A method, system and device for cross-vlan network device discovery and vlan home identification

By hop-by-hop diffusion of discovery requests in a Layer 2 network and combining port semantic determination, the problem of limited network device discovery range and inaccurate VLAN affiliation identification in existing technologies is solved, realizing device discovery and VLAN affiliation identification in multi-level Layer 2 networks.

CN121864530BActive Publication Date: 2026-05-19SHANGHAI BAUD DATA COMM
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANGHAI BAUD DATA COMM
Filing Date
2026-03-17
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing network device discovery technologies have limited scope in multi-VLAN and multi-level Layer 2 networks, making it difficult to accurately identify the VLAN affiliation of terminal devices, and they rely on management VLANs or centralized management protocols.

Method used

A distributed VLAN affiliation identification method based on a Layer 2 discovery mechanism is adopted. The master node generates a discovery request message with a unique identifier and propagates it hop by hop in the Layer 2 network. The network device parses and reconstructs the request message, generates neighbor information and uploads it layer by layer. The VLAN affiliation is determined by combining port semantics.

Benefits of technology

Without relying on management VLANs or centralized management protocols, the discovery and VLAN affiliation identification of network devices and terminal devices in multi-level Layer 2 networks were achieved, covering devices without management capabilities, and the results are consistent with the actual network structure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864530B_ABST
    Figure CN121864530B_ABST
Patent Text Reader

Abstract

The application discloses a network device discovery and VLAN attribution identification method, system and device across VLANs. The method is based on a two-layer discovery mechanism to realize network device and terminal device discovery in a network environment where a multi-level two-layer network coexists with a three-layer forwarding boundary, and dynamically identifies device VLAN attribution in the discovery process. The method can discover devices in a two-layer network step by step without relying on a management VLAN or a centralized management protocol, and can accurately identify device VLAN attribution in the discovery process, thereby effectively overcoming problems in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of computer network technology, specifically relating to a scheme for discovering network devices and terminal devices based on a Layer 2 discovery mechanism in a network environment where multi-level Layer 2 networks and Layer 3 forwarding boundaries coexist, and dynamically identifying the VLAN affiliation of devices during the discovery process. Background Technology

[0002] In existing network operation and maintenance management technologies, network device discovery typically relies on the following methods:

[0003] (1) The broadcast-based discovery mechanism can only discover devices within a single broadcast domain and cannot work across VLANs;

[0004] (2) Link-layer neighbor discovery protocols (such as LLDP and CDP) are mainly used to identify the connection relationship between network devices, but they are difficult to cover terminal devices and do not have the ability to determine VLAN affiliation.

[0005] (3) The centralized discovery method based on management VLAN or management protocols such as SNMP and Netconf relies on the device's management interface and pre-configured management network, and is only applicable to manageable network devices.

[0006] In summary, current mainstream device discovery solutions have the following shortcomings in practical applications:

[0007] (1) The scope of discovery is limited, making it difficult to completely discover all devices in multi-VLAN and multi-level Layer 2 networks;

[0008] (2) Terminal devices typically do not have management interfaces and cannot obtain their VLAN affiliation through existing management methods;

[0009] (3) VLAN information is mostly read as device configuration, and cannot fully reflect the VLAN affiliation of the device in the actual forwarding path;

[0010] (4) When a VLAN is configured only at a certain level of the network, existing technologies make it difficult to accurately determine the VLAN affiliation of downstream devices.

[0011] As prior art, US Patent Application Publication No. US20060002311A1 discloses a topology discovery method for VLAN network environments. This scheme employs a centralized control query model, collecting device and local VLAN configuration information by sending query messages carrying VLAN tags within the broadcast domain of a specified VLAN and receiving response messages. Based on this, by accumulating path information of devices traversed in the messages, the physical connection relationships within the specified VLAN are reconstructed.

[0012] When implemented, this solution relies on a pre-configured database on the device for VLAN information, which is a static configuration read. This solution cannot handle scenarios where VLANs are defined on upstream devices (e.g., terminals accessing the device via a non-smart device), and it cannot dynamically determine the VLAN affiliation of downstream devices on the actual forwarding path.

[0013] Therefore, this existing technology struggles to form a complete end-to-end topology view with logical VLAN affiliation in complex network environments containing a large number of unmanaged Layer 2 devices.

[0014] In summary, there is an urgent need in this field for a technical solution that does not rely on management VLANs or centralized management protocols, can gradually discover devices in a Layer 2 network, and accurately identify the VLAN affiliation of devices during the discovery process. Summary of the Invention

[0015] To address the problems existing in network device discovery technology in current network operation and management technologies, the present invention aims to provide a network device discovery and VLAN affiliation identification scheme that can cross VLANs. This scheme can discover network devices and terminal devices based on the Layer 2 discovery mechanism in network environments where multi-level Layer 2 networks and Layer 3 forwarding boundaries coexist, without relying on management VLANs or centralized management protocols, and dynamically identify the VLAN affiliation of devices during the discovery process, which can effectively overcome the problems existing in the prior art.

[0016] To achieve the above objectives, the present invention provides a method for cross-VLAN network device discovery and VLAN affiliation identification, comprising:

[0017] In the network, at least one network device with VLAN discrimination function is selected and configured as the master node for network device discovery. The master node is configured upstream of the VLAN definition boundary, and the Layer 2 port of the master node is connected to the downstream Layer 2 network.

[0018] The master node generates a unique identifier corresponding to the current discovery behavior, generates a discovery request message based on the generated unique identifier, and sends the discovery request message to all its available Layer 2 ports;

[0019] Other network devices in the network are configured to mark the network device that sent the discovery request message as an upper-layer node after receiving the discovery request message, and reply with their own device information to the upper-layer node that sent the discovery request message as a lower-layer node. At the same time, the current network device will also act as an upper-layer node, reconstruct the discovery request message and send the reconstructed discovery request message to other ports.

[0020] When a network device acting as an upper-layer node receives a discovery response from a corresponding lower-layer node, it generates a neighbor information and sends the neighbor information directly to the corresponding upper-layer node layer by layer until it is sent to the master node.

[0021] Network devices acting as upper-layer nodes in the network also perform VLAN affiliation identification based on the VLAN affiliation identification mechanism, which is based on the neighbor information received from lower-layer nodes and / or the neighbor information formed by parsing the discovery response sent by lower-layer nodes.

[0022] In some embodiments of the present invention, the discovery request message generated by the network device is a link layer control message, which can transmit the request to discover the device in a Layer 2 network.

[0023] In some embodiments of the present invention, in the method, after receiving a discovery request message, the network device parses the received discovery request message, retains the unique identifier in the original discovery request message, replaces the source MAC address in the original discovery request message with the MAC address of the current network device port, and completes the reconstruction of the discovery request message.

[0024] In some embodiments of the present invention, the neighbor information in the method is generated by the unique identifiers of the current node and its corresponding lower-level node, as well as the port information connecting the two.

[0025] In some embodiments of the present invention, the VLAN affiliation identification mechanism in the method includes:

[0026] Neither the discovery request nor the discovery response message payload carries VLAN attribution information;

[0027] When a network device receives "neighbor information" from a lower-level node, or parses a "discovery reply" sent by a lower-level node into "neighbor information," it first determines whether the neighbor information has completed VLAN affiliation determination:

[0028] If VLAN affiliation identification has not yet been completed for the neighbor information, VLAN affiliation determination will be made by combining the type of the receiving port that received the neighbor information with the local port configuration:

[0029] (1) When the message corresponding to the neighbor information is received via the access port, the VLAN affiliation of the neighbor information is determined according to the VLAN configured on the access port;

[0030] (2) When the message corresponding to the neighbor information is received via a trunk port, the VLAN affiliation of the neighbor information is determined based on the VLAN tag carried in the message;

[0031] (3) When the receiving port of the message corresponding to the neighbor information is not configured with VLAN, or the current network device does not have VLAN resolution capability, the current network device does not perform VLAN affiliation determination on the neighbor information, but uploads the neighbor information to the upper-layer node, and the upper-layer node continues to complete the determination based on the same VLAN affiliation identification mechanism;

[0032] (4) After the VLAN affiliation determination is completed for the first time, add a VLAN field to the neighbor information and set the "VLAN identified flag";

[0033] If the VLAN affiliation identification and determination have already been completed for the neighbor information, then the VLAN determination will not be repeated.

[0034] To achieve the above objectives, the present invention also provides a computer-readable storage medium having a program stored thereon that, when executed by a processor, implements the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0035] To achieve the above objectives, the present invention also provides a processor for running a program that, when running, executes the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0036] To achieve the above objectives, the present invention also provides a computer system, including a processor, a memory, and a program stored in the memory and executable on the processor, the program being loaded and executed by the processor to implement the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0037] To achieve the above objectives, the present invention also provides a computer program product that, when executed on a data processing device, is adapted to perform the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0038] The cross-VLAN network device discovery and VLAN affiliation identification method provided by this invention has the following advantages over existing technologies:

[0039] (1) Device discovery can be completed in a pure Layer 2 network environment without relying on management VLANs or centralized management protocols, as specifically demonstrated below:

[0040] First, the discovery request message of the present invention is propagated by the master node in the Layer 2 network through port hop-by-hop diffusion. The discovery process is not limited to a certain preset management VLAN, nor does it require the existence of a unified management VLAN in the network in advance, thereby avoiding the prerequisite that the prior art must rely on the management VLAN to complete the device discovery.

[0041] Secondly, the present invention adopts a distributed VLAN affiliation identification mechanism based on port semantics. When processing discovery replies or neighbor information, network devices only combine the type of the receiving port and the local port configuration to complete VLAN affiliation identification at the location where the VLAN determination conditions are first met, without having to read the device configuration through SNMP or other means.

[0042] Through the above-mentioned technical means, the present invention can discover network devices and terminal devices in a pure Layer 2 network environment without relying on management VLANs or centralized management protocols.

[0043] (2) It can automatically discover network devices and terminal devices in multi-level Layer 2 networks, and can cover Layer 2 devices and terminal devices without management capabilities.

[0044] (3) Through innovative hop-by-hop diffusion and port semantic determination, dynamic identification of device VLAN affiliation can be achieved in cross-VLAN scenarios.

[0045] (4) The location where VLAN information first meets the judgment conditions in the actual forwarding path is determined, rather than relying on reading device configuration, and the result is more consistent with the actual network structure.

[0046] (5) The solution of the present invention is applicable to application scenarios such as network operation and maintenance, asset inventory and automatic topology generation. Attached Figure Description

[0047] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.

[0048] Figure 1 This is a network topology diagram in an embodiment of the present invention. Detailed Implementation

[0049] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below with reference to specific illustrations.

[0050] The present invention provides a cross-VLAN network device discovery and VLAN affiliation identification method that, without relying on management VLANs or centralized management protocols, in a network environment where multi-level Layer 2 networks and Layer 3 forwarding boundaries coexist, achieves gradual discovery of network devices and terminal devices based on a Layer 2 discovery mechanism, and dynamically identifies the VLAN affiliation of devices during the discovery process.

[0051] For ease of explanation, the technical terms involved in this invention will be explained first:

[0052] Master node: Also known as the initiating node, it is the network device that initiates the first discovery request in the network and is the last node to receive and integrate all neighbor information to generate the current complete network topology.

[0053] Upper-layer nodes: Network devices that send discovery request messages to the outside world;

[0054] Lower-level nodes: Network devices in the network that receive discovery request messages.

[0055] It should be noted that the definition of upper-layer nodes and lower-layer nodes is determined based on the direction of discovery request propagation. The same network device can simultaneously assume the roles of upper-layer node and lower-layer node in different propagation paths or different port directions.

[0056] Accordingly, the cross-VLAN network device discovery and VLAN affiliation identification method provided by this invention is mainly achieved through the following steps:

[0057] First, in the network, select at least one network device with VLAN discrimination function and configure it as the master node for network device discovery. The master node is configured upstream of the VLAN definition boundary, and the Layer 2 port of the master node is connected to the downstream Layer 2 network.

[0058] The network device configuration with VLAN identification capability mentioned here refers to network hardware devices that support the Virtual Local Area Network (VLAN) protocol standard, can identify and process port link types, and possess at least one of the following capabilities. Specifically, such network devices can determine the attribution of incoming raw packets based on the default VLAN configuration information of their physical / logical ports; or they can identify the logical isolation zone to which data traffic belongs by parsing the VLAN tag information carried in the header of received data packets; such devices can perform corresponding Layer 2 forwarding decisions, packet processing, or neighbor attribution determination based on the VLAN identification results.

[0059] The upstream position of the VLAN definition boundary here refers to the functional node side in the network topology layer that is responsible for defining, managing, or initially identifying VLAN attributes.

[0060] As an example, the master node here is usually a network device that connects to the downstream Layer 2 network and has VLAN configuration capabilities, such as a Layer 3 switch, router, or switching device with VLAN configuration function.

[0061] Based on this, the master node generates a unique identifier corresponding to the current discovery session behavior, generates a discovery request message based on the generated unique identifier, and sends the discovery request message to all its available Layer 2 ports.

[0062] Specifically, in this solution, the master node is configured to generate a unique identifier for each discovery session, meaning that the unique identifier generated for each discovery session is different, thereby distinguishing different discovery sessions.

[0063] Next, other network devices in the network are configured to, upon receiving a discovery request message, mark the network device that sent the discovery request message as an upper-layer node, and reply with their own device information to the upper-layer node that sent the discovery request message as a lower-layer node. At the same time, the current network device (i.e., the network device that currently receives the discovery request message) will also act as an upper-layer node, reconstruct the discovery request message based on the received discovery request message, and send the reconstructed discovery request message to other ports. This allows the discovery request to spread hop by hop in the Layer 2 network, forming a discovery path that extends layer by layer from the master node downstream.

[0064] As a supplementary explanation, the other ports mentioned here refer to the ports in the current network device that, in addition to the ports that receive discovery request packets, also have Layer 2 forwarding capabilities.

[0065] Next, after receiving the discovery response sent by the corresponding lower-level node, the network device acting as an upper-level node in the network will generate a neighbor information and send the neighbor information directly to the corresponding upper-level node layer by layer until it is sent to the master node.

[0066] At the same time, network devices acting as upper-layer nodes in the network also perform dynamic VLAN affiliation identification based on the VLAN affiliation identification mechanism to identify the VLAN affiliation of the neighbor information received from the lower-layer nodes and / or the neighbor information formed by parsing the discovery response sent by the lower-layer nodes.

[0067] The following section further elaborates on the specific implementation scheme of the cross-VLAN network device discovery and VLAN affiliation identification method provided by this invention.

[0068] In this scheme, the discovery request generated by the corresponding node is specifically formed by the link layer control message, which can be used to realize the transmission of the device discovery request in the layer 2 network.

[0069] As an example, the discovery request generated in this scheme can use MAC multicast messages and a fixed Ethernet type.

[0070] As further explanation, the discovery request generated by the network device of each node will be sent through the Layer 2 port of the network device, and at the same time, the network device of each node will also receive the discovery requests sent by the network devices of other upper-layer nodes through the Layer 2 port of the network device.

[0071] Furthermore, after receiving a discovery request, the network device in the Layer 2 network parses and processes the received discovery request locally to obtain the corresponding discovery request message. However, the network device does not directly forward the discovery request message obtained from the upper-layer node network device. Instead, it reconstructs a new discovery request based on the parsed discovery request message and sends it to the downstream port through the Layer 2 port of the network device.

[0072] As a supplementary explanation, in this invention, after receiving a discovery request, the network device does not transparently forward the received discovery request. Instead, it parses the received discovery request and reconstructs a new discovery request based on the parsing result. This can be achieved through the following process steps:

[0073] (1) After receiving the discovery request, the network device first parses the discovery session identifier and upper-layer node information carried in the discovery request, and records the upper-layer node relationship locally;

[0074] (2) Based on the discovery session identifier obtained by parsing, the network device reconstructs the discovery request message while keeping the discovery session identifier unchanged to ensure the continuity of the discovery process;

[0075] (3) The reconstructed discovery request is sent by the current network device as the sending body, and is sent downstream through other Layer 2 ports besides the upper layer ports, thus forming a hop-by-hop diffusion discovery path.

[0076] As a supplementary explanation, the upper-layer port mentioned here refers to the local port used by the current network device to record the received discovery requests.

[0077] The present invention avoids the discovery request being simply flooded or transparently forwarded in the Layer 2 network by using the above-mentioned "parse-reconstruct-send" method, thus effectively controlling the discovery path.

[0078] Furthermore, the specific implementation techniques for reconstructing the discovery request message in step (2) are not limited here, and can be determined according to actual needs.

[0079] In this scheme, after receiving a discovery request sent by an upper-layer node, the network device node located in the Layer 2 network will generate a corresponding discovery response based on the discovery request and send it to the corresponding upper-layer node.

[0080] As a supplementary explanation, the corresponding upper-layer node here is the upper-layer node that sent the received discovery request.

[0081] Furthermore, the discovery response in this scheme is specifically formed by link-layer control messages.

[0082] Specifically, after receiving a "discovery request" from an upper-layer node, the current network device node fills its own "unique identifier" (such as the base MAC address) and the port name for receiving the discovery request into the reply message and sends it to the upper-layer node.

[0083] Meanwhile, it was discovered that the payload in the response message could also contain operation and maintenance related information such as device type, software version, and CPU utilization.

[0084] As an example, in this scheme, after receiving a discovery request sent by an upper-layer node, the network device node located in the Layer 2 network first parses the discovery session identifier and upper-layer node information carried in the discovery request, and records the upper-layer node relationship locally.

[0085] Next, the session identifier, the unique identifier of the local device, the port name that received the discovery request, and other operation and maintenance related information are filled into the "discovery response" and sent to the upper-layer node.

[0086] In this scheme, when a network device node located in the Layer 2 network acts as an upper-layer node, it will generate a "neighbor information" message after receiving a discovery response from a lower-layer network device.

[0087] As further explanation, the neighbor information generated in this scheme is used as a logical data unit to describe the actual connection relationship between devices (specifically, the port-level adjacency relationship between devices), and no longer relies on the original discovery reply message during subsequent processing and uploading.

[0088] Specifically, this neighbor information is used to abstractly describe the physical relationship between upper-layer nodes and lower-layer nodes; furthermore, this neighbor information does not need to contain VLAN affiliation information in the initial stage of its generation, thus allowing it to be uploaded layer by layer in the network and complete VLAN affiliation identification at the location where the VLAN determination conditions are first met; furthermore, this neighbor information can be passed layer by layer to the master node for centralized construction of network topology and VLAN affiliation view.

[0089] Furthermore, the neighbor information in this scheme is specifically generated by the unique identifiers of the upper-layer and lower-layer nodes (such as the base MAC address) and the port information connecting the two.

[0090] As a further explanation, the neighbor information in this scheme is generated by the upper-layer node after receiving the discovery response from the lower-layer node, and specifically includes:

[0091] (1) Extract the unique identifier of the lower-level node in the discovery response;

[0092] (2) Extract the port identifiers used by the lower-level nodes in the discovery response;

[0093] (3) Combine the unique identifier of the current network device as the upper-layer node and the corresponding port information to generate a neighbor information record.

[0094] The resulting neighbor information can concisely and accurately describe the connection relationships between devices in the network; and it decouples the topology relationship from the VLAN affiliation identification process, entrusting the VLAN affiliation identification function to the device that actually has the identification capability.

[0095] Furthermore, in this scheme, after each network device node in the Layer 2 network generates the corresponding "neighbor information," it needs to send the "neighbor information" directly to its corresponding upper-layer node, which then forwards it directly to its corresponding upper-layer node, and so on, layer by layer, until it is sent to the master node. Similarly, after each network device node in the Layer 2 network receives the "neighbor information" sent by its corresponding lower-layer node, it first performs VLAN affiliation identification based on the received "neighbor information," and then, without any processing, directly forwards the received "neighbor information" to the upper-layer node corresponding to the current network device node, and so on, layer by layer, until it is sent to the master node. Finally, all "neighbor information" will be converged to the master node.

[0096] This method of sending "neighbor information" ensures that neighbor information converges upwards along the real forwarding path, enabling VLAN affiliation identification to be completed at the location where the determination conditions are first met. At the same time, compared with the discovery method that relies on broadcast flooding, it avoids the dependence on network-wide broadcast reachability, thereby reducing network configuration requirements and reducing the risk of control message flooding.

[0097] Based on the above-mentioned "discovery request", "discovery response" and "neighbor information" settings, this solution further configures corresponding response mechanisms for network devices, thereby enabling the discovery and affiliation identification of all network devices in a pure Layer 2 network environment without relying on management VLANs or centralized management protocols.

[0098] (1) Discovery of request-response and hop-by-hop diffusion

[0099] This solution first selects at least one network device with VLAN discrimination function in the network and configures it as the master node for network device discovery, and connects the Layer 2 port of the network device serving as the master node to the downstream Layer 2 network; at the same time, it generates a discovery request message for the unique identifier generated for each discovery session, and sends the discovery request message to all its available Layer 2 ports.

[0100] Furthermore, when deploying the master node, this solution specifically selects a network device that is deployed upstream of the VLAN definition boundary and has VLAN discrimination capabilities, so that it can complete VLAN affiliation identification after the discovery results are aggregated.

[0101] Furthermore, the selected master node generates a unique identifier for each discovery session and includes this unique identifier in the discovery request to identify the current discovery session and cooperate with the loop prevention mechanism. This discovery request is actively generated by the selected master node and sent through all its available Layer 2 ports.

[0102] Through the above deployment method and discovery request generation mechanism, this solution can initiate and control a complete network discovery process without relying on management VLANs, centralized control protocols, or Layer 3 interconnection conditions.

[0103] Based on this, when any network device in a Layer 2 network receives a "discovery request" from one of its own Layer 2 ports, it first records the network device connected to the port that received the discovery request as its upper-layer node.

[0104] As an example, in this scheme, after a network device receives a discovery request from a certain Layer 2 port, it can mark the network device that sent the discovery request through that port as an upper-layer node in the following way:

[0105] (1) First, record the local port that receives the discovery request;

[0106] (2) Next, record the unique identifier of the upper-level node carried in the discovery request;

[0107] (3) Finally, during the current discovery session, the port and its corresponding device are designated as the only upper-layer node.

[0108] The aforementioned upper-level node marking mechanism ensures that discovery requests only propagate downstream in a predetermined direction, and provides a basis for the directional return of subsequent discovery responses and the hierarchical aggregation of neighbor information, thereby effectively avoiding path confusion and loop propagation during the discovery process.

[0109] Next, the network device generates a corresponding discovery response based on the received discovery request and sends the generated discovery response to the corresponding upper-layer node (i.e., the network device that sent the received discovery request).

[0110] Next, the network device reconstructs a new discovery request based on the received discovery request and sends the discovery request to other Layer 2 ports except for the upper-layer ports, continuing to spread to the lower layers.

[0111] Here, the network device does not forward the received "discovery request." Instead, it reconstructs a new "send request" within the device and sends it to a Layer 2 port other than the upper-layer port that received the "discovery request." In the reconstructed "send request," the unique identifier remains unchanged, but the source MAC address is replaced with the MAC address of the network device's port.

[0112] By employing the aforementioned device response and hop-by-hop propagation rules, this solution enables discovery requests to propagate hop-by-hop along the actual Layer 2 forwarding path, covering multi-level Layer 2 network structures. Simultaneously, the "parsing-reconstructing-sending" approach avoids simple flooding or transparent forwarding of discovery requests, effectively controlling the discovery scope. Furthermore, it reduces reliance on overall network configuration consistency and broadcast interoperability conditions, making this solution adaptable to complex network environments.

[0113] (ii) Information is transmitted back layer by layer

[0114] When any network device in a Layer 2 network receives a discovery response from a lower-layer node using the identity of a higher-layer node, it generates a "neighbor information" based on the port connection relationship between the devices. This "neighbor information" contains the port names connecting the upper-layer node and the lower-layer node, as well as the unique device identifiers of the upper-layer node and the lower-layer node.

[0115] The network device generates "neighbor information" and sends it to the corresponding upper-layer node (i.e., the upper-layer node marked according to the received discovery request) through its upper-layer port. The upper-layer node then forwards it to the corresponding upper-layer node through its upper-layer port, and the information is transmitted back layer by layer until it reaches the master node.

[0116] As a supplementary explanation, when any network device in a Layer 2 network receives "neighbor information" from a lower-level node, it does not perform any processing, but simply continues to report the received neighbor information to its upper-level node until it is reported to the master node.

[0117] As shown above, in this scheme, any "discovery response" will be parsed into neighbor information by the upper-layer node and passed layer by layer to the master node. By adopting a layer-by-layer upward transmission of neighbor information, this scheme ensures that neighbor information converges layer by layer along the actual Layer 2 forwarding path, enabling subsequent VLAN affiliation identification to be completed at the location where the determination conditions are first met in the network. At the same time, through the layer-by-layer transmission mechanism, the master node can centrally obtain the neighbor relationship information of all devices in the network, thereby uniformly constructing a complete network topology and VLAN affiliation view.

[0118] (iii) VLAN Affiliation Identification

[0119] In the process of discovering network devices in a Layer 2 network, each network device, when acting as an upper-layer node, will also synchronously perform VLAN affiliation identification on the information sent by the corresponding lower-layer node based on the VLAN affiliation identification mechanism.

[0120] When each network device acts as an upper-layer node, it will receive the following two types of information from the lower-layer nodes:

[0121] (1) Receive "neighbor information" sent by the lower-level node;

[0122] (2) Receive the "discovery reply" sent by the lower-level node and parse it into "neighbor information";

[0123] Based on this, each network device, when processing neighbor information, determines whether the neighbor information has completed VLAN affiliation identification; if not, it performs VLAN affiliation determination based on the receiving port type and VLAN configuration of the discovery reply message used to generate the neighbor information or the corresponding message during its forwarding process.

[0124] (a) When the message corresponding to the neighbor information is received via an access port, the VLAN affiliation of the neighbor information is determined according to the VLAN configured on the access port;

[0125] (b) When the message corresponding to the neighbor information is received via a trunk port, the VLAN affiliation of the neighbor information is determined based on the VLAN tag carried in the message;

[0126] (c) When the receiving port of the message is not configured with a VLAN, or the current network device does not have VLAN resolution capability, the current network device does not perform VLAN affiliation determination on the neighbor information, but uploads the neighbor information to the upper-layer network device, which then completes the determination based on the same VLAN affiliation identification mechanism.

[0127] As a supplementary explanation, the lack of VLAN resolution capability in current network devices refers to a technical state where the network device only performs Layer 2 transparent forwarding of received packets. Specifically, this manifests as follows: the device's hardware chip or system firmware does not enable or support the extraction, comparison, and logical matching of VLAN-related fields (such as TPID and VLAN ID) in Ethernet frames, preventing the device from maintaining the mapping relationship between physical ports and VLAN IDs locally. In this state, the device treats packets carrying VLAN tags as ordinary Ethernet packets and forwards them according to their original structure, without performing logical determination based on VLAN affiliation.

[0128] Specifically, the VLAN affiliation identification mechanism given in this solution mainly includes:

[0129] (1) The discovery request and discovery reply packets generated by the network devices in this scheme do not carry VLAN affiliation information.

[0130] (2) When a network device receives "neighbor information" from the corresponding lower-level node, or parses the "discovery reply" sent by the lower-level node into "neighbor information", it first determines whether the "neighbor information" has completed VLAN affiliation determination:

[0131] (2.1) If the "neighbor information" has not yet completed VLAN identification, then the following determination is made based on the type of the receiving port and the local port configuration:

[0132] (2.1.1) If the message corresponding to “neighbor information” is received through an access port, the VLAN affiliation of the “neighbor information” shall be determined according to the VLAN configured on that port.

[0133] As an example, in a specific implementation, the network device determines the access VLAN corresponding to the access port based on the local port configuration of the access port, and uses the access VLAN as the VLAN to which the neighbor information belongs, thereby completing the VLAN attribution determination of the neighbor information.

[0134] (2.1.2) If the message corresponding to “neighbor information” is received through a trunk port, the VLAN affiliation is determined based on the VLAN tag carried in the message.

[0135] As an example, in a specific implementation, the network device parses the VLAN tag carried in the packet that carries the neighbor information to determine the VLAN corresponding to the neighbor information; and uses the parsed VLAN as the VLAN affiliation of the neighbor information, thereby completing the VLAN affiliation determination.

[0136] (2.1.3) If the port receiving the message is not configured with a VLAN, no VLAN affiliation determination is performed on the neighbor information. Subsequently, while keeping the neighbor information from carrying VLAN affiliation information, the neighbor information is sent to its corresponding upper-layer node. The upper-layer node will then complete the VLAN affiliation determination at the location where the VLAN discrimination conditions are first met in the subsequent processing, in accordance with the above rules.

[0137] (2.1.4) After the VLAN affiliation determination is completed for the first time, add a VLAN field to the neighbor information and set a "VLAN identified flag" to indicate that the VLAN affiliation of the "neighbor information" has been determined.

[0138] (2.2) If the VLAN affiliation identification and determination have been completed in the neighbor information, such as the "neighbor information" which already contains the VLAN identification flag, the VLAN affiliation determination will not be repeated.

[0139] Through the above mechanism, the VLAN affiliation of each neighbor relationship in the network is dynamically determined at the location in the network where the determination criteria are first met.

[0140] (iv) Neighbor information integration

[0141] In this scheme, the master node is configured to wait for all "discovery replies" and "neighbor information" to be sent to the network device within a preset time window (e.g., 30 seconds) when conducting a discovery session.

[0142] The master node also parses the received "discovery reply" into "neighbor information", and after determining the VLAN affiliation based on the VLAN affiliation identification mechanism, it determines the connection status of all devices in the current network and the VLAN to which each port belongs based on the received "neighbor information" and the parsed "neighbor information".

[0143] As a supplementary explanation, the neighbor information aggregated into the master node includes neighbor information that has not yet undergone VLAN affiliation identification.

[0144] In practical implementation, the master node in this scheme receives and summarizes the neighbor information reported by each lower-level node within a preset time window. Each piece of neighbor information contains at least a pair of interconnected network device identifiers and corresponding port identifiers, and is marked with the corresponding VLAN affiliation information at the first location where the judgment conditions are met.

[0145] Next, based on the received neighbor information, the master node constructs a connection graph between network devices according to the correspondence between device identifiers and port identifiers, thereby restoring the physical or logical connection topology between each network device and its port in the current Layer 2 network.

[0146] At the same time, the master node determines the VLAN affiliation of each port connection relationship based on the VLAN field carried in each neighbor information, and further derives the VLAN information to which each network device port belongs.

[0147] Based on this, the master node can form a complete network view, including network device topology, port connection relationships, and port VLAN affiliation.

[0148] Based on this, users can access this network information on the master node, and the master node can also generate a topology map or statistical information based on this information and present it to the user.

[0149] (v) Boundary discovery and termination

[0150] To avoid uncertain propagation across three domains, this solution further incorporates a termination mechanism during the construction and configuration process.

[0151] (1) The request was found to be bypassing the port that performs the Layer 3 forwarding function.

[0152] Specifically, when a network device receives a discovery request, before sending the "discovery request" to the next layer, if the port to be sent is a port that performs Layer 3 forwarding function, the discovery request will not be forwarded or disseminated through that port, thus using the Layer 3 forwarding interface as the discovery boundary.

[0153] (2) When the device does not have any available Layer 2 forwarding ports other than the upper-layer ports, terminate the discovery diffusion;

[0154] Specifically, when a network device detects that it does not have any other ports available for Layer 2 forwarding besides the upper-layer port after marking the upper-layer node, it will no longer construct and send a new discovery request, thereby terminating the discovery propagation.

[0155] (3) When the device is a terminal device, terminate the detection of spread.

[0156] Specifically, when a network device is an end device, or is identified as a device that does not have Layer 2 forwarding capabilities, it only responds to the received discovery request and generates a discovery reply, and no longer continues to spread the discovery request as an upper-layer node, thereby terminating the discovery spread.

[0157] Based on the above discovery boundary and termination mechanism, the three-layer forwarding interface can be used as the discovery boundary to achieve complete discovery of networks within a single two-layer domain or a single three-layer domain.

[0158] (vi) Prevention mechanism

[0159] To prevent discovery requests from propagating infinitely within a ring topology, this solution further constructs and configures the following anti-ring mechanism:

[0160] (1) Each discovery action corresponds to a unique discovery identifier;

[0161] (2) When any network device receives a discovery request with the same discovery identifier within a preset time window (e.g., 30s-60s): it still replies its own device information to the upper-layer node; but no longer forwards the discovery request to other ports.

[0162] The cross-VLAN network device discovery and VLAN affiliation identification scheme developed above has the following technical characteristics compared to existing technologies:

[0163] (1) Device discovery can be completed in a pure Layer 2 network environment without relying on management VLANs or centralized management protocols;

[0164] (2) It can cover terminal devices;

[0165] (3) Dynamic identification of device VLAN affiliation is achieved through hop-by-hop diffusion and port semantic determination;

[0166] (4) The location where VLAN information first meets the judgment conditions in the actual forwarding path is determined, rather than relying on reading device configuration, and the result is more consistent with the actual network structure.

[0167] The following specific embodiments further illustrate the application process of the cross-VLAN network device discovery and VLAN affiliation identification scheme provided by the present invention.

[0168] Example 1

[0169] (I) Network Topology Description

[0170] like Figure 1 As shown, the network in this embodiment includes:

[0171] A Layer 3 switch, Switch1, acts as a Layer 3 boundary device for the network, connecting to the external network.

[0172] A manageable Layer 2 switch, Switch2, is connected to Switch1 via a trunk port;

[0173] A Layer 2 forwarding device, Dumb Switch3, is connected to Switch1 via an access port;

[0174] Two wireless access points, AP1 and AP2, are connected to Switch2 via repeater ports;

[0175] Several wireless terminals STA are associated with AP1 and AP2 respectively;

[0176] Several wired terminals, PC1 and PC2, are connected to the network via Dumb Switch 3;

[0177] A wireless controller AC is connected to the management VLAN (VLAN10) through the access port of Switch1.

[0178] in:

[0179] Configure the port between Switch1 and Switch2 as a trunk, allowing VLAN10, VLAN20, and VLAN30;

[0180] Configure the port between Switch1 and Dumb Switch3 as access VLAN30;

[0181] Configure the ports between Switch2 and AP1 and AP2 as trunks, allowing VLAN10, VLAN20 and VLAN30;

[0182] Among the SSIDs provided by AP1 and AP2, SSID1 is mapped to VLAN20, and SSID2 is mapped to VLAN30.

[0183] Configure the port between Switch1 and AC as access VLAN10;

[0184] Switch1 has a three-layer forwarding capability, and its three-layer interface serves as the propagation boundary of the discovery protocol.

[0185] (II) Discovery, Initiation, and Overall Process

[0186] In this embodiment, the Layer 3 switch Switch1 initiates a discovery process as the master node.

[0187] Switch1 sends discovery request messages through all its ports involved in Layer 2 forwarding, with each message carrying a unique identifier for this discovery.

[0188] The discovery request propagates hop-by-hop down the Layer 2 network, and each device, upon receiving the discovery request, executes the method of this invention:

[0189] The upper-layer node and the local port that receives the discovery request are recorded as the "upper-layer port";

[0190] Reply with your own device information;

[0191] Continue forwarding discovery requests to ports other than the upper-layer port;

[0192] Collect device information from lower-level nodes and transmit it back layer by layer.

[0193] (III) Processing procedures and VLAN affiliation identification for various types of equipment:

[0194] 1. Switch1 (Master Node)

[0195] Switch1 direction:

[0196] • The trunk port (to Switch2) sends a "discovery request" once each in VLANs 10, 20, and 30;

[0197] •Send a discovery request once to the VLAN30 port (to Dumb Switch3);

[0198] • Access VLAN 10 port (to AC) and send a "discovery request" once.

[0199] Switch1 will receive "discovery replies" from AC and Switch2, and convert the received "discovery replies" into "neighbor information" with the Switch1 port. Switch1 will also receive "neighbor information" collected by Switch2, as well as "discovery replies" from PC1 and PC2 passed through by Switch3.

[0200] VLAN affiliation identification is performed on the acquired "neighbor information":

[0201] • If a packet is received from an access port and the packet payload does not yet contain a VLAN identification flag, then the VLAN to which the corresponding neighbor relationship belongs is determined based on the access VLAN configured for that port, and the VLAN identification flag is set.

[0202] • If a packet is received from a trunk port and the load does not yet contain a VLAN identification flag, then the VLAN is determined based on the VLAN tag in the packet, and the VLAN identification flag is set.

[0203] • If the VLAN identification flag is already included, the determination will not be repeated; only information aggregation will be performed.

[0204] 2. Switch2 (Manageable Layer 2 Switch)

[0205] After Switch2 receives the discovery request from Switch1's trunk port:

[0206] • Record Switch1 as the upper-layer node, and also record the local port that receives the discovery request from the trunk port of Switch1 as the "upper-layer port";

[0207] • Reply to Switch1 with its own device information;

[0208] • The discovery request continues to be forwarded to the downlink trunk ports (to AP1 and AP2).

[0209] When Switch2 receives "neighbor information" collected by AP1 and AP2, or generates "neighbor information" from "discovery replies" received from AP1 and AP2, it performs VLAN determination similar to Switch1, and sends all "neighbor information" to the upper-layer node (Switch1) one by one.

[0210] 3. AP1, AP2 (Wireless Access Points)

[0211] After AP1 and AP2 receive the discovery request from Switch2:

[0212] • Record Switch2 as the upper-layer node, and also record the local port from which the discovery request is received from Switch2 as the "upper-layer port";

[0213] • Reply with your own device information;

[0214] • It sends discovery requests to each STA associated with its wireless side.

[0215] When the AP receives device information from the wireless terminal STA:

[0216] • If the AP knows the VLAN corresponding to the STA based on the SSID or user policy (e.g., SSID1→VLAN20, SSID2→VLAN30), then: the VLAN determination condition is met for the first time at the AP; when generating "neighbor information", the corresponding VLAN information is filled into the load and the VLAN identification flag is set;

[0217] • If the AP itself does not have VLAN determination capabilities (for example, if its uplink is an access port), the VLAN field will not be filled in, and the information will be directly reported to the upstream switching device, where the upstream node that first meets the conditions will complete the determination.

[0218] 4. Dumb Switch3 (Layer 2 forwarding device)

[0219] After Dumb Switch3 receives a discovery request from the access VLAN30 port of Switch1:

[0220] The request was found to be directly forwarded to the downstream ports (PC1, PC2).

[0221] When Dumb Switch3 receives device information from PC1 and PC2, it will be directly forwarded to the upstream Switch1;

[0222] After Switch1 receives the above information from its access VLAN 30 port:

[0223] Generate neighbor information for Switch1, PC1, and PC2;

[0224] The VLAN determination criteria are first established here; based on the port configuration, the neighbor relationship between PC1, PC2 and Switch1 is determined to belong to VLAN30, and the VLAN field and VLAN identification flag are filled in.

[0225] 5. Terminal equipment STA, PC

[0226] After receiving the discovery request, the wireless terminal STA and the wired terminal PC:

[0227] • Only reply with information about its own device;

[0228] • Do not forward discovery requests;

[0229] (iv) Information feedback and result aggregation

[0230] Each lower-level device transmits the collected device information back to the upper-level node step by step, and finally converges to the master node Switch1.

[0231] Based on the filled VLAN field and VLAN identification flag, Switch1 obtains the VLAN relationships of each neighbor in the network and the VLAN affiliation information of terminal devices, thereby forming device discovery results or topology that include VLAN dimensions.

[0232] • Therefore, through the above process, this embodiment can achieve the following:

[0233] • In a network where both trunk and access links coexist;

[0234] • In an environment where both manageable switches and dumb switches exist;

[0235] • In scenarios where both wireless and wired terminals exist;

[0236] It enables automatic discovery of devices in the network and completes VLAN affiliation determination at the first node that meets the VLAN identification conditions, thereby accurately obtaining the VLAN information of each device (or neighbor relationship).

[0237] Based on the above-mentioned cross-VLAN network device discovery and VLAN affiliation identification scheme, this embodiment of the invention also provides a computer-readable storage medium storing a program thereon, which, when executed by a processor, implements the steps of the above-mentioned cross-VLAN network device discovery and VLAN affiliation identification method.

[0238] This invention also provides a processor for running a program, wherein the program executes the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0239] This invention also provides a computer system including a processor, a memory, and a program stored in the memory and executable on the processor. The program code is loaded and executed by the processor to implement the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0240] The present invention also provides a computer program product, which, when executed on a data processing device, is adapted to perform the steps of the above-described cross-VLAN network device discovery and VLAN affiliation identification method.

[0241] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0242] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0243] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0244] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0245] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0246] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0247] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0248] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0249] Computer-readable media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0250] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0251] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0252] The method, specific system unit, or part thereof of the present invention described above is a pure software architecture. It can be deployed via program code on physical media, such as hard disks, optical discs, or any electronic device (such as smartphones or computer-readable storage media). When a machine loads and executes the program code (e.g., a smartphone loads and executes it), the machine becomes a device for implementing the present invention. The method and device of the present invention can also be transmitted in program code form via transmission media, such as cables, optical fibers, or any other transmission method. When the program code is received, loaded, and executed by a machine (e.g., a smartphone), the machine becomes a device for implementing the present invention.

[0253] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for discovering network devices across VLANs and identifying VLAN affiliation, characterized in that, include: In the network, at least one network device with VLAN discrimination function is selected and configured as the master node for network device discovery. The master node is configured upstream of the VLAN definition boundary, and the Layer 2 port of the master node is connected to the downstream Layer 2 network. The master node generates a unique identifier corresponding to the current discovery behavior, generates a discovery request message based on the generated unique identifier, and sends the discovery request message to all its available Layer 2 ports; Other network devices in the network are configured to mark the network device that sent the discovery request message as an upper-layer node after receiving the discovery request message, and reply with their own device information to the upper-layer node that sent the discovery request message as a lower-layer node. At the same time, the current network device will also act as an upper-layer node, reconstruct the discovery request message and send the reconstructed discovery request message to other ports. When a network device acting as an upper-layer node receives a discovery response from a corresponding lower-layer node, it generates a neighbor information and sends the neighbor information directly to the corresponding upper-layer node layer by layer until it is sent to the master node. Network devices acting as upper-layer nodes in the network also perform VLAN affiliation identification based on the VLAN affiliation identification mechanism, which is based on the neighbor information received from the lower-layer nodes and / or the neighbor information formed by parsing the discovery response sent by the lower-layer nodes. The VLAN affiliation identification mechanism includes: Neither the discovery request nor the discovery response message payload carries VLAN attribution information; When a network device receives "neighbor information" from a lower-level node, or parses a "discovery reply" sent by a lower-level node into "neighbor information," it first determines whether the neighbor information has completed VLAN affiliation determination: If VLAN affiliation identification has not yet been completed for the neighbor information, VLAN affiliation determination will be made by combining the type of the receiving port that received the neighbor information with the local port configuration: (1) When the message corresponding to the neighbor information is received via the access port, the VLAN affiliation of the neighbor information is determined according to the VLAN configured on the access port; (2) When the message corresponding to the neighbor information is received via a trunk port, the VLAN affiliation of the neighbor information is determined based on the VLAN tag carried in the message; (3) When the receiving port of the message corresponding to the neighbor information is not configured with VLAN, or the current network device does not have VLAN resolution capability, the current network device does not perform VLAN affiliation determination on the neighbor information, but uploads the neighbor information to the upper-layer node, and the upper-layer node continues to complete the determination based on the same VLAN affiliation identification mechanism; (4) After the VLAN affiliation determination is completed for the first time, add a VLAN field to the neighbor information and set the "VLAN identified flag"; If the VLAN affiliation identification and determination have already been completed for the neighbor information, then the VLAN determination will not be repeated.

2. The method for cross-VLAN network device discovery and VLAN affiliation identification according to claim 1, characterized in that, In the method described, the discovery request message generated by the network device is a link layer control message, which can transmit the request to discover the device in the Layer 2 network.

3. The method for cross-VLAN network device discovery and VLAN affiliation identification according to claim 1, characterized in that, In the method, after receiving a discovery request message, the network device parses the received discovery request message, retains the unique identifier in the original discovery request message, replaces the source MAC address in the original discovery request message with the MAC address of the current network device port, and completes the reconstruction of the discovery request message.

4. The method for cross-VLAN network device discovery and VLAN affiliation identification according to claim 1, characterized in that, The neighbor information in the method is generated by the unique identifiers of the current node and its corresponding lower-level node, as well as the port information connecting the two.

5. A computer system comprising a processor, a memory, and a program stored in the memory and executable on the processor, characterized in that, The program is loaded and executed by the processor to implement the steps of the cross-VLAN network device discovery and VLAN affiliation identification method according to any one of claims 1-4.

6. A computer-readable storage medium having a program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the cross-VLAN network device discovery and VLAN affiliation identification method according to any one of claims 1-4.

7. A processor for running a program, characterized in that, When the program runs, it executes the steps of the cross-VLAN network device discovery and VLAN affiliation identification method according to any one of claims 1-4.

8. A computer program product, characterized in that, When executed on a data processing device, it is suitable for performing the steps of the cross-VLAN network device discovery and VLAN affiliation identification method as described in any one of claims 1-4.