Backup service function notification and synchronization
By encapsulating backup service function information in the network service header, dynamically synchronize the status of active service functions and backup service functions, the status synchronization problem of service function chains in the computer network is solved, and the high availability and continuity of network services is ensured.
Patent Information
- Application Number
- CN202111304561.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-10-27
- Filing Date
- 2021-11-05
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-11-05
AI Technical Summary
In the prior art, it is difficult to realize dynamic state synchronization between active service functions and backup service functions in the service function chain in the computer network, especially in the event of a failure or topological change in the active service function, resulting in functional loss or data interruption.
By encapsulating backup service function information in the network service header, the service function next jump allows dynamic state synchronization with the backup service function, and synchronizes with packets in the data plane without relying on the static configuration of the coordinator or network controller.
It realizes the low latency switch to the backup service function when service function fails or topological changes, ensuring the continuity and reliability of network services and avoiding functional losses and data interruptions.
Smart Images

Figure CN114448878B_ABST
Abstract
Description
[0001] This application claims the benefit of U.S. Patent Application No. 17 / 452,536, filed Oct. 27, 2021, which claims the benefit of U.S. Provisional Patent Application No. 63 / 110,830, filed Nov. 6, 2020, the entire contents of each of which are incorporated herein by reference. TECHNICAL FIELD
[0002] This disclosure relates to computer networks and, more particularly, to applying network services to data traffic traversing a computer network. BACKGROUND ART
[0003] A computer network consists of a set of nodes (e.g., computing devices) and a set of links that connect one node to another. For example, a computer network can consist of a set of routers, and the set of links can be the paths between the routers. When a first node in the network sends data traffic to a second node in the network, a message can pass through many links and many nodes. The set of links and nodes that a message traverses as it propagates from the first node to the second node is called the path through the network.
[0004] A network operator can deploy one or more computing devices to apply network services to data traffic traversing a computer network, such as firewalls, carrier-grade network address translation (CG-NAT), performance enhancement proxies for video, Transmission Control Protocol (TCP) optimization and header enrichment, caching, and load balancing. Each of these network services can be referred to as a service function and is implemented by one or more service function instances. In addition, a network operator can configure service function chains, each of which identifies a set of service functions to be applied to a packet flow mapped to the corresponding service function chain. In other words, a service function chain defines one or more service functions to be applied in a specific order to provide a composite service to be applied to a packet flow bound to the service function chain for processing. In this way, a service function chain is a series of service functions through which packet flows that meet specified criteria will pass. An example service function chain architecture is described in “Service Function Chaining (SFC) Architecture” by Halpern, J., Ed. and C. Pignataro, Ed., available at www.rfc-editor.org / info / rfc7665 (RFC7665, October 2015), the entire contents of which are incorporated herein by reference. SUMMARY OF THE INVENTION
[0005] In general, techniques for backup service function notification and synchronization are described. For example, in a computer network that provides service functions, a service function classifier (e.g., an ingress to a service function overlay network) (also simply referred to herein as a "classifier") may encapsulate a network service header into packets classified to a service function chain to implement a service path along the service function chain. The network service header typically includes a service path identifier that uniquely identifies the service path and a service index that provides a location within the service path. As described herein, the service function classifier may also include backup service function information in the network service header such that an active service function next hop (referred to herein as a "service function next hop") in the service function chain can use the backup service function information to identify a backup service function with which to perform state synchronization.
[0006] In one example, the classifier may store a table that includes backup service function information such as one or more network addresses of computing devices that host backup service functions. When the classifier receives a packet classified to a service function chain, the classifier may determine the location of one or more backup service functions for the active service function in the service function chain based on a lookup of the table. In addition to specifying the service path identifier and service index of the network service header, the classifier may also specify the location of one or more backup service functions (e.g., one or more network addresses of computing devices that host one or more backup service functions) in the network service header and forward the packet to the service function next hop.
[0007] In response to receiving a packet, the service function next hop may use the backup service function information in the network service header to identify one or more backup service functions with which to synchronize its session (e.g., flow state). In this way, by sending a packet with a network service header that includes backup service function information, the classifier can use packets in the data plane to facilitate state synchronization between an active service function and one or more backup service functions without statically configuring the active service function by a coordinator or network controller. This can provide a switchover in the event of an active service function failure or otherwise being unavailable without significant loss of functionality or data - which would otherwise occur in cases where a coordinator or network controller is required to statically configure backup service functions. This also enables the classifier to dynamically update the active service function with the backup service function next hop in scenarios such as topology changes caused by changes or updates to backup service functions. For example, if a backup service function changes (e.g., a backup service function fails), the classifier can dynamically update the backup service function next hop by sending a subsequent packet with updated backup service function information, such that the service function next hop can perform state synchronization with a computing device that hosts one or more backup service functions identified in the updated backup service function information.
[0008] In one example, the described techniques include a method that includes: receiving, by a computing device hosting an active service function of a service function chain, a packet classified to the service function chain, where the packet is encapsulated with a network service header that includes backup service function information for the active service function of the service function chain; and sending, by the computing device, status data of the active service function to one or more computing devices hosting one or more backup service functions, at least based on the backup service function information included in the network service header.
[0009] In another example, the described techniques include a method that includes: classifying, by a service function classifier, a packet to a service function chain; determining, by the service function classifier, one or more backup service functions for an active service function of the service function chain; encapsulating, by the classifier, the packet with a network service header that includes backup service function information that identifies one or more computing devices hosting one or more backup service functions; and sending, by the classifier, the packet encapsulated with the network service header to a computing device hosting the active service function in the service function chain such that the computing device hosting the active service function sends status data for the active service function to the one or more backup service functions, at least based on the backup service function information.
[0010] In another example, the described techniques include a network system that includes: a plurality of service functions; a computing device including a service function classifier configured to: classify packets classified to a service function chain including the plurality of service functions; determine one or more backup service functions for an active service function of the service function chain; encapsulate the packets with a network service header that includes backup service function information that identifies one or more computing devices hosting one or more backup service functions; and send the packets encapsulated with the network service header to a computing device hosting the active service function in the service function chain such that the computing device hosting the active service function synchronizes status information for the active service function with the one or more backup service functions, at least based on the backup service function information.
[0011] Details of one or more examples of the present disclosure are set forth in the accompanying drawings and the description below. Other features, objects, and advantages will be apparent from the description and drawings, and from the claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 An example network system that provides backup service function notification and synchronization in accordance with the techniques described herein is illustrated.
[0013] Figure 2is a block diagram illustrating an example computing device that provides one or more service function instances according to the techniques described in the present disclosure.
[0014] Figures 3A - 3B is a block diagram illustrating an example tunnel packet that guides internal grouping along a service function chain according to the techniques described in the present disclosure and a network service header that includes backup service function information.
[0015] Figure 4 is a block diagram illustrating further details of an example of a computing device operating according to one or more techniques of the present disclosure.
[0016] Figure 5 is a block diagram illustrating an example service function link architecture reference model according to the techniques described in the present invention.
[0017] Figure 6 is a block diagram illustrating an example service function overlay network according to the techniques described in the present invention.
[0018] Figure 7 is a flowchart illustrating an example operating mode according to the techniques described in the present disclosure.
[0019] Throughout the description and the drawings, like reference characters denote like elements. Detailed Description
[0020] Figure 1 illustrates an example network system that provides backup service function notification and synchronization according to the techniques described herein. Figure 1 The example network system includes a service provider network 2 that provides packet-based network services to subscriber devices 16 (collectively referred to as "subscriber devices 16"). That is, the service provider network 2 provides authentication and establishment of network access for the subscriber devices 16 so that the subscriber devices can begin to exchange data packets with a public network 12 (also referred to herein as a "packet data network"), and the public network 12 can be an internal or external packet-based network, such as the Internet.
[0021] In Figure 1In the example, the service provider network 2 includes an access network 6 (“access network 6”), which provides connectivity to the public network 12 via a service provider core network 7 (referred to herein as “core network 7”) and a gateway 8. The service provider core network 7 and the public network 12 provide packet-based services that can be requested and used by subscriber devices 16. As an example, the core network 7 and / or the public network 12 can provide, for example, bulk data delivery, Voice over Internet Protocol (VoIP), Internet Protocol Television (IPTV), Short Message Service (SMS), Wireless Application Protocol (WAP) services, or customer-specific application services. The public network 12 can include, for example, a Local Area Network (LAN), a Wide Area Network (WAN), the Internet, a Virtual LAN (VLAN), an enterprise LAN, a Layer 3 Virtual Private Network (VPN), an Internet Protocol (IP) intranet operated by the service provider operating the access network 6, an enterprise IP network, or some combination thereof. In various examples, the public network 12 is connected to a public WAN, the Internet, or connected to other networks. The public network 12 implements one or more Packet Data Protocols (PDPs), such as IP (IPv4 and / or IPv6), X.25, or Point-to-Point Protocol (PPP), to enable packet-based delivery of public network 12 services.
[0022] Subscriber devices 16 are connected to the gateway 8 via the access network 6 to receive connectivity to subscriber services for applications hosted by the subscriber devices 16. Subscribers can represent, for example, enterprises, residential subscribers, or mobile subscribers. The subscriber device 16 can be, for example, a personal computer, a laptop computer, or other types of computing devices associated with the subscriber. In addition, the subscriber device 16 can include a mobile device that accesses data services of the service provider network 2 via a Radio Access Network (RAN) 4. Example mobile subscriber devices include mobile phones, laptops or desktop computers with, for example, wireless cards, netbooks with wireless capabilities, video game devices, pagers, smart phones, Personal Digital Assistants (PDAs), and the like. Each subscriber device 16 can run various software applications, such as word processing and other office support software, web browsing software, software that supports voice calls, video games, video conferencing, and email, among others. The subscriber device 16 is connected to the access network 6 via an access link 5 that includes wired and / or wireless communication links. The term “communication link” as used herein includes any form of wired or wireless transmission medium and can include intermediate nodes, such as network devices. Each access link 5 can include, for example, aspects of an Asymmetric DSL network, WiMAX, a T-1 line, an Integrated Services Digital Network (ISDN), a wired Ethernet, or a cellular radio link.
[0023] The network service provider operates or, in some cases, leases elements of the access network 6 to provide packet transfer between the subscriber device 16 and the gateway 8. The access network 6 represents a network that aggregates data traffic from one or more subscribers for transfer to / from the service provider's service provider core network 7. The access network 6 includes network nodes for performing communication protocols to transfer control and user data to facilitate communication between the subscriber device 16 and the gateway 8. The access network 6 can include a broadband access network, a network, a wireless LAN, a public switched telephone network (PSTN), or other types of access networks, and can include or otherwise provide connectivity for a cellular access network, such as Figure 1 a radio access network (RAN). Examples include networks that conform to the following: the Universal Mobile Telecommunications System (UMTS) architecture, fifth-generation mobile technology (5G), the UMTS evolution known as Long-Term Evolution (LTE), Mobile IP standardized by the Internet Engineering Task Force (IETF), and other standards proposed by the Third Generation Partnership Project (3GPP), the Third Generation Partnership Project 2 (3GGP / 2), and the Worldwide Interoperability for Microwave Access (WiMAX) Forum.
[0024] The service provider core network 7 provides packet-based connectivity to subscriber devices 16 attached to the access network 6 for access to the public network 12. The core network 7 can represent a network owned and operated by the service provider to interconnect multiple networks, which can include the access network 6. The core network 7 can implement Multiprotocol Label Switching (MPLS) forwarding and in such instances can be referred to as an MPLS network or an MPLS backbone. In some instances, the core network 7 represents multiple interconnected autonomous systems, such as the Internet, which provides services from one or more service providers. The public network 12 can represent, for example, an edge network coupled to the core network 7 via a customer edge device such as Figure 1 not shown in the figure). The public network 12 can include a data center.
[0025] In an example of a service provider network 2 that includes a wired / broadband access network, for example, the gateway 8 can represent a Broadband Network Gateway (BNG), a Broadband Remote Access Server (BRAS), an MPLS Provider Edge (PE) router, a core router or gateway, or a Cable Modem Termination System (CMTS). In an example of a service provider network 2 that includes a cellular access network as the access network 6, the gateway 8 can represent a mobile gateway, such as a Gateway General Packet Radio Service (GPRS) Serving Node (GGSN), an Access Gateway (aGW), or a Packet Data Network (PDN) Gateway (PGW). In other examples, the functionality described with respect to the gateway 8 can be implemented in a switch, a service card, or other network elements or components.
[0026] A network service provider that manages at least a portion of the service provider network 2 generally provides services to subscribers associated with a device (e.g., subscriber device 16) that accesses the access service provider network. For example, the services provided can include traditional Internet access, Voice over Internet Protocol (VoIP), video and multimedia services, and security services. As described above with respect to access network 6, the core network 7 can support multiple types of access network infrastructure that connect to the service provider network access gateway to provide access to the services provided. In some instances, the network system can include subscriber devices 16 attached to multiple different access networks 6 having different architectures.
[0027] Generally, any one or more of the subscriber devices 16 can request authorization and data services by sending a session request to the gateway 8. In turn, the gateway 8 generally accesses an Authentication, Authorization, and Accounting (AAA) server 11 to authenticate the subscriber device requesting network access. Once authenticated, any subscriber device 16 can send subscriber data traffic to the service provider core network 7 to access and receive services provided by the public network 12, and such packets traverse the gateway 8 as part of at least one packet flow. Figure 1 The flow 26A illustrated therein represents one or more upstream packet flows from any one or more of the subscriber devices 16 and directed to the public network 12. The flow 26B represents one or more downstream packet flows from the public network 12 and directed to any one or more of the subscriber devices 16.
[0028] The terms "packet flow", "traffic flow", or simply "flow" refer to a set of packets originating from a specific source device and sent to a specific destination device. For example, a single packet flow in the upstream (originated by one of the subscriber devices 16) or downstream (destination is one of the subscriber devices 16) direction can be identified by values used in the header of the packet, such as the network "5-tuple", i.e., source network address (IP address), destination network address, source port, destination port, and protocol. This five-tuple generally identifies the packet flow to which the received packet corresponds. An n-tuple refers to any n items selected from the 5-tuple. For example, a binary tuple of a packet can refer to a combination of <source network address, destination network address> or <source network address, source port> of the packet. Additionally, a subscriber device can originate multiple packet flows when authenticating with the service provider network 2 and establishing a communication session for receiving data services. The techniques described in this disclosure can be applied to packet flows between any two computing devices and are not limited to being applied to Figure 1 the flow 26 depicted therein.
[0029] As described herein, service provider network 2 includes service complex 9, which has service function instances 10A - 10N that provide an execution environment for network services. That is, each of service function instances 10 applies one or more service functions. The service functions are applied to packets of a received packet flow and can operate at various layers of the protocol stack (e.g., network layer, application layer).
[0030] As an example, service functions applied by service function instances 10 can include firewall and security services, carrier - grade network address translation (CG - NAT), media optimization (voice / video), WAN optimization, NAT44, NAT64, HTTP header enrichment, TCP optimizer, IPSec / VPN services, deep packet inspection (DPI), HTTP filtering, counting, accounting, billing, and load balancing of packet flows or other types of services applied to network traffic. Service functions can alternatively be referred to as virtualized network functions (VNFs), but service functions need not be virtual. In this way, each service function instance 10 represents an instance of a service function. Each service function instance 10 represents a component that can be implemented as a virtual element of a computing device (e.g., a physical server) and / or be embedded in a physical network element (e.g., a firewall or NAT device). Multiple service function instances 10 can be executed in a single computing device or physical network element computing device. The computing device hosting one or more service function instances 10 can refer to a physical server or a physical network element.
[0031] Although illustrated as part of service complex 9, which can represent a data center, service function instances 10 can, for example, be located within the core network and be interconnected via one or more switches or virtual switches of core network 7. In some instances, service function instances 10 can be located in multiple different data centers. One or more service function instances 10 can be located within an enterprise / customer site attached to service provider core 7. In some examples, each service function instance 10 can be executed by a virtual machine in a virtual computing environment. Additionally, the computing environment can include a scalable cluster of general - purpose computing devices, such as x86 - based servers. As another example, service function instances 10 can be executed by a combination of general - purpose computing devices and specialized devices. Because they are virtualized, the individual network services provided by service function instances 10 can scale horizontally like a modern data center through the allocation of virtualized memory, processor utilization, storage, and network policies, and by adding additional load - balancing virtual machines. Service complex 9 can represent or otherwise be implemented using a public cloud, a private cloud, a hybrid cloud, or a combination thereof. Other network architectures for delivering network traffic to service complex 9 can be envisioned, and these techniques are not limited to as Figure 1The network service provider architecture illustrated therein.
[0032] In Figure 1 the example, gateway 8 directs individual packet flows 26 through a set of defined service functions provided by service function instances 10. That is, each packet flow can be forwarded through a specific ordered combination of service functions, each ordered combination providing an overall "network service" or "composite service", and referred to herein as a "service function chain" or more simply as a "service chain". A service function chain can include specific service function instances 10 that provide the service functions, or can indicate that the service functions can be applied by any service function instance 10 that provides the service function. In this way, according to the service function chain configured by the service provider, packet flows 26 can be processed by service function instances 10 as packets flow between access network 6 and public network 12. A particular service function instance 10 can support multiple service function chains. Figure 1 An example service chain 28 is depicted in
[0033] A "service function chain" defines one or more services applied in a specific order to provide a composite service to be applied to a packet flow bound to the service function chain, and a "service tunnel" or "service path" refers to the logical and / or physical path taken by the packet flow processed by the service function chain and the forwarding state for forwarding the packet flow according to the service function chain ordering. Each service function chain can be associated with a corresponding service path.
[0034] Gateway 8 or one or more computing devices hosting service function instances 10 can classify packet flows 26 into service function chains. The classification granularity can vary based on device capabilities, customer requirements, service provider network policies, and the services provided. The initial classification determines the service function chain for processing the packet flow. Subsequent classification can occur within the service function chain to change the order of the service functions applied.
[0035] Service function instance 10 can implement each service function chain using an internally configured forwarding state that guides packets of a packet flow along the service function chain for processing according to an identified set of service function instances 10. Such a forwarding state can specify a network tunnel such as an Internet Protocol (IP) or Generic Routing Encapsulation (GRE) tunnel or a tunnel interface for tunneling between service function instances 10 using, for example, Virtual Local Area Network (VLAN), Multiprotocol Label Switching (MPLS) technology, etc. Tunnel encapsulation for a service function chain can be referred to as service function chain encapsulation, which enables the creation of a service function chain in the data plane of service provider network 2. In some instances, a physical or virtual switch, router, or other network element interconnecting service function instances 10 can be configured to direct a packet flow to service function instances 10 according to a service function chain.
[0036] Service function chain encapsulation enables forwarding between service function instances 10 that provide a service function overlay network over a physical underlying network, which consists of an existing Layer 3 network topology of computing devices (such as physical servers) interconnected by routing and switching devices for exchanging packet data between computing devices. The service function overlay network can enable a network service provider to create paths between service function instances 10 and locate service functions in service provider network 2 in a network topology-independent manner (e.g., without the need to change the underlying network topology).
[0037] Computing devices implementing service function instances 10 can distribute service function data describing the service function instances 10. As an example, a computing device can utilize a Layer 3 routing protocol, such as a Border Gateway Protocol (BGP) message (e.g., a BGP UPDATE message), to distribute service function data. More specifically, a computing device hosting at least one service function instance 10 can output a service function instance route 20. Generally, a Service Function Instance Route (SFIR) describes a particular service function instance of a particular service function and the manner in which packets are forwarded to the service function instance over the underlying network. For example, service function instance route 20 can include the network address of a computing device and service function instance data that specifies the service function type and service identifier (e.g., defined by the Internet Assigned Numbers Authority (IANA)) of a service function for one or more service function instances 10 hosted by the computing device, where the combination of the service function type and service identifier identifies service function instance 10 in service provider network 2. Service function instance route 20 can specify, in some instances, an address family for the service function instance data that is different from the address family of the underlying computer network, and in this way, service function instance route 20 distributes service function data for an overlay network of service function instances 10 that overlay the computer network consisting of computing devices.
[0038] In some cases, the service function instance routing 20 may be originated by the computing device hosting the described service function instance 10. However, the service function instance routing 20 may be originated by the controller 19 or some other device. The service function instance routing 20 includes the network address of the computing device hosting the described service function instance 10, such as an IPv4 or IPv6 address. In some examples, the service function instance routing 20 may also include encapsulation data that describes the tunnel encapsulation of the packets to be received by the computing device in order to reach the service function instance 10.
[0039] In Figure 1 it, the controller 19 may manage the deployment of service function instances within the operating environment of the service complex 9. For example, the controller 19 may coordinate service functions and deploy the service functions as service function instances, such as any of the service function instances 10. In some examples, the controller 19 may coordinate virtual machines, containers, or other operating environments to host the coordinated service functions. The controller 19 may coordinate service functions in response to requests from application or network service provider operators.
[0040] In some examples, the controller 19 may distribute service function chain data that describes an overlay topology for a service function chain, each service function chain consisting of one or more service function instances 10 described by the service function chain data. As an example, the controller 19 may utilize a Layer 3 routing protocol to output a service function chain routing 21 to the service provider network 2, the service function chain routing 21 including an ordered set of one or more service function instances 10 to define a service chain for processing at least one packet flow 26. The controller 19 may inject the service function chain routing 21 into the service provider network 2 by sending the service function chain routing 21 to any of the service function instances 10, a route reflector, or another routing device of the service provider network 2 for advertisement by routing devices in the network. The controller 19 may be a Layer 3 routing protocol speaker and directly advertise the service function chain routing 21. The controller 19 may output multiple service function chain routings, and the service function chain routing 21 is just one example. Generally, the controller 19 originates a service function chain routing for each service function chain, and each service function chain routing may include a service path identifier for the described service function chain, the types of service functions included in the chain, and / or the sequence of service function instances, and for each such type of service function and / or service function instance, includes a service index representing it in the described service function chain.
[0041] The controller 19 may receive a service function instance route 20 via a Layer 3 protocol. The controller 19 may use service function instance data included in the service function instance route 20 to generate a service function chain and a service function chain route 21 for the service function chain. For example, the controller 19 may receive a request from an operator to create a service function chain having a series of service functions (each having a different service function type) to be applied to a packet flow. The controller 19 may identify service function instances that match the service function types of the service functions, as indicated in the service function instance route 20. Additional examples of service function instance routing and service function chain routing are described in U.S. Patent Application No. 15 / 368,282, entitled “Distributed Service Function Chain Data and Service Function Instance Data in a Network,” filed on Dec. 2, 2016, the entire content of which is incorporated herein by reference. Using a Layer 3 routing protocol to distribute service function chain data is merely an example, and the controller 19 may use any protocol to distribute service function data and / or service function chain data, such as the Network Configuration Protocol (NETCONF).
[0042] In Figure 1In an example, service function instance 10A can operate as an ingress service function instance for a service function overlay network to apply a classification service function to a packet flow. In this case, service function instance 10A can be referred to as a "classifier", which is a special service function located at the ingress point of the service function overlay network. In such an instance, service function instance 10A, operating as a classifier, assigns packets of a given packet flow to a specific service function chain. To classify a packet flow using a service function chain for processing, service function instance 10A can apply a policy to the packet header fields of the packet flow packets (e.g., 5-tuple values such as source / destination address, source / destination port, protocol) to determine the service chain for the packet. For example, the policy can be specific to a subscriber of subscriber device 16, specific to the network, or specific to an application service carried by the packet flow. The policy can specify a service path identifier that identifies the service function chain for processing packets that match the policy. In some cases, service function instance 10A, operating as a classifier, selects a service function chain for a packet flow, sets a service path identifier for the service function chain, sets a service index for the first hop in the selected service function chain, and adds a Network Service Header (NSH) indicating the service path identifier and service index to the packets of the packet flow. Other examples of network service headers are described in "Network Service Header (NSH)" by P. Quinn, Ed. et al. (Request for Comments (RFC) 8300, January 2018), the entire content of which is incorporated herein by reference.
[0043] In Figure 1 an example, service function instance 10A can classify one or more of packet flows 26 into service function chain 28. Although service function instance 10A is the first service function instance in service function chain 28, service function instance 10A can classify some packet flows 26 into service function chains that do not have service function instance 10A as the first service function instance. Additionally, in addition to one of service function instances 10, a computing device can also classify a packet flow into a service function chain and direct the packet flow to the first service function instance 10 in the service function chain.
[0044] To apply the service functions indicated by the service function chain, service function instance 10 forwards packets through an ordered combination of service function instances 10 to apply the corresponding service functions. The service function instance 10 that applies the service function to the packet determines the next service function instance 10 in the service function chain and forwards the packet to the next service function instance 10 (referred to herein as "service function next hop"). In some examples, the service function next hop can be determined based on service chain next hop information, such as service path identifiers and service function types, which combinatorially identify the service function instance as the next service function instance in the service chain. For example, service function instance 10A can add a network service header (NSH) to the packet, where the NSH includes at least one of a service path identifier and a service index.
[0045] The packet with the NSH can be further encapsulated in a tunnel encapsulation header that includes an IP address in the underlying network for the computing device hosting the service function next hop (e.g., service function instance 10B). As an example, the tunnel encapsulation header can be based on the encapsulation data included in the service function instance route 20 of service function instance 10B. If more than one service function instance 10 can be used as the next service function instance for a service function in the service function chain, then anycast addresses in the underlying network or direct knowledge of the underlying network topology can be used to select the next service function instance 10 to apply the indicated service function.
[0046] Service function instance 10B receives the packet and applies its corresponding service function to the packet to further implement service function chain 28. The computing device hosting service function instance 10B uses the NSH included in the packet to determine the next service function instance 10 in the service chain and, in some cases, the next service index. For example, the combination of the service path identifier and the service index provides an identification of the service function and its order in the service function chain. In this example, the computing device hosting service function instance 10B determines that the next service function instance is service function instance 10N and forwards the packet to the computing device hosting service function instance 10N.
[0047] Service function instance 10N receives the packet and applies its corresponding service function to the packet to further implement service function chain 28. The computing device hosting service function instance 10N uses the NSH included in the packet to determine the next service function instance 10 in the service chain. In this case, service function instance 10N is the terminal service function instance in service chain 28. The computing device hosting service function instance 10N can therefore output the packet to the IP next hop of the packet in the underlying network.
[0048] To provide high availability of service functions, service functions can be deployed in a cluster as part of the same service function chain or across multiple service function chains. Service functions in the cluster can be configured as active service functions and / or backup service functions for a given service function chain. For example, service function chain 28 can include a first service function (e.g., firewall) provided by service function instance 10A, a second service function (e.g., network address translation) provided by service function instance 10B, and a third service function (e.g., WAN optimization) provided by service function instance 10N. In Figure 1 the example, service function instance 10C can also provide network address translation and can operate as a backup service function in the event that service function instance 10B fails or is otherwise unavailable. Generally, the controller statically configures the active service function and the backup service function. For example, a network operator can pre-configure the active service function and one or more backup service functions for the active service function for a given service function chain. However, service function instances in the cluster may change, and the controller may not be able to dynamically update the backup service function in such a topology change.
[0049] According to the techniques described in this disclosure, service provider network 2 provides backup service function notification and synchronization. In Figure 1 the example, when service function instance 10A, which operates as a classifier, receives a packet and classifies the packet into service function chain 28, service function instance 10A determines whether there are any backup service functions for the active service function in service function chain 28. For example, service function instance 10A can store a table, such as table 30, that includes backup service function information. In Figure 1 the example, table 30 includes the network addresses of the computing devices hosting the backup service functions for the active service function for a given service path. In this example, service chain 28 can be identified by a service path identifier (SPI) "10". The location of the network service for which backup service function information is provided is indicated by a service index (SI) "3". The backup service function information specifies the network address of the active service function next hop and one or more network addresses of the backup service function next hops for the active service function for a given service function chain. In this example, the backup service function information for service chain 28 at the location indicated by service index 3 includes the active service function next hop located at 203.0.113.1 and its backup service function next hop located at 203.0.113.3. In this example, the backup service function information for service chain 28 at the location indicated by service index 3 includes another active service function next hop located at 203.0.113.2 and its backup service function next hop located at 203.0.113.3. Traffic can be load balanced among the active service functions.
[0050] In some examples, the backup service function information specifies the network addresses of multiple backup service function next hops for an active service function. In this example, the backup service function information for service chain 28 at the location indicated by service index 3 includes another active service function next hop located at 203.0.113.3, a first backup service function next hop located at 203.0.113.1, and a second backup service function next hop located at 203.0.113.2. Table 30 is just one example of a data structure that stores backup service function information and can include additional information, such as metric information. In some examples, the controller 19 can push the active and backup service functions stored in table 30. In other examples, table 30 can be generated based on service function instance data such as data distributed together with service function instance route 20 and / or service function chain information included in service function chain route 21.
[0051] When a classifier (e.g., service function instance 10A) receives a packet and classifies the packet into service chain 28 (service path identifier is 10 in this example), service function instance 10A performs a lookup in table 30 to determine if there are any backup service functions for the active service function instances in service chain 28. Service function instance 10A can include backup service function information (e.g., the network address of the computing device hosting the backup service function instance). For example, service function instance 10A encapsulates the packet with a network service header that includes the service path identifier "10", the service index "3", and the address of the computing device hosting backup service function instance 10C (e.g., 203.0.113.3), and sends the packet encapsulated with the network service header to the service function next hop, such as service function instance 10B which is an active service function. In some examples, the classifier can include the backup service function information in the network service header during initialization or when the backup service function information is updated or changed.
[0052] In response to receiving a packet, a service function next hop can use the backup service function information in the network service header to identify a backup service function that is synchronized with its session (e.g., flow state). For example, in response to receiving a network service header that includes backup service function information, service function instance 10B can synchronize a NAT session with service function instance 10C identified by the backup service function information. As an example, a computing device hosting an active service function can establish a communication session (e.g., a TCP or UDP session) with a computing device hosting a backup service function so that the active service function can synchronize state information with the backup service function. In this way, by sending a packet with a network service header that includes backup service function information, a classifier can provide state synchronization between an active service function and a backup service function using a packet in the data plane without the need for the controller to statically configure the backup service function information, e.g., in a computing device hosting the classifier or a prior service function in a service function chain. By synchronizing service function state data for a packet flow, the active service function and the backup service function can achieve a low-latency handover to the backup service function because the backup service function has a similar state as the active service function and can assume that the state handling of the flow was previously handled by the active service function.
[0053] In some examples, for a given service function chain, the backup service function may change. For example, the backup service function for active service function 10B for service function chain 28 can change from service function instance 10C to service function 10D ( Figure 1 not shown in). In this example, service function instance 10A, which acts as a classifier, can add a network service header that includes updated backup service function information identifying service function 10D so that the service function next hop (e.g., service function instance 10B) can use the service function information included in the updated backup network service header to perform state synchronization.
[0054] Figure 2is a block diagram of an example computing device that illustrates providing one or more service function instances in accordance with the techniques described in this disclosure. Computing device 200 may represent a physical or virtual server and in this example includes a system bus 242 that couples the hardware components of the computing device 200's hardware environment. The system bus 242 couples a memory 244, a network interface card (NIC) 240, a storage disk 246, and a microprocessor 210. The network interface card 240 includes one or more interfaces that are configured to exchange packets using the links of an underlying physical network. The microprocessor 210 may include one or more processors, each processor including independent execution units to execute instructions that conform to an instruction set architecture. The execution units may be implemented as separate integrated circuits (ICs), or may be combined within one or more multi-core processors (or “multi-core” processors), each multi-core processor being implemented using a single IC (i.e., a chip multi-processor).
[0055] Disk 246 represents a computer-readable storage medium that includes volatile and / or non-volatile, removable and / or non-removable media implemented in any method or technology for storing information such as processor-readable instructions, data structures, program modules, or other data. Computer-readable storage media includes, but is not limited to, random access memory (RAM), read only memory (ROM), EEPROM, flash memory, CD-ROM, digital versatile disks (DVD) or other optical storage devices, magnetic tapes, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by the microprocessor 210.
[0056] Memory 244 includes one or more computer-readable storage media, which may include random access memory (RAM), such as various forms of dynamic RAM (DRAM), e.g., DDR2 / DDR3 SDRAM, or static RAM (SRAM), flash memory, or any other form of fixed or removable storage media that can be used to carry or store the desired program code and program data in the form of instructions or data structures and can be accessed by a computer. Memory 244 provides a physical address space consisting of addressable memory locations.
[0057] Memory 244, NIC 240, storage disk 246, and microprocessor 210 provide an operating environment for a software stack that executes a hypervisor 214 and one or more virtual machines 216A - 216M (collectively “virtual machines 216”). Although illustrated and described in relation to virtual machines, service function instances 203A - 203M (collectively “service function instances 203”) may be executed by other operating environments such as containers (e.g., DOCKER containers). The operating system kernel ( Figure 2) may execute in kernel space and may include, for example, Linux, Berkeley Software Distribution (BSD), another Unix variant kernel, or a Windows server operating system kernel available from Microsoft Corporation.
[0058] Computing device 200 executes hypervisor 214 to manage virtual machines 216. Example hypervisors include Kernel-based Virtual Machine (KVM) for the Linux kernel, Xen, ESXi available from VMware, Windows Hyper-V available from Microsoft, and other open source and proprietary hypervisors.
[0059] The virtual machine 216 hosts the corresponding service function instance 203. Each of the service function instances 203 can represent Figure 1 200. In some examples, the virtual machine 216 can host one or more service function instances 203. The service function instance 203 is described below with respect to the service function instance 203A. The service function instance 203 includes a service function 220A for applying to the packet flow. Some examples of the computing device 200 host only one service function instance 203.
[0060] The service function 220A represents software that can be applied to any of the aforementioned service functions described above with respect to the service function instance 10. The service function instance 203A can be coordinated by a controller such as the controller 19 to be executed by the virtual machine 216A to apply the service function 220A. The service function instance configuration data 226 includes data describing the service function instance 203A. For example, the service function instance configuration data 226 can specify the service function type of the service function 220A and the service identifier of the service function instance 203A. The service function instance configuration data 226 can further describe a virtual machine tap or other identifier of the virtual machine 216A, which enables the virtual router 221 to direct the received packet to the virtual machine 216A for processing using the service function instance 203A.
[0061] The hypervisor 214 in the example computing device 200 provides an operating environment for the routing protocol module 228, which may represent processes that execute various protocols at different layers of the network stack. Figure 2 In the example of , the network protocol includes Border Gateway Protocol (BGP) 219, which is a layer 3 routing protocol. BGP 219 may include Multi-Protocol BGP (MP-BGP). Routing protocol module 228 may execute Figure 2Other protocols not shown, such as the MPLS label distribution protocol and / or other MPLS protocols. The routing protocol module 228 is responsible for maintaining routing information 224 to reflect the current topology of the network to which the computing device 200 is connected via the NIC 240. In particular, BGP 219 updates the routing information 224 based on the routing protocol messages received by the computing device 200 to accurately reflect the topology of the network and other entities.
[0062] The routing protocol module 228 uses BGP to send and receive service function routes, which distribute service function chain data and service function instance data for describing service function overlay network nodes and topologies. The routing protocol module 228 can receive one or more service function instance (SFI) routes 230 and one or more service function chain routes 232, and store these service function routes into the routing information 224. The service function instance route 230 and the service function chain route 232 can respectively represent Figure 1 instances of the service function instance route 20 and the service function chain route 21.
[0063] The routing protocol module 228 can generate and output a service function instance route 230 to announce the service function instance 203 of the computing device 200. That is, the routing protocol module 228 can originate such a service function instance route 230. For example, for the service function instance 203A, the routing protocol module 228 can obtain the service function type of the service function 220A and the service identifier for the service function instance 203A from the service function instance configuration data 226. The routing protocol module 228 can generate a service function instance route based on the service function type and the service identifier, and output the service function instance route via the network interface card 240.
[0064] The virtual router 221 of the hypervisor 214 can manage one or more virtual networks configured for the computing device 200, such as the overlay network for the service function instance 203. Additional descriptions of the virtual router can be found in U.S. Patent No. 9,571,394, filed on March 26, 2014, the entire content of which is incorporated herein by reference. For example, a packet received by the network interface card 240 from the underlying physical network can include an outer header to allow the physical network to tunnel the payload or "inner packet" to the physical network address of the NIC 240 of the computing device 200 that executes the virtual router 221. The outer header can include not only the physical network address of the NIC 240 of the computing device, but also a network service header. Aspects of the virtual router 221 can be executed in user space rather than in the hypervisor 214. For example, aspects of the virtual router 221 that include aspects of the service function forwarder 222 can be executed by the virtual machine 216.
[0065] The service function forwarder 222 provides a service function data plane and determines the forwarding of packets based on a service function chain. In some examples, the computing device 200 may include a separate instance of the service function forwarder 222 for each service function instance 203. In some examples, the service function forwarder 222 may be partially performed by dedicated hardware designed to support virtual networking. The service function forwarder 222 may be performed by an application in user space rather than in the hypervisor 214.
[0066] The service function forwarder 222 may be conceptually regarded as a portal in the underlying network through which the service function instance 203 can be reached. Note that although the service function forwarder 222 and the routing protocol module 228 are illustrated and described as separate modules, operations such as the routing protocol module 228 importing, exporting, and processing routes may be considered, for example, as control plane operations of the service function forwarder 222. Additionally, as used herein, the term "service function forwarder" may refer to the computing device 200 as a whole because such operations involve service function route import / export / selection, packet forwarding in a service overlay network, etc., but do not include the operations of the service function instance 203.
[0067] When the service function forwarder 222 receives a service function chain route, the service function forwarder 222 may determine whether to import the service function chain route based on the route target. If the service function forwarder 222 imports the route, by determining whether the route distinguisher for the computing device 200 is specified for any service index / hop of the service function chain, the service function forwarder 222 may determine whether it is on the described service function chain. If so, the service function forwarder 222 may create forwarding states for incoming packets that have been processed by one of the service function instances 203 and create forwarding states for outgoing packets.
[0068] The service function forwarder 222 can create local forwarding state, such that an association is established between a service path identifier / service index and a specific service function instance, as identified by a routing differentiator for service function instance routing and service type combination. The service function forwarder 222 can also create next-hop forwarding state for packets received back from the local service function instance 203 that need to be forwarded to the next hop in the service function chain. There may be a choice of next hops. The service function forwarder 222 can install forwarding state for all potential next hops, or can make a selection and install forwarding state only to a subset of the potential next hops. The installed forwarding state can change over time in response to the availability of a specific service function instance 203 and changes in the underlying network. Note that in some cases, the service function forwarder 222 can create and store only the forwarding state for the service function chain on which it is included. That is, the service function forwarder 222 may not maintain state for all the advertised service function chains.
[0069] This selection of forwarding state includes: determining a service index from the service function chain routing to place in the network service header of an outbound packet. This selection can be conditional on information returned from the local service function instance 203. The service function forwarder 222 can also install forwarding state to support loops, jumps, and branches.
[0070] The network interface card 240 receives packets of a packet flow. The packet flow can be classified to a service function chain that includes the service function instance 203A. Packets received by the network interface card 240 can include a tunnel encapsulation header that identifies the packets for processing by the service function forwarder 222. The service function forwarder 222 can remove the tunnel encapsulation header. Packets to be processed by the service function forwarder 222 and received from a previous service function instance (executed by the computing device 200 or another computing device) can include a network service header with a service path identifier and a service index.
[0071] The service function forwarder 222 can determine that the service function instance 203A applies the service function 220A to the packet based on the network service header. For example, the service function forwarder 222 can determine the service function chain route 232 with a matching service path identifier, and encrypt the service index encryption key from the network service header to determine that the service function instance 203A is indicated for the service index. A combination of the service function type and service identifier identifying the service function instance 203A can be used to indicate the service function instance 203A for the service index in the matching service function chain route 232. In some cases, the service function instance can be indicated only by the service function type, which corresponds to at least one of the service functions 220. For example, if the service identifier indicates that any service function instance supporting the service function type can apply the service function, the service function instance can be indicated only by the service function type. In an example instance of the computing device 200, where each service function instance 203 has an instance of the service function forwarder 222 (e.g., there is only one service function forwarder 222 and one service function instance 203), the service function forwarder 222 can direct its corresponding service function instance 203 to apply the service function to the received packet without first determining the specific service function instance 203 for applying the service function.
[0072] The service function forwarder 222 can direct the service function instance 203A to process the packet based in part on the network service header. The service function instance 203A processes the packet by applying the service function 220A. In addition to or as part of processing the packet by applying the service function 220A, the service function instance 203A can determine a new network service header for the packet. That is, the service function instance 203A can select the next service function instance along the service chain (or another service chain) for processing the packet. The service function 203A can select among multiple service function instances (in some cases, of different service function types). The service index and service path identifier in the new network service header can indicate the next service function in the service chain, the previous service function in the chain (referred to as a "loop"), or a service function downstream in the chain (referred to as "jumping"). The service index and service path identifier in the new network service header can alternatively indicate a service function on a different service function chain (referred to as a "branch").
[0073] The service function forwarder 222 then selects the service function instance that provides the service function identified by the service path identifier and service index in the next network service header, and the service function forwarder 222 forwards the packet to the service function forwarder that supports the selected service function instance.
[0074] The service index in the new network service header received from service function instance 203A enables service function forwarder 222 to select the next-hop service function type and service function instances for each service function type. That is, the service index indicates a set of one or more entries in service function chain route 232 for the service path identifier, each entry corresponding to the service function type and service identifier (e.g., route distinguisher) of service function instance route 230 that advertises a particular service function instance. Service function forwarder 222 selects one of these service function instances, identifies the service function forwarder that supports the selected service function instance, and sends the packet to that next-hop service function forwarder. Additional examples of computing device 200 that processes packets for service function next-hop are described in U.S. Patent Application No. 15 / 368,282, which is incorporated by reference above.
[0075] In accordance with the techniques described in this disclosure, service function instance 203, operating as a classifier, can add a network service header that includes backup service function information. In this example, service function instance 203A can operate as a service function classifier. Service function instance 203A can classify packets into a service function chain. To notify the active service function in the service function chain of its backup service function, service function instance 203A encapsulates a network service header that includes backup service function information.
[0076] For example, service function instance 203A can determine one or more backup service functions for the active service function of the service function chain from backup service function information 234. Backup service function information 234 can represent a table that includes backup service function information (e.g., Figure 1 table 30). Computing device 200 can perform a lookup of backup service function information 234 to identify one or more backup service functions for the active service function of a given service chain.
[0077] In response to determining one or more backup service functions for the active service function of the service function chain, service function instance 203A encapsulates the received packet with a network service header that includes the location of one or more backup service functions determined from backup service function information 234, and forwards the packet to the service function next-hop so that the service function next-hop synchronizes its state information with its backup service function.
[0078] For example, assume that the network interface card 240 of computing device 200 receives a packet from a previous service function instance (e.g., a classifier executed by another computing device 200), and the packet is encapsulated with a network service header that includes backup service function information. The service function forwarder 222 processes the packet and may determine that a service function instance hosted by another computing device can apply the service function as a backup for service function instance 203A. In this example, service function instance 203A may send status information 250A to the other computing device hosting the backup service function to synchronize its status with the backup service function. If the network service header includes multiple backup service functions, service function instance 203A may send status information 250A to each computing device hosting the backup service function to synchronize its forwarding status with each backup service function.
[0079] Figures 3A - 3B An example tunnel packet and network service header in accordance with the techniques of the present disclosure are illustrated, respectively. Figure 3A An example tunnel packet that guides an internal packet along a service function chain in accordance with the techniques of the present disclosure is illustrated. In Figure 3A the example, an original internal packet 309 having a header 308 and a payload 310 is encapsulated with a network service header 304 and encapsulated as a payload 306 using an external (or encapsulating) header 302 to form a tunnel packet 300.
[0080] The external header 302 may include tunnel encapsulation data advertised in encapsulation attributes 314 or otherwise included in the service function instance routing. The external header 302 enables the underlying network to forward the tunnel packet 300 to the computing device hosting the service function instance identified in the network service header 304. As Figure 3B further described in, the network service header 304 may include a basic header 311 that includes information for implementing a service function path. For example, the network service header 304 may include a service path identifier and a service index.
[0081] In accordance with the techniques described in the present disclosure, the network service header 304 may further include backup service function information 312. A service function classifier that receives a packet classified to a service function chain may add a network service header 304 that includes a service path identifier, a service index, and backup service function information.
[0082] A computing device that receives a tunnel packet 300 can determine a service function instance hosted by the computing device to process an internal packet 309 based on a service function instance route stored by the computing device that describes a service function chain identified by a network service header 304. The computing device can also determine, based on backup service function information 312 included in the network service header 304, one or more computing devices that host one or more backup service functions for the service function instance hosted by the computing device.
[0083] Figure 3B is an example of a more detailed network service header 304. For example, the network service header 304 includes a base header 311 (also referred to as the "NSH service path header") to implement a service path and backup service function information 312. The base header 311 includes at least a service path identifier that identifies a service function chain. In some examples, the network service header 304 can include a service path identifier and another service function chain identifier that, in combination, identify a service function chain. The network service header 304 can also include a service index that identifies the next service function in the service function chain to be applied. The base header 311 can also include other information, such as a metadata type (illustrated as "MD type" in Figure 3B to indicate that the network service header 304 includes one or more variable-length context headers that, according to the techniques described in this disclosure, include backup service function information, such as one or more network addresses of computing devices that host backup service functions, such as service function backup nodes 314A - 314N (collectively referred to as "backup service function nodes 314").
[0084] As an example, a variable-length context header can include fields such as a metadata class, type, unassigned bits, length of variable-length metadata, and variable-length metadata that specifies one or more network addresses of computing devices that host backup service functions. The metadata class can define the range of the type field. The type field can specify the type of metadata being carried. The length field can specify the length of the variable-length metadata. As a specific example, the variable-length context header can specify: a metadata class of 0x0000, which is a type that can be assigned by the Internet Assigned Numbers Authority (IANA) to specify a base NSH metadata class; and a value of the metadata type that indicates that the network service header includes backup service function information.
[0085] A service function instance that operates as a classifier (e.g., Figure 1The service function instance 10A) can add a packet including a network service header 304 - the network service header 304 includes backup service function information 312, and forward the encapsulated packet to the service function next hop so that the service function next hop can perform stateful synchronization with the computing device identified by the service function backup node 314.
[0086] Figure 4 is a block diagram that illustrates further details of one example of a computing device operating in accordance with one or more techniques of the present disclosure. Figure 4 A specific example of a server or other computing device 400 that can illustrate including one or more processors 402 for executing any one or more of the controller 19, the service function instance 10, or any other computing device described herein. In other instances, other examples of the computing device 400 can be used. Although shown as a stand-alone computing device 400 for purposes of example, the computing device can be any component or system that includes one or more processors or other suitable computing environment for executing software instructions and, for example, need not include Figure 4 shown in Figure 4 one or more of the elements shown (e.g., the communication unit 406; and in some examples, components such as the (one or more) storage devices 408 may not be co-located or in the same rack as other components).
[0087] As Figure 4 the specific example of
[0088] In one example, the processor 402 is configured to implement functional and / or procedural instructions for execution within the computing device 400. For example, the processor 402 may be capable of processing instructions stored in the storage device 408. Examples of the processor 402 may include any one or more of a microprocessor, a controller, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or equivalent discrete or integrated logic circuitry.
[0089] One or more storage devices 408 may be configured to store information within the computing device 400 during operation. In some examples, the storage device 408 is described as a computer-readable storage medium. In some examples, the storage device 408 is a transient memory, meaning that the primary purpose of the storage device 408 is not long-term storage. In some examples, the storage device 408 is described as volatile memory, meaning that the storage device 408 does not retain stored content when the computer is turned off. Examples of volatile memory include random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), and other forms of volatile memory known in the art. In some examples, the storage device 408 is used to store program instructions for execution by the processor 402. In one example, the storage device 408 is used by software or an application running on the computing device 400 to temporarily store information during program execution.
[0090] In some examples, the storage device 408 further includes one or more computer-readable storage media. The storage device 408 may be configured to store a greater amount of information than volatile memory. The storage device 408 may be further configured for long-term storage of information. In some examples, the storage device 408 includes non-volatile storage elements. Examples of such non-volatile storage elements include magnetic hard disks, optical discs, floppy disks, flash memory, or forms of electrically programmable read-only memory (EPROM) or electrically erasable programmable (EEPROM) memory.
[0091] In some examples, the computing device 400 further includes one or more communication units 406. In one example, the computing device 400 utilizes the communication unit 406 to communicate with external devices via one or more networks, such as one or more wired / wireless / mobile networks. The communication unit 406 may include a network interface card, such as an Ethernet card, an optical transceiver, a radio frequency transceiver, or any other type of device capable of sending and receiving information. Other examples of such network interfaces may include wireless mobile network technologies (e.g., 3G, LTE, 5G) and WiFi radios. In some examples, the computing device 400 uses the communication unit 406 to communicate with external devices.
[0092] In one example, computing device 400 further includes one or more user interface devices 410. In some examples, user interface devices 410 are configured to receive input from a user via tactile, audio, or visual feedback. Examples of (a) user interface device(s) 410 include a presence-sensing display, a mouse, a keyboard, a voice response system, a camera, a microphone, or any other type of device for detecting commands from a user. In some examples, the presence-sensing display includes a touch-sensitive screen.
[0093] One or more output devices 412 may also be included in computing device 400. In some examples, output devices 412 are configured to provide output to a user using tactile, audio, or visual stimuli. In one example, output device 412 includes a presence-sensing display, a sound card, a video graphics adapter card, or any other type of device for converting a signal into a suitable form understandable by a human or a machine. Additional examples of output device 412 include speakers, a cathode ray tube (CRT) monitor, a liquid crystal display (LCD), or any other type of device that can show an understandable output to a user.
[0094] Computing device 400 may include an operating system 416. In some examples, operating system 416 controls the operation of the components of computing device 400. For example, in one example, operating system 416 facilitates the communication of one or more applications with processor 402, communication unit 406, storage device 408, input device 404, user interface device 410, and output device 412.
[0095] The coordination module 430 may coordinate service function instances in a service function overlay network and generate a service function chain. A network service provider operator may use user interface device 410 and / or input device 404 to configure the service function chain.
[0096] The routing protocol module 432 may represent processes that execute various protocols at different layers of the network stack. In Figure 4 an example, the network protocol includes Border Gateway Protocol (BGP) 419, which is a Layer 3 routing protocol. BGP 419 may include Multiprotocol BGP (MP-BGP). The routing protocol module 432 may execute Figure 4 other protocols not shown in
[0097] The routing protocol module 432 uses BGP to send and receive service function routes, which distribute service function instance data and service function chain data for describing service function overlay network nodes and topologies. The routing protocol module 432 can receive one or more service function instance routes 440 and can receive one or more service function chain routes 442, and store these service function routes into the routing information 434. The service function instance routes 440 and the service function chain routes 442 can represent service function instance routes 20 and service function chain routes 21 of an instance Figure 1 .
[0098] Using the service function instance routes 440 received or generated by the computing device 400, the routing protocol module 432 can generate and output service function chain routes 442 to advertise service function chains 400 configured for a service function overlay network that is at least partially controlled by the computing device. That is, the routing protocol module 432 can originate such service function chain routes 442 and inject these routes into the service function overlay network.
[0099] According to the techniques described herein, the computing device 400 includes a network service header module 446 to provide backup service function notification and synchronization. In an example where the (one or more) processors 402 of the computing device 400 perform operations for a service function instance that is a service function classifier (e.g., an ingress to a service function overlay network, such as Figure 1 a service function instance 10A), the network service header module 446 can store backup service function information 444 (e.g., in the routing information 434). In some examples, the network service header module 446 can generate backup service function information based on the service function instance routes 440 and the service function chain routes 442. In other examples, the network service header module 446 can receive backup service function information from a controller. As described above, the backup service function information 444 can include the network addresses of computing devices hosting backup service functions.
[0100] The network service header module 446 can determine one or more backup service functions for an active service function of a service chain. For example, in response to receiving a packet and classifying the packet to a service chain, the network service header module 446 can determine one or more backup service functions resulting from a lookup of the backup service function information 444. The network service header module 446 can encapsulate a packet with a network service header including the backup service function information 444. For example, the network service header can include a service path identifier, a service index, and one or more network addresses (e.g., IP addresses) of computing devices hosting one or more backup service functions, such as Figure 3A and Figure 3B the network service header shown in.
[0101] In an example where the (multiple) processors 402 of computing device 400 execute a service function instance, the service function instance receives a packet encapsulated with a network service header that includes backup service function information (e.g., Figure 1 service function instance 10B of ), the network service module 446 can identify, from the network service header information, one or more computing devices hosting one or more backup service functions and send the status information of computing device 400 to the computing devices identified from the backup service function information included in the network service header.
[0102] Figure 5 FIG. is a block diagram illustrating an example service function link architecture reference model in accordance with the techniques described herein. In this example, the service function overlay network 501 operates over a physical underlying network of interconnected computing devices, with each computing device providing an operating environment for one or more service function forwarders 504A - 504D. Each service function forwarder 504 can represent an example instance of service function forwarder 222 or any service function forwarder described herein. Tunnels 510 connect pairs of service function forwarders 504 over the underlying network.
[0103] The service function overlay network 501 includes service function instances 506A - 506D (collectively referred to as "service function instances 506") and a classifier 502, which can also represent a service function instance. Each of the classifier 502 and the service function instances 506 is hosted or otherwise located local to one of the service function forwarders 504. For example, service function instances 506A, 506B are local to service function forwarder 504B, while service function instance 506D is local to service function forwarder 504D. The service function instances 506 can have different service function types 508. For example, service function instances 506A, 506B, and 506C all have service function type 508A, while service function instance 506D has a different service function type 508B.
[0104] The service function overlay network 501 is merely an example. Examples of service function overlay networks 501 can have any number of service function forwarders 504, service function instances 506, and can be arranged in various overlay topologies determined by the configuration of the tunnel interfaces of the tunnels 510.
[0105] The packet group 512 enters at the classifier 502, which classifies each packet into a service function chain of one or more service function instances 506. The service function forwarder 504 exchanges service function chain routes and service function instance routes as described elsewhere in this document. The service function forwarder 504 selects the next service function instance 506 and forwards each classified packet along its service function chain via the tunnel 510 to the next-hop service function forwarder 504 that is local to the next service function instance 506. Once the last service function instance 506D in the service function chain processes the packet, the last service function forwarder 504D can egress the processed packet 514 from the service function overlay network 501 to their respective destinations.
[0106] In Figure 5 the example of, the service function chain can include the service function instance 506A and the next-hop 506D of the service function instance. That is, the service function instance 506A and the service function instance 506D are the active service functions of the service function chain. The service function instance 506C can operate as a backup service function for the service function instance 506A of the service function chain.
[0107] The classifier 502 receives the packet 512 and classifies the packet into a service function chain. The classifier 502 can determine one or more backup service functions for the active service function of the service function chain. For example, the classifier 502 can determine that the service function instance 506C can operate as a backup service function for the service function instance 506A. The classifier 502 encapsulates the packet 512 with a network service header that includes a service path identifier, a service index, and backup service function information. As described in this disclosure, the backup service function information 503 (e.g., stored in Figure 1The backup service information in Table 30 (e.g.,) may include one or more network addresses of a computing device hosting a backup service function. In this example, the network service header includes the network address of service function forwarder 504C, which hosts backup service function instance 506C and forwards packets to service function forwarder 504B, which forwards the packets to the service function next hop, such as service function instance 506A. In response to receiving the packet, service function forwarder 504B may de-encapsulate the network service header from the packet and send the packet to service function instance 506A. Service function forwarder 504B may also identify that service function forwarder 504C hosts backup service function instance 506C based on the backup service function information included in the network service header. Service function forwarder 504B may notify service function instance 506A that service function forwarder 504C hosts backup service function instance 506C. In response, service function instance 506A may send status information to service function forwarder 504C that hosts service function instance 506C to synchronize its status information with backup service function instance 506C.
[0108] Figure 6 is a block diagram illustrating an example service function overlay network in accordance with the techniques described herein. Service function overlay network 601 may be an example instance of service function overlay network 501. In this example, service function overlay network 601 includes service function forwarders 604, service function instances 606, classifier 502, and is managed by controller 19. For ease of illustration, tunnels are not shown. Each service function instance 606 has Figure 6 the corresponding service function type 608 value as illustrated in. For example, service function type 608A value is 41 and is shared by service function instances 606A, 606C, service function type 608B value is 42 and is provided by service function instance 606E, service function type 608C value is 43 and is shared by service function instances 606D, 606G, and service function type 608D value is 44 and is shared by service function instances 606B, 606F, 606H.
[0109] Each of service function forwarders 604A - 604D has Figure 6The corresponding network addresses illustrated therein. Although illustrated and described with respect to IPv4 addresses, other types of network addresses such as IPv6 can also be contemplated. For example, service function forwarder 604A has an IP address of 192.0.2.1, service function forwarder 604B has an IP address of 192.0.2.2, service function forwarder 604C has an IP address of 192.0.2.3, and service function forwarder has an IP address of 192.0.2.4. Service function forwarder 604A provides access to service function instances 606A, 606B. Service function forwarder 604B provides access to service function instances 606C, 606D. Service function forwarder 604C provides access to service function instances 606E, 606F. Service function forwarder 604D provides access to service function instances 606G, 606H. Service function forwarder 604E provides access to classifier 502. Controller 19 has an IP address of 198.51.100.1.
[0110] Each service function forwarder 604 advertises routes to the service function instances 606 to which it provides access. The following are example service function instance routes for service function instances 606:
[0111] ·RD = 192.0.2.1,1, SFT = 41[606A]
[0112] ·RD = 192.0.2.1,2, SFT = 44[606B]
[0113] ·RD = 192.0.2.2,1, SFT = 41[606C]
[0114] ·RD = 192.0.2.2,2, SFT = 43[606D]
[0115] ·RD = 192.0.2.3,7, SFT = 42[606E]
[0116] ·RD = 192.0.2.3,8, SFT = 44[606F]
[0117] ·RD = 192.0.2.4,5, SFT = 43[606G]
[0118] ·RD = 192.0.2.4,6, SFT = 44[606H]
[0119] A route distinguisher (RD) is an example of a service distinguisher and includes an advertised home IP address and another value, and the SFT is the service function type of the service function instance being advertised. The addressing used for communication between service function forwarders 604 is taken from the tunnel encapsulation attributes of the service function instance route rather than from the RD of that route.
[0120] Service function chain routes can define explicit service function chains (i.e., define specific service function next hops), service function chains that provide a selection of service function instances (i.e., define the selection of the next-hop service function forwarder for performing the next hop in the chain), service function chains with open selection of service function instances (e.g., define the selection of the next-hop service function forwarder for services that support a specific service function type), service function chains with a selection of service function types, related two-way service function chains, related two-way and asymmetric service function chains, asymmetric two-way service function chains, service chains for providing loops, jumps, or branches.
[0121] The following are examples of service function chains. Consider the following service function chain route:
[0122] · SFC1: RD = 198.51.100.1,101, SPI = 15, [SI = 255, SFT = 41, RD = 192.0.2.1,1], [SI = 250, SFT = 43, RD = 192.0.2.2,2]
[0123] The service function chain for SFC1 consists of a service function of type 41 located at service function forwarder 604A and subsequently a service function of type 43 located at service function forwarder 604B. In one example, classifier 502 can receive packets 514 that are classified to SFC1. Classifier 502 determines backup service function information for the active service function of SFC1. For example, service function instance 606C can operate as a backup service function for service function instance 606A of type 608A with a value of 41. In this example, backup service function information 503 can specify the active service function next hop as the network address of service function forwarder 604A (e.g., RD = 192.0.2.1,1) and the backup service function next hop as the network address of service function forwarder 604B that hosts backup service function instance 606C (e.g., RD = 192.0.2.2,1).
[0124] Classifier 502 sends the packets on the chain to service function forwarder 604A, which includes a network service header that specifies a service path identifier (SPI) (value = 15), a service index 255, and backup service function information, as described below:
[0125] ·[SFI = 15, SI = 255, Active SF RD = 192.0.2.1,1, Backup SF RD = 192.0.2.2,1]
[0126] The service function forwarder 604A can receive a packet encapsulated with a network service header including backup service function information and identify a service function chain from the SPI and service index. The service function forwarder 604A determines that for an initial service index of 255, the service function forwarder 604A will deliver the packet to a service function instance 606A of service function type 608A having a value of 41. The service function forwarder 604A also determines that for an initial service index of 255, the service function forwarder 604B provides access to a backup service function instance 606C. The service function forwarder 604A delivers the packet to the service function instance 606A of service function type 608A having a value of 41. The service function forwarder 604A can also notify the service function instance 606A of the location of its backup service function instance. The service function instance 606A can send its status information (illustrated as 610 in Figure 6 to the service function forwarder 604B hosting the service function instance 606C to synchronize the status information with the service function instance 606C.
[0127] When the packet returns from the service function instance 606A to the service function forwarder 604A, the service index for the next hop will be reduced to 250. The service function forwarder 604A forwards the packet to the service function forwarder 604B, which sends the packet to a service function instance 606D of service function type 608C having a value of 43 before forwarding the packet to their destination. The service function forwarder 604B determines that for a service index of 250, the service function forwarder 604B will deliver the packet to the service function instance 606D of service function type 608C having a value of 43.
[0128] In some examples, an active service function can have multiple backup service functions. Consider the following example service function chain routing:
[0129] ·SFC2:RD = 198.51.100.1,101, SPI = 16, [SI = 255, SFT = 41, RD = 192.0.2.1,1], [SI = 250, SFT = 44, RD = 192.0.2.3,7]
[0130] The service function chain for SFC2 consists of a service function of type 41 located at service function forwarder 604A and a subsequent service function of type 44 located at service function forwarder 604C. In one example, classifier 502 may receive a packet 514 classified to SFC2. Classifier 502 determines backup service function information for the active service functions of SFC2. For example, service function instances 606B and 606H may each operate as backup service functions for service function instance 606F of type 608B with a value of 44. In this example, backup service function information 503 may specify the active service function next hop as the network address of service function forwarder 604C (e.g., RD = 192.0.2.3,7) and the first backup service function next hop as the network address of service function forwarder 604A (e.g., RD = 192.0.2.1,2) and the second backup service function next hop as the network address of service function forwarder 604D (e.g., RD = 192.0.2.4,6).
[0131] Classifier 502 sends the packet on the chain to service function forwarder 604A, which includes a network service header specifying a service path identifier (SPI) (value = 16), a service index 250, and backup service function information, as described below:
[0132] ·[SFI = 16, SI = 250, Active SF RD = 192.0.2.2.3,7, Backup SF RD = 192.0.2.1,2; 192.0.2.4,6]
[0133] Service function forwarder 604A may receive a packet encapsulated with a network service header including backup service function information and identify the service function chain from the SPI and service index. Service function forwarder 604A determines that: for an initial service index 255, service function forwarder 604A will deliver the packet to a service function instance 606A of service function type 608A with a value of 41. When the packet returns to service function forwarder 604A from service function instance 606A, the service index for the next hop will be reduced to 250. Service function forwarder 604A forwards the packet to service function forwarder 604C, which sends the packet to a service function instance 606F of service function type 608D with a value of 44 before forwarding the packet to their destination. Service function forwarder 604C may also notify service function instance 606F of the locations of its backup service function instances, e.g., service function forwarder 604A (e.g., 192.0.2.1,2) and service function forwarder 604D (e.g., 192.0.2.4,6). Service function instance 606F may send its status information (at Figure 6Shown in the figure is a service function forwarder 604A that sends (as shown in 612A) to a managed service function instance 606B to synchronize status information with the service function instance 606B. Similarly, the service function instance 606F can send its status information (as shown in Figure 6 612B) to a service function forwarder 604D of a managed service function instance 606H to synchronize status information with the service function instance 606H.
[0134] Figure 7 is a flowchart illustrating an example operation mode of the technology according to the present invention. Regarding Figure 6 to describe operation 700. Operation 700 is also described with respect to Figure 2 the computing device 200, but can be performed by any computing or network device.
[0135] The classifier 502 can receive a packet (e.g., of multiple packets 514) and classify the packet into a service function chain (702). For example, the computing device 200 acting as the classifier 502 can match the packet with a policy, where each policy specifies a service path identifier identifying a given service function chain. As an example, the classifier 502 receives Figure 6 the service function chain routing of SFC1. In response to receiving the packet, the classifier 502 can apply the policy to the packet header fields (e.g., 5-tuple values) of the packet to determine that a service function chain (e.g., Figure 6 SFC1) is applied to the packet. As described above, SFC1 can identify a service function chain including service function instance 606A followed by service function instance 606D.
[0136] The classifier 502 determines one or more backup service functions (704) for the active service functions of the service function chain. For example, the classifier 502 can perform a lookup in a table that includes backup service function information (e.g., Figure 6 the backup service function information 503) and determine the locations of the backup service functions for service function instance 606A and service function instance 606D. In this example, the backup service function information 503 can specify the active service function next hop as the network address of service function forwarder 604A (e.g., RD = 192.0.2.1,1) and the backup service function next hop as the network address of service function forwarder 604B (e.g., RD = 192.0.2.2,1). The backup service function information 503 can also specify the active service function next hop as the network address of service function forwarder 604B (e.g., RD = 192.0.2.2,2) and the backup service function next hop as the network address of service function forwarder 604D (e.g., RD = 192.0.2.4,5).
[0137] To implement a service path, classifier 502 encapsulates a packet with a network service header that includes a service path identifier for a service function chain (e.g., SPI = 15) and a service index for the first hop in the selected service function chain (SI = 255). According to the techniques described in the present disclosure, classifier 502 also includes backup service function information (706) in the network service header. For example, classifier 502 includes the network address of a computing device hosting a backup service function instance. For example, a packet classified to SFC1 is encapsulated with a network service header that includes service path identifier 15, service index 255, and the network address of service function forwarder 604B to indicate the location of backup service function instance 606D for active service function instance 606A.
[0138] Classifier 502 sends a packet (708) encapsulated with a network service header that includes backup service function information to the first service function instance in the service chain (e.g., service function instance 606A). For example, classifier 502 sends the packet to service function forwarder 604A, which delivers the packet to service function instance 606A in the service chain.
[0139] Service function instance 606A may receive a packet (710) encapsulated with a network service header that includes backup service function information and send status information for the active service function to a computing device hosting one or more backup service functions (712) based at least on the backup service function information included in the network service header. For example, service function instance 606A may identify the service chain from service path identifier 15 and one or more computing devices hosting one or more backup service functions specified in a variable length context header of the network service header.
[0140] Service function instance 606A may send the status information to one or more computing devices hosting one or more backup service functions (714). In this example, service function instance 606A (e.g., the active service function) may send the status information to service function instance 606D (e.g., the backup service function).
[0141] Although not shown in Figure 7In the figure, each next hop of the service function can receive a packet encapsulated with a network service header including backup service function information and synchronize its session state with the computing device identified from the backup service function information. For example, the classifier 502 can send another packet encapsulated with a network service header that includes a service path identifier for the service function chain (e.g., SPI = 15), a service index (SI = 250) for the second service function instance in the selected service chain, and backup service information, so that the computing device hosting the second service function instance in the managed service chain can synchronize the state information with one or more backup service functions identified from the backup service function information at least based on the backup service function information.
[0142] The techniques described herein can be implemented in hardware, software, firmware, or any combination thereof. The various features described as modules, units, or components can be implemented together in an integrated logic device or separately as discrete but interoperable logic devices or other hardware devices. In some cases, the various features of an electronic circuit can be implemented as one or more integrated circuit devices, such as an integrated circuit chip or chipset.
[0143] If implemented in hardware, the present disclosure can relate to apparatuses such as a processor or an integrated circuit device, such as an integrated circuit chip or chipset. Alternatively or additionally, if implemented in software or firmware, the techniques can be at least partially implemented via a computer-readable data storage medium including instructions that, when executed, cause a processor to perform one or more of the above-described methods. For example, a computer-readable data storage medium can store such instructions for execution by a processor.
[0144] The computer-readable medium can form part of a computer program product, which can include packaging materials. The computer-readable medium can include computer data storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, magnetic or optical data storage media, and the like. In some examples, an article of manufacture can include one or more computer-readable storage media.
[0145] In some examples, the computer-readable storage medium can include a non-transitory medium. The term "non-transitory" can indicate that the storage medium is not embodied in a carrier wave or a propagated signal. In certain examples, the non-transitory storage medium can store data that can change over time (e.g., in RAM or a cache).
[0146] The code or instructions can be software and / or firmware executed by processing circuitry, which includes one or more processors, such as one or more digital signal processors (DSPs), general microprocessors, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Thus, as used herein, the term “processor” can refer to any of the foregoing structures or any other structure suitable for implementing the techniques described herein. Additionally, in some aspects, the functionality described in this disclosure may be provided within software modules or hardware modules.
Claims
1. A method for computer networking, comprising: receiving, by a computing device hosting an active service function of a managed service function chain, packets of a packet flow classified to the service function chain, wherein the packets are encapsulated with a network service header, the network service header including backup service function information that identifies one or more computing devices hosting one or more backup service functions; and sending, by the computing device hosting the active service function, state information of a session for the active service function to the one or more computing devices hosting the one or more backup service functions, at least based on the backup service function information included in the network service header, to synchronize the session state of the session for the active service function with the session states of corresponding sessions for the one or more backup service functions, so that the one or more backup service functions can assume stateful processing of the packets of the packet flow, the one or more backup service functions being identified by the backup service function information.
2. The method according to claim 1, wherein the backup service function information includes one or more network addresses of the one or more computing devices hosting the one or more backup service functions, and the method further comprises: identifying, by the computing device hosting the active service function, the one or more computing devices hosting the one or more backup service functions for the active service function of the service function chain, at least based on the backup service function information included in the network service header.
3. The method according to any one of claims 1-2, wherein the backup service function information is specified as one or more variable-length context headers of the network service header.
4. The method according to claim 3, wherein the network service header includes a value of a metadata type that indicates that the network service header includes backup service function information specified as one or more variable-length context headers.
5. A method for computer networking, comprising: classifying, by a service function classifier, packets of a packet flow to a service function chain; determining, by the service function classifier, one or more backup service functions for an active service function of the service function chain; encapsulating, by the service function classifier, the packets with a network service header, wherein the network service header includes backup service function information that identifies one or more computing devices hosting the one or more backup service functions; and The packet encapsulated with the network service header is sent by the service function classifier to a computing device hosting the active service function in the service function chain, so that the computing device hosting the active service function sends status information for a session of the active service function to one or more computing devices hosting the one or more backup service functions at least based on the backup service function information, to synchronize the session state of the session for the active service function with the session states of the corresponding sessions for the one or more backup service functions, so that the one or more backup service functions can assume state processing of the packets in the packet flow.
6. The method according to claim 5, wherein the backup service function information includes one or more network addresses of the one or more computing devices hosting the one or more backup service functions.
7. The method according to any one of claims 5-6, wherein the backup service function information is specified as one or more variable-length context headers of the network service header.
8. The method according to claim 7, wherein the network service header includes a value of a metadata type, and the value indicates that the network service header includes backup service function information specified as one or more variable-length context headers.
9. The method according to claim 5, wherein determining one or more backup service functions for the active service function of the service function chain includes: Performing a lookup in a table by the service function classifier, the table including one or more network addresses of the one or more computing devices hosting the one or more backup service functions.
10. The method according to claim 9, wherein the table further includes: A service path identifier for the service function chain; A service index providing the location of the active service function within the service function chain; And The network address of the computing device hosting the active service function.
11. The method according to claim 5, wherein the one or more backup service functions include a first one or more backup service functions, wherein the packet includes a first packet encapsulated with a first network service header, the first network service header including first backup service function information, and the method further includes: Classifying a second packet of the packet flow by the service function classifier into the service function chain; Determining, by the service function classifier, a second one or more backup service functions for the active service function of the service function chain, wherein the second one or more backup service functions are different from the first one or more backup service functions; Encapsulating, by the service function classifier, the second packet with a second network service header, wherein the second network service header includes second backup service function information, and the second backup service function information identifies one or more computing devices hosting the second one or more backup service functions; And The service function classifier sends the second packet encapsulated with the second network service header to the computing device hosting the active service function in the service function chain, so that the computing device hosting the active service function can send the status information of the session for the active service function to one or more computing devices hosting the second one or more backup service functions at least based on the second backup service function information.
12. A network system, comprising: A plurality of service functions; And A computing device including a service function classifier, the service function classifier being configured to: Classify packets of a packet flow classified into a service function chain, the service function chain including the plurality of service functions; Determine one or more backup service functions for the active service function of the service function chain; Encapsulate the packet with a network service header, where the network service header includes backup service function information, and the backup service function information identifies one or more computing devices hosting the one or more backup service functions; And Send the packet encapsulated with the network service header to the computing device hosting the active service function in the service function chain, so that the computing device hosting the active service function sends the status information of the session for the active service function to one or more computing devices hosting the one or more backup service functions at least based on the backup service function information, to synchronize the session state of the session for the active service function with the session states of the corresponding sessions for the one or more backup service functions, so that the one or more backup service functions can assume state processing of the packets of the packet flow.
13. The network system according to claim 12, wherein the computing device hosting the active service function is configured to: Receive the packet encapsulated with the network service header; and Send the status information of the session for the active service function to one or more computing devices hosting the one or more backup service functions at least based on the backup service function information included in the network service header.
14. The network system according to any one of claims 12-13, wherein the backup service function information includes one or more network addresses of the one or more computing devices hosting the one or more backup service functions, and the computing device is further configured to: Identify one or more computing devices hosting the one or more backup service functions for the active service function of the service function chain at least based on the backup service function information included in the network service header.
15. The network system according to claim 12, wherein the backup service function information includes one or more network addresses of the one or more computing devices hosting the one or more backup service functions.
16. The network system according to any one of claims 12 and 15, wherein the backup service function information is designated as one or more variable-length context headers of the network service header.
17. The network system according to claim 16, wherein the network service header includes a value of a metadata type, the value indicating that the network service header includes backup service function information designated as one or more variable-length context headers.
18. The network system according to claim 12, wherein, in order to determine one or more backup service functions of the active service function for the service function chain, the service function classifier is configured to: perform a lookup in a table that includes one or more network addresses of one or more computing devices hosting the one or more backup service functions.
19. The network system according to claim 18, wherein the table further includes: a service path identifier for the service function chain; a service index providing the location of the active service function within the service function chain; and the network address of the computing device hosting the active service function.
20. The network system according to claim 12, wherein the one or more backup service functions include a first one or more backup service functions, wherein the packet includes a first packet encapsulated with a first network service header, the first network service header including first backup service function information, and the service function classifier is further configured to: classify a second packet of the packet flow into the service function chain; determine a second one or more backup service functions of the active service function for the service function chain, wherein the second one or more backup service functions are different from the first one or more backup service functions; encapsulate the second packet with a second network service header, wherein the second network service header includes second backup service function information that identifies one or more computing devices hosting the second one or more backup service functions; and send the second packet encapsulated with the second network service header to the computing device hosting the active service function in the service function chain, such that the computing device hosting the active service function can send status information for the session of the active service function to the one or more computing devices hosting the second one or more backup service functions at least based on the second backup service function information.
21. A computer-readable storage medium encoded with instructions for causing one or more programmable processors to perform the method according to any one of claims 1-11.
Citation Information
Patent Citations
Tunneled packet aggregation for virtual networks
US9571394B1
Method and device for protecting stateful service function path
CN116530066A
Method and system of performing service function chaining
US20160119253A1
Service function path performance monitoring
US20170093658A1
Apparatus for processing network packet using service function chaining and method for controlling the same
US20170288998A1