Method and device for transmitting service in network

Through the controller, the IPSec tunnel between some network devices is reasonably and flexibly established in the network, which solves the problem of high storage and processing capabilities requirements in large-scale networks, and achieves fast and simple tunnel establishment and cost savings.

CN113472622BActive Publication Date: 2025-09-02HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010238369.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-03-30
Publication Date
2025-09-02
Estimated Expiration
2040-03-30

AI Technical Summary

Technical Problem

When using controllers to establish IPSec tunnels in large-scale networks, network devices need to save a large amount of IPSec Security Alliance (SA) parameter information, resulting in high storage and processing capabilities requirements and increasing network deployment costs.

Method used

Through the controller, IPSec tunnels between some network devices are reasonably and flexibly established in the network, and tunnels between other network devices are established only when there are business needs, reducing the need for storage and processing capabilities.

Benefits of technology

It reduces the network deployment cost, realizes the rapid and simple establishment of IPSec tunnels in the network, adapts to the characteristics of different network devices, and saves storage and processing resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113472622B_ABST
    Figure CN113472622B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses a method and device for transmitting services in a network, the method comprising: a first network device receives a first service message of a first service flow; in response to receiving the first service message, the first network device establishes a first IPSec tunnel directly connected to a second network device; then, when the first network device receives a second service message of the first service flow, the second service message can be sent to the second network device through the first IPSec tunnel. In this way, when the controller establishes an IPSec tunnel in the network, it no longer establishes a fully connected IPSec tunnel, but reasonably establishes IPSec tunnels between some network devices. IPSec tunnels between other network devices are only established when there is a service demand, which can reduce the demand for storage and processing capabilities of some network devices in the network to a certain extent, thereby effectively saving the deployment cost of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method and device for transmitting services in a network. The method is based on Internet Protocol Security (IPSec) tunnel transmission services to achieve reasonable utilization of resources on various network devices in the network. Background Art

[0002] IPSec is a set of framework protocols developed by the Internet Engineering Task Force (IETF) to ensure the security of communications on the Internet by using encrypted secure transmission channels.

[0003] Currently, establishing an IPSec tunnel through IKE negotiation requires multiple conversations between network devices, making the process complex and cumbersome for large-scale networks with numerous network devices. Therefore, a controller is used to replace the IKE protocol, enabling the establishment of IPSec tunnels between network devices. Specifically, the controller must first establish a secure channel with all network devices in the network. The controller then sends the IPSec Security Association (SA) parameters supported by each network device to other network devices in the network. Each network device then establishes an IPSec SA with all other network devices in the network, thereby establishing an IPSec tunnel between every two network devices in the network.

[0004] However, when a controller is used to establish IPSec tunnels, each network device must establish an IPSec tunnel between them. This requires each network device to store a large number of IPSec SAs. This requires all network devices deployed in the network to have strong storage and processing capabilities, resulting in high network deployment costs. Therefore, a method for transmitting services in a network that can reduce the storage and processing requirements of network devices when establishing IPSec tunnels using a controller is desired, thereby reducing network deployment costs. Summary of the Invention

[0005] Based on this, the embodiments of the present application provide a method and device for transmitting services in a network. The controller can reasonably and flexibly implement the establishment of IPSec tunnels based on the characteristics of the network equipment deployed in the network and the actual business needs, so that the network does not need to deploy all network equipment that supports strong storage and processing capabilities, thereby saving the cost of network deployment.

[0006] In the first aspect, a method for transmitting services in a network in an embodiment of the present application is implemented by a first network device. The method may include, for example: the first network device receives a first service message of a first service flow; in response to receiving the first service message, the first network device establishes a first IPSec tunnel directly connected to the second network device; then, when the first network device receives a second service message of the first service flow, it can send the second service message to the second network device through the first IPSec tunnel. In this way, when the controller establishes an IPSec tunnel in the network, it no longer establishes a fully connected IPSec tunnel, but reasonably establishes IPSec tunnels between some network devices. IPSec tunnels between other network devices are only established when there is a service demand, which can reduce the demand for storage and processing capabilities of some network devices in the network to a certain extent, thereby effectively saving the deployment cost of the network.

[0007] As an example, the first network device and the second network device may both be Spoke nodes, and the first network device and the second network device are both connected to a third network device, and the third network device may be a Hub node.

[0008] In one possible implementation, establishing a first IPSec tunnel directly connected between a first network device and the second network device may specifically include: the first network device sends a first message to a controller, the first message being used to request establishment of the directly connected first IPSec tunnel between the first network device and the second network device; the first network device receives a second message sent by the controller, the second message carrying second IPSec SA parameter information of the second network device; the first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA parameter information and the second IPSec SA parameter information stored by itself, wherein the first IPSec SA is used to securely protect messages transmitted from the first network device to the second network device, and the second IPSec SA is used to securely protect messages transmitted from the second network device to the first network device; the first network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0009] In addition, in this embodiment, after the controller receives the first message sent by the first network device, the controller can also send a third message to the second network device, where the third message carries the first IPSecSA parameter information of the first network device. The third message is used to instruct the second network device to determine the first IPSec SA and the second IPSec SA based on the second IPSec SA parameter information and the first IPSec SA parameter information stored by itself, so that the second network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0010] The first message, the second message and the third message are all Border Gateway Protocol update BGPUPDATE messages.

[0011] The first message includes the source IP address and destination IP address of the first service packet, as well as the network segment address of the local area network (LAN) to which the first network device is connected. Furthermore, the first message may include the loopback address of the first network device and / or the IP address of the wide area network (WAN) port of the first network device. The first network device may also carry the first IPSec SA of the first network device. The first message may be extended with a new extended attribute to carry the aforementioned content.

[0012] The second message may include a network layer reachability information NLRI field, the NLRI field including a tunnel type TunnelType field, an endpoint address endpoint address field and the second IPSec SA parameter information, wherein the Tunnel Type field indicates that the type of the tunnel is an IPSec tunnel, and the endpoint address field is used to carry the IP address of the second network device.

[0013] The third message may include a network layer reachability information NLRI field, the NLRI field includes a tunnel type TunnelType field, an endpoint address endpoint address field and the first IPSec SA parameter information, wherein the Tunnel Type field indicates that the type of the tunnel is an IPSec tunnel, and the endpoint address field is used to carry the IP address of the first network device.

[0014] As an example, before the first network device establishes a first IPSec tunnel directly connected to the second network device, the method may also include: the first network device sends the first service message to the second network device through a third network device, wherein the third network device is a central hub node, the first network device and the third network device are directly connected through a second IPsec tunnel, and the second network device is directly connected to the third network device through a third IPsec tunnel.

[0015] It can be seen that through this implementation, in response to business needs, the first network device can dynamically send a message to the controller to request the controller to establish a direct IPSec tunnel between it and the second network device, which can not only enable the controller to flexibly establish IPSec tunnels between network devices in the network, but also eliminate the need for complex message interactions between network devices based on the IKE protocol to establish IPSec tunnels, making the process of establishing IPSec tunnels in the network simple and fast; moreover, the controller will reasonably establish IPSec tunnels at appropriate times based on the characteristics of each network device in the network, rather than establishing a fully connected IPSec tunnel in the network, so that some network devices can choose to deploy network devices with general storage and processing capabilities, saving the cost of network deployment to a certain extent. Preferably, for Hub-Spoke traffic models such as SD-WAN, Hub nodes that support a larger number of IPSec tunnels and Spoke nodes that support a smaller number of IPSec tunnels can be deployed in the same network, and the controller can replace the IKE protocol to manage IPSec tunnels between network devices, realizing a more intelligent, convenient and fast transmission service in the network.

[0016] In another possible implementation, establishing a first IPSec tunnel directly connected to the first network device and the second network device may further include: the first network device sending a third service message to the second network device through a third network device, the third service message carrying first IPSec SA parameter information, the first IPSec SA parameter information being used to determine a first IPSec SA, the first IPSec SA being used to securely protect messages transmitted from the first network device to the second network device; wherein the first network device is directly connected to the third network device through a second IPSec tunnel, and the second network device is directly connected to the third network device through a third IPSec tunnel; then, the first network device receives a fourth service message sent by the second network device through the third network device, the fourth service message carrying second IPSec SA parameter information, the second IPSec SA parameter information being used to determine a second IPSec SA, the second IPSec SA being used to securely protect messages transmitted from the second network device to the first network device; the first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA parameter information and the second IPSec SA parameter information; then, the first network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0017] As an example, the third service packet may carry the first IPSec SA parameter information through an extended first packet header; the fourth service packet includes an extended second packet header, and the extended second packet header carries the second IPSec SA parameter information.

[0018] It can be seen that through this embodiment, in response to business needs, the network device can carry its own IPSec SA parameter information in the business message to be sent, and forward it to the opposite network device through the existing IPSec tunnel, so that the opposite network device can determine the IPSec SA based on the IPSec SA parameter information. Moreover, the opposite network device performs the same operation, realizing flexible establishment of IPSec tunnels between network devices in the network, without the need for complex message exchange between network devices based on the IKE protocol to establish IPSec tunnels, making the process of establishing IPSec tunnels in the network simple and fast; Moreover, based on the characteristics of each network device in the network, the controller reasonably establishes some IPSec tunnels at appropriate times instead of establishing a fully connected IPSec tunnel in the network, so that some network devices can choose to deploy network devices with general storage and processing capabilities, saving network deployment costs to a certain extent. Preferably, for Hub-Spoke traffic models such as SD-WAN, it is possible to deploy Hub nodes that support a large number of IPSec tunnels and Spoke nodes that support a small number of IPSec tunnels in the same network, and the controller can replace the IKE protocol to manage the IPSec tunnels between network devices, realizing more intelligent, convenient and fast transmission of services in the network.

[0019] In some further implementations, the first network device sends the second service packet to the second network device through the first IPSec tunnel, which may specifically include: the first network device determines to send the second service packet to the second network device through the first IPSec tunnel based on the first routing table entry associated with the first IPSec tunnel, and the next hop of the first routing table entry is the second network device.

[0020] As an example, the method may also include: when the number of packets transmitted through the first IPSec tunnel within a preset first time period is less than or equal to a first threshold, the first network device ages the first routing table entry; or, when the establishment time of the first IPSec tunnel reaches a second time period, the first network device deletes the IPSec SA associated with the first IPSec tunnel, and the second time period is the preset available time period of the first IPSec tunnel. Wherein, aging the first routing table entry, in one case, may refer to deleting the first routing table entry locally from the first network device, and in another case, may refer to setting the status of the first IPSec tunnel associated with the first routing table entry to unavailable. Similarly, deleting the first IPSec SA and the second IPSec SA related to the first IPSec tunnel, in one case, may refer to deleting the first IPSec SA and the second IPSec SA locally from the first network device, and in another case, may refer to setting both the first IPSec SA and the second IPSec SA to an unavailable state.

[0021] In this way, by monitoring the usage of the first IPSec tunnel and making a decision on whether to maintain or dismantle the first IPSec tunnel based on the monitoring results, temporary IPSec tunnels with low utilization are effectively managed, and resources in the network are optimized in a timely manner, making the method for transmitting services in the network provided in the embodiment of the present application more intelligent.

[0022] In some other possible implementations, the method may further include: collecting statistics on usage of each temporarily established direct IPSec tunnel to obtain statistical information, and optimizing and managing the IPSec tunnels in the network based on the statistical information.

[0023] As an example, the method for optimizing the management of IPSec tunnels in the network may specifically include: the first network device counts the usage of each directly connected IPSec tunnel established between the first network device and the second network device to obtain statistical information; then, the first network device determines that the usage of each directly connected IPSec tunnel meets the preset conditions, and then sets the fourth IPSec tunnel directly connected to the second network device as a normally connected IPSec tunnel.

[0024] As another example, the method for optimizing and managing IPSec tunnels in the network may also specifically include: the first network device counts the usage of each directly connected IPSec tunnel established between the first network device and the second network device to obtain statistical information; the first network device sends a third message to the controller, and the third message carries the statistical information; the first network device receives a fourth message sent by the controller, and the fourth message is generated when the controller determines that the usage of each directly connected IPSec tunnel meets a preset condition, and the fourth message is used to indicate the establishment of a directly connected IPSec tunnel between the first network device and the second network device; the first network device sets the fourth IPSec tunnel directly connected to the second network device as a normally connected IPSec tunnel.

[0025] The statistical information includes at least one of the following: the establishment frequency of each directly connected IPSec tunnel; and the average traffic volume of each directly connected IPSec tunnel. When the statistical information includes the establishment frequency of each directly connected IPSec tunnel, the preset condition includes: the establishment frequency is greater than or equal to a second threshold. When the statistical information includes the average traffic volume of each directly connected IPSec tunnel, the preset condition includes: the average traffic volume is greater than or equal to a third threshold.

[0026] It can be seen that in this embodiment, by counting the usage of each direct IPSec tunnel temporarily established on each network device, statistical information is obtained, and based on the statistical information, the IPSec tunnels in the network are optimized and managed, and the temporarily connected IPSec tunnels and the normally connected IPSec tunnels are adaptively adjusted to achieve optimized management of each IPSec tunnel in the network and improve resource utilization in the network. Preferably, for Hub-Spoke traffic models such as SD-WAN, a normally connected IPSec tunnel is established between the Hub node and the Spoke node that transmits business messages more frequently, while a direct IPSec tunnel is dynamically established between the Spoke nodes that transmit fewer business messages based on business needs, and the strategy for managing the IPSec tunnel is flexibly adjusted based on the usage of each network device, so that the transmission business in the network in this scenario is more intelligent and reasonable.

[0027] In the second aspect, an embodiment of the present application also provides a method for transmitting services in a network, which is implemented by a controller. The method may, for example, include: the controller receives a first message sent by a first network device, the first message being used to request establishment of a direct IPSec tunnel between the first network device and the second network device, wherein, based on a pre-configured policy, a direct first IPSec tunnel is established between the first network device and the third network device, a direct second IPSec tunnel is established between the second network device and the third network device, and no direct IPSec tunnel is established between the first network device and the second network device; the controller sends a second message to the first network device, the second message carries first IPSec SA parameter information of the second network device, the first IPSec SA parameter information is used by the first network device to establish a third IPSec tunnel directly connected to the second network device; the controller sends a third message to the second network device, the third message carries second IPSec SA parameter information of the first network device, the second IPSec SA parameter information is used by the second network device to establish the third IPSec tunnel directly connected to the first network device.

[0028] The first network device and the second network device may both be Spoke nodes, and the third network device may be a Hub node.

[0029] The first message, the second message and the third message are Border Gateway Protocol update BGPUPDATE messages.

[0030] As an example, before the controller sends the second message and the third message, the method may also include: the controller obtains a first number of IPSec tunnels currently available on the first network device and a second number of IPSec tunnels currently available on the second network device; the controller determines that the first number is less than or equal to a first threshold and the second number is less than or equal to a second threshold, wherein the first threshold is the maximum number of IPSec tunnels allowed to be established on the first network device, and the second threshold is the maximum number of IPSec tunnels allowed to be established on the second network device. In this way, the controller can comprehensively consider the storage and processing capabilities currently borne by each network device and determine whether to allow the first directly connected IPSec tunnel to be established between the first network device and the second network device, making the method more intelligent and reliable.

[0031] In some possible implementations, the method may further include: the controller receives a fourth message sent by the first network device, the fourth message carries statistical information, and the statistical information is used to indicate the usage of each permanently connected direct IPSec tunnel established between the first network device and the second network device; the controller determines that the statistical information meets a preset condition, then updates the pre-configured policy to obtain an updated configuration policy; the controller instructs the first network device to establish a permanently connected fourth IPSec tunnel between the second network device in accordance with the updated configuration policy.

[0032] The statistical information includes at least one of the following: the establishment frequency of each directly connected IPSec tunnel; and the average traffic volume of each directly connected IPSec tunnel. When the statistical information includes the establishment frequency of each directly connected IPSec tunnel, the preset condition includes the establishment frequency being greater than or equal to a third threshold. When the statistical information includes the average traffic volume of each directly connected IPSec tunnel, the preset condition includes the average traffic volume being greater than or equal to a fourth threshold.

[0033] It should be noted that the method provided in the second aspect corresponds to the method provided in the first aspect. For the specific implementation method and the effects achieved, please refer to the relevant instructions in the method provided in the first aspect above.

[0034] On the third aspect, an embodiment of the present application also provides a method for transmitting services in a network, which is implemented by a second network device. The method may, for example, include: the second network device receives a first service message sent by the first network device through a third network device, the first network device and the third network device are directly connected through a first IPsec tunnel, the second network device and the third network device are directly connected through a second IPsec tunnel, and the first service message carries the first IPSec SA parameter information of the first network device; the second network device establishes a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored in itself; the second network device receives the second service message; the second network device sends the second service message to the first network device through the third IPSec tunnel.

[0035] The first network device and the second network device may both be Spoke nodes, and the third network device may be a Hub node.

[0036] As an example, the second network device establishes a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored by itself. Specifically, it may include: the second network device determines the first IPSec SA and the second IPSec SA according to the first IPSec SA parameter information and the second IPSec SA parameter information, wherein the first IPSec SA is used to securely protect the messages transmitted from the first network device to the second network device, and the second IPSec SA is used to securely protect the messages transmitted from the second network device to the first network device; the second network device establishes the third IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0037] In some possible implementations, before the second network device sends the second service message to the first network device through the third IPSec tunnel, the method may further include: the second network device sends a third service message to the first network device through the third network device, the third service message carries the second IPSec SA parameter information of the second network device, and the second IPSec SA parameter information is used by the first network device to establish the third IPSec tunnel directly connected to the second network device.

[0038] As an example, the second network device sends the second service message to the first network device through the third IPSec tunnel, which may specifically include: the second network device determines to send the second service message to the first network device through the third IPSec tunnel based on the first routing table entry associated with the third IPSec tunnel.

[0039] The first service message carries the first IPSec SA parameter information through an extended message header.

[0040] It should be noted that the method provided in the third aspect corresponds to the method provided in the first aspect. For the specific implementation method and the effects achieved, please refer to the relevant instructions in the method provided in the first aspect above.

[0041] In a fourth aspect, an embodiment of the present application further provides a network device. The network device includes a transceiver unit and a processing unit. The transceiver unit is used to perform the transceiver operation implemented by the first network device in the method provided in the first aspect above; the processing unit is used to perform other operations except the transceiver operation implemented by the first network device in the method provided in the first aspect above. For example: when the network device executes the method implemented by the first network device in the first aspect, the transceiver unit can be used to receive the first business message of the first business flow, and can also be used to receive the second business message, and can also be used to send the second business message based on the first IPSec tunnel; the processing unit can be used to establish a directly connected first IPSec tunnel with the second network device in response to the received first business message.

[0042] In a fifth aspect, an embodiment of the present application further provides a network device, which includes a transceiver unit and a processing unit. The transceiver unit is used to perform the transceiver operation implemented by the second network device in the method provided in the third aspect; the processing unit is used to perform other operations except the transceiver operation implemented by the second network device in the method provided in the third aspect. For example: when the network device executes the method implemented by the second network device in the third aspect, the transceiver unit can be used to receive the first service message sent by the first network device through the third network device; the processing unit can be used to establish a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored by itself.

[0043] In a sixth aspect, an embodiment of the present application further provides a controller, which includes a transceiver unit and a processing unit. The transceiver unit is used to perform the transceiver operation implemented by the controller in the method provided in the second aspect; the processing unit is used to perform other operations implemented by the controller in the method provided in the second aspect except for the transceiver operation. For example: when the controller executes the method implemented by the controller in the second aspect, the transceiver unit can be used to receive a first message sent by a first network device, and also to send a second message to the first network device, and also to send a third message to the second network device; the processing unit can be used to obtain a first number of IPSec tunnels currently available on the first network device and a second number of IPSec tunnels currently available on the second network device, and can also be used to determine that the first number is less than or equal to a first threshold and the second number is less than or equal to a second threshold.

[0044] In a seventh aspect, embodiments of the present application further provide a network device comprising a communication interface and a processor. The communication interface is configured to perform the transceiver operations performed by the first network device in the method provided in the first aspect or any possible implementation of the first aspect, and the processor is configured to perform other operations, other than the transceiver operations, performed by the first network device in the method provided in the first aspect or any possible implementation of the first aspect.

[0045] In an eighth aspect, embodiments of the present application further provide a network device comprising a communication interface and a processor. The communication interface is configured to perform the transceiver operations performed by the second network device in the method provided in the third aspect or any possible implementation of the third aspect; and the processor is configured to perform other operations, other than the transceiver operations, performed by the second network device in the method provided in the third aspect or any possible implementation of the third aspect.

[0046] In a ninth aspect, embodiments of the present application further provide a controller comprising a communication interface and a processor. The communication interface is configured to perform the transceiver operations performed by the controller in the method provided in the second aspect or any possible implementation of the second aspect; and the processor is configured to perform other operations performed by the controller in the method provided in the second aspect or any possible implementation of the second aspect, except for the transceiver operations.

[0047] In a tenth aspect, embodiments of the present application further provide a network device comprising a memory and a processor. The memory comprises computer-readable instructions; the processor, in communication with the memory, is configured to execute the computer-readable instructions, thereby enabling the network device to perform the method provided in any possible implementation of the first aspect.

[0048] In an eleventh aspect, an embodiment of the present application further provides a network device comprising a memory and a processor. The memory comprises computer-readable instructions; the processor, in communication with the memory, is configured to execute the computer-readable instructions, thereby enabling the network device to perform the method provided in any possible implementation of the third aspect.

[0049] In a twelfth aspect, embodiments of the present application further provide a controller comprising a memory and a processor. The memory comprises computer-readable instructions; the processor, in communication with the memory, is configured to execute the computer-readable instructions, so that the controller performs the method provided in any possible implementation of the second aspect.

[0050] In the thirteenth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computer, the computer executes the method provided by the first aspect, the second aspect, the third aspect or any possible implementation of any of the above aspects.

[0051] In the fourteenth aspect, the embodiments of the present application also provide a computer program product, including a computer program or computer-readable instructions. When the computer program or the computer-readable instructions are run on a computer, the computer executes the method provided by any possible implementation of the aforementioned first aspect, second aspect, third aspect or any of the above aspects.

[0052] In the fifteenth aspect, an embodiment of the present application also provides a communication system, which includes: the network device provided in the fourth aspect, the seventh aspect or the tenth aspect, the network device provided in the fifth aspect, the eighth aspect or the eleventh aspect, and the controller provided in the sixth aspect, the ninth aspect or the twelfth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0054] Figure 1 This is a schematic diagram of a network 100 framework involved in an application scenario in an embodiment of the present application;

[0055] Figure 2 This is a signaling flow chart of an example of a transmission service in the network 100 according to an embodiment of the present application;

[0056] Figure 3 This is a signaling flow chart of a method for transmitting services in the network 100 provided in an embodiment of the present application;

[0057] Figure 4 This is a flow chart of a method 100 for transmitting services in a network according to an embodiment of the present application;

[0058] Figure 5 Schematic diagram of the NLRI of a routing table entry in the network device 10 according to an embodiment of the present application;

[0059] Figure 6a Schematic diagram of the NLRI carried in message 1 in an embodiment of the present application;

[0060] Figure 6bSchematic diagram of the NLRI carried in message 2 in an embodiment of the present application;

[0061] Figure 6c Schematic diagram of the NLRI carried in message 3 in an embodiment of the present application;

[0062] Figure 7 This is an exemplary schematic diagram of service message 3 in an embodiment of the present application;

[0063] Figure 8 This is a signaling flow chart of an implementation method of S102 in an embodiment of the present application;

[0064] Figure 9 This is a signaling flow chart of another implementation of S102 in an embodiment of the present application;

[0065] Figure 10 This is a flow chart of a method 200 for transmitting services in a network according to an embodiment of the present application;

[0066] Figure 11 This is a flow chart of a method 300 for transmitting services in a network according to an embodiment of the present application;

[0067] Figure 12 This is a flow chart of a method 400 for transmitting services in a network according to an embodiment of the present application;

[0068] Figure 13 This is a schematic diagram of the structure of a network device 1300 according to an embodiment of the present application;

[0069] Figure 14 This is a schematic diagram of the structure of a network device 1400 according to an embodiment of the present application;

[0070] Figure 15 This is a schematic diagram of the structure of a controller 1500 in an embodiment of the present application;

[0071] Figure 16 This is a schematic diagram of the structure of a network device 1600 according to an embodiment of the present application;

[0072] Figure 17 This is a schematic diagram of the structure of a network device 1700 according to an embodiment of the present application;

[0073] Figure 18 This is a schematic diagram of the structure of a controller 1800 in an embodiment of the present application;

[0074] Figure 19 This is a schematic diagram of the structure of a network device 1900 according to an embodiment of the present application;

[0075] Figure 20 This is a schematic diagram of the structure of a network device 2000 according to an embodiment of the present application;

[0076] Figure 21 This is a schematic diagram of the structure of a controller 2100 in an embodiment of the present application;

[0077] Figure 22 This is a structural diagram of a communication system 2200 in an embodiment of the present application. DETAILED DESCRIPTION

[0078] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings. The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions in the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0079] In this application, ordinal numbers such as "1", "2", "3", "first", "second" and "third" are used to distinguish multiple objects and are not used to limit the order of multiple objects.

[0080] “A and / or B” mentioned in this application should be understood to include the following situations: only A, only B, or both A and B.

[0081] The following is a brief explanation of some technical terms involved in this application.

[0082] An IPSec tunnel typically corresponds to a pair of IPSec SAs. IPSec SAs are directional and exist in pairs. To establish an IPSec tunnel between two network devices, the two network devices must establish two IPSec SAs in different directions, respectively, between the local and remote network devices. IPSec tunnels established between network devices can be used to secure service packets as well as packets for protocols such as Open Shortest Path First version 3 (OSPFv3). It should be noted that, based on different service requirements, IPSec tunnels of varying granularity can be established between network devices. Examples of IPSec tunnels include device-level IPSec tunnels, port-level IPSec tunnels, virtual private network (VPN)-level IPSec tunnels, subnet-level IPSec tunnels, IP segment-level IPSec tunnels, and IP address-level IPSec tunnels. The embodiment of the present application is described using a device-level IPSec tunnel as an example. The method provided in the embodiment of the present application can be used to establish any other IPSec tunnels of one or more granularities.

[0083] Specifically, an IPSec SA may include a triplet used to uniquely identify the IPSec SA: a Security Parameter Index (SPI), the destination Internet Protocol (IP) address of the IPSec tunnel, and the security protocol used (such as the Message Authentication Header (AH) protocol or the Encapsulating Security Payload (ESP) protocol). An IPSec SA may also include parameters such as the encapsulation mode, authentication algorithm, authentication key, encryption algorithm, encryption and decryption keys, authentication keys, and IPSec SA aging period to implement security protections such as message encryption. For example, to establish IPSec tunnel 1 between network device 1 and network device 2, network device 1 needs to determine IPSec SA 1 for the outbound direction and IPSec SA 2 for the inbound direction. Similarly, network device 2 determines IPSec SA 2 for the outbound direction and IPSec SA 1 for the inbound direction. Then, both network device 1 and network device 2 determine IPSec SA 1 and IPSec SA 2, which is equivalent to establishing IPSec tunnel 1 between network device 1 and network device 2. In this way, when network device 1 sends packet 1 to network device 2 via IPSec tunnel 1, network device 1 can protect packet 1 based on IPSec SA 1. After network device 2 receives the protected packet 1 from IPSec tunnel 1, it can perform security verification on the protected packet 1 based on IPSec SA 1. Conversely, when network device 2 sends message 2 to network device 1 based on IPSec tunnel 1, network device 2 can perform security protection on message 2 based on IPSec SA 2. After network device 1 receives the security-protected message 2 from the IPSec tunnel 1, it can perform security verification on the security-protected message 2 based on IPSec SA 2.

[0084] IPSec SA parameter information refers to information related to IPSec SAs that are locally supported by network devices. The two network devices to establish an IPSec tunnel need to each inform the peer network device of their own IPSec SA parameter information. This allows both network devices to determine a pair of IPSec SAs for IPSec communication with the peer based on the received IPSec SA parameter information and their own IPSec SA parameter information, thereby establishing an IPSec tunnel between the two network devices. For example, the IPSec SA parameter information of network device 1 may include two encryption algorithms supported by network device 1. Based on these two encryption algorithms and the encryption algorithm locally supported by network device 2, peer network device 2 determines an encryption algorithm as the encryption algorithm used for IPSec communication between network devices 1 and 2. It should be noted that after determining the IPSec SA with the peer network device based on the peer network device's IPSec SA parameter information, the determined IPSec SA can be stored locally on the network device. Furthermore, the network device can also locally store the IPSec SA parameter information.

[0085] It should be noted that the IPSec SA parameter information may carry the public key of the network device itself, and the peer network device determines the decryption key and encryption key based on the public key and the private key on the peer network device. Alternatively, the IPSec SA parameter information may also carry a symmetric key calculated by the controller, and the network device can directly protect the transmitted message based on the symmetric key. Whether the IPSec SA parameter information carries a public key or a symmetric key is not specifically limited in the embodiments of the present application.

[0086] Currently, establishing an IPSec tunnel through IKE negotiation requires exchanging at least four messages between two network devices, which is time-consuming and inefficient, preventing fast and efficient secure communication. These issues with establishing IPSec tunnels through IKE negotiation are even more pronounced in large-scale networking scenarios. Therefore, a controller is proposed to establish and manage IPSec tunnels between network devices. This eliminates the need for complex message exchanges between network devices, enabling faster and more efficient secure communication within the network.

[0087] For relevant instructions on establishing IPSec tunnels between network devices by replacing the IKE protocol with a controller involved in this application, please refer to the relevant instructions of the IETF draft "IPsec Key Exchange using a Controller draft-carrel-ipsecme-controller-ike-01", which is incorporated into this application by reference in its entirety.

[0088] See also Figure 1 The network 100 shown in FIG. 1 includes a network device 10, a network device 20, a network device 30, and a controller 40. The network device 10, the network device 20, and the network device 30 establish a secure channel 1, a secure channel 2, and a secure channel 3 with the controller 40, respectively. It should be noted that the secure channel 1, the secure channel 2, and the secure channel 3 may be an IPSec tunnel or any other form of secure channel. The secure channels established between the network devices in the network 100 and the controller 40 are intended to ensure that the communication between the controller 40 and the network devices is secure, thereby ensuring that the process by which the controller 40 creates IPSec tunnels between the network devices in the network 100 is secure and reliable.

[0089] by Figure 1 Taking the scenario shown as an example, the exemplary process of establishing an IPSec tunnel between network devices by the controller is introduced. The process of establishing an IPSec tunnel in the network 100 by the controller 40 is shown in FIG. Figure 2For example, the process may include: S11, the network device 10 sends its own IPSec SA parameter information 1 to the controller 40 through the secure channel 1, the network device 20 sends its own IPSec SA parameter information 2 to the controller 40 through the secure channel 2, and the network device 30 sends its own IPSec SA parameter information 3 to the controller 40 through the secure channel 3; S12, the controller 40 sends the IPSec SA parameter information 1 and the IPSec SA parameter information 2 to the network device 30 through the secure channel 3; S13, the controller 40 sends the IPSec SA parameter information 1 and the IPSec SA parameter information 3 to the network device 20 through the secure channel 2; S14, the controller 40 sends the IPSec SA parameter information 2 and the IPSec SA parameter information 3 to the network device 10 through the secure channel 1; S15, the network device 10 determines IPSec SA 12 and IPSec SA 21 according to the IPSec SA parameter information 2, and determines IPSec SA 13 and IPSec SA 31 according to the IPSec SA reference information 3; S16, the network device 20 determines IPSec SA 21 and IPSec SA 31 according to the IPSec SA parameter information 1 12, determine IPSec SA 23 and IPSec SA 32 according to IPSec SA reference information 3; S17, network device 30 determines IPSec SA 31 and IPSec SA 13 according to IPSec SA parameter information 1, and determines IPSec SA 32 and IPSec SA 23 according to IPSec SA reference information 2; S18, network device 10 and network device 20 establish IPSec tunnel 1 according to IPSec SA 12 and IPSec SA 21; S19, network device 10 and network device 30 establish IPSec tunnel 2 according to IPSec SA 13 and IPSec SA 31; S20, network device 20 and network device 30 establish IPSec tunnel 3 according to IPSec SA 23 and IPSec SA 32.

[0090] As can be seen, by using a controller to establish IPSec tunnels between network devices in a network, there is no need for network devices to perform complex message exchanges based on the IKE protocol to establish IPSec tunnels, making secure communication in the network faster and more efficient. However, a controller typically establishes a fully connected IPSec tunnel in the network, that is, it establishes at least one IPSec tunnel between every two network devices in the network. This requires each network device in the network to store the IPSec SA between other network devices in the network, requiring all network devices deployed in the network to have strong storage and processing capabilities, which can lead to very high network deployment costs.

[0091] However, in many networks, such as large-network, small-device enterprise networks, deployments often prioritize central sites for communication with branch sites, ensuring robust functionality. Therefore, central sites are typically equipped with network devices with robust storage and processing capabilities, capable of supporting a large number of IPSec tunnels. Branch sites, on the other hand, connect to fewer networks, with low communication frequency between them. Furthermore, a large number of branch sites are required. Therefore, to control network costs, branch sites are typically equipped with network devices with modest storage and processing capabilities, typically supporting only a small number of IPSec tunnels. Consequently, networks deployed according to this approach cannot meet the current requirement for a controller to establish fully meshed IPSec tunnels within the network. Specifically, the network devices deployed at each branch site may not be able to support fully meshed IPSec tunnels. Furthermore, networks deployed according to this requirement for a controller to establish fully meshed IPSec tunnels within the network suffer from low communication frequency between some network devices (such as those at branch sites), leading to low utilization of IPSec tunnels established between these devices. This not only increases network deployment costs but also wastes network resources.

[0092] Based on this, in order to strike a relative balance between network deployment costs and the establishment of IPSec tunnels in the network by the controller, an embodiment of the present application provides a method for transmitting services in a network, in which the controller can reasonably establish IPSec tunnels based on the characteristics of the network devices deployed in the network, and can quickly, efficiently, and reasonably establish IPSec tunnels between network devices by the controller while reducing deployment costs. In specific implementations, the controller only establishes IPSec tunnels between some network devices based on the characteristics of the network devices deployed in the network (such as location, frequency of communication, etc.), while temporarily establishing IPSec tunnels between other network devices when needed. For example: a directly connected IPSec tunnel is not established between a first network device and a second network device. When the first network device receives a first service message of a first service flow, the network segment to which the source IP address of each service message included in the first service flow belongs belongs to the network segment of the local area network (English: Local Area Network, abbreviated as: LAN) network to which the first network device is connected, that is, the source terminal device of each service message included in the first service flow belongs to the LAN network to which the first network device is connected. Similarly, the network segment to which the destination IP address of each service message included in the first service flow belongs belongs to the network segment of the LAN network to which the second network device is connected, that is, the destination terminal device of each service message included in the first service flow belongs to the LAN network to which the second network device is connected. Then, in response to receiving the first service message, the first network device establishes a directly connected first IPSec tunnel between the second network device. At this time, when the first network device receives the second service message of the first service flow, the first network device can send the second service message to the second network device through the first IPSec tunnel. In this way, when the controller establishes an IPSec tunnel in the network, it no longer establishes a fully connected IPSec tunnel, but reasonably establishes IPSec tunnels between some network devices. IPSec tunnels between other network devices are only established when there is business demand. This can reduce the demand for storage and processing capabilities of some network devices in the network to a certain extent, thereby effectively saving network deployment costs.

[0093] For example, still Figure 1 Taking the network 100 shown as an example, the process of establishing an IPSec tunnel between network devices by the controller in the embodiment of the present application is exemplarily introduced. Figure 3As shown, in the embodiment of the present application, a pre-configured policy is stored on the controller 40. The pre-configured policy indicates that a direct IPSec tunnel is established between the central Hub node and each branch Spoke node, and no direct IPSec tunnel is established between each Spoke node. Assume that in the network 100, the network device 30 is a Hub node, and the network devices 10 and 20 are both Spoke nodes. A direct IPSec tunnel is established between the network device 10 and the network device 30, and between the network device 20 and the network device 30, respectively. The specific process may include: S21, the network device 10 sends its own IPSec SA parameter information 1 to the controller 40 through the secure channel 1, the network device 20 sends its own IPSec SA parameter information 2 to the controller 40 through the secure channel 2, and the network device 30 sends its own IPSec SA parameter information 3 to the controller 40 through the secure channel 3; S22, the controller 40 sends the IPSec SA parameter information 1 and the IPSec SA parameter information 2 to the network device 30 through the secure channel 3 according to the pre-configured information stored locally; S23, the controller 40 sends the IPSec SA parameter information 3 to the network device 10 through the secure channel 1; S24, the controller 40 sends the IPSec SA parameter information 3 to the network device 20 through the secure channel 2; S25, the network device 10 determines the IPSec SA 13 and the IPSec SA 31 according to the IPSec SA reference information 3; S26, the network device 20 determines the IPSec SA 13 and the IPSec SA 31 according to the IPSec SA reference information 3 23 and IPSec SA 32; S27, network device 30 determines IPSec SA 31 and IPSec SA 13 according to IPSec SA parameter information 1, and determines IPSec SA 32 and IPSec SA 23 according to IPSec SA reference information 2; S28, network device 10 and network device 30 establish IPSec tunnel 2 according to IPSec SA 13 and IPSec SA 31; S29, network device 20 and network device 30 establish IPSec tunnel 3 according to IPSec SA 23 and IPSec SA 32.

[0094] For Spoke nodes, the establishment of a direct IPSec tunnel is triggered only when there is an actual need. Specifically, in the network 100, the specific process of establishing the direct IPSec tunnel 1 between the network device 10 and the network device 20 can be found in Figure 3As shown, it includes: S31, the network device 10 receives the business message 1 in the business flow 1, the source IP address of each business message included in the business flow 1 belongs to the network segment of the LAN network connected to the network device 10, and the destination IP address of each business message included in the business flow 1 belongs to the network segment of the LAN network connected to the network device 20; S32, in response to the received business message 1, the network device 10 establishes an IPSec tunnel 1 directly connected to the network device 20; S33, the network device 10 receives the business message 2 in the business flow 1; S34, the network device 10 sends the business message 2 to the network device 20 based on the IPSec tunnel 1.

[0095] Thus, when network device 10 and network device 20 initially enable the IPSec function, only a direct IPSec tunnel is established with network device 30, and no direct IPSec tunnel is established between network device 10 and network device 20. Only the IPSec SA of the direct IPSec tunnel established with network device 30 and its own IPSec SA parameter information are stored. A direct IPSec tunnel is only temporarily established between network device 10 and network device 20 when needed. This reduces the processing and storage capacity requirements of network device 10 and network device 20, allowing network device 10 and network device 20 to deploy lower-cost network devices, thereby reducing the deployment cost of network 100. It should be noted that the above description uses only three network devices as an example. The more network devices there are, the more significant the effect of reducing network deployment costs under this approach.

[0096] In this way, through the method provided in the embodiment of the present application, the controller can establish an IPSec tunnel between network devices in the network without the need for complex message interaction between network devices based on the IKE protocol to establish the IPSec tunnel, making the process of establishing an IPSec tunnel in the network simple and fast; moreover, the controller will establish IPSec tunnels between some of the network devices in the network based on the characteristics of each network device in the network, instead of establishing a fully connected IPSec tunnel, thereby reducing the demand for storage and processing capabilities of some network devices in the network and saving the cost of network deployment.

[0097] The network 100 can be a central Hub-Spoke traffic model, the network device 30 can be the central Hub node of the central site, and the network device 10 and the network device 20 can be the branch Spoke nodes of the two branch sites. The network device 30 can be the customer edge equipment (English: Customer premises equipment, CPE) of the central site, and the network device 10 and the network device 20 can be the CPE of the branch site. The pre-configured policy on the controller 40 is specifically used to instruct the establishment of IPSec tunnels between the Hub node and each Spoke node in the network 100, and between the Hub nodes. Among them, the network from the Spoke node to the Hub node can be a backbone network, and there may be multiple tunnels between the Spoke node and the Hub node. The embodiment of the present application takes the IPSec tunnel as the outermost tunnel to provide security protection for the transmitted messages as an example.

[0098] It should be noted that the network devices and nodes in the embodiments of the present application have the same meaning and can be used interchangeably. Each network device can be a gateway device in its corresponding site, responsible for achieving mutual access with other sites, and can specifically be a router, switch or firewall and other devices. The network device supports IPSec tunnel-related protocols and can also support the Border Gateway Protocol (English: Border Gateway Protocol, abbreviated: BGP), Ethernet Virtual Private Network (English: Ethernet Virtual Private Network, abbreviated: EVPN) protocol or Layer 3 Virtual Private Network (English: Layer 3 Virtual Private Network, abbreviated: L3VPN) protocol. Based on "Secure EVPN draft-sajassi-bess-secure-evpn-02", it can be known that the controller 40 can be a Border Gateway Protocol (English: Border Gateway Protocol, abbreviated: BGP) route reflector (English: Route Reflector, abbreviated: RR). The controller 40 can be an independent hub node or an independent server; the controller 40 can also be integrated with the network device 30 or other hub nodes, for example, it can be a new service board added to the network device 30; the controller 40 can also be a functional module integrated into the public cloud. As long as the control function of the controller 40 in the embodiment of the present application can be realized, it will be sufficient.

[0099] As an example, the network 100 may be a software-defined wide area network (SD-WAN), and the controller 40 may be a software-defined network (SDN) controller in the SD-WAN, which may support BGP RR functions.

[0100] It can be understood that the above scenario is only an example scenario provided by the embodiment of the present application, and the embodiment of the present application is not limited to this scenario.

[0101] The specific implementation of the method for transmitting services in a network in the embodiment of the present application is described in detail below with reference to the accompanying drawings through embodiments.

[0102] by Figure 1 Taking the network 100 shown in FIG. 1 as an example, a method 100 for transmitting services in a network provided by an embodiment of the present application is introduced. The method 100 can be used for Figure 1 In the network 100 shown in FIG. 1 , the controller 40 establishes a direct IPSec tunnel 2 and a direct IPSec tunnel 3 between the network device 10 and the network device 30 and between the network device 20 and the network device 30 according to its local pre-configured policy. For the specific establishment process, see Figure 3 According to the pre-configured policy, no direct IPSec tunnel is established between the network device 10 and the network device 20.

[0103] Figure 4 This is a signaling flow chart of a method 100 for transmitting services in a network provided by an embodiment of the present application. Figure 4 The method 100 may include, for example, the following S101 to S104:

[0104] S101 , the network device 10 receives service packet 1 in service flow 1 .

[0105] The source node of each service message in service flow 1 is a terminal device at the site where network device 10 is located. The destination node of each service message in service flow 1 is a terminal device at the site where network device 20 is located. The terminal device at the site where network device 10 is located can also be referred to as a terminal device in the LAN network to which network device 10 is connected. The terminal device at the site where network device 20 is located can also be referred to as a terminal device in the LAN network to which network device 20 is connected. Examples of these terminal devices include printers, mobile phones, and personal computers.

[0106] In the present application, the network device 10 can distinguish different business flows based on different flow rules. In a specific implementation, the business flow can be divided based on the destination IP address of the business message. For example, the business flow is determined based on the correspondence between the network segment to which the destination IP address of the business message belongs and the network segment to which the LAN network to which the network device 20 is connected belongs. The set of business messages whose destination IP address of the business message belongs to the same network segment as a certain LAN network to which the network device 20 is connected can be considered as a business flow. For another example, the network device 10 can distinguish business flows based on the destination IP address, and consider the set of all business messages sent to the same destination IP address as a business flow. In a specific implementation method, the business flow can also be divided based on the source IP address and destination IP address of the business message, that is, the business flow is divided based on the binary group. As for how to divide the business flow, those skilled in the art can obtain a variety of division methods based on existing technical common sense, which will not be repeated here.

[0107] The network device 10 receives the service message 1, which can trigger it to establish the IPSec tunnel directly connected to the network device 20. That is, S101 provides a trigger condition for the subsequent execution of S102.

[0108] S102 , in response to the received service message 1 , the network device 10 establishes a direct IPSec tunnel 1 with the network device 20 .

[0109] Before S102, the non-direct route to the network device 20 stored on the network device 10 can be obtained by learning the network layer reachability information (English: Network Layer Reachability Information, abbreviated as: NLRI) in the route advertisement message received from the controller 40. The NLRI in the route advertisement message can be, for example, Figure 5As shown, in addition to the IPSec SA parameter information 3 of the network device 30, the NRLI may also include an NLRI field, a tunnel type (English: Tunnel Type) field, and an endpoint address (English: endpointaddress) field. Depending on the granularity of the IPSec tunnel, the value of the NLRI field may specifically be at least one of the following addresses: the loopback address of the network device 20, the IP address of the WAN port of the network device 20, or the network segment address of the local area network (English: Local Area Network, abbreviated as: LAN) to which the network device 20 is connected. The value of the Tunnel Type field is used to indicate the type of tunnel, specifically IPSec; the value of the endpoint address field may be the IP address of the network device 30, for example, the IP address of the network device 30 may refer to the loopback address of the network device 30 or the IP address of the WAN port of the network device 30. The NLRI may also include a flag bit, which is used to indicate whether the NLRI learns a direct or indirect routing table entry. For example, if the flag bit value is 0, it is determined that the NLRI learns an indirect routing table entry. If the flag bit value is 1, it is determined that the NLRI learns a direct routing table entry. Figure 5 In the example, the value of this flag bit = 0.

[0110] Network Equipment 10 Learning Figure 5 After the NLRI shown, the routing table entry obtained may include: the routing prefix and next-hop IP address of network device 20, and the routing table entry can be associated with the corresponding IPSec tunnel. For example, the next-hop IP address of network device 10 is the IP address of network device 30, through which network device 30 can point to network device 20, and the corresponding IPSec tunnel 2 can be found through the IP address of network device 30. Similarly, the routing table entry of the non-direct route from network device 20 to network device 10 learned by network device 20 may include: the routing prefix and next-hop IP address of network device 10, and the routing table entry can be associated with the corresponding IPSec tunnel. For example, the next-hop IP address of network device 20 is the IP address of network device 30, through which network device 30 can point to network device 10, and the corresponding IPSec tunnel 3 can be found through the IP address of network device 30.

[0111] For example: before S102, when the network device 10 receives the service message a, it uses the destination IP address of the service message a to search the current routing table entry on the network device 10, and determines that the next hop in the routing table entry matching the destination IP address is network device 30, and points to network device 20 through network device 30; at this time, it can also be determined in the network device 10 that the network device 30 is associated with the IPSec tunnel 2, then the network device 10 can send the service message a to the network device 30 through the IPSec tunnel 2, and the network device 30 forwards the service message a to the network device 20.

[0112] In specific implementation, S102 is implemented through the following two methods: in a first possible implementation method, the network device 10 can send a request message to the controller 40, and the request message is used to request the establishment of a direct IPSec tunnel 1 between the network device 10 and the network device 20; in a second possible implementation method, the network device 10 can also carry the IPSec SA parameter information of the network device 10 in the service message forwarded to the network device 20 through the network device 30, and the network device 20 carries the IPSec SA parameter information of the network device 20 in the service message forwarded to the network device 10 through the network device 30, thereby establishing a direct IPSec tunnel 1 between the network device 10 and the network device 20, wherein the service message carrying the IPSec SA parameter information can specifically be any service message forwarded by the network device 10 and the network device 20 through the network device 30. In the embodiment of the present application, the above-mentioned service message 1 received by the network device 10 is used as an example for illustration.

[0113] For the first possible implementation method, it may specifically include: the network device 10 sends a message 1 to the controller 40, where the message 1 is used to request to establish a direct IPSec tunnel between the network device 10 and the network device 20; after the controller 40 receives the request for establishing a direct IPSec tunnel sent by the network device 10, the controller 40 sends a message 2 and a message 3 to the network device 10 and the network device 20 respectively, wherein the message 2 carries the IPSec SA parameter information 2 of the network device 20, and the message 3 carries the IPSec SA parameter information 1 of the network device 10; then, the network device 10 determines the IPSec SA 12 and the IPSec SA 21 based on its own IPSec SA parameter 1 and the received IPSec SA parameter information 2, and the network device 20 determines the IPSec SA 21 and the IPSec SA 12 based on the IPSec SA parameter information 2 stored by itself and the received IPSec SA parameter information 1. Among them, IPSec SA 12 is the outbound IPSec SA of network device 10, and the inbound IPSec SA of network device 20, and is used to securely protect packets sent from network device 10 to network device 20. IPSec 12 is the inbound IPSec SA of network device 10, and the outbound IPSec SA of network device 20, and is used to securely protect packets sent from network device 20 to network device 10. Based on IPSec SA 12 and IPSec SA 21, network device 10 and network device 20 establish a direct IPSec tunnel 1.

[0114] Message 1, message 2, and message 3 may all be routing advertisement messages, such as a Border Gateway Protocol update BGPUpdate message.

[0115] Message 1 carries the source IP address of service message 1 and the destination IP address of service message 1. On the one hand, since the network segment to which the source IP address of service message 1 belongs belongs to the network segment of the LAN network to which network device 10 is connected, and the network segment to which the destination IP address of service message 1 belongs belongs to the network segment of the LAN network to which network device 20 is connected, the controller 40 can determine, based on the content carried in message 1, that the network device 10 is requesting to establish an IPSec tunnel directly connected between network devices 10 and 20. On the other hand, message 1 carries the source IP address of service packet 1. Since controller 40 can pre-define the service types and service granularity for which direct IPSec tunnels are permitted and knows the corresponding LAN networks or LAN network terminal device IP addresses, controller 40 can also compare the source IP address of service packet 1 carried in message 1 with the LAN networks or LAN network terminal device IP addresses corresponding to the service types and service granularity for which direct IPSec tunnels are permitted, to determine whether service packet 1 belongs to the service types or service granularity for which direct IPSec tunnels are permitted. If permitted, controller 40 instructs establishment of direct IPSec tunnel 1 (i.e., sends message 2 and message 3 to network device 10 and network device 20, respectively). If not permitted, controller 40 does not send message 2 and message 3 to network device 10 and network device 20. The service type may refer to whether service flow 1 belongs to a telephone conference or video conference type, and the service granularity may refer to whether the LAN network terminal device corresponding to the source node of service flow 1 belongs to the R&D department or the finance department, for example.

[0116] For example, the source IP address and destination IP address of service message 1 can be carried in the NLRI of message 1. The format of NLRI in message 1 can be found in Figure 6a In addition to the NLRI field, the NLRI may also include a NLRI field, a TunnelType field, and an endpoint address field. Depending on the granularity of the IPSec tunnel, the value of the NLRI field can be at least one of the following addresses: the loopback address of network device 10, the IP address of the WAN port of network device 10, or the network segment address of the LAN network to which network device 10 is connected. The value of the TunnelType field is IPSec. The value of the endpointaddress field can be the IP address of network device 10, which can be, for example, the loopback address of network device 10 or the IP address of the WAN port of network device 10.

[0117] When the IPSec tunnel 1 is established through the first possible implementation manner, routes may also be updated on the network device 10 and the network device 20 .

[0118] For details about the NLRI in message 2, see Figure 6b As shown, the NLRI includes not only the IPSec parameter information 2, but also the NLRI field, the Tunnel Type field, and the endpoint address field. According to the different granularities of the IPSec tunnel, the value of the NLRI field includes any one of the network segment address of the LAN network to which the network device 20 is connected, the loopback address of the network device 20, or the IP address of the WAN port of the network device 20; the value of the Tunnel Type field is IPSec; the value of the endpoint address field can be the IP address of the network device 20, and the IP address of the network device 20 can be, for example, the loopback address of the network device 20 or the IP address of the WAN port of the network device 20. The NLRI can also include a flag bit, which is used to indicate whether the NLRI has learned a direct or indirect routing table entry. For example, if the value of the flag bit is 0, it is determined that the NLRI has learned an indirect routing table entry. If the value of the flag bit is 1, it is determined that the NLRI has learned a direct routing table entry. Figure 6b In the example, the value of this flag bit = 1.

[0119] For network device 10, the routing update operation may include: network device 10 learning routing table entry 1 associated with IPSec tunnel 1 based on the NLRI in message 2. In this way, network device 10 stores routing table entry 1 directly connecting network device 10 to network device 20. Routing table entry 1 may specifically include the routing prefix and next-hop IP address of network device 20. Routing table entry 1 can be associated with IPSec tunnel 1. For example, IPSec tunnel 1 can be found through the next hop of routing table entry 1.

[0120] For details about NLRI in message 3, please refer to Figure 6cAs shown, the NLRI includes not only the IPSec parameter information 1, but also the NLRI field, the Tunnel Type field, and the endpoint address field. According to the different granularities of the IPSec tunnel, the value of the NLRI field may specifically include any one of the network segment address of the LAN network to which the network device 10 is connected, the loopback address of the network device 10, or the IP address of the WAN port of the network device 10; the value of the Tunnel Type field is IPSec; the value of the endpoint address field may be the IP address of the network device 10, and the IP address of the network device 10 may be, for example, the loopback address of the network device 10 or the IP address of the WAN port of the network device 10. The NLRI may also include a flag bit, which is used to indicate whether the NLRI has learned a direct or indirect routing table entry. For example, if the value of the flag bit is 0, it is determined that the NLRI has learned an indirect routing table entry. If the value of the flag bit is 1, it is determined that the NLRI has learned a direct routing table entry. Figure 6c In the example, the value of this flag bit = 1.

[0121] For network device 20, the routing update operation may include: network device 20 learning a new routing table entry 2 associated with IPSec tunnel 1 based on the NLRI in message 3. In this way, network device 20 stores a direct routing table entry 2 from network device 20 to network device 10. Routing table entry 2 may specifically include the routing prefix and next-hop IP address of network device 10. Routing table entry 2 can be associated with IPSec tunnel 1. For example, IPSec tunnel 1 can be found through the next hop of routing table entry 2.

[0122] It should be noted that the description of the first possible implementation method can be found in Figure 8 The embodiments shown are not described in detail here.

[0123] For the second possible implementation method, it may specifically include: network device 10 carries IPSec SA parameter information 1 of network device 10 in service message 1 to obtain service message 3; then, network device 10 sends the service message 3 to network device 20 through network device 30, wherein network device 30 is a Hub node, network device 10 and network device 30 are directly connected through IPsec tunnel 2, and network device 10 is directly connected to network device 30 through IPsec tunnel 3; network device 20 determines IPSec SA 21 and IPSec SA12 based on its own stored IPSec SA parameter information 2 and the received IPSec SA parameter information 1, wherein IPSec SA 21 is used to securely protect messages transmitted from network device 20 to network device 10, and IPSec SA 12 is used to securely protect messages transmitted from network device 10 to network device 20. After network device 20 receives service message 5 destined for a terminal device at the site where network device 10 is located, it adds its IPSec SA parameter information 2 to service message 5, resulting in service message 4. Network device 20 then sends service message 4 to network device 10 via network device 30. Network device 10 determines IPSec SA 12 and IPSec SA 21 based on its stored IPSec SA parameter information 1 and the received IPSec SA parameter information 2. At this point, network devices 10 and 20 establish IPSec tunnel 1 based on IPSec SA 12 and IPSec SA 21.

[0124] It should be noted that service message 5 can specifically be a response service message to service message 3 (or service message 1). After network device 20 receives service message 3, service message 5 can be generated. Therefore, the time when network device 20 receives service message 3 and the time when network device 20 sends service message 4 are relatively close. In other words, IPSec tunnel 1 can be established between network devices 10 and 20 relatively quickly, meeting the demand for fast service transmission in the network.

[0125] Among them, network device 10 carries IPSec SA parameter information 1 of network device 10 in service message 1, obtaining service message 3. Specifically, network device 10 may extend message header 1 (this extended message header may also be called an extended security header or an extended security message header, denoted as: IPSec Header) in service message 1, and carries IPSec SA parameter information 1 in the IPSec Header, obtaining service message 3. Similarly, network device 20 carries IPSec SA parameter information 2 of network device 20 in service message 5, obtaining service message 4. Specifically, network device 20 may extend message header 2 in service message 5, and carry IPSec SA parameter information 2 in message header 2, obtaining service message 4.

[0126] As an example, taking ESP as an example, the format of service message 3 can be as follows Figure 7 As shown, it includes: an outer IP header, an ESP header, a Virtual Extensible Local Area Network (VXLAN) header / Generic Routing Encapsulation (GRE) header, an IPSec header, an inner IP / Media Access Control Address (MAC) header, and a payload. The VXLAN header or GRE header can also be replaced with a Network Virtualization using Generic Routing Encapsulation (NVGRE) header, both of which can be used to indicate that the next extended header is an IPSec header, which carries IPSec SA parameter information 1.

[0127] Furthermore, in ESP scenarios, Network Address Translation (NAT) traversal can be achieved through SPI mapping or User Datagram Protocol (UDP) encapsulation. SPI mapping relies on the Application Layer Gateway (ALG) processing of the NAT traversal device, while UDP encapsulation relies solely on the network devices at both ends of the IPSec tunnel. Therefore, UDP encapsulation can be more widely used for NAT traversal in IPSec scenarios. When ESP NAT traversal is enabled, since there is no dynamic NAT traversal monitoring mechanism similar to IKE, network device 10 can add a UDP header between the outer IP header and the ESP header of service message 3. The source and destination ports in this UDP header are both 4500, and the source port on the private network side will be converted by the NAT traversal device. It should be noted that, according to the provisions of the relevant IPSec protocols, even if the intermediate device does not have NAT traversal functionality, the additional UDP header added to the transmitted service message will not affect the secure transmission of the service message in the IPSec tunnel or its normal processing by the receiving network device.

[0128] It should be noted that when network device 10 generates IPSec SA 12 and IPSec SA 21, it can update the routing and use the established direct IPSec tunnel 1 to transmit messages that need to be sent to network device 20 and the terminal devices at its site. Network device 20 can update the routing after sending the service message 4 to network device 10 via network device 30, and use the established direct IPSec tunnel 1 to transmit messages that need to be sent to network device 10 and the terminal devices at its site. Alternatively, for more reliable communication, network device 20 can update the routing and use the direct IPSec tunnel 1 to transmit messages that need to be sent to network device 10 and the terminal devices at its site only after receiving messages sent by network device 10 via IPSec tunnel 1.

[0129] After establishing IPSec tunnel 1 through the second possible implementation method, the network device 10 and the network device 20 update the routing operation specifically can be: after determining to establish IPSec tunnel 1, the network device 10 and the network device 20 locally and spontaneously update the direct route between the network device 10 and the network device 20.

[0130] It should be noted that the relevant description of the second possible implementation method can be found in Figure 9 The embodiments shown are not described in detail here.

[0131] When the IPSec tunnel 1 between the network device 10 and the network device 20 is established through S102, the method 100 also includes the operation of the network device 10 and the network device 20 performing route updates respectively. After the route update, in one case, the network device 10 stores direct route entries and indirect route entries from the network device 10 to the network device 20, wherein different route priorities can be set. For example, the priority of the direct route entry can be set higher than the priority of the indirect route entry. Then, when both route entries are available, the network device 10 can determine to transmit the message based on the IPSec tunnel 1 based on the direct route entry with a higher priority; or, if one of the two route entries is unavailable, then the message transmission is guided based on the other available route entry; or, if the direct IPSec tunnel 1 is not established or has been deleted, then the message transmission is guided based on the indirect route entry. In another case, network device 10 can replace the indirect routing entry with a direct routing entry. In this case, network device 10 stores a direct routing entry from network device 10 to network device 20. In this case, network device 10 determines to transmit the packet based on IPSec tunnel 1 based on the direct routing entry. It should be noted that the availability of the routing entry depends on factors such as whether the outbound interface indicated by the routing entry is normal and whether the next-hop neighbor node is online.

[0132] In this way, by establishing a direct IPSec tunnel 1 between network device 10 and network device 20, it provides convenience for subsequent network device 10 to directly transmit business messages to network device 20. At the same time, during the existence of IPSec tunnel 1, it also provides convenience for network device 20 to transmit business messages to network device 10. In this way, the efficiency of business message transmission between network device 10 and network device 20 can be effectively improved, and the waste of network resources caused by forwarding business messages can be avoided.

[0133] S103 , the network device 10 receives the service packet 2 of the service flow 1 .

[0134] S104 , the network device 10 sends the service packet 2 to the network device 20 through the IPSec tunnel 1 .

[0135] In specific implementation, after S102, when the network device 10 receives the service message 2 of the service flow 1, the network device 10 in S104 sends the service message 2 to the network device 20 through the IPSec tunnel 1. Specifically, it can be: the network device 10 determines to send the service message 2 to the network device 20 through the directly connected IPSec tunnel 1 according to the routing table item 1 associated with the IPSec tunnel 1.

[0136] It should be noted that after IPSec tunnel 1 is established, the number of IPSec tunnels currently available to network device 10 should be less than the maximum number of IPSec tunnels allowed to be established on it. At the same time, the number of IPSec tunnels currently available to network device 20 should also be less than the maximum number of IPSec tunnels allowed to be established on it. The maximum number of IPSec tunnels allowed to be established on network device 10 and the maximum number of IPSec tunnels allowed to be established on network device 20 both depend on the storage and processing capabilities of the network devices themselves, and the values ​​can be the same or different. The number of IPSec tunnels currently available to network device 10 refers to the number of all currently valid IPSec tunnels with network device 10 as the IPSec tunnel endpoint.

[0137] IPSec tunnel 1 is a temporarily established IPSec tunnel. Since IPSec tunnel 1 occupies storage and processing resources on network device 10 and network device 20, after S102, the usage of IPSec tunnel 1 can be monitored, and a decision can be made on whether to continue to maintain or dismantle IPSec tunnel 1 based on the monitoring results.

[0138] As an example, the network device 10 can monitor the monitoring results obtained by itself to manage the IPSec tunnel 1. For example, when the network device 10 determines that no service packets are transmitted through the IPSec tunnel 1 within a preset duration 1 (e.g., 1 minute), or the number of service packets transmitted through the IPSec tunnel 1 is less than or equal to a preset threshold (e.g., 5), the network device 10 ages the routing table entry 1 and / or deletes the IPSec SA 12 and IPSec SA 21 associated with the IPSec tunnel 1. For another example, when the network device 10 determines that the establishment time of the IPSec tunnel 1 exceeds the preset temporary IPSec tunnel retention duration 2 (e.g., 2 hours), the network device 10 ages the routing table entry 1 and / or deletes the IPSec SA 12 and IPSec SA 21 associated with the IPSec tunnel 1. Aging the routing table entry 1 may, in one case, refer to deleting the routing table entry 1 locally from the network device 10, or in another case, may refer to setting the status of the IPSec tunnel 1 associated with the routing table entry 1 to unavailable. Similarly, deleting IPSec SA 12 and IPSec SA 21 related to IPSec tunnel 1 may, in one case, mean deleting the IPSec SA 12 and IPSec SA 21 locally from the network device 10, or in another case, mean setting both IPSec SA 12 and IPSec SA 21 to an unavailable state.

[0139] As another example, the network device 10 may also send the monitoring result obtained by its own monitoring to the controller 40 , and the controller 40 may manage the temporarily established IPSec tunnel 1 . For example: when the controller 40 determines, based on one or more monitoring results sent by the network device 10, that no business packets are transmitted through the IPSec tunnel 1 within the preset time length 1, or the number of business packets transmitted through the IPSec tunnel 1 is less than or equal to a preset threshold, then the controller 40 can send an indication message to the network device 10 (and / or network device 20), and the indication message is used to instruct the aging of the routing table entry 1 and / or the deletion of the IPSec SA 12 and IPSec SA 21 related to the IPSec tunnel 1; for another example: when the controller 40 determines, based on one or more monitoring results sent by the network device 10, that the establishment time of the IPSec tunnel 1 exceeds the preset temporary IPSec tunnel retention time length 2, then the controller 40 can send an indication message to the network device 10 (and / or network device 20), and the indication message is used to instruct the aging of the routing table entry 1 and / or the deletion of the IPSec SA 12 and IPSec SA 21 related to the IPSec tunnel 1.

[0140] It should be noted that the monitoring results may also include the number of IPSec tunnels currently established on the network device 10 and the network device 20 and the maximum number of IPSec tunnels allowed to be established. Then, the controller 40, the network device 10 or the network device 20 may also decide whether to continue to maintain or dismantle the temporarily established IPSec tunnel 1 based on the size of the gap between the two.

[0141] The content monitored in the specific monitoring results can be flexibly selected and set according to actual conditions and is not specifically limited in the embodiments of this application.

[0142] In this way, by monitoring the usage of IPSec tunnel 1 and making a decision on whether to maintain or dismantle IPSec tunnel 1 based on the monitoring results, temporary IPSec tunnels with low utilization are effectively managed, and resources in the network are optimized in a timely manner, making the method for transmitting services in the network provided in the embodiment of the present application more intelligent.

[0143] In this way, through this method 100, the controller 40 can establish an IPSec tunnel between network devices in the network 100 without the need for complex message interaction between network devices based on the IKE protocol to establish the IPSec tunnel, making the process of establishing the IPSec tunnel in the network 100 simple and fast; moreover, the controller 40 will establish an IPSec tunnel between some of the network devices in the network 100 based on the characteristics of each network device in the network 100, instead of establishing a fully connected IPSec tunnel. The other network devices will only temporarily establish an IPSec tunnel when there is a business need, thereby reducing the number of IPSec tunnels established by some network devices, reducing the demand for storage and processing capabilities of some network devices in the network, and saving the cost of network deployment. Preferably, for Hub-Spoke traffic models such as SD-WAN, a permanently connected IPSec tunnel is established between the Hub node and the Spoke node that transmit business messages more frequently, while a direct IPSec tunnel is dynamically established between the Spoke nodes that transmit less business messages based on business needs. This not only enables the deployment of network devices with general capabilities such as storage and processing at the Spoke nodes, saving network deployment costs, but also makes the transmission of business in the network more intelligent and reasonable, optimizing network resources.

[0144] In some possible embodiments, in order to make the method 100 for transmitting services in a network provided by the embodiments of the present application more intelligent, statistics may be collected on the usage of each temporarily established direct IPSec tunnel to obtain statistical information, and based on the statistical information, the IPSec tunnels in the network 100 may be optimized and managed. Each direct IPSec tunnel may include all directly connected IPSec tunnels historically established by the network device 10 and the network device 20. If there is a currently available direct IPSec tunnel, the statistical information may include the usage of the currently available direct IPSec tunnel, or may not include the usage of the currently available direct IPSec tunnel.

[0145] As an example, the network device 10 can optimize and manage the IPSec tunnels in the network 100 based on the statistical information. The method 100 can also include: the network device 10 counts the usage of each directly connected IPSec tunnel established between the network device 10 and the network device 20 to obtain statistical information; thereby, the network device 10 determines whether the statistical information meets the preset conditions. If so, the network device 10 establishes an IPSec tunnel 4 with the network device 20. The IPSec tunnel 4 is a permanently connected IPSec tunnel and will not be deleted due to the usage of the IPSec tunnel 4; if not, a permanently connected IPSec tunnel is not established between the network device 10 and the network device 20. Instead, based on the above method 100, a direct IPSec tunnel is temporarily established between the two when there is a business demand.

[0146] As another example, the network device 10 may also send the statistical information it obtains to the controller 40, and the controller 40 optimizes and manages the IPSec tunnel in the network 100 based on the statistical information. The method 100 may also include: the network device 10 counts the usage of each directly connected IPSec tunnel established between the network device 10 and the network device 20, obtains statistical information, and sends the message 4 to the controller 40, wherein the message 4 carries the statistical information; after receiving the message 4, the controller 40 obtains the statistical information from it, and after determining that the statistical information meets the preset conditions, updates the pre-configuration policy, and generates and sends a message 5 to the network device 10 based on the updated pre-configuration policy, wherein the updated pre-configuration policy includes information for instructing the establishment of a permanently connected IPSec tunnel between the network device 10 and the network device 20, and the message 5 is used to instruct the network device 10 to establish a permanently connected IPSec tunnel with the network device 20; then, the network device 10 establishes a permanently connected IPSec tunnel 4 with the network device 20 in accordance with the instructions of the message 5.

[0147] It should be noted that if it is determined that a permanent direct IPSec tunnel needs to be established between the network device 10 and the network device 20, and there is no direct IPSec tunnel between the current network device 10 and the network device 20, a permanent direct IPSec tunnel 4 can be established. The IPSec tunnel 4 can be set with the same holding time as other permanent IPSec tunnels (such as the permanent IPSec tunnel between the Spoke node and the Hub node) so that the IPSec tunnel 4 is in a permanent connection state like other permanent IPSec tunnels; alternatively, the holding time may not be set, and the IPSec tunnel 4 without a holding time is the permanent IPSec tunnel by default. If it is determined that a permanent direct IPSec tunnel needs to be established between the network device 10 and the network device 20, and there is currently a direct IPSec tunnel 1 between the network device 10 and the network device 20, the IPSec tunnel 1 can be set to a permanent connection state. For example: assuming that the retention period of the permanent IPSec tunnel between the Spoke node and the Hub node is 1 year, then by modifying the retention period of the IPSec tunnel 1 to 1 year, it can be made into a permanent IPSec tunnel; or, if it is determined that a permanent direct IPSec tunnel needs to be established between the network device 10 and the network device 20, and there is currently a direct IPSec tunnel 1 between the network device 10 and the network device 20, a permanent direct IPSec tunnel 4 can also be re-established, and the IPSec tunnel 1 is automatically dismantled when the establishment period reaches the preset retention period (such as 2 hours).

[0148] It should be noted that for network device 10 or network device 20, whether the IPSec tunnel is a persistent tunnel can be determined based on the hold time of each IPSec tunnel. For example, if the hold time of an IPSec tunnel is greater than or equal to the preset hold time threshold of the persistent IPSec tunnel between the Spoke node and the Hub node, the IPSec tunnel is considered to be a persistent tunnel. For another example, if the IPSec tunnel does not have a corresponding hold time threshold, the IPSec tunnel is considered to be a persistent tunnel. Moreover, the persistent IPSec tunnel can be considered to be able to exist at all times unless it is determined that the IPSec tunnel needs to be removed based on the management of the IPSec tunnels in the network.

[0149] For example, the statistical information may specifically include the frequency of establishing each direct IPSec tunnel between network device 10 and network device 20, and / or the average traffic volume of each direct IPSec tunnel between network device 10 and network device 20. The establishment frequency may specifically refer to the number of times a direct IPSec tunnel is established between network device 10 and network device 20 per unit time; the average traffic volume may specifically refer to the size of service packets transmitted per unit time on each direct IPSec tunnel established between network device 10 and network device 20 to date. For another example, the statistical information may also include other parameter indicators reflecting the usage of each direct IPSec tunnel, such as the peak traffic volume of each direct IPSec tunnel between network device 10 and network device 20.

[0150] The preset condition is set corresponding to the statistical information. For example, if the statistical information is the establishment frequency of each directly connected IPSec tunnel between the network device 10 and the network device 20, then the statistical information satisfies the preset condition specifically if the establishment frequency is greater than or equal to the first threshold (for example, 5 times per hour); for another example, if the statistical information is the average flow of each directly connected IPSec tunnel between the network device 10 and the network device 20, then the statistical information satisfies the preset condition specifically if the average flow is greater than or equal to the second threshold (for example, 100 kilobits per second); for another example, if the statistical information includes the establishment frequency and average flow of each directly connected IPSec tunnel between the network device 10 and the network device 20, then the statistical information satisfies the preset condition including the establishment frequency being greater than or equal to the first threshold and the average flow being greater than or equal to the second threshold. It should be noted that the first threshold and the second threshold are maximum values ​​set according to the actual scenario requirements, and the specific values ​​are not limited in the embodiments of this application.

[0151] In addition, the statistical information may also include the number of IPSec tunnels currently established on network device 10 and network device 20 and the maximum number of IPSec tunnels allowed to be established, and decide whether to establish a permanently connected IPSec tunnel between network device 10 and network device 20 based on the size of the gap between the two.

[0152] The statistical content in the specific statistical information can be flexibly selected and set according to actual conditions and is not specifically limited in this embodiment.

[0153] It should be noted that the network device 10 or the controller 40 can also send statistical information to the network manager, and the network manager will manage the constantly connected IPSec tunnel in the network 100. For example, the network manager configures the instruction of "establishing a constantly connected IPSec tunnel between the network device 10 and the network device 20" to the network device 10 or the controller 40, so as to manage the IPSec tunnel according to any of the two examples above.

[0154] For example, taking the device-level granularity as an example, assuming that the IPSec function is initially enabled, the pre-configured policy on the controller 40 can be specifically reflected in the form of the following Table 1:

[0155] Table 1 Pre-configured policies when initially enabling the IPSec function

[0156] Local network devices IPSec granularity IPSec tunnel in pre-configured policy Network device 10 Device-level IPSec tunnel Network device 30 Network device 20 Device-level IPSec tunnel Network device 30 Network device 30 Device-level IPSec tunnel Network device 10, network device 20

[0157] The pre-configured policy shown in Table 1 instructs network device 10 and network device 30 to establish a persistent IPSec tunnel 2 , and instructs network device 20 and network device 30 to establish a persistent IPSec tunnel 3 .

[0158] If the pre-configuration policy is updated based on this embodiment, and the updated pre-configuration policy indicates that the network device 10 and the network device 20 establish a permanent IPSec tunnel 4, then the updated pre-configuration policy can be embodied in the form shown in Table 2 below:

[0159] Table 2 Updated pre-configured policies

[0160] Local network devices IPSec granularity IPSec tunnel in pre-configured policy Network device 10 Device level Network device 30, network device 20 Network device 20 Device level Network device 30, network device 10 Network device 30 Device level Network device 10, network device 20

[0161] It should be noted that as the network structure changes or the business is updated, the embodiments of the present application can also optimize the management of the always-connected IPSec tunnel indicated in the pre-configured policy. For example, the IPSec tunnel with an average traffic flow less than the third threshold (for example, 200 kilobits per second) in the always-connected IPSec tunnel is updated to a temporary IPSec tunnel. The temporary IPSec tunnel is temporarily established only when there is a business demand and is not established at other times to save network resources.

[0162] It can be seen that in this embodiment, by counting the usage of each direct IPSec tunnel temporarily established on each network device, statistical information is obtained, and based on the statistical information, the IPSec tunnels in the network are optimized and managed, and the temporarily connected IPSec tunnels and the normally connected IPSec tunnels are adaptively adjusted to achieve optimized management of each IPSec tunnel in the network and improve resource utilization in the network. Preferably, for Hub-Spoke traffic models such as SD-WAN, a normally connected IPSec tunnel is established between the Hub node and the Spoke node that transmits business messages more frequently, while a direct IPSec tunnel is dynamically established between the Spoke nodes that transmit fewer business messages based on business needs, and the strategy for managing the IPSec tunnel is flexibly adjusted based on the usage of each network device, so that the transmission business in the network in this scenario is more intelligent and reasonable.

[0163] In the first possible implementation, Figure 8As shown, S102 in the above method 100 may specifically include:

[0164] S102a1 , the network device 10 sends a message 1 to the controller 40 , where the message 1 is used to request to establish a direct IPSec tunnel between the network device 10 and the network device 20 .

[0165] S102a2 , the controller 40 sends a message 2 to the network device 10 , where the message 2 carries the IPSecSA parameter information 2 of the network device 20 .

[0166] S102a3 , the controller 40 sends a message 3 to the network device 20 , where the message 3 carries the IPSecSA parameter information 1 of the network device 10 .

[0167] S102a4, network device 10 determines IPSec SA 12 and IPSec SA 21 based on its own stored IPSec parameter 1 and IPSec SA parameter information 2 in message 2, where IPSec SA 12 is used to securely protect messages transmitted from network device 10 to network device 20, and IPSec SA 21 is used to securely protect messages transmitted from network device 20 to network device 10.

[0168] S102a5 : The network device 20 determines the IPSec SA 21 and the IPSec SA 12 based on the IPSec parameter 2 stored in the network device 20 and the IPSec SA parameter information 1 in the message 3 .

[0169] S102a6 , network device 10 and network device 20 establish IPSec tunnel 1 based on IPSec SA 12 and IPSec SA 21 .

[0170] It should be noted that there is no order restriction on the execution of S102a2 and S102a3. S102a2 can be executed first and then S102a3, or S102a3 can be executed first and then S102a2, or S102a2 and S102a3 can be executed simultaneously. There is no order restriction on the execution of S102a4 and S102a5. S102a4 can be executed first and then S102a5, or S102a5 can be executed first and then S102a4, or S102a4 and S102a5 can be executed simultaneously.

[0171] It should be noted that after S102a4 and S102a5 are executed, IPSec tunnel 1 is considered to have been established, that is, S102a6 is completed. Specifically, after network device 10 executes S102a4, network device 10 considers IPSec tunnel 1 to have been established with network device 20. Similarly, after network device 20 executes S102a5, network device 20 considers IPSec tunnel 1 to have been established with network device 10.

[0172] The format of NLRI in message 1, message 2 and message 3 can be found in Figure 6a to Figure 6c , I will not go into details here.

[0173] When the controller 40 determines that the IPSec tunnel to be established is between the network device 10 and the network device 20, in one case, the controller 40 can directly generate message 2 and message 3 and execute S102a2 and S102a3, so that the network device 10 and the network device 20 can respectively determine a pair of IPSec SAs based on the IPSec SA reference information of the opposite network device carried in the received message, and establish the direct IPSec tunnel 1. In another case, considering that the controller 40 has the function of managing the IPSec tunnels in the entire network 100, the controller 40 can also consider the storage and processing capabilities currently borne by the network devices 10 and 20 after receiving the message 1, or consider the service type or service granularity of the service flow 1 corresponding to the source IP address of the service packet 1 carried in the message 1, and decide whether to allow the direct IPSec tunnel 1 to be established between the network device 10 and the network device 20.

[0174] As an example, taking the example of controller 40 determining whether to establish a direct IPSec tunnel 1 based on the current storage and processing capabilities of network device 10 and network device 20, between S102a1 and S102a2, the embodiment of the present application may further include: S41, controller 40 obtaining the number n of IPSec tunnels currently established on network device 10 and the number m of IPSec tunnels currently established on network device 20, where n and m are both positive integers; S42, controller 40 determining whether the number n reaches a threshold N and whether the data m reaches a threshold M. In one case, if it is determined that the number n does not reach the threshold N and the data m does not reach the threshold M, it indicates that both network device 10 and network device 20 currently allow the establishment of a new IPSec tunnel. Controller 40 may generate message 2 and message 3 and execute S102a2 and S102a3, so that network device 10 and network device 20, respectively, determine a pair of IPSec SAs based on the IPSec SA reference information of the peer network device carried in the received messages, and establish the direct IPSec tunnel 1. In another case, when it is determined that the number n reaches a threshold N or the data m reaches a threshold M, it indicates that network device 10 or network device 20 cannot currently establish a new IPSec tunnel, and controller 40 does not generate message 2 and message 3, and does not execute S102a2 and S102a3. In addition, controller 40 may also send a feedback message to network device 10 to inform network device 10 that it cannot currently establish a direct IPSec tunnel 1 between it and network device 20. Here, threshold N may be the maximum number of IPSec tunnels allowed to be established on network device 10, and threshold M may be the maximum number of IPSec tunnels allowed to be established on network device 20. Alternatively, threshold N may refer to a preset proportion (e.g., 80%) of the maximum number of IPSec tunnels allowed to be established on network device 10, and threshold M may refer to a preset proportion of the maximum number of IPSec tunnels allowed to be established on network device 20. N and M may be equal or unequal.

[0175] It should be noted that after IPSec tunnel 1 is established according to S102a6, the number of IPSec tunnels currently established by network device 10 is (n+1), which should satisfy (n+1)≤N. At the same time, the number of IPSec tunnels currently established by network device 20 is (m+1), which should satisfy (m+1)≤M.

[0176] As another example, taking the example of the controller 40 considering the service type or service granularity of the service flow 1 corresponding to the source IP address of the service message 1 carried in the message 1 and deciding whether to establish a direct IPSec tunnel 1, between S102a1 and S102a2, the embodiment of the present application may also include: S51, the controller 40 obtains the source IP address of the service message 1 from the message 1; S52, the controller 40 determines whether the LAN network or the terminal device IP address in the LAN network corresponding to the source IP address belongs to the pre-known service type and service granularity allowed to be established based on the LAN network or the terminal device IP address in the LAN network corresponding to the pre-known service type and service granularity allowed to be established. If so, the controller 40 can generate message 2 and message 3 and execute S102a2 and S102a3. Otherwise, the controller 40 does not generate message 2 and message 3, and no longer executes S102a2 and S102a3.

[0177] Among them, since when the IPSec function is enabled, each network device will send its own IPSec SA parameter information to the controller 40, the controller 40 can locally save the IPSec SA parameter information of each network device. Then, the controller 40 can directly generate message 2 based on the locally saved IPSec SA parameter information 2 of the network device 20, and generate message 2 based on the locally saved IPSec SA parameter information 1 of the network device 10. Alternatively, if the controller 40 does not locally store the IPSec SA parameter information of each network device, then the message 1 may also carry the IPSec SA parameter information 1 of the network device 10, so that the controller 40 generates message 3 based on the IPSec SA parameter information 1 carried in the message 1 and sends it to the network device 20; the network device 20 not only generates IPSec SA 21 and IPSec SA 12 based on the IPSec SA parameter information 1 in the received message 3, but also sends the IPSec SA parameter information 2 of the network device 20 to the controller 40; the controller 40 generates message 2 based on the IPSec SA parameter information 2 received and sends it to the network device 10, so that the network device 10 generates IPSec SA 12 and IPSec SA 21 based on the IPSec SA parameter information 2.

[0178] It can be seen that through this Figure 8In the implementation method shown, in response to business needs, the network device can dynamically send a message to the controller to request the controller to establish a direct IPSec tunnel between it and another network device. This allows the controller to flexibly establish IPSec tunnels between network devices in the network without the need for complex message interaction between network devices based on the IKE protocol to establish IPSec tunnels, making the process of establishing IPSec tunnels in the network simple and fast. Moreover, the controller will reasonably establish IPSec tunnels at appropriate times based on the characteristics of each network device in the network, rather than establishing a fully connected IPSec tunnel in the network, so that some network devices can choose to deploy network devices with general storage and processing capabilities, saving the cost of network deployment to a certain extent. Preferably, for Hub-Spoke traffic models such as SD-WAN, Hub nodes that support a large number of IPSec tunnels and Spoke nodes that support a small number of IPSec tunnels can be deployed in the same network, and the controller can replace the IKE protocol to manage IPSec tunnels between network devices, achieving more intelligent, convenient and fast transmission services in the network.

[0179] In the second possible implementation, Figure 9 As shown, S102 in the above method 100 may specifically include:

[0180] S102b1 , the network device 10 carries the IPSec SA parameter information 1 of the network device 10 in the service message 1 to obtain the service message 3 .

[0181] S102b2, network device 10 sends the service message 3 to network device 20 through network device 30, wherein network device 10 and network device 30 are directly connected through IPsec tunnel 2, and network device 10 is directly connected to network device 30 through IPsec tunnel 3.

[0182] S102b3, network device 20 determines IPSec SA 21 and IPSec SA 12 based on its own stored IPSec parameter 2 and IPSec SA parameter information 1 in service message 3, wherein IPSec SA 21 is used to securely protect messages transmitted from network device 20 to network device 10, and IPSec SA 12 is used to securely protect messages transmitted from network device 10 to network device 20.

[0183] S102b4, the network device 20 obtains the service message 5, the destination terminal device of the service message 5 belongs to the LAN network to which the network device 10 is connected.

[0184] S102b5 , the network device 20 carries the IPSec SA parameter information 2 of the network device 20 in the service message 5 to obtain the service message 4 .

[0185] S102b6, network device 20 sends the service message 4 to network device 10 through network device 30.

[0186] S102b7 : The network device 10 determines IPSec SA 12 and IPSec SA 21 based on the IPSec parameter 1 stored in the network device 10 and the IPSec SA parameter information 2 in the service packet 4 .

[0187] S102b8 , network device 10 and network device 20 establish IPSec tunnel 1 based on IPSec SA 12 and IPSec SA 21 .

[0188] It should be noted that the execution of the above S101, S102b1~S102b3, and S102b4~S102b7 are independent, and there is no restriction on the order of execution. Whether S101, S102b1~S102b3 or S102b4~S102b7S102a2 are executed first may depend on the time sequence of when the network device 10 receives the service message 1 and when the network device 20 receives the service message 5. If network device 10 receives service message 1 first, it can specifically execute S101, S102b1~S102b3 first and then S102b4~S102b7, and service message 5 can be a response service message to service message 1; if network device 20 receives service message 5 first, it can specifically execute S102b4~S102b7 first and then execute S101, S102b1~S102b3, and service message 1 can be a response service message to service message 5; alternatively, if the time when network device 10 receives service message 1 is the same as the time when network device 20 receives service message 5, then S101, S102b1~S102b3 and S102b4~S102b7 can also be executed simultaneously.

[0189] It should be noted that after S102b3 and S102b7 are executed, IPSec tunnel 1 is considered to have been established, that is, S102b8 is completed. Specifically, after network device 10 executes S102b3, network device 10 considers that IPSec tunnel 1 has been established between itself and network device 20. Similarly, after network device 20 executes S102b7, network device 20 considers that IPSec tunnel 1 has been established between itself and network device 10.

[0190] The establishment process of the permanent IPSec tunnel established between network device 10 and network device 30, and between network device 20 and network device 30 can be seen in detail. Figure 3 Relevant description of "S21~S29" in the embodiment shown.

[0191] In specific implementation, the service message 3 generated by the network device 10 is as follows: Figure 7 As shown, when network device 30 receives service packet 3, it can strip off the OUTER IP header, UDP header, ESP header, VXLAN header / GRE header, and extended IPSec header, revealing the INNER IP / MAC header. Based on the content of the INNER IP / MAC header and local routing information of network device 30, network device 30 can determine whether to send service packet 3 to network device 20 via IPSec tunnel 3. Next, network device 30 sequentially encapsulates the extended IPSec header, VXLAN header / GRE header, ESP header, UDP header, and OUTER IP header into service packet 3, and sends the encapsulated service packet 3 to network device 20 via IPSec tunnel 3. During network device 30's processing of service packet 3, except for the change in the ESP header from the content protected by IPSec SA 13 to the content protected by IPSec SA 32, the content of the other headers remains unchanged. The structure of the service message 4 is similar to that of the service message 3. The service message 4 may also carry the IPSec SA parameter information 2 of the network device 20 through an extended message header IPSec Header.

[0192] It should be noted that, in addition to carrying the IPSec SA parameter information of the local network device, the IPSec header may also carry a flag bit, and the value of the flag bit is used to instruct the receiving network device to enable a direct IPSec tunnel.

[0193] As an example, in this embodiment, after S102b8 and before S103, a process of updating routing may also be included. For network device 10, after network device 10 receives service packet 4 and determines IPSec SA 12 and IPSec SA 21, it may update routing table entry 1 associated with IPSec tunnel 1. Routing table entry 1 is used to indicate that the next hop is network device 20. For network device 20, in one case, network device 20 may update routing table entry 2 associated with IPSec tunnel 1 after executing S102b6; or, in another case, for more reliable communication, network device 20 may update routing table entry 2 associated with IPSec tunnel 1 only after receiving a service packet sent by network device 10 based on IPSec tunnel 1, and send a service packet to network device 10 using IPSec tunnel 1 based on routing table entry 2. Routing table entry 2 is used to indicate that the next hop is network device 10. For example, routing table entry 2 may include the routing prefix and next-hop IP address of network device 10, and routing table entry 2 is associated with IPSec tunnel 1, wherein the next-hop IP address may be, for example, the loopback address of network device 10, through which IPSec tunnel 1 may be found.

[0194] It should be noted that, in the embodiment of the present application, if network device 10 does not update routing table entry 1 associated with IPSec tunnel 1, then all service packets to be sent to the site where network device 10 is located are forwarded to network device 20 via network device 30; similarly, if network device 20 does not update routing table entry 2 associated with IPSec tunnel 1, then all service packets to be sent to the site where network device 20 is located are forwarded to network device 10 via network device 30. If network device 10 updates routing table entry 1 associated with IPSec tunnel 1, then all service packets to be sent to the site where network device 10 is located are sent to network device 20 via the directly connected IPSec tunnel 1; similarly, if network device 20 updates routing table entry 2 associated with IPSec tunnel 1, then all service packets to be sent to the site where network device 20 is located are sent to network device 10 via the directly connected IPSec tunnel 1.

[0195] It can be seen that through this Figure 9In the implementation shown, in response to business needs, a network device can carry its own IPSec SA parameter information in a business message to be sent, and forward it to the peer network device through the existing IPSec tunnel, so that the peer network device can determine the IPSec SA based on the IPSec SA parameter information. In addition, the peer network device performs the same operation, thereby flexibly establishing IPSec tunnels between network devices in the network. This eliminates the need for complex message exchanges between network devices based on the IKE protocol to establish IPSec tunnels, making the process of establishing IPSec tunnels in the network simple and fast. Moreover, based on the characteristics of each network device in the network, the controller reasonably establishes some IPSec tunnels at appropriate times instead of establishing a fully connected IPSec tunnel in the network, allowing some network devices to choose to deploy network devices with average storage and processing capabilities, thereby saving network deployment costs to a certain extent. Preferably, for Hub-Spoke traffic models such as SD-WAN, Hub nodes supporting a large number of IPSec tunnels and Spoke nodes supporting a small number of IPSec tunnels can be deployed in the same network, and the controller can replace the IKE protocol to manage IPSec tunnels between network devices, achieving more intelligent, convenient and fast transmission of services in the network.

[0196] Figure 10 A flow chart of a method 200 for transmitting a service in a network according to an embodiment of the present application is shown. The method 200 is implemented by a first network device. The method 200 for transmitting a service in a network may include, for example:

[0197] S201, a first network device receives a first service packet of a first service flow;

[0198] S202: In response to receiving the first service message, the first network device establishes a first IPSec tunnel directly connected to the second network device;

[0199] S203: The first network device receives a second service packet of the first service flow;

[0200] S204: The first network device sends the second service packet to the second network device through the first IPSec tunnel.

[0201] The first network device in method 200 may specifically be network device 10 in the above-described embodiment, and the operations performed by the first network device may refer to the operations performed by network device 10 in method 100. Specifically, the descriptions of S201 to S204 may refer to S101 to S104 in method 100. The first service flow may be service flow 1 in method 100, the first service packet may be service packet 1 in method 100, the second service packet may be service packet 2 in method 100, the second network device may be network device 20 in method 100, and the first IPSec tunnel may be the IPSec tunnel in method 100.

[0202] As an example, the first network device and the second network device may both be Spoke nodes, and the first network device and the second network device are both connected to a third network device, and the third network device may be a Hub node.

[0203] In a possible implementation, in S202, the first network device establishes a first IPSec tunnel directly connected to the second network device, which may specifically include: the first network device sends a first message to the controller, where the first message is used to request establishment of the first directly connected IPSec tunnel between the first network device and the second network device; the first network device receives a second message sent by the controller, where the second message carries second IPSec SA parameter information of the second network device; the first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA parameter information and the second IPSec SA parameter information stored by itself, wherein the first IPSec SA is used to securely protect messages transmitted from the first network device to the second network device, and the second IPSec SA is used to securely protect messages transmitted from the second network device to the first network device; the first network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0204] In addition, in this embodiment, after the controller receives the first message sent by the first network device, the controller can also send a third message to the second network device, where the third message carries the first IPSecSA parameter information of the first network device. The third message is used to instruct the second network device to determine the first IPSec SA and the second IPSec SA based on the second IPSec SA parameter information and the first IPSec SA parameter information stored by itself, so that the second network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0205] The first message, the second message and the third message are all Border Gateway Protocol update BGPUPDATE messages.

[0206] The first message includes the source IP address and destination IP address of the first service packet, as well as the network segment address of the local area network (LAN) to which the first network device is connected. Furthermore, the first message may include the loopback address of the first network device and / or the IP address of the wide area network (WAN) port of the first network device. The first network device may also carry the first IPSec SA of the first network device. The first message may be extended with a new extended attribute to carry the aforementioned content.

[0207] The second message may include a network layer reachability information NLRI field, the NLRI field including a tunnel type TunnelType field, an endpoint address endpoint address field and the second IPSec SA parameter information, wherein the Tunnel Type field indicates that the type of the tunnel is an IPSec tunnel, and the endpoint address field is used to carry the IP address of the second network device.

[0208] The third message may include a network layer reachability information NLRI field, the NLRI field includes a tunnel type TunnelType field, an endpoint address endpoint address field and the first IPSec SA parameter information, wherein the Tunnel Type field indicates that the type of the tunnel is an IPSec tunnel, and the endpoint address field is used to carry the IP address of the first network device.

[0209] As an example, before S202, the method 200 may also include: the first network device sends the first service message to the second network device through the third network device, wherein the third network device is a central hub node, the first network device and the third network device are directly connected through a second IPsec tunnel, and the second network device is directly connected to the third network device through a third IPsec tunnel.

[0210] The implementation method can be specifically referred to Figure 8 In the embodiment shown, the first message, the second message, and the third message correspond to Figure 8 In the embodiment shown, message 1, message 2, and message 3, the first IPSec SA parameter information, the second IPSec SA parameter information, the first IPSec SA, and the second IPSec SA correspond to Figure 8In the embodiment shown, the IPSec SA parameter information 1, IPSec SA parameter information 2, IPSec SA 12, and IPSec SA 21; the controller may specifically be the controller 40 in the network 100, and the third network device may specifically correspond to the network device 30 in the network 100. The extended NLRI in the first message, the second message, and the third message may specifically refer to Figure 6a to Figure 6c .

[0211] It can be seen that through this implementation, in response to business needs, the first network device can dynamically send a message to the controller to request the controller to establish a direct IPSec tunnel between it and the second network device, which can not only enable the controller to flexibly establish IPSec tunnels between network devices in the network, but also eliminate the need for complex message interactions between network devices based on the IKE protocol to establish IPSec tunnels, making the process of establishing IPSec tunnels in the network simple and fast; moreover, the controller will reasonably establish IPSec tunnels at appropriate times based on the characteristics of each network device in the network, rather than establishing a fully connected IPSec tunnel in the network, so that some network devices can choose to deploy network devices with general storage and processing capabilities, saving the cost of network deployment to a certain extent. Preferably, for Hub-Spoke traffic models such as SD-WAN, Hub nodes that support a larger number of IPSec tunnels and Spoke nodes that support a smaller number of IPSec tunnels can be deployed in the same network, and the controller can replace the IKE protocol to manage IPSec tunnels between network devices, realizing a more intelligent, convenient and fast transmission service in the network.

[0212] In another possible implementation, in S202, the first network device establishes a first IPSec tunnel directly connected to the second network device, which may specifically include: the first network device sends a third service message to the second network device through the third network device, the third service message carries first IPSec SA parameter information, the first IPSec SA parameter information is used to determine a first IPSec SA, and the first IPSec SA is used to securely protect messages transmitted from the first network device to the second network device; wherein the first network device is directly connected to the third network device through a second IPSec tunnel, and the second network device is directly connected to the third network device through a third IPSec tunnel; then, the first network device receives a fourth service message sent by the second network device through the third network device, the fourth service message carries second IPSec SA parameter information, the second IPSec SA parameter information is used to determine a second IPSec SA, and the second IPSec SA is used to securely protect messages transmitted from the second network device to the first network device; the first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA parameter information and the second IPSec SA parameter information; then, the first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA and the second IPSec SA. SA, establish the first IPSec tunnel.

[0213] As an example, the third service packet may carry the first IPSec SA parameter information through an extended first packet header; the fourth service packet includes an extended second packet header, and the extended second packet header carries the second IPSec SA parameter information.

[0214] The implementation method can be specifically referred to Figure 9 In the embodiment shown, the third service message and the fourth service message correspond to Figure 9 In the embodiment shown, the service message 3 and the service message 4, the first IPSec SA parameter information, the second IPSec SA parameter information, the first IPSec SA, and the second IPSec SA correspond to Figure 9 In the embodiment shown, IPSec SA parameter information 1, IPSec SA parameter information 2, IPSec SA 12 and IPSec SA 21; the third network device may specifically correspond to the network device 30 in the network 100, and the second IPSec tunnel may correspond to Figure 9 In the embodiment shown, IPSec tunnel 2 and the third IPSec tunnel correspond to Figure 9 The IPSec tunnel 3 in the embodiment shown. The format of the third service message can be specifically referred to Figure 7.

[0215] It can be seen that through this embodiment, in response to business needs, the network device can carry its own IPSec SA parameter information in the business message to be sent, and forward it to the opposite network device through the existing IPSec tunnel, so that the opposite network device can determine the IPSec SA based on the IPSec SA parameter information. Moreover, the opposite network device performs the same operation, realizing flexible establishment of IPSec tunnels between network devices in the network, without the need for complex message exchange between network devices based on the IKE protocol to establish IPSec tunnels, making the process of establishing IPSec tunnels in the network simple and fast; Moreover, based on the characteristics of each network device in the network, the controller reasonably establishes some IPSec tunnels at appropriate times instead of establishing a fully connected IPSec tunnel in the network, so that some network devices can choose to deploy network devices with general storage and processing capabilities, saving network deployment costs to a certain extent. Preferably, for Hub-Spoke traffic models such as SD-WAN, it is possible to deploy Hub nodes that support a large number of IPSec tunnels and Spoke nodes that support a small number of IPSec tunnels in the same network, and the controller can replace the IKE protocol to manage the IPSec tunnels between network devices, realizing more intelligent, convenient and fast transmission of services in the network.

[0216] In some other possible implementations, in S204, the first network device sends the second service packet to the second network device through the first IPSec tunnel, which may specifically include: the first network device determines to send the second service packet to the second network device through the first IPSec tunnel based on the first routing table entry associated with the first IPSec tunnel, and the next hop of the first routing table entry is the second network device.

[0217] As an example, the method 200 may also include: when the number of packets transmitted through the first IPSec tunnel within a preset first time period is less than or equal to a first threshold, the first network device ages the first routing table entry; or, when the establishment time of the first IPSec tunnel reaches a second time period, the first network device deletes the IPSec SA associated with the first IPSec tunnel, and the second time period is the preset available time period of the first IPSec tunnel. Wherein, aging the first routing table entry, in one case, may refer to deleting the first routing table entry locally from the first network device, and in another case, may refer to setting the status of the first IPSec tunnel associated with the first routing table entry to unavailable. Similarly, deleting the first IPSec SA and the second IPSec SA related to the first IPSec tunnel, in one case, may refer to deleting the first IPSec SA and the second IPSec SA locally from the first network device, and in another case, may refer to setting both the first IPSec SA and the second IPSec SA to an unavailable state.

[0218] In this way, by monitoring the usage of the first IPSec tunnel and making a decision on whether to maintain or dismantle the first IPSec tunnel based on the monitoring results, temporary IPSec tunnels with low utilization are effectively managed, and resources in the network are optimized in a timely manner, making the method for transmitting services in the network provided in the embodiment of the present application more intelligent.

[0219] In some other possible implementations, the method 200 may further include: collecting statistics on usage of each temporarily established direct IPSec tunnel, obtaining statistical information, and optimizing and managing the IPSec tunnels in the network based on the statistical information.

[0220] As an example, the method 200 for optimizing the management of IPSec tunnels in the network may specifically include: the first network device counts the usage of each directly connected IPSec tunnel established between the first network device and the second network device to obtain statistical information; then, the first network device determines that the usage of each directly connected IPSec tunnel meets the preset conditions, and then sets the fourth IPSec tunnel directly connected to the second network device as a normally connected IPSec tunnel.

[0221] As another example, the method 200 for optimizing and managing IPSec tunnels in the network may also specifically include: the first network device counts the usage of each directly connected IPSec tunnel established between the first network device and the second network device to obtain statistical information; the first network device sends a third message to the controller, and the third message carries the statistical information; the first network device receives a fourth message sent by the controller, and the fourth message is generated when the controller determines that the usage of each directly connected IPSec tunnel meets a preset condition, and the fourth message is used to indicate the establishment of a directly connected IPSec tunnel between the first network device and the second network device; the first network device sets the fourth IPSec tunnel directly connected to the second network device as a normally connected IPSec tunnel.

[0222] The statistical information includes at least one of the following: the establishment frequency of each directly connected IPSec tunnel; and the average traffic volume of each directly connected IPSec tunnel. When the statistical information includes the establishment frequency of each directly connected IPSec tunnel, the preset condition includes: the establishment frequency is greater than or equal to a second threshold. When the statistical information includes the average traffic volume of each directly connected IPSec tunnel, the preset condition includes: the average traffic volume is greater than or equal to a third threshold.

[0223] It can be seen that in this embodiment, by counting the usage of each direct IPSec tunnel temporarily established on each network device, statistical information is obtained, and based on the statistical information, the IPSec tunnels in the network are optimized and managed, and the temporarily connected IPSec tunnels and the normally connected IPSec tunnels are adaptively adjusted to achieve optimized management of each IPSec tunnel in the network and improve resource utilization in the network. Preferably, for Hub-Spoke traffic models such as SD-WAN, a normally connected IPSec tunnel is established between the Hub node and the Spoke node that transmits business messages more frequently, while a direct IPSec tunnel is dynamically established between the Spoke nodes that transmit fewer business messages based on business needs, and the strategy for managing the IPSec tunnel is flexibly adjusted based on the usage of each network device, so that the transmission business in the network in this scenario is more intelligent and reasonable.

[0224] It should be noted that the specific implementation and effect of the method 200 in the embodiment of the present application can be found in the above Figure 3 、 Figure 4 、 Figure 8 and Figure 9 Related descriptions in the illustrated embodiments.

[0225] Figure 11A flow chart of a method 300 for transmitting a service in a network according to an embodiment of the present application is shown. The method 300 is implemented by a controller. The method 300 for transmitting a service in a network may include, for example:

[0226] S301, a controller receives a first message sent by a first network device, where the first message is used to request establishment of a direct IPSec tunnel between the first network device and a second network device, wherein, based on a preconfigured policy, a direct first IPSec tunnel is established between the first network device and a third network device, a direct second IPSec tunnel is established between the second network device and the third network device, and no direct IPSec tunnel is established between the first network device and the second network device;

[0227] S302: The controller sends a second message to the first network device, where the second message carries first IPSec SA parameter information of the second network device, and the first IPSec SA parameter information is used by the first network device to establish a third IPSec tunnel directly connected to the second network device.

[0228] S303, the controller sends a third message to the second network device, where the third message carries the second IPSec SA parameter information of the first network device, and the second IPSec SA parameter information is used by the second network device to establish the third IPSec tunnel directly connected to the first network device.

[0229] The first network device and the second network device may both be Spoke nodes, and the third network device may be a Hub node.

[0230] The first message, the second message and the third message are BGPUPDATE messages. Figure 6a to Figure 6c .

[0231] The method 300 can be specifically referred to Figure 4 and Figure 8 In the embodiment shown, the first message, the second message, and the third message correspond to Figure 8 In the embodiment shown, message 1, message 2, and message 3, the first IPSec SA parameter information, the second IPSec SA parameter information, the first IPSec SA, and the second IPSec SA correspond to Figure 8IPSec SA parameter information 1, IPSec SA parameter information 2, IPSec SA 12 and IPSec SA 21 in the illustrated embodiment; the controller can specifically be the controller 40 in the network 100, the first network device can specifically be the network device 10 in the network 100, the second network device can specifically be the network device 20 in the network 100, and the third network device can specifically correspond to the network device 30 in the network 100.

[0232] As an example, before S302 and S303, that is, before the controller sends the second message and the third message, the method 300 may also include: the controller obtains a first number of IPSec tunnels currently available on the first network device and a second number of IPSec tunnels currently available on the second network device; the controller determines that the first number is less than or equal to a first threshold and the second number is less than or equal to a second threshold, wherein the first threshold is the maximum number of IPSec tunnels allowed to be established on the first network device, and the second threshold is the maximum number of IPSec tunnels allowed to be established on the second network device. In this way, the controller can comprehensively consider the storage and processing capabilities currently borne by each network device and determine whether to allow the first directly connected IPSec tunnel to be established between the first network device and the second network device, making the method 300 more intelligent and reliable.

[0233] In some possible implementations, the method 300 may further include: a controller receiving a fourth message sent by the first network device, the fourth message carrying statistical information, the statistical information being used to indicate usage of each permanently connected direct IPSec tunnel established between the first network device and the second network device; the controller determining that the statistical information meets a preset condition, then updating the pre-configured policy to obtain an updated configuration policy; the controller instructing the first network device to establish a permanently connected fourth IPSec tunnel between the second network device in accordance with the updated configuration policy.

[0234] The statistical information includes at least one of the following: the establishment frequency of each directly connected IPSec tunnel; and the average traffic volume of each directly connected IPSec tunnel. When the statistical information includes the establishment frequency of each directly connected IPSec tunnel, the preset condition includes the establishment frequency being greater than or equal to a third threshold. When the statistical information includes the average traffic volume of each directly connected IPSec tunnel, the preset condition includes the average traffic volume being greater than or equal to a fourth threshold.

[0235] It should be noted that the specific implementation and effect of the method 300 in the embodiment of the present application can be found in the above Figure 3 、 Figure 4 、 Figure 8 and Figure 10 Related descriptions in the illustrated embodiments.

[0236] Figure 12 A flow chart of a method 400 for transmitting a service in a network according to an embodiment of the present application is shown. The method 400 is implemented by a second network device. The method 400 for transmitting a service in a network may include, for example:

[0237] S401: A second network device receives, via a third network device, a first service packet sent by a first network device. The first network device and the third network device are directly connected via a first IPsec tunnel, and the second network device and the third network device are directly connected via a second IPsec tunnel. The first service packet carries first IPsec SA parameter information of the first network device.

[0238] S402: The second network device establishes a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored in the second network device.

[0239] S403, the second network device receives a second service message;

[0240] S404: The second network device sends the second service packet to the first network device through the third IPSec tunnel.

[0241] The first network device and the second network device may both be Spoke nodes, and the third network device may be a Hub node.

[0242] The method 400 can be specifically referred to Figure 4 and Figure 9 In the embodiment shown, the first network device may be the network device 10 in the network 100, the second network device may be the network device 20 in the network 100, the third network device may correspond to the network device 30 in the network 100, and the first service message may be Figure 9 In the embodiment shown, the service message 3, the first IPSec SA parameter information, the second IPSec SA parameter information, the first IPSec SA, and the second IPSec SA correspond to Figure 9 In the embodiment shown, IPSec SA parameter information 1, IPSec SA parameter information 2, IPSec SA 12 and IPSec SA 21; the first IPSec tunnel, the second IPSec tunnel and the third IPSec tunnel correspond to Figure 9 IPSec tunnel 2, IPSec tunnel 3 and IPSec tunnel 1 in the illustrated embodiment.

[0243] As an example, in S402, the second network device establishes a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored by itself. Specifically, it may include: the second network device determines the first IPSec SA and the second IPSec SA according to the first IPSec SA parameter information and the second IPSec SA parameter information, wherein the first IPSec SA is used to securely protect the messages transmitted from the first network device to the second network device, and the second IPSec SA is used to securely protect the messages transmitted from the second network device to the first network device; the second network device establishes the third IPSec tunnel based on the first IPSec SA and the second IPSec SA.

[0244] In some possible implementations, before S404, that is, before the second network device sends the second service message to the first network device through the third IPSec tunnel, the method 400 may also include: the second network device sends a third service message to the first network device through the third network device, and the third service message carries the second IPSec SA parameter information of the second network device, and the second IPSec SA parameter information is used by the first network device to establish the third IPSec tunnel directly connected to the second network device.

[0245] As an example, S404 may specifically include: the second network device determines, according to a first routing table entry associated with the third IPSec tunnel, to send the second service packet to the first network device through the third IPSec tunnel.

[0246] The first service message carries the first IPSec SA parameter information through an extended message header.

[0247] It should be noted that the specific implementation and effect of the method 400 in the embodiment of the present application can be found in the above Figure 3 、 Figure 4 、 Figure 9 and Figure 10 Related descriptions in the illustrated embodiments.

[0248] Accordingly, the embodiment of the present application also provides a network device 1300, see Figure 13As shown. The network device 1300 includes a transceiver unit 1301 and a processing unit 1302. The transceiver unit 1301 is used to perform the transceiver operation implemented by the network device 10 in the above-mentioned method 100, or the transceiver unit 1301 is used to perform the transceiver operation implemented by the first network device in the above-mentioned method 200, method 300 or method 400; the processing unit 1302 is used to perform other operations other than the transceiver operation implemented by the network device 10 in the above-mentioned method 100, or the processing unit 1302 is used to perform other operations other than the transceiver operation implemented by the first network device in the above-mentioned method 200, method 300 or method 400. For example: when the network device 1300 executes the method implemented by the network device 10 in the method 100, the transceiver unit 1301 can be used to receive business message 1 of business flow 1, and can also be used to receive business message 2 of business flow 1, and can also be used to send business message 2 based on IPSec tunnel 1; the processing unit 1302 can be used to establish IPSec tunnel 1 with the network device 20 in response to the received business message 1.

[0249] In addition, the embodiment of the present application also provides a network device 1400, see Figure 14 As shown. The network device 1400 includes a transceiver unit 1401 and a processing unit 1402. The transceiver unit 1401 is used to perform the transceiver operation implemented by the network device 20 in the above-mentioned method 100, or the transceiver unit 1401 is used to perform the transceiver operation implemented by the second network device in the method 200, method 300 or method 400; the processing unit 1402 is used to perform other operations other than the transceiver operation implemented by the network device 20 in the above-mentioned method 100, or the processing unit 1402 is used to perform other operations other than the transceiver operation implemented by the second network device in the above-mentioned method 200, method 300 or method 400. For example: when the network device 1400 executes the method implemented by the network device 20 in the method 100, the transceiver unit 1401 can be used to receive service message 3, can also be used to receive service message 5, and can also be used to send service message 4; the processing unit 1402 can be used to determine IPSec SA 21 and IPSec SA 12 in response to the IPSec SA parameter information 2 stored in itself and the IPSec SA parameter information 1 in the service message 3, and the processing unit 1402 can also be used to carry IPSec SA parameter information 2 in the service message 5 to obtain service message 4.

[0250] In addition, the present application embodiment also provides a controller 1500, see Figure 15As shown. The controller 1500 includes a transceiver unit 1501 and a processing unit 1502. The transceiver unit 1501 is used to perform the transceiver operation implemented by the controller 40 in the above-mentioned method 100, or the transceiver unit 1501 is used to perform the transceiver operation implemented by the controller in the method 200 or the method 300; the processing unit 1502 is used to perform other operations other than the transceiver operation implemented by the controller 40 in the above-mentioned method 100, or the processing unit 1502 is used to perform other operations other than the transceiver operation implemented by the controller in the above-mentioned method 200 or the method 300. For example: when the controller 1500 executes the method implemented by the controller 40 in the method 100, the transceiver unit 1501 can be used to receive message 1, and can also be used to send message 2 to the network device 10 and send message 3 to the network device 20; the processing unit 1502 can be used to update the preconfigured policy based on the statistical information obtained from the received message 4, after determining that the statistical information meets the preset conditions.

[0251] In addition, the embodiment of the present application further provides a network device 1600, see Figure 16 As shown. The network device 1600 includes a communication interface 1601 and a processor 1602. The communication interface 1601 includes a first communication interface 1601a and a second communication interface 1601b. The first communication interface 1601a is used to perform the receiving operation performed by the network device 10 in the embodiment shown in the aforementioned method 100, or the first communication interface 1601a is also used to perform the receiving operation performed by the first network device in the embodiments shown in the aforementioned methods 200 to 400; the second communication interface 1601b is used to perform the sending operation performed by the network device 10 in the embodiment shown in the aforementioned method 100, or the second communication interface 1601b is also used to perform the sending operation performed by the first network device in the embodiments shown in the aforementioned methods 200 to 400; the processor 1602 is used to perform other operations other than the receiving and sending operations performed by the network device 10 in the embodiment shown in the aforementioned method 100, or the processor 1602 is also used to perform other operations other than the receiving and sending operations performed by the first network device in the embodiments shown in the aforementioned methods 200 to 400. For example, the processor 1602 may execute the operations in the embodiment of the method 100 : in response to the received service message 1 , establish a direct IPSec tunnel 1 with the network device 20 .

[0252] In addition, the embodiment of the present application also provides a network device 1700, see Figure 17As shown. The network device 1700 includes a communication interface 1701 and a processor 1702. The communication interface 1701 includes a first communication interface 1701a and a second communication interface 1701b. The first communication interface 1701a is used to perform the receiving operation performed by the network device 20 in the embodiment shown in the aforementioned method 100, or the first communication interface 1701a is also used to perform the receiving operation performed by the second network device in the embodiments shown in the aforementioned methods 200 to 400; the second communication interface 1701b is used to perform the sending operation performed by the network device 20 in the embodiment shown in the aforementioned method 100, or the second communication interface 1701b is also used to perform the sending operation performed by the second network device in the embodiments shown in the aforementioned methods 200 to 400; the processor 1702 is used to perform other operations other than the receiving and sending operations performed by the network device 20 in the embodiment shown in the aforementioned method 100, or the processor 1702 is also used to perform other operations other than the receiving and sending operations performed by the second network device in the embodiments shown in the aforementioned methods 200 to 400. For example, the processor 1702 may execute the operation in the embodiment of the method 400: establishing a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored in the processor 1702.

[0253] In addition, the present application embodiment also provides a controller 1800, see Figure 18As shown. The controller 1800 includes a communication interface 1801 and a processor 1802. The communication interface 1801 includes a first communication interface 1801a and a second communication interface 1801b. The first communication interface 1801a is used to perform the receiving operation performed by the controller 40 in the embodiment shown in the aforementioned method 100, or the first communication interface 1801a is also used to perform the receiving operation performed by the controller in the embodiment shown in the aforementioned method 200 or method 300; the second communication interface 1801b is used to perform the sending operation performed by the controller 40 in the embodiment shown in the aforementioned method 100, or the second communication interface 1801b is also used to perform the sending operation performed by the controller in the embodiment shown in the aforementioned method 200 or method 300; the processor 1802 is used to perform other operations other than the receiving and sending operations performed by the controller 40 in the embodiment shown in the aforementioned method 100, or the processor 1802 is also used to perform other operations other than the receiving and sending operations performed by the controller in the embodiment shown in the aforementioned method 200 or method 200. For example: processor 1802 can perform the operations in the embodiment of method 300: obtain a first number of IPSec tunnels currently available on the first network device and a second number of IPSec tunnels currently available on the second network device; determine that the first number is less than or equal to a first threshold and the second number is less than or equal to a second threshold.

[0254] In addition, the embodiment of the present application also provides a network device 1900, see Figure 19 As shown. The network device 1900 includes a memory 1901 and a processor 1902 in communication with the memory 1901. The memory 1901 includes computer-readable instructions; the processor 1902 is configured to execute the computer-readable instructions, so that the network device 1900 performs the method performed by the network device 10 in the above method 100, as well as the methods performed by the first network device in methods 200 to 400.

[0255] In addition, the present invention also provides a network device 2000. Figure 20 As shown. The network device 2000 includes a memory 2001 and a processor 2002 in communication with the memory 2001. The memory 2001 includes computer-readable instructions; the processor 2002 is configured to execute the computer-readable instructions, causing the network device 2000 to execute the method executed by the network device 20 in the above method 100, as well as the method executed by the second network device in methods 200 to 400.

[0256] In addition, the present application embodiment also provides a controller 2100, see Figure 21The controller 2100 includes a memory 2101 and a processor 2102 in communication with the memory 2101. The memory 2101 includes computer-readable instructions; the processor 2102 is configured to execute the computer-readable instructions, causing the controller 2100 to execute the method executed by the controller 40 in the above method 100, as well as the methods executed by the controller in methods 200 and 300.

[0257] It is understood that in the above embodiments, the processor may be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP. The processor may also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor may refer to one processor or may include multiple processors. Memory can include volatile memory (e.g., random-access memory (RAM)). Memory can also include non-volatile memory (e.g., read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD). Memory can also include a combination of the aforementioned types of memory. Memory can refer to a single memory or multiple memories. In one specific embodiment, the memory stores computer-readable instructions, which include multiple software modules, such as a sending module, a processing module, and a receiving module. After executing each software module, the processor can perform corresponding operations according to the instructions of each software module. In this embodiment, the operations performed by a software module actually refer to the operations performed by the processor according to the instructions of the software module. After executing the computer-readable instructions in the memory, the processor can perform all operations that can be performed by the network device or controller according to the instructions of the computer-readable instructions.

[0258] It will be understood that in the above embodiment, the communication interface 1601 of the network device 1600 can be specifically used as the transceiver unit 1301 in the network device 1300 to implement communication between the network device and other network devices or controllers. Similarly, the communication interface 1701 of the network device 1700 can be specifically used as the transceiver unit 1401 in the network device 1400 to implement communication between the network device and other network devices or controllers; and the communication interface 1801 of the controller 1800 can be specifically used as the transceiver unit 1501 in the controller 1500 to implement communication between the controller and other network devices.

[0259] In addition, the present embodiment also provides a communication system 2200, see Figure 22 The communication system 2200 includes a first network device 2201, a second network device 2202, and a controller 2203, wherein the first network device 2201 may be the network device 1300, the network device 1600, or the network device 1900, the second network device 2202 may be the network device 1400, the network device 1700, or the network device 2000, and the controller 2203 may be the controller 1500, the controller 1800, or the controller 2100. Alternatively, the first network device 2201 may also be Figure 1 The network device 10 in the network shown, the second network device 2202 can also be Figure 1 The network device 20 in the network shown, the controller 2203 can also be Figure 1 Controller 40 in the network shown.

[0260] In addition, an embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is run on a computer, the computer executes the method for transmitting services in the network in the embodiments shown in the above method 100, method 200, method 300 or method 400.

[0261] In addition, an embodiment of the present application also provides a computer program product, including a computer program or computer-readable instructions. When the computer program or the computer-readable instructions are run on a computer, the computer executes the method for transmitting services in the network in the embodiments shown in the aforementioned method 100, method 200, method 300 or method 400.

[0262] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or certain parts of the embodiments of the present application.

[0263] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments. The device and system embodiments described above are merely schematic. The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative effort.

[0264] The above description is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application. It should be noted that those skilled in the art may make several improvements and modifications without departing from the scope of protection of the present application, and such improvements and modifications should also be considered as within the scope of protection of the present application.

Claims

1. A method for transmitting services in a network, characterized in that: The method comprises: The first network device receives a first service packet of a first service flow; In response to receiving the first service packet, the first network device establishes, based on the first IPSec SA parameter information and the second IPSec SA parameter information of the second network device, a first IPSec tunnel directly connected to the second network device, where the first IPSec SA parameter information is used to determine a first IPSec SA, which is used to securely protect packets transmitted from the first network device to the second network device, and the second IPSec SA parameter information is used to determine a second IPSec SA, which is used to securely protect packets transmitted from the second network device to the first network device. The first network device receives a second service message of the first service flow; The first network device sends the second service message to the second network device through the first IPSec tunnel.

2. The method according to claim 1, characterized in that The first network device establishing a first IPSec tunnel directly connected to the second network device includes: The first network device sends a first message to the controller, where the first message is used to request establishment of the directly connected first IPSec tunnel between the first network device and the second network device; The first network device receives a second message sent by the controller, where the second message carries second IPSec SA parameter information of the second network device; The first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA parameter information and the second IPSec SA parameter information stored in the first network device; The first network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

3. The method according to claim 2, characterized in that The first message and the second message are both Border Gateway Protocol update BGP UPDATE messages.

4. The method according to claim 2, characterized in that The second message includes a network layer reachability information NLRI field, the NLRI field includes a tunnel type Tunnel Type field, an endpoint address endpoint address field and the second IPSec SA parameter information, wherein the Tunnel Type field indicates that the type of the tunnel is an IPSec tunnel, and the endpoint address field is used to carry the IP address of the second network device.

5. The method according to claim 1, wherein Before the first network device establishes a first IPSec tunnel directly connected to the second network device, the method further includes: The first network device sends the first service message to the second network device through a third network device, wherein the third network device is a central hub node, the first network device and the third network device are directly connected through a second IPsec tunnel, and the second network device is directly connected to the third network device through a third IPsec tunnel.

6. The method according to claim 1, characterized in that The first network device establishing a first IPSec tunnel directly connected to the second network device includes: The first network device sends a third service message to the second network device through the third network device, where the third service message carries first IPSec SA parameter information; wherein the first network device is directly connected to the third network device through the second IPsec tunnel, and the second network device is directly connected to the third network device through the third IPsec tunnel; The first network device receives, through the third network device, a fourth service packet sent by the second network device, where the fourth service packet carries second IPSec SA parameter information; The first network device determines the first IPSec SA and the second IPSec SA based on the first IPSec SA parameter information and the second IPSec SA parameter information; The first network device establishes the first IPSec tunnel based on the first IPSec SA and the second IPSec SA.

7. The method according to claim 6, characterized in that The third service message carries the first IPSec SA parameter information through the extended first message header; The fourth service message includes an extended second message header, and the extended second message header carries the second IPSec SA parameter information.

8. The method according to any one of claims 1 to 7, characterized in that The first network device sending the second service packet to the second network device through the first IPSec tunnel includes: The first network device determines to send the second service packet to the second network device through the first IPSec tunnel based on a first routing table entry associated with the first IPSec tunnel, where the next hop of the first routing table entry is the second network device.

9. The method according to claim 8, characterized in that The method further comprises: When the number of packets transmitted through the first IPSec tunnel within a preset first time period is less than or equal to a first threshold, the first network device ages the first routing table entry; or When the duration of establishing the first IPSec tunnel reaches a second duration, the first network device deletes the IPSec SA associated with the first IPSec tunnel, where the second duration is a preset available duration of the first IPSec tunnel.

10. The method according to claim 1, characterized in that The method further comprises: The first network device collects statistics on usage of each directly connected IPSec tunnel established between the first network device and the second network device to obtain statistical information; If the first network device determines that usage of each directly connected IPSec tunnel meets a preset condition, then the fourth IPSec tunnel directly connected to the second network device is set as a constantly connected IPSec tunnel.

11. The method according to claim 1, wherein The method further comprises: The first network device collects statistics on usage of each directly connected IPSec tunnel established between the first network device and the second network device to obtain statistical information; The first network device sends a third message to the controller, where the third message carries the statistical information; The first network device receives a fourth message sent by the controller, where the fourth message is generated by the controller when determining that usage of each direct IPSec tunnel meets a preset condition, and the fourth message is used to instruct the first network device to establish a permanent direct IPSec tunnel with the second network device; The first network device sets a fourth IPSec tunnel directly connected to the second network device as a constantly connected IPSec tunnel.

12. The method according to claim 10 or 11, characterized in that The statistical information includes at least one of the following: The frequency of establishing each direct IPSec tunnel; The average traffic volume of each direct IPSec tunnel.

13. The method according to claim 12, characterized in that The statistical information includes the establishment frequency of each direct IPSec tunnel, and the preset condition includes that the establishment frequency is greater than or equal to a second threshold.

14. The method according to claim 12, characterized in that The statistical information includes an average flow rate of each directly connected IPSec tunnel, and the preset condition includes: the average flow rate is greater than or equal to a third threshold.

15. The method according to any one of claims 1 to 7, characterized in that The first network device and the second network device are both Spoke nodes. The first network device and the second network device are both connected to a third network device, and the third network device is a Hub node.

16. A method for transmitting services in a network, characterized in that: The method comprises: The controller receives a first message sent by a first network device, where the first message is used to request establishment of a direct IPSec tunnel between the first network device and a second network device, the first message being a message generated by the first network device when receiving a first service message of a first service flow and sent to the controller, wherein, based on a preconfigured policy, a direct first IPSec tunnel is established between the first network device and a third network device, a direct second IPSec tunnel is established between the second network device and the third network device, and no direct IPSec tunnel is established between the first network device and the second network device; The controller sends a second message to the first network device, where the second message carries first IPSec SA parameter information of the second network device, where the first IPSec SA parameter information is used by the first network device to establish a third IPSec tunnel directly connected to the second network device, where the first IPSec SA parameter information is used to determine a first IPSec SA, where the first IPSec SA is used to securely protect packets transmitted from the first network device to the second network device. The controller sends a third message to the second network device, where the third message carries second IPSec SA parameter information of the first network device. The second IPSec SA parameter information is used by the second network device to establish the third IPSec tunnel directly connected to the first network device. The second IPSec SA parameter information is used to determine the second IPSec SA, which is used to securely protect messages transmitted from the second network device to the first network device.

17. The method according to claim 16, characterized in that The first message, the second message and the third message are Border Gateway Protocol Update BGP UPDATE messages.

18. The method according to claim 16, characterized in that Before the controller sends the second message and the third message, the method further includes: The controller obtains a first number of IPSec tunnels currently available on the first network device and a second number of IPSec tunnels currently available on the second network device; The controller determines that the first number is less than or equal to a first threshold and the second number is less than or equal to a second threshold, wherein the first threshold is the maximum number of IPSec tunnels allowed to be established on the first network device, and the second threshold is the maximum number of IPSec tunnels allowed to be established on the second network device.

19. The method according to any one of claims 16 to 18, characterized in that: The method further comprises: The controller receives a fourth message sent by the first network device, where the fourth message carries statistical information, where the statistical information is used to indicate usage of each non-trivial direct IPSec tunnel established between the first network device and the second network device; If the controller determines that the statistical information satisfies a preset condition, then the pre-configured policy is updated to obtain an updated configuration policy; The controller instructs the first network device to establish a fourth IPSec tunnel that is always connected between the first network device and the second network device according to the updated configuration policy.

20. The method according to claim 19, wherein The statistical information includes at least one of the following: The frequency of establishing each direct IPSec tunnel; The average traffic volume of each direct IPSec tunnel.

21. The method according to claim 20, characterized in that The statistical information includes the establishment frequency of each direct IPSec tunnel, and the preset condition includes that the establishment frequency is greater than or equal to a third threshold.

22. The method according to claim 20 or 21, characterized in that The statistical information includes the average traffic of each directly connected IPSec tunnel, and the preset condition includes that the average traffic is greater than or equal to a fourth threshold.

23. The method according to any one of claims 16 to 18, characterized in that The first network device and the second network device are both branch Spoke nodes, and the third network device is a central Hub node.

24. A method for transmitting services in a network, characterized in that: The method comprises: The second network device receives a first service packet sent by the first network device through the third network device, the first network device and the third network device are directly connected via a first IPsec tunnel, and the second network device and the third network device are directly connected via a second IPsec tunnel, the first service packet carries first IPSec SA parameter information of the first network device, and the first service packet is a service packet sent by the first network device to the second network device through the third network device after receiving the fourth service packet of the first service flow; The second network device establishes, based on the second IPSec SA parameter information stored in the second network device and the first IPSec SA parameter information, a third IPSec tunnel directly connected to the first network device, where the first IPSec SA parameter information is used to determine a first IPSec SA, which is used to securely protect messages transmitted from the first network device to the second network device, and the second IPSec SA parameter information is used to determine a second IPSec SA, which is used to securely protect messages transmitted from the second network device to the first network device. The second network device receives a second service packet of the first service flow; The second network device sends the second service message to the first network device through the third IPSec tunnel.

25. The method according to claim 24, characterized in that The second network device establishes a third IPSec tunnel directly connected to the first network device based on the second IPSec SA parameter information and the first IPSec SA parameter information stored in the second network device, including: The second network device determines a first IPSec SA and a second IPSec SA according to the first IPSec SA parameter information and the second IPSec SA parameter information; The second network device establishes the third IPSec tunnel based on the first IPSec SA and the second IPSec SA.

26. The method according to claim 24, characterized in that Before the second network device sends the second service packet to the first network device through the third IPSec tunnel, the method further includes: The second network device sends a third service message to the first network device through the third network device, and the third service message carries the second IPSec SA parameter information of the second network device. The second IPSec SA parameter information is used by the first network device to establish the third IPSec tunnel directly connected to the second network device.

27. The method according to claim 26, characterized in that The second network device sending the second service message to the first network device through the third IPSec tunnel includes: The second network device determines, based on a first routing table entry associated with the third IPSec tunnel, to send the second service packet to the first network device through the third IPSec tunnel.

28. The method according to any one of claims 24 to 27, characterized in that The first service message carries the first IPSec SA parameter information through an extended message header.

29. The method according to any one of claims 24 to 27, characterized in that The first network device and the second network device are both branch Spoke nodes, and the third network device is a central Hub node.

30. A network device, characterized in that: include: a memory comprising computer-readable instructions; A processor in communication with the memory, the processor being configured to execute the computer-readable instructions so that the network device is configured to execute the method according to any one of claims 1 to 15.

31. A controller, characterized in that: include: a memory comprising computer-readable instructions; A processor in communication with the memory, the processor being configured to execute the computer-readable instructions so that the controller is configured to execute the method of any one of claims 16 to 23.

32. A network device, characterized in that: include: a memory comprising computer-readable instructions; A processor in communication with the memory, the processor being configured to execute the computer-readable instructions so that the network device is configured to execute the method of any one of claims 24-29.

33. A computer-readable storage medium, characterized in that The method comprises computer-readable instructions, wherein when the computer-readable instructions are executed on a computer, the computer is caused to implement the method according to any one of claims 1 to 29.

34. A communication system comprising the network device according to claim 30, the controller according to claim 31 and the network device according to claim 32.

35. A computer program product, characterized in that The method comprises a computer program or a computer-readable instruction, which, when the computer program or the computer-readable instruction is run on a computer, causes the computer to execute the method according to any one of claims 1 to 29.

Citation Information

Patent Citations

  • NAT (network address translation) method and device applied to DVPN (dynamic virtual private network)

    CN104427010A

  • Safety-alliance (SA) generation method for safety communication between nodes of network area

    CN1406005A