Implementation method for limiting bandwidth of IPv6

By combining QoS policies with routers and VPC border firewalls, and using shared bandwidth to control IPv6 traffic, the problems of IPv6 bandwidth limitation and sale in existing technologies are solved, achieving flexible bandwidth management and resource saving.

CN116319560BActive Publication Date: 2026-04-14UNICLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-16
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Existing technologies cannot effectively limit and sell IPv6 traffic bandwidth, resulting in wasted resources and poor customer experience.

Method used

By combining routers with VPC boundary firewalls and QoS policies, IPv6 traffic can be controlled using shared bandwidth, IPv6 bandwidth can be limited, traffic statistics can be sold, and bandwidth values ​​can be dynamically adjusted.

Benefits of technology

It enables flexible IPv6 bandwidth limiting and traffic management, saves resources, provides a user-friendly experience, and supports the sale of shared bandwidth for multiple IPv6 addresses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319560B_ABST
    Figure CN116319560B_ABST
Patent Text Reader

Abstract

The application provides an implementation method for limiting the bandwidth of IPv6, wherein the address of the IPV6 is placed on a CVK virtual machine or a single server in a VPC network; when the IPV6 accesses an external network, the data packet flow path is Leaf switch, Spine switch, VPC border firewall, Internet interface and router in sequence; the router and the VPC border firewall limit the bandwidth and flow of the IPV6; when the IPV6 is sold, the shared bandwidth is added; and when the IPV6 stops serving, the shared bandwidth is removed. The application has the beneficial effect that the router and the VPC border firewall are used to limit the bandwidth and flow of the IPV6, and the QOS strategy of the uplink and downlink ports on the router is used to realize the purpose of the flow limitation and flow statistics selling of the IPV6.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of public cloud networks, and in particular relates to a method for limiting IPv6 bandwidth. Background Technology

[0002] IPv6, short for "Internet Protocol Version 6," is the next-generation IP protocol designed to replace IPv4, and is the protocol for the next generation of the Internet. The use of IPv6 not only solves the problem of the limited number of network address resources but also removes obstacles for various access devices to connect to the Internet. Its 128-bit address format, with its significant advantages in IP address quantity, security, mobility, and quality of service, will transform modern information life.

[0003] Virtual Private Cloud (VPC) provides users with a dedicated network environment, allowing for flexible configuration of the network and cloud servers within the VPC, effectively meeting users' needs for elastic and secure networks. Virtual machines within a VPC can be configured with both IPv4 and IPv6 addresses. IPv4 addresses are internal network addresses, requiring binding to an Elastic IP Address (EIP) or NAT operations for access from outside the cloud. A simple VPC private IPv4 address cannot be directly accessed from the external network. However, due to the sheer number of IPv6 addresses, they can directly access and be accessed by the Internet without binding to an additional EIP. Current technology cannot solve the problems of limiting IPv6 bandwidth and its resale. Summary of the Invention

[0004] In view of this, the present invention aims to propose a method for limiting IPv6 bandwidth. This method limits IPv6 bandwidth and traffic through routers and VPC boundary firewalls, and utilizes the QoS policies of the uplink and downlink ports on the router to achieve the purpose of IPv6 rate limiting and traffic statistics sales, thereby solving the problems of limiting IPv6 traffic bandwidth and sales.

[0005] To achieve the above objectives, the technical solution of the present invention is implemented as follows:

[0006] In the first aspect, this invention mentions a method for limiting IPv6 bandwidth;

[0007] VPC networks control IPv6 traffic by using shared bandwidth;

[0008] IPv6 addresses are placed in CVK virtual machines within a VPC network or on a separate server;

[0009] When IPv6 accesses an external network, the data packet flow path is as follows: Leaf switch, Spine switch, VPC border firewall, Internet interface, router;

[0010] The router and VPC border firewall limit the bandwidth and traffic of IPv6. IPv6 is added to the shared bandwidth when it is sold and removed from the shared bandwidth when IPv6 service is discontinued.

[0011] Furthermore, the VPC network restricts IPv6 traffic through the inter-domain policies of the VPC boundary firewall;

[0012] The VPC network restricts IPv6 traffic through the QoS access policies of the router's uplink and downlink ports.

[0013] Furthermore, the configuration of the shared bandwidth of the VPC network includes: ACL access policy, behavior actions, and classifier flow behavior;

[0014] The addresses of data packets that need to be allowed can be added to the ACL;

[0015] The behavior action controls bandwidth to allow or block data packets;

[0016] The classifier flow behavior combines ACLs and behaviors; when an ACL policy is matched, the corresponding behavior action is applied.

[0017] Furthermore, the steps for restricting IPv6 in the VPC network are as follows:

[0018] A1: After a user purchases a virtual machine and sets up IPv6, IPv6 does not support individual bandwidth values ​​for the device. Instead, a basic behavior action named denyipv6 is configured on the router, and the action executed by denyipv6 is deny.

[0019] A2: Create a basic ACL access policy named acl_ipv6deny, with the rule under the ACL access policy being permit_ipv6.

[0020] A3: The common practice of classifier is to combine denyipv6 and acl_ipv6deny and then apply them to the QoS access policies of the router's uplink and downlink ports.

[0021] Furthermore, the steps for adding shared bandwidth to IPv6 are as follows:

[0022] B1: Create a shared bandwidth instance of type IPv6 in the VPC network, and at the same time create a corresponding ACL access policy;

[0023] B2: A VPC network creates a behavior action and a classifier flow behavior;

[0024] B3: When IPv6 is added to the shared bandwidth, add an IPv6 address to the shared bandwidth ACL access policy, configure the bandwidth value of the shared bandwidth in the behavior action, and set the behavior action to allow.

[0025] Furthermore, when removing IPv6 from the shared bandwidth, the IPv6 address in the shared bandwidth's ACL access policy is also removed.

[0026] Furthermore, when adjusting the IPv6 bandwidth value, the bandwidth value can be dynamically adjusted by adjusting the bandwidth value of the shared bandwidth instance.

[0027] In a second aspect, an electronic device includes a processor and a memory communicatively connected to the processor and used to store executable instructions of the processor, characterized in that: the processor is used to execute an implementation method for limiting IPv6 bandwidth as described in any of the first aspects above.

[0028] Thirdly, a server, characterized in that it includes at least one processor and a memory communicatively connected to the processor, the memory storing instructions executable by the at least one processor, the instructions being executed by the processor to cause the at least one processor to perform an implementation method for limiting IPv6 bandwidth as described in any of the first aspects.

[0029] Fourthly, a computer-readable storage medium storing a computer program, characterized in that: when the computer program is executed by a processor, it implements the method for limiting IPv6 bandwidth as described in any one of the first aspects.

[0030] Compared with existing technologies, the method for limiting IPv6 bandwidth described in this invention has the following advantages:

[0031] The present invention describes a method for limiting IPv6 bandwidth. By controlling IPv6 traffic through shared bandwidth, the method utilizes the QoS policies of the uplink and downlink ports on the router to achieve the purpose of IPv6 rate limiting and traffic statistics for sale. Furthermore, because IPv6 is incorporated into the shared bandwidth, the bandwidth value of the shared bandwidth can be dynamically adjusted. This allows for more flexible adjustments to the IPv6 bandwidth value at any time, resulting in a more user-friendly experience. Additionally, multiple IPv6 addresses can be added to a single shared bandwidth, saving resources and reducing costs compared to customers purchasing multiple IPv6 addresses individually. Attached Figure Description

[0032] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings:

[0033] Figure 1 This is a schematic diagram of the overall structure of the VPC network according to an embodiment of the present invention. Detailed Implementation

[0034] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.

[0035] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0036] like Figure 1 The diagram illustrates a method for limiting IPv6 bandwidth. A VPC network controls IPv6 traffic using shared bandwidth. IPv6 addresses are located on CVK virtual machines or individual servers within the VPC network. When an IPv6 address accesses an external network, the data packet path is sequentially: Leaf switch, Spine switch, VPC border firewall, Internet interface, and router. The router and VPC border firewall limit the bandwidth and traffic of the IPv6 address. IPv6 addresses are added to the shared bandwidth when sold and removed when service is discontinued. The Internet cannot access individual IPv6 addresses not included in the shared bandwidth.

[0037] VPC networks restrict IPv6 traffic through inter-domain policies of the VPC boundary firewall. To prevent excessive pressure on the VPC boundary firewall, VPC networks also restrict IPv6 traffic through QoS access policies on the router's uplink and downlink ports.

[0038] By controlling IPv6 traffic through shared bandwidth, and utilizing the QoS policies of the uplink and downlink ports on the router, the purpose of IPv6 rate limiting and traffic statistics sales can be achieved.

[0039] The configuration of shared bandwidth in a VPC network includes: ACL access policies, behavior actions, and classifier flow behavior. The ACL access policies can include the addresses of packets that need to be allowed. Behavior actions control whether the bandwidth allows or blocks packets. The classifier flow behavior combines the ACL access policies and behavior actions. When an ACL access policy is matched, the corresponding behavior action is applied.

[0040] The steps to restrict IPv6 in a VPC network are as follows:

[0041] A1: After a user purchases a virtual machine and sets up IPv6, IPv6 does not support individual bandwidth values ​​for the device. Instead, it configures a basic behavior action named denyipv6 on the router. The action of denyipv6 is to deny.

[0042] A2: Create a basic ACL access policy named acl_ipv6deny. The rule under the ACL access policy is permit_ipv6, which means all IPv6 rules are matched.

[0043] A3: The common practice of classifier is to combine denyipv6 and acl_ipv6deny and then apply them to the QoS access policies of the router's uplink and downlink ports.

[0044] Steps A1 to A3 ensure that all IPv6 traffic reaching the router is matched by the ACL access policy. Once matched, the behavior action that would deny traffic based on the classifier flow behavior is applied, thus ensuring that all IPv6 addresses cannot be accessed by the Internet.

[0045] The steps to add shared bandwidth in IPv6 are as follows:

[0046] B1: Create a shared bandwidth instance of type IPv6 in the VPC network, and at the same time create a corresponding ACL access policy;

[0047] B2: A VPC network creates a behavior action and a classifier flow behavior;

[0048] B3: When IPv6 is added to the shared bandwidth, add an IPv6 address to the shared bandwidth ACL access policy, configure the bandwidth value of the shared bandwidth in the behavior action, and set the behavior action to allow.

[0049] Steps B1 to B3 enable all IPv6 addresses that are added to the shared bandwidth to share the bandwidth value of the shared bandwidth.

[0050] Under the QoS policy of the router's uplink and downlink ports, the classifier flow behavior for shared bandwidth must precede the classifier flow behavior of the basic IPv6 configuration. The router's QoS policy matches from top to bottom. When the shared bandwidth classifier flow behavior is matched first, the denied classifier flow behavior will not be matched next. This ensures that as long as the basic denied classifier flow behavior is at the bottom, IPv6 traffic included in the shared bandwidth can proceed, while IPv6 traffic not included in the shared bandwidth will be blocked. This achieves the goal of limiting some IPv6 traffic, thus limiting the IPv6 bandwidth value, and also provides a way to sell IPv6.

[0051] When removing IPv6 from shared bandwidth, the IPv6 address is removed from the shared bandwidth's ACL access policy.

[0052] Once IPv6 is removed from the shared bandwidth, it will no longer be matched by the shared bandwidth's ACL access policy. In the end, it will be matched by the default ACL_IPv6deny, because the behavior of ACL_IPv6deny is deny, which will prevent IPv6 traffic from passing through, thereby achieving the purpose of IPv6 rate limiting.

[0053] When adjusting the IPv6 bandwidth value, the bandwidth value is dynamically adjusted by adjusting the bandwidth value of the shared bandwidth instance.

[0054] Those skilled in the art will recognize that the units and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0055] In the several embodiments provided in this application, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the division of units described above is merely a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. The aforementioned units may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of the present invention according to actual needs.

[0056] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered within the scope of the claims and specification of the present invention.

[0057] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for limiting IPv6 bandwidth, characterized in that: IPv6 addresses are placed in CVK virtual machines within a VPC network or on a separate server; When IPv6 accesses an external network, the data packet flow path is as follows: Leaf switch, Spine switch, VPC border firewall, Internet interface, router; The router and VPC border firewall limit the bandwidth and traffic of IPv6. IPv6 is added to the shared bandwidth when it is sold and removed from the shared bandwidth when IPv6 service is discontinued. The VPC network restricts IPv6 traffic through inter-domain policies of the VPC boundary firewall. The VPC network restricts IPv6 traffic through the QoS access policies of the router's uplink and downlink ports; The configuration of the shared bandwidth of the VPC network includes: ACL access policy, behavior actions, and classifier flow behavior; The addresses of data packets that need to be allowed can be added to the ACL access policy; The behavior action controls bandwidth to allow or block data packets; The classifier behavior combines ACL access policies and behavioral actions. When an ACL access policy is matched, the corresponding behavioral action is applied.

2. The method for limiting IPv6 bandwidth according to claim 1, characterized in that: The steps for restricting IPv6 in the VPC network are as follows: A1: After a user purchases a virtual machine and sets up IPv6, IPv6 does not support individual bandwidth values ​​for the device. Instead, it configures a basic behavior action named denyipv6 on the router. The action executed by denyipv6 is deny. A2: Create a basic ACL access policy named acl_ipv6deny, with the rule under the ACL access policy being permit_ipv6; A3: The common practice of classifier is to combine denyipv6 and acl_ipv6deny and then apply them to the QoS access policies of the router's uplink and downlink ports.

3. The method for limiting IPv6 bandwidth according to claim 1, characterized in that: The steps for adding IPv6 to shared bandwidth are as follows: B1: Create a shared bandwidth instance of type IPv6 in the VPC network, and at the same time create a corresponding ACL access policy; B2: A VPC network creates a behavior action and a classifier flow behavior; B3: When IPv6 is added to the shared bandwidth, add an IPv6 address to the shared bandwidth ACL access policy, configure the bandwidth value of the shared bandwidth in the behavior action, and set the behavior action to allow.

4. The method for limiting IPv6 bandwidth according to claim 1, characterized in that: When removing IPv6 from shared bandwidth, the IPv6 address is removed from the shared bandwidth's ACL access policy.

5. The method for limiting IPv6 bandwidth according to claim 1, characterized in that: When adjusting the IPv6 bandwidth value, the bandwidth value is dynamically adjusted by adjusting the bandwidth value of the shared bandwidth instance.

6. An electronic device, comprising a processor and a memory communicatively connected to the processor and used for storing processor-executable instructions, characterized in that: The processor is used to execute the method for limiting IPv6 bandwidth as described in any one of claims 1-5.

7. A server, characterized in that: The device includes at least one processor and a memory communicatively connected to the processor, the memory storing instructions executable by the at least one processor, the instructions being executed by the processor to cause the at least one processor to perform an implementation method for limiting IPv6 bandwidth as described in any one of claims 1-5.

8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, it implements the method for limiting IPv6 bandwidth as described in any one of claims 1-5.