作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (5): 89-91,115.

• 网络与通信 • 上一篇    下一篇

地址检查 BGP/MPLS VPN 中MP-BGP配置错误的方法

梁海英 1,2,滕国文2,王洪君1,王大东1,高远 1   

  1. 1.东北大学信息科学与工程学院,沈阳 110004;2.吉林师范大学计算机学院,四平 136000
  • 出版日期:2006-03-05 发布日期:2006-03-05

Method of Inspecting MP-BGP Misconfiguration in BGP/MPLS VPN

LIANG Haiying1,2, TENG Guowen2, WANG Hongjun1, WANG Dadong1, GAO Yuan1   

  1. 1. School of Information Science and Engineering, Northeastern University, Shenyang 110004;2. School of Computer, Jilin Normal University, Siping 136000
  • Online:2006-03-05 Published:2006-03-05

摘要: 在BGP/MPLS VPN 中,用MP-BGP 交换VPN 路由信息。由于配置错误,AS 可能有意地通告属于其它AS 地址空间的地址前缀或输出违反自己路由策略的路由。检查MP-BGP 配置错误的方法要求每个ASBR 或PE 路由器分别为它所信任的AS 维持一个地址前缀集和AS 关系集。仿真表明通过AS 关系和地址前缀集结合使用的算法,能有效地检查起源配置错误和输出配置错误。

关键词: 边界网关协议;MP-BGP;BGP/MPLS VPN;配置错误

Abstract: In BGP/MPLS VPN, MP-BGP is used to exchange VPN routing information. An AS may accidentally advertise a prefix belonging to someone else’s address space and may also export a route that violates its own routing policy due to misconfiguration. This paper presents an approach which can detect MP-BGP configuration errors based on prefixes sets of neighboring ASes and the AS relationships. This approach requires that every ASBR or PE router respectively remains a prefixes set for each trusted AS and AS relationships constructed according to bilateral economical agreements. Simulation shows that the solution can effectively detect original misconfigurations and export misconfigurations by using the combination of AS relationships and prefixes sets

Key words: BGP; Multiprotocol extensions for border gateway protocol(MP-BGP); BGP/MPLS VPN; Misconfiguration