Message forwarding method and system, computer device, medium and product
By deploying service gateway devices and SDN controllers that support SRv6 protocol on the service side, dynamically obtaining and issuing service routing information, the problem of traffic path inconsistency caused by EVPN's automatic SID list is solved, and precise traffic path control and network security and service quality improvement are achieved.
Patent Information
- Application Number
- CN202510574659.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-05-06
AI Technical Summary
In complex business scenarios, because the end.dt4 SID is forced to include the SID list automatically issued by EVPN, the actual traffic path is inconsistent with the forwarding policy path expected by the user, resulting in the traffic not undergoing the security check of the firewall.
By deploying a service gateway device that supports SRv6 protocol and SID list orchestration on the service side, the SDN controller is called to dynamically obtain service routing information, convert it into a target flow table, and send it to the service gateway device. The message path is judged based on the preset flow table mechanism, and the target strategy is called for path control.
Accurate path control of traffic is realized, ensuring that traffic can pass through the firewall for security checks as expected by users, improving network security and service quality, and reducing management costs and error probability.
Smart Images

Figure CN120090969A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network communication technologies, and in particular, to a method and system for packet forwarding, a computer device, a medium, and a product. Background Art
[0002] In some complex business scenarios, traffic needs to pass through a specific path to reach the destination; when EVPN runs on Provider Edge (PE) devices, it automatically generates and distributes a list of SIDs through the BGP protocol, and these SID lists define the paths of traffic in the network. In some cases, the SID list generated by EVPN will compulsorily include a special SID named end.dt4 SID, and the role of this SID is to convert traffic from the IPv6 SRv6 domain to the traditional IPv4 network (such as the public network egress).
[0003] Specifically, in complex business scenarios, the user's expectation is that traffic starts from the source node, passes through the SRv6 path, and at a certain node, the traffic is directed to the firewall using the end.dx4 SID. After the firewall processes it, the traffic then enters the public network egress. However, due to the fact that the SID list automatically distributed by EVPN compulsorily includes the end.dt4 SID, and the end.dt4 SID is usually the last hop of the SID list (that is, according to the specification of RFC 8986, the role of the end.dt4 SID is to convert traffic from the IPv6 domain to the IPv4 domain, so it is usually placed at the end of the SID list), the actual path of the traffic becomes: the traffic passes through the SRv6 path, and since the end.dt4 SID is placed at the end, the traffic is directly directed to the public network egress without passing through the firewall expected by the user; therefore, this will cause the traffic not to pass through the security check of the firewall, and the functions of the firewall (such as intrusion detection, policy filtering, etc.) cannot take effect, and the end.dx4 SID set by the user does not play the expected forwarding role. Summary of the Invention
[0004] In view of this, embodiments of the present disclosure provide a method and system for packet forwarding, a computer device, a medium, and a product, which can solve the problems in the prior art that due to the limitations of the RFC 8986 protocol specification, the actual forwarding path of traffic is inconsistent with the expected forwarding policy path, etc.
[0005] In a first aspect, an embodiment of the present disclosure provides a method for packet forwarding, including: In response to a packet forwarding instruction, a service gateway device is called to receive the service packet to be forwarded; the service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of SID lists; Invoke the SDN controller to dynamically obtain service routing information from the edge nodes of EVPN through the EBGP protocol; Convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface; Judge the service packet based on the preset flow table mechanism, and when it meets the preset flow table mechanism, trigger a service information acquisition instruction; Obtain the service information of the service packet in response to the service information acquisition instruction; When it is determined according to the service information that the service packet is a packet that needs path control, call a target policy from the at least two preset policies; The target policy includes a target SR policy and a target SID list; Based on the target SR policy, encapsulate an outer IPv6 header and an SRH SID List for the service packet, and set the SL value at the same time to obtain an SRv6 packet; Forward the SRv6 packet according to the target SID list.
[0006] In a second aspect, the present application discloses a packet forwarding system, including: A deployment module for deploying a service gateway device on the service side to completely separate the forwarding plane from the control plane, and the service gateway device supports the SRv6 protocol and supports the orchestration of the SID list; An SDN controller module for dynamically obtaining service routing information from the edge nodes of EVPN through the EBGP protocol, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two configured preset policies to the service gateway device through the API interface; An invocation module for invoking the service gateway device to receive the service packet to be forwarded in response to a packet forwarding instruction; A trigger execution module for judging the service packet based on the preset flow table mechanism, triggering a service information acquisition instruction when it meets the preset flow table mechanism, and obtaining the service information of the service packet in response to the service information acquisition instruction; An invocation module for calling a target policy from the at least two preset policies when it is determined according to the service information that the service packet is a packet that needs path control; The target policy includes a target SR policy and a target SID list; An encapsulation module for encapsulating an outer IPv6 header and an SRH SIDList for the service packet based on the target SR policy, and setting the SL value at the same time to obtain an SRv6 packet; A forwarding module for forwarding the SRv6 packet according to the target SID list.
[0007] In a third aspect, the present application discloses a packet forwarding method, including: Deploy a service gateway device on the service side; the service gateway device supports the SRv6 protocol and supports the orchestration of SID lists; In response to a packet forwarding instruction, call the service gateway device to receive the service packet to be forwarded; Call the SDN controller to dynamically obtain service routing information from the edge nodes of the EVPN through the EBGP protocol, and convert the service routing information into a target flow table according to the docking protocol; According to the service attributes of the packet to be forwarded, obtain the policies associated with the service attributes from the SDN controller, and send the target flow table and the associated policies to the service gateway device through the API interface; Judge the service packet based on a preset flow table mechanism, and when it meets the preset flow table mechanism, trigger a service information acquisition instruction; In response to the service information acquisition instruction, obtain the service information of the service packet; Judge whether the service packet is a packet that requires path control according to the service information. If not, call the first policy from the associated policies, execute the first policy to obtain the encapsulated SRv6 packet, and forward the SRv6 packet; If so, call the second policy from the associated policies, execute the second policy to obtain the encapsulated SRv6 packet, and forward the SRv6 packet.
[0008] In a fourth aspect, the present application discloses a collaborative management system for SRv6 policies and EVPN automatic SIDs, including a service system, a service gateway device, an SDN controller, several intermediate node routers, an egress node router, and a side-mounted firewall. The service system is communicatively connected to the service gateway device, and the SDN controller is communicatively connected to one or more of the several intermediate node routers; one or more of the several intermediate node routers are communicatively connected to the egress node router; the egress node router is communicatively connected to the side-mounted firewall; The service system is used to initiate a packet forwarding instruction; The SDN controller is used to configure at least two SR policies and the policies associated with the service attributes of the packet to be forwarded, to dynamically obtain service routing information from the corresponding intermediate node routers of the EVPN through the EBGP protocol, to convert the service routing information into a target flow table according to the docking protocol, and to send the target flow table and the associated policies to the service gateway device through the API interface; The service gateway device is used to judge the received service message based on a preset flow table mechanism. When it meets the preset flow table mechanism, it obtains the service information of the service message, judges whether the service message is a message that needs path control according to the service information, and triggers the execution of corresponding policies according to different judgment results.
[0009] In a fifth aspect, an embodiment of the present disclosure further provides a computer device, which adopts the following technical solution: The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any one of the above message forwarding methods.
[0010] In a sixth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute any one of the above message forwarding methods.
[0011] In a seventh aspect, an embodiment of the present disclosure further provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of any one of the above methods are implemented.
[0012] The packet forwarding method disclosed in this application, in response to a packet forwarding instruction, calls a service gateway device deployed on the service side to receive service packets to be forwarded, calls an SDN controller, dynamically obtains service routing information from the edge nodes of the EVPN through the EBGP protocol, converts the service routing information into a target flow table according to the docking protocol, and issues the target flow table and at least two preset policies in the SDN controller to the service gateway device through an API interface. This method enables the service gateway device to flexibly adjust the flow table and policies according to different docking protocols and service requirements, improving the adaptability and scalability of the system. As the core of centralized control, the SDN controller can uniformly manage and issue flow tables and policies, avoiding the complexity and inconsistency of decentralized device configuration in traditional networks, and reducing management costs and error probabilities; judging service packets based on a preset flow table mechanism, and triggering a service information acquisition instruction when the preset flow table mechanism is met; acquiring service information of service packets in response to the service information acquisition instruction; when it is determined according to the service information that the service packet is a packet that requires path control, calling a target policy from at least two preset policies. Only qualified service packets will acquire service information and select a target policy according to the service information. This intelligent judgment and policy selection mechanism can provide precise path control for packets according to different service requirements and network conditions, improving the utilization rate of network resources and the quality of service of services. The existence of at least two preset policies enables the system to flexibly select appropriate policies according to different service scenarios and requirements, meeting diverse service needs; encapsulating an outer IPv6 header and an SRH SID List for a service packet based on a target SR policy, and setting an SL value at the same time to obtain an SRv6 packet, and forwarding the SRv6 packet according to the target SID list. Forwarding the SRv6 packet according to the target SID list enables the packet to be forwarded along a pre-set path, achieving precise control of the packet forwarding path and meeting the special path requirements of different services. By introducing a service gateway device between network-side edge devices (i.e., PE devices) and combining with an SDN controller for dynamic SID policy orchestration, interference of the EVPN default attached SID on SRv6 traffic is effectively avoided. Compared with traditional methods, there is no need to modify the RFC 8986 rules, and there is no need to modify the software implementation of device manufacturers one by one, with lower compatibility and implementation costs, while improving the flexibility and controllability of traffic forwarding.
[0013] The above description is only an overview of the technical solution of the present disclosure. In order to understand the technical means of the present disclosure more clearly, it can be implemented according to the content of the specification. In order to make the above and other purposes, features, and advantages of the present disclosure more obvious and understandable, the following specific preferred embodiments are given and described in detail in conjunction with the accompanying drawings. Brief Description of the Drawings
[0014] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0015] Figure 1 It is a schematic flowchart of the packet forwarding method provided in the first aspect of the embodiments of the present disclosure.
[0016] Figure 2 It is a schematic flowchart of the method for judging service packets based on a preset flow table mechanism provided in the embodiments of the present disclosure.
[0017] Figure 3 It is a schematic flowchart of the analysis and forwarding method of service packets when it is determined according to service information that the service packet is not a packet that requires path control provided in the embodiments of the present disclosure.
[0018] Figure 4 It is a schematic flowchart of the method for forwarding SRv6 packets according to a target SID list provided in the embodiments of the present disclosure.
[0019] Figure 5 It is a schematic flowchart of the deployment method of the service gateway device provided in the embodiments of the present disclosure.
[0020] Figure 6 It is a schematic flowchart of the packet forwarding method provided in the second aspect of the embodiments of the present disclosure.
[0021] Figure 7 For Figure 6 It is a schematic flowchart of the method for calling the first policy from associated policies, executing the first policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet in
[0022] Figure 8 For Figure 6 It is a schematic flowchart of the method for calling the second policy from associated policies, executing the second policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet in
[0023] Figure 9 It is a schematic diagram of the composition of the SRv6 policy and EVPN automatic SID collaborative management system in the SRv6 policy side-hanging networking scenario provided in the embodiments of the present disclosure.
[0024] Figure 10 It is a schematic diagram of the structure of a computer device provided in the embodiments of the present disclosure.
[0025] Description of the reference numerals: 100, service system; 200, service gateway device; 300, SDN controller; 400, intermediate node router; 500, tail node router; 600, side-mounted firewall. Detailed implementation manners
[0026] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0027] It should be clear that the embodiments of the present disclosure are described below through specific specific examples. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts fall within the scope of protection of the present disclosure.
[0028] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, this device and / or this method can be implemented using other structures and / or functions in addition to one or more of the aspects described herein.
[0029] It should also be noted that the drawings provided in the following embodiments only illustrate the basic concept of the present disclosure schematically. Only the components related to the present disclosure are shown in the drawings, rather than drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in its actual implementation can be an arbitrary change, and the component layout type may also be more complex.
[0030] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0031] Referring to Figure 1 , the first aspect of the present application discloses a message forwarding method, including: S100, in response to the instruction that the service message is to be forwarded, call the service gateway device to receive the service message to be forwarded.
[0032] Among them, the service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of the SID list.
[0033] In this step, the service gateway device is deployed on the service side, which can be closer to the service source, quickly receive the service message to be forwarded, reduce the delay of message transmission, and the support for the SRv6 protocol and SID list orchestration lays a foundation for subsequent flexible path control.
[0034] S200, call the SDN controller to dynamically obtain service routing information from the edge nodes of the EVPN through the EBGP protocol.
[0035] In this step, by calling the SDN controller and using the EBGP protocol to dynamically obtain service routing information from the edge nodes of the EVPN, it is possible to perceive the changes in the network topology, the changes in the link state, and the update of the routing information in real time; the SDN controller can make more reasonable path decisions based on the latest routing information, avoiding forwarding errors caused by using outdated routing information.
[0036] In this embodiment, at least two SR policies are configured in the SDN controller; at least two SR policies include the mapping relationship between different types of service messages and the SRH SID list (i.e., the SRv6 SRH SID lis); among them, different types of service messages are messages corresponding to different service requirements.
[0037] In this embodiment, the SDN controller supports the multi-tenant scenario and can generate different SID policies according to the tenant's needs. For example, in the first type of scenario, it is required that the service message passes through the firewall, and the corresponding SID list is: [SID1, SID2, end.dx4 corresponding to SID1], and the service gateway device ensures that this order is not affected by the EVPN and PE1 forwards correctly.
[0038] In the second type of scenario, it is required that the service message directly enters the public network without passing through the firewall check. The SID list is: [SID1, SID2, end.dt4 corresponding to SID2].
[0039] In the multi-tenant scenario, the traffic of different tenants passes through different firewall policies; through the configuration in the SDN controller, the SID list can be dynamically adjusted. For example, for tenant A: [SID1, SID2, end.dx4 corresponding to SID3], and for tenant B: [SID1, SID2, end.dx4 corresponding to SID4].
[0040] A variety of preset policies can be pre-configured in the SDN controller, and these policies can be added, modified or deleted at any time as needed; when new business needs or network policies emerge, only the corresponding configuration needs to be made in the SDN controller, and then the updated policies can be sent to the business gateway device through the API interface, without the need for large-scale transformation of the entire network, which enhances the scalability of the network.
[0041] As for S200, as long as the SDN controller establishes an EBGP protocol neighbor, it can be triggered to execute. This step can be after S100 or before S100.
[0042] S300, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two preset policies in the SDN controller to the service gateway device through an API interface.
[0043] Specifically, it includes: 1) converting the service routing information into a target flow table in the SDN controller according to the docking protocol; 2) determining the policy associated with the service attribute of the service message from several policies configured by the SDN controller according to the service needs of the message to be forwarded, as at least two preset policies to be sent to the service gateway device; 3) the SDN controller sends the target flow table and at least two preset policies to the service gateway device through the API interface.
[0044] In this embodiment, the at least two preset policies are policies associated with the service attributes of the service message determined from the at least two SR policies.
[0045] At least two preset policies include a default policy and at least one target policy. The default policy matches the default attributes of the service message through the default route. The last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN. The target policy is a detailed policy after modifying the SR policy and SID list according to the preset path requirements of the service message.
[0046] It should be noted that the delivery of the target flow table can be automatically triggered by a set period or increment.
[0047] This step includes determining policies associated with the service attributes of the service message according to the service requirements of the service message, that is, selecting these associated policies as at least two preset policies to be issued in the SDN controller.
[0048] In this embodiment, compared with the forwarding mechanism of SRv6 traffic in the prior art, the first node is changed from an intermediate router to a deployed service gateway device. The service gateway device receives the information sent by the SDN controller, and it is not allowed to autonomously insert any other SIDs into the SID List in the service gateway device.
[0049] In this embodiment, the SDN controller can modify and delete the policies that have been sent to the service gateway through the API, and batch deletion is supported.
[0050] Convert the service routing information into a target flow table, so that the service gateway device can forward packets according to the flow table rules; sending preset policies allows the service gateway device to select appropriate policies for path control according to different situations, improving the flexibility and manageability of the network.
[0051] S400, judge the service packets based on the preset flow table mechanism. When the preset flow table mechanism is met, trigger the service information acquisition instruction.
[0052] Preliminarily judge the service packets through the preset flow table mechanism. Only the packets that meet specific conditions will trigger the service information acquisition instruction, avoiding detailed parsing and processing of all packets, reducing unnecessary calculations and resource consumption, and improving the efficiency of packet processing.
[0053] S500, respond to the service information acquisition instruction to obtain the service information of the service packets.
[0054] Among them, the service information includes one or more of the source IP address, destination IP address, DSCP value, port number, and protocol type.
[0055] Specifically, when the service gateway device receives the service information acquisition instruction, obtain the service information of the service packets through the service gateway device.
[0056] S600, when it is judged according to the service information that the service packet is a packet that needs path control, call the target policy from at least two preset policies.
[0057] Among them, the target policy includes a target SR policy and a target SID list.
[0058] Judge whether the packet needs path control based on the service information, and call the target policy from multiple preset policies, so as to customize appropriate forwarding paths for different services and meet the special needs of diversified services.
[0059] In the target policy, filter and adjust the SID corresponding to end.dt4 automatically attached by EVPN to ensure that it does not affect the forwarding logic of SRv6 packets. Specifically, by adjusting the order of the SID list or adding / removing SIDs in the SID list, combined with the SRv6 policy configuration, the SID corresponding to end.dt4 is only used for traffic paths that do not need to pass through the firewall.
[0060] In this step, the service gateway device makes a judgment based on the obtained service information. For example, if the service packet is a high-priority real-time video stream and needs to pass through a specific security check node, it is determined that the packet is a packet that requires path control. Then, select the target policy suitable for the service from the preset policies issued. The target policy includes the target SR policy and the target SID list. The target SR policy defines the encapsulation rules of the packet, and the target SID list specifies the forwarding path of the packet. Selecting the appropriate target policy according to the service information can achieve fine-grained path control for different service packets, meet the special needs of different services, and improve the quality of network services.
[0061] S700, based on the target SR policy, encapsulates the outer IPv6 header and the SRH SID List for the service packet, and at the same time sets the SL value to obtain the SRv6 packet.
[0062] Specifically, in the scenario of side-hanging networking beside the firewall, encapsulating the outer IPv6 header for the service packet generates a SID list with the end.dx4 corresponding IPv6 address as the last hop.
[0063] In this step, the service gateway device adds the outer IPv6 header and the SRH (Segment Routing Header) SID List to the service packet according to the target SR policy. The outer IPv6 header contains information such as the destination address of the packet, and the SRH SIDList specifies the order of nodes that the packet needs to pass through. At the same time, set the SL (Segment Left) value. The SL value represents the number of SIDs that the packet still needs to pass through. Encapsulating the outer IPv6 header and the SRH SID List enables the packet to be forwarded according to the SRv6 protocol. By setting the SL value, the forwarding path of the packet can be controlled, and flexible routing of the packet can be achieved.
[0064] S800, forwards the SRv6 packet according to the target SID list.
[0065] Among them, the target SID list is composed of multiple SIDs arranged in a certain order, which defines the path that the packet passes from the source node to the destination node. For example, [SID1, SID2, SID3] means that the packet first passes through the resource represented by SID1, then passes through SID2, and finally reaches SID3.
[0066] Forwarding packets according to the target SID list can ensure that the packets are forwarded along the predetermined path, avoiding the path problems caused by the end.dt4 SID in the SID list automatically issued by EVPN, enabling the traffic to pass through security devices such as firewalls expected by users, and improving the network security.
[0067] Dynamically obtaining service routing information through the SDN controller, combined with the preset policy and the target flow table, can flexibly adjust the packet forwarding path according to the service requirements, effectively avoiding the problems brought by the default path, ensuring that the traffic can pass through specific nodes, such as firewalls, as expected by users, and realizing the precise control of the path.
[0068] The packet forwarding method disclosed in the first aspect of this application, in response to a packet forwarding instruction, calls the service gateway device deployed on the service side to receive the service packet to be forwarded, calls the SDN controller, dynamically obtains service routing information from the edge nodes of the EVPN through the EBGP protocol, converts the service routing information into a target flow table according to the docking protocol, and issues the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface. This method enables the service gateway device to flexibly adjust the flow table and policies according to different docking protocols and service requirements, improving the adaptability and scalability of the system. As the core of centralized control, the SDN controller can uniformly manage and issue flow tables and policies, avoiding the complexity and inconsistency of decentralized device configuration in traditional networks, and reducing management costs and error probabilities; judging the service packet based on the preset flow table mechanism, and triggering a service information acquisition instruction when it meets the preset flow table mechanism; acquiring the service information of the service packet in response to the service information acquisition instruction; when judging that the service packet is a packet that requires path control according to the service information, calling a target policy from at least two preset policies. Only eligible service packets will acquire service information and select a target policy according to the service information. This intelligent judgment and policy selection mechanism can provide precise path control for packets according to different service requirements and network conditions, improving the utilization rate of network resources and the quality of service of the service. The existence of at least two preset policies enables the system to flexibly select appropriate policies according to different service scenarios and requirements, meeting diverse service needs; encapsulating an outer IPv6 header and an SRH SIDList for the service packet based on the target SR policy, and setting the SL value at the same time to obtain an SRv6 packet, and forwarding the SRv6 packet according to the target SID list. Forwarding the SRv6 packet according to the target SID list enables the packet to be forwarded along a pre-set path, achieving precise control of the packet forwarding path and meeting the special path requirements of different services. By introducing a service gateway device between network-side edge devices (i.e., PE devices) and combining with the SDN controller for dynamic SID policy orchestration, the interference of the EVPN default attached SID to SRv6 traffic can be effectively avoided. Compared with traditional methods, it is not necessary to modify the RFC 8986 rules, and it is not necessary to modify the software implementation of device manufacturers one by one, with lower compatibility and implementation costs, while improving the flexibility and controllability of traffic forwarding.
[0069] The packet forwarding method disclosed in this application can solve the problem that in complex service scenarios, due to the mandatory inclusion of the end.dt4 SID in the SID list automatically issued by EVPN, traffic cannot pass through the firewall expected by the user, ensuring that traffic can be forwarded along the path expected by the user and undergo necessary security checks; by dynamically obtaining service routing information through the SDN controller and issuing preset policies and target flow tables, the service gateway device can perform flexible path control according to different service requirements and network conditions, improving the network manageability; selecting appropriate target policies according to service information and performing refined path control on different service packets can meet the special requirements of different services, improve the network service quality, and ensure the normal operation of high-priority services.
[0070] Referring to Figure 2 , in S400, "judging the service packet based on the preset flow table mechanism, and triggering the service information acquisition instruction when it conforms to the preset flow table mechanism", that is, the method of judging the service packet based on the preset flow table mechanism includes: S410, calling the service gateway device to receive the service packet to be forwarded and obtaining the destination IP address of the service packet.
[0071] S420, obtaining the target entry corresponding to the target flow table based on the destination IP address.
[0072] Among them, the target flow table stores the entry information corresponding to different destination IP addresses.
[0073] By searching for the target entry based on the destination IP address, the forwarding rule related to the packet can be quickly located, improving the efficiency of packet processing. At the same time, this method enables the service gateway device to forward packets according to the pre-configured flow table rules, ensuring the accuracy and consistency of forwarding.
[0074] S430, judging whether the target entry is complete. If it is, trigger the service information acquisition instruction; if not, report the destination IP address to the SDN controller and initiate a query request.
[0075] Specifically, a complete target entry should contain all the key information required for forwarding. In this embodiment, a complete target entry refers to that it must contain the destination IP address, the next-hop address, and the outgoing interface name. If the entry lacks the next-hop address information, it is considered that the target entry is incomplete. At this time, the service gateway device will report the destination IP address to the SDN controller and send a query request to inquire about the complete forwarding information of the destination IP address. If the target entry contains all the necessary information, the service information acquisition instruction is triggered and the next step of processing is entered.
[0076] Judging the integrity of the target entry can ensure that the business gateway device has sufficient information when forwarding packets. When the target entry is incomplete, reporting it to the SDN controller in a timely manner and requesting a query can utilize the global information advantage of the SDN controller to obtain complete forwarding information, avoid forwarding errors caused by information loss, and improve the reliability of the system.
[0077] S440, in response to the received signal of the query request, calls the global routing information library.
[0078] Specifically, after receiving the query request sent by the business gateway device, the SDN controller will process the request and trigger the call to the global routing information library. The global routing information library is a database that stores the entire network topology and routing information. For example, after receiving a query request regarding the destination IP address, the SDN controller will search for relevant information about this IP address in the global routing information library.
[0079] The global routing information library contains the global information of the entire network. By calling this library, the SDN controller can obtain the most comprehensive and accurate routing information, which helps to solve the problem of insufficient local information of the business gateway device and provides a more reliable basis for packet forwarding.
[0080] S450, query in the global routing information library whether there is legal forwarding information corresponding to the destination IP address. If so, obtain the legal forwarding information corresponding to the destination IP address from the global routing information library and convert it into an incremental flow table; if not, generate an incremental flow table pointing to NULL0 for the destination IP address.
[0081] For example, the SDN controller queries the destination IP address X.Y 1 .Y 2 .Y 3 (where X can be any one of 1 - 255, and Y 1 、Y 2 、Y 3 can be any one of 0 - 255). If the legal forwarding information corresponding to this IP address is queried, for example, the next-hop address is x.y 1 .y 2 .y 3 (where X can be any one of 1 - 255, and y 1 、y 2 、y 3(which can be any value from 0 to 255), and the forwarding port is eth0, then these information are organized into an incremental flow table; if the legal forwarding information of the destination IP address is not queried in the global routing information database, it indicates that the IP address may be illegal or there is no corresponding reachable path in the network. At this time, the SDN controller will generate an incremental flow table pointing to NULL0 (black hole), which means the packet will be discarded.
[0082] Generate different incremental flow tables according to the query results, which can process packets reasonably. For packets with legal forwarding information, generating the corresponding incremental flow table can supplement the flow table information of the service gateway device to ensure that the packets can be correctly forwarded; for illegal or unreachable packets, generating an incremental flow table pointing to the black hole can prevent the waste of network resources and improve the security of the network.
[0083] S460, send the incremental flow table to the service gateway device through the SDN controller.
[0084] Unify the sending of the incremental flow table to the service gateway device through the SDN controller, which realizes the centralized management and configuration of the network. The service gateway device can update its flow table information in a timely manner, ensuring the consistency and accuracy of network configuration, and at the same time improving the manageability of the network.
[0085] S470, trigger a service information acquisition instruction in response to the received signal of the incremental flow table.
[0086] Specifically, after the service gateway device receives the incremental flow table sent by the SDN controller, it will send a received signal to the SDN controller. When the SDN controller receives this signal, the service gateway device triggers a service information acquisition instruction to continue the subsequent processing of the service packet. Through this step, it can be ensured that the incremental flow table has been successfully sent to the service gateway device before triggering the service information acquisition instruction, which can avoid processing errors caused by unupdated flow tables. This step ensures the coherence and reliability of the entire processing flow.
[0087] Refer to Figure 3 , when it is determined according to the service information that the service packet is not a packet that needs to perform path control, the analysis and forwarding method of the service packet includes: A100, call the default policy from at least two preset policies, and the default policy includes the default SR policy and the default SID list; A200, trigger the execution based on the default SR policy to generate an encapsulated SRv6 packet according to the end.dt4 SID automatically attached by EVPN.
[0088] A300, forward the SRv6 packet based on the default SID list.
[0089] In an SRv6 VPN network environment deployed based on EVPN, when the tail node of SRv6 sends service routes (i.e., VPN routes) to the head node, it needs to attach the SID corresponding to end.dt4. This SID can be automatically generated by the tail node router or manually configured through opcode. When the tail node transmits the route to the head node through the EVPN protocol, it will automatically attach this SID. When the head node performs SRv6 packet encapsulation, it will list this SID as the last hop in the SRH SID list.
[0090] Regarding subsequent forwarding instructions: According to the requirements of the RFC 8986 protocol rules, after the SRv6 packet encapsulated by the head node arrives at the tail node, the tail node only forwards according to the forwarding policy corresponding to the last hop SID. The forwarding policy of end.dt4 can only be set for VPN and cannot set the next hop and outgoing interface, so it is impossible to forward the packet to the firewall as needed.
[0091] In this embodiment, invoking the default policy can simplify the processing flow of packet forwarding. For packets that do not require special path control, the default policy is directly used for processing, reducing additional judgment and configuration steps and improving processing efficiency. At the same time, the existence of the default policy provides a unified and standardized forwarding method for the network, ensuring the stability and consistency of the network.
[0092] After the service gateway device invokes the default SR policy, it will operate according to the end.dt4 SID automatically attached by EVPN. The end.dt4 SID is a specific type of SID used to identify the function of Ethernet termination and three-layer forwarding in an SRv6 (Segment Routing over IPv6) network. The service gateway device will encapsulate this SID and other necessary information into the outer layer of the service packet to generate an SRv6 packet. For example, it will add information such as an outer IPv6 header, SRH (Segment Routing Header), and SID List to the packet to complete the packet encapsulation. Using the end.dt4 SID automatically attached by EVPN for packet encapsulation fully combines the advantages of EVPN and SRv6 technologies. EVPN provides flexible network virtualization and multi-tenant support, while SRv6 realizes efficient path orchestration and forwarding. In this way, while ensuring network flexibility, the efficiency and scalability of packet forwarding can be improved. In addition, the unified encapsulation method also facilitates network devices to process and identify packets.
[0093] Forwarding packets based on the default SID list can achieve fast and accurate packet forwarding; the default SID list predefines the packet forwarding path, avoiding hop-by-hop routing lookups in the network and reducing forwarding latency. At the same time, this method also facilitates network administrators to monitor and manage network traffic, because the packet forwarding path can be changed by adjusting the default SID list.
[0094] In this embodiment, the target flow table and at least two preset policies are both stored in the target database of the service gateway device, that is, the information sent by the SDN controller to the service gateway device through the API interface is all sent to the target database of the service gateway device.
[0095] Among them, when it is determined according to the service information that the service packet is a packet that needs path control, the target policy is called from the target database; when it is determined according to the service information that the service packet is not a packet that needs path control, the default policy is called from the target database.
[0096] In the computer field, the default policy refers to a default policy. When the user does not set or specify a specific option or value, the computer system will operate according to the preset default value. For example, in the configuration of the operating system, the settings of software applications, or the parameter configuration of network devices, the application of default values is involved, which can ensure the stable operation of the system in various situations; when encountering a situation where no clear specification is made, using the default value can simplify the operation process and improve efficiency and convenience.
[0097] Refer to Figure 4 , for the method of forwarding SRv6 packets according to the target SID list in S800, it includes: S810, sending the SRv6 packet to the intermediate node through the service gateway device.
[0098] The intermediate node is a router with the role of an intermediate node.
[0099] S820, replacing the destination IP of the outer IPv6 header of the SRv6 packet according to the SRH SID List, and at the same time reducing the SL value by n 1s to obtain the processed SRv6 packet, and sending it to the tail node.
[0100] Among them, n is the number of intermediate nodes.
[0101] In this embodiment, the intermediate node dynamically replaces the destination IP of the outer IPv6 header and adjusts the SL value according to the SRH SID List, realizing the per-hop forwarding of SRv6 packets. This method enables the packets to be accurately transmitted in the network according to the pre-planned path, improving the flexibility and scalability of the network; by reducing the SL value, the node can know the number of hops the packet has passed through, which helps to control the packet forwarding process and avoid problems such as loops.
[0102] S830, the tail node forwards the processed SRv6 packet to the side-mounted firewall according to the destination SID list.
[0103] Among them, the destination SID list includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address.
[0104] S840, the firewall performs a security check on the processed SRv6 packet and forwards the packet that passes the security check to the public network exit corresponding to the public network exit router.
[0105] When the packet reaches the tail node, SL = 0, and the tail node forwards it according to the forwarding policy configured by its opcode. In this embodiment, the forwarding policy of end.dx4 set by the corresponding opcode includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address, which can accurately direct the traffic to the side-mounted firewall.
[0106] Specifically, after receiving the processed SRv6 packet, the firewall can check the packet according to the pre-configured security policy. For example, the firewall checks information such as the source IP address, destination IP address, and port number of the packet to determine whether the packet complies with the security rules; if the packet passes the security check, the firewall forwards the packet to the public network exit corresponding to the public network exit router, enabling the packet to enter the public network for further transmission. The security check of the firewall provides important security protection for the network. It can prevent illegal network traffic from entering the enterprise network, prevent security incidents such as network attacks and data leakage, and ensure the normal operation of legitimate network communications by forwarding the packets that pass the security check to the public network exit, improving the security and reliability of the network.
[0107] Refer to Figure 5 , the deployment method of the service gateway device in this application includes: B100, determine the service gateway device. The physical form of the service gateway device is a general computing power server or a programmable network device. The service gateway device supports the SRv6 protocol and supports the orchestration of the SID list.
[0108] Selecting a business gateway device with an appropriate physical form can meet the diverse needs of different enterprises. General computing power servers have powerful computing capabilities and flexibility, enabling complex business processing and function expansion; programmable network devices provide higher flexibility and customizability at the network level, supporting the SRv6 protocol and SID list orchestration, and laying a foundation for implementing SRv6-based path control and traffic forwarding.
[0109] For B200, deploy the business gateway device on the service side and connect the business gateway device to the SDN controller through the API.
[0110] Deploying the business gateway device on the service side can reduce the transmission delay of service traffic and improve the efficiency of business processing; connecting to the SDN controller through the API enables centralized management and control of the business gateway device. The SDN controller can dynamically send control instructions to the business gateway device according to the real-time state of the network and business requirements, adjust the SID list and forwarding policies, enhancing the flexibility and manageability of the network.
[0111] For B300, configure the connection between the SDN controller and the edge node of the EVPN.
[0112] Configuring the connection between the SDN controller and the EVPN edge node can achieve the integration of SDN technology and EVPN technology; the SDN controller can obtain the topology information and service status of the EVPN network, thus better performing path planning and traffic scheduling. At the same time, through the centralized management of the SDN controller, the configuration and maintenance process of the EVPN network can be simplified, improving the reliability and scalability of the network.
[0113] For B400, set the business gateway device as the gateway of the business system.
[0114] In an enterprise's business system, such as an ERP system, CRM system, etc., configure the IP address of the business gateway device as the default gateway of the business system. Taking a Windows server as an example, in the network settings of the server, set the default gateway address to the IP address of the business gateway device. In this way, all external network traffic generated by the business system will be forwarded through the business gateway device.
[0115] Setting the business gateway device as the gateway of the business system enables the traffic of the business system to be uniformly processed through the business gateway device; the business gateway device can monitor, filter, and optimize the business traffic, ensuring the network security and performance of the business system; at the same time, through the unified forwarding of the business gateway device, it is convenient to conduct centralized management and analysis of the business traffic.
[0116] For B500, configure the communication connection between the business gateway device and the intermediate router.
[0117] Configuring the communication connection between the service gateway device and the intermediate router ensures the smooth transmission of service traffic in the enterprise network. The intermediate router can act as a bridge between the service gateway device and other network nodes, expanding the coverage of the service gateway device. At the same time, by reasonably configuring the routing protocol, network load balancing and failover can be achieved, improving the reliability and availability of the network.
[0118] In a second aspect, the present application discloses a packet forwarding system for executing the packet forwarding method disclosed in the first aspect of the present application. The system specifically includes: A deployment module for deploying a service gateway device on the service side, completely separating the forwarding plane from the control plane. The service gateway device supports the SRv6 protocol and supports the orchestration of the SID list; An SDN controller module for dynamically obtaining service routing information from the edge nodes of the EVPN through the EBGP protocol, converting the service routing information into a target flow table according to the docking protocol, and sending the target flow table and at least two preset policies that have been configured to the service gateway device through the API interface; An invocation module for, in response to a packet to-be-forwarded instruction, invoking the service gateway device to receive the service packet to be forwarded; A trigger execution module for judging the service packet based on a preset flow table mechanism. When it conforms to the preset flow table mechanism, triggering a service information acquisition instruction and acquiring the service information of the service packet in response to the service information acquisition instruction; An invocation module for invoking a target policy from at least two preset policies when it is judged according to the service information that the service packet is a packet that requires path control; the target policy includes a target SR policy and a target SID list; An encapsulation module for encapsulating an outer IPv6 header and an SRH SID List for the service packet based on the target SR policy, and at the same time setting the SL value to obtain an SRv6 packet; A forwarding module for forwarding the SRv6 packet according to the target SID list.
[0119] The packet forwarding system disclosed in the present application further includes a first configuration module and a second configuration module; The first configuration module is used to configure at least two SR policies in the SDN controller; the at least two SR policies include the mapping relationship between different types of service packets and the SRH SID list (i.e., the SRv6 SRH SID lis); The second configuration module is used to determine a policy associated with the service attributes of service packets from at least two SR policies; the at least two preset policies include a default policy and at least one target policy. The default policy matches the default attributes of service packets through a default route, and the last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN. The target policy is a detailed policy that includes a modified target SR policy and a target SID list.
[0120] Referring to Figure 6 , thirdly, the present application discloses a packet forwarding method, including: S10, deploying a service gateway device on the service side.
[0121] Among them, the service gateway device supports the SRv6 protocol and supports the orchestration of the SID list.
[0122] Deploying the service gateway device on the service side can reduce the transmission distance of service packets in the network, reduce transmission latency, and improve the service response speed. Supporting the SRv6 protocol and SID list orchestration enables the service gateway device to flexibly perform path planning and traffic scheduling for packets, enhancing the flexibility and scalability of the network.
[0123] S20, in response to a packet to be forwarded instruction, invoking the service gateway device to receive the service packet to be forwarded.
[0124] Specifically, when a service server within an enterprise needs to send data to an external network, a packet to be forwarded instruction will be generated; after receiving this instruction, the service gateway device starts to monitor the network port where the service server is located and receives the service packet to be forwarded. Through the service gateway device, the packet to be forwarded instruction can be timely responded to, ensuring the timely reception of service packets, avoiding the loss and backlog of packets, and guaranteeing the normal operation of services.
[0125] S30, invoking the SDN controller to dynamically obtain service routing information from the edge nodes of EVPN through the EBGP protocol, and converting the service routing information into a target flow table according to the docking protocol.
[0126] Specifically, the SDN controller can periodically send a routing information request to the edge nodes of EVPN, and the edge nodes of EVPN will send the service routing information they have mastered to the SDN controller through the EBGP protocol. After receiving these routing information, the SDN controller converts them into a target flow table according to the docking protocol with the service gateway device.
[0127] S40, according to the service attributes of the packet to be forwarded, obtaining the policy associated with the service attributes from the SDN controller, and sending the target flow table and the associated policy to the service gateway device through the API interface.
[0128] Among them, when the EBGP neighbor between the SDN controller and the edge node of EVPN is established, it is possible to execute the dynamic acquisition of routing information from the edge node of EVPN through the EBGP protocol, convert the routing information into a target flow table according to the docking protocol, and then the operation of issuing can be automatically triggered periodically or incrementally, that is, the target flow table is issued to the service gateway device through the standard API interface.
[0129] Obtaining the associated policy according to the service attribute realizes the differential processing of different service packets; issuing the target flow table and the policy to the service gateway device enables the service gateway device to forward packets according to specific service requirements and network status, improving the intelligent and refined management level of the network.
[0130] S50, judging the service packet based on the preset flow table mechanism, and triggering the service information acquisition instruction when it meets the preset flow table mechanism.
[0131] The preset flow table mechanism can preliminarily screen the service packets, and only further process the packets that meet specific conditions, reducing unnecessary service information acquisition operations and improving the processing efficiency.
[0132] S60, acquiring the service information of the service packet in response to the service information acquisition instruction.
[0133] S70, judging whether the service packet is a packet that needs path control according to the service information. If not, calling the first policy from the associated policies, executing the first policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet; If so, calling the second policy from the associated policies, executing the second policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet.
[0134] In this embodiment, the associated policies are stored in the target database of the service gateway device.
[0135] Judging the path control according to the service information and forwarding the packets by using different policies realizes the optimized processing of different types of service packets; for the packets that need path control, it can provide better network services to meet the special needs of the service; for the packets that do not need path control, the default policy is used for forwarding, ensuring the basic performance and efficiency of the network.
[0136] Referring to Figure 7 , the method of calling the first policy from the associated policies, executing the first policy to obtain the encapsulated SRv6 packet and forwarding the SRv6 packet includes: A10, calling the first policy from the target database, and the first policy includes a default SR policy and a default SID list.
[0137] The default policies have been pre-tested and verified to provide a stable operating environment for the network. In most cases, these default policies can meet the basic business requirements and reduce the risk of network failures caused by incorrect policy configurations.
[0138] A20, trigger the execution based on the default SR policy to generate an encapsulated SRv6 packet according to the end.dt4 SID automatically attached by EVPN.
[0139] EVPN (Ethernet Virtual Private Network) can automatically attach the end.dt4 SID, which means that network devices do not need to perform a large number of manual configurations. This automation feature reduces the possibility of human errors, speeds up the packet encapsulation process, and improves the efficiency of network deployment. The end.dt4 SID is a standardized mechanism that has good compatibility with the SRv6 (Segment Routing over IPv6) network architecture. By leveraging this feature of EVPN, it can be ensured that the generated SRv6 packets can be smoothly transmitted between network devices of different vendors, enhancing the network interoperability. The default SR policy combined with the end.dt4 SID can flexibly encapsulate packets according to the actual situation of the network. It can add necessary information to the packets based on the network topology and business requirements, enabling the packets to accurately find the forwarding path in the SRv6 network.
[0140] A30, forward the SRv6 packet based on the default SID list.
[0141] The default SID list defines the forwarding path of the packets. Network devices can directly forward the SRv6 packets to the corresponding destinations based on the information in the list. This list-based forwarding method avoids complex routing calculations, reduces the delay in the packet forwarding process, and improves the forwarding efficiency. The default SID list is usually planned according to the overall situation of the network and resource allocation. By forwarding packets according to this list, the network bandwidth and device resources can be reasonably utilized, avoiding congestion on certain links or devices due to overuse.
[0142] Refer to Figure 8 , a method for invoking a second policy from associated policies, executing the second policy to obtain an encapsulated SRv6 packet and forwarding the SRv6 packet, including: B10, invoke the second policy from the target database, where the second policy is a detailed policy obtained by modifying the SR policy and the SID list according to the preset path requirements of the service packets; B20. Encapsulate the outer IPv6 header and SRH SID List for the service packet according to the SR policy in the second policy, and at the same time set the SL value to obtain the SRv6 packet.
[0143] Among them, the SL (Segment Left) value is used to indicate the segments that the SRv6 packet needs to pass through, that is, the SL value represents how many segments the packet still needs to pass through to reach the destination; the SL value is the total number of segments in the SID List minus 1.
[0144] B30. Send the SRv6 packet to the intermediate node through the service gateway device according to the SID list in the second policy.
[0145] B40. The intermediate node replaces the destination IP of the outer IPv6 header of the SRv6 packet according to the SRH SID List, and at the same time reduces the SL value by n 1s to obtain the processed SRv6 packet, and sends it to the tail node.
[0146] Among them, n is the number of intermediate nodes; B50. The tail node forwards the processed SRv6 packet to the firewall attached on the side according to the target SID list; the target SID list includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address.
[0147] B60. Perform a security check on the processed SRv6 packet through the firewall, and forward the packet that passes the security check to the public network exit corresponding to the public network exit router.
[0148] The overall solution executes and forwards the SRv6 packet by invoking the second policy. From policy invocation, packet encapsulation to finally passing through the firewall check and forwarding to the public network exit, each step is closely coordinated. From a business perspective, the second policy is a detailed policy obtained by modifying the SR policy and SID list according to the preset path requirements of the service packet. This enables the network to tailor exclusive forwarding paths for different business special requirements, such as video conferencing services with high real-time requirements and file transfer services with large bandwidth requirements, greatly improving the operation effect of the service; when network failures or traffic congestion occur, the SR policy and SID list in the second policy can be adjusted to quickly re-plan the path for the service packet, avoid service interruption, and ensure the continuous and stable operation of critical services.
[0149] From the perspective of network performance, encapsulating the outer IPv6 header and SRH SID List for packets based on the SR policy and setting the SL value clarifies the precise forwarding path of the packets. Intermediate nodes only need to perform simple operations based on this information without complex routing calculations, greatly improving the packet forwarding efficiency and reducing the transmission delay. By reasonably designing the SID list, network traffic can be evenly distributed to different links and nodes, avoiding congestion on some links or nodes due to overloading, and enhancing the throughput and performance of the entire network.
[0150] From the perspective of network management, all policies are stored in the target database. Network administrators can manage, modify, and update policies in a unified location, with simple operations, reducing management costs and workload. When the network scale expands or business requirements change, only the second policy in the target database needs to be adjusted, without the need for large-scale transformation of the entire network architecture, facilitating network expansion and upgrade.
[0151] From the security perspective, forwarding the processed SRv6 packets to the side-mounted firewall for security inspection can effectively filter malicious traffic such as viruses, Trojans, DDoS attacks, etc., protecting the internal network from external threats and providing strong security for the network. The target SID list specifies a specific vpn-instance, which can isolate packets of different services in different virtual private networks, preventing interference and data leakage between different services, and further enhancing network security and privacy.
[0152] From the compatibility perspective, as a standardized network technology, SRv6 has good compatibility with existing IPv6 networks. This solution is designed based on SRv6 and can be easily integrated into existing network infrastructure, reducing the cost of network upgrade and transformation.
[0153] Fourthly, this application discloses a packet forwarding system, which is based on the packet forwarding method disclosed in the third aspect of this application and includes: A service gateway device invocation module, which is used to respond to a packet forwarding instruction and invoke the service gateway device to receive service packets to be forwarded. The service gateway device is deployed on the service side and supports the SRv6 protocol and the orchestration of the SID list; An SDN controller invocation module, which is used to invoke the SDN controller to dynamically obtain service routing information from the edge nodes of the EVPN through the EBGP protocol; A distribution module, which is used to convert the service routing information into a target flow table according to the docking protocol, and distribute the target flow table and at least two preset policies in the SDN controller to the service gateway device through the API interface; A judgment module, configured to judge service packets based on a preset flow table mechanism, and trigger a service information acquisition instruction when the preset flow table mechanism is met; An information acquisition module, configured to acquire service information of a service packet in response to the service information acquisition instruction; An analysis module, configured to judge whether the service packet is a packet that needs path control according to the service information. If not, call a first policy from at least two preset policies, execute the first policy to obtain an encapsulated SRv6 packet, and forward the SRv6 packet; if so, call a second policy from at least two preset policies, execute the second policy to obtain an encapsulated SRv6 packet, and forward the SRv6 packet.
[0154] In a fifth aspect, the present application discloses a collaborative management system for SRv6 policies and EVPN automatic SIDs, including a service system, a service gateway device, an SDN controller, several intermediate node routers, an egress node router, and a side-mounted firewall. The service system is communicatively connected to the service gateway device, and the SDN controller is communicatively connected to one or more of the several intermediate node routers; one or more of the several intermediate node routers are communicatively connected to the egress node router; the egress node router is communicatively connected to the side-mounted firewall.
[0155] Among them, the service system is used to initiate a packet forwarding instruction.
[0156] The SDN controller is configured to configure at least two SR policies and policies associated with the service attributes of the packet to be forwarded, dynamically acquire service routing information from the intermediate node router corresponding to EVPN through the EBGP protocol, convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and the associated policies to the service gateway device through the API interface.
[0157] The service gateway device is configured to judge the received service packet based on a preset flow table mechanism, acquire the service information of the service packet when the preset flow table mechanism is met, judge whether the service packet is a packet that needs path control according to the service information, and trigger the execution of corresponding policies according to different judgment results.
[0158] Refer to Figure 9, the figure shows a schematic diagram of the collaborative management system of SRv6 policy and EVPN automatic SID in the firewall bypass networking scenario. After all connections of the service gateway device are deployed, when the EBGP neighbor of the SDN controller 300 and the edge node of the EVPN is established, it will automatically execute the dynamic acquisition of routing information from the edge node of the EVPN (in this embodiment, the intermediate node router 400) through the EBGP protocol, and convert the routing information into a flow table according to the docking protocol; then it can automatically trigger the execution of the distribution operation according to the set period or increment, that is, the flow table can be distributed to the target database of the service gateway device through the standard API interface.
[0159] The business system 100 wants to send a message. When receiving a message to be forwarded instruction, it calls the business gateway device 200 to receive the business message to be forwarded, and judges the business message based on the preset flow table mechanism in the business gateway device 200. When it meets the preset flow table mechanism, it triggers the business information acquisition instruction, which specifically includes: obtaining the destination IP address of the business message, obtaining (i.e., querying) the target table entry corresponding to the target flow table based on the destination IP address, and judging whether the target table entry is complete (i.e., whether there is a destination IP address, a next-hop address, and an outbound interface name). If so, triggering the business information acquisition instruction; if not, the destination IP The address is reported to the SDN controller 300, and a query request is initiated; the SDN controller responds to the received signal of the query request, calls the global routing information base, and then queries whether there is legal forwarding information corresponding to the destination IP address in the global routing information base. If so, the legal forwarding information corresponding to the destination IP address is obtained from the global routing information base and converted into an incremental flow table; if not, an incremental flow table pointing to NULL0 (black hole) is generated for the destination IP address, and the incremental flow table is sent to the service gateway device through the SDN controller. The service gateway device responds to the received signal of the incremental flow table and triggers the service information acquisition instruction.
[0160] In the service gateway device, in response to the service information acquisition instruction, the service information of the service message is obtained, and whether the service message is a message that needs path control is determined according to the service information. If so, a target policy is called from at least two preset policies, and the target policy includes a target SR policy and a target SID list. Based on the target SR policy, an outer IPv6 header and an SRH SID List are encapsulated for the service message, and an SL value is set at the same time to obtain an SRv6 message; Then, forward the SRv6 packets according to the target SID list, specifically: send the SRv6 packets to the intermediate node router 400 through the service gateway device. The intermediate node router replaces the destination IP of the outer IPv6 header of the SRv6 packet according to the SRH SID List, and at the same time reduces the SL value by n 1s to obtain the processed SRv6 packet, and sends it to the tail node router 500; where n is the number of intermediate nodes; the tail node router forwards the processed SRv6 packet to the side-mounted firewall 600 according to the target SID list; the target SID list includes specifying a specific vpn-instance, the outgoing interface name, and the next-hop IP address; perform a security check on the processed SRv6 packet through the side-mounted firewall 600, and forward the packets that pass the security check to the public network egress router (i.e., the tail node router 500), and forward them to the corresponding public network egress ISP through the public network egress router (i.e., the tail node router 500).
[0161] In the side-mounted networking scenario, the public network egress router and the SRv6 tail node router are the same network device.
[0162] In the prior art, in order to reduce the operation and maintenance difficulty and configuration complexity, the firewall is often connected in series in the network, such as between different routers, or between the egress router and the operator router, or between the router and the switch. However, such a setting is not convenient for the horizontal expansion of the firewall, and will make the firewall become the bandwidth bottleneck of the entire network, resulting in slow network speed; therefore, in order to enable the capacity of the firewall to be smoothly horizontally expanded and to bypass the firewall for traffic in necessary cases, the side-mounted setting of the firewall is proposed. However, in the side-mounted setting, the traffic of the router needs to be diverted to the firewall. The current mainstream solution is to divert traffic through policy routing, which is complex to set up and operate. Therefore, SRv6 technology is used for diversion.
[0163] However, after adopting the SRv6 technology, in the business scenario, the user's expectation is that the traffic starts from the source node, passes through the SRv6 path, and at a certain node, the traffic is directed to the firewall using the end.dx4 SID. After the firewall processes the traffic, it then enters the public network egress. However, since the SID list automatically distributed by EVPN compulsorily includes the end.dt4 SID, and the end.dt4 SID is usually the last hop of the SID list (that is, according to the specification of RFC 8986, the role of the end.dt4 SID is to redirect the traffic from the IPv6 domain to the IPv4 domain, so it is usually placed at the end of the SID list), the actual path of the traffic becomes: the traffic passes through the SRv6 path. Since the end.dt4 SID is placed at the end, the traffic is directly directed to the public network egress without passing through the firewall expected by the user. Therefore, this causes the traffic not to pass through the security check of the firewall, and the functions of the firewall (such as intrusion detection, policy filtering, etc.) cannot take effect, and the end.dx4 SID set by the user does not play the expected forwarding role.
[0164] The packet forwarding method disclosed in this application has good flexibility. By flexibly combining service characteristics and the SID list on the SDN control, SRv6 policies suitable for various scenarios and meeting various requirements can be flexibly combined. Based on the SRv6 policies, flexible control of the traffic forwarding path can be achieved, avoiding the problem that the default and unchangeable rules of control layer protocols such as EVPN lead to uncontrollable traffic forwarding paths.
[0165] The packet forwarding method disclosed in this application has good compatibility. This solution does not need to modify the protocol specification of RFC 8986, nor does it need to modify the implementation methods of the operating systems (OS) of each device manufacturer, and can be compatible with different manufacturers and different models of communication devices that support SRv6.
[0166] The packet forwarding method disclosed in this application has high reliability. The SDN controller and the EVPN edge node synchronize routes in real time through EBGP. At the same time, a dual query confirmation mechanism is set between the service gateway and the SDN controller to ensure information synchronization between the service gateway and the SDN controller, avoid the occurrence of unreasonable traffic black holes, and improve the overall reliability of the system.
[0167] The computer device according to the embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-temporary computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0168] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the computer device executes all or part of the steps of the message forwarding method according to the various embodiments of the present disclosure described above.
[0169] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain a good user experience effect, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included in the protection scope of the present disclosure.
[0170] As Figure 10 FIG. is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of a computer device suitable for implementing the computer device in the embodiments of the present disclosure. Figure 10 The shown computer device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0171] As Figure 10 As shown, the computer device may include a processor (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) or a program loaded from a storage device into a random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.
[0172] Generally, the following devices may be connected to the I / O interface: an input device including, for example, a sensor or a visual information acquisition device; an output device including, for example, a display screen; a storage device including, for example, a magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the computer device to communicate with other devices (such as edge computing devices) wirelessly or wireline to exchange data. Although Figure 10 the shown computer device has various devices, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0173] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the message forwarding method according to the embodiments of the present disclosure are executed.
[0174] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not described herein again.
[0175] A computer-readable storage medium according to an embodiment of the present disclosure stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are run by a processor, all or part of the steps of the message forwarding methods according to the foregoing embodiments of the present disclosure are executed.
[0176] The above-mentioned computer-readable storage media include but are not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or external hard drives), media with built-in rewritable non-volatile memories (such as memory cards), and media with built-in ROMs (such as ROM cartridges).
[0177] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not described herein again.
[0178] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-mentioned specific details are only for illustrative and easy-to-understand purposes and not for limitation, and the above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.
[0179] In this disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0180] In addition, as used herein, "or" in the listing of items starting with "at least one" indicates a disjunctive listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the wording "exemplary" does not mean that the examples described are preferred or better than other examples.
[0181] It should also be noted that in the systems and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.
[0182] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.
[0183] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0184] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those of ordinary skill in the art will recognize some variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A message forwarding method, characterized in that: include: In response to a message to be forwarded instruction, calling a service gateway device to receive a service message to be forwarded; the service gateway device is deployed on the service side and supports the SRv6 protocol and the arrangement of the SID list; Call the SDN controller to dynamically obtain service routing information from the edge node of EVPN through the EBGP protocol; Convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and at least two preset policies in the SDN controller to the service gateway device through an API interface; The service message is judged based on a preset flow table mechanism, and when it meets the preset flow table mechanism, a service information acquisition instruction is triggered; Acquire the service information of the service message in response to the service information acquisition instruction; When it is determined according to the service information that the service message is a message that needs path control, a target strategy is called from the at least two preset strategies; the target strategy includes a target SR strategy and a target SID list; Based on the target SR policy, encapsulate the service message with an outer IPv6 header and an SRH SID List, and set an SL value to obtain an SRv6 message; The SRv6 message is forwarded according to the target SID list.
2. The message forwarding method according to claim 1, characterized in that: The judging the service message based on the preset flow table mechanism, and triggering the service information acquisition instruction when the service message meets the preset flow table mechanism, includes: Calling the service gateway device to receive the service message to be forwarded, and obtaining the destination IP address of the service message; Obtaining a target table entry corresponding to the target flow table based on the destination IP address; Determine whether the target entry is complete, if so, trigger a service information acquisition instruction; if not, report the destination IP address to the SDN controller and initiate a query request; In response to a received signal of the query request, calling a global routing information base; Querying whether there is legal forwarding information corresponding to the destination IP address in the global routing information base, if so, obtaining the legal forwarding information corresponding to the destination IP address from the global routing information base and converting it into an incremental flow table; if not, generating an incremental flow table pointing to NULL0 for the destination IP address; Sending the incremental flow table to the service gateway device through the SDN controller; In response to the received signal of the incremental flow table, a service information acquisition instruction is triggered.
3. The message forwarding method according to claim 1, characterized in that: The service information includes one or more of a source IP address, a destination IP address, a DSCP value, a port number, and a protocol type; When it is determined according to the service information that the service message is not a message that requires path control, calling a default policy from the at least two preset policies, the default policy including a default SR policy and a default SID list; Based on the default SR policy, trigger execution according to the end.dt4 SID automatically attached to EVPN to generate an encapsulated SRv6 message; The SRv6 message is forwarded based on the default SID list.
4. The message forwarding method according to claim 3, characterized in that: The target flow table and the at least two preset strategies are stored in a target database of the service gateway device; When it is determined according to the service information that the service message is a message that needs path control, calling a target policy from the target database; When it is determined according to the service information that the service message is not a message that requires path control, a default strategy is called from the target database.
5. The message forwarding method according to claim 4, characterized in that: At least two SR strategies are configured in the SDN controller; at least two of the SR strategies include mapping relationships between different types of service messages and SRH SID lists; The at least two preset policies are policies associated with the service attributes of the service message determined from the at least two SR policies; The at least two preset policies include a default policy and at least one target policy, the default policy matches the default attribute of the service message through a default route, and the last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN; The target policy is a detailed policy after modifying the SR policy and the SID list according to the preset path requirements of the service message.
6. The message forwarding method according to claim 1, characterized in that: S800, forwarding the SRv6 message according to the target SID list includes: Sending the SRv6 message to the intermediate node through the service gateway device; Replace the IP of the outer IPv6 header of the SRv6 message according to the SRH SID List, and reduce the SL value by n 1s to obtain the processed SRv6 message, and send it to the egress node; wherein n is the number of intermediate nodes; The tail node forwards the processed SRv6 message to the side-mounted firewall according to the target SID list; the target SID list includes a specified specific vpn-instance, an outbound interface name, and a next-hop IP address; The processed SRv6 message is subjected to a security check through the firewall, and the message that passes the security check is forwarded to the public network egress corresponding to the public network egress router.
7. The message forwarding method according to claim 1, characterized in that: The deployment method of the service gateway device includes: Determine a service gateway device, the physical form of which is a general computing server or a programmable network device, and the service gateway device supports the SRv6 protocol and supports the arrangement of SID lists; Deploy the service gateway device on the service side, and connect the service gateway device to the SDN controller through an API; Configure the connection between the SDN controller and the edge node of EVPN; Setting the service gateway device as the gateway of the service system; Configure the communication connection between the service gateway device and the intermediate router.
8. A message forwarding system, characterized in that: include: A deployment module is used to deploy a service gateway device on the service side to completely separate the forwarding plane from the control plane, wherein the service gateway device supports the SRv6 protocol and supports the arrangement of the SID list; The SDN controller module is used to dynamically obtain service routing information from the edge node of EVPN through the EBGP protocol, convert the service routing information into a target flow table according to the docking protocol, and send the target flow table and at least two configured preset policies to the service gateway device through an API interface; A calling module, used for calling a service gateway device to receive a service message to be forwarded in response to a message to be forwarded instruction; A trigger execution module, used to judge the service message based on a preset flow table mechanism, trigger a service information acquisition instruction when the service message meets the preset flow table mechanism, and acquire the service information of the service message in response to the service information acquisition instruction; A calling module, configured to call a target strategy from the at least two preset strategies when judging, according to the business information, that the business message is a message that needs path control; the target strategy includes a target SR strategy and a target SID list; An encapsulation module, configured to encapsulate an outer IPv6 header and an SRH SIDList for the service message based on the target SR policy, and set an SL value to obtain an SRv6 message; A forwarding module is used to forward the SRv6 message according to the target SID list.
9. The message forwarding system according to claim 8, characterized in that: Also includes a first configuration module and a second configuration module; The first configuration module is used to configure at least two SR strategies in the SDN controller; at least two of the SR strategies include mapping relationships between different types of service messages and SRH SID lists; The second configuration module is used to determine a policy associated with the service attribute of the service message from the at least two SR policies; the at least two preset policies include a default policy and at least one target policy, the default policy matches the default attribute of the service message through a default route, and the last hop of the SID list in the default policy is the SID corresponding to end.dt4 automatically carried by EVPN; the target policy is a detailed policy including a modified target SR policy and a target SID list.
10. A message forwarding method, characterized in that: include: Deploy service gateway equipment on the service side; The service gateway device supports the SRv6 protocol and supports the arrangement of the SID list; In response to the message to be forwarded instruction, calling the service gateway device to receive the service message to be forwarded; Call the SDN controller to dynamically obtain service routing information from the edge node of EVPN through the EBGP protocol, and convert the service routing information into a target flow table according to the docking protocol; According to the service attributes of the message to be forwarded, the policy associated with the service attribute is obtained from the SDN controller, and the target flow table and the associated policy are sent to the service gateway device through the API interface; The service message is judged based on a preset flow table mechanism, and when it meets the preset flow table mechanism, a service information acquisition instruction is triggered; Acquire the service information of the service message in response to the service information acquisition instruction; Determine whether the service message is a message that needs path control according to the service information, and if not, call a first strategy from the associated strategies, execute the first strategy to obtain an encapsulated SRv6 message and forward the SRv6 message; If so, call the second policy from the associated policies, execute the second policy to obtain the encapsulated SRv6 message and forward the SRv6 message.
11. The message forwarding method according to claim 10, characterized in that: The associated policy is stored in a target database of the service gateway device; The calling of the first policy from the associated policies, executing the first policy to obtain the encapsulated SRv6 message and forwarding the SRv6 message includes: Invoke a first policy from the target database, where the first policy includes a default SR policy and a default SID list; Based on the default SR policy, trigger execution according to the end.dt4 SID automatically attached to EVPN to generate an encapsulated SRv6 message; The SRv6 message is forwarded based on the default SID list.
12. The message forwarding method according to claim 11, characterized in that: The calling of the second policy from the associated policies, executing the second policy to obtain the encapsulated SRv6 message and forwarding the SRv6 message includes: Calling a second strategy from the target database, where the second strategy is a detailed strategy after modifying the SR strategy and the SID list according to the preset path requirement of the service message; encapsulating an outer IPv6 header and an SRH SID List for the service message according to the SR policy in the second policy, and setting an SL value to obtain an SRv6 message; The SL value is used to indicate the segment that the SRv6 message needs to pass through; Sending the SRv6 message to the intermediate node through the service gateway device according to the SID list in the second policy; Replace the IP of the outer IPv6 header of the SRv6 message according to the SRH SID List, and reduce the SL value by n 1s to obtain the processed SRv6 message, and send it to the egress node; wherein n is the number of intermediate nodes; The tail node forwards the processed SRv6 message to the side-mounted firewall according to the target SID list; the target SID list includes a specified specific vpn-instance, an outbound interface name, and a next-hop IP address; The firewall performs security checks on the processed SRv6 packets and forwards the packets that pass the security check to the public network egress corresponding to the public network egress router.
13. A collaborative management system for SRv6 policy and EVPN automatic SID, characterized in that: It includes a business system, a business gateway device, an SDN controller, several intermediate node routers, an exit node router and a side-mounted firewall, wherein the business system is communicatively connected to the business gateway device, the SDN controller is communicatively connected to one or more of the several intermediate node routers; one or more of the several intermediate node routers are communicatively connected to the exit node router; The egress node router is in communication connection with the side-mounted firewall; The business system is used to initiate a message forwarding instruction; The SDN controller is used to configure at least two SR policies and policies associated with the service attributes of the message to be forwarded, to dynamically obtain service routing information from the intermediate node router corresponding to the EVPN through the EBGP protocol, and to convert the service routing information into a target flow table according to the docking protocol and send the target flow table and the associated policies to the service gateway device through the API interface; The service gateway device is used to judge the received service message based on the preset flow table mechanism. When it meets the preset flow table mechanism, it obtains the service information of the service message, judges whether the service message is a message that requires path control based on the service information, and triggers the execution of corresponding strategies based on different judgment results.
14. A computer device, characterized in that: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the message forwarding method described in any one of claims 1-7 or any one of claims 10-12.
15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the message forwarding method described in any one of claims 1-7 or any one of claims 10-12.
16. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the steps of the method described in any one of claims 1 to 7 or any one of claims 10 to 12 are implemented.
Citation Information
Patent Citations
Message transmission method, proxy node and storage medium
CN112787931A
Message processing method, device and system
CN113162849A
Service flow forwarding method and device based on 5G core network, and equipment
CN113676959A
Message forwarding method and device and computer readable storage medium
CN118573551A
SFC path change scheme based on SRV6
CN119155244A
Cited By
Message forwarding method and device and related equipment
CN122316976A