SBNs to route traffic between sites. This is particularly true when ECT paths exist between the site metanodes of the BEB and SBN. ECMP deployments can be achieved by providing multiple gateway paths to route to remote subnets. Each site is configured with multiple Layer 3 VPN ISIDs operating in different ECTs to provide multipath reachability. Such multipath ISIDs can also be provided for Fabric VPNs when ECT paths exist in the core network.

[0072] Providing ECMP-based routing can improve the load balancing and redundancy of Layer 3 routing in MS-SPB networks.

[0073] Therefore, network administrators can choose to deploy each site in a Spine-and-Leaf model, where SBNs constitute the Spine and BEBs constitute the Leaf. In the core network, Spine nodes can be fully mesh-connected or connected to a common forwarding plane (shared plane) to establish direct connections between all SBNs. Thus, both intra-site and inter-site networks can be configured with multi-path routing, where each ECT / BVLAN of the SPB network can be associated with a dedicated path.

[0074] The hierarchical segmentation of Layer 3 VPNs on each SBN, serving as both site meta VPNs (for local site routing reachability) and Fabric VPNs (for core network routing reachability), provides additional capabilities in MS-SPB network deployments: Fabric VPN deployments can be replaced by different overlay deployments (i.e., the Level 2 SPB core can be replaced by services in the core network such as MPLS, Vxlan, or EVPN overlays), which is agnostic to Layer 3 VPN operations in intra-site networks that rely solely on site meta VPNs. This allows customers to flexibly select the optimal overlay deployment for the core network based on their network needs and management operations, independent of intra-site network operations. Furthermore, site-based and route label-based policies provide greater granularity and security for inter-site route propagation.

[0075] It should be noted that in this specification, the terms "gateway interface," "IP interface," and "VPN interface" all refer to Layer 3 IP subnet interfaces based on IPv4 and IPv6. Therefore, the proposed technology is applicable to both IPv4 and IPv6 inter-site unicast routing.

[0076] Example of inter-site routing in an MS-SPB network: Figure 3a and 3b It shows in Figure 1 This example illustrates SPB route distribution using the ISIS control plane in a network where there is a Layer 3 inter-site connection between two sites. This is an example of route distribution between BEB nodes at two different sites, with a single-path reachability route.

[0077] SPB ISIS TLV 184 (IPv4-based prefix routing) is used in both Level 1 and Level 2 networks to advertise routes across site boundaries using the aforementioned mechanism.

[0078] In the level 1 network of local site 1021, for site meta node SMN1 ( Figure 3a and Figure 3b Example illustration of 3021), in the level 1 network of local site 1022, for site meta node SMN2 ( Figure 3a and Figure 3b Example illustration is provided for 3022).

[0079] Figure 3a Special notes were given regarding the VRF (VRF-X) during configuration: - Appendix label 3104 11 and 3104 21 They represent BEB B1 104 respectively 11 And BEB B2 104 21 Example configuration; - Appendix label 3105 11 3105 12 and 3105 21 They represent SBN A 105 respectively 11 SBN B 105 12 and SBN C105 21 Example configuration.

[0080] Figure 3b Special notes on route management (export / import and redistribution): - Appendix label 3204 11 Represents BEB B1 104 11 Example routing table; - The reference numerals 32051 and 32052 in the attached diagram represent SBN A 105, respectively. 11 And SBN B 105 12 (The same) and SBN C105 21 Example routing table; - Figure reference numerals 306 to 308 are BEB B2 104 21 With SBN C 105 21 Between, SBN C 105 21 With SBN A105 11 Or SBN B 105 12 Between, and SBN A 105 11 Or SBN B 105 12 With BEB B1 104 11 Example LSP frames between; - Figure 305 represents: - To be determined by BEB B2 104 21 External routes advertised to SMN2 3022: - To be determined by SBN C 105 21 External routes announced to internal sites; and - Staying remotely SBN SBN A 105 11 And SBN B 105 12 The above notification was sent by SMN1 3021 to BEB B1 104. 11 External routes.

[0081] At each step in each node, the node's Layer 3 VPN acts as a gateway for that external route.

[0082] More specifically, according to the first sequence mentioned above (routing distribution between BEB and site meta nodes (within the site)): - For BEB B2 104 21 and BEB B1 104 11 : - BEB B2 104 21 : Create and use VPN1 (3104) with site meta 21 The same ISID (ISID4000:ECT-1), and in BEB B2 104 21 And SBN C 105 21 Establish an SPB tunnel between them; - BEB B1 104 11 : Create and use VPN1 (3104) with site meta 11 The same ISID (ISID3000:ECT-1), and as determined by ECT in BEB B1 104 11 with SBN A 105 11 Or SBN B 105 12 An SPB tunnel will be built between one of them; - Create a subnet on the same network as site meta VPN1 (20.20.20.X / 24, see Figure 3b The IP interface in 305); - Establish SPB IP VPN binding between VRF and VPN1 ISID / gateway tuple; - Exporting prefix routes from VRF - Import the prefix route from ISID to VRF; - For SBN SBN A 105 11 SBN B 105 12 And SBN C 105 21 (As a site meta node, the same configuration applies to SBN A 105) 11 And SBN B 105 12 ): - SBN C 105 21 : Create (3105) 21 ISID (ISID4000:ECT-1) - SBN A 105 11 And SBN B 105 12 : Create (3105 respectively) 11 and 3105 12 )ISID(ISID3000:ECT-1); - Create an IP interface for the site meta VPN1 ISID (SBN A 105) 11 And SBN B 105 12 (Image configuration on the image). - Create an SPB IP VPN binding between the VRF and the site meta VPN1 ISID / gateway tuple; - Redistribute all routes from Fabric VPN1 to Site Meta VPN1 (for intra-site distribution). - Import all routes from site meta VPN1 into VRF (for route reachability in the data plane).

[0083] More specifically, based on the second sequence mentioned above (routing distribution between SBNs (sites) in the MS-SPB network), for SBN SBN A 105 11 SBN B 105 12 And SBN C 105 21 : - Create a VPN with Fabric VPN1 attribute (3105) 11 3105 12 3105 21 ) ISID (ISID5000:ECT-1); - Create an IP interface for Fabric VPN1 ISID; - Establish SPB IP VPN binding between VRF and Fabric VPN1 ISID / gateway tuple; - SBN SBN A 105 11 And SBN B 105 12 For remote SBN C 105 21 For each learned route, capture the site ID associated with that route (2.2.2). - SBN C 105 21 For remote SBN A 105 11 And SBN B 105 12 For each learned route, capture the site identifier associated with that route (1.1.1); - Redistribute all routes from Site Meta VPN1 to Fabric VPN1 (for inter-site distribution); - Import all routes from Fabric VPN1 into VRF (for route reachability in the data plane).

[0084] Figure 4 represent Figure 3a and Figure 3b This refers to the forwarding data path used for Layer 3 connections between two sites. As shown in the figure, when two BEB 104... 11 and 104 21 During connection, the data forwarding path between sites consists of three different segments: 404, 405, and 406.

[0085] The inbound section within the station is 404, including BEB B1 104. 11 The SPB frame will be routed to the hosted server at SBN 105. 11 and 105 12 The site meta node is SMN1 3021. The encapsulation here will be in BEB B1 104. 11 The source address (MAC_SA) is used, with the site metanode SMN1 3021 address as the destination address (MAC_DA). Here, the destination MAC-DA SMN1 is a network-unique site metanode system ID, generated by concatenating a 3-byte OUI and a 3-byte site ID. (BEB B1 104) 11 Based on BEBB1 104 11 Calculate the shortest path between SMN1 and 3021, and establish a tunnel endpoint that leads only to one of the local sites SBN.

[0086] In SBN (in the case shown, SBN A 105) 11 After the tunnel on CE1501 terminates, 11 The MAC address is used to point to BEB B1 104 11 SBN A 105 of the tunnel 11 Learned. SBN A 105 11 This will determine that the destination MAC address of SMN1 is its own address for the Layer 3 interface VRF-X:VPN1 targeting ISID-ID1. SBN A 105 11 A Layer 3 route lookup will be initiated in VRF-X to determine the destination IP of the frame. If the lookup is successful, the frame will be routed to the remote SBN (SBN C 105 in the case shown). 21 The source address of the frame will be modified to SBN A 105. 11 The router's MAC address, and the destination address was modified to match SBN C 105. 21 The MAC address of the router associated with the Fabric VPN1 service. Then, the frame is encapsulated with an SPB ISIS header and bridged to SBN C 105. 21 Normal routing operations, such as MTU checks and TTL updates, will be performed as part of the routing process.

[0087] Inter-site transmission segment 405, in which SPB frames are transmitted from the local site's SBN (SBN A105 in the indicated case). 11 The SBN (SBN C 105 in the indicated case) is forwarded to the remote site. 21 ).

[0088] When the tunnel terminates, the SPB frame is decapsulated and the internal routing frame is replaced by the SBN (in this case, SBN C105). 21 The frame's source address is the sender's SBN (SBN A 105). 11 The address of ) and used to point to SBN A 105 11 The tunnel of SBN C 105 21 I learned this from above. SBN C 105 21 Next, we will determine SBN C 105. 21 The destination MAC address is its own address for the Layer 3 interface VRF-X:Fabric VPN1 for ISID-ID1. This SBN will initiate a Layer 3 route lookup in VRF-X for the destination IP of the frame. If the route lookup is successful, then SBN C 105 21 The site's egress segment 406 will route frames encapsulated in route SPB to the local BEB B2 104. 21 The source node here will be used for hosting on SBN C 105. 21 The site meta node's SMN2 3022 address was modified, and the destination address was changed to match BEB B2 104. 21 The MAC address of the router associated with VPN1 service. Normal routing operations, such as MTU checks and TTL updates, will be performed as part of the routing process. BEB B2 104 21 This frame will then be routed to CE2 501. 21 .

[0089] The forwarding here will be based on CE2 501. 21 The goal is to successfully find the MAC address. If the address is not found on the SBN, it will be flooded to all Level 1 tunnels of ISID-ID1. A split horizon check will prevent the frame from being flooded to Level 2 tunnels of ISID-ID1 to avoid creating loops in the inter-site network.

[0090] Figure 5a and 5b It shows in Figure 1 In the example network, where there is an inter-site Layer 3 connection between two sites, ECMP-based routing is provided in the SPB control plane distribution using ISIS. This is an example of an ECMP deployment that provides multiple gateway paths to route to remote subnets. Each site has multiple Layer 3 VPN ISIDs running in different ECTs to provide multi-path reachability. According to the mechanism described above, the multiple ISIDs are set up in both the intra-site network (as a site meta VPN) and the inter-site network (as a Fabric VPN).

[0091] exist Figure 5a superior: - Appendix label 5104 11 and 5104 21 These represent the components used in BEB B1 104. 11 And BEB B2 104 21 Example configuration; - Appendix label 3105 11 3105 12 3105 21 and 3105 22 These represent the components used in SBN A 105. 11 SBN B105 12 SBN C 105 21 And SBN D 105 22 Example configuration.

[0092] exist Figure 5b superior: - Appendix label 5204 11 Represents BEB B1 104 11 Example routing table; - The reference numerals 52051 and 52052 in the attached diagram represent SBN A 105 respectively. 11 And SBN B 105 12 (The same) and SBN C105 21 And SBN D 105 22 (The same) example routing table; - Figure reference numerals 506-508 are BEB B2 104 21 With SBN C 105 21 Or SBN D 105 22 Between, SBN C105 21 Or SBN D 105 22 with SBN A 105 11 Or SBN B 105 12 Between, and SBN A 105 11 Or SBN B 105 12 With BEB B1 104 11 Example LSP frames between; - Attached figure 505 represents: - To be determined by BEBB2 104 21 The external route is advertised to SMN 2 3022; - To be determined by SBN C 105 21 And SBN D 105 22 Announcements to external routes between sites; and - In remote SBN SBN A 105 11 And SBN B 105 12 The above information is to be communicated to BEB B1 104 by SMN1 3021. 11 External routes.

[0093] At each step in each node, the node's Layer 3 VPN acts as a gateway for that external route.

[0094] More specifically, according to the first sequence mentioned above (routing distribution between BEB and site meta nodes (within the site)): - For BEB B2 104 21 and BEB B1 104 11 : - BEB B2 104 21 : Create and use VPN1 (5104) with site meta 21 The same ISID (ISID4000:ECT-1) and the same site meta VPN2 (5104) 21 The same ISID (ISID3000:ECT-1), and respectively in BEB B2 104 21 With SBN C 105 21 And SBN D 105 22 Establish an SPB tunnel between them; - BEB B1 104 11 : Create and use VPN1 (5104) with site meta 11 The same ISID (ISID3000:ECT-1) and the same site meta VPN2 (5104) 11 The same ISID (ISID4000:ECT-1), and respectively in BEB B1 104 11 with SBN A 105 11 And SBN B 105 12 Establish an SPB tunnel between them; - Create a subnet located in the same subnet as Site Meta VPN1 or Site Meta VPN2 (20.20.20.X / 24, see [link]). Figure 5b The IP interface in the 505 error message; - Establish SPB IP VPN bindings between VRF and VPN1 ISID / gateway tuples and VPN2 ISID / gateway tuples; - Export prefix routes from VRF; - Import the prefix route from ISID to VRF; - For SBN SBN A 10511, SBN B 10512, SBN C 10521 and SBN D 10522 (as site meta nodes; the same configuration applies to SBN A 10511 and SBN B 10512, and SBN C 10521 and SBN D 10522 respectively): - SBN C 105 21 And SBN D 105 22 Create ISIDs (ISID4000:ECT-1 for VPN1 and ISID3000:ECT-1 for VPN2) (5105) 21 and 5105 22 ) - SBN A 105 11 And SBN B 105 12 Create ISIDs (ISID3000:ECT-1 for VPN1 and ISID4000:ECT-1 for VPN2) (5105) 11 and 5105 12 ); - Create IP interfaces for the ISIDs of site elements VPN1 and VPN2 (in SBN A 105 respectively). 11 And SBN B 105 12 and SBN C 105 21 And SBN D 105 22 (Image configuration on the image). - Create an SPB IP VPN binding between the VRF and the site meta VPN1 and VPN2 ISID / gateway tuples; - Redistribute all routes from Fabric VPN1 and VPN2 to site meta VPN1 and VPN2 respectively (for intra-site distribution). - Import all routes from site meta VPN1 and VPN2 into VRF (for route reachability in the data plane).

[0095] More specifically, based on the second sequence mentioned above (routing distribution between SBNs (sites) in the MS-SPB network), for SBN SBN A 105 11 SBN B 105 12 SBN C 105 21 And SBN D 105 22 : - Create an ISID (ISID5000:ECT-1) with Fabric VPN1 attribute and an ISID (ISID6000:ECT-1) with Fabric VPN2 attribute (5105) 11 5105 12 5105 21 and 5105 21 ); - Create IP interfaces for Fabric VPN1 ISID and Fabric VPN2 ISID; - Establish SPB IP VPN bindings between VRF and Fabric VPN1 and VPN2 ISID / gateway tuples; - SBN SBN A 105 11 And SBN B 105 12 For remote SBN C 105 21 Or SBN D 105 22 For the learned routes, capture the site ID associated with that route (2.2.2). - SBN SBN C 105 21 And SBN D 105 22 For remote SBN A 105 11 Or SBN B 105 12 For the learned routes, capture the site ID (1.1.1) associated with that route. - Redistribute all routes from site meta VPN1 to Fabric VPN1 and from site meta VPN2 to Fabric VPN2 (for inter-site distribution). - Import all routes from Fabric VPN1 and Fabric VPN2 into VRF (for route reachability in the data plane).

[0096] Figure 6 The steps of a computer-implemented method according to one aspect of the present technology are described.

[0097] In step 601, the method includes partitioning each of the site boundary nodes, i.e., SBNs, of any given site in an MS-SPB network that is a local site and includes at least two sites and an ISIS network topology for SPB, into: (i) a FabricVPN component configured to advertise all Layer 3 routes within the local site's intranet to all other sites in the MS-SPB network that are remote sites on an internet operating at ISIS Level 2 for SPB between all SBNs; and (ii) a site meta VPN component configured to advertise all Layer 3 routes within the local site's intranet on an intranet operating at ISIS Level 1 for SPB between each node of the local site and all SBNs of the local site.

[0098] In step 602, the method includes providing a gateway IP interface in each of the Fabric VPN component and the site meta VPN component, the gateway IP interface being configured to route Layer 3 traffic from a node of a local site to a node of a remote site in the MS-SPB network on the inter-site network.

[0099] The methods and procedures described above can be implemented in a computing system, and non-limiting examples can be found by referring to [reference needed]. Figure 7 As those skilled in the art will understand, such computing systems can be implemented in any other suitable hardware, software and / or firmware or a combination thereof, and can be a single physical entity or several independent physical entities with distributed functionality.

[0100] In some aspects of this technology, the computing system 700 may include various hardware components, including: one or more single-core or multi-core processors (collectively referred to as processor 701), a solid-state drive 702, memory 703, and input / output interfaces 704. In the context of this document, processor 701 may or may not be contained within an FPGA. In some other aspects, the computing system 700 may be an "off-the-shelf" general-purpose computing system. In some aspects, the computing system 700 may also be distributed among multiple systems. The computing system 700 may also be specifically designed to implement this technology. As those skilled in the art will understand, various variations of how the computing system 700 can be implemented can be conceived without departing from the scope of this technology.

[0101] Communication between the various components of the computing system 700 can be achieved through one or more internal buses and / or external buses 705 (such as PCI bus, Universal Serial Bus, IEEE 1394 "Firewire" bus, SCSI bus, Serial-ATA bus, ARINC bus, etc.), with various hardware components electronically coupled to these buses.

[0102] Input / output interface 704 may enable networking capabilities, such as wired or wireless access. For example, input / output interface 704 may include a network interface, such as, but not limited to, a network port, network socket, network interface controller, etc. Those skilled in the art will understand various examples of how to implement a network interface. According to an implementation of this technology, solid-state drive 702 may store program instructions, such as a library, a portion of program instructions for an application, etc., which are suitable for loading into memory 703 and being executed by processor 701 to implement the methods and process steps according to this technology.

[0103] Modifications and improvements to the above embodiments of this technology will be readily apparent to those skilled in the art. The foregoing description is intended to be exemplary and not restrictive. Therefore, the scope of this technology is intended to be limited only by the scope of the appended claims.< / id>

Claims

1. A computer-implemented method for implementing unicast layer 3 connections in a MS-SPB network (100) comprising at least two sites (102 i ) and a SPB using ISIS network topology, wherein each site is assigned a unique site id, wherein: - each of the sites (102 i ) in the MS-SPB network comprises at least one site border node SBN (105 il ) and comprises at least one of an endpoint node (BEB 104 ij ) and an intermediate node (BCB 103 ik ), the at least one of an endpoint node and an intermediate node being connected to at least one SBN by SPB with ISIS level 1 interface to form an intra-site network running in SPB with ISIS level 1, wherein the at least one SBN and the at least one node are each identified by a unique system id; and - all SBNs in the MS-SPB network are connected with ISIS level 2 over SPB to form an inter-site network running ISIS level 2 over SPB; The method comprises: - segmenting each SBN (105 il ) of any given site in the MS-SPB network that is a local site into third layer VPN components, each corresponding third layer VPN providing an end-to-end third layer connection across tunnel endpoints, such third layer VPN components comprising at least: - a Fabric VPN component configured to advertise on the inter-site network all Layer 3 routes within the intra-site network of the local site to all other sites in the MS-SPB network as remote sites; and - a site meta VPN component configured to advertise on the intra-site network of the local site all Layer 3 routes within the intra-site network of the local site; and - providing in each of the Fabric VPN component and the site meta VPN component a gateway IP interface configured to route on the inter-site network Layer 3 traffic from one node of the local site to a node of one of the remote sites in the MS-SPB network.

2. The method of claim 1, further comprising, for all SBNs (105 il ) in the MS-SPB network: configuring a common Fabric VPN ISID in the VRF of each SBN (105 il ); and setting the gateway IP interface for the Fabric VPN component into a public subnet with the Fabric VPN ISID.

3. The method of claim 1, further comprising, for all SBNs (105 il ) and at least one node of each site in the MS-SPB network: - configuring a common site meta VPN ISID in the VRF of each SBN (105 il ) and in the VRF of the node; and - setting the gateway IP interface for the site meta VPN component into a public subnet with the site meta VPN ISID.

4. The method of claim 2 or 3, wherein, configuring the public Fabric VPN ISID and / or the public site meta-VPN ISID further comprises associating an ISID VPN type in a VRF of each SBN (105 il ) 5. The method of claim 4, further comprising applying a route distribution policy to exchange Layer 3 routes between the inter-site network and the intra-site network.

6. The method of claim 2, further comprising, for each SBN of the SBNs (105 il ) of the local site in the MS-SPB network, the Fabric VPN component: - creating the public Fabric VPN ISID with Fabric VPN properties; - creating the gateway IP interface for the Fabric VPN component based on the VRF; - establishing a route distribution policy between the VRF and a tuple consisting of the Fabric VPN ISID and the gateway IP interface created for the Fabric VPN component, including: - receiving the site id associated with each route learned due to SBN (105 il ) advertisement by a remote site in the MS-SPB network; - redistributing all routes from the site meta VPN component to the Fabric VPN component; and - importing all routes from the Fabric VPN component to the VRF.

7. The method of claim 3, further comprising: - for each of the nodes of the local site in the MS-SPB network: - creating a node ISID identical to the node ISID of the site meta-VPN component of the local site and establishing a SPB tunnel to the SBN (105 il ) of the local site; - creating a node gateway IP interface in the same subnet as the site meta VPN component for the local site based on the VRF; - establishing a route distribution policy between the VRF and a tuple consisting of the node ISID created and the node gateway IP created, including: - exporting all prefix routes from the VRF; - importing all prefix routes from the node ISID created to the VRF; - For each SBN (105 il ) in the SBN of the local site in the MS-SPB network: - creating a public site meta VPN ISID with site meta VPN properties; - creating the gateway IP interface for the site meta VPN ISID for the local site based on the VRF; - establishing a route distribution policy between the VRF and a tuple consisting of the site meta VPN ISID created by the Fabric VPN component and the gateway IP interface created for the site meta VPN ISID for the local site, comprising: - redistributing all routes from the Fabric VPN component to the site meta VPN component; - importing all routes from the site meta VPN component to the VRF.

8. The method of any one of claims 1 to 7, wherein, The third layer VPN component presents one of an IPv4 based third layer interface or an IPv6 based third layer interface.

9. A computer readable medium containing computer readable instructions which, when executed by a system, cause the system to perform the method of any one of claims 1 to 8.

10. A segmented SPB network (100) comprising at least two sites (102 i ) and an ISIS network topology for SPB, wherein each site is assigned a unique site id, wherein: - each of the sites (102 i ) in the MS-SPB network comprises at least one site border node SBN (105 il ) and comprises at least one of an endpoint node (BEB 104 ij ) and an intermediate node (BCB 103 ik ), the at least one of an endpoint node (BEB 104 ij ) and an intermediate node (BCB 103 ik ) being connected to the at least one SBN by SPB with ISIS level 1 interface to form an intra-site network running in SPB with ISIS level 1, wherein the at least one SBN and the at least one node are each identified by a unique system id; - all SBNs in the MS-SPB network are connected by SPB ISIS level 2 interfaces to form an inter-site network running in SPB ISIS level 2; - each SBN (105 il ) in the SBNs of any given site in the MS-SPB network is segmented into third layer VPN components, each corresponding third layer VPN providing an end-to-end third layer connection across the tunnel endpoints, such third layer VPN components comprising at least: - a Fabric VPN component configured to advertise on the inter-site network all third layer routes within an intra-site network at the local site to all other sites in the MS-SPB network as remote sites: and - a site meta VPN component configured to advertise on the intra-site network at the local site all third layer routes within the intra-site network at the local site; and - providing a gateway IP interface in each of the Fabric VPN component and the site meta VPN component configured to route third layer traffic from one node of the local site to a node of one of the remote sites in the MS-SPB network on the inter-site network.

11. The segmented SPB network of claim 10, wherein: - a common Fabric VPN ISID is configured in the VRF of each SBN (105 il ) in the MS-SPB network; and - the gateway IP interface for the Fabric VPN component is provided into a public subnet with the Fabric VPN ISID.

12. The segmented SPB network of claim 10, wherein: - in the VRF of each SBN (105 il ) in the MS-SPB network and in the VRF of at least one node of each site in the MS-SPB network, a common site meta VPN ISID is configured; and - the gateway IP interface for the site meta VPN component is provided into a public subnet with the site meta VPN ISID.

13. The segmented SPB network of claim 11 or 12, wherein, configuring the common Fabric VPN ISID and / or the common site meta-VPN ISID further comprises associating an ISID VPN type in a VRF of each SBN (105 il ) 14. The segmented SPB network of claim 13, wherein, A route distribution policy is used to exchange third layer routes between the inter-site network and the intra-site network.

15. The segmented SPB network of any of claims 10 to 14, wherein, The third layer VPN component presents one of an IPv4 based third layer interface or an IPv6 based third layer interface.

16. A site border node, SBN, (105 il ) of a local site (102 i ) with a unique site id in a MS-SPB network (100) having a SPB ISIS network topology, the SBN being configured to:​​​ - local nodes of the local site are connected by SPB ISIS level 1 interfaces to form an intra-site network running in SPB ISIS level 1; - local nodes of the local site are connected by SPB ISIS level 1 interfaces to form an intra-site network running in SPB ISIS level 1; - a remote SBN connected by SPB using ISIS level 2 to remote sites in the MS-SPB network (100) to form an inter-site network running in SPB using ISIS level 2; - segmented into third layer VPN components, each corresponding third layer VPN providing end-to-end third layer connectivity across tunnel endpoints, such third layer VPN components comprising at least: - a Fabric VPN component configured to advertise on the inter-site network all third layer routes located within the intra-site network of the local site to all remote sites in the MS-SPB network; and - a site meta VPN component configured to advertise on the intra-site network of the local site all third layer routes located within the intra-site network of the local site; wherein, a gateway IP interface is provided in each of the Fabric VPN component and the site meta VPN component, the gateway IP interface configured to route third layer traffic from a local node of the local site to a remote node of one of the remote sites in the MS-SPB network on the inter-site network.

Citation Information

Patent Citations

  • BE510411A

  • BE510421A

  • Improving aliasing behavior for traffic to multihomed sites in ethernet virtual private network (EVPN) networks

    CN110324226A

  • Method and system for using is-is for SPB in environment of service providor network

    CN116076058A

  • Routing method of virtual special network

    CN1852214A