Method, device, and system for sending IPv6 messages

By configuring preset thresholds in network devices and checking the hop limit field of IPv6 messages, avoiding forwarding or discarding IPv6 messages whose hop limit is less than or equal to the threshold, the problem of too many ICMPv6 error messages during IPv6 message forwarding is solved, and the security of IPv6 message forwarding and network bandwidth utilization are improved.

CN114071375BActive Publication Date: 2025-08-29HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202010944510.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-08-06
Filing Date
2020-09-10
Publication Date
2025-08-29
Estimated Expiration
2040-09-10

AI Technical Summary

Technical Problem

During IPv6 message forwarding, if the hop limit field is less than or equal to 1, it will cause a large number of ICMPv6 error messages to be generated, resulting in waste of network bandwidth and device attacks. How to avoid this situation becomes an urgent problem.

Method used

Configure a preset threshold in a network device to check whether the hop limit field of the IPv6 message is less than or equal to the threshold, and avoid forwarding the IPv6 message or discarding the message when the inner layer message is a multicast message and the destination address is a unicast address to reduce the generation of ICMPv6 error messages.

Benefits of technology

It effectively reduces the probability of ICMPv6 error packets caused by the hop limit value of 1 or 0, avoids waste of network bandwidth and bandwidth of attacked devices, and improves the security of IPv6 packet forwarding.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114071375B_ABST
    Figure CN114071375B_ABST
Patent Text Reader

Abstract

The present application provides a method, device, and system for sending an IPv6 message. The method includes: a first network device receiving a first IPv6 message, the first IPv6 message including a message header and an inner message, the message header including a hop limit field; determining whether the value of the hop limit field is less than or equal to a preset threshold; and determining whether the inner message is a multicast message. When the value of the hop limit field is less than or equal to the preset threshold and the inner message is a multicast message, forwarding the first IPv6 message is avoided. The technical solution provided by the present application can avoid the waste of network bandwidth caused by a large number of ICMPv6 error messages and the waste of bandwidth of the attacked device, thereby improving the security of IPv6 message forwarding.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on August 6, 2020, with application number 202010785073.1 and invention name “A P2MP tunnel detection method, device and system”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of network communications, and more specifically, to a method, network device, and system for sending IPv6 messages. Background Art

[0003] During the forwarding process of Internet Protocol version 6 (IPv6) messages, if the value of the hop limit field in the outer IPv6 header of the IPv6 message is less than or equal to 1, the IPv6 message will not be forwarded to the downstream device. Instead, an Internet Control Message Protocol version 6 (ICMPv6) error message will be sent to the source address of the outer IPv6 header.

[0004] If an attacker forges an IPv6 message with a hop limit value less than or equal to 1, the source address in the outer IPv6 header will receive multiple, or even a large number of, ICMPv6 error messages. Therefore, preventing forwarding network devices from generating multiple, or even a large number of, ICMPv6 error messages and improving the security of IPv6 message forwarding have become urgent issues. Summary of the Invention

[0005] The present application provides a method, network device, and system for sending IPv6 messages, which can avoid the waste of network bandwidth and bandwidth of attacked devices caused by multiple or even a large number of ICMPv6 error messages, and improve the security of IPv6 message forwarding.

[0006] In a first aspect, a method for sending an IPv6 message is provided, comprising: a first network device receives a first IPv6 message, the first IPv6 message comprising an outer IPv6 message header and an inner message, the message header comprising a hop limit hoplimit field; the first network device determines whether the value of the hop limit field in the first IPv6 message is less than or equal to a preset threshold on the first network device, wherein the preset threshold is a number greater than or equal to 2; the first network device determines whether the inner message is a multicast message; when the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the inner message is the multicast message, and the destination address in the outer IPv6 header is a unicast address, the first network device avoids forwarding the first IPv6 message.

[0007] It should be understood that the first network device avoiding forwarding the IPv6 message can be considered as the first network device preventing the IPv6 message from being sent to the next hop device, or can also be considered as the first network device skipping forwarding the IPv6 message. In other words, the first network device does not send the IPv6 message to the next hop device of the first network device.

[0008] In the above technical solution, a threshold greater than or equal to 2 can be configured on a first network device (a device that supports multicast forwarding based on the unicast destination address of an IPv6 message). Before forwarding an IPv6 message, the first network device checks that the hop limit of the message is less than or equal to the threshold and avoids forwarding the IPv6 message. This reduces the probability of ICMPv6 error messages being generated due to an IPv6 hop limit value of 1 or 0, thereby improving the security of IPv6 message forwarding and avoiding the waste of network bandwidth and bandwidth of the attacked device caused by multiple or even large numbers of ICMPv6 error messages.

[0009] In a possible implementation, the method further includes: the first network device discarding the first IPv6 packet.

[0010] In another possible implementation, the preset threshold is a threshold determined based on the number of one or more consecutive second network devices connected to the first network device, and the second network device is a network device that performs unicast forwarding based on the destination address of the IPv6 message received from the first network device, and the destination address of the IPv6 message received from the first network device is different from the address of the second network device.

[0011] In the above technical solution, the first network device avoids forwarding the IPv6 message when checking that the hop limit of the message is less than or equal to the threshold before forwarding the IPv6 message. In this way, the probability of generating ICMPv6 error messages due to the IPv6 hop limit value of 1 or 0 when the BIERv6 message is sent to the above-mentioned second network device can be reduced, thereby improving the security of IPv6 message forwarding and avoiding the waste of network bandwidth and bandwidth of the attacked device caused by multiple or even a large number of ICMPv6 error messages.

[0012] In another possible implementation, the method also includes: the first network device receives a second IPv6 message, the second IPv6 message includes a message header and an inner message, and the message header includes a hop limit field; the first network device determines whether the value of the hop limit field in the second IPv6 message is less than or equal to the preset threshold; the first network device determines whether the inner message of the second IPv6 message is the multicast message; when the value of the hop limit field in the second IPv6 message is greater than the preset threshold, and the inner message of the second IPv6 message is the multicast message, the first network device processes the second IPv6 message.

[0013] In another possible implementation, if the first network device is an intermediate forwarding device, the first network device sends the second IPv6 message to the second network device, and the second network device forwards the second IPv6 message to the third network device, and the destination address of the second IPv6 message is the address of the third network device; or if the first network device is an egress device, the first network device decapsulates the second IPv6 message and forwards the inner layer message obtained after decapsulating the second IPv6 message.

[0014] In another possible implementation, the multicast message includes any one of the following: an IPv6 multicast message, an Internet Protocol version 4 (IPv4) multicast message, or an Ethernet message.

[0015] In another possible implementation, the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the method further includes: when the inner layer message of the first IPv6 message is an operation, maintenance and management (OAM) message, if the transmission rate of the first IPv6 message is greater than the preset rate, the first network device avoids forwarding the IPv6 message.

[0016] In the above technical solution, the security of IPv6 message forwarding can also be improved while considering how to support OAM, avoiding the waste of network bandwidth and bandwidth of attacked devices caused by multiple or even a large number of ICMPv6 error messages, or in other words, while improving the security of IPv6 message transmission, the OAM detection function can also be ensured not to be affected.

[0017] In another possible implementation, the method further includes: the first network device discarding the first IPv6 packet.

[0018] In another possible implementation, the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the method further includes: when the inner multicast message is an OAM message, if the transmission rate of the first IPv6 message is less than or equal to the preset rate, the first network device forwards the first IPv6 message.

[0019] In a second aspect, a first network device is provided, including:

[0020] A receiving module, configured to receive a first IPv6 message, wherein the first IPv6 message includes a message header and an inner message, wherein the message header includes a hop limit field;

[0021] a processing module, configured to determine whether a value of the hop limit field in the first IPv6 packet is less than or equal to a preset threshold on the first network device, wherein the preset threshold is a number greater than or equal to 2;

[0022] The processing module is further configured to determine whether the inner layer message is a multicast message;

[0023] The processing module is further configured to avoid forwarding the first IPv6 message when the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold and the inner message is the multicast message.

[0024] In a possible implementation, the processing module is further configured to discard the first IPv6 packet.

[0025] In another possible implementation, the preset threshold is a threshold determined based on the number of one or more consecutive second network devices connected to the first network device, and the second network device is a network device that performs unicast forwarding based on the destination address of the IPv6 message received from the first network device, and the destination address of the IPv6 message received from the first network device is different from the address of the second network device.

[0026] In another possible implementation, the receiving module is further configured to: receive a second IPv6 packet, where the second IPv6 packet includes a packet header and an inner packet, and the packet header includes a hop limit field;

[0027] The processing module is further configured to determine whether a value of the hop limit field in the second IPv6 message is less than or equal to the preset threshold;

[0028] The processing module is further configured to determine whether the inner packet of the second IPv6 packet is the multicast packet;

[0029] The processing module is further configured to process the second IPv6 message when the value of the hop limit field in the second IPv6 message is greater than the preset threshold and the inner message of the second IPv6 message is the multicast message.

[0030] In another possible implementation, the processing module is specifically used to: if the first network device is an intermediate forwarding device, send the second IPv6 message to the second network device, and the second network device forwards the second IPv6 message to the third network device, and the destination address of the second IPv6 message is the address of the third network device; or if the first network device is an egress device, decapsulate the second IPv6 message and forward the inner layer message obtained after decapsulating the second IPv6 message.

[0031] In another possible implementation, the multicast message includes any one of the following: an IPv6 multicast message, an Internet Protocol version 4 (IPv4) multicast message, or an Ethernet message.

[0032] In another possible implementation, the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the processing module is also used to: when the inner layer message of the first IPv6 message is an operation, maintenance and management OAM message, if the transmission rate of the first IPv6 message is greater than the preset rate, avoid forwarding the IPv6 message.

[0033] In another possible implementation, the processing module is further configured to discard the first IPv6 packet.

[0034] In another possible implementation, the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the processing module is further used to: when the inner multicast message is an OAM message, if the transmission rate of the first IPv6 message is less than or equal to the preset rate, forward the first IPv6 message.

[0035] The beneficial effects of the second aspect and any possible implementation of the second aspect correspond to the beneficial effects of the first aspect and any possible implementation of the first aspect, and will not be elaborated on herein.

[0036] In a third aspect, a first network device is provided, wherein the first network device has the function of implementing the first network device behavior in the above method. The function can be implemented in hardware or by executing corresponding software based on the hardware. The hardware or software includes one or more modules corresponding to the above function.

[0037] In one possible design, the structure of the first network device includes a processor and an interface, wherein the processor is configured to support the first network device in performing the corresponding functions in the above method. The interface is used to support the first network device in receiving the first IPv6 packet; or receiving the second IPv6 packet.

[0038] The first network device may further include a memory, which is coupled to the processor and stores program instructions and data necessary for the first network device.

[0039] In another possible design, the first network device includes: a processor, a transmitter, a receiver, a random access memory, a read-only memory, and a bus. The processor is coupled to the transmitter, receiver, random access memory, and read-only memory, respectively, via the bus. When the first network device needs to be operated, it is booted via a basic input / output system embedded in the read-only memory or a bootloader in an embedded system, thereby booting the first network device into normal operation. After the first network device enters normal operation, an application program and an operating system are run in the random access memory, causing the processor to execute the method of the first aspect or any possible implementation of the first aspect.

[0040] In a fourth aspect, a first network device is provided. The first network device includes a main control board and an interface board, and may further include a switching network board. The first network device is configured to perform the method of the first aspect or any possible implementation of the first aspect. Specifically, the first network device includes a module configured to perform the method of the first aspect or any possible implementation of the first aspect.

[0041] In a fifth aspect, a first network device is provided, which includes a control module and a first forwarding sub-device. The first forwarding sub-device includes: an interface board, and further, may also include a switching network board. The first forwarding sub-device is used to perform the functions of the interface board in the fourth aspect, and further, may also perform the functions of the switching network board in the fourth aspect. The control module includes a receiver, a processor, a transmitter, a random access memory, a read-only memory, and a bus. The processor is respectively coupled to the receiver, the transmitter, the random access memory, and the read-only memory through the bus. When the control module needs to be run, it is started by the basic input / output system solidified in the read-only memory or the bootloader boot system in the embedded system, and the control module is guided into normal operating state. After the control module enters normal operating state, the application program and the operating system are run in the random access memory, so that the processor performs the functions of the main control board in the sixth aspect.

[0042] It is understandable that, in practical applications, the first network device may include any number of interfaces, processors or memories.

[0043] In a sixth aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the above-mentioned first aspect or any possible execution method of the first aspect.

[0044] In a seventh aspect, a computer-readable medium is provided, the computer-readable medium storing program code, which, when executed on a computer, causes the computer to execute the method of the first aspect or any possible execution of the first aspect. Such computer-readable storage includes, but is not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM), and hard drive.

[0045] In an eighth aspect, a chip is provided, comprising a processor and a data interface, wherein the processor reads instructions stored in a memory through the data interface to execute the method of the first aspect or any possible implementation of the first aspect. In a specific implementation, the chip can be implemented in the form of a central processing unit (CPU), a microcontroller unit (MCU), a microprocessor (MPU), a digital signal processor (DSP), a system on chip (SoC), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a programmable logic device (PLD).

[0046] In a ninth aspect, a system for sending IPv6 packets is provided, the system comprising the above-mentioned first network device. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a schematic diagram of a scenario applicable to an embodiment of the present application.

[0048] Figure 2 This is a schematic flowchart of a method for sending an IPv6 message provided in an embodiment of the present application.

[0049] Figure 3 This is a schematic flowchart of another method for sending IPv6 packets provided in an embodiment of the present application.

[0050] Figure 4 This is a schematic flowchart of another method for sending IPv6 packets provided in an embodiment of the present application.

[0051] Figure 5 This is a schematic flowchart of another method for sending IPv6 packets provided in an embodiment of the present application.

[0052] Figure 6 This is a schematic flowchart of another method for sending IPv6 packets provided in an embodiment of the present application.

[0053] Figure 7 It is a schematic structural diagram of a first network device 700 provided in an embodiment of the present application.

[0054] Figure 8It is a hardware structure diagram of the first network device 2000 according to an embodiment of the present application.

[0055] Figure 9 This is a schematic diagram of the hardware structure of another first network device 2100 according to an embodiment of the present application. DETAILED DESCRIPTION

[0056] The technical solution in this application will be described below with reference to the accompanying drawings.

[0057] This application will present various aspects, embodiments, or features around systems including multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.

[0058] Additionally, in the embodiments of this application, words such as "exemplary" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner.

[0059] In the embodiments of the present application, “corresponding” and “relevant” may sometimes be used interchangeably. It should be noted that when the distinction between them is not emphasized, the meanings they intend to express are consistent.

[0060] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person skilled in the art will appreciate that, with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems.

[0061] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0062] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: including the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0063] Multicast is a data transmission method that uses a single multicast address to efficiently send user multicast messages simultaneously to multiple receivers on a Transmission Control Protocol (TCP) / Internet Protocol (IP) network. A multicast source sends a multicast stream to all multicast group members in a multicast group via links in the network, and all multicast group members in the multicast group can receive the multicast stream. Multicast transmission enables point-to-multipoint data connections between the multicast source and multicast group members. Because a multicast stream only needs to be transmitted once on each network link and is replicated only when a branch occurs on the link, multicast transmission improves data transmission efficiency and reduces the likelihood of backbone network congestion.

[0064] IP multicast technology uses the multicast group address as the destination address of packets and establishes a multicast forwarding tree using Protocol Independent Multicast (PIM) signaling. This multicast forwarding tree then organizes the network plane into a logical tree, enabling point-to-multipoint multicast data forwarding. This IP multicast technology, based on the construction of a multicast forwarding tree, enables efficient point-to-multipoint data transmission within IP networks, effectively conserving network bandwidth and reducing network load. Consequently, it has found widespread application in real-time data transmission, multimedia conferencing, data copying, interactive Internet Protocol Television (IPTV), gaming, and simulation.

[0065] As an example, the above IP multicast technology can be implemented by using an Internet Protocol version 6 (IPv6) unicast address as the destination address of the message. A point-to-multipoint (P2MP) forwarding path is established from an ingress router to multiple egress routers, and the multicast message is forwarded along the P2MP forwarding path. As an example, the P2MP forwarding path can be used as a tunnel. The ingress router encapsulates the user multicast message in the tunnel, and the egress router decapsulates and restores the user multicast message and sends it.

[0066] Figure 1 This is a schematic diagram of a scenario applicable to the embodiment of this application. Figure 1 The segment routing replication (SR-replication) domain may include: R1, R3, R5, R6, R7, and R8. Among them, R1 is the ingress device of the segment routing replication domain, responsible for IPv6 encapsulation of user multicast messages. Specifically, an IPv6 header may be encapsulated in the outer layer of the user multicast message, and the IPv6 header may contain a destination address (DA) field and a source address (SA) field. R3 and R5 are intermediate forwarding (transit) devices of the segment routing replication domain, responsible for forwarding messages according to the destination address (DA) in the IPv6 header encapsulated in the outer layer of the user multicast message. R6, R7, and R8 are egress devices of the segment routing replication domain, responsible for decapsulating the encapsulated user multicast message and then forwarding the inner user multicast message.

[0067] The embodiment of the present application does not specifically limit the type of the above-mentioned user multicast message. It can be an Internet Protocol version 4 (IPv4) multicast message, or it can also be an Internet Protocol version 6 (IPv6) multicast message, or it can also be an Ethernet message.

[0068] R1 acts as the ingress device of the segment routing replication domain, and the format of the IPv6 message it encapsulates is: outer IPv6 header + user multicast message (IPv4 multicast message or IPv6 multicast message or Etherent message). In the embodiment of the present application, there are multiple specific implementation methods for partitioning the type of user multicast message following the outer IPv6 header. Several possible implementation methods are described in detail below.

[0069] In one possible implementation, different user multicast message types can be identified by the value of the next header (NH) field of the outer IPv6 header. For example, a value of 4 in the next header field can indicate that the user multicast message following the outer IPv6 header is an IPv4 multicast message. For another example, a value of 41 in the next header field can indicate that the user multicast message following the outer IPv6 header is an IPv6 multicast message. For another example, a value of 143 in the next header field can indicate that the user multicast message following the outer IPv6 header is an Etherent message.

[0070] In another possible implementation, the type of the user multicast message can also be determined based on the destination address (DA) field of the inner user multicast message. For example, if the address in the DA field is an IPv4 multicast address (specifically, the upper 4 bits of the IPv4 address are 1110, i.e., the address range is 224.0.0.0 to 239.255.255.255.255), the user multicast message can be determined to be an IPv4 multicast message. Alternatively, if the address in the DA field is an IPv6 multicast address (specifically, the first byte of the IPv6 address is 0xff), the user multicast message can be determined to be an IPv6 multicast message.

[0071] It should be noted that, for an etherent message, the etherent header is followed by an IPv4 or IPv6 multicast message, and therefore, the above method is also applicable.

[0072] Optionally, in some embodiments, multicast forwarding based on IPv6 unicast addresses may also support operation administration and maintenance (OAM) functions. Therefore, the user multicast message may also be an operation administration and maintenance (OAM) message.

[0073] The above-mentioned process of multicast forwarding based on the IPv6 unicast address is forwarding based on the hop-by-hop change of the IPv6 unicast address in the outer IPv6 header.

[0074] exist Figure 1 In the scenario shown, there are many specific implementation methods for devices in the network to use IPv6 unicast addresses as destination addresses to forward multicast messages, which are not specifically limited in this application. Two possible implementation methods are described in detail below.

[0075] It should be understood that in the various implementations described below, IPv6 unicast addresses are used as destination addresses and that the destination addresses are modified during forwarding. For example, the destination address of a message sent from R1 to R3 is R3's unicast address. The destination addresses of messages sent from R3 to R5 and R6 are R5 and R6, respectively. The destination addresses of messages sent from R5 to R7 and R8 are R7 and R8, respectively.

[0076] It should also be understood that Figure 1 In the scenario shown, the IPv6 unicast addresses configured on each device can be different, or two or more devices can be configured with the same IPv6 unicast address. Configuring the same IPv6 unicast address on two or more devices constitutes IPv6 anycast.

[0077] For ease of description, the following uses an example in which different devices use different IPv6 unicast addresses.

[0078] In one possible implementation, when multiple multicast trees (also called P2MP trees) need to be established with R1 as the root node, Figure 1 Each device (R1, R3, R5, R6, R7, R8) in the segment routing replication domain shown needs to reserve multiple addresses in its own IPv6 address space, so as to achieve the purpose of establishing multiple multicast trees with R1 as the root node.

[0079] 1. Figure 1 The multicast tree marked with a solid line is shown in the following table 1.

[0080] Table 1 Information of the multicast tree marked by the solid line

[0081]

[0082]

[0083] The multicast tree with a replication ID (RepID) of 1 is indicated by a solid line. A device's branch information may represent one or more of its downstream P2MP devices. It should be understood that if the device is a P2MP leaf device, it typically decapsulates messages before forwarding inner multicast messages. Therefore, such a leaf device may have no downstream devices, and its corresponding branch information can be represented using decapsulation (decap).

[0084] Figure 1 The P2MP forwarding table entries generated by each device in accordance with the multicast tree information marked with a solid line issued by the controller are shown in Table 2 below.

[0085] Table 2 P2MP forwarding table entries corresponding to the multicast tree marked by solid lines

[0086]

[0087] The destination address (DA) R1_1 in the table is determined based on R1's node identifier (node ​​ID) and RepID = 1. When applied to the IPv6 data plane, R1_1 is an IPv6 address. The determination of other addresses is similar to that of the destination address R1_1 and will not be repeated here.

[0088] For example, if R1 receives a packet with a destination address of R1_1 in the outer IPv6 header, the forwarding plane further searches the forwarding table for DA = R1_1. Finding the P2MP entry described above, the forwarding plane determines that the packet is to be "copied" to R3_1. Therefore, the forwarding plane changes the destination address of the packet to R3_1 and sends it to R3. The packet is then sent along the P2MP tree (marked by the solid line) to each leaf node, where it is decapsulated.

[0089] 2. Figure 1 The information of the P2MP tree marked with a dotted line sent by the controller is shown in Table 3 below.

[0090] Table 3 Information of the multicast tree marked by the dotted line

[0091]

[0092]

[0093] Wherein, replication ID (RepID)=2 is the multicast tree marked by the dotted line.

[0094] Figure 1 The P2MP forwarding entries generated by each device in accordance with the multicast tree information marked with a dotted line issued by the controller are shown in Table 4 below.

[0095] Table 4 P2MP forwarding table entries corresponding to the multicast tree marked by the dotted line

[0096]

[0097] For example, if R1 receives a packet with a destination address of R1_2 in the outer IPv6 header, the forwarding plane further searches the forwarding table for DA = R1_2. Finding the P2MP entry described above, the forwarding plane determines that the packet is to be "copied" to R3_2. Therefore, the forwarding plane changes the destination address of the packet to R3_2 and sends it to R3. The packet is then sent along the P2MP tree (marked by the dotted lines) to each leaf node, where it is decapsulated.

[0098] In another possible implementation, when multiple multicast trees (also called P2MP trees) need to be established with R1 as the root node, the root node R1 only needs to reserve multiple addresses corresponding to the multiple multicast trees. Figure 1 The remaining devices in the segment routing replication domain shown do not need to reserve multiple addresses corresponding to multiple multicast trees. In this way, the purpose of establishing multiple multicast trees with R1 as the root node can also be achieved.

[0099] 1. Establish based on need Figure 1 For example, in the multicast tree with R1 as the root node, an address R1_1 needs to be assigned to R1. The address R1_1 is sent to each node in the multicast tree, and the branch information of the multicast tree on each node is sent.

[0100] The devices under the multicast tree marked with a solid line with R1 as the root node may include: R1, R3, R5, R6, R7, and R8. The information of the multicast tree marked with a solid line received by each of the above nodes is shown in Table 5.

[0101] Table 5 Information of the multicast tree marked by the solid line

[0102]

[0103] Taking R1 as an example, “tree=R1_1” means the multicast tree is Figure 1 In the multicast tree indicated by the solid line, “branch=R3” indicates that the downstream device of R1 is R3.

[0104] Taking R5 as an example, the multicast tree is Figure 1 The multicast tree marked by the solid line is shown in the figure. The downstream devices of R3 are R7 and R8. For R6, the multicast tree is Figure 1In the multicast tree marked by the solid line, "branch=Decap" indicates that R6 is a leaf device, which needs to decapsulate the encapsulated multicast message and then forward the inner multicast message.

[0105] The P2MP forwarding table entries established by each device in the network according to the multicast tree information shown in Table 5 are shown in Table 6.

[0106] Table 6 P2MP forwarding table entries corresponding to the multicast tree marked by solid lines

[0107]

[0108] It should be understood that each device in the network is configured with a first address as the destination address of the message, and the first address is used to indicate that the source address corresponding to the message is searched according to the destination address of the message. When the destination address of the message received on the device is the first address, the device will search for the source address of the message.

[0109] For example, the first addresses assigned to R1, R3, R5, R6, R7, and R8 are R1_0, R3_0, R5_0, R6_0, R7_0, and R8_0, respectively. When R1 receives a message with a destination address of R1_0, R1 searches for the message's source address. When R3 receives a message with a destination address of R3_0, R3 searches for the message's source address. And so on.

[0110] Taking R1 as an example, since the multicast tree is Figure 1 In the multicast tree marked by the solid line, the downstream device of R1 is R3. Therefore, the source address represented by "SA=R1_1" in the P2MP forwarding table entry established by R1 is R1_1, and "branch_IP=R3_0" indicates that the IP address of the downstream device of R1 is the first address R3_0 allocated by R3.

[0111] R1 detects that the destination address of the message's outer IPv6 header is R1_0. Based on R1_0's instructions, it searches for the message's source address SA. R1 determines that the message's source address SA is R1_1, and based on the P2MP forwarding table entries shown in Table 6, it determines that the branch_IP corresponding to SA = R1_1 is R3_0. Therefore, R1 learns that the message is to be "copied" to R3_0. R1's forwarding plane can modify the message's destination address to R3_0 and send it to R3. Similarly, R5 receives a message with a destination address of R5_0. Based on the indication that the destination address is R5_0, R5 searches for the message's source address SA. R5 determines that the message's source address SA is R1_1, and based on the P2MP forwarding table entries shown in Table 7, it determines that the branch_IP corresponding to SA = R1_1 is R7_0 / R8_0. Therefore, R5 learns that the message is to be "copied" to R7_0 and R8_0. R5's forwarding plane modifies the message's destination address to R7_0 and sends it to R7. It also modifies the message's destination address to R8_0 and sends it to R8. The message is then sent along the P2MP tree (marked by the solid line) to each leaf node, where it is decapsulated.

[0112] 2. Establish based on need Figure 1 For example, in the multicast tree with R1 as the root node, an address R1_2 needs to be assigned to R1. The address R1_2 is sent to each node in the multicast tree, and the branch information of the multicast tree on each node is sent.

[0113] The devices under the multicast tree marked with a dotted line with R1 as the root node may include: R1, R3, R5, R6, R7, and R8. The information of the multicast tree marked with a dotted line received by each of the above nodes is shown in Table 7.

[0114] Table 7 Information of the multicast tree marked by the dotted line

[0115]

[0116]

[0117] Taking R1 as an example, “tree=R1_2” means the multicast tree is Figure 1 In the multicast tree indicated by the dotted line, “branch=R3” indicates that the downstream device of R1 is R3.

[0118] The P2MP forwarding table entries established by each device in the network according to the multicast tree information shown in Table 7 are shown in Table 8.

[0119] Table 8 P2MP forwarding table entries corresponding to the multicast tree marked by the dotted line

[0120]

[0121] Taking R1 as an example, since the multicast tree is Figure 1 In the multicast tree marked by the dotted line, the downstream device of R1 is R3. Therefore, the source address represented by "SA=R1_2" in the P2MP forwarding table entry established by R1 is R1_2, and "branch_IP=R3_0" indicates that the IP address of the downstream device of R1 is the first address R3_0 allocated by R3.

[0122] R1 detects the destination address of the packet's outer IPv6 header as R1_0. Based on R1_0's instructions, it searches for the packet's source address SA. R1 determines the packet's source address SA to be R1_2. Based on the P2MP forwarding table entries shown in Table 8, it determines that the branch_IP corresponding to SA = R1_2 is R3_0. Therefore, R1 knows the packet is to be "copied" to R3_0. R1's forwarding plane modifies the packet's destination address to R3_0 and sends it to R3. Similarly, R5 receives a packet with a destination address of R5_0. Based on the indication of R5_0, R5 searches for the packet's source address SA. R5 determines the packet's source address SA to be R1_2. Based on the P2MP forwarding table entries shown in Table 8, it determines that the branch_IP corresponding to SA = R1_2 is R7_0. Therefore, R5 knows the packet is to be "copied" to R7_0. R5's forwarding plane modifies the packet's destination address to R7_0 and sends it to R7. After that, the message will be sent to each leaf node along the P2MP tree marked by the dotted line and decapsulated by each leaf node.

[0123] In the above method of forwarding multicast packets based on IPv6 unicast addresses as destination addresses, there is a forwarding security issue. As an example, Figure 1 The illustrated scenario also includes devices that do not perform the "multicast forwarding based on IPv6 unicast addresses" as described above.

[0124] It should be understood that a device that does not perform "multicast forwarding based on IPv6 unicast address" as described above may be a network device that performs unicast forwarding based on the destination address of the received IPv6 message, where the destination address of the received IPv6 message is different from the address of the device.

[0125] For example, Figure 1In this example, there is R35 between R3 and R5, and R36 between R3 and R6. Both R35 and R36 are IPv6 routers and do not perform multicast forwarding based on IPv6 unicast addresses as described above. For these devices that do not perform multicast forwarding based on IPv6 unicast addresses, the destination address of the IPv6 packet is not the address of the device itself. When R3 receives a packet with a hop limit (HL) field value of 2 in the outer IPv6 header, the packet actually needs to pass through R35 and R36, respectively, as specified by the protocol. The hop limit field value of the packet received by R35 and R36 is 1. R35 and R36, following the protocol for processing ordinary IPv6 unicast packets (unaware that the packet is an IPv6 unicast packet intended for multicast forwarding), send an Internet Control Message Protocol version 6 (ICMPv6) error message to R1, placing significant processing pressure on R1.

[0126] In particular, in a network that performs multicast forwarding based on IPv6 unicast addresses, the source IPv6 address remains unchanged during the multicast forwarding process, and in a scenario where the destination address is a unicast address, if the message is a forged message, for example, R1 sends a message to R3 with the hop limit field value of 2 and the source address forged as R1's IPv6 address, R35 and R36 will simultaneously send ICMPv6 error messages to R1. Since one forged message causes multiple ICMPv6 error messages, this will cause a denial of service (DoS) attack on R1.

[0127] For R35 and R36 that do not perform "multicast forwarding based on IPv6 unicast addresses", one possible scenario is that R35 and R36 are devices that do not support multicast forwarding based on unicast addresses as described above, and therefore, such devices must be traversed (or skipped) when generating the corresponding forwarding table. Another possible scenario is that R35 and R36 are devices that support multicast forwarding based on unicast addresses as described above, but traverse (or skip) such devices when generating the corresponding forwarding table to improve their forwarding performance. This application does not make specific restrictions on this.

[0128] Therefore, in the scenario of multicast forwarding based on IPv6 unicast addresses, how to avoid generating a large number of ICMPv6 error messages and improve the security of message forwarding has become an urgent problem that needs to be solved.

[0129] In view of this, an embodiment of the present application provides a method for sending an IPv6 message, which can set a threshold greater than or equal to 2 on a device that performs multicast forwarding based on an IPv6 unicast address. The device that supports multicast forwarding based on an IPv6 unicast address checks the value of the hop limit field of the message before forwarding the IPv6 message. If the hop limit of the message is less than or equal to the hop limit threshold on the device, and the inner user message is a multicast message (multicast messages include but are not limited to: IPv4 multicast messages or IPv6 multicast messages or etherent messages), forwarding of the IPv6 message is avoided. If the hop limit of the message is less than or equal to the threshold, and the inner user message is not a multicast message (for example, an OAM message), forwarding of messages whose rate exceeds the limited rate is avoided.

[0130] This, on the one hand, reduces the probability of IPv6 packets being sent to devices that forward unicast packets based on IPv6 unicast addresses, thereby reducing the probability of ICMPv6 error packets being generated on such devices. This improves the security of IPv6 packet forwarding and avoids the waste of network bandwidth and bandwidth of attacked devices caused by large numbers of ICMPv6 error packets. On the other hand, it is also possible to consider how to improve security while supporting OAM, or in other words, to improve data transmission security while ensuring that OAM detection functions are not affected.

[0131] It should be understood that in the present application, avoiding forwarding the IPv6 message can be considered as preventing the IPv6 message from being sent to the next hop device, or can also be considered as skipping the forwarding of the IPv6 message. In other words, avoiding forwarding the IPv6 message can be understood as not sending the IPv6 message to the next hop device.

[0132] It should be noted that the hoplimit threshold can be configured on one or more, or even all, devices in the network. For example, a network administrator can configure the hoplimit threshold on one or more, or even all, devices. These thresholds can be the same or different, and this embodiment of the application does not specifically limit this.

[0133] The following combination Figure 2 , a method for sending IPv6 packets provided in an embodiment of the present application is described in detail.

[0134] Figure 2 This is a schematic flow chart of a method for sending an IPv6 message provided in an embodiment of the present application. Figure 2 As shown, the method may include steps 210-230, and steps 210-230 are described in detail below.

[0135] Step 210: The first network device receives a first IPv6 message, where the first IPv6 message includes a message header and an inner message, and the message header includes a hop limit field.

[0136] The first IPv6 message can be an ordinary IPv6 message, or it can be a bit indexed explicit replication internet protocol version 6 (BIERv6) message based on the Internet Protocol version 6. The embodiment of the present application does not make any specific restrictions on this.

[0137] Step 220: The first network device determines whether the value of the hop limit field in the first IPv6 message is less than or equal to a preset threshold on the first network device, where the preset threshold is a number greater than or equal to 2.

[0138] The preset threshold configured on the first network device is a number greater than or equal to 2. The preset threshold may be a threshold determined based on the number of one or more consecutive second network devices connected to the first network device. The second network device is a network device that performs unicast forwarding based on the destination address of the IPv6 message received from the first network device, and the destination address of the IPv6 message received from the first network device is different from the address of the second network device.

[0139] As an example, a hop limit threshold may be configured on the first network device, and the threshold value is not less than the number of consecutive second network devices plus 1. The specific implementation method for determining the preset threshold configured on the first network device is described in detail below.

[0140] by Figure 1 In the scenario shown, R35 is a device that does not perform multicast forwarding based on IPv6 unicast addresses as described above. Both R3 and R5 are connected to R35, and the number of R35s connected to each is one. Therefore, the preset threshold number on R3 and R5 can be set to no less than 2.

[0141] Step 230: The first network device determines whether the inner message is a multicast message.

[0142] The multicast message in the embodiment of the present application includes but is not limited to any of the following: IPv6 multicast message, fourth edition Internet Protocol IPv4 multicast message, Ethernet message. For the specific implementation method of determining the type of the inner message, please refer to the description above and will not be repeated here.

[0143] Step 240: When the value of the hop limit field in the first IPv6 message is less than or equal to a preset threshold, and the inner message is a multicast message, the first network device avoids forwarding the first IPv6 message.

[0144] It should be understood that in the present application, avoiding forwarding the IPv6 message can be considered as preventing the IPv6 message from being sent to the next hop device, or can also be considered as skipping the forwarding of the IPv6 message. In other words, avoiding forwarding the IPv6 message can be understood as not sending the IPv6 message to the next hop device.

[0145] In the above technical solution, a threshold greater than or equal to 2 can be configured on a first network device (a device that supports multicast forwarding based on the unicast destination address of an IPv6 message). Before forwarding an IPv6 message, the first network device checks that the hop limit of the message is less than or equal to the threshold and avoids forwarding the IPv6 message. This reduces the probability of ICMPv6 error messages being generated due to an IPv6 hop limit value of 1 or 0, thereby improving the security of IPv6 message forwarding and avoiding the waste of network bandwidth and bandwidth of the attacked device caused by multiple or even large numbers of ICMPv6 error messages.

[0146] Optionally, in some embodiments, after the first network device avoids forwarding the IPv6 packet, the first network device may further discard the IPv6 packet.

[0147] Optionally, in some embodiments, the first network device determines that the value of the hop limit field in the IPv6 message is greater than a threshold, and the inner message is a multicast message, and the first network device may forward the IPv6 message.

[0148] In one example, if the first network device is an intermediate forwarding device, the first network device sends the IPv6 packet to the second network device, and the second network device forwards the second IPv6 packet to the third network device, and the destination address of the second IPv6 packet is the address of the third network device. Or

[0149] In another example, if the first network device is an egress device, the first network device decapsulates the IPv6 message and forwards the inner message obtained after decapsulating the IPv6 message.

[0150] Optionally, in some embodiments, the security of IPv6 message forwarding can be improved while considering how to support OAM, avoiding the waste of network bandwidth and bandwidth of the attacked device caused by multiple or even a large number of ICMPv6 error messages, or in other words, while improving the security of IPv6 message transmission, the OAM detection function can also be ensured to be unaffected. In this implementation, a possible IPv6 message format encapsulated by R1 is: outer IPv6 header + OAM message. Among them, the OAM message can be an IP-encapsulated OAM message, which includes an inner IPv6 header, a UDP header, and an OAM header. The inner IPv6 header, UDP header, and OAM header together constitute the Echo Request message described in the embodiment of the present application.

[0151] That is, in this embodiment, the Echo Request message itself includes an IPv6 header, a UDP header, and an OAM header, and the Echo Request message is encapsulated in an outer IPv6 header so that the Echo Request message will be forwarded point-to-multipoint (P2MP) according to the outer IPv6 header.

[0152] It should be understood that the destination address of the inner IPv6 header is a valid IPv6 address that can be recognized by the network device. Specifically, the valid IPv6 address that can be recognized can be any one in the range of 0:0:0:0:0:FFFF:7F00:0 / 104.

[0153] In one possible implementation, when the inner layer of the IPv6 message is an OAM message, if the transmission rate of the IPv6 message is greater than a preset rate, the first network device avoids forwarding the IPv6 message. Optionally, the first network device may also discard the IPv6 message.

[0154] In another possible implementation, when the inner multicast message of the IPv6 message is an OAM message, if the transmission rate of the IPv6 message is less than or equal to a preset rate, the first network device forwards the IPv6 message. It should be understood that the message transmission rate can be the number of messages transmitted per second (pps) or the number of bits per second (bps).

[0155] Below Figure 1 Take the configuration of the hop limit threshold on R3 as an example, combined with Figure 3 , a specific implementation process of the method for sending IPv6 packets provided in an embodiment of the present application is described in detail.

[0156] It should be understood that Figure 3The examples are only for helping those skilled in the art to understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to the specific numerical values ​​or specific scenarios illustrated. Figure 3 It is obvious that various equivalent modifications or changes can be made, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0157] Figure 3 This is a schematic flow chart of another method for sending an IPv6 message provided in an embodiment of the present application. Figure 3 As shown, the method may include steps 310-375, and steps 310-375 are described in detail below.

[0158] It should be understood that Figure 3 In this example, the hop limit threshold configured on R3 is 3.

[0159] Here is a possible scenario.

[0160] Step 310: R3 receives the encapsulated IPv6 message. In the outer IPv6 header of the encapsulated IPv6 message, the source address (SA) is R1, DA is R3, and the hop limit is 3. The user multicast message following the outer IPv6 header is an IPv4 multicast message.

[0161] Step 315: R3 avoids forwarding the IPv6 message in step 310.

[0162] R3 determines that the hop limit in the outer IPv6 header is equal to the threshold and that the user multicast message is an IPv4 multicast message. Therefore, R3 avoids forwarding the encapsulated IPv6 message. The specific method for determining user multicast messages is described above and is not repeated here.

[0163] It should be understood that in the present application, avoiding forwarding the encapsulated IPv6 message can be considered as preventing the encapsulated IPv6 message from being sent to the next hop device, or can also be considered as skipping the forwarding of the encapsulated IPv6 message. In other words, avoiding forwarding the encapsulated IPv6 message can be understood as not sending the encapsulated IPv6 message to the next hop device.

[0164] Optionally, in some embodiments, R3 may also discard the encapsulated IPv6 message.

[0165] Here is another possible scenario.

[0166] Step 320: R3 receives the encapsulated IPv6 message. In the outer IPv6 header of the encapsulated IPv6 message, SA=R1, DA=R3, hop limit=3, and the user multicast message following the outer IPv6 header is an IPv6 message.

[0167] Step 325: R3 avoids forwarding the IPv6 message in steps 320.

[0168] R3 determines that the hop limit in the outer IPv6 header is equal to the threshold and that the user multicast message is an IPv6 multicast message. Therefore, R3 avoids forwarding the encapsulated IPv6 message. The specific method for determining user multicast messages is described above and is not repeated here.

[0169] Optionally, in some embodiments, R3 may also discard the encapsulated IPv6 message.

[0170] Here is another possible scenario.

[0171] Step 330: R3 receives the encapsulated IPv6 message. In the outer IPv6 header of the encapsulated IPv6 message, SA=R1, DA=R3, hop limit=3, and the user multicast message following the outer IPv6 header is an etherent message.

[0172] Step 335: R3 avoids forwarding the IPv6 message in steps 330.

[0173] R3 determines that the hop limit in the outer IPv6 header is equal to the threshold and that the user multicast message is an Etherent message. Therefore, R3 avoids forwarding the encapsulated IPv6 message. The specific method for determining user multicast messages is described above and is not repeated here.

[0174] Optionally, in some embodiments, R3 may also discard the encapsulated IPv6 message.

[0175] Here is another possible scenario.

[0176] Step 340: R3 receives the encapsulated IPv6 message. In the outer IPv6 header of the encapsulated IPv6 message, SA=R1, DA=R3, hop limit=3, and the user multicast message following the outer IPv6 header is an OAM message.

[0177] Step 345: R3 forwards the IPv6 message whose transmission rate does not exceed the rate limit in step 340 to R6.

[0178] R3 determines that the hop limit in the outer IPv6 header is equal to the threshold and that the user multicast message is an OAM message. Therefore, it limits the rate of such messages to prevent forwarding of messages that exceed the rate limit. However, messages that do not exceed the rate limit are forwarded.

[0179] Specifically, in one possible implementation, R3 can determine that the user multicast message is an OAM message by excluding the possibility that the user multicast message is not an IPv4 multicast message, an IPv6 multicast message, or an Ethernet message. Based on the Next Header value of 41 in the outer IPv6 header, R3 can rule out the possibility that the user multicast message is an IPv4 multicast message or an Ethernet message, as these correspond to Next Header values ​​of 4 or 143, respectively. R3 can further check that the first 8 bits of the inner user multicast message's destination address are not equal to 0xff, or that the first 8 bits of the destination address are equal to 0, or that the first 104 bits of the destination address are 0:0:0:0:0:FFFF:7F00 (i.e., the destination address is an address in the 0:0:0:0:0:FFFF:7F00:0 / 104 address segment), thereby concluding that the inner user multicast message is not an IPv6 message.

[0180] If the user multicast message is an OAM message and the transmission rate does not exceed the rate limit, R3 forwards it to R5 along the P2MP path. The outer IPv6 header of the message sent to R5 contains: SA = R1, DA = R6, and hop limit = 2.

[0181] Step 350: R6 decapsulates the encapsulated IPv6 message received from step 350 and sends a response message to SA (SA=R1).

[0182] R6, as the egress node, decapsulates the IPv6 message and determines that the inner user multicast message is an OAM message. R6 sends a response message to the SA (SA=R1) in the outer IPv6 header.

[0183] As an example, the response message is an Echo Reply OAM message.

[0184] Step 355: R3 forwards the IPv6 message in step 340 whose transmission rate does not exceed the rate limit to R5.

[0185] If the user multicast message is an OAM message and the transmission rate does not exceed the rate limit, R3 forwards it to R6 along the P2MP path. The outer IPv6 header of the message sent to R6 contains: SA = R1, DA = R5, and hop limit = 2.

[0186] Step 360: R5 forwards the OAM multicast message with a hop limit of 2 received in step 355 to R7.

[0187] Assume that R5 does not have a hop limit threshold configured. It forwards an OAM multicast message with a hop limit of 2 to R7. The outer IPv6 header of the message sent to R7 contains: SA = R1, DA = R7, and hop limit = 1.

[0188] Step 365: R7 decapsulates the encapsulated IPv6 message received from step 360 and sends a response message to SA (SA=R1).

[0189] R7, as the egress node, decapsulates the IPv6 message and determines that the inner user multicast message is an OAM message. R7 sends a response message to the SA (SA=R1) in the outer IPv6 header.

[0190] Step 370: R5 forwards the OAM user multicast message with a hop limit of 2 received in step 355 to R8.

[0191] Assume that R5 does not have a hop limit threshold configured. It forwards an OAM multicast message with a hop limit of 2 to R8. The outer IPv6 header of the message sent to R8 contains: SA = R1, DA = R8, and hop limit = 1.

[0192] Step 475: R8 decapsulates the encapsulated IPv6 message received from step 370 and sends a response message to SA (SA=R1).

[0193] R8, as the egress node, decapsulates the IPv6 message and determines that the inner user multicast message is an OAM message. R8 sends a response message to the SA (SA=R1) in the outer IPv6 header.

[0194] In the above technical solution, for scenarios involving multicast data packet forwarding based on IPv6 unicast addresses, a hop limit threshold greater than or equal to 2 can be set on a device. During forwarding, if the forwarded message is a multicast data message and the message hop limit value is less than or equal to the threshold, forwarding is avoided. This prevents ICMPv6 error messages from being generated when the multicast data message is sent to some intermediate nodes, thereby reducing the possibility of network attacks. Normal multicast data packet forwarding will not be affected as long as the hop limit is not less than the set threshold. Furthermore, this application also considers support for OAM functions such as Ping or Traceroute. Since Ping / Traceroute generally does not require very high rates, for received messages with a hop limit less than or equal to the threshold but greater than 1, if the message is determined not to be a multicast data message, the message is forwarded at a limited rate, allowing the Ping / Traceroute function to function normally. At the same time, forwarding of messages exceeding the rate limit is avoided, preventing attackers from forging Ping / Traceroute messages or other non-multicast data messages and launching attacks.

[0195] In some embodiments, there are two hop limit transmission modes: Uniform mode and Pipe mode. Figure 4 and Figure 6 Provide a detailed description.

[0196] Below is Figure 1 In the example, the hop limit threshold is configured on R1. The hop limit transmission mode of R1 is Uniform mode. Figure 4 , a specific implementation process of the device in the embodiment of the present application performing multicast forwarding based on the IPv6 unicast address is described in detail.

[0197] It should be understood that Figure 4 The examples are only for helping those skilled in the art to understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to the specific numerical values ​​or specific scenarios illustrated. Figure 4 It is obvious that various equivalent modifications or changes can be made, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0198] Figure 4 This is a schematic flow chart of another method for sending an IPv6 message provided in an embodiment of the present application. Figure 4 As shown, the method may include steps 410-450, and steps 410-450 are described in detail below.

[0199] It should be understood that Figure 4 In this example, the hop limit threshold configured on R1 is 5 and the hop limit transmission mode of R1 is Uniform.

[0200] It should be noted that, for the convenience of description, Figure 4 The following uses IPv4 multicast data packets as an example. The same processing applies to IPv6 multicast data packets. The HL field in an IPv6 multicast data packet corresponds to the TTL field in an IPv4 multicast data packet.

[0201] Here is a possible scenario.

[0202] Step 410: R1 receives an IPv4 multicast data packet sent by customer edge device 1 (CE1), and the time to live (TTL) of the packet is 5.

[0203] Step 415: R1 avoids encapsulating the IPv4 multicast data message in step 410.

[0204] The TTL in the IPv4 multicast datagram corresponds to the hop limit in the IPv6 multicast datagram. The hop limit threshold configured on R1 is 5. The TTL of the IPv4 multicast datagram received by R1 is 5 (the TTL is equal to the hop limit threshold). Therefore, R1 avoids encapsulating the IPv4 multicast datagram and does not multicast forward the IPv4 multicast datagram.

[0205] Optionally, in some embodiments, R1 discards the IPv4 multicast data packet.

[0206] Here is another possible scenario.

[0207] Step 420: R1 receives the IPv4 multicast data packet sent by CE1, and the TTL of the packet is 4.

[0208] Step 425: R1 avoids encapsulating the IPv4 multicast data message in step 420.

[0209] The TTL in the IPv4 multicast data packet corresponds to the hop limit in the IPv6 multicast data packet. The hop limit threshold configured on R1 is 5. The TTL of the IPv4 multicast data packet received by R1 is 4 (the TTL is less than the hop limit threshold). Therefore, R1 avoids encapsulating the IPv4 multicast data packet and does not multicast forward the IPv4 multicast data packet.

[0210] Optionally, in some embodiments, R1 discards the IPv4 multicast data packet.

[0211] Here is another possible scenario.

[0212] Step 430: R1 receives an IPv4 multicast data packet sent by customer edge device 1 (CE1), and the time to live (TTL) of the packet is 6.

[0213] Step 435: R1 encapsulates the IPv4 multicast data packet with a TTL of 6 in step 430 and sends it to R3.

[0214] The TTL in the IPv4 multicast data packet corresponds to the hop limit in the IPv6 multicast data packet. The hop limit threshold configured on R1 is 5. The TTL is greater than the hop limit threshold. Therefore, R1 encapsulates the IPv4 multicast data packet and sends it to R3.

[0215] For example, R1 encapsulates an IPv4 multicast data packet with an outer IPv6 header. Using uniform mode, the TTL value of the IPv4 multicast data packet is decremented by one, and the decremented TTL value is used as the hop limit field value in the outer IPv6 header. Therefore, in the outer IPv6 header of the IPv6 packet sent from R1 to R3, SA = R1, DA = R3, and hop limit = 5. The TTL value of the inner IPv4 multicast data packet is 5.

[0216] Step 440: R3 sends the encapsulated IPv6 packet to R5.

[0217] In the outer IPv6 header of the IPv6 packet sent from R3 to R5, SA = R1, DA = R5, hop limit = 4, and the TTL of the inner IPv4 multicast data packet = 5.

[0218] Step 445: R5 sends the IPv6 packet to R7.

[0219] In the outer IPv6 header of the IPv6 packet sent from R5 to R7, SA = R1, DA = R7, hop limit = 3, and the TTL of the inner IPv4 multicast data packet = 5.

[0220] Step 450: R7 sends the inner IPv4 multicast data packet to CE2.

[0221] In the outer IPv6 header of the IPv6 packet received by R7, SA = R1, DA = R7, and hop limit = 3. The TTL of the inner IPv4 multicast data packet is 5. Assuming R7's hop limit transmission mode is Uniform, R7 decrements the HL value by 1 and assigns it to the TTL of the inner IPv4 multicast data packet. Therefore, the TTL value of the IPv4 multicast data packet sent by R7 to CE2 is 2.

[0222] Below is Figure 1 The hop limit threshold is configured on multiple devices in the process. For example, the hop limit transmission mode of R1 is Uniform mode. Figure 5 , a specific implementation process of the device in the embodiment of the present application performing multicast forwarding based on the IPv6 unicast address is described in detail.

[0223] It should be understood that Figure 5 The examples are only for helping those skilled in the art to understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to the specific numerical values ​​or specific scenarios illustrated. Figure 5 It is obvious that various equivalent modifications or changes can be made, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0224] Figure 5 This is a schematic flow chart of another method for sending an IPv6 message provided in an embodiment of the present application. Figure 5 As shown, the method may include steps 510-565, and steps 510-565 are described in detail below.

[0225] It should be understood that Figure 5 In this example, the hop limit threshold set on R1 is 5, the hop limit transmission mode of R1 is Uniform mode, and the hop limit thresholds of other devices R3 / R5 / R7 / R8 are also set.

[0226] It should be noted that the hop limit thresholds set on each device R3 / R5 / R7 / R8 can be the same or different. Figure 5 In this example, the hop limit threshold set on R3 / R5 / R7 / R8 is 3.

[0227] The following is a possible scenario: R1 initiates the first round of detection and constructs an Echo Request OAM message using HL=1.

[0228] Step 510: R1 sends the encapsulated IPv6 message to R3. The inner layer of the IPv6 message is an OAM message.

[0229] In the outer IPv6 header of the IPv6 packet constructed by R1, SA = R1, DA = R3, and hop limit = 1. Although hop limit = 1 is lower than the hop limit threshold configured on R1 (threshold = 5), R1 forwards the inner user multicast packet at a limited rate because it is an OAM packet. If the rate is within the limited range, the packet is forwarded to R3.

[0230] Step 615: R3 feeds back a response message to R1.

[0231] In the outer IPv6 header of the IPv6 packet received by R3 from R1, SA = R1, DA = R3, and hop limit = 1, and the inner user multicast message is an OAM message. Because the hop limit is 1 and the inner user multicast message is an OAM message, R3 sends a response message to the SA in the outer IPv6 header (SA = R1) and does not forward it to R5 or R6. This concludes the first round of detection.

[0232] As an example, the response message is an Echo Reply OAM message.

[0233] The following is another possible scenario: R1 initiates a second round of detection and constructs an Echo Request OAM message using HL=2.

[0234] Step 520: R1 sends the encapsulated IPv6 message to R3. The inner layer of the IPv6 message is an OAM message.

[0235] In the outer IPv6 header of the IPv6 packet sent from R1 to R3, SA = R1, DA = R3, hop limit = 2, and the inner user multicast packet is an OAM packet.

[0236] Step 525: R3 sends the encapsulated IPv6 message to R5. The inner layer of the IPv6 message is an OAM message.

[0237] In the outer IPv6 header of the IPv6 packet sent by R3 to R5, SA = R1, DA = R5, and hop limit = 2. The inner user multicast packet is an OAM packet. Although hop limit = 1 is lower than the hop limit threshold configured on R3 (threshold = 3), R3 forwards the inner user multicast packet at a limited rate because it is an OAM packet. If the rate is within the limited range, the packet is forwarded to R5.

[0238] Step 530: R5 feeds back a response message to R1.

[0239] The IPv6 packet R5 receives from R3 has a hop limit of 1 in the outer IPv6 header, and the inner user multicast message is an OAM message. Although the hop limit threshold configured on R3 is 3, R5 does not directly discard the message because it is an OAM message. Furthermore, because the hop limit in the outer IPv6 header is 1, R5 sends a response message to the SA in the outer IPv6 header (SA = R1) and does not forward it to R7 or R8. This concludes the second round of detection.

[0240] Step 533: R3 sends the encapsulated IPv6 message to R6. The inner layer of the IPv6 message is an OAM message.

[0241] In the outer IPv6 header of the IPv6 packet sent by R3 to R6, SA = R1, DA = R6, and hop limit = 2. The inner user multicast packet is an OAM packet. Although hop limit = 1 is lower than the hop limit threshold configured on R3 (threshold = 3), R3 forwards the inner user multicast packet at a limited rate because it is an OAM packet. If the rate is within the limited range, the packet is forwarded to R6.

[0242] Step 535: R6 feeds back a response message to R1.

[0243] Since R6 is the egress node, the hop limit received by R6 is 1. Therefore, R6 sends a response message to the SA (SA=R1) in the outer IPv6 header. The second round of detection ends.

[0244] Another possible scenario is as follows: R1 initiates a second round of detection and constructs an Echo Request OAM message using HL=3.

[0245] Step 540: R1 sends the encapsulated IPv6 message to R3. The inner layer of the IPv6 message is an OAM message.

[0246] In the outer IPv6 header of the IPv6 packet sent from R1 to R3, SA = R1, DA = R3, hop limit = 3, and the inner user multicast packet is an OAM packet.

[0247] Step 545: R3 sends the encapsulated IPv6 message to R6. The inner layer of the IPv6 message is an OAM message.

[0248] In the outer IPv6 header of the IPv6 packet sent by R3 to R6, SA = R1, DA = R6, hop limit = 2, and the inner user multicast packet is an OAM packet.

[0249] Step 548: R6 feeds back a response message to R1.

[0250] The outer IPv6 header of the IPv6 packet R6 receives from R3 contains a hop limit of 2, and the inner user multicast message is an OAM message. Although the hop limit threshold configured on R6 is 3, R6 does not directly discard the message because it is an OAM message. Because R6 is the egress node, it sends a response message to the SA in the outer IPv6 header (SA = R1). This concludes the third round of detection.

[0251] Step 550: In the outer IPv6 header of the IPv6 message sent by R3 to R5, SA=R1, DA=R5, hop limit=2, and the inner user multicast message is an OAM message.

[0252] Step 555: R5 sends the encapsulated IPv6 message to R8. The inner layer of the IPv6 message is an OAM message.

[0253] In the outer IPv6 header of the IPv6 packet sent by R5 to R8, SA = R1, DA = R8, hop limit = 1, and the inner user multicast packet is an OAM packet.

[0254] Step 558: R8 feeds back a response message to R1.

[0255] Because R8 is the egress node, R8 will send a response message to the SA (SA=R1) in the outer IPv6 header. The third round of detection ends. Please refer to the description in step 660 for details, which will not be repeated here.

[0256] Step 560: R5 sends the encapsulated IPv6 message to R7. The inner layer of the IPv6 message is an OAM message.

[0257] In the outer IPv6 header of the IPv6 packet sent from R5 to R7, SA = R1, DA = R7, hop limit = 1, and the inner user multicast packet is an OAM packet.

[0258] Step 565: R7 feeds back a response message to R1.

[0259] The outer IPv6 header of the IPv6 packet R7 receives from R5 contains a hop limit of 1, and the inner user multicast message is an OAM message. Although the hop limit threshold configured on R7 is 3, R7 does not directly discard the message because it is an OAM message. Furthermore, because the outer IPv6 header contains a hop limit of 1, R7 sends a response message (7) to the SA (SA = R1) in the outer IPv6 header. This concludes the third round of detection.

[0260] Below is Figure 1 The hop limit threshold is set on R1 in the example. For example, the hop limit transmission mode of R1 is Pipe mode. Figure 6 , a specific implementation process of the device in the embodiment of the present application performing multicast forwarding based on the IPv6 unicast address is described in detail.

[0261] It should be understood that Figure 6 The examples are only for helping those skilled in the art to understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to the specific numerical values ​​or specific scenarios illustrated. Figure 6 It is obvious that various equivalent modifications or changes can be made, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0262] Figure 6 This is a schematic flow chart of another method for sending an IPv6 message provided in an embodiment of the present application. Figure 6 As shown, the method may include steps 610-685, and steps 610-685 are described in detail below.

[0263] It should be understood that Figure 6 In this example, the hop limit threshold set on R1 is 5.

[0264] It should be noted that, for the convenience of description, Figure 6 The following uses IPv4 multicast data packets as an example. The same process is used for IPv6 multicast data packets. The HL field of the IPv6 multicast data packet corresponds to the TTL of the IPv4 multicast data packet.

[0265] Here is a possible scenario.

[0266] Step 610: R1 receives an IPv4 multicast data packet sent by CE1, and the time to live (TTL) of the packet is 6.

[0267] Step 615: R1 encapsulates the IPv4 multicast data packet in step 610 and forwards it to R3.

[0268] The TTL in the IPv4 multicast data packet corresponds to the hop limit in the IPv6 multicast data packet. The hop limit threshold configured on R1 is 5. The TTL of the IPv4 multicast data packet received by R1 is 6 (the TTL is greater than the hop limit threshold). Therefore, R1 can encapsulate the IPv4 multicast data packet and forward it to R3.

[0269] Specifically, during forwarding, R1 encapsulates the IPv4 multicast data packet with an outer IPv6 header according to Pipe processing. The hop limit of the outer IPv6 header is set to 255. Therefore, in the outer IPv6 header of the IPv6 packet sent by R1 to R3, SA = R1, DA = R3, hop limit = 255, and the TTL of the inner IPv4 multicast data packet is 5.

[0270] Step 620: R3 forwards the message received from R1 to R5.

[0271] In the outer IPv6 header of the IPv6 packet sent from R3 to R5, SA = R1, DA = R5, hop limit = 254, and the TTL of the inner IPv4 multicast data packet = 5.

[0272] Step 625: R5 forwards the message received from R3 to R7.

[0273] In the outer IPv6 header of the IPv6 packet sent from R5 to R7, SA = R1, DA = R7, hop limit = 253, and the TTL of the inner IPv4 multicast data packet = 5.

[0274] Step 630: R7 sends the inner IPv4 multicast data packet to CE2.

[0275] In the outer IPv6 header of the IPv6 packet received by R7, SA = R1, DA = R7, hop limit = 253, and the TTL field of the inner IPv4 multicast data packet = 5. Assuming that R7's hop limit transmission mode is Pipe mode, R7 strips off the outer IPv6 header and decrements the TTL field of the inner IPv4 multicast data packet by 1. Therefore, the TTL value of the packet sent by R7 to CE2 is 4.

[0276] Here is another possible scenario.

[0277] Step 640: R1 receives the IPv4 multicast data packet sent by CE1, and the time to live (TTL) of the packet is 5.

[0278] Step 645: R1 encapsulates the IPv4 multicast data packet in step 640 and forwards it to R3.

[0279] The TTL in the IPv4 multicast data packet corresponds to the hop limit in the IPv6 multicast data packet. The hop limit threshold configured on R1 is 5. The TTL of the IPv4 multicast data packet received by R1 is 5 (the TTL is equal to the hop limit threshold). R1 ​​can encapsulate the IPv4 multicast data packet according to the Pipe processing and forward it to R3.

[0280] Specifically, during forwarding, R1 encapsulates the IPv4 multicast data packet with an outer IPv6 header according to Pipe processing, with the hop limit of the outer IPv6 header set to 255. Therefore, in the outer IPv6 header of the IPv6 packet sent by R1 to R3, SA = R1, DA = R3, hop limit = 255, and the TTL of the inner IPv4 multicast data packet = 4.

[0281] Step 650: R3 forwards the message received from R1 to R5.

[0282] In the outer IPv6 header of the IPv6 packet sent from R3 to R5, SA = R1, DA = R5, hop limit = 254, and the TTL of the inner IPv4 multicast data packet = 4.

[0283] Step 655: R5 forwards the message received from R3 to R7.

[0284] In the outer IPv6 header of the IPv6 packet sent from R5 to R7, SA = R1, DA = R7, hop limit = 253, and the TTL of the inner IPv4 multicast data packet = 4.

[0285] Step 660: R7 sends the inner IPv4 multicast data packet to CE2.

[0286] In the outer IPv6 header of the IPv6 packet received by R7, SA = R1, DA = R7, hop limit = 253, and the TTL field of the inner IPv4 multicast data packet is 4. Assuming that R7's hop limit transmission mode is Pipe mode, R7 strips off the outer IPv6 header and decrements the TTL field of the inner IPv4 multicast data packet by 1. Therefore, the TTL value of the packet sent by R7 to CE2 is 3.

[0287] Here is another possible scenario.

[0288] Step 665: R1 receives the IPv4 multicast data packet sent by CE1, and the time to live (TTL) of the packet is 4.

[0289] Step 670: R1 encapsulates the IPv4 multicast data packet in step 665 and forwards it to R3.

[0290] The TTL in the IPv4 multicast data packet corresponds to the hop limit in the IPv6 multicast data packet. The hop limit threshold configured on R1 is 4. The TTL of the IPv4 multicast data packet received by R1 is 5 (the TTL is less than the hop limit threshold). According to the Pipe processing, R1 can encapsulate the IPv4 multicast data packet and forward it to R3.

[0291] Specifically, during forwarding, R1 encapsulates the IPv4 multicast data packet with an outer IPv6 header according to Pipe processing. The hop limit of the outer IPv6 header is set to 255. Therefore, in the outer IPv6 header of the IPv6 packet sent by R1 to R3, SA = R1, DA = R3, hop limit = 255, and the TTL of the inner IPv4 multicast data packet is 3.

[0292] Step 675: R3 forwards the message received from R1 to R5.

[0293] In the outer IPv6 header of the IPv6 packet sent from R3 to R5, SA = R1, DA = R5, hop limit = 254, and the TTL of the inner IPv4 multicast data packet = 3.

[0294] Step 680: R5 forwards the message received from R3 to R7.

[0295] In the outer IPv6 header of the IPv6 packet sent from R5 to R7, SA = R1, DA = R7, hop limit = 253, and the TTL of the inner IPv4 multicast data packet = 3.

[0296] Step 685: R7 sends the inner IPv4 multicast data packet to CE2.

[0297] In the outer IPv6 header of the IPv6 packet received by R7, SA = R1, DA = R7, hop limit = 253, and the TTL field of the inner IPv4 multicast data packet = 3. Assuming that R7's hop limit transmission mode is Pipe mode, R7 strips off the outer IPv6 header and decrements the TTL field of the inner IPv4 multicast data packet by 1. Therefore, the TTL value of the packet sent by R7 to CE2 is 2.

[0298] Combined with the above Figures 1 to 6 , describes in detail a method for sending a Pv6 message provided by an embodiment of the present application, and will be combined with Figures 7 to 9 , the embodiments of the device of the present application are described in detail. It should be understood that the description of the method embodiment corresponds to the description of the device embodiment, so for parts not described in detail, reference can be made to the previous method embodiment.

[0299] Figure 7 It is a schematic structural diagram of a first network device 700 provided in an embodiment of the present application. Figure 7 The first network device 700 shown in FIG. 1 can execute the corresponding steps executed by the first network device in the method of the above embodiment. Figure 7 As shown, the first network device 700 includes: a receiving module 710, a processing module 720,

[0300] The receiving module 710 is configured to receive a first IPv6 packet, where the first IPv6 packet includes a packet header and an inner packet, where the packet header includes a hop limit field;

[0301] a processing module 720 configured to determine whether a value of the hop limit field in the first IPv6 packet is less than or equal to a preset threshold on the first network device, wherein the preset threshold is a number greater than or equal to 2;

[0302] The processing module 720 is further configured to determine whether the inner layer message is a multicast message;

[0303] The processing module 720 is further configured to avoid forwarding the first IPv6 message when the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold and the inner message is the multicast message.

[0304] Optionally, the processing module 720 is further configured to discard the first IPv6 packet.

[0305] Optionally, the preset threshold is a threshold determined based on the number of one or more consecutive second network devices connected to the first network device, and the second network device is a network device that performs unicast forwarding based on the destination address of the IPv6 message received from the first network device, and the destination address of the IPv6 message received from the first network device is different from the address of the second network device.

[0306] Optionally, the receiving module 710 is further configured to: receive a second IPv6 packet, where the second IPv6 packet includes a packet header and an inner packet, and the packet header includes a hop limit field;

[0307] The processing module 720 is further configured to determine whether the value of the hop limit field in the second IPv6 message is less than or equal to the preset threshold;

[0308] The processing module 720 is further configured to determine whether the inner packet of the second IPv6 packet is the multicast packet;

[0309] The processing module 720 is further configured to process the second IPv6 packet when the value of the hop limit field in the second IPv6 packet is greater than the preset threshold and the inner packet of the second IPv6 packet is the multicast packet.

[0310] Optionally, the processing module 720 is specifically used to: if the first network device is an intermediate forwarding device, send the second IPv6 message to the second network device, and the second network device forwards the second IPv6 message to the third network device, and the destination address of the second IPv6 message is the address of the third network device; or if the first network device is an export device, decapsulate the second IPv6 message and forward the inner layer message obtained after decapsulating the second IPv6 message.

[0311] Optionally, the multicast message includes any one of the following: an IPv6 multicast message, an Internet Protocol version 4 (IPv4) multicast message, or an Ethernet message.

[0312] Optionally, the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the processing module is also used to: when the inner layer message of the first IPv6 message is an operation, maintenance and management OAM message, if the transmission rate of the first IPv6 message is greater than the preset rate, avoid forwarding the IPv6 message.

[0313] Optionally, the processing module 720 is further configured to discard the first IPv6 packet.

[0314] Optionally, the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the processing module is also used to: when the inner multicast message is an OAM message, if the transmission rate of the first IPv6 message is less than or equal to the preset rate, forward the first IPv6 message.

[0315] Figure 8 It is a hardware structure diagram of the first network device 2000 according to an embodiment of the present application. Figure 8 The first network device 2000 shown can execute the corresponding steps executed by the first network device in the method of the above embodiment.

[0316] like Figure 8 As shown, the first network device 2000 includes a processor 2001, a memory 2002, an interface 2003, and a bus 2004. The interface 2003 can be implemented wirelessly or wired, and can be a network card. The processor 2001, the memory 2002, and the interface 2003 are connected via the bus 2004.

[0317] The interface 2003 may specifically include a transmitter and a receiver, which are used by the first network device to implement the above-mentioned transmission and reception. For example, the interface 2003 is used to receive IPv6 packets.

[0318] The processor 2001 is used to execute the processing performed by the first network device in the above-mentioned embodiment. For example, it is used to determine whether the value of the hop limit field in the first IPv6 message is less than or equal to a preset threshold on the first network device; it is also used to determine whether the inner layer message is a multicast message; it is also used to avoid forwarding the first IPv6 message by the first network device when the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold and the inner layer message is the multicast message; and / or other processes of the technology described herein. The memory 2002 includes an operating system 20021 and an application 20022, which is used to store programs, codes or instructions. When the processor or hardware device executes these programs, codes or instructions, the processing process involving the first network device in the method embodiment can be completed. Optionally, the memory 2002 may include read-only memory (ROM) and random access memory (RAM). The ROM includes a basic input / output system (BIOS) or an embedded system; the RAM includes an application and an operating system. When the first network device 2000 needs to be operated, it is started by the BIOS stored in the ROM or the bootloader in the embedded system, and the first network device 2000 is guided into a normal operating state. After the first network device 2000 enters the normal operating state, the application program and operating system stored in the RAM are run, thereby completing the processing process involving the first network device 2000 in the method embodiment.

[0319] It is understandable that Figure 8 Only a simplified design of the first network device 2000 is shown. In actual applications, the first network device may include any number of interfaces, processors or memories.

[0320] Figure 9This is a schematic diagram of the hardware structure of another first network device 2100 according to an embodiment of the present application. Figure 9 The first network device 2100 shown can execute the corresponding steps executed by the first network device in the method of the above embodiment.

[0321] like Figure 9 The first network device 2100 includes a main control board 2110, an interface board 2130, a switching network board 2120, and an interface board 2140. The main control board 2110, interface boards 2130 and 2140, and the switching network board 2120 are interconnected via a system bus and a system backplane. The main control board 2110 is used to perform functions such as system management, device maintenance, and protocol processing. The switching network board 2120 is used to exchange data between the interface boards (also known as line cards or service boards). The interface boards 2130 and 2140 are used to provide various service interfaces (e.g., POS interfaces, GE interfaces, ATM interfaces, etc.) and implement data packet forwarding.

[0322] Interface board 2130 includes a central processing unit (CPU) 2131, a forwarding table entry memory 2134, a physical interface card 2133, and a network processor 2132. CPU 2131 controls and manages the interface board and communicates with the CPU on the main control board. Forwarding table entry memory 2134 stores table entries. Physical interface card 2133 receives and sends traffic.

[0323] It should be understood that the operations on the interface board 2140 in the embodiment of the present application are consistent with the operations of the interface board 2130, and for the sake of brevity, they will not be repeated.

[0324] It should be understood that the first network device 2100 of this embodiment may correspond to the functions and / or various steps implemented in the above method embodiment, which will not be described in detail here.

[0325] Additionally, it should be noted that there may be one or more main control boards, and when there are multiple boards, they may include a primary main control board and a backup main control board. There may be one or more interface boards. The stronger the data processing capabilities of the first network device, the more interface boards are provided. The interface board may also have one or more physical interface cards. There may be no switching network board, or one or more. When there are multiple switching network boards, they can collectively implement load balancing and redundant backup. In a centralized forwarding architecture, the first network device may not require a switching network board; the interface board handles the service data processing function for the entire system. In a distributed forwarding architecture, the first network device may have at least one switching network board, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a first network device with a distributed architecture are greater than those of a device with a centralized architecture. The specific architecture to be adopted depends on the specific network deployment scenario and is not limited here.

[0326] The present application also provides a computer-readable medium storing program code, which, when executed on a computer, causes the computer to execute the method executed by the first network device. Such computer-readable storage includes, but is not limited to, one or more of the following: read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), Flash memory, electrically EPROM (EEPROM), and hard drive.

[0327] An embodiment of the present application also provides a chip system, which is applied to a first network device. The chip system includes: at least one processor, at least one memory and an interface circuit, wherein the interface circuit is responsible for information interaction between the chip system and the outside world, the at least one memory, the interface circuit and the at least one processor are interconnected through lines, and instructions are stored in the at least one memory; the instructions are executed by the at least one processor to perform the operations of the first network device in the methods described in the above aspects.

[0328] In the specific implementation process, the chip can be implemented in the form of a central processing unit (CPU), a micro controller unit (MCU), a micro processing unit (MPU), a digital signal processor (DSP), a system on chip (SoC), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a programmable logic device (PLD).

[0329] An embodiment of the present application further provides a computer program product, which is applied to a first network device. The computer program product includes a series of instructions. When the instructions are executed, the operations of the first network device in the methods described in the above aspects are performed.

[0330] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0331] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0332] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0333] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0334] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0335] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0336] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0337] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for sending an IPv6 message, characterized in that: The method comprises: The first network device receives a first IPv6 message, where the first IPv6 message includes a message header and an inner message, the message header includes a hop limit field, and the destination address of the message header is a unicast address; The first network device determines whether a value of the hop limit field in the first IPv6 packet is less than or equal to a preset threshold on the first network device, wherein the preset threshold is a number greater than or equal to 2; The first network device determines whether the inner layer message is a multicast message; When the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the inner message is the multicast message, the first network device avoids forwarding the first IPv6 message.

2. The method according to claim 1, characterized in that The method further comprises: The first network device discards the first IPv6 packet.

3. The method according to claim 1, characterized in that The preset threshold is a threshold determined based on the number of one or more consecutive second network devices connected to the first network device, the second network device is a network device that performs unicast forwarding based on the destination address of the IPv6 message received from the first network device, and the destination address of the IPv6 message received from the first network device is different from the address of the second network device.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: The first network device receives a second IPv6 packet, where the second IPv6 packet includes a packet header and an inner packet, and the packet header includes a hop limit field; Determining, by the first network device, whether a value of the hop limit field in the second IPv6 packet is less than or equal to the preset threshold; Determining, by the first network device, whether an inner packet of the second IPv6 packet is the multicast packet; When the value of the hop limit field in the second IPv6 message is greater than the preset threshold, and the inner message of the second IPv6 message is the multicast message, the first network device processes the second IPv6 message.

5. The method according to claim 4, characterized in that The first network device processes the second IPv6 message, including: If the first network device is an intermediate forwarding device, the first network device sends the second IPv6 packet to the second network device, and the second network device forwards the second IPv6 packet to the third network device, and the destination address of the second IPv6 packet is the address of the third network device; or If the first network device is an egress device, the first network device decapsulates the second IPv6 message and forwards the inner message obtained after decapsulating the second IPv6 message.

6. The method according to any one of claims 1 to 3, characterized in that The multicast message includes any one of the following: IPv6 multicast message, fourth edition Internet Protocol IPv4 multicast message, Ethernet message.

7. The method according to any one of claims 1 to 3, characterized in that The value of the hoplimit field in the first IPv6 message is less than or equal to the preset threshold, and the method further includes: When the inner layer message of the first IPv6 message is an operation, maintenance and management (OAM) message, and if the transmission rate of the first IPv6 message is greater than a preset rate, the first network device avoids forwarding the IPv6 message.

8. The method according to claim 7, characterized in that The method further comprises: The first network device discards the first IPv6 packet.

9. The method according to claim 7, characterized in that The value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, and the method further includes: When the inner layer message is an OAM message, if the transmission rate of the first IPv6 message is less than or equal to the preset rate, the first network device forwards the first IPv6 message.

10. A first network device, characterized in that: include: a receiving module, configured to receive a first IPv6 message, wherein the first IPv6 message includes a message header and an inner message, the message header includes a hop limit field, and the destination address of the message header is a unicast address; a processing module, configured to determine whether a value of the hop limit field in the first IPv6 packet is less than or equal to a preset threshold on the first network device, wherein the preset threshold is a number greater than or equal to 2; The processing module is further configured to determine whether the inner layer message is a multicast message; The processing module is further configured to avoid forwarding the first IPv6 message when the value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold and the inner message is the multicast message.

11. The first network device according to claim 10, characterized in that The processing module is further configured to: The first IPv6 packet is discarded.

12. The first network device according to claim 10, characterized in that The preset threshold is a threshold determined based on the number of one or more consecutive second network devices connected to the first network device, the second network device is a network device that performs unicast forwarding based on the destination address of the IPv6 message received from the first network device, and the destination address of the IPv6 message received from the first network device is different from the address of the second network device.

13. The first network device according to any one of claims 10 to 12, characterized in that: The receiving module is further configured to receive a second IPv6 message, wherein the second IPv6 message includes a message header and an inner message, wherein the message header includes a hop limit field; The processing module is further configured to determine whether a value of the hop limit field in the second IPv6 message is less than or equal to the preset threshold; The processing module is further configured to determine whether the inner packet of the second IPv6 packet is the multicast packet; The processing module is further configured to process the second IPv6 message when the value of the hop limit field in the second IPv6 message is greater than the preset threshold and the inner message of the second IPv6 message is the multicast message.

14. The first network device according to claim 13, characterized in that: The processing module is specifically used for: If the first network device is an intermediate forwarding device, the second IPv6 packet is sent to the second network device, and the second network device forwards the second IPv6 packet to the third network device, where the destination address of the second IPv6 packet is the address of the third network device; or If the first network device is an egress device, the second IPv6 message is decapsulated, and the inner message obtained after the second IPv6 message is decapsulated is forwarded.

15. The first network device according to any one of claims 10 to 12, characterized in that: The multicast message includes any one of the following: IPv6 multicast message, fourth edition Internet Protocol IPv4 multicast message, Ethernet message.

16. The first network device according to any one of claims 10 to 12, characterized in that: The value of the hop limit field in the first IPv6 message is less than or equal to the preset threshold, The processing module is further configured to: when the inner layer message of the first IPv6 message is an operation, maintenance and management (OAM) message, and if the transmission rate of the first IPv6 message is greater than a preset rate, avoid forwarding the IPv6 message.

17. The first network device according to claim 16, characterized in that The processing module is further configured to: The first IPv6 packet is discarded.

18. The first network device according to claim 16, characterized in that The value of the hoplimit field in the first IPv6 message is less than or equal to the preset threshold, The processing module is further configured to: when the inner layer message is an OAM message, if the transmission rate of the first IPv6 message is less than or equal to the preset rate, forward the first IPv6 message.

19. A first network device, characterized in that: include: A processor and a memory, the memory being used to store a program, and the processor being used to call and run the program from the memory to execute the method according to any one of claims 1 to 9.

20. A system for sending Internet Protocol version 6 (IPv6) packets, comprising the first network device according to any one of claims 10 to 18.

21. A computer-readable storage medium, characterized in that The invention comprises a computer program which, when run on a computer, causes the computer to execute the method according to any one of claims 1 to 9.