Implementation of vpns over a link state protocol controlled ethernet network
Abstract
Nodes on a link state protocol controlled Ethernet network implement a link state routing protocol such as IS-IS. Nodes assign an IP address or I-SID value per VRF and then advertise the IP addresses or I-SID values in IS-IS LSAs. When a packet is to be forwarded on the VPN, the ingress node identifies the VRF for the packet and performs an IP lookup in customer address space in the VRF to determine the next hop and the IP address or I-SID value of the VRF on the egress node. The ingress node prepends an I-SID or IP header to identify the VRFs and then creates a MAC header to allow the packet to be forwarded to the egress node on the link state protocol controlled Ethernet network. When the packet is received at the egress node, the MAC header is stripped from the packet and the appended I-SID or IP header is used to identify the egress VRF. A customer address space IP lookup is then performed in the identified VRF on the egress node using the information in the client IP header to determine how to forward the packet. Customer reachability information within a VPN may be exchanged between VRFs using iBGP, or directly by using link state protocol LSAs tagged with the relevant I-SID.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 - 20 . (canceled)
21 . A method of operating an Ethernet node in a link state protocol controlled Ethernet network to contribute to implementation of a layer 3 Virtual Private Network (VPN), the Ethernet network comprising plural Ethernet nodes implementing a link state protocol in a network control plane operable to enable each Ethernet node to individually populate a forwarding information base according to a computed view of the network, the method comprising:
establishing a Virtual Routing and Forwarding Table (VRF) for the VPN; associating an I-SID with the VRF, the I-SID comprising a community of interest identifier for the VPN within the link state protocol controlled Ethernet network carried in at least one field of an Ethernet frame that would not be used by bridges in making forwarding decisions according to the IEEE 802.1Q standard; advertising the I-SID in a link state protocol link state advertisement; and receiving the I-SID in a link state protocol link state advertisement originated by another Ethernet node of the link state protocol controlled Ethernet network.
22 . The method of claim 21 , further comprising:
including the I-SID in packets belonging to the VPN when said packets are forwarded over the link state protocol controlled Ethernet network; and using the I-SID in a packet received from the link state protocol controlled Ethernet network to identify a correct VRF to be used to determine further handling of the received packet.
23 . The method of claim 21 , wherein the I-SID is an I-SID as defined in IEEE 802.1ah (Provider Backbone Bridges) standard.
24 . The method of claim 21 , further comprising advertising customer routes of the layer 3 VPN in association with the I-SID.
25 . The method of claim 24 , wherein advertising customer routes comprises using iBGP to advertise the customer routes.
26 . The method of claim 24 , wherein the step of advertising customer routes comprises using link state protocol to advertise the customer routes.
27 . The method of claim 26 , wherein:
the network control plane of the link state protocol controlled Ethernet network uses an instance of a link state protocol; and advertising customer routes comprises using the same instance of the link state protocol to advertise the customer routes.
28 . The method of claim 27 , wherein the link state protocol is Intermediate-System to Intermediate-System (IS-IS) and IS-IS link state protocol advertisements advertising customer routes have Type Length Values (TLVs) indicating that said IS-IS link state advertisements advertise customer routes.
29 . The method of claim 28 , wherein the TLVs enable both IPv4 and IPv6 customer routes to be advertised in IS-IS link state protocol advertisements.
30 . The method of claim 21 , wherein the link state protocol is configurable to enable each Ethernet node of the Ethernet network to have a common view of the topology of the Ethernet network.
31 . The method of claim 21 , wherein the link state protocol is configurable to enable each Ethernet node of the Ethernet network to have a synchronized view of the topology of the Ethernet network.
32 . An Ethernet node for an link state protocol controlled Ethernet network, the link state protocol Ethernet network comprising plural Ethernet nodes implementing a link state protocol in a network control plane operable to implement a layer 3 Virtual Private Network (VPN) and to enable each Ethernet node to individually populate a forwarding information base according to a computed view of the network, the Ethernet node comprising:
at least one Virtual Routing and Forwarding Table (VRF) associated with the VPN; a packet processor configured:
to associate an I-SID with the VRF which is associated with the VPN, the I-SID comprising a community of interest identifier for the VPN within the link state protocol controlled Ethernet network carried in at least one field of an Ethernet frame that would not be used by bridges in making forwarding decisions according to the IEEE 802.1Q standard; and
a routing system configured:
to advertise the I-SID in a link state protocol link state advertisement; and
to receive the I-SID in a link state protocol link state advertisement originated by another Ethernet node of the link state protocol controlled Ethernet network.
33 . The Ethernet node of claim 32 , wherein the packet processor is further configured:
to use the I-SID in a packet received from the link state protocol controlled Ethernet network to identify a correct VRF to be used to determine further handling of said received packet; and to include the I-SID in packets belonging to the VPN when said packets are forwarded over the link state protocol controlled Ethernet network.
34 . The Ethernet node of claim 32 , wherein the I-SID is an I-SID as defined in the IEEE 802.1ah (Provider Backbone Bridges) standard.
35 . The Ethernet node of claim 32 , wherein the routing system is further configured to advertise customer routes of the layer 3 VPN in association with the I-SID.
36 . The Ethernet node of claim 35 , wherein the routing system is further configured to use iBGP to advertise the customer routes.
37 . The Ethernet node of claim 35 , wherein the routing system is further configured to use link state protocol advertisements to advertise the customer routes.
38 . The Ethernet node of claim 37 , wherein:
the network control plane of the link state protocol controlled Ethernet network uses an instance of a link state protocol; and the routing system is further configured to use the same instance of the link state protocol to advertise the customer routes.
39 . The Ethernet node of claim 38 , wherein the link state protocol is Intermediate-System to Intermediate-System (IS-IS) and IS-IS link state protocol and the advertisements advertising customer routes have Type Length Value (TLVs) indicating that the IS-IS link state advertisements advertise customer routes.
40 . The Ethernet node of in claim 39 , wherein the TLVs enable both IPv4 and IPv6 customer routes to be advertised in IS-IS link state protocol advertisements.Join the waitlist — get patent alerts
Track US2015016304A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.