A message forwarding method, device and system based on user groups
By carrying group information in SRv6 messages, the problem of forwarding user group policies in SRv6 networks is solved, enabling coordinated control between the sending and receiving devices. This method is applicable to user group message forwarding in non-VXLAN networks.
Patent Information
- Application Number
- CN202011357010.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-09-30
- Filing Date
- 2020-11-26
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-11-26
AI Technical Summary
In SRv6-based communication networks, existing technologies cannot achieve packet forwarding based on user groups and group policies, and the VXLAN-GPE solution requires modification of the existing VXLAN protocol and cannot be applied in non-VXLAN networks.
By carrying group information in SRv6 messages, the sending and receiving devices can jointly determine the forwarding strategy for user groups. Group information can be programmed using the SRv6 extended header to achieve message forwarding for user groups.
It enables user group-based packet forwarding in SRv6 networks, supports collaborative determination of forwarding strategies between sending and receiving devices, and avoids modifications to existing network equipment.
Smart Images

Figure CN114363252B_ABST
Abstract
Description
[0001] This application claims priority to the Chinese Patent Application No. CN202011059313.6, filed on September 30, 2020, and entitled "Method, Device and System for Realizing Service Grouping", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, and in particular to a message forwarding method, device and system based on a user group. BACKGROUND
[0003] The fourth version of Internet Protocol (Internet Protocol version 4, IPv4) is currently widely deployed Internet protocol. IPv4 technology is simple, easy to implement, and good interoperability. However, an important lesson learned from the development of IPv4 technology is the scalability problem, which was not initially designed to have so many devices accessing the Internet Protocol (IP) network, which triggered the development of the sixth version of Internet Protocol (Internet Protocol version 6, IPv6) technology. IPv6 replaces IPv4 mainly to solve the problem of IPv4 address exhaustion, and IPv6 also has many improvements over IPv4 in other aspects. However, an important lesson learned from the development of IPv6 technology is the compatibility problem. The assumption at the time was relatively simple, that the 32-bit address space was not enough, so it was expanded to 128 bits, but the 128-bit IPv6 address is not compatible with the 32-bit IPV4 address, so the entire network needs to be upgraded to support IPv6, which leads to difficulties in deploying applications. From this perspective, Segment Routing over Internet Protocol version 6 (SRv6) is compatible with IPv6 routing forwarding, and takes into account the advantages of Multiprotocol Label Switching (MPLS) forwarding, which ensures that SRv6 can evolve smoothly from an IPv6 network.
[0004] Segment Routing (SR) technology is to specify a path for an application message by a source node, and encapsulate the path into a ordered Segment list in a header, and intermediate nodes of the path only need to forward according to the path specified in the header. Segment is any instruction for directing a device to process a message, such as forwarding a message to a destination according to a shortest path, forwarding a message through a specified interface, forwarding a message to a specified application / service instance, etc. In order to implement SRv6 forwarding in IPv6, an SRv6 extension header, i.e. Segment Routing header (SRH), is introduced in an IPv6 message for programming combination of Segments to form an SRv6 path. The standardization work of SRv6 mainly focuses on the Internet Engineering Task Force (IETF) SPRING (Source Packet Routing in Networking) working group, and the standardization work of the message encapsulation format SRH is carried out in the 6MAN (IPv6 Maintenance) working group.
[0005] However, in the scenario of a communication network based on SRv6, according to the existing SRv6 related protocols, the message forwarding technology based on a user group and a group policy cannot be implemented. SUMMARY
[0006] The present application provides a message forwarding method, device and system based on a user group, so as to implement the message forwarding technology based on a user group and a group policy in the scenario of a communication network based on SRv6.
[0007] In a first aspect, a message forwarding method based on a user group is provided, the method comprising: receiving, by a first network device, a first service message sent by a first user device, the first service message comprising information of the first user device, and a destination of the first service message being a second user device; determining, by the first network device, whether a first user group corresponding to the information of the first user device is included in the first network device, the first user group being a user group to which the first user device belongs; determining, by the first network device, a value of first group information and generating a first SRv6 message according to a determination result of whether the first user group corresponding to the information of the first user device is included in the first network device, the first SRv6 message comprising the first group information and the first service message, and the first group information being used to indicate an interworking policy of the first user device and the second user device for transmitting the first service message determined by the first network device based on the first user group; and sending, by the first network device, the first SRv6 message to a second network device.
[0008] Based on the scheme provided in the present application, the first network device carries group information in the SRv6 message sent to the second network device, so that the first network device as the sending end device can participate in the control of determining the forwarding policy for the user group.
[0009] In a possible implementation manner of the first aspect, the first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first network device determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network device, including: in response to the first network device determining that the first user group corresponding to the information of the first user equipment is included in the first network device, the first network device determines that the value of the first group identifier indicates the first user group.
[0010] In another possible implementation manner of the first aspect, the first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first network device determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network device, including: in response to the first network device determining that the first user group corresponding to the information of the first user equipment is not included in the first network device, the first network device determines that the value of the first group identifier indicates invalid.
[0011] In another possible implementation manner of the first aspect, the first group information includes a first group identifier and a first group policy identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first group policy identifier being used to indicate a specific interworking policy.
[0012] In another possible implementation manner of the first aspect, the first group policy identifier includes a first identifier, the first identifier being used to indicate that the first network device includes the first user group and the second network device does not include a second user group, the second user group being a user group to which the second user equipment belongs, and the first network device determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network device, including: in response to the first network device determining that the first user group corresponding to the information of the first user equipment is included in the first network device, the first network device determines that the value of the first group identifier indicates the first user group and determines the value of the first identifier.
[0013] In a further possible implementation form of the first aspect, the first group policy identifier comprises a second identifier and a third identifier, the second identifier being used to indicate that the first network device does not comprise the first user group and the second network device comprises a second user group, and the third identifier being used to indicate that the first network device does not comprise the first user group and the second network device does not comprise the second user group, the second user group being a user group to which the second user device belongs, and the determining, by the first network device, the value of the first group information according to the determination result of whether the first network device comprises the first user group corresponding to the information of the first user device comprises: in response to the first network device determining that the first network device comprises the first user group corresponding to the information of the first user device, determining, by the first network device, that the value of the first group identifier indicates invalidity and the values of the second identifier and the third identifier.
[0014] In a further possible implementation form of the first aspect, the first group policy identifier comprises a fourth identifier, the fourth identifier being used to indicate that the second network device does not comprise a second user group, the second user group being a user group to which the second user device belongs, and the determining, by the first network device, the value of the first group information according to the determination result of whether the first network device comprises the first user group corresponding to the information of the first user device comprises: in response to the first network device determining that the first network device comprises the first user group corresponding to the information of the first user device, determining, by the first network device, that the value of the first group identifier indicates the first user group and the value of the fourth identifier.
[0015] In a further possible implementation form of the first aspect, the first group policy identifier comprises a fifth identifier and a sixth identifier, the fifth identifier being used to indicate that the second network device comprises a second user group, and the sixth identifier being used to indicate that the second network device does not comprise the second user group, the second user group being a user group to which the second user device belongs, and the determining, by the first network device, the value of the first group information according to the determination result of whether the first network device comprises the first user group corresponding to the information of the first user device comprises: in response to the first network device determining that the first network device comprises the first user group corresponding to the information of the first user device, determining, by the first network device, that the value of the first group identifier indicates invalidity and the values of the fifth identifier and the sixth identifier.
[0016] In a second aspect, a packet forwarding method based on a user group is provided. The method includes: receiving, by a second network device, a first SRv6 packet sent by a first network device, the first SRv6 packet including first group information and a first service packet, the first group information being used to indicate an interworking policy of the first service packet determined by the first network device based on a first user group, the first service packet being from a first user device, the first service packet being destined for a second user device, the first user group being a user group to which the first user device belongs, and the first service packet including information of the second user device. Then, determining, by the second network device, whether a second user group corresponding to the information of the second user device is included in the second network device, the second user group being a user group to which the second user device belongs. And determining, by the second network device, a forwarding policy of forwarding the first service packet to the second user device according to a determination result of whether the second user group corresponding to the information of the second user device is included in the second network device and the first group information.
[0017] Based on the scheme provided in the present application, the second network device receives a first SRv6 packet sent by a first network device, and then the second network device as a receiving end device can control the forwarding policy of the user group according to the interworking policy determined by the sending end device and the interworking policy determined by the receiving end device.
[0018] In a possible implementation of the second aspect, the first group information includes a first group identifier, the first group identifier being used to indicate the user group to which the first user device belongs. The second network device determines the forwarding policy of forwarding the first service packet to the second user device according to the determination result of whether the second user group corresponding to the information of the second user device is included in the second network device and the first group information, including: in response to the second network device determining that the second user group corresponding to the information of the second user device is included in the second network device and the value of the first group identifier indicates the first user group, the second network device sends the first service packet to the second user device.
[0019] In a further possible implementation form of the second aspect, the first group information comprises a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the second network device determines the forwarding policy for forwarding the first service packet to the second user equipment according to a determination result of whether the second network device comprises a second user group corresponding to information of the second user equipment and the first group information, comprises: in response to the second network device determining that the second network device does not comprise the second user group corresponding to the information of the second user equipment and the value of the first group identifier indicates the first user group, the second network device sends the first service packet to the second user equipment in a random discarding manner or in a limited rate forwarding manner.
[0020] In a further possible implementation form of the second aspect, the first group information comprises a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the second network device determines the forwarding policy for forwarding the first service packet to the second user equipment according to a determination result of whether the second network device comprises a second user group corresponding to information of the second user equipment and the first group information, comprises: in response to the second network device determining that the second network device comprises the second user group corresponding to the information of the second user equipment and the value of the first group identifier indicates invalid, the second network device sends the first service packet to the second user equipment in a random discarding manner or in a limited rate forwarding manner.
[0021] In a further possible implementation form of the second aspect, the first group information comprises a first group identifier and a first group policy identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first group policy identifier being used to indicate a specific interworking policy.
[0022] In a further possible implementation form of the second aspect, the second network device determines the forwarding policy for forwarding the first service packet to the second user equipment according to a determination result of whether the second network device comprises a second user group corresponding to information of the second user equipment and the first group information, comprises: the second network device determines a second group policy according to the determination result, the second group policy being used to indicate an interworking policy determined by the second network device based on the second user group for the first user equipment and the second user equipment to transmit the first service packet; and the second network device determines the forwarding policy for forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy.
[0023] In a further possible implementation form of the second aspect, the second network device determines the forwarding policy of forwarding the first service packet to the second user device according to the interworking policy indicated by the first group policy identifier and the second group policy, comprising: the second network device determines that a first identifier in the first group policy identifier is valid, the first identifier being used to indicate that the first network device comprises the first user group and the second network device does not comprise the second user group; the second network device determines a first sub-policy in the second group policy according to the first identifier, the first sub-policy indicating the interworking policy determined by the second user group in the case that the first network device comprises the first user group and the second network device does not comprise the second user group; the second network device determines the forwarding policy of forwarding the first service packet to the second user device according to the interworking policy indicated by the value of the first identifier and the first sub-policy.
[0024] In a further possible implementation form of the second aspect, the second network device determines the forwarding policy of forwarding the first service packet to the second user device according to the interworking policy indicated by the first group policy identifier and the second group policy, comprising: the second network device determines that a second identifier and a third identifier in the first group policy identifier are valid, the second identifier being used to indicate that the first network device does not comprise the first user group and the second network device comprises the second user group, and the third identifier being used to indicate that the first network device does not comprise the first user group and the second network device does not comprise the second user group; the second network device determines a second sub-policy in the second group policy according to the second identifier and the third identifier, the second sub-policy indicating the interworking policy determined by the second user group in the case that the first network device does not comprise the first user group and the second network device comprises the second user group; the second network device determines the forwarding policy of forwarding the first service packet to the second user device according to the interworking policy indicated by the value of the second identifier and the second sub-policy.
[0025] In a further possible implementation form of the second aspect, the second network device determines the forwarding policy for forwarding the first service packet to the second user device according to a result of determining whether the second user group corresponding to the information of the second user device is included in the second network device and the first group information, comprising: the second network device determines a second group policy according to the result of determining, the second group policy being used to indicate an interworking policy determined by the second user group based on the first user device and the second user device for transmitting the first service packet; and the second network device determines the forwarding policy for forwarding the first service packet to the second user device according to the first group identifier and the second group policy indicated by the first group policy identifier.
[0026] In a further possible implementation form of the second aspect, the forwarding policy is any one of the following forwarding policies: forwarding, discarding, forwarding in a random discarding manner, and forwarding in a rate-limiting manner.
[0027] In the first aspect or the second aspect, optionally, the first group information is carried in any one of the following headers included in the first SRv6 packet: an IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
[0028] In the first aspect or the second aspect, optionally, the first group identifier is carried in any one of the following headers included in the first SRv6 packet: an IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
[0029] In the first aspect or the second aspect, optionally, the first group policy identifier is carried in any one of the following headers included in the first SRv6 packet: an IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
[0030] In the first aspect or the second aspect, optionally, the first SRv6 packet is transmitted via an SRv6 tunnel between the first network device and the second network device.
[0031] In the first aspect or the second aspect, optionally, the information of the second user device is a destination IP address included in the first service packet, or the information of the second user device is a destination MAC address included in the first service packet.
[0032] In the first aspect or the second aspect, optionally, the information of the first user device is a source IP address included in the first service packet, or the information of the first user device is a source MAC address included in the first service packet.
[0033] In a third aspect, a first network device is provided, which has the function of implementing the behavior of the first network device in the above method. The function can be implemented based on hardware, or corresponding software is executed based on hardware. The hardware or software includes one or more modules corresponding to the above function.
[0034] In a possible design, the first network device includes a processor and an interface, where the processor is configured to support the first network device to perform the corresponding function in the above method. The interface is used to support the communication between the first network device and another network device, and receive information or instructions related to the above method from the another network device. The interface is also used to support the communication between the first network device and a user equipment. The first network device can further include a memory coupled with the processor, which stores the necessary program instructions and data of the first network device.
[0035] In another possible design, the first network device includes a processor, a transmitter, a receiver, a random access memory, a read-only memory, and a bus. The processor is coupled with the transmitter, the receiver, the random access memory, and the read-only memory through the bus. When the first network device needs to be run, the system is started by a basic input / output system or a bootloader in an embedded system solidified in the read-only memory, and the first network device is guided to a normal running state. After the first network device enters the normal running state, an application program and an action system are run in the random access memory, so that the processor executes the method in the first aspect or any possible implementation manner of the first aspect.
[0036] In a fourth aspect, a first network device is provided, which includes a main board and an interface board, and further includes a switching network board. The first network device is used to execute the method in the first aspect or any possible implementation manner of the first aspect. Specifically, the first network device includes a module used to execute the method in the first aspect or any possible implementation manner of the first aspect.
[0037] In a fifth aspect, a first network device is provided, which comprises a controller and a first forwarding sub-device. The first forwarding sub-device comprises an interface board and further comprises a switching network board. The first forwarding sub-device is configured to perform the functions of the interface board in the fourth aspect and further configured to perform the functions of the switching network board in the fourth aspect. The controller comprises a receiver, a processor, a transmitter, a random access memory, a read-only memory and a bus. The processor is coupled to the receiver, the transmitter, the random access memory and the read-only memory via the bus respectively. When the controller needs to be started, a basic input / output system or a bootloader in an embedded system solidified in the read-only memory is used to boot the system to start the controller and make it enter a normal operation state. After the controller enters the normal operation state, an application program and an action system are run in the random access memory, so that the processor performs the functions of the main control board in the fourth aspect.
[0038] In a sixth aspect, a computer storage medium is provided, which is used to store programs, codes or instructions for the first network device described above. When the processor or the hardware device executes the programs, codes or instructions, the functions or steps of the first network device in the first aspect described above can be completed.
[0039] In a seventh aspect, a second network device is provided, which has functions to realize the behaviors of the second network device in the method described above. The functions can be realized based on hardware or corresponding software executed by hardware. The hardware or software comprises one or more modules corresponding to the functions described above.
[0040] In a possible design, the second network device comprises a processor and an interface. The processor is configured to support the second network device to perform the corresponding functions in the method described above. The interface is configured to support the communication between the second network device and the first network device, to send information or instructions involved in the method described above to the first network device, or to receive the information or instructions involved in the method described above sent by the first network device. The second network device can further comprise a memory coupled to the processor, which stores the necessary program instructions and data of the second network device.
[0041] In another possible design, the second network device includes a processor, a transmitter, a receiver, a random access memory, a read only memory, and a bus. The processor is coupled to the transmitter, the receiver, the random access memory, and the read only memory via the bus respectively. When the second network device needs to be run, the second network device is started by a basic input / output system or a bootloader in an embedded system fixed in the read only memory, and is guided to a normal operation state. After the second network device enters the normal operation state, an application program and an action system are run in the random access memory, so that the processor executes the method in the second aspect or any possible implementation manner of the second aspect.
[0042] In an eighth aspect, a second network device is provided. The second network device includes a master board and an interface board, and can further include a switching network board. The second network device is configured to execute the method in the second aspect or any possible implementation manner of the second aspect. Specifically, the second network device includes modules configured to execute the method in the second aspect or any possible implementation manner of the second aspect.
[0043] In a ninth aspect, a second network device is provided. The second network device includes a controller and a second forwarding sub-device. The second forwarding sub-device includes an interface board, and can further include a switching network board. The second forwarding sub-device is configured to execute the function of the interface board in the eighth aspect, and can further execute the function of the switching network board in the eighth aspect. The controller includes a receiver, a processor, a transmitter, a random access memory, a read only memory, and a bus. The processor is coupled to the receiver, the transmitter, the random access memory, and the read only memory via the bus respectively. When the controller needs to be run, the controller is started by a basic input / output system or a bootloader in an embedded system fixed in the read only memory, and is guided to a normal operation state. After the controller enters the normal operation state, an application program and an action system are run in the random access memory, so that the processor executes the function of the master board in the eighth aspect.
[0044] In a tenth aspect, a computer storage medium is provided. The computer storage medium is configured to store programs, codes, or instructions for the second network device described above. When a processor or a hardware device executes the programs, codes, or instructions, the functions or steps of the second network device in the second aspect described above can be completed.
[0045] In an eleventh aspect, a network system is provided. The network system includes a first network device and a second network device. The first network device is the first network device in the third aspect, the fourth aspect, or the fifth aspect described above. The second network device is the second network device in the seventh aspect, the eighth aspect, or the ninth aspect described above.
[0046] Through the above scheme, the group information is carried in the SRv6 message transmitted between the first network device and the second network device, so that the second network device as the receiving end device can control the forwarding policy of the user group according to the interworking policy determined by the sending end device and the interworking policy determined by the receiving end device. BRIEF DESCRIPTION OF DRAWINGS
[0047] Figure 1 A communication network structure schematic diagram of an embodiment of the present application;
[0048] Figure 2 A message forwarding method flowchart of an embodiment of the present application;
[0049] Figure 3 A group information format of an embodiment of the present application;
[0050] Figure 4 A header format of an SRv6 message of an embodiment of the present application;
[0051] Figure 5 A structure schematic diagram of a first network device of an embodiment of the present application;
[0052] Figure 6 A hardware structure schematic diagram of a first network device of an embodiment of the present application;
[0053] Figure 7 A hardware structure schematic diagram of another first network device of an embodiment of the present application;
[0054] Figure 8 A structure schematic diagram of a second network device of an embodiment of the present application;
[0055] Figure 9 A hardware structure schematic diagram of a second network device of an embodiment of the present application;
[0056] Figure 10 A hardware structure schematic diagram of another second network device of an embodiment of the present application. DETAILED DESCRIPTION
[0057] The technical scheme of the present application will be described in detail below through specific embodiments.
[0058] Figure 1 A communication network structure schematic diagram of an embodiment of the present application. The communication network includes a plurality of network devices. The communication network may, for example, be an IP network. Specifically, the communication network can be an SRv6-based communication network, that is, the communication network can transmit and process SRv6 messages. For example Figure 1As shown, the communication network includes a first network device and a second network device. The first network device communicates with the second network device via a communication link. In one possible implementation, the communication link between the first network device and the second network device is a physical communication link. The physical communication link can be a cable, fiber optic cable, or wireless link. The port on which the first network device is connected to the communication link can be a physical port, and the port on which the second network device is connected to the communication link can be a physical port. In another possible implementation, the communication link between the first network device and the second network device is a direct link. A direct link means that two devices (e.g., the first network device and the second network device) are directly connected via a link, and the link between the two devices does not include other forwarding or processing devices, but may include pass-through devices. The first network device can be a router or a Layer 3 switch. The second network device can be a router or a Layer 3 switch. The roles of the first network device and the second network device may differ in different types of communication networks. For example, in a campus network, the first network device and the second network device can be edge switches. As another example, in a core network, the first network device and the second network device can be provider edge (PE) devices.
[0059] The first network device can connect to at least one user device. For example... Figure 1 As shown, the first network device connects a first user equipment and a third user equipment. Similarly, the second network device can connect to at least one user equipment. Figure 1 As shown, the second network device connects the second user equipment and the fourth user equipment. The connection relationship between the first network device and the first user equipment and the third user equipment is illustrated as an example. In one possible implementation, the communication link between the first network device and the first user equipment and the third user equipment is a physical communication link. The physical communication link can be a cable, fiber optic cable, or wireless link. The port connecting the first network device to the communication link can be a physical port, and the ports connecting the first user equipment and the third user equipment to the communication link can also be physical ports. In another possible implementation, the communication link between the first network device and the first user equipment and the third user equipment is a direct link. Furthermore, the communication link between the first network device and the first user equipment may include other network devices, such as customer edge (CE) devices. Similarly, the communication link between the first network device and the third user equipment may also include other network devices. In this embodiment, for Figure 1 The specific form of the user equipment is not restricted. For example,Figure 1 The user equipment in this context can be network equipment used in home or public networks, such as mobile phones, personal computers, tablets, and other terminal devices. For example, Figure 1 The user equipment in the context can also be a computer or server in a corporate network.
[0060] like Figure 1 As shown, the communication network can be an SRv6-based communication network. The first network device can send SRv6 messages to the second network device. Specifically, the first network device receives service messages from the first user equipment or the third user equipment. The first network device encapsulates the service messages into SRv6 messages. Then, the first network device sends the SRv6 messages to the second network device. In one possible implementation, an SRv6 tunnel exists between the first network device and the second network device, through which the first network device sends SRv6 messages to the second network device. The second network device receives the SRv6 messages and decapsulates them to obtain the service messages. Then, the second network device forwards the service messages to the second user equipment or the fourth user equipment.
[0061] However, existing SRv6-based communication networks do not support data forwarding of SRv6 traffic based on user groups and group policies. Furthermore, existing SRv6-based communication networks also lack a scheme for the sender and receiver of SRv6 traffic to jointly determine the forwarding policy for user groups.
[0062] In a related art, a group policy identifier is carried in a virtual extensible local area network (VXLAN) packet. For example, refer to IETF drafts: Generic Protocol Extension for VXLAN (draft-ietf-nvo3-vxlan-gpe-10) and Group Policy Encoding with VXLAN-GPE and LISP-GPE (draft-lemon-vxlan-lisp-gpe-gbp-02). The implementation of the above drafts can be referred to as Generic Protocol Extension for Virtual Extensible Local Area Network (VXLAN-GPE). A generic protocol extension (GPE) header is carried in a VXLAN-GPE packet, and the GPE header includes group policy identifier information. Meanwhile, a reserved field in a VXLAN header in the VXLAN-GPE packet is set to indicate that the GPE header is included in the VXLAN-GPE packet. A sending device and a receiving device implement isolation between user devices by transmitting the VXLAN-GPE packet. The implementation of VXLAN-GPE is similar to the implementation of an access control list (ACL). Compared with the ACL, the implementation of VXLAN-GPE reduces the workload of rule configuration.
[0063] However, VXLAN-GPE can only be implemented in a VXLAN-based network scenario, and the existing VXLAN protocol needs to be modified and the existing network device needs to be upgraded. However, according to the provisions of the VXLAN-based protocol IETF Request For Comments (RFC) 7348 (for example, refer to chapter 5 of RFC 7348): the remaining 7 bits (designated as “R”) are reserved fields, which must be set to zero during transmission and are ignored during reception. Therefore, in the VXLAN network scenario, in order to comply with the provisions of RFC 7348, the network device can discard the VXLAN-GPE packet because the reserved field in the VXLAN header of the VXLAN-GPE packet is set to a non-zero value, and the GPE header can not be identified. Further, the above drafts only disclose how to implement the carrying of the group policy identifier in the existing VXLAN packet, so as to implement the isolation between user devices. However, the above drafts do not disclose the implementation of the specific group policy, and it is more impossible to implement an implementation scheme in which the sending end and the receiving end of the data flow jointly determine the forwarding policy for the user group.
[0064] To solve the above problems, the present application provides a corresponding solution. As shown in Figure 1 The first network device receives a service packet from a first user device. The first network device determines a user group to which the first user device belongs according to information of a source user device carried by the service packet. The first network device determines group information corresponding to the service packet, which is used to indicate an interworking strategy of the first user device and a second user device for transmitting the service packet determined by the first network device based on the user group. The second user device is the destination of the service packet. The first network device encapsulates the service packet to obtain an SRv6 packet, and the SRv6 packet further includes the group information. The first network device sends the SRv6 packet to a second network device according to the determined group information. Therefore, through the above implementation manner, the group information is carried in the SRv6 packet, so that the first network device as a sending end device can participate in the control of the forwarding strategy for the user group.
[0065] For the receiving end device, the second network device decapsulates the SRv6 packet after receiving the SRv6 packet. The second network device determines a user group to which the second user device belongs according to information of a destination user device of the service packet. Then, the second network device determines an interworking strategy of the first user device and the second user device for transmitting the service packet according to the user group to which the second user device belongs. Correspondingly, the second network device can know the interworking strategy of the first user device and the second user device for transmitting the service packet determined by the first network device based on the user group according to the group information carried in the service packet. In this way, the second network device determines a forwarding strategy for forwarding the service packet to the second user device according to the interworking strategy determined by the first network device (sending end) and the interworking strategy determined by the second network device (receiving end). Therefore, through the above implementation manner, the group information is carried in the SRv6 packet, so that the second network device as a receiving end device can control the forwarding strategy for the user group according to the interworking strategy determined by the sending end device and the interworking strategy determined by the receiving end device.
[0066] Figure 2 A packet forwarding method flowchart of an embodiment of the present application. Figure 2 The method shown can be applied in Figure 1 The network structure shown. In the present application, the interaction between the first network device and the second network device in Figure 1 should be understood that the communication link between the first network device and the second network device can include other network devices. Specifically, the method comprises:
[0067] S101, the first network device receives a first service packet sent by a first user device, wherein the first service packet comprises information of the first user device.
[0068] Referring to Figure 1 , the first network device communicates with the first user device, and in a possible implementation, a communication link between the first network device and the first user device comprises other network devices. The first user device generates the first service packet. The embodiments of the present application do not limit the encapsulation format of the first service packet. For example, the first service packet can be a layer 2 Ethernet frame, and for another example, the first service packet can be an IP packet.
[0069] The first service packet comprises information of the first user device, and the information of the first user device is used to indicate the first user device. In a possible implementation, the information of the first user device is address information, and specifically, the information of the first user device comprises a media access control (MAC) address or an IP address. The first user device is a sending end device of the first service packet. Therefore, the MAC address comprised in the information of the first user device is a source MAC address of the first service packet, and the IP address comprised in the information of the first user device is a source IP address of the first service packet.
[0070] The first service packet can further comprise information of a second user device. As Figure 1 indicated, the first service packet sent by the first user device is sent to the second user device. Therefore, the information of the second user device is used to indicate the second user device. In a possible implementation, the information of the second user device is address information, and specifically, the information of the second user device comprises a MAC address or an IP address. The second user device is a receiving end device of the first service packet. Therefore, the MAC address comprised in the information of the second user device is a destination MAC address of the first service packet, and the IP address comprised in the information of the second user device is a destination IP address of the first service packet.
[0071] The first service packet includes a packet header and a payload. The packet header in the first service packet is used to carry information of the first user equipment and information of the second user equipment. The payload in the first service packet is service data that the first user equipment hopes to send to the second user equipment. The first network equipment receives the first service packet sent by the first user equipment. In an actual service scenario, the first network equipment receives a service flow sent by the first user equipment, and the service flow includes a plurality of service packets. The first service packet can be understood as any one service packet or any plurality of service packets in the service flow. Therefore, the implementation manner of the present application can be understood as an implementation manner of performing group policy forwarding on a data flow from a user equipment based on a user group.
[0072] S102, the first network equipment determines whether the first network equipment includes a first user group corresponding to the information of the first user equipment, the first user group being a user group to which the first user equipment belongs;
[0073] S103, according to a determination result of whether the first network equipment includes the first user group corresponding to the information of the first user equipment, the first network equipment determines a value of first group information and generates a first SRv6 packet, the first SRv6 packet including the first group information and the first service packet, the first group information being used to indicate an interworking policy determined by the first network equipment based on the first user group for the first user equipment and the second user equipment to transmit the first service packet;
[0074] The first network equipment receives the first service packet sent by the first user equipment. After receiving the first service packet, the first network equipment parses the first service packet and obtains the information of the first user equipment in the first service packet. The first network equipment determines whether the first network equipment includes a first user group corresponding to the information of the first user equipment. The first user group is a user group to which the first user equipment belongs. That is, the mutual isolation of the user group to the user equipment is an implementation manner. For example, the first network equipment is connected with user equipment 1, user equipment 2, user equipment 3 and user equipment 4. The user equipment 1 and the user equipment 2 belong to the user group 1, the user equipment 3 belongs to the user group 2, and the user equipment 4 belongs to the user group 3. Therefore, one user group can include one or more user equipments. The first network equipment can determine to which user group the user equipment that sends the service packet belongs according to the information in the service packet received from the user equipment.
[0075] In a particular implementation, the first network device can store at least one table item, each of the at least one table item including a corresponding relationship between user equipment information and a user group, wherein the user equipment information is user equipment information of a user equipment sending a service message, such as a source MAC address or a source IP address. For the convenience of description, the user equipment information in Table 1 is referred to as source user equipment information, the user equipment in Table 1 is referred to as a source user equipment, and the user group in Table 1 is referred to as a source user group. As shown in Table 1, the first user equipment information corresponds to the first user group, indicating that the first user equipment belongs to the first user group; the third user equipment information corresponds to the third user group, indicating that the third user equipment belongs to the third user group. It should be noted that the representation of Table 1 is to clearly show the belonging of the source user equipment. In an implementation, the table item stored in the first network device can not include
[0076] The first column information (source user equipment) in Table 1.
[0077] Source user equipment Information of the source user equipment Source user group First user equipment Information of the first user equipment First user group Third user equipment Information of the third user equipment Third user group User equipment 1 Information of the user equipment 1 First user group User equipment 4 Information of the user equipment 4 Third user group … … …
[0078] Table 1
[0079] After the first network device obtains the first user equipment information in the first service message, the first network device queries the at least one table item (as shown in Table 1) stored in the first network device according to the first user equipment information. According to the corresponding relationship between the first user equipment information and the first user group, the first network device determines that the user group corresponding to the first user equipment information is the first user group. Therefore, the first network device can determine that the first user equipment belongs to the first user group.
[0080] In a possible implementation, the source user group in Table 1 can be represented in the form of a group identifier. For example, the first user group can be represented by a group identifier Group_ID_1, and the third user group can be represented by a group identifier Group_ID_3. In a possible implementation, the group identifier can be represented by 16-bit length data. Accordingly, when the first network device stores the table item shown in Table 1, the group identifier can be stored as the source user group. Therefore, the group identifier is used to indicate the user group, and it can also be understood that the group identifier is used to indicate the user group to which the user equipment belongs.
[0081] The first network device can generate a first SRv6 packet according to the received first service packet. The first SRv6 packet is a packet obtained by encapsulating the first service packet. The first service packet can be encapsulated in the first SRv6 packet as a payload. The first SRv6 packet further includes first group information, which is used to indicate an interworking policy of the first user device and the second user device for transmitting the first service packet determined by the first network device based on the first user group. The first group information indicates that the first network device determines the interworking policy of the first network device and the second network device for the first service packet belonging to the first user group. Among them, the interworking policy determined by the first network device is the forwarding policy expected by the first network device. That is, the first network device expects that the second network device forwards the first service packet to the destination according to the rule of the interworking policy given by the first network device after receiving the first service packet. For example, the first network device determines the value of the first group information so as to indicate that the first service packet can be forwarded to the second user device by the second network device after reaching the second network device. For another example, the first network device determines the value of the first group information so as to indicate that the first service packet can be discarded (not forwarded to the second user device) by the second network device after reaching the second network device. Therefore, the first group information is determined by the first network device, which affects whether the first service packet can be forwarded to the second user device.
[0082] In a possible implementation, the first group information includes the first group identifier.
[0083] For example, the first group identifier is used as the first group information. According to the table entry shown in Table 1, the first network device determines that the first user device sending the first service packet belongs to the first user group, which is represented as the first group identifier. Therefore, the first group identifier indicates that the first user device belongs to the first user group. The first network device determines the value of the first group information as the first group identifier, and the first network device generates the first SRv6 packet including the first group information. It can be understood that when the value of the first group information is the first group identifier, the specific interworking policy indicated is that the first network device forwards the first service packet, and expects that the second network device can forward the first service packet to the second network device.
[0084] For example, the first network device cannot find a corresponding user according to the received service packet. For example, the first network device cannot find a corresponding user group in the table item shown in Table 1 according to the first service packet. This indicates that the first user device does not belong to any user group. Based on this, the first network device determines the value of the first group identifier as an invalid value, for example, set to all 0, and correspondingly, the value of the first group information indicates an invalid value, i.e., all 0. Then, the first network device generates the first SRv6 packet including the first group information (invalid value). It can be understood that in the case that the value of the first group information is invalid, the specific interworking strategy indicated is that the first network device forwards the first service packet, and hopes that the second network device can discard the first service packet.
[0085] In another possible implementation, the first group information includes the first group identifier and a first group policy identifier. Figure 3 A format of group information is shown. Figure 3 The group information in Table 1 includes a group identifier and a group policy identifier. For example, the total length of the group information is 16 bits, of which the highest three bits are used to represent the group policy identifier, and the remaining 13 bits are used to represent the group identifier. Figure 3 An implementation in which the group identifier and the group policy identifier are in the same field is shown. It should be understood that the group identifier and the group policy identifier can be implemented in different fields. In combination with the foregoing, the first group identifier in the first group information is used to indicate the user group to which the first user device belongs; the first group policy identifier in the first group information is used to indicate the specific interworking strategy. That is, the first group policy identifier is used to indicate the specific interworking strategy determined by the first network device based on the first user group for the first user device and the second user device to transmit the first service packet. In an actual scenario, the first network device can determine that the first user device belongs to the first user group according to the information of the first user device in the first service packet in the foregoing implementation, thereby determining the value of the first group identifier. Then, the first network device determines the value of the first group policy identifier according to the interworking strategy stored by the first network device and the first group identifier. Therefore, the first network device can determine the value of the first group information, so that the first network device can determine the interworking strategy for the first user device and the second user device to transmit the first service packet based on the first user group.
[0086] For example, the first group information includes the first group identifier and a first group policy identifier, and the first group policy identifier includes a first identifier. The first identifier indicates that the first network device includes the first user group and the second network device does not include the second user group, and the second user group is a user group to which the second user device belongs, and the second user device is a user device receiving the first service packet. In combination with the foregoing, the first network device determines, according to the first service packet, that the first user device matches the first user group. The first network device indicates the first group identifier in the first group information as the first user group, and the first network device determines a specific interworking policy according to a result that the first user device can match the first user group. According to the foregoing, the total length of the group information is 16 bits, and the highest three bits are used to represent a group policy identifier. Specifically, the first identifier (for example, the highest bit in the highest three bits) is used to represent the first identifier. The meaning of the first identifier is that the source user device has a user group and the destination user device has no user group. Since the first network device determines that the first user device can match the first user group, the first network device enables the first identifier (the first bit) to be valid. Further, the first network device can set the value of the first identifier according to a locally stored interworking policy. The value of the first identifier specifically indicates a forwarding policy of the first network device for the first service packet to the second network device. For example, the value of the first identifier is 1, indicating that the first network device expects the second network device to forward the first service packet to the second user device. For another example, the value of the first identifier is 0, indicating that the first network device expects the second network device to discard the first service packet.
[0087] For example, the first group information includes the first group identifier and a first group policy identifier, and the first group policy identifier includes a second identifier and a third identifier. The second identifier is used to indicate that the first network device does not include the first user group and the second network device includes the second user group. The third identifier is used to indicate that the first network device does not include the first user group and the second network device does not include the second user group. In combination with the foregoing, the first network device determines, according to the first service packet, that none of the entries stored by the first network device can match the user group of the first user device. The first network device indicates the first group identifier in the first group information as invalid, and the first network device determines a specific interworking policy according to the result that the first user device does not match the user group. According to the foregoing, the total length of the group information is 16 bits, of which the highest three bits are used to represent the group policy identifier. Specifically, the second identifier is represented by the second bit (for example, the second highest bit in the highest three bits), and the third identifier is represented by the third bit. The meaning of the second identifier is “source user device without user group, and destination user device with user group”; and the meaning of the third identifier is “source user device without user group, and destination user device without user group”. Since the first network device determines that the first user device does not match the user group, and the first network device does not know whether the second network device can match the user group after receiving the first service packet, the first network device enables the second identifier (the second bit) and the third identifier (the third bit) to be valid. Further, the first network device can set the value of the second identifier and the value of the third identifier according to the locally stored interworking policy. The value of the second identifier specifically indicates the forwarding policy of the first network device for the first service packet to the second network device. The value of the third identifier specifically indicates the forwarding policy of the first network device for the first service packet to the second network device. For example, the value of the second identifier is 1, and the value of the third identifier is 0, which indicates that the first network device expects the second network device to forward the first service packet to the second user device in the case of matching the user group according to the first service packet, and the first network device expects the second network device to discard the first service packet in the case of not matching the user group according to the first service packet. For another example, the value of the second identifier is 0, and the value of the third identifier is 1, which indicates that the first network device expects the second network device to discard the first service packet in the case of matching the user group according to the first service packet, and the first network device expects the second network device to forward the first service packet to the second user device in the case of not matching the user group according to the first service packet.
[0088] In the above implementation manner, the first group policy identifier is used to indicate that the first network device matches the user group according to the first service message, and is also used to indicate that the second network device matches the user group according to the service message. In this way, after the second network device obtains the first service message, the second network device can know the interworking policy configured by the first network device by parsing the first group policy identifier in the first group information. Therefore, the second network device does not need to parse the first group identifier in the first group information. Thus, the processing speed of the second network device for the first service message is improved.
[0089] In another possible implementation manner, the first group information includes a first group identifier and a first group policy identifier. The first group policy identifier is used to indicate that the second network device matches the user group according to the service message, and is not used to indicate that the first network device matches the user group according to the first service message.
[0090] For example, the first group policy identifier includes a fourth identifier. The implementation manner of the fourth identifier can refer to the implementation manner of the first identifier. Different from the first identifier, the fourth identifier is used to indicate that the second network device does not include a second user group, and the fourth identifier is not used to indicate that the first network device matches the user group according to the first service message. The meaning of the fourth identifier is: "destination user equipment has no user group". In this way, the first group identifier and the fourth identifier jointly indicate: "source user equipment has a user group, and destination user equipment has no user group".
[0091] For example, the first group policy identifier includes a fifth identifier and a sixth identifier. The implementation manner of the fifth identifier can refer to the implementation manner of the second identifier. Different from the second identifier, the fifth identifier is used to indicate that the second network device includes a second user group, and the fifth identifier is not used to indicate that the first network device matches the user group according to the first service message. The meaning of the fifth identifier is: "destination user equipment has a user group". In this way, the first group identifier and the fifth identifier jointly indicate: "source user equipment has no user group, and destination user equipment has a user group". Correspondingly, the implementation manner of the sixth identifier can refer to the implementation manner of the third identifier. Different from the third identifier, the sixth identifier is used to indicate that the second network device does not include a second user group, and the sixth identifier is not used to indicate that the first network device matches the user group according to the first service message. The meaning of the sixth identifier is: "destination user equipment has no user group". In this way, the first group identifier and the sixth identifier jointly indicate: "source user equipment has no user group, and destination user equipment has no user group".
[0092] In the foregoing implementation, the second network device can know the interworking policy configured by the first network device by analyzing the first group of identifiers and the first group of policy identifiers in the first group of information after obtaining the first service packet.
[0093] In combination with the foregoing, the first group of information is carried in a first SRv6 packet, and the first SRv6 packet is a packet obtained by the first network device encapsulating the first service packet. Figure 4 A header format of an SRv6 packet is shown in an embodiment of the present application. As shown in Figure 4 The SRv6 header includes an IPv6 header and a segment routing header (SRH), and optionally, the SRv6 header can further include a hop-by-hop options header (HBH) and / or a destination options header (Destination Options Header). In the present application, the segment routing header can be denoted as SRH, and the hop-by-hop options header can be denoted as HBH. The first group of information can be carried in the IPv6 header, or the first group of information can be carried in the HBH, or the first group of information can be carried in the destination options header, or the first group of information can be carried in the SRH. In a possible implementation, the first group of information includes the first group of identifiers. Therefore, the first group of identifiers can be carried in the IPv6 header, or the HBH, or the destination options header, or the SRH. In another possible implementation, the first group of information includes the first group of identifiers and the first group of policy identifiers. Therefore, the first group of identifiers and the first group of policy identifiers can be carried in the IPv6 header, or the HBH, or the destination options header, or the SRH. In addition, the first group of identifiers and the first group of policy identifiers can be carried in the same field, as shown in Figure 3 The first group of identifiers and the first group of policy identifiers can also be carried in different fields of the same header, or in different fields of different headers. For example, the first group of identifiers is carried in the IPv6 header, and the first group of policy identifiers is carried in the SRH. The following will be specifically described by taking the first group of information as an example.
[0094] For example, according to the definition of RFC8200, the IPv6 header (Section 3 of RFC8200) includes next header information, which can also be referred to as next header field. If the value of the next header information in the IPv6 header is 0, it indicates that the next header of the IPv6 header is the HBH option header. Wherein, the next header of the IPv6 header means that the HBH option header immediately follows the IPv6 header. Specifically, the HBH header is encapsulated between the IPv6 header and the payload, and is adjacent to the IPv6 header. According to the explanation of Section 4.3 of RFC8200, the HBH option header is processed by each hop network device on the path of the SRv6 packet. Further, the HBH option header includes option information, which is processed by each hop network device on the path of the SRv6 packet. The IPv6 header also includes version information, traffic class information, flow label information, payload length information, hop limit information, source address information and destination address information. Wherein, the length of the flow label information is 20 bits. In a possible implementation, the flow label information is used to carry the first group of information. Specifically, part of the length (for example, 16 bits) of the flow label information is used as the first group of information. The remaining part of the length (4 bits) of the flow label information remains the original flow label function. In addition, a flag bit (length of 1 bit) can also be set in the traffic class information, which is used to indicate that the first group of information is included in the flow label information.
[0095] For example, referring to the explanation of section 4.3 of RFC8200, the HBH option header includes next header information, header extension length (hdr ext len) information and options. A first option is defined in the options, and the first option is used to carry the first set of information. Specifically, the first option includes option type information, option data length (opt data len) information and option data, wherein the option data is used to carry the first set of information. In the implementation of carrying the first set of information based on the HBH option header, the second network device needs to enable the configuration of processing the option. Correspondingly, when the first network device and the second network device include other network devices, the other network devices can not enable the configuration of processing the option. In addition, the flag bit mentioned above can also be used to indicate that the first set of information is included in the HBH option header.
[0096] For example, referring to the explanation of section 4.6 of RFC8200, the destination option header includes next header information, header extension length (hdr ext len) information and options. A second option is defined in the options, and the second option is used to carry the first set of information. Specifically, the second option includes option type information, option data length (opt data len) information and option data, wherein the option data is used to carry the first set of information. In addition, the flag bit mentioned above can also be used to indicate that the first set of information is included in the destination option header.
[0097] For example, referring to the explanation in section 2 of RFC8754, the SRH includes next header (next header) information, header extension length (header extension length) information, routing type (routing type) information, remaining segments (segments left) information, last entry (last entry) information, flags, a tag, and segment list information. Optionally, the SRH can also include SRH TLV (TLV: type-length-value) information. In a possible implementation, the first group of information can be carried in the tag. Further, a partial length (for example, 16 bits) of the tag can be used as the first group of information. The remaining partial length in the tag remains the original tag function. In addition, a flag bit (length of 1 bit) can also be set in the flag, which is used to indicate that the first group of information is included in the SRH. In another possible implementation, the first group of information can be carried in the SRH TLV. In yet another possible implementation, the first group of information can be carried in the segment list information.
[0098] S104, the first network device sends the first SRv6 packet to the second network device.
[0099] S105, the second network device receives the first SRv6 packet sent by the first network device.
[0100] The first network device generates the first SRv6 packet according to the implementation manner of S102 and S103, and the first SRv6 packet includes the first group of information and the first service packet. The information of the first user device can be a source IP address included in the first service packet, or the information of the first user device can be a source MAC address included in the first service packet. In a possible implementation manner, the first network device and the second network device include an SRv6 tunnel. The first network device sends the first SRv6 packet to the second network device based on the SRv6 tunnel. The second network device receives the first SRv6 packet. Wherein, other network devices can be included on the SRv6 tunnel between the first network device and the second network device.
[0101] S106, the second network device determines whether the second network device includes a second user group corresponding to the information of the second user device, the second user group being a user group to which the second user device belongs.
[0102] S107. According to the determination result of whether the second network device includes a second user group corresponding to the information of the second user device and the first group information, the second network device determines a forwarding policy of forwarding the first service packet to the second user device.
[0103] The second network device receives the first SRv6 packet, and decapsulates the first SRv6 packet to obtain the first group information and the first service packet. The first service packet is destined for the second user device, as shown in FIG. 1, the second user device communicates with the second network device. The first service packet includes information of the second user device, and the information of the second user device is used to indicate the second user device. In a possible implementation, the information of the second user device is address information, and specifically, the information of the second user device includes a MAC address or an IP address. The second user device is a receiving end device of the first service packet. Therefore, the MAC address included in the information of the second user device is a destination MAC address of the first service packet, and the IP address included in the information of the second user device is a destination IP address of the first service packet. Figure 1
[0104] The second network device determines whether the second network device includes a second user group corresponding to the information of the second user device, and the second user group is a user group to which the second user device belongs. In a specific implementation, as shown in Table 1, the second network device can store at least one table entry, and each table entry in the at least one table entry includes a correspondence between user device information and a user group, wherein the user device information is user device information of a user device receiving a service packet, for example, a destination MAC address or a destination IP address. For convenience of description, the user device information in Table 2 is referred to as destination user device information, the user device in Table 2 is referred to as a destination user device, and the user group in Table 2 is referred to as a destination user group. As shown in Table 2, the information of the second user device corresponds to the second user group, indicating that the second user device belongs to the second user group; the information of the fourth user device corresponds to the fourth user group, indicating that the fourth user device belongs to the fourth user group. It should be noted that the representation of Table 2 is for the purpose of clearly showing the belonging of the destination user device, and in implementation, the table entry stored in the second network device can not include the first column information (destination user device) in Table 2.
[0105] Destination user equipment Information of the destination user equipment Destination user group Second user equipment Information of the second user equipment Second user group Fourth user equipment Information of the fourth user equipment Fourth user group User equipment 2 Information of the user equipment 2 Second user group User equipment 3 Information of the user equipment 3 Fourth user group … … …
[0106] Table 2
[0107] The second network device acquires the information of the second user device in the first service packet, and queries the at least one table item (as shown in Table 2) stored in the second network device according to the information of the second user device. The second network device determines, according to the correspondence between the information of the second user device and the second user group, that the user group corresponding to the information of the second user device is the second user group. Therefore, the second network device can determine that the second user device belongs to the second user group.
[0108] In a possible implementation, the destination user group in Table 2 can be represented in the form of a group identifier. For example, the second user group can be represented by group identifier header 2, and the fourth user group can be represented by group identifier Group_ID_4. In a possible implementation, the group identifier can be represented by data with a length of 16 bits. Accordingly, when the second network device stores the table item shown in Table 2, the group identifier can be stored as the destination user group. Therefore, the group identifier is used to indicate the user group, and it can also be understood that the group identifier is used to indicate the user group to which the user device belongs.
[0109] According to the foregoing, the first service packet includes the first group information. The first group information is used to indicate the interworking strategy of the first user device and the second user device for transmitting the first service packet, which is determined by the first network device based on the first user group. That is, the second network device can obtain the interworking strategy of the first user device and the second user device for transmitting the first service packet, which is determined by the first network device based on the first user group, by analyzing the first service packet. Accordingly, according to the determination result of whether the second network device includes the second user group corresponding to the information of the second user device, the second network device determines the interworking strategy of the first user device and the second user device for transmitting the first service packet, which is determined by the second network device based on the second user group. Then, the second network device determines the forwarding strategy of forwarding the first service packet to the second user device according to the interworking strategy determined by the first network device and the interworking strategy determined by the second network device.
[0110] In the above implementation, the second network device considers the interworking policy determined by the first network device and the interworking policy determined by the second network device simultaneously in determining the forwarding policy for forwarding the first service packet to the second user device. The interworking policy determined by the first network device indicates that the first network device expects the second network device to forward the first service packet according to the interworking policy determined by the first network device. The interworking policy determined by the second network device indicates that the second network device determines the interworking policy based on a local policy according to a case that a user group is matched in the destination address in the first service packet. In a possible implementation, the second network device stores at least one table item, and the at least one table item indicates a corresponding relationship between a "source end interworking policy" and a "destination end interworking policy" and a "forwarding policy", as shown in Table 3.
[0111] Source interworking policy Destination interworking policy Forwarding policy Interworkable Interworkable Forward Interworkable Non-interworkable Randomly discarded Non-interworkable Interworkable Rate-limited forwarding Non-interworkable Non-interworkable Discarded
[0112] Table 3
[0113] As shown in Table 3, the "source end interworking policy" indicates the interworking policy determined by the first network device based on the first user group for the first user device and the second user device to transmit the first service packet, and the specific implementation can be referred to the foregoing embodiments. The interworking policy determined by the first network device can reflect whether the first network device expects the first service packet to be forwarded on the second network device. For example, in the implementation in which the first group information includes the first group identifier, when the value of the first group identifier indicates the first user group, the first network device expects the first service packet to be forwarded on the second network device, and the source end interworking policy is "interworkable". Correspondingly, when the value of the first group identifier indicates an invalid value, the first network device does not expect the first service packet to be forwarded on the second network device, and the source end interworking policy is "non-interworkable". For another example, in the implementation in which the first group information includes the first group identifier and the first policy identifier, when the value of the identifier included in the first policy identifier is 1, the first network device expects the first service packet to be forwarded on the second network device, and the source end interworking policy is "interworkable". Correspondingly, when the value of the identifier included in the first policy identifier is 0, the first network device does not expect the first service packet to be forwarded on the second network device, and the source end interworking policy is "non-interworkable".
[0114] As shown in Table 3, the "destination end intercommunication policy" indicates an intercommunication policy of the first user equipment and the second user equipment for transmitting the first service message determined by the second network equipment based on the second user group. The intercommunication policy determined by the second network equipment can reflect whether the second network equipment expects the first service message to be forwarded on the second network equipment. In a possible implementation, the second network equipment determines the intercommunication policy according to the second user group based on a local policy. In another possible implementation, the second network equipment determines the intercommunication policy according to the first user group and the second user group based on a local policy. It should be understood that the specific forwarding policies shown in Table 3 are exemplary.
[0115] The following describes different implementations based on the first group information respectively.
[0116] For example, the first set of information includes the first set of identifiers. After receiving the first SRv6 packet, the second network device obtains the first set of information in the first SRv6 packet. The second network device determines a source interworking policy according to the first set of identifiers included in the first set of information. For example, the value of the first set of identifiers indicates the first user group, and the second network device can determine that the source interworking policy is "interworkable". For another example, the value of the first set of identifiers indicates an invalid value, and the second network device can determine that the source interworking policy is "non-interworkable". The second network device determines whether the second network device includes a second user group corresponding to information of the second user device according to the first service packet. If the second network device determines that the second network device includes the second user group corresponding to the information of the second user device, the second network device can determine that the destination interworking policy is "interworkable". If the second network device determines that the second network device does not include the second user group corresponding to the information of the second user device, the second network device can determine that the destination interworking policy is "non-interworkable". After determining the source interworking policy and the destination interworking policy, the second network device can determine a forwarding policy for forwarding the first service packet to the second user device according to the implementation manner of Table 3. For example, the source interworking policy is "interworkable", and the destination interworking policy is "interworkable", and the second network device determines that the forwarding policy is "forward", that is, the second network device forwards the first service packet to the second user device. For another example, the source interworking policy is "interworkable", and the destination interworking policy is "non-interworkable", and the second network device determines that the forwarding policy is "randomly discarded", that is, the second network device forwards the first service packet to the second user device in a random discarding manner. Wherein, "in a random discarding manner" means that the second network device determines whether the first service packet is sent to the second user device according to a preset random parameter. Therefore, the first service packet has a certain probability of being sent to the second user device, and for the same reason, the first service packet also has a certain probability of being discarded by the second network device.
[0117] For example, the first set of information includes the first set of identifiers and the first set of policy identifiers, and the first set of policy identifiers includes the first identifier. The first identifier indicates that the first network device includes the first user group and the second network device does not include the second user group. The second network device determines that the second user group corresponding to the information of the second user device is not included in the second network device. Thus, the second network device can know that the first identifier is consistent with the result determined by the second network device. If the value of the first identifier is 1, the second network device determines that the source intercommunication policy is "intercommunicable" according to the value of the first identifier. If the value of the first identifier is 0, the second network device determines that the source intercommunication policy is "non-intercommunicable" according to the value of the first identifier. Correspondingly, the second network device can determine the destination intercommunication policy according to the matching of the second user group based on the local policy. For example, the second network device determines that the information of the second user device matches the second user group, and the second network device determines that the destination intercommunication policy is "intercommunicable". For another example, the second network device determines that the information of the second user device does not match any user group, and the second network device determines that the destination intercommunication policy is "non-intercommunicable". The second network device can determine the destination intercommunication policy according to the matching of the second user group and the matching of the first user group based on the local policy. For example, the first user group can match and the second user group cannot match, and the second network device determines that the destination intercommunication policy is "non-intercommunicable". For another example, the first user group can match and the second user group can match, and the second network device determines that the destination intercommunication policy is "intercommunicable". After determining the source intercommunication policy and the destination intercommunication policy, the second network device can determine the forwarding policy of forwarding the first service packet to the second user device according to the implementation mode of Table 3. For example, the source intercommunication policy is "non-intercommunicable", and the destination intercommunication policy is "non-intercommunicable", and the forwarding policy determined by the second network device is "discarding", that is, the second network device discards the first service packet. For another example, the source intercommunication policy is "non-intercommunicable", and the destination intercommunication policy is "intercommunicable", and the forwarding policy determined by the second network device is "limited-rate forwarding", that is, the second network device forwards the first service packet to the second user device in a limited-rate forwarding manner. The "limited-rate forwarding manner" means that the second network device forwards the first service packet to the second user device and limits the forwarding rate to not exceed the set rate.
[0118] In the foregoing embodiment, no indication is given that the first network device comprises the first user group and the second network device comprises the second user group. The reason is that in this case, the first network device and the second network device can determine the final forwarding policy through the case of group identification. It should be understood that in a more specific implementation scenario, the above-mentioned identification can also be configured to indicate that the first network device comprises the first user group and the second network device comprises the second user group. The determination of the specific interworking policy and forwarding policy can refer to the foregoing implementation mode, which will not be described here.
[0119] For example, the first group information comprises the first group identification and the first group policy identification, and the first group policy identification comprises the second identification and the third identification. The second identification is used to indicate that the first network device does not comprise the first user group and the second network device comprises the second user group. The third identification is used to indicate that the first network device does not comprise the first user group and the second network device does not comprise the second user group. The second network device determines whether the second network device comprises the second user group corresponding to the information of the second user device according to the first service packet. If the second network device determines that the second network device comprises the second user group corresponding to the information of the second user device, the second network device determines the source end interworking policy according to the second identification. If the second network device determines that the second network device does not comprise the second user group corresponding to the information of the second user device, the second network device determines the source end interworking policy according to the third identification. Further, if the value of the second identification or the third identification is 1, the second network device determines that the source end interworking policy is "interworkable" according to the value of the second identification or the third identification. If the value of the second identification or the third identification is 0, the second network device determines that the source end interworking policy is "non-interworkable" according to the value of the second identification or the third identification. Correspondingly, the second network device can determine the destination end interworking policy according to the matching condition of the second user group based on the local policy, and the specific implementation mode can refer to the foregoing embodiment, which will not be described here. After determining the source end interworking policy and the destination end interworking policy, the second network device can determine the forwarding policy of forwarding the first service packet to the second user device according to the implementation mode of Table 3.
[0120] For example, the first group information comprises the first group identification and the first group policy identification, and the first group policy identification comprises the fourth identification, which is used to indicate that the second network device does not comprise the second user group. The implementation mode of the second network device for determining the forwarding policy can refer to the foregoing implementation mode of the first identification, which will not be described here.
[0121] For example, the first set of information includes the first set of identifiers and the first set of policy identifiers, the first set of policy identifiers includes a fifth identifier and a sixth identifier, the fifth identifier is used to indicate that the second network device includes a second user group, and the sixth identifier is used to indicate that the second network device does not include a second user group. The second network device determines the implementation manner of the forwarding policy, which can be referred to the foregoing implementation manners of the second identifier and the third identifier, and details are not described herein.
[0122] In the foregoing implementation manners, the source interconnection policy is a first set of policies, which can be identified by a first set of policy identifiers; correspondingly, the destination interconnection policy is a second set of policies, which can be identified by a second set of policy identifiers. The specific group policy included in the second set of policies can be a sub-policy. For example, the second set of policies includes a first sub-policy, and the first sub-policy indicates an interconnection policy determined by the second user group in a case where the first network device includes the first user group and the second network device does not include the second user group. For example, the second set of policies includes a second sub-policy, and the second sub-policy indicates an interconnection policy determined by the second user group in a case where the first network device does not include the first user group and the second network device includes the second user group.
[0123] Through the foregoing implementation manners, the SRv6 packet transmitted between the first network device and the second network device carries group information, so that the second network device as a receiving end device can control the forwarding policy of the user group according to the interconnection policy determined by the sending end device and the interconnection policy determined by the receiving end device.
[0124] Figure 5 A structure diagram of the first network device 1000 of an embodiment of the present application is shown. Figure 5 The first network device 1000 shown can perform the corresponding steps performed by the second network device in the method of the foregoing embodiments. The second network device 1000 is deployed in a communication network, and the communication network further includes a second network device. As shown in Figure 5 As shown, the first network device 1000 includes a receiving unit 1002, a processing unit 1004, and a sending unit 1006.
[0125] The receiving unit 1002 is configured to receive a first service packet sent by a first user device, the first service packet including information of the first user device, and a destination of the first service packet being a second user device.
[0126] The processing unit 1004 is configured to determine whether a first user group corresponding to the information of the first user device is included in the first network device, the first user group being a user group to which the first user device belongs.
[0127] According to a determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network equipment, the processing unit 1004 is further configured to determine a value of the first group information and generate a first SRv6 packet, the first SRv6 packet including the first group information and the first service packet, the first group information being used to indicate an interworking strategy of the first user equipment and the second user equipment for transmitting the first service packet based on a determination of the first network equipment.
[0128] The sending unit 1006 is configured to send the first SRv6 packet to a second network equipment in communication with the second user equipment.
[0129] Optionally, the first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the processing unit 1004 determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network equipment, including: in response to the processing unit 1004 determining that the first user group corresponding to the information of the first user equipment is included in the first network equipment, the processing unit 1004 is configured to determine that the value of the first group identifier indicates the first user group.
[0130] Optionally, the first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the processing unit 1004 determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network equipment, including: in response to the processing unit 1004 determining that the first user group corresponding to the information of the first user equipment is not included in the first network equipment, the processing unit 1004 is configured to determine that the value of the first group identifier indicates invalid.
[0131] Optionally, the first group information includes a first group identifier and a first group policy identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first group policy identifier being used to indicate a specific interworking strategy.
[0132] Optionally, the first group policy identifier includes a first identifier, the first identifier being used to indicate that the first network device includes the first user group and the second network device does not include the second user group, the second user group being a user group to which the second user device belongs, and the processing unit 1004 determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: in response to the processing unit 1004 determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit 1004 is configured to determine that the value of the first group identifier indicates the first user group and determine the value of the first identifier.
[0133] Optionally, the first group policy identifier includes a second identifier and a third identifier, the second identifier being used to indicate that the first network device does not include the first user group and the second network device includes the second user group, and the third identifier being used to indicate that the first network device does not include the first user group and the second network device does not include the second user group, the second user group being a user group to which the second user device belongs, and the processing unit 1004 determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: in response to the processing unit 1004 determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit 1004 is configured to determine that the value of the first group identifier indicates invalid and determine the value of the second identifier and the value of the third identifier.
[0134] Optionally, the first group policy identifier includes a fourth identifier, the fourth identifier being used to indicate that the second network device does not include the second user group, the second user group being a user group to which the second user device belongs, and the processing unit 1004 determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: in response to the processing unit 1004 determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit is configured to determine that the value of the first group identifier indicates the first user group and determine the value of the fourth identifier.
[0135] Optionally, the first group policy identifier includes a fifth identifier and a sixth identifier, the fifth identifier is used to indicate that the second network device includes a second user group, and the sixth identifier is used to indicate that the second network device does not include a second user group, the second user group is a user group to which the second user device belongs, and the processing unit 1004 determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: in response to the processing unit 1004 determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit 1004 is configured to determine that the value of the first group identifier indicates invalidity and determine the value of the fifth identifier and the value of the sixth identifier.
[0136] Optionally, the first group identifier is carried in any one of the following headers included in the first SRv6 message: an IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
[0137] Optionally, the first group policy identifier is carried in any one of the following headers included in the first SRv6 message: an IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
[0138] Optionally, the first SRv6 message is transmitted via an SRv6 tunnel between the first network device and the second network device.
[0139] Optionally, the information of the first user device is a source IP address included in the first service message, or the information of the first user device is a source MAC address included in the first service message.
[0140] Figure 5 The first network device 1000 shown can perform the corresponding steps performed by the first network device in the method of the above-mentioned embodiments. The first network device carries group information in the SRv6 message sent to the second network device, so that the first network device as a sending end device can participate in the control of determining the forwarding policy for the user group.
[0141] Figure 6 The first network device 1100 of the embodiment of the present application is a hardware structure diagram. Figure 6 The first network device 1100 shown can perform the corresponding steps performed by the first network device in the method of the above-mentioned embodiments.
[0142] As Figure 6As shown, the first network device 1100 includes a processor 1101, a memory 1102, an interface 1103 and a bus 1104. The interface 1103 can be implemented by wireless or wired manner. The processor 1101, the memory 1102 and the interface 1103 are connected through the bus 1104.
[0143] The interface 1103 can specifically include a transmitter and a receiver, for transmitting and receiving information between the first network device and the second network device in the above embodiments, and for transmitting and receiving information between the first network device and the first user device in the above embodiments. For example, the interface 1103 is configured to support receiving the first service packet sent by the first user device. In addition, the interface 1103 is configured to support sending the first SRv6 packet to the second network device. As an example, the interface 1103 is configured to support the processes S101 and S104 in FIG. 11. Figure 2 The processor 1101 is configured to perform the processes performed by the first network device in the above embodiments. For example, the processor 1101 is configured to perform the actions of determining the user group of the first user device, determining the interworking policy according to the determination result, and generating the first SRv6 packet; and / or other processes of the techniques described herein. As an example, the processor 1101 is configured to support the processes S102 and S103 in FIG. 11. Figure 2 The memory 1102 is configured to store programs, codes or instructions, for example, the action system 11021 and the application program 11022, which can complete the processes involving the first network device in the method embodiments when the processor or the hardware device executes these programs, codes or instructions. Optionally, the memory 1102 can include a read-only memory (ROM) and a random access memory (RAM). The ROM includes a basic input / output system (BIOS) or an embedded system; and the RAM includes an application program and an action system. When the first network device 1100 needs to be run, the first network device 1100 is started by the BIOS or the bootloader in the embedded system solidified in the ROM, and is guided to a normal running state. After the first network device 1100 enters the normal running state, the application program and the action system running in the RAM are executed, so that the processes involving the first network device in the method embodiments are completed.
[0144] It can be understood that, Figure 6 Only a simplified design of the first network device 1100 is shown. In actual applications, the first network device can include any number of interfaces, processors or memories.
[0145] Figure 7 This is a schematic diagram of the hardware structure of another first network device 1200 according to an embodiment of this application. Figure 7 The first network device 1200 shown can perform the corresponding steps executed by the first network device in the method of the above embodiments.
[0146] like Figure 7 The first network device 1200 includes a main control board 1210, an interface board 1230, a switching board 1220, and an interface board 1240. The main control board 1210, interface boards 1230 and 1240, and the switching board 1220 are interconnected with the system backplane via a system bus. The main control board 1210 performs system management, equipment maintenance, and protocol processing functions. The switching board 1220 performs data exchange between the interface boards (also called line cards or service boards). Interface boards 1230 and 1240 provide various service interfaces (e.g., POS interface, GE interface, ATM interface, etc.) and forward data packets.
[0147] The interface board 1230 may include a central processing unit 1231, a forwarding table entry memory 1234, a physical interface card 1233, and a network processor 1232. The central processing unit 1231 is used to control and manage the interface board and communicate with the central processing unit on the main control board. The forwarding table entry memory 1234 is used to store forwarding table entries. The physical interface card 1233 is used to receive and send traffic. The network memory 1232 is used to control the physical interface card 1233 to send and receive traffic according to the forwarding table entries.
[0148] Specifically, the physical interface card 1233 is used to receive the first service message sent by the first user equipment. The physical interface card 1233 is also used to send the first SRv6 message to the second network device.
[0149] After receiving the first service message, the physical interface card 1233 sends the first service message to the central processing unit 1231. The central processing unit 1231 determines that the first service message needs to be processed by the central processing unit 1231 based on the information in the message header of the first service message. Accordingly, the central processing unit 1231 processes the first service message.
[0150] Optionally, after receiving the first service message, the physical interface card 1233 sends the first service message to the central processing unit 1231. The central processing unit 1231 determines that the first service message needs to be processed by the central processing unit 1211 based on the information in the header of the first service message. The central processing unit 1231 then uploads the first service message to the central processing unit 1211, which processes the first service message.
[0151] The central processor 1231 is further configured to control the network memory 1232 to obtain the forwarding table entry in the forwarding table entry memory 1234, and the central processor 1231 is further configured to control the network memory 1232 to send the first SRv6 packet to the second network device via the physical interface card 1233.
[0152] It should be understood that the actions of the interface board 1240 in the embodiments of the present application are consistent with the actions of the interface board 1230, and for the sake of brevity, will not be described again. It should be understood that the first network device 1200 in the embodiments can correspond to the functions and / or various steps implemented in the above-mentioned method embodiments, which will not be described again here.
[0153] In addition, it should be noted that the master board can have one or more, and when there are multiple, it can include a master master board and a standby master board. The interface board can have one or more, and the stronger the data processing capability of the first network device, the more interface boards it provides. The physical interface card on the interface board can also have one or more. The switching network board can have none or one or more, and when there are multiple, they can collectively implement load sharing and redundancy. Under the centralized forwarding architecture, the first network device can not need a switching network board, and the interface board undertakes the processing function of the entire system of the service data. Under the distributed forwarding architecture, the first network device can have at least one switching network board, and the data exchange between multiple interface boards is realized through the switching network board, providing large-capacity data exchange and processing capability. Therefore, the data access and processing capability of the first network device of the distributed architecture is greater than that of the centralized architecture. The specific architecture to be adopted depends on the specific networking deployment scenario, which is not limited here.
[0154] In addition, the embodiments of the present application provide a computer storage medium for storing computer software instructions for the first network device described above, which contains programs designed to execute the above-mentioned method embodiments.
[0155] Figure 8 A structural schematic diagram of the second network device 2000 of the embodiments of the present application is shown. Figure 8 The second network device 2000 shown can perform the corresponding steps performed by the second network device in the method of the above-mentioned embodiments. The second network device is deployed in a communication network, and the communication network further includes a first network device. As Figure 8 As shown, the second network device 2000 includes a receiving unit 2002 and a processing unit 2004.
[0156] The receiving unit 2002 is configured to receive a first SRv6 packet sent by a first network device, the first SRv6 packet comprising first group information and a first service packet, the first group information being used to indicate an interworking strategy of the first service packet transmitted by a first user equipment and a second user equipment based on a first user group determined by the first network device, the first service packet being from the first user equipment, a destination of the first service packet being the second user equipment, the first user group being a user group to which the first user equipment belongs, and the first service packet comprising information of the second user equipment.
[0157] The processing unit 2004 is configured to determine whether a second user group corresponding to the information of the second user equipment is included in the second network device, the second user group being a user group to which the second user equipment belongs.
[0158] According to a determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network device and the first group information, the processing unit 2004 is further configured to determine a forwarding strategy of forwarding the first service packet to the second user equipment.
[0159] Optionally, the second network device further comprises a sending unit 2006, the first group information comprises a first group identifier, the first group identifier being used to indicate the user group to which the first user equipment belongs, and the processing unit 2004 determines the forwarding strategy of forwarding the first service packet to the second user equipment according to the determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network device and the first group information, comprising: in response to the processing unit 2004 determining that the second network device includes the second user group corresponding to the information of the second user equipment and that a value of the first group identifier indicates the first user group, the sending unit 2004 is configured to send the first service packet to the second user equipment.
[0160] Optionally, the second network device further comprises a sending unit 2006, the first group information comprises a first group identifier, the first group identifier being used to indicate the user group to which the first user equipment belongs, and the processing unit 2004 determines the forwarding strategy of forwarding the first service packet to the second user equipment according to the determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network device and the first group information, comprising: in response to the processing unit 2004 determining that the second network device does not include the second user group corresponding to the information of the second user equipment and that a value of the first group identifier indicates the first user group, the sending unit 2006 is configured to send the first service packet to the second user equipment in a random discarding manner or in a limited-speed forwarding manner.
[0161] Optionally, the second network device further comprises a sending unit 2006, the first group information comprises a first group identifier, the first group identifier is used to indicate a user group to which the first user equipment belongs, and the processing unit 2004 determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second network device comprises a second user group corresponding to the information of the second user equipment and the first group information, which comprises: in response to the processing unit 2004 determining that the second network device comprises the second user group corresponding to the information of the second user equipment and the value of the first group identifier indicates invalid, the sending unit 2006 is used to send the first service packet to the second user equipment in a random discarding manner or in a limited speed forwarding manner.
[0162] Optionally, the first group information comprises a first group identifier and a first group policy identifier, the first group identifier is used to indicate a user group to which the first user equipment belongs, and the first group policy identifier is used to indicate a specific interworking policy.
[0163] Optionally, the processing unit 2004 determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second network device comprises a second user group corresponding to the information of the second user equipment and the first group information, which comprises: the processing unit 2004 is used to determine a second group policy according to the determination result, the second group policy is used to indicate an interworking policy of the first user equipment and the second user equipment transmitting the first service packet determined by the second network equipment based on the second user group; and the processing unit 2004 is further used to determine the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy.
[0164] Optionally, the processing unit 2004 determines the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy, comprising: the processing unit 2004 is configured to determine that a first identifier in the first group policy identifier is valid, the first identifier is used to indicate that the first network device includes the first user group and the second network device does not include the second user group; the processing unit 2004 is further configured to determine a first sub-policy in the second group policy according to the first identifier, the first sub-policy indicates the interworking policy determined by the second user group in the case that the first network device includes the first user group and the second network device does not include the second user group; and the processing unit 2004 is further configured to determine the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the value of the first identifier and the first sub-policy.
[0165] Optionally, the processing unit 2004 determines the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy, comprising: the processing unit 2004 is configured to determine that a second identifier and a third identifier in the first group policy identifier are valid, the second identifier is used to indicate that the first network device does not include the first user group and the second network device includes the second user group, and the third identifier is used to indicate that the first network device does not include the first user group and the second network device does not include the second user group; the processing unit 2004 is further configured to determine a second sub-policy in the second group policy according to the second identifier and the third identifier, the second sub-policy indicates the interworking policy determined by the second user group in the case that the first network device does not include the first user group and the second network device includes the second user group; and the processing unit 2004 is further configured to determine the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the value of the second identifier and the second sub-policy.
[0166] Optionally, the processing unit 2004 determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network equipment and the first group information, including: the processing unit 2004 is configured to determine a second group policy according to the determination result, the second group policy being used to indicate an interworking policy of the first user equipment and the second user equipment transmitting the first service packet determined by the second network equipment based on the second user group; the processing unit 2004 is further configured to determine the forwarding policy of forwarding the first service packet to the second user equipment according to the first group identifier and the first group policy identifier indicating the interworking policy and the second group policy.
[0167] Optionally, the forwarding policy is any one of the following forwarding policies: forwarding, discarding, forwarding in a random discarding manner, and forwarding in a rate limiting manner.
[0168] Optionally, the first group information is carried in any one of the following headers included in the first SRv6 packet: an IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
[0169] Optionally, the first SRv6 packet is transmitted via an SRv6 tunnel between the first network equipment and the second network equipment.
[0170] Optionally, the information of the second user equipment is a destination IP address included in the first service packet, or the information of the second user equipment is a destination MAC address included in the first service packet.
[0171] Figure 8 The second network equipment 2000 shown can perform the corresponding steps performed by the second network equipment in the method of the above-mentioned embodiments. The second network equipment receives the first SRv6 sent by the first network equipment, and then the second network equipment as a receiving end equipment can control the forwarding policy of the user group according to the interworking policy determined by the sending end equipment and the interworking policy determined by the receiving end equipment.
[0172] Figure 9 The hardware structure of the second network equipment 2100 of the embodiments of the present application is shown in the figure. Figure 9 The second network equipment 2100 shown can perform the corresponding steps performed by the second network equipment in the method of the above-mentioned embodiments.
[0173] As Figure 9As shown, the second network device 2100 includes a processor 2101, a memory 2102, an interface 2103 and a bus 2104. The interface 2103 can be implemented in a wireless or wired manner. The processor 2101, the memory 2102 and the interface 2103 are connected through the bus 2104.
[0174] The interface 2103 can specifically include a transmitter and a receiver, for the second network device to transceive information or data with the first network device in the above embodiments. For example, the interface 2103 is configured to support receiving the first SRv6 packet sent by the first network device. As an example, the interface 2103 is configured to support the process S105 in the first network device. Figure 2 The processor 2101 is configured to perform the processing performed by the second network device in the above embodiments. For example, the processor 2101 is configured to receive the first SRv6 packet sent by the first network device, determine the second user group, and determine the forwarding policy for forwarding the first service packet according to the interworking policy determined by the first network device and the interworking policy determined by the second network device; and / or other processes of the techniques described herein. As an example, the processor 2101 is configured to support the processes S106 and S107 in the second network device. Figure 2 The memory 2102 includes an action system 21021 and an application program 21022, configured to store programs, codes or instructions, which can complete the processing processes related to the second network device in the method embodiments when the processor or the hardware device executes the programs, codes or instructions. Optionally, the memory 2102 can include a read-only memory (ROM) and a random access memory (RAM). The ROM includes a basic input / output system (BIOS) or an embedded system; and the RAM includes an application program and an action system. When the second network device 2100 needs to be run, the second network device 2100 is started by the BIOS or the bootloader in the embedded system solidified in the ROM, and is guided to a normal running state. After the second network device 2100 enters the normal running state, the application program and the action system running in the RAM are executed, so that the processing processes related to the second network device in the method embodiments are completed.
[0175] It can be understood that, Figure 9 Only a simplified design of the second network device 2100 is shown. In actual applications, the second network device can include any number of interfaces, processors or memories.
[0176] Figure 10This is a schematic diagram of the hardware structure of another second network device 2200 according to an embodiment of this application. Figure 10 The second network device 2200 shown can perform the corresponding steps executed by the second network device in the method of the above embodiments.
[0177] like Figure 10 The second network device 2200 includes a main control board 2210, an interface board 2230, a switching board 2220, and an interface board 2240. The main control board 2210, interface boards 2230 and 2240, and the switching board 2220 communicate with each other via a system bus connected to the system backplane. The main control board 2210 performs system management, equipment maintenance, and protocol processing functions. The switching board 2220 performs data exchange between the interface boards (also called line cards or service boards). Interface boards 2230 and 2240 provide various service interfaces (e.g., POS interface, GE interface, ATM interface, etc.) and forward data packets. In one possible implementation, the second network device 2200 is a blade server.
[0178] The interface board 2230 may include a central processing unit 2231, a forwarding table entry memory 2234, a physical interface card 2233, and a network processor 2232. The central processing unit 2231 is used to control and manage the interface board and communicate with the central processing unit 2211 on the main control board 2210. The forwarding table entry memory 2234 is used to store forwarding table entries. The physical interface card 2233 is used to receive and send traffic. The network memory 2232 is used to control the physical interface card 2233 to send and receive traffic according to the forwarding table entries.
[0179] Specifically, the physical interface card 2233 is used to receive the first SRv6 message sent by the first network device. The physical interface card 2233 is also used to forward the first service message.
[0180] After receiving the first SRv6 message, the physical interface card 2233 sends the first SRv6 message to the central processing unit 2231. The central processing unit 2231 determines that the first SRv6 message needs to be processed by the central processing unit 2231 based on the information in the message header of the first SRv6 message. Accordingly, the central processing unit 2231 processes the first SRv6 message.
[0181] Optionally, after receiving the first SRv6 packet, the physical interface card 2233 sends the first SRv6 packet to the central processor 2231, the central processor 2231 determines, according to information in the packet header of the first SRv6 packet, that the first SRv6 packet needs to be processed by the central processor 2211, and the central processor 2231 sends the first SRv6 packet to the central processor 2211, and the central processor 2211 processes the first SRv6 packet.
[0182] The central processor 2231 is further configured to control the network memory 2232 to obtain the forwarding table entry in the forwarding table entry memory 2234, and the central processor 2231 is further configured to control the network memory 2232 to complete the receiving and sending of the traffic via the physical interface card 2233.
[0183] It should be understood that the actions of the interface board 2240 in the embodiments of the present application are consistent with the actions of the interface board 2230, and for the sake of brevity, will not be described again. It should be understood that the second network device 2200 in the embodiments can correspond to the functions and / or various steps implemented in the above-mentioned method embodiments, which will not be described again here.
[0184] In addition, it should be noted that the master control board can have one or more, and when there are multiple, it can include a master master control board and a standby master control board. The interface board can have one or more, and the stronger the data processing capability of the second network device, the more interface boards it provides. The physical interface card on the interface board can also have one or more. The switching network board can have none or one or more, and when there are multiple, they can jointly implement load sharing and redundancy. Under the centralized forwarding architecture, the second network device can not need a switching network board, and the interface board undertakes the processing function of the entire system of service data. Under the distributed forwarding architecture, the second network device can have at least one switching network board, and the data exchange between multiple interface boards is realized through the switching network board, providing large-capacity data exchange and processing capability. Therefore, the data access and processing capability of the second network device of the distributed architecture is greater than that of the centralized architecture. The specific architecture to be adopted depends on the specific networking deployment scenario, which is not limited here.
[0185] In addition, the embodiments of the present application provide a computer storage medium for storing computer software instructions for the above-mentioned second network device, which contains programs for executing the designs of the above-mentioned method embodiments.
[0186] The embodiments of the present application also include a network system, which comprises a first network device and a second network device, the first network device being the first network device in the above-mentioned Figure 5 or Figure 6 or Figure 7 the second network device being the second network device in the above-mentioned Figure 8or Figure 9 or Figure 10 the second network device in the network.
[0187] The steps of a method or algorithm described in connection with the present disclosure can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium can be integral to the processor. The processor and the storage medium can reside in an ASIC. Alternatively, the processor and the storage medium can be located in a user terminal. The processor and the storage medium can comprise any combination of a microprocessor, a microcontroller, a processor, or any other circuitry capable of reading information from, and writing information to, a storage medium.
[0188] Those skilled in the art should appreciate that the functions described herein can be implemented in hardware and / or software and / or firmware. If implemented in software and / or firmware, the functions can be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. Storage media can be any available media that can be accessed by a general purpose or special purpose computer.
[0189] The specific implementation described above is illustrative for purposes of teaching the present application. Alternative implementations will be apparent to those skilled in the art from consideration of this document.
Claims
1. A packet forwarding method based on user groups, characterized by, The method comprises: The first network device receives a first service message sent by a first user equipment, the first service message comprising information of the first user equipment, and the first service message being destined for a second user equipment; The first network device determines whether the first network device comprises a first user group corresponding to the information of the first user equipment, the first user group being a user group to which the first user equipment belongs; According to a determination result of whether the first network device comprises the first user group corresponding to the information of the first user equipment, the first network device determines a value of first group information and generates a first Segment Routing version 6 (SRv6) message, the first SRv6 message comprising the first group information and the first service message, and the first group information being used to indicate an interworking strategy of the first network device determined based on the first user group for the first user equipment and the second user equipment to transmit the first service message; The first network device sends the first SRv6 message to a second network device, the second network device being in communication with the second user equipment.
2. The method of claim 1, wherein, The first group information comprises a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first network device determining the value of the first group information according to the determination result of whether the first network device comprises the first user group corresponding to the information of the first user equipment comprising: In response to the first network device determining that the first network device comprises the first user group corresponding to the information of the first user equipment, the first network device determines that the value of the first group identifier indicates the first user group.
3. The method of claim 1, wherein, The first group information comprises a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first network device determining the value of the first group information according to the determination result of whether the first network device comprises the first user group corresponding to the information of the first user equipment comprising: In response to the first network device determining that the first network device does not comprise the first user group corresponding to the information of the first user equipment, the first network device determines that the value of the first group identifier indicates invalidity.
4. The method of claim 1, wherein, The first group information comprises a first group identifier and a first group policy identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first group policy identifier being used to indicate a specific interworking strategy.
5. The method of claim 4, wherein, The first group policy identifier comprises a first identifier, the first identifier being used to indicate that the first network device comprises the first user group and the second network device does not comprise a second user group, the second user group being a user group to which the second user equipment belongs, and the first network device determining the value of the first group information according to the determination result of whether the first network device comprises the first user group corresponding to the information of the first user equipment comprising: In response to the first network device determining that the first user group corresponding to the information of the first user device is included in the first network device, the first network device determines that the value of the first group identifier indicates the first user group and determines the value of the first identifier.
6. The method of claim 4, wherein, The first group policy identifier includes a second identifier and a third identifier, the second identifier is used to indicate that the first network device does not include the first user group and the second network device includes a second user group, and the third identifier is used to indicate that the first network device does not include the first user group and the second network device does not include a second user group, the second user group being a user group to which the second user device belongs, and the first network device determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user device is included in the first network device, including: In response to the first network device determining that the first user group corresponding to the information of the first user device is included in the first network device, the first network device determines that the value of the first group identifier indicates invalid and determines the value of the second identifier and the value of the third identifier.
7. The method of claim 4, wherein, The first group policy identifier includes a fourth identifier, the fourth identifier is used to indicate that the second network device does not include a second user group, the second user group being a user group to which the second user device belongs, and the first network device determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user device is included in the first network device, including: In response to the first network device determining that the first user group corresponding to the information of the first user device is included in the first network device, the first network device determines that the value of the first group identifier indicates the first user group and determines the value of the fourth identifier.
8. The method of claim 4, wherein, The first group policy identifier includes a fifth identifier and a sixth identifier, the fifth identifier is used to indicate that the second network device includes a second user group, and the sixth identifier is used to indicate that the second network device does not include a second user group, the second user group being a user group to which the second user device belongs, and the first network device determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user device is included in the first network device, including: In response to the first network device determining that the first user group corresponding to the information of the first user device is included in the first network device, the first network device determines that the value of the first group identifier indicates invalid and determines the value of the fifth identifier and the value of the sixth identifier.
9. The method according to any one of claims 2-8, characterized in that, The first group identifier is carried in any one of the following headers included in the first SRv6 packet: The sixth version of the Internet Protocol IPv6 header, hop-by-hop option header, destination option header and segment routing header.
10. The method according to any one of claims 4-8, characterized in that, The first group policy identifier is carried in any one of the following headers included in the first SRv6 packet: The IPv6 header, hop-by-hop option header, destination option header and segment routing header.
11. The method according to any one of claims 1-8, characterized in that, The first SRv6 packet is transmitted via an SRv6 tunnel between the first network device and the second network device.
12. The method of any one of claims 1-8, wherein, The information of the first user equipment is a source Internet Protocol (IP) address included in the first service packet, or the information of the first user equipment is a source Media Access Control (MAC) address included in the first service packet.
13. A method for packet forwarding based on user groups, the method comprising: The method comprises: The second network device receives a first Segment Routing version 6 (SRv6) packet sent by the first network device, the first SRv6 packet comprising a first group of information and a first service packet, the first group of information being used to indicate an interworking policy of the first service packet determined by the first network device based on a first user group, the first service packet being from the first user equipment, a destination of the first service packet being the second user equipment, the first user group being a user group to which the first user equipment belongs, the first service packet comprising information of the second user equipment; The second network device determines whether the second network device comprises a second user group corresponding to the information of the second user equipment, the second user group being a user group to which the second user equipment belongs; According to a determination result of whether the second network device comprises the second user group corresponding to the information of the second user equipment and the first group of information, the second network device determines a forwarding policy of forwarding the first service packet to the second user equipment.
14. The method of claim 13, wherein, The first group of information comprises a first group identifier, the first group identifier being used to indicate the user group to which the first user equipment belongs, and the second network device determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second network device comprises the second user group corresponding to the information of the second user equipment and the first group of information, comprising: In response to the second network device determining that the second network device comprises the second user group corresponding to the information of the second user equipment and that a value of the first group identifier indicates the first user group, the second network device sends the first service packet to the second user equipment.
15. The method of claim 13, wherein, The first group of information comprises a first group identifier, the first group identifier being used to indicate the user group to which the first user equipment belongs, and the second network device determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second network device comprises the second user group corresponding to the information of the second user equipment and the first group of information, comprising: In response to the second network device determining that the second network device does not comprise the second user group corresponding to the information of the second user equipment and that a value of the first group identifier indicates the first user group, the second network device sends the first service packet to the second user equipment in a random discarding manner or in a limited-speed forwarding manner.
16. The method of claim 13, wherein, The first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the second network equipment determines a forwarding policy of forwarding the first service packet to the second user equipment according to a determination result of whether the second network equipment includes a second user group corresponding to information of the second user equipment and the first group information, including: In response to the second network equipment determining that the second network equipment includes the second user group corresponding to the information of the second user equipment and the value of the first group identifier indicating invalid, the second network equipment sends the first service packet to the second user equipment in a random discarding manner or a limited speed forwarding manner.
17. The method of claim 13, wherein, The first group information includes a first group identifier and a first group policy identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first group policy identifier being used to indicate a specific interworking policy.
18. The method of claim 17, wherein, The second network equipment determines a forwarding policy of forwarding the first service packet to the second user equipment according to a determination result of whether the second network equipment includes a second user group corresponding to information of the second user equipment and the first group information, including: The second network equipment determines a second group policy according to the determination result, the second group policy being used to indicate an interworking policy of the first user equipment and the second user equipment transmitting the first service packet determined by the second user group; The second network equipment determines a forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy.
19. The method of claim 18, wherein, The second network equipment determines a forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy, including: The second network equipment determines that a first identifier in the first group policy identifier is valid, the first identifier being used to indicate that the first network equipment includes the first user group and the second network equipment does not include a second user group; The second network equipment determines a first sub-policy in the second group policy according to the first identifier, the first sub-policy indicating an interworking policy determined by the second user group in a case where the first network equipment includes the first user group and the second network equipment does not include a second user group; The second network equipment determines a forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the value of the first identifier and the first sub-policy.
20. The method of claim 18, wherein, The second network equipment determines a forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy, including: The second network device determines that the second identifier and the third identifier in the first group of policy identifiers are valid. The second identifier is used to indicate that the first network device does not include the first user group and the second network device includes the second user group. The third identifier is used to indicate that the first network device does not include the first user group and the second network device does not include the second user group. The second network device determines a second sub-policy in the second group of policies based on the second identifier and the third identifier. The second sub-policy indicates the interoperability policy determined by the second user group in the case where the first network device does not include the first user group and the second network device includes the second user group. The second network device determines the forwarding strategy for forwarding the first service packet to the second user equipment based on the interoperability policy indicated by the value of the second identifier and the second sub-policy.
21. The method of claim 17, wherein, The step of determining a forwarding strategy for forwarding the first service packet to the second user equipment based on the determination result of whether the second network device includes the second user equipment's information and the first group information, includes: The second network device determines a second set of policies based on the determination result. The second set of policies is used to instruct the second network device on the interoperability policy for transmitting the first service message between the first user equipment and the second user equipment, based on the second user group. The second network device determines the forwarding policy for forwarding the first service packet to the second user equipment based on the interoperability policy indicated by the first set of identifiers and the first set of policy identifiers and the second set of policies.
22. The method of any one of claims 17-21, wherein, The forwarding strategy is any one of the following forwarding strategies: Forward, discard, forward in a randomly discarded manner, and forward in a rate-limited manner.
23. The method of any one of claims 13-21, wherein, The first set of information is carried in any one of the following headers included in the first SRv6 message: The Internet Protocol version 6 (IPv6) header, hop-by-hop options header, destination options header, and segment routing header.
24. The method of any one of claims 13-21, wherein, The first SRv6 message is transmitted via an SRv6 tunnel between the first network device and the second network device.
25. The method of any one of claims 13-21, wherein, The information of the second user equipment is the destination Internet Protocol (IP) address included in the first service message, or the information of the second user equipment is the destination Media Access Control (MAC) address included in the first service message.
26. A first network device, comprising: The first network device includes: The receiving unit is configured to receive a first service message sent by a first user equipment, the first service message including information of the first user equipment, and the destination of the first service message being a second user equipment. The processing unit is configured to determine whether the first network device includes a first user group corresponding to the information of the first user device, wherein the first user group is the user group to which the first user device belongs; According to a determination result of whether the first user group corresponding to information of the first user equipment is included in the first network equipment, the processing unit is further configured to determine a value of the first group information and generate a first Segment Routing version 6 (SRv6) message, the first SRv6 message including the first group information and the first service message, the first group information being used to indicate an interworking strategy of the first user equipment and the second user equipment for transmitting the first service message, which is determined by the first network equipment based on the first user group. The sending unit is configured to send the first SRv6 message to a second network equipment in communication with the second user equipment.
27. The first network device of claim 26, wherein, The first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the processing unit determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network equipment, including: In response to the processing unit determining that the first user group corresponding to the information of the first user equipment is included in the first network equipment, the processing unit is configured to determine that the value of the first group identifier indicates the first user group.
28. The first network device of claim 26, wherein, The first group information includes a first group identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the processing unit determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network equipment, including: In response to the processing unit determining that the first user group corresponding to the information of the first user equipment is not included in the first network equipment, the processing unit is configured to determine that the value of the first group identifier indicates invalidity.
29. The first network device of claim 26, wherein, The first group information includes a first group identifier and a first group policy identifier, the first group identifier being used to indicate a user group to which the first user equipment belongs, and the first group policy identifier being used to indicate a specific interworking strategy.
30. The first network device of claim 29, wherein, The first group policy identifier includes a first identifier, the first identifier being used to indicate that the first network equipment includes the first user group and the second network equipment does not include a second user group, the second user group being a user group to which the second user equipment belongs, and the processing unit determines the value of the first group information according to the determination result of whether the first user group corresponding to the information of the first user equipment is included in the first network equipment, including: In response to the processing unit determining that the first user group corresponding to the information of the first user equipment is included in the first network equipment, the processing unit is configured to determine that the value of the first group identifier indicates the first user group and determine the value of the first identifier.
31. The first network device of claim 29, wherein, The first group policy identifier includes a second identifier and a third identifier, the second identifier is used to indicate that the first network device does not include the first user group and the second network device includes a second user group, and the third identifier is used to indicate that the first network device does not include the first user group and the second network device does not include the second user group, the second user group being a user group to which the second user device belongs, and the processing unit determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: In response to the processing unit determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit is configured to determine that the value of the first group identifier indicates invalidity and determine the values of the second identifier and the third identifier.
32. The first network device of claim 29, wherein, The first group policy identifier includes a fourth identifier, the fourth identifier is used to indicate that the second network device does not include a second user group, the second user group being a user group to which the second user device belongs, and the processing unit determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: In response to the processing unit determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit is configured to determine that the value of the first group identifier indicates the first user group and determine the value of the fourth identifier.
33. The first network device of claim 29, wherein, The first group policy identifier includes a fifth identifier and a sixth identifier, the fifth identifier is used to indicate that the second network device includes a second user group, and the sixth identifier is used to indicate that the second network device does not include the second user group, the second user group being a user group to which the second user device belongs, and the processing unit determines the value of the first group information according to a determination result of whether the first network device includes the first user group corresponding to the information of the first user device, including: In response to the processing unit determining that the first network device includes the first user group corresponding to the information of the first user device, the processing unit is configured to determine that the value of the first group identifier indicates invalidity and determine the values of the fifth identifier and the sixth identifier.
34. The first network device of any of claims 27-33, wherein, The first group identifier is carried in any one of the following headers included in the first SRv6 packet: A sixth version of Internet Protocol (IPv6) header, a hop-by-hop option header, a destination option header, and a segment routing header.
35. The first network device of any of claims 29-33, wherein, The first group policy identifier is carried in any one of the following headers included in the first SRv6 packet: An IPv6 header, a hop-by-hop option header, a destination option header, and a segment routing header.
36. The first network device of any of claims 27-33, wherein, The first SRv6 packet is transmitted via an SRv6 tunnel between the first network device and the second network device.
37. The first network device of any of claims 26-33, wherein, The information of the first user equipment is a source Internet Protocol (IP) address included in the first service packet, or the information of the first user equipment is a source Media Access Control (MAC) address included in the first service packet.
38. A second network device, comprising: The second network device includes: The receiving unit is configured to receive a first Segment Routing version 6 (SRv6) packet sent by a first network device, the first SRv6 packet including first group information and a first service packet, the first group information being used to indicate an interworking policy of a first user equipment and a second user equipment for transmitting the first service packet, which is determined by the first network device based on a first user group to which the first user equipment belongs, the first service packet being from the first user equipment, a destination of the first service packet being the second user equipment, the first service packet including information of the second user equipment; The processing unit is configured to determine whether a second user group corresponding to the information of the second user equipment is included in the second network device, the second user group being a user group to which the second user equipment belongs. The processing unit is further configured to determine a forwarding policy of forwarding the first service packet to the second user equipment according to a determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network device and the first group information.
39. The second network device of claim 38, wherein, The second network device further includes a sending unit, the first group information includes a first group identifier, the first group identifier being used to indicate the user group to which the first user equipment belongs, and the processing unit determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network device and the first group information, including: In response to the processing unit determining that the second user group corresponding to the information of the second user equipment is included in the second network device and a value of the first group identifier indicates the first user group, the sending unit is configured to send the first service packet to the second user equipment.
40. The second network device of claim 38, wherein, The second network device further includes a sending unit, the first group information includes a first group identifier, the first group identifier being used to indicate the user group to which the first user equipment belongs, and the processing unit determines the forwarding policy of forwarding the first service packet to the second user equipment according to the determination result of whether the second user group corresponding to the information of the second user equipment is included in the second network device and the first group information, including: In response to the processing unit determining that the second user group corresponding to the information of the second user equipment is not included in the second network device and a value of the first group identifier indicates the first user group, the sending unit is configured to send the first service packet to the second user equipment in a random discarding manner or in a limited-speed forwarding manner.
41. The second network device of claim 38, wherein, The second network device further comprises a sending unit, the first group information comprises a first group identifier, the first group identifier is used to indicate a user group to which the first user equipment belongs, and the processing unit determines a forwarding policy of forwarding the first service packet to the second user equipment according to a determination result of whether the second network device comprises a second user group corresponding to information of the second user equipment and the first group information, and the forwarding policy comprises: In response to the processing unit determining that the second network device comprises the second user group corresponding to the information of the second user equipment and that a value of the first group identifier indicates invalidity, the sending unit is configured to send the first service packet to the second user equipment in a random discarding manner or in a limited-speed forwarding manner.
42. The second network device of claim 38, wherein, The first group information comprises a first group identifier and a first group policy identifier, the first group identifier is used to indicate a user group to which the first user equipment belongs, and the first group policy identifier is used to indicate a specific interworking policy.
43. The second network device of claim 42, wherein, The processing unit determines a forwarding policy of forwarding the first service packet to the second user equipment according to a determination result of whether the second network device comprises a second user group corresponding to information of the second user equipment and the first group information, and the forwarding policy comprises: The processing unit is configured to determine a second group policy according to the determination result, the second group policy being used to indicate an interworking policy of the first user equipment and the second user equipment transmitting the first service packet, which is determined by the second network device based on the second user group; The processing unit is further configured to determine the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by the first group policy identifier and the second group policy.
44. The second network device of claim 43, wherein, The processing unit determines a forwarding policy of forwarding the first service packet to the second user equipment according to an interworking policy indicated by the first group policy identifier and a second group policy, and the forwarding policy comprises: The processing unit is configured to determine that a first identifier in the first group policy identifier is valid, the first identifier being used to indicate that the first network device comprises the first user group and that the second network device does not comprise a second user group; The processing unit is further configured to determine a first sub-policy in the second group policy according to the first identifier, the first sub-policy being used to indicate an interworking policy determined by the second user group in a case where the first network device comprises the first user group and the second network device does not comprise the second user group; The processing unit is further configured to determine the forwarding policy of forwarding the first service packet to the second user equipment according to the interworking policy indicated by a value of the first identifier and the first sub-policy.
45. The second network device of claim 43, wherein, The processing unit determines a forwarding policy of forwarding the first service packet to the second user equipment according to an interworking policy indicated by a first group policy identifier and a second group policy, and the forwarding policy comprises: The processing unit is configured to determine that a second identifier and a third identifier in the first set of policy identifiers are valid, the second identifier indicating that the first network device does not include the first user group and the second network device includes the second user group, and the third identifier indicating that the first network device does not include the first user group and the second network device does not include the second user group. The processing unit is further configured to determine a second sub-policy in the second set of policies according to the second identifier and the third identifier, the second sub-policy indicating an interworking policy determined by the second user group in a case where the first network device does not include the first user group and the second network device includes the second user group. The processing unit is further configured to determine a forwarding policy of the first service packet to the second user device according to the interworking policy indicated by a value of the second identifier and the second sub-policy.
46. The second network device of claim 42, wherein, The processing unit determines the forwarding policy of the first service packet to the second user device according to a determination result of whether the second network device includes a second user group corresponding to information of the second user device and the first group information, including: The processing unit is configured to determine a second set of policies according to the determination result, the second set of policies indicating an interworking policy determined by the second network device based on the second user group for transmission of the first service packet by the first user device and the second user device. The processing unit is further configured to determine the forwarding policy of the first service packet to the second user device according to the interworking policy indicated by the first set of identifiers and the second set of policies.
47. The second network device according to any of claims 42-46, wherein, The forwarding policy is any one of the following forwarding policies: forwarding, discarding, forwarding in a random discarding manner, and forwarding in a rate limiting manner.
48. The second network device according to any of claims 38-46, wherein, The information of the second user device is a destination Internet Protocol (IP) address included in the first service packet, or the information of the second user device is a destination Media Access Control (MAC) address included in the first service packet.
49. A communication network system, characterized by The communication network system includes a first network device and a second network device, the first network device being the first network device of any one of claims 26-37, and the second network device being the second network device of any one of claims 38-48.
Citation Information
Patent Citations
Information synchronization method, authentication method and device
CN111277543A
Methods and apparatus for use in providing transport and data center segmentation in a mobile network
US20200120022A1