BROADCAST TRAFFIC TRANSFER AT A STITCHING BORDER NETWORK DEVICE
The stitching border network device addresses the challenge of forwarding broadcast packets between different physical domains by assigning distinct broadcast groups to tunnels, ensuring efficient broadcast traffic forwarding and reducing network costs.
Patent Information
- Application Number
- DE102024117948
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-09
- Filing Date
- 2024-06-25
- Publication Date
- 2025-05-15
AI Technical Summary
In network environments with underlay and overlay networks, border network devices may face challenges in forwarding broadcast packets between different physical domains due to split-horizon rules and changes in network configurations, such as the addition of new physical domains.
Implementing a stitching border network device that assigns different broadcast groups to tunnels connecting various physical domains, allowing broadcast traffic to be forwarded across domains without being blocked by split-horizon rules.
Enables efficient forwarding of broadcast traffic between different physical domains, reducing the need for separate core switches and lowering network provisioning costs, while maintaining network integrity and avoiding forwarding loops.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
background
[0001] A network environment may include an underlay and an overlay network, with an overlay network deployed over an underlying (underlay) network. In some examples, a Layer 2 network (e.g., an Ethernet network) may overlay a Layer 3 network (e.g., an Internet Protocol (IP) network). Brief description of the drawings
[0002] Some embodiments of the present disclosure are described with reference to the following figures. Fig. 1 and Fig. 2 are block diagrams of switching equipment for an underlay and overlay network according to some examples. Fig. 3 and Fig. 4 are block diagrams of border network devices according to some examples. Fig. 5 is a block diagram of a stitching border network device according to some examples. Fig. 6 is a block diagram of a storage medium storing machine-readable instructions according to some examples. Fig. 7 is a flowchart of a method according to some examples.
[0003] In the drawings, identical reference numbers indicate similar, but not necessarily identical, elements. The illustrations are not necessarily to scale, and the size of some parts may be exaggerated to better illustrate the example shown. Furthermore, the drawings contain examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments shown in the drawings. Detailed description
[0004] A Layer 2 overlay network is implemented by encapsulating Layer 2 frames as payload in Layer 3 packets, e.g., according to the VXLAN (Virtual Extensible Local Area Network) protocol. The Layer 3 packets are transmitted over a Layer 3 underlay network. Based on an underlay and overlay network (where a Layer 2 network overlays a Layer 3 network), virtual Layer 2 networks such as virtual local areas (VLANs) can span the Layer 3 network, possibly across different physical domains (e.g., different data centers, different sites, different geographic locations, etc.). Spanning a VLAN across different physical domains refers to the extension or expansion of the VLAN across the different physical domains.
[0005] A network device, such as a switch or other network device, may include a data plane unit that performs VXLAN encapsulation and decapsulation. Such a data plane unit is referred to as a VXLAN tunnel endpoint (VTEP). The VTEP is part of the data plane of the underlay and overlay network, which is used for forwarding data through the network device. The network device also includes a control plane unit (which is part of the control plane of the underlay and overlay network) that exchanges control information with other network devices to enable the forwarding of data through the network devices. In some examples, the control plane of the underlay and overlay network may operate according to Ethernet Virtual Private Network (EVPN) technology.
[0006] A network environment may include multiple layers of network devices (e.g., multiple layers of switches). Network devices in a first layer may be connected to endpoint devices such as computer servers, storage systems, communication nodes (e.g., wireless access points, base stations, etc.), and / or other devices for performing specific tasks. The network devices in the first layer may be connected to one or more network devices in a second layer. In some examples, the network devices in the first layer may be referred to as edge network devices (e.g., edge switches), and the network devices in the second layer may be referred to as border network devices. The edge network devices may include access network devices, leaf network devices, or other network devices connected to endpoint devices.Border network devices may be aggregation network devices, core network devices, backbone network devices, or any other network devices that connect edge or other border network devices to other networks.
[0007] The first-tier edge network devices may include corresponding VTEPs. The VTEPs may be connected to VTEP(s) in one or more second-tier edge network devices through VXLAN tunnels (or equivalent VXLAN segments). In further examples, there may be more than two layers of network devices in network environments.
[0008] A host connected to a first VTEP (in an edge network device) may transmit a packet that may be forwarded to a broadcast group. A "host" may refer to a machine (e.g., an endpoint device), an electronic component in a machine, or a program executing in a machine. Such a packet is called a "broadcast packet," which may refer to a broadcast, unknown unicast, or multicast (BUM) packet, as explained below. The broadcast packet may be forwarded through the first VTEP (after VXLAN encapsulation) and via a first tunnel to a border network device. The broadcast packet may traverse one or more network devices between the first VTEP and the border network device.
[0009] In some cases, the edge network device may be connected to multiple different physical domains, with each physical domain of the different physical domains comprising a particular arrangement of network devices. The physical domains may include fabrics, sites, or other types of physical domains. To save costs, the edge network device may be a common core network device shared by the physical domains. Instead of each physical domain being connected to a different core network device, multiple physical domains may be connected to the same core network device. The core network device is intended to enable communication between the physical domains.
[0010] However, in certain scenarios, the core network device (or more generally, a border network device) may not be able to forward a broadcast packet received via a first tunnel from a first physical domain to a second physical domain via a second tunnel. For example, in a first scenario, the core network device (e.g., a Fig. 1, which will be discussed further below) as a Border Gateway Protocol (BGP) peer of neighboring network devices (e.g., a first border switch 104 and a second border switch 106 in Fig. 1) in the first and second physical domain (e.g., a first fabric 108 and a second fabric 110 in Fig. 1). If the BGP peers of the core network device belong to the same broadcast group, a split-horizon rule implemented by the core network device may prevent the core network device (i.e., without mechanisms according to some implementations of the present disclosure) from transmitting the packet transmitted over a first tunnel (e.g., a tunnel 114 or 116 in Fig. 1)prevents a broadcast packet received from the first physical domain (e.g., the first fabric 108) from being transmitted via a second tunnel (e.g., a tunnel 118 or 120 in Fig. 1) to be forwarded to the second physical domain (e.g., the second fabric 110).
[0011] A split-horizon rule refers to a way to prevent the advertisement of routes between peer network devices under certain conditions to avoid loops. Implementing the split-horizon rule can cause the core network device to block the forwarding of broadcast traffic between different physical domains, including BGP peers in the same broadcast group as the core network device, to prevent forwarding loops in which broadcast traffic can potentially be forwarded back to a source of the broadcast traffic or to network devices that are part of a physical domain that includes a BGP peer through which the broadcast traffic was originally received. In other words, the split-horizon rule prevents the return flow of broadcast traffic to a physical domain from which the broadcast traffic was received.
[0012] A second scenario where a border network device may not be able to forward a broadcast packet between different domains involves a new physical domain (e.g., a new fabric 202 in Fig. 2) to existing physical domains (e.g. Fabrics 204, 206 and 208 in Fig. 2) is added, wherein the respective border network devices (e.g., border switches 214, 216, and 218) are connected in a full mesh. Border network devices of a set of physical domains may be connected in a full network if any border network device of a particular physical domain of the set is connected to border network devices of all other physical domains of the set. When a new physical domain is added to a network arrangement, a border network device (e.g., 212 in Fig. 2) the new physical domain (this border network device is referred to as a "new" border network device) to one of the border network devices in the existing physical domains (a border network device of an existing physical domain is referred to as an "existing" border network device), but not to existing border network devices of other existing physical domains. For example, the border switch 212 of the new fabric 202 in Fig. 2 may be connected to border switch 214 of existing fabric 204, but not to border switches 216 and 218 of existing fabrics 206 and 208. The new border network device may also be configured as a BGP peer of the existing border network device to which the new border network device is connected. After the new physical domain is added, the border network devices of the new and existing physical domains are connected in a partial mesh. If the new border network device is configured in the same broadcast group as the existing border network device to which the new border network device is connected, a broadcast packet sent by a client in one of the existing physical domains may not reach the new physical domain due to the implementation of a split-horizon rule by BGP peers.
[0013] In accordance with some implementations of the present disclosure, a stitching border network device that stitches network devices of multiple physical domains (as in the first and second scenarios discussed above, or in any other scenario) may be configured with different broadcast groups for different tunnels to the stitching border network device from the multiple physical domains. For example, the stitching border network device (e.g., the core switch 102 of Fig. 1 or the border switch 214 of Fig. 2) via a first tunnel (e.g. tunnel 114 or 116 from Fig. 1 or a tunnel 236 in Fig. 2) with a first physical domain (e.g., the substance 108 in Fig. 1 or the substance 206 in Fig. 2) and via a second tunnel (e.g. tunnel 118 or 120 in Fig. 1 or a tunnel 232 in Fig. 2) with a second physical area (e.g. substance 110 in Fig. 1 or substance 202 in Fig. 2). In this example, the stitching border network device is assigned to a first broadcast group that also includes a border network device of the first physical domain. Furthermore, the stitching border network device is assigned to a separate second broadcast group that also includes a border network device of the second physical domain. The stitching border network device is configured with a broadcast traffic rule that specifies that broadcast traffic from a client in the first broadcast group should be forwarded by the stitching border network device to network devices of the second broadcast group. By assigning multiple broadcast groups at the stitching border device, blocking of broadcast traffic by a split-horizon rule can be avoided, which prevents broadcast traffic from being forwarded to network devices that are BGP peers of the same broadcast group.
[0014] A "broadcast group" refers to a grouping (or domain) of entities that are to receive a packet directed to the broadcast group. In some examples, a packet may be forwarded to a broadcast group if the packet is part of broadcast, unicast, or multicast (BUM) traffic. BUM traffic refers to any one or a combination of: (1) traffic sent to a broadcast address, (2) traffic that has a unicast address for which a network device does not have information (e.g., the network device's forwarding table is not populated with the unicast address, so the network device does not know how to forward the traffic), or (3) traffic sent to a multicast address. As used herein, "traffic" (or more simply "traffic") may include one or more packets. Thus, broadcast traffic may include one or more broadcast packets.
[0015] An autonomous system (AS) is based on a collection of IP routing prefixes, where a routing prefix (also called a network prefix) identifies a network portion of an Internet Protocol (IP) address. The first part of the IP address is a network address that identifies a network (the "network portion"), and the second part of the IP address is a host address that identifies a host (e.g., a machine, an electronic component, or a program).
[0016] An autonomous system can be assigned an autonomous system number (ASN). An autonomous system can be controlled by a single provider, such as an Internet service provider (ISP) or another type of provider. In some cases, a single provider can control multiple autonomous systems. An autonomous system can also be referred to as a fabric, which is an example of a physical domain.
[0017] A site, which is another example of a physical domain, can refer to a geographically separate location (i.e., separate from another geographical location). For example, different sites can be located in different countries, different states or provinces, different cities, different parts of a city, different buildings or sites, or at any other physical location. A site can include one or more autonomous systems (one or more fabrics).
[0018] In the following discussion, reference is made to autonomous systems (or fabrics). In other examples, techniques or mechanisms according to some implementations of the present disclosure may be applied to network devices deployed in other types of physical domains.
[0019] A switch is capable of forwarding data packets based on Layer 2 network addresses, such as Media Access Control (MAC) addresses, contained within the data packets. More generally, a "switch" refers to any network device on a network capable of forwarding data packets along network paths based on forwarding information contained within the data packets. The forwarding information may include network addresses (e.g., Layer 2 network addresses, Layer 3 network addresses such as IP addresses), labels such as Multiprotocol Label Switching (MPLS) labels, or other forwarding information.
[0020] A "data packet" (or simply: a "packet") refers to a data unit. The packet can contain a payload to transfer data that can include user data, program data, control information, or other data types. The packet can also contain a header that includes control fields such as network address fields, protocol fields to identify a used protocol, and other fields or parameters.
[0021] Fig. 1 is a block diagram of an exemplary network arrangement with fabrics 108 and 110 that share the Core Switch 102. The Core Switch 102 has a direct tunnel to the fabrics 108 and 110. A direct tunnel between the Core Switch 102 and a fabric does not go through another switch. The Core Switch 102 is an example of a stitching network device that connects multiple physical domains to each other, as in the example of Fig. 1, which includes fabrics 108 and 110. By sharing the core switch 102, no additional stitching network devices need to be deployed between fabrics 108 and 110, saving infrastructure costs and reducing complexity.
[0022] Network 108 is a first autonomous system with an autonomous system number (ASN) of ASN 100. Network structure 110 is a second autonomous system with ASN 200. Core switch 102 is part of a third autonomous system with ASN 300.
[0023] BGP refers to a protocol that supports routing between different autonomous systems. BGP peers are neighboring network devices that exchange routing information with each other. BGP can be used for routing within an autonomous system, which is called inner BGP (iBGP). Alternatively, BGP can also be used for routing between different autonomous systems, which is called external BGP (eBGP). Although some examples refer to BGP peers, the term "peer" can refer to any network device that is a neighbor of another network device; the neighboring network devices can exchange control information with each other to establish network paths, including establishing broadcast groups for forwarding broadcast traffic through tunnels to different physical domains.
[0024] In the example of Fig. 1, core switch 102 in the autonomous system assigned to ASN300 and switch 104 in the autonomous system assigned to AS100 are eBGP peers. Similarly, core switch 102 in the autonomous system assigned to ASN300 and switch 106 in the autonomous system assigned to AS200 are eBGP peers.
[0025] Edge switches 122, 124, and switch 104 are located in the same autonomous system (ASN100) and are thus iBGP peers. Similarly, edge switches 126, 128, and switch 106 are located in the same autonomous system (ASN100) and are thus iBGP peers. Although a certain number of edge switches are located in each fabric of Fig. 1, in other examples, a fabric may also include a different number of fabrics.
[0026] Switches 104 and 106 are also referred to as "border switches." A "border switch" can refer to a core switch, an aggregation switch, or any other type of switch that can connect another switch to another entity, where the other entity can be a switch, a network, or another entity.
[0027] An "edge switch" is a switch that is connected to end devices. Examples of edge switches are access switches, leaf switches, or other switches that are connected to end devices. An "end device" is an electronic device that can communicate over a network. Examples of end devices are computers, wireless access points, storage systems, Internet of Things (IoT) devices, or other types of electronic devices. An endpoint device is an example of a host that is capable of facilitating the communication of data in the network arrangement of Fig. 1. A host may also refer to an electronic component in the endpoint device or to a program executing in the endpoint device.
[0028] In the example of Fig. 1, edge switch 122 is connected to an endpoint device 130, edge switch 124 is connected to an endpoint device 132, edge switch 126 is connected to an endpoint device 134, and edge switch 128 is connected to an endpoint device 136. It should be noted that an edge switch may be connected to multiple endpoint devices.
[0029] The network arrangement of Fig. 1 comprises an underlay and an overlay network, with an overlay network (an L2 network) deployed over an underlay network, which is an L3 network such as an IP network. The overlay network comprises a control plane (operating, for example, according to EVPN technology) and a data plane with tunnels (e.g., VXLAN tunnels).
[0030] The control plane is implemented using controllers in the respective switches, including controller 140 in core switch 102, controller C1 in border switch 104, controller C2 in border switch 106, and controllers C3, C4, C5, and C6 in the respective edge switches 122, 124, 126, and 128. Controllers 140, C1, C2, C3, C4, C5, and C6 may operate according to EVPN in some examples. As used herein, a "controller" may refer to one or more hardware processing circuits, which may include any one or a combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuitry.Alternatively, a “controller” may refer to a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.
[0031] The control plane performs control functions that support the forwarding of packets from the overlay network. For example, the control plane can perform network address learning (e.g., MAC addresses), a process that determines the MAC addresses of devices communicating over a network. As MAC addresses are learned, they are added to forwarding tables in switches that are used to forward packets. A forwarding table is also called a Forwarding Information Base (FIB).
[0032] EVPN is a standards-based technology that provides virtual multipoint bridged connectivity between different Layer 2 domains over a Layer 3 underlay network. EVPN is an extension of the Border Gateway Protocol (BGP) that enables the network to carry endpoint reachability information such as Layer 2 MAC addresses and Layer 3 IP addresses. According to EVPN, the Layer 2 overlay network (referred to as the EVPN-VXLAN overlay network) overlays an IP network. Controllers 140, C1, C2, C3, C4, C5, and C6, operating according to EVPN, can exchange reachability information, allowing VTEPs to interact with each other.
[0033] In the example of Fig. 1, tunnel 114 is established between edge switch 122 and core switch 102, tunnel 116 is established between edge switch 124 and core switch 102, tunnel 118 is established between edge switch 126 and core switch 102, and tunnel 120 is established between edge switch 128 and core switch 102. Note that it is possible to establish multiple tunnels between a given switch pair.
[0034] As in Fig. 1, a tunnel 142 is established between edge switch 122 and edge switch 124 (within fabric 108), and a tunnel 144 is established between edge switch 126 and edge switch 128 (within fabric 110). Tunnel 142 is an intra-fabric tunnel within fabric 108, and tunnel 144 is an intra-fabric tunnel within fabric 110.
[0035] In some examples, tunnels 114, 116, 118, 120, 142, and 144 may be VXLAN tunnels. Tunnels 114, 116, 118, 120, 142, and 144 are part of the overlay network.
[0036] In other examples, other types of tunnels based on other technologies (e.g., other than EVPN and VXLAN) may also be used for an overlay network.
[0037] In the Fig. 1, tunnel 114 is established between a VTEP 152 in edge switch 122 and an edge VTEP 160 in core switch 102; tunnel 116 is established between a VTEP 154 in edge switch 124 and edge VTEP 160; tunnel 118 is established between a VTEP 156 in edge switch 126 and edge VTEP 160; and tunnel 120 is established between a VTEP 158 in edge switch 128 and edge VTEP 160. Tunnel 142 is established between VTEP 152 in edge switch 122 and VTEP 154 in edge switch 124, and tunnel 144 is established between VTEP 156 in edge switch 126 and VTEP 158 in edge switch 128.
[0038] VTEPs 152, 154, 156, 158, and 160 are part of the data plane of the overlay network. A VTEP can be implemented with one or more hardware processing circuits or a combination of one or more hardware processing circuits and machine-readable instructions. For example, the VTEP can be implemented with an application-specific integrated circuit (ASIC) or another type of hardware processing circuit.
[0039] As previously mentioned, a VTEP can perform VXLAN encapsulation and decapsulation. VXLAN encapsulation encapsulates a Layer 2 packet by adding a VXLAN header. VXLAN encapsulation creates an encapsulated packet containing the VXLAN header and a payload with the encapsulated Layer 2 packet. The VXLAN header contains a Virtual Network Identifier (VNI) that identifies a Layer 2 segment. The VNI is mapped to a VLAN; in other words, given a specific VNI, a VTEP can identify the corresponding VLAN, e.g., based on mapping information that correlates VNIs with VLANs (or more precisely, with VLAN identifiers). The combination of a VNI and an address (e.g., an IP address) of a VTEP (e.g., a VTEP in an edge switch) can uniquely identify a tunnel between the edge switch and the core switch 102.Note that there may be multiple VNIs used between a pair of VTEPs, e.g., multiple VNIs identify corresponding VLANs. A combination of a VNI and a VTEP address is used to uniquely identify a tunnel.
[0040] VXLAN decapsulation extracts the Layer 2 packet from the payload of the encapsulated packet and removes the VXLAN header.
[0041] According to some implementations of the present disclosure, the controller 140 includes a broadcast group assignment module 162 capable of assigning broadcast groups at the granularity of a tunnel, such that different tunnels can be assigned to different broadcast groups. The broadcast group assignment module 162 may be implemented with a portion of the hardware circuitry of the controller 140 or as machine-readable instructions executable by the controller 140.
[0042] Based on interactions between the controller 140 of the core switch 102 and the respective controllers C1, C3, and C4 in the fabric 108 (e.g., based on the exchange of EVPN control messages between the controllers), the tunnels 114 and 116 are established between the border VTEP 160 of the core switch 102 and the respective VTEPs 152 and 154 in the edge switches 122 and 124. Similarly, based on interactions between the controller 140 of the core switch 102 and the respective controllers C2, C5, and C6 in the fabric 110, the tunnels 118 and 120 are established between the border VTEP 160 of the core switch 102 and the respective VTEPs 156 and 158 in the edge switches 126 and 128.
[0043] In some examples, the broadcast group assignment module 162 may assign the tunnels 114, 116 (connected to the fabric 108) to a first broadcast group and assign the tunnels 118, 120 (connected to the fabric 110) to a second broadcast group. The broadcast group assignment module 162 identifies the tunnels established between the border VTEP 160 of the core switch 102 and the respective fabrics 108 and 110. The broadcast group assignment module 162 determines that the tunnels 114 and 116 are connected to one fabric (108) and that the tunnels 118 and 120 are connected to a different fabric (110). The broadcast group assignment module 162 assigns different broadcast groups to the tunnels connected to different fabrics.By being able to assign different broadcast groups to different tunnels connected to different fabrics, broadcast traffic received by a first tunnel of a first broadcast group can be forwarded by the border VTEP 160 in the core switch 102 through a second tunnel of a second broadcast group. For example, after receiving a broadcast packet 170 generated by the endpoint device 130 through the tunnel 114 of one broadcast group, the border VTEP 160 can forward the broadcast packet 170 through the tunnel 118 of another broadcast group for receipt by the endpoint device 134 (or multiple destination endpoint devices). The border VTEP 160 can also forward a broadcast packet received through the tunnel 118 or 120 from the fabric 110 through the tunnel 114 or 116 to the fabric 108.More generally, the border VTEP 160 applies a broadcast traffic rule that specifies that broadcast traffic from a client in a first broadcast group should be forwarded through the border VTEP 160 to network devices in a second broadcast group.
[0044] If the broadcast group assignment module does not assign the tunnels connected to different fabrics to different broadcast groups (in other words, tunnels 114, 116, 118, and 120 are all assigned to the same broadcast group), a split-horizon rule implemented by core switch 102 may prevent core switch 102 from transmitting the data transmitted over a first tunnel (e.g., tunnel 114 or 116 in FIG, tunnel 114 or 116 in FIG Fig. 1)was received from the fabric 108, via a second tunnel (e.g. a tunnel 118 or 120 in Fig. 1) to Fabric 110 (and vice versa).
[0045] In further examples, the broadcast group assignment module 162 may assign each tunnel to a different broadcast group. For example, the broadcast group assignment module 162 may assign tunnel 114 to a first broadcast group, tunnel 116 to a second broadcast group, tunnel 118 to a third broadcast group, and tunnel 120 to a fourth broadcast group.
[0046] As mentioned above, a tunnel is identified by a combination of a VNI and an address (e.g., an IP address) of a VTEP (e.g., a VTEP in an edge switch). Thus, the assignment of a tunnel to a broadcast group is based on the combination of a VNI and a VTEP address. A VNI is assigned to a VLAN using mapping information that correlates VNIs with VLANs (or, more precisely, with VLAN identifiers).
[0047] In the example of Fig. 1, the end devices 130, 132, 134, and 136 communicate over the same VLAN 180 associated with a particular VNI. In some examples, the VLAN 180 is extended or expanded across different physical domains, e.g., across different autonomous systems, as in Fig. 1. Broadcast packets that can be forwarded from the border VTEP 160 via various broadcast groups via appropriate tunnels can be communicated via VLAN 180.
[0048] In examples where endpoint devices 130, 132, 134, and 136 include wireless access points, a mobile device may roam between the wireless access points while still being able to transmit data (including broadcast packets) over VLAN 180.
[0049] The broadcast group assignment module 162 may manage tunnel broadcast group assignment information 166 stored in a memory 164. The memory 164 may be implemented with one or more memory devices, including any one or a combination of dynamic random access memory (DRAM), static random access memory (SRAM), a flash memory device, or another type of memory device. The tunnel broadcast group assignment information 166 may map tunnels to broadcast groups to which the tunnels are assigned. The tunnel broadcast group assignment information 166 may include multiple entries, with each entry assigning a tunnel to a corresponding broadcast group. The VTEP 160 may access the tunnel broadcast group assignment information 166 when forwarding broadcast packets between tunnels assigned to different broadcast groups.
[0050] By being able to forward broadcast packets at the border VTEP 160 based on the assignment of tunnels to different broadcast groups, network arrangements according to some examples of the present disclosure do not need to deploy separate core switches for the different fabrics 108 and 110 to support the forwarding of broadcast packets between the different fabrics. By being able to share the same core switch 102 for multiple fabrics, the deployment costs of the Fig. 1 compared to network deployments that use separate core switches for different fabrics. For example, fabric 110 may be a new fabric that can be added to the existing fabric 108. The new fabric 110 can simply be connected to the shared core switch 102, eliminating the need to deploy a new core switch along with the new fabric 110.
[0051] Fig. is a block diagram of another example network arrangement showing the addition of a new fabric 202 to the existing fabrics 204, 206, and 208. The existing fabrics 204, 206, and 208 each include border switches 214, 216, and 218. The new fabric 202 has a border switch 212. Within each fabric, the corresponding border switch is connected to other switches (not shown), including edge switches connected to endpoint devices.
[0052] In some examples, fabric 204 is an autonomous system assigned ASN400, fabric 206 is an autonomous system assigned ASN500, fabric 208 is an autonomous system assigned ASN600, and fabric 202 is an autonomous system assigned ASN700.
[0053] The existing fabrics 204, 206, and 208 have a full-mesh connection arrangement in which the respective boundary switches 214, 216, and 218 are connected to each other. In other words, according to the full-mesh connection arrangement, the boundary switch 214 is connected to the boundary switches 216 and 218, the boundary switch 216 is connected to the boundary switches 214 and 218, and the boundary switch 218 is connected to the boundary switches 214 and 216.
[0054] The new fabric 202 is added to the network array after the existing fabrics 204, 206, and 208 have been deployed. Before adding the new fabric 202 to the network array comprising the existing fabrics 204, 206, and 208, the border switches of the existing fabrics 204, 206, and 208 have a full mesh connection. The border switch 212 of the new fabric 202 is connected to the border switch 214 of the existing fabric 204, but not to the border switches 216 and 218 of the other existing fabrics 206 and 208. After the new fabric 202 is added to the existing fabrics 204, 206, and 208, the border switches 212, 214, 216, and 218 of the new and existing fabrics have a partial mesh connection in which the border switch 212 is connected to the border switch 214, but not to the border switches 216 and 218.
[0055] Border switch 212 may be configured as an eBGP peer of border switch 214, and each of border switches 216 and 218 may be similarly configured as an eBGP peer of border switch 214. If the new border switch 212 is configured in the same broadcast group as the existing border switch 214 to which the new border switch 212 is connected, a broadcast packet sent from an endpoint device in any of the existing fabrics 204, 206, and 208 may not reach the new fabric 202 due to a split-horizon rule applied in the context of BGP peers. Similarly, a broadcast packet sent from an endpoint device in the new fabric 202 cannot reach any of the existing fabrics 204, 206, and 208 due to a split-horizon rule applied in the context of BGP peers.
[0056] However, in accordance with some implementations of the present disclosure, the border switch 214 includes a controller 220 having a broadcast group assignment module 222 capable of assigning tunnels connected to different fabrics to different broadcast groups. As shown in Fig. 2, the border switch 214 is connected via a tunnel 236 to the border switch 216, a tunnel 238 to the border switch 218, and a tunnel 232 to the border switch 212. More specifically, the tunnel 236 is connected between a border VTEP 224 in the border switch 214 and a VTEP (not shown) in the border switch 216, the tunnel 238 is connected between the border VTEP 224 in the border switch 214 and a VTEP (not shown) in the border switch 218, and the tunnel 232 is connected between the border VTEP 224 in the border switch 214 and a VTEP (not shown) in the border switch 212. The border VTEP 224 in the border switch 214 is similar to that shown in Fig. 1 shown border VTEP 160.
[0057] The broadcast group assignment module 222 assigns the tunnels 236 and 238 to a first broadcast group, and assigns the tunnel 232 to a second broadcast group that is different from the first broadcast group. The assignments of tunnels to the respective broadcast groups may be stored by the broadcast group assignment module 222 in tunnel broadcast group assignment information 242 stored in a memory 240 of the boundary switch 214.
[0058] The border VTEP 224 in the border switch 214 is capable of using the tunnel broadcast group assignment information 242 to forward broadcast packets received via a tunnel of the first broadcast group to a tunnel of the second broadcast group (or vice versa).
[0059] The assignment of tunnels to broadcast groups by a broadcast group assignment module (e.g. 162 in Fig. 1 or Fig. 222 in Fig. 2) may be based on configuration information provided to the broadcast group assignment module. The configuration information may be static configuration information provided to the broadcast group assignment module, for example, by a network administrator or by another entity, such as a program or machine.
[0060] In other examples, the configuration information provided to the broadcast group assignment module may include dynamic configuration information that may change, e.g., due to changing network conditions or due to the addition or removal of physical domains and / or network devices.
[0061] An example of configuration information can have the following form: BGP peer switch 1xx, Set broadcast group 1; BGP peer switch 2xx, Set the transmission group 2.
[0062] Based on the above example configuration information, the broadcast group assignment module may perform a first detection of a first peer network device (e.g., the border switch 104 in Fig. 1 or the border switch 216 in Fig. 2) with a specific identifier (e.g., "1xx"). Based on the first detection, the broadcast group assignment module assigns a tunnel (or multiple tunnels) from a first fabric containing the first peer network device with the identifier 1xx to broadcast group 1. Similarly, based on the above-mentioned example configuration information, the broadcast group assignment module may perform a second detection of a second peer network device (e.g., the boundary switch 106 in Fig. 1 or the limit switch 212 in Fig. 2) with a specific identifier (e.g., "2xx"). Based on the second detection, the broadcast group assignment module assigns one or more tunnels (with the identifier 2xx) from a second fabric containing the second peer network device to broadcast group 2.
[0063] In other examples, such as Fig. 3, a broadcast group assignment module 302 may assign broadcast groups to tunnels based on conditional information 304 stored in a memory 306 of a border network device 300. The conditional information 304 may include, for example, a BGP route map. A BGP route map includes if-then program statements that check for certain conditions (referred to as "match conditions") and set corresponding values in response to those conditions. For example, a route map may include a match condition with a community parameter, which is a BGP attribute. Generally, the conditional information 304 includes conditional logic that assigns values based on detected conditions, including community parameters or other types of parameters.
[0064] A community parameter can take the form of a tag associated with a network path (e.g., a route) reported from one peer network device to another peer network device. The community parameter can be included in control messages (e.g., BGP messages) exchanged between network devices. The community parameter can be used to customize routing policies at the network devices. An example of a BGP message is an update message, which is used to advertise routing information such as attributes of a network path and network prefixes. The update message can also, in some cases, contain a community parameter.
[0065] In accordance with some examples of the present disclosure, a community parameter 310 included in a control message 308, such as the BGP update message, may be used by the broadcast group assignment module 302 to control the assignment of tunnels to broadcast groups. In some examples, the broadcast group assignment module 302 may receive a first control message having a first community parameter value from a first peer network device and a second control message having a second community parameter value from a second peer network device. The broadcast group assignment module 302 may assign tunnels to the respective broadcast groups according to the conditional information 304 based on the community parameter values in the respective control messages.Based on the application of the conditional information 304, the broadcast group assignment module 302 may assign a community parameter value included in a control message (e.g., BGP update message) sent by a peer network device to a given broadcast group, and the broadcast group assignment module 302 may assign a tunnel from the physical domain containing the peer network device to the given broadcast group.
[0066] In connection with Fig. 1, the controller C1 in the border switch 104 may, for example, include a community parameter set to a value (e.g., COMMUNITY_1) in a control message sent from the controller C1 to the controller 140 in the core switch 102. Similarly, in Fig. 1, controller C2 in border switch 106 may include a community parameter set to a different value (e.g., COMMUNITY_2) in a control message sent from controller C2 to controller 140 in core switch 102. As previously mentioned, border switches 104, 106, and core switch 102 are BGP peers.
[0067] In the above example, in response to the community parameter in the control message of the boundary switch 104 having the value COMMUNITY_1, the broadcast group assignment module 162 may assign one (or more) tunnels from the network 108 including the boundary switch 104 to a first broadcast group according to conditional information (e.g., a route map). Similarly, in response to the community parameter having the value COMMUNITY_1, the broadcast group assignment module 162 may assign one (or more) tunnels from the structure 108 including the boundary switch 104 that announced COMMUNITY_1 to a first broadcast group according to the conditional information.
[0068] The ability to assign tunnels to broadcast groups based on parameter values, such as the community parameter in control messages, increases flexibility in assigning broadcast groups to tunnels. By varying the parameter values, tunnels can, for example, be assigned to different broadcast groups.
[0069] In some examples, a border VTEP (e.g. 160 in Fig. 1 or Fig. 224 in Fig. 2) a limited number of configurable broadcast groups are available. A "configurable broadcast group" refers to a broadcast group that can be used by the border VTEP when forwarding broadcast traffic between physical domains. A full range of broadcast groups can be, for example, 1 to 48. However, within this full range, broadcast groups 25 to 48 are configurable broadcast groups that can be used by the border VTEP, while broadcast groups 1 to 24 are reserved for other purposes and cannot be used by the border VTEP for forwarding broadcast traffic based on broadcast groups. In other examples, other example ranges of broadcast groups can be used by network devices.
[0070] As in Fig. 4, network devices in a network arrangement according to some examples of the present disclosure may support broadcast groups that are outside the restricted range of configurable broadcast groups that may be used by a border VTEP 402 in a border network device 400. The border network device 400 may be, for example, the core switch 102 of Fig. 1 or the border switch 214 of Fig. 2 act.
[0071] In order for the border VTEP 402 to cooperate with the other network devices in the network arrangement, a broadcast group converter 404 may be provided for use with the border VTEP 402. A control device 406 (e.g., the control device 140 or the control device 220 in a border switch, as in Fig. 1 or Fig. 2) can assign tunnels to broadcast groups, some of which may be outside the restricted range of configurable broadcast groups that can be used by the border VTEP 402. The broadcast group converter 404 is capable of converting a broadcast group BGX from the controller 406 into another broadcast group BGY within the restricted range of configurable broadcast groups that can be used by the border VTEP 402.
[0072] Broadcast group translator 404 may be implemented as a hardware component or as machine-readable instructions (e.g., as plug-in program code or other forms of machine-readable instructions). When implemented as plug-in program code, broadcast group translator 404 may be added to boundary VTEP 402 to support translation between a first range of broadcast groups and a second range of broadcast groups.
[0073] By using the broadcast group converter 404, the tunnel-based assignment techniques or mechanisms according to some examples of the present disclosure can be used with any type of border VTEP. Flexibility is increased because the tunnel-based assignment techniques or mechanisms are not limited by the broadcast groups supported by the border VTEP.
[0074] Fig. 5 is a block diagram of a border network device 500 according to some examples of the present disclosure. In some examples, the border network device 500 may be the core switch 102 of Fig. 1 or the border switch 214 of Fig. 2 or the border network device 300 of Fig. 3 or the border network device 400 of Fig. 4 act.
[0075] The stitching border network device 500 includes a border tunnel endpoint 502 for connecting to a first network device of a first physical domain via a first tunnel 504 and to a second network device of a second physical domain via a second tunnel 506. The border tunnel endpoint may, for example, comprise a border VTEP, such as one of the 160, 224, or 402 in Fig. 1, Fig. 2 or Fig. 4.
[0076] The stitching network device 500 includes a controller 508 that performs various tasks. The controller 508 may, for example, be the controller 140, 220, or 406 in Fig. 1, Fig. 2 or Fig. 4 include.
[0077] The tasks of the controller 508 include broadcast group assignment tasks 510 to assign a first broadcast group comprising the stitching border network device 500 and the first network device of the first physical domain, and to assign a second broadcast group comprising the stitching border network device 500 and the second network device of the second physical domain. More specifically, the broadcast group assignment tasks 510 may assign the first tunnel 504 from the first physical domain to the first broadcast group and assign the second tunnel 506 from the second physical domain to the second broadcast group. In some examples, the first and second broadcast groups are assigned at a granularity of tunnels connected to the stitching border network device 500. The assignment of broadcast groups at the granularity of tunnels by a controller (e.g.,the controller 508) in a stitching border network device refers to the assignment of a broadcast group to a first collection of tunnels (including one or more tunnels) connected to the stitching border network device that is different from another broadcast group assigned to a second collection of tunnels (including one or more tunnels) connected to the stitching border network device.
[0078] The border tunnel endpoint 502 may perform a broadcast traffic forwarding task 512. The broadcast traffic forwarding task 512 includes receiving broadcast traffic over the first tunnel 504 from the first network device in the first broadcast group and forwarding the broadcast traffic over the second tunnel 506 to the second network device in the second broadcast group.
[0079] In some examples, the controller 508 performs a first detection that the first physical domain includes a first neighbor network device that is a peer (e.g., a BGP peer) of the stitching border network device 500. The controller 508 assigns the first broadcast group based on the first detection. The control device 508 performs a second detection that the second physical domain includes a second neighbor network device that is a peer (e.g., a BGP peer) of the stitching border network device 500. The control unit 508 assigns the second broadcast group based on the first detection.
[0080] In some examples, the controller 508 applies a rule (e.g., a stitching rule as described above) that prevents the stitching border network device 400 from forwarding broadcast traffic between different physical domains, including peers in the same broadcast group as the core network device.
[0081] In some examples, the stitching border network device 500 includes a memory to store conditional information related to the creation of broadcast groups. The conditional information may include, for example, a route map. The controller 508 receives a first control message (e.g., a first BGP update message) from the first network device. Based on matching a parameter in the first control message with the conditional information, the controller 508 assigns the first broadcast group including the stitching border network device 500 and the first border network device. The controller 508 receives a second control message (e.g., a second BGP update message) from the second network device.Based on the matching of a parameter in the second control message with the conditional information, the control device 508 assigns the second broadcast group including the stitching border network device 500 and the second border network device.
[0082] In some examples, the border tunnel endpoint 502 uses a restricted range of broadcast groups. The stitching border network device 500 includes a broadcast group converter (e.g., 404 in Fig. 4) to convert between a first range of broadcast groups and another second range of broadcast groups.
[0083] Fig. 6 is a block diagram of a non-transitory machine-readable or computer-readable storage medium 600 that stores machine-readable instructions that, when executed, cause a border network device having a border tunnel endpoint to perform various tasks.
[0084] The machine-readable instructions include first tunnel information receive instructions 602 to receive first information associated with a first tunnel between a first physical domain and the border tunnel endpoint of the stitching border network device. In some examples, the first information associated with the first tunnel may include information identifying the first physical domain or a first peer network device in the first physical domain. In other examples, the first information associated with the first tunnel may include a first value of a community parameter in a first control message from the first peer network device.
[0085] The machine-readable instructions include instructions for assigning the first broadcast group 604 to assign the first tunnel to a first broadcast group based on the first information. The assignment may be based on configuration information or conditional information, as described above.
[0086] The machine-readable instructions include second tunnel information receive instructions 606 to receive second information associated with a second tunnel between a second physical domain and the border tunnel endpoint of the stitching border network device. In some examples, the second information associated with a second tunnel may include information identifying the second physical domain or a second peer network device in the second physical domain. In other examples, the second information associated with the second tunnel may include a second value of the community parameter in a second control message from the second peer network device.
[0087] The machine-readable instructions include instructions for assigning the first broadcast group 608 to assign the second tunnel to a second broadcast group that is different from the first broadcast group based on the second information. The assignment may be based on configuration information or conditional information, as described above.
[0088] The machine-readable instructions include tunnel broadcast group assignment information storage instructions 610 for storing in memory tunnel broadcast group assignment information that can be used by the border tunnel endpoint to forward broadcast traffic between the first tunnel and the second tunnel.
[0089] Fig. 7 is a flowchart of a process 700 according to some examples. The process 700 may be performed, for example, by a stitching border network device. The process 700 includes receiving (at 702) at the stitching border network device a first value of a parameter associated with a first tunnel between a first physical domain and a border tunnel endpoint of the stitching border network device. The parameter may be, for example, a community parameter included in a BGP control message.
[0090] Process 700 includes assigning (at 704) the first tunnel to a first broadcast group by the stitching border network device based on the first value of the parameter. The assignment may be based, for example, on a route map or other type of conditional information.
[0091] The process 700 includes receiving (at 706) a second value of the parameter associated with a second tunnel between a second physical domain and the border tunnel endpoint of the border network device. The process 700 includes assigning (at 708), by the stitching border network device, the second tunnel to a second broadcast group different from the first broadcast group based on the second value of the parameter.
[0092] In some examples, the first value of the parameter is received from a first peer network device of the stitching border network device, and the second value of the parameter is received from a second peer network device of the stitching border network device, wherein the first peer network device is part of the first physical domain and the second peer network device is part of the second physical domain.
[0093] The process 700 includes forwarding (at 710) broadcast traffic between the first tunnel and the second tunnel through the border tunnel endpoint based on the assignment of the first tunnel to the first broadcast group and the assignment of the second tunnel to the second broadcast group.
[0094] A storage medium (e.g., 600 in Fig.6) may include any one or a combination of the following: a semiconductor storage device such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory; a magnetic disk such as a hard disk, floppy disk, and removable disk; other magnetic medium including tape; an optical medium such as a compact disk (CD) or digital video disk (DVD); or another type of storage device. It should be noted that the instructions described above may be provided on a single computer- or machine-readable storage medium, or alternatively, on multiple computer- or machine-readable storage media distributed throughout a large system, possibly with multiple nodes.Such computer-readable or machine-readable storage medium or media are considered part of an article (or article of manufacture). An article or article of manufacture may refer to each manufactured component or multiple components. The storage medium or media may be located either in the machine on which the machine-readable instructions are executed or at a remote location from which machine-readable instructions can be downloaded over a network for execution.
[0095] In this disclosure, the use of the term "a," "an," or "the" includes the plural forms unless the context clearly indicates otherwise. Also, the terms "comprises," "having," "includes," "comprising," and "having," as used in this disclosure, indicate the presence of the specified elements, but do not preclude the presence or addition of other elements.
[0096] In the foregoing description, numerous details are set forth to provide an understanding of the subject matter disclosed herein. However, implementations may be practiced without some of these details. Other implementations may include modifications and variations from the details described above. The appended claims are intended to cover such modifications and variations.
Claims
[1] Stitching border network device comprising: a border tunnel endpoint for connecting to a first network device of a first physical domain via a first tunnel and to a second network device of a second physical domain via a second tunnel; a controller for: Assigning a first broadcast group comprising the stitching border network device and the first network device of the first physical domain, and Assigning a second broadcast group comprising the stitching border network device and the second network device of the second physical domain, where the border tunnel end point is determined to be: Receiving broadcast traffic over the first tunnel from the first network device in the first broadcast group and Forward the broadcast traffic through the second tunnel to the second network device in the second broadcast group. [2] Stitching border network device according to claim 1, wherein the controller is designed to: Performing a first detection that the first physical domain includes a first neighbor network device that is a peer of the stitching border network device, Assign the first broadcast group based on the first detection, Performing a second detection that the second physical domain includes a second neighbor network device that is a peer of the stitching border network device, and Assign the second broadcast group based on the first detection. [3] The stitching border network device of claim 2, wherein the first neighbor network device of the first physical domain and the second neighbor network device of the second physical domain are Border Gateway Protocol (BGP) peers of the stitching border network device. [4] The stitching border network device of claim 2, wherein the controller applies a rule that prevents the stitching border network device from forwarding broadcast traffic between different physical domains, including peers in the same broadcast group as the stitching border network device. [5] The stitching border network device of claim 1, wherein the first and second broadcast groups are assigned at a granularity of tunnels connected to the stitching border network device. [6] The stitching border network device of claim 1, wherein the stitching border network device is a common core network device shared by the first and second physical domains. [7] The stitching border network device of claim 1, wherein the stitching border network device is part of a third physical domain and has a full mesh connection to the first network device of the first physical domain and a third network device of a fourth physical domain, and wherein the second network device has no connection to the second network device and / or the third network device. [8] The stitching border network device according to claim 7, wherein the first network device is a border network device of the first physical domain, the second network device is a border network device of the second physical domain, and the third network device is a border network device of the fourth physical domain. [9] The stitching boundary network device according to claim 8, wherein, before adding the second physical domain to a network arrangement including the first physical domain, the third physical domain, and the fourth physical domain as existing physical domains, the stitching boundary network device, the boundary network device of the first physical domain, and the boundary network device of the fourth physical domain have a full mesh connection, and wherein, after adding the second physical domain to the network arrangement, the stitching border network device, the first physical domain border network device, the second physical domain border network device, and the fourth physical domain border network device have a partial mesh connection. [10] Stitching boundary network device according to claim 1, comprising: a memory for storing tunnel broadcast group assignment information comprising assignments of tunnels, including the first and second tunnels, to respective broadcast groups, wherein the border tunnel endpoint is designated to use the tunnel broadcast group assignment information when forwarding broadcast traffic. [11] Stitching boundary network device according to claim 1, comprising: a memory for storing conditional information regarding the creation of broadcast groups, where the controller is intended to: Receiving a first control message from the first network device and based on the matching of a parameter in the first control message with the conditional information, assigning the first broadcast group comprising the stitching border network device and the first network device. [12] Stitching network device according to claim 11, wherein the controller is intended to: Receiving a second control message from the second network device and based on the matching of a parameter in the second control message with the conditional information, assigning the second broadcast group comprising the stitching border network device and the second network device. [13] The stitching border network device of claim 11, wherein the first control message comprises a Border Gateway Protocol (BGP) control message. [14] The stitching boundary network device according to claim 13, wherein the conditional information comprises a route map. [15] The stitching border network device of claim 14, wherein the parameter comprises a community parameter, wherein the route map indicates that the first broadcast group is assigned based on a first value of the community parameter, and wherein the route map indicates that the second broadcast group is assigned based on a second value of the community parameter. [16] The stitching border network device of claim 1, wherein the border tunnel endpoint uses a restricted range of broadcast groups, and the stitching border network device comprises: a broadcast group converter for converting between a first range of broadcast groups and another, second range of broadcast groups. [17] A non-transitory, machine-readable storage medium storing machine-readable instructions that, when executed, cause a stitching border network device comprising a border tunnel endpoint to: Receiving first information associated with a first tunnel between a first physical domain and the border tunnel endpoint of the stitching border network device; Assigning the first tunnel to a first broadcast group based on the first information; Receiving second information associated with a second tunnel between a second physical domain and the border tunnel endpoint of the stitching border network device; based on the second information, assigning the second tunnel to a second broadcast group that is different from the first broadcast group; and Store tunnel broadcast group assignment information in memory that can be used by the border tunnel endpoint to forward broadcast traffic between the first tunnel and the second tunnel. [18] The non-transitory machine-readable storage medium of claim 17, wherein the first information is received in a first control message and the second information is received in a second control message, and wherein the instructions, when executed, cause the stitching border network device to: Applying conditional information based on matching parameter values in the first and second control messages to assign the first and second tunnels to the first and second broadcast groups. [19] Method comprising: Receiving, at a stitching border network device, a first value of a parameter associated with a first tunnel between a first physical domain and a border tunnel endpoint of the border network device; Assigning the first tunnel to a first broadcast group by the border network device based on the first value of the parameter; Receiving, at the stitching border network device, a second value of the parameter associated with a second tunnel between a second physical domain and the border tunnel endpoint of the border network device; Assigning the second tunnel to a second broadcast group different from the first broadcast group by the stitching border network device using the second value of the parameter and Forwarding broadcast traffic between the first tunnel and the second tunnel through the border tunnel endpoint based on the first tunnel's association with the first broadcast group and the second tunnel's association with the second broadcast group. [20] The method of claim 19, wherein the first value of the parameter is received from a first peer network device of the stitching border network device and the second value of the parameter is received from a second peer network device of the stitching border network device, the first peer network device being part of the first physical domain and the second peer network device being part of the second physical domain.