Unicast Packet Processing Method, Apparatus, Computer Device, and Readable Medium

By configuring policies in the access control list ACL, unicast messages are processed according to the URPF mode type, the problem of URPF checking occupies the routing table resources, simplifying the message forwarding process and improving forwarding efficiency.

CN114124816BActive Publication Date: 2025-07-08SANECHIPS TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202010886294.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-28
Publication Date
2025-07-08
Estimated Expiration
2040-08-28

AI Technical Summary

Technical Problem

In the prior art, URPF checking, when the routing table resources are limited, leads to a reduction in the destination IP address entries, affects the message forwarding service, and the message forwarding process is complicated under strict mode.

Method used

By configuring policies in the access control list ACL, obtaining policies according to URPF mode type, using incoming interfaces and source IP addresses to process unicast messages, reducing dependence on routing tables and simplifying the forwarding process.

Benefits of technology

Reduces the resource consumption of routing tables, simplifies the message forwarding process in URPF mode, and improves forwarding efficiency. In particular, the step of finding the next hop index is omitted in strict mode.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114124816B_ABST
    Figure CN114124816B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method for processing unicast packets. The method includes: receiving a unicast packet and obtaining the source IP address carried therein; determining the ingress interface of the unicast packet; if the URPF mode of the ingress interface is enabled, obtaining a preset policy in the ACL according to the enabled URPF mode type, and processing the unicast packet according to the source IP address, the ingress interface, and the policy. In the embodiments of the present disclosure, the ingress interface of the unicast packet and the URPF mode type are taken as considerations for packet forwarding. In this way, there is no need to store the source IP address information in the routing table, which will not occupy the resources of the routing table, reduce the consumption of routing table resources, and simplify the packet forwarding process under the URPF mode. In the strict mode, the step of looking up the next-hop index according to the source IP address can be omitted when forwarding packets, saving a table lookup process and improving the packet forwarding efficiency. The present disclosure also provides a unicast packet processing device, a computer device, and a readable medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technologies, and in particular, to a method, apparatus, computer device, and readable medium for processing unicast packets. Background Art

[0002] The rapid development of IP (Internet Protocol) technology has greatly enriched people's material and cultural lives, and the level of network development has also become an important symbol to measure a country's strength and modernization level. At the same time, the advantages of IP networks such as openness and ease of operation have also introduced various risks. A common network attack method is that an attacker uses the method of changing the source IP address to achieve the purpose of attacking other devices, that is, source IP address spoofing.

[0003] In response to source IP address spoofing, a defense technology has emerged: Unicast Reverse Path Forwarding (URPF). This technology performs a table entry lookup on the source IP address of the unicast packet entering the device to confirm the existence of the entry. More strictly, while confirming the existence of the entry, it also checks whether the entry port of the packet is correct. If the check passes, the packet is forwarded; if the check fails, the packet is discarded.

[0004] The implementation of URPF check requires adding source IP address entries to the routing table. However, in actual engineering applications, the resources of the routing table are limited, and the source IP address and the destination IP address share this storage space. The increase in source IP address entries will lead to a decrease in destination IP address entries, thereby affecting the packet forwarding service. And in strict mode, another table entry needs to be looked up through the next-hop index obtained from the source IP, and it is also necessary to compare whether the ingress interface meets the expectation, so the packet forwarding process is complex. Summary of the Invention

[0005] In view of the above deficiencies in the prior art, the present disclosure provides a method, apparatus, computer device, and readable medium for processing unicast packets.

[0006] In a first aspect, an embodiment of the present disclosure provides a method for processing unicast packets, including:

[0007] Receiving a unicast packet and obtaining the source Internet Protocol (IP) address carried therein;

[0008] Determining the ingress interface of the unicast packet;

[0009] If the Unicast Reverse Path Forwarding (URPF) mode of the ingress interface is enabled, obtaining a preset policy in the Access Control List (ACL) according to the enabled URPF mode type;

[0010] Process the unicast packet according to the source IP address, the ingress interface, and the policy.

[0011] In some embodiments, after receiving the unicast packet and before determining the ingress interface of the unicast packet, the method further includes: obtaining the destination IP address carried in the unicast packet;

[0012] The processing of the unicast packet includes: determining an egress interface according to the destination IP address and a routing table, and forwarding the unicast packet according to the egress interface.

[0013] In some embodiments, the determining the policy preset in the access control list (ACL) according to the enabled URPF mode type includes: if the enabled URPF mode type is the loose mode, obtaining a first policy and a second policy preset in the ACL and corresponding to the loose mode;

[0014] The first policy includes matching the source IP address and the ingress interface; the second policy includes matching the ingress interface and not matching the source IP address.

[0015] In some embodiments, the processing of the unicast packet according to the source IP address, the ingress interface, and the policy includes:

[0016] If the source IP address and the ingress interface satisfy the first policy, or, the source IP address and the ingress interface do not satisfy the first policy and do not satisfy the second policy, forward the unicast packet.

[0017] In some embodiments, if the source IP address is the same as the IP address preset in the ACL and the ingress interface exists in the ACL, the source IP address and the ingress interface satisfy the first policy; or,

[0018] If the ingress interface does not exist in the ACL, the source IP address and the ingress interface do not satisfy the first policy and do not satisfy the second policy.

[0019] In some embodiments, the processing of the unicast packet according to the source IP address, the ingress interface, and the policy includes:

[0020] If the ingress interface and the source IP address do not satisfy the first policy and satisfy the second policy, discard the unicast packet.

[0021] In some embodiments, if the source IP address is not the same as the IP address preset in the ACL, the ingress interface and the source IP address do not satisfy the first policy and satisfy the second policy.

[0022] In some embodiments, the storage address of the first policy in the ACL is higher than the storage address of the second policy in the ACL.

[0023] In some embodiments, determining to obtain a preset policy in an access control list (ACL) according to the enabled URPF mode type includes: if the enabled URPF mode is the strict mode, obtaining a second policy and a third policy preset in the ACL that correspond to the strict mode;

[0024] The second policy includes matching the incoming interface and not matching the source IP address; the third policy includes matching the consistency of the incoming interface and the source IP address.

[0025] In some embodiments, processing the unicast packet according to the source IP address, the incoming interface, and the policy includes:

[0026] If the source IP address and the incoming interface satisfy the third policy, or if the source IP address and the incoming interface do not satisfy the third policy and do not satisfy the second policy, forward the unicast packet.

[0027] In some embodiments, if the source IP address is the same as the preset IP address in the ACL and the incoming interface is the same as the preset incoming interface in the ACL, then the source IP address and the incoming interface satisfy the third policy; or,

[0028] If the incoming interface is not the same as the preset incoming interface in the ACL, then the source IP address and the incoming interface do not satisfy the third policy and do not satisfy the second policy.

[0029] In some embodiments, processing the unicast packet according to the source IP address, the incoming interface, and the policy includes:

[0030] If the incoming interface and the IP address do not satisfy the third policy and satisfy the second policy, discard the unicast packet.

[0031] In some embodiments, if the source IP address is not the same as the preset IP address in the ACL, then the incoming interface and the IP address do not satisfy the third policy and satisfy the second policy.

[0032] In some embodiments, the storage address of the third policy in the ACL is higher than the storage address of the second policy in the ACL.

[0033] In another aspect, an embodiment of the present disclosure further provides a unicast packet forwarding device, including: a receiving module, an obtaining module, a determining module, and a processing module, where the receiving module is configured to receive a unicast packet;

[0034] The obtaining module is configured to obtain the source Internet Protocol (IP) address carried in the unicast packet;

[0035] The determining module is configured to determine the ingress interface of the unicast packet;

[0036] The processing module is configured to, when the unicast Reverse Path Forwarding (URPF) mode of the ingress interface is enabled, obtain a preset policy in an Access Control List (ACL) according to the enabled URPF mode type, and process the unicast packet according to the source IP address, the ingress interface, and the policy.

[0037] On the other hand, an embodiment of the present disclosure further provides a computer device, including:

[0038] One or more processors;

[0039] A storage device storing one or more programs thereon;

[0040] When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the unicast packet processing method as described above.

[0041] On the other hand, an embodiment of the present disclosure further provides a computer-readable medium storing a computer program thereon, wherein when the program is executed, the unicast packet processing method as described above is implemented.

[0042] The unicast packet forwarding method and apparatus provided by the embodiments of the present disclosure, the method includes: receiving a unicast packet, obtaining the source IP address carried therein; determining the ingress interface of the unicast packet; if the URPF mode of the ingress interface is enabled, obtaining a preset policy in the ACL according to the enabled URPF mode type, and processing the unicast packet according to the source IP address, the ingress interface, and the policy; the embodiments of the present disclosure take the ingress interface of the unicast packet and the URPF mode type as considerations for packet forwarding, so that it is not necessary to store the source IP address information in the routing table, which does not occupy the resources of the routing table, reduces the consumption of routing table resources, and simplifies the packet forwarding process in the URPF mode; moreover, in the strict mode, the step of looking up the next-hop index according to the source IP address can be omitted when forwarding the packet, saving a table lookup process and improving the packet forwarding efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a schematic diagram of the unicast packet processing flow provided by an embodiment of the present disclosure;

[0044] Figure 2 It is a schematic diagram of the process of forwarding a unicast packet provided by an embodiment of the present disclosure;

[0045] Figure 3Schematic diagram of the unicast packet processing process in the loose mode provided by the embodiments of the present disclosure;

[0046] Figure 4 Schematic diagram of the unicast packet processing process in the strict mode provided by the embodiments of the present disclosure;

[0047] Figure 5 Schematic diagram of the structure of the unicast packet processing device provided by the embodiments of the present disclosure. Detailed implementation manners

[0048] Hereinafter, the example embodiments will be described more fully with reference to the accompanying drawings. However, the example embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0049] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0050] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a" and "the" are also intended to include the plural forms unless the context clearly indicates otherwise. It will also be understood that when the terms "comprises" and / or "consists of" are used in this specification, it specifies the presence of the stated features, wholes, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their groups.

[0051] The embodiments described herein may be described with reference to the plan views and / or cross-sectional views by means of the ideal schematic diagrams of the present disclosure. Therefore, the example illustrations may be modified according to the manufacturing technology and / or tolerances. Therefore, the embodiments are not limited to the embodiments shown in the drawings, but include modifications of the configurations formed based on the manufacturing process. Therefore, the regions illustrated in the drawings have schematic attributes, and the shapes of the regions shown in the drawings illustrate the specific shapes of the regions of the elements, but are not intended to be restrictive.

[0052] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly so defined herein.

[0053] The URPF mode types include the loose mode and the strict mode. In the URPF loose mode, source IP address checking is performed. When the source IP address exists in the routing table, the URPF check is considered passed, and the unicast packet is forwarded; otherwise, the URPF check fails, and the packet is discarded. In the URPF strict mode, source IP address checking is performed. When the source IP address exists in the routing table, the next-hop index corresponding to the source IP address is obtained, and another table is queried through the next-hop index to obtain the expected ingress interface of the packet. When the expected ingress interface of the packet is the same as the actual ingress interface, the URPF check is considered successful. When the source IP address does not exist in the routing table, or when the source IP address exists in the routing table but the expected ingress interface of the packet is different from the actual ingress interface, the URPF check fails, and the packet is discarded.

[0054] ACL (Access Control Lists) is an access control technology based on packet filtering that is widely used in routers and layer-3 switching devices. Multiple policy entries are configured in the ACL, and each policy entry can be considered a matching condition. If a policy entry is hit, the action set for the policy is executed. With the help of the ACL, network security can be guaranteed more flexibly and effectively.

[0055] To reduce the resource occupation of the source IP address on the routing table and simplify the packet forwarding process in the URPF mode, an embodiment of the present disclosure provides a method for processing unicast packets. The method is applied to a unicast packet processing device. In the initialization stage, the following configurations are performed on the unicast packet processing device:

[0056] 1. Power on and initialize the unicast packet processing device;

[0057] 2. Configure the ingress interface IIF_A (Ingress Interface, IIF) of the unicast packet processing device to receive packets;

[0058] 3. Configure the URPF mode type of the ingress interface IIF_A. The URPF mode type can include the loose mode and the strict mode;

[0059] 4. Configure policies in the ACL according to the URPF mode type. The policies are stored in the ACL in the form of entries;

[0060] a. In the loose mode, configure the first policy and the second policy in the ACL. The rule defined by the first policy is: match the ingress interface IIF_A and the source IP address. The rule defined by the second policy is: only match the ingress interface IIF_A. Considering the attribute that the low-address policy is returned when multiple policies in the ACL are hit simultaneously, the first policy is configured in the high-address segment of the ACL, and the second policy is configured in the low-address segment, that is, the storage address of the first policy in the ACL is higher than the storage address of the second policy in the ACL;

[0061] b. In strict mode, configure the second policy and the third policy in the ACL. The rule defined by the third policy is: match the source IP address and the consistency between the ingress interface IIF_A and the expected ingress interface IIF_B (the expected ingress interface IIF_B is pre-configured in the ACL). The rule defined by the second policy is: only match the ingress interface IIF_A. Similarly, the storage address of the third policy in the ACL is higher than that of the second policy in the ACL.

[0062] After initialization is completed, construct a unicast data packet and send it using a meter.

[0063] As Figure 1 shown, the unicast packet processing method provided by the embodiments of the present disclosure includes the following steps:

[0064] Step 11, receive a unicast packet and obtain the source Internet Protocol (IP) address carried therein.

[0065] The unicast packet can carry packet forwarding information such as the source IP address and the destination IP address. In this step, parse the received unicast packet to obtain the source IP address carried therein.

[0066] Step 12, determine the ingress interface of the unicast packet.

[0067] There are the following three types of ingress interfaces: physical layer-3 interface, layer-3 sub-interface, and VLAN (Virtual Local Area Network) layer-3 interface. In this step, the methods for obtaining the above three types of ingress interfaces are different. For a physical layer-3 interface, it can be exported through a physical port; for a layer-3 sub-interface, it can be exported through a physical port combined with the VLAN carried in the packet; for a VLAN layer-3 interface, it can be exported through the VLAN carried in the packet.

[0068] Step 13, if the URPF mode of the ingress interface is enabled, obtain the preset policy in the ACL according to the enabled URPF mode type.

[0069] In this step, first determine that the URPF mode of the ingress interface IIF_A is enabled, and determine which URPF mode type is enabled, that is, whether it is the loose mode or the strict mode. Then, obtain the policy used to judge the forwarding of the unicast packet according to the URPF mode type. The policies used to process the unicast packet are different for different URPF mode types. For example, in the loose mode, the first policy and the second policy are used for judgment; in the strict mode, the second policy and the third policy are used for judgment.

[0070] Step 14, process the unicast packet according to the source IP address, the ingress interface, and the policy.

[0071] In this step, use the rules defined by the policy obtained in step 13 to determine whether the source IP address of the unicast packet and the incoming interface IIF_A meet the corresponding policy, and decide the processing action for the unicast packet according to the judgment result.

[0072] The unicast packet forwarding method and device provided by the embodiments of the present disclosure, the method includes: receiving a unicast packet, and obtaining the source Internet Protocol IP address carried therein; determining the incoming interface of the unicast packet; if the URPF mode of the incoming interface is enabled, obtain the preset policy in the ACL according to the enabled URPF mode type, and process the unicast packet according to the source IP address, the incoming interface and the policy; the embodiments of the present disclosure take the incoming interface and the URPF mode type of the unicast packet as the considerations for packet forwarding. In this way, there is no need to store the source IP address information in the routing table, which will not occupy the resources of the routing table, reduce the consumption of routing table resources and simplify the packet forwarding process under the URPF mode; moreover, in the strict mode, the step of looking up the next-hop index according to the source IP address can be omitted when forwarding the packet, saving a table lookup process and improving the packet forwarding efficiency.

[0073] In some embodiments, the unicast packet processing method further includes the following steps: if the URPF mode of the incoming interface is disabled, there is no need to configure a policy in the ACL at this time, and there is no need to process the received unicast packet according to the policy, and the unicast packet can be directly passed through.

[0074] In some embodiments, processing the unicast packet (i.e., step 14) includes: forwarding the unicast packet or discarding the unicast packet. Before receiving the unicast packet and determining the incoming interface of the unicast packet (i.e., step 12), the method further includes the following steps: obtaining the destination IP address carried in the unicast packet, that is, parsing the unicast packet to obtain the destination IP address carried therein. This step can be executed synchronously with the step of obtaining the source IP address in step 11.

[0075] Correspondingly, as Figure 2 shown, forwarding the unicast packet may include the following steps:

[0076] Step 21, determine the outgoing interface according to the destination IP address and the routing table.

[0077] In this step, look up the routing table according to the destination IP address parsed from the unicast packet to obtain the outgoing interface corresponding to the destination IP address, and this outgoing interface is the expected outgoing interface for the unicast packet processing device to forward the unicast packet.

[0078] Step 22, forward the unicast packet according to the outgoing interface.

[0079] In this step, the received unicast packet is sent out from the egress interface determined in step 21.

[0080] As can be seen from steps 21 - 22, the source IP address information does not need to be stored in the routing table anymore. Therefore, it does not occupy the resources of the routing table, reduces the consumption of routing table resources, and simplifies the packet forwarding process in the URPF mode.

[0081] In some embodiments, obtaining the preset policies in the ACL according to the enabled URPF mode type (i.e., step 13) includes: if the enabled URPF mode type is the loose mode, obtaining the first policy and the second policy preset in the ACL corresponding to the loose mode; the first policy includes matching the source IP address and the ingress interface; the second policy includes matching the ingress interface and not matching the source IP address.

[0082] The following combines Figure 3 , and details the processing flow of unicast packets in the loose mode. As Figure 3 shown, processing the unicast packet according to the source IP address, the ingress interface, and the policy includes the following steps:

[0083] Step 31, determine whether the source IP address and the ingress interface satisfy the first policy. If so, execute step 33; otherwise, execute step 32.

[0084] In this step, if the source IP address and the ingress interface IIF_A both satisfy the rules defined by the first policy, it indicates that the URPF check passes, and the unicast packet is forwarded. If at least one of the source IP address and the ingress interface IIF_A does not satisfy the rules defined by the first policy, it indicates that the URPF check fails, and further judgment in combination with the second policy is required (i.e., execute step 32).

[0085] In some embodiments, if the source IP address is the same as the preset IP address in the ACL and the ingress interface IIF_A exists in the ACL, the source IP address and the ingress interface satisfy the first policy.

[0086] Step 32, determine whether the ingress interface and the source IP address satisfy the second policy. If so, execute step 34; otherwise, execute step 33.

[0087] In this step, if the incoming interface IIF_A meets the second policy, that is, the incoming interface and the source IP address only meet the second policy (and do not meet the first policy), then discard the unicast packet. If the incoming interface and the source IP address do not meet the second policy, that is, the source IP address and the incoming interface IIF_A neither meet the first policy nor meet the second policy, it means that the unicast packet does not enter from the incoming interface IIF_A, then forward the unicast packet, that is, directly pass through the unicast packet transparently.

[0088] In some embodiments, if the source IP address is inconsistent with the IP address preset in the ACL, then the incoming interface and the source IP address do not meet the first policy and meet the second policy.

[0089] In some embodiments, if the incoming interface IIF_A does not exist in the ACL, then the source IP address and the incoming interface do not meet the first policy and do not meet the second policy.

[0090] Step 33, forward the unicast packet.

[0091] Step 34, discard the unicast packet.

[0092] That is to say, when enabling loose-mode URPF check, if the source IP address and the incoming interface IIF_A meet the first policy, then forward the unicast packet; if the incoming interface IIF_A only meets the second policy (and does not meet the first policy), then discard the unicast packet; if the source IP address and the incoming interface IIF_A neither meet the first policy nor meet the second policy, then directly pass through the unicast packet transparently.

[0093] The following combines Figure 4 , and details the processing flow of unicast packets in strict mode. As Figure 4 shown, processing the unicast packet according to the source IP address, the incoming interface, and the policy includes the following steps:

[0094] Step 41, check whether the source IP address and the incoming interface meet the third policy. If so, execute step 43; otherwise, execute step 42.

[0095] In this step, if both the source IP address and the incoming interface IIF_A meet the rules defined by the third policy, it means that the URPF check passes, then forward the unicast packet. If at least one of the source IP address and the incoming interface IIF_A does not meet the rules defined by the third policy, it means that the URPF check fails, and it is necessary to further judge in combination with the second policy (that is, execute step 42).

[0096] In some embodiments, if the source IP address is the same as the IP address preset in the ACL, and the incoming interface IIF_A is the same as the incoming interface IIF_B preset in the ACL, then the source IP address and the incoming interface IIF_A meet the third policy.

[0097] Step 42: Determine whether the incoming interface and the source IP address meet the second policy. If so, execute Step 44; otherwise, execute Step 43.

[0098] In this step, if the incoming interface IIF_A meets the second policy, that is, the incoming interface and the source IP address only meet the second policy (do not meet the third policy), then discard the unicast packet. If the incoming interface and the source IP address do not meet the second policy, that is, the source IP address and the incoming interface IIF_A neither meet the third policy nor meet the second policy, it means that the unicast packet does not enter from the incoming interface IIF_A, then forward the unicast packet, that is, directly pass through the unicast packet.

[0099] In some embodiments, if the source IP address is different from the IP address preset in the ACL, then the incoming interface and the source IP address do not meet the third policy and meet the second policy.

[0100] In some embodiments, if the incoming interface IIF_A is different from the incoming interface IIF_B preset in the ACL, then the source IP address and the incoming interface do not meet the third policy and do not meet the second policy.

[0101] Step 43: Forward the unicast packet.

[0102] Step 44: Discard the unicast packet.

[0103] That is to say, when the strict-mode URPF check is enabled, if the source IP address and the incoming interface IIF_A meet the third policy, then forward the unicast packet; if the incoming interface IIF_A only meets the second policy (does not meet the third policy), then discard the unicast packet; if the source IP address and the incoming interface IIF_A neither meet the third policy nor meet the second policy, then directly pass through the unicast packet.

[0104] Based on the same inventive concept, the embodiments of the present disclosure further provide a unicast packet processing device, as Figure 5 shown, the unicast packet processing device includes a receiving module 101, an obtaining module 102, a determining module 103, and a processing module 104. The receiving module 101 is configured to receive unicast packets.

[0105] The obtaining module 102 is configured to obtain the source Internet Protocol IP address carried in the unicast packet.

[0106] The determining module is configured to determine the ingress interface of the unicast packet.

[0107] The processing module is configured to, when it is determined that the unicast reverse path forwarding (URPF) mode of the ingress interface is enabled, obtain a preset policy in the access control list (ACL) according to the enabled URPF mode type, and process the unicast packet according to the source IP address, the ingress interface, and the policy.

[0108] In some embodiments, the processing module 104 is configured to forward the unicast packet or discard the unicast packet.

[0109] The obtaining module 102 is further configured to obtain the destination IP address carried in the unicast packet after the receiving module 101 receives the unicast packet and before the determining module 103 determines the ingress interface of the unicast packet.

[0110] The processing module 104 is configured to determine the egress interface according to the destination IP address and the routing table, and forward the unicast packet according to the egress interface.

[0111] In some embodiments, the processing module 104 is configured to, when the enabled URPF mode type is the loose mode, obtain a first policy and a second policy preset in the ACL corresponding to the loose mode; the first policy includes matching the source IP address and the ingress interface; the second policy includes matching the ingress interface and not matching the source IP address.

[0112] In some embodiments, the processing module 104 is configured to forward the unicast packet when the source IP address and the ingress interface satisfy the first policy, or when the source IP address and the ingress interface do not satisfy the first policy and do not satisfy the second policy.

[0113] In some embodiments, if the source IP address is the same as the IP address preset in the ACL and the ingress interface exists in the ACL, the source IP address and the ingress interface satisfy the first policy; or, if the ingress interface does not exist in the ACL, the source IP address and the ingress interface do not satisfy the first policy and do not satisfy the second policy.

[0114] In some embodiments, the processing module 104 is configured to discard the unicast packet when the ingress interface and the source IP address do not satisfy the first policy and satisfy the second policy.

[0115] In some embodiments, if the source IP address is not the same as the IP address preset in the ACL, the ingress interface and the source IP address do not satisfy the first policy and satisfy the second policy.

[0116] In some embodiments, the storage address of the first policy in the ACL is higher than the storage address of the second policy in the ACL.

[0117] In some embodiments, the processing module 104 is configured to, when the enabled URPF mode is the strict mode, obtain a second policy and a third policy preset in the ACL corresponding to the strict mode; the second policy includes matching the incoming interface and not matching the source IP address; the third policy includes matching the consistency of the incoming interface and the source IP address.

[0118] In some embodiments, the processing module 104 is configured to forward the unicast packet when the source IP address and the incoming interface satisfy the third policy, or when the source IP address and the incoming interface do not satisfy the third policy and do not satisfy the second policy.

[0119] In some embodiments, if the source IP address is consistent with the IP address preset in the ACL, and the incoming interface is consistent with the incoming interface preset in the ACL, then the source IP address and the incoming interface satisfy the third policy; or,

[0120] If the incoming interface is not consistent with the incoming interface preset in the ACL, then the source IP address and the incoming interface do not satisfy the third policy and do not satisfy the second policy.

[0121] In some embodiments, the processing module 104 is configured to discard the unicast packet when the incoming interface and the IP address do not satisfy the third policy and satisfy the second policy.

[0122] In some embodiments, if the source IP address is not consistent with the IP address preset in the ACL, then the incoming interface and the IP address do not satisfy the third policy and satisfy the second policy.

[0123] In some embodiments, the storage address of the third policy in the ACL is higher than the storage address of the second policy in the ACL.

[0124] Embodiments of the present disclosure further provide a computer device, which includes: one or more processors and a storage device; wherein, one or more programs are stored on the storage device, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the unicast packet forwarding method provided in the foregoing embodiments.

[0125] Embodiments of the present disclosure further provide a computer-readable medium, on which a computer program is stored, wherein when the computer program is executed, the unicast packet forwarding method provided in the foregoing embodiments is implemented.

[0126] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In a hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.

[0127] Example embodiments have been disclosed herein, and although specific terms have been employed, they are used only for and should be construed only as general illustrative meanings and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly stated, features, characteristics, and / or elements described in connection with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in connection with other embodiments. Accordingly, those skilled in the art will understand that various forms and details may be changed without departing from the scope of the invention as set forth in the appended claims.

Claims

1. A unicast packet processing method, characterized in that, The method includes: Receiving a unicast packet and obtaining the source Internet Protocol (IP) address carried therein; Determining the ingress interface of the unicast packet; If the unicast Reverse Path Forwarding (URPF) mode of the ingress interface is enabled, obtaining the preset policies in the Access Control List (ACL) according to the enabled URPF mode type; Processing the unicast packet according to the source IP address, the ingress interface, and the policies.

2. The method according to claim 1, wherein Before determining the ingress interface of the unicast packet after receiving the unicast packet, the method further includes: obtaining the destination IP address carried in the unicast packet; The processing of the unicast packet includes: determining an egress interface according to the destination IP address and the routing table, and forwarding the unicast packet according to the egress interface.

3. The method according to claim 1, wherein The obtaining the preset policies in the Access Control List (ACL) according to the enabled URPF mode type includes: if the enabled URPF mode type is the loose mode, obtaining the first policy and the second policy preset in the ACL corresponding to the loose mode; The first policy includes matching the source IP address and the ingress interface; the second policy includes matching the ingress interface and not matching the source IP address.

4. The method according to claim 3, characterized in that, The processing the unicast packet according to the source IP address, the ingress interface, and the policies includes: If the source IP address and the ingress interface satisfy the first policy, or the source IP address and the ingress interface do not satisfy the first policy and do not satisfy the second policy, forwarding the unicast packet.

5. The method according to claim 4, wherein If the source IP address is the same as the preset IP address in the ACL and the ingress interface exists in the ACL, the source IP address and the ingress interface satisfy the first policy; Or, If the ingress interface does not exist in the ACL, the source IP address and the ingress interface do not satisfy the first policy and do not satisfy the second policy.

6. The method according to claim 3, characterized in that The processing the unicast packet according to the source IP address, the ingress interface, and the policies includes: If the ingress interface and the source IP address do not satisfy the first policy and satisfy the second policy, discarding the unicast packet.

7. The method according to claim 6, wherein If the source IP address is not the same as the preset IP address in the ACL, the ingress interface and the source IP address do not satisfy the first policy and satisfy the second policy.

8. The method according to any one of claims 3-7, characterized in that, The storage address of the first policy in the ACL is higher than the storage address of the second policy in the ACL.

9. The method according to claim 1, wherein The obtaining the preset policies in the Access Control List (ACL) according to the enabled URPF mode type includes: if the enabled URPF mode is the strict mode, obtaining the second policy and the third policy preset in the ACL corresponding to the strict mode; The second policy includes matching the ingress interface and not matching the source IP address; the third policy includes matching the consistency of the ingress interface and the source IP address.

10. The method according to claim 9, characterized in that, The processing the unicast packet according to the source IP address, the ingress interface, and the policies includes: If the source IP address and the ingress interface satisfy the third policy, or the source IP address and the ingress interface do not satisfy the third policy and do not satisfy the second policy, forwarding the unicast packet.

11. The method according to claim 10, wherein If the source IP address is the same as the pre-set IP address in the ACL, and the incoming interface is the same as the pre-set incoming interface in the ACL, then the source IP address and the incoming interface meet the third policy; Or, If the incoming interface is different from the pre-set incoming interface in the ACL, then the source IP address and the incoming interface do not meet the third policy and do not meet the second policy.

12. The method according to claim 9, characterized in that Processing the unicast packet according to the source IP address, the incoming interface and the policy includes: If the incoming interface and the IP address do not meet the third policy but meet the second policy, then discard the unicast packet.

13. The method according to claim 12, characterized in that, If the source IP address is different from the pre-set IP address in the ACL, then the incoming interface and the IP address do not meet the third policy but meet the second policy.

14. The method according to any one of claims 9-13, characterized in that, The storage address of the third policy in the ACL is higher than the storage address of the second policy in the ACL.

15. A unicast packet processing device, characterized in that, Including: A receiving module, an obtaining module, a determining module and a processing module, where the receiving module is used to receive a unicast packet; The obtaining module is used to obtain the source Internet Protocol (IP) address carried in the unicast packet; The determining module is used to determine the incoming interface of the unicast packet; The processing module is used to, when the unicast Reverse Path Forwarding (URPF) mode of the incoming interface is enabled, obtain the pre-set policy in the Access Control List (ACL) according to the enabled URPF mode type, and process the unicast packet according to the source IP address, the incoming interface and the policy.

16. A computer device, including: One or more processors; A storage device, on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the unicast packet processing method according to any one of claims 1-14.

17. A computer-readable medium having a computer program stored thereon, wherein, When the program is executed, it implements the unicast packet processing method according to any one of claims 1-14.

Citation Information

Patent Citations

  • Method and device for realizing unicast reverse path forwarding (URPF) examination

    CN103220255A