Message Processing Method, Device, System, and Storage Medium

By using IPv6 expansion header to carry EPG information in IPv6 network, the problem of large transmission overhead and insufficient scalability caused by VXLAN header carrying EPG information in the prior art is solved, and more efficient micro-segmentation function and lower configuration complexity are achieved.

CN113472650BActive Publication Date: 2025-06-24HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010245961.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-03-31
Publication Date
2025-06-24
Estimated Expiration
2040-03-31

AI Technical Summary

Technical Problem

When transmitting packets, the existing micro-segmentation technology relies on the VXLAN header to carry EPG information, resulting in excessive overhead of transmitting packets in the network and insufficient scalability.

Method used

In an IPv6 network, by carrying EPG information in the IPv6 extension header of the IPv6 message, the EPG information is visible to the receiver, avoiding decapsulation of the VXLAN header, thereby realizing the micro-segmentation function and reducing the processing complexity.

Benefits of technology

Carrying EPG information through the IPv6 expansion header reduces the overhead of transmitting packets, improves scalability, reduces the configuration complexity of group policy execution nodes, and improves the efficiency of deploying micro-segmentation in IPv6 networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113472650B_ABST
    Figure CN113472650B_ABST
Patent Text Reader

Abstract

The present application provides a message processing method, device, system and storage medium, belonging to the field of communication technologies. The present application provides a method for implementing microsegmentation in an IPv6 network. By using the IPv6 extension header of an IPv6 message to carry EPG information, the EPG information is made visible to the receiving end of the IPv6 message, so that the receiving end of the IPv6 message can execute group policies according to the EPG information in the IPv6 extension header, thereby implementing the function of microsegmentation. Since the IPv6 extension header has stronger extensibility, the problem of weak extensibility existing in carrying EPG information through the VXLAN header is solved, which helps to continue to expand new functions. Moreover, since the encapsulation format of the message is more concise and the header occupies fewer bytes, the overhead caused by transmitting the message is saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and particularly to a method, device, system, and storage medium for message processing. Background Art

[0002] Micro-segmentation is a network isolation technology based on refined grouping. The micro-segmentation technology can group the devices in the network according to a grouping rule with a finer granularity than that of a Virtual Local Area Network (VLAN), define group policies for each group, and execute the group policies to achieve traffic isolation, thereby ensuring service security.

[0003] In the field of micro-segmentation, a group is called an Endpoint Group (EPG). An EPG can include multiple members such as servers and terminals, and the members included in the EPG are called endpoints. In the process of implementing micro-segmentation, when an original message sent by a source Endpoint device arrives at a source Virtual Tunnel Endpoint (VTEP) device, the source VTEP will carry the EPG information of the source Endpoint device in the Virtual Extensible Local Area Network (VXLAN) header, encapsulate the VXLAN header for the original message, and obtain a VXLAN message. The source VTEP will send the VXLAN message to the destination VTEP. After receiving the VXLAN message, the destination VTEP device will de-encapsulate the VXLAN header to obtain the EPG information of the source Endpoint device. The destination VTEP will execute the group policy according to the EPG information of the source Endpoint device and the EPG information of the destination end.

[0004] When implementing the micro-segmentation technology using the above method, it is necessary to rely on the VXLAN header to carry the EPG information, and the VXLAN header is an Overlay header, and the encapsulation of the header is not concise enough, resulting in too large an overhead for the messages transmitted in the network. Summary of the Invention

[0005] Embodiments of this application provide a method, device, system, and storage medium for message processing, which can reduce the overhead of transmitted messages. The technical solution is as follows:

[0006] In a first aspect, a packet processing method is provided, which is applied to an Internet Protocol version 6 (IPv6) network. In this method, a first network device in the IPv6 network receives an original packet; the first network device generates an IPv6 packet according to the original packet and endpoint group (EPG) information, where the IPv6 packet includes an IPv6 extension header and the original packet, and the IPv6 extension header includes the EPG information; the first network device sends the IPv6 packet.

[0007] The above provides a method for implementing micro-segmentation in an IPv6 network. By using the IPv6 extension header of the IPv6 packet to carry the EPG information, the EPG information is made visible to the receiving end of the IPv6 packet, so that the receiving end of the IPv6 packet does not need to de-encapsulate the VXLAN header and can execute the group policy according to the EPG information in the IPv6 extension header, thereby implementing the function of micro-segmentation and reducing the processing complexity. Moreover, since the IPv6 extension header has stronger extensibility, the problem of weak extensibility existing in carrying the EPG information through the VXLAN header is solved, which helps to continue to expand new functions. And, since the encapsulation format of the packet is more concise and the header occupies fewer bytes, the overhead caused by transmitting the packet is saved.

[0008] Optionally, the EPG information includes first EPG information. The first EPG information is used to identify the EPG to which a first computing device belongs, and the source Internet Protocol (IP) address of the original packet includes the IP address of the first computing device.

[0009] By carrying the EPG information of the source Endpoint device in the IPv6 extension header of the IPv6 packet, the EPG information of the source Endpoint device is forwarded in the IPv6 network along with the IPv6 packet. During the process of forwarding the IPv6 packet, the execution node of the group policy can obtain the EPG information of the source Endpoint device from the IPv6 extension header, thus eliminating the workload caused by pre-configuring the EPG information of the source Endpoint device on the execution node of the group policy, thereby reducing the configuration complexity of the execution node of the group policy and helping to improve the efficiency of deploying micro-segmentation in the IPv6 network.

[0010] Optionally, the EPG information includes second EPG information. The second EPG information is used to identify the EPG to which a second computing device belongs, and the destination IP address of the original packet includes the IP address of the second computing device.

[0011] By using an IPv6 extension header to transfer the EPG information of the destination Endpoint device in an IPv6 network, the execution node of the group policy can obtain the EPG information of the destination Endpoint device from the IPv6 extension header during the process of forwarding IPv6 packets. Therefore, the workload caused by pre-configuring the EPG information of the destination Endpoint device on the execution node of the group policy is eliminated, thereby reducing the configuration complexity of the execution node of the group policy and helping to improve the efficiency of deploying micro-segmentation in the IPv6 network.

[0012] Optionally, the EPG information includes first EPG information and second EPG information.

[0013] By using an IPv6 extension header to transfer the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device in an IPv6 network, the execution node of the group policy can obtain the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device from the IPv6 extension header during the process of forwarding IPv6 packets. Therefore, the workload caused by pre-configuring the EPG information of the source Endpoint device and the destination Endpoint device on the execution node of the group policy is eliminated, thereby reducing the configuration complexity of the execution node of the group policy and helping to improve the efficiency of deploying micro-segmentation in the IPv6 network.

[0014] Optionally, the IPv6 packet includes a hop-by-hop options header, and the hop-by-hop options header includes the EPG information.

[0015] Optionally, the hop-by-hop options header includes first EPG information.

[0016] Optionally, the hop-by-hop options header includes second EPG information.

[0017] Optionally, the hop-by-hop options header includes first EPG information and second EPG information.

[0018] Since the hop-by-hop options header is an IPv6 extension header that can be parsed by intermediate nodes, by using the hop-by-hop options header to carry EPG information, when an IPv6 packet passes through an intermediate node during the forwarding process, the intermediate node can obtain the EPG information of the source Endpoint device and / or the EPG information of the destination Endpoint device from the hop-by-hop options header. In other words, the EPG information of the source Endpoint device and / or the EPG information of the destination Endpoint device are visible to the intermediate node. Therefore, the intermediate node can use the EPG information of the source Endpoint device and / or the EPG information of the destination Endpoint device to execute group policies, enabling non-VTEP devices such as intermediate nodes to also serve as execution nodes for group policies. On the one hand, it solves the limitation problem that only VTEP devices can support micro-segmentation, expands the function of supporting micro-segmentation for intermediate nodes, and thus makes the applicable scenarios of micro-segmentation more. On the other hand, by having the intermediate node execute group policies, unnecessary forwarding can be avoided. For example, when the processing action in the group policy is to discard, the packet will be discarded by the intermediate node and will no longer occupy network resources to forward to the destination VTEP. On the other hand, compared with the encapsulation format of Ovaly headers such as VXLAN, the encapsulation format of the hop-by-hop options header is more concise, and the hop-by-hop options header occupies fewer bytes, so the transmission overhead of the packet can be reduced. And. The hop-by-hop options header has stronger scalability and can continue to support other features by expanding new options in the hop-by-hop options header. On the other hand, this method can be widely applied to network devices that support IPv6 without requiring the intermediate node to support SRv6-TE, so the universality of this method is stronger. On the other hand, since the workload of pre-configuring the EPG information of the source Endpoint device and the destination Endpoint device on the intermediate node is eliminated, the configuration complexity of the intermediate node is reduced.

[0019] Optionally, the IPv6 extension header includes a destination options header, and the destination options header includes the EPG information.

[0020] Optionally, the destination options header includes first EPG information.

[0021] Optionally, the destination options header includes second EPG information.

[0022] Optionally, the destination options header includes first EPG information and second EPG information.

[0023] Since the destination option header is an IPv6 extension header for the destination node to parse, by using the destination option header to carry EPG information, the group policy can be specified to be executed by the destination node. On the one hand, compared with the encapsulation format of Ovaly headers such as VXLAN, the encapsulation format of the destination option header is more concise, and the destination option header occupies fewer bytes, so the transmission overhead of the packet can be reduced. Moreover, the destination option header has stronger scalability and can continue to support other features by extending new options in the destination option header. On the other hand, this method can be widely applied to network devices that support IPv6 without requiring intermediate nodes to support SRv6-TE, so the universality of this method. On the other hand, since the workload of pre-configuring the EPG information of the source Endpoint device on the destination node is eliminated, the configuration complexity of the destination node is reduced.

[0024] Optionally, the IPv6 extension header includes a hop-by-hop option header and a destination option header, and the hop-by-hop option header and the destination option header include the EPG information.

[0025] In this way, during the forwarding of the IPv6 packet along the way, the intermediate node can obtain the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device through the hop-by-hop option header. Therefore, the intermediate node can execute the group policy according to the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device. Moreover, the destination VTEP can obtain the EPG information of the source Endpoint device through the destination option header. Therefore, the destination VTEP can also execute the group policy according to the EPG information of the source Endpoint device. In this way, the same IPv6 packet can be successively executed by the intermediate node and the destination node with the group policy. Among them, the group policy executed by the intermediate node and the group policy executed by the destination node are the same or different.

[0026] Optionally, the IPv6 extension header includes a type length value TLV, and the EPG information is located in the value field of the TLV.

[0027] By extending a new TLV in the IPv6 extension header to carry the EPG information, the network device can obtain the EPG information from the new TLV. Since the workload of configuring the correspondence between the IP address and the EPG information is eliminated, it helps to reduce the configuration complexity of the network device.

[0028] Optionally, the IPv6 extension header includes one or more options, and the EPG information includes first EPG information and second EPG information; the first EPG information and the second EPG information are located in the same option of the IPv6 extension header; or, the first EPG information and the second EPG information are respectively located in different options of the IPv6 extension header.

[0029] By expanding new options in the IPv6 extension header to carry EPG information, network devices can obtain EPG information from the new options, which helps reduce the configuration complexity of network devices.

[0030] Optionally, the IPv6 packet includes an IPv6 header located outside the original packet, and the destination IP address of the IPv6 header includes a Virtual Private Network Segment Identifier (VPN SID).

[0031] In this optional way, using the SRv6-BE technology, different tenants' traffic can be differentiated by different VPN SIDs, thereby achieving tenant isolation.

[0032] Optionally, the IPv6 packet includes an identification field, which is used to indicate whether the IPv6 packet has been processed according to the group policy corresponding to the EPG information.

[0033] By carrying an identification field in the IPv6 packet, during the process of the IPv6 packet passing through each node, if the upstream node has executed the group policy, the upstream node can use the identification field to indicate that the group policy has been executed, so that the downstream node does not have to re-execute the group policy. In the scenario where the same group policy only needs to be executed once along the way, it can meet the requirements of this scenario and save the processing overhead of the nodes after the node that executes the group policy.

[0034] Optionally, the EPG information is not in the IPv6 routing header, and the IPv6 routing header includes a Segment Routing Header (SRH).

[0035] In this way, the receiving device of the IPv6 packet does not need to support special routing functions (such as SR) to obtain EPG information from the IPv6 packet, thus reducing the functional requirements for the receiving device.

[0036] In a second aspect, a packet processing method is provided, which is applied to an Internet Protocol Version 6 (IPv6) network. In this method,

[0037] A second network device in the IPv6 network receives an IPv6 packet, where the IPv6 packet includes an IPv6 extension header and an original packet, and the IPv6 extension header includes Endpoint Group (EPG) information; the second network device obtains the EPG information from the IPv6 extension header; and the second network device processes the IPv6 packet according to the group policy corresponding to the EPG information.

[0038] Optionally, the EPG information includes at least one of first EPG information and second EPG information. The first EPG information is used to identify the EPG to which the first computing device belongs, and the source Internet Protocol (IP) address of the original message includes the IP address of the first computing device. The second EPG information is used to identify the EPG to which the second computing device belongs, and the destination IP address of the original message includes the IP address of the second computing device.

[0039] Optionally, the IPv6 extension header includes at least one of a hop-by-hop options header and a destination options header, and at least one of the hop-by-hop options header and the destination options header includes the EPG information.

[0040] Optionally, after the second network device obtains the EPG information from the IPv6 extension header, the method further includes: the second network device obtains the group policy according to the EPG information.

[0041] Optionally, the IPv6 extension header includes a type length value (TLV), and the EPG information is located in the value field of the TLV.

[0042] Optionally, the IPv6 extension header includes one or more options, and the EPG information includes first EPG information and second EPG information;

[0043] The first EPG information and the second EPG information are located in the same option of the IPv6 extension header; or, the first EPG information and the second EPG information are respectively located in different options of the IPv6 extension header.

[0044] Optionally, the IPv6 message includes an IPv6 header located outside the original message, and the destination IP address of the IPv6 header includes a virtual private network segment identifier (VPN SID).

[0045] Optionally, the IPv6 message includes an identification field, which is used to indicate whether the IPv6 message has been processed according to the group policy corresponding to the EPG information. Before the second network device processes the IPv6 message according to the group policy corresponding to the EPG information, the method further includes:

[0046] The second network device determines, according to the value of the identification field, that the IPv6 message has not been processed according to the group policy.

[0047] Optionally, when the second network device processes the IPv6 message according to the group policy corresponding to the EPG information, it includes: the second network device updates the value of the identification field.

[0048] Optionally, the EPG information is not in the IPv6 routing header, and the IPv6 routing header includes a segment routing header (SRH).

[0049] In a third aspect, a first network device is provided. The first network device has a function of implementing packet processing in the above first aspect or any optional manner of the first aspect. The first network device includes at least one module, and the at least one module is used to implement the packet processing method provided in the above first aspect or any optional manner of the first aspect. For the specific details of the first network device provided in the third aspect, reference may be made to the above first aspect or any optional manner of the first aspect, which will not be elaborated here.

[0050] In a fourth aspect, a second network device is provided. The second network device has a function of implementing packet processing in the above second aspect or any optional manner of the second aspect. The second network device includes at least one module, and the at least one module is used to implement the packet processing method provided in the above second aspect or any optional manner of the second aspect. For the specific details of the second network device provided in the fourth aspect, reference may be made to the above second aspect or any optional manner of the second aspect, which will not be elaborated here.

[0051] In a fifth aspect, a first network device is provided. The first network device includes a processor and a communication interface. The processor is configured to execute instructions to cause the first network device to execute the packet processing method provided in the above first aspect or any optional manner of the first aspect, and the communication interface is used to receive and send packets. For the specific details of the first network device provided in the fifth aspect, reference may be made to the above first aspect or any optional manner of the first aspect, which will not be elaborated here.

[0052] In a sixth aspect, a second network device is provided. The second network device includes a processor and a communication interface. The processor is configured to execute instructions to cause the second network device to execute the packet processing method provided in the above second aspect or any optional manner of the second aspect, and the communication interface is used to receive packets. For the specific details of the second network device provided in the sixth aspect, reference may be made to the above second aspect or any optional manner of the second aspect, which will not be elaborated here.

[0053] In a seventh aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the instruction is read by a processor to cause a first network device to execute the packet processing method provided in the above first aspect or any optional manner of the first aspect.

[0054] In an eighth aspect, a computer-readable storage medium is provided. At least one instruction is stored in the storage medium, and the instruction is read by a processor to cause a second network device to execute the packet processing method provided in the above second aspect or any optional manner of the second aspect.

[0055] In a ninth aspect, a computer program product is provided. When the computer program product runs on a first network device, the first network device is caused to execute the packet processing method provided in the first aspect or any optional manner of the first aspect.

[0056] In a tenth aspect, a computer program product is provided. When the computer program product runs on a second network device, the second network device is caused to execute the packet processing method provided in the second aspect or any optional manner of the second aspect.

[0057] In an eleventh aspect, a chip is provided. When the chip runs on a first network device, the first network device is caused to execute the packet processing method provided in the first aspect or any optional manner of the first aspect.

[0058] In a twelfth aspect, a chip is provided. When the chip runs on a second network device, the second network device is caused to execute the packet processing method provided in the second aspect or any optional manner of the second aspect.

[0059] In a thirteenth aspect, a network system is provided. The network system includes a first network device and a second network device. The first network device is configured to execute the method described in the first aspect or any optional manner of the first aspect, and the second network device is configured to execute the method described in the second aspect or any optional manner of the second aspect.

[0060] In a fourteenth aspect, a first network device is provided. The first network device includes a central processing unit, a network processor, and a physical interface. The physical interface is configured to receive an original packet. The central processing unit is configured to generate an IPv6 packet based on the original packet and endpoint group (EPG) information. The network processor is configured to trigger the physical interface to send the IPv6 packet.

[0061] Optionally, the first network device includes a main control board and an interface board. The central processing unit is disposed on the main control board, the network processor and the physical interface are disposed on the interface board, and the main control board and the interface board are coupled.

[0062] In a possible implementation, an inter-process communication (IPC) channel is established between the main control board and the interface board, and the main control board and the interface board communicate through the IPC channel.

[0063] In a fifteenth aspect, a second network device is provided, which includes a central processing unit, a network processor, and a physical interface. The physical interface is used to receive IPv6 packets. The central processing unit is used to obtain the EPG information from the IPv6 extension header and process the IPv6 packets according to the group policy corresponding to the EPG information.

[0064] Optionally, the first network device includes a main control board and an interface board. The central processing unit is disposed on the main control board, the network processor and the physical interface are disposed on the interface board, and the main control board and the interface board are coupled.

[0065] In a possible implementation, an inter-process communication (IPC) channel is established between the main control board and the interface board, and the main control board and the interface board communicate through the IPC channel. Description of the Drawings

[0066] Figure 1 is a schematic diagram of the format of a VXLAN header provided by an embodiment of the present application;

[0067] Figure 2 is a schematic diagram of the format of a VXLAN-GPE header provided by an embodiment of the present application;

[0068] Figure 3 is a schematic diagram of the format of a GENEVE header provided by an embodiment of the present application;

[0069] Figure 4 is a schematic diagram of a system architecture 100 provided by an embodiment of the present application;

[0070] Figure 5 is a schematic diagram of a system architecture 100 provided by an embodiment of the present application;

[0071] Figure 6 is a flowchart of a packet processing method 200 provided by an embodiment of the present application;

[0072] Figure 7 is a schematic diagram of the format of an IPv6 packet provided by an embodiment of the present application;

[0073] Figure 8 is a schematic diagram of the format of an IPv6 header provided by an embodiment of the present application;

[0074] Figure 9 is a schematic diagram of the format of a hop-by-hop option header or a destination option header provided by an embodiment of the present application;

[0075] Figure 10 is a schematic diagram of the format of an SRH provided by an embodiment of the present application;

[0076] Figure 11 It is a schematic diagram of the format of an IPv6 extension header carrying EPG information provided by an embodiment of the present application;

[0077] Figure 12 It is a schematic diagram of the format of a hop-by-hop options header carrying EPG information provided by an embodiment of the present application;

[0078] Figure 13 It is a schematic diagram of the format of a destination options header carrying EPG information provided by an embodiment of the present application;

[0079] Figure 14 It is a schematic diagram of the format of a group policy TLV provided by an embodiment of the present application;

[0080] Figure 15 It is a schematic diagram of the format of a group policy TLV provided by an embodiment of the present application;

[0081] Figure 16 It is a schematic diagram of the format of a group policy option provided by an embodiment of the present application;

[0082] Figure 17 It is a schematic diagram of the format of an IPv6 packet carrying EPG information and a VPN SID provided by an embodiment of the present application;

[0083] Figure 18 It is a schematic diagram of the header overhead for encapsulating EPG information provided by an embodiment of the present application;

[0084] Figure 19 It is a schematic diagram of the header overhead for encapsulating EPG information provided by an embodiment of the present application;

[0085] Figure 20 It is a schematic diagram of a scenario for implementing microsegmentation provided by an embodiment of the present application;

[0086] Figure 21 It is a schematic diagram of a scenario for implementing microsegmentation provided by an embodiment of the present application;

[0087] Figure 22 It is a flowchart of a message processing method 300 provided by an embodiment of the present application;

[0088] Figure 23 It is a schematic diagram of a scenario for implementing microsegmentation provided by an embodiment of the present application;

[0089] Figure 24 It is a flowchart of a message processing method 400 provided by an embodiment of the present application;

[0090] Figure 25It is a schematic structural diagram of a network device 500 provided by an embodiment of the present application;

[0091] Figure 26 It is a schematic structural diagram of a network device 600 provided by an embodiment of the present application;

[0092] Figure 27 It is a schematic structural diagram of a network device 700 provided by an embodiment of the present application;

[0093] Figure 28 It is a schematic structural diagram of a network device 800 provided by an embodiment of the present application;

[0094] Figure 29 It is a schematic structural diagram of a network system 900 provided by an embodiment of the present application. Detailed implementation manners

[0095] To make the objectives, technical solutions and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0096] In the present application, terms such as "first" and "second" are used to distinguish identical items or similar items with basically the same functions. It should be understood that there is no logical or temporal dependence between "first", "second", and "nth", nor are the quantity and execution order limited. It should also be understood that although the following description uses terms such as first and second to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various described examples, the first EPG information may be referred to as the second EPG information, and similarly, the second EPG information may be referred to as the first EPG information. Both the first EPG information and the second EPG information can be EPG information, and in some cases, they can be separate and different EPG information.

[0097] It should also be understood that the term "if" can be interpreted to mean "when" ("when" or "upon") or "in response to a determination" or "in response to a detection". Similarly, depending on the context, the phrase "if a determination is made..." or "if [the stated condition or event] is detected" can be interpreted to mean "when a determination is made" or "in response to a determination" or "when [the stated condition or event] is detected" or "in response to a detection of [the stated condition or event]".

[0098] The packet processing method provided by the embodiments of the present application can be applied to scenarios in data center networks, campus networks, and other various networks that require ensuring network boundary security through microsegmentation technology, which helps to achieve the purpose of security control and simplified operation and maintenance. The following briefly introduces the microsegmentation technology.

[0099] The traditional network security model is the perimeter security model. The main threats to the network come from the outside, and only a firewall needs to be deployed at the network perimeter. The security monitoring of internal network traffic needs to divert the traffic to the perimeter firewall. As the scale of the network increases in scenarios such as data centers and campuses, and the number of tenants in the network increases, threats may come from users within the network, making the perimeter security model no longer applicable. Whether north-south traffic or east-west traffic needs to undergo security analysis, and firewalls or isolation policies need to be distributed. This kind of security model is the zero-trust security model. Among them, north-south traffic refers to the traffic flowing into or out of the data center. East-west traffic refers to the traffic within the data center.

[0100] In view of this, currently, the east-west traffic can be analyzed through Micro-segmentation technology to achieve the purpose of security isolation and protection.

[0101] Micro-segmentation can be literally split into two parts: "Micro" and "segmentation". "Segmentation" means grouping devices in the network such as servers and terminals, and then defining group policies based on the groups, and executing group policies on the packets transmitted between different groups or between different members of the same group. Optionally, "Micro" means that the granularity of grouping is finer than that of subnets. Specifically, when dividing subnets, usually only subnet division can be achieved based on Virtual Local Area Network (VLAN) or VXLAN ID (Virtual Network ID, VNI). Devices belonging to different VLANs / VNIs are isolated from each other, and devices belonging to the same VLAN / VNI can communicate with each other. However, the granularity based on subnets is too coarse to achieve isolation between different servers within the same subnet, and when the business changes, the subnets need to be re-divided. While micro-segmentation can group based on Internet Protocol (IP) address, IP network segment, Media Access Control (MAC) address, virtual machine (VM) name, container, operating system, etc. Obviously, the granularity of grouping is much finer than that of subnets, and different devices belonging to the same VLAN can also be isolated from each other through micro-segmentation. Therefore, more fine-grained and more flexible traffic isolation is achieved, to achieve the purpose of security control and simplified operation and maintenance, and ensure business security. Of course, the granularity of micro-segmentation may not be finer than that of VLANs. The description here is only for example.

[0102] The above introduced the micro-segmentation technology. Next, the term concepts in the micro-segmentation technology involved in the embodiments of this application will be introduced.

[0103] (1) EPG

[0104] An Endpoint Group (EPG), also known as microsegmentation, refers to the grouping of Endpoint devices based on grouping methods such as Internet Protocol (IP) addresses, IP subnets, Media Access Control (MAC) addresses, virtual machine (VM) names, containers, operating systems, etc. An EPG includes multiple Endpoint devices. Different Endpoint devices in the same EPG have the same characteristics (such as IP addresses, IP subnets, MAC addresses, VMs, etc.).

[0105] (2) Endpoint device

[0106] An Endpoint device can be implemented by any device with computing and processing capabilities such as a computer. Different Endpoint devices within the same EPG can be called intra-group members of the EPG. Endpoint devices belonging to different EPGs can be called inter-group members of the EPG.

[0107] (3) EPG information

[0108] EPG information is used to identify the EPG to which an Endpoint device belongs. EPG information can include various data forms, which are illustrated by Case 1 to Case 3 below.

[0109] Case 1: Use the ID of the EPG to identify the EPG to which the Endpoint device belongs.

[0110] In Case 1, the EPG information includes the ID of the EPG, and the EPG information is also called Group ID or group ID. For example, the Endpoint devices are VM1 and VM2. The EPG to which VM1 belongs is EPG1, and the EPG to which VM2 belongs is EPG2. In this example, the EPG information of VM1 includes "1", and the EPG information of VM2 both includes "2".

[0111] Case 2: Use the IP address prefix to identify the EPG to which the Endpoint device belongs.

[0112] In Case 2, the IP address prefixes of each Endpoint device in the same EPG are the same, and the EPG information includes the IP address prefix of the Endpoint device. For example, based on the IP subnet, the Endpoint devices are grouped, and VM5 and VM6 with the same IP address prefix of A1::3:1 / 80 are assigned to the same EPG. The EPG information of VM5 and VM6 both includes A1::3:1 / 80.

[0113] Case 3: Use the interface name to identify the EPG to which the Endpoint device belongs.

[0114] In Case 3, the EPG information includes the interface name of the interface through which the VTEP device is connected to the Endpoint device. This interface includes, but is not limited to, virtual interfaces or physical interfaces. For example, VM7 and VM8 connected to the same virtual interface are divided into the same EPG, and the name of this virtual interface is vInf103-1. The EPG information of VM7 and VM8 both includes vInf103-1.

[0115] (4) Group Policy

[0116] Group Based Policy (GBP) is a traffic control policy based on EPG. Group Policy is used to indicate the processing actions to be performed on the packets transmitted between the members within the EPG or between the members of different EPGs. By implementing the Group Policy, access control can be performed on the members within the EPG and the members of different EPGs.

[0117] The processing actions corresponding to the Group Policy include multiple types. For example, the Group Policy includes allow (also known as permit or allow), deny (also known as Deny), mark, redirect, and mirror, etc. When the Group Policy is allow, the processing action performed by the network device on the packet is forwarding, thereby allowing the communication between the members within the EPG or between the members of different EPGs. When the Group Policy is deny, the processing action performed by the network device on the packet is to deny, thereby prohibiting the communication between the members within the EPG or between the members of different EPGs. When the Group Policy is redirect, the processing action performed by the network device on the packet is to redirect the packet to the firewall. Marking is a special type of forwarding. When the Group Policy is mark, the processing action performed by the network device on the packet is to mark the packet first and then forward the marked packet. Marking includes, but is not limited to, relabeling the differentiated services code point (DSCP) of the packet or modifying the priority of the packet, etc. By supporting multiple Group Policies, the requirements of multiple network services can be matched, and more application scenarios can be satisfied.

[0118] The Group Policy is usually associated with matching conditions, and the corresponding relationship between the Group Policy and the matching conditions is usually saved through a policy matrix. For example, please refer to Table 1 below. The policy matrix shown in Table 1 includes four Group Policies. Among them, * represents a wildcard.

[0119] Table 1

[0120]

[0121] The matching condition is also called the matching rule or rule. When the EPG information carried in the packet matches the matching condition, the network device will execute the group policy corresponding to the EPG information. There are various cases regarding whether the EPG information in the matching condition is the EPG information of the source Endpoint device or the destination Endpoint device. The following examples are given through Case 1 to Case 3.

[0122] Case 1: The matching condition includes the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device.

[0123] For example, refer to the first matching condition shown in Table 1 above. The first matching condition includes EPG1 and EPG2. EPG1 is an example of the EPG information of the source Endpoint device, and EPG2 is an example of the EPG information of the destination Endpoint device. When the EPG information of the source Endpoint device carried in the packet is EPG1 and the EPG information of the destination Endpoint device is EPG2, the packet matches the first matching condition, and the network device will discard the packet according to the group policy of Deny.

[0124] Case 2: The matching condition includes the EPG information of the source Endpoint device and does not include the EPG information of the destination Endpoint device.

[0125] Please refer to the third matching condition shown in Table 1 above. The third matching condition includes EPG3 and *. EPG3 is an example of the EPG information of the source Endpoint device. This matching condition means that packets sent from EPG3 to all other EPGs should be allowed. When the EPG information of the source Endpoint device carried in the packet is EPG3, the packet matches the third matching condition, and the network device will forward the packet according to the group policy of Allow. In this way, it is not limited which EPG the destination Endpoint of the packet belongs to, nor is it limited whether the packet carries the EPG information of the destination Endpoint.

[0126] Case 3: The matching condition includes the EPG information of the destination Endpoint device and does not include the EPG information of the source Endpoint device.

[0127] Please refer to the fifth matching condition shown in Table 1 above. The fifth matching condition includes * and EPG6. EPG6 is an example of the EPG information of the destination Endpoint device. This matching condition means that any packet sent to EPG6 should be allowed. When the EPG information of the destination Endpoint device carried in the packet is EPG6, the packet matches the fifth matching condition, and the network device will forward the packet according to the Allow group policy. In this way, the source Endpoint of the packet is not limited to which EPG, nor is it limited whether the packet carries the EPG information of the source Endpoint.

[0128] The group policy can include various data forms. The allow, Deny, etc. shown in Table 1 are only examples of the data forms of the group policy. In some embodiments, the group policy can also be represented by other data forms. For example, the group policy is represented by the number of the processing action. For instance, the number 1 is assigned to the forwarding processing action, and the number 2 is assigned to the discarding processing action. The group policy can be in the data form of 1, 2. When the group policy is 1, the group policy is executed to forward the packet. When the group policy is 2, the group policy is executed to discard the packet. Another example is that the group policy is represented by the instruction corresponding to the processing action, such as the group policy is represented by pseudocode. For example, the group policy is remark dscp 40, and remark dscp 40 is the corresponding instruction, which instructs to modify the DSCP of the packet to 40. When the network device executes the group policy, it marks the packet.

[0129] This embodiment does not limit that the matching condition only includes EPG information. Optionally, the matching condition includes other information besides EPG information. In other words, the network device determines which group policy to execute not only based on the EPG information of the packet, but also according to other information related to the packet. For example, the matching condition also includes the transmission direction of the packet. The transmission direction of the packet includes in (inflow) and out (outflow). When the matching condition includes in, the network device will execute the group policy on the received packet. When the matching condition includes out, the network device will execute the group policy on the packet to be sent.

[0130] The microsegmentation technology and some term concepts in the microsegmentation technology are introduced above. Next, the forwarding scenarios of microsegmentation are introduced.

[0131] In data center and campus scenarios, Endpoint devices are connected to VTEP devices (such as access switches). In other words, at least one Endpoint device is attached to each VTEP device. When deploying micro-segmentation, group policies and matching conditions are configured on the VTEP devices, and the EPG information of the Endpoint devices is also configured on the VTEP devices. Considering that the number of Endpoint devices in the network is often large, usually the EPG information of all Endpoint devices in the network is not configured on each VTEP device. Instead, the EPG information of the Endpoint devices is configured on the VTEP devices to which the Endpoint devices are connected. In other words, for a particular Endpoint device, the EPG information of that device is configured on the VTEP device to which it is connected, so that each VTEP device will pre-store the EPG information of the attached Endpoint devices.

[0132] In this technical context, there are differences in the implementation of mutual access between different Endpoint devices under the same VTEP device and between Endpoint devices under different VTEP devices. The following uses Scenario 1 and Scenario 2 as examples to illustrate respectively.

[0133] Scenario 1: Mutual access between different Endpoint devices under the same VTEP device.

[0134] Scenario 1 is also called the local forwarding scenario. The source Endpoint device and the destination Endpoint device of the original packet are connected to the same VTEP device, and this VTEP device serves as the execution node of the group policy. Specifically, in Scenario 1, the forwarding path of the original packet includes the source Endpoint device → VTEP device → destination Endpoint device. Since the VTEP device is connected to both the source Endpoint device and the destination Endpoint device, the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device are both stored on this VTEP device, and this VTEP device can execute the group policy using the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device.

[0135] Scenario 2: Mutual access between Endpoint devices under different VTEP devices.

[0136] Scenario 2 is also called the cross-EPG forwarding scenario. The source Endpoint device and the destination Endpoint device of the original packet are connected to different VTEP devices respectively, and usually the VTEP device to which the destination Endpoint device is connected serves as the execution node of the group policy.

[0137] Taking the VTEP device accessed by the source Endpoint device as the source VTEP device and the VTEP device accessed by the destination Endpoint device as the destination VTEP device as an example, in scenario two, the forwarding path of the original packet includes source Endpoint device → source VTEP device → one or more intermediate nodes → destination VTEP device → destination Endpoint device. Since the EPG information of the source Endpoint device is stored on the source VTEP device and not on the destination VTEP device, the source VTEP device needs to transmit the EPG information of the source Endpoint device to the destination VTEP device in some way so that the destination VTEP device can use the EPG information of the source Endpoint device to enforce the group policy.

[0138] The above introduces two forwarding scenarios of microsegmentation. Since some embodiments of this application focus on describing how to implement microsegmentation in scenario two, for ease of understanding, the following introduces the specific application of microsegmentation in scenario two.

[0139] In a possible implementation, the EPG information is carried in the VXLAN header of a Virtual Extensible Local Area Network (VXLAN) packet. For example, please refer to Figure 1 , Figure 1Shows a VXLAN header carrying a group policy ID (group policy ID, corresponding to EPG information). Specifically, there are multiple reserved fields in the native VXLAN encapsulation. In this method, the 3rd and 4th bytes in the VXLAN packet are used to carry the group policy ID, and at the same time, the first bit is set as the flag G (Gflag). When the G flag is set to 1, it indicates that there is a group policy ID. When the traffic from the source Endpoint device arrives at the source VTEP device, if the source VTEP device determines according to the routing table that the destination Endpoint device is not directly connected to the source VTEP device, at this time, the source VTEP device performs VXLAN encapsulation on the packet and sends the VXLAN packet to the destination VTEP device where the destination Endpoint device is located. When the source VTEP device performs overlay (also known as stacking) encapsulation, it needs to encapsulate the EPG information of the source Endpoint device in the group policy ID according to the local configuration and set the G flag to 1. When the VXLAN packet arrives at the destination VTEP device, the destination VTEP device performs VXLAN decapsulation, caches the EPG information of the source Endpoint device in the group policy ID, and at the same time determines the EPG to which the destination Endpoint device belongs according to the destination address of the inner packet. The destination VTEP device determines the group policy to be executed according to the EPG to which the source Endpoint device belongs and the EPG to which the destination Endpoint device belongs.

[0140] When adopting the above method, two defects will be faced.

[0141] First, the two roles of the policy execution node and the VTEP device are coupled. Specifically, the EPG information of the source Endpoint device is carried in the overlay header and transmitted to the destination VTEP device. Since the intermediate node does not decapsulate the overlay header, the EPG information of the source Endpoint device is invisible to the intermediate node. Therefore, it is difficult for the intermediate node to execute the group policy according to the EPG information of the source Endpoint device, resulting in more complex processing for the intermediate node.

[0142] Second, the scalability is weak. Because the length of the VXLAN header is fixed and the number of reserved fields is limited, after carrying the EPG information through the VXLAN header, it is impossible to continue to expand other features based on the overlay header.

[0143] In another possible implementation, the extended header of the Overlay header such as the VXLAN Generic Protocol Encapsulation (VXLAN-GPE) and the Generic Network Virtualization Encapsulation (GENEVE) carries EPG information. For example, please refer to Figure 2 , Figure 2 shows the VXLAN-GPE header and the extended header carrying EPG information, Figure 3 shows the GENEVE header and the extended header carrying EPG information.

[0144] Specifically, the extended header is defined in VXLAN-GPE and GENEVE and can be used to carry EPG information. At this time, the Next protocol (corresponding to VXLAN-GPE) or Protocol Type (corresponding to GENEVE) field in the basic header of VXLAN-GPE or GENEVE needs to be set to the corresponding value for indexing the EPG information..

[0145] When the traffic from the source Endpoint device arrives at the source VTEP device, if the source VTEP device determines according to the routing table that the destination Endpoint device is not directly connected to the source VTEP device and the source VTEP device does not have the EPG information of the destination Endpoint device locally, the source VTEP device needs to perform Overlay encapsulation (VXLAN-GPE or GENEVE encapsulation) on the packet and send it to the destination VTEP device where the destination Endpoint device is located. When performing Overlay encapsulation, the source VTEP device needs to encapsulate the EPG information of the source Endpoint device in the group policy ID of the extended header according to the local configuration and set the Next Protocol / Protocol Type field in the basic header. When the VXLAN packet arrives at the destination VTEP device, the destination VTEP device de-encapsulates the Overlay and caches the EPG information of the source Endpoint device in the group policy ID of the extended header. At the same time, it determines the EPG to which the destination Endpoint device belongs according to the destination address of the inner packet. The destination VTEP device determines the group policy to be executed according to the EPG to which the source Endpoint device belongs and the EPG to which the destination Endpoint device belongs.

[0146] In addition, the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device can be carried in the header at the same time. In VXLAN-GPE, two group policy extension headers are used, and 1 bit is used to distinguish the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device. In GENEVE, two type length values (TLVs) are used, and different types are used to distinguish the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device. In this case, the group policy can be carried out at a centralized gateway / firewall. The Overlay tunnel needs to be divided into two segments. The first segment is from the source VTEP device to the centralized gateway / firewall, and the second segment is from the centralized gateway / firewall to the destination VTEP device. The gateway also assumes the role of the VTEP device. In this technology, the source VTEP device is responsible for finding and encapsulating the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device in the inner-layer packet, and the centralized gateway / firewall is responsible for executing the group policy according to the EPG information.

[0147] However, when adopting the above method, two defects will be faced.

[0148] First, the two roles of the policy execution node and the VTEP device are coupled. The EPG information of the source Endpoint device and the EPG information of the destination Endpoint device are both carried after the Overlay header and passed to the destination VTEP. The intermediate node must de-encapsulate it to see the EPG information of the source Endpoint device. Due to the additional action of de-encapsulating the VXLAN header, the processing of the intermediate node is complicated.

[0149] Second, the encapsulation is not concise enough: after adding the extension header, the header overhead is larger.

[0150] In view of this, in some embodiments of the present application, for the scenario where Endpoint devices under different VTEP devices access each other, a method of using IPv6 to carry EPG information is provided. On the basis of implementing the function of micro-segmentation, no Overlay headers such as VXLAN, VXLAN-GPE or GENEVE are used, making the packet encapsulation more concise. In some embodiments, the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device are visible to the intermediate node, enabling the group policy to be executed at the intermediate node. Therefore, the role of the policy execution node is decoupled from the role of the destination VTEP device, and the deployment of the group policy is more flexible.

[0151] Next, the technical solutions provided in the embodiments of the present application will be described from multiple perspectives such as system architecture, method, virtual device, physical device, and medium.

[0152] The following introduces the system architecture provided in the embodiments of the present application.

[0153] See the appendix Figure 4 , the embodiments of the present application provide a system architecture 100. The system architecture 100 is an example illustration of a networking topology that implements microsegmentation based on IPv6. The system architecture 100 includes multiple network devices and multiple computing devices.

[0154] The network devices correspond to VTEP devices or intermediate nodes between different VTEP devices. The network devices are, for example, network device 101, network device 102, network device 103, or network device 104. Optionally, network device 101 and network device 103 are configured as VTEP devices. Network device 102 and network device 103 are configured as intermediate nodes on the forwarding path of the message.

[0155] The computing devices correspond to Endpoint devices in the microsegmentation technology. The computing devices include, but are not limited to, hosts, servers, or personal computers, etc. The computing devices can be physical devices or virtualized devices such as VMs or containers. For example, see the appendix Figure 4 , the computing devices are VM1, VM2, VM3, VM4, VM5, VM6, VM7, or VM8.

[0156] The network devices of the system architecture 100 support IPv6. The computing devices of the system architecture 100 may or may not support IPv6. Specifically, network device 101, network device 102, network device 103, or network device 104 belong to the same IPv6 network, and network device 101, network device 102, network device 103, or network device 104 support the routing and forwarding function of IPv6. VM1, VM2, VM3, VM4, VM5, VM6, VM7, or VM8 may or may not support IPv6 but support IPv4.

[0157] The network device 101 is connected to VM1, VM2, VM3, and VM4, and the EPG information of these four VMs, namely VM1, VM2, VM3, and VM4, is stored on the network device 101. Among them, VM1 and VM2 belong to the same EPG: EPG1. The EPG information of VM1 is used to identify EPG1, and the EPG information of VM2 is used to identify EPG1. VM3 and VM4 belong to the same EPG: EPG2. The EPG information of VM3 is used to identify EPG2, and the EPG information of VM4 is used to identify EPG2. In addition, the network device 101 is also connected to the network device 102 and the network device 104; the network device 102 is connected to the network device 101 and the network device 103; the network device 104 is connected to the network device 101 and the network device 103; the network device 103 is connected to VM5, VM6, VM7, and VM8, and the EPG information of these four VMs, namely VM5, VM6, VM7, and VM8, is stored on the network device 103. Among them, VM5 and VM6 belong to the same EPG: EPG3. The EPG information of VM1 is used to identify EPG3, and the EPG information of VM2 is used to identify EPG3. VM7 and VM8 belong to the same EPG: EPG4. The EPG information of VM3 is used to identify EPG4, and the EPG information of VM4 is used to identify EPG4. In addition, the network device 101 is also connected to the network device 102 and the network device 104; at the same time, the network device 103 is also connected to the network device 102 and the network device 104.

[0158] The system architecture 100 does not limit the specific connection methods between the network device 101, the network device 103 and their corresponding VMs. They can be directly connected, or can be connected to the corresponding VMs through other network devices such as switches, firewalls and other devices. As Figure 5 shown, the network device 101 is connected to VM1 and VM3 through the network device 201, and the network device 101 is connected to VM2 and VM4 through the network device 202. The network device 103 is connected to VM5 and VM6 through the network device 203, and the network device 103 is connected to VM7 and VM8 through the network device 204. In terms of the network device 101 and the network device 103, the way to divide the corresponding micro-segments for the endpoint groups is not limited to the specific connection method, that is, not only can the micro-segments be divided according to their own physical or virtual interfaces, but also can be divided based on the characteristics of the final endpoint groups, such as IP addresses, or DSCP, or a combination of both or more characteristics, etc.

[0159] Those skilled in the art can know that the number of network devices in the system architecture 100 can be more or less. For example, the above-mentioned network devices can be dozens or hundreds, or more in number. The embodiments of the present application do not limit the number and type of network devices.

[0160] The system architecture 100 has been introduced above. Next, through Method 200, Method 300, and Method 400, the method flow for implementing microsegmentation based on the system architecture provided above will be exemplarily introduced.

[0161] See Figure 6 , Figure 6 which is a flowchart of a packet processing method 200 provided by an embodiment of the present application.

[0162] Taking the scenario where a first computing device accesses a second computing device as an example, Method 200 describes how members between EPG groups across VTEP devices implement microsegmentation based on IPv6. In Method 200, the forwarding path of the original packet includes First Computing Device → First Network Device → Second Network Device → Second Computing Device.

[0163] Optionally, the first computing device and the second computing device correspond to Endpoint devices in the microsegmentation technology. The first computing device corresponds to the source Endpoint device. The second computing device corresponds to the destination Endpoint device. The first computing device and the second computing device are not under the same VTEP device. In other words, the VTEP device connected to the first computing device and the VTEP device connected to the second computing device are different. The first computing device and the second computing device belong to different EPGs, and the first computing device and the second computing device correspond to members between groups of EPGs in the microsegmentation technology.

[0164] Optionally, the first network device is the VTEP device connected to the first computing device, and the first network device corresponds to the source VTEP device. Among them, the source VTEP device is also called the ingress VTEP device or Ingress VTEP. The source VTEP device refers to the VTEP device connected to the source Endpoint device.

[0165] The second network device is a downstream node of the first network device in the forwarding path of the original packet. Optionally, the second network device is the VTEP device connected to the second computing device, and the second network device may correspond to the destination VTEP device. Or, the second network device is an intermediate node. Among them, the destination VTEP device is also called the egress VTEP device or Egress VTEP. The destination VTEP device refers to the VTEP device connected to the destination Endpoint device. The intermediate node is a forwarding node between the source VTEP device and the destination VTEP device in the forwarding path of the original packet. The intermediate node is also called a non-VTEP device. For example, please refer to Figure 4 , in the scenario where VM1 accesses VM5, the destination VTEP device is network device 103, and the intermediate nodes are network device 102 or network device 104.

[0166] Optionally, method 200 is executed by a network device and a computing device in system architecture 100. For example, the first computing device in method 200 is VM1, VM2, VM3, or VM4. The first network device in method 200 is network device 101. The second network device in method 200 is network device 102, network device 103, or network device 104. The second computing device in method 200 is VM5, VM6, VM7, or VM8.

[0167] Optionally, method 200 is processed by a general - purpose central processing unit (CPU), or jointly processed by a CPU and a network processor (NP), or without using a CPU or an NP, but using other processors suitable for packet forwarding, which is not limited in this application. For example, the CPU is used to undertake the processing work corresponding to S203, S206, and S207, and the NP is used to undertake the processing work corresponding to S201, S202, S204, S205, and S208.

[0168] Exemplarily, method 200 includes S201 to S208.

[0169] S201. The first computing device sends an original packet.

[0170] This paragraph explains the original packet. The original packet includes, but is not limited to, IPv4 packets, IPv6 packets, or Ethernet frames. Optionally, the original packet is a data packet. The source IP address of the original packet includes the IP address of the first computing device. The destination IP address of the original packet includes the IP address of the second computing device. For example, please refer to Figure 4 , taking VM1 accessing VM5 as an example. The first computing device is VM1, the second computing device is VM5. When VM1 sends an original packet to VM5, the source IP address of the original packet includes the IP address of VM1, and the destination IP address of the original packet includes the IP address of VM5.

[0171] S202. The first network device receives the original packet.

[0172] There are various implementation manners for how the first network device receives the original packet. In a possible implementation, the first network device and the first computing device are located in the same physical device, and the first network device and the first computing device communicate through an internal communication manner of the device, so as to receive the original packet sent by the first computing device. For example, the first network device and the first computing device are located in the same server, the first computing device is a VM running in the server, and the first network device is a network card or a hypervisor (also called a virtual machine monitor, VMM) in the server. After the VM sends the original packet, the network card or the hypervisor will receive the original packet sent by the VM. In another possible implementation, the first network device and the first computing device are located in different physical devices, and the first network device and the first computing device communicate through a network, so as to receive the original packet sent by the first computing device. For example, the first computing device is a VM running in the server, and the first network device is a data center switch network-connected to the server. After the VM sends the original packet, the data center switch will receive the original packet sent by the VM.

[0173] S203. The first network device generates an IPv6 packet according to the original packet and the EPG information.

[0174] The first network device obtains the EPG information according to the original packet. The first network device carries the original packet and the EPG information in the IPv6 packet together, and obtains an IPv6 packet including the original packet and the EPG information. There are various situations for the EPG information carried by the first network device in the IPv6 packet. The following examples are given through Situation 1 to Situation 3.

[0175] Situation 1. The first network device carries the EPG information of the source Endpoint device in the IPv6 packet.

[0176] This embodiment is described by taking the scenario where the first computing device accesses the second computing device as an example. The EPG information includes at least one of the EPG information of the first computing device or the EPG information of the second computing device. To distinguish and describe the EPG information of the first computing device and the EPG information of the second computing device, the EPG information of the first computing device is called the first EPG information, and the EPG information of the second computing device is called the second EPG information. Among them, the first EPG information is an example of the EPG information of the source Endpoint device, and the second EPG information is an example of the EPG information of the destination Endpoint device.

[0177] The first EPG information is used to identify the EPG to which the first computing device belongs. For example, please refer to the appendix Figure 4, VM1 sends an original message to VM5, and the original message is transmitted from VM1 to network device 101 (the first network device). In this example, the first computing device (source Endpoint device) is VM1, the EPG to which VM1 belongs is EPG1, and the first EPG information is used to identify EPG1. For example, the first EPG information is the ID of EPG1, the IP address prefix of VM1, the IP address of VM1, or the interface name of the connection between VM1 and network device 101.

[0178] Case 2: The first network device carries the EPG information of the destination Endpoint device in the IPv6 message.

[0179] The second EPG information is used to identify the EPG to which the second computing device belongs. For example, please refer to the appendix Figure 4 , VM1 sends an original message to VM5, and the original message is transmitted from VM1 to network device 101 (the first network device). In this example, the second computing device (destination Endpoint device) is VM5, the EPG to which VM5 belongs is EPG3, and the second EPG information (the EPG information of the destination Endpoint device) is used to identify EPG3. For example, the second EPG information is the ID of EPG3, the IP address prefix of VM5, the IP address of VM5, or the interface name of the connection between VM5 and network device 103.

[0180] Case 3: The first network device carries the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device in the IPv6 message.

[0181] Specifically, the EPG information carried by the first network device in the IPv6 message includes the first EPG information and the second EPG information, so as to carry the EPG information of both the first computing device and the second computing device in the IPv6 message.

[0182] There are various implementation methods for how the first network device obtains the EPG information according to the original message. The following is illustrated by Method A and Method B.

[0183] Method A: The first network device determines the EPG information according to the IP address included in the original message.

[0184] Specifically, the first network device pre - saves the correspondence between IP addresses and EPG information locally. The first network device queries the correspondence between the IP address and the EPG information based on the IP address included in the original packet, and obtains the EPG information corresponding to the IP address. For example, the first network device queries the correspondence between the IP address and the EPG information based on the source IP address of the original packet, and obtains the first EPG information corresponding to the source IP address. Also, for example, the first network device queries the correspondence between the IP address and the EPG information based on the destination IP address included in the original packet, and obtains the second EPG information corresponding to the destination IP address.

[0185] Among them, the correspondence between the IP address and the EPG information can be referred to as the local matching policy. For example, the correspondence between the IP address and the EPG information is shown in Table 2 below. Exemplarily, the first network device receives an original packet, the source IP address of the original packet is 192.168.10.1 / 32, and the destination IP address of the original packet is 192.168.20.2 / 32. The first network device queries Table 2 below, determines that the first EPG information is EPG1, and determines that the second EPG information is EPG2.

[0186] Table 2

[0187]

[0188]

[0189] Method B: The first network device determines the EPG information according to the interface that receives the original packet. For example, the first network device saves the correspondence between the interface name and the EPG information. After the first network device receives the original packet from the interface, it queries the correspondence between the interface name and the EPG information according to the interface name of the interface, and obtains the EPG information.

[0190] The above Method A and Method B are only examples of determining the EPG information. In other embodiments, the first network device identifies the IP network segment, MAC address, VM name, container, or operating system to which the first computing device belongs according to the original packet, and determines the EPG information according to the identification result.

[0191] The IPv6 packet generated by the first network device includes an IPv6 header (IPv6 Header), an IPv6 extension header (IPv6 extension header), and the original packet. The IPv6 header and the IPv6 extension header are two types of headers in IPv6. For example, please refer to Figure 7 , Figure 7Two structures of IPv6 packets are shown. One IPv6 packet includes an IPv6 header but no IPv6 extension headers, and the other IPv6 packet includes an IPv6 header and IPv6 extension headers. The following introduces the IPv6 header and IPv6 extension headers.

[0192] The IPv6 header is also called the IPv6 base header or IPv6 standard header. The IPv6 header is usually the first header of an IPv6 packet, that is, the outermost header. The structure of the IPv6 header can be referred to Figure 8 . The IPv6 header includes a Version field, a Traffic Class field, a flow label field, a payload length field, a Next Header field, a source address field, and a destination address field. Among them, the source address field is used to carry a 128-bit source IPv6 address. The destination address field is used to carry a 128-bit destination IPv6 address.

[0193] The IPv6 extension headers include multiple types. For example, the IPv6 extension headers include a Hop-by-Hop Options header, a Destination Options header, and an SRH. The following introduces several IPv6 extension headers respectively.

[0194] (1) Hop-by-Hop Options header

[0195] The Hop-by-Hop Options header (HBH) is an IPv6 extension header. The Hop-by-Hop Options header can be processed by each intermediate node encountered during the forwarding process. When an IPv6 packet carries a Hop-by-Hop Options header, the value of the next header field of the previous header of the Hop-by-Hop Options header is 0. Optionally, the Hop-by-Hop Options header is the first IPv6 extension header after the IPv6 header. In other words, the previous header of the Hop-by-Hop Options header is the IPv6 header, and the value of the next header field of the IPv6 header is 0. Please refer to Figure 9 , Figure 9 shows the structural schematic of the Hop-by-Hop Options header. The Hop-by-Hop Options header includes a Next Header field, a header Extended Length (abbreviation: Hdr Ext Len) field, and at least one option. The value of the next header field in the Hop-by-Hop Options header is used to indicate the type of the first header after the Hop-by-Hop Options header. The value of the Hdr Ext Len field in the Hop-by-Hop Options header is used to indicate the length of the Hop-by-Hop Options header. The options in the Hop-by-Hop Options header are also called Hop-by-Hop Options. The Hop-by-Hop Options are usually encoded in the form of TLV, and the Hop-by-Hop Options include an option type field, an option data length field, and a value field.

[0196] (2) Destination Options header

[0197] The Destination option Header (DOH) is an IPv6 extension header. The DOH is processed by the destination node in the forwarding path of the IPv6 packet, and the destination node is, for example, the device corresponding to the destination IPv6 address of the IPv6 header. When the IPv6 packet carries the DOH, the value of the next header field of the previous header of the DOH is 60. Please refer to Figure 9 , the formats of the DOH and the Hop-by-Hop option header are similar. The DOH includes a next header field, an Hdr Ext Len field, and at least one option. Among them, the value of the next header field is used to indicate the type of the first header after the DOH. The value of the Hdr Ext Len field is used to indicate the length of the DOH. The options in the DOH are also called destination options. Destination options are usually encoded in the form of TLVs, and destination options include an option type field, an option data length field, and a value field.

[0198] (3) SRH

[0199] The SRH is an IPv6 extension header. Specifically, the SRH is an IPv6 Routing Header. The value of the Routing Type field of the SRH is 4. See Figure 10 , Figure 10 is a schematic diagram of the format of an SRH provided by an embodiment of the present application. The SRH includes a segment list, Segments Left (SL), one or more TLVs, a next header field, an Hdr Ext Len field, a Routing Type field, a Last Entry field, a Flags field, a Tag field for identifying packets in the same group, etc.

[0200] There are various implementation manners for how to carry EPG information through an IPv6 packet. In a possible implementation, please refer to Figure 7 , the first network device uses an IPv6 extension header to carry EPG information. Specifically, the first network device generates an IPv6 extension header including EPG information, and adds the IPv6 extension header to the original packet to obtain an IPv6 packet.

[0201] The EPG information carried through the IPv6 extension header includes various situations, which are illustrated by examples from situation a to situation c below.

[0202] Situation a: Carry the EPG information of the source Endpoint device through the IPv6 extension header.

[0203] For example, the IPv6 extension header includes first EPG information. The effects of case a include: by carrying the EPG information of the source Endpoint device in the IPv6 extension header of the IPv6 packet, the EPG information of the source Endpoint device is forwarded in the IPv6 network along with the IPv6 packet. During the process of forwarding the IPv6 packet, the execution node of the group policy can obtain the EPG information of the source Endpoint device from the IPv6 extension header, thus eliminating the workload caused by pre-configuring the EPG information of the source Endpoint device on the execution node of the group policy, thereby reducing the configuration complexity of the execution node of the group policy and helping to improve the efficiency of deploying micro-segmentation in the IPv6 network.

[0204] In case b, the EPG information of the destination Endpoint device is carried by the IPv6 extension header.

[0205] For example, the IPv6 extension header includes second EPG information. The effects of case b include: by using the IPv6 extension header to transmit the EPG information of the destination Endpoint device in the IPv6 network, during the process of forwarding the IPv6 packet, the execution node of the group policy can obtain the EPG information of the destination Endpoint device from the IPv6 extension header, thus eliminating the workload caused by pre-configuring the EPG information of the destination Endpoint device on the execution node of the group policy, thereby reducing the configuration complexity of the execution node of the group policy and helping to improve the efficiency of deploying micro-segmentation in the IPv6 network.

[0206] In case c, the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device are carried by the IPv6 extension header.

[0207] For example, the IPv6 extension header includes first EPG information and second EPG information. The effects of case c include: by using the IPv6 extension header to transmit the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device in the IPv6 network, during the process of forwarding the IPv6 packet, the execution node of the group policy can obtain the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device from the IPv6 extension header, thus eliminating the workload caused by pre-configuring the EPG information of the source Endpoint device and the destination Endpoint device on the execution node of the group policy, thereby reducing the configuration complexity of the execution node of the group policy and helping to improve the efficiency of deploying micro-segmentation in the IPv6 network.

[0208] For the various cases of EPG information and the various types of IPv6 extension headers, please refer to Figure 11 , Figure 11It is a schematic diagram of the format of an IPv6 extension header carrying EPG information provided by an embodiment of the present application. There are various implementation methods for using the IPv6 extension header to carry EPG information. The following illustrates by Implementation Method 1 to Implementation Method 3.

[0209] Implementation Method 1: Use the Hop-by-Hop Options header to carry EPG information.

[0210] In Implementation Method 1, the IPv6 packet generated by the first network device includes a Hop-by-Hop Options header, and the Hop-by-Hop Options header includes EPG information. For example, please refer to Figure 11 the IPv6 packet with a Hop-by-Hop Options header shown. After the 40-byte IPv6 header of the IPv6 packet, there is an 8-byte Hop-by-Hop Options header, and the EPG information is located in the Hop-by-Hop Options header. The EPG information carried by the Hop-by-Hop Options header includes but is not limited to at least one of the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device. The following illustrates by Method 1A to Method 1C.

[0211] Method 1A: Use the Hop-by-Hop Options header to carry the EPG information of the source Endpoint device and the destination Endpoint device.

[0212] For example, the Hop-by-Hop Options header includes the first EPG information and the second EPG information. For example, please refer to Figure 12 , Figure 12 which shows a Hop-by-Hop Options header including the first EPG information and the second EPG information. The Hop-by-Hop Options header includes a Source EPG field and a Destination EPG field. The Source EPG field includes the first EPG information, and the Destination EPG field includes the second EPG information.

[0213] Method 1B: Use the Hop-by-Hop Options header to carry the EPG information of the source Endpoint device.

[0214] For example, the Hop-by-Hop Options header includes the first EPG information. For example, the Hop-by-Hop Options header includes a Source EPG field, and the Source EPG field includes the first EPG information.

[0215] Method 1C: Use the Hop-by-Hop Options header to carry the EPG information of the destination Endpoint device.

[0216] For example, the Hop-by-Hop Options header includes the second EPG information. For example, the Hop-by-Hop Options header includes a Destination EPG field, and the Destination EPG field includes the second EPG information.

[0217] The effects achieved by Implementation Method 1 include: Since the Hop-by-Hop Options header is an IPv6 extension header that can be parsed by intermediate nodes, by using the Hop-by-Hop Options header to carry EPG information, when an IPv6 packet passes through an intermediate node during the forwarding process, the intermediate node can obtain the EPG information of the source Endpoint device and / or the EPG information of the destination Endpoint device from the Hop-by-Hop Options header. In other words, the EPG information of the source Endpoint device and / or the EPG information of the destination Endpoint device is visible to the intermediate node. Therefore, the intermediate node can execute group policies using the EPG information of the source Endpoint device and / or the EPG information of the destination Endpoint device, enabling non-VTEP devices such as intermediate nodes to also serve as execution nodes for group policies. On the one hand, it solves the limitation problem that only VTEP devices can support micro-segmentation, extends the function of supporting micro-segmentation to intermediate nodes, and thus makes the applicable application scenarios of micro-segmentation more. On the other hand, by having the intermediate node execute group policies, unnecessary forwarding can be avoided. For example, when the processing action in the group policy is to discard, the packet will be discarded by the intermediate node and will no longer occupy network resources to forward to the destination VTEP. On the other hand, compared with the encapsulation format of Ovaly headers such as VXLAN, the encapsulation format of the Hop-by-Hop Options header is more concise, and the Hop-by-Hop Options header occupies fewer bytes, so the transmission overhead of the packet can be reduced. And. The Hop-by-Hop Options header has stronger scalability and can continue to support other features by expanding new options in the Hop-by-Hop Options header. On the other hand, this method can be widely applied to network devices that support IPv6 without requiring intermediate nodes to support SRv6-TE, so the universality of this method is stronger. On the other hand, since the workload of pre-configuring the EPG information of the source Endpoint device and the destination Endpoint device on the intermediate node is eliminated, the configuration complexity of the intermediate node is reduced.

[0218] Implementation Method 2: Use the Destination Options header to carry EPG information.

[0219] In Implementation Method 2, the IPv6 packet generated by the first network device includes a Destination Options header, and the Destination Options header includes EPG information. For example, please refer to Figure 11 the IPv6 packet with a Destination Options header shown. There is an 8-byte Destination Options header after the 40-byte IPv6 header in the IPv6 packet, and the EPG information is located in the Destination Options header. The EPG information carried by the Destination Options header includes, but is not limited to, at least one of the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device. The following examples are given through Method 2A to Method 2C.

[0220] Method 2A: Use the Destination Options header to carry the EPG information of the source Endpoint device.

[0221] For example, the destination option header includes the first EPG information. For example, please refer to Figure 13 , Figure 13 shows a destination option header including the first EPG information. The destination option header includes a source EPG field, and the source EPG field includes the first EPG information.

[0222] Method 2B: Use the destination option header to carry the EPG information of the destination Endpoint device.

[0223] For example, the destination option header includes the second EPG information. For example, the destination option header includes a destination EPG field, and the destination EPG field includes the second EPG information.

[0224] Method 2C: Use the destination option header to carry the EPG information of the source Endpoint device and the destination Endpoint device.

[0225] For example, the destination option header includes the first EPG information and the second EPG information. For example, the destination option header includes a source EPG field and a destination EPG field. The source EPG field includes the first EPG information, and the destination EPG field includes the second EPG information.

[0226] The effects achieved by Implementation Method 2 include: Since the destination option header is an IPv6 extension header for the destination node to parse, by using the destination option header to carry the EPG information, the group policy can be specified to be executed by the destination node. On the one hand, compared with the encapsulation format of Ovaly headers such as VXLAN, the encapsulation format of the destination option header is more concise, and the destination option header occupies fewer bytes. Therefore, the transmission overhead of the packet can be reduced. And. The destination option header has stronger scalability and can continue to support other features by expanding new options in the destination option header. On the other hand, this method can be widely applied to network devices that support IPv6 without requiring intermediate nodes to support SRv6-TE. Therefore, the universality of this method. On the other hand, since the workload of pre-configuring the EPG information of the source Endpoint device on the destination node is eliminated, the configuration complexity of the destination node is reduced.

[0227] The above Implementation Method 1 to Implementation Method 2 can be combined to form the following Implementation Method 3.

[0228] Implementation Method 3: Use the hop-by-hop option header and the destination option header to carry the EPG information.

[0229] Under Implementation Method 3, the IPv6 packet generated by the first network device includes a hop-by-hop option header and a destination option header, and both the hop-by-hop option header and the destination option header include the EPG information. For example, please refer to Figure 11The IPv6 packet with a hop-by-hop options header and a destination options header as shown. After the 40-byte IPv6 header of the IPv6 packet, there is an 8-byte hop-by-hop options header and an 8-byte destination options header, and the EPG information is located in the hop-by-hop options header and the destination options header. Optionally, the hop-by-hop options header is located before the destination options header, and the hop-by-hop options header is parsed by the receiving end first, and the destination options header is parsed by the receiving end later. There are various implementation methods for how to use the EPG information carried by these two IPv6 extension headers, namely the hop-by-hop options header and the destination options header. The following examples are given through Method 3A to Method 3F.

[0230] Method 3A: Use the hop-by-hop options header to carry the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device, and use the destination options header to carry the EPG information of the source Endpoint device.

[0231] For example, the IPv6 packet generated by the first network device includes a hop-by-hop options header and a destination options header. The hop-by-hop options header includes the first EPG information and the second EPG information, and the destination options header includes the first EPG information. In this way, during the forwarding process of the IPv6 packet along the way, the intermediate node can obtain the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device through the hop-by-hop options header. Therefore, the intermediate node can execute the group policy according to the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device. Also, the destination VTEP can obtain the EPG information of the source Endpoint device through the destination options header. Therefore, the destination VTEP can also execute the group policy according to the EPG information of the source Endpoint device. Thus, the same IPv6 packet can be successively executed by the intermediate node and the destination node for the group policy. Among them, the group policy executed by the intermediate node and the group policy executed by the destination node can be the same or different.

[0232] Method 3B: Use the hop-by-hop options header to carry the EPG information of the source Endpoint device, and use the destination options header to carry the EPG information of the source Endpoint device.

[0233] For example, the IPv6 packet includes a hop-by-hop options header and a destination options header. The hop-by-hop options header includes the first EPG information, and the destination options header includes the first EPG information.

[0234] Method 3C: Use the hop-by-hop options header to carry the EPG information of the destination Endpoint device, and use the destination options header to carry the EPG information of the source Endpoint device.

[0235] For example, the IPv6 packet includes a hop-by-hop options header and a destination options header. The hop-by-hop options header includes the second EPG information, and the destination options header includes the first EPG information.

[0236] Method 3D: Carry the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device using the hop-by-hop option header, and carry the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device using the destination option header.

[0237] For example, an IPv6 packet includes a hop-by-hop option header and a destination option header. The hop-by-hop option header includes the first EPG information and the second EPG information, and the destination option header includes the first EPG information and the second EPG information.

[0238] Method 3E: An IPv6 packet includes a hop-by-hop option header and a destination option header. The hop-by-hop option header includes the first EPG information, and the destination option header includes the first EPG information and the second EPG information.

[0239] Method 3F: An IPv6 packet includes a hop-by-hop option header and a destination option header. The hop-by-hop option header includes the second EPG information, and the destination option header includes the first EPG information and the second EPG information.

[0240] Through the above implementation methods 1 to 3, some possible implementation methods of using the IPv6 extension header to carry EPG information are listed. In addition to the hop-by-hop option header and the destination option header, the IPv6 extension header also includes an IPv6 routing header. Optionally, the EPG information is not carried through the IPv6 routing header (such as SRH). In other words, the EPG information is not in the IPv6 routing header (such as SRH). The situation where the EPG information is not in the IPv6 routing header includes multiple cases, including both the case where the IPv6 packet does not carry the IPv6 routing header and the case where the IPv6 packet carries the IPv6 routing header but the EPG information is not in the IPv6 routing header. For example, the IPv6 packet includes a hop-by-hop option header and does not include an IPv6 routing header (such as SRH), and the EPG information is located in the hop-by-hop option header. Another example is that the IPv6 packet includes a hop-by-hop option header and an IPv6 routing header (such as SRH), and the EPG information is located in the hop-by-hop option header rather than in the IPv6 routing header. For example, the IPv6 packet includes a destination option header and does not include an IPv6 routing header (such as SRH), and the EPG information is located in the destination option header. Another example is that the IPv6 packet includes a destination option header and an IPv6 routing header (such as SRH), and the EPG information is located in the destination option header rather than in the IPv6 routing header.

[0241] Optionally, an identification field is carried in the IPv6 packet to indicate whether the group policy has been executed. Specifically, the IPv6 packet includes an identification field, which is used to indicate whether the IPv6 packet has been processed according to the group policy corresponding to the EPG information. For example, the identification field occupies one bit in the IPv6 packet. If this bit is set, it means that the IPv6 packet has been processed according to the group policy. If the bit is not set, it means that the IPv6 packet has not been processed according to the group policy. Optionally, the identification field is called the "A" bit.

[0242] There are various implementation methods for how to carry the identification field in the IPv6 packet. For example, the identification field is carried through the IPv6 extension header. For instance, the identification field is carried through the Hop-by-Hop Options header, or through the Destination Options header. There are various situations for the positional relationship between the identification field and the EPG information. Optionally, the identification field and the EPG information are in the same IPv6 extension header. For example, the identification field and the EPG information are in the same Hop-by-Hop Options header. Another example is that the identification field and the EPG information are in the same Destination Options header. Another example is that the identification field and the EPG information are in the same option. Another example is that the identification field and the EPG information are in the same TLV. Another example is that the identification field and the EPG information are in the same field. For instance, there is a flag field in the IPv6 packet, and the high-order bit of this flag field is the identification field, and the low-order bit of this flag field carries the EPG information.

[0243] By carrying the identification field in the IPv6 packet, during the process of the IPv6 packet passing through each node, if the upstream node has executed the group policy, the upstream node can use the identification field to indicate that the group policy has been executed, so that the downstream node does not have to execute the group policy again. In the scenario where the same group policy only needs to be executed once along the way, the requirements of this scenario can be met, saving the processing overhead of the nodes after the node that executes the group policy.

[0244] There are various implementation methods for which fields of the IPv6 extension header are used to carry the EPG information. Optionally, a new TLV is extended in the IPv6 extension header to carry the EPG information. Specifically, TLV is a coding format. A TLV includes a type field, a length field, and a value field. The IPv6 extension header in the IPv6 packet includes TLV, and the EPG information is located in the value field of the TLV.

[0245] Taking the TLV carrying EPG information, which is called the group policy TLV, as an example, the group policy TLV refers to the TLV carrying EPG information. The value field of the group policy TLV includes the EPG information. The types of the group policy TLV include multiple cases. Optionally, the group policy TLV is a new top TLV, and the value of the type field of this group policy TLV represents the type of the unused top TLV. Optionally, this group policy TLV is a new sub-TLV of the top TLV, and the value of the type field of this group policy TLV represents the type of the unused sub-TLV. Optionally, this group policy TLV is a new sub-sub-TLV (sub-sub-TLV) of the top TLV, and the type of this group policy TLV is the type of the unused sub-sub-TLV. This embodiment does not limit whether the group policy TLV is a top TLV, a sub-TLV or a sub-sub-TLV. The length field of the group policy TLV is used to indicate the length of the group policy TLV.

[0246] There are multiple implementation methods for using TLV to carry EPG information, which are illustrated below by Implementation Method I and Implementation Method II.

[0247] Implementation Method I: Use one TLV to carry at least one of the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device.

[0248] For example, carry the EPG information of the source Endpoint device through a group policy TLV. The value field of this group policy TLV includes a source EPG field, and the source EPG field includes the first EPG information. Also, carry the EPG information of the destination Endpoint device through a group policy TLV. The value field of this group policy TLV includes a destination EPG field, and the destination EPG field includes the second EPG information. Also, carry the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device through a group policy TLV. The value field of this group policy TLV includes the EPG information of the source Endpoint device and the destination EPG field. The source EPG field includes the first EPG information, and the destination EPG field includes the second EPG information. When carrying the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device through a group policy TLV, optionally, the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device occupy different bit positions, and the EPG information is distinguished as the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device according to the bit position where the EPG information is located.

[0249] Implementation II: Use multiple TLVs to carry the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device respectively.

[0250] For example, the group policy TLV includes a source group policy TLV and a destination group policy TLV. The value field of the source group policy TLV includes a source EPG field, and the source EPG field includes the first EPG information. The value field of the destination group policy TLV includes a destination EPG field, and the destination EPG field includes the second EPG information. Optionally, the value of the type field of the source group policy TLV is different from the value of the type field of the destination group policy TLV. In other words, the source group policy TLV and the destination group policy TLV are distinguished by different Types. Or, both the source group policy TLV and the destination group policy TLV include a flag field, and the value of the flag field of the source group policy TLV is different from the value of the flag field of the destination group policy TLV. In other words, the source group policy TLV and the destination group policy TLV are distinguished by different flags. For example, please refer to Figure 14 and Figure 15 , Figure 14 and Figure 15 which are examples of the group policy TLV.

[0251] Figure 14 In the group policy TLV shown, the EPG field is used to carry the EPG information of 1 Endpoint device, for example, carrying the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device. Figure 14 In the group policy TLV shown, the EPG field occupies 2 bytes, for example, and the value of the length field of the group policy TLV is 2, for example.

[0252] Figure 15 In the group policy TLV shown, it is used to carry the EPG information of the source Endpoint device, the EPG information of the destination Endpoint device, and an identification field. Among them, the source EPG field occupies 2 bytes, for example, the destination EPG field occupies 2 bytes, for example, and the identification field occupies 1 bit. The value of the length field of the group policy TLV is greater than 4, for example, 5. Figure 15 In the group policy TLV shown, the group policy TLV includes an OptionType field, an Opt Data Len field, an identification field, a reserved field, a source EPG field, and a destination EPG field. The value of the OptType field is 5, which is used to indicate that the length from the first byte after OptLen to the last byte of the option is 5 bytes. The source EPG field includes the first EPG information. The destination EPG field includes the second EPG information. Among them, Figure 15The Source EPG and SourceEPG con shown are the same field. The meaning expressed by this drawing is that Figure 15 One line of Figure 15 represents 32 bits. The Source EPG field includes the last byte of the first line and the first byte of the second line. The Source EPG field is not ended until the last byte of the first line, and the first byte of the second line needs to be continuously read.

[0253] By expanding a new TLV in the IPv6 extension header to carry the EPG information, the network device can obtain the EPG information from the new TLV. Since the workload of configuring the correspondence between the IP address and the EPG information is eliminated, it helps to reduce the configuration complexity of the network device.

[0254] Combined with different types of IPv6 extension headers, there are multiple cases of carrying the above group policy TLV through the IPv6 extension header. The following are illustrated by case (1) and case (2).

[0255] Case (1) carries the group policy TLV through the Hop-by-Hop Options header.

[0256] The IPv6 packet generated by the first network device includes a Hop-by-Hop Options header, and the Hop-by-Hop Options header includes one or more group policy TLVs. For example, please refer to Figure 12 , Figure 12 which is an example illustration of carrying the group policy TLV through the Hop-by-Hop Options header. Figure 12 The group policy TLV shown includes the EPG information (the first EPG information) of the source Endpoint device, the EPG information (the second EPG information) of the destination Endpoint device, and an identification field. In addition, optionally, the Hop-by-Hop Options header also includes a Padding field, and the Padding field is used for alignment.

[0257] Case (2) carries the group policy TLV through the Destination Options header.

[0258] The IPv6 packet generated by the first network device includes a Destination Options header, and the Destination Options header includes one or more group policy TLVs. For example, please refer to Figure 13 , Figure 13 which is an example illustration of carrying the group policy TLV through the Destination Options header. Figure 13 The group policy TLV shown includes the EPG information (the first EPG information) of the source Endpoint device. In addition, optionally, the Destination Options header also includes a two-byte Padding field, and the Padding field is used for alignment.

[0259] The above cases (1) and (2) can be combined, that is, the group policy TLV is carried by the hop-by-hop option header and the destination option header. Specifically, the IPv6 packet includes a hop-by-hop option header and a destination option header, and both the hop-by-hop option header and the destination option header include the group policy TLV. The cases where both the hop-by-hop option header and the destination option header include the group policy TLV can refer to the above-mentioned methods 3A to 3F. For example, referring to the above method 3A, the group policy TLV in the hop-by-hop option header includes the first EPG information and the second EPG information, and the group policy TLV in the destination option header includes the first EPG information.

[0260] Carrying the EPG information by extending a new TLV is only an optional method. In some other embodiments, instead of extending a new TLV, the EPG information is carried in the IPv6 extension header by other means. For example, the EPG information is carried in the flag field in the IPv6 extension header, so as to save the overhead brought by the type field and the length field of the policy TLV. Optionally, the flag field carrying the EPG information is located in a reserved field, or the flag field carrying the EPG information is located in the V field of a certain TLV, or the flag field carrying the EPG information occupies one or more bits in the original flag field.

[0261] Optionally, the EPG information is carried by extending a new option in the IPv6 extension header. Specifically, the IPv6 extension header in the IPv6 packet includes one or more options, and the EPG information is located in one or more options. Taking the option carrying the EPG information, which is called the group policy option (group policy Option), as an example, optionally, the hop-by-hop option header is used to carry the group policy option, so that the hop-by-hop option header includes one or more group policy options. Or, the destination option header is used to carry the group policy option, so that the destination option header includes one or more group policy options. Among them, the group policy option can be encoded in the form of a TLV. For example, Figure 14 or Figure 15 The type field of the group policy TLV shown is replaced with the option type (Option Type), and Figure 14 or Figure 15 The length field of the group policy TLV shown is replaced with the option data length (Opt Data Len) field, and the form of the group policy option can be obtained. For example, please refer to Figure 16 , Figure 16 is an example illustration of the group policy option. Among them, Figure 16 The value of the OptLen field in is 2, which is used to indicate that the length from the 1st bit after OptLen to the last bit of the option is 2 bytes. The EPG field occupies 2 bytes.

[0262] Using group policy options to carry EPG information includes multiple scenarios. The following examples illustrate this through Implementation Method 1 to Implementation Method 2.

[0263] Method 1: Use one group policy option to carry EPG information.

[0264] For example, use one group policy option to carry the EPG information of the source Endpoint device. For example, the IPv6 extension header includes a group policy option that includes the first EPG information.

[0265] Another example is to use one group policy option to carry the EPG information of the destination Endpoint device. For example, the IPv6 extension header includes a group policy option that includes the second EPG information

[0266] Another example is to use one group policy option to carry the EPG information of the source Endpoint device and the destination Endpoint device, such that the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device are in the same option. For example, the IPv6 extension header includes a group policy option that includes the first EPG information and the second EPG information.

[0267] Method 2: Use multiple group policy options to carry EPG information.

[0268] For example, use different group policy options to carry the EPG information of different Endpoint devices respectively. For example, use the source group policy option to carry the EPG information of the source Endpoint device, and use the destination group policy option to carry the EPG information of the destination Endpoint device. For example, the source group policy option includes the first EPG information, and the destination group policy option includes the second EPG information. In other words, the first EPG information and the second EPG information are in different options.

[0269] Among them, the source group policy option and the destination group policy option are in the same or different IPv6 extension headers. For example, use the same hop-by-hop option header to carry the source group policy option and the destination group policy option. Another example is to use the hop-by-hop option header to carry the destination group policy option and use the destination option header to carry the source group policy option. Optionally, the source group policy option and the destination group policy option have different Option types, or the source group policy option and the destination group policy option have the same Option type, and are distinguished by the flag field or other fields.

[0270] By expanding new options in the IPv6 extension header to carry EPG information, network devices can obtain the EPG information from the new options, which helps to reduce the configuration complexity of network devices.

[0271] Optionally, not only is IPv6 used to transmit EPG information, but also the Segment Routing-Best Effort (SR-BE) technology is used to implement tenant isolation. Specifically, the IPv6 packet generated by the first network device is an SRv6-BE packet. The IPv6 packet does not include an SRH. The IPv6 packet includes an IPv6 header located outside the original packet. The destination IP address of the IPv6 header includes a Virtual Private Network Segment ID (VPN SID). Different tenant traffic is distinguished by different VPN SIDs, thereby implementing tenant isolation.

[0272] This paragraph introduces the VPN SID. The VPN SID is an Internet Protocol Version 6 for Segment Routing (SRv6) Segment ID (SID). The VPN SID can serve as a Virtual Private Network ID (VPN ID), and the VPN SID can identify the corresponding VPN. Optionally, in method 200, the VPN SID is a SID pre-published by the destination VTEP device. The Locator of the VPN SID is used to locate the destination VTEP device, and the Function of the VPN SID is used to instruct the destination VTEP device to send a packet to the VPN instance. By using the VPN SID as the destination IP address of the IPv6 header, when the destination VTEP receives the IPv6 packet and queries the local SID table using the destination IP address, the destination IP address will hit the VPN SID in the local SID table. Then, the destination VTEP will perform the operation corresponding to the VPN SID and forward the IPv6 packet to the corresponding VPN instance, enabling the IPv6 packet to enter the corresponding VPN from the destination VTEP, thereby implementing tenant isolation. The positional relationship between the VPN SID and the EPG information in the IPv6 packet includes multiple cases. For example, the VPN SID is located outside the EPG information. For example, please refer to Figure 17, in the order from the outer layer to the inner layer, the IPv6 packet sequentially includes the IPv6 header of the VPN SID, the IPv6 extension header carrying the EPG information, and the original packet. The types of VPN SID include, but are not limited to, End.DX and End.DT. The operations corresponding to the End.DX SID include decapsulating the outer IPv6 packet header and forwarding the remaining packet out of the egress interface bound to the End.DX SID. End.DX includes, but is not limited to, End.DX6, End.DX4, End.DX2, or End.DX2V. The operations corresponding to the End.DT SID include decapsulating the outer IPv6 packet header and forwarding according to the destination address included in the remaining packet by looking up the VPN instance routing table. End.DT includes, but is not limited to, End.DT4 or End.DT6.

[0273] The following compares various encapsulation forms of EPG information under the best effort condition.

[0274] For various encapsulation forms carrying one EPG information, exemplarily, taking the EPG information (the first EPG information) of the source Endpoint device as an example, refer to Figure 18, when using VXLAN packets to encapsulate the first EPG information, the outer IPv6 header occupies 40 bytes, the UDP header occupies 8 bytes, and the VXLAN header carrying the first EPG information occupies 8 bytes. When using VXLAN-GPE packets to encapsulate the first EPG information, the outer IPv6 header occupies 40 bytes, the UDP header occupies 8 bytes, and the VXLAN-GPE header occupies 8 bytes. The first EPG information occupies 4 bytes. When using GENEVE packets to encapsulate the first EPG information, the outer IPv6 header occupies 40 bytes, the UDP header occupies 8 bytes, and the GENEVE header occupies 8 bytes. The first EPG information occupies 8 bytes. When using IPv6 (SRv6-BE) and the destination option header to encapsulate the first EPG information, the outer IPv6 header occupies 40 bytes, and the destination option header carrying the first EPG information occupies 8 bytes. When using IPv6 (SRv6-BE) and the hop-by-hop option header to encapsulate the first EPG information, the outer IPv6 header occupies 40 bytes, and the hop-by-hop option header carrying the first EPG information occupies 8 bytes. By comparison, it can be seen that by using SRv6-BE and the hop-by-hop option header to carry the first EPG information, or using SRv6-BE and the destination option header to carry the first EPG information, in the case of achieving the same function, it saves 8 bytes compared to VXLAN, 12 bytes compared to VXLAN-GPE, and 16 bytes compared to GENEVE. Similarly, in the case of carrying the EPG information (the second EPG information) of the destination Endpoint device, by using SRv6-BE and the hop-by-hop option header to carry the second EPG information, or using SRv6-BE and the destination option header to carry the second EPG information, it can also save 8 bytes compared to VXLAN, 12 bytes compared to VXLAN-GPE, and 16 bytes compared to GENEVE in the case of achieving the same function. Obviously, on the premise of achieving the same effect as other encapsulation methods, the encapsulation method using SRv6-BE and the IPv6 extension header is more concise and significantly saves the overhead of the header.

[0275] For various encapsulation forms carrying two EPG information, by way of example, taking the carrying of the first EPG information and the second EPG information as an example, please refer to Figure 19 , by using SRv6-BE and the hop-by-hop option header to carry the first EPG information and the second EPG information, in the case of achieving the same function, it saves 8 bytes compared to VXLAN-GPE and 12 bytes compared to GENEVE. Obviously, on the premise of achieving the same effect as other encapsulation methods, the encapsulation method using SRv6-BE and the hop-by-hop option header is more concise and significantly saves the overhead of the header.

[0276] There are various specific ways to add the IPv6 extension header, which are illustrated below by way a and way b.

[0277] Method a: Add an IPv6 extension header in the encapsulation mode.

[0278] Optionally, the first network device generates an IPv6 header and an IPv6 extension header, uses the original packet as the payload, and adds the IPv6 header and the IPv6 extension header to the outer layer of the original packet to obtain an IPv6 packet, thereby realizing the generation of the IPv6 packet. When the original packet is an IP packet, the IPv6 packet generated by using method a is in the form of a mobile IP data encapsulation and tunneling (IP in IP) packet, and the generated IPv6 packet includes multiple IP headers. The outer IP header includes the added IPv6 extension header, and the inner IP header includes the IP header of the original packet. For example, if the original packet is an IPv6 packet, the IPv6 packet generated by using method a includes two IPv6 headers. The outer IPv6 header is added by the first network device, and the inner IPv6 header is the IPv6 header of the original packet itself. Another example is that if the original packet is an IPv4 packet, the IPv6 packet generated by using method a includes one IPv6 header and one IPv4 header. The outer IPv6 header is added by the first network device, and the inner IPv4 header is the IPv4 header of the original packet itself.

[0279] Method b: Add an IPv6 extension header in the insert mode.

[0280] Specifically, the first network device generates an IPv6 extension header and inserts the IPv6 extension header between the IPv6 header of the original packet and the payload of the original packet, thereby realizing the generation of the IPv6 packet.

[0281] Optionally, in method b, the first network device does not need to generate and add the outer IPv6 header, but uses the original IPv6 header of the original packet to generate the IPv6 packet.

[0282] S204: The first network device sends the IPv6 packet.

[0283] After the first network device sends the IPv6 packet to the second network device, since the IPv6 packet includes the original packet and EPG information, the original packet and the EPG information are transmitted to the second network device together.

[0284] S205: The second network device in the IPv6 network receives the IPv6 packet.

[0285] Optionally, after receiving an IPv6 packet, the second network device first identifies the identification field in the IPv6 packet. The second network device determines whether the IPv6 packet has been processed according to the group policy based on the value of the identification field. If the second network device determines, based on the identification field, that the IPv6 packet has not been processed according to the group policy, that is, the group policy has not been executed by the upstream node, the second network device performs the following S206.

[0286] If the second network device determines, based on the identification field, that the IPv6 packet has been processed according to the group policy, that is, the group policy has been executed by the upstream node, the actions performed by the second network device include multiple cases. Optionally, if the group policy has been executed by the upstream node, the second network device does not execute the group policy. That is, the second network device does not perform the following S206 and S207, but skips S206 and S207 and goes to execute S208. For example, in the case where the identification field occupies one bit in the IPv6 packet, the second network device determines whether the identification field is set. If the identification field is not set, the second network device determines that the IPv6 packet has not been processed according to the group policy and performs the following S206. If the identification field has been set, the second network device determines that the IPv6 packet has been processed according to the group policy, does not perform the following S206, and forwards the IPv6 packet.

[0287] Optionally, this technical means is applied to the scenario where the intermediate node supports the micro-segmentation function. For example, if both the intermediate node through which the IPv6 packet passes and the destination VTEP device support the micro-segmentation function, after the IPv6 packet is processed according to the group policy by the intermediate node, the destination VTEP device (the second network device) no longer processes the IPv6 packet according to the group policy according to the indication of the identification field. Another example is that if multiple-hop intermediate nodes through which the IPv6 packet passes all support the micro-segmentation function, after the IPv6 packet is processed according to the group policy by a certain hop of the intermediate node, the downstream intermediate node of the intermediate node that executes the group policy no longer processes the IPv6 packet according to the group policy according to the indication of the identification field. In this way, it is possible to specify that the IPv6 packet is only processed by one hop of the intermediate node, avoiding the forwarding delay and processing overhead caused by the same group policy being executed multiple times by different nodes.

[0288] S206. The second network device obtains the EPG information from the IPv6 extension header.

[0289] Combined with different situations of carrying the EPG information, the process of obtaining the EPG information also includes multiple cases, which are illustrated by Case 1 to Case 3 below.

[0290] Case 1. The second network device obtains the EPG information from the hop-by-hop options header.

[0291] For example, the second network device obtains the first EPG information from the hop-by-hop options header. Another example is that the second network device obtains the first EPG information and the second EPG information from the hop-by-hop options header. Another example is that the second network device obtains the second EPG information from the hop-by-hop options header.

[0292] Case 2: The second network device obtains the EPG information from the destination options header.

[0293] For example, the second network device obtains the first EPG information from the destination options header. Another example is that the second network device obtains the first EPG information and the second EPG information from the destination options header. Another example is that the second network device obtains the second EPG information from the destination options header.

[0294] Case 3: The second network device obtains different EPG information from the hop-by-hop options header and the destination options header respectively.

[0295] For example, the second network device obtains the first EPG information from the hop-by-hop options header and the second EPG information from the destination options header. Another example is that the second network device obtains the second EPG information from the hop-by-hop options header and the first EPG information from the destination options header.

[0296] S207: The second network device processes the IPv6 packet according to the group policy corresponding to the EPG information.

[0297] Optionally, the second network device obtains the group policy according to the EPG information in the IPv6 packet. Specifically, the second network device pre-obtains and saves the group policy. After receiving the IPv6 packet, the second network device obtains the EPG information from the IPv6 packet and finds the pre-saved group policy according to the EPG information. Among them, there are multiple implementation methods for the location where the group policy is saved. Optionally, the second network device saves the group policy in the GBP entry.

[0298] There are multiple implementation methods for how to obtain the group policy. The following examples are given by Method 1 to Method 2.

[0299] Method 1: The method of static configuration.

[0300] Specifically, the second network device receives a configuration instruction, and the second network device obtains the group policy according to the configuration instruction. Optionally, the configuration instruction is triggered by the configuration operation of the operation and maintenance personnel. Or, the configuration instruction is sent by the network management system or the network application to the second network device.

[0301] Method 2: The method of pre-setting at the time of production.

[0302] For example, the second network device saves the group policy at the time of factory by burning in the processor or other hard-coding methods.

[0303] There are multiple implementation methods for processing packets according to group policies. Specifically, the second network device queries the policy matrix based on the EPG information carried in the IPv6 packet, and uses the EPG information carried in the IPv6 packet to match the matching conditions. When the EPG information carried in the IPv6 packet matches the matching conditions, the second network device executes the group policy corresponding to the matching conditions. Among them, the process of executing the group policy is the process of processing the IPv6 packet according to the group policy.

[0304] The matching methods include strict matching and longest matching. The strict matching method means that when the EPG information in the IPv6 packet completely meets the matching conditions, it is determined that the EPG information meets the matching conditions. When using the strict matching method, the processing actions corresponding to the completely met matching conditions are executed. The longest matching method means that the matching length between the EPG information in the IPv6 packet and each matching condition is determined, the matching condition with the longest matching length is found, and the matching condition with the longest matching length is used as the satisfied matching condition. When using the longest matching method, the processing actions corresponding to the matching condition with the longest matching length are executed. Optionally, when there are multiple group policies with equal matching lengths, the first hit group policy is executed, or the last hit group policy is executed, or the group policy with the highest priority hit is executed. Among them, there are multiple implementation methods for calculating the matching length. For example, the first EPG information is matched with the EPG information of the source Endpoint device in the matching condition. If the two EPG information match, the matching length is incremented by one. And, the second EPG information is matched with the EPG information of the destination Endpoint device in the matching condition. If the two EPG information match, the matching length is incremented by one.

[0305] In the case where the IPv6 packet carries the EPG information of the source Endpoint device and does not carry the EPG information of the destination Endpoint device, in the case where the IPv6 packet carries the EPG information of the destination Endpoint device and does not carry the EPG information of the source Endpoint device, and in the case where the IPv6 packet carries the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device, the second network device can all execute S207 to implement the function of microsegmentation. Hereinafter, through Implementation Method A to Implementation Method C, an example is given of how to implement microsegmentation in the case where the IPv6 packet carries one of the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device.

[0306] Implementation Method A: The correspondence between IP addresses and EPG information is pre-stored.

[0307] Specifically, the second network device has pre-stored the correspondence between the IP address of the Endpoint device and the EPG information. When the IPv6 packet carries the EPG information of the source Endpoint device but does not carry the EPG information of the destination Endpoint device, when the second network device receives the IPv6 packet, it not only obtains the first EPG information from the IPv6 extension header of the IPv6 packet, but also queries the correspondence between the IP address and the EPG information according to the destination IP address included in the IPv6 packet to obtain the second EPG information, and processes the IPv6 packet according to the group policy corresponding to the first EPG information and the second EPG information. When the IPv6 packet carries the EPG information of the destination Endpoint device but does not carry the EPG information of the source Endpoint device, when the second network device receives the IPv6 packet, it not only obtains the second EPG information from the IPv6 extension header of the IPv6 packet, but also queries the correspondence between the IP address and the EPG information according to the source IP address included in the IPv6 packet to obtain the first EPG information, and processes the IPv6 packet according to the group policy corresponding to the first EPG information and the second EPG information.

[0308] Implementation method B: The matching condition of the group policy includes either the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device.

[0309] For example, the matching condition of the group policy includes the EPG information of the source Endpoint device and does not include the EPG information of the destination Endpoint device. For example, the matching condition of the group policy is EPG1 to*. When the second network device receives the IPv6 packet, it obtains the first EPG information from the IPv6 extension header of the IPv6 packet and only needs to match the first EPG information with EPG1. In this way, the IPv6 packet can carry only the EPG information of the source Endpoint device and not carry the EPG information of the destination Endpoint device.

[0310] Another example is that the second network device is a device such as a firewall. The matching condition corresponding to the group policy includes the EPG information of the destination Endpoint device and does not include the EPG information of the source Endpoint device. For example, the matching condition of the group policy is *to EPG1. When the second network device receives the IPv6 packet, it obtains the second EPG information from the IPv6 extension header of the IPv6 packet and only needs to match the second EPG information with EPG1. In this way, the IPv6 packet can carry only the EPG information of the destination Endpoint device and not carry the EPG information of the source Endpoint device.

[0311] Implementation method C: Search for group policies in the longest matching manner.

[0312] For example, when determining whether the EPG information in the IPv6 packet matches the EPG information in the matching condition of the group policy, it is not required that both the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device in the group policy be matched. When either the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device in the group policy is matched, the matching length between the group policy and the IPv6 packet is incremented by one. Then, when the IPv6 packet carries either the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device, the group policy that matches either the EPG information of the source Endpoint device or the EPG information of the destination Endpoint device has a probability of being executed.

[0313] The processing methods of the packet according to the group policy include multiple situations, which are illustrated by S2071 to S2074 below.

[0314] S2071: When the group policy is to discard, the second network device discards the IPv6 packet and ends the process.

[0315] S2072: When the group policy is to mirror, the second network device mirrors the IPv6 packet to the specified address and ends the process.

[0316] S2073: When the group policy is to redirect, the second network device changes the destination address of the IPv6 packet and ends the process.

[0317] S2074: When the group policy is to forward or mark, the second network device executes S308 below.

[0318] S208: The second network device sends the original packet.

[0319] Specifically, the second network device forwards the IPv6 packet according to the destination IP address of the outer IPv6 header in the IPv6 packet. During the forwarding process, the second network device will at least send the original packet in the IPv6 packet, and there are multiple situations regarding whether to send the outer IPv6 header and the IPv6 extension header, which are illustrated by Situation A to Situation C below.

[0320] Situation A: The second network device strips the outer IPv6 header and the IPv6 extension header and sends the inner original packet. Situation A is suitable for the scenario where the second network device is the destination VTEP device.

[0321] Situation B: The second network device strips the IPv6 extension header and sends the outer IPv6 header and the inner original packet.

[0322] In case B, the second network device does not strip the outer IPv6 header. This is illustrated by case B1 and case B2 below.

[0323] Case B1: The outer IPv6 header is used for routing and forwarding by downstream intermediate nodes.

[0324] Case B1 is applicable to the scenario where the second network device is an intermediate node. For example, after an intermediate node executes a group policy based on the EPG information in the IPv6 extension header (such as the hop-by-hop options header), it removes the IPv6 extension header and forwards the remaining IPv6 packet to the next-hop intermediate node. The remaining IPv6 packet includes the outer IPv6 header and the inner original packet, so that the next-hop intermediate node can perform routing and forwarding based on the outer IPv6 header.

[0325] Case B2: The outer IPv6 header is the header carried by the original packet itself.

[0326] For example, when the original packet is an IPv6 packet, the outer IPv6 header in the IPv6 packet received by the second network device may not be added by the first network device, but carried by the original packet itself. In this case, the second network device does not strip the IPv6 header in order to pass the IPv6 header carried by the original packet itself to the next-hop node.

[0327] Optionally, case B2 is applied when the second network device is a tail node. The tail node does not strip the IPv6 header, but strips the IPv6 extension header and sends the stripped packet to the Customer Edge (CE) node, so that the packet received by the CE node retains the IPv6 header of the original packet itself and does not contain the IPv6 extension header added during the routing and forwarding process. Of course, case B2 can also be applied when the second network device is an intermediate node.

[0328] Case C: The second network device does not strip the IPv6 extension header and sends the outer IPv6 header, the IPv6 extension header, and the inner original packet. Case C is applicable to the scenario where the second network device is an intermediate node. For example, the IPv6 extension header (such as the hop-by-hop options header) carries not only the EPG information required for executing the group policy, but also some other information required for the forwarding plane, such as the fragmentation identifier for network fragmentation, the required delay, the required bandwidth, etc. After the intermediate node executes the group policy based on the EPG information in the IPv6 extension header, it forwards the IPv6 packet including the IPv6 header, the IPv6 extension header, and the original packet to the next-hop intermediate node, so that the next-hop intermediate node can use the information in the IPv6 extension header.

[0329] Optionally, the IPv6 packet is an SRv6-BE packet, and the destination IP address in the outer IPv6 header of the IPv6 packet is the VPNSID. The following uses Method 1, Method 2, and Method 3 to illustrate how the second network device forwards packets in the SRv6-BE scenario. Among them, Method 1 is about how the destination VTEP device forwards packets when using SRv6-BE, Method 2 is about how the intermediate nodes that do not support SRv6 forward packets when using SRv6-BE, and Method 3 is about how the intermediate nodes that support SRv6 forward packets when using SRv6-BE.

[0330] Method 1: The second network device queries the Local SID table according to the destination IP address in the outer IPv6 header. If it is determined that the destination address matches the VPN SID in the local SID table, the IPv6 header and the IPv6 extension header are stripped off, and the original packet is sent to the VPN instance (such as the second computing device or the CE device connected to the second computing device), so that the original packet is finally forwarded to the second computing device. For example, if the second network device determines, according to the Local SID table, that the type of the destination IP address is End.DX, the second network device sends the original packet out from the outgoing interface bound to the End.DX SID. Another example is that if the second network device determines, according to the Local SID table, that the type of the destination IP address is End.DT, it queries the VPN instance routing table for forwarding according to the destination address in the original packet.

[0331] Method 2: The second network device queries the IPv6 routing forwarding table according to the destination IP address in the outer IPv6 header, and forwards the IPv6 packet by the longest match according to the IPv6 routing forwarding table, so that the IPv6 packet is forwarded to the destination VTEP device.

[0332] Method 3: The second network device first queries the Local SID table according to the destination IP address in the outer IPv6 header. If it is determined that the destination address does not match each SID in the local SID table, it then queries the IPv6 routing forwarding table and forwards the IPv6 packet by the longest match according to the IPv6 routing forwarding table, so that the IPv6 packet is forwarded to the destination VTEP device.

[0333] Optionally, when the IPv6 packet includes an identification field, the second network device first updates the value of the identification field and then forwards the IPv6 packet with the updated identification field. For example, when the second network device is an intermediate node, the second network device not only enforces the group policy, but also sets the identification field and sends the IPv6 packet with the set identification field that has been processed according to the group policy to the downstream intermediate node. Through this optional method, since the node that enforces the policy updates the identification field after enforcing the group policy, it can indicate that the group policy has been enforced, so that in the subsequent forwarding process of the IPv6 packet, the group policy does not have to be repeatedly enforced, thus reducing the processing overhead of the downstream nodes of the node that enforces the policy.

[0334] This embodiment provides a method for implementing microsegmentation in an IPv6 network. By using the IPv6 extension header of the IPv6 packet to carry EPG information, the EPG information is made visible to the receiving end of the IPv6 packet, so that the receiving end of the IPv6 packet does not need to de-encapsulate the VXLAN header and can enforce the group policy according to the EPG information in the IPv6 extension header, thereby implementing the function of microsegmentation and reducing the processing complexity. And because the IPv6 extension header has stronger extensibility, the problem of weak extensibility existing in carrying EPG information through the VXLAN header is solved, which helps to continue to expand new functions. Also, because the encapsulation format of the packet is more concise and the header occupies fewer bytes, the overhead caused by transmitting the packet is saved.

[0335] The above method 200 introduced a method for implementing microsegmentation based on IPv6. The following uses method 300 and method 400 to illustrate method 200 respectively.

[0336] Please refer to Figure 20 and Figure 21 In the following method 300, the first computing device (source Endpoint device) is VM1, the first network device is the source VTEP device, the second network device is the destination VTEP device, and the second computing device (destination Endpoint device) is VM4. In other words, the method flow described in method 300 is about how the destination VTEP device enforces the group policy based on IPv6 during the process of VM1 accessing VM4. For the steps that are the same as those in method F00 in method 300, please refer to method F00 and will not be elaborated in method S00.

[0337] Figure 20 The scenario of implementing the VTEP device through a server is shown. The VTEP device is a virtual switch in the server, and the virtual switch can be implemented through the Hypervisor or the network card. For example, the source VTEP device is virtual switch 1 in the server where VM1 is located. The destination VTEP device is virtual switch 2 in the server where VM4 is located.

[0338] Figure 21 The scenario of implementing a VTEP device through a network device is shown. The VTEP device is a network device (such as a data center TOR switch). For example, the source VTEP device is Leaf1. The destination VTEP device is Leaf2.

[0339] Please refer to Figure 22 , and exemplarily, method 300 includes S301 to S308.

[0340] S301. VM1 sends an original packet.

[0341] S302. The source VTEP device in the IPv6 network receives the original packet.

[0342] For example, please refer to Figure 20 or Figure 21 , the transmission direction of the packet flow is from VM1 to VM4. VM1 sends an original packet, and the original packet reaches the source VTEP device. The source VTEP device identifies the EPG to which VM1 belongs as GroupB according to the IP address of the original packet, and determines that the destination end VM4 of the original packet is not under the source VTEP device, then S303 is executed.

[0343] S303. The source VTEP device generates an IPv6 packet according to the original packet and the EPG information of VM1. The destination option header of the IPv6 packet includes the EPG information of VM1.

[0344] The EPG information of VM1 is an illustration of the first EPG information (the EPG information of the source Endpoint device) in method 200. The EPG information of VM1 is used to identify the EPG to which VM1 belongs. For example, if the EPG to which VM1 belongs is EPG B, the EPG information of VM1 is the ID of EPG B. The source VTEP device encapsulates the ID of EPG B in the destination option header, for example, in the TLV in the destination option header. The source VTEP device encapsulates the destination option header for the original packet, and after encapsulation, forwards it in the direction of the destination VTEP device.

[0345] S304. The source VTEP device sends the IPv6 packet.

[0346] S305. The destination VTEP device in the IPv6 network receives the IPv6 packet.

[0347] S306. The destination VTEP device obtains the EPG information of VM1 from the destination option header.

[0348] In method 300, the destination VTEP device has two roles: the VTEP device and the execution node of the group policy. After the packet arrives at the destination VTEP, the destination VTEP device reads and caches the EPG information of VM1 from the TLV in the destination option header.

[0349] S307. The destination VTEP device processes the IPv6 packet according to the group policy corresponding to the EPG information of VM1 and the EPG information of VM4.

[0350] The EPG information of VM4 is an illustration of the second EPG information (the EPG information of the destination Endpoint device) in method 200. The EPG information of VM4 is used to identify the EPG to which VM4 belongs. Specifically, the destination VTEP device de-encapsulates the outer IPv6 encapsulation to expose the original packet. The destination VTEP device matches the EPG information of VM4 according to the destination IP address in the original packet. The destination VTEP device looks up the policy matrix according to the EPG information of VM1 and the EPG information of VM4 to obtain the corresponding group policy; the destination VTEP device processes the original packet according to the group policy.

[0351] S308. The destination VTEP device sends the original packet to VM4.

[0352] This embodiment provides a method for a destination VTEP device to execute a group policy based on an IPv6 network. By using the destination option header of IPv6 to carry the EPG information of the source Endpoint device, the EPG information of the source Endpoint device is passed to the destination VTEP device through the destination option header. Therefore, the destination VTEP device does not need to de-encapsulate the VXLAN header and can execute the group policy according to the EPG information of the source Endpoint device, thus realizing the function of micro-segmentation and reducing the processing complexity. And because the destination option header has stronger scalability, the problem of weak scalability existing in carrying EPG information through the VXLAN header is solved, which helps to continue to expand new functions. Also, because the encapsulation format of the destination option header is more concise and the overhead of the outer encapsulation of the packet is smaller, the overhead brought by transmitting the packet is saved.

[0353] Please refer to Figure 23 , in the following method 400, the first computing device is VM1, the first network device is the source VTEP device, the second network device is the intermediate node, and the second computing device is VM4. In other words, the method flow described in method 400 is about how the intermediate node executes the group policy based on IPv6 during the process of VM1 accessing VM4. For the steps in method 400 that are the same as those in method 200 or method 300, please refer to method 200 or method 300 and will not be elaborated in method 400.

[0354] Please refer to Figure 24, exemplarily, method 400 includes S401 to S409.

[0355] S401. VM1 sends an original message.

[0356] S402: The source VTEP device in the IPv6 network receives the original message.

[0357] S403. The source VTEP device generates an IPv6 message according to the original message, the EPG information of VM1, and the EPG information of VM4. The IPv6 message includes a hop-by-hop option header and the original message. The hop-by-hop option header includes the EPG information of VM1 and the EPG information of VM4.

[0358] The EPG information of VM1 is an example of the first EPG information (EPG information of the source Endpoint device) in method 200. The EPG information of VM4 is an example of the second EPG information (EPG information of the destination Endpoint device) in method 200. Specifically, in method 400, the vSwitch on the data center server serves as a VTEP device, and the VTEP device searches for the EPG information of VM1 and the EPG information of VM4 according to the source IP address, the destination IP address and the local table entry information of the inner original message, encapsulates the EPG information of VM1 and the EPG information of VM4 in the hop-by-hop option header of IPv6, and forwards the IPv6 message encapsulated with the hop-by-hop option header.

[0359] S404: The source VTEP device sends an IPv6 message.

[0360] S405: An intermediate node in the IPv6 network receives an IPv6 message.

[0361] S406 . The intermediate node obtains the EPG information of VM1 and the EPG information of VM4 from the hop-by-hop option header.

[0362] S407 . The intermediate node processes the IPv6 message according to the group policy corresponding to the EPG information of VM1 and the EPG information of VM4 .

[0363] Since the hop-by-hop option header carries the EPG information of the source endpoint device and the destination endpoint device, any intermediate node on the forwarding path can execute the group policy based on the EPG information of the source endpoint device and the destination endpoint device. The intermediate node is, for example, a data center leaf switch or a spine switch. For example, Figure 23It shows the execution of group policies on the Spine switch. Among them, when the group policy is forwarding or marking, the intermediate node executes the following S408. When the group policy is discarding, the intermediate node ends the process.

[0364] S408: The intermediate node sends an IPv6 packet.

[0365] S409: The destination VTEP device receives the IPv6 packet, decapsulates the IPv6 packet to obtain the original packet, and sends the original packet to VM4.

[0366] This embodiment provides a method for an intermediate node to execute group policies based on an IPv6 network. By using the hop-by-hop option header of IPv6 to carry the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device, the EPG information of the source Endpoint device and the EPG information of the destination Endpoint device are passed to the intermediate node through the hop-by-hop option header. Therefore, the intermediate node does not need to decapsulate the VXLAN header and can execute group policies according to the EPG information of the source Endpoint device and the destination Endpoint device, thereby realizing the function of micro-segmentation and reducing the processing complexity. And because the hop-by-hop option header has stronger scalability, the problem of weak scalability existing in carrying EPG information through the VXLAN header is solved, which helps to continue to expand new functions. On the one hand, because the encapsulation format of the hop-by-hop option header is more concise and the overhead of the outer encapsulation of the packet is smaller, the overhead brought by transmitting the packet is saved. On the other hand, the limitation that only the VTEP device can execute group policies is broken, and the role of the policy execution node is decoupled from the role of the VTEP device, so that the intermediate node can also execute group policies, thereby supporting the function of micro-segmentation. On the other hand, when the intermediate node executes group policies, it does not need to perform outer encapsulation decapsulation, so the processing overhead of outer encapsulation decapsulation is eliminated and the processing flow is simplified.

[0367] The methods 200, 300, and 400 of the embodiments of the present application are introduced above. The network devices of the embodiments of the present application are introduced below. The network devices introduced below have any functions of the first network device or the second network device in the above methods 200, 300, or 400.

[0368] Figure 25 It is a schematic structural diagram of a network device 500 provided by an embodiment of the present application. As Figure 25 shown, the network device 500 includes: a receiving module 501, configured to execute S202, S302, or S402; a generating module 502, configured to execute S203, S303, or S403; a sending module 503, configured to execute S204, S304, or S404.

[0369] The network device 500 corresponds to the first network device in the above method embodiments. Each module in the network device 500 and the above other operations and / or functions respectively implement various steps and methods implemented by the first network device in the method embodiments. For specific details, refer to the above method 200, method 300, or method 400. For the sake of brevity, they will not be elaborated here.

[0370] When the network device 500 processes packets, only the division of the above functional modules is used for illustration. In practical applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the network device 500 is divided into different functional modules to complete all or part of the functions described above. In addition, the network device 500 provided in the above embodiments and the above method 200, method 300, or method 400 belong to the same concept. For the specific implementation process, refer to method 200, method 300, or method 400, which will not be elaborated here.

[0371] Figure 26 It is a schematic structural diagram of a network device 600 provided by an embodiment of the present application. As Figure 26 shown, the network device 600 includes: a receiving module 601 for performing S205, S305, or S405; an obtaining module 602 for performing S206, S306, or S406; and a processing module 603 for performing S207, S307, or S407.

[0372] The network device 600 corresponds to the second network device in the above method embodiments. Each module in the network device 600 and the above other operations and / or functions respectively implement various steps and methods implemented by the second network device in the method embodiments. For specific details, refer to the above method 200, method 300, or method 400. For the sake of brevity, they will not be elaborated here.

[0373] When the network device 600 processes packets, only the division of the above functional modules is used for illustration. In practical applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the network device 600 is divided into different functional modules to complete all or part of the functions described above. In addition, the network device 600 provided in the above embodiments and the above method 200, method 300, or method 400 belong to the same concept. For the specific implementation process, refer to method 200, method 300, or method 400, which will not be elaborated here.

[0374] Corresponding to the method embodiments and virtual device embodiments provided by the present application, the present application embodiments also provide a network device. The following introduces the hardware structure of the network device.

[0375] The network device 700 or network device 800 described below corresponds to the first network device or the second network device in the above method embodiments. Each hardware and module in the network device 700 or network device 800 and the above other operations and / or functions respectively implement various steps and methods implemented by the network device 700 or network device 800 in the method embodiments. For the detailed process of how the network device 700 or network device 800 implements microsegmentation based on IPv6, specific details can be referred to the above method embodiments. For the sake of brevity, they will not be elaborated here. Among them, each step of the above method 200, method 300, or method 400 is completed by the integrated logic circuit of the hardware in the processor of the network device 700 or network device 800 or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly implemented by the execution of the hardware processor, or implemented by the combination of the hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, registers, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here

[0376] The network device 700 or network device 800 corresponds to the network device 500 or network device 600 in the above virtual device embodiments. Each functional module in the network device 500 or network device 600 is implemented by the software of the network device 700 or network device 800. In other words, the functional modules included in the network device 500 or network device 600 are generated after the processor of the network device 700 or network device 800 reads the program code stored in the memory

[0377] See Figure 27 , Figure 27 FIG. shows a schematic structural diagram of a network device 700 provided by an exemplary embodiment of the present application. The network device 700 can be configured as the first network device or the second network device. The network device 700 can be implemented by a general bus architecture

[0378] The network device 700 includes at least one processor 701, a communication bus 702, a memory 703, and at least one communication interface 704

[0379] The processor 701 can be a general-purpose CPU, NP, microprocessor, or can be one or more integrated circuits for implementing the solution of this application. For example, an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The above PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0380] The communication bus 702 is used to transfer information between the above components. The communication bus 702 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 27 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0381] The memory 703 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, or can be a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 703 can exist independently and be connected to the processor 701 through the communication bus 702. The memory 703 can also be integrated with the processor 701.

[0382] The communication interface 704 uses any transceiver-like device for communicating with other devices or communication networks. The communication interface 704 includes a wired communication interface and may also include a wireless communication interface. Among them, the wired communication interface can be, for example, an Ethernet interface. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface can be a wireless local area networks (WLAN) interface, a cellular network communication interface, or a combination thereof, etc.

[0383] In a specific implementation, as an example, the processor 701 may include one or more CPUs, such as Figure 27 the CPU0 and CPU1 shown in

[0384] In a specific implementation, as an example, the network device 700 may include multiple processors, such as Figure 27 the processor 701 and the processor 705 shown in

[0385] Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0386] In some embodiments, the memory 703 is used to store the program code 710 for executing the solution of this application, and the processor 701 can execute the program code 710 stored in the memory 703. That is, the network device 700 can implement the methods 200, 300, or 400 provided by the method embodiments through the processor 701 and the program code 710 in the memory 703.

[0387] The network device 700 in the embodiments of the present application may correspond to the first network device or the second network device in each of the above method embodiments. Moreover, the processor 701, communication interface 704, etc. in the network device 700 may implement the functions and / or various steps and methods performed by the first network device or the second network device in each of the above method embodiments. For the sake of brevity, details are not described herein again.

[0388] The receiving module 501 and the transmitting module 503 in the network device 500 are equivalent to the communication interface 704 in the network device 700; the generating module 502 in the network device 500 may be equivalent to the processor 701 in the network device 700.

[0389] The receiving module 601 in the network device 600 is equivalent to the communication interface 704 in the network device 700; the obtaining module 602 and the processing module 603 in the network device 600 may be equivalent to the processor 701 in the network device 700.

[0390] See Figure 28 , Figure 28 FIG. shows a schematic structural diagram of a network device 800 provided by an exemplary embodiment of the present application. The network device 800 may be configured as a first network device or a second network device. The network device 800 includes: a main control board 810 and an interface board 830.

[0391] The main control board 810 is also referred to as a main processing unit (MPU) or a route processor card. The main control board 810 is used for controlling and managing various components in the network device 800, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 810 includes: a central processor 811 and a memory 812.

[0392] The interface board 830 is also referred to as a line processing unit card (LPU), a line card, or a service board. The interface board 830 is used to provide various service interfaces and implement packet forwarding. The service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc. The Ethernet interface is, for example, a Flexible Ethernet Clients (FlexE Clients). The interface board 830 includes: a central processor 831, a network processor 832, a forwarding table entry memory 834, and a physical interface card (PIC) 833.

[0393] The central processor 831 on the interface board 830 is used to control and manage the interface board 830 and communicate with the central processor 811 on the main control board 810.

[0394] The network processor 832 is used to implement the forwarding and processing of packets. The form of the network processor 832 can be a forwarding chip. Specifically, the network processor 832 is used to forward the received packets based on the forwarding table entries stored in the forwarding table entry memory 834. If the destination address of the packet is the address of the network device 800, the packet is sent to the CPU (such as the central processor 811) for processing; if the destination address of the packet is not the address of the network device 800, the next hop and output interface corresponding to the destination address are found from the forwarding table according to the destination address, and the packet is forwarded to the output interface corresponding to the destination address. Among them, the processing of the upstream packets includes: the processing of the packet input interface, and the search of the forwarding table; the processing of the downstream packets: the search of the forwarding table, etc.

[0395] The physical interface card 833 is used to implement the docking function of the physical layer. The original traffic enters the interface board 830 from here, and the processed packets are sent out from the physical interface card 833. The physical interface card 833 is also called a daughter card and can be installed on the interface board 830. It is responsible for converting the optical and electrical signals into packets, performing a legality check on the packets, and then forwarding them to the network processor 832 for processing. In some embodiments, the central processor can also perform the function of the network processor 832, such as implementing software forwarding based on a general CPU, so that the network processor 832 is not required in the physical interface card 833.

[0396] Optionally, the network device 800 includes multiple interface boards. For example, the network device 800 further includes an interface board 840, and the interface board 840 includes: a central processor 841, a network processor 842, a forwarding table entry memory 844, and a physical interface card 843.

[0397] Optionally, the network device 800 further includes a switching fabric board 820. The switching fabric board 820 can also be called a switching fabric unit (SFU). In the case where the network device has multiple interface boards 830, the switching fabric board 820 is used to complete the data exchange between the interface boards. For example, the interface board 830 and the interface board 840 can communicate through the switching fabric board 820.

[0398] The main control board 810 is coupled to the interface board 830. For example, the main control board 810, the interface board 830, the interface board 840, and the switching fabric board 820 are interconnected through a system bus and a system backplane. In a possible implementation, an inter-process communication (IPC) channel is established between the main control board 810 and the interface board 830, and the main control board 810 and the interface board 830 communicate through the IPC channel.

[0399] Logically, the network device 800 includes a control plane and a forwarding plane. The control plane includes the main control board 810 and the central processing unit 831, and the forwarding plane includes various components that perform forwarding, such as the forwarding table entry memory 834, the physical interface card 833, and the network processor 832. The control plane performs functions such as acting as a router, generating a forwarding table, processing signaling and protocol messages, and configuring and maintaining the device status. The control plane distributes the generated forwarding table to the forwarding plane. In the forwarding plane, the network processor 832 looks up and forwards the packets received by the physical interface card 833 based on the forwarding table distributed by the control plane. The forwarding table distributed by the control plane can be stored in the forwarding table entry memory 834. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same device.

[0400] If the network device 800 is configured as a first network device, the physical interface card 833 receives the original packet and sends it to the network processor 832. The network processor 832 generates an IPv6 packet based on the original packet and the EPG information, and after completing the link layer encapsulation according to information such as the outgoing interface, sends the IPv6 packet out from the physical interface card 833, so that the IPv6 packet is transmitted to a second network device.

[0401] If the network device 800 is configured as a second network device, the physical interface card 833 receives the IPv6 packet and sends it to the network processor 832. The network processor 832 obtains the EPG information from the IPv6 extension header and processes the IPv6 packet according to the group policy corresponding to the EPG information.

[0402] The receiving module 501 and the sending module 503 in the network device 500 are equivalent to the physical interface card 833 in the network device 800; the generating module 502 in the network device 500 can be equivalent to the network processor 832 or the central processing unit 811.

[0403] The receiving module 601 in the network device 600 is equivalent to the physical interface card 833 in the network device 800; the obtaining module 602 and the processing module 603 in the network device 600 can be equivalent to the network processor 832 or the central processing unit 811.

[0404] In the embodiments of the present application, the operations on interface board 840 are the same as those on interface board 830. For the sake of brevity, they will not be described again. The network device 800 in this embodiment may correspond to the first network device or the second network device in each of the above method embodiments. The main control board 810, interface board 830, and / or 840 in the network device 800 can implement the functions and / or various steps performed by the first network device or the second network device in each of the above method embodiments. For the sake of brevity, they will not be described here again.

[0405] It should be noted that there may be one or more main control boards. When there are multiple main control boards, they may include an active main control board and a standby main control board. There may be one or more interface boards. The stronger the data processing capacity of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching fabric board, or there may be one or more switching fabric boards. When there are multiple switching fabric boards, they can jointly implement load sharing and redundant backup. In a centralized forwarding architecture, the network device may not require a switching fabric board, and the interface board undertakes the processing function of the service data of the entire system. In a distributed forwarding architecture, the network device may have at least one switching fabric board, and data exchange between multiple interface boards is achieved through the switching fabric board, providing a large-capacity data exchange and processing capacity. Therefore, the data access and processing capabilities of network devices with a distributed architecture are greater than those of devices with a centralized architecture. Optionally, the form of the network device may also be a single board, that is, without a switching fabric board, and the functions of the interface board and the main control board are integrated on this single board. At this time, the central processors on the interface board and the main control board can be combined into one central processor on this single board to execute the functions after their superposition. The data exchange and processing capabilities of this form of device are relatively low (for example, network devices such as low-end switches or routers). Which architecture is specifically adopted depends on the specific networking deployment scenario, and no limitations are imposed here.

[0406] In some possible embodiments, the above first network device or second network device may be implemented as a virtualized device.

[0407] For example, the virtualized device can be a virtual machine (VM) running a program for sending packets. The virtual machine is deployed on a hardware device (e.g., a physical server). A virtual machine refers to a complete computer system with complete hardware system functions simulated by software and running in a completely isolated environment. The virtual machine can be configured as a first network device or a second network device. For example, a first network device or a second network device can be implemented based on a general physical server combined with Network Functions Virtualization (NFV) technology. The first network device or the second network device is a virtual host, a virtual router, or a virtual switch. Those skilled in the art can, by reading this application, virtualize a first network device or a second network device with the above functions on a general physical server in combination with NFV technology. Details are not described herein again.

[0408] For example, the virtualized device can be a container. A container is an entity used to provide an isolated virtualized environment. For example, the container can be a docker container. The container can be configured as a first network device or a second network device. For example, a first network device or a second network device can be created through a corresponding image. For example, through the image of a proxy-container (a container providing a proxy service), two container instances, namely container instance proxy-container1 and container instance proxy-container2, can be created for the proxy-container. The container instance proxy-container1 is provided as a first network device or a first computing device, and the container instance proxy-container2 is provided as a second network device or a second computing device. When implemented using container technology, the first network device or the second network device can run using the kernel of the physical machine, and multiple first network devices or second network devices can share the operating system of the physical machine. Different first network devices or second network devices can be isolated through container technology. The containerized first network device or second network device can run in a virtualized environment, for example, it can run in a virtual machine, and the containerized first network device or second network device can also directly run on the physical machine.

[0409] For example, the virtualized device can be a Pod. A Pod is the basic unit for deploying, managing, and orchestrating containerized applications in Kubernetes (Kubernetes is an open-source container orchestration engine developed by Google, abbreviated as K8s in English). A Pod can include one or more containers. Each container in the same Pod is usually deployed on the same host. Therefore, each container in the same Pod can communicate through the host and can share the storage resources and network resources of the host. The Pod can be configured as a first network device or a second network device. For example, specifically, it can be instructed to a container as a service (English full name: container as a service, abbreviated as CaaS, which is a container-based PaaS service) to create a Pod and provide the Pod as a first network device or a second network device.

[0410] Of course, the first network device or the second network device can also be other virtualized devices, which will not be listed one by one here.

[0411] In some possible embodiments, the above-mentioned first network device or second network device can also be implemented by a general-purpose processor. For example, the form of the general-purpose processor can be a chip. Specifically, the general-purpose processor implementing the first network device or the second network device includes a processing circuit, an input interface internally connected and communicating with the processing circuit, and an output interface. The processing circuit is used to execute the step of generating the message in each of the above method embodiments through the input interface. The processing circuit is used to execute the receiving step in each of the above method embodiments through the input interface. The processing circuit is used to execute the sending step in each of the above method embodiments through the output interface. Optionally, the general-purpose processor can also include a storage medium. The processing circuit is used to execute the storage step in each of the above method embodiments through the storage medium. The storage medium can store instructions executed by the processing circuit, and the processing circuit is used to execute the instructions stored in the storage medium to execute each of the above method embodiments.

[0412] See Figure 29 , an embodiment of the present application provides a network system 900. The system 900 includes: a first network device 901 and a second network device 902. Optionally, the first network device 901 is such as the network device 500, the network device 700, or the network device 800, and the second network device 902 is the network device 600, the network device 700, or the network device 800.

[0413] An embodiment of the present application provides a computer program product. When the computer program product runs on the first network device or the second network device, the first network device or the second network device is caused to execute the methods 200, 300, or 400 in the above method embodiments.

[0414] An embodiment of the present application provides a chip. When the chip runs on a first network device or a second network device, the first network device or the second network device is enabled to execute method 200, method 300, or method 400 in the above method embodiments.

[0415] The network devices in the above various product forms respectively have any functions of the first network device or the second network device in the above method embodiments, which will not be elaborated here.

[0416] Those of ordinary skill in the art can realize that, in combination with the method steps and units described in the embodiments disclosed herein, they can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the steps and components of the embodiments have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0417] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, which will not be elaborated here.

[0418] In several embodiments provided by the present application, the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the unit is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection to each other can be an indirect coupling or communication connection through some interfaces, devices, or units, and can also be in an electrical, mechanical, or other form of connection.

[0419] The unit described as a separated component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present application.

[0420] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0421] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0422] The above description is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

[0423] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid-state drive), etc.

[0424] Those of ordinary skill in the art can understand that all or part of the steps for implementing the above embodiments can be completed by hardware, or can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk, an optical disc, or the like.

[0425] The above description is only an alternative embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A message processing method, characterized in that, Applied to the Internet Protocol Version 6 (IPv6) network, the method includes: A first network device in the IPv6 network receives an original packet. The first network device generates an IPv6 packet according to the original packet and Endpoint Group (EPG) information. The IPv6 packet includes an IPv6 extension header and the original packet. The IPv6 extension header includes the EPG information. The EPG information includes at least one of first EPG information and second EPG information. The first EPG information is used to identify the EPG to which a first computing device belongs, and the source Internet Protocol (IP) address of the original packet includes the IP address of the first computing device. The second EPG information is used to identify the EPG to which a second computing device belongs, and the destination IP address of the original packet includes the IP address of the second computing device. The IPv6 extension header includes at least one of a Hop-by-Hop Options header and a Destination Options header, and at least one of the Hop-by-Hop Options header and the Destination Options header includes the EPG information. The first network device sends the IPv6 packet.

2. The method according to claim 1, wherein The IPv6 extension header includes a Type-Length-Value (TLV), and the EPG information is located in the value field of the TLV.

3. The method according to claim 1, wherein The IPv6 extension header includes one or more options, and the EPG information includes first EPG information and second EPG information. The first EPG information and the second EPG information are located in the same option of the IPv6 extension header; or, the first EPG information and the second EPG information are respectively located in different options of the IPv6 extension header.

4. The method according to claim 1, wherein The IPv6 packet includes an IPv6 header outside the original packet, and the destination IP address of the IPv6 header includes a Virtual Private Network Segment Identifier (VPN SID).

5. The method according to claim 1, characterized in that The IPv6 packet includes an identification field, which is used to indicate whether the IPv6 packet has been processed according to the group policy corresponding to the EPG information.

6. A message processing method, characterized in that, Applied to the Internet Protocol Version 6 (IPv6) network, the method includes: A second network device in the IPv6 network receives an IPv6 packet. The IPv6 packet includes an IPv6 extension header and an original packet. The IPv6 extension header includes Endpoint Group (EPG) information. The EPG information includes at least one of first EPG information and second EPG information. The first EPG information is used to identify the EPG to which a first computing device belongs, and the source Internet Protocol (IP) address of the original packet includes the IP address of the first computing device. The second EPG information is used to identify the EPG to which a second computing device belongs, and the destination IP address of the original packet includes the IP address of the second computing device. The IPv6 extension header includes at least one of a Hop-by-Hop Options header and a Destination Options header, and at least one of the Hop-by-Hop Options header and the Destination Options header includes the EPG information. The second network device obtains the EPG information from the IPv6 extension header. The second network device processes the IPv6 packet according to the group policy corresponding to the EPG information.

7. The method according to claim 6, characterized in that, After the second network device obtains the EPG information from the IPv6 extension header, the method further includes: The second network device obtains the group policy according to the EPG information.

8. The method according to claim 6, characterized in that, The IPv6 extension header includes a type length value TLV, and the EPG information is located in the value field of the TLV.

9. The method according to claim 6, wherein The IPv6 extension header includes one or more options, and the EPG information includes first EPG information and second EPG information; The first EPG information and the second EPG information are located in the same option of the IPv6 extension header; or, the first EPG information and the second EPG information are respectively located in different options of the IPv6 extension header.

10. The method according to claim 6, wherein The IPv6 packet includes an IPv6 header located outside the original packet, and the destination IP address of the IPv6 header includes a virtual private network segment identifier VPN SID.

11. The method according to claim 6, characterized in that, The IPv6 packet includes an identification field for indicating whether the IPv6 packet has been processed according to the group policy corresponding to the EPG information. Before the second network device processes the IPv6 packet according to the group policy corresponding to the EPG information, the method further includes: The second network device determines that the IPv6 packet has not been processed according to the group policy according to the value of the identification field.

12. The method according to claim 11, wherein The second network device processes the IPv6 packet according to the group policy corresponding to the EPG information, including: The second network device updates the value of the identification field.

13. A first network device, characterized in that, The device is applied to an Internet Protocol version 6 (IPv6) network. The device includes: A receiving module, configured to receive an original packet; A generating module, configured to generate an IPv6 packet according to the original packet and endpoint group (EPG) information. The IPv6 packet includes an IPv6 extension header and the original packet. The IPv6 extension header includes the EPG information. The EPG information includes at least one of first EPG information and second EPG information. The first EPG information is used to identify the EPG to which a first computing device belongs, the source Internet Protocol (IP) address of the original packet includes the IP address of the first computing device, the second EPG information is used to identify the EPG to which a second computing device belongs, the destination IP address of the original packet includes the IP address of the second computing device, the IPv6 extension header includes at least one of a hop-by-hop option header and a destination option header, and at least one of the hop-by-hop option header and the destination option header includes the EPG information; A sending module, configured to send the IPv6 packet.

14. The device according to claim 13, wherein The IPv6 extension header includes a type length value TLV, and the EPG information is located in the value field of the TLV.

15. The device according to claim 13, characterized in that, The IPv6 extension header includes one or more options, and the EPG information includes first EPG information and second EPG information; The first EPG information and the second EPG information are located in the same option of the IPv6 extension header; or, the first EPG information and the second EPG information are respectively located in different options of the IPv6 extension header.

16. The device according to claim 13, characterized in that, The IPv6 packet includes an IPv6 header located outside the original packet, and the destination IP address of the IPv6 header includes a virtual private network segment identifier (VPN SID).

17. The device according to claim 13, characterized in that, The IPv6 packet includes an identification field, and the identification field is used to indicate whether the IPv6 packet has been processed according to the group policy corresponding to the EPG information.

18. A second network device, characterized in that, The device is applied to an Internet Protocol Version 6 (IPv6) network, and the device includes: a receiving module, configured to receive an IPv6 packet, where the IPv6 packet includes an IPv6 extension header and an original packet, the IPv6 extension header includes endpoint group (EPG) information, the EPG information includes at least one of first EPG information and second EPG information, the first EPG information is used to identify the EPG to which a first computing device belongs, the source Internet Protocol (IP) address of the original packet includes the IP address of the first computing device, the second EPG information is used to identify the EPG to which a second computing device belongs, the destination IP address of the original packet includes the IP address of the second computing device, the IPv6 extension header includes at least one of a hop-by-hop option header and a destination option header, and at least one of the hop-by-hop option header and the destination option header includes the EPG information; an obtaining module, configured to obtain the EPG information from the IPv6 extension header; a processing module, configured to process the IPv6 packet according to the group policy corresponding to the EPG information.

19. The device according to claim 18, characterized in that, The obtaining module is further configured to obtain the group policy according to the EPG information.

20. The apparatus according to claim 18, characterized in that, The IPv6 extension header includes a type length value (TLV), and the EPG information is located in the value field of the TLV.

21. The device according to claim 18, characterized in that, The IPv6 extension header includes one or more options, and the EPG information includes first EPG information and second EPG information; The first EPG information and the second EPG information are located in the same option of the IPv6 extension header; or, the first EPG information and the second EPG information are respectively located in different options of the IPv6 extension header.

22. The device according to claim 18, characterized in that, The IPv6 packet includes an IPv6 header located outside the original packet, and the destination IP address of the IPv6 header includes a virtual private network segment identifier (VPN SID).

23. The device according to claim 18, characterized in that, The IPv6 packet includes an identification field, and the identification field is used to indicate whether the IPv6 packet has been processed according to the group policy corresponding to the EPG information. The device further includes a determining module, configured to determine, according to the value of the identification field, that the IPv6 packet has not been processed according to the group policy.

24. The device according to claim 23, characterized in that, The processing module is further configured to update the value of the identification field.

25. A network system, characterized in that, The network system includes a first network device and a second network device. The first network device is the first network device according to any one of claims 13 to 17, and the second network device is the second network device according to any one of claims 18 to 24.

26. A computer-readable storage medium, characterized in that, At least one instruction is stored in the storage medium, and the instruction is read by a processor to cause the network device to execute the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Processing method, equipment and system for Internet protocol version 6 (IPv6) message

    CN102088391A

  • Group strategy implementation method based on VXLAN, network equipment and group strategy implementation system

    CN110650075A

  • Mechanism to coordinate end to end quality of service between network nodes and service provider core

    WO2020041150A1