Packet transfer method and apparatus, and network system

The packet transfer method in SD-WAN networking enables SLA quality detection and automatic switching by encapsulating packets with inner and outer tunnel encapsulations, addressing the challenge of detecting quality on segmented data transmission paths.

JP7696434B2Active Publication Date: 2025-06-20HUAWEI TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2023539748
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-12-29
Filing Date
2021-11-25
Publication Date
2025-06-20
Estimated Expiration
2041-11-25

AI Technical Summary

Technical Problem

In SD-WAN networking, it is not possible to perform service-level agreement (SLA) quality detection on a segmented data transmission path that includes an overlay tunnel, a backbone network, and another overlay tunnel.

Method used

A packet transfer method that involves encapsulating packets with inner and outer tunnel encapsulations, allowing for end-to-end tunnel establishment between customer premise equipment (CPE) and automatic switching based on SLA quality.

Benefits of technology

Enables SLA quality detection on end-to-end tunnels, facilitating automatic switching and improving network performance and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007696434000001
    Figure 0007696434000001
  • Figure 0007696434000002
    Figure 0007696434000002
  • Figure 0007696434000003
    Figure 0007696434000003
Patent Text Reader

Abstract

The embodiments of the present application disclose a packet forwarding method and apparatus, and a network system, and belong to the field of communication technology. The method includes that, when sending a first packet, a first CPE may perform inner encapsulation and outer encapsulation on the first packet. The inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, and a second destination address in the outer tunnel encapsulation may be an address of a GW. In the present application, it can be known that an end-to-end inner tunnel may be established between the first CPE and the second CPE, and the inner tunnel may pass through a backbone network via a GW and then reach the second CPE based on the outer tunnel being established so that the first CPE and the GW communicate with each other. In this manner, the inner tunnel is an end-to-end tunnel, and SLA quality detection may be performed, whereby an automatic switch between the inner tunnel and another end-to-end tunnel may be implemented based on the SLA quality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and more particularly, to a packet forwarding method and apparatus, and a network system.

Background Art

[0002] This application claims priority to Chinese Patent Application No. 202011598688.X, titled "PACKET FORWARDING METHOD AND APPARATUS, AND NETWORK SYSTEM", filed on December 29, 2020, the entire content of which is incorporated herein by reference.

[0003] As enterprise services are continuously migrating to the cloud, software-defined networking in a wide area network (SD-WAN) is emerging in wide area networks.

[0004] In SD-WAN networking, usually, an operator deploys an SD-WAN gateway (GW) at the edge of the backbone network to establish an overlay tunnel between the edge device (Edge) of the enterprise branch and the SD-WAN gateway, and implement communication between the local area network (LAN) side of the enterprise branch or headquarters and the backbone network. For example, customer premise equipment (CPE) at each of the headquarters and branches of an enterprise establishes an overlay tunnel to the SD-WAN GW. In this way, a segmented data transmission path including the overlay tunnel, the backbone network, and the overlay tunnel is formed between the headquarters and the branch.

[0005] In SD-WAN networking, a company's branch offices and headquarters are connected on a per-segment basis. However, service-level agreement (SLA) quality detection is performed based on overlay tunnels. Thus, it is not possible to perform SLA quality detection on a segmented data transmission path that includes an overlay tunnel, a backbone network, and an overlay tunnel.

Summary of the Invention

[0006] Embodiments of the present application provide a packet transfer method and apparatus, and a network system, for solving the problem that it is not possible to perform SLA quality detection on a segmented data transmission path that includes an overlay tunnel, a backbone network, and an overlay tunnel. The technical solutions are as follows.

[0007] According to a first aspect, a packet transfer method is provided. This method is applied to a network system, the network system includes a first CPE and a second CPE, this method is executed by the first CPE in the network system, and this method Receiving a first packet and obtaining the initial destination address of the first packet, and then encapsulating the first packet, which may specifically include inner tunnel encapsulation and outer tunnel encapsulation. The specific process of inner tunnel encapsulation may be to determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and execute inner tunnel encapsulation on the first packet based on the first source address and the first destination address. The inner tunnel is an end-to-end tunnel between a first CPE and a second CPE. The specific process of outer tunnel encapsulation may be to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and execute outer tunnel encapsulation on the first packet on which inner tunnel encapsulation has been executed based on the second source address and the second destination address, and finally, including the step of forwarding the first packet on which outer tunnel encapsulation has been executed.

[0008] The inner tunnel is an end-to-end tunnel on which SLA quality detection can be performed, whereby automatic switching can be implemented between the inner tunnel and another end-to-end tunnel based on the SLA quality.

[0009] In a specific embodiment, before the first CPE performs packet transfer, the first CPE may first be configured. The specific configuration process may be as follows. Receiving the second destination address sent by the RR and establishing an outer tunnel based on the second source address and the second destination address, wherein the routing domain of the port corresponding to the second destination address is the same as the routing domain of the port corresponding to the second source address. OuterBased on the completion of the establishment of the tunnel, receiving the first destination address sent by the RR and establishing an inner tunnel based on the first source address and the first destination address, wherein the routing domain of the port corresponding to the first destination address is the same as the routing domain of the port corresponding to the first source address, and generating routing information of the inner tunnel at the first CPE, wherein the routing information includes the correspondence between the first destination address and the second source address and the second destination address.

[0010] In certain embodiments, the configuration of the first CPE may further include the following processing. Receiving an overlay VRF configuration message sent by the controller and establishing a first overlay VRF and a second overlay VRF at the first CPE, receiving an underlay VRF configuration message sent by the controller and establishing a first underlay VRF at the first CPE, and receiving a port association message sent by the controller, associating the second overlay VRF with the port corresponding to the first source address, and associating the first underlay VRF with the second source address To the corresponding port Steps of association.

[0011] In connection with the foregoing specific embodiments, after a first packet is received, a first overlay VRF in a first CPE may determine a first source address and a first destination address of an inner tunnel corresponding to an initial destination address, and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address. Next, the first overlay VRF transmits the first packet on which the inner tunnel encapsulation is performed to a second overlay VRF in the first CPE and corresponding to the first source address. Next, the second overlay VRF determines a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address. Next, the second overlay VRF transmits the first packet on which the outer tunnel encapsulation is performed to a first underlay VRF corresponding to the second source address. Finally, the first underlay VRF forwards the first packet on which the outer tunnel encapsulation is performed.

[0012] In another specific embodiment, the configuration of the first CPE may further include the following processing. Receiving an overlay VRF configuration message sent by a controller to establish a first overlay VRF and a second overlay VRF in the first CPE, receiving an underlay VRF configuration message sent by the controller to establish a first underlay VRF and a second underlay VRF in the first CPE, and receiving a port association message sent by the controller, associating the second underlay VRF with a port corresponding to the first source address, and associating the first underlay VRF with the second source address Corresponding port step.

[0013] In connection with the foregoing specific embodiments, after the first packet is received, the first overlay VRF determines the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and may perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address. Next, the first overlay VRF transmits the first packet on which the inner tunnel encapsulation is performed to the second underlay VRF corresponding to the first source address. Next, the second underlay VRF transmits the first packet on which the inner tunnel encapsulation is performed to the second overlay VRF that is at the first CPE and is connected to the second underlay VRF. Next, the second overlay VRF determines the second source address and the second destination address of the outer tunnel corresponding to the first destination address, performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address, and the second overlay VRF transmits the first packet on which the outer tunnel encapsulation is performed to the first underlay VRF corresponding to the second source address. Finally, the first underlay VRF forwards the first packet on which the outer tunnel encapsulation is performed.

[0014] In certain embodiments, the connection mode between the second underlay VRF and the second overlay VRF may be an outer loop connection.

[0015] In certain embodiments, the outer loop connection may be to connect the physical ports associated with the second overlay VRF and the second underlay VRF by using the physical line outside the first CPE.

[0016] In certain embodiments, the connection mode between the second underlay VRF and the second overlay VRF may be an inner loop connection.

[0017] In certain embodiments, the inner loop connection can be to establish a communication connection between loopback ports associated with a second underlay VRF and a second overlay VRF.

[0018] In connection with the foregoing specific embodiments, the connection between the loopback ports can be established through the following process. Receiving a connection establishment message sent by a controller, the connection establishment message carrying an identifier of a second underlay VRF and an identifier of a second overlay VRF, and establishing a connection between a loopback port corresponding to the second underlay VRF and a loopback port corresponding to the second overlay VRF.

[0019] In another specific embodiment, the configuration of the first CPE can further include the following process. Receiving an overlay VRF configuration message sent by a controller to establish a first overlay VRF in the first CPE, receiving an underlay VRF configuration message sent by a controller to establish a first underlay VRF in the first CPE, and receiving a port association message sent by a controller to associate the first underlay VRF with a port corresponding to a first source address and a second source address.

[0020] In connection with the foregoing specific embodiments, after a first packet is received, a first overlay VRF determines a first source address and a first destination address of an inner tunnel corresponding to an initial destination address, and may perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address. Next, the first overlay VRF transmits the first packet on which the inner tunnel encapsulation is performed to a first underlay VRF corresponding to the first source address. Next, the first underlay VRF determines a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address. Finally, the first underlay VRF forwards the first packet on which the outer tunnel encapsulation is performed.

[0021] In a specific embodiment, the inner tunnel is an end-to-end tunnel between a first CPE and a second CPE. When there are multiple end-to-end tunnels between the first CPE and the second CPE, when the first CPE transmits a packet to the second CPE, the first CPE may perform path selection based on the SLA quality of these tunnels. The specific processing may be as follows. Determining an inner tunnel having the highest tunnel service quality among a plurality of inner tunnels corresponding to the initial destination address, and determining a first source address and a first destination address of the inner tunnel having the highest tunnel service quality. Further, in addition to the inner tunnel, there may be another type of tunnel, such as an Internet tunnel.

[0022] According to a second aspect, a packet transfer method is provided. This method is applied to a network system, and the network system includes First a CPE, a GW, and a second CPE. This method is executed by the GW, and this method includes Receiving a first packet transmitted by a first CPE, the first packet including inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel being an end-to-end tunnel between the first CPE and a second CPE; removing the outer tunnel encapsulation of the first packet; and forwarding the first packet with the outer tunnel encapsulation removed based on a first destination address in the inner tunnel encapsulation of the first packet, the first destination address being associated with the second CPE.

[0023] In a particular embodiment, if an outer tunnel is established between the GW and the second CPE, after removing the outer encapsulation from the first packet, the GW may further need to perform further outer encapsulation. The specific processing may be as follows. Determining a third source address and a third destination address of an outer tunnel corresponding to the first destination address in the inner tunnel encapsulation of the first packet, and performing further outer tunnel encapsulation on the first packet with the outer tunnel encapsulation removed based on the third source address and the third destination address, and forwarding the first packet with the further outer tunnel encapsulation performed.

[0024] In a particular embodiment, if the GW has established an outer tunnel to the second CPE, the processing may be as follows. Receiving a third destination address associated with the second CPE transmitted by the RR, and establishing an outer tunnel based on the third destination address and a third source address, the routing domain of the port corresponding to the third source address being the same as the routing domain of the port corresponding to the third destination address, and Establishing a correspondence between the first destination address and the third source address and the third destination address of the outer tunnel.

[0025] According to a third aspect, a packet transfer method is provided. This method is applied to a network system, the network system includes a first CPE, a GW, and a second CPE, this method is executed by the second CPE, and this method Receiving a first packet, where the first packet is from the first CPE, the first packet includes inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; removing the outer tunnel encapsulation of the first packet; and removing the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transferring the first packet with the inner tunnel encapsulation removed.

[0026] In a specific embodiment, the second CPE may process the first packet by using a VRF configured in the second CPE. Specifically, the processing may be as follows.

[0027] The first underlay VRF in the second CPE receives the first packet, removes the outer tunnel encapsulation of the first packet, and then transmits the first packet with the outer tunnel encapsulation removed to the first overlay VRF in the second CPE. Then, the first overlay VRF removes the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transfers the first packet with the inner tunnel encapsulation removed.

[0028] In another specific embodiment, the processing performed on the first packet by using a VRF may include the following processing.

[0029] The first underlay VRF in the second CPE receives the first packet and transmits the first packet to the second overlay VRF in the second CPE. Next, the second overlay VRF removes the outer tunnel encapsulation of the first packet, and the second overlay VRF transmits the first packet with the outer tunnel encapsulation removed to the first overlay VRF in the second CPE. Finally, the first overlay VRF removes the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and forwards the first packet with the inner tunnel encapsulation removed.

[0030] In connection with the foregoing specific embodiments, the second overlay VRF transmitting the first packet with the outer tunnel encapsulation removed to the first overlay VRF may further specifically include the following processing.

[0031] The second overlay VRF removes the outer tunnel encapsulation of the first packet and transmits the first packet with the outer tunnel encapsulation removed to the second underlay VRF connected to the second overlay VRF. Finally, the second underlay VRF transmits the first packet with the outer tunnel encapsulation removed to the first overlay VRF.

[0032] In a specific embodiment, the second underlay VRF is connected to the second overlay VRF by using an outer loop.

[0033] In a specific embodiment, the second underlay VRF is connected to the second overlay VRF through a corresponding physical port.

[0034] In a specific embodiment, the second underlay VRF is connected to the second overlay VRF by using an inner loop.

[0035] In certain embodiments, the second underlay VRF is connected to the second overlay VRF through a corresponding loopback port.

[0036] According to a fourth aspect, a CPE configuration method is provided. This method is applied to a network system, which includes a first customer premise equipment ( CPE ) , a gateway ( GW ) , a second CPE, and a route reflector ( RR ) . This method is executed by a first CPE , and this method includes steps of receiving a second destination address associated with the GW sent by the RR and establishing an outer tunnel based on the second source address and the second destination address; receiving a first destination address associated with the second CPE sent by the RR and establishing an inner tunnel based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; and generating routing information of the inner tunnel at the first CPE, where the routing information includes a correspondence between the first destination address and the second source address and the second destination address.

[0037] In certain embodiments, after the foregoing configuration, the first CPE may forward a first packet. The specific processing may be as follows. Receiving a first packet and obtaining an initial destination address of the first packet; determining a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between a first CPE and a second CPE; determining a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performing outer tunnel encapsulation on the first packet on which inner tunnel encapsulation has been performed based on the second source address and the second destination address; and forwarding the first packet on which outer tunnel encapsulation has been performed.

[0038] In certain embodiments, the VRF may further be configured at the first CPE to process the first packet. The specific configuration may be as follows. Receiving an overlay VRF configuration message sent by a controller and establishing a first overlay VRF and a second overlay VRF at the first CPE; receiving an underlay VRF configuration message sent by the controller and establishing a first underlay VRF at the first CPE; and receiving a port association message sent by the controller, associating the second overlay VRF with a port corresponding to the first source address, and associating the first underlay VRF with the second source address To the corresponding port Steps.

[0039] In certain embodiments, after the foregoing configuration, the first CPE may forward the first packet. The specific processing may be as follows.

[0040] After the first packet is received and the initial destination address of the first packet is obtained, the first overlay VRF determines the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and performs inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, and transmits the first packet on which the inner tunnel encapsulation is performed to the second overlay VRF corresponding to the first source address. Next, the second overlay VRF determines the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address, and transmits the first packet on which the outer tunnel encapsulation is performed to the first underlay VRF corresponding to the second source address. Finally, the first underlay VRF forwards the first packet on which the outer tunnel encapsulation is performed.

[0041] In another specific embodiment, the VRF in the first CPE may alternatively be processed in the following manner. Receiving an overlay VRF configuration message sent by a controller to establish a first overlay VRF and a second overlay VRF in the first CPE, receiving an underlay VRF configuration message sent by the controller to establish a first underlay VRF and a second underlay VRF in the first CPE, and receiving a port association message sent by the controller, associating the second underlay VRF with the port corresponding to the first source address, and associating the first underlay VRF with the port corresponding to the second source address.

[0042] In a specific embodiment, after the aforementioned configuration, the first CPE may transfer the first packet. The specific processing may be as follows.

[0043] After the first packet is received and the initial destination address of the first packet is obtained, the first overlay VRF determines the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and performs inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, and transmits the first packet on which the inner tunnel encapsulation is performed to the second underlay VRF corresponding to the first source address. Next, the second underlay VRF transmits the first packet on which the inner tunnel encapsulation is performed to the second overlay VRF that is at the first CPE and is connected to the second underlay VRF. Next, the second overlay VRF determines the second source address and the second destination address of the outer tunnel corresponding to the first destination address, performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address, and transmits the first packet on which the outer tunnel encapsulation is performed to the first underlay VRF corresponding to the second source address. Finally, the first underlay VRF transfers the first packet on which the outer tunnel encapsulation is performed.

[0044] In another specific embodiment, the VRF in the first CPE may alternatively be processed in the following manner. Receiving an overlay VRF configuration message sent by a controller and establishing a first overlay VRF at a first CPE; receiving an underlay VRF configuration message sent by the controller and establishing a first underlay VRF at the first CPE; and receiving a port association message sent by the controller and associating the first overlay VRF with ports corresponding to a first source address and a second source address.

[0045] In a particular embodiment, after the foregoing configuration, the first CPE may forward a first packet. The specific processing may be as follows.

[0046] After the first packet is received and the initial destination address of the first packet is obtained, the first overlay VRF determines a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performs inner tunnel encapsulation on the first packet based on the first source address and the first destination address, and sends the first packet on which the inner tunnel encapsulation has been performed to a first underlay VRF corresponding to the first source address. Next, the first underlay VRF determines a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation has been performed based on the second source address and the second destination address, and forwards the first packet on which the outer tunnel encapsulation has been performed.

[0047] According to a fifth aspect, a CPE configuration method is provided. This method is applied to an RR, and this method receiving a second destination address associated with a GW sent by the GW and sending the second destination address to a first CPE; Receiving, by a second CPE, a first destination address associated with the second CPE that was transmitted by the second CPE, and transmitting the first destination address to the 1 th CPE.

[0048] According to a sixth aspect, a CPE configuration method is provided. This method is applied to a controller, and this method includes transmitting an overlay VRF configuration message to a first CPE, transmitting an underlay VRF configuration message to the first CPE, and transmitting a port association message to the first CPE.

[0049] In certain embodiments, the overlay VRF configuration message carries a VRF identifier of a first overlay VRF and a VRF identifier of a second overlay VRF, the underlay VRF configuration message carries a VRF identifier of a first underlay VRF, and the port association message carries a correspondence between the VRF identifier of the second overlay VRF and a first source address and a correspondence between the VRF identifier of the first underlay VRF and a second source address.

[0050] In certain embodiments, the overlay VRF configuration message carries a VRF identifier of a first overlay VRF and a VRF identifier of a second overlay VRF, the underlay VRF configuration message carries a VRF identifier of a first underlay VRF and a VRF identifier of a second underlay VRF, and the port association message carries a correspondence between the VRF identifier of the second underlay VRF and a first source address and a correspondence between the VRF identifier of the first underlay VRF and a second source address.

[0051] In certain embodiments, an overlay VRF configuration message carries the VRF identifier of a first overlay VRF, an underlay VRF configuration message carries the VRF identifier of a first underlay VRF, and a port association message carries the correspondence between the VRF identifier of the first overlay VRF and a first source address and a second source address.

[0052] According to a seventh aspect, there is provided a packet transfer device configured to execute any possible embodiment of the first aspect or the fourth aspect. Specifically, the device includes a module configured to execute any possible embodiment of the first aspect or the fourth aspect.

[0053] According to an eighth aspect, there is provided a packet transfer device configured to execute any possible embodiment of the second aspect. Specifically, the device includes a module configured to execute any possible embodiment of the second aspect.

[0054] According to a ninth aspect, there is provided a packet transfer device configured to execute any possible embodiment of the third aspect. Specifically, the device includes a module configured to execute any possible embodiment of the third aspect.

[0055] According to a tenth aspect, a first CPE is provided. The first CPE includes a processor and a memory, the memory is configured to store instructions, and the processor is configured to execute the instructions to implement the method according to the first aspect or the fourth aspect.

[0056] According to an eleventh aspect, a GW is provided. The GW includes a processor and a memory, the memory is configured to store instructions, and the processor is configured to execute the instructions to implement the method according to the second aspect.

[0057] According to the 12th aspect, a second CPE is provided. This second CPE includes a processor and a memory. The memory is configured to store instructions, and the processor is configured to execute those instructions to implement the method according to the 3rd aspect.

[0058] According to the 13th aspect, an RR is provided. This RR includes a processor and a memory. The memory is configured to store instructions, and the processor is configured to execute those instructions to implement the method according to the 5th aspect.

[0059] According to the 14th aspect, a controller is provided. This controller includes a processor and a memory. The memory is configured to store instructions, and the processor is configured to execute those instructions to implement the method according to the 6th aspect.

[0060] According to the 15th aspect, a network system is provided. This network system includes a first CPE according to the 10th aspect, a GW according to the 11th aspect, and a second CPE according to the 12th aspect.

[0061] The beneficial effects brought about by the technical solutions provided in the embodiments of this application are as follows.

[0062] In an embodiment of the present application, when transmitting a first packet, the first CPE may perform inner encapsulation and outer encapsulation on the first packet. The inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, and the second destination address in the outer tunnel encapsulation may be the address of the GW. In the present application, an end-to-end inner tunnel may be established between the first CPE and the second CPE, and based on the fact that the outer tunnel is established so that the first CPE and the GW communicate with each other, it is known that the inner tunnel can pass through the backbone network via the GW and then reach the second CPE. In this way, the inner tunnel is an end-to-end tunnel on which SLA quality detection can be performed, whereby automatic switching can be performed between the inner tunnel and another end-to-end tunnel based on the SLA quality.

Brief Description of the Drawings

[0063]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Figure 27

Figure 28

Embodiments for Carrying Out the Invention

[0064] Embodiments of the present application provide a packet transfer method. This method can be applied to SD-WAN networking. FIG. 1 shows an SD-WAN networking deployment mode. FIG. 1 includes the headquarters and branches of the same company. The headquarters uses CP to access the operator's backbone network to establish a connection to the GW in the SD-WAN networking. The branch also uses a CPE to access the operator's backbone network to establish a connection to the GW. A plurality of tunnels, for example, Internet tunnels, can also be established between the headquarters and the branch by using their respective CPEs. According to an embodiment of the present application, an end-to-end tunnel between two CPEs can be established by using the GW and the backbone network, and packets can be transmitted through that tunnel. E Establish a connection to the GW in the SD-WAN networking by using it. The branch also uses a CPE to access the operator's backbone network to establish a connection to the GW. A plurality of tunnels, for example, Internet tunnels, can also be established between the headquarters and the branch by using their respective CPEs. According to an embodiment of the present application, an end-to-end tunnel between two CPEs can be established by using the GW and the backbone network, and packets can be transmitted through that tunnel.

[0065] In addition, in addition to the deployment mode shown in FIG. 1, two CPEs can be connected to the same GW, or one CPE can be connected to the GW, and the other CPE can directly access the backbone network without being connected to the GW, or one CPE can be connected to multiple GWs. Certainly, the aforementioned example is an SD-WAN networking including the CPE of the headquarters and the CPE of only one branch. In actual applications, there can be CPEs of multiple branches, and each CPE can be individually connected to one GW, or multiple branches can be connected to the same GW, or some CPEs can be directly connected to the backbone network without being connected to the GW, or the same CPE can be connected to multiple GWs.

[0066] Hereinafter, the processing procedures implemented by the first CPE (on the packet transmission side), the GW, and the second CPE (on the packet reception side) of the present application will be described.

[0067] Hereinafter, the CPEs in FIGS. 2 and 3 will be used as the first CPE on the transmission side, and the processing procedures for packet transfer by the first CPE will be described. Refer to FIG. 4. The processing procedures for packet transfer by the first CPE may include the following steps.

[0068] S101. Receive the first packet and obtain the initial destination address of the first packet.

[0069] In an embodiment, a terminal device on the local area network (LAN) side corresponding to the first CPE may transmit a packet to a terminal device on the LAN side of another CPE. For example, the first terminal device on the LAN side corresponding to the first CPE may transmit a packet to the second terminal device on the LAN side corresponding to the second CPE.

[0070] The terminal device on the LAN side corresponding to the first CPE may generate the first packet and transmit the first packet to the LAN port to which the first CPE is connected. The first packet carries the initial destination address, and the initial destination address is the IP address of a terminal device that is located on the LAN side of another CPE and is configured to receive the first packet.

[0071] The first overlay VRF in the first CPE associated with the LAN port may receive and obtain the first packet, and obtain the initial destination address carried in the first packet.

[0072] S102. By using the first overlay VRF in the first CPE, determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address.

[0073] The first overlay VRF is the VRF associated with each LAN port on the LAN side of the first CPE.

[0074] In an embodiment, the first overlay VRF may determine that the CPE corresponding to the initial destination address is the second CPE based on the stored correspondence between the set destination address and the CPE. Then, at least one end-to-end tunnel between the first CPE and the second CPE may be determined based on the stored correspondence between the CPE and the end-to-end tunnel.

[0075] In addition, the quality of service of each tunnel may be further recorded at the first CPE. The quality of service may be obtained by the first CPE through measurements based on a preset periodicity.

[0076] The first overlay VRF may select, from a plurality of end-to-end tunnels corresponding to the second CPE, the tunnel with the best quality of service as the tunnel to be used for transmitting the first packet this time.

[0077] Next, the first overlay VRF may determine, from the source address and destination address stored in the tunnel, the first source address and the first destination address of the tunnel to be used for transmitting the first packet this time. In the present application, only the selected tunnel which is the inner tunnel is described. As shown in FIG. 2, the first source address of the inner tunnel is the IP address of the first wide area network (WAN) port in the first CPE, and the first destination address is the IP address of the first WAN port in the second CPE. Alternatively, as shown in FIG. 3, the first source address is the IP address of the first loopback port in the first CPE, and the first destination address is the IP address of the first loopback port in the second CPE.

[0078] Next, the first overlay VRF determines the tunneling protocol of the selected tunnel and performs inner tunnel encapsulation on the first packet based on the tunneling protocol. The first packet on which the inner tunnel encapsulation is performed carries the first source address and the first destination address of the tunnel. The tunneling protocol may be a generic routing encapsulation (GRE) protocol, an Internet protocol security (IPsec) protocol, or the like.

[0079] In addition, the first packet on which the inner tunnel encapsulation is performed may further carry the VRF identifier of the first overlay VRF that performs the inner tunnel encapsulation.

[0080] At the first CPE, by using a second underlying VRF corresponding to the first source address, a first packet in which inner tunnel encapsulation is performed is transmitted from the first CPE to a second overlay VRF connected to the second underlying VRF.

[0081] In an embodiment, the first overlay VRF transmits a first packet in which inner tunnel encapsulation is performed to an underlying VRF associated with a port corresponding to the first source address, for example, the second underlying VRF shown in FIGS. 2 and 3. Next, the second underlying VRF transmits the first packet in which inner tunnel encapsulation is performed to a connected overlay VRF, for example, the second overlay VRF shown in FIGS. 2 and 3, through a port corresponding to the first source address.

[0082] Here, it should be noted that in the first CPE shown in FIG. 2 and the first CPE shown in FIG. 3, the second underlying VRF and the second overlay VRF are connected in different manners. Specifically, in FIG. 2, a first WAN port associated with the second underlying VRF and a first LAN port associated with the second overlay VRF are connected by using a physical line. In FIG. 3, an inner loop tunnel is established between a first loopback port associated with the second underlying VRF and a second loopback port associated with the second overlay VRF to implement the connection. The tunneling protocol based on which the inner loop tunnel is established can be a GRE protocol or the like.

[0083] By using the second overlay VRF in the first CPE, determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation is being performed based on the second source address and the second destination address.

[0084] In an embodiment, after receiving the first packet on which inner tunnel encapsulation is being performed, the second overlay VRF obtains the first destination address carried in the first packet, queries the routing information, and determines the egress port corresponding to the first destination address, for example, the second WAN port shown in FIG. 2. Next, the second source address and the second destination address of the outer tunnel corresponding to the second WAN port, and the tunneling protocol of that outer tunnel can be obtained, and based on that tunneling protocol, outer tunnel encapsulation is performed on the first packet on which inner tunnel encapsulation is being performed. The first packet on which outer tunnel encapsulation is being performed carries the second source address and the second destination address of the outer tunnel. The second source address is the IP address of the second WAN port in the first CPE, and the second destination address is the IP address of the corresponding WAN port in the GW at the tunnel destination end. The tunneling protocol of the outer tunnel can be the GRE over IPsec protocol.

[0085] In addition, the first packet on which outer tunnel encapsulation is being performed may further carry the VRF identifier of the second overlay VRF that performs the outer tunnel encapsulation.

[0086] S105. At the first CPE, by using the first underlay VRF corresponding to the second source address, transfer the first packet on which outer tunnel encapsulation is being performed.

[0087] In an embodiment, the second overlay VRF sends a first packet with outer encapsulation being performed to a second source address Corresponding to an underlay VRF, for example, the first underlay VRF shown in FIG. 2. Then, the first underlay VRF transfers the first packet with outer tunnel encapsulation being performed to the GW through a second WAN port.

[0088] Hereinafter, using the CPE in FIG. 5 as the first CPE on the sending side, the packet transfer processing procedure by the first CPE will be described. Refer to FIG. 6. The packet transfer processing procedure by the first CPE may include the following steps.

[0089] S201. Receive a first packet and obtain the initial destination address of the first packet.

[0090] S202. By using the first overlay VRF in the first CPE, determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address, and the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE.

[0091] As shown in FIG. 5, the first source address is the IP address of the loopback port in the first CPE. If the second CPE is deployed in the same manner as the CPE shown in FIG. 5, the first destination address is the IP address of the loopback port in the second CPE.

[0092] S203. By using the first overlay VRF, send the first packet with inner tunnel encapsulation being performed to a second overlay VRF corresponding to the first source address.

[0093] In an embodiment, as shown in FIG. 5, the first overlay VRF sends a first packet with inner tunnel encapsulation to a loopback port corresponding to the first source address. A second overlay VRF associated with that loopback port obtains the first packet with inner tunnel encapsulation through that loopback port.

[0094] S204. By using the second overlay VRF in the first CPE, determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and perform outer tunnel encapsulation on the first packet with inner tunnel encapsulation based on the second source address and the second destination address.

[0095] In an embodiment, after receiving the first packet with inner tunnel encapsulation, the second overlay VRF obtains the first destination address carried in the first packet, queries the routing information, and determines an exit port corresponding to the first destination address, for example, the WAN port shown in FIG. 5. Then, the second source address and the second destination address of the outer tunnel corresponding to that WAN port, and the tunneling protocol of that outer tunnel can be obtained, and based on that tunneling protocol, outer tunnel encapsulation is performed on the first packet with inner tunnel encapsulation. The first packet with outer tunnel encapsulation carries the second source address and the second destination address of the outer tunnel. The second source address is the IP address of the WAN port in the first CPE, and the second destination address is the IP address of the corresponding WAN port in the GW at the tunnel destination end.

[0096] In the first CPE, by using the first underlay VRF corresponding to the second source address, transfer the first packet for which outer tunnel encapsulation has been performed.

[0097] Note that in this specification, the specific embodiments of S201, S202, and S205 are the same as or similar to the specific embodiments of S101, S102, and S105 shown in FIG. 4, respectively. Details will not be described again in this specification.

[0098] Hereinafter, using the CPE in FIG. 7 as the first CPE on the transmission side, the processing procedure for packet transfer by the first CPE will be described. Refer to FIG. 8. The processing procedure for packet transfer by the first CPE may include the following steps.

[0099] S301. Receive the first packet and obtain the initial destination address of the first packet.

[0100] S302. By using the first overlay VRF in the first CPE, determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address.

[0101] As shown in FIG. 7, the first source address is the IP address of the loopback port in the first CPE. When the second CPE is deployed in the same manner as the CPE shown in FIG. 7, the first destination address is the IP address of the loopback port in the second CPE.

[0102] In S303, at the first CPE, by using the first underlay VRF corresponding to the first source address, determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and based on the second source address and the second destination address, perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation has been performed, and transfer the first packet on which outer tunnel encapsulation has been performed.

[0103] As shown in FIG. 7, the second source address is the IP address of the WAN port of the first CPE, and correspondingly, the second destination address is the IP address of the WAN port of the GW in FIG. 7.

[0104] In an embodiment, the first overlay VRF sends the first packet on which inner tunnel encapsulation has been performed to the underlay VRF associated with the port corresponding to the first source address, for example, the first underlay VRF shown in FIG. 7.

[0105] After receiving the first packet on which inner tunnel encapsulation has been performed, the first underlay VRF obtains the first destination address carried in the first packet, queries the routing information, and determines the egress port corresponding to the first destination address, for example, the WAN port shown in FIG. 7.

[0106] Next, the first underlay VRF obtains the second source address and the second destination address of the outer tunnel corresponding to its WAN port, and the tunneling protocol of the outer tunnel, and based on the tunneling protocol, can perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation is being performed. The first packet on which outer tunnel encapsulation is being performed carries the second source address and the second destination address of the outer tunnel. The second source address is the IP address of the WAN port in the first CPE, and the second destination address is the IP address of the corresponding WAN port in the GW at the tunnel destination end.

[0107] Finally, the first underlay VRF forwards the first packet on which outer tunnel encapsulation is being performed to the GW through the WAN port.

[0108] Note that in this specification, the specific embodiments of S301 and S302 are the same as or similar to the specific embodiments of S101 and S102 shown in FIG. 4, respectively. Details will not be described again in this specification.

[0109] Hereinafter, the processing procedure of packet forwarding by the GW in the SD-WAN networking scenario shown in FIG. 9 will be described. Please refer to FIG. 10. The processing procedure of packet forwarding by the GW may include the following steps.

[0110] S401. Receive a first packet, where the first packet includes inner tunnel encapsulation and outer tunnel encapsulation.

[0111] In an embodiment, the GW may receive the first packet sent by the first CPE on which inner tunnel encapsulation and outer tunnel encapsulation are being performed.

[0112] S402. Remove the outer tunnel encapsulation of the first packet.

[0113] In an embodiment, the GW may remove the outer tunnel encapsulation from a first packet in which inner tunnel encapsulation and outer tunnel encapsulation are being performed, based on the protocol of the outer tunnel. The protocol of the outer tunnel may be the GRE over IPsec protocol.

[0114] S403. Determine the third source address and the third destination address of the outer tunnel corresponding to the first destination address in the inner tunnel encapsulation of the first packet, and perform further outer tunnel encapsulation on the first packet from which the outer tunnel encapsulation has been removed, based on the third source address and the third destination address.

[0115] In an embodiment, the GW obtains the first destination address carried in the first packet from which the outer tunnel encapsulation has been removed, and determines the egress port used to forward the packet by querying the routing information. In addition, the third source address and the third destination address of the outer tunnel corresponding to that egress port are further obtained through the query. The third source address of the outer tunnel is, at the GW, the IP address of the egress port used to forward the first packet, and the third destination address is the IP address of the WAN port of the destination end (the second CPE) of the outer tunnel.

[0116] Next, based on the outer tunnel protocol, the VRF at the GW may perform further outer tunnel encapsulation on the first packet from which the outer tunnel encapsulation has been removed. The first packet on which further outer tunnel encapsulation is performed carries the third source address and the third destination address of the outer tunnel. In addition, when further outer tunnel encapsulation is performed, in addition to the third source address and the third destination address of the outer tunnel, the VRF identifier of the VRF that performs the further outer tunnel encapsulation is further encapsulated.

[0117] S404. Forward the first packet on which further outer tunnel encapsulation is performed.

[0118] In an embodiment, the GW forwards the first packet on which further outer tunnel encapsulation is performed to the second CPE through the egress port.

[0119] Hereinafter, the packet forwarding processing procedure by the first GW in the SD-WAN networking scenario shown in FIG. 11 will be described. Refer to FIG. 12. The packet forwarding processing procedure by the first GW may include the following steps.

[0120] S501. Receive the first packet, where the first packet includes inner tunnel encapsulation and outer tunnel encapsulation.

[0121] The first source address in the inner tunnel encapsulation is the IP address of the port in the first CPE. For example, if the first CPE is the CPE shown in FIGS. 2, 3, 5, or 7, the first source address is the IP address of the first WAN port in FIG. 2, or the IP address of the first loopback port in FIG. 3, or the IP address of the loopback port in FIGS. 5 or 7. The first destination address is the IP address of the port in the second CPE. For example, if the second CPE is the CPE shown in FIGS. 2, 3, 5, or 7, the first destination address is the IP address of the first WAN port in FIG. 2, or the IP address of the first loopback port in FIG. 3, or the IP address of the loopback port in FIGS. 5 or 7. The second source address in the outer tunnel encapsulation is the IP address of the port in the first CPE, for example, the IP address of the second WAN port in FIGS. 2 or 3, or the WAN port address in FIGS. 5 or 7 The IP of is. The second destination address is the IP address of the port in the first GW, for example, the IP address of the WAN port in the first GW.

[0122] S502. Remove the outer tunnel encapsulation of the first packet.

[0123] S503. Based on the first destination address in the inner tunnel encapsulation of the first packet, transfer the first packet from which the outer tunnel encapsulation has been removed.

[0124] In an embodiment, the GW determines the next-hop address corresponding to the first destination address by querying the routing information, and based on that next-hop address, transfers the first packet from which the outer tunnel encapsulation has been removed.

[0125] Note that here, specific embodiments of S501 and S502 are the same as or similar to the specific embodiments of S401 and S402 shown in FIG. 10, respectively. Details are not described again in this specification.

[0126] Hereinafter, the processing procedure of packet transfer by the second GW in the SD-WAN networking scenario shown in FIG. 11 will be described. Refer to FIG. 13. The processing procedure of packet transfer by the second GW may include the following steps.

[0127] S504. Receive a first packet with the outer tunnel encapsulation removed.

[0128] In an embodiment, the second GW receives a first packet with the outer tunnel encapsulation removed, which is sent by the first GW and transferred through the backbone network.

[0129] S505. Determine the third source address and the third destination address of the outer tunnel corresponding to the first destination address in the inner tunnel encapsulation of the first packet, and perform further outer tunnel encapsulation on the first packet with the outer tunnel encapsulation removed based on the third source address and the third destination address.

[0130] As shown in FIG. 11, the third source address is the IP address of the port at the source end (the second GW) of the outer tunnel between the second GW and the second CPE, and the third destination address is the IP address of the port at the destination end (the second CPE) of the outer tunnel. Both the port of the second GW and the port of the second CPE can be WAN ports.

[0131] S506. Transfer the first packet with further outer tunnel encapsulation performed.

[0132] Note that in this specification, certain embodiments of S505 and S506 are the same as or similar to the specific embodiments of S403 and S404 shown in FIG. 10, respectively. Details will not be described again in this specification.

[0133] The processing procedure for packet forwarding by the GW in the SD-WAN networking scenario shown in FIG. 14 is the same as the procedure for packet forwarding by the first GW shown in FIG. 11. Details will not be described again in this specification.

[0134] Hereinafter, the CPE shown in FIG. 2 or FIG. 3 will be used as the second CPE on the receiving side, and the processing procedure for packet forwarding by the second CPE will be described. Refer to FIG. 15. The processing procedure for packet forwarding by the second CPE may include the following steps.

[0135] S601. By using the first underlay VRF in the second CPE, receive the first packet transmitted by the GW and transmit the first packet to the second overlay VRF in the second CPE. The first packet includes inner tunnel encapsulation and outer tunnel encapsulation.

[0136] In an embodiment, in the second CPE, the second WAN port corresponding to the third destination address receives the first packet for which further outer encapsulation is being performed.

[0137] In this specification, when performing inner encapsulation on the first packet, the first overlay VRF in the first CPE encapsulates the VRF identifier of the first overlay VRF into the first packet, and it should be noted that the VRF identifier of the first overlay VRF in the first CPE is the same as the VRF identifier of the first overlay VRF in the second CPE. Similarly, when performing further outer tunnel encapsulation on the first packet from which the outer tunnel encapsulation has been removed, the GW encapsulates the VRF identifier of the VRF that performs the further outer tunnel encapsulation in that GW into the first packet, and the VRF identifier in the GW is the same as the VRF identifier of the second overlay VRF in the second CPE and is also the same as the VRF identifier of the second overlay VRF in the first CPE.

[0138] When it is determined that the VRF identifier in the outer tunnel encapsulation of the first packet is the identifier of the second overlay VRF, the first underlay VRF associated with the second WAN port sends the first packet on which further outer tunnel encapsulation is being performed to the second overlay VRF.

[0139] S602. Remove the outer tunnel encapsulation of the first packet by using the second overlay VRF, and send the first packet from which the outer tunnel encapsulation has been removed to the connected second underlay VRF.

[0140] In an embodiment, the second overlay VRF removes the outer tunnel encapsulation from the received first packet on which further outer tunnel encapsulation is being performed based on a pre-configured protocol of the outer tunnel, and transfers the first packet from which the outer tunnel encapsulation has been removed to the connected second underlay VRF.

[0141] Transmit a first packet with outer tunnel encapsulation removed to a first overlay VRF by using a second underlay VRF.

[0142] In an embodiment, if it is determined that the VRF identifier in the inner tunnel encapsulation of the first packet with outer tunnel encapsulation removed is the identifier of the first overlay VRF, the second overlay VRF transmits the first packet with outer tunnel encapsulation removed to the first overlay VRF.

[0143] Remove inner tunnel encapsulation from a first packet with outer tunnel encapsulation removed by using a first overlay VRF, and transfer the first packet with inner tunnel encapsulation removed based on the initial destination address.

[0144] In an embodiment, after obtaining the first packet with outer tunnel encapsulation removed, the first overlay VRF removes inner tunnel encapsulation from the first packet with outer tunnel encapsulation removed based on a preconfigured protocol of the inner tunnel. Then, the first overlay VRF obtains the initial destination address carried in the first packet with inner tunnel encapsulation removed, queries routing information to determine the next-hop address corresponding to the initial destination address, and transfers the first packet with inner tunnel encapsulation removed based on the next-hop address.

[0145] Hereinafter, the CPE shown in FIG. 16 is used as the second CPE on the receiving side, and the packet transfer processing procedure by the second CPE will be described. Note that the CPE shown in FIG. 16 is not connected to the GW but directly accesses the backbone network. Corresponding to the case where the first packet is transferred by the GW shown in FIG. 14, the packet received by the CPE is the first packet from which the outer tunnel encapsulation has been removed. Refer to FIG. 17. The packet transfer processing procedure by the second CPE may include the following steps.

[0146] S701. By using the first underlay VRF in the second CPE, receive the first packet transmitted by the GW, and transmit the first packet to the first overlay VRF in the second CPE. The first packet includes inner tunnel encapsulation.

[0147] In an embodiment, in the second CPE, the WAN port corresponding to the first destination address receives the first packet from which the outer encapsulation has been removed. When it is determined that the VRF identifier in the inner tunnel encapsulation of the first packet is the identifier of the first overlay VRF, the first underlay VRF associated with the WAN port transmits the first packet from which the outer tunnel encapsulation has been removed to the first overlay VRF.

[0148] S702. By using the first overlay VRF, remove the inner tunnel encapsulation from the first packet from which the outer tunnel encapsulation has been removed, and based on the initial destination address, transfer the first packet from which the inner tunnel encapsulation has been removed.

[0149] In an embodiment, after obtaining a first packet from which the outer tunnel encapsulation has been removed, the first overlay VRF removes the inner tunnel encapsulation from the first packet from which the outer tunnel encapsulation has been removed, based on a preconfigured protocol of the inner tunnel. Next, the first overlay VRF obtains the initial destination address carried in the first packet from which the inner tunnel encapsulation has been removed, queries the routing information to determine the next-hop address corresponding to the initial destination address, and transfers the first packet from which the inner tunnel encapsulation has been removed based on the next-hop address.

[0150] Hereinafter, using the CPE shown in FIG. 5 as the second CPE on the receiving side, the packet transfer processing procedure by the second CPE will be described. Note that the second CPE shown in FIG. 5 is connected to the GW to access the backbone network. Corresponding to the case where the first packet is transferred by the GW shown in FIG. 9 or FIG. 11, the packet received by the CPE is the first packet for which further outer tunnel encapsulation is being performed. Refer to FIG. 19. The packet transfer processing procedure by the second CPE may include the following steps.

[0151] S901. By using the first underlay VRF in the second CPE, receive the first packet transmitted by the GW and transmit the first packet to the second overlay VRF in the second CPE. The first packet includes inner tunnel encapsulation and outer tunnel encapsulation.

[0152] In an embodiment, in the second CPE, the WAN port corresponding to the third destination address receives the first packet for which further outer encapsulation is being performed.

[0153] Note that in this specification, the VRF identifier of the first overlay VRF in the first CPE is the same as the VRF identifier of the first overlay VRF in the second CPE. In the GW, the VRF identifier of the VRF that performs the task of further outer tunnel encapsulation is the same as the VRF identifier of the second overlay VRF in the second CPE.

[0154] If it is determined that the VRF identifier in the outer tunnel encapsulation of the first packet is the VRF identifier of the second overlay VRF, the first underlay VRF associated with the WAN port transfers the first packet to the second overlay VRF.

[0155] S902. Remove the outer tunnel encapsulation of the first packet by using the second overlay VRF, and send the first packet with the outer tunnel encapsulation removed to the first overlay VRF.

[0156] In an embodiment, the second overlay VRF removes the outer tunnel encapsulation of the first packet based on a pre-configured tunneling protocol of the outer tunnel. Then, if it is determined that the VRF identifier in the inner tunnel encapsulation of the first packet with the outer tunnel encapsulation removed is the VRF identifier of the first overlay VRF, the first underlay VRF transfers the first packet with the outer tunnel encapsulation removed to the first overlay VRF.

[0157] S903. Remove the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed by using the first overlay VRF, and transfer the first packet with the inner tunnel encapsulation removed.

[0158] In an embodiment, after obtaining a first packet with the outer tunnel encapsulation removed, the first overlay VRF removes the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed, based on a pre-configured protocol of the inner tunnel. Next, the first overlay VRF obtains the initial destination address carried in the first packet with the inner tunnel encapsulation removed, queries the routing information to determine the next-hop address corresponding to the initial destination address, and forwards the first packet with the inner tunnel encapsulation removed based on that next-hop address.

[0159] Hereinafter, using the CPE shown in FIG. 7 as the second CPE on the receiving side, the packet transfer processing procedure by the second CPE will be described. Note that the CPE shown in FIG. 7 is connected to the GW to access the backbone network. Corresponding to the case where the first packet is transferred by the GW shown in FIG. 9 or FIG. 11, the packet received by the CPE is the first packet with further outer tunnel encapsulation being performed. Refer to FIG. 18. The packet transfer processing procedure by the second CPE may include the following steps.

[0160] S801. By using the first underlay VRF in the second CPE, receive the first packet sent by the GW. The first packet includes inner tunnel encapsulation and outer tunnel encapsulation. Remove the outer tunnel encapsulation of the first packet, and send the first packet with the outer tunnel encapsulation removed to the first overlay VRF.

[0161] In an embodiment, in the second CPE, the WAN port corresponding to the third destination address receives the first packet with further outer encapsulation being performed.

[0162] Note that in this specification, the VRF identifier of the first overlay VRF in the first CPE is the same as the VRF identifier of the first overlay VRF in the second CPE. Similarly, when performing further outer tunnel encapsulation on the first packet from which the outer tunnel encapsulation has been removed, the GW encapsulates the VRF identifier of the VRF that performs the further outer tunnel encapsulation at that GW into the first packet, and the VRF identifier of the VRF at the GW is the same as the VRF identifier of the first overlay VRF in the second CPE and is also the same as the VRF identifier of the first overlay VRF in the first CPE. 1 first overlay VRF in the second CPE is the same as the first overlay VRF in the first CPE. 1 first overlay VRF in the first CPE.

[0163] If it is determined that the VRF identifier in the outer tunnel encapsulation of the first packet is the same as the VRF identifier of the first underlay VRF, the first underlay VRF associated with the WAN port removes the outer tunnel encapsulation of the first packet based on the pre-configured tunneling protocol of the outer tunnel. Next, if it is determined that the VRF identifier in the inner tunnel encapsulation of the first packet from which the outer tunnel encapsulation has been removed is the VRF identifier of the first overlay VRF, the first underlay VRF transfers the first packet from which the outer tunnel encapsulation has been removed to the first overlay VRF.

[0164] S802. By using the first overlay VRF, remove the inner tunnel encapsulation from the first packet from which the outer tunnel encapsulation has been removed, and transfer the first packet from which the inner tunnel encapsulation has been removed.

[0165] In an embodiment, after obtaining a first packet with the outer tunnel encapsulation removed, a first overlay VRF removes the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed, based on a preconfigured protocol of the inner tunnel. Next, the first overlay VRF obtains the initial destination address carried in the first packet with the inner tunnel encapsulation removed, queries the routing information to determine the next-hop address corresponding to the initial destination address, and transfers the first packet with the inner tunnel encapsulation removed based on the next-hop address.

[0166] In a particular embodiment, the embodiments of the present application may also be applied to the scenario shown in FIG. 20, in which a first CPE is connected to two GWs, a second CPE is connected to one GW, and the first CPE uses the first GW and the third GW to establish an inner tunnel to the second CPE A first overlay VRF, a second overlay VRF, a third overlay VRF, a first underlay VRF, a second underlay VRF, and a third underlay VRF are deployed in the first CPE. A first LAN port associated with the second overlay VRF and a first WAN port associated with the second underlay VRF are connected by using a physical line. A second LAN port associated with the third overlay VRF and a third WAN port associated with the third underlay VRF are connected by using a physical line, and the second WAN port is associated with the first underlay VRF. The first overlay VRF, the second overlay VRF, the first underlay VRF, and the second underlay VRF are deployed in the second CPE, and a first LAN port associated with the second overlay VRF and a first WAN port associated with the second underlay VRF are connected by using a physical line.

[0167] In this scenario, there are two end-to-end tunnels between the first CPE and the second CPE. Therefore, when the first CPE sends a packet to the second CPE, the first overlay VRF in the first CPE can perform load sharing in the two tunnels based on the Equal-Cost Multi-path (ECMP) protocol. Certainly, if there is another end-to-end tunnel between the first CPE and the second CPE, when the first CPE sends a packet to the second CPE, the first overlay VRF can perform load sharing in various end-to-end tunnels between the first CPE and the second CPE based on the ECMP protocol.

[0168] In addition, it should be noted that the second overlay VRF and the second underlay VRF can alternatively be connected in the inner-loop connection mode shown in FIG. 3. Similarly, the third overlay VRF and the third underlay VRF can alternatively be connected in the inner-loop connection mode shown in FIG. 3. Similarly, the second overlay VRF and the second underlay VRF in the second CPE can alternatively be connected in the inner-loop connection mode shown in FIG. 3.

[0169] When a packet is transferred, the processing of the first CPE in FIG. 20 is the same as or similar to the processing procedure shown in FIG. 4 for packet transfer by the CPE. Details are not described again in this specification. The processing of the first GW and the third GW in FIG. 20 is the same as or similar to the processing procedure shown in FIG. 12 for packet transfer by the first GW. Details are not described again in this specification. The processing of the 3 GW in FIG. 20 is the same as or similar to the processing procedure shown in FIG. 14 for packet transfer by the second GW. Details are not described again in this specification.

[0170] Before the packet transfer method is implemented, the CPE needs to be configured. Please refer to FIG. 21. The CPE shown in FIGS. 2 and 3 can be configured as follows.

[0171] S111. The controller sends a port address assignment message to the first CPE.

[0172] In an embodiment, the controller may specify the IP address of each port in the first CPE. Specifically, for the CPE shown in FIG. 2, the controller may specify the IP addresses of the first WAN port, the first LAN port, and the second WAN port. For the CPE shown in FIG. 3, the controller may specify the IP addresses of the first loopback port, the second loopback port, and the second WAN port.

[0173] S112. The first CPE configures the address of each port based on the port address assignment message.

[0174] In an embodiment, the first CPE may configure the IP addresses for the first WAN port, the first LAN port, and the second WAN port shown in FIG. 2 based on the IP address information carried in the port address assignment message. Alternatively, IP addresses are configured for the first loopback port, the second loopback port, and the second WAN port shown in FIG. 3.

[0175] S113. The controller sends an overlay VRF establishment message to the first CPE.

[0176] In an embodiment, for the cases shown in FIGS. 2 and 3, the overlay VRF establishment message may carry the VRF identifier of the first overlay VRF and the VRF identifier of the second overlay VRF.

[0177] Regarding the case shown in FIG. 5, the overlay VRF establishment message may carry the VRF identifier of the first overlay VRF and the VRF identifier of the second overlay VRF.

[0178] Regarding the case shown in FIG. 7, the overlay VRF establishment message may carry the VRF identifier of the first overlay VRF.

[0179] Regarding the case shown in FIG. 20, the overlay VRF establishment message may carry the VRF identifier of the first overlay VRF, the VRF identifier of the second overlay VRF, and the VRF identifier of the third overlay VRF.

[0180] S114. The first CPE establishes the corresponding overlay VRF in the first CPE based on the overlay VRF establishment message.

[0181] In an embodiment, regarding the cases shown in FIGS. 2 and 3, the first CPE establishes the first overlay VRF and the second overlay VRF in the first CPE.

[0182] Regarding the case shown in FIG. 5, the first CPE establishes the first overlay VRF and the second overlay VRF in the first CPE.

[0183] Regarding the case shown in FIG. 7, the first CPE establishes the first overlay VRF in the first CPE.

[0184] Regarding the case shown in FIG. 20, the first CPE establishes the first overlay VRF, the second overlay VRF, and the third overlay VRF in the first CPE.

[0185] S115. The controller sends an underlay VRF establishment message to the first CPE.

[0186] In an embodiment, for the cases shown in FIGS. 2 and 3, the underlay VRF establishment message carries the VRF identifier of the first underlay VRF and the VRF identifier of the second underlay VRF.

[0187] For the case shown in FIG. 5, the underlay VRF establishment message carries the VRF identifier of the first underlay VRF.

[0188] For the case shown in FIG. 7, the underlay VRF establishment message carries the VRF identifier of the first underlay VRF.

[0189] For the case shown in FIG. 20, the underlay VRF establishment message carries the VRF identifier of the first underlay VRF, the VRF identifier of the second underlay VRF, and the VRF identifier of the third underlay VRF.

[0190] S116. The first CPE establishes the corresponding underlay VRF at the first CPE based on the underlay VRF establishment message.

[0191] In an embodiment, for the cases shown in FIGS. 2 and 3, the first CPE establishes the first underlay VRF and the second underlay VRF at the first CPE.

[0192] For the case shown in FIG. 5, the first CPE establishes the first underlay VRF at the first CPE.

[0193] For the case shown in FIG. 7, the first CPE establishes the first underlay VRF at the first CPE.

[0194] Regarding the case shown in FIG. 20, the first CPE establishes a first underlay VRF, a second underlay VRF, and a third underlay VRF in the first CPE.

[0195] S117. The controller sends a port association message to the first CPE, and the port association message includes an identifier of a port corresponding to the first source address and a corresponding VRF identifier, and an identifier of a port corresponding to the second source address and a corresponding VRF identifier.

[0196] In an embodiment, regarding the case shown in FIG. 2, in the port association message, the port corresponding to the first source address is the first WAN port, the corresponding VRF identifier is the VRF identifier of the second underlay VRF, the port corresponding to the second source address is the second WAN port, and the corresponding VRF identifier is the VRF identifier of the first underlay VRF. In addition, the port association message may further carry an identifier of the first LAN port and a VRF identifier of the second overlay VRF.

[0197] Regarding the case shown in FIG. 3, in the port association message, the port corresponding to the first source address is the first loopback port, the corresponding VRF identifier is the VRF identifier of the second underlay VRF, the port corresponding to the second source address is the second WAN port, and the corresponding VRF identifier is the VRF identifier of the first underlay VRF. In addition, the port association message may further carry an identifier of the second loopback port and a VRF identifier of the second overlay VRF.

[0198] Regarding the case shown in FIG. 5, in the port association message, the port corresponding to the first source address is a loopback port, the corresponding VRF identifier is the VRF identifier of the second overlay VRF, the port corresponding to the second source address is a WAN port, and the corresponding VRF identifier is the VRF identifier of the first underlay VRF.

[0199] Regarding the case shown in FIG. 7, in the port association message, the port corresponding to the first source address is a loopback port, the corresponding VRF identifier is the VRF identifier of the first underlay VRF, the port corresponding to the second source address is a WAN port, and the corresponding VRF identifier is also the VRF identifier of the first underlay VRF.

[0200] Regarding the case shown in FIG. 20, in the port association message, the port corresponding to the first source address is the first WAN port, and the corresponding VRF identifier is the VRF identifier of the second underlay VRF. Alternatively, in the port association message, the port corresponding to the first source address is the third WAN port, and the corresponding VRF identifier is the VRF identifier of the third underlay VRF. The port corresponding to the second source address is the second WAN port, and the corresponding VRF identifier is the VRF identifier of the first underlay VRF. In addition, the port association message may further carry the identifier of the first LAN port, the VRF identifier of the second overlay VRF, the identifier of the second LAN port, and the VRF identifier of the third overlay VRF.

[0201] S118. The first CPE associates the ports in the first CPE with the corresponding VRFs based on the port association message.

[0202] In an embodiment, with respect to the case shown in FIG. 2, the first CPE associates the first WAN port with the second underlay VRF, the second WAN port with the first underlay VRF, and the first LAN port with the second overlay VRF.

[0203] With respect to the case shown in FIG. 3, the first CPE associates the first loopback port with the second underlay VRF, the second WAN port with the first underlay VRF, and the second loopback port with the second overlay VRF.

[0204] With respect to the case shown in FIG. 5, the first CPE associates the loopback port with the second overlay VRF and the WAN port with the first underlay VRF.

[0205] With respect to the case shown in FIG. 7, the first CPE associates the loopback port with the first underlay VRF and also associates the WAN port with the first underlay VRF.

[0206] With respect to the case shown in FIG. 20, the first CPE associates the first WAN port with the second underlay VRF, the second WAN port with the first underlay VRF, the third WAN port with the third underlay VRF, the first LAN port with the second overlay VRF, and the second LAN port with the third overlay VRF.

[0207] Next, in the case shown in FIG. 2, the first CPE may establish an outer loop physical line connection for the second overlay VRF and the second underlay VRF. In the case shown in FIG. 3, the first CPE may establish an inner loop tunnel between the loopback ports of the second overlay VRF and the second underlay VRF. In the case shown in FIG. 20, the first CPE may establish an outer loop physical line connection for the second overlay VRF and the second underlay VRF, and may establish an outer loop physical line connection for the third overlay VRF and the third underlay VRF. Indeed, in the case shown in FIG. 20, the connection between the second overlay VRF and the second underlay VRF, and the connection between the third overlay VRF and the third underlay VRF may alternatively be implemented by establishing an inner loop tunnel, or the connection may be implemented by establishing an outer loop physical line connection for one pair, and the connection may be implemented by establishing an inner loop tunnel for the other pair.

[0208] S119. The controller transmits a routing domain assignment message to the first CPE.

[0209] In an embodiment, a technician configures, in the controller, routing domain assignment information corresponding to a port in the first CPE. The routing domain assignment information indicates the routing domain assigned to the port. The port in the first CPE may include a WAN port and a loopback port, and the routing domain assigned may include a backbone, the Internet, etc. The controller then distributes a routing domain assignment message to the first CPE. The routing domain assignment message carries a port identifier and a corresponding routing domain identifier.

[0210] S1110. The first CPE assigns a routing domain to a port.

[0211] In an embodiment, the first CPE assigns a routing domain to each WAN port and loopback port based on a routing domain assignment message. The first source address and the second source address have different routing domains. Regarding the case shown in FIG. 2, the routing domain of the first WAN port is different from the routing domain of the second WAN port. For example, the routing domain of the first WAN port may be a backbone, and the routing domain of the second WAN port may be the Internet. Regarding the case shown in FIG. 3, the routing domain of the first loopback port is different from the routing domain of the second WAN port. For example, the routing domain of the first loopback port may be a backbone, and the routing domain of the second WAN port may be the Internet.

[0212] S1111. A route reflector (RR) sends the second destination address associated with the GW to the first CPE.

[0213] In an embodiment, after the foregoing configuration is completed, each network device such as the first CPE, the second CPE, and the GW may send the IP address of each port of the device, the corresponding routing domain identifier, and the device identifier to the RR. After receiving the message sent by the GW, the RR may send the routing domain corresponding to the IP address of the GW's port, the device identifier, etc. to the first CPE.

[0214] S1112. The first CPE establishes an outer tunnel based on the second source address and the second destination address, and the routing domain of the port corresponding to the second destination address is the same as the routing domain of the port corresponding to the second source address.

[0215] The second source address is the IP address of the WAN port in the first CPE, and the second destination address is the IP address of the WAN port in the GW.

[0216] In an embodiment, after receiving the IP address of the port of the GW, the corresponding routing domain, the device identifier, etc. transmitted by the RR, the first CPE attempts to establish a tunnel through the ports in the same routing domain in the two devices. In this way, a tunnel, that is, an outer tunnel, is established between the port corresponding to the second source address in the first CPE and the port corresponding to the second destination address in the GW.

[0217] S1113. The RR transmits the first destination address associated with the second CPE to the first CPE.

[0218] The first destination address is the IP address of the WAN port or the loopback port in the second CPE.

[0219] In an embodiment, after receiving the IP address of each port transmitted by the second CPE, the corresponding routing domain identifier, the device identifier, etc., the RR may transmit that information to the first CPE.

[0220] S1114. The first CPE establishes an inner tunnel based on the first source address and the first destination address, and the routing domain of the port corresponding to the first destination address is the same as the routing domain of the port corresponding to the first source address.

[0221] In an embodiment, after receiving the IP address of the port of the second CPE transmitted by the RR, the corresponding routing domain identifier, the device identifier, etc., the first CPE attempts to establish a tunnel through the ports in the same routing domain in the two devices. Since a connection has already been established between the first CPE and the GW through the outer tunnel, the first CPE can establish a tunnel, i.e., an inner tunnel, between the port corresponding to the first source address in the first CPE and the port corresponding to the first destination address in the second CPE based on the outer tunnel. The inner tunnel connects the first CPE and the second CPE by using the GW and the backbone network.

[0222] When the tunnel is established, each network device on the path where the tunnel is arranged can know and store the routing information. For example, the first CPE can know the routing information of the inner tunnel in the first CPE. The routing information includes the correspondence between the first destination address and the second WAN port, and the correspondence between the second WAN port and the second source address and the second destination address. The GW can know the routing information of the inner tunnel in the GW, i.e., the correspondence between the first destination address and the next-hop address.

[0223] S1115. The controller transmits the destination address set on the LAN side corresponding to the second CPE to the first CPE.

[0224] In an embodiment, the CPE may report the IP address of the corresponding terminal device on the LAN side and the device identifier of the CPE to the controller. For example, the second CPE may report the IP address of each terminal device on the LAN side and the device identifier of the second CPE to the controller. After receiving the information, the controller may send the information to another CPE. For example, the controller may send the IP address of each terminal device on the LAN side of the second CPE and the device identifier of the second CPE to the first CPE.

[0225] S1116. The first CPE establishes a correspondence between the second CPE and the destination address set on the LAN side.

[0226] In an embodiment, after receiving the IP address of each terminal device on the LAN side of the second CPE and the device identifier of the second CPE, the first CPE may correspondingly store the device identifier of the second CPE and the IP address of each terminal device on the LAN side of the second CPE.

[0227] In the present application, an end-to-end tunnel between two CPEs passing through the backbone network can be established through the foregoing configuration.

[0228] Based on the same technical concept, an embodiment of the present invention further provides a packet transfer device. The packet transfer device may be the CPE of FIG. 2, FIG. 3, FIG. 5, or FIG. 7. As shown in FIG. 22, the device includes a receiving module 220, an inner encapsulation module 221, an outer encapsulation module 222, and a transfer module 223.

[0229] The receiving module 220 is configured to receive a first packet and obtain the initial destination address of the first packet. For specific embodiments, refer to the detailed description of step S101 in the embodiment shown in FIG. 4, or the detailed description of step S201 in the embodiment shown in FIG. 6, or the detailed description of step S301 in the embodiment shown in FIG. 8. Details will not be described again in this specification.

[0230] The inner encapsulation module 221 is configured to determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address. The inner tunnel is an end-to-end tunnel between the first CPE and the second CPE. For specific embodiments, refer to the detailed description of step S102 in the embodiment shown in FIG. 4, or the detailed description of step S202 in the embodiment shown in FIG. 6, or the detailed description of step S302 in the embodiment shown in FIG. 8. Details will not be described again in this specification.

[0231] The outer encapsulation module 222 is configured to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and perform outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation has been performed based on the second source address and the second destination address. For specific embodiments, refer to the detailed description of steps S103 and S104 in the embodiment shown in FIG. 4, or the detailed description of steps S203 and S204 in the embodiment shown in FIG. 6, or the detailed description of step S303 in the embodiment shown in FIG. 8. Details will not be described again in this specification.

[0232] The transfer module 223 is configured to transfer the first packet on which the outer tunnel encapsulation has been performed.

[0233] In certain embodiments, the receiving module 220 route reflector ( RR ) receives the second destination address sent by the RR, and establishes an outer tunnel based on the second source address and the second destination address, wherein the routing domain of the port corresponding to the second destination address is the same as the routing domain of the port corresponding to the second source address, and receives and establishes; receives the first destination address sent by the RR, and establishes an inner tunnel based on the first source address and the first destination address, wherein the routing domain of the port corresponding to the first destination address is the same as the routing domain of the port corresponding to the first source address, and receives and establishes; generates routing information for the inner tunnel in the first CPE, wherein the routing information includes the correspondence between the first destination address and the second source address and the second destination address; and is further configured to perform the above.

[0234] In certain embodiments, the receiving module 220 receives the overlay VRF configuration message sent by the controller, and establishes a first overlay VRF and a second overlay VRF in the first CPE, receives the underlay VRF configuration message sent by the controller, and establishes a first underlay VRF in the first CPE, receives the port association message sent by the controller, associates the second overlay VRF with the port corresponding to the first source address, and associates the first underlay VRF with the second source address To the corresponding port and is further configured to perform the above.

[0235] In certain embodiments, the inner encapsulation module 221 The first overlay VRF determines the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and is configured to perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, The inner encapsulation module 221 The first overlay VRF is further configured to send the first packet on which the inner tunnel encapsulation is performed to the second overlay VRF corresponding to the first source address, The outer encapsulation module 222 The second overlay VRF determines the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and is further configured to perform outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address, The outer encapsulation module 222 The second overlay VRF is further configured to send the first packet on which the outer tunnel encapsulation is performed to the first underlay VRF corresponding to the second source address, and The forwarding module 223 The first underlay VRF is configured to forward the first packet on which the outer tunnel encapsulation is performed.

[0236] In a particular embodiment, the receiving module 220 receives the overlay VRF configuration message sent by the controller, and establishes the first overlay VRF and the second overlay VRF at the first CPE, Receive the underlay VRF configuration message sent by the controller, establish a first underlay VRF and a second underlay VRF in the first CPE, and Receive the port association message sent by the controller, associate the second underlay VRF with the port corresponding to the first source address, and further configure the first underlay VRF to be To the corresponding port associated with the second source address.

[0237] In certain embodiments, the inner -er encapsulation module 221 is configured by the first overlay VRF to determine a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and perform inner tunnel encapsulation on a first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, The inner encapsulation module 221 is configured by the first overlay VRF to send the first packet on which inner tunnel encapsulation is being performed to a second underlay VRF corresponding to the first source address, and further configured by the second underlay VRF to send the first packet on which inner tunnel encapsulation is being performed to a second overlay VRF within the first CPE and connected to the second underlay VRF, The outer -er encapsulation module 222 is configured by the second overlay VRF to determine a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and further configured to perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation is being performed based on the second source address and the second destination address, The outer encapsulation module 222 is The second overlay VRF is further configured to send a first packet on which outer tunnel encapsulation is performed to a first underlay VRF corresponding to a second source address, and The transfer module 223 is configured by the first underlay VRF to transfer a first packet on which outer tunnel encapsulation is performed.

[0238] In certain embodiments, the second underlay VRF is connected to the second overlay VRF by using an outer loop.

[0239] In certain embodiments, the second underlay VRF is connected to the second overlay VRF through a corresponding physical port.

[0240] In certain embodiments, the second underlay VRF is connected to the second overlay VRF by using an inner loop.

[0241] In certain embodiments, the second underlay VRF is connected to the second overlay VRF through a corresponding loopback port.

[0242] In certain embodiments, Receiving module 220 is to receive a connection establishment message sent by a controller Matters wherein the connection establishment message carries an identifier of the second underlay VRF and an identifier of the second overlay VRF And The and further includes establishing a connection between a loopback port corresponding to the second underlay VRF and a loopback port corresponding to the second overlay VRF Matters and .

[0243] In certain embodiments, the receiving module 220 is Receive the overlay VRF configuration message sent by the controller, establish a first overlay VRF in the first CPE, Receive the underlay VRF configuration message sent by the controller, establish a first underlay VRF in the first CPE, and Receive the port association message sent by the controller, and further configure the first underlay VRF to be associated with the port corresponding to the first source address and the second source address.

[0244] In a particular embodiment, the inner -er encapsulation module 221 Determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address by the first overlay VRF, and configure to perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address. Inner -er encapsulation module 221 Is further configured to send the first packet on which the inner tunnel encapsulation is performed by the first overlay VRF to the first underlay VRF corresponding to the first source address. Outer -er encapsulation module 222 Determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address by the first underlay VRF, and configure to perform outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address. Forwarding module 223 Is configured to forward the first packet on which the outer tunnel encapsulation is performed by the first underlay VRF.

[0245] In certain embodiments, the inner tunnel encapsulation module is configured to determine an inner tunnel having the highest tunnel service quality among a plurality of inner tunnels corresponding to an initial destination address, and to determine a first source address and a first destination address of the inner tunnel having the highest tunnel service quality.

[0246] It should be noted that when the packet transfer device provided in the foregoing embodiments transfers a packet, the division of the foregoing functional modules is only used as an example for illustration. In actual applications, the foregoing functions can be assigned to different functional modules as needed and thereby completed. That is, the internal structure of the first CPE is divided into different functional modules to implement all or some of the functions described above. In addition, the packet transfer device provided in the foregoing embodiments belongs to the same concept as the embodiment of the packet transfer method. For the specific implementation process of the packet transfer device, please refer to the method embodiment. Details will not be described again in this specification.

[0247] Based on the same technical concept, embodiments of the present invention further provide a packet transfer device. The packet transfer device can be the GW in FIG. 9, FIG. 11, or FIG. 14. As shown in FIG. 23, the device includes a receiving module 230, a decapsulation module 231, and a transfer module 232.

[0248] The receiving module 230 is configured to receive a first packet transmitted by a first CPE. The first packet includes inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE. For specific embodiments, please refer to the detailed description of step S401 in the embodiment shown in FIG. 10, or the detailed description of step S501 in the embodiment shown in FIG. 12. Details will not be described again in this specification.

[0249] The decapsulation module 231 is configured to remove the outer tunnel encapsulation of the first packet. For specific embodiments, refer to the detailed description of step S402 in the embodiment shown in FIG. 10, or the detailed description of step S502 in the embodiment shown in FIG. 12. The details will not be described again herein.

[0250] The transfer module 232 is configured to transfer the first packet with the outer tunnel encapsulation removed based on the first destination address in the inner tunnel encapsulation of the first packet. The first destination address is associated with the second CPE. For specific embodiments, refer to the detailed description of step S403 in the embodiment shown in FIG. 10, or the detailed description of step S503 in the embodiment shown in FIG. 12. The details will not be described again herein.

[0251] In a specific embodiment, the transfer module 232 is configured to determine the third source address and the third destination address of the outer tunnel corresponding to the first destination address in the inner tunnel encapsulation of the first packet, and perform further outer tunnel encapsulation on the first packet with the outer tunnel encapsulation removed based on the third source address and the third destination address, and transfer the first packet with the further outer tunnel encapsulation performed.

[0252] In a specific embodiment, the receiving module 240 receives the routing domain assignment message sent by the controller and assigns the routing domain to the port corresponding to the third source address, Receiving the third destination address sent by RR and establishing an outer tunnel based on the third destination address and the third source address, wherein the routing domain of the port corresponding to the third source address is the same as the routing domain of the port corresponding to the third destination address, receiving and establishing; Establishing a correspondence between the first destination address and the third source address and the third destination address of the outer tunnel; is configured to perform.

[0253] It should be noted that when the packet transfer device provided in the foregoing embodiment transfers a packet, the division of the foregoing functional modules is only used as an example for explanation. In actual applications, the foregoing functions can be assigned to different functional modules as needed and thereby completed. That is, the internal structure of the GW is divided into different functional modules to implement all or some of the functions described above. In addition, the packet transfer device provided in the foregoing embodiment belongs to the same concept as the embodiment of the packet transfer method. For the specific implementation process of the packet transfer device, please refer to the method embodiment. Details are not described again in this specification.

[0254] Based on the same technical concept, an embodiment of the present invention further provides a packet transfer device. The packet transfer device can be the CPE of FIG. 2, FIG. 3, FIG. 5, or FIG. 7. As shown in FIG. 24, the device includes a receiving module 240, a decapsulation module 241, and a transfer module 242.

[0255] The receiving module 240 is configured to receive a first packet. The first packet is from a first CPE, and the first packet includes inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE. For specific embodiments, refer to the detailed description of step S601 of the embodiment shown in FIG. 15, or the detailed description of step S701 of the embodiment shown in FIG. 17, or the detailed description of step S801 of the embodiment shown in FIG. 18, or the detailed description of step S901 of the embodiment shown in FIG. 19. The details will not be described again herein.

[0256] The encapsulation removal module 241 is configured to remove the outer tunnel encapsulation of the first packet. For specific embodiments, refer to the detailed description of step S602 of the embodiment shown in FIG. 15, or the detailed description of step S801 of the embodiment shown in FIG. 18, or the detailed description of step S902 of the embodiment shown in FIG. 19. The details will not be described again herein.

[0257] Decapsulation removal module 241 is configured to remove the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transfer the first packet with the inner tunnel encapsulation removed. For specific embodiments, refer to the detailed description of step S603 of the embodiment shown in FIG. 15, or the detailed description of step S702 of the embodiment shown in FIG. 17, or the detailed description of step S802 of the embodiment shown in FIG. 18, or the detailed description of step S903 of the embodiment shown in FIG. 19. The details will not be described again herein.

[0258] In a specific embodiment, the receiving module 240 is configured to receive the first packet by using a first underlying VRF in the second CPE, The decapsulation removal module 241 By using the first overlay VRF, the inner tunnel encapsulation is removed from the first packet from which the outer tunnel encapsulation has been removed, removes the outer tunnel encapsulation of the first packet by using the first underlay VRF, and is configured to transmit the first packet with the outer tunnel encapsulation removed to the first overlay VRF in the second CPE by using the first underlay VRF, and the transfer module 242 、 In is configured to transfer the first packet with the inner tunnel encapsulation removed.

[0259] In certain embodiments, the receiving module 240 receives the first packet by using the first underlay VRF in the second CPE, and is configured to transmit the first packet to the second overlay VRF in the second CPE by using the first underlay VRF in the second CPE, the decapsulation removal module 241 By using the first overlay VRF, the inner tunnel encapsulation is removed from the first packet from which the outer tunnel encapsulation has been removed, removes the outer tunnel encapsulation of the first packet by using the second overlay VRF, and is configured to transmit the first packet with the outer tunnel encapsulation removed to the first overlay VRF in the second CPE by using the second overlay VRF, the transfer module 242 、 In is configured to transfer the first packet with the inner tunnel encapsulation removed.

[0260] In certain embodiments, the decapsulation removal module 241 By using a second overlay VRF, the outer tunnel encapsulation of the first packet is removed, and the first packet with the outer tunnel encapsulation removed is sent to a second underlay VRF connected to the second overlay VRF, and configured to send the first packet with the outer tunnel encapsulation removed to the first overlay VRF by using the second underlay VRF.

[0261] In certain embodiments, the second underlay VRF is connected to the second overlay VRF by using an outer loop.

[0262] In certain embodiments, the second underlay VRF is connected to the second overlay VRF through a corresponding physical port.

[0263] In certain embodiments, the second underlay VRF is connected to the second overlay VRF by using an inner loop.

[0264] In certain embodiments, the second underlay VRF is connected to the second overlay VRF through a corresponding loopback port.

[0265] It should be noted that when the packet transfer device provided in the foregoing embodiments transfers a packet, the division of the foregoing functional modules is only used as an example for explanation. In actual applications, the foregoing functions can be allocated to different functional modules as needed and thereby completed. That is, the internal structure of the second CPE is divided into different functional modules to implement all or some of the functions described above. In addition, the packet transfer device provided in the foregoing embodiments belongs to the same concept as the embodiment of the packet transfer method. For the specific implementation process of the packet transfer device embodiment, please refer to the method embodiment. Details are not described again in this specification.

[0266] Based on the same technical concept, embodiments of the present application further provide a CPE Configuration device composition method. The packet transfer device can be the CPE of FIG. 2, FIG. 3, FIG. 5, or FIG. 7. As shown in FIG. 25, the device includes a receiving module 250, an encapsulation module 251, and a generation module 252.

[0267] The receiving module 250 is configured to receive the second destination address associated with the GW transmitted by the RR and establish an outer tunnel based on the second source address and the second destination address. For specific embodiments, refer to the detailed description of step S1112 of the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0268] The encapsulation module 251 is configured to receive the first destination address associated with the second CPE transmitted by the RR and establish an inner tunnel based on the first source address and the first destination address. The inner tunnel is an end-to-end tunnel between the first CPE and the second CPE. For specific embodiments, refer to the detailed description of step S1114 of the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0269] The generation module 252 is configured to generate routing information of the inner tunnel in the first CPE. The routing information includes the correspondence between the first destination address and the second source address and the second destination address. For specific embodiments, refer to the detailed description of step S1114 of the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0270] In a specific embodiment, the receiving module 250 receives the first packet and obtains the initial destination address of the first packet, and Determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, determine and perform; Determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation has been performed based on the second source address and the second destination address; Transmit the first packet on which outer tunnel encapsulation has been performed; It is further configured to perform the above.

[0271] In a specific embodiment, the receiving module 250 Receives the overlay VRF configuration message sent by the controller, establishes the first overlay VRF and the second overlay VRF at the first CPE, Receives the underlay VRF configuration message sent by the controller, establishes the first underlay VRF at the first CPE, and Receives the port association message sent by the controller, associates the second overlay VRF with the port corresponding to the first source address, and associates the first underlay VRF with the second source address To the corresponding port It is further configured to do so.

[0272] In a specific embodiment, the receiving module 250 Receives the first packet and obtains the initial destination address of the first packet; By the first overlay VRF, determine the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, and Transmit the first packet on which inner tunnel encapsulation is being performed to the second overlay VRF corresponding to the first source address, and By the second overlay VRF, determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation is being performed based on the second source address and the second destination address, and transmit the first packet on which outer tunnel encapsulation is being performed to the first underlay VRF corresponding to the second source address, and By the first underlay VRF, transfer the first packet on which outer tunnel encapsulation is being performed and Is further configured to perform.

[0273] In certain embodiments, the receiving module 250 Receives the overlay VRF configuration message sent by the controller, establishes the first overlay VRF and the second overlay VRF at the first CPE, Receives the underlay VRF configuration message sent by the controller, establishes the first underlay VRF and the second underlay VRF at the first CPE, and Receives the port association message sent by the controller, associates the second underlay VRF with the port corresponding to the first source address, and associates the first underlay VRF with the second source address To the corresponding port Is further configured to.

[0274] In certain embodiments, the receiving module 250 receives a first packet and obtains the initial destination address of the first packet, determines, by a first overlay VRF, a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performs inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between a first CPE and a second CPE, and transmits the first packet on which the inner tunnel encapsulation is performed to a second underlay VRF corresponding to the first source address, transmits, by the second underlay VRF, the first packet on which the inner tunnel encapsulation is performed to a second overlay VRF that is within the first CPE and is connected to the second underlay VRF, determines, by the second overlay VRF, a second source address and a second destination address of an outer tunnel corresponding to the first destination address, performs outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address, and transmits the first packet on which the outer tunnel encapsulation is performed to a first underlay VRF corresponding to the second source address, and transfers, by the first underlay VRF, the first packet on which the outer tunnel encapsulation is performed and is further configured to perform.

[0275] In certain embodiments, the receiving module 250 receives an overlay VRF configuration message sent by a controller and establishes a first overlay VRF at the first CPE, receives an underlay VRF configuration message sent by a controller and establishes a first underlay VRF at the first CPE, It is further configured to receive a port association message sent by a controller and associate a first overlay VRF with a port corresponding to a first source address and a second source address.

[0276] In certain embodiments, the receiving module 250 receives a first packet, obtains an initial destination address of the first packet, determines, by a first overlay VRF, a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, performs inner tunnel encapsulation on the first packet based on the first source address and the first destination address, and transmits the first packet on which the inner tunnel encapsulation has been performed to a first underlay VRF corresponding to the first source address, and is further configured to determine, by the first underlay VRF, a second source address and a second destination address of an outer tunnel corresponding to the first destination address, perform outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation has been performed based on the second source address and the second destination address, and transfer the first packet on which the outer tunnel encapsulation has been performed.

[0277] In the foregoing embodiments, CPE configuration it should be noted that when the device provided in the foregoing embodiments transfers a packet, the division of the foregoing functional modules is only used as an example for illustration. In actual applications, the foregoing functions can be assigned to different functional modules as needed and thereby completed. That is, the internal structure of the first CPE is divided into different functional modules to implement all or some of the functions described above. In addition, in the foregoing embodiments, CPE configuration the device belongs to the same concept as the embodiment of the packet transfer method. For the specific implementation process of the embodiment of the packet transfer device, please refer to the method embodiment. Details are not described again in this specification.

[0278] Embodiments of the present application further provide a CPE configuration device. The device can be an RR. As shown in FIG. 26, the device includes a receiving module 260 and a transmitting module 261.

[0279] The receiving module 260 is configured to receive a second destination address associated with the GW, which is transmitted by the GW. For specific embodiments, refer to the detailed description of step S1111 in the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0280] The transmitting module 261 is configured to transmit the second destination address to the first CPE. For specific embodiments, refer to the detailed description of step S1111 in the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0281] The receiving module 260 is configured to receive a first destination address associated with the second CPE, which is transmitted by the second CPE. For specific embodiments, refer to the detailed description of step S1113 in the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0282] The transmitting module 261 is configured to transmit the first destination address to the 1 CPE. For specific embodiments, refer to the detailed description of step S1113 in the embodiment shown in FIG. 21. The details will not be described again in this specification.

[0283] When the CPE configuration device provided in the foregoing embodiments constitutes a CPE, it should be noted that the division of the foregoing functional modules is only used as an example for illustration. In actual applications, the foregoing functions can be assigned to different functional modules as needed and thereby completed. That is, the internal structure of the RR is divided into different functional modules to implement all or some of the functions described above. In addition, the CPE configuration device provided in the foregoing embodiments belongs to the same concept as the embodiment of the CPE configuration method. For the specific implementation process of the CPE configuration device, please refer to the method embodiment. Details will not be described again in this specification.

[0284] Embodiments of the present application further provide a CPE configuration device. The device is applied to a controller. As shown in FIG. 27, the device includes a configuration module 270 and an association module 271.

[0285] The configuration module 270 is configured to send an overlay VRF configuration message to a first CPE and send an underlay VRF configuration message to the first CPE. For specific embodiments, please refer to the detailed description of step S113 of the embodiment shown in FIG. 21. Details will not be described again in this specification.

[0286] The association module 271 is configured to send a port association message to the first CPE. For specific embodiments, please refer to the detailed description of step S115 of the embodiment shown in FIG. 21. Details will not be described again in this specification.

[0287] In a specific embodiment, the overlay VRF configuration message carries the VRF identifier of the first overlay VRF and the VRF identifier of the second overlay VRF, the underlay VRF configuration message carries the VRF identifier of the first underlay VRF, and The port association message conveys the correspondence between the VRF identifier of the second overlay VRF and the first source address, and the correspondence between the VRF identifier of the first underlay VRF and the second source address.

[0288] In certain embodiments, the overlay VRF configuration message conveys the VRF identifier of the first overlay VRF, and the underlay VRF configuration message conveys the VRF identifier of the first underlay VRF, and the port association message conveys the correspondence between the VRF identifier of the second underlay VRF and the first source address, and the correspondence between the VRF identifier of the first underlay VRF and the second source address.

[0289] In certain embodiments, the overlay VRF configuration message conveys the VRF identifier of the first overlay VRF, the underlay VRF configuration message conveys the VRF identifier of the first underlay VRF, and the port association message conveys the correspondence between the VRF identifier of the first overlay VRF and the first and second source addresses.

[0290] It should be noted that when the CPE configuration device provided in the foregoing embodiments constitutes a CPE, the division of the foregoing functional modules is only used as an example for explanation. In actual applications, the foregoing functions can be assigned to different functional modules as needed and thereby completed. That is, the internal structure of the controller is divided into different functional modules to implement all or some of the functions described above. In addition, the CPE configuration device provided in the foregoing embodiments belongs to the same concept as the embodiment of the CPE configuration method. For the specific implementation process of the CPE configuration device, please refer to the method embodiment. Details will not be described again in this specification.

[0291] FIG. 28 is a schematic diagram of a communication device 1000 according to an embodiment of the present application. The communication device 1000 can be a first CPE that executes any one of the methods of FIGS. 4, 6, and 8. The communication device 1000 includes at least one processor 1001, an internal connection 1002, a memory 1003, and at least one transceiver 1004.

[0292] Optionally, the processor 1001 can be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to control the execution of the solution program in the present application.

[0293] The internal connection 1002 can include a path for transmitting information between the foregoing components. Optionally, the internal connection 1002 is a board, a bus, or the like.

[0294] The transceiver 1004 is configured to communicate with another device or a communication network.

[0295] The memory 1003 can be, but is not limited to, a read-only memory (ROM), or another type of static memory device capable of storing static information and instructions, a random access memory (RAM), or another type of dynamic memory device capable of storing information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or another compact disc storage device, an optical disc storage device (including compact discs, laser discs, optical discs, digital versatile discs, and Blu-ray discs, etc.), a magnetic disk storage medium, or another magnetic storage device, or any other medium that can be used to carry or store the expected program code in the form of instructions or data structures and can be accessed by a computer. The memory can exist independently and be connected to the processor by using a bus. Alternatively, the memory can be integrated into the processor.

[0296] The memory 1003 is configured to store application program code for executing the solutions of the present application, and the processor 1001 controls the execution. The processor 1001 is configured to execute the application program stored in the memory 1003 and cooperate with at least one transceiver 1004, whereby the communication device 1000 implements the functions in the present application.

[0297] In a particular embodiment, in one embodiment, the processor 1001 may include one or more CPUs, such as CPU 0 and CPU 1 shown in FIG. 27.

[0298] In certain embodiments, in one embodiment, communication device 1000 may include a plurality of processors, such as processor 1001 and processor 1007 shown in FIG. 27. Each of the processors may be a single-CPU or a multi-CPU processor. The processors herein may be one or more devices, circuits, and / or processing cores configured to process data (e.g., computer program instructions).

[0299] Communication device 1000 may be a first CPE, a second CPE, a GW, etc.

[0300] When communication device 1000 is the first CPE, processor 1001 Memory executes the application program code stored in 1003, whereby communication device 1000 executes the following processes. Receiving a first packet and obtaining the initial destination address of the first packet, determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and performing outer tunnel encapsulation on the first packet on which inner tunnel encapsulation has been performed based on the second source address and the second destination address, and transferring the first packet on which outer tunnel encapsulation has been performed.

[0301] Specifically, for a specific embodiment of the process executed by communication device 1000, refer to the specific processing process of the first CPE in the embodiments shown in FIGS. 4, 6, and 8.

[0302] When the communication device 1000 is the second CPE, the processor 1001 Memory executes the application program code stored in 1003, whereby the communication device 1000 executes the following processes. A step of receiving a first packet, the first packet including inner tunnel encapsulation and outer tunnel encapsulation, a step of removing the outer tunnel encapsulation of the first packet, and a step of removing the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transferring the first packet with the inner tunnel encapsulation removed.

[0303] Specifically, for a specific embodiment of the process executed by the communication device 1000, refer to the specific process of the second CPE in the embodiments shown in FIGS. 15, 17, 18, and 19.

[0304] When the communication device 1000 is the GW, the processor 1001 Memory executes the application program code stored in 1003, whereby the communication device 1000 executes the following processes. A step of receiving a first packet transmitted by a first CPE, the first packet including inner tunnel encapsulation and outer tunnel encapsulation, a step of removing the outer tunnel encapsulation of the first packet, and a step of transferring the first packet with the outer tunnel encapsulation removed based on the first destination address in the inner tunnel encapsulation of the first packet.

[0305] Specifically, for a specific embodiment of the process executed by the communication device 1000, refer to the specific process of the GW in the embodiments shown in FIGS. 10, 12, and 13.

[0306] When the communication device 1000 is an RR, the processor 1001 Memory executes the application program code stored in 1003, whereby the communication device 1000 executes the following processes. The step of receiving the second destination address associated with the GW, which is transmitted by the GW, the step of transmitting the second destination address to the first CPE, the step of receiving the first destination address associated with the second CPE, which is transmitted by the second CPE, and the step of transmitting the first destination address to the 1 first CPE.

[0307] Specifically, for a specific embodiment of the process executed by the communication device 1000, refer to the specific process of the RR in the embodiment shown in FIG. 21.

[0308] When the communication device 1000 is a controller, the processor 1001 Memory executes the application program code stored in 1003, whereby the communication device 1000 executes the following processes. The step of transmitting an overlay VRF configuration message to the first CPE, the step of transmitting an underlay VRF configuration message to the first CPE, and the step of transmitting a port association message to the first CPE.

[0309] Specifically, for a specific embodiment of the process executed by the communication device 1000, refer to the specific process of the controller in the embodiment shown in FIG. 21.

[0310] All or some of the foregoing embodiments may be implemented by software, hardware, firmware, or any combination thereof. When software is used in an embodiment, all or some of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a device, all or some of the processes or functions described in the embodiments of the present application are generated. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted in a wired manner (such as coaxial optical cable, optical fiber, or digital subscriber line) or a wireless manner (such as infrared, wireless, or microwave) from one website, computer, server, or data center to another website, computer, server, or data center. The computer-readable storage medium may be any available medium accessible by a device or a data storage device such as a server or a data center that integrates one or more available media. The available media may be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a Digital Video Disk (DVD)), or a semiconductor medium (such as a solid state disk).

[0311] Those skilled in the art can understand that all or some of the steps of the embodiments may be implemented by hardware or a program that instructs the relevant hardware. The program may be stored in a computer-readable storage medium. The storage medium may be a read-only memory, a magnetic disk, an optical disk, etc.

[0312] The foregoing description is only an embodiment of the present application and is not intended to limit the present application. Any modification, equivalent replacement, or improvement that does not depart from the principle of the present application shall be included within the protection scope of the present application.

Claims

1. A packet transfer method, which is applied to a network system, the network system includes a first customer premise equipment (CPE) and a second customer premise equipment (CPE), the method is executed by the first CPE, and the method is receiving a first packet and obtaining an initial destination address of the first packet; determining a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; determining a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performing outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation has been performed based on the second source address and the second destination address; and transferring the first packet on which the outer tunnel encapsulation has been performed. Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, at the first CPE, using a first underlying VRF corresponding to the first source address to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address. Packet transfer method.

2. The method is Receiving the second destination address transmitted by the root reflector (RR) and establishing the outer tunnel based on the second source address and the second destination address, wherein a routing domain of a port corresponding to the second destination address is the same as a routing domain of a port corresponding to the second source address; Receiving the first destination address transmitted by the RR and establishing the inner tunnel based on the first source address and the first destination address, wherein a routing domain of a port corresponding to the first destination address is the same as a routing domain of a port corresponding to the first source address; Generating, at the first CPE, routing information for the inner tunnel, the routing information including a correspondence between the first destination address and the second source address and the second destination address. The method according to claim 1 further includes this step.

3. The method includes: Receiving an overlay VRF configuration message transmitted by a controller and establishing a first overlay VRF and a second overlay VRF at the first CPE; Receiving an underlay VRF configuration message transmitted by the controller and establishing a first underlay VRF at the first CPE; Receiving a port association message transmitted by the controller and associating the second overlay VRF with the port corresponding to the first source address, and associating the first underlay VRF with the port corresponding to the second source address. The method according to claim 1 or 2 further includes this step.

4. Determining a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, the step of: By using the first overlay VRF, determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, the inner tunnel being an end-to-end tunnel between the first CPE and the second CPE, the step comprising: The method further comprises: By using the first overlay VRF, further comprising the step of transmitting the first packet on which the inner tunnel encapsulation is being performed to a second overlay VRF corresponding to the first source address; Determining a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performing outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is being performed based on the second source address and the second destination address, the step of: By using the second overlay VRF, determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and further comprising the step of performing outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is being performed based on the second source address and the second destination address; The method further comprises: By using the second overlay VRF, further comprising the step of transmitting the first packet on which the outer tunnel encapsulation is being performed to a first underlay VRF corresponding to the second source address; The step of forwarding the first packet for which the outer tunnel encapsulation is being performed comprises: The method according to claim 3, further comprising the step of forwarding the first packet for which the outer tunnel encapsulation is being performed by using the first underlay VRF.

5. The method comprises: receiving an overlay VRF configuration message sent by a controller, and establishing a first overlay VRF and a second overlay VRF at the first CPE; receiving an underlay VRF configuration message sent by the controller, and establishing a first underlay VRF and a second underlay VRF at the first CPE; The method according to claim 2, further comprising receiving a port association message sent by the controller, associating the second underlay VRF with the port corresponding to the first source address, and associating the first underlay VRF with the port corresponding to the second source address.

6. The step of determining a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, comprises: determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address by using the first overlay VRF, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE. The method comprises: By using the first overlay VRF, transmitting the first packet in which the inner tunnel encapsulation is performed to the second underlay VRF corresponding to the first source address; Further including: by using the second underlay VRF, transmitting the first packet in which the inner tunnel encapsulation is performed to the second overlay VRF that is in the first CPE and is connected to the second underlay VRF; Determining a second source address and a second destination address of an outer tunnel corresponding to the first destination address, and performing outer tunnel encapsulation on the first packet in which the inner tunnel encapsulation is performed based on the second source address and the second destination address, the step is: By using the second overlay VRF, determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and further including the step of performing outer tunnel encapsulation on the first packet in which the inner tunnel encapsulation is performed based on the second source address and the second destination address; The method is: Further including: by using the second overlay VRF, transmitting the first packet in which the outer tunnel encapsulation is performed to the first underlay VRF corresponding to the second source address; The step of transferring the first packet in which the outer tunnel encapsulation is performed is: The method according to claim 5, including the step of transferring the first packet in which the outer tunnel encapsulation is performed by using the first underlay VRF.

7. The method according to claim 5, wherein the second underlay VRF is connected to the second overlay VRF by using an outer loop.

8. The method according to claim 7, wherein the second underlay VRF is connected to the second overlay VRF through a corresponding physical port.

9. The method according to claim 5, wherein the second underlay VRF is connected to the second overlay VRF by using an inner loop.

10. The method according to claim 9, wherein the second underlay VRF is connected to the second overlay VRF through a corresponding loopback port.

11. The method further comprises: receiving a connection establishment message sent by the controller, the connection establishment message carrying an identifier of the second underlay VRF and an identifier of the second overlay VRF; establishing a connection between a loopback port corresponding to the second underlay VRF and a loopback port corresponding to the second overlay VRF. The method according to claim 10.

12. The method further comprises: receiving an overlay VRF configuration message sent by the controller to establish a first overlay VRF at the first CPE; receiving an underlay VRF configuration message sent by the controller to establish a first underlay VRF at the first CPE; receiving a port association message sent by the controller to associate the first underlay VRF with the port corresponding to the first source address and the second source address. The method according to claim 2.

13. Determining a first source address and a first destination address of an inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, the step of: Including the step of determining a first source address and a first destination address of the inner tunnel corresponding to the initial destination address by using the first overlay VRF, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address. The method is: Further including the step of transmitting, by using the first overlay VRF, the first packet on which the inner tunnel encapsulation is being performed to the first underlay VRF corresponding to the first source address. The step of forwarding the first packet on which the outer tunnel encapsulation is being performed is: The method according to claim 12, including the step of forwarding the first packet on which the outer tunnel encapsulation is being performed by using the first underlay VRF.

14. The step of determining a first source address and a first destination address of an inner tunnel corresponding to the initial destination address is: The method according to claim 1, including the step of determining an inner tunnel having the highest tunnel service quality among a plurality of inner tunnels corresponding to the initial destination address, and determining a first source address and a first destination address of the inner tunnel having the highest tunnel service quality.

15. A packet forwarding method, the method being applied to a network system, the network system including a first customer premise equipment (CPE), a gateway (GW), and a second CPE, the method being executed by the GW, and the method being: Receiving a first packet transmitted by the first CPE, wherein the first packet includes inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; Removing the outer tunnel encapsulation of the first packet; Transferring the first packet with the outer tunnel encapsulation removed based on a first destination address in the inner tunnel encapsulation of the first packet, wherein the first destination address is associated with the second CPE; Determining a second source address and a second destination address of an outer tunnel corresponding to the first destination address at the first CPE by using a first underlay VRF corresponding to a first source address, wherein the GW receives the first packet with the outer tunnel encapsulation executed based on the second source address and the second destination address from the first underlay VRF. A packet transfer method.

16. The step of transferring the first packet with the outer tunnel encapsulation removed based on a first destination address in the inner tunnel encapsulation of the first packet includes: Determining a third source address and a third destination address of an outer tunnel corresponding to the first destination address in the inner tunnel encapsulation of the first packet, and based on the third source address and the third destination address, performing further outer tunnel encapsulation on the first packet with the outer tunnel encapsulation removed; The method according to claim 15, further comprising the step of forwarding the first packet in which the further outer tunnel encapsulation is being performed. **Claim 17** The method comprises receiving, by the RR, the third destination address associated with the second CPE, and establishing the outer tunnel based on the third destination address and the third source address, wherein a routing domain of a port corresponding to the third source address is the same as a routing domain of a port corresponding to the third destination address; The method according to claim 16, further comprising the step of establishing a correspondence between the first destination address and the third source address and the third destination address of the outer tunnel. **Claim 18** A packet forwarding method, which is applied to a network system, the network system including a first customer premise equipment (CPE), a gateway (GW), and a second CPE, the method being executed by the second CPE, and the method comprising receiving a first packet, the first packet being from the first CPE, the first packet including inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel being an end-to-end tunnel between the first CPE and the second CPE; removing the outer tunnel encapsulation of the first packet; removing the inner tunnel encapsulation from the first packet in which the outer tunnel encapsulation has been removed, and forwarding the first packet in which the inner tunnel encapsulation has been removed. Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, at the first CPE, determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address by using a first underlay VRF corresponding to the first source address, wherein the GW receives the first packet for which the outer tunnel encapsulation is to be performed based on the second source address and the second destination address from the first underlay VRF, and the second CPE receives the first packet transmitted by the GW by using the first underlay VRF in the second CPE. A packet transfer method.

19. The step of receiving the first packet includes receiving the first packet by using a first underlay VRF in the second CPE, The step of removing the outer tunnel encapsulation of the first packet includes removing the outer tunnel encapsulation of the first packet by using the first underlay VRF, The method further includes transmitting the first packet with the outer tunnel encapsulation removed to a first overlay VRF in the second CPE by using the first underlay VRF, The step of removing the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transferring the first packet with the inner tunnel encapsulation removed includes removing the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transferring the first packet with the inner tunnel encapsulation removed by using the first overlay VRF. The method according to claim 18.

20. The step of receiving the first packet includes: receiving the first packet by using a first underlay VRF in the second CPE; The method further includes: transmitting the first packet to a second overlay VRF in the second CPE by using the first underlay VRF in the second CPE; The step of removing the outer tunnel encapsulation of the first packet includes: removing the outer tunnel encapsulation of the first packet by using the second overlay VRF; The method further includes: transmitting the first packet with the outer tunnel encapsulation removed to a first overlay VRF in the second CPE by using the second overlay VRF; The step of removing the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transferring the first packet with the inner tunnel encapsulation removed includes: The method according to claim 18, including removing the inner tunnel encapsulation from the first packet with the outer tunnel encapsulation removed and transferring the first packet with the inner tunnel encapsulation removed by using the first overlay VRF.

21. The step of transmitting the first packet with the outer tunnel encapsulation removed to a first overlay VRF by using the second overlay VRF includes: Removing the outer tunnel encapsulation of the first packet by using the second overlay VRF, and transmitting the first packet with the outer tunnel encapsulation removed to a second underlay VRF connected to the second overlay VRF; The method according to claim 20, further comprising transmitting the first packet with the outer tunnel encapsulation removed to the first overlay VRF by using the second underlay VRF. **Claim 22** The method according to claim 21, wherein the second underlay VRF is connected to the second overlay VRF by using an outer loop. **Claim 23** The method according to claim 22, wherein the second underlay VRF is connected to the second overlay VRF through a corresponding physical port. **Claim 24** The method according to claim 21, wherein the second underlay VRF is connected to the second overlay VRF by using an inner loop. **Claim 25** The method according to claim 24, wherein the second underlay VRF is connected to the second overlay VRF through a corresponding loopback port. **Claim 26** A CPE configuration method, which is applied to a network system, the network system includes a first customer premise equipment (CPE), a gateway (GW), a second CPE, and a route reflector (RR), the method is executed by the first CPE, and the method includes: Receiving a second destination address associated with the GW transmitted by the RR, and establishing an outer tunnel based on the second source address and the second destination address; Receiving the first destination address associated with the second CPE transmitted by the RR, and establishing an inner tunnel based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; Generating, at the first CPE, routing information for the inner tunnel, the routing information including a correspondence between the first destination address and the second source address and the second destination address; The method includes: Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and performing outer tunnel encapsulation on a first packet on which inner tunnel encapsulation is being performed, based on the second source address and the second destination address; Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, at the first CPE, using a first underlay VRF corresponding to the first source address to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address; CPE configuration method. Claim 27 The method includes: Receiving a first packet and obtaining an initial destination address of the first packet; Determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; The method according to claim 26, further comprising the step of forwarding the first packet for which the outer tunnel encapsulation is being performed. **Claim 28** The method comprises: receiving an overlay VRF configuration message sent by a controller to establish a first overlay VRF and a second overlay VRF in the first CPE; receiving an underlay VRF configuration message sent by the controller to establish a first underlay VRF in the first CPE; receiving a port association message sent by the controller, and associating the second overlay VRF with a port corresponding to the first source address, and associating the first underlay VRF with the port corresponding to the second source address, the method according to claim 26. **Claim 29** The method comprises: receiving a first packet to obtain an initial destination address of the first packet; step; determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address by using the first overlay VRF, and performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, the inner tunnel being an end-to-end tunnel between the first CPE and the second CPE, and sending the first packet for which the inner tunnel encapsulation is being performed to the second overlay VRF corresponding to the first source address; by using the second overlay VRF, for the first destination address; packet; end; sending the first packet for which the inner tunnel encapsulation is being performed to the second overlay VRF corresponding to the first source address; step; by using the second overlay VRF, for the first destination address; the second source address and the second destination address of the corresponding outer tunnel determine, and based on the second source address and the second destination address, perform outer tunnel encapsulation on the first packet on which inner tunnel encapsulation is being performed and send the first packet on which outer tunnel encapsulation is being performed to the first underlay VRF corresponding to the second source address step; further including the step of transferring the first packet on which outer tunnel encapsulation is being performed by using the first underlay VRF. The method according to claim 28

30. The method includes receiving an overlay VRF configuration message sent by a controller and establishing a first overlay VRF and a second overlay VRF at the first CPE, receiving an underlay VRF configuration message sent by the controller and establishing a first underlay VRF and a second underlay VRF at the first CPE, receiving a port association message sent by the controller, associating the second underlay VRF with the port corresponding to the first source address, and associating the first underlay VRF with the port corresponding to the second source address. The method according to claim 26

31. The method includes receiving a first packet and obtaining the initial destination address of the first packet, ​​​​By using the first overlay VRF, determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address, performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, where the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE, and transmitting the first packet on which the inner tunnel encapsulation is performed to the second underlay VRF corresponding to the first source address. By using the second underlay VRF, transmitting the first packet on which the inner tunnel encapsulation is performed to the second overlay VRF connected to the second underlay VRF at the first CPE. By using the second overlay VRF, determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address, performing outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation is performed based on the second source address and the second destination address, and transmitting the first packet on which the outer tunnel encapsulation is performed to the first underlay VRF corresponding to the second source address. The method according to claim 30, further comprising transmitting the first packet on which the outer tunnel encapsulation is performed by using the first underlay VRF.

32. The method includes Receiving an overlay VRF configuration message sent by a controller and establishing a first overlay VRF at the first CPE. Receiving an underlay VRF configuration message sent by the controller and establishing a first underlay VRF at the first CPE. Receiving a port association message sent by the controller and associating the first overlay VRF with a port corresponding to the first source address and a port corresponding to the second source address, the method according to claim 26 further comprising.

33. The method includes Receiving a first packet and obtaining an initial destination address of the first packet; Determining the first source address and the first destination address of the inner tunnel corresponding to the initial destination address by using the first overlay VRF, performing inner tunnel encapsulation on the first packet based on the first source address and the first destination address, and transmitting the first packet on which the inner tunnel encapsulation has been performed to the first underlay VRF corresponding to the first source address; Transferring the first packet on which the outer tunnel encapsulation has been performed, the method according to claim 32 further comprising.

34. A packet transfer device, the device being applied to a first CPE, and the device comprising A receiving module configured to receive a first packet and obtain an initial destination address of the first packet; An inner encapsulation module configured to determine a first source address and a first destination address of an inner tunnel corresponding to the initial destination address and perform inner tunnel encapsulation on the first packet based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and a second CPE; Determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and based on the second source address and the second destination address, perform outer tunnel encapsulation on the first packet on which the inner tunnel encapsulation has been performed, an outer encapsulation module configured as such; And a transfer module configured to transfer the first packet on which the outer tunnel encapsulation has been performed. Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, in the first CPE, using a first underlying VRF corresponding to the first source address to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address. A packet transfer device.

35. A packet transfer device, the device is applied to a GW, and the device A receiving module configured to receive a first packet sent by a first CPE, the first packet includes inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel is an end-to-end tunnel between the first CPE and a second CPE; An encapsulation removal module configured to remove the outer tunnel encapsulation of the first packet; A transfer module configured to transfer the first packet on which the outer tunnel encapsulation has been removed based on a first destination address in the inner tunnel encapsulation of the first packet, the first destination address being associated with the second CPE. Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, in the first CPE, using a first underlay VRF corresponding to the first source address to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and the GW receives the first packet for which the outer tunnel encapsulation is to be performed based on the second source address and the second destination address from the first underlay VRF. A packet transfer device.

36. A packet transfer device, the device being applicable to a second CPE, and the device A receiving module configured to receive a first packet, the first packet being from a first CPE, the first packet including inner tunnel encapsulation and outer tunnel encapsulation, and the inner tunnel being an end-to-end tunnel between the first CPE and the second CPE. A receiving module; A decapsulation module configured to remove the outer tunnel encapsulation of the first packet and to remove the inner tunnel encapsulation from the first packet from which the outer tunnel encapsulation has been removed; And a transfer module configured to transfer the first packet from which the inner tunnel encapsulation has been removed. Determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, in the first CPE, using a first underlay VRF corresponding to the first source address to determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address. The GW receives the first packet for which the outer tunnel encapsulation is to be performed based on the second source address and the second destination address from the first underlay VRF, and the second CPE receives the first packet transmitted by the GW by using the first underlay VRF in the second CPE. Packet transfer device.

37. A CPE configuration device, the device is applied to a first CPE, and the device A receiving module configured to receive a second destination address associated with a GW transmitted by an RR and establish an outer tunnel based on the second source address and the second destination address; A encapsulation module configured to receive a first destination address associated with a second CPE transmitted by the RR and establish an inner tunnel based on the first source address and the first destination address, wherein the inner tunnel is an end-to-end tunnel between the first CPE and the second CPE; A generation module configured to generate routing information of the inner tunnel in the first CPE, wherein the routing information includes a correspondence between the first destination address and the second source address and the second destination address; The device Determine the second source address and the second destination address of the outer tunnel corresponding to the first destination address, and further include performing outer tunnel encapsulation on a first packet on which inner tunnel encapsulation is being performed based on the second source address and the second destination address. The determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address includes, at the first CPE, determining the second source address and the second destination address of the outer tunnel corresponding to the first destination address by using a first underlay VRF corresponding to the first source address. CPE configuration device.

38. A first CPE, the first CPE includes a processor and a memory, the memory is configured to store instructions, and the processor is configured to execute the instructions to implement the method according to any one of claims 1 to 14 or 26 to 33. First CPE.

39. A GW, the GW includes a processor and a memory, the memory is configured to store instructions, and the processor is configured to execute the instructions to implement the method according to claims 15 to 17. GW.

40. A second CPE, the second CPE includes a processor and a memory, the memory is configured to store instructions, and the processor is configured to execute the instructions to implement the method according to claims 18 to 25. Second CPE.

41. A network system, the network system includes the first CPE according to claim 38, the GW according to claim 39, and the second CPE according to claim 40. Network system.

Citation Information

Patent Citations

  • Network system, router apparatus, node apparatus, and packet transfer method and program

    JP2004193878A

  • Network system and communication device

    JP2005260594A

  • System and method for performing network service insertion

    JP2017506025A

  • Creating a virtual network across multiple public clouds

    JP2020536403A

  • Tunnel-in-tunnel source address correction

    US20160359738A1