This application provides a security protection method and a security
resource pool. The method includes: obtaining service traffic from a service switch through a traffic splitter deployed on a third
server and forwarding it to an orchestrator deployed on a second
server; using the orchestrator, sequentially forwarding the service traffic to corresponding security devices for security detection according to a preset
security service chain, wherein the security devices are deployed on a first
server; the traffic splitter, the orchestrator, and the security devices are all virtual machines; using the orchestrator, the service traffic that passes the security detection is returned to the service switch via the traffic splitter. Through a full-dimensional redundancy design from the underlying platform to
virtual network elements, the
single point of failure problem is completely solved, the availability of the security
resource pool is improved, and continuous security protection of service traffic is achieved.