ODL流表添加后未生效咨询:Mininet拓扑下MPLS标签推送失败
排查MPLS流表未生效的核心步骤
我来帮你一步步拆解这个问题——你搭了2交换机的线性Mininet拓扑,连了远程ODL控制器,推了MPLS流表却没触发标签推送,大概率是流表配置、下发链路或者配套规则的问题,咱们逐个排查:
1. 先检查流表的匹配规则是否精准命中ping流量
你贴的流表内容没完整显示<match>部分,但ping是ICMP包,必须确保匹配规则精准对应:
- 要指定以太网类型为
0x0800(IPv4) - 匹配h1和h2的源/目的IP(比如h1是10.0.0.1,h2是10.0.0.2)
- 指定IP协议号为
1(ICMP)
举个正确的匹配片段例子:
<match> <ethernet-match> <ethernet-type> <type>0x0800</type> </ethernet-type> </ethernet-match> <ipv4-source>10.0.0.1/32</ipv4-source> <ipv4-destination>10.0.0.2/32</ipv4-destination> <ip-match> <ip-protocol>1</ip-protocol> </ip-match> </match>
如果匹配规则太宽(比如没指定ICMP)或者太窄(比如IP写错了),流量根本触发不了动作。
2. 验证MPLS推送动作的配置是否合规
ODL里推送MPLS的动作有几个关键参数不能错:
- 以太网类型必须是
0x8847(MPLS单播的标准类型) - MPLS标签的
<bos>(栈底标识)如果是单层标签要设为true - 动作顺序要对:先推送MPLS标签,再指定输出端口
正确的动作配置片段参考:
<instructions> <instruction> <order>0</order> <apply-actions> <action> <order>0</order> <push-mpls-action> <ethernet-type>0x8847</ethernet-type> <mpls-header> <mpls-label>100</mpls-label> <mpls-ttl>64</mpls-ttl> <bos>true</bos> </mpls-header> </push-mpls-action> </action> <action> <order>1</order> <output-action> <output-node-connector>OFPP_NORMAL</output-node-connector> </output-action> </action> </apply-actions> </instruction> </instructions>
3. 确认流表真的下发到了目标交换机
别光看Postman返回成功,得去ODL里验证:
- 用Karaf命令行:登录ODL的Karaf控制台,执行
flow:show <交换机ID>(比如交换机ID是openflow:1),看看流表push-mpls-action是否存在 - 用REST API:发送GET请求到
http://<ODL_IP>:8181/restconf/config/opendaylight-inventory:nodes/node/<交换机ID>/table/0/flow/push-mpls-action,用admin/admin认证,检查返回的流表内容是否和你推送的一致
如果流表没出现在交换机上,那可能是Postman的请求URL错了、XML格式有语法问题,或者认证失败。
4. 检查交换机和控制器的MPLS支持能力
- 你的交换机用的是
ovsk,datapath=user,要确保OpenFlow版本是1.3及以上(MPLS是OF1.3才引入的),可以在启动Mininet时强制指定:sudo mn --mac --controller,remote,ip=xx.xx.xx.xx --topo=linear,2 --switch=ovsk,datapath=user,protocols=OpenFlow13 - ODL这边要安装MPLS相关特性,登录Karaf执行:
feature:install odl-mpls odl-openflowplugin-applications-mpls
5. 抓包验证流量是否触发了MPLS封装
在Mininet里给交换机的端口抓包:
# 在s1上抓连接s2的端口流量 mininet> s1 tcpdump -i eth1 -w s1-s2.pcap # 启动ping mininet> h1 ping h2 -c 3 # 停止抓包(按Ctrl+C)
然后用Wireshark打开h1-s1.pcap和s1-s2.pcap,看s1-s2的包里有没有MPLS头部。如果没有,说明流表没触发;如果有,那大概率是另一台交换机s2没配置MPLS弹出流表——因为s2收到MPLS包后,需要弹出标签才能转发给h2,否则会丢弃流量。
6. 别忘了给s2配置MPLS弹出流表
你的拓扑是s1连h1,s2连h2,s1和s2相连。只给s1配push是不够的,s2需要匹配MPLS标签,弹出后转发给h2。举个s2的流表示例:
<flow xmlns="urn:opendaylight:flow:inventory"> <flow-name>pop-mpls-action</flow-name> <table-id>0</table-id> <priority>1000</priority> <match> <ethernet-match> <ethernet-type> <type>0x8847</type> </ethernet-type> </ethernet-match> <mpls-match> <mpls-label>100</mpls-label> </mpls-match> </match> <instructions> <instruction> <order>0</order> <apply-actions> <action> <order>0</order> <pop-mpls-action> <ethernet-type>0x0800</ethernet-type> </pop-mpls-action> </action> <action> <order>1</order> <output-action> <output-node-connector>eth1</output-node-connector> </output-action> </action> </apply-actions> </instruction> </instructions> </flow>
最后检查控制器和交换机的连接状态
在ODL的Karaf里执行openflow:show,看看交换机是不是在线状态。如果连接断开了,流表根本没法生效。
内容的提问来源于stack exchange,提问作者Juan Andrés Martínez
相关产品推荐
相关产品推荐

