Method, device and system for routing data between network segments
Abstract
FIELD: physics, computer engineering. SUBSTANCE: group of inventions relates to a method of redirecting an Internet protocol (IP) packet in a network element and a network element for redirecting an IP packet through Ethernet segments. A network element comprises a virtual router, which connects at least two level 2 network segments to allow data transmission in between, wherein each level 2 network segment is connected to a corresponding I-SID value, wherein each network element is configured to receive, from the level 2 network segment, an Ethernet frame in which an IP packet is encapsulated, wherein the IP packet contains the IP address of the recipient, and the Ethernet frame contains the I-SID and MAC address of the recipient associated with the virtual router, and when the MAC address of the recipient in the received Ethernet frame is associated with the virtual router, perform at least one routing data stream processing in the encapsulated IP packet, wherein said routing data stream processing includes identification of the level 2 network segment associated with the IP address of the recipient in the IP packet, and direct the IP packet to the identified level 2 network segment in the Ethernet frame with the I-SID associated with the identified level 2 network segment. EFFECT: optimising data routing in a network. 12 cl, 3 dwg
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
12 claims: 12 independent, 0 dependent
- 1A method for packet forwarding an Internet Protocol (IP-packet) in a network element comprising a virtual router connects at least two segments layer network 2 to transmit data therebetween, each segment of the network level 2 is associated with a corresponding service identifier value (I-SID), and comprising:receiving a segment of the network Layer 2 Ethernet network of the sender of the frame, in which IP-encapsulated packet, wherein the Ethernet frame comprises an identifier I-SID and address at least the Medium Access Control (MAC) address of the recipient;andapplication data flow routing where the MAC address of the destination in the received frame, the Ethernet network associated with the virtual router, and routing the data flow comprises:identifying Layer 2 network segment associated with the IP-destination address in the IP-packet;andtransmitting IP-packet to the identified network segment Layer 2 Ethernet network in the frame, comprising an identifier value I-SID, associated with the identified network segment 2 level. 1. Способ переадресации пакета по Интернет-протоколу (IP-пакета) в сетевом элементе, содержащем виртуальный маршрутизатор, соединяющий по меньшей мере два сегмента сети уровня 2 с возможностью передачи данных между ними, причем каждый сегмент сети уровня 2 связан с соответствующей величиной идентификатора сервисов (I-SID), и включающий:прием из сегмента сети уровня 2 отправителя кадра сети Ethernet, в который инкапсулирован IP-пакет, причем кадр сети Ethernet содержит идентификатор I-SID и по меньшей мере адрес управления доступом к среде (МАС-адрес) получателя;иприменение обработки потока данных маршрутизации, когда МАС-адрес получателя в полученном кадре сети Ethernet связан с виртуальным маршрутизатором, причем обработка потока данных маршрутизации включает:идентификацию сегмента сети уровня 2, связанного с IP-адресом получателя в IP-пакете;ипередачу IP-пакета в идентифицированный сегмент сети уровня 2 в кадре сети Ethernet, содержащем величину идентификатора I-SID, связанного с идентифицированным сегментом сети уровня 2. 1. Способ переадресации пакета по Интернет-протоколу (IP-пакета) в сетевом элементе, содержащем виртуальный маршрутизатор, соединяющий по меньшей мере два сегмента сети уровня 2 с возможностью передачи данных между ними, причем каждый сегмент сети уровня 2 связан с соответствующей величиной идентификатора сервисов (I-SID), и включающий:прием из сегмента сети уровня 2 отправителя кадра сети Ethernet, в который инкапсулирован IP-пакет, причем кадр сети Ethernet содержит идентификатор I-SID и по меньшей мере адрес управления доступом к среде (МАС-адрес) получателя;иприменение обработки потока данных маршрутизации, когда МАС-адрес получателя в полученном кадре сети Ethernet связан с виртуальным маршрутизатором, причем обработка потока данных маршрутизации включает:идентификацию сегмента сети уровня 2, связанного с IP-адресом получателя в IP-пакете;ипередачу IP-пакета в идентифицированный сегмент сети уровня 2 в кадре сети Ethernet, содержащем величину идентификатора I-SID, связанного с идентифицированным сегментом сети уровня 2.
- 2The method of claim. 1, wherein the application data flow routing implementation also includes the data flow on at least one of the levels 4-7 seven-layer Open System Interconnection (OSI). 2. Способ по п. 1, в котором применение обработки потока данных маршрутизации включает также осуществление обработки потока данных по меньшей мере на одном из уровней 4-7 семиуровневой модели взаимодействия открытых систем (OSI). 2. Способ по п. 1, в котором применение обработки потока данных маршрутизации включает также осуществление обработки потока данных по меньшей мере на одном из уровней 4-7 семиуровневой модели взаимодействия открытых систем (OSI).
- 3The method of claim. 2, in which the implementation of the data flow on at least one of the layers 4-7 comprises processing for network security, and / or measurement of the network traffic, and / or detecting unauthorized network entry. 3. Способ по п. 2, в котором осуществление обработки потока данных по меньшей мере на одном из уровней 4-7 включает обработку для сетевой защиты, и/или измерение сетевого трафика, и/или обнаружение несанкционированного входа в сеть. 3. Способ по п. 2, в котором осуществление обработки потока данных по меньшей мере на одном из уровней 4-7 включает обработку для сетевой защиты, и/или измерение сетевого трафика, и/или обнаружение несанкционированного входа в сеть.
- 4The method of claim. 1, wherein the data flow routing protocol is address resolution (ARP), and / or routing information protocol (RIP), and / or selecting a shortest path first (OSPF), and / or protocol border routing (BGP). 4. Способ по п. 1, в котором при обработке потока данных маршрутизации используется протокол определения адресов (ARP), и/или протокол информации маршрутизации (RIP), и/или выбор в первую очередь кратчайшего пути (OSPF), и/или протокол пограничной маршрутизации (BGP). 4. Способ по п. 1, в котором при обработке потока данных маршрутизации используется протокол определения адресов (ARP), и/или протокол информации маршрутизации (RIP), и/или выбор в первую очередь кратчайшего пути (OSPF), и/или протокол пограничной маршрутизации (BGP).
- 5The method of claim. 1, comprising binding IP-packet with MAC destination address on the network segment-level 2 of the sender, when the MAC destination address in the frame is associated with the Ethernet network segment-level node 2 sender. 5. Способ по п. 1, включающий связывание IP-пакета с МАС-адресом получателя на сегменте сети уровня 2 отправителя, когда МАС-адрес получателя в кадре сети Ethernet связан с узлом сегмента сети уровня 2 отправителя. 5. Способ по п. 1, включающий связывание IP-пакета с МАС-адресом получателя на сегменте сети уровня 2 отправителя, когда МАС-адрес получателя в кадре сети Ethernet связан с узлом сегмента сети уровня 2 отправителя.
- 6A network element for forwarding IP-packet through the Ethernet segment on standard IEEE 802.1aq the addresses of recipients, comprising:virtual router connects at least two segments layer network 2 to transmit data therebetween, each segment of the network level 2 is associated with the corresponding value identifier I-SID, and the network element is configured to receive a segment of the network layer 2 frame network Ethernet, in which IP-encapsulated packet, the IP-packet contains the IP address of the recipient, and the Ethernet frame contains an identifier I-SID and at least one MAC destination address associated with the virtual router;andwhen the MAC address of the destination in the received frame, the Ethernet network associated with the virtual router, then:performing at least one data flow routing the encapsulated IP-packet, and this processing flow of the routing data comprises identifying a network segment layer 2 associated with the IP-destination address in the IP-packet and forwarding IP-packet to the identified network segment Tier 2 in an Ethernet frame with an identifier I-SID, associated with the identified network segment 2 level. 6. Сетевой элемент для переадресации IP-пакета через сегменты сети Ethernet по стандарту IEEE 802.1aq по адресам получателей, содержащий:виртуальный маршрутизатор, соединяющий по меньшей мере два сегмента сети уровня 2 с возможностью передачи данных между ними, причем каждый сегмент сети уровня 2 связан с соответствующей величиной идентификатора I-SID, и сетевой элемент сконфигурирован для приема из сегмента сети уровня 2 кадра сети Ethernet, в который инкапсулирован IP-пакет, причем IP-пакет содержит IP-адрес получателя, и кадр сети Ethernet содержит идентификатор I-SID и по меньшей мере один МАС-адрес получателя, связанный с виртуальным маршрутизатором;икогда МАС-адрес получателя в принятом кадре сети Ethernet связан с виртуальным маршрутизатором, то:осуществление по меньшей мере одной обработки потока данных маршрутизации в инкапсулированном IP-пакете, причем эта обработка потока данных маршрутизации включает идентификацию сегмента сети уровня 2, связанного с IP-адресом получателя в IP-пакете, и направление IP-пакета в идентифицированный сегмент сети уровня 2 в кадре сети Ethernet с идентификатором I-SID, связанным с идентифицированным сегментом сети уровня 2. 6. Сетевой элемент для переадресации IP-пакета через сегменты сети Ethernet по стандарту IEEE 802.1aq по адресам получателей, содержащий:виртуальный маршрутизатор, соединяющий по меньшей мере два сегмента сети уровня 2 с возможностью передачи данных между ними, причем каждый сегмент сети уровня 2 связан с соответствующей величиной идентификатора I-SID, и сетевой элемент сконфигурирован для приема из сегмента сети уровня 2 кадра сети Ethernet, в который инкапсулирован IP-пакет, причем IP-пакет содержит IP-адрес получателя, и кадр сети Ethernet содержит идентификатор I-SID и по меньшей мере один МАС-адрес получателя, связанный с виртуальным маршрутизатором;икогда МАС-адрес получателя в принятом кадре сети Ethernet связан с виртуальным маршрутизатором, то:осуществление по меньшей мере одной обработки потока данных маршрутизации в инкапсулированном IP-пакете, причем эта обработка потока данных маршрутизации включает идентификацию сегмента сети уровня 2, связанного с IP-адресом получателя в IP-пакете, и направление IP-пакета в идентифицированный сегмент сети уровня 2 в кадре сети Ethernet с идентификатором I-SID, связанным с идентифицированным сегментом сети уровня 2.
- 7The network element of claim. 6, configured to use the data flow on at least one of the levels 4-7 for IP-encapsulated packet, wherein the data flow on at least one of the layers 4-7 comprises processing for network security and / or measurement of the network traffic, and / or detecting unauthorized network entry. 7. Сетевой элемент по п. 6, сконфигурированный для применения обработки потока данных по меньшей мере на одном из уровней 4-7 к инкапсулированному IP-пакету, причем обработка потока данных по меньшей мере на одном из уровней 4-7 включает обработку для сетевой защиты, и/или измерение сетевого трафика, и/или обнаружение несанкционированного входа в сеть. 7. Сетевой элемент по п. 6, сконфигурированный для применения обработки потока данных по меньшей мере на одном из уровней 4-7 к инкапсулированному IP-пакету, причем обработка потока данных по меньшей мере на одном из уровней 4-7 включает обработку для сетевой защиты, и/или измерение сетевого трафика, и/или обнаружение несанкционированного входа в сеть.
- 8A network element according to claim. 6, wherein the identification layer 2 network segment associated with the IP-address of the recipient includes receiving information at least partially using at least one routing protocol. 8. Сетевой элемент по п. 6, в котором идентификация сегмента сети уровня 2, связанного с IP-адресом получателя, включает получение информации по меньшей мере частично с использованием по меньшей мере одного протокола маршрутизации. 8. Сетевой элемент по п. 6, в котором идентификация сегмента сети уровня 2, связанного с IP-адресом получателя, включает получение информации по меньшей мере частично с использованием по меньшей мере одного протокола маршрутизации.
- 9The network element according to claim. 8, wherein the at least one routing protocol includes a protocol determination addresses (ARP), and / or routing information protocol (RIP), and / or selecting a shortest path first (OSPF), and / or Border Gateway Protocol (BGP). 9. Сетевой элемент по п. 8, в котором по меньшей мере один протокол маршрутизации включает протокол определения адресов (ARP), и/или протокол информации маршрутизации (RIP), и/или выбор в первую очередь кратчайшего пути (OSPF), и/или протокол пограничной маршрутизации (BGP). 9. Сетевой элемент по п. 8, в котором по меньшей мере один протокол маршрутизации включает протокол определения адресов (ARP), и/или протокол информации маршрутизации (RIP), и/или выбор в первую очередь кратчайшего пути (OSPF), и/или протокол пограничной маршрутизации (BGP).
- 10The network element of claim. 6, further comprising:received information processing unit configured to determine a segment of the layer 2 by the recipient:checks network Ethernet frame header, which is encapsulated in the IP-packet;andchecking for a match identifier value I-SID header field with the value of I-SID identifier, the segment associated with the Layer 2 network of the recipient. 10. Сетевой элемент по п. 6, содержащий также:блок обработки принятой информации, сконфигурированный для определения сегмента сети уровня 2 получателя путем:проверки заголовка кадра сети Ethernet, в который инкапсулирован IP-пакет;ипроверки на совпадение величины идентификатора I-SID в поле заголовка с величиной идентификатора I-SID, связанного с сегментом сети уровня 2 получателя. 10. Сетевой элемент по п. 6, содержащий также:блок обработки принятой информации, сконфигурированный для определения сегмента сети уровня 2 получателя путем:проверки заголовка кадра сети Ethernet, в который инкапсулирован IP-пакет;ипроверки на совпадение величины идентификатора I-SID в поле заголовка с величиной идентификатора I-SID, связанного с сегментом сети уровня 2 получателя.
- 11The network element of claim. 6, further comprising:the user network interface port (UNI) for receiving IP-packets received from the computing devices, each IP-packet contains a header of a MAC address;andreceived information processing unit configured to determine a destination network segment of the received IP-packet of fields which contain one MAC header addresses. 11. Сетевой элемент по п. 6, содержащий также:порт сетевого интерфейса пользователя (UNI) для приема IP-пакетов, поступающих из компьютерных устройств, причем каждый IP-пакет содержит один заголовок МАС-адресов;иблок обработки принятой информации, сконфигурированный для определения сегмента сети получателя в принятом IP-пакете из полей, которые содержат один заголовок МАС-адресов. 11. Сетевой элемент по п. 6, содержащий также:порт сетевого интерфейса пользователя (UNI) для приема IP-пакетов, поступающих из компьютерных устройств, причем каждый IP-пакет содержит один заголовок МАС-адресов;иблок обработки принятой информации, сконфигурированный для определения сегмента сети получателя в принятом IP-пакете из полей, которые содержат один заголовок МАС-адресов.
- 12The network element of claim. 6, wherein the network element is a router. 12. Сетевой элемент по п. 6, в котором сетевой элемент представляет собой маршрутизатор. 12. Сетевой элемент по п. 6, в котором сетевой элемент представляет собой маршрутизатор.
Independent claims12
50 paragraphs in 6 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
The present application is related to US Patent Application 11 / 899.118, filed on September 4, 2007, the entire contents of which are incorporated herein by reference herein.
TECHNICAL FIELD
The present invention relates generally to data transmission networks and, in particular, to a method for routing data between network segments.
BACKGROUND
Networks can logically be divided into virtual private networks (VPN), virtual LAN (VLAN), and other logical subnets, network segments or domains. For example, a VLAN can be further logically divided into a number of user the VLAN or VPN user. Technology to connect to the backbone network of the operator (PBB) and / or the connection given the state of the channel (PLSB) can be used for distinguishing the enterprise domain from one or more user domains with an additional header addresses MAC (Media Access Control) frame in the Ethernet. PLSB technology can provide the use of a protocol to the identification of routes, taking into account the state of communication channels to enhance information sharing at level 2. However, VPN, Layer 2 can end with a port network interface user. Routing between networks VPN client may require a physical connection between the ports. The establishment of such compounds port-port connection may require VPN ports to the outside router. With this routing may be difficulties associated with scaling and control as the number of user networks VPN.
In another approach, provides connectivity with routing between user networks, VPN, a VPN transition between Layer 2 and Layer 2 VPN network using PLSB may be a function of the external routing. This approach may also require additional connections to an external router for the transition between the network layer 2 VPN network and Layer 2 VPN using PLSB PN for multiple networks using Layer 2 PLSB, ending UNI port on the VLAN. Therefore, this approach may also require the use of external routing, thereby increasing overhead costs and system complexity.
All of the above allows us to understand that there may be significant problems and limitations associated with modern technology for routing data between network segments.
SUMMARY OF THE INVENTION
The invention provides a method for routing data between network segments. One specific embodiment is a method for routing data between network segments Layer 2 backbone bridges, comprising: receiving data in a network element comprising an inner finished internetwork interface (NNI) for a plurality of network segments;
identification of the destination address associated with the data; segment definition associated with the data of a plurality of network segments; and performing one or more operations associated with data processing flow using internally a complete gateway (NNI).
In accordance with other aspects of this particular embodiment, one or more operations associated with the data, processing the data stream may contain routing data in a network segment that has been determined.
In accordance with other aspects of this particular embodiment, one or more operations associated with the data, processing the data stream may contain at least one of the following: definition of the rules of network traffic, providing a firewall, measurement of network traffic and detect unauthorized entry into the network .
In accordance with other aspects of this particular embodiment of network segments may comprise virtual private network (VPN).
In accordance with other aspects of this particular embodiment of network segments may comprise virtual local networks (VLAN).
In accordance with other aspects of this particular embodiment of virtual local area networks may be associated with the service identifier VLAN (I-SID).
In accordance with other aspects of this particular embodiment of network element may be associated with a plurality of service VLAN identifiers and performing one or more processing operations on the data stream using at least one of the plurality of service VLAN identifiers.
In accordance with other aspects of this particular embodiment may comprise a destination address an address Medium Access Control backbone network (B-MAC).
In accordance with another aspect of this particular embodiment of the definition of a network segment associated with data may include the use of the service identifier VLAN (I-SID), associated with the data, to determine the network segment.
In accordance with other aspects of this particular embodiment of the above method can be implemented in the form of at least one medium which can be read by a processor for recording a computer program comprising instructions that can be read by at least one processor, and the method is carried out by executing commands said at least one processor.
In another particular embodiment, the method can be implemented in the form of devices for routing data between network segments Layer 2 backbone bridges, comprising: at least one information carrier, which can be read by the processor; and instructions recorded on said at least one storage medium; wherein the commands can be read from said at least one information carrier at least one processor, as a result of which said at least one processor is operative to: receiving data in a network element, comprising an inner finished internetwork interface (NNI) for a plurality of network segments; identification of the destination address associated with the data; segment definition associated with the data of a plurality of network segments; and performing one or more operations associated with data processing flow using internally a complete gateway (NNI).
In another particular embodiment, the method may be implemented as a system for routing data between network segments, comprising: one or more processors coupled to the network element, the network element is configured such that it provides: receiving at the network element comprising Internally finished internetwork interface (NNI) for multiple network segments; identification of the destination address associated with the data; segment definition associated with the data of a plurality of network segments; and performing one or more operations associated with data processing flow using internally a complete gateway (NNI).
In accordance with other aspects of this particular embodiment, one or more operations associated with the data, processing the data stream may contain routing data in a network segment that has been determined.
In accordance with other aspects of this particular embodiment, one or more operations associated with the data, processing the data stream may contain at least one of the following: definition of the rules of network traffic, providing a firewall, measurement of network traffic and detect unauthorized entry into the network .
In accordance with other aspects of this particular embodiment of network segments may comprise virtual private network (VPN).
In accordance with other aspects of this particular embodiment of network segments may comprise virtual local networks (VLAN).
In accordance with other aspects of this particular embodiment of virtual local area networks may be associated with the service identifier VLAN (I-SID).
In accordance with other aspects of this particular embodiment of network element may be associated with a plurality of service VLAN identifier, and the execution of one or more processing operations on the data stream using at least one of the plurality of service VLAN identifiers.
In accordance with other aspects of this particular embodiment may comprise a destination address an address Medium Access Control backbone network (B-MAC).
In accordance with another aspect of this particular embodiment of the definition of a network segment connected to the data network element may comprise using the identifier service VLAN (I-SID), linked to the data to determine the network segment.
The present invention will be described in more detail with reference to specific embodiments thereof which are illustrated in the accompanying drawings. While the present invention is described below with reference to specific embodiments, it should be understood that the invention is not limited to these embodiments. Those skilled in the art familiar with the principles of the invention set forth herein will suggest further embodiments and modifications and other applications of the invention, which are within the scope of the present invention discussed herein, and for which the use of the present The invention can be quite useful.
BRIEF DESCRIPTION OF THE DRAWINGS
To facilitate a more complete understanding of the present invention to the description of the accompanying drawings, in which like elements are indicated by like reference numerals. These drawings are only intended to illustrate the present invention and in no way limit its scope.
Figure 1 - scheme of the system for routing data between the network segments in accordance with one embodiment of the present invention;
Figure 2 - schematic diagram of the system for routing data between the network segments in accordance with one embodiment of the present invention;
Figure 3 - a block diagram of a method for routing data between the network segments in accordance with one embodiment of the present invention.
DETAILED DESCRIPTION OF EMBODIMENTS
Figure 1 is a diagram of a system 100 for routing data between the network segments in accordance with one embodiment of the present invention. Figure 1 shows a simplified diagram of a system 100, which in principle can also contain other elements. In system 100, network elements 108, 110, 112, 114, 116, 118, 120 and 122 may be connected communicatively to the network 106. The network 106 may be logically divided into segments. For example, the network 106 can be IPv4 network protocol, which may be divided into multiple segments or domains such as the segments 102 and 104 of the network. Each of the network elements 108, 110, 112, 114, 116, 118, 120 and 122 may be connected to the segment 102 and / or to a segment of network 104 capable of exchanging data. Each of the network elements 108, 110, 112, 114, 116, 118, 120 and 122 may also be connected to additional network segments (not shown) capable of exchanging data. As shown in Figure 1, the network elements 110, 112 and 114 may be connected to the network segment 102 is capable of communicating. Network elements 118, 120 and 122 can be connected to a segment of network 104 capable of exchanging data. Network elements 108 and 116 may be connected to the two segments 102 and 104 of network capable of exchanging data.
Network 106 may be a virtual LAN (VLAN), a backbone network VLAN (BVLAN), or another logical network structure, which facilitates the exchange of data between network elements 108, 110.112, 114, 116, 118, 120 and 122, as well as other devices connected network 106 capable of exchanging data. In accordance with one or more embodiments network 106 may be a network VLAN network service provider is implemented using data transmission technology using connection technology, given the state of communication channels (PLSB) technology or defined by standard IEEE 802.laq. Network 106 may be implemented logically on the upper level of the main IEEE 802.lah or operator of bridges (PBB). The backbone bridges operator can be used subaddress medium access control (MAC), or may be realized by addressing MAC-in-MAC (encapsulation MAC address in MAC) in the Ethernet frame to the routing in the backbone structure of the operator (e.g., the MAC address of the backbone ( B-MAC), or the address can be used to encapsulate the Ethernet frame with the MAC address of the user). Can be used an additional frame header Ethernet, which contains the addresses of the sender and recipient backbone network VLAN ID LAN (BVLAN) and 24-bit identifier service VLAN (I-SID). Network 106 may be implemented on a routing protocol based on link-state, such as, for example, routing protocol "transit system - Transit System" (IS-IS) to receive and distribute network information such as a MAC address B and size I- SID.
Segments 102 and 104 can be network LPARs network 106, such as a VLAN or VPN. Network segments may be associated with 24-bit service identifier VLAN (I-SID). In one or more embodiments, the segments 102 and 104 may be networks VLAN members. Although Figure 1 shows two network segments, it should be understood that the user can realize an increasing number of network segments, such as additional network VLAN.
Network elements 108, 110, 112, 114, 116, 118, 120 and 122 can be routers, switches or other devices connected to the network 106 capable of exchanging data. Network elements 108, 110, 112, 114, 116, 118, 120 and 122 may be connected to network resources, such as servers, databases and / or networked storage. Network elements 108, 110, 112, 114, 116, 118, 120 and 122 may be network end devices, such as terminal equipment of the operator, which can be connected to several end users.
As already mentioned, in one or more embodiments, multiple network elements 108, 110, 112, 114, 116, 118, 120 and 122 can be associated with multiple network segments, such as segments 102 and 104. For example, network element 116 and / or the network element 108 may be associated with segments 102 and 104 of the network. These segments of the network can be associated with a specific 24-bit service identifier VLAN (I-SID). For example, the network segment 102 may be associated with the I-SID 102, and the network segment 104 may be associated with the I-SID 104. For example, receiving a request from a user connected to a network element 120, the server associated with the network element 110 may transmit reply message. The network element such as network element 108 may receive the data transmitted by the network element 110.
In accordance with one or more embodiments of routing may be accomplished using a routing function implemented on the NNI interface (gateway) using PLSB technology. NNI interface can be a network between the segment 102 and segment 104, and the network can be implemented at the network element 108. The routing function may determine the 24-bit service identifier VLAN (I-SID) in the Ethernet frame and can identify the segment of network 104, as the segment associated with the I-SID. Thus, network element 108 may send the piece of data that it receives from the network element 110 to network element 120 via a network segment 104.
Network element 108 may perform alternative and / or additional functions such as the processing operations of data stream, for example, one or more data processing operations performed on levels 4-7 of the standard model OSI (Open System Interconnection). For example, network element 108 may ODA edelyat rules of network traffic, implement network security, network traffic measurement and detection of unauthorized entry into the network (ingress). Routing capabilities can support the upper layer protocol, including for example: ARP (address resolution protocol), RIP (Routing Information Protocol), OSPF (choice in the shortest path first) and BGP (Border Gateway Protocol).
Figure 2 shows a diagram of a system 200 for routing data between the network segments in accordance with one embodiment of the present invention. Figure 2 is a simplified diagram of a system 200, which in principle can also contain other elements. Elements of system 100 are included in system 200 have the same reference numerals as in Figure 1.
Computers 202, 204, 206 and / or 208 can be desktop computers, laptops, servers, databases, host computers or other computers connected to network elements associated with the network 106, to transmit the data. As shown in Figure 2, the computers 202 and 206 can be associated with a network segment 102, which can have an identifier I-SID 102. Computers 204 and 208 can be associated with a segment of network 104, which may have an identifier I-SID 104. Data receiving network element may be inspected to determine whether to route data, such as, for example, an incoming Ethernet frame.
In accordance with some embodiments of routing can be performed by means of internally finished gateway (NNI) between the two segments PLSB network. For example, network element 116 may comprise a virtual router (VR) 210, which uses the NNI interface between the two network segments. NNI interface between the network segment 102 and a segment 104 may be a network associated with the network element 116 and may support a router that can perform one or more processing operations on the data stream. For example, the data received by the network element 116 of the computer 202 may be checked to determine the MAC address of the recipient. If the MAC destination address associated with computer 206, then network element 116 may determine that the computer 206 is connected to the same network segment (i.e., segment 102, having identifier 102 I-SID). Then, the network element 116 may pass data through the bridge to the network element 114. The network element 116 may be configured to perform routing of data or transmit it through the bridge regardless of whether they come from the network segment 106, or from the device connected to the user network interface port ( UNI) (e.g., a network element can handle data that contains a MAC header address in the frame encapsulating the data or MAC address in MAC).
If the MAC destination address associated with NNI interface of the network element 116, then network element 116 may determine that traffic should be routed in the network segment 104, which has an identifier I-SID 104. Then, the network element 116 may use a virtual interface to the router 210 between the NNI two segments of a network to one or more processing operations on the data stream, such as the processing operation on the levels 4-7 of the standard model OSI (Open System Interconnection). For example, network element 116 may implement routing of data for transmission to the network segment 104. Network element 116 may also perform other actions, such as, for example, the determination rules of the network traffic, ensuring network security, network traffic measurement and detection of unauthorized entry into the network (penetration). Routing capabilities can support the upper layer protocol, including for example: ARP (address resolution protocol), RIP (Routing Information Protocol), OSPF (choice in the shortest path first) and BOP (Border Gateway Protocol).
Figure 3 is a flowchart of a method 300 for routing data between the network segments in accordance with one embodiment of the present invention. The method may begin in step 302.
In step 304, method 300 may include the identification of individual segments of the network, which can be accessed from a network node. For example, the network may be identified VLAN or VPN. In accordance with one or more embodiments of network elements such as routers in a network implementing the method 300 may use a data transmission technology using connection technology stateful communication channels (PLSB) technology or defined by standard IEEE 802.laq. The method 300 may be implemented in a routing protocol based on link-state, such as, for example, routing protocol "transit system - Transit System" (IS-IS), to receive and distribute network information, such as addresses B-MAC and the value I -SID. Network elements such as routers and switches, can utilize the information received by the routing protocol IS-IS, to identify segments of the network, such as networks, VLAN, identifier associated with the I-SID.
Step 306, the method may include receiving network traffic in the network element. For example, network element 116 may receive data from a computer 206 associated with a segment of the network, such as a VLAN, or more specifically, the VLAN user.
Step 308 may include the identification of a single network segment associated with the user MAC address of the network traffic received. User MAC address may be associated with a segment of the network such as the VLAN.
In step 310 may determine whether the current segment of the destination network segment. For example, if the SMAS address is the MAC address of the current node (e.g., network element 116), the internal logical routing interface using means gateway NNI, such as, for example, the virtual router 210, can be determined by SMAS-address network traffic whether it should be sent to the router interface NNI. In this case, in step 314 can route the network traffic. If SMAS address of the network traffic is not the MAC address associated with the NNI interface, the network traffic can be transmitted across the bridge at step 312. Other processing operations data stream may be performed instead of routing or in addition to routing. For example, routing traffic may be restricted firewall. Routing capabilities can support the upper layer protocol, including for example: ARP (address resolution protocol), RIP (Routing Information Protocol), OSPF (choice in the shortest path first) and BGP (Border Gateway Protocol). In accordance with one or more embodiments of routing and / or other processing operations of the data stream can be performed at NNI interface technology PLSB between two network segments, such as the VLAN.
The method may end at step 312.
It should be noted that routing between logical networks in accordance with the present invention, as described, includes some processing of the input data and generate the output data. These processing operations of the input data and generating output data can be implemented in software or hardware. For example, a router or other corresponding devices implementing the functions related to the management of data flow between the network segments in accordance with the present invention, as described, can be used a specialized electronic parts. Other embodiments may use one or more processors operating in accordance with instructions that implement the functions associated with managing data flow between the network segments in accordance with the present invention as described above. In this case, within the scope of the present invention provides that such instructions may be stored on one or more computer readable media (e.g., magnetic disk or other media), or may enter the one or more processors in a part of messages transmitted by radio.
The present invention is not limited to the particular embodiments discussed in this description. Other embodiments or their modifications, in addition to the discussed herein will be apparent to those skilled in the art from the foregoing description and accompanying drawings. Thus, such other embodiments and modifications within the scope of the present invention. Furthermore, although the present invention has been described with reference to a particular implementation in a particular environment for a particular purpose, those skilled in the art will recognize that its application is not limited to this implementation, and that the present invention may be embodied in many other environments for different purposes . Accordingly, the appended claims are to be interpreted taking into account the full scope and spirit of the present invention, as described above.
Contents6
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office |
|---|---|---|
| US20040042454A1 | Cites | United States of America |
| US20080049753A1 | Cites | United States of America |
| US20020067731A1 | Cites | United States of America |
| US20080170573A1 | Cites | United States of America |
| RU2265282C2 | Cites | Russian Federation |
44 members in 9 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 12483690 | United States of America | – | |
| 48369009 | United States of America | A | |
| 2010037733 | United States of America | W | |
| 12483690 | – | – | – |
| US2010037733 | – | – | – |
| US20090483690 | – | – | – |
| WO2010US37733 | – | – | – |
Members44
| Document | Office | Kind | |
|---|---|---|---|
| US2008144644A1 | United States of America | A1 | |
| CA2671671A1 | Canada | A1 | |
| WO2008076201A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2092692A1 | European Patent Office (EPO) | A1 | |
| KR20090099556A | Republic of Korea | A | |
| US2010020797A1 | United States of America | A1 | |
| CN101663859A | China | A | |
| CA2764632A1 | Canada | A1 | |
| US2010316056A1 | United States of America | A1 | |
| WO2010144418A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CA2776895A1 | Canada | A1 | |
| WO2011041895A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2441214A1 | European Patent Office (EPO) | A1 | |
| CN102484604A | China | A | |
| KR20120060810A | Republic of Korea | A | |
| EP2092692A4 | European Patent Office (EPO) | A4 | |
| US8223668B2 | United States of America | B2 | |
| EP2486703A1 | European Patent Office (EPO) | A1 | |
| CN102648605A | China | A | |
| KR20120097377A | Republic of Korea | A | |
| US2012233350A1 | United States of America | A1 | |
| US8270319B2 | United States of America | B2 | |
| US2012263075A1 | United States of America | A1 | |
| JP2012529855A | Japan | A | |
| US2012300774A1 | United States of America | A1 | |
| JP2013507797A | Japan | A | |
| CN101663859B | China | B | |
| RU2011153500A | Russian Federation | A | |
| RU2012116597A | Russian Federation | A | |
| EP2685669A1 | European Patent Office (EPO) | A1 | |
| RU2507698C2 | Russian Federation | C2 | |
| EP2092692B1 | European Patent Office (EPO) | B1 | |
| EP2486703A4 | European Patent Office (EPO) | A4 | |
| KR101421511B1 | Republic of Korea | B1 | |
| US2014226527A1 | United States of America | A1 | |
| US2014301244A1 | United States of America | A1 | |
| US8879424B2 | United States of America | B2 | |
| EP2441214A4 | European Patent Office (EPO) | A4 | |
| RU2544766C2This record | Russian Federation | C2 | |
| US9001829B2 | United States of America | B2 | |
| RU2013144245A | Russian Federation | A | |
| RU2013144973A | Russian Federation | A | |
| BR112012007996A2 | Brazil | A2 | |
| BR112012000198A2 | Brazil | A2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A |
Numbers
- Publication
- 0002544766
- Publication, DOCDB
- 2544766
- Publication, EPODOC
- RU2544766
- Application
- 201115350008
- Application, DOCDB
- 2011153500
- Application, EPODOC
- RU20110153500
Titles2
- English
- METHOD, DEVICE AND SYSTEM FOR ROUTING DATA BETWEEN NETWORK SEGMENTS
- Russian
- ??????, ?????????? ? ??????? ????????????? ?????? ????? ?????????? ?????
Classification
- CPC, 4
- H04L12/4625
- H04L12/4633
- H04L45/04
- H04L45/66