A method, device, network equipment and storage medium for processing session messages
By labeling the session packets with the target VLAN tag in the data exchange matrix unit and using the link aggregation group forwarding mechanism, the problem of unbalanced session packet distribution in multiple CPU devices is solved, which improves resource utilization and reduces management costs.
Patent Information
- Application Number
- CN202210072305.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-21
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2042-01-21
AI Technical Summary
In the existing multi-CPU device scheme, session packets of the same session are easily divided into different CPUs for processing, resulting in waste of reserved session channel resources and increased management costs.
The session channel interface connecting the CPU using the data exchange matrix unit belongs to a link aggregation group in the incoming direction and can belong to multiple link aggregation groups in the outgoing direction. The to-process session messages are labeled with the target VLAN tag, and forwarded to the target CPU through the link aggregation group for processing.
Improve port resource utilization, reduce unnecessary port bandwidth consumption, and avoid session channel resource waste and management costs.
Smart Images

Figure CN116527606B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of network communication technology, and specifically relates to a session message processing method, apparatus, network equipment and storage medium. Background Art
[0002] In network devices such as routers and firewalls, the number of sessions is often used as an important indicator to measure the capabilities of a device. With the diversification and scale of user access, conventional single-CPU (Central Processing Unit) devices can no longer meet the increasing demand for user data, and a multi-CPU device solution is needed. However, the multi-CPU device solution is prone to the situation where subsequent packets of the same session are not assigned to the CPU that processes the first packet of the session, that is, multiple packets belonging to the same session are assigned to different CPUs for processing. This is because although it is the same session, the session packets may be original packets, or they may be packets after being encapsulated through a tunnel or NAT (Network Address Translation), resulting in different packets of the same session being assigned to different CPUs for processing.
[0003] The current approach is to reserve a certain number of session channels (session channel interfaces connected to the CPU) for each CPU. This allows the CPU to not only receive session packets for session processing but also ensure that packets from the same session, if not assigned to the corresponding CPU, are forwarded to the corresponding CPU through the reserved session channels. This approach wastes reserved session channel resources and increases management costs. Summary of the Invention
[0004] In view of this, the purpose of the present application is to provide a session message processing method, apparatus, network device and storage medium to improve the existing session message processing method which requires a reserved session channel to ensure that the session messages of the same session can be forwarded to the CPU of the corresponding session through the reserved session channel for processing when they are not allocated to the corresponding CPU, resulting in a waste of reserved session channel resources and increased management costs.
[0005] The embodiment of the present application is implemented as follows:
[0006] In a first aspect, embodiments of the present application provide a session packet processing method, applied to a network device comprising multiple CPUs and a data switching matrix unit, the method comprising: determining, by a current CPU, that a received session packet to be processed needs to be forwarded to a corresponding target CPU for processing; tagging, by the current CPU, a target VLAN tag for the session packet to be processed, wherein the target VLAN tag is a VLAN tag supported by a first link aggregation group to which a session channel interface of the data switching matrix unit connected to the target CPU belongs in the outbound direction; and forwarding, by the current CPU, the session packet to be processed with the target VLAN tag to the target CPU via the first link aggregation group for processing. In embodiments of the present application, by adopting a scheme in which the same session channel interface of the data switching matrix unit connected to the CPU belongs to only one link aggregation group in the inbound direction but can belong to multiple link aggregation groups in the outbound direction, the session packet to be processed needs to be forwarded to the corresponding target CPU for processing, and tagging, by the target VLAN tag for the session packet to be processed, ensuring that session packets not destined for the corresponding CPU can be forwarded to the corresponding CPU via other link aggregation groups formed in the outbound direction by the port of the CPU connected to the data switching matrix unit, thereby improving the utilization of existing port resources and resolving the defects of existing session packet processing methods.
[0007] In combination with a possible implementation of the embodiment of the first aspect, before the current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing, the method further includes: the data exchange matrix unit obtains the session message received from the service port, and adds a VLAN tag corresponding to the service port to the session message to obtain the session message to be processed, wherein different service ports correspond to different VLAN tags; forwarding the session message to be processed to the corresponding CPU through the second link aggregation group corresponding to the VLAN tag corresponding to the service port, wherein the second link aggregation group members include multiple session channel interfaces connected to each CPU by the data exchange matrix unit. In the embodiment of the present application, by adding a VLAN tag corresponding to the service port to the session message received by the service port, and then forwarding the session message to be processed to the corresponding CPU through the second link aggregation group corresponding to the VLAN tag corresponding to the service port, session messages from different service ports can be normally forwarded to the CPU.
[0008] In conjunction with a possible implementation of the embodiment of the first aspect, multiple session channel interfaces of the data exchange matrix unit connected to the same CPU belong to the same link aggregation group in the outbound direction, and the link aggregation group is only responsible for forwarding session packets with specific VLAN tags. In an embodiment of the present application, multiple session channel interfaces of the data exchange matrix unit connected to the same CPU belong to the same link aggregation group in the outbound direction, and the link aggregation group is only responsible for forwarding session packets with specific VLAN tags, so that when forwarding session packets, they can be forwarded to the CPU through multiple session channel interfaces in the link aggregation group, avoiding congestion caused by forwarding using a single session channel interface.
[0009] In combination with a possible implementation of the embodiment of the first aspect, the network device also includes a management CPU; the current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing, including: the current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing based on the session decision table sent by the management CPU, wherein each CPU, upon receiving the session message, will synchronize the corresponding session table item information to the management CPU, so that the management CPU determines the session message to be processed by each CPU based on the summarized session table item information, generates the session decision table, and sends the session decision table to each CPU. In the example of the present application, the session table item information of each CPU is summarized by the management CPU, and a session decision table is generated based on this to determine the session message to be processed by each CPU, thereby ensuring that different messages of the same session can be assigned to the same CPU for processing, so as to ensure the continuity of the session.
[0010] In a second aspect, an embodiment of the present application further provides a network device comprising: multiple CPUs and a data exchange matrix unit; each of the multiple CPUs is configured to, when determining that a session message to be processed received by its own CPU needs to be forwarded to a corresponding target CPU for processing, add a target VLAN tag to the session message to be processed, wherein the target VLAN tag is a VLAN tag supported for forwarding by a first link aggregation group to which a session channel interface of the data exchange matrix unit connected to the target CPU belongs in an outgoing direction; the data exchange matrix unit is connected to each CPU through a different session channel interface, and the data exchange matrix unit is configured to forward the session message to be processed with the target VLAN tag to the target CPU through the first link aggregation group for processing.
[0011] In combination with a possible implementation manner of the second aspect of the embodiment, the data exchange matrix unit has multiple external service ports, and different service ports correspond to different VLAN tags; the data exchange matrix unit is also used to: obtain a session message received from the service port, and add a VLAN tag corresponding to the service port to the session message to obtain the session message to be processed; forward the session message to be processed to the corresponding CPU through the second link aggregation group corresponding to the VLAN tag corresponding to the service port, and the members of the second link aggregation group include multiple session channel interfaces of the data exchange matrix unit connected to each CPU.
[0012] In combination with a possible implementation manner of the second aspect of the embodiment, the network device also includes a management CPU, which is connected to each CPU; each CPU is further used to synchronize session table entry information corresponding to the session message to the management CPU when receiving the session message; the management CPU is used to determine the session message processed by each CPU based on the summarized session table entry information, generate a session decision table, and send the session decision table to each CPU; each CPU is further used to determine, based on the session decision table sent by the management CPU, that the session message to be processed received by its own CPU needs to be forwarded to the corresponding target CPU for processing.
[0013] In combination with a possible implementation of the second aspect, multiple session channel interfaces connected to the same CPU belong to the same link aggregation group in the outbound direction, and the link aggregation group is only responsible for forwarding session messages with specific VLAN tags.
[0014] In combination with a possible implementation of the embodiment of the second aspect, the multiple CPUs are respectively located on different master processing units MPU with service ports. In the third aspect, the embodiment of the present application also provides a session message processing device, which belongs to a network device including multiple CPUs and a data exchange matrix unit, and the device includes: a processing module and a forwarding module; the processing module is used to determine that the session message to be processed received by the current CPU needs to be forwarded to the corresponding target CPU for processing, and to add a target VLAN tag to the session message to be processed, wherein the target VLAN tag is a VLAN tag supported by the first link aggregation group to which the session channel interface of the data exchange matrix unit connected to the target CPU belongs in the outgoing direction; the forwarding module is used to forward the session message to be processed with the target VLAN tag to the target CPU through the first link aggregation group for processing.
[0015] In a fourth aspect, an embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is run by a network device, it executes the session message processing method provided in the above-mentioned first aspect embodiment and / or any possible implementation method combined with the first aspect embodiment.
[0016] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or understood by practicing the embodiments of the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures particularly pointed out in the written description and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative work. The above and other purposes, features and advantages of the present application will be more clearly shown in the accompanying drawings. The same reference numerals indicate the same parts throughout the drawings. The drawings are not intentionally scaled to actual size, and the focus is on illustrating the main purpose of the present application.
[0018] Figure 1 A schematic structural diagram of a network device provided in an embodiment of the present application is shown.
[0019] Figure 2 A flow chart of a session message processing method provided in an embodiment of the present application is shown.
[0020] Figure 3 A module diagram of a session message processing device provided in an embodiment of the present application is shown.
[0021] Figure 4 A structural diagram of another network device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0022] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0023] It should be noted that similar numbers and letters represent similar items in the following figures, so once an item is defined in one figure, it does not need to be further defined and explained in the subsequent figures. At the same time, in the description of this application, relational terms such as "first", "second", etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements includes not only those elements, but also includes other elements that are not clearly listed, or also includes elements inherent to such process, method, article or equipment. In the absence of more restrictions, the elements defined by the sentence "comprise a..." do not exclude the presence of other identical elements in the process, method, article or equipment including the elements.
[0024] Furthermore, the term "and / or" in this application is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0025] In view of the fact that the existing session message processing method requires a reserved session channel to ensure that the session messages of the same session can be forwarded to the CPU of the corresponding session through the reserved session channel for processing when they are not allocated to the corresponding CPU, it leads to a waste of reserved session channel resources and increases management costs. The embodiment of the present application provides a new session message processing method that does not require a reserved session channel. By adopting a solution in which the same session channel interface belongs to only one link aggregation group in the inbound direction and can belong to multiple link aggregation groups in the outbound direction, it is ensured that the session message can be sent to the CPU through the link aggregation group to which the session channel interface belongs in the inbound direction, and the session message that is not destined for the corresponding CPU can be forwarded to the corresponding CPU through other link aggregation groups formed by the members of the link aggregation group in the outbound direction, thereby improving the utilization rate of existing port resources and effectively reducing unnecessary port bandwidth consumption.
[0026] For a better understanding, the following Figure 1The structure of the network device shown illustrates the principle of the session message processing method provided in the embodiment of the present application. The network device includes: a data exchange matrix unit (a switching chip, or a module unit containing a switching chip) and multiple CPUs, and the data exchange matrix unit is connected to each CPU through a different session channel interface. When the network device has a distributed architecture, the multiple CPUs are respectively located on different main processing units (MPUs) with service ports. The communication between the data exchange matrix unit and each MPU is the communication with each CPU.
[0027] The data exchange matrix unit has multiple service ports, presented to the outside world (i.e., users), for example, 32 service ports. Each service port is assigned a VLAN (Virtual Local Area Network). Data packets from the same VLAN can be forwarded to each other. Each VLAN is assigned a unique VLAN tag, and different service ports are assigned different VLAN tags. For example, the 32 service ports are assigned VLANs 1 to 32, totaling 32 VLAN tags. For example, service port 1 is assigned VLAN 1, service port 2 is assigned VLAN 2, and so on, service port 32 is assigned VLAN 32. See Table 1 for details.
[0028] Table 1
[0029] VLAN Business Port 1 1 2 2 … … 32 32
[0030] Figure 1In the data exchange matrix unit, there are three pairs of interfaces interconnecting each CPU. The interfaces connected to CPU0 in the data exchange matrix unit are interface S0, interface S1, and interface SM0. Interfaces S0 and S1 are session channel interfaces (also called data channel interfaces) connected to CPU0, and interface SM0 is a management channel interface. The interfaces connected to interfaces S0, S1, and SM0 in CPU0 are interface A0, interface A1, and interface AM0. The interfaces connected to CPU1 in the data exchange matrix unit are interface S2, interface S3, and interface SM1. Interfaces S2 and S3 are session channel interfaces (also called data channel ports) connected to CPU1, and interface SM1 is a management channel interface. The interfaces connected to interfaces S2, S3, and SM1 in CPU1 are interface B0, interface B1, and interface BM0. The interfaces connected to CPU2 in the data exchange matrix unit are interface S4, interface S5, and interface SM2. Interface S4 and interface S5 are session channel interfaces (also called data channel ports) connected to CPU2, and interface SM2 is a management channel port. The interfaces in CPU2 corresponding to interface S4, interface S5, and interface SM2 are C0, interface C1, and interface CM0. It should be noted that the number of session channel interfaces connected to each CPU in the data exchange matrix unit can be greater than or equal to 2. In addition, the number of CPUs can also be greater than or equal to 3, so it is not possible to Figure 2 The situations shown are understood to be limitations of this application.
[0031] In this application, since there is no need to reserve session channels, the session channel interfaces connecting the data exchange matrix unit to all CPUs can be added to the same aggregation group (hereinafter referred to as "aggregation group A"), and aggregation group A is added to the VLANs to which the service ports of the data exchange matrix unit belong, that is, to VLANs 1 to VLAN 32, a total of 32 VLANs 32, so that session packets received by each service port can be forwarded to the corresponding CPU through aggregation group A. For example, the above-mentioned interfaces S0, S1, S2, S3, S4, and S5 are added to aggregation group A, and aggregation group A is added to VLANs 1 to VLAN 32 respectively. See Table 2 for details. It should be noted that in the prior art, for each CPU, the data exchange matrix unit needs to reserve at least one session channel interface, and only some session channel interfaces can be added to aggregation group A. For example, interface S0, interface S2, and interface S4 are added to aggregation group A, interface S1 is used as the reserved session channel interface of CPU0, interface S3 is used as the reserved session channel interface of CPU1, and interface S5 is used as the reserved session channel interface of CPU2. This will result in a waste of session channel interfaces.
[0032] Table 2
[0033]
[0034] Add the session channel interface connecting the data switching matrix unit to each CPU to other link aggregation groups in the outbound direction. Multiple session channel interfaces connecting the data switching matrix unit to the same CPU belong to the same link aggregation group in the outbound direction. This link aggregation group is responsible for forwarding session packets with specific VLAN tags only. For example, add interfaces S0 and S1 to aggregation group lag0 in the outbound direction, add interfaces S2 and S3 to aggregation group lag1 in the outbound direction, and add interfaces S4 and S5 to aggregation group lag2 in the outbound direction. Then, add aggregation groups lag0, lag1, and lag2 to other VLANs (such as VLANs 100 to 102). For details, see Table 3.
[0035] Table 3
[0036]
[0037] The same session channel interface of the data exchange matrix unit belongs to only one link aggregation group in the inbound direction and to multiple link aggregation groups in the outbound direction. As can be seen from Table 3, interfaces S0, S1, S2, S3, S4, and S5 in this application belong to only one aggregation group in the inbound direction and to multiple aggregation groups in the outbound direction. For example, interfaces S0 and S1 belong to both aggregation group A and aggregation group Lag0 in the outbound direction; similarly, interfaces S2 and S3 belong to both aggregation group A and aggregation group Lag1 in the outbound direction; and interfaces S4 and S5 belong to both aggregation group A and aggregation group Lag2 in the outbound direction.
[0038] Configure the corresponding ACL (Access Control List) rule to match VLAN tags, with the action being to redirect session packets with specific VLAN tags to the corresponding CPU. For example, aggregation group lag0 only forwards session packets with VLAN 100 tags, aggregation group lag1 only forwards session packets with VLAN 101 tags, and aggregation group lag2 only forwards session packets with VLAN 102 tags. Configure the ACL to redirect packets matching VLAN 100 to aggregation group lag0; packets matching VLAN 101 to aggregation group lag1; and packets matching VLAN 102 to aggregation group lag2. For details, see Table 4.
[0039] Table 4
[0040] Matches action VLAN 100 Redirect to aggregation group Lag0 VLAN 101 Redirect to aggregation group Lag1 VLAN 102 Redirect to aggregation group Lag2
[0041] After completing the above configuration, session messages can be forwarded to the CPU through the link aggregation group (such as aggregation group A). For session messages that have not reached the corresponding CPU, they can be forwarded to the corresponding CPU through other link aggregation groups (such as aggregation group Lag0, aggregation group Lag1 or aggregation group Lag2) composed of members of the link aggregation group. In this way, without reserving session channels, the session messages of the same session can be normally forwarded to the CPU of the corresponding session for processing when they are not assigned to the corresponding CPU.
[0042] When processing session packets, the data switching matrix unit is configured to obtain session packets received from a service port, tag the session packets with the VLAN tag corresponding to the service port, obtain session packets to be processed, and forward the session packets to the corresponding CPU via a second link aggregation group (such as aggregation group A described above) corresponding to the VLAN tag corresponding to the service port. The second link aggregation group members include multiple session channel interfaces of the data switching matrix unit connected to each CPU. For example, if the data switching matrix unit receives session packets 0, 1, and 2 via service port 1, it will tag VLAN 1 for each of these packets and then flood them to aggregation group A via VLAN flooding. Loading is performed using the load algorithm of aggregation group A. For example, if the packets of session 0 are loaded into CPU 0, some of the packets of session 1 are loaded into CPU 0 and some into CPU 1, and the packets of session 2 are loaded into CPU 2, then the packets of session 2 are loaded into CPU 2. For example, if sessions 0, 1, and 2 each contain 60 packets, the load situation in one embodiment is shown in Table 5.
[0043] Table 5
[0044] Session ID Number of messages Load conditions 0 60 S0 (30), S1 (30) 1 60 S2 (30), S0 (30) 2 60 S4 (30), S5 (30)
[0045] Each CPU is configured to, upon determining that a pending session packet received by the CPU needs to be forwarded to a corresponding target CPU for processing, tag the pending session packet with a target VLAN tag. The target VLAN tag is a VLAN tag supported for forwarding by the first link aggregation group (e.g., aggregation group Lag0, aggregation group Lag1, or aggregation group Lag2) to which the session channel interface connected to the target CPU belongs in the outbound direction. The first link aggregation group includes the session channel interface connected to the target CPU.
[0046] Each CPU is also used to synchronize the session table entry information corresponding to the session message (which can be the five-tuple information of the session message, usually referring to the source IP address, source port, destination IP address, destination port and transport layer protocol) to the management CPU when receiving the session message. The management CPU is used to determine the session message processed by each CPU based on the summarized session table entry information, and generate a session decision table based on the first-come-first-served principle (that is, the subsequent messages of the session will be assigned to the CPU where the first packet of the session is located for processing), and send the session decision table to each CPU so that the CPU can determine whether the session message to be processed received by its own CPU needs to be forwarded to the corresponding target CPU for processing based on the session decision table sent by the management CPU. Multiple messages belonging to the same session have the same five-tuple. At this time, the network device also includes a management CPU, and the management CPU is connected to each CPU.
[0047] It should be noted that in one embodiment, one of the multiple CPUs (e.g., CPU0) can, in addition to processing service packets (including session packets), also serve as the overall control hub and act as the management CPU. That is, the management CPU can be one of the multiple CPUs. In another embodiment, the management CPU can also be a separate CPU.
[0048] For a better understanding, the following example illustrates this. For example, after receiving messages from session 0 and session 1, CPU0 synchronizes the five-tuple information in the messages to the management CPU. After receiving messages from session 1, CPU1 synchronizes the five-tuple information in the messages to the management CPU. After receiving messages from session 2, CPU2 synchronizes the five-tuple information in the messages to the management CPU. The management CPU follows the first-come, first-served principle, such as deciding to process session 0 on CPU0, session 1 on CPU1, and session 2 on CPU2. Based on this, the management CPU generates a session decision table, as shown in Table 6. The session decision table is then distributed to each CPU. Based on this session decision table, CPU0 determines that the message from session 1 needs to be forwarded to CPU1 for processing. Because the first link aggregation group (aggregation group Lag1 in the example) to which the session channel interface connected to the target CPU (CPU1 in the example) belongs in the outbound direction supports forwarding VLAN 101, CPU0 will add VLAN 101 tags to the packets of session 1. Then, the packets of session 1 with the VLAN 101 tag are forwarded to the data switching matrix unit through aggregation group Lag0.
[0049] Table 6
[0050] Session ID Processing CPU 0 CPU0 1 CPU1 2 CPU2
[0051] When receiving a session message to be processed with a target VLAN tag, the data exchange matrix unit forwards the session message to be processed with the target VLAN tag to the target CPU through the first link aggregation group (such as the aggregation group lag1 mentioned above) for processing.
[0052] Based on the same inventive concept, the embodiment of the present application also provides a session message processing method, which is applied to a network device including multiple CPUs and data exchange matrix units. Figure 2 The method for processing the session message is described below.
[0053] S1: Determine that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing.
[0054] Among them, the CPU in the network device can determine that the unprocessed session message received by its own CPU needs to be forwarded to the corresponding target CPU for processing. In one embodiment, it can be determined that the unprocessed session message received by its own CPU needs to be forwarded to the corresponding target CPU for processing based on the session decision table sent by the management CPU. When each CPU receives a session message, it will synchronize the corresponding session table item information (such as five-tuple information) to the management CPU, so that the management CPU determines the session message processed by each CPU based on the summarized session table item information, generates a session decision table, and sends the session decision table to each CPU.
[0055] Before S1, the session message processing method further includes: obtaining a session message received from a service port, and adding a VLAN tag corresponding to the service port to the session message to obtain a session message to be processed, wherein different service ports correspond to different VLAN tags; forwarding the session message to be processed to a corresponding CPU via a second link aggregation group corresponding to the VLAN tag corresponding to the service port, wherein the second link aggregation group includes multiple session channel interfaces connected to each CPU.
[0056] Among them, the data exchange matrix unit in the network device can obtain the session message received from the service port, and add the VLAN tag corresponding to the service port to the session message to obtain the session message to be processed, and then forward the session message to be processed to the corresponding CPU through the second link aggregation group corresponding to the VLAN tag corresponding to the service port.
[0057] S2: Add a target VLAN tag to the session message to be processed.
[0058] When determining that the session message to be processed received by its own CPU needs to be forwarded to the corresponding target CPU for processing, the CPU adds a target VLAN tag to the session message to be processed, wherein the target VLAN tag is a VLAN tag supported for forwarding by the first link aggregation group to which the session channel interface of the data switching matrix unit connected to the target CPU belongs in the outgoing direction.
[0059] For example, when CPU0 determines that the message of session 1 needs to be forwarded to CPU1 for processing, it tags the message of session 1 with VLAN 101, which is supported by the first link aggregation group (aggregation group Lag1) to which the session channel interface connected to CPU1 belongs in the outgoing direction.
[0060] S3: Forwarding the to-be-processed session message with the target VLAN tag to the target CPU through the first link aggregation group for processing.
[0061] The CPU in the network device may forward the pending session message with the target VLAN tag to the target CPU for processing through the first link aggregation group. Specifically, the CPU forwards the pending session message with the target VLAN tag to the data exchange matrix unit through the session channel interface connected to the data exchange matrix unit, and the data exchange matrix unit forwards the pending session message with the target VLAN tag to the target CPU for processing through the first link aggregation group.
[0062] The session message processing method provided in the embodiment of the present application has the same implementation principle and technical effects as those of the aforementioned network device embodiment. For the sake of brief description, for matters not mentioned in the method embodiment, reference can be made to the corresponding content in the aforementioned network device embodiment.
[0063] Based on the same inventive concept, the embodiment of the present application further provides a session message processing device 100, such as Figure 3 The session message processing device 100 includes: a processing module 110 and a forwarding module 120 .
[0064] The processing module 110 is configured to determine whether a pending session message received by the current CPU needs to be forwarded to a corresponding target CPU for processing, and to add a target VLAN tag to the pending session message, wherein the target VLAN tag is a VLAN tag supported for forwarding by the first link aggregation group to which the session channel interface connected to the target CPU belongs in the outbound direction.
[0065] The forwarding module 120 is configured to forward the to-be-processed session message with the target VLAN tag to the target CPU through the first link aggregation group for processing.
[0066] The session message processing apparatus 100 further includes an acquisition module configured to acquire session messages received from a service port and tag the session messages with a VLAN tag corresponding to the service port to obtain the session messages to be processed, wherein different service ports correspond to different VLAN tags. Accordingly, a forwarding module 120 is further configured to forward the session messages to be processed to the corresponding CPU via a second link aggregation group corresponding to the VLAN tag corresponding to the service port, wherein the second link aggregation group includes multiple session channel interfaces connected to the respective CPUs by a data switching matrix unit.
[0067] The processing module is specifically configured to determine, based on the session decision table sent by the management CPU, that the session message to be processed received by the current CPU needs to be forwarded to the corresponding target CPU for processing. Upon receiving the session message, each CPU synchronizes the corresponding session table entry information to the management CPU, so that the management CPU determines the session message to be processed by each CPU based on the aggregated session table entry information, generates the session decision table, and sends the session decision table to each CPU.
[0068] The session message processing device 100 provided in the embodiment of the present application has the same implementation principle and technical effects as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference may be made to the corresponding content in the aforementioned method embodiment.
[0069] like Figure 4 As shown, Figure 4 The block diagram of a network device 200 provided in an embodiment of the present application is shown. The network device 200 includes: a transceiver 210, a memory 220, a communication bus 230, and a processor 240. In addition, the network device also includes a data exchange matrix unit (not shown in the figure).
[0070] The transceiver 210, the memory 220, and the processor 240 are electrically connected to each other directly or indirectly to achieve data transmission or interaction. For example, these components can be electrically connected to each other via one or more communication buses 230 or signal lines. The transceiver 210 is used to send and receive data. The memory 220 is used to store computer programs, such as Figure 3The software functional module shown in the figure is the session message processing device 100. The session message processing device 100 includes at least one software functional module that can be stored in the memory 220 in the form of software or firmware or embedded in the operating system (OS) of the network device 200. The processor 240 is configured to execute the executable module stored in the memory 220, such as the software functional module or computer program included in the session message processing device 100. For example, the processor 240 is configured to determine that a session message to be processed received by the current CPU needs to be forwarded to a corresponding target CPU for processing; add a target VLAN tag to the session message to be processed, wherein the target VLAN tag data exchange matrix unit is a VLAN tag supported for forwarding by the first link aggregation group to which the session channel interface connected to the target CPU belongs in the outbound direction; and forward the session message to be processed with the target VLAN tag to the target CPU via the first link aggregation group for processing.
[0071] Among them, the memory 220 can be, but is not limited to, random access memory (RAM), read only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.
[0072] The processor 240 may be an integrated circuit chip with signal processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The various methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor may be a microprocessor or the processor 240 may also be any conventional processor, etc.
[0073] The above-mentioned network device 200 includes but is not limited to a router, a firewall, etc.
[0074] An embodiment of the present application further provides a non-volatile computer-readable storage medium (hereinafter referred to as storage medium), on which a computer program is stored. When the computer program is run by a computer such as the above-mentioned network device 200, the session message processing method shown above is executed.
[0075] It should be noted that the various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referenced to each other.
[0076] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0077] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0078] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a computer-readable storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a laptop, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned computer-readable storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0079] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for processing session messages, characterized in that: The method is applied to a network device including multiple CPUs and a data exchange matrix unit, wherein multiple session channel interfaces of the data exchange matrix unit connected to the same CPU belong to the same link aggregation group in the outbound direction, and the link aggregation group is only responsible for forwarding session messages with a specific VLAN tag, wherein the specific VLAN tag is a VLAN tag supported by the link aggregation group for forwarding; the method comprises: The current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing; The current CPU adds a target VLAN tag to the session message to be processed, wherein the target VLAN tag is a VLAN tag supported for forwarding by the first link aggregation group to which the session channel interface of the data switching matrix unit connected to the target CPU belongs in the outbound direction; The current CPU forwards the session message to be processed with the target VLAN tag to the data switching matrix unit; The data exchange matrix unit forwards the to-be-processed session message with the target VLAN tag to the target CPU through the first link aggregation group for processing.
2. The method according to claim 1, characterized in that Before the current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing, the method further includes: The data exchange matrix unit obtains the session message received from the service port and adds a VLAN tag corresponding to the service port to the session message to obtain the session message to be processed, wherein different service ports correspond to different VLAN tags; The session message to be processed is forwarded to the corresponding CPU through the second link aggregation group corresponding to the VLAN tag corresponding to the service port, and the second link aggregation group members include multiple session channel interfaces of the data exchange matrix unit connected to each CPU.
3. The method according to claim 1, characterized in that The network device further includes a management CPU; the current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing, including: The current CPU determines that the received session message to be processed needs to be forwarded to the corresponding target CPU for processing based on the session decision table sent by the management CPU. When each CPU receives a session message to be processed, it synchronizes the corresponding session table entry information to the management CPU, so that the management CPU determines the session message to be processed by each CPU based on the summarized session table entry information, generates the session decision table, and sends the session decision table to each CPU.
4. A network device, characterized in that: include: Multiple CPUs, each CPU being configured to, upon determining that a session message to be processed received by the CPU itself needs to be forwarded to a corresponding target CPU for processing, tag the session message to be processed with a target VLAN tag, and forward the session message to be processed with the target VLAN tag to a data switching matrix unit, wherein the target VLAN tag is a VLAN tag supported for forwarding by a first link aggregation group to which a session channel interface of the data switching matrix unit connected to the target CPU belongs in an outbound direction; a data exchange matrix unit connected to each CPU via a different session channel interface, the data exchange matrix unit being configured to forward the to-be-processed session message with the target VLAN tag to the target CPU for processing via the first link aggregation group; Among them, multiple session channel interfaces of the data exchange matrix unit connected to the same CPU belong to the same link aggregation group in the outbound direction. The link aggregation group is only responsible for forwarding session messages with specific VLAN tags. The specific VLAN tags are VLAN tags supported by the link aggregation group for forwarding.
5. The network device according to claim 4, characterized in that The data exchange matrix unit has multiple external service ports, and different service ports correspond to different VLAN tags; the data exchange matrix unit is further used to: Acquire a session message received from a service port, and add a VLAN tag corresponding to the service port to the session message to obtain the session message to be processed; The session message to be processed is forwarded to the corresponding CPU through the second link aggregation group corresponding to the VLAN tag corresponding to the service port, and the second link aggregation group members include multiple session channel interfaces of the data exchange matrix unit connected to each CPU.
6. The network device according to claim 5, characterized in that The network device further includes a management CPU connected to each CPU; each CPU is further configured to synchronize session table entry information corresponding to the session message to be processed to the management CPU upon receiving the session message to be processed; The management CPU is used to determine the session messages processed by each CPU based on the aggregated session table information, generate a session decision table, and issue the session decision table to each CPU; Each CPU is further configured to determine, based on the session decision table sent by the management CPU, that the to-be-processed session message received by its own CPU needs to be forwarded to a corresponding target CPU for processing.
7. The network device according to any one of claims 4 to 6, characterized in that: The multiple CPUs are respectively located on different main control processing units MPU with service ports.
8. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is run by the network device, the session message processing method according to any one of claims 1 to 3 is executed.
Citation Information
Patent Citations
Packet forwarding method and device based on multi-core system
CN105634958A
Message forwarding method and device
CN107948076A