BGP flow rule routing publication method, network device and storage medium
By generating detailed BGP flow rule routing and matching them with the outer MAC header, label stack, inner MAC header, IP header, etc. of the MPLS message, the problem of inaccurate MPLS message matching in the existing technology is solved and higher matching accuracy is achieved.
Patent Information
- Application Number
- CN202011172206.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-28
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2040-10-28
AI Technical Summary
In the prior art, BGP flow rule routing is not accurate enough in matching Multi-Protocol Label Switching (MPLS) messages, and it is impossible to refine the specific matching method.
By generating BGP flow rule routes containing tunnel type information, outer flow rules, tunnel header flow rules, and inner flow rules, and matching them with the outer MAC header, label stack, inner MAC header, and IP header of MPLS packets, the matching method of MPLS packets is refined.
Improves the matching accuracy of MPLS packets and can more accurately control the MPLS packet flow.
Smart Images

Figure CN114513457B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a method for publishing BGP flow rule routing, a network device, and a storage medium. Background Art
[0002] A Border Gateway Protocol flow specification (BGP flow specification or BGP flowspec) route is a type of BGP route that incorporates a new type of BGP network layer reachability information and extended community attributes. When a network device publishes a BGP flow specification route, it transmits the BGP flow specification route to a BGP flow specification peer. The BGP flow specification peer converts the preferred route from the received BGP flow specification route into a forwarding-layer flow control policy. By matching received packets against the flow control policy, it executes the actions specified in the flow control policy when a match is found, thereby controlling attack traffic.
[0003] Currently, BGP flow rule routing has not yet refined the specific method for matching multi-protocol labelswitching (MPLS) packets, resulting in insufficient accuracy in matching MPLS packets using BGP flow rule routing. Summary of the Invention
[0004] The embodiments of the present application provide a method for publishing BGP flow rule routing, a network device, and a storage medium, which can improve the accuracy of MPLS message matching. The technical solution is as follows.
[0005] In a first aspect, a method for publishing BGP flow rule routing is provided, in which a network device generates a BGP flow rule (BGP flow specification) routing, wherein the BGP flow rule routing includes tunnel type information, outer flow rules (outer flowspec), tunnel header flow rules (tunnel header flowspec) and inner flow rules (innerflowspec), wherein the tunnel type information is used to indicate that the type of the tunnel is Multi-Protocol Label Switching (MPLS), the outer flow rules are used to match the outer media access control MAC header of the MPLS message, the tunnel header flow rules are used to match the label stack of the MPLS message, and the inner flow rules are used to match at least one of the inner MAC header, IP header and transport layer protocol header of the MPLS message; and the network device publishes the BGP flow rule routing.
[0006] The above provides a new BGP flow support method for MPLS packets, which supports MPLS packets by newly defining a tunnel type and refines the flow rules in BGP flow rule routing according to the format of MPLS packets. It matches the outer MAC header of the MPLS packet based on the outer flow rule, matches the label stack of the MPLS packet based on the tunnel header flow rule, and matches the inner MAC header, IP header, transport layer protocol header, etc. of the MPLS packet based on the inner flow rule. Network devices can use BGP flow rule routing to match each part of the MPLS packet separately, thereby improving the accuracy of MPLS packet matching.
[0007] In a possible implementation, the tunnel header flow rule includes a label value, and the label value in the tunnel header flow rule is used to match the label value of the MPLS label in the label stack.
[0008] Through the above optional method, the label value in the tunnel header flow rule can be used to match the label value in the MPLS message, thereby refining the matching method of the label value in the MPLS message and helping to improve the accuracy of MPLS message matching.
[0009] In a possible implementation, the label value in the tunnel header flow rule includes at least one set of operators and values, and the at least one set of operators and values is used to indicate a value range of the label value of the successfully matched MPLS label.
[0010] In one possible implementation, the label value in the tunnel header flow rule includes at least one of a first label value or a second label value, the first label value is used to match the label value in the outer MPLS label in the label stack, and the second label value is used to match the label value in the inner MPLS label in the label stack.
[0011] Through the above optional method, the two label values in the tunnel header flow rule can be used to match the outer label value and inner label value in the MPLS message respectively, so that the solution supports scenarios where the MPLS message contains multiple labels, which helps to improve the accuracy of MPLS message matching.
[0012] In one possible implementation, the tunnel header flow rule includes at least one of a first component or a second component; the first component includes first type information and the first label value, and the first type information is used to identify that the first component carries the first label value; the second component includes second type information and the second label value, and the second type information is used to identify that the second component carries the second label value.
[0013] In a possible implementation, the tunnel header flow rule includes a traffic class TC, and the TC in the tunnel header flow rule is used to match the TC of the MPLS label in the MPLS packet.
[0014] Through the above optional method, the TC in the tunnel header flow rule can be used to match the TC in the MPLS message, thereby refining the matching method of the TC in the MPLS message and helping to improve the accuracy of MPLS message matching.
[0015] In a possible implementation, the TC in the tunnel header flow rule includes at least one set of operators and values, and the at least one set of operators and values is used to indicate a value range of the TC of the successfully matched MPLS label.
[0016] In one possible implementation, the TC in the tunnel header flow rule includes at least one of a first TC or a second TC, the first TC is used to match the TC in the outer MPLS label in the MPLS packet, and the second TC is used to match the TC in the inner MPLS label in the MPLS packet.
[0017] In one possible implementation, the tunnel header flow rule includes at least one of a third component or a fourth component; the third component includes third type information and the first TC, and the third type information is used to identify that the third component carries the first TC; the fourth component includes fourth type information and the second TC, and the fourth type information is used to identify that the fourth component carries the second TC.
[0018] In a possible implementation, the tunnel header flow rule includes a time to live (TTL), and the TTL in the tunnel header flow rule is used to match the TTL of the MPLS label in the MPLS packet.
[0019] Through the above optional method, the TTL in the tunnel header flow rule can be used to match the TTL in the MPLS message, thereby refining the matching method of the TTL in the MPLS message and helping to improve the accuracy of MPLS message matching.
[0020] In a possible implementation, the TTL in the tunnel header flow rule includes at least one set of operators and values, and the at least one set of operators and values is used to indicate a value range of the TTL of the successfully matched MPLS label.
[0021] In one possible implementation, the TTL in the tunnel header flow rule includes at least one of a first TTL or a second TTL, the first TTL is used to match the TTL in the outer MPLS label in the MPLS message, and the second TTL is used to match the TTL in the inner MPLS label in the MPLS message.
[0022] In one possible implementation, the tunnel header flow rule includes at least one of the fifth component or the sixth component; the fifth component includes fifth type information and the first TTL, and the fifth type information is used to identify that the fifth component carries the first TTL; the sixth component includes sixth type information and the second TTL, and the sixth type information is used to identify that the sixth component carries the second TTL.
[0023] In one possible implementation, the BGP flow rule route is carried in the multi-protocol reachable network layer reachability information NLRI, and the multi-protocol reachable NLRI includes the BGP flow rule route and the first address family identifier AFI, and the first AFI is used to indicate that the outer layer flow rule is the flow rule corresponding to the MAC header.
[0024] In a possible implementation, the inner flow rule includes a second AFI, where the second AFI is used to indicate whether to match an inner MAC header of an MPLS packet.
[0025] In a possible implementation, the inner layer flow rule includes an inner layer AFI field, and the second AFI is the AFI carried by the inner layer AFI field.
[0026] In a possible implementation, the inner layer flow rule includes a third AFI, and the third AFI is used to indicate whether to match the IP header or the transport layer protocol header of the MPLS packet.
[0027] In a possible implementation, the inner layer flow rule includes an L3-AFI field, and the third AFI is the AFI carried by the L3-AFI field.
[0028] In one possible implementation, the third AFI is used to indicate matching with the Internet Protocol version 4 IPv4 header of the MPLS message; or, the third AFI is used to indicate matching with the Internet Protocol version 6 IPv6 header of the MPLS message; or, the third AFI is used to indicate not matching with the IP header and transport layer protocol header of the MPLS message.
[0029] In a possible implementation, the BGP flow rule routing further includes MPLS action information, where the MPLS action information is used to indicate a processing action to be performed on an MPLS label in an MPLS packet.
[0030] In one possible implementation, the MPLS action information includes a pop-up flag, an add flag, or a replace flag, wherein the pop-up flag is used to indicate popping an MPLS label in an MPLS message, the add flag is used to indicate adding an MPLS label to an MPLS message, and the replace flag is used to indicate replacing an MPLS label in an MPLS message.
[0031] In a possible implementation, the MPLS action information further includes a target MPLS label, the addition flag is used to instruct to add the target MPLS label, and the replacement flag is used to instruct to replace the MPLS label in the MPLS packet with the target MPLS label.
[0032] In one possible implementation, the pop-up identifier includes at least one of a first pop-up identifier or a second pop-up identifier, the first pop-up identifier is used to indicate the pop-up of an outer MPLS label, and the second pop-up identifier is used to indicate the pop-up of an inner MPLS label; the add identifier includes a first add identifier and a second add identifier, the first add identifier is used to indicate the addition of an outer MPLS label, and the second add identifier is used to indicate the addition of an inner MPLS label; the replacement identifier includes at least one of a first replacement identifier or a second replacement identifier, the first replacement identifier is used to indicate the replacement of an outer MPLS label, and the second replacement identifier is used to indicate the replacement of an inner MPLS label.
[0033] In a second aspect, a network device is provided, which has the function of implementing the first aspect or any optional manner of the first aspect. The network device includes at least one unit, and the at least one unit is used to implement the method provided by the first aspect or any optional manner of the first aspect.
[0034] In some embodiments, the units in the network device are implemented by software, and the units in the network device are program modules. In other embodiments, the units in the network device are implemented by hardware or firmware. The specific details of the network device provided in the second aspect can be found in the first aspect or any optional embodiment of the first aspect, and will not be repeated here.
[0035] In a third aspect, a network device is provided, comprising a processor and a communication interface. The processor is configured to execute instructions so that the network device performs the method provided in the first aspect or any optional embodiment of the first aspect, and the communication interface is configured to receive or send messages. Specific details of the network device provided in the third aspect can be found in the first aspect or any optional embodiment of the first aspect and are not further described here.
[0036] In a fourth aspect, a network device is provided, comprising: a main control board and an interface board. The main control board comprises a first processor and a first memory. The interface board comprises a second processor, a second memory, and an interface card. The main control board and the interface board are coupled.
[0037] The first memory can be used to store program code, and the first processor is used to call the program code in the first memory to perform the following operations: generate BGP flow rule routing, the BGP flow rule routing includes tunnel type information, outer flow rules, tunnel header flow rules and inner flow rules, the tunnel type information is used to indicate that the type of the tunnel is multi-protocol label switching MPLS, the outer flow rules are used to match the outer media access control MAC header of the MPLS message, the tunnel header flow rules are used to match the label stack of the MPLS message, and the inner flow rules are used to match at least one of the inner MAC header, IP header, and transport layer protocol header of the MPLS message.
[0038] The second memory may be used to store program codes, and the second processor is used to call the program codes in the second memory to trigger the interface card to perform the following operations: publishing the BGP flow rule routing.
[0039] In a possible implementation, an inter-process communication (IPC) channel is established between the main control board and the interface board, and the main control board and the interface board communicate with each other through the IPC channel.
[0040] In a fifth aspect, a computer-readable storage medium is provided, in which at least one instruction is stored. The instruction is read by a processor to enable a network device to execute the method provided in the first aspect or any optional manner of the first aspect.
[0041] In a sixth aspect, a computer program product is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a network device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the network device to perform the method provided in the first aspect or any optional embodiment of the first aspect.
[0042] In a seventh aspect, a chip is provided. When the chip runs on a network device, the network device executes the method provided in the first aspect or any optional manner of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 1 is a schematic diagram of the architecture of a network system 10 provided in an embodiment of the present application;
[0044] Figure 2This is a schematic diagram of a message format provided in an embodiment of the present application;
[0045] Figure 3 This is a flow chart of a method for publishing BGP flow rule routing provided by an embodiment of the present application;
[0046] Figure 4 4 is a schematic diagram of the structure of a network device 400 provided in an embodiment of the present application;
[0047] Figure 5 6 is a schematic diagram of the structure of a network device 600 provided in an embodiment of the present application;
[0048] Figure 6 It is a structural diagram of a network device 700 provided in an embodiment of the present application. DETAILED DESCRIPTION
[0049] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0050] The following is an introduction to some terminology concepts involved in this embodiment.
[0051] BGP flow specification routing: This includes a new type of BGP network layer reachability information (NLRI) and extended community attributes. Through this new network layer reachability information and extended community attributes, BGP flow specification routing can carry traffic matching conditions and actions to be performed after traffic matching.
[0052] BGP flow specification peer relationships are established between the device that creates BGP flow specification routes and the network ingress device to transmit BGP flow specification routes. Upon receiving a BGP flow specification route, the BGP flow specification peer converts the preferred route into a forwarding-layer traffic control policy, thereby controlling attack traffic.
[0053] The following is a brief introduction to the situations faced by BGP flow in related technologies.
[0054] RFC 5575, a request for comments (RFC), defines two types of BGP flow routing: the regular Internet Protocol version 4 flow specification (IPv4 flow specification) and the Layer 3 virtual private network flow specification (L3 VPN flow specification). Draft-ietf-idr-flow-spec-v6 adds the Internet Protocol version 6 flow specification (IPv6 flow specification) and the Layer 3 IPv6 VPN flow specification (L3 VPNv6 flow specification). Draft-ietf-idr-flowspec-l2vpn adds L2 Ethernet routing. Draft-ietf-idr-flowspec-nvo3 adds tunnel-type routes, including virtual extensible local area network (VXLAN), VXLAN generic protocol encapsulation (VXLAN-GPE), network virtual GRE (NVGRE), Layer 2 tunneling protocol-version 3 (L2TPv3), generic routing encapsulation (GRE), and mobile IP data encapsulation and tunneling (internet protocol in internet protocol, IP-in-IP). Draft-ietf-idr-flowspec-mpls-match adds MPLS label routes.
[0055] The draft-ietf-idr-flowspec-mpls-match specification defines two matching conditions: label value and experimental (EXP) value. However, it does not specify the MPLS label packet format, nor does it provide specific matching criteria for these specific MPLS label packets. For example, a typical labeled packet can consist of an outer Layer 2 header + label + inner Layer 2 header + payload, or an outer Layer 2 header + label + inner Layer 2 header + Internet Protocol (IP) header + Transmission Control Protocol (TCP) / User Datagram Protocol (UDP) header + payload. The original draft only roughly matched label information (label value and EXP value) against the IP header and TCP / UDP header, but not against the outer Layer 2 header and inner Layer 2 header, making it impossible to accurately match a specific packet.
[0056] This embodiment proposes a new BGP flow support method for label messages and solves the problem of accurate matching of MPLS messages.
[0057] The following describes the system operating environment provided by the embodiments of the present application.
[0058] Attachment Figure 1 1 is a schematic diagram of the architecture of a network system 10 provided in an embodiment of the present application. Network system 10 includes R1, R2, R3, and R4. R1, R2, R3, and R4 are all network devices. Network devices are, for example, switches or routers. Network devices are, for example, physical devices or virtualized devices.
[0059] When network system 10 implements BGP flows, the operating principle is as follows: R1 and R2 establish a BGP flow specification peer relationship. R2 and R3 establish a BGP flow specification peer relationship. R3 publishes a BGP flow specification route to R2. R2 receives the BGP flow specification route and then passes it to R1. R1 and R2 convert the BGP flow specification route into a flow control policy, and R1 and R2 control the flow matching the policy. By passing the BGP flow rule route described below, network system 10 facilitates more precise matching and control of MPLS packet flows.
[0060] The following describes the message format.
[0061] Please refer to the attached Figure 2 , attached Figure 2 This is a diagram showing the format of the tunneled traffic flowspecNLRI. Figure 2 The network layer reachability information for the tunnel traffic shown includes BGP flow rule routing. Figure 2 The format definition of the network layer reachability information of the tunnel traffic shown in FIG can be referred to draft-ietf-idr-flowspec-nvo3. Figure 2 The routing format of the tunnel traffic shown is extended with a protocol to support accurate matching of MPLS packets.
[0062] Specifically, the network layer reachability information of the tunnel traffic includes the tunnel type field, the outer flow rule (outer flowspec) field, the tunnel header flow rule (tunnel header flowspec) field, the optional inner flow rule (optional inner flowspec) field, etc. The information carried by these fields is specifically introduced below.
[0063] 1. Tunnel Type Information
[0064] Tunnel type information is the type value carried in the tunnel type field. Tunnel type information is used to indicate MPLS. Because BGP flow specification routes contain tunnel type information, they can be used when tunnel traffic is MPLS packet flow. Therefore, by adding a new tunnel type to support MPLS packets, BGP flow specification routes can be better applied in MPLS scenarios.
[0065] 2. Outer Laminar Flow Rules
[0066] The outer flow rule is the information carried by the outer flow rule field. The outer flow rule is used to match the outer media access control (MAC) header of the MPLS message. The MAC header is also called the layer 2 header, Ethernet header, or L2 header. The MPLS message may include two MAC headers, namely the outer MAC header (also called the outer layer 2 header) and the inner MAC header (also called the inner layer 2 header). For example, the outer MAC header is located at the outer layer of the label stack in the MPLS message, and the inner MAC header is located at the inner layer of the label stack in the MPLS message. In other words, the outer MAC header is before the label stack, and the inner MAC header is after the label stack.
[0067] The outer flow rule includes MAC layer information. For example, the outer flow rule includes 15 types of MAC layer information, such as Ethernet type, source MAC address, destination MAC address, destination service access point (DSAP), source service access point (SSAP), virtual local area network (VLAN) identity (ID), and VLAN priority code point (PCP). By including 15 types of MAC layer information, the outer flow rule can match the 15 fields in the MAC header respectively. For the specific content of the outer flow rule, please refer to 2.1 of draft-ietf-idr-flowspec-l2vpn. In some embodiments, the MAC layer information included in the outer flow rule appears alone; in other embodiments, the MAC layer information included in the outer flow rule appears in combination, that is, the outer flow rule includes multiple types of MAC layer information at the same time.
[0068] The encoding methods of the outer layer flow rules include but are not limited to the following two methods.
[0069] Encoding method 1: Use operators (operator, op) and values (value) that appear in pairs to encode.
[0070] When using encoding mode 1, the outer flow rule includes at least one set of operators and values ([op, value]). At least one set of operators and values is used to indicate the value range of the MAC layer information of the outer MAC header that matches successfully. Specifically, the encoding format of the outer flow rule is<type(1octet),length(1octet),[op,value]+> . Among them, the Chinese translation of type is type, the Chinese translation of octet is byte, and the Chinese translation of length is length. + means that [op, value] can appear multiple times. For example, encoding method 1 is applied to the scenario of matching ethernet type. Specifically, for ethernet type, it is matched according to the length and [op, value] in the outer flow rule, where the definition of the operator is shown in 4.2.1.1 of RFC5575bis, which can be greater than, less than, equal to, or a combination of greater than or equal to. In this way, a range of ethernet types is matched.
[0071] Coding method 2: using prefix length and prefix coding.
[0072] When using encoding method 2, the outer flow rule includes prefix length and prefix. Specifically, the encoding format of the outer flow rule is<type(1octet),MAC prefix length(1octet),MAC prefix> Encoding method 2 is suitable for scenarios where MAC addresses (such as source or destination MAC addresses) are matched. For example, if the prefix length in the outer flow rule is 24 and the prefix is 0000-1200-0000, then a range of MAC addresses is matched, that is, all MAC addresses with a prefix of 0000-1200.
[0073] In some embodiments, when the MAC layer information contained in the outer flow rule appears, the match is successful when multiple MAC layer information in the outer flow rule matches. For example, the content carried by the outer flow rule is the source MAC address and the destination MAC address. The format of the outer flow rule is<type(1octet),MAC prefix length(1octet),MAC prefix> , a match succeeds when the source MAC address falls within the range specified by the outer layer flow rule and the destination MAC address falls within the range specified by the outer layer flow rule.
[0074] This embodiment does not limit which fields in the outer MAC header are matched by the outer flow rule. The specific fields to be matched in the outer MAC header can be determined based on actual needs. In some embodiments, the outer flow rule is used to match all fields in the outer MAC header of the MPLS packet. In other embodiments, the outer flow rule is used to match only some fields in the outer MAC header of the MPLS packet. There are various ways to determine which field in the outer MAC header is matched. In some embodiments, the specific matching field in the outer MAC header is determined through manual configuration. In other embodiments, the specific matching field in the outer MAC header is automatically determined by a network device. For example, a network device receives an attack packet and determines the specific matching field based on the characteristics of the attack packet.
[0075] In some embodiments, an address family identifier (AFI) is used to indicate that the outer flow rule is to match the MAC header. This embodiment involves three types of AFIs, each of which is carried in a different AFI field. To distinguish the descriptions, the three AFIs are referred to below as the first AFI, the second AFI, and the third AFI. From the perspective of the message structure, the first AFI is located at the outermost layer of the message, the second AFI is next, and the third AFI is located at the innermost layer of the message. For example, the first AFI is outside the NLRI, the second AFI is carried in the inner AFI field, and the third AFI is carried in the layer 3 AFI (L3-AFI) field in the inner flow rule (inner flowspec).
[0076] The first AFI is the AFI corresponding to the outer-layer flow rule. The first AFI is used to indicate that the outer-layer flow rule is a flow rule corresponding to the MAC header. For example, the first AFI is 6. Specifically, the AFI corresponding to the MAC header is 6, the AFI corresponding to the Internet Protocol version 4 (IPv4) header is 1, and the AFI corresponding to the Internet Protocol version 6 (IPv6) header is 2. Since the format of an MPLS packet is MAC header + label header + Ethernet header or IP header, with the MAC header being the outermost layer, an AFI value of 6 (i.e., the first AFI) indicates that the information contained in the outer-layer flow rule belongs to the MAC layer and that the outer-layer flow rule is intended to match the MAC header. In this embodiment, the terms IP header and Layer 3 (L3) header are used interchangeably. The terms transport layer protocol header and Layer 4 (L4) header are used interchangeably. The terms MAC header and Layer 2 (L2) header are used interchangeably in this embodiment.
[0077] In some embodiments, the first AFI is information carried by the address family identifier field in the multi-protocol reachable NLRI (MP_REACH_NLRI). Figure 2The BGP flow rule routing shown is carried in MP_REACH_NLRI. The entire MP_REACH_NLRI contains three AFI fields. See Table 1 below, which is a format diagram of MP_REACH_NLRI. MP_REACH_NLRI includes a 2-byte addressfamily identifier field, a 1-byte subsequent address family identifier field, a 1-byte next hop network address length field, a 1-byte reserved field, a variable-length network layer reachability information (NLRI) field, etc. Appendix Figure 2 The network layer reachability information of the tunnel traffic shown is located in the variable-length network layer reachability information field in Table 1. The address family identifier field in Table 1 is the outermost field of the three AFI fields, and the first AFI carries the address family identifier field in Table 1.
[0078] Table 1
[0079] Address family identifier (2 bytes) subsequent address family identifier (1 byte) length of next hop network address (1 byte) network address of next hop (variable) reserved (1 byte) network layer reachability information(variable)
[0080] MP_REACH_NLRI is a path attribute newly added in RFC 4670. For the definition of MP_REACH_NLRI, refer to RFC 4760.
[0081] 3. Tunnel head flow rules
[0082] The tunnel header flow rule is the information carried by the tunnel header flow rule field. The tunnel header flow rule is used to match the label stack of the MPLS message. The label stack of the MPLS message includes at least one MPLS label. An MPLS label includes fields such as a label value (label) field, a traffic control (TC) field, and a time to live (TTL) field. In this embodiment, the tunnel header flow rule contains information corresponding to each field in the MPLS label, so as to accurately match each field in the MPLS label. Specifically, the tunnel header flow rule includes a label value, TC, and TTL, which are introduced below through (3.1) to (3.3).
[0083] (3.1) Tag value
[0084] The label value in the tunnel header flow rule is used to match the label value of the MPLS label in the label stack of the MPLS packet. In some embodiments, the label value in the tunnel header flow rule includes at least one set of operators and values, and at least one set of operators and values is used to indicate the value range of the label value of the MPLS label that is successfully matched. Specifically, the encoding format used by the label value in the tunnel header flow rule is<type(1octet),length(1octet),[op,value]+> .
[0085] [op, value] represents a set of operators and values, where op represents the operator and value represents the value. [op, value] can specify a range of label values (e.g., greater than 5000 and less than 50000). If the label value of the MPLS label in the MPLS packet is within this range, the match is successful. The op encoding is as described in Section 4 of RFC5575, and the value field is encoded as 3 bytes (24 bits). Of the 24 bits in the value field, 20 bits are the label value, and the remaining 4 bits are all 0. Optionally, the first 4 bits of the 24 bits in the value field are all 0, and the remaining 20 bits are the label value.
[0086] In some embodiments, a tunnel header flow rule includes multiple label values to match label values in different MPLS labels. For example, the label value in the tunnel header flow rule includes at least one of a first label value and a second label value. The first label value is used to match the label value (outer label) in the outer MPLS label in the label stack. The second label value is used to match the label value (inner label) in the inner MPLS label in the label stack.
[0087] Specifically, the label stack of an MPLS packet may include multiple MPLS labels. Taking an MPLS packet including two layers of MPLS labels as an example, the overall format of the MPLS packet is outer MAC header + outer MPLS label + inner MPLS label + inner MAC header (or IP header). The outer MPLS label is adjacent to the outer MAC header. In other words, the outer MPLS label refers to the MPLS label immediately following the outer MAC header. The outer MPLS label can also be called the outermost MPLS label. The inner MPLS label follows the outer MPLS label. At least one MPLS label exists between the inner MPLS label and the outer MAC header.
[0088] The second label value can be used to match any inner label following the outer MPLS label. In some embodiments, the second label value is used to match the label value in the next-outer MPLS label in the label stack. The next-outer label is the label following the outermost MPLS label.
[0089] In some embodiments, the specific content of the tunnel header flow rule is carried by adding at least one type of tunnel header flow rule component (tunnel header flowspec component). A tunnel header flowspec component includes parts such as type, length, and value. In order to distinguish the description, different types of tunnel header flowspec components are respectively referred to as the first component (component), the second component, the third component, the fourth component, the fifth component, and the sixth component, and the types (type values) of the first component, the second component, the third component, the fourth component, the fifth component, and the sixth component are respectively referred to as the first type information, the second type information, the third type information, the fourth type information, the fifth type information, and the sixth type information.
[0090] The first component refers to the tunnel header flowspeccomponent that carries the first label value (outer label). The first component includes first type information and the first label value. The first type information is used to identify that the first component carries the first label value. For example, the first component is a type 6-outer label (type6-outer label) component. The first type information is the type value in the type6-outer label component. Of course, type6 is only a schematic name, and this embodiment does not limit the type of the component carrying the outer label value to 6. By adding the first component, it can be used to match the outermost label value of the MPLS message.
[0091] The second component refers to the tunnel header flowspeccomponent that carries the second label value (inner label). The second component includes second type information and a second label value, and the second type information is used to identify that the second component carries the second label value. For example, the second component is a type 7-inner label (type7-inner label) component. The second type information is the type value in the type7-inner label component. Of course, type7 is only a schematic designation, and this embodiment does not limit the type of the component carrying the inner label value to 7. By adding a second component, it can be used to match the inner label value of the MPLS message (such as the sub-outer label value).
[0092] (3.2)TC
[0093] The TC in the tunnel header flow rule is used to match the TC of the MPLS label in the label stack of the MPLS packet. In some embodiments, the TC in the tunnel header flow rule includes at least one set of operators and values, and at least one set of operators and values is used to indicate the value range of the TC of the MPLS label that is successfully matched. Specifically, the encoding format used by the TC in the tunnel header flow rule is<type(1octet),length(1octet),[op,value]+> .
[0094] [op, value] represents a set of operators and values, where op represents the operator and value represents the value. [op, value] can specify a range of TCs. A match is successful if the TC of the MPLS label in the MPLS packet falls within this range. The op field is encoded as described in Section 4 of RFC5575, and the value field is encoded as 1 byte (8 bits). Of the 8 bits in the value field, 3 bits represent the TC, and the remaining 5 bits are all 0. Optionally, the first 5 bits of the [op, value] portion are all 0, and the last 3 bits represent the TC.
[0095] In some embodiments, a tunnel header flow rule includes multiple TCs to match TCs in different MPLS labels. For example, the TCs in the tunnel header flow rule include at least one of a first TC and a second TC. The first TC is used to match the TC in the outer MPLS label in the label stack (the outer TC). The second TC is used to match the TC in the inner MPLS label in the label stack (the inner TC).
[0096] The second TC can be used to match any inner label following the outer MPLS label. In some embodiments, the second TC is used to match the TC in the next outer MPLS label in the label stack.
[0097] In some embodiments, the TC is carried by adding at least one type of tunnel header flowspec component. Specifically, the tunnel header flow rule includes at least one of the third component or the fourth component.
[0098] The third component refers to the tunnel header flowspec component that carries the first TC (outer TC). The third component includes third type information and the first TC. The third type information is used to identify that the third component carries the first TC. For example, the third component is the type8-outer TC1 component. The third type information is the type value in the type8-outer TC1 component. Of course, type8 is merely a schematic designation, and this embodiment does not limit the type of the component carrying the TC value in the outer label to type 6. By adding the third component, it can be used to match the TC value in the outermost label of the MPLS packet.
[0099] The fourth component refers to the tunnel header flowspec component that carries the second TC (inner TC). The fourth component includes fourth type information and the second TC, and the fourth type information is used to identify that the fourth component carries the second TC. For example, the fourth component is the type9-inner TC2 component. The fourth type information is the type value in the type9-inner TC2 component. Of course, type9 is only a schematic designation, and this embodiment does not limit the type of the component that carries the TC value in the inner label to 9. By adding the fourth component, it can be used to match the TC value in the inner label (such as the second outer label) of the MPLS packet.
[0100] (3.3)TTL
[0101] The TTL in the tunnel header flow rule is used to match the TTL of the MPLS label in the label stack of the MPLS packet. In some embodiments, the TTL in the tunnel header flow rule includes at least one set of operators and values, and at least one set of operators and values is used to indicate the value range of the TTL of the MPLS label that is successfully matched. Specifically, the encoding format used by the TTL in the tunnel header flow rule is<type(1octet),length(1octet),[op,value]+> .
[0102] [op, value] represents a set of operators and values, where op represents the operator and value represents the value. [op, value] can specify a TTL range. A match is successful if the TTL of the MPLS label in the MPLS packet falls within this range. The op field is encoded as described in Section 4 of RFC 5575, and the value field is encoded as 1 byte (8 bits). The value field includes the TTL specified in the tunnel header flow rule.
[0103] In some embodiments, a tunnel header flow rule includes multiple TTLs, each of which is used to match the TTLs in different MPLS labels. For example, the TTL in the tunnel header flow rule includes at least one of a first TTL and a second TTL. The first TTL is used to match the TTL in the outer MPLS label in the label stack (the outer TTL). The second TTL is used to match the TTL in the inner MPLS label in the label stack (the inner TTL).
[0104] The second TTL can be used to match any inner label following the outer MPLS label. In some embodiments, the second TTL is used to match the TTL in the next outer MPLS label in the label stack.
[0105] In some embodiments, at least one type of tunnel header flowspec component is added to carry the TTL in the tunnel header flow rule. Combined with the first TTL and the second TTL described above, the tunnel header flow rule includes at least one of the fifth component or the sixth component.
[0106] The fifth component refers to the tunnel header flowspec component that carries the first TTL (outer TTL). The fifth component includes the fifth type information and the first TTL. The fifth type information is used to identify that the fifth component carries the first TTL. For example, the fifth component is the type 10-outer TTL (type10-outer TTL) component. The fifth type information is the type value in the type10-outer TTL component. Of course, type10 is only a schematic designation, and this embodiment does not limit the type of the component carrying the TTL value in the outer label to 10. By adding the fifth component, it can be used to match the outer TTL value of the MPLS message (such as the outermost TTL value).
[0107] The sixth component refers to the tunnel header flowspec component that carries the second TTL (inner TTL). The sixth component includes the sixth type information and the second TTL, and the sixth type information is used to identify that the sixth component carries the second TTL. For example, the sixth component is a type 11-inner TTL (type11-inner TTL) component. Of course, type11 is only a schematic name, and this embodiment does not limit the type of the component carrying the TTL value in the inner label to 11. By adding the sixth component, it can be used to match the inner TTL value of the MPLS message (such as the sub-outer TTL value).
[0108] The six tunnelheader flowspec components extended by this embodiment are described above through the first component, the second component to the sixth component. It can be determined which types of the six tunnel header flowspec components to match according to actual needs.
[0109] 4. Internal laminar flow rules
[0110] The inner flow rule is the information carried by the inner flow rule field. The inner flow rule is used to match at least one of the inner MAC header, IP header, and transport layer protocol header of the MPLS message. Specifically, refer to Table 2 below, which shows the format of the L2 flow rule NLRI. The inner flow rule includes a 2- or 3-byte total length (total-length) field, a 2-byte L3-AFI field, a 2- or 3-byte L2 length (L2-length) field, and a variable-length NLRI value (NLRI-value) field. For the meaning of each field in Table 2, please refer to draft-ietf-idr-flowspec-l2vpn-15.
[0111] Table 2
[0112] total-length (0xnn or 0xfnnn (2 or 3 bytes) L3-AFI (2 bytes) L2-length (0xnn or 0xfnnn (2 or 3 bytes) NLRI-value (variable)
[0113] The inner flow rule includes at least one of MAC layer information, IP layer information, and transport layer information. That is, the content of the inner flow rule may include one of MAC layer information, IP layer information, and transport layer information, or may include two or more of the MAC layer information, IP layer information, and transport layer information at the same time. In the case where the inner flow rule includes MAC layer information, the type of MAC layer information in the inner flow rule is similar to that of the outer flow rule. For example, the inner flow rule can also include 15 types such as source MAC address and destination MAC address. For details, see 2.1 in draft-ietf-idr-flowspec-l2vpn. In the case where the inner flow rule includes IP layer information, the IP layer information in the inner flow rule includes at least one of IPv4 information or IPv6 information. For example, the IP layer information in the inner flow rule includes the destination prefix, source prefix, IP protocol, etc. In the case where the inner flow rule includes transport layer information, the transport layer information in the inner flow rule includes at least one of TCP information or UDP information. For example, the transport layer information in the inner layer flow rule includes the destination port, source port, TCP flags, and the like.
[0114] The inner flow rule specifies the value range of the MAC layer information of the inner MAC header that matches successfully. The matching method of the inner flow rule is the same as that of the outer flow rule. Specifically, the inner flow rule can also adopt the above-mentioned encoding method 1, that is, using paired operators and value encoding; or, the inner flow rule adopts the above-mentioned encoding method 2, that is, using prefix length and prefix encoding. For example, in the scenario of matching MAC addresses, the inner flow rule adopts encoding method 2, and the inner flow rule includes<type(1octet),MAC prefix length(1octet),MAC prefix> , thereby specifying the value range of the MAC prefix that matches successfully.
[0115] In some embodiments, the AFI included in the inner flow rule identifies whether the information in the inner flow rule is MAC layer information or IP layer information. For example, the inner flow rule includes a second AFI, and the second AFI indicates whether to match the inner MAC header of the MPLS message. For example, if the value of the second AFI is 6, it indicates that the inner MAC header of the MPLS message is to be matched (i.e., the inner MAC header information needs to be filtered). If the value of the second AFI is 1 or 2, it indicates that the inner MAC header of the MPLS message is not to be matched (i.e., the inner MAC header information is not to be filtered), but the IPv4 header and transport layer protocol header of the MPLS message are to be matched, or the IPv6 header and transport layer protocol header of the MPLS message are to be matched (i.e., the IPv4 header, IPv6 header and transport layer protocol header are to be directly filtered). In some embodiments, the second AFI is carried in the inner AFI field. In other words, the second AFI is the AFI carried by the inner AFI field.
[0116] When an inner flow rule includes both MAC layer information and IP layer information, in some embodiments, the AFI included in the inner flow rule also indicates whether the MAC layer information is followed by IPv4 or IPv6 information. Specifically, the inner flow rule includes a third AFI. The third AFI is used to indicate whether to match the IP header or transport layer protocol header of the MPLS packet. In some embodiments, the third AFI is carried in the L3-AFI field. Specifically, the inner flow rule includes the L3-AFI field, and the third AFI is the AFI carried in the L3-AFI field. In other words, the third AFI is the value of the L3-AFI field.
[0117] In some embodiments, the third AFI is used to indicate the use of inner-layer flow rules to match the IPv4 header of the MPLS message; or, the third AFI is used to indicate the use of inner-layer flow rules to match the IPv6 header of the MPLS message; or, the third AFI is used to indicate not to match the IP header and transport layer protocol header of the MPLS message. Taking the L3-AFI field as an example, if the value of the L3-AFI field is 0, it means that the IP layer information or transport layer protocol information is not filtered. If the value of the L3-AFI field is 1, it means that the inner-layer flow rule is to match IPv4 information; if the value of the L3-AFI field is 2, it means that the inner-layer flow rule is to match IPv6 information. Then, the MPLS message is matched according to the corresponding type value in the NLRI-value, because IPv4 and IPv6 respectively define their own matching type values.
[0118] The inner flowspec variable field in an inner flow rule is used to match the field following the label stack in an MPLS packet. The inner flowspec variable field can contain various content. The following examples illustrate two scenarios.
[0119] Scenario 1: L2 VPN
[0120] In an L2 VPN scenario, the packet structure of an MPLS packet can be simplified as outer MAC header + label stack + inner MAC header + IP header + payload. The payload includes the transport layer protocol header and application layer information. Accordingly, the innerflowspec variable field contains MAC layer information, and the inner flowspec variable field is used to match the inner MAC header following the label stack. Alternatively, the inner flowspec variable field contains MAC layer information and IP layer information, and the innerflowspec variable field is used to match the inner MAC header and IP header following the label stack. Alternatively, the innerflowspec variable field contains MAC layer information, IP layer information, and transport layer information, and the inner flowspecvariable field is used to match the inner MAC header, IP header, and transport layer protocol header following the label stack.
[0121] Scenario 2: L3 VPN
[0122] In L3 VPN scenarios, the MPLS packet structure can be simplified as the outer MAC header + label stack + IP header + payload. The payload includes the transport layer protocol header and application layer information. Accordingly, the inner flowspec variable field contains IP layer information and is used to match the IP header following the label stack. Alternatively, the inner flowspec variable field contains both IP and transport layer information and is used to match the IP header and transport layer protocol header following the label stack.
[0123] This embodiment does not limit which fields in the MPLS message the outer layer flow rules, tunnel header flow rules, and inner layer flow rules are used to match, respectively. The specific fields to be matched in the MPLS message can be determined based on actual needs. In some embodiments, the outer layer flow rules, tunnel header flow rules, or inner layer flow rules are used to match all fields in the MPLS message of the MPLS message. In other embodiments, the outer layer flow rules, tunnel header flow rules, or inner layer flow rules are used to match some fields in the MPLS message of the MPLS message. There are multiple ways to determine which field in the MPLS message to match. In some embodiments, the specific matching field in the MPLS message is determined by manual configuration. In other embodiments, the specific matching field in the MPLS message is automatically determined by the network device. For example, the network device receives an attack message and determines the specific matching field based on the characteristics of the attack message.
[0124] The above describes the matching conditions in BGP flow rule routing using network layer reachability information. The following describes the processing actions in BGP flow rule routing. When the matching conditions described above are met, the following processing actions are performed.
[0125] 5. MPLS Action
[0126] This embodiment adds a new type of processing action for MPLS packets, referred to herein as an MPLS action. An MPLS action is a processing action performed on an MPLS label in an MPLS packet. For example, MPLS actions include, but are not limited to, popping an MPLS label from an MPLS packet, adding an MPLS label to an MPLS packet, and replacing an MPLS label in an MPLS packet.
[0127] In some embodiments, a BGP flow rule route includes MPLS action information, which is used to indicate an MPLS action. The MPLS action information is carried in an extended community attribute. For example, please refer to Table 3 below, which illustrates an example format of MPLS action information. The type value of the MPLS action information is "to be defined" (TBD). The extended community attribute corresponding to the MPLS action information is MPLS action. The MPLS action information is encoded as a bit mask.
[0128] Table 3
[0129] type Extended Community Attributes encoding TBD MPLS-action bitmask
[0130] In some embodiments, the MPLS action information includes a pop flag, an add flag, or a replace flag, and the pop flag, the add flag, and the replace flag respectively indicate a pop action, an add action, and a replace action on the MPLS label.
[0131] The pop flag is used to indicate that the MPLS label in an MPLS packet is popped. In one example, a BGP flow rule route includes a pop (PO) field, and the pop flag is the value of the PO field. For example, a PO field value of 1 indicates that the MPLS label is popped, while a PO field value of 0 indicates that the MPLS label is not popped. In this example, the pop flag is the 1 carried in the PO field.
[0132] The add flag is used to indicate the addition of an MPLS label to an MPLS packet. In one example, a BGP flow rule route includes a push (PU) field, where the add flag is the value of the PU field. For example, a PU field value of 1 indicates that an MPLS label is added, while a PU field value of 0 indicates that no MPLS label is added. In this example, the add flag is the 1 carried in the PU field.
[0133] The replacement flag is used to indicate the replacement of the MPLS label in an MPLS packet. In one example, a BGP flow rule route includes a switch (SW) field, and the replacement flag is the value of the SW field. For example, a value of 1 in the SW field indicates that the MPLS label is replaced, while a value of 0 in the SW field indicates that the MPLS label is not replaced. The replacement flag is the 1 carried in the SW field.
[0134] In some embodiments, the MPLS action information also specifies which MPLS label to add or which MPLS label to replace the original label. Specifically, the MPLS action information also includes a target MPLS label, the add identifier is specifically used to indicate the addition of the target MPLS label, and the replace identifier is specifically used to indicate the replacement of the MPLS label in the MPLS message with the target MPLS label, thereby controlling the forwarding of the message by adding or replacing the target MPLS label. In some embodiments, the MPLS action information includes an MPLS label field, a traffic class (TC) field, an S field, and a TTL field. The MPLS label field carries the label value of the target MPLS label, the TC field carries the TC of the target MPLS label, the S field carries the flag bit (S) of the target MPLS label, and the TTL field carries the TTL of the target MPLS label. The TC field in the MPLS label is also called the Exp field. The S field in the MPLS label is a 1-bit label stack bottom flag.
[0135] In some embodiments, when an MPLS packet contains multiple MPLS labels, the MPLS action information indicates the MPLS action to be performed on each MPLS label, specifically, the MPLS action information indicates the MPLS action to be performed on the outer MPLS label and the inner MPLS label.
[0136] For example, the pop-up flag described above includes at least one of a first pop-up flag and a second pop-up flag, wherein the first pop-up flag is used to instruct to pop out the outer MPLS label, and the second pop-up flag is used to instruct to pop out the inner MPLS label.
[0137] For example, the addition identifier described above is the first addition identifier; or, the addition identifier includes the first addition identifier and the second addition identifier. The first addition identifier is used to indicate the addition of an outer MPLS label, and the second addition identifier is used to indicate the addition of an inner MPLS label. Schematically, the addition identifier is carried by the PU field, the first addition identifier is carried by the PU1 field, and the second addition identifier is carried by the PU2 field. Then, the addition identifier is the first addition identifier, for example: PU1=1, PU2=0, which indicates the addition of one layer of MPLS label. The addition identifier includes the first addition identifier and the second addition identifier, for example: PU1=1, PU2=1, which indicates the addition of two layers of MPLS labels.
[0138] For example, the replacement identifier includes at least one of a first replacement identifier and a second replacement identifier, the first replacement identifier is used to indicate replacement of an outer MPLS label, and the second replacement identifier is used to indicate replacement of an inner MPLS label.
[0139] Please refer to Table 4, which is an example of the format of MPLS action information (MPLS-action). The following example illustrates the specific implementation of MPLS action information in conjunction with Table 4.
[0140] Table 4
[0141]
[0142] The MPLS action information shown in Table 4 includes 12 bytes. Specifically, the MPLS action information includes the PO1 field, the PU1 field, the SW1 field, the reserved (Resv) field, the PO2 field, the PU2 field, the SW2 field, the MPLS label 1 (MPLSlabel1) field, the TC1 field, the S1 field, the TTL1 field, the MPLS label 2 (MPLSlabel2) field, the TC2 field, the S2 field, the TTL2 field, and the like. In some embodiments, the first pop-up identifier described above is the value carried by the PO1 field. The first addition identifier described above is the value carried by the PU1 field. The first replacement identifier described above is the value carried by the SW1 field. The second pop-up identifier described above is the value carried by the PO2 field. The second addition identifier described above is the value carried by the PU2 field. The second replacement identifier described above is the value carried by the SW2 field. The formats of the fields in Table 4 are as follows.
[0143] When the value of the PO1 field is 1, the outermost label is popped up. When the value of the PO1 field is 0, the outermost label is not popped up.
[0144] When the PU1 field value is 1, an outermost label is added, specifying MPLSlabel1 as the outermost label. Specifically, the label value, EXP (TC), flags (S), and TTL in the added outermost label are MPLSlabel1, TC1, S1, and TTL1, respectively, as shown in Table 4. When the PU1 field value is 0, no outermost label is added. In this case, the MPLSlabel1, TC1, S1, and TTL1 fields in Table 4 are also initialized to 0.
[0145] When the SW1 field is 1, the outermost label is replaced, and the replaced outermost label is designated as MPLSlabel1. Specifically, the label value, EXP (TC), flags (S), and TTL in the replaced outermost label are MPLSlabel1, TC1, S1, and TTL1, respectively, as shown in Table 4. When the SW1 field is 0, the outermost label does not need to be replaced.
[0146] When the value of the PO2 field is 1, it indicates that the second outermost label is popped up. When the value of the PO2 field is 0, it indicates that the outermost label is not popped up.
[0147] When the PU2 field value is 1, a sub-outer label is added, specifying MPLSlabel2. Specifically, the label value, EXP (TC), flags (S), and TTL in the added sub-outer label are MPLSlabel2, TC2, S2, and TTL2, respectively, as shown in Table 4. When the PU2 field value is 0, no sub-outer label is added. In this case, the MPLSlabel2, TC2, S2, and TTL2 fields in Table 4 are also initialized to 0.
[0148] When the SW2 field value is 1, the second-outer label is replaced, and the replaced second-outer label is designated as MPLSlabel2. Specifically, the label value, EXP (TC), flags (S), and TTL in the replaced second-outer label are MPLSlabel2, EXP2, S2, and TTL2, respectively, as shown in Table 4. When the SW2 field value is 0, the second-outer label does not need to be replaced.
[0149] The above describes the various MPLS-actions extended by this embodiment. The different MPLS-actions described above can be combined with each other. For example, for the label popping action, both the outermost label and the second outermost label in the received MPLS message can be popped. For the label adding action, one or more labels are added based on the received MPLS message, for example, up to two layers of labels are added. For the label replacement action, both the outermost label and the second outermost label are supported to be replaced. The label popping action and the label replacement action can be performed simultaneously, that is, the outermost label can be popped and the second outermost label can be replaced at the same time.
[0150] The MPLS-action described above is an example of a newly added action. In other embodiments, the matching conditions in BGP flow rule routing are determined by the outer flow rules, tunnel header flow rules, and inner flow rules described above, and the processing actions in BGP flow rule routing are not MPLS-actions, but other processing actions that can be performed on MPLS packets. For example, the processing actions in BGP flow rule routing include, but are not limited to, limiting traffic rate, redirecting, marking differentiated services code points (DSCP), etc.
[0151] The above describes the message format of the BGP flow rule routing provided by this embodiment. The above scheme can be used as a new BGP flow implementation method for MPLS label messages. By extending the routing format of tunnel traffic defined by draft-ietf-idr-flowspec-nvo3, a new tunnel type is defined to support MPLS messages. The format and specific matching method of BGP flow specification routing are refined based on the format of MPLS messages. It can accurately match based on the outer layer 2 header (MAC, VLAN, etc. information), label stack, inner layer 2 header (MAC, VLAN, etc. information), L3 and L4 layer information, thereby solving the problem of accurate matching of MPLS messages.
[0152] The following is an introduction to the method flow provided in the embodiments of the present application.
[0153] Attachment Figure 3 It is a flowchart of the method for publishing BGP flow rule routing provided by an embodiment of the present application. The method includes the following steps S310 to S340. In order to distinguish and describe different network devices, the following method embodiments use "first network device" and "second network device" to refer to different network devices respectively. "First network device" and "second network device" can both be data communication devices such as routers and switches. In some embodiments, the method is applied in typical data communication scenarios to deal with distributed denial of service (DDoS) attacks with MPLS labels and ensure network security. In some embodiments, the deployment scenarios of the first network device and the second network device are as shown in the attached figure. Figure 1 For example, in combination with the Figure 1 From the perspective of FIG. 1 , the first network device is R3 in the network system 10 ; the second network device is R1 or R2 in the network system 10 .
[0154] Step S310: The first network device generates a BGP flow rule route.
[0155] There are multiple implementations for generating BGP flow rule routes. In some embodiments, BGP flow rule routes are generated through manual configuration. In other embodiments, a network device automatically generates BGP flow rule routes. For example, a network device detects an attack message and automatically generates a BGP flow rule route based on the characteristics of the attack message.
[0156] Step S320: The first network device publishes a BGP flow rule route.
[0157] Step S330: The second network device receives the BGP flow rule routing and determines a flow control policy according to the BGP flow rule routing.
[0158] The matching condition in the flow control policy includes at least one of an outer layer flow rule, a tunnel header flow rule, or an inner layer flow rule. The execution action in the flow control policy includes an MPLS action.
[0159] Step S340: The second network device controls the traffic matching the flow rule according to the traffic control policy.
[0160] In the MPLS scenario, the traffic is specifically an MPLS packet flow, which includes a series of MPLS packets. When the second network device receives the MPLS packet, it matches the MPLS packet with the matching conditions in the traffic control policy, and executes the execution action in the traffic control policy if the MPLS packet meets the matching conditions.
[0161] The matching conditions include, but are not limited to, at least one of the following: one or more fields in the MPLS packet match one or more fields in the outer flow rule; one or more fields in the MPLS packet match one or more fields in the tunnel header flow rule; or one or more fields in the MPLS packet match one or more fields in the inner flow rule. The executed action may be, for example, the MPLS action described above or another action.
[0162] For example, if the action to be executed is an MPLS action, the second network device can control the forwarding path of the MPLS message by executing the MPLS action on the MPLS message, allowing the MPLS message to be sent to the traffic detection and analysis device. For example, if the MPLS action is a label replacement action, the outermost label after replacement is set to the label assigned by the traffic detection and analysis device. By executing the outermost label replacement action, the second network device redirects the MPLS message to the traffic detection and analysis device, thereby preventing DDoS attacks launched through MPLS messages.
[0163] This embodiment provides a new BGP flow support method for MPLS messages. It supports MPLS messages by newly defining a tunnel type and refines the flow rules in BGP flow rule routing according to the format of MPLS messages. It matches the outer MAC header of the MPLS message based on the outer flow rule, matches the label stack of the MPLS message based on the tunnel header flow rule, and matches the inner MAC header, IP header, transport layer protocol header, etc. of the MPLS message based on the inner flow rule. Network devices can use BGP flow rule routing to match various parts of the MPLS message, thereby improving the accuracy of MPLS message matching.
[0164] The above describes the method embodiment of the embodiment of the present application, and the following describes the network device of the embodiment of the present application.
[0165] Attachment Figure 4 FIG1 shows a possible structural diagram of the network equipment involved in the above embodiment. Figure 4 The network device 400 shown implements, for example, Figure 3 The function of the first network device in the method shown, or the network device 400 implements Figure 1 Function of R3 in the scenario shown.
[0166] Please refer to the attached Figure 4 The network device 400 includes a generating unit 401 and a publishing unit 402. The generating unit 401 is used to support the network device 400 to perform step S310. The publishing unit 402 is used to support the network device 400 to perform step S320.
[0167] The division of units in the embodiment of the present application is schematic and is merely a logical function division. In actual implementation, other division methods may be optional.
[0168] In some embodiments, the various units in network device 400 are integrated into a single unit. For example, the various units in network device 400 are integrated into the same chip. The chip includes processing circuitry and input and output interfaces that are internally connected and communicate with the processing circuitry. Generation unit 401 is implemented by the processing circuitry in the chip. Publishing unit 402 is implemented by the output interface in the chip. For example, the chip is implemented by one or more field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), controllers, state machines, gate logic, discrete hardware components, any other suitable circuitry, or any combination of circuits capable of performing the various functions described throughout this application.
[0169] In other embodiments, each unit of network device 400 exists physically separately. In other embodiments, some units of network device 400 exist physically separately, while other units are integrated into a single unit. For example, in some embodiments, generation unit 401 and publishing unit 402 are the same unit. In other embodiments, generation unit 401 and publishing unit 402 are different units. In some embodiments, the integration of different units is implemented in hardware, i.e., the different units correspond to the same hardware. In another example, the integration of different units is implemented in software.
[0170] In the case of hardware implementation in the network device 400 , the generation unit 401 in the network device 400 is implemented, for example, by the central processing unit 611 on the main control board 610 in the network device 600 , or by the processor 701 in the network device 700 .
[0171] The publishing unit 402 in the network device 400 is implemented, for example, by the interface board 630 in the network device 600 , or by the communication interface 704 in the network device 700 .
[0172] When network device 400 is implemented via software, each unit in network device 400 may be, for example, software generated by the central processing unit 611 on the main control board 610 in network device 600 reading program code stored in memory 612, or software generated by the processor 701 in network device 700 reading program code stored in memory 703. For example, network device 400 is a virtualized device. Virtualized devices include, but are not limited to, at least one of a virtual machine, a container, and a Pod. In some embodiments, network device 400 is deployed on a hardware device (such as a physical server) in the form of a virtual machine. For example, network device 400 is implemented based on a general-purpose physical server in combination with network function virtualization (NFV) technology. When implemented using a virtual machine, network device 400 may be, for example, a virtual host, a virtual router, or a virtual switch. Those skilled in the art, by reading this application, can virtualize network device 400 on a general-purpose physical server in combination with NFV technology. In other embodiments, network device 400 is deployed on a hardware device in the form of a container (such as a Docker container). For example, the process of executing the above-described method embodiment by network device 400 is encapsulated in an image file, and a hardware device creates network device 400 by running the image file. In other embodiments, network device 400 is deployed on a hardware device in the form of a Pod. The Pod includes multiple containers, each of which is used to implement one or more units in network device 400.
[0173] The above describes how to implement the first network device from the perspective of logical functions through network device 400. The following describes how to implement the first network device from the perspective of hardware through network device 600 and network device 700. Figure 5 The network device 600 and the attached Figure 6 The network device 700 shown is an example of the hardware structure of the first network device.
[0174] Network device 600 or network device 700 corresponds to the first network device in the above-described method embodiment. The various hardware, modules, and other operations and / or functions in network device 600 or network device 700 are respectively for implementing the various steps and methods implemented by the first network device in the method embodiment. For detailed information on how network device 600 or network device 700 publishes BGP flow rule routes, please refer to the above-described method embodiment. For the sake of brevity, they are not described in detail here. Among them, each step of the method embodiment is performed by hardware integrated logic circuits or software instructions in the processor of network device 600 or network device 700. The steps of the method disclosed in the embodiments of the present application can be directly implemented as being executed by a hardware processor, or by a combination of hardware and software modules in the processor. The software module is located, for example, in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above-described method. To avoid repetition, they are not described in detail here.
[0175] See attached Figure 5 , attached Figure 5 FIG. 6 is a schematic diagram showing the structure of a network device provided by an exemplary embodiment of the present application. The network device 600 is configured as a first network device, for example. The network device 600 includes a main control board 610 and an interface board 630 .
[0176] The main control board 610, also known as the main processing unit (MPU) or route processor card, is used to control and manage various components in the network device 600, including routing calculation, device management, device maintenance, and protocol processing. The main control board 610 includes a central processing unit 611 and a memory 612.
[0177] Interface board 630 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are flexible Ethernet clients (FlexE clients). Interface board 630 includes a central processing unit (CPU) 631, a network processor (NPU) 632, a forwarding table memory 634, and a physical interface card (PIC) 633.
[0178] The central processing unit 631 on the interface board 630 is used to control and manage the interface board 630 and communicate with the central processing unit 611 on the main control board 610 .
[0179] The network processor 632 is used to implement message forwarding processing. The network processor 632 is, for example, a forwarding chip. Specifically, the network processor 632 is used to forward received messages based on the forwarding table stored in the forwarding table memory 634. If the destination address of the message is the address of the network device 600, the message is sent to the CPU (such as the central processing unit 611) for processing. If the destination address of the message is not the address of the network device 600, the next hop and outgoing interface corresponding to the destination address are searched in the forwarding table based on the destination address, and the message is forwarded to the outgoing interface corresponding to the destination address. The processing of uplink messages includes: processing of the message input interface and forwarding table search; processing of downlink messages includes forwarding table search, etc.
[0180] Physical interface card 633 implements physical layer connectivity. Raw traffic enters interface board 630 through this card, and processed messages are sent from this physical interface card 633. Physical interface card 633, also known as a daughter card, can be installed on interface board 630. It converts optical and electrical signals into messages, performs a validity check on these messages, and then forwards them to network processor 632 for processing. In some embodiments, a central processing unit (CPU) can also perform the functions of network processor 632, such as implementing software forwarding based on a general-purpose CPU. This eliminates the need for network processor 632 in physical interface card 633.
[0181] Optionally, the network device 600 includes multiple interface boards. For example, the network device 600 further includes an interface board 640 . The interface board 640 includes a central processing unit 641 , a network processor 642 , a forwarding table entry memory 644 , and a physical interface card 643 .
[0182] Optionally, the network device 600 further includes a switching fabric board 620. The switching fabric board 620 is also referred to as a switch fabric unit (SFU). If the network device has multiple interface boards 630, the switching fabric board 620 is used to exchange data between the interface boards. For example, the interface board 630 and the interface board 640 communicate via the switching fabric board 620.
[0183] The main control board 610 and the interface board 630 are coupled. For example, the main control board 610, the interface board 630, the interface board 640, and the switching network board 620 are connected to the system backplane via a system bus to achieve intercommunication. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 610 and the interface board 630, and communication between the main control board 610 and the interface board 630 is performed via the IPC channel.
[0184] Logically, network device 600 includes a control plane and a forwarding plane. The control plane includes a main control board 610 and a central processing unit 631. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 634, a physical interface card 633, and a network processor 632. The control plane performs functions such as routing, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining device status. The control plane sends the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor 632 forwards messages received by the physical interface card 633 based on the forwarding tables sent by the control plane. The forwarding tables sent by the control plane are stored, for example, in the forwarding table entry memory 634. In some embodiments, the control plane and forwarding plane are completely separate and not located on the same device.
[0185] It should be understood that the operations on the interface board 640 in the embodiment of the present application are consistent with the operations on the interface board 630. For the sake of brevity, detailed description is omitted. It should be understood that the network device 600 in this embodiment may correspond to the network device in each of the above-mentioned method embodiments. The main control board 610, interface board 630, and / or 640 in the network device 600, for example, implement the functions and / or various steps performed by the network device in each of the above-mentioned method embodiments. For the sake of brevity, detailed description is omitted here.
[0186] It's worth noting that there may be one or more main control boards, including, for example, a primary and backup main control board. There may be one or more interface boards. The higher the network device's data processing capabilities, the more interface boards it provides. Interface boards can also have one or more physical interface cards. There may be no switching fabric boards, one or more switching fabric boards, and multiple switching fabric boards can collectively implement load balancing and redundant backup. In a centralized forwarding architecture, network devices may not require switching fabric boards; the interface boards handle the entire system's service data processing. In a distributed forwarding architecture, network devices may have at least one switching fabric board, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, network devices with distributed architectures have greater data access and processing capabilities than those with centralized architectures. Alternatively, a network device can consist of a single card, without a switching fabric board (SFB), integrating the functions of the interface board and the main control board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU on this card, performing the combined functions of the two. This type of device has lower data exchange and processing capabilities (for example, low-end network devices such as switches or routers). The specific architecture used depends on the specific network deployment scenario and is not specified here.
[0187] See attached Figure 6 , attached Figure 6 FIG2 shows a schematic diagram of the structure of a network device 700 provided by an exemplary embodiment of the present application. The network device 700 can be configured as a first network device. The network device 700 can be a host, a server, or a personal computer. The network device 700 can be implemented by a general bus architecture.
[0188] The network device 700 includes at least one processor 701 , a communication bus 702 , a memory 703 , and at least one communication interface 704 .
[0189] The processor 701 is, for example, a general-purpose central processing unit (CPU), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 701 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0190] The communication bus 702 is used to transmit information between the above components. The communication bus 702 can be divided into an address bus, a data bus, a control bus, etc. Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0191] The memory 703 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 703 is, for example, independent and connected to the processor 701 via the communication bus 702. The memory 703 can also be integrated with the processor 701.
[0192] Communication interface 704 uses any transceiver or other device for communicating with other devices or communication networks. Communication interface 704 includes a wired communication interface and may also include a wireless communication interface. The wired communication interface may be, for example, an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof.
[0193] In a specific implementation, as an embodiment, the processor 701 may include one or more CPUs, such as the attached Figure 6 CPU0 and CPU1 are shown in the figure.
[0194] In a specific implementation, as an embodiment, the network device 700 may include multiple processors, such as the attached Figure 6 1 and 705. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0195] In a specific implementation, as an embodiment, the network device 700 may further include an output device and an input device. The output device communicates with the processor 701 and can display information in a variety of ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 701 and can receive user input in a variety of ways. For example, the input device can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0196] In some embodiments, the memory 703 is used to store program code 710 for executing the solution of the present application, and the processor 701 can execute the program code 710 stored in the memory 703. That is, the network device 700 can implement the method provided by the method embodiment through the processor 701 and the program code 710 in the memory 703.
[0197] The network device 700 in the embodiment of the present application may correspond to the first network device in each of the above-mentioned method embodiments, and the processor 701, communication interface 704, etc. in the network device 700 may implement the functions and / or various steps and methods implemented by the first network device in each of the above-mentioned method embodiments. For the sake of brevity, detailed description is omitted here.
[0198] Those skilled in the art will appreciate that the various method steps and units described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0199] Those skilled in the art will clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0200] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the unit is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0201] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0202] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0203] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0204] In this application, the terms "first" and "second" are used to distinguish between identical or similar items having substantially the same effects and functions. It should be understood that there is no logical or temporal dependency between "first" and "second", nor is the quantity and execution order limited. It should also be understood that although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of various examples, a first component can be referred to as a second component, and similarly, a second component can be referred to as a first component. Both the first component and the second component can be components, and in some cases, can be separate and different components.
[0205] The term "at least one" in this application means one or more, and the term "plurality" in this application means two or more.
[0206] It should also be understood that the term "if" may be interpreted to mean "when" or "upon" or "in response to determining" or "in response to detecting." Similarly, the phrase "if it is determined that..." or "if [stated condition or event] is detected" may be interpreted to mean "upon determining that..." or "in response to determining that..." or "upon detecting [stated condition or event]" or "in response to detecting [stated condition or event]," depending on the context.
[0207] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and such modifications or substitutions should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
[0208] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer program instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.
[0209] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a digital video disc (DVD), or a semiconductor medium (e.g., a solid-state drive), etc.
[0210] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0211] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for publishing Border Gateway Protocol (BGP) flow rule routing, characterized in that: The method comprises: The network device generates a BGP flow rule route, wherein the BGP flow rule route includes tunnel type information, an outer flow rule, a tunnel header flow rule, and an inner flow rule, wherein the tunnel type information is used to indicate that the type of the tunnel is Multi-Protocol Label Switching (MPLS), the outer flow rule is used to match an outer Media Access Control (MAC) header of an MPLS message, the tunnel header flow rule is used to match a label stack of an MPLS message, and the inner flow rule is used to match at least one of an inner MAC header, an Internet Protocol (IP) header, and a transport layer protocol header of an MPLS message; The network device publishes the BGP flow rule route.
2. The method according to claim 1, characterized in that The tunnel header flow rule includes a label value, and the label value in the tunnel header flow rule is used to match the label value of the MPLS label in the label stack.
3. The method according to claim 2, characterized in that The label value in the tunnel header flow rule includes at least one set of operators and values, and the at least one set of operators and values is used to indicate a value range of the label value of the successfully matched MPLS label.
4. The method according to claim 2 or 3, characterized in that The label value in the tunnel header flow rule includes at least one of a first label value or a second label value, the first label value is used to match the label value in the outer MPLS label in the label stack, and the second label value is used to match the label value in the inner MPLS label in the label stack.
5. The method according to claim 4, characterized in that The tunnel head flow rule includes at least one of the first component or the second component; The first component includes first type information and the first label value, where the first type information is used to identify that the first component carries the first label value; The second component includes second type information and the second label value, where the second type information is used to identify that the second component carries the second label value.
6. The method according to claim 1, characterized in that The tunnel header flow rule includes a traffic class TC, and the TC in the tunnel header flow rule is used to match the TC of the MPLS label in the MPLS message.
7. The method according to claim 6, characterized in that The TC in the tunnel header flow rule includes at least one set of operators and values, and the at least one set of operators and values is used to indicate a value range of the TC of the successfully matched MPLS label.
8. The method according to claim 6 or 7, characterized in that The TC in the tunnel header flow rule includes at least one of a first TC or a second TC, the first TC is used to match the TC in the outer MPLS label in the MPLS message, and the second TC is used to match the TC in the inner MPLS label in the MPLS message.
9. The method according to claim 8, characterized in that The tunnel head flow rule includes at least one of the third component or the fourth component; The third component includes third type information and the first TC, where the third type information is used to identify that the third component carries the first TC; The fourth component includes fourth type information and the second TC, where the fourth type information is used to identify that the fourth component carries the second TC.
10. The method according to claim 1, characterized in that The tunnel header flow rule includes a time to live (TTL), and the TTL in the tunnel header flow rule is used to match the TTL of the MPLS label in the MPLS message.
11. The method according to claim 10, characterized in that The TTL in the tunnel header flow rule includes at least one set of operators and values, and the at least one set of operators and values is used to indicate a value range of the TTL of the successfully matched MPLS label.
12. The method according to claim 10 or 11, characterized in that The TTL in the tunnel header flow rule includes at least one of a first TTL or a second TTL, the first TTL is used to match the TTL in the outer MPLS label in the MPLS message, and the second TTL is used to match the TTL in the inner MPLS label in the MPLS message.
13. The method according to claim 12, characterized in that The tunnel head flow rule includes at least one of the fifth component or the sixth component; The fifth component includes fifth type information and the first TTL, where the fifth type information is used to identify that the fifth component carries the first TTL; The sixth component includes sixth type information and the second TTL, and the sixth type information is used to identify that the sixth component carries the second TTL.
14. The method according to any one of claims 1 to 13, characterized in that The BGP flow rule route is carried in the multi-protocol reachable network layer reachability information NLRI, and the multi-protocol reachable NLRI includes the BGP flow rule route and the first address family identifier AFI, and the first AFI is used to indicate that the outer layer flow rule is the flow rule corresponding to the MAC header.
15. The method according to any one of claims 1 to 14, characterized in that The inner layer flow rule includes a second AFI, and the second AFI is used to indicate whether to match the inner layer MAC header of the MPLS message.
16. The method according to claim 15, characterized in that The inner layer flow rule includes an inner layer AFI field, and the second AFI is the AFI carried by the inner layer AFI field.
17. The method according to claim 15, characterized in that The inner layer flow rule includes a third AFI, and the third AFI is used to indicate whether to match the IP header or the transport layer protocol header of the MPLS message.
18. The method according to claim 17, characterized in that The inner layer flow rule includes an L3-AFI field, and the third AFI is the AFI carried by the L3-AFI field.
19. The method according to claim 17 or 18, characterized in that The third AFI is used to indicate matching with the Internet Protocol Version 4 IPv4 header of the MPLS message; or, The third AFI is used to indicate matching with the Internet Protocol Version 6 IPv6 header of the MPLS message; or, The third AFI is used to indicate that the IP header and the transport layer protocol header of the MPLS message are not matched.
20. The method according to any one of claims 1 to 19, characterized in that The BGP flow rule routing further includes MPLS action information, where the MPLS action information is used to indicate a processing action to be performed on an MPLS label in an MPLS message.
21. The method according to claim 20, characterized in that The MPLS action information includes a pop-up flag, an add flag, or a replace flag. The pop-up flag is used to indicate popping an MPLS label in an MPLS message, the add flag is used to indicate adding an MPLS label to an MPLS message, and the replace flag is used to indicate replacing an MPLS label in an MPLS message.
22. The method according to claim 21, characterized in that The MPLS action information further includes a target MPLS label. The adding flag is used to instruct the addition of the target MPLS label. The replacing flag is used to instruct the replacement of the MPLS label in the MPLS message with the target MPLS label.
23. The method according to claim 21 or 22, characterized in that The pop-up flag includes at least one of a first pop-up flag and a second pop-up flag, wherein the first pop-up flag is used to instruct to pop out an outer MPLS label, and the second pop-up flag is used to instruct to pop out an inner MPLS label; The adding identifier includes a first adding identifier and a second adding identifier, wherein the first adding identifier is used to indicate adding an outer MPLS label, and the second adding identifier is used to indicate adding an inner MPLS label; The replacement identifier includes at least one of a first replacement identifier and a second replacement identifier, the first replacement identifier is used to indicate replacement of an outer MPLS label, and the second replacement identifier is used to indicate replacement of an inner MPLS label.
24. A network device, characterized in that: The network equipment includes: a generating unit, configured to generate a BGP flow rule route, wherein the BGP flow rule route includes tunnel type information, an outer flow rule, a tunnel header flow rule, and an inner flow rule, wherein the tunnel type information is used to indicate that the type of the tunnel is Multi-Protocol Label Switching (MPLS), the outer flow rule is used to match an outer Media Access Control (MAC) header of an MPLS message, the tunnel header flow rule is used to match a label stack of an MPLS message, and the inner flow rule is used to match at least one of an inner MAC header, an IP header, and a transport layer protocol header of an MPLS message; The publishing unit is used to publish the BGP flow rule route.
25. A network device, characterized in that: The network device includes a processor and a communication interface, the processor is used to execute instructions so that the network device performs the method according to any one of claims 1 to claim 23, and the communication interface is used to publish Border Gateway Protocol BGP flow rule routing.
26. A computer-readable storage medium, characterized in that The storage medium stores at least one instruction, and the instruction is read by the processor to enable the network device to execute the method according to any one of claims 1 to 23.
Citation Information
Patent Citations
Flow specification protocol based communication method, device and system
CN107222449A
Method of realizing special multiple-protocol label exchanging virtual network
CN1507230A