Security entry maintenance method, device, network device, and storage medium

By assigning valid lifetimes to remote MAC-IP entries and managing them based on protocol connection interruptions, the method effectively prevents resource waste and maintains network security by ensuring timely deletion of invalid entries.

JP2026508356APending Publication Date: 2026-03-10NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-05-17
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing network security systems waste resources and discard legitimate packets when protocol connections between access devices and aggregation devices are interrupted, leading to reduced network security due to invalid MAC-IP entries.

Method used

Implement a method to maintain security entries by assigning a valid lifetime to remote MAC-IP entries, deleting them only when the protocol connection interruption duration reaches this lifetime, and managing local and remote MAC-IP entries to prevent resource occupation and unauthorized packet entry.

Benefits of technology

Prevents resource waste and ensures legitimate packets are not discarded, enhancing network security by timely deletion of invalid entries without affecting subsequent validity checks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026508356000001_ABST
    Figure 2026508356000001_ABST
Patent Text Reader

Abstract

The present invention provides a security entry maintenance method, device, network device, and storage medium, which relate to the field of communication technology. The method includes: when a protocol connection with a second network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, where the valid lifetime value indicates the valid lifetime of an IP address included in the remote MAC-IP entry; and deleting at least one remote MAC-IP entry when the duration of the protocol connection interruption reaches the valid lifetime value. This can deny unauthorized packets from entering the network and improve network security.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to the field of communication technology, and in particular to a method, an apparatus, a network device and a storage medium for maintaining security entries. [Background technology]

[0002] To improve network security, a source address security check mechanism can be implemented in the access device, which can check the validity of received packets based on Media Access Control address-Internet Protocol address (MAC-IP) entries to prevent unauthorized packets from passing through.

[0003] After creating a MAC-IP entry for the terminal, the access device 1 notifies the aggregation device of the MAC-IP entry through a protocol connection. Furthermore, the aggregation device notifies the MAC-IP entry to other access devices. In this way, after the terminal moves from an access point (AP) connected to the access device 1 to an AP connected to the access device 2, the access device 2 can perform a validity check for the terminal based on the MAC-IP entry.

[0004] When an access device 2 is connected to only one aggregation device, if the protocol connection between the access device 2 and the aggregation device is interrupted, the access device 2 deletes the MAC-IP entry from the protocol connection. In this case, if the source address security check mechanism is enabled, the access device 2 cannot check the validity based on the MAC-IP entry, and valid packets are discarded. If the source address security check mechanism is not enabled, invalid packets may also enter the network, reducing network security.

[0005] If the access device 2 does not delete the MAC-IP entry from the protocol connection and the protocol connection is not restored afterwards, the MAC-IP entry will occupy hardware resources for a long time, resulting in resource waste. Therefore, how to maintain the MAC-IP entry when the protocol connection is interrupted is an urgent issue. Summary of the Invention [Problem to be solved by the invention]

[0006] The present invention aims to provide a method, an apparatus, a network device, and a storage medium for maintaining security entries, which can avoid wasting resources and discarding legitimate packets. Specific technical solutions are as follows: [Means for solving the problem]

[0007] In a first aspect, an embodiment of the present invention provides a method for maintaining security entries, adapted to a first network device, the first network device comprising a remote MAC-IP table including at least one remote MAC-IP entry notified by the second network device; The method comprises: When a protocol connection with the second network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating a valid lifetime of an IP address included in the remote MAC-IP entry; and deleting the at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value.

[0008] In one possible embodiment, the method further comprises: When the first network device creates a DHCP relay entry, establish a local MAC-IP entry based on the DHCP relay entry and issue a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, where the local MAC-IP entry includes a first valid lifetime value of a first IP address; sending a first MAC-IP advertisement message to the third network device so that the third network device establishes a first remote MAC-IP entry; the first MAC-IP notification message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value; The first sequence number is the sum of the highest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0009] In one possible embodiment, after issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resource, the method further comprises: deleting the forwarding MAC-IP entry when an access entry matching the local MAC-IP entry is deleted.

[0010] In one possible embodiment, if the protocol connection with the second network device is interrupted, before obtaining the valid lifetime value included in each remote MAC-IP entry, the method further comprises: receiving a second MAC-IP notification message sent from the second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; establishing a second remote MAC-IP entry including the second valid lifetime value and the second sequence number.

[0011] In one possible embodiment, the first network device comprises a local MAC-IP table containing at least one local MAC-IP entry; After establishing the second remote MAC-IP entry, the method further comprises: receiving a first packet transmitted from a terminal, the first packet including a MAC address and an IP address of the terminal; If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, performing access detection for the terminal; When receiving an access response sent from the terminal, generating a composite MAC-IP entry including a MAC address and an IP address of the terminal, a port identifier, and a VLAN identifier; generating a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including a MAC address and an IP address of the terminal; and publishing the forwarding MAC-IP entry to a hardware resource.

[0012] In one possible embodiment, after issuing the forwarding MAC-IP entry to a hardware resource, the method further comprises: When the access entry of the terminal is deleted, the composite MAC-IP entry and the forwarding MAC-IP entry are deleted.

[0013] In one possible embodiment, the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including a third sequence number; After establishing the second remote MAC-IP entry, the method further comprises: If the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, deleting the first local MAC-IP entry and deleting the DHCP relay entry corresponding to the first local MAC-IP entry.

[0014] In one possible embodiment, the MAC-IP notification message sent from the first network device includes a first extended community attribute containing a valid lifetime value of the IP address.

[0015] In one possible embodiment, the MAC-IP notification message sent from the first network device further includes a second extended community attribute containing a sequence number of the MAC-IP entry.

[0016] In a second aspect, an embodiment of the present invention provides a method for maintaining security entries, adapted to a second network device, the second network device comprising: a first remote MAC-IP table including at least one remote MAC-IP entry notified from a fourth network device; The method comprises: When a protocol connection with the fourth network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating a valid lifetime of an IP address included in the remote MAC-IP entry; and deleting the at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value.

[0017] In one possible embodiment, if the protocol connection with the fourth network device is interrupted, before obtaining the valid lifetime value included in each remote MAC-IP entry, the method further comprises: receiving a first MAC-IP notification message sent from the fourth network device, the first MAC-IP notification message including a first valid lifetime value and a first sequence number of a first IP address; establishing a first remote MAC-IP entry including the first valid lifetime value and the first sequence number.

[0018] In one possible embodiment, the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry matching the first remote MAC-IP entry, and the second remote MAC-IP entry including a second sequence number; After establishing the first remote MAC-IP entry, the method further comprises: If the first sequence number is greater than the second sequence number, sending a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device.

[0019] In one possible embodiment, the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry; After deleting the at least one remote MAC-IP entry, the method further comprises: For each deleted remote MAC-IP entry, if there is no remote MAC-IP entry in the third remote MAC-IP table that matches the remote MAC-IP entry, sending a first MAC-IP revocation message to another network device other than the fourth network device, the first MAC-IP revocation message including the MAC address and the IP address in the remote MAC-IP entry; or, For each deleted remote MAC-IP entry, if there is a matching remote MAC-IP entry in the third remote MAC-IP table, selecting a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, wherein the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number; sending a third MAC-IP notification message including the second valid lifetime value and the third sequence number to another network device other than the fifth network device, the fifth network device being the source device of the third remote MAC-IP entry.

[0020] In one possible embodiment, the MAC-IP notification message sent from the second network device includes a first extended community attribute containing a valid lifetime value of the IP address.

[0021] In one possible embodiment, the MAC-IP notification message sent from the second network device further includes a second extended community attribute containing a sequence number of the MAC-IP entry.

[0022] In a third aspect, an embodiment of the present invention provides a security entry maintenance apparatus, adapted to a first network device, the first network device comprising a remote MAC-IP table including at least one remote MAC-IP entry notified from the second network device; The device comprises: an acquisition module for acquiring a valid lifetime value included in each remote MAC-IP entry when a protocol connection between the second network device and the remote MAC-IP entry is interrupted, the valid lifetime value indicating the valid lifetime of an IP address included in the remote MAC-IP entry; a deletion module for deleting the at least one remote MAC-IP entry when the duration for which the protocol connection is suspended reaches the valid lifetime value.

[0023] In one possible embodiment, the device further comprises: an establishment module for, when the first network device generates a DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, wherein the local MAC-IP entry includes a first valid lifetime value of a first IP address; a sending module for sending a first MAC-IP notification message to the third network device so that the third network device establishes a first remote MAC-IP entry; the first MAC-IP notification message includes a first sequence number and the first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value; The first sequence number is the sum of the highest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0024] In one possible embodiment, the deletion module further deletes the forwarding MAC-IP entry when an access entry matching the local MAC-IP entry is deleted.

[0025] In one possible embodiment, the device further comprises: a receiving module for receiving a second MAC-IP notification message sent from the second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; and an establishment module for establishing a second remote MAC-IP entry including the second valid lifetime value and the second sequence number.

[0026] In one possible embodiment, the first network device comprises a local MAC-IP table containing at least one local MAC-IP entry; The apparatus further includes a detection module, a generation module, and an issuing module; The receiving module further receives a first packet transmitted from a terminal, the first packet including a MAC address and an IP address of the terminal; the detection module performs access detection for the terminal when there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal and the MAC address and IP address of the terminal match the second remote MAC-IP entry; When the generating module receives an access response sent from the terminal, the generating module generates a composite MAC-IP entry including a MAC address and an IP address of the terminal, a port identifier, and a VLAN identifier; The generating module further generates a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including a MAC address and an IP address of the terminal; The issuing module issues the forwarding MAC-IP entry to a hardware resource.

[0027] In one possible embodiment, the deletion module further deletes the composite MAC-IP entry and the forwarding MAC-IP entry when the terminal access entry is deleted.

[0028] In one possible embodiment, the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including a third sequence number; The deletion module further deletes the first local MAC-IP entry and deletes a DHCP relay entry corresponding to the first local MAC-IP entry if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number.

[0029] In one possible embodiment, the MAC-IP notification message sent from the first network device includes a first extended community attribute that includes a valid lifetime value of the IP address.

[0030] In one possible embodiment, the MAC-IP notification message sent from the first network device further includes a second extended community attribute containing a sequence number of the MAC-IP entry.

[0031] In a fourth aspect, an embodiment of the present invention provides a security entry maintenance apparatus, adapted to a second network device, the second network device comprising a first remote MAC-IP table including at least one remote MAC-IP entry notified from a fourth network device; The device comprises: an acquisition module for acquiring a valid lifetime value included in each remote MAC-IP entry when a protocol connection with the fourth network device is interrupted, the valid lifetime value indicating the valid lifetime of an IP address included in the remote MAC-IP entry; a deletion module for deleting the at least one remote MAC-IP entry when the duration for which the protocol connection is suspended reaches the valid lifetime value.

[0032] In one possible embodiment, the device further comprises: a receiving module for receiving a first MAC-IP notification message sent from the fourth network device, the first MAC-IP notification message including a first valid lifetime value of a first IP address and a first sequence number; an establishment module for establishing a first remote MAC-IP entry including the first valid lifetime value and the first sequence number.

[0033] In one possible embodiment, the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry matching the first remote MAC-IP entry, and the second remote MAC-IP entry including a second sequence number; The apparatus further comprises: and a sending module for sending a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device if the first sequence number is greater than the second sequence number.

[0034] In one possible embodiment, the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry; The apparatus further includes a transmitting module; The transmitting module: For each deleted remote MAC-IP entry, if there is no remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, sending a first MAC-IP revocation message to another network device other than the fourth network device, the first MAC-IP revocation message including the MAC address and the IP address in the remote MAC-IP entry; or, For each deleted remote MAC-IP entry, if there is a remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, select a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number, and send a third MAC-IP notification message to another network device other than the fifth network device, the third MAC-IP notification message includes the second valid lifetime value and the third sequence number, and the fifth network device is the source device of the third remote MAC-IP entry.

[0035] In one possible embodiment, the MAC-IP notification message sent from the second network device includes a first extended community attribute containing a valid lifetime value of the IP address.

[0036] In one possible embodiment, the MAC-IP notification message sent from the second network device further includes a second extended community attribute containing a sequence number of the MAC-IP entry.

[0037] In a fifth aspect, an embodiment of the present invention provides a first network device, the first network device comprising a remote MAC-IP table including at least one remote MAC-IP entry notified from the second network device; the first network device, a processor; A walkie-talkie and a machine-readable storage medium having stored thereon machine-executable instructions executable by said processor; The machine-executable instructions may cause the processor to: When a protocol connection with the second network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating a valid lifetime of an IP address included in the remote MAC-IP entry; deleting the at least one remote MAC-IP entry if the duration for which the protocol connection is suspended reaches the valid lifetime value.

[0038] In one possible embodiment, the machine executable instructions may cause the processor to: When the first network device generates a DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, wherein the local MAC-IP entry includes a first valid lifetime value of a first IP address; sending, by the transceiver, a first MAC-IP advertisement message to the third network device, so that the third network device establishes a first remote MAC-IP entry; the first MAC-IP notification message includes a first sequence number and the first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value; The first sequence number is the sum of the highest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0039] In one possible embodiment, the machine executable instructions may cause the processor to: If an access entry matching the local MAC-IP entry is deleted, the forwarding MAC-IP entry is deleted.

[0040] In one possible embodiment, the machine executable instructions may cause the processor to: receiving, by the transceiver, a second MAC-IP notification message sent from the second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; establishing a second remote MAC-IP entry including the second valid lifetime value and the second sequence number.

[0041] In one possible embodiment, the first network device comprises a local MAC-IP table containing at least one local MAC-IP entry; The machine-executable instructions may cause the processor to: receiving, by a transceiver, a first packet transmitted from a terminal, the first packet including a MAC address and an IP address of the terminal; If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, performing access detection for the terminal; generating a composite MAC-IP entry, when receiving an access response sent from the terminal, including a MAC address and an IP address of the terminal, a port identifier, and a VLAN identifier; generating a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including the MAC address and IP address of the terminal; and issuing the forwarding MAC-IP entry to a hardware resource.

[0042] In one possible embodiment, the machine executable instructions may cause the processor to: When the access entry of the terminal is deleted, the step of deleting the composite MAC-IP entry and the forwarding MAC-IP entry is further executed.

[0043] In one possible embodiment, the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including a third sequence number; The machine-executable instructions may cause the processor to: If the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, deleting the first local MAC-IP entry and deleting the DHCP relay entry corresponding to the first local MAC-IP entry is further performed.

[0044] In one possible embodiment, the MAC-IP notification message sent from the first network device includes a first extended community attribute that includes a valid lifetime value of the IP address.

[0045] In one possible embodiment, the MAC-IP notification message sent from the first network device further includes a second extended community attribute containing a sequence number of the MAC-IP entry.

[0046] In a sixth aspect, an embodiment of the present invention provides a second network device, the second network device comprising a first remote MAC-IP table including at least one remote MAC-IP entry notified from a fourth network device; the second network device, a processor; A walkie-talkie and a machine-readable storage medium having stored thereon machine-executable instructions executable by said processor; The machine-executable instructions may cause the processor to: When the protocol connection with the fourth network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating the valid lifetime of the IP address included in the remote MAC-IP entry; deleting the at least one remote MAC-IP entry if the duration for which the protocol connection is suspended reaches the valid lifetime value.

[0047] In one possible embodiment, the machine executable instructions may cause the processor to: receiving, by the transceiver, a first MAC-IP notification message sent from the fourth network device, the first MAC-IP notification message including a first valid lifetime value of a first IP address and a first sequence number; establishing a first remote MAC-IP entry including the first valid lifetime value and the first sequence number.

[0048] In one possible embodiment, the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry matching the first remote MAC-IP entry, and the second remote MAC-IP entry including a second sequence number; The machine-executable instructions may cause the processor to: If the first sequence number is greater than the second sequence number, the step of sending a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device is performed.

[0049] In one possible embodiment, the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry; The machine-executable instructions may cause the processor to: for each deleted remote MAC-IP entry, if there is no remote MAC-IP entry in the third remote MAC-IP table that matches the deleted remote MAC-IP entry, sending a first MAC-IP revocation message to another network device other than the fourth network device, the first MAC-IP revocation message including the MAC address and the IP address in the deleted remote MAC-IP entry; or, for each deleted remote MAC-IP entry, if there is a matching remote MAC-IP entry in the third remote MAC-IP table, selecting a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, wherein the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number; and sending a third MAC-IP notification message including the second valid lifetime value and the third sequence number to another network device other than the fifth network device, the fifth network device being the source device of the third remote MAC-IP entry.

[0050] In one possible embodiment, the MAC-IP notification message sent from the second network device includes a first extended community attribute containing a valid lifetime value of the IP address.

[0051] In one possible embodiment, the MAC-IP notification message sent from the second network device further includes a second extended community attribute containing a sequence number of the MAC-IP entry.

[0052] In a seventh aspect, an embodiment of the present invention provides a machine-readable storage medium having stored thereon machine-executable instructions that, when called and executed by a processor, cause the processor to implement a method according to the first or second aspect.

[0053] In an eighth aspect, an embodiment of the present invention provides a computer program product, causing the processor to implement a method according to the first or second aspect. [Effects of the Invention]

[0054] When the above technical solution is adopted, the remote MAC-IP entry in the first network device includes a valid lifetime value, which indicates the valid lifetime of the IP address included in the remote MAC-IP entry. When the duration of the protocol connection interruption reaches the valid lifetime value, the IP address included in the MAC-IP entry becomes invalid. That is, the terminal that originally applied for the IP address can no longer use the IP address. Deleting the remote MAC-IP entry at this time does not affect subsequent validity checks for the terminal, does not affect network security, and prevents the remote MAC-IP entry from continuing to occupy resources in the first network device. Since the first network device does not delete the remote MAC-IP entry until the duration of the protocol connection interruption reaches the valid lifetime value, even when the source address security check mechanism is enabled, legitimate packets matching the remote MAC-IP entry are not discarded and invalid packets are prevented from entering the network, thereby improving network security. [Brief explanation of the drawings]

[0055] The drawings described herein are included to provide a further understanding of the invention and constitute a part of the invention. The exemplary embodiments of the invention and their description are intended to be illustrative and not limiting of the invention.

[0056] [Figure 1] FIG. 1 is a structural schematic diagram of a spine-leaf network system provided by an embodiment of the present invention. [Figure 2] FIG. 2 is a flowchart of a security entry maintenance method provided by an embodiment of the present invention. [Figure 3] FIG. 3 is an exemplary schematic diagram of a format of a MAC-IP NLRI provided by an embodiment of the present invention. [Figure 4] FIG. 4 is an exemplary schematic diagram of a Route Type format provided by an embodiment of the present invention. [Figure 5] FIG. 5 is an exemplary schematic diagram of a first extended community attribute format provided by an embodiment of the present invention. [Figure 6] FIG. 6 is an exemplary schematic diagram of a second extended community attribute format provided by an embodiment of the present invention. [Figure 7] FIG. 7 is a flowchart of another security entry maintenance method provided by an embodiment of the present invention. [Figure 8] FIG. 8 is a structural schematic diagram of another spine-leaf network system provided by an embodiment of the present invention. [Figure 9] FIG. 9 is a structural schematic diagram of yet another spine-leaf network system provided by an embodiment of the present invention. [Figure 10] FIG. 10 is a structural schematic diagram of yet another spine-leaf network system provided by an embodiment of the present invention. [Figure 11] FIG. 11 is a structural schematic diagram of a security entry maintenance device provided by an embodiment of the present invention. [Figure 12]FIG. 12 is a structural schematic diagram of another security entry maintenance device provided by an embodiment of the present invention. [Figure 13] FIG. 13 is a structural schematic diagram of a first network device provided by an embodiment of the present invention. [Figure 14] FIG. 14 is a structural schematic diagram of a second network device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0057] In order to clarify the objectives, technical solutions and advantages of the present invention, the present invention will be described in more detail below by way of examples with reference to the drawings. Obviously, the described examples are only some of the embodiments of the present invention, and are not all of the embodiments. All other embodiments that those skilled in the art can obtain based on the embodiments of the present invention fall within the scope of protection of the present invention.

[0058] The network system used in the embodiment of the present invention may be a spine-leaf network. As shown in Figure 1, the network system includes two levels of aggregation devices. Here, Spine3 is an upper-level aggregation device for Spine1 in Area 1 and Spine2 in Area 2.

[0059] Spine3 is connected to a Dynamic Host Configuration Protocol Version 6 (DHCPv6) server and an Access Controller (AC). The DHCPv6 server assigns Internet Protocol Version 6 (IPv6) addresses to terminals.

[0060] Spine1 is located in Area1 and further includes three access devices, Leaf1, Leaf2 and Leaf3, in Area1, and Leaf1, Leaf2 and Leaf3 are all connected to Spine1.

[0061] AP1 is connected to Leaf1, AP2 is connected to Leaf2, and AP3 is connected to Leaf3. A terminal can communicate with the APs. Figure 1 exemplarily shows that a terminal accesses AP1.

[0062] The number of devices in FIG. 1 is an example, and in actual implementation, the number of devices in FIG. 1 is not limited to this.

[0063] A security check mechanism is implemented in the access device, including a control plane check mechanism and a data plane check mechanism.

[0064] Here, the control plane check mechanism refers to performing a validity check on received protocol packets, such as filtering the Media Access Control (MAC) addresses and Internet Protocol (IP) addresses of the senders of Neighbor Discovery (ND) packets and Address Resolution Protocol (ARP) discovery packets, to prevent the creation of invalid ND entries and ARP entries.

[0065] The data plane check mechanism refers to filtering control of the source MAC address and source IP address of received service packets to prevent unauthorized service packets from passing through.

[0066] Both the control plane check mechanism and the data plane check mechanism rely on pre-generated MAC-IP entries. Currently, methods for dynamically generating MAC-IP entries include generating MAC-IP entries based on Dynamic Host Configuration Protocol (DHCP) relay entries and generating MAC-IP entries by DHCP snooping. The embodiments of the present invention do not limit the method by which the access device generates local security entries.

[0067] It should be noted that if a user configures an IP address for a terminal without permission, the access device will not be triggered to create a MAC-IP entry, and the access device will discard packets from the terminal.

[0068] In an embodiment of the present invention, the IP address may be an Internet Protocol Version 4 (IPv4) address or an IPv6 address.

[0069] An embodiment of the present invention provides a security entry maintenance method applied to a first network device. The first network device may be an access device, for example, a leaf device in a spine-leaf architecture. The first network device has a remote MAC-IP table containing at least one remote MAC-IP entry notified from a second network device. As shown in Figure 2, the method includes the following steps:

[0070] In S201, when the protocol connection with the second network device is interrupted, the valid lifetime value included in each remote MAC-IP entry is obtained.

[0071] Here, the valid lifetime value is intended to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0072] The second network device may be an aggregation device. Taking the network system shown in FIG. 1 as an example, the first network device may be Leaf1, Leaf2, or Leaf3 in FIG. 1, and the second network device may be Spine1. The protocol connection between the first network device and the second network device may be a Border Gateway Protocol (BGP) connection. Alternatively, the protocol connection between the first network device and the second network device may be a customized private protocol connection. When the protocol connection is a private protocol connection, each network device notifies the MAC-IP entry through the private protocol.

[0073] In S202, if the duration during which the protocol connection is interrupted reaches the valid lifetime value, delete at least one remote MAC-IP entry.

[0074] It can be understood that when the remote MAC-IP table includes one MAC-IP entry, the first network device obtains the valid lifetime value included in the MAC-IP entry. The first network device maintains the valid lifetime value of the remote MAC-IP entry starting from the time when it detects the interruption of the protocol connection. That is, after detecting the interruption of the protocol connection, the first network device maintains the valid lifetime value of the remote MAC-IP entry and does not delete the remote MAC-IP entry until the valid lifetime value is reached.

[0075] If the protocol connection is not restored when the time elapsed from the start point reaches the valid lifetime value, the remote MAC-IP entry is deleted.

[0076] For example, if the valid lifetime value is 100,000 seconds, when the first network device detects an interruption in the protocol connection, it starts counting and maintains the remote MAC-IP entry for 100,000 seconds, and if the protocol connection is not restored after 100,000 seconds, the first network device deletes the remote MAC-IP entry.

[0077] If the remote MAC-IP table includes multiple MAC-IP entries, the first network device can obtain the valid lifetime values ​​of the multiple remote MAC-IP entries.

[0078] In one embodiment, when the duration of the interrupted protocol connection reaches all of the acquired valid lifetime values, i.e., when the duration of the interrupted protocol connection reaches the largest lifetime value among the acquired valid lifetime values, multiple MAC-IP entries included in the remote MAC-IP table are deleted at once.

[0079] In another embodiment, for each valid lifetime value, if the duration that the protocol connection has been interrupted reaches the valid lifetime value, the MAC-IP entry to which the valid lifetime value belongs is deleted.

[0080] With the above method, the remote MAC-IP entry in the first network device includes a valid lifetime value, which indicates the valid lifetime of the IP address included in the remote MAC-IP entry. When the duration of the protocol connection interruption reaches the valid lifetime value, the IP address included in the MAC-IP entry becomes invalid. That is, the terminal that originally requested the IP address can no longer use the IP address. Deleting the remote MAC-IP entry at this time does not affect subsequent validity checks for the terminal, does not affect network security, and prevents the remote MAC-IP entry from continuing to occupy resources in the first network device. Since the first network device does not delete the remote MAC-IP entry until the duration of the protocol connection interruption reaches the valid lifetime value, even when the source address security check mechanism is enabled, legitimate packets matching the remote MAC-IP entry are not discarded and unauthorized packets are prevented from entering the network, thereby improving network security.

[0081] Hereinafter, a specific example will be described. Referring to Fig. 1, for example, assume that the first network device is Leaf1 and the second network device is Spine1. Leaf1 receives MAC-IP entry 1 and MAC-IP entry 2 notified from Spine1 and stores them as remote MAC-IP entry 1 and remote MAC-IP entry 2. Assume that the valid lifetime value of the IP address in remote MAC-IP entry 1 is 90,000 seconds and the valid lifetime value of the IP address in remote MAC-IP entry 2 is 100,000 seconds.

[0082] In one embodiment, when Leaf1 detects that the protocol connection with Spine1 has been interrupted, Leaf1 maintains Remote MAC-IP Entry 1 and Remote MAC-IP Entry 2 for 100,000 seconds, starting from the time when the interruption of the protocol connection was detected. If the protocol connection between Leaf1 and Spine1 has not been restored after 100,000 seconds, Leaf1 deletes Remote MAC-IP Entry 1 and Remote MAC-IP Entry 2.

[0083] In this way, the first network device can delete multiple remote MAC-IP entries at once, avoiding resource waste and reducing the processing overhead of the process of deleting remote MAC-IP entries by the first network device without affecting network security.

[0084] In other embodiments, the example is also taken in which leaf1 includes the above-mentioned remote MAC-IP entry 1 and remote MAC-IP entry 2. When leaf1 detects that the protocol connection with spine1 has been interrupted, leaf1 maintains remote MAC-IP entry 1 for 90,000 seconds, starting from the time when the interruption of the protocol connection was detected, and if the protocol connection has not been restored after 90,000 seconds, deletes remote MAC-IP entry 1. When leaf1 detects that the interruption of the protocol connection has been detected, leaf1 maintains remote MAC-IP entry 2 for 100,000 seconds, starting from the time when the interruption of the protocol connection was detected, and if the protocol connection has not been restored after 100,000 seconds, deletes remote MAC-IP entry 2.

[0085] In this way, each invalid remote MAC-IP entry can be deleted in a timely and accurate manner, and the invalid remote MAC-IP entries can be prevented from occupying resources without affecting network security.

[0086] In the embodiment of the present invention, the first network device can also create a local MAC-IP entry and notify other network devices of the local MAC-IP entry. This process specifically includes: When the first network device generates the DHCP relay entry, the method includes establishing a local MAC-IP entry based on the DHCP relay entry, issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, and including a first valid lifetime value of the first IP address in the local MAC-IP entry.

[0087] In an embodiment of the present invention, the first network device may be used as a DHCP relay device. After the terminal requests an IP address from a DHCP server, the DHCP relay device obtains a first IP address assigned to the terminal from the DHCP server, as well as a preferred lifetime value and a valid lifetime value for the first IP address. In an embodiment of the present invention, the first network device may add the first valid lifetime value of the first IP address to a local MAC-IP entry. Optionally, the preferred lifetime value of the first IP address may be added to the local MAC-IP entry.

[0088] Taking an IPv6 network as an example, a local MAC-IP entry contains at least the fields shown in Table 1. [Table 1]

[0089] Among them, the local MAC-IP entry is a control MAC-IP entry, which can be maintained by software in the network device and stored in the memory of the network device. The control plane checks the validity of control plane protocol packets based on the control MAC-IP entry, for example, checking the validity of ND packets.

[0090] The forwarding MAC-IP entry corresponding to the local MAC-IP entry contains the above MAC address and IPv6 address fields and is stored in the hardware resources of the hardware forwarding chip. This requires consuming the MAC-IP entry resource in the hardware forwarding chip to perform validity checks on the service packets in the forwarding plane. Among these, the MAC-IP entry resource in the hardware forwarding chip is a scarce resource.

[0091] After the first network device creates the local MAC-IP entry, it sends a first MAC-IP advertisement message to the third network device, so that the third network device establishes a first remote MAC-IP entry.

[0092] Wherein the first MAC-IP notification message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes a first sequence number and a first valid lifetime value, where the first sequence number is the sum of the highest sequence number in the remote MAC-IP entry matching the local MAC-IP entry and 1.

[0093] It can be understood that the first MAC-IP notification message further includes the MAC address and the first IP address in the local MAC-IP entry, and correspondingly, the first remote MAC-IP entry also includes the MAC address and the first IP address.

[0094] Here, the third network device is an aggregation device, and the third network device and the second network device may be the same aggregation device or different aggregation devices.

[0095] A remote MAC-IP entry matching a local MAC-IP entry refers to a remote MAC-IP entry that has the same MAC address and IP address as the local MAC-IP entry. When a remote MAC-IP entry matching a local MAC-IP entry is stored in the first network device, it indicates that the terminal has been migrated from another access device, and each remote MAC-IP entry includes a sequence number. The larger the sequence number included in the remote MAC-IP entry, the later the creation time of the remote MAC-IP entry.

[0096] Taking an IPv6 network as an example, the first MAC-IP notification message includes the fields shown in Table 2. [Table 2]

[0097] Based on the above embodiment, the first network device may delete an ARP entry or an ND entry. For example, taking an IPv6 scenario as an example, some terminals may not respond to the ND entry aging detection message issued by the first network device when in a locked screen state, etc., and the ND entry corresponding to the terminal in the first network device will be aged and deleted. Alternatively, when the access device detects that the access interface of the terminal is interrupted, the access device may delete the ND entry of the terminal that has come online through the access interface.

[0098] After issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resource, the first network device deletes the forwarding MAC-IP entry when the access entry matching the local MAC-IP entry is deleted. Here, the access entry is an ND entry or an ARP entry.

[0099] In an embodiment of the present invention, the hardware resource can be saved by deleting the forwarding MAC-IP entry in the hardware resource. At this time, the local MAC-IP entry stored in the memory is not deleted, so when the terminal accesses again and re-learns the access entry of the terminal, the forwarding MAC-IP entry can be re-issued to the hardware resource based on the local MAC-IP entry. Therefore, the deletion of the forwarding MAC-IP entry will not cause legitimate packets to be discarded, and network security can be improved.

[0100] Furthermore, the deletion of an ND entry or ARP entry does not mean that the lease period for the IP address applied for by the terminal has expired, so after the ND entry or ARP entry is deleted, the DHCP relay entry corresponding to the terminal is not deleted.

[0101] In an embodiment of the present invention, the first network device can also receive MAC-IP entries notified by other network devices. Based on this, in the above S201, if the protocol connection with the second network device is interrupted, before obtaining the valid lifetime value included in each remote MAC-IP entry, the method further comprises: receiving a second MAC-IP notification message sent from the second network device and establishing a second remote MAC-IP entry, where the second MAC-IP notification message includes a second valid lifetime value and a second sequence number of the second IP address; the second remote MAC-IP entry includes a second valid lifetime value and a second sequence number of the second IP address; it can be understood that the second MAC-IP notification message further includes a MAC address and a second IP address; and correspondingly, the second remote MAC-IP entry also includes a MAC address and a second IP address.

[0102] Optionally, the second MAC-IP advertisement message may further include a preferred lifetime value of the second IP address, and correspondingly, the remote MAC-IP entry also includes a preferred lifetime value of the second IP address.

[0103] The second network device notifies the first network device of the MAC-IP entry received from a network device other than the first network device, so that after the terminal migrates from another access device to the first network device, the first network device can use the second remote MAC-IP entry to check the validity of the terminal's packets, thereby preventing unauthorized packets from entering the network and improving network security. Furthermore, since the second MAC-IP notification message includes a second sequence number, when the terminal subsequently migrates to the first network device, the first network device can obtain the migration status of the terminal based on the sequence number.

[0104] The first network device may store the second remote MAC-IP entry in its memory. At this time, the second remote MAC-IP entry does not occupy a control MAC-IP entry resource in its memory. That is, the first network device can store the second remote MAC-IP entry using available resources other than the control MAC-IP entry resource in its memory, and at this time, the remote MAC-IP entry does not occupy a hardware resource. The first network device maintains one remote MAC-IP entry for the second network device. The second remote MAC-IP entry is stored in the remote MAC-IP table.

[0105] Taking the IPv6 scenario as an example, the fields contained in the second remote MAC-IP entry are shown in Table 3. [Table 3]

[0106] In an embodiment of the present invention, the first network device further comprises a local MAC-IP table, and the local MAC-IP table includes a first local MAC-IP entry including a third sequence number.

[0107] After establishing the second remote MAC-IP entry, if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, delete the first local MAC-IP entry and delete the DHCP relay entry corresponding to the first local MAC-IP entry.

[0108] Here, when the second remote MAC-IP entry matches the first local MAC-IP entry, it means that the MAC address and IP address included in the second remote MAC-IP entry are the same as the MAC address and IP address included in the first local MAC-IP entry.

[0109] If the second sequence number is greater than the third sequence number, it means that the terminal corresponding to the first local MAC-IP entry has already moved to another access device. That is, the first network device will not receive service packets sent from the terminal until the terminal returns. Accordingly, the first network device cannot continue to use the first local MAC-IP entry to check the validity of the terminal's service packets, so it deletes the first local MAC-IP entry and deletes the DHCP relay entry corresponding to the first local MAC-IP entry.

[0110] The first network device can delete the first local MAC-IP entry from its memory and delete the corresponding forwarding MAC-IP entry stored in the hardware resources of the hardware forwarding chip, thereby saving memory and hardware resources of the first network device without affecting network security.

[0111] After creating the first local MAC-IP entry, the first network device notifies other network devices of the first local MAC-IP entry. Correspondingly, after deleting the first local MAC-IP entry, the first network device needs to send a MAC-IP revocation message to the other network devices, thereby causing the other network devices to delete the remote MAC-IP entry corresponding to the first local MAC-IP entry.

[0112] In addition, when the first network device deletes a DHCP relay entry because the terminal releases the IP address or the IP address lease expires, the first network device can simultaneously delete the local MAC-IP entry corresponding to the DHCP relay entry.

[0113] In another embodiment of the present invention, the first network device comprises a local MAC-IP table, and the local MAC-IP table includes at least one local MAC-IP entry. After establishing the second remote MAC-IP entry, the method further includes the steps of:

[0114] In step A, a first packet transmitted from a terminal is received, and the first packet includes the MAC address and the IP address of the terminal.

[0115] In step B, if there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match a second remote MAC-IP entry, access detection is performed for the terminal.

[0116] If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, but the MAC address and IP address of the terminal match a second remote MAC-IP entry, it can be understood that this means that the terminal has migrated from another access device.

[0117] Optionally, after the terminal migrates to the AP connected to the first network device, if the terminal does not immediately renew the IP address lease expiration, the first network device may receive a first packet from the terminal, and the first packet may be a protocol packet or a service packet.

[0118] After the first network device receives the first packet, the forwarding plane of the first network device generates a first packet event for the source MAC address of the first packet, which in an IPv6 scenario triggers an ND discovery, and in an IPv4 scenario triggers an ARP discovery.

[0119] In step C, upon receiving the access response sent from the terminal, a composite MAC-IP entry is generated, which includes the MAC address and IP address of the terminal, a port identifier, and a VLAN identifier.

[0120] In an IPv4 scenario, the first network device may generate an ARP entry after performing ARP detection and receiving an access response sent from the terminal. The ARP entry includes a port identifier and a VLAN identifier for the terminal access. Furthermore, the first network device generates a composite MAC-IP entry based on the second remote MAC-IP entry and the ARP entry.

[0121] In an IPv6 scenario, after the first network device performs ND detection, it generates an ND entry when it receives an access response sent from the terminal. The ND entry includes a port identifier and a VLAN identifier for the terminal access. Furthermore, the first network device generates a composite MAC-IP entry based on the second remote MAC-IP entry and the ND entry.

[0122] Using the IPv6 scenario as an example, the fields contained in a composite MAC-IP entry are shown in Table 4. [Table 4]

[0123] The composite MAC-IP entry is used only by the first network device that generates the composite MAC-IP entry, and the first network device does not notify other network devices of the composite MAC-IP entry.

[0124] Wherein, the composite MAC-IP entry occupies resources for storing the control MAC-IP entry in the memory of the first network device.

[0125] In step D, a forwarding MAC-IP entry is generated based on the composite MAC-IP entry, where the forwarding MAC-IP entry includes the MAC address and the IP address of the terminal.

[0126] Step E issues a forwarding MAC-IP entry to the hardware resource.

[0127] The hardware resource is a hardware resource for storing forwarding MAC-IP entries in the hardware forwarding chip.

[0128]

[0013] By adopting the above method, after the first network device generates the second remote MAC-IP entry, the terminal may not have migrated to the terminal connected to the first network device at this time, so there is no need to perform a security check using the second remote MAC-IP entry, and there is no need to issue a forwarding MAC-IP entry corresponding to the second remote MAC-IP entry to hardware resources, thereby avoiding occupying scarce hardware resources.

[0014] After the first network device determines that the terminal corresponding to the second remote MAC-IP entry will access the first network device, it generates a composite MAC-IP entry and issues a forwarding MAC-IP entry corresponding to the composite MAC-IP entry to hardware resources, and further performs control plane check and forwarding plane check on packets from the terminal, thereby denying unauthorized packets from entering the network and improving network security.

[0129] Based on the above embodiment, the first network device may delete an ARP entry or an ND entry. For example, taking an IPv6 scenario as an example, some terminals may not respond to the ND entry aging detection message issued by the first network device when in a state such as a locked screen, and the ND entry corresponding to the terminal in the first network device is aged and deleted. Alternatively, when the access device detects that the access interface of the terminal is interrupted, the access device may delete the ND entry of the terminal that has come online through the access interface.

[0130] When the access entry of the terminal is deleted, the first network device deletes the above-mentioned merged MAC-IP entry and forwarding MAC-IP entry.

[0131] Among them, the access entry of a terminal is the ND entry or ARP entry corresponding to the terminal.

[0132] The first network device deletes the ND entry or ARP entry only when it determines that the terminal has been suspended. Furthermore, since there is no need to temporarily check the validity of packets from the terminal, the first network device can delete the composite MAC-IP entry stored in memory and delete the forwarding MAC-IP entry corresponding to the composite MAC-IP entry. This reduces the occupation of memory and hardware resources in the first network device. Because the second remote MAC-IP entry corresponding to the composite MAC-IP entry has not been deleted in the first network device, when the terminal accesses again, the first network device generates a new composite MAC-IP entry based on the second remote MAC-IP entry, and legitimate packets from the terminal are not discarded. The first network device can perform packet security checks using the composite MAC-IP entry, improving network security.

[0133] The MAC-IP notification message sent from the first network device will now be described.

[0134] The MAC-IP notification message includes a first extended community attribute, and the first extended community attribute includes a valid lifetime value of the IP address.

[0135] Optionally, the MAC-IP notification message includes a second extended community attribute, and the second extended community attribute includes a sequence number of the MAC-IP entry.

[0136] The first network device sends a MAC-IP notification message and a MAC-IP withdrawal message according to the BGP protocol, and the MAC-IP notification message and the MAC-IP withdrawal message can both be BGP Update packets.

[0137] The MAC-IP Notify message may be a BGP Update packet that carries a Multiprotocol_Reachable_Network_Layer_Reachability_Information (MP_REACH_NLRI) attribute, which indicates that the terminal corresponding to the MAC-IP entry can reach the device that sends the MAC-IP Notify message.

[0138] The MAC-IP withdrawal message may be a BGP Update packet that carries a Multiprotocol_UNReachable_Network_Layer_Reachability_Information (MP_UNREACH_NLRI) attribute, which indicates that the endpoint corresponding to the MAC-IP entry is unreachable relative to the device sending the MAC-IP withdrawal message.

[0139] The MP_REACH_NLRI attribute and the MP_UNREACH_NLRI attribute both contain MAC-IP NLRI. The format of the MAC-IP NLRI includes a route type, a length, and a route type specific, as shown in FIG.

[0140] Here, Route Type represents the type of MAC-IP NLRI and occupies one octet. In an embodiment of the present invention, the Route Type can be defined as a route type for transmitting a MAC-IP entry.

[0141] Length represents the length of the MAC-IP NLRI and occupies one octet. The Route Type specific indicates the route type of the MAC-IP NLRI, and the number of bits occupied is variable.

[0142] As shown in FIG. 4, the Route Type specific includes a Route Distinguisher (RD), an Ethernet Segment Identifier, an Ethernet Tag ID, a MAC Address Length, a MAC Address, an IP Address Length, and an IP Address.

[0143] Of these, the RD occupies 8 octets.

[0144] The Ethernet Segment Identifier is a unique non-zero identifier that identifies an Ethernet segment and occupies 10 octets.

[0145] The Ethernet Tag ID is used to store the VLAN identifier of the VLAN in which the terminal is located, and occupies 4 octets.

[0146] The MAC Address Length field is used to record the length of the MAC address of the terminal and occupies one octet.

[0147] The MAC Address field is used to record the MAC address of the terminal and occupies 6 octets.

[0148] The IP Address Length field is used to record the length of the IP address of the terminal and occupies one octet.

[0149] The IP Address is used to record the IP address of the terminal and occupies 0, 4 or 16 octets.

[0150] To add the valid lifetime value of the IP address in the MAC-IP entry to the BGP Update packet, the BGP protocol may be extended to introduce a first extended community attribute of the MAC-IP entry into the BGP protocol. The length of the first extended community attribute may be 16 bytes, and its structure is shown in Figure 5.

[0151] Here, "Type" represents the type of the first extended community attribute and is 1 byte long. For example, the value of "Type" may be 0x8d. The value of "Type" may be set according to actual circumstances, but is not limited in the embodiments of the present invention.

[0152] Sub-Type represents the sub-type of the first extended community attribute and is 1 byte long. For example, the value of Sub-Type may be 0x01. The value of Sub-Type can be set according to actual circumstances, but is not limited in the embodiments of the present invention.

[0153] Reserved is a reserved bit and has a length of 2 bytes. For example, the value of Reserved may be 0. The value of Reserved can be set according to the actual situation, but is not limited in the embodiment of the present invention.

[0154] The Preferred lifetime is the preferred lifetime value of the IP address in the local MAC-IP entry, and is 4 bytes in length. In the present embodiment, this parameter is not used.

[0155] Valid lifetime is the valid lifetime value of the IP address in the local MAC-IP entry, and is 4 bytes in length.

[0156] Similarly, to add a sequence number to a BGP Update packet, the BGP protocol may be extended and a second extended community attribute corresponding to a MAC-IP entry may be introduced into the BGP protocol. The length of the second extended community attribute may be 8 bytes, and its structure is shown in Figure 6.

[0157] Here, "Type" represents the type of the second extended community attribute and is 1 byte long. For example, the value of "Type" may be 0x8e. The value of "Type" can be set according to actual circumstances, but is not limited in the embodiments of the present invention.

[0158] Sub-Type represents the sub-type of the second extended community attribute and is 1 byte long. For example, the value of Sub-Type may be 0x01. The value of Sub-Type can be set according to actual circumstances, but is not limited in the embodiment of the present invention.

[0159] Reserved is a reserved bit and is 2 bytes long. As an example, the value of Reserved may be set to 0. The value of Reserved can be set according to the actual situation, but is not limited in the embodiment of the present invention.

[0160] The Sequence Number is a sequence number corresponding to the MAC-IP entry and is 4 bytes in length.

[0161] Corresponding to the above embodiment, an embodiment of the present invention further provides a security entry maintenance method applied to a second network device. The second network device may be Spine1, Spine2, or Spine3 in FIG. 1. The second network device has a first remote MAC-IP table, which includes at least one remote MAC-IP entry notified from a fourth network device. As shown in FIG. 7, the method includes the following steps:

[0162] In S701, when the protocol connection with the fourth network device is interrupted, the valid lifetime value included in each remote MAC-IP entry is obtained.

[0163] Here, the valid lifetime value is intended to indicate the valid lifetime of the IP address included in the remote MAC-IP entry.

[0164] The second network device may be an aggregation device, and the fourth network device may be an access device or an aggregation device that is protocol connected to the second network device.

[0165] Taking the network system shown in FIG. 1 as an example, when the second network device is Spine1 in FIG. 1, the fourth network device may be Leaf1, Leaf2 or Leaf3, or may be Spine3.

[0166] Alternatively, if the second network device is Spine3 in FIG. 1, the fourth network device may be Spine1 or Spine2.

[0167] The protocol connection between the second network device and the fourth network device may be a BGP protocol connection. Alternatively, the protocol connection between the second network device and the fourth network device may be a customized private protocol connection. When the protocol connection is a private protocol connection, each network device notifies the MAC-IP entry through the private protocol.

[0168] In S702, if the duration that the protocol connection is interrupted reaches the valid lifetime value, delete at least one remote MAC-IP entry.

[0169] It can be understood that when the first remote MAC-IP table includes one MAC-IP entry, the second network device obtains the valid lifetime value included in the MAC-IP entry. The second network device maintains the valid lifetime value of the remote MAC-IP entry starting from the time when it detects the interruption of the protocol connection. That is, after detecting the interruption of the protocol connection, the second network device maintains the valid lifetime value of the remote MAC-IP entry and does not delete the remote MAC-IP entry until the valid lifetime value is reached.

[0170] If the protocol connection is not restored when the time elapsed from the start point reaches the valid lifetime value, the remote MAC-IP entry is deleted.

[0171] For example, if the valid lifetime is 100,000 seconds, when the second network device detects an interruption in the protocol connection, it starts counting and maintains the remote MAC-IP entry for 100,000 seconds, and if the protocol connection is not restored after 100,000 seconds, the second network device deletes the remote MAC-IP entry.

[0172] When the first remote MAC-IP table includes multiple MAC-IP entries, the second network device can obtain the valid lifetime values ​​of the multiple remote MAC-IP entries.

[0173] In one embodiment, when the duration of the interrupted protocol connection reaches all of the acquired valid lifetime values, i.e., when the duration of the interrupted protocol connection reaches the largest lifetime value among the acquired valid lifetime values, multiple MAC-IP entries included in the second remote MAC-IP table are deleted at once.

[0174] In another embodiment, for each valid lifetime value, if the duration that the protocol connection has been interrupted reaches the valid lifetime value, the MAC-IP entry to which the valid lifetime value belongs is deleted.

[0175] With the above method, the remote MAC-IP entry in the second network device includes a valid lifetime value, which indicates the valid lifetime of the IP address included in the remote MAC-IP entry. When the duration of the protocol connection interruption reaches the valid lifetime value, the IP address included in the MAC-IP entry becomes invalid. That is, the terminal that originally applied for the IP address can no longer use the IP address. Deleting the remote MAC-IP entry at this time does not affect subsequent validity checks for the terminal, does not affect network security, and prevents the remote MAC-IP entry from continuing to occupy resources in the second network device. Since the second network device does not delete the remote MAC-IP entry until the duration of the protocol connection interruption reaches the valid lifetime value, even when the source address security check mechanism is enabled, legitimate packets matching the remote MAC-IP entry are not discarded and invalid packets are prevented from entering the network, thereby improving network security.

[0176] In another embodiment of the present invention, the second network device receives MAC-IP entries notified by other network devices, and based on this, when the protocol connection with the fourth network device is interrupted in the above step S701, before obtaining the valid lifetime value of each remote MAC-IP entry, the method further comprises: receiving a first MAC-IP advertisement message sent from the fourth network device and establishing a first remote MAC-IP entry;

[0177] The first MAC-IP notification message includes a first valid lifetime value and a first sequence number of the first IP address, and the first remote MAC-IP entry includes a first valid lifetime value and a first sequence number correspondingly.

[0178] It can be understood that the first MAC-IP notification message further includes a MAC address and a first IP address, and the first remote MAC-IP entry also includes the MAC address and the first IP address.

[0179] Optionally, the first MAC-IP advertisement message may further include a preferred lifetime value of the first IP address, and correspondingly, the first remote MAC-IP entry also includes a preferred lifetime value of the first IP address.

[0180] It can be understood that since MAC-IP entries are notified to each other between network devices, after a terminal transitions, the access device accessed by the terminal can perform a validity check on the terminal's packets based on the remote MAC-IP entry, thereby denying unauthorized packets from entering the network and improving network security.

[0181] In one embodiment of the present invention, the second network device further includes a second remote MAC-IP table, and the second remote MAC-IP table includes a second remote MAC-IP entry including a second sequence number. After the second network device establishes the remote MAC-IP entry, the method further includes: If the first sequence number is greater than the second sequence number, sending a second MAC-IP notification message to another network device other than the fourth network device, the second MAC-IP notification message including the first valid lifetime value and the first sequence number.

[0182] If the first sequence number is greater than the second sequence number, it means that there is no remote MAC-IP entry in each remote MAC-IP table stored in the second network device that matches the first remote MAC-IP entry and contains a sequence number greater than the first sequence number.

[0183] It can be understood that for remote MAC-IP entries with the same IP address and MAC address, the larger the sequence number, the later the creation time of the remote MAC-IP entry corresponding to that sequence number. Therefore, if the first sequence number is larger than the second sequence number, it means that the first remote MAC-IP entry is the most recently created MAC-IP entry, and further, it is necessary to notify other network devices other than the fourth network device of the first remote MAC-IP entry.

[0184] When the above method is adopted, since the sequence number indicates the order in which MAC-IP entries corresponding to the same terminal were created, the larger the sequence number, the later the creation time of the MAC-IP entry corresponding to that sequence number. Therefore, a remote MAC-IP entry with a small sequence number may not be applicable to the terminal corresponding to that remote MAC-IP entry. If the first sequence number is larger than the second sequence number, a second MAC-IP notification message is sent to network devices other than the fourth network device. This improves the timeliness and accuracy of MAC-IP notification.

[0185] In another embodiment of the present invention, based on the embodiment corresponding to FIG. 7, the second network device further includes a third remote MAC-IP table, and the third remote MAC-IP table includes at least one remote MAC-IP entry.

[0186] It can be understood that after creating a remote MAC-IP entry, the second network device notifies other network devices than the fourth network device of the created remote MAC-IP entry. Correspondingly, after deleting a remote MAC-IP entry, the second network device must also send a MAC-IP revocation message or a MAC-IP notification message based on the deleted remote MAC-IP entry. After the second network device deletes at least one remote MAC-IP entry, there are two specific situations:

[0187] In situation 1, for each deleted remote MAC-IP entry, if there is no remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, send a first MAC-IP revocation message to another network device other than the fourth network device.

[0188] The first MAC-IP revocation message includes the MAC address and IP address of the remote MAC-IP entry.

[0189] After receiving the first MAC-IP revocation message, other network devices other than the fourth network device can timely update the remote MAC-IP entries stored therein, thereby avoiding continuing to use the invalid remote MAC-IP entries and improving network security.

[0190] In situation 2, for each deleted remote MAC-IP entry, if there is a remote MAC-IP entry in the third remote MAC-IP table that matches the remote MAC-IP entry, select the third remote MAC-IP entry with the highest sequence number from the other matching MAC-IP entries, and send a fifth MAC-IP notification message to other network devices other than the fifth network device.

[0191] Wherein, the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number, and the third MAC-IP notification message correspondingly includes the second valid lifetime value and the third sequence number, and the fifth network device is the source device of the third remote MAC-IP entry, which may be an access device or an upper-level aggregation device of the aggregation device.

[0192] That is, if the second network device has other remote MAC-IP entries that match the deleted remote MAC-IP entry, the second network device must re-advertise the remote MAC-IP entry that has the same IP address and MAC address as the deleted remote MAC-IP entry and has the highest sequence number.

[0193] There may be multiple remote MAC-IP entries with the highest sequence number among the remote MAC-IP entries that match the remote MAC-IP entry. That is, the multiple remote MAC-IP entries have the same sequence number, and all of them are the highest. In this case, the second network device randomly selects one of the multiple remote MAC-IP entries with the highest sequence number, and notifies the selected remote MAC-IP entry with the highest sequence number to other network devices other than the fifth network device as the third remote MAC-IP entry.

[0194] For example, in the second network device: Remote MAC-IP entry 1 from network device A with sequence number 3; Remote MAC-IP entry 2 from network device B, with sequence number 2; Remote MAC-IP entry 3 from network device C, with sequence number 1; A remote MAC-IP entry 4 from network device D, which has a sequence number of 2, is stored.

[0195] The MAC addresses and IP addresses in the above four remote MAC-IP entries are all the same. After the protocol connection between the second network device and network device A is interrupted and then remote MAC-IP entry 1 is deleted by the method described in the above embodiment, it can be determined that remote MAC-IP entry 2 and remote MAC-IP entry 4 have the largest sequence numbers. If the second network device randomly selects remote MAC-IP entry 2 from remote MAC-IP entry 2 and remote MAC-IP entry 4, the second network device will notify network device C and network device D of remote MAC-IP entry 2.

[0196] After receiving the remote MAC-IP entry 2 notified from the second network device, the network device C searches for the remote MAC-IP entry 1 notified previously by the second network device, and changes the remote MAC-IP entry 1 stored in itself to the remote MAC-IP entry 2.

[0197] After receiving the remote MAC-IP entry 2 notified from the second network device, the network device D searches for the remote MAC-IP entry 1 notified previously by the second network device, and changes the remote MAC-IP entry 1 stored in itself to the remote MAC-IP entry 2.

[0198] In this way, after deleting a remote MAC-IP entry, if other remote MAC-IP entries with the same MAC address and IP address are still stored, the second network device will notify other network devices of the remote MAC-IP entry in a timely manner, thereby preventing other network devices from continuing to use the invalid remote MAC-IP entry, ensuring the accuracy of the remote MAC-IP entries stored in each network device, and improving network security.

[0199] The MAC-IP notification message sent from the second network device will now be described.

[0200] The MAC-IP notification message sent from the second network device includes a first extended community attribute that includes a valid lifetime value for the IP address.

[0201] The MAC-IP notification message sent from the second network device includes a second extended community attribute that includes a sequence number of the MAC-IP entry.

[0202] For the format of the MAC-IP notification message, please refer to the relevant description in the above embodiment.

[0203] The security entry maintenance method provided by the embodiment of the present invention will be described below in conjunction with a specific scenario.

[0204] As shown in Figure 8, the structure of Figure 8 is the same as Figure 1, in which Leaf1, Leaf2 and Leaf3 are access devices, Spine1 and Spine2 are aggregation devices, and Spine3 is an upper-level aggregation device of Spine1 and Spine2.

[0205] After Leaf1 in Area1 creates a new local MAC-IP entry, it sends a MAC-IP notification message to Spine1 via a protocol connection. The MAC-IP notification message contains the IP address, MAC address, sequence number (SN) and valid lifetime value of the IP address in the local MAC-IP entry. The sequence number in the MAC-IP notification message is 1.

[0206] After receiving the MAC-IP notification message sent from Leaf1, Spine1 creates a remote MAC-IP entry, and the remote MAC-IP entry includes the IP address, MAC address, SN and valid lifetime value of the IP address in the MAC-IP notification message.

[0207] At this time, Spine1 stores only one remote MAC-IP entry corresponding to the terminal and whose sequence number is 1. Spine1 sends a MAC-IP notification message to Leaf2, Leaf3, and Spine3. The MAC-IP notification message includes the contents of the remote MAC-IP entry.

[0208] Leaf2, Leaf3 and Spine3 can also create a remote MAC-IP entry after receiving the MAC-IP notification message.

[0209] Furthermore, assuming that there is no other remote MAC-IP entry in Spine3 that matches the remote MAC-IP entry, Spine3 sends a MAC-IP notification message to Spine2 in Area 2, and the MAC-IP notification message includes the contents of the remote MAC-IP entry.

[0210] Spine2 can also create a remote MAC-IP entry after receiving a MAC-IP notification message.

[0211] Furthermore, based on FIG. 8, if the terminal migrates to AP2 connected to Leaf2, as shown in FIG. 9, in one embodiment, when the terminal immediately renews the lease of the IPv6 address to the DHCPv6 server, Leaf2 can generate a DHCP relay entry and generate a local MAC-IP entry based on the DHCP relay entry.

[0212] Then, Leaf2 sends a MAC-IP notification message to Spine1. The sequence number added to the MAC-IP notification message is 2. After receiving the MAC-IP notification message, Spine1 creates a remote MAC-IP entry based on the MAC-IP notification message, and the sequence number included in the remote MAC-IP entry is 2.

[0213] At this time, Spine1 determines that there is still a remote MAC-IP stored locally with a sequence number of 1 and the same MAC address and IP address as in this newly created remote MAC-IP entry.

[0214] Since the sequence number of the newly created remote MAC-IP entry is relatively large, Spine1 notifies Spine3, Leaf1, and Leaf3 of the remote MAC-IP entry with sequence number 2.

[0215] After Spine3, Leaf1, and Leaf3 receive the MAC-IP notification message, Leaf1 creates a remote MAC-IP entry with a sequence number of 2. At this time, if both Spine3 and Leaf3 store a remote MAC-IP entry with a sequence number of 1 from Spine1 and the MAC address and IP address in the remote MAC-IP entry are the same as the MAC address and IP address in the MAC-IP notification message received this time, Spine3 and Leaf3 change the remote MAC-IP entry with a sequence number of 1 to the remote MAC-IP entry with a sequence number of 2.

[0216] Spine3 then sends a MAC-IP notification message to Spine2. Spine2 then changes the remote MAC-IP entry with the corresponding sequence number 1 to the remote MAC-IP entry with the sequence number 2.

[0217] When a terminal adopts another embodiment, based on Fig. 8, if the terminal moves to AP2 connected to Leaf2, the terminal does not immediately renew the lease expiration of the IPv6 address to the DHCPv6 server, as shown in Fig. 10. When Leaf2 receives a packet that is a protocol packet or a service packet sent from the terminal, the first packet event triggers Leaf2 to perform ND detection for the terminal. Leaf2 learns the ND entry corresponding to the terminal, and generates a composite MAC-IP entry based on the ND entry and the remote MAC-IP entry corresponding to the terminal stored in Leaf2.

[0218] In addition, based on the embodiment of Figure 10, after Leaf2 generates a composite MAC-IP entry corresponding to the terminal, when the terminal subsequently renews the lease of its IPv6 address to the DHCPv6 server, the access device may execute the flow described in Figure 9, i.e., Leaf2 may generate a local MAC-IP entry for the terminal.

[0219] Based on the same idea, an embodiment of the present invention provides a security entry maintenance device applied to a first network device, the first network device having a remote MAC-IP table, the remote MAC-IP table including at least one remote MAC-IP entry notified from a second network device. As shown in Figure 11, the device comprises: an acquisition module 1101 for acquiring a valid lifetime value included in each remote MAC-IP entry when a protocol connection with a second network device is interrupted, the valid lifetime value indicating the valid lifetime of an IP address included in the remote MAC-IP entry; a deletion module 1102 for deleting at least one remote MAC-IP entry when the duration for which the protocol connection has been suspended reaches the valid lifetime value.

[0220] Optionally, the apparatus further comprises: an establishing module for, when the first network device generates a DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, wherein the local MAC-IP entry includes a first valid lifetime value of the first IP address; a sending module for sending a first MAC-IP notification message to the third network device, so that the third network device establishes a first remote MAC-IP entry; Wherein, the first MAC-IP notification message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes a first sequence number and a first valid lifetime value; The first sequence number is the sum of the highest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0221] Optionally, the deletion module 1102 further deletes a forwarding MAC-IP entry when an access entry matching the local MAC-IP entry is deleted.

[0222] Optionally, the apparatus further comprises: a receiving module for receiving a second MAC-IP notification message sent from a second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; and an establishing module for establishing a second remote MAC-IP entry including a second valid lifetime value and a second sequence number.

[0223] Optionally, the first network device comprises a local MAC-IP table, the local MAC-IP table including at least one local MAC-IP entry; The apparatus further includes a detection module, a generation module, and an issuing module; The receiving module further receives a first packet sent from the terminal, the first packet including a MAC address and an IP address of the terminal; The detection module performs access detection for the terminal when there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal and the MAC address and IP address of the terminal match a second remote MAC-IP entry; The generating module generates a synthetic MAC-IP entry when receiving an access response sent from the terminal, the synthetic MAC-IP entry including a MAC address and an IP address of the terminal, a port identifier, and a VLAN identifier; The generating module further generates a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including the MAC address and the IP address of the terminal; The issuing module issues the forwarding MAC-IP entry to the hardware resource.

[0224] Optionally, the deletion module 1102 further deletes the composite MAC-IP entry and the forwarding MAC-IP entry when the access entry of the terminal is deleted.

[0225] Optionally, the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including the third sequence number; The deletion module 1102 further deletes the first local MAC-IP entry and deletes the DHCP relay entry corresponding to the first local MAC-IP entry if the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number.

[0226] Optionally, the MAC-IP notification message sent from the first network device includes a first extended community attribute that includes a valid lifetime value of the IP address.

[0227] Optionally, the MAC-IP notification message sent from the first network device further includes a second extended community attribute including a sequence number of the MAC-IP entry.

[0228] Based on the same idea, an embodiment of the present invention provides a security entry maintenance device applied to a second network device, the second network device having a first remote MAC-IP table, the first remote MAC-IP table including at least one remote MAC-IP entry notified from a fourth network device, as shown in FIG. 12 , the device: an acquisition module 1201 for acquiring a valid lifetime value included in each remote MAC-IP entry when the protocol connection with the fourth network device is interrupted, the valid lifetime value indicating the valid lifetime of the IP address included in the remote MAC-IP entry; a deletion module 1202 for deleting at least one remote MAC-IP entry when the duration for which the protocol connection has been suspended reaches the valid lifetime value.

[0229] Optionally, the apparatus further comprises: a receiving module for receiving a first MAC-IP notification message sent from a fourth network device, the first MAC-IP notification message including a first valid lifetime value of the first IP address and a first sequence number; and an establishing module for establishing a first remote MAC-IP entry including a first valid lifetime value and a first sequence number.

[0230] Optionally, the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table includes a second remote MAC-IP entry, the second remote MAC-IP entry matches the first remote MAC-IP entry, and the second remote MAC-IP entry includes a second sequence number, and the device further comprises: and a sending module for sending a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device if the first sequence number is greater than the second sequence number.

[0231] Optionally, the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table includes at least one remote MAC-IP entry, and the device further comprises a sending module; The transmission module is For each deleted remote MAC-IP entry, if there is no remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, sending a first MAC-IP revocation message to another network device other than the fourth network device, the first MAC-IP revocation message including the MAC address and the IP address in the remote MAC-IP entry; or, For each deleted remote MAC-IP entry, if there is a remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, select the third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number, and send a third MAC-IP notification message including the second valid lifetime value and the third sequence number to another network device other than the fifth network device, where the fifth network device is the source device of the third remote MAC-IP entry.

[0232] Optionally, the MAC-IP notification message sent from the second network device includes a first extended community attribute that includes a valid lifetime value of the IP address.

[0233] Optionally, the MAC-IP notification message sent from the second network device further includes a second extended community attribute including a sequence number of the MAC-IP entry.

[0234] Based on the same idea, an embodiment of the present invention further provides a first network device, wherein the first network device comprises a remote MAC-IP table, and the remote MAC-IP table includes at least one remote MAC-IP entry notified by the second network device, and as shown in FIG. 13 , the first network device: a processor 1301; Walkie-talkie 1304 and a machine-readable storage medium 1302 having stored thereon machine-executable instructions executable by the processor 1301; The machine-executable instructions may be used to cause the processor 1301 to: When the protocol connection with the second network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating the valid lifetime of the IP address included in the remote MAC-IP entry; and deleting at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value.

[0235] Optionally, the machine-executable instructions may further cause the processor 1301 to: When the first network device generates the DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, wherein the local MAC-IP entry includes a first valid lifetime value of the first IP address; sending, by the transceiver 1304, a first MAC-IP advertisement message to the third network device, so that the third network device establishes a first remote MAC-IP entry; Wherein, the first MAC-IP notification message includes a first sequence number and a first valid lifetime value, and the first remote MAC-IP entry includes a first sequence number and a first valid lifetime value; The first sequence number is the sum of the highest sequence number in the remote MAC-IP entry that matches the local MAC-IP entry and 1.

[0236] Optionally, the machine-executable instructions may further cause the processor 1301 to: When an access entry that matches the local MAC-IP entry is deleted, a step of deleting the forwarding MAC-IP entry is performed.

[0237] Optionally, the machine-executable instructions may further cause the processor 1301 to: receiving, by the transceiver 1304, a second MAC-IP advertisement message sent from the second network device, the second MAC-IP advertisement message including a second valid lifetime value of the second IP address and a second sequence number; establishing a second remote MAC-IP entry including a second valid lifetime value and the second sequence number.

[0238] Optionally, the first network device comprises a local MAC-IP table, the local MAC-IP table including at least one local MAC-IP entry; The machine-executable instructions further cause the processor 1301 to: receiving, by the transceiver 1304, a first packet transmitted from the terminal, the first packet including a MAC address and an IP address of the terminal; performing access detection for the terminal when there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal and the MAC address and IP address of the terminal match a second remote MAC-IP entry; generating a composite MAC-IP entry when receiving an access response sent from the terminal, the composite MAC-IP entry including the MAC address and IP address of the terminal, a port identifier, and a VLAN identifier; generating a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including the MAC address and the IP address of the terminal; and issuing the forwarding MAC-IP entry to a hardware resource.

[0239] Optionally, the machine-executable instructions may further cause the processor 1301 to: When the access entry of the terminal is deleted, the step of deleting the composite MAC-IP entry and the forwarding MAC-IP entry is executed.

[0240] Optionally, the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including the third sequence number; The machine-executable instructions further cause the processor 1301 to: If the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, delete the first local MAC-IP entry and delete the DHCP relay entry corresponding to the first local MAC-IP entry.

[0241] Optionally, the MAC-IP notification message sent from the first network device includes a first extended community attribute that includes a valid lifetime value of the IP address.

[0242] Optionally, the MAC-IP notification message sent from the first network device further includes a second extended community attribute including a sequence number of the MAC-IP entry.

[0243] 13 further includes a communication bus 1303. The processor 1301, the machine-readable storage medium 1302, and the transceiver 1304 can communicate with each other via the communication bus 1303. The communication bus 1303 may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The communication bus may be an address bus, a data bus, a control bus, or the like.

[0244] The transceiver 1304 may be a wireless communication module, and under the control of the processor 1301, the transceiver 1304 exchanges data with other devices.

[0245] The machine-readable storage medium 1302 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. Note that the machine-readable storage medium may be at least one storage device remote from the processor.

[0246] Processor 1301 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc. Processor 1301 may also be a digital signal processing device (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware assembly.

[0247] Based on the same idea, an embodiment of the present invention further provides a second network device, wherein the second network device comprises a first remote MAC-IP table, the first remote MAC-IP table includes at least one remote MAC-IP entry notified by the fourth network device, and as shown in FIG. 14 , the second network device comprises: a processor 1401; Transceiver 1404 and a machine-readable storage medium 1402 having stored thereon machine-executable instructions executable by the processor 1401; The machine-executable instructions may cause the processor 1401 to: When the protocol connection with the fourth network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating the valid lifetime of the IP address included in the remote MAC-IP entry; and deleting at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value.

[0248] Optionally, the machine-executable instructions may further cause the processor 1401 to: receiving, by the transceiver 1404, a first MAC-IP advertisement message sent from the fourth network device, the first MAC-IP advertisement message including a first valid lifetime value of the first IP address and a first sequence number; establishing a first remote MAC-IP entry including a first valid lifetime value and a first sequence number.

[0249] Optionally, the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table includes a second remote MAC-IP entry, the second remote MAC-IP entry matches the first remote MAC-IP entry, and the second remote MAC-IP entry includes a second sequence number; The machine-executable instructions may cause the processor 1401 to: If the first sequence number is greater than the second sequence number, a step of sending a second MAC-IP notification message to another network device other than the fourth network device is performed, where the second MAC-IP notification message includes the first valid lifetime value and the first sequence number.

[0250] Optionally, the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry, and the machine-executable instructions cause the processor 1401 to: for each deleted remote MAC-IP entry, if there is no remote MAC-IP entry in the third remote MAC-IP table that matches the deleted remote MAC-IP entry, sending a first MAC-IP revocation message to another network device other than the fourth network device, the first MAC-IP revocation message including the MAC address and the IP address in the deleted remote MAC-IP entry; or, For each deleted remote MAC-IP entry, if a matching remote MAC-IP entry exists in the third remote MAC-IP table, the method performs the steps of selecting a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, where the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number; and sending a third MAC-IP notification message to another network device other than the fifth network device, where the third MAC-IP notification message includes the second valid lifetime value and the third sequence number, and the fifth network device is the source device of the third remote MAC-IP entry.

[0251] Optionally, the MAC-IP notification message sent from the second network device includes a first extended community attribute that includes a valid lifetime value of the IP address.

[0252] Optionally, the MAC-IP notification message sent from the second network device further includes a second extended community attribute including a sequence number of the MAC-IP entry.

[0253] 14 further includes a communication bus 1403. The processor 1401, the machine-readable storage medium 1402, and the transceiver 1404 can communicate with each other via the communication bus 1303. The communication bus 1403 may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The communication bus may be an address bus, a data bus, a control bus, or the like.

[0254] The transceiver 1404 may be a wireless communication module, and under the control of the processor 1401, the transceiver 1404 exchanges data with other devices.

[0255] The machine-readable storage medium 1402 may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk memory. Note that the machine-readable storage medium may be at least one storage device remote from the processor.

[0256] Processor 1401 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc. It may also be a Digital Signal Processing (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware assembly.

[0257] Based on the same idea as the security entry maintenance method provided by the above-mentioned embodiment of the present invention, the embodiment of the present invention further provides a machine-readable storage medium storing machine-executable instructions executable by a processor, the machine-executable instructions causing the processor to implement any one of the steps of the security entry maintenance method described above.

[0258] In another embodiment provided by the present invention, there is provided a computer program product including instructions which, when executed on a computer, cause the computer to perform the steps of the security entry maintenance method of any one of the above embodiments.

[0259] It should be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another and do not necessarily require or imply that any actual relationship or order exists between those entities or operations. Furthermore, the terms "comprise," "comprises," and any other variations thereof are intended to cover the non-exclusive "comprise," such that a process, method, article, or device that includes a set of elements not only includes those elements, but also other elements not expressly listed or that are inherent in such process, method, article, or device. Absent further limitations, an element qualified by the term "comprising" does not exclude the presence of other identical elements in a process, method, article, or device that includes the element.

[0260] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments may be referred to, and the main points described in each embodiment are the differences from other embodiments. In particular, the device embodiments are basically similar to the method embodiments, so they are only briefly described. For related points, please refer to the description of some of the method embodiments.

[0261] The above description is only a preferred embodiment of the present invention, and does not limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are included in the scope of protection of the present invention.

Claims

1. A method for maintaining security entries, the method being applied to a first network device, the first network device having a remote MAC-IP table containing at least one remote MAC-IP entry notified by a second network device; The security entry maintenance method includes: When a protocol connection with the second network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating a valid lifetime of an IP address included in the remote MAC-IP entry; and deleting the at least one remote MAC-IP entry if the duration that the protocol connection has been interrupted reaches the valid lifetime value. A method for maintaining security entries, comprising:

2. The security entry maintenance method further comprises: When the first network device creates a DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, wherein the local MAC-IP entry includes a first valid lifetime value of a first IP address; sending a first MAC-IP advertisement message to a third network device so that the third network device establishes a first remote MAC-IP entry; the first MAC-IP notification message includes a first sequence number and the first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value; the first sequence number is the sum of the highest sequence number in a remote MAC-IP entry that matches the local MAC-IP entry and 1; 2. The method for maintaining security entries according to claim 1.

3. After issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to the hardware resource, the security entry maintenance method further includes: deleting the forwarding MAC-IP entry when an access entry matching the local MAC-IP entry is deleted; 3. The security entry maintenance method according to claim 2.

4. When the protocol connection with the second network device is interrupted, before obtaining the valid lifetime value included in each remote MAC-IP entry, the security entry maintenance method further includes: receiving a second MAC-IP notification message sent from the second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; establishing a second remote MAC-IP entry including the second valid lifetime value and the second sequence number; 2. The method for maintaining security entries according to claim 1.

5. the first network device comprises a local MAC-IP table containing at least one local MAC-IP entry; After establishing the second remote MAC-IP entry, the security entry maintenance method further comprises: receiving a first packet transmitted from a terminal, the first packet including a MAC address and an IP address of the terminal; If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, performing access detection for the terminal; When receiving an access response sent from the terminal, generating a composite MAC-IP entry including the MAC address and IP address of the terminal, a port identifier, and a VLAN identifier; generating a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including the MAC address and the IP address of the terminal; publishing the forwarding MAC-IP entry to a hardware resource; 5. The method for maintaining security entries according to claim 4.

6. After issuing the forwarding MAC-IP entry to a hardware resource, the security entry maintenance method further includes: When the access entry of the terminal is deleted, deleting the composite MAC-IP entry and the forwarding MAC-IP entry.

6. The method for maintaining security entries according to claim 5.

7. the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including a third sequence number; After establishing the second remote MAC-IP entry, the security entry maintenance method further comprises: If the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, deleting the first local MAC-IP entry and deleting a DHCP relay entry corresponding to the first local MAC-IP entry.

5. The method for maintaining security entries according to claim 4.

8. the MAC-IP notification message sent from the first network device includes a first extended community attribute including a valid lifetime value of the IP address; 2. The method for maintaining security entries according to claim 1.

9. the MAC-IP notification message sent from the first network device further includes a second extended community attribute including a sequence number of the MAC-IP entry; 9. The method for maintaining security entries according to claim 8.

10. A method for maintaining security entries, comprising: The method is applied to a second network device, the second network device having a first remote MAC-IP table including at least one remote MAC-IP entry notified from a fourth network device; The security entry maintenance method includes: When a protocol connection with the fourth network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value indicating a valid lifetime of an IP address included in the remote MAC-IP entry; and deleting the at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value. A method for maintaining security entries, comprising:

11. When the protocol connection with the fourth network device is interrupted, before obtaining the valid lifetime value included in each remote MAC-IP entry, the security entry maintenance method further includes: receiving a first MAC-IP notification message sent from the fourth network device, the first MAC-IP notification message including a first valid lifetime value of a first IP address and a first sequence number; establishing a first remote MAC-IP entry including the first valid lifetime value and the first sequence number; 11. The method for maintaining security entries according to claim 10.

12. the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry matching the first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; After establishing the first remote MAC-IP entry, the security entry maintenance method further comprises: If the first sequence number is greater than the second sequence number, sending a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device; 12. The method for maintaining security entries according to claim 11.

13. the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry; After deleting the at least one remote MAC-IP entry, the security entry maintenance method further comprises: For each deleted remote MAC-IP entry, if there is no remote MAC-IP entry in the third remote MAC-IP table that matches the remote MAC-IP entry, sending a first MAC-IP withdrawal message to another network device other than the fourth network device, the first MAC-IP withdrawal message including the MAC address and the IP address in the remote MAC-IP entry; or, For each deleted remote MAC-IP entry, if there is a remote MAC-IP entry in the third remote MAC-IP table that matches the deleted remote MAC-IP entry, selecting a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, wherein the third remote MAC-IP entry includes a second valid lifetime value and a third sequence number; sending a third MAC-IP notification message including the second valid lifetime value and the third sequence number to another network device other than the fifth network device, wherein the fifth network device is a source device of the third remote MAC-IP entry; 11. The method for maintaining security entries according to claim 10.

14. the MAC-IP notification message sent from the second network device includes a first extended community attribute including a valid lifetime value of the IP address; 11. The method for maintaining security entries according to claim 10.

15. the MAC-IP notification message sent from the second network device further includes a second extended community attribute including a sequence number of the MAC-IP entry; 15. The method for maintaining security entries according to claim 14.

16. A security entry maintenance device, adapted to a first network device, the first network device having a remote MAC-IP table containing at least one remote MAC-IP entry notified from a second network device; The security entry maintenance device comprises: an acquisition module for acquiring a valid lifetime value included in each remote MAC-IP entry when a protocol connection with the second network device is interrupted, the valid lifetime value indicating the valid lifetime of an IP address included in the remote MAC-IP entry; a deletion module for deleting the at least one remote MAC-IP entry when the duration for which the protocol connection is interrupted reaches the valid lifetime value. A security entry maintenance device.

17. an establishment module for, when the first network device creates a DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, the local MAC-IP entry including a first valid lifetime value of a first IP address; a sending module for sending a first MAC-IP notification message to the third network device so that the third network device establishes a first remote MAC-IP entry; the first MAC-IP notification message includes a first sequence number and the first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value; the first sequence number is the sum of the highest sequence number in a remote MAC-IP entry that matches the local MAC-IP entry and 1; 17. The security entry maintenance device of claim 16.

18. The deletion module further deletes the forwarding MAC-IP entry when an access entry matching the local MAC-IP entry is deleted.

18. The security entry maintenance device of claim 17.

19. a receiving module for receiving a second MAC-IP notification message sent from the second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; an establishing module for establishing a second remote MAC-IP entry including the second valid lifetime value and the second sequence number.

17. The security entry maintenance device of claim 16.

20. the first network device comprises a local MAC-IP table containing at least one local MAC-IP entry; The security entry maintenance device further includes a detection module, a generation module, and an issuance module; The receiving module further receives a first packet transmitted from a terminal, the first packet including a MAC address and an IP address of the terminal; the detection module performs access detection for the terminal when there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal and the MAC address and IP address of the terminal match the second remote MAC-IP entry; When the generating module receives an access response sent from the terminal, the generating module generates a composite MAC-IP entry including a MAC address and an IP address of the terminal, a port identifier, and a VLAN identifier; The generating module further generates a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including the MAC address and the IP address of the terminal; the issuing module issues the forwarding MAC-IP entry to a hardware resource; 20. The security entry maintenance device of claim 19.

21. The deletion module further deletes the composite MAC-IP entry and the forwarding MAC-IP entry when the access entry of the terminal is deleted.

21. The security entry maintenance device of claim 20.

22. the first network device comprises a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including a third sequence number; The deletion module further deletes the first local MAC-IP entry and deletes a DHCP relay entry corresponding to the first local MAC-IP entry when the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number.

20. The security entry maintenance device of claim 19.

23. the MAC-IP notification message sent from the first network device includes a first extended community attribute including a valid lifetime value of the IP address; 23. The security entry maintenance device according to any one of claims 16 to 22.

24. the MAC-IP notification message sent from the first network device further includes a second extended community attribute including a sequence number of the MAC-IP entry; 24. The security entry maintenance device of claim 23.

25. A security entry maintenance device, adapted to a second network device, the second network device comprising a first remote MAC-IP table including at least one remote MAC-IP entry notified from a fourth network device; The security entry maintenance device comprises: an acquisition module for acquiring a valid lifetime value included in each remote MAC-IP entry when a protocol connection with the fourth network device is interrupted, the valid lifetime value indicating the valid lifetime of an IP address included in the remote MAC-IP entry; a deletion module for deleting the at least one remote MAC-IP entry when the duration for which the protocol connection is interrupted reaches the valid lifetime value. A security entry maintenance device.

26. a receiving module for receiving a first MAC-IP notification message sent from the fourth network device, the first MAC-IP notification message including a first valid lifetime value of a first IP address and a first sequence number; an establishing module for establishing a first remote MAC-IP entry including the first valid lifetime value and the first sequence number.

26. The security entry maintenance device of claim 25.

27. the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry matching the first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; The security entry maintenance device comprises: a sending module for sending a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device when the first sequence number is greater than the second sequence number; 27. The security entry maintenance device of claim 26.

28. the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry; The security entry maintenance device further includes a transmission module; The transmitting module: For each deleted remote MAC-IP entry, if there is no remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, sending a first MAC-IP withdrawal message to a network device other than the fourth network device, the first MAC-IP withdrawal message including the MAC address and the IP address in the remote MAC-IP entry; or, For each deleted remote MAC-IP entry, if there is a remote MAC-IP entry matching the remote MAC-IP entry in the third remote MAC-IP table, select a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, the third remote MAC-IP entry including a second valid lifetime value and a third sequence number, and send a third MAC-IP notification message to another network device other than the fifth network device, the third MAC-IP notification message including the second valid lifetime value and the third sequence number, and the fifth network device being the source device of the third remote MAC-IP entry; 26. The security entry maintenance device of claim 25.

29. the MAC-IP notification message sent from the second network device includes a first extended community attribute including a valid lifetime value of the IP address; The security entry maintenance device according to any one of claims 25 to 28.

30. the MAC-IP notification message sent from the second network device further includes a second extended community attribute including a sequence number of the MAC-IP entry; 30. The security entry maintenance apparatus of claim 29.

31. a first network device, the first network device comprising a remote MAC-IP table including at least one remote MAC-IP entry notified by a second network device; the first network device, a processor; A walkie-talkie and a machine-readable storage medium having stored thereon machine-executable instructions executable by said processor; The machine-executable instructions may cause the processor to: When a protocol connection with the second network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating a valid lifetime of an IP address included in the remote MAC-IP entry; deleting the at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value.

1. A first network device comprising:

32. The machine-executable instructions may cause the processor to: When the first network device creates a DHCP relay entry, establishing a local MAC-IP entry based on the DHCP relay entry and issuing a forwarding MAC-IP entry corresponding to the local MAC-IP entry to a hardware resource, wherein the local MAC-IP entry includes a first valid lifetime value of a first IP address; sending, by the transceiver, a first MAC-IP advertisement message to the third network device so that the third network device establishes a first remote MAC-IP entry; the first MAC-IP notification message includes a first sequence number and the first valid lifetime value, and the first remote MAC-IP entry includes the first sequence number and the first valid lifetime value; the first sequence number is the sum of the highest sequence number in a remote MAC-IP entry that matches the local MAC-IP entry and 1; 32. The first network device of claim 31, wherein the first network device is a network device.

33. The machine-executable instructions may cause the processor to: and deleting the forwarding MAC-IP entry when an access entry matching the local MAC-IP entry is deleted.

33. The first network device of claim 32.

34. The machine-executable instructions may cause the processor to: receiving, by the transceiver, a second MAC-IP notification message sent from the second network device, the second MAC-IP notification message including a second valid lifetime value of a second IP address and a second sequence number; establishing a second remote MAC-IP entry including the second valid lifetime value and the second sequence number.

32. The first network device of claim 31, wherein the first network device is a network device.

35. the first network device comprises a local MAC-IP table containing at least one local MAC-IP entry; The machine-executable instructions may cause the processor to: receiving, by a transceiver, a first packet transmitted from a terminal, the first packet including a MAC address and an IP address of the terminal; If there is no local MAC-IP entry in the local MAC-IP table that matches the MAC address and IP address of the terminal, and the MAC address and IP address of the terminal match the second remote MAC-IP entry, performing access detection for the terminal; generating a composite MAC-IP entry including the MAC address and IP address of the terminal, a port identifier, and a VLAN identifier when receiving an access response sent from the terminal; generating a forwarding MAC-IP entry based on the composite MAC-IP entry, the forwarding MAC-IP entry including the MAC address and the IP address of the terminal; and publishing the forwarding MAC-IP entry to a hardware resource.

35. The first network device of claim 34, wherein the first network device is a network device.

36. The machine-executable instructions may cause the processor to: When the access entry of the terminal is deleted, the synthetic MAC-IP entry and the forwarding MAC-IP entry are deleted.

36. The first network device of claim 35,

37. the first network device has a local MAC-IP table, the local MAC-IP table including a first local MAC-IP entry including a third sequence number; The machine-executable instructions may cause the processor to: If the second remote MAC-IP entry matches the first local MAC-IP entry and the second sequence number is greater than the third sequence number, deleting the first local MAC-IP entry and deleting the DHCP relay entry corresponding to the first local MAC-IP entry.

35. The first network device of claim 34, wherein the first network device is a network device.

38. the MAC-IP notification message sent from the first network device includes a first extended community attribute including a valid lifetime value of the IP address; 38. The first network device according to any one of claims 31 to 37, characterized in that:

39. the MAC-IP notification message sent from the first network device further includes a second extended community attribute including a sequence number of the MAC-IP entry; 39. The first network device of claim 38.

40. a second network device, the second network device comprising a first remote MAC-IP table including at least one remote MAC-IP entry notified by the fourth network device; the second network device, a processor; A walkie-talkie and a machine-readable storage medium having stored thereon machine-executable instructions executable by said processor; The machine-executable instructions may cause the processor to: When the protocol connection with the fourth network device is interrupted, obtaining a valid lifetime value included in each remote MAC-IP entry, the valid lifetime value being for indicating the valid lifetime of the IP address included in the remote MAC-IP entry; deleting the at least one remote MAC-IP entry if the duration for which the protocol connection has been suspended reaches the valid lifetime value. A second network device.

41. The machine-executable instructions may cause the processor to: receiving, by the transceiver, a first MAC-IP notification message sent from the fourth network device, the first MAC-IP notification message including a first valid lifetime value of a first IP address and a first sequence number; establishing a first remote MAC-IP entry including the first valid lifetime value and the first sequence number.

41. The second network device of claim 40.

42. the second network device further comprises a second remote MAC-IP table, the second remote MAC-IP table including a second remote MAC-IP entry, the second remote MAC-IP entry matching the first remote MAC-IP entry, the second remote MAC-IP entry including a second sequence number; The machine-executable instructions may cause the processor to: If the first sequence number is greater than the second sequence number, transmitting a second MAC-IP notification message including the first valid lifetime value and the first sequence number to another network device other than the fourth network device; 42. The second network device of claim 41 .

43. the second network device further comprises a third remote MAC-IP table, the third remote MAC-IP table including at least one remote MAC-IP entry; The machine-executable instructions may cause the processor to: For each deleted remote MAC-IP entry, if there is no remote MAC-IP entry in the third remote MAC-IP table that matches the remote MAC-IP entry, sending a first MAC-IP revocation message to another network device other than the fourth network device, the first MAC-IP revocation message including the MAC address and the IP address in the remote MAC-IP entry; or for each deleted remote MAC-IP entry, if there is a remote MAC-IP entry in the third remote MAC-IP table that matches the deleted remote MAC-IP entry, selecting a third remote MAC-IP entry with the highest sequence number from the matching remote MAC-IP entries, the third remote MAC-IP entry including a second valid lifetime value and a third sequence number; sending a third MAC-IP notification message including the second valid lifetime value and the third sequence number to another network device other than the fifth network device, the fifth network device being the source device of the third remote MAC-IP entry; 41. The second network device of claim 40.

44. the MAC-IP notification message sent from the second network device includes a first extended community attribute including a valid lifetime value of the IP address; The second network device according to any one of claims 40 to 43, characterized in that:

45. the MAC-IP notification message sent from the second network device further includes a second extended community attribute including a sequence number of the MAC-IP entry; 45. The second network device of claim 44.

46. 1. A machine-readable storage medium, comprising: storing machine-executable instructions which, when called and executed by a processor, cause the processor to implement the security entry maintenance method of any one of claims 1 to 9 or 10 to 15; A machine-readable storage medium comprising:

47. A computer program comprising: causing a processor to implement the method for maintaining security entries according to any one of claims 1 to 9 or 10 to 15; A computer program characterized by: