VPP-based double-layer-vxlan tunnel encapsulation method

By configuring dual-layer VXLAN in VPP network elements and adopting dual-bridge-domain forwarding, combined with vrf-0's three-layer interconnection, the same subnet second-layer access between cloud and cloud resources is achieved, and the problem of upper and lower-layer second-layer interconnection in the existing technology that cannot be achieved through layer three-layer routing is solved, and a more flexible and extensive VXLAN tunnel packaging effect is achieved.

WO2025124472A1PCT designated stage expired Publication Date: 2025-06-19CHINA TELECOM CLOUD TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/138783
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-12
Filing Date
2024-12-12
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

In a cloud computing environment, it is impossible to achieve layer two interconnection on the cloud and layer two interconnection on the cloud and the same subnet access to the IDC resources on the cloud and the two-layer VXLAN tunnels need to be encapsulated and decapsulated.

Method used

The VPP-based dual-layer VXLAN tunnel packaging method is adopted. By configuring a dual-layer VXLAN in the VPP network element, dual bridge-domain forwarding, and interconnecting it in three layers through vrf-0, packet packaging and de-encapsulation of the inner and outer VXLANs is realized.

Benefits of technology

It realizes layer 2 inter-visit access to the same subnet resources on and off the cloud, expands the flexibility of VXLAN tunnel packaging, is suitable for a wider range of special scenarios, and supports VXLAN tunnel packaging of any layer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024138783_19062025_PF_FP_ABST
    Figure CN2024138783_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application involves a VPP-based double-layer-VXLAN tunnel encapsulation method, comprising: configuring double-layer VXLANs in a VPP network element; in layer 2, using double bridge-domains to perform forwarding; in layer 3, interconnecting the double bridge-domains by means of VRF-0; in bridge-domain-1, an inner-layer VXLAN performing message encapsulation and decapsulation; and in bridge-domain-2, an outer-layer VXLAN performing message encapsulation and decapsulation. Therefore, the purpose of mutual access between cloud resources and on-premises resources in the same subnet layer 2 is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

A double-layer VXLAN tunnel encapsulation method based on VPP

[0001] This application claims priority to Chinese patent application number CN202311703084.0, filed on December 12, 2023, entitled “A dual-layer VXLAN tunnel encapsulation method based on VPP”, the entire text of which is hereby incorporated by reference. Technical Field

[0002] The present application relates to the field of cloud computing and cloud network technology, and in particular to a double-layer VXLAN tunnel encapsulation method based on VPP. Background Art

[0003] VPP is a high-performance packet processing framework. As a representative of high-performance forwarding for general-purpose processors, it is widely used in network forwarding elements. It is commonly used to build network devices and functions, enabling highly flexible packet processing in Software-Defined Networking (SDN) and Network Function Virtualization (NFV) environments. Bridge-domain manages Layer 2 forwarding, allowing communication between different Layer 2 domains. Loopback is commonly used to implement virtual interfaces. VXLAN is used to create logical tunnels on the underlying network to connect virtual networks. VRF is used to implement Layer 3 forwarding, allowing multiple virtual routing tables to be created on the same physical device. In cloud networks, VPP is commonly used using bridge-domain / loopback / vxlan for Layer 2 forwarding and loopback / vrf for Layer 3 forwarding. Typical application scenarios involve single-layer VXLAN decapsulation of overlay packets, route lookup, and then single-layer VXLAN encapsulation.

[0004] However, in some special scenarios, such as Layer 2 interconnection between on-premises and off-premises clouds, and mutual access between on-premises and IDC resources in the same subnet, Layer 3 routing cannot be used. Therefore, VPP network elements are required to encapsulate / decapsulate packets through double-layer VXLAN tunnels to achieve Layer 2 mutual access between on-premises and off-premises resources in the same subnet. Summary of the Invention

[0005] This application aims to solve, at least to some extent, one of the technical problems in the related art. To this end, one purpose of this application is to propose a dual-layer VXLAN tunnel encapsulation method based on VPP, which achieves the purpose of Layer 2 mutual access between on-cloud and off-cloud resources in the same subnet by performing double-layer VXLAN encapsulation on overlay messages.

[0006] One aspect of the present application provides a dual-layer VXLAN tunnel encapsulation method based on VPP, including:

[0007] Configure dual-layer vxlan in vpp network elements;

[0008] Dual bridge-domain forwarding is used at Layer 2;

[0009] Use vrf-0 to interconnect the two bridge-domains at Layer 3.

[0010] Implement inner vxlan packet encapsulation and decapsulation on bridge-domain-1;

[0011] Implement outer vxlan packet encapsulation and decapsulation in bridge-domain-2;

[0012] Configuring two-layer VXLAN in a VPP network element means: in the initialization phase of the network device, configuring bridge-domain-1 to process the encapsulation and decapsulation of the inner VXLAN, configuring bridge-domain-2 to process the encapsulation and decapsulation of the outer VXLAN, configuring vrf-0 for the three-layer interconnection between bridge-domain-1 and bridge-domain-2, and configuring routing to define routes in vrf-0;

[0013] The specific method for configuring a double-layer vxlan in a vpp network element is:

[0014] The specific process of configuring bridge-domain-1 is as follows:

[0015] Create bridge-domain-1 to handle packet encapsulation and decapsulation of the inner vxlan tunnel;

[0016] Create a VXLAN tunnel and encapsulate the inner VXLAN packet from the source IP address 10.10.10.1 to the destination IP address 20.20.20.1. The VXLAN network identifier is 1 and the instance is 0.

[0017] Create a loopback interface as the interface instance of the inner vxlan tunnel;

[0018] Create a second VXLAN tunnel for Layer 3 interconnection of the inner VXLAN tunnel. The inner VXLAN tunnel encapsulates VXLAN packets from the source IP address 192.168.1.1 to the destination IP address 172.16.0.1. The VXLAN network identifier is 100 and the instance is 1.

[0019] Add interface l2 to bridge-domain-1 and associate it with vxlan tunnel instance 1;

[0020] Add interface l2 to bridge-domain-1 and associate it with loopback interface instance 1 to use it as a virtual bridge interface.

[0021] Add interface l2 to bridge-domain-1 and associate it with the second vxlan tunnel instance 2;

[0022] The specific process of configuring bridge-domain-2 is as follows:

[0023] Create bridge-domain-2 to handle packet encapsulation and decapsulation of the outer vxlan tunnel;

[0024] Create a second VXLAN tunnel to encapsulate the outer VXLAN packet from the source IP address 10.10.10.1 to the destination IP address 30.30.30.1. The VXLAN network identifier is 2 and the instance is 2.

[0025] Create a second loopback interface as the interface instance of the outer VXLAN tunnel;

[0026] Add interface l2 to bridge-domain-2 and associate it with vxlan tunnel instance 2;

[0027] Add interface l2 to bridge-domain-2 and associate it with the second loopback interface instance 2 to use as a bridge virtual interface.

[0028] The specific process of configuring vrf-0 is as follows: add a vrf route and forward the message with the destination address 172.16.0.1 / 32 to loop2 through the next hop address 192.168.1.254;

[0029] When configuring a double-layer vxlan in the vpp network element, if there is overlay mac information of the opposite end, the second-layer forwarding table and the third-layer arp table of the bridge-domain are configured as static;

[0030] Configuring the bridge-domain's Layer 2 forwarding table and Layer 3 ARP table to be static can reduce Layer 2 flooding.

[0031] When configuring a double-layer vxlan in a vpp network element, n double-layer vxlan instances are configured on one vpp by specifying a vxlan tunnel output vrf, thereby enabling n users to share one vpp;

[0032] The two-layer vxlan instance includes: two bridge-domains and one vrf;

[0033] The realization of n users sharing a vpp means: configuring n double-layer vxlan instances on a vpp, and each user will be configured with an independent double-layer vxlan instance, so that network isolation between different users can be achieved, thereby achieving network isolation of n users on a vpp;

[0034] The specific process of message encapsulation is as follows:

[0035] Step S100: The single-layer vxlan tunnel encapsulated message on the cloud enters the vpp network element, is decapsulated in bridge-domain-1, and obtains the overlay message;

[0036] Step S200: The overlay message is forwarded at Layer 2 in bridge-domain-1. The overlay message is encapsulated with the inner vxlan-tunnel-1 tunnel information to obtain a vxlan tunnel message.

[0037] The overlay message is forwarded at Layer 2 in bridge-domain-1 as forwarding or unknown unicast flood;

[0038] Step S300: The vxlan tunnel message finds the next-hop interface of vrf-0 through routing as loop-back-2, and the vxlan tunnel message enters bridge-domain-2;

[0039] Step S400: The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-2, encapsulating the vxlan-tunnel-2 tunnel information.

[0040] The layer 2 forwarding is forwarding or unknown unicast flood;

[0041] The specific process of message decapsulation is as follows:

[0042] Step R100: The return message from the cloud enters the vpp;

[0043] Step R200: The return message is decapsulated in bridge-domain-2 to obtain the vxlan tunnel message of vxlan-tunnel-2. The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-2.

[0044] Step R300: The vxlan tunnel message performs a route lookup through vrf-0, and the next-hop outbound interface is loop-back-1;

[0045] Step R400: The vxlan tunnel message enters bridge-domain-1;

[0046] Step R500: The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-1. During the Layer 2 forwarding process, the tunnel information of the inner layer vxlan-tunnel-1 is decapsulated.

[0047] One aspect of the present application provides a VPP-based double-layer VXLAN tunnel encapsulation system, including:

[0048] vxlan configuration module, used to configure double-layer vxlan in vpp network elements;

[0049] Layer 2 forwarding module, used for dual-bridge-domain forwarding at Layer 2;

[0050] The Layer 3 interconnection module is used to interconnect two bridge-domains at Layer 3 through vrf-0.

[0051] The inner packet processing module is used to implement inner VXLAN packet encapsulation and decapsulation in bridge-domain-1;

[0052] The outer packet processing module is used to implement outer VXLAN packet encapsulation and decapsulation in bridge-domain-2.

[0053] One aspect of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the steps in a VPP-based double-layer VXLAN tunnel encapsulation method are implemented.

[0054] One aspect of the present application provides a readable storage medium storing a computer program, wherein the computer program is suitable for loading by a processor to execute steps in a VPP-based double-layer VXLAN tunnel encapsulation method.

[0055] The VPP-based dual-layer VXLAN tunnel encapsulation method proposed in this application has the following advantages over existing technologies:

[0056] VPP's dual-layer VXLAN encapsulation and decapsulation features flexible configuration and two-layer L2FIB self-learning capabilities, making it applicable to a wider range of special scenarios. The VPP-based dual-layer VXLAN tunnel encapsulation method can be extended to any number of VXLAN tunnel encapsulation layers. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] FIG1 is a diagram showing a scenario of Layer 2 interconnection between an IDC and the same subnet on the cloud, using a VPP-based double-layer VXLAN tunnel encapsulation method of the present application;

[0058] FIG2 is a schematic diagram of a double-layer VXLAN encapsulation and decapsulation solution implementation of a double-layer VXLAN tunnel encapsulation method based on VPP of the present application;

[0059] FIG3 is a VPP double-layer VXLAN configuration diagram of a double-layer VXLAN tunnel encapsulation method based on VPP of the present application;

[0060] FIG4 is a message processing flow chart of a double-layer VXLAN tunnel encapsulation method based on VPP of the present application;

[0061] FIG5 is a schematic structural diagram of an electronic device provided by the present application;

[0062] FIG6 is a schematic diagram of the structure of a readable storage medium provided by this application. DETAILED DESCRIPTION

[0063] For a better understanding of the present application, various aspects of the present application will be described in more detail with reference to the accompanying drawings. It should be understood that these detailed descriptions are merely descriptions of exemplary embodiments of the present application and are not intended to limit the scope of the present application in any way. Throughout the specification, the same reference numerals refer to the same elements. The expression "and / or" includes any and all combinations of one or more of the associated listed items.

[0064] In the accompanying drawings, the size, dimensions, and shapes of the elements have been slightly adjusted for ease of illustration. The accompanying drawings are for illustration only and are not drawn strictly to scale. As used herein, the terms "substantially," "approximately," and similar terms are used to indicate approximations, not degrees, and are intended to illustrate inherent deviations in measurements or calculations that would be recognized by a person of ordinary skill in the art. In addition, in this application, the order in which the steps are described does not necessarily represent the order in which these steps would occur in actual operation, unless otherwise specified or inferred from the context.

[0065] It should also be understood that expressions such as "comprises," "including," "having," "includes," and / or "comprising" are open rather than closed expressions in this specification, indicating the presence of the stated features, elements, and / or components, but do not exclude the presence of one or more other features, elements, components, and / or combinations thereof. In addition, when expressions such as "at least one of..." appear after a list of listed features, they modify the entire list of features rather than just the individual elements in the list. In addition, when describing embodiments of the present application, "may" is used to mean "one or more embodiments of the present application." And, the term "exemplary" is intended to refer to an example or illustration.

[0066] Unless otherwise defined, all words used herein (including engineering terms and scientific and technological terms) have the same meaning as commonly understood by those skilled in the art to which this application belongs. It should also be understood that, unless otherwise specified in this application, words defined in commonly used dictionaries should be interpreted as having the same meaning as they do in the context of the relevant technology, and should not be interpreted in an idealized or overly formal sense.

[0067] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0068] Example 1

[0069] As shown in Figure 1, this application provides a scenario diagram of a two-layer VXLAN tunnel encapsulation method based on VPP for Layer 2 interconnection between an IDC and the same subnet on the cloud. The scenario is a two-layer interconnection between the cloud and the cloud, and mutual access between the cloud and the IDC resources in the same subnet. The double-layer VXLAN, the inner layer is Layer 2 forwarding, and the outer layer is Layer 3 routing forwarding. The double-layer VXLAN tunnel encapsulation method based on VPP solves the problem of double-layer VXLAN tunnel encapsulation and decapsulation in this scenario.

[0070] As shown in FIG2 , a schematic diagram of a double-layer VXLAN encapsulation and decapsulation solution for a double-layer VXLAN tunnel encapsulation method based on VPP described in this application is shown, including:

[0071] Configure dual-layer vxlan in vpp network elements;

[0072] Dual bridge-domain forwarding is used at Layer 2;

[0073] Use vrf-0 to interconnect the two bridge-domains at Layer 3.

[0074] Implement inner vxlan packet encapsulation and decapsulation on bridge-domain-1;

[0075] Implement outer vxlan packet encapsulation and decapsulation in bridge-domain-2;

[0076] The vrf-0 is used to interconnect two Bridge-Domains at Layer 3.

[0077] The bridge-domain-1 refers to the bridge-domain that processes the message encapsulation and decapsulation of the inner vxlan tunnel, and the bridge-domain-2 refers to the bridge-domain that processes the message encapsulation and decapsulation of the outer vxlan tunnel;

[0078] As shown in Figure 3, this is a vpp double-layer vxlan configuration diagram of a double-layer VXLAN tunnel encapsulation method based on VPP of the present application. The double-layer vxlan in the vpp network element is configured according to the configuration method shown in Figure 3;

[0079] Configuring two-layer VXLAN in a VPP network element means: in the initialization phase of the network device, configuring bridge-domain-1 to process the encapsulation and decapsulation of the inner VXLAN, configuring bridge-domain-2 to process the encapsulation and decapsulation of the outer VXLAN, configuring vrf-0 for the three-layer interconnection between bridge-domain-1 and bridge-domain-2, and configuring routing to define routes in vrf-0;

[0080] The specific method for configuring a double-layer vxlan in a vpp network element is:

[0081] The specific process of configuring bridge-domain-1 is as follows:

[0082] Create bridge-domain-1 to handle packet encapsulation and decapsulation of the inner vxlan tunnel;

[0083] Create a VXLAN tunnel and encapsulate the inner VXLAN packet from the source IP address 10.10.10.1 to the destination IP address 20.20.20.1. The VXLAN network identifier is 1 and the instance is 0.

[0084] Create a loopback interface as the interface instance of the inner vxlan tunnel;

[0085] Create a second VXLAN tunnel for Layer 3 interconnection of the inner VXLAN tunnel. The inner VXLAN tunnel encapsulates VXLAN packets from the source IP address 192.168.1.1 to the destination IP address 172.16.0.1. The VXLAN network identifier is 100 and the instance is 1.

[0086] Add interface l2 to bridge-domain-1 and associate it with vxlan tunnel instance 1;

[0087] Add interface l2 to bridge-domain-1 and associate it with loopback interface instance 1 to use it as a virtual bridge interface.

[0088] Add interface l2 to bridge-domain-1 and associate it with the second vxlan tunnel instance 2;

[0089] The specific process of configuring bridge-domain-2 is as follows:

[0090] Create bridge-domain-2 to handle packet encapsulation and decapsulation of the outer vxlan tunnel;

[0091] Create a second VXLAN tunnel to encapsulate the outer VXLAN packet from the source IP address 10.10.10.1 to the destination IP address 30.30.30.1. The VXLAN network identifier is 2 and the instance is 2.

[0092] Create a second loopback interface as the interface instance of the outer VXLAN tunnel;

[0093] Add interface l2 to bridge-domain-2 and associate it with vxlan tunnel instance 2;

[0094] Add interface l2 to bridge-domain-2 and associate it with the second loopback interface instance 2 to use as a bridge virtual interface.

[0095] The specific process of configuring vrf-0 is as follows: add a vrf route and forward the message with the destination address 172.16.0.1 / 32 to loop2 through the next hop address 192.168.1.254;

[0096] When configuring a double-layer vxlan in the vpp network element, if there is overlay mac information of the opposite end, the second-layer forwarding table and the third-layer arp table of the bridge-domain are configured as static;

[0097] Configuring the bridge-domain's Layer 2 forwarding table and Layer 3 ARP table to be static can reduce Layer 2 flooding.

[0098] The bridge-domain's layer 2 forwarding table is used to record MAC addresses and associated interface information;

[0099] The three-layer arp table is used to map IP addresses to MAC addresses;

[0100] When configuring a double-layer vxlan in a vpp network element, n double-layer vxlan instances are configured on one vpp by specifying a vxlan tunnel output vrf, thereby enabling n users to share one vpp;

[0101] Configuring n double-layer VXLAN instances on a VPP means using two layers of VXLAN tunnels in the network to achieve virtual network connections in a cloud environment.

[0102] The two-layer vxlan instance includes: two bridge-domains and one vrf;

[0103] The two bridge-domains are used to process Layer 2 forwarding of messages, and the one vrf is used to forward messages from one bridge-domain to another bridge-domain;

[0104] The realization of n users sharing a vpp means: configuring n double-layer vxlan instances on a vpp, and each user will be configured with an independent double-layer vxlan instance, so that network isolation between different users can be achieved, thereby achieving network isolation of n users on a vpp;

[0105] As shown in Figure 4, this is a message processing flow chart of a dual-layer VXLAN tunnel encapsulation method based on VPP in this application. The specific process of implementing message encapsulation and decapsulation of the inner layer VXLAN in bridge-domain-1 is as follows:

[0106] Step S100: The single-layer vxlan tunnel encapsulated message on the cloud enters the vpp network element, is decapsulated in bridge-domain-1, and obtains the overlay message;

[0107] Step S200: The overlay message is forwarded at Layer 2 in bridge-domain-1. The overlay message is encapsulated with the inner vxlan-tunnel-1 tunnel information to obtain a vxlan tunnel message.

[0108] The overlay message is forwarded at Layer 2 in bridge-domain-1 as forwarding or unknown unicast flood;

[0109] Step S300: The vxlan tunnel message finds the next-hop interface of vrf-0 through routing as loop-back-2, and the vxlan tunnel message enters bridge-domain-2;

[0110] Step S400: The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-2, encapsulating the vxlan-tunnel-2 tunnel information.

[0111] The layer 2 forwarding is forwarding or unknown unicast flood;

[0112] The specific process of implementing outer vxlan message encapsulation and decapsulation in bridge-domain-2 is as follows:

[0113] Step R100: The return message from the cloud enters the vpp;

[0114] Step R200: The return message is decapsulated in bridge-domain-2 to obtain the vxlan tunnel message of vxlan-tunnel-2. The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-2.

[0115] Step R300: The vxlan tunnel message performs a route lookup through vrf-0, and the next-hop outbound interface is loop-back-1;

[0116] Step R400: The vxlan tunnel message enters bridge-domain-1;

[0117] Step R500: The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-1. During the Layer 2 forwarding process, the tunnel information of the inner layer vxlan-tunnel-1 is decapsulated.

[0118] Example 2

[0119] This application provides a double-layer VXLAN tunnel encapsulation method based on VPP, which can be applied to the tenant gateway on the cloud. The inner-layer VXLAN encapsulation message is carried on the existing three-layer network resources such as dedicated line / VPN, achieving the effect of double-layer VXLAN tunnel encapsulation, thereby realizing the second-layer interconnection of on-cloud and off-cloud resources, and relaxing the requirement that on-cloud and off-cloud access must be in different subnet CIDRs.

[0120] Example 3

[0121] This application proposes a dual-layer VXLAN tunnel encapsulation system based on VPP, including:

[0122] vxlan configuration module, used to configure double-layer vxlan in vpp network elements;

[0123] Layer 2 forwarding module, used for dual-bridge-domain forwarding at Layer 2;

[0124] The Layer 3 interconnection module is used to interconnect two bridge-domains at Layer 3 through vrf-0.

[0125] The inner packet processing module is used to implement inner VXLAN packet encapsulation and decapsulation in bridge-domain-1;

[0126] The outer packet processing module is used to implement outer VXLAN packet encapsulation and decapsulation in bridge-domain-2.

[0127] Example 4

[0128] Figure 5 is a schematic diagram of the structure of an electronic device provided by one embodiment of the present application. As shown in Figure 5, according to another aspect of the present application, an electronic device is also provided. The electronic device may include one or more processors and one or more memories. The memories store computer-readable code, which, when executed by one or more processors, can execute the above-described VPP-based double-layer VXLAN tunnel encapsulation method.

[0129] The method or system according to the embodiment of the present application can also be implemented with the help of the architecture of the electronic device shown in Figure 5. As shown in Figure 5, the electronic device may include a bus, one or more CPUs, a read-only memory (ROM), a random access memory (RAM), a communication port connected to the network, an input / output component, a hard disk, etc. The storage device in the electronic device, such as a ROM or a hard disk, can store a double-layer VXLAN tunnel encapsulation method based on VPP provided in this application. A double-layer VXLAN tunnel encapsulation method based on VPP may, for example, include: configuring a double-layer VXLAN in a VPP network element; using double bridge-domain forwarding at the second layer; interconnecting the double bridge-domain at the third layer through vrf-0; implementing the inner layer VXLAN to perform message encapsulation and decapsulation at bridge-domain-1; and implementing the outer layer VXLAN to perform message encapsulation and decapsulation at bridge-domain-2. Furthermore, the electronic device may also include a user interface. Of course, the architecture shown in Figure 5 is only exemplary. When implementing different devices, one or more components in the electronic device shown in Figure 5 can be omitted according to actual needs.

[0130] Example 5

[0131] FIG6 is a schematic diagram of the structure of a readable storage medium provided by an embodiment of the present application. As shown in FIG6 , a readable storage medium according to an embodiment of the present application is shown. Computer-readable instructions are stored on the computer-readable storage medium. When the computer-readable instructions are executed by the processor, a dual-layer VXLAN tunnel encapsulation method based on VPP according to an embodiment of the present application described with reference to the above figures can be executed. The storage medium includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and cache memory. Non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.

[0132] In addition, according to the implementation manner of the present application, the process described with reference to the flowchart above can be implemented as a computer software program. For example, the present application provides a non-transitory machine-readable storage medium, which stores machine-readable instructions, and the machine-readable instructions can be run by a processor to execute instructions corresponding to the method steps provided in the present application, for example: configuring a double-layer vxlan in a vpp network element; using double bridge-domain forwarding at the second layer; interconnecting the double bridge-domain at the third layer through vrf-0; implementing message encapsulation and decapsulation of the inner layer vxlan at bridge-domain-1; and implementing message encapsulation and decapsulation of the outer layer vxlan at bridge-domain-2. When the computer program is executed by a central processing unit (CPU), the above functions defined in the method of the present application are executed.

[0133] The methods, apparatuses, and devices of the present application may be implemented in many ways. For example, the methods, apparatuses, and devices of the present application may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is for illustration only, and the steps of the method of the present application are not limited to the order specifically described above unless otherwise specified. In addition, in some embodiments, the present application may also be implemented as programs recorded in a recording medium, which include machine-readable instructions for implementing the methods according to the present application. Therefore, the present application also covers recording media that store programs for executing the methods according to the present application.

[0134] In addition, the parts of the above technical solutions provided in the embodiments of the present application that are consistent with the implementation principles of the corresponding technical solutions in the prior art are not described in detail to avoid excessive redundancy.

[0135] The above-described specific embodiments further illustrate the purpose, technical solutions, and beneficial effects of this application. It should be understood that the above description is merely a specific embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this application shall be included within the scope of protection of this application.

Claims

1. A double-layer VXLAN tunnel encapsulation method based on VPP, characterized in that: include: Configure double-layer vxlan in the vpp network element; use double bridge-domain forwarding at the second layer; interconnect the double bridge-domain at the third layer through vrf-0; implement message encapsulation and decapsulation of the inner vxlan at bridge-domain-1; implement message encapsulation and decapsulation of the outer vxlan at bridge-domain-2.

2. A double-layer VXLAN tunnel encapsulation method based on VPP as claimed in claim 1, characterized in that: The configuration of two-layer vxlan in the vpp network element refers to: in the initialization phase of the network device, configuring bridge-domain-1 to process the encapsulation and decapsulation of the inner vxlan, configuring bridge-domain-2 to process the encapsulation and decapsulation of the outer vxlan, configuring vrf-0 for the three-layer interconnection between bridge-domain-1 and bridge-domain-2, and configuring routing to define the routes in vrf-0.

3. A double-layer VXLAN tunnel encapsulation method based on VPP as claimed in claim 2, characterized in that: When configuring the double-layer vxlan in the vpp network element, if there is overlay mac information of the other end, the second-layer forwarding table and the third-layer arp table of the bridge-domain are configured as static.

4. A double-layer VXLAN tunnel encapsulation method based on VPP as claimed in claim 3, characterized in that: When configuring a double-layer vxlan in a vpp network element, n double-layer vxlan instances are configured on one vpp by specifying the vxlan tunnel output vrf, so that n users can share one vpp.

5. A double-layer VXLAN tunnel encapsulation method based on VPP as claimed in claim 4, characterized in that: The two-layer vxlan instance includes: two bridge-domains and one vrf.

6. A double-layer VXLAN tunnel encapsulation method based on VPP as claimed in claim 5, characterized in that: The specific process of message encapsulation is as follows: the single-layer vxlan tunnel encapsulated message on the cloud enters the vpp network element, is decapsulated in bridge-domain-1, and an overlay message is obtained; the overlay message is forwarded at the second layer in bridge-domain-1, and the overlay message encapsulates the inner layer vxlan-tunnel-1 tunnel information to obtain a vxlan tunnel message; The vxlan tunnel message finds the next-hop interface of loop-back-2 through routing in vrf-0, and enters bridge-domain-2. The vxlan tunnel message is forwarded at Layer 2 in bridge-domain-2 and encapsulates the vxlan-tunnel-2 tunnel information.

7. A double-layer VXLAN tunnel encapsulation method based on VPP as claimed in claim 6, characterized in that: The specific process of decapsulation of the message is as follows: the return message under the cloud enters the vpp; the return message is decapsulated in bridge-domain-2 to obtain the vxlan tunnel message of vxlan-tunnel-2, and the vxlan tunnel message is forwarded at the second layer in bridge-domain-2; the vxlan tunnel message is routed through vrf-0, and the next hop out interface is loop-back-1; The vxlan tunnel message enters bridge-domain-1; the vxlan tunnel message is forwarded at Layer 2 in bridge-domain-1. During the Layer 2 forwarding process, the tunnel information of the inner layer vxlan-tunnel-1 is decapsulated.

8. A double-layer VXLAN tunnel encapsulation system based on VPP, characterized in that: include: The vxlan configuration module is used to configure double-layer vxlan in the vpp network element; the layer 2 forwarding module is used to adopt double bridge-domain forwarding at the second layer; The three-layer interconnection module is used to interconnect the two bridge-domains at the three-layer through vrf-0; the inner-layer message processing module is used to implement the inner-layer vxlan message encapsulation and decapsulation in bridge-domain-1; the outer-layer message processing module is used to implement the outer-layer vxlan message encapsulation and decapsulation in bridge-domain-2.

9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the steps in the VPP-based double-layer VXLAN tunnel encapsulation method as described in any one of claims 1 to 7 are implemented.

10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and the computer program is suitable for being loaded by a processor to execute the steps in a VPP-based double-layer VXLAN tunnel encapsulation method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Message forwarding method and device, equipment and medium

    CN115442366A

  • Message processing method, device and equipment and machine readable storage medium

    CN116418632A

  • Cloud network system and interaction method of cloud network system

    CN116996343A

  • Double-layer VXLAN tunnel packaging method based on VPP

    CN117896207A

  • Communication method for hybrid cloud environment, gateway, and management method and apparatus

    WO2021043314A1