Data forwarding method, device, router and storage medium
By encapsulating the target forwarding link information of the application-level server identification information to the SR BE tunnel in the network edge router and appending it to the service access message, the problem that the service access message under the SR BE tunnel cannot be forwarded to the application-level server is solved, and the effective forwarding and processing of messages is realized.
Patent Information
- Application Number
- CN202211531318.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-01
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-12-01
AI Technical Summary
When an application-level server is deployed in the network, when forwarding service access messages based on SR BE tunnels, it is not possible to ensure that service access messages can be forwarded to the application-level server.
By receiving the service access message sent by the client network router in the network edge router, the target forwarding link information carried on the SR BE tunnel is determined. The link information includes the identification information of the application-level server, which is encapsulated in the service access message, and forwarded according to the target forwarding link information to ensure that the message is processed by the application-level server.
Ensure that service access packets sent based on SR BE tunnels can be processed and forwarded to the destination device by application-level servers, solving the problem of not being able to ensure that messages are forwarded to application-level servers.
Smart Images

Figure CN115766560B_ABST
Abstract
Description
Technical Field
[0001] This application relates to data processing technologies, and in particular, to a data forwarding method, apparatus, router, and storage medium. Background Art
[0002] Currently, the development of network technologies is accelerating day by day. Users can perform data interaction with other users through the network. To ensure the security of data transmission between different users, it is usually necessary to set up an application-level server in the network to ensure data transmission security.
[0003] In the related art, by deploying a policy-based IPv6 segment routing (abbreviated as: SRv6 Policy) tunnel and a best-effort service-based IPv6 segment routing (abbreviated as: SRv6 BE) tunnel between the client device and the destination device, data interaction between the client device and the destination device is realized. When the client device accesses the destination device, it preferably uses the SRv6 Policy tunnel to carry service access packets. When the SRv6 Policy tunnel fails, the SRv6 BE tunnel is used to carry data instead.
[0004] However, in the related art, in an application scenario where an application-level server is deployed in the network and the service access packets sent by the client device must be processed by the application-level server and then forwarded to the destination device, if the SRv6 Policy tunnel deployed between the client device and the destination device fails and it is necessary to use the SRv6 BE tunnel to carry data instead, it cannot be ensured that the service access packets sent by the client can pass through the application-level server. That is, in the related art, when an application-level server is deployed in the network and the service access packets are forwarded based on the SR BE tunnel, there is a technical problem that it cannot be ensured that the service access packets can be forwarded to the application-level server. Summary of the Invention
[0005] Embodiments of this application provide a data forwarding method, apparatus, router, and storage medium, which are used to solve the technical problem in the prior art that when an application-level server is deployed in the network and the service access packets are forwarded based on the SR BE tunnel, it cannot be ensured that the service access packets can be forwarded to the application-level server.
[0006] In a first aspect, an embodiment of the present application provides a data forwarding method. The method is applied to a network edge router and includes: receiving a service access packet sent by a client network router, where the service access packet includes source device identification information and destination device identification information; determining target forwarding link information carried on a segment routing best effort (SR BE) tunnel based on the source device identification information and the destination device identification information; the target forwarding link information includes application-level server identification information; encapsulating the target forwarding link information in the service access packet to form an encapsulated service access packet; and forwarding the encapsulated service access packet according to the target forwarding link information, so that when the application-level server receives the encapsulated service access packet, the application-level server performs corresponding application-level processing on the encapsulated service access packet and then forwards it to the destination device.
[0007] In a second aspect, an embodiment of the present application provides a data forwarding device. The device is located in a network backbone access router and includes: a receiving module, configured to receive a service access packet sent by a client network router, where the service access packet includes source device identification information and destination device identification information; a determining module, configured to determine target forwarding link information carried on an SR BE tunnel based on the source device identification information and the destination device identification information; the target forwarding link information includes application-level server identification information; an encapsulating module, configured to encapsulate the target forwarding link information in the service access packet to form an encapsulated service access packet; and a forwarding module, configured to forward the encapsulated service access packet according to the target forwarding link information, so that after the application-level server receives the encapsulated service access packet, the application-level server performs corresponding application-level processing on the encapsulated service access packet and then forwards it to the destination device.
[0008] In a third aspect, an embodiment of the present application provides a network edge router, including: a processor, as well as a memory and a transceiver communicatively connected to the processor; the memory stores computer-executable instructions; the transceiver is configured to transmit and receive data; and the processor executes the computer-executable instructions stored in the memory to implement the method described in the first aspect.
[0009] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. The computer program is executed by a processor to implement the method described in the first aspect.
[0010] An embodiment of the present invention provides a data forwarding method, apparatus, router, and storage medium. By receiving a service access packet sent by a client network router, the service access packet includes source device identification information and destination device identification information, and determining target forwarding link information carried on an SR BE tunnel based on the source device identification information and the destination device identification information; the target forwarding link information includes application-level server identification information; encapsulating the target forwarding link information in the service access packet to form an encapsulated service access packet; forwarding the encapsulated service access packet according to the target forwarding link information, so that when the application-level server receives the encapsulated service access packet, performing corresponding application-level processing on the encapsulated service access packet and then forwarding it to the destination device. Based on the target forwarding link information including application-level server identification information carried on the SR BE tunnel, obtaining the encapsulated service access packet and forwarding the encapsulated service access packet according to the target forwarding link information. Thus, it can be ensured that the encapsulated service access packet is forwarded to the destination device after being processed by the application-level server. That is, through the data forwarding method, apparatus, router, and storage medium of this solution, it can be ensured that when sending a service access packet based on an SR BE tunnel, the service access packet passes through the application-level server. Thus, the technical problem that in the related art, when deploying an application-level server in the network, it is impossible to ensure that the service access packet can be forwarded to the application-level server when transmitting the service access packet based on the SR BE tunnel is solved.
[0011] It should be understood that the content described in the above invention content part is not intended to limit the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0013] Figure 1 It is a schematic diagram of an application scenario for data forwarding in the prior art;
[0014] Figure 2 It is a schematic diagram of an application scenario for data forwarding based on an SRv6 BE tunnel in the prior art;
[0015] Figure 3 It is a schematic diagram of an application scenario for data forwarding based on an SRv6 Policy tunnel in the prior art;
[0016] Figure 4 This is a schematic diagram of an application scenario of the data forwarding method provided by an embodiment of the present invention.
[0017] Figure 5 This is a flowchart of the data forwarding method provided by an embodiment of the present invention;
[0018] Figure 6 This is a schematic structural diagram of the data forwarding device provided by an embodiment of the present invention;
[0019] Figure 7 This is a schematic structural diagram of the network edge router provided by an embodiment of the present invention;
[0020] Through the above-mentioned drawings, the specific embodiments of the present application have been shown, and more detailed descriptions will be given later. These drawings and text descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed implementation manners
[0021] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are only examples of the devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0022] First, the nouns involved in the present application are explained:
[0023] Segment Routing (abbreviated as SR in English), is a source routing protocol, also known as the segment routing protocol, which is used to divide a network path into multiple segments and assign segment routing identifiers (abbreviated as SID in English) for identifying segments to these segments and forwarding nodes in the network. The forwarding path is obtained by arranging the segments and forwarding nodes in an orderly manner. Specifically, the network edge router that receives the client router to forward the packet specifies the forwarding path, and converts the specified path into an ordered list of segments and encapsulates it into the packet header of the network edge router to indicate that the packet is forwarded according to the specified path.
[0024] Segment Routing ID (abbreviated as SID in English: Segment Routing ID), the format depends on the specific technical implementation. For example, Multi-Protocol Label Switching (abbreviated as MPLS in English) labels, IPv6 addresses, etc. can be used.
[0025] Segment Routing Internet Protocol Version 6 (abbreviated as SRv6 in English), specifies the forwarding path based on the IPv6 packet header, and uses the IPV6 address as the Segment Routing ID.
[0026] Segment Routing Multi-Protocol Label Switching (abbreviated as SR MPLS in English), the data forwarding plane is based on the Segment Routing of MPLS, and uses the MPLS label as the Segment Routing ID.
[0027] Locator, used to identify SRv6 nodes. Each node in the network has a unique Locator value, which is used as the prefix of the local SID.
[0028] Figure 1 For the schematic diagram of the application scenario of data forwarding in the prior art, refer to Figure 1 As shown, the network includes a client device 111, a router 112, a data terminal device 113, an Internet exit 115, and an application-level server 114. Among them, the client device 111 is connected to the data terminal device 113 through the router 112. Among them, the router 112 may include at least one of the following: Provider Edge (abbreviated as PE in English), Customer Edge (abbreviated as CE in English), and Provider (abbreviated as P in English).
[0029] In the related art, an SRv6 Policy tunnel and an SRv6 BE tunnel are deployed between a client device 111 and a data terminal device 113, and an SRv6 BE tunnel is deployed between the client device 111 and the client device 111. When the client device 111 accesses the data terminal device 113, service access packets are preferentially carried by the SRv6 Policy tunnel. When the SRv6 Policy tunnel fails, the SRv6 BE tunnel is used instead to ensure the service connectivity of the client device accessing the data terminal device. When the client device 111 accesses other client devices 111, service access packets are usually carried by the SRv6 BE tunnel. Because the uncertainty of mutual access between client devices 111 is strong and the flexibility requirement is high, certain security policies also need to be deployed. If an SRv6 Policy tunnel is deployed between each client, it will consume a large amount of forwarding resources of the router, increasing the network service configuration amount and maintenance complexity.
[0030] Figure 2 It is a schematic diagram of an application scenario for data forwarding based on an SRv6 BE tunnel in the prior art. Refer to Figure 2 As shown, the scenario includes: a client network router CE1 on the client device side, an operator network edge router PE1 communicatively connected to CE1, an operator network backbone access router P communicatively connected to PE1, and a client network router CE2 on the destination device side, an operator network edge router PE2 communicatively connected to CE2, and PE2 is communicatively connected to the operator network backbone access router P.
[0031] Refer to Figure 2 , the routing advertisement method based on the SRv6 BE tunnel includes the following solution: The controller in the network system configures a locator (English: Locator) on PE2, and this locator is the device identifier of PE2. PE2 uses the Interior Gateway Protocol (English: Interior Gateway Protocol, abbreviated as: IGP) protocol to advertise the Locator A2:1:: / 64 configured for PE2 to PE1, and PE1 installs the received Locator A2:1:: / 64 into its IPv6 routing table. PE2 configures the End.DT4SID A2:1::B100 of the Virtual Private Network (English: Virtual Private Network, abbreviated as: VPN) instance (such as CE2) to generate a local SID (English: Local SID) table. Among them, the End.DT4 SID is used to identify a certain VPN instance in the network. In Figure 2In the application scenario shown, End.DT4 SID A2:1::B100 is the device identifier of CE2. After PE2 receives the private network IPv4 route published by CE2, PE2 converts the private network IPv4 route into an External Gateway Protocol (English: Border Gateway Protocol, abbreviated as: BGP) VPNv4 route, and publishes it to PE1 through the BGP neighbor relationship. Specifically, after PE2 converts the private network IPv4 route published by CE2 into a BGP VPNv4 route, it is forwarded to PE1 sequentially through adjacent routing devices. Among them, PE2 and PE1 perform data transmission based on the backward-compatible Border Gateway Protocol (English: Multiprotocol Border Gateway Protocol, abbreviated as: MP-BGP). This BGP VPNv4 route carries the SRv6 VPN SID attribute. Specifically, this BGP VPNv4 route includes the Locator End.DT4 SID A2:1::B100 of the VPN instance CE2. After PE1 receives the BGP VPNv4 route containing the Locator of CE2, it writes it into the corresponding VPN instance routing table in PE1, then converts it into a normal IPv4 route, and publishes it to CE1. Thus, CE1 can obtain the device identifier information of PE2.
[0032] Refer to Figure 2, the data forwarding method based on the SRv6 BE tunnel includes the following solution: CE1 sends a private network IPv4 packet to PE1. After receiving the private network IPv4 packet sent by CE1 from the interface bound to the VPN instance, PE1 obtains the route prefix of the destination device in the private network IPv4 packet by looking up the route table of the corresponding VPN instance, and finds the associated SRv6 VPN SID and the device identification information of the next-hop node according to the route table. Then, it encapsulates the packet into an IPv6 packet using the Locator SRv6 VPNSID A2:1::B100 of PE2 as the destination address, and obtains the encapsulated service access packet. PE1 matches the route A2:1:: / 64 according to the longest matching principle and forwards it to the P device along the shortest path. The P device matches the route A2:1:: / 64 according to the longest matching principle and forwards it to PE2 along the shortest path. PE2 uses the Locator End.DT4 SID A2:1::B100 of PE2 to look up the Local SID table set in the route advertisement phase, and matches the forwarding action corresponding to the Locator End.DT4 SID A2:1::B100, removes the IPv6 packet header of the encapsulated service access packet, and then matches the VPN instance according to the LocatorEnd.DT4 SID A2:1::B100, looks up the VPN instance route table for forwarding. At this time, the forwarded packet has been restored to an ordinary IPv4 packet.
[0033] The SRv6 Policy tunnel is described below. It should be understood that SRv6 Policy is a new tunnel technology. The SRv6 Policy path represents a segment list (Segment List) of a specified path, and this segment list is called a SID list (Segment ID List). Each SID list includes an end-to-end path from the source to the destination. In the application scenario where the client device accesses the destination device, each SID list includes an end-to-end path from the client device to the destination device. The SID list can be used to instruct the devices in the network to forward the service access packet following the forwarding link specified by the user, rather than forwarding the service access packet following the shortest path calculated by the IGP. If the service access packet is imported into the SRv6 Policy tunnel, the PE1 device encapsulates the SID list into the packet header, and the remaining devices in the network execute the forwarding link information instructions embedded in the SID list.
[0034] Among them, the SRv6 Policy tunnel includes the following three attribute parts: the head-end attribute representing the forwarding node in the SRv6 Policy tunnel; the extended community attribute Color carried by the SRv6 Policy tunnel, where BGP routes carrying the same Color attribute can use this SRv6 Policy tunnel; the end-end attribute (English: End Point) representing the destination address of the SRv6 Policy, where the destination address is the destination device identification information of the destination device.
[0035] Among them, both the Color and End Point information are attributes of the SRv6 Policy tunnel. The SRv6 Policy calculates the forwarding link according to the Color attribute representing the Service Level Agreement (English: Service Level Agreement, abbreviated as: SLA). PE1 matches the corresponding SRv6 Policy through the Color attribute carried by the route and the destination device identification information of the destination device, thereby realizing the forwarding of service access packets.
[0036] It should be noted that Figure 2 the specific routing information involved is only an example and not the real routing information of an actual router.
[0037] Figure 3 It is a schematic diagram of the application scenario for data forwarding based on the SRv6 Policy tunnel in the prior art. Refer to Figure 3, nodes A, B, C, D, E, F, G, and H in the figure are all routing devices, and I is the controller. Among them, the SRv6 Policy can forward traffic based on the extended community attributes (such as Color) carried by the route. Color attribute-based traffic forwarding means directly iterating to the SRv6 Policy based on the extended community attribute Color of the route and the destination address. Specifically, the controller issues the SRv6 Policy to the client device A. The Color of the SRv6 Policy is 123, and the address of the tail-end device B is 2001:DB8:1::1. Configure the BGP export policy or VPN export policy on the destination device B (or configure the BGP import policy or VPN import policy on the device A), set the extended community attribute Color 123 for the route prefix 2001:DB8:90:: / 80, and the next hop of the route is the address 2001:DB8:1::1 of the device B. The route of the destination device B is sent to the client device A through the BGP neighbor. Configure the tunnel policy on the client device A. When the client device A receives the BGP route 2001:DB8:90:: / 80 (prefix), it iterates to the SRv6 Policy according to the extended community attribute 123 of the route and the next hop 2001:DB8:1::1. Refer to Figure 3 As shown, when the service data packet sent by the client device A is forwarded to the destination device B, the client device A needs to add a specific SID stack to the packet sent to 2001:DB8:90:: / 80. This SID stack is <C, E, G, B>, that is, the service access packet is sent to the destination device B through nodes C, E, and G in sequence.
[0038] Continue to refer to Figure 1 , the data forwarding method in the related technology is described. In the related technology, in the application scenario where the application-level server 114 is deployed in the network, when the service access packet is carried through the SRv6 Policy tunnel, the network operator or network maintenance personnel can arrange the SID corresponding to the application-level server into the SIDList of the SRv6 Policy tunnel to ensure that the service access packet can be sent to the application-level server 114. However, when the SRv6 Policy tunnel fails and the SRv6 BE tunnel is used to carry the service access packet, since the SRv6 BE tunnel forwards the service access packet based on the shortest path, and the application-level server 114 may be deployed at the core node or aggregation node, it cannot be guaranteed that the forwarding link based on the SRv6 BE tunnel can include the node of the application-level server 114. For example, Figure 1 as shown in tunnel 109b in Figure 1As shown by the tunnel 109a in [description], the forwarding path corresponding to the SRv6 BE tunnel deployed between the client device 111 and other client devices 111 does not pass through the application-level server 114. Therefore, the data exchanged between the client 111 and the client device 111 also cannot pass through the application-level server 114. That is, in the prior art, when an application-level server is deployed in the network and the service access packets are forwarded based on the SR BE tunnel, there is a technical problem that it cannot be ensured that the service access packets can be forwarded to the application-level server.
[0039] To solve the problem in the related art that when an application-level server is deployed in the network and the service access packets are forwarded based on the SR BE tunnel, it cannot be ensured that the service access packets can be forwarded to the application-level server. It is necessary to forward the packets based on the target forwarding link carrying the application-level server identification information on the Segment Routing Best Effort (SRBE) tunnel. Further, after receiving the service access packet sent by the client network router, the network edge router can determine the source device identification information and the destination device identification information according to the service access packet sent by the client network router, determine the target forwarding link information carried on the SR BE tunnel according to the source device identification information and the destination device identification information, encapsulate the target forwarding link information in the service access packet, and forward the service access packet based on the encapsulated target forwarding link information to ensure that the encapsulated service access packet can be forwarded to the application-level server and then forwarded to the destination device after being processed by the application-level server. Thus, the problem in the related art that when an application-level server is deployed in the network and the service access packets are forwarded based on the SR BE tunnel, it cannot be ensured that the service access packets can be forwarded to the application-level server is solved.
[0040] Then when the client device 111 accesses the data terminal device 113, if it is detected that the SRv6 Policy tunnel fails and after switching to the SRv6 BE tunnel for carrying, after receiving the service access packet sent by the client network router, the target forwarding link information including the application-level server identification information is encapsulated in the service access packet. When the client devices access each other, instead of using the forwarding link information without the application-level server identification information carried by the existing SRv6 BE tunnel, the target forwarding link information including the application-level server identification information is encapsulated in the service access packet, which can ensure that the encapsulated service access packet can be forwarded to the application-level server 114 and then forwarded to the destination device after being processed by the application-level server 114.
[0041] The following introduces the application scenarios of a data forwarding method, device, router, and storage medium provided by this application.
[0042] Figure 4 This is a schematic diagram of the application scenario of the data forwarding method, device, router, and storage medium provided by the embodiments of the present invention. As Figure 4 shown, the network includes client devices 401, destination devices 402, network edge routers 403a and 403b, network backbone routers 404a and 404b, routers 405a and 405b, network edge routers 406a and 406b, and a network service-oriented resource pool 407 including application-level servers 407a and 407b.
[0043] Among them, the network edge routers 403a and 403b belong to the Service Classifier (SC) nodes, the network backbone routers 404a and 404b belong to the Provider (P) nodes, the routers 405a and 405b belong to the Service Function Forwarder (SFF) nodes, the network edge routers 406a and 406b belong to the destination (END) nodes, and the application-level servers 407a and 407b are Service Function (SF) nodes. It should be noted that the SF nodes are usually nodes that provide value-added service (VAS) functions for the network, and the nodes are application-level servers. Specifically, the SF nodes can include value-added service devices such as firewalls, load balancers, and application parsing servers. The SC nodes are usually used to implement service flow identification, set service identifiers, encapsulate service message headers, etc., and determine which forwarding link to divert the service access message to. The SFF nodes are usually devices such as switches, routers, and gateways connecting to the SF nodes, and are used to forward the service access message according to the forwarding link.
[0044] Among them, an SRv6 Policy tunnel (not shown in the figure) and an SRv6 BE tunnel 408 are deployed between the client device 401 and the destination device 402. Taking the routing device that receives the service access packet sent by the client network router (not shown in the figure) as the network edge router 403a, and the service access packet sent by the client device 401 needs to pass through the application-level server 407b as an example for explanation: If the SRv6 Policy tunnel does not fail, the service access packet is preferably carried through the SRv6 Policy tunnel, and the service access packet sent by the client device 401 is forwarded to the destination device 402 through the forwarding link of the SRv6 Policy tunnel. Network operation and maintenance personnel can arrange the SID corresponding to the application-level server 407b into the SID List of the SRv6 Policy tunnel to ensure that the service access packet can be forwarded to the application-level server 407b. When the SRv6 Policy tunnel fails, the network edge router 403a diverts the service access packet to the SRv6 BE tunnel for forwarding. Specifically, the network edge router 403a determines the target forwarding link information carried on the segment routing SR BE tunnel 408 based on the best-effort service according to the source device identification information of the client upper device 401 and the destination device identification information of the destination device 402, where the target forwarding link information includes the application server identification information of the application-level server 407b. The network edge router 403a encapsulates the target forwarding link information in the service access packet to form an encapsulated service access packet, and then forwards the encapsulated service access packet according to the target forwarding link information, so that the service access packet passes through the application-level server 407b and then is forwarded to the destination device 402. Thus, it is ensured that the service access data can be forwarded to the application-level server when transmitting the service access packet based on the SR BE tunnel 408, and the technical problem that in the related art, when an application-level server is deployed in the network, it is impossible to ensure that the service access packet can be forwarded to the application-level server when transmitting the service access packet based on the SR BE tunnel is solved.
[0045] It should be noted that the present application can implement data forwarding in multiple application scenarios. For example, it can be applied to the application scenario where the client device of an enterprise customer accesses a destination terminal device such as a data center, and can also be applied to other scenarios where the client device needs to access the destination terminal device. Exemplarily, for example, the enterprise customer can be a commission office, and the data center can be a government affairs system. It can be applied to the scenario where the service access packet passes through one application-level server during forwarding, and can also be applied to the scenario where the service access packet passes through multiple application-level servers during forwarding. For example, Figure 4As shown in the figure, the network operation and maintenance personnel can arrange the application-level server SID corresponding to the application-level server 407b into the SIDList of the SRv6 Policy tunnel to ensure that the service access packets can be forwarded to the application-level server 407b. The network operation and maintenance personnel can also arrange the SIDs corresponding to the application-level servers 407a and 407b into the SID List of the SRv6 Policy tunnel to ensure that the service access packets can be forwarded to the application-level servers 407a and 407b.
[0046] The following uses specific embodiments to describe in detail the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0047] Figure 5 It is a flowchart of a data forwarding method provided by an embodiment of the present invention. The execution subject of the method of the present application is a data forwarding device, and the data forwarding device is located in the network edge router PE, as Figure 5 shown, the method of this embodiment includes the following steps.
[0048] S101, receive the service access packet sent by the client network router, and the service access packet includes source device identification information and destination device identification information.
[0049] Among them, the source device can be a client device or a global server. By way of example, the source device can be a single client device or a device cluster composed of multiple client devices.
[0050] Among them, the client network router is a routing device connecting the source device and the network edge router.
[0051] Among them, the service access packet is a packet for accessing the destination device for services. The specific service type is not limited, such as it can be a data acquisition service, a data query service, etc.
[0052] If the service access packet complies with the IPv6 protocol, the source device identification information can be the first Internet protocol IP address information of the source device. If the service access packet complies with MPLS, the source device identification information can be an MPLS label. It can be understood that the identification information of the source device can also be other information that uniquely identifies the source device.
[0053] Similarly, the destination device identification information can be the IP address information or MPLS label of the destination device, or other information that uniquely identifies the destination device.
[0054] Among them, the destination device is the device that the client device needs to access. It can be another client device or the device corresponding to a certain data center. The device corresponding to the data center can be deployed in the cloud.
[0055] In one embodiment, receiving the service access packet sent by the client network router may include the following solution: The client device sends service data to the client network router CE, and the client network router CE encapsulates the service data into a service access packet containing the client device identification information and the destination device identification information, and sends the service access packet to the network edge router PE, so that the network edge router receives the service access packet.
[0056] It can be understood that the network edge router receives the service access packet through the SR technology and also sends the service access packet to the next forwarding node through the SR technology. In one embodiment, receiving the service access packet sent by the client network router may include the following solution: The client device sends a service access packet to the client network router CE, and the client network router CE encapsulates the service access packet into a service access packet containing the client device identification information and the destination device identification information, and sends the service access packet to the network edge router PE.
[0057] S102. Determine the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information; the target forwarding link information includes the application-level server identification information.
[0058] Among them, the target forwarding link information at least includes: the identification information of multiple devices that the service forwarding packet needs to pass through during the forwarding process, or the identification information of multiple application programs that the service forwarding packet needs to pass through during the forwarding process. Among them, the multiple devices and the multiple application programs at least include the application-level server. For example, the multiple devices can be firewalls, and the multiple application programs can be load balancers.
[0059] Among them, the destination device identification information includes the second IP information of the destination device, and the application server identification information can be the IP address information of the application-level server or other information that uniquely identifies the application server.
[0060] Among them, the application-level server is a device that provides value-added service functions for the network. In one embodiment, the application-level server includes any one or more of a firewall, a load balancer, an application parsing server, etc.
[0061] Among them, the SR BE tunnel can be an SRv6 BE tunnel or a Segment Routing over Multi-Protocol Label Switching Best Effort (abbreviated as: SR MPLS BE) tunnel. This embodiment does not limit this.
[0062] In one embodiment, determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information may include the following solutions: Obtain at least one candidate forwarding link information pre-stored in the network edge router PE, including the identification information of the application-level server, as well as the source device identification information and the destination device identification information, and determine the target forwarding link information from the at least one candidate forwarding link information.
[0063] In another embodiment, determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information may further include the following solutions: Obtain the original forwarding path that has been determined based on the source device identification information and the destination device identification information and is carried on the SR BE tunnel but does not include the identification information of the application-level server. Obtain the network structure of this application, and based on the network structure, obtain the two nodes closest to the application-level server from the original forwarding path, and respectively determine the first forwarding path between the front node and the application-level server, and the second forwarding path between the back node and the application-level server. Concatenate the original forwarding path with the first forwarding path and the second forwarding path to obtain the target forwarding path including the identification information of the application-level server.
[0064] In yet another embodiment, determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information may further include the following solutions: Obtain the network demand information of the client device, and based on the network demand information, with the condition that the determined optimal forwarding path includes the identification information of the application-level server, determine the optimal forwarding path carried on the SR BE tunnel, and determine the optimal forwarding path as the target forwarding path.
[0065] It can be understood that determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information can also be other methods, and this embodiment does not limit this.
[0066] S103, encapsulate the target forwarding link information in the service access message to form the encapsulated service access message.
[0067] In one embodiment, if the SR BE tunnel is an SRv6 BE tunnel, the network edge router PE generates target forwarding link information based on the IPv6 protocol and encapsulates the target forwarding link information in the service access message. In another embodiment, if the SR BE tunnel is an SR MPLS BE tunnel, the network edge router PE generates target forwarding link information based on the MPLS protocol and encapsulates the target forwarding link information in the service access message.
[0068] S104, forward the encapsulated service access message according to the target forwarding link information, so that when the application-level server receives the encapsulated service access message, perform corresponding application-level processing on the encapsulated service access message and then forward it to the destination device.
[0069] In one embodiment, forwarding the encapsulated service access message according to the target forwarding link information may include the following solution: The network edge router PE determines the next forwarding node for forwarding the encapsulated service access message according to the target forwarding link information, and forwards the encapsulated service access message to the next forwarding node, so that the next forwarding node determines which forwarding node to forward the encapsulated service access message to according to the target forwarding link information in the encapsulated service access message. And so on until it is forwarded to the application-level server. After the application-level server receives the encapsulated service access message, perform corresponding application-level processing on the encapsulated service access message and then forward it to the destination device.
[0070] In one embodiment, the application-level server is a firewall. When the application-level server receives the encapsulated service access message, after performing a legality confirmation on the encapsulated service access message, forward the encapsulated service access message to the destination device.
[0071] In this alternative embodiment, by receiving a service access packet sent by a client network router, where the service access packet includes source device identification information and destination device identification information, determine target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information; the target forwarding link information includes application-level server identification information; encapsulate the target forwarding link information in the service access packet to form an encapsulated service access packet; forward the encapsulated service access packet according to the target forwarding link information, so that when the application-level server receives the encapsulated service access packet, perform corresponding application-level processing on the encapsulated service access packet and then forward it to the destination device. Based on the target forwarding link information including the application-level server identification information carried on the SR BE tunnel, obtain the encapsulated service access packet and forward the encapsulated service access packet according to the target forwarding link information. Thus, it can be ensured that the encapsulated service access packet is forwarded to the destination device after being processed by the application-level server. That is, through the data forwarding method of this solution, it can be ensured that when sending a service access packet based on the SR BE tunnel, the service access packet passes through the application-level server. Thus, the technical problem in the related art that when deploying an application-level server in the network, it cannot be ensured that the service access packet can be forwarded to the application-level server when transmitting the service access packet based on the SR BE tunnel is solved.
[0072] In an alternative embodiment, in the above step S102, determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information includes:
[0073] S201, in response to the pre-stored routing table including a routing table carried on the SR BE tunnel, where each forwarding link information of the routing table carried on the SR BE tunnel includes the identification information of the application-level server, obtain at least one candidate forwarding link information including the source device identification information and the destination device identification information from the routing table carried on the SR BE tunnel.
[0074] Among them, each forwarding link information of the routing table carried on the SR BE tunnel includes the identification information of the application-level server.
[0075] In an alternative embodiment, for the network structure of the embodiments of the present application, there may be a forwarding link management device, which can manage each forwarding link in the network structure. If the source device is a client device and the destination device is a device corresponding to the data center, the forwarding link determined by the forwarding link management device may include a forwarding link carried on an SRv6 Policy tunnel. It also includes a forwarding link carried on an SR BE tunnel, and the application-level server identification information is included in the forwarding link carried on the SR BE tunnel determined for it. If the source device is a client device and the destination device is another client device, the forwarding link determined by the forwarding link management device may include a forwarding link carried on the SR BE tunnel, and the application-level server identification information is included in the forwarding link carried on the SR BE tunnel determined for it. Then, each forwarding path is parsed to determine the network edge router identification information included in each forwarding link. The forwarding links including the same network edge router identification information are formed into a routing table carried on the SRv6 Policy tunnel and a routing table carried on the SR BE tunnel according to different bearer tunnel types, and are sent to the corresponding network edge routers. The network edge routers store the routing table of the SRv6 Policy tunnel and the routing table carried on the SR BE tunnel.
[0076] Then, the routing table carried on the SR BE tunnel is included in the network edge router. The routing table carried on the SR BE tunnel is obtained. The routing table carried on the SR BE tunnel includes multiple forwarding link information. Among them, each forwarding link information in the multiple forwarding link information includes the identification information of multiple devices corresponding to multiple forwarding nodes respectively, and the multiple forwarding nodes are arranged in a preset forwarding order.
[0077] As an alternative embodiment, obtaining the routing table carried on the SR BE tunnel may include the following solution: The network edge router PE monitors that a forwarding link where the client network router carried on the SR Policy tunnel is located fails, generates a tunnel switching instruction for carrying service access packets through the SR BE tunnel, generates an instruction for calling the routing table including the routing table carried on the SR BE tunnel stored in advance based on the tunnel switching instruction, and calls the routing table including the routing table carried on the SR BE tunnel stored in advance based on the instruction.
[0078] As an alternative implementation, obtaining at least one candidate forwarding link information including source device identification information and destination device identification information from the routing table carried on the SR BE tunnel may include: by matching the source device identification information and destination device identification information in the service access packet with the source device identification information and destination device identification information in the routing table carried on the SR BE tunnel, obtaining from the routing table carried on the SR BE tunnel at least one forwarding link information where the source device identification information of the service access packet is the same as the source device identification information in the routing table carried on the SR BE tunnel, and the destination device identification information of the service access packet is also the same as the destination device identification information in the routing table carried on the SR BE tunnel. The at least one selected forwarding link information is the candidate forwarding link information.
[0079] S202, determine the target forwarding link information from at least one candidate forwarding link information.
[0080] It can be understood that if there is one candidate forwarding link information, the candidate forwarding link information is determined as the target forwarding link information.
[0081] If there are multiple candidate forwarding link information, as an alternative implementation, the target forwarding link information can be determined from at least one candidate forwarding link information according to the network requirement information of the client device.
[0082] Among them, the network requirement information is used to identify the user requirement situation and may include: meeting the bandwidth requirement for the client device to send service access packets, minimizing network overhead, and so on.
[0083] If there are multiple candidate forwarding link information, as another alternative implementation, the load situation of the candidate forwarding links can also be determined, and a candidate forwarding link with a smaller load is selected as the target forwarding link.
[0084] It can be understood that determining the target forwarding link information from at least one candidate forwarding link information can also be other methods, which are not limited in this embodiment.
[0085] In this alternative embodiment, at least one candidate forwarding link information including source device identification information and destination device identification information is determined according to the routing table stored in advance and carried on the SR BE tunnel, and the target forwarding link information is determined based on the at least one candidate forwarding link information. Compared with the method of temporarily determining the candidate forwarding link information and the target forwarding link information after obtaining the service access packet at the network edge router PE, this solution can quickly determine at least one candidate forwarding link information and the target forwarding link information. Since the identification information of the application-level server is included in each forwarding link information in the routing table carried on the SR BE tunnel, at least one candidate forwarding link information determined therefrom also includes the identification information of the application-level server, and the target forwarding link information determined from the at least one candidate forwarding link information necessarily includes the identification information of the application-level server. Thus, it can be ensured that when the encapsulated service access packet is forwarded according to the target forwarding link information, the encapsulated service access packet will necessarily pass through the application-level server, solving the technical problem in the related art that when an application-level server is deployed in the network and the service access packet is transmitted based on the SR BE tunnel, it cannot be ensured that the service data can be forwarded to the application-level server.
[0086] In an alternative embodiment, in step S202, the marking data of each forwarding link is associated and stored in the routing table carried on the SR BE tunnel.
[0087] Correspondingly, obtaining at least one candidate forwarding link information including source device identification information and destination device identification information from the routing table carried on the SR BE tunnel includes:
[0088] S301, determining the candidate marking data corresponding to at least one candidate forwarding link information.
[0089] S302, obtaining at least one candidate forwarding link information from the routing table carried on the SR BE tunnel based on the candidate marking data.
[0090] Among them, the routing table carried on the SR BE tunnel includes at least multiple forwarding links and the marking data corresponding to each forwarding link respectively. In one embodiment, there can be multiple types of marking data. Exemplarily, the marking data can include extended community attribute data (such as Color attribute).
[0091] Continuing the above embodiment for illustration. In an alternative implementation manner, each time the forwarding link management device generates a forwarding link information, marking data is configured for the forwarding link information based on the destination device identification information, and a mapping relationship between the destination device identification information and the marking data is established. The marking data corresponding to the same destination device identification information is the same.
[0092] In this embodiment, after the client network router receives the service access packet sent by the client device, it can determine the marked data with a mapping relationship based on the destination device identification information, and carry the marked data in the service access packet. Therefore, the network edge router PE directly compares the marked data in the service access packet with the marked data in the routing table carried on the SR BE tunnel based on the mapping relationship between the destination device identification information and the marked data in the pre-stored routing table carried on the SR BE tunnel, and obtains the forwarding link information with consistent marked information as the candidate forwarding link information.
[0093] In this alternative embodiment, by determining the candidate marked data corresponding to at least one candidate forwarding link information, and obtaining at least one candidate forwarding link information from the routing table carried on the SR BE tunnel based on the candidate marked data, compared with the method of comparing the source device identification information and the destination device identification information of the service access packet with the source device identification information and the destination device identification information in the routing table carried on the SR BE tunnel, the solution of this alternative embodiment only needs to compare the marked data. Because the amount of data for comparison is small, the comparison speed is fast and the processing efficiency is high.
[0094] In an alternative embodiment, when there are multiple candidate forwarding link information, determining the target forwarding link information from at least one candidate forwarding link information includes:
[0095] S401, obtaining the network requirement information of the source device from the client network router.
[0096] Among them, the network requirement information is used to identify the user requirement situation. In one embodiment, the types of network requirement information may include any one or more of the following: bandwidth requirement information, network overhead information, etc.
[0097] It should be noted that there are many methods to obtain the network requirement information of the source device from the client network router, which are not limited here.
[0098] S402, screening out the candidate forwarding link information that meets the network requirements from the multiple candidate forwarding link information as the target forwarding link information based on the network requirement information.
[0099] Based on the difference of the network requirement information, meeting the network requirements will also be different. Exemplarily, if the network requirement information is bandwidth requirement information, then meeting the network requirements means meeting the bandwidth requirements required for the client device to send service access packets. If the network requirement information is network overhead requirement, then meeting the network requirements means meeting the network overhead requirements of the service access packets sent by the client device. If the network requirement information is bandwidth requirement information and network overhead information, then meeting the network requirements means meeting both the bandwidth requirements and the network overhead requirements.
[0100] Exemplarily, if meeting the network requirements means having a relatively small network overhead, screening out the candidate forwarding link information that meets the network requirements from multiple candidate forwarding link information as the target forwarding link information may include the following solution: calculating the network overhead of each candidate forwarding link in the multiple candidate forwarding link information respectively, and determining the candidate forwarding link with a relatively small network overhead as the target forwarding link information.
[0101] In this alternative embodiment, screening out the candidate forwarding link information that meets the network requirements from multiple candidate forwarding link information as the target forwarding link information according to the network requirement information of the client device can ensure that the service access packets sent from the client device to the client network router and then sent by the client network router can be successfully forwarded to the destination device according to the target forwarding link information while meeting the user's network requirements, and improving the user experience of using the network service.
[0102] In an alternative embodiment, in step S102, determining the target forwarding link information carried on the segment routing SR BE tunnel based on the source device identification information and the destination device identification information may include the following solution:
[0103] S501, in response to the routing table stored in advance not including the routing table carried on the SR BE tunnel, generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server.
[0104] In an alternative implementation manner, for the network structure of the embodiments of the present application, there is no forwarding link management device, or even if there is a forwarding link management device, the determined original forwarding links are stored in the forwarding link management device. If the source device is a client device and the destination device is a device corresponding to the data center, the forwarding links determined by the forwarding link management device for it include the forwarding links carried on the SRv6Policy tunnel and also include the forwarding links carried on the SR BE tunnel, but the forwarding links carried on the SR BE tunnel do not include the identification information of the application-level server. Or if the source device is a client device and the destination device is another client device, the forwarding links of the SR BE tunnel determined by the forwarding link management device for it also do not include the identification information of the application-level server. Therefore, there is no routing table carried on the SR BE tunnel including the identification information of the application-level server in the network edge router.
[0105] Then in this alternative implementation manner, generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server.
[0106] As an alternative implementation, generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server may include the following solution: inserting the identification information of the application-level server into the forwarding link including the source device identification information and the destination device identification information to generate at least one candidate forwarding link information carried on the SR BE tunnel.
[0107] S502. Determine the target forwarding link information from at least one candidate forwarding link information.
[0108] As an alternative implementation, determine the target forwarding link information from at least one candidate forwarding link information according to the network requirement information of the source device.
[0109] In this alternative embodiment, when the routing table carried on the SR BE tunnel is not included in the pre-stored routing table, at least one candidate forwarding link information carried on the SR BE tunnel is generated according to the source device identification information, the destination device identification information, and the identification information of the application-level server. The at least one candidate forwarding link information obtained thereby includes the identification information of the application-level server, and the target forwarding link information determined from at least one candidate forwarding link information will necessarily include the identification information of the application-level server. Thus, it can be ensured that the service access packet will necessarily pass through the application-level server when forwarded based on the SR BE tunnel. And the target forwarding link information is determined only when there is a need to forward based on the SR BE tunnel, which can reduce the occupation of processing resources.
[0110] In an alternative embodiment, in step S501, generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server includes:
[0111] S601. Generate at least one first-segment candidate forwarding link information carried on the SR BE tunnel based on the source device identification information and the identification information of the application-level server.
[0112] Wherein, the first-segment candidate forwarding link information at least includes: the forwarding link information with the source device as the source end device for data sending and the application-level server as the data receiving device.
[0113] In one embodiment, the configuration information of multiple devices and the device identification information of multiple devices deployed between the source device and the application-level server in the network are obtained. The configuration information includes information such as the bandwidth of the devices. According to the configuration information and device identification information of the multiple devices, at least one first segmented candidate forwarding link information carried on the SR BE tunnel is determined.
[0114] S602, generate at least one second segmented candidate forwarding link information carried on the SR BE tunnel based on the identification information of the application-level server and the destination device identification information.
[0115] Among them, the second segmented candidate forwarding link information at least includes: the forwarding link information with the application-level server as the source device for data transmission and the destination terminal device as the data receiving device.
[0116] In one embodiment, the configuration information of multiple devices and the device identification information of multiple devices deployed between the application-level server and the destination terminal device in the network are obtained. The configuration information includes information such as the bandwidth of the devices. According to the configuration information and device identification information of the multiple devices, at least one second segmented candidate forwarding link information carried on the SR BE tunnel is determined.
[0117] S603, generate at least one candidate forwarding link information based on at least one first segmented candidate forwarding link information and at least one second segmented candidate forwarding link information.
[0118] In one embodiment, the at least one first segmented candidate forwarding link information and the at least one second segmented candidate forwarding link information are arranged and combined to generate at least one candidate forwarding link information. Among them, each candidate link forwarding information in the at least one candidate forwarding link information includes a first segmented candidate forwarding link information and a second segmented candidate forwarding link information.
[0119] In this alternative embodiment, at least one first segmented candidate forwarding link information carried on the SR BE tunnel is generated according to the source device identification information and the identification information of the application-level server, and at least one second segmented candidate forwarding link information carried on the SR BE tunnel is generated based on the identification information of the application-level server and the destination device identification information. At least one candidate forwarding link information is generated according to the at least one first segmented candidate forwarding link information and the at least one second segmented candidate forwarding link information. The at least one candidate forwarding link information obtained thereby includes the identification information of the application-level server, which can ensure that the service access message will necessarily pass through the application-level server when being forwarded based on the SR BE tunnel and the target forwarding link information determined from the at least one candidate forwarding link information.
[0120] In an alternative embodiment, in step S102, the destination device identification information is cloud device identification information. Determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information may include the following solutions:
[0121] In response to detecting a failure in the forwarding link where the client network router of the policy-based segment routing SR Policy tunnel is located, determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information.
[0122] Among them, the target forwarding link information includes application-level server identification information.
[0123] Among them, the cloud device is the device corresponding to the data center.
[0124] Among them, there may be various situations where the forwarding link where the client network router of the segment routing SR Policy tunnel is located fails. For example, it may include the situation where a device of a forwarding node in the forwarding link fails.
[0125] In an embodiment, determining whether the forwarding link where the client network router of the SR Policy tunnel is located fails may include the following solutions: performing bidirectional forwarding detection (abbreviated as BDF in English: Bidirectional Forwarding Detection) between the network edge router PE and the destination device, and determining whether the forwarding link where the client network router of the SR Policy tunnel is located fails according to the detection result.
[0126] In this alternative embodiment, by responding to detecting a failure in the forwarding link where the client network router of the policy-based segment routing SR Policy tunnel is located, and determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information, it can ensure that when the SR Policy tunnel between the client device and the destination device fails, the service access packets can be forwarded based on the SR BE tunnel, and ensure that the service access packets pass through the application-level server during forwarding.
[0127] In an alternative embodiment, for the data plane of the service access packets carried by SRv6 BE, the data forwarding method includes the following solutions:
[0128] S701, the network edge router on the destination device side advertises a BGP route to the network edge router on the client side, and assigns an extended community attribute Color value of the BGP route to the route prefix.
[0129] Among them, the BGP route includes the destination device identification information. In one embodiment, the route prefix is the destination device identification information of the destination device.
[0130] The network edge router on the client side generates a routing table according to the received BGP route and stores the routing table in the network edge router on the client side. The routing table includes the routing table carried on the SRv6 BE tunnel, and the identification information of the application-level server is included in each forwarding link information of the routing table carried on the SRv6 BE tunnel.
[0131] S702, the client device sends a service access message to the network edge router on the client device side through the client network router. The network edge router on the source device side parses the service access message to obtain the source device identification information and the destination device identification information included in the service access message.
[0132] S703, if the routing table stored in the network edge router on the client side includes the routing table carried on the SRv6 BE tunnel, at least one candidate forwarding link information including the source device identification information and the destination device identification information is obtained from the routing table carried on the SRv6 BE tunnel, and at least one candidate forwarding link information includes the application-level server identification information in the target forwarding link information. Then, the network edge router on the client side determines the target forwarding link information from at least one candidate forwarding link information in response to the routing table stored in advance including the routing table carried on the SRv6 BE tunnel.
[0133] If the routing table stored in the network edge router on the client side does not include the routing table carried on the SR BE tunnel, at least one candidate forwarding link information carried on the SRv6 BE tunnel is generated based on the source device identification information, the destination device identification information, and the identification information of the application-level server, and the target forwarding link information is determined from at least one candidate forwarding link information.
[0134] S704, the network edge router on the client device side encapsulates the target forwarding link information in the service access message and forwards the encapsulated service access message according to the target forwarding link information, so that the service access message can be forwarded to the application-level server, and the application-level server provides application-level services for the service access message.
[0135] In this alternative embodiment, if the encapsulated service access packet sent by the network edge router on the client device side contains application-level server identification information, the encapsulated service access packet will first be forwarded to the application-level server corresponding to the application-level server identification information. After being processed by the application-level server, the service access packet will then be forwarded to the network edge router on the destination device side, and the network edge router on the destination device side will forward the service access packet to the destination device.
[0136] In an alternative embodiment, for the data plane of the service access packet carried by SR MPLS BE, the data forwarding method includes the following solutions:
[0137] S801, the network edge router on the destination device side publishes a BGP route to the network edge router on the client side and assigns a Color value of the extended community attribute of the BGP route to the route prefix.
[0138] Among them, the BGP route includes destination device identification information. In one embodiment, the route prefix is the destination device identification information of the destination device.
[0139] The network edge router on the client side generates a routing table based on the received BGP route and stores the routing table in the network edge router on the client side. The routing table includes the routing table carried on the SR MPLS BE tunnel, and the forwarding link information of the routing table carried on the SR MPLS BE tunnel includes the identification information of the application-level server.
[0140] S802, the client device sends a service access packet to the network edge router on the client device side through the client network router. The network edge router on the source device side parses the service access packet to obtain the source device identification information and destination device identification information contained in the service access packet.
[0141] S803, if the routing table stored in the network edge router on the client side includes the routing table carried on the SR MPLS BE tunnel, at least one candidate forwarding link information including the source device identification information and the destination device identification information is obtained from the routing table carried on the SR MPLS BE tunnel, and at least one candidate forwarding link information includes the application-level server identification information in the target forwarding link information, then the network edge router on the client side determines the target forwarding link information from at least one candidate forwarding link information in response to the routing table stored in advance including the routing table carried on the SR MPLS BE tunnel.
[0142] If the routing table stored in the network edge router on the client side does not include the routing table carried on the SR BE tunnel, at least one candidate forwarding link information carried on the SR MPLS BE tunnel is generated based on the source device identification information, the destination device identification information, and the identification information of the application-level server, and the target forwarding link information is determined from the at least one candidate forwarding link information.
[0143] S804, the network edge router on the client device side encapsulates the target forwarding link information in the service access message, and forwards the encapsulated service access message according to the target forwarding link information, so that the service access message can be forwarded to the application-level server, and the application-level server provides application-level services for the service access message.
[0144] In this alternative embodiment, if the encapsulated service access message sent by the network edge router on the client device side contains the application-level server identification information, the encapsulated service access message will first be forwarded to the application-level server corresponding to the application-level server identification information. After being processed by the application-level server, the service access message will then be forwarded to the network edge router on the destination device side, and the network edge router on the destination device side will forward the service access message to the destination device.
[0145] In the above alternative embodiment, by mapping the BGP routing extended community attribute Color to the service-oriented SID, all traffic flows carried on the SR BE tunnel are supported to be forwarded to the application-level server corresponding to the service-oriented SID, which can ensure that regardless of whether the SR Policy tunnel or the SR BE tunnel is deployed between the client device and the destination device, and regardless of whether the network link is in a normal state or a fault state, the service access message can be ensured to be forwarded to the application-level server to provide application-level services for the service forwarding message. In addition, based on the method of this embodiment, the service-oriented SID can be supported for orchestration for the traffic carried on the SR MPLS BE tunnel or the SRv6 BE tunnel, thereby ensuring that application-level services are provided for the service access message carried on the SR BR tunnel.
[0146] Figure 6 This is a schematic structural diagram of a data forwarding device provided by an embodiment of the present invention. As Figure 6 shown, the data forwarding device 90 provided in this embodiment includes: a receiving module 901, a determining module 902, an encapsulating module 903, and a forwarding module 904.
[0147] Among them, a receiving module 901 is configured to receive a service access packet sent by a client network router, where the service access packet includes source device identification information and destination device identification information; a determining module 902 is configured to determine target forwarding link information carried on an SR BE tunnel based on the source device identification information and the destination device identification information; the target forwarding link information includes application-level server identification information; a packaging module 903 is configured to package the target forwarding link information in the service access packet to form a packaged service access packet; a forwarding module 904 is configured to forward the packaged service access packet according to the target forwarding link information, so that after the application-level server receives the packaged service access packet, perform corresponding application-level processing on the packaged service access packet and then forward it to the destination device.
[0148] The data forwarding device provided in this embodiment may execute Figure 5 the technical solution of the method embodiment shown, and its implementation principle and technical effects are similar, which will not be elaborated here.
[0149] Optionally, when determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information, the determining module 902 is specifically configured to: in response to the pre-stored routing table including the routing table carried on the SR BE tunnel, each forwarding link information of the routing table carried on the SR BE tunnel includes the identification information of the application-level server; obtain at least one candidate forwarding link information including the source device identification information and the destination device identification information from the routing table carried on the SR BE tunnel;
[0150] determine the target forwarding link information from at least one candidate forwarding link information.
[0151] Optionally, the routing table carried on the SR BE tunnel is associated with and stores the marking data of each forwarding link; correspondingly, when the determining module 902 obtains at least one candidate forwarding link information including the source device identification information and the destination device identification information from the routing table carried on the SR BE tunnel, it is specifically configured to: determine the candidate marking data corresponding to at least one candidate forwarding link information; obtain at least one candidate forwarding link information from the routing table carried on the SR BE tunnel based on the candidate marking data.
[0152] Optionally, there are multiple candidate forwarding link information. Correspondingly, when the determining module 902 determines the target forwarding link information from at least one candidate forwarding link information, it is specifically configured to: obtain the network demand information of the source device from the client network router; filter out the candidate forwarding link information that meets the network demand from the multiple candidate forwarding link information as the target forwarding link information.
[0153] Optionally, the data forwarding device further includes a generating module, configured to: in response to the routing table pre-stored not including the routing table carried on the SR BE tunnel, generate at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server; determine the target forwarding link information from the at least one candidate forwarding link information.
[0154] Optionally, when generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server, the generating module is specifically configured to: generate at least one first-segment candidate forwarding link information carried on the SR BE tunnel based on the source device identification information and the identification information of the application-level server; generate at least one second-segment candidate forwarding link information carried on the SR BE tunnel based on the identification information of the application-level server and the destination device identification information; generate at least one candidate forwarding link information according to the at least one first-segment candidate forwarding link information and the at least one second-segment candidate forwarding link information.
[0155] Optionally, the destination device identification information is cloud device identification information; when determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information, the determining module 902 is specifically configured to: in response to detecting a failure in the forwarding link where the client network router of the policy-based segment routing SR Policy tunnel is located, determine the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information.
[0156] Figure 7 The figure is a schematic structural diagram of a network edge router provided by an embodiment of the present invention. As Figure 7 shown, the network edge router 100 includes: a processor 1001, a memory 1002 communicatively connected to the processor, and a transceiver 1003.
[0157] Among them, the memory stores computer-executable instructions; the transceiver is used for sending and receiving data; the processor executes the computer-executable instructions stored in the memory to implement the data forwarding method provided by the corresponding embodiment.
[0158] The embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement any of the above method embodiments. The specific implementation manners and technical effects are similar and will not be elaborated here.
[0159] The present application also provides a computer program product, including a computer program which, when executed by a processor, implements any of the above method embodiments. The specific implementation manners and technical effects are similar and will not be elaborated herein.
[0160] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or modules can be in electrical, mechanical or other forms.
[0161] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they can be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0162] In addition, in each embodiment of the present application, the various functional modules can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module. The above integrated modules can be implemented in the form of hardware, or in the form of a combination of hardware and software functional modules.
[0163] The program code for implementing the method of the present invention can be written in any combination of one or more programming languages. These program codes can be provided to the processor or controller of a general-purpose computer, a special-purpose computer or other programmable data processing devices, so that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.
[0164] In the context of the present invention, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0165] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the present application are pointed out by the following claims.
[0166] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A data forwarding method, characterized in that, the method is applied to a network edge router, and the method includes: receiving a service access message sent by a client network router, where the service access message includes source device identification information and destination device identification information; in response to the pre-stored routing table including a routing table carried on an SR BE tunnel; obtaining at least one candidate forwarding link information including the source device identification information and the destination device identification information from the routing table carried on the SR BE tunnel; each forwarding link information in the routing table carried on the SR BE tunnel includes identification information of an application-level server; determining target forwarding link information from at least one of the candidate forwarding link information; the target forwarding link information includes application-level server identification information; encapsulating the target forwarding link information in the service access message to form an encapsulated service access message; forwarding the encapsulated service access message according to the target forwarding link information, so that when the application-level server receives the encapsulated service access message, the encapsulated service access message is subjected to corresponding application-level processing and then forwarded to the destination device.
2. The method according to claim 1, characterized in that, tag data of each forwarding link is associated and stored in the routing table carried on the SR BE tunnel; obtaining at least one candidate forwarding link information including the source device identification information and the destination device identification information from the routing table carried on the SR BE tunnel includes: determining candidate tag data corresponding to the at least one candidate forwarding link information; obtaining at least one candidate forwarding link information from the routing table carried on the SR BE tunnel based on the candidate tag data.
3. The method according to claim 1, characterized in that, there are multiple pieces of candidate forwarding link information, and determining the target forwarding link information from at least one of the candidate forwarding link information includes: obtaining network requirement information of the source device from the client network router; filtering out candidate forwarding link information that meets the network requirements from the multiple pieces of candidate forwarding link information as the target forwarding link information based on the network requirement information.
4. The method according to claim 1, characterized in that, further includes: in response to the pre-stored routing table not including a routing table carried on an SR BE tunnel, generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server; determining the target forwarding link information from at least one of the candidate forwarding link information.
5. The method according to claim 4, characterized in that, generating at least one candidate forwarding link information carried on the SR BE tunnel based on the source device identification information, the destination device identification information, and the identification information of the application-level server includes: Generate at least one first segmented candidate forwarding link information carried on an SR BE tunnel based on the source device identification information and the identification information of the application-level server; Generate at least one second segmented candidate forwarding link information carried on an SR BE tunnel based on the identification information of the application-level server and the destination device identification information; Generate at least one candidate forwarding link information according to at least one first segmented candidate forwarding link information and at least one second segmented candidate forwarding link information.
6. The method according to any one of claims 1-5, characterized in that the destination device identification information is cloud device identification information; The determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information includes: In response to detecting a failure in the forwarding link where the client network router of the policy-based segment routing SR Policy tunnel is located, determining the target forwarding link information carried on the SR BE tunnel based on the source device identification information and the destination device identification information.
7. A data forwarding device, characterized in that the device is located in a network backbone access router, and the device includes: a receiving module, configured to receive a service access message sent by a client network router, where the service access message includes source device identification information and destination device identification information; a determining module, configured to, in response to the pre-stored routing table including a routing table carried on an SR BE tunnel, obtain at least one candidate forwarding link information including the source device identification information and the destination device identification information in the routing table carried on the SR BE tunnel; each forwarding link information in the routing table carried on the SR BE tunnel includes the identification information of the application-level server; determine the target forwarding link information from at least one of the candidate forwarding link information; the target forwarding link information includes the application-level server identification information; an encapsulation module, configured to encapsulate the target forwarding link information in the service access message to form an encapsulated service access message; a forwarding module, configured to forward the encapsulated service access message according to the target forwarding link information, so that after the application-level server receives the encapsulated service access message, perform corresponding application-level processing on the encapsulated service access message and then forward it to the destination device.
8. A network edge router, characterized in that it includes: a processor, and a memory and a transceiver communicatively connected to the processor; the memory stores computer execution instructions; the transceiver is used for sending and receiving data; the processor executes the computer execution instructions stored in the memory to implement the method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that a computer program is stored thereon, and the computer program is executed by a processor to implement the method according to any one of claims 1-6.
Citation Information
Patent Citations
5G service dynamic intelligent SR tunnel application method
CN112291147A
Message sending method, device and system
CN115004656A